WO2004099990A1 - 計算機システム及び同システムに適用される故障計算機代替制御方法 - Google Patents

計算機システム及び同システムに適用される故障計算機代替制御方法 Download PDF

Info

Publication number
WO2004099990A1
WO2004099990A1 PCT/JP2004/006500 JP2004006500W WO2004099990A1 WO 2004099990 A1 WO2004099990 A1 WO 2004099990A1 JP 2004006500 W JP2004006500 W JP 2004006500W WO 2004099990 A1 WO2004099990 A1 WO 2004099990A1
Authority
WO
WIPO (PCT)
Prior art keywords
computer
computers
failed
unit
boot
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2004/006500
Other languages
English (en)
French (fr)
Inventor
Kenichi Mizoguchi
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toshiba Corp
Toshiba Digital Solutions Corp
Original Assignee
Toshiba Corp
Toshiba Solutions Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toshiba Corp, Toshiba Solutions Corp filed Critical Toshiba Corp
Priority to US10/556,051 priority Critical patent/US7478230B2/en
Publication of WO2004099990A1 publication Critical patent/WO2004099990A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/16Error detection or correction of the data by redundancy in hardware
    • G06F11/20Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements
    • G06F11/202Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where processing functionality is redundant
    • G06F11/2038Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where processing functionality is redundant with a single idle spare processing component
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/16Error detection or correction of the data by redundancy in hardware
    • G06F11/20Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements
    • G06F11/202Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where processing functionality is redundant
    • G06F11/2023Failover techniques
    • G06F11/2028Failover techniques eliminating a faulty processor or activating a spare
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/14Error detection or correction of the data by redundancy in operations
    • G06F11/1402Saving, restoring, recovering or retrying
    • G06F11/1415Saving, restoring, recovering or retrying at system level
    • G06F11/1417Boot up procedures
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/14Error detection or correction of the data by redundancy in operations
    • G06F11/1402Saving, restoring, recovering or retrying
    • G06F11/1415Saving, restoring, recovering or retrying at system level
    • G06F11/142Reconfiguring to eliminate the error
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/16Error detection or correction of the data by redundancy in hardware
    • G06F11/20Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements
    • G06F11/202Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where processing functionality is redundant
    • G06F11/2046Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where processing functionality is redundant where the redundant components share persistent storage

Definitions

  • the present invention relates to a computer system including a plurality of computers including a preliminary computer called a provisioning node.
  • the present invention provides a computer system suitable for enabling a boot computer to be executed on a spare computer when a running computer fails, and a fault computer applied to the system. It relates to an alternative control method.
  • a high-density computer system including tens to hundreds of computer nodes in one housing has been marketed.
  • Such a computer system often includes a spare computer called a provisioning node.
  • a spare computer is not normally used, but is used as a substitute computer (alternate node) when a computer normally used fails. To do so, an operator operation is required to set the boot image that was running on the failed computer as the boot image for the standby computer. By starting the spare computer after this setting, the spare computer can be used as a substitute for the failed computer.
  • a spare computer provisioning node
  • the spare computer can be used in place of the failed computer.
  • conventional techniques require the intervention of an operator to make a spare computer usable as a substitute for a failed computer.
  • the present invention has been made in consideration of the above circumstances, and has as its object to operate a computer included in a computer system in the event of a failure. —To make a spare computer available to replace a failed computer without the intervention of an evening.
  • a computer system including a plurality of computers including a standby computer.
  • the computer system includes a plurality of storage devices that individually store boot images for booting the plurality of computers, respectively, and a first storage device that stores statuses of the plurality of computers.
  • a second unit for storing information indicating a correspondence relationship between a storage unit and each of the plurality of storage devices and a computer booted by a boot image stored in the storage device;
  • a storage unit; a faulty computer search unit configured to search for a faulty computer in the computer system; and a faulty computer when the faulty computer search unit finds a faulty computer.
  • a spare computer for use as an alternative to the plurality of computers according to the status of the plurality of computers stored in the first storage unit.
  • a storage device in which a spare computer search unit and a boot image for booting the selected spare computer when the failed computer search unit finds a failed computer are stored by the spare computer search unit.
  • a boot computer image selection unit configured to select the boot computer image according to the information stored in the second storage unit, and the boot computer image selected by the standby computer search unit.
  • a boot unit configured to boot using the boot image stored in the storage device selected by the selection unit.
  • FIG. 1 is a block diagram showing a configuration of a computer system according to the first embodiment of the present invention.
  • Figure 3 is a state transition diagram showing the state transition of the computer.
  • FIG. 4 is a diagram showing an example of the data structure of the database DBB in FIG.
  • Fig. 5 shows an example of the data structure of the data base HD in Fig. 1.
