User registration for services provisioned in multi-cloud infrastructure

Through the multi-cloud control plane framework, the problem of service interoperability between cloud environments is solved, service delivery and native user experience across cloud environments is realized, and the availability and user experience of cloud services are enhanced.

CN120077378APending Publication Date: 2025-05-30ORACLE INT CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380072837.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-07
Filing Date
2023-10-13
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The cloud environment of existing cloud service providers provides their subscription customers with a closed ecosystem, and customers have difficulty using services provided by another cloud service provider in one cloud environment.

Method used

Using the multi-cloud control plane (MCCP) framework, by receiving the user's lease identifier on the console of the multi-cloud infrastructure, determine whether a network link has been established between accounts in different cloud environments, and configure prerequisite resources to establish a network link if necessary.

Benefits of technology

The ability to deliver services from specific cloud networks to users on other clouds is realized, allowing users to access services in the external cloud with the user experience of a native cloud environment, and enhancing service availability and user experience across cloud environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077378A_ABST
    Figure CN120077378A_ABST
Patent Text Reader

Abstract

Techniques are described for providing a multi-cloud control plane (MCCP) in a first cloud infrastructure, including in a first cloud environment provided by a first cloud service provider, that enable services and / or resources provided in the first cloud infrastructure to be used by users of a second cloud environment, where the second cloud environment is different from the first cloud environment. The multi-cloud infrastructure enables a user associated with an account of a second cloud service provider to use a first service of a set of one or more cloud services from the second cloud infrastructure. The multi-cloud infrastructure creates a link between the account of the second cloud service provider and the lease created in the first cloud infrastructure to enable the user to use the first service.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application is a non - provisional application of and claims the benefit of each of the following provisional applications. The entire content of each of the following provisional applications is hereby incorporated by reference herein for all purposes:

[0003] (1) U.S. Provisional Application No. 63 / 416,042, filed October 14, 2022;

[0004] (2) U.S. Provisional Application No. 63 / 464,903, filed May 8, 2023;

[0005] (3) U.S. Provisional Application No. 63 / 467,241, filed May 17, 2023;

[0006] (4) U.S. Provisional Application No. 63 / 468,739, filed May 24, 2023;

[0007] (5) U.S. Provisional Application No. 63 / 469,763, filed May 30, 2023;

[0008] (6) U.S. Provisional Application No. 63 / 471,573, filed June 7, 2023; Technical Field

[0009] This disclosure relates to cloud architectures and, more particularly, to techniques for linking two cloud environments provided by different cloud service providers. A user of one cloud environment provided by one service provider can use and manage services provided by another cloud environment provided by another cloud service provider. Background Art

[0010] In the past few years, the adoption rate of cloud services has increased sharply, and this trend will only continue to grow. A variety of different cloud environments are provided by different cloud service providers (CSPs), and each cloud environment provides a set of one or more cloud services. The set of cloud services provided by a cloud environment can include one or more different types of services, including but not limited to software - as - a - service (SaaS) services, infrastructure - as - a - service (IaaS) services, platform - as - a - service (PaaS) services, etc.

[0011] Although there are currently a variety of different cloud environments available, each cloud environment provides a closed ecosystem for its subscribing customers. Thus, customers of a cloud environment are limited to using the services provided by that cloud environment. For customers subscribing to a cloud environment provided by one CSP, there is no easy way to use, via that cloud environment, the services provided in a different cloud environment provided by a different CSP. The embodiments discussed herein address these and other problems. Summary of the Invention

[0012] The present disclosure relates to cloud architectures and, more particularly, to techniques for linking two cloud environments provided by different cloud service providers. A user of one cloud environment provided by one service provider can manage services provided by another cloud environment provided by another cloud service provider. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media storing programs, code, or instructions executable by one or more processors, and the like. Some embodiments may be implemented by using a computer program product that includes a computer program / instructions that, when executed by a processor, cause the processor to perform any of the methods described in the present disclosure.

[0013] Embodiments of the present disclosure provide a Multi-Cloud Control Plane (MCCP) framework that provides the ability to deliver services of a particular cloud network (e.g., Oracle Cloud Infrastructure (OCI)) to users on other clouds (e.g., AWS). The MCCP framework allows users of (one or more) other cloud environments to access services of the cloud environment (e.g., PaaS services, database services such as autonomous database services, etc.), while providing a user experience as close as possible to the (one or more) native cloud environments of the users. The key value proposition of MCCP is that customers will be able to experience the full data plane capabilities of services in external clouds.

[0014] An embodiment of the present disclosure relates to a method, including: receiving, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a lease of a user in a first cloud environment, the multi-cloud infrastructure providing one or more services of the first cloud environment to a customer of a second cloud environment; determining, based on the identifier, whether a network link has been established between the lease of the user in the first cloud environment and an account of the user in the second cloud environment; in response to determining that the network link has not been established, redirecting the user to a second GUI associated with the second cloud environment, the redirecting facilitating configuring a set of prerequisite resources in the second cloud environment for the user; and, after configuring the set of prerequisite resources in the second cloud environment, initiating a workflow for establishing a network link between the first cloud environment and the second cloud environment.

[0015] According to one aspect of the present disclosure, there is provided one or more computer-readable non-transitory media storing computer-executable instructions that, when executed by one or more processors, cause: receiving, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a lease of a user in a first cloud environment, the multi-cloud infrastructure providing one or more services of the first cloud environment to a customer of a second cloud environment; determining, based on the identifier, whether a network link has been established between the lease of the user in the first cloud environment and an account of the user in the second cloud environment; in response to determining that the network link has not been established, redirecting the user to a second GUI associated with the second cloud environment, the redirecting facilitating configuring a set of prerequisite resources in the second cloud environment for the user; and after configuring the set of prerequisite resources in the second cloud environment, initiating a workflow for establishing a network link between the first cloud environment and the second cloud environment.

[0016] According to one aspect of the present disclosure, there is provided a computing device including: one or more processors; and a memory including instructions that, when executed by the one or more processors, cause the computing device to at least: receive, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a lease of a user in a first cloud environment, wherein the multi-cloud infrastructure provides one or more services of the first cloud environment to a customer of a second cloud environment; determine, based on the identifier, whether a network link has been established between the lease of the user in the first cloud environment and an account of the user in the second cloud environment; in response to determining that the network link has not been established, redirect the user to a second GUI associated with the second cloud environment, wherein redirecting the user facilitates configuring a set of prerequisite resources in the second cloud environment for the user; and after configuring the set of prerequisite resources in the second cloud environment, initiate a workflow for establishing a network link between the first cloud environment and the second cloud environment.

[0017] One aspect of the present disclosure provides a computing device including one or more data processors and a non-transitory computer-readable storage medium containing instructions that, when executed on the one or more data processors, cause the computing device to perform some or all of one or more methods disclosed herein.

[0018] Another aspect of the present disclosure provides a computer program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to perform some or all of one or more methods disclosed herein.

[0019] The foregoing and other features and embodiments will become more apparent when reference is made to the following specification, claims, and drawings. Description of the Drawings

[0020] The features, embodiments, and advantages of the present disclosure may be better understood when the following detailed description is read with reference to the drawings.

[0021] Figure 1 is an advanced diagram of a distributed environment, showing a virtual or overlay cloud network hosted by a cloud service provider infrastructure according to certain embodiments.

[0022] Figure 2 Depicts a simplified architecture diagram of physical components in a physical network within a CSPI according to certain embodiments.

[0023] Figure 3 Shows an example arrangement within a CSPI according to certain embodiments, where a host machine is connected to multiple network virtualization devices (NVDs).

[0024] Figure 4 Depicts the connectivity between a host machine and an NVD according to certain embodiments for providing I / O virtualization to support multi-tenancy.

[0025] Figure 5 Depicts a simplified block diagram of a physical network provided by a CSPI according to certain embodiments.

[0026] Figure 6 Depicts a simplified high-level diagram of a distributed environment according to certain embodiments, the distributed environment including multiple cloud environments provided by different cloud service providers (CSPs), where a cloud environment includes a specific cloud environment providing dedicated infrastructure that enables one or more cloud services provided by the specific cloud environment to be used by customers of other cloud environments.

[0027] Figure 7 Depicts an exemplary high-level architecture of a multi-cloud infrastructure interconnecting two different cloud environments according to some embodiments.

[0028] Figure 8 Depicts a multi-cloud architecture illustrating an identity framework according to some embodiments.

[0029] Figure 9 Depicts an exemplary flowchart illustrating steps corresponding to a user registration process according to some embodiments.

[0030] Figure 10 Depicts a block diagram illustrating an identity connector framework of a first cloud environment according to some embodiments.

[0031] Figure 11 Depicts an exemplary swimlane diagram illustrating steps corresponding to a process of performing identity federation according to some embodiments.

[0032] Figure 12 Depicts an exemplary swimlane diagram illustrating steps corresponding to a prerequisite resource verification process according to some embodiments.

[0033] Figure 13 Depicts an exemplary swimlane diagram illustrating steps performed to solve the confounding proxy problem according to some embodiments.

[0034] Figure 14 Depicts a schematic diagram illustrating a cloud link resource object according to some embodiments.

[0035] Figure 15 Depicts a schematic diagram illustrating the deployment of resources by a multi-cloud infrastructure according to some embodiments.

[0036] Figure 16 Is a block diagram illustrating a mode for implementing a cloud infrastructure as a service system according to at least one embodiment.

[0037] Figure 17 Is a block diagram illustrating another mode for implementing a cloud infrastructure as a service system according to at least one embodiment.

[0038] Figure 18 Is a block diagram illustrating another mode for implementing a cloud infrastructure as a service system according to at least one embodiment.

[0039] Figure 19 Is a block diagram illustrating another mode for implementing a cloud infrastructure as a service system according to at least one embodiment.

[0040] Figure 20 Is a block diagram of an example computer system according to at least one embodiment. Detailed Description

[0041] In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of certain embodiments. However, it will be apparent that various embodiments may be practiced without these specific details. The figures and description are not intended to be restrictive. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration". Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or superior to other embodiments or designs.

[0042] The present disclosure generally relates to improved cloud architectures and, more particularly, to techniques for linking two cloud environments (each provided by a different cloud service provider (CSP)) such that users of one cloud environment can use services provided by another different cloud environment. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media storing programs, code, or instructions executable by one or more processors, etc. Some embodiments may be implemented by using a computer program product that includes a computer program / instructions that, when executed by a processor, cause the processor to perform any method described in the present disclosure.

[0043] Embodiments of the present disclosure provide a Multi-Cloud Control Plane (MCCP) framework that provides the ability to deliver services of a particular cloud network (e.g., Oracle Cloud Infrastructure (OCI)) to users on other clouds (e.g., in Amazon's AWS). The MCCP framework allows users of ((one or more) other cloud environments) to access services of the cloud environment (e.g., PaaS services) while providing a user experience as close as possible to the (one or more) native cloud environments of the users. The key value proposition of MCCP is that customers will be able to experience the full data plane capabilities of services in external clouds.

[0044] MCCP enables users of a second cloud infrastructure (e.g., AWS users) to utilize resources (e.g., database resources) provided by a first cloud infrastructure (e.g., OCI) in a manner transparent to the users. Specifically, the services provided by the first cloud infrastructure are presented as "native" services in the second cloud infrastructure. This allows customers of the second cloud infrastructure to natively access the services provided by the first cloud infrastructure. As will be referred to below Figure 6 - 11 described, MCCP is a collection of microservices executed in the first cloud infrastructure that exposes the resources of the first cloud infrastructure for use by external cloud users (e.g., users of the second cloud infrastructure). Each microservice acts as an agent providing communication with the resources provided by the first cloud infrastructure.

[0045] Example of cloud network

[0046] The term cloud service is generally used to refer to services provided by a cloud service provider (CSP) to users or customers on demand (e.g., via a subscription model) using the systems and infrastructure (cloud infrastructure) provided by the CSP. Typically, the servers and systems that make up the CSP's infrastructure are separate from the customer's own on-premises servers and systems. Thus, customers can utilize the cloud services provided by the CSP without having to purchase separate hardware and software resources for the services. Cloud services are designed to provide subscribing customers with simple, scalable access to applications and computing resources without the customer having to invest in the infrastructure for providing the services.

[0047] There are several cloud service providers that offer various types of cloud services. There are various different types or models of cloud services, including Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS), etc.

[0048] A customer can subscribe to one or more cloud services provided by a CSP. The customer can be any entity, such as an individual, an organization, a business, etc. When the customer subscribes to or registers for a service provided by the CSP, a lease or account is created for that customer. The customer can then access the one or more subscribed cloud resources associated with that account via this account.

[0049] As described above, Infrastructure as a Service (IaaS) is a specific type of cloud computing service. In the IaaS model, the CSP provides the infrastructure (referred to as the cloud service provider infrastructure or CSPI), which can be used by the customer to build its own customizable network and deploy customer resources. Thus, the customer's resources and network are hosted by the infrastructure provided by the CSP in a distributed environment. This is different from traditional computing, where the customer's resources and network are hosted by the infrastructure provided by the customer.

[0050] A CSPI may include interconnected high-performance computing resources that form a physical network, including various host machines, memory resources, and network resources, which physical network is also referred to as the substrate network or underlying network. The resources in a CSPI may be spread across one or more data centers, which data centers may be geographically spread across one or more geographical regions. Virtualization software may be executed by these physical resources to provide a virtualized distributed environment. Virtualization creates an overlay network (also referred to as a software-based network, software-defined network, or virtual network) on top of the physical network. The CSPI physical network provides the underlying foundation for creating one or more overlay or virtual networks on top of the physical network. The physical network (or substrate network or underlying network) includes physical network devices such as physical switches, routers, computers, and host machines. An overlay network is a logical (or virtual) network that runs on top of the physical substrate network. A given physical network may support one or more overlay networks. Overlay networks typically use encapsulation techniques to distinguish traffic belonging to different overlay networks. A virtual or overlay network is also referred to as a Virtual Cloud Network (VCN). A virtual network is implemented using software virtualization techniques (e.g., hypervisors, virtualization functions implemented by Network Virtualization Devices (NVDs) (e.g., smartNICs), Top-of-Rack (TOR) switches, intelligent TORs that implement one or more functions performed by NVDs, and other mechanisms) to create a layer of network abstraction that can run on top of the physical network. Virtual networks can take many forms, including peer-to-peer networks, IP networks, etc. Virtual networks are typically either layer 3 IP networks or layer 2 VLANs. This method of virtual or overlay networking is often referred to as virtual or overlay layer 3 networking. Examples of protocols developed for virtual networks include IP-in-IP (or Generic Routing Encapsulation (GRE)), Virtual Extensible LAN (VXLAN - IETF RFC7348), Virtual Private Networks (VPNs) (e.g., MPLS layer 3 virtual private networks (RFC 4364)), VMware's NSX, GENEVE (Generic Network Virtualization Encapsulation), etc.

[0051] For IaaS, the infrastructure provided by the CSP (CSPI) can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, the cloud computing service provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, the IaaS provider can also supply various services to accompany those infrastructure components (e.g., billing, monitoring, logging, security, load balancing, and clustering, etc.). Thus, since these services can be policy-driven, IaaS users can be able to implement policies to drive load balancing to maintain application availability and performance. CSPI provides the infrastructure and a set of complementary cloud services that enable customers to build and run a wide range of applications and services in a highly available hosted distributed environment. CSPI provides high-performance computing resources and capabilities, as well as storage capacity, in a flexible virtual network that can be securely accessed from various networked locations (such as from the customer's on-premises network). When a customer subscribes to or registers for the IaaS services provided by the CSP, the lease created for that customer is a secure and isolated partition within CSPI where the customer can create, organize, and manage their cloud resources.

[0052] Customers can use the computing, memory, and networking resources provided by CSPI to build their own virtual networks. One or more customer resources or workloads, such as compute instances, can be deployed on these virtual networks. For example, customers can use the resources provided by CSPI to build one or more customizable and private virtual networks, called virtual cloud networks (VCNs). Customers can deploy one or more customer resources, such as compute instances, on the customer VCN. Compute instances can take the form of virtual machines, bare metal instances, etc. Thus, CSPI provides the infrastructure and a set of complementary cloud services that enable customers to build and run a wide range of applications and services in a highly available virtual hosted environment. Customers do not manage or control the underlying physical resources provided by CSPI, but can control the operating system, storage devices, and deployed applications; and may have limited control over the selected networking components (e.g., firewalls).

[0053] The CSP can provide a console that enables customers and network administrators to configure, access, and manage the resources deployed in the cloud using CSPI resources. In certain embodiments, the console provides a web-based user interface that can be used to access and manage CSPI. In certain implementations, the console is a web-based application provided by the CSP.

[0054] CSPI can support a single-tenant or multi-tenant architecture. In a single-tenant architecture, software (e.g., applications, databases) or hardware components (e.g., host machines or servers) serve a single customer or tenant. In a multi-tenant architecture, software or hardware components serve multiple customers or tenants. Thus, in a multi-tenant architecture, CSPI resources are shared among multiple customers or tenants. In a multi-tenant scenario, preventive measures are taken and protection measures are implemented in CSPI to ensure that each tenant's data is isolated and invisible to other tenants.

[0055] In a physical network, a network endpoint ("endpoint") refers to a computing device or system that is connected to a physical network and communicates back and forth with the network to which it is connected. Network endpoints in a physical network can be connected to a local area network (LAN), a wide area network (WAN), or other types of physical networks. Examples of traditional endpoints in a physical network include modems, hubs, bridges, switches, routers, and other networking devices, physical computers (or host machines), etc. Each physical device in a physical network has a fixed network address that can be used to communicate with the device. This fixed network address can be a layer 2 address (e.g., MAC address), a fixed layer 3 address (e.g., IP address), etc. In a virtualized environment or virtual network, endpoints can include various virtual endpoints, such as virtual machines hosted by components of the physical network (e.g., hosted by a physical host machine). These endpoints in a virtual network are addressed by overlay addresses, such as an overlay layer 2 address (e.g., overlay MAC address) and an overlay layer 3 address (e.g., overlay IP address). Network overlay enables flexibility by allowing network administrators to move around the overlay addresses associated with network endpoints using software management (e.g., via software that implements a control plane for the virtual network). Accordingly, different from a physical network, in a virtual network, an overlay address (e.g., overlay IP address) can be moved from one endpoint to another using network management software. Since a virtual network is built on top of a physical network, communication between components in a virtual network involves both the virtual network and the underlying physical network. To facilitate such communication, components of CSPI are configured to learn and store mappings that map overlay addresses in the virtual network to actual physical addresses in the underlying network, and vice versa. These mappings are then used to facilitate communication. Customer traffic is encapsulated to facilitate routing in the virtual network.

[0056] Accordingly, a physical address (e.g., a physical IP address) is associated with a component in a physical network, and an overlay address (e.g., an overlay IP address) is associated with an entity in a virtual or overlay network. A physical IP address is an IP address associated with a physical device (e.g., a network device) in a substrate or physical network. For example, each NVD has an associated physical IP address. An overlay IP address is an overlay address associated with an entity in an overlay network, such as an overlay address associated with a compute instance in a customer's Virtual Cloud Network (VCN). Two different customers or tenants (each with its own private VCN) can potentially use the same overlay IP address in their VCNs without knowing about each other. Both physical IP addresses and overlay IP addresses are types of real IP addresses. These addresses are separate from virtual IP addresses. A virtual IP address is typically a single IP address that represents or maps to multiple real IP addresses. A virtual IP address provides a one-to-many mapping between the virtual IP address and multiple real IP addresses. For example, a load balancer can use a VIP to map or represent multiple servers, each with its own real IP address.

[0057] The cloud infrastructure or CSPI is physically hosted in one or more data centers in one or more regions of the world. The CSPI can include components in a physical or substrate network and virtualized components (e.g., virtual networks, compute instances, virtual machines, etc.) in a virtual network built on top of the physical network components. In some embodiments, the CSPI is organized and hosted in realms, regions, and availability domains. A region is generally a local geographic area that contains one or more data centers. Regions are generally independent of each other and can be far apart, e.g., spanning countries or even continents. For example, a first region can be in Australia, another in Japan, another in India, and so on. CSPI resources are partitioned across regions such that each region has its own independent subset of CSPI resources. Each region can provide a set of core infrastructure services and resources, such as compute resources (e.g., bare metal servers, virtual machines, containers, and associated infrastructure, etc.); storage resources (e.g., block volume storage, file storage, object storage, archival storage); networking resources (e.g., Virtual Cloud Network (VCN), load balancing resources, connection to an on-premises network), database resources; edge networking resources (e.g., DNS); and access management and monitoring resources, etc. Each region generally has multiple paths connecting it to other regions in the realm.

[0058] Generally, an application is deployed in the region where it is most frequently used (i.e., deployed on the infrastructure associated with that region) because using nearby resources is faster than using distant resources. An application can also be deployed in different regions for various reasons, such as redundancy to mitigate the risk of region-wide events (such as large weather systems or earthquakes), to meet different requirements such as legal jurisdictions, tax domains, and other commercial or social standards.

[0059] Data centers within a region can be further organized and subdivided into Availability Domains (ADs). An Availability Domain can correspond to one or more data centers located within the region. A region can consist of one or more Availability Domains. In such a distributed environment, CSPI resources are either region-specific, such as a Virtual Cloud Network (VCN), or Availability Domain-specific, such as a compute instance.

[0060] The ADs within a region are isolated from each other, fault-tolerant, and configured such that it is highly unlikely for them to fail simultaneously. This is achieved by the ADs not sharing critical infrastructure resources (such as networking, physical cables, cable paths, cable entry points, etc.), such that a failure at one AD within a region is unlikely to affect the availability of other ADs within the same region. The ADs within the same region can be connected to each other via a low-latency, high-bandwidth network, which enables providing highly available connections to other networks (e.g., the Internet, the customer's on-premises network, etc.) and building replicated systems across multiple ADs to achieve high availability and disaster recovery. Cloud services use multiple ADs to ensure high availability and prevent resource failures. As the infrastructure provided by the IaaS provider grows, more regions and ADs, as well as additional capacity, can be added. Traffic between Availability Domains is typically encrypted.

[0061] In some embodiments, regions are grouped into realms. A realm is a logical collection of regions. Realms are isolated from each other and do not share any data. Regions within the same realm can communicate with each other, but regions in different realms cannot. A customer's lease or account with the CSP exists within a single realm and can be spread across one or more regions belonging to that realm. Typically, when a customer subscribes to an IaaS service, a lease or account for that customer is created in the region (referred to as the "primary" region) specified by the customer within the realm. The customer can extend the customer's lease to one or more other regions within the realm. A customer cannot access regions that are not within the realm where the customer's lease resides.

[0062] IaaS providers can offer multiple realms, each catering to a specific group of customers or users. For example, a business realm can be provided for business customers. As another example, a realm can be provided for a specific country for the customers within that country. As yet another example, a government realm can be provided for the government, etc. For example, a government realm can cater to a specific government and can have a higher security level than a business realm. For example, Oracle Cloud Infrastructure (OCI) currently offers realms for commercial regions and two realms for government cloud regions (e.g., FedRAMP authorized and IL5 authorized).

[0063] In some embodiments, an AD can be subdivided into one or more fault domains. A fault domain is a grouping of infrastructure resources within an AD to provide anti-affinity. Fault domains allow the distribution of compute instances such that these instances do not reside on the same physical hardware within a single AD. This is known as anti-affinity. A fault domain refers to a group of hardware components (computers, switches, etc.) that share a single point of failure. The compute pool is logically divided into fault domains. Thus, a hardware failure or a compute hardware maintenance event affecting one fault domain does not affect the instances in other fault domains. Depending on the embodiment, the number of fault domains for each AD can vary. For example, in some embodiments, each AD contains three fault domains. Fault domains act as logical data centers within an AD.

[0064] When a customer subscribes to an IaaS service, resources from the CSPI are provisioned to the customer and associated with the customer's lease. The customer can use these provisioned resources to build private networks and deploy resources on these networks. The customer network hosted by the CSPI in the cloud is referred to as a Virtual Cloud Network (VCN). The customer can use the CSPI resources allocated to the customer to set up one or more Virtual Cloud Networks (VCNs). A VCN is a virtual or software-defined private network. The customer resources deployed in the customer's VCN can include compute instances (e.g., virtual machines, bare metal instances) and other resources. These compute instances can represent various customer workloads, such as applications, load balancers, databases, etc. The compute instances deployed on a VCN can communicate with publicly accessible endpoints ("public endpoints") via a public network such as the Internet, with other instances in the same VCN or other VCNs (e.g., other VCNs of the customer or VCNs that do not belong to the customer), with the customer's on-premises data center or network, and with service endpoints and other types of endpoints.

[0065] CSPs can use CSPIs to provide various services. In some cases, the customers of CSPIs themselves can act like service providers and use CSPI resources to provide services. Service providers can expose service endpoints, which are characterized by identification information (e.g., IP addresses, DNS names, and ports). A customer's resources (e.g., compute instances) can use a particular service by accessing the service endpoint exposed by the service for that particular service. These service endpoints are generally endpoints that are publicly accessible to users via a public communication network such as the Internet using the public IP address associated with the endpoint. Publicly accessible network endpoints are sometimes also referred to as public endpoints.

[0066] In some embodiments, a service provider can expose a service via an endpoint for the service (sometimes referred to as a service endpoint). A customer of the service can then use this service endpoint to access the service. In some implementations, the service endpoints provided for a service can be accessed by multiple customers who intend to consume the service. In other implementations, a dedicated service endpoint can be provided for a customer such that only that customer can use the dedicated service endpoint to access the service.

