On demand operations access to cloud customer resources
Disclosed is an approach to implement an on-demand secure communications channel to a cloud-related resource that is located in a customer's on-premises data center, where the on-demand channel provides access to the resource to a cloud provider's operator employees. This creates on a temporary basis all of the infrastructure that is needed to allow the operational access to the customer system, which can then be destroyed once it is no longer needed.
1. A method, comprising:
receiving a request to establish a connection between a cloud-based environment and an on-premises environment;
sending the request from the cloud-based environment to the on-premises environment, wherein a temporary communications channel is established from the on-premises environment to the cloud-based environment; and
sending network communications to implement operational or administrative activities from the cloud-based environment to the on-premises environment over the temporary communications channel;
wherein the temporary communications channel is destroyed when it is determined that the temporary communications channel is no longer needed.
2. The method of claim 1 , wherein the temporary communications channel comprises a reverse inner tunnel created within an outer tunnel.
3. The method of claim 2 , wherein the reverse inner tunnel is a SSH tunnel and the outer tunnel is a SSL tunnel.
4. The method of claim 2 , wherein a SSH wrapper is established in the cloud-based environment to access the temporary communications channel.
5. The method of claim 2 , wherein the reverse inner tunnel connects to an isolated environment at the cloud-based environment.
6. The method of claim 5 , wherein the isolated environment is implemented as a container.
7. The method of claim 1 , wherein a REST-based control plane is used to initiate the request from the cloud-based environment to the on-premises environment.
8. The method of claim 7 , wherein an agent at the on-premises environment establishes certificates and keys based upon the request initiated through the REST-based control plane, the certificates and keys used to authenticate a connection for a specific entity.
9. The method of claim 1 , wherein a timeout period is established to destroy the temporary communications channel.
10. A computer program product embodied on a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor, executes a method comprising:
receiving a request to establish a connection between a cloud-based environment and an on-premises environment;
sending the request from the cloud-based environment to the on-premises environment;
creating, from the on-premises environment to the cloud-based environment, a temporary communications channel; and
sending network communications to implement operational or administrative activities from the cloud-based environment to the on-premises environment over the temporary communications channel;
wherein the temporary communications channel is destroyed when it is determined that the temporary communications channel is no longer needed.
11. The computer program product of claim 10 , wherein the temporary communications channel comprises a reverse inner tunnel created within an outer tunnel.
12. The computer program product of claim 11 , wherein the reverse inner tunnel is a SSH tunnel and the outer tunnel is a SSL tunnel.
13. The computer program product of claim 11 , wherein the sequence of instructions when executed by the processor establishes a SSH wrapper in the cloud-based environment to access the temporary communications channel.
14. The computer program product of claim 11 , wherein the reverse inner tunnel connects to an isolated environment at the cloud-based environment.
15. The computer program product of claim 14 , wherein the isolated environment is implemented as a container.
16. The computer program product of claim 10 , wherein the sequence of instructions when executed by the processor uses a REST-based control plane to initiate the request from the cloud-based environment to the on-premises environment.
17. The computer program product of claim 16 , wherein an agent at the on-premises environment establishes certificates and keys based upon the request initiated through the REST-based control plane, the certificates and keys used to authenticate a connection for a specific entity.
18. The computer program product of claim 10 , wherein the sequence of instructions when executed by the processor establishes a timeout period to destroy the temporary communications channel.
19. A system, comprising:
a processor;
a memory for holding programmable code; and
wherein the programmable code includes instructions executable by the processor for receiving a request to establish a connection between a cloud-based environment and an on-premises environment; sending the request from the cloud-based environment to the on-premises environment; creating, from the on-premises environment to the cloud-based environment, a temporary communications channel; sending network communications to implement operational or administrative activities from the cloud-based environment to the on-premises environment over the temporary communications channel; wherein the temporary communications channel is destroyed when it is determined that the temporary communications channel is no longer needed.
20. The system of claim 19 , wherein the temporary communications channel comprises a reverse inner tunnel created within an outer tunnel.
21. The system of claim 20 , wherein the reverse inner tunnel is a SSH tunnel and the outer tunnel is a SSL tunnel.
22. The system of claim 20 , wherein the instructions when executed by the processor establishes a SSH wrapper in the cloud-based environment to access the temporary communications channel.
23. The system of claim 20 , wherein the reverse inner tunnel connects to an isolated environment at the cloud-based environment.
24. The system of claim 23 , wherein the isolated environment is implemented as a container.
25. The system of claim 19 , wherein the instructions when executed by the processor uses a REST-based control plane to initiate the request from the cloud-based environment to the on-premises environment.
26. The system of claim 25 , wherein an agent at the on-premises environment establishes certificates and keys based upon the request initiated through the REST-based control plane, the certificates and keys used to authenticate a connection for a specific entity.
27. The system of claim 19 , wherein the instructions when executed by the processor establishes a timeout period to destroy the temporary communications channel.