Kubernetes Custom Resource Locking for Multi-Cloud Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a distributed hybrid multi-cloud environment with Kubernetes clusters, accessing persistent volumes across multiple clusters asynchronously poses challenges, leading to potential corruption without proper locking methods, and existing technologies fail to enable seamless stateful application and database mobility across geographically dispersed locations.

Innovation Solution

The implementation of a system that uses a new Custom Resource within Kubernetes clusters to ensure locking of persistent volumes, providing asynchronous replication and application integrity locking across different clouds, including private on-premises clouds, through the creation of a Custom Resource with an API service for communication between clusters, ensuring data integrity and secure mobility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If persistent volumes are accessed asynchronously across multiple Kubernetes clusters, then application mobility and cloud flexibility are improved, but data corruption risk increases due to lack of proper locking mechanisms

Engineering Contradiction:
Improveapplication mobilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a locking mechanism as an intermediary component that mediates access to persistent volumes across multiple Kubernetes clusters. This locking mechanism coordinates asynchronous access operations between clusters, ensuring that only one cluster can modify a persistent volume at a time, thus preventing data corruption while maintaining application mobility across geographically dispersed locations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple cloud providers are used in a hybrid multi-cloud environment, then service diversity and cost optimization are improved, but system complexity increases due to managing clusters across different clouds

Engineering Contradiction:
Improvecloud flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal locking mechanism that functions across multiple cloud providers and Kubernetes cluster types. The locking system is designed to be cloud-agnostic, providing the same data protection and coordination functionality whether the persistent volumes are accessed from AWS, Azure, Google Cloud, or on-premises clusters, thereby managing complexity while maintaining multi-cloud flexibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If stateful applications are migrated across geographically dispersed clusters, then disaster recovery and business continuity are improved, but data consistency challenges arise due to asynchronous replication

Engineering Contradiction:
Improvedisaster recoveryVSAvoiddata consistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent employs preliminary locking actions before data migration or replication operations begin. The locking mechanism preemptively secures persistent volumes before asynchronous replication starts, ensuring that source and target clusters maintain consistent data states during migration. This preliminary action prevents data consistency issues while enabling disaster recovery capabilities across geographically dispersed locations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11811888B2Ensuring data protection and control in distributed hybrid multi-cloud environment
Publication Date: 2023.11.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11811888B2 patent drawing
  • US11811888B2 patent drawing
  • US11811888B2 patent drawing

AI summary

In an approach for ensuring data protection and control in a distributed hybrid multi-cloud environment with Kubernetes clusters, a processor determines whether a respective quorum of the set of clusters are online. A processor, responsive to determining that a respective quorum of the set of clusters are online, determines whether one or more applications of the cluster are running on another cluster of the set of clusters. A processor, responsive to determining the one or more applications of the cluster are not running on another cluster of the set of clusters, determines whether the cluster is designated as a highest priority cluster. A processor, responsive to determining the cluster is designated as the highest priority cluster, determines whether a main cluster of the set of clusters is online. A processor, responsive to determining the main cluster is online, scales a new custom resource to one (1).