IP Library › Granted Patent US 12,417,085
Granted Patent B2
US 12,417,085 · App. 18/647,838 · Granted Sep 16, 2025

Obtaining deployment tokens for deploying artifacts to a cloud environment

Inventor: Barry Shilmover (Seattle, WA)
Assignee: Oracle International Corporation
G06F8/60G06F9/5005H04L9/3213H04L41/0806H04L41/0869H04L63/108H04L67/10G06Q30/015
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,085
App. No.
18/647,838
Filed
Apr 26, 2024
Granted
Sep 16, 2025
Kind
B2
Art Unit
2441
USPC
709/220
Abstract

Techniques for deploying artifacts to a computing environment are disclosed. A system includes a deployment service for routing requests to destination addresses in a target computing environment. The deployment service detects a request from an artifact deployment tool to deploy an artifact to the target computing environment. The deployment service obtains a deployment token representing verification that a set of one or more customer designated conditions are satisfied to deploy the artifact to the target computing environment. The deployment service obtains validation of the deployment token. Responsive to successfully obtaining validation of the deployment token, the deployment service directs the artifact to a destination address in the target computing environment. The artifact is received at the destination address and deployed in the target computing environment.

Claims (88)

1. A method comprising:

detecting, by a deployment service for routing requests to destination addresses in a target computing environment, a first request from a first artifact deployment tool to deploy a first artifact to the target computing environment;

obtaining, by the deployment service, a first deployment token representing verification that a first set of one or more customer designated conditions are satisfied to deploy the first artifact to the target computing environment,

wherein deployment of the first artifact to the target computing environment is conditioned on having a valid deployment token;

based on deployment of the first artifact to the target computing environment being conditioned on having a valid deployment token, obtaining validation, by the deployment service, of the first deployment token;

responsive to successfully obtaining validation of the first deployment token, directing the first artifact to a first destination address in the target computing environment;

wherein the first artifact is received at the first destination address and deployed in the target computing environment;

wherein the method is performed by at least one device including a hardware processor.

2. The method of claim 1 , further comprising:

determining, based on a set of one or more attributes of the target computing environment, that deployment of the first artifact to the target computing environment is conditioned on having a valid deployment token;

obtaining the first deployment token responsive to determining that deployment of the first artifact to the target computing environment is conditioned on having the valid deployment token.

3. The method of claim 1 , further comprising:

receiving, at the deployment service, a second request from a second artifact deployment tool to deploy a second artifact to a second destination address in the target computing environment;

initiating, by the deployment service, a process for verifying that a second set of one or more customer designated conditions are satisfied to deploy the second artifact to the target computing environment;

determining, by the deployment service, that the second set of one or more customer designated conditions are unsatisfied;

responsive to determining that the second set of one or more customer designated conditions are unsatisfied, refraining from directing the second artifact to the second destination address in the target computing environment.

4. The method of claim 3 , further comprising:

responsive to determining that the second set of one or more customer designated conditions are unsatisfied:

directing, to the second artifact deployment tool, a non-validation response indicating that the second set of one or more customer designated conditions are unsatisfied;

subsequent to directing the non-validation response to the second artifact deployment tool:

receiving, from the second artifact deployment tool, a third request to deploy the second artifact to the target computing environment;

initiating, by the deployment service, a second attempt for verification that the second set of one or more customer designated conditions are satisfied;

receiving a second deployment token in response to the second attempt, wherein the second deployment token represents verification that the second set of one or more customer designated conditions are satisfied;

obtaining validation, by the deployment service, of the second deployment token;

responsive to successfully obtaining validation of the second deployment token, directing the second artifact to the second destination address;

wherein the second artifact is received at the second destination address and deployed in the target computing environment.

5. The method of claim 1 , wherein obtaining the first deployment token comprises:

initiating a process for verifying that the first set of one or more customer designated conditions are satisfied;

queuing the first request while awaiting the first deployment token representing verification that the first set of one or more customer designated conditions are satisfied;

receiving the first deployment token;

subsequent to receiving the first deployment token, resuming the process for verifying that the first set of one or more customer designated conditions are satisfied, wherein the process further comprises:

subsequent to resuming the process: obtaining validation of the first deployment token.

6. The method of claim 1 , wherein obtaining the first deployment token comprises:

initiating a first attempt for verification that the first set of one or more customer designated conditions are satisfied;

receiving a non-validation response indicating that the first set of one or more customer designated conditions are unsatisfied;

subsequent to receiving the non-validation response, initiating a second attempt for verification that the first set of one or more customer designated conditions are satisfied;

receiving the first deployment token in response to the second attempt.

7. The method of claim 1 , further comprising:

determining, by the deployment service, that the first request is directed to the first destination address in the target computing environment;

based at least on the first request being directed to the first destination address, initiating, by the deployment service, a process for verifying that the first set of one or more customer designated conditions are satisfied, wherein requests directed to the first destination address trigger the deployment service to initiate the process for verifying that the first set of one or more customer designated conditions are satisfied.

