IP Library › Granted Patent US 12,015,603
Granted Patent B2
US 12,015,603 · App. 17/643,784 · Granted Jun 18, 2024

Multi-tenant mode for serverless code execution

Inventors: Mikhail Danilov (Sammamish, WA); Deepthi Chelupati (Issaquah, WA); David Nasi (Seattle, WA); Dylan Owen Marriner (Seattle, WA); Suganya Rajendran (Bellevue, WA); Sean Tyler Myers (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L63/083G06F9/5077H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,015,603
App. No.
17/643,784
Granted
Jun 18, 2024
Kind
B2
Abstract

Systems and methods are described for a multi-tenant mode of a serverless code execution system. For instance, a method may include maintaining a set of execution environments, wherein each execution environment is associated with a serverless function, wherein the serverless function is associated with a software as a service (SaaS) provider that is a tenant of a cloud services provider, wherein the SaaS provider provides services to sub-tenants, wherein the set of execution environments are partitioned based on sub-tenants of the SaaS provider; receiving a call to execute a serverless function, wherein the call includes a serverless function identifier and a sub-tenant identifier; identifying a sub-tenant-specific execution environment of the set of execution environments that is associated with the sub-tenant; and in response to identifying the tenant-specific execution environment, invoking the serverless function on the sub-tenant-specific execution environment.

Claims (47)

1. A serverless code execution system comprising:

one or more data stores including information for a set of identity and access management (IAM) policies defining access to a serverless function hosted by the serverless code execution system, wherein the serverless function is associated with a software as a service (SaaS) provider;

one or more worker devices hosting a set of execution environments, wherein each execution environment is associated with the serverless function, and wherein the set of execution environments are partitioned based on sub-tenants of the SaaS provider; and

one or more computing devices of the serverless code execution system configured to:

receive a call to execute a serverless function, wherein the call includes a serverless function identifier and a sub-tenant identifier;

determine whether the serverless function is configured for a multi-tenant mode of the serverless code execution system based on the serverless function identifier;

in response to determining the serverless function is configured for the multi-tenant mode of the serverless code execution system, determine whether the call is authorized to proceed based on at least an IAM policy of the set of IAM policies;

in response to determining the call is authorized to proceed, determine a sub-tenant of the sub-tenants based on the sub-tenant identifier;

in response to determining the sub-tenant, identify a sub-tenant-specific execution environment of the set of execution environments that is associated with the sub-tenant, wherein other calls to execute the serverless function from other sub-tenants of the sub-tenants are blocked from being invoked on the sub-tenant-specific execution environment; and

in response to identifying the sub-tenant-specific execution environment, invoke the serverless function on the sub-tenant-specific execution environment.

2. The serverless code execution system of claim 1 , wherein the one or more computing devices are further configured to, using the sub-tenant-specific execution environment, interact with one or more tenant services to access sub-tenant data, in accordance with an authentication token indicating the sub-tenant.

3. The serverless code execution system of claim 1 , wherein, to identify the sub-tenant-specific execution environment associated with the sub-tenant, the one or more computing devices are further configured to:

determine whether any execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier; and

in response to determining none of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier, instantiate the sub-tenant-specific execution environment, wherein, to instantiate the sub-tenant-specific execution environment, the one or more computing devices generate the sub-tenant-specific execution environment with an authentication token so that the sub-tenant-specific execution environment assumes the role of the sub-tenant.

4. The serverless code execution system of claim 3 , wherein, to instantiate the sub-tenant-specific execution environment, the one or more computing devices are further configured to select a non-tenant-specific execution environment in a warm state to be modified into the sub-tenant-specific execution environment, or create the sub-tenant-specific execution environment, wherein the one or more computing devices of the serverless code execution system pass the authentication token to the sub-tenant-specific execution environment.

5. A computer-implemented method comprising:

maintaining, by a multi-tenant cloud services provider, a set of execution environments, wherein each execution environment is associated with a serverless function, wherein the serverless function is associated with a software as a service (SaaS) provider that is a tenant of the cloud services provider, wherein the SaaS provider provides services to a plurality of sub-tenants, wherein the set of execution environments are partitioned based on sub-tenants of the SaaS provider;

receiving a call to execute a serverless function, wherein the call includes a serverless function identifier and a sub-tenant identifier;

identifying a sub-tenant-specific execution environment of the set of execution environments that is associated with the sub-tenant identifier; and

invoking the serverless function on the sub-tenant-specific execution environment.

6. The computer-implemented method of claim 5 , further comprising, using the sub-tenant-specific execution environment, interacting with one or more tenant services to access tenant data, in accordance with an authentication token indicating the sub-tenant.

7. The computer-implemented method of claim 5 , wherein identifying the sub-tenant-specific execution environment that is associated with the sub-tenant includes:

determining whether any execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier; and

in response to determining none of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier, instantiating the sub-tenant-specific execution environment, wherein instantiating the sub-tenant-specific execution environment includes generating the sub-tenant-specific execution environment with an authentication token so that the sub-tenant-specific execution environment assumes the role of the sub-tenant.

