Architecture and services provided by multi-cloud infrastructure

Through the multi-cloud control plane framework, the problem of difficulty in interoperability between cloud environments of different cloud service providers is solved, and users can access services in different cloud environments with native experience.

CN120153641APending Publication Date: 2025-06-13ORACLE INT CORP
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202380072701.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-07
Filing Date
2023-10-13
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The cloud environment of existing cloud service providers provides their subscription customers with a closed ecosystem, and customers have difficulty using services provided by another cloud service provider in one cloud environment.

Method used

Using the multi-cloud control plane (MCCP) framework, it receives user requests from different cloud environments through multi-cloud infrastructure, verifies user settings, configures link resource objects, and realizes service interoperability between different cloud environments.

Benefits of technology

It allows users to access and manage services from different cloud service providers with the user experience of a native cloud environment, realizing service interoperability and data plane capabilities across cloud environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120153641A_ABST
    Figure CN120153641A_ABST
Patent Text Reader

Abstract

Techniques are described for providing a multi-cloud control plane (MCCP) in a first cloud infrastructure, including in a first cloud environment provided by a first cloud service provider, that enable services and / or resources provided in the first cloud infrastructure to be used by users of a second cloud environment, where the second cloud environment is different from the first cloud environment. The multi-cloud infrastructure enables a user associated with an account of a second cloud service provider to use a first service of a set of one or more cloud services from the second cloud infrastructure. The multi-cloud infrastructure creates a link between the account of the second cloud service provider and the lease created in the first cloud infrastructure to enable the user to use the first service.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application is a non - provisional application of and claims the benefit of each of the following provisional applications. The entire contents of each of the following provisional applications are hereby incorporated by reference for all purposes:

[0003] (1) U.S. Provisional Application No. 63 / 416,042, filed on October 14, 2022;

[0004] (2) U.S. Provisional Application No. 63 / 464,903, filed on May 8, 2023;

[0005] (3) U.S. Provisional Application No. 63 / 467,241, filed on May 17, 2023;

[0006] (4) U.S. Provisional Application No. 63 / 468,739, filed on May 24, 2023;

[0007] (5) U.S. Provisional Application No. 63 / 469,763, filed on May 30, 2023;

[0008] (6) U.S. Provisional Application No. 63 / 471,573, filed on June 7, 2023; Technical Field

[0009] This disclosure relates to cloud architectures and, more particularly, to techniques for linking two cloud environments provided by different cloud service providers. A user of one cloud environment provided by one service provider can use and manage services provided by another cloud environment provided by another cloud service provider. Background Art

[0010] In the past few years, the adoption rate of cloud services has increased sharply, and this trend will only continue to grow. A variety of different cloud environments are provided by different cloud service providers (CSPs), and each cloud environment provides a set of one or more cloud services. The set of cloud services provided by a cloud environment can include one or more different types of services, including but not limited to software - as - a - service (SaaS) services, infrastructure - as - a - service (IaaS) services, platform - as - a - service (PaaS) services, etc.

[0011] Although there are currently a variety of different cloud environments available, each cloud environment provides a closed ecosystem for its subscribing customers. Thus, customers of a cloud environment are limited to using the services provided by that cloud environment. For customers subscribing to a cloud environment provided by one CSP, there is no easy way to use services provided in a different cloud environment provided by a different CSP via that cloud environment. The embodiments discussed herein address these and other problems. Summary of the Invention

[0012] The present disclosure relates to cloud architectures and, more particularly, to techniques for linking two cloud environments provided by different cloud service providers. A user of one cloud environment provided by one service provider can manage services provided by another cloud environment provided by another cloud service provider. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media storing programs, code, or instructions executable by one or more processors, and the like. Some embodiments may be implemented by using a computer program product that includes a computer program / instructions that, when executed by a processor, cause the processor to execute any of the methods described in the present disclosure.

[0013] Embodiments of the present disclosure provide a Multi-Cloud Control Plane (MCCP) framework that provides the ability to deliver services of a particular cloud network (e.g., Oracle Cloud Infrastructure (OCI)) to users on other clouds (e.g., AWS). The MCCP framework allows users of (one or more) other cloud environments to access services of the cloud environment (e.g., PaaS services, database services, such as autonomous database services, etc.) while providing a user experience as close as possible to the (one or more) native cloud environments of the users. The key value proposition of MCCP is that customers will be able to experience the full data plane capabilities of services in external clouds.

[0014] An embodiment of the present disclosure relates to a method, comprising: receiving, by a multi-cloud infrastructure included in a first cloud environment, a request from a user associated with an account in a second cloud environment, the request requesting the user to register for a service provided by the multi-cloud infrastructure and including metadata information associated with the user; in response to determining, based on the metadata information, that a set of prerequisite resources is not configured for the user in the second cloud environment, transmitting, by the multi-cloud infrastructure, a notification to the user indicating that the set of prerequisite resources is to be configured in the second cloud environment; verifying, by the multi-cloud infrastructure, the set of prerequisite resources and user settings configured in the second cloud environment; and creating, by the multi-cloud infrastructure, a link resource object that includes information linking a lease of the user in the first cloud environment to the account of the user in the second cloud environment, the link resource object enabling the user to utilize the services provided by the multi-cloud infrastructure.

[0015] According to one aspect of the present disclosure, there is provided one or more computer-readable non-transitory media storing computer-executable instructions that, when executed by one or more processors, cause: a multi-cloud infrastructure included in a first cloud environment to receive a request from a user associated with an account in a second cloud environment, the request requesting the user to register for a service provided by the multi-cloud infrastructure and including metadata information associated with the user; in response to determining, based on the metadata information, that a set of prerequisite resources is not configured for the user in the second cloud environment, the multi-cloud infrastructure to transmit a notification to the user, the notification indicating that the set of prerequisite resources is to be configured in the second cloud environment; the multi-cloud infrastructure to verify the set of prerequisite resources and user settings configured in the second cloud environment; and the multi-cloud infrastructure to create a link resource object, the link resource object including information that links a lease of the user in the first cloud environment to the account of the user in the second cloud environment, the link resource object enabling the user to utilize the service provided by the multi-cloud infrastructure.

[0016] According to one aspect of the present disclosure, there is provided a computing device including: one or more processors; and a memory including instructions that, when executed by the one or more processors, cause the computing device to at least: a multi-cloud infrastructure included in a first cloud environment to receive a request from a user associated with an account in a second cloud environment, the request requesting the user to register for a service provided by the multi-cloud infrastructure and including metadata information associated with the user; in response to determining, based on the metadata information, that a set of prerequisite resources is not configured for the user in the second cloud environment, the multi-cloud infrastructure to transmit a notification to the user, the notification indicating that the set of prerequisite resources is to be configured in the second cloud environment; the multi-cloud infrastructure to verify the set of prerequisite resources and user settings configured in the second cloud environment; and the multi-cloud infrastructure to create a link resource object, the link resource object including information that links a lease of the user in the first cloud environment to the account of the user in the second cloud environment, the link resource object enabling the user to utilize the service provided by the multi-cloud infrastructure.

[0017] One aspect of the present disclosure provides a computing device including one or more data processors and a non-transitory computer-readable storage medium containing instructions that, when executed on the one or more data processors, cause the computing device to perform some or all of one or more methods disclosed herein.

[0018] Another aspect of the present disclosure provides a computer program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to perform some or all of one or more methods disclosed herein.

[0019] The foregoing and other features and embodiments will become more apparent when reference is made to the following specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The features, embodiments, and advantages of the present disclosure can be better understood when the following detailed description is read with reference to the accompanying drawings.

[0021] Figure 1 is a high-level diagram of a distributed environment, showing a virtual or overlay cloud network hosted by a cloud service provider infrastructure according to certain embodiments.

[0022] Figure 2 depicts a simplified architecture diagram of physical components in a physical network within a CSPI according to certain embodiments.

[0023] Figure 3 shows an example arrangement within a CSPI according to certain embodiments, where a host machine is connected to multiple network virtualization devices (NVDs).

[0024] Figure 4 depicts the connectivity between a host machine and an NVD according to certain embodiments for providing I / O virtualization to support multi-tenancy.

[0025] Figure 5 depicts a simplified block diagram of a physical network provided by a CSPI according to certain embodiments.

[0026] Figure 6 depicts a simplified high-level diagram of a distributed environment according to certain embodiments, the distributed environment including multiple cloud environments provided by different cloud service providers (CSPs), where a cloud environment includes a specific cloud environment providing specialized infrastructure that enables one or more cloud services provided by the specific cloud environment to be used by customers of other cloud environments.

[0027] Figure 7 depicts an exemplary high-level architecture of a multi-cloud infrastructure interconnecting two different cloud environments according to some embodiments.

[0028] Figure 8 depicts an exemplary swimlane diagram illustrating steps corresponding to a user registration process according to some embodiments.

[0029] Figure 9 depicts an exemplary swimlane diagram illustrating steps corresponding to an inbound authorization process according to some embodiments.

[0030] Figure 10 depicts an exemplary swimlane diagram illustrating steps corresponding to an outbound authorization process according to some embodiments.

[0031] Figure 11A Depicts an exemplary swimlane diagram illustrating steps corresponding to a user login process according to some embodiments.

[0032] Figure 11B Depicts a schematic diagram illustrating the deployment of resources by a multi-cloud infrastructure according to some embodiments.

[0033] Figure 12 Is a block diagram illustrating a mode for implementing an Infrastructure as a Service (IaaS) cloud system according to at least one embodiment.

[0034] Figure 13 Is a block diagram illustrating another mode for implementing an Infrastructure as a Service (IaaS) cloud system according to at least one embodiment.

[0035] Figure 14 Is a block diagram illustrating another mode for implementing an Infrastructure as a Service (IaaS) cloud system according to at least one embodiment.

[0036] Figure 15 Is a block diagram illustrating another mode for implementing an Infrastructure as a Service (IaaS) cloud system according to at least one embodiment.

[0037] Figure 16 Is a block diagram of an example computer system according to at least one embodiment. Detailed Description

[0038] In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of certain embodiments. However, it will be apparent that the various embodiments may be practiced without these specific details. The accompanying drawings and description are not intended to be restrictive. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or superior to other embodiments or designs.

[0039] The present disclosure generally relates to improved cloud architectures and, more particularly, to techniques for linking two cloud environments (each provided by a different cloud service provider (CSP)) such that users of one cloud environment can use services provided by another different cloud environment. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media storing programs, code, or instructions executable by one or more processors, etc. Some embodiments may be implemented by using a computer program product that includes a computer program / instructions that, when executed by a processor, cause the processor to perform any of the methods described in the present disclosure.

[0040] Embodiments of the present disclosure provide a Multi-Cloud Control Plane (MCCP) framework that provides the ability to deliver services of a particular cloud network (e.g., Oracle Cloud Infrastructure (OCI)) to users on other clouds (e.g., in Amazon's AWS). The MCCP framework allows users of (one or more) other cloud environments to access services of the cloud environment (e.g., PaaS services) while providing a user experience as close as possible to the (one or more) native cloud environments of the users. The key value proposition of MCCP is that customers will be able to experience the full data plane capabilities of services in external clouds.

[0041] MCCP enables users of a second cloud infrastructure (e.g., AWS users) to utilize resources (e.g., database resources) provided by a first cloud infrastructure (e.g., OCI) in a manner that is transparent to the users. Specifically, the services provided by the first cloud infrastructure are presented as "native" services in the second cloud infrastructure. This allows customers of the second cloud infrastructure to natively access the services provided by the first cloud infrastructure. As will be described below with reference to Figure 6-1 1, MCCP is a collection of microservices executed in the first cloud infrastructure that exposes the resources of the first cloud infrastructure for use by external cloud users (e.g., users of the second cloud infrastructure). Each microservice acts as an agent that provides communication with the resources provided by the first cloud infrastructure.

[0042] Example of cloud network

[0043] The term cloud service is generally used to refer to services provided by a cloud service provider (CSP) to users or customers on demand (e.g., via a subscription model) using systems and infrastructure (cloud infrastructure) provided by the CSP. Typically, the servers and systems that make up the CSP's infrastructure are separate from the customer's own on-premises servers and systems. Thus, customers can utilize the cloud services provided by the CSP without having to purchase separate hardware and software resources for the services. Cloud services are designed to provide subscribing customers with simple, scalable access to applications and computing resources without the customer having to invest in the infrastructure for providing the services.

[0044] There are several cloud service providers that offer various types of cloud services. There are various different types or models of cloud services, including Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS), etc.

[0045] Customers can subscribe to one or more cloud services provided by a CSP. A customer can be any entity, such as an individual, an organization, a business, etc. When a customer subscribes or registers for a service provided by a CSP, a lease or account is created for that customer. The customer can then access the one or more subscribed cloud resources associated with that account via this account.

[0046] As described above, Infrastructure as a Service (IaaS) is a specific type of cloud computing service. In the IaaS model, the CSP provides the infrastructure (referred to as the Cloud Service Provider Infrastructure or CSPI), which can be used by customers to build their own customizable networks and deploy customer resources. Thus, the customer's resources and network are hosted in a distributed environment by the infrastructure provided by the CSP. This is different from traditional computing, where the customer's resources and network are hosted by the infrastructure provided by the customer.

[0047] The CSPI can include interconnected high-performance computing resources that form a physical network, including various host machines, memory resources, and network resources. This physical network is also referred to as the substrate network or underlying network. The resources in the CSPI can be spread across one or more data centers, which can be geographically dispersed across one or more geographical regions. Virtualization software can be executed by these physical resources to provide a virtualized distributed environment. Virtualization creates an overlay network (also referred to as a software-based network, software-defined network, or virtual network) on top of the physical network. The CSPI physical network provides the underlying foundation for creating one or more overlay or virtual networks on top of the physical network. The physical network (or substrate network or underlying network) includes physical network devices such as physical switches, routers, computers, and host machines. The overlay network is a logical (or virtual) network that runs on top of the physical substrate network. A given physical network can support one or more overlay networks. Overlay networks typically use encapsulation techniques to distinguish traffic belonging to different overlay networks. The virtual or overlay network is also referred to as a Virtual Cloud Network (VCN). The virtual network is implemented using software virtualization techniques (e.g., hypervisors, virtualization functions implemented by Network Virtualization Devices (NVDs) (e.g., smartNICs), Top-of-Rack (TOR) switches, intelligent TORs that implement one or more functions performed by NVDs, and other mechanisms) to create a layer of network abstraction that can run on top of the physical network. The virtual network can take various forms, including peer-to-peer networks, IP networks, etc. The virtual network is typically either a Layer 3 IP network or a Layer 2 VLAN. This method of virtual or overlay networking is often referred to as virtual or overlay Layer 3 networking. Examples of protocols developed for virtual networks include IP-in-IP (or Generic Routing Encapsulation (GRE)), Virtual Extensible LAN (VXLAN - IETF RFC7348), Virtual Private Networks (VPNs) (e.g., MPLS Layer 3 Virtual Private Networks (RFC 4364)), VMware's NSX, GENEVE (Generic Network Virtualization Encapsulation), etc.

[0048] For IaaS, the infrastructure provided by the CSP (CSPI) can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing service provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, the IaaS provider can also supply various services to accompany those infrastructure components (e.g., billing, monitoring, logging, security, load balancing, and clustering, etc.). Thus, since these services can be policy-driven, IaaS users can be able to implement policies to drive load balancing to maintain application availability and performance. CSPI provides the infrastructure and a set of complementary cloud services that enable customers to build and run a wide range of applications and services in a highly available, hosted, distributed environment. CSPI provides high-performance computing resources and capabilities, as well as storage capacity, in a flexible virtual network that can be securely accessed from various networked locations (such as from the customer's on-premises network). When a customer subscribes to or registers for IaaS services provided by the CSP, the tenancy created for that customer is a secure and isolated partition within CSPI where the customer can create, organize, and manage their cloud resources.

[0049] Customers can use the computing, memory, and networking resources provided by CSPI to build their own virtual networks. One or more customer resources or workloads, such as compute instances, can be deployed on these virtual networks. For example, a customer can use the resources provided by CSPI to build one or more customizable and private virtual networks, called virtual cloud networks (VCNs). A customer can deploy one or more customer resources, such as compute instances, on the customer VCN. Compute instances can take the form of virtual machines, bare-metal instances, etc. Thus, CSPI provides the infrastructure and a set of complementary cloud services that enable customers to build and run a wide range of applications and services in a highly available, virtualized, hosted environment. Customers do not manage or control the underlying physical resources provided by CSPI, but can control the operating system, storage devices, and deployed applications; and may have limited control over selected networking components (e.g., firewalls).

[0050] The CSP can provide a console that enables customers and network administrators to configure, access, and manage resources deployed in the cloud using CSPI resources. In certain embodiments, the console provides a web-based user interface that can be used to access and manage CSPI. In certain implementations, the console is a web-based application provided by the CSP.

[0051] CSPI can support single-tenant or multi-tenant architectures. In a single-tenant architecture, software (e.g., applications, databases) or hardware components (e.g., host machines or servers) serve a single customer or tenant. In a multi-tenant architecture, software or hardware components serve multiple customers or tenants. Thus, in a multi-tenant architecture, CSPI resources are shared among multiple customers or tenants. In a multi-tenant scenario, preventive measures are taken and protection measures are implemented in CSPI to ensure that each tenant's data is isolated and invisible to other tenants.

[0052] In a physical network, a network endpoint ("endpoint") refers to a computing device or system that is connected to a physical network and communicates back and forth with the network to which it is connected. Network endpoints in a physical network can be connected to a local area network (LAN), a wide area network (WAN), or other types of physical networks. Examples of traditional endpoints in a physical network include modems, hubs, bridges, switches, routers, and other networking devices, physical computers (or host machines), etc. Each physical device in a physical network has a fixed network address that can be used to communicate with the device. This fixed network address can be a layer 2 address (e.g., MAC address), a fixed layer 3 address (e.g., IP address), etc. In a virtualized environment or virtual network, endpoints can include various virtual endpoints, such as virtual machines hosted by components of the physical network (e.g., hosted by a physical host machine). These endpoints in a virtual network are addressed by overlay addresses, such as an overlay layer 2 address (e.g., overlay MAC address) and an overlay layer 3 address (e.g., overlay IP address). Network overlay enables flexibility by allowing network administrators to move around the overlay addresses associated with network endpoints using software management (e.g., via software implementing a control plane for the virtual network). Accordingly, different from a physical network, in a virtual network, an overlay address (e.g., overlay IP address) can be moved from one endpoint to another using network management software. Since a virtual network is built on top of a physical network, communication between components in a virtual network involves both the virtual network and the underlying physical network. To facilitate such communication, components of CSPI are configured to learn and store mappings that map overlay addresses in the virtual network to actual physical addresses in the underlying network, and vice versa. These mappings are then used to facilitate communication. Customer traffic is encapsulated to facilitate routing in the virtual network.

[0053] Accordingly, a physical address (e.g., a physical IP address) is associated with a component in a physical network, and an overlay address (e.g., an overlay IP address) is associated with an entity in a virtual or overlay network. A physical IP address is an IP address associated with a physical device (e.g., a network device) in a substrate or physical network. For example, each NVD has an associated physical IP address. An overlay IP address is an overlay address associated with an entity in an overlay network, such as an overlay address associated with a compute instance in a customer's Virtual Cloud Network (VCN). Two different customers or tenants (each with their own private VCN) can potentially use the same overlay IP address in their VCNs without knowing about each other. Both physical IP addresses and overlay IP addresses are types of real IP addresses. These addresses are separate from virtual IP addresses. A virtual IP address is typically a single IP address that represents or maps to multiple real IP addresses. A virtual IP address provides a one-to-many mapping between the virtual IP address and multiple real IP addresses. For example, a load balancer can use a VIP to map or represent multiple servers, each with its own real IP address.

[0054] A cloud infrastructure or CSPI is physically hosted in one or more data centers in one or more regions of the world. The CSPI can include components in a physical or substrate network and virtualized components (e.g., virtual networks, compute instances, virtual machines, etc.) located in virtual networks built on top of the physical network components. In some embodiments, the CSPI is organized and hosted in realms, regions, and availability domains. A region is typically a local geographic area that contains one or more data centers. Regions are generally independent of each other and can be far apart, e.g., spanning countries or even continents. For example, a first region can be in Australia, another in Japan, another in India, and so on. CSPI resources are partitioned across regions such that each region has its own independent subset of CSPI resources. Each region can provide a set of core infrastructure services and resources, such as compute resources (e.g., bare metal servers, virtual machines, containers, and associated infrastructure, etc.); storage resources (e.g., block volume storage, file storage, object storage, archival storage); networking resources (e.g., Virtual Cloud Network (VCN), load balancing resources, connection to an on-premises network), database resources; edge networking resources (e.g., DNS); and access management and monitoring resources, etc. Each region generally has multiple paths connecting it to other regions in the realm.

[0055] Generally, an application is deployed in the region where it is most frequently used (i.e., deployed on the infrastructure associated with that region) because using nearby resources is faster than using distant resources. An application can also be deployed in different regions for various reasons, such as redundancy to mitigate the risk of region-wide events (such as large weather systems or earthquakes), to meet different requirements such as legal jurisdictions, tax domains, and other commercial or social standards.

[0056] Data centers within a region can be further organized and subdivided into Availability Domains (ADs). An Availability Domain can correspond to one or more data centers located within the region. A region can consist of one or more Availability Domains. In such a distributed environment, CSPI resources are either region-specific, such as a Virtual Cloud Network (VCN), or Availability Domain-specific, such as a compute instance.

[0057] ADs within a region are isolated from each other, fault-tolerant, and configured such that it is highly unlikely for them to fail simultaneously. This is achieved by ADs not sharing critical infrastructure resources (such as networking, physical cables, cable paths, cable entry points, etc.), such that a failure at one AD within a region is unlikely to affect the availability of other ADs within the same region. ADs within the same region can be connected to each other via a low-latency, high-bandwidth network, which enables providing high-availability connectivity to other networks (e.g., the Internet, a customer's on-premises network, etc.) and building replicated systems across multiple ADs to achieve high availability and disaster recovery. Cloud services use multiple ADs to ensure high availability and prevent resource failures. As the infrastructure provided by an IaaS provider grows, more regions and ADs can be added, as well as additional capacity. Traffic between Availability Domains is typically encrypted.

[0058] In some embodiments, regions are grouped into realms. A realm is a logical collection of regions. Realms are isolated from each other and do not share any data. Regions within the same realm can communicate with each other, but regions in different realms cannot. A customer's lease or account with a CSP exists within a single realm and can be spread across one or more regions belonging to that realm. Typically, when a customer subscribes to an IaaS service, a lease or account for that customer is created in a region (referred to as the "primary" region) specified by the customer within the realm. A customer can extend the customer's lease to one or more other regions within the realm. A customer cannot access regions that are not within the realm where the customer's lease resides.

[0059] IaaS providers can offer multiple realms, each catering to a specific group of customers or users. For example, a business realm can be offered for business customers. As another example, a realm can be provided for a specific country for the customers within that country. As yet another example, a government realm can be provided for a government, etc. For example, a government realm can cater to a specific government and can have a higher security level than a business realm. For example, Oracle Cloud Infrastructure (OCI) currently offers realms for commercial regions and two realms for government cloud regions (e.g., FedRAMP authorized and IL5 authorized).

