IP Library Granted Patent US 11,336,567
Granted Patent B2
US 11,336,567 · App. 16/853,331 · Granted May 17, 2022

Service aware virtual private network for optimized forwarding in cloud native environment

Inventors: Nagendra Kumar Nainar (Morrisville, NC); Carlos M. Pignataro (Cary, NC); Alejandro Eguiarte (Cary, NC); Rajiv Asati (Morrisville, NC)
Assignee: Cisco Technology, Inc.
H04L45/38H04L12/4675H04L45/02H04L45/745
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,567
App. No.
16/853,331
Granted
May 17, 2022
Kind
B2
Abstract

Techniques for defining a service flow definition among container pods that provide services in a network. The techniques may include an orchestrator of a computer network platform of the network determining which container pods need to communicate with which container pods. The service flow definition thus indicates needed paths between the container pods. In configurations, a cluster topology may be determined where the cluster topology indicates corresponding nodes of the network in which each container pod is located, as well as end points of the network with which the corresponding nodes communicate. Based at least in part on the service flow definition and the cluster topology, corresponding route distribution policies may be determined for the end points. The corresponding route distribution policies may be applied to the end points.

Claims (64)

1. A method comprising:

a first instance of determining, by an orchestrator of a computer network platform of a network, a first container pod with which a second container pod communicates, the first container pod providing a first service and the second container pod providing a second service;

a second instance of determining, by the orchestrator, a third container pod with which the first container pod communicates, the third container pod providing a third service;

a third instance of determining, by the orchestrator, a fourth container pod with which the second container pod communicates, the fourth container pod providing a fourth service;

a fourth instance of determining, by the orchestrator, a fifth container pod with which the second container pod communicates, the fifth container pod providing a fifth service;

a fifth instance of determining, by the orchestrator, that the third container pod communicates with the fifth container pod;

based at least in part on the first instance of determining, the second instance of determining, the third instance of determining, the fourth instance of determining, and the fifth instance of determining, defining, by the orchestrator, service flow definitions, the service flow definitions defining paths among one or more of the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod;

determining a cluster topology indicating corresponding nodes of the network on which each container pod is hosted and the corresponding end points with which the corresponding nodes communicate; and

based at least in part on (i) the service flow definition and (ii) the cluster topology, providing corresponding route distribution policies to corresponding end points of the network with which the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod communicate.

2. The method of claim 1 , wherein the third service is related to the second service and the fifth service is related to the fourth service.

3. The method of claim 1 , wherein:

the first container pod is hosted by a first node;

the third service is related to the second service, and the second container pod and the third container pod are co-hosted by a second node; and

the fifth service is related to the fourth service, and the fourth container pod and the fifth container pod are co-hosted by a third node.

4. The method of claim 1 , wherein:

providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding route distribution policies to the corresponding end points based on a unique internet protocol (IP) address of each end point of the corresponding end points.

5. The method of claim 1 , further comprising:

assigning a unique bit identification to each end point of the corresponding end points,

wherein providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding distribution policies to the corresponding end points based on the unique bit identification.

6. The method of claim 1 , further comprising:

based on one of (i) one of the first, second, third, fourth, or fifth container pods moving to a different node or (ii) one of the first, second, third, fourth, or fifth container pods terminating, updating one or more of the corresponding route distribution policies.

7. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

a first instance of determining a first container pod with which a second container pod communicates, the first container pod providing a first service and the second container pod providing a second service;

a second instance of determining a third container pod with which the first container pod communicates, the third container pod providing a third service;

a third instance of determining a fourth container pod with which the second container pod communicates, the fourth container pod providing a fourth service;

a fourth instance of determining a fifth container pod with which the second container pod communicates, the fifth container pod providing a fifth service;

a fifth instance of determining that the third container pod communicates with the fifth container pod;

based at least in part on the first instance of determining, the second instance of determining, the third instance of determining, the fourth instance of determining, and the fifth instance of determining, defining service flow definitions, the service flow definitions defining paths among one or more of the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod;

determining a cluster topology indicating corresponding nodes of a network on which each container pod is hosted and the corresponding end points with which the corresponding nodes communicate; and

based at least in part on (i) the service flow definition and (ii) the cluster topology, providing corresponding route distribution policies to corresponding end points of the network with which the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod communicate.

8. The system of claim 7 , wherein the third service is related to the second service and the fifth service is related to the fourth service.

9. The system of claim 7 , wherein:

the first container pod is hosted by a first node;

the third service is related to the second service, and the second container pod and the third container pod are co-hosted by a second node; and

the fifth service is related to the fourth service, and the fourth container pod and the fifth container pod are co-hosted by a third node.

10. The system of claim 7 , wherein:

providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding route distribution policies to the corresponding end points based on a unique internet protocol (IP) address of each end point of the corresponding end points.

11. The system of claim 7 , wherein the actions further comprise:

assigning a unique bit identification to each end point of the corresponding end points,

wherein providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding route distribution policies to the corresponding end points based on the unique bit identification.

12. The system of claim 7 , wherein the actions further comprise:

based on one of (i) one of the first, second, third, fourth, or fifth container pods moving to a different node or (ii) one of the first, second, third, fourth, or fifth container pods terminating, updating one or more of the corresponding route distribution policies.

13. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:

a first instance of determining a first container pod with which a second container pod communicates, the first container pod providing a first service and the second container pod providing a second service;

a second instance of determining a third container pod with which the first container pod communicates, the third container pod providing a third service;

a third instance of determining a fourth container pod with which the second container pod communicates, the fourth container pod providing a fourth service;

a fourth instance of determining a fifth container pod with which the second container pod communicates, the fifth container pod providing a fifth service;

a fifth instance of determining that the third container pod communicates with the fifth container pod;

based at least in part on the first instance of determining, the second instance of determining, the third instance of determining, the fourth instance of determining, and the fifth instance of determining, defining service flow definitions, the service flow definitions defining paths among one or more of the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod;

determining a cluster topology indicating corresponding nodes of a network on which each container pod is hosted and the corresponding end points with which the corresponding nodes communicate; and

based at least in part on (i) the service flow definition and (ii) the cluster topology, providing corresponding route distribution policies to corresponding end points of the network with which the first container pod, the second container pod, the third container pod, the fourth container pod, or the fifth container pod communicate.

14. The one or more non-transitory computer-readable media of claim 13 , wherein:

the first container pod is hosted by a first node;

the third service is related to the second service, and the second container pod and the third container pod are co-hosted by a second node; and

the fifth service is related to the fourth service, and the fourth container pod and the fifth container pod are co-hosted by a third node.

15. The one or more non-transitory computer-readable media of claim 13 , wherein:

providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding route distribution policies to the corresponding end points based on a unique internet protocol (IP) address of each end point of the corresponding end points.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the actions further comprise:

assigning a unique bit identification to each end point of the corresponding end points,

wherein providing the corresponding route distribution policies to the corresponding end points comprises providing the corresponding route distribution policies to the corresponding end points based on the unique bit identification.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the actions further comprise:

based on one of (i) one of the first, second, third, fourth, or fifth container pods moving to a different node or (ii) one of the first, second, third, fourth, or fifth container pods terminating, updating one or more of the corresponding route distribution policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2020
From: NAINAR, NAGENDRA KUMAR; PIGNATARO, CARLOS M.; EGUIARTE, ALEJANDRO; ASATI, RAJIV
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052446/0633 →
Continuity (1)
Related Publication 20210328913A1 · Oct 21, 2021