Deploying a target cloud service platform
By leveraging existing resources in a public cloud service platform to build a bootstrap infrastructure for a target cloud service platform, the deployment process is accelerated, addressing inefficiencies and enabling faster service delivery.
Patent Information
- Application Number
- PCT/US2024/053307
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-27
- Filing Date
- 2024-10-29
- Publication Date
- 2025-06-05
AI Technical Summary
The conventional deployment mechanism for a target cloud service platform requires waiting for the completion of data center construction, which is time-consuming and inefficient.
The proposed solution involves using existing resources in a public cloud service platform to build a bootstrap infrastructure, which provides a collection of kernel services for the target cloud service platform, allowing for early deployment without waiting for data center completion.
This approach enables rapid deployment of the target cloud service platform, improves service parity, and addresses circular dependency issues, allowing for the provision of user-oriented services more efficiently.
Smart Images

Figure US2024053307_05062025_PF_FP_ABST
Abstract
Description
DEPLOYING A TARGET CLOUD SERVICE PLATFORMBACKGROUND
[0001] Cloud computing technology is currently developing rapidly and has revolutionized the way in which businesses and organizations store, manage, and process data. In cloud computing, computing, storing, networking, and other computing services may be provided over the Internet. Cloud computing may make computing tasks to be distributed over a resource pool consisting of a large number of computing devices, enabling various application systems to obtain computing capability, storage space, network communication capability’, etc., from the resource pool as needed.SUMMARY
[0002] This Summary is provided to introduce a selection of concepts that are further described below in the Detailed Description. It is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0003] Embodiments of the present disclosure propose methods, apparatuses, and non- transitory computer-readable medium for deploying a target cloud service platform. Configuration information for a target cloud service platform may be obtained. A bootstrap infrastructure may be built in a public cloud service platform based on the configuration information, the bootstrap infrastructure provides a collection of kernel services associated with the target cloud service platform. A collection of target services may be created in the target cloud service platform based on the collection of kernel services.
[0004] Embodiments of the present disclosure propose a cloud service system. The cloud service system may comprise a public cloud service platform and a target cloud service platform. The public cloud service platform may comprise a configuration storage, a workflow engine, and a bootstrap infrastructure. The configuration storage may be for storing configuration information for the target cloud service platform. The workflow engine may be for obtaining the configuration information from the configuration storage and to build the bootstrap infrastructure based on the configuration information. The bootstrap infrastructure may be for providing a collection of kernel services associated with the target cloud service platform. The workflow engine is further for creating a collection of target services in the target cloud service platform based on the collection of kernel services. The target cloud service platform may be for providing the collection of target service.
[0005] It should be noted that the above one or more aspects comprise the features hereinafter fully described and particularly pointed out in the claims. The following descriptionand the drawings set forth in detail certain illustrative features of the one or more aspects. These features are only indicative of the various ways in which the principles of various aspects may be implemented, and this disclosure is intended to include all such aspects and their equivalents.BRIEF DESCRIPTION OF THE DRAWINGS
[0006] The disclosed aspects will hereinafter be described in conjunction with the appended drawings that are provided to illustrate and not to limit the disclosed aspects.
[0007] FIG. 1A illustrates a schematic diagram of a cloud service system at a configuration information obtaining stage according to embodiments.
[0008] FIG. IB illustrates a schematic diagram of a cloud service system at a bootstrap infrastructure building stage according to embodiments.
[0009] FIG. 1C illustrates a schematic diagram of a cloud service system at a collection of target services creating stage according to embodiments.
[0010] FIG. ID illustrates a schematic diagram of a cloud service system at a target cloud service platform enabling stage according to embodiments.
[0011] FIG. 2 illustrates an exemplary process for obtaining configuration information according to embodiments.
[0012] FIG. 3 illustrates an exemplary process for building a bootstrap infrastructure according to embodiments.
[0013] FIG. 4 illustrates an exemplary process for creating a collection of target service according to embodiments.
[0014] FIG. 5 illustrates an exemplary' process for enabling a target cloud service platform according to embodiments.
[0015] FIG. 6 illustrates a flowchart of an exemplary method for deploying a target cloud service platform according to embodiments.
[0016] FIG. 7 illustrates an exemplary' apparatus for deploying a target cloud service platform according to embodiments.
[0017] FIG. 8 illustrates an exemplary apparatus for deploying a target cloud service platform according to embodiments.DETAILED DESCRIPTION
[0018] The present disclosure will now be discussed with reference to several exemplary' implementations. It is to be understood that these implementations are discussed only for enabling those skilled in the art to better understand and thus implement the embodiments of the present disclosure, rather than suggesting any limitations on the scope of the present disclosure.
[0019] A cloud service platform may refer to a platform that is capable of providing a range of cloud-based services to a user, which may also be referred to as a cloud, a cloud instance, andother similar concepts. The services provided by the cloud service platform can utilize computing, storing, networking, and other resources of the cloud service platform through virtualization technology to achieve various functions, such as email, database, video conferencing, etc. A data center may provide infrastructure for the cloud service platform. The data center may include computing devices, supporting facilities, etc. Computing devices of the data center refer to hardware devices that provide computing capability, storing capability, and network communication capability, and may include, for example, several types of devices, such as servers, storage devices, switches, routers, etc. Supporting facilities refer to various types of auxiliary systems that support the normal operation of the data center, and may include, for example, power systems, cooling systems, etc.
[0020] In some scenarios, a cloud service provider needs to build a new cloud service platform in a specific region. This new cloud service platform may also be referred to as a target cloud service platform, a new cloud instance, etc. In the present disclosure, for brevity, this new cloud service platform is collectively referred to as the target cloud service platform. Deploying a target cloud service platform refers to a process of configuring hardware and software of the target cloud service platform to enable the target cloud service platform to provide the required services or functions.
[0021] In a conventional deployment mechanism for the target cloud service platform, it is necessary to wait until the completion of the construction of a data center to begin to perform the deployment process. The construction process of the data center may include installing computing devices and supporting facilities of the data center, and configuring some underlying services on a few servers first to enable device management of the computing devices in the data center. The process of constructing the data center is very time consuming and typically takes several years.
