Update Method for Redundancy System, Redundancy System, and Update Control Device

The method for updating virtual servers in active-standby redundancy systems by managing multiple stacks with secondary interfaces addresses downtime and ensures restoration to the initial state, enhancing availability and reliability.

JP7709647B2Active Publication Date: 2025-07-17NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023567302
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-14
Publication Date
2025-07-17
Estimated Expiration
2041-12-14

AI Technical Summary

Technical Problem

Conventional methods for updating applications on virtual servers in an active-standby configuration require temporarily putting the system into a single-system state, risking downtime and making it difficult to restore the server cluster to its initial state if an unexpected problem occurs.

Method used

A method for updating virtual servers in an active-standby redundancy system by creating and managing multiple stacks with secondary interfaces, allowing seamless transitions between active and standby states without deleting stacks, and incorporating a control device to manage these processes.

Benefits of technology

Reduces downtime during updates and ensures the server cluster can be restored to its initial state even if an unexpected problem occurs, improving availability and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709647000001
    Figure 0007709647000001
  • Figure 0007709647000002
    Figure 0007709647000002
  • Figure 0007709647000003
    Figure 0007709647000003
Patent Text Reader

Abstract

An update control device (100) for a redundancy system (300) causes applications to be updated, the applications being installed in virtual machines (211, 212) that respectively belong to a stack (201) and a stack (202) indicating groups of instances of virtual resources. The update control device (100) executes a creation step for generating virtual machines (215, 216) that correspond to the stacks (201, 202) and include stacks (205, 206) in which new applications are stored, and a change step for sequentially performing processes for changing a stack indicating a secondary interface linked to the stacks (205, 206) to a stack (203, 204).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for updating a redundancy system that provisions server resources, executes settings, changes, etc. on a cloud environment, a redundancy system, and an update control device.

Background Art

[0002] With the spread of cloud services, for example, in order to easily construct, expand, or relocate a virtual resource environment on the cloud, a technique of templatizing configuration information of virtual resources and performing batch deployment is known (see, for example, Non-Patent Document 1 and Non-Patent Document 2).

[0003] In this technique, a group of instances of virtual resources deployed based on a template is called a stack. The virtual resources generated within a stack can be referred to and used from other stacks, etc., and the construction of the environment of the entire cloud environment can be easily realized by combining stacks.

Prior Art Documents

Non-Patent Documents

[0004]

Non-Patent Document 1

Non-Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the configuration of a conventional stack, when executing an update of an application on a virtual server, a method of using the latest template definition and recreating the stack is generally used.

[0006] However, when executing an update of an application on a virtual server that is redundant in an active - standby configuration, in order to perform the update without changing the IP (Internet protocol) address for communication between servers, it is necessary to delete one - side stack, temporarily put the virtual servers of the system into a single - system state, and then update the virtual servers one by one.

[0007] Here, in the procedure for executing this update, there are two problems. The first problem is that during the update, the virtual server becomes a single - system state. In the event of a failure, the virtual server may not be operating in either the active state or the standby state.

[0008] Also, the second problem is that since the operating stack is deleted each time the update process progresses, if an unexpected problem occurs during the update, the server cluster cannot be restored to its initial state.

[0009] The present invention has been made in view of such points, and an object of the present invention is to shorten the time during which the virtual server becomes a single - system state when updating an application of the virtual server, improve availability, and be able to restore the server cluster to its initial state even if an unexpected problem occurs.

Means for Solving the Problems

[0010] The update control method for a redundancy system according to the present invention is an update control method for a redundancy system including a first stack indicating a group of virtual resource instances, a second stack indicating a group of virtual resource instances, and an update control device for controlling the update of an application stored in the virtual resources of the first stack and the second stack. The first stack is linked to a third stack indicating a secondary interface for communication with other stacks other than itself to form a virtual server. The second stack is linked to a fourth stack indicating the secondary interface to form a virtual server. The virtual servers are redundant in an active state / standby state. The update control device corresponds to the first stack and includes a virtual server including a fifth stack storing a new application indicating the updated application, and corresponds to the second stack, and creates a virtual server including a sixth stack storing the new application. A creation step of generating, and a change step of sequentially performing a process of changing a stack indicating the secondary interface linked to the fifth stack to the third stack and a process of changing a stack indicating the secondary interface linked to the sixth stack to the fourth stack. It is characterized by executing.

Effect of the Invention

[0011] According to the present invention, when updating the application of a virtual server, the time during which the virtual server is in a single-system state can be shortened, the availability can be improved, and even if an unexpected problem occurs, the server cluster can be restored to the initial state.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2A

Figure 2B

Figure 3A

Figure 3B

Figure 3C

Figure 3D

Figure 3E

Figure 4

Figure 5A

Figure 5B

Figure 5C

Figure 5D

Figure 5E

Embodiment for Carrying Out the Invention

[0013] Next, an embodiment for carrying out the present invention (hereinafter referred to as "this embodiment") will be described. First, the outline of this technology will be described using the prior art as a comparative example.

[0014] <Outline of this technology> In this technology, a group of instances of virtual resources deployed based on a template is called a stack. In a redundancy system composed of two stacks (two servers), as an example, a method for updating a predetermined application (APL: application) installed on virtual machines respectively owned by the two stacks will be described.

[0015] FIG. 5A is an explanatory diagram showing the construction of an ACT (Active) / SBY (Standby) type redundancy system 500 using a conventional stack as a comparative example. As shown in FIG. 5A, the ACT / SBY type redundancy system 500 as a comparative example is configured to include a stack 501 on the left side and a stack 502 on the right side.