[0067] In some embodiments, when a VCN is created, it is associated with a private overlay Classless Inter-Domain Routing (CIDR) address space, which is a range of private overlay IP addresses assigned to the VCN (e.g., 10.0 / 16). A VCN includes associated subnets, a routing table, and gateways. A VCN resides within a single region but can span one or more or all of the availability domains within that region. A gateway is a virtual interface configured for the VCN and enables communication of traffic between the VCN and one or more endpoints external to the VCN. One or more different types of gateways can be configured for the VCN to enable communication to and from different types of endpoints.

[0068] A VCN can be subdivided into one or more sub-networks, such as one or more subnets. Thus, a subnet is a configured unit or subdivision that can be created within a VCN. A VCN can have one or more subnets. Each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24) that do not overlap with other subnets in the VCN and represent a subset of the address space within the VCN's address space.

[0069] Each compute instance is associated with a virtual network interface card (VNIC), which enables the compute instance to participate in a subnet of a VCN. A VNIC is a logical representation of a physical network interface card (NIC). Generally speaking, a VNIC is an interface between an entity (e.g., a compute instance, a service) and a virtual network. A VNIC exists within a subnet, has one or more associated IP addresses, and associated security rules or policies. A VNIC is analogous to a layer 2 port on a switch. A VNIC is attached to a compute instance and a subnet within a VCN. The VNIC associated with a compute instance makes the compute instance part of a subnet of the VCN and enables the compute instance to communicate (e.g., send and receive data packets) with endpoints on the same subnet as the compute instance, with endpoints in different subnets within the VCN, or with endpoints outside the VCN. Thus, the VNIC associated with a compute instance determines how the compute instance connects to endpoints inside and outside the VCN. When a compute instance is created and added to a subnet within a VCN, a VNIC for the compute instance is created and associated with that compute instance. For a subnet that includes a set of compute instances, the subnet contains VNICs corresponding to the set of compute instances, with each VNIC attached to a compute instance within the set of compute instances.

[0070] A private overlay IP address is assigned to each compute instance via the VNIC associated with the compute instance. This private overlay network IP address is assigned to the VNIC associated with the compute instance when the compute instance is created and is used to route traffic to and from the compute instance. All VNICs within a given subnet use the same routing table, security list, and DHCP options. As described above, each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24), which do not overlap with other subnets in the VCN and represent a subset of the address space within the VCN's address space. For a VNIC on a particular subnet of a VCN, the private overlay IP address assigned to the VNIC is an address from the contiguous range of overlay IP addresses assigned to the subnet.

[0071] In some embodiments, in addition to the private secondary IP address, a compute instance may optionally be assigned additional secondary IP addresses, such as, for example, one or more public IP addresses if in a public subnet. These addresses are assigned either on the same VNIC or on multiple VNICs associated with the compute instance. However, each instance has a primary VNIC, which is created during instance launch and is associated with the secondary private IP address assigned to the instance - this primary VNIC cannot be deleted. Additional VNICs, called secondary VNICs, can be added to an existing instance in the same availability domain as the primary VNIC. All VNICs are in the same availability domain as the instance. A secondary VNIC can be in a subnet in the same VCN as the primary VNIC, or in a different subnet in the same VCN or a different VCN.

[0072] If a compute instance is in a public subnet, it can optionally be assigned a public IP address. When creating a subnet, the subnet can be designated as either a public subnet or a private subnet. A private subnet means that resources in the subnet (e.g., compute instances) and associated VNICs cannot have public secondary IP addresses. A public subnet means that resources in the subnet and associated VNICs can have public IP addresses. The customer can specify that the subnet exists in a single availability domain or across multiple availability domains in a region or realm.

[0073] As described above, a VCN can be subdivided into one or more subnets. In some embodiments, a virtual router (VR) configured for the VCN (referred to as the VCN VR or simply the VR) enables communication between the subnets of the VCN. For subnets within a VCN, the VR represents the logical gateway for that subnet, which enables the subnet (i.e., compute instances on that subnet) to communicate with endpoints on other subnets within the VCN and endpoints outside the VCN. The VCN VR is a logical entity that is configured to route traffic between VNICs in the VCN and virtual gateways associated with the VCN ("gateways"). Below regarding Figure 1Further describe the gateway. VCN VR is a Layer 3 / IP layer concept. In one embodiment, there is a VCN VR for a VCN, where the VCN VR has a potentially unlimited number of ports addressed by IP addresses, and each subnet of the VCN has one port. In this way, the VCN VR has a different IP address for each subnet in the VCN to which the VCN VR is attached. The VR is also connected to various gateways configured for the VCN. In some embodiments, a specific overlay IP address within the overlay IP address range for a subnet is reserved for the port of the VCN VR of that subnet. For example, consider a VCN with two subnets, and the associated address ranges are 10.0 / 16 and 10.1 / 16 respectively. For the first subnet in the VCN with the address range 10.0 / 16, the addresses within this range are reserved for the ports of the VCN VR of that subnet. In some cases, the first IP address within the range can be reserved for the VCN VR. For example, for a subnet with an overlay IP address range of 10.0 / 16, the IP address 10.0.0.1 can be reserved for the port of the VCN VR of that subnet. For the second subnet in the same VCN with the address range 10.1 / 16, the VCN VR can have a port for the second subnet with the IP address 10.1.0.1. The VCN VR has a different IP address for each subnet in the VCN.

[0074] In some other embodiments, each subnet within a VCN can have its own associated VR, which can be addressed by the subnet using a reserved or default IP address associated with the VR. For example, the reserved or default IP address can be the first IP address within the IP address range associated with that subnet. The VNICs in the subnet can use this default or reserved IP address to communicate (e.g., send and receive data packets) with the VR associated with the subnet. In such an embodiment, the VR is the ingress / egress point for that subnet. The VR associated with a subnet within a VCN can communicate with other VRs associated with other subnets within the VCN. The VR can also communicate with the gateways associated with the VCN. The VR functionality of a subnet runs on or is performed by one or more NVDs that perform VNIC functions for the VNICs in the subnet.

[0075] A routing table, security rules, and DHCP options can be configured for the VCN. The routing table is a virtual routing table for the VCN and includes rules for routing traffic from subnets within the VCN to destinations outside the VCN through gateways or specially configured instances. The routing table of the VCN can be customized to control how data packets are forwarded / routed into and out of the VCN. The DHCP options refer to the configuration information automatically provided to an instance when the instance is launched.

[0076] The security rules configured for a VCN represent an overlay firewall rule for the VCN. The security rules can include ingress and egress rules and specify the types of traffic (e.g., based on protocol and port) that are allowed to flow in and out of the VCN instance. The customer can choose whether a given rule is stateful or stateless. For example, the customer can allow incoming SSH traffic from anywhere to a set of instances by setting a stateful ingress rule with source CIDR 0.0.0.0 / 0 and destination TCP port 22. The security rules can be implemented using network security groups or security lists. A network security group consists of a set of security rules that apply only to the resources in that group. On the other hand, a security list includes rules that apply to all resources in any subnet that uses that security list. A default security list with default security rules can be provided for the VCN. The DHCP options configured for the VCN provide configuration information that is automatically provided to the instances in the VCN when the instances are launched.

[0077] In some embodiments, the configuration information for the VCN is determined and stored by the VCN control plane. For example, the configuration information for the VCN can include information about the address range associated with the VCN, the subnets within the VCN and associated information, one or more VRs associated with the VCN, the compute instances in the VCN and associated VNICs, the NVDs (e.g., VNICs, VRs, gateways) that perform various virtualized network functions associated with the VCN, the status information for the VCN, and other VCN-related information. In some embodiments, the VCN distribution service publishes the configuration information stored by the VCN control plane or a portion thereof to the NVDs. The distributed information can be used to update the information (e.g., forwarding tables, routing tables, etc.) stored and used by the NVDs to forward data packets to and from the compute instances in the VCN.

[0078] In some embodiments, the creation of the VCN and subnets is disposed of by the VCN control plane (CP) and the startup of the compute instances is disposed of by the compute control plane. The compute control plane is responsible for allocating physical resources for the compute instances and then calls the VCN control plane to create VNICs and attach them to the compute instances. The VCN CP also sends the VCN data map to the VCN data plane that is configured to perform packet forwarding and routing functions. In some embodiments, the VCN CP provides a distribution service that is responsible for providing updates to the VCN data plane. Examples of the VCN control plane are also depicted in Figure 12 , Figure 13 , Figure 14 and Figure 15 and described below (see reference numerals 1216, 1316, 1416, and 1516).

[0079] Customers can create one or more VCNs using resources hosted by CSPI. Compute instances deployed on customer VCNs can communicate with different endpoints. These endpoints can include endpoints hosted by CSPI and endpoints external to CSPI.

[0080] Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and Figure 12 - 16 Various different architectures for implementing cloud-based services using CSPI are depicted in and are described below. Figure 1 is a high-level diagram of a distributed environment 100 showing an overlay or customer VCN hosted by CSPI according to certain embodiments. Figure 1 The distributed environment depicted in includes multiple components in an overlay network. Figure 1 The distributed environment 100 depicted in FIG. 1 is merely an example and is not intended to unduly limit the scope of the claimed embodiments. Many variations, substitutions, and modifications are possible. For example, in some embodiments, Figure 1 The distributed environment depicted in Figure 1 More or fewer systems or components than those shown in the drawings may be used, two or more systems may be combined, or there may be different system configurations or arrangements.

[0081] like Figure 1 As shown in the example depicted in , the distributed environment 100 includes a CSPI 101 that provides services and resources that customers can subscribe to and use to build their virtual cloud network (VCN). In some embodiments, CSPI 101 provides IaaS services to subscribing customers. Data centers within CSPI 101 can be organized into one or more regions. Figure 1 An example region "Region US" 102 is shown in FIG. A customer has configured a customer VCN c / o Oracle International Corporation for region 102. The customer can deploy various computing instances on VCN 104, where the computing instances can include virtual machines or bare metal instances. Examples of instances include applications, databases, load balancers, etc.

[0082] exist Figure 1 In the embodiment depicted in , customer VCN 104 includes two subnets, namely, "Subnet-1" and "Subnet-2", each with its own CIDR IP address range. Figure 1In it, the covered IP address range of Subnet-1 is 10.0 / 16, and the address range of Subnet-2 is 10.1 / 16. The VCN virtual router 105 represents the logical gateway for the VCN, which enables communication between the subnets of VCN104 and other endpoints outside the VCN. The VCN VR 105 is configured to route traffic between the VNICs in VCN 104 and the gateways associated with VCN 104. The VCN VR 105 provides ports for each subnet of VCN 104. For example, VR 105 can provide a port with the IP address 10.0.0.1 for Subnet-1 and a port with the IP address 10.1.0.1 for Subnet-2.

[0083] Multiple computing instances can be deployed on each subnet, where the computing instances can be virtual machine instances and / or bare metal instances. The computing instances in a subnet can be hosted by one or more host machines within CSPI 101. The computing instances participate in the subnet via the VNICs associated with the computing instances. For example, as Figure 1 shown in, the computing instance C1 becomes part of Subnet-1 via the VNIC associated with the computing instance. Similarly, the computing instance C2 becomes part of Subnet-1 via the VNIC associated with C2. In a similar manner, multiple computing instances (which can be virtual machine instances or bare metal instances) can be part of Subnet-1. Via its associated VNIC, each computing instance is assigned a private covered IP address and a MAC address. For example, in Figure 1 shown in, the covered IP address of the computing instance C1 is 10.0.0.2 and the MAC address is M1, while the private covered IP address of the computing instance C2 is 10.0.0.3 and the MAC address is M2. Each computing instance in Subnet-1 (including computing instances C1 and C2) has a default route to the VCN VR 105 using the IP address 10.0.0.1, which is the IP address of the port of the VCN VR 105 for Subnet-1.

[0084] Multiple computing instances can be deployed on Subnet-2, including virtual machine instances and / or bare metal instances. For example, as Figure 1 shown in, the computing instances D1 and D2 become part of Subnet-2 via the VNICs associated with the respective computing instances. In the Figure 1 embodiment shown in, the covered IP address of the computing instance D1 is 10.1.0.2 and the MAC address is MM1, while the private covered IP address of the computing instance D2 is 10.1.0.3 and the MAC address is MM2. Each computing instance in Subnet-2 (including computing instances D1 and D2) has a default route to the VCN VR 105 using the IP address 10.1.0.1, which is the IP address of the port of the VCN VR 105 for Subnet-2.

[0085] The VCN A 104 may also include one or more load balancers. For example, a load balancer can be provided for a subnet and configured to load balance traffic across multiple compute instances on the subnet. A load balancer can also be provided to load balance traffic across subnets in the VCN.

[0086] A particular compute instance deployed on the VCN 104 can communicate with a variety of different endpoints. These endpoints can include endpoints hosted by the CSPI 200 and endpoints external to the CSPI 200. Endpoints hosted by the CSPI 101 can include: endpoints on the same subnet as the particular compute instance (e.g., communication between two compute instances in Subnet-1); endpoints on different subnets but within the same VCN (e.g., communication between a compute instance in Subnet-1 and a compute instance in Subnet-2); endpoints in different VCNs in the same region (e.g., communication between a compute instance in Subnet-1 and an endpoint in a VCN in the same region 106 or 110, communication between a compute instance in Subnet-1 and an endpoint in a service network 110 in the same region); or endpoints in VCNs in different regions (e.g., communication between a compute instance in Subnet-1 and an endpoint in a VCN in a different region 108). Compute instances in a subnet hosted by the CSPI 101 can also communicate with endpoints not hosted by the CSPI 101 (i.e., external to the CSPI 101). These external endpoints include endpoints in the customer's on-premises network 116, endpoints in other remote cloud-hosted networks 118, public endpoints 114 accessible via a public network such as the Internet, and other endpoints.

[0087] Use the VNICs associated with the source compute instance and the destination compute instance to facilitate communication between compute instances on the same subnet. For example, a compute instance C1 in subnet-1 may want to send a packet to a compute instance C2 in subnet-1. For a packet originating from a source compute instance and destined for another compute instance in the same subnet, the packet is first processed by the VNIC associated with the source compute instance. The processing performed by the VNIC associated with the source compute instance can include determining the destination information of the packet from the packet header, identifying any policies (e.g., security lists) configured for the VNIC associated with the source compute instance, determining the next hop for the packet, performing any packet encapsulation / decapsulation functions as needed, and then forwarding / routing the packet to the next hop with the aim of facilitating the communication of the packet to its intended destination. When the destination compute instance is in the same subnet as the source compute instance, the VNIC associated with the source compute instance is configured to identify the VNIC associated with the destination compute instance and forward the packet to that VNIC for processing. Then the VNIC associated with the destination compute instance is executed and the packet is forwarded to the destination compute instance.

[0088] For packets to be transmitted from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, communication is facilitated through the VNICs associated with the source and destination compute instances and the VCN VR. For example, if Figure 1 compute instance C1 in subnet-1 in [reference] wants to send a packet to compute instance D1 in subnet-2, then the packet is first processed by the VNIC associated with compute instance C1. The VNIC associated with compute instance C1 is configured to route the packet to VCN VR 105 using the default route or port 10.0.0.1 of the VCN VR. VCN VR 105 is configured to route the packet to subnet-2 using port 10.1.0.1. Then, the VNIC associated with D1 receives and processes the packet and the VNIC forwards the packet to compute instance D1.

[0089] For packets to be transmitted from a compute instance in the VCN 104 to an endpoint outside the VCN 104, communication is facilitated by the VNIC associated with the source compute instance, the VCN VR 105, and the gateway associated with the VCN 104. One or more types of gateways can be associated with the VCN 104. A gateway is an interface between the VCN and another endpoint, where that other endpoint is outside the VCN. A gateway is a layer 3 / IP layer concept and enables the VCN to communicate with endpoints outside the VCN. Thus, a gateway facilitates the flow of traffic between the VCN and other VCNs or networks. Various different types of gateways can be configured for the VCN to facilitate different types of communication with different types of endpoints. Depending on the gateway, communication can occur over a public network (e.g., the Internet) or over a private network. Various communication protocols can be used for these communications.

[0090] For example, compute instance C1 may want to communicate with an endpoint outside the VCN 104. The packet can first be processed by the VNIC associated with the source compute instance C1. The VNIC processing determines that the destination of the packet is outside C1's subnet-1. The VNIC associated with C1 can forward the packet to the VCN VR 105 for the VCN 104. The VCN VR 105 then processes the packet and, as part of the processing, determines a specific gateway associated with the VCN 104 as the next hop for the packet based on the destination of the packet. The VCN VR 105 can then forward the packet to the specific identified gateway. For example, if the destination is an endpoint within the customer's on-premises network, then the packet can be forwarded by the VCN VR 105 to the dynamic routing gateway (DRG) gateway 122 configured for the VCN 104. The packet can then be forwarded from the gateway to the next hop to facilitate the delivery of the packet to its final intended destination.

[0091] Various different types of gateways can be configured for the VCN. Examples of gateways that can be configured for the VCN are depicted in Figure 1 and described below. Examples of gateways associated with the VCN are also depicted in Figure 12 、 Figure 13 、 Figure 14 and Figure 15 (e.g., gateways referenced by reference numerals 1234, 1236, 1238, 1334, 1336, 1338, 1434, 1436, 1438, 1534, 1536, and 1538) and are described as follows. As Figure 1As shown in the embodiments depicted, a Dynamic Routing Gateway (DRG) 122 can be added to or associated with a customer VCN 104 and provide a path for private network traffic communication between the customer VCN 104 and another endpoint, where the other endpoint can be the customer's on-premises network 116, a VCN 108 in a different region of the CSPI 101, or another remote cloud network 118 not hosted by the CSPI 101. The customer on-premises network 116 can be a customer network or customer data center built using the customer's resources. Access to the customer on-premises network 116 is generally very restricted. For customers who have both a customer on-premises network 116 and one or more VCNs 104 deployed or hosted by the CSPI 101 in the cloud, the customer may want their on-premises network 116 and their cloud-based VCN 104 to be able to communicate with each other. This enables the customer to build an extended hybrid environment that includes the customer's VCN 104 hosted by the CSPI 101 and their on-premises network 116. The DRG 122 enables this communication. To enable such communication, a communication channel 124 is set up, where one endpoint of the channel is in the customer on-premises network 116 and the other endpoint is in the CSPI 101 and connected to the customer VCN 104. The communication channel 124 can be through a public communication network (such as the Internet) or a private communication network. Various different communication protocols can be used, such as IPsec VPN technology over a public communication network (such as the Internet), Oracle's FastConnect technology that uses a private network instead of a public network, etc. The device or equipment that forms one endpoint of the communication channel 124 in the customer on-premises network 116 is referred to as customer-premises equipment (CPE), such as Figure 1 the CPE 126 depicted in

[0092] In some embodiments, a Remote Peering Connection (RPC) can be added to the DRG, which allows the customer to peer one VCN with another VCN in a different region. Using this RPC, the customer VCN 104 can be connected to the VCN 108 in another region using the DRG 122. The DRG 122 can also be used to communicate with other remote cloud networks 118 not hosted by the CSPI 101 (such as the Microsoft Azure cloud, the Amazon AWS cloud, etc.).

[0093] As Figure 1As shown, an Internet Gateway (IGW) 120 can be configured for the customer's VCN 104, which enables compute instances on the VCN 104 to communicate with public endpoints 114 that are accessible via a public network such as the Internet. The IGW 120 is a gateway that connects the VCN to a public network such as the Internet. The IGW 120 enables public subnets within the VCN (such as VCN 104), where resources in the public subnets have public covering IP addresses, to directly access public endpoints 112 on the public network 114 (such as the Internet). Using the IGW 120, connections can be initiated from subnets within the VCN 104 or from the Internet.

[0094] A Network Address Translation (NAT) Gateway 128 can be configured for the customer's VCN 104 and enables cloud resources in the customer's VCN that do not have dedicated public covering IP addresses to access the Internet and do so without exposing those resources to direct incoming Internet connections (e.g., L4-L7 connections). This enables private subnets within the VCN (such as Private Subnet-1 in VCN 104) to privately access public endpoints on the Internet. In a NAT gateway, connections to the public Internet can only be initiated from private subnets and not from the Internet to private subnets.

[0095] In some embodiments, a Service Gateway (SGW) 126 can be configured for the customer VCN 104 and provides a path for private network traffic between the VCN 104 and service endpoints supported in the service network 110. In some embodiments, the service network 110 can be provided by a CSP and can provide various services. An example of such a service network is Oracle's service network, which provides various services available to customers. For example, compute instances (such as database systems) in the private subnets of the customer VCN 104 can back up data to service endpoints (such as Object Storage) without a public IP address or access to the Internet. In some embodiments, a VCN can have only one SGW, and the connection can only be initiated from subnets within the VCN and not from the service network 110. If a VCN is peered with another, resources in the other VCN generally cannot access the SGW. Resources in an on-premises network connected to the VCN using FastConnect or VPN Connect can also use the service gateway configured for that VCN.

[0096] In some embodiments, the SGW 126 uses the concept of a service Classless Inter-Domain Routing (CIDR) label, which is a string representing all the regional public IP address ranges for a service or group of services of interest. Customers use the service CIDR label when they configure the SGW and associated routing rules to control traffic to the service. If the public IP address of the service changes in the future, then customers can optionally use it when configuring security rules without having to adjust them.

[0097] A Local Peering Gateway (LPG) 132 is a gateway that can be added to a customer VCN 104 and enables the VCN 104 to peer with another VCN in the same region. Peering means that the VCNs communicate using private IP addresses and traffic does not need to cross a public network (such as the Internet) or be routed through the customer's on-premises network 116. In the preferred embodiment, the VCN has a separate LPG for each peer it establishes. Local peering or VCN peering is a common practice for establishing network connectivity between different applications or infrastructure management functions.

[0098] Service providers (such as providers of services in the service network 110) can provide access to services using different access models. According to the public access model, a service can be exposed as a public endpoint that can be publicly accessed by compute instances in the customer VCN via a public network (such as the Internet), and / or can be privately accessed via the SGW 126. According to a specific private access model, a service can be accessed as a private IP endpoint in a private subnet in the customer's VCN. This is referred to as Private Endpoint (PE) access and enables the service provider to expose its service as an instance in the customer's private network. A private endpoint resource represents a service within the customer's VCN. Each PE appears as a VNIC (referred to as a PE-VNIC, with one or more private IPs) in a subnet chosen by the customer in the customer's VCN. Thus, the PE provides a way to present a service in a private customer VCN subnet using a VNIC. Since the endpoint is exposed as a VNIC, all the features associated with the VNIC (such as routing rules, security lists, etc.) can now be used for the PE VNIC.

[0099] Service providers can register their services to enable access through the PE. The provider can associate policies with the service, which limit the visibility of the service to the customer's tenancy. The provider can register multiple services under a single Virtual IP Address (VIP), especially for multi-tenant services. There can be multiple such private endpoints (in multiple VCNs) representing the same service.

[0100] Compute instances in the private subnet can then access the service using the private IP address of the PE VNIC or the service DNS name. Compute instances in the customer VCN can access the service by sending traffic to the private IP address of the PE in the customer VCN. The Private Access Gateway (PAGW) 130 is a gateway resource that can be attached to a service provider VCN (e.g., a VCN in the service network 110), which serves as the ingress / egress point for all traffic to / from the private endpoints of the customer subnets. The PAGW 130 enables the provider to scale the number of PE connections without utilizing its internal IP address resources. The provider only needs to configure one PAGW for any number of services registered in a single VCN. The provider can represent a service as private endpoints in multiple VCNs of one or more customers. From the customer's perspective, the PE VNIC is not attached to the customer's instance but appears to be attached to the service that the customer wishes to interact with. Traffic going to the private endpoint is routed to the service via the PAGW 130. These are called customer-to-service private connections (C2S connections).

[0101] By allowing traffic to flow through the FastConnect / IPsec link and the private endpoints in the customer VCN, the PE concept can also be used to extend private access for services to the customer's on-premises networks and data centers. By allowing traffic to flow between the LPG 132 and the PE in the customer's VCN, private access to the service can also be extended to the customer's peered VCNs.

[0102] The customer can control routing in the VCN at the subnet level, so the customer can specify which subnets in the customer's VCN (such as VCN 104) use each gateway. The routing table of the VCN is used to decide whether to allow traffic to leave the VCN through a specific gateway. For example, in a particular instance, the routing table for the public subnet within the customer VCN 104 can send non-local traffic through the IGW 120. The routing table for the private subnet within the same customer VCN 104 can send traffic destined for the CSP service through the SGW 126. All remaining traffic can be sent via the NAT gateway 128. The routing table only controls traffic flowing out of the VCN.

[0103] The security list associated with the VCN is used to control the traffic entering the VCN via the gateway through inbound connections. All resources in a subnet use the same route table and security list. The security list can be used to control specific types of traffic to and from the instances in the subnet of the VCN. Security list rules can include ingress (inbound) and egress (outbound) rules. For example, the ingress rule can specify the allowed source address range, while the egress rule can specify the allowed destination address range. Security rules can specify a particular protocol (e.g., TCP, ICMP), a particular port (e.g., 22 for SSH, 3389 for Windows RDP), etc. In some embodiments, the operating system of the instance can enforce its own firewall rules that comply with the security list rules. The rules can be stateful (e.g., tracking connections and automatically allowing responses without an explicit security list rule for the response traffic) or stateless.