[0060] In some embodiments, an AD can be subdivided into one or more fault domains. A fault domain is a grouping of infrastructure resources within an AD to provide anti-affinity. Fault domains allow the distribution of compute instances such that these instances do not reside on the same physical hardware within a single AD. This is referred to as anti-affinity. A fault domain refers to a set of hardware components (computers, switches, etc.) that share a single point of failure. The compute pool is logically divided into fault domains. Thus, a hardware failure or a compute hardware maintenance event affecting one fault domain does not affect the instances in other fault domains. Depending on the embodiment, the number of fault domains for each AD can vary. For example, in some embodiments, each AD contains three fault domains. Fault domains act as logical data centers within an AD.

[0061] When a customer subscribes to an IaaS service, resources from the CSPI are provisioned to the customer and associated with the customer's lease. The customer can use these provisioned resources to build private networks and deploy resources on these networks. The customer network hosted by the CSPI in the cloud is referred to as a Virtual Cloud Network (VCN). The customer can use the CSPI resources allocated to the customer to set up one or more Virtual Cloud Networks (VCNs). A VCN is a virtual or software-defined private network. The customer resources deployed in the customer's VCN can include compute instances (e.g., virtual machines, bare metal instances) and other resources. These compute instances can represent various customer workloads, such as applications, load balancers, databases, etc. The compute instances deployed on a VCN can communicate with public accessible endpoints (“public endpoints”) via a public network (such as the Internet), with other instances in the same VCN or other VCNs (e.g., other VCNs of the customer or VCNs that do not belong to the customer), with the customer's on-premises data center or network, and with service endpoints and other types of endpoints.

[0062] A CSP can use a CSPI to provide various services. In some cases, the customers of the CSPI can themselves act like service providers and use CSPI resources to provide services. The service provider can expose a service endpoint, which is characterized by identification information (e.g., IP address, DNS name, and port). The customer's resources (e.g., compute instances) can use a particular service by accessing the service endpoint exposed by the service for that particular service. These service endpoints are generally endpoints that are publicly accessible by users via a public communication network such as the Internet using the public IP address associated with the endpoint. A publicly accessible network endpoint is sometimes also referred to as a public endpoint.

[0063] In some embodiments, a service provider can expose a service via an endpoint for the service (sometimes referred to as a service endpoint). The customers of the service can then use this service endpoint to access the service. In some implementations, the service endpoint provided for a service can be accessed by multiple customers who intend to consume the service. In other implementations, a dedicated service endpoint can be provided for a customer such that only that customer can use the dedicated service endpoint to access the service.

[0064] In some embodiments, when a VCN is created, it is associated with a private overlay Classless Inter-Domain Routing (CIDR) address space, which is a range of private overlay IP addresses assigned to the VCN (e.g., 10.0 / 16). The VCN includes associated subnets, a routing table, and a gateway. The VCN resides within a single region but can span one or more or all of the availability domains within that region. The gateway is a virtual interface configured for the VCN and enables communication of traffic between the VCN and one or more endpoints external to the VCN. One or more different types of gateways can be configured for the VCN to enable communication to and from different types of endpoints.

[0065] A VCN can be subdivided into one or more sub-networks, such as one or more subnets. Thus, a subnet is a configured unit or subdivision that can be created within a VCN. A VCN can have one or more subnets. Each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24) that do not overlap with other subnets in the VCN and represent a subset of the address space within the VCN's address space.

[0066] Each compute instance is associated with a virtual network interface card (VNIC), which enables the compute instance to participate in a subnet of a VCN. A VNIC is a logical representation of a physical network interface card (NIC). Generally speaking, a VNIC is an interface between an entity (e.g., a compute instance, a service) and a virtual network. A VNIC exists within a subnet, has one or more associated IP addresses, and associated security rules or policies. A VNIC is equivalent to a layer 2 port on a switch. A VNIC is attached to a compute instance and a subnet within a VCN. The VNIC associated with a compute instance makes the compute instance part of a subnet of a VCN and enables the compute instance to communicate (e.g., send and receive data packets) with endpoints on the same subnet as the compute instance, with endpoints in different subnets within the VCN, or with endpoints outside the VCN. Therefore, the VNIC associated with a compute instance determines how the compute instance connects to endpoints inside and outside the VCN. When a compute instance is created and added to a subnet within a VCN, a VNIC for the compute instance is created and associated with that compute instance. For a subnet that includes a set of compute instances, the subnet contains VNICs corresponding to the set of compute instances, with each VNIC attached to a compute instance within the set of compute instances.

[0067] A private overlay IP address is assigned to each compute instance via the VNIC associated with the compute instance. This private overlay network IP address is assigned to the VNIC associated with the compute instance when the compute instance is created and is used to route traffic to and from the compute instance. All VNICs within a given subnet use the same routing table, security list, and DHCP options. As described above, each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24), which do not overlap with other subnets in the VCN and represent a subset of the address space within the VCN's address space. For a VNIC on a particular subnet of a VCN, the private overlay IP address assigned to the VNIC is an address from the contiguous range of overlay IP addresses assigned to the subnet.

[0068] In some embodiments, in addition to a private secondary IP address, a compute instance can optionally be assigned additional secondary IP addresses, such as one or more public IP addresses if in a public subnet, for example. These addresses are assigned either on the same VNIC or on multiple VNICs associated with the compute instance. However, each instance has a primary VNIC that is created during instance launch and is associated with the secondary private IP address assigned to the instance - this primary VNIC cannot be deleted. Additional VNICs, called secondary VNICs, can be added to an existing instance in the same availability domain as the primary VNIC. All VNICs are in the same availability domain as the instance. A secondary VNIC can be in a subnet in the same VCN as the primary VNIC, or in a different subnet in the same VCN or a different VCN.

[0069] If a compute instance is in a public subnet, it can optionally be assigned a public IP address. When creating a subnet, the subnet can be designated as either a public subnet or a private subnet. A private subnet means that resources (e.g., compute instances) in the subnet and the associated VNICs cannot have public secondary IP addresses. A public subnet means that resources and associated VNICs in the subnet can have public IP addresses. A customer can specify that a subnet exists in a single availability domain or across multiple availability domains in a region or realm.

[0070] As described above, a VCN can be subdivided into one or more subnets. In some embodiments, a virtual router (VR) configured for the VCN (referred to as the VCN VR or simply the VR) enables communication between subnets of the VCN. For subnets within a VCN, the VR represents the logical gateway for the subnet, which enables the subnet (i.e., compute instances on that subnet) to communicate with endpoints on other subnets within the VCN as well as endpoints outside the VCN. The VCN VR is a logical entity that is configured to route traffic between VNICs in the VCN and virtual gateways ("gateways") associated with the VCN. Below, regarding Figure 1Further describe the gateway. VCN VR is a Layer 3 / IP layer concept. In one embodiment, there is a VCN VR for a VCN, where the VCN VR has a potentially unrestricted number of ports addressed by IP addresses, and each subnet of the VCN has one port. In this way, the VCN VR has a different IP address for each subnet in the VCN to which the VCN VR is attached. The VR is also connected to various gateways configured for the VCN. In some embodiments, a specific overlay IP address within the overlay IP address range for a subnet is reserved for the port of the VCN VR of that subnet. For example, consider a VCN having two subnets with associated address ranges of 10.0 / 16 and 10.1 / 16 respectively. For the first subnet in the VCN with an address range of 10.0 / 16, the addresses within this range are reserved for the ports of the VCN VR of that subnet. In some cases, the first IP address within the range can be reserved for the VCN VR. For example, for a subnet with an overlay IP address range of 10.0 / 16, the IP address 10.0.0.1 can be reserved for the port of the VCN VR of that subnet. For the second subnet in the same VCN with an address range of 10.1 / 16, the VCN VR can have a port for the second subnet with an IP address of 10.1.0.1. The VCN VR has a different IP address for each subnet in the VCN.

[0071] In some other embodiments, each subnet within a VCN can have its own associated VR, which can be addressed by the subnet using a reserved or default IP address associated with the VR. For example, the reserved or default IP address can be the first IP address within the IP address range associated with that subnet. The VNICs within the subnet can use this default or reserved IP address to communicate (e.g., send and receive data packets) with the VR associated with the subnet. In such an embodiment, the VR is the ingress / egress point for the subnet. The VRs associated with subnets within a VCN can communicate with other VRs associated with other subnets within the VCN. The VR can also communicate with the gateways associated with the VCN. The VR functionality of a subnet runs on or is performed by one or more NVDs that perform VNIC functions for the VNICs within the subnet.

[0072] A routing table, security rules, and DHCP options can be configured for the VCN. The routing table is a virtual routing table for the VCN and includes rules for routing traffic from subnets within the VCN to destinations outside the VCN through gateways or specially configured instances. The routing table of the VCN can be customized to control how data packets are forwarded / routed into and out of the VCN. The DHCP options refer to the configuration information automatically provided to an instance when the instance is launched.

[0073] The security rules configured for a VCN represent the overlay firewall rules for the VCN. The security rules can include ingress and egress rules and specify the types of traffic (e.g., based on protocol and port) that are allowed to enter and leave the VCN instance. The customer can choose whether a given rule is stateful or stateless. For example, the customer can allow incoming SSH traffic from anywhere to a set of instances by setting a stateful ingress rule with source CIDR 0.0.0.0 / 0 and destination TCP port 22. The security rules can be implemented using network security groups or security lists. A network security group consists of a set of security rules that apply only to the resources in that group. On the other hand, a security list includes rules that apply to all resources in any subnet that uses that security list. A default security list with default security rules can be provided for the VCN. The DHCP options configured for the VCN provide the configuration information that is automatically provided to the instances in the VCN when they are launched.

[0074] In some embodiments, the configuration information for the VCN is determined and stored by the VCN control plane. For example, the configuration information for the VCN can include information about: the address ranges associated with the VCN, the subnets within the VCN and associated information, one or more VRs associated with the VCN, the compute instances in the VCN and associated VNICs, the NVDs (e.g., VNICs, VRs, gateways) that perform the various virtualized network functions associated with the VCN, the status information for the VCN, and other VCN-related information. In some embodiments, the VCN distribution service publishes the configuration information stored by the VCN control plane or a portion thereof to the NVDs. The distributed information can be used to update the information (e.g., forwarding tables, routing tables, etc.) stored and used by the NVDs to forward data packets to and from the compute instances in the VCN.

[0075] In some embodiments, the creation of the VCN and subnets is handled by the VCN control plane (CP) and the startup of the compute instances is handled by the compute control plane. The compute control plane is responsible for allocating physical resources for the compute instances and then calls the VCN control plane to create VNICs and attach them to the compute instances. The VCN CP also sends the VCN data mapping to the VCN data plane that is configured to perform packet forwarding and routing functions. In some embodiments, the VCN CP provides a distribution service that is responsible for providing updates to the VCN data plane. Examples of the VCN control plane are also depicted in Figure 12 , Figure 13 , Figure 14 and Figure 15 and described below (see reference numerals 1216, 1316, 1416, and 1516).

[0076] Customers can create one or more VCNs using resources hosted by CSPI. Compute instances deployed on the customer VCN can communicate with different endpoints. These endpoints can include endpoints hosted by CSPI and endpoints external to CSPI.

[0077] Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 and Figures 12-16 Various different architectures for implementing cloud-based services using CSPI are depicted in ,

[0077] , Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figures 12-16 and are described below. Figure 1 FIG. Figure 1 is a high-level diagram of a distributed environment 100 showing an overlay or customer VCN hosted by CSPI according to certain embodiments. Figure 1 The distributed environment depicted in FIG. Figure 1 includes multiple components in an overlay network. Figure 1 The distributed environment 100 depicted in FIG. Figure 1 is merely an example and is not intended to unduly limit the scope of the claimed embodiments. Many variations, alternatives, and modifications are possible. For example, in some implementations, Figure 1 the distributed environment depicted in FIG. Figure 1 can have more or fewer systems or components than shown in Figure 1 FIG. Figure 1 , two or more systems can be combined, or can have different system configurations or arrangements.

[0078] As shown in the example depicted in Figure 1 FIG. Figure 1 , the distributed environment 100 includes CSPI 101 that provides services and resources that customers can subscribe to and use to build their virtual cloud network (VCN). In certain embodiments, CSPI 101 provides IaaS services to subscribing customers. Data centers within CSPI 101 can be organized into one or more regions. Figure 1 An example region "Region US" 102 is shown in FIG. Figure 1 . The customer has configured a customer VCN c / o Oracle International Corporation for region 102. The customer can deploy various compute instances on VCN 104, where the compute instances can include virtual machines or bare metal instances. Examples of instances include applications, databases, load balancers, etc.

[0079] In Figure 1 the embodiment depicted in FIG. Figure 1 , the customer VCN 104 includes two subnets, namely, "Subnet-1" and "Subnet-2", each subnet having its own CIDR IP address range. In Figure 1In it, the covered IP address range of Subnet-1 is 10.0 / 16, and the address range of Subnet-2 is 10.1 / 16. The VCN virtual router 105 represents the logical gateway for the VCN, which enables communication between the subnets of VCN104 and other endpoints outside the VCN. The VCN VR 105 is configured to route traffic between the VNICs in VCN 104 and the gateways associated with VCN 104. The VCN VR 105 provides ports for each subnet of VCN 104. For example, VR 105 can provide a port with the IP address 10.0.0.1 for Subnet-1 and a port with the IP address 10.1.0.1 for Subnet-2.

[0080] Multiple computing instances can be deployed on each subnet, where the computing instances can be virtual machine instances and / or bare metal instances. The computing instances in the subnet can be hosted by one or more host machines within CSPI 101. The computing instances participate in the subnet via the VNIC associated with the computing instance. For example, as Figure 1 shown in, the computing instance C1 becomes part of Subnet-1 via the VNIC associated with the computing instance. Similarly, the computing instance C2 becomes part of Subnet-1 via the VNIC associated with C2. In a similar manner, multiple computing instances (which can be virtual machine instances or bare metal instances) can be part of Subnet-1. Via its associated VNIC, each computing instance is assigned a private covered IP address and a MAC address. For example, in Figure 1 shown in, the covered IP address of the computing instance C1 is 10.0.0.2, and the MAC address is M1, while the private covered IP address of the computing instance C2 is 10.0.0.3, and the MAC address is M2. Each computing instance in Subnet-1 (including computing instances C1 and C2) has a default route to the VCN VR 105 using the IP address 10.0.0.1, which is the IP address of the port of the VCN VR 105 for Subnet-1.

[0081] Multiple computing instances can be deployed on Subnet-2, including virtual machine instances and / or bare metal instances. For example, as Figure 1 shown in, the computing instances D1 and D2 become part of Subnet-2 via the VNICs associated with the respective computing instances. In the Figure 1 embodiment shown in, the covered IP address of the computing instance D1 is 10.1.0.2, and the MAC address is MM1, while the private covered IP address of the computing instance D2 is 10.1.0.3, and the MAC address is MM2. Each computing instance in Subnet-2 (including computing instances D1 and D2) has a default route to the VCN VR 105 using the IP address 10.1.0.1, which is the IP address of the port of the VCN VR 105 for Subnet-2.

[0082] The VCN A 104 may also include one or more load balancers. For example, a load balancer may be provided for a subnet and configured to load balance traffic across multiple compute instances on the subnet. A load balancer may also be provided to load balance traffic across subnets in the VCN.

[0083] A particular compute instance deployed on the VCN 104 may communicate with a variety of different endpoints. These endpoints may include endpoints hosted by the CSPI 200 and endpoints external to the CSPI 200. Endpoints hosted by the CSPI 101 may include: endpoints on the same subnet as the particular compute instance (e.g., communication between two compute instances in Subnet-1); endpoints on different subnets but within the same VCN (e.g., communication between a compute instance in Subnet-1 and a compute instance in Subnet-2); endpoints in different VCNs in the same region (e.g., communication between a compute instance in Subnet-1 and an endpoint in a VCN in the same Region 106 or 110, communication between a compute instance in Subnet-1 and an endpoint in a service outlet 110 in the same region); or endpoints in VCNs in different regions (e.g., communication between a compute instance in Subnet-1 and an endpoint in a VCN in a different Region 108). Compute instances in subnets hosted by the CSPI 101 may also communicate with endpoints not hosted by the CSPI 101 (i.e., external to the CSPI 101). These external endpoints include endpoints in the customer's on-premises network 116, endpoints in other remote cloud-hosted networks 118, public endpoints 114 accessible via a public network such as the Internet, and other endpoints.

[0084] Use the VNICs associated with the source compute instance and the destination compute instance to facilitate communication between compute instances on the same subnet. For example, a compute instance C1 in subnet-1 may want to send a packet to a compute instance C2 in subnet-1. For a packet originating from a source compute instance and destined for another compute instance in the same subnet, the packet is first processed by the VNIC associated with the source compute instance. The processing performed by the VNIC associated with the source compute instance can include determining the destination information of the packet from the packet header, identifying any policies (e.g., security lists) configured for the VNIC associated with the source compute instance, determining the next hop for the packet, performing any packet encapsulation / decapsulation functions as needed, and then forwarding / routing the packet to the next hop with the aim of facilitating the communication of the packet to its intended destination. When the destination compute instance is in the same subnet as the source compute instance, the VNIC associated with the source compute instance is configured to identify the VNIC associated with the destination compute instance and forward the packet to that VNIC for processing. The VNIC associated with the destination compute instance then executes and forwards the packet to the destination compute instance.

[0085] For a packet to be transmitted from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, communication is facilitated through the VNICs associated with the source and destination compute instances and the VCN VR. For example, if Figure 1 compute instance C1 in subnet-1 in wants to send a packet to compute instance D1 in subnet-2, then the packet is first processed by the VNIC associated with compute instance C1. The VNIC associated with compute instance C1 is configured to route the packet to VCN VR 105 using the default route or port 10.0.0.1 of the VCN VR. VCN VR 105 is configured to route the packet to subnet-2 using port 10.1.0.1. Then, the VNIC associated with D1 receives and processes the packet and the VNIC forwards the packet to compute instance D1.

[0086] For packets to be sent from a compute instance in VCN 104 to an endpoint outside VCN 104, communication is facilitated by the VNIC associated with the source compute instance, the VCN VR 105, and the gateway associated with VCN 104. One or more types of gateways can be associated with VCN 104. A gateway is an interface between the VCN and another endpoint, where that other endpoint is outside the VCN. A gateway is a layer 3 / IP layer concept and enables the VCN to communicate with endpoints outside the VCN. Thus, the gateway facilitates the flow of traffic between the VCN and other VCNs or networks. Various different types of gateways can be configured for a VCN to facilitate different types of communication with different types of endpoints. Depending on the gateway, communication can occur over a public network (e.g., the Internet) or over a private network. Various communication protocols can be used for these communications.

[0087] For example, compute instance C1 may want to communicate with an endpoint outside VCN 104. The packet can first be processed by the VNIC associated with the source compute instance C1. The VNIC processing determines that the destination of the packet is outside C1's subnet-1. The VNIC associated with C1 can forward the packet to the VCN VR 105 for VCN 104. The VCN VR 105 then processes the packet and, as part of the processing, determines a specific gateway associated with VCN 104 as the next hop for the packet based on the destination of the packet. The VCN VR 105 can then forward the packet to the specific identified gateway. For example, if the destination is an endpoint within the customer's on-premises network, then the packet can be forwarded by the VCN VR 105 to the Dynamic Routing Gateway (DRG) gateway 122 configured for VCN 104. The packet can then be forwarded from the gateway to the next hop to facilitate the delivery of the packet to its final intended destination.

[0088] Various different types of gateways can be configured for a VCN. Examples of gateways that can be configured for a VCN are depicted in Figure 1 and described below. Examples of gateways associated with a VCN are also depicted in Figure 12 、 Figure 13 、 Figure 14 and Figure 15 (e.g., gateways referenced by reference numerals 1234, 1236, 1238, 1334, 1336, 1338, 1434, 1436, 1438, 1534, 1536, and 1538) and are described as follows. As Figure 1As shown in the embodiments depicted, a Dynamic Routing Gateway (DRG) 122 can be added to or associated with a customer VCN 104 and provide a path for private network traffic communication between the customer VCN 104 and another endpoint, where the other endpoint can be the customer's on-premises network 116, a VCN 108 in a different region of the CSPI 101, or another remote cloud network 118 not hosted by the CSPI 101. The customer on-premises network 116 can be a customer network or customer data center built using the customer's resources. Access to the customer on-premises network 116 is generally very restricted. For customers who have both a customer on-premises network 116 and one or more VCNs 104 deployed or hosted by the CSPI 101 in the cloud, the customer may want their on-premises network 116 and their cloud-based VCN 104 to be able to communicate with each other. This enables the customer to build an extended hybrid environment that includes the customer's VCN 104 hosted by the CSPI 101 and their on-premises network 116. The DRG 122 enables this communication. To enable such communication, a communication channel 124 is set up, where one endpoint of the channel is in the customer on-premises network 116 and the other endpoint is in the CSPI 101 and connected to the customer VCN 104. The communication channel 124 can be through a public communication network (such as the Internet) or a private communication network. Various different communication protocols can be used, such as IPsec VPN technology over a public communication network (such as the Internet), Oracle's FastConnect technology that uses a private network instead of a public network, etc. The device or equipment that forms one endpoint of the communication channel 124 in the customer on-premises network 116 is referred to as customer-premises equipment (CPE), such as Figure 1 the CPE 126 depicted in

[0089] In some embodiments, a Remote Peering Connection (RPC) can be added to the DRG, which allows the customer to peer one VCN with another VCN in a different region. Using this RPC, the customer VCN 104 can be connected to the VCN 108 in another region using the DRG 122. The DRG 122 can also be used to communicate with other remote cloud networks 118 not hosted by the CSPI 101 (such as the Microsoft Azure cloud, the Amazon AWS cloud, etc.).

[0090] As Figure 1As shown, an Internet Gateway (IGW) 120 can be configured for the customer VCN 104, which enables compute instances on the VCN 104 to communicate with public endpoints 114 accessible via a public network such as the Internet. The IGW 120 is a gateway that connects the VCN to a public network such as the Internet. The IGW 120 enables public subnets within the VCN (such as VCN 104), where resources in the public subnets have public overlay IP addresses, to directly access public endpoints 112 on the public network 114 (such as the Internet). Using the IGW 120, connections can be initiated from subnets within the VCN 104 or from the Internet.

[0091] A Network Address Translation (NAT) gateway 128 can be configured for the customer's VCN 104 and enables cloud resources in the customer's VCN that do not have dedicated public overlay IP addresses to access the Internet and do so without exposing those resources to direct incoming Internet connections (e.g., L4-L7 connections). This enables private subnets within the VCN (such as private subnet-1 in VCN 104) to privately access public endpoints on the Internet. In a NAT gateway, connections can only be initiated from the private subnet to the public Internet and not from the Internet to the private subnet.

[0092] In some embodiments, a Service Gateway (SGW) 126 can be configured for the customer VCN 104 and provides a path for private network traffic between the VCN 104 and service endpoints supported in the service network 110. In some embodiments, the service network 110 can be provided by a CSP and can provide various services. An example of such a service network is Oracle's service network, which provides various services available to customers. For example, compute instances (such as database systems) in the private subnets of the customer VCN 104 can back up data to a service endpoint (such as an Object Storage device) without a public IP address or access to the Internet. In some embodiments, a VCN can have only one SGW, and connections can only be initiated from subnets within the VCN and not from the service network 110. If a VCN is peered with another, resources in the other VCN generally cannot access the SGW. Resources in an on-premises network connected to the VCN using FastConnect or VPN Connect can also use the service gateway configured for that VCN.

