IP Library Granted Patent US 12,407,591
Granted Patent B2
US 12,407,591 · App. 18/607,374 · Granted Sep 2, 2025

Centralized monitoring of containerized workloads in a multi-tenant, multi-cloud environment

Inventors: Avi Sharma (Neemuch, IN); Srinivas Banoth (Hyderabad, IN); Nilabh Nikunj (Bangalore, IN); Gyanendra Pratap Singh (Bangalore, IN)
Assignee: VMware LLC
H04L43/08H04L41/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,591
App. No.
18/607,374
Granted
Sep 2, 2025
Kind
B2
Abstract

The disclosure provides a method for monitoring tenant workloads in a multi-cloud environment. The method generally includes determining a first new workload for a first tenant is deployed on a first data plane associated with a first cloud platform in the multi-cloud environment; configuring a monitoring stack on a second data plane associated with a second cloud platform in the multi-cloud environment to collect first metrics data for the first new workload; and creating a network policy allow list including a source internet protocol (IP) address associated with the monitoring stack, wherein the network policy allow list is to be used by an ingress controller deployed on the first data plane to control ingress traffic to the first new workload, including at least ingress traffic from the monitoring stack intended for the first new workload.

Claims (67)

1. A method for monitoring tenant workloads in a multi-cloud environment, comprising:

determining a first new workload for a first tenant is deployed on a first data plane associated with a first cloud platform in the multi-cloud environment;

configuring a monitoring stack on a second data plane associated with a second cloud platform in the multi-cloud environment to collect first metrics data for the first new workload; and

creating a network policy allow list including a source internet protocol (IP) address associated with the monitoring stack, wherein the network policy allow list is to be used by an ingress controller deployed on the first data plane to control ingress traffic to the first new workload, including at least ingress traffic from the monitoring stack intended for the first new workload.

2. The method of claim 1 , further comprising, prior to determining the first new workload for the first tenant is deployed on the first data plane:

determining a second new workload for the first tenant is deployed on the second data plane;

deploying the monitoring stack on the second data plane for the first tenant based on the second new workload being a first workload in time deployed for the first tenant in the multi-cloud environment; and

configuring the monitoring stack to collect second metrics data for the second new workload.

3. The method of claim 2 , further comprising after creating the network policy allow list including the source IP:

determining the first new workload deployed on the first data plane and the second new workload deployed on the second data plane have been removed; and

removing the monitoring stack deployed on the second data plane based on the first new workload and the second new workload for the first tenant being removed.

4. The method of claim 2 , further comprising after creating the network policy allow list including the source IP:

determining the first new workload deployed on the first data plane has been removed; and

configuring the monitoring stack on the second data plane to stop collecting the first metrics data for the first new workload.

5. The method of claim 1 , further comprising, after creating the network policy allow list including the source IP:

determining a third new workload for the first tenant is deployed on the first data plane; and

configuring the monitoring stack on the second data plane associated with the second cloud platform to collect third metrics data for the third new workload based on the third new workload for the first tenant being deployed on the same first data plane as the first new workload.

6. The method of claim 1 , further comprising:

determining a third new workload for a second tenant is deployed on the first data plane associated with the first cloud platform in the multi-cloud environment;

deploying a second monitoring stack on the first data plane for the second tenant based on the third new workload being a first workload in time deployed for the second tenant in the multi-cloud environment; and

configuring the second monitoring stack to collect second metrics data for the third new workload.

7. The method of claim 1 , wherein a controller service deployed on a control plane node associated with the first cloud platform or another could platform in the multi-cloud environment determines the first new workload for the first tenant is deployed on the first data plane based on one or more status updates received from a monitoring service deployed on the first data plane.

8. A system comprising:

one or more processors; and

at least one memory, the one or more processors and the at least one memory configured to:

determine a first new workload for a first tenant is deployed on a first data plane associated with a first cloud platform in a multi-cloud environment;

configuring a monitoring stack on a second data plane associated with a second cloud platform in the multi-cloud environment to collect first metrics data for the first new workload; and

create a network policy allow list including a source internet protocol (IP) address associated with the monitoring stack, wherein the network policy allow list is to be used by an ingress controller deployed on the first data plane to control ingress traffic to the first new workload, including at least ingress traffic from the monitoring stack intended for the first new workload.

9. The system of claim 8 , wherein the one or more processors and the at least one memory are further configured to, prior to determining the first new workload for the first tenant is deployed on the first data plane:

determine a second new workload for the first tenant is deployed on the second data plane;

deploy the monitoring stack on the second data plane for the first tenant based on the second new workload being a first workload in time deployed for the first tenant in the multi-cloud environment; and

configure the monitoring stack to collect second metrics data for the second new workload.