[0016] The stack 501 creates predetermined virtual resources by using a predetermined template and creates one of the servers in the ACT / SBY configuration. Specifically, the stack 501 is created with a predetermined template, one virtual machine (Virtual Machine) 601 is started, and a predetermined application (APL: old) is installed.

[0017] The virtual machine 601 has a maintenance interface and has an IP (Internet Protocol) address of 10.10.2.10 (hereinafter simply referred to as.2.10. The same applies to other IP addresses). The virtual machine 601 is attached with a NIC611 indicating a secondary network interface card (NIC: Network Interface Card) for communication between servers, and the NIC611 has an IP address of.1.10.

[0018] The virtual machine 601 is set with an ACT / SBY inter-system monitoring program (keepalived: hereinafter also simply referred to as the monitoring program), and is set to perform normality monitoring on the IP address.3.10 of the NIC612 of the paired virtual machine 602. Note that in Figure 5A, the virtual machine 601 has transitioned to the ACT (active) state.

[0019] Similarly, the stack 502 also creates a predetermined virtual resource and creates one of the servers in the ACT / SBY configuration by using a predetermined template. Specifically, the stack 502 is created with a predetermined template, one virtual machine 602 is started, and a predetermined application (APL: old) is installed.

[0020] The virtual machine 602 has a maintenance interface and has an IP address of.4.10. The virtual machine 602 is attached with a secondary NIC612 for communication between servers, and the NIC612 has an IP address of.3.10.

[0021] The virtual machine 602 is also set with an ACT / SBY inter-system monitoring program, and is set to perform normality monitoring on the IP address.1.10 of the NIC611 of the paired virtual machine 601. Note that in Figure 5A, the virtual machine 602 has transitioned to the SBY (standby) state.

[0022] In the configuration of the redundancy system 500 having such two stacks 501 and 502, when updating a predetermined application (APL: old) of the virtual machines 601 and 602, a method of recreating a new stack using the latest template definition has been generally used conventionally.

[0023] For example, when updating a predetermined application (APL: old) of the virtual machines 601 and 602, in order to perform the update without changing the IP addresses for communication between the virtual machines 601 and 602, first, one of the stacks 501 and 502 constituting the redundancy system 500 is deleted. Then, in the redundancy system 500, with the stacks 501 and 502 temporarily in a single-system state, the predetermined application (APL: old) of the virtual machines 601 and 602 is updated one by one. Hereinafter, a method of updating the predetermined application (APL: old) of the virtual machines 601 and 602 will be described starting from the state of FIG. 5A.

[0024] FIG. 5B shows a state in which the stack 502 is deleted from the state of FIG. 5A. As shown in FIG. 5B, first, in the redundancy system 500, the standby stack 502 that constitutes one of the servers is deleted.

[0025] Next, as shown in FIG. 5C, a stack 503 in which a predetermined application (APL: old) of the virtual machine 602 that the stack 502 had is updated is added to the redundancy system 500.

[0026] The stack 503 is created from the latest template corresponding to the stack 503. The stack 503 starts the virtual machine 603, and a predetermined new application (APL: new) is installed. Then, the virtual machine 603 transitions to the standby state.

[0027] The virtual machine 603 has a secondary NIC 613 attached, and the NIC 613 has an IP address of.3.10. The virtual machine 603 monitors the virtual machine 601 with respect to the IP address.1.10 of the NIC 611 of the virtual machine 601. In other words, the virtual machine 603 monitors the virtual machine 601 via the network interface of the virtual machine 601.

[0028] Figure 5D shows the state where the stack 501 has been deleted from the state of Figure 5C. As shown in Figure 5D, when the active virtual machine 601 is deleted, the virtual machine 603 transitions from the standby state to the active state.

[0029] As shown in Figure 5E, a stack 504 in which a predetermined application (APL: old) of the virtual machine 601 that the stack 501 had is updated is added to the redundancy system 500.

[0030] The stack 504 is created from the latest template corresponding to the stack 504. The stack 504 starts the virtual machine 604 and a predetermined new application (APL: new) is installed. Then, the virtual machine 604 transitions to the standby state.

[0031] The virtual machine 604 has a secondary NIC 614 attached, and the NIC 614 has an IP address of.1.10. The virtual machine 604 monitors the virtual machine 603 with respect to the IP address.3.10 of the NIC 613 of the virtual machine 603. In other words, the virtual machine 604 monitors the virtual machine 603 via the network interface of the virtual machine 603.

[0032] In this way, by the method shown in Figures 5A to 5E, conventionally, a predetermined application (APL: old) of the virtual machines 601 and 602 has been updated to a predetermined application (APL: new) of the virtual machines 603 and 604.

[0033] However, this method has two problems. The first problem is that while updating a predetermined application (APL: old) of the virtual machines 601 and 602, the virtual machines (virtual servers) enter a single-system state. Therefore, in the event of a failure in the redundancy system 500, there may occur a state where the virtual machines (virtual servers) are neither in the active state nor in the standby state.

[0034] The second problem is that in the method of the comparative example, a stack having a predetermined application (APL: old) to be updated is deleted in advance, the stack is recreated from the latest template, and then the predetermined application (APL: new) is installed. Therefore, for example, if any problem occurs when the stack is recreated from the latest template, the virtual machine (virtual server) to be updated has already been deleted, and thus it is impossible to return the redundancy system 500 (server cluster) to its original state, that is, the initial state.

