IP Library Granted Patent US 12,159,176
Granted Patent B2
US 12,159,176 · App. 17/491,224 · Granted Dec 3, 2024

Protecting instances of resources of a container orchestration platform from unintentional deletion

Inventors: Yuvaraja Mariappan (San Jose, CA); Thayumanavan Sridhar (Sunnyvale, CA); Sajeesh Mathew (Saratoga, CA); Raj Yavatkar (Los Gatos, CA); Senthilnathan Murugappan (Fremont, CA); Raja Kommula (Cupertino, CA); Kiran K N (Bangalore, IN)
Assignee: Juniper Networks, Inc.
G06F9/547G06F9/45558G06F2009/45562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,159,176
App. No.
17/491,224
Granted
Dec 3, 2024
Kind
B2
Abstract

A container orchestration platform manages a plurality of instances of resources including a first custom resource and a second custom resource. An API server of the container orchestration platform receives a request to delete an instance of the second custom resource; determines whether instance data associated with the instance of the second custom resource has a backreference identifying an instance of the first custom resource, the backreference indicating the instance of the first custom resource is dependent on the instance of the second custom resource; and in response to determining that the instance data has the backreference to the instance of the first custom resource, bypasses deletion of the instance of the second custom resource.

Claims (33)

1. A method comprising:

receiving, by an API server of a container orchestration platform managing a plurality of instances of custom resources including a first custom resource and a second custom resource, a request to create an instance of the first custom resource;

creating, by a reconciler and for an instance of the second custom resource, instance data including a backreference identifying the instance of the first custom resource, the backreference indicating the instance of the first custom resource is dependent on the instance of the second custom resource; and

based on determining that the instance data has the backreference identifying the instance of the first custom resource, bypassing deletion of the instance of the second custom resource.

2. The method of claim 1 , further comprising:

based on determining that the instance data has the backreference identifying the instance of the first custom resource, outputting an indication of an error for the request to delete the instance of the second customer resource.

3. The method of claim 1 , wherein based on determining that the instance data does not have a backreference identifying any custom resource, deleting the instance of the second custom resource.

4. The method of claim 1 , further comprising inserting, into the backreference, a label prefix distinguishing the backreference from other types of references and an identifier of the instance of the first custom resource.

5. The method of claim 4 , further comprising:

inserting a name into the backreference; and

hashing the identifier of the instance of the first custom resource to create a hash value of the identifier, wherein inserting the identifier of the instance of the first custom resource into the backreference comprises inserting the hash value into the backreference.

6. The method of claim 4 , wherein determining that the instance data has the backreference identifying the instance of the first custom resource comprises determining whether the instance data includes the label prefix.

7. The method of claim 1 , wherein the API server comprises an extension API server for handling requests identifying the second custom resource.

8. The method of claim 1 , wherein determining that the instance data has the backreference identifying the instance of the first custom resource comprises determining, by a webhook associated with a validating admission block of the API server, that the instance data has the backreference identifying the instance of the first custom resource.

9. The method of claim 1 , wherein the backreference of the instance of the second custom resource identifies the instance of the first custom resource to indicate dependence by the first custom resource on the second customer resource.

10. The method of claim 1 , wherein the container orchestration platform comprises Kubernetes.

11. A container orchestration system configured to manage a plurality of instances of resources including a first custom resource and a second custom resource, the container orchestration system comprising:

an API server comprising processing circuitry configured to:

receive a request to create an instance of the first custom resource;

create, for an instance of the second custom resource, instance data including a backreference identifying the instance of the first custom resource, the backreference indicating the instance of the first custom resource is dependent on the instance of the second custom resource; and

based on a determination that the instance data has the backreference identifying the instance of the first custom resource, bypassing deletion of the instance of the second custom resource.

12. The container orchestration system of claim 11 , wherein the API server is further configured to, based on a determination that the instance data has the backreference identifying the instance of the first custom resource, output an indication of an error for the request to delete the instance of the second customer resource.

13. The container orchestration system of claim 11 , wherein the API server is further configured to, based on a determination that the instance data does not have a backreference identifying any custom resource, delete the instance of the second custom resource.

14. The container orchestration system of claim 11 , wherein the processing circuitry is further configured to insert, into the backreference, a label prefix distinguishing the backreference from other types of references and an identifier of the instance of the first custom resource.

15. The container orchestration system of claim 14 , wherein the processing circuitry is further configured to:

insert a name into the backreference; and

hash the identifier of the instance of the first custom resource to create a hash value of the identifier, wherein to insert the identifier of the instance of the first custom resource into the backreference comprises to insert the hash value into the backreference.

16. The container orchestration system of claim 14 , wherein to determine that the instance data has the backreference identifying the instance of the first custom resource the processing circuitry is further configured to determine whether the instance data includes the label prefix.

17. The container orchestration system of claim 11 , wherein the API server comprises an extension API server for handling requests identifying the second custom resource.

18. A non-transitory computer-readable storage medium having instructions stored thereon that cause one or more processors of a container orchestration platform managing a plurality of instances of resources including a first custom resource and a second custom resource to perform operations comprising:

receive a request to create an instance of the first custom resource;

create, for an instance of the second custom resource, instance data including a backreference identifying the instance of the first custom resource, the backreference indicating the instance of the first custom resource is dependent on the instance of the second custom resource; and

based on a determination that the instance data has the backreference identifying the instance of the first custom resource, bypass deletion of the instance of the second custom resource.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2025
From: YAVATKAR, RAJENDRA SHIVARAM
To: JUNIPER NETWORKS, INC.
Reel/Frame 073226/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: MARIAPPAN, YUVARAJA; SRIDHAR, THAYUMANAVAN; MATHEW, SAJEESH; YAVATKAR, RAJ; MURUGAPPAN, SENTHILNATHAN; KOMMULA, RAJA; K N, KIRAN
To: JUNIPER NETWORKS, INC.
Reel/Frame 057662/0347 →
Continuity (1)
Related Publication 20230101973A1 · Mar 30, 2023
Cited By (2)
US 12,418,495 US 12,423,289