IP Library › Granted Patent US 11,811,767
Granted Patent B2
US 11,811,767 · App. 17/837,819 · Granted Nov 7, 2023

Streamlined secure deployment of cloud services

Inventors: Vladimir Pogrebinsky (Redmond, WA); Sergei Popov (Edmonds, WA); Alexander Wayne Eager (Redmond, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/10G06F9/5016G06F9/5077G06F21/31H04L67/1001
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,767
App. No.
17/837,819
Granted
Nov 7, 2023
Kind
B2
Abstract

Techniques for streamlined secure deployment of cloud services in cloud computing environments are disclosed herein. In one embodiment, a method can include in response to receiving an instruction to deploy a cloud service in the cloud computing system, creating a deployment subscription to resources in the cloud computing system, the deployment subscription being owned by the deployment service and instantiating one or more computing resources accessible by the deployment service in the cloud computing system in accordance with the created deployment subscription. The method also includes retrieving one or more components of an application corresponding to the cloud service based on a manifest with the instantiated one or more computing resources and installing the retrieved one or more components of the application in the cloud computing system in accordance with an installation sequence identified in the manifest.

Claims (81)

1. A method for streamlined secure deployment in a cloud computing system configured to execute a deployment service, the method comprising:

receiving an instruction to deploy an application in the cloud computing system;

retrieving, based on the instruction, a manifest for the application, the manifest identifying a plurality of components of the application and an installation sequence for the plurality of components;

creating, by the deployment service and based on the manifest, a deployment subscription for the application in the cloud computing system, wherein:

the deployment subscription is created automatically without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and

the deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and

instantiating, based at least in part on the deployment subscription, a resource in the cloud computing system for executing the application.

2. The method of claim 1 , wherein instantiating the resource in the cloud computing system for executing the application comprises:

creating a directory for a component of the plurality of components of the application;

and copying the component into the directory.

3. The method of claim 1 , further comprising:

retrieving, using the resource, a component of the plurality of components of the application;

installing the component in the cloud computing system; and

executing the installed component to provide access to the application for the user of the cloud computing system without exposing the installed component to the user of the cloud computing system.

4. The method of claim 3 , further comprising collecting an account credential from the administrator of the cloud computing system, wherein retrieving the component uses the account credential collected from the administrator of the cloud computing system.

5. The method of claim 4 , wherein:

the manifest includes metadata identifying a property of an acceptable account credential;

instantiating the resource includes instantiating a secret storage; and

the method further comprises:

determining that the account credential collected from the administrator of the cloud computing system includes the property of the acceptable account credential; and

in response to determining that the account credential collected from the administrator of the cloud computing system includes the property of the acceptable account credential, storing the account credential in the secret storage.

6. The method of claim 1 , further comprising:

retrieving, using the resource, the plurality of components of the application;

installing the plurality of components of the application in the cloud computing system according to the installation sequence for the plurality of components; and

executing the installed plurality of components of the application to provide access to the application for the user of the cloud computing system without exposing the installed plurality of components of the application to the user of the cloud computing system.

7. The method of claim 1 , wherein creating the deployment subscription comprises:

transmitting, from the deployment service, a request for the deployment subscription to a resource manager of the cloud computing system; and

receiving, from the resource manager of the cloud computing system, an authorization to create the deployment subscription, the authorization identifying at least one of a quantity or a type of the resource.

8. The method of claim 1 , wherein:

instantiating the resource in the cloud computing system includes instantiating a secret storage; and the method further includes:

collecting an account credential from the administrator of the cloud computing system;

storing the account credential collected from the administrator of the cloud computing system in the secret storage; and

deploying, based on the account credential stored in the secret storage, another application in the cloud computing system in lieu of again collecting the account credential from the administrator of the cloud computing system.

9. The method of claim 1 , wherein:

the cloud computing system comprises a private cloud computing system; and

the method further comprises:

receiving, from a public cloud computing system, a notification indicating that the application is available for deployment or update in the private cloud computing system; and

in response to receiving the notification, generating the instruction for the deployment service to create the deployment subscription for the application in the cloud computing system.