[0104] Access from the customer VCN (i.e., through resources or compute instances deployed on VCN 104) can be classified as public access, private access, or dedicated access. Public access refers to an access model that uses a public IP address or NAT to access public endpoints. Private access enables customer workloads with private IP addresses in VCN 104 (e.g., resources in a private subnet) to access services without traversing a public network such as the Internet. In some embodiments, CSPI 101 enables customer VCN workloads with private IP addresses to access the public service endpoints of services using a service gateway. Thus, the service gateway provides a private access model by establishing a virtual link between the customer's VCN and the public endpoints of the services residing outside the customer's private network.

[0105] In addition, CSPI can provide dedicated public access using technologies such as FastConnect public peering, where customer on-premises instances can use FastConnect connections to access one or more services in the customer VCN without traversing a public network such as the Internet. CSPI can also provide dedicated private access using FastConnect private peering, where customer on-premises instances with private IP addresses can use FastConnect connections to access the customer's VCN workloads. FastConnect is a network connectivity alternative to using the public Internet to connect the customer's on-premises network to CSPI and its services. Compared to Internet-based connections, FastConnect provides a simple, flexible, and cost-effective way to create dedicated and private connections with higher bandwidth options and a more reliable and consistent network experience.

[0106] Figure 1The above - mentioned accompanying description describes various virtualized components in an example virtual network. As described above, the virtual network is built on an underlying physical or substrate network. Figure 2 FIG. depicts a simplified architecture diagram of physical components in a physical network within CSPI 200 that provides the underlying layer for a virtual network according to certain embodiments. As shown, CSPI 200 provides a distributed environment that includes components and resources (e.g., computing, memory, and network resources) provided by a cloud service provider (CSP). These components and resources are used to provide cloud services (e.g., IaaS services) to subscribing customers (i.e., customers who have subscribed to one or more services provided by the CSP). Based on the services subscribed to by the customer, a subset of the resources of CSPI 200 (e.g., computing, memory, and network resources) are provisioned for the customer. Then, the customer can use the physical computing, memory, and networking resources provided by CSPI 200 to build their own cloud - based (i.e., CSPI - hosted) customizable and private virtual network. As previously indicated, these customer networks are referred to as virtual cloud networks (VCNs). The customer can deploy one or more customer resources, such as computing instances, on these customer VCNs. The computing instances can be in the form of virtual machines, bare - metal instances, etc. CSPI 200 provides the infrastructure and a set of complementary cloud services that enable customers to build and run a wide range of applications and services in a highly available hosted environment.

[0107] In Figure 2 the example embodiment depicted in, the physical components of CSPI 200 include one or more physical host machines or physical servers (e.g., 202, 206, 208), network virtualization devices (NVDs) (e.g., 210, 212), top - of - rack (TOR) switches (e.g., 214, 216), and a physical network (e.g., 218), as well as switches in the physical network 218. The physical host machines or servers can host and execute various computing instances that participate in one or more subnets of the VCN. The computing instances can include virtual machine instances and bare - metal instances. For example, Figure 1 the various computing instances depicted in Figure 2 are hosted by the physical host machines depicted in. The virtual machine computing instances in the VCN can be executed by one host machine or multiple different host machines. The physical host machines can also host virtual host machines, container - based hosts, or functions, etc. Figure 1 the VNICs and VCN VRs depicted in Figure 2 are executed by the NVDs depicted in. Figure 1 the gateways depicted in Figure 2 are executed by the host machines and / or NVDs described in.

[0108] A host machine or server can execute a hypervisor (also known as a virtual machine monitor or VMM) that creates and enables a virtualized environment on the host machine. Virtualization or the virtualized environment facilitates cloud-based computing. One or more computing instances can be created, executed, and managed by the hypervisor on the host machine. The hypervisor on the host machine enables the physical computing resources of the host machine (e.g., computing, memory, and network resources) to be shared among various computing instances executed by the host machine.

[0109] For example, as Figure 2 depicted in, host machines 202 and 208 execute hypervisors 260 and 266 respectively. These hypervisors can be implemented using software, firmware, hardware, or a combination thereof. Generally, a hypervisor is a process or software layer located above the operating system (OS) of the host machine, and the OS in turn executes on the hardware processor of the host machine. The hypervisor provides a virtualized environment by enabling the physical computing resources of the host machine (e.g., processing resources such as processors / cores, memory resources, network resources) to be shared among various virtual machine computing instances executed by the host machine. For example, in Figure 2 , hypervisor 260 can be located above the OS of host machine 202 and enable the computing resources of host machine 202 (e.g., processing, memory, and network resources) to be shared among computing instances (e.g., virtual machines) executed by host machine 202. A virtual machine can have its own operating system (referred to as a guest operating system), which can be the same as or different from the OS of the host machine. The operating system of a virtual machine executed by a host machine can be the same as or different from the operating system of another virtual machine executed by the same host machine. Thus, the hypervisor enables multiple operating systems to be executed simultaneously while sharing the same computing resources of the host machine. Figure 2 The host machines depicted in can have the same or different types of hypervisors.

[0110] A computing instance can be a virtual machine instance or a bare-metal instance. In Figure 2 , computing instances 268 on host machine 202 and computing instance 274 on host machine 208 are examples of virtual machine instances. Host machine 206 is an example of a bare-metal instance provided to a customer.

[0111] In some cases, an entire host machine can be provisioned to a single customer, and one or more compute instances (either virtual machines or bare metal instances) hosted by that host machine all belong to the same customer. In other cases, the host machine can be shared among multiple customers (i.e., multiple tenants). In such a multi-tenant scenario, the host machine can host virtual machine compute instances belonging to different customers. These compute instances can be members of different VCNs of different customers. In some embodiments, bare metal compute instances are hosted by bare metal servers without a hypervisor. When provisioning a bare metal compute instance, a single customer or tenant maintains control over the physical CPUs, memory, and network interfaces of the host machine hosting the bare metal instance, and the host machine is not shared with other customers or tenants.

[0112] As previously described, each compute instance that is part of a VCN is associated with a VNIC that enables the compute instance to be a member of a subnet of the VCN. The VNIC associated with a compute instance facilitates the communication of data packets or frames to and from the compute instance. The VNIC is associated with the compute instance when the compute instance is created. In some embodiments, for a compute instance executed by a host machine, the VNIC associated with the compute instance is executed by an NVD connected to the host machine. For example, in Figure 2 the embodiment depicted in, host machine 202 executes virtual machine compute instance 268 associated with VNIC 276, and VNIC 276 is executed by NVD 210 connected to host machine 202. As another example, bare metal instance 272 hosted by host machine 206 is associated with VNIC 280 executed by NVD 212 connected to host machine 206. As yet another example, VNIC 284 is associated with compute instance 274 executed by host machine 208, and VNIC 284 is executed by NVD 212 connected to host machine 208.

[0113] For a compute instance hosted by a host machine, the NVD connected to that host machine also executes a VCN VR corresponding to the VCN of which the compute instance is a member. For example, in Figure 2 the embodiment depicted in, NVD 210 executes VCN VR 277 corresponding to the VCN of which compute instance 268 is a member. NVD 212 can also execute one or more VCN VRs 283 corresponding to the VCNs corresponding to the compute instances hosted by host machines 206 and 208.

[0114] The host machine may include one or more network interface cards (NICs) that enable the host machine to connect to other devices. The NICs on the host machine may provide one or more ports (or interfaces) that enable the host machine to communicate and connect to another device. For example, the host machine may connect to the NVD using one or more ports (or interfaces) provided on the host machine and on the NVD. The host machine may also connect to other devices (such as another host machine).

[0115] For example, in Figure 2 , host machine 202 is connected to NVD 210 using link 220, which extends between port 234 provided by NIC 232 of host machine 202 and port 236 of NVD 210. Host machine 206 is connected to NVD 212 using link 224, which extends between port 246 provided by NIC 244 of host machine 206 and port 248 of NVD 212. Host machine 208 is connected to NVD 212 using link 226, which extends between port 252 provided by NIC 250 of host machine 208 and port 254 of NVD 212.

[0116] The NVDs are in turn connected via communication links to top-of-rack (TOR) switches, which are connected to the physical network 218 (also referred to as the switch fabric). In some embodiments, the links between the host machines and the NVDs and between the NVDs and the TOR switches are Ethernet links. For example, in Figure 2 , NVDs 210 and 212 are connected to TOR switches 214 and 216 using links 228 and 230, respectively. In some embodiments, links 220, 224, 226, 228, and 230 are Ethernet links. The collection of host machines and NVDs connected to the TOR is sometimes referred to as a rack.

[0117] The physical network 218 provides a communication fabric that enables the TOR switches to communicate with each other. The physical network 218 may be a multi-layer network. In some implementations, the physical network 218 is a multi-layer Clos network of switches, where TOR switches 214 and 216 represent the leaf-level nodes of the multi-layer and multi-node physical switching network 218. Different Clos network configurations are possible, including but not limited to 2-layer networks, 3-layer networks, 4-layer networks, 5-layer networks, and general "n"-layer networks. Examples of Clos networks are depicted in Figure 5 and described below.

[0118] There may be various different connection configurations between the host machines and the NVDs, such as one-to-one configurations, many-to-one configurations, one-to-many configurations, etc. In a one-to-one configuration implementation, each host machine is connected to its own separate NVD. For example, inFigure 2 In [description], the host machine 202 is connected to the NVD 210 via the NIC 232 of the host machine 202. In a multi-to-one configuration, multiple host machines are connected to one NVD. For example, in Figure 2 [description], the host machines 206 and 208 are connected to the same NVD 212 via the NICs 244 and 250 respectively.

[0119] In a one-to-many configuration, one host machine is connected to multiple NVDs. Figure 3 An example within the CSPI 300 is shown, where a host machine is connected to multiple NVDs. As Figure 3 shown in [description], the host machine 302 includes a network interface card (NIC) 304, which includes multiple ports 306 and 308. The host machine 300 is connected to the first NVD 310 via the port 306 and the link 320, and is connected to the second NVD 312 via the port 308 and the link 322. The ports 306 and 308 can be Ethernet ports and the links 320 and 322 between the host machine 302 and the NVDs 310 and 312 can be Ethernet links. The NVD 310 is further connected to the first TOR switch 314 and the NVD 312 is connected to the second TOR switch 316. The links between the NVDs 310 and 312 and the TOR switches 314 and 316 can be Ethernet links. The TOR switches 314 and 316 represent layer 0 switching devices in the multi-layer physical network 318.

[0120] Figure 3 The arrangement depicted in [description] provides two separate physical network paths from the physical switch network 318 to the host machine 302: the first path passes through the TOR switch 314 to the NVD 310 and then to the host machine 302, and the second path passes through the TOR switch 316 to the NVD 312 and then to the host machine 302. The separate paths provide enhanced availability (referred to as high availability) for the host machine 302. If there is a problem with a path (e.g., a link in one of the paths is broken) or a device (e.g., a particular NVD is not operating), then the other path can be used for communication with the host machine 302.

[0121] In Figure 3 the configuration depicted in [description], the host machine uses two different ports provided by the NIC of the host machine to connect to two different NVDs. In other embodiments, the host machine can include multiple NICs that enable the host machine to connect to multiple NVDs.

[0122] Referring back to Figure 2, an NVD is a physical device or component that performs one or more network and / or storage virtualization functions. An NVD can be any device having one or more processing units (e.g., CPU, network processing unit (NPU), FPGA, packet processing pipeline, etc.), memory (including caches), and ports. Various virtualization functions can be performed by software / firmware executed by one or more processing units of the NVD.

[0123] The NVD can be implemented in various different forms. For example, in some embodiments, the NVD is implemented as an interface card called a smartNIC or a smart NIC with an on-board embedded processor. A smartNIC is a device independent of the NIC on the host machine. In Figure 2 , the NVDs 210 and 212 can be implemented as smartNICs respectively connected to the host machine 202 and the host machines 206 and 208.

[0124] However, a smartNIC is just one example of an NVD implementation. Various other implementations are possible. For example, in some other implementations, the NVD or one or more functions performed by the NVD can be incorporated into or performed by one or more host machines, one or more TOR switches, and other components of the CSPI 200. For example, the NVD can be implemented in a host machine, where the functions performed by the NVD are performed by the host machine. As another example, the NVD can be part of a TOR switch, or the TOR switch can be configured to perform the functions performed by the NVD, which enables the TOR switch to perform various complex packet conversions for a public cloud. A TOR that performs the functions of an NVD is sometimes referred to as a smart TOR. In other implementations that provide virtual machine (VM) instances rather than bare metal (BM) instances to customers, the functions performed by the NVD can be implemented inside the hypervisor of the host machine. In some other implementations, some of the functions of the NVD can be offloaded to a centralized service running on a group of host machines.

[0125] In some embodiments, such as when implemented as a smartNIC as shown in Figure 2 , the NVD can include multiple physical ports that enable it to connect to one or more host machines and one or more TOR switches. The ports on the NVD can be classified as host-facing ports (also referred to as "south ports") or network-facing or TOR-facing ports (also referred to as "north ports"). The host-facing ports of the NVD are the ports used to connect the NVD to the host machine. Figure 2 Examples of the host-facing ports inFigure 2 Examples of network-facing ports include port 256 on the NVD 210 and port 258 on the NVD 212. As Figure 2 shown, the NVD 210 is connected to the TOR switch 214 using a link 228 that extends from port 256 of the NVD 210 to the TOR switch 214. Similarly, the NVD 212 is connected to the TOR switch 216 using a link 230 that extends from port 258 of the NVD 212 to the TOR switch 216.

[0126] The NVD receives packets and frames (e.g., packets and frames generated by a compute instance hosted by the host machine) from the host machine via the host-facing port, and after performing necessary packet processing, can forward the packets and frames to the TOR switch via the network-facing port of the NVD. The NVD can receive packets and frames from the TOR switch via the network-facing port of the NVD, and after performing necessary packet processing, can forward the packets and frames to the host machine via the host-facing port of the NVD.

[0127] In some embodiments, there can be multiple ports and associated links between the NVD and the TOR switch. These ports and links can be aggregated to form a link aggregation group (referred to as a LAG) of multiple ports or links. Link aggregation allows multiple physical links between two endpoints (e.g., between the NVD and the TOR switch) to be treated as a single logical link. All physical links in a given LAG can operate at the same speed in full-duplex mode. LAG helps increase the bandwidth and reliability of the connection between two endpoints. If one of the physical links in the LAG fails, then traffic will be dynamically and transparently re-assigned to one of the other physical links in the LAG. The aggregated physical links deliver a higher bandwidth than each individual link. The multiple ports associated with the LAG are treated as a single logical port. Traffic can be load-balanced across the multiple physical links of the LAG. One or more LAGs can be configured between two endpoints. These two endpoints can be located between the NVD and the TOR switch, between the host machine and the NVD, and so on.

[0128] The NVD implements or executes network virtualization functions. These functions are executed by the software / firmware executed by the NVD. Examples of network virtualization functions include, but are not limited to: packet encapsulation and decapsulation functions; functions for creating VCN networks; functions for implementing network policies, such as VCN security list (firewall) functionality; functions for facilitating packet routing and forwarding to and from compute instances in the VCN; and so on. In some embodiments, upon receiving a packet, the NVD is configured to execute a packet processing pipeline to process the packet and determine how to forward or route the packet. As part of this packet processing pipeline, the NVD can execute one or more virtual functions associated with the overlay network, such as executing a VNIC associated with a compute instance in the VCN, executing a virtual router (VR) associated with the VCN, encapsulating and decapsulating packets to facilitate forwarding or routing in the virtual network, executing certain gateways (e.g., local peer gateways), implementing security lists, network security groups, network address translation (NAT) functionality (e.g., translating public IPs to private IPs on a per-host basis), throttling functions, and other functions.

[0129] In some embodiments, the packet processing data path in the NVD can include multiple packet pipelines, each pipeline consisting of a series of packet transformation stages. In some implementations, upon receiving a packet, the packet is parsed and classified into a single pipeline. The packet is then processed linearly, stage by stage, until the packet is either discarded or sent out through an interface of the NVD. These stages provide basic functional packet processing building blocks (e.g., validating headers, enforcing throttling, inserting new layer 2 headers, enforcing L4 firewalls, VCN encapsulation / decapsulation, etc.) so that new pipelines can be constructed by combining existing stages, and new functionality can be added by creating new stages and inserting them into existing pipelines.

[0130] The NVD can execute control plane and data plane functions corresponding to the control plane and data plane of the VCN. Examples of the VCN control plane are also depicted in Figure 12 , Figure 13 , Figure 14 and Figure 15 (see reference numerals 1216, 1316, 1416, and 1516) and described below. Examples of the VCN data plane are in Figure 12 , Figure 13 , Figure 14 and Figure 15Depicted (see reference numerals 1218, 1318, 1418, and 1518) and described below. The control plane functions include functions for configuring the network for how control data is forwarded (e.g., setting up routes and routing tables, configuring VNICs, etc.). In some embodiments, a VCN control plane is provided that centrally computes all overlay-to-substrate mappings and publishes them to the NVD and virtual network edge devices (such as various gateways, such as DRG, SGW, IGW, etc.). Firewall rules can also be published using the same mechanism. In some embodiments, the NVD only obtains the mappings relevant to that NVD. The data plane functions include functions for actually routing / forwarding data packets based on the configuration set using the control plane. The VCN data plane is implemented by encapsulating the customer's network packets before they cross the substrate network. The encapsulation / decapsulation functionality is implemented on the NVD. In some embodiments, the NVD is configured to intercept all network packets going in and out of the host machine and perform network virtualization functions.

[0131] As indicated above, the NVD performs various virtualization functions, including VNIC and VCN VR. The NVD can perform the VNIC associated with a computing instance hosted by one or more host machines connected to the VNIC. For example, as Figure 2 depicted, the NVD 210 performs the functionality of the VNIC 276 associated with the computing instance 268 hosted by the host machine 202 connected to the NVD 210. As another example, the NVD 212 performs the VNIC 280 associated with the bare-metal computing instance 272 hosted by the host machine 206 and performs the VNIC 284 associated with the computing instance 274 hosted by the host machine 208. The host machine can host computing instances belonging to different VCNs (belonging to different customers), and the NVD connected to the host machine can perform the VNIC corresponding to the computing instance (i.e., perform VNIC-related functionality).

[0132] The NVD also performs the VCN virtual router corresponding to the VCN of the computing instance. For example, in the Figure 2 embodiment depicted, the NVD 210 performs the VCN VR 277 corresponding to the VCN to which the computing instance 268 belongs. The NVD 212 performs one or more VCN VRs 283 corresponding to one or more VCNs to which the computing instances hosted by the host machines 206 and 208 belong. In some embodiments, the VCN VR corresponding to the VCN is performed by all NVDs connected to the host machine hosting at least one computing instance belonging to that VCN. If the host machine hosts computing instances belonging to different VCNs, then the NVD connected to that host machine can perform the VCN VRs corresponding to those different VCNs.

[0133] In addition to VNICs and VCN VRs, the NVD can execute various software (e.g., daemons) and includes one or more hardware components that facilitate the various network virtualization functions performed by the NVD. For simplicity, these various components are grouped together as the Figure 2 "packet processing components" shown in. For example, NVD 210 includes packet processing component 286 and NVD 212 includes packet processing component 288. For example, the packet processing components for the NVD can include a packet processor that is configured to interact with the ports and hardware interfaces of the NVD to monitor all packets received by and transmitted using the NVD and store network information. The network information can include, for example, network flow information identifying different network flows handled by the NVD and per-flow information (e.g., per-flow statistics) for each flow. In some embodiments, the network flow information can be stored on a per-VNIC basis. The packet processor can perform per-packet manipulation and implement stateful NAT and L4 firewall (FW). As another example, the packet processing component can include a replication agent configured to copy the information stored by the NVD to one or more different replication target repositories. As yet another example, the packet processing component can include a logging agent configured to perform the logging function of the NVD. The packet processing component can also include software for monitoring the performance and health of the NVD and also potentially monitoring the state and health of other components connected to the NVD.

[0134] Figure 1 Shows the components of an example virtual or overlay network, including a VCN, subnets within the VCN, compute instances deployed on the subnets, VNICs associated with the compute instances, a VR for the VCN, and a set of gateways configured for the VCN. Figure 1 The overlay components depicted in can be executed or hosted by one or more of the Figure 2 physical components depicted in. For example, a compute instance in a VCN can be executed or hosted by one or more of the Figure 2 host machines depicted in. For a compute instance hosted by a host machine, the VNIC associated with that compute instance is typically executed by an NVD connected to that host machine (i.e., VNIC functionality is provided by the NVD connected to that host machine). The VCN VR functionality for a VCN is executed by all NVDs connected to the host machine that hosts or executes the compute instances that are part of that VCN. Gateways associated with a VCN can be executed by one or more different types of NVDs. For example, some gateways can be executed by a smartNIC, while other gateways can be executed by one or more host machines or other implementations of the NVD.

[0135] As described above, the compute instances in the customer VCN can communicate with a variety of different endpoints, where the endpoints can be within the same subnet as the source compute instance, in different subnets but within the same VCN as the source compute instance, or communicate with endpoints located outside the VCN of the source compute instance. The VNIC associated with the compute instance, the VCN VR, and the gateways associated with the VCN are used to facilitate these communications.

[0136] For communication between two compute instances on the same subnet in a VCN, the VNICs associated with the source and destination compute instances are used to facilitate the communication. The source and destination compute instances can be hosted by the same host machine or different host machines. Packets originating from the source compute instance can be forwarded from the host machine hosting the source compute instance to the NVD connected to that host machine. At the NVD, the packets are processed using the packet processing pipeline, which can include the execution of the VNIC associated with the source compute instance. Since the destination endpoint for the packets is within the same subnet, the execution of the VNIC associated with the source compute instance causes the packets to be forwarded to the NVD that executes the VNIC associated with the destination compute instance, and then the NVD processes the packets and forwards them to the destination compute instance. The VNICs associated with the source and destination compute instances can be executed on the same NVD (e.g., when the source and destination compute instances are hosted by the same host machine) or on different NVDs (e.g., when the source and destination compute instances are hosted by different host machines connected to different NVDs). The VNIC can use the routing / forwarding table stored by the NVD to determine the next hop for the packets.

[0137] For packets to be transmitted from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, the packet originating from the source compute instance is transmitted from the host machine hosting the source compute instance to the NVD connected to that host machine. At the NVD, the packet is processed using a packet processing pipeline, which can include the execution of one or more VNICs and the VR associated with the VCN. For example, as part of the packet processing pipeline, the NVD executes or invokes the functionality corresponding to the VNIC associated with the source compute instance (also referred to as executing the VNIC). The functionality executed by the VNIC can include examining the VLAN tag on the packet. Since the destination of the packet is outside the subnet, the NVD then calls and executes the VCN VR functionality. The VCN VR then routes the packet to the NVD that executes the VNIC associated with the destination compute instance. The VNIC associated with the destination compute instance then processes the packet and forwards the packet to the destination compute instance. The VNICs associated with the source and destination compute instances can be executed on the same NVD (e.g., when the source and destination compute instances are hosted by the same host machine) or on different NVDs (e.g., when the source and destination compute instances are hosted by different host machines connected to different NVDs).

[0138] If the destination for the packet is outside the VCN of the source compute instance, then the packet originating from the source compute instance is transmitted from the host machine hosting the source compute instance to the NVD connected to that host machine. The NVD executes the VNIC associated with the source compute instance. Since the destination endpoint of the packet is outside the VCN, the packet is then processed by the VCN VR for that VCN. The NVD calls the VCN VR functionality, which causes the packet to be forwarded to the NVD that executes the appropriate gateway associated with the VCN. For example, if the destination is an endpoint within the customer's on-premises network, then the packet can be forwarded by the VCN VR to the NVD that executes the DRG gateway configured for the VCN. The VCN VR can be executed on the same NVD as the NVD that executes the VNIC associated with the source compute instance, or by a different NVD. The gateway can be executed by the NVD, which can be a smartNIC, a host machine, or other NVD implementations. The packet is then processed by the gateway and forwarded to the next hop, which facilitates the transmission of the packet to its intended destination endpoint. For example, in Figure 2In the illustrated embodiment, data packets originating from compute instance 268 can be transferred from host machine 202 to NVD 210 via link 220 (using NIC 232). At NVD 210, VNIC 276 is invoked because it is the VNIC associated with source compute instance 268. VNIC 276 is configured to inspect the information encapsulated in the data packet and determine the next hop for forwarding the data packet, with the aim of facilitating the transfer of the data packet to its intended destination endpoint, and then forwarding the data packet to the determined next hop.

