Secondary Storage Controller Failover Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data replication environments, secondary storage systems are underutilized during normal operations to ensure they can meet performance requirements in case of a failover, leading to suboptimal resource utilization.
Innovation Solution
Implementing a mechanism where the storage system controller at a secondary site allows non-critical workloads to access storage volumes during normal operations, but switches to a failover mode by blocking or lowering priority of these workloads' access requests in case of a failover notification, thereby allocating all resources to primary workloads, and optionally transferring and merging volume priority settings to ensure seamless transition and maximize resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secondary storage systems are reserved exclusively for primary workload failover, then reliability of data protection is improved, but storage resource utilization deteriorates
Solution Approach 1:
The storage system dynamically adjusts the allocation of secondary storage resources based on operational mode. During normal operation, secondary storage is shared between local workloads and reserved for failover. Upon detecting a failover condition, the system rapidly reconfigures storage access rights to prioritize primary workload data, ensuring both resource utilization and protection reliability are optimized for current conditions.
Solution Approach 2:
The system changes the access parameters of storage volumes based on operational state. Volume access rights, priority levels, and I/O throttling parameters are modified dynamically. During normal operation, local workloads receive standard access parameters. When failover is detected, parameters are changed to grant priority access to primary workload volumes while reducing or blocking access to non-critical volumes.
2Productivity
If secondary storage is made available to local workloads during normal operation, then storage utilization is improved, but performance availability during failover deteriorates
Solution Approach 1:
The system performs preliminary actions by pre-configuring storage volume priorities and access parameters during normal operation. Volume attributes are set to identify critical versus non-critical workloads in advance. When failover is detected, these pre-configured settings enable rapid reconfiguration without requiring real-time analysis, ensuring performance availability is maintained while allowing local workload access during normal conditions.
Solution Approach 2:
The storage system implements dynamic access control that adapts to operational conditions. During normal operation, the system permits local workloads to access secondary storage volumes, maximizing utilization. Upon detecting a failover condition, the system dynamically switches to a different access control mode that prioritizes primary workload access, ensuring performance requirements are met while having allowed local workloads to use storage resources during normal conditions.
3Speed
If the system blocks all non-critical workload access during failover, then primary workload performance is improved, but workload flexibility and system adaptability deteriorate
Solution Approach 1:
The system applies different quality levels of service to different workloads. During failover, critical primary workloads receive high-priority access with minimal latency, while non-critical workloads receive reduced priority or blocked access. The system maintains this differentiation by continuously monitoring workload priorities and adjusting storage access parameters accordingly, ensuring performance for critical workloads while maintaining system adaptability through priority-based resource allocation rather than complete blocking.
Data Source
AI summary
Mechanisms for controlling access to storage volumes on the secondary storage system is provided. A determination is made as to whether a first site computing device has sent a notification of a failure condition of a first site. In response to a determination that the notification of the failure condition of the first site has not been received, secondary workloads of a second site computing device are permitted to access storage volumes on the secondary storage system. In response to a determination that the notification of the failure condition of the first site has been received, a mode of operation of the second site is modified from a normal mode of operation to a failure mode of operation. In the failure mode of operation, the storage system controller of the second site blocks at least a portion of access requests from secondary workloads of the second site computing device.