[0022] Embodiments of the present disclosure propose a mechanism for deploying a target cloud services platform. The target cloud service platform deployment mechanism of the present disclosure may utilize existing resources in a public cloud service platform to build a bootstrap infrastructure in the public cloud service platform. The bootstrap infrastructure may have an initial configuration for the target cloud sendee platform. A collection of target services may be created in the target cloud service platform through utilizing the bootstrap infrastructure, thereby enabling the target cloud service platform to provide user-oriented services.
[0023] In one aspect, embodiments of the present disclosure may obtain configuration information for a target cloud service platform. The configuration information may refer to any information or data used to configure the target cloud sen ice platform to enable it to achieve the required services or functions. The configuration information may be generated by a developerat a development management platform, and may include buildout artifacts generated during software development and other information used to configure the target cloud service platform, such as certificates, keys, etc., associated with the target cloud service platform.
[0024] In one aspect, the present disclosure may build the bootstrap infrastructure in the public cloud service platform based on the obtained configuration information. The built bootstrap infrastructure may provide a collection of kernel services associated with the target cloud service platform. The collection of kernel services includes kernel services for implementing internal kernel functions of the target cloud service platform, and these kernel services may serve as a basis for forming the target cloud service platform.
[0025] In one aspect, the present disclosure may create a collection of target services in the target cloud service platform based on the collection of kernel services. The collection of target services is a superset of the collection of kernel services, and may include a large number of services provided to fulfill user needs. After creating the collection of target services, the target cloud service platform may operate in a mode approaching a delivered product.
[0026] In one aspect, the target cloud service platform may be a cloud service platform that is isolated from the public cloud service platform. The isolated cloud services platform is able to provide enhanced data security and data compliance. Data security is used to protect digital information from unauthorized access, corruption or theft throughout its whole lifecycle. Data compliance is used to enable digital information to meet the requirements of regulations formulated by different organizations or jurisdictions (e.g., countries, cities, etc.) through defining a series of criteria for avoiding loss, theft, corruption, and misuse of sensitive data.
[0027] The target cloud service platform deployment mechanism of the present disclosure facilitates to realize rapid deployment of the target cloud service platform. For example, through utilizing existing resources in the public cloud sen-ice platform, the deployment process for the target cloud service platform may be started in advance without the need for waiting until the completion of constructing the data center of the target cloud service platform.
[0028] The target cloud service platform deployment mechanism of the present disclosure facilitates to provide better service parity. The target cloud service platform deployment mechanism of the present disclosure may build the bootstrap infrastructure in the public cloud service platform to provide a collection of kernel sendees associated with the target cloud service platform. Benefiting from the network connection between the public cloud service platform and a development management platform, the development management platform may update the collection of kernel services, so that the versions the services in the collection of kernel sendees are consistent with the versions of the corresponding services in the public cloud service platform. When multiple target cloud service platforms are built at the same time, thetarget cloud service platform deployment mechanism of the present disclosure also facilitates to ensure that there is service parity among multiple collections of kernel services associated with the multiple target cloud sendee platforms.
[0029] The target cloud senice platform deployment mechanism of the present disclosure facilitates to solve a circular dependency problem. During the deployment process of the target cloud sen ice platform, there may be situations where there are circular dependency relationships between services that need to be created. The target cloud sendee platform deployment mechanism of the present disclosure may utilize existing services in the public cloud service platform to break such loop-locked circular dependency.
[0030] The target cloud service platform deployment mechanism of the present disclosure facilitates to implement some services associated with non-kemel functions of the target cloud service platform in advance. Services associated with non-kemel functions are typically created in a later period in the deployment of the target cloud sendee platform, which may result in some data of earlier periods in the deployment of the target cloud service platform being missed. The target cloud service platform deployment mechanism of the present disclosure may utilize existing resources in the public cloud service platform to implement these non-kemel functions in advance.
[0031] Exemplary embodiments of the present disclosure will be described below with reference to the appended drawings.
[0032] FIGS. 1A to ID illustrate schematic diagrams of a cloud service system 100 according to embodiments. The target cloud senice platform deployment mechanism according to embodiments of the present disclosure may be implemented in the cloud service system 100 to implement deployment of the target cloud service platform. Exemplarily, the cloud service system 100 may include a public cloud service platform 110, a development management platform 120, a target cloud sendee platform 130, etc.
[0033] The public cloud service platform 110 is a currently existing cloud service platform that may provide open cloud services to users in a coverage area. In one example, the public cloud service platform 1 10 may provide a worldwide coverage area utilizing data centers constructed at different geographic locations. The public cloud sendee platform 110 may be built and managed by a cloud service provider.
[0034] In embodiments of the present disclosure, existing resources of the public cloud service platform 110 may be utilized to facilitate early deployment of the target cloud service platform 130. These existing resources may include: hardware resources of the public cloud service platform 110, for example, servers, etc.; and software resources of the public cloud service platform 110, for example, services, etc. FIGS. 1A to ID illustrate that the public cloudservice platform 110 may include a workflow engine 112. The workflow engine 1 12 may also be referred to as a task orchestration engine, a task orchestration tool, etc., which is used to automatically perform resource provisioning and configuring within the public cloud service platform 110.
[0035] The development management platform 120 may refer to a computing platform used by the cloud service provider to perform development and management of the public cloud service platform and the target service platform. There may be a network connection between the public cloud service platform 110 and the development management platform 120. The development management platform 120 may manage the public cloud service platform 110, e.g., release updated services to the public cloud sendee platform 110, etc.
[0036] FIGS. 1A to ID illustrate that the development management platform 120 may include a development tool 122 for performing software development work for the public cloud service platform and the target cloud senice platform. For example, the development tool 122 may be implemented by utilizing Visual Studio, Eclipse, IntelliJ IDEA, and other common software development tools. The development management platform 120 may also include other tools not shown, such as a code repository for implementing storage and management of codes, a Continuous Integration Continuous Delivery (CID) pipeline for implementing integration and delivery of codes from different software modules, a releasing engine for releasing codes to the public cloud service platform and the target cloud service platform, and other tools associated with the development and management of the public cloud service platform and the target cloud service platform.
