Fine-grained SD-WAN optimization services for cloud-native applications
In one embodiment, a device of a software-defined wide area network (SD-WAN) receives, from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application. The device translates the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the cloud-native application. The device applies the network policy to a traffic flow in the SD-WAN between an endpoint and a particular microservice of the cloud-native application.
1 . A method comprising:
receiving, at a device of a software-defined wide area network (SD-WAN) and from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;
identifying, by the device, network requirements for each of the microservices specified in the contextual data for the cloud-native application;
translating, by the device and based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and
applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.
2 . The method as in claim 1 , wherein applying the access policy to the traffic flow comprises:
preventing the endpoint from accessing the particular microservice of the cloud-native application.
3 . The method as in claim 2 , wherein the access policy for the particular microservice specifies a user group to which the endpoint belongs.
4 . The method as in claim 1 , wherein the contextual data specifies one or more SD-WAN services to be applied to traffic in the SD-WAN associated with the particular microservice.
5 . The method as in claim 4 , wherein the one or more SD-WAN services comprise at least one of: a path visibility service, a Transport Control Protocol (TCP) optimization service, a Forward Error Control (FEC) service, a packet duplication service, or a firewall service.
6 . The method as in claim 4 , wherein application of the network policy causes the one or more SD-WAN services specified in the contextual data to be applied to the traffic flow between the endpoint and the particular microservice.
7 . The method as in claim 1 , wherein receiving the contextual data for the cloud-native application that identifies microservices of the cloud-native application comprises:
extracting the contextual data from a Hypertext Transfer Protocol (HTTP) header of traffic sent by the cloud-native application.
8 . The method as in claim 1 , wherein receiving the contextual data for the cloud-native application that identifies microservices of the cloud-native application comprises:
receiving the contextual data via an application programming interface (API).
9 . The method as in claim 1 , wherein the device is an edge router in the SD-WAN.
10 . The method as in claim 9 , wherein the edge router extracts the contextual data from data traffic for the cloud-native application.
11 . An apparatus, comprising:
one or more network interfaces to communicate with a software-defined wide area network (SD-WAN);
a processor coupled to the one or more network interfaces and configured to execute one or more processes; and
a memory configured to store a process that is executable by the processor, the process when executed configured to:
receive, from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;
identify network requirements for each of the microservices specified in the contextual data for the cloud-native application;
translate, based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and
applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.
12 . The apparatus as in claim 11 , wherein the apparatus applies the network policy to the traffic flow by:
preventing the endpoint from accessing the particular microservice of the cloud-native application.
13 . The apparatus as in claim 12 , wherein the access policy for the particular microservice specifies a user group to which the endpoint belongs.
14 . The apparatus as in claim 11 , wherein the contextual data specifies one or more SD-WAN services to be applied to traffic in the SD-WAN associated with the particular microservice.
15 . The apparatus as in claim 14 , wherein the one or more SD-WAN services comprise at least one of: a path visibility service, a Transport Control Protocol (TCP) optimization service, a Forward Error Control (FEC) service, a packet duplication service, or a firewall service.
16 . The apparatus as in claim 14 , wherein application of the network policy causes the one or more SD-WAN services specified in the contextual data to be applied to the traffic flow between the endpoint and the particular microservice.
17 . The apparatus as in claim 11 , wherein the apparatus receives the contextual data for the cloud-native application that identifies microservices of the cloud-native application by:
extracting the contextual data from a Hypertext Transfer Protocol (HTTP) header of traffic sent by the cloud-native application.
18 . The apparatus as in claim 11 , wherein the apparatus receives the contextual data for the cloud-native application that identifies microservices of the cloud-native application by:
receiving the contextual data via an application programming interface (API).
19 . The apparatus as in claim 11 , wherein the apparatus is an edge router in the SD-WAN.
20 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device of a software-defined wide area network (SD-WAN) to execute a process comprising:
receiving, at the device and from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;
identifying, by the device, network requirements for each of the microservices specified in the contextual data for the cloud-native application;
translating, by the device and based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and
applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.