Attachment and detachment of compute instances owned by different tenancies
Techniques are disclosed for creating an attachment between two compute instances. An infrastructure and a generalized method is described for attaching two or more cloud resources (e.g., two compute instances) in spite of the compute resources being provisioned by two different services from different cloud tenancies. An automated process is described that is executed for wiring the compute instances. The automated process can be generally applied to attach any two compute instances providing two different services and provisioned from two different service tenancies.
1 . A method, comprising:
receiving, by a first control plane for a first service, a request to detach a first compute instance of the first service and a second compute instance of a second service, where the first compute instance is controlled by the first control plane, the second compute instance is controlled by the first control plane, the first compute instance is within a customer tenancy, the second compute instance is within the customer tenancy, and the first compute instance is isolated from the second compute instance within the customer tenancy;
executing, by the first control plane, a set of processing steps to detach the first compute instance and the second compute instance; and
after executing the set of processing steps, giving control of the second compute instance to a second control plane.
2 . The method of claim 1 , wherein executing the set of processing steps includes:
removing, by the first control plane, stored information about an attachment between the first compute instance and the second compute instance.
3 . The method of claim 1 , wherein executing the set of processing steps includes:
sending, by the first control plane, to the second control plane, a detachment request, the detachment request including information identifying the first compute instance and the second compute instance, wherein the second control plane removes stored information about an attachment between the first compute instance and the second compute instance.
4 . The method of claim 3 , wherein executing the set of processing steps includes:
obtaining, by the first control plane, a token indicating that the first control plane can communicate with the second control plane on behalf of a customer, wherein the detachment request includes the token, and wherein the second control plane verifies authenticity of the token or permissions associated with the token.
5 . The method of claim 1 , wherein executing the set of processing steps includes:
removing, by the first control plane, one or more restrictions on operations that can be performed on the second compute instance due to an attachment between the first compute instance and the second compute instance.
6 . The method of claim 5 , wherein removing the one or more restrictions on the operations that can be performed on the second compute instance due to the attachment includes deleting a list of operations associated with the attachment.
7 . The method of claim 1 , further comprising:
after executing the set of processing steps and due to removing an attachment between the first compute instance and the second compute instance, disabling communication between the first compute instance and the second compute instance.
8 . The method of claim 1 , wherein the first control plane is a dominant control plane, the second control plane is a passive control plane, the first compute instance is a dominant compute instance, and the second compute instance is a passive compute instance.
9 . The method of claim 1 , wherein the first service is an Enterprise Resource Planning (ERP) service, and the second service is a conversational Artificial Intelligence (AI) service.
10 . The method of claim 1 , wherein the second compute instance previously had ownership and control of the second control plane before an attachment was created between the first compute instance and the second compute instance.
11 . A non-transitory computer-readable storage medium, storing computer-executable instructions that, when executed, cause one or more processors of a computer system to perform a method comprising:
receiving a request to detach a first compute instance of a first service and a second compute instance of a second service, where the first compute instance is controlled by a first control plane of the computer system, the second compute instance is controlled by the first control plane, the first compute instance is within a customer tenancy, the second compute instance is within the customer tenancy, and the first compute instance is isolated from the second compute instance within the customer tenancy;
executing a set of processing steps to detach the first compute instance and the second compute instance; and
after executing the set of processing steps, giving control of the second compute instance to a second control plane.
12 . The non-transitory computer-readable storage medium of claim 11 , wherein executing the set of processing steps includes:
obtaining a token indicating that the computer system can communicate with the second control plane on behalf of a customer.
13 . The non-transitory computer-readable storage medium of claim 11 , wherein executing the set of processing steps includes:
restoring a previous of set of allowed on operations that can be performed on the second compute instance.
14 . The non-transitory computer-readable storage medium of claim 11 , wherein executing the set of processing steps includes:
sending to the second control plane, a detachment request, the detachment request including an identifier for an attachment between the first compute instance and the second compute instance.
15 . The non-transitory computer-readable storage medium of claim 11 , wherein executing the set of processing steps includes:
deleting a first set of stored information about an attachment, wherein the second control plane deletes a second set of stored information about the attachment, and wherein the second control plane modifies ownership associated with the second compute instance.
16 . A computer system comprising:
a processor; and
a memory configured to store a plurality or instructions executable by the processor and upon execution by the processor to cause processing to be performed comprising:
receiving a request to detach a first compute instance of a first service and a second compute instance of a second service, where the first compute instance is controlled by a first control plane of the computer system, the second compute instance is controlled by the first control plane, the first compute instance is within a customer tenancy, the second compute instance is within the customer tenancy, and the first compute instance is isolated from the second compute instance within the customer tenancy;
executing a set of processing steps to detach the first compute instance and the second compute instance; and
after executing the set of processing steps, giving control of the second compute instance to a second control plane.
17 . The computer system of claim 16 , wherein executing the set of processing steps includes:
removing an attachment between the first compute instance and the second compute instance.
18 . The computer system of claim 16 , wherein executing the set of processing steps includes:
deleting stored information associated an attachment between the first compute instance and the second compute instance.
19 . The computer system of claim 16 , wherein executing the set of processing steps includes:
sending to the second control plane, a detachment request, the detachment request including an identifier for an attachment between the first compute instance and the second compute instance; and
configuring the first compute instance to no longer show the attachment between the first compute instance and the second compute instance.
20 . The computer system of claim 16 , wherein the second control plane regains control of the second compute instance, and wherein the second control plane modifies the second compute instance within the customer tenancy to show that a previous attachment no longer exists.