Controller driven reconfiguration of a multi-layered application or service model
Abstract
Some embodiments provide novel inline switches that distribute data messages from source compute nodes (SCNs) to different groups of destination service compute nodes (DSCNs). In some embodiments, the inline switches are deployed in the source compute nodes datapaths (e.g., egress datapath). The inline switches in some embodiments are service switches that (1) receive data messages from the SCNs, (2) identify service nodes in a service-node cluster for processing the data messages based on service policies that the switches implement, and (3) use tunnels to send the received data messages to their identified service nodes. Alternatively, or conjunctively, the inline service switches of some embodiments (1) identify service-nodes cluster for processing the data messages based on service policies that the switches implement, and (2) use tunnels to send the received data messages to the identified service-node clusters. The service-node clusters can perform the same service or can perform different services in some embodiments. This tunnel-based approach for distributing data messages to service nodes/clusters is advantageous for seamlessly implementing in a datacenter a cloud-based XaaS model (where XaaS stands for X as a service, and X stands for anything), in which any number of services are provided by service providers in the cloud.
Claims
exact text as granted — not AI-modified1 - 17 . (canceled)
18 . A method of reconfiguring a multi-layer server deployment model in a datacenter comprising a plurality of host computers executing a plurality of servers, the method comprising:
providing a first set of distribution actions with a flow identifier to the particular host computer, said host computer using the first set of distribution actions and the flow identifier to configure a filter that (i) executes on the host computer, (ii) intercepts data messages sent by a first server executing on the host computer, and (iii) directs intercepted data messages to a first set of servers identified by the first set of distribution actions when the data messages have a set header values that match the flow identifier; receiving a modification to the set of distribution actions; providing a modified second set of distribution actions with the flow identifier to the particular host to reconfigure the filter to distribute data messages that match the flow identifier to a second set of servers instead of the first set of servers.
19 . The method of claim 18 , wherein providing the first and second sets of distribution actions comprises providing first and second distribution rules to the host, each distribution rule comprising the flow identifier as the rule's identifier, the first rule comprising identifiers identifying the first set of servers, while the second rule comprising identifiers identifying the second set of servers.
20 . The method of claim 18 , wherein
the first set of servers is a set of application servers or a set of database servers, the second set of servers is a set of middlebox servers.
21 . The method of claim 18 ,
wherein the flow identifier comprises a virtual IP (Internet) address (VIP), wherein by reconfiguring the filter to perform the modified second set of distribution actions for the same VIP that was used to identify the first set of distribution actions, the first server does not need to be reconfigured to send data messages to different destinations.
22 . The method of claim 18 , wherein
the first set of actions includes the first distribution action, the modified set of distribution actions include first and second distribution actions, the modified set of distribution actions specifying the second distribution action as an initial action and the first action as a subsequent action that has to be performed after receiving a data message reply from a second-set server that performs the second action.
23 . The method of claim 22 , wherein the second set of servers is a set of middlebox servers.
24 . The method of claim 18 , wherein the first server is a virtual machine or container.
25 . The method of claim 18 ,
wherein the flow identifier comprises Layer 3 data message header parameters, wherein by reconfiguring the filter to perform the modified second set of distribution actions for a set of Layer 3 header parameters that was used to identify the first set of distribution actions, the first server does not need to be reconfigured to send data messages to different destinations.
26 . A non-transitory machine readable medium storing a program for reconfiguring a multi-layer server deployment model in a datacenter comprising a plurality of host computers executing a plurality of servers, the program comprising sets of instructions for:
at a host computer,
receiving a first set of distribution actions with a flow identifier;
using the first set of distribution actions and the flow identifier to configure a filter that (i) executes on the host computer, (ii) intercepts data messages sent by a first server executing on the host computer, and (iii) directs intercepted data messages to a first set of servers identified by the first set of distribution actions when the data messages have a set header values that match the flow identifier;
receiving a modified second set of distribution actions associated with the flow identifier;
using the second set of distribution actions and the flow identifier to reconfigure the filter to distribute data messages that match the flow identifier to a second set of servers instead of the first set of servers.
27 . The machine readable medium of claim 26 , wherein the sets of instructions for receiving the first and second sets of distribution actions comprises sets of instructions for receiving first and second distribution rules, each distribution rule comprising the flow identifier as the rule's identifier, the first rule comprising identifiers identifying the first set of servers, while the second rule comprising identifiers identifying the second set of servers.
