IP Library Granted Patent US 11,704,426
Granted Patent B1
US 11,704,426 · App. 17/692,375 · Granted Jul 18, 2023

Information processing system and information processing method

Inventors: Takaki Nakamura (Tokyo, JP); Takahiro Yamamoto (Tokyo, JP); Hideo Saito (Tokyo, JP); Keisuke Matsumoto (Tokyo, JP); Hiroto Ebara (Tokyo, JP); Naruki Kurata (Tokyo, JP)
Assignee: HITACHI, LTD.
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,704,426
App. No.
17/692,375
Granted
Jul 18, 2023
Kind
B1
Abstract

An object of the invention is to appropriately separate an available cluster for each user in a storage system configured by using a plurality of clusters each of which is an aggregate of nodes. A computer system includes a plurality of K8s clusters each configured by one or a plurality of K8s nodes, a storage that provides a volume, and a tenant management unit that manages the plurality of the K8s clusters and the storage. The tenant management unit creates, in the storage, a plurality of tenants respectively corresponding to the plurality of the K8s clusters. The storage, for each of the plurality of the K8s clusters, permits access from the K8s cluster to a tenant corresponding to the K8s cluster and prohibits access from the K8s cluster to a tenant not corresponding to the K8s cluster.

Claims (43)

1. An information processing system that includes a plurality of bare metal nodes having a processor and a storage device, the information processing system comprising:

a plurality of node clusters operated on bare metal nodes and configured to execute a process;

a storage configured to process data that the node cluster receives from or outputs to the storage device; and

a management unit configured to manage the node cluster and the storage,

the plurality of node clusters, the storage, and the management unit operating on the processor, wherein

the management unit is configured to create a tenant and assign the node cluster and a resource of the storage to the tenant,

the node clusters operating on different bare metal nodes are capable of being assigned to the same tenant,

the node clusters operating on the same bare metal node are capable of being assigned to different tenants, each node cluster including a logical initiator port logically associated with the node cluster,

tenant information related to the tenant is associated with the initiator port used by the respective node cluster assigned to the tenant, and

the management unit is configured to

determine the tenant to which the node cluster is assigned from an ID of the initiator port of the node cluster when an access request is issued from the node cluster, and

determine whether access from the node cluster to the storage is possible based on the tenant to which the resource of the storage and the node cluster are assigned and permit or prohibit the access.

2. The information processing system according to claim 1 , wherein

the storage includes a storage control program, a logic storage area that is associated with a physical storage area of the storage device and stores data, and a target port serving as an access target to be accessed by the node cluster, and

the storage is configured to assign the logic storage area and the target port to the tenant as the resource of the storage, and

in the decision whether the access is possible, it is determined whether the node cluster is permitted to login to the target port.

3. The information processing system according to claim 2 , wherein

the logic storage area and the target port are assigned by the storage control program, and

a plurality of the logic storage areas and a plurality of the target ports, which are provided by the same storage control program, are capable of being assigned to different tenants.

4. The information processing system according to claim 3 , wherein

the processor and a plurality of nodes connected to one another by a network are provided,

a plurality of the storage control programs are respectively installed in the plurality of nodes and the resource of the storage is assigned to each of the nodes, and

the resources of the storage for different nodes are capable of being assigned to the same tenant.

5. The information processing system according to claim 1 , wherein

the management unit is configured to create tenant information in which the tenant, and the node cluster and the resource of the storage, which are assigned to the tenant, are stored in association with each other, and

the storage is configured to permit or prohibit, based on the tenant information, access of the node cluster.

6. The information processing system according to claim 1 , wherein

the management unit is configured to

set a tenant group by grouping a plurality of the tenants, and

determine whether the access from the node cluster to the storage is possible based on the tenant group of the tenant to which the resource of the storage and the node cluster are assigned, and to permit or prohibit the access.

7. The information processing system according to claim 1 , wherein

the management unit is configured to, when receiving a tenant creation request from the node cluster, create the tenant to which the node cluster and the resource of the storage are assigned, and to notify the node cluster of identification information of a target port serving as an access destination in the storage.

8. An information processing method, comprising:

a plurality of bare metal nodes having a processor operating as a plurality of node clusters configured to execute a process,

a storage configured to process data that the node cluster receives from or outputs to the storage device, and

a management unit configured to manage the node cluster and the storage; and

the management unit creating a tenant and assigning the node cluster and a resource of the storage to the tenant,

the node clusters operating on different bare metal nodes are capable of being assigned to the same tenant,

the node clusters operating on the same bare metal node are capable of being assigned to different tenants, each node cluster including a logical initiator port logically associated with the node cluster,

tenant information related to the tenant is associated with the initiator port used by the respective node cluster assigned to the tenant, and

the management unit is configured to

determine the tenant to which the node cluster is assigned from an ID of the initiator port of the node cluster when an access request is issued from the node cluster, and

determine whether access from the node cluster to the storage is possible based on the tenant to which the resource of the storage and the node cluster are assigned, and permit or prohibit the access.

Assignments (2)
COMPANY SPLIT Recorded Aug 20, 2024
From: HITACHI, LTD.
To: HITACHI VANTARA, LTD.
Reel/Frame 069518/0761 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2022
From: NAKAMURA, TAKAKI; YAMAMOTO, TAKAHIRO; SAITO, HIDEO; MATSUMOTO, KEISUKE; EBARA, HIROTO; KURATA, NARUKI
To: HITACHI, LTD.
Reel/Frame 059236/0298 →
Priority Claims (1)
JP 2021-209498 · Dec 23, 2021 · national