IP Library › Granted Patent US 11,075,913
Granted Patent B1
US 11,075,913 · App. 16/566,592 · Granted Jul 27, 2021

Enforceable launch configurations

Inventors: Marvin M. Theimer (Bellevue, WA); Eric Jason Brandwine (Haymarket, VA); Marc J. Brooker (Seattle, WA); David Everard Brown (Cape Town, ZA); Christopher Richard Jacques de Kadt (Cape Town, ZA)
Assignee: Amazon Technologies, Inc.
H04L63/101G06F9/44505G06F9/45558H04L63/0272H04L63/105G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,075,913
App. No.
16/566,592
Granted
Jul 27, 2021
Kind
B1
Abstract

Users intending to launch instances or otherwise access virtual resources in a multi-tenant environment can specify a launch configuration. For each type of instance or each type of user, at least one launch configuration is created that includes parameters and values to be used in instantiating an instance of that type, the values being optimized for the current environment and type of instance. Launch configurations can be optimized for different types of users, such as to account for security credentials and access levels. Such an approach enables users to launch instances by contacting the resource provider directly without need for a proxy, which can function as a choke point under heavy load. The use of an appropriate launch configuration can be enforced for any type of user at any level, such as at the sub-net level, by modifying a request that does not specify an appropriate launch configuration.

Claims (51)

1. A method implemented by a computer system of a cloud environment, the method comprising:

receiving a request to launch a database instance for a user of the cloud environment;

accessing a create database workflow template based at least in part on the request, the create database workflow template indicating (i) values for parameters of the database instance, (ii) a persistent storage volume for use by the database instance, and (iii) tasks to be performed to launch the database instance and dependencies between the tasks, the values for the parameters corresponding to particular values that are associated with a type of the database instance;

launching the database instance based at least in part on the parameters and the tasks and the dependencies;

launching the persistent storage volume; and

attaching the persistent storage volume to the database instance.

2. The method of claim 1 , wherein the create database workflow template further indicates a domain name system (DNS) address, and wherein the method further comprises:

allocating the DNS address to the database instance, wherein user access to the database instance is based at least in part on the DNS address.

3. The method of claim 2 , wherein the create database workflow template further indicates a port, and wherein the method further comprises:

allocating the port to the database instance, wherein user access to the database instance is based at least in part on the port.

4. The method of claim 1 , wherein the parameters are associated with a launch configuration that indicates at least one of a size of the database instance or a network connection, and wherein the database instance is launched based at least in part on the launch configuration.

5. The method of claim 1 , wherein the create database workflow template is associated with a MYSQL database, and wherein the database instance is launched as an instance of the MYSQL database.

6. The method of claim 1 , further comprising:

receiving a second request associated with an action to be applied to the database instance, the action comprising at least one of a modification to the database instance, a replication of the database instance, a deletion of the database instance, a recovery of the database instance, a relocation of the database instance, a security group creation to be associated with the database instance, an association of a user credential with the database instance, or a rotation of a key associated with the database instance;

accessing a second workflow template associated with the action; and

performing the action on the database instance based at least in part on the second workflow template.

7. The method of claim 6 , wherein the request and the second request are received from one or more devices of the user based at least in part on a set of application programming interfaces (APIs).

8. The method of claim 5 , further comprising:

determining an authorization associated with the user to launch the database instance, and wherein the database instance is launched based at least in part on the authorization.

9. One or more non-transitory computer-readable media comprising instructions that, upon execution with one or more processors, cause a system of a cloud environment to perform operations comprising:

receiving a request to launch a database instance for a user of the cloud environment;

accessing a create database workflow template based at least in part on the request, the create database workflow template indicating (i) values for parameters of the database instance, (ii) a persistent storage volume for use by the database instance, and (iii) tasks to be performed to launch the database instance and dependencies between the tasks, the values for the parameters corresponding to particular values that are associated with a type of the database instance;

launching the database instance based at least in part on the parameters and the tasks and the dependencies;

launching the persistent storage volume; and

attaching the persistent storage volume to the database instance.

10. The one or more non-transitory computer-readable media of claim 9 , wherein the operations further comprise:

storing a history of events associated with the database instance; and

providing user access to the history of events based at least in part on an application programming interface (API).

11. The one or more non-transitory computer-readable media of claim 9 , wherein the create database workflow template further indicates a domain name system (DNS) address, and wherein the operations comprise:

allocating the DNS address to the database instance;

receiving a second request associated with an action to be applied to the database instance, the action comprising at least one of a modification to the database instance, a replication of the database instance, a relocation of the database instance; and

performing the action on the database instance, wherein the DNS address remains allocated to the database instance after the action is performed.

12. The one or more non-transitory computer-readable media of claim 9 , wherein the create database workflow template further indicates a domain name system (DNS) address and is associated with a MYSQL database, and wherein the operations comprise:

allocating the DNS address to the database instance, wherein the database instance is launched as an instance of the MYSQL database.

13. The one or more non-transitory computer-readable media of claim 12 , wherein the operations further comprise:

receiving, from a device associated with the user, a structured query language (SQL) command associated with data in the database instance; and

providing user access to the data based at least in part on the DNS address.

14. The one or more non-transitory computer-readable media of claim 12 , wherein the parameters are associated with a launch configuration for the database instance, and wherein the operations further comprise:

validating the launch configuration for the user prior to launching the database instance.

15. The one or more non-transitory computer-readable media of claim 14 , wherein validating the launch configuration comprises performing a remedial action that modifies one or more of the parameters.

16. A system of a cloud environment, the system comprising:

one or more processors; and

one or more memories comprising computer-readable instructions that, upon execution with the one or more processors, cause the system to at least:

receive a request to launch a database instance for a user of the cloud environment;

access a create database workflow template based at least in part on the request, the create database workflow template indicating (i) values for parameters of the database instance, (ii) a persistent storage volume for use by the database instance, and (iii) tasks to be performed to launch the database instance and dependencies between the tasks, the values for the parameters corresponding to particular values that are associated with a type of the database instance;

launch the database instance based at least in part on the parameters and the tasks and the dependencies;

launch the persistent storage volume; and

attach the persistent storage volume to the database instance.

17. The system of claim 16 , wherein the create database workflow template is associated with a policy that restricts a launch of the database instance based at least in part on the type of the user, and wherein the database instance is launched based at least in part on the policy.

18. The system of claim 17 , wherein the create database workflow template is associated with a plurality of policies having a hierarchical order, and wherein the database instance is launched based at least in part on the plurality of policies and the hierarchical order.

19. The system of claim 16 , wherein the create database workflow template is associated with a policy applicable to a security group, and wherein the database instance is launched for the security group based at least in part on the policy.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT STATE LISTED FOR ASSIGNEE. ASSINEE STATE SHOULD READ "NEVADA" PREVIOUSLY RECORDED AT REEL: 050331 FRAME: 0589. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 19, 2021
From: THEIMER, MARVIN M.; BRANDWINE, ERIC JASON; BROOKER, MARC J.; BROWN, DAVID; JACQUES DE KADT, CHRISTOPHER RICHARD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 056367/0362 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2019
From: THEIMER, MARVIN M.; BRANDWINE, ERIC JASON; BROOKER, MARC J.; BROWN, DAVID; JACQUES DE KADT, CHRISTOPHER RICHARD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 050331/0589 →
Continuity (4)
Continuation 15470495 · Mar 27, 2017
Continuation 14683460 · Apr 10, 2015
Continuation 13967146 · Aug 14, 2013
Continuation 12979863 · Dec 28, 2010
Cited By (1)
US 12,549,358