DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is responsive to the Applicant’s amendments filed on 06/04/2026. Claims 1-2, 4-9, and 11-20 remain pending in the application. Claims 1, 8, and 15 have been amended. Any examiner’s note, objection, and rejection not repeated is withdrawn due to Applicant’s amendment.
Examiner’s Note
The Examiner cites particular columns, paragraphs, figures, and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may also apply. It is respectfully requested that, in preparing responses, the Applicant fully consider the references in its entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the Examiner.
Claim Objections
Claims 1-20 are objected to because of the following informalities: Claims 1, 8, and 15 recite “that is mounted as a volume that allows value of the Kubernetes secret…”. The phrase “allows value of the Kubernetes secret” is grammatically incomplete because the singular noun “value” is not preceded by an appropriate article or other determiner. The Examiner suggests “…that allows a value of the Kubernetes secret…”.
Any claim not explicitly mentioned above is objected to due to dependency on an objected claim.
Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 4-9, and 11-20 are rejected under 35 U.S.C. 103 as being unpatentable over Klein et al. (US 20230229319 A1) hereafter Klein in view of Li et al. (US 20230037986 A1) hereafter Li, further in view of Pissay Srinivasa Rao et al. (US 20230022226 A1) hereafter Rao, further in view of Da Canal et al. (US 20240333475 A1) hereafter Da Canal, further in view of Eker et al. (US 20230422095 A1) hereafter Eker.
Regarding claim 1, Klein teaches:
A computer-implementable method for providing persistent storage for a container based application running on a container orchestration system comprising:
mounting a directory volume in a pod of the container orchestration system (Paragraph 270; “persistent storage may be provided by the container orchestration system” and that storage management is handled when the system is “deployed on all nodes in a cluster… using, for example, a Kubernetes DaemonSet” corresponds to mounting an empty directory volume in a pod of the container orchestration system because Kubernetes mounts volumes, which may include into pods as part of its container runtime orchestration);
performing a read to a persistent storage by a container of the pod, wherein the persistent storage is not local to a node of the pod (Paragraph 298; “the additional volume may provide persistent storage to which the running container instance may write persistent data and from which the running container instance may read persistent data” corresponds to performing a read to performing a persistent storage because it explicitly discloses reading from persistent storage. FIG. 1A shows that persistent storage resources 170A and 170B are separate subsystems with their own controllers. The connection from the computing devices to the persistent storage is made through the storage area network (SAN 158) and not through directly attached storage within the pod);
writing from the container data read from the persistent storage to the directory volume (Paragraph 299; “The writeable layer 708 may include one or more writeable volumes (e.g., writeable volume 710) configured to be used to store persistent data for the container instance” corresponds to writing from the init container read from the persistent storage to the empty directory volume because it discloses that the writeable volume is used to store persistent data. If a volume is disclosed as being configured to store persistent data for a container instance, it is inherent that the container can and does perform write operations);
mounting the directory volume to an application container that runs the container based application, to allow read/write operations between the directory volume and application container (Paragraphs 301-302; “the volume 704 may define a stack of dependent volumes that may be used by the container system 502 to run a container instance of the container image 602 and to read and write persistent data while running the container instance” and “the container system 502 may access and use mounted volumes… to run the container instance from the container image 602 and to read and write persistent data” corresponds to the claimed limitation because it explicitly discloses mounting writeable volumes for use by a container instance to execute the container application and to perform read/write operations which satisfies the claimed functionality);
monitoring changes to the directory volume by a manager container (Paragraph 361; “a storage system that provides one or more storage services to a container system may monitor the storage services, determine an interruption to one or more of the storage services, and perform one or more remediation operations in response to determining the interruption”. The storage system acts as the manager and P291 further discloses that this is implemented within a container, “the driver may perform the storage operation on one or more storage resources within the storage pool 406, possibly under direction from or using additional logic within containers that implement the container storage system 402 as a containerized service”);
providing by the manager container the changes to the persistent storage (Paragraph 361; “the storage system may provide, based on the interruption, an alert to the container system, such as by providing the alert to a container orchestrator of the container system” corresponds to providing by the manager container the changes to the persistent storage because the alert conveys information about changes in the storage system to the container system, which may then perform actions accordingly);
and container-based application replicas (Paragraph 206; “A container server cluster might also be able to replicate all data to all cluster nodes, presuming the containers don't tend to be too large and their bulk data (the data manipulated by the applications that run in the containers) is stored elsewhere such as in an S3 cluster or an external file server.”, explicitly disclosing replication of data in containers across cluster nodes, including the data belonging to the applications. Paragraph 195 confirms containerized application deployment, “The systems described above can support the execution of a wide array of software applications. Such software applications can be deployed in a variety of ways, including container-based deployment models. Containerized applications may be managed using a variety of tools.”).
