Sharing Configuration Resources for Network Devices in an Application
By associating the attributes of the configured resources with application identifiers in the network management system, the network device configuration conflict problem in the multi-tenant and multi-administrator environment is solved, resource sharing and management are realized, and the stability and utilization of network devices are improved.
Patent Information
- Application Number
- CN202211145505.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-09-21
- Filing Date
- 2022-09-20
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-09-20
AI Technical Summary
In a multi-tenant and multi-administrator environment, there are conflicts and inconsistencies in the configuration resource management of network devices, resulting in network instability.
The properties of the configuration resource are associated with the application identifier through the network management system, and configuration requests are stored and managed using the associated data structure, ensuring that each attribute/value pair is associated with one or more applications, and subsequent configuration requests are processed to reduce conflicts.
It realizes the sharing and management of configuration resources, reduces conflicts between network equipment and systems, improves utilization rate and user experience, and ensures the stability and consistency of network equipment.
Smart Images

Figure CN115842726B_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims the benefit of U.S. Patent Application No. 17 / 448,339, filed on September 21, 2021, the entire content of which is incorporated herein by reference. Technical Field
[0003] This disclosure relates to computer networks, and more particularly, to the management of network devices. Background Art
[0004] A computer network is a collection of interconnected computing devices that can exchange data and share resources. A variety of devices operate to facilitate communication between computing devices. For example, a computer network can include routers, switches, gateways, firewalls, and various other network devices that provide and facilitate network communication.
[0005] These network devices typically include mechanisms for locally or remotely configuring the device, such as a management interface. Through interaction with the management interface, a client can perform configuration tasks, as well as execute operational commands to collect and view configuration data and operational data of the managed device. For example, a client can configure an interface card of the device, adjust parameters of supported network protocols, specify physical components within the device, modify routing information maintained by a router, access software modules and other resources resident on the device, and perform other configuration tasks. In addition, the client can allow a user to view current configuration data and operational parameters, system logs, information related to network connections, network activities, or other status information from the device, and view and react to event information received from the device.
[0006] Network services can be performed by multiple different devices, such as routers with service cards and / or dedicated service devices. Such services include connectivity services, such as Layer 3 Virtual Private Network (L3VPN), Virtual Private LAN Service (VPLS), and Point - to - Point (P2P) services. Other services include network configuration services, such as Dot1q VLAN service. A Network Management System (NMS) and NMS devices (also referred to as controllers or control devices) can support these services so that an administrator can easily create and manage these advanced network configuration services. Summary of the Invention
[0007] Generally speaking, techniques for sharing configuration resources for a network device by associating (e.g., "tagging") attributes of the configuration resources with application identifiers of applications seeking to modify the configuration of the network device are described. For example, a network management system may store data defining the configuration resources, which model resources on the network device that are managed by the network management system. The configuration resources may be created, updated, and deleted using an interface to the network management system. Modifying the configuration resources in any of these ways triggers corresponding modifications by the network management system to the corresponding resources on the network device to change the operation of the network device. For example, deleting a configuration resource for a routing policy for a network device causes the network management system to delete the configuration data (i.e., the resource) for that routing policy from the network device.
[0008] The network management system may receive configuration requests from multiple different applications that relate to the same resources of the same network device. The network management system may enable these applications to share the configuration resources for the resources on the network device by each of the multiple applications modifying the configuration resources and, more specifically, modifying the attributes of the configuration resources and the corresponding attribute values (hereinafter simply referred to as "attribute / value pairs"). To reduce conflicts in applications that have different configuration intents for the corresponding resources of the network device, the network management system associates each attribute / value pair with the application identifier(s) of one or more applications that used the network management system to create or modify the attribute / value pair. The network management system may use this association to process subsequent configuration requests for the configuration resources.
[0009] These techniques may provide one or more technical advantages that can enable at least one practical application. For example, these techniques can improve network device and network management system utilization and the user experience in a multi-tenant and / or multi-administrator context by facilitating sharing while reducing conflicts. Without these techniques, such conflicts may lead to inconsistent configurations of the network device and network instability. As another related example, these techniques can reduce and in some cases eliminate conflicts in multiple applications that are using the network management system to configure resources of the network device. By associating each attribute / value pair that has been set for a configuration resource with one or more applications, the network management system can (1) allow multiple applications to configure different attribute / value pairs for the same configuration resource and can also (2) allow multiple applications to configure the same attribute / value pairs for the same configuration resource, as long as the requested values do not conflict. Additionally, these techniques can allow different applications to start and stop using the configuration resources at different times.
[0010] In an example, a network management system includes: a control unit including processing circuitry coupled to a memory, wherein the control unit is configured to: receive a configuration request including first configuration data for a network device, the first configuration data defining a data structure including first attribute / value pairs; generate corresponding first path / value pairs for the first attribute / value pairs from the first configuration data, wherein the paths in the first path / value pairs uniquely identify the first path / value pairs in an associated data structure; modify the associated data structure based on the first path / value pairs; generate a configuration resource including second configuration data for the network device from the associated data structure, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs; and send the second configuration data to the network device to modify the configuration of the network device.
[0011] In an example, a method includes: receiving, by a network management system, a configuration request including first configuration data for a network device, the first configuration data defining a data structure including first attribute / value pairs; generating, by the network management system, corresponding first path / value pairs for the first attribute / value pairs from the first configuration data, wherein the paths in the first path / value pairs uniquely identify the first path / value pairs in an associated data structure; modifying, by the network management system, the associated data structure based on the first path / value pairs; generating, by the network management system, a configuration resource including second configuration data for the network device from the associated data structure, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs; and sending, by the network management system, the second configuration data to the network device to modify the configuration of the network device.
[0012] In an example, a non-transitory computer-readable medium includes instructions for causing processing circuitry of a network management system to perform operations including: receiving a configuration request including first configuration data for a network device, the first configuration data defining a data structure including first attribute / value pairs; generating corresponding first path / value pairs for the first attribute / value pairs from the first configuration data, wherein the paths in the first path / value pairs uniquely identify the first path / value pairs in an associated data structure; modifying the associated data structure based on the first path / value pairs; generating a configuration resource including second configuration data for the network device from the associated data structure, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs; and sending the second configuration data to the network device to modify the configuration of the network device.
[0013] Details of one or more examples will be set forth in the accompanying drawings and the following description. Other features, objects, and advantages will be apparent from the description, the drawings, and from the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1is a block diagram illustrating an example of network devices including a network managed by a network management system according to one or more techniques of the present disclosure.
[0015] Figure 2 is a block diagram illustrating an example network management system and network devices according to the techniques of the present disclosure.
[0016] Figure 3 depicts configuration data in various representations according to the techniques of the present disclosure.
[0017] Figure 4 is a conceptual diagram illustrating an example data structure for managing configuration resources according to the techniques of the present disclosure.
[0018] Figure 5 is a flowchart illustrating an example process performed by a network management system to process a configuration request according to the techniques of the present disclosure.
[0019] Figure 6 is a flowchart illustrating an example process performed by a network management system to process a configuration request according to the techniques of the present disclosure.
[0020] Figure 7 is a flowchart illustrating an example operation of a network management system according to the techniques of the present disclosure.
[0021] Like reference numerals represent like elements throughout the drawings and the text. DETAILED DESCRIPTION
[0022] Figure 1 is a block diagram illustrating an example of network devices including network 2 managed by network management system 10 according to one or more techniques of the present disclosure. The network devices 14A - 14G of network 2 (collectively referred to as "network devices 14") include network devices interconnected via communication links to form a communication topology to exchange packetized data. The network devices 14 (also referred to herein as "elements" or "managed network devices") can include, for example, routers, switches, gateways, bridges, hubs, edge devices, software-defined network - wide area network (SD-WAN) devices, firewalls or other intrusion detection systems (IDS) or intrusion prevention systems (IDP), other network devices, or combinations of such network devices. The communication links interconnecting the network devices 14 can be physical links (e.g., optical fibers, copper wires, etc.), wireless, or any combination thereof.
