Configuration of node ports for maintenance without load balancer coordination
By implementing network policies in the cluster network, simulating node failures and pre-equipping nodes to process transaction data, the problem of transaction data interruption during node failure processing and maintenance is solved, and the stability and reliability of the network are improved.
Patent Information
- Application Number
- CN202280101307.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-10
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-11-10
AI Technical Summary
In clustered networks, there are difficulties in handling node failures, especially during maintenance periods, which may lead to interruption in transaction data processing and affect network stability.
The network policy is received and implemented through the network management server, and the second port of the node is configured to simulate a failure, preventing the load balancer from transmitting transaction data to the node being maintained. At the same time, the backup nodes are pre-configured to process transaction data and cancel the network policy after maintenance is completed to resume normal operation.
It effectively avoids transaction data processing interruptions caused by node maintenance, improves network stability and reliability, and reduces the overall time of maintenance period.
Smart Images

Figure CN120092434A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the configuration of nodes in a cluster network based on network policies. In particular, the techniques herein disclose network policies that simulate node failures that prevent new transaction data from being sent to nodes undergoing maintenance. Summary of the Invention
[0002] In one aspect, this disclosure provides a method that includes: receiving, by a network management server, a network policy corresponding to a node in a cluster pool that includes a plurality of nodes, where the node includes a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implementing, by the network management server, the network policy to configure a port limit for the second port of the node, where the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining, by the network management server, that after implementing the network policy in preparation for maintenance of the node, the transaction data received at the first port is processed by the node; and revoking, by the network management server, the network policy based on a network policy status indicator after the maintenance at the node is complete to lift the port limit at the second port.
[0003] In another aspect, this disclosure provides a system that includes: a plurality of nodes; a cluster pool that includes the plurality of nodes; a load balancer server; and a network management server communicatively coupled to the plurality of nodes, where the network management server is configured to: receive a network policy corresponding to a node in the cluster pool, where the cluster pool includes a plurality of nodes, and where the nodes in the cluster pool include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implement the network policy to configure a port limit for the second port of the node, where the port limit causes the load balancer to stop transmitting the transaction data to the first port; determine that after implementing the network policy in preparation for maintenance of the node, the transaction data received at the first port is processed by the node; and revoke the network policy based on a network policy status indicator after the maintenance at the node is complete to lift the port limit at the second port.
[0004] In yet another aspect, the present disclosure provides a non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including: receiving a network policy corresponding to nodes in a cluster pool including a plurality of nodes, wherein the nodes include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; provisioning a standby node to the cluster pool; initializing the standby node to receive the transaction data; implementing the network policy to configure a port limit for the second port of the nodes, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining that after implementing the network policy in preparation for maintenance of the nodes, the transaction data received at the first port is processed by the nodes; and based on a network policy status indicator, revoking the network policy after the maintenance is completed at the nodes to lift the port limit at the second port. BRIEF DESCRIPTION OF THE DRAWINGS
[0005] In the description, for purposes of explanation and not limitation, specific details are set forth, such as specific aspects, procedures, techniques, etc. to provide a thorough understanding of the technical aspects of the present invention. However, it will be apparent to those skilled in the art that the technical aspects of the present invention may be practiced in other aspects different from these specific details.
[0006] The drawings are incorporated into the specification and form a part of the specification, together with the following detailed description, and are used to further illustrate aspects of the concepts embodying the claimed disclosure and to explain various principles and advantages of those aspects. In the drawings, like reference numerals refer to the same or functionally similar elements throughout different views.
[0007] The [devices, systems, and methods] disclosed herein have been represented in the drawings by conventional symbols, where appropriate, showing only those specific details relevant to an understanding of the various aspects of the present disclosure, so as not to obscure the present disclosure with details that will be apparent to those of ordinary skill in the art having the benefit of the description herein.
[0008] Figure 1 A network architecture of a cluster network including a plurality of worker nodes according to at least one aspect of the present disclosure is shown.
[0009] Figure 2 A cluster network including a load balancer and a plurality of worker nodes in a cluster pool according to at least one aspect of the present disclosure is shown.
[0010] Figure 3 is a logic flow diagram for implementing a new network policy according to at least one aspect of the present disclosure.
[0011] Figure 4is a logic flow diagram for revoking a network policy according to at least one aspect of the present disclosure.
[0012] Figure 5 is a logic flow diagram for pre-provisioning a standby node before implementing a network policy to simulate a failure at a first node according to at least one aspect of the present disclosure.
[0013] Figure 6 presents a block diagram of a computer device according to at least one aspect of the present disclosure.
[0014] Figure 7 is an illustrative representation of an example system including a host within which an instruction set for performing any one or more of the methods discussed herein can be executed according to at least one aspect of the present disclosure. Detailed Description
[0015] The following disclosure may provide exemplary systems, apparatuses, and methods for conducting financial transactions and related activities. Although such financial transactions may be referred to in the examples provided below, the aspects are not limited thereto. That is, the systems, methods, and devices may be used for any suitable purpose.
[0016] Before discussing specific embodiments, aspects, or examples, some descriptions of the terms used herein are provided below.
[0017] As used herein, the terms "client" and "client device" may refer to one or more client-side devices or systems (e.g., remote from a transaction service provider) for initiating or facilitating a transaction (e.g., a payment transaction). Additionally, "client" may also refer to an entity (e.g., a merchant, an acquirer, etc.) that owns, utilizes, and / or operates a client device for initiating a transaction (e.g., for initiating a transaction with a transaction service provider).
[0018] The terms "client device" and "user device" refer to any electronic device configured to communicate with one or more servers or remote devices and / or systems. A client device or user device may include a mobile device, a network-enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, etc.), a computer, a POS system, and / or any other device or system capable of communicating with a network. A client device may also include a desktop computer, a laptop computer, a mobile computer (e.g., a smartphone), a wearable computer (e.g., a watch, glasses, lenses, clothing, etc.), a cellular phone, a network-enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, etc.), a point-of-sale (POS) system, and / or any other device, system, and / or software application configured to communicate with a remote device or system.
[0019] As used herein, the term "communication (communicate)" can refer to the acceptance, receipt, sending, transmission, provisioning, etc. of information (e.g., data, signals, messages, instructions, calls, commands, etc.). Communication can use direct or indirect connections and can be inherently wired and / or wireless. As an example, one unit (e.g., a device, system, component of a device or system, a combination thereof, etc.) communicating with another unit means that the one unit is capable of receiving information from and / or transmitting information to the other unit, either directly or indirectly. Even if the information may be modified, processed, forwarded, and / or routed between one unit and another unit, the one unit can still communicate with the other unit. In one example, even if a first unit receives information and does not convey the information to a second unit, the first unit can still communicate with the second unit. For example, although the first unit receives data passively and does not actively transmit the data to the second unit, the first unit can still communicate with the second unit. As another example, if an intermediate unit (e.g., a third unit located between the first unit and the second unit) receives information from the first unit, processes the information received from the first unit to generate processed information, and conveys the processed information to the second unit, then the first unit can communicate with the second unit. In some non-limiting embodiments or aspects, a message can refer to a packet containing data (e.g., a data packet, a network packet, etc.). It should be understood that there may be many other arrangements.