Klein does not teach that the directory volume is explicitly empty; or the container is an init container.
However, Li teaches:
an empty directory volume (Paragraph 91; “In one illustrative example, shared storage 424 can be an emptyDir volume that is first created when pod 426 is assigned a node and exist as long as pod 426 runs on the node” explicitly discloses an empty directory volume created when the pod is first assigned);
and an init container (Paragraph 101; “configuration container 504 can be one of an init container and a sidecar container when container manager 406 is implemented using a container orchestration platform such as Kubernetes” explicitly discloses the use of an init container for configuration).
Klein and Li are considered to be analogous to the claimed invention because they are in the same field of storage management in container orchestration systems. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Klein to incorporate the teachings of Li and have the mounted directory volume be empty and have an init container created when deploying the pod. A person of ordinary skill in the art would have recognized that the addition of an empty directory would have been a logical design choice to add additional storage to systems. Further, the use of an init container would have been a logical design choice to ensure proper ordering of operations, modularity, and security based on Kubernetes best practices.
Klein in view of Li does not teach that the container is a sidecar container of the pod.
However, Rao teaches:
the container is a sidecar container of the pod (Paragraph 11; “service instance is implemented in the form of a pod that includes multiple containers, including a main container and one or more sidecar containers, which are responsible for supporting the main container. For instance, a main container may be a content server and a sidecar container may perform logging functions for the content server, with the content server and the logging sidecar container sharing resources such as storage associated with the pod”, where Rao explicitly discloses that a pod may contain multiple containers including a main and one or more sidecar containers that support the main container by performing services for the main container).
Klein, Li, and Rao are considered to be analogous to the claimed invention because they are in the same field of storage management in container orchestration systems. Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have modified Klein in view of Li to incorporate the teachings of Rao to have the container be a sidecar container of a pod. A person of ordinary skill in the art would have recognized that, where Klein in view of Li teaches a container, designating that container as a sidecar container of a pod would be a known implementation choice in container-based systems, used to modularize auxiliary functions such as storage management. Applying the known sidecar patterns of Rao to the container arrangement of Klein in view of Li would have yielded the predictable outcome of enabling persistent storage functionality to operate alongside the primary application container without changing the pod abstraction.
Klein in view of Li, further in view of Rao does not teach mount the secret and allows a value of the Kubernetes secret to be available as a file inside a file system of containers of the pod, wherein Kubernetes secret mounts are read only; wherein the persistent storage is a Kubernetes secret that is created to include sensitive data that the container based application needs access to.
