Configuration of node ports for maintenance without load balancer coordination

By restricting and resuming transaction data transmission of nodes through network policies, the problems of resource waste and data interruption during node maintenance in the cluster network are solved, and an efficient and seamless maintenance process is achieved.

CN120092434BActive Publication Date: 2026-02-17VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202280101307.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2026-02-17
Estimated Expiration
2042-11-10

AI Technical Summary

Technical Problem

In cluster networks, traditional methods require frequent coordination between I/O management and maintenance teams during node maintenance, leading to extended maintenance time and wasted resources, and failing to effectively prevent transaction data interruptions.

Method used

Network policies are implemented through a network management server to restrict transaction data transmission from the load balancer to nodes under maintenance, and data transmission is automatically restored after node maintenance is completed. Periodic health check messages are used to simulate node failures, reducing human intervention.

Benefits of technology

It achieves a seamless node maintenance process, reduces human capital consumption and maintenance time, avoids transaction data interruption, and improves maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120092434B_ABST
    Figure CN120092434B_ABST
Patent Text Reader

Abstract

A computer-implemented method provides a network policy configured to prevent transaction data processing from being interrupted during performance of maintenance on a node in a cluster network. The network policy reduces maintenance period time and the number of personnel required to perform node maintenance by simulating node failure. The simulated node failure prevents new transaction data from being sent to the node that is undergoing maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to configuration of nodes in a cluster network based on network policies. In particular, the technology herein discloses network policies that simulate node failures that prevent new transaction data from being sent to a node that is undergoing maintenance. SUMMARY

[0002] In one aspect, the present disclosure provides a method comprising: receiving, by a network management server, a network policy corresponding to a node in a cluster pool comprising a plurality of nodes, wherein the node comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implementing, by the network management server, the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining, by the network management server, that the transaction data received at the first port is processed by the node after implementing the network policy in preparation for maintenance of the node; and revoking, by the network management server, the network policy to remove the port limit at the second port after the maintenance at the node is completed based on a network policy status indicator.

[0003] In another aspect, the present disclosure provides a system comprising: a plurality of nodes; a cluster pool comprising the plurality of nodes; a load balancer server; a network management server communicably coupled to the plurality of nodes, wherein the network management server is configured to: receive a network policy corresponding to a node in a cluster pool, wherein the cluster pool comprises a plurality of nodes, and wherein the node in the cluster pool comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implement the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determine that transaction data received at the first port is processed by the node after implementing the network policy in preparation for maintenance of the node; and revoke the network policy to remove the port limit at the second port after the maintenance at the node is completed based on a network policy status indicator.

[0004] In yet another aspect, the present disclosure provides a non-transitory computer- readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations comprising: receiving a network policy corresponding to a node in a cluster pool comprising a plurality of nodes, wherein the node comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; provisioning a standby node to the cluster pool; initializing the standby node to receive the transaction data; implementing the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining that transaction data received at the first port is processed by the node after implementing the network policy in preparation for maintenance of the node; and revoking the network policy to remove the port limit at the second port after the maintenance of the node is completed based on a network policy state indicator. BRIEF DESCRIPTION OF DRAWINGS

[0005] In the description, for purposes of explanation and not limitation, specific details are set forth, such as particular aspects, procedures, techniques, etc. in order to provide a thorough understanding of the present technology. However, it will be apparent to one skilled in the art that the present technology can be practiced in other aspects that depart from these specific details.

[0006] The accompanying drawings are incorporated in and constitute a part of the specification for the disclosure and, along with the detailed description, serve to explain the aspects including the concepts claimed herein and, to illustrate the principles and advantages of such aspects, in which:

[0007] The [apparatuses, systems, and methods] disclosed herein have been represented, where appropriate, by conventional symbols, showing only those specific details that are pertinent to understanding the various aspects of the present disclosure, in order not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0008] Figure 1 A network architecture of a cluster network comprising a plurality of worker nodes is shown in accordance with at least one aspect of the present disclosure.

[0009] Figure 2 A cluster network comprising a load balancer and a plurality of worker nodes in a cluster pool is shown in accordance with at least one aspect of the present disclosure.

[0010] Figure 3 A logical flow diagram for implementing a new network policy in accordance with at least one aspect of the present disclosure.

[0011] Figure 4is a logical flow diagram for revoking network policies according to at least one aspect of the present disclosure.

[0012] Figure 5 is a logical flow diagram for provisioning a backup node prior to implementing a network policy to simulate a failure at a first node according to at least one aspect of the present disclosure.

[0013] Figure 6 A block diagram of a computer device according to at least one aspect of the present disclosure is presented.

[0014] Figure 7 is a graphical representation of an example system including a host machine within which a set of instructions for performing any one or more methods discussed herein can be executed according to at least one aspect of the present disclosure. DETAILED DESCRIPTION

[0015] The following disclosure can provide exemplary systems, apparatus, and methods for conducting financial transactions and related activities. Although reference can be made to such financial transactions in the examples provided below, aspects are not limited thereto. That is, the systems, methods, and devices can be used for any suitable purpose.

[0016] Before discussing specific embodiments, aspects, or examples, some description of terminology used herein is provided below.

[0017] As used herein, the terms "client" and "client device" can refer to one or more client-side devices or systems (e.g., remote from a transaction service provider) used to initiate or facilitate a transaction (e.g., a payment transaction). Further, "client" can also refer to an entity (e.g., a merchant, acquirer, etc.) that owns, utilizes, and / or operates a client device for initiating a transaction (e.g., for initiating a transaction with a transaction service provider).

[0018] The terms "client device" and "user device" refer to any electronic device configured to communicate with one or more servers or remote devices and / or systems. A client device or user device can include a mobile device, a network-enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, etc.), a computer, a POS system, and / or any other device or system capable of communicating with a network. A client device can also include a desktop computer, a laptop computer, a mobile computer (e.g., a smartphone), a wearable computer (e.g., a watch, glasses, lenses, clothing, etc.), a cellular phone, a network-enabled appliance (e.g., a network-enabled television, refrigerator, thermostat, etc.), a point-of-sale (POS) system, and / or any other device, system, and / or software application configured to communicate with a remote device or system.

