Home Region Switching
Patent Information
- Application Number
- JP2024525431
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-27
- Filing Date
- 2022-10-28
- Publication Date
- 2025-07-09
AI Technical Summary
Cloud service providers face challenges in synchronizing write operations between data centers when switching a customer's home region, leading to potential delays and loss of write operations due to data center unavailability, which affects the customer experience and data integrity.
A method and system for reassigning a cloud service provider's customer home region by updating identity control planes in both the source and target data centers, ensuring synchronized write operations and maintaining data integrity during the switch, with mechanisms for handling unavailability and discrepancies.
Enables seamless reassignment of home regions, ensuring consistent and synchronized write operations across data centers, reducing the risk of data loss and improving customer experience by allowing on-the-fly domain home region switching.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 63 / 273,811, entitled "HOME REGION SWITCH," filed on October 29, 2021, and U.S. Patent Application No. 18 / 050,455, entitled "HOME REGION SWITCH," filed on October 27, 2022, the entire disclosures of which are incorporated herein by reference.
[0002] Field The present disclosure relates to a framework for switching home regions for customers of a cloud service provider. [Background technology]
[0003] background Cloud service providers (CSPs) use one or more networks to provide a variety of services to their customers on demand. Each customer can have an account that specifies the services the customer can access and use. Customers can register in one or more regions, and when registered, they can use the services provided by the data center in the location where the customer is registered.
[0004] An account associated with a customer may have a defined home region. Services provided by data centers in the home region may be able to perform write operations to a domain (such as an ID domain), while services provided by data centers in other regions may not be able to perform write operations to the domain. The home region is typically defined as one of the regions in which the customer is registered upon opening of the customer's account.
[0005] However, a customer may wish to reassign a home region, such as when the datacenter of the home region becomes unavailable for some reason. When switching a domain home region from a first datacenter to a second datacenter, write operations between the first and second datacenters may not be synchronized in time. For example, there may be a time delay between the first and second datacenters such that a write operation may be performed in one datacenter but not in the other datacenter. Furthermore, if one datacenter is unavailable when switching to the other datacenter, the unavailable datacenter may not receive the write operation that is provided to the available datacenter. Summary of the Invention
[0006] overview The present disclosure generally relates to techniques for reassigning a home region from a first region to a second region. Various embodiments are described herein, including methods, systems, non-transitory computer-readable media that store programs, codes, or instructions that one or more processors may execute, and the like. These exemplary embodiments are mentioned to provide examples that aid in the understanding of the disclosure, and are not intended to limit or define the disclosure. Additional embodiments are discussed and detailed descriptions are provided in the detailed description section.
[0007] One aspect of the disclosure is directed to a method, the method may include receiving a request by a first datacenter of a cloud service provider (CSP) located in a first geographic region, the request being a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of the cloud service provider indicated in the request, the datacenter corresponding to the home region assignment being capable of performing a write operation to the domain. The method may further include updating a first identity control plane (IDCP) of the first datacenter to indicate that the home region assignment of the account is assigned to the designated datacenter, the designated datacenter being capable of performing a write operation to the domain in response to at least the first identity control plane being updated, the method may further include updating a second identity control plane of a second datacenter of the cloud service provider located in a second geographic region to indicate that the home region assignment is assigned to the designated datacenter. The method may further include causing the first datacenter to provide an indication that the home region assignment is assigned to the designated datacenter.
[0008] An aspect of the disclosure is directed to one or more non-transitory computer-readable media having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations, the operations including receiving a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of a cloud service provider (CSP) indicated in the request, the datacenter corresponding to the home region assignment capable of performing a write operation to the domain. The operations may further include updating a first identity control plane (IDCP) of a first datacenter of the cloud service provider located in a first geographical region to indicate that the home region assignment of the account is assigned to the designated datacenter, the designated datacenter being capable of performing a write operation to the domain in response to at least the first identity control plane being updated, the operations may further include updating a second identity control plane of a second datacenter of the cloud service provider located in a second geographical region to indicate that the home region assignment is assigned to the designated datacenter. The operations may further include causing an indication that the home region assignment is assigned to the designated datacenter.
[0009] One aspect of the disclosure is directed to a first datacenter of a cloud service provider located in a first geographic region, the first datacenter comprising a memory storing a domain and one or more processors coupled to the memory. The one or more processors may be adapted to receive a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of a cloud service provider (CSP) indicated in the request, the datacenter corresponding to the home region assignment capable of performing a write operation to the domain. The one or more processors may further be adapted to update a first identity control plane (IDCP) of the first datacenter to indicate that the home region assignment of the account is assigned to the designated datacenter, the designated datacenter capable of performing a write operation to the domain in response to at least the first identity control plane being updated, and the one or more processors may further be adapted to update a second identity control plane of a second datacenter of the cloud service provider located in a second geographic region to indicate that the home region assignment is assigned to the designated datacenter. The one or more processors may further be adapted to cause an indication that the home region assignment is assigned to the designated datacenter to be presented.
[0010] The above, together with other features and embodiments, will become more apparent with reference to the following specification, claims, and accompanying drawings. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 illustrates an exemplary cloud service provider (CSP) configuration, according to at least one embodiment. [Diagram 2] FIG. 2 illustrates another example CSP configuration according to at least one embodiment. [Diagram 3]FIG. 2 illustrates another example CSP configuration according to at least one embodiment. [Figure 4] FIG. 2 illustrates another example CSP configuration according to at least one embodiment. [Diagram 5] FIG. 2 illustrates a first portion of an example procedure for reallocating a home region assignment, according to at least one embodiment. [Figure 6] 6 illustrates a second portion of the example procedure of FIG. 5 according to at least one embodiment. [Figure 7] FIG. 1 is a block diagram illustrating a pattern for implementing a service-based cloud infrastructure system in accordance with at least one embodiment. [Figure 8] FIG. 2 is a block diagram illustrating another pattern for implementing a service-based cloud infrastructure system in accordance with at least one embodiment. [Figure 9] FIG. 2 is a block diagram illustrating another pattern for implementing a service-based cloud infrastructure system in accordance with at least one embodiment. [Figure 10] FIG. 2 is a block diagram illustrating another pattern for implementing a service-based cloud infrastructure system in accordance with at least one embodiment. [Figure 11] FIG. 1 is a block diagram illustrating an exemplary computer system according to at least one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Detailed Description In the following specification, various embodiments are described. For the purpose of explanation, specific configurations and details are described to enable a thorough understanding of the embodiments. However, it will be apparent to those skilled in the art that the embodiments may be realized without these specific details. Furthermore, well-known features may be omitted or simplified so as not to obscure the description of the embodiments.
[0013] A Cloud Service Provider (CSP) may offer multiple cloud services to its subscribing customers. These services may be delivered in a variety of models, such as Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS) models.
[0014] In a cloud environment, an identity management system is typically provided by a CSP to control user access to resources provided or used by the cloud service. Typical services or functions provided by an identity management system include, but are not limited to, single sign-on functionality for users, authentication and authorization services, and other identity-based services.
[0015] The resources protected by an identity management system can be of many different types, such as computer instances, block storage volumes, virtual cloud networks (VCNs), subnets, route tables, various callable APIs, internal or legacy applications, etc. These resources include resources stored in the cloud and / or resources on customer premises. Each resource is typically identified by a unique identifier (e.g., ID) that is assigned when the resource is created.
[0016] A CSP may provide two or more separate and independent identity management systems for cloud services. This may be done, for example, where a first identity management system or platform (e.g., Infrastructure Identity and Access Management (IAM)) is provided for controlling access to cloud resources for IaaS applications and services provided by the CSP. Separately, a second identity management system or platform (e.g., ID Cloud Service (IDCS)) may be provided for security and identity management for SaaS and PaaS services provided by the CSP.
[0017] As a result of offering these two separate platforms, a CSP's customer, when subscribing to both SaaS or PaaS and IaaS services offered by the CSP, typically has two separate accounts (one with IAM for the IaaS subscription and one with IDCS for the PaaS / SaaS subscription). Each account has its own credentials, such as user login, password, etc. Thus, the same customer has two separate sets of credentials for the two accounts, resulting in an unsatisfactory customer experience. Also, having two separate identity management systems creates obstacles to interactions between SaaS / PaaS and IaaS services.
[0018] For purposes of this application, the two platforms will be referred to as IAM and IDCS, by way of example, but these names and terms are not intended to be limiting in any way. The teachings of this disclosure apply to any situation in which two (or more) different identity management systems are integrated. The integrated identity management systems, services, or platforms may be provided by one or more CSPs.
[0019] In one embodiment, an integrated identity management platform (referred to as IIMS (Integrated Identity Management System)) is provided that integrates two separate (e.g., IAM and IDCS) platforms transparently to users or customers of the cloud service while retaining and providing various features and functions provided by the multiple identity management platforms (e.g., IAM and IDCS platforms). Such integration improves the user experience to be more seamless.
[0020] However, such integration is technically very challenging for multiple reasons. The two platforms may use different procedures and protocols to perform identity-related functions. IAM may be, for example, an attribute-based access control (ABAC) system, also known as a policy-based access control system, which specifies an access control paradigm in which access rights are granted to users through the use of policies expressing complex Boolean rule sets that may evaluate many different attributes. The purpose of ABAC is to protect objects such as data, network devices, and IT resources from unauthorized users and actions that do not have the "authorization" characteristics as specified by the organization's security policy. On the other hand, IDCS may be a role-based access control (RBAC) system, which is an access control mechanism that does not rely on policies specified in terms of roles and permissions. Components of RBAC (such as role authorization, user-role and role-role relationships) facilitate the execution of user assignments. Yet another reason is that the authentication and authorization frameworks or workflows used by the two platforms (for example, types of tokens used, various authentication frameworks such as OAUTH) may be different. This is just a few of the reasons why providing an integrated solution is technically very challenging.
[0021] Described herein are techniques for customers and / or clients (collectively referred to as customers throughout this disclosure) to switch home regions of a CSP. For example, a CSP may include one or more data centers (which may also be referred to as regions), each of which may be located in a corresponding geographic area served by the CSP. For example, a first data center may be located in a first geographic area served by the CSP and a second data center may be located in a second geographic area served by the CSP, the second geographic area being different from the first geographic area. Each data center may include computer hardware and / or software that may provide one or more services to the customer. A data center may include one or more domains, such as an identity domain. In some embodiments, a domain may include a container that includes data (such as data indicative of access information for the customer and / or services that may be provided to the customer).
[0022] Any given domain may be replicated in multiple datacenters within a CSP. A customer may have a home region (sometimes referred to as a domain home region) defined for a domain, which gives the customer more authority over the domain than other regions. For example, a domain's home region may be a datacenter where updates to customer identity related information (users, groups, apps, etc.) are allowed. A customer may want to switch the home region of this domain to one of the datacenters where the domain is replicated. For example, a customer may request the CSP to switch the domain home region from a first datacenter to a second datacenter. A customer may request to switch the domain home region from a first datacenter to a second datacenter when both the first datacenter and the second datacenter are available, when the first datacenter is unavailable (e.g., the datacenter may be down or services in the datacenter may be inaccessible) and the second datacenter is available, or when the first datacenter is available and the second datacenter is unavailable. According to various embodiments, the CSP switches a customer's domain home region based on a request from the customer. In particular, the domain home region may be specified in an identity control plane (IDCP) (which may be a distributed command line interface) of a datacenter that indicates the datacenter corresponding to the domain home region. The CSP may update the IDCPs of the first datacenter and the second datacenter to indicate that the second datacenter is the new domain home region. Thus, the CSP enables the customer to switch domain home regions, and in some embodiments, may enable the customer to switch domain home regions on the fly.
[0023] In some embodiments, the CSP may limit the number of times a domain home region can be switched, such as limiting a maximum number of switches for a customer within a period of time. For example, the CSP may keep a count of the number of domain home region switches requested within the current period for a given customer and prevent further domain home region switches if the number of domain home region switches exceeds a maximum number of switches within the current period.
[0024] When switching a domain home region from a first data center to a second data center, write operations between the first data center and the second data center may not be synchronized in time. For example, there may be a time delay between when a write operation is performed to the domain of the first data center and when the replication domain of the second data center is updated, such that a write operation may be performed in the domain of the first data center but not in the replication domain of the second data center. Furthermore, if the first data center is unavailable upon switching of the domain home region to the second data center, the first data center may not be able to replicate to the domain of the first data center a write operation performed to the domain of the second data center based on the unavailability of the first data center. In some embodiments, the CSP may indicate to the customer that one or more write operations may have been lost during the switchover period, which may indicate to the customer that one or more write operations may be repeated upon completion of the switchover and / or which write operations may be repeated. In some embodiments, the CSP may perform reconciliation between the first datacenter and the second datacenter after the switch is completed and / or after any of the datacenters that were unavailable during the switch become available. For example, the CSP may compare snapshots of the first datacenter and the second datacenter to determine what write operations, if any, are missing from one of the datacenters and whether write operations should be added to the datacenter that is missing the write operations. Thus, the CSP may be able to accommodate any write operations that are missing due to the domain home region switch.
[0025] 1 illustrates an exemplary CSP configuration 100 according to at least one embodiment. The CSP configuration 100 illustrates an example of a portion of a CSP that may provide services to customers. The CSP may be accessed by one or more customer devices to utilize the services that the CSP offers.
[0026] The CSP configuration 100 may include a CSP 102. The CSP may comprise a network of computer hardware implementing software that may provide services to customers. The computer hardware and / or software of the CSP 102 may also be referred to as resources, where customers may utilize or request resources to perform operations. The CSP 102 may include an IAM, where the IAM may control user access to the CSP 102.
[0027] The hardware and / or software of the CSP 102 may be separated into one or more data centers. Each of the data centers may be located in a corresponding geographic region. For example, the CSP 102 may include a first data center 104 and a second data center 106. The first data center may be located in a first geographic region and the second data center may be located in a second geographic region, the second geographic region being different from the first geographic region. Each of the data centers may include computer hardware and software to provide services to customers. In some embodiments, each of the data centers may include one or more servers.
[0028] A data center may store one or more domains. In some cases, one or more domains may be replicated in multiple regions. For example, multiple data centers in different regions may store copies of the same domain. In the illustrated embodiment, a first data center 104 may store a first copy 108 of a domain, and a second data center 106 may store a second copy 110 of the domain.
[0029] The CSP configuration 100 may include a gateway 112. The gateway 112 may be coupled to one or more data centers of the CSP 102. The gateway 112 provides access to the data center to which the gateway 112 is coupled. In the illustrated embodiment, the gateway 112 is coupled to a first data center 104 and a second data center 106. The gateway 112 may be capable of establishing a connection between a customer device and a region. The data centers coupled to the gateway 112 may correspond to unique Domain Name System (DNS) addresses. For example, the first data center 104 may correspond to a first DNS address and the second data center 106 may correspond to a second DNS address. The gateway 112 may be responsive to receiving a request from a device indicating a DNS address to establish a connection between the device and the data center corresponding to the DNS address.
[0030] The CSP configuration 100 may include a customer device 114. The customer device 114 may include a computing device. The customer device 114 may be operated by a customer. The customer may be registered with one or more data centers of the CSP 102. For example, in the illustrated embodiment, the customer may be registered with the first data center 104 and the second data center 106. The customer may be able to use one or more of the services offered by the data centers with which the customer is registered. For example, the customer may be able to use one or more of the services offered by the first data center 104 and the second data center 106. The CSP 102 may maintain an account indicating the data center with which the customer is registered and / or additional information associated with the customer. The account may further include information available for authenticating the customer's access to the CSP 102.