[0020] A "communication channel" can refer to any suitable path for communication between two or more entities. A suitable communication channel can exist directly between two entities (such as a payment processing network and a merchant or issuer computer), or can include multiple different entities. Any suitable communication protocol can be used to generate a communication channel. In some cases, a communication channel can include a "secure communication channel" or "tunnel" that can be established in any known manner, including using mutual authentication and session keys and establishing a secure communication session. However, any method for creating a secure communication channel can be used, and the communication channel can be wired or wireless, as well as remote, short-range, or mid-range. By establishing a secure channel, sensitive information related to a payment device (such as an account number, CVV value, expiration date, etc.) can be securely transmitted between two entities to facilitate a transaction.
[0021] As used herein, the term "comprising" is not intended to be limiting, but may be a transitional term synonymous with "including", "containing", or "characterized by". Thus, the term "comprising" may be inclusive or open-ended and, when used in a claim, does not exclude additional unrecited elements or method steps. For example, when describing a method, "comprising" indicates that the claim is open-ended and allows additional steps. When describing an apparatus, "comprising" may mean that the recited elements may be essential for one embodiment or aspect, but other elements may be added and still form a configuration within the scope of the claim. In contrast, the transitional phrase "consisting of" excludes any element, step, or ingredient not specified in the claim. This is consistent with the usage of the term throughout the specification.
[0022] As used herein, the term "computing device" or "computer device" may refer to one or more electronic devices configured to communicate directly or indirectly with one or more networks or to communicate over one or more networks. The computing device may be a mobile device, a desktop computer, etc. As an example, a mobile device may include a cellular phone (e.g., a smart phone or a standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, etc.), a personal digital assistant (PDA), and / or other similar devices. The computing device may not be a mobile device, such as a desktop computer. Additionally, the term "computer" may refer to any computing device that includes the necessary components for sending, receiving, processing, and / or outputting data and typically includes a display device, a processor, a memory, an input device, and a network interface and / or the like.
[0023] As used herein, a reference to a "device", "server", "processor", etc. may refer to a previously recited device, server, or processor stated to perform a previous step or function, a different server or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server or first processor stated to perform a first step or first function may refer to the same or a different server or the same or a different processor stated to perform a second step or second function.
[0024] "Interface" can include any software module configured to handle communications. For example, an interface can be configured to receive, process, and respond to a particular entity in a particular communication format. Additionally, a computer, device, and / or system can include any number of interfaces, depending on the functionality and capabilities of the computer, device, and / or system. In some embodiments or aspects, an interface can include an application programming interface (API) or other communication format or protocol that can be provided to a third party or a particular entity to allow communication with the device. Additionally, an interface can be designed based on functionality, the specified entity it is configured to communicate with, or any other variable. For example, an interface can be configured to allow a system to perform field processing on a particular request, or can be configured to allow a particular entity to communicate with the system.
[0025] "Original" transaction can include any transaction that includes an authorization provided by or on behalf of an issuer.
[0026] "Payment network" can refer to an electronic payment system used to accept, transfer, or process transactions made by a payment device for funds, goods, or services. The payment network can transfer information and funds between an issuer, an acquirer, a merchant, and a payment device user. An illustrative non-limiting example of a payment network is VisaNet, which is operated by Visa, Inc.
[0027] "Provisioning" can include the process of providing data for use. For example, provisioning can include providing, delivering, or enabling a token on a device. Provisioning can be done by any entity within or external to a transaction system. For example, in some embodiments or aspects, an issuer or a payment processing network can provision a token to a consumer's (e.g., account holder's) mobile device. The provisioned token can have corresponding token data stored and maintained in a token library or a token registry. In some embodiments or aspects, a token library or a token registry can generate tokens that can then be provisioned or delivered to a device. In some embodiments or aspects, an issuer can specify a token range from which token generation and provisioning can occur. Additionally, in some embodiments or aspects, an issuer can generate a token value and notify the token library, and provide token record information (e.g., token attributes) for storage in the token library.
[0028] As used herein, the term "server" can include one or more computing devices, which can be individual, stand-alone machines located at the same or different locations, can be owned or operated by the same or different entities, and can also be one or more clusters of distributed computers or "virtual" machines housed within a data center. Those skilled in the art should understand and appreciate that the functions performed by one "server" may be spread across multiple different computing devices for various reasons. As used herein, "server" is intended to refer to all such scenarios and should not be construed as or limited to a particular configuration. Additionally, a server as described herein may, but need not, reside at (or be operated by) a merchant, a payment network, a financial institution, a healthcare provider, a social media provider, a government agency, or an agent of any of the foregoing entities. The term "server" can also refer to or include one or more processors or computers, storage devices, or similar computer arrangements that operate or facilitate communication and processing among multiple parties in a network environment such as the Internet, but it should be understood that communication can be facilitated through one or more public or private network environments and various other arrangements are possible. Additionally, multiple computers (such as servers) or other computerized devices (such as point-of-sale devices) that communicate directly or indirectly in a network environment can constitute a "system" (such as a merchant's point-of-sale system). As used herein, a reference to a "server" or "processor" can refer to a previously recited server and / or processor stated to perform a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server and / or a first processor stated to perform a first step or function can refer to the same or a different server and / or processor stated to perform a second step or function.
[0029] A "server computer" can generally be a powerful computer or a cluster of computers. For example, a server computer can be a mainframe, a mini-computer cluster, or a group of servers acting as a unit. A server computer can be associated with entities such as a payment processing network, a wallet provider, a merchant, an authentication cloud, an acquirer, or an issuer. In one example, a server computer can be a database server coupled to a web server. A server computer can be coupled to a database and can include any hardware, software, other logic, or a combination of the foregoing for servicing requests from one or more client computers. A server computer can include one or more computing devices and can use any of a variety of computing architectures, arrangements, and compilations for servicing requests from one or more client computers. In some embodiments or aspects, a server computer can provide and / or support payment network cloud services.
[0030] As used herein, the term "system" may refer to one or more computing devices or a combination of computing devices (e.g., processors, servers, client devices, software applications, components of these computing devices, and / or the like).