[0023] Network 2 is shown as being connected to a public network 18 (e.g., the Internet) via a communication link 16. The public network 18 can include, for example, one or more client computing devices. The public network 18 can provide access to web servers, application servers, public databases, media servers, end-user devices, and other types of network resource devices and content. Although the network 2 is described herein mainly with respect to an enterprise network, the techniques of the present disclosure are also applicable to other public or private networks, such as Internet service provider (ISP) or network service provider (NSP) networks, cloud service provider networks, and so on. The network 2 can also be referred to herein as a "managed network" in that it is at least partially managed by applications 11A - 11N (collectively referred to as "applications 11") using a network management system 10.
[0024] The network management system 10 can be a network appliance, one or more applications executing on one or more physical or virtual servers, or a combination thereof. In various examples, the network management system 10 can be deployed within the network 2, at a management site of the network 2, at a branch office, within a public or private cloud, or some combination thereof. The network management system 10 can be vendor-specific, i.e., specifically developed to manage some or all of the network devices 14 that have been manufactured by a particular vendor. However, the network management system 10 can be non-vendor-specific and capable of, for example, using standardized device management protocols to configure devices from multiple different vendors. The network management system 10 can include or represent an element management system (EMS) or a device management system (DMS).
[0025] The network management system 10 communicates via a network that optionally includes the network 2 to manage the network devices 14. The network management system 10 can establish corresponding persistent or non-persistent communication sessions with one or more of the network devices 14 for configuration and monitoring. Once the network devices 14 are deployed and activated, an administrator (not shown) and / or the applications 11 can interface with the network management system 10 to manage the network devices 14 via the network management system 10. That is, the applications 11 use the network management system 10 rather than directly interfacing with the network devices 14 using, for example, a network device command line interface (CLI) or a device management protocol executed by the applications 11. This allows an operator to centrally control and monitor the network devices 14 within the network management system 10. Additionally, the network management system 10 can provide a high-level service that translates the high-level intents of the applications 11 and the operator into low-level network device configurations.
[0026] Each application 11 represents an execution instance of one or more applications. Each application 11 can be executed by a physical or virtual server or by an appliance. Each application 11 can be deployed at a management site of network 2, at a branch office, within a public or private cloud, or within some combination thereof. Application 11 can include an orchestration platform such as Openstack, Kubernetes, or other orchestration platforms; a network controller or software-defined network (SDN) controller; a network director or network provisioning platform; a network service provisioning platform; an operations / business support system (OSS / BSS); another network management system other than NMS 10; or any other application or system that can invoke NMS 10 to configure any network device 14.
[0027] To manage network 2 including network devices 14, application 11 can interface with network management system 10 to remotely monitor and configure network devices 14. For example, application 11 can receive an alert from network management system 10 regarding any of network devices 14, view the configuration data of network devices 14, modify the configuration data of network devices 14, add a new network device to network 2, remove an existing network device from network 2, or otherwise manipulate network 2 and the network devices therein.
[0028] Any one of applications 11 can send a configuration request to network management system 10, e.g., configuration requests 17A - 17N, to cause network management system 10 to configure network devices 14 to specify certain operational characteristics that advance the goals of the application. For example, application 11A can specify a particular operational policy for network device 14A regarding security, device accessibility, traffic engineering, quality of service (QoS), network address translation (NAT), packet filtering, packet forwarding, rate limiting, or other policies. If necessary, network management system 10 converts the operational policy included in the configuration request into configuration data for network device 14A. Network management system 10 uses one or more device management protocols designed to manage configuration data within managed network devices 14, such as the Simple Network Management Protocol (SNMP) protocol, the Network Configuration Protocol (NETCONF) protocol, the General Remote Procedure Call (gRPC) Network Management Interface (gNMI), or similar interfaces / protocols, to perform the configuration. Generally, NETCONF provides a mechanism for configuring network devices and can use an XML-based data encoding for configuration data.
[0029] In some examples, network management system 10 includes a management interface. The management interface of network management system 10 can be configured to accept high-level configuration data or a configuration request in the form of an intent from application 11 (the high-level configuration data or intent can be expressed as structured input parameters, for example, according to the Yet Another Next Generation (YANG) language, which is described in Bjorklund's "YANG - A Data Modeling Language for the Network Configuration Protocol (NETCONF)", Internet Engineering Task Force, RFC6020, October 2010, available at tools.ietf.org / html / rfc6020, which is incorporated herein by reference in its entirety). The management interface of network management system 10 can also be configured to output corresponding low-level device configuration data sets, such as device configuration additions, modifications, and removals.
[0030] In some examples, network management system 10 can use YANG modeling for the intent data model and the low-level device configuration model. The data can include relationships across YANG entities, such as list items and containers. In some examples, network management system 10 can transform the YANG data model into a database model and transform YANG validation into data validation. Network management system 10 can receive data from application 11 representing any one or all of the create, update, and / or delete actions with respect to the intent data model.
[0031] According to the techniques of this disclosure, the network management system 10 includes configuration resources 60 for network devices 14. Each configuration resource 60 is defined by data stored by or otherwise accessible to the NMS 10. Each configuration resource 60 models a resource on one of the network devices 14. As used herein, a resource of a network device is an instance of a data structure that, when configured with appropriate structure, attributes, and values and stored on the network device, affects at least one operation of the network device. A resource is configuration data for a network device. A resource can correspond directly to a hardware resource, such as a hardware interface, or can more broadly affect the operation of the network device by configuring services, policies, or other functionality of the network device. Example resources of the network device 14 include interfaces, sub-interfaces, network instances (such as SD-WAN or virtual private networks), routing instances, zones, routing policies, firewall policies, routing and other protocols, classes of service, billing, chassis, security, system resources, and others. These various types of resources for the network device 14 can correspond to different types of configuration resources 60 that model such resources of the network device 14 within the network management system 10. The network management system 10 may store configuration resources 60 for a plurality of network devices 14 .
[0032] Any of the applications 11 can send configuration requests to the NMS 10 to create, update, or delete configuration resources 60. Modifications to configuration resources in any of the above manners trigger corresponding modifications to resources on network devices by the network management system 10 to modify the operation of the network devices. For example, deleting one of the configuration resources 60 corresponding to a routing policy for network device 14A causes the network management system 10 to delete the configuration data for the routing policy from network device 14A (i.e., delete the resource), and network device 14A will no longer operate according to the deleted routing policy.
[0033] The network management system 10 may receive multiple configuration requests from different applications 11 that relate to the same resource of any of the network devices 14. For example, application 11A and application 11N may send respective configuration requests 17A, 17N to the network management system 10 in an attempt to configure a configuration resource corresponding to a particular resource of the network device 14A, such as a resource that configures an interface or routing policy of the network device.
[0034] The network management system 10 can arbitrate configuration access to the configuration resources 60 among multiple applications 11. For example, the network management system 10 can share any of the configuration resources 60 by allowing multiple applications 11 to edit the configuration resources for network devices, and more specifically, to edit the attributes and corresponding attribute values (hereinafter simply referred to as "attribute / value pairs") of the configuration resources. To reduce conflicts among applications 11 that have different configuration intents for the corresponding resources of network devices, the network management system 10 associates each attribute / value pair with one or more applications 11 that interface with the network management system 10 to create, update, or delete the attribute / value pair. The network management system 10 can use this association to process subsequent configuration requests for a specified configuration resource received from any of the applications 11. As described above, creating, updating, or deleting the attribute / value pairs of the configuration resources causes the NMS 10 to interface with an appropriate one of the network devices 14 to create, update, or delete the corresponding resources, thereby reconfiguring the network devices.
[0035] In Figure 1 an example, to associate the path / value pairs of the configuration resources with applications, the network management system 10 can store association data 61. The association data 61 can include an association data structure having one or more entries, such as a table, a list, a dictionary, or a map. Each entry can associate a unique path / value pair of one of the configuration resources 60 with one or more application identifiers of the corresponding applications 11 that have sent a configuration request to the NMS 10 to configure the corresponding attribute / value pair in the configuration resource. The application identifiers can be referred to as "tags" because the application identifiers can be used to effectively tag the path / value pairs with the corresponding one of the application identifiers in the applications 11 in the association data 61.
