IP Library Granted Patent US 12,301,657
Granted Patent B2
US 12,301,657 · App. 18/497,734 · Granted May 13, 2025

Sharing objects across namespaces in a container-orchestration system

Inventors: Savithru Mallikarjuna Durga Lokanath (San Jose, CA); Arpeet Kale (San Jose, CA)
Assignee: Salesforce, Inc.
H04L67/1095G06F9/45558G06F9/5077G06F2009/4557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,657
App. No.
18/497,734
Filed
Oct 30, 2023
Granted
May 13, 2025
Kind
B2
Art Unit
2449
USPC
709/201
Abstract

A method for replicating a set of parent resources from an administrator namespace to a set of tenant namespaces is described. The method includes receiving, by the administrator namespace, a global object that includes a set of object fields that reference (1) a set of parent resources and (2) the set of tenant namespaces; monitoring, by an operator controller of the administrator namespace, the global object to determine whether a change has been made to the global object; and replicating, by the operator controller, the set of parent resources to the set of tenant namespaces as child resources based on the global object in response to detecting a change to the global object.

Claims (47)

1. A method for replicating a set of parent resources from an administrator namespace to a set of namespaces for customers, the method comprising:

receiving, by the administrator namespace, a global object that includes a set of object fields that reference (1) a set of parent resources and (2) the set of namespaces for customers;

monitoring, by an operator controller of the administrator namespace, the global object to determine whether a change has been made to the global object; and

replicating, by the operator controller, the set of parent resources to the set of namespaces for customers as child resources based on the global object in response to detecting a change to the global object.

2. The method of claim 1 , further comprising:

receiving, by the administrator namespace, a custom resource definition that describes a schema for the global object,

wherein the operator controller verifies that the global object complies with the schema of the custom resource definition before monitoring the global object.

3. The method of claim 2 , wherein the schema of the custom resource definition indicates a set of fields that are permitted to be in the global object and a set of fields that are required to be in the global object, and

wherein the set of object fields are to include the set of fields that are required to be in the global object and the set of object fields are to be selected from the set of fields that are permitted to be in the global object.

4. The method of claim 1 , further comprising:

monitoring, by the operator controller, the child resources in the set of namespaces for customers to detect changes between each of the child resources and each respective parent resource in the set of parent resources; and

in response to detecting a change to a child resource in a namespace for a customer, replicating, by the operator controller, a respective parent resource to the namespace for the customer to replace the child resource for which the change was detected.

5. The method of claim 1 , wherein the change to the global object includes one or more of (1) additions of object fields to the global object, (2) changes to values for the set of object fields within the global object, (3) deletion of object fields within the global object, and (4) creation or receipt of the global object.

6. The method of claim 1 , wherein each of the namespaces for customers in the set of namespaces for customers does not have permission to access resources from the administrator namespace or other namespaces for customers in the set of namespaces for customers; and

wherein the administrator namespace has permission to access resources in each of the namespaces for customers in the set of namespaces for customers.

7. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, will cause said processor to perform operations comprising:

receiving a global object that includes a set of object fields that reference (1) a set of parent resources and (2) a set of namespaces for customers;

monitoring the global object to determine whether a change has been made to the global object; and

replicating the set of parent resources from an administrator namespace to the set of namespaces for customers as child resources based on the global object in response to detecting a change to the global object.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further include:

receiving a custom resource definition that describes a schema for the global object; and

verifying that the global object complies with the schema of the custom resource definition before monitoring the global object.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the schema of the custom resource definition indicates a set of fields that are permitted to be in the global object and a set of fields that are required to be in the global object, and

wherein the set of object fields are to include the set of fields that are required to be in the global object and the set of object fields are to be selected from the set of fields that are permitted to be in the global object.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further include:

monitoring the child resources in the set of namespaces for customers to detect changes between each of the child resources and each respective parent resource in the set of parent resources; and

in response to detecting a change to a child resource in a namespace for a customer, replicating a respective parent resource to the namespace for the customer to replace the child resource for which the change was detected.

11. The non-transitory machine-readable storage medium of claim 8 , wherein the change to the global object includes one or more of (1) additions of object fields to the global object, (2) changes to values for the set of object fields within the global object, (3) deletion of object fields within the global object, and (4) creation or receipt of the global object.

12. The non-transitory machine-readable storage medium of claim 8 , wherein each of the namespaces for customers in the set of namespaces for customers does not have permission to access resources from the administrator namespace or other namespaces for customers in the set of namespaces for customers; and

wherein the administrator namespace has permission to access resources in each of the namespaces for customers in the set of namespaces for customers.

13. A device for replicating a set of parent resources from an administrator namespace to a set of namespaces for customers, the device comprising:

a processor; and

a set of memory units, wherein the set of memory units include instructions that, when performed by the processor, cause the processor to:

receive a global object that includes a set of object fields that reference (1) a set of parent resources and (2) the set of namespaces for customers;

monitor the global object to determine whether a change has been made to the global object; and

replicate the set of parent resources to the set of namespaces for customers as child resources based on the global object in response to detecting a change to the global object.