[0139] Compute instances deployed on a VCN can communicate with a variety of different endpoints. These endpoints can include endpoints hosted by CSPI 200 and endpoints external to CSPI 200. Endpoints hosted by CSPI 200 can include instances in the same VCN or other VCNs, which can be the customer's VCNs or VCNs that do not belong to the customer. Communication between endpoints hosted by CSPI 200 can be performed via physical network 218. Compute instances can also communicate with endpoints that are not hosted by CSPI 200 or are external to CSPI 200. Examples of these endpoints include endpoints or data centers within the customer's on-premises network, or public endpoints accessible via a public network (such as the Internet). Communication with endpoints external to CSPI 200 can be performed via a public network (e.g., the Internet) ( Figure 2 not shown in [[]] Figure 2 not shown in [[]]

[0140] Figure 2 The architecture of CSPI 200 depicted in [[]] Figure 2 Figure 2 is merely an example and is not intended to be limiting. In alternative embodiments, variations, substitutions, and modifications are possible. For example, in some implementations, CSPI 200 can have more or fewer systems or components than Figure 2 the systems or components shown in [[]]

[0141] Figure 4 depicts the connection between a host machine and an NVD according to certain embodiments for providing I / O virtualization to support multi-tenancy. As Figure 4 ​As depicted in, host machine 402 executes hypervisor 404 that provides a virtualized environment. Host machine 402 executes two virtual machine instances, VM1 406 belonging to customer / tenant #1 and VM2 408 belonging to customer / tenant #2. Host machine 402 includes physical NIC 410 connected to NVD 412 via link 414. Each computing instance is attached to a VNIC executed by NVD 412. In Figure 4 the embodiment of, VM1 406 is attached to VNIC-VM1 420 and VM2 408 is attached to VNIC-VM2 422.

[0142] As Figure 4 shown in, NIC 410 includes two logical NICs, logical NIC A 416 and logical NIC B 418. Each virtual machine is attached to its own logical NIC and is configured to work with its own logical NIC. For example, VM1 406 is attached to logical NIC A 416 and VM2 408 is attached to logical NIC B 418. Although host machine 402 includes only one physical NIC 410 shared by multiple tenants, due to the logical NICs, each tenant's virtual machine believes they have their own host machine and NIC.

[0143] In some embodiments, each logical NIC is assigned its own VLAN ID. Thus, a specific VLAN ID is assigned to logical NIC A 416 for tenant #1, and a separate VLAN ID is assigned to logical NIC B 418 for tenant #2. When a data packet is transmitted from VM1 406, the label assigned to tenant #1 is attached to the data packet by the hypervisor, and then the data packet is transmitted from host machine 402 to NVD 412 via link 414. In a similar manner, when a data packet is transmitted from VM2 408, the label assigned to tenant #2 is attached to the data packet by the hypervisor, and then the data packet is transmitted from host machine 402 to NVD 412 via link 414. Accordingly, data packet 424 transmitted from host machine 402 to NVD 412 has an associated label 426 that identifies the specific tenant and the associated VM. At NVD, for data packet 424 received from host machine 402, the label 426 associated with the data packet is used to determine whether the data packet is to be processed by VNIC-VM1 420 or by VNIC-VM2 422. The data packet is then processed by the corresponding VNIC. Figure 4 The configuration described in enables each tenant's computing instance to believe they have their own host machine and NIC. Figure 4 The setup described in provides I / O virtualization to support multi-tenancy.

[0144] Figure 5Depicts a simplified block diagram of a physical network 500 according to certain embodiments. Figure 5 The embodiment depicted in Figure 5 is structured as a Clos network. A Clos network is a particular type of network topology that is designed to provide connection redundancy while maintaining high bisection bandwidth and maximum resource utilization. A Clos network is a non-blocking, multi-stage or multi-layer switching network, where the number of stages or layers can be two, three, four, five, etc. Figure 5 The embodiment depicted in Figure 5 is a three-layer network, including Layer 1, Layer 2, and Layer 3. The TOR switch 504 represents the Layer 0 switch in the Clos network. One or more NVDs are connected to the TOR switch. The Layer 0 switch is also referred to as an edge device of the physical network. The Layer 0 switch is connected to the Layer 1 switches, also known as leaf switches. In Figure 5 the embodiment depicted in Figure 5 , a group of "n" Layer 0 TOR switches is connected to a group of "n" Layer 1 switches and together form a pod. Each Layer 0 switch in the pod is interconnected to all the Layer 1 switches in the pod, but there is no switch connectivity between pods. In certain implementations, two pods are referred to as a block. Each block is served by or connected to a group of "n" Layer 2 switches (sometimes referred to as spine switches). There can be several blocks in the physical network topology. The Layer 2 switches are in turn connected to "n" Layer 3 switches (sometimes referred to as super-spine switches). Communication of data packets over the physical network 500 is typically performed using one or more Layer 3 communication protocols. Generally, all layers of the physical network (except the TOR layer) are n-way redundant, thus allowing for high availability. Policies can be specified for pods and blocks to control the visibility of switches to each other in the physical network, thus enabling the scale of the physical network.

[0145] A characteristic of a Clos network is that the maximum number of hops reached from one Layer 0 switch to another Layer 0 switch (or from an NVD connected to a Layer 0 switch to another NVD connected to a Layer 0 switch) is fixed. For example, in a three-layer Clos network, a data packet requires at most seven hops to reach another NVD, where the source and destination NVDs are connected to the leaf layer of the Clos network. Similarly, in a four-layer Clos network, a data packet requires at most nine hops to reach another NVD, where the source and destination NVDs are connected to the leaf layer of the Clos network. Thus, the Clos network architecture maintains consistent latency throughout the network, which is important for communication within and between data centers. The Clos topology is horizontally scalable and cost-effective. The bandwidth / throughput capacity of the network can be easily increased by adding more switches at each layer (e.g., more leaf switches and backbone switches) and by increasing the number of links between switches in adjacent layers.

[0146] In some embodiments, each resource within CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the information for the resource and can be used to manage the resource, e.g., via the console or through an API. An example syntax for a CID is:

[0147] ocid1.<RESOURCE TYPE>. <realm>.[REGION][.FUTURE USE].<UNIQUE ID>

[0148] Among them,

[0149] ocid1: A text string indicating the version of the CID;

[0150] resource type: The type of the resource (e.g., instance, volume, VCN, subnet, user, group, etc.);

[0151] realm: The realm where the resource is located. Example values are "c1" for the commercial realm, "c2" for the government cloud realm, or "c3" for the federal government cloud realm, etc. Each realm can have its own domain name;

[0152] region: The region where the resource is located. If this region is not applicable to the resource, then this part may be empty;

[0153] future use: Reserved for future use.

[0154] unique ID: The unique part of the ID. The format can vary depending on the type of the resource or service.

[0155] Introduction to multi - cloud

[0156] Figure 6 Depicts a simplified high-level diagram of a distributed environment 600 according to certain embodiments, the distributed environment including multiple cloud environments provided by different cloud service providers (CSPs), where the cloud environments include a specific cloud environment providing specialized infrastructure that enables one or more cloud services provided by the specific cloud environment to be used by customers of other cloud environments. As Figure 6 depicted, various different cloud environments (also referred to as "clouds") can be provided by different cloud service providers (CSPs), and each cloud environment or cloud offering can include one or more cloud services subscribed to by one or more customers of the cloud environment. A set of cloud services provided by a cloud environment offering by a CSP can include one or more different types of cloud services, including but not limited to software as a service (SaaS) services, infrastructure as a service (IaaS) services, platform as a service (PaaS) services, database as a service (DBaaS) services, etc. Examples of cloud environments provided by various CSPs include Cloud Infrastructure (OCI) provided by Oracle Corporation, Azure provided by Microsoft Corporation, TM , Amazon Web Services provided by Amazon Corporation and so on. Cloud services provided by a particular cloud environment can be different from a set of cloud services provided by another cloud environment.

[0157] In a typical cloud environment, a CSP provides cloud service provider infrastructure (CSPI) for providing one or more cloud services provided by that cloud environment to its customers. The CSPI provided by the CSP can include various types of hardware and software resources, including computing resources, memory resources, networking resources, consoles for accessing cloud services, etc. Customers of the cloud environment provided by the CSP can subscribe to one or more of the cloud services provided by that cloud environment. Various subscription models can be provided by the CSP to its customers. After a customer subscribes to a cloud service provided by a cloud environment, one or more users can be associated with the subscribing customer, and these users can use the cloud services subscribed to by the customer. In some embodiments, when a customer subscribes to a cloud service provided by a particular cloud environment, a customer account or customer lease is created for that customer. One or more users can then be associated with the customer lease, and these users can then use the services subscribed to by the customer under the customer lease. Information about the services subscribed to by the customer, the users associated with the customer lease, etc. is typically stored within the cloud environment and associated with the customer lease.

[0158] For example, Figure 6 depicts three different cloud environments provided by three different CSPs. These include cloud environment A (Cloud A) 610 provided by CSP A, cloud environment B (Cloud B) 640 provided by CSP B, and cloud environment C (Cloud C) 660 provided by CSP C. Cloud A 610 includes infrastructure CSPI_A 612 provided by CSP A, and this infrastructure can be used to provide a set of services "Service A" 614 provided by Cloud A 610. One or more customers (e.g., Cust_A1 616-1, Cust_A2 616-2) can subscribe to one or more of the services A 614 provided by Cloud A 610. One or more users 618-1 can be associated with customer A1 616-1, and can use the services subscribed to by customer A1 616-1 in Cloud A 610. In a similar manner, one or more users 618-2 can be associated with customer A2 616-2, and can use the services subscribed to by customer A2 616-2 in Cloud A 610. In various use cases, the services subscribed to by customer A1 616-1 can be different from the services subscribed to by customer A2 616-2.

[0159] As Figure 6 As depicted, cloud B 640 includes infrastructure CSPI_B 642 provided by CSP B, and this infrastructure can be used to provide a set of services "Service B" 644 supplied by cloud B 640. One or more customers (e.g., Cust_B1 646-1) can subscribe to one or more of the services in Service B 644. One or more users 648-1 can be associated with customer B1 646-1 and can use the services subscribed to by customer B1 646-1 in cloud B 640.

[0160] As Figure 6 As depicted, cloud C 660 includes infrastructure CSPI_C 662 provided by CSP C, and this infrastructure can be used to provide a set of services "Service C" 664 supplied by cloud C 660. One or more customers (e.g., Cust_C1 666-1) can subscribe to one or more of the services in Service C 664. One or more users 668-1 can be associated with customer C1 666-1 and can use the services subscribed to by customer C1 666-1 in cloud C 660. Note that Service A 614, Service B 644, and Service C 664 can be different from each other.

[0161] In existing cloud implementations, each cloud provides a closed ecosystem for its subscribing customers and associated users. Thus, the customers of a cloud environment and their associated users are limited to using the services supplied by the cloud subscribed to by that customer. For example, customer B1 646-1 and its users 648-1 are limited to using Service B 644 provided by cloud B 640 and cannot use their accounts in cloud B 640 to access services from different cloud environments, such as services in Service A 614 supplied by cloud A 610 or services in Service C 664 supplied by cloud C 660. The teachings described herein overcome this limitation. As described in this disclosure, various techniques are described that enable the creation of a link between two cloud environments, which enables the services provided by a first cloud environment provided by a first CSP to be used by the customers (and associated users) of a second different cloud environment provided by a second different CSP using the customer's account in the second cloud environment.

[0162] For example, in Figure 6 In the embodiments depicted, in addition to other infrastructure 620, the infrastructure CSPI_A 612 provided by CSP A also includes special infrastructure 622 (referred to as multi-cloud enabled infrastructure 622 or MEI 622 or multi-cloud infrastructure 622), which enables one or more services 614 supplied by Cloud A to be used by customers of other clouds (such as Cloud B 640 and C 660) and associated users using customer accounts in those other clouds. In certain embodiments, customers of Cloud B and C do not have to open separate accounts in Cloud A to use one or more of the services 614 supplied by Cloud A 610. Customer B1 646-1 of Cloud B 640 and associated users 648-1 can use their customer accounts or leases in Cloud B640 to use one or more of the services 614 provided by Cloud A 610. As another example, customer C1 666-1 of Cloud C 660 and associated users 668-1 can use their customer accounts or leases in Cloud C 660 to use one or more of the services 614 provided by Cloud A610.

[0163] In certain embodiments, MEI 622 enables the creation of links between Cloud A 610 and other clouds, where these links can be used by customers of other clouds and their associated users to access and use the services provided by Cloud A 610. This is shown symbolically in Figure 6 as link 670 created between Cloud A 610 and Cloud B 640, and link 672 created between Cloud A 610 and Cloud C660. Via link 670, customers of Cloud B 640 can access or use one or more of the services 614 provided by Cloud A 610. Similarly, via link 672, customers of Cloud C 660 can access or use one or more of the services 614 provided by Cloud A 610.

[0164] There are different ways to implement MEI 612. In certain embodiments, MEI 612 can include components that enable the creation of links with different clouds. For example, in Figure 6 MEI 622 includes infrastructure component 624 responsible for enabling link 670 with Cloud B 640, and infrastructure component 626 for enabling link 672 with Cloud C 660. In a similar manner, MEI622 can include other components that enable and facilitate links with other clouds. In some embodiments, the components of MEI 622 can also facilitate links with multiple different clouds.

[0165] There are several reasons why a customer of one cloud may want or expect to use cloud services provided by a different cloud. For Figure 6 For example, there can be multiple reasons why customer B1 646-1 of cloud B 640 may want to use cloud service 614 provided by cloud A 610. In one use case scenario, this can happen because cloud A 610 supplies a cloud service with functionality that cloud B 640 does not offer. As another use case scenario, cloud A and B can supply similar services, but the service provided by cloud A 610 can be better than the corresponding service supplied by cloud B 640 (e.g., more features / functionality, faster, etc.). As another use case scenario, customer B1 646-1 of cloud B 640 may want to use the cloud service provided by cloud A 610 because the price of that service is cheaper than that provided by cloud B 640. In some cases, there can be geographical restrictions or other reasons why customer B1 646-1 of cloud B 640 may want to use the cloud service provided by cloud A 610. For example, cloud A 610 can supply the desired service in a geographical area where cloud B 640 does not offer services, or cloud B 640 does not provide a specific service in the geographical area where the customer desires the service. There can also be several other use case scenarios for why a customer of one cloud may want to use services provided by a different cloud.

[0166] In certain embodiments, MEI 622 provides the ability and performs functions to create a link between cloud A 610 and another cloud, and via that link, enables a user associated with a customer of the other cloud to access and use the services provided by cloud A 610 in a seamless manner from the other cloud itself. For example, MEI 622 enables user 648-1 associated with customer B1 646-1 of cloud 640 to access the services in service A 614 supplied by cloud A 610 in a seamless manner. In certain implementations, a user interface (e.g., a console) that user 648-1 can access from within cloud B 640 can be provided, and this user interface enables the user to see a list of the services 614 provided by cloud A 610 and select a specific service that user 648-1 wishes to access. In response to the user selection, MEI 622 is responsible for performing the process of establishing link 670 between clouds A and B to enable access to the requested service. The process for setting up link 670 is basically automatically performed by MEI 622. Customer B1 646-1 or associated user 648-1 does not have to worry about performing any system, networking, or other configuration changes required to facilitate the creation, maintenance, and use of link 670 between clouds A 610 and B 640. There is no burden on the user or customer when creating a link between clouds. Using the techniques described in this disclosure, a link is created in a fast and efficient manner.

[0167] The MEI 622 can use various techniques to make the creation and use of the link seamless for users and customers, thereby providing an enhanced user experience. In some embodiments, the MEI 622 makes the user interface (e.g., graphical user interface GUI, etc.) and processing flow (such as for requesting services from cloud A 610 and for accessing the requested services from cloud A 610) with which customer B1 and associated user 648-1 interact substantially similar to the interface and processing flow that the customer / user would experience in cloud B 640. In this way, a customer or user who may be accustomed to the interface and processing flow of cloud B 640 does not have to learn a new interface and processing flow to access service 614 from cloud A 610. The MEI 622 can present different interfaces and processing flows to users in different cloud environments. For example, a first set of user interfaces and processes substantially similar to the user interface and processes of cloud B can be presented to users from cloud B 640, while another set of user interfaces and processes substantially similar to the user interface and processes of cloud C can be presented to users accessing cloud A 610 from cloud C 660. This is done to simplify and thus enhance the experience of users accessing service 614 of cloud A 610 from other clouds.

[0168] As another example, each cloud environment typically includes an identity management system configured to provide the security of the cloud environment. The identity management system is configured to protect resources in the cloud environment, including resources provided by the CSP and resources of subscribed cloud customers deployed in the cloud environment. Functions performed by the identity management system include, for example, managing identity credentials (e.g., usernames, passwords, etc.) associated with subscribed customers of the cloud and associated users, regulating user access to cloud resources and services using the identity credentials based on the permissions / access policies configured for the cloud environment, and other functions. Different clouds can use different identity management systems and associated technologies. For example, the identity management system and associated processes in cloud A 610 can be completely different from the identity management system and associated processes in cloud B 640, and the identity management system and associated processes in cloud B 640 can in turn be completely different from the identity management system and associated processes in cloud C 660. In some embodiments, although there are differences in the identity management systems and associated processes between different cloud environments, the techniques described herein enable users associated with customers of a first cloud to use the same identity credentials associated with the customers and users in the first cloud to access cloud services provided by different clouds.

[0169] For example, in Figure 6 In the depicted embodiment, cloud B 640 provided by CSP B may include an identity management system that assigns or allocates identity credentials to its subscribing customers and associated users, such as customer B1 646-1 and associated user 648-1. These identity credentials are associated with the lease created for customer B1 646-1 in cloud B 640. In certain embodiments, MEI 622 provided by cloud A 610 enables user 648-1 associated with cloud B customer B1 646-1 to access services from service A 614 in cloud A 610 using the identity credentials associated with user 648-1 and customer B1 646-1 in cloud B 640. This greatly enhances the user experience of user 648-1 as they do not have to create new identity credentials specific to cloud A 610 just to access services in cloud A 610. MEI 622 facilitates this access.

[0170] As an example, customer B1 of cloud B 640 may choose to use a service, such as database as a service (DBaaS), from a set of services 614 provided by cloud A 610. In response to such a choice, MEI 622 enables an automatic creation of a link 670 between cloud A 610 and cloud B 640 to enable user 648-1 associated with customer B1 646-1 to use the DBaaS service provided by cloud A 610. The automatic setup of link 670 is facilitated by MEI 622. After setting up link 670, user 668-1 may use the DBaaS service in cloud A 610 via cloud B 640. As part of using this service, user 668-1 may send a request to create a database resource to cloud A 610 via cloud B 640. In response, CSPI_A 612 may create the requested database in cloud A 610. In certain embodiments, the created database may be provisioned in a virtual network (e.g., virtual cloud network or VCN) created for customer B1 in cloud A 610 and accessible by user 668-1 via cloud B 640. Then, user 668-1 may send requests from cloud B 640 to cloud A 610 to use the provisioned database. These requests may include, for example, requests to write data to the database, update data stored in the database, delete data in the database, delete the database, create additional databases, etc. In some use cases, these requests may originate from user 668-1 or from service 644 provided by cloud B 640 via cloud B 640. In this way, MEI 622 provided by cloud A 610 enables users associated with customers of different clouds provided by different CSPs to seamlessly access services provided by cloud A 610.

[0171] Figure 6 The distributed environment 600 depicted is merely an example and is not intended to unduly limit the scope of the claimed embodiments. Many variations, alternatives, and modifications are possible. For example, in alternative embodiments, the distributed environment 600 may have more or fewer cloud environments. The cloud environment may also have more or fewer systems and components, or may have different configurations or arrangements of systems and components. Figure 6 The systems and components depicted may be implemented in software (e.g., code, instructions, programs) executed by one or more processing units (e.g., processors, cores) of the respective systems, using hardware, or a combination thereof. The software may be stored on a non-transitory storage medium (e.g., on a memory device).

[0172] Multi - cloud control plane (MCCP)

[0173] Figure 7 Depicts a high-level architecture of a multi-cloud infrastructure that interconnects two different cloud environments, each provided by a cloud service provider. As Figure 7 shown, the high-level architecture 700 includes a first cloud environment provided by a first cloud service provider (e.g., OCI) 710 and a second cloud environment provided by a second cloud service provider 720 (e.g., AWS). The first cloud environment 710 includes a multi-cloud infrastructure that provides the ability to deliver the services of the first cloud environment to users of other cloud environments (e.g., the second cloud environment 720). Specifically, as will be described below, the multi-cloud infrastructure includes a multi-cloud control plane (MCCP) 712 and a multi-cloud network data plane (MCNDP) 716, which provide users with the ability to access / manage the services (e.g., PaaS services) of the first cloud environment from another cloud environment.

[0174] The multi-cloud infrastructure provides a user experience as close as possible to the native cloud environment (e.g., the second cloud environment 720) of the user, while providing simple integration between cloud environments. Note that the MCCP 712 and the MCNDP 716 are components of the multi-cloud infrastructure that are deployed (and managed) by the first cloud service provider in the first cloud environment 710. In some embodiments, the multi-cloud infrastructure includes another component (i.e., the multi-cloud service account 726A), which is deployed in the second cloud environment 720 and managed by the first cloud service provider.

[0175] According to some embodiments, the second cloud environment 720 includes a customer account 721 and an account of a first cloud service provider (referred to herein as a multi-cloud account or multi-cloud service account 726A). Note that the second cloud environment 720 may also include a second cloud portal (not shown), which forms a centralized access point where customers of the second environment 720 can log in and manage their native cloud deployments and instances. The second cloud portal may provide options for monitoring and operating the services provided by the second cloud infrastructure. According to some embodiments, the second cloud environment 720 includes a provisioning module 722, a monitoring module 724, and an identity system 723, which includes an identity module 723A and an access control module 723B (i.e., also referred to herein as an identity and access management (IAM) module). Additionally, included in the customer account 721 is the customer's virtual private cloud (VPC) 725A, which may host one or more compute instances 725B. The identity module 723A is configured to perform tasks such as creating a set of one or more roles (and associated policies, permissions, etc. corresponding to the respective roles) for one or more users of the second cloud environment 720. In some implementations, the access control module 723B acts as a user directory for the second cloud environment. Specifically, the access control module 723B may be configured to create a user pool and perform functions such as adding user registrations, logins, and access control for web and mobile applications.

[0176] The provisioning module 722 corresponds to the services provided by the second cloud environment 720, which enables users to model and manage infrastructure resources in an automated and secure manner. For example, using the provisioning module 722, developers can define and provision infrastructure resources using infrastructure-as-code templates. In other words, the provisioning module 722 automates the prerequisite setup of resources in the customer account within the second cloud environment 720. As another example, the provisioning module 722 may also be configured to set up prerequisite resources that allow components of the first cloud environment to access resources in the customer account within the second cloud environment. According to certain embodiments, this is achieved by allowing the multi-cloud service account 726A to access resources in the customer account 721, for example, by making the multi-cloud service account peer with the customer account, allowing components of the multi-cloud infrastructure (e.g., an observability adapter for publishing metrics in the second cloud environment, etc.). The monitoring module 724 enables the monitoring of the entire stack (e.g., applications, infrastructure, network, and services) and uses alert, log, and event data to perform automated actions. The monitoring module 724 may also visually depict one or more metric data obtained from the first cloud environment using a dashboard (e.g., in a GUI).

[0177] The multi-cloud service account 726A includes a virtual private cloud 726B that hosts a transit gateway and a direct connect component. The direct connect component is a networking component that provides an alternative to using the Internet to consume cloud services of a second cloud environment. The direct connect enables a customer to establish a low-latency, secure, and private connection to the second cloud environment for workloads that require higher speed or lower latency than the Internet. The transit gateway is a networking hub that can be used to interconnect the VPC and an on-premises network. In some embodiments, the transit gateway in the multi-cloud service account 726A is used to peer (i.e., communicatively couple) with a customer account 721 in the second cloud environment 720.

[0178] The first cloud environment 710 includes an MCCP 712, a customer tenancy 714, and an MCNDP 716. As previously described, the MCCP 712 and the MCNDP 716 are parts of the multi-cloud infrastructure that provide access to the services offered by the first cloud environment 710 to users of other cloud environments (e.g., the second cloud environment 720), where the user experience is as close as possible to the user experience of the user's native cloud environment while providing simple integration between the cloud environments.

[0179] The first cloud environment 710 also includes a multi-cloud console 750 (different from the second cloud portal) that allows authenticated users in the second cloud infrastructure 720 to perform control plane operations on the resources of the first cloud infrastructure 710 exposed via the multi-cloud infrastructure. In other words, the multi-cloud console 750 forms a gateway for users of the second cloud environment 720 to access the resources deployed in the first cloud environment 710. It should be appreciated that the user 705 can directly issue requests (e.g., CRUD requests) for the resources offered by the first cloud infrastructure from the multi-cloud console 750.

[0180] The MCCP 712 included in the first cloud environment includes a plurality of microservices, such as a proxy module 712A, a platform service module 712B, and an adapter pool 712C. The adapter pool 712C includes cloud link adapters, database (DB) adapters, network adapters, observability adapters, and support adapters.

[0181] Each adapter included in the adapter pool 712C is responsible for exposing a unique set of underlying resources (provided by the first cloud environment) to users of other cloud environments (e.g., the second cloud environment). Specifically, each adapter in the adapter pool 712C is mapped to a specific product or resource provisioned by the first cloud infrastructure. In some embodiments, it should be noted that the actual resources may be created by the native control plane (not shown) of the first cloud infrastructure. The native control plane of the first cloud environment provides management and orchestration across cloud environments. Configuration baselines, user and role access provisioning, and application residency can be set here so that they can execute with associated services. For example, with respect to Database as a Service (DBaaS), the DBaaS control plane included in the native control plane of the first cloud environment is configured to instantiate Exa database resources in the customer lease 714 of the first cloud environment.