[0036] These techniques can provide one or more technical advantages that can enable at least one practical application. For example, these techniques can improve the utilization of the network devices 14 and the network management system 10 and the user experience in a multi-tenant and / or multi-administrator context by facilitating sharing while reducing conflicts, which may lead to inconsistent configurations of the network devices 14 and instability of the network 2. As another related example, these techniques can reduce and in some cases eliminate conflicts among multiple applications 11 that are using the resources of the network management system 10 to configure any of the network devices 14. By associating each attribute / value pair that has been set for a configuration resource with one or more applications 11, the network management system 10 can (1) allow multiple applications 11 to configure different attribute / value pairs for the same one of the configuration resources 60, and can also (2) allow multiple applications 11 to configure the same attribute / value pair for the same configuration resource, as long as the requested values do not conflict. In addition, these techniques can allow different applications 11 to start and stop using any of the configuration resources at different times.
[0037] Figure 2 FIG. is a block diagram illustrating an example network management system and network devices according to the present disclosure. The network management system 22 uses a management protocol (such as NETCONF) to manage the network device 24 for exchanging management protocol messages over a communication link. Although described with respect to one particular protocol (e.g., NETCONF) for managing network devices, the techniques of the present disclosure can be applied to any network management protocol that provides a mechanism for creating, updating, and deleting configuration data of network devices.
[0038] The network management system 22 can be Figure 1 an example of the network management system 10, and the managed network device 24 can be Figure 1 any one of the network devices 14. In the Figure 2 example illustrated in FIG., the network management system 22 includes a control unit 26, and the network device 24 includes a configuration interface 44 and a control unit 38. Each of the network management system 22 and the network device 24 may also include a network interface card (not shown).
[0039] Each of the control unit 26 and the control unit 38 may include processing circuitry that executes software instructions, such as software instructions for defining software or a computer program, software instructions stored in a computer-readable storage medium (such as a storage device (e.g., a disk drive or an optical disk drive) or a memory (such as flash memory, random access memory or RAM) or any other type of volatile or non-volatile memory) that stores instructions that cause the processing circuitry to perform the techniques described herein. Alternatively or additionally, the control unit 26 and / or the control unit 38 may include dedicated hardware for performing the techniques described herein, such as one or more integrated circuits, one or more application-specific integrated circuits (ASICs), one or more application-specific special processors (ASSPs), one or more field-programmable gate arrays (FPGAs), or any combination of one or more of the foregoing examples of dedicated hardware.
[0040] The control unit 26 provides an operating environment for the interface 30, the service layer 29, and the device management layer 31. Generally, the service layer 29 may be responsible for generating requests according to the service model 55 and passing the requests to the management module 28 within the device management layer 31. In addition, the device management layer 31 may be responsible for constructing configuration change requests according to the device model 57. As shown, the service layer 29 includes the service model 55. The device management layer 31 includes the management module 28 and the configuration data (CONFIG.DATA) 32.
[0041] Interface 30 may be provided by an API server 59 executed by the control unit 26. Interface 30 may be a Representational State Transfer (REST) interface that allows an application to issue a configuration request as a Remote Procedure Call (RPC). Interface 30 may be configured to receive configuration data in the configuration request in a format such as, for example, Extensible Markup Language (XML), JSON, or plain text.
[0042] The service model 55 may include an application-level model (e.g., yet another Next Generation model or simply a "YANG model") that can be used to model configuration and state data manipulated by NETCONF, NETCONF Remote Procedure Calls, and NETCONF notifications. For example, the service model 55 may receive, via interface 30, an application-level configuration for the network device 24 in a configuration request from an application. In this example, the application-level configuration may be according to the YANG model. The service model 55 may convert the application-level configuration from the YANG model into a configuration change to the device model 57.
[0043] In some examples, the management module 28 may receive, via interface 30, a configuration request 17 from the application 11 that includes a desired configuration of resources for the network device 24. The desired configuration may be in the form of object notation, such as JavaScript Object Notation (JSON). The application 11 may be modified to use interface 30.
[0044] The configuration request may also indicate an application identifier of the application that issued the configuration request. The application identifier may be a unique identifier (e.g., UUID), an application name, or other identifier.
[0045] The management module 28 represents an exemplary instance of a management application, or more generally, a network management application. The management module 28 is an example of a network management module. In one example, the management module 28 provides mechanisms for installing, manipulating, and deleting configurations of network devices in the network device 24. The device model 57 may include a low-level or device-level data model (e.g., OpenConfig) that can be used to model configuration change requests. The configuration module 34 may be configured to send and / or submit configuration data to the network device 24.
[0046] The network device 24 can be any device having one or more processors and a memory and capable of executing one or more software processes, which includes a configuration engine 40 that operates according to a network management protocol (such as NETCONF). The network device 24 stores the "operational" or "running" configuration for the network device in the configuration data (CONFIG.DATA) 42. That is, the configuration data 42 determines the operation of the network device 24 regarding, for example, packet forwarding and other services provided by the network device 24. The control unit 38 of the network device 24 provides the operating environment for the configuration engine 40 as well as the configuration data 42. The configuration data 42 can be stored in a data repository and can each store data in the form of one or more tables, databases, linked lists, radix trees, or other suitable data structures. The configuration data 42 can be local or remote to the network device 24.
[0047] The application issues a configuration request to the interface 30 to direct the management module 28 to manage the network device 24 in a specified manner, for example, to modify the configuration of the device 24. According to the techniques of the present disclosure, the configuration request can indicate configuration resources in order to create, update, or delete one or more corresponding configuration resources 65. The configuration request can invoke an API method and / or an endpoint of the interface 30. The configuration request can specify a particular network device, such as the network device 14B, to be configured according to the type of configuration operation (e.g., create, update, or delete) and any configuration data included.
[0048] For example, the application can issue a configuration request that causes the NMS 22 to modify a configuration resource 65 including a portion of the configuration data 32 and ultimately causes the NMS 22 to deploy the modified configuration data 32 to the configuration data 42 as the running configuration of the network device 24 via the configuration interface 44 and the configuration engine 40. Each configuration resource 65 can be associated with a particular network device to be configured with the corresponding resource, such as the network device 24 to be configured with a resource 63. The configuration engine 40 can, for example, ensure the consistency of the configuration data 42, process configuration submissions, and other operations regarding the configuration data 42. The configuration data 42 includes the resource 63. The term "resource" is defined above.
[0049] The configuration interface 44 can be provided by an API server executed by the control unit 38. The configuration interface 44 can be a REST interface that allows the network management system 22 to send configuration data to the network device 24 in, for example, XML, JSON, or plain text format. The configuration interface 44 can execute one or more network management protocols, such as NETCONF or SNMP, to receive configuration data including resources from the network management system 22. The configuration engine 40 can submit the received configuration data including resources to the configuration data 42.