[0031] The term "transaction data" may include any data associated with one or more transactions. In some embodiments or aspects, the transaction data may include only an account identifier (e.g., PAN) or a payment token. Alternatively, in other embodiments or aspects, the transaction data may include any information generated, stored, or associated with a merchant, consumer, account, or any other transaction-related information. For example, the transaction data may include data in an authorization request message generated in response to a payment transaction initiated by a consumer with a merchant. Alternatively, the transaction data may include information associated with one or more previously processed transactions, and the transaction information has been stored in a merchant database or other merchant computer. The transaction data may include an account identifier associated with a payment instrument used to initiate the transaction, consumer personal information, products or services purchased, or any other information that may be relevant or suitable for transaction processing. Additionally, the transaction information may include a payment token or other tokenized or masked account identifier substitute that may be used to complete the transaction and protect the consumer's underlying account information.
[0032] As used herein, the term "transaction service provider" may refer to an entity that receives a transaction authorization request from a merchant or other entity and, in some cases, provides payment guarantee through an agreement between the transaction service provider and the issuer. For example, the transaction service provider may include a payment network, such as American or any other entity that processes transactions. As used herein, a "transaction service provider system" may refer to one or more systems operated by or on behalf of a transaction service provider, such as a transaction service provider system that executes one or more software applications associated with the transaction service provider. In some non-limiting embodiments or aspects, the transaction processing system may include one or more server computers having one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.
[0033] A "user device" is an electronic device that can be transferred and / or operated by a user. The user device can provide remote communication capabilities to a network. The user device can be configured to transmit data or communications to other devices and receive data or communications from other devices. In some embodiments or aspects, the user device can be portable. Examples of user devices can include mobile phones (e.g., smartphones, cellular phones, etc.), PDAs, portable media players, wearable electronic devices (e.g., smartwatches, fitness bands, anklets, rings, earrings, etc.), electronic reading devices, and portable computing devices (e.g., laptops, netbooks, ultrabooks, etc.). Examples of user devices can also include cars with remote communication capabilities.
[0034] "User information" can include any information associated with a user. For example, user information can include device identifiers of devices owned or operated by the user and / or account credentials of accounts held by the user. The device identifier can include a unique identifier assigned to the user device, which can later be used to authenticate the user device. In some embodiments or aspects, the device identifier can include a device fingerprint. The device fingerprint can be an aggregation of device attributes. The device fingerprint can be generated by a software development kit (SDK) provided on the user device using, for example, a unique identifier assigned by the operating system, an International Mobile Station Equipment Identity (IMEI) number, an operating system (OS) version, a plugin version, etc.
[0035] This disclosure describes a cluster management platform that includes a pool of multiple worker nodes. The multiple worker nodes are configured to process a continuous transaction data stream (e.g., payment authorization) from multiple external sources. The external sources are communicatively coupled to an I / O (input / output) server at a network gateway. The I / O server includes a load balancer that is configured to evenly distribute the transaction data stream to the multiple nodes. The load balancer is configured based on multiple distribution factors, which include the total number of nodes in the cluster pool, the expected number of incoming transactions, and / or the estimated processing time for each transaction authorization. The configuration factors allow for real-time distribution of transaction data to the multiple worker nodes. The load balancer is rarely reconfigured based on new or updated configuration factors. The cluster pool is configured to process global transactions and does not experience a reduction in transaction data due to time zones, weekends, and / or holidays. Therefore, the network cannot afford the consequences of taking worker nodes offline for maintenance.
[0036] Each worker node in the cluster pool can correspond to a physical machine that requires regular hardware, software patch, and / or firmware maintenance by maintenance personnel in the data center. In some cluster pools, there may be hundreds of worker nodes corresponding to the respective physical machines. The maintenance personnel are responsible for performing regular maintenance on each node in the cluster pool. This can result in marathon maintenance sessions where the maintenance personnel perform regular maintenance on one node or a number of nodes in sequence each time until the entire cluster pool has been updated. For example, the maintenance session can last from several hours to several days.
[0037] During the maintenance session, spare nodes can be added to the cluster pool or automatically provisioned in the cluster pool to compensate for the worker nodes that are offline for maintenance. Once the regular maintenance is completed, the worker nodes can resume operation in the cluster pool. Once all the worker nodes in the cluster pool have been patched or updated, the spare nodes can be taken offline, thus restoring the original node configuration in the cluster pool.
[0038] During the maintenance session, the maintenance personnel have traditionally communicated continuously with a separate group that manages the I / O servers. The I / O administrators configure the load balancer for the I / O servers. The load balancer distributes transaction data to multiple nodes in the cluster pool. The maintenance personnel must communicate with the I / O administrators so that a particular node can be taken offline without disturbing or interrupting any pending transaction data processing. Additionally, the I / O administrators must know the duration for which the node will be offline so that the cluster configuration can compensate for the change in workload. Thus, the I / O administrators manually update the load balancer to stop sending transaction data to the first node being maintained during the maintenance session. When the I / O personnel receive notification from the maintenance personnel that the first node has been updated, the I / O personnel configure the load balancer to resume sending the first node's transaction data as part of the cluster pool. The maintenance process can last for hours or days and tie up resources from both the I / O management and maintenance teams. Additionally, if the maintenance personnel encounter a problem that requires a node to be offline for a longer duration, they must notify the I / O administrators of the need for additional offline time to route transactions away from the node being maintained. Team coordination extends the overall time of the maintenance session and can limit the availability for performing the overall maintenance. Regular maintenance can only be performed when personnel from both I / O management and maintenance are available. Thus, the maintenance sessions are very expensive as they tie up the human capital from both the maintenance personnel team and the business personnel team.
[0039] This disclosure describes aspects of performing regular maintenance on nodes in a cluster pool that avoid the need for continuous communication between the I / O management team and the maintenance team. Using only the maintenance personnel reduces the amount of human capital such that there is no need to coordinate regular maintenance times applicable to multiple teams and reduces the overall maintenance session due to no communication / action delays.
[0040] The present disclosure utilizes periodic status requests from a load balancer, which are commonly referred to as periodic health checks performed by the load balancer. During the periodic health check, the load balancer sends requests via periodic health check packets to a specific port of each node in the cluster pool to verify whether each node is working properly. Once a node receives a periodic health check packet, the node has a predetermined amount of response time. If there is a delay in the response that exceeds a predetermined time period, or if no response is received at all, the load balancer determines that the node has experienced some type of error or failure that will prevent the node from operating properly. Accordingly, the load balancer stops sending transaction data to the node as part of the load balancing data distribution in the cluster pool. In various aspects, the present disclosure provides a network policy that is configured to simulate a failure at a node. Through the network policy, a simulated node failure can be determined by the load balancer as a result of a blocked periodic health check packet or a blocked node response.