[0093] In some embodiments, the SGW 126 uses the concept of a service Classless Inter-Domain Routing (CIDR) label, which is a string representing all the regional public IP address ranges for a service or group of services of interest. Customers use the service CIDR label when they configure the SGW and associated routing rules to control traffic to the service. If the public IP address of the service changes in the future, then customers can optionally use it when configuring security rules without having to adjust them.

[0094] The Local Peering Gateway (LPG) 132 is a gateway that can be added to a customer VCN 104 and enables the VCN 104 to peer with another VCN in the same region. Peering means that the VCNs communicate using private IP addresses and traffic does not have to cross a public network (such as the Internet) or be routed through the customer's on-premises network 116. In a preferred embodiment, the VCN has a separate LPG for each peer it establishes. Local peering or VCN peering is a common practice for establishing network connectivity between different applications or infrastructure management functions.

[0095] Service providers (such as providers of services in the service network 110) can provide access to services using different access models. According to the public access model, the service can be exposed as a public endpoint that can be publicly accessed by compute instances in the customer VCN via a public network (such as the Internet), and / or can be privately accessed via the SGW 126. According to a specific private access model, the service can be accessed as a private IP endpoint in a private subnet in the customer's VCN. This is referred to as Private Endpoint (PE) access and enables the service provider to expose their service as an instance in the customer's private network. The private endpoint resource represents the service within the customer's VCN. Each PE appears as a VNIC (referred to as a PE-VNIC, with one or more private IPs) in a subnet selected by the customer in the customer's VCN. Thus, the PE provides a way to present the service in a private customer VCN subnet using a VNIC. Since the endpoint is exposed as a VNIC, all the features associated with the VNIC (such as routing rules, security lists, etc.) can now be used for the PE VNIC.

[0096] Service providers can register their services to enable access through the PE. The provider can associate policies with the service, which limit the visibility of the service to the customer tenancy. The provider can register multiple services under a single Virtual IP Address (VIP), especially for multi-tenant services. There can be multiple such private endpoints (in multiple VCNs) representing the same service.

[0097] Compute instances in the private subnet can then access the service using the private IP address of the PE VNIC or the service DNS name. Compute instances in the customer VCN can access the service by sending traffic to the private IP address of the PE in the customer VCN. The Private Access Gateway (PAGW) 130 is a gateway resource that can be attached to a service provider VCN (e.g., a VCN in the service network 110), which serves as the ingress / egress point for all traffic to / from the private endpoints of the customer subnets. The PAGW 130 enables the provider to scale the number of PE connections without utilizing its internal IP address resources. The provider only needs to configure one PAGW for any number of services registered in a single VCN. The provider can represent a service as private endpoints in multiple VCNs of one or more customers. From the customer's perspective, the PE VNIC is not attached to the customer's instance but appears to be attached to the service the customer wishes to interact with. Traffic destined for the private endpoint is routed to the service via the PAGW 130. These are referred to as customer-to-service private connections (C2S connections).

[0098] By allowing traffic to flow through the FastConnect / IPsec link and the private endpoints in the customer VCN, the PE concept can also be used to extend private access for services to the customer's on-premises networks and data centers. By allowing traffic to flow between the LPG 132 and the PE in the customer's VCN, private access to the service can also be extended to the customer's peered VCNs.

[0099] The customer can control routing within the VCN at the subnet level, so the customer can specify which subnets in the customer's VCN (such as VCN 104) use each gateway. The routing table of the VCN is used to decide whether to allow traffic to leave the VCN through a specific gateway. For example, in a particular instance, the routing table for the public subnet within the customer VCN 104 can send non-local traffic through the IGW 120. The routing table for the private subnet within the same customer VCN 104 can send traffic destined for the CSP service through the SGW 126. All remaining traffic can be sent via the NAT gateway 128. The routing table only controls traffic flowing out of the VCN.

[0100] The security list associated with the VCN is used to control the traffic entering the VCN via the gateway through inbound connections. All resources in a subnet use the same route table and security list. The security list can be used to control specific types of traffic allowed to and from instances in the subnet of the VCN. Security list rules can include ingress (inbound) and egress (outbound) rules. For example, an ingress rule can specify the allowed source address range, while an egress rule can specify the allowed destination address range. Security rules can specify a particular protocol (e.g., TCP, ICMP), a particular port (e.g., 22 for SSH, 3389 for Windows RDP), etc. In some embodiments, the operating system of an instance can enforce its own firewall rules that comply with the security list rules. The rules can be stateful (e.g., tracking connections and automatically allowing responses without an explicit security list rule for the response traffic) or stateless.

[0101] Access from a customer VCN (i.e., through resources or compute instances deployed on VCN 104) can be classified as public access, private access, or dedicated access. Public access refers to an access model that uses a public IP address or NAT to access public endpoints. Private access enables customer workloads in VCN 104 with private IP addresses (e.g., resources in a private subnet) to access services without traversing a public network such as the Internet. In some embodiments, CSPI 101 enables customer VCN workloads with private IP addresses to access the public service endpoints of services using a service gateway. Thus, the service gateway provides a private access model by establishing a virtual link between the customer's VCN and the public endpoints of services residing outside the customer's private network.

[0102] In addition, CSPI can provide dedicated public access using technologies such as FastConnect public peering, where on-premises customer instances can use FastConnect connections to access one or more services in the customer VCN without traversing a public network such as the Internet. CSPI can also provide dedicated private access using FastConnect private peering, where on-premises customer instances with private IP addresses can use FastConnect connections to access the customer's VCN workloads. FastConnect is a network connectivity alternative to using the public Internet to connect a customer's on-premises network to CSPI and its services. Compared to Internet-based connections, FastConnect provides a simple, flexible, and cost-effective way to create dedicated and private connections with higher bandwidth options and a more reliable and consistent network experience.

[0103] Figure 1The above and the accompanying description describe various virtualized components in an example virtual network. As described above, the virtual network is built on an underlying physical or substrate network. Figure 2 FIG. 2 depicts a simplified architecture diagram of physical components in a physical network within a CSPI 200 that provides the underlying for a virtual network, according to certain embodiments. As shown, the CSPI 200 provides a distributed environment that includes components and resources (e.g., computing, memory, and network resources) provided by a cloud service provider (CSP). These components and resources are used to provide cloud services (e.g., IaaS services) to subscribing customers (i.e., customers who have subscribed to one or more services provided by the CSP). Based on the services subscribed to by the customer, a subset of the resources of the CSPI 200 (e.g., computing, memory, and network resources) are provisioned for the customer. The customer can then use the physical computing, memory, and networking resources provided by the CSPI 200 to build their own cloud-based (i.e., CSPI-hosted) customizable and private virtual network. As previously indicated, these customer networks are referred to as virtual cloud networks (VCNs). The customer can deploy one or more customer resources, such as computing instances, on these customer VCNs. The computing instances can be in the form of virtual machines, bare-metal instances, etc. The CSPI 200 provides the infrastructure and a set of complementary cloud services that enable the customer to build and run a wide range of applications and services in a highly available hosted environment.

[0104] In Figure 2 the example embodiment depicted in FIG. 2, the physical components of the CSPI 200 include one or more physical host machines or physical servers (e.g., 202, 206, 208), network virtualization devices (NVDs) (e.g., 210, 212), top-of-rack (TOR) switches (e.g., 214, 216), and a physical network (e.g., 218), as well as switches in the physical network 218. The physical host machines or servers can host and execute various computing instances participating in one or more subnets of the VCN. The computing instances can include virtual machine instances and bare-metal instances. For example, Figure 1 the various computing instances depicted in FIG. 2 can be hosted by Figure 2 the physical host machines depicted in FIG. 2. The virtual machine computing instances in the VCN can be executed by one host machine or multiple different host machines. The physical host machines can also host virtual host machines, container-based hosts, functions, etc. Figure 1 the VNICs and VCN VRs depicted in FIG. 2 can be executed by Figure 2 the NVDs depicted in FIG. 2. Figure 1 the gateways depicted in FIG. 2 can be executed by Figure 2 the host machines and / or NVDs described in FIG. 2.

[0105] A host machine or server can execute a hypervisor (also known as a virtual machine monitor or VMM) that creates and enables a virtualized environment on the host machine. Virtualization or the virtualized environment facilitates cloud-based computing. One or more computing instances can be created, executed, and managed on the host machine by the hypervisor on the host machine. The hypervisor on the host machine enables the physical computing resources of the host machine (e.g., computing, memory, and network resources) to be shared among various computing instances executed by the host machine.

[0106] For example, as Figure 2 depicted, host machines 202 and 208 execute hypervisors 260 and 266 respectively. These hypervisors can be implemented using software, firmware, hardware, or a combination thereof. Generally, a hypervisor is a process or software layer that is located above the operating system (OS) of the host machine, and the OS in turn executes on the hardware processor of the host machine. The hypervisor provides a virtualized environment by enabling the physical computing resources of the host machine (e.g., processing resources such as processors / cores, memory resources, network resources) to be shared among various virtual machine computing instances executed by the host machine. For example, in Figure 2 , hypervisor 260 can be located above the OS of host machine 202 and enable the computing resources of host machine 202 (e.g., processing, memory, and network resources) to be shared among computing instances (e.g., virtual machines) executed by host machine 202. A virtual machine can have its own operating system (referred to as a guest operating system), which can be the same as or different from the OS of the host machine. The operating system of a virtual machine executed by a host machine can be the same as or different from the operating system of another virtual machine executed by the same host machine. Thus, the hypervisor enables multiple operating systems to be executed simultaneously while sharing the same computing resources of the host machine. Figure 2 The host machines depicted in

[0107] can have the same or different types of hypervisors. Figure 2 A computing instance can be a virtual machine instance or a bare-metal instance. In

[0108] In some cases, an entire host machine can be supplied to a single customer, and one or more compute instances (either virtual machines or bare metal instances) hosted by that host machine all belong to the same customer. In other cases, the host machine can be shared among multiple customers (i.e., multiple tenants). In such a multi-tenant scenario, the host machine can host virtual machine compute instances belonging to different customers. These compute instances can be members of different VCNs of different customers. In some embodiments, bare metal compute instances are hosted by bare metal servers without a hypervisor. When a bare metal compute instance is provisioned, a single customer or tenant maintains control over the physical CPUs, memory, and network interfaces of the host machine hosting the bare metal instance, and the host machine is not shared with other customers or tenants.

[0109] As previously described, each compute instance that is part of a VCN is associated with a VNIC that enables the compute instance to be a member of a subnet of the VCN. The VNIC associated with a compute instance facilitates the communication of data packets or frames to and from the compute instance. The VNIC is associated with the compute instance when the compute instance is created. In some embodiments, for a compute instance executed by a host machine, the VNIC associated with the compute instance is executed by an NVD connected to the host machine. For example, in Figure 2 the embodiment depicted in, host machine 202 executes virtual machine compute instance 268 associated with VNIC 276, and VNIC 276 is executed by NVD 210 connected to host machine 202. As another example, bare metal instance 272 hosted by host machine 206 is associated with VNIC 280 executed by NVD 212 connected to host machine 206. As yet another example, VNIC 284 is associated with compute instance 274 executed by host machine 208, and VNIC 284 is executed by NVD 212 connected to host machine 208.

[0110] For a compute instance hosted by a host machine, the NVD connected to the host machine also executes the VCN VR corresponding to the VCN of which the compute instance is a member. For example, in Figure 2 the embodiment depicted in, NVD 210 executes VCN VR 277 corresponding to the VCN of which compute instance 268 is a member. NVD 212 can also execute one or more VCN VRs 283 corresponding to the VCNs corresponding to the compute instances hosted by host machines 206 and 208.

[0111] The host machine may include one or more network interface cards (NICs) that enable the host machine to connect to other devices. The NICs on the host machine may provide one or more ports (or interfaces) that enable the host machine to communicate and connect to another device. For example, the host machine may connect to an NVD using one or more ports (or interfaces) provided on the host machine and on the NVD. The host machine may also connect to other devices, such as another host machine.

[0112] For example, in Figure 2 , the host machine 202 connects to the NVD 210 using the link 220, which extends between the port 234 provided by the NIC 232 of the host machine 202 and the port 236 of the NVD 210. The host machine 206 connects to the NVD 212 using the link 224, which extends between the port 246 provided by the NIC 244 of the host machine 206 and the port 248 of the NVD 212. The host machine 208 connects to the NVD 212 using the link 226, which extends between the port 252 provided by the NIC 250 of the host machine 208 and the port 254 of the NVD 212.

[0113] The NVDs are in turn connected to top-of-rack (TOR) switches via communication links, and these switches are connected to the physical network 218 (also known as the switch fabric). In some embodiments, the links between the host machines and the NVDs and between the NVDs and the TOR switches are Ethernet links. For example, in Figure 2 , the NVDs 210 and 212 connect to the TOR switches 214 and 216 using the links 228 and 230, respectively. In some embodiments, the links 220, 224, 226, 228, and 230 are Ethernet links. The set of host machines and NVDs connected to the TOR is sometimes referred to as a rack.

[0114] The physical network 218 provides a communication fabric that enables the TOR switches to communicate with each other. The physical network 218 can be a multi-layer network. In some implementations, the physical network 218 is a multi-layer Clos network of switches, where the TOR switches 214 and 216 represent the leaf-level nodes of the multi-layer and multi-node physical switching network 218. Different Clos network configurations are possible, including but not limited to 2-layer networks, 3-layer networks, 4-layer networks, 5-layer networks, and general "n"-layer networks. Examples of Clos networks are depicted in Figure 5 and described below.

[0115] There can be various different connection configurations between the host machines and the NVDs, such as one-to-one configurations, many-to-one configurations, one-to-many configurations, etc. In a one-to-one configuration implementation, each host machine is connected to its own separate NVD. For example, inFigure 2 In this case, the host machine 202 is connected to the NVD 210 via the NIC 232 of the host machine 202. In a multi-to-one configuration, multiple host machines are connected to one NVD. For example, in Figure 2 this case, the host machines 206 and 208 are respectively connected to the same NVD 212 via the NICs 244 and 250.

[0116] In a one-to-many configuration, one host machine is connected to multiple NVDs. Figure 3 An example within the CSPI 300 is shown where a host machine is connected to multiple NVDs. As Figure 3 shown, the host machine 302 includes a network interface card (NIC) 304, which includes multiple ports 306 and 308. The host machine 300 is connected to the first NVD 310 via the port 306 and the link 320, and is connected to the second NVD 312 via the port 308 and the link 322. The ports 306 and 308 can be Ethernet ports and the links 320 and 322 between the host machine 302 and the NVDs 310 and 312 can be Ethernet links. The NVD 310 is further connected to the first TOR switch 314 and the NVD 312 is connected to the second TOR switch 316. The links between the NVDs 310 and 312 and the TOR switches 314 and 316 can be Ethernet links. The TOR switches 314 and 316 represent layer 0 switching devices in the multi-layer physical network 318.

[0117] Figure 3 The arrangement depicted in this case provides two separate physical network paths from the physical switch network 318 to the host machine 302: the first path passes through the TOR switch 314 to the NVD 310 and then to the host machine 302, and the second path passes through the TOR switch 316 to the NVD 312 and then to the host machine 302. The separate paths provide enhanced availability (referred to as high availability) for the host machine 302. If there is a problem with a path (e.g., a link in one of the paths is broken) or a device (e.g., a particular NVD is not operating), then the other path can be used for communication with the host machine 302.

[0118] In Figure 3 the configuration depicted in this case, the host machine uses two different ports provided by the NIC of the host machine to connect to two different NVDs. In other embodiments, the host machine can include multiple NICs that enable the host machine to connect to multiple NVDs.

[0119] Referring back to Figure 2, an NVD is a physical device or component that performs one or more network and / or storage virtualization functions. An NVD can be any device with one or more processing units (e.g., CPU, network processing unit (NPU), FPGA, packet processing pipeline, etc.), memory (including caches), and ports. Various virtualization functions can be performed by software / firmware executed by one or more processing units of the NVD.

[0120] The NVD can be implemented in various different forms. For example, in some embodiments, the NVD is implemented as an interface card called a smartNIC or a smart NIC with an on-board embedded processor. A smartNIC is a device independent of the NIC on the host machine. In Figure 2 , the NVDs 210 and 212 can be implemented as smartNICs respectively connected to the host machine 202 and the host machines 206 and 208.

[0121] However, the smartNIC is just one example of an NVD implementation. Various other implementations are possible. For example, in some other embodiments, the NVD or one or more functions performed by the NVD can be incorporated into or performed by one or more host machines, one or more TOR switches, and other components of the CSPI 200. For example, the NVD can be implemented in a host machine, where the functions performed by the NVD are performed by the host machine. As another example, the NVD can be part of a TOR switch, or the TOR switch can be configured to perform the functions performed by the NVD, which enables the TOR switch to perform various complex packet conversions for a public cloud. A TOR that performs the functions of an NVD is sometimes referred to as a smart TOR. In other embodiments that provide virtual machine (VM) instances rather than bare metal (BM) instances to customers, the functions performed by the NVD can be implemented inside the hypervisor of the host machine. In some other embodiments, some of the functions of the NVD can be offloaded to a centralized service running on a group of host machines.

[0122] In certain embodiments, such as when implemented as a smartNIC as shown in Figure 2 , the NVD can include multiple physical ports that enable it to connect to one or more host machines and one or more TOR switches. The ports on the NVD can be classified as host-facing ports (also referred to as "south ports") or network-facing or TOR-facing ports (also referred to as "north ports"). The host-facing ports of the NVD are the ports used to connect the NVD to the host machine. Figure 2 Examples of the host-facing ports inFigure 2 Examples of network-facing ports include port 256 on NVD 210 and port 258 on NVD 212. As Figure 2 shown, NVD 210 is connected to TOR switch 214 using link 228 that extends from port 256 of NVD 210 to TOR switch 214. Similarly, NVD 212 is connected to TOR switch 216 using link 230 that extends from port 258 of NVD 212 to TOR switch 216.

[0123] The NVD receives packets and frames from the host machine via the host-facing port (e.g., packets and frames generated by a compute instance hosted by the host machine), and after performing necessary packet processing, can forward the packets and frames to the TOR switch via the network-facing port of the NVD. The NVD can receive packets and frames from the TOR switch via the network-facing port of the NVD, and after performing necessary packet processing, can forward the packets and frames to the host machine via the host-facing port of the NVD.

[0124] In some embodiments, there can be multiple ports and associated links between the NVD and the TOR switch. These ports and links can be aggregated to form an aggregate group of multiple ports or links (referred to as a LAG). Link aggregation allows multiple physical links between two endpoints (e.g., between the NVD and the TOR switch) to be treated as a single logical link. All physical links within a given LAG can operate at the same speed in full-duplex mode. LAG helps increase the bandwidth and reliability of the connection between two endpoints. If one of the physical links within the LAG fails, then traffic will be dynamically and transparently re-assigned to one of the other physical links within the LAG. The aggregated physical links deliver higher bandwidth than each individual link. The multiple ports associated with the LAG are treated as a single logical port. Traffic can be load-balanced across the multiple physical links of the LAG. One or more LAGs can be configured between two endpoints. These two endpoints can be located between the NVD and the TOR switch, between the host machine and the NVD, and so on.

[0125] The NVD implements or executes network virtualization functions. These functions are executed by software / firmware executed by the NVD. Examples of network virtualization functions include, but are not limited to: packet encapsulation and decapsulation functions; functions for creating VCN networks; functions for implementing network policies, such as VCN security list (firewall) functionality; functions for facilitating packet routing and forwarding to and from compute instances in the VCN; and so on. In some embodiments, after receiving a packet, the NVD is configured to execute a packet processing pipeline to process the packet and determine how to forward or route the packet. As part of this packet processing pipeline, the NVD can execute one or more virtual functions associated with the overlay network, such as executing a VNIC associated with a compute instance in the VCN, executing a virtual router (VR) associated with the VCN, encapsulating and decapsulating packets to facilitate forwarding or routing in the virtual network, executing certain gateways (e.g., local peer gateways), implementing security lists, network security groups, network address translation (NAT) functionality (e.g., translating public IPs to private IPs on a per-host basis), throttling functions, and other functions.

[0126] In some embodiments, the packet processing data path in the NVD can include multiple packet pipelines, each pipeline consisting of a series of packet transformation stages. In some implementations, after receiving a packet, the packet is parsed and classified into a single pipeline. The packet is then processed linearly, stage by stage, until the packet is either discarded or sent out through an interface of the NVD. These stages provide basic functional packet processing building blocks (e.g., validating headers, enforcing throttling, inserting new layer 2 headers, enforcing L4 firewalls, VCN encapsulation / decapsulation, etc.) so that new pipelines can be built by combining existing stages, and new functionality can be added by creating new stages and inserting them into existing pipelines.

[0127] The NVD can execute control plane and data plane functions corresponding to the control plane and data plane of the VCN. Examples of the VCN control plane are also depicted in Figure 12 , Figure 13 , Figure 14 and Figure 15 (see reference numerals 1216, 1316, 1416, and 1516) and are described below. Examples of the VCN data plane are in Figure 12 , Figure 13 , Figure 14 and Figure 15Depicted (see reference numerals 1218, 1318, 1418, and 1518) and described below. Control plane functions include functions for configuring the network for how control data is forwarded (e.g., setting up routes and routing tables, configuring VNICs, etc.). In some embodiments, a VCN control plane is provided that centrally computes all overlay-to-substrate mappings and publishes them to the NVD and virtual network edge devices (such as various gateways, such as DRG, SGW, IGW, etc.). Firewall rules can also be published using the same mechanism. In some embodiments, the NVD only obtains the mappings relevant to that NVD. Data plane functions include functions for actually routing / forwarding data packets based on the configuration set using the control plane. The VCN data plane is implemented by encapsulating the customer's network packets before they pass through the substrate network. The encapsulation / de-encapsulation functionality is implemented on the NVD. In some embodiments, the NVD is configured to intercept all network packets going in and out of the host machine and perform network virtualization functions.

[0128] As indicated above, the NVD performs various virtualization functions, including VNIC and VCN VR. The NVD can perform VNICs associated with computing instances hosted by one or more host machines connected to the VNIC. For example, as Figure 2 depicted in, the NVD 210 performs the functionality of the VNIC 276 associated with the computing instance 268 hosted by the host machine 202 connected to the NVD 210. As another example, the NVD 212 performs the VNIC 280 associated with the bare-metal computing instance 272 hosted by the host machine 206 and performs the VNIC 284 associated with the computing instance 274 hosted by the host machine 208. The host machine can host computing instances belonging to different VCNs (belonging to different customers), and the NVDs connected to the host machine can perform the VNICs corresponding to the computing instances (i.e., perform VNIC-related functionality).

[0129] The NVD also performs the VCN virtual router corresponding to the VCN of the computing instance. For example, in the Figure 2 embodiment depicted in, the NVD 210 performs the VCN VR 277 corresponding to the VCN to which the computing instance 268 belongs. The NVD 212 performs one or more VCN VRs 283 corresponding to one or more VCNs to which the computing instances hosted by the host machines 206 and 208 belong. In some embodiments, the VCN VR corresponding to that VCN is performed by all NVDs connected to the host machine hosting at least one computing instance belonging to that VCN. If the host machine hosts computing instances belonging to different VCNs, then the NVDs connected to that host machine can perform the VCN VRs corresponding to those different VCNs.

