DETAILED ACTION
This office action is in response to the application filed on 08/14/2026. Claim(s) 1-24 is/are pending and are examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 08/14/2026 has been entered.
Response to Arguments
Applicant's arguments filed on 08/14/2026 have been fully considered but they are not persuasive for the following reasons:
Applicant’s Argument:
The Examiner states that replacing Szigeti with Banda "fully addressed"
Applicant's prior arguments because Banda allegedly supplies the admission-controller
limitations missing from Szigeti. Respectfully, replacing a reference is not itself a
substantive response to arguments that remain applicable to the references and rejection
of record.
Applicant's prior arguments included arguments directed specifically to Lee,
including that Lee's firewall policy operates on runtime network traffic and does not
disclose an admission controller, a policy applied by an admission controller, or the
claimed policy operations within software-container clusters. Because Lee continued to
be applied for substantially the same subject matter, those arguments remained relevant
notwithstanding the replacement of Szigeti.
MPEP § 707.0?(f) states that, when a rejection is repeated, the Examiner should
answer the substance of Applicant's traversal. The Examiner Notes accompanying form
paragraph 7.38 further state that, even when arguments are considered moot because of
a new ground, "the examiner must, however, address any arguments presented by the
applicant which are still relevant to any references being applied." MPEP § 707.0?(f).
Moreover, the April 29, 2026 Response did not merely repeat arguments
concerning Szigeti. It specifically addressed the newly asserted Lee-Banda combination,
the distinction between Lee's firewall and the claimed admission controller, and the
absence of a reason to modify the references in the claimed manner. Accordingly, the
fact that Banda replaced Szigeti did not answer those arguments. (Applicant’s response filed on 08/14/2026, page 2).
Examiner’s Response:
The Examiner respectfully disagrees. In the prior office action, the deficiencies pointed out by the argumentation was covered by the introduction of new art as such the argued deficiencies were moot on the grounds of a new rejection.
Applicant’s Argument:
The Examiner next states that Banda teaches "the admission controller policy"
because paragraph 190 describes policy controller 228 selecting and merging policies.
This response conflates a policy controller with an admission controller.
Banda, in paragraph 190, states that policy controller 228 selects first and second
policies and merges them into an aggregate policy. It does not identify policy controller
228 as an admission controller. Indeed, Banda does not describe policy controller 228 as
intercepting API requests before persistence, determining whether requested resource
operations should be admitted, or validating or mutating a resource as part of admission
processing. These are not merely different names for the same component. An admission
controller performs a particular control-plane function. Kubernetes describes an
admission controller as code that intercepts requests to the API server before resource
persistence and applies to requests that create, delete, or modify objects. Banda's policy
controller instead performs centralized policy creation, selection, hierarchical conflict
resolution, aggregation, propagation, and management.
A general policy-management controller does not become an admission controller
merely because both components may be described using the word "controller". The
rejection identifies no disclosure or technical reasoning establishing that Banda's policy
controller performs the admission-control functionality required by claim 1. (Applicant’s response filed on 08/14/2026, page 2-3).
Examiner’s Response:
The Examiner respectfully disagrees. The Examiner respectfully disagrees the cited portion of Banda ¶ 190 teaches, “The policy controller selects first and second policies of a plurality of policies enabled for enforcement in a cluster, each of the first and second policies comprising a set of rules and corresponding to a different set of operations performed in the cluster.” Discusses receiving two policies and merging them to be applied to cluster. Banda’s teachings are not meant to be taken in isolation, but in combination with the other prior arts to resolve in the areas that it is lacking to teach the claimed limitation. For the sake of prosecution a new art Chen and Dubro has been cited to cover the argued deficiencies of Banda. It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen in view of Dubro with Banda, to modify the system for a federated operator for edge computing networks of Chen with the control plane orchestator of Dubro with the merging and application of policies of Banda. The motivation to do so, Banda ¶ 23, can enable not only high availability, load balancing, scaling, and high performance but also provide a policy management tool that creates, updates, and verifies policies using a central policy enforcement point that overcomes challenges due to cloud-based cluster complexity.
Applicant’s Argument:
For the limitation reciting the admission controller to receive first and second
policies from a unified policy engine, the Office Action cites Banda at paragraph [0190]
that policy controller 228 "selects first and second policies of a plurality of policies enabled
for enforcement in a cluster". Selecting policies is not the claimed receipt of policies by an admission controller from a unified policy engine. The rejection does not identify a
unified policy engine serving as the source of the policies, an admission controller
receiving the policies from that engine, or a communication or operational relationship
between such an engine and admission controller.
