IP Library Granted Patent US 11,588,693
Granted Patent B2
US 11,588,693 · App. 16/801,940 · Granted Feb 21, 2023

Migrating networking configurations

Inventors: Yuval Lifshitz (Raanana, IL); Sebastian Scheinkman (Raanana, IL)
Assignee: Red Hat, Inc.
H04L41/0843G06F9/45558H04L41/0873H04L41/0886H04L41/22H04L63/0263G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,693
App. No.
16/801,940
Granted
Feb 21, 2023
Kind
B2
Abstract

A method includes receiving, from an agent executing in a virtual machine, network information associated with the virtual machine, the virtual machine to be migrated to a container. The method further includes generating a container networking configuration based on the network information. The container networking configuration is to provide network access to processes migrated from the virtual machine to the container. The method further includes providing the container networking configuration to a container orchestration system. The container orchestration system is to use the container networking configuration to provide network access to the container.

Claims (49)

1. A method comprising:

receiving, from an agent executing in a virtual machine, network information associated with the virtual machine, the virtual machine to be migrated to a container, wherein the container comprises an isolated execution environment managed by a container orchestration system;

generating, by a processing device, a container networking configuration in view of the network information associated with the virtual machine, the container networking configuration to provide network access to processes of the virtual machine migrated to the container, wherein the container networking configuration defines networking rules between containers and processes within the container orchestration system;

providing the container networking configuration to the container orchestration system, the container orchestration system to apply the container networking configuration to the container to provide network access to the virtual machine migrated to the container, wherein the virtual machine continues to execute within the container;

monitoring, by the agent in the virtual machine, the network information associated with the virtual machine to identify updates to the network information after migration of the virtual machine to the container; and

updating the container networking configuration in view of the updated network information after migration of the virtual machine to the container to maintain network access to the virtual machine through the container as the virtual machine continues to execute within the container.

2. The method of claim 1 , further comprising:

configuring a secondary network for the container in view of the container orchestration system and the container networking configuration.

3. The method of claim 1 , wherein generating the container networking configuration comprises:

generating network traffic ingress rules for communications received from systems external to the container orchestration system; and

generating network traffic egress rules for communications to systems external to the container orchestration system.

4. The method of claim 3 , wherein generating the container networking configuration further comprises:

identifying network access associated with processes of the virtual machine;

generating at least one network access rule for a container to provide access to the processes migrated from the virtual machine; and

generating the container networking configuration including the at least one network access rule for the container.

5. The method of claim 1 , further comprising:

identifying a conflict between the network information and the container orchestration system; and

recommending a user to perform a manual intervention.

6. The method of claim 1 , wherein the network information comprises at least one of: an Internet protocol table, firewall configuration rules, or a network interface configuration.

7. The method of claim 1 , wherein the container networking configuration defines networking rules between the container in the container orchestration system and networks external to the container orchestration system.

8. A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

receive, by an agent executed by the processing device, an indication that a virtual machine is to be migrated to a container, wherein the container comprises an isolated execution environment managed by a container orchestration system;

in response to receiving the indication, retrieve, by the agent, network information associated with the virtual machine, the network information corresponding to a networking configuration of the virtual machine;

forward, by the agent, the network information associated with the virtual machine to a networking migration controller, the networking migration controller to generate, in view of the network information of the virtual machine, a container networking configuration to be applied to the container to provide network access to the virtual machine executing within the container, wherein the container networking configuration defines networking rules between containers and processes within the container orchestration system;

monitor, by the agent, the network information associated with the virtual machine to identify updates to the network information after migration of the virtual machine to the container; and

provide, by the agent, the updated network information to the networking migration controller to update the container networking configuration after migration of the virtual machine to the container to maintain network access to the virtual machine through the container as the virtual machine continues to execute within the container.

9. The system of claim 8 , wherein the network information comprises at least one of: an Internet protocol table, a firewall configuration, or a network interface configuration.

10. The system of claim 8 , wherein the migration controller is further to provide the container networking configuration to a container orchestration system.

11. The system of claim 8 , wherein the container networking configuration provides network access to at least one process migrated from the virtual machine to the container.

12. The system of claim 8 , wherein the agent continuously retrieves and forwards the network information of the virtual machine to the networking migration controller.

13. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, from an agent executing in a virtual machine, network information associated with the virtual machine, the virtual machine to be migrated to a container, wherein the container comprises an isolated execution environment managed by a container orchestration system;

generate, by the processing device, a container networking configuration in view of the network information associated with the virtual machine, the container networking configuration to provide network access to processes migrated from the virtual machine to the container, wherein the container networking configuration defines networking rules between containers and processes within the container orchestration system;

provide the container networking configuration to the container orchestration system, the container orchestration system to apply the container networking configuration to the container to provide network access to the virtual machine migrated to the container, wherein the virtual machine continues to execute within the container;

monitor, by the agent in the virtual machine, the network information associated with the virtual machine to identify updates to the network information after migration of the virtual machine to the container; and

update the container networking configuration in view of the updated network information identified after migration of the virtual machine to the container to maintain network access to the virtual machine through the container as the virtual machine continues to execute within the container.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the processing device is further to:

configure a secondary network for the container in view of the container orchestration system and the container networking configuration.

15. The non-transitory computer-readable storage medium of claim 13 , wherein to generate the container networking configuration, the processing device is further to:

identify network access associated with processes of the virtual machine;

generate at least one network access rule for a container to provide access to the processes migrated from the virtual machine; and

generate the container networking configuration including the at least one network access rule for the container.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the processing device is further to:

identify a conflict between the network information and the container orchestration system; and

recommend a user to perform a manual intervention.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the network information comprises at least one of: an Internet protocol table, firewall configuration rules, or a network interface configuration.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the container networking configuration defines networking rules between the container in the container orchestration system and networks external to the container orchestration system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2020
From: LIFSHITZ, YUVAL; SCHEINKMAN, SEBASTIAN
To: RED HAT, INC.
Reel/Frame 051939/0451 →
Continuity (1)
Related Publication 20210266224A1 · Aug 26, 2021