[0130] In addition to VNICs and VCN VRs, an NVD can execute various software (e.g., daemons) and includes one or more hardware components that facilitate the various network virtualization functions performed by the NVD. For simplicity, these various components are grouped together as the Figure 2 "packet processing components" shown in. For example, NVD 210 includes packet processing component 286 and NVD 212 includes packet processing component 288. For example, a packet processing component for an NVD can include a packet processor that is configured to interact with the ports and hardware interfaces of the NVD to monitor all packets received by and transmitted using the NVD and store network information. The network information can include, for example, network flow information identifying different network flows handled by the NVD and per-flow information (e.g., per-flow statistics) for each flow. In some embodiments, the network flow information can be stored on a per-VNIC basis. The packet processor can perform per-packet manipulation and implement stateful NAT and L4 firewall (FW). As another example, a packet processing component can include a replication agent configured to copy information stored by the NVD to one or more different replication target repositories. As yet another example, a packet processing component can include a logging agent configured to perform the logging function of the NVD. The packet processing component can also include software for monitoring the performance and health of the NVD and also potentially the state and health of other components connected to the NVD.

[0131] Figure 1 Shows the components of an example virtual or overlay network, including a VCN, subnets within the VCN, compute instances deployed on the subnets, VNICs associated with the compute instances, a VR for the VCN, and a set of gateways configured for the VCN. Figure 1 The overlay components depicted in can be executed or hosted by one or more of the Figure 2 physical components depicted in. For example, a compute instance in a VCN can be executed or hosted by one or more of the Figure 2 host machines depicted in. For a compute instance hosted by a host machine, the VNIC associated with that compute instance is typically executed by an NVD connected to that host machine (i.e., VNIC functionality is provided by the NVD connected to that host machine). The VCN VR functionality for a VCN is executed by all NVDs connected to the host machine that hosts or executes the compute instances that are part of that VCN. Gateways associated with a VCN can be executed by one or more different types of NVDs. For example, some gateways can be executed by smartNICs, while other gateways can be executed by one or more host machines or other implementations of NVDs.

[0132] As described above, the compute instances in the customer VCN can communicate with various different endpoints, where the endpoints can be within the same subnet as the source compute instance, in different subnets but within the same VCN as the source compute instance, or communicate with endpoints located outside the VCN of the source compute instance. The VNIC associated with the compute instance, the VCN VR, and the gateways associated with the VCN are used to facilitate these communications.

[0133] For communications between two compute instances on the same subnet in a VCN, the VNICs associated with the source and destination compute instances are used to facilitate the communication. The source and destination compute instances can be hosted by the same host machine or different host machines. Packets originating from the source compute instance can be forwarded from the host machine hosting the source compute instance to the NVD connected to that host machine. At the NVD, the packets are processed using the packet processing pipeline, which can include the execution of the VNIC associated with the source compute instance. Since the destination endpoint for the packet is within the same subnet, the execution of the VNIC associated with the source compute instance causes the packet to be forwarded to the NVD that executes the VNIC associated with the destination compute instance, and then the NVD processes the packet and forwards it to the destination compute instance. The VNICs associated with the source and destination compute instances can be executed on the same NVD (e.g., when the source and destination compute instances are hosted by the same host machine) or on different NVDs (e.g., when the source and destination compute instances are hosted by different host machines connected to different NVDs). The VNIC can use the routing / forwarding table stored by the NVD to determine the next hop for the packet.

[0134] For packets that are to be transmitted from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, the packet originating from the source compute instance is transmitted from the host machine hosting the source compute instance to the NVD connected to that host machine. At the NVD, the packet is processed using a packet processing pipeline, which can include the execution of one or more VNICs and the VR associated with the VCN. For example, as part of the packet processing pipeline, the NVD executes or invokes the functionality corresponding to the VNIC associated with the source compute instance (also referred to as executing the VNIC). The functionality executed by the VNIC can include examining the VLAN tag on the packet. Since the destination of the packet is outside the subnet, the NVD then calls and executes the VCN VR functionality. The VCN VR then routes the packet to the NVD that executes the VNIC associated with the destination compute instance. The VNIC associated with the destination compute instance then processes the packet and forwards the packet to the destination compute instance. The VNICs associated with the source and destination compute instances can be executed on the same NVD (e.g., when the source and destination compute instances are hosted by the same host machine) or on different NVDs (e.g., when the source and destination compute instances are hosted by different host machines connected to different NVDs).

[0135] If the destination for the packet is outside the VCN of the source compute instance, then the packet originating from the source compute instance is transmitted from the host machine hosting the source compute instance to the NVD connected to that host machine. The NVD executes the VNIC associated with the source compute instance. Since the destination endpoint of the packet is outside the VCN, the packet is then processed by the VCN VR for that VCN. The NVD calls the VCN VR functionality, which causes the packet to be forwarded to the NVD that executes the appropriate gateway associated with the VCN. For example, if the destination is an endpoint within the customer's on-premises network, then the packet can be forwarded by the VCN VR to the NVD that executes the DRG gateway configured for the VCN. The VCN VR can be executed on the same NVD as the NVD that executes the VNIC associated with the source compute instance, or by a different NVD. The gateway can be executed by the NVD, which can be a smartNIC, a host machine, or other NVD implementation. The packet is then processed by the gateway and forwarded to the next hop, which facilitates the transmission of the packet to its intended destination endpoint. For example, in Figure 2In the illustrated embodiment, data packets originating from compute instance 268 can be transferred from host machine 202 to NVD 210 via link 220 (using NIC 232). At NVD 210, VNIC 276 is invoked because it is the VNIC associated with source compute instance 268. VNIC 276 is configured to inspect the information encapsulated in the data packet and determine the next hop for forwarding the data packet, with the aim of facilitating the transfer of the data packet to its intended destination endpoint, and then forwarding the data packet to the determined next hop.

[0136] Compute instances deployed on a VCN can communicate with a variety of different endpoints. These endpoints can include endpoints hosted by CSPI 200 and endpoints external to CSPI 200. Endpoints hosted by CSPI 200 can include instances within the same VCN or other VCNs, which can be the customer's VCNs or VCNs that do not belong to the customer. Communication between endpoints hosted by CSPI 200 can be performed via physical network 218. Compute instances can also communicate with endpoints that are not hosted by CSPI 200 or are external to CSPI 200. Examples of these endpoints include endpoints or data centers within the customer's on-premises network, or public endpoints accessible via a public network (such as the Internet). Communication with endpoints external to CSPI 200 can be performed via a public network (e.g., the Internet) Figure 2 (not shown in []) or a private network ( Figure 2 (not shown in []).

[0137] Figure 2 The architecture of CSPI 200 depicted in [] is merely an example and is not intended to be limiting. In alternative embodiments, variations, substitutions, and modifications are possible. For example, in some implementations, CSPI 200 can have more or fewer systems or components than the Figure 2 systems or components shown in [], two or more systems can be combined, or it can have a different system configuration or arrangement. Figure 2 The systems, subsystems, and other components depicted in [] can be implemented in software (e.g., code, instructions, programs) executed by one or more processing units (e.g., processors, cores) of the respective systems, using hardware, or a combination thereof. The software can be stored on a non-transitory storage medium (e.g., a memory device).

[0138] Figure 4 Depicts the connection between a host machine and an NVD according to certain embodiments for providing I / O virtualization to support multi-tenancy. As Figure 4As depicted, host machine 402 executes hypervisor 404 that provides a virtualized environment. Host machine 402 executes two virtual machine instances, VM1 406 belonging to customer / tenant #1 and VM2 408 belonging to customer / tenant #2. Host machine 402 includes physical NIC 410 connected to NVD 412 via link 414. Each computing instance is attached to a VNIC executed by NVD 412. In Figure 4 the embodiment of, VM1 406 is attached to VNIC-VM1 420 and VM2 408 is attached to VNIC-VM2 422.

[0139] As Figure 4 shown, NIC 410 includes two logical NICs, logical NIC A 416 and logical NIC B 418. Each virtual machine is attached to its own logical NIC and is configured to work with its own logical NIC. For example, VM1 406 is attached to logical NIC A 416 and VM2 408 is attached to logical NIC B 418. Although host machine 402 includes only one physical NIC 410 shared by multiple tenants, due to the logical NICs, each tenant's virtual machine believes they have their own host machine and NIC.

[0140] In some embodiments, each logical NIC is assigned its own VLAN ID. Thus, a specific VLAN ID is assigned to logical NIC A 416 for tenant #1, and a separate VLAN ID is assigned to logical NIC B 418 for tenant #2. When a data packet is transmitted from VM1 406, the label assigned to tenant #1 is attached to the data packet by the hypervisor, and then the data packet is transmitted from host machine 402 to NVD 412 via link 414. In a similar manner, when a data packet is transmitted from VM2 408, the label assigned to tenant #2 is attached to the data packet by the hypervisor, and then the data packet is transmitted from host machine 402 to NVD 412 via link 414. Accordingly, data packet 424 transmitted from host machine 402 to NVD 412 has an associated label 426 that identifies the specific tenant and the associated VM. At the NVD, for data packet 424 received from host machine 402, the label 426 associated with the data packet is used to determine whether the data packet is to be processed by VNIC-VM1 420 or by VNIC-VM2 422. The data packet is then processed by the corresponding VNIC. Figure 4 The configuration described in enables each tenant's computing instance to believe they have their own host machine and NIC. Figure 4 The setup described in provides I / O virtualization to support multi-tenancy.

[0141] Figure 5Depicts a simplified block diagram of a physical network 500 according to certain embodiments. Figure 5 The embodiment depicted in Figure 5 is structured as a Clos network. A Clos network is a particular type of network topology that is designed to provide connection redundancy while maintaining high bisection bandwidth and maximum resource utilization. A Clos network is a non-blocking, multi-stage or multi-layer switching network where the number of stages or layers can be two, three, four, five, etc. Figure 5 The embodiment depicted in Figure 5 is a three-layer network, including Layer 1, Layer 2, and Layer 3. The TOR switch 504 represents the Layer 0 switch in the Clos network. One or more NVDs are connected to the TOR switch. The Layer 0 switch is also referred to as an edge device of the physical network. The Layer 0 switch is connected to the Layer 1 switches, which are also referred to as leaf switches. In Figure 5 the embodiment depicted in Figure 5 , a group of "n" Layer 0 TOR switches are connected to a group of "n" Layer 1 switches and together form a pod. Each Layer 0 switch in the pod is interconnected to all the Layer 1 switches in the pod, but there is no switch connectivity between pods. In certain implementations, two pods are referred to as a block. Each block is served by or connected to a group of "n" Layer 2 switches (sometimes referred to as spine switches). There can be several blocks in the physical network topology. The Layer 2 switches are in turn connected to "n" Layer 3 switches (sometimes referred to as super-spine switches). Communication of data packets over the physical network 500 is typically performed using one or more Layer 3 communication protocols. Generally, all layers of the physical network (except the TOR layer) are n-way redundant, thus allowing for high availability. Policies can be specified for pods and blocks to control the visibility of switches to each other in the physical network, thereby enabling the scaling of the physical network.

[0142] A characteristic of a Clos network is that the maximum number of hops reached from one Layer 0 switch to another Layer 0 switch (or from an NVD connected to a Layer 0 switch to another NVD connected to a Layer 0 switch) is fixed. For example, in a three-layer Clos network, a data packet requires a maximum of seven hops to reach from one NVD to another NVD, where the source and destination NVDs are connected to the leaf layer of the Clos network. Similarly, in a four-layer Clos network, a data packet requires a maximum of nine hops to reach from one NVD to another NVD, where the source and destination NVDs are connected to the leaf layer of the Clos network. Thus, the Clos network architecture maintains a consistent latency throughout the network, which is important for communication within and between data centers. The Clos topology is horizontally scalable and cost-effective. The bandwidth / throughput capacity of the network can be easily increased by adding more switches at each layer (e.g., more leaf switches and backbone switches) and by increasing the number of links between switches in adjacent layers.

[0143] In some embodiments, each resource within the CSPI is assigned a unique identifier called a Cloud Identifier (CID). This identifier is included as part of the information for the resource and can be used to manage the resource, for example, via the console or through the API. An example syntax for the CID is:

[0144] ocid1.<RESOURCE TYPE>. <realm>.[REGION].[FUTURE USE].<UNIQUE ID>

[0145] Among them,

[0146] ocid1: A text string indicating the version of the CID;

[0147] resource type: The type of the resource (e.g., instance, volume, VCN, subnet, user, group, etc.);

[0148] realm: The realm where the resource is located. Example values are "c1" for the commercial realm, "c2" for the government cloud realm, or "c3" for the federal government cloud realm, etc. Each realm can have its own domain name;

[0149] region: The region where the resource is located. If this region is not applicable to the resource, then this part may be empty;

[0150] future use: Reserved for future use.

[0151] unique ID: The unique part of the ID. The format can vary depending on the type of the resource or service.

[0152] Introduction to multi-cloud

[0153] Figure 6 Depicts a simplified high-level diagram of a distributed environment 600 according to certain embodiments. The distributed environment includes multiple cloud environments provided by different cloud service providers (CSPs), where a cloud environment includes a specific cloud environment that provides dedicated infrastructure, enabling one or more cloud services provided by the specific cloud environment to be used by customers of other cloud environments. As Figure 6 depicted, various different cloud environments (also referred to as "clouds") can be provided by different cloud service providers (CSPs). Each cloud environment or cloud offering can be one or more cloud services subscribed to by one or more customers of that cloud environment. A set of cloud services provided by a cloud environment offering by a CSP can include one or more different types of cloud services, including but not limited to software as a service (SaaS) services, infrastructure as a service (IaaS) services, platform as a service (PaaS) services, database as a service (DBaaS) services, etc. Examples of cloud environments provided by various CSPs include Cloud Infrastructure (OCI) provided by Oracle Corporation, Azure provided by Microsoft Corporation, TM , Amazon Web Services provided by Amazon Corporation and so on. Cloud services provided by a particular cloud environment can be different from a set of cloud services provided by another cloud environment.

[0154] In a typical cloud environment, a CSP provides cloud service provider infrastructure (CSPI) for providing one or more cloud services provided by that cloud environment to its customers. The CSPI provided by the CSP can include various types of hardware and software resources, including computing resources, memory resources, networking resources, consoles for accessing cloud services, etc. Customers of the cloud environment provided by the CSP can subscribe to one or more of the cloud services provided by that cloud environment. Various subscription models can be provided by the CSP to its customers. After a customer subscribes to cloud services provided by a cloud environment, one or more users can be associated with the subscribing customer, and these users can use the cloud services subscribed by the customer. In some implementations, when a customer subscribes to cloud services provided by a particular cloud environment, a customer account or customer lease is created for that customer. One or more users can then be associated with the customer lease, and these users can use the services subscribed by the customer under the customer lease. Information about the services subscribed by the customer, the users associated with the customer lease, etc. is typically stored within the cloud environment and associated with the customer lease.

[0155] For example, Figure 6 depicts three different cloud environments provided by three different CSPs. These include cloud environment A (Cloud A) 610 provided by CSP A, cloud environment B (Cloud B) 640 provided by CSP B, and cloud environment C (Cloud C) 660 provided by CSP C. Cloud A 610 includes infrastructure CSPI_A 612 provided by CSP A, and this infrastructure can be used to provide a set of services "Service A" 614 provided by Cloud A 610. One or more customers (e.g., Cust_A1 616-1, Cust_A2 616-2) can subscribe to one or more of the services A 614 provided by Cloud A 610. One or more users 618-1 can be associated with customer A1 616-1 and can use the services subscribed by customer A1 616-1 in Cloud A 610. In a similar manner, one or more users 618-2 can be associated with customer A2 616-2 and can use the services subscribed by customer A2 616-2 in Cloud A 610. In various use cases, the services subscribed by customer A1 616-1 can be different from the services subscribed by customer A2 616-2.

[0156] As Figure 6 As depicted in, Cloud B 640 includes infrastructure CSPI_B 642 provided by CSP B, and this infrastructure can be used to provide a set of services "Service B" 644 supplied by Cloud B 640. One or more customers (e.g., Cust_B1 646-1) can subscribe to one or more of the services in Service B 644. One or more users 648-1 can be associated with customer B1 646-1 and can use the services subscribed to by customer B1 646-1 in Cloud B 640.

[0157] As Figure 6 As depicted in, Cloud C 660 includes infrastructure CSPI_C 662 provided by CSP C, and this infrastructure can be used to provide a set of services "Service C" 664 supplied by Cloud C 660. One or more customers (e.g., Cust_C1 666-1) can subscribe to one or more of the services in Service C 664. One or more users 668-1 can be associated with customer C1 666-1 and can use the services subscribed to by customer C1 666-1 in Cloud C 660. Note that Service A 614, Service B 644, and Service C 664 can be different from each other.

[0158] In existing cloud implementations, each cloud provides a closed ecosystem for its subscribing customers and associated users. Thus, the customers of a cloud environment and their associated users are limited to using the services supplied by the cloud subscribed to by that customer. For example, customer B1 646-1 and its users 648-1 are limited to using Service B 644 provided by Cloud B 640 and cannot use their accounts in Cloud B 640 to access services from different cloud environments, such as services in Service A 614 supplied by Cloud A 610 or services in Service C 664 supplied by Cloud C 660. The teachings described herein overcome this limitation. As described in this disclosure, various techniques are described that enable the creation of a link between two cloud environments, the link enabling services provided by a first cloud environment provided by a first CSP to be used by customers (and associated users) of a second different cloud environment provided by a second different CSP using the customer's account in the second cloud environment.

[0159] For example, in Figure 6 In the embodiments depicted, in addition to other infrastructure 620, the infrastructure CSPI_A 612 provided by CSP A also includes special infrastructure 622 (referred to as multi-cloud enabled infrastructure 622 or MEI 622 or multi-cloud infrastructure 622), which enables one or more services 614 supplied by Cloud A to be used by customers of other clouds (such as Cloud B 640 and C 660) and associated users using customer accounts in those other clouds. In certain embodiments, customers of Cloud B and C do not have to open separate accounts in Cloud A to use one or more of the services 614 supplied by Cloud A 610. Customer B1 646-1 of Cloud B 640 and associated users 648-1 can use their customer accounts or leases in Cloud B640 to use one or more of the services 614 provided by Cloud A 610. As another example, customer C1 666-1 of Cloud C 660 and associated users 668-1 can use their customer accounts or leases in Cloud C 660 to use one or more of the services 614 provided by Cloud A610.

[0160] In certain embodiments, MEI 622 enables the creation of links between Cloud A 610 and other clouds, where these links can be used by customers of other clouds and their associated users to access and use the services provided by Cloud A 610. This is shown symbolically in Figure 6 as link 670 created between Cloud A 610 and Cloud B 640, and link 672 created between Cloud A 610 and Cloud C660. Via link 670, customers of Cloud B 640 can access or use one or more of the services 614 provided by Cloud A 610. Similarly, via link 672, customers of Cloud C 660 can access or use one or more of the services 614 provided by Cloud A 610.

[0161] There are different ways to implement MEI 612. In certain embodiments, MEI 612 can include components that enable the creation of links with different clouds. For example, in Figure 6 MEI 622 includes infrastructure component 624 responsible for enabling link 670 with Cloud B 640, and infrastructure component 626 for enabling link 672 with Cloud C 660. In a similar manner, MEI622 can include other components that enable and facilitate links with other clouds. In some embodiments, the components of MEI 622 can also facilitate links with multiple different clouds.

[0162] There are several reasons why a customer of one cloud may want or expect to use cloud services provided by a different cloud. For Figure 6 For example, there can be multiple reasons why customer B1 646-1 of cloud B 640 may want to use the cloud service 614 provided by cloud A 610. In one use case scenario, this can happen because cloud A 610 supplies cloud services with functionality that cloud B 640 does not offer. As another use case scenario, cloud A and B can supply similar services, but the services provided by cloud A 610 can be better than the corresponding services supplied by cloud B 640 (e.g., more features / functionality, faster, etc.). As another use case scenario, customer B1 646-1 of cloud B 640 may want to use the cloud service provided by cloud A 610 because the price of that service is cheaper than that provided by cloud B 640. In some cases, there can be geographical restrictions or other reasons why customer B1 646-1 of cloud B 640 may want to use the cloud service provided by cloud A 610. For example, cloud A 610 can supply the desired service in a geographical area where cloud B 640 does not offer services, or cloud B 640 does not provide a specific service in the geographical area where the customer desires the service. There can also be several other use case scenarios for why a customer of one cloud may want to use the services provided by a different cloud.

[0163] In certain embodiments, MEI 622 provides the ability and performs functions to create a link between cloud A 610 and another cloud, and via that link, enables a user associated with a customer of the other cloud to access and use the services provided by cloud A 610 in a seamless manner from the other cloud itself. For example, MEI 622 enables user 648-1 associated with customer B1 646-1 of cloud 640 to access the services in service A 614 supplied by cloud A 610 in a seamless manner. In certain implementations, a user interface (e.g., a console) that user 648-1 can access from within cloud B 640 can be provided, which enables the user to see a list of the services 614 provided by cloud A 610 and select a specific service that user 648-1 wishes to access. In response to the user selection, MEI 622 is responsible for performing the process of establishing link 670 between clouds A and B to enable access to the requested service. The process for setting up link 670 is performed automatically by MEI 622 substantially. Customer B1 646-1 or associated user 648-1 does not have to worry about performing any system, networking, or other configuration changes required to facilitate the creation, maintenance, and use of link 670 between cloud A 610 and B 640. There is no burden on the user or customer when creating a link between clouds. Using the techniques described in this disclosure, a link is created in a fast and efficient manner.

[0164] The MEI 622 can use various techniques to make the creation and use of the link seamless for users and customers, thereby providing an enhanced user experience. In some embodiments, the MEI 622 makes the user interface (e.g., graphical user interface GUI, etc.) and processing flow (such as for requesting services from Cloud A 610 and for accessing the requested services from Cloud A 610) with which Customer B1 and the associated user 648-1 interact substantially similar to the interface and processing flow that the customer / user will experience in Cloud B 640. In this way, a customer or user who may be accustomed to the interface and processing flow of Cloud B 640 does not have to learn a new interface and processing flow to access Service 614 from Cloud A 610. The MEI 622 can present different interfaces and processing flows to users of different cloud environments. For example, a first set of user interfaces and processes substantially similar to the user interface and processes of Cloud B can be presented to users from Cloud B 640, while another set of user interfaces and processes substantially similar to the user interface and processes of Cloud C can be presented to users accessing Cloud A 610 from Cloud C 660. This is done to simplify and thus enhance the experience of users accessing Service 614 of Cloud A 610 from other clouds.

[0165] As another example, each cloud environment typically includes an identity management system configured to provide the security of the cloud environment. The identity management system is configured to protect resources in the cloud environment, including resources provided by the CSP and resources of subscribing cloud customers deployed in the cloud environment. Functions performed by the identity management system include, for example, managing identity credentials (e.g., usernames, passwords, etc.) associated with subscribing customers of the cloud and associated users, regulating user access to cloud resources and services based on the permissions / access policies configured for the cloud environment, and other functions. Different clouds can use different identity management systems and associated technologies. For example, the identity management system and associated processes in Cloud A 610 can be completely different from the identity management system and associated processes in Cloud B 640, and the identity management system and associated processes in Cloud B 640 can in turn be completely different from the identity management system and associated processes in Cloud C 660. In some embodiments, although there are differences in the identity management systems and associated processes between different cloud environments, the techniques described herein enable users associated with customers of a first cloud to use the same identity credentials associated with the customers and users in the first cloud to access cloud services provided by different clouds.