[0019] As used herein, the term "communication" (or "communicate") can refer to the reception, receipt, transmission, transfer, provision, and / or the like of information (e.g., data, signals, messages, instructions, calls, commands, and / or the like). Communications can use direct or indirect connections, and can be wired or / and wireless in nature. As an example, one unit (e.g., a device, system, component of a device or system, combinations thereof, and / or the like) communicating with another unit means that the one unit is able to directly or indirectly receive

[0020] A "communication channel" can refer to any suitable path for communication between two or more entities. A suitable communication channel can exist directly between two entities, such as a payment processing network and a merchant or issuer computer, or can include a number of different entities. Any suitable communication protocol can be used to generate a communication channel. In some cases, a communication channel can comprise a "secure communication channel" or "tunnel" that can be established in any known manner, including using mutual authentication and session keys and establishing a secure communication session. However, any method of creating a secure communication channel can be used, and the communication channel can be wired or wireless, and long, short, or medium range. By establishing a secure channel, sensitive information related to a payment device, such as an account number, CVV value, expiration date, and / or the like, can be securely transmitted between two entities to facilitate a transaction.

[0021] As used herein, the term "includes" is not intended to be limiting, but rather can be a transitional term used in conjunction with "comprising," "containing," or "having," or equivalent terms, to indicate open-ended, non- limiting inclusion. Thus, the term "includes" can be inclusive or open-ended, and use of this term in a claim does not exclude additional, unrecited elements or method steps. For example, when describing a method, "includes" indicates that the claim is open-ended and allows additional steps. When describing an apparatus, "includes" can mean that the recited elements can be necessary for one embodiment or aspect, but other elements can be added, and still form a construction within the scope of the claim. In contrast, the transitional phrase "consisting of excludes any element, step, or ingredient not specified in the claim. This is consistent with the use of this term throughout the specification.

[0022] As used herein, the term "computing device" or "computer device" can refer to one or more electronic devices configured to communicate directly or indirectly with one or more networks. The computing device can be a mobile device, a desktop computer, etc. As an example, a mobile device can include a cellular phone (e.g., a smartphone or a standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, etc.), a personal digital assistant (PDA), and / or other similar devices. The computing device can not be a mobile device, such as a desktop computer. Further, the term "computer" can refer to any computing device that includes the necessary components for sending, receiving, processing, and / or outputting data, and typically includes a display device, a processor, a memory, an input device, and a network interface, and / or the like.

[0023] As used herein, references to "devices," "servers," "processors," and the like can refer to the devices, servers, or processors recited as performing a previous step or function, different servers or processors, and / or combinations of servers and / or processors. For example, as used in the specification and claims, a first server or a first processor recited as performing a first step or a first function can refer to the same or different server or the same or different processor recited as performing a second step or a second function.

[0024] An "interface" can include any software module configured to handle communications. For example, an interface can be configured to receive, process, and respond to specific entities in a specific communication format. Further, a computer, device, and / or system can include any number of interfaces depending on the functionality and capabilities of the computer, device, and / or system. In some embodiments or aspects, an interface can include an application programming interface (API) or other communication format or protocol that can be provided to third parties or specific entities to allow for communication with a device. Additionally, an interface can be designed based on functionality, designated entities configured to communicate therewith, or any other variable. For example, an interface can be configured to allow a system to field process specific requests, or can be configured to allow specific entities to communicate with a system.

[0025] An "original" transaction can include any transaction that includes an authorization provided by an issuer or an authorization provided on behalf of an issuer.

[0026] A "payment network" can refer to an electronic payment system that is used to accept, transport, or process transactions made by payment devices for funds, goods, or services. A payment network can communicate information and funds between issuers, acquirers, merchants, and payment device users. One illustrative, non-limiting example of a payment network is VisaNet, operated by Visa, Inc.

[0027] "Provisioning" can include a process of providing data for use. For example, provisioning can include providing, delivering, or enabling a token on a device. Provisioning can be done by any entity within or external to a transaction system. For example, in some embodiments or aspects, a token can be provisioned onto a mobile device of a consumer (e.g., account holder) by an issuer or a payment processing network. A provisioned token can have corresponding token data stored and maintained within a token vault or token registry. In some embodiments or aspects, a token vault or token registry can generate tokens that can be provisioned or delivered to a device after generation. In some embodiments or aspects, an issuer can specify a token range from which token generation and provisioning can occur. Further, in some embodiments or aspects, an issuer can generate token values and notify a token vault, and provide token record information (e.g., token attributes) for storage in the token vault.

[0028] As used herein, the term“server” can include one or more computing devices, which can be individual independent machines located at the same or different locations, can be owned or operated by the same or different entities, and can also be one or more clusters of distributed computers or“virtual” machines housed within a data center. Those skilled in the art will understand and appreciate that the functions performed by one“server” can be spread across multiple different computing devices for a variety of reasons. As used herein,“server” is intended to refer to all such scenarios and should not be construed or limited to one particular configuration. Further, a server as described herein can, but need not, reside at or be operated by a merchant, payment network, financial institution, medical provider, social media provider, government agency, or agent of any of the foregoing (or be operated by). The term“server” can also refer to or include one or more processors or computers, storage devices, or similar computer arrangements operated or facilitating communication and processing by multiple parties in a network environment such as the Internet, although it will be appreciated that communication can be facilitated over one or more public or private network environments and various other arrangements are possible. Further, multiple computers (e.g., servers) or other computerized devices (e.g., point-of-sale devices) in direct or indirect communication in a network environment can constitute a“system” (e.g., a merchant’s point-of-sale system). As used herein, a reference to a“server” or“processor” can refer to the server and / or processor recited as performing a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server and / or a first processor recited as performing a first step or function can refer to the same or different server and / or processor recited as performing a second step or function.

[0029] A“server computer” can generally be a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers acting in concert. The server computer can be associated with an entity such as a payment processing network, a wallet provider, a merchant, an authentication cloud, an acquirer, or an issuer. In one example, the server computer can be a database server coupled to a web server. The server computer can be coupled to a database and can include any hardware, software, other logic, or combination thereof for servicing the requests from one or more client computers. The server computer can comprise one or more computing devices and can use any of a variety of computing structures, arrangements, and compilations for servicing the requests from one or more client computers. In some embodiments or aspects, the server computer can provide and / or support a payment network cloud service.

[0030] As used herein, the term“system” can refer to one or more computing devices or combinations of computing devices (e.g., processors, servers, client devices, software applications, components of these computing devices, and / or the like).

