Virtual devices in a reliable distributed computing system
Providing differing degrees of reliability or security for distinct devices within a reliable distributed system. Allowing virtual machines to operate in a reliable distributed system without either exposing the actual available devices to guest operating systems, or requiring the guest OS to maintain, or to maintain information about, reliability or security. Methods are responsive to a hierarchy of possible reliability or security failures, to guard more carefully against simultaneous failures of reliability or breaches of security, without additional work or delay. Functions invoked by the user that relate to reliability and security are hidden, so the user can specify a degree of reliability or security without having to implement those requirements themselves. Providing a uniform set of resources available to all users, separating out those individual resources that are allocated to particular users, and emulating particular devices at the request of those particular users. Users do not have access to “real” devices the distributed system can use, only “virtual” devices presented by the distributed system, where those virtual devices have properties similar, but not necessarily equal, to real devices.
1 . A method,
in a reliable distributed computing system, said system including one or more virtual machines, each said virtual machine having access to a plurality of virtual devices, each said virtual machine operating under a control of a guest operating system,
of providing differing degrees of reliability for distinct devices accessible by said one or more virtual machines in said reliable distributed computing system;
said method including steps of:
providing a set of real devices available to said one or more virtual machines;
emulating said one or more virtual devices using said set of real devices, said steps of emulating including:
being responsive to distinct metadata associated with each of said one or more virtual machines, said metadata defining within said set of real devices a plurality of reliability requirements,
for each one or more of said virtual devices, defining a set of failure groups, and
assuring that real devices associated with each of those failure groups are subject to the reliability requirements of said metadata;
wherein said steps of emulating are responsive to said differing degrees of reliability with respect to distinct virtual devices, and
wherein the metadata can require protection against multiple concurrent failures;
wherein the metadata defines a first set and a second set of failure groups to include real devices which are disposed according to one or more of the following:
the first set and the second set of failure groups are disposed on separate nodes, whereby those included real devices are respectively required to be emulated across those separate nodes,
the first set and the second set of failure groups are disposed on separate racks of nodes, whereby those included real devices are respectively required to be emulated across those separate racks of nodes,
the first set and the second set of failure groups are disposed on separate banks of racks, whereby those included real devices are respectively required to be emulated across those separate banks of racks,
the first set and the second set of failure groups are disposed on separate rooms of devices, whereby those included real devices are respectively required to be emulated across those separate rooms of devices,
the first set and the second set of failure groups are disposed with respect to separate buildings, whereby those included real devices are respectively required to be emulated across those separate buildings, or
the first set and the second set of failure groups are disposed with respect to separate clusters of buildings, whereby those included real devices are respectively required to be emulated across those separate clusters of buildings.
2 . The method as in claim 1 , including steps of
providing one or more functions invocable by one or more of said virtual machines, said functions individually or collectively disposed to specify a degree of desired reliability.
3 . The method as in claim 2 , wherein said steps of emulating are responsive to said differing degrees of security with respect to distinct virtual devices.
4 . The method as in claim 1 , wherein
said degree of desired reliability includes data reliability; and
said steps of emulating include steps of assuring that a collection of concurrent failures are protected against;
wherein said collection of concurrent failures includes concurrent failures within designated groups of said real devices.
5 . The method as in claim 4 , wherein
said designated groups of said real devices include more than one level in a failure hierarchy, in which logically closer real devices are considered closer together in said failure hierarchy.
6 . The method as in claim 1 , wherein
said degree of desired reliability includes data reliability; and
said steps of emulating include steps of assuring that a number of concurrent failures, response to said metadata, are protected against.
7 . The method as in claim 6 , wherein
said number of concurrent failures is other than a RAID specification.
8 . The method as in claim 1 , wherein
said degree of desired reliability includes security; and
said steps of emulating include steps of assuring that said designated group of real devices are not vulnerable to security breaches.
9 . The method as in claim 8 , wherein
said vulnerability to security breaches includes a location of one or more of said devices.