[0037] The target cloud service platform 130 refers to a new cloud service platform to be built in a specific region. After deployment is completed, the target cloud service platform 130 may operate independently of the public cloud service platform 110 and may provide the same or not exactly the same services as the public cloud serv ice platform 110. The target cloud service platform 130 and the public cloud service platform 110 may have different coverage areas. For example, the public cloud service platform 110 may cover worldwide, while the target cloud service platform may only cover a specific jurisdiction.
[0038] In one example, the target cloud service platform 130 may be a cloud service platform isolated from the public cloud service platform 110, in order to provide enhanced data security and data compliance. Depending on the level of data security and data compliance as required, the isolated cloud service platform may further include a fully isolated cloud service platform, a partially isolated cloud sendee platform, etc. There should not be any network connection between the fully isolated cloud service platform and the public cloud service platform 110. For example, the fully isolated cloud service platform may include an air-gappedtype of cloud service platform, etc. There may be a restricted network connection between the partially isolated cloud service platform and the public cloud sendee platform 110. For example, the partially isolated cloud service platform may include a sovereign type cloud service platform, etc. In a sovereign type of cloud sen ice platform, it is required that data involving secure access and privacy may only reside within the sovereign type of cloud service platform. It should be understood that although the target cloud service platform 130 is exemplarily explained in various portions of the present disclosure as being a cloud senice platform that is isolated from the public cloud service platform 110, embodiments of the present disclosure are not limited thereto, but may further cover any other scenario in which the target cloud service platform 130 is not a cloud service platform that is isolated from the public cloud service platform 110.
[0039] FIGS. 1A to ID illustrate schematic diagrams of the cloud service system 100 at different stages of deployment, respectively.
[0040] FIG. 1A illustrates a schematic diagram of the cloud service system 100 at a configuration information obtaining stage. At this time, a data center of the target cloud service platform 130 may still be under construction without affecting running of the configuration information obtaining stage. As shown in FIG. 1A, there is a network connection between the public cloud service platform 110 and the development management platform 120. Configuration information 115 for the target cloud service platform 130 may be delivered from the development management platform 120 to the public cloud service platform 110 through utilizing the network connection.
[0041] The configuration information 115 may be generated at the development management platform 120 or obtained in any other manner. The configuration information 115 may refer to any information or data used to configure the target cloud service platform 130 to enable it to implement required sendees or functions.
[0042] In one implementation, the configuration information 115 may include buildout artifacts for the target cloud service platform 130. The buildout artifacts refer to tangible products generated during developers perform software development for the target cloud service platform 130 through utilizing the development tool 122, and may include, for example, source codes, development documents, compilation files, executable files, test cases, test documents, test results, etc.
[0043] In one example, the buildout artifacts may be validated. Validation for the buildout artifacts may ensure that the different software modules of the buildout artifacts are correct on the one hand, and may ensure that the software modules developed by different development teams are consistent on the other hand. The validation of the buildout artifacts may be performed, for example, through performing integration tests on the buildout artifacts.
[0044] In one implementation, the configuration information 115 for the target cloud service platform 130 may also include other information in addition to the buildout artifacts, such as certificates, keys, etc., associated with the target cloud service platform 130. The other information may be determined after a few computing devices in the target cloud service platform 130 have been configured to provide some internal underlying services. For example, a few of computing devices in the target cloud service platform 130 may have been configured to provide a dial-tune sendee, which defines the manner in which data interactions are performed between the computing devices and specifies the certificates and keys that will be used for the target cloud service platform 130. In addition, a few of computing devices in the target cloud service platform 130 may have been configured to provide network services to exchange data with the development management platform 120 over the network. Accordingly, the development management platform 120 may extract information such as certificates, keys, etc., from the target cloud service platform 130 over the network and provide the extracted information to the public cloud service platform 110 as part of the configuration information 1 15.
[0045] The public cloud service platform 110 may include a configuration storage 114 for storing the configuration information 115. The configuration storage 114 may be a separate storage area divided by the workflow engine 112 in a storage space of the public cloud service platform 110.
[0046] FIG. IB illustrates a schematic diagram of the cloud service system 100 at a bootstrap infrastructure building stage. At this time, the data center of the target cloud service platform 130 may still be under construction without affecting running of the bootstrap infrastructure building stage. As shown in FIG. IB, a bootstrap infrastructure 116 may be built in the public cloud service platform 110. The bootstrap infrastructure 116 may be built by the workflow engine 112 based on the configuration information 115. The bootstrap infrastructure 116 is an infrastructure that is implemented through utilizing resources in the public cloud service platform and with a preliminary configuration for the target cloud service platform, and the bootstrap infrastructure 116 may also be referred to as a bootstrap environment. The bootstrap infrastructure 116 may provide a collection of kernel services 118. The collection of kernel services 118 defines a series of kernel services associated with kernel or underlying functions used to support operation of the target cloud service platform, and the collection of kernel services 118 may also be referred to as a Minimum Viable Product (MVP), etc. For example, the kernel services in the collection of kernel services 118 may include a control plane service, which is used to automatically manage computing devices in the cloud service platform, including performing operations such as software installation, patch management, restart, service deployment, etc., on the computing devices. The kernel services may also include: anauthentication sendee for verifying an identity of a user to ensure that only authenticated users are allowed to perform data access; an authorization service for determining permissions of a user and allowing the user to perform corresponding data access operations based on the type of permissions the user possesses; an inventory management service for managing a list of hardware assets of the data center; etc. It should be understood that in embodiments of the present disclosure, the kernel services in the collection of kernel services 1 18 may include any one or more of the exemplars' services listed above, and may also include any other type of services for kernel or underlying functions used to support operation of the target cloud service platform.
[0047] The bootstrap infrastructure 116 may be treated as a tenant in the public cloud service platform 110 that occupies virtual resources in the public cloud service platform to provide the collection of kernel services 118. The bootstrap infrastructure 116 is isolated from other tenants in the public cloud service platform 110 to ensure that the bootstrap infrastructure 116 is protected in terms of security and data compliance in the public cloud service platform 110. The isolation between the bootstrap infrastructure 116 and other tenants in the public cloud service platform 110 may be implemented through any tenant isolation techniques known in the art, for example, firewall techniques, Software Defined Network (SDN) techniques, etc.