  • FIG. 6 is a flowchart showing a processing procedure of a failure computer search process F # mainly in the first embodiment.
  • FIG. 7 is a diagram showing a state in which the failure computer search process F # is failed over from the computer C 1 to the computer C 2 in the first embodiment.
  • FIG. 8 is a diagram showing the contents of the database DBD # after execution of step S5 in FIG.
  • FIG. 9 is a diagram showing the contents of the database CDDBi after execution of step S5 in FIG.
  • FIG. 10 is a diagram illustrating a state in which a computer image that was being executed by the failed computer C 1 can now be executed by the computer C 5.
  • FIG. 11 is a block diagram showing the configuration of a computer system according to the second embodiment of the present invention.
  • Fig. 12 shows the failure computer search program of the second embodiment. 2004/006500
  • FIG. 13 is a block diagram showing a configuration of a computer system according to the third embodiment of the present invention.
  • FIG. 14 is a flowchart showing a processing procedure of a failure computer search process FP 1 according to the third embodiment.
  • FIG. 15 is a block diagram showing a configuration of a computer system according to the fourth embodiment of the present invention.
  • FIG. 16 is a flowchart showing a processing procedure of a failure computer search process FP1 mainly in the fourth embodiment.
  • FIG. 1 is a block diagram showing a configuration of a computer system according to the first embodiment of the present invention.
  • the computer system in Fig. 1 is composed of five computers C1 to C5.
  • the computers C 1 to C 5 are interconnected by a network N.
  • Computers C1 to C5 are connected to the storage area network SAN.
  • the storage device S S is also connected to the storage area network S AN.
  • the storage device S S is provided with disks (disk drives) D 1 to D 4. That is, the computers C1 to C5 and the disks D1 to D4 in the storage device SS are connected by the storage area network SAN.
  • Hosts "host-1”, “host-2”, “host-3” and “host-4" are assigned to disks D1, D2, D3 and D4, respectively. Pre-stored image for computer Have been.
  • the “host-i” boot image is Includes operating system OS i and application programs that operate under the operating system OS i. That is, the disk Di is used as the "host-i” boot disk.
  • FIG. 1 shows that the computers C 1 to C 4 of the computers C 1 to C 5 are started and operated by using the boot images stored in the disks D 1 to D 4, respectively.
  • the state is shown.
  • FIG. 1 also shows a state in which the operating systems ⁇ S 1 to OS 4 are operating on the operating computers C 1 to C 4, respectively.
  • These running computers C1 to C4 recognize their own host names as "host-1" to "host-4" recorded in the boot images of disks D1 to D4, respectively.
  • the remaining computer C5 among the computers C1 to C5 is arranged as a spare computer called a provisioning node in the state of FIG. That is, the boot image including the operating system is not loaded on the computer C5, and the computer C5 is not booted.
  • the number of spare computers does not need to be one, and a configuration in which a plurality of spare computers are arranged may be used.
  • the storage device SS has a database DBDB.
  • the data base DBDB uses the disks D1 to D4 and the disks D1 to D4 in the storage device SS as boot disks.
  • management table 7 holds a management table (management information) for managing the correspondence with the computer (boot computer).
  • the preliminary computer mining unit PPi has a database CDDBi.
  • the database CDDB i holds a management table (management information) for managing the relationship between the status of each computer C 1 to C 5 and the disks D 1 to D 4 in the computer system of FIG. I do.
  • the boot image stored on the disk D i in the storage device SS is harmed by “host-i” as the host name.
  • the corresponding relationship between the boot image and the computer so that it is executed on the computer
  • Boot unit B Bi is the host name
  • the computer to which "host-i" is assigned is booted by the boot image set by the boot image setting unit BSi.
  • the faulty computer search process FP runs on one of the running computers C1 to C4, for example, the computer C1.
  • Failure computer search process FP uses database HDB It functions as a fault computer search unit for searching for fault computers.
  • the database HDB holds a management table (management information) for managing whether the computer to which "host-i" is assigned is running (live).
  • the preliminary computer search unit P Pi, the boot image setting unit B Si, and the boot unit B Bi, which operate on the computer C i, are, for example, program units.
  • each program unit is included in the fault computer alternative control program.
  • the units PP i, BS i and B BI are realized by the computer C i (not shown C PU) reading and executing the fault computer alternative control program.
  • the fault computer search process FP running on computer C 1 is also a program unit included in the fault computer substitution control program.
  • the search process F P is also realized by the computer C 1 reading and executing the faulty computer alternative control program. Therefore, the search process FP may operate on a computer other than the computer C1.
  • the operating computers C1 to C4 also operate the class control units CC1 to CC4.
  • the cluster control units CC1 to CC4 detect a failed computer (failed computer) by communicating with each other via the network N.
