IP Library Granted Patent US 11,863,352
Granted Patent B2
US 11,863,352 · App. 17/185,844 · Granted Jan 2, 2024

Hierarchical networking for nested container clusters

Inventors: Jianjun Shen (Redwood City, CA); Mark Johnson (McKinleyville, CA); Gaetano Borgione (San Jose, CA); Benjamin John Corrie (Snohomish, WA); Derek Beard (Austin, TX); Zach James Shepherd (San Francisco, CA); Vinay Reddy (Pleasanton, CA)
Assignee: VMWARE, INC.
H04L12/66H04L45/42H04L45/44H04L45/586H04L47/125H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,352
App. No.
17/185,844
Granted
Jan 2, 2024
Kind
B2
Abstract

Some embodiments of the invention provide a novel network architecture for deploying guest clusters (GCs) including workload machines for a tenant (or other entity) within an availability zone. The novel network architecture includes a virtual private cloud (VPC) deployed in the availability zone (AZ) that includes a centralized routing element that provides access to a gateway routing element of the AZ. In some embodiments, the centralized routing element provides a set of services for packets traversing a boundary of the VPC. The services, in some embodiments, include load balancing, firewall, quality of service (QoS) and may be stateful or stateless. Guest clusters are deployed within the VPC and use the centralized routing element of the VPC to access the gateway routing element of the AZ.

Claims (16)

1. A method for deploying a plurality of guest clusters (GCs) for an entity in a datacenter comprising:

deploying a virtual private cloud (VPC) network for a first cluster of machines of the entity in the datacenter, the VPC network comprising a centralized routing element that provides access to a datacenter gateway routing element and provides a set of services for packets traversing a boundary of the first VPC; and

deploying, in the VPC network, a plurality of GCs and a GC network for each GC comprising a plurality of GC machines and a plurality of routing elements implementing a distributed routing element executing on a plurality of host computers along with GC machines, each GC network configured to use the VPC's centralized routing element to access the datacenter gateway routing element, wherein the GC comprises a set of service Pods for which a load balancer of the VPC provides a load balancing service,

wherein the set of service Pods connect to a network segment that is not directly reachable by the load balancer of the VPC, the load balancer of the VPC performs a first load balancing operation over a set of virtual machines (VMs) on which the Pods execute, and a VM in the set of VMs that receives a data message destined to a service Pod in the set of service Pods performs a second load balancing operation over the set of service Pods to select a service Pod in the set of service Pods and provide the data message to the selected service Pod.

2. The method of claim 1 , wherein each GC is a Kubernetes cluster.

3. The method of claim 1 , wherein the VPC is a Kubernetes cluster.

4. The method of claim 1 , wherein the VPC is a non-Kubernetes cluster comprising at least one of virtual machines and non-Kubernetes Pods.

5. The method of claim 1 , wherein a set of resources allocated to the VPC network are shared by the plurality of GC networks.

6. The method of claim 5 , wherein the shared resources comprise at least one of processing resources, storage resources, and network resources.

7. The method of claim 6 , wherein the shared resources comprise network resources and the network resources comprise a set of internet protocol (IP) addresses allocated to the VPC network.

8. The method of claim 1 , wherein the VPC network implements a distributed firewall comprising a set of firewall rules and each of the plurality of GC networks inherits the set of firewall rules for implementing the distributed firewall within the GC network.

9. The method of claim 1 , wherein the VPC network and a set of GC networks in the plurality of GC networks are deployed by a software defined datacenter manager that is aware of network addresses of each network component in the VPC network and the set of GC networks.

10. A system comprising:

a virtual private cloud (VPC) network for a first cluster of machines of an entity in a datacenter, the VPC network comprising a centralized routing element that provides access to a datacenter gateway routing element and provides a set of services for packets traversing a boundary of the first VPC; and

a plurality of guest clusters (GCs) and a GC network for each GC comprising a plurality of GC machines and a plurality of routing elements implementing a distributed routing element executing on a plurality of host computers along with GC machines, each GC network configured to use the VPC's centralized routing element to access the datacenter gateway routing element, wherein the GC comprises a set of service Pods for which a load balancer of the VPC provides a load balancing service,

wherein the set of service Pods connect to a network segment that is not directly reachable by the load balancer of the VPC, the load balancer of the VPC performs a first load balancing operation over a set of virtual machines (VMs) on which the Pods execute, and a VM in the set of VMs that receives a data message destined to a service Pod in the set of service Pods performs a second load balancing operation over the set of service Pods to select a service Pod in the set of service Pods and provide the data message to the selected service Pod.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2021
From: SHEN, JIANJUN; JOHNSON, MARK; BORGIONE, GAETANO; CORRIE, BENJAMIN JOHN; BEARD, DEREK; SHEPHERD, ZACH JAMES; REDDY, VINAY
To: VMWARE, INC.
Reel/Frame 055422/0187 →
Continuity (2)
Provisional Application 63058490 · Jul 30, 2020
Related Publication 20220038311A1 · Feb 3, 2022