[0031] Each customer may have a defined home region. In particular, a customer may have one of the registered datacenters assigned a home region assignment that defines the customer's home region. In conventional approaches, a home region is assigned at the time of account creation and cannot be reassigned by the customer after the account is created. A customer's home region may enable different permissions than other regions. For example, a home region may be a datacenter where the customer can perform write operations to one or more defined domains, while other datacenters may be prevented from performing write operations to one or more defined domains. In the illustrated embodiment, the customer has a first datacenter 104 defined as a home region. In this example, the customer is restricted by the first datacenter 104 to perform write operations to the first copy 108 of the domain based on the first datacenter 104 being defined as the home region. Additionally, the customer is prevented by the second datacenter 106 from performing write operations to the second copy 110 of the domain based on the second datacenter 106 not being assigned a home region. However, a customer may wish to reassign the home region if, for example, the first data center 104 becomes unavailable for some reason.
[0032] A customer may send a request to reallocate a home region from the first data center 104 to the second data center 106 via a customer device 114. The customer device 114 may send the request to the gateway 112 along with a DNS address corresponding to a data center that will perform the home region allocation reallocation. For brevity, the first data center 104 is described herein as performing the home region allocation reallocation, however, it is understood that the home region allocation reallocation may be performed by another data center of the CSP 102 (such as the second data center 106) in the same manner as the first data center 104 performs the home region allocation reallocation as described herein.
[0033] For example, in the described embodiment, the DNS address sent with the request may correspond to the first data center 104. The gateway 112 may receive the request from the customer device 114. The gateway 112 may determine that the request should be provided to the first data center 104 based on the DNS address corresponding to the first data center 104 included with the request. The gateway 112 may provide the request to the first data center 104.
[0034] The first data center 104 may identify a request received from the gateway 112. Based on the request, the first data center 104 may determine that a home region assignment is to be reallocated from the first data center 104 to the second data center 106 such that the second data center 106 is assigned as the home region. The first data center 104 may have a first IDCP indicating the data center assigned as the customer's home region. In the illustrated embodiment, the first IDCP indicates that the first data center 104 is the home region. Based on the request, the first data center 104 may determine that the first IDCP is to be updated to indicate that the second data center 106 is the home region. The first data center 104 may update the first IDCP to indicate that the second data center 106 is the home region. The first data center 104 may prevent the customer from performing write operations to the first copy 108 of the domain after updating the first IDCP to indicate that the second data center 106 is the home region.
[0035] The second data center 106 may have a second IDCP indicating the data center assigned as the customer's home region. In the illustrated embodiment, the second IDCP may indicate that the first data center 104 is the home region. Based on the request, the first data center 104 may determine that the second IDCP is to be updated to indicate that the second data center 106 is the home region. The first data center 104 may update the second IDCP to indicate that the second data center 106 is the home region. According to various embodiments, the second data center 106 prevents the customer from performing write operations on the second copy of the domain 110 prior to updating the second IDCP and allows the customer to perform write operations on the second copy of the domain 110 once the second IDCP has been updated.
[0036] Based on the updated first IDCP and second IDCP, the first data center 104 may indicate to the customer that the home region has been updated to the second data center 106. For example, the first data center 104 may provide an indication to the gateway 112 that the reassignment of the home region is complete. For example, the first data center 104 may provide an indication that the assignment of the home region to the second data center 106 is complete. The gateway 112 may provide the indication to the customer device 114. The customer device 114 may display the indication that the home region has been updated to the second data center 106.
[0037] Thus, the CSP 102 has authorized the customer to update the customer's home region to the second data center 106. The first IDCP and the second IDCP may maintain the second data center 106 as the home region until another home region assignment is performed. Thus, the customer may continue to use the second data center 106 to perform write operations to the second copy 110 of the domain until another home region assignment is performed.
[0038] 2 illustrates another exemplary CSP configuration 200 according to at least one embodiment. CSP configuration 200 illustrates an example of a portion of a CSP that may provide services to customers. The CSP may be accessed by one or more customer devices to enable the customer devices to utilize the services that the CSP offers.
[0039] CSP configuration 200 may include a customer device 202. Customer device 202 may include one or more of the features of customer device 114 (FIG. 1). Customer device 202 may include a computing device. Customer device 202 may be used by a customer to access the CSP to utilize one or more services offered by the CSP. The CSP may maintain an account associated with the customer that may indicate services offered by the CSP that are available to the customer.
[0040] In the illustrated embodiment, the CSP may include a first data center 204, a second data center 206, and a third data center 208. The first data center 204, the second data center 206, and the third data center 208 may each include one or more of the features of the first data center 104 (FIG. 1) and / or the second data center 106 (FIG. 1). A customer utilizing a customer device 202 may be registered with one or more data centers of the CSP. In the illustrated embodiment, the customer may be registered with the first data center 204, the second data center 206, and the third data center 208. An account associated with the customer may indicate that the customer is registered with the first data center 204, the second data center 206, and the third data center 208.
[0041] Based on registration with the first data center 204, the second data center 206, and the third data center 208, the customer device 202 may be able to utilize one or more services provided by the first data center 204, the second data center 206, and the third data center 208. The CSP arrangement 200 may include a gateway 210. The gateway 210 may be coupled to the first data center 204, the second data center 206, and the third data center 208. The gateway 210 may facilitate access of the customer device 202 to the first data center 204, the second data center 206, and the third data center 208. The first data center 204, the second data center 206, and the third data center 208 may each be associated with a corresponding DNS address. For example, the first data center 204 may be associated with a first DNS address, the second data center 206 may be associated with a second DNS address, and the third data center may be associated with a third DNS address. The gateway 210 may be able to determine which data center the customer device 202 is attempting to access based on the DNS address provided by the information from the customer device 202. The gateway 210 may establish a connection between the customer device 202 and the data center based on the DNS address indicated by the customer device 202.
[0042] One or more of the data centers in which the customer is registered may store one or more domains associated with the customer. Additionally, a domain associated with a customer may be replicated in multiple data centers, with each data center in which the domain is replicated storing a copy of the domain. In the illustrated embodiment, the customer may have a domain replicated in a first data center 204, a second data center 206, and a third data center 208. In particular, the first data center 204 may store a first copy 212 of the domain, the second data center 206 may store a second copy 214 of the domain, and the third data center 208 may store a third copy 216 of the domain.
[0043] Each data center may have a corresponding IDCP. For example, the first data center 204 may have a first IDCP 218, the second data center 206 may have a second IDCP 220, and the third data center 208 may have a third IDCP 222. Although the IDCPs are shown separate from the corresponding data centers, it will be understood that in other embodiments, the IDCPs may be included in the corresponding data centers. The IDCPs may store information associated with customers.
[0044] A CSP may allow the definition of a single home region for a customer. The home region may be defined as a data center where the customer can perform write operations to one or more domains of the home region. Meanwhile, other data centers not assigned as the home region may be prevented from performing write operations to one or more domains requested by the customer. Each IDCP may store an indication of the data center that is assigned as the home region. In the illustrated embodiment, the first data center 204 may be defined as the home region. Thus, the first IDCP 218, the second IDCP 220, and the third IDCP 222 each store an indication that the first IDCP 218 is assigned as the home region.
[0045] The first data center 204, being assigned as the home region, may perform write operations requested by the customer device 202 to the first copy of the domain 212. The second data center 206 may be prevented from performing customer requested write operations to the second copy of the domain 214, and the third data center 208 may be prevented from performing write operations to the third copy of the domain 216. Thus, the customer may be able to request to perform write operations to the first copy of the domain 212, and may be prevented from directly performing the requested write operations to the second copy of the domain 214 and the third copy of the domain 216.
[0046] The home region may be able to update the replication domains of other data centers to match the copies of the domain stored in the home region. The home region may update the replication domains at set intervals, in response to a trigger, or some combination thereof. For example, the first data center 204, which is assigned as the home region in the illustrated embodiment, updates the second copy of the domain 214 and the third copy of the domain 216 to match the first copy of the domain 212. If updates can be performed at set intervals and / or in response to a trigger, the first copy of the domain 212 may differ from the second copy of the domain 214 and the third copy of the domain 216 based on a delay that may occur between the time the first data center 204 performs a write operation to the first copy of the domain 212 and the time the first data center 204 updates the second copy of the domain 214 and / or the third copy of the domain 216.
[0047] If a customer has only one home region and other datacenters are in limited operation, the customer may wish to reassign the home region assignment to a different datacenter and assign the other region as the home region. For example, the customer may wish to change the home region assignment if the datacenter assigned as the home region is unavailable (due to being updated, connectivity issues, and / or other system issues, etc.). As described in more detail throughout this disclosure, the CSP may enable the customer to reassign the home region assignment to a different datacenter. The CSP may enable the customer to reassign the home region assignment when all datacenters are available or when one or more of the datacenters (including the datacenter assigned as the home region) are unavailable. Enabling the customer to reassign the home region assignment may be beneficial to the customer.
[0048] In some embodiments, the CSP may limit home region reassignments performed by a customer. For example, the CSP may limit the number of times a customer reassigns a home region assignment within a certain period of time. In some of these embodiments, the CSP may allow a customer to reassign a home region assignment if the data center to which the home region assignment is currently assigned is unavailable, regardless of whether the customer has reassigned the home region assignment more than a threshold number of times.
[0049] 3 illustrates another exemplary CSP configuration 300 according to at least one embodiment. The CSP configuration 300 illustrates an example of a home region assignment reassignment with registered datacenters available.
[0050] CSP configuration 300 may include one or more of the features of CSP configuration 200 (FIG. 2). For example, CSP configuration 300 may include customer device 302. Customer device 302 may include one or more of the features of customer device 202 (FIG. 2). Customer device 302 may be utilized by a customer to access a CSP of CSP configuration 300. The CSP may maintain an account for the customer.
[0051] The CSP configuration 300 may include a CSP. In the illustrated embodiment, the CSP may include a first data center 304, a second data center 306, and a third data center 208. The first data center 304, the second data center 306, and the third data center 308 may include one or more of the features of the first data center 204 (FIG. 2), the second data center 206 (FIG. 2), and / or the third data center 208 (FIG. 2). In the illustrated embodiment, the first data center 304 may be assigned as a home region.
[0052] The first data center 304 may store a first copy 312 of the domain, the second data center 306 may store a second copy 314 of the domain, and the third data center 308 may store a third copy 316 of the domain. The first copy 312 of the domain, the second copy 314 of the domain, and the third copy 316 of the domain may include one or more of the characteristics of the first copy 212 of the domain (FIG. 2), the second copy 214 of the domain (FIG. 2), and / or the third copy 216 of the domain (FIG. 2). The first copy 312 of the domain, the second copy 314 of the domain, and the third copy 316 of the domain may be associated with a customer operating a customer device. The CSP may allow a customer request to perform write operations on the domain in the home region, while other regions may be restricted from performing operations on the domain by a customer request. Thus, while the first data center 304, because it is assigned as the home region, may allow customers to perform write operations to the first copy 312 of the domain, the second data center 306 may prevent customers from performing write operations to the second copy 314 of the domain, and the third data center 308 may prevent customers from performing write operations to the third copy 316 of the domain.
[0053] Each data center may have a corresponding IDCP. In the illustrated embodiment, the first data center 304 may have a first IDCP 318, the second data center 306 may have a second IDCP 320, and the third data center 308 may have a third IDCP 322. The first IDCP 318, the second IDCP 320, and the third IDCP 322 may each include one or more of the features of the first IDCP 218 (FIG. 2), the second IDCP 220 (FIG. 2), and / or the third IDCP 222 (FIG. 2). The IDCPs may each store information associated with a customer, such as the data center to which the customer's home region assignment is assigned.
[0054] A corresponding data center may access a corresponding IDCP to retrieve information associated with a customer. For example, in the illustrated embodiment, the first IDCP 318, the second IDCP 320, and the third IDCP 322 may store an indication that the customer's home region assignment is assigned to the first data center 304, thereby causing the first data center 304 to act as the customer's home region. The first data center 304 may access the first IDCP 318 to determine that the customer's home region assignment is assigned to the first data center 304, the second data center 306 may access the second IDCP 320 to determine that the customer's home region assignment is assigned to the first data center 304, and the third data center 308 may access the third IDCP 322 to determine that the customer's home region assignment is assigned to the first data center 304. Each datacenter may access a corresponding IDCP upon receiving a write operation request from a customer to determine which datacenter is assigned as the customer's home region. The datacenter may or may not execute the write operation request based on which datacenter is assigned as the home region. For example, the first datacenter 304 may access the first IDCP 318 to determine that the first datacenter 304 is assigned as the home region, and the first datacenter 304 may execute the requested write operation to the first copy 312 of the domain based on the first datacenter 304 being assigned as the home region. The second datacenter 306 may access the second IDCP 320 to determine that the first datacenter 304 is assigned as the home region, and the second datacenter 306 may prevent execution of the requested write operation to the second copy 314 of the domain based on the second datacenter 306 not being assigned as the home region.Additionally, the third data center 308 may access the third IDCP 322 to determine that the first data center 304 is assigned as a home region, and the third data center 308 may prevent performance of the requested write operation to the third copy of the domain 316 based on the third data center 308 not being assigned as a home region.
[0055] The CSP configuration 300 may include a gateway 310. The gateway 310 may include one or more of the features of the gateway 210 (FIG. 2). The gateway 310 may establish connections between the customer device 302 and the first data center 304, between the customer device 302 and the second data center 306, and between the customer device 302 and the third data center 308. The first data center 304, the second data center 306, and the third data center 308 may each be associated with a unique DNS address. For example, the first data center 304 may be associated with a first DNS address, the second data center 306 may be associated with a second DNS address, and the third data center 308 may be associated with a third DNS address. The gateway 310 may establish connections and / or route transmission signals according to DNS addresses included with the connection establishment request and / or transmission signals. For example, the gateway 310 may establish a connection and / or route transmission signals to a first data center 304 based on a first DNS address being provided, may establish a connection and / or route transmission signals to a second data center 306 based on a second DNS address being provided, and may establish a connection and / or route transmission signals to a third data center 308 based on a third DNS address being provided.
[0056] A customer may request a reallocation of a home region assignment. In the illustrated embodiment, a first data center 304, a second data center 306, and a third data center 308 may be available when a reallocation of a home region assignment is requested. For brevity, the reallocation of a home region assignment is described as being performed by the customer device 302 providing a request to the first data center 304 and the first data center 304 performing the reallocation of the home region assignment. It is to be understood that this procedure may be similarly performed by any of the available data centers (including the second data center 306 and the third data center 308). Furthermore, although this procedure is described as a reallocation of a home region assignment from the first data center 304 to the second data center 306, it is to be understood that in other examples, the home region assignment may be reallocated to any data center with which the customer is registered.