10 . Apparatus including
a reliable distributed computing system, said system including one or more virtual machines, each said virtual machine having access to a plurality of virtual devices, each said virtual machine operating under a control of a guest operating system;
one or more guest operating systems, each guest operating system being subject to a control of an associated host operating system, each said host operating system having control of one or more real devices;
each said host operating system including one or more elements of non-transitory storage, said non-transitory storage including instructions disposed to be executed by a computing devices,
said instructions associating said real devices with said virtual devices, and disposed to emulate said virtual devices using one or more associated real devices,
said instructions causing said computing devices to associate said real devices with said virtual devices, and disposed to assure that said instructions cause said virtual devices to meet a selected degree of reliability;
wherein
each said host operating system includes metadata associated with each of said one or more virtual machines;
said instructions in response to said metadata, define for each one or more of said virtual devices, one or more failure groups; and
said instructions, in response to said failure groups, cause said computing devices to associate multiple real devices in the same failure groups with distinct virtual devices,
wherein the metadata can require protection against multiple concurrent failures;
wherein the metadata defines a first set and a second set of failure groups to include real devices which are disposed according to one or more of the following:
the first set and the second set of failure groups are disposed on separate nodes, whereby those included real devices are respectively required to be emulated across those separate nodes,
the first set and the second set of failure groups are disposed on separate racks of nodes, whereby those included real devices are respectively required to be emulated across those separate racks of nodes,
the first set and the second set of failure groups are disposed on separate banks of racks, whereby those included real devices are respectively required to be emulated across those separate banks of racks,
the first set and the second set of failure groups are disposed on separate rooms of devices, whereby those included real devices are respectively required to be emulated across those separate rooms of devices,
the first set and the second set of failure groups are disposed with respect to separate buildings, whereby those included real devices are respectively required to be emulated across those separate buildings, or
the first set and the second set of failure groups are disposed with respect to separate clusters of buildings, whereby those included real devices are respectively required to be emulated across those separate clusters of buildings.
11 . The apparatus as in claim 10 , including
instructions provided one or more functions invocable by one or more of said virtual machines, said functions individually or collectively disposed to specify a degree of desired reliability.
12 . The apparatus as in claim 11 , wherein said differing degrees of desired soundness includes one or more of: reliability, security instructions cause said virtual storage devices to meet said degree of security.
13 . The apparatus as in claim 10 , wherein
said degree of desired reliability includes data reliability; and
said instructions cause said computing device to assure that a collection of concurrent failures are protected against;
wherein
said collection of concurrent failures includes concurrent failures within designated groups of said real storage devices.
14 . The apparatus as in claim 13 , wherein
said designated groups of said real storage devices include more than one level in a failure hierarchy, in which logically closer real storage devices are considered closer together in said failure hierarchy.
15 . The apparatus as in claim 10 , wherein
said degree of desired reliability includes data reliability; and
said instructions cause said computing device to assure that a number of concurrent failures, responsive to said metadata, are protected against.
16 . The apparatus as in claim 15 , wherein
said number of concurrent failures is other than a RAID specification.
17 . The apparatus as in claim 10 , wherein
said degree of desired reliability includes a degree of desired security; and
said instructions cause said computing devices to assure that said designated groups of real storage devices are not vulnerable to security breaches.
18 . The apparatus as in claim 17 , wherein said vulnerability to security breaches includes a location of one or more of said real storage devices.
19 . A method,
in a reliable distributed computing system, said system including one or more virtual machines, each said virtual machine having access to a plurality of virtual storage devices, each said virtual machine operating under a control of a guest operating system,
of providing differing degrees of reliability for distinct devices accessible by said one or more virtual machines in said reliable distributed computing system;
said method including steps of:
providing a set of real devices available to said one or more virtual machines;
emulating said one or more virtual devices using said set of real devices, said steps of emulating including:
being responsive to distinct metadata associated with each of said one or more virtual machines, said metadata defining within said set of real devices a plurality of security requirements,
for each one or more of said virtual devices, defining a set of failure groups, and
assuring that real devices associated with each of those failure groups are subject to security requirements defined by said metadata;
wherein said steps of emulating are responsive to said differing degrees of security with respect to distinct virtual devices, and
wherein the metadata can require protection against multiple concurrent failures;
wherein a first set and a second set of failure groups are defined to include real devices which are disposed according to one or more of the following:
the first set and the second set of failure groups are disposed on separate nodes, whereby those included real devices are respectively required to be emulated across those separate nodes,
the first set and the second set of failure groups are disposed on separate racks of nodes, whereby those included real devices are respectively required to be emulated across those separate racks of nodes,
the first set and the second set of failure groups are disposed on separate banks of racks, whereby those included real devices are respectively required to be emulated across those separate banks of racks,
the first set and the second set of failure groups are disposed on separate rooms of devices, whereby those included real devices are respectively required to be emulated across those separate rooms of devices,
the first set and the second set of failure groups are disposed with respect to separate buildings, whereby those included real devices are respectively required to be emulated across those separate buildings, or
the first set and the second set of failure groups are disposed with respect to separate clusters of buildings, whereby those included real devices are respectively required to be emulated across those separate clusters of buildings.
20 . The method as in claim 19 , including steps of
providing one or more functions invocable by one or more of said virtual machines, said functions individually or collectively disposed to specify a degree of desired security.