Generation, actuation, and enforcement of policies for resources within a distributed computing system
Abstract
The generation, actuation, and enforcement of policies within a distributed computing system is provided. The policies are employed to manage the resources of the system. The resources include virtualized resources, such as virtual machines (VMs) and virtual storage disks (VSDs). A policy includes a rule and scope. Enforcing a policy includes applying the rule to resources that are within the policy's scope. Policies are employed to constrain the leasing period and reclaim leased resources, as well constrain the access of certain users to specific operations on the leased resources. Policies may be created via a UI that automatically generates a policy encoding. The policy is registered and accessed via a policy store. When multiple policies target a particular resource, merging strategies are applied to the multiple policies, to generate an effective policy that is consistent with the multiple policies and is enforced on the particular resource.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for operating a distributed computing system that comprises a set of resources, the method comprising:
at a policy server employing one or more processors and a memory:
providing a user interface for creation of a policy by a user, the user interface having one or more fields for entry of values defining the policy;
receiving, via the user interface, one or more of the values;
generating a user policy from the one or more received values;
registering the generated user policy in a policy store;
selecting, from among a set of policies of the policy store, the set of policies including the user policy, a subset of policies each governing a particular resource of the set of resources;
generating, based on the selected subset of policies, an effective policy associated with the particular resource; and
enforcing the effective policy on the particular resource.
2 . The method of claim 1 , wherein the selecting, the generating an effective policy, and the enforcing are performed in response to one or more requests from a user.
3 . The method of claim 2 , wherein the one or more requests are received via the user interface.
4 . The method of claim 1 , further comprising providing access to the user policy to other users, via the policy store.
5 . The method of claim 1 , wherein the generating an effective policy further comprises:
ordering the policies of the subset of policies based on one or more ordering rules; and merging the policies of the subset of policies based on the ordering, so as to generate the effective policy.
6 . The method of claim 5 , further comprising providing a preview indication of one or more effects of the effective policy on one or more resources of the set of resources.
7 . The method of claim 5 , wherein the generating an effective policy further comprises filtering the subset of policies based on one or more incompatible conditions of the subset of policies.
8 . The method of claim 1 , wherein the one or more fields include a field for entry of a policy type.
9 . The method of claim 8 , wherein the policy type comprises a lease policy type and a day-2 operations policy type.
10 . The method of claim 1 , wherein the one or more fields include one or more of a field for entry of a default lease period of a first resource of the set of resources, a field for entry of a maximum lease period of the first resource, or a field for entry of a grace period of the first resource.
11 . The method of claim 1 , wherein a first policy of the set of policies constrains a user from initiating an operation of a first resource of the set of resources.
12 . The method of claim 1 , wherein the one or more fields include a field for entry of an enforcement type, the enforcement type having at least two possible values, the enforcement type further indicating a priority for ordering the subset of policies.
13 . The method of claim 12 , wherein the at least two possible values include a hard value corresponding to a policy that may be overridden, and a soft value corresponding to a policy that may not be overridden.
14 . The method of claim 1 , wherein the one or more fields include a field for entry of a type of the resources governed by a policy, wherein the type of the resources includes one or more of virtual machines (VMs) or virtual storage disks (VSDs).
15 . The method of claim 1 , wherein the one or more fields include a field for entry of one or more logical statements that, when applied to each resource in the set of resources, evaluates to true or false, and wherein evaluation of each of the one or more logical statements is applied as a filter that narrows a scope of the policy.
16 . The method of claim 1 , wherein the one or more fields include a field for entry of a policy scope.
17 . The method of claim 1 , further comprising receiving, via the user interface, an update to a policy of the set of policies.
18 . The method of claim 1 , the one or more fields include one or more of a field for entry of a policy name or a field for entry of a policy description.
19 . A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a distributed-computing system comprising a set of resources, the one or more programs including instructions for:
at a policy server employing one or more processors and a memory:
providing a user interface for entry of a policy by a user, the user interface having one or more fields for entry of values defining the policy;
receiving, via the user interface, one or more of the values;
generating a user policy from the one or more received values;
registering the generated user policy in a policy store;
selecting, from among a set of policies of the policy store, the set of policies including the user policy, a subset of policies each governing a particular resource of the set of resources;
generating, based on the selected subset of policies, an effective policy associated with the particular resource; and
enforcing the effective policy on the particular resource.
20 . A distributed-computing system comprising a set of resources, the system comprising:
one or more processors; and memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for:
at a policy server employing one or more processors and a memory:
providing a user interface for entry of a policy by a user, the user interface having one or more fields for entry of values defining the policy;
receiving, via the user interface, one or more of the values;
generating a user policy from the one or more received values;
registering the generated user policy in a policy store;
selecting, from among a set of policies of the policy store, the set of policies including the user policy, a subset of policies each governing a particular resource of the set of resources;
generating, based on the selected subset of policies, an effective policy associated with the particular resource; and
enforcing the effective policy on the particular resource.Join the waitlist — get patent alerts
Track US2024028377A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.