  • the cluster control units CC1 to CC4 mutually and periodically transmit a signal called a hard beat signal.
  • the class control units CC1 to CC4 allow the heartbeat signal to be transmitted for a predetermined period of time (timeout time). Based on the interruption, the failure occurrence is determined for the computer on which the corresponding cluster control unit exists.
  • the cluster control units CC1 to CC4 constitute one virtual class control system CC.
  • the cluster control system CC performs a control for transferring the service executed on the computer in which the failure was detected (that is, the failure computer) to another computer.
  • a failure computer search process FP is defined in advance as one of the services controlled by the class control system CC.
  • the search process FP is designed so that, when the computer on which the process FP is operating (computer C1 in FIG. 1) is stopped due to a failure or the like, the search process FP is started by another computer. Controlled by control system CC.
  • the class controller C C i is realized by the computer C i reading and executing a cluster control software program (cluster software).
  • cluster software cluster software
  • the class software and the fault computer alternative control program are independent programs.
  • code information corresponding to a fault computer alternative control program into class software in advance.
  • each record of the database CDDB i includes items for setting information of a computer, the status of the computer, and each disk.
  • the computer identifier used to identify the computer is used as the computer information.
  • Status is the status of the corresponding computer And indicates “Run” (S), “Provisioning” (P), “Down” (D) or “Reserve” (R). If the status is "Active” (S), the disk item in the corresponding record contains the boot image used to start the computer indicated by the computer identifier in the record.
  • a disk identifier is set to identify the stored disk (storage device).
  • the database C DDB i in FIG. 2 shows the state of the computer system in FIG. First, the computers C 1 to C 4 are "operating"
  • Figure 3 is a state transition diagram showing the state transition of the computer.
  • a state (1) that is not physically incorporated into the system is shown.
  • the computer (preliminary computer) in the “provisioning” (P) state passes through the “reserved” (R) state and becomes the “operating” (S) state. It can be switched to a state.
  • Fig. 4 shows an example of the data structure of the database DBDB in Fig. 1.
  • each record in the database DBDB includes information (for example, a disk identifier) of a disk (boot disk) storing a boot image, and a record of the disk.
  • Fig. 5 shows an example of the data structure of the database HDB in Fig. 1.
  • each record of the database HDB includes items for setting information indicating a host (for example, a host name) and information of a counter (counter value).
  • a host for example, a host name
  • a counter counter value
  • FIG. 1 is a flowchart mainly showing the processing procedure of the fault computer search process FP.
  • an example is given of an operation in which a failure computer is detected, and a backup computer is started using the boot image applied to the failure computer.
  • the computers C 1 to C 4 are operating according to the boot images of “host-1” to “host-4”, respectively, that is, “operating” (S ).
  • Boot images of "hos1" to "host-4" are stored on disks D1 to D4 in the storage device SS, respectively.
  • the computer C5 is arranged in the computer system as a standby computer and is in the "provisioning" (P) state.
  • the contents of the databases CDDB1 to CDDB4 of the preliminary computer search units PP1 to PP4 in the operating computers C1 to C4 are all as shown in FIG. .
  • the contents of the database DBDB in the storage device SS are shown in Fig. 4. It's getting up.
  • the unit CC i transmits and receives a heartbeat signal to and from each other.
  • the computer Cj determined to have a fault by the class control system CC is assigned to the computer Cl on which the faulty computer search process FP is operating, that is, the host name "host-1". It is assumed that it is the assigned computer C 1.
  • the search process FP is defined as a service that should be taken over (failover) to another computer when the computer on which the process FP is running is determined to be a faulty computer. I have.
  • the computers C2 to C4 are positioned as standby computers.
  • the search process FP is executed by the computer C 1. 2 to C4.
  • the search process FP is carried over from the fault occurrence computer C1 to the computer C2 as shown in FIG. Thereafter, the search process FP runs on the computer C2.
  • the failure computer search process FP executes the following procedure to detect such a state and switch from the computer C j to the spare computer.
  • the search process FP refers to the database HDB to search for a host whose count has not changed during the above-mentioned fixed time (step S2). If there are no hosts whose counters have not changed, that is, if none of the counters corresponding to each host has changed, the search process FP determines that no host has failed. to decide. In this case, the mining process FP returns to step S1 and sleeps. Thereafter, the search process FP repeats the processing of steps S1 and S2 unless there is no host whose power has not changed.
  • the search process FP determines the cause of the interruption of the heartbeat signal from the cluster control unit of the host. This is because the host has failed and the host has been rebooted. It is one of the things to be done.
  • the search process FP sleeps for a certain period of time necessary for the reboot to determine this factor (step S3). After that, the search process FP determines whether the count of the host previously determined to be unchanged has not changed by referring to the de-night base HDB again. (Step S4). If the above counter has not changed yet, the search process FP determines that the corresponding host is not alive and has therefore failed.