[0057] A customer may input a request into the customer device 302 to change and reallocate a home region assignment to one of the data centers with which the customer is registered. In the described embodiment, the customer may request a reallocation of the home region assignment to the second data center 306. The customer device 302 may generate a request transmission signal indicating that the home region assignment is to be reallocated to the second data center 306. In some embodiments, the request transmission signal may include a DNS address corresponding to a data center at which the home region assignment reallocation operation is intended to be performed. For example, the request transmission signal may include a first DNS address corresponding to the first data center 304. The customer device 302 may transmit the request transmission signal to the gateway 310.
[0058] The gateway 310 may establish a connection between the customer device 302 and the first data center 304, as indicated by the solid transmission line 324 between the gateway 310 and the first data center 304. The connection may have been previously established based on a request from the customer device 302 to establish a connection, or may be established based on a first DNS address corresponding to the first data center 304 included in a request transmission received from the customer device 302. The gateway 310 may provide a request transmission to the first data center 304 based on the connection.
[0059] The first data center 304 may receive a request transmission signal from the gateway 310. Based on the request transmission signal, the first data center 304 may determine that a home region assignment is to be reallocated to the second data center 306. In particular, because the first data center 304 is currently assigned as a home region, the first data center 304 may determine that a home region assignment is to be reallocated from the first data center 304 to the second data center 306.
[0060] Based on a determination that the home region assignment is reallocated to the second data center 306, the first data center 304 may update the first IDCP 318 to indicate that the second data center 306 is the home region. For example, the first data center 304 may access the first IDCP 318 to replace an indication that the home region assignment is assigned to the first data center 304 with an indication that the home region assignment is assigned to the second data center 306. In some embodiments, the first IDCP 318 may store a field having a value indicating the data center that is the home region, and a reallocation of the home region assignment may update the value of the field from a value corresponding to the first data center 304 to a value corresponding to the second data center 306. When updated, the first IDCP 318 may indicate to the first data center 304 that the home region when accessed by the first data center 304 is the second data center 306.
[0061] Prior to the update of the home region assignment to the second data center 306, the first data center 304 may have been assigned as the home region. The first data center 304 may have been able to perform write operations by customers to the first copy 312 of the domain while assigned as the home region. Once the first IDCP 318 is updated to indicate that the second data center 306 is assigned as the home region, the first data center 304 may determine that it is no longer the home region based on access to the first IDCP 318. While the first data center 304 is not assigned as the home region, it may be prevented from performing write operations by customers to the first copy 312 of the domain. Thus, the first data center 304 may be prevented from performing write operations by customers to the first copy 312 of the domain in response to the first IDCP 318 being updated to indicate that the home region assignment is assigned to the second data center 306.
[0062] The first data center 304 may also update the second IDCP 320 to indicate that the second data center 306 is assigned as the home region. For example, the first data center 304 may send a request to the second IDCP 320 to reallocate the home region assignment to the second data center 306. In some embodiments, the first data center 304 may send the request to the second IDCP 320 via the second data center 306. An indication stored in the second IDCP 320 that the home region assignment is assigned to the first data center 304 may be updated to indicate that the home region assignment is assigned to the second data center 306. In some embodiments, the second IDCP 320 may store a field indicating the data center to which the home region assignment is assigned, and the update updates the value of the field from a value corresponding to the first data center 304 to a value corresponding to the second data center 306.
[0063] Prior to the update of the home region assignment to the second data center 306, the second data center 306 may not have been assigned as a home region. While the second data center 306 was not assigned as a home region, the customer may have been prevented from performing write operations to the second copy of the domain 314. Once the second IDCP 320 is updated to indicate that the second data center 306 is assigned as a home region, the second data center 306 may be determined to have become a home region based on access to the second IDCP 320. While the second data center 306 is assigned as a home region, the second data center 306 may be capable of performing write operations to the second copy of the domain 314 by the customer. Thus, the second data center 306 may be capable of performing write operations to the second copy of the domain 314 by the customer in response to the second IDCP 320 being updated to indicate that the home region assignment is assigned to the second data center 306.
[0064] Additionally, the first data center 304 may update the third IDCP 322 to indicate that the second data center 306 is assigned as the home region. For example, the first data center 304 may send a request to the third IDCP 322 to reallocate the home region assignment to the second data center 306. In some embodiments, the first data center 304 may send the request to the third IDCP 322 via the third data center 308. The indication stored in the third IDCP 322 that the home region assignment is assigned to the first data center 304 may be updated to indicate that the home region assignment is assigned to the second data center 306. In some embodiments, the third IDCP 322 may store a field indicating the data center to which the home region assignment is assigned, and the update updates the value of the field from a value corresponding to the first data center 304 to a value corresponding to the second data center 306.
[0065] The first data center 304 may provide an indication to the customer device 302 that the reallocation of the home region assignment to the second data center 306 is complete. In some embodiments, the first data center 304 may provide this indication to the customer device 302 upon completion of updating the first IDCP 318. In other embodiments, the first data center 304 may provide this indication to the customer device 302 in response to the first IDCP 318, the second IDCP 320, and the third IDCP 322 all being updated. For example, the first data center 304 may wait to receive an indication from the second IDCP 320 and the third IDCP 322 that the reallocation of the home region assignment is complete and provide the indication to the customer device 302. In response to receiving the indication, the customer device 302 may display an indication to the customer that the reallocation of the home region assignment is complete. In other embodiments, the indication that the home region reassignment is complete may be omitted.
[0066] 4 illustrates another example CSP configuration 400 according to at least one embodiment. CSP configuration 400 illustrates an example of home region assignment reassignment in the event that some of the registered data centers are unavailable.
[0067] CSP configuration 400 may include one or more of the features of CSP configuration 200 (FIG. 2) and / or CSP configuration 300 (FIG. 3). For example, the CSP configuration may include customer device 402. Customer device 402 may include one or more of the features of customer device 202 (FIG. 2) and / or customer device 302 (FIG. 3). Customer device 402 may be utilized by a customer to access a CSP of CSP configuration 400. The CSP may maintain an account for the customer.
[0068] The CSP configuration 400 may include a CSP. In the illustrated embodiment, the CSP may include a first data center 404, a second data center 406, and a third data center 408. The first data center 404, the second data center 406, and the third data center 408 may include one or more of the features of the first data center 204 (FIG. 2), the first data center 304 (FIG. 3), the second data center 206 (FIG. 2), the second data center 306 (FIG. 3), the third data center 208 (FIG. 2), and / or the third data center 308 (FIG. 3). In the illustrated embodiment, the first data center 404 may be assigned as a home region. Additionally, in the illustrated embodiment, the first data center 404 may be unavailable, as indicated by an "X" on the first data center 404. Thus, the customer device 402 , the second data center 406 , and the third data center 408 may be inaccessible to the first data center 404 .
[0069] The first data center 404 may store a first copy of the domain 412, the second data center 406 may store a second copy of the domain 414, and the third data center 408 may store a third copy of the domain 416. The first copy of the domain 412, the second copy of the domain 414, and the third copy of the domain 416 may include one or more of the features of the first copy of the domain 212 (FIG. 2), the first copy of the domain 312 (FIG. 3), the second copy of the domain 214 (FIG. 2), the second copy of the domain 314 (FIG. 3), the third copy of the domain 216 (FIG. 2), and / or the third copy of the domain 316 (FIG. 3). The first copy of the domain 312, the second copy of the domain 314, and the third copy of the domain 316 may be associated with a customer operating a customer device.
[0070] The CSP may allow a customer to request write operations to the domain in the home region, while the other regions may be restricted from performing operations on the domain at the customer's request. Thus, the first data center 404 may be assigned as the home region and therefore may allow the customer to perform write operations on the first copy 412 of the domain, while the second data center 406 may be prevented from performing write operations on the second copy 414 of the domain, and the third data center 408 may be prevented from performing write operations on the third copy 416 of the domain. In the illustrated embodiment, the customer device 402 may be prevented from performing any write operations on the domain because the first data center 404 is unavailable yet assigned as the home region. In particular, the customer device 402 may be unable to access the first data center 404 because the first data center 404 is unavailable, and the first data center 404 may be unable to receive requests from the customer device 402 to perform write operations. Furthermore, based on neither the second data center 406 nor the third data center 408 being assigned as a home region, the customer device 402 may be prevented by the second data center 406 and the third data center 408 from performing write operations to the second copy of the domain 414 and the third copy of the domain 416, respectively. Thus, the customer may be unable to perform writes to the domain while the first data center 404 is unavailable, which may cause inconvenience to the customer.
[0071] Each data center may have a corresponding IDCP. In the illustrated embodiment, the first data center 404 may have a first IDCP 418, the second data center 406 may have a second IDCP 420, and the third data center 508 may have a third IDCP 422. The first IDCP 418, the second IDCP 420, and the third IDCP 422 may each include one or more of the features of the first IDCP 218 (FIG. 2), the first IDCP 318 (FIG. 3), the second IDCP 220 (FIG. 2), the second IDCP 320 (FIG. 3), the third IDCP 222 (FIG. 2), and / or the third IDCP 322 (FIG. 3). Each IDCP may store information associated with the customer, such as the data center to which the home region assignment is assigned. In the illustrated embodiment, the first IDCP 418 may be unavailable. Thus, the customer device 402, the second data center 406, and the third data center 408 may be unable to access the first IDCP 418 while the first IDCP 418 is unavailable.
[0072] A corresponding data center may access a corresponding IDCP to retrieve information associated with the customer. For example, in the illustrated embodiment, the first IDCP 418, the second IDCP 420, and the third IDCP 422 may store an indication that a home region assignment has been assigned to the first data center 404, thereby assigning the first data center 404 as a home region. The first data center 404 may access the first IDCP 318 to determine that a home region assignment has been assigned to the first data center 404, the second data center 406 may access the second IDCP 320 to determine that a home region assignment has been assigned to the first data center 404, and the third data center 408 may access the third IDCP 422 to determine that a home region assignment has been assigned to the first data center 404. Each datacenter may access its corresponding IDCP upon receiving a write operation request to determine which datacenter is assigned as a home region. The datacenter may or may not execute the write operation request based on which datacenter is assigned as a home region. For example, the first datacenter 404 may access the first IDCP 418 to determine that the first datacenter 404 is assigned as a home region, and the first datacenter 404 may execute the requested write operation to the first copy of the domain 412 based on the first datacenter 404 being assigned as the home region. The second datacenter 406 may access the second IDCP 420 to determine that the first datacenter 404 is assigned as a home region, and the second datacenter 406 may prevent execution of the requested write operation to the second copy of the domain 414 based on the second datacenter 406 not being assigned as a home region.Additionally, the third data center 408 may access the third IDCP 422 to determine that the first data center 404 is assigned as a home region, and the third data center 408 may prevent performance of the requested write operation to the third copy of the domain 416 based on the third data center 408 not being assigned as a home region.
[0073] The CSP configuration 400 may include a gateway 410. The gateway 410 may include one or more of the features of the gateway 210 (FIG. 2) and / or the gateway 310 (FIG. 3). The gateway 410 may establish connections between the customer device 402 and the first data center 404, between the customer device 402 and the second data center 406, and between the customer device 402 and the third data center 408. The first data center 404, the second data center 406, and the third data center 408 may each be associated with a unique DNS address. For example, the first data center 404 may be associated with a first DNS address, the second data center 406 may be associated with a second DNS address, and the third data center 408 may be associated with a third DNS address. The gateway 410 may establish connections and / or route transmission signals according to DNS addresses included with the connection establishment request and / or transmission signals. For example, the gateway 410 may establish a connection and / or route transmission signals to a first data center 404 based on a first DNS address being provided, may establish a connection and / or route transmission signals to a second data center 406 based on a second DNS address being provided, and may establish a connection and / or route transmission signals to a third data center 408 based on a third DNS address being provided.
[0074] A customer may request a reallocation of a home region assignment. In the illustrated embodiment, when a reallocation of a home region assignment is requested, the first datacenter 404 may be unavailable while the second datacenter 406 and the third datacenter 408 may be available. For brevity, the reallocation of a home region assignment is described as being performed by the customer device 402 providing a request to the second datacenter 406 and the second datacenter 406 performing the reallocation of the home region assignment. It is to be understood that this procedure may be performed by any of the available datacenters as well, including the third datacenter 408. Furthermore, although this procedure is described as a reallocation of a home region assignment from the first datacenter 404 to the second datacenter 406, it is to be understood that in other examples, the home region assignment may be reallocated to any datacenter with which the customer is registered.
[0075] A customer may input a request into the customer device 402 to change and reallocate a home region assignment to one of the data centers with which the customer is registered. In the described embodiment, the customer may request a reallocation of the home region assignment to a second data center 406. The customer device 402 may generate a request transmission signal indicating that the home region assignment is to be reallocated to the second data center 406.
[0076] In some embodiments, the customer device 402 may display an option to switch the home region to another data center based on one or more of the data centers becoming unavailable. For example, the customer device 402 may display an option to switch the home region to another data center in response to an assigned data center becoming unavailable. In the illustrated embodiment, the customer device 402 may display an option to switch the home region from the first data center 404 in response to the first data center 404 becoming unavailable. The customer device 402 may have a connection to the home region or one of the other data centers in the event that the first data center 404 becomes unavailable, which may also enable the display of the option. In some of these embodiments, the option may provide a list of other data centers in which the customer is registered and to which the home region assignment can be assigned. The customer may select a data center from the list to indicate the data center to which the home region assignment will be reassigned. In other of these embodiments, the customer may have one or more data centers predefined as a backup home region. The options may indicate one or more of these datacenters. If one datacenter is predefined, the options may allow the customer to select whether to reassign the home region assignment to the predefined datacenter. If more than one datacenter is predefined, the options may display a list of the predefined datacenters and the customer may select from the list the datacenter to which the home region assignment will be reassigned. In the described embodiment, the customer device 402 may display an option to switch the home region to the second datacenter 406 in response to the first datacenter 404 becoming unavailable.
[0077] In some embodiments, the request transmission signal may include a DNS address corresponding to a data center where the home region assignment reallocation operation is intended to be performed. For example, the request transmission signal may include a second DNS address corresponding to the second data center 406. The customer device 402 may send the request transmission signal to the gateway 410.
[0078] The gateway 410 may establish a connection between the customer device 402 and the second data center 406, as indicated by the solid transmission line 424 between the gateway 410 and the second data center 406. The connection may have been previously established based on a request from the customer device 402 to establish a connection, or may be established based on a second DNS address corresponding to the second data center 406 included in a request transmission received from the customer device 402. The gateway 410 may provide a request transmission to the second data center 406 based on the connection.
[0079] The second data center 406 may receive a request transmission signal from the gateway 410. Based on the request transmission signal, the second data center 406 may determine that the home region assignment is to be reallocated to the second data center 406. In particular, because the first data center 404 is currently assigned as the home region, the second data center 406 may determine that the home region assignment is to be reallocated from the first data center 404 to the second data center 406.
[0080] Based on the determination that the home region assignment is reallocated to the second data center 406, the second data center 406 may update the second IDCP 420 to indicate that the second data center 406 is the home region. For example, the second data center 406 may access the second IDCP 420 to replace an indication that the home region assignment is assigned to the first data center 404 with an indication that the home region assignment is assigned to the second data center 406. In some embodiments, the second IDCP 420 may store a field having a value indicating the data center that is the home region, and a reallocation of the home region assignment may update the value of the field from a value corresponding to the first data center 404 to a value corresponding to the second data center 406. When updated, the second IDCP 420 may indicate to the second data center 406 that the home region when accessed by the second data center 406 is the second data center 406.