8. The computer-implemented method of claim 7 , wherein instantiating the sub-tenant-specific execution environment includes selecting a non-tenant-specific execution environment in a warm state to be modified into the sub-tenant-specific execution environment, or creating the sub-tenant-specific execution environment, wherein the sub-tenant-specific execution environment obtains the authentication token based on the sub-tenant identifier.

9. The computer-implemented method of claim 5 , wherein identifying the sub-tenant-specific execution environment associated with the sub-tenant includes:

determining whether any execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier; and

in response to determining at least one execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier, selecting an execution environment of the at least one execution environment to be the sub-tenant-specific execution environment.

10. The computer-implemented method of claim 9 , further comprising, before selecting the execution environment of the at least one execution environment to be the sub-tenant-specific execution environment, determining whether any of the at least one execution environment are available to handle the call.

11. The computer-implemented method of claim 5 , further comprising, before invoking the serverless function on the sub-tenant-specific execution environment, determining whether the call is authorized to proceed based on at least an IAM policy of a set of IAM policies and/or a context of the call.

12. The computer-implemented method of claim 11 , wherein determining whether the call is authorized to proceed based on the context includes retrieving contextual data; determining whether one or more conditions are satisfied to limit call rates; and in response to none of the one or more conditions are satisfied, determining the call is authorized to proceed.

13. One or more non-transitory computer-readable media comprising computer-executable instructions that, when executed on a serverless compute system, cause the serverless compute system to:

maintain, by a multi-tenant cloud services provider, a set of execution environments, wherein each execution environment is associated with a serverless function, wherein the serverless function is associated with a software as a service (SaaS) provider that is a tenant of the cloud services provider, wherein the SaaS provider provides services to a plurality of sub-tenants, wherein the set of execution environments are partitioned based on sub-tenants of the SaaS provider;

receive a call to execute a serverless function, wherein the call includes a serverless function identifier and a sub-tenant identifier;

identify a sub-tenant-specific execution environment of the set of execution environments that is associated with the sub-tenant; and

invoke the serverless function on the sub-tenant-specific execution environment.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the sub-tenant-specific execution environment assumes the role of the sub-tenant.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the computer-executable instructions further cause the serverless computing system to, using the sub-tenant-specific execution environment, interact with one or more tenant services to access tenant data, in accordance with an authentication token indicating the sub-tenant.

16. The one or more non-transitory computer-readable media of claim 13 , wherein, to identify the sub-tenant-specific execution environment associated with the sub-tenant, the computer-executable instructions further cause the serverless computing system to:

determine whether any execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier; and

in response to determining none of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier, instantiate the sub-tenant-specific execution environment, wherein instantiating the sub-tenant-specific execution environment includes generating the sub-tenant-specific execution environment with an authentication token so that the sub-tenant-specific execution environment assumes the role of the sub-tenant.

17. The one or more non-transitory computer-readable media of claim 16 , wherein, to instantiate the sub-tenant-specific execution environment, the computer-executable instructions further cause the serverless computing system to: select a non-tenant-specific execution environment in a warm state to be modified into the sub-tenant-specific execution environment, or create the sub-tenant-specific execution environment, wherein the sub-tenant-specific execution environment obtains the authentication token based on the sub-tenant identifier.

18. The one or more non-transitory computer-readable media of claim 13 , wherein, to identify the sub-tenant-specific execution environment associated with the sub-tenant, the computer-executable instructions further cause the serverless computing system to:

determine whether any execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier; and

in response to determining at least one execution environment of the set of execution environments are associated with the sub-tenant identifier and the serverless function identifier, select an execution environment of the at least one execution environment to be the sub-tenant-specific execution environment.

19. The one or more non-transitory computer-readable media of claim 18 , wherein, before invoking the serverless function on the sub-tenant-specific execution environment, the computer-executable instructions further cause the serverless computing system to: determine whether the call is authorized to proceed based on at least an IAM policy of a set of IAM policies and/or a context of the call.

20. The one or more non-transitory computer-readable media of claim 19 , wherein, to determine whether the call is authorized to proceed based on the context, the computer-executable instructions further cause the serverless computing system to retrieve contextual data; determine whether one or more conditions are satisfied to limit call rates; and in response to none of the one or more conditions are satisfied, determine the call is authorized to proceed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2023
From: DANILOV, MIKHAIL; CHELUPATI, DEEPTHI; NASI, DAVID; MARRINER, DYLAN OWEN; RAJENDRAN, SUGANYA; MYERS, SEAN TYLER
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 063897/0119 →
Continuity (1)
Related Publication 20230188516A1 · Jun 15, 2023
Cited By (3)
US 12,314,752 US 12,321,766 US 12,327,133