Techniques for dynamic client-side traffic routing with server-side control
Techniques are disclosed for enabling dynamic routing of identity and access (IA) requests to a cloud identity and access management (IAM) system. In some embodiments, the health (or service quality) of a cloud IAM system is continuously monitored in the background to update routing information for dynamically routing IA requests for client cloud services to the cloud IAM system in the foreground. In some embodiments, background monitoring is performed by sending first-type IA requests to the cloud IAM system to discover traffic patterns. In some embodiments, routing information may be mappings between client cloud services and identity endpoints of service cells in the cloud IAM system with configurable attributes that help rebalance and distribute the IA traffic.
1 . A method, comprising:
generating, by a computing system, a first-type identity and access (IA) service request for a randomly selected client cloud service of a set of client cloud services of different types provided by a cloud service provider (CSP), the first-type IA service request generated periodically according to a regular time interval;
monitoring, by the computing system, health of an identity management service that comprises a set of identity service cells, the monitoring comprising sending the first-type identity and access (IA) service request to one of the set of identity service cells;
creating, by the computing system, routing information associated with a first client cloud service and a first identity service cell of the set of identity service cells, the first client cloud service being one of the set of client cloud services provided by the cloud service provider (CSP);
updating, by the computing system, the routing information to generate updated routing information based at least in part on the monitored health of the identity management service; and
routing, by the computing system, a second-type IA service request by the first client cloud service to a first identity service cell of the set of identity service cells based at least in part on the updated routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells, wherein the updated routing information is updated based at least in part on at least one of a workflow type or a capacity utilization rate threshold.
2 . The method of claim 1 , wherein sending the first-type IA service request to one of the set of identity service cells and routing the second-type IA service request are performed in parallel.
3 . The method of claim 1 , wherein each of the set of identity service cells comprises at least a host machine.
4 . The method of claim 1 , wherein the regular time interval is configured for identifying traffic changes.
5 . The method of claim 4 , wherein the first-type IA service request for the randomly selected client cloud service invokes a response from the identity management service without performing an identity management function for the randomly selected client cloud service.
6 . The method of claim 1 , wherein the second-type IA service request by the first client cloud service invokes a response from the identity management service and an identity management function for the first client cloud service.
7 . The method of claim 1 , wherein the updated routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells is a mapping between the first client cloud service and a service endpoint of the first identity service cell.
8 . The method of claim 7 , wherein the updated routing information further comprising a mapping between the first client cloud service and a service endpoint of a second identity service cell of the set of identity service cells.
9 . The method of claim 8 , further comprising routing the second-type IA service request by the first client cloud service to a second service cell of the set of identity service cells instead when the first identity service cell is determined to be in an unhealthy condition.
10 . The method of claim 1 , wherein the updated routing information further comprising one or more attributes related to the health of the first identity service cell of the set of identity service cells.
11 . The method of claim 10 , wherein the one or more attributes comprises at least one of a utilization rate threshold, and an identity management function.
12 . The method of claim 1 , wherein the updated routing information is updated by following a configurable priority scheme.
13 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more processors of a computing system, cause the one or more processors to perform operations comprising:
generating, by the computing system, a first-type identity and access (IA) service request for a randomly selected client cloud service of a set of client cloud services of different types provided by a cloud service provider (CSP), the first-type IA service request generated periodically according to a regular time interval;
monitoring, by the computing system, health of an identity management service that comprises a set of identity service cells, the monitoring comprising sending the first-type identity and access (IA) service request to one of the set of identity service cells;
creating, by the computing system, routing information associated with a first client cloud service and a first identity service cell of the set of identity service cells, the first client cloud service being one of the set of client cloud services provided by the cloud service provider (CSP);
updating, by the computing system, the routing information to generate updated routing information, based at least in part on the monitored health of the identity management service and by following a configurable priority scheme; and
routing, by the computing system, a second-type IA service request by the first client cloud service to a first identity service cell of the set of identity service cells based at least in part on the updated routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells, wherein the updated routing information is updated based at least in part on at least one of a workflow type or a capacity utilization rate threshold.
14 . The non-transitory computer-readable medium of claim 13 , wherein the regular time interval is configured for identifying traffic changes.
15 . The non-transitory computer-readable medium of claim 13 , wherein the second-type IA service request by the first client cloud service invokes a response from the identity management service and an identity management function for the first client cloud service.
16 . The non-transitory computer-readable medium of claim 13 ,
wherein the routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells is a mapping between the first client cloud service and a service endpoint of the first identity service cell; and
wherein the updated routing information further comprises a mapping between the first client cloud service and a service endpoint of a second identity service cell of the set of identity service cells.
17 . A computing system, comprising:
one or more processors; and
one or more non-transitory computer readable media storing computer-executable instructions that, when executed by the one or more processors of a computing system, cause the system to:
generating, by the computing system, a first-type identity and access (IA) service request for a randomly selected client cloud service of a set of client cloud services of different types provided by a cloud service provider (CSP), the first-type IA service request generated periodically according to a regular time interval;
monitoring, by the computing system, health of an identity management service that comprises a set of identity service cells, the monitoring comprising sending the first-type identity and access (IA) service request to one of the set of identity service cells;
creating, by the computing system, routing information associated with a first client cloud service and a first identity service cell of the set of identity service cells, the first client cloud service being one of the set of client cloud services provided by the cloud service provider (CSP);
update, by the computing system, the routing information to generate updated routing information, based at least in part on the monitored health of the identity management service and by following a configurable priority scheme; and
route, by the computing system, a second-type IA service request by the first client cloud service to a first identity service cell of the set of identity service cells based at least in part on the updated routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells, wherein the updated routing information is updated based at least in part on at least one of a workflow type or a capacity utilization rate threshold.
18 . The system of claim 17 , wherein wherein the regular time interval is configured for identifying traffic changes.
19 . The system of claim 17 , wherein the second-type IA service request by the first client cloud service invokes a response from the identity management service and an identity management function for the first client cloud service.
20 . The system of claim 17 ,
wherein the routing information associated with the first client cloud service and the first identity service cell of the set of identity service cells is a mapping between the first client cloud service and a service endpoint of the first identity service cell; and
wherein the updated routing information further comprises a mapping between the first client cloud service and a service endpoint of a second identity service cell of the set of identity service cells.