RESOURCE FENCING FOR VLAN MULTI-TENANT SYSTEMS
First Claim
1. In a storage system having a plurality of nodes, the nodes being grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants, a node in the cluster system comprising:
- a memory, anda controller operable to bind each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and has a destination IP address of the IP network to which the capability is bound;
wherein it is permissible for one or more capabilities to be bound to the same IP network; and
wherein each IP network has one corresponding network interface.
3 Assignments
0 Petitions
Accused Products
Abstract
A storage system has a plurality of nodes which are grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants. A node in the cluster system comprises: a memory, and a controller operable to bind each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and has a destination IP address of the IP network to which the capability is bound. It is permissible for one or more capabilities to be bound to the same IP network. Each IP network has one corresponding network interface.
24 Citations
13 Claims
-
1. In a storage system having a plurality of nodes, the nodes being grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants, a node in the cluster system comprising:
-
a memory, and a controller operable to bind each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and has a destination IP address of the IP network to which the capability is bound; wherein it is permissible for one or more capabilities to be bound to the same IP network; and wherein each IP network has one corresponding network interface. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A method for managing access to capabilities, in a storage system having a plurality of independent nodes, the nodes being grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants, a node in the cluster system including a memory and a controller, the method comprising:
-
binding each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and have a destination IP address of the IP network to which the capability is bound; wherein it is permissible for one or more capabilities to be bound to the same IP network; and wherein each IP network has one corresponding network interface. - View Dependent Claims (8, 9, 10, 11, 12, 13)
-
Specification