[0166] For example, in Figure 6 In the embodiments depicted, cloud B 640 provided by CSP B may include an identity management system that assigns or allocates identity credentials to its subscribing customers and associated users, such as customer B1 646-1 and associated user 648-1. These identity credentials are associated with the lease created for customer B1 646-1 in cloud B 640. In certain embodiments, MEI 622 provided by cloud A 610 enables user 648-1 associated with cloud B customer B1 646-1 to access services from service A 614 in cloud A 610 using the identity credentials associated with user 648-1 and customer B1 646-1 in cloud B 640. This greatly enhances the user experience of user 648-1 as they do not have to create new identity credentials specific to cloud A 610 just to access services in cloud A 610. MEI 622 facilitates this access.

[0167] As an example, customer B1 of cloud B 640 may choose to use a service, such as database as a service (DBaaS), from a set of services 614 provided by cloud A 610. In response to such a choice, MEI 622 enables an automatic creation of a link 670 between cloud A 610 and cloud B 640 to enable user 648-1 associated with customer B1 646-1 to use the DBaaS service provided by cloud A 610. The automatic setup of link 670 is facilitated by MEI 622. After setting up link 670, user 668-1 may use the DBaaS service in cloud A 610 via cloud B 640. As part of using this service, user 668-1 may send a request to create a database resource to cloud A 610 via cloud B 640. In response, CSPI_A 612 may create the requested database in cloud A 610. In certain embodiments, the created database may be provisioned in a virtual network (e.g., virtual cloud network or VCN) created for customer B1 in cloud A 610 and accessible to user 668-1 via cloud B 640. Then, user 668-1 may send requests from cloud B 640 to cloud A 610 to use the provisioned database. These requests may include, for example, requests to write data to the database, update data stored in the database, delete data in the database, delete the database, create additional databases, etc. In some use cases, these requests may originate from user 668-1 or from services 644 provided by cloud B 640 via cloud B 640. In this way, MEI 622 provided by cloud A 610 enables users associated with customers of different clouds provided by different CSPs to seamlessly access services provided by cloud A 610.

[0168] Figure 6 The distributed environment 600 depicted is merely an example and is not intended to unduly limit the scope of the claimed embodiments. Many variations, alternatives, and modifications are possible. For example, in alternative embodiments, the distributed environment 600 can have more or fewer cloud environments. The cloud environment can also have more or fewer systems and components, or can have different configurations or arrangements of systems and components. Figure 6 The systems and components depicted can be implemented in software (e.g., code, instructions, programs) executed by one or more processing units (e.g., processors, cores) of the respective systems, using hardware, or a combination thereof. The software can be stored on a non-transitory storage medium (e.g., on a memory device).

[0169] Multi-cloud control plane (MCCP)

[0170] Figure 7 Depicts a high-level architecture of a multi-cloud infrastructure that interconnects two different cloud environments, each provided by a cloud service provider. As Figure 7 shown, the high-level architecture 700 includes a first cloud environment provided by a first cloud service provider (e.g., OCI) 710 and a second cloud environment provided by a second cloud service provider 720 (e.g., AWS). The first cloud environment 710 includes a multi-cloud infrastructure that provides the ability to deliver the services of the first cloud environment to users of other cloud environments (e.g., the second cloud environment 720). Specifically, as will be described below, the multi-cloud infrastructure includes a multi-cloud control plane (MCCP) 712 and a multi-cloud network data plane (MCNDP) 716, which provide users with the ability to access / manage the services (e.g., PaaS services) of the first cloud environment from another cloud environment.

[0171] The multi-cloud infrastructure provides a user experience as close as possible to the native cloud environment (e.g., the second cloud environment 720) of the user, while providing simple integration between cloud environments. Note that the MCCP 712 and the MCNDP 716 are components of the multi-cloud infrastructure that are deployed (and managed) by the first cloud service provider in the first cloud environment 710. In some embodiments, the multi-cloud infrastructure includes another component (i.e., the multi-cloud service account 726A), which is deployed in the second cloud environment 720 and managed by the first cloud service provider.

[0172] According to some embodiments, the second cloud environment 720 includes a customer account 721 and an account of a first cloud service provider (referred to herein as a multi-cloud account or multi-cloud service account 726A). It should be noted that the second cloud environment 720 may also include a second cloud portal (not shown), which forms a centralized access point where customers of the second environment 720 can log in and manage their native cloud deployments and instances. The second cloud portal may provide options for monitoring and operating the services provided by the second cloud infrastructure. According to some embodiments, the second cloud environment 720 includes a provisioning module 722, a monitoring module 724, and an identity system 723, which includes an identity module 723A and an access control module 723B (i.e., also referred to herein as an identity and access management (IAM) module). In addition, a customer's virtual private cloud (VPC) 725A is included in the customer account 721, which may host one or more computing instances 725B. The identity module 723A is configured to perform tasks such as creating a set of one or more roles (and associated policies, permissions, etc. corresponding to the respective roles) for one or more users of the second cloud environment 720. In some implementations, the access control module 723B acts as a user directory for the second cloud environment. Specifically, the access control module 723B may be configured to create a user pool and perform functions such as adding user registrations, logins, and access control for web and mobile applications.

[0173] The provisioning module 722 corresponds to the services provided by the second cloud environment 720, which enables users to model and manage infrastructure resources in an automated and secure manner. For example, using the provisioning module 722, developers can define and provision infrastructure resources using infrastructure-as-code templates. In other words, the provisioning module 722 automates the prerequisite setup of resources in the customer account in the second cloud environment 720. As another example, the provisioning module 722 may also be configured to set up prerequisite resources that allow components of the first cloud environment to access resources in the customer account in the second cloud environment. According to certain embodiments, this is achieved by allowing the multi-cloud service account 726A to access the resources in the customer account 721, for example, allowing the multi-cloud service account to be peer-to-peer with the customer account, allowing components of the multi-cloud infrastructure (e.g., an observability adapter for publishing metrics in the second cloud environment, etc.). The monitoring module 724 enables the monitoring of the entire stack (e.g., applications, infrastructure, network, and services) and uses alert, log, and event data to perform automated actions. The monitoring module 724 may also visually depict one or more metric data obtained from the first cloud environment using a dashboard (e.g., in a GUI).

[0174] The multi-cloud service account 726A includes a virtual private cloud 726B that hosts a transit gateway and a direct connect component. The direct connect component is a networking component that provides an alternative to using the Internet to leverage cloud services of a second cloud environment. The direct connect enables a customer to establish a low-latency, secure, and private connection to the second cloud environment for workloads that require higher speed or lower latency than the Internet. The transit gateway is a networking hub that can be used to interconnect networks of a VPC and an on-premises deployment. In some embodiments, the transit gateway in the multi-cloud service account 726A is used to peer (i.e., communicatively couple) with a customer account 721 in the second cloud environment 720.

[0175] The first cloud environment 710 includes an MCCP 712, a customer tenancy 714, and an MCNDP 716. As previously described, the MCCP 712 and the MCNDP 716 are parts of the multi-cloud infrastructure that supply access to services provided by the first cloud environment 710 to users of other cloud environments (e.g., the second cloud environment 720), where the user experience is as close as possible to the user experience of the user's native cloud environment while providing simple integration between cloud environments.

[0176] The first cloud environment 710 also includes a multi-cloud console 750 (different from the second cloud portal) that allows authenticated users in the second cloud infrastructure 720 to perform control plane operations on resources of the first cloud infrastructure 710 exposed via the multi-cloud infrastructure. In other words, the multi-cloud console 750 forms a gateway for users of the second cloud environment 720 to be able to access resources deployed in the first cloud environment 710. It should be recognized that the user 705 can directly issue requests (e.g., CRUD requests) for resources provided by the first cloud infrastructure from the multi-cloud console 750.

[0177] The MCCP 712 included in the first cloud environment includes a plurality of microservices, such as a proxy module 712A, a platform service module 712B, and an adapter pool 712C. The adapter pool 712C includes a cloud link adapter, a database (DB) adapter, a network adapter, an observability adapter, and a support adapter.

[0178] Each adapter included in the adapter pool 712C is responsible for exposing a unique set of underlying resources (provided by the first cloud environment) to users in other cloud environments (e.g., the second cloud environment). Specifically, each adapter in the adapter pool 712C is mapped to a specific product or resource provisioned by the first cloud infrastructure. In some embodiments, it should be noted that the actual resources may be created by the native control plane (not shown) of the first cloud infrastructure. The native control plane of the first cloud environment provides management and orchestration across cloud environments. Configuration baselines, user and role access provisioning, and application residency can be set here so that they can execute with related services. For example, with respect to Database as a Service (DBaaS), the DBaaS control plane included in the native control plane of the first cloud environment is configured to instantiate Exa database resources in the customer lease 714 of the first cloud environment.

[0179] Requests issued by the user 705 at the multi-cloud console 750 are routed to the proxy module 712A of the MCCP. It should be noted that the proxy module 712A processes incoming requests for authentication and access control. Each request includes a token (described below) associated with a user account in the second cloud infrastructure. The proxy module extracts the token and validates it with the access control module 723B (i.e., the identity provider system of the second cloud environment). After successful validation, the proxy module 712A can check the role (i.e., the privilege set) associated with the user. It should be noted that a role can be associated with one or more tasks / operations that the role is allowed to perform.

[0180] According to one embodiment, the proxy module 712A is responsible for authenticating incoming requests to the MCCP and authorizing whether the user is allowed to perform the requested operation based on the role associated with the token. In some embodiments, the proxy module 712A can perform the above authentication process by leveraging the custom authentication features of the service platform (SPLAT) associated with the first cloud infrastructure. It should be recognized that, in general, SPLAT is the infrastructure that facilitates the delivery of various cloud services provided by a cloud service provider. SPLAT accepts incoming requests and forwards them to the proxy module 712A, which further parses the incoming requests to determine the authorization decision and returns a success or failure message to SPLAT. When successful, SPLAT can direct the request to the routing module, which directs the request to the appropriate adapter in the adapter pool, and when failed, SPLAT directly returns an error response to the caller.

[0181] According to one embodiment, the proxy module 712A receives a pre-authentication request from a service platform (i.e., SPLAT) of a first cloud environment and routes the request to an appropriate adapter based on the path information included in the incoming request. In some implementations, the proxy module may extract an identifier corresponding to the provider of the service (from the incoming request) and route the request to an appropriate adapter in the adapter pool 712C.

[0182] The cloud link adapter included in the MCCP 712 is responsible for handling the life cycle operations of the resources provided by the first cloud environment. The cloud link adapter is configured to create a mapping (or relationship created during the registration process) between the user's account in the second cloud environment and the corresponding lease / account of the user in the first cloud infrastructure. In other words, the cloud link adapter generates a mapping between a first identifier associated with the user's lease in the first cloud environment and a second identifier associated with the user's account in the second cloud environment.

[0183] In some embodiments, the cloud link adapter performs a conversion between an external cloud identifier (e.g., a second identifier associated with the user's account in the second cloud environment) and a first identifier (associated with the user's lease in the first cloud environment) so that the operations through the MCCP can be mapped to the appropriate underlying resources in the first cloud environment. In some embodiments, the cloud link adapter generates data objects to store the above mapping information. In addition, the cloud link adapter also generates a resource principal associated with the data object. One or more permissions are assigned to the resource principal based on the token (and its associated role) included in the request. The user accesses the downstream services provided by the first cloud environment from the second cloud infrastructure based on the resource principal. The cloud link adapter may store the data object and the associated resource principal in the root compartment of the user's lease in the first cloud infrastructure. Alternatively or additionally, the cloud link adapter may also persist the data object and the resource principal locally on the platform module 712B of the multi-cloud infrastructure for seamless access by other adapters included in the multi-cloud infrastructure.

[0184] The network adapter (also referred to as the network link adapter) is responsible for creating a network link (i.e., a communication link / channel) between the customer account 721 (in the second cloud environment) and the corresponding customer lease / account (in the first cloud environment) 714. According to some embodiments, the network link adapter obtains a token (from the platform module 712B) and creates (1) a first peer relationship between the MCNDP 716 and the customer lease 714 (in the first cloud environment), and (2) a second peer relationship between the customer account 721 and the multi-cloud service account 726A of the first cloud service provider 717 included in the second cloud environment (in the second cloud environment).

[0185] The MCNDP 716 in the first cloud environment 710 includes a FastConnect and a hub and spoke VCN that provision network connections (e.g., from an on-premises location, from an external cloud environment) to be established with a customer lease 714 in the first cloud environment. On the other hand, a transit gateway included in a multi-cloud service account peers with a customer account in the second cloud environment. A network adapter can be configured to communicatively couple the two cloud environments via an Interconnect 719. Specifically, at one end, the Interconnect is coupled to a Direct Connect (located in the multi-cloud service account 726A), and at the other end, the Interconnect is coupled to the FastConnect in the MCDP. It should be appreciated that the FastConnect (including in the first cloud environment) and the Direct Connect included in the second cloud environment can be co-located in the same region. Further, after a network link is formed between the two cloud environments, an application executed in a customer account (e.g., in a customer VPC in the second cloud environment) can access resources such as an Exa database resource deployed in the customer lease 714 in the first cloud environment. It should be appreciated that the network link communicatively couples the user's lease in the first cloud environment with the user's account in the second cloud environment.

[0186] As Figure 7 shown, an observability module (included in the adapter pool 712C) is configured to mirror or forward (e.g., publish) logs, metrics, and other performance parameters related to resources deployed in a customer tenant in the first cloud environment to a dashboard such as included in a monitoring module 724 included in the second cloud environment for further processing. According to some embodiments, a platform services module 712B included in the multi-cloud infrastructure is configured to store credentials associated with services of the first cloud environment provided to users of the second cloud infrastructure. The platform services module 712B provides, for example, tokens / resource principals to different adapters included in the adapter pool 712C such that the adapters can communicate with the native control plane of the first cloud infrastructure. According to some embodiments, the platform services module 712B exposes APIs that are invoked by different adapters to perform tasks such as:

[0187] · Sell a minimal scope access token (issued by the second cloud infrastructure) to an adapter. For example, a network adapter requires an access token to perform the network peering operation described above.

[0188] · Provide a resource principal that an adapter will use to call downstream services to create resources in a customer lease in the first cloud infrastructure.

[0189] · Trigger the replication of observability data

[0190] (logs, metrics, events) from the first cloud infrastructure to the second cloud infrastructure.

[0191] As described above, the adapter pool 712C includes multiple adapters, each of which is responsible for exposing a unique set of underlying resources of the first cloud infrastructure to users of the second cloud infrastructure, i.e., each adapter is mapped to a specific product or resource provisioned by the first cloud environment. For example, the Exa Database adapter acts as an agent for users of the second cloud infrastructure to create and utilize Exa Database resources. Exa Database is a preconfigured combination of hardware and software that provides the infrastructure for executing databases. According to some embodiments, Exa Database includes a set of resources: (a) Exadata infrastructure (i.e., hardware), (b) VM cloud clusters, (c) container databases, and (d) pluggable databases. According to some embodiments, the multi-cloud infrastructure provides the ability (for users of the second cloud infrastructure) for each level of the infrastructure of the analytics stack. Moreover, MCCP provides flexibility to users such that users only need to issue a creation command for a workflow (via the multi-cloud console 750), after which MCCP automatically creates the respective resources at each level of the stack. It should be recognized that although Figure 7 the adapter pool 712C depicted in

[0192] includes five different adapters, this in no way limits the scope of the MCCP architecture 700. The MCCP architecture may include other adapters, e.g., dedicated adapters specifically for a particular cloud service provider based on the requirements of the cloud service provider.

[0193] The provisioning process allows, for example, a multi-cloud service account in the second cloud environment to access resources in the customer account of the second cloud environment. In doing so, resources in the first cloud environment 710 can perform certain actions for the second cloud environment. For example, the observability adapter / module (included in the adapter pool 712C) can transmit metrics associated with resources deployed in the first cloud environment to the monitoring module of the second cloud environment. As another example of the provisioning process, the network adapter (included in the adapter pool 712C) can attach a transit gateway to the customer VPC in the second cloud environment, i.e., form a peer in the second cloud environment.

[0194] According to some embodiments of the present disclosure, the identity system 723 of the second cloud environment 720 includes features that allow users or services to temporarily assume different roles (referred to herein as "assuming a role"). Such features enable cross-account access or permission delegation within or outside the same account. When a user or service assumes a role, they receive a set of temporary security credentials, which may include access keys, secret access keys, and session tokens. These credentials can then be used to make API calls or access resources (in the second cloud environment) based on the permissions granted for the assumed role. Thus, as part of the provisioning process, a multi-cloud service account can be configured to assume certain roles, and the multi-cloud service account can utilize these roles to obtain access to customer accounts in the second cloud environment.

[0195] When a user successfully logs in to the second cloud environment 720 and completes the above provisioning process, an access token can be issued to the user. The token is then forwarded to the multi-cloud console 750, which in turn forwards the token to the MCCP 712. The proxy module 712A included in the MCCP 712 performs user authentication as described above, and after the user is successfully authorized (e.g., checks whether the user has sufficient privileges to issue a specific type of request), the request is forwarded to the appropriate adapter included in the adapter pool 712C to execute the user's request.

[0196] Figure 8 An exemplary swimlane diagram depicting steps corresponding to a user registration process according to some embodiments is shown. Specifically, Figure 8 Steps performed when registering a user (of the second cloud environment) to utilize a multi-cloud service provisioned by a first cloud environment different from the second cloud environment are shown. Figure 8 Interactions between a user 801, a provisioning module 802 of the second cloud environment, an identity module 803 of the second cloud environment, an identity and access management module (IAM) 804 (also referred to herein as an access control module) of the second cloud environment, a multi-cloud console (e.g., a registration console) 805 included in the first cloud environment, and a multi-cloud control plane (MCCP) 806 of the multi-cloud infrastructure included in the first cloud environment are shown. It should be appreciated that the multi-cloud console 805 and the MCCP 806 can be considered components of the multi-cloud infrastructure included in the first cloud environment.

[0197] The process begins at step S1, where user 801 transmits a request to a multi-cloud console 805 (e.g., the registration API of the multi-cloud console) to register for a multi-cloud service provided by a first cloud environment. In some embodiments, after receiving the request, the user may be redirected to a second cloud environment to perform a login operation for the second cloud environment, i.e., user 801 inputs his / her (second cloud environment's) login credentials, which may be verified by the identity system (e.g., identity module 803) of the second cloud environment. After successfully logging in to the second cloud environment (step S2), user 801 may be redirected to multi-cloud console 805. In some embodiments, metadata information including the user's account ID (corresponding to the user's account in the second cloud environment), the user's email address / ID, etc. may be forwarded to multi-cloud console 805. It should be appreciated that the link (e.g., hyperlink) corresponding to the registration API of the multi-cloud console may be provided to the user by various means, such as via a service associated with the second cloud environment, via the online documentation of the first cloud environment (which may include a link to the registration console of the multi-cloud infrastructure), etc. Moreover, the services provided by the multi-cloud infrastructure may include an Exa database service, a shared autonomous database service, a dedicated autonomous database service, or a virtual machine database service, etc.

[0198] After receiving the metadata information, multi-cloud console 805 transmits a request to MCCP 806 to determine whether a set of prerequisite resources has been configured for the user (step S3). In step S4, MCCP begins processing to determine whether the set of prerequisite resources has been configured. In step S5, MCCP continues to assume the role of the verifier, i.e., the role that allows MCCP to perform user verification. In some embodiments, the API associated with MCCP assumes the role of the verifier to perform user verification. Since this is the first time user 801 has accessed multi-cloud console 805 to register for a service provided by the multi-cloud infrastructure, the provisioning of the set of prerequisite resources has not been performed. Therefore, in step S6, the identity system (e.g., Figure 7 the identity system 723) of the second cloud environment including IAM module 804 transmits a notification to MCCP indicating that the verifier role does not exist.

[0199] MCCP 806 transmits a notification to multi-cloud console 805 (step S7), notifying that the prerequisite settings for the resources are incomplete or invalid. Further, in step S8, the multi-cloud console provides a notification to the user (e.g., via the API associated with the multi-cloud console) to initiate or start the provisioning process of the prerequisite resources. In step S9, user 801 communicates with the provisioning module 802 included in the customer account of the second cloud environment to trigger the provisioning process.

[0200] In step S10, the provisioning module 802 triggers the identity module 803 to start provisioning prerequisite resources for the user. For example, as previously referenced Figure 7 and described, provisioning includes creating a set of one or more roles (and associated policies, permissions, etc. corresponding to each role) for one or more users of the second cloud environment. In some embodiments, the identity module 803 acts as a user directory for the second cloud environment. Additionally, the access control module 804 can be configured to create a user pool and perform functions such as adding user enrollments, logins, and access control for web and mobile applications. In some embodiments, the provisioning module 802 is configured to create a hierarchy of resources, each resource associated with a corresponding role, e.g., a networking role, an observability role, and a verifier role. It should be recognized that the networking role allows for the creation of network links, i.e., communication paths that interconnect the resources of the first and second cloud environments, while the observability role provisions the observability module (of the MCCP) to publish metrics associated with one or more resources deployed in the first cloud environment to be transmitted to the monitoring module of the second cloud environment.

[0201] Figure 8 The configuration of the prerequisite resources is depicted in steps S10 - S12 in [reference]. Note that in step S11, the identity module 803 of the second cloud environment can perform user verification based on the credentials (e.g., login information) of the users associated with the second cloud environment. It should be recognized that when performing the provisioning process of the prerequisite resources in the second cloud environment, the multi-cloud console 805 of the first cloud environment can simultaneously communicate with the MCCP 806 to determine whether the prerequisite verification of the resources has been configured (steps S8' and S9'). Since the provisioning of the prerequisite resources is occurring simultaneously (i.e., not yet complete), in step S10', the IAM module 804 of the second cloud environment transmits a notification to the MCCP 806 indicating that the roles have not been created.

[0202] In step S13, the MCCP 806 re - attempts to assume the verifier role. This time, since the roles have been created (i.e., the provisioning of the prerequisite resources was completed in step S12), the MCCP 806 receives a notification from the IAM module 804 of the second cloud environment indicating the existence of the verifier role. Moreover, in step S14, the IAM module 804 provides the MCCP with temporary credentials for a multi - cloud service account (e.g., deployed in the second cloud environment and controlled by the first CSP of the first cloud environment). In step S15, the MCCP 806 verifies the other roles in the role hierarchy. For example, the MCCP 806 verifies whether the networking role and the observability role have been created. In step S16, the MCCP 806 receives confirmation that the role creation was successful.

[0203] In step S17, the MCCP 806 transmits a request to the identity module 803 included in the identity system of the second cloud environment to verify user settings (e.g., verify the configuration of the user pool of the user) and obtain a client ID (e.g., the ID of the user pool to which the user 801 belongs). Specifically, the user setting verification may include determining the identifier of the user pool in the second cloud environment and membership information indicating that the user is a member of the user pool (e.g., an administrator group with sufficient rights / privileges). In step S18, the MCCP 806 provides a uniform resource link (URL) to the multi-cloud console 805. Such a URL corresponds to the login URL, i.e., to log in to the multi-cloud service provided by the first cloud environment. In step S19, a notification may be provided to the user 801 instructing the user to perform the login process. It should be appreciated that such a notification may be provided via the API associated with the multi-cloud console 805.

