- 专利标题: Container in container method to confine privileged mode execution during host data exchange in a containerized environment
-
申请号: US17573737申请日: 2022-01-12
-
公开(公告)号: US11928528B2公开(公告)日: 2024-03-12
- 发明人: HongYao Tang , Dong Zhang , XiaoJun Wu , Muzhar S. Khokar
- 申请人: Dell Products L.P.
- 申请人地址: US TX Round Rock
- 专利权人: Dell Products L.P.
- 当前专利权人: Dell Products L.P.
- 当前专利权人地址: US TX Round Rock
- 代理机构: Jackson Walker L.L.P.
- 主分类号: G06F15/04
- IPC分类号: G06F15/04 ; G06F9/445 ; G06F9/54
摘要:
A disclosed method for implementing containers in an information handling system generates, with a first non-privileged container, a request that is sent to a RESTful API. Whenever the API identifies a request requiring host access the API launches a second container, which is configured to operate in a privileged execution mode. The second container accesses the host and executes the requested actions. When the request completes, the first container resumes non-privileged execution, thereby confining privileged mode execution to a container that is only active during host interaction. The host access can be access required to: exchange data with the host, query the host for hardware information, and modify host configuration. The host may be implanted within a device featuring an HCI infrastructure. In one configuration, the host resides of one of multiple distinct nodes of an HCI appliance.
公开/授权文献
信息查询