[0041] Turning now to the figures, Figure 1 A network architecture of a cluster network 100 including a plurality of worker nodes 102a - n is shown in accordance with at least one aspect of the present disclosure. The I / O server 108 includes a load balancer 106 that is configured to evenly distribute transaction data to the plurality of worker nodes 102a - n. The I / O server 108 is located on the local network side of a network gateway 110 that bridges a wide area network 112 (WAN) and a local area network (LAN). The I / O server 108 is configured to receive transaction data from a plurality of external data sources 114 - n. In various aspects, the I / O server 108 includes hardware that can be configured to execute cloud cluster computing software (e.g., Kubernetes). The cloud cluster computing software can be configured to execute the load balancer 106 for incoming transaction data received by the I / O server 108.
[0042] Figure 1 A network management server 104 communicating with the plurality of worker nodes 102a - n is also shown. The network management server 104 can receive a network policy and configure one or more nodes such that periodic health check messages are blocked at the health check ports of the nodes. In various aspects, once the network policy is implemented, the health check ports can be blocked indefinitely until the network management server receives a de - policy and a second policy to unblock the health check ports. In another aspect, the network policy can be configured according to an expiration time - to - live (TTL) value. Once the TTL timer reaches a predetermined value, counts up or counts down to zero, the network policy can be automatically revoked.
[0043] In various aspects, the network management server 104 can act as a firewall block or intercept periodic health check messages before they reach the node. The network management server 104 can perform deep packet inspection and monitor traffic for specific addresses and ports corresponding to the node. In one example, the network policy can be configured to identify the health check port of the first node in the destination field of the packet header. The policy can block all traffic to this destination. In this instance, the health check port of the first node never receives periodic health check messages from the load balancer and thus does not respond. In another example, the network policy can be configured to identify the health check port of the first node in the source field of the packet header. The policy can block all outgoing traffic from this source from reaching its destination. In this example, the health check port can still receive periodic health check messages from the load balancer, but the response may be blocked from reaching the load balancer.
[0044] Figure 2 illustrates a cluster network 200 including a load balancer 206 and a plurality of worker nodes 202 1-3 (W1 - W3) and a master node 224 1-5 in accordance with at least one aspect of the present disclosure. Each of the plurality of worker nodes 202 includes at least two ports, namely a transaction data port 216 and a health check port 217. The load balancer 206 is configured to send periodic health check messages 222 to each worker node 202 1-3 to the health check port 217 of (W1 - W3). The worker nodes 202 1-3 (W1 - W3) are configured to transmit a response within a predetermined time period to indicate that the worker nodes 202 1-3 (W1 - W3) are healthy and can receive or continue to receive transaction data 220 at the transaction data port 216. It should be understood that the cluster network 200 is not limited to the configuration shown, and there can be n worker nodes 202 1-n and m master nodes 224 1-m , where n and m are any positive integers.
[0045] Figure 3 is a logic flow diagram 300 for implementing a new network policy in accordance with at least one aspect of the present disclosure. Now referring to Figure 3 and Figure 2 , the network management server 204 receives 302 a new network policy to restrict network traffic directed to the health check port of the first node 202 1 (W1). The network management server 204 configures 304 the first node 202 1(W1) or a firewall to block all traffic of periodic health check messages or port destination addresses with health check ports. The network management server 204 determines 306 the first node 202 1 (W1) does not receive periodic health check messages at the periodic health check container, and thus the first node 202 (W1) stops responding to the periodic health check messages sent by the load balancer 206. The network management server 204 monitors the network traffic in the cluster network 200 and determines 308 that the load balancer 206 has not received a response to the periodic health check message sent to the first node 202 1 (W1) within a predetermined time period. Responses received within the threshold period indicate to the load balancer 206 that the first node 202 1 (W1) is working properly. The network management server 204 determines 310 based on the failure of the response of the first node 202 1 (W1) that the load balancer 206 infers that the first node 202 1 (W1) is experiencing an error or a fault. The network management server 204 monitors the network traffic and determines 312 that the load balancer 206 stops transmitting transaction data to the first node 202 1 (W1). The network management server 204 determines 314 that all transaction data processing has been completed based on the timestamp of the last transaction data received at the first node 202 1 (W1) and after the processing time of the transaction data. The network management server 204 may be configured to wait for a predetermined time period after the last transaction data is received by the first node 202 1 (W1), and generate a notification that all pending processing has been completed when the predetermined time period expires. The network management server 204 determines 316 that the first node 202 1 (W1) can be taken offline for maintenance without interrupting the processing of transaction data.
[0046] Figure 4 is a logic flowchart 400 for revoking a network policy according to at least one aspect of the present disclosure. In various aspects, the network policy can be revoked due to a new network policy or due to the expiration of an existing policy. Refer to Figure 4 and Figure 2 , the time-to-live value in the new network policy or the first policy may include a network policy status indicator that indicates to the network management server 204 that the first policy is no longer valid. The network management server 204 determines that the first policy is no longer valid and revokes 402 the first policy. The network management server 204 monitors the network traffic and determines 404 that the first node 202 1 (W1) receives periodic health check messages from the load balancer. The network management server 204 monitors the network traffic and determines 406 that the first node 202 1(W1) Responds to periodic health check messages within a predetermined time period. The network management server 204 monitors network traffic and determines 408 that the load balancer 206 receives periodic health check responses within a predetermined time period. The network management server 204 monitors network traffic and verifies 410 that the load balancer 206 has resumed transmitting transaction data to the first node 202 1 (W1). The network management server 204 determines 412 the first node 202 1 (W1) is processing transaction data as part of the cluster pool 218 and polls the next node 202 in the polling sequence 2 (W2) can be maintained without disturbing the traffic load of the cluster pool 218.
[0047] Figure 5 is a logic flow diagram 500 for pre-provisioning a standby node before implementing a network policy to simulate a failure at a first node or in response to implementing a network policy to simulate a failure at a first node, according to at least one aspect of the present disclosure. Refer to Figure 5 and Figure 2 , the network policy may include instructions for the network management server 204 to pre-provision 502 a standby node 202 2 (W2) as part of the cluster pool 218. The network management server 204 establishes 504 a drain connection between the first node 202 1 (W1) scheduled for maintenance and the standby node 202 2 (W2). The first node 202 1 (W1) transfers 506 a copy of all container data to the standby node 202 2 (W2) such that when the first node 202 1 (W1) goes offline for maintenance, processing can continue seamlessly. The standby node 202 2 (W2) responds to periodic health check messages and receives 508 transaction data from the load balancer 206 as part of the cluster pool 218. Once the network management server 204 verifies that the standby node 202 2 (W2) is actively processing transaction data in the cluster pool 218, the network management server 204 can simulate 510 a node failure of the first node 202 1 (W1) for maintenance. To maintain subsequent nodes 202 3 (W3), the standby node 202 2 (W2) can remain active until all nodes have been updated. In various aspects, each node 202 in the cluster pool 218 1-3 (W1-W3) can transfer container data to the standby node 202 2 (W2) before the node undergoes maintenance.
