IP Library › Granted Patent US 12,273,442
Granted Patent B2
US 12,273,442 · App. 17/890,149 · Granted Apr 8, 2025

Automating the creation and maintenance of containerized applications' custom routes and associated SSL certificates

Inventors: Aqeel Hussain Alkhawaja (Dammam, SA); Haidar A. AlDajani (Dammam, SA); Hamad Abdullatif Almaghlouth (Al Khobar, SA); Hossam Abdulwahid Aljunaidi (Dammam, SA)
Assignee: Saudi Arabian Oil Company
H04L9/0825H04L9/3213H04L9/3247H04L9/3268H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,442
App. No.
17/890,149
Granted
Apr 8, 2025
Kind
B2
Abstract

Systems and methods include a system in which a creation request is received at a job-based pod to create a containerized application custom route and SSL certificates. A signed certificate for the creation request is received from a Public Key Infrastructure services system. A DNS request is sent to a DNS service with instructions to query an IP address associated with the DNS request. A DNS response is received from the DNS service. An application request is connected to an OpenShift Container (OCP) cluster to validate certificates for a route associated with the IP address and to feed a URL for the route to a master OCP cluster. A documentation request to document activities associated with the app request and the URL is provided to a ticketing system. A developer is informed of a completion of the creation request, and the URL is provided to the developer.

Claims (48)

1. A computer-implemented method, comprising:

receiving, at a job-based pod used in a container orchestration system, a creation request to create a containerized application custom route and Secure Sockets Layer (SSL) certificates associated with the containerized application custom route;

sending, by the job-based pod to a Public Key Infrastructure (PKI) services system, the creation request for auto-signing of the creation request, wherein the PKI services system adjusts a certificate template to comply with PKI standards to generate a signed certificate, the private PKI server makes the signed certificate available through a download link customized for the job-based pod;

receiving, from the PKI services system in response to sending the creation request, the signed certificate for the creation request;

sending, to a Domain Name System (DNS) service, a DNS request with instructions to query an Internet protocol (IP) address associated with the DNS request and provide a list of aliases associated with the IP address;

receiving, from the DNS service, a DNS response to the DNS request;

connecting, to an OpenShift Container (OCP) cluster, an application (app) request to validate certificates for a route associated with the IP address and to feed a universal resource locator (URL) for the route to a master OCP cluster;

receiving, from the OCP cluster, a response to the app request;

providing, to a ticketing system, a documentation request to document activities associated with the app request and the URL; and

informing a developer associated with the creation request of a completion of the creation request, comprising providing the URL to the developer.

2. The computer-implemented method of claim 1 , wherein the container orchestration system is an open-source container orchestration system.

3. The computer-implemented method of claim 1 , further comprising determining that the SSL certificate is set to expire within a threshold period.

4. The computer-implemented method of claim 1 , further comprising performing a renewal process on the SSL certificate.

5. The computer-implemented method of claim 4 , wherein performing the renewal process on the SSL certificate comprises extracting certificate details from the SSL certificate comprising an Openshift cluster name, a project name, and project users.

6. The computer-implemented method of claim 4 , wherein performing the renewal process on the SSL certificate comprises sending a request to the PKI services system and receiving a response upon completion.

7. The computer-implemented method of claim 4 , wherein performing the renewal process on the SSL certificate comprises performing API calls to edit an application route and validating the SSL certificate assigned to the application route.

8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, at a job-based pod used in a container orchestration system, a creation request to create a containerized application custom route and Secure Sockets Layer (SSL) certificates associated with the containerized application custom route;

sending, by the job-based pod to a Public Key Infrastructure (PKI) services system, the creation request for auto-signing of the creation request, wherein the PKI services system adjusts a certificate template to comply with PKI standards to generate a signed certificate, the private PKI server makes the signed certificate available through a download link customized for the job-based pod;

receiving, from the PKI services system in response to sending the creation request, the signed certificate for the creation request;

sending, to a Domain Name System (DNS) service, a DNS request with instructions to query an Internet protocol (IP) address associated with the DNS request and provide a list of aliases associated with the IP address;

receiving, from the DNS service, a DNS response to the DNS request;

connecting, to an OpenShift Container (OCP) cluster, an application (app) request to validate certificates for a route associated with the IP address and to feed a universal resource locator (URL) for the route to a master OCP cluster;

receiving, from the OCP cluster, a response to the app request;

providing, to a ticketing system, a documentation request to document activities associated with the app request and the URL; and

informing a developer associated with the creation request of a completion of the creation request, comprising providing the URL to the developer.

