IP Library Granted Patent US 12,438,842
Granted Patent B2
US 12,438,842 · App. 18/212,677 · Granted Oct 7, 2025

High-availability egress access with consistent source IP addresses for workloads

Inventors: Quan Tian (Beijing, CN); Jianjun Shen (Redwood City, CA); Donghai Han (Beijing, CN); Shuyang Xin (Shanghai, CN); Wenqi Qiu (Beijing, CN)
Assignee: VMware LLC
H04L61/103H04L45/04H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,842
App. No.
18/212,677
Granted
Oct 7, 2025
Kind
B2
Abstract

Systems and methods for configuring an egress node for an egress pod set comprising one or more pods are provided. The egress pod set may be allocated one or more egress internet protocol (IP) addresses. The egress node may be selected among nodes of a cluster including the one or more pods. The egress node may be configured as the routing destination for an egress IP address selected among the one or more egress internet protocol (IP) addresses.

Claims (46)

1. A method for configuring an egress node for an egress pod set comprising one or more pods, the method comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set has a single active egress internet protocol (IP) address, wherein the single egress IP address is outside a classless inter-domain routing (CIDR) block of a subnet of the egress node, and wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node; and

configuring a router with a static route to associate the egress node with the single active egress IP address.

2. The method of claim 1 , wherein configuring the router comprises configuring the router via border gateway protocol (BGP).

3. The method of claim 1 , further comprising:

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the single egress IP address; and

an inner header including a source IP address set as an IP address of one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the single egress IP address.

4. The method of claim 3 , further comprising applying a firewall policy to the packet based on the source IP address.

5. The method of claim 1 , wherein the single active egress address is one of a plurality of egress IP addresses assigned to the egress pod.

6. One or more non-transitory computer readable media comprising instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations for configuring an egress node for an egress pod set comprising one or more pods, the operations comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set has a single active egress internet protocol (IP) address, wherein the single egress IP address is outside a classless inter-domain routing (CIDR) block of a subnet of the egress node, and wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node; and

configuring a router with a static route to associate the egress node with the single active egress IP address.

7. The one or more non-transitory computer readable media of claim 6 , wherein configuring the router comprises configuring the router via border gateway protocol (BGP).

8. The one or more non-transitory computer readable media of claim 6 , the operations further comprising:

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the single egress IP address; and

an inner header including a source IP address set as an IP address of one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the single egress IP address.

9. The one or more non-transitory computer readable media of claim 8 , the operations further comprising applying a firewall policy to the packet based on the source IP address.

10. The one or more non-transitory computer readable media of claim 6 , wherein the single active egress address is one of a plurality of egress IP addresses assigned to the egress pod.

11. A computer system, the computer system comprising:

one or more memories; and

one or more processors, the one or more processors being configured to perform operations for configuring an egress node for an egress pod set comprising one or more pods, the operations comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set has a single active egress internet protocol (IP) address, wherein the single egress IP address is outside a classless inter-domain routing (CIDR) block of a subnet of the egress node, and wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node; and

configuring a router with a static route to associate the egress node with the single active egress IP address.

12. The computer system of claim 11 , wherein configuring the router comprises configuring the router via border gateway protocol (BGP).

13. The computer system of claim 11 , the operations further comprising:

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the single egress IP address; and

an inner header including a source IP address set as an IP address of one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the single egress IP address.

14. The computer system of claim 13 , the operations further comprising applying a firewall policy to the packet based on the source IP address.

15. The computer system of claim 11 , wherein the single active egress address is one of a plurality of egress IP addresses assigned to the egress pod.

16. The method of claim 5 , further comprising:

determining, from the plurality of egress IP addresses assigned to the egress pod, the single active egress IP address as the active egress IP address for the egress pod.

17. The method of claim 16 , wherein the single active IP address is determined based on the CIDR block of the subnet of the egress node.

18. The one or more non-transitory computer readable media of claim 10 , the operations further comprising:

determining, among the plurality of egress IP addresses assigned to the egress pod, the single active egress IP address of the egress pod.

19. The one or more non-transitory computer readable media of claim 18 , wherein the single active IP address is determined based on the CIDR block of the subnet of the egress node.

20. The system of claim 15 , the operations further comprising:

selecting, from the plurality of egress IP addresses assigned to the egress pod, the single active egress IP address as the active egress IP address for the egress pod.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2023
From: TIAN, QUAN; SHEN, JIANJUN; HAN, DONGHAI; XIN, SHUYANG; QIU, WENQI
To: VMWARE, INC.
Reel/Frame 065274/0252 →
Priority Claims (1)
WO PCT/CN2023/094437 · May 16, 2023 · international
Continuity (1)
Related Publication 20240388523A1 · Nov 21, 2024
References Cited (14)
US 11425054B1 · Dunsmore · 2022 [cited by examiner]
US 20210266259A1 · Renner, III et al. · 2021 [cited by applicant]
US 20220029917A1 · Masnauskas et al. · 2022 [cited by applicant]
US 20230031821A1 · Keane · 2023 [cited by examiner]
US 20240388559A1 · Tian et al. · 2024 [cited by applicant]
US 20250039074A1 · Ahmed · 2025 [cited by examiner]
CN 115955502A · 2023 [cited by examiner]
CN 116132435A · 2023 [cited by examiner]
Author Unknown, kube-static-egress-ip, pp. 1-6, May 12, 2019. [cited by examiner]
Author Unknown, Static to BGP redistribute, pp. 1-5, Nov. 5, 2021. [cited by examiner]
Author Unknown, Kubernates under the Hood, pp. 1-11, Dec. 2, 2019. [cited by examiner]
Author Unknown, Submariner, pp. 1-8, Mar. 21, 2023. [cited by examiner]
Extended European Search Report, European Application No. 24174619.7 dated Oct. 9, 2024, 11 pages. [cited by applicant]
Sookocheff, Kevin: “A Guide to the Kubernetes Networking Model”, Jul. 11, 2018, pp. 1-29, XP093065536, Retrieved from the Internet: URL: https://sookocheff.com/post/kubernetes/understanding-kubernetes-networking, 29 pag… [cited by applicant]