  • the failure of the computer C 1 to which the host name “host-1” is assigned is determined.
  • the search process FP is controlled by the class control system C C and is operating on the computer C 2 instead of the computer C 1 (see FIG. 7).
  • the standby computer PP2 is used to search for a standby computer (provisioning node).
  • the search for the preliminary computer by the preliminary computer search unit PP2 is performed as follows.
  • the preliminary computer search unit PP2 refers to the database CDDB2. Then, the search unit P P2 will be able to see the status “Provisioning”
  • the computer identifier of the computer in the state of (P) is C5.
  • the computer C5 is detected (selected) as a standby computer.
  • the search unit PP 2 detects (selects) the computer C 5 as a spare computer, it operates the database CDDB 2 as follows. That is, when the computer C 1 is a failure computer and the computer C 5 is a standby computer, the search unit PP 2 sets the status of the failure computer C 1 and the standby computer C 5 to “down” (D) and “ To "Reserve” (R).
  • the database operation contents of this search unit PP 2 are reflected in the database base CDDB 3 and CDDB 4 of the search units PP 3 and PP 4 of the other computers C 3 and C 4 in operation. .
  • the contents of the database CDDB 3 and CDDB 4 will be changed to match the contents of the database CDDB 2.
  • FIG. 9 shows the contents of the databases CDDB 2 to CDDB 4 (CDDB i) after this change.
  • the failure computer search process FP performs a control for causing the spare computer C5 to use the boot image used by the failed computer C1. Do. In this case, the search process FP executes the boot image used by the computer C1 on the spare computer C5, so that the database DBDB in the storage device SS is set to the boot image setting unit. G is operated by BS2 (step S5).
  • the boot image setting unit BS2 is a record in which the failure computer C1 is set as the boot computer among the records in the database DBDB, that is, the information (calculation) of the computer C1. Select the record that contains the (machine identifier). This selected record As is apparent from FIG. 4, the information of the disk D1 (disk identifier) is set in the code in pairs with the information of the computer C1 (computer identifier). Therefore, the selected record indicates that the boot image used to boot the failure computer C1 is stored in the disk D1.
  • the boot image setting unit BS 2 operates the selected record as follows in order to execute the boot image stored in the disk D 1 on the preliminary computer C 5.
  • the update operation of the record by the setting unit BS2, that is, the update operation of the database DBDB, is performed by replacing the boot image used for booting the failure computer C1 with the backup computer C5. This is equivalent to selecting the boot image as the boot image for booting. That is, the setting unit BS2 functions as a boot image selection unit.
  • the boot image selection operation (operation of the database DBDB) by the setting unit BS2 allows the boot image (disk D1) of “host-1” running on the failure computer C1 to be executed. Is indirectly set in the spare computer C5.
  • Figure 8 shows the contents of the database DBB at this time.
  • the failure computer search process FP executes the boot image by executing the step S5 using the boot image setting unit BS2.
  • the preliminary computer C5 is booted with the selected boot image (step S6).
  • the spare computer C5 has an interface circuit (not shown).
  • This interface circuit operates as a control circuit for connecting to the network N.
  • This interface circuit is on standby to receive a special packet transmitted from the network N to itself. Therefore, the standby current is always supplied to the interface circuit.
  • the interface circuit receives a special packet addressed to itself via the network N, the interface circuit has a function to start (boot) a computer having the interface circuit (in this case, the preliminary computer 5). Have.
  • the standby computer C5 having such an interface circuit is set in a state in which it can always be started (standby).
  • the boot nit BB 2 sends a special packet to the backup computer C 5 via the network N in order to activate the backup computer C 5.
  • the interface circuit of the preparatory computer C5 causes the preparatory computer C5 to start startup processing (processing such as boot boot loader) based on the reception of the special packet.
  • the preliminary computer C5 that has started the boot process refers to the database DBDB to search for a disk on which a booty image for booting itself is recorded.
  • the standby computer C5 refers to the database DBDB to search for a record in which the identifier of the standby computer C5 is set.
  • the preliminary computer C 5 According to the identifier of the disk D1 recorded in the record in which the identifier of the found preliminary computer C5 is set, the "host-11" block stored in the disk D1 in the storage device SS is recorded. — Boot with toy image.
  • the technique of transmitting a special bucket to a specific computer via a network and activating the specific computer as described above is widely and generally known under the name of Wakeon LAN (trademark).
  • the boot image of host-1 "that was being executed by the failed computer C1 can be executed by the computer C5.
  • the computer C 5 is started as “host-1.”
  • the database CDDB 2 is operated, and the status of the computer C 5 changes from “reserved” (R) to “active” (S).