8. The method of claim 1 , further comprising:

determining, by the deployment service, that the first request comprises an artifact deployment request;

based at least on the first request comprising the artifact deployment request, initiating, by the deployment service, a process for verifying that the first set of one or more customer designated conditions are satisfied, wherein artifact deployment requests trigger the deployment service to initiate the process for verifying that the first set of one or more customer designated conditions are satisfied.

9. The method of claim 1 ,

wherein the target computing environment comprises a private label cloud environment accessible using a first set of identity resources associated with a customer and a second set of identity resources associated with a cloud infrastructure provider,

wherein the deployment service is operated by a requester associated with an identity resource of the second set of identity resources.

10. The method of claim 1 , wherein the first set of one or more customer designated conditions comprises:

verification that an approval to deploy the first artifact to the target computing environment, associated with an approval workflow defined by a customer, has been obtained.

11. The method of claim 1 , wherein the deployment service is configured to (a) determine that an approval to deploy the first artifact to the target computing environment, associated with an approval workflow defined by a customer has been obtained, and (b) obtain the first deployment token based at least on the approval.

12. The method of claim 11 , wherein (i) the deployment service generates the first deployment token, or (ii) an identity service generates the first deployment token and the deployment service obtains the first deployment token from the identity service.

13. The method of claim 1 , wherein the first set of one or more customer designated conditions comprises:

verification that a set of one or more deployment states of the target computing environment designated by a customer are satisfied.

14. The method of claim 13 , wherein verification that the set of one or more deployment states of the target computing environment are satisfied comprises at least one of:

verification that a deployment time for deploying the first artifact to the target computing environment is within a time window specified by at least one of: the customer, or a provider of a cloud infrastructure for the target computing environment;

verification that deployment of the first artifact to the target computing environment corresponds to a deployment sequence specified by the customer for deployments to the target computing environment; or

verification that a change ticket associated with deployment of the first artifact to the target computing environment satisfies a set of one or more ticket verification criteria.

15. The method of claim 1 , wherein obtaining the first deployment token comprises:

obtaining, from the first request, metadata pertaining to the first artifact;

directing, to a verification service, a token request to obtain the first deployment token, wherein the token request comprises the metadata pertaining to the first artifact;

wherein the verification service (a) receives the token request, (b) verifies, based at least in part on the metadata pertaining to the first artifact, that the first set of one or more customer designated conditions are satisfied, (c) obtains the first deployment token, and (d) provides the first deployment token to the deployment service.

16. The method of claim 15 , wherein the verification service verifies at least one of:

an approval to deploy the first artifact to the target computing environment, associated with an approval workflow defined by a customer has been obtained;

a set of one or more deployment states of the target computing environment designated by the customer are satisfied; or

a change ticket associated with deployment of the first artifact to the target computing environment satisfies a set of one or more ticket verification criteria.

17. The method of claim 15 , wherein (a) the verification service generates the first deployment token, or (b) an identity service generates the first deployment token and the verification service obtains the first deployment token from the identity service.

18. The method of claim 1 , further comprising:

receiving, at the deployment service, a second request from a second artifact deployment tool to deploy a second artifact to the target computing environment;

obtaining, by the deployment service, a second deployment token representing verification that a second set of one or more customer designated conditions are satisfied to deploy the second artifact to the target computing environment;

obtaining validation, by the deployment service, of the second deployment token;

responsive to successfully obtaining validation of the second deployment token, directing the second artifact to a second destination address in the target computing environment;

wherein the second artifact is received at the second destination address and deployed in the target computing environment;

wherein the second set of one or more customer designated conditions differs from the first set of one or more customer designated conditions.

19. One or more non-transitory computer-readable media storing instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

detecting, by a deployment service for routing requests to destination addresses in a target computing environment, a first request from a first artifact deployment tool to deploy a first artifact to the target computing environment;

obtaining, by the deployment service, a first deployment token representing verification that a first set of one or more customer designated conditions are satisfied to deploy the first artifact to the target computing environment,

wherein deployment of the first artifact to the target computing environment is conditioned on having a valid deployment token;

based on deployment of the first artifact to the target computing environment being conditioned on having a valid deployment token, obtaining validation, by the deployment service, of the first deployment token;

responsive to successfully obtaining validation of the first deployment token, directing the first artifact to a first destination address in the target computing environment;

wherein the first artifact is received at the first destination address and deployed in the target computing environment.

