IP Library Granted Patent US 12,367,117
Granted Patent B2
US 12,367,117 · App. 18/199,328 · Granted Jul 22, 2025

Selecting a witness service when implementing a recovery plan

Inventors: Ankush Jindal (Bengaluru, IN); Kiran Tatiparthi (Dublin, CA); Sharad Maheshwari (Benagaluru, IN); Shubham Gupta (Etah, IN); Bharat Kumar Beedu (Santa Clara, CA)
Assignee: Nutanix, Inc.
G06F11/2023G06F9/45558G06F2201/815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,117
App. No.
18/199,328
Filed
May 18, 2023
Granted
Jul 22, 2025
Kind
B2
Art Unit
2114
USPC
714/11
Abstract

Methods, systems, and computer program products for selection of a witness during virtualization system recovery after a disaster event. A recovery plan is configured to identify a witness that is then used to elect a leader to implement the recovery. Various system, and/or network, and/or component failures and/or various loss of function of components of the virtualization system can trigger initiation of the recovery plan. Based on the particular recovery plan that is invoked upon a determination of a network outage, or component failure or loss of function of a component of the virtualization system, a particular witness corresponding to a subset of entities of the particular recovery plan is selected. The witness is used to elect the leader, and the leader initiates actions of the recovery plan. The implementation of the recovery plan includes consideration of the health of components that would potentially be involved in the recovery actions.

Claims (47)

1. A non-transitory computer readable medium comprising a sequence of instructions which, when stored in memory and executed by a processor, cause the processor to perform a set of acts, the set of acts comprising:

determining a recovery plan that comprises information pertaining to multiple witnesses in a virtualization system;

determining a witness to implement a recovery of the virtualization system from the multiple witnesses based at least in part on the recovery plan; and

bringing up a replacement computing entity to replace another computing entity for the recovery of the virtualization system to implement the recovery at least by using at least the witness.

2. The non-transitory computer readable medium of claim 1 , bringing up the replacement computing entity to replace the another computing entity for the recovery comprising triggering the recovery of at least one subset of corresponding subsets of entities specified in the recovery plan in response to an event, wherein the recovery plan identifies the multiple witnesses that respectively correspond to the corresponding subsets of entities of the virtualization system, and the witness comprises a software service.

3. The non-transitory computer readable medium of claim 2 , wherein the witness is determined from the multiple witnesses based at least in part upon how the event affects the at least one subset of the corresponding subsets of entities, and an implementation of the recovery comprises bringing up the replacement computing entity in a cloud environment.

4. The non-transitory computer readable medium of claim 3 , wherein the recovery plan defines a relationship between at least two subsets of the corresponding subsets of entities, and the event in the virtualization system comprises at least one of degradation of unreachability of a computing node in the virtualization system, or a failure of a virtual machine in the virtualization system, or a loss of function of an entity in the virtualization system, or liveness of a first virtualization system component, or a loss of communication with the first virtualization system component, or a decrease of health of the first virtualization system component, or a loss of function of the first virtualization system component.

5. The non-transitory computer readable medium of claim 1 , wherein the witness is used to elect a leader that is used to implement the recovery in the virtualization system, and the leader comprises a node that is referenced in the recovery plan, or an application that is referenced in the recovery plan, or a virtual machine that is referenced in the recovery plan.

6. The non-transitory computer readable medium of claim 5 , wherein the witness is located in a first fault domain that is different from a second fault domain in which the leader is located, and the recovery plan identifies one or more specific acts to be carried out for the recovery and specifies one or more parameters pertaining to at least one of failover detection, or a witness location or usage, or a timing threshold, or an act to be carried out after a detected failure or outage, or an IP (Internet Protocol) address that accounts for a difference between heterogeneous environments.

7. The non-transitory computer readable medium of claim 1 , wherein the multiple witnesses are distributed in different fault domains, and the different fault domains comprise a first cloud computing domain and a second cloud computing domain.

8. The non-transitory computer readable medium of claim 1 , wherein two different recovery plans respectively correspond to two different witnesses, at least one recovery plan of the two different recovery plans comprises a specification of a plurality of subsets of an overall set of components of the virtualization system.

