IP Library Granted Patent US 11,657,436
Granted Patent B2
US 11,657,436 · App. 17/179,841 · Granted May 23, 2023

Managing storage volume in a virtual computing infrastructure

Inventors: Willem Robert Van Biljon (Cape Town, ZA); Christopher Conway Pinkham (Los Gatos, CA); Russell Andrew Cloran (Cape Town, ZA); Michael Carl Gorven (Cape Town, ZA); Alexandre Hardy (Cape Town, ZA); Brynmor K. B. Divey (Cape Town, ZA); Quinton Robin Hoole (Cape Town, ZA); Girish Kalele (Sunnyvale, CA)
Assignee: ORACLE INTERNATIONAL CORPORATION
G06Q30/04G06F21/6218G06Q40/00H04L63/0236H04L63/101H04L63/102H04L67/10H04L67/60H04M15/66G06F2221/2141G06F2221/2145G06Q40/02G06Q40/10H04L9/40H04L41/0213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,657,436
App. No.
17/179,841
Granted
May 23, 2023
Kind
B2
Abstract

Techniques are provided for authorizations in a virtual computing infrastructure using a federation token service. The techniques may include receiving a request for a launch plan from a user for launching instances in a plurality of sites, determining object permissions required for actions to be performed to launch one or more of the instances at each site of the plurality of sites, contacting an authorization caching service to obtain authorization tokens for each of the determined object permissions required for the actions, receiving the authorization tokens for each of the determined object permissions required for the actions, and forwarding the request to each site of the plurality of sites with an authentication token and the authorization tokens for each of the determined object permissions required for the actions to be performed to launch the one or more of the instances at each site of the plurality of sites.

Claims (45)

1. A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors, cause the one or more processors to:

receive, at a site controller of a computing system, a request to attach a virtual storage volume to an instance of an object;

obtain, by the site controller, a network location and storage area network protocols supported by the virtual storage volume;

augment, by the site controller, the request with the network location and the storage area network protocols to generate an augmented request;

forward, by the site controller, the augmented request to a storage cluster controller of the computing system based upon an internal mapping between instances and storage clusters;

forward, by the storage cluster controller, the augmented request to a storage node controller responsible for a node on which the instance of the object is hosted;

create, by the storage node controller, an attachment of a storage area network to the virtual storage volume based on the network location and the storage area network protocols supported by the virtual storage volume; and

attach, by the storage node controller, the virtual storage volume and the attached storage area network to the instance as a virtual block device.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the object is (i) a machine image executed as a virtual machine, (ii) executed as code, or (iii) an accessible data store.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the storage node controller is registered with the storage cluster controller, which manages a fleet of storage node controllers.

4. The non-transitory computer-readable storage medium of claim 1 , wherein the request is received as part of a plan to execute the instance.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the virtual block device is a pre-populated virtual block device with machine images or an empty virtual block device.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the one or more processors are further caused to in response to receiving the request, determine whether the request is authorized based on stored permissions that define whether a user is allowed to attach the virtual storage volume to the instance of the object.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the site controller obtains the network location and the storage area network protocols supported by the virtual storage volume from a storage site controller that keeps track of an aggregate state of the storage clusters.

8. A system comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to execute a method including:

receiving, at a site controller of a computing system, a request to attach a virtual storage volume to an instance of an object;

obtaining, by the site controller, a network location and storage area network protocols supported by the virtual storage volume;

augmenting, by the site controller, the request with the network location and the storage area network protocols to generate an augmented request;

forwarding, by the site controller, the augmented request to a storage cluster controller of the computing system based upon an internal mapping between instances and storage clusters;

forwarding, by the storage cluster controller, the augmented request to a storage node controller responsible for a node on which the instance of the object is hosted;

creating, by the storage node controller, an attachment of a storage area network to the virtual storage volume based on the network location and the storage area network protocols supported by the virtual storage volume; and

attaching, by the storage node controller, the virtual storage volume and the attached storage area network to the instance as a virtual block device.

9. The system of claim 8 , wherein the object is (i) a machine image executed as a virtual machine, (ii) executed as code, or (iii) an accessible data store.

10. The system of claim 8 , wherein the storage node controller is registered with the storage cluster controller, which manages a fleet of storage node controllers.

11. The system of claim 8 , wherein the request is received as part of a plan to execute the instance.

12. The system of claim 8 , wherein the virtual block device is a pre-populated virtual block device with machine images or an empty virtual block device.

13. The system of claim 8 , wherein the method further includes:

in response to receiving the request, determining, by the computing system, whether the request is authorized based on stored permissions that define whether a user is allowed to attach the virtual storage volume to the instance of the object.

14. The system of claim 8 , wherein the site controller obtains the network location and the storage area network protocols supported by the virtual storage volume from a storage site controller that keeps track of an aggregate state of the storage clusters.

15. A method comprising:

receiving, at a site controller of a computing system, a request to attach a virtual storage volume to an instance of an object;

obtaining, by the site controller, a network location and storage area network protocols supported by the virtual storage volume;

augmenting, by the site controller, the request with the network location and the storage area network protocols to generate an augmented request;

forwarding, by the site controller, the augmented request to a storage cluster controller of the computing system based upon an internal mapping between instances and storage clusters;

forwarding, by the storage cluster controller, the augmented request to a storage node controller responsible for a node on which the instance of the object is hosted;

creating, by the storage node controller, an attachment of a storage area network to the virtual storage volume based on the network location and the storage area network protocols supported by the virtual storage volume; and

attaching, by the storage node controller, the virtual storage volume and the attached storage area network to the instance as a virtual block device.

16. The method of claim 15 , wherein the object is (i) a machine image executed as a virtual machine, (ii) executed as code, or (iii) an accessible data store.

17. The method of claim 15 , wherein the storage node controller is registered with the storage cluster controller, which manages a fleet of storage node controllers.

18. The method of claim 15 , wherein the request is received as part of a plan to execute the instance.

19. The method of claim 15 , wherein the virtual block device is a pre-populated virtual block device with machine images or an empty virtual block device.

20. The method of claim 15 , further comprising:

in response to receiving the request, determining, by the computing system, whether the request is authorized based on stored permissions that define whether a user is allowed to attach the virtual storage volume to the instance of the object.

Assignments (2)
IP TRANSFER AGREEMENT Recorded Feb 22, 2021
From: NIMBULA, INC.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 055362/0127 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2021
From: VAN BILJON, WILLEM ROBERT; PINKHAM, CHRISTOPHER CONWAY; CLORAN, RUSSELL ANDREW; GORVEN, MICHAEL CARL; HARDY, ALEXANDRE; DIVEY, BRYNMOR K.B.; HOOLE, QUINTON ROBIN; KALELE, GIRISH
To: NIMBULA, INC.
Reel/Frame 055335/0122 →
Continuity (7)
Continuation 16357607 · Mar 19, 2019
Continuation 15692929 · Aug 31, 2017
Continuation 14724043 · May 28, 2015
Continuation 13299301 · Nov 17, 2011
Continuation PCTUS2011040590 · Jun 15, 2011
Provisional Application 61355078 · Jun 15, 2010
Related Publication 20210174411A1 · Jun 10, 2021