IP Library › Granted Patent US 11,729,218
Granted Patent B2
US 11,729,218 · App. 16/676,964 · Granted Aug 15, 2023

Implementing a service mesh in the hypervisor

Inventors: Michael Tsirkin (Westford, MA); Francisco Javier Martinez Canillas (Barcelona, ES); Alberto Carlos Ruiz Ruiz (Madrid, ES)
Assignee: Red Hat, Inc.
H04L63/20G06F9/45558H04L61/256G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,218
App. No.
16/676,964
Granted
Aug 15, 2023
Kind
B2
Abstract

A packet is received by a hypervisor from a first container, the packet to be provided to a second container, the packet including a header including a first network address associated with the second container. A network policy is identified for the packet in view of the first network address. A second network address corresponding to the second container is determined in view of the network policy. A network address translation is performed by the hypervisor to modify the header of the packet to include the second network address corresponding to the second container.

Claims (44)

1. A method comprising:

receiving, by a processing device executing a hypervisor, a packet from a first container, the packet to be provided to a second container, the packet comprising a header including a first network address associated with the second container, the first container and the second container comprising isolated execution environments running within a virtual machine maintained by the hypervisor;

in response to the second container obtaining a new network address, updating, by a container orchestration system, a network policy to associate the second container with a second network address;

identifying, by the hypervisor, a plurality of network policies, each of the plurality of network policies having a corresponding network address; and

identifying, by the hypervisor, a network policy for the packet from the plurality of network policies in view of the corresponding network address of the network policy matching the first network address;

determining, by the hypervisor, the second network address corresponding to the second container in view of the network policy, wherein the network policy correlates the first network address received from the first container with the second network address corresponding to a location of the second container;

performing, by the hypervisor, a network address translation to modify the header of the packet to include the second network address corresponding to the second container; and

providing the packet to the second container at the second network address of the modified header.

2. The method of claim 1 , wherein the packet is received from a first service executing in the first container and provided to a second service executing in the second container, wherein the first service uses a first programming language and the second service uses a second programming language that is different than the first programming language.

3. The method of claim 1 , wherein the network policy is received from a container orchestration system.

4. The method of claim 1 , wherein the first container and the second container reside within one or more virtual machines.

5. The method of claim 1 , wherein the packet is received from the first container by the hypervisor via a virtual network interface card.

6. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

receive, by a hypervisor, a packet from a first container to be provided to a second container, the packet comprising a header including a first network address associated with the second container, the first container and the second container comprising isolated execution environments running within a virtual machine maintained by the hypervisor;

detecting, by the hypervisor, the second container obtaining a new network address, updating, by a container orchestration system, a network policy to associate the second container with a second network address;

identifying, by the hypervisor, a plurality of network policies, each of the plurality of network policies having a corresponding network address;

identifying, by the hypervisor, a network policy for the packet from the plurality of network policies in view of the corresponding network address of the network policy matching the first network address;

determining, by the hypervisor, the second network address corresponding to the second container in view of the network policy, wherein the network policy correlates the first network address received from the first container with the second network address corresponding to a location of the second container;

performing, by the hypervisor, a network address translation to modify the header of the packet to include the second network address corresponding to the second container; and

providing the packet to the second container at the second network address of the modified header.

7. The system of claim 6 , wherein to determine whether the packet was successfully delivered to the second container, the processing device is further to:

receive, from the second container, an indication that the delivery of the packet was unsuccessful.

8. The system of claim 6 , wherein the network policy indicates a threshold number of times the packet is to be subsequently provided to the second container.

9. The system of claim 8 , wherein the processing device is further to:

determine whether a number of times the packet has been subsequently provided to the second container satisfies the threshold number of times indicated by the network policy; and

in response to determining that the number of times the packet has been subsequently provided satisfies the threshold number of times, determine to not subsequently provide the packet to the second container.

10. The system of claim 6 , wherein the packet is received from a first application executing in the first container and provided to a second application executing in the second container, wherein the first application uses a first programming language and the second application uses a second programming language that is different than the first programming language.

11. The system of claim 6 , wherein the first container and the second container reside within one or more virtual machines.

12. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, by a hypervisor from a virtual machine, a packet from a first container to be provided to a second container, the packet comprising a header including a first network address associated with the second container, the first container and the second container comprising isolated execution environments running within a virtual machine maintained by the hypervisor;

detecting, by the hypervisor, the second container obtaining a new network address, updating, by a container orchestration system, a network policy to associate the second container with a second network address;

identifying, by the hypervisor, a plurality of network policies, each of the plurality of network policies having a corresponding network address;

identifying, by the hypervisor, a network policy for the packet from the plurality of network policies in view of the corresponding network address of the network policy matching the first network address;

determining, by the hypervisor, the second network address corresponding to the second container in view of the network policy, wherein the network policy correlates the first network address received from the first container with the second network address corresponding to a location of the second container;

performing, by the hypervisor, a network address translation to modify the header of the packet to include the second network address corresponding to the second container; and

providing the packet to the second container at the second network address of the modified header.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the processing device is further to:

install a forwarding rule to a memory associated with the processing device, the forwarding rule to cause the processing device to perform the network address translation on subsequent packets received from the first container.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the processing device is further to:

detect a disconnect by the first container; and

remove the forwarding rule from the memory associated with the processing device.

15. The non-transitory computer-readable storage medium of claim 12 , wherein the processing device is executing a hypervisor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: TSIRKIN, MICHAEL; MARTINEZ CANILLAS, FRANCISCO JAVIER; RUIZ RUIZ, ALBERTO CARLOS
To: RED HAT, INC.
Reel/Frame 064057/0486 →
Continuity (1)
Related Publication 20210144177A1 · May 13, 2021