Systems and methods for migration planning, evaluation, and activation
The cloud bridge mechanism and discovery/inventory system address integration challenges by facilitating seamless cloud service integration with on-premises environments, reducing adoption barriers and network exposure, and supporting complex migrations.
Patent Information
- Application Number
- JP2025536733
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2023-12-21
- Publication Date
- 2026-01-14
AI Technical Summary
Organizations face challenges in managing and integrating diverse cloud and on-premises resources due to IT silos, leading to time-consuming and error-prone manual integration tasks, and existing cloud service integration methods create adoption barriers and require significant network changes.
A cloud bridge mechanism and discovery/inventory system for integrating cloud services with on-premises environments, using specialized agents and a discovery control plane to facilitate migration and multi-cloud use cases, with support for various asset types and environments.
Enables seamless integration of cloud services with on-premises resources, reducing adoption barriers and network exposure, and providing a flexible framework for complex migrations.
Smart Images

Figure 2026501299000001_ABST
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Nonprovisional Patent Application No. 18 / 533,704, filed December 8, 2023, which claims the benefit of and priority under 35 U.S.C. 119(e) to U.S. Provisional Patent Application No. 63 / 434,879, filed December 22, 2022, and U.S. Provisional Patent Application No. 63 / 434,846, filed December 22, 2022, the entire contents of which are incorporated herein by reference for all purposes.
[0002] Field The present disclosure relates generally to resource integration with cloud services, and more particularly to techniques for extending the reach of cloud services to on-premise or off-premise environments and other cloud platforms to enable migration and multi-cloud use cases. [Background technology]
[0003] background Cloud computing has been a staple of many organizations for many years, providing a suite of online services such as collaboration, communication, data storage and backup, and user relationship management tools—essentially all the technological elements needed to run a business. Currently, there are four main types of cloud computing: private cloud, public cloud, hybrid cloud, and multicloud. A private cloud architecture is a cloud environment dedicated to a single user, group, or organization, which can be on-premises or off-premises. A public cloud architecture is a cloud environment dedicated to multiple users, groups, or organizations, which can be on-premises or off-premises. A hybrid cloud architecture uses both a public cloud architecture and a private cloud architecture or on-premises infrastructure. A multicloud architecture is a combination of clouds (private and / or public) across multiple vendors. Each of these cloud types can be configured to offer a variety of cloud computing services, including Infrastructure as a Service (IaaS), Platforms as a Service (PaaS), Software as a Service (SaaS), and Integration Platform as a Service (iPaaS). IaaS provides standard compute, storage, and network resources at a scale based on demand. PaaS provides software development and deployment resources. SaaS provides software distribution to end users. iPaaS is a set of cloud services that allows users to develop, run, and manage integration flows between different applications.
[0004] The growth of cloud computing has enabled organizations to use a wide variety of highly scalable resources and services on demand, rather than building and maintaining them on- or off-premises. However, in some organizations, the emergence of these diverse resources and services has created information technology (IT) silos as administrators struggle to manage and maintain each different cloud resource and / or on- or off-premises resource (non-cloud resources). For example, IT silos can arise when only one group of people (e.g., one department within an organization) has access to a particular resource. Cloud-based integration (also known as cloud integration) unifies all different cloud resources and / or on- or off-premises resources to avoid such instances of IT silos. Cloud integration is a form of systems integration business delivered as a cloud computing service that addresses the integration of data, processes, service-oriented architecture (SOA), and applications. At the most basic level, cloud integration means connecting a wide range of processes, applications, systems, data repositories, and other IT environments (e.g., public cloud, private cloud, on-premises infrastructure, etc.) in either hybrid or multi-cloud deployments so that they can operate as a single, cohesive IT infrastructure for an organization. Without a cloud integration solution, administrators must perform each integration task separately and manually, a process that is time-consuming and increases the likelihood of error. Summary of the Invention [Means for solving the problem]
[0005] Quick Overview Provided herein are techniques (e.g., methods, systems, non-transitory computer-readable media having code or instructions executable by one or more processors) for planning, assessing, and initiating migration. One aspect relates to a method. The method includes identifying at least one asset in a source environment; adding the asset to a migration project, where the migration project specifies a source environment and a destination environment for replicating the asset; receiving a request for generation of a recommended shape, where the recommended shape specifies a shape of the replicated asset in the destination environment; and generating the recommended shape based on metadata characterizing attributes of the source environment, a user-provided replication strategy, and rules specifying compatibility requirements for the recommended shape. In some embodiments, the metadata characterizes at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.
[0006] In some embodiments, the destination environment is within a tenancy on a cloud services provider infrastructure (CSPI). In some embodiments, the method includes receiving metadata characterizing attributes of the source environment. In some embodiments, the metadata characterizes attributes of assets in the source environment. In some embodiments, the CPU-related attributes characterize at least one of a number of CPUs of assets in the source environment, an average CPU usage by assets in the source environment, or a maximum CPU usage in the source environment.
[0007] In some embodiments, the network-related attributes characterize at least one of an average bandwidth usage by assets in the source environment, or a maximum bandwidth usage by assets in the source environment. In some embodiments, the metadata characterizes at least a graphics processing unit (GPU)-related attribute and a memory-related attribute. In some embodiments, the GPU-related attribute characterizes at least one of a number of GPUs of assets in the source environment, an average GPU usage by assets in the source environment, or a maximum GPU usage in the source environment.
[0008] In some embodiments, the method includes receiving an evaluation strategy from a user. In some embodiments, the evaluation strategy specifies a performance capability of the recommended shape. In some embodiments, the evaluation strategy specifies at least one of an average strategy or a peak strategy.
[0009] In some embodiments, the method includes generating shape requirements for a recommended shape based on the evaluation strategy. In some embodiments, generating the recommended shape includes identifying a plurality of potential shapes. In some embodiments, generating the recommended shape includes generating a compatibility score characterizing the compatibility of the potential shape with the source asset.
[0010] In some embodiments, generating the recommended shapes further includes selecting at least one of the potential shapes based at least in part on a compatibility score of the selected at least one of the potential shapes. In some embodiments, the selected at least one of the potential shapes is fully compatible with the source asset. In some embodiments, the selected at least one of the potential shapes is at least partially incompatible with the source asset.
[0011] One aspect relates to a system including a memory including executable instructions and one or more processors capable of executing the executable instructions, the executable instructions performing the following actions: identifying at least one asset in a source environment; adding the asset to a migration project, the migration project specifying a source environment and a destination environment for replicating the asset; receiving a request for generation of a recommended shape, the recommended shape specifying a shape of the replicated asset in the destination environment; and generating the recommended shape based on metadata characterizing attributes of the source environment, a user-provided replication strategy, and rules specifying compatibility requirements for the recommended shape. In some embodiments, the metadata characterizes at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.
[0012] In some embodiments, the one or more processors may further execute executable instructions to receive metadata characterizing attributes of the source environment, hi some embodiments, the metadata characterizing attributes of assets in the source environment.
[0013] One aspect relates to a non-transitory computer-readable storage medium storing instructions executable by one or more processors. In some embodiments, the instructions, when executed by the one or more processors, cause the one or more processors to: identify at least one asset in a source environment; add the asset to a migration project, where the migration project specifies a source environment and a destination environment for replicating the asset; receive a request for generation of a recommended shape, where the recommended shape specifies a shape of the replicated asset in the destination environment; and generate the recommended shape based on metadata characterizing attributes of the source environment, a replication strategy provided by a user, and rules specifying compatibility requirements for the recommended shape. In some embodiments, the metadata characterizes at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.
[0014] The techniques described above and below can be implemented in many ways and in many contexts. Several example implementations and contexts are provided with reference to the following figures, as described in further detail below. However, the following implementations and contexts are only some of the many implementations and contexts. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a high-level diagram of a distributed environment showing an overlay cloud network or a user's virtual cloud network hosted by a cloud service provider infrastructure, according to various embodiments. [Figure 2] FIG. 1 is a simplified architectural diagram of physical components in a physical network within an underlying cloud service provider infrastructure for a virtual network, according to various embodiments. [Figure 3]FIG. 1 illustrates an example in a cloud service provider infrastructure where a host machine is connected to multiple network virtualization devices, according to various embodiments. [Figure 4A] 4 is a high-level diagram of a distributed environment 400 illustrating a cloud bridge architecture for managing and configuring remote resources that interact with cloud services, according to various embodiments. [Figure 4B] FIG. 1 is a simplified block diagram illustrating a user's external environment as part of a virtual appliance, according to various embodiments. [Figure 4C] FIG. 1 is a simplified block diagram illustrating a user's external environment as part of a virtual appliance, according to various embodiments. [Figure 5] FIG. 1 is a schematic diagram of a cloud migration workflow, according to various embodiments. [Figure 6] FIG. 1 is a simplified block diagram of an architecture that may be implemented for cloud migration, according to various embodiments. [Figure 7] FIG. 1 illustrates one embodiment of a workflow for a transition service. [Figure 8] 1 is a flowchart illustrating one embodiment of a recommendation process. [Figure 9] FIG. 1 is a block diagram illustrating one pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 10] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 11] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 12] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 13]FIG. 1 is a block diagram illustrating an exemplary computer system according to at least one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] Detailed Description In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of certain embodiments. However, it will be apparent that various embodiments may be practiced without these specific details. The figures and descriptions are not intended to be limiting. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or designs.
[0017] introduction Cloud computing is on-demand access to computing resources (e.g., applications, servers (physical and virtual), data storage, development tools, network functions, etc.) hosted in remote data centers managed by a cloud service provider over a network such as the Internet. A cloud infrastructure, such as Oracle Cloud Infrastructure (OCI), is a set of cloud computing services (cloud services) that enables users to build and run a variety of applications and services within a hosted environment. The cloud infrastructure provides high-performance computing and storage capacity (as physical or virtual hardware instances) physically hosted within one or more global regions (i.e., data centers managed by a cloud service provider such as Oracle) within a flexible overlay virtual network securely accessible from a user's on-premises network. The cloud services offered by the cloud infrastructure are natively integrated with resources maintained within the hosted environment, such as databases and compute instances (e.g., physical and / or virtual servers). There is a strong demand to use these cloud services with resources in remote environments, which can be on-premises or off-premises resources, including other cloud resources.
[0018] Traditionally, the user experience of integrating remote resources with cloud services has been complicated. Many services require the deployment of service-specific agents, and connecting on- or off-premises resources to the cloud requires either a one-time service-specific solution or the establishment of a private site-to-site network connection to the cloud infrastructure. For example, Database Management Cloud Service, Oracle Data Safe Service, and Database Migration Service have traditionally implemented three separate frameworks for integrating with remote databases. Service-specific solutions create adoption barriers, fragment cloud service providers' service portfolios with inconsistent on-premises support, and force users to onboard each service independently. Furthermore, all cloud services are burdened with building and maintaining support for remote sites. Site-to-site network connections offer a more unified experience, but have a high barrier to adoption because they require significant changes to the remote network infrastructure and force wide exposure of users' networks to the cloud infrastructure.
[0019] The approach described in this disclosure provides a simple and secure mechanism for extending the reach of cloud services to on-premises or off-premises environments and other cloud platforms, enabling migration and multi-cloud use cases. This mechanism is implemented by a cloud bridge, which provides a framework and platform for integrating cloud service capabilities with external environments or assets (i.e., bridging the gap and connecting cloud services with external environments or assets). An exemplary use case is facilitating the native migration of virtual machines from an on-premises VMware virtualization environment to a cloud infrastructure (i.e., cloud migration). Another exemplary use case is facilitating the use of virtual machines deployed on a cloud infrastructure provided by a first cloud provider with assets stored on a different cloud infrastructure provided by a second cloud provider (i.e., multi-cloud). This integration is based on specialized software components (i.e., agents) deployed by the user to the external environment. Each agent consists of agent software residing in the external environment and a corresponding agent control plane residing in the cloud infrastructure.
[0020] Nevertheless, users often struggle to understand their legacy environments, including what assets they have and how they interact. For example, to migrate on-premises VMware virtual appliances to OCI native virtual machines, customers need to understand what virtual appliances they have and how they interact. Discovery involves learning about a customer's environment. For a migration use case, it involves discovering customer resources that are part of various customers' on-premises VMware environments. After discovery, customers need to investigate the properties of their on-premises resources to determine what they want to migrate to OCI. As an example, a customer may want to identify virtual appliances running Oracle E-Business Suite by filtering a list of all VMware appliances to VMware appliances with "ebs" in their names. Then, the customer may want to further limit the list to appliances running production workloads by filtering only appliances with five or more cores.
[0021] To address these and other challenges, this disclosure describes a system and workflow for discovery and inventory of components for remote resource integration with cloud services. The discovery and inventory are designed to support thousands of customers, each with tens of thousands of assets. Because migrations are often highly complex, the goal is to build a flexible framework with various capabilities, such as support for various types of external user environments, various types of assets, and various types of asset discovery mechanisms. In summary, the system and workflow include discovery and inventory to provide a representation of a user's external environment to support various services, such as migration use cases. Discovery includes discovering resources in a customer's environment and creating / updating assets that represent the resources in the inventory. Discovery is implemented using a discovery control plane on the cloud infrastructure side and discovery plugins on the external environment side. The discovery control plane is deployed in an overlay, backed by one or more databases, and includes customer-facing application programming interfaces (APIs) that are responsible for configuring discovery and coordinating the discovery plugins. Discovery plugins are deployed in the customer's external environment and are responsible for collecting asset metadata and reporting it to the inventory control plane. Inventory involves storing metadata about assets and relationships discovered by the discovery component or imported by the customer. Inventory is implemented on the cloud infrastructure side using an inventory control plane that includes customer-facing APIs deployed in the overlay and backed by one or more database-based data stores.
[0022] In various embodiments, a computer-implemented process is provided that includes deploying a remote agent appliance in a user's external environment, the remote agent appliance including a discovery plug-in; creating an asset source that specifies locations in the external environment where external assets and associated asset metadata should be discovered along with references to authentication information stored in a data store; creating a discovery policy for discovering the external assets in the asset source; generating a discovery job to retrieve asset metadata about the external assets discovered in the asset source; running the discovery job using the discovery plug-in to discover the external assets in the asset source based on the discovery policy, where running the discovery job includes retrieving asset metadata about the external assets discovered in the asset source and adding the asset metadata to an inventory, the inventory including a collection of assets including the asset metadata about the external assets; and providing the collection of assets in the inventory and the associated asset metadata to a user. In some cases, an asset analytics API is also provided to the user to help the user aggregate asset metadata to gain insight into the user's external environment (e.g., an on-premises environment).
[0023] As used herein, when an action is "based on" something, this means that the action is at least partially based on at least a portion of something. As used herein, the terms "similarly," "substantially," "approximately," and "about" are defined as approximately, but not necessarily completely (including completely), as understood by one of ordinary skill in the art. In any disclosed embodiment, the terms "similarly," "substantially," "approximately," and "about" may be substituted "within a percentage of" what is specified, including 0.1, 1, 5, and 10 percent.
[0024] Cloud Network Example The term cloud services is typically used to refer to services made available on-demand (e.g., through a subscription model) by a cloud services provider (CSP) to users (e.g., cloud service customers) using systems and infrastructure (cloud infrastructure) provided by the CSP. Typically, the servers and systems that make up the CSP's infrastructure are separate from the users' own on-premises servers and systems. Thus, users can utilize cloud services provided by the CSP without having to purchase separate hardware and software resources for the service. Cloud services are designed to provide subscribing users with easy and scalable access to applications and computing resources without requiring the users to invest in procuring the infrastructure used to deliver the service.
[0025] There are multiple cloud service providers offering various types of cloud services. As described herein, cloud services come in various types or models, including SaaS, PaaS, IaaS, etc. A user can subscribe to one or more cloud services offered by a CSP. A user can be any entity, such as an individual, an organization, or a business. When a user subscribes or registers for a service offered by a CSP, a tenancy or account is created for the user. The account then enables the user to access one or more subscribed cloud resources associated with the account.
[0026] As mentioned above, IaaS is a specific type of cloud computing service. In the IaaS model, a CSP provides infrastructure (called cloud service provider infrastructure, or CSPI) that can be used by users to build their own customizable networks and deploy their resources. Thus, the user's resources and network are hosted in a distributed environment by the infrastructure provided by the CSP. This differs from traditional computing, where the user's resources and network are hosted by the infrastructure provided by the user.
[0027] CSPI can comprise interconnected, high-performance computing resources, including various host machines, memory resources, and network resources that form a physical network, also known as a substrate network or underlay network. Resources in CSPI can be distributed across one or more data centers, which can be geographically distributed across one or more geographic regions. Virtualization software can be run by these physical resources to provide a virtualized, distributed environment. This virtualization creates an overlay network (also known as a software-based network, software-defined network, or virtual network) on top of the physical network. The CSPI physical network provides the underlying foundation upon which one or more overlay or virtual networks can be created on top of the physical network. The physical network (or substrate or underlay network) includes physical network devices such as physical switches, routers, computers, and host machines. An overlay network is a logical (or virtual) network that operates on top of the physical substrate network. A particular physical network can support one or more overlay networks. Overlay networks typically use encapsulation techniques to distinguish traffic belonging to different overlay networks. A virtual network or overlay network is also called a virtual cloud network (VCN). A virtual network is implemented using software virtualization technologies (e.g., hypervisors, network virtualization devices (NVDs) (e.g., smart NICs), top-of-rack (TOR) switches, virtualization functions performed by smart TORs that perform one or more functions performed by NVDs, and other mechanisms) to create a layer of network abstraction that can run on top of a physical network. Virtual networks can take many forms, including peer-to-peer networks, IP networks, etc.Virtual networks are typically either Layer 3 IP networks or Layer 2 VLANs. This method of virtual or overlay networking is often called a virtual Layer 3 network or an overlay Layer 3 network. Examples of protocols developed for virtual networks include IP-in-IP (or Generic Routing Encapsulation (GRE)), Virtual Extensible LAN (VXLAN - IETF RFC 7348), Virtual Private Networks (VPN) (e.g., MPLS Layer 3 Virtual Private Network (RFC 4364)), VMware's NSX, and Generic Network Virtualization Encapsulation (GENEVE).
[0028] In the case of IaaS, the infrastructure provided by the CSP (CSPI) may be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing service provider may host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, the IaaS provider may offer various services (e.g., billing, monitoring, logging, security, load balancing, clustering, etc.) incidental to those infrastructure components. Accordingly, these services may be policy-driven, allowing IaaS users to implement policies to drive load balancing and maintain application availability and performance. The CSPI provides infrastructure and a set of complementary cloud services that enable users to build and run a wide range of applications and services within a highly available, hosted, distributed environment. The CSPI provides high-performance computing resources and computing power as well as storage capacity within a flexible virtual network that can be securely accessed from various networked locations, such as from the user's on-premises network. When a user subscribes or registers for an IaaS service offered by a CSP, the tenancy created for that user is a secure, isolated partition within the CSP where the user can create, organize, and manage their cloud resources.
[0029] Users can build their own virtual networks using the compute, memory, and network resources provided by CSPI. One or more user resources or workloads, such as compute instances, can be deployed into these virtual networks. For example, users can build one or more customizable private virtual networks called virtual cloud networks (VCNs) using resources provided by CSPI. Users can deploy one or more user resources, such as compute instances, into their VCNs. Compute instances can take the form of virtual machines, bare metal instances, etc. Thus, CSPI provides infrastructure and a set of complementary cloud services that enable users to build and run a wide range of applications and services within a highly available hosted virtual environment. Users do not manage or control the underlying physical resources provided by CSPI, but they do have control over the operating system, storage, and deployed applications, and in some cases, limited control over selected network components (e.g., firewalls).
[0030] The CSP may provide a console that allows users and network administrators to configure, access, and manage resources deployed in the cloud using CSPI resources. In one embodiment, the console provides a web-based user interface that can be used to access and manage the CSPI. In some implementations, the console is a web-based application provided by the CSP.
[0031] CSPI may support single-tenancy or multi-tenancy architectures. In a single-tenancy architecture, a software component (e.g., an application, a database) or a hardware component (e.g., a host machine or server) serves a single user or tenant. In a multi-tenancy architecture, a software component or hardware component serves multiple users or tenants. Thus, in a multi-tenancy architecture, CSPI resources are shared among multiple users or tenants. In a multi-tenancy situation, precautions are taken and safeguards are implemented within CSPI to ensure that each tenant's data remains isolated and invisible to other tenants.
[0032] In a physical network, a network endpoint (“endpoint”) refers to a computing device or system that is connected to the physical network and communicates with the connected network. Network endpoints in a physical network may be connected to a local area network (LAN), a wide area network (WAN), or other types of physical networks. Examples of traditional endpoints in a physical network include modems, hubs, bridges, switches, routers, and other network devices, physical computers (or host machines), and the like. Each physical device in a physical network has a fixed network address that can be used to communicate with the device. This fixed network address can be a Layer 2 address (e.g., a MAC address), a fixed Layer 3 address (e.g., an IP address), and the like. In a virtual environment or virtual network, endpoints can include various virtual endpoints, such as virtual machines hosted by components of the physical network (e.g., hosted by a physical host machine). These endpoints in the virtual network are addressed by overlay addresses, such as overlay Layer 2 addresses (e.g., an overlay MAC address) and overlay Layer 3 addresses (e.g., an overlay IP address). Network overlays enable flexibility by allowing network administrators to move between overlay addresses associated with network endpoints using software management (e.g., by software implementing the virtual network's control plane). Thus, unlike physical networks, in virtual networks, overlay addresses (e.g., overlay IP addresses) can be moved from one endpoint to another using network management software. Because virtual networks are built on top of physical networks, communication between components in a virtual network involves both the virtual network and the underlying physical network.To facilitate such communications, CSPI components are configured to learn and store mappings that map overlay addresses in the virtual network to actual physical addresses in the substrate network, and vice versa. These mappings are then used to facilitate communications. User traffic is encapsulated to facilitate routing within the virtual network.
[0033] Thus, a physical address (e.g., a physical IP address) is associated with a component in a physical network, and an overlay address (e.g., an overlay IP address) is associated with an entity in a virtual or overlay network. A physical IP address is an IP address associated with a physical device (e.g., a network device) in a substrate or physical network. For example, each NVD has an associated physical IP address. An overlay IP address is an overlay address associated with an entity in an overlay network, such as associated with a compute instance in a user's VCN. Two different users or tenants, each with their own private VCN, could potentially use the same overlay IP address in their VCNs without any knowledge of each other. Both physical IP addresses and overlay IP addresses are types of real IP addresses. These IP addresses exist separately from virtual IP addresses. A virtual IP address is typically a single IP address that represents or maps to multiple real IP addresses. A virtual IP address provides a one-to-many mapping between a virtual IP address and multiple real IP addresses. For example, a load balancer may use a VIP to map to or represent multiple servers, each with its own real IP address.
[0034] A cloud infrastructure or CSPI is physically hosted in one or more data centers in one or more regions around the world. The CSPI may include components in a physical or substrate network and virtual components (e.g., virtual networks, compute instances, virtual machines, etc.) in a virtual network built on top of the physical network components. In one embodiment, the CSPI is organized and hosted in realms, regions, and availability domains. A region is a local geographic area that typically contains one or more data centers. Regions are generally independent of each other and may be separated by vast distances, for example, spanning multiple countries or continents. For example, a first region may be in Australia, another region may be in Japan, yet another region may be in India, etc. CSPI resources are divided among regions so that each region contains its own independent subset of CSPI resources. Each region may provide a set of core infrastructure services and resources, such as compute resources (e.g., bare metal servers, virtual machines, containers, and related infrastructure), storage resources (e.g., block volume storage, file storage, object storage, archive storage), network resources (e.g., VCNs), load balancing resources, connectivity to on-premises networks, database resources, edge network resources (e.g., DNS), and access management and monitoring resources. Each region typically has multiple paths connecting it to other regions within the realm.