  • the operating system ⁇ S 1 the standby computer search unit PP 1, and the boot image setting unit that were operating on the computer C 1 until the computer C 1 failed.
  • the BS1, the boot unit BB1 and the class control unit CC1 operate on the computer C5 as shown in FIG.
  • the process FP is taken over by another computer (here, the computer C2). For this reason, the failure of the computer C 1 can be reliably determined by the search process FP.
  • the standby computer search unit, boot image setting unit, and boot unit (here, standby computer) that operate on the succeeding computer Using the computer search unit PP 2, the boot image setting unit BS 2 and the boot unit BB 2), search for the spare computer and the boot image used by the fault computer C 1, respectively. It is possible to realize the setting for making the standby computer usable and to automate the boot of the standby computer.
  • a counter that is incremented each time a heartbeat signal is received within the timeout period is used to detect a host failure.
  • the time when the heartbeat signal is still not received even after the timeout time elapses that is, by monitoring the elapsed time from the timeout time (first timeout time)
  • the failure of the corresponding host may be determined.
  • FIG. 11 is a block diagram showing a configuration of a computer system according to the second embodiment of the present invention.
  • components equivalent to those of the computer system of FIG. 1 are denoted by the same reference numerals.
  • the configuration of the computer system in Fig. 11 will be described focusing on the differences from the computer in Fig. 1.
  • a remote distribution server RDS is connected to the network N.
  • the remote distribution server RDS is connected to the network N.
  • disk drive R1, R2, R3 and R4 are provided.
  • the disks R 1, R 2, R 3 and R 4 contain
  • the computers C 1, C 2, C 3, C 4 and C 5 have disks (local disk drives) D 1, D 2, D 3, D 4 and D 5, respectively.
  • Disks Dl, D2, D3, and D4 contain disks Rl, R2, R of remote distribution server RDS.
  • FIG. 11 is a flowchart mainly showing the processing procedure of the fault computer search process FP.
  • an operation of detecting a failure computer, setting the boot image applied to the failure computer as a standby computer, and starting the standby computer will be described as an example.
  • the computers C 1 to C 4 are connected to the host computers “host-l” to “host-4” copied to the disks D 1 to D 4, respectively.
  • Operating state that is, the state of “operating” (S).
  • Computer C5 is located in the computer system as a standby computer, and is called "Provisioning".
  • the search process FP is a process corresponding to steps S I, S 2, S 3 and S 4 in FIG.
  • Steps Sl, S12, S13, and S14 determine the failure of the computer C1.
  • the search process FP is taken over by any of the standby computers C2 to C4, for example, the computer C2, in the following stage.
  • This stage means that the heartbeat signal from the cluster control unit CC1 operating on the computer C1 is interrupted beyond the time-out time, and as a result, the computer C1 is controlled by the cluster control system CC. This is the stage at which the occurrence of a failure has been detected.
  • the spare computer search unit PP2 is used to search for a spare computer.
  • the search process FP causes the backup computer C5 to use the boot image of "host-1" used by the failed computer C1. Control for the operation.
  • the search process FP executes the boot image by the boot image setting unit BS2 to execute the boot image. Copy it to the local disk D5 of C5 (step S15).
  • the boot image of "host-1" is stored on disk R1 in the remote distribution server RDS.
  • boot image setup unit BS2 selects disk R1 from remote distribution server RDS, and boot image setup unit BS2 is stored on disk R1.
  • the boot image of "host-1” is copied to the local disk D5 of the preliminary computer C5 (step S15).
  • the boot image of “host-1” executed on the failure computer C 1 is directly set to the spare computer C 5 detected (selected) by the failure computer search process FP. .
  • This is different from the first embodiment in which the boot image of "host-1" executed on the failure computer C1 is indirectly set on the spare computer C5.
  • the search process FP causes the boot unit BB2 to boot the computer C5 according to the boot image of "host-1" copied to the disk D5 of the preliminary computer C5.
  • Step S16 The boot operation of the computer C5 by the boot unit BB2 is performed in the same manner as the boot operation in the first embodiment.
  • the computer C5 is started as "host-1".
  • the operating system OS 1, the standby computer search unit PP 1, the boot image setting unit BS 1, the unit BB 1, and the cluster control unit CC 1 are configured to operate on the computer C 5. Become.
  • FIG. 13 is a block diagram showing a configuration of a computer system according to the third embodiment of the present invention.
  • components equivalent to those of the computer system of FIG. 1 are denoted by the same reference numerals.
  • computers C1, C2, C3, and C4 are stored on disks D1, D2, D3, and D4 in the storage device SS, respectively.
  • the feature of the fault computer search process FP1, FP2, FP3 and FP4 is that the host names are "host-1", "host-2”,
  • the search processes FP 1, FP 2, FP 3 and FP 4 correspond to the search process FP, Is different from the search process FP, which operates only on one of the computers.