[0035] On the other hand, the update method of the redundancy system according to the present embodiment can shorten the time during which the virtual machine (virtual server) enters the single-system state when updating the application of the virtual machine (virtual server), improve the availability, and can return the redundancy system (server cluster) to the initial state even if an unexpected problem occurs.

[0036] <Redundancy system> FIG. 1 is a block diagram showing the overall configuration of a redundancy system 300 including an update control device 100 according to the present embodiment. Note that FIG. 1 shows the configuration during operation (initial state) before the update.

[0037] As shown in FIG. 1, the redundancy system 300 includes an update control device 100 and a server cluster 200.

[0038] The redundancy system 300 is a cloud computing system that updates a predetermined application (APL: old) installed on virtual machines 211 and 212 of stacks 201 and 202 housed in the server cluster 200.

[0039] The server cluster 200 houses stacks 201 to 204. In the server cluster 200, stacks 201 (first stack) and 203 (third stack), and stacks 202 (second stack) and 204 (fourth stack) constitute an ACT (active) / SBY (standby) type redundancy system.

[0040] Stack 201 and stack 203, for example, constitute virtual servers in an active state, and stack 202 and stack 204 constitute virtual servers in a standby state. Stack 201 has a virtual machine 211, and the virtual machine 211 has an IP address.2.10. Also, stack 202 has a virtual machine 212, and the virtual machine 212 has an IP address.4.10.

[0041] A predetermined application (APL: old) to be updated is installed on virtual machines 211 and 212, respectively.

[0042] On stack 201, NIC213 of stack 203 is attached as a secondary network interface for inter-server communication with stack 202 and the like, and NIC213 has an IP address.1.10. Also, on stack 202, NIC214 of stack 204 is attached as a secondary network interface for inter-server communication with stack 201 and the like, and NIC214 has an IP address.3.10.

[0043] In this embodiment, stacks 203 and 204 are configured separately as stacks different from stacks 201 and 202. Also, stack 201 monitors stack 202 via stack 204, and stack 202 monitors stack 201 via stack 203.

[0044] When configuring the virtual machine 211 of stack 201, stack 201 is created by referring to stack 203 and using a template that generates virtual machine 211 with NIC 213 of stack 203 as a secondary interface. Also, when configuring the virtual machine 212 of stack 202, stack 202 is created by referring to stack 204 and using a template that generates virtual machine 212 with NIC 214 of stack 204 as a secondary interface.

[0045] Each of stacks 201 to 204 creates predetermined virtual resources by using a predetermined template. Note that the method for creating each stack is not limited to this. For example, the templates may be made common according to the type of stack, and stacks may be created from the common templates so that each stack has different parameters.

[0046] The update control device 100 is a device that constitutes cloud computing and is realized by a computer (see FIG. 4) described later.

[0047] The update control device 100 updates a predetermined application (APL: old) installed in the virtual machines 211 and 212 of stacks 201 and 202 accommodated in the server cluster 200. The update control device 100 includes a stack creation unit 110, a stack setting change unit 120, a stack update unit 130, a normality confirmation unit 140, and a stack deletion unit 150.

[0048] Here, the stack creation unit 110, the stack setting change unit 120, the stack update unit 130, and the normality confirmation unit 140 are related to each other and execute in cooperation with each other. Therefore, each function executed by the stack creation unit 110, the stack setting change unit 120, the stack update unit 130, and the normality confirmation unit 140 is not limited to the following processes. That is, each function executed by the stack creation unit 110, the stack setting change unit 120, the stack update unit 130, and the normality confirmation unit 140 may be realized by other components with respect to each other.

[0049] The functions executed by the stack creation unit 110, the stack setting change unit 120, the stack update unit 130, and the normality confirmation unit 140 will be described using the stacks 201 to 210, the virtual machines 211, 212, 215, 216, and the NICs 213, 214, 217, 218, 219, 220, which will be described later in FIGS. 3A to 3E.

[0050] The stack creation unit 110 performs a process of creating a predetermined stack to be created using a corresponding template. Specifically, the following processes are performed.

[0051] The stack creation unit 110 creates a stack 205 (the fifth stack) and a stack 207 (the seventh stack) corresponding to the stack 201 and the stack 203, respectively, using each template. Also, the stack creation unit 110 creates a stack 206 (the sixth stack) and a stack 208 (the eighth stack) corresponding to the stack 202 and the stack 204, respectively, using each template (see FIG. 3A). Also, the stack creation unit 110 creates a stack 209 and a stack 210, which are stacks corresponding to the stack 203 and the stack 204, respectively, and are temporarily used, using each template (see FIG. 3A).

[0052] The stack setting change unit 120 performs a process of changing the network interface currently being monitored for a predetermined stack to another network interface. Specifically, the following processes are performed.

[0053] The stack setting change unit 120 changes the network interface to be monitored of the stack 206 from the NIC 217 of the stack 207 associated with the stack 205 to the NIC 213 of the stack 203 associated with the stack 201 (see FIG. 3B). Further, the stack setting change unit 120 changes the network interface to be monitored of the stack 205 from the NIC 218 of the stack 208 to the NIC 214 of the stack 204 associated with the stack 206 (FIG. 3D).

[0054] The stack update unit 130 executes a process of stopping the instance of the stack and a process of switching the association of the network interface of the stack at the current time to the association with another network interface. Specifically, the following processes are performed.

