IP Library › Granted Patent US 12,079,515
Granted Patent B2
US 12,079,515 · App. 17/733,781 · Granted Sep 3, 2024

Immutable nodes in a container system

Inventors: Taher Vohra (Sunnyvale, CA); Luis Pablo Pabón (Sturbridge, MA); Anne Cesa Klein (Mercer Island, WA)
Assignee: Pure Storage, Inc.
G06F3/0659G06F3/0604G06F3/0622G06F3/067
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,515
App. No.
17/733,781
Granted
Sep 3, 2024
Kind
B2
Abstract

A node of a container system is made immutable to containers (e.g., to applications operating in the containers) running on the node. For example, the node may be made immutable by performing a method comprising: mounting, by a container runtime operating on a node within a container system, a volume comprising a container image, wherein the node comprises storage resources; creating, on the node and based on access to the volume, an instance of a container associated with the container image; and mapping, with respect to the container, accesses to the storage resources to one or more volumes stored remotely from the node, where the storage resources on the node are immutable to the container based on the mapping the accesses to the storage resources to the one or more volumes.

Claims (37)

1. A method comprising:

mounting, on a node and based on a request from a container runtime for a container image, a virtual volume mapped to an off-node volume comprising the container image, wherein the node comprises on-node storage resources;

instantiating, on the node and based on the container runtime accessing the container image through the virtual volume, an instance of a container associated with the container image; and

mapping, with respect to the instance of the container instantiated on the node, accesses to the on-node storage resources to one or more off-node volumes, wherein the on-node storage resources are immutable to the instance of the container instantiated on the node based on the mapping the accesses to the on-node storage resources to the one or more off-node volumes.

2. The method of claim 1 , wherein an application operating in the instance of the container instantiated on the node has write privileges to the on-node storage resources of the node.

3. The method of claim 1 , further comprising:

mapping the one or more off-node volumes to one or more directories within a user space of the node.

4. The method of claim 1 , wherein the off-node volume comprising the container image further comprises the one or more off-node volumes, and wherein the one or more off-node volumes comprise data written by an application operating in the instance of the container instantiated on the node.

5. The method of claim 1 , further comprising:

mapping all operating system accesses directed to the on-node storage resources to the one or more off-node volumes.

6. The method of claim 1 , wherein the one or more off-node volumes are mapped to one or more directories used by an application that operates within the instance of the container instantiated on the node.

7. The method of claim 1 , wherein the one or more off-node volumes are mapped to one or more directories within a kernel namespace, wherein the one or more directories are associated with operation of the kernel, and wherein the instance of the container instantiated on the node operates within user space.

8. A system comprising:

one or more memories storing computer-executable instructions; and

one or more processors to execute the computer-executable instructions to:

mount, on a node and based on a request from a container runtime for a container image, a virtual volume mapped to an off-node volume comprising the container image, wherein the node comprises on-node storage resources;

instantiate, on the node and based on the container runtime accessing the container image through the virtual volume, an instance of a container associated with the container image; and

map, with respect to the instance of the container instantiated on the node, accesses to the on-node storage resources to one or more off-node volumes, wherein the on-node storage resources are immutable to the instance of the container instantiated on the node based on the mapping the accesses to the on-node storage resources to the one or more off-node volumes.

9. The system of claim 8 , wherein an application operating in the instance of the container instantiated on the node has write privileges to the on-node storage resources of the node.

10. The system of claim 8 , wherein the one or more processors further execute the computer-executable instructions to:

map the one or more off-node volumes to one or more directories within a user space of the node.

11. The system of claim 8 , wherein the off-node volume comprising the container image further comprises the one or more off-node volumes, and wherein the one or more off-node volumes comprise data written by an application operating in the instance of the container instantiated on the node.

12. The system of claim 8 , wherein the one or more processors further execute the computer-executable instructions to:

map all operating system accesses directed to the on-node storage resources to the one or more off-node volumes.

13. The system of claim 8 , wherein the one or more off-node volumes are mapped to one or more directories used by an application that operates within the instance of the container instantiated on the node.

14. The system of claim 8 , wherein the one or more off-node volumes are mapped to one or more directories within a kernel namespace, wherein the one or more directories are associated with operation of the kernel, and wherein the instance of the container instantiated on the node operates within user space.

15. A non-transitory, computer-readable medium storing computer instructions that, when executed, direct one or more processors of one or more computing devices to:

mount, on a node and based on a request from a container runtime for a container image, a virtual volume mapped to an off-node volume comprising the container image, wherein the node comprises on-node storage resources;

instantiate, on the node and based on the container runtime accessing the container image through the virtual volume, an instance of a container associated with the container image; and

map, with respect to the instance of the container instantiated on the node, accesses to the on-node storage resources to one or more off-node volumes, wherein the on-node storage resources are immutable to the instance of the container instantiated on the node based on the mapping the accesses to the on-node storage resources to the one or more off-node volumes.

16. The non-transitory, computer-readable medium of claim 15 , wherein an application operating in the instance of the container instantiated on the node has write privileges to the on-node storage resources of the node.

17. The non-transitory, computer-readable medium of claim 15 , wherein the one or more processors further execute the computer instructions to:

map the one or more off-node volumes to one or more directories within a user space of the node.

18. The non-transitory, computer-readable medium of claim 15 , wherein the off-node volume comprising the container image further comprises the one or more off-node volumes, and wherein the one or more off-node volumes comprise data written by an application operating in the instance of the container instantiated on the node.

19. The non-transitory, computer-readable medium of claim 15 , wherein the one or more processors further execute the computer instructions to:

map all operating system accesses directed to the on-node storage resources to the one or more off-node volumes.

20. The non-transitory, computer-readable medium of claim 15 , wherein the one or more off-node volumes are mapped to one or more directories used by an application that operates within the instance of the container instantiated on the node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2022
From: VOHRA, TAHER; PABÓN, LUIS PABLO; KLEIN, ANNE CESA
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 059716/0963 →
Continuity (2)
Continuation In Part 17580098 · Jan 20, 2022
Related Publication 20230229355A1 · Jul 20, 2023