[0048] Figure 6 It is a block diagram of a computer device 3000 having a data processing subsystem or component according to at least one aspect of the present disclosure. Figure 6 The subsystems shown therein are interconnected via a system bus 3010. Additional subsystems are shown, such as a printer 3018, a keyboard 3026, a fixed disk 3028 (or other memory including a computer-readable medium), a monitor 3022 coupled to a display adapter 3020, etc. Peripheral devices and input / output (I / O) devices coupled to an I / O controller 3012 (which may be a processor or any suitable controller) can be connected to the computer system by any number of means known in the art (e.g., a serial port 3024). For example, the serial port 3024 or an external interface 3030 can be used to connect the computer device to a wide area network (e.g., the Internet), a mouse input device, or a scanner. The interconnection via the system bus allows the central processor 3016 to communicate with each subsystem and allows control of the execution of instructions from the system memory 3014 or the fixed disk 3028 and the exchange of information between the subsystems. The system memory 3014 and / or the fixed disk 3028 can embody the computer-readable medium.
[0049] Figure 7 It is a graphical representation of an example system 4000 including a host 4002 within which a set of instructions for performing any one or more of the methods discussed herein can be executed. In various aspects, the host 4002 operates as a stand-alone device or can be connected (e.g., network-connected) to other machines. In a network deployment, the host 4002 can operate in the function of a server or a client machine in a server-client network environment or as a peer machine in a peer-to-peer (or distributed) network environment. The host 4002 can be a computer or a computing device, a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular phone, a portable music player (e.g., a portable hard disk audio device, such as a Moving Picture Experts Group Audio Layer 3 (MP3) player), a network appliance, a network router, a switch, or a bridge, or any machine capable of executing a set of instructions (sequentially or otherwise) specifying the actions to be taken by that machine. Additionally, although only a single machine is illustrated, the term "machine" should also be understood to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methods discussed herein.
[0050] Example system 4000 includes a host 4002 that runs a host operating system (OS) 4004 on one or more processors / processor cores 4006 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both) and various memory nodes 4008. The host OS 4004 may include a hypervisor 4010 that is capable of controlling functions and / or communicating with virtual machines (“VMs”) 4012 running on machine-readable media. The VM 4012 may also include a virtual CPU or vCPU 4014. The memory nodes 4008 may be linked or pinned to virtual memory nodes or vNodes 4016. When a memory node 4008 is linked or pinned to a corresponding vNode 4016, data may then be directly mapped from the memory node 4008 to its corresponding vNode 4016.
[0051] All of the various components shown in the host 4002 may be connected to and communicate with each other, either via a bus (not shown) or via other coupling or communication channels or mechanisms. The host 4002 may also include a video display, an audio device, or other peripheral devices 4018 (e.g., a liquid crystal display (LCD), one or more alphanumeric input devices (including, e.g., a keyboard), a cursor control device (e.g., a mouse), a voice recognition or biometric authentication unit, an external drive, a signal generating device (e.g., a speaker)), a permanent storage device 4020 (also referred to as a disk drive unit), and a network interface device 4022. The host 4002 may also include a data encryption module (not shown) for encrypting data. The components provided in the host 4002 are components that are typically present in computer systems suitable for use with aspects of the present disclosure and are intended to represent a broad category of such computer components known in the art. Thus, the system 4000 may be a server, a minicomputer, a mainframe computer, or any other computer system. The computer may also include different bus configurations, network platforms, multiprocessor platforms, and the like. A variety of operating systems may be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.
[0052] The disk drive unit 4024 can also be a solid state drive (SSD), a hard disk drive (HDD), or other drives that include a computer or machine-readable medium having stored thereon one or more sets of instructions and data structures (e.g., data / instruction 4026) that embody or utilize any one or more of the methods or functions described herein. The data / instruction 4026 can also reside, in whole or in part, within the main memory node 4008 and / or within the (one or more) processors 4006 during execution by the host 4002. The data / instruction 4026 can be further transmitted or received via a network interface device 4022 using any one of several well-known transfer protocols (e.g., Hyper Text Transfer Protocol (HTTP)) over a network 4028.
[0053] (One or more) processors 4006 and memory nodes 4008 can also include machine-readable media. The term "computer-readable medium" or "machine-readable medium" should be understood to include a single medium or multiple media (e.g., a centralized or distributed database and / or associated cache memories and servers) that store one or more sets of instructions. The term "computer-readable medium" should also be understood to include any medium that is capable of storing, encoding, or carrying a set of instructions for execution by the host 4002 that cause the host 4002 to perform any one or more of the methods of this application, or any medium that is capable of storing, encoding, or carrying a data structure used by or associated with such a set of instructions. Thus, the term "computer-readable medium" should be understood to include, but not be limited to, solid state memories, optical and magnetic media, and carrier signals. This medium can also include, but is not limited to, hard disks, floppy disks, flash memory cards, digital video discs, random access memory (RAM), read only memory (ROM), etc. The example aspects described herein can be implemented in an operating environment that includes software installed on a computer, software installed in hardware, or a combination of software and hardware.
[0054] Those skilled in the art will recognize that an Internet service can be configured to provide Internet access to one or more computing devices coupled to the Internet service, and the computing devices can include one or more processors, buses, memory devices, display devices, input / output devices, etc. Additionally, those skilled in the art can appreciate that the Internet service can be coupled to one or more databases, repositories, servers, etc., which can be used to implement any one of the aspects of the present disclosure described herein.
[0055] Computer program instructions can also be loaded onto a computer, a server, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer or other programmable apparatus provide a process for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0056] For example, a suitable network can include any one or more of the following or interface with any one or more of the following: a local intranet, a PAN (Personal Area Network), a LAN (Local Area Network), a WAN (Wide Area Network), a MAN (Metropolitan Area Network), a Virtual Private Network (VPN), a Storage Area Network (SAN), a Frame Relay connection, an Advanced Intelligent Network (AIN) connection, a Synchronous Optical Network (SONET) connection, a digital T1, T3, E1, or E3 line, a Digital Data Service (DDS) connection, a DSL (Digital Subscriber Line) connection, an Ethernet connection, an ISDN (Integrated Services Digital Network) line, a dial-up port (e.g., a V.90, V.34, or V.34bis analog modem connection), a cable modem, an ATM (Asynchronous Transfer Mode) connection, or an FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connection. Additionally, the communication can also include a link to any one of a variety of wireless networks, including a WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access), or TDMA (Time Division Multiple Access), a cellular telephone network, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), a RIM (Research In Motion) duplex paging network, a Bluetooth radio, or a radio frequency network based on IEEE 802.11. The network 4030 can also include any one or more of the following or interface with any one or more of the following: an RS-232 serial connection, an IEEE-1394 (FireWire) connection, a Fibre Channel connection, an IrDA (Infrared) port, a SCSI (Small Computer System Interface) connection, a USB (Universal Serial Bus) connection, or other wired or wireless, digital or analog interface or connection, a mesh or network connection.
