IP Library › Granted Patent US 12,684,017
Granted Patent B2
US 12,684,017 · App. 17/487,524 · Granted Jul 14, 2026

Automated generation of objects for kubernetes services

Inventors: Chiradeep Vittal (Santa Clara, CA); Sharvari Mithyantha (Bangalore, IN); Apoorva Kamath (Bangalore, IN); Bharathi M (Bangalore, IN)
H04L63/20G06F9/45558H04L63/0227G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,684,017
App. No.
17/487,524
Filed
Sep 28, 2021
Granted
Jul 14, 2026
Kind
B2
Art Unit
2455
USPC
726/1
Abstract

Methods and systems for automatic generation of Kubernetes objects based on network security policies are described herein. A computing device may receive a template object file. The template object file may comprise a format for a Kubernetes Ingress object and/or a Kubernetes Custom Resource Definition. The template object file may comprise a template identifier. The computing device may receive an indication of a network security policy. The computing device may identify a Kubernetes service object that comprises the template identifier and generate, based on the template object file and based on the network security policy, a new Kubernetes object. The new Kubernetes object may comprise one or both of a new Kubernetes Ingress object for the Kubernetes service object, or a new CRD for the Kubernetes service object. The computing device may store the new Kubernetes object.

Claims (80)

1 . A computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing device to:

receive a template object file comprising:

a format for both of:

a Kubernetes Ingress object,

a Kubernetes Custom Resource Definition (CRD); and

a template identifier;

receive an indication of a network security policy;

identify a Kubernetes service object that comprises the template identifier; generate,

based on the template object file and based on the network security policy, a new Kubernetes object wherein:

the template object file defines structural parameters and placeholders to be populated;

the network security policy defines dynamic rules for access control and traffic filtering; and

the new Kubernetes object comprises:

a new Kubernetes Ingress object for the Kubernetes service object, and

a new CRD for the Kubernetes service object; and

store the newly generated Kubernetes object in a Kubernetes-accessible data store for deployment;

wherein the newly generated CRD comprises one or more programmatically-inserted Internet Protocol (IP) addresses indicated by the network security policy, and wherein the Kubernetes service object is configured with an IP blocklist to prevent communications, from the one or more IP addresses to the Kubernetes service object.

2 . The computing device of claim 1 , wherein the new Kubernetes Ingress object is configured to manage, based on the network security policy, input to the Kubernetes service object.

3 . The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to retrieve the indication of the network security policy based on detecting a change to the network security policy, and wherein the instructions, when executed by the one or more processors, cause the computing device to generate the new Kubernetes object based on detecting the change to the network security policy.

4 . The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

detect a change to the template object file;

generate, based on the change to the template object file, a second new Kubernetes object; and

replace the new Kubernetes object with a second new Kubernetes object.

5 . The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

responsive to detecting a deletion of the Kubernetes service object, delete one or more of:

the new Kubernetes Ingress object, or

the new CRD.

6 . The computing device of claim 1 , wherein the network security policy specifies a blocklist, and wherein the newly generated Kubernetes object is configured to filter traffic associated with the blocklist.

7 . A method comprising:

receiving, by a computing device, a template object file comprising:

a format for both of:

a Kubernetes Ingress object,

a Kubernetes Custom Resource Definition (CRD); and

a template identifier;

receiving, by the computing device, an indication of a network security policy; identifying, by the computing device, a Kubernetes service object that comprises the template identifier;

generating, by the computing device, based on the template object file, and based on the network security policy, a new Kubernetes object wherein:

the template object file defines structural parameters and placeholders to be populated;

the network security policy defines dynamic rules for access control and traffic filtering; and

the new Kubernetes object comprises:

a new Kubernetes Ingress object for the Kubernetes service object, and

a new CRD for the Kubernetes service object; and

storing, by the computing device, the newly generated Kubernetes object in a Kubernetes-accessible data store for deployment;

wherein the newly generated CRD comprises one or more programmatically-inserted Internet Protocol (IP) addresses indicated by the network security policy, and wherein the Kubernetes service object is configured with an IP blocklist to prevent communications, from the one or more IP addresses to the Kubernetes service object.

8 . The method of claim 7 , wherein the new Kubernetes Ingress object is configured to manage, based on the network security policy, input to the Kubernetes service object.

9 . The method of claim 7 , wherein retrieving the indication of the network security policy is based on detecting a change to the network security policy, and wherein generating the new Kubernetes object is based on detecting the change to the network security policy.

10 . The method of claim 7 , further comprising:

detecting a change to the template object file;

generating, based on the change to the template object file, a second new Kubernetes object; and

replacing the new Kubernetes object with a second new Kubernetes object.

11 . The method of claim 7 , further comprising:

responsive to detecting a deletion of the Kubernetes service object, delete one or more of:

the new Kubernetes Ingress object, or

the new CRD.

12 . The method of claim 7 , wherein the network security policy specifies a blocklist, and wherein the new Kubernetes object is configured to filter traffic associated with the blocklist.

13 . One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors of a computing device, cause the computing device to:

receive a template object file comprising:

a format for both of:

a Kubernetes Ingress object,

a Kubernetes Custom Resource Definition (CRD); and

a template identifier;

receive an indication of a network security policy;

identify a Kubernetes service object that comprises the template identifier;

generate, based on the template object file and based on the network security policy, a new Kubernetes object wherein:

the template object file defines structural parameters and placeholders to be populated;

the network security policy defines dynamic rules for access control and traffic filtering; and

the new Kubernetes object comprises:

a new Kubernetes Ingress object for the Kubernetes service object, and

a new CRD for the Kubernetes service object; and

store the newly generated Kubernetes object in a Kubernetes-accessible data store for deployment;

wherein the newly generated CRD comprises one or more programmatically-inserted Internet Protocol (IP) addresses indicated by the network security policy, and wherein the Kubernetes service object is configured with an IP blocklist to prevent communications, from the one or more IP addresses to the Kubernetes service object.

14 . The one or more non-transitory computer-readable media of claim 13 , wherein the new Kubernetes Ingress object is configured to manage, based on the network security policy, input to the Kubernetes service object.

15 . The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing device to retrieve the indication of the network security policy based on detecting a change to the network security policy, and wherein the instructions, when executed by the one or more processors, cause the computing device to generate the new Kubernetes object based on detecting the change to the network security policy.

16 . The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

detect a change to the template object file;

generate, based on the change to the template object file, a second new Kubernetes object; and

replace the new Kubernetes object with a second new Kubernetes object.

17 . The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

responsive to detecting a deletion of the Kubernetes service object, delete one or more of:

the new Kubernetes Ingress object, or the new CRD.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2021
From: VITTAL, CHIRADEEP; MITHYANTHA, SHARVARI; KAMATH, APOORVA; M, BHARATHI
To: CITRIX SYSTEMS, INC.
Reel/Frame 057626/0210 →
Continuity (1)
Related Publication 20230108778A1 · Apr 6, 2023
References Cited (8)
US 11102076B1 · Pieczul et al. · 2021 [cited by applicant]
US 12079242B2 · Banerjee · 2024 [cited by examiner]
US 20190052549A1 · Duggal · 2019 [cited by examiner]
US 20190158537A1 · Miriyala · 2019 [cited by applicant]
US 20210218652A1 · Raut · 2021 [cited by examiner]
US 20210318914A1 · Moyer · 2021 [cited by examiner]
US 20230079209A1 · Nallamothu · 2023 [cited by examiner]
CN 111752681A · 2020 [cited by examiner]