10. The system of claim 9 , wherein the one or more processors and the at least one memory are further configured to, after creating the network policy allow list including the source IP:

determine the first new workload deployed on the first data plane and the second new workload deployed on the second data plane have been removed; and

remove the monitoring stack deployed on the second data plane based on the first new workload and the second new workload for the first tenant being removed.

11. The system of claim 9 , wherein the one or more processors and the at least one memory are further configured to, after creating the network policy allow list including the source IP:

determine the first new workload deployed on the first data plane has been removed; and

configure the monitoring stack on the second data plane to stop collecting the first metrics data for the first new workload.

12. The system of claim 8 , wherein the one or more processors and the at least one memory are further configured to, after creating the network policy allow list including the source IP:

determine a third new workload for the first tenant is deployed on the first data plane; and

configure the monitoring stack on the second data plane associated with the second cloud platform to collect third metrics data for the third new workload based on the third new workload for the first tenant being deployed on the same first data plane as the first new workload.

13. The system of claim 8 , wherein the one or more processors and the at least one memory are further configured to:

determine a third new workload for a second tenant is deployed on the first data plane associated with the first cloud platform in the multi-cloud environment;

deploy a second monitoring stack on the first data plane for the second tenant based on the third new workload being a first workload in time deployed for the second tenant in the multi-cloud environment; and

configure the second monitoring stack to collect second metrics data for the third new workload.

14. The system of claim 8 , wherein a controller service deployed on a control plane node associated with the first cloud platform or another could platform in the multi-cloud environment determines the first new workload for the first tenant is deployed on the first data plane based on one or more status updates received from a monitoring service deployed on the first data plane.

15. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations for monitoring tenant workloads in a multi-cloud environment, the operations comprising:

determining a first new workload for a first tenant is deployed on a first data plane associated with a first cloud platform in the multi-cloud environment;

configuring a monitoring stack on a second data plane associated with a second cloud platform in the multi-cloud environment to collect first metrics data for the first new workload; and

creating a network policy allow list including a source internet protocol (IP) address associated with the monitoring stack, wherein the network policy allow list is to be used by an ingress controller deployed on the first data plane to control ingress traffic to the first new workload, including at least ingress traffic from the monitoring stack intended for the first new workload.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise, prior to determining the first new workload for the first tenant is deployed on the first data plane:

determining a second new workload for the first tenant is deployed on the second data plane;

deploying the monitoring stack on the second data plane for the first tenant based on the second new workload being a first workload in time deployed for the first tenant in the multi-cloud environment; and

configuring the monitoring stack to collect second metrics data for the second new workload.

17. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise, after creating the network policy allow list including the source IP:

determining the first new workload deployed on the first data plane and the second new workload deployed on the second data plane have been removed; and

removing the monitoring stack deployed on the second data plane based on the first new workload and the second new workload for the first tenant being removed.

18. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise, after creating the network policy allow list including the source IP:

determining the first new workload deployed on the first data plane has been removed; and

configuring the monitoring stack on the second data plane to stop collecting the first metrics data for the first new workload.

19. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise, after creating the network policy allow list including the source IP:

determining a third new workload for the first tenant is deployed on the first data plane; and

configuring the monitoring stack on the second data plane associated with the second cloud platform to collect third metrics data for the third new workload based on the third new workload for the first tenant being deployed on the same first data plane as the first new workload.

20. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

determining a third new workload for a second tenant is deployed on the first data plane associated with the first cloud platform in the multi-cloud environment;

deploying a second monitoring stack on the first data plane for the second tenant based on the third new workload being a first workload in time deployed for the second tenant in the multi-cloud environment; and

configuring the second monitoring stack to collect second metrics data for the third new workload.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: BANOTH, SRINIVAS; SHARMA, AVI; NIKUNJ, NILABH; SINGH, GYANENDRA PRATAP
To: VMWARE, INC.
Reel/Frame 066938/0335 →
CHANGE OF NAME Recorded Mar 28, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066945/0721 →
Priority Claims (1)
IN 202341067125 · Oct 6, 2023 · national
Continuity (1)
Related Publication 20250119368A1 · Apr 10, 2025
References Cited (4)
US 11876691B2 · Chang · 2024 [cited by examiner]
US 20180074724A1 · Tremblay · 2018 [cited by examiner]
US 20190028300A1 · Mathew · 2019 [cited by examiner]
US 20240323087A1 · Koyfman · 2024 [cited by examiner]