[0048] FIG. 1C illustrates a schematic diagram of the cloud service system 100 at a collection of target services creating stage. At this time, the construction of the data center of the target cloud service platform 130 has been completed or substantially completed, whereby computing devices of the data center may be enabled to create a collection of target services 132 in the target cloud service platform 130 on the basis of the collection of kernel services 118. As shown in FIG. 1C, the collection of target services 132 may be created in the target cloud service platform 130. The collection of target services 132 may be created by the workflow' engine 112 based on the collection of kernel serv ices 118. The collection of target services 132 defines a series of target services used to fulfill user requirements in the target cloud service platform, and the collection of target services 132 may also be referred to as a Minimum Marketable Product (MMP). For example, the target services in the collection of target services 132 may include: an email service for email delivery'; a file share sendee for implementing sharing of files among multiple users; a file collaboration service for implementing editing of files collaboratively by multiple users; an instant communication service for implementing real-time data communication among users; etc. It should be understood that in embodiments of the present disclosure, the target services in the collection of target services 132 may include any one or more of the exemplary services listed above, and may also include any other type of service used to fulfill user requirements in the target cloud service platform.
[0049] As shown in FIG. 1C, there may be a network connection between the bootstrap infrastructure 116 and the target cloud service platform 130. Through utilizing the network connection, kernel services in the collection of kernel services 118 may be migrated from the bootstrap infrastructure 116 to the target cloud service platform 130. For example, the migration may be performed by the workflow engine 112.
[0050] The collection of target services 132 may be a superset of the collection of kernel services 118. Thus, the collection of target services 132 may include services that are added on the basis of the collection of kernel services 118. In one implementation, which services are needed to be added may be determined based on a product service list. The product service list may define a list of services that should be provided by the target cloud service platform 130 upon completion of deployment, and may be provided based on requirements for the target cloud service platform 130. In one example, these added serv ices may be scaled in the target cloud services platform 130 based on the migrated kernel services. For example, the scaling may be performed by the workflow engine 112. The workflow engine 112 may configure the kernel services in the collection of kernel services 118 to cause the migrated kernel services to scale as the services to be added in the target cloud service platform. In one example, these added services may be released from the development management platform 120 to the target cloud service platform 130 over the network connection between the development management platform 120 and the target cloud service platform 130.
[0051] FIG. ID illustrates a schematic diagram of the cloud service system 100 at a target cloud service platform enabling stage. As shown in FIG. ID, the target cloud service platform 130 may be enabled after the collection of target services 132 has been created in the target cloud service platform 130. After the target cloud service platform 130 is enabled, the network connection between the target cloud service platform 130 and the bootstrap infrastructure 116 may be disconnected or an access restriction may be imposed on the network connection, e.g., a firewall 125 may be imposed on the network connection. In one example, the network connection between the development management platform 120 and the target cloud service platform 130 may be maintained, to implement managing of the target cloud service platform 130 by the development management platform 120, e.g., updating versions of services in the target cloud service platform 130, etc. In one example, after the target cloud service platform 130 is enabled, the network connection between the development management platform 120 and the target cloud service platform 130 may be disconnected or an access restriction may be imposed on the network connection, which allows the target cloud service platform 130 to be sufficiently isolated from the outside world, in order to meet further data security and compliance requirements.
[0052] FIG. 2 illustrates an exemplary process 200 for obtaining configuration information according to embodiments. The operations in the process 200 may be performed by the workflow engine 112 as illustrated in FIGS. lA to ID.
[0053] At 210, the workflow engine may build a configuration storage within a public cloud service platform. The workflow engine may divide a separate storage area in the storage space of the public cloud service platform as the configuration storage. Dividing the separate configuration storage is helpful to achieve isolation between the configuration information and the data of other tenants of the public cloud service platform, which may improve the security of the configuration information. The configuration storage may be used to store configuration information for a target cloud service platform, for example, the configuration information 115 as discussed in combination with FIGS. 1A to ID. The configuration information may be generated at a development management platform or obtained in any other manner. For example, via a network connection between the development management platform and the public cloud service platform, the configuration information may be delivered to the public cloud service platform and subsequently stored in a configuration storage. In one example, building the configuration storage may be a broad concept, which may include not only dividing the separate storage area in the storage space, but may also include constructing a configuration database in the divided storage area. As a result, after receiving the configuration information from the development management platform, storing of the configuration information may be realized through populating data into the configuration database.
[0054] At 220, the workflow engine may obtain the configuration information from the configuration storage. The workflow engine may perform a data read operation on the configuration storage, e.g., reading data entries in the configuration database, to obtain the configuration information.
[0055] According to embodiments of the present disclosure, after the configuration information is obtained, a bootstrap infrastructure may be built in the public cloud service platform based on the configuration information to provide a collection of kernel services associated with the target cloud service platform.
[0056] FIG. 3 illustrates an exemplary7process 300 for building a bootstrap infrastructure according to embodiments. Operations in the process 300 may be performed by the workflow engine 112 as illustrated in FIGS. 1 A to ID.
[0057] In one example, in order to build a bootstrap infrastructure that provides a collection of kernel services, some kernel sen-ices may be replicated from a public cloud service platform at 310. The replication of the kernel services from the public cloud service platform may be performed based on configuration information, wherein the configuration information decideswhich services should be included in the collection of kernel services provided by the bootstrap infrastructure. The workflow engine may obtain copies of the corresponding kernel services in the public cloud service platform and arrange the obtained copies on a server for forming the bootstrap infrastructure.