9. The non-transitory computer readable medium of claim 8 , wherein a different witness is determined, based at least in part upon the at least one recovery plan and an aspect of an event that triggers the recovery, for a different hierarchically-interrelated subset of a plurality of hierarchically-interrelated subsets of the recovery plan.

10. The non-transitory computer readable medium of claim 1 , wherein the witness is determined from the multiple witnesses based at least in part upon one or more parameters specified in the recovery plan, and the one or more parameters comprise at least one of respective locations or usage of the multiple witnesses, or a specific action to be carried out for bringing up a virtualization entity in the virtualization system for the recovery of the virtualization system, or a timing threshold.

11. A non-transitory computer readable medium comprising a sequence of instructions which, when stored in memory and executed by a processor, cause the processor to perform a set of acts, the set of acts comprising:

determining a recovery plan comprising a hierarchical relationship that includes multiple hierarchies to which a plurality of virtualization system components belong, wherein the recovery plan specifies, based at least in part upon the hierarchical relationship, a witness that facilitates recovery of a subset of the plurality of virtualization system components;

determining, based at least in part on the recovery plan, a lower hierarchy virtualization system component that is affected by an event;

determining a subset of virtualization system components for the recovery based at least in part upon the lower hierarchy virtualization system component; and

performing the recovery according to the recovery plan.

12. The non-transitory computer readable medium of claim 11 , wherein the set of acts further comprises:

determining a specific witness from the recovery plan based at least in part upon how the event affects the subset of virtualization system components, wherein a respective witness is determined for a corresponding subset of virtualization system components, and the specific witness or the respective witness comprises a software service.

13. The non-transitory computer readable medium of claim 12 , wherein the recovery plan comprises information pertaining to respective locations or respective usages of multiple witnesses from which the specific witness is determined for the subset of virtualization system components.

14. The non-transitory computer readable medium of claim 13 , wherein the witness is used to elect a leader computing node that further initiates one or more actions to implement the recovery plan for the recovery.

15. The non-transitory computer readable medium of claim 11 , wherein the recovery is performed to recover only the subset of virtualization system components of the plurality of virtualization system components.

16. The non-transitory computer readable medium of claim 11 , wherein determining the subset of virtualization system components comprises:

identifying a higher virtualization system component based at least in part upon information specified in the recovery plan, wherein the higher virtualization system component is located at a higher hierarchical level than a lower hierarchical level at which the lower hierarchy virtualization system component is located, and the recovery plan characterizes both the higher virtualization system component and the lower hierarchy virtualization system component.

17. The non-transitory computer readable medium of claim 11 , wherein the set of acts further comprises:

identifying, for the lower hierarchy virtualization system component, an entry from a plurality of entries in the recovery plan;

determining the subset of virtualization system components by using at least the entry; and

identifying a separate subset of virtualization system components based at least in part upon information or data codified in the recovery plan and the subset of virtualization system components, wherein the subset of virtualization system components corresponds to a first witness, the separate subset of virtualization system components corresponds to a second witness different from the first witness.

18. A method comprising:

determining a recovery plan that comprises multiple witnesses in a virtualization system;

determining a witness to implement a recovery of the virtualization system from the multiple witnesses based at least in part on the recovery plan; and

bringing up a replacement computing entity to replace another computing entity for the recovery of the virtualization system to implement the recovery at least by using at least the witness.

19. The method of claim 18 , wherein an event that triggers the recovery of at least a subset of entities in the virtualization system comprises at least one of unreachability of a computing node in the virtualization system, or a failure of a virtual machine in the virtualization system, or a loss of function of an entity in the virtualization system, and the event in the virtualization system affects a first virtualization system component in a first cloud environment, and an implementation of the recovery comprises bringing up the replacement computing entity in a cloud environment.

20. The method of claim 18 , wherein the witness that comprises a software service is used to elect a leader computing node that is used to implement the recovery in the virtualization system, and the leader computing node comprises a node that is referenced in the recovery plan, or an application that is referenced in the recovery plan, or a virtual machine that is referenced in the recovery plan, and the witness is located in a first fault domain that is different from a second fault domain in which the leader computing node is located.