[0204] In step S20, once the user performs the login process, for example, by logging in to the identity system (e.g., the identity module 803) of the second cloud environment, in step S21, the user is directed to the multi-cloud console. Note that when the user 801 successfully logs in to the identity module 803 of the second cloud environment, the identity module 803 may provide an access token to the user. When the user selects any one of the services provided by the multi-cloud infrastructure, such an access token may be forwarded to the multi-cloud console 805, where the token is used to authenticate the user's permissions.

[0205] In step S22, when the user is successfully directed to the multi-cloud console, the cloud link adapter included in the MCCP may be activated to provide the user 801 with an option to link the customer account in the second cloud environment with the customer account in the first cloud environment. In other words, the cloud link adapter performs the process of linking the two accounts of the customers in two different cloud environments, as described previously with reference to Figure 7 the above. Note that after linking the two accounts in different cloud environments, the user(s) of the second cloud environment may utilize the service(s) provided by the multi-cloud infrastructure included in the first cloud environment. In addition, it should be appreciated that in the case where the user does not have an account in the first cloud environment, the multi-cloud infrastructure may provide the user with an option to create a tenancy in the first cloud environment (for the user).

[0206] Figure 9 Depicts an exemplary swimlane diagram illustrating steps corresponding to an inbound authorization process. The inbound authorization process corresponds to the process of initiating / creating an action at the multi-cloud console and executing the result of that action in a customer tenancy (e.g., the customer's OCI tenancy) in the first cloud environment. Figure 9 Depicts the interactions between several entities including an administrator 910, an identity module 915 (of the second cloud environment), a user 920, a multi-cloud console 925, an MCCP 930, and an adapter (e.g., an ADB sharing adapter) 935.

[0207] As Figure 9 shown, in step S1, the customer's administrator (i.e., the person performing the Figure 8 registration operation) performs a login operation for the identity module 915 of the second cloud environment. Note that the administrator performs the login operation using the credentials associated with the second cloud environment. Since the administrator has sufficient privileges, the administrator 910 may expect to add a specific user (e.g., the user 920) to the administrative group. After adding the user 920 to the administrative group, in step S2, a verification message is transmitted to the user 920. For example, the verification message can be transmitted to the user 920 via email.

[0208] In step S3, when the verification message is received, the user 920 performs a verification process, i.e., logs in to the second cloud environment using their credentials. It should be recognized that the verification message can include a temporary password generated by the identity module 915. When the user 920 successfully logs in to their account associated with the second cloud environment, the user can choose to reset the temporary password in step S4. Additionally, when successfully logged in to the second cloud environment, the identity module 915 grants a token (e.g., an access token) to the user in step S5.

[0209] In step S6, the user is directed to the multi-cloud console 925 (e.g., the GUI of the multi-cloud console) included in the first cloud environment. It should be recognized that the token granted to the user and the metadata are forwarded to the multi-cloud console 925. The metadata can include information such as the user's account ID in the second cloud environment, the user pool ID (i.e., the identifier associated with the user group to which the user belongs), etc. In step S7, the user 920 selects a type of resource from among the various types of resources available for deployment. Note that each of the various types of resources can be provided as an icon on the GUI of the multi-cloud console 925, where the user can select a specific type of resource for deployment by selecting (e.g., clicking) the corresponding icon on the GUI. Alternatively, the user 920 can select the desired resource type for deployment from the drop-down menu of the GUI.

[0210] After the user 920 performs a selection of a desired resource type to be deployed, in step S8, a request is transmitted from the multi-cloud console 925 to the corresponding adapter (associated with the resource type) included in the adapter pool of the multi-cloud infrastructure of the first cloud environment. For the sake of illustration, it is assumed here that the user 920 desires to deploy an Autonomous Database Shared (ADB-S) resource. However, it should be noted that this in no way limits the scope of the present disclosure. Additionally, the request includes a token associated with the user 920 and other metadata information (obtained in step S6). In some embodiments, the request transmitted from the multi-cloud console 925 to the database adapter 935 may be signed using a private key associated with the identity module of the second cloud environment to generate a signed request (i.e., a signature).

[0211] After the database adapter 935 receives a request to deploy an ADB-S resource in the customer's lease in the first cloud environment of the customer, the database adapter 935 forwards the signed request (i.e., the signature) to the MCCP 930 in step S9 for authorizing the user, that is, determining whether the user who initiated the request to deploy this type of resource at the multi-cloud console has sufficient privileges to issue the request. The MCCP 925 continues to authorize the user by decrypting the signed request using the public key associated with the identity module 915. If the MCCP 925 successfully decrypts the signature, then the MCCP 925 extracts the token from the decrypted signed request and authorizes the user 920 based on the token. For example, based on the token, it is determined whether the user 920 is a member of a user group (e.g., an administrative group having the permission to issue requests (such as to deploy resources)). When the user is successfully authorized, the MCCP 925 transmits an authorization notice to the database adapter 935 in step S10. It should be noted that the above authorization process may be performed by a proxy module (e.g., the proxy module 712A of the MCCP).

[0212] After receiving the authorization notice, the database adapter continues to deploy the selected type of resource (e.g., an ADB-S resource) in the compartment of the customer's lease in the first cloud environment. For example, in one embodiment, the database adapter may obtain a link resource object previously created for the user. The link resource object includes information that links the lease associated with the user in the first cloud environment to the account associated with the user in the second cloud environment. In step S11, the database adapter transmits a notice indicating the deployment of the resource in the first cloud environment to the multi-cloud console 925. The multi-cloud console 925 then notifies the user 920 of the resource being deployed. It should be recognized that a similar notice may be transmitted from the database adapter to the multi-cloud console after the resource deployment is completed.

[0213] Figure 10 Depicts an exemplary swimlane diagram illustrating steps corresponding to an outbound authorization process. The outbound authorization process corresponds to a process where a resource / component in a first cloud environment desires to access (one or more) resources in a second cloud environment (different from the first cloud environment). For example, an example of an outbound process can correspond to an observability module (e.g., an observability adapter) of an MCCP in a first cloud environment accessing a resource (e.g., a monitoring module of a second cloud environment) to publish one or more metrics related to the performance of one or more resources deployed in the first cloud environment. Figure 10 Depicts the interactions among several entities, including an observability module 1005, a multi-cloud secret repository 1010 (e.g., a database), a multi-cloud service account 1015 (i.e., an account of a first cloud service provider in a second cloud environment), a customer account in a second cloud environment 1020, and a monitoring module in a second cloud environment 1025. Figure 10 The swimlane diagram depicted in corresponds to a scenario where an observability module of a multi-cloud infrastructure (including in a first cloud environment) desires to access a monitoring module included in a second cloud environment in order to publish metrics related to the performance of one or more resources (e.g., a database) deployed in the first cloud environment.

[0214] In step S1, the observability module 1005 retrieves credentials associated with a multi-cloud service account (included in the multi-cloud infrastructure) that is deployed in a second cloud environment (and controlled by a first CSP). This is performed to enable the observability module 1005 to obtain access to the multi-cloud service account in the second cloud environment.

[0215] After retrieving the credentials associated with the multi-cloud service account, in step S2, the observability module 1005 proceeds to assume the role in the multi-cloud service account to act on behalf of the customer. In other words, the observability module determines whether it has the (one or more) permissions to assume the role in the multi-cloud service account on behalf of the customer. Note that during the registration phase (previously described with respect to Figure 8 ), in the step of provisioning prerequisite resources in the second cloud environment, the multi-cloud service account is granted the permission to act on behalf of the customer. If the prerequisite resources are configured in an appropriate manner, then the observability module 1005 is granted the permission to act on behalf of the customer (in step S2).

[0216] In step S3, the observability module continues to assume a specific role (e.g., the observability role) to push metrics associated with one or more resources into the second cloud environment. In some embodiments, the identity system 723 of the second cloud environment may authenticate the customer to ensure that the prerequisite resource provisioning is properly configured to enable the multi-cloud service account to assume such a role. If the identity system 723 of the second cloud environment successfully authenticates the prerequisite provisioning of the resources, it provides temporary credentials to the observability module 1005 to obtain access to the customer account in the second cloud environment. In other words, during the Figure 8 registration phase of, a trust policy is configured that enables the multi-cloud service account to assume the observability role in order to push metrics associated with one or more resources in the first cloud environment into the second cloud environment. After successfully assuming the observability role, in step S4, the observability module transmits or pushes the metrics to a monitoring module (e.g., Figure 7 the monitoring module 724 of) for publishing these metrics in the dashboard application of the monitoring module.

[0217] Figure 11A FIG. depicts an exemplary swimlane diagram illustrating steps corresponding to a user login process according to certain embodiments. Figure 11A FIG. depicts an interaction between several entities including a user 1101, a browser 1102, an identity module 1103 (of the second cloud environment), and a multi-cloud console 1104 and an MCCP 1105, which are included in the first cloud environment.

[0218] In step S1, the user 1101 accesses the multi-cloud console 1104 using the browser 1102, e.g., the API of the multi-cloud console 1104. In step S2, the multi-cloud console 1104 provides the user with a prompt to enter an account ID associated with a customer (e.g., an organization). Note that the user is a member of the customer (e.g., an employee). In step S3, the user 1101 enters the customer's account ID and subsequently transmits a request from the browser to the MCCP 1105 to obtain a unique configuration associated with the customer (step S4). Note that this configuration may correspond to information including a unique URL of the customer (e.g., a URL corresponding to the customer and associated with the second cloud environment where the user can perform a login operation) and other metadata associated with the customer (e.g., client ID, scope, redirect URL (e.g., a URL associated with the multi-cloud console to which the customer is to be redirected), etc.).

[0219] Based on the customer account ID obtained in S2, the MCCP 1105 returns the customer configuration to the browser in step S5. It should be appreciated that during Figure 8 In the customer registration process, the mapping of the customer's account ID to a specific configuration associated with the customer can be stored in the database of the MCCP 1105. Steps S6 to S9 described below are related to the authorization process, including a Proof Key for Code Exchange (PKCE), which enhances the security of the customer. Specifically, in step S6, the browser can generate a code verifier and a code challenge and store the generated verifier and challenge in the browser storage. In some embodiments, the code verifier corresponds to a randomly generated string by a password, e.g., a high-entropy secret string. Additionally, a code challenge can be generated based on the code verifier, e.g., by performing a hash operation on the code verifier (using a hash function, e.g., SHA 256). Note that the code verifier and the code challenge can be used to perform challenge-response verification.

[0220] Based on the code challenge generated in step S6 and the configuration information received in step S5, in step S7, the browser configures / creates a URL for directing the user to the identity module 1103 of the second cloud environment. In step S8, the user 1101 accesses the URL generated in step S7 to perform a login operation. In some embodiments, the authorization request in S8 can include the code challenge generated in step S6. In step S9, the identity module 1103 of the second cloud environment provides a prompt for the user 1101 to enter user credentials. After the user 1101 enters the user credentials, the credentials are submitted to the identity module 1103 of the second cloud environment in step S11.

[0221] In step S12, the identity provider of the second cloud environment redirects the user's browser using an authentication code. In step S13, the browser 1102 performs a GET function on the URL as instructed in step S12. In step S14, a response is obtained from the multi-cloud console 1104. For example, the response can correspond to a status response (e.g., a 200 OK response), which includes a script (e.g., a Java script) for making calls in subsequent steps.

[0222] In step S15, a request is transmitted from the browser to the MCCP 1105 to obtain a unique configuration associated with the customer. Note that the configuration may correspond to information including the customer's unique URL. Configuration information is obtained in step S16. Note that the configuration information includes the customer's unique URL and other metadata, including client ID, scope, redirect URL, etc. In step S17, the browser retrieves the code verifier from its local storage. In step S18, in order to obtain a token from the identity system of the second cloud environment, the browser 1102 transmits a request to obtain a token, where the request includes the code verifier, and then transmits an authentication code. In some embodiments, the identity module 1103 of the second cloud environment may perform processing to determine: (i) whether the authentication code received in step S18 corresponds to the authentication code previously transmitted in step S12, and (ii) based on the code verifier, the identity module 1103 may generate a code challenge and compare it with the challenge received in step S8. Based on the verification of the above conditions, the identity module 1103 may generate one or more tokens for the user (step S19). Note that the user 1101 may utilize the (one or more) tokens (via the multi-cloud console) to access multi-cloud services provided by the first cloud environment, which is different from the cloud environment (i.e., the second cloud environment) from which the user is initiating a request to access such services.

[0223] Figure 11B depicts a schematic diagram illustrating the deployment of resources by a multi-cloud infrastructure according to some embodiments. As Figure 11B shown, the first cloud environment includes a multi-cloud console 1151, a service platform (SPLAT) 1152, an agent 1153, a cloud link adapter 1154, a database adapter 1155, and a platform 1156. When a user accesses the multi-cloud console 1151, in some embodiments, the user may be directed to the identity management system 1160 of the second cloud environment to perform a login operation for the second cloud environment. Note that after successful login, the user is redirected back to the multi-cloud console 1151 along with a token (e.g., an access token). It should be recognized that the user may utilize the multi-cloud console 1151 to issue commands to access, create, or update resources in the user's tenancy in the first cloud infrastructure. For ease of illustration, a scenario where the user issues a request to create a database resource (e.g., an Exa database resource) using the multi-cloud console 1151 is described below.

[0224] The multi-cloud console 1151 provides multiple options, for example, creating resources, accessing resources, updating resources, etc. These options can be provided to users in the form of selectable icons (e.g., buttons) in the multi-cloud console 1151. When the user makes a selection (e.g., to create a resource), an API call to the service platform 1152 is triggered. It should be recognized that in some embodiments, the request made to the service platform 1151 can be a call such as a REST-type call (or a POST call), which includes an authorization header that includes a token associated with a user in the second cloud infrastructure. Also included in the request is metadata information, including the account ID, resource name, provider name, and type of resource requested by the user (of the second cloud environment).

[0225] The call including the token is further forwarded to the proxy module 1153 that performs authentication and access control operations. According to some embodiments, the proxy module 1153 performs the authentication operation by extracting the token included in the call. In some embodiments, the proxy module 1153 verifies the token by comparing a signature (used to sign the request) with a publicly available signature of the second cloud infrastructure to ensure that the request originates from a valid customer associated with the second cloud infrastructure. Additionally, the proxy module 1153 can also check the role (i.e., privilege) associated with the token, for example, whether the role corresponds to a DB administrator, etc. Based on the role, the proxy module 1153 can route the request to an appropriate adapter included in the MCCP framework, i.e., one of the adapters included in the adapter pool 712C, as Figure 7 shown.

[0226] According to one embodiment, the proxy module 1153 compares the role (associated with the token) with a pre-configured list of roles published and assigned (as part of the API specification) for each adapter. For example, if the role associated with the token corresponds to "Exadata DB administrator", then the request can be understood as a request to create an Exa database, and thus the request is forwarded to the database adapter 1155. Additionally, according to some embodiments, the proxy module 1153 can analyze the information included in the REST call, such as the provider ID, the type of resource requested, etc., and based on the analyzed information, the proxy module 1153 can forward the request to an appropriate adapter.

[0227] In some embodiments, the request obtained by the proxy module 1153 may not contain information identifying the user's lease in the first cloud infrastructure where the resources are to be deployed. Thus, the proxy module 1153 communicates with the cloud link adapter 1154 to obtain mapping information of the user account in the second cloud infrastructure to the user lease in the first cloud infrastructure. If the mapping information exists, then the proxy module 1153 obtains information related to the user lease in the first cloud infrastructure and passes the information to the database adapter 1155. In this way, the database adapter 1155 knows the user's lease in the first cloud infrastructure where the resources are to be created / deployed. However, if the cloud link adapter 1154 determines that there is no mapping information, then the proxy module 1153 can simply issue an "Unauthorized access" message back to the user as a response to the request to create database resources.

[0228] Note that, in some embodiments, the cloud link adapter 1154 creates data objects (referred to herein as cloud link resource objects or link resource objects) for storing metadata information identifying the two linked accounts. For example, the data object stores metadata information including the mapping of a first identifier associated with a lease (i.e., account) in the first cloud infrastructure and a second identifier associated with the user account of the second cloud service provider. Such a mapping is referred to herein as a resource context. In addition, the cloud link adapter 1154 may also create a resource principal (referred to herein as a cloud link resource principal) associated with the resource context. The cloud link adapter 1154 may maintain the data object and the resource principal within the root compartment of the user lease in the first cloud infrastructure. In some embodiments, the cloud link adapter 1154 may also persistently store the data object and / or the resource principal locally in the platform 1156.

[0229] In some embodiments, the database adapter 1155 may obtain the resource principal that is persistently stored locally in the platform 1156. The database adapter 1155 may transmit requests (including the resource principal) to one or more downstream services included in the first cloud infrastructure to create resources in the user lease in the first cloud infrastructure. In other words, the downstream services included in the first cloud infrastructure utilize the identity (i.e., the resource principal) obtained from the platform 1156 to create / deploy the required resources, such as an Exa database, in the user lease in the first cloud infrastructure. When the user issues a request to create an Exa database, the user may intermittently poll the MCCP to obtain the status of the request. When the downstream services of the first cloud infrastructure create resources in the user lease in the first cloud infrastructure, the MCCP may notify the user of the successful completion of the request.

[0230] Example of cloud infrastructure

[0231] As noted above, Infrastructure as a Service (IaaS) is a specific type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, the IaaS provider can also supply various services to accompany these infrastructure components (e.g., billing, monitoring, logging, security, load balancing, and clustering, etc.). Thus, since these services may be policy-driven, IaaS users can be able to implement policies to drive load balancing to maintain the availability and performance of applications.

[0232] In some cases, IaaS customers can access resources and services over a wide area network (WAN) such as the Internet and can use the cloud provider's services to install the remaining elements of an application stack. For example, a user can log in to an IaaS platform to create a virtual machine (VM), install an operating system (OS) on each VM, deploy middleware such as a database, create buckets for workloads and backups, and even install enterprise software into that VM. Then, the customer can use the provider's services to perform various functions, including balancing network traffic, troubleshooting applications, monitoring performance, managing disaster recovery, etc.

[0233] In most cases, the cloud computing model will require the participation of a cloud provider. The cloud provider can be, but is not necessarily, a third-party service that specifically provides (e.g., supplies, rents, sells) IaaS. An entity may also choose to deploy a private cloud and thus become its own infrastructure service provider.

[0234] In some examples, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server, etc. It can also include the process of preparing the server (e.g., installing libraries, daemons, etc.). This is typically managed by the cloud provider and is below the hypervisor layer (e.g., servers, storage devices, network hardware, and virtualization). Thus, the customer can be responsible for handling the (OS), middleware, and / or application deployment (e.g., on self-service virtual machines, etc. that can be launched on demand).

[0235] In some examples, IaaS provisioning can refer to obtaining computers or virtual hosts for use and even installing the required libraries or services on them. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.

[0236] In some cases, there are two different challenges in IaaS provisioning. First, there is an initial challenge in provisioning a set of initial infrastructure before anything is running. Second, once everything has been provisioned, there is a challenge in evolving the existing infrastructure (e.g., adding new services, changing services, removing services, etc.). In some cases, these two challenges can be addressed by enabling the configuration of the infrastructure to be defined in a declarative manner. In other words, the infrastructure (e.g., which components are needed and how they interact) can be defined by one or more configuration files. Thus, the overall topology of the infrastructure (e.g., which resources depend on which resources and how they work together) can be described in a declarative manner. In some cases, once the topology is defined, a workflow for creating and / or managing the different components described in the configuration files can be generated.

[0237] In some examples, the infrastructure can have many interconnected elements. For example, there may be one or more virtual private clouds (VPCs) (e.g., a potentially on-demand pool of configurable and / or shared computing resources), also referred to as the core network. In some examples, one or more security group rules can also be provisioned to define how the security of the network is set up and one or more virtual machines (VMs). Other infrastructure elements, such as load balancers, databases, etc., can also be provisioned. As more and more infrastructure elements are desired and / or added, the infrastructure can evolve incrementally.

[0238] In some cases, continuous deployment techniques can be employed to enable the deployment of infrastructure code across various virtual computing environments. Additionally, the techniques described can enable infrastructure management within these environments. In some examples, a service team can write code that is desired to be deployed to one or more but typically many different production environments (e.g., across various different geographical locations, sometimes spanning the entire world). However, in some examples, the infrastructure on which the code will be deployed must first be set up. In some cases, provisioning can be done manually, resources can be provisioned using provisioning tools, and / or once the infrastructure is provisioned, the code can be deployed using deployment tools.

[0239] Figure 12 FIG. 1200 is a block diagram illustrating an example schema of an IaaS architecture according to at least one embodiment. A service operator 1202 can be communicatively coupled to a secure host lease 1204 that can include a virtual cloud network (VCN) 1206 and a secure host subnet 1208. In some examples, the service operator 1202 can use one or more client computing devices, which can be portable handheld devices (e.g., cellular phones, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., Google a head-mounted display), running software (such as Microsoft Windows ), and / or various mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, etc.), and supporting the Internet, email, Short Message Service (SMS), or other communication protocols. Alternatively, the client computing device can be a general-purpose personal computer, including, for example, personal computers and / or laptop computers running various versions of Microsoft Apple and / or Linux operating systems. The client computing device can be a workstation computer running any of various commercially available or UNIX-like operating systems, including but not limited to any of various GNU / Linux operating systems (such as, for example, Google Chrome OS). Alternatively or additionally, the client computing device can be any other electronic device, such as a thin client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox gaming console with or without a gesture input device), and / or a personal messaging device capable of communicating via a network that can access VCN 1206 and / or the Internet.

[0240] VCN 1206 can include a Local Peer Gateway (LPG) 1210, which can be communicatively coupled to a Secure Shell (SSH) VCN 1212 via the LPG 1210 included in the SSH VCN 1212. The SSH VCN 1212 can include an SSH subnet 1214, and the SSH VCN 1212 can be communicatively coupled to a control plane VCN 1216 via the LPG 1210 included in the control plane VCN 1216. Additionally, the SSH VCN 1212 can be communicatively coupled to a data plane VCN 1218 via the LPG 1210. The control plane VCN 1216 and the data plane VCN 1218 can be included in a service lease 1219 that can be owned and / or operated by an IaaS provider.

[0241] The control plane VCN 1216 may include a control plane demilitarized zone (DMZ) layer 1220 that serves as a perimeter network (e.g., a portion of the corporate network between the corporate intranet and the external network). Servers based on the DMZ can assume limited liability and help control security vulnerabilities. Additionally, the DMZ layer 1220 may include one or more load balancer (LB) subnets 1222, a control plane application layer 1224 that may include one or more application subnets 1226, and a control plane data layer 1228 that may include one or more database (DB) subnets 1230 (e.g., one or more front-end DB subnets and / or one or more back-end DB subnets). The one or more LB subnets 1222 included in the control plane DMZ layer 1220 may be communicatively coupled to the one or more application subnets 1226 included in the control plane application layer 1224 and the Internet gateway 1234 that may be included in the control plane VCN 1216, and the one or more application subnets 1226 may be communicatively coupled to the one or more DB subnets 1230 included in the control plane data layer 1228, as well as the service gateway 1236 and the network address translation (NAT) gateway 1238. The control plane VCN 1216 may include the service gateway 1236 and the NAT gateway 1238.

