Secure Tenant Network Overlays for HCI Shared Storage Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of securely configuring a hyperconverged computing infrastructure (HCI) shared storage pool in a multi-tenant datacenter setting, where per-tenant allocated networking infrastructure must be trusted before configuring the storage pool, while the configuration software needs to be loaded onto node-local storage devices.
Innovation Solution
The orchestrator service provisions a secure overlay network (e.g., VxLAN) first, then allocates tenant-specific hardware resources and IP addresses, configures per-tenant firewalls, and provisions an authenticated tenant-unique identity to bootstrap the HCI cluster and its shared storage pool in a secure, tenant-specific manner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If per-tenant allocated networking infrastructure is configured before forming the shared storage pool, then security and trust are improved, but the configuration process becomes more complex and time-consuming
Solution Approach 1:
The patent applies preliminary action by pre-configuring secure networking infrastructure (VxLAN overlays, firewalls, routing) before deploying storage pool configuration software. This ensures that the networking layer is trusted and secure before any software is loaded onto node-local storage devices, resolving the chicken-and-egg problem of requiring trust before configuration while maintaining security.
Solution Approach 2:
The patent segments the infrastructure configuration into distinct layers: networking infrastructure (VxLAN, firewalls, routing) is configured separately and independently before the storage pool configuration. This segmentation allows the networking layer to be established and trusted first, then the storage layer can be configured on top of it without compromising security or creating circular dependencies.
2Reliability
If per-tenant allocated networking infrastructure is configured before forming the shared storage pool, then security isolation between tenants is improved, but provisioning time is increased
Solution Approach 1:
The patent performs preliminary configuration of networking infrastructure templates and policies before tenant provisioning. By pre-establishing VxLAN overlays, firewall rules, and routing configurations as reusable templates, the system can quickly instantiate secure per-tenant networks without manually configuring each component from scratch, thus maintaining security isolation while reducing overall provisioning time.
3Reliability
If configuration software is loaded onto node-local storage devices after networking is established, then security is maintained, but the configuration process becomes more difficult
Solution Approach 1:
The patent introduces a configuration management system as an intermediary that automates the deployment of configuration software onto node-local storage devices. This intermediary system leverages the already-established secure networking infrastructure to securely distribute and install configuration software, eliminating the need for manual configuration while maintaining security. The intermediary handles authentication, software distribution, and configuration deployment automatically.
Data Source
AI summary
A cluster configuration request to form a hyperconverged computing infrastructure (HCI) cluster in a cloud computing environment is processed. Based on the cluster configuration request and any other cluster specifications, a plurality of bare metal computing nodes of the cloud computing environment are configured to operate as an HCI cluster. First, a tenant-specific secure network overlay is formed on a first set of tenant-specific networking hardware resources. Then, the tenant-specific secure network overlay is used by an orchestrator to provision a second set of tenant-specific networking hardware resources. The second set of tenant-specific networking hardware resources are configured to interconnect node-local storage devices into a shared storage pool having a contiguous address space. Top-of-rack switches are configured to form a network overlay on the first set of tenant-specific networking hardware resources. Then, top-of-rack switches are configured to form a layer-2 subnet on the second set of tenant-specific networking hardware resources.