[0055] The stack update unit 130 stops the instance of the stack 202 as an execution of an update command for the stack 202 (see FIG. 3B). The stack update unit 130 switches the association of the network interface of the stack 202 from the NIC 214 of the stack 204 to the NIC 219 of the temporarily used stack 209 (see FIG. 3B).

[0056] Further, the stack update unit 130 switches the association of the network interface of the stack 206 from the NIC 218 of the stack 208 to the NIC 214 of the stack 204 as an execution of an update command for the stack 206 (see FIG. 3B). The stack update unit 130 changes the monitoring target of the stack 201 from the stack 202 via the stack 204 to the stack 206 via the stack 204 (see FIG. 3B).

[0057] Further, the stack update unit 130 stops (shuts down) the instance of the stack 201 (see FIG. 3C). In this case, the stack update unit 130 transitions the stack 206 from the standby state to the active state.

[0058] As an execution of an update command for stack 201, the stack update unit 130 stops the process of the application (APL) of the virtual machine 211 with respect to stack 201 (see FIG. 3C). The stack update unit 130 switches the association of the network interface of stack 201 from the NIC 213 of stack 203 to the NIC 220 of the temporarily used stack 210 (see FIG. 3D).

[0059] Also, as an execution of an update command for stack 205, the stack update unit 130 switches the association of the network interface of stack 205 from the NIC 217 of stack 207 to the NIC 213 of stack 203 (see FIG. 3D).

[0060] The normality confirmation unit 140 executes processing for operation confirmation of whether the stack operates normally after creation and operation confirmation of whether the stack operates normally when the association of the stack is changed and the stack is restarted. Specifically, the following processing is performed.

[0061] The normality confirmation unit 140 starts up the created stacks 205 to 208 and confirms whether each operates normally. Stacks 205 and 207, as an example, constitute active servers, and stacks 206 and 208 constitute standby servers. Stack 205 has a virtual machine 215, and the virtual machine 215 has an IP address.2.11. Also, stack 206 has a virtual machine 216, and the virtual machine 216 has an IP address.4.11.

[0062] Also, the normality confirmation unit 140 determines whether the stack 206 that monitors stack 201 is operating normally in an active state (first confirmation determination step). In this case, the normality confirmation unit 140 determines the packet output from the NIC 214 of stack 204 attached to stack 206 and confirms whether stack 206 is operating normally.

[0063] When an abnormality occurs in stack 206, the normality confirmation unit 140 activates the virtual machine 211 of stack 201 and reverts. Here, in this embodiment, reverting means returning the server cluster 200 to the previous state or returning the server cluster 200 to the initial state.

[0064] In this case, the normality confirmation unit 140 starts a predetermined application (APL: old) of the virtual machine 211 and a monitoring program, and activates the virtual machine 211 of stack 201 based on the determination rule of the monitoring program. That is, the normality confirmation unit 140 can return the server cluster 200 to the state before the abnormality occurred. Further, since the normality confirmation unit 140 has detected that an abnormality has occurred, not only can it return to the state before the abnormality occurred, but it can also return the server cluster 200 to the initial state by tracing the processing procedure in reverse order.

[0065] Also, the normality confirmation unit 140 determines whether stack 205 is operating normally (second confirmation determination step). In this case, the normality confirmation unit 140 determines the packets output from the NIC 213 of stack 203 attached to stack 205, and confirms whether stack 205 is operating normally.

[0066] When an abnormality occurs in stack 205, the normality confirmation unit 140 stops the instance of stack 205 and changes the instance of stack 206 to the active state.

[0067] In this case, the normality confirmation unit 140 can return to the state before the occurrence of an abnormality by tracing back the processing procedure in reverse order. For example, when the normality confirmation unit 140 detects that an abnormality has occurred in the second confirmation determination step, it executes the update of the stack 205 and reconnects the network interface of the stack 205 from the NIC 213 of the stack 203 to the NIC 217 of the stack 207. Further, the normality confirmation unit 140 executes the update of the stack 201 and reconnects the network interface of the stack 201 from the NIC 220 of the stack 210 to the NIC 213 of the stack 203.

[0068] The stack deletion unit 150 executes a process of deleting unnecessary stacks. Specifically, the stack deletion unit 150 deletes unnecessary stacks when the stack 205 is operating normally.

[0069] <Update control process> The update control device 100 of the redundancy system 300 according to the present embodiment creates update stacks 205 and 206 corresponding to the stacks 201 and 202, respectively, and switches the monitoring targets in order between the created stacks 205 and 206 and the stacks 201 and 202. Thereby, the update control device 100 updates the predetermined applications (APL: old) installed in the virtual machines 211 and 212 of the stacks 201 and 202, respectively.

[0070] With reference to FIG. 1, the update control process of the predetermined application (APL: old) installed in the virtual machines 211 and 212 of the stacks 201 and 202 accommodated in the server cluster 200 of the redundancy system 300 according to the present embodiment will be described.

[0071] FIGS. 2A and 2B are flowcharts showing the flow of the update control process executed by the update control device 100 of the redundancy system 300.

[0072] This update control process starts, for example, when the update control device 100 receives an update start instruction for the server cluster 200 from the outside.

[0073] First, the stack creation unit 110 of the update control device 100 executes stack creation (step S1).

[0074] FIG. 3A is a diagram for explaining the process of the stack creation unit 110 creating stacks 205 to 210 in the server cluster 200.