[0035] Because using nearby resources is faster than using resources that are farther away, applications are typically deployed in the region where they are most frequently used (i.e., deployed to the infrastructure associated with that region). Applications may also be deployed in different regions for a variety of reasons, such as redundancy to mitigate the risk of region-wide events such as large weather systems or earthquakes, to meet changing requirements for legal jurisdictions, tax areas, and other business or societal criteria.
[0036] Data centers within a region may be further organized and subdivided into availability domains (ADs). An availability domain may correspond to one or more data centers located within a region. A region may be composed of one or more availability domains. In such a distributed environment, CSPI resources are specific to a region, such as a VCN, or specific to an availability domain, such as a compute instance.
[0037] ADs within a region are isolated from each other, fault-tolerant, and configured to be highly unlikely to fail simultaneously. This is achieved by ADs that do not share critical infrastructure resources, such as networks, physical cables, cable paths, or cable entry points, so that a failure in one AD within a region is unlikely to affect the availability of other ADs in the same region. ADs within the same region may be connected to each other by low-latency, high-bandwidth networks that provide highly available connectivity to other networks (e.g., the Internet, a user's on-premises network, etc.) and enable the creation of replicated systems in multiple ADs for both high availability and disaster recovery. Cloud services use multiple ADs to ensure high availability and protect against resource failures. As the infrastructure provided by an IaaS provider grows, more regions and ADs with additional capacity may be added. Traffic between availability domains is typically encrypted.
[0038] In one embodiment, regions are grouped into realms. A realm is a logical collection of regions. Realms are isolated from each other and do not share any data. Regions within the same realm may communicate with each other, but regions in different realms cannot. A user's tenancy or account, along with a CSP, exists within a single realm and can be distributed across one or more regions belonging to that realm. Typically, when a user subscribes to an IaaS service, a tenancy or account is created for the user in a region specified by the user within the realm (called the "home" region). The user can extend their tenancy across one or more other regions within the realm. The user cannot access regions that are not within the realm in which the user's tenancy resides.
[0039] An IaaS provider may offer multiple realms, each catering to the needs of a user or a particular set of users. For example, a commercial realm may be offered to commercial users. As another example, a realm may be offered to a particular country for users within that country. As yet another example, a government realm may be offered to a government, etc. For example, the government realm may cater to the needs of a particular government and may have higher security than the commercial realm. For example, Oracle Cloud Infrastructure (OCI) currently offers two realms: one for a commercial region and one for a government cloud region (e.g., FedRAMP-certified and IL5-certified).
[0040] In one embodiment, an AD can be subdivided into one or more failure domains. A failure domain is a group of infrastructure resources within an AD to provide anti-affinity. Fault domains enable the distribution of compute instances so that multiple compute instances do not reside on the same physical hardware within a single AD. This distribution is known as anti-affinity. A failure domain refers to a set of hardware components (computers, switches, etc.) that share a single point of failure. A compute pool is logically divided into failure domains. Therefore, a hardware failure or compute hardware maintenance event that affects one failure domain does not affect instances in other failure domains. Depending on the embodiment, the number of failure domains per AD may vary. For example, in one embodiment, each AD includes three failure domains. Fault domains act as logical data centers within an AD.
[0041] When a user subscribes to an IaaS service, resources from CSPI are provisioned for the user and associated with the user's tenancy. The user can use these provisioned resources to build private networks and deploy resources to these networks. A user's network hosted in the cloud by CSPI is called a VCN. A user can configure one or more virtual cloud networks (VCNs) using the CSPI resources allocated to the user. A VCN is a virtual private network or software-defined private network. The user's resources deployed within the user's VCN can include compute instances (e.g., virtual machines, bare metal instances) and other resources. These compute instances may represent various user workloads, such as applications, load balancers, databases, etc. Compute instances deployed in a VCN can communicate with endpoints publicly accessible over a public network such as the Internet ("public endpoints"), with other instances in the same VCN or other VCNs (e.g., the user's other VCNs or VCNs not belonging to the user), with the user's on-premises data center or network, and with service endpoints and other types of endpoints.
[0042] CSPs may offer various services using CSPI. In some cases, users of CSPI may act as service providers themselves and offer services using CSPI resources. Service providers may expose service endpoints characterized by identifying information (e.g., IP addresses, DNS names, and DNS ports). User resources (e.g., compute instances) can consume a particular service by accessing the service endpoint exposed by the service for that service. These service endpoints are generally publicly accessible by users over a public communications network, such as the Internet, using a public IP address associated with the endpoint. Publicly accessible network endpoints are sometimes referred to as public endpoints.
[0043] In one embodiment, a service provider may expose a service via an endpoint for the service (sometimes referred to as a service endpoint). Users of the service can then access the service using this service endpoint. In some implementations, a service endpoint provided for a service can be accessed by multiple users wishing to consume the service. In other implementations, a dedicated service endpoint may be provided to a user, allowing only that user to access the service using that dedicated service endpoint.
[0044] In one embodiment, when a VCN is created, it is associated with a private overlay Classless Inter-Domain Routing (CIDR) address space, which is a range of private overlay IP addresses (e.g., 10.0 / 16) that is assigned to the VCN. A VCN includes associated subnets, route tables, and gateways. A VCN exists within a single region but can span one, more, or all of the region's availability domains. A gateway is a virtual interface configured for a VCN that enables traffic to and from the VCN to one or more endpoints outside the VCN. One or more different types of gateways may be configured for a VCN to enable communication with different types of endpoints.
[0045] A VCN can be subdivided into one or more subnetworks, such as one or more subnets. A subnet is thus a unit of configuration or subdivision that can be created within a VCN. A VCN can contain one or more subnets. Each subnet in a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24) that represents a subset of address space within the VCN's address space and does not overlap with other subnets in that VCN.
[0046] Each compute instance is associated with a virtual network interface card (VNIC) that allows the compute instance to participate in a subnet of a VCN. A VNIC is a logical representation of a physical network interface card (NIC). In general, a VNIC is an interface between an entity (e.g., a compute instance, a service) and a virtual network. A VNIC resides in a subnet and has one or more associated IP addresses and associated security rules or policies. A VNIC is equivalent to a Layer 2 port on a switch. A VNIC is connected to a compute instance and to a subnet within a VCN. A VNIC associated with a compute instance allows the compute instance to become part of a subnet of a VCN and enables the compute instance to communicate (e.g., send and receive packets) with endpoints on the same subnet as the compute instance, endpoints in a different subnet within the VCN, or endpoints outside the VCN. Thus, the VNIC associated with a compute instance determines how the compute instance connects with endpoints inside and outside the VCN. A VNIC for a compute instance is created and associated with the compute instance when the compute instance is created and added to a subnet in a VCN. For a subnet containing a set of compute instances, the subnet contains VNICs corresponding to the set of compute instances, and each VNIC connects to one compute instance in the set of compute instances.
[0047] Each compute instance is assigned a private overlay IP address via the VNIC associated with the compute instance. This private overlay IP address is assigned to the VNIC associated with the compute instance when the compute instance is created and is used to route traffic to and from the compute instance. All VNICs within a particular subnet use the same route table, security lists, and Dynamic Host Configuration Protocol (DHCP) options. As previously mentioned, each subnet within a VCN is associated with a contiguous range of overlay IP addresses (e.g., 10.0.0.0 / 24 and 10.0.1.0 / 24) that represents a subset of address space within the VCN's address space that does not overlap with other subnets within that VCN. For a VNIC on a particular subnet of a VCN, the private overlay IP address assigned to the VNIC is an address from the contiguous range of overlay IP addresses assigned to that subnet.
[0048] In one embodiment, a compute instance may optionally be assigned an additional overlay IP address in addition to the private overlay IP address, such as one or more public IP addresses if it is in a public subnet. These multiple addresses may be assigned to the same VNIC or across multiple VNICs associated with the compute instance. However, each instance has a primary VNIC that is created during instance launch and associated with the overlay private IP address assigned to the instance, and this primary VNIC cannot be removed. Additional VNICs, called secondary VNICs, may be added to an existing instance in the same availability domain as the primary VNIC. All VNICs are in the same availability domain as the instance. The secondary VNICs can be in a subnet in the same VCN as the primary VNIC or in a different subnet, either in the same VCN or in a different VCN.
[0049] If a compute instance is in a public subnet, the compute instance may optionally be assigned a public IP address. When a subnet is created, it can be specified as either a public subnet or a private subnet. A private subnet means that resources (e.g., compute instances) and associated VNICs in the subnet cannot have public overlay IP addresses. A public subnet means that resources and associated VNICs in the subnet can have public IP addresses. Users can specify a subnet to exist in a single availability domain or across multiple availability domains within a region or realm.
[0050] As mentioned above, a VCN may be subdivided into one or more subnets. In one embodiment, a virtual router (VR) configured for a VCN (referred to as a VCN VR or simply VR) enables communication between subnets of the VCN. For a subnet within a VCN, the VR represents the logical gateway for that subnet, allowing the subnet (i.e., the compute instances on that subnet) to communicate with endpoints on other subnets within the VCN and with other endpoints outside the VCN. A VCN VR is a logical entity configured to route traffic between VNICs within a VCN and a virtual gateway ("gateway") associated with the VCN. Gateways are further described below with respect to FIG. 1. A VCN VR is a Layer 3 / IP layer concept. In one embodiment, there is one VCN VR per VCN, and the VCN VR has a potentially unlimited number of ports addressed by IP addresses, one port for each subnet of the VCN. In this way, the VCN VR has a different IP address for each subnet within the VCN to which the VCN VR is connected. The VRs are also connected to various gateways configured for the VCN. In one embodiment, a specific overlay IP address from a subnet's overlay IP address range is reserved for ports in that subnet's VCN VR. For example, consider a VCN that includes two subnets with associated address ranges 10.0 / 16 and 10.1 / 16, respectively. For the first subnet in the VCN with address range 10.0 / 16, an address from this range is reserved for ports in that subnet's VCN VR. In some cases, the first IP address from this range may be reserved for a VCN VR. For example, for a subnet with overlay IP address range 10.0 / 16, IP address 10.0.0.1 may be reserved for ports in that subnet's VCN VR.For a second subnet in the same VCN with address range 10.1 / 16, the VCN VR may have a port in that second subnet with IP address 10.1.0.1. The VCN VR has a different IP address for each of the subnets in the VCN.
[0051] In some other embodiments, each subnet in a VCN may include a VR associated with it that is addressable by the subnet using a reserved or default IP address associated with the VR. The reserved or default IP address may, for example, be the first IP address from a range of IP addresses associated with the subnet. VNICs in a subnet can use this default or reserved IP address to communicate with (e.g., send and receive packets from) the VR associated with the subnet. In such embodiments, a VR is an ingress / egress point for that subnet. VRs associated with a subnet in a VCN can communicate with other VRs associated with other subnets in the VCN. VRs can also communicate with gateways associated with the VCN. The VR functions for a subnet are running on or performed by one or more NVDs that are performing the VNIC functions for VNICs in the subnet.
[0052] Route tables, security rules, and DHCP options may be configured for a VCN. A route table is a virtual route table for a VCN and contains rules for routing traffic from subnets within the VCN to destinations outside the VCN via gateways or specially configured instances. A VCN's route table can be customized to control how packets are forwarded / routed to and from the VCN. DHCP options refer to configuration information that is automatically provided to instances when they launch.
[0053] Security rules configured for a VCN represent the overlay firewall rules for the VCN. Security rules include ingress and egress rules and can specify the type of traffic (e.g., based on protocol and port) allowed in and out of instances within the VCN. Users can choose whether a particular rule is stateful or stateless. For example, a user can allow incoming SSH traffic from any location to a set of instances by configuring a stateful ingress rule with a source CIDR of 0.0.0.0 / 0 and a destination TCP port of 22. Security rules can be implemented using network security groups or security lists. A network security group consists of a set of security rules that apply only to resources within that group. A security list, on the other hand, contains rules that apply to all resources in any subnet that uses the security list. A VCN may have a default security list that contains default security rules. DHCP options configured for a VCN provide configuration information that is automatically provided to instances within the VCN when the instances launch.
[0054] In one embodiment, configuration information for a VCN is determined and stored by a VCN control plane. The configuration information for a VCN may include, for example, information about address ranges associated with the VCN, subnets and associated information within the VCN, one or more VRs associated with the VCN, compute instances and associated VNICs within the VCN, NVDs (e.g., VNICs, VRs, gateways) performing various virtualized network functions associated with the VCN, VCN state information, and other VCN-related information. In one embodiment, a VCN distribution service publishes the configuration information stored by the VCN control plane or portions thereof to the NVD. The distributed information may be used to update information (e.g., forwarding tables, routing tables, etc.) stored and used by the NVD to forward packets to and from compute instances within the VCN.
[0055] In one embodiment, VCN and subnet creation is handled by a VCN Control Plane (CP), and compute instance launch is handled by the Compute Control Plane. The Compute Control Plane is responsible for allocating physical resources to compute instances and then calls the VCN Control Plane to create and attach VNICs to the compute instances. The VCN CP also sends VCN data mappings to the VCN Data Plane, which is configured to perform packet forwarding and routing functions. In one embodiment, the VCN CP provides a distribution service that is responsible for providing updates to the VCN Data Plane.
[0056] A user may create one or more VCNs using resources hosted by CSPI. Compute instances deployed in a user's VCN may communicate with various endpoints. These endpoints may include endpoints hosted by CSPI and endpoints external to CSPI.
[0057] Various different architectures for implementing cloud-based services using CSPI are shown in FIGS. 1-4C and described below. FIG. 1 is a high-level diagram of a distributed environment 100 illustrating an overlay VCN or a user VCN hosted by CSPI according to one embodiment. The distributed environment shown in FIG. 1 includes multiple components within an overlay network. The distributed environment 100 shown in FIG. 1 is merely an example and is not intended to unduly limit the scope of the claimed embodiments. Many variations, alternatives, and modifications are possible. For example, in some implementations, the distributed environment shown in FIG. 1 may include more or fewer systems or components than those shown in FIG. 1, may combine two or more subsystems, or may include a different configuration or arrangement of systems.
[0058] As shown in the example depicted in FIG. 1 , distributed environment 100 includes CSPI 101, which provides services and resources that users can subscribe to and use to build their own VCNs. In one embodiment, CSPI 101 provides IaaS services to subscribing users. Data centers within CSPI 101 may be organized into one or more regions. One exemplary region, “Region US” 102, is shown in FIG. 1 . A user configures a VCN for a user of Oracle International Corporation with region 102. A user may deploy various compute instances into VCN 104, which may include virtual machines or bare metal instances. Example instances include applications, databases, load balancers, etc.
[0059] In the embodiment shown in FIG. 1 , a user's VCN 104 includes two subnets, "Subnet 1" and "Subnet 2," each with its own CIDR IP address range. In FIG. 1 , Subnet 1's overlay IP address range is 10.0 / 16, and Subnet 2's address range is 10.1 / 16. VCN virtual router 105 represents the VCN's logical gateway, enabling communication between subnets in VCN 104 and with other endpoints outside the VCN. VCN VR 105 is configured to route traffic between VNICs in VCN 104 and the gateway associated with VCN 104. VCN VR 105 provides a port for each subnet in VCN 104. For example, VR 105 may provide a port with IP address 10.0.0.1 for Subnet 1 and a port with IP address 10.1.0.1 for Subnet 2.
[0060] Multiple compute instances may be deployed in each subnet, and the compute instances can be virtual machine instances and / or bare metal instances. The compute instances in a subnet may be hosted by one or more host machines in CSPI101. A compute instance joins a subnet through a VNIC associated with the compute instance. For example, as shown in FIG. 1, compute instance C1 becomes part of subnet 1 through a VNIC associated with C1. Similarly, compute instance C2 becomes part of subnet 1 through a VNIC associated with C2. In a similar manner, multiple compute instances, which may be virtual machine instances or bare metal instances, may become part of subnet 1. Each compute instance is assigned a private overlay IP address and a MAC address through its associated VNIC. For example, in FIG. 1, compute instance C1 has an overlay IP address of 10.0.0.2 and a MAC address of M1, while compute instance C2 has a private overlay IP address of 10.0.0.3 and a MAC address of M2. Each compute instance in Subnet 1, including compute instances C1 and C2, has a default route to VCN VR105 using IP address 10.0.0.1, which is the IP address of a port in VCN VR105 in Subnet 1.
[0061] Subnet2 may have multiple compute instances deployed, including virtual machine instances and / or bare metal instances. For example, as shown in FIG. 1, compute instances D1 and D2 become part of Subnet2 through VNICs associated with the respective compute instances. In the embodiment shown in FIG. 1, compute instance D1 has an overlay IP address of 10.1.0.2 and a MAC address of MM1, while compute instance D2 has a private overlay IP address of 10.1.0.3 and a MAC address of MM2. Each compute instance in Subnet2, including compute instances D1 and D2, has a default route to VCN VR105 using IP address 10.1.0.1, which is the IP address of a port in VCN VR105 in Subnet2.
[0062] VCN A 104 may include one or more load balancers. For example, a load balancer may be provided for a subnet and configured to load balance traffic across multiple compute instances on the subnet. A load balancer may be provided to load balance traffic across multiple subnets within a VCN.
[0063] A particular compute instance deployed in VCN 104 can communicate with various endpoints. These endpoints may include endpoints hosted by CSPI 101 and endpoints outside of CSPI 101. Endpoints hosted by CSPI 101 may include endpoints on the same subnet as the particular compute instance (e.g., communication between two compute instances in Subnet 1), endpoints on a different subnet but within the same VCN (e.g., communication between a compute instance in Subnet 1 and a compute instance in Subnet 2), endpoints in a different VCN within the same region (e.g., communication between a compute instance in Subnet 1 and an endpoint in a VCN in the same region 106 or 110, communication between a compute instance in Subnet 1 and an endpoint in a service network 110 in the same region), or endpoints in a VCN in a different region (e.g., communication between a compute instance in Subnet 1 and an endpoint in a VCN in a different region 108). Compute instances in a subnet hosted by CSPI 101 may communicate with endpoints not hosted by CSPI 101 (i.e., outside of CSPI 101). These external endpoints include endpoints within the user's on-premise network 116, endpoints within other remote cloud-hosted networks 118, public endpoints 114 accessible via public networks such as the Internet, and other endpoints.
[0064] Communication between compute instances on the same subnet is facilitated using VNICs associated with the source and destination compute instances. For example, compute instance C1 in Subnet 1 may want to send a packet to compute instance C2 in Subnet 1. For a packet originating from the source compute instance and destined for another compute instance in the same subnet, the packet is first processed by the VNIC associated with the source compute instance. The processing performed by the VNIC associated with the source compute instance may include determining the packet's destination information from the packet header, identifying any policies (e.g., security lists) configured for the VNIC associated with the source compute instance, determining the packet's next hop, performing any packet encapsulation / decapsulation functions as needed, and then forwarding / routing the packet to the next hop to facilitate communication of the packet with its intended destination. If the destination compute instance is in the same subnet as the source compute instance, the VNIC associated with the source compute instance is configured to identify the VNIC associated with the destination compute instance and forward the packet to that VNIC for processing. The VNIC associated with the destination compute instance then executes and forwards the packet to the destination compute instance.
[0065] For packets traveling from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, this communication is facilitated by the VNICs and VCN VRs associated with the source and destination compute instances. For example, if compute instance C1 in Subnet 1 in Figure 1 wants to send a packet to compute instance D1 in Subnet 2, the packet is first processed by the VNIC associated with compute instance C1. The VNIC associated with compute instance C1 is configured to route the packet to VCN VR105 using the VCN VR's default route or port 10.0.0.1. VCN VR105 is configured to route the packet to Subnet 2 using port 10.1.0.1. The packet is then received and processed by the VNIC associated with D1, which forwards the packet to compute instance D1.
[0066] For packets traveling from a compute instance within VCN 104 to an endpoint outside VCN 104, the communication is facilitated by a VNIC associated with the source compute instance, VCN VR 105, and a gateway associated with VCN 104. One or more types of gateways may be associated with VCN 104. A gateway is an interface between a VCN and another endpoint, where the other endpoint is outside the VCN. A gateway is a Layer 3 / IP layer concept that allows a VCN to communicate with endpoints outside the VCN. Thus, a gateway facilitates traffic flow between a VCN and other VCNs or networks. Different types of gateways may be configured for a VCN to facilitate different types of communication with different types of endpoints. Depending on the gateway, the communication may go over a public network (e.g., the Internet) or a private network. Various communication protocols may be used for these communications.
[0067] For example, compute instance C1 may wish to communicate with an endpoint outside VCN 104. The packet may first be processed by a VNIC associated with the source compute instance C1. This VNIC processing determines that the packet's destination is outside of Subnet 1 of C1. The VNIC associated with C1 may forward the packet to VCN VR105 of VCN 104. VCN VR105 then processes the packet and, as part of this processing, determines a particular gateway associated with VCN 104 as the packet's next hop based on the packet's destination. VCN VR105 may then forward the packet to the particular identified gateway. For example, if the destination is an endpoint within a user's on-premises network, VCN VR105 may forward the packet to a dynamic routing gateway (DRG) gateway 122 configured for VCN 104. The packet may then be forwarded from the gateway to the next hop to facilitate propagation of the packet to its final intended destination.
[0068] Various types of gateways may be configured for a VCN. Examples of gateways that may be configured for a VCN are shown in FIG. 1 and described below. As shown in the embodiment shown in FIG. 1, a dynamic routing gateway (DRG) 122 may be added to or associated with a user's VCN 104 to provide a path for private network traffic communication between the user's VCN 104 and another endpoint, which may be the user's on-premises network 116, a VCN 108 in a different region of CSPI 101, or another remote cloud network 118 not hosted by CSPI 101. The user's on-premises network 116 may be the user's network or the user's data center built using the user's resources. Access to the user's on-premises network 116 is typically highly restricted. In the case of a user who has both the user's on-premises network 116 and one or more VCNs 104 deployed or hosted in the cloud by CSPI 101, the user may want the user's on-premises network 116 and the user's cloud-based VCN 104 to be able to communicate with each other. This allows users to build an extended hybrid environment that encompasses the user's VCN 104 hosted by CSPI 101 and the user's on-premises network 116. DRG 122 enables this communication. To enable such communication, a communication channel 124 is set up, with one endpoint of the channel in the user's on-premises network 116 and the other endpoint in CSPI 101 connected to the user's VCN 104. The communication channel 124 can traverse a public communication network such as the Internet or a private communication network. Various communication protocols may be used, such as IPsec VPN technology over a public communication network such as the Internet, or Oracle's FastConnect technology, which uses a private network instead of a public network.A device or equipment in a user's on-premise network 116 that forms one endpoint of a communication channel 124 is called user premise equipment (CPE), such as CPE 126 shown in Figure 1. On the CSPI 101 side, the endpoint may be a host machine running DRG 122.
[0069] In one embodiment, a Remote Peering Connection (RPC) can be added to a DRG, allowing a user to peer one VCN with another VCN in a different region. Using such an RPC, a user's VCN 104 can connect with a VCN 108 in another region using the DRG 122. The DRG 122 may also be used to communicate with other remote cloud networks 118 not hosted by the CSPI 101, such as the Microsoft Azure cloud, the Amazon AWS cloud, etc.