9. The non-transitory, computer-readable medium of claim 8 , wherein the container orchestration system is an open-source container orchestration system.

10. The non-transitory, computer-readable medium of claim 8 , further comprising determining that the SSL certificate is set to expire within a threshold period.

11. The non-transitory, computer-readable medium of claim 8 , further comprising performing a renewal process on the SSL certificate.

12. The non-transitory, computer-readable medium of claim 11 , wherein performing the renewal process on the SSL certificate comprises extracting certificate details from the SSL certificate comprising an Openshift cluster name, a project name, and project users.

13. The non-transitory, computer-readable medium of claim 11 , wherein performing the renewal process on the SSL certificate comprises sending a request to the PKI services system and receiving a response upon completion.

14. The non-transitory, computer-readable medium of claim 11 , wherein performing the renewal process on the SSL certificate comprises performing API calls to edit an application route and validating the SSL certificate assigned to the application route.

15. A computer-implemented system, comprising:

one or more processors; and a non-transitory computer-readable storage medium coupled to the one or more processors and storing programming instructions for execution by the one or more processors, the programming instructions instructing the one or more processors to perform operations comprising:

receiving, at a job-based pod used in a container orchestration system, a creation request to create a containerized application custom route and Secure Sockets Layer (SSL) certificates associated with the containerized application custom route;

sending, by the job-based pod to a Public Key Infrastructure (PKI) services system, the creation request for auto-signing of the creation request, wherein the PKI services system adjusts a certificate template to comply with PKI standards to generate a signed certificate, the private PKI server makes the signed certificate available through a download link customized for the job-based pod;

receiving, from the PKI services system in response to sending the creation request, the signed certificate for the creation request;

sending, to a Domain Name System (DNS) service, a DNS request with instructions to query an Internet protocol (IP) address associated with the DNS request and provide a list of aliases associated with the IP address;

receiving, from the DNS service, a DNS response to the DNS request;

connecting, to an OpenShift Container (OCP) cluster, an application (app) request to validate certificates for a route associated with the IP address and to feed a universal resource locator (URL) for the route to a master OCP cluster;

receiving, from the OCP cluster, a response to the app request;

providing, to a ticketing system, a documentation request to document activities associated with the app request and the URL; and

informing a developer associated with the creation request of a completion of the creation request, comprising providing the URL to the developer.

16. The computer-implemented system of claim 15 , wherein the container orchestration system is an open-source container orchestration system.

17. The computer-implemented system of claim 15 , further comprising determining that the SSL certificate is set to expire within a threshold period.

18. The computer-implemented system of claim 15 , further comprising performing a renewal process on the SSL certificate.

19. The computer-implemented system of claim 18 , wherein performing the renewal process on the SSL certificate comprises extracting certificate details from the SSL certificate comprising an Openshift cluster name, a project name, and project users.

20. The computer-implemented system of claim 18 , wherein performing the renewal process on the SSL certificate comprises sending a request to the PKI services system and receiving a response upon completion.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2022
From: ALKHAWAJA, AQEEL HUSSAIN; ALDAJANI, HAIDAR A.; ALMAGHLOUTH, HAMAD ABDULLATIF; ALJUNAIDI, HOSSAM ABDULWAHID
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 060841/0585 →
Continuity (1)
Related Publication 20240064005A1 · Feb 22, 2024
References Cited (14)
US 10599402B2 · Landowski et al. · 2020 [cited by applicant]
US 20110047374A1 · Liu · 2011 [cited by examiner]
US 20120204032A1 · Wilkins · 2012 [cited by examiner]
US 20150088754A1 · Kirsch · 2015 [cited by examiner]
US 20150121078A1 · Fu · 2015 [cited by examiner]
US 20150271296A1 · Borzycki · 2015 [cited by examiner]
US 20200272768A1 · Zou · 2020 [cited by examiner]
US 20210337033A1 · Madisetti · 2021 [cited by examiner]
US 20220158926A1 · Wennerstrom et al. · 2022 [cited by examiner]
US 20230008901A1 · McDowall · 2023 [cited by examiner]
US 20230082851A1 · Liu · 2023 [cited by examiner]
US 20240146511A1 · S · 2024 [cited by examiner]
US 20240211157A1 · Prasannakumar · 2024 [cited by examiner]
US 20240212478A1 · Brown · 2024 [cited by examiner]