Failover Service Coordinates Application Cell State
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for network-based failover services are overly complex, increase design work for customers, and lack features for customer visibility and control, leading to inadequate management of data integrity during application failures.
Innovation Solution
The implementation of a highly available failover service that coordinates failover workflows across multiple availability zones, allowing customers to manually or automatically trigger failovers, provides a visual editor for dependency tree creation, and ensures data integrity through event history logs and authoritative state information management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing failover mechanisms are implemented, then application availability is maintained during failures, but system complexity and customer design workload increase
Solution Approach 1:
The patent introduces a failover service as an intermediary component that manages failover workflows between application cells. This service abstracts the complexity of failover management from customers, providing a coordinated failover mechanism while maintaining application availability. The failover service acts as a mediator that handles the complex coordination logic, thereby resolving the contradiction between maintaining reliability and reducing system complexity.
2Reliability
If existing failover mechanisms are implemented, then application continuity is ensured, but customer control and visibility over failover processes are reduced
Solution Approach 1:
The patent implements feedback mechanisms through event history logs that record failover events and states. These logs provide customers with visibility into the failover process, allowing them to monitor and understand what is happening during failover events. The feedback mechanism maintains application continuity while simultaneously improving customer control and visibility, resolving the stated contradiction.
3Ease of operation
If manual failover management is required, then customer control is maintained, but operational time and effort increase during failures
Solution Approach 1:
The patent implements preliminary action by allowing customers to pre-configure failover workflows and policies before failures occur. The system stores these configurations and automatically executes them when failures are detected, eliminating the need for customers to make decisions during critical failure moments. This preliminary configuration approach maintains customer control over the failover behavior while significantly reducing operational time and effort during actual failures.
4Manufacturing precision
If data integrity checks are performed during failover, then data consistency is maintained, but failover execution time increases
Solution Approach 1:
The patent applies partial action by implementing selective data integrity checks during failover. Rather than performing comprehensive checks on all data, the system performs targeted checks on critical data elements that are essential for maintaining data consistency. This partial verification approach maintains adequate data integrity while reducing the time overhead associated with exhaustive checking, thereby resolving the contradiction between data integrity and failover execution time.
Data Source
AI summary
a data store and a proxy system. The data store may store state data relating to a cell of the application, each cell having a state. The proxy system may identify whether the cell is operating in the active state, the passive state, or the fenced state and access a database of acceptable and unacceptable commands for the cell's state. For each request directed to the cell received, the proxy system may identifies the request as an acceptable request based on identifying that one or more commands of the request are acceptable to process in the cell's state or identifies the request as an unacceptable request based on identifying that one or more commands of the request are unacceptable to process in the cell's state. The proxy system then conveys the acceptable requests and unacceptable requests appropriately.