[0070] 1, an Internet Gateway (IGW) 120 may be configured for a user's VCN 104, which enables compute instances on VCN 104 to communicate with public endpoints 114 accessible via a public network, such as the Internet. IGW 120 is a gateway that connects a VCN to a public network, such as the Internet. IGW 120 enables direct access for public subnets within a VCN, such as VCN 104 (resources within the public subnet have public overlay IP addresses), to public endpoints 112 on the public network 114, such as the Internet. Using IGW 120, connections can be initiated from subnets within VCN 104 or from the Internet.
[0071] A Network Address Translation (NAT) gateway 128 is configured for a user's VCN 104 to enable access to the Internet for cloud resources in the user's VCN that do not have dedicated public overlay IP addresses, without exposing those resources to direct incoming Internet connections (e.g., L4-L7 connections). This allows private subnets in a VCN, such as Private Subnet 1 in VCN 104, to private endpoints on the Internet. The NAT gateway only allows connections to be initiated from the private subnet to the public Internet; connections cannot be initiated from the Internet to the private subnet.
[0072] In one embodiment, a service gateway (SGW) 126 may be configured for a user's VCN 104 and provides a pathway for private network traffic between VCN 104 and supported service endpoints in service network 110. In one embodiment, service network 110 may be provided by a CSP and may offer a variety of services. An example of such a service network is Oracle's Services Network, which offers a variety of services that may be used by users. For example, a compute instance (e.g., a database system) in a private subnet of a user's VCN 104 can back up data to a service endpoint (e.g., object storage) without requiring a public IP address or access to the Internet. In one embodiment, a VCN may include only one SGW, and connections can be initiated only from subnets within the VCN, not from service network 110. When a VCN is peered with another VCN, resources in the other VCN typically do not have access to the SGW. Resources in an on-premises network connected to a VCN using a FastConnect or VPN connection can also use a service gateway configured for that VCN.
[0073] In one implementation, SGW 126 uses the concept of a service classless inter-domain routing (CIDR) label, which is a string that represents the public IP address range of all regions for a service or group of services of interest. Users use the service CIDR label when configuring the SGW and associated route rules to control traffic to the service. Users can optionally utilize the service CIDR label when configuring security rules, avoiding the need to adjust those security rules if the service's public IP address changes in the future.
[0074] A Local Peering Gateway (LPG) 132 is a gateway that can be added to a user's VCN 104, allowing the VCN 104 to peer with another VCN in the same region. Peering means that the VCNs communicate using private IP addresses without the traffic traversing a public network such as the Internet or routing the traffic through the user's on-premises network 116. In a preferred embodiment, a VCN includes a separate LPG for each peering it establishes. Local peering or VCN peering is a common method used to establish network connectivity between different applications or infrastructure management functions.
[0075] A service provider, such as a provider of a service in service network 110, may provide access to the service using various access models. According to a public access model, the service may be exposed as a public endpoint, which may be publicly accessible by a compute instance in the user's VCN over a public network such as the Internet, and / or privately accessible through SGW 126. According to a specific private access model, the service is made accessible as a private IP endpoint in a private subnet in the user's VCN. This access is called Private Endpoint (PE) access and allows service providers to expose services as instances in the user's private network. A private endpoint resource represents a service in the user's VCN. Each PE appears as a VNIC (referred to as a PE-VNIC with one or more private IPs) in a user-selected subnet in the user's VCN. Thus, the PE provides a way to present services in a subnet of the private user's VCN using VNICs. Because the endpoints are exposed as VNICs, all features associated with the VNIC, such as routing rules, security lists, etc., are available to the PE VNIC.
[0076] A service provider can register a service to make it accessible through the PE. The provider can associate a policy with the service that limits the visibility of the service to the customer's tenancy. The provider can register multiple services under a single virtual IP address (VIP), especially for multi-tenant services. There can be multiple such private endpoints (in multiple VCNs) representing the same service.
[0077] Compute instances in the private subnet can then access the service using the private IP address of the PE VNIC or the DNS name of the service. Compute instances in a user's VCN can access the service by sending traffic to the private IP address of the PE in the user's VCN. A Private Access Gateway (PAGW) 130 is a gateway resource that can be connected to a service provider's VCN (e.g., a VCN in service network 110) and serves as the ingress / egress point for all traffic to and from the private endpoints of the user's subnet. The PAGW 130 allows providers to scale the number of PE connections without utilizing internal IP address resources. A provider needs to configure only one PAGW for any number of services registered within a single VCN. A provider can represent services as private endpoints in multiple VCNs for one or more users. From the user's perspective, the PE VNIC appears to be connected to the service with which the user wants to interact, instead of to the user's instance. Traffic going to the private endpoint is routed to the service through the PAGW 130. These are called user-to-service private connections (C2S (user-to-service) connections).
[0078] The PE concept can also be used to extend private access of services to a user's on-premises network and data center by allowing traffic to flow through a FastConnect / IPsec link and a private endpoint in the user's VCN. Private access of services can also be extended to a user's peered VCN by allowing traffic to flow between LPG 132 and a PE in the user's VCN.
[0079] A user can control routing within a VCN at the subnet level, allowing the user to specify which subnets within the user's VCN, such as VCN 104, use each gateway. A VCN's route table is used to determine whether traffic is allowed to exit the VCN through a particular gateway. For example, in a particular example, the route table for a public subnet in a user's VCN 104 may send non-local traffic through IGW 120. The route table for a private subnet in the same user's VCN 104 may send traffic going to a CSP service through SGW 126. All remaining traffic may be sent through NAT gateway 128. The route table controls only traffic that exits the VCN.
[0080] Security lists associated with a VCN are used to control traffic entering the VCN through the gateway via inbound connections. All resources within a subnet use the same route table and security lists. Security lists may be used to control the specific types of traffic allowed into and out of instances within a VCN's subnet. Security list rules may include ingress (inbound) rules and egress (outbound) rules. For example, ingress rules may specify allowed source address ranges, while egress rules may specify allowed destination address ranges. Security rules may specify a specific protocol (e.g., TCP, ICMP), a specific port (e.g., 22 for SSH, 3389 for Windows RDP), etc. In some implementations, the instance's operating system may enforce its own firewall rules that match the security list rules. Rules may be stateful (e.g., connections are tracked and responses are automatically allowed without explicit security list rules for the response traffic) or stateless.
[0081] Access from a user's VCN (i.e., by resources or compute instances deployed in VCN 104) can be categorized as public access, private access, or dedicated access. Public access refers to an access model in which public IP addresses or NATs are used to access public endpoints. Private access allows a user's workloads (e.g., resources in a private subnet) in VCN 104 with private IP addresses to access services without traversing a public network such as the Internet. In one embodiment, CSPI 101 enables workloads in a user's VCN with private IP addresses to access (public service endpoints of) services using a service gateway. Thus, the service gateway provides a private access model by establishing a virtual link between the user's VCN and the public endpoints of services that reside outside the user's private network.
[0082] Additionally, CSPI may provide dedicated public access using technologies such as FastConnect public peering, where a user's on-premises instances can use a FastConnect connection to access one or more services in the user's VCN without traversing a public network such as the Internet. CSPI may also provide dedicated private access using FastConnect private peering, where a user's on-premises instances with private IP addresses can use a FastConnect connection to access workloads in the user's VCN. FastConnect is a network connection alternative to using the public Internet for connecting a user's on-premises network to CSPI and its services. FastConnect provides an easy, resilient, and economical way to create dedicated private connections with higher bandwidth options and a more reliable and consistent network experience when compared to Internet-based connections.
[0083] FIG. 1 and the accompanying discussion above describe various virtual components within an exemplary virtual network. As previously mentioned, a virtual network is built on top of an underlying physical network or substrate network. FIG. 2 illustrates a simplified architectural diagram of physical components in a physical network within CSPI 200 that serves as the foundation for a virtual network, according to one embodiment. As illustrated, CSPI 200 provides a distributed environment that includes components and resources (e.g., compute, memory, and network resources) provided by a CSP. These components and resources are used to provide cloud services (e.g., IaaS services) to subscribing users, i.e., users who subscribe to one or more services offered by a CSP. Based on the services to which the user subscribes, a subset of CSPI 200's resources (e.g., compute, memory, and network resources) is provisioned for the user. The user can then build their own cloud-based (i.e., CSPI-hosted), customizable private virtual network using the physical compute, memory, and network resources provided by CSPI 200. As previously indicated, these user networks are referred to as VCNs. Users can deploy one or more of their resources, such as compute instances, into their VCNs. The compute instances can be in the form of virtual machines, bare metal instances, etc. CSPI200 provides infrastructure and a set of complementary cloud services that enable users to build and run a wide range of applications and services within a highly available hosted environment.
[0084] In the example embodiment shown in FIG. 2, the physical components of CSPI 200 include one or more physical host machines or servers (e.g., 202, 206, 208), network virtualization devices (NVDs) (e.g., 210, 212), top-of-rack (TOR) switches (e.g., 214, 216), and a physical network (e.g., 218), as well as switches within physical network 218. The physical host machines or servers may host and execute various compute instances that participate in one or more subnets of the VCN. The compute instances may include virtual machine instances and bare metal instances. For example, the various compute instances shown in FIG. 1 may be hosted by the physical host machines shown in FIG. 2. The virtual machine compute instances in the VCN may be executed by one host machine or by multiple different host machines. The physical host machines may host virtual host machines, container-based hosts or functions, etc. The VNICs and VCN VRs shown in FIG. 1 may be executed by the NVDs shown in FIG. 2. The gateway shown in FIG. 1 may be executed by a host machine and / or by the NVD shown in FIG.
[0085] A host machine or server may run a hypervisor (also called a virtual machine monitor or VMM) that creates and enables a virtual environment on the host machine. The virtualized environment facilitates cloud-based computing. One or more compute instances may be created, run, and managed on the host machine by the hypervisor on the host machine. The hypervisor on the host machine enables the host machine's physical computing resources (e.g., compute, memory, and network resources) to be shared among the various compute instances executed by the host machine.
[0086] For example, as shown in FIG. 2, host machines 202 and 208 execute hypervisors 260 and 266, respectively. These hypervisors may be implemented using software, firmware, or hardware, or a combination thereof. Typically, a hypervisor is a process or software layer that resides on a host machine's operating system (OS), which executes on the host machine's hardware processor. A hypervisor provides a virtual environment by allowing the host machine's physical computing resources (e.g., processing resources such as processors / cores, memory resources, and network resources) to be shared among various virtual machine computing instances executed by the host machine. For example, in FIG. 2, hypervisor 260 may reside on top of host machine 202's OS and allow host machine 202's computing resources (e.g., processing resources, memory resources, and network resources) to be shared among computing instances (e.g., virtual machines) executed by host machine 202. A virtual machine can have its own operating system (referred to as a guest operating system), which may be the same as or different from the host machine's OS. The operating system of a virtual machine executed by a host machine may be the same as or different from the operating system of another virtual machine executed by the same host machine. Thus, a hypervisor allows multiple operating systems to run side by side with each other while sharing the same computing resources of the host machine. The host machines shown in Figure 2 may have the same or different types of hypervisors.
[0087] A compute instance can be a virtual machine instance or a bare metal instance. In Figure 2, compute instance 268 on host machine 202 and compute instance 274 on host machine 208 are examples of virtual machine instances. Host machine 206 is an example of bare metal instance 272 that is provided to a user.
[0088] In some examples, an entire host machine may be provisioned to a single user, and one or more compute instances (either virtual machines or bare metal instances) hosted by that host machine all belong to that same user. In other examples, a host machine may be shared among multiple users (i.e., multiple tenants). In such a multi-tenancy situation, the host machine may host virtual machine compute instances belonging to different users. These compute instances may be members of different VCNs of different users. In some embodiments, bare metal compute instances are hosted by bare metal servers that do not have a hypervisor. When a bare metal compute instance is provisioned, a single user or tenant maintains control of the physical CPU, memory, and network interfaces of the host machine hosting the bare metal instance, and the host machine is not shared with other users or tenants.
[0089] As previously mentioned, each compute instance that is part of a VCN is associated with a VNIC that enables the compute instance to be a member of a subnet of the VCN. The VNIC associated with a compute instance facilitates communication of packets or frames to and from the compute instance. The VNIC is associated with the compute instance when the compute instance is created. In one embodiment, for a compute instance executed by a host machine, the VNIC associated with the compute instance is executed by an NVD connected to the host machine. For example, in FIG. 2, host machine 202 executes virtual machine compute instance 268 that is associated with VNIC 276, which is executed by NVD 210 connected to host machine 202. As another example, bare metal instance 272 hosted by host machine 206 is associated with VNIC 280, which is executed by NVD 212 connected to host machine 206. As yet another example, VNIC 284 is associated with compute instance 274 executed by host machine 208, which is executed by NVD 212 connected to host machine 208.
[0090] For compute instances hosted by a host machine, the NVD connected to that host machine also executes VCN VRs corresponding to the VCNs of which those compute instances are members. For example, in the embodiment shown in Figure 2, NVD 210 executes VCN VR 277 corresponding to the VCN of which compute instance 268 is a member. NVD 212 may execute one or more VCN VRs 283 corresponding to the VCNs corresponding to the compute instances hosted by host machines 206 and 208.
[0091] A host machine may include one or more network interface cards (NICs) that allow the host machine to be connected to other devices. The NICs on the host machine may provide one or more ports (or interfaces) that allow the host machine to be communicatively connected to another device. For example, a host machine may be connected to an NVD using one or more ports (or interfaces) provided on the host machine and the NVD. A host machine may also be connected to other devices, such as another host machine.
[0092] 2, host machine 202 is connected to NVD 210 using link 220 extending between port 234 provided by NIC 232 of host machine 202 and port 236 of NVD 210. Host machine 206 is connected to NVD 212 using link 224 extending between port 246 provided by NIC 244 of host machine 206 and port 248 of NVD 212. Host machine 208 is connected to NVD 212 using link 226 extending between port 252 provided by NIC 250 of host machine 208 and port 254 of NVD 212.
[0093] The NVDs are then connected via communication links to top-of-rack (TOR) switches (also called switch fabrics) that are connected to a physical network 218. In one embodiment, the links between the host machines and the NVDs and between the NVDs and the TOR switches are Ethernet links. For example, in Figure 2, links 228 and 230 are used to connect NVDs 210 and 212 to TOR switches 214 and 216, respectively. In one embodiment, links 220, 224, 226, 228, and 230 are Ethernet links. The collection of host machines and NVDs connected to a TOR may be referred to as a rack.
[0094] The physical network 218 provides a communications fabric that allows the TOR switches to communicate with each other. The physical network 218 can be a multi-tier network. In one implementation, the physical network 218 is a multi-tier Clos network of switches, with the TOR switches 214 and 216 representing leaf-level nodes of the multi-tier, multi-node physical switching network 218. Various Clos network configurations are possible, including, but not limited to, 2-tier networks, 3-tier networks, 4-tier networks, 5-tier networks, and generally, "n"-tier networks. An example Clos network is shown in FIG. 5 and described below.
[0095] Various connection configurations are possible between host machines and NVDs, such as one-to-one, many-to-one, and one-to-many configurations. In a one-to-one implementation, each host machine is connected to its own separate NVD. For example, in FIG. 2, host machine 202 is connected to NVD 210 via NIC 232 on host machine 202. In a many-to-one configuration, multiple host machines are connected to a single NVD. For example, in FIG. 2, host machines 206 and 208 are connected to the same NVD 212 via NICs 244 and 250, respectively.
[0096] In a one-to-many configuration, one host machine is connected to multiple NVDs. FIG. 3 illustrates an example of a CSPI 300 in which a host machine is connected to multiple NVDs. As illustrated in FIG. 3, a host machine 302 includes a network interface card (NIC) 304 including multiple ports 306 and 308. The host machine 300 is connected to a first NVD 310 via port 306 and link 320, and to a second NVD 312 via port 308 and link 322. Ports 306 and 308 may be Ethernet ports, and links 320 and 322 between the host machine 302 and the NVDs 310 and 312 may be Ethernet links. The NVD 310 is then connected to a first TOR switch 314, and the NVD 312 is connected to a second TOR switch 316. The links between the NVDs 310 and 312 and the TOR switches 314 and 316 may be Ethernet links. TOR switches 314 and 316 represent layer 0 switching devices within a multi-tier physical network 318 .
[0097] 3 provides two separate physical network paths between the physical switch network 318 and the host machine 302: a first path traversing the TOR switch 314, through the NVD 310, and to the host machine 302, and a second path traversing the TOR switch 316, through the NVD 312, and to the host machine 302. The separate paths result in improved availability (referred to as high availability) of the host machine 302. If there is a problem with one of the paths (e.g., a link in one of the paths fails) or devices (e.g., a particular NVD is not functioning), the other path may be used for communication to and from the host machine 302.
[0098] In the configuration shown in Figure 3, the host machine is connected to two different NVDs using two different ports provided by the host machine's NIC. In other embodiments, the host machine may include multiple NICs that allow the host machine to be connected to multiple NVDs.
[0099] Referring again to Figure 2, an NVD is a physical device or component that performs one or more network and / or storage virtualization functions. An NVD may be any device that has one or more processing units (e.g., a CPU, Network Processing Units (NPUs), FPGAs, packet processing pipelines, etc.), memory including cache, and ports. Various virtualization functions may be performed by software / firmware executed by the one or more processing units of the NVD.
[0100] The NVD may be implemented in various forms. For example, in one embodiment, the NVD is implemented as an interface card called a smart NIC or intelligent NIC that contains an embedded processor. A smart NIC is a separate device from the NIC on the host machine. In Figure 2, NVDs 210 and 212 may be implemented as smart NICs connected to host machine 202 and host machines 206 and 208, respectively.
[0101] However, a smart NIC is just one example of an implementation of an NVD. Various other implementations are possible. For example, in some other implementations, the NVD or one or more functions performed by the NVD may be incorporated into or performed by one or more host machines, one or more TOR switches, and other components of CSPI200. For example, the NVD may be embodied in a host machine, and the functions performed by the NVD may be performed by the host machine. As another example, the NVD may be part of a TOR switch, or a TOR switch may be configured to perform the functions performed by the NVD, allowing the TOR switch to perform various complex packet transformations used in public clouds. A TOR that performs the functions of an NVD may be referred to as a smart TOR. In yet other implementations where users are provided with virtual machine (VM) instances rather than bare metal (BM) instances, the functions performed by the NVD may be implemented inside the hypervisor of a host machine. In some other implementations, some of the NVD's functions may be offloaded to a centralized service running on a set of host machines.
[0102] In one embodiment, such as when implemented as a smart NIC as shown in FIG. 2, the NVD may include multiple physical ports that allow the NVD to be connected to one or more host machines and one or more TOR switches. Ports on the NVD may be classified as host-facing ports (also referred to as "south ports") or network-facing or TOR-facing ports (also referred to as "north ports"). Host-facing ports of an NVD are ports used to connect the NVD to host machines. Examples of host-facing ports in FIG. 2 include port 236 on NVD 210 and ports 248 and 254 on NVD 212. Network-facing ports of an NVD are ports used to connect the NVD to TOR switches. Examples of network-facing ports in FIG. 2 include port 256 on NVD 210 and port 258 on NVD 212. As shown in FIG. 2, the NVD 210 is connected to the TOR switch 214 using link 228 extending from port 256 of the NVD 210 to the TOR switch 214. Similarly, the NVD 212 is connected to the TOR switch 216 using a link 230 that extends from a port 258 of the NVD 212 to the TOR switch 216 .
[0103] The NVD may receive packets and frames from the host machine (e.g., packets and frames generated by compute instances hosted by the host machine) via a host-facing port, and after performing any necessary packet processing, may forward those packets and frames to the TOR switch via the NVD's network-facing port. The NVD may receive packets and frames from the TOR switch via the NVD's network-facing port, and after performing any necessary packet processing, may forward those packets and frames to the host machine via the NVD's host-facing port.
[0104] In one embodiment, there may be multiple ports and associated links between the NVD and the TOR switch. These ports and links may be aggregated to form a link aggregator group (called a LAG) of multiple ports or links. Link aggregation allows multiple physical links between two endpoints (e.g., between the NVD and the TOR switch) to be treated as a single logical link. All physical links within a particular LAG may operate in full-duplex mode at the same speed. LAGs help increase bandwidth and improve the reliability of the connection between two endpoints. If one of the physical links in the LAG fails, traffic is dynamically and transparently reassigned to one of the other physical links in the LAG. The aggregated physical link provides higher bandwidth than an individual link. Multiple ports associated with a LAG are treated as a single logical port. Traffic can be load-balanced across the multiple physical links in a LAG. One or more LAGs may be configured between two endpoints. Two endpoints may exist between the NVD and the TOR switch, between a host machine and the NVD, etc.
[0105] The NVD implements or performs network virtualization functions. These functions are performed by software / firmware executed by the NVD. Examples of network virtualization functions include, but are not limited to, packet encapsulation and decapsulation functions, functions for creating VCN networks, functions for enforcing network policies such as VCN security list (firewall) functions, and functions for facilitating routing and forwarding of packets to and from compute instances in the VCN. In one embodiment, upon receiving a packet, the NVD is configured to execute a packet processing pipeline to process the packet and determine how the packet should be forwarded or routed. As part of this packet processing pipeline, the NVD may perform one or more virtual functions associated with the overlay network, such as running VNICs associated with compute instances in the VCN, running virtual routers (VRs) associated with the VCN, encapsulating and decapsulating packets to facilitate forwarding or routing within the virtual network, running certain gateways (e.g., local peering gateways), enforcing security lists, network security groups, network address translation (NAT) functions (e.g., per-host public IP to private IP translation), bandwidth throttling functions, and other functions.
[0106] In one embodiment, the packet processing data path within the NVD may comprise multiple packet pipelines, each consisting of a series of packet transformation stages. In one implementation, upon receipt of a packet, the packet is parsed and sorted into a single pipeline. The packet is then processed in a linear fashion, one stage at a time, until the packet is either dropped or transmitted through an interface of the NVD. These stages provide basic functional packet processing building blocks (e.g., header validation, performing bandwidth throttling, inserting a new Layer 2 header, performing L4 firewalling, VCN encapsulation / decapsulation, etc.), such that new pipelines can be constructed by assembling existing stages, and new functionality can be added by creating and inserting new stages into existing pipelines.
[0107] The NVD may perform both control plane and data plane functions corresponding to the VCN's control plane and data plane. Control plane functions include functions used to configure the network (e.g., setting up routes and route tables, configuring VNICs, etc.) that control how data is forwarded. In one embodiment, a VCN control plane is provided that centrally computes mappings between all overlays and the substrate and publishes these mappings to the NVD and to virtual network edge devices such as various gateways, such as DRGs, SGWs, and IGWs. Firewall rules may also be published using the same mechanism. In one embodiment, the NVD retrieves only mappings relevant to that NVD. Data plane functions include functions for the actual routing / forwarding of packets based on configuration settings using the control plane. The VCN data plane is implemented by encapsulating user network packets before they traverse the substrate network. The encapsulation / decapsulation functions are implemented in the NVD. In one embodiment, the NVD is configured to intercept all network packets entering and leaving the host machine and perform network virtualization functions.
[0108] As indicated above, the NVD performs various virtualization functions, including VNICs and VCN VRs. The NVD may execute VNICs associated with compute instances hosted by one or more host machines connected to the VNICs. For example, as shown in FIG. 2, NVD 210 executes the functions of VNIC 276 associated with compute instance 268 hosted by host machine 202 connected to NVD 210. As another example, NVD 212 executes VNIC 280 associated with bare metal compute instance 272 hosted by host machine 206 and VNIC 284 associated with compute instance 274 hosted by host machine 208. The host machines may host compute instances that belong to different VCNs that belong to different users, and the NVDs connected to the host machines may execute VNICs (i.e., perform functions related to the VNICs) corresponding to the compute instances.
