Tenant unique disaster recovery

The tenant-specific disaster recovery approach addresses customer-specific needs by configuring data replication and routing through a central control plane, ensuring continuous access and cost-effective disaster recovery tailored to individual customer preferences.

JP2025162502APending Publication Date: 2025-10-27エスアーペーエスエー
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024161080
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-15
Filing Date
2024-09-18
Publication Date
2025-10-27

AI Technical Summary

Technical Problem

Cloud computing customers face challenges in managing disaster recovery due to heterogeneous environments, high costs, regulatory restrictions, and varying hyperscaler strategies, leading to incomplete or costly data replication solutions that do not meet individual customer needs.

Method used

A tenant-specific disaster recovery approach that configures data replication and routing based on individual customer preferences, using a central control plane to manage service mesh communication, replication, and failover across multiple data centers, allowing customers to choose their preferred data center locations and hyperscalers.

Benefits of technology

Enables customizable disaster recovery solutions that meet specific customer requirements, reducing costs for those who don't need it and ensuring continuous access during disasters, while accommodating regulatory and strategic preferences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025162502000001_ABST
    Figure 2025162502000001_ABST
Patent Text Reader

Abstract

To provide a computer mounting method, a system and a non-temporal computer readable medium for tenant unique disaster recovery.SOLUTION: A method includes a step of converting a tenant unique preference for primary and secondary data center locations, in a routing constitution. Service persistency having an end point in the data center location is used so as to constitute a replication agent between the service persistency. The data replication copies data to a redundancy storage according to the tenant unique preference. A permanent storage replication agent is constituted for each of the service persistence in a tenant selection primary data center, using an end point of the permanent storage replication agent for each of the service persistence in the tenant selection primary data center.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a computer-implemented method, a non-transitory computer-readable medium, and a computer-implemented system for tenant-specific disaster recovery. [Background technology]

[0002] Disaster recovery is a top priority for cloud computing customers. Because customers entrust their data to cloud computing environments, their operational capability depends on the cloud computing environment providing continuous access even under catastrophic circumstances / adversities (e.g., earthquakes, floods, fires, and war). While the probability of such events occurring is small, many customers are willing to pay a premium to replicate data across multiple data centers across different regions and protect against an extended outage at any one of those data centers. For customers with heterogeneous environments, replicating data across multiple data centers can be cost-prohibitive (e.g., due to data volume, geographic location, hyperscaler strategies, or regulatory restrictions), so heterogeneous customers may simply forego disaster recovery or select only a subset of their data to protect. Summary of the Invention

[0003] This disclosure describes tenant-specific disaster recovery. [Means for solving the problem]

[0004] In one implementation, a computer-implemented method for tenant-specific disaster recovery includes translating, by a routing configurator, tenant-specific software application solution preferences for primary and secondary datacenter locations into a routing configuration; using the routing configurator to set up a service mesh for communication between services within and across the primary and secondary datacenter locations; and configuring a replication configurator and service persistence configurator with endpoints at the datacenter locations as determined from a landscape directory. configuring a replication agent between service persistencies using the routing configurator and service endpoints read from the landscape directory; configuring a virtual service implementing a service mesh used to route service requests to service deployments in the tenant-selected primary data center using the routing configurator; configuring an ingress gateway to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center using the routing configurator; configuring data replication using a replication configurator to copy data to redundant storage according to tenant-specific software application solution preferences for primary and secondary data center locations; and configuring a replication configurator and each service persistency in the tenant-selected primary data center.and configuring a persistent storage replication agent for each service persistence at the tenant-selected primary data center using the persistent storage replication agent endpoints fetched from the landscape directory for the service persistence.

[0005] The described subject matter may be implemented using computer-implemented methods, non-transitory computer-readable media storing computer-readable instructions for performing the computer-implemented methods, and computer-implemented systems having one or more computer memory devices interoperably coupled with one or more computers and having tangible, non-transitory machine-readable media storing instructions that, when executed by the one or more computers, perform the computer-implemented methods / computer-readable instructions stored on the non-transitory computer-readable media.

[0006] The subject matter described herein can be implemented to realize one or more of the following advantages.

[0007] First, disaster recovery can be configured per application and customer tenant, allowing for a default configuration with no overhead or additional costs for customers who do not need this feature, while enabling activation (e.g., at a premium price) for other customers. Second, each customer can individually select which combination of data centers (and hyperscalers) should be used for their unique workloads, independent of other customers. This allows for free choice to accommodate customers' strategic preferences (e.g., customers who do not want to host Amazon Web Services or other cloud computing providers' platforms), regulatory requirements (e.g., European Union (EU) access only), and of course location dependencies (e.g., to achieve the lowest latency and fastest response times). Third, the described approach allows cloud computing providers to build complex microservices-based solutions that leverage deployment to either regional hubs or satellites, driven purely by operational and cost considerations, without impacting customers' ability to enable disaster recovery.

[0008] The details of one or more implementations of the subject matter herein are set forth in the Summary, Claims, and accompanying drawings. Other features, aspects, and advantages of the subject matter will become apparent to those skilled in the art from the Summary, Claims, and accompanying drawings. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a box diagram of an exemplary cloud computing system during normal operation, according to one implementation of the present disclosure. [Figure 2] 2 is a box diagram of the example cloud computing system of FIG. 1 in a failover situation, according to one implementation of the present disclosure. [Figure 3]1 is a box diagram illustrating an example of a computer-implemented system and method for tenant-specific disaster recovery, according to one implementation of the present disclosure. [Figure 4] FIG. 1 is a block diagram illustrating an example of a computer-implemented system used to provide the computational functionality associated with the described algorithms, methods, functions, processes, flows, and procedures, according to one implementation of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0010] Like reference numbers and designations in the various drawings indicate like elements.

[0011] The following detailed description describes tenant-specific disaster recovery and is presented to enable any person skilled in the art to make and use the disclosed subject matter in the context of one or more specific implementations. Various modifications, alterations, and substitutions of the disclosed implementations may be made and will be readily apparent to those skilled in the art, and the general principles defined may be applied to other implementations and applications without departing from the scope of the present disclosure. In some cases, one or more technical details not necessary to gain an understanding of the described subject matter and within the skill of those skilled in the art may be omitted so as not to obscure one or more described implementations. The present disclosure is not intended to be limited to the implementations described or illustrated, but is intended to be accorded the widest scope consistent with the principles and features described.

[0012] Disaster recovery is a top priority for cloud computing customers. Because customers entrust their data to the cloud computing environment, their operational ability depends on the cloud computing environment providing continuous access even under catastrophic circumstances / adversities (e.g., earthquakes, floods, fires, and war). While the probability of such events occurring is small, many customers are willing to pay a premium to replicate their data across multiple data centers across different locations to protect against an extended outage at any one of those data centers.