[0081] Prior to the update of the home region assignment to the second data center 406, the second data center 406 may not have been assigned as a home region. While the second data center 406 was not assigned as a home region, the customer may have been prevented from performing write operations to the second copy of the domain 414. Once the second IDCP 420 is updated to indicate that the second data center 406 is assigned as a home region, the second data center 406 may be determined to have become the home region based on access to the second IDCP 420. While the second data center 406 is assigned as a home region, the second data center 406 may be able to perform write operations to the second copy of the domain 414 by the customer. Thus, the second data center 406 may be able to perform write operations to the second copy of the domain 414 by the customer in response to the second IDCP 420 being updated to indicate that the home region assignment is assigned to the second data center 406.
[0082] In some embodiments, the second data center 406 may attempt to update the first IDCP 418 to indicate that the second data center 406 is assigned as the home region. In particular, the second data center 406 may attempt to update the first IDCP 418 upon request. The second data center 406 may not be able to update the first IDCP 418 on a first attempt because the first IDCP 418 is unavailable. In some of these embodiments, the second data center 406 may wait for an indication that the first IDCP 418 is available and update the first IDCP 418 in response to the indication that the first IDCP 418 is available. In other of these embodiments, the second data center 406 may reattempt to update the first IDCP 418 at set intervals and / or in response to one or more triggers until the first IDCP 418 is successfully updated.
[0083] In other embodiments, the second data center 406 may know that the first IDCP 418 is unavailable. In some of these embodiments, the second data center 406 may not initially attempt to update the first IDCP 418. For example, the second data center 406 may wait for an indication that the first IDCP 418 is available or until the end of a set interval or trigger before attempting to update the first IDCP 418. The second data center 406 may continually attempt to update the first IDCP 418 at set intervals and / or in response to triggers until it is successful in updating the first IDCP 418.
[0084] Once the first IDCP 418 is available, the second data center 406 may update the first IDCP 418 to indicate that the second data center 406 is the home region. For example, the second data center 406 may access the first IDCP 418 to replace an indication that the home region assignment is assigned to the first data center 404 with an indication that the home region assignment is assigned to the second data center 406. In some embodiments, the first IDCP 418 may store a field having a value indicating the data center that is the home region, and a reassignment of the home region assignment may update the value of the field from a value corresponding to the first data center 404 to a value corresponding to the second data center 406. When updated, the first IDCP 418 may indicate to the first data center 404 that the home region when accessed by the first data center 404 is the second data center 406.
[0085] Prior to the update of the home region assignment to the second data center 406, the first data center 404 may have been assigned as the home region. The first data center 404 may have been able to perform write operations by customers to the first copy of the domain 412 while assigned as the home region. Once the first IDCP 418 is updated to indicate that the second data center 406 is assigned as the home region, the first data center 404 may determine that it is no longer the home region based on access to the first IDCP 418. While the first data center 404 is not assigned as the home region, it may be prevented from performing write operations by customers to the first copy of the domain 412. Thus, the first data center 404 may be prevented from performing write operations by customers to the first copy of the domain 412 in response to the first IDCP 418 being updated to indicate that the home region assignment is assigned to the second data center 406.
[0086] Additionally, the second data center 406 may update the third IDCP 422 to indicate that the second data center 406 is assigned as the home region. For example, the second data center 406 may send a request to the third IDCP 422 to reallocate the home region assignment to the second data center 406. In some embodiments, the second data center 406 may send the request to the third IDCP 422 via the third data center 408. The indication stored in the third IDCP 422 that the home region assignment is assigned to the first data center 404 may be updated to indicate that the home region assignment is assigned to the second data center 406. In some embodiments, the third IDCP 422 may store a field indicating the data center to which the home region assignment is assigned, and the update updates the value of the field from a value corresponding to the first data center 404 to a value corresponding to the second data center 406.
[0087] The second data center 406 may provide an indication to the customer device 402 that the reallocation of the home region assignment to the second data center 406 is complete. In some embodiments, the second data center 406 may provide this indication to the customer device 402 upon completion of updating the second IDCP 420. In other embodiments, the second data center 406 may provide this indication to the customer device 402 in response to completion of updating all available IDCPs (which in the illustrated embodiment include the second IDCP 420 and the third IDCP 422). For example, the second data center 406 may wait to receive an indication from the third IDCP 422 that the reallocation of the home region assignment is complete before providing the indication to the customer device 402. In response to receiving the indication, the customer device 402 may display an indication to the customer that the reallocation of the home region assignment is complete. In other embodiments, the indication that the reallocation of the home region assignment is complete may be omitted.
[0088] The second data center 406 may further determine whether the copies of the domain match at the registered data center. For example, in some cases, there may be differences between the first copy of the domain 412, the second copy of the domain 414, and / or the third copy of the domain 416. The second data center 406 may determine whether differences exist between the first copy of the domain 412, the second copy of the domain 414, and the third copy of the domain 416. If a data center is unavailable during the reallocation of the home region assignment, the unavailable data center may be missing updates or write operations performed on the corresponding copy of the domain may not be replicated in the copies of the domain at the other data centers. In some embodiments, the home region may determine whether the copy of the domain at the home region matches the copy of the domain at the data center that was unavailable during the reallocation of the home region assignment. For example, in the illustrated embodiment, the second data center 406 may determine whether differences exist between the first copy of the domain 412 and the second copy of the domain 416 .
[0089] The home region may compare copies of the domain stored in the home region with copies of the domain stored in other available data centers in response to a reassignment of the home region assignment to the home region. For example, the second data center 406 may compare a state of the second copy of the domain 414 with a state of the third copy of the domain 416 in response to a home region assignment being assigned. In some embodiments, the second data center 406 may take a snapshot of the second copy of the domain 414 and a snapshot of the third copy of the domain 416. The second data center 406 may compare the snapshot of the second copy of the domain 414 and the snapshot of the third copy of the domain 416 to determine whether differences exist between the second copy of the domain 414 and the third copy of the domain 416.
[0090] In the event one or more datacenters are unavailable during the reallocation of the home region assignment, the home region may compare copies of the domain stored in the home region with copies of the domain stored in the unavailable datacenters after the datacenters become available. For example, the second datacenter 406 may compare the state of the second copy of the domain 414 with the state of the first copy of the domain 416 after the first datacenter 404 becomes available. In some embodiments, the second datacenter 406 may take a snapshot of the second copy of the domain 414 and a snapshot of the first copy of the domain 412 after the first datacenter 404 becomes available. The second datacenter 406 may compare the snapshot of the second copy of the domain 414 with the snapshot of the first copy of the domain 412 to determine if differences exist between the second copy of the domain 414 and the first copy of the domain 416.
[0091] If the home region is unavailable when the home region reassignment is performed, there may be differences between the copy of the domain stored in the home region and the copy of the domain stored in other data centers based on the home region reassignment performed while the home region was unavailable. For example, because the home region replicates the domain to other data centers at set intervals and / or in response to triggers, a write operation performed to the domain before the home region became unavailable may not have been replicated to the other data centers. Furthermore, after the home region reassignment, a write operation performed to the domain in the new home region may have occurred before the original home region becomes available again. Also, even after the IDCP of the available data center is updated to point to the new home region, the original home region may receive a write operation request before the IDCP corresponding to the original home region is updated by the other data centers. Because the IDCP corresponding to the original home region still indicates that the original home region was the home region prior to the update by the other data center, the original home region may erroneously determine that the home region assignment is still assigned based on the IDCP corresponding to the original home region still indicating that the original home region is the home region, and may erroneously perform a write operation on the copy of the domain stored in the original home region.
[0092] For example, in some cases, the first data center 404 may receive one or more write operation requests and perform the write operations on the first copy of the domain 412 before the first data center 404 becomes unavailable. However, the first data center 404 may become unavailable before replicating the write operations to the second copy of the domain 414 and the third copy of the domain 416. Thus, in these cases, the first copy of the domain 412 may differ from the second copy of the domain 414 and the third copy of the domain 416.
[0093] In some cases, the second data center 404 may receive one or more write operation requests and perform the write operations on the second copy of the domain 414 after the second IDCP 420 is updated and before the first data center 404 is available. Because the first data center 404 was unavailable, the second data center 406 could not replicate the write operations to the first copy of the domain 412. Thus, in these cases, the first copy of the domain 412 may differ from the second copy of the domain 414.
[0094] In some cases, the second data center 406 may receive one or more write operation requests and perform a write operation on the first copy of the domain 412 after the first data center 404 becomes available and before the second data center 406 updates the first IDCP 418. The write operation may not be performed on the second copy of the domain 414 and the third copy of the domain 416 because the second IDCP 420 and the third IDCP 422 do not indicate the first data center 404 as a home region and the second data center 406 and the third data center 408 may prevent the first data center 404 from replicating any write operations to the first copy of the domain 412. Thus, in these cases, the first copy of the domain 412 may differ from the second copy of the domain 414 and the third copy of the domain 416.
[0095] If the home region determines that differences exist between copies of the domain stored in the data center, the home region may consolidate the domains and / or write operations that caused the differences between the copies of the domain. The home region may perform one or more operations to consolidate the domains and / or write operations.
[0096] In some cases, the second data center 406 may determine that differences exist between the first copy of the domain 412, the second copy of the domain 414, and the third copy of the domain 416. In some embodiments, based on determining that differences exist, the second data center 406 may cause an indication of the differences to be displayed on the customer device 402 as part of the integration. Additionally, the customer device 402 may provide the customer with an option to select one of the copies of the domain to be utilized. Based on the customer's selection, the second data center 406 may cause the other data centers to replicate the selected copy of the domain. For example, the customer may select the second copy of the domain 414 as the copy of the domain to be utilized. The second data center 406 may cause the first copy of the domain 412 and the third copy of the domain 416 to replicate the second copy of the domain 414.
[0097] In some cases, the second data center 406 may determine that a difference exists between the first copy of the domain 412 and the second copy of the domain 414. The second data center 406 may determine that the difference is due to one or more write operations performed by the first data center 404 to the first copy of the domain 412 before the first data center 404 became unavailable but that have not been replicated to the second copy of the domain 414. The second data center 406 may determine write operations performed by the first data center 404 to the first copy of the domain 412 but that have not been replicated to the second copy of the domain 414. For example, the first data center 404 may store an indication of write operations performed to the first copy of the domain 412 and the second data center 406 may store an indication of write operations performed to the second copy of the domain 414. Based on these indicators, the second data center 406 may determine write operations that were performed to the domain first copy 412 but that were not replicated to the domain second copy 414.
[0098] In some embodiments, the second data center 406 may, as part of the consolidation, perform the identified write operations on the second copy of the domain 414 or may not perform the identified write operations on the second copy of the domain 414. In other embodiments, the second data center 406 may, as part of the consolidation, cause the customer device 402 to indicate the identified write operations. The customer device 402 may allow the customer to select whether all of the identified write operations are performed on the second copy of the domain 414, whether none of the identified write operations are performed on the second copy of the domain 414, or whether some of the identified write operations are performed on the second copy of the domain 414. The customer device 402 may indicate the customer's selection to the second data center 406, and the second data center 406 may or may not perform the write operations on the second copy of the domain 414 according to the customer's selection.
[0099] FIG. 5 illustrates a first portion of an example procedure 500 for reallocating home region assignments in accordance with at least one embodiment. FIG. 6 illustrates a second portion of the example procedure 500 in accordance with at least one embodiment. Execution of procedure 500 allows for the reallocation of home region assignments from one datacenter to another. The procedure may be performed by a datacenter, such as the first datacenter 204 (FIG. 2), the second datacenter 206 (FIG. 2), the third datacenter 208 (FIG. 2), the first datacenter 304 (FIG. 3), the second datacenter 306 (FIG. 3), the third datacenter 308 (FIG. 3), the first datacenter 404 (FIG. 4), the second datacenter 406 (FIG. 4), and / or the third datacenter 408 (FIG. 4).
[0100] At 502, a data center may receive a request to switch a home region assignment corresponding to an account. The data center may be a first data center of a CSP located in a first geographic region. The first data center may receive a request to switch a home region assignment corresponding to an account associated with the request to a designated data center of a cloud service provider (CSP) indicated in the request. The data center corresponding to the home region assignment may perform write operations to a domain, such as the first copy of domain 212 ( FIG. 2 ), the second copy of domain 214 ( FIG. 2 ), the third copy of domain 216 ( FIG. 2 ), the first copy of domain 312 ( FIG. 3 ), the second copy of domain 314 ( FIG. 3 ), the third copy of domain 316 ( FIG. 3 ), the first copy of domain 412 ( FIG. 4 ), the second copy of domain 414 ( FIG. 4 ), and / or the third copy of domain 416 ( FIG. 4 ).
[0101] In some embodiments, the first data center may receive a request from a customer device, such as customer device 202 (FIG. 2), customer device 302 (FIG. 3), and / or customer device 402 (FIG. 4). The customer device may generate the request based on a customer input of a request to reallocate a home region assignment from the first data center to a designated data center.
[0102] In some embodiments, the designated data center may include a first data center that may be prevented from performing write operations to a domain prior to an update of a first ID control plane (e.g., first IDCP 218 (FIG. 2), second IDCP 220 (FIG. 2), third IDCP 222 (FIG. 2), first IDCP 318 (FIG. 3), second IDCP 320 (FIG. 3), third IDCP 322 (FIG. 3), first IDCP 418 (FIG. 4), second IDCP 420 (FIG. 4), and / or third IDCP 422 (FIG. 4)) and may be capable of performing write operations to a domain in response to an update of at least the first ID control plane.
[0103] In some embodiments, the request may indicate that the home region assignment is to be switched from the second data center to the first data center, where the second data center may be unavailable at the time the request is received.
[0104] In some embodiments, the request may indicate that a home region assignment is to be switched from a first datacenter to a second datacenter. The first datacenter may update a first identity control plane at a first time and update a second identity control plane at a second time after the first time. The first datacenter may block write operations to the domain through the first datacenter between the first time and the second time. For example, the first datacenter may block write operations based on the first identity control plane being updated at the first time to indicate that the home region assignment is assigned to the second datacenter.
[0105] In some embodiments, the request to switch the home region assignment may be received based on a selection to switch the home region assignment from a user interface indicating that a third datacenter of the cloud service provider located in a third geographic region has become unavailable. The third datacenter may have been assigned a home region assignment prior to receipt of the request. For example, the customer device may display a user interface providing an option to switch the home region assignment. The customer device may display the user interface in response to the third datacenter becoming unavailable. The user interface may indicate that the third datacenter has become unavailable.
[0106] At 504, the first data center may update the first IDCP. For example, the first data center may update the first data center's first IDCP to indicate that the account's home region assignment is assigned to the designated data center. The designated data center may be capable of performing write operations to the domain in response to at least the first ID control plane being updated.
[0107] At 506, the first data center may update the second IDCP. For example, the second data center may update the second IDCP (e.g., first IDCP 218, second IDCP 220, third IDCP 222, first IDCP 318, second IDCP 320, third IDCP 322, first IDCP 418, second IDCP 420, and / or third IDCP 422) of the CSP's second data center (e.g., first data center 204, second data center 206, third data center 208, first data center 304, second data center 306, third data center 308, first data center 404, second data center 406, and / or third data center 408) located in the second geographic region to indicate that the home region assignment is assigned to the designated data center. In some embodiments, the update of the second IDCP may be performed in response to at least the second data center becoming available.