[0050] According to the technology of the present disclosure, the network management system 22 stores, creates, updates, and deletes configuration resources 65 for corresponding resources 63 of the network device 24. The configuration resources 65 can be Figure 1 example instances of the configuration resources 60 of
[0051] The management module 28 processes configuration requests received at the interface 30 and issued by multiple different applications. Figure 5 is a flowchart illustrating an example process 500 performed by a network management system according to the technology of the present disclosure to process configuration requests. Regarding Figure 2 the NMS 22 of
[0052] describes the process 500 of configuring the network device 24, but the process 500 can be performed by other NMSs or other systems (e.g., EMS, DMS) to configure other examples of the network devices described herein. Figure 3 Each configuration request indicates the configuration data of the configuration resources in the configuration resources 65 and includes an indication of the application that issued the configuration request. The indication can be the application identifier of the application. In response to receiving the configuration request, which includes an indication of the configuration data of the configuration resources of the network device 24 and also includes the application identifier of the application that issued the configuration request (502), the management module 28 processes the configuration request to obtain the configuration data of the configuration resources (504). In some cases, the configuration data of the configuration resources is included in the configuration request as JSON, XML, or other structured configuration data. In some cases, the configuration data of the configuration resources must be generated from the indication in the configuration request. An example of the configuration data of the configuration resources is shown as the configuration data of the configuration resource 302 in
[0053] Examples of data that can be included in the configuration request are as follows and include configuration data (“ConfigurationData”), application identifier (“Application-ID”), device identifier (“Device-ID”), and a prefix (“Prefix”) for identifying a specific resource of the device identified by the device identifier:
[0054] In the above example, "Prefix" can be considered as the resource name or resource ID that uniquely identifies a resource within the context of a device. If no prefix is specified, "ConfigurationData" should contain the complete configuration starting from the root of the configuration hierarchy. Another example of data that can be included in a configuration request is as follows and does not include the value of "Prefix":
[0055]
[0056]
[0057] The property / value pairs of the configuration data can be arranged according to the hierarchy. For example, the configuration data can include a syntax that defines one or more property / value pairs of a configuration resource. This syntax can construct property / value pairs within a hierarchical data structure (such as a tree, a group of containers, another data structure, or a combination thereof). In an example of the configuration data of the configuration resource 302, for example, the configuration data of this interface configuration resource includes a list of containers defined by curly braces: the "config" container that defines three property / value pairs (the properties "description", "mtu", and "name"), and the "gratuitous-arp" container that itself includes a different "config" container with one property / value pair (the property "reply"). Therefore, this configuration data conforms to a tree structure with a hierarchical path.
[0058] The management module 28 generates path / value pairs (506) from the property / value pairs in the configuration data obtained from the configuration request. For example, having obtained the configuration data of a configuration resource, the management module 28 "flattens" the configuration data such that each property / value pair has a separate path / value pair, and the path is generated partially from the structure of the configuration data. In Figure 3 the example, the configuration data of the configuration resource 302 is flattened as shown by the path / value pairs of the associated data in Table 300 of the configuration resource 302, specifically the Path column and the Value column. Table 300 can represent the associated data 61 or be included in the associated data 61. In some cases, the Tags column will not be part of the table and will be stored separately using a tagging function, which can be implemented as a separate library or module, or can also be implemented as part of the API server. In some cases, the corresponding configuration resource will have a "Prefix" associated with it to shorten the length of the path that needs to be stored in Table 300 (or other forms of associated data 61). This prefix will uniquely identify the configuration resource for this device.
[0059] The management module 28 can use various path encoding conventions for generating the paths of path / value pairs. For example, the management module 28 can use gNMI path encoding to transform structured configuration data (e.g., XML or JSON) into structured paths. Again, referring to the configuration data of the configuration resource 302 as an example, the management module 28 can generate paths by obtaining the prefix strings ("prefixes") of each attribute / value pair and applying path encoding to traverse the structure. The "config" container (or node) becomes the prefix for all attributes within that container. The names of these attributes are appended to the prefix. Thus, the attribute "name" in the "config" container has a partial path of "config / name" and a value of "ge-0 / 0 / 1". A high-level prefix can be pre-appended to each path in the path / value pair. This prefix can be based on the identifier of the configuration resource to uniquely identify each path / value record within a set of path / value records for any configuration resource 65 stored for the network device 24 (and other network devices in some instances). In the path / value pairs of the associated data in Table 300, the prefix is "Interfaces / interface[name=ge / 0 / 0 / 1]". (This prefix has been separated from the Path column for readability). The configuration resource being configured is of the interface type, and the interface has a unique name among configuration resources of the interface type. Thus, the full paths of the attributes "config / name" and "gratuitous-arp / config / reply" are "Interfaces / interface[name=ge / 0 / 0 / 1] / config / name" and "Interfaces / interface[name=ge / 0 / 0 / 1] / gratuitous-arp / config / reply", respectively. Similar conventions can be applied to other resource types. Any even higher-level prefix of the path can be the device identifier of the network device 24 for the corresponding resource 63 having the configuration resource 65. The management module 28 can use other schemes for ensuring uniqueness among the paths of each attribute of the configuration resource 63.
[0060] Thus, the configuration request can also include an optional "prefix" that will uniquely identify the resource within the configuration data model of a particular device. The configuration request can include a prefix; however, the prefix can also be calculated as described above.
[0061] In some examples, the prefix is a gNMI path that will uniquely identify the resource within the configuration data model. The configuration data model can be any hierarchical data model representing the device configuration. For example, using the OpenConfig data model to represent the device configuration, the following prefixes can uniquely identify resources within the configuration hierarchy:
[0062] ·interfaces / interface[name=ge-0 / 0 / 0] —— This will identify an instance of the interface configuration resource named "ge-0 / 0 / 0", as well as any other interface configurations that fall within the / root / interfaces / interface hierarchy.
[0063] ·network-instances / network-instance[name=sdwan] —— This will uniquely identify the network instance named "sdwan".
[0064] The following example configuration data model has been annotated with square brackets to indicate the optional prefix positions in the model for identifying configuration resources. If the configuration resource at that position in the configuration data model is a collection, the square brackets can include a comma-separated list of <key,value> pairs. The key will be the name of the key element of the collection, and the value will be its value. If the collection has a composite key, there can be multiple <key,value> pairs.
[0065]
[0066]
[0067] The full path can be used as a unique key within the associated data 61 that qualifies the associated data structure, which can be a table, dictionary, list, map, or other associated data structure in a relational or other database. For purposes of description, the associated data structure will be described as a table in the relational database 43. The table has rows that include path / value pairs. Table 300 includes four attribute / value pairs of the configuration data of the configuration resource 302 in four rows.
[0068] The database 43 can be a relational database, a NoSQL database, a cloud database, a columnar database, an object-oriented database, a key-value database, other databases, or a combination of the above. The database 43 can be cloud-based, off-system, or otherwise remotely accessible by the NMS 22, or the database 43 can be stored in a storage device such as the control unit 26.
[0069] The management module 28 can iterate (or otherwise process) each of the generated (flattened) path / value pairs of the configuration data of the configuration resource by comparing each of them with the path / value pairs stored in the associated data 61. If there are additional path / value pairs to process (the "yes" branch of 508), the management module uses the path in the additional path / value pair as a lookup key to query the associated data 61 (510). If an entry for the path does not exist (the "no" branch of 512), the path / value pair represents a new attribute / value pair of the configuration resource, and the management module 28 adds the path / value pair associated with the application identifier to the associated data 61 (514).
[0070] If an entry for the path already exists (the "yes" branch of 512), the management module 28 determines whether the value in the entry matches the value in the path / value pair being processed (516). If so (the "yes" branch of 516), there is no conflict for the corresponding attribute / value that may have been added by another application, and the management module 28 adds the association of the application identifier to the path / value pair in the existing entry (518). The path / value pair in the existing entry can be associated with multiple different application identifiers. As a result of the process 500 performed on multiple configuration requests issued by multiple different applications, the associated data 61 stores the unique path / value pairs of the configuration resource 65 in a structure that facilitates fast key lookup for unique paths for comparison with new paths generated from incoming configuration requests.