[0013] Many cloud computing customers are heterogeneous in nature. For some, the additional cost of replicating data across multiple data centers is prohibitive, necessitating alternative solutions that offer limited protection based on multi-availability-zone redundancy but do not offer multi-region disaster recovery. To minimize additional costs, customers who choose disaster recovery protection may choose only a subset of those solutions that qualify.

[0014] Customers may also have different hyperscaler strategies: for some, it is acceptable to use different providers for primary and secondary data center locations, while others have made a strict single hyperscaler decision.

[0015] Additionally, there may be regulatory restrictions that apply to secondary disaster recovery sites as well, for example, regulatory restrictions could specify that secondary disaster recovery sites have European Union (EU) access only.

[0016] As an additional dimension, on the cloud computing provider side, there are various intra-regional deployment strategies that must be considered. Customers can choose their preferred data center locations, but cloud computing providers may have separate data center deployment strategies within each region. With the introduction of intra-regional hub and satellite deployments, applications and consumable services may be distributed across multiple data center locations. Determining disaster recovery sites for each service in each primary location, replicating data between these different sites, and rerouting data access in the event of a failover becomes a multidimensional problem that must be addressed in a controlled manner.

[0017] What is needed is an approach that manages customer data separately at a tenant-specific level for each service, supporting different replication targets from within each service as needed, while also ensuring consistency and coordinated failover in the event of a disaster.

[0018] The described approach addresses several issues, including:

[0019] 1. Disaster recovery must be enabled for each application and customer tenant individually, as disaster recovery comes with an additional price tag that is opted in by some, but not all, customers.

[0020] 2. Customers must be able to choose their primary and secondary data center locations (and hyperscalers) independently from other customers.

[0021] 3. For distributed services with a regional hub / satellite deployment strategy, even within a single application (e.g., composed of many microservices), data replication and failover should be configurable at the service level, rather than a simple 1:1 relationship of data centers.

[0022] 4. As a result, each service deployment can be a primary, secondary, or only (if disaster recovery is not selected) location and can be configured individually for each of the tenants and solutions it hosts.

[0023] 5. Configuring replication directions during normal operations, switching those directions in the event of a failure (even for data centers not directly affected due to inter-service dependencies), and reconfiguring service bindings and request routing according to per-tenant customer preferences must be possible from one central control plane with a single action for all customers, applications, and services affected by a disaster recovery-causing event.

[0024] FIG. 1 is a box diagram 100 of an exemplary cloud computing system during normal operation according to one implementation of the present disclosure. Illustrated are data centers I-III, 102a-102c, respectively, data center IV 104, and data center V 106. In FIG. 1, a software application solution is assembled from four services labeled Service 1 108, Service 2 110, Service 3 112, and Service 4 114. Each service has a separate multi-tenant persistence, depicted as a database. For purposes of this disclosure, separate multi-tenant persistence is indicated by adding a "'" to the label identifying the particular service (e.g., persistence 108' in Data Center I 102a associated with Service 1 108). In some implementations, multi-tenant persistence may include other data structures. In some implementations, tenant isolation may be implemented as separate database schemas or in other ways, but this is not relevant to understanding the presented solution.

[0025] There are two customers who subscribe to this software application solution, labeled Customer A and Customer B. As a result, there are customer tenants and their associated persistence for Customer A and Customer B in Services 1 through 4.

[0026] The five data centers are in different geographic regions hosting a subset of services such that each service is deployed in at least two data centers for redundancy. For example, service 1 108 is deployed in both data center 1 102a and data center III 102c. Due to the implemented deployment strategy of hub and satellite deployment within a region of services, a complete software application solution may not be hosted in a single data center, but any combination of services will result in a multi-data center setup.

[0027] Customers must choose a set of data centers within their preferred region for their primary use case, and a secondary set for disaster recovery (either explicitly or transparently to the customer, depending on how much detail about the deployment scheme is made available to the customer). Depending on individual customer requirements (e.g., location within a region (region or location), hyperscaler preference, or regulatory requirements), the two customers in this example make different decisions: · Customer A has selected Data Center I 102a and Data Center II 102b as primary locations and Data Center III 102c and Data Center IV 104 as secondary locations. · Customer B also selected Data Center I 102a and Data Center II 102b as primary locations, but preferred Data Center III 102c and Data Center V 106 as secondary locations.

[0028] As depicted in Figure 1, this means replicating customer data to prevent data loss in the event of a disaster recovery event, as follows: Service 1 108 and Service 2 110 need to replicate data for both Customer A and Customer B from Data Center I 102a to Data Center III 102c. Service 3 112 needs to replicate data for Customer A from Data Center I 102a to Data Center IV 104 and data for Customer B from Data Center I 102a to Data Center V 106. Service 4 114 needs to replicate data for Customer A from Data Center II 102b to Data Center IV 106 and data for Customer B from Data Center II 102b to Data Center V 106.

[0029] Additionally, the call routing between services needs to be configured. Since both Customer A and Customer B selected the same primary location, they are the same. That is, the customer request is routed to Service 1 108 in Data Center I 102a, which calls Service 2 110 in Data Center I 102a, which calls Service 3 112 in Data Center I 102a and Service 4 114 in Data Center II 102b, and in addition, Service 3 112 in Data Center I 102a also calls Service 4 114 in Data Center II 102b.

[0030] FIG. 2 is a box diagram 200 of the example cloud computing system of FIG. 1 in a failover situation, according to one implementation of the present disclosure.

[0031] 2, assume that a disaster recovery event occurs with respect to data center I 102a and a failover operation needs to be performed, in which case both service request routing and persistence data replication need to be reconfigured based on the customer's individual preferences for the failover situation.

[0032] For data replication, in most cases, only the failed primary data persistence is replaced with the corresponding secondary data persistence that is promoted to the new primary data persistence, and data replication is reversed. Because the original data persistence is unavailable during the outage, the original secondary data persistence cannot replicate data back during this phase, but either buffers all changes for later replication or starts synchronizing based on the current data when the situation is resolved. However, there may also be reasons to reverse data replication between data centers that are not directly affected by the outage.

[0033] In the example of Figure 2, this is the case for customer B using service 4 114, where the replication of service 4 114 needs to be switched from data center V 106 to data center II 102b. This is different for customer A, where the replication direction of service 4 114 remains from data center II 102b to data center IV 104. The reason for this different behavior is the failover to two different deployments of service 3, as follows:

[0034] 1) Data center IV 104 is "close enough" to data center II 102b so that service 3 112 deployed in data center IV 104 can continue to use the deployment of service 4 114 in data center II 102b, which applies to customer A.

[0035] 2) For Customer B, the failover of Service 3 112 occurs to Data Center V 106, which in this example is considered too far (e.g., in terms of communication latency) from Data Center II 102b. Service 4 114 also needs to fail over to Data Center V 106, but Data Center II 102b, where the primary for Service 4 114 is deployed, is not directly affected by the outage. Nevertheless, for Service 4 114, the roles of primary and secondary are switched, and therefore the direction of replication is also reversed. In this special case, replication continues to keep the data synchronized, just in the opposite direction.