[0108] At 508, the first data center may cause the customer device to provide an indication that the home region assignment has been assigned to the designated data center. For example, the first data center may cause the customer device to provide an indication that the home region assignment has been assigned to the designated data center. The first data center may cause the customer device to provide the indication based on completing updates of the first IDCP and the second IDCP.
[0109] At 510, the first data center may compare a state of the domain stored at the first data center and a state of the domain stored at the second data center. For example, the first data center may compare a state of the domain stored at the first data center and a state of the domain stored at the second data center in response to at least the second data center becoming available. In some embodiments, the first data center may compare a snapshot of the domain stored at the first data center with a snapshot of the domain stored at the second data center. In some embodiments, 510 may be omitted.
[0110] At 512, the first data center may determine one or more differences. For example, the first data center may determine one or more differences between a state of the domain stored at the first data center and a state of the domain stored at the second data center. In some embodiments, the first data center may determine the one or more differences based at least in part on a comparison of the state of the domain stored at the first data center and the state of the domain stored at the second data center. In some embodiments, 512 may be omitted.
[0111] At 514, the first data center may determine whether one or more write operations contributed to the one or more differences. For example, the first data center may determine whether one or more write operations performed by the second data center between the first data center's last update by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more differences. The first data center may determine the one or more write operations based on a comparison of write operations performed on the domain stored in the first data center and write operations performed on the domain stored in the second data center. The second data center may replicate the domain to other data centers at set intervals and / or in response to triggers, such that there may be a time between the last replication of the domain to the first data center and the time the second data center became unavailable. During this time, one or more write operations may be performed by the second data center.
[0112] In some embodiments, the first data center may determine that a write operation contributed to the one or more discrepancies. Further, the first data center may determine that one or more write operations performed by the second data center between the first data center's last update by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more discrepancies. In some embodiments, 514 may be omitted.
[0113] At 516, the first data center may cause an indication of the one or more differences to be displayed. For example, the first data center may cause an indication of the one or more differences determined at 512. The first data center may cause the indication to be displayed on the customer device. In some embodiments, the first data center may cause the indication to be displayed if the first data center determines that one or more write operations performed by the second data center between the first data center's last update by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more differences. In some embodiments, 516 may be omitted.
[0114] At 518, the first data center may present an option to perform a write operation on the domain. For example, the first data center may present an option to perform a write operation on the domain stored at the first data center. The first data center may present the option if it determines that the write operation caused one or more discrepancies. In some embodiments, the first data center may present the option to the customer device if the customer device can provide an indication to the first data center of whether the write operation will be performed on the domain. The customer device may provide the indication based on input from a customer using the customer device. In some embodiments, 518 may be omitted.
[0115] The procedure 500 may proceed from 518 to 520. 520 in Figure 5 may indicate that the procedure 500 proceeds from 520 in Figure 5 to 520 in Figure 6. Thus, the procedure 500 may proceed from 518 in Figure 5 to 602 in Figure 6.
[0116] At 602, the first data center may prevent one or more write operations from being applied to the domain. For example, the first data center may prevent one or more write operations from being applied to a domain stored at the first data center. The first data center may prevent one or more write operations from being applied to the domain if the first data center determines that one or more write operations performed by the second data center between the first data center's last update by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to one or more discrepancies. In some embodiments, 602 may be omitted.
[0117] At 604, the first data center may apply at least a portion of the one or more write operations to the domain. For example, the first data center may apply at least a portion of the one or more write operations to the domain stored at the first data center. In some embodiments, the first data center may apply at least a portion of the one or more write operations if the first data center determines that one or more write operations performed by the second data center between the first data center's last update by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more discrepancies. In some embodiments, 604 may be omitted.
[0118] At 606, the first data center may update a domain stored in the second data center to match the domain stored in the first data center. For example, the first data center may update a domain stored in the second data center to match the domain stored in the first data center in response to at least the second data center becoming available. In some embodiments, 606 may be omitted.
[0119] 6 may arguably suggest an order of operations for procedure 500, although it is understood that in other embodiments, the order of operations for procedure 500 may be different and / or one or more of the operations for procedure 500 may be performed simultaneously. Additionally, it is understood that in other embodiments, procedure 500 may omit one or more of the operations and / or include one or more additional operations.
[0120] Exemplary Service-Based Infrastructure Architecture As mentioned above, infrastructure as a service (IaaS) is a particular type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In an IaaS model, a cloud computing provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, an IaaS provider may also provide various services (e.g., billing, monitoring, logging, load balancing, clustering, etc.) that are associated with these infrastructure components. Thus, since these services can be policy-driven, an IaaS user can maintain application availability and performance by implementing policies that drive load balancing.
[0121] In some cases, IaaS customers can access resources and services over a wide area network (WAN) such as the Internet and use the cloud provider's services to install other elements of their application stack. For example, a user can log into an IaaS platform to create virtual machines (VMs), install operating systems (OS) on each VM, deploy middleware such as databases, create storage buckets for workloads and backups, and even install enterprise software on the VMs. The customer can then use the provider's services to perform a variety of functions, such as distributing network traffic, troubleshooting application issues, monitoring performance, and managing disaster recovery.
[0122] In most cases, the cloud computing model requires the participation of a cloud provider, which may be, but does not have to be, a third-party service that specializes in providing IaaS (e.g., recruiting, renting, selling), or an entity may deploy a private cloud and become its own infrastructure service provider.
[0123] In some examples, IaaS deployment is the process of putting a new application or a new version of an application onto a prepared application server, etc. It may also include the process of preparing the server (e.g., installing libraries, daemons, etc.). This is often managed below the hypervisor layer (e.g., server, storage, network hardware, and virtualization) by the cloud provider. Thus, the customer may be responsible for handling (e.g., on self-service virtual machines (which can be spun up on demand)), middleware, and / or application deployment, etc.
[0124] In some instances, IaaS provisioning may refer to obtaining a computer or virtual host to use and even installing the necessary libraries or services on them. In most cases, deployment does not include provisioning, which may need to be performed first.
[0125] Sometimes there are two different challenges in IaaS provisioning. First, there is the initial challenge of provisioning an initial set of infrastructure before anything works. Second, there is the challenge of evolving the existing infrastructure after all the provisioning (e.g. adding new services, modifying services, removing services, etc.). Sometimes these two challenges can be addressed by allowing the configuration of the infrastructure to be defined declaratively. In other words, the infrastructure (e.g. the components required and how they interact) can be specified by one or more configuration files. Thus, the overall topology of the infrastructure (e.g. resource dependencies and how they work together) can be described declaratively. Sometimes, once the topology is specified, workflows can be generated that configure and / or manage the various components described in the configuration files.
[0126] In some examples, the infrastructure may have many interconnected elements. For example, there may be one or more virtual private clouds (VPCs) (e.g., potential on-demand pools of configurable and / or shared computing resources), also known as a core network. Also, in some examples, there may be one or more inbound / outbound traffic group rules provisioned to define how the network inbound and / or outbound traffic is configured and one or more virtual machines (VMs). Other infrastructure elements such as load balancers, databases, etc. may also be provisioned. If there is a desire and / or addition of more infrastructure elements, the infrastructure may evolve in increments.
[0127] In some cases, employment of continuous deployment techniques may enable deployment of infrastructure code across various virtual computing environments. The described techniques may also enable infrastructure management within these environments. In some instances, a service team may write code for which deployment to one or more (but often many) different production environments (e.g., across various geographic locations, possibly even across the globe) is desirable. In some instances, however, the infrastructure into which the code will be deployed must first be set up. In some cases, provisioning may be performed manually, provisioning tools may be used to provision resources, and / or deployment tools may be used to deploy the code after the infrastructure has been provisioned.
[0128] FIG. 7 is a block diagram 700 illustrating an example pattern of an IaaS architecture according to at least one embodiment. A service operator 702 may be communicatively coupled to a secure host tenancy 704, which may include a virtual cloud network (VCN) 706 and a secure host subnet 708. In some examples, the service operator 702 may use one or more client computing devices, which may be portable handheld devices (e.g., iPhones, mobile phones, iPads, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., Google Glass head-mounted displays, etc.) running software such as Microsoft Windows Mobile and / or various mobile operating systems such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, etc., and capable of using the Internet, email, short message service (SMS), BlackBerry, or other communication protocols. Alternatively, the client computing devices may be general-purpose personal computers, examples of which include personal computers and / or laptop computers running various versions of Microsoft Windows, Apple Macintosh, and / or Linux operating systems. The client computing device may be a workstation computer running any of a variety of commercially available UNIX or UNIX-like operating systems, including, but not limited to, various GNU / Linux operating systems such as Google Chrome OS.Alternatively or additionally, the client computing devices may be any other electronic device, such as a thin-client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox gaming console with or without a Kinect® gesture input device), and / or a personal messaging device, capable of communicating over a network that can access the VCN 706 and / or the Internet.
[0129] The VCN 706 may include a local peering gateway (LPG) 710 that may be communicatively coupled to a secure shell (SSH) VCN 712 via an LPG 710 that is included in the SSH VCN 712. The SSH VCN 712 may include an SSH subnet 714, and the SSH VCN 712 may be communicatively coupled to a control plane VCN 716 via an LPG 710 that is included in the control plane VCN 716. The SSH VCN 712 may also be communicatively coupled to a data plane VCN 718 via the LPG 710. The control plane VCN 716 and the data plane VCN 718 may be included in a service tenancy 719, which may be owned and / or operated by the IaaS provider.
[0130] The control plane VCN 716 may include a control plane demilitarized zone (DMZ) tier 720 that serves as a perimeter network (e.g., a portion of an enterprise network between an enterprise intranet and an external network). DMZ-based servers may help limit liability and mitigate intrusions. The DMZ tier 720 may also include one or more load balancer (LB) subnets 722, a control plane app tier 724 that may include an app subnet 726, and a control plane data tier 728 that may include a database (DB) subnet 730 (e.g., a front-end DB subnet and / or a back-end DB subnet). The LB subnet 722 included in the control plane DMZ tier 720 may be communicatively coupled to the app subnet 726 included in the control plane app tier 724 and an Internet gateway 734 that may be included in the control plane VCN 716, and the app subnet 726 may be communicatively coupled to the DB subnet 730, a service gateway 736, and a network address translation (NAT) gateway 738 included in the control plane data tier 728. The control plane VCN 716 may include a service gateway 736 and a NAT gateway 738 .
[0131] The control plane VCN 716 can include a data plane mirrored app layer 740 that can include an app subnet 726. The app subnet 726 included in the data plane mirrored app layer 740 can include a virtual network interface controller (VNIC) 742 that can run a compute instance 744. The compute instance 744 can communicatively couple the app subnet 726 of the data plane mirrored app layer 740 to the app subnet 726 that can be included in the data plane app layer 746.
[0132] The data plane VCN 718 may include a data plane app layer 746, a data plane DMZ layer 748, and a data plane data layer 750. The data plane DMZ layer 748 may include a LB subnet 722 that may be communicatively coupled to an app subnet 726 of the data plane app layer 746 and an Internet gateway 734 of the data plane VCN 718. The app subnet 726 may be communicatively coupled to a service gateway 736 of the data plane VCN 718 and a NAT gateway 738 of the data plane VCN 718. Additionally, the data plane data layer 750 may include a DB subnet 730 that may be communicatively coupled to the app subnet 726 of the data plane app layer 746.
[0133] The internet gateways 734 of the control plane VCNs 716 and data plane VCNs 718 may be communicatively coupled to a metadata management service 752, which may be communicatively coupled to the public internet 754. The public internet 754 may be communicatively coupled to a NAT gateway 738 of the control plane VCNs 716 and data plane VCNs 718. The service gateways 736 of the control plane VCNs 716 and data plane VCNs 718 may be communicatively coupled to cloud services 756.
[0134] In some examples, the service gateways 736 of the control plane VCNs 716 and data plane VCNs 718 can make application programming interface (API) calls to the cloud services 756 without going through the public Internet 754. The API calls from the service gateways 736 to the cloud services 756 can be unidirectional. The service gateways 736 can make API calls to the cloud services 756, and the cloud services 756 can send the requested data to the service gateways 736. However, the cloud services 756 do not have to initiate the API calls to the service gateways 736.
[0135] In some examples, the secure host tenancy 704 may be directly connected to an otherwise isolated service tenancy 719. The secure host subnet 708 may communicate with the SSH subnet 714 through the LPG 710, which may allow bidirectional communication through an otherwise isolated system. By connecting the secure host subnet 708 to the SSH subnet 714, the secure host subnet 708 may be accessible to other entities in the service tenancy 719.
[0136] The control plane VCN 716 may enable configuration or provisioning of desired resources by users of the service tenancy 719. The desired resources provisioned in the control plane VCN 716 may be deployed or used in the data plane VCN 718. In some examples, the control plane VCN 716 may be isolated from the data plane VCN 718, and the data plane mirror app layer 740 of the control plane VCN 716 may communicate with the data plane app layer 746 of the data plane VCN 718 via a VNIC 742, which may be included in the data plane mirror app layer 740 and the data plane app layer 746.
[0137] In some examples, a user or customer of the system may make a request (e.g., create, read, update, or delete (CRUD) operations) over the public Internet 754, which may communicate the request to the metadata management service 752. The metadata management service 752 may communicate the request to the control plane VCN 716 through the Internet Gateway 734. The request may be received by the LB Subnet 722 in the control plane DMZ layer 720. The LB Subnet 722 may determine that the request is valid, and in response to this determination, the LB Subnet 722 may send the request to the app Subnet 726 in the control plane app layer 724. If the request is validated and a call to the public Internet 754 is required, the call to the public Internet 754 may be sent to the NAT Gateway 738, which may make the call to the public Internet 754. Metadata that may be desirable to store with the request may be stored in the DB Subnet 730.
[0138] In some examples, the data plane mirror app layer 740 may facilitate direct communication between the control plane VCN 716 and the data plane VCN 718. For example, it may be desirable to apply configuration changes, updates, or other suitable modifications to resources included in the data plane VCN 718. The control plane VCN 716 may perform the configuration changes, updates, or other suitable modifications to the resources by communicating directly with the resources included in the data plane VCN 718 via the VNIC 742.
[0139] In some embodiments, the control plane VCN 716 and the data plane VCN 718 may be included in the service tenancy 719. In this case, the user or customer of the system may not own or operate either the control plane VCN 716 or the data plane VCN 718. Alternatively, the IaaS provider may own or operate both the control plane VCN 716 and the data plane VCN 718, and both may be included in the service tenancy 719. This embodiment may allow for network isolation that may prevent users or customers from interacting with the resources of other users or customers. This embodiment may also allow for private storage of databases by users or customers of the system without having to rely on the public Internet 754, which may not have the desired level of threat prevention for storage.
[0140] In another embodiment, the LB subnet 722 included in the control plane VCN 716 may be configured to receive signals from the service gateway 736. In this embodiment, the control plane VCN 716 and the data plane VCN 718 may be configured to be called by the IaaS provider's customers without calling the public Internet 754. The IaaS provider's customers may desire this embodiment because databases used by the customers may be stored in a service tenancy 719 that is controlled by the IaaS provider and may be isolated from the public Internet 754.