[0071] In some cases, when the value of the path / value pair is not a scalar but an array or list of elements, the management module 28 can add, update, or delete the value. In such cases, the management module 28 generates separate path / value pairs for each element in the list of elements associated with the application identifier. For example, for a configuration resource of the AsPathSet type with an as-path-set having two elements or "members", the management module 28 can generate the following (for ease of description, a prefix is shown) in the associated data 61:
[0072] Prefix: / routing-policy / defined-sets / bgp-defined-sets / as-path-sets / as-path-set
[0073] Paths:
[0074] ·config / as-path-set-member[0] = 1234
[0075] ·config / as-path-set-member[1] = 4321
[0076] Each path may also have one or more associated application identifiers (and / or default identifiers) of any application for which corresponding elements have been configured. The management module 28 may add any new elements to the end of the list. If any application is using any of the elements, the corresponding path / value entry is associated with the application identifier of that application. If no application is using a particular index from the list of elements (e.g., after deletion), the management module 28 may delete the corresponding path / value pair from the associated data 61. However, the management module 28 may not update the index value:
[0077] · config / as-path-set-member[0] = 1234
[0078] · / / deleted
[0079] · config / as-path-set-member[2] = 4321
[0080] In addition, the list should not contain any duplicate items - an application may use a subset of the elements from the list. The management module 28 may use a list prefix (e.g., 'config / as-path-set-member%') to query the associated data 61, and all list items will be retrieved from the associated data. The management module 28 may update the association information based on scalar values passed by the application in the configuration request and match them to the rows of the retrieved path / value pairs. If necessary, the management module 28 may create new path / value pairs and will include the next highest index. The above techniques may enable the ownership / sharing of independent values in a leaf list as well as the ownership / sharing of values in an object list. The following is an example of storing an object list (e.g., sub-interfaces belonging to an interface) by flattening in an associated data structure. Here [index = 0] and [index = 1] are key-value pairs that uniquely identify the sub-interface instances.
[0081] Prefix: Interfaces / Interface[name = ge-0 / 0 / 1]
[0082]
[0083]
[0084] The corresponding configuration data in the configuration request may be as follows:
[0085]
[0086]
[0087] If the value in the entry does not match the value in the path / value pair being processed (the "No" branch of 516), then updating the value to the value in the configuration request will overwrite the existing configuration of the corresponding resource configured by another application, which may have precedence for that resource, at least by virtue of having configured the resource earlier. To avoid disturbing the expectations of another application regarding the network device 24 due to inadvertently updating configuration parameters used by another application, the management module 28 may, in response to the configuration request received at 502, return an error message via the interface 30 to notify the originating application of the configuration request failure (520). In some cases, the management module 28 may roll back any earlier changes made to the associated data 61 (e.g., at steps 514, 518) so that the configuration request will have no effect on the configured resource 65 or the resource 63. Returning an error will end the iteration through the path / value pairs. In some cases, if the values are different (the "No" branch of 516), but the path / value of the existing entry is associated only with the default identifier and not with any other application identifier, then the management module 28 may update the value of the existing entry to the new value and may delete the default identifier while adding the application identifier, rather than sending an error. This reflects an update to the factory default configuration for the network device 24 and does not disturb the expectations of another application. The default identifier will be described in more detail below.
[0088] At 508, the management module 28 iterates through the path / value pairs until there are no additional path / value pairs remaining (the "No" branch of 508). At this stage, the relevant path / value pairs in the associated data 61 have been created or updated, and the management module 28 therefore updates the corresponding configured resources in the configured resource 65 to reflect the updated path / value pairs (522). For example, the management module 28 may obtain all the path / value pairs of the configured resource and "unflatten" them to generate the configuration data of the configured resource. This can effectively reverse the scenario described in step 506 and is illustrated in Figure 3 whereby the management module 28 processes the path and value columns of the entries of the associated data of the configured resource read from the table 300 to generate the configured resource 302. This includes configuration data for non-scalar values (e.g., a list of elements having their own path / value pairs in the associated data 61). In some cases, the management module 28 may generate the configured resource by creating and / or updating the property / value pairs of the existing configured resource based only on the new and / or updated path / value pairs, rather than completely regenerating the configured resource.
[0089] The configuration resources generated in step 522 include the cumulative configuration data created by all the applications that have issued configuration requests for the configuration resources. The management module 28 sends the configuration data of the configuration resources to the network device 22 to modify the configuration data 42 for the device, and more specifically, the corresponding resources (524) of the resource 63.
[0090] For example, the management module 28 can generate the configuration data of the configuration resources in a structured form. In this case, if the configuration interface 44 assumes a format (e.g., using OpenConfig to support JSON, or supporting XML, etc.), the management module 28 can simply send the configuration data as it is to the configuration interface 44. In some cases, the management module 28 can convert the configuration data into a vendor-specific format that meets the vendor's specific requirements for the configuration data and requests / commands sent to the configuration interface 44.
[0091] Figure 4 is a conceptual diagram illustrating an example data structure for managing configuration resources according to the technology of the present disclosure. For example, the configuration resource 401 can represent any one of the configuration resources 65 of the NMS 22. The configuration resource 401 is for configuring the corresponding resources on the network device.
[0092] The configuration resource 401 can include a device identifier 403 for identifying the network device that will be configured using the configuration resource 401. The configuration resource 401 includes one or more attribute / value pairs 402A - 402N (collectively referred to as "attribute / value pairs 402"). Each of the attribute / value pairs 402 is configuration data that identifies an attribute of the resource and specifies a value for the attribute of the resource. The configuration resource 401 can be structured data that includes the attribute / value pairs 402 and, in some cases, the device identifier 403. Figure 3 The configuration resource 302 illustrates a configuration resource having structured data including multiple attribute / value pairs.
[0093] The NMS 22 uses the path / value pairs 404A - 404N (collectively referred to as "path / value pairs 404") stored in the associated data 61 to create, update, delete, and arbitrate access to the corresponding attribute / value pairs 402A–402N of the configuration resource 401. As described above with respect to Figure 5 The NMS 22 can, for example, generate or update the path / value pair 404A using the configuration data included in the configuration request, or can delete the path / value pair 404A based on a delete operation requested for the attribute / value 402A in the configuration request. The NMS 22 also associates (or "tags") each path / value pair with one or more application identifiers or with a "default" identifier or "label" (as shown for the associated path / value pair 404A).
[0094] In some cases, the NMS 22 may perform device discovery on the network device 24 to obtain factory default configuration data. The NMS 22 may generate configuration resources 65 for any resources included in the factory default configuration. As part of generating these configuration resources, the NMS 22 may also create association data 61 in a manner similar to how it processes configuration requests and associate the property / value pairs obtained in the factory default configuration with default identifiers. As shown, the path / value 404A is associated with a default identifier, indicating that the corresponding property / value pair 402A may be the factory default configuration, and the configuration resource 401 is generated from the factory default resources on the network device 24.
[0095] The NMS 22 generates the configuration resource 401 from the path / value pairs 404 of the configuration resource 401. More specifically, the NMS 22 may convert each of the path / value pairs 404 into the corresponding one of the property / value pairs 402 in the configuration resource 401, and in some cases, may conform the generated property / value pair 402 data to the schema of the configuration data of the configuration resource 401. That is, the configuration data of the configuration resource (shown here by the property / value pairs 402) may be structured.
[0096] The NMS 22 sends the property / value pairs 402 to the network device 22 in the form of the configuration data 410 of the configuration resource 401. The configuration module 32 may convert the configuration data 410 into committed configuration data 412 and then update the configuration data 42 with the committed configuration data 412. In this way, the NMS 22 and the network device 24 update the corresponding one of the resources 63 of the configuration resource 401. The committed configuration data of the resource may be structured data. Figure 3 The configuration data 306 of the resource in is shown as an example.
[0097] Figure 6 is a flowchart illustrating an example process 600 performed by a network management system according to the techniques of the present disclosure to process a configuration request. Regarding Figure 2 the NMS 22 of describes the process 500 of configuring the network device 24, but the process 500 may be performed by other NMSs or other systems (e.g., EMS, DMS) to configure other examples of the network devices described herein.
[0098] The network management system 22 receives, via the interface 30, a configuration request to delete a configuration resource in the configuration resource 65, the configuration request including an indication of the application that issued the configuration request (602). This indication may be the application identifier of the application. Examples of the data included in the configuration request to delete the configuration resource are as follows:
[0099] Application-ID:App_2
[0100] Device-ID: <unique-device-identifier>
[0101] Prefix: Interfaces / Interface[name=ge-0 / 0 / 1]
[0102] As in the earlier example, the Prefix can be understood as the resource name or resource identifier of a configuration resource that will be uniquely identified in the context of the device identified by the Device-ID. The Application-ID identifies the application that issued the configuration request to delete the configuration resource.