However, Da Canal teaches:
mount the secret and allows a value of the Kubernetes secret to be available as a file inside a file system of containers of the pod (Paragraph 4; “The secrets can be mounted in the files system of a container group, so the data are readable as normal files.”, where Paragraph 74 confirms that the secrets are values, “This method therefore allows the data fields to be created and the values of the data fields to be populated, after the secret 1200 has been created and, in particular, based on the information contained in the secret description 4400.”, explicitly describing the secret being mounted to the file system and available as a normal file, in which Paragraph 86 discloses “the container group 1100 is not allowed to access the secret 1200 for writing into it”, the container group corresponding to containers of the pod. Utilization in Kubernetes is disclosed in Paragraph 111; “Although the invention can be applied to any container-orchestration system 4000, it has been found by the inventors that it is particularly suitable to an implementation in which the container-orchestration system 4000 comprises Kubernetes”), wherein Kubernetes secret mounts are read only (Paragraph 86; “As described, the container group 1100 is not allowed to access the secret 1200 for writing into it, so that it cannot update the content of the data fields itself.”, explicitly describing the container group being unable to write to the secret, and Paragraph 87 describes “a step S2400 of reading the secret description 4400”, corresponding to being able to read the secret. Paragraph 111 discloses the utilization of this invention in Kubernetes. A person of ordinary skill in the art before the effective filing date of the claimed invention would recognize the ability to read but not write to a secret corresponds a read only setting.);
a Kubernetes secret that is created to include sensitive data that the container needs access to (Paragraph 68; “The method for operating a container group 4100 comprises a step S2100 of creating the secret description 4400 for identifying one or more characteristics of the secret 1200.”, which includes “if a certificate for establishing a TLS connection with a given server is needed as secret, the secret description might comprise all information needed for identifying the certificate, that is, the one or more characteristics of the secret 1200, such as the description of the server to which connection is to be established and an indication that a certificate for TLS connection is needed”, which is explicitly described as needed. Paragraph 111 discloses the utilization of this invention in Kubernetes.).
Klein, Li, Rao, and Da Canal are considered to be analogous to the claimed invention because they are in the same field of container orchestration systems. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Klein in view of Li, further in view of Rao to incorporate the teachings of Da Canal to have mounted the Kubernetes secret as a volume disclosed by Klein (Paragraph 270), that allows a value of the Kubernetes secret to be available as a file inside a file system of containers of the pod and set as read only. A person of ordinary skill in the art before the effective filing date of the claimed invention would have been motivated to mount the Kubernetes secret as a read-only volume because the secret contains sensitive information intended to be provided to a container for access rather than modification, and would have further been motivated to make the secret available as a file within the file system of the container because it would be recognized that it would allow access to the secret using a conventional file interface without requiring the secret to be embedded in the container image or otherwise incorporated into the container application, whose implementation would yield the predictable result of making the secret value accessible to the container pod as a file through the container file system while preventing modifications to the secret. Further, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have the persistent storage be a Kubernetes secret that includes sensitive data that the container-based application and its replicas need access to. A person of ordinary skill in the art would have recognized the externalizing of sensitive data into persistent storage to be a known method in the art yielding the predictable result of ensuring that multiple replicas of the application can reliably access consistent sensitive data during the container pod lifecycle.
While Klein suggests reduced coupling between the application and its orchestrator (Paragraph 313; “a container orchestrator may operate to deploy and/or redeploy containers within a cluster without any knowledge of a volume being associated with container images”. Paragraph 260 further discloses “the containerized application may be abstracted away from host operating systems as a combined collection of lightweight and portable packages and configurations, where the containerized application may be uniformly deployed and consistently executed in different computing environments that use different container-compatible operating systems or different infrastructures”, the abstraction of which would reduce the need for the application to have awareness of the orchestration system.), Klein in view of Li, further in view of Rao, further in view of Da Canal does not explicitly teach an application unaware of the orchestrator.
However, Eker teaches:
an application unaware of the orchestrator (Paragraph 77; “FIG. 5 shows an exemplary real-time resource management framework, also known as ACTORS. The ACTORS resource management abstracts available physical computing resources via “virtual platforms”, e.g., virtual machines (VMs), containers (e.g., Kubernetes), or other execution environments. Individual applications can be ACTORS-aware or ACTORS-unaware”, where ACTORS functions as the orchestration layer and therefore corresponds to applications that may either be aware or not aware of the orchestration system.).
