IP Library Granted Patent US 10,860,444
Granted Patent B2
US 10,860,444 · App. 16/049,493 · Granted Dec 8, 2020

Seamless mobility for kubernetes based stateful pods using moving target defense

Inventor: Assaf Natanzon (Tel Aviv, IL)
Assignee: EMC IP Holding Company LLC
G06F11/203G06F3/065G06F3/067G06F3/0619G06F3/0647G06F3/0664G06F9/455G06F11/2094G06F2201/805G06F2201/81G06F2201/815G06F2201/82
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,860,444
App. No.
16/049,493
Granted
Dec 8, 2020
Kind
B2
Abstract

Providing seamless mobility of stateful pods in a container management system, by: receiving an indication that a pod needs to be moved from a first site to a replica site, identifying, through a moving target defense (MTD) process, all persistent volumes attached to the pod; determining if an RPO/RTO objective for the movement is below a threshold value, draining all local I/O operations to a container having the persistent volumes attached; killing containers of the pod using the persistent volumes after the draining, waiting for data to be flushed to the replica site, initiating a failover of a first storage of the first site, and restarting a container to run on the replica site attached to replica storage. In this process, a resource management system (RMS) is used to provide an address of a secure golden copy of the container as the address of the replica site.

Claims (40)

1. A computer-implemented method of providing seamless mobility of stateful pods in a container management system, comprising:

receiving an indication that a pod requires a movement from a first site to a second site;

identifying, through a moving target defense (MTD) process, all persistent volumes attached to the pod;

determining if a time objective for the movement is below a threshold value of a recovery point objective or recovery time objective;

draining all local I/O operations to a container having the persistent volumes attached;

killing, by the MTD process if the time objective is below the threshold, containers of the pod using the persistent volumes after the draining step;

waiting, by the MTD process, for data to be flushed to the second site;

initiating a failover of a first storage of the first site; and

restarting, by the MTD process, a container to run on the second site attached to a second storage.

2. The method of claim 1 wherein the pod comprises a basic unit of the container management system and comprising a plurality of closely related containers grouped together to be controlled as a single application.

3. The method of claim 2 wherein the container management system comprises a Kubernetes system, and wherein each persistent volume is implemented as a Kubernetes PersistentVolume (PV) in a cluster.

4. The method of claim 1 wherein the second site comprises a replica site, the second storage comprises a replica storage, and the movement from the first site to the replica site comprises a replication operation.

5. The method of claim 4 wherein the time objective comprises at least one of a recovery point objective and a recovery time objective of the replication operation.

6. The method of claim 1 further comprising invoking a checkpoint restore in user space (CRIU) operation if the draining step does not complete within a defined period of time.

7. The method of claim 6 wherein the CRIU operation comprises:

creating a snapshot copy of a container memory;

sending the snapshot copy to memory of the second site; and

using virtualization methods to ensure that respective storage addresses between the container memory and the memory of the second site remain unchanged.

8. The method of claim 1 wherein the MTD process periodically changes at least one of IP address, name, and MAC address of the container having the persistent volumes prior to moving the pod to the second site.

9. The method of claim 1 wherein the MTD process uses a resource management system (RMS) process to create a secure golden copy storage location to store the container having the persistent volumes.

10. The method of claim 9 wherein the MTD process using an address of the golden copy storage location as a container location on the second site.

11. A computer-implemented method of providing seamless mobility of stateful pods in a container management system, comprising:

defining, through a resource management system (RMS) process an address of a golden copy of a container created on a first periodic basis for the container;

changing, through a moving target defense (MTD) process an address of the container on a second periodic basis;

killing the container, upon indication of a desire move of the container and through the MTD process;

waiting, by the MTD process, I/O operations to be drained by a draining process to the container and flushed to a replica site; and

using the address of the golden copy assigned by the RMS process as an address of the replica site.

12. The method of claim 11 further comprising:

requesting, by the MTD process, failover of first storage attached to the container; and

restarting, by the MTD process, a new container to run on replica storage attached to the replica site.

13. The method of claim 12 wherein the container comprises a stateful container having at least one of: one or more stateful applications with parameters to maintain in the container management system, or a sticky network identity.

14. The method of claim 13 wherein the container comprises part of a pod within the container management system, and wherein the pod comprises a plurality of closely related containers grouped together to be controlled as a single application.

15. The method of claim 14 wherein the container management system comprises a Kubernetes system, and wherein a persistent volume is implemented as a Kubernetes PersistentVolume (PV) in a cluster.

16. The method of claim 11 further comprising invoking a checkpoint restore in user space (CRIU) operation if the draining process does not complete within a defined period of time.

17. The method of claim 16 wherein the CRIU operation comprises: creating a snapshot copy of a container memory; sending the snapshot copy to the replica storage; and using virtualization methods to ensure that respective storage addresses between the container memory and the memory of the second site remain unchanged.

18. The method of claim 11 wherein the first periodic basis is one of: the same, longer, or shorter than the second periodic basis.

19. A system for providing seamless mobility of stateful pods in a container management system, comprising:

an interface receiving an indication that a pod requires a movement from a first site to a replica site; and

a hardware processor functionally coupled to the interface and having a moving target defense (MTD) component identifying all persistent volumes attached to the pod, determining if a time objective for the movement is below a threshold value of a recovery point objective or recovery time objective, draining all local I/O operations to a container having the persistent volumes attached, killing if the time objective is below the threshold, containers of the pod using the persistent volumes after the draining, waiting for data to be flushed to the replica site, initiating a failover of a first storage of the first site, and restarting a container to run on replica storage attached to the replica site.

20. The system of claim 19 further comprising the hardware processor executing a resource management system (RMS) process to create a secure golden copy storage location to store the container having the persistent volumes, wherein the MTD component uses an address of the golden copy storage location as a container location on the replica site.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: NATANZON, ASSAF
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046504/0923 →
Continuity (1)
Related Publication 20200034254A1 · Jan 30, 2020
Cited By (12)
US 12,197,971 US 12,199,833 US 12,231,398 US 12,248,494 US 12,261,746 US 12,267,212 US 12,301,382 US 12,638,989 US 12,676,835 US 12,683,864 US 12,693,896 US 12,717,660