[0031] The term“transaction data” can include any data associated with one or more transactions. In some embodiments or aspects, the transaction data can include only an account identifier (e.g., a PAN) or a payment token. Alternatively, in other embodiments or aspects, the transaction data can include any information generated, stored, or associated with a merchant, a consumer, an account, or any other transaction-related information. For example, the transaction data can include data in an authorization request message generated in response to a payment transaction initiated by a consumer with a merchant. Alternatively, the transaction data can include information associated with one or more transactions that have already been processed and the transaction information has been stored on a merchant database or other merchant computer. The transaction data can include an account identifier associated with a payment instrument used to initiate a transaction, consumer personal information, a product or service purchased, or any other information that can be relevant or appropriate for transaction processing. Additionally, the transaction information can include a payment token or other tokenized or masked account identifier substitute that can be used to complete a transaction and protect a consumer’s underlying account information.

[0032] As used herein, the term“transaction service provider” can refer to an entity that receives transaction authorization requests from merchants or other entities and in some cases provides payment guarantees through an agreement between the transaction service provider and an issuer. For example, a transaction service provider can include a payment network, such as American Express® or any other entity that processes transactions. As used herein, a“transaction service provider system” can refer to one or more systems operated by or on behalf of a transaction service provider, such as a transaction service provider system executing one or more software applications associated with a transaction service provider. In some non-limiting embodiments or aspects, a transaction processing system can include one or more server computers having one or more processors and, in some non-limiting embodiments or aspects, can be operated by or on behalf of a transaction service provider.

[0033] A "user device" is an electronic device that can be transferred and / or operated by a user. A user device can provide remote communication capabilities to a network. A user device can be configured to transmit data or communications to and receive data or communications from other devices. In some embodiments or aspects, a user device can be portable. Examples of user devices can include a phone (e.g., a smartphone, a cellular phone, etc.), a PDA, a portable media player, a wearable electronic device (e.g., a smartwatch, a fitness band, an ankle bracelet, a ring, an earring, etc.), an e-reading device, and a portable computing device (e.g., a laptop, a netbook, an ultrabook, etc.). Examples of user devices can also include a car with remote communication capabilities.

[0034] "User information" can include any information associated with a user. For example, user information can include a device identifier of a device owned or operated by a user and / or account credentials of an account held by a user. A device identifier can include a unique identifier assigned to a user device that can later be used to authenticate the user device. In some embodiments or aspects, a device identifier can include a device fingerprint. A device fingerprint can be an aggregation of device attributes. A device fingerprint can be generated by a software development kit (SDK) provided on a user device using, for example, a unique identifier assigned by an operating system, an international mobile station equipment identity (IMEI) number, an operating system (OS) version, a plug-in version, etc.

[0035] The present disclosure describes a cluster management platform that includes a pool of multiple worker nodes. The multiple worker nodes are configured to process continuous transaction data streams (e.g., payment authorizations) from multiple external sources. The external sources are communicatively coupled to an I / O (input / output) server at a network gateway. The I / O server includes a load balancer configured to evenly distribute transaction data transformation streams to the multiple nodes. The load balancer is configured based on multiple distribution factors including a total number of nodes in the cluster pool, an expected number of incoming transactions, and / or an estimated processing time per transaction authorization. The configuration factors allow real-time transaction data distribution to the multiple worker nodes. The load balancer is rarely reconfigured based on new or updated configuration factors. The cluster pool is configured to process transactions globally and does not experience a reduction in transaction data due to time zones, weekends, and / or holidays. As a result, the network cannot afford the consequences of taking worker nodes offline for maintenance.

[0036] Each worker node in a cluster pool can correspond to a physical machine that requires periodic hardware, software patch, and / or firmware maintenance by a maintenance person in the data center. In some cluster pools, there can be hundreds of worker nodes corresponding to respective physical machines. The maintenance person is responsible for performing periodic maintenance on each node in the cluster pool. This can result in a marathon maintenance session in which the maintenance person performs periodic maintenance on one or several nodes sequentially, one after the other, until the entire cluster pool has been updated. For example, the maintenance session can last for hours to days.

[0037] During the maintenance session, spare nodes can be added to or automatically provisioned in the cluster pool to compensate for the worker nodes that are taken offline for maintenance. Once the periodic maintenance is complete, the worker nodes can resume operation in the cluster pool. Once all worker nodes in the cluster pool have been patched or updated, the spare nodes can be taken offline, restoring the original node configuration in the cluster pool.

[0038] During the maintenance session, the maintenance person traditionally communicates continuously with a separate group of people managing the I / O servers. The I / O managers configure the load balancers of the I / O servers. The load balancers distribute transaction data to the multiple nodes in the cluster pool. The maintenance person must communicate with the I / O managers so that a particular node can be taken offline without interfering with or interrupting any pending transaction data processing. Additionally, the I / O managers must know the duration of time that a node will be taken offline so that the cluster configuration can compensate for changes in the workload. Thus, the I / O managers manually update the load balancers to stop sending transaction data to the first node under maintenance during the maintenance session. When the I / O personnel receive a notification from the maintenance person that the first node has been updated, the I / O personnel configure the load balancers to resume sending the first node transaction data as part of the cluster pool. The maintenance process can last for hours or days and ties up resources from both the I / O management and maintenance teams. Additionally, if the maintenance person encounters a problem that requires the node to be taken offline for a longer period of time, they must notify the I / O management personnel of the need for additional offline time to route transactions away from the node under maintenance. The team coordination extends the overall time of the maintenance session and can limit the availability to perform the overall maintenance. The periodic maintenance can only be performed when personnel from both the I / O management and maintenance are available. Thus, the maintenance sessions are very expensive as they tie up human capital from both the maintenance person team and the business personnel team.

[0039] This disclosure describes various aspects of performing periodic maintenance on nodes in a cluster pool that avoid the need for continuous communication between the I / O management team and the maintenance team. The use of only the maintenance person reduces the amount of human capital, so that there is no need to coordinate periodic maintenance times that apply to multiple teams, and reduces the overall maintenance session due to no communication / action delays.

[0040] The present disclosure utilizes periodic status requests from a load balancer, commonly referred to as periodic health checks performed by the load balancer. During a periodic health check, the load balancer sends a request via a periodic health check packet to a specific port of each node in a cluster pool to verify that each node is functioning properly. Once a node receives a periodic health check packet, the node has a predetermined amount of response time. If there is a delay in the response that exceeds the predetermined period, or no response is received at all, the load balancer determines that the node has experienced some type of error or failure that will prevent the node from operating properly. As a result, the load balancer stops sending transaction data to the node as part of load balancing data distribution in the cluster pool. In various aspects, the present disclosure provides a network policy configured to simulate a failure at a node. By way of the network policy, a simulated node failure can be determined by the load balancer as a result of a blocked periodic health check packet or a blocked node response.