[0182] Requests issued by user 705 at the multi-cloud console 750 are routed to the proxy module 712A of the MCCP. It should be noted that the proxy module 712A processes incoming requests for authentication and access control. Each request includes a token (described below) associated with a user account in the second cloud infrastructure. The proxy module extracts the token and validates it with the access control module 723B (i.e., the identity provider system of the second cloud environment). After successful validation, the proxy module 712A can check the role (i.e., set of privileges) associated with the user. It should be noted that a role can be associated with one or more tasks / operations that the role is permitted to perform.

[0183] According to one embodiment, the proxy module 712A is responsible for authenticating incoming requests to the MCCP and authorizing whether the user is permitted to perform the requested operation based on the role associated with the token. In some embodiments, the proxy module 712A can perform the above authentication process by leveraging the custom authentication features of the service platform (SPLAT) associated with the first cloud infrastructure. It should be recognized that, generally speaking, SPLAT is the infrastructure that facilitates the delivery of various cloud services provided by a cloud service provider. SPLAT accepts incoming requests and forwards them to the proxy module 712A, which further parses the incoming requests to determine the authorization decision and returns a success or failure message to SPLAT. When successful, SPLAT can direct the request to the routing module, which directs the request to the appropriate adapter in the adapter pool, and when failed, SPLAT directly returns an error response to the caller.

[0184] According to one embodiment, the proxy module 712A receives a pre-authentication request from a service platform (i.e., SPLAT) of a first cloud environment and routes the request to an appropriate adapter based on the path information included in the incoming request. In some implementations, the proxy module may extract an identifier corresponding to the provider of the service (from the incoming request) and route the request to an appropriate adapter in the adapter pool 712C.

[0185] The cloud link adapter included in the MCCP 712 is responsible for handling the life cycle operations of the resources provided by the first cloud environment. The cloud link adapter is configured to create a mapping (or relationship created during the registration process) between a user's account in the second cloud environment and the corresponding lease / account of the user in the first cloud infrastructure. In other words, the cloud link adapter generates a mapping between a first identifier associated with the user's lease in the first cloud environment and a second identifier associated with the user's account in the second cloud environment.

[0186] In some embodiments, the cloud link adapter performs a conversion between an external cloud identifier (e.g., a second identifier associated with the user's account in the second cloud environment) and a first identifier (associated with the user's lease in the first cloud environment) so that the operations through the MCCP can be mapped to the appropriate underlying resources in the first cloud environment. In some embodiments, the cloud link adapter generates a data object to store the above mapping information. In addition, the cloud link adapter also generates a resource principal associated with the data object. One or more permissions are assigned to the resource principal based on the token (and its associated role) included in the request. The user accesses the downstream services provided by the first cloud environment from the second cloud infrastructure based on the resource principal. The cloud link adapter may store the data object and the associated resource principal in the root compartment of the user's lease in the first cloud infrastructure. Alternatively or additionally, the cloud link adapter may also persist the data object and the resource principal locally on the platform module 712B of the multi-cloud infrastructure for seamless access by other adapters included in the multi-cloud infrastructure.

[0187] The network adapter (also referred to as the network link adapter) is responsible for creating a network link (i.e., a communication link / channel) between the customer account 721 (in the second cloud environment) and the corresponding customer lease / account (in the first cloud environment) 714. According to some embodiments, the network link adapter obtains a token (from the platform module 712B) and creates (1) a first peer relationship between the MCNDP 716 and the customer lease 714 (in the first cloud environment), and (2) a second peer relationship between the customer account 721 and the multi-cloud service account 726A of the first cloud service provider 717 included in the second cloud environment (in the second cloud environment).

[0188] The MCNDP 716 in the first cloud environment 710 includes fast connect and hub and spoke VCNs that provision network connections (e.g., from an on-premises location, from an external cloud environment) to be established with the customer lease 714 in the first cloud environment. On the other hand, the transit gateway included in the multi-cloud service account peers with the customer account in the second cloud environment. The network adapter can be configured to communicatively couple the two cloud environments via the interconnect 719. Specifically, at one end, the interconnect is coupled to a direct connect (located in the multi-cloud service account 726A), and at the other end, the interconnect is coupled to the fast connect in the MCDP. It should be appreciated that the fast connect (including in the first cloud environment) and the direct connect included in the second cloud environment can co-reside in the same region. Further, after a network link is formed between the two cloud environments, applications executed in the customer account (e.g., in the customer VPC of the second cloud environment) are able to access resources such as Exa database resources deployed in the customer lease 714 of the first cloud environment. It should be appreciated that the network link communicatively couples the user's lease in the first cloud environment with the user's account in the second cloud environment.

[0189] As Figure 7 shown, the observability module (included in the adapter pool 712C) is configured to mirror or forward (e.g., publish) logs, metrics, and other performance parameters related to resources deployed in the customer tenant in the first cloud environment to a dashboard such as included in the monitoring module 724 included in the second cloud environment for further processing. According to some embodiments, the platform service module 712B included in the multi-cloud infrastructure is configured to store credentials associated with the services of the first cloud environment provided to users of the second cloud infrastructure. The platform service module 712B provides, for example, tokens / resource principals to different adapters included in the adapter pool 712C such that the adapters can communicate with the native control plane of the first cloud infrastructure. According to some embodiments, the platform service module 712B exposes APIs that are invoked by different adapters to perform tasks such as:

[0190] · Sell a minimal scope access token (issued by the second cloud infrastructure) to the adapter. For example, the network adapter needs an access token to perform the network peering operation described above.

[0191] · Provide a resource principal that the adapter will use to call downstream services to create resources in the customer lease of the first cloud infrastructure.

[0192] · Trigger the replication of observability data

[0193] (logs, metrics, events) from the first cloud infrastructure to the second cloud infrastructure.

[0194] As described above, the adapter pool 712C includes multiple adapters, each of which is responsible for exposing a unique set of underlying resources of the first cloud infrastructure to users of the second cloud infrastructure, i.e., each adapter is mapped to a specific product or resource provisioned by the first cloud environment. For example, the Exa Database adapter acts as a proxy for users of the second cloud infrastructure to create and utilize Exa Database resources. Exa Database is a preconfigured combination of hardware and software that provides the infrastructure for executing databases. According to some embodiments, Exa Database includes a set of resources: (a) Exadata infrastructure (i.e., hardware), (b) VM cloud clusters, (c) container databases, and (d) pluggable databases. According to some embodiments, the multi-cloud infrastructure provides the ability (for users of the second cloud infrastructure) to analyze each level of the stacked infrastructure. Moreover, MCCP provides flexibility to users, who only need to issue a creation command for a workflow (via the multi-cloud console 750), after which MCCP automatically creates the respective resources at each level of the stack. It should be recognized that although Figure 7 the adapter pool 712C depicted in

[0195] includes five different adapters, this in no way limits the scope of the MCCP architecture 700. The MCCP architecture can include other adapters, for example, dedicated adapters specifically for a particular cloud service provider based on the requirements of the cloud service provider.

[0196] In operation, when the user 705 accesses the multi-cloud console 750 (e.g., for the first time) to perform a registration operation (e.g., for a multi-cloud service), the user 705 is redirected to the provisioning module 722 (included in the second cloud environment 720). The user can perform a login operation for the second cloud environment, i.e., using the credentials associated with the second cloud environment. After successfully logging in to the second cloud environment, the provisioning module 722 performs the prerequisite setup of resources in the customer account in the second cloud environment. Note that the provisioning of prerequisite resources in the second cloud environment can include creating roles (and associated policies) and setting up a user pool for the identity system 723.

[0197] According to some embodiments of the present disclosure, the identity system 723 of the second cloud environment 720 includes features that allow users or services to temporarily assume different roles (referred to herein as "assuming a role"). Such features enable cross-account access or permission delegation within or outside the same account. When a user or service assumes a role, they receive a set of temporary security credentials, which may include an access key, a secret access key, and a session token. These credentials can then be used to make API calls or access resources (in the second cloud environment) based on the permissions granted for the assumed role. Thus, as part of the provisioning process, a multi-cloud service account can be configured to assume certain roles, and the multi-cloud service account can utilize these roles to obtain access to customer accounts in the second cloud environment.

[0198] When a user successfully logs in to the second cloud environment 720 and completes the above-mentioned provisioning process, an access token can be issued to the user. The token is then forwarded to the multi-cloud console 750, which in turn forwards the token to the MCCP 712. The proxy module 712A included in the MCCP 712 performs user authentication as described above and, after the user is successfully authorized (e.g., checks if the user has sufficient privileges to issue a particular type of request), forwards the request to the appropriate adapter included in the adapter pool 712C to execute the user's request.

[0199] When providing services of a cloud environment (e.g., the first cloud environment 710) to customers of other cloud environments (e.g., the second cloud environment 720), a framework (i.e., a multi-cloud infrastructure framework) is needed to enable users of the other cloud environment (i.e., the second cloud environment) to access / control resources (deployed in the first cloud environment) in a manner that is transparent to the (one or more) users from their respective cloud environments. An important aspect of the multi-cloud infrastructure is to design an identity framework that is configured to verify whether users of other cloud environments have sufficient privileges / permissions to issue requests to access / modify the deployed resources in the first cloud environment.

[0200] A simple way to implement an identity management framework in a multi-cloud setting is to rely on the identity management tools of an external cloud (e.g., the second cloud environment) to perform user verification. For example, if the second cloud environment is AWS, its identity management tool (i.e., Cognito) can be used for identity management. The drawback of this approach is that services like Cognito require special setup and are time-consuming. Moreover, relying on the identity management system of a specific service provider (e.g., Cognito of AWS) brings compatibility issues and may not be widely used and accepted as a result. Therefore, a unified identity management framework is described herein that enables users of any external cloud environment to access resources (in the first cloud environment) after being verified.

[0201] Figure 8 Depicts a multi-cloud architecture 800 that illustrates an identity framework according to some embodiments. Figure 8 Depicts the interaction between two cloud environments, e.g., a first cloud environment 810 (provided by a first cloud service provider) and a second cloud environment 860 (provided by a second cloud service provider). The first cloud environment 810 includes several components, such as a portal 811 (e.g., a login portal for the first cloud environment), a customer tenancy 813, a service platform 815, a multi-cloud control plane 820, a database 821, and downstream services 830. The customer tenancy 813 includes an identity module 813A and one or more policies 813B (e.g., associated with a user).

[0202] The second cloud environment 860 includes a customer account 861, a multi-cloud account (also referred to herein as a multi-cloud service account) 863, and one or more APIs 864 of the second cloud environment. As will be described below, Figure 8 the architecture 800 supplies resources in the first cloud environment 810 for deployment and utilization by users of the second cloud environment 860. In some implementations, a request to deploy such resources can be made via a multi-cloud console 850. For example, the request can be directed to the GUI of the multi-cloud console, which provides a list of one or more services (e.g., exa database service, MySQL service, autonomous database service, virtual database service, etc.). An identity framework is described below that is implemented to allow authorized users (of the second cloud environment) to utilize the services of the first cloud environment. The identity framework uses identity federation as a tool for multi-cloud authentication of users.

[0203] According to some embodiments, the steps for managing user identities in a multi-cloud infrastructure environment 800 are as follows: (1) In step 1, a user 801 performs a login operation into the first cloud environment. Note that the login operation can be performed using the credentials of the user associated with the first cloud environment. Note that the login operation can be performed via the portal 811, e.g., a sign-on user interface portal (SOUP), also referred to as the login portal of the first cloud environment. The request is forwarded from the SOUP to the identity management system (i.e., the identity module) of the first cloud environment 813A to authenticate the user. An example of an identity management system can be an Identity Cloud Service (IDCS).

[0204] After successful authentication, the user can be redirected to the second cloud environment. Specifically, the user can be directed to the identity provider of the second cloud environment. In step 1.1, the user can perform a login operation for the second cloud environment using user credentials associated with the second cloud environment. After successful login, in step 1.2, the user identity (e.g., user group, group policy, role, etc.) from the second cloud environment 860 can be federated, i.e., migrated to the first cloud environment. According to some embodiments, the federation process is facilitated via the use of a connector framework associated with the identity system of the first cloud environment. Details of the federation process and the use of the connector framework will be described later with reference to Figure 10 and 11 describe the details of the federation process and the use of the connector framework.

[0205] After the user 801 successfully logs in to the first cloud environment 810, in step 2, an access token, e.g., a user principal session token (UPST), is provided to the user and the user is redirected to the multi-cloud console 850. Note that the UPST is generated by the identity module 813A in response to successful authentication of the user's credentials (e.g., login information). Using the multi-cloud console 850, the user 801 can issue requests such as deploying one or more resources (e.g., exa database resources, autonomous database resources, etc.) in the first cloud environment 810. The multi-cloud console 850 triggers an API call (including the UPST) to the service platform (SPLAT), as shown in step 3. The SPLAT is configured to authorize the UPST (in step 4), i.e., determine whether the user is eligible (i.e., has sufficient privileges / permissions) to make a call to the multi-cloud console 850, verify roles, permissions associated with the token, etc. According to some embodiments, the authorization of the user can be performed for the user roles, policies, and other information in the customer lease (i.e., policy 813B) federated from the second cloud environment 860 and stored in the first cloud environment 810. After successful verification of the UPST (i.e., the user is successfully verified), the request is forwarded to the multi-cloud control plane 820.

[0206] According to some embodiments, and as previously described with respect to Figure 7 one aspect of the multi-cloud control plane 820 is to establish a network link between the first cloud environment and the second cloud environment (e.g., establish a network / communication link between customer accounts in the two cloud environments). To do this, the multi-cloud control plane 820 needs access to the (one or more) customer accounts in the second cloud environment. In some implementations, this is achieved via the multi-cloud account 863 (i.e., a multi-cloud service account deployed in the second cloud environment and belonging to the cloud service provider of the first cloud environment).

[0207] It should be recognized that a simple way for the multi-cloud control plane 820 to obtain access to different customer accounts in the second cloud environment 860 is that each customer can provide an API key to the multi-cloud control plane 820. In such a setup, the multi-cloud control plane 820 will undertake the task of storing multiple keys - each key corresponding to each customer account in the second cloud environment - to obtain access to the corresponding customer account in the second cloud environment. Obviously, such a framework is not scalable and will impose a computational burden on the multi-cloud control plane 820. Therefore, to avoid this situation, according to some embodiments of the present disclosure, the multi-cloud control plane 820 obtains access to different customer accounts in the second cloud environment 860 via the multi-cloud service account 863 previously deployed in the second cloud environment 860. Such access to different customer accounts in the second cloud environment 860 can be obtained via a single session token stored in the database 821 in the first cloud environment 810.

[0208] The multi-cloud control plane 820 obtains a session token (e.g., a secret key) from the database to access the multi-cloud service account 863 in the second cloud environment 860 (step 5). The multi-cloud service account 863 is in turn coupled to different customer accounts in the second cloud environment to establish a network link. Note that, as part of the coupling, the multi-cloud service account also obtains access to the computing instances executed in the (one or more) customer accounts of the second cloud environment. Moreover, a copy of the user role can be provided in the multi-cloud service account 863 (step 6). Note that the multi-cloud control plane 820 can also utilize the session token to access one or more APIs of the second cloud environment, e.g., to access one or more APIs of the second cloud environment to perform prerequisite resource provisioning (described later with reference to Figure 12 ). In addition, the multi-cloud control plane in step 8 exchanges / transforms the UPST into a On-Behalf-Of token (OBO) to make a downstream call to the native service (i.e., the downstream service) of the first cloud environment.

[0209] It should be recognized that in order for the multi-cloud service account 863 to obtain access to each customer account in the second cloud environment, prerequisite provisioning of resources must be performed in the second cloud environment. For example, as previously referenced Figure 7 As described, using the provisioning module 722, developers can define and provision infrastructure resources using infrastructure-as-code templates. In other words, the provisioning module 722 automates the prerequisite setup of resources in the customer accounts in the second cloud environment 720. The provisioning module 722 can also be configured to set up prerequisite resources to allow components of the first cloud environment (i.e., the multi-cloud service account) to obtain access to the resources in the customer accounts in the second cloud environment. Prerequisite resource provisioning will be described in detail later with reference to Figure 12 And, in the above Figure 8 In the architecture, a user may implement a software development kit (SDK) 840 to programmatically perform the above functions.

[0210] Figure 9 FIG. 900 depicts an exemplary flowchart that illustrates steps corresponding to a user registration process according to some embodiments. Figure 9 The processes depicted in FIG. 900 may be implemented in software (e.g., code, instructions, programs) executed by one or more processing units (e.g., processors, cores) of a corresponding system, using hardware, or a combination thereof. The software may be stored on a non-transitory storage medium (e.g., a memory device). Figure 9 The methods presented in FIG. 900 and described below are intended to be illustrative and non-limiting. Although Figure 9 FIG. 900 depicts various processing steps that occur in a particular order or sequence, this is not intended to be limiting. In certain alternative embodiments, the processing may be performed in a different order, or some steps may be performed in parallel.

[0211] The process begins at step 901, where a user (e.g., via a browser) navigates to a multi-cloud console. For example, the user navigates to the registration API / GUI of the multi-cloud console to register for a multi-cloud service provided by a first cloud environment. Such an interface of the multi-cloud console is referred to herein as a registration GUI. In step 903, the user inputs a lease name (e.g., an identifier of a lease in the first cloud environment) or selects to register a lease in the first cloud environment.

[0212] In response to the user selecting to register a lease in the first cloud environment, the process moves to step 904, where the user is directed to the registration page of the first cloud environment. Thereafter, after registering a lease in the first cloud environment, the process loops back to step 903. In response to the user inputting a lease name in step 903, the process moves to step 905, where the user inputs their credentials (e.g., login username, password, etc.) to perform a login operation. The process in step 907 performs a query to determine whether a network link exists (i.e., a communication link between a customer account in a second cloud environment and a customer lease in the first cloud environment). In some implementations, such a determination may be made by querying a link resource object that includes information linking the user's lease in the first cloud environment to the user's account in the second cloud environment. Such a link resource object may also include information indicating whether a network link is configured between the respective cloud environments (e.g., a status flag). If the response to the query is affirmative, then the process moves to step 923, otherwise, in response to the query being negative, the process moves to step 908.

[0213] If the multi-cloud link (i.e., the network link) does not exist, then the processing in step 908 redirects the user to the second cloud environment (e.g., redirects the user to the GUI associated with the second cloud environment). Specifically, the user is redirected to perform a login operation using the credentials associated with the second cloud environment. Such a GUI can correspond to the login GUI associated with the portal of the second cloud environment. After successful login, the processing in step 909 begins the verification processing. Specifically, the processing attempts to verify a set of prerequisite resources to be configured in the second cloud environment. Note that this set of prerequisite resources is necessary to establish the network link between the two cloud environments.

[0214] According to some embodiments, a provisioning module ( Figure 7 the box labeled 722 in) included in the customer account of the second cloud environment can trigger the provisioning process of the prerequisite resources. For example, the provisioning module triggers the access control module ( Figure 7 the box labeled 723B in) to start provisioning the prerequisite resources for the user. Provisioning includes creating a set of one or more roles (and associated policies, permissions, etc. corresponding to the respective roles) for one or more users of the second cloud environment. In some implementations, the access control module serves as the user directory of the second cloud environment. Specifically, the access control module can be configured to create a user pool and perform functions such as adding user registration, login, and access control for web and mobile applications.

[0215] In some implementations, the provisioning module is configured to create a hierarchy of resources (i.e., a set of prerequisite resources), each resource associated with a corresponding role, e.g., a networking role, an observability role, and a verifier role. It should be recognized that the networking role allows the creation of a network link, i.e., a communication path that interconnects the resources of the first cloud environment and the second cloud environment, while the observability role provisions the observability module (i.e., the observability adapter included in the MCCP) to publish metrics associated with one or more resources deployed in the first cloud environment to be transmitted to the monitoring module in the second cloud environment. In some embodiments, the provisioning module can also be configured to set the prerequisite resources to allow components of the first cloud environment to obtain access to the resources in the customer account in the second cloud environment. According to some embodiments, this is achieved by allowing the multi-cloud service account ( Figure 7 the box labeled 726A in) to access the resources in the customer account, e.g., allowing the multi-cloud service account to peer with the customer account, allowing components of the multi-cloud infrastructure (e.g., the observability adapter to publish metrics in the second cloud environment, etc.). More details regarding the provisioning of prerequisite resources will be referred to later in Figure 12 for a description of.

[0216] The processing in step 911 performs a query to determine whether prerequisite resources have been correctly configured and verified. If the response to the query is affirmative, then the processing moves to step 917; otherwise, the processing moves to step 913. In step 913, that is, if the prerequisite resources have not been configured, then the provisioning module in the customer account of the second cloud environment is activated to start the provisioning process of the prerequisite resources as described above. Such a process includes the user performing a login operation in the second cloud environment to execute the prerequisite resource provisioning process (step 915). After successfully executing the prerequisite resource provisioning process, the processing loops back to step 911.

[0217] After verifying the prerequisite resources, the processing in step 917 checks which geographical regions are available (for both the first cloud environment and the second cloud environment) such that a network link can be established. For example, a check can be performed to determine whether the regions selected for the first cloud environment and the second cloud environment are located in the same location (i.e., in close proximity to each other geographically) such that a network link can be established between the two cloud environments.

[0218] In step 919, a primary region is selected for the two cloud environments (from the available regions obtained in step 917). For example, a first primary region is selected for the first cloud environment from the available regions of the first cloud environment, and a second primary region is selected for the second cloud environment from the available regions of the second cloud environment. After selecting the primary regions for the two cloud environments, the processing in step 921 establishes a network link between the two cloud environments.

[0219] In some embodiments, in step 921, a workflow that performs several functions can be initiated. For example, the workflow can include the following steps: (i) triggering the network adapter (included in the Figure 7 MCCP) to configure the interconnection ( Figure 7 the link labeled 719 in the to communicatively couple the two cloud environments, and (ii) creating a compartment in the user lease in the first cloud environment such that the requested resources can be deployed therein, etc. It should be appreciated that the configuration of the interconnection can include coupling the interconnection (at one end) to a direct connection in the second cloud environment (located in the multi-cloud service account 726A) and coupling the interconnection (at the other end) to a fast connection included in the first cloud environment.

[0220] The processing in step 923 determines the status of the multi-cloud link. For example, this processing determines whether the network link has been started and is operating properly. In step 925, a query is executed to determine whether the network link is ready. If the response to the query is affirmative, then the processing moves to step 927, where the user is directed to the multi-cloud console, e.g., to the API of the multi-cloud console that describes the various resources available for the user to deploy in the lease in the first cloud environment (i.e., provides a list of these resources). If the response to the query in step 925 is negative, then the processing loops back to step 923, where the status of the network link is rechecked.

[0221] As previously mentioned, when providing the services of the first cloud environment to customers of other cloud environments (e.g., the second cloud environment), a framework (i.e., the multi-cloud infrastructure framework) is needed to enable users of other cloud environments to access / control the resources (deployed in the first cloud environment) from their respective cloud environments in a manner that is transparent to the (one or more) users. Figure 8 A multi-cloud infrastructure framework is depicted, which includes a unified identity management framework that enables users of any external cloud environment to access the resources deployed in the first cloud environment after successful authentication. An important aspect of the authentication process is to federate the user credentials in one cloud environment (e.g., the second cloud environment) to be automatically replicated / synchronized in another cloud environment (e.g., the first cloud environment) (see Figure 8 step 1.2).

[0222] The following describes the processing, i.e., the federation mechanism, which instantiates a multi-cloud service account in the second cloud environment (e.g., Figure 7 the box labeled 726A in Figure 10 to establish trust between the two cloud environments, and thereafter enables the user credentials to be synchronized from the second cloud environment to the first cloud environment. It should be recognized that identity federation is the process of delegating the authentication responsibility of an individual or entity to a trusted external party. Each party in the federation process acts as an identity provider (IdP) or a service provider (SP). In identity federation, the IdP vouches for the identity of the user, and the SP provides services to the user. When a user wants to access the services of the SP, the SP delegates the authentication to the IdP. Note that for identity federation to occur, the SP must trust the authentication capabilities of the IdP. The following references

[0223] Now turning to Figure 10 , a block diagram 1000 depicting an identity connector framework of a first cloud environment according to some embodiments is shown. Specifically, Figure 10 Depicts an identity system 1010 of a first cloud environment and an identity system 1030 of a second cloud environment, which are communicatively coupled to each other. The identity system 1010 of the first cloud environment includes an identity management service 1011, an identity connector framework 1013, and a connector 1015.

[0224] According to some embodiments of the present disclosure, federation is achieved by using an Identity Connector Framework (ICF), which provides a consistent common layer between a calling application (e.g., the identity management service 1011) and a connector module / bundle that accesses a target resource (e.g., user credentials in the identity system of the second cloud environment 1030). Each target resource itself can be a system or an application, but the connector bundle enables any calling application to manage the objects present on the target resource. Thus, the connector 1015 is an integration tool used in the identity system of the first cloud environment. The connector is built on the ICF framework 1013 and is stateless by design, i.e., the connector does not store any information. The calling application (e.g., the identity management service 1011) supplies the connector 1015 with a set of values for its configuration, including the information required to connect to the target application. This is because the identity connector is stateless, and in doing so, each connector bundle implementation is decoupled from the implementation of the calling application. In other words, the connector is the component that enables federation from one identity system (e.g., the second cloud environment) to another identity system (e.g., the first cloud environment).