[0058] In one example, in order to build a bootstrap infrastructure that provides a collection of kernel services, some kernel services may be generated through utilizing a seed server at 311. The seed server is the first server or a few of servers in the bootstrap infrastructure that is / are firstly configured to be enabled, which may provide the most underlying services used to deploy the target cloud service platform. These most underlying services are typically not user-oriented, but rather provide internal functions used to facilitate the initial running of the data center. For example, these most underlying services may include services for managing servers so that more servers in the data center may be configured to provide kernel services at a subsequent stage. The seed server and the most underlying services provided by the seed server may invoke more servers in the bootstrap infrastructure based on configuration information to generate kernel services in the more servers. Utilizing the seed server to generate the kernel services may reduce the association between the kernel services provided by the bootstrap infrastructure and the existing services in the public cloud platform as much as possible, which helps to avoid the eventually deployed target cloud service platform being affected by the existing services in the public cloud platform.
[0059] At 320, the bootstrap infrastructure may be built through utilizing kernel services replicated from the public cloud service platform and / or generated by the seed server, and the built bootstrap infrastructure may provide a collection of kernel services. The kernel services in the collection of kernel services implement internal kernel functions of the target cloud service platform.
[0060] In one example, the collection of kernel services may also include other services that are not closely related to the internal kernel functions of the target cloud service platform, for example, a monitoring service, a logging service, etc. The monitoring service may be used to monitor operational data for the deployment process of the target cloud service platform. The logging service may be used to record log data for the deployment process of the target cloud service platform. These services are typically created at a later stage of the deployment of the target cloud service platform. However, in embodiments of the present disclosure, these services may be created in advance at the stage of building the bootstrap infrastructure to avoid some data being missed in the early stage of the deployment of the target cloud service platform.
[0061] In one example, some kernel services in the collection of kernel sendees of the bootstrap infrastructure and the corresponding kernel services in the public cloud serviceplatform may be the same services. In this case, these kernel services in the collection of kernel services and the corresponding kernel services in the public cloud service platform should employ the same version, in order to ensure service parity.
[0062] In one example, a problem of circular dependency for kernel services may be encountered during the process of generating the collection of kernel services. The problem of cyclic dependency for kernel services is caused by the fact that there may be dependency between the kernel services. For example, the creation of a first kernel service may depend on a second kernel service, the creation of the second kernel service may depend on a third kernel service, and the creation of the third kernel service may depend on the first kernel service. As a result, the dependency relationship among the three kernel services forms a complete closed loop, resulting in that it is impossible to start performing the collection of kernel services creating process from any of the kernel services. In order to break this closed-loop circular dependency of kernel services, existing services in the public cloud service platform may be utilized to create at least one kernel service of a plurality of kernel services with circular dependency relationship. For example, the same existing service in the public cloud service platform as the first kernel service may be utilized to first create the third kernel service in the bootstrap infrastructure that is dependent on the first kernel service, and then the created third kernel service may be utilized to create the second kernel service in the bootstrap infrastructure that is dependent on the third kernel service, and finally the created second kernel sen-ice may be utilized to create the first kernel service in the bootstrap infrastructure that is dependent on the second kernel service. In this way, the existing service in the public cloud service platform may be utilized to break the closed-loop circular dependency of kernel services.
[0063] In one example, the public cloud service platform may include a plurality of data centers. The bootstrap infrastructure may be built in a data center in the public cloud service platform that has the geographic location closest to a data center of the target cloud service platform. This helps to make an efficient data transmission between the bootstrap infrastructure and the target cloud service platform at a later stage.
[0064] In one example, a plurality of target cloud service platforms 130 may be deployed simultaneously. In this case, a respective bootstrap infrastructure 116 may be built in the public cloud service platform 110 for each target cloud service platform 130 respectively.
[0065] At 330. a separate identity’ manager may be created in the bootstrap infrastructure. An identity manager is a system for managing user access permission, which is used to control which users can access which resources based on respective access permissions assigned to users by a system administrator. When a user attempts to access a resource, the identity7manager may allow the user or prevent the user from performing an access operation based on the accesspermission of the user. The identity manager created in the bootstrap infrastructure is specialized for the target cloud service platform and therefore, may be separated from the existing identity manager in the public cloud sendee platform. The separation between the identity manager created in the bootstrap infrastructure and the existing identity manager in the public cloud service platform may be embodied in that, a system administrator of the existing identity manager does not have permission to log into the identity manager created at 330 to perform permission assignment operations. Instead, the identity manager created at 330 may be managed by a platform operator responsible for operating the target cloud sen ice platform. In the case where the target cloud service platform is an isolated cloud service platform, the creation of the separate identity manager can help to fulfill the data security and compliance requirements of the isolated cloud sendee platform.
[0066] According to embodiments of the present disclosure, after the building of the bootstrap infrastructure is completed, it may be waited for the construction of the data center of the target cloud service platform to be completed, in order to proceed to a next stage for creating a collection of target services in the target cloud service platform. During the waiting process, kernel services in the collection of kernel services provided by the bootstrap infrastructure may be updated in the public cloud service platform, to facilitate service parity between the kernel services provided by the bootstrap infrastructure and corresponding services in the public cloud service platform. In one example, the updating of the kernel services may be implemented through utilizing a control plane service of the bootstrap infrastructure. The development management platform may provide updated codes to the control plane to update the version of the kernel services. This allows the kernel sendees in the collection of kernel services and corresponding sen-ices in the public cloud senice platform to be updated at the same cadence. As a result, the kernel services in the collection of kernel senices and the corresponding services in the public cloud service platform may satisfy the service parity requirement. In one example, in a similar manner, when a plurality of target cloud service platforms are built at the same time, there may also be service parity between a plurality of collections of kernel senices respectively associated with the plurality of target cloud service platforms.
[0067] According to embodiments of the present disclosure, after the construction of the data center is completed, a next stage may be entered to create the collection of target services in the target cloud service platform.
[0068] FIG. 4 illustrates an exemplary process 400 for creating a collection of target senices according to embodiments. Operations in the process 400 may be performed by the workflow engine 112 as illustrated in FIGS. 1 A to ID.