21. A system comprising:

a storage medium having stored thereon a sequence of instructions; and

a processor that executes the sequence of instructions to cause the processor to perform a set of acts, the set of acts comprising:

determining a recovery plan comprising a hierarchical relationship that includes multiple hierarchies to which a plurality of virtualization system components belong, wherein the recovery plan specifies, based at least in part upon the hierarchical relationship, a witness that facilitates recovery of a subset of the plurality of virtualization system components;

determining, based at least in part on the recovery plan, a lower hierarchy virtualization system component that is affected by an event;

determining a subset of virtualization system components for a recovery based at least in part upon the lower hierarchy virtualization system component; and

performing the recovery according to the recovery plan.

22. The system of claim 21 , wherein the set of acts further comprises:

determining a specific witness from the recovery plan based at least in part upon how the event affects the subset of virtualization system components, wherein a respective witness is determined for a corresponding subset of virtualization system components, wherein the respective witness or the specific witness comprises a software service.

23. The system of claim 22 , wherein the recovery plan comprises information pertaining to respective locations or respective usages of multiple witnesses from which the specific witness is determined for the subset of virtualization system components, and the witness is used to elect a leader computing node that further initiates one or more actions to implement the recovery plan for the recovery.

24. The system of claim 21 , wherein determining the subset of virtualization system components comprises:

identifying a higher virtualization system component based at least in part upon information specified in the recovery plan, wherein the higher virtualization system component is located at a higher hierarchical level than a lower hierarchical level at which the lower hierarchy virtualization system component is located, and the recovery plan characterizes both the higher virtualization system component and the lower hierarchy virtualization system component.

