IP Library Granted Patent US 12,218,942
Granted Patent B2
US 12,218,942 · App. 16/994,099 · Granted Feb 4, 2025

Methods and apparatus for automatic configuration of a containerized computing namespace

Inventors: Miroslav Shipkovenski (Sofia, BG); Stanislav Asenov Hadjiiski (Sofia, BG); Georgi Muleshkov (Sofia, BG)
Assignee: VMware LLC
H04L63/102G06F9/44505G06F9/45545H04L63/0823H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,942
App. No.
16/994,099
Granted
Feb 4, 2025
Kind
B2
Abstract

Methods, apparatus, systems and articles of manufacture for automatic configuration of a containerized computing namespace are disclosed. An example method includes identifying, in response to creation of a containerized computing namespace, a user account that is to be granted access to a containerized computing namespace, creating a service account, the service account representing the user account for the containerized computing namespace creating a role within the containerized computing namespace, and assigning a role binding between the role and the service account.

Claims (40)

1. An apparatus for configuration of a containerized computing namespaces, the apparatus comprising:

at least one processor;

memory including machine readable instructions that, when executed by the at least one processor, cause the at least one processor to at least:

identify, in response to creation of a containerized computing namespace, a user account that is to be granted access to the containerized computing namespace, the containerized computing namespace being associated with resources representing one or more Kubernetes pods;

create a service account, the service account representing the user account for the containerized computing namespace;

create a role within the containerized computing namespace;

assign a role binding between the role and the service account;

store a secret associated with the service account, the secret being stored in a namespace information memory, the secret being recalled for configuration file generation for the user account, wherein the secret includes a certificate and a token;

generate a configuration file including a name of the containerized computing namespace and the secret associated with the service account;

monitor the containerized computing namespace; and

provide the configuration file to a user, the configuration file to be used to grant access the containerized computing namespace;

wherein the resources associated with the containerized computing namespace are assigned based on roles assigned to users.

2. The apparatus of claim 1 , wherein the instructions, when executed, cause the at least one processor to create the containerized computing namespace.

3. The apparatus of claim 1 , wherein the instructions, when executed, cause the at least one processor to assign permissions to the role.

4. The apparatus of claim 1 , wherein the roles are defined to limit access to a resource within a namespace.

5. At least one non-transitory computer readable medium comprising instructions that, when executed, cause at least one processor to at least:

identify, in response to creation of a containerized computing namespace, a user account that is to be granted access to the containerized computing namespace, the containerized computing namespace being associated with resources representing one or more Kubernetes pods;

create a service account, the service account representing the user account for the containerized computing namespace;

create a role within the containerized computing namespace;

assign a role binding between the role and the service account;

store a secret associated with the service account, the secret being stored in a namespace information memory, the secret being recalled for configuration file generation for the user account, wherein the secret includes a certificate and a token;

generate a configuration file including a name of the containerized computing namespace and the secret associated with the service account;

monitor the containerized computing namespace; and

provide the configuration file to a user, the configuration file to be used to grant access the containerized computing namespace;

wherein the resources associated with the containerized computing namespace are assigned based on roles assigned to users.

6. The at least one non-transitory computer readable medium of claim 5 , wherein the instructions, when executed, cause the at least one processor to create the containerized computing namespace.

7. The at least one non-transitory computer readable medium of claim 5 , wherein the instructions, when executed, cause the at least one processor to assign permissions to the role.

8. A method for configuration of a containerized computing namespaces, the method comprising:

identifying, by executing an instruction with at least one processor, in response to creation of a containerized computing namespace, a user account that is to be granted access to the containerized computing namespace, the containerized computing namespace being associated with resources representing one or more Kubernetes pods;

creating, by executing an instruction with the at least one processor, a service account, the service account representing the user account for the containerized computing namespace;

creating a role within the containerized computing namespace;

assigning a role binding between the role and the service account;

storing a secret associated with the service account, the secret being stored in a namespace information memory, the secret being recalled for configuration file generation for the user account, wherein the secret includes a certificate and a token;

generating a configuration file including a name of the containerized computing namespace and the secret associated with the service account;

monitor the containerized computing namespace; and

providing the configuration file to a user, the configuration file to be used to grant access the containerized computing namespace;

wherein the resources associated with the containerized computing namespace are assigned based on roles assigned to users.

9. The method of claim 8 , further including creating the containerized computing namespace.

10. The method of claim 8 , wherein the creating of the role within the containerized computing namespace further includes assigning permissions to the role.

11. The method of claim 8 , wherein the containerized computing namespace is a Kubernetes namespace.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2021
From: SHIPKOVENSKI, MIROSLAV; HADJIISKI, STANISLAV ASENOV; MULESHKOV, GEORGI
To: VMWARE, INC.
Reel/Frame 055184/0990 →