[0069] At 410. kernel senices in a collection of kernel services may be migrated from abootstrap infrastructure to a target cloud service platform. Exemplarily, the migration process may be divided into three stages. At a first stage, the kernel services in the collection of kernel services may be fully provided by N serv ers in the bootstrap infrastructure; at a second stage, the kernel services may be jointly provided by the N servers in the bootstrap infrastructure and M servers in the target cloud service platform; and at a third stage, the kernel services may be fully provided by the M servers in the target cloud service platform. These three stages implement a process of gradually migrating the collection of kernel services from the bootstrap infrastructure in the public cloud sen-ice platform to the target cloud service platform. In one example, moving from the first stage into the second stage involves a process of transferring data from the bootstrap infrastructure to the target cloud service platform. For example, copies and operational data of kernel services may be transferred from the bootstrap infrastructure to the target cloud service platform, such that servers in the target cloud service platform and servers in the bootstrap infrastructure may provide the same kernel services in synchronization. In one example, moving from the first stage into the second stage may not involve a process of transferring data from the bootstrap infrastructure to the target cloud sendee platform, e.g., some services such as web-based services do not require state information to be maintained during operation, and thus may be scaled to any servers to cause these servers to provide the same kernel services. In one example, the above two approaches may be combined, e.g.. the migrating process of part of the kernel services in the collection of kernel services may involve data transfer, while the migrating process of part of the kernel services may not involve data transfer.
[0070] At 420, the migrated kernel services may be scaled as a collection of target services. Scaling the migrated kernel services as the collection of target services may be implemented through adding some services on the basis of the migrated kernel services. In one implementation, the workflow engine may determine which services are required to be added based on a product service list. In one example, the workflow engine may configure the kernel services in the collection of kernel services to cause the migrated kernel services to scale, in the target cloud service platform, the services to be added. For example, the migrated kernel services may invoke more servers in the target cloud service platform to generate the added services. In one example, the development management platform may release the added services to the target cloud service platform over a network connection between the development management platform and the target cloud service platform.
[0071] In one example, it may encounter a problem of circular dependency for target services in the process of creating the collection of target services in the target cloud service platform. In order to break the closed-loop circular dependency of target services, existing services in the public cloud service platform, including kernel services in the bootstrapinfrastructure or other services in the public cloud service platform that are outside of the bootstrap infrastructure, may be utilized to create at least one target service of a plurality of target services with a circular dependency relationship. In the same manner as solving the problem of circular dependency for kernel services, existing services in the public cloud service platform may be utilized to break the closed-loop circular dependency for target services.
[0072] In one example, creating the collection of target services in the target cloud service platform may be an ongoing process. For example, when a dependency of a certain target service required by the target cloud service platform is satisfied, the target service may be created in the target cloud service platform based on the collection of kernel services. During the process of creating the target cloud service platform, some overlapping functions between the collection of kernel services and the collection of target sendees may be controlled by the collection of target service.
[0073] According to embodiments of the present disclosure, completion of the creation of the collection of target services means the completion of the deployment process for the target cloud service platform, and accordingly, the target cloud sendee platform may be operated at this time in a mode close to that of a delivered product. In this case, the target cloud service platform may be enabled.
[0074] FIG. 5 illustrates an exemplary process 500 for enabling a target cloud service platform according to embodiments. In one example, the operations in the process 500 may be performed by a workflow engine within the target cloud service platform.
[0075] At 510, the target cloud service platform may be enabled. In one example, before enabling the target cloud service platform, it may be determined whether the target cloud service platform satisfies an enabling condition. For example, a risk assessment, a security test, a data compliance review, etc., may be performed on the target cloud service platform. The target cloud service platform may be enabled in a case that it is determined that the target cloud service platform satisfies the enabling condition.
[0076] At 520, a network connection between the bootstrap infrastructure and the target cloud service platform may be disconnected, or an access restriction may be imposed on the network connection, e.g., a firewall may be imposed on the network connection.
[0077] In one example, after the target cloud service platform is enabled, the built bootstrap infrastructure may be discarded in the public cloud service platform. For example, virtual resources occupied by the bootstrap infrastructure may be released for use by other tenants in the public cloud service platform. In one example, the bootstrap infrastructure may be maintained in the public cloud service platform for use of subsequent security, data compliance, and review of other aspects for the target cloud service platform.
[0078] In one example, after the target cloud service platform is enabled, certificates, keys, etc., may be updated in the target cloud sendee platform to avoid security problems.
[0079] In one example, after the target cloud service platform is enabled, the development management platform may manage the target cloud service platform in a similar manner as it manages the public cloud service platform, e.g., releasing new services to the target cloud service platform, updating sen ices in the target cloud service platform, etc. In this case, a network connection between the development management platform and the target cloud service platform may be maintained. In one example, after the target cloud service platform is enabled, the network connection between the development management platform and the target cloud service platform may be disconnected or an access restriction may be imposed on the network connection, which allows the target cloud service platform to be sufficiently isolated from the outside world to meet further data security and compliance requirements.
[0080] FIG. 6 illustrates a flowchart of an exemplary method 600 for deploying a target cloud service platform according to embodiments.
[0081] At 610, configuration information for a target cloud service platform may be obtained.
[0082] At 620. a bootstrap infrastructure may be built in a public cloud service platform based on the configuration information, the bootstrap infrastructure provides a collection of kernel services associated with the target cloud service platform.
[0083] At 630, a collection of target services may be created in the target cloud service platform based on the collection of kernel services.
[0084] In one implementation, the method 600 may further comprise building a configuration storage for storing the configuration information in the public cloud service platform, wherein the obtaining configuration information comprises obtaining the configuration information from the configuration storage.
[0085] In one implementation, the configuration information may comprise buildout artifacts for the target cloud service platform.
[0086] In one implementation, kernel services in the collection of kernel services may be generated at least through utilizing a seed server in the bootstrap infrastructure. In one implementation, the kernel services in the collection of kernel services may be replicated from the public cloud service platform based on the configuration information.
[0087] In one implementation, the creating a collection of target services in the target cloud service platform based on the collection of kernel services may comprise: migrating kernel services in the collection of kernel services from the bootstrap infrastructure to the target cloud service platform.
[0088] The creating a collection of target sendees in the target cloud service platform based on the collection of kernel sendees may further comprise: scaling the migrated kernel services as the collection of target services in the target cloud senice platform according to a product service list associated with the target cloud service platform.