[0141] 8 is a block diagram 800 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 802 (e.g., service operator 702 of FIG. 7 ) may be communicatively coupled to a secure host tenancy 804 (e.g., secure host tenancy 704 of FIG. 7 ), which may include a virtual cloud network (VCN) 806 (e.g., VCN 706 of FIG. 7 ) and a secure host subnet 808 (e.g., secure host subnet 708 of FIG. 7 ). The VCN 806 may include a local peering gateway (LPG) 810 (e.g., LPG 710 of FIG. 7 ), which may be communicatively coupled to a secure shell (SSH) VCN 812 via an LPG 710 included in the SSH VCN 812 (e.g., SSH VCN 712 of FIG. 7 ). SSH VCN 812 can include an SSH subnet 814 (e.g., SSH subnet 714 in FIG. 7), and SSH VCN 812 can be communicatively coupled to a control plane VCN 816 via an LPG 810 that is included in a control plane VCN 816 (e.g., control plane VCN 716 in FIG. 7). The control plane VCN 816 can be included in a service tenancy 819 (e.g., service tenancy 719 in FIG. 7), and the data plane VCN 818 (e.g., data plane VCN 718 in FIG. 7) can be included in a customer tenancy 821, which can be owned or operated by a user or customer of the system.
[0142] The control plane VCN 816 may include a control plane DMZ layer 820 (e.g., control plane DMZ layer 720 of FIG. 7 ) that may include a LB subnet 822 (e.g., LB subnet 722 of FIG. 7 ), a control plane app layer 824 (e.g., control plane app layer 724 of FIG. 7 ) that may include an app subnet 826 (e.g., app subnet 726 of FIG. 7 ), and a control plane data layer 828 (e.g., control plane data layer 728 of FIG. 7 ) that may include a database (DB) subnet 830 (e.g., similar to database subnet 730 of FIG. 7 ). The LB subnet 822 included in the control plane DMZ layer 820 is communicatively coupled to an app subnet 826 included in the control plane app layer 824 and an Internet gateway 834 (e.g., Internet gateway 734 in FIG. 7 ) that may be included in the control plane VCN 816, and the app subnet 826 may be communicatively coupled to a DB subnet 830, a service gateway 836 (e.g., service gateway 736 in FIG. 7 ), and a network address translation (NAT) gateway 838 (e.g., NAT gateway 738 in FIG. 7 ) included in the control plane data layer 828. The control plane VCN 816 may comprise the service gateway 836 and the NAT gateway 838.
[0143] The control plane VCN 816 may include a data plane mirror app layer 840 (e.g., data plane mirror app layer 740 of FIG. 7 ), which may include an app subnet 826. The app subnet 826 included in the data plane mirror app layer 840 may include a virtual network interface controller (VNIC) 842 (e.g., VNIC 742 of FIG. 7 ), which may run a compute instance 844 (e.g., similar to compute instance 744 of FIG. 7 ). The compute instance 844 may facilitate communication between the app subnet 826 of the data plane mirror app layer 840 and the app subnet 826 included in the data plane app layer 846 via the VNIC 842 included in the data plane mirror app layer 840 and the VNIC 842 included in the data plane app layer 846 (e.g., data plane app layer 746 of FIG. 7 ).
[0144] An internet gateway 834 included in the control plane VCN 816 may be communicatively coupled to a metadata management service 852 (e.g., metadata management service 752 of FIG. 7), which may be communicatively coupled to a public internet 854 (e.g., public internet 754 of FIG. 7). The public internet 854 may be communicatively coupled to a NAT gateway 838 included in the control plane VCN 816. A service gateway 836 included in the control plane VCN 816 may be communicatively coupled to cloud services 856 (e.g., cloud services 756 of FIG. 7).
[0145] In some examples, the data plane VCN 818 may be included in the customer tenancy 821. In this case, the IaaS provider may provide a control plane VCN 816 for each customer, and the IaaS provider may configure a unique compute instance 844 for each customer in the service tenancy 819. Each compute instance 844 may enable communication between the control plane VCN 816 in the service tenancy 819 and the data plane VCN 818 in the customer tenancy 821. The compute instance 844 may enable deployment or use of resources provisioned in the control plane VCN 816 in the service tenancy 819 in the data plane VCN 818 in the customer tenancy 821.
[0146] In another example, an IaaS provider customer may have a database that resides in customer tenancy 821. In this example, control plane VCN 816 may include data plane mirror app layer 840, which may include app subnet 826. Data plane mirror app layer 840 may reside in data plane VCN 818, but may not reside in data plane VCN 818. That is, data plane mirror app layer 840 may be accessible to customer tenancy 821, but may not reside in data plane VCN 818, and may not be owned or operated by the IaaS provider customer. Data plane mirror app layer 840 may be configured to make calls to data plane VCN 818, but may not be configured to make calls to any entities included in control plane VCN 816. A customer may desire deployment or use of resources in the data plane VCN 816 that have been provisioned in the control plane VCN 816, and the data plane mirror app layer 840 may facilitate the deployment or other use of the resources that the customer desires.
[0147] In some embodiments, the IaaS provider's customer can apply filters to the data plane VCN 818. In this embodiment, the customer can determine what the data plane VCN 818 can access, and the customer may limit access from the data plane VCN 818 to the public internet 854. The IaaS provider may not be able to apply filters or control the access of the data plane VCN 818 to any external networks or databases. The customer's application of filters and controls to the data plane VCN 818 in the customer tenancy 821 can help isolate the data plane VCN 818 from other customers and the public internet 854.
[0148] In some embodiments, the cloud services 856 can access services that may not be in the public internet 854, the control plane VCN 816, or the data plane VCN 818 through calls made by the service gateway 836. The connection between the cloud services 856 and the control plane VCN 816 or the data plane VCN 818 may not be live or continuous. The cloud services 856 may be on different networks owned or operated by the IaaS provider. The cloud services 856 may be configured to receive calls from the service gateway 836 or may not be configured to receive calls from the public internet 854. Some cloud services 856 may be isolated from other cloud services 856, and the control plane VCN 816 may be isolated from cloud services 856 that may not be in the same region as the control plane VCN 816. For example, the control plane VCN 816 may be located in "Region 1" and the cloud service "Deployment 7" may be located in Region 1 and Region 2. If a call to deployment 7 is made by a service gateway 836 included in a control plane VCN 816 located in region 1, the call may be sent to the deployment 7 in region 1. In this example, the control plane VCN 816 or the deployment 7 in region 1 may not be communicatively coupled to or in communication with the deployment 7 in region 2.
[0149] 9 is a block diagram 900 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 902 (e.g., service operator 702 of FIG. 7) may be communicatively coupled to a secure host tenancy 904 (e.g., secure host tenancy 704 of FIG. 7), which may include a virtual cloud network (VCN) 906 (e.g., VCN 706 of FIG. 7) and a secure host subnet 908 (e.g., secure host subnet 708 of FIG. 7). The VCN 906 may include an LPG 910, which may be communicatively coupled to an SSH VCN 912 via an LPG 910 (e.g., LPG 710 of FIG. 7) included in the SSH VCN 912 (e.g., SSH VCN 712 of FIG. 7). SSH VCN 912 may include an SSH subnet 914 (e.g., SSH subnet 714 in FIG. 7), and SSH VCN 912 may be communicatively coupled to a control plane VCN 916 via an LPG 910 included in the control plane VCN 916 (e.g., control plane VCN 716 in FIG. 7) and to a data plane VCN 918 via an LPG 910 included in the data plane VCN 918 (e.g., data plane VCN 718 in FIG. 7). The control plane VCN 916 and the data plane VCN 918 may be included in a service tenancy 919 (e.g., service tenancy 719 in FIG. 7).
[0150] The control plane VCN 916 may include a control plane DMZ layer 920 (e.g., control plane DMZ layer 720 of FIG. 7 ) that may include a load balancer (LB) subnet 922 (e.g., LB subnet 722 of FIG. 7 ), a control plane app layer 924 (e.g., control plane app layer 724 of FIG. 7 ) that may include an app subnet 926 (e.g., similar to app subnet 726 of FIG. 7 ), and a control plane data layer 928 (e.g., control plane data layer 728 of FIG. 7 ) that may include a DB subnet 930. The LB subnet 922 included in the control plane DMZ tier 920 is communicatively coupled to an app subnet 926 included in the control plane app tier 924 and an Internet gateway 934 (e.g., Internet gateway 734 in FIG. 7 ) that may be included in the control plane VCN 916, and the app subnet 926 may be communicatively coupled to a DB subnet 930, a service gateway 936 (e.g., service gateway in FIG. 7 ), and a network address translation (NAT) gateway 938 (e.g., NAT gateway 738 in FIG. 7 ) included in the control plane data tier 928. The control plane VCN 916 may comprise the service gateway 936 and the NAT gateway 938.
[0151] The data plane VCN 918 may include a data plane app layer 946 (e.g., data plane app layer 746 of FIG. 7), a data plane DMZ layer 948 (e.g., data plane DMZ layer 748 of FIG. 7), and a data plane data layer 950 (e.g., data plane data layer 750 of FIG. 7). The data plane DMZ layer 948 may include a LB subnetwork 922 that may be communicatively coupled to a trusted app subnetwork 960 and a non-trusted app subnetwork 962 of the data plane app layer 946 and an Internet gateway 934 included in the data plane VCN 918. The trusted app subnetwork 960 may be communicatively coupled to a service gateway 936 included in the data plane VCN 918, a NAT gateway 938 included in the data plane VCN 918, and a DB subnetwork 930 included in the data plane data layer 950. The non-trusted app subnetwork 962 may be communicatively coupled to a service gateway 936 included in the data plane VCN 918 and a DB subnetwork 930 included in the data plane data layer 950. The data plane data layer 950 may include a DB subnet 930 that may be communicatively coupled to a service gateway 936 included in the data plane VCN 918.
[0152] The untrusted app subnet 962 may include one or more primary VNICs 964(1)-964(N), which may be communicatively coupled to tenant virtual machines (VMs) 966(1)-966(N). Each tenant VM 966(1)-966(N) may be communicatively coupled to a respective app subnet 967(1)-967(N), which may be included in a respective container egress VCN 968(1)-968(N), which may be included in a respective customer tenancy 970(1)-970(N). Each secondary VNIC 972(1)-972(N) may facilitate communication between the untrusted app subnet 962, which may be included in the data plane VCN 918, and the app subnets included in the respective container egress VCNs 968(1)-968(N). Each container egress VCN 968(1)-968(N) may include a NAT gateway 938 that may be communicatively coupled to the public Internet 954 (eg, public Internet 754 in FIG. 7).
[0153] An internet gateway 934 included in the control plane VCN 916 and the data plane VCN 918 may be communicatively coupled to a metadata management service 952 (e.g., metadata management system 752 of FIG. 7 ), which may be communicatively coupled to the public internet 954. The public internet 954 may be communicatively coupled to a NAT gateway 938 included in the control plane VCN 916 and the data plane VCN 918. A service gateway 936 included in the control plane VCN 916 and the data plane VCN 918 may be communicatively coupled to cloud services 956.
[0154] In some embodiments, data plane VCN 918 may be integrated with customer tenancy 970. This integration may be useful or desirable for an IaaS provider's customer, such as when they may want support in running code. A customer may provide code to run, which may be disruptive, may communicate with other customer resources, or may have undesirable effects. In response, the IaaS provider may determine whether to run code provided to the IaaS provider by the customer.
[0155] In some examples, a customer of an IaaS provider may grant temporary network access to the IaaS provider to request functionality granted to the data plane app layer 946. The code performing this functionality may be configured to run in VMs 966(1)-966(N) and may not be configured to run anywhere else on the data plane VCN 918. Each VM 966(1)-966(N) may be connected to one customer tenancy 970. Each container 971(1)-971(N) contained in a VM 966(1)-966(N) may be configured to run code. In this case, double isolation may exist (e.g., containers 971(1)-971(N) that run code may be contained in VMs 966(1)-966(N) that are at least in the untrusted app subnet 962), which may help prevent erroneous or unwanted code from damaging the IaaS provider's network or a different customer's network. Containers 971(1)-971(N) may be communicatively coupled to customer tenancy 970 and may be configured to send or receive data from customer tenancy 970. Containers 971(1)-971(N) may be configured not to send or receive data from any other entities in data plane VCN 918. Upon completion of code execution, the IaaS provider may disable or discard containers 971(1)-971(N).
[0156] In some embodiments, the trusted app subnet 960 may execute code that may be owned or operated by the IaaS provider. In this embodiment, the trusted app subnet 960 may be communicatively coupled to the DB subnet 930 and may be configured to perform CRUD operations on the DB subnet 930. The non-trusted app subnet 962 may be communicatively coupled to the DB subnet 930, but in this embodiment, may be configured to perform read operations on the DB subnet 930. The containers 971(1)-971(N) included in each customer's VMs 966(1)-966(N) that may execute code from the customer may not be communicatively coupled to the DB subnet 930.
[0157] In other embodiments, the control plane VCN 916 and the data plane VCN 918 may not be directly communicatively coupled. In this embodiment, there may not be direct communication between the control plane VCN 916 and the data plane VCN 918. However, communication may occur indirectly in at least one manner. An LPG 910 may be established by an IaaS provider that may facilitate communication between the control plane VCN 916 and the data plane VCN 918. In another example, the control plane VCN 916 or the data plane VCN 918 may make a call to a cloud service 956 via a service gateway 936. For example, a call from the control plane VCN 916 to the cloud service 956 may include a request for a service that may communicate with the data plane VCN 918.
[0158] 10 is a block diagram 1000 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 1002 (e.g., service operator 702 of FIG. 7 ) may be communicatively coupled to a secure host tenancy 1004 (e.g., secure host tenancy 704 of FIG. 7 ), which may include a virtual cloud network (VCN) 1006 (e.g., VCN 706 of FIG. 7 ) and a secure host subnet 1008 (e.g., secure host subnet 708 of FIG. 7 ). The VCN 1006 may include an LPG 1010, which may be communicatively coupled to an SSH VCN 1012 via an LPG 1010 (e.g., LPG 710 of FIG. 7 ) included in the SSH VCN 1012 (e.g., SSH VCN 712 of FIG. 7 ). SSH VCN 1012 may include an SSH subnet 1014 (e.g., SSH subnet 714 in FIG. 7 ), and SSH VCN 1012 may be communicatively coupled to a control plane VCN 1016 via an LPG 1010 included in the control plane VCN 1016 (e.g., control plane VCN 716 in FIG. 7 ) and to a data plane VCN 1018 via an LPG 1010 included in the data plane VCN 1018 (e.g., data plane VCN 718 in FIG. 7 ). The control plane VCN 1016 and the data plane VCN 1018 may be included in a service tenancy 1019 (e.g., service tenancy 719 in FIG. 7 ).