[0036] In summary, the following changes to data replication are implemented: Reverse data replication for Service 1 108 and Service 2 110 for Customer A and Customer B, originating from Data Center III 102c and pointing to Data Center I 102a, but suspending replication since target Data Center I 102a is unavailable. Reverse data replication for Service 3 112, pointing from Data Center IV 104 to Data Center I 102a for Customer A, and from Data Center V 106 to Data Center I 102a for Customer B, but suspending replication since target Data Center I 102a is unavailable. Reverse data replication for Service 4 114 for Customer B, originating from Data Center V 106 and pointing to Data Center II 102b; replication continues in the new direction because the target Data Center II 102b is available. · Do not change data replication for Service 4 114 from Data Center II 102b to Data Center IV 104 for Customer A.

[0037] Additionally, routing must be adjusted to use services from secondary data centers as defined by each customer, as follows: Inbound requests for both Customer A and Customer B are routed to Service 1 108 in Data Center III 102c, which invokes Service 2 110 in Data Center III 102c. For Customer A, Service 2 110 in Data Center III 102c calls Service 3 112 in Data Center IV 104 and Service 4 114 in Data Center II 102b, and in addition, Service 3 112 in Data Center IV 104 calls Service 4 114 in Data Center II 102b. For Customer B, Service 2 110 calls Service 3 112 in Data Center V 106 and Service 4 114 in Data Center V 106, and in addition, Service 3 112 in Data Center V 106 also calls Service 4 114 in Data Center V 106.

[0038] In this approach, operations continue until the outage in data center I 102a is resolved and the configuration can be switched back: pending data replication is initiated, all buffered data is flushed (or can be synchronized to the latest state of the secondary data persistence), data replication is then reversed as needed, routing is reset, and customers can resume working in a normal, non-failover configuration.

[0039] 3 is a box diagram illustrating an example of a computer-implemented system and method 300 for tenant-specific disaster recovery, according to one implementation of the present disclosure. For clarity of presentation, the following description generally describes method 300 in the context of other figures in this description. However, it will be understood that method 300 may be performed, for example, by any system, environment, software, and hardware, or combination of systems, environments, software, and hardware, as appropriate. In some implementations, various steps of method 300 may be performed in parallel, in combination, in a loop, or in any order.

[0040] To enable consistent execution of all steps described in the sample scenario with respect to Figures 1 and 2, a central disaster recovery control plane 302 is introduced, taking into account each customer's (or tenant's) individual preference for primary and secondary locations. The described steps of method 300, initial configuration (1-3) and reconfiguration (5-7), are executed for failover for all affected tenants after the occurrence of a disaster recovery-causing event in (4). Note that while the steps are the same for all tenants, the actual configuration may be different for each tenant (i.e., tenant-specific). That is, routing and replication may be configured between different data centers depending on how each customer configured their primary and secondary data center preferences (as described in the example with respect to Figures 1 and 2). Here, 303a is considered the primary data center, and 303b / 303c are considered secondary data centers.

[0041] Disaster recovery control plane 302 is a software application hosted in a cloud computing environment and runs either redundantly in multiple data center locations managed by disaster recovery control plane 302 or in a location different from the locations managed by disaster recovery control plane 302. Disaster recovery control plane 302 provides two types of graphical user interfaces (UIs) (or GUIs): 1) a first UI for customers to configure preferences for primary and secondary data centers for each solution, and 2) a second UI for cloud computing operators to trigger failover procedures after a disaster-causing event is determined.

[0042] At (1), a customer configures preferences for primary and secondary data center locations for each of their software application solutions in disaster recovery control plane 302. The preferences are stored (e.g., in a database) as failover configurations in failover configuration persistence 304, which is persisted to disaster recovery control plane 302. Failover configuration persistence 304 stores the customer's preference selections for primary and secondary data centers for each of the customer's solutions. From (1), method 300 proceeds to (2a)-(2d).

[0043] At (2a), the configured preferences for primary and secondary data center locations are translated into a routing configuration using a routing configurator 306 that is used to set up a service mesh for communication between services within and across data center locations. The routing configurator 306 configures the actual endpoint to be invoked and the credentials to use when a component in the service mesh invokes a service by its symbolic name. From (2a), method 300 proceeds to (2b).

[0044] At (2b), service endpoints are read from landscape directory 308, which lists all services across data center locations along with, for example, name, type, persistence, and deployment coordinates (e.g., uniform resource locator (URL) and credentials). Landscape directory 308 also enables routing configurator 306 to determine services with endpoints in various data center locations and configure the services into a service mesh. Similarly, replication configurator 314 uses landscape directory 308 to find service persistencies with endpoints in various data center locations and configure replication agents between service persistencies.

[0045] The replication configurator 314 configures the replication agents 316 / 318 / 322 / 324 attached to all service persistences to replicate data written to the primary persistence to the corresponding secondary persistence. If the secondary persistence is inaccessible (e.g., after a disaster recovery event with subsequent replication reversal), the replication agent can either buffer updates to that persistence or identify data that has not yet been replicated. After the outage is resolved, when the replication configurator 314 triggers replication initiation, the replication agent flushes its buffered data or, respectively, retrieves and transmits data that has not been replicated in the meantime. From (2b), method 300 proceeds to (2c).

[0046] At (2c), the service endpoints are used by the routing configurator 306 to configure the virtual service 310 implementing the service mesh to route the service request to a service deployment in the primary data center of the customer's choice. From (2c), the method 300 proceeds to (2d).

[0047] At (2d), a global ingress is additionally configured by routing configurator 306 within ingress gateway 312 to route the end user's initial request 313 to the service mesh to the first service instance in the customer's preferred primary data center. From (2d), method 300 proceeds to (3a).

[0048] At (3a), data replication is configured to copy all data to redundant storage using replication configurator 314, again according to customer preferences for primary and secondary data center locations. From (3a), method 300 proceeds to (3b).

[0049] At (3b), the persistent storage replication agent endpoints, as well as the routing configuration, are fetched from the landscape directory 308. From (3b), the method 300 proceeds to (3c)+(3d).

[0050] In (3c)+(3d), a replication agent (316+318 for (3c)+(3d), respectively) for each service persistence is configured in the primary data center using the fetched endpoints of the persistent storage replication agents. The configured replication agents are used to replicate all data written for each customer tenant to a corresponding replication agent in the customer-selected secondary data center. From (3c) and (3d), method 300 proceeds to (4).

[0051] At (4), it is assumed that a disaster recovery event has occurred and a failover needs to be performed. The disaster recovery control plane 302 is triggered to orchestrate the necessary steps. From (4), the method 300 proceeds to (5).

[0052] At (5), the disaster recovery control plane 302 retrieves the per-customer failover configuration from the failover configuration persistence 304 and reconfigures routing and replication. From (5), the method 300 proceeds to (6a).