[0225] It should be recognized that the federation process enables any changes made to the user identities in the second cloud environment (e.g., user addition, removal of user membership from certain user groups, etc.) to be seamlessly reflected in the identity system of the first cloud environment. The federation process in the present disclosure is implemented via the connector 1015, which communicates with an endpoint in a multi-cloud service account (i.e., an account owned by the first cloud service provider of the first cloud environment and deployed in the second cloud environment) to retrieve information (e.g., user identity information) from the second cloud environment.

[0226] Figure 11 Depicts an exemplary swimlane diagram illustrating the steps corresponding to the process of performing identity federation according to some embodiments. Specifically, Figure 11 Depicts the steps performed when federating the identity of one or more users in a second cloud environment 1130 to a first cloud environment 1110. Figure 11 Depicts the interaction between the identity service of a first cloud environment 1101, the multi-cloud platform 1102 of the first cloud environment, the database (secret repository) 1103 of the first cloud environment, a multi-cloud account (i.e., the multi-cloud service account 1105 included in the second cloud environment), a customer VPC including a customer account 1106, and the identity service 1107 of the second cloud environment.

[0227] According to some embodiments, the identity service (or alternatively, the connector module) of the first cloud environment 1101 communicates with an endpoint in the second cloud environment to retrieve customer credentials from a customer account in the second cloud environment. It should be recognized that due to trust and policy issues, the identity service of the first cloud environment will not be able to directly access the customer account in the second cloud environment. Thus, the endpoint with which the connector communicates is a multi-cloud service account that is owned by the provider of the first cloud environment and located in the second cloud environment. Note that during the prerequisite resource provisioning process (described next with reference to Figure 12 ), the multi-cloud service account is granted access to the customer account in the second cloud environment. In other words, trust is established between the multi-cloud service account and the customer account in the second cloud environment.

[0228] Furthermore, according to some embodiments of the present disclosure, the identity system 723 of the second cloud environment 720 includes a feature that allows users or services to temporarily assume different roles (referred to herein as "assuming a role"). Such a feature enables cross-account access or permission delegation within or outside the same account. When a user or service assumes a role, they receive a set of temporary security credentials, which may include an access key, a secret access key, and a session token. These credentials can then be used to make API calls or access resources (of the second cloud environment) based on the permissions granted for the assumed role. Thus, as part of the provisioning process, the multi-cloud service account can be configured to assume certain roles, and the multi-cloud service account can use these roles to obtain access to the customer account in the second cloud environment.

[0229] The Figure 11 process depicted in starts at step 1, where the identity service of the first cloud environment 1101 transmits a request to the multi-cloud platform 1102 to retrieve credentials associated with the multi-cloud account 1105 deployed in the second cloud environment. In step 2, the multi-cloud platform 1102 attempts to retrieve the credentials from the database 1103 included in the first cloud environment. In step 3, the multi-cloud platform 1102 obtains the credentials. After retrieving the credentials, in step 4, the multi-cloud platform 1102 attempts to assume a role associated with the multi-cloud service account, i.e., the multi-cloud platform 1102 is assigned a role that allows it to access the multi-cloud service account 1105. At user registration, if the prerequisite resources are properly configured, then the multi-cloud platform 1102 obtains the credentials associated with the multi-cloud service account (e.g., a first credential) (step 5).

[0230] After successfully obtaining access to the multi-cloud service account, in step 6, the multi-cloud platform 1102 attempts to assume the role associated with the customer account 1106 in the second cloud environment 1130 (based on the credentials obtained in step 5). Note that this is possible because during setup, the multi-cloud service account 1105 was granted access to the customer account in the second cloud environment. In step 7, the multi-cloud platform 1102 obtains credentials associated with the customer account (e.g., second credentials). In step 8, a role change process is performed, where the credentials obtained by the multi-cloud platform 1102 and associated with the customer account 1106 in the second cloud environment are passed / transmitted to the identity service module of the first cloud environment 1101. After obtaining the second credentials, the identity service module of the first cloud environment is communicatively coupled with the identity service 1107 of the second cloud environment (step 9). In step 10, after obtaining the second credentials, the identity service 1101 of the first cloud environment can issue a call / request to the identity service of the second cloud environment to synchronize user identities, i.e., user groups, permissions, roles, etc. In this way, the user identity is federated from the second cloud environment to the first cloud environment. Note that the above identity federation process can be continuously executed at fixed time instances such that any changes to the user identity executed in the second cloud environment can be seamlessly migrated to the first cloud environment.

[0231] Now turn to Figure 12 , which depicts an exemplary swimlane diagram illustrating steps corresponding to a prerequisite resource verification process according to some embodiments. Specifically, Figure 12 depicts the steps performed when determining whether a set of resources has been configured in the second cloud environment, the set of resources facilitating the use of multi-cloud services provided by a first cloud environment different from the second cloud environment by users of the second cloud environment. Figure 12 depicts the interaction between a user 1201, a provisioning module 1202 of the second cloud environment, an identity management module 1203 of the second cloud environment, a multi-cloud console (registration) 1205 included in the first cloud environment, a multi-cloud control plane (MCCP) 1206 of the multi-cloud infrastructure included in the first cloud environment, a multi-cloud database 1207, and a multi-cloud service account 1208. It should be recognized that the multi-cloud console 1205 as well as the MCCP 1206 can be considered components of the multi-cloud infrastructure included in the first cloud environment.

[0232] The process begins at step S1, where the user 1201 provides credentials (e.g., an account ID associated with the second cloud environment) to the multi-cloud registration console 1205 (e.g., the registration API of the multi-cloud console). After receiving the credentials, the multi-cloud console 1205 transmits a request to the MCCP 1206 to determine whether a set of prerequisite resources has been configured for the user (step S2).

[0233] In response to receiving a request to start verifying a set of prerequisite resources, in step S3A, the MCCP 1206 obtains credentials associated with a service account (i.e., a multi-cloud service account instantiated in a second cloud environment and belonging to a first cloud environment) from the database 1207. In step S3B, the MCCP 1206 obtains the credentials associated with the service account. Additionally, in step S4A, based on the credentials obtained in step S3B, the MCCP 1206 accesses the service account 1208. Essentially, the MCCP 1206 assumes an agent role, i.e., acts on behalf of the customer and accesses the service account. In step S4B, the MCCP 1206 obtains temporary access credentials for the service account.

[0234] In step S5, the MCCP 1206 continues to assume a verifier role, i.e., the role that allows the MCCP 1206 to perform user verification. In some embodiments, the API associated with the MCCP 1206 assumes the verifier role to perform user verification. In one case, if this is the first time user 1201 accesses the multi-cloud console 1205 (e.g., to register for services provided by the multi-cloud infrastructure), then a set of prerequisite resources has not been provisioned yet. Thus, in step S6, the identity system of the second cloud environment (which includes the IAM module 1204) transmits a notification to the MCCP 1206 indicating that the verifier role does not exist. In step S7, the MCCP 1206 may store metadata information including the tenant identifier of the user in the first cloud environment and the user's account in the second cloud environment.

[0235] The MCCP 1206 transmits a notification to the multi-cloud console 1205 (step S8) indicating that the prerequisite settings for the resources are incomplete or invalid. Subsequently, in step S9, the multi-cloud console 1205 provides a notification to the user (e.g., via the API associated with the multi-cloud console) to start or initiate the provisioning process of the prerequisite resources. In step S10, the user 1201 communicates with the provisioning module 1202 included in the customer account of the second cloud environment to trigger the provisioning process.

[0236] In step S11, the provisioning module 1202 triggers the IAM module 1203 to start provisioning prerequisite resources for the user. For example, as previously referenced Figure 7 As described, the provisioning includes creating a set of one or more roles (and associated policies, permissions, etc. corresponding to the respective roles) for one or more users of the second cloud environment. In some embodiments, an access control module (included in the identity system of the second cloud environment) serves as a user directory for the second cloud environment. Specifically, the access control module can be configured to create a user pool and perform functions such as adding user registration, login, and access control for web and mobile applications. In some embodiments, the provisioning module 1202 is configured to create a hierarchy of resources, each resource associated with a corresponding role, e.g., a networking role, an observability role, and a verifier role.

[0237] It should be recognized that when processing the prerequisite resources in the second cloud environment, the multi-cloud console 1205 of the first cloud environment can simultaneously communicate with the MCCP 1206 to determine whether the prerequisite verification of the resources has been configured (steps S2', S5', S6', and S8', corresponding to steps S2, S5, S6, and S8 respectively). Since the provisioning of the prerequisite resources is occurring simultaneously (i.e., not yet completed), in step S6', the IAM module 1204 of the second cloud environment transmits a notification to the MCCP 1206 indicating that the role has not been created.

[0238] In step S12, the multi-cloud console 1205 transmits another request to the MCCP 1206 to determine whether a set of prerequisite resources has been configured for the user. The MCCP 1206 reattempts to assume the verifier role (step S13). This time, since the role has been created (i.e., the provisioning of the prerequisite resources is complete), the MCCP 1206 receives a notification from the IAM module 1204 of the second cloud environment indicating that the verifier role exists. Specifically, in step S14, the IAM module 1204 provides the MCCP 1206 with temporary credentials for the multi-cloud service account (e.g., deployed in the second cloud environment and controlled by the first CSP of the first cloud environment).

[0239] In step S15, the MCCP 1206 verifies other roles in the role hierarchy. For example, the MCCP 1206 verifies whether the networking role and the observability role have been created. In step S16, the MCCP 1206 receives confirmation of successful role creation. In step S17, the MCCP 1206 transmits a notification to the multi-cloud console 1205 indicating the completion of the configuration of the prerequisite resources. In step S18, the multi-cloud console 1205 can then notify the user of the successful configuration of the prerequisite resources.

[0240] In addition, in step S19, after the user is successfully directed to the multi-cloud console 1205, the cloud link adapter included in the MCCP can be activated to provide the user 1201 with an option to link the customer account in the second cloud environment with the customer account in the first cloud environment. In other words, the cloud link adapter performs the process of linking the two accounts of the customer in two different cloud environments, as described below with reference to Figure 14 stated. Note that after linking the two accounts in different cloud environments, the user(s) of the second cloud environment can utilize the service(s) provided by the multi-cloud infrastructure included in the first cloud environment. It should be recognized that after the user registers with the multi-cloud infrastructure, the MCCP 1206 is also configured to create a network link that communicatively couples the first cloud environment with the second cloud environment.

[0241] According to some embodiments, one aspect of the multi-cloud infrastructure is to instantiate a multi-cloud account (also referred to as a multi-cloud service account) in the second cloud environment, which is controlled by the service provider of the first cloud environment and is pre-configured with sufficient privileges to communicate with different customer accounts in the second cloud environment. In such a setup, there may be some security considerations where the multi-cloud service account may be coerced (e.g., by a malicious third party) to improperly obtain access to a specific customer account in the second cloud environment. Such a security issue is referred to herein as the "confused proxy problem", i.e., the multi-cloud service account corresponds to the confused proxy. A security solution to address the confused proxy problem implemented by the multi-cloud control plane is described below.

[0242] As previously mentioned, in the second cloud environment, a service called cross-account access service is provided, i.e., a specific account is allowed to assume the role in another account in the second cloud environment. In a multi-cloud environment setup, the multi-cloud service account (deployed in the second cloud environment) can utilize this cross-account service. A security consideration arising from this cross-account access service is the confused proxy problem, i.e., the multi-cloud service account may (under the coercion of a malicious third party) attempt to assume the role in a specific customer account to obtain fraudulent access to customer information. Techniques to prevent such fraudulent access by the multi-cloud service account are described herein. Specifically, the techniques proposed herein involve: (a) utilizing an external ID (unique for each customer) that can be generated by the multi-cloud platform and / or the multi-cloud console, and (b) a mechanism for generating and storing the external ID.

[0243] Figure 13 An exemplary swimlane diagram depicting the steps performed to address the confused proxy problem according to some embodiments is shown. Specifically, Figure 13 Depicts steps of the interaction between the illustrated multi-cloud registration console 1301, the provisioning module 1302 (including in the second cloud environment), the MCCP registration API 1303, the API of the cloud link adapter 1304, the adapter 1305 (included in the adapter pool), the MCCP platform 1306, and the customer account 1307 in the second cloud environment. Figure 13 The swimlane diagram depicted in Figure 13 includes the generation of a unique ID (referred to herein as the external ID) for each customer by the multi-cloud platform (MCP). The external ID of the customer is initially stored on the platform (e.g., stored in a key-value database included in the first cloud environment during the user registration process) and is transient. When a cloud link is formed (i.e., a mapping between a customer account in the first cloud environment and a customer account in the second cloud environment), the external ID is ultimately stored in the corresponding customer account (e.g., the customer vault) in the second cloud environment. It should be recognized that the external ID can be stored in the customer vault or in a link resource object (i.e., a cloud link object), and thereafter, for security reasons, the external ID can be deleted from the key-value database included in the first cloud environment.

[0244] Figure 13 The process in Figure 13 starts at step S1, where the multi-cloud console 1301 transmits a request (i.e., a verify prerequisite request) to the MCCP registration API 1303. Such a request can include the account ID of the customer (in the second cloud environment). In step S2, the MCCP registration API 1303 attempts to obtain the customer's credentials from the MCCP platform 1306. Since the customer's account has not been established yet, a "no access" message can be transmitted back to the MCCP registration API 1303, which can then relay it to the multi-cloud console 1301 (step S3).

[0245] In step S4, the multi-cloud console 1301 transmits a request to the MCCP platform 1306 to obtain the external ID of the customer. In step S5, the MCCP platform 1306 generates an external ID for the customer, i.e., a unique ID, and stores the generated ID in a database (e.g., a key-value database). In step S6, the MCCP platform 1306 provides the external ID to the multi-cloud console 1301. In step S7, the multi-cloud console 1301 issues a request to the provisioning module 1302 to start the process of provisioning prerequisite resources. The provisioning process can include the provisioning module 1302 triggering an access control module (e.g., Figure 8 the box labeled 803 in Figure 13 ) to start provisioning prerequisite resources for the user. For example, as previously referenced in Figure 7 Figure 13 , provisioning includes creating a set of one or more roles (and associated policies, permissions, etc. corresponding to the respective roles) for one or more users of the second cloud environment.

[0246] The access control module can be configured to create a user pool and perform functions such as adding user registrations, logins, and access control for web and mobile applications. In some embodiments, the provisioning module 1303 is configured to create a hierarchy of resources (referred to herein as a set of prerequisite resources), each resource being associated with a corresponding role, e.g., a networking role, an observability role, and a verifier role. It should be recognized that the networking role allows for the creation of network links, i.e., communication paths that interconnect resources in a first cloud environment and a second cloud environment, while the observability role provisions the (MCCP's) observability module to publish metrics associated with one or more resources deployed in the first cloud environment to be transmitted to the monitoring module in the second cloud environment. The verifier role allows the control plane of the multi-cloud infrastructure to perform user verification. Note that the resource prerequisite provisioning in step S7 corresponds to the resource prerequisite provisioning corresponding to step S10 of Figure 12 However, an additional requirement in the resource prerequisite provisioning of step S7 is to use the generated external ID as a parameter in the prerequisite verification process for the customer.

[0247] It should be recognized that when the process of provisioning prerequisite resources is executed in the second cloud environment, the multi-cloud console 1301 in the first cloud environment can simultaneously communicate with the MCCP registration API 1303 to determine whether the prerequisite verification of the resources has been configured (step S8). Since the provisioning of the prerequisite resources is occurring simultaneously (i.e., not yet complete), in step S9, the MCCP registration API 1303 transmits a notification to the multi-cloud console 1301 indicating that the role has not been created.

[0248] In addition, in step S10, after the multi-cloud console 1301 in the first cloud environment communicates with the MCCP registration API 1303 to determine whether the prerequisite verification of the resources has been configured. If the provisioning module in the second cloud environment has completed the prerequisite verification, then in step S11, the MCCP registration API 1303 transmits a request to obtain credentials from the MCCP platform 1306. The MCCP platform 1306 then extracts the external ID stored in the key-value database in step S5 in step S12. Based on the extracted external ID, in step S13, the MCCP platform 1306 assumes the role associated with the customer account in the second cloud environment 1307 and extracts the session key in step S14. In step S15, the MCCP registration API 1303 obtains a list of roles, user groups, and other resources using the session key (step S16), after which the MCCP registration API 1303 can notify the multi-cloud console 1301 that the verification process is complete (step S17).

[0249] Up to this step (i.e., step S17), note that the customer's external ID is stored locally on the MCCP platform (e.g., in a key-value database). Additionally, after initiating the cloud link process (i.e., the process of mapping the customer's account in the first cloud environment to the customer's account in the second cloud environment), the external ID can be deleted from the MCCP platform and stored in the customer's vault, i.e., in the compartment of the customer's account (e.g., in the second cloud environment). The external ID can be stored on the platform for a short period (e.g., one week), after which it can be stored long-term in the customer's vault. It should be recognized that steps S1 - S17 correspond to the verification process, while steps S19 - S22 correspond to the resource provisioning process.

[0250] In step S18, the multi-cloud console triggers a request that is transmitted to the API of the cloud link adapter 1304 to initiate the cloud link process. Figure 14 A graphical representation of such mapping is depicted. Specifically, go to Figure 14 , where a schematic diagram showing a cloud link resource object according to some embodiments is depicted. The cloud link resource object maps information about the user's account in the second cloud infrastructure to the user's lease in the first cloud infrastructure. As Figure 14 shown, the second cloud environment 1410 includes the customer's account 1401, including some account metadata 1402. The account metadata can include information such as an identifier for the user group. The first cloud environment 1405 includes the customer lease 1411, which includes the cloud link resource object 1430. The cloud link resource object 1430 includes several parameters, such as the lease ID 1430A of the customer in the first cloud environment, the user pool ID 1430B that mirrors the account metadata 1402 information, the client ID 1430C corresponding to the identifier of the identity management system of the second cloud environment, the base compartment ID including a pointer to the compartment 1440 instantiated for the customer, and the account ID 1430D including the identifier of the customer's account in the second cloud environment and including a pointer to the compartment 1440A instantiated for the customer in the first cloud environment. It should be recognized that the customer's resources are deployed in the compartment instantiated for the customer in the first cloud environment.

[0251] Return Figure 13 , after completing the cloud link processing, in the resource provisioning phase, the adapter 1305 (e.g., from the adapter pool included in the MCCP) transmits a request to obtain credentials (e.g., of a multi-cloud service account in the second cloud environment) from the MCCP platform 1306. The MCCP platform 1306 can then extract the external ID from the customer account in the second cloud environment and further assume the role of allowing the MCCP platform to perform operations on behalf of the customer (step S20). For example, after obtaining the session key (step S21) from the customer account in the second cloud environment 1307, the adapter 1305 can use the session key to deploy resources (e.g., autonomous database) in the customer account in the first cloud environment.

[0252] In this way, the multi-cloud infrastructure of the present disclosure solves the problem of the confused proxy by prohibiting fraudulent third-party entities from obtaining access to the customer account (i.e., because they will not be able to access the external ID stored in the customer vault and required to obtain access to the customer account). It should be noted that the features described above with respect to Figure 13 in no way limit the scope of the present disclosure. For example, in an alternative approach, generating the external ID for the customer (and storing the generated external ID in the customer vault) can be performed by the multi-cloud registration console.

[0253] Figure 15 depicts a schematic diagram illustrating the deployment of resources by a multi-cloud infrastructure according to some embodiments. As Figure 15 shown, the first cloud environment includes a multi-cloud console 1551, a service platform (SPLAT) 1552, a proxy 1553, a cloud link adapter 1554, a database adapter 1555, and a platform 1556. When a user accesses the multi-cloud console 1551, in some embodiments, the user can be directed to the identity management system 1560 of the second cloud environment to perform a login operation for the second cloud environment. It should be noted that after successful login, the user is redirected back to the multi-cloud console 1551 together with a token (e.g., an access token). It should be recognized that the user can use the multi-cloud console 1551 to issue commands to access, create, or update resources in the user's tenancy in the first cloud infrastructure. For the sake of illustration, a scenario where the user issues a request to create a database resource (e.g., an Exa database resource) using the multi-cloud console 1551 is described below.

[0254] The multi-cloud console 1551 provides multiple options, such as creating resources, accessing resources, updating resources, etc. These options can be provided to users in the form of optional icons (e.g., buttons) in the multi-cloud console 1551. When the user makes a selection (e.g., to create a resource), an API call to the service platform 1552 is triggered. It should be recognized that in some embodiments, the request made to the service platform 1551 can be a call such as a REST-type call (or a POST call), which includes an authorization header that includes a token associated with the user in the second cloud infrastructure. Also included in the request is metadata information, including the account ID, resource name, provider name, and type of resource requested by the user (of the second cloud environment).

[0255] The call including the token is further forwarded to the proxy module 1553 that performs authentication and access control operations. According to some embodiments, the proxy module 1553 performs the authentication operation by extracting the token included in the call. In some embodiments, the proxy module 1553 verifies the token by comparing the signature (used to sign the request) with the publicly available signature of the second cloud infrastructure to ensure that the request originates from a valid customer associated with the second cloud infrastructure. Additionally, the proxy module 1553 can also check the role (i.e., privilege) associated with the token, e.g., whether the role corresponds to a DB administrator, etc. Based on the role, the proxy module 1553 can route the request to the appropriate adapter included in the MCCP framework, i.e., one of the adapters included in the adapter pool 712C, as Figure 7 shown.

[0256] According to one embodiment, the proxy module 1553 compares the role (associated with the token) with a pre-configured list of roles published and assigned (as part of the API specification) for each adapter. For example, if the role associated with the token corresponds to "Exadata DB administrator", then the request can be understood as a request to create an Exa database, and thus the request is forwarded to the database adapter 1555. Additionally, according to some embodiments, the proxy module 1553 can analyze the information included in the REST call, such as the provider ID, the type of resource requested, etc., and based on the analyzed information, the proxy module 1553 can forward the request to the appropriate adapter.

[0257] In some embodiments, the request obtained by the proxy module 1553 may not contain information identifying the user's lease in the first cloud infrastructure where the resources are to be deployed. Accordingly, the proxy module 1553 communicates with the cloud link adapter 1554 to obtain mapping information of the user account in the second cloud infrastructure to the user lease in the first cloud infrastructure. If the mapping information exists, then the proxy module 1553 obtains information related to the user lease in the first cloud infrastructure and passes the information to the database adapter 1555. In this way, the database adapter 1555 knows the user's lease in the first cloud infrastructure where the resources are to be created / deployed. However, if the cloud link adapter 1554 determines that no mapping information exists, then the proxy module 1553 can simply issue an "unauthorized access" message back to the user as a response to the request to create database resources.

[0258] Note that in some embodiments, the cloud link adapter 1554 creates data objects (referred to herein as cloud link resource objects or link resource objects) for storing metadata information identifying the two linked accounts. For example, the data object stores metadata information including a mapping of a first identifier associated with a lease (i.e., account) in the first cloud infrastructure and a second identifier associated with a user account of a second cloud service provider. Such a mapping is referred to herein as a resource context. Additionally, the cloud link adapter 1554 may also create a resource principal (referred to herein as a cloud link resource principal) associated with the resource context. The cloud link adapter 1554 may maintain the data object as well as the resource principal within the root compartment of the user lease in the first cloud infrastructure. In some embodiments, the cloud link adapter 1554 may also persist the data object and / or the resource principal locally in the platform 1156.

[0259] In some embodiments, the database adapter 1555 may obtain the resource principal persisted locally in the platform 1556. The database adapter 1555 may transmit a request (including the resource principal) to one or more downstream services included in the first cloud infrastructure to create a resource in the user lease in the first cloud infrastructure. In other words, the downstream services included in the first cloud infrastructure utilize the identity (i.e., the resource principal) obtained from the platform 1556 to create / deploy the required resources, such as an Exa database, in the user lease in the first cloud infrastructure. When the user issues a request to create an Exa database, the user may intermittently poll the MCCP to obtain the status of the request. When the downstream services of the first cloud infrastructure create a resource in the user lease in the first cloud infrastructure, the MCCP may notify the user of the successful completion of the request.

[0260] Example of cloud infrastructure

[0261] As noted above, Infrastructure as a Service (IaaS) is a specific type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, the IaaS provider can also supply various services to accompany these infrastructure components (e.g., billing, monitoring, logging, security, load balancing, and clustering, etc.). Thus, since these services may be policy-driven, IaaS users can be able to implement policies to drive load balancing to maintain the availability and performance of applications.

[0262] In some cases, IaaS customers can access resources and services over a wide area network (WAN) such as the Internet and can use the cloud provider's services to install the remaining elements of the application stack. For example, a user can log in to the IaaS platform to create a virtual machine (VM), install an operating system (OS) on each VM, deploy middleware such as a database, create buckets for workloads and backups, and even install enterprise software into that VM. Then, the customer can use the provider's services to perform various functions, including balancing network traffic, troubleshooting applications, monitoring performance, managing disaster recovery, etc.

[0263] In most cases, the cloud computing model will require the participation of a cloud provider. The cloud provider can be, but is not necessarily, a third-party service that specifically provides (e.g., supplies, rents, sells) IaaS. An entity may also choose to deploy a private cloud and thus become its own infrastructure service provider.

[0264] In some examples, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server, etc. It can also include the process of preparing the server (e.g., installing libraries, daemons, etc.). This is typically managed by the cloud provider and is below the hypervisor layer (e.g., servers, storage devices, network hardware, and virtualization). Thus, the customer can be responsible for the processing of the (OS), middleware, and / or application deployment (e.g., on a self-service virtual machine, etc. that can be launched on demand).