Instead, the rejection treats Banda's policy controller as both the alleged policy
engine and the alleged admission controller. Banda provides no support for that mapping,
and the rejection provides no explanation why a person of ordinary skill would have
divided or reassigned the functions of policy controller 228 in the claimed manner.
Banda paragraph [0190] states that policy controller 228 merges two policies into
an aggregate policy. Claim 1, however, recites that the admission controller deployed in
the first software-container cluster performs the merger. An obviousness analysis must
give effect to the component expressly assigned to perform a claimed operation. It is
insufficient to show that some different component somewhere in a prior-art system
performs a generally similar operation.
Banda describes policy controller 228 as part of a policy-management architecture.
In the Figure 2 embodiment, policy controller 228 is an instruction set of application
management server 1 OS's management plane. Banda separately states in paragraph 84
that a cluster may have its own controller or control plane different from application
management server 108. Thus, Banda itself distinguishes the cluster's control-plane
component from the application-management component containing policy controller
228. function
would have been relocated from policy controller 228 to an admission controller deployed
in the first cluster. Nor does it identify any known technique or design incentive for making
that particular reassignment.
The Office Action again cites paragraph [0190] for the requirement that the
admission controller apply the single policy to a resource of the first software-container
cluster. Paragraph [0190] states only that the aggregate policy is "to be enforced at a
selected hierarchical level".
That passage does not state that an admission controller applies the policy. It also
does not identify the claimed resource to which the admission controller applies the
The Office Action does not explain why or how Banda's policy-merging Furthermore, Banda's policy controller merges policies according to organizational
or administrative hierarchical levels, not according to admission-control processing.
Banda describes its hierarchy in terms of service-provider, tenant, project, and application
levels. This disclosure concerns the hierarchical organization of users, tenants, projects,
roles, and access privileges. It does not describe an admission controller, an admissioncontrol
policy, or a policy applied during the admission of a request to create, modify, or
delete a software-container-cluster resource. Nor does it suggest that the "hierarchical
level" at which Banda's aggregate policy is enforced corresponds to an admission-control
stage or to an admission controller deployed in a cluster.
Banda's other examples confirm this distinction. Banda describes policies
associated with service-provider, tenant, project, and application levels and policy types
concerning storage, networking, security, resource limits, and performance. Thus,
Banda's hierarchy identifies the administrative scope and priority of policies. It does not
identify the component that performs admission control or transform policy controller 228
into an admission controller. Accordingly, Banda's disclosure that policy controller 228 merges policies from
different hierarchical levels does not satisfy claim 1 's materially different recital that an
admission controller deployed in the first software-container cluster receives first and
second policies, merges those policies into a single policy, and applies that single policy
to a cluster resource. The rejection improperly equates hierarchical policy aggregation
with admission-control enforcement, without any supporting disclosure or technical
reasoning.
Banda additionally explains that policy controller 228 may interpret policies and
provide enforcement configurations to corresponding feature-specific controllers. This disclosure further confirms that policy controller 228's aggregation of policies is distinct
from the subsequent enforcement performed by other components. It does not disclose
the claimed admission controller both merging and applying the single policy. (Applicant’s response filed on 08/14/2026, page 4-6).
Examiner’s Response:
The Examiner respectfully disagrees. The arguments presented by the Applicant above all appear to take Banda’s teachings in isolation and not in combination with what prior arts would teach to fulfill those deficiencies. For the sake of prosecution the new art Chen has replaced Lee with the new art Dubro fulfilling any other perceived deficiencies of Banda, the teachings of Chen in view of Dubro as can be seen in the rejection below teach the deficiencies of Banda to fully teach the limitations below. The cited portion of Banda is meant to teach the concept of a policy controller merging two different policies to create a singular policy for application, which it does. To address the arguments above for the controller to merge to different policies it must have received the policies from somewhere as such arguing that it does not directly teach receiving two different policies is a stretch.