[0089] In one implementation, the creating a collection of target services in the target cloud service platform based on the collection of kernel services may comprise: based on dependency relationship among a plurality of target sendees in the collection of target sendees, creating at least one target service of the plurality of target services through utilizing an existing sen ice in the public cloud service platform.
[0090] In one implementation, the building a bootstrap infrastructure may comprise: based on dependency relationship among a plurality7of kernel services in the collection of kernel services, creating at least one kernel service of the plurality7of kernel services through utilizing an existing service in the public cloud service platform.
[0091] In one implementation, the target cloud service platform may comprise a cloud service platform isolated from the public cloud service platform, and the method 600 may further comprise: after the collection of target services is created, disconnecting a network connection between the bootstrap infrastructure and the target cloud service platform or imposing access restriction to the network connection.
[0092] In one implementation, the method 600 may further comprise: updating kernel services in the collection of kernel services provided by the bootstrap infrastructure so as to meet a service parity requirement.
[0093] In one implementation, the method 600 may further comprise: creating an identity7manager associated with the target cloud sendee platform in the bootstrap infrastructure, wherein the created identity manager is separate from an existing identity manager in the public cloud sendee platform.
[0094] In one implementation, the collection of kernel services may comprise at least one of a monitoring service and a logging service for deployment of the target cloud service platform.
[0095] It should be appreciated that the method 600 may further comprise any steps / processes for deploying the target cloud service platform according to the above embodiments of the present disclosure.
[0096] FIG. 7 illustrates an exemplary apparatus 700 for deploying a target cloud service platform according to embodiments.
[0097] The apparatus 700 may comprise: a configuration information obtaining module 710 for obtaining configuration information for a target cloud service platform; a bootstrap infrastructure building module 720 for building a bootstrap infrastructure in a public cloudservice platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud sendee platform; and a collection of target services creating module 730 for creating a collection of target services in the target cloud service platform based on the collection of kernel sen ices.
[0098] Additionally, the apparatus 700 may further include any other module configured to perform any operation of the method for deploying a target cloud service platform according to the above embodiments of the present disclosure.
[0099] FIG. 8 illustrates an exemplary apparatus 800 for deploying a target cloud service platform according to embodiments.
[0100] The apparatus 800 may include at least one processor 810. The apparatus 800 may also include a memory 820 coupled to the at least one processor 810. The memory 820 may store computer-executable instructions that, when the computer-executable instructions are executed, cause the at least one processor 810 to: obtain configuration information for a target cloud service platform; build a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform; and create a collection of target services in the target cloud service platform based on the collection of kernel services. Additionally, the at least one processor 810 may be further configured to perform any other operation of the method for deploying a target cloud service platform according to the above embodiments of the present disclosure.
[0101] Embodiments of the present disclosure may be implemented in a non-transitory computer-readable medium. The non-transitory computer-readable medium may include instructions that, when the instructions are executed, may cause at least one processor to: obtain configuration information for a target cloud service platform; build a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform; and create a collection of target services in the target cloud service platform based on the collection of kernel sendees. Additionally, the instructions, when being executed, may also cause the at least one processor to perform any step / process of the method for deploying a target cloud service platform according to the above embodiments of the present disclosure.
[0102] Embodiments of the present disclosure present a cloud service system comprising a public cloud service platform and a target cloud service platform. The public cloud service platform may comprise a configuration storage, a workflow engine, and a bootstrap infrastructure. The configuration storage may be for storing configuration information for the target cloud service platform. The workflow engine may be for obtaining the configurationinformation from the configuration storage and may build the bootstrap infrastructure based on the configuration information. The bootstrap infrastructure may be for providing a collection of kernel services associated with the target cloud service platform. The workflow engine may be further for creating a collection of target services in the target cloud service platform based on the collection of kernel services. The target cloud service platform may be for providing the collection of target services.
[0103] In one implementation, the configuration information may comprise buildout artifacts for the target cloud service platform.
[0104] In one implementation, the bootstrap infrastructure may comprise a seed server, and kernel services in the collection of kernel sendees may be generated at least through utilizing the seed server; or kernel services in the collection of kernel services may be replicated by the workflow engine from the public cloud service platform based on the configuration information.
[0105] In one implementation, the workflow engine may be further for creating a collection of target services by: migrating kernel services in the collection of kernel services from the bootstrap infrastructure to the target cloud service platform.
[0106] The workflow engine may be further for creating a collection of target services by: scaling the collection of kernel sen-ices as the collection of target services in the target cloud service platform according to a product service list associated with the target cloud service platform.
[0107] In one implementation, the target cloud service platform may comprise a cloud service platform isolated from the public cloud service platform, and the workflow engine may be further for: after the collection of target services is created, disconnecting a network connection between the bootstrap infrastructure and the target cloud service platform or imposing access restriction to the network connection.
[0108] Additionally, the components included in the cloud service system may be further configured respectively to perform any other operation of the method for deploying a target cloud service platform according to the above embodiments of the present disclosure.
[0109] Embodiments of the present disclosure present a computer program product comprising computer programs, the computer programs being operable by a processor for: obtaining configuration information for a target cloud service platform; building a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform; and creating a collection of target services in the target cloud service platform based on the collection of kernel services. Additionally, the computer programs may also be executed by the processor for performing any step / process of the method for deploying a targetcloud service platform according to the above embodiments of the present disclosure.
[0110] It should be appreciated that all the operations in the methods described above are merely exemplary7, and the present disclosure is not limited to any operations in the methods or orders of these operations, and should cover all other equivalents under the same or similar concepts.
[0111] Moreover, the articles “a” and ‘'an’’ as used in this specification and the appended claims should generally be construed to mean “one” or “one or more” unless specified otherwise or clear from the context to be directed to a singular form.
[0112] It should also be appreciated that all the modules in the apparatuses described above may be implemented in various approaches. These modules may be implemented as hardware, software, or a combination thereof. Moreover, any of these modules may be further functionally divided into sub-modules or combined together.