  • Another feature of the search processes FP 1, FP 2, FP 3 and FP 4 is that they can recognize the computer on which they should operate.
  • the search processes FP1, FP2, FP3, and FP4 determine the host name (own host name) assigned to the computer on which they are running by using the storage device.
  • the search processes FP1, FP2, FP3, and FP4 search for faulty computers by using the host name recognition function. Therefore, unlike the search process FP, the search processes FP1, FP2, FP3, and FP4 do not require the database HDB to search for a faulty computer.
  • failure computer search processes FP1, FP2, FP3, and FP4 are defined in advance as services controlled by the cluster control system CC.
  • the search processes FP1, FP2, FP3, and FP4 are executed by the computers on which the processes FP1, FP2, FP3, and FP4 are operating (the computers C1, C2, When C3 and C4) are stopped due to a failure or the like, they are controlled by the class control system CC so that they are started by other computers.
  • FIG. 14 is a flowchart mainly showing the processing procedure of the fault computer search process FPl (FPi).
  • FPi fault computer search process
  • TM fault computer search process
  • the fault computer search process FP 1 determines whether or not it is running on the computer which should operate itself, that is, the computer C 1 whose host name is “host-1” (Ste S21). Normally, the search process F P1 is running on the computer C 1 as shown in FIG. In this case, the search process FP1 sleeps until the next time it is started (step S28). Now, it is assumed that a failure has occurred in the computer C 1 on which the search process F P 1 is running. Then, the search process FP1 is transferred (failed over) from the faulty computer C1 to another computer in the computer system under the control of the class controller CC. That is, the location where the search process FP1 is activated is changed from the faulty computer C1 to another computer.
  • the search process FP1 operates on a computer different from the computer (C1) having the host name "host-1" on which the search process FP1 should operate.
  • the search process FP1 has been started on the computer C2 whose host name is "host-2".
  • the search process FP 1 When the search process FP 1 is started on the computer C 2, in step S 21 above, the search process FP 1 is not a computer C 1 whose own host name is “host-1” and is not a computer (host). It is determined that it is running on the computer C2) whose name is "hosts.” Then, the search process FP1 determines that the host name on which it was originally running is It recognizes that a failure has occurred in the computer C1 on "host-1". In this case, the search process FP1 searches for a spare computer by using, for example, the spare computer search unit PP2 on the computer C2 on which it is currently operating (steps S22, S23).
  • the search for the preliminary computer by the search unit PP 2 is performed by referring to the database CDDB 2 and determining that the computer is in the “provisioning” (P) state. This is achieved by acquiring the computer identifier of If there is no computer in the “provisioning” (P) state, the faulty computer search process FP1 sleeps for a certain period of time (step S24), and then enters the standby computer search unit. A backup computer is searched again using PP2 (steps S22 and S23).
  • the computer C5 is detected as a standby computer.
  • the failure computer search process FP1 executes processing (steps S25 and S26) corresponding to steps S5 and S6 in FIG. 6 when the standby computer C5 is detected (selected).
  • the search process FP 1 controls the boot computer of “host-1” used by the failed computer C 1 to be used by the standby computer C 5.
  • the search process F P 1
  • Step S25 By operating this database DBDB, the first embodiment Similarly to the state, the boot image used to boot the failure computer C1 is selected as the boot image for booting the spare computer C5.
  • the search process FP1 uses the boot unit BB2 on the computer C2 on which it is currently operating to switch the standby computer C5 to the above-mentioned “host-1” booth.
  • the boot image of "host-1" that was being executed by the failed computer C1 can be executed by the computer C5. That is, the computer C5 was started as "host-1", and was operating on the computer C1 until the computer C1 failed.
  • the operating system OS1 and the standby computer search unit PP1 Then, the boot image setting unit BS1, the boot unit BB1, and the class control unit CC1 operate on the computer C5.
  • step S28 Sleep until activated on step 28 (step S28).
  • the spare computer search unit PP 1 (PP i), the boot image setting unit BS 1 (BS i), and the boot unit BB 1 (BB i) are connected to the fault computer search process FP 1 (FP i).
  • the preliminary computer search unit PPI (PPi), the boot image setting unit BSI (BSi) and the boot unit BB1 (BBi) are attached to the fault computer search process FP1 (FPi). It is also possible to adopt a configuration that includes (includes). In this configuration, when the fault computer search process FP1 is transferred from the computer C1 to the computer C2 under the control of the class control system CC, the standby computer search unit PP1 and the boot image setting are performed.
  • the unit BS1 and the boot unit BB1 are also moved to the computer C2.
