System and Method for a Workload Management and Scheduling Module to Manage Access to a Compute Environment According to Local and Non-Local User Identity Information
Abstract
A system, method and computer-readable media for managing a compute environment are disclosed. The method includes importing identity information from an identity manager into a module performs workload management and scheduling for a compute environment and, unless a conflict exists, modifying the behavior of the workload management and scheduling module to incorporate the imported identity information such that access to and use of the compute environment occurs according to the imported identity information. The compute environment may be a cluster or a grid wherein multiple compute environments communicate with multiple identity managers.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for managing access to a compute environment according to local and non-local identity information, the method comprising:
periodically sending, by a management module executing on a processor in a first compute environment to an identity manager shared by the first compute environment and a second compute environment; periodically importing, by the management module, identity information from the identity manager; scheduling, by the management module, a workload that consumes resources in the first compute environment by:
determining, by the management module, a conflict between local identity information and the imported identity information from the identity manager;
resolving the conflict, by the management module, between the imported identity information and local identity information, wherein the resolving a conflict comprises determining a priority between the imported identity information and the local identity information by applying rules that determine whether the identity information or the local configuration information has precedence;
modifying allocation of resources for the workload based on the conflict resolution such that a scheduling decision associated with a resource in the first compute environment is based at least in part on the conflict resolution, wherein in response to the conflict being resolved in favor of the local configuration information, access to and use of the first compute environment are managed according to the local configuration information;
running the workload; and while running the workload, sending, by the management module, to the identity manager, updated identity information, wherein the updated identity information is available to the second compute environment in an event that the workload is transferred to the second compute environment.
22 . The method of claim 21 , wherein resolving the conflict between the identity information and the other information comprises determining in advance which source of information is more authoritative.
23 . The method of claim 21 , wherein the identity information further comprises information associated with at least one of default credential associations and credential specification constraints.
24 . The method of claim 23 , wherein the default credential associations define credentials for users for whom no specified constraints exist.
25 . The method of claim 23 , wherein the credential specification constraints comprise constraints related to at least one of: a service level agreement, priority information, usage limit information, fairshare targets, service guarantees, resource constraints, usage statistics, contact information and billing information.
26 . The method of claim 21 , wherein local configuration information comprises information on arrangement of computers and computer types in the compute environment.
27 . The method of claim 21 , further comprising in response to the conflict being resolved in favor of the local configuration information, managing access to and use of the compute environment according to the local configuration information.
28 . A system for managing access to a compute environment according to local and non-local identity information, the system comprising:
a processor; and a non-transitory computer-readable storage medium storing instructions, which, when executed by the processor, cause the processor to perform operations comprising:
periodically sending, by a management module executing on a processor in a first compute environment to an identity manager shared by the first compute environment and a second compute environment;
periodically importing, by the management module, identity information from the identity manager;
scheduling, by the management module, a workload that consumes resources in the first compute environment by:
determining, by the management module, a conflict between local identity information and the imported identity information from the identity manager;
resolving the conflict, by the management module, between the imported identity information and local identity information, wherein the resolving a conflict comprises determining a priority between the imported identity information and the local identity information by applying rules that determine whether the identity information or the local configuration information has precedence;
modifying allocation of resources for the workload based on the conflict resolution such that a scheduling decision associated with a resource in the first compute environment is based at least in part on the conflict resolution, wherein in response to the conflict being resolved in favor of the local configuration information, access to and use of the first compute environment are managed according to the local configuration information;
running the workload; and while running the workload, sending, by the management module, to the identity manager, updated identity information, wherein the updated identity information is available to the second compute environment in an event that the workload is transferred to the second compute environment.
29 . The system of claim 28 , wherein resolving the conflict between the identity information and the other information comprises determining in advance which source of information is more authoritative.
30 . The system of claim 28 , wherein the identity information further comprises information associated with at least one of default credential associations and credential specification constraints.
31 . The system of claim 30 , wherein the default credential associations define credentials for users for whom no specified constraints exist.
32 . The system of claim 30 , wherein the credential specification constraints comprise constraints related to at least one of: a service level agreement, priority information, usage limit information, fairshare targets, service guarantees, resource constraints, usage statistics, contact information and billing information.
33 . The system of claim 28 , wherein local configuration information comprises information on arrangement of computers and computer types in the compute environment.
34 . The system of claim 28 , further comprising in response to the conflict being resolved in favor of the local configuration information, managing access to and use of the compute environment according to the local configuration information.
35 . A non-transitory computer-readable storage device storing instructions for managing a compute environment, which, when executed by a processor, cause the processor to perform operations comprising:
periodically sending, by a management module executing on a processor in a first compute environment to an identity manager shared by the first compute environment and a second compute environment; periodically importing, by the management module, identity information from the identity manager; scheduling, by the management module, a workload that consumes resources in the first compute environment by:
determining, by the management module, a conflict between local identity information and the imported identity information from the identity manager;
resolving the conflict, by the management module, between the imported identity information and local identity information, wherein the resolving a conflict comprises determining a priority between the imported identity information and the local identity information by applying rules that determine whether the identity information or the local configuration information has precedence;
modifying allocation of resources for the workload based on the conflict resolution such that a scheduling decision associated with a resource in the first compute environment is based at least in part on the conflict resolution, wherein in response to the conflict being resolved in favor of the local configuration information, access to and use of the first compute environment are managed according to the local configuration information;
running the workload; and while running the workload, sending, by the management module, to the identity manager, updated identity information, wherein the updated identity information is available to the second compute environment in an event that the workload is transferred to the second compute environment.
36 . The non-transitory computer-readable storage device of claim 35 , wherein resolving the conflict between the identity information and the other information comprises determining in advance which source of information is more authoritative.
37 . The non-transitory computer-readable storage device of claim 35 , wherein the identity information further comprises information associated with at least one of default credential associations and credential specification constraints.
38 . The non-transitory computer-readable storage device of claim 37 , wherein the default credential associations define credentials for users for whom no specified constraints exist, and wherein the credential specification constraints comprise constraints related to at least one of: a service level agreement, priority information, usage limit information, fairshare targets, service guarantees, resource constraints, usage statistics, contact information and billing information.
39 . The non-transitory computer-readable storage device of claim 35 , wherein local configuration information comprises information on arrangement of computers and computer types in the compute environment.
40 . The non-transitory computer-readable storage device of claim 35 , further comprising in response to the conflict being resolved in favor of the local configuration information, managing access to and use of the compute environment according to the local configuration information.Join the waitlist — get patent alerts
Track US2023222003A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.