US2023367622A1PendingUtilityA1

Logical processing for containers

Assignee: NICIRA INCPriority: May 17, 2015Filed: Jul 27, 2023Published: Nov 16, 2023
Est. expiryMay 17, 2035(~8.8 yrs left)· nominal 20-yr term from priority
H04L 45/745G06F 9/45558H04L 41/0806H04L 45/586H04L 12/4641H04L 69/329G06F 9/5077G06F 2009/45595G06F 2009/45583
78
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments provide a local network controller that manages a first managed forwarding element (MFE) operating to forward traffic on a host machine for several logical networks and configures the first MFE to forward traffic for a set of containers operating within a container virtual machine (VM) that connects to the first MFE. The local network controller receives, from a centralized network controller, logical network configuration information for a logical network to which the set of containers logically connect. The local network controller receives, from the container VM, a mapping of a tag value used by a second MFE operating on the container VM to a logical forwarding element of the logical network to which the set of containers connect. The local network controller configures the first MFE to apply the logical network configuration information to data messages received from the container VM that are tagged with the tag value.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method of operating containers on a host computer, the method comprising:
 deploying a first virtual machine (VM) to execute on the host computer;   configuring a plurality of containers to operate on the first VM to process packets receives by the host computer; and   configuring a first managed forwarding element (MFE) to operate on the first VM to forward to each container packets that the first VM receives for the container and to forward packets received from each container to a module executing on the host computer outside of the first VM.   
     
     
         22 . The method of  claim 21 , wherein the module is a second MFE executing on the host computer outside of the first VM to forward data message among different VMs. 
     
     
         23 . The method of  claim 22 , wherein the first and second MFEs implement a logical forwarding element (LFE) along with other MFEs executing on other host computers. 
     
     
         24 . The method of  claim 21 , wherein configuring the first MFE comprises configuring the first MFE to use tags provided with the packets to identify the containers associated with the packets that should receive the packets. 
     
     
         25 . The method of  claim 24 , wherein each tag uniquely identifies a particular container as each tag is only associated with one container executing on the first VM. 
     
     
         26 . The method of  claim 24 , wherein the first MFE uses each tag received with each packet to identify the container that should receive the packet by using the tag with at least one header value of the received packet to identify the container. 
     
     
         27 . The method of  claim 24 , wherein the header value is a MAC (media access control) address 
     
     
         28 . The method of  claim 27 , wherein the first MFE implements a plurality of logical forwarding elements along with a plurality of sets of other MFEs executing on other host computers, and each received packet's tag identifies the LFE to which a container that is the destination of the received packet belongs. 
     
     
         29 . The method of  claim 21 , wherein configuring the first MFE comprises configuring the first MFE to provide a tag with a packet sent by a container when the first MFE forwards the packet to said module, said module using the provided tag to identify a set of one or more network policies to apply to the packet before forwarding the packet through a network. 
     
     
         30 . The method of  claim 29 , wherein the first MFE implements a plurality of logical forwarding elements along with a plurality of sets of other MFEs executing on other host computers, and each packet's tag identifies the LFE to which a container that is the source of the packet belongs. 
     
     
         31 . A non-transitory machine readable medium storing a program for operating containers on a host computer on which a plurality of virtual machines (VM), including a first VM, execute, the program comprising sets of instructions for:
 configuring a plurality of containers to operate on the first VM to process packets receives by the host computer; and   configuring a first managed forwarding element (MFE) to operate on the first VM to forward to each container packets that the first VM receives for the container and to forward packets received from each container to a module executing on the host computer outside of the first VM.   
     
     
         32 . The non-transitory machine readable medium of  claim 31 , wherein the module is a second MFE executing on the host computer outside of the first VM to forward data message among different VMs. 
     
     
         33 . The non-transitory machine readable medium of  claim 32 , wherein the first and second MFEs implement a logical forwarding element (LFE) along with other MFEs executing on other host computers. 
     
     
         34 . The non-transitory machine readable medium of  claim 31 , wherein the set of instructions for configuring the first MFE comprises a set of instructions for configuring the first MFE to use tags provided with the packets to identify the containers associated with the packets that should receive the packets. 
     
     
         35 . The non-transitory machine readable medium of  claim 34 , wherein each tag uniquely identifies a particular container as each tag is only associated with one container executing on the first VM. 
     
     
         36 . The non-transitory machine readable medium of  claim 34 , wherein the first MFE uses each tag received with each packet to identify the container that should receive the packet by using the tag with at least one header value of the received packet to identify the container. 
     
     
         37 . The non-transitory machine readable medium of  claim 34 , wherein the header value is a MAC (media access control) address 
     
     
         38 . The non-transitory machine readable medium of  claim 37 , wherein the first MFE implements a plurality of logical forwarding elements along with a plurality of sets of other MFEs executing on other host computers, and each received packet's tag identifies the LFE to which a container that is the destination of the received packet belongs. 
     
     
         39 . The non-transitory machine readable medium of  claim 31 , wherein the set of instructions for configuring the first MFE comprises a set of instructions for configuring the first MFE to provide a tag with a packet sent by a container when the first MFE forwards the packet to said module, said module using the provided tag to identify a set of one or more network policies to apply to the packet before forwarding the packet through a network. 
     
     
         40 . The non-transitory machine readable medium of  claim 39 , wherein the first MFE implements a plurality of logical forwarding elements along with a plurality of sets of other MFEs executing on other host computers, and each packet's tag identifies the LFE to which a container that is the source of the packet belongs.

Join the waitlist — get patent alerts

Track US2023367622A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.