  • the fault computer search process FP1 uses the spare computer search unit PP1, the boot image setting unit BS1 and the boot unit BB1 to perform the processing shown in the flowchart of FIG. Run.
  • the cluster control system CC uses a time-out time longer than the time-out time used for detecting a computer failure with respect to the failure computer search process FP 1 (FP i). Movement control from a faulty computer to another computer It is good to do aileo.
  • FIG. 15 is a block diagram showing a configuration of a computer system according to the fourth embodiment of the present invention.
  • components equivalent to those of the computer system of FIG. 11 or FIG. 13 are denoted by the same reference numerals.
  • the difference between the computer system of FIG. 15 and the computer system of FIG. 13 applied in the third embodiment is that the computer system of FIG. 11 applied in the second embodiment differs from the computer system of FIG. This differs from the computer system of FIG. 1 applied in the embodiment of FIG.
  • the processing procedure of the faulty computer search process FP1 (FPi) in the computer system of Fig. 15 is shown in the flowchart of Fig. 16. As is clear from FIG.
  • the failure computer search process FPI corresponds to steps S21 to S28 of the flow chart of FIG. 14 applied in the third embodiment.
  • Step S31 to S38 step S37 is executed by the cluster control system CC similarly to step S27 in FIG.
  • the flow chart of FIG. 16 differs from the flow chart of FIG. 14 in the process (step S35) corresponding to step S25 in FIG. That is, the process for causing the spare computer C5 to use the boot image used by the failure computer C1 is different.
  • step S35 the boot image used by the failure computer C1, that is, the boot image stored in the disk R1 in the remote distribution server RDS, is immediately copied to the local disk of the standby computer C5. Processing to copy to D5 is performed. This process is shown in Figure 12 This is the same as step S15.
  • the failure detection of the computer is used as a trigger to execute the boot image executed by the computer.
  • the technique of starting up the standby computer in the printer is applied. Applying this technology, for example, a configuration in which a standby computer is started with the boot image executed by the computer, as a trigger when the load on the computer becomes larger than the reference value, for example, is triggered. Is also possible. In this case, it is not always necessary to take over the fault computer search process. It is also possible to adopt a configuration in which the arrival of a predetermined time triggers the same computer to be booted with different boot images depending on the time zone.
  • the same computer is started in the first boot image including the first operating system during the day, for example, and is started in the second boot image including the second operating system during the night.
  • This configuration is particularly suitable for the computer system shown in Fig. 1 or Fig. 13 which does not require copying of the booty image.
  • the present invention is not limited to the above-described embodiments as they are, and can be embodied by modifying constituent elements without departing from the scope of the invention in the implementation stage.