[0041] Turning now to the figures, Figure 1 A network architecture is shown that includes a cluster network 100 of a plurality of worker nodes 102a-n in accordance with at least one aspect of the present disclosure. An I / O server 108 includes a load balancer 106 configured to distribute transaction data evenly to the plurality of worker nodes 102a-n. The I / O server 108 is located on a local network side of a network gateway 110 that bridges a wide area network 112 (WAN) with a local area network (LAN). The I / O server 108 is configured to receive transaction data from a plurality of external data sources 114-n. In various aspects, the I / O server 108 includes hardware that can be configured to execute cloud cluster computing software (e.g., Kubernetes). The cloud cluster computing software can be configured to execute the load balancer 106 for incoming transaction data received by the I / O server 108.

[0042] Figure 1 A network management server 104 is also shown in communication with the plurality of worker nodes 102a-n. The network management server 104 can receive a network policy and configure one or more nodes such that periodic health check messages are blocked at a health check port of the node. In various aspects, once the network policy is implemented, the health check port can be blocked indefinitely until the network management server receives a second policy that unblocks the health check port and unblocks the policy. In another aspect, the network policy can be configured according to an expiration time-to-live (TTL) value. Once the TTL timer reaches a predetermined value, counts up to, or counts down to zero, the network policy can be automatically revoked.

[0043] In various aspects, the network management server 104 can act as a firewall block, or intercept the periodic health check message before it reaches the node. The network management server 104 can perform deep packet inspection and monitor traffic for a particular address and port corresponding to the node. In one example, a network policy can be configured to identify the health check port of the first node in the destination field of the packet header. This policy can block all traffic to this destination. In this example, the health check port of the first node never receives the periodic health check message from the load balancer and therefore does not respond. In another example, a network policy can be configured to identify the health check port of the first node in the source field of the packet header. This policy can block all outgoing traffic from this source from reaching its destination. In this example, the health check port can still receive the periodic health check message from the load balancer, but the response can be blocked from reaching the load balancer.

[0044] Figure 2 A cluster network 200 including a load balancer 206 and a plurality of worker nodes 202 in a cluster pool 218 is shown in accordance with at least one aspect of the present disclosure 1-3 (W1-W3) and master nodes 224 1-5 (M1-M5) (e.g., control nodes). Each worker node 202 of the plurality of worker nodes includes at least two ports, a transaction data port 216 and a health check port 217. The load balancer 206 is configured to send periodic health check messages 222 to each worker node 202 in a round robin sequence 1-3 (W1-W3) to the health check port 217 of the worker node 202 1-3 (W1-W3) is configured to transmit a response within a predetermined period of time to indicate that the worker node 202 1-3 (W1-W3) is healthy and can receive or continue to receive transaction data 220 at the transaction data port 216. It should be appreciated that the cluster network 200 is not limited to the configuration shown and there can be n worker nodes 202 1-n and m master nodes 224 1-m where n and m are any positive integer.

[0045] Figure 3 A logic flow diagram 300 for implementing a new network policy in accordance with at least one aspect of the present disclosure. Referring now to Figure 3 and Figure 2network management server 204 receives 302 a new network policy to limit network traffic directed to a health check port of the first node 202i (Wi). The network management server 204 configures 304 the first node 202i (Wi) or a firewall to block periodic health check messages or all traffic with a port destination address of the health check port. The network management server 204 determines 306 that the periodic health check container at the first node 202i (Wi) does not receive periodic health check messages and, as a result, the first node 202i (Wi) stops responding to periodic health check messages sent by the load balancer 206. The network management server 204 monitors network traffic in the cluster network 200 and determines 308 that the load balancer 206 does not receive a response to a periodic health check message sent to the first node 202i (Wi) within a predetermined period of time. A response received within the threshold period of time indicates to the load balancer 206 that the first node 202i (Wi) is functioning properly. The network management server 204 determines 310 that the load balancer 206 infers that the first node 202i (Wi) is experiencing an error or failure based on a failure of the first node 202i (Wi) to respond. The network management server 204 monitors network traffic and determines 312 that the load balancer 206 stops transmitting transaction data to the first node 202i (Wi). The network management server 204 determines 314 that all transaction data processing has completed based on a timestamp of last transaction data received at the first node 202i (Wi) and after a processing time of the transaction data. The network management server 204 can be configured to wait a predetermined period of time after the last transaction data is received by the first node 202i (Wi) and generate a notification that all pending processing has completed when the predetermined period of time expires. The network management server 204 determines 316 that the first node 202i (Wi) can be taken offline to perform maintenance without interrupting processing of transaction data.

[0046] Figure 4 is a logical flow diagram 400 for revoking a network policy in accordance with at least one aspect of the present disclosure. In various aspects, a network policy can be revoked due to a new network policy or due to expiration of an existing policy. Reference is made to Figure 4 and Figure 2, the time-to-live value in the new network policy or the first policy can include a network policy state indicator that indicates to the network management server 204 that the first policy is no longer valid. The network management server 204 determines that the first policy is no longer valid and revokes 402 the first policy. The network management server 204 monitors network traffic and determines 404 that the first node 2021 (W1) receives periodic health check messages from the load balancer. The network management server 204 monitors network traffic and determines 406 that the first node 2021 (W1) responds to the periodic health check messages within a predetermined period. The network management server 204 monitors network traffic and determines 408 that the load balancer 206 receives periodic health check responses within a predetermined period. The network management server 204 monitors network traffic and verifies 410 that the load balancer 206 has resumed transmitting transaction data to the first node 2021 (W1). The network management server 204 determines 412 that the first node 2021 (W1) is processing transaction data as part of the cluster pool 218 and that the next node 2022 (W2) in the rotation sequence can be taken for maintenance without disrupting the load of the cluster pool 218.

[0047] Figure 5 is a logical flowchart 500 for provisioning a backup node prior to or in response to implementing a network policy to simulate a failure at a first node in accordance with at least one aspect of the present disclosure. Reference is made to Figure 5 and Figure 2 The network policy can include instructions for the network management server 204 to provision 502 the backup node 2022 (W2) as part of the cluster pool 218. The network management server 204 establishes 504 a drain connection between the first node 2021 (W1) that is scheduled for maintenance and the backup node 2022 (W2). The first node 2021 (W1) transmits 506 a copy of all container data to the backup node 2022 (W2) so that processing can continue seamlessly when the first node 2021 (W1) is taken offline for maintenance. The backup node 2022 (W2) responds to periodic health check messages and receives 508 transaction data from the load balancer 206 as part of the cluster pool 218. Once the network management server 204 verifies that the backup node 2022 (W2) is actively processing transaction data in the cluster pool 218, the network management server 204 can simulate 510 a node failure of the first node 2021 (W1) for maintenance. To maintain subsequent nodes 2023 (W3), the backup node 2022 (W2) can remain active until all nodes have been updated. In various aspects, each node 202 1-3 (W1-W3) can transfer container data to the backup node 2022 (W2) prior to the node being taken for maintenance.