[0053] At (6a), the failover configuration is converted into a routing configuration using the routing configurator 306. From (6a), the method 300 proceeds to (6b).

[0054] At (6b), the service endpoints are retrieved from the landscape directory 308. From (6b), the method 300 proceeds to (6c).

[0055] At (6c), using the routing configurator and the retrieved service endpoints, the virtual service 320 implementing the service mesh is configured to route the service request to a service deployment in a secondary data center of the customer's choice. From (6c), method 300 proceeds to (6d).

[0056] At (6d), the global ingress is additionally configured to route the end user's initial request to the service mesh to the first service instance in the preferred secondary data center using the ingress gateway 312. From (6d), method 300 proceeds to (7a).

[0057] At (7a), data replication is configured using replication configurator 314 to copy all data to redundant storage (subject to its availability), again according to customer preferences for primary and secondary data center locations. From (7a), method 300 proceeds to (7b).

[0058] At (7b), the persistent storage replication agent endpoints, as well as the routing configuration, are fetched by the replication configurator from the landscape directory 308. From (7b), the method 300 proceeds to (7c)+(7d).

[0059] In (7c)+(7d), using the fetched endpoints of the persistent storage replication agents, the replication agent for each service persistence at the secondary data center (322+324 for (7c)+(7d), respectively) is configured with information indicating to which primary data center the replication agent should replicate any writes, and the replication direction for the affected persistent storage is reversed. Although replication will not be performed for the affected persistences during the primary data center outage phase, the reconfigured replication agents (e.g., 322 and 324) will collect data that needs to be replicated at the secondary data center until it can be flashed back to the primary after the outage is resolved. After (7c)+(7d), method 300 can stop.

[0060] 4 is a block diagram illustrating an example of a computer-implemented system 400 that may be used to provide the computational functionality associated with the described algorithms, methods, functions, processes, flows, and procedures, according to one implementation of the present disclosure. In the illustrated implementation, the computer-implemented system 400 includes a computer 402 and a network 430.

[0061] The illustrated computer 402 is intended to encompass any computing device, such as a server, desktop computer, laptop / notebook computer, wireless data port, smartphone, personal digital assistant (PDA), tablet computer, one or more processors within these devices, or combinations of computing devices, including physical or virtual instances of a computing device. In addition, the computer 402 can include input devices, such as a keypad, keyboard, or touch screen, or combination of input devices capable of accepting user information, and output devices that communicate information associated with the operation of the computer 402, including digital data, visual, auditory, another type of information, or a combination of several types of information on a GUI or other type of UI.

[0062] The computer 402 may play one role in a distributed computing system, for example, as a client, network component, server, or database or another peripheral, or may combine several roles to perform the subject matter described in this disclosure. The illustrated computer 402 is communicatively coupled to a network 430. In some implementations, one or more components of the computer 402 may be configured to operate in an environment or a combination of environments, including cloud computing, local, or global.

[0063] At a high level, computer 402 is an electronic computing device operable to receive, transmit, process, store, or manage data and information associated with the described subject matter. According to some implementations, computer 402 may also include or be communicatively coupled to a server, such as an application server, an email server, a web server, a cache server, or a streaming data server, or a combination of servers.

[0064] Computer 402 can receive requests over network 430 (e.g., from a client software application running on another computer 402) and respond to the received requests by processing the received requests using a software application or combination of software applications. In addition, requests can also be sent to computer 402 from internal users (e.g., from a command console or by another internal access method), external or third parties, or other entities, individuals, systems, or computers.

[0065] Each of the components of computer 402 can communicate using system bus 403. In some implementations, any or all of the components of computer 402, including hardware, software, or a combination of hardware and software, can interface over system bus 403 using application programming interfaces (APIs) 412, service layer 413, or a combination of APIs 412 and service layer 413. API 412 can include specifications of routines, data structures, and object classes. API 412 can be either computer language independent or dependent and refer to a complete interface, a single function, or even a set of APIs. Service layer 413 provides software services to computer 402 or other components (illustrated or not) communicatively coupled to computer 402. Functionality of computer 402 can be accessible to all service consumers using service layer 413. Software services, such as those provided by service layer 413, provide reusable, defined functionality through defined interfaces. For example, the interface may be software written in a computing language (e.g., JAVA or C++) or combination of computing languages ​​that provides data in a particular format (e.g., Extensible Markup Language (XML)) or combination of formats. Although illustrated as an integrated component of computer 402, alternative implementations may illustrate API 412 or services layer 413 as a standalone component with respect to other components of computer 402 or other components (illustrated or not) communicatively coupled to computer 402. Furthermore, any or all portions of API 412 or services layer 413 may be implemented as a child or sub-module of another software module, enterprise application, or hardware module without departing from the scope of this disclosure.

[0066] The computer 402 includes an interface 404. While illustrated as a single interface 404, two or more interfaces 404 may be used according to the particular needs, desires, or implementation of the computer 402. The interface 404 is used by the computer 402 to communicate with another computing system (illustrated or not) communicatively linked to the network 430 in a distributed environment. Generally, the interface 404 is operable to communicate with the network 430 and comprises logic encoded in software, hardware, or a combination of software and hardware. More specifically, the interface 404 may comprise software supporting one or more communication protocols associated with communication such that the network 430 or the hardware of the interface 404 is operable to communicate physical signals internally or externally to the illustrated computer 402.

[0067] Computer 402 includes a processor 405. Although illustrated as a single processor 405, two or more processors 405 may be used according to the particular needs, desires, or particular implementation of computer 402. Generally, processor 405 executes instructions and manipulates data to perform the operations of computer 402 and the algorithms, methods, functions, processes, flows, and procedures as described in this disclosure.

[0068] The computer 402 also includes a database 406 that can maintain data for the computer 402, another component communicatively linked to the network 430 (illustrated or not), or a combination of the computer 402 and another component. For example, the database 406 can be an in-memory or conventional database that stores data consistent with the present disclosure. In some implementations, the database 406 can be a combination of two or more different database types (e.g., a hybrid in-memory and conventional database) according to the particular needs, desires, or particular implementation of the computer 402 and the described functionality. Although illustrated as a single database 406, two or more databases of similar or different types can be used according to the particular needs, desires, or particular implementation of the computer 402 and the described functionality. While the database 406 is illustrated as an internal component of the computer 402, in alternative implementations, the database 406 can be external to the computer 402. The database 406 can maintain and manipulate at least any of the data types mentioned, or any data types consistent with the present disclosure.

[0069] The computer 402 also includes a memory 407 that can retain data for the computer 402, another component or components communicatively linked to the network 430 (illustrated or not), or a combination of the computer 402 and another component. The memory 407 can store any data consistent with this disclosure. In some implementations, the memory 407 can be a combination of two or more different types of memory (e.g., a combination of semiconductor and magnetic storage) according to the particular needs, desires, or particular implementation of the computer 402 and the described functionality. While illustrated as a single memory 407, two or more memories 407 or similar or different types can be used according to the particular needs, desires, or particular implementation of the computer 402 and the described functionality. While the memory 407 is illustrated as an internal component of the computer 402, in alternative implementations, the memory 407 can be external to the computer 402.