[0103] The network management system 22 can query the associated data 61 to obtain all the path / value pairs (along with any associated identifiers) of the configuration resource that are associated with the application identifier of the application (604). The network management system 22 can filter all the path / value pairs of the configuration resource by the application identifier in the query or for the result set of the query.
[0104] The management module 28 iteratively processes (or otherwise processes) the path / value pairs that meet the criteria (606). If there is another path / value pair to process (the "yes" branch of 606), the management module 28 determines whether the path / value pair is associated with any additional application identifiers (612). If not (the "no" branch of 612), no configuration is required, and the management module 28 deletes the path / value pair from the associated data 61 (614). If there is an associated additional application identifier (the "yes" branch of 612), the configuration is still required by at least one other application, and thus the management module 28 only deletes the application identifier of the application that issued the configuration request received at 602 from the associated data 61 of the path / value pair (618). In effect, this removes the label of the path / value pair.
[0105] At 606, the management module 28 iteratively processes the path / value pairs until there are no more path / value pairs remaining (the "no" branch of 606). At this stage, the relevant path / value pairs in the associated data 61 have been deleted, and thus the management module 28 updates the corresponding configuration resource in the configuration resource 65 to reflect the updated path / value pairs (620). For example, the management module 28 can obtain all the path / value pairs of the configuration resource and "unflatten" them to generate the configuration data of the configuration resource. This can effectively reverse the scheme described in step 506, and at Figure 3 In the figure shown, the management module 28 processes the path and value columns of the entries of the associated data of the configuration resources read from the table 300 to generate the configuration resources 302. This includes configuration data of non-scalar values (e.g., a list of elements having their own path / value pairs in the associated data 61). In some cases, the management module 28 can generate the configuration resources by simply creating and / or updating the attribute / value pairs of the existing configuration resources based on the new and / or updated path / value pairs, rather than completely regenerating the configuration resources.
[0106] The configuration resources generated in step 620 include the cumulative configuration data created by all the applications that have issued configuration requests for the configuration resources. The management module 28 sends the configuration data of the configuration resources to the network device 22 to modify the configuration data 42 for the device, and more specifically, the corresponding resources (622) of the resource 63.
[0107] For example, the management module 28 can generate the configuration data of the configuration resources in a structured form. In this case, if the configuration interface 44 assumes a format (e.g., using OpenConfig to support JSON, or supporting XML, etc.), the management module 28 can simply send the configuration data as it is to the configuration interface 44. In some cases, the management module 28 can convert the configuration data into a vendor-specific format that meets the specific requirements of the vendor for the configuration data and requests / commands sent to the configuration interface 44.
[0108] Using a relational database to store path / value pairs with the path as the unique key improves the search for existing paths in the relational database because queries with different types of matching clauses can be executed on the relational database. In some examples, the use of the relational database and the tagging function can effectively add, update, and remove path / value and application identifier associations. Further, these techniques can improve the efficiency of determining whether a specific attribute / value pair is no longer used by any application - the absence of any associated application identifier for the corresponding attribute / value pair means that the attribute / value pair can be removed from the network device configuration. These techniques can allow multiple applications to independently update different path / value pairs of the same configuration resource (and the corresponding resources on the network device). These techniques can also allow an application to stop using a configuration resource, which allows the NMS 22 to remove the configuration as long as the configuration resource is dedicated to that application. These techniques can also allow the NMS 22 and the network device 24 to retain the factory default configuration, at least until no application updates it. These techniques can allow multiple applications to run on top of the NMS 22 and provide flexibility in defining and using shared configuration resources of multiple applications.
[0109] In some examples, the NMS 22 can perform disaster recovery using the configuration resources 65 and other techniques described herein. For example, the NMS 22 can encode data indicating the ownership / association of path / value pairs on the network device 24. Then, the NMS 22 can subsequently obtain and "regenerate" the configuration resources 65 from the network device 24, and can also populate the association data 61 with path / value pairs and application associations. This can be particularly useful in cases where the NMS 22 fails due to, for example, a site disaster, in which case the NMS 22 is hosted such that the configuration data 32 or the database 43 is corrupted.
[0110] For events such as database corruption or site disaster, the association data 61 of the configuration resources can be encoded into a structure similar to the following, where a list of paths and associated applications can be maintained:
[0111]
[0112] The NMS 22 can push this structured representation of the association data 61 to the network device 24 for each configuration resource. The NMS 22 can store this data as an annotation / comment within the configuration data 42, as in the following example:
[0113]
[0114]
[0115] Using the embedded comments above, the NMS 22 can obtain and reconstruct the configuration resources and the association data 61 for each path / value pair by processing the comments. For example, the NMS 22 can issue the following RPC to the network device 24 to obtain the configuration and the ownership information of the device from interface 'ge-0 / 0 / 1'.
[0116]
[0117]
[0118] The NMS 22 receives a reply:
[0119]
[0120] The NMS 22 can transform the comment into, for example, JSON and accordingly populate the association data 61 of the configuration resources.
[0121] In some examples, the application is expected to maintain all configurations required for the configuration resources. However, the NMS 22 can provide a Get option to retrieve the configuration resources. The Get request will include the application identifier, and the NMS 22 can generate the configuration data of the configuration resources by obtaining the path / value pairs associated with the application identifier in the associated data 61, optionally already formatted.
[0122] In some examples of using the gNMI-based interface of the interface 30, then, after initially creating the configuration resources, subsequent updates or deletions of the property / value pairs do not require sending the full payload. The application can send only the gNMI path / value pairs that need to be updated or deleted in the SetRequest. The gNMI specification supports an extended prototype that can be sent in the SetRequest. The application identifier can be populated in this extended prototype.
[0123] These techniques can provide one or more technical advantages not possessed by server-side applications. For example, these techniques can be applied across domains. For example, they do not require Kubernetes or any specific orchestration platform. The NMS 22 uses different mechanisms for storing and managing the association of property / value pairs and applications, namely, the associated data 61. Compared with server-side applications, these techniques can store data more efficiently because the configuration resource definition (CRD) is stored in etcd as an unexplained block.
[0124] Regarding conflicts, these techniques may be superior to server-side applications: once the configuration resources are flattened, simple relational database queries can be executed to see if the values of the paths used by another application are being modified. In contrast, server-side applications browse the managed fields of each field manager to identify conflicts. That is, in a Kubernetes server-side application, changes to the fields of an object are tracked through the "field management" mechanism. When the value of a field changes, the owner changes from its current manager to the manager making the change.
[0125] Compared with server-side applications, these techniques use less verbose associated data 61, which can make it easier to serialize the associated data 61 of the configuration resources 65 to network devices or backup resources, and deserialize such backups and regenerate the configuration resources 65. Compared with server-side applications, these techniques can provide a more consistent method for deletion, that is, replacing sending an empty configuration with an explicit delete request. In the above techniques, the delete operation may be more efficient than server-side applications because for the application issuing the request, only the application identifier needs to be removed. In addition, deleting path / value pairs from the configuration resources is also effective: the presence of an unassociated application identifier for the path / value pair prompts removal.
[0126] As yet another advantage, in some examples, the NMS 22 can use a relational database for various storage requirements. Using a relational database has distinct advantages such as indexing, faster queries. For an NMS for a server-side application that leverages Kubernetes, the NMS will have to use an additional storage system in the form of etcd and will also have to copy information into etcd. The purpose of Kubernetes config-map and CRD is to store the configuration information of the application, not business data, and a relational database is built for handling large amounts of business data. Additionally, in a server-side application, the association with the application is maintained based on the participants with the management keys (i.e., the keys are owned and shared). In contrast, the NMS 22 additionally maintains these associations based on the value of the key / path (i.e., these values are shared among applications). As a result, ownership / sharing of values can occur in the leaf list and ownership / sharing of values can occur in the object list.