[0057] Generally speaking, a cloud-based computing environment is a resource that typically combines the computing power of large groupings of processors (e.g., within a web server) and / or combines the storage capacity of large groupings of computer memory or storage devices. A system that provides cloud-based resources can be employed only by its owner, or such systems can be accessed by external users who deploy applications within the computing infrastructure to obtain the benefits of large-scale computing or storage resources.
[0058] For example, a cloud is formed by a network of web servers that includes multiple computing devices (e.g., host 4002), where each server 4030 (or at least a plurality thereof) provides processor and / or storage resources. These servers manage workloads provided by multiple users (e.g., cloud resource customers or other users). Generally, the workload demands of each user on the cloud change in real time and sometimes even vary greatly. The nature and extent of these changes typically depend on the type of business associated with the user.
[0059] It should be noted that any hardware platform suitable for performing the processes described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage media" refer to any one or more media that participate in providing instructions to a CPU for execution. This medium can take many forms, including (but not limited to) non-volatile media, volatile media, and transmission media. Non-volatile media includes (e.g.) optical or magnetic disks, such as a fixed disk. Volatile media includes dynamic memory, such as system RAM. Transmission media includes coaxial cables, copper wire, and fiber optics, among others, which includes wires that form an aspect of a bus. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include (e.g.) floppy disks, hard disks, magnetic tape, any other magnetic media, CD-ROM discs, digital video discs (DVDs), any other optical media, any other physical media with a pattern of marks or holes, RAM, PROM, EPROM, EEPROM, FLASH EPROM, any other memory chip or data exchange adapter, a carrier wave, or any other medium from which a computer can read.
[0060] Various forms of computer-readable media can participate in carrying one or more sequences of one or more instructions to a CPU for execution. A bus carries data to system RAM, and the CPU retrieves instructions from system RAM and executes the instructions. Instructions received by system RAM can optionally be stored on a fixed disk before or after being executed by the CPU.
[0061] Computer program code for performing operations on aspects of the technology of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages (such as Java, Smalltalk, C++, etc.) and conventional procedural programming languages (such as the "C" programming language, Go, Python, or other programming languages including assembly language). The program code may execute entirely on the user's computer, partially on the user's computer; as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider through the Internet).
[0062] Examples of methods according to various aspects of the present disclosure are provided in the numbered clauses below. One aspect of the method may include any one or more and any combination of the numbered clauses described below.
[0063] Clause 1. A method, comprising: receiving, by a network management server, a network policy corresponding to a node in a pool of clusters including a plurality of nodes, wherein the node includes a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implementing, by the network management server, the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining, by the network management server, that after implementing the network policy in preparation for maintenance of the node, the transaction data received at the first port is processed by the node; and revoking, by the network management server, the network policy based on a network policy status indicator after the maintenance at the node is completed to lift the port limit at the second port.
[0064] Clause 2. The method according to Clause 1, wherein the port limit causes an emulated error at the node, the emulated error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the emulated error causes the load balancer to determine that the node is unable to process the transaction data.
[0065] Clause 3. The method according to Clause 1, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy lifts the port limit at the second port of the node.
[0066] Clause 4. The method according to Clause 1, wherein the network policy status indicator is a TTL (Time-To-Live) value, and wherein the network policy is lifted when the TTL value expires.
[0067] Clause 5. The method according to Clause 1, further comprising monitoring, by the network management server, the node for a response to at least one of the periodic health check messages within a predetermined period after the revocation of the network policy.
[0068] Clause 6. The method according to Clause 5, further comprising monitoring, by the network management server, the node for receipt of new transaction data at the first port after the revocation of the network policy.
[0069] Clause 7. The method according to Clause 1, further comprising: pre-provisioning, by the network management server, a standby node to the cluster pool; and initializing, by the network management server, the standby node to receive the transaction data.
[0070] Clause 8. The method according to Clause 1, wherein the maintenance comprises at least one of installing a software patch on the node or fixing a hardware fault at the node.
[0071] Clause 9. A system, comprising: a plurality of nodes; a cluster pool including the plurality of nodes; a load balancer server; a network management server communicatively coupled to the plurality of nodes, wherein the network management server is configured to: receive a network policy corresponding to a node in the cluster pool, wherein the cluster pool includes a plurality of nodes, and wherein the nodes in the cluster pool include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from the load balancer; implement the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determine that the transaction data received at the first port is processed by the node after implementing the network policy to prepare for maintenance of the node; and revoke the network policy to lift the port limit at the second port after the maintenance is completed at the node based on a network policy status indicator.
[0072] Clause 10. The system according to Clause 9, wherein the port limit causes an emulated error at the node, the emulated error preventing the node from responding to the periodic health check messages within a predetermined period, and wherein the emulated error causes the load balancer to determine that the node is unable to process the transaction data.
[0073] Clause 11. The system according to Clause 9, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy lifts the port restriction at the second port of the node.
[0074] Clause 12. The system according to Clause 9, wherein the network policy status indicator is a TTL (Time-To-Live) value, and wherein the network policy is lifted when the TTL value expires.
[0075] Clause 13. The system according to Clause 9, wherein the network management server is further configured to monitor the node to respond to at least one of the periodic health check messages within a predetermined period after revocation of the network policy.
[0076] Clause 14. The system according to Clause 13, wherein the network management server is further configured to monitor the node to receive new transaction data at the first port after revocation of the network policy.
[0077] Clause 15. The system according to Clause 9, wherein the network management server is further configured to: provision a standby node to the cluster pool; and initialize the standby node to receive the transaction data.
[0078] Clause 16. The system according to Clause 9, wherein the maintenance includes at least one of installing software patches on the node or fixing hardware failures at the node.
[0079] Clause 17. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations including: receiving a network policy corresponding to a node in a cluster pool including a plurality of nodes, wherein the node includes a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; provisioning a standby node to the cluster pool; initializing the standby node to receive the transaction data; implementing the network policy to configure a port restriction of the second port of the node, wherein the port restriction causes the load balancer to stop transmitting the transaction data to the first port; determining that, after implementing the network policy in preparation for maintenance of the node, the transaction data received at the first port is processed by the node; and based on a network policy status indicator, revoking the network policy after the maintenance at the node to lift the port restriction at the second port.
[0080] Clause 18. The non-transitory computer-readable medium according to Clause 17, wherein the port restriction causes an emulation error at the node, the emulation error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the emulation error causes the load balancer to determine that the node is unable to process the transaction data.