The argued different levels of application management vs control plane is satisfied by the introduction of the new art Dubro. It would be obvious to apply Banda’s policy merging on an management level to a control plane level as it well known in the art the proper implementation of policy across all levels of the technology stack is important to have a clear and concise policy system that will allow for improved security and efficiency. The remaining argumentation discussing Banda’s application of the merged policy is covered in the new cited art Dubro. As for the motivation of combination the Examiner believes the argument presented as well as the new arts as well as the new cited motivation should be sufficient for the Applicant as to why the motivation to combine is relevant. As such the combination of Chen-Dubro-Banda teaches the argued limitations. It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen in view of Dubro with Banda, to modify the system for a federated operator for edge computing networks of Chen with the control plane orchestrator of Dubro with the merging and application of policies of Banda. The motivation to do so, Banda ¶ 23, can enable not only high availability, load balancing, scaling, and high performance but also provide a policy management tool that creates, updates, and verifies policies using a central policy enforcement point that overcomes challenges due to cloud-based cluster complexity.
2. Applicant's arguments with respect to the other argued claims have been fully considered but are moot in view of the new ground(s) of rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 6-7, 12-15, 17-18, and 24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen (EP 3,929,741 A1), hereinafter Chen in view of Dubrovsky (US 2024/0354426 A1), hereinafter Dubro in further view of Bandarupalli (US 2023/0148158 A1), hereinafter Banda.
Regarding Claim(s) 1, 12, and 13 Chen teaches:
A method for applying a unified policy across multiple computing environments, comprising: (Chen ¶ 10 teaches, federated operator components (i.e., unified policy engine) provide policies for system/component upgrade and/or maintenance globally across all tiers of edge computing clusters. The federated operator component may implement a CDN upgrade policy that triggers update of cache services on Edge Clusters A and B only after successful update of a Storage Service cluster. Federated control of upgrade and/or maintenance policies help to ensure service availability during maintenance.) the first software container cluster deployed in a first computing environment; (Chen ¶ 2 teaches, The federated operator component is configured to send a first request to provision a first compute resource according to the first compute resource requirement to a first operator component executing on a first container orchestration framework of a first cluster of compute nodes)
applying the single policy on a second resource in a second computing environment. (Chen ¶ 10 teaches, federated operator components provide policies for system/component upgrade and/or maintenance globally across all tiers of edge computing clusters. The federated operator component may implement a CDN upgrade policy that triggers update of cache services on Edge Clusters A and B (i.e. first and second environments).)
and a second software […] across the first computing environment and the second computing environment. (Chen ¶ 10 teaches, federated operator components provide policies for system/component upgrade and/or maintenance globally across all tiers of edge computing clusters. The federated operator component may implement a CDN upgrade policy that triggers update of cache services on Edge Clusters A and B (i.e. first and second environments).)
Chen does not appear to explicitly teach an admission controller applying a policy but in related art:
configuring the admission controller to apply the single policy to a resource of the first software container cluster; and (Dubro ¶ 149 teaches, Operation depicts distributing the access policy to a control plane of a target container orchestrator, wherein the target container orchestrator configured to apply the access policy.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen in view of Dubro, to modify the system for a federated operator for edge computing networks of Chen with the control plane policy orchestrator of Dubro. The motivation to do so, Dubro ¶ 24, distribute and use the created policies in a decentralized environment.)
Chen in view of Dubro does not appear to explicitly teach merging two policies into a singular policy to be applied to a cluster but in related art:
configuring an admission controller deployed in a first software container cluster to receive a first policy and a second policy from a unified policy engine, (Banda ¶ 190 teaches, The policy controller selects first and second policies of a plurality of policies enabled for enforcement in a cluster, each of the first and second policies comprising a set of rules and corresponding to a different set of operations performed in the cluster.)
configuring the admission controller to merge the received first policy and the second policy to generate a single policy (Banda ¶ 190 teaches, in response to determining that the first and second policies correspond to differing first and second policy types, the policy controller merges the first and second policies into an aggregate policy to be enforced at a selected hierarchical level.)
thereby, the applied single policy is provided for the first software container cluster (Banda ¶4 teaches, merging the first and second policies into an aggregate policy to be enforced at a selected hierarchical level. ¶ 190 The policy controller selects first and second policies of a plurality of policies enabled for enforcement in a cluster)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen in view of Dubro with Banda, to modify the system for a federated operator for edge computing networks of Chen with the policy orchestrator of Dubro with the merging and application of policies of Banda. The motivation to do so, ¶ 23, can enable not only high availability, load balancing, scaling, and high performance but also provide a policy management tool that creates, updates, and verifies policies using a central policy enforcement point that overcomes challenges due to cloud-based cluster complexity.