[0070] Application 408 is an algorithmic software engine that provides functionality according to the particular needs, desires, or particular implementation of computer 402, particularly with respect to the functionality described in this disclosure. For example, application 408 can serve as one or more components, modules, or applications. Moreover, while illustrated as a single application 408, application 408 may be implemented as multiple applications 408 on computer 402. Additionally, while illustrated as being internal to computer 402, in alternative implementations, application 408 may be external to computer 402.

[0071] The computer 402 may also include a power supply 414. The power supply 414 may include a rechargeable or non-rechargeable battery, which may be configured as either user-replaceable or non-user-replaceable. In some implementations, the power supply 414 may include power saving or management circuitry (including charging, standby, or another power management function). In some implementations, the power supply 414 may include a power plug for plugging the computer 402 into a wall outlet, or another power source, for example, to power the computer 402 or to charge a rechargeable battery.

[0072] There may be many computers 402 associated with or external to the computer system that includes computer 402, with each computer 402 communicating over network 430. Furthermore, the terms "client," "user," or other appropriate terminology may be used interchangeably where appropriate without departing from the scope of this disclosure. Furthermore, this disclosure contemplates that many users may use one computer 402, or that one user may use multiple computers 402.

[0073] The described implementations of the subject matter may include one or more of the features alone or in combination.

[0074] For example, in a first implementation, a computer-implemented method for tenant-specific disaster recovery includes translating, by a routing configurator, tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration; setting up a service mesh for communication between services within and across the primary and secondary data center locations using the routing configurator; configuring replication agents between service persistencies using a replication configurator and service persistencies with endpoints at the data center locations as determined from a landscape directory; and configuring service deployments at the tenant-selected primary data center using the routing configurator and service endpoints read from the landscape directory. The method includes configuring a virtual service implementing a service mesh to be used to route service requests; configuring an ingress gateway using a routing configurator to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center; configuring data replication using a replication configurator to copy data to redundant storage according to tenant-specific software application solution preferences for primary and secondary data center locations; and configuring a persistent storage replication agent for each service persistence in the tenant-selected primary data center using the replication configurator and the persistent storage replication agent endpoints fetched from the landscape directory for each service persistence in the tenant-selected primary data center.

[0075] The above and other described implementations may each optionally include one or more of the following features.

[0076] The first feature, which can be combined with any of the following features, includes receiving, by the disaster recovery control plane, tenant-specific software application solution preferences for the primary and secondary data center locations; and storing the tenant-specific software application solution preferences for the primary and secondary data center locations in failover configuration persistence.

[0077] A second feature may be combined with either the previous or next feature, wherein the persistent storage replication agent replicates data for each tenant to a corresponding replication agent in a tenant-selected secondary data center.

[0078] A third feature, which can be combined with any of the previous or next features, includes triggering a disaster recovery control plane to perform a failover operation after detecting a disaster recovery event, and using the disaster recovery control plane to retrieve tenant-specific software application solution preferences for primary and secondary data center locations from failover configuration persistence 304 and reconfigure routing and replication.

[0079] A fourth feature, which can be combined with any of the previous or next features, includes translating tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration using a routing configurator, and retrieving service endpoints from a landscape directory.

[0080] A fifth feature, combinable with any of the previous or next features, includes configuring the service mesh to route service requests to service deployments in tenant-selected secondary data centers using a routing configurator and service endpoints.

[0081] A sixth feature, combinable with any of the previous or next features, includes configuring, using a routing configurator, an ingress gateway to route a user initial request to the service mesh to a first service instance at a tenant-selected secondary data center.

[0082] A seventh feature, combinable with any of the previous or next features, includes configuring data replication using a replication configurator to copy data to redundant storage based on tenant-specific software application solution preferences for primary and secondary data center locations.

[0083] An eighth feature, combinable with any of the previous or next features, includes fetching, by the replication configurator, an endpoint of a persistent storage replication agent from the landscape directory.

[0084] A ninth feature, which may be combined with any of the previous or next features, includes configuring, by the replication configurator and using the persistent storage replication agent endpoints, each service persistence in a tenant-selected secondary data center with information indicating to which primary data center the replication agent should replicate written data.

[0085] In a second implementation, a non-transitory computer-readable medium storing one or more instructions executable by a computer system to perform one or more operations for tenant-specific disaster recovery, the non-transitory computer-readable medium including: translating, by a routing configurator, tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration; setting up a service mesh for communication between services within and across the primary and secondary data center locations using the routing configurator; configuring replication agents between the service persistencies using a replication configurator and service persistencies with endpoints at the data center locations as determined from a landscape directory; and configuring a service persistency configuration using a replication configurator and service persistencies with endpoints at the data center locations as determined from a landscape directory. configuring a virtual service implementing a service mesh used to route service requests to a service deployment in the tenant-selected primary data center using the routing configurator and service endpoints provided; configuring an ingress gateway using the routing configurator to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center; configuring data replication using the replication configurator to copy data to redundant storage according to tenant-specific software application solution preferences for primary and secondary data center locations; and using the replication configurator and the persistent storage replication agent endpoints fetched from the landscape directory for each service persistence in the tenant-selected primary data center;and configuring a persistent storage replication agent for each service persistence in the tenant-selected primary data center.

[0086] The above and other described implementations may each optionally include one or more of the following features.

[0087] The first feature, which can be combined with any of the following features, includes receiving, by the disaster recovery control plane, tenant-specific software application solution preferences for the primary and secondary data center locations; and storing the tenant-specific software application solution preferences for the primary and secondary data center locations in failover configuration persistence.

[0088] A second feature may be combined with either the previous or next feature, wherein the persistent storage replication agent replicates data for each tenant to a corresponding replication agent in a tenant-selected secondary data center.

[0089] A third feature, which can be combined with any of the previous or next features, includes triggering a disaster recovery control plane to perform a failover operation after detecting a disaster recovery event, and using the disaster recovery control plane to retrieve tenant-specific software application solution preferences for primary and secondary data center locations from failover configuration persistence 304 and reconfigure routing and replication.

[0090] A fourth feature, which can be combined with any of the previous or next features, includes translating tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration using a routing configurator, and retrieving service endpoints from a landscape directory.

[0091] A fifth feature, combinable with any of the previous or next features, includes configuring the service mesh to route service requests to service deployments in tenant-selected secondary data centers using a routing configurator and service endpoints.

[0092] A sixth feature, combinable with any of the previous or next features, includes configuring an ingress gateway to route a user initial request to the service mesh to a first service instance at a tenant-selected secondary data center using a routing configurator.

[0093] A seventh feature, combinable with any of the previous or next features, includes configuring data replication using a replication configurator to copy data to redundant storage based on tenant-specific software application solution preferences for primary and secondary data center locations.