[0081] Clause 19. The non-transitory computer-readable medium according to Clause 17, further configured to perform operations including the following when executed by one or more processors: receiving a second network policy corresponding to the node in the cluster pool, wherein the second network policy lifts the port restriction on the second port.
[0082] Clause 20. The non-transitory computer-readable medium according to Clause 17, wherein preparing for maintenance of the node includes draining container data from the node to the standby node.
[0083] The foregoing detailed description has set forth various forms of systems and / or processes using block diagrams, flowcharts, and / or examples. Insofar as such block diagrams, flowcharts, and / or examples contain one or more functions and / or operations, those skilled in the art will recognize that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented, individually and / or jointly, by a wide variety of hardware, software, firmware, or virtually any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be equivalently implemented in integrated circuits, as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as virtually any combination thereof, and will recognize that designing the circuitry and / or writing code for the software and / or firmware would be well within the skill of those in the art in light of this disclosure. Additionally, those skilled in the art will appreciate that the mechanisms of the subject matter described herein are capable of being distributed as one or more program products in a variety of forms, and will understand that the illustrative forms of the subject matter described herein apply regardless of the particular type of signal-bearing medium used to actually effect the distribution.
[0084] Instructions for programming logic to perform the various disclosed aspects can be stored in a memory of the system (such as dynamic random access memory (DRAM), cache memory, flash memory, or other storage devices). Additionally, the instructions can be distributed via a network or through other computer-readable media. Thus, a machine-readable medium can include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), but is not limited to floppy disks, optical disks, compact discs, read-only memory (CD-ROM) and magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic or optical cards, flash memory, or a tangible machine-readable storage device for transmitting information via electrical, optical, acoustic, or other forms of propagated signals (such as carrier waves, infrared signals, digital signals, etc.) over the Internet. Accordingly, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).
[0085] Any software component or functionality described in this application can be implemented as software code executed by a processor using, for example, conventional or object-oriented techniques, in any suitable computer language (e.g., Python, Java, C++, or Perl). The software code can be stored as a series of instructions or commands on a computer-readable medium, such as RAM, ROM, magnetic media (e.g., hard disk or floppy disk), or optical media (e.g., CD-ROM). Any such computer-readable medium can reside on a single computing device or within a single computing device, and can be present on or within different computing devices in a system or network.
[0086] As used in any aspect herein, the term "logic" can refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software can be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware can be embodied as code, instructions, or instruction sets and / or data hard-coded (e.g., non-volatile) in a memory device.
[0087] As used in any aspect herein, the terms "component", "system", "module", etc. can refer to a computer-related entity, i.e., hardware, a combination of hardware and software, software, or software in execution.
[0088] As used in any aspect of this document, "algorithm" refers to a self-consistent sequence of steps that produce a desired result, where "step" refers to the manipulation of physical quantities and / or logical states, which although not necessarily in the form of electrical or magnetic signals capable of being stored, transmitted, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms can be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.
[0089] The network can include a packet-switched network. The communication devices may be able to communicate with each other using a selected packet-switched network communication protocol. An example communication protocol can include the Ethernet communication protocol, which may be able to permit communication using the Transmission Control Protocol / Internet Protocol (TCP / IP). The Ethernet protocol can conform to or be compatible with the Ethernet standard titled "IEEE 802.3 Standard" published by the Institute of Electrical and Electronics Engineers (IEEE) in December 2008 and / or subsequent versions of this standard. Alternatively or additionally, the communication devices may be able to communicate with each other using the X.25 communication protocol. The X.25 communication protocol can conform to or be compatible with the standards promulgated by the International Telecommunication Union - Telecommunication Standardization Sector (ITU-T). Alternatively or additionally, the communication devices may be able to communicate with each other using the Frame Relay communication protocol. The Frame Relay communication protocol can conform to or be compatible with the standards promulgated by the Consultative Committee for International Telegraph and Telephone (CCITT) and / or the American National Standards Institute (ANSI). Alternatively or additionally, the transceivers may be able to communicate with each other using the Asynchronous Transfer Mode (ATM) communication protocol. The ATM communication protocol can conform to or be compatible with the ATM standard titled "ATM-MPLS Network Interworking 2.0" published by the ATM Forum in August 2001 and / or subsequent versions of this standard. Of course, different and / or developed connection-oriented network communication protocols are also envisioned herein.
[0090] Unless otherwise specified in the foregoing disclosure, it should be understood that throughout this disclosure, discussions using terms such as "processing", "computing", "calculating", "determining", "displaying", etc. refer to actions and processes of a computer system or similar electronic computing device that manipulates data represented as physical (electronic) quantities within computer system registers and memories and transforms them into other data similarly represented as physical quantities within a computer system memory or register or other such information storage, transmission, or display devices.
[0091] One or more components may be referred to herein as "configured to", "configurable to", "operable / operating", "adapted / adaptable", "capable", "compliant / compliant with", etc. Those skilled in the art will recognize that "configured to" generally can encompass active state components and / or inactive state components and / or standby state components, unless the context requires otherwise.
[0092] Those skilled in the art will recognize that, generally speaking, the terms used herein and particularly in the appended claims (e.g., the body of the appended claims) are generally intended to be "open" terms (e.g., the term "including" should be interpreted as "including but not limited to", the term "having" should be interpreted as "having at least", the term "includes" should be interpreted as "includes but is not limited to", etc.). Those skilled in the art will further understand that if a specific number of introduced claim recitations is intended, such intent will be expressly stated in the claim, and in the absence of such a statement, there is no such intent. For example, for purposes of illustration, the following appended claims may contain the use of introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to mean that the introduction of a claim recitation by the indefinite article "a" or "an" limits any particular claim containing such introduced claim recitation to a claim containing only one such recitation, even when the same claim contains an introductory phrase "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should generally be interpreted to mean "at least one" or "one or more"); the same is true for the use of the definite article to introduce a claim recitation.
[0093] In addition, even if a specific number of introduced claim statements is explicitly recited, one of ordinary skill in the art will recognize that such statements typically should be interpreted to mean at least that number (e.g., reciting only "two statements" without further modifiers typically means at least two statements, or two or more statements). Further, in those instances where a convention such as "at least one of A, B, and C, etc." is used, generally speaking, such constructs are intended in a sense that one of ordinary skill in the art will understand the convention (e.g., a "system having at least one of A, B, and C" will include, but not be limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). In those instances where a convention such as "at least one of A, B, or C, etc." is used, generally speaking, such constructs are intended to be made in a sense that one of ordinary skill in the art will understand the convention (e.g., a "system having at least one of A, B, or C" will include, but not be limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). One of ordinary skill in the art should further understand that, whether in the description, claims, or drawings, distinguishing words and / or phrases that typically present two or more alternative terms should be understood to contemplate the possibility of including one of the terms, any one of the terms, or both terms, unless the context dictates otherwise. For example, the phrase "A or B" will typically be understood to include the possibility of "A" or "B" or "A and B".