Klein, Li, Rao, Da Canal, and Eker are considered to be analogous to the claimed invention because they are in the same field of container orchestration systems. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Klein in view of Li, further in view of Rao, further in view of Da Canal to incorporate the teachings of Eker and have the application be unaware of the orchestrator. Eker discloses that an application may be configured to be either aware of or unaware of the orchestration system (ACTORS). In view of this teaching of alternative configurations, it would have been obvious to a person of ordinary skill in the art to implement the application in an unaware configuration, as selecting between the two known alternatives corresponds to a design choice between a finite number of identified, predictable solutions.
Claim 8 recites similar limitations as those of claim 1, directed towards a system, additionally reciting a plurality of processing systems communicably coupled through a network, wherein the processing systems include non-transitory, computer-readable storage medium embodying computer program code. Klein teaches:
a plurality of processing systems communicably coupled through a network (Paragraph 84; “A switch fabric 146 couples storage nodes 150 within chassis 138 together and to a network for communication to the memory”, where Paragraph 105 further describes storage nodes as “Each storage node 150 has a CPU 156”. Each storage node CPU is a processing system. Since they are interconnected via the switch fabric and the network, the system corresponds to the claimed limitation);
wherein the processing systems include non-transitory, computer-readable storage medium embodying computer program code (Paragraph 233; “a non-transitory computer-readable medium storing computer-readable instructions may be provided in accordance with the principles described herein. The instructions, when executed by a processor of a computing device, may direct the processor and/or computing device to perform one or more operations, including one or more of the operations described”).
Claim 8 is rejected for similar reasons as those of claim 1.
Claim 15 recites similar limitations as those of claim 1, directed towards an apparatus, additionally reciting a non-transitory, computer-readable storage medium embodying computer program code. Klein teaches:
a non-transitory, computer-readable storage medium embodying computer program code (Paragraph 233; “a non-transitory computer-readable medium storing computer-readable instructions may be provided in accordance with the principles described herein. The instructions, when executed by a processor of a computing device, may direct the processor and/or computing device to perform one or more operations, including one or more of the operations described”).
Claim 15 is rejected for similar reasons as those of claim 1.
Regarding claim 2, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the method of claim 1. Klein teaches:
wherein the container orchestration system is Kubernetes (Paragraph 264; “The container system 400 may include or be implemented by one or more container orchestration systems, including Kubernetes”).
Claim 9 recites similar limitations as those of claim 2. Claim 9 is rejected for similar reasons as those of claim 2.
Claim 16 recites similar limitations as those of claim 2. Claim 16 is rejected for similar reasons as those of claim 2.
Regarding claim 17, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the apparatus of claim 15. Klein teaches:
a persistent storage (Paragraph 298; “the additional volume may provide persistent storage to which the running container instance may write persistent data”).
Li teaches:
wherein the storage includes a Kubernetes secret (Paragraph 4; “For example, the sensitive data can be encrypted with the encrypted sensitive data being stored in an object such as a secret in Kubernetes”. Paragraph 86 further discloses “Location 416 can be, for example, a secret, a configmap, a database, a data store, a file, or some other location in which sensitive data 412 can be located”).
It would have been obvious to a person of ordinary skill in the art to have included a Kubernetes secret as taught by Li with the persistent storage taught by Klein. A person of ordinary skill in the art before the effective filing date of the claimed invention would have been motivated to include the Kubernetes secret in persistent storage because persisting the secret would allow the secret to remain available across restarts or redeployments of the container rather than requiring the secret be recreated or reprovisioned each time the container is started/restarted, yielding the predictable result of retaining the Kubernetes secret data in persistent storage for subsequent access by the container.