Assignments (1)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
Priority Claims (1)
IN 202141002109 · Jan 16, 2021 · national
Continuity (2)
Continuation 17246565 · Apr 30, 2021
Related Publication 20240004766A1 · Jan 4, 2024
References Cited (68)
US 6173420B1 · Sunkara · 2001 [cited by examiner]
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 9189339B1 · Cohen et al. · 2015 [cited by applicant]
US 9306825B2 · Prahalad et al. · 2016 [cited by applicant]
US 9442792B2 · Pershin et al. · 2016 [cited by applicant]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 9772916B2 · Rangasamy · 2017 [cited by applicant]
US 10409988B2 · Reinecke · 2019 [cited by applicant]
US 10826812B2 · Casacio et al. · 2020 [cited by applicant]
US 20070124348A1 · Claborn · 2007 [cited by examiner]
US 20070168704A1 · Connolly · 2007 [cited by examiner]
US 20080126845A1 · Luo · 2008 [cited by examiner]
US 20080137528A1 · O'Toole · 2008 [cited by examiner]
US 20080256548A1 · Branson · 2008 [cited by examiner]
US 20140359128A1 · Bhattacharya · 2014 [cited by examiner]
US 20150339200A1 · Madduri et al. · 2015 [cited by applicant]
US 20150363282A1 · Rangasamy · 2015 [cited by examiner]
US 20150370660A1 · Pershin et al. · 2015 [cited by applicant]
US 20160077936A1 · Tang et al. · 2016 [cited by applicant]
US 20160179635A1 · Kondalsamy · 2016 [cited by examiner]
US 20170060639A1 · Miller et al. · 2017 [cited by applicant]
US 20190317789A1 · Chakraborty et al. · 2019 [cited by applicant]
US 20200026625A1 · Konka · 2020 [cited by examiner]
US 20200112499A1 · Casacio · 2020 [cited by examiner]
US 20200349036A1 · Sathavalli et al. · 2020 [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/246,565 dated Aug. 30, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/246,565 dated Feb. 8, 2023. [cited by applicant]
“A good Cloud use case: Failover Cluster quorum witness,” URL: https://tech-addict.fr/a-good-cloud-use-case-failover-cluster-quorum-witness/, Feb. 24, 2019 (Year: 2019). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 4, 2015), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 12, 2016), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2016), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2017), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 8, 2017), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2018), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 25, 2018), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 8, 2019), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 9, 2019), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Feb. 3, 2020), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Aug. 1, 2020), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 30, 2021), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Cano, I. et al., “Curator: Self-Managing Storage for Enterprise Clusters”, [cited by applicant]
“Disaster Recovery for Azure VMS with Site Recovery,” samcogan, dated May 31, 2017, URL: https://samcogan.com/disaster-recovery-for-azure-vms-with-site-recovery/. [cited by applicant]
“About recovery plans,” Microsoft, dated Jan. 14, 2022, URL: https://docs.microsoft.com/en-us/azure/site-recovery/recovery-plan-overview. [cited by applicant]
“IBM VM Recovery Manager HA for Power Systems, Version 1.4.0,” International Business Machines Corporation, Copyright 2019. [cited by applicant]
“Protect your Hyper-V Virtual Machines with Azure Site Recovery and Windows Admin Center,” Microsoft, dated Dec. 23, 2021, URL: https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-sit… [cited by applicant]
“New-AzRecoveryServicesAsrRecoveryPlan,” Microsoft, date found via Google as Dec. 19, 2018, URL: https://docs.microsoft.com/en-us/powershell/module/az.recoveryservices/new-azrecoveryservicesasrrecoveryplan?view=azps-7.4… [cited by applicant]
Potheri, M., “Disaster Recovery for Virtualized Business Critical Applications (Part 2 of 3),” VMWare, dated Oct. 15, 2014, URL: https://blogs.vmware.com/apps/2014/10/dr_bca_part2.html. [cited by applicant]
“Actifio Resiliency Director Server User Guide,” Actifio, Inc., Copyright 2019. [cited by applicant]
“SRM 5.5 Recovery Plans,” The IT Hollow, date found via Google as Oct. 27, 2013, URL: https://theithollow.com/site-recovery-manager-5-5-guide/srm-5-5-recovery-plans/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 9, 2022), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
“Citrix XenDesktop 7.1 on Microsoft Hyper-V Server 2012 R2 on Nutanix Virtual Computing Platform—Solution Design,” Citrix Validated Solutions, Prepared by: Citrix APAC Solutions, dated Jun. 25, 2014. [cited by applicant]
“Dell EMC PowerMax overview,” Dell Technologies, URL: https://infohub.delltechnologies.com/l/dell-emc-powermax-and-vmax-all-flash-srdf-metro-overview-and-best-practices-1/overview-2502/, date found via Google as Jan. 13… [cited by applicant]
“Step 3: Set up Witness and establish the connection to vWitness,” Dell Technologies, URL: https://infohub.delltechnologies.com/l/deploying-dell-emc-srdf-metro-smart-dr-with-microsoft-sql-server-for-physical-and-virtual… [cited by applicant]
“Witness behavior during failures and recovery,” Dell Technologies, URL: https://infohub.delltechnologies.com/l/dell-emc-powermax-and-vmax-all-flash-srdf-metro-overview-and-best-practices-1/witness-behavior-during-failu… [cited by applicant]
“Understanding the vSAN Witness Host,” Tech Zone Home, VMWare, dated Aug. 2, 2021. [cited by applicant]
“Deploy a Cloud Witness for a FailoverCluster,” Microsoft Learn, dated Mar. 10, 2023. [cited by applicant]
“Confidence in Your Disaster Recovery Planning,” Zerto, URL: https://www.zerto.com/solutions/use-cases/disaster-recovery/, date found via Google as Feb. 12, 2017. [cited by applicant]
“Switchover and Failover Operations,” Oracle Help Center, URL: https://docs.oracle.com/en/database/oracle/oracle-database/19/dgbkr/using-data-guard-broker-to-manage-switchovers-failovers.html♯GUID-44E7A982-7CD4-4A51-B00… [cited by applicant]
“Virtual Data Guard Environment,” datadisk, URL: https://web.archive.org/web/20111103073927/http:datadisk.co.uk/html_docs/oracle_dg/vm_setup.htm, date found via Internet Archive as Nov. 3, 2011. [cited by applicant]
Simon, F., “Observer, More Than One,” Personal Blog, URL: https://web.archive.org/web/20200825013938/https:/ www.fernandosimon.com/blog/observer-more-than-one/, date found via Internet Archive as Aug. 25, 2020. [cited by applicant]
“Data Guard implementation for Oracle 10gR2,” RACLE FAQ's, URL: https://web.archive.org/web/20071129220022/ https:/www.orafaq.com/wiki/Data_Guard_implementation_for_Oracle_10gR2, date found via Internet Archive as Nov. … [cited by applicant]