Regarding Claim(s) 2 and 14 Chen-Dubro-Banda teaches:
The method of claim 1, further comprising: (Chen-Dubro-Banda teaches the parent claim above.)
the second software container deployed in a second computing environment. (Chen ¶ 2 teaches, The federated operator component is configured to send a second request to provision a second compute resource according to the second compute resource requirement to a second operator component executing on a second container orchestration framework of a second cluster of compute nodes)
configuring an admission controller deployed in a second software container cluster to receive the policy from the unified policy engine, (Dubro ¶ 149 teaches, Operation depicts distributing the access policy to a control plane of a target container orchestrator or a service mesh, wherein the target container orchestrator or the service mesh is configured to apply the access policy. This can be similar to service mesh or control plane.)
The motive given in Claim 1 and 12 is equally applicable to the above claim.
Regarding Claim(s) 3 and 15 Chen-Dubro-Banda teaches:
The method of claim 2, further comprising: (Chen-Dubro-Banda teaches the parent claim above.)
configuring the admission controller deployed in the second software container cluster to apply the received policy to a resource of the second software container. (Dubro ¶ 149 teaches, Operation depicts distributing the access policy to a control plane of a target container orchestrator or a service mesh, wherein the target container orchestrator or the service mesh is configured to apply the access policy. This can be similar to service mesh or control plane.)
The motive given in Claim 1 and 12 is equally applicable to the above claim.
Regarding Claim(s) 6 and 18 Chen-Dubro-Banda teaches:
The method of claim 1, further comprising: (Chen-Dubro-Banda teaches the parent claim above.)
applying the policy to a second resource deployed in the first computing environment. (Chen ¶ 4 teaches, the federated operator component may send a third request to provision a second compute resource for the compute service among the second cluster of computer nodes to a second operator component associated with a second cluster of computer nodes)
The motive given in Claim 1 is equally applicable to the above claim.
Regarding Claim(s) 7 and 19 Chen-Dubro-Banda teaches:
The method of claim 6, (Chen-Dubro-Banda teaches the parent limitation above.) wherein the second resource is any one of: a virtual machine, a software container, a serverless function, a code object in an infrastructure as code declaratory code, and a combination thereof. (Chen ¶ 14 teaches, for example, VM, which may in turn host additional virtual environments (e.g., VMs and/or containers). In an example, a container (e.g., storage container 160, service containers 1 S0A-B).)
Regarding Claim(s) 24 Chen-Dubro-Banda teaches:
The method of claim 1, (Chen-Dubro-Banda in view of Banda teaches the parent claim above.) wherein the single policy is a control-plane policy. (Dubro ¶ 149 teaches, Operation 1106 depicts distributing the access policy to a control plane of a target container orchestrator or a service mesh, wherein the target container orchestrator or the service mesh is configured to apply the access policy. This can be similar to service mesh or control plane.)
The motive given in Claim 1 is equally applicable to the above claim.
Claim(s) 4-5 and 16-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Banda as applied to claim 1 above, and further in view of Beedu (US 2026/0072606 A1), hereinafter Beedu.
Regarding Claim(s) 4 and 16 Chen-Dubro-Banda teaches:
The method of claim 1, (Chen-Dubro-Banda teaches the parent claim above.)
Chen-Dubro-Banda does not appear to explicitly teach generating a resource from a code object but in related art:
wherein the second resource is a second software container cluster generated based on a code object from which the first software container cluster is deployed. (Beedu claim 6 teaches, he source container cluster comprise generating a pod snapshot for the first set of one or more pods and a storage volume snapshot for the storage volume)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen-Dubro-Banda with Beedu, to modify the system for a federated operator for edge computing networks of Chen with the policy orchestrator of Dubro with the merging and application of policies of Banda with the generating of a pod of Beedu The motivation to do so constitutes applying a known technique of generating a pod to known devices and/or methods federated operation in an edge computing network ready for improvement to yield predictable results having similar objects across clusters.
Regarding Claim(s) 5 and 17 Chen-Dubro-Banda-Beedu teaches:
The method of claim 1, wherein the resource is any one of: (Chen-Dubro-Banda teaches the parent claim above.)
a node, a container, a pod, a service, a volume, a namespace, a deployment, a replica controller, a replicaset, a daemonset, a statefulset, a configmap, a job, and any combination thereof. (Beedu claim 6 teaches, he source container cluster comprise generating a pod snapshot for the first set of one or more pods and a storage volume snapshot for the storage volume)
Claim(s) 8-11 and 20-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen-Dubro-Banda as applied to claim 1 above, and further in view of Ikäheimo (US 2022/0158912 A1), hereinafter Ika.