[0075] In step S1, the stack creation unit 110 creates a stack 205 (the fifth stack) and a stack 207 (the seventh stack) corresponding to the stack 201 and the stack 203 respectively, using each template. Also, the stack creation unit 110 creates a stack 206 (the sixth stack) and a stack 208 (the eighth stack) corresponding to the stack 202 and the stack 204 respectively, using each template. Further, the stack creation unit 110 creates stacks 209 and 210 that are corresponding stacks for the stack 203 and the stack 204 respectively and are temporarily used, using each template.

[0076] Next, the normality confirmation unit 140 of the update control device 100 confirms the normality of the created stacks 205 to 208 (step S2).

[0077] The normality confirmation unit 140 starts the created stacks 205 to 208 and checks whether they operate normally (normality confirmation). The stack 205 and the stack 207, as an example, constitute active servers, and the stack 206 and the stack 208 constitute standby servers.

[0078] The stack 205 has a virtual machine 215, and the virtual machine 215 has an IP address.2.11. Also, the stack 206 has a virtual machine 216, and the virtual machine 216 has an IP address.4.11.

[0079] In virtual machines 215 and 216, a predetermined application (APL: new) obtained by updating a predetermined application (APL: old) is installed, and operation confirmation is performed.

[0080] In stack 205, NIC 217 of stack 207 is attached as a secondary network interface for communication between servers with stack 206 and the like, and NIC 217 has an IP address of.1.11. In stack 206, NIC 218 of stack 208 is attached as a secondary network interface for communication between servers with stack 205 and the like, and NIC 218 has an IP address of.3.11.

[0081] Stacks 207 and 208 are configured separately as stacks different from stacks 205 and 206. Stack 205 monitors stack 206 via stack 208, and stack 206 monitors stack 205 via stack 207.

[0082] Next, stack setting change unit 120 of update control device 100 changes the setting of stack 206, and stack update unit 130 executes an update command for stacks 202 and 206 (step S3).

[0083] FIG. 3B is a diagram for explaining a process in which stack setting change unit 120 changes the setting of stack 206 and stack update unit 130 executes an update command for stacks 202 and 206.

[0084] As shown in FIG. 3B, stack setting change unit 120 changes the network interface to be monitored for stack 206 from NIC 217 of stack 207 that monitors stack 205 to NIC 213 of stack 203 that monitors stack 201. Thereby, stack setting change unit 120 changes the monitoring target of stack 206 from stack 205 to stack 201 via stack 203.

[0085] Also, as an execution of an update command for the stack 202, the stack update unit 130 stops the instance of the stack 202. The stack update unit 130 switches the association of the network interface of the stack 202 from the NIC 214 of the stack 204 to the NIC 219 of the temporarily used stack 209.

[0086] Also, as an execution of an update command for the stack 206, the stack update unit 130 switches the association of the network interface of the stack 206 from the NIC 218 of the stack 208 to the NIC 214 of the stack 204. The stack update unit 130 changes the monitoring target of the stack 201 from the stack 202 via the stack 204 to the stack 206 via the stack 204. In this case, when the instance of the stack 206 is restarted, the stack 206 can recognize the NIC 214 of the stack 204, and the changed configuration becomes effective. Thereby, the stack 206 can apply the IP address.3.10 of the NIC 214 of the stack 204.

[0087] Next, the stack update unit 130 of the update control device 100 stops the instance of the stack 201 (step S4). The stack 206 that has been monitoring the stack 201 transitions from the standby state to the active state due to the stop of the instance of the stack 201.

[0088] FIG. 3C is a diagram for explaining the process in which the stack 206 transitions from the standby state to the active state by stopping the instance of the stack 201.

[0089] As shown in FIG. 3C, when the stack update unit 130 stops the instance of the stack 201, the stack 206 detects the stop of the stack 201 via the NIC 213 of the stack 203 and transitions from the standby state to the active state.

[0090] Here, in this embodiment, different from the comparative example, without deleting the stack 201, by stopping the virtual machine 211, the operation of the stack 206 is confirmed. Thereby, this embodiment can shorten the time during which the stack 206 is in a single-system state and improve the availability.

[0091] Next, the normality confirmation unit 140 of the update control device 100 executes normality confirmation (step S5). In this case, the normality confirmation unit 140 determines the packets output from the NIC 214 of the stack 204 attached to the stack 206, and checks whether the stack 206 is operating normally. That is, the normality confirmation unit 140 determines whether the stack 206 is normal or abnormal based on the packets output by a predetermined application (APL: new) from the NIC 214 of the stack 204.

[0092] In step S6 (first confirmation determination step), if an abnormality has occurred in the stack 206 (Yes in step S6), the normality confirmation unit 140 starts the instance of the stack 201 and reverts (step S7).

[0093] Specifically, the normality confirmation unit 140 returns the server cluster 200 from the state of FIG. 3C to the state of FIG. 3B.

[0094] Thereby, a predetermined application (APL: old) of the virtual machine 211 and the monitoring program are started, and based on the determination rule of the monitoring program, the virtual machine 211 of the stack 201 becomes active. That is, the normality confirmation unit 140 can return the server cluster 200 to the state before the occurrence of the abnormality.

[0095] Furthermore, by detecting that an abnormality has occurred, the normality confirmation unit 140 can not only return to the state before the occurrence of the abnormality, but also return the server cluster 200 to the initial state by tracing back the processing procedure in reverse order.