[0048] Figure 6 is a block diagram of a computer device 3000 having a data processing subsystem or component, in accordance with at least one aspect of the present disclosure. Figure 6 The subsystems shown in FIG. 30 are interconnected via a system bus 3010. Additional subsystems such as a printer 3018, a keyboard 3026, a fixed disk 3028 (or other memory providing a computer readable medium), a monitor 3022 coupled to a display adapter 3020, etc. can also be connected to the system bus 3010. Peripherals and input / output (I / O) devices, which can include mice, modems, scanners, or other devices, can be connected to the computer system either directly or through an I / O controller 3012 (which can be a processor or any suitable controller) coupled to the system bus 3010. For example, a serial port 3024 or an external interface 3030 can be used to connect the computer device to a wide area network such as the Internet, a mouse input device, or a scanner. The interconnection via the system bus allows the central processor 3016 to communicate with each subsystem and to control the execution of instructions from the system memory 3014 or the fixed disk 3028, as well as the exchange of information between subsystems. The system memory 3014 and / or the fixed disk 3028 can embody a computer readable medium.

[0049] Figure 7 is a diagrammatic representation of an example system 4000 including a host 4002 within which a set of instructions can be executed to perform any one or more of the methodologies discussed herein, in accordance with at least one aspect of the present disclosure. In various aspects, the host 4002 operates as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, the host 4002 can operate in the capacity of a server or a client machine in server-client network environments, or it can act as a peer machine in peer-to-peer (or distributed) network environments. The host 4002 can be a computer or a computing device, a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular telephone, a portable music player (e.g., an iPod®, a portable hard disk audio device, such as a Moving Picture Experts Group Audio Layer 3 (MP3) player), a web appliance, a network router, switch or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.

[0050] The example system 4000 includes a host 4002 running a host operating system (OS) 4004 on a processor(s) / processor core(s) 4006 (e.g., central processing units (CPUs), graphics processing units (GPUs), or both) and various memory nodes 4008. The host OS 4004 can include a hypervisor 4010 that is capable of controlling functions and / or communicating with virtual machines (“VMs”) 4012 running on machine-readable media. The VMs 4012 can also include virtual CPUs or vCPUs 4014. The memory nodes 4008 can be linked or pinned to virtual memory nodes or vNodes 4016. When the memory nodes 4008 are linked or pinned to corresponding vNodes 4016, data can then be mapped directly from the memory nodes 4008 to their corresponding vNodes 4016.

[0051] All of the various components shown in the host 4002 can be connected with and to each other, or communicate with each other, via a bus (not shown) or via other coupling or communication channels or mechanisms. The host 4002 can also include a video display, audio device or other peripheral devices 4018 (e.g., liquid crystal display (LCD), alphanumeric input device(s) (including, e.g., a keyboard), cursor control device(s) (e.g., a mouse), voice recognition or biometric authentication units, external drive(s), signal generation device(s) (e.g., a speaker)), persistent storage device(s) 4020 (also referred to as disk drive units), and network interface device(s) 4022. The host 4002 can also include a data encryption module (not shown) for encrypting data. The components disposed in the host 4002 are those typically found in a computer system that can be suitable for use with aspects of the present disclosure, and are intended to represent a broad category of such computer components known in the art. Thus, the system 4000 can be a server, a minicomputer, a mainframe computer, or any other computer system. The computer can also include different bus configurations, network platforms, multiprocessor platforms, and the like. Various operating systems can be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.

[0052] The disk drive unit 4024 can also be a solid state drive (SSD), a hard disk drive (HDD), or other drive containing computer or machine readable media on which is stored one or more sets of instructions and data structures (e.g., data / instructions 4026) embodying or utilized by any one or more of the methodologies or functions described herein. The data / instructions 4026 can also reside completely, or at least partially, within the main memory node 4008 and / or the processor(s) 4006 during execution thereof by the host 4002. The data / instructions 4026 can further be transmitted or received over a network 4028 via the network interface device 4022 utilizing any one of a number of well-known transfer protocols (e.g., Hyper Text Transfer Protocol (HTTP)).

[0053] The processor(s) 4006 and memory node 4008 can also include machine- readable media. The term "computer-readable medium" or "machine-readable medium" is intended to include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store one or more sets of instructions and data structures (e.g., software / patentable applications) embodying or utilized by any one or more of the methodologies or functions described herein. The term "computer- readable medium" shall also be taken to include any medium that is capable of storing, encoding or carrying the instructions and data structures utilized by the host 4002 for execution by the host 4002 and that cause the host 4002 to perform any one or more of the methodologies of the present application. Therefore, the term "computer-readable medium" shall accordingly be taken to include, but not be limited to, solid-state memories, optical and magnetic media, and carrier wave signals. The media can also include, but not limited to, hard disks, floppy disks, flash memory cards, digital video disks, random access memories (RAMs), read only memories (ROMs) and the like. The example aspects described herein can be implemented in an operating environment comprising a computer, a hardware-implemented module or a combination of software and hardware.

[0054] Those skilled in the art will recognize that an internet service can be configured to provide internet access to one or more computing devices coupled to the internet service, and that the computing devices can include one or more processors, buses, memory devices, display devices, input / output devices, etc. Further, those skilled in the art can appreciate that the internet service can be coupled to one or more databases, repositories, servers, etc. that can be utilized to implement any of the aspects of the present disclosure described herein.

[0055] The computer program instructions can also be loaded onto a computer, server, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0056] For example, a suitable network can include or interface to any one or more of the following: a local intranet, a PAN (personal area network), a LAN (local area network), a WAN (wide area network), a MAN (metropolitan area network), a virtual private network (VPN), a storage area network (SAN), a frame relay connection, an advanced intelligent network (AIN) connection, a synchronous optical network (SONET) connection, a digital Tl, T3, El, or E3 line, a Digital Data Service (DDS) connection, a DSL (digital subscriber line) connection, an Ethernet connection, an ISDN (integrated services digital network) line, a dial-up port (e.g., V.90, V.34, or V.34bis analog modem connection) a cable modem, an ATM (asynchronous transfer mode) connection, or a FDDI (fiber distributed data interface) or CDDI (copper distributed data interface) connection. Also, communication can include links to any one or more of the following: a wireless network, including a WAP (wireless application protocol), GPRS (general packet radio service), GSM (global system for mobile communication), CDMA (code division multiple access) or TDMA (time division multiple access), a cellular telephone network, a GPS (global positioning system), a CDPD (cellular digital packet data), a RIM (research in motion) duplex pager network, a Bluetooth radio, or an IEEE 802.11 -based radio frequency network. The network 4030 can also include, or interface to, any one or more of the following: an RS-232 serial connection, an IEEE-1394 (Firewire) connection, a Fibre Channel connection, an IrDA (infrared) port, a SCSI (small computer system interface) connection, a USB (universal serial bus) connection, or other wired or wireless, digital or analog, interface or connection, mesh or Network connections.

