In-Service Software Upgrade for Virtual Switching Stacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In-service software upgrades (ISSU) in complex virtual switching stacks often disrupt traffic flow due to the need for rebooting switches, which can lead to significant unavailability periods, especially in networks with many switches, impacting performance.
Innovation Solution
The solution involves orchestrating ISSU across multiple phases, where subsets of switches with different roles are upgraded without interrupting traffic by installing new software elements, freezing line card states, and synchronizing databases, allowing seamless failover and upgrade of conductor and standby switches without traffic disruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional software upgrade methods are used in virtual switching stacks, then software can be updated, but traffic flow is interrupted and unavailability increases
Solution Approach 1:
The upgrade process is divided into multiple phases (first phase for conductor switch, second phase for standby switch, third phase for member switches). Each phase upgrades specific subsets of switches independently, allowing the system to maintain functionality during upgrades by segmenting the overall upgrade task into manageable, non-blocking portions.
Solution Approach 2:
The standby switch is upgraded before the conductor switch in the first phase. This preliminary action allows the standby switch to be ready to take over control plane functions if needed, while the conductor switch remains operational. The freezing of line card states before upgrades ensures that no traffic disruption occurs during the actual upgrade process.
2Productivity
If all switches are upgraded simultaneously, then upgrade efficiency is improved, but traffic disruption increases
Solution Approach 1:
The upgrade process segments switches into different groups based on their roles (conductor, standby, member) and upgrades them in separate phases. This segmentation ensures that at any given time, only non-critical switches are being upgraded, while critical conductor and standby switches remain operational or are upgraded in a controlled manner that does not disrupt traffic flow.
Solution Approach 2:
The upgrade process dynamically adjusts the upgrade sequence based on the operational state of each switch type. The conductor switch is upgraded after the standby switch to ensure control plane continuity. The freezing and unfreezing of line card states is dynamically managed to prevent traffic disruption during upgrades while allowing efficient progression through upgrade phases.
3Reliability
If conductor switch is upgraded first, then control plane is maintained, but standby switch cannot be upgraded
Solution Approach 1:
The standby switch is upgraded in the first phase before the conductor switch. This preliminary action is possible because the standby switch does not hold critical control plane functions - those are maintained by the conductor switch. Upgrading the standby switch first prepares it for potential failover while the conductor switch remains operational, allowing upgrade progress to be made without compromising control plane continuity.
Solution Approach 2:
The upgrade process uses dynamic role assignment and state management. The standby switch is upgraded while the conductor switch maintains control plane functions. After the standby switch is upgraded, the system dynamically prepares for its potential promotion to conductor role. The freezing of line card states during upgrades ensures that control plane continuity is maintained regardless of which switch is being upgraded at any given time.
Data Source
AI summary
One aspect of the present technology can provide a system for facilitating in-service software upgrade (ISSU) for a switch in a virtual switching stack. During operation, the system can initiate ISSU that facilitate uninterrupted traffic flow. The system can upgrade a first set of daemons of the switch that manage operations of the switch. The system can also upgrade a database stored on the switch. The database can store operational information of the switch. The system can further upgrade a second set of daemons of the switch that configure forwarding information on the forwarding hardware of the switch and facilitate data-plane operations for the switch. The forwarding information configured on the forwarding hardware can remain unchanged during the upgrade. The system can configure the upgraded second set of daemons to obtain control-plane information from a standby switch of a conductor switch of the virtual switching stack.


