Partitioned Connector Scope Management in Multitenant Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing application server environments face challenges in supporting connectors and resource adapters in a multitenant setup, where resources and applications need to be isolated and managed efficiently across partitions, while ensuring security and administrative isolation between tenants.
Innovation Solution
The system provides a method for deploying and managing connectors and resource adapters within a multitenant application server environment by using partitions as administrative and runtime subdivisions, with a connector container determining the partition scope of deployed resource adapters to ensure isolation and access control, and utilizing resource group templates to configure and deploy resources specific to each partition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If connectors and resource adapters are deployed in a multitenant application server environment, then resource sharing and scalability are improved, but resource isolation and security between tenants deteriorate
Solution Approach 1:
The patent introduces partitions as administrative and runtime subdivisions of the domain, creating isolated environments for different tenants. Each partition can have its own resource adapters and connectors, enabling resource sharing at the domain level while maintaining isolation at the partition level. This segmentation resolves the contradiction by allowing multiple tenants to share the same application server infrastructure without compromising security or resource isolation.
2Reliability
If partition-level resource adapters are deployed to ensure tenant isolation, then security and isolation are improved, but device complexity and management overhead deteriorate
Solution Approach 1:
The patent implements a universal connector container that handles both domain-level and partition-level resource adapters through a unified mechanism. The connector container determines the scope (domain or partition) of resource adapters and manages them accordingly, eliminating the need for separate management mechanisms for different scopes. This multi-functionality reduces management overhead while maintaining secure tenant isolation through partition-level resource adapters.
3Adaptability or versatility
If domain-level resource adapters are used for shared resources, then adaptability and resource sharing are improved, but tenant-specific access control and isolation deteriorate
Solution Approach 1:
The patent segments resource adapter management into two levels: domain-level for shared resources and partition-level for tenant-specific resources. The connector container automatically determines the scope of each resource adapter and enforces access control accordingly. This segmentation allows domain-level resource adapters to provide shared functionality while partition-level resource adapters ensure tenant-specific access control, resolving the contradiction between resource sharing and access control.
Data Source
AI summary
In accordance with an embodiment, described herein is a system and method for supporting the use of connectors in an application server environment. The method can provide, a plurality of deployable resources which can be used within the application server environment, and one or more partitions, wherein each partition provides an administrative and runtime subdivision of the domain. The methods and systems can associate one or more deployed partition-level resource adapters to the one or more partitions, each of the one or more deployed partition-level resource adapters associated with one of the one or more partitions. Finally, the methods and systems can determine, by a connector container, a partition scope of one of the one or more deployed partition-level resource adapters.