[0109] NVDs also execute VCN virtual routers corresponding to the VCNs of the compute instances. For example, in the embodiment shown in FIG. 2, NVD 210 executes VCN VR 277 corresponding to the VCN to which compute instance 268 belongs. NVD 212 executes one or more VCN VRs 283 corresponding to one or more VCNs to which compute instances hosted by host machines 206 and 208 belong. In one embodiment, a VCN VR corresponding to that VCN is executed by all NVDs connected to a host machine that hosts at least one compute instance belonging to that VCN. If a host machine hosts compute instances that belong to different VCNs, the NVDs connected to that host machine may execute VCN VRs corresponding to those different VCNs.
[0110] In addition to VNICs and VCN VRs, the NVD may run various software (e.g., daemons) and may include one or more hardware components that facilitate the various network virtualization functions performed by the NVD. For simplicity, these various components are grouped together as a “packet processing component” shown in FIG. 2 . For example, NVD 210 includes packet processing component 286, and NVD 212 includes packet processing component 288. For example, the packet processing component of the NVD may include a packet processor configured to interact with the NVD's ports and hardware interfaces, monitor all packets received by and transmitted using the NVD, and store network information. The network information may include, for example, network flow information and per-flow information (e.g., per-flow statistics) that identify the various network flows processed by the NVD. In one embodiment, the network flow information may be stored per VNIC. In addition to performing per-packet operations, the packet processor may implement a stateful NAT and an L4 firewall (FW). As another example, the packet processing component may include a replication agent configured to replicate information stored by the NVD to one or more different replication target stores. As yet another example, the packet processing component may include a logging agent configured to perform the logging functions of the NVD. The packet processing component may also include software for monitoring the performance and health of the NVD, and possibly software for monitoring the status and health of other components connected to the NVD.
[0111] FIG. 1 illustrates components of an exemplary virtual network or overlay network, including a VCN, subnets within the VCN, compute instances deployed to the subnets, VNICs associated with the compute instances, VRs for the VCN, and a set of gateways configured for the VCN. The overlay components illustrated in FIG. 1 may be executed or hosted by one or more of the physical components illustrated in FIG. 2. For example, compute instances within a VCN may be executed or hosted by one or more host machines illustrated in FIG. 2. For compute instances hosted by a host machine, the VNICs associated with the compute instances are typically executed by an NVD connected to the host machine (i.e., the VNIC functionality is provided by the NVD connected to the host machine). The VCN VR functionality for the VCN is performed by all NVDs connected to host machines hosting or running compute instances that are part of the VCN. The gateways associated with a VCN may be executed by one or more different types of NVDs. For example, some gateways may be executed by smart NICs, while other gateways may be executed by one or more host machines or other implementations of NVDs.
[0112] As previously mentioned, compute instances within a user's VCN may communicate with various endpoints, which can be in the same subnet as the source compute instance, or in a different subnet within the same VCN as the source compute instance, or the endpoints are outside the VCN of the source compute instance. These communications are facilitated using VNICs associated with the compute instances, VCN VRs, and gateways associated with the VCN.
[0113] For communication between two compute instances on the same subnet within a VCN, the communication is facilitated using VNICs associated with the source and destination compute instances. The source and destination compute instances may be hosted by the same host machine or by different host machines. A packet originating from the source compute instance may be forwarded from the host machine hosting the source compute instance to an NVD connected to that host machine. In the NVD, the packet is processed using a packet processing pipeline, which may include execution of the VNIC associated with the source compute instance. Because the packet's destination endpoint is within the same subnet, execution of the VNIC associated with the source compute instance causes the packet to be forwarded to an NVD running the VNIC associated with the destination compute instance, which then processes the packet and forwards it to the destination compute instance. The VNICs associated with the source and destination compute instances may run on the same NVD (e.g., when the source and destination compute instances are both hosted by the same host machine) or on different NVDs (e.g., when the source and destination compute instances are hosted by different host machines connected to different NVDs). The VNICs may use routing / forwarding tables stored by the NVDs to determine the next hop of a packet.
[0114] For packets traveling from a compute instance in a subnet to an endpoint in a different subnet within the same VCN, the packet originating from the source compute instance travels from the host machine hosting the source compute instance to the NVD connected to that host machine. In the NVD, the packet is processed using a packet processing pipeline, which may include running one or more VNICs and VRs associated with the VCN. For example, as part of the packet processing pipeline, the NVD executes or invokes a function corresponding to the VNIC associated with the source compute instance (also referred to as executing the VNIC). The function executed by the VNIC may include examining the VLAN tag on the packet. Because the packet's destination is outside the subnet, a VCN VR function is then invoked and executed by the NVD. The VCN VR then routes the packet to the NVD running the VNIC associated with the destination compute instance. The VNIC associated with the destination compute instance then processes the packet and forwards the packet to the destination compute instance. The VNICs associated with the source compute instance and the destination compute instance may run on the same NVD (e.g., when the source compute instance and the destination compute instance are both hosted by the same host machine) or on different NVDs (e.g., when the source compute instance and the destination compute instance are hosted by different host machines connected to different NVDs).
[0115] If the packet's destination is outside the VCN of the source compute instance, the packet originating from the source compute instance is propagated from the host machine hosting the source compute instance to the NVD connected to that host machine. The NVD runs the VNIC associated with the source compute instance. Because the packet's destination endpoint is outside the VCN, the packet is then processed by the VCN VR for that VCN. The NVD may invoke a VCN VR function to cause the packet to be forwarded to an NVD running the appropriate gateway associated with the VCN. For example, if the destination is an endpoint in a user's on-premises network, the packet may be forwarded by the VCN VR to an NVD running a DRG gateway configured for the VCN. The VCN VR may run on the same NVD as the NVD running the VNIC associated with the source compute instance or by a different NVD. The gateway may be run by the NVD, which can be a smart NIC, a host machine, or another NVD implementation. The packet is then processed by the gateway and forwarded to the next hop, which facilitates the packet's propagation to the intended destination endpoint. 2, a packet originating from compute instance 268 may be communicated from host machine 202 (using NIC 232) over link 220 to NVD 210. At NVD 210, VNIC 276 is invoked because it is the VNIC associated with source compute instance 268. VNIC 276 is configured to examine information encapsulated within the packet, determine a next hop for forwarding the packet in order to facilitate communication of the packet to its intended destination endpoint, and then forward the packet to the determined next hop.
[0116] Compute instances deployed in a VCN can communicate with various endpoints. These endpoints may include endpoints hosted by CSPI200 and endpoints outside of CSPI200. Endpoints hosted by CSPI200 may include instances in the same VCN or other VCNs, which may be the user's VCN or VCNs not belonging to the user. Communication between endpoints hosted by CSPI200 may occur via physical network 218. Compute instances may communicate with endpoints not hosted by CSPI200 or external to CSPI200. Examples of these endpoints include endpoints in the user's on-premises network or data center, or public endpoints accessible via a public network such as the Internet. Communication with endpoints external to CSPI200 may occur via a public network (e.g., the Internet) (not shown in FIG. 2) or a private network (not shown in FIG. 2) using various communication protocols.
[0117] The architecture of CSPI 200 shown in FIG. 2 is merely exemplary and is not intended to be limiting. Variations, substitutions, and modifications are possible in alternative embodiments. For example, in some implementations, CSPI 200 may include more or fewer systems or components than those shown in FIG. 2, may combine two or more systems, or may include a different configuration or arrangement of systems. The systems, subsystems, and other components shown in FIG. 2 may be implemented in software (e.g., code, instructions, programs) executed by one or more processing units (e.g., processors, cores) of the respective systems, using hardware, or a combination thereof. The software may be stored in a non-transitory storage medium (e.g., a memory device).
[0118] Cloud Bridge and Cloud Migration Services Architecture CSPI (e.g., CSPI 101 and 200 described with respect to FIGS. 1 and 2) can be configured to provide cloud integration services. At least a portion of the cloud integration services is provided using a cloud bridge service (e.g., Oracle Cloud Bridge (OCB)) for management and configuration of remote resources that interact with other cloud services provided by the CSPI. Cloud Bridge addresses key aspects of this integration, including automatic discovery and identity of remote resources, representation of remote resources as assets within the user's tenancy, secure network connectivity between remote resources and the CSPI, lifecycle management of agent technology running in the remote environment, and assistance with migration of existing user workloads from external environments to the CSPI. Cloud Bridge enables users to give remote resources (e.g., databases, compute nodes, etc.) a virtual presence within the CSPI for seamless interaction with other cloud services provided by the CSPI. To enable the virtual presence, Cloud Bridge provides the remote resources with a unique cloud identifier (e.g., CloudID, resource principal, etc.) and a remote network connection for interacting with the service. This allows Cloud Bridge to reside in a single location, enabling users to coordinate and manage CSPI agent functionality on remote resources. For users, Cloud Bridge provides a unified, cloud-centric experience across both cloud-native and remote resources while minimizing configuration within the remote environment. For CSPI service teams, Cloud Bridge simplifies environment integration by enabling services to interact with remote resources as if they were cloud resources, and by providing a standardized framework for deploying and managing remote agent capabilities. This allows CSPI service teams to focus on their core cloud experience without worrying about remote connectivity or software lifecycle management.
[0119] Cloud Bridge is managed and configured through a console (e.g., the CSPI console described with respect to Figures 1 and 2), application programming interfaces (APIs), and a software development kit (SDK). Cloud Bridge management and configuration focuses on three fundamental resource types: environments, agents, and assets. Users create an environment for each location where they want access to other cloud services provided by CSPI. The environment acts as a container for assets and defines the scope for managing default policies at that location.
[0120] Agents are part of virtual machines that users create from images provided by Cloud Bridge. Agents act as extensions of the Cloud Bridge service in remote environments and are monitored, updated, and operated by CSPI based on the associated environment's configuration. Agents provide basic Cloud Bridge services, such as remote asset discovery and inventory integration, and include a framework for running service-specific plugins within the environment. For example, the Oracle Cloud Migration service deploys a replication plugin that creates a virtual machine snapshot and uploads it to OCI for migration to OCI compute. Cloud Bridge allows users to select from a catalog of agent-based services and automatically deploys the associated functionality to their environment. Cloud Bridge monitors deployed agents and software versions and provides manually triggered or automated lifecycle management. Multiple agents may exist in the same environment for redundancy and performance reasons.
[0121] Assets are CSPI resources that represent remote resources discovered by agents, capture their properties in the remote environment, and provide CSPI properties (e.g., CloudID, resource principal, etc.) for use across other cloud services provided by CSPI. Users can manually add assets in an environment or trigger automatic discovery based on integration with infrastructure / systems management products such as Oracle Enterprise Manager and Microsoft Active Directory. CSPI applies default access policies based on asset type. For example, a database asset may default to allowing only SQLNet connections encrypted by SSL. Environments and discovered assets may be managed by an asset inventory exposed to users through a console. Users may choose to perform any action on an asset depending on the asset type and the service plugins available for the asset type. For example, a virtual machine asset type may support multiple actions, such as cloud migration using Oracle Cloud Migrations, exposure as a VNIC using a virtual network, or dispatching metrics to CSPI using observability, as described in detail herein. A database asset type may similarly support integration with various database services, such as the Data Safe service and the Database Migration service. Cloud Bridge can also integrate with various data management services, such as the Management Agent Cloud Service (MACS) agent, which provides an on-guest agent, and agent plug-in capabilities to collect additional metadata about assets. MAC agents can use the Cloud Bridge agent framework, making the integration and functionality seamless for users.
[0122] FIG. 4A is a high-level diagram of a distributed environment 400 illustrating a cloud bridge architecture for managing and configuring remote resources that interact with cloud services, according to one embodiment. As shown in the example depicted in FIG. 4A , distributed environment 400 includes a cloud infrastructure 402 (CSPI) physically hosted within one or more global regions 403 (i.e., data centers managed by a cloud service provider, such as Oracle) that provides high-performance computing and storage capacity (as physical or virtual hardware instances) within a flexible overlay virtual network securely accessible from users' on-premises networks (e.g., on-premises network 404 and / or on-premises network 406). CSPI 402 includes a console 408 that enables users and network administrators to configure, access, and manage remote resources and resources deployed within the cloud using CSPI resources. In one embodiment, console 408 provides a web-based user interface that can be used to access and manage CSPI 402 and various service functions, including cloud bridge and migration services. In some implementations, console 408 is a web-based application provided by the CSP.
[0123] CSPs may use CSPI402 to offer various services. In some cases, users of CSPI402 may act as service providers themselves and offer services using CSPI402's resources. Service providers may expose service endpoints characterized by identifying information (e.g., IP addresses, DNS names, and DNS ports). User resources (e.g., compute instances, on-premises resources, off-premises resources, etc.) can consume a particular service by accessing the service endpoint exposed by the service for that service. These service endpoints are generally endpoints that are publicly accessible by users via a public communication network such as the Internet using a public IP address associated with the endpoint. In one embodiment, a service provider may expose a service (e.g., Cloud Service A, Cloud Service B, Cloud Service C, Cloud Service D, Cloud Service E) through an endpoint for the service (sometimes referred to as a service endpoint) (e.g., CSA, CSB, CSC, CSD, CSE). Users of the service can then access the service using this service endpoint. In one implementation, a service endpoint provided for a service can be accessed by multiple users seeking to consume the service. In other implementations, a dedicated service endpoint may be provided to a user, allowing only that user to access the service using that dedicated service endpoint.
[0124] CSPI402 provides services and resources that users can subscribe to and use to build VCNs. In one embodiment, CSPI402 provides IaaS and iPaaS services to subscribing users. In this example, the user configures VCN410 for global region 403. The user may deploy various compute instances to VCN410, which may include virtual machines or bare metal instances. Example instances include applications, databases, load balancers, and the like. Multiple compute instances may be deployed in each subnet. In the embodiment shown in FIG. 4A, VCN410 includes a single subnet412, but it should be understood that VCN410 may be configured using any number of subnets. The compute instances within a subnet may be hosted by one or more host machines within CSPI402. The compute instances join the subnet through VNICs associated with the compute instances, as described in detail with respect to FIG. 1.
[0125] Compute instances deployed in a subnet, such as subnet 412 of VCN 410, can communicate with various endpoints. These endpoints may include endpoints hosted by CSPI 402 and endpoints outside of CSPI 402. Endpoints hosted by CSPI 402 may include endpoints on the same subnet as the particular compute instance, endpoints on a different subnet but in the same VCN, endpoints in a different VCN in the same region, or endpoints in a VCN in a different region. Compute instances in a subnet hosted by CSPI 402 may communicate with endpoints not hosted by CSPI 402 (i.e., outside of CSPI 402). These outside endpoints include endpoints in the user's on-premises network (e.g., on-premises network 404 and / or on-premises network 406), endpoints in networks hosted by other remote clouds, public endpoints accessible over a public network such as the Internet, and other endpoints.
[0126] The user's on-premises network 404 and / or on-premises network 406 may be the user's network or the user's data center built using the user's resources. While the user's external resources are all shown as on-premises in FIG. 4A , it should be understood that the resources may also be off-premises, such as part of a VCN within a CSPI of a different CSP. Access to the on-premises network 404 and / or on-premises network 406 is typically highly restricted. For a user who has both the user's on-premises network 404 and / or on-premises network 406 and one or more VCNs 410 deployed or hosted in the cloud by CSPI 402, the user may want to allow cloud services (e.g., cloud services A-E) to interact with the user's external resources (e.g., on-premises database 416, on-premises virtual machine 418, on-premises database 420, etc.). This allows the user to build an extended hybrid or multi-cloud environment that encompasses the user's VCN 104 and the user's external resources hosted by CSPI 101. A cloud bridge service enables this interaction. To enable such interaction, a communication channel 422 is established, with one endpoint of the channel being within on-premises network 404 and / or on-premises network 406 and the other endpoint being within CSPI 402 and connected to the user's VCN 410. Communication channel 422 can traverse a public communication network such as the Internet or a private communication network. Various communication protocols may be used, such as IPsec VPN technology over a public communication network such as the Internet, or Oracle's FastConnect technology, which uses a private network instead of a public network. The software or virtual machine within user's on-premises network 404 and / or on-premises network 406 that forms one endpoint of communication channel 422 is referred to as agent 424.On the CSPI 402 side, the endpoints (eg, DB1, DB2, VM1) may be host machines running gateways such as DRG.
[0127] The Cloud Bridge service consists of three main functions: agents, asset discovery, and asset inventory.
[0128] The agent functionality enables the cloud services provided by CSPI 402 to interact with a user's external resources (e.g., on-premises database 416, on-premises virtual machine 418, and on-premises database 420). The agent functionality is implemented using agents 424 and a corresponding cloud bridge control plane 425 (also known as an agent control plane or appliance control plane). Agents 424 are specialized software components used as a platform for deploying cloud service functions that interact with external resources. Each agent 424 has a corresponding agent identifier (e.g., a CSPI identifier used to identify an asset as a resource in CSPI 402), which is associated with an external site identifier (e.g., externalSiteId) of the external environment (e.g., on-premises network 404 and / or on-premises network 406) in which the agent 424 is deployed. The external site identifier is used to identify the external resources and the external environment in which the agent is deployed. The agent control plane 425 provides management and coordination of the entire cloud bridge architecture, such as agent registration and agent lifecycle management.
[0129] The asset discovery functionality enables learning about a user's resources in the external environment (e.g., on-premises network 404 and / or on-premises network 406) and creating / updating assets representing the resources in cloud bridge inventory 426. An asset is a resource in CSPI 402 that represents metadata for resources residing in the external environment, such as a vSphere VM, an EC2 instance, or a database. Each asset has an asset type that defines different types of assets, an asset identifier (e.g., a CSPI identifier used to identify the asset as a resource in CSPI 402), an associated external site identifier, and a source identifier used to identify the discovery plugin that discovered the resource associated with the asset. The asset discovery functionality is implemented using discovery plugins 427 and corresponding discovery control plane 428 integrated with agent 425. Discovery plugins 427 are software components deployed in the external environment that provide functionality such as asset discovery, metadata and metrics collection, and reporting of resources and metadata to inventory 426. The discovery control plane 428 is deployed in the overlay and includes one or more applications backed by a data store (e.g., an autonomous transaction processing (ATP) data store), and is responsible for handling requests related to asset discovery received from user-facing APIs, as well as communication and coordination of discovery plugin 427 tasks.
[0130] The asset inventory function allows for storing metadata about assets and relationships discovered through asset discovery or imported by a user. The asset inventory also exposes user-facing APIs for creating, retrieving, searching, and analyzing various assets. The asset inventory is implemented using inventory 426 and a corresponding inventory control plane 430. Inventory 426 is a region-specific CSPI 402 resource (e.g., data table or database) that supports standard CRUDL operations. Inventory control plane 430 is an application deployed in the overlay and backed by a data store (e.g., an ATP data store) that is responsible for handling asset inventory-related requests received from the user-facing APIs, as well as communication and coordination of inventory 426 and asset-related tasks. In one embodiment, the asset inventory function is limited to a single inventory per region. Advantageously, this helps eliminate duplication of assets within a tenancy. Preventing asset duplication helps prevent downstream services, such as migration and replication services, from copying the same VM data multiple times and creating multiple CSPI 402 resources for the same asset. This also provides a single global view of a user's assets across different external environments (e.g., multi-cloud services).
[0131] As shown in FIGS. 4B and 4C , agent 424 is deployed within a user's external environment (e.g., on-premises network 404 and / or on-premises network 406) as part of virtual appliance 432. Virtual appliance 432 is a virtual machine pre-configured with agent software, plug-ins, and management components. The key components of virtual appliance 432 are agent services subsystem 434, update services subsystem 436, and security services subsystem 438. Agent services subsystem 434 provides the core functionality of the agent and lifecycle management of plug-ins, such as discovery plug-in 427 and replication plug-in 440. This includes collecting and reporting plug-in status to agent control plane 425, generating and communicating agent metrics (e.g., CPU, memory, etc.) to CSPI monitoring, publishing local logs (e.g., of the appliance, agent, and its plug-ins) to CSPI logging, and running local console application functions (e.g., local console 445 used for agent registration).
[0132] The plug-in is a self-contained / standalone application that is integrated with the agent 424 as part of a virtual appliance 432 that a user creates in an external environment from an Open Virtualization Application (OVA) template. The OVA template is a virtual appliance in the Open Virtualization Format (OVF) used by virtualization applications such as VMware Workstation and Oracle VM Virtualbox. The OVA template can be used by a user to create multiple virtual machines (e.g., multiple VMs for agent functions in multiple external environments). In some embodiments, the OVA template is sealed (preventing user remote access) and does not allow the user to execute arbitrary code using the virtual appliance 432. The user may only interact with the OVA template via the local console 445 for registration; all other management operations are coordinated with the virtual appliance 432 from CSPI 402. The agent 424 provides the plug-in with environment / configuration information (e.g., CSPI 402 region, external site identifier, agent identifier, agent type, etc.) and the information the plug-in needs to obtain a resource principal session token for communication with CSPI 402. Agent 424 also provides monitoring capabilities (metrics and logging) and reports the status of plugins to agent control plane 425. Agent 424 itself is not publicly accessible from the internet; agent 424 and associated plugins initiate connections to CSPI 402's API endpoints (either direct or through a corporate proxy).
[0133] As described with respect to FIG. 4A , discovery plugin 427 learns about a user's resources in the external environment (e.g., on-premises network 404 and / or on-premises network 406) and facilitates creating / updating assets representing the resources in cloud bridge inventory 426. Replication plugin 440 is deployed in external environment 404 and is responsible for replicating (i.e., migrating) data from on-premises VMs to the user's CSPI 402 tenancy using an asset replication task. The asset replication task is the atomic unit of work by which replication plugin 440 imports a user's assets into CSPI 402's object storage. This approach lowers the barrier to entry for migration by not requiring users to establish an on-premises connection to CSPI 402 or to open ports for communication to CSPI 402 for each asset source (e.g., vCenter). Replication plugin 440 is published as a binary and then deployed to the corresponding appliance by the CSPI 402 service. Although only detection plug-in 427 and replication plug-in 440 are shown and described in this specification with respect to virtual appliance 432, it should be understood that other types of plug-ins may be integrated with agent 424 as part of virtual appliance 432 to facilitate the provision of one or more functions (e.g., cloud services).
[0134] For some features, agent 424 requires third-party libraries / packages that may not be distributed as part of the agent package and require consent and special actions by the user. For example, in the case of cloud migration scope, the Virtual Disk Development Kit (VDDK) is required to generate snapshots of VMware VM disks by replication plugin 440. The user-initiated agent dependency process involves the user downloading the third-party library / package from the relevant third-party site, accepting the terms of service, and uploading the library / package to a pre-configured CSPI 402 object storage bucket. In some cases, public documentation provided by the CSP provides the user with links and specific instructions on how the download / upload is performed, which may be performed once per version of the dependency. The user then logs into console 408, navigates to agent dependency settings, and creates a new agent dependency for the library / package, including providing the object location in object storage (e.g., namespace, bucket, object name), and selects the library / package type. This causes the agent control plane 425 to initiate a dependency signature verification workflow, which downloads and calculates the library / package's signature (checksum) and compares the library / package's signature with the whitelist signature in the database to identify and validate the library / package. Once the library / package is identified and validated, the user goes to the console 408, navigates to the external site settings, and adds the agent dependency identifier to the external site identifier. The agent 424 then retrieves this information from the agent control plane 425 and installs the dependency locally, making it available for plugin consumption.