[0242] The control plane VCN 1216 may include a data plane mirror application layer 1240, which may include one or more application subnets 1226. The one or more application subnets 1226 included in the data plane mirror application layer 1240 may include virtual network interface controllers (VNICs) 1242 that may execute compute instances 1244. The compute instances 1244 may communicatively couple the one or more application subnets 1226 of the data plane mirror application layer 1240 to the one or more application subnets 1226 that may be included in the data plane application layer 1246.

[0243] The data plane VCN 1218 may include a data plane application layer 1246, a data plane DMZ layer 1248, and a data plane data layer 1250. The data plane DMZ layer 1248 may include one or more LB subnets 1222, which may be communicatively coupled to the one or more application subnets 1226 of the data plane application layer 1246 and the Internet gateway 1234 of the data plane VCN 1218. The one or more application subnets 1226 may be communicatively coupled to the service gateway 1236 of the data plane VCN 1218 and the NAT gateway 1238 of the data plane VCN 1218. The data plane data layer 1250 may also include one or more DB subnets 1230 that may be communicatively coupled to the one or more application subnets 1226 of the data plane application layer 1246.

[0244] The Internet gateway 1234 for the control plane VCN 1216 and the data plane VCN 1218 can be communicatively coupled to the metadata management service 1252, and the metadata management service 1252 can be communicatively coupled to the public Internet 1254. The public Internet 1254 can be communicatively coupled to the NAT gateway 1238 for the control plane VCN 1216 and the data plane VCN 1218. The service gateway 1236 for the control plane VCN 1216 and the data plane VCN 1218 can be communicatively coupled to the cloud service 1256.

[0245] In some examples, the service gateway 1236 for the control plane VCN 1216 or the data plane VCN 1218 can make application programming interface (API) calls to the cloud service 1256 without going through the public Internet 1254. The API calls from the service gateway 1236 to the cloud service 1256 can be one-way: the service gateway 1236 can make API calls to the cloud service 1256, and the cloud service 1256 can send the requested data to the service gateway 1236. However, the cloud service 1256 may not initiate API calls to the service gateway 1236.

[0246] In some examples, the secure host lease 1204 can be directly connected to the service lease 1219, which would otherwise be isolated. The secure host subnet 1208 can communicate with the SSH subnet 1214 via the LPG 1210, and the LPG 1210 can enable two-way communication on otherwise isolated systems. Connecting the secure host subnet 1208 to the SSH subnet 1214 can enable the secure host subnet 1208 to access other entities within the service lease 1219.

[0247] The control plane VCN 1216 can allow users of the service lease 1219 to set or otherwise provision desired resources. The desired resources provisioned in the control plane VCN 1216 can be deployed or otherwise used in the data plane VCN 1218. In some examples, the control plane VCN 1216 can be isolated from the data plane VCN 1218, and the data plane mirror application layer 1240 of the control plane VCN 1216 can communicate with the data plane application layer 1246 of the data plane VCN 1218 via the VNIC 1242, and the VNIC 1242 can be included in both the data plane mirror application layer 1240 and the data plane application layer 1246.

[0248] In some examples, a user or customer of the system can make requests, such as create, read, update, or delete (CRUD) operations, over a public internet 1254 that can transmit requests to a metadata management service 1252. The metadata management service 1252 can transmit requests over an internet gateway 1234 to a control plane VCN 1216. The requests can be received by one or more LB subnets 1222 included in a control plane DMZ layer 1220. The one or more LB subnets 1222 can determine that the requests are valid, and in response to that determination, the one or more LB subnets 1222 can transmit the requests to one or more application subnets 1226 included in a control plane application layer 1224. If the requests are verified and a call to the public internet 1254 is required, then the call to the public internet 1254 can be transmitted to a NAT gateway 1238 that can make calls to the public internet 1254. Memory where requests may expect to be stored can be stored in one or more DB subnets 1230.

[0249] In some examples, a data plane mirror application layer 1240 can facilitate direct communication between a control plane VCN 1216 and a data plane VCN 1218. For example, it may be desirable to apply configuration changes, updates, or other appropriate modifications to resources included in the data plane VCN 1218. Via a VNIC 1242, the control plane VCN 1216 can communicate directly with resources included in the data plane VCN 1218 and thereby can perform configuration changes, updates, or other appropriate modifications.

[0250] In some embodiments, the control plane VCN 1216 and the data plane VCN 1218 can be included in a service tenancy 1219. In such a case, a user or customer of the system may not own or operate the control plane VCN 1216 or the data plane VCN 1218. Instead, an IaaS provider can own or operate the control plane VCN 1216 and the data plane VCN 1218, both of which can be included in the service tenancy 1219. This embodiment can enable isolation of networks that may prevent a user or customer from interacting with resources of other users or other customers. Additionally, this embodiment can allow a user or customer of the system to privately store databases without relying on the public internet 1254, which may not have a desired threat prevention level, for storage.

[0251] In other embodiments, the (one or more) LB subnets 1222 included in the control plane VCN 1216 can be configured to receive signals from the service gateway 1236. In this embodiment, the control plane VCN 1216 and the data plane VCN 1218 can be configured to be invoked by a customer of the IaaS provider without invoking the public Internet 1254. A customer of the IaaS provider may desire this embodiment because the (one or more) databases used by the customer can be controlled by the IaaS provider and can be stored on the service lease 1219, which may be isolated from the public Internet 1254.

[0252] Figure 13 is a block diagram 1300 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1302 (e.g., Figure 12 the service operator 1202) can be communicatively coupled to a secure host lease 1304 (e.g., Figure 12 the secure host lease 1204), which can include a virtual cloud network (VCN) 1306 (e.g., Figure 12 the VCN 1206) and a secure host subnet 1308 (e.g., Figure 12 the secure host subnet 1208). The VCN 1306 can include a local peering gateway (LPG) 1310 (e.g., Figure 12 the LPG 1210), which can be communicatively coupled to a Secure Shell (SSH) VCN 1312 (e.g., Figure 12 the SSH VCN 1212) via the LPG 1310 included in the SSH VCN 1312. The SSH VCN 1312 can include an SSH subnet 1314 (e.g., Figure 12 the SSH subnet 1214), and the SSH VCN 1312 can be communicatively coupled to a control plane VCN 1316 (e.g., Figure 12 the control plane VCN 1216) via the LPG 1310 included in the control plane VCN 1316. The control plane VCN 1316 can be included in a service lease 1319 (e.g., Figure 12 the service lease 1219), and a data plane VCN 1318 (e.g., Figure 12 the data plane VCN 1218) can be included in a customer lease 1321 that may be owned or operated by a user or customer of the system.

[0253] The control plane VCN 1316 can include a control plane DMZ layer 1320 that can include the (one or more) LB subnets 1322 (e.g., Figure 12 the (one or more) LB subnets 1222) (e.g., Figure 12 The control plane DMZ layer 1220) may include one or more application subnets 1326 (e.g., Figure 12 The control plane application layer 1324 of one or more application subnets 1226) (e.g., Figure 12 The control plane application layer 1224) may include one or more database (DB) subnets 1330 (e.g., similar to Figure 12 One or more DB subnets 1230) of the control plane data layer 1328 (e.g., Figure 12 The control plane data layer 1228). One or more LB subnets 1322 included in the control plane DMZ layer 1320 may be communicatively coupled to one or more application subnets 1326 included in the control plane application layer 1324 and an Internet gateway 1334 that may be included in the control plane VCN 1316 (e.g., Figure 12 The Internet gateway 1234), and one or more application subnets 1326 may be communicatively coupled to one or more DB subnets 1330 included in the control plane data layer 1328, as well as a service gateway 1336 (e.g., Figure 12 The service gateway) and a network address translation (NAT) gateway 1338 (e.g., Figure 12 The NAT gateway 1238). The control plane VCN 1316 may include a service gateway 1336 and a NAT gateway 1338.

[0254] The control plane VCN 1316 may include a data plane mirror application layer 1340 that may include one or more application subnets 1326 (e.g., Figure 12 The data plane mirror application layer 1240). One or more application subnets 1326 included in the data plane mirror application layer 1340 may include a virtual network interface controller (VNIC) 1342 that may execute a compute instance 1344 (e.g., similar to Figure 12 The compute instance 1244) of 1242). The compute instance 1344 may facilitate communication between one or more application subnets 1326 of the data plane mirror application layer 1340 and one or more application subnets 1326 that may be included in the data plane application layer 1346 (e.g., Figure 12 The data plane application layer 1246) via the VNIC 1342 included in the data plane mirror application layer 1340 and the VNIC 1342 included in the data plane application layer 1346.

[0255] The Internet gateway 1334 included in the control plane VCN 1316 may be communicatively coupled to a metadata management service 1352 (e.g., Figure 12 a metadata management service 1252), and the metadata management service 1352 can be communicatively coupled to a public Internet 1354 (e.g., Figure 12 the public Internet 1254). The public Internet 1354 can be communicatively coupled to a NAT gateway 1338 included in the control plane VCN 1316. A service gateway 1336 included in the control plane VCN 1316 can be communicatively coupled to a cloud service 1356 (e.g., Figure 12 the cloud service 1256).

[0256] In some examples, the data plane VCN 1318 can be included in a customer tenancy 1321. In such a case, the IaaS provider can provide a control plane VCN 1316 for each customer, and the IaaS provider can set up a unique compute instance 1344 included in a service tenancy 1319 for each customer. Each compute instance 1344 can permit communication between the control plane VCN 1316 included in the service tenancy 1319 and the data plane VCN 1318 included in the customer tenancy 1321. The compute instance 1344 can permit resources provisioned in the control plane VCN 1316 included in the service tenancy 1319 to be deployed or otherwise used in the data plane VCN 1318 included in the customer tenancy 1321.

[0257] In other examples, a customer of the IaaS provider can have a database that exists in the customer tenancy 1321. In this example, the control plane VCN 1316 can include a data plane mirror application layer 1340, which can include one or more application subnets 1326. The data plane mirror application layer 1340 can reside in the data plane VCN 1318, but the data plane mirror application layer 1340 may not be in the data plane VCN 1318. That is, the data plane mirror application layer 1340 can access the customer tenancy 1321, but the data plane mirror application layer 1340 may not exist in the data plane VCN 1318 or be owned or operated by the customer of the IaaS provider. The data plane mirror application layer 1340 can be configured to make calls to the data plane VCN 1318, but may not be configured to make calls to any entity included in the control plane VCN 1316. The customer may desire to deploy or otherwise use resources provisioned in the control plane VCN 1316 in the data plane VCN 1318, and the data plane mirror application layer 1340 can facilitate the customer's desired deployment or other use of the resources.

[0258] In some embodiments, a customer of an IaaS provider can apply filters to a data plane VCN 1318. In this embodiment, the customer can determine what the data plane VCN 1318 can access, and the customer can restrict access from the data plane VCN 1318 to the public Internet 1354. The IaaS provider may not be able to apply filters or otherwise control the data plane VCN 1318's access to any external network or database. Applying filters and controls by the customer to the data plane VCN 1318 included in the customer's tenancy 1321 can help isolate the data plane VCN 1318 from other customers and the public Internet 1354.

[0259] In some embodiments, a cloud service 1356 can be invoked by a service gateway 1336 to access services that may not be present on the public Internet 1354, control plane VCN 1316, or data plane VCN 1318. The connection between the cloud service 1356 and the control plane VCN 1316 or data plane VCN 1318 may not be real-time or continuous. The cloud service 1356 can exist on a different network owned or operated by the IaaS provider. The cloud service 1356 can be configured to receive calls from the service gateway 1336 and can be configured not to receive calls from the public Internet 1354. Some cloud services 1356 can be isolated from other cloud services 1356, and the control plane VCN 1316 can be isolated from cloud services 1356 that may not be in the same region as the control plane VCN 1316. For example, the control plane VCN 1316 may be located in "Region 1", and the cloud service "Deployment 12" may be located in Region 1 and "Region 2". If the service gateway 1336 included in the control plane VCN 1316 located in Region 1 makes a call to Deployment 12, then the call can be transmitted to Deployment 12 in Region 1. In this example, the control plane VCN 1316 or Deployment 12 in Region 1 may not be communicatively coupled or otherwise communicate with Deployment 12 in Region 2.

[0260] Figure 14 is a block diagram 1400 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1402 (e.g., Figure 12 the service operator 1202) can be communicatively coupled to a secure host tenancy 1404 (e.g., Figure 12 the secure host tenancy 1204), which can include a virtual cloud network (VCN) 1406 (e.g., Figure 12 the VCN 1206) and a secure host subnet 1408 (e.g., Figure 12 the secure host subnet 1208). The VCN 1406 can include an LPG 1410 (e.g., Figure 12 1210), which may be communicatively coupled to the SSH VCN 1412 via the LPG 1410 contained in the SSH VCN 1412 (e.g., Figure 12 SSH VCN 1412 may include SSH subnet 1414 (e.g., Figure 12 SSH subnet 1214 of the control plane VCN 1416), and SSH VCN 1412 can be communicatively coupled to control plane VCN 1416 via LPG 1410 contained in control plane VCN 1416 (e.g., Figure 12 The control plane VCN 1216 of FIG. 1414 is coupled to the data plane VCN 1418 via the LPG 1410 included in the data plane VCN 1418 (e.g., Figure 12 The control plane VCN 1416 and the data plane VCN 1418 may be included in a service lease 1419 (e.g., Figure 12 Service lease 1219).

[0261] The control plane VCN 1416 may include a subnet 1422 that may include (one or more) load balancers (LBs) (e.g., Figure 12 The control plane DMZ layer 1420 (e.g., Figure 12 The control plane DMZ layer 1220 may include (one or more) application subnets 1426 (e.g., similar to Figure 12 (one or more) application subnets 1226) of the control plane application layer 1424 (e.g., Figure 12 A control plane application layer 1224), a control plane data layer 1428 (eg, Figure 12 1428). The LB subnet(s) 1422 contained in the control plane DMZ layer 1420 may be communicatively coupled to the application subnet(s) 1426 contained in the control plane application layer 1424 and the internet gateway 1434 (e.g., Figure 12 1434), and the application subnet(s) 1426 may be communicatively coupled to the DB subnet(s) 1430 and the service gateway 1436 (e.g., Figure 12 ) and a network address translation (NAT) gateway 1438 (e.g., Figure 12 The control plane VCN 1416 may include a service gateway 1436 and a NAT gateway 1438.

[0262] The data plane VCN 1418 may include a data plane application layer 1446 (e.g., Figure 12 the data plane application layer 1246 of), a data plane DMZ layer 1448 (e.g., Figure 12 the data plane DMZ layer 1248 of), and a data plane data layer 1450 (e.g., Figure 12 the data plane data layer 1250 of). The data plane DMZ layer 1448 may include one or more trusted application subnets 1460 and one or more untrusted application subnets 1462 that may be communicatively coupled to the data plane application layer 1446 and one or more LB subnets 1422 of the Internet gateway 1434 included in the data plane VCN 1418. One or more trusted application subnets 1460 may be communicatively coupled to a service gateway 1436 included in the data plane VCN 1418, a NAT gateway 1438 included in the data plane VCN 1418, and one or more DB subnets 1430 included in the data plane data layer 1450. One or more untrusted application subnets 1462 may be communicatively coupled to a service gateway 1436 included in the data plane VCN 1418 and one or more DB subnets 1430 included in the data plane data layer 1450. The data plane data layer 1450 may include one or more DB subnets 1430 that may be communicatively coupled to a service gateway 1436 included in the data plane VCN 1418.

[0263] One or more untrusted application subnets 1462 may include one or more primary VNICs 1464(1)-(N) that may be communicatively coupled to tenant virtual machines (VMs) 1466(1)-(N). Each tenant VM 1466(1)-(N) may be communicatively coupled to a corresponding application subnet 1467(1)-(N) that may be included in a corresponding container egress VCN 1468(1)-(N), and the corresponding container egress VCNs 1468(1)-(N) may be included in corresponding customer tenancies 1470(1)-(N). Corresponding secondary VNICs 1472(1)-(N) may facilitate communication between one or more untrusted application subnets 1462 included in the data plane VCN 1418 and the application subnets included in the container egress VCNs 1468(1)-(N). Each container egress VCN 1468(1)-(N) may include a NAT gateway 1438 that may be communicatively coupled to the public Internet 1454 (e.g., Figure 12 the public Internet 1254 of).

[0264] An Internet gateway 1434 that is included in the control plane VCN 1416 and that is included in the data plane VCN 1418 can be communicatively coupled to a metadata management service 1452 (e.g., Figure 12 the metadata management system 1252), and the metadata management service 1452 can be communicatively coupled to a public Internet 1454. The public Internet 1454 can be communicatively coupled to a NAT gateway 1438 that is included in the control plane VCN 1416 and that is included in the data plane VCN 1418. A service gateway 1436 that is included in the control plane VCN 1416 and that is included in the data plane VCN 1418 can be communicatively coupled to a cloud service 1456.

[0265] In some embodiments, the data plane VCN 1418 can be integrated with a customer lease 1470. In some cases, such as when it may be desirable to support during code execution, this integration may be useful or desirable for customers of an IaaS provider. A customer may provide code that may be disruptive, may communicate with other customer resources, or may otherwise cause undesired effects to run. In response to this, the IaaS provider can determine whether to run the code given to the IaaS provider by the customer.

[0266] In some examples, a customer of an IaaS provider can grant temporary network access to the IaaS provider and request functionality attached to the data plane layer application 1446. The code that runs the functionality can be executed in VMs 1466(1)-(N), and the code can be not configured to run anywhere else on the data plane VCN 1418. Each VM 1466(1)-(N) can be connected to a customer lease 1470. The corresponding containers 1471(1)-(N) included in the VMs 1466(1)-(N) can be configured to run the code. In this case, there can be dual isolation (e.g., the containers 1471(1)-(N) run the code, where the containers 1471(1)-(N) may be at least included in the VMs 1466(1)-(N) included in one or more untrusted application subnets 1462), which can help prevent incorrect or otherwise undesired code from corrupting the IaaS provider's network or corrupting the networks of different customers. The containers 1471(1)-(N) can be communicatively coupled to the customer lease 1470 and can be configured to transmit or receive data from the customer lease 1470. The containers 1471(1)-(N) can be not configured to transmit or receive data from any other entity in the data plane VCN 1418. After the code execution is complete, the IaaS provider can terminate or otherwise dispose of the containers 1471(1)-(N).

[0267] In some embodiments, the (one or more) trusted application subnets 1460 may run code that may be owned or operated by an IaaS provider. In this embodiment, the (one or more) trusted application subnets 1460 may be communicatively coupled to the (one or more) DB subnets 1430 and configured to perform CRUD operations in the (one or more) DB subnets 1430. The (one or more) untrusted application subnets 1462 may be communicatively coupled to the (one or more) DB subnets 1430, but in this embodiment, the (one or more) untrusted application subnets may be configured to perform read operations in the (one or more) DB subnets 1430. Containers 1471(1)-(N) that may be included in each customer's VM 1466(1)-(N) and may run code from the customer may not be communicatively coupled to the (one or more) DB subnets 1430.

[0268] In other embodiments, the control plane VCN 1416 and the data plane VCN 1418 may not be directly communicatively coupled. In this embodiment, there may be no direct communication between the control plane VCN 1416 and the data plane VCN 1418. However, communication may occur indirectly through at least one method. The LPG 1410 may be established by the IaaS provider, which may facilitate communication between the control plane VCN 1416 and the data plane VCN 1418. In another example, the control plane VCN 1416 or the data plane VCN 1418 may invoke a cloud service 1456 via a service gateway 1436. For example, an invocation of the cloud service 1456 from the control plane VCN 1416 may include a request for a service that may communicate with the data plane VCN 1418.

[0269] Figure 15 is a block diagram 1500 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 1502 (e.g., Figure 12 the service operator 1202) may be communicatively coupled to a secure host lease 1504 (e.g., Figure 12 the secure host lease 1204), which may include a virtual cloud network (VCN) 1506 (e.g., Figure 12 the VCN 1206) and a secure host subnet 1508 (e.g., Figure 12 the secure host subnet 1208). The VCN 1506 may include an LPG 1510 (e.g., Figure 12 the LPG 1210), which may communicate via an SSH VCN 1512 (e.g., Figure 12 LPG 1510 in SSH VCN 1512 of the present invention is communicatively coupled to SSH VCN 1512. SSH VCN 1512 may include SSH subnet 1514 (e.g., Figure 12 SSH subnet 1214 of the control plane VCN 1514), and SSH VCN 1512 can be communicatively coupled to control plane VCN 1516 via LPG 1510 contained in control plane VCN 1516 (e.g., Figure 12 1516) and is coupled to the data plane VCN 1518 via the LPG 1510 included in the data plane VCN 1518 (e.g., Figure 12 The control plane VCN 1516 and the data plane VCN 1518 may be included in a service lease 1519 (e.g., Figure 12 Service lease 1219).

[0270] The control plane VCN 1516 may include a LB subnet 1522 (e.g., Figure 12 The control plane DMZ layer 1520 (e.g., Figure 12 The control plane DMZ layer 1220 may include (one or more) application subnets 1526 (e.g., Figure 12 (one or more) application subnets 1226) of the control plane application layer 1524 (e.g., Figure 12 The control plane application layer 1224 of FIG. 1224 may include (one or more) DB subnets 1530 (e.g., Figure 14 (one or more) DB subnets 1430) of the control plane data layer 1528 (e.g., Figure 12 1528). The LB subnet(s) 1522 contained in the control plane DMZ layer 1520 may be communicatively coupled to the application subnet(s) 1526 contained in the control plane application layer 1524 and the internet gateway 1534 (e.g., Figure 12 1234), and the application subnet(s) 1526 may be communicatively coupled to the DB subnet(s) 1530 and the service gateway 1536 (e.g., Figure 12 ) and a network address translation (NAT) gateway 1538 (e.g., Figure 12 The control plane VCN 1516 may include a service gateway 1536 and a NAT gateway 1538.

[0271] The data plane VCN 1518 may include a data plane application layer 1546 (e.g., Figure 12 the data plane application layer 1246 of Figure 12 ), a data plane DMZ layer 1548 (e.g., Figure 12 the data plane DMZ layer 1248 of Figure 14 ), and a data plane data layer 1550 (e.g., Figure 14 the data plane data layer 1250 of

[0272] ). The data plane DMZ layer 1548 may include one or more trusted application subnets 1560 (e.g., Figure 12 one or more trusted application subnets 1460 of

[0273] Figure 14 ) that may be communicatively coupled to the data plane application layer 1546, and one or more untrusted application subnets 1562 (e.g., Figure 14 one or more untrusted application subnets 1462 of

[0272] ) and one or more LB subnets 1522 of an Internet gateway 1534 included in the data plane VCN 1518. One or more trusted application subnets 1560 may be communicatively coupled to a service gateway 1536 included in the data plane VCN 1518, a NAT gateway 1538 included in the data plane VCN 1518, and one or more DB subnets 1530 included in the data plane data layer 1550. One or more untrusted application subnets 1562 may be communicatively coupled to a service gateway 1536 included in the data plane VCN 1518 and one or more DB subnets 1530 included in the data plane data layer 1550. The data plane data layer 1550 may include one or more DB subnets 1530 that may be communicatively coupled to a service gateway 1536 included in the data plane VCN 1518. (One or more) untrusted application subnets 1562 may include one or more primary VNICs 1564(1)-(N) that may be communicatively coupled to tenant virtual machines (VMs) 1566(1)-(N) residing within the (one or more) untrusted application subnets 1562. Each tenant VM 1566(1)-(N) may run code in a respective container 1567(1)-(N) and be communicatively coupled to an application subnet 1526 in the data plane application layer 1546 that may be included in a container egress VCN 1568. Respective secondary VNICs 1572(1)-(N) may facilitate communication between the (one or more) untrusted application subnets 1562 included in the data plane VCN 1518 and the application subnet included in the container egress VCN 1568. The container egress VCN may include a NAT gateway 1538 that may be communicatively coupled to a public Internet 1554 (e.g., Figure 12 the public Internet 1254 of

[0273] The Internet gateway 1534 included in the control plane VCN 1516 and included in the data plane VCN 1518 can be communicatively coupled to the metadata management service 1552 (e.g., Figure 12 15), which can be communicatively coupled to the public Internet 1554. The public Internet 1554 can be communicatively coupled to the NAT gateway 1538 contained in the control plane VCN 1516 and contained in the data plane VCN 1518. The service gateway 1536 contained in the control plane VCN 1516 and contained in the data plane VCN 1518 can be communicatively coupled to the cloud service 1556.