[0094] Regarding the appended claims, one of ordinary skill in the art will appreciate that the operations generally may be performed in any order. Additionally, although various operation flowcharts are presented in one or more sequences, it should be understood that the various operations may be performed in other orders than those illustrated, or may be performed concurrently. Examples of such alternative orderings may include overlapping, interleaving, interrupting, reordering, incrementing, preparatory, supplementary, concurrent, reversing, or other variations of ordering, unless the context dictates otherwise. Further, terms such as "in response to", "associated with", or other past tense adjectives generally are not intended to exclude such variations, unless the context dictates otherwise.
[0095] It should be noted that any reference to "an aspect", "one aspect", "an example", "one example", etc. means that the particular features, structures, or characteristics described in connection with that aspect are included in at least one aspect. Thus, the phrases "in one aspect", "in one aspect", "in an example", and "in one example" that appear throughout this specification do not necessarily all refer to the same aspect. Additionally, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.
[0096] As used herein, unless the context clearly dictates otherwise, the singular forms "a", "an", and "the" include plural referents.
[0097] Any patent application, patent, non-patent publication, or other published material cited in this specification and / or listed in any application data sheet is incorporated herein by reference to the extent that the incorporated material is not inconsistent therewith. Thus, and to the extent necessary, the disclosure as expressly set forth herein supersedes any conflicting material incorporated by reference. Any material or portion thereof that is said to be incorporated by reference herein but which conflicts with the existing definitions, statements, or other published material set forth herein will be incorporated only to the extent that there is no conflict between the incorporated material and the existing published material. It is not admitted that they are prior art.
[0098] In summary, numerous advantages have been described that result from employing the concepts described herein. The foregoing description has been presented in one or more forms for purposes of illustration and description. It is not intended to be exhaustive or limited to the precise forms disclosed. Modifications or variations are possible in light of the above teachings. One or more forms have been selected and described in order to illustrate the principles and practical applications so that others skilled in the art may utilize the various forms and make various modifications as contemplated for particular uses. The claims presented herein are intended to define the general scope.
Claims
1. A method, comprising: receiving, by a network management server, a network policy corresponding to nodes in a cluster pool including a plurality of nodes, wherein the nodes include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implementing, by the network management server, the network policy to configure a port limit for the second port of the nodes, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining, by the network management server, that after implementing the network policy in preparation for maintenance of the nodes, the transaction data received at the first port is processed by the nodes; and revoking, by the network management server, the network policy based on a network policy status indicator after the maintenance at the nodes is completed to lift the port limit at the second port.
2. The method according to claim 1, wherein the port limit causes an emulated error at the nodes, the emulated error preventing the nodes from responding to the periodic health check messages for a predetermined period of time, and wherein the emulated error causes the load balancer to determine that the nodes are unable to process the transaction data.
3. The method according to claim 1, wherein the network policy status indicator is a second network policy corresponding to the second port of the nodes, and wherein the second network policy lifts the port limit at the second port of the nodes.
4. The method according to claim 1, wherein the network policy status indicator is a TTL (Time To Live) value, and wherein the network policy is lifted when the TTL value expires.
5. The method according to claim 1, further comprising monitoring, by the network management server, the nodes for a response to at least one of the periodic health check messages within a predetermined period after the revocation of the network policy.
6. The method according to claim 5, further comprising monitoring, by the network management server, the nodes for receipt of new transaction data at the first port after the revocation of the network policy.
7. The method according to claim 1, further comprising: provisioning, by the network management server, a standby node to the cluster pool; and initializing, by the network management server, the standby node to receive the transaction data.
8. The method according to claim 1, wherein the maintenance includes at least one of installing a software patch on the nodes or fixing a hardware fault at the nodes.
9. A system, comprising: a plurality of nodes; a cluster pool including the plurality of nodes; a load balancer server; a network management server communicatively coupled to the plurality of nodes, wherein the network management server is configured to: receive a network policy corresponding to nodes in the cluster pool, wherein the cluster pool includes a plurality of nodes, and wherein the nodes in the cluster pool include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; Implement the network policy to configure the port limit of the second port of the node, where the port limit causes the load balancer to stop transmitting the transaction data to the first port; Determine that after implementing the network policy to prepare for maintenance of the node, the transaction data received at the first port is processed by the node; And Based on the network policy status indicator, revoke the network policy after the maintenance at the node to lift the port limit at the second port.
10. The system according to claim 9, wherein the port limit causes an emulation error at the node, the emulation error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the emulation error causes the load balancer to determine that the node cannot process the transaction data.
11. The system according to claim 9, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy lifts the port limit at the second port of the node.
12. The system according to claim 9, wherein the network policy status indicator is a TTL (Time-To-Live) value, and wherein the network policy is lifted when the TTL value expires.
13. The system according to claim 9, wherein the network management server is further configured to monitor the node's response to at least one of the periodic health check messages within a predetermined time period after the revocation of the network policy.
14. The system according to claim 13, wherein the network management server is further configured to monitor the node's reception of new transaction data at the first port after the revocation of the network policy.
15. The system according to claim 9, wherein the network management server is further configured to: Provision a standby node to the cluster pool; and Initialize the standby node to receive the transaction data.
16. The system according to claim 9, wherein the maintenance includes at least one of installing a software patch on the node or fixing a hardware fault at the node.
17. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including the following: Receive a network policy corresponding to a node in a cluster pool including a plurality of nodes, where the node includes a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; Provision a standby node to the cluster pool; Initialize the standby node to receive the transaction data; Implement the network policy to configure the port limit of the second port of the node, where the port limit causes the load balancer to stop transmitting the transaction data to the first port; Determine that after implementing the network policy in preparation for maintenance of the node, the transaction data received at the first port is processed by the node; And After the maintenance at the node based on the network policy status indicator is completed, revoke the network policy to lift the port restriction at the second port.
18. The non-transitory computer-readable medium according to claim 17, wherein the port restriction causes a simulation error at the node, the simulation error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the simulation error causes the load balancer to determine that the node cannot process the transaction data.
19. The non-transitory computer-readable medium according to claim 17, further configured to perform operations including the following when executed by one or more processors: Receive a second network policy corresponding to the node in the cluster pool, wherein the second network policy lifts the port restriction on the second port.
20. The non-transitory computer-readable medium according to claim 17, wherein preparing for maintenance of the node includes draining container data from the node to the standby node.
Citation Information
Patent Citations
Heartbeat detection method and heartbeat detection apparatus
CN101345663A
Heartbeat detection processing method and device
CN110768853A
Server connection control method and device
CN112737945A
Distributed load balancer health management using data center network manager
CN113796048A
Distributed health check for global server load balancing
US20100121932A1