[0127] Figure 7 is a flowchart illustrating an example operation of a network management system 10 in accordance with one or more techniques of the present disclosure. As Figure 7 illustrated in the example of, the network management system 10 can initially receive a configuration request including first configuration data for a network device 14A, the first configuration data defining a data structure (702) including first attribute / value pairs. Next, the network management system 10 can generate corresponding first path / value pairs for the first attribute / value pairs from the first configuration data, where the path of the first path / value pairs uniquely identifies the first path / value pairs in the associated data structure (704). Next, the network management system 10 can modify the associated data structure based on the first path / value pairs (706). Next, the network management system 10 can generate a configuration resource including second configuration data for the network device 14A from the associated data structure, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs (708). Next, the network management system 10 sends the second configuration data to the network device 14A to modify the configuration of the network device 14A (710).
[0128] The techniques described in this disclosure may be implemented, at least in part, in hardware, software, firmware, or any combination thereof. For example, aspects of the described techniques may be implemented within one or more processors, which include one or more microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or any other equivalent integrated or discrete logic circuitry, as well as any combination of such components. The term "processor" or "processing circuitry" generally may refer to any of the foregoing logic circuitry, alone or in combination with other logic circuitry, or any other equivalent circuitry. A control unit including hardware may also perform one or more of the techniques of this disclosure.
[0129] This hardware, software, and firmware may be implemented within the same device or in separate devices to support the various operations and functions described in this disclosure. Additionally, any of the described units, modules, or components may be implemented together or separately as discrete but interoperable logic devices. Describing different features as modules or units is intended to emphasize different functional aspects and does not necessarily imply that such modules or units must be implemented by separate hardware or software components. Rather, the functions associated with one or more modules or units may be performed by separate hardware or software components, or integrated within common or separate hardware or software components.
[0130] The techniques described in this disclosure may also be embodied or encoded in a computer-readable medium that includes instructions, such as a computer-readable storage medium. The instructions embedded or encoded in the computer-readable medium may cause a programmable processor or other processor to perform a method, for example, when the instructions are executed. The computer-readable medium may include non-transitory computer-readable storage medium and transitory communication medium. Tangible and non-transitory computer-readable storage medium may include random access memory (RAM), read only memory (ROM), programmable read only memory (PROM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), flash memory, hard disks, CD-ROMs, floppy disks, cassette tapes, magnetic media, optical media, or other computer-readable storage media. The term "computer-readable storage medium" refers to physical storage media and not signals, carriers, or other transitory media.
[0131] In addition to or as an alternative to the foregoing, the following examples are described. The features described in any of the following examples may be utilized in conjunction with any of the other examples described herein.
[0132] Example 1. A method includes: generating, by a network management system, a path / value pair for configuring attributes / value pairs of a network device, where the path of the path / value pair uniquely identifies the path / value pair in an associated data structure; and in response to the network management system determining that an entry for the path of the path / value pair exists in the associated data structure and the value of the entry is the same as the value in the attribute / value pair, tagging the entry with an application identifier of the application and sending, to the network device, configuration data generated from the entry to modify the configuration of the network device.
[0133] Example 2. The method according to Example 1 further includes: in response to the network management system determining that an entry for the path in the path / value pair does not exist in the associated data structure: storing the path / value pair as a stored entry in the associated data structure, tagging the stored entry with an application identifier of the application, and outputting configuration data generated from the stored entry to modify the configuration of the network device.
[0134] Example 3. The method according to any one of Examples 1 to 2, wherein generating the path / value pair includes: in response to receiving a configuration request including an attribute / value pair and an application identifier, generating the path / value pair.
[0135] Example 4. The method according to Example 3, wherein the application identifier identifies the application as having issued the configuration request.
[0136] Example 5. The method according to any one of Examples 1 to 4 further includes: in response to the network management system determining that an entry for the path / value pair exists in the associated data structure and the value of the entry is different from the value in the attribute / value pair, outputting an indication of an error.
[0137] Example 6. The method according to any one of Examples 1 to 5, wherein the configuration data includes first configuration data, and the method further includes: generating, by the network management system, a configuration resource including second configuration data from the associated data structure, the second configuration data including the attribute / value pair generated from the entry.
[0138] Example 7. The method according to Example 6, wherein generating the configuration resource including the second configuration data includes: obtaining the path / value pair from the associated data structure; generating, from the path / value pair, the attribute / value pair generated from the entry; and generating the second configuration data of the configuration resource to include the attribute / value pair generated from the entry.
[0139] Example 8. The method according to any one of Examples 1 to 2 or 5 to 7 further includes: in response to the network management system receiving a configuration request including an application identifier of the application for deleting the configuration data, deleting the application identifier tag from the entry.
[0140] Example 9. The method according to any one of Examples 1 to 2 or 5 to 7 further includes: receiving, by a network management system, a configuration request to delete configuration data, the configuration request including an application identifier of an application; and deleting an entry from an associated data structure in response to determining that no other application identifier is used to label the entry.
[0141] Example 10. The method according to Example 9 further includes: sending, by the network management system to a network device after deleting the entry, updated configuration data generated from the associated data structure to modify the configuration of the network device.
[0142] Example 11. The method according to any one of Examples 1 to 10, wherein generating a path / value pair of an attribute / value pair includes: receiving a prefix string with the attribute / value pair; forming a path of the path / value pair from the prefix string and an attribute of the attribute / value pair; and setting a value of the path / value pair to a value of the attribute / value pair.
[0143] Example 12. The method according to any one of Examples 1 to 11, wherein generating a path / value pair of an attribute / value pair includes: forming a path of the path / value pair using a pattern of a General Network Management Interface (gNMI) path; and setting a value of the path / value pair to a value of the attribute / value pair.
[0144] Example 13. A network management system includes: a processing circuit, and a storage device, wherein the processing circuit is accessible to the storage device and is configured to: generate a path / value pair of an attribute / value pair for configuring a network device, wherein the path of the path / value pair uniquely identifies the path / value pair in an associated data structure; and in response to determining that an entry of the path of the path / value pair exists in the associated data structure and a value of the entry is the same as a value of the attribute / value pair, label the entry with an application identifier of an application, and send configuration data generated from the entry to the network device to modify the configuration of the network device.
[0145] Example 14. The network management system according to Example 13, wherein the processing circuit is configured to, in response to an entry of the path of the path / value pair not existing in the associated data structure: store the path / value pair as a stored entry in the associated data structure, label the stored entry with an application identifier of an application, and output configuration data generated from the stored entry to modify the configuration of the network device.
[0146] Example 15. The network management system according to any one of Examples 13 to 14, wherein the processing circuit is configured to, in response to determining that an entry of the path of the path / value pair exists in the associated data structure and a value of the entry is different from a value in the attribute / value pair, output an indication of an error.
[0147] Example 16. A network management system according to any one of Examples 13 to 15, wherein the configuration data includes first configuration data, and wherein the processing circuitry is configured to: generate a configuration resource including second configuration data from an associated data structure, the second configuration data including property / value pairs generated from entries.
[0148] Example 17. The network management system according to Example 16, wherein, to generate a configuration resource including second configuration data, the processing circuitry is configured to: obtain path / value pairs from an associated data structure; generate property / value pairs generated from entries from the path / value pairs; and generate second configuration data of the configuration resource to include property / value pairs generated from entries.
[0149] Example 18. A network management system according to any one of Examples 13 to 17, wherein the processing circuitry is configured to: delete an application identifier from an entry in response to receiving a configuration request for deleting configuration data including the application identifier of an application.
[0150] Example 19. A network management system according to any one of Examples 13 to 17, wherein the processing circuitry is configured to: receive a configuration request for deleting configuration data, the configuration request including the application identifier of an application; and delete the entry from the associated data structure in response to determining that the entry is not tagged with any other application identifier.