[0057] Generally, a cloud-based computing environment is a resource that typically combines the processing power of a large group of processors (e.g., within a web server) and / or the storage capacity of a large group of computer memories or storage devices. Systems that provide cloud-based resources can be employed only by their owners, or such systems can be accessed by external users who deploy applications within the computing infrastructure to obtain the benefits of large computing or storage resources.

[0058] For example, a cloud is formed by a network of web servers comprising a plurality of computing devices (e.g., host 4002), where each server 4030 (or at least a plurality of them) provides processor and / or storage resources. These servers manage workloads provided by a plurality of users (e.g., cloud resource customers or other users). Typically, each user's workload demand on the cloud is changing in real time, sometimes even dramatically. The nature and extent of these changes typically depends on the type of business associated with the user.

[0059] Notably, any hardware platform suitable for performing the processes described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage media" refer to any medium or media used to provide instructions to CPU for execution. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks, such as a fixed disk. Volatile media includes dynamic memory, such as a system RAM. Transmission media includes coaxial cables, copper wire and fiber optics, including the wires that comprise a bus that also can be included as part of the digital logic circuitry. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, a floppy disk, a rigid disk, a magnetic tape, any other magnetic medium, a CD-ROM disk, digital video disk (DVD), any other optical medium, punch cards, paper tape, any other physical medium with patterns of holes, a RAM, a PROM, an EPROM, a FLASH-EPROM, any other memory chip or cartridge, a carrier wave, or any other medium from which a computer can read.

[0060] Various forms of computer-readable media can be involved in carrying one or more sequences of one or more instructions to the CPU for execution. A bus carries the data to system RAM, from which a CPU retrieves and executes the instructions. The instructions received by system RAM can optionally be stored on a fixed disk either before or after execution by CPU.

[0061] Computer program code for carrying out operations for aspects of the present technology can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language, Go, Python, or another programming language including assembly languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0062] Examples of methods in accordance with various aspects of the present disclosure are provided below in the following numbered clauses. One aspect of the methods can include any one or more of the following numbered clauses, and any combination thereof, described below.

[0063] Clause 1. A method comprising: receiving, by a network management server, a network policy corresponding to a node in a cluster pool comprising a plurality of nodes, wherein the node comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implementing, by the network management server, the network policy to configure a port limit for the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determining, by the network management server, that the transaction data received at the first port is processed by the node after implementing the network policy in preparation for maintenance of the node; and revoking, by the network management server, the network policy to remove the port limit at the second port after the maintenance at the node is completed based on a network policy state indicator.

[0064] Clause 2. The method of clause 1, wherein the port limit causes a simulated error at the node that prevents the node from responding to the periodic health check messages for a predetermined period of time, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

[0065] Clause 3. The method of clause 1, wherein the network policy state indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy removes the port limit at the second port of the node.

[0066] Clause 4. The method of clause 1, wherein the network policy status indicator is a TTL (Time To Live) value, and wherein the network policy is disengaged upon expiration of the TTL value.

[0067] Clause 5. The method of clause 1, further comprising monitoring, by the network management server, for a response by the node to at least one of the periodic health check messages within a predetermined period of time after the revocation of the network policy.

[0068] Clause 6. The method of clause 5, further comprising monitoring, by the network management server, for receipt of new transaction data at the first port by the node after the revocation of the network policy.

[0069] Clause 7. The method of clause 1, further comprising provisioning, by the network management server, a backup node to the cluster pool; and initializing, by the network management server, the backup node to receive the transaction data.

[0070] Clause 8. The method of clause 1, wherein the maintenance comprises at least one of installing a software patch on the node or fixing a hardware fault at the node.

[0071] Clause 9. A system comprising: a plurality of nodes; a cluster pool comprising the plurality of nodes; a load balancer server; a network management server communicably coupled to the plurality of nodes, wherein the network management server is configured to: receive a network policy corresponding to a node in a cluster pool, wherein the cluster pool comprises a plurality of nodes, and wherein the node in the cluster pool comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; implement the network policy to configure a port limit of the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; determine that transaction data received at the first port is processed by the node after implementing the network policy in preparation for maintenance of the node; and revoke the network policy to disengage the port limit at the second port based on a network policy status indicator after the maintenance at the node is completed.

[0072] Clause 10. The system of clause 9, wherein the port limit causes a simulated error at the node that prevents the node from responding to the periodic health check messages within a predetermined period of time, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

[0073] Clause 11. The system of clause 9, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy removes the port restriction at the second port of the node.

[0074] Clause 12. The system of clause 9, wherein the network policy status indicator is a TTL (Time-To-Live) value, and wherein the network policy is removed upon expiration of the TTL value.

[0075] Clause 13. The system of clause 9, wherein the network management server is further configured to monitor the node for responding to at least one of the periodic health check messages within a predetermined period of time after removal of the network policy.

[0076] Clause 14. The system of clause 13, wherein the network management server is further configured to monitor the node for receiving new transaction data at the first port after removal of the network policy.

[0077] Clause 15. The system of clause 9, wherein the network management server is further configured to: provision a backup node to the pool of clusters; and initialize the backup node to receive the transaction data.

[0078] Clause 16. The system of clause 9, wherein the maintenance comprises at least one of installing a software patch on the node or fixing a hardware fault at the node.

[0079] Clause 17. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising: receiving a network policy corresponding to a node in a pool of clusters comprising a plurality of nodes, wherein the node comprises a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer; provisioning a backup node to the pool of clusters; initializing the backup node to receive the transaction data; enforcing the network policy to configure a port restriction of the second port of the node, wherein the port restriction causes the load balancer to stop transmitting the transaction data to the first port; determining that transaction data received at the first port is processed by the node after enforcing the network policy in preparation for maintenance of the node; and removing the network policy based on a network policy status indicator to remove the port restriction at the second port after the maintenance of the node is completed.

