IP Library Patent Application 18245790
Patent Application
App. No. 18/245,790

Managing Tenant Users in Coordination with Identity Provider

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/245,790
Abstract

Systems and methods for mapping users to tenants within a containerized workload management architecture. A method includes identifying a tenant group comprising a plurality of users. The method includes mapping the tenant group to a tenant and adding the tenant to a cluster, wherein the cluster comprises compute resources for executing workloads. The method is such that each of the plurality of users within the tenant group is assigned a same role and same permissions within the cluster.

Claims (53)

1 . A method for organizing users within a network architecture, the method comprising:

identifying a tenant group comprising a plurality of users;

mapping the tenant group to a tenant; and

adding the tenant to a cluster, wherein the cluster comprises compute resources for executing workloads; and

wherein each of the plurality of users within the tenant group is assigned a same role within the tenant; and

wherein each of the plurality of users within the tenant group is assigned same permissions within the cluster.

2 . The method of claim 1 , wherein the tenant group is an internal tenant group such that each of the plurality of users is authenticated and managed by the cluster or another compute resource within the network architecture.

3 . The method of claim 1 , wherein the tenant group is an external tenant group such that each of the plurality of users is authenticated by an external identity provider.

4 . The method of claim 3 , wherein the external identity provider provides authentication services to the cluster.

5 . The method of claim 4 , wherein the external identity provider is responsible for authenticating users within an identity provider user group and managing membership of the identity provider user group.

6 . The method of claim 5 , wherein identifying the tenant group comprises retrieving a listing of tenant users, and wherein the listing of the tenant users is managed by the cluster; and

wherein the method further comprises synchronizing the listing of the tenant users with the identity provider user group managed by the external identity provider.

7 . The method of claim 6 , wherein synchronizing the listing of the tenant users within the identity provider user group comprises:

cross-checking the listing of the tenant users against the identity provider user group to identify any discrepancies in usernames included in the listing of the tenant users versus usernames included in the identity provider user group;

in response to identifying a first username included in the listing of the tenant users that is not included in the identity provider user group, removing the first username from the listing of the tenant users; and

in response to identifying a second username included in the identity provider user group that is not included in the listing of the tenant users, adding the second username to the listing of the tenant users.

8 . The method of claim 1 , further comprising:

adding a user to the tenant group; and

in response to adding the user to the tenant group, automatically mapping the user to the tenant and the cluster.

9 . The method of claim 1 , further comprising:

removing a user from the tenant group; and

in response to removing the user from the tenant group, automatically removing any mapping from the user to the tenant.

10 . The method of claim 1 , wherein each of the plurality of users within the tenant group is assigned a role comprising super administrator permissions, and wherein the super administrator permissions grant the plurality of users permission to:

read and write to all cluster objects;

add users to the cluster;

register storage repositories to the cluster;

share storage repositories associated with the cluster; and

export and/or import application backups for applications executed by the cluster.

11 . The method of claim 1 , wherein each of the plurality of users within the tenant group is assigned a role comprising tenant administrator permissions, and wherein the tenant administrator permissions grant the plurality of users permission to:

read and write to tenant objects;

add users to the tenant group mapped to the tenant;

register storage repositories to the tenant;

share storage repositors associated with the tenant; and

export and/or import application backups for applications executed by compute resources of the cluster that are dedicated to the tenant.

12 . The method of claim 1 , wherein each of the plurality of users within the tenant group is assigned a role comprising user-only permissions, and wherein the user-only permissions grant the plurality of users permission to manage one or more applications deployed by or registered to the plurality of users.

13 . The method of claim 1 , wherein the tenant is a construct within the network architecture that enables users to be separated into discrete groups based on function or business requirements, and wherein the plurality of users mapped to the tenant are only allowed to access system resources assigned to the tenant.

14 . The method of claim 1 , further comprising:

authenticating one of the plurality of users to log into the tenant;

receiving instructions from the one of the plurality of users to deploy an application; and

binding the application to the tenant due to the user being logged into the tenant when the user provided the instructions to deploy the application.

15 . The method of claim 1 , wherein the cluster is a component of a containerized workload management system, and wherein the cluster comprises:

a control plane node communicating with a plurality of compute nodes;

wherein the plurality of compute nodes comprises a physical machine or virtual machine configured to execute objects associated with the cluster.

16 . The method of claim 1 , further comprising mapping a plurality of different tenant groups to the tenant, wherein each of the plurality of different tenant groups comprises different users.

17 . The method of claim 1 , further comprising:

mapping a first tenant group comprising a first plurality of users to the tenant; and

mapping a second tenant group comprising a second plurality of users to the tenant;

wherein the first tenant group comprises different membership than the second tenant group such that no user included within the first plurality of users is also included within the second plurality of users.

18 . The method of claim 1 , wherein the cluster comprises a plurality of tenants, and wherein at least one user is mapped to two or more of the plurality of tenants of the cluster.

19 . The method of claim 1 , further comprising:

partitioning the cluster into a plurality of different namespaces; and

binding the tenant to one or more of the plurality of different namespaces.

20 . The method of claim 19 , wherein mapping the tenant group to the tenant comprises scoping each of the plurality of users within the tenant group to at least one of the one or more of the plurality of different namespaces within the cluster.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: ROBIN SYSTEMS, INC.
To: RAKUTEN SYMPHONY, INC.
Reel/Frame 068193/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2023
From: MORANO, THOMAS JAY; DOSHI, TUSHAR ANIL
To: ROBIN SYSTEMS, INC
Reel/Frame 063039/0647 →