Cross-tenancy Compute Instance Attachment Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in allowing compute instances from different service tenancies to interact and communicate, as they are isolated due to being provisioned by separate infrastructures, making it difficult for customers to benefit from integrated resource utilization across different services.
Innovation Solution
An automated process is implemented to attach compute instances from different service tenancies, enabling communication and cooperative functioning by using a workflow that involves the control planes and identity management and authorization services, allowing for on-demand attachment and detachment of resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If compute instances are provisioned by separate service infrastructures in different tenancies, then service isolation and security are maintained, but communication and interaction between compute instances from different services are blocked
Solution Approach 1:
The patent introduces an attachment mechanism that acts as an intermediary between compute instances from different service tenancies. This attachment creates a controlled communication channel that allows instances to interact while maintaining the underlying tenancy boundaries. The attachment includes authorization configurations that mediate access control, enabling communication without compromising service isolation or security.
2Adaptability or versatility
If compute instances from different service tenancies are allowed to interact, then resource integration and cooperation are improved, but system complexity and authorization management become more difficult
Solution Approach 1:
The attachment mechanism serves as an intermediary that simplifies authorization management by providing a standardized interface for cross-tenancy communication. Rather than managing complex direct authorization between multiple service infrastructures, the attachment abstracts this complexity into a single manageable object with built-in authorization policies.
Solution Approach 2:
The attachment mechanism provides universal functionality for enabling communication between any compute instances from different services, regardless of which specific service tenancies they originate from. This multi-functional approach allows a single mechanism to handle diverse cross-service communication scenarios without requiring service-specific customization.
3Reliability
If compute instances are strictly isolated by service tenancies, then security and control are maintained, but resource utilization efficiency and cooperative functionality are reduced
Solution Approach 1:
The attachment mechanism introduces dynamic flexibility to the previously static tenancy isolation model. Attachments can be created and removed on-demand, allowing the system to dynamically adjust the level of isolation based on operational requirements. This enables compute instances to be isolated when security is paramount but connected when resource utilization efficiency is the priority.
Data Source
AI summary
Techniques are disclosed for creating an attachment between two compute instances. An infrastructure and a generalized method is described for attaching two or more cloud resources (e.g., two compute instances) in spite of the compute resources being provisioned by two different services from different cloud tenancies. An automated process is described that is executed for wiring the compute instances. The automated process can be generally applied to attach any two compute instances providing two different services and provisioned from two different service tenancies.