[0159] The control plane VCN 1016 may include a control plane DMZ layer 1020 (e.g., control plane DMZ layer 720 of FIG. 7 ) that may include a LB subnet 1022 (e.g., LB subnet 722 of FIG. 7 ), a control plane app layer 1024 (e.g., control plane app layer 724 of FIG. 7 ) that may include an app subnet 1026 (e.g., app subnet 726 of FIG. 7 ), and a control plane data layer 1028 (e.g., control plane data layer 728 of FIG. 7 ) that may include a DB subnet 1030 (e.g., DB subnet 930 of FIG. 9 ). The LB subnet 1022 included in the control plane DMZ tier 1020 is communicatively coupled to an app subnet 1026 included in the control plane app tier 1024 and an Internet gateway 1034 (e.g., Internet gateway 734 of FIG. 7 ) that may be included in the control plane VCN 1016, and the app subnet 1026 may be communicatively coupled to a DB subnet 1030, a service gateway 1036 (e.g., service gateway of FIG. 7 ), and a network address translation (NAT) gateway 1038 (e.g., NAT gateway 738 of FIG. 7 ) included in the control plane data tier 1028. The control plane VCN 1016 may comprise the service gateway 1036 and the NAT gateway 1038.
[0160] The data plane VCN 1018 can include a data plane app layer 1046 (e.g., data plane app layer 746 of FIG. 7), a data plane DMZ layer 1048 (e.g., data plane DMZ layer 748 of FIG. 7), and a data plane data layer 1050 (e.g., data plane data layer 750 of FIG. 7). The data plane DMZ layer 1048 can include a trusted app subnet 1060 (e.g., trusted app subnet 960 of FIG. 9) and a non-trusted app subnet 1062 (e.g., non-trusted app subnet 962 of FIG. 9) of the data plane app layer 1046 and a LB subnet 1022 that can be communicatively coupled to an Internet gateway 1034 included in the data plane VCN 1018. The trusted app subnet 1060 may be communicatively coupled to a service gateway 1036 included in the data plane VCN 1018, a NAT gateway 1038 included in the data plane VCN 1018, and a DB subnet 1030 included in the data plane data layer 1050. The untrusted app subnet 1062 may be communicatively coupled to a service gateway 1036 included in the data plane VCN 1018 and a DB subnet 1030 included in the data plane data layer 1050. The data plane data layer 1050 may include a DB subnet 1030 that may be communicatively coupled to a service gateway 1036 included in the data plane VCN 1018.
[0161] The untrusted app subnet 1062 may include primary VNICs 1064(1)-1064(N) that may be communicatively coupled to tenant virtual machines (VMs) 1066(1)-1066(N) that reside within the untrusted app subnet 1062. Each tenant VM 1066(1)-1066(N) may be capable of executing code in a respective container 1067(1)-1067(N) and may be communicatively coupled to an app subnet 1026 that may be included in a data plane app layer 1046 that may be included in a container egress VCN 1068. Each secondary VNIC 1072(1)-1072(N) may facilitate communication between the untrusted app subnet 1062 included in the data plane VCN 1018 and the app subnet included in the container egress VCN 1068. The container egress VCN may include a NAT gateway 1038 that may be communicatively coupled to the public Internet 1054 (e.g., the public Internet 754 in FIG. 7).
[0162] An Internet gateway 1034 included in the control plane VCN 1016 and the data plane VCN 1018 may be communicatively coupled to a metadata management service 1052 (e.g., metadata management system 752 of FIG. 7 ), which may be communicatively coupled to the public Internet 1054. The public Internet 1054 may be communicatively coupled to a NAT gateway 1038 included in the control plane VCN 1016 and the data plane VCN 1018. A service gateway 1036 included in the control plane VCN 1016 and the data plane VCN 1018 may be communicatively coupled to cloud services 1056.
[0163] In some examples, the pattern illustrated by the architecture of block diagram 1000 of FIG. 10 may be an exception to the pattern illustrated by the architecture of block diagram 900 of FIG. 9 and may be desirable for customers of an IaaS provider when the IaaS provider cannot communicate directly with the customer (e.g., in a disconnected area). Containers 1067(1)-1067(N) contained in VMs 1066(1)-1066(N) for each customer may be accessible in real time by the customer. Containers 1067(1)-1067(N) may be configured to make calls to secondary VNICs 1072(1)-1072(N) contained in app subnet 1026 of data plane app tier 1046 that may be contained in container egress VCN 1068, respectively. Secondary VNICs 1072(1)-1072(N) may send the calls to NAT gateway 1038, which may send the calls to public Internet 1054. In this example, containers 1067(1)-1067(N) that are accessible in real time by a customer may be isolated from the control plane VCN 1016 and may be isolated from other entities included in the data plane VCN 1018. Containers 1067(1)-1067(N) may also be isolated from resources of other customers.
[0164] In another example, a customer can use containers 1067(1)-1067(N) to invoke cloud service 1056. In this example, the customer can execute code in containers 1067(1)-1067(N) that requests a service from cloud service 1056. Containers 1067(1)-1067(N) can send the request to secondary VNICs 1072(1)-1072(N), which can send the request to a NAT gateway, which can send the request to public internet 1054. Public internet 1054 can send the request to LB subnet 1022 included in control plane VCN 1016 via internet gateway 1034. In response to determining that the request is valid, the LB subnet can send the request to the app subnet 1026, which can send the request to the cloud service 1056 via the service gateway 1036.
[0165] It should be understood that the IaaS architectures 700, 800, 900, 1000 depicted in the figures may include other components than those depicted. Additionally, the embodiment depicted in the figures is merely one example of a cloud infrastructure system that may incorporate an embodiment of the present disclosure. In other embodiments, an IaaS system may include more or fewer components than depicted, may combine two or more components, or may have a different configuration or arrangement of components.
[0166] In one embodiment, the IaaS system described herein may include a suite of application, middleware, and database services delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. Oracle Cloud Infrastructure (OCI), offered by the Assignee, is one example of such an IaaS system.
[0167] 11 illustrates an exemplary computer system 1100 upon which various embodiments may be implemented. The system 1100 may be adapted to implement any of the computer systems described above. As shown in the figure, the computer system 1100 includes a processing unit 1104 that communicates with a number of peripheral subsystems via a bus subsystem 1102. The peripheral subsystems may include a processing acceleration unit 1106, an I / O subsystem 1108, a storage subsystem 1118, and a communication subsystem 1124. The storage subsystem 1118 includes a tangible computer readable storage medium 1122 and a system memory 1110.
[0168] Bus subsystem 1102 provides a mechanism for allowing the various components and subsystems of computer system 1100 to communicate with each other as desired. Although bus subsystem 1102 is shown diagrammatically as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. Bus subsystem 1102 may be any of a number of types of bus structures including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures may include an Industry Standard Architecture (ISA) bus, which may be implemented as a mezzanine bus manufactured in accordance with the IEEE P1386.1 standard, a MicroChannel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.
[0169] The processing unit 1104, which may be implemented as one or more integrated circuits (e.g., conventional microprocessors or microcontrollers), controls the operation of the computer system 1100. The processing unit 1104 may include one or more processors. These processors may include single-core or multi-core processors. In some embodiments, the processing unit 1104 may be implemented as one or more independent processing units 1132 and / or 1134, each including a single-core or multi-core processor. In other embodiments, the processing unit 1104 may be implemented as a quad-core processing unit formed by incorporating two dual-core processors on a single chip.
[0170] In various embodiments, the processing unit 1104 may execute various programs in response to program code and may maintain multiple simultaneously executing programs or processes. At any given time, some or all of the program code being executed may reside on the processor 1104 and / or on the storage subsystem 1118. With suitable programming, the processor 1104 may provide the various functions discussed above. The computer system 1100 may also include a processing acceleration unit 1106, which may include a digital signal processor (DSP), a special purpose processor, and / or the like.
[0171] The I / O subsystem 1108 may include user interface input devices and user interface output devices. User interface input devices may include pointing devices such as keyboards, mice or trackballs, touch pads or touch screens integrated into displays, scroll wheels, click wheels, dials, buttons, switches, keypads, audio input devices with voice command recognition systems, microphones, and other types of input devices. User interface input devices may include motion sensing and / or gesture recognition devices such as Microsoft Kinect® motion sensors that enable user control and interaction with input devices such as Microsoft Xbox® 360 game controllers through a natural user interface using gestures and spoken commands. User interface input devices may also include eye gesture recognition devices such as the Google Glass® blink detector that detects a user's eye activity (e.g., "blinking" during filming and / or menu selection) and translates eye gestures as input to an input device (e.g., Google Glass®). The user interface input devices may also include a voice recognition sensing device that allows a user to interact with a voice recognition system (eg, the Siri® navigator) via voice commands.
[0172] User interface input devices may also include, but are not limited to, three-dimensional (3D) mice, joysticks or pointing sticks, game pads and graphic tablets, as well as audio / visual devices such as speakers, digital cameras, digital video cameras, portable media players, webcams, image scanners, fingerprint scanners, barcode readers 3D scanners, 3D printers, laser range finders, and eye-tracking devices. User interface input devices may also include medical imaging input devices such as, for example, computed tomography, magnetic resonance imaging, positron emission tomography, and medical ultrasound devices. User interface input devices may also include audio input devices such as, for example, MIDI keyboards, digital musical instruments, and the like.
[0173] User interface output devices may include non-visual displays such as a display subsystem, indicator lights, or audio output devices. The display subsystem may be a flat panel device such as one using a cathode ray tube (CRT), a liquid crystal display (LCD) or a plasma display, a projection device, a touch screen, etc. In general, use of the term "output device" is intended to include all conceivable types of devices and mechanisms for outputting information from computer system 1100 to a user or to another computer. For example, user interface output devices may include, but are not limited to, a variety of display devices that visually convey text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, automobile navigation systems, plotters, audio output devices, and modems.
[0174] Computer system 1100 may also include a storage subsystem 1118 that includes software elements illustrated here as located within system memory 1110. System memory 1110 may store program instructions that can be loaded and executed by processing unit 1104, as well as data generated during the execution of these programs.
[0175] Depending on the configuration and type of computer system 1100, the system memory 1110 may be volatile (such as random access memory (RAM)) and / or non-volatile (such as read-only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that are immediately accessible to the processing unit 1104 and / or currently being operated on and executed by the processing unit 1104. In some embodiments, the system memory 1110 may include a number of different types of memory, such as static random access memory (SRAM) or dynamic random access memory (DRAM). In some embodiments, the ROM may typically store a basic input / output system (BIOS) containing the basic routines that help transfer information between elements within the computer system 1100, such as during start-up. Also, by way of non-limiting example, the system memory 1110 illustrates application programs 1112, program data 1114, and an operating system 1116, which may include client applications, web browsers, mid-tier applications, relational database management systems (RDBMS), and the like. By way of example, operating systems 1116 may include various versions of Microsoft Windows, Apple Macintosh, and / or Linux operating systems, various commercially available UNIX or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, Google Chrome OS, etc.), and / or mobile operating systems such as iOS, Windows Phone, Android OS, BlackBerry OS, and Palm OS operating systems.
[0176] The storage subsystem 1118 may also provide a tangible computer readable storage medium for storing basic programming and data constructs that provide the functionality of some embodiments. The storage subsystem 1118 may store software (programs, code modules, instructions) that, when executed by a processor, provide the functionality described above. These software modules or instructions may be executed by the processing unit 1104. The storage subsystem 1118 may also provide a repository for storing data used in accordance with the present disclosure.
[0177] Storage subsystem 1100 may also include a computer readable storage medium reader 1120 that may be further connected to a computer readable storage medium 1122. Computer readable storage medium 1122, integral with system memory 1110, and optionally in combination with system memory 1100, may comprehensively represent remote, local, fixed, and / or removable storage devices, as well as storage media for temporarily and / or permanently containing, storing, transmitting, and retrieving computer readable information.
[0178] Additionally, the computer readable storage medium 1122 containing the code or portions of code may include any suitable medium known or used in the art (including storage media and communication media), including, but not limited to, volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing and / or transmitting information. This may include tangible computer readable storage media, such as RAM, ROM, Electronically Erasable Programmable ROM (EEPROM), flash memory, and other memory technologies, optical storage, such as CD-ROM, digital versatile disk (DVD), magnetic storage, such as magnetic cassettes, magnetic tape, magnetic disk storage, or other tangible computer readable media. This may also include intangible computer readable media, such as a data signal, data transmission, or any other medium usable to transmit the desired information and accessible by computer system 1100.
[0179] By way of example, the computer readable storage medium 1122 may include hard disk drives that read from and write to non-removable, non-volatile magnetic media, magnetic disk drives that read from and write to removable, non-volatile magnetic disks, and optical disk drives that read from and write to removable, non-volatile optical disks, such as CD-ROMs, DVDs, Blu-Ray disks, or other optical media. The computer readable storage medium 1122 may include, but is not limited to, Zip drives, flash memory cards, Universal Serial Bus (USB) flash drives, Secure Digital (SD) cards, DVD disks, digital video tapes, and the like. The computer readable storage medium 1122 may also include flash memory-based SSDs, enterprise flash drives, solid-state drives (SSDs) based on non-volatile memory, such as solid-state ROMs, solid-state RAMs, dynamic RAMs, static RAMs, DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs using a combination of DRAM and flash memory-based SSDs. The disk drives and their associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 1100.
[0180] The communication subsystem 1124 provides an interface to other computer systems and networks. The communication subsystem 1124 serves as an interface for sending and receiving data between the computer system 1100 and other systems. For example, the communication subsystem 1124 may enable the computer system 1100 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 1124 may include a wireless voice and / or data network (e.g., using cellular technology, 3G, 4G, or advanced data network technology such as EDGE (Enhanced Data Rates for Global Evolution), WiFi (IEEE 802.11 family standard), or other mobile communication technology, or any combination thereof), a global positioning system (GPS) receiver component, and / or a radio frequency (RF) transceiver component for accessing other components. In some embodiments, the communication subsystem 1124 may provide a wired network connection (e.g., Ethernet) in addition to or as an alternative to a wireless interface.
[0181] In some embodiments, the communications subsystem 1124 can also receive input information in the form of structured and / or unstructured data feeds 1126, event streams 1128, event updates 1130, etc., on behalf of one or more users who may be using the computer system 1100.
[0182] As an example, the communications subsystem 1124 may be configured to receive data feeds 1126 in real time from users of other communications services, such as social networks and / or web feeds, such as Twitter® feeds, Facebook® updates, RSS (Rich Site Summary) feeds, and / or real-time updates from one or more third party information sources.
[0183] The communications subsystem 1124 may also be configured to receive data in the form of a continuous data stream, which may include an event stream 1128 of real-time events and / or event updates 1130, which may be continuous or may be effectively infinite with no apparent end. Examples of applications that generate continuous data include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automobile traffic monitoring, and the like.
[0184] The communications subsystem 1124 may also be configured to output structured and / or unstructured data feeds 1126, event streams 1128, event updates 1130, etc. to one or more databases that may be in communication with one or more streaming data source computers coupled to the computer system 1100.
[0185] The computer system 1100 can be one of a variety of types, including a portable handheld device (such as an iPhone® mobile phone, an iPad® computing tablet, a PDA, etc.), a wearable device (such as a Google Glass® head mounted display), a PC, a workstation, a mainframe, a kiosk, a server rack, or any other data processing system.
[0186] Due to the ever-changing nature of computers and networks, the description of the illustrated computer system 1100 is intended as an example only. Many other configurations are possible, whether they include more or fewer components than the illustrated system. For example, the use of customized hardware and / or implementation of particular elements in hardware, firmware, software (including applets), or a combination is also contemplated. Additionally, connections to other computing devices, such as network I / O devices, may be employed. Based on the disclosure and teachings provided herein, one of ordinary skill in the art will recognize other ways and / or methods of implementing various embodiments.