[0096] On the other hand, when there is no abnormality in the stack 206 (first confirmation determination step) (No in step S6), the normality confirmation unit 140 determines that the stack 206 is operating normally, the stack setting change unit 120 changes the setting of the stack 205, and the stack update unit 130 executes an update command for the stacks 201 and 205 (step S8).

[0097] FIG. 3D is a diagram for explaining a process in which the stack setting change unit 120 changes the setting of the stack 205 and the stack update unit 130 executes an update command for the stacks 201 and 205.

[0098] As shown in FIG. 3D, the stack setting change unit 120 changes the network interface to be monitored for the stack 205 from the NIC 218 of the stack 208 to the NIC 214 of the stack 204 that monitors the stack 206. Thereby, the stack setting change unit 120 can change the monitoring target of the stack 205 to the stack 206 via the stack 204.

[0099] Also, as an execution of an update command for the stack 201, the stack update unit 130 stops the process of a predetermined application (APL: old) of the virtual machine 211 for the stack 201. The stack update unit 130 switches the association of the network interface of the stack 201 from the NIC 213 of the stack 203 to the NIC 220 of the temporarily used stack 210.

[0100] Also, as an execution of an update command for the stack 205, the stack update unit 130 switches the association of the network interface of the stack 205 from the NIC 217 of the stack 207 to the NIC 213 of the stack 203. In this case, when the instance of the stack 205 is restarted, the stack 205 can recognize the NIC 213 of the stack 203, and the changed configuration becomes effective. That is, the stack 205 can apply the IP address.1.10 of the NIC 213 of the stack 203.

[0101] As a result, stack 205 monitors stack 206 via stack 204, and stack 206 monitors stack 205 via stack 203.

[0102] Therefore, the monitoring programs of virtual machine 215 of stack 205 and virtual machine 216 of stack 206 monitor each other. Here, when virtual machine 215 and virtual machine 216 are both in an active state, for example, it is set to prioritize virtual machine 215 of stack 205. As a result, virtual machine 216 of stack 206 transitions from the active state to the standby state.

[0103] Next, the normality confirmation unit 140 of the update control device 100 executes normality confirmation (step S9 in FIG. 2B). In this case, the normality confirmation unit 140 determines the packets output from the NIC 213 of stack 203 attached to stack 205, and checks whether stack 205 is operating normally. That is, the normality confirmation unit 140 determines whether stack 205 is normal or abnormal based on the packets output by a predetermined application (APL: new) from the NIC 213 of stack 203.

[0104] In step S10 (second confirmation determination step), if no abnormality has occurred in stack 205 (No in step S10), the normality confirmation unit 140 determines that stack 205 is operating normally, and the stack deletion unit 150 deletes unnecessary stacks (step S11), and ends the update control process.

[0105] FIG. 3E is a diagram for explaining the process in which the stack deletion unit 150 deletes unnecessary stacks in step S11.

[0106] As shown in FIG. 3E, the stack deletion unit 150 deletes stacks 201, 202, 207 to 210. Since the redundancy system 300 has completed the update of a predetermined application (APL: new) of the virtual machines 215 and 216 by the stacks 205 and 206, the stack deletion unit 150 deletes the unnecessary stacks 201, 202, 207 to 210.

[0107] On the other hand, in step S10 (second confirmation determination step), if an abnormality has occurred in stack 205 (Yes in step S10), the normality confirmation unit 140 stops the instance of stack 205 and returns the instance of stack 206 to the active state (step S12), and ends the update control process.

[0108] Specifically, the normality confirmation unit 140 returns the server cluster 200 from the state of FIG. 3D to the state of FIG. 3C and ends the update control process.

[0109] Thereby, the normality confirmation unit 140 can eliminate (avoid) the stopped state of the service of the server cluster 200.

[0110] In this case, the normality confirmation unit 140 can return to the state before the abnormality occurred by tracing back the processing procedure in reverse order. For example, when the normality confirmation unit 140 detects that an abnormality has occurred in the second confirmation determination step, it executes the update of stack 205 and reconnects the network interface of stack 205 from the NIC 213 of stack 203 to the NIC 217 of stack 207. Also, the normality confirmation unit 140 executes the update of stack 201 and reconnects the network interface of stack 201 from the NIC 220 of stack 210 to the NIC 213 of stack 203.

[0111] As a result, the normality confirmation unit 140 can return the server cluster 200 to the state before the occurrence of an abnormality. Also, since the redundancy system 300 has not deleted any of the stacks 201 to 210, it is also possible to return the server cluster 200 to the initial state by further tracing back the processing procedure in reverse order.

[0112] In this way, unlike the comparative example, the redundancy system 300 does not delete the stack until the update is completed. Therefore, even if an unexpected problem occurs, it is possible to return the server cluster 200 to the initial state by tracing back the processing procedure in reverse order.

[0113] <Hardware Configuration of Update Control Device> The update control device 100 according to the present embodiment is realized by, for example, a computer 900 configured as shown in FIG. 4.

[0114] FIG. 4 is a hardware configuration diagram showing an example of a computer 900 that realizes the functions of the update control device 100. The computer 900 includes a CPU (Central Processing Unit) 901, a ROM (Read Only Memory) 902, a RAM 903, an HDD (Hard Disk Drive) 904, an input / output I / F (Interface) 905, a communication I / F 906, and a media I / F 907.

