Providing stateful services in a scalable manner for machines executing on host computers
Abstract
Some embodiments provide a method for performing services on a host computer that executes several machines in a datacenter. The method configures a first set of one or more service containers for a first machine executing on the host computer, and a second set of one or more service containers for a second machine executing on the host computer. Each configured service container performs a service operation (e.g., a middlebox service operation, such as firewall, load balancing, encryption, etc.) on data messages associated with a particular machine (e.g., on ingress and/or egress data messages to and/or from the particular machine). For each particular machine, the method also configures a module along the particular machine's datapath to identify a subset of service operations to perform on a set of data messages associated with the particular machine, and to direct the set of data messages to a set of service containers configured for the particular machine to perform the identified set of service operations on the set of data messages. In some embodiments, the first and second machines are part of one logical network or one virtual private cloud that is deployed over a common physical network in the datacenter.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for providing services on a host computer that executes a plurality of machines, the method comprising:
configuring a first plurality of service containers on a first Pod operating on the host computer to perform a first plurality of services for a first machine executing on the host computer; configuring a second plurality of service containers on a second Pod operating on the host computer to perform a second plurality of services for a second machine executing on the host computer; using the first plurality of service containers on the first Pod to perform the first plurality of services for the first machine; and using the second plurality of service containers on the second Pod to perform second first plurality of services for the second machine.
22 . The method of claim 21 further comprising identifying each particular Pod as being part of a resource group of the particular machine for which the Pod's service containers perform services, to ensure that the particular Pod will be migrated with the particular machine to another host computer when the particular machine migrates to the other computer.
23 . The method of claim 21 further comprising:
identifying a service chain for a data message associated with the first machine; and
forwarding the data message to at least two first-Pod service containers associated with the service chain to perform at least two services on the data message.
24 . The method of claim 21 further comprising:
identifying different service chains for at least two different data message flows associated with the first machine; and
forwarding the two different data message flows to at least two different sets of first-Pod service containers that are associated with the two different service chains, each of the different sets of service containers performing at least two services for the data messages of the flow that is forwarded.
25 . The method of claim 21 , wherein the first and second Pods execute the same set of service containers.
26 . The method of claim 21 , wherein the first and second Pods execute different sets of service containers.
27 . The method of claim 21 , wherein the first and second machines belong to first and second logical networks implemented over a physical network on which a plurality of logical networks are defined.
28 . The method of claim 21 , wherein the first and second machines belong to one logical network implemented over a physical network on which a plurality of logical networks are defined.
29 . The method of claim 21 , wherein
the first and second Pods execute on first and second service virtual machines (SVMs) that execute on the host computer; the first and second machines are first and second guest virtual machines (GVMs), and the SVMs consume less storage resources and have faster bootup times than the GVMs.
30 . The method of claim 21 , wherein the first and second Pods are configured when the first and second machines are configured to operate on the host computer, and the first and second Pods are terminated when the first and second machines are respectively terminated on the host computer.
31 . A non-transitory machine readable medium storing sets of instructions for execution by at least one processing unit of the host computer, the program providing services on the host computer that executes a plurality of machines, the sets of instructions for:
operating a first plurality of service containers on a first Pod operating on the host computer to perform a first plurality of services for a first machine executing on the host computer; operating a second plurality of service containers on a second Pod operating on the host computer to perform a second plurality of services for a second machine executing on the host computer; using the first plurality of service containers on the first Pod to perform the first plurality of services for the first machine; and using the second plurality of service containers on the second Pod to perform second first plurality of services for the second machine.
32 . The non-transitory machine readable medium of claim 31 , wherein the sets of instructions are further for identifying each particular Pod as being part of a resource group of the particular machine for which the Pod's service containers perform services, to ensure that the particular Pod will be migrated with the particular machine to another host computer when the particular machine migrates to the other computer.
33 . The non-transitory machine readable medium of claim 31 , wherein the sets of instructions are further for:
identifying a service chain for a data message associated with the first machine; and forwarding the data message to at least two first-Pod service containers associated with the service chain to perform at least two services on the data message.
34 . The non-transitory machine readable medium of claim 31 , wherein the sets of instructions are further for:
identifying different service chains for at least two different data message flows associated with the first machine; and forwarding the two different data message flows to at least two different sets of first-Pod service containers that are associated with the two different service chains, each of the different sets of service containers performing at least two services for the data messages of the flow that is forwarded.
35 . The non-transitory machine readable medium of claim 31 , wherein the first and second Pods execute the same set of service containers.
36 . The non-transitory machine readable medium of claim 31 , wherein the first and second Pods execute different sets of service containers.
37 . The non-transitory machine readable medium of claim 31 , wherein the first and second machines belong to first and second logical networks implemented over a physical network on which a plurality of logical networks are defined.
38 . The non-transitory machine readable medium of claim 31 , wherein the first and second machines belong to one logical network implemented over a physical network on which a plurality of logical networks are defined.
39 . The non-transitory machine readable medium of claim 31 , wherein
the first and second Pods execute on first and second service virtual machines (SVMs) that execute on the host computer; the first and second machines are first and second guest virtual machines (GVMs), and the SVMs consume less storage resources and have faster bootup times than the GVMs.
40 . The non-transitory machine readable medium of claim 31 , wherein the first and second Pods are configured when the first and second machines are configured to operate on the host computer, and the first and second Pods are terminated when the first and second machines are respectively terminated on the host computer.Join the waitlist — get patent alerts
Track US2023359478A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.