Regarding claim 4, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the method of claim 1. Klein teaches:
wherein the init container and the manager container are aware of the container orchestration system (Paragraphs 277-278; “Such a storage system may be referred to as a container-aware storage system” and “The container system may then use the immutable container image from the volume to run the container instance of the immutable container image in the container system” corresponds to the claimed limitation because the storage system interacts directly with the container orchestration system to provide volumes and container images, demonstrating that both types of containers operate in the context of, thereby having awareness of, the orchestration system).
Claim 11 recites similar limitations as those of claim 4. Claim 11 is rejected for similar reasons as those of claim 4.
Claim 18 recites similar limitations as those of claim 4. Claim 18 is rejected for similar reasons as those of claim 4.
Regarding claim 5, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the method of claim 1. Klein teaches:
wherein the persistent storage is one of a secret, config map, or object store (Paragraph 261; “The storage resources may include any of the illustrative storage resources described herein and may include on-node resources such as a local tree of files and directories, off-node resources such as external networked file systems, databases or object stores, or both on-node and off-node resources” discloses the object store element of the claim).
Claim 12 recites similar limitations as those of claim 5. Claim 12 is rejected for similar reasons as those of claim 5.
Claim 19 recites similar limitations as those of claim 5. Claim 19 is rejected for similar reasons as those of claim 5.
Regarding claim 6, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the method of claim 1. Klein teaches:
wherein data of the persistent storage is available to replicas of the container based applications (Paragraph 336; “Based on the replication factor of Z, the container orchestrator may deploy Z instances of the container image 1210 associated with the application among Z nodes 420” corresponds to the claimed limitation because deploying multiple instances of the same container image across multiple nodes inherently allows each replica to access data of the persistent storage, thereby making it available to newly deployed instances of the container image, corresponding to replicas of the container based applications).
Claim 13 recites similar limitations as those of claim 6. Claim 13 is rejected for similar reasons as those of claim 6.
Claim 20 recites similar limitations as those of claim 6. Claim 20 is rejected for similar reasons as those of claim 6.
Regarding claim 7, Klein in view of Li, further in view of Rao, further in view of Da Canal, further in view of Eker teach the method of claim 1. Li teaches:
wherein data in the persistent storage is sensitive information (Paragraph 121; “If the checksum exchanged between the first checksum and the second checksum, the sensitive information stored in volume 620 can be updated” explicitly discloses stored sensitive information).
Klein teaches:
a persistent storage (Paragraph 298; “the additional volume may provide persistent storage to which the running container instance may write persistent data”).
Claim 14 recites similar limitations as those of claim 7. Claim 14 is rejected for similar reasons as those of claim 7.
Response to Arguments
Applicant's arguments filed 06/04/2026 have been fully considered. Applicant’s arguments are summarized below:
The amended portion of independent claims 1, 8, and 15 is not described or shown by the cited art.
Dependent claims are submitted as allowable for at least the above reasons.
Examiner’s response:
The Examiner agrees that the amended portion of claims 1, 8, and 15 is not described or shown by the prior art. Accordingly, the previous rejections of claims 1, 8, and 15 under 35 U.S.C. 103 are withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Klein, Li, Rao, Da Canal, and Eker, under 35 U.S.C. 103.
Independent claims 1, 8, and 15 remain rejected for the reasons stated above. Therefore, contrary to Applicant's arguments, because the dependent claims depend from an unpatentable claim and does not add limitations that overcome the rejection, it likewise remains rejected.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Pabón (US 20230229359 A1) discusses the use of a container-aware storage system that may provide persistent storage for a container system for use by the container images.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KENNETH P TRAN whose telephone number is (571)272-6926. The examiner can normally be reached M-TH 4:30 a.m. - 12:30 p.m. PT, F 4:30 a.m. - 8:30 a.m. PT, or at Kenneth.Tran@uspto.gov.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, April Blair can be reached at (571) 270-1014. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KENNETH P TRAN/ Examiner, Art Unit 2196
/APRIL Y BLAIR/ Supervisory Patent Examiner, Art Unit 2196