28 . The machine readable medium of claim 26 , wherein
the first set of actions includes the first distribution action, the modified set of distribution actions include first and second distribution actions, the modified set of distribution actions specifying the second distribution action as an initial action and the first action as a subsequent action that has to be performed after receiving a data message reply from a second-set server that performs the second action.
29 . A non-transitory machine readable medium storing a program for reconfiguring a multi-layer server deployment model in a datacenter comprising a plurality of host computers executing a plurality of servers, the program comprising sets of instructions for:
providing a first set of distribution actions with a flow identifier to the particular host computer, said host computer using the first set of distribution actions and flow identifier to configure a filter that (i) executes on the host computer, (ii) intercepts data messages sent by a first server executing on the host computer, and (iii) directs intercepted data messages to a first set of service nodes identified by the first set of distribution actions when the data messages have a set header values that match the flow identifier; receiving a modification to the set of distribution actions; providing a modified second set of distribution actions with the flow identifier to the particular host to reconfigure the filter to distribute data messages that match the flow identifier to a second set of service nodes instead of the first set of service nodes.
30 . The machine readable medium storing of claim 29 , wherein the sets of instructions for providing the first and second sets of distribution actions comprises sets of instructions for providing first and second distribution rules to the host, each distribution rule comprising the flow identifier as the rule's identifier, the first rule comprising identifiers identifying the first set of service nodes, while the second rule comprising identifiers identifying the second set of service nodes.
31 . The machine readable medium storing of claim 29 , wherein the service nodes in each set of service nodes performs a middlebox service operation.
32 . The machine readable medium storing of claim 29 , wherein the service nodes of the first set performs the same middlebox service operation as the service nodes of the second set, but are in a different location than the service nodes of the second set.
33 . The machine readable medium storing of claim 32 , wherein the first set of service nodes are provided by a first service provider, while the second set of service nodes are provided by a second service provider that is different than the first service provider.
34 . The machine readable medium storing of claim 29 ,
wherein the flow identifier comprises a virtual IP (Internet) address (VIP), wherein by reconfiguring the filter to perform the modified second set of distribution actions for the same VIP that was used to identify the first set of distribution actions, the first server does not need to be reconfigured to send data messages to different destinations.
35 . The machine readable medium storing of claim 29 , wherein
the first set of actions includes a first service action, the modified set of distribution actions include first and second service actions, the modified set of distribution actions specifying the second service action as an initial service action and the first action as a subsequent service action that has to be performed after receiving a data message reply from a second-set server that performs the second service action.
36 . The machine readable medium storing of claim 35 , wherein both first and second sets of actions are middlebox service actions.
37 . A non-transitory machine readable medium storing a program for reconfiguring a multi-layer server deployment model in a datacenter comprising a plurality of host computers executing a plurality of servers, the program comprising sets of instructions for:
at a host computer,
receiving a first set of distribution actions with a flow identifier;
using the first set of distribution actions and the flow identifier to configure a filter that (i) executes on the host computer, (ii) intercepts data messages sent by a first server executing on the host computer, and (iii) directs intercepted data messages to a first set of service nodes identified by the first set of distribution actions when the data messages have a set header values that match the flow identifier;
receiving a modified second set of distribution actions associated with the flow identifier;
using the second set of distribution actions and the flow identifier to reconfigure the filter to distribute data messages that match the flow identifier to a second set of service nodes instead of the first set of service nodes.
38 . The machine readable medium of claim 37 , wherein the sets of instructions for receiving the first and second sets of distribution actions comprises sets of instructions for receiving first and second distribution rules, each distribution rule comprising the flow identifier as the rule's identifier, the first rule comprising identifiers identifying the first set of service nodes, while the second rule comprising identifiers identifying the second set of service nodes.
39 . The machine readable medium of claim 37 , wherein
the first set of actions includes the first distribution action, the modified set of distribution actions include first and second distribution actions, the modified set of distribution actions specifying the second distribution action as an initial action and the first action as a subsequent action that has to be performed after receiving a data message reply from a second-set server that performs the second action.Join the waitlist — get patent alerts
Track US2023052818A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.