IP Library › Granted Patent US 11,805,102
Granted Patent B2
US 11,805,102 · App. 17/168,648 · Granted Oct 31, 2023

Remote management of software on private networks

Inventor: Matt Albert Woodson (Raleigh, NC)
Assignee: RED HAT, INC.
H04L63/0281H04L9/3073H04L9/321H04L63/029H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,102
App. No.
17/168,648
Granted
Oct 31, 2023
Kind
B2
Abstract

Systems and methods for remote management of software on private networks are generally described. In various examples, a cluster of compute instances are deployed by a cloud compute service provider. A first compute pod may be deployed among the cluster of compute instances. The first compute pod may be configured to execute a secure shell daemon (SSHD) network proxy. The first compute pod may be configured to open ports to allow access to the cluster of compute instances by an authorized administrative user. In some examples, a connection may be established between a first computing device executing a secure shell (SSH) process and the SSHD network proxy of the first compute pod. Data may be sent from the first computing device to at least one compute instance of the cluster of compute instances using the connection.

Claims (47)

1. A method comprising:

deploying a cluster of compute instances with a cloud compute service provider;

deploying a first compute pod among the cluster of compute instances, the first compute pod configured to execute a secure shell daemon (SSHD) network proxy, wherein the first compute pod is configured to open ports to allow access to the cluster of compute instances by an authorized administrative user;

establishing a connection between a first computing device executing a secure shell (SSH) process and the SSHD network proxy of the first compute pod;

sending data from the first computing device to at least one compute instance of the cluster of compute instances using the connection;

deleting, by the first compute pod, configuration data of the SSHD network proxy, the configuration data defining open ports and/or firewall rules; and

removing the first compute pod from the cluster of compute instances.

2. The method of claim 1 , wherein the cluster of compute instances deploys at least one software application and wherein the cluster is managed using a container application platform.

3. The method of claim 1 , wherein the cluster of compute instances is deployed on a private network that is inaccessible using the Internet.

4. The method of claim 1 , wherein the first compute pod is configured to open the ports and internet protocol (IP) addresses that are associated with the authorized administrative user, wherein the ports and the IP addresses enable access by the authorized administrative user to the cluster of compute instances and software deployed by the cluster of compute instances.

5. The method of claim 1 , further comprising executing, by the first computing device a client application configured to initialize the SSH process and the connection as an SSH tunnel.

6. The method of claim 1 , further comprising performing SSH authentication for the connection using a public-private key pair, the connection comprising an SSH tunnel.

7. The method of claim 6 , further comprising:

sending, by the first computing device to an authentication pod of the cluster of compute instances, authentication data configured to authenticate the first computing device to the cluster of compute instances; and

authenticating, by the authentication pod, the first computing device to the cluster of compute instances.

8. The method of claim 7 , further comprising sending the data from the first computing device, using the SSH tunnel, to the at least one compute instance of the cluster of compute instances via the SSHD network proxy, wherein the data is encrypted using a public key of the public-private key pair.

9. The method of claim 1 , further comprising:

deploying a second compute pod among a second plurality of computing resources, the second compute pod configured to execute a second SSHD network proxy enabling communication between the administrator computing device and the second plurality of computing resources using a second SSH process.

10. A system comprising:

a cloud service comprising a plurality of computing resources; and

an administrator device, comprising:

at least one processor; and

non-transitory computer-readable memory storing instructions that, when executed by the at least one processor, are configured to:

deploy a cluster of compute instances on the plurality of computing resources;

deploy a first compute pod among the cluster of compute instances, the first compute pod configured to execute a secure shell daemon (SSHD) network proxy, wherein the first compute pod is configured to open ports to allow access to the cluster of compute instances by the administrator device;

establish a connection with the SSHD network proxy of the first compute pod;

send data from the administrator device to at least one compute instance of the cluster of compute instances using the connection;

delete, by the first compute pod, configuration data of the SSHD network proxy, the configuration data defining open ports and/or firewall rules; and

remove the first compute pod from the cluster of compute instances.

11. The system of claim 10 , wherein a deployment of at least one software application on the cluster of compute instances is managed using a container application platform.

12. The system of claim 10 , wherein the cluster of compute instances is deployed on a private network that is inaccessible from the Internet.

13. The system of claim 10 , wherein the first compute pod includes configuration data specifying internet protocol (IP) addresses that are associated with the administrator device, wherein the IP addresses enable access by the administrator device to the cluster of compute instances and software deployed by the cluster of compute instances.

14. The system of claim 10 , storing further instructions that, when executed by the at least one processor, are further effective to execute, by the administrator device, a client application configured to initialize an SSH process and the connection as an SSH tunnel.

15. The system of claim 14 , storing further instructions that, when executed by the at least one processor, are further effective to perform SSH authentication for the SSH tunnel using a public-private key pair.

16. The system of claim 15 , storing further instructions that, when executed by the at least one processor, are further effective to:

send, by the administrator device to an authentication pod of the cluster of compute instances, authentication data configured to authenticate the administrator device to the cluster of compute instances; and

authenticate, by the authentication pod, the administrator device to the cluster of compute instances.

17. A non-transitory machine readable medium storing a program, which when executed by at least one processor causes the at least one processor to:

deploy a cluster of compute instances on a cloud service comprising a plurality of computing resources;

deploy a first compute pod among the cluster of compute instances, the first compute pod configured to execute a secure shell daemon (SSHD) network proxy, wherein the first compute pod is configured to open ports to allow access to the cluster of compute instances by an administrator device;

establish a connection with the SSHD network proxy of the first compute pod;

send data from the administrator device to at least one compute instance of the cluster of compute instances using the connection;

delete, by the first compute pod, configuration data of the SSHD network proxy, the configuration data defining open ports and/or firewall rules; and

remove the first compute pod from the cluster of compute instances.

18. The non-transitory machine readable medium of claim 17 , wherein a deployment of at least one software application on the cluster of compute instances is managed using a container application platform.

19. The non-transitory machine readable medium of claim 17 , wherein the cluster of compute instances is deployed on a private network that is inaccessible from the Internet.

20. The non-transitory machine readable medium of claim 17 , wherein the first compute pod includes configuration data specifying internet protocol (IP) addresses that are associated with the administrator device, wherein the IP addresses enable access by the administrator device to the cluster of compute instances and software deployed by the cluster of compute instances.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2021
From: WOODSON, MATT ALBERT
To: RED HAT, INC.
Reel/Frame 055164/0236 →
Continuity (1)
Related Publication 20220255902A1 · Aug 11, 2022
Cited By (1)
US 12,323,399