[0080] Clause 18. The non-transitory computer-readable medium of clause 17, wherein the port restriction causes a simulated error at the node that prevents the node from responding to the periodic health check message within a predetermined time period, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

[0081] Clause 19. The non-transitory computer-readable medium of clause 17, when executed by one or more processors, is further configured to perform operations comprising receiving a second network policy corresponding to the node in the cluster pool, wherein the second network policy removes the port restriction on the second port.

[0082] Clause 20. The non-transitory computer-readable medium of clause 17, wherein preparing the node for maintenance includes draining container data from the node to the standby node.

[0083] The foregoing detailed description has set forth various forms of systems and / or processes that can be contemplated. As such, the foregoing detailed description is not intended to limit the scope of the disclosure, as claimed, but rather is merely contemplated to provide realizations for the forms set forth herein. Further, to the extent that the foregoing detailed description set forth various forms of systems and / or processes, it should be recognized that interchangeable terms can be used in some circumstances. Accordingly, no limitation is implied by the use of interchangeable terms. Further, where the foregoing detailed description has set forth forms of systems and / or processes that can be contemplated, it should be recognized that such describe only forms of systems and / or processes and do not limit the scope of the disclosure. Accordingly, the disclosure is not limited to that which can be possibly implied by the foregoing detailed description.

[0084] Instructions used to program logic to perform various disclosed aspects can be stored within a memory in the system, such as dynamic random access memory (DRAM), cache memory, flash memory, or other storage. Furthermore, instructions can be distributed over network coupled computer systems so that the instructions are stored and executed in a distributed fashion. Hence, a machine-readable medium can also take many forms of technical effect within a system as long as the form is such that the technical effect is to facilitate information storage and exchange. Therefore, a machine-readable medium can include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), but is not limited to, soft disks, optical disks, magnetic disks, magnetic tapes, hard disk drives, RAM, flash memory, or the Internet or other communication networks or technical effects communicating such forms of information.

[0085] Any of the software components or functions described in this application can be implemented as software code to be executed by a processor using, for example, conventional or object-oriented techniques. The software code can be stored as a series of instructions or commands or as a series of codes on a non-transitory computer-readable medium such as a RAM, a ROM, a magnetic medium such as a hard disk or a floppy disk, or an optical medium such as a CD-ROM. Any such computer-readable medium can reside on or within a single computational apparatus, and can be present on or within different computational apparatuses within a system or network.

[0086] As used in any aspect herein, the term “logic” can refer to an app, software, firmware and / or circuitry configured to perform any of the aforementioned operations. Software can be embodied as a software package, code, instructions, instruction sets, and / or data stored anywhere on a non-transitory computer-readable storage medium, such as a hard disk, a removable magnetic media, a removable optical media, flash memory, and / or any other storage medium. Firmware can be embodied as code, instructions or instruction sets stored in memory devices (e.g., non-volatile memory devices).

[0087] As used in any aspect herein, the terms “component,” “system,” “module” and the like can refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution.

[0088] As used in any aspect herein, an “algorithm” refers to a self-consistent sequence of steps leading to a desired result, where a “step” refers to a manipulation of physical quantities and / or logical states, although not necessarily in a manner that manipulates electrical signals or magnetic signals per se. Typically, such signals are referred to as bits, values, elements, symbols, characters, terms, numbers, or the like. These and similar terms can be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.

[0089] The network can include a packet-switched network. The communication devices can be capable of communicating with one another using a selected packet-switched network communication protocol. One example communication protocol can include an Ethernet communication protocol, which can be capable of permitting communication using the Transmission Control Protocol / Internet Protocol (TCP / IP). The Ethernet protocol can conform to or be compatible with the Ethernet standard entitled “IEEE 802.3 Standard,” published by the Institute of Electrical and Electronics Engineers (IEEE) in December 2008, and / or subsequent versions of this standard. Alternatively or additionally, the communication devices can be capable of communicating with one another using an X.25 communication protocol. The X.25 communication protocol can conform to or be compatible with a standard promulgated by the International Telecommunication Union-Telecommunication Standardization Sector (ITU-T). Alternatively or additionally, the communication devices can be capable of communicating with one another using a Frame Relay communication protocol. The Frame Relay communication protocol can conform to or be compatible with a standard promulgated by the Consultative Committee for International Telegraph and Telephone (CCITT) and / or the American National Standards Institute (ANSI). Alternatively or additionally, the transceivers can be capable of communicating with one another using an Asynchronous Transfer Mode (ATM) communication protocol. The ATM communication protocol can conform to or be compatible with the ATM standard entitled “ATM-MPLS Network Interworking 2.0,” published by the ATM Forum in August 2001, and / or subsequent versions of this standard. Of course, different and / or developed later connection-oriented network communication protocols are likewise contemplated herein.

[0090] Unless specifically stated otherwise, as apparent from the preceding disclosure, it is appreciated that throughout this disclosure, the use of a "we" or "us" terminology, refers to the computer system or similar electronic computing device operating in conjunction with one or more human operators. Unless specifically stated otherwise, as apparent from the preceding disclosure, discussions utilizing terms such as "processing," "computing," "calculating," "determining," "displaying," or the like, refer to the action and processes of a computer system, or similar electronic computing device, that manipulates and transforms data represented as physical (electronic) quantities within the computer system memories or registers into other data similarly represented as physical quantities within the computer system memories or registers or other such information storage, transmission or display devices.

[0091] One or more components can be referred to herein as "configured to," "configurable to," "operable / operative to," "adapted to / adaptable to," "capable of," "suitable to / suitable for," "to be" and the like. Those skilled in the art will recognize that "configured to" can generally cover active- state components as well as inactive-state components and / or standby state components unless context requires otherwise.

[0092] Those skilled in the art will recognize that, in general, the terms used herein and especially in the appended claims (e.g., in the claims body) are generally intended as "open" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "includes but is not limited to," etc.). Those skilled in the art will further recognize that where terms are used in the claims body in a manner consistent with their usage in the previous disclosure, such terminology should not be interpreted to exclude other usage as understood by those skilled in the art. Those skilled in the art will further understand that, unless specifically set forth in the preceding disclosure, no identification of a specific number of introduced claim recitations is intended or should be inferred. For example, although the following claims body can contain the introduced phrase "at least one of," the use of such phrasing should not be interpreted to imply that more than one of the introduced claim recitations is present in the claims body, even though such phrasing can cover that possibility. Similarly, the use of the indefinite article "a" should not be interpreted as excluding the presence of more than one of the claimed recitations, even though such phrasing can cover that possibility.