20. A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

detecting, by a deployment service for routing requests to destination addresses in a target computing environment, a first request from a first artifact deployment tool to deploy a first artifact to the target computing environment;

obtaining, by the deployment service, a first deployment token representing verification that a first set of one or more customer designated conditions are satisfied to deploy the first artifact to the target computing environment,

wherein deployment of the first artifact to the target computing environment is conditioned on having a valid deployment token;

based on deployment of the first artifact to the target computing environment being conditioned on having a valid deployment token, obtaining validation, by the deployment service, of the first deployment token;

responsive to successfully obtaining validation of the first deployment token, directing the first artifact to a first destination address in the target computing environment;

wherein the first artifact is received at the first destination address and deployed in the target computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: SHILMOVER, BARRY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067286/0346 →
Continuity (2)
Provisional Application 63462875 · Apr 28, 2023
Related Publication 20240364588A1 · Oct 31, 2024
References Cited (44)
US 9438599B1 · Yuhan et al. · 2016 [cited by applicant]
US 10649834B2 · Dhayapule · 2020 [cited by examiner]
US 10878483B1 · Felbinger et al. · 2020 [cited by applicant]
US 11356273B1 · Patel et al. · 2022 [cited by applicant]
US 20060230281A1 · Hofmann · 2006 [cited by applicant]
US 20070179859A1 · Chan et al. · 2007 [cited by applicant]
US 20130054426A1 · Rowland et al. · 2013 [cited by applicant]
US 20150363852A1 · Vautour · 2015 [cited by applicant]
US 20160043909A1 · Pogrebinsky et al. · 2016 [cited by applicant]
US 20160080479A1 · Zhang · 2016 [cited by examiner]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20170230229A1 · Sasturkar et al. · 2017 [cited by applicant]
US 20180173510A1 · Koshkin · 2018 [cited by examiner]
US 20180288063A1 · Koottayi et al. · 2018 [cited by applicant]
US 20180367542A1 · Wolf et al. · 2018 [cited by applicant]
US 20190087835A1 · Schwed et al. · 2019 [cited by applicant]
US 20190155674A1 · Dhayapule · 2019 [cited by examiner]
US 20200112497A1 · Yenumulapalli et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200358617A1 · Baierlein · 2020 [cited by examiner]
US 20210216190A1 · Vakil et al. · 2021 [cited by applicant]
US 20210234864A1 · Dube et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari et al. · 2021 [cited by applicant]
US 20220255902A1 · Woodson · 2022 [cited by applicant]
US 20240054063A1 · Wichelman et al. · 2024 [cited by applicant]
US 20240095739A1 · Adogla et al. · 2024 [cited by applicant]
US 20240259389A1 · Wu et al. · 2024 [cited by applicant]
EP 3429156A1 · 2019 [cited by applicant]
EP 3271857B1 · 2020 [cited by applicant]
WO 2021150306A1 · 2021 [cited by applicant]
“Create a Reseller and Reseller Administrator User”, Retrieved from https://abiquo.atlassian.net/wiki/spaces/ABI54/pages/310740667/Create+a+Reseller+and+Reseller+Administrator+User, May 3, 2022, pp. 1-5. [cited by applicant]
“General Variables for All Requests”, Jun. 28, 2023, pp. 6. [cited by applicant]
“Overview of Access Approval”, Retrieved from https://cloud.google.com/assured-workloads/access-approval/docs/overview, Jun. 6, 2024, pp. 5. [cited by applicant]
“Periodic 802.1X reauthentication”, Retrieved from https://techhub.hpe.com/eginfolib/networking/docs/switches/5130ei/5200-3946_security_cg/content/485048074.htm, Retrieved from Oct. 25, 2023, p. 1. [cited by applicant]
“Policy Syntax”, Jan. 4, 2023, pp. 7. [cited by applicant]
“Reinstate admin privileges for a customer's Azure CSP subscriptions”, Retrieved from https://learn.microsoft.com/en-us/partner-center/reinstate-csp, Aug. 1, 2023, pp. 7. [cited by applicant]
“Tenant administrator settings”, Retrieved from https://backstage.forgerock.com/docs/idcloud/latest/tenants/tenant-administrator-settings.html, Jun. 7, 2023, pp. 12. [cited by applicant]
“Verbs”, Jun. 5, 2023, pp. 2. [cited by applicant]
Anonymbus: “Tokenization—(data security)”, Wikipedia, Feb. 12, 2023, pp. 1-12. [cited by applicant]
Bhat S., “Admin access management in Azure Cloud Solution Provider (CSP) subscriptions”, Retrieved from https://techcommunity.microsoft.com/t5/security-compliance-and-identity/admin-access-management-in-azure-cloud-solu… [cited by applicant]
Ducharme et al., “Seamlessly Protect Your IBM Cloud Application Infrastructure with Privileged Access Gateway”, Oct. 3, 2022, pp. 13. [cited by applicant]
George et al., “Data anonymization and integrity checking in cloud computing”, 2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 2013, pp. 5. [cited by applicant]
Ma et al., “ServiceRank: Root Cause Identification of Anomaly in Large-Scale Microservice Architectures”, : IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 5, Sep.-Oct. 2022, pp. 3087-3100. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro) Service-Based Cloud Applications: A Survey”, ACM Computing Surveys, vol. 55, No. 3, Article 59, Feb. 2022, pp. 1-39. [cited by applicant]