[0094] An eighth feature, combinable with any of the previous or next features, includes fetching, by the replication configurator, an endpoint of a persistent storage replication agent from the landscape directory.

[0095] A ninth feature, which may be combined with any of the previous or next features, includes configuring, by the replication configurator and using the persistent storage replication agent endpoints, each service persistence in a tenant-selected secondary data center with information indicating to which primary data center the replication agent should replicate written data.

[0096] In a third implementation, a computer-implemented system for tenant-specific disaster recovery includes one or more computers and one or more computer memory devices interoperably coupled to the one or more computers and having a tangible, non-transitory, machine-readable medium storing one or more instructions that, when executed by the one or more computers, perform one or more operations, the operations including translating, by a routing configurator, tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration; setting up a service mesh using the routing configurator for communication between services within and across the primary and secondary data center locations; and configuring endpoints at the data center locations as determined from a landscape directory. configuring a replication agent between service persistencies using both the replication configurator and the service persistency; configuring a virtual service implementing a service mesh used to route service requests to a service deployment in a tenant-selected primary data center using the routing configurator and service endpoints read from the landscape directory; configuring an ingress gateway using the routing configurator to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center; and configuring data replication using the replication configurator to copy data to redundant storage according to tenant-specific software application solution preferences for primary and secondary data center locations;and configuring a persistent storage replication agent for each service persistence at the tenant-selected primary data center using the replication configurator and the persistent storage replication agent endpoints fetched from the landscape directory for each service persistence at the tenant-selected primary data center.

[0097] The above and other described implementations may each optionally include one or more of the following features.

[0098] The first feature, which can be combined with any of the following features, includes receiving, by the disaster recovery control plane, tenant-specific software application solution preferences for the primary and secondary data center locations; and storing the tenant-specific software application solution preferences for the primary and secondary data center locations in failover configuration persistence.

[0099] A second feature may be combined with either the previous or next feature, wherein the persistent storage replication agent replicates data for each tenant to a corresponding replication agent in a tenant-selected secondary data center.

[0100] A third feature, which can be combined with any of the previous or next features, includes triggering a disaster recovery control plane to perform a failover operation after detecting a disaster recovery event, and using the disaster recovery control plane to retrieve tenant-specific software application solution preferences for primary and secondary data center locations from failover configuration persistence 304 and reconfigure routing and replication.

[0101] A fourth feature, which can be combined with any of the previous or next features, includes translating tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration using a routing configurator, and retrieving service endpoints from a landscape directory.

[0102] A fifth feature, combinable with any of the previous or next features, includes configuring the service mesh to route service requests to service deployments in tenant-selected secondary data centers using a routing configurator and service endpoints.

[0103] A sixth feature, combinable with any of the previous or next features, includes configuring, using a routing configurator, an ingress gateway to route a user initial request to the service mesh to a first service instance at a tenant-selected secondary data center.

[0104] A seventh feature, combinable with any of the previous or next features, includes configuring data replication using a replication configurator to copy data to redundant storage based on tenant-specific software application solution preferences for primary and secondary data center locations.

[0105] An eighth feature, combinable with any of the previous or next features, includes fetching, by the replication configurator, an endpoint of a persistent storage replication agent from the landscape directory.

[0106] A ninth feature, which may be combined with any of the previous or next features, includes configuring, by the replication configurator and using the persistent storage replication agent endpoints, each service persistence in a tenant-selected secondary data center with information indicating to which primary data center the replication agent should replicate written data.

[0107] Implementations of the subject matter and functional operations described herein can be implemented in digital electronic circuitry, tangibly embodied computer software or firmware, computer hardware, or a combination of one or more of these, including the structures disclosed herein and structural equivalents thereof. Software implementations of the described subject matter may be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible, non-transitory computer-readable medium for execution by or to control the operation of a computer or computer-implemented system. Alternatively, or in addition, the program instructions may be encoded in / on an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to a receiver device for execution by the computer or computer-implemented system. The computer storage medium can be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of computer storage media. Configuring one or more computers means that the one or more computers already have installed hardware, firmware, or software (or a combination of hardware, firmware, and software) such that certain computing operations are performed when the software is executed by the one or more computers. However, a computer storage medium is not a propagating signal.

[0108] The terms "real-time," "real time," "realtime," "real (fast) time (RFT)," "near(ly) real-time (NRT)," "quasi real-time," or similar terms (as understood by those skilled in the art) mean that an action and response are so close in time that an individual perceives the action and response as occurring substantially simultaneously. For example, the time lag between an individual's action to access data and the response to the display (or beginning of display) of the data following the response may be less than 1 millisecond (ms), less than 1 second, or less than 5 seconds. The requested data need not be displayed (or begin to be displayed) instantly, although it may be displayed (or begin to be displayed) without any intentional delay, taking into account the processing limitations of the computing system being described and the time it takes, for example, to collect, accurately measure, analyze, process, store, or transmit the data.

[0109] The terms “data processing apparatus,” “computer,” “computing device,” or “electronic computing device” (or equivalent terms as understood by those skilled in the art) refer to data processing hardware and encompass all types of apparatus, devices, and machines for processing data, including, for example, a programmable processor, a computer, or multiple processors or computers. A computer may also be or further include special-purpose logic circuitry, such as a central processing unit (CPU), a field programmable gate array (FPGA), or an application-specific integrated circuit (ASIC). In some implementations, a computer or computer-implemented system or special-purpose logic circuitry (or a combination of a computer or computer-implemented system and special-purpose logic circuitry) may be hardware- or software-based (or based on a combination of both hardware and software-based). A computer may also optionally include code that creates an execution environment for a computer program, such as processor firmware, a protocol stack, a database management system, an operating system, or code that constitutes a combination of the execution environment. This disclosure contemplates the use of a computer or computer-implemented system with an operating system, such as LINUX, UNIX, WINDOWS, MAC OS, ANDROID, or IOS, or a combination of operating systems.

[0110] A computer program, which may also be referred to or described as a program, software, software application, unit, module, software module, script, code, or other component, can be written in any form of programming language, including compiled or interpreted languages, or declarative or procedural languages, and can be deployed in any form, including, for example, a stand-alone program, module, component, or subroutine, for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program can be stored in part of a file that holds other programs or data, e.g., one or more scripts stored in a markup language document, in a single file dedicated to the program of interest, or in multiple cooperating files, e.g., files that store one or more modules, subprograms, or portions of code. A computer program can be deployed to run on one computer or on multiple computers that are located at one site or distributed across multiple sites and interconnected by a communications network.

[0111] Although portions of the programs illustrated in the various figures may be illustrated as separate components, such as units or modules, that implement the described features and functionality using various objects, methods, or other processes, the programs may instead include multiple sub-units, sub-modules, third-party services, components, libraries, or other components, as appropriate. Conversely, features and functionality of various components may be combined into a single component, as appropriate. Thresholds used to make computational decisions may be determined statically, dynamically, or both statically and dynamically.