[0151] Example 20. A non-transitory computer-readable medium, including: instructions for causing processing circuitry of a network management system to perform operations, the operations including: generating path / value pairs for property / value pairs for configuring a network device, wherein the path of the path / value pairs uniquely identifies the path / value pairs in an associated data structure; and in response to determining that an entry of the path of the path / value pairs exists in the associated data structure and the value of the entry is the same as the value in the property / value pairs, tagging the entry with the application identifier of an application, and sending configuration data generated from the entry to the network device to modify the configuration of the network device.
[0152] In addition, any one of the specific features stated in any of the above examples can be combined into a beneficial example of the described technology. That is, any one of the specific features is generally applicable to all examples of the present invention.
Claims
1. A network management system, comprising: A control unit, including a processing circuit coupled to a memory, wherein the control unit is configured to: Receive a configuration request including first configuration data for a network device, the first configuration data defining a data structure including first attribute / value pairs; Generate, from the first configuration data, first path / value pairs corresponding to the first attribute / value pairs, wherein the paths in the first path / value pairs uniquely identify the first path / value pairs in an associated data structure; Modify the associated data structure based on the first path / value pairs; Generate, from the associated data structure, a configuration resource including second configuration data for the network device, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs; and Send the second configuration data to the network device to modify the configuration of the network device.
2. The network management system according to claim 1, Among them, The configuration request includes an application identifier of an application that issues the configuration request, and wherein, in order to modify the associated data structure to include the first path / value pairs, the control unit is configured to: Modify the associated data structure to associate the first path / value pairs with the application identifier.
3. The network management system according to claim 2, Among them, The configuration request includes a first configuration request, and wherein the control unit is configured to: Receive a second configuration request for deleting configuration data, the second configuration request including the application identifier of the application; Obtain, from the associated data structure, the obtained path / value pairs associated with the application identifier based on the application identifier; and In response to determining that the obtained path / value pairs are also associated with application identifiers of different applications, delete the association between the application identifier and the obtained path / value pairs.
4. The network management system according to claim 2, Among them, The configuration request includes a first configuration request, and wherein the control unit is configured to: Receive a second configuration request for deleting configuration data, the second configuration request including the application identifier of the application; Obtain, from the associated data structure, the obtained path / value pairs associated with the application identifier based on the application identifier; In response to determining that the obtained path / value pairs are not associated with application identifiers of any other applications, delete the obtained path / value pairs from the associated data structure; Generate, from the associated data structure from which the obtained path / value pairs have been deleted, an updated configuration resource including third configuration data for the network device; and Send the third configuration data to the network device to modify the configuration of the network device.
5. The network management system according to claim 2, Among them, The application includes a first application, wherein the configuration request includes a first configuration request, and wherein the control unit is configured to: Receive a second configuration request to include third configuration data for the network device and an application identifier of a different second application that issued the second configuration request, the third configuration data defining a data structure including second attribute / value pairs; Generate, from the third configuration data, second path / value pairs corresponding to the second attribute / value pairs, wherein the paths of the second path / value pairs uniquely identify the second path / value pairs in the associated data structure; and In response to determining, by querying the associated data structure, that a first path / value pair included in the associated data structure has the same path and the same value as the second path / value pair, modify the associated data structure to associate the first path / value pair with the application identifier of the second application.
6. The network management system according to claim 2, Among them, The application includes a first application, wherein the configuration request includes a first configuration request, and wherein the control unit is configured to: Receive a second configuration request to include third configuration data for the network device and an application identifier of a different second application that issued the second configuration request, the third configuration data defining a data structure including second attribute / value pairs; Generate, from the third configuration data, second path / value pairs corresponding to the second attribute / value pairs, wherein the paths of the second path / value pairs uniquely identify the second path / value pairs in the associated data structure; and In response to determining, by querying the associated data structure, that a first path / value pair included in the associated data structure has the same path and a different value as the second path / value pair, output an indication of an error.
7. The network management system according to any one of claims 1 to 6, wherein To modify the associated data structure to include the first path / value pair, the control unit is configured to: In response to determining that the associated data structure does not store the first path / value pair, modify the associated data structure to include the first path / value pair.
8. The network management system according to any one of claims 1 to 6, wherein To generate the first path / value pair corresponding to the first attribute / value pair, the control unit is configured to: Process the data structure to obtain a prefix string of the first attribute / value pair; Form the path of the first path / value pair from the prefix string and the attribute of the first attribute / value pair; and Form the value of the first path / value pair from the value of the first attribute / value pair.
9. The network management system according to any one of claims 1 to 6, wherein To generate the first path / value pair corresponding to the first attribute / value pair, the control unit is configured to: Process the data structure to form the path of the first path / value pair using a pattern of a general remote procedure call network management interface gNMI path; and Form the value of the first path / value pair from the value of the first attribute / value pair.
10. The network management system according to any one of claims 1 to 6, wherein, To generate the configuration resource including the second configuration data for the network device, the control unit is configured to: Obtain the first path / value pair from the associated data structure; Generate the second attribute / value pair from the first path / value pair; and Generate the second configuration data of the configuration resource to include the second attribute / value pair.
11. The network management system according to claim 1, Among them, wherein the configuration request includes an application identifier of the application that issues the configuration request, and wherein the control unit is configured to: embed a representation of the first path / value pair and the application identifier in the second configuration data; obtain the second configuration data from the network device after sending the second configuration data to the network device; and generate the associated data structure to include the association between the first path / value pair and the application identifier.
12. The network management system according to any one of claims 1 to 6, wherein, The second configuration data of the configuration resource is formatted according to one of JavaScript Object Notation and Extensible Markup Language.
13. The network management system according to any one of claims 1 to 6, Among them, wherein the second configuration data configures a resource in the network device corresponding to the configuration resource, wherein the type of the resource includes one of an interface, a routing instance, a network instance, and a protocol.
14. A method for configuring a network device, comprising: receiving, by a network management system, a configuration request including first configuration data for a network device, the first configuration data defining a data structure including first attribute / value pairs; generating, by the network management system, first path / value pairs corresponding to the first attribute / value pairs from the first configuration data, wherein the path of the first path / value pair uniquely identifies the first path / value pair in an associated data structure; modifying, by the network management system, the associated data structure based on the first path / value pairs; generating, by the network management system, a configuration resource including second configuration data for the network device from the associated data structure, the second configuration data including second attribute / value pairs corresponding to the first path / value pairs; and sending, by the network management system, the second configuration data to the network device to modify the configuration of the network device.
15. The method according to claim 14, Among them, wherein the configuration request includes an application identifier of the application that issues the configuration request, and wherein modifying the associated data structure to include the first path / value pair includes: modifying the associated data structure to associate the first path / value pair with the application identifier.
16. The method according to claim 15, Among them, wherein the configuration request includes a first configuration request, and the method further includes: receiving, by the network management system, a second configuration request for deleting configuration data, the second configuration request including the application identifier of the application; obtaining, by the network management system, the obtained path / value pairs associated with the application identifier from the associated data structure based on the application identifier; and deleting the association between the application identifier and the obtained path / value pairs in response to determining that the obtained path / value pairs are also associated with application identifiers of different applications.
17. The method according to any one of claims 14 to 16, wherein Modifying the associated data structure to include the first path / value pair includes: modifying the associated data structure to include the first path / value pair in response to determining that the associated data structure does not store the first path / value pair.
18. The method according to any one of claims 14 to 16, wherein Generating the first path / value pair corresponding to the first attribute / value pair includes: Processing the data structure to obtain a prefix string of the first attribute / value pair; Forming the path of the first path / value pair from the prefix string and the attribute of the first attribute / value pair; and Forming the value of the first path / value pair from the value of the first attribute / value pair.
19. The method according to any one of claims 14 to 16, Among them, wherein the second configuration data configures resources in the network device corresponding to the configuration resources, and wherein the type of the resources includes one of an interface, a routing instance, a network instance, and a protocol.
20. A computer-readable storage medium encoded with instructions that, when executed, cause one or more programmable processors to perform the method according to any one of claims 14 to 19.
Citation Information
Patent Citations
Tree-oriented configuration management service
US10044522B1
Arrangement for aggregating multiple router configurations into a single router configuration
US7155534B1