[0115] The CPU 901 operates based on a program (update control program) stored in the ROM 902 or the HDD 904 to embody the stack creation unit 110, the stack setting change unit 120, the stack update unit 130, the normality confirmation unit 140, and the stack deletion unit 150. The ROM 902 stores a boot program executed by the CPU 901 when the computer 900 is started up, a program related to the hardware of the computer 900, and the like.

[0116] The CPU 901 controls an input device 910 such as a mouse or a keyboard, and an output device 911 such as a display or a printer via the input / output I / F 905. The CPU 901 acquires data from the input device 910 via the input / output I / F 905, and outputs the generated data to the output device 911. Note that, as a processor, a GPU (Graphics Processing Unit) or the like may be used together with the CPU 901.

[0117] The HDD 904 stores programs executed by the CPU 901 and data used by the programs. The communication I / F 906 receives data from other devices via a communication network (for example, NW (Network) 920) and outputs it to the CPU 901, and transmits the data generated by the CPU 901 to other devices via the communication network.

[0118] The media I / F 907 reads a program (update control program) or data stored in the recording medium 912, and outputs it to the CPU 901 via the RAM 903. The CPU 901 loads a program related to the target process from the recording medium 912 onto the RAM 903 via the media I / F 907, and executes the loaded program. The recording medium 912 is an optical recording medium such as a DVD (Digital Versatile Disc) or a PD (Phase change rewritable Disk), a magneto-optical recording medium such as an MO (Magneto Optical disk), a magnetic recording medium, a semiconductor memory, or the like.

[0119] For example, when the computer 900 functions as the update control device 100 of the present invention, the CPU 901 of the computer 900 realizes each function of the update control device 100 by executing the program loaded onto the RAM 903. Further, the data in the RAM 903 is stored in the HDD 904. The CPU 901 reads and executes a program related to the target process from the recording medium 912. In addition, the CPU 901 may read a program related to the target process from other devices via the communication network (NW 920).

[0120] <Effect> The effects of the update control method and the like of the redundancy system 300 according to the present invention will be described below.

[0121] The update control method of the redundancy system 300 according to the present invention includes a stack 201 (first stack) indicating a group of virtual resource instances, a stack 201 (second stack) indicating a group of virtual resource instances, and an update control device 100 for controlling the update of applications stored in the virtual resources of the stack 201 and the stack 202. The update control method of the redundancy system 300 is characterized in that the stack 201 is linked to a stack 203 (third stack) indicating a secondary interface for communication with other stacks other than itself to form a virtual machine 211 (virtual server), the stack 202 is linked to a stack 204 (fourth stack) indicating a secondary interface to form a virtual machine 212 (virtual server), the virtual machines 211 and 212 are redundant in an active state / standby state, and the update control device 100 corresponds to the stack 201 and includes a virtual machine 215 (virtual server) including a stack 205 (fifth stack) in which a new application indicating the updated application is stored, and a virtual machine 216 (virtual server) corresponding to the stack 202 and including a stack 206 (sixth stack) in which the new application is stored. The method includes a creation step of generating the virtual machines, and a change step of sequentially performing a process of changing the stack indicating the secondary interface linked to the stack 205 to the stack 203 and a process of changing the stack indicating the secondary interface linked to the stack 206 to the stack 204.

[0122] Thus, according to the update control method of the redundancy system 300 according to the present invention, the created stacks 205 and 206 can shorten the time during which the stacks 201 and 202 are in a single-system state, and the availability can be improved. Further, since the update control method of the redundancy system 300 does not delete any stack, even if an unexpected problem occurs, the server cluster 200 can be switched back. That is, the update control method of the redundancy system 300 can return the server cluster 200 to its initial state..

[0123] Further, the update control method of the redundancy system 300 according to the present invention includes, in the change step, changing the monitoring target of the stack 206 from the stack 205 to the stack 201 via the stack 203, and stopping the instance of the stack 202, and changing the monitoring target of the stack 201 from the stack 202 via the stack 204 to the stack 206 via the stack 204.

[0124] Thus, according to the update control method of the redundancy system 300 according to the present invention, the stack 201 and the stack 206 monitor each other's operations. Therefore, the update control method of the redundancy system 300 can shorten the time in the single-system state and improve the availability.

[0125] Further, the update control method of the redundancy system 300 according to the present invention includes, in the change step, stopping the instance of the stack 201, and when the stack 206 that monitors the stack 201 is in an active state and operating normally, changing the network interface of the stack 205 to the stack 203, and the stack 205 monitors the stack 206 via the stack 204, and the stack 206 monitors the stack 205 via the stack 203, and when the stack 205 is in an active state, changing the stack 206 to a standby state.

[0126] Thus, according to the update control method of the redundancy system 300 according to the present invention, after determining whether the stack 206 is operating normally, the stacks 205 and 206 monitor each other's operations, so the time in a single-system state can be shortened, and the availability can be improved.

[0127] Further, the update control method of the redundancy system 300 according to the present invention is characterized in that, in the change step, when the instance of the stack 201 is stopped and the stack 206 monitoring the stack 201 is not operating normally in the active state, the instance of the stack 201 is started.

[0128] Thus, according to the update control method of the redundancy system 300 according to the present invention, if the stack 206 is not operating normally in the active state during the update, it can be returned to the previous state. That is, the update control method of the redundancy system 300 can trace back the processing procedure in reverse order and return to the state where it was operating normally. Further, the update control method of the redundancy system 300 can return the server cluster 200 to the initial state by tracing back the processing procedure in reverse order.