14. The device of claim 13 , wherein the instructions further cause the processor to:

receive a custom resource definition that describes a schema for the global object, and

verify that the global object complies with the schema of the custom resource definition before monitoring the global object.

15. The device of claim 14 , wherein the schema of the custom resource definition indicates a set of fields that are permitted to be in the global object and a set of fields that are required to be in the global object, and

wherein the set of object fields are to include the set of fields that are required to be in the global object and the set of object fields are to be selected from the set of fields that are permitted to be in the global object.

16. The device of claim 13 , wherein the instructions further cause the processor to:

monitor the child resources in the set of namespaces for customers to detect changes between each of the child resources and each respective parent resource in the set of parent resources; and

in response to detecting a change to a child resource in a namespace for a customer, replicate a respective parent resource to the namespace for the customer to replace the child resource for which the change was detected.

17. The device of claim 13 , wherein the change to the global object includes one or more of (1) additions of object fields to the global object, (2) changes to values for the set of object fields within the global object, (3) deletion of object fields within the global object, and (4) creation or receipt of the global object.

18. The device of claim 13 , wherein each of the namespaces for customers in the set of namespaces for customers does not have permission to access resources from the administrator namespace or other namespaces for customers in the set of namespaces for customers; and

wherein the administrator namespace has permission to access resources in each of the namespaces for customers in the set of namespaces for customers.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: MALLIKARJUNA DURGA LOKANATH, SAVITHRU; KALE, ARPEET
To: SALESFORCE.COM, INC.
Reel/Frame 065393/0233 →
CHANGE OF NAME Recorded Oct 30, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 065395/0890 →
Continuity (3)
Continuation 17817606 · Aug 4, 2022
Continuation 17131296 · Dec 22, 2020
Related Publication 20240064201A1 · Feb 22, 2024
References Cited (20)
US 7730478B2 · Weissman · 2010 [cited by applicant]
US 8782748B2 · Olszewski · 2014 [cited by examiner]
US 10097589B2 · Hopkins et al. · 2018 [cited by applicant]
US 10339123B2 · Venkatesh et al. · 2019 [cited by applicant]
US 11100129B1 · Popick et al. · 2021 [cited by applicant]
US 11140166B2 · Berg · 2021 [cited by examiner]
US 11275733B1 · Batsakis et al. · 2022 [cited by applicant]
US 20160004760A1 · Rogers et al. · 2016 [cited by applicant]
US 20200125582A1 · O'Shaughnessy · 2020 [cited by applicant]
US 20210241241A1 · Lokanath · 2021 [cited by applicant]
Kappes et al., “Multitenant Access Control for Cloud Aware Distributed Filesystems”, IEEE Transactions on Dependable and Secure Computing, vol. 16, Issue 6, Nov. 1, 2019. [cited by examiner]
Kappes et al., “Multitenant Access Control for Cloud-Aware Distributed Filesystems”, IEEE Transactions on Dependendable and Secure Computing, vol. 16, Issue 6, Nov.-Dec. 2019, IEEE Publishing. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/817,606, Sep. 5, 2023, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/131,296, May 4, 2022, 9 pages. [cited by applicant]
The Linux Foundation, “Control Plane,” Standardized Glossary, Kubernetes Documentation, Feb. 22, 2019, downloaded from https://web.archive.org/web/20201113143251/https://kubernetes.io/docs/reference/glossary/?all=true, … [cited by applicant]
The Linux Foundation, “Controllers,” Kubernetes Documentation, Oct. 12, 2020, 3 pages. [cited by applicant]
The Linux Foundation, “Custom Resources,” Kubernetes Documentation, Oct. 13, 2020, downloaded from https://web.archive.org/web/20201208203013/https://kubernetes.io/docs/concepts/extend-kubernetes/api-extension/custom-re… [cited by applicant]
The Linux Foundation, “Operator pattern,” Kubernetes Documentation, Oct. 22, 2020, downloaded from https://web.archive.org/web/20201221021833/https://kubernetes.io/docs/concepts/extend-kubernetes/operator/, 3 pages. [cited by applicant]
The Linux Foundation, “Overview of kubectl,” Kubernetes Documentation, Nov. 20, 2020, downloaded from https://web.archive.org/web/20201211173616/https://kubernetes.io/docs/reference/kubectl/overview/, 13 pages. [cited by applicant]
Vasilyev, S. “Kopf: Kubernetes Operators Framework,” Copyright 2020 Sergey Vasilyev; 2019-2020 Zalando SE. Revision ab53ace8, downloaded from https://kopf.readthedocs.io/en/latest/, 7 pages. [cited by applicant]