[0274] In some examples, Figure 15 The architecture model shown in block diagram 1500 can be considered as Figure 14 1400 , and may be desired by customers of the IaaS provider if the IaaS provider cannot communicate directly with the customer (e.g., in a disconnected region). The customer may access the corresponding container 1567(1)-(N) contained in each customer's VM 1566(1)-(N) in real time. The container 1567(1)-(N) may be configured to make calls to the corresponding secondary VNIC 1572(1)-(N) contained in the (one or more) application subnets 1526 of the data plane application layer 1546, which may be contained in the container egress VCN 1568. The secondary VNIC 1572(1)-(N) may transmit the call to the NAT gateway 1538, which may transmit the call to the public Internet 1554. In this example, containers 1567(1)-(N), which may be accessed by customers in real time, may be isolated from control plane VCN 1516 and may be isolated from other entities contained in data plane VCN 1518. Containers 1567(1)-(N) may also be isolated from resources from other customers.

[0275] In other examples, a customer can use containers 1567(1)-(N) to invoke cloud service 1556. In this example, the customer can run code in containers 1567(1)-(N) that requests services from cloud service 1556. Containers 1567(1)-(N) can transmit the request to secondary VNICs 1572(1)-(N), which can transmit the request to a NAT gateway that can transmit the request to public Internet 1554. Public Internet 1554 can transmit the request via Internet gateway 1534 to (one or more) LB subnets 1522 included in control plane VCN 1516. In response to determining that the request is valid, (one or more) LB subnets can transmit the request to (one or more) application subnets 1526, which can transmit the request to cloud service 1556 via service gateway 1536.

[0276] It should be appreciated that the IaaS architectures 1200, 1300, 1400, 1500 depicted in the figures can have other components than those depicted. Additionally, the embodiments shown in the figures are merely some examples of cloud infrastructure systems that can incorporate the embodiments of the present disclosure. In some other embodiments, the IaaS system can have more or fewer components than shown in the figures, can combine two or more components, or can have a different configuration or arrangement of components.

[0277] In certain embodiments, the IaaS systems described herein can include application suite, middleware, and database service offerings that are delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such an IaaS system is the Oracle Cloud Infrastructure (OCI) offered by the present assignee.

[0278] Figure 16 An example computer system 1600 in which various embodiments can be implemented is illustrated. System 1600 can be used to implement any of the computer systems described above. As shown, computer system 1600 includes a processing unit 1604 that communicates with a plurality of peripheral subsystems via bus subsystem 1602. These peripheral subsystems can include a processing acceleration unit 1606, an I / O subsystem 1608, a storage subsystem 1618, and a communication subsystem 1624. Storage subsystem 1618 includes tangible computer-readable storage medium 1622 and system memory 1610.

[0279] The bus subsystem 1602 provides a mechanism for enabling the various components and subsystems of the computer system 1600 to communicate with each other as intended. Although the bus subsystem 1602 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. The bus subsystem 1602 can be any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures can include Industry Standard Architecture (ISA) buses, Micro Channel Architecture (MCA) buses, Enhanced ISA (EISA) buses, Video Electronics Standards Association (VESA) local buses, and Peripheral Component Interconnect (PCI) buses, which can be implemented as Mezzanine buses manufactured to the IEEE P1386.1 standard.

[0280] The processing unit 1604, which can be implemented as one or more integrated circuits (e.g., conventional microprocessors or microcontrollers), controls the operation of the computer system 1600. One or more processors can be included in the processing unit 1604. These processors can include single-core or multi-core processors. In certain embodiments, the processing unit 1604 can be implemented as one or more independent processing units 1632 and / or 1634, where each processing unit includes a single-core or multi-core processor. In other embodiments, the processing unit 1604 can also be implemented as a quad-core processing unit formed by integrating two dual-core processors into a single chip.

[0281] In various embodiments, the processing unit 1604 can execute various programs in response to program code and can maintain multiple concurrently executing programs or processes. At any given time, some or all of the program code to be executed can reside in the (one or more) processors 1604 and / or the storage subsystem 1618. Through appropriate programming, the (one or more) processors 1604 can provide the various functions described above. The computer system 1600 can additionally include a processing acceleration unit 1606, which can include a digital signal processor (DSP), a dedicated processor, and so on.

[0282] The I / O subsystem 1608 can include user interface input devices and user interface output devices. User interface input devices can include a keyboard, a pointing device such as a mouse or trackball, a touchpad or touchscreen incorporated into a display, a scroll wheel, a click wheel, a dial, buttons, switches, a keyboard, an audio input device with a voice command recognition system, a microphone, and other types of input devices. User interface input devices can include, for example, motion sensing and / or gesture recognition devices, such as Microsoft's A motion sensor that enables a user to control and interact with an input device such as a Microsoft 360 game controller using gestures and voice commands through a natural user interface. The user interface input device may also include an eye gesture recognition device, such as one that detects eye activity from the user (e.g., "blinking" when taking a photo and / or making a menu selection) and converts the eye gesture into an input to the input device (e.g., Google ) in Google Blink Detector. Additionally, the user interface input device may include a voice recognition sensing device that enables the user to interact with a voice recognition system (e.g., Navigator) via voice commands.

[0283] The user interface input device may also include, but is not limited to, a three-dimensional (3D) mouse, joystick or pointing stick, game pad, and graphics tablet, as well as audio / video devices such as speakers, digital cameras, digital video cameras, portable media players, webcams, image scanners, fingerprint scanners, barcode readers, 3D scanners, 3D printers, laser rangefinders, and eye tracking devices. Additionally, the user interface input device may include, for example, medical imaging input devices such as computed tomography, magnetic resonance imaging, positron emission tomography, and medical ultrasound devices. The user interface input device may also include, for example, audio input devices such as MIDI keyboards, digital musical instruments, etc.

[0284] The user interface output device may include a display subsystem, indicator lights, or a non-visual display such as an audio output device, etc. The display subsystem may be a cathode ray tube (CRT), a flat panel device such as one using a liquid crystal display (LCD) or a plasma display, a projection device, a touch screen, etc. In general, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computer system 1600 to the user or other computers. For example, the user interface output device may include, but is not limited to, various display devices that visually convey text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, automotive navigation systems, plotters, voice output devices, and modems.

[0285] The computer system 1600 may include a storage subsystem 1618 that contains software elements and is shown as currently residing in the system memory 1610. The system memory 1610 may store program instructions that are loadable and executable on the processing unit 1604, as well as data generated during the execution of these programs.

[0286] Depending on the configuration and type of the computer system 1600, the system memory 1610 can be volatile (such as random access memory (RAM)) and / or non-volatile (such as read-only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that can be immediately accessed by the processing unit 1604 and / or are currently being operated on and executed by the processing unit 1604. In some implementations, the system memory 1610 can include multiple different types of memory, such as static random access memory (SRAM) or dynamic random access memory (DRAM). In some implementations, a basic input / output system (BIOS), such as containing basic routines that help transfer information between elements of the computer system 1600 during startup, can typically be stored in the ROM. By way of example, but not limitation, the system memory 1610 is also shown to include application programs 1612, program data 1614, and an operating system 1616 that can include client applications, web browsers, middleware applications, relational database management systems (RDBMS), etc. By way of example, the operating system 1616 can include various versions of Microsoft Apple and / or Linux operating systems, various commercially available or UNIX-like operating systems (including but not limited to various GNU / Linux operating systems, Google OS, etc.) and / or mobile operating systems such as iOS, Phone, OS, 16OS, and OS operating systems.

[0287] The storage subsystem 1618 can also provide a tangible computer-readable storage medium for storing the basic programming and data structures that provide the functionality of some embodiments. Software (programs, code modules, instructions) that provides the above functionality when executed by a processor can be stored in the storage subsystem 1618. These software modules or instructions can be executed by the processing unit 1604. The storage subsystem 1618 can also provide a repository for storing data used in accordance with the present disclosure.

[0288] The storage subsystem 1600 can also include a computer-readable storage medium reader 1620 that can be further connected to a computer-readable storage medium 1622. Together with and, optionally, in combination with the system memory 1610, the computer-readable storage medium 1622 can comprehensively represent remote, local, fixed, and / or removable storage devices plus storage media for temporarily and / or more persistently containing, storing, sending, and retrieving computer-readable information.

[0289] The computer-readable storage medium 1622 that contains code or portions of code may also include any suitable medium known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media implemented with any method or technology for the storage and / or transmission of information. This may include tangible computer-readable storage media such as RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage or other magnetic storage devices, or other tangible computer-readable media. This may also include non-tangible computer-readable media such as data signals, data transmissions or any other medium that can be used to transmit the desired information and can be accessed by the computing system 1600.

[0290] For example, the computer-readable storage medium 1622 may include a hard disk drive that reads from or writes to a non-removable non-volatile magnetic medium, a disk drive that reads from or writes to a removable non-volatile disk, and an optical disk drive that reads from or writes to a removable non-volatile optical disk (such as a CD ROM, DVD, and disk or other optical media). The computer-readable storage medium 1622 may include, but is not limited to, drives, flash cards, universal serial bus (USB) flash drives, secure digital (SD) cards, DVD disks, digital audio tapes, and so on. The computer-readable storage medium 1622 may also include solid state drives (SSDs) based on non-volatile memory (such as flash memory-based SSDs, enterprise flash drives, solid state ROMs, etc.), SSDs based on volatile memory (such as solid state RAM, dynamic RAM, static RAM), DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs that use a combination of DRAM and flash memory-based SSDs. Disk drives and their associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 1600.

[0291] The communication subsystem 1624 provides an interface to other computer systems and networks. The communication subsystem 1624 serves as an interface for receiving data from other systems and sending data from the computer system 1600 to other systems. For example, the communication subsystem 1624 may enable the computer system 1600 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 1624 may include radio frequency (RF) transceiver components for accessing wireless voice and / or data networks (e.g., using cellular phone technologies such as advanced data network technologies like 3G, 4G, or EDGE (Enhanced Data Rates for Global Evolution), Wi-Fi (IEEE 802.11 series standards), or other mobile communication technologies, or any combination thereof), global positioning system (GPS) receiver components, and / or other components. In some embodiments, as an addition or alternative to the wireless interface, the communication subsystem 1624 may provide a wired network connection (e.g., Ethernet).

[0292] In some embodiments, the communication subsystem 1624 may also receive input communications in the form of structured and / or unstructured data feeds 1626, event streams 1628, event updates 1630, etc. on behalf of one or more users who may use the computer system 1600.

[0293] For example, the communication subsystem 1624 may be configured to receive data feeds 1626 from users of social networks and / or other communication services in real time, such as feeds, updates, web feeds such as Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third-party information sources.

[0294] In addition, the communication subsystem 1624 may also be configured to receive data in the form of continuous data streams, which may include event streams 1628 and / or event updates 1630 of real-time events that may be continuous or unbounded in nature and have no explicit termination. Examples of applications that produce continuous data may include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automotive traffic monitoring, and so on.

[0295] The communication subsystem 1624 may also be configured to output structured and / or unstructured data feeds 1626, event streams 1628, event updates 1630, etc. to one or more databases, which may communicate with one or more streaming data source computers coupled to the computer system 1600.

[0296] The computer system 1600 may be one of various types, including handheld portable devices (e.g., cellular phones, computing tablets, PDAs), wearable devices (e.g., Glass head-mounted displays), PCs, workstations, mainframes, kiosks, server racks, or any other data processing system.

[0297] Due to the ever-changing nature of computers and networks, the description of the computer system 1600 depicted in the figure is merely to serve as a specific example. Many other configurations with more or fewer components than the system depicted in the figure are possible. For example, custom hardware can also be used and / or specific elements can be implemented in hardware, firmware, software (including applets), or combinations thereof. Additionally, connections to other computing devices such as network input / output devices can also be employed. Based on the disclosure and teachings provided herein, those of ordinary skill in the art will recognize other ways and / or methods of implementing the various embodiments.

[0298] Although specific embodiments have been described, various modifications, variations, alternative constructs, and equivalent forms are also included within the scope of the present disclosure. The embodiments are not limited to operating within certain specific data processing environments, but can operate freely within multiple data processing environments. Furthermore, although the embodiments have been described using a specific series of transactions and steps, those skilled in the art should appreciate that the scope of the present disclosure is not limited to the described series of transactions and steps. The various features and aspects of the above embodiments can be used alone or in combination.

[0299] In addition, although the embodiments have been described using a specific combination of hardware and software, it should be recognized that other combinations of hardware and software are also within the scope of the present disclosure. The embodiments can be implemented using only hardware, or only software, or using a combination thereof. The various processes described herein can be implemented in any combination on the same processor or on different processors. Accordingly, in cases where a component or module is described as being configured to perform certain operations, such configuration can be accomplished by, for example, designing an electronic circuit to perform the operations, programming a programmable electronic circuit (such as a microprocessor) to perform the operations, or any combination thereof. The processes can communicate using a variety of techniques, including but not limited to conventional techniques for inter-process communication, and different pairs of processes can use different techniques, or the same pair of processes can use different techniques at different times.

[0300] Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive. However, it is obvious that additions, subtractions, deletions, and other modifications and changes can be made thereto without departing from the broader spirit and scope set forth in the claims. Thus, although specific disclosed embodiments have been described, these are not intended to be limiting. Various modifications and equivalent forms are within the scope of the following claims.

[0301] In the context of describing the disclosed embodiments (especially in the context of the following claims), the terms "a", "an", "the", and similar references are to be construed to cover both the singular and the plural unless otherwise indicated herein or clearly contradicted by the context. Unless otherwise stated, the terms "comprising", "having", "including", and "containing" are to be construed as open-ended terms (i.e., meaning "including but not limited to"). The term "connected" shall be construed to mean partly or wholly incorporated in, attached to, or joined together, even if there is something in between. Unless otherwise indicated herein, the recitation of a range of values herein is merely intended to be a shorthand method of referring individually to each separate value falling within the range, and each separate value is incorporated into the specification as if it were individually recited herein. Unless otherwise indicated herein or clearly contradicted by the context, all methods described herein may be performed in any suitable order. The use of any and all examples, or exemplary language (e.g., "such as") provided herein is merely intended to better illuminate the embodiments and does not pose a limitation on the scope of the disclosure unless otherwise stated. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.

[0302] Disjunctive language, such as the phrase "at least one of X, Y, or Z", unless otherwise expressly stated, is generally intended to be understood in the context of items, terms, etc. which can be X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Thus, such disjunctive language is not generally intended to, and should not, imply that certain embodiments require the presence of at least one of each of X, at least one of Y, or at least one of Z.

[0303] Preferred embodiments of the present disclosure are described herein, including the best mode known for carrying out the present disclosure. Variations of those preferred embodiments will become apparent to those of ordinary skill in the art upon reading the foregoing description. Ordinary skill in the art should be able to appropriately adopt such variations and practice the present disclosure in a manner different from that specifically described herein. Accordingly, the present disclosure includes all modifications and equivalent forms of the subject matter recited in the appended claims as permitted by applicable law. In addition, unless otherwise indicated herein, the present disclosure includes any combination of the above elements in all possible variations thereof.

[0304] All references cited herein, including publications, patent applications, and patents, are incorporated herein by reference to the same extent as if each reference were individually and specifically indicated to be incorporated by reference and set forth in full herein. In the foregoing specification, aspects of the present disclosure have been described with reference to specific embodiments thereof, but those skilled in the art will recognize that the present disclosure is not limited thereto. The various features and aspects disclosed above may be used singly or in combination. Additionally, embodiments may be used in any number of environments and applications other than those described herein without departing from the broader spirit and scope of this specification. Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive.< / realm>

Claims

1. A method, comprising: receiving, by a multi-cloud infrastructure included in a first cloud environment, a request from a user associated with an account in a second cloud environment, the request requesting the user to register for a service provided by the multi-cloud infrastructure and including metadata information associated with the user; transmitting, by the multi-cloud infrastructure, a notification to the user indicating that a set of prerequisite resources is to be configured in the second cloud environment in response to determining, based on the metadata information, that the set of prerequisite resources is not configured for the user in the second cloud environment; verifying, by the multi-cloud infrastructure, the set of prerequisite resources and user settings configured in the second cloud environment; and creating, by the multi-cloud infrastructure, a link resource object that includes information linking a tenancy of the user in the first cloud environment to the account of the user in the second cloud environment, the link resource object enabling the user to utilize the service provided by the multi-cloud infrastructure.

2. The method according to claim 1, wherein a first cloud infrastructure of the first cloud environment is provided by a first cloud service provider (CSP), and a second cloud infrastructure corresponding to the second cloud environment is provided by a second CSP different from the first CSP, and the first cloud environment is different from the second cloud environment.

3. The method according to claim 1 or 2, wherein the metadata information included in the request comprises an identifier of the user's account in the second cloud environment or the user's email address.

4. The method according to claim 1, 2, or 3, wherein the set of prerequisite resources comprises a hierarchy of resources, and each resource in the hierarchy of resources is associated with a corresponding role.

5. The method according to claim 4, wherein the hierarchy of roles associated with the hierarchy of resources comprises a networking role, an observability role, and a verifier role, and wherein the networking role allows creation of a network link between the first cloud environment and the second cloud environment, the observability role allows an observability module included in the multi-cloud infrastructure to publish data associated with resources deployed in the first cloud environment to the second cloud environment, and the verifier role allows a control plane of the multi-cloud infrastructure to perform user verification.

6. The method according to any one of the preceding claims, wherein the user settings comprise data corresponding to: (i) an identifier of a user pool in the second cloud environment, and (ii) membership information indicating that the user is a member of the user pool.

7. The method according to any one of the preceding claims, further comprising: obtaining, by the multi-cloud infrastructure, an access token from the second cloud environment in response to the user successfully configuring the set of prerequisite resources in the second cloud environment; and triggering, by the multi-cloud infrastructure, a cloud link adapter to perform the creation.

8. The method according to any one of the preceding claims, wherein the request from the user is received by a registration API associated with a multi-cloud console of the multi-cloud infrastructure.

9. The method according to any one of the preceding claims, further comprising: creating, by the multi-cloud infrastructure, a network link communicatively coupling the tenancy of the user in the first cloud environment to the account of the user in the second cloud environment.

10. The method according to any one of the preceding claims, wherein the service is one of the following: Exa Database Service, Shared Autonomous Database Service, Dedicated Autonomous Database Service, or Virtual Machine Database Service.

11. One or more computer-readable non-transitory media storing computer-executable instructions, which when executed by one or more processors, cause: a multi-cloud infrastructure included in a first cloud environment to receive a request from a user associated with an account in a second cloud environment, the request requesting the user to register for a service provided by the multi-cloud infrastructure and including metadata information associated with the user; in response to determining, based on the metadata information, that a set of prerequisite resources is not configured for the user in the second cloud environment, the multi-cloud infrastructure to transmit a notification to the user, the notification indicating that the set of prerequisite resources is to be configured in the second cloud environment; the multi-cloud infrastructure to verify the set of prerequisite resources and user settings configured in the second cloud environment; and the multi-cloud infrastructure to create a link resource object, the link resource object including information that links the user's lease in the first cloud environment to the user's account in the second cloud environment, the link resource object enabling the user to utilize the service provided by the multi-cloud infrastructure.

12. The one or more computer-readable non-transitory media storing computer-executable instructions according to claim 11, wherein the first cloud infrastructure of the first cloud environment is provided by a first cloud service provider (CSP), and the second cloud infrastructure corresponding to the second cloud environment is provided by a second CSP different from the first CSP, and the first cloud environment is different from the second cloud environment.

13. The one or more computer-readable non-transitory media storing computer-executable instructions according to claim 11 or 12, wherein the metadata information included in the request includes an identifier of the user's account in the second cloud environment or the user's email address.

14. The one or more computer-readable non-transitory media storing computer-executable instructions according to claim 11, 12, or 13, wherein the set of prerequisite resources includes a hierarchy of resources, and each resource in the hierarchy of resources is associated with a corresponding role.

15. The one or more computer-readable non-transitory media storing computer-executable instructions according to claim 14, wherein the hierarchy of roles associated with the hierarchy of resources includes a networking role, an observability role, and a verifier role, and wherein the networking role allows creation of a network link between the first cloud environment and the second cloud environment, the observability role allows an observability module included in the multi-cloud infrastructure to publish data associated with resources deployed in the first cloud environment to the second cloud environment, and the verifier role allows the control plane of the multi-cloud infrastructure to perform user verification.

16. One or more computer-readable non-transitory media storing computer-executable instructions as recited in any one of claims 11 to 15, wherein the user settings include data corresponding to the following: (i) an identifier of a user pool in a second cloud environment, and (ii) membership information indicating that the user is a member of the user pool.

17. One or more computer-readable non-transitory media storing computer-executable instructions as recited in any one of claims 11 to 16, further comprising: obtaining, by the multi-cloud infrastructure, an access token from the second cloud environment in response to the user successfully configuring the set of prerequisite resources in the second cloud environment; and triggering, by the multi-cloud infrastructure, a cloud link adapter to perform the creation.

18. One or more computer-readable non-transitory media storing computer-executable instructions as recited in any one of claims 11 to 17, wherein the request from the user is received by a registration API associated with a multi-cloud console of the multi-cloud infrastructure.

19. One or more computer-readable non-transitory media storing computer-executable instructions as recited in any one of claims 11 to 18, further comprising: creating, by the multi-cloud infrastructure, a network link communicatively coupling a lease of the user in the first cloud environment to an account of the user in the second cloud environment.

20. A computing device, comprising: one or more processors; and a memory including instructions that, when executed by the one or more processors, cause the computing device to at least: receive, by the multi-cloud infrastructure included in the first cloud environment, a request from a user associated with an account in the second cloud environment, the request requesting the user to register for services provided by the multi-cloud infrastructure and including metadata information associated with the user; transmit, by the multi-cloud infrastructure, a notification to the user indicating that the set of prerequisite resources is to be configured in the second cloud environment in response to determining, based on the metadata information, that the set of prerequisite resources has not been configured for the user in the second cloud environment; verify, by the multi-cloud infrastructure, the set of prerequisite resources and user settings configured in the second cloud environment; and create, by the multi-cloud infrastructure, a link resource object including information that links a lease of the user in the first cloud environment to an account of the user in the second cloud environment, the link resource object enabling the user to utilize services provided by the multi-cloud infrastructure.

Citation Information

Cited By

  • Private cloud dynamic permission generation system and method

    CN120729643A

  • A private cloud dynamic permission generation system and method

    CN120729643B