[0135] The update service subsystem 436 updates the software and parameters of the agent service subsystem 434 and the virtual appliance 432. The update service subsystem 436 includes the updater 440, a software component that runs on the virtual appliance 432 and is responsible for keeping the virtual appliance 432 up to date. The components of the agent 424 are managed by Cloud Bridge engineers. The release of new code (e.g., a new agent security update) triggers the creation of a new bundle for a specific component of the agent 424 (e.g., the security service subsystem 438). The updater 440 maintains a list of currently used components and the version of the bundle each component uses. A bundle is a specific realization or instance of a component. The bundle description is stored in the agent control plane 425's database or embeddable key / value store, while the data portion is a blob stored in the agent control plane 425's object storage. The blob is a binary file containing executables, configurations, and other data required to update the component. The updater 440 periodically polls the agent control plane 425. If a new bundle is available, agent control plane 425 responds to the poll with an "update" command containing information about the new bundle to install. When updater 440 receives the "update" command, it downloads the blob, creates a rollback snapshot, prepares a new file system (e.g., a subvolume) using the updates based on the blob, stops agent 424 processing, and restarts agent 424 into the new file system.
[0136] The security services subsystem 438 implements security and compliance controls for the agent services subsystem 434 and the virtual appliance 432 using firewalls, antivirus scanning tools, auditing tools, and system configurations.
[0137] To facilitate understanding of the Cloud Bridge architecture, the following use cases are provided, however, it should be understood that these use cases are non-limiting and that other use cases are contemplated and may be implemented by the Cloud Bridge within CSPI.
[0138] Use Case 1: Private access to remote databases for database security cloud services. 1. A user uses the console 408 to create an external environment, i.e., an on-premise network 404. 2. The user downloads the OVA template of the virtual appliance 432 and deploys the agent 424 to the on-premise network 404. 3. The user accesses the local console 445 of the agent 424 and registers the agent 424 with the cloud bridge. 4. The user initiates discovery from the console 408 to discover resources in the on-premise network 404, including the on-premise database 416. 5. Agent 424 collects host, database, and database object metadata and creates or updates database assets in inventory 426 using discovery plugins 427, discovery control plane 428, and inventory control plane 430. 6. The user views the discovered database assets in inventory 426 via console 408, identifies the asset associated with on-premises database 416, and creates a database private endpoint (DB1) in VCN 410 to enable private network access to the asset associated with on-premises database 416 that the user wants to use with a database security cloud service (cloud service A) (e.g., Data Safe). 7. The user creates a private endpoint (CSA) for the database security cloud service (Cloud Service A) in VCN 410 and configures the private endpoint to protect assets associated with on-premises database 416 based on CloudID or IP address, just as the user protects the cloud-native database in VCN 410. 8. Optionally, the user configures the compute instance in VCN 410 to connect to on-premise database 416 via a private endpoint (DB1) and communication channel 422.
[0139] Use case 2: Private access to a remote virtual machine hosting a data repository. 1. A user uses the console 408 to create an external environment, i.e., an on-premise network 404. 2. The user downloads the OVA template of the virtual appliance 432 and deploys the agent 424 to the on-premise network 404. 3. The user accesses the local console 445 of the agent 424 and registers the agent 424 with the cloud bridge. 4. The user initiates discovery from the console 408 to discover resources in the on-premise network 404, including the on-premise virtual machine 418 running the self-hosted Bitbucket Server. 5. Agent 424 collects host, database, and database object metadata and creates or updates database assets in inventory 426 using discovery plugins 427, discovery control plane 428, and inventory control plane 430. 6. The user views the discovered VM assets in inventory 426 via console 408, identifies the asset associated with the on-premises virtual machine 418, and creates a VM private endpoint (VM1) in VCN 410 to enable private network access to the asset associated with the on-premises virtual machine 418 that the user wants to use with a VM cloud service (cloud service B) (e.g., CSPI DevOps services). 7. User creates a private endpoint (CSB) for CSPI DevOps service (e.g. self-hosted Bitbucket Server) in VCN410, selects the newly created VM private endpoint (VM1) to configure the connection URL, and adds authentication information. 8. User configures CSPI DevOps "Managed Build Stage" to use the Private Endpoint (CSB) and VM Private Endpoint (VM1) as part of the DevOps CI / CD pipeline. 9. A user runs a pipeline that can access the data repository from a remote self-hosted Bitbucket Server via a private endpoint (CSB), a VM private endpoint (VM1), and communication channel 422.
[0140] In some embodiments, the cloud integration service facilitates the migration of workloads from external environments to other environments, such as CSPIs (e.g., CSPIs 101 and 200 described with respect to FIGS. 1 and 2 ) or other CSPIs. The workload migration service assists users with all aspects of cloud migration, whether migrating a multi-tier application, a specific data center, or a specific class of infrastructure. The cloud migration service (e.g., Oracle Cloud Migration (OCB)) interfaces with a cloud bridge service (e.g., Oracle Cloud Bridge (OCB)) for management and configuration of remote resources that interact with other cloud services provided by the CSPI. The cloud bridge handles key aspects of this integration, including automatic discovery and cloud identity of remote resources, representation of remote resources as assets within the user's tenancy, secure network connectivity between the remote resources and the CSPI, and lifecycle management of agent technology running within the remote environment.
[0141] In some embodiments, the cloud migration service provides an end-to-end, comprehensive self-service experience for migrating existing VMware virtual machine-based workloads from on-premises to CSPI. The cloud migration service enables users to identify virtual machine workloads hosted in environments external to CSPI, plan the migration, and automate the migration workflow. For example, the cloud migration service may provide the following tasks: Automatically discover virtual machines outside of CSPI. Organizing virtual machines for migration. Replicate virtual machine data to CSPI. Plan for virtual machine redeployment. Reconfigure the virtual machine to automatically boot successfully as a CSPI compute instance. Start a virtual machine as a CSPI compute instance using the replicated data.
[0142] A successful migration can involve using a framework to discover and survey existing assets, such as on-premises assets, and then plan the migration, replicate data, and initiate the target environment. The top-level container is used as a migration service resource to track all aspects of the migration from discovery to activation. From discovery to migration execution, the cloud migration service maintains a standardized asset inventory and provides a unified experience for migrating assets to any appropriate cloud service, regardless of their type. For example, VM instances in the cloud migration inventory can be migrated to Virtual Machine Interface (VMI), Bare Metal, or VMware over CSP. The cloud migration service can provide recommendations and cost estimates to maximize user benefits; for example, a CSP may recommend that instead of migrating a database server as a VM, the user should consider migrating the logical database to DBaaS.
[0143] The steps of an exemplary migration are shown in FIG. 5. As shown, the exemplary migration 500 includes managing migration assets (505), analyzing and migrating assets (510), and verifying the success of the migration (515). Managing migration assets 505 includes connecting to a source environment (520), deploying a virtual agent (525), and discovering assets in the source environment (530). The source environment represents an on-premises environment (external to CSPI), such as an on-premises data center in a VMware asset source deployment. To connect an external source environment to CSPI (520), a user configures the source environment using a console (a browser-based interface such as console 408 described with reference to FIGS. 4A-4C), a CSPI command line interface (CLI), or a REST API. For example, a user may open the console's navigation menu and select a service, such as Migration Services. In Migration Services, a user may select Remote Connection and then select Create Source Environment. The user may then enter a name for the source environment, select a partition created on the CSPI associated with the source environment (which provides a global logical namespace as a folder in a file system against which policies can be enforced), and execute the creation of the source environment. Once the source environment is created, the user may download an appropriate remote agent appliance, e.g., an OVA file, and install the agent appliance, as described in detail with respect to FIGS. 4A-4C. The agent appliance is then registered and validated for use in the source environment. To enable operation of the remote agent appliance, agent dependencies may be added to the source environment as third-party library dependencies on the agent appliance. For example, the agent dependencies may be added using VDDK, as described in detail with respect to FIGS. 4A-4C.
[0144] Asset discovery 530 enables identification and metadata collection of various assets, including VMs, from external environments and representation of the assets and associated metadata in an inventory asset, facilitating the migration process. Asset discovery 530 is performed using connectors and includes creating asset sources and discovery work requests and initiating and running one or more plug-ins in the on-premises environment, including, for example, a discovery plug-in for performing external asset discovery. The discovery plug-in searches for assets in the source environment using environment-specific connectors and APIs. The discovery plug-in is described herein as supporting VMware through a Cloud Bridge-based connector and agent deployed directly on the VM to be migrated. However, it should be understood that other connectors may be built and used to support other assets, clouds, and environments, such as Hyper-V or Enterprise Manager. Users may configure connectors for one-time use or for ongoing monitoring to extract cloud monitoring runtime metrics and track changes to external assets. In addition to metadata and metrics, external assets include their history and how they were discovered / imported. Metadata history is tracked so that users can monitor the evolution of assets over the course of a migration over time, allowing the cloud migration service to highlight changes that may require modifications to the migration plan.
[0145] Discovered assets are recorded and tracked in an inventory subsystem (e.g., cloud bridge inventory 426 described with respect to Figures 4A-4C). The inventory subsystem retrieves metadata information that tracks assets, including physical and runtime properties of virtual machines, such as operating system, hardware, and resource utilization. The inventory subsystem then stores the metadata information in a table or database as a collection of assets and associated metadata (i.e., inventory). The inventory subsystem is used to store information about assets discovered in the on-premises environment that can be migrated. These assets are added to the inventory subsystem by importing a CSV file using an API or by performing automatic discovery in the external environment via a discovery plugin.
[0146] After external assets are discovered and the required data is collected, asset analysis and migration 510 is performed to create a migration project (535), create one or more migration plans (540), and / or replicate migration assets (545). More specifically, after a user discovers their external assets, the user can create a migration project (535) to group interrelated and dependent assets for migration. Projects are independent of how they are configured; a user may want to migrate a specific tier of an application or infrastructure. The user can query the inventory for suggested groupings based on observed runtime dependencies or other metadata extracted from the source environment. Migration assets located in the inventory subsystem can then be added to the migration project. The migration project can be used to replicate all migration assets related to the migration. Migration assets within a project can be configured to reference replication policies that describe how assets are moved to the CSPI. Replication policies allow for manual or connector-based replication of full images or incremental asset snapshots on demand or on a schedule specified by the user. Users can also specify whether replicated data overwrites or extends previous snapshots to manage storage costs.
[0147] From a project, a user can manage grouped inventory assets. For example, a user may set a default replication policy or update external assets from discovery. Within a project, a user creates launch plans (540). A launch plan is a context containing a mapping of source assets to target resource types in CSPI, as well as the partitions, subnets, and launch dependencies that launch those source assets. A user may want to create multiple launch plans for a single migration project for various reasons. A user may want to create an initial launch with minimal sizing calculations to easily test functionality after migration, another plan later for performance testing, and yet another plan for dial-in right-sizing. Each of these may launch in a different environment to ensure isolation.
[0148] When a user creates a new launch plan, they can instruct the Cloud Migration Service to pre-populate target resource selections with recommendations based on inventory and metric metadata. For example, a user may want the Cloud Migration Service to select a target compute shape using minimum size, average utilization, or peak utilization. Users can override any target selection, exclude individual assets from the launch, or select an existing CSPI instance if the migration has already occurred out-of-band. When edited, the plan provides updated cost and other assessments of the CSPI deployment (such as the impact of limitations) and highlights possible compatibility or capacity issues. Users can launch, restart (terminate the existing one and restart using the latest one), and terminate from a launch plan.
[0149] Replication of migration assets 545 includes the creation of an asset in CSPI that replicates an asset within an external user environment, such as within an on-premises environment. In some embodiments, this replication is performed in part by a replication plugin that can manage the replication of external asset snapshots. This replication includes the management of one or more full image and / or incremental virtual machine snapshots. The user indirectly controls replication by defining replication policies. Each policy corresponds to a migration project and specifies the assets to be replicated to CSPI and the frequency of replication. Multiple workflows within the migration and replication control plane monitor replication policies, schedule replication tasks according to existing replication policies, and monitor the progress of each replication. With each replication run, a snapshot of the asset is taken and imported into CSPI. The user enables the replication plugin on the Cloud Bridge appliance by providing the credentials and metadata required by the Cloud Bridge appliance configuration. The installation process is handled by the Cloud Bridge appliance. Once the replication plugin is enabled, it registers with the replication service and begins polling for replication tasks using the replication service API.
[0150] Migration can be a long-term process and can include one or more iterations of test launches using various configurations. In some embodiments, these iterations can include successive updates of source data from the source environment before the final migration and activation of the migrated system within CSPI. For example, in embodiments in which a user migrates information from a source environment to CSPI, and specifically to the user's tenancy within CSPI, the user may repeatedly discover and / or capture on-premises assets, and a migration plan can be generated for some or all of the times the on-premises assets are discovered. For example, in embodiments in which a user modifies one or more on-premises assets, these changes can be captured and / or detected by repeated iterations of discovery of those assets. In such embodiments, a migration can be planned that can capture each of these versions of the user's assets. In some embodiments, only the final versions of the assets are migrated, and in some embodiments, the user can control which versions of the assets are replicated to CSPI.
[0151] In some embodiments, planning for the migration includes evaluating the capabilities of the CSPI compared to the capabilities of the on-premises environment and / or on-premises assets. This evaluation includes determining whether and to what extent the on-premises capabilities differ from and / or exceed the capabilities of the CSPI. Based on this determination, the plan for the migration of the assets may be modified.
[0152] In particular, for example, during the planning step, the capabilities of a user's on-premises VMs are identified and one or more VM configurations (recommended) within OCI are presented. This identification includes identifying attributes of each on-premises VM, including hardware, capabilities, and actual usage metrics. The attributes may include the number of CPUs, average CPU usage, maximum CPU usage, memory, average memory usage, maximum memory usage, number of VNICs, number of graphics processing units (GPUs), and / or network bandwidth.
[0153] Based on this information, several suggested OCI VM shapes are presented, which may be generated and presented based in part on information relevant to the user, such as the user's preferences for optimal pricing or optimal performance.
[0154] The attributes of the on-premises VM are compared with the identified attributes of the OCI VM shape, and a difference score is generated that characterizes the differences between the attributes of the OCI VM shape and the attributes of the on-premises VM. If the difference score indicates that the differences between the attributes of the OCI VM shape and the on-premises VM are too large, an incompatibility error is generated.
[0155] The VM shapes selected by the user are combined to form a migration plan, which can be a terraform representation of the migration plan.
[0156] After the migration planning is complete, a migration replication step may be performed. In some embodiments, the replication step is performed once, while in other embodiments, the replication step may be performed repeatedly as on-premises assets change and / or are modified. In some embodiments, the replication step may include creating a snapshot of one or more assets to be replicated and storing the snapshot. In some embodiments, the snapshot may be stored in a golden volume group (GVG). A copy of the snapshot stored in the GVG may be created, modified, and then used in creating an executable stack, such as a terraform stack. In some embodiments, a user may be provided with an executable stack and modify the executable stack before running it, thereby replicating assets to the CSPI, and in particular, to the user's tenancy within the CSPI.
[0157] Validating the success of the migration (515) includes launching the target assets into the CSPI instance (550), validating the instance creation within the CSPI (555), and marking the migration project as complete (560). Launching the target assets into the CSPI instance (550) includes the cloud migration service launching compute instances to run hydration agents during data replication. Target assets may be launched into the CSPI instance using a resource manager, such as Oracle Resource Manager (ORM). Hydration agents are pooled together based on the location of the replication. Hydration agents are automatically started to load balance the replication process based on the object pool. These agents are then automatically terminated after they become idle and there are no more pending replication jobs. During the replication workflow, volume snapshots of the VMs are stored in object storage. The snapshot data is deleted from object storage after the hydration agent writes the data to the block volume. During the replication workflow, a temporary VCN is created to provide the hydration agents with connectivity to the object storage. This VCN is terminated after all hydration agents are no longer active. A set of block volumes resides in the user's tenancy for the entire life of the migration asset. A golden volume, also known as a volume group, is created for each boot and data volume attached to the source asset, such as a VM. The golden volumes are kept synchronized with snapshots created in the source environment. As part of each replication update, a new set of volumes is created and used to launch compute instances into CSPI. Launching a compute instance involves launching an asset, such as a VM, including its partition, subnet, and launch dependencies. The VM is then replicated to the OCI instance. The user can then mark the project as complete.This action prevents the migration module from attempting to detect further changes to the source environment or from proposing new recommendations. After the project is marked as complete, the cloud migration service disconnects the production environment from the migration workflow and archives the migrated inventory.
[0158] An example embodiment of an architecture 600 that may be implemented for migration is shown in Figure 6. Architecture 600 includes an external user environment 602 and a CSPI 604. External user environment 602 includes any environment that is distinct from CSPI 604. In some embodiments, external user environment 602 may include an on-premises environment and / or a CSPI that is separate from CSPI 602. CSPI 604 and external user environment 602 are communicatively coupled via a public network 606. Public network 606 may be a wired and / or wireless communication network and may include, for example, the public Internet.
[0159] The user environment 602 includes a virtual appliance 610 (as described in detail with respect to FIGS. 4A-4C ), which may include a replication plug-in 612. The replication plug-in 608 is an application developed by a cloud migration service and deployed to the user's virtual appliance 610 by a cloud bridge service. Installation, registration, and lifecycle management of the replication plug-in 612 may be performed by the cloud bridge service. After the replication plug-in 612 starts up, it registers with the replication control plane 615 and repeatedly polls the replication control plane 615 for replication tasks. Each task describes a single asset to be replicated (e.g., a VMware VM), metadata for the corresponding asset source 616 (e.g., a vCenter), and a destination in object storage 618 (e.g., an object storage bucket for uploading a disk snapshot). The asset source's credentials are retrieved directly from the CSPI vault or data storage by the replication plug-in 608 using the metadata; the replication control plane 615 does not have access to these credentials. The credentials are kept only in memory and are re-acquired when the replication plug-in 608 restarts.
[0160] While a task is running, the replication plug-in 608 periodically updates the task status and progress, which are then aggregated by the replication workflow and propagated to the user interface. Progress is reported to the user interface as part of the overall migration iteration progress. As described with respect to FIG. 5, the replication control plane 615 schedules replication tasks according to the replication policies specified by the customer during migration configuration. The policies specify which customer assets should be migrated, how the customer assets are mapped to CSPI assets, and the frequency of migration. A separate replication task may be created for each asset in a single iteration of the migration. This allows for maximum replication concurrency when multiple Cloud Bridge appliances are connected to the same asset source and can run replication tasks for the same migration in parallel.
[0161] Given the iterative nature of replication, the replication plug-in 608 performs incremental snapshots whenever possible. Specifically, if the asset source allows the replication plug-in 608 to calculate and access changes to the asset disk since the most recently imported snapshot, only these changes, along with corresponding metadata, are imported by the plug-in into CSPI 604 and then used by the replication server 620 to create the latest golden volume group (the volume group corresponding to the most recently imported snapshot of the customer's asset's as-is disk). This optimization results in significant performance and cost improvements. It should be noted that the replication plug-in 608 is an optional part of the replication component / workflow. In some cases, for data centers where migration and replication services have direct access to assets (e.g., AWS Elastic Block Store direct API) and can import disk snapshots directly into CSPI 604, the replication plug-in 608 is not required.
[0162] CSPI 604 includes a user tenancy 622 and a service tenancy 624. User tenancy 622 includes object storage 618, replication server 620, and block storage 625. Object storage 618 is an internet-scale storage platform that provides reliable, cost-effective data durability for retaining assets during replication. In some cases, object storage 618 can store large amounts of unstructured data. This unstructured data can be any content type, including analytical data and rich content such as images and videos. For example, an asset analytics API may be provided to users to help them aggregate asset metadata in object storage 618 to gain insight into their external environment (e.g., an on-premises environment). Replication server 620, in some embodiments, is a virtual machine that can read one or more asset snapshots and write those one or more asset snapshots to one or more volumes. In some embodiments, replication server 620 can effectively save one or more snapshots to one or more desired locations. In some embodiments, the location or locations to which one or more assets are written can be volumes corresponding to one or more attributes or all or part of each of the assets. In some embodiments, after any modifications, these volumes can be used to launch one or more assets in CSPI 604 that are identical to the source asset. Block storage 625 is structured storage and / or storage for structured data and is used to hold migrated assets after replication. In some embodiments, block storage can, for example, store data in one or more equal-sized blocks. These blocks can be stored in the underlying physical storage in a manner optimized for fast access and retrieval.
[0163] Service tenancy 624 includes an appliance control plane 630, a migration and replication control plane 632, a replication control plane 615, an inventory control plane 634, and a discovery control plane 640. Appliance control plane 630 includes customer-facing APIs deployed in the overlay that provide management and coordination of the entire cloud bridge architecture, such as agent registration and agent lifecycle management, as described with respect to FIGS. 4A-4C. Migration and replication control plane 632 is the main endpoint for all tasks related to migration planning, migration execution, and replication. More specifically, migration and replication control plane 632 includes customer-facing APIs deployed in the overlay that are responsible for managing migration resources, scheduling and triggering asset migrations, and coordinating asset replication. Replication control plane 615 includes customer-facing APIs deployed in the overlay that are responsible for replicating one or more source assets. Inventory control plane 634 includes customer-facing APIs deployed in the overlay that are responsible for managing assets and their metadata in the inventory. The discovery control plane 640 includes a customer-facing API deployed in the overlay that is responsible for configuring discovery and coordinating discovery plugins.
[0164] Plan, evaluate, and launch A user may have one or more local resources and / or resources in one environment, and the user desires to migrate those resources to another environment, and in particular, to CSPI. This migration may include, for example, migrating one or more resources from an on-premises environment to CSPI, migrating one or more resources from another CSPI to CSPI, migrating one or more resources from one part of CSPI to another part of CSPI, e.g., from one tenancy within CSPI to another tenancy within CSPI, etc. These local resources may include, for example, one or more VMs, databases, directories, etc. Thus, in some embodiments, migrating one or more resources to CSPI may include migrating one or more VMs, databases, directories, libraries, and / or the like to CSPI. This migration may include, for example, replicating these local resources within CSPI.
[0165] Traditionally, the user experience for migrating to a tenancy in and / or within a CSPI can be complex and time-consuming. Currently, user migrations can be provided through a patchwork approach. In such an approach, for example, users at large customers with large amounts of local resources to be migrated may be provided with dedicated migration assistance. However, such personalized assistance does not scale. As a result, users with smaller migration needs may use a combination of third-party products and consultants to migrate their workloads to CSPI.
[0166] Migration challenges similarly apply to migration planning, assessment, and / or activation, which may include discovery and / or investigation of assets to be migrated, migration planning, data replication, and / or activation of the target environment.
[0167] In some embodiments, migration can be a long-term process in which a user migrating one or more resources can perform one or more iterations of test runs in various configurations, iteratively updating data from the source environment before making the final migration and immediately running a production system within CSPI.
[0168] In many cases, a user migrating resources may not understand the source environment to which they are migrating resources. This may include not understanding the assets contained in the source environment and / or how those assets interact. Additionally, a user migrating resources may not understand the configuration of the source environment, including the capabilities of the source environment. As a result, the user may not be able to fully describe the source environment and / or the capabilities or configuration of the source environment for the migration.
[0169] The present disclosure relates to systems and methods for automatically discovering resources in a source environment, discovering capabilities and / or configurations of a source environment, and / or the like. The present disclosure further relates to automatically generating migration planning information, including generating recommendations regarding one or more configurations.
[0170] A migrating user can select resources for migration. These resources can be identified by a discovery process or can be identified and / or selected by a user. In some embodiments, the migrating user can select a set of related discovered assets. A migration plan can then be developed for these selected assets. Development of the migration plan can include assessment of the source environment and generation of one or more shapes and / or configurations of the destination environment and / or of VMs to be created for the assets to be migrated. The user can select from the shapes and / or configurations, and the selected shapes and / or configurations can be implemented in the migration.
