Containerized Control Plane for Shadow-Mode Application Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current powered system architectures are rigid and inflexible, requiring recompilation and code changes for new software applications, limiting scalability and real-time operation, and preventing simultaneous testing of new applications without disrupting existing systems.
Innovation Solution
A control system utilizing software containers deployed on a seamless control/data plane, allowing processors to run different applications and switch between normal and shadow modes, enabling modular architecture, flexible application deployment, and real-time testing without affecting the powered system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If point-to-point data connections are used between applications for control and communication, then the architecture provides direct control capability, but the system becomes rigid and not easily scalable
Solution Approach 1:
The system segments applications into isolated containers that communicate through a standardized data plane interface rather than direct point-to-point connections. Each container is an independent unit that can be added, removed, or modified without affecting others, enabling scalability while maintaining controlled communication through the data plane.
Solution Approach 2:
The data plane serves as a universal communication interface that all containers use to interact with the powered system. This single standardized interface replaces multiple point-to-point connections, providing adaptability for new applications while maintaining system control through a consistent architecture.
2Adaptability or versatility
If new software applications are integrated into the embedded deployment node, then the system gains new functionality, but other applications require recompiling and code changes
Solution Approach 1:
Applications are segmented into self-contained containers with their own environments and dependencies. Each container is independently deployable and can be updated without affecting other containers, eliminating the need to recompile or modify existing applications when adding new functionality.
Solution Approach 2:
The container runtime environment acts as an intermediary layer between applications and the host system. This intermediary manages application deployment, isolation, and resource allocation, allowing new applications to be integrated without direct modifications to the host system or other applications.
3Reliability
If new software applications are tested in simulation environments, then system safety is maintained, but real-time operation testing is prevented
Solution Approach 1:
The system dynamically switches containers between shadow mode and active mode. In shadow mode, containers operate in parallel with the active system, observing behavior without affecting operations. The system can dynamically promote shadow containers to active status after validation, enabling both safe simulation and real-time testing.
Solution Approach 2:
New applications are first deployed in shadow mode containers that run alongside the active system, performing preliminary testing in a controlled manner. Once validated in shadow mode, the applications can be promoted to active status, ensuring safety before full real-time operation.
4Reliability
If shadow mode is enabled for a container, then system operation safety is maintained during testing, but the container output cannot change powered system operation
Solution Approach 1:
The shadow mode is a dynamic state that can be switched on or off for containers. When enabled, it provides safety by preventing output changes; when disabled, it allows full operational control. This dynamic switching enables flexible testing scenarios where the level of intervention can be adjusted based on validation needs.
Data Source
AI summary
A powered system is provided that can include a control system having processors communicatively coupled with each other by a data plane of a communication network. The processors may run software applications in containers to control operation of the powered system. The processors may switch which of the processors are running different ones of the software applications operating in different ones of the containers. The processors may change a mode of at least one of the containers to a shadow mode that prevents output from at least a first application of the software applications that is running in the at least one of the containers operating in the shadow mode from changing operation of the powered system.