[0265] In some examples, IaaS provisioning can refer to obtaining computers or virtual hosts for use and even installing the required libraries or services on them. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.

[0266] In some cases, there are two different challenges with IaaS provisioning. First, there is an initial challenge in provisioning an initial set of infrastructure before anything is running. Second, once everything has been provisioned, there is a challenge in evolving the existing infrastructure (e.g., adding new services, changing services, removing services, etc.). In some cases, these two challenges can be addressed by enabling the configuration of the infrastructure to be defined in a declarative manner. In other words, the infrastructure (e.g., which components are needed and how they interact) can be defined by one or more configuration files. Thus, the overall topology of the infrastructure (e.g., which resources depend on which resources and how they work together) can be described in a declarative manner. In some cases, once the topology is defined, a workflow can be generated to create and / or manage the different components described in the configuration file.

[0267] In some examples, the infrastructure can have many interconnected elements. For example, there may be one or more virtual private clouds (VPCs) (e.g., a potentially on-demand pool of configurable and / or shared computing resources), also referred to as the core network. In some examples, one or more security group rules can also be provisioned to define how the security of the network is set up and one or more virtual machines (VMs). Other infrastructure elements, such as load balancers, databases, etc., can also be provisioned. As more and more infrastructure elements are desired and / or added, the infrastructure can evolve incrementally.

[0268] In some cases, continuous deployment techniques can be employed to enable the deployment of infrastructure code across various virtual computing environments. Additionally, the described techniques can enable infrastructure management within these environments. In some examples, a service team can write code that is intended to be deployed to one or more but typically many different production environments (e.g., across various different geographical locations, sometimes spanning the entire world). However, in some examples, the infrastructure on which the code will be deployed must first be set up. In some cases, provisioning can be done manually, resources can be provisioned using provisioning tools, and / or code can be deployed using deployment tools once the infrastructure has been provisioned.

[0269] Figure 16 FIG. 1600 is a block diagram illustrating an example schema of an IaaS architecture according to at least one embodiment. A service operator 1602 can be communicatively coupled to a secure host lease 1604 that can include a virtual cloud network (VCN) 1606 and a secure host subnet 1608. In some examples, the service operator 1602 can use one or more client computing devices, which can be portable handheld devices (e.g., cellular phones, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., Google a head-mounted display), running software (such as Microsoft Windows ), and / or various mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, etc.), and supporting the Internet, email, Short Message Service (SMS), or other communication protocols. Alternatively, the client computing device can be a general-purpose personal computer, including, for example, personal computers and / or laptop computers running various versions of Microsoft Apple and / or Linux operating systems. The client computing device can be a workstation computer running any of various commercially available or UNIX-like operating systems, including but not limited to any of various GNU / Linux operating systems (such as, for example, Google Chrome OS). Alternatively or additionally, the client computing device can be any other electronic device, such as a thin client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox gaming console with or without a gesture input device), and / or a personal messaging device capable of communicating via a network that can access VCN 1606 and / or the Internet.

[0270] VCN 1606 can include a Local Peer Gateway (LPG) 1610, which can be communicatively coupled to a Secure Shell (SSH) VCN 1612 via the LPG 1610 included in the SSH VCN 1612. The SSH VCN 1612 can include an SSH subnet 1614, and the SSH VCN 1612 can be communicatively coupled to a control plane VCN 1616 via the LPG 1610 included in the control plane VCN 1616. Additionally, the SSH VCN 1612 can be communicatively coupled to a data plane VCN 1618 via the LPG 1610. The control plane VCN 1616 and the data plane VCN 1618 can be included in a service lease 1619 that can be owned and / or operated by an IaaS provider.

[0271] The control plane VCN 1616 may include a control plane demilitarized zone (DMZ) layer 1620 that serves as a perimeter network (e.g., a portion of a corporate network between an intranet and an external network). Servers based on the DMZ can assume limited liability and help control security vulnerabilities. Additionally, the DMZ layer 1620 may include one or more load balancer (LB) subnets 1622, a control plane application layer 1624 that may include one or more application subnets 1626, and a control plane data layer 1628 that may include one or more database (DB) subnets 1630 (e.g., one or more front-end DB subnets and / or one or more back-end DB subnets). The one or more LB subnets 1622 included in the control plane DMZ layer 1620 may be communicatively coupled to the one or more application subnets 1626 included in the control plane application layer 1624 and an Internet gateway 1634 that may be included in the control plane VCN 1616, and the one or more application subnets 1626 may be communicatively coupled to the one or more DB subnets 1630 included in the control plane data layer 1628, as well as a service gateway 1636 and a network address translation (NAT) gateway 1638. The control plane VCN 1616 may include a service gateway 1636 and a NAT gateway 1638.

[0272] The control plane VCN 1616 may include a data plane mirror application layer 1640, which may include one or more application subnets 1626. The one or more application subnets 1626 included in the data plane mirror application layer 1640 may include virtual network interface controllers (VNICs) 1642 that may execute compute instances 1644. The compute instances 1644 may communicatively couple the one or more application subnets 1626 of the data plane mirror application layer 1640 to the one or more application subnets 1626 that may be included in the data plane application layer 1646.

[0273] The data plane VCN 1618 may include a data plane application layer 1646, a data plane DMZ layer 1648, and a data plane data layer 1650. The data plane DMZ layer 1648 may include one or more LB subnets 1622, which may be communicatively coupled to the one or more application subnets 1626 of the data plane application layer 1646 and an Internet gateway 1634 of the data plane VCN 1618. The one or more application subnets 1626 may be communicatively coupled to a service gateway 1636 of the data plane VCN 1618 and a NAT gateway 1638 of the data plane VCN 1618. The data plane data layer 1650 may also include one or more DB subnets 1630 that may be communicatively coupled to the one or more application subnets 1626 of the data plane application layer 1646.

[0274] The Internet gateway 1634 for the control plane VCN 1616 and the data plane VCN 1618 can be communicatively coupled to the metadata management service 1652, and the metadata management service 1652 can be communicatively coupled to the public Internet 1654. The public Internet 1654 can be communicatively coupled to the NAT gateway 1638 for the control plane VCN 1616 and the data plane VCN 1618. The service gateway 1636 for the control plane VCN 1616 and the data plane VCN 1618 can be communicatively coupled to the cloud service 1656.

[0275] In some examples, the service gateway 1636 for the control plane VCN 1616 or the data plane VCN 1618 can make application programming interface (API) calls to the cloud service 1656 without going through the public Internet 1654. The API calls from the service gateway 1636 to the cloud service 1656 can be one-way: the service gateway 1636 can make API calls to the cloud service 1656, and the cloud service 1656 can send the requested data to the service gateway 1636. However, the cloud service 1656 may not initiate API calls to the service gateway 1636.

[0276] In some examples, the secure host lease 1604 can be directly connected to the service lease 1619, which would otherwise be isolated. The secure host subnet 1608 can communicate with the SSH subnet 1614 via the LPG 1610, and the LPG 1610 can enable two-way communication on otherwise isolated systems. Connecting the secure host subnet 1608 to the SSH subnet 1614 can enable the secure host subnet 1608 to access other entities within the service lease 1619.

[0277] The control plane VCN 1616 can allow users of the service lease 1619 to set or otherwise provision desired resources. The desired resources provisioned in the control plane VCN 1616 can be deployed or otherwise used in the data plane VCN 1618. In some examples, the control plane VCN 1616 can be isolated from the data plane VCN 1618, and the data plane mirror application layer 1640 of the control plane VCN 1616 can communicate with the data plane application layer 1646 of the data plane VCN 1618 via the VNIC 1642, and the VNIC 1642 can be included in both the data plane mirror application layer 1640 and the data plane application layer 1646.

[0278] In some examples, a user or customer of the system can make requests, such as create, read, update, or delete (CRUD) operations, over a public Internet 1654 that can transmit requests to a metadata management service 1652. The metadata management service 1652 can transmit the requests to a control plane VCN 1616 via an Internet gateway 1634. The requests can be received by one or more LB subnets 1622 included in a control plane DMZ layer 1620. The one or more LB subnets 1622 can determine that the requests are valid, and in response to that determination, the one or more LB subnets 1622 can transmit the requests to one or more application subnets 1626 included in a control plane application layer 1624. If the requests are authenticated and a call to the public Internet 1654 is required, then the call to the public Internet 1654 can be transmitted to a NAT gateway 1638 that can make calls to the public Internet 1654. Memory where the requests may expect to be stored can be stored in one or more DB subnets 1630.

[0279] In some examples, a data plane mirror application layer 1640 can facilitate direct communication between a control plane VCN 1616 and a data plane VCN 1618. For example, it may be desirable to apply configuration changes, updates, or other appropriate modifications to resources included in the data plane VCN 1618. Via a VNIC 1642, the control plane VCN 1616 can communicate directly with resources included in the data plane VCN 1618 and thereby can perform configuration changes, updates, or other appropriate modifications.

[0280] In some embodiments, a control plane VCN 1616 and a data plane VCN 1618 can be included in a service tenancy 1619. In such a case, a user or customer of the system may not own or operate the control plane VCN 1616 or the data plane VCN 1618. Instead, an IaaS provider can own or operate the control plane VCN 1616 and the data plane VCN 1618, both of which can be included in the service tenancy 1619. This embodiment can enable isolation of networks that may prevent a user or customer from interacting with resources of other users or other customers. Additionally, this embodiment can allow a user or customer of the system to privately store databases without relying on a public Internet 1654 that may not have a desired threat prevention level for storage.

[0281] In other embodiments, the (one or more) LB subnets 1622 included in the control plane VCN 1616 may be configured to receive signals from the service gateway 1636. In this embodiment, the control plane VCN 1616 and the data plane VCN 1618 may be configured to be invoked by a customer of the IaaS provider without invoking the public Internet 1654. A customer of the IaaS provider may desire this embodiment because the (one or more) databases used by the customer may be controlled by the IaaS provider and may be stored on the service lease 1619, which may be isolated from the public Internet 1654.

[0282] Figure 17 is a block diagram 1700 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1702 (e.g., Figure 16 the service operator 1602) may be communicatively coupled to a secure host lease 1704 (e.g., Figure 16 the secure host lease 1604), which may include a virtual cloud network (VCN) 1706 (e.g., Figure 16 the VCN 1606) and a secure host subnet 1708 (e.g., Figure 16 the secure host subnet 1608). The VCN 1706 may include a local peering gateway (LPG) 1710 (e.g., Figure 16 the LPG 1610), which may be communicatively coupled to a secure shell (SSH) VCN 1712 via the LPG 1710 included in the SSH VCN 1712 (e.g., Figure 16 the SSH VCN 1612). The SSH VCN 1712 may include an SSH subnet 1714 (e.g., Figure 16 the SSH subnet 1614), and the SSH VCN 1712 may be communicatively coupled to a control plane VCN 1716 via the LPG 1710 included in the control plane VCN 1716 (e.g., Figure 16 the control plane VCN 1616). The control plane VCN 1716 may be included in a service lease 1719 (e.g., Figure 16 the service lease 1619), and a data plane VCN 1718 (e.g., Figure 16 the data plane VCN 1618) may be included in a customer lease 1721 that may be owned or operated by a user or customer of the system.

[0283] The control plane VCN 1716 may include a control plane DMZ layer 1720 that may include the (one or more) LB subnets 1722 (e.g., Figure 16 the (one or more) LB subnets 1622) (e.g., Figure 16 The control plane DMZ layer 1620), which may include one or more application subnets 1726 (e.g., Figure 16 The control plane application layer 1724 of one or more application subnets 1626), e.g., Figure 16 The control plane application layer 1624), which may include one or more database (DB) subnets 1730 (e.g., similar to Figure 16 One or more DB subnets 1630), the control plane data layer 1728 (e.g., Figure 16 The control plane data layer 1628). One or more LB subnets 1722 included in the control plane DMZ layer 1720 may be communicatively coupled to one or more application subnets 1726 included in the control plane application layer 1724 and an Internet gateway 1734 that may be included in the control plane VCN 1716 (e.g., Figure 16 The Internet gateway 1634), and one or more application subnets 1726 may be communicatively coupled to one or more DB subnets 1730 included in the control plane data layer 1728, as well as a service gateway 1736 (e.g., Figure 16 The service gateway) and a network address translation (NAT) gateway 1738 (e.g., Figure 16 The NAT gateway 1638). The control plane VCN 1716 may include a service gateway 1736 and a NAT gateway 1738.

[0284] The control plane VCN 1716 may include a data plane mirror application layer 1740 that may include one or more application subnets 1726 (e.g., Figure 16 The data plane mirror application layer 1640). One or more application subnets 1726 included in the data plane mirror application layer 1740 may include a virtual network interface controller (VNIC) 1742 that may execute a compute instance 1744 (e.g., similar to Figure 16 The compute instance 1644) (e.g., the VNIC of 1642). The compute instance 1744 may facilitate communication between one or more application subnets 1726 of the data plane mirror application layer 1740 and one or more application subnets 1726 that may be included in the data plane application layer 1746 (e.g., Figure 16 The data plane application layer 1646) via the VNIC 1742 included in the data plane mirror application layer 1740 and the VNIC 1742 included in the data plane application layer 1746.

[0285] The Internet gateway 1734 included in the control plane VCN 1716 may be communicatively coupled to a metadata management service 1752 (e.g., Figure 16 The metadata management service 1652), and the metadata management service 1752 can be communicatively coupled to a public Internet 1754 (e.g., Figure 16 the public Internet 1654). The public Internet 1754 can be communicatively coupled to a NAT gateway 1738 included in the control plane VCN 1716. A service gateway 1736 included in the control plane VCN 1716 can be communicatively coupled to a cloud service 1756 (e.g., Figure 16 the cloud service 1656).

[0286] In some examples, the data plane VCN 1718 can be included in a customer tenancy 1721. In this case, the IaaS provider can provide a control plane VCN 1716 for each customer, and the IaaS provider can set up a unique compute instance 1744 included in a service tenancy 1719 for each customer. Each compute instance 1744 can permit communication between the control plane VCN 1716 included in the service tenancy 1719 and the data plane VCN 1718 included in the customer tenancy 1721. The compute instance 1744 can permit resources provisioned in the control plane VCN 1716 included in the service tenancy 1719 to be deployed or otherwise used in the data plane VCN 1718 included in the customer tenancy 1721.

[0287] In other examples, a customer of the IaaS provider can have a database that exists in the customer tenancy 1721. In this example, the control plane VCN 1716 can include a data plane mirror application layer 1740, which can include one or more application subnets 1726. The data plane mirror application layer 1740 can reside in the data plane VCN 1718, but the data plane mirror application layer 1740 may not be in the data plane VCN 1718. That is, the data plane mirror application layer 1740 can access the customer tenancy 1721, but the data plane mirror application layer 1740 may not exist in the data plane VCN 1718 or be owned or operated by the customer of the IaaS provider. The data plane mirror application layer 1740 can be configured to make calls to the data plane VCN 1718, but may not be configured to make calls to any entity included in the control plane VCN 1716. The customer may desire to deploy or otherwise use resources provisioned in the control plane VCN 1716 in the data plane VCN 1718, and the data plane mirror application layer 1740 can facilitate the customer's desired deployment or other use of the resources.

[0288] In some embodiments, a customer of an IaaS provider can apply filters to the data plane VCN 1718. In this embodiment, the customer can determine what the data plane VCN 1718 can access, and the customer can restrict access from the data plane VCN 1718 to the public Internet 1754. The IaaS provider may not be able to apply filters or otherwise control the access of the data plane VCN 1718 to any external network or database. Applying filters and controls by the customer to the data plane VCN 1718 included in the customer lease 1721 can help isolate the data plane VCN 1718 from other customers and the public Internet 1754.

[0289] In some embodiments, a cloud service 1756 can be invoked by a service gateway 1736 to access services that may not be present on the public Internet 1754, the control plane VCN 1716, or the data plane VCN 1718. The connection between the cloud service 1756 and the control plane VCN 1716 or the data plane VCN 1718 may not be real-time or continuous. The cloud service 1756 can exist on a different network owned or operated by the IaaS provider. The cloud service 1756 can be configured to receive calls from the service gateway 1736 and can be configured not to receive calls from the public Internet 1754. Some cloud services 1756 can be isolated from other cloud services 1756, and the control plane VCN 1716 can be isolated from cloud services 1756 that may not be in the same region as the control plane VCN 1716. For example, the control plane VCN 1716 may be located in "Region 1", and the cloud service "Deployment 16" may be located in Region 1 and "Region 2". If the service gateway 1736 included in the control plane VCN 1716 located in Region 1 makes a call to Deployment 16, then the call can be transmitted to Deployment 16 in Region 1. In this example, the control plane VCN 1716 or Deployment 16 in Region 1 may not be communicatively coupled or otherwise communicate with Deployment 16 in Region 2.

[0290] Figure 18 is a block diagram 1800 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1802 (e.g., Figure 16 service operator 1602 of Figure 16 can be communicatively coupled to a secure host lease 1804 (e.g., Figure 16 secure host lease 1604 of Figure 16 which can include a virtual cloud network (VCN) 1806 (e.g., Figure 16 1610), which may be communicatively coupled to the SSH VCN 1812 via the LPG 1810 contained in the SSH VCN 1812 (e.g., Figure 16 SSH VCN 1812). SSH VCN 1812 may include SSH subnet 1814 (e.g., Figure 16 SSH subnet 1614 of the control plane VCN 1816), and SSH VCN 1812 can be communicatively coupled to control plane VCN 1816 via LPG 1810 contained in control plane VCN 1816 (e.g., Figure 16 1616) and is coupled to the data plane VCN 1818 via the LPG 1810 included in the data plane VCN 1818 (e.g., Figure 16 The control plane VCN 1816 and the data plane VCN 1818 may be included in a service lease 1819 (e.g., Figure 16 Service lease 1619).

[0291] The control plane VCN 1816 may include a subnet 1822 (e.g., Figure 16 LB subnet(s) 1622) of the control plane DMZ layer 1820 (e.g., Figure 16 The control plane DMZ layer 1620 may include (one or more) application subnets 1826 (e.g., similar to Figure 16 (one or more) application subnets 1626) of the control plane application layer 1824 (e.g., Figure 16 ), and a control plane data layer 1828 (e.g., Figure 16 1828 of the control plane data layer 1820). The LB subnet(s) 1822 contained in the control plane DMZ layer 1820 may be communicatively coupled to the application subnet(s) 1826 contained in the control plane application layer 1824 and the Internet gateway 1834 (e.g., Figure 16 1634), and the application subnet(s) 1826 may be communicatively coupled to the DB subnet(s) 1830 and the service gateway 1836 (e.g., Figure 16 ) and a network address translation (NAT) gateway 1838 (e.g., Figure 16 The control plane VCN 1816 may include a service gateway 1836 and a NAT gateway 1838.

[0292] The data plane VCN 1818 may include a data plane application layer 1846 (e.g., Figure 16 the data plane application layer 1646 of), a data plane DMZ layer 1848 (e.g., Figure 16 the data plane DMZ layer 1648 of), and a data plane data layer 1850 (e.g., Figure 16 the data plane data layer 1650 of). The data plane DMZ layer 1848 may include one or more trusted application subnets 1860 and one or more untrusted application subnets 1862 that may be communicatively coupled to the data plane application layer 1846 and one or more LB subnets 1822 of an Internet gateway 1834 included in the data plane VCN 1818. One or more trusted application subnets 1860 may be communicatively coupled to a service gateway 1836 included in the data plane VCN 1818, a NAT gateway 1838 included in the data plane VCN 1818, and one or more DB subnets 1830 included in the data plane data layer 1850. One or more untrusted application subnets 1862 may be communicatively coupled to a service gateway 1836 included in the data plane VCN 1818 and one or more DB subnets 1830 included in the data plane data layer 1850. The data plane data layer 1850 may include one or more DB subnets 1830 that may be communicatively coupled to a service gateway 1836 included in the data plane VCN 1818.

[0293] One or more untrusted application subnets 1862 may include one or more primary VNICs 1864(1)-(N) that may be communicatively coupled to tenant virtual machines (VMs) 1866(1)-(N). Each tenant VM 1866(1)-(N) may be communicatively coupled to a corresponding application subnet 1867(1)-(N) that may be included in a corresponding container egress VCN 1868(1)-(N), and the corresponding container egress VCNs 1868(1)-(N) may be included in corresponding customer tenancies 1870(1)-(N). Corresponding secondary VNICs 1872(1)-(N) may facilitate communication between one or more untrusted application subnets 1862 included in the data plane VCN 1818 and application subnets included in the container egress VCNs 1868(1)-(N). Each container egress VCN 1868(1)-(N) may include a NAT gateway 1838 that may be communicatively coupled to a public Internet 1854 (e.g., Figure 16 the public Internet 1654 of).

[0294] An Internet gateway 1834 included in the control plane VCN 1816 and included in the data plane VCN 1818 can be communicatively coupled to a metadata management service 1852 (e.g., Figure 16 the metadata management system 1652), and the metadata management service 1852 can be communicatively coupled to the public Internet 1854. The public Internet 1854 can be communicatively coupled to a NAT gateway 1838 included in the control plane VCN 1816 and included in the data plane VCN 1818. A service gateway 1836 included in the control plane VCN 1816 and included in the data plane VCN 1818 can be communicatively coupled to a cloud service 1856.

[0295] In some embodiments, the data plane VCN 1818 can be integrated with a customer lease 1870. In some cases, such as when it may be desirable to support during code execution, this integration may be useful or desirable for customers of an IaaS provider. A customer may provide code to run that may be disruptive, may communicate with other customer resources, or may otherwise cause undesired effects. In response to this, the IaaS provider can determine whether to run the code given to the IaaS provider by the customer.

[0296] In some examples, a customer of an IaaS provider can grant the IaaS provider temporary network access and request functionality attached to the data plane layer application 1846. The code running the functionality can be executed in VMs 1866(1)-(N), and the code can be not configured to run anywhere else on the data plane VCN 1818. Each VM 1866(1)-(N) can be connected to a customer lease 1870. The corresponding containers 1871(1)-(N) included in the VMs 1866(1)-(N) can be configured to run the code. In this case, there can be double isolation (e.g., the containers 1871(1)-(N) run the code, where the containers 1871(1)-(N) may be at least included in the VMs 1866(1)-(N) included in one or more untrusted application subnets 1862), which can help prevent incorrect or otherwise undesired code from corrupting the IaaS provider's network or corrupting the networks of different customers. The containers 1871(1)-(N) can be communicatively coupled to the customer lease 1870 and can be configured to transmit or receive data from the customer lease 1870. The containers 1871(1)-(N) can be not configured to transmit or receive data from any other entity in the data plane VCN 1818. After the code execution is complete, the IaaS provider can terminate or otherwise dispose of the containers 1871(1)-(N).

[0297] In some embodiments, the trusted application subnet(s) 1860 may run code that may be owned or operated by an IaaS provider. In this embodiment, the trusted application subnet(s) 1860 may be communicatively coupled to the DB subnet(s) 1830 and configured to perform CRUD operations in the DB subnet(s) 1830. The untrusted application subnet(s) 1862 may be communicatively coupled to the DB subnet(s) 1830, but in this embodiment, the untrusted application subnet(s) may be configured to perform read operations in the DB subnet(s) 1830. Containers 1871(1)-(N) that may be included in each customer's VM 1866(1)-(N) and may run code from the customer may not be communicatively coupled to the DB subnet(s) 1830.

[0298] In other embodiments, the control plane VCN 1816 and the data plane VCN 1818 may not be directly communicatively coupled. In this embodiment, there may be no direct communication between the control plane VCN 1816 and the data plane VCN 1818. However, communication may occur indirectly through at least one method. The LPG 1810 may be established by the IaaS provider, which may facilitate communication between the control plane VCN 1816 and the data plane VCN 1818. In another example, the control plane VCN 1816 or the data plane VCN 1818 may invoke cloud services 1856 via the service gateway 1836. For example, an invocation of cloud services 1856 from the control plane VCN 1816 may include a request for a service that may communicate with the data plane VCN 1818.

[0299] Figure 19 is a block diagram 1900 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1902 (e.g., Figure 16 the service operator 1602) may be communicatively coupled to a secure host lease 1904 (e.g., Figure 16 the secure host lease 1604), which may include a virtual cloud network (VCN) 1906 (e.g., Figure 16 the VCN 1606) and a secure host subnet 1908 (e.g., Figure 16 the secure host subnet 1608). The VCN 1906 may include an LPG 1910 (e.g., Figure 16 the LPG 1610), which may be via an SSH VCN 1912 (e.g., Figure 16 The LPG 1910 in the SSH VCN 1612 is communicatively coupled to the SSH VCN 1912. The SSH VCN 1912 may include an SSH subnet 1914 (e.g., Figure 16 the SSH subnet 1614), and the SSH VCN 1912 may be communicatively coupled to the control plane VCN 1916 via the LPG 1910 included in the control plane VCN 1916 (e.g., Figure 16 the control plane VCN 1616) and coupled to the data plane VCN 1918 via the LPG 1910 included in the data plane VCN 1918 (e.g., Figure 16 the data plane 1618). The control plane VCN 1916 and the data plane VCN 1918 may be included in a service tenancy 1919 (e.g., Figure 16 the service tenancy 1619).