[0112] The described methods, processes, or logic flows represent one or more examples of functionality consistent with the present disclosure and are not intended to limit the disclosure to the implementations described or illustrated, but are intended to be accorded the widest scope consistent with the principles and features described. The described methods, processes, or logic flows may be performed by one or more programmable computers executing one or more computer programs to perform functions by manipulating input data and generating output. The methods, processes, or logic flows may also be performed by, and the computers may also be implemented as, special purpose logic circuitry, such as a CPU, FPGA, or ASIC.

[0113] A computer for executing a computer program may be based on a general-purpose microprocessor, a special-purpose microprocessor, both, or another type of CPU. Typically, a CPU receives instructions and data from and writes them to memory. The essential elements of a computer are a CPU for performing or executing instructions and one or more memory devices for storing instructions and data. Typically, a computer also includes one or more mass storage devices, e.g., magnetic disks, magneto-optical disks, or optical disks, for storing data and is operatively coupled to receive data from, transfer data to, or both. However, a computer need not have such devices. Furthermore, a computer can be incorporated into other devices, such as a mobile phone, a personal digital assistant (PDA), a portable audio or video player, a game console, a global positioning system (GPS) receiver, or a portable memory storage device, e.g., a universal serial bus (USB) flash drive, to name a few.

[0114] Non-transitory computer-readable media for storing computer program instructions and data may include all forms of permanent / non-permanent or volatile / non-volatile memory, media, and memory devices, including, for example, semiconductor memory devices such as random access memory (RAM), read-only memory (ROM), phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory devices, magnetic devices such as tapes, cartridges, cassettes, internal / removable disks, magneto-optical disks, and optical memory devices such as digital versatile / video discs (DVDs), compact discs (CD)-ROMs, DVD+ / -R, DVD-RAMs, DVD-ROMs, high-definition / density (HD)-DVDs, and BLU-RAYs / BLU-RAY DISCs (BDs), as well as other optical memory technologies. The memory may store various objects or data, including caches, classes, frameworks, applications, modules, backup data, jobs, web pages, web page templates, data structures, database tables, repositories that store dynamic information, or other suitable information, including parameters, variables, algorithms, instructions, rules, constraints, or references. In addition, the memory may contain other suitable data, such as logs, policies, security or access data, or report files. The processor and memory may be supplemented by or incorporated in special purpose logic circuitry.

[0115] To interact with a user, implementations of the subject matter described herein may be implemented on a computer having a display device, e.g., a cathode ray tube (CRT), liquid crystal display (LCD), light-emitting diode (LED), or plasma monitor, for displaying information to the user, and a keyboard and pointing device, e.g., a mouse, trackball, or trackpad, for the user to provide input to the computer. Input may also be provided to a computer using a touchscreen, such as a tablet computer screen with pressure-sensitive capabilities or a multi-touch screen with capacitive or electrical sensing capabilities. Other types of devices may also be used to interact with the user. For example, feedback provided to the user can be any form of sensory feedback (visual feedback type, auditory feedback type, haptic feedback type, or a combination of these types). Input from the user can be received in any form, including acoustic, speech, or tactile input. In addition, the computer can interact with the user by sending documents to and receiving documents from a client computing device used by the user (e.g., by sending a web page to a web browser on the user's mobile computing device in response to a request received from the web browser).

[0116] The term "graphical user interface (GUI)" may be used in the singular or plural to describe one or more graphical user interfaces and each of the displays of a particular graphical user interface. Thus, a GUI may refer to any graphical user interface, including, but not limited to, a web browser, a touch screen, or a command line interface (CLI), that processes information and efficiently presents information results to a user. In general, a GUI may include numerous user interface (UI) elements, some or all of which are associated with a web browser, such as interactive fields, pull-down lists, and buttons. These and other UI elements may relate to or represent the functionality of a web browser.

[0117] Implementations of the subject matter described herein may be implemented in a computing system that includes a back-end component, e.g., as a data server, or includes a middleware component, e.g., an application server, or includes a front-end component, e.g., a client computer having a graphical user interface or web browser that a user can use to interact with an implementation of the subject matter described herein, or any combination of one or more such back-end, middleware, or front-end components. The components of the system may be interconnected by any form or medium of wired or wireless digital data communication (or combination of data communication), e.g., a communications network. Examples of communications networks include a local area network (LAN), a radio access network (RAN), a metropolitan area network (MAN), a wide area network (WAN), Worldwide Interoperability for Microwave Access (WIMAX), a wireless local area network (WLAN) using e.g., 802.11x or other protocols, all or a portion of the Internet, another communications network, or a combination of communications networks. A communications network may communicate, for example, Internet Protocol (IP) packets, Frame Relay frames, Asynchronous Transfer Mode (ATM) cells, voice, video, data, or other information between network nodes.

[0118] A computing system may include clients and servers. Clients and servers are generally remote from each other and typically interact through a communication network. The relationship of clients and servers arises by virtue of computer programs running on the respective computers and having a client-server relationship thereto.

[0119] While this specification contains many implementation-specific details, these should not be construed as limitations on the scope of the inventive concepts or the scope of the claims, but rather as descriptions of features that may be unique to particular implementations of particular inventive concepts. Some features that are described in the context of separate implementations herein may also be realized in combination in a single implementation. Conversely, various features that are described in the context of a single implementation may also be implemented separately or in any subcombination in multiple implementations. Furthermore, while the features described above may be described as working in several combinations, and even initially claimed as such, one or more features from a claimed combination may in some cases be deleted from the combination, and the claimed combination may be directed to a subcombination or a variation of a subcombination.

[0120] Particular implementations of the subject matter have been described. Other implementations, modifications, and permutations of the described implementations are within the scope of the following claims, as will be apparent to those skilled in the art. While operations are shown in the figures or in the claims in a particular order, it should be understood that such operations need not be performed in the particular order or sequence shown to achieve desirable results, nor that all illustrated operations need be performed (some operations may be considered optional). In some situations, multitasking or parallel processing (or a combination of multitasking and parallel processing) may be advantageous and performed where deemed appropriate.

[0121] It should be understood that the separation or incorporation of various system modules and components in the above-described implementations should not be understood as requiring such separation or incorporation in all implementations, and that the described program components and systems may generally be integrated into a single software product or packaged as multiple software products.

[0122] Accordingly, the foregoing exemplary implementations do not define or constrain this disclosure, and other changes, substitutions, and alterations are also possible without departing from the scope of this disclosure.