[0113] Processors have been described in connection with various apparatuses and methods. These processors may be implemented using electronic hardware, computer software, or any combination thereof. Whether such processors are implemented as hardware or software will depend upon the particular application and overall design constraints imposed on the system. By way of example, a processor, any portion of a processor, or any combination of processors presented in the present disclosure may be implemented with a micro-processor, microcontroller, digital signal processor (DSP), a field-programmable gate array (FPGA), a programmable logic device (PLD), a state machine, gated logic, discrete hardware circuits, and other suitable processing components configured to perform the various functions described in the present disclosure. The functionality of a processor, any portion of a processor, or any combination of processors presented in the present disclosure may be implemented with software being executed by a microprocessor, micro-controller, DSP, or other suitable platform.
[0114] Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, threads of execution, procedures, functions, etc. The software may reside on a computer-readable medium. A computer-readable medium may include, by way of example, memory such as a magnetic storage device (e.g., hard disk, floppy disk, magnetic strip), an optical disk, a smart card, a flash memory device, random access memory (RAM), read only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), a register, or a removable disk. Although a memory is shown as being separate from the processor in various aspects presented in this disclosure, the memory may also be internal to the processor (e.g., a cache or a register).
[0115] The previous description is provided to enable any person skilled in the art topractice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other aspects. Thus, the claims are not intended to be limited to the aspects shown herein. All structural and functional equivalents to the elements of the various aspects described throughout the present disclosure that are known or later come to be known to those of ordinary skilled in the art are intended to be encompassed by the claims.
Claims
CLAIMS1 . A method for deploying a target cloud service platform, comprising: obtaining configuration information for a target cloud service platform; building a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform; and creating a collection of target sendees in the target cloud service platform based on the collection of kernel services.
2. The method of claim 1, further comprising: building a configuration storage for storing the configuration information in the public cloud service platform, wherein the obtaining configuration information comprises obtaining the configuration information from the configuration storage.
3. The method of claim 1, wherein the configuration information comprises buildout artifacts for the target cloud sendee platform.
4. The method of claim 1, wherein kernel services in the collection of kernel services are generated at least through utilizing a seed server in the bootstrap infrastructure; or kernel sendees in the collection of kernel services are replicated from the public cloud service platform based on the configuration information.
5. The method of claim 1, wherein the creating a collection of target sendees in the target cloud service platform based on the collection of kernel services comprises: migrating kernel services in the collection of kernel services from the bootstrap infrastructure to the target cloud service platform.
6. The method of claim 5, wherein the creating a collection of target sendees in the target cloud service platform based on the collection of kernel sendees further comprises: scaling the migrated kernel services as the collection of target services in the target cloud service platform according to a product service list associated with the target cloud service platform.
7. The method of claim 1, wherein the creating a collection of target services in the target cloud service platform based on the collection of kernel services comprises: based on dependency relationship among a plurality of target services in the collection of target services, creating at least one target sendee of the plurality of target services through utilizing an existing service in the public cloud service platform.
8. The method of claim 1, wherein the building a bootstrap infrastructure comprises:based on dependency relationship among a plurality of kernel services in the collection of kernel services, creating at least one kernel service of the plurality of kernel services through utilizing an existing service in the public cloud service platform.
9. The method of claim 1, wherein the target cloud service platform comprises a cloud service platform isolated from the public cloud service platform, and the method further comprises: after the collection of target services is created, disconnecting a network connection between the bootstrap infrastructure and the target cloud service platform or imposing access restriction to the network connection.
10. The method of claim 1 , further comprising: updating kernel services in the collection of kernel services provided by the bootstrap infrastructure so as to meet a service parity' requirement.
11. The method of claim 1, further comprising: creating an identity manager associated with the target cloud service platform in the bootstrap infrastructure, wherein the created identity manager is separate from an existing identity manager in the public cloud serv ice platform.
12. The method of claim 1, wherein the collection of kernel services comprises at least one of a monitoring service and a logging service for deployment of the target cloud service platform.
13. A cloud service system, comprising a public cloud service platform and a target cloud service platform, wherein the public cloud service platform comprises a configuration storage, a workflow engine, and a bootstrap infrastructure, wherein the configuration storage is for storing configuration information for the target cloud service platform; the workflow engine is for obtaining the configuration information from the configuration storage, and building the bootstrap infrastructure based on the configuration information; the bootstrap infrastructure is for providing a collection of kernel services associated with the target cloud service platform; and the workflow engine is further for creating a collection of target services in the target cloud service platform based on the collection of kernel services, and the target cloud service platform is for providing the collection of target services.
14. The cloud service system of claim 13, wherein the configuration information comprises buildout artifacts for the target cloud service platform.
15. The cloud service system of claim 13, whereinthe bootstrap infrastructure comprises a seed server, and kernel services in the collection of kernel services are generated at least through utilizing the seed server; or kernel services in the collection of kernel services are replicated by the workflow engine from the public cloud service platform based on the configuration information.
16. The cloud service system of claim 13, wherein the workflow engine is further for creating a collection of target services by: migrating kernel services in the collection of kernel services from the bootstrap infrastructure to the target cloud service platform.
17. The cloud service system of claim 16, wherein the workflow engine is further for creating a collection of target services by: scaling the migrated kernel services as the collection of target services in the target cloud service platform according to a product service list associated with the target cloud service platform.
18. The cloud service system of claim 13, wherein the target cloud service platform comprises a cloud service platform isolated from the public cloud service platform, and the workflow engine is further for: after the collection of target services is created, disconnecting a network connection between the bootstrap infrastructure and the target cloud sendee platform or imposing access restriction to the network connection.
19. An apparatus for deploying a target cloud service platform, comprising: at least one processor; and a memory storing computer-executable instructions that, when executed, cause the at least one processor to: obtain configuration information for a target cloud service platform, build a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform, and create a collection of target services in the target cloud service platform based on the collection of kernel sendees.
20. A non-transitory computer-readable medium, comprising instructions that, when executed, cause at least one processor to: obtain configuration information for a target cloud service platform; build a bootstrap infrastructure in a public cloud service platform based on the configuration information, the bootstrap infrastructure providing a collection of kernel services associated with the target cloud service platform; andcreate a collection of target services in the target cloud service platform based on the collection of kernel services.
Citation Information
Patent Citations
User interface for critical path resources
US20230251873A1