Regarding Claim(s) 8 and 20 Chen-Dubro-Banda teaches:
The method of claim 1, further comprising: (Chen-Dubro-Banda teaches the parent claim above.)
Chen-Dubro-Banda does not appear to explicitly teach intercepting a request and sending it to an Admission controller but in related art:
intercepting a request at a control plane of the first software container cluster; (Ika ¶ 187 teaches, Admission Webhooks are used to intercept Kubernetes API requests and may change the object or validate them before the objects are read by other cluster components. Admission Webhooks are divided into two types, the Mutating Admission Webhook that may change the content of the request object, and the Validating Admission Webhook that either accepts or rejects the content of the request object. ¶ 189 teaches, The consumer of Admission Webhooks are called Admission Controllers. On initialization the Admission Controller registers an URL path with Kubernetes that the Admission Controller will listen for HTTP POST requests at. The POST request will contain the request object (i.e., Kubernetes resource object) that the Admission Controller will either validate or mutate.)
sending the request to the admission controller; and (Ika ¶ 189 teaches, the consumer of Admission Webhooks are called Admission Controllers. On initialization the Admission Controller registers an URL path with Kubernetes that the Admission Controller will listen for HTTP POST requests at. The POST request will contain the request object (i.e., Kubernetes resource object) that the Admission Controller will either validate or mutate.)
configuring the admission controller to apply the policy to the request. (Ika ¶ 189 teaches, The consumer of Admission Webhooks are called Admission Controllers. On initialization the Admission Controller registers an URL path with Kubernetes that the Admission Controller will listen for HTTP POST requests at. The POST request will contain the request object (i.e., Kubernetes resource object) that the Admission Controller will either validate or mutate.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Chen-Dubro-Banda with Ika, to modify the system for a federated operator for edge computing networks of Chen with the policy orchestrator of Dubro with the merging and application of policies of Banda with the admission webhooks of Ika. The motivation to do so Ika ¶ 187, to intercept Kubernetes API requests and may change the object or validate them before the objects are read by other cluster components.
Regarding Claim(s) 9 and 21 Chen-Dubro-Banda-Ika teaches:
The method of claim 8, (Chen-Dubro-Banda-Ika teaches the parent limitation above.) wherein the request is intercepted between a container of the first software container cluster and the control plane by a webhook of the control plane. (Ika ¶ 187 teaches, Admission Webhooks are used to intercept Kubernetes API requests and may change the object or validate them before the objects are read by other cluster components)
The motive given in Claim 8 is equally applicable to the above claim.
Regarding Claim(s) 10 and 22 Chen-Dubro-Banda-Ika teaches:
The method of claim 8, (Chen-Dubro-Banda-Ika teaches the parent limitation above.) wherein the request includes an instruction which when initiated by the control plane, deploys a software container in the first software container cluster. (Ika ¶ 442 teaches, if the Sidecar would have been added to the Pod.sup.K object without an Admission Webhook, the Poe would first have been deployed on a node without the Sidecar container.)
The motive given in Claim 8 is equally applicable to the above claim.
Regarding Claim(s) 11 and 23 Chen-Dubro-Banda-Ika teaches:
The method of claim 1, wherein the admission controller is any one of: (Chen-Dubro-Banda teaches the parent claim above.) a mutating admission controller, a validating admission controller, and a combination thereof. (Ika ¶ 187 teaches, Admission Webhooks are used to intercept Kubernetes API requests and may change the object or validate them before the objects are read by other cluster components. Admission Webhooks are divided into two types, the Mutating Admission Webhook that may change the content of the request object, and the Validating Admission Webhook that either accepts or rejects the content of the request object.)
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 20240272958 A1 - DISTRIBUTED OPERATING SYSTEM IMPLEMENTED WITHIN A COMPUTER CLUSTER
US 20240241944 A1 - SECURITY INTENTS AND TRUST COORDINATION FOR CLOUD NATIVE WORKLOADS
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JACOB BENEDICT KNACKSTEDT whose telephone number is (703)756-5608. The examiner can normally be reached Monday-Friday 8:00 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/J.B.K./Examiner, Art Unit 2408
/LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408