[0123] Furthermore, the claimed implementations are believed to be applicable to a computer system comprising at least a computer-implemented method, a non-transitory computer-readable medium storing computer-readable instructions for performing the computer-implemented method, and a computer memory interoperably coupled with a hardware processor configured to execute the computer-implemented method or the instructions stored in the non-transitory computer-readable medium. [Explanation of symbols]

[0124] 100 Box Diagrams 102a~102c Data Center I~III 104 Data Center IV 106 Data Center V 108 Service 1 108' Persistence 110 Service 2 112 Service 3 114 Service 4 200 Box Diagrams 300 ways 302 Central Disaster Recovery Control Plane 304 Failover Configuration Persistence 306 Routing Configurator 308 Landscape Directory 310 Virtual Services 312 Ingress Gateway 313 End User Initial Request 314 Replication Configurator 316 / 318 / 322 / 324 Replication Agents 320 Virtual Services 400 Computerized Implementation Systems 402 Computer 403 System Bus 404 Interface 405 processor 406 Database 407 Memory 408 Application 412 Application Programming Interface (API) 413 Service Layer 414 Power supply 430 Network

Claims

1. 1. A computer-implemented method for tenant-specific disaster recovery, comprising: translating, by a routing configurator, tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration; using the routing configurator to set up a service mesh for communication between services within and across the primary and secondary data center locations; configuring replication agents between said service persistencies using a replication configurator and service persistencies with endpoints at data center locations as determined from the landscape directory; using the routing configurator and service endpoints read from the landscape directory to configure a virtual service implementing the service mesh to be used to route service requests to service deployments in tenant-selected primary data centers; configuring an ingress gateway to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center using the routing configurator; configuring data replication using the replication configurator to copy data to redundant storage according to the tenant-specific software application solution preferences for primary and secondary data center locations; and configuring a persistent storage replication agent for each service persistence at the tenant-selected primary data center using the replication configurator and persistent storage replication agent endpoints fetched from the landscape directory for each service persistence at the tenant-selected primary data center.

2. receiving, by a disaster recovery control plane, the tenant-specific software application solution preferences for primary and secondary data center locations; and saving the tenant-specific software application solution preferences for primary and secondary data center locations in a failover configuration persistence.

3. 3. The computer-implemented method of claim 2, wherein the persistent storage replication agent replicates data for each tenant to a corresponding replication agent in a tenant-selected secondary data center.

4. triggering the disaster recovery control plane to perform a failover operation upon detection of a disaster recovery event; retrieving the tenant-specific software application solution preferences for primary and secondary data center locations from the failover configuration persistence 304 using the disaster recovery control plane; and reconfiguring routing and replication.

5. translating the tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration using the routing configurator; and retrieving the service endpoint from the landscape directory.

6. 6. The computer-implemented method of claim 5, further comprising configuring the service mesh to route service requests to service deployments at the tenant-selected secondary data centers using the routing configurator and the service endpoints.

7. 7. The computer-implemented method of claim 6, comprising using the routing configurator to configure an ingress gateway to route a user initial request to the service mesh to a first service instance in the tenant-selected secondary data center.

8. 8. The computer-implemented method of claim 7, further comprising using the replication configurator to configure data replication to copy data to redundant storage based on the tenant-specific software application solution preferences for primary and secondary data center locations.

9. 9. The computer-implemented method of claim 8, further comprising fetching, by the replication configurator, an endpoint for the persistent storage replication agent from the landscape directory.

10. 10. The computer-implemented method of claim 9, further comprising configuring, by the replication configurator, each service persistence in the tenant-selected secondary data center using the endpoint of the persistent storage replication agent with information indicating to which primary data center the replication agent should replicate written data.

11. A non-transitory computer-readable medium storing one or more instructions executable by a computer system to perform one or more operations for tenant-specific disaster recovery, the non-transitory computer-readable medium comprising: translating tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration via a routing configurator; using the routing configurator to set up a service mesh for communication between services within and across the primary and secondary data center locations; configuring replication agents between said service persistencies using a replication configurator and service persistencies with endpoints at data center locations as determined from a landscape directory; configuring a virtual service implementing the service mesh to be used to route service requests to service deployments in tenant-selected primary data centers using the routing configurator and service endpoints read from the landscape directory; configuring an ingress gateway to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center using the routing configurator; configuring data replication using the replication configurator to copy data to redundant storage according to the tenant-specific software application solution preferences for primary and secondary data center locations; and configuring a persistent storage replication agent for each service persistence at the tenant-selected primary data center using the replication configurator and persistent storage replication agent endpoints fetched from the landscape directory for each service persistence at the tenant-selected primary data center.

12. receiving, by a disaster recovery control plane, the tenant-specific software application solution preferences for primary and secondary data center locations; and saving the tenant-specific software application solution preferences for primary and secondary data center locations in a failover configuration persistence.

13. 13. The non-transitory computer-readable medium of claim 12, wherein the persistent storage replication agent replicates data for each tenant to a corresponding replication agent in a tenant-selected secondary data center.

14. triggering the disaster recovery control plane to perform a failover operation upon detection of a disaster recovery event; Retrieving the tenant-specific software application solution preferences for primary and secondary data center locations from the failover configuration persistence 304 using the disaster recovery control plane; and reconfiguring routing and replication.

15. translating the tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration using the routing configurator; and and reading the service endpoint from the landscape directory.

16. 16. The non-transitory computer-readable medium of claim 15, further comprising configuring the service mesh to route service requests to service deployments at the tenant-selected secondary data centers using the routing configurator and the service endpoints.

17. 17. The non-transitory computer-readable medium of claim 16, further comprising using the routing configurator to configure an ingress gateway to route a user initial request to the service mesh to a first service instance in the tenant-selected secondary data center.

18. 20. The non-transitory computer-readable medium of claim 17, further comprising using the replication configurator to configure data replication to copy data to redundant storage based on the tenant-specific software application solution preferences for primary and secondary data center locations.

19. 20. The non-transitory computer-readable medium of claim 18, further comprising fetching, by the replication configurator, an endpoint of the persistent storage replication agent from the landscape directory.

20. 1. A computer-implemented system for tenant-specific disaster recovery, comprising: one or more computers; one or more computer memory devices interoperably coupled with the one or more computers and having a tangible, non-transitory, machine-readable medium storing one or more instructions that, when executed by the one or more computers, perform one or more operations; translating tenant-specific software application solution preferences for primary and secondary data center locations into a routing configuration via a routing configurator; using the routing configurator to set up a service mesh for communication between services within and across the primary and secondary data center locations; configuring replication agents between said service persistencies using a replication configurator and service persistencies with endpoints at data center locations as determined from a landscape directory; configuring a virtual service implementing the service mesh to be used to route service requests to service deployments in tenant-selected primary data centers using the routing configurator and service endpoints read from the landscape directory; configuring an ingress gateway to route end-user requests in the service mesh to a first service instance in the tenant-selected primary data center using the routing configurator; configuring data replication using the replication configurator to copy data to redundant storage according to the tenant-specific software application solution preferences for primary and secondary data center locations; and configuring a persistent storage replication agent for each service persistence at the tenant-selected primary data center using the replication configurator and persistent storage replication agent endpoints fetched from the landscape directory for each service persistence at the tenant-selected primary data center.