[0093] Additionally, even if specific numbers are explicitly stated in the description of an

[0094] With respect to the appended claims, those skilled in the art will appreciate that one or more of the included apparatus elements can be further divided into further apparatus elements as appropriate. In the description of aspects, any identification of documents, acts, items, or the like is not intended to be, nor is it, a limitation on the aspects described. Descriptions of techniques, methods, or the like can be used synonymously, unless otherwise indicated. Descriptions of the various embodiments are not meant to be limiting, but rather are illustrative. As such, it is contemplated that various modifications, alterations, and / or combinations of the aspects described can be made by those skilled in the art without departing from the scope of the aspects. Further, it is contemplated that any steps, operations, or the like described in the aspects can be performed in any order, unless otherwise specified. The following examples are illustrative of the aspects described herein and are not meant to be limiting in any way.

[0095] Notably, any reference to "one aspect," "an aspect," "an example," "one example," and the like means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, appearances of the phrases "in one aspect," "in an aspect," "in an example," and "in one example" in various places throughout the specification are not necessarily referring to the same aspect. Furthermore, the particular features, structures, or characteristics can be combined in any suitable manner in one or more aspects.

[0096] As used herein, the singular forms "a", "an" and "the" include plural referents unless the context clearly dictates otherwise.

[0097] Any patent application, patent, non-patent publication, or other disclosure material cited herein is incorporated by reference in its entirety to the extent that it is not inconsistent with the present disclosure. Thus, and to the extent necessary, the disclosure as explicitly set forth herein supersedes any contradictory material incorporated by reference. Any material on or areas of the present disclosure that are not expressly incorporated by reference are only incorporated and made part of the present disclosure as of their existence on the date of this document.

[0098] In closing, many benefits have been described which are attributable to embodiments in accordance with the concepts described herein. The foregoing description has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the form of the embodiments to the precise form disclosed. Modifications or variations are possible in light of the above teachings. The one or more forms were chosen and described in order to illustrate principles and practical application to thereby enable one of ordinary skill in the art to utilize the forms in various forms and with various modifications as are suited to the particular use contemplated. Claims appended hereto are intended to define the overall scope of the disclosure.

Claims

1. A method comprising: The network management server receives network policies corresponding to nodes in a cluster pool comprising multiple nodes, wherein the nodes include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer. The network management server implements the network policy to configure a port restriction on the second port of the node, wherein the port restriction causes the load balancer to stop transmitting the transaction data to the first port; After the network management server determines that the network policy will be implemented when preparing for maintenance of the node, the transaction data received at the first port will be processed by the node. as well as After the maintenance at the node is completed, the network management server, based on the network policy status indicator, revoks the network policy to remove the port restriction at the second port.

2. The method of claim 1, wherein the port restriction causes a simulated error at the node, the simulated error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

3. The method of claim 1, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy removes the port restriction at the second port of the node.

4. The method according to claim 1, wherein the network policy status indicator is a Time-to-Live (TTL) value, and wherein the network policy is terminated when the TTL value expires.

5. The method of claim 1, further comprising the network management server monitoring the node's response to at least one of the periodic health check messages within a predetermined period following the revocation of the network policy.

6. The method of claim 5, further comprising the network management server monitoring the node receiving new transaction data at the first port after the revocation of the network policy.

7. The method according to claim 1, further comprising: The network management server pre-configures the backup nodes into the cluster pool; as well as The backup node is initialized by the network management server to receive the transaction data.

8. The method of claim 1, wherein the maintenance includes at least one of installing software patches on the node or repairing hardware faults at the node.

9. A system comprising: Multiple nodes; A cluster pool, which includes the plurality of nodes; Load balancer; A network management server communicatively coupled to the plurality of nodes, wherein the network management server is configured to: Receive network policies corresponding to nodes in a cluster pool, wherein the cluster pool includes multiple nodes, and wherein the nodes in the cluster pool include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from the load balancer. The network policy is implemented to configure a port limit on the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; After it is determined that the network strategy is implemented in preparation for the maintenance of the node, the transaction data received at the first port is processed by the node; as well as After the maintenance at the node is completed based on the network policy status indicator, the network policy is revoked to remove the port restriction at the second port.

10. The system of claim 9, wherein the port restriction causes a simulated error at the node, the simulated error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

11. The system of claim 9, wherein the network policy status indicator is a second network policy corresponding to the second port of the node, and wherein the second network policy removes the port restriction at the second port of the node.

12. The system of claim 9, wherein the network policy status indicator is a Time-to-Live (TTL) value, and wherein the network policy is terminated when the TTL value expires.

13. The system of claim 9, wherein the network management server is further configured to monitor the node's response to at least one of the periodic health check messages within a predetermined period after the revocation of the network policy.

14. The system of claim 13, wherein the network management server is further configured to monitor the node receiving new transaction data at the first port after the network policy is revoked.

15. The system of claim 9, wherein the network management server is further configured to: Pre-provisioning backup nodes to the cluster pool; and Initialize the backup node to receive the transaction data.

16. The system of claim 9, wherein the maintenance includes at least one of installing a software patch on the node or repairing a hardware fault at the node.

17. A non-transient computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including: Receive network policies corresponding to nodes in a cluster pool comprising multiple nodes, wherein the nodes include a first port configured to receive transaction data and a second port configured to receive periodic health check messages from a load balancer. Pre-configure the backup nodes into the cluster pool; Initialize the backup node to receive the transaction data; The network policy is implemented to configure a port limit on the second port of the node, wherein the port limit causes the load balancer to stop transmitting the transaction data to the first port; After determining that the network policy is implemented in preparation for maintenance of the node, the transaction data received at the first port is processed by the node. as well as After the maintenance at the node is completed based on the network policy status indicator, the network policy is revoked to remove the port restriction at the second port.

18. The non-transient computer-readable medium of claim 17, wherein the port limitation causes a simulated error at the node, the simulated error preventing the node from responding to the periodic health check message within a predetermined time period, and wherein the simulated error causes the load balancer to determine that the node is unable to process the transaction data.

19. The non-transient computer-readable medium of claim 17, further configured, when executed by one or more processors, to perform operations including: Receive a second network policy corresponding to the node in the cluster pool, wherein the second network policy removes the port restriction on the second port.

20. The non-transient computer-readable medium of claim 17, wherein preparing for maintenance of the node includes draining container data from the node to the standby node.

Citation Information

Patent Citations

  • Heartbeat detection method and heartbeat detection apparatus

    CN101345663A

  • Heartbeat detection processing method and device

    CN110768853A