Establishing a persistent connection with a remote secondary storage system
A first persistent connection pipe is established from a node of a secondary storage system to an access service associated with a cloud service system. A second persistent connection pipe is established from the node of the secondary storage system to the access service. A communication direction role of the second persistent connection pipe is switched to enable the access service to initiate a communication to the node of the secondary storage system via the second persistent pipe.
1. A method, comprising:
establishing a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;
establishing a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and
reversing communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with a cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe.
2. The method of claim 1 , further comprising establishing a multiplexing protocol on the second persistent connection pipe.
3. The method of claim 2 , wherein the first persistent connection pipe is configured to multiplex a plurality of requests from the node of the secondary storage system.
4. The method of claim 1 , wherein the first persistent connection pipe is established using a first certificate associated with the cloud service system, wherein the first certificate is signed by a private key associated with a trusted third party.
5. The method of claim 4 , wherein the first persistent connection pipe is established using a second certificate associated with the cloud service system, wherein the second certificate is signed by a private key associated with the cloud service system.
6. The method of claim 1 , wherein the access service is configured to host a persistent connection virtualization container, wherein the persistent connection virtualization container is a virtual instance of a microservice.
7. The method of claim 1 , wherein the cloud service system is associated with a load balancer.
8. The method of claim 7 , wherein the load balancer is configured to intercept data packets sent from the secondary storage system to a persistent connection virtualization container.
9. The method of claim 8 , wherein the load balancer is configured to forward the data packets to a first destination of the access service based on a header associated with the data packets.
10. The method of claim 9 , wherein the load balancer is configured to forward the data packets to a second destination port of the access service based on the header associated with the data packets.
11. The method of claim 1 , wherein the first persistent connection pipe and the second persistent connection pipe have a same connection descriptor information.
12. The method of claim 1 , wherein the secondary storage system is located behind a firewall.
13. The method of claim 1 , wherein the first persistent connection pipe and the second persistent connection pipe are established between a persistent connection virtualization receiver container of the access service and a master node of the secondary storage system.
14. A system, comprising:
a processor configured to:
establish a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;
establish a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and
reverse communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with the cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe; and
a memory coupled to the processor and configured to provide the processor with instructions.
15. The system of claim 14 , wherein the processor is further configured to establish a multiplexing protocol on the second persistent connection pipe.
16. The system of claim 14 , wherein the first persistent connection pipe is configured to multiplex a plurality of requests from the node of the secondary storage system.
17. The system of claim 14 , wherein the first persistent connection pipe is established using a first certificate associated with the cloud service system and a second certificate associated with the cloud service system, wherein the first certificate is signed by a private key associated with a trusted third party, and wherein the second certificate is signed by a private key associated with the cloud service system.
18. The system of claim 14 , wherein the cloud service system is associated with a load balancer, wherein the load balancer is configured to intercept data packets sent from the secondary storage system to a persistent connection virtualization container.
19. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
establishing a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;
establishing a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and
reversing communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with a cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe.