IP Library › Granted Patent US 11,403,028
Granted Patent B2
US 11,403,028 · App. 16/870,114 · Granted Aug 2, 2022

Virtualized block device backing for virtualization containers

Inventors: Cornelle Christiaan Pretorius Janse van Rensburg (Seattle, WA); Samuel Benjamin Karp (Seattle, WA)
Assignee: Amazon Technologies, Inc.
G06F3/065G06F3/064G06F3/067G06F3/0619
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,403,028
App. No.
16/870,114
Granted
Aug 2, 2022
Kind
B2
Abstract

Technologies are provided for backing virtualization containers with layered storage volumes stored in remote storage devices. A virtualization container can present a virtual storage volume to a process running in the virtualization container and handle data access requests from the process using a layered storage volume based on one or more read-only snapshots stored in one or more remote storage devices. Changes can be recorded in a read-write layer in one or more of the remote storage devices and associated with the layered storage volume. A new read-only snapshot can be created based on the data in the read-write storage layer and associated with the one or more read-only snapshots on which the layered storage volume is based. A virtualization container can be associated with a new layered storage volume based on the created read-only snapshot and the one or more read-only snapshots on which it is based.

Claims (83)

1. A system comprising:

a host computer and a virtualization container instantiated on the host computer, wherein the virtualization container is configured to:

present a virtual storage volume to a process executing in the virtualization container as a physical storage volume connected to the virtualization container, and

transmit a data access request for the virtual storage volume to a storage service, separate from the host computer, to access data stored on a remote storage volume;

the storage service, configured to:

receive the data access request,

access the remote storage volume on a storage device, wherein the remote storage volume is associated with one or more read-only data snapshots, and

process the data access request using at least one of the one or more read-only data snapshots;

another virtualization container instantiated on another host computer, wherein the another virtualization container is configured to:

execute another process in isolation from one or more other processes executing on the another host computer,

present a different virtual storage volume to the another process as a different physical storage volume connected to the another virtualization container, and

transmit data access requests for the different virtual storage volume to the storage service to access data stored in another remote storage volume; and

wherein the storage service is further configured to:

receive the data access requests from the another virtualization container, and

access the another remote storage volume on the storage device over the network, wherein the another remote storage volume comprises at least one of the one or more read-only data snapshots associated with the remote storage volume.

2. The system of claim 1 , wherein the data access request is a request to perform a data write operation; and

the storage service is further configured to:

identify a data block in one of the one or more read-only data snapshots that is a target of the data write operation,

copy the identified data block to a read-write storage space in the storage device, the read-write storage space being associated with the remote storage volume, and

modify the copied data block in the read-write storage space according to the data write operation.

3. The system of claim 2 , wherein the storage service is further configured to:

receive a subsequent data access request to perform a data read operation targeting the data block;

determine that the target of the data read operation is the data block that was the target of the previous data write operation; and

transmit the modified data block in the read-write storage space to the virtualization container.

4. The system of claim 2 , further comprising:

a second storage device storing the read-write storage space associated with the remote storage volume.

5. The system of claim 2 , wherein:

the virtualization container is further configured to:

transmit a request to the storage service to create a new container image based on the remote storage volume; and

the storage service is further configured to:

receive the request to create a new container image; and

create a new read-only data snapshot comprising the modified data block in the read-write storage space.

6. The system of claim 5 , wherein the storage service is further configured to:

generate an image manifest for the new container image describing the container image as comprising the new read-only data snapshot and the one or more read-only data snapshots associated with the remote storage volume.

7. The system of claim 6 , further comprising an image repository configured to:

receive the image manifest from the storage service; and

associate it with an identifier for the new container image.

8. The system of claim 5 , further comprising:

a second host computer and a second virtualization container instantiated on the second host computer, wherein the second virtualization container is configured to:

execute a second process in isolation from one or more other processes executing on the second host computer,

transmit a request to the storage service to generate a new remote storage volume based on the new container image, and

present a second virtual storage volume, associated with the new remote storage volume, to the second process as a physical storage volume connected to the second virtualization container; and

wherein the storage service is further configured to:

receive the request to generate the new remote storage volume based on the new container image,

determine that the new read-only data snapshot is associated with the new container image, and

create a new remote storage volume associated with the new read-only data snapshot.

9. The system of claim 1 , wherein the accessing the remote storage volume on the storage device comprises accessing a distributed storage.

10. A method comprising:

presenting a virtual storage volume to a process as a physical storage volume, wherein the process is executing in a virtualization container;

receiving a request for data in the virtual storage volume at a storage service separate from the virtualization container, wherein the data access request comprises a request to perform a data write operation;

accessing a remote storage volume on a storage device, wherein the remote storage volume is associated with one or more read-only data snapshots; and

processing the request for data using the one or more read-only data snapshots, comprising:

identifying a data block in one of the one or more read-only data snapshots that is a target of the data write operation,

copying the identified data block to a read-write storage space in the storage device, the read-write storage space being associated with the remote storage volume, and

modifying the copied data block in the read-write storage space according to the data write operation.

11. The method of claim 10 , further comprising:

receiving a subsequent data access request to perform a data read operation targeting the data block;

determine that the target of the data read operation is the data block that was the target of the previous data write operation; and

transmit the modified data block in the read-write storage space to the virtualization container.

12. The method of claim 10 , further comprising:

storing the read-write storage space in a storage device associated with the remote storage volume.

13. The method of claim 10 , further comprising:

receiving a request to create a new container image based on the remote storage volume; and

creating a new read-only data snapshot comprising the modified data block in the read-write storage space.

14. The method of claim 13 , further comprising:

generating an image manifest for the new container image describing the container image as comprising the new read-only data snapshot and the one or more read-only data snapshots associated with the remote storage volume.

15. The method of claim 14 , further comprising:

receiving the image manifest from the storage service; and

associating it with an identifier for the new container image.

16. The method of claim 10 , wherein accessing the remote storage volume on the storage device comprises accessing a distributed storage service.

17. A system comprising:

a virtualization container comprising a storage driver, wherein the storage driver is configured to:

present a virtual storage volume to a process executing in the virtualization container as a physical storage volume connected to the virtualization container, and

transmit a data access request for the virtual storage volume to a storage service, wherein the data access request is a request to perform a data write operation; and

the storage service, wherein the storage service is configured to:

receive the data access request,

access the remote storage volume on a storage device, wherein the remote storage volume is associated with one or more read-only data snapshots, and

process the data access request using at least one of the one or more read-only data snapshots, comprising:

identify a data block in one of the one or more read-only data snapshots that is a target of the data write operation,

copy the identified data block to a read-write storage space in the storage device, the read-write storage space being associated with the remote storage volume, and

modify the copied data block in the read-write storage space according to the data write operation.

18. The system of claim 17 , wherein:

accessing the remote storage volume on the storage device comprises accessing a distributed storage.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2020
From: KARP, SAMUEL BENJAMIN; JANSE VAN RENSBURG, CORNELLE CHRISTIAAN PRETORIUS
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 053272/0088 →
Continuity (2)
Division 15377912 · Dec 13, 2016
Related Publication 20200264776A1 · Aug 20, 2020