10. A computing device in a cloud computing system configured to execute a deployment service, the computing device comprising:

a processor; and

a memory operatively coupled to the processor, the memory containing instructions executable by the processor to:

receive an instruction to deploy an application in the cloud computing system;

retrieve, based on the instruction, a manifest for the application, the manifest identifying a plurality of components of the application and an installation sequence for the plurality of components;

create, based on the manifest, a deployment subscription for the application in the cloud computing system, wherein:

the deployment subscription is created automatically without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and

the deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and

instantiate, based at least in part on the deployment subscription, a resource in the cloud computing system for executing the application.

11. The computing device of claim 10 , wherein instantiating the resource in the cloud computing system for executing the application comprises:

creating a directory for a component of the plurality of components of the application;

and copying the component into the directory.

12. The computing device of claim 10 , wherein the instructions are further executable by the processor to:

retrieve, using the resource, a component of the plurality of components of the application;

install the component in the cloud computing system; and

execute the installed component to provide access to the application for the user of the cloud computing system without exposing the installed component to the user of the cloud computing system.

13. The computing device of claim 12 , wherein the instructions are further executable by the processor to collect an account credential from the administrator of the cloud computing system, wherein retrieving the component uses the account credential collected from the administrator of the cloud computing system.

14. The computing device of claim 13 , wherein:

the manifest includes metadata identifying a property of an acceptable account credential;

instantiating the resource includes instantiating a secret storage; and

the instructions are further executable by the processor to:

determine that the account credential collected from the administrator of the cloud computing system includes the property of the acceptable account credential; and

in response to determining that the account credential collected from the administrator of the cloud computing system includes the property of the acceptable account credential, store the account credential in the secret storage.

15. The computing device of claim 10 , wherein the instructions are further executable by the processor to:

retrieve, using the resource, the plurality of components of the application;

install the plurality of components of the application in the cloud computing system according to the installation sequence for the plurality of components; and

execute the installed plurality of components of the application to provide access to the application for the user of the cloud computing system without exposing the installed plurality of components of the application to the user of the cloud computing system.

16. The computing device of claim 10 , wherein creating the deployment subscription comprises:

transmitting a request for the deployment subscription to a resource manager of the cloud computing system; and

receiving, from the resource manager of the cloud computing system, an authorization to create the deployment subscription, the authorization identifying at least one of a quantity or a type of the resource.

17. The computing device of claim 10 , wherein:

instantiating the resource in the cloud computing system includes instantiating a secret storage; and

the instructions are further executable by the processor to:

collect an account credential from the administrator of the cloud computing system;

store the account credential collected from the administrator of the cloud computing system in the secret storage; and

deploy, based on the account credential stored in the secret storage, another application in the cloud computing system in lieu of again collecting the account credential from the administrator of the cloud computing system.

18. Computer-readable storage media operatively coupled to a processor and containing instructions executable by the processor to:

receive an instruction to deploy an application in the cloud computing system;

retrieve, based on the instruction, a manifest for the application, the manifest identifying a plurality of components of the application and an installation sequence for the plurality of components;

create, based on the manifest, a deployment subscription for the application in the cloud computing system, wherein:

the deployment subscription is created automatically without interaction with an administrator of the cloud computing system or a user of the cloud computing system; and

the deployment subscription is hidden from the administrator of the cloud computing system and the user of the cloud computing system; and

instantiate, based at least in part on the deployment subscription, a resource in the cloud computing system for executing the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2022
From: POGREBINSKY, VLADIMIR; POPOV, SERGEI; EAGER, ALEXANDER WAYNE
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 060171/0407 →
Continuity (3)
Continuation 16290551 · Mar 1, 2019
Provisional Application 62772920 · Nov 29, 2018
Related Publication 20220374271A1 · Nov 24, 2022
Cited By (1)
US 12,609,934