[0129] Further, the update control method of the redundancy system 300 according to the present invention is characterized in that, in the change step, when the stack 205 is operating normally, unnecessary stacks are deleted.

[0130] Thus, according to the update control method of the redundancy system 300 according to the present invention, unnecessary stacks can be deleted after confirming that the update process is completed.

[0131] Further, the update control method of the redundancy system 300 according to the present invention is characterized in that, in the change step, when the stack 205 is not operating normally, the instance of the stack 205 is stopped and the instance of the stack 206 is changed to the active state.

[0132] In this way, the update control method of the redundancy system 300 according to the present invention can return to the previously normal operating state when the stack 205 is not operating normally during the update process. Furthermore, the update control method of the redundancy system 300 can return to the initial state of the server cluster 200 by tracing back the processing steps in reverse order.

[0133] Note that the present invention is not limited to the embodiments described above, and many modifications are possible by those with ordinary knowledge in the art within the technical idea of the present invention.

Explanation of Reference Numerals

[0134] 100 Update control device 110 Stack creation unit (creation unit) 120 Stack setting change unit (change unit) 130 Stack update unit (update unit) 140 Normality confirmation unit 150 Stack deletion unit 200 Server cluster 201~210 Stacks 211, 212, 215, 216 Virtual machines 203, 204, 207, 208, 209, 210 NICs 300 Redundancy system

Claims

1. A method for updating a redundancy system, comprising: a first stack indicating a group of virtual resource instances, a second stack indicating a group of virtual resource instances, and an update control device for controlling an update of an application stored in the virtual resources of the first stack and the second stack, wherein the first stack is associated with a third stack indicating a secondary interface for communication with other stacks other than itself to form a virtual server, and the second stack is associated with a fourth stack indicating the secondary interface to form a virtual server, wherein the virtual servers are redundant in an active / standby state, and the update control device includes a creation step of generating a virtual server including a fifth stack storing a new application indicating the updated application corresponding to the first stack, and a virtual server including a sixth stack storing the new application corresponding to the second stack; and a change step of sequentially performing a process of changing a stack indicating the secondary interface associated with the fifth stack to the third stack, and a process of changing a stack indicating the secondary interface associated with the sixth stack to the fourth stack. The method for updating a redundancy system according to claim 1, characterized by executing the above steps.

2. The change step includes: a step of changing a monitoring target of the sixth stack from the fifth stack to the first stack via the third stack; a step of stopping an instance of the second stack and changing a monitoring target of the first stack from the second stack via the fourth stack to the sixth stack via the fourth stack. The method for updating a redundancy system according to claim 1, characterized by including the above steps.

3. The change step includes: stopping an instance of the first stack; when the sixth stack monitoring the first stack is in an active state and operating normally, changing a network interface of the fifth stack to the third stack and monitoring the sixth stack via the fourth stack by the fifth stack. The step of the sixth stack monitoring the fifth stack via the third stack and, when the fifth stack is in an active state, changing the sixth stack to a standby state; The method for updating a redundancy system according to claim 2, characterized by including this.

4. The changing step includes: Stopping the instance of the first stack; When the sixth stack monitoring the first stack is in an active state and not operating normally, starting the instance of the first stack. The method for updating a redundancy system according to claim 2, characterized by this.

5. The changing step includes: When the fifth stack is operating normally, deleting an unnecessary stack. The method for updating a redundancy system according to claim 3, characterized by this.

6. The changing step includes: When the fifth stack is not operating normally, stopping the instance of the fifth stack and changing the instance of the sixth stack to an active state. The method for updating a redundancy system according to claim 3, characterized by this.

7. A redundancy system including a first stack indicating a group of virtual resource instances, a second stack indicating a group of virtual resource instances, and an update control device for controlling the update of applications stored in the virtual resources of the first stack and the second stack, The first stack is linked to a third stack indicating a secondary interface for communication with other stacks other than itself to form a virtual server, and the second stack is linked to a fourth stack indicating the secondary interface to form a virtual server. The virtual servers are redundant in an active state / standby state. The update control device includes: A creation unit that generates a virtual server including a fifth stack storing a new application indicating the updated application corresponding to the first stack, and a virtual server including a sixth stack storing the new application corresponding to the second stack. A changing unit that sequentially performs a process of changing the stack indicating the secondary interface linked to the fifth stack to the third stack, and a process of changing the stack indicating the secondary interface linked to the sixth stack to the fourth stack; A redundancy system characterized by comprising the same. **Claim 8** An update control device that controls updates of applications stored in each virtual resource of a first stack indicating a group of virtual resource instances and a second stack indicating a group of virtual resource instances, The first stack is linked to a third stack indicating a secondary interface for communication with other stacks other than itself to form a virtual server, and the second stack is linked to a fourth stack indicating the secondary interface to form a virtual server. The virtual servers are redundant in an active state / standby state. A creating unit that creates a virtual server including a fifth stack corresponding to the first stack and storing a new application indicating the updated application, and a virtual server including a sixth stack corresponding to the second stack and storing the new application; A changing unit that sequentially performs a process of changing the stack indicating the secondary interface linked to the fifth stack to the third stack, and a process of changing the stack indicating the secondary interface linked to the sixth stack to the fourth stack; An update control device characterized by comprising the same.

Citation Information

Patent Citations

  • Version update method for virtual host and network equipment

    JP2015032301A

  • Method for automatically applying update to snapshot of virtual machine, computer system thereof, and program for computer system

    JP2016085663A