[0171] In some embodiments, migration can be an iterative process that helps users migrate resources from on-premises environments or other clouds to CSPI. In some embodiments, users can modify the migration process, roll back the migration, and / or reapply the migration at any time.
[0172] In some embodiments, a "transition" as used herein can be a grouping of assets that a user chooses to migrate together.
[0173] An "asset" can be a resource that is part of the migration inventory and represents metadata for one or more external resources, such as virtual machines, databases, volumes, etc., discovered in the external environment.
[0174] The "external environment" can be the environment from which the asset is transferred. A "migration plan" can be a high-level container that defines the target environment and target configuration for each asset to be migrated. In some embodiments, a migration plan can be iterated to test different target recommendations and to distinguish between test migrations and final production migrations.
[0175] A "migration asset" can be a "snapshot" of the metadata of an asset that has been discovered and is in the inventory of assets for migration. Example: a migration plan to boot to a test partition on a VM with the same number of CPUs.
[0176] A "replication policy" can be a schedule for performing asset data replication for an entire migration or for a single asset.
[0177] A "target asset" can be the configuration and metadata about the target of a migration for a single asset to be migrated. A target asset can be based on recommendations such as specific representation resources that may be created. A target asset can include recommended resource configurations / shapes, estimated costs, and / or compatibility ratings.
[0178] 7, one embodiment of a workflow 700 for migration services is shown. Workflow 700 may be performed by multiple components and / or modules, which may include, for example, a client 702, a migration API 704, a migration asset API 706, a migration plan API 708, an assessment workflow 710, a target asset API 712, and an RMS API 714. In some embodiments, the workflow may include the following major steps: managing a migration project 716, managing a migration plan 718, managing one or more target assets 720, replicating and / or modifying data 722, and executing the migration 724.
[0179] In some embodiments, managing migration projects 716 may include, for example, a client 702 interacting with a migration API 704 to create / update migration protections. In some embodiments, a migration may be a resource in CSPI 604 that represents a migration project. In some embodiments, managing migration projects 716 may include identifying assets, a source environment, and / or a destination environment for the migration. This identification may include identifying one or more assets in the source environment. The one or more assets may be added to the migration through interactions between the client 702 and the migration asset API 706. In some embodiments, a user may explore assets available for migration. In some embodiments, these assets may include assets that are not yet in the migration project. In some embodiments, a user may update a migration project. Such updates may occur at any time and may include adding one or more new assets to the migration project and / or removing one or more assets from the migration project.
[0180] In some embodiments, managing the transition plan 718 may include, for example, the client 702 interacting with the transition plan API 708 to create and / or update the transition plan. This creation and / or update may include creating and / or updating one or more transition plans. In some embodiments, when a user creates a transition plan or adds new transition assets to an existing transition plan, one or more target assets may be generated that represent a mapping between the source assets and assets generated in the destination CSPI 604.
[0181] In some embodiments, a user may create one or more migration plans, which may include, for example, different types of migration plans. These migration plans may include, for example, a test migration plan, a staging migration plan, and / or a production migration plan. In some embodiments, for example, a test migration plan may be associated with a test environment, a staging migration plan may be associated with a staging environment, and a production migration plan may be associated with a production environment. In some embodiments, the creation of different migration plans may enable testing and / or validation of a migration before executing a production migration. In some embodiments, a test migration may have a shape size that is smaller than the shape size of a production migration.
[0182] In some embodiments, for each migration plan, a user may specify one or more properties of the target environment, or in other words, properties of the environment into which the migration assets will be replicated. In some embodiments, these user-specified properties may be used to generate the target assets. In some embodiments, in the case of VMs, the target environment specification may include identification of one or more of a VCN, a preferred shape type, a dedicated host, a target partition, an availability domain, and / or the like.
[0183] In some embodiments, each migration plan may define some properties of the target asset in addition to properties of the target environment, such as the target partition and / or network. In some embodiments, the migration plan may further specify one or more strategies to use during generation of migration recommendations. In some embodiments, as part of managing 718 the migration plan API 708 may interact with an evaluation workflow 710, also referred to herein as evaluation module 710, to evaluate the compatibility of the target asset with the source environment. This evaluation may include evaluation of hardware compatibility, software compatibility, etc. In some embodiments, this evaluation may include generating cost estimates for different configurations of the target asset.
[0184] In some embodiments, as part of managing 718 the migration plan, one or more target asset recommendations may be generated. This generation may include generating one or more recommendations regarding the shape of the target asset. This recommendation may include, for example, calculating optimal shapes and / or VM instance parameters based on the current metadata of the migration asset.
[0185] In particular, using the migration asset's current metadata, calculating one or more recommended shapes may include calculating, for each shape, a number of CPUs based on the migration asset's metadata indicating one or more of the multiple CPUs in the source environment, an average CPU usage by the migration asset and / or a maximum CPU usage by the migration asset, a memory based on the migration asset's metadata indicating the average memory usage by the migration asset and / or a maximum memory usage by the migration asset, a number of VNICs based on the migration asset's metadata indicating the number of VNICs available to the migration asset, a number of GPUs based on the migration asset's metadata indicating one or more of the multiple GPUs in the source environment, an average GPU usage by the migration asset and / or a maximum GPU usage by the migration asset, a network bandwidth based on the migration asset's, average bandwidth usage by the migration asset and / or a maximum bandwidth usage by the migration asset metadata, and / or the like. In some embodiments, the calculation of the one or more shapes may further be based on a cost estimate for the shape and / or one or more user specifications. In some embodiments, as part of the computation of one or more shapes, each of the computed shapes may be evaluated for one or more incompatibilities, and the identification of the one or more incompatibilities may trigger the generation of errors and / or warnings indicating the incompatibilities.
[0186] In some embodiments, managing target assets 720 may include the client 702 interacting with the target asset API 712 to modify and / or override all or a portion of the plan for the production of the target assets. In some embodiments, a user may review one or more generated and / or planned target assets and modify those one or more target assets. In some embodiments, when a user modifies one or more target assets, new cost estimates may be recalculated for the modified one or more target assets.
[0187] In some embodiments, executing 724 the migration may include the client 702 interacting with the migration plan API 708 and / or the RMS API 714. In some embodiments, as part of executing 724 the migration, the migration plan API 708 may further interact with the RMS API 714. In some embodiments, executing 724 the migration may include the client 702 invoking the migration plan API 708 to generate a stack, such as a terraform stack. This stack may be executable by a user in the destination environment to cause copies of one or more assets to be migrated. In some embodiments, this stack may be provided to the client 702, and this stack may be modified by a user. In some embodiments, the client 702 may execute the stack, which may be a modified stack, in the destination environment. Execution of the stack causes creation of one or more resources and / or assets corresponding to the assets being modified. In some embodiments, execution of the stack may further cause information regarding the creation of the one or more resources and / or assets to be added back to the migration.
[0188] In some embodiments, after executing 724 a transition, the user can return to any step in the workflow 700 and reapply the transition. In other words, the user can return to any previous step in the workflow 700 and re-execute the transition.
[0189] 8, a flowchart illustrating one embodiment of a recommendation process 800 is shown. Process 800, in some embodiments, can generate one or more recommended shapes for the target asset. In some embodiments, the one or more recommended shapes for the target asset can be generated based on metadata characterizing attributes of the source environment, a replication strategy provided by a user, and rules specifying compatibility requirements for the recommended shapes. This metadata can, for example, characterize at least CPU-related and network-related attributes of the source environment.
[0190] In some embodiments, process 800 may be performed by all or part of system 400 and / or system 600, which may include virtual appliance 610, replication server 620, and / or replication control plane 615. Although process 800 is shown in a particular order, those skilled in the art will recognize that the steps of process 800 may be performed in a different order, that one or more shown steps may be omitted, and / or that process 800 may include one or more steps in addition to those shown in FIG.
[0191] Process 800 begins at block 802, where a request to generate a shape recommendation is received. In some embodiments, the request may be received from a client 702. The request may be received as part of the replication process 700 and / or as part of managing a migration plan 718.
[0192] At block 804, metadata for the migration assets is received. In some embodiments, the metadata characterizes attributes of the assets in the source environment. The metadata may characterize CPU-related attributes, GPU-related attributes, network-related attributes, memory-related attributes, VNIC-related attributes, and / or any other attributes of the assets in the source environment. In some embodiments, the CPU-related attributes may characterize at least one of the number of CPUs of the assets in the source environment, the average CPU usage by the assets in the source environment, and the maximum CPU usage in the source environment. In some embodiments, the GPU-related attributes characterize at least one of the number of GPUs of the assets in the source environment, the average GPU usage by the assets in the source environment, and the maximum GPU usage in the source environment. In some embodiments, the network-related attributes characterize at least one of the average bandwidth usage by the assets in the source environment and the maximum bandwidth usage by the assets in the source environment.
[0193] In some embodiments, the migration asset metadata characterizes attributes and / or configurations of the migration asset in the configuration being migrated. These attributes and / or configurations may include, for example, the number of processors (CPUs and / or GPUs), processor usage, memory, memory usage, network bandwidth, network bandwidth usage, number of VNICs and / or virtualized devices, etc.
[0194] This information may be collected by the virtual appliance 610 from a source environment, such as the external environment 602. In some embodiments, the information collected by the virtual appliance 610 may be stored in one or more databases, which may be made available to the CSPI 604. In some embodiments, this information may characterize, for example, processor usage of one or more assets, memory usage of one or more assets, network usage of one or more assets, one or more software configurations of one or more assets, etc. In some embodiments, for example, this information may characterize hardware type and / or hardware information. This information may include, for example, identification of the number of CPUs, the number of GPUs, etc. This information may further include information related to attributes of the hardware, for example, performance capabilities of one or more CPUs and / or GPUs, usage of one or more CPUs, GPUs, memory, etc. This usage information may identify maximum usage, average usage, etc. In some embodiments, this usage information may be obtained over a desired window of time, such as, for example, a 24-hour time frame, a multi-day time frame, a one-week time frame, a multi-week time frame, a one-month time frame, a multi-month time frame, etc. In some embodiments, the hardware information may include information such as, for example, processor speed, processor manufacture, operating software, and / or hardware configuration.
[0195] In some embodiments, the metadata of the migrating assets may include information related to memory. This information may identify, for example, the amount of memory, the type of memory, memory usage, etc. In some embodiments, the memory usage may identify peak usage, average usage, etc. In some embodiments, the memory usage may be the usage of all memory or may be divided into usage of different types of memory.
[0196] In some embodiments, the migration asset metadata may relate to the network and / or network usage. This may include, for example, identifying bandwidth usage, which may include, for example, maximum bandwidth usage, average bandwidth usage, etc. In some embodiments, the network information may further include information characterizing the network speed. The network information may further include, for example, information identifying the number of VNICs, smart NICs, other virtualization devices, etc.
[0197] At block 806, shape requirements based on an evaluation strategy are retrieved, received, and / or generated. In some embodiments, the step of block 806 may include receiving an evaluation strategy from a user. These evaluation strategies may specify, for example, a level of usage for which the shape should be configured, or in other words, the performance capabilities of the shape. The levels may include, for example, a level of processor usage, a level of memory usage, a level of bandwidth usage, and / or the like. In some embodiments, for example, a user may indicate that a shape's capabilities corresponding to maximum CPU usage are desired, or alternatively, that average CPU usage is desired. The strategies may include, for example, an "as is" strategy, a "custom" strategy, an "average" strategy, a "peak" strategy, a "percentile" strategy, etc.
[0198] In some embodiments, the "as is" strategy generates shapes that correspond to measurements of source assets taken from the source environment. Thus, adopting the "as is" strategy results in the creation of shapes that correspond to measurements of source assets and do not reflect usage of the source assets.
[0199] In some embodiments, a "custom" strategy may generate shapes that correspond to measurements of a source asset obtained from a source environment multiplied by a conversion factor. Thus, employing a "custom" strategy results in the creation of shapes that correspond to measurements of the source asset via a conversion factor and do not reflect usage of the source asset.
[0200] In some embodiments, an "average" strategy generates and / or selects a shape based on average resource usage over a specified timer interval. In some embodiments, a "peak" strategy generates and / or selects a shape based on maximum resource usage over a specified time interval. In some embodiments, a "percentile" strategy generates and / or selects a shape based on percentile resource usage over a specified time interval, e.g., the 90th, 95th, 99th, etc.
[0201] At block 808, a plurality of potential shapes are identified and / or generated. In some embodiments, these shapes may be identified and / or generated based on one or more of a valuation strategy and transition asset metadata. In some embodiments, potential shapes may be identified from one or more databases of shapes.
[0202] At block 810, compatibility of potential shapes is evaluated. In some embodiments, this evaluation includes evaluating migration asset metadata to determine compatibility of the migration asset with the destination environment, and particularly with the CSPI 604 to which the migration asset is being migrated. In some embodiments, compatibility may be based on, for example, software compatibility, hardware compatibility, network compatibility, memory compatibility, etc.
[0203] In some embodiments, this evaluation may include obtaining and / or generating compatibility information by asset type and setting and / or generating a compatibility score. In some embodiments, the compatibility score may characterize the compatibility of the potential shape with the source asset. In particular, this characterization may include generating compatibility by asset type. This characterization may include analyzing the compatibility of each VM to be migrated with the destination environment, and in particular with the CSPI 604 to which the VM is being migrated. In some embodiments, analyzing compatibility may include generating one or more warnings and / or errors if one or more incompatibilities are identified.
[0204] In some embodiments, assessing compatibility may include obtaining a compatibility index by asset type. The compatibility index may be retrieved from a database stored in memory. In some embodiments, the compatibility index may characterize differences between capabilities of the source environment and the destination environment. For example, in some embodiments, the compatibility index may identify one or more capabilities of the source environment that may not be available in the destination environment. For example, in some embodiments, the source environment may include one or more CPUs and / or GPUs that may not be available in the destination environment.
[0205] Evaluating compatibility may further include establishing a compatibility score. The compatibility score, in some embodiments, may be stored in a database in memory. In some embodiments, the compatibility score may be stored in different databases corresponding to different asset types. For example, in one embodiment, an asset may include one or more VMs and / or one or more databases. In such an embodiment, the compatibility score may be stored in a first database for the VMs and in a second database for the databases.
[0206] In some embodiments, when an asset is selected, an associated database of compatibility scores for the asset may be identified. The associated database may be queried to determine whether an exact match exists between the asset and a compatibility score in the associated database. If an exact match is determined to exist, the compatibility score associated with the exact match may be returned. Alternatively, if it is determined that an exact match does not exist, "unknown" may be returned for the capability score. Alternatively, as opposed to identifying an exact match, in some embodiments, a best and / or closest match may be identified between the selected asset and information contained in the associated database. In such embodiments, the compatibility score of the best match may be returned.
[0207] In some embodiments, a compatibility score may be generated. This generation may be in response to not finding an exact match and / or a sufficiently close match. In such embodiments, the compatibility score may be generated based on information contained in an associated database. This generation may include, for example, identifying one or more close compatibility scores and generating one or more compatibility scores based on these close scores. Alternatively, in such embodiments, the compatibility score may be generated by incorporating one or more attributes of the selected asset into a model, such as, for example, a decision tree model, a machine learning model, Euclidean distance between vectors, a DB filter, or the like, which may output a compatibility score.
[0208] In some embodiments, establishing the compatibility score may include generating a list of warnings and / or incompatibilities between the source environment and the destination environment and / or providing the list of warnings and / or incompatibilities to a user, as shown in step 812. In some embodiments, this step may include identifying one or more incompatibilities in the information provided to the user, and in some embodiments, this step may further include identifying one or more steps to mitigate one or more of the one or more incompatibilities. In some embodiments, the list of incompatibilities may further identify the severity of each incompatibility. In some embodiments, the severity of the incompatibility may be determined based on one or more rules indicating the severity of the incompatibility. In some embodiments, these rules may include a list of absolute incompatibilities. As used herein, an absolute incompatibility is an incompatibility that prevents an asset from operating in the destination environment. In some embodiments, an absolute incompatibility may arise from software, hardware, etc. In some embodiments, the list of warnings and / or incompatibilities may be provided to a user and / or stored in a database.
[0209] In some embodiments, the compatibility score may include a value from a range of values. In some embodiments, for example, the compatibility score may include a value selected from a range of 0-100, and particularly, a value selected from 0%-100%, with higher values indicating a higher level of compatibility. In some embodiments, each identified warning and / or incompatibility may be combined to form a compatibility score. In some embodiments, some or all of the identified warnings and / or incompatibilities may be associated with a value that may be within the range of values of the incompatibility score. This associated value may be stored in a database. In some embodiments, after the warnings and / or incompatibilities are identified, one or more values may be retrieved for each identified warning and / or incompatibility.
[0210] In some embodiments, these values may be combined to generate a compatibility score. In some embodiments, these values associated with warnings and / or incompatibilities may be evaluated, and one of the values may be selected as representing the combined compatibility score. In some embodiments, this selection may include selecting the lowest value associated with one of the warnings and / or incompatibilities as representative of the overall compatibility score.
[0211] In some embodiments, warnings and / or incompatibilities with low scores, such as a 0% compatibility score, include, for example, when CSPI 604 does not include memory, such as a disk, with the required throughput and / or input / output operations per second (IOPS), when CSPI 604 is unable to provide and / or create the required size, and / or when CSPI 604 is unable to provide and / or create a shape that includes the required hardware components, such as a required GPU. In some embodiments, a 0% compatibility score may be provided if an asset, which may be, for example, a VM and / or database, relies on hardware or software that is not currently supported by CSPI 604. The configured OS, patch, and hardware combination is given the remainder of the score, ranging from 0% to 100%. A score is set to "Unknown" if there is "insufficient data to set a score."
[0212] In some embodiments, based on the compatibility score, an asset specified using the shouldMigrate flag may be further specified as either "true" or "false." In some embodiments, an asset may be specified as "true" so that the asset may be migrated if the compatibility score is high enough, or in other words, if a sufficiently small number of incompatibilities are identified. In some embodiments, an asset may be specified as "false" so that the asset may not be migrated if the compatibility score is not high enough, or in other words, if incompatibilities above a threshold are identified.
[0213] At step 814, fully compatible and / or partially compatible shapes are selected. In some embodiments, a shape may be fully compatible if no compatibility errors and / or warnings are generated. In some embodiments, a partially compatible shape may be a shape that does not have absolute incompatibility and has a compatibility score high enough to indicate operability. In some embodiments, a partially compatible shape may be partially incompatible with assets in the source environment. In some embodiments, fully compatible and / or partially compatible shapes may be associated with a shouldMigrate flag specified as "true."
[0214] At step 816, a cost is determined for one or more of the shapes. In some embodiments, costs may be determined for some or all of the selected shapes, or in other words, for the selected fully compatible and / or partially compatible shapes. In some embodiments, costs may be determined based on attributes of the shapes, such as, for example, the number, type, and / or capabilities of CPUs, GPUs, amount of memory, bandwidth, etc. In some embodiments, cost estimates may be broken down into categories including compute, storage, and licensing. In some embodiments, compute costs may be based on shape attributes related to the shape's CPU, GPU, and / or memory. In some embodiments, storage costs may be associated with block storage, and licensing costs may be associated with software used in connection with the shapes.
[0215] The selected shapes may be ordered according to cost and / or compatibility in optional step 818. In some embodiments, this step may include selecting one or more shapes with the highest compatibility and / or lowest cost.
[0216] In step 820, one or more shapes are presented to the user. In some embodiments, this step may include presenting the shapes ordered by rank. In some embodiments, this step may include presenting one or more shapes with the highest compatibility score. In some embodiments where multiple shapes have the same compatibility score, the shape with the highest compatibility score and lowest cost may be presented.
[0217] In some embodiments, step 820 may include presenting one or more shapes to the user and providing information to the user that identifies a price for the presented one or more shapes and includes a description of the one or more presented shapes, which may characterize key attributes of the one or more presented shapes. In some embodiments, the user may select one of the one or more presented shapes, may change one of the presented one or more shapes, and / or may request the presentation of another one or more shapes.
[0218] When a user selects one of the shapes, a terraform stack of the selected shape may be generated based on the selection. When a user changes a shape, a terraform stack may be generated based on the changed shape after the shape change. When a user requests the presentation of another shape, a list of remaining possible shapes may be presented and / or one or more other shapes may be presented to the user. At this point, the user may accept one of the presented shapes, change one of the presented shapes, or request the presentation of additional shapes. These outlined steps may continue until the user selects a shape, at which point a terraform stack may be generated from the selected shape.
[0219] Exemplary System As mentioned above, infrastructure as a service (IaaS) is a specific type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, an IaaS provider may also offer various services incidental to those infrastructure components (example services include billing software, monitoring software, logging software, load balancing software, clustering software, etc.). Accordingly, these services can be policy-driven, allowing IaaS users to implement policies to drive load balancing and maintain application availability and performance.
[0220] In some cases, IaaS users may access resources and services over a wide area network (WAN), such as the Internet, and can use the cloud provider's services to install the remaining elements of their application stack. For example, a user may log in to an IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as a database, create storage buckets for workloads and backups, and even install enterprise software on the VMs. The user can then use the provider's services to perform a variety of functions, including balancing network traffic, troubleshooting application issues, monitoring performance, managing disaster recovery, etc.
[0221] In most cases, the cloud computing model requires the participation of a cloud provider. A cloud provider may be, but need not be, a third-party service that specializes in providing (e.g., offering, renting, selling) IaaS. An entity may choose to deploy a private cloud and become its own provider of infrastructure services. In some examples, IaaS deployment is the process of connecting a new application or a new version of an application to a prepared application server or the like. This process may include the process of preparing the server (e.g., installing libraries, daemons, etc.). This process is often managed by the cloud provider below the hypervisor layer (e.g., server, storage, network hardware, and virtualization). Thus, the user may be responsible for handling the deployment of the OS, middleware, and / or application (e.g., on top of self-service virtual machines (e.g., that can be spun up on demand)).
[0222] In some examples, IaaS provisioning may also refer to obtaining computers or virtual hosts for use and installing needed libraries or services on those computers or virtual hosts. In most cases, deployment does not include provisioning, which may need to be performed first.
[0223] In some cases, IaaS provisioning presents two distinct challenges. First, there is the initial challenge of provisioning an initial set of infrastructure before anything can be run. Second, there is the challenge of evolving the existing infrastructure (e.g., adding new services, modifying services, removing services, etc.) after everything has been provisioned. In some cases, these two challenges may be addressed by allowing the configuration of the infrastructure to be defined declaratively. In other words, the infrastructure (e.g., which components are needed and how those components interact) may be defined by one or more configuration files. In this way, the entire topology of the infrastructure (e.g., which resources depend on which resources and how each of those resources works together) may be described declaratively. In some cases, after the topology is defined, workflows may be generated to create and / or manage the various components described in the configuration files.
[0224] In some examples, the infrastructure may include many interconnected elements. For example, there may be one or more virtual private clouds (VPCs) (e.g., configurable and / or shared, possibly on-demand pools of computing resources), also known as a core network. In some examples, there may also be one or more inbound / outbound traffic group rules, as well as one or more virtual machines (VMs), provisioned to define how the network's inbound and / or outbound traffic is configured. Other infrastructure elements, such as load balancers, databases, etc., may also be provisioned. The infrastructure can evolve over time as more infrastructure elements are desired and / or added.
[0225] In some cases, continuous deployment techniques may be employed to enable deployment of infrastructure code across various virtual computing environments. Additionally, the described techniques may enable infrastructure management within these environments. In some examples, a service team may write code that is desired to be deployed to one or more, but often many, different production environments (e.g., across various geographic locations, sometimes across the world). However, in some examples, the infrastructure onto which the code will be deployed must first be set up. In some cases, provisioning can be done manually, and provisioning tools may be utilized to provision the resources and / or deployment tools may be utilized to deploy the code after the infrastructure has been provisioned.