[0187] Although specific embodiments have been described above, various improvements, modifications, alternatives, configurations, and equivalents are within the scope of the present disclosure. The embodiments are not limited to operate in a particular data processing environment, but may freely operate in multiple data processing environments. For example, the embodiments may be realized by using a computer program product that includes computer programs / instructions that, when executed by a processor, cause the processor to perform any of the methods described in the present disclosure. Also, while the embodiments have been described using a specific sequence of transactions and steps, it will be apparent to one skilled in the art that the scope of the present disclosure is not limited to the sequence of transactions and steps described. Also, various features and aspects of the above-described embodiments may be used individually or together.
[0188] Furthermore, while embodiments have been described using a particular combination of hardware and software, it will be appreciated that other combinations of hardware and software are within the scope of the present disclosure. The embodiments may be implemented solely in hardware, solely in software, or by using a combination thereof. The various processes described herein may be implemented on the same processor or on different processors in any combination. Thus, when a component or module is described as being configured to perform an operation, such configuration may be achieved, for example, by designing an electronic circuit to perform the operation, by programming a programmable electronic circuit (such as a microprocessor) to perform the operation, or any combination thereof. Processes may communicate using a variety of techniques, including, but not limited to, conventional techniques for inter-process communication. Also, different parts of a process may use different techniques, or the same part of a process may use different techniques at different times.
[0189] Accordingly, the specification and drawings are to be regarded in an illustrative and not a limiting sense. However, it will be apparent that additions, differences, deletions, and other modifications and changes may be made without departing from the broad spirit and scope of the appended claims. Thus, although specific embodiments of the present disclosure have been described, they are not intended to be limiting. Various modifications and equivalents are intended to be within the scope of the following claims.
[0190] Use of the terms "a," "an," and "the," and similar referents in the context of describing the disclosed embodiments (particularly in the context of the claims below) shall be construed to cover both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context. The terms "comprising," "having," "including," and "containing" shall be construed as open-ended terms (i.e., meaning "including, but not limited to"), unless otherwise noted. The term "connected" shall be construed as partly or wholly contained, attached, or integrally connected, even if there is something intervening. The recitation of ranges of values herein is merely intended to serve as a shorthand method of individually referring to each separate value included in the range, unless otherwise indicated herein, and each separate value is incorporated herein as if it were a separate recitation herein. All methods described herein may be performed in any suitable order, unless otherwise indicated herein or clearly contradicted by context. The use of any and all examples or exemplary language (e.g., "such as") herein is intended to facilitate understanding of the embodiments only and does not limit the scope of the disclosure unless otherwise asserted. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0191] Unless otherwise noted, disjunctive language, such as the phrase "at least one of X, Y, or Z," is intended to be understood in the context in which it is commonly used to indicate that an item, term, etc. can be either X, Y, Z, or any combination thereof (e.g., X, Y, and / or Z). Thus, such disjunctive language is generally not intended to, and should not, imply that an embodiment requires the presence of at least one of X, at least one of Y, or at least one of Z, respectively.
[0192] Preferred embodiments of the present disclosure are described herein, including the best mode known for carrying out the present disclosure. Variations of these preferred embodiments may become apparent to those skilled in the art upon reading the above description. Such variations can be accommodated by those skilled in the art as necessary, and the present disclosure may be practiced differently from the specific descriptions herein. Accordingly, this disclosure includes all modifications and equivalents of the subject matter recited in the claims appended hereto as permitted by applicable law. Moreover, unless otherwise indicated herein, this disclosure includes any combination of the above-described elements in all possible variations thereof.
[0193] All references cited in this specification, including publications, patent applications, and patents, are herein incorporated by reference to the same extent as if each reference was individually and specifically indicated to be incorporated by reference in its entirety.
[0194] example In the following sections, other exemplary embodiments are provided.
[0195] Example 1 may include a method. The method includes receiving a request by a first datacenter of a cloud service provider (CSP) located in a first geographic region. The request is a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of the cloud service provider indicated in the request. The datacenter corresponding to the home region assignment is capable of performing a write operation to the domain. The method further includes the first datacenter updating a first identity control plane (IDCP) of the first datacenter to indicate that the home region assignment of the account is assigned to the designated datacenter. The designated datacenter is capable of performing a write operation to the domain in response to at least the first identity control plane being updated. The method further includes the first datacenter updating a second identity control plane of a second datacenter of the cloud service provider located in a second geographic region to indicate that the home region assignment is assigned to the designated datacenter. The method further includes causing the first datacenter to provide an indication that the home region assignment is assigned to the designated datacenter.
[0196] Example 2 may include the method of example 1, where the designated data center includes a first data center, where the first data center cannot perform write operations to the domain before the first identity control plane is updated and is capable of performing write operations to the domain in response to at least the first identity control plane being updated.
[0197] Example 3 may include the method of example 1, where the request indicates that the home region assignment is to be switched from a second datacenter to a first datacenter, the second datacenter being unavailable when the request is received, and the second identity control plane update is performed in response to at least the second datacenter becoming available.
[0198] Example 4 may include the method of example 3. The method further includes the first datacenter, in response to at least the second datacenter becoming available, comparing a state of the domain stored at the first datacenter and a state of the domain stored at the second datacenter. The method further includes the first datacenter determining one or more differences between the state of the domain stored at the first datacenter and the state of the domain stored at the second datacenter. The method further includes the first datacenter determining whether one or more write operations performed by the second datacenter between a last update of the first datacenter by the second datacenter before the second datacenter became unavailable and the time the second datacenter became unavailable contributed to the one or more differences.
[0199] Example 5 may include the method of example 4, where the first data center determines a write operation that caused the one or more discrepancies, the method further including the first data center presenting an option to perform the write operation to a domain stored at the first data center.
[0200] Example 6 may include the method of example 4, in which the first datacenter determines that one or more write operations performed by the second datacenter between a last update of the first datacenter by the second datacenter before the second datacenter became unavailable and the time the second datacenter became unavailable contributed to the one or more discrepancies, the method further including causing the first datacenter to display an indication of the one or more discrepancies.
[0201] Example 7 may include the method of example 4, in which the first datacenter determines that one or more write operations performed by the second datacenter between a last update of the first datacenter by the second datacenter before the second datacenter became unavailable and the time the second datacenter became unavailable contributed to the one or more discrepancies, the method further including preventing the one or more write operations from being applied to a domain stored at the first datacenter.
[0202] Example 8 may include the method of example 4, in which the first datacenter determines that one or more write operations performed by the second datacenter between a last update of the first datacenter by the second datacenter before the second datacenter became unavailable and the time the second datacenter became unavailable contributed to the one or more discrepancies, the method further including the first datacenter applying at least a portion of the one or more write operations to a domain stored in the first datacenter.
[0203] Example 9 may include the method of example 3. The method further includes, in response to at least the second data center becoming available, the first data center updating a domain stored in the second data center to match the domain stored in the first data center.
[0204] Example 10 may include the method of example 1, in which the request indicates that a home region assignment is to be switched from a first datacenter to a second datacenter. The first datacenter updates a first identity control plane at a first time. The first datacenter updates a second identity control plane at a second time after the first time. The first datacenter blocks write operations to the domain through the first datacenter between the first time and the second time.
[0205] Example 11 may include the method of example 1, in which a request to switch home region assignments is received based on a selection to switch home region assignments from a user interface indicating that a third datacenter of a cloud service provider located in a third geographic region has become unavailable, the third datacenter having been assigned a home region assignment prior to receiving the request.
[0206] Example 12 may include one or more non-transitory computer-readable media having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations. The operations include receiving a request. The request is a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of a cloud service provider (CSP) indicated in the request. The datacenter corresponding to the home region assignment is capable of performing a write operation to the domain. The operations include updating a first identity control plane (IDCP) of a first datacenter of the cloud service provider located in a first geographic region to indicate that the home region assignment of the account is assigned to the designated datacenter. The designated datacenter is capable of performing a write operation to the domain in response to at least the first identity control plane being updated. The operations include updating a second identity control plane of a second datacenter of the cloud service provider located in a second geographic region to indicate that the home region assignment is assigned to the designated datacenter, and causing an indication that the home region assignment is assigned to the designated datacenter.
[0207] Example 13 may include the one or more non-transitory computer-readable media of Example 12, in which the designated datacenter includes a first datacenter, the first datacenter unable to perform write operations to the domain before the first identity control plane is updated, and able to perform write operations to the domain in response to at least the first identity control plane being updated.
[0208] Example 14 may include the one or more non-transitory computer-readable media of example 12, in which the request indicates that the home region assignment is to be switched from a second datacenter to a first datacenter, the second datacenter being unavailable when the request is received, and the second identity control plane update is performed in response to at least the second datacenter becoming available.
[0209] Example 15 may include one or more non-transitory computer-readable media as described in Example 14, the one or more instructions in which, when executed by one or more processors, cause the one or more processors to further perform operations including, in response to at least a second datacenter becoming available, comparing a state of the domain stored at the first datacenter and a state of the domain stored at the second datacenter, determining one or more differences between the state of the domain stored at the first datacenter and the state of the domain stored at the second datacenter, and determining whether one or more write operations performed by the second datacenter between a last update of the first datacenter by the second datacenter before the second datacenter became unavailable and the time the second datacenter became unavailable contributed to the one or more differences.
[0210] Example 16 may include the one or more non-transitory computer-readable media of example 15, in which a write operation that caused the one or more discrepancies is determined, and the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including presenting an option to perform the write operation to a domain stored in the first data center.
[0211] Example 17 may include the one or more non-transitory computer readable media of Example 15, in which it is determined that one or more write operations performed by the second data center between a last update of the first data center by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more discrepancies. When executed by the one or more processors, the instructions further cause the one or more processors to perform operations including displaying an indication of the one or more discrepancies.
[0212] Example 18 may include the one or more non-transitory computer readable media of Example 15, in which it is determined that one or more write operations performed by the second data center between a last update of the first data center by the second data center before the second data center became unavailable and the time the second data center became unavailable contributed to the one or more discrepancies. When executed by the one or more processors, the instructions further cause the one or more processors to perform operations including applying at least a portion of the one or more write operations to a domain stored in the first data center.
[0213] Example 19 may include a first datacenter of a cloud service provider located in a first geographic region. The first datacenter comprises a memory storing a domain and one or more processors coupled to the memory. The one or more processors are configured to receive a request to switch a home region assignment corresponding to an account associated with the request to a designated datacenter of a cloud service provider (CSP) indicated in the request. The datacenter corresponding to the home region assignment is operable to perform a write operation to the domain. The one or more processors update a first identity control plane (IDCP) of the first datacenter to indicate that the home region assignment of the account is assigned to the designated datacenter. The designated datacenter is operable to perform a write operation to the domain in response to at least the first identity control plane being updated. The one or more processors update a second identity control plane of a second datacenter of the cloud service provider located in a second geographic region to indicate that the home region assignment is assigned to the designated datacenter. The one or more processors cause an indication that the home region assignment is assigned to the designated datacenter to be provided.
[0214] Example 20 may include the first datacenter of example 19, where the designated datacenter includes the first datacenter, where the first datacenter cannot perform write operations to the domain before the first identity control plane is updated, and is capable of performing write operations to the domain in response to at least the first identity control plane being updated.
[0215] Although aspects of the disclosure are described in the above specification with reference to specific embodiments, those skilled in the art will recognize that the disclosure is not limited thereto. The various features and aspects of the disclosure described above may be used individually or together. In addition, various modifications and equivalents include any appropriate combination of the features disclosed in the embodiments. The embodiments may be utilized in any number of environments and applications beyond those described herein without departing from the broad spirit and scope of the present specification. Accordingly, the present specification and drawings are to be regarded as illustrative and not limiting.
Claims
Claim 1 A method comprising: receiving, at a first data center of a cloud service provider (CSP) located in a first geographic region, a request, wherein the request is a request to switch a home region assignment corresponding to an account associated with the request to a designated data center of the cloud service provider indicated in the request, and a data center corresponding to the home region assignment is capable of performing a write operation to a domain; the method further comprising: updating, by the first data center, a first ID control plane (IDCP) of the first data center such that the home region assignment of the account is indicated as being assigned to the designated data center, and the designated data center is capable of performing a write operation to the domain based at least on the first ID control plane being updated; the method further comprising: updating, by the first data center, a second ID control plane of a second data center of the cloud service provider located in a second geographic region such that the home region assignment is indicated as being assigned to the designated data center; causing, by the first data center, an indicator to be presented indicating that the home region assignment has been assigned to the designated data center; A method further comprising the above. Claim 2 The method according to claim 1, wherein the designated data center includes the first data center, the first data center being unable to perform a write operation to the domain before the first ID control plane is updated and being capable of performing a write operation to the domain in response to at least the first ID control plane being updated. Claim 3 The method according to claim 1, wherein the request indicates that the home region assignment is switched from the second data center to the first data center, the second data center being unavailable when the request is received, and the update of the second ID control plane is performed in response to at least the second data center becoming available. Claim 4 In response to at least the second data center becoming available, the first data center compares the state of the domain stored in the first data center and the state of the domain stored in the second data center, the first data center determines one or more differences between the state of the domain stored in the first data center and the state of the domain stored in the second data center, the first data center determines whether one or more write operations performed by the second data center between the last update of the first data center by the second data center before the second data center became unavailable and when the second data center became unavailable caused the one or more differences, The method according to claim 3, further comprising.
5. The first data center determines the write operation that caused the one or more differences, and the method The method according to claim 4, further comprising the first data center presenting an option to perform the write operation on the domain stored in the first data center. Method.
6. The first data center determines that the one or more write operations performed by the second data center between the last update of the first data center by the second data center before the second data center became unavailable and when the second data center became unavailable caused the one or more differences, and the method The method according to claim 4, further comprising the first data center displaying an indicator of the one or more differences.
7. The first data center determines that the one or more write operations performed by the second data center between the last update of the first data center by the second data center before the second data center became unavailable and when the second data center became unavailable caused the one or more differences, and the method The method according to claim 4, further comprising preventing the one or more write operations from being applied to the domain stored in the first data center.
8. The first data center determines that one or more write operations performed by the second data center between the last update of the first data center by the second data center before the second data center becomes unavailable and the time when the second data center becomes unavailable are the cause of the one or more differences, and the method The method according to claim 4, further comprising the first data center applying at least a part of the one or more write operations to the domain stored in the first data center.
9. The method according to claim 3, further comprising the first data center updating the domain stored in the second data center to match the domain stored in the first data center, at least in response to the second data center becoming available.
10. The request indicates that the home region assignment is switched from the first data center to the second data center, the first data center updates the first ID control plane at a first time, the first data center updates the second ID control plane at a second time after the first time, and the first data center blocks write operations to the domain via the first data center between the first time and the second time. The method according to claim 1.
11. The request to switch the home region assignment is received based on a selection to switch the home region assignment from a user interface indicating that a third data center of the cloud service provider located in a third geographic region has become unavailable, and the home region assignment was assigned to the third data center before the request was received. The method according to claim 1.
12. A program for causing one or more processors to execute the method according to any one of claims 1 to 11.
13. A first data center of a cloud service provider located in a first geographic region, A memory for storing a domain, One or more processors coupled to the memory and configured to execute the method according to any one of claims 1 to 11, a first data center.