IP Library Granted Patent US 12,585,484
Granted Patent B2
US 12,585,484 · App. 17/821,232 · Granted Mar 24, 2026

General network policy for namespaces

Inventors: Danting Liu (Beijing, CN); Qian Sun (Beijing, CN); Jianjun Shen (Redwood City, CA); Wenfeng Liu (Beijing, CN); Donghai Han (Beijing, CN)
Assignee: VMware, Inc.
G06F9/45558H04L63/0263H04L63/20G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,484
App. No.
17/821,232
Granted
Mar 24, 2026
Kind
B2
Abstract

Disclosed herein is a system and method for controlling network traffic among namespaces in which various entities, such as virtual machines, pod virtual machines, and a container orchestration system, such as Kubernetes, reside and operate. The entities have access to a network that includes one or more firewalls. The traffic that is permitted to flow over the network among and between the namespaces is defined by a security policy definition. The security policy definition is posted to a master node in a supervisor cluster that supports and provisions the namespaces. The master node invokes a network manager to generate a set of firewall rules and program the one or more firewalls in the network to enforce the rules.

Claims (41)

1 . A method for controlling network traffic among a plurality of namespaces, the method comprising:

creating a security policy definition describing allowed traffic on a network, the network including one or more firewalls, wherein one or more entities reside and operate in each namespace of the plurality of namespaces and have access to each other via the network; and

sending the security policy definition to a node that supports the plurality of namespaces, wherein the node sends the security policy definition to a network manager that formulates a set of rules for the one or more firewalls controlling the allowed traffic on the network according to the security policy definition, and

wherein the one or more firewalls enforce the set of rules controlling the allowed traffic on the network.

2 . The method of claim 1 , wherein the node supporting the plurality of namespaces is a master node in a Kubernetes cluster, the master node having an application programming interface that receives the security policy definition.

3 . The method of claim 1 , wherein the security policy definition includes a namespace and one or more of:

an ingress policy to the namespace;

an egress policy from the namespace; or

a network protocol for controlling the allowed traffic on the network.

4 . The method of claim 1 , wherein one of the entities of the one or more entities is a virtual machine residing in a first namespace, and another one of the entities is a pod virtual machine residing in a second namespace, and the security policy definition applies to the virtual machine and the pod virtual machine.

5 . The method of claim 1 , wherein one of the entities of the one or more entities is a pod virtual machine residing in a first namespace, and another one of the entities of the one or more entities is a Kubernetes cluster associated with a second namespace, and the security policy definition applies to the Kubernetes cluster and the pod virtual machine.

6 . The method of claim 1 , wherein the security policy definition includes a namespace and allows no traffic in or out of the namespace.

7 . The method of claim 1 , wherein one of the entities of the one or more entities is a load balancer service, and the security policy definition allows traffic only into and not out of the load balancer service.

8 . A system comprising:

a supervisor cluster having a master node and supporting a plurality of namespaces;

an entity residing and operating in each of the namespaces in the plurality of namespaces; and

a network providing access among each of the respective entities, the network including one or more firewalls;

wherein the master node is configured to:

receive a security policy definition describing allowed traffic on the network; and

send the security policy definition to a network manager that formulates a set of rules for the one or more firewalls controlling the allowed traffic on the network according to the security policy definition, wherein the one or more firewalls enforce the set of rules controlling the allowed traffic on the network.

9 . The system of claim 8 , wherein the master node has an application programming interface that receives the security policy definition.

10 . The system of claim 8 , wherein the security policy definition includes a namespace and one or more of:

an ingress policy to the namespace;

an egress policy from the namespace; or

a network protocol for controlling the allowed traffic on the network.

11 . The system of claim 8 , wherein one of the entities of the one or more entities is a virtual machine residing in a first namespace, and another one of the entities is a pod virtual machine residing in a second namespace, and the security policy definition applies to the virtual machine and the pod virtual machine.

12 . The system of claim 8 , wherein one of the entities of the one or more entities is a pod virtual machine residing in a first namespace, and another one of the entities of the one or more entities is a Kubernetes cluster associated with a second namespace, and the security policy definition applies to the Kubernetes cluster and the pod virtual machine.

13 . The system of claim 8 , wherein the security policy definition includes a namespace and allows no traffic in or out of the namespace.

14 . The system of claim 8 , wherein one of the entities of the one or more entities is a load balancer service, and the security policy definition allows traffic only into and not out of the load balancer service.

15 . A non-transitory computer-readable medium comprising instructions, which, when executed, cause a computer system to carry out a method for controlling network traffic among a plurality of namespaces, the method comprising:

creating a security policy definition describing allowed traffic on a network, the network including one or more firewalls, wherein one or more entities reside and operate in each namespace of the plurality of namespaces and have access to each other via the network; and sending the security policy definition to a node that supports the plurality of namespaces,

wherein the node sends the security policy definition to a network manager that formulates a set of rules for the one or more firewalls controlling the allowed traffic on the network according to the security policy definition, and

wherein the one or more firewalls enforce the set of rules controlling the allowed traffic on the network.

16 . The non-transitory computer-readable medium of claim 15 , wherein the node supporting the plurality of namespaces is a master node in a Kubernetes cluster, the master node having an application programming interface that receives the security policy definition.

17 . The non-transitory computer-readable medium of claim 15 , wherein the security policy definition includes a namespace and one or more of:

an ingress policy to the namespace;

an egress policy from the namespace, or

a network protocol for controlling the allowed traffic on the network.

18 . The non-transitory computer-readable medium of claim 15 , wherein one of the entities of the one or more entities is a pod virtual machine residing in a first namespace, and another one of the entities of the one or more entities is a Kubernetes cluster associated with a second namespace, and the security policy definition applies to the Kubernetes cluster and the pod virtual machine.

19 . The non-transitory computer-readable medium of claim 15 , wherein one of the entities is a pod virtual machine residing in a first namespace, and another one of the entities is a Kubernetes cluster associated with a second namespace, and the security policy definition applies to the Kubernetes cluster and the pod virtual machine.

20 . The non-transitory computer-readable medium of claim 15 , wherein one of the entities of the one or more entities is a load balancer service, and the security policy definition allows traffic only into and not out of the load balancer service.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2022
From: LIU, DANTING; SUN, QIAN; SHEN, JIANJUN; LIU, WENFENG; HAN, DONGHAI
To: VMWARE, INC.
Reel/Frame 060855/0406 →
Continuity (1)
Related Publication 20240028358A1 · Jan 25, 2024
References Cited (4)
US 20190386891A1 · Chitalia · 2019 [cited by examiner]
US 20200218798A1 · Kosaka · 2020 [cited by examiner]
US 20210218652A1 · Raut · 2021 [cited by examiner]
US 20230104129A1 · Miriyala · 2023 [cited by examiner]