[0226] 11 is a block diagram 1100 illustrating an example pattern of an IaaS architecture according to at least one embodiment. A service operator 1102 may be communicatively coupled to a secure host tenancy 1104, which may include a virtual cloud network (VCN) 1106 and a secure host subnet 1108. In some examples, the service operator 1102 may employ one or more client computing devices, which may be portable handheld devices (e.g., iPhones, mobile phones, iPads, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., Google Glass head-mounted displays) that are Internet, email, short message service (SMS), Blackberry, or other communication protocol enabled, running software such as Microsoft Windows Mobile, and / or various mobile operating systems such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, etc. Alternatively, the client computing devices may be general-purpose personal computers, including, by way of example, personal and / or laptop computers running various versions of the Microsoft Windows, Apple Macintosh, and / or Linux operating systems. The client computing devices may be workstation computers running any of a variety of commercially available UNIX or UNIX-like operating systems, including, but not limited to, various GNU / Linux operating systems, such as Google Chrome OS.Alternatively or additionally, the client computing device may be any other electronic device, such as a thin client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox gaming console with or without a Kinect® gesture input device), and / or a personal messaging device, that can communicate over a network accessible to VCN 1106 and / or the Internet.
[0227] VCN 1106 may include a local peering gateway (LPG) 1110, which may be communicatively coupled to a secure shell (SSH) VCN 1112 via an LPG 1110 included in SSH VCN 1112. SSH VCN 1112 may include an SSH subnet 1114, which may be communicatively coupled to a control plane VCN 1116 via an LPG 1110 included in control plane VCN 1116. SSH VCN 1112 may also be communicatively coupled to a data plane VCN 1118 via LPG 1110. The control plane VCN 1116 and the data plane VCN 1118 may be included in a service tenancy 1119, which may be owned and / or operated by the IaaS provider.
[0228] The control plane VCN 1116 may include a control plane demilitarized zone (DMZ) tier 1120 that serves as a perimeter network (e.g., a portion of an enterprise network between the enterprise intranet and an external network). Servers based in the DMZ may have limited responsibility and help keep breaches contained. Additionally, the DMZ tier 1120 may include one or more load balancer (LB) subnets 1122, a control plane app tier 1124 that may include an app subnet 1126, and a control plane data tier 1128 that may include a database (DB) subnet 1130 (e.g., a front-end DB subnet and / or a back-end DB subnet). The LB subnet 1122 included in the control plane DMZ tier 1120 can be communicatively coupled to an app subnet 1126 and an Internet gateway 1134 included in the control plane app tier 1124, which may be included in the control plane VCN 1116, and the app subnet 1126 can be communicatively coupled to a DB subnet 1130 included in the control plane data tier 1128, as well as a service gateway 1136 and a network address translation (NAT) gateway 1138. The control plane VCN 1116 can include the service gateway 1136 and the NAT gateway 1138.
[0229] The control plane VCN 1116 can include a data plane mirror app layer 1140, which can include an app subnet 1126. The app subnet 1126 included in the data plane mirror app layer 1140 can include a virtual network interface controller (VNIC) 1142, which can run a compute instance 1144. The compute instance 1144 can communicatively couple the app subnet 1126 of the data plane mirror app layer 1140 to the app subnet 1126, which can be included in the data plane app layer 1146.
[0230] The data plane VCN 1118 may include a data plane app layer 1146, a data plane DMZ layer 1148, and a data plane data layer 1150. The data plane DMZ layer 1148 may include a LB subnet 1122, which may be communicatively coupled to an app subnet 1126 of the data plane app layer 1146 and an Internet gateway 1134 of the data plane VCN 1118. The app subnet 1126 may be communicatively coupled to a service gateway 1136 of the data plane VCN 1118 and a NAT gateway 1138 of the data plane VCN 1118. The data plane data layer 1150 may also include a DB subnet 1130, which may be communicatively coupled to the app subnet 1126 of the data plane app layer 1146.
[0231] The internet gateways 1134 of the control plane VCN 1116 and of the data plane VCN 1118 may be communicatively coupled to a metadata management service 1152, which may be communicatively coupled to the public internet 1154. The public internet 1154 may be communicatively coupled to NAT gateways 1138 of the control plane VCN 1116 and of the data plane VCN 1118. The service gateways 1136 of the control plane VCN 1116 and of the data plane VCN 1118 may be communicatively coupled to cloud services 1156.
[0232] In some examples, a service gateway 1136 in the control plane VCN 1116 or in the data plane VCN 1118 can make application programming interface (API) calls to a cloud service 1156 without traversing the public internet 1154. The API calls from the service gateway 1136 to the cloud service 1156 can be one-way: the service gateway 1136 can make the API call to the cloud service 1156, and the cloud service 1156 can send the requested data to the service gateway 1136. However, the cloud service 1156 need not initiate the API call to the service gateway 1136.
[0233] In some examples, secure host tenancy 1104 can be directly connected to service tenancy 1119 or may be otherwise separate. Secure host subnet 1108 can communicate with SSH subnet 1114 through LPG 1110, which can enable bidirectional communication on otherwise separate systems. Connecting secure host subnet 1108 to SSH subnet 1114 may give secure host subnet 1108 access to other entities within service tenancy 1119.
[0234] The control plane VCN 1116 may enable users of the service tenancy 1119 to configure or otherwise provision desired resources. The desired resources provisioned in the control plane VCN 1116 may be deployed or otherwise used in the data plane VCN 1118. In some examples, the control plane VCN 1116 may be separate from the data plane VCN 1118, and the data plane mirror app layer 1140 of the control plane VCN 1116 may communicate with the data plane app layer 1146 of the data plane VCN 1118 via a VNIC 1142, which may be included in the data plane mirror app layer 1140 and the data plane app layer 1146.
[0235] In some examples, a user or users of the system may make a request, for example, a create, read, update, or delete (CRUD) operation, via the public Internet 1154, which may communicate the request to a metadata management service 1152. The metadata management service 1152 may communicate the request to the control plane VCN 1116 via an Internet gateway 1134. The request may be received by a LB subnet 1122 included in the control plane DMZ tier 1120. The LB subnet 1122 may determine that the request is valid, and in response to this determination, the LB subnet 1122 may send the request to an app subnet 1126 included in the control plane app tier 1124. If the validity of the request is confirmed and the request requires a call to the public Internet 1154, the call to the public Internet 1154 may be sent to a NAT gateway 1138, which may make the call to the public Internet 1154. Metadata that may be desirable to store with the request may be stored within the DB subnet 1130.
[0236] In some examples, the data plane mirror app layer 1140 can facilitate direct communication between the control plane VCN 1116 and the data plane VCN 1118. For example, it may be desirable for changes, updates, or other appropriate modifications to the configuration to be applied to resources included in the data plane VCN 1118. Via the VNIC 1142, the control plane VCN 1116 communicates directly with the resources included in the data plane VCN 1118, thereby enabling the control plane VCN 1116 to perform changes, updates, or other appropriate modifications to the configuration of the resources.
[0237] In some embodiments, the control plane VCN 1116 and the data plane VCN 1118 may be included in the service tenancy 1119. In this case, a user or users of the system may not own or operate either the control plane VCN 1116 or the data plane VCN 1118. Instead, an IaaS provider may own or operate the control plane VCN 1116 and the data plane VCN 1118, which may both be included in the service tenancy 1119. This embodiment may enable network isolation that can prevent a user or users from interacting with other users' resources or with other users' resources. This embodiment may also allow a user or users of the system to store databases privately without having to rely on the public internet 1154 for storage, which may not have a desirable level of threat protection.
[0238] In another embodiment, the LB subnet 1122 included in the control plane VCN 1116 may be configured to receive signals from the service gateway 1136. In this embodiment, the control plane VCN 1116 and the data plane VCN 1118 may be configured to be called by users of the IaaS provider without calling the public Internet 1154. Users of the IaaS provider may desire this embodiment because the databases they use may be stored in a service tenancy 1119 that may be controlled by the IaaS provider and isolated from the public Internet 1154.
[0239] 12 is a block diagram 1200 illustrating another exemplary pattern of an IaaS architecture, according to at least one embodiment. A service operator 1202 (e.g., service operator 1102 in FIG. 11 ) may be communicatively coupled to a secure host tenancy 1204 (e.g., secure host tenancy 1104 in FIG. 11 ), which may include a virtual cloud network (VCN) 1206 (e.g., VCN 1106 in FIG. 11 ) and a secure host subnet 1208 (e.g., secure host subnet 1108 in FIG. 11 ). VCN 1206 may include a local peering gateway (LPG) 1210 (e.g., LPG 1110 in FIG. 11 ), which may be communicatively coupled to a secure shell (SSH) VCN 1212 (e.g., SSH VCN 1112 in FIG. 11 ) via an LPG 1110 included in an SSH VCN 1212. SSH VCN 1212 can include SSH subnet 1214 (e.g., SSH subnet 1114 in FIG. 11 ), and SSH VCN 1212 can be communicatively coupled to control plane VCN 1216 (e.g., control plane VCN 1116 in FIG. 11 ) via LPG 1210 included in control plane VCN 1216. Control plane VCN 1216 can be included in service tenancy 1219 (e.g., service tenancy 1119 in FIG. 11 ), and data plane VCN 1218 (e.g., data plane VCN 1118 in FIG. 11 ) can be included in user tenancy 1221, which can be owned or operated by a user or users of the system.
[0240] The control plane VCN 1216 may include a control plane DMZ layer 1220 (e.g., the control plane DMZ layer 1120 of FIG. 11 ) that may include a LB subnet 1222 (e.g., the LB subnet 1122 of FIG. 11 ), a control plane app layer 1224 (e.g., the control plane app layer 1124 of FIG. 11 ) that may include an app subnet 1226 (e.g., the app subnet 1126 of FIG. 11 ), and a control plane data layer 1228 (e.g., the control plane data layer 1128 of FIG. 11 ) that may include a database (DB) subnet 1230 (e.g., similar to the database (DB) subnet 1130 of FIG. 11 ). LB subnet 1222 included in control plane DMZ tier 1220 can be communicatively coupled to app subnet 1226 included in control plane app tier 1224, which may be included in control plane VCN 1216, and to Internet gateway 1234 (e.g., Internet gateway 1134 in FIG. 11 ), and app subnet 1226 can be communicatively coupled to DB subnet 1230 included in control plane data tier 1228, as well as to service gateway 1236 (e.g., service gateway 1136 in FIG. 11 ) and network address translation (NAT) gateway 1238 (e.g., NAT gateway 1138 in FIG. 11 ). Control plane VCN 1216 can include service gateway 1236 and NAT gateway 1238.
[0241] Control plane VCN 1216 can include a data plane mirror app layer 1240 (e.g., data plane mirror app layer 1140 of FIG. 11 ), which can include an app subnet 1226. App subnet 1226 included in data plane mirror app layer 1240 can include a virtual network interface controller (VNIC) 1242 (e.g., VNIC 1142) that can run compute instance 1244 (e.g., similar to compute instance 1144 of FIG. 11 ). Compute instance 1244 can facilitate communication between app subnet 1226 of data plane mirror app layer 1240 and app subnet 1226 that can be included in data plane app layer 1246 (e.g., data plane app layer 1146 of FIG. 11 ) via VNIC 1242 included in data plane mirror app layer 1240 and VNIC 1242 included in data plane app layer 1246.
[0242] An internet gateway 1234 included in the control plane VCN 1216 may be communicatively coupled to a metadata management service 1252 (e.g., metadata management service 1152 of FIG. 11 ), which may be communicatively coupled to a public internet 1254 (e.g., public internet 1154 of FIG. 11 ). The public internet 1254 may be communicatively coupled to a NAT gateway 1238 included in the control plane VCN 1216. A service gateway 1236 included in the control plane VCN 1216 may be communicatively coupled to a cloud service 1256 (e.g., cloud service 1156 of FIG. 11 ).
[0243] In some examples, data plane VCN 1218 may be included in user tenancy 1221. In this case, the IaaS provider may provide a control plane VCN 1216 for each user, and the IaaS provider may configure a unique compute instance 1244 for each user that is included in service tenancy 1219. Each compute instance 1244 may enable communication between the control plane VCN 1216 included in service tenancy 1219 and the data plane VCN 1218 included in user tenancy 1221. The compute instance 1244 may enable resources provisioned in the control plane VCN 1216 included in service tenancy 1219 to be deployed or otherwise used in the data plane VCN 1218 included in user tenancy 1221.
[0244] In another example, a user of the IaaS provider may have a database that resides in the user's tenancy 1221. In this example, control plane VCN 1216 may include a data plane mirror app tier 1240, which may include app subnet 1226. The data plane mirror app tier 1240 may reside in data plane VCN 1218, but the data plane mirror app tier 1240 may not reside in data plane VCN 1218. That is, while the data plane mirror app tier 1240 may have access to the user's tenancy 1221, the data plane mirror app tier 1240 may not reside in data plane VCN 1218 and may not be owned or operated by the IaaS provider's user. The data plane mirror app tier 1240 may be configured to make calls to the data plane VCN 1218, but may not be configured to make calls to any entities included in the control plane VCN 1216. A user may desire to deploy or otherwise use resources in the data plane VCN 1218 that have been provisioned in the control plane VCN 1216, and the data plane mirror app layer 1240 can facilitate the desired deployment or other use of the user's resources.
[0245] In some embodiments, a user of the IaaS provider can apply filters to the data plane VCN 1218. In this embodiment, the user can determine which data plane VCNs 1218 are accessible, and the user may restrict access from the data plane VCN 1218 to the public internet 1254. The IaaS provider may not be able to apply filters or otherwise control the access of the data plane VCN 1218 to any external networks or databases. Applying filters and controls by the user to the data plane VCN 1218 included in the user's tenancy 1221 can help to isolate the data plane VCN 1218 from other users and from the public internet 1254.
[0246] In some embodiments, cloud services 1256 may be called by service gateway 1236 to access services that may not reside on public internet 1254, control plane VCN 1216, or data plane VCN 1218. The connection between cloud services 1256 and control plane VCN 1216 or data plane VCN 1218 may not be up and running or continuous. Cloud services 1256 may reside on different networks owned or operated by the IaaS provider. Cloud services 1256 may be configured to receive calls from service gateway 1236 and may not be configured to receive calls from public internet 1254. Some cloud services 1256 may be isolated from other cloud services 1256, and control plane VCN 1216 may be isolated from cloud services 1256 that may not be in the same region as control plane VCN 1216. For example, control plane VCN 1216 may be located in "Region 1," and cloud service "Deployment 11" may be located in Region 1 and Region 2. If a call to deployment 11 is made by service gateway 1236 included in control plane VCN 1216 located in Region 1, the call may be sent to deployment 11 in Region 1. In this example, control plane VCN 1216, or deployment 11 in Region 1, may not be communicatively coupled to or otherwise in communication with deployment 11 in Region 2.
[0247] 13 is a block diagram 1300 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 1302 (e.g., service operator 1102 in FIG. 11 ) may be communicatively coupled to a secure host tenancy 1304 (e.g., secure host tenancy 1104 in FIG. 11 ), which may include a virtual cloud network (VCN) 1306 (e.g., VCN 1106 in FIG. 11 ) and a secure host subnet 1308 (e.g., secure host subnet 1108 in FIG. 11 ). VCN 1306 may include an LPG 1310 (e.g., LPG 1110 in FIG. 11 ), which may be communicatively coupled to an SSH VCN 1312 (e.g., SSH VCN 1112 in FIG. 11 ) via an LPG 1310 included in SSH VCN 1312. SSH VCN 1312 can include SSH subnet 1314 (e.g., SSH subnet 1114 in FIG. 11 ), and SSH VCN 1312 can be communicatively coupled to control plane VCN 1316 (e.g., control plane VCN 1116 in FIG. 11 ) via LPG 1310 included in control plane VCN 1316, and to data plane VCN 1318 (e.g., data plane 1118 in FIG. 11 ) via LPG 1310 included in data plane VCN 1318. Control plane VCN 1316 and data plane VCN 1318 can be included in service tenancy 1319 (e.g., service tenancy 1119 in FIG. 11 ).
[0248] The control plane VCN 1316 may include a control plane DMZ tier 1320 (e.g., the control plane DMZ tier 1120 of FIG. 11 ) that may include a load balancer (LB) subnet 1322 (e.g., the LB subnet 1122 of FIG. 11 ), a control plane app tier 1324 (e.g., the control plane app tier 1124 of FIG. 11 ) that may include an app subnet 1326 (e.g., similar to the app subnet 1126 of FIG. 11 ), and a control plane data tier 1328 (e.g., the control plane data tier 1128 of FIG. 11 ) that may include a DB subnet 1330. LB subnet 1322 included in control plane DMZ tier 1320 can be communicatively coupled to app subnet 1326 included in control plane app tier 1324, which may be included in control plane VCN 1316, and to an Internet gateway 1334 (e.g., Internet gateway 1134 in FIG. 11 ), and app subnet 1326 can be communicatively coupled to DB subnet 1330 included in control plane data tier 1328, as well as to service gateway 1336 (e.g., service gateway in FIG. 11 ) and network address translation (NAT) gateway 1338 (e.g., NAT gateway 1138 in FIG. 11 ). Control plane VCN 1316 can include service gateway 1336 and NAT gateway 1338.
[0249] Data plane VCN 1318 may include a data plane app layer 1346 (e.g., data plane app layer 1146 in FIG. 11 ), a data plane DMZ layer 1348 (e.g., data plane DMZ layer 1148 in FIG. 11 ), and a data plane data layer 1350 (e.g., data plane data layer 1150 in FIG. 11 ). Data plane DMZ layer 1348 may include a trusted app subnet 1360 and an untrusted app subnet 1362 of data plane app layer 1346 and an LB subnet 1322 that may be communicatively coupled to an Internet gateway 1334 included in data plane VCN 1318. Trusted app subnet 1360 may be communicatively coupled to a service gateway 1336 included in data plane VCN 1318, a NAT gateway 1338 included in data plane VCN 1318, and a DB subnet 1330 included in data plane data layer 1350. The untrusted app subnet 1362 may be communicatively coupled to a service gateway 1336 included in the data plane VCN 1318 and to a DB subnet 1330 included in the data plane data layer 1350. The data plane data layer 1350 may include a DB subnet 1330 that may be communicatively coupled to a service gateway 1336 included in the data plane VCN 1318.
[0250] The untrusted app subnet 1362 may include one or more primary VNICs 1364(1)-(N), which may be communicatively coupled to tenant virtual machines (VMs) 1366(1)-(N). Each tenant VM 1366(1)-(N) may be communicatively coupled to a respective app subnet 1367(1)-(N), which may be included in a respective container egress VCN 1368(1)-(N), which may be included in a respective user's tenancy 1370(1)-(N). Each secondary VNIC 1372(1)-(N) may facilitate communication between the untrusted app subnet 1362 included in the data plane VCN 1318 and the app subnet included in the container egress VCN 1368(1)-(N). Each container egress VCN 1368(1)-(N) may include a NAT gateway 1338, which may be communicatively coupled to the public internet 1354 (e.g., public internet 1154 in FIG. 11 ).
[0251] An internet gateway 1334 included in the control plane VCN 1316 and included in the data plane VCN 1318 may be communicatively coupled to a metadata management service 1352 (e.g., metadata management system 1152 of FIG. 11 ), which may be communicatively coupled to the public internet 1354. The public internet 1354 may be communicatively coupled to a NAT gateway 1338 included in the control plane VCN 1316 and included in the data plane VCN 1318. A service gateway 1336 included in the control plane VCN 1316 and included in the data plane VCN 1318 may be communicatively coupled to cloud services 1356.
[0252] In some embodiments, data plane VCN 1318 may be integrated with a user's tenancy 1370. This integration may be useful or desirable for an IaaS provider's user in some cases, such as when they may want support when executing code. A user may provide code for execution that may be destructive, may communicate with other users' resources, or may otherwise cause undesirable effects. In response, the IaaS provider may determine whether to execute the code provided to the IaaS provider by the user.
[0253] In some examples, a user of an IaaS provider may grant temporary network access to the IaaS provider and request functionality connected to the data plane app layer 1346. Code to perform this functionality may run in VMs 1366(1)-(N), and this code may not be configured to run elsewhere on the data plane VCN 1318. Each VM 1366(1)-(N) may be connected to one user's tenancy 1370. Each container 1371(1)-(N) contained in a VM 1366(1)-(N) may be configured to run code. In this case, double isolation may exist (e.g., containers 1371(1)-(N) running code may be contained in at least VMs 1366(1)-(N) that are included in untrusted app subnet 1362), which may help prevent incorrect or otherwise unwanted code from damaging the IaaS provider's network or damaging a different user's network. Containers 1371(1)-(N) may be communicatively coupled to a user's tenancy 1370 and may be configured to send or receive data to or from the user's tenancy 1370. Containers 1371(1)-(N) may not be configured to send or receive data to or from any other entities in data plane VCN 1318. Upon completion of code execution, the IaaS provider may kill or otherwise destroy containers 1371(1)-(N).
[0254] In some embodiments, trusted app subnet 1360 may execute code that may be owned or operated by the IaaS provider. In this embodiment, trusted app subnet 1360 may be communicatively coupled to DB subnet 1330 and may be configured to perform CRUD operations within DB subnet 1330. Untrusted app subnet 1362 may be communicatively coupled to DB subnet 1330, but in this embodiment, the untrusted app subnet may be configured to perform read operations within DB subnet 1330. Containers 1371(1)-(N) that can execute code from users, which may be included in each user's VMs 1366(1)-(N), may not be communicatively coupled to DB subnet 1330.
[0255] In other embodiments, the control plane VCN 1316 and the data plane VCN 1318 may not be directly communicatively coupled. In this embodiment, there may not be direct communication between the control plane VCN 1316 and the data plane VCN 1318. However, communication can occur indirectly through at least one method. The LPG 1310 may be established by an IaaS provider and can facilitate communication between the control plane VCN 1316 and the data plane VCN 1318. In another example, the control plane VCN 1316 or the data plane VCN 1318 can make a call to a cloud service 1356 via the service gateway 1336. For example, a call from the control plane VCN 1316 to the cloud service 1356 can include a request for a service that can communicate with the data plane VCN 1318.
[0256] 14 is a block diagram 1400 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 1402 (e.g., service operator 1102 in FIG. 11 ) may be communicatively coupled to a secure host tenancy 1404 (e.g., secure host tenancy 1104 in FIG. 11 ), which may include a virtual cloud network (VCN) 1406 (e.g., VCN 1106 in FIG. 11 ) and a secure host subnet 1408 (e.g., secure host subnet 1108 in FIG. 11 ). VCN 1406 may include an LPG 1410 (e.g., LPG 1110 in FIG. 11 ), which may be communicatively coupled to an SSH VCN 1412 (e.g., SSH VCN 1112 in FIG. 11 ) via an LPG 1410 included in SSH VCN 1412. SSH VCN 1412 can include SSH subnet 1414 (e.g., SSH subnet 1114 in FIG. 11 ), and SSH VCN 1412 can be communicatively coupled to control plane VCN 1416 (e.g., control plane VCN 1116 in FIG. 11 ) via LPG 1410 included in control plane VCN 1416, and to data plane VCN 1418 (e.g., data plane 1118 in FIG. 11 ) via LPG 1410 included in data plane VCN 1418. Control plane VCN 1416 and data plane VCN 1418 can be included in service tenancy 1419 (e.g., service tenancy 1119 in FIG. 11 ).
