Multi-tenant Cloud Resource Pool Segmentation for Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Platform-as-a-Service (PaaS) offerings face inefficiencies due to the need for significant expertise and resources to manage web applications across different hypervisors and cloud providers, leading to costly and resource-intensive virtual machine (VM) management, especially when multiple customers' applications are deployed on separate VMs, which can result in underutilization of resources.
Innovation Solution
A method for command execution in a multi-tenant cloud hosting environment where a broker layer coordinates actions across multiple resource pools and nodes, allowing multiple applications from different owners to share resources while maintaining security and segregation through techniques like SELinux security labeling and Linux control groups, enabling efficient resource utilization and simplified application management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple customers' applications are deployed on separate VMs, then security and isolation are improved, but resource utilization deteriorates and costs increase
Solution Approach 1:
The system segments the VM into isolated resource pools using Linux control groups (cgroups) and SELinux security labels. Each customer's application components are assigned to specific resource pools with dedicated CPU, memory, and I/O resources, ensuring security and isolation while sharing the same physical VM. This segmentation allows multiple customers to coexist on a single VM without resource contention or security breaches.
Solution Approach 2:
The patent merges multiple customers' applications onto a single VM, combining resources that would otherwise be wasted in separate VMs. By using resource pools and orchestration, the system efficiently packs multiple applications together, improving overall resource utilization and reducing the total number of VMs needed, while maintaining security through isolation mechanisms.
2Reliability
If a VM is sized to accommodate a single application, then application performance is improved, but resource utilization deteriorates when the application does not fully utilize the VM resources
Solution Approach 1:
The system dynamically allocates resources within the VM to different applications based on their actual needs and performance requirements. The orchestration layer can adjust resource pool configurations, CPU shares, memory limits, and I/O priorities dynamically, allowing applications to receive appropriate resources without over-provisioning. This dynamic allocation ensures application performance while minimizing wasted resources.
3Productivity
If applications are deployed across multiple nodes for distribution, then scalability and fault tolerance are improved, but command coordination and management complexity increase
Solution Approach 1:
The patent introduces an intermediary orchestration layer that manages command coordination across distributed applications and nodes. This intermediary receives customer commands, determines which resource pools and application components are affected, and coordinates execution across multiple nodes. This abstraction layer simplifies command management while maintaining the scalability and fault tolerance benefits of distributed deployment.
Data Source
AI summary
A owner command to an application hosted by a platform as a service (PaaS) system can be performed, in one embodiment, by receiving the command from the authenticated owner at a first resource pool containing a first application component of the application, wherein the first node hosts a plurality of resource pools each containing application components belonging to different application owners. A second resource pool associated with the application is then identified, the second resource pool being hosted on a second node and containing a second application component of the application. The, a command implementation sequence defining the implementation of the received command over multiple application components is executed by performing a first action on the first application component on the first node and performing a second action on the second application component on the second node.