[0300] The control plane VCN 1916 may include a control plane DMZ layer 1920 that may include one or more LB subnets 1922 (e.g., Figure 16 one or more LB subnets 1622), a control plane application layer 1924 that may include one or more application subnets 1926 (e.g., Figure 16 the control plane DMZ layer 1620), a control plane application layer 1924 that may include one or more application subnets 1926 (e.g., Figure 16 one or more application subnets 1626), a control plane data layer 1928 that may include one or more DB subnets 1930 (e.g., Figure 16 the control plane application layer 1624), a control plane data layer 1928 that may include one or more DB subnets 1930 (e.g., Figure 18 one or more DB subnets 1830). One or more LB subnets 1922 included in the control plane DMZ layer 1920 may be communicatively coupled to one or more application subnets 1926 included in the control plane application layer 1924 and an Internet gateway 1934 that may be included in the control plane VCN 1916 (e.g., Figure 16 the control plane data layer 1628), and one or more application subnets 1926 may be communicatively coupled to one or more DB subnets 1930 included in the control plane data layer 1928, a service gateway 1936 (e.g., Figure 16 the Internet gateway 1634), and a network address translation (NAT) gateway 1938 (e.g., Figure 16 the service gateway) and a network address translation (NAT) gateway 1938 (e.g., Figure 16 the NAT gateway 1638). The control plane VCN 1916 may include a service gateway 1936 and a NAT gateway 1938.

[0301] The data plane VCN 1918 may include a data plane application layer 1946 (e.g., Figure 16 's data plane application layer 1646), a data plane DMZ layer 1948 (e.g., Figure 16 's data plane DMZ layer 1648)), and a data plane data layer 1950 (e.g., Figure 16 's data plane data layer 1650). The data plane DMZ layer 1948 may include one or more trusted application subnets 1960 (e.g., Figure 18 's one or more trusted application subnets 1860) and one or more untrusted application subnets 1962 (e.g., Figure 18 's one or more untrusted application subnets 1862) that are communicatively coupled to the data plane application layer 1946, and one or more LB subnets 1922 of the Internet gateway 1934 included in the data plane VCN 1918. The one or more trusted application subnets 1960 may be communicatively coupled to a service gateway 1936 included in the data plane VCN 1918, a NAT gateway 1938 included in the data plane VCN 1918, and one or more DB subnets 1930 included in the data plane data layer 1950. The one or more untrusted application subnets 1962 may be communicatively coupled to a service gateway 1936 included in the data plane VCN 1918 and one or more DB subnets 1930 included in the data plane data layer 1950. The data plane data layer 1950 may include one or more DB subnets 1930 that are communicatively coupled to a service gateway 1936 included in the data plane VCN 1918.

[0302] The one or more untrusted application subnets 1962 may include primary VNICs 1964(1)-(N) that are communicatively coupled to tenant virtual machines (VMs) 1966(1)-(N) residing within the one or more untrusted application subnets 1962. Each tenant VM 1966(1)-(N) may run code in a corresponding container 1967(1)-(N) and is communicatively coupled to an application subnet 1926 in the data plane application layer 1946 that may be included in a container egress VCN 1968. Corresponding secondary VNICs 1972(1)-(N) may facilitate communication between the one or more untrusted application subnets 1962 included in the data plane VCN 1918 and the application subnet included in the container egress VCN 1968. The container egress VCN may include a NAT gateway 1938 that is communicatively coupled to a public Internet 1954 (e.g., Figure 16 's public Internet 1654).

[0303] An Internet gateway 1934 included in the control plane VCN 1916 and an Internet gateway 1934 included in the data plane VCN 1918 can be communicatively coupled to a metadata management service 1952 (e.g., Figure 16 the metadata management system 1652), and the metadata management service 1952 can be communicatively coupled to the public Internet 1954. The public Internet 1954 can be communicatively coupled to a NAT gateway 1938 included in the control plane VCN 1916 and included in the data plane VCN 1918. A service gateway 1936 included in the control plane VCN 1916 and included in the data plane VCN 1918 can be communicatively coupled to a cloud service 1956.

[0304] In some examples, Figure 19 the pattern shown in the architecture of the block diagram 1900 of Figure 18 can be considered an exception to the pattern shown in the architecture of the block diagram 1800 of

[0305] In other examples, a customer can use containers 1967(1)-(N) to invoke cloud service 1956. In this example, the customer can run code in containers 1967(1)-(N) that requests services from cloud service 1956. Containers 1967(1)-(N) can transmit the request to secondary VNICs 1972(1)-(N), which can transmit the request to a NAT gateway that can transmit the request to public Internet 1954. Public Internet 1954 can transmit the request via Internet gateway 1934 to (one or more) LB subnets 1922 included in control plane VCN 1916. In response to determining that the request is valid, (one or more) LB subnets can transmit the request to (one or more) application subnets 1926, which can transmit the request via service gateway 1936 to cloud service 1956.

[0306] It should be appreciated that the IaaS architectures 1600, 1700, 1800, 1900 depicted in the figures can have other components in addition to those depicted. Additionally, the embodiments shown in the figures are merely some examples of cloud infrastructure systems that can incorporate the embodiments of the present disclosure. In some other embodiments, the IaaS system can have more or fewer components than shown in the figures, can combine two or more components, or can have a different configuration or arrangement of components.

[0307] In certain embodiments, the IaaS systems described herein can include application suite, middleware, and database service offerings that are delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such an IaaS system is the Oracle Cloud Infrastructure (OCI) offered by the present assignee.

[0308] Figure 20 An example computer system 2000 in which various embodiments can be implemented is illustrated. System 2000 can be used to implement any of the above computer systems. As shown, computer system 2000 includes a processing unit 2004 that communicates with a plurality of peripheral subsystems via a bus subsystem 2002. These peripheral subsystems can include a processing acceleration unit 2006, an I / O subsystem 2008, a storage subsystem 2018, and a communication subsystem 2024. Storage subsystem 2018 includes a tangible computer-readable storage medium 2022 and system memory 2010.

[0309] The bus subsystem 2002 provides a mechanism for enabling the various components and subsystems of the computer system 2000 to communicate with each other as intended. Although the bus subsystem 2002 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. The bus subsystem 2002 can be any of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures can include Industry Standard Architecture (ISA) buses, Micro Channel Architecture (MCA) buses, Enhanced ISA (EISA) buses, Video Electronics Standards Association (VESA) local buses, and Peripheral Component Interconnect (PCI) buses, which can be implemented as Mezzanine buses manufactured to the IEEE P1386.1 standard.

[0310] The processing unit 2004, which can be implemented as one or more integrated circuits (e.g., conventional microprocessors or microcontrollers), controls the operation of the computer system 2000. One or more processors can be included in the processing unit 2004. These processors can include single-core or multi-core processors. In certain embodiments, the processing unit 2004 can be implemented as one or more independent processing units 2032 and / or 2034, where each processing unit includes a single-core or multi-core processor. In other embodiments, the processing unit 2004 can also be implemented as a quad-core processing unit formed by integrating two dual-core processors onto a single chip.

[0311] In various embodiments, the processing unit 2004 can execute various programs in response to program code and can maintain multiple concurrently executing programs or processes. At any given time, some or all of the program code to be executed can reside in the (one or more) processors 2004 and / or the storage subsystem 2018. Through appropriate programming, the (one or more) processors 2004 can provide the various functions described above. The computer system 2000 can additionally include a processing acceleration unit 2006, which can include a digital signal processor (DSP), a dedicated processor, and so on.

[0312] The I / O subsystem 2008 can include user interface input devices and user interface output devices. User interface input devices can include a keyboard, a pointing device such as a mouse or trackball, a touchpad or touch screen incorporated into a display, a scroll wheel, a click wheel, a dial, buttons, switches, a keypad, an audio input device with a voice command recognition system, a microphone, and other types of input devices. User interface input devices can include, for example, motion sensing and / or gesture recognition devices, such as Microsoft's A motion sensor that enables a user to control and interact with an input device such as a Microsoft 360 game controller through a natural user interface using gestures and voice commands. The user interface input device may also include an eye gesture recognition device, such as one that detects eye activity from a user (e.g., a "blink" when taking a photo and / or making a menu selection) and converts the eye gesture into an input to the input device (e.g., a Google blink detector). Additionally, the user interface input device may include a voice recognition sensing device that enables the user to interact with a voice recognition system (e.g., a navigator) through voice commands. The user interface input device may also include, but is not limited to, a three-dimensional (3D) mouse, joystick or pointing stick, game pad, and graphics tablet, as well as audio / video devices such as speakers, digital cameras, digital video cameras, portable media players, webcams, image scanners, fingerprint scanners, barcode readers, 3D scanners, 3D printers, laser rangefinders, and eye tracking devices. Additionally, the user interface input device may include, for example, medical imaging input devices such as computed tomography, magnetic resonance imaging, positron emission tomography, and medical ultrasound devices. The user interface input device may also include, for example, audio input devices such as MIDI keyboards, digital musical instruments, etc.

[0313]

[0314] The user interface output device may include a display subsystem, indicator lights, or a non-visual display such as an audio output device, etc. The display subsystem may be a cathode ray tube (CRT), a flat panel device such as one using a liquid crystal display (LCD) or plasma display, a projection device, a touch screen, etc. In general, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computer system 2000 to a user or other computer. For example, the user interface output device may include, but is not limited to, various display devices that visually convey text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, automotive navigation systems, plotters, voice output devices, and modems.

[0315] The computer system 2000 may include a storage subsystem 2018 that contains software elements and is shown as currently residing in the system memory 2010. The system memory 2010 may store program instructions that are loadable and executable on the processing unit 2004, as well as data generated during the execution of these programs.

[0316] Depending on the configuration and type of the computer system 2000, the system memory 2010 can be volatile (such as random access memory (RAM)) and / or non-volatile (such as read-only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that can be immediately accessed by the processing unit 2004 and / or are currently being operated on and executed by the processing unit 2004. In some implementations, the system memory 2010 can include multiple different types of memory, such as static random access memory (SRAM) or dynamic random access memory (DRAM). In some implementations, a basic input / output system (BIOS), such as containing basic routines that help transfer information between elements of the computer system 2000 during startup, can typically be stored in the ROM. By way of example, but not limitation, the system memory 2010 is also shown to include application programs 2012, program data 2014, and an operating system 2016 that can include client applications, web browsers, middle-tier applications, relational database management systems (RDBMS), etc. By way of example, the operating system 2016 can include various versions of Microsoft Apple and / or Linux operating systems, various commercially available or UNIX-like operating systems (including but not limited to various GNU / Linux operating systems, Google OS, etc.) and / or mobile operating systems such as iOS, Phone, OS, 16OS and OS operating systems.

[0317] The storage subsystem 2018 can also provide a tangible computer-readable storage medium for storing the basic programming and data structures that provide the functionality of some embodiments. Software (programs, code modules, instructions) that provides the above functionality when executed by a processor can be stored in the storage subsystem 2018. These software modules or instructions can be executed by the processing unit 2004. The storage subsystem 2018 can also provide a repository for storing data used in accordance with the present disclosure.

[0318] The storage subsystem 2000 can also include a computer-readable storage medium reader 2020 that can be further connected to a computer-readable storage medium 2022. Together with and, optionally, in combination with the system memory 2010, the computer-readable storage medium 2022 can comprehensively represent remote, local, fixed, and / or removable storage devices plus storage media for temporarily and / or more persistently containing, storing, sending, and retrieving computer-readable information.

[0319] The computer-readable storage medium 2022 that contains code or portions of code may also include any suitable medium known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media implemented with any method or technology for the storage and / or transmission of information. This may include tangible computer-readable storage media such as RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic tape cartridges, tapes, magnetic disk storage or other magnetic storage devices, or other tangible computer-readable media. This may also include non-tangible computer-readable media such as data signals, data transmissions or any other medium that can be used to transmit the desired information and can be accessed by the computing system 2000.

[0320] For example, the computer-readable storage medium 2022 may include a hard disk drive that reads from or writes to a non-removable non-volatile magnetic medium, a disk drive that reads from or writes to a removable non-volatile disk, and an optical disk drive that reads from or writes to a removable non-volatile optical disk (such as a CD ROM, DVD, and disk or other optical medium). The computer-readable storage medium 2022 may include, but is not limited to, drives, flash cards, universal serial bus (USB) flash drives, secure digital (SD) cards, DVD disks, digital audio tapes, and so on. The computer-readable storage medium 2022 may also include solid state drives (SSDs) based on non-volatile memory (such as flash memory-based SSDs, enterprise flash drives, solid state ROMs, etc.), SSDs based on volatile memory (such as solid state RAM, dynamic RAM, static RAM), DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs that use a combination of DRAM and flash memory-based SSDs. Disk drives and their associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 2000.

[0321] The communication subsystem 2024 provides an interface to other computer systems and networks. The communication subsystem 2024 serves as an interface for receiving data from other systems and sending data from the computer system 2000 to other systems. For example, the communication subsystem 2024 can enable the computer system 2000 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 2024 can include radio frequency (RF) transceiver components for accessing wireless voice and / or data networks (e.g., using cellular phone technologies such as advanced data network technologies like 3G, 4G, or EDGE (Enhanced Data Rates for Global Evolution), Wi-Fi (IEEE 802.11 series standards), or other mobile communication technologies, or any combination thereof), global positioning system (GPS) receiver components, and / or other components. In some embodiments, as an addition or alternative to the wireless interface, the communication subsystem 2024 can provide a wired network connection (e.g., Ethernet).

[0322] In some embodiments, the communication subsystem 2024 can also receive input communications in the form of structured and / or unstructured data feeds 2026, event streams 2028, event updates 2030, etc. on behalf of one or more users who may use the computer system 2000.

[0323] For example, the communication subsystem 2024 can be configured to receive data feeds 2026 from users of social networks and / or other communication services in real time, such as feeds, updates, web feeds such as Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third-party information sources.

[0324] In addition, the communication subsystem 2024 can also be configured to receive data in the form of continuous data streams, which can include event streams 2028 and / or event updates 2030 of real-time events that can be continuous or unbounded in nature and have no explicit termination. Examples of applications that generate continuous data can include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automotive traffic monitoring, and so on.

[0325] The communication subsystem 2024 can also be configured to output structured and / or unstructured data feeds 2026, event streams 2028, event updates 2030, etc. to one or more databases, which can communicate with one or more streaming data source computers coupled to the computer system 2000.

[0326] The computer system 2000 can be one of various types, including handheld portable devices (e.g., cellular phones, computing tablets, PDAs), wearable devices (e.g., Glass head-mounted displays), PCs, workstations, mainframes, kiosks, server racks, or any other data processing system.

[0327] Due to the ever-changing nature of computers and networks, the description of the computer system 2000 depicted in the figure is merely to serve as a specific example. Many other configurations with more or fewer components than the system depicted in the figure are possible. For example, custom hardware can also be used and / or specific elements can be implemented in hardware, firmware, software (including applets), or combinations thereof. Additionally, connections to other computing devices such as network input / output devices can also be employed. Based on the disclosure and teachings provided herein, those of ordinary skill in the art will recognize other ways and / or methods of implementing the various embodiments.

[0328] Although specific embodiments have been described, various modifications, alterations, alternative constructions, and equivalent forms are also included within the scope of the present disclosure. The embodiments are not limited to operating within certain specific data processing environments, but can operate freely within multiple data processing environments. Additionally, although the embodiments have been described using a specific series of transactions and steps, those skilled in the art should appreciate that the scope of the present disclosure is not limited to the described series of transactions and steps. The various features and aspects of the above embodiments can be used alone or in combination.

[0329] Furthermore, although the embodiments have been described using a specific combination of hardware and software, it should be recognized that other combinations of hardware and software are also within the scope of the present disclosure. The embodiments can be implemented using only hardware, or only software, or using a combination thereof. The various processes described herein can be implemented in any combination on the same processor or on different processors. Accordingly, in cases where a component or module is described as being configured to perform certain operations, such a configuration can be accomplished by, for example, designing electronic circuitry to perform the operations, programming a programmable electronic circuit (such as a microprocessor) to perform the operations, or any combination thereof. Processes can communicate using a variety of techniques, including but not limited to conventional techniques for inter-process communication, and different pairs of processes can use different techniques, or the same pair of processes can use different techniques at different times.

[0330] Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive. However, it is obvious that additions, subtractions, deletions, and other modifications and changes can be made thereto without departing from the broader spirit and scope set forth in the claims. Thus, although specific disclosed embodiments have been described, these are not intended to be limiting. Various modifications and equivalent forms are within the scope of the following claims.

[0331] In the context of describing the disclosed embodiments, particularly in the context of the following claims, the terms "a", "an", "the", and similar references are to be construed to cover both the singular and the plural unless otherwise indicated herein or clearly contradicted by the context. Unless otherwise noted, the terms "comprising", "having", "including", and "containing" are to be construed as open-ended terms (i.e., meaning "including but not limited to"). The term "connected" shall be construed to mean partly or wholly contained in, attached to, or joined together, even if there is something in between. Unless otherwise indicated herein, the recitation of a range of values herein is merely intended to be a shorthand method of referring individually to each separate value falling within the range, and each separate value is incorporated into the specification as if it were individually recited herein. Unless otherwise indicated herein or clearly contradicted by the context, all methods described herein can be performed in any suitable order. The use of any and all examples, or exemplary language (e.g., "such as") provided herein is intended merely to better illuminate the embodiments and does not pose a limitation on the scope of the disclosure unless otherwise stated. Any language in the specification should not be construed as indicating any non-claimed element as essential to the practice of the disclosure.

[0332] Disjunctive language, such as the phrase "at least one of X, Y, or Z", unless otherwise explicitly stated, is intended to be understood in the context generally used for indicating items, terms, etc. and can be X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Thus, such disjunctive language generally is not intended to and should not imply that certain embodiments require the presence of at least one of X, at least one of Y, or at least one of Z each.

[0333] Preferred embodiments of the present disclosure are described herein, including the best mode known for practicing the present disclosure. Variations of those preferred embodiments will become apparent to those of ordinary skill in the art upon reading the above description. Those of ordinary skill in the art should be able to appropriately adopt such variations and practice the present disclosure in a manner different from that specifically described herein. Accordingly, the present disclosure includes all modifications and equivalent forms of the subject matter recited in the appended claims as permitted by applicable law. In addition, unless otherwise indicated herein, the present disclosure includes any combination of the above elements in all possible variations.

[0334] All references cited herein, including publications, patent applications, and patents, are incorporated herein by reference to the same extent as if each reference were individually and specifically indicated to be incorporated by reference and set forth in full herein. In the foregoing specification, aspects of the disclosure have been described with reference to specific embodiments thereof, but those skilled in the art will recognize that the disclosure is not limited thereto. The various features and aspects of the foregoing disclosure may be used singly or in combination. Additionally, embodiments may be used in any number of environments and applications other than those described herein without departing from the broader spirit and scope of this specification. Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive.< / realm>

Claims

1. A method, comprising: receiving, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a lease of a user in a first cloud environment, the multi-cloud infrastructure providing one or more services of the first cloud environment to a customer of a second cloud environment; determining, based on the identifier, whether a network link has been established between the lease of the user in the first cloud environment and an account of the user in the second cloud environment; in response to determining that the network link has not been established, redirecting the user to a second GUI associated with the second cloud environment, the redirecting facilitating the configuration of a set of prerequisite resources in the second cloud environment for the user; and after configuring the set of prerequisite resources in the second cloud environment, initiating a workflow to establish a network link between the first cloud environment and the second cloud environment.

2. The method according to claim 1, wherein a first cloud infrastructure of the first cloud environment is provided by a first cloud service provider (CSP), and a second cloud infrastructure corresponding to the second cloud environment is provided by a second CSP different from the first CSP, the first cloud environment being different from the second cloud environment.

3. The method according to claim 1 or 2, wherein the first GUI corresponds to a registration GUI of the multi-cloud console, and the second GUI corresponds to a login GUI associated with a portal of the second cloud environment.

4. The method according to claim 1, 2 or 3, wherein the determining further comprises: verifying whether a link resource object has been created, wherein the link resource object includes information linking the lease of the user in the first cloud environment to the account of the user in the second cloud environment, and includes information indicating whether a network link has been created; and in response to determining that the network link has not been established, creating a link resource object.

5. The method according to any one of the preceding claims, wherein the set of prerequisite resources includes a hierarchy of resources, and each resource in the hierarchy of resources is associated with a corresponding role.

6. The method according to claim 5, wherein the hierarchy of roles associated with the hierarchy of resources includes a networking role, an observability role and a verifier role, and wherein the networking role allows the creation of a network link between the first cloud environment and the second cloud environment, the observability role allows an observability module included in the multi-cloud infrastructure to publish data associated with resources deployed in the first cloud environment to the second cloud environment, and the verifier role allows the control plane of the multi-cloud infrastructure to perform user verification.

7. The method according to any one of the preceding claims, further comprising: selecting a first primary region for the first cloud environment and a second primary region for the second cloud environment; and establishing a network link between the first primary region and the second primary region.

8. The method according to any one of the preceding claims, wherein the workflow is further configured to create a compartment in the lease of the user in the first cloud environment, the compartment hosting at least one resource associated with the one or more services.

9. The method according to any one of the preceding claims, further comprising: In response to establishing a network link between a first cloud environment and a second cloud environment, redirect a user to a third GUI of a multi-cloud console, the third GUI providing a list of the one or more services provisioned by the multi-cloud infrastructure.

10. One or more computer-readable non-transitory media storing computer-executable instructions that, when executed by one or more processors, cause: Receive, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a lease of a user in a first cloud environment, wherein the multi-cloud infrastructure provides one or more services of the first cloud environment to a customer of a second cloud environment; Determine, based on the identifier, whether a network link has been established between the lease of the user in the first cloud environment and an account of the user in the second cloud environment; In response to determining that the network link has not been established, redirect the user to a second GUI associated with the second cloud environment, the redirect facilitating the configuration of a set of prerequisite resources in the second cloud environment for the user; And After configuring the set of prerequisite resources in the second cloud environment, initiate a workflow for establishing a network link between the first cloud environment and the second cloud environment.

11. The one or more computer-readable non-transitory media storing computer-executable instructions as recited in claim 10, wherein a first cloud infrastructure of the first cloud environment is provided by a first cloud service provider (CSP), and a second cloud infrastructure corresponding to the second cloud environment is provided by a second CSP different from the first CSP, and the first cloud environment is different from the second cloud environment.

12. The one or more computer-readable non-transitory media storing computer-executable instructions as recited in claim 10 or 11, wherein the first GUI corresponds to a registration GUI of the multi-cloud console, and the second GUI corresponds to a login GUI associated with a portal of the second cloud environment.

13. The one or more computer-readable non-transitory media storing computer-executable instructions as recited in claim 10, 11, or 12, wherein the determining further Comprises: Verifying whether a link resource object has been created, wherein the link resource object includes information linking the lease of the user in the first cloud environment to the account of the user in the second cloud environment, and includes information indicating whether a network link has been created; And In response to determining that the network link has not been established, create a link resource object.

14. The one or more computer-readable non-transitory media storing computer-executable instructions as recited in any one of claims 10 to 13, wherein the set of prerequisite resources includes a hierarchy of resources, and each resource in the hierarchy of resources is associated with a corresponding role.

15. The one or more computer-readable non-transitory media storing computer-executable instructions as recited in claim 14, wherein the hierarchy of roles associated with the hierarchy of resources includes a networking role, an observability role, and a verifier role, and wherein The networking role allows for creating a network link between the first cloud environment and the second cloud environment, The observability role allows an observability module included in the multi-cloud infrastructure to publish data associated with resources deployed in the first cloud environment to the second cloud environment, and The verifier role allows the control plane of a multi-cloud infrastructure to perform user verification.

16. The one or more computer-readable non-transitory media storing computer-executable instructions according to any one of claims 10 to 15, further comprising selecting a first primary region for a first cloud environment and a second primary region for a second cloud environment; and establishing a network link between the first primary region and the second primary region.

17. The one or more computer-readable non-transitory media storing computer-executable instructions according to any one of claims 10 to 16, wherein the workflow is further configured to create a compartment in a tenancy of a user in a first cloud environment, the compartment hosting at least one resource associated with the one or more services.

18. The one or more computer-readable non-transitory media storing computer-executable instructions according to any one of claims 10 to 17, further comprising: redirecting the user to a third GUI of a multi-cloud console in response to establishing a network link between the first cloud environment and the second cloud environment, the third GUI providing a list of the one or more services provisioned by the multi-cloud infrastructure.

19. A computing device, comprising: one or more processors; and a memory including instructions that, when executed by the one or more processors, cause the computing device to at least: receive, at a first GUI of a multi-cloud console of a multi-cloud infrastructure, an identifier of a tenancy of a user in a first cloud environment, wherein the multi-cloud infrastructure provides one or more services of the first cloud environment to customers of a second cloud environment; determine, based on the identifier, whether a network link has been established between the tenancy of the user in the first cloud environment and an account of the user in the second cloud environment; in response to determining that the network link has not been established, redirect the user to a second GUI associated with the second cloud environment, wherein redirecting the user facilitates configuring a set of prerequisite resources in the second cloud environment for the user; and initiate a workflow to establish a network link between the first cloud environment and the second cloud environment after configuring the set of prerequisite resources in the second cloud environment.

20. The computing device according to claim 19, wherein the first cloud infrastructure of the first cloud environment is provided by a first cloud service provider (CSP), and the second cloud infrastructure corresponding to the second cloud environment is provided by a second CSP different from the first CSP, and the first cloud environment is different from the second cloud environment.