[0257] The control plane VCN 1416 may include a control plane DMZ layer 1420 (e.g., control plane DMZ layer 1120 in FIG. 11 ) that may include a LB subnet 1422 (e.g., LB subnet 1122 in FIG. 11 ), a control plane app layer 1424 (e.g., control plane app layer 1124 in FIG. 11 ) that may include an app subnet 1426 (e.g., app subnet 1126 in FIG. 11 ), and a control plane data layer 1428 (e.g., control plane data layer 1128 in FIG. 11 ) that may include a DB subnet 1430 (e.g., DB subnet 1330 in FIG. 13 ). LB subnet 1422 included in control plane DMZ tier 1420 can be communicatively coupled to app subnet 1426 included in control plane app tier 1424, which may be included in control plane VCN 1416, and to an Internet gateway 1434 (e.g., Internet gateway 1134 in FIG. 11 ), and app subnet 1426 can be communicatively coupled to DB subnet 1430 included in control plane data tier 1428, as well as to service gateway 1436 (e.g., service gateway in FIG. 11 ) and network address translation (NAT) gateway 1438 (e.g., NAT gateway 1138 in FIG. 11 ). Control plane VCN 1416 can include service gateway 1436 and NAT gateway 1438.
[0258] Data plane VCN 1418 may include a data plane app layer 1446 (e.g., data plane app layer 1146 in FIG. 11 ), a data plane DMZ layer 1448 (e.g., data plane DMZ layer 1148 in FIG. 11 ), and a data plane data layer 1450 (e.g., data plane data layer 1150 in FIG. 11 ). Data plane DMZ layer 1448 may include trusted app subnet 1460 (e.g., trusted app subnet 1360 in FIG. 13 ) and untrusted app subnet 1462 (e.g., untrusted app subnet 1362 in FIG. 13 ) of data plane app layer 1446, as well as LB subnet 1422, which may be communicatively coupled to an Internet gateway 1434 included in data plane VCN 1418. Trusted app subnet 1460 may be communicatively coupled to service gateway 1436 included in data plane VCN 1418, NAT gateway 1438 included in data plane VCN 1418, and DB subnet 1430 included in data plane data layer 1450. Untrusted app subnet 1462 may be communicatively coupled to service gateway 1436 included in data plane VCN 1418 and DB subnet 1430 included in data plane data layer 1450. Data plane data layer 1450 may include DB subnet 1430, which may be communicatively coupled to service gateway 1436 included in data plane VCN 1418.
[0259] The untrusted app subnet 1462 may include primary VNICs 1464(1)-(N), which may be communicatively coupled to tenant virtual machines (VMs) 1466(1)-(N) residing in the untrusted app subnet 1462. Each tenant VM 1466(1)-(N) may execute code in a respective container 1467(1)-(N) and may be communicatively coupled to an app subnet 1426, which may be included in a data plane app layer 1446, which may be included in a container egress VCN 1468. Each secondary VNIC 1472(1)-(N) may facilitate communication between the untrusted app subnet 1462, which is included in the data plane VCN 1418, and the app subnet included in the container egress VCN 1468. The container egress VCN may include a NAT gateway 1438, which may be communicatively coupled to the public internet 1454 (e.g., public internet 1154 in FIG. 11 ).
[0260] An internet gateway 1434 included in the control plane VCN 1416 and included in the data plane VCN 1418 may be communicatively coupled to a metadata management service 1452 (e.g., metadata management system 1152 of FIG. 11 ), which may be communicatively coupled to the public internet 1454. The public internet 1454 may be communicatively coupled to a NAT gateway 1438 included in the control plane VCN 1416 and included in the data plane VCN 1418. A service gateway 1436 included in the control plane VCN 1416 and included in the data plane VCN 1418 may be communicatively coupled to cloud services 1456.
[0261] In some examples, the pattern illustrated by the architecture of block diagram 1400 in FIG. 14 may be considered an exception to the pattern illustrated by the architecture of block diagram 1300 in FIG. 13 and may be desirable for users of an IaaS provider when the IaaS provider cannot communicate directly with the users (e.g., in a disconnected region). Each container 1467(1)-(N) contained in a VM 1466(1)-(N) for each user may be accessed by the user in real time. The containers 1467(1)-(N) may be configured to make calls to each secondary VNIC 1472(1)-(N) contained in the app subnet 1426 of the data plane app layer 1446, which may be included in a container egress VCN 1468. The secondary VNICs 1472(1)-(N) may send the calls to a NAT gateway 1438, which may send the calls to the public Internet 1454. In this example, containers 1467(1)-(N) that may be accessed in real time by users may be isolated from control plane VCN 1416 and may be isolated from other entities included in data plane VCN 1418. Containers 1467(1)-(N) may be isolated from other user resources.
[0262] In another example, a user may use container 1467(1)-(N) to invoke cloud service 1456. In this example, the user may execute code in container 1467(1)-(N) that requests a service from cloud service 1456. Container 1467(1)-(N) may send the request to secondary VNICs 1472(1)-(N), which may send the request to a NAT gateway, which may send the request to public Internet 1454. Public Internet 1454 may send the request via Internet gateway 1434 to LB subnet 1422, which is included in control plane VCN 1416. In response to determining that the request is valid, LB subnet 1426 may send the request to app subnet 1426, which may send the request via service gateway 1436 to cloud service 1456.
[0263] It should be understood that the IaaS architectures 1100, 1200, 1300, 1400 depicted in the figures may include components other than those depicted. Additionally, the depicted embodiments are merely some examples of cloud infrastructure systems that may incorporate embodiments of the present disclosure. In some other embodiments, the IaaS systems may include more or fewer components than those depicted in the figures, may combine two or more components, or may have a different configuration or arrangement of components.
[0264] In one embodiment, the IaaS system described herein may include the offering of a suite of application, middleware, and database services that are delivered to users in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such an IaaS system is Oracle Cloud Infrastructure (OCI), offered by the present assignee.
[0265] 15 illustrates an exemplary computer system 1500 upon which various embodiments may be implemented. System 1500 may be used to implement any of the computer systems described above. As shown, computer system 1500 includes a processing unit 1504 that communicates with multiple peripheral subsystems via a bus subsystem 1502. These peripheral subsystems may include a processing acceleration unit 1506, an I / O subsystem 1508, a storage subsystem 1518, and a communication subsystem 1524. Storage subsystem 1518 includes a tangible computer-readable storage medium 1522 and a system memory 1510.
[0266] Bus subsystem 1502 provides a mechanism for allowing the various components and subsystems of computer system 1500 to communicate with each other as intended. While bus subsystem 1502 is shown schematically as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. Bus subsystem 1502 may be any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures may include an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus, which may be implemented as a mezzanine bus manufactured to the IEEE P1386.1 standard.
[0267] Processing unit 1504, which may be implemented as one or more integrated circuits (e.g., conventional microprocessors or microcontrollers), controls the operation of computer system 1500. One or more processors may be included in processing unit 1504. These processors may include single-core or multi-core processors. In one embodiment, processing unit 1504 may be implemented as one or more independent processing units 1532 and / or 1534, with a single-core or multi-core processor included in each processing unit. In other embodiments, processing unit 1504 may be implemented as a quad-core processing unit formed by integrating two dual-core processors into a single chip.
[0268] In various embodiments, processing unit 1504 may execute various programs according to program code and may maintain multiple simultaneously executing programs or processes. At any particular time, some or all of the program code being executed may reside on processor 1504 and / or on storage subsystem 1518. With appropriate programming, processor 1504 may provide the various functions described above. Computer system 1500 may further include a processing acceleration unit 1506, which may include a digital signal processor (DSP), a special purpose processor, and / or the like.
[0269] The I / O subsystem 1508 may include user interface input devices and user interface output devices. User interface input devices may include a keyboard, a pointing device such as a mouse or trackball, a touchpad or touchscreen integrated into a display, a scroll wheel, a click wheel, a dial, buttons, switches, a keypad, a voice input device with a voice command recognition system, a microphone, and other types of input devices. User interface input devices may include, for example, a motion detection device and / or gesture recognition device, such as a Microsoft Kinect® motion sensor, which allows a user to control and interact with an input device, such as a Microsoft Xbox® 360 game controller, through a natural user interface using gestures and spoken commands. User interface input devices may also include an eye gesture recognition device, such as a Google Glass® blink detector, which detects a user's eye activity (e.g., "blinking" when taking a photo and / or selecting a menu) and translates the eye gesture as input to an input device (e.g., Google Glass®). Additionally, the user interface input devices may include a voice recognition detection device that allows a user to interact with a voice recognition system (e.g., the Siri® navigator) via voice commands.
[0270] User interface input devices may include, but are not limited to, three-dimensional (3D) mice, joysticks or pointing sticks, gamepads, and graphic tablets, as well as audio / visual devices such as speakers, digital cameras, digital video cameras, portable media players, webcams, image scanners, fingerprint scanners, barcode reader 3D scanners, 3D printers, laser range finders, and eye-tracking devices. Additionally, user interface input devices may include medical imaging input devices such as, for example, computed tomography, magnetic resonance imaging, position emission tomography, and medical ultrasound devices. User interface input devices may also include audio input devices such as, for example, MIDI keyboards, digital musical instruments, and the like.
[0271] User interface output devices may include non-visual displays such as a display subsystem, indicator lights, or audio output devices. The display subsystem may be a flat-panel device, such as a flat-panel device using a cathode ray tube (CRT), a liquid crystal display (LCD), or a plasma display, a projection device, a touch screen, or the like. In general, use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from computer system 1500 to a user or to another computer. For example, user interface output devices may include, but are not limited to, various display devices that visually convey textual, graphical, and audio / video information, such as monitors, printers, speakers, headphones, navigation systems, plotters, audio output devices, and modems.
[0272] Computer system 1500 may include a storage subsystem 1518 that provides a tangible, non-transitory, computer-readable storage medium for storing software and data structures that provide the functionality of embodiments described in this disclosure. The software may include programs, code modules, instructions, scripts, etc. that, when executed by one or more cores or processors of processing unit 1504, provide the aforementioned functionality. Storage subsystem 1518 may also provide a repository for storing data used in accordance with the present disclosure.
[0273] 15, storage subsystem 1518 may include various components, including system memory 1510, computer-readable storage medium 1522, and computer-readable storage medium reader 1520. System memory 1510 may store program instructions readable and executable by processing unit 1504. System memory 1510 may also store data used during execution of the instructions and / or data generated during execution of the program instructions. Various types of programs may be loaded into system memory 1510, including, but not limited to, client applications, web browsers, middle-tier applications, relational database management systems (RDBMS), virtual machines, containers, etc.
[0274] System memory 1510 may also store operating system 1516. Examples of operating system 1516 may include various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems, various commercially available UNIX® or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, Google Chrome® OS, etc.), and / or mobile operating systems such as iOS, Windows® Phone, Android® OS, BlackBerry® OS, and Palm® OS operating systems. In particular implementations in which computer system 1500 runs one or more virtual machines, the virtual machines along with their guest operating systems (GOS) may be loaded into system memory 1510 and executed by one or more processors or cores of processing unit 1504.
[0275] The system memory 1510 may be provided in different configurations depending on the type of computer system 1500. For example, the system memory 1510 may be volatile memory (such as random access memory (RAM)) and / or non-volatile memory (such as read-only memory (ROM) or flash memory). Various types of RAM configurations may be provided, including static random access memory (SRAM), dynamic random access memory (DRAM), etc. In some implementations, the system memory 1510 may include a basic input / output system (BIOS), which contains the basic routines that help to transfer information between elements within the computer system 1500, such as during start-up.
[0276] Computer-readable storage medium 1522 may represent storage media, in addition to remote, local, fixed, and / or removable storage devices, for temporarily and / or more permanently containing and storing computer-readable information for use by computer system 1500, including instructions executable by processing unit 1504 of computer system 1500.
[0277] The computer-readable storage medium 1522 may include any suitable medium known or used in the art, including storage and communication media, such as, but not limited to, volatile and nonvolatile, removable and non-removable media, implemented in any manner or technology for storing and / or transmitting information. The computer-readable storage medium 1522 may include tangible computer-readable storage media, such as RAM, ROM, electronically erasable programmable ROM (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device, or other tangible computer-readable medium.
[0278] By way of example, the computer-readable storage medium 1522 may include a hard disk drive that reads from or writes to non-removable, non-volatile magnetic media, a magnetic disk drive that reads from or writes to removable, non-volatile magnetic disks, and an optical disk drive that reads from or writes to removable, non-volatile optical disks, such as CD-ROMs, DVDs, and Blu-ray disks or other optical media. The computer-readable storage medium 1522 may include, but is not limited to, Zip drives, flash memory cards, universal serial bus (USB) flash drives, secure digital (SD) cards, DVD disks, digital video tapes, etc. The computer-readable storage media 1522 may include solid-state drives (SSDs) based on non-volatile memory such as flash memory-based SSDs, enterprise flash drives, semiconductor ROM, volatile memory-based SSDs such as semiconductor RAM, dynamic RAM, static RAM, DRAM-based SSDs, magneto-resistive RAM (MRAM) SSDs, and hybrid SSDs that use a combination of DRAM and flash memory-based SSDs. Disk drives and associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 1500.
[0279] Machine-readable instructions executable by one or more processors or cores of the processing unit 1504 may be stored on a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium may include physically tangible memory or storage devices, including volatile and / or non-volatile memory storage devices. Examples of non-transitory computer-readable storage media include magnetic storage media (e.g., disks or tapes), optical storage media (e.g., DVDs, CDs), various types of RAM, ROM, or flash memory, hard drives, floppy drives, removable memory drives (e.g., USB drives), or other types of storage devices.
[0280] The communications subsystem 1524 provides an interface to other computer systems and networks. The communications subsystem 1524 serves as an interface for receiving data from and transmitting data to other systems in the computer system 1500. For example, the communications subsystem 1524 may enable the computer system 1500 to connect to one or more devices via the Internet. In some embodiments, the communications subsystem 1524 may include radio frequency (RF) transceiver components for accessing wireless voice and / or data networks (e.g., using cellular technology, advanced data network technologies such as 3G, 4G, or EDGE (enhanced data rates for global evolution), WiFi (using the IEEE 802.11 family of standards, or other mobile communications technologies, or any combination thereof), global positioning system (GPS) receiver components, and / or other components. In some embodiments, the communications subsystem 1524 may provide a wired network connection (e.g., Ethernet) in addition to or instead of a wireless interface.
[0281] In some embodiments, the communications subsystem 1524 may receive incoming communications in the form of structured and / or unstructured data feeds 1526, event streams 1528, event updates 1530, etc., on behalf of one or more users who may use the computer system 1500.
[0282] By way of example, the communications subsystem 1524 may be configured to receive data feeds 1526 in real time from users of social networks and / or other communications services, such as Twitter® feeds, Facebook® updates, web feeds, such as Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third-party sources.
[0283] Additionally, the communications subsystem 1524 may be configured to receive data in the form of a continuous data stream, which may include an event stream 1528 of real-time events and / or event updates 1530 that may have no explicit end, be continuous in nature, or be unbounded. Examples of applications that generate continuous data may include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automobile traffic monitoring, etc.
[0284] The communications subsystem 1524 may be configured to output structured and / or unstructured data feeds 1526, event streams 1528, event updates 1530, etc. to one or more databases that can communicate with one or more streaming data source computers coupled to the computer system 1500.
[0285] The computer system 1500 can be one of a variety of types, including a handheld portable device (e.g., an iPhone® mobile phone, an iPad® computing tablet, a PDA), a wearable device (e.g., a Google Glass® head-mounted display), a PC, a workstation, a mainframe, a ticket machine, a server rack, or any other data processing system.
[0286] Due to the ever-changing nature of computers and networks, the description of computer system 1500 shown in the figure is intended to be a specific example only. Many other configurations are possible, including more or fewer components than the system shown in the figure. For example, customized hardware may be used, and / or particular elements may be implemented in hardware, firmware, software (including applets), or a combination thereof. Furthermore, connections to other computing devices, such as network input / output devices, may be employed. Based on the disclosure and teachings provided herein, those skilled in the art will appreciate other ways and / or manners for implementing the various embodiments.
[0287] While specific embodiments have been described, various modifications, variations, alternative constructions, and equivalents are encompassed within the scope of the present disclosure. The embodiments are not limited to operation in one particular data processing environment, but can freely operate in multiple data processing environments. Furthermore, while the embodiments have been described using a particular sequence of transactions and steps, it should be apparent to those skilled in the art that the scope of the present disclosure is not limited to the sequence of transactions and steps described. Various features and aspects of the above-described embodiments may be used individually or together.
[0288] Furthermore, while embodiments have been described using particular combinations of hardware and software, it should be recognized that other combinations of hardware and software are within the scope of the present disclosure. Embodiments may be implemented exclusively in hardware, exclusively in software, or using a combination thereof. Various processes described herein may be performed on the same processor or on different processors in any combination. Thus, when a component or service is described as being configured to perform an operation, such configuration may be realized, for example, by designing electronic circuitry to perform the operation, by programming a programmable electronic circuit (such as a microprocessor) to perform the operation, or by any combination thereof. Processes may communicate using various techniques, including, but not limited to, conventional techniques for inter-process communication, and different pairs of processes may use different techniques, or the same pair of processes may use different techniques at different times.
[0289] Accordingly, the specification and drawings should be regarded in an illustrative, rather than a limiting sense. However, it will be apparent that additions, subtractions, deletions, and other modifications and changes may be made to the specification and drawings without departing from the broader spirit and scope as set forth in the claims. Accordingly, while particular disclosed embodiments have been described, they are not intended to be limiting. Various modifications and equivalents are within the scope of the appended claims.
[0290] The use of the terms "a," "an," and "the" and similar referents in the context of describing the disclosed embodiments (particularly in the context of the appended claims) should be construed to cover both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context. The terms "comprising," "having," "including," and "containing" should be construed as open-ended (i.e., meaning "including, but not limited to"), unless otherwise noted. The term "connected" should be construed as partially or fully contained within, connected to, or joined together, even if there is something intervening. The recitation of ranges of values herein is merely intended to serve as a shorthand method of individually referring to each separate value included in the range, unless otherwise indicated herein, and each separate value is incorporated herein as if it were individually recited herein. All methods described herein can be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. Any and all examples provided herein, or the use of exemplary language (e.g., "etc.") are intended merely to better clarify the embodiments and do not impose limitations on the scope of the disclosure unless specifically claimed. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0291] Disjunctive language, such as the phrase "at least one of X, Y, or Z," is generally intended to be understood within the context as being used to state that an item, condition, etc. may be either X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z), unless expressly stated otherwise. Thus, such disjunctive language is generally not intended to, and should not, imply that an embodiment requires that at least one of X, at least one of Y, or at least one of Z, respectively, be present.
[0292] Preferred embodiments of the present disclosure are described herein, including the best mode known for carrying out the disclosure. Variations of such preferred embodiments may become apparent to those skilled in the art upon reading the foregoing description. Those skilled in the art will be able to adopt such variations as appropriate, and the present disclosure may be practiced other than as specifically described herein. Accordingly, this disclosure includes all modifications and equivalents of the subject matter recited in the claims appended hereto as permitted by applicable law. Moreover, any combination of the above-described elements in all possible variations of the embodiments is encompassed by the present disclosure, unless otherwise indicated herein.
[0293] All references, including publications, patent applications, and patents, cited in this specification are hereby incorporated by reference to the same extent as if each reference was individually indicated to be incorporated by reference and were set forth in its entirety herein.
[0294] While the foregoing specification has described aspects of the present disclosure with reference to specific embodiments thereof, those skilled in the art will recognize that the disclosure is not limited thereto. Various features and aspects of the foregoing disclosure may be used individually or together. Moreover, the embodiments may be utilized in any number of environments and applications beyond those described herein without departing from the broader spirit and scope of the specification. Accordingly, the specification and drawings should be regarded as illustrative rather than restrictive.
Claims
1. 1. A method comprising: Identifying at least one asset in a source environment; adding the asset to a migration project, the migration project specifying the source and destination environments for replication of the asset; The method further includes receiving a request for generation of a recommended shape, the recommended shape specifying a shape of the replicated asset in the destination environment; The method further includes generating the recommended shape based on metadata characterizing attributes of the source environment, a replication strategy provided by a user, and rules specifying compatibility requirements for the recommended shape, wherein the metadata characterizes at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.
2. The method of claim 1 , wherein the destination environment is within a tenancy on a cloud service provider infrastructure (CSPI).
3. The method of claim 1 , further comprising receiving the metadata characterizing attributes of the source environment.
4. The method of claim 3 , wherein the metadata characterizes attributes of the assets in the source environment.
5. 5. The method of claim 4, wherein the CPU-related attribute characterizes at least one of a number of CPUs of the asset in the source environment, an average CPU usage by the asset in the source environment, or a maximum CPU usage in the source environment.
6. The method of claim 4 , wherein the network-related attribute characterizes at least one of an average bandwidth usage by the asset in the source environment or a maximum bandwidth usage by the asset in the source environment.
7. The method of claim 4 , wherein the metadata characterizes at least graphics processing unit (GPU)-related attributes and memory-related attributes.
8. 8. The method of claim 7, wherein the GPU-related attributes characterize at least one of a number of GPUs of the asset in the source environment, an average GPU usage by the asset in the source environment, or a maximum GPU usage in the source environment.
9. The method of claim 4 , further comprising receiving an evaluation strategy from the user.
10. The method of claim 9 , wherein the evaluation strategy specifies performance capabilities of the recommended shape.
11. The method of claim 10 , wherein the evaluation strategy specifies at least one of an average strategy or a peak strategy.
12. The method of claim 10 , further comprising generating shape requirements for the recommended shape based on the evaluation strategy.
13. The method of claim 12 , wherein generating the recommended shape comprises identifying a plurality of possible shapes.
14. The method of claim 13 , wherein generating the recommended shape comprises generating a compatibility score that characterizes the compatibility of the potential shape with the source asset.
15. 15. The method of claim 14, wherein generating the recommended shapes further comprises selecting at least one of the potential shapes based at least in part on a compatibility score of the selected at least one of the potential shapes.
16. The method of claim 15 , wherein the selected at least one of the possible shapes is fully compatible with the source asset.
17. The method of claim 15 , wherein the selected at least one of the possible shapes is at least partially incompatible with the source asset.
18. a memory containing executable instructions; one or more processors configured to execute the executable instructions, the executable instructions comprising: Identifying at least one asset in a source environment; adding the asset to a migration project, the migration project specifying the source and destination environments for replication of the asset; further performing receiving a request for generation of a recommended shape, the recommended shape specifying a shape of the replicated asset in the destination environment; The system further performs generating the recommended shape based on metadata characterizing attributes of the source environment, a replication strategy provided by a user, and rules specifying compatibility requirements for the recommended shape, wherein the metadata characterizes at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.
19. 20. The system of claim 18, wherein the one or more processors are further capable of executing the executable instructions to receive the metadata characterizing attributes of the source environment, the metadata characterizing attributes of the assets within the source environment.
20. A non-transitory computer-readable storage medium storing a plurality of instructions executable by one or more processors, the plurality of instructions, when executed by the one or more processors, causing the one or more processors to: Identifying at least one asset in a source environment; adding the asset to a migration project, the migration project specifying the source and destination environments for replication of the asset; receiving a request for generation of a recommended shape, the recommended shape specifying a shape of the replicated asset in the destination environment; and generating the recommended shape based on metadata characterizing attributes of the source environment, a replication strategy provided by a user, and rules specifying compatibility requirements for the recommended shape, the metadata characterizing at least central processing unit (CPU)-related attributes and network-related attributes of the source environment.