  • various inventions can be formed by appropriately combining a plurality of constituent elements disclosed in the above embodiments. For example, some components may be deleted from all the components shown in the embodiment. Further, constituent elements of different embodiments may be appropriately combined.
  • a boot image is set in the spare computer so that the spare computer can be used as a substitute for the failed computer without the intervention of an operator. Can be activated.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Quality & Reliability (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Hardware Redundancy (AREA)
  • Stored Programmes (AREA)

Abstract

計算機(C1)上で動作する故障計算機探索プロセス(FP)は、当該計算機(C1)で障害が発生すると、他の計算機、例えば計算機(C2)で起動される。探索プロセス(FP)は、故障計算機(C1)を見つけると、予備計算機探索ユニット(PP2)を用いて予備計算機(C5)を探す。ブートイメージ設定ユニット(BS2)は、故障計算機(C1)で実行されていたブートイメージを記憶する記憶ユニット(D1)を選択する。ブートユニット(BB2)は、選択された記憶ユニット(D1)に記憶されているブートイメージを用いて、選択された予備計算機(C5)をブートさせる。

Description

P2004/006500
明 細 書
計算機システム及び同システムに適用される故障計算機代替 制御方法
技術分野
本発明は、 プロ ビジョ エングノー ド と呼ばれる予備計算機 を含む複数の計算機で構成される計算機システムに係わる。 本発明は特に、 稼動中の計算機が故障した場合に、 その故障 した計算機で実行されていたブー トイ メージを予備計算機で 実行可能とするのに好適な計算機システム及び同システムに 適用される故障計算機代替制御方法に関する。
背景技術
近年、 1 つの筐体内に数十乃至数百もの計算機ノー ドを含 む高密度型の計算機システムが市販されている。 このような 計算機システムには、 プロビジョ ニングノー ド と呼ばれる予 備計算機が含まれる こ とが多い。 一般に、 予備計算機は通常 は使用されず、 通常使用 している計算機が故障した場合の代 替計算機 (代替ノー ド) として使用される。 そのためには、 故障した計算機で実行されていたブー トイ メージを、 予備計 算機のブー トイ メージと して設定するためのオペレータ操作 が必要となる。 この設定の後、 予備計算機を起動する ことに よ り、 当該予備計算機を故障した計算機の代わ り と して使用 する こ とができる。
一方、 金子哲夫、 森良哉、 "ク ラスタソフ ト ウェア " 、 東 芝レビュー、 Vol .54 No . 1 2( 1999)、 p . 1 8 -21 (以下、 先行技術 文献と称する) には、 ク ラスタシステムと呼ばれる計算機シ T JP2004/006500
2 ステムが記載されている。 ク ラスタシステムにおいては、 稼 動状態にある計算機で障害が発生した場合に、 その障害が発 生した計算機で実行されていたサービス (業務) を、 システ ム内の他の計算機に引き継がせる (フェイルオーバする) こ とができる。 このサービスを引き継ぐ計算機には、 例えば待 機状態 (ホッ トスィ 夕ンバイ状態) にある計算機が用い られ る。
上記したよう に、 予備計算機 (プロ ビジョ ニングノー ド) を含む従来の計算機システムでは、 システム内の計算機が故 障した場合、 予備計算機を故障した計算機の代わ り として使 用する ことができる。 しかし、 従来の技術では、 予備計算機 を故障した計算機の代わ り と して使用可能とするには、 オペ レー夕の介在が必要である。
一方、 上記先行技術文献に記載されたク ラス夕システムで は、 故障した (障害が発生した) 計算機で実行されていたサ —ビスを、 システム内の他の計算機に自動的に引き継がせる (フェイルオーバする) こ とが可能である。
しかし、 このク ラス夕システムでは、 サービスの引き継ぎ 先の計算機は起動 (ブー ト) されている必要がある。 このた め、 ク ラスタシステムで適用されるサービスを引き継ぐ技術 を、 予備計算機を故障した計算機の代わ り として使用可能と する仕組みに応用する こ とは困難である。
発明の開示
本発明は上記事情を考慮してなされたものでその目的は、 計算機システムに含まれる計算機が故障した場合に、 ォペレ —夕の介在なしで、 予備計算機を故障した計算機の代わ り と して使用できるよう にする こ とにある。
本発明の 1 つの観点によれば、 予備計算機を含む複数の計 算機を備えた計算機システムが提供される。 この計算機シス テムは、 前記複数の計算機をブー トするための各ブー 卜ィ メ ージをそれぞれ個別に記憶する複数のス 卜 レージ装置と、 前 記複数の計算機のステータスを記憶する第 1 の記憶ュニッ ト と、 前記複数のス ト レージ装置の各々 と当該ス ト レ一ジ装置 に記憶されているブー トイ メージでブー ト されている計算機 との対応関係を表す情報を記憶する第 2 の記憶ュニッ 卜 と、 前記計算機システム内で故障した計算機を探索するよう に構 成された故障計算機探索ユニッ ト と、 前記故障計算機探索ュ ニッ トが故障した計算機を見つけたとき、 前記故障した計算 機の代替として使用するための予備計算機を、 前記第 1 の記 憶ュニッ 卜に記憶されている前記複数の計算機のステータス に従って選択するよう に構成された予備計算機探索ュニッ 卜 と、 前記故障計算機探索ュニッ トが故障した計算機を見つけ たとき、 前記予備計算機探索ユニッ トが選択した予備計算機 をブー 卜するためのブー トイ メージが記憶されたス 卜 レージ 装置を、 前記第 2 の記憶ュニッ トに記憶されている情報に従 つて選択するよう に構成されたブー トイ メージ選択ュニッ ト と、 前記予備計算機探索ュニッ 卜が選択した予備計算機を、 前記ブー トイ メージ選択ュニッ 卜が選択したス ト レージ装置 に記憶されているブー トイ メージを用いてブー トするよう に 構成されたブ一 卜ュニッ 卜 とを具備する。 P T/JP2004/006500
4 図面の簡単な説明
図 1 は本発明の第 1 の実施形態に係る計算機システムの構 成を示すブロ ッ ク図。
図 2 は図 1 中のデータベース C D D B i ( i = l , 2 , 3 , 4 ) のデータ構造例を示す図。
図 3 は計算機の状態の遷移を示す状態遷移図。
図 4 は図 1 中のデータベース D B D B のデータ構造例を示 す図。
図 5 は図 1 中のデ一夕ベース H D Βのデータ構造例を示す 図。
図 6 は同第 1 の実施形態の主と して故障計算機探索プロセ ス F Ρ の処理手順を示すフローチヤ一 ト。
図 7 は同第 1 の実施形態において故障計算機探索プロセス F Ρが計算機 C 1 から計算機 C 2 にフェイルオーバされた状 態を示す図。
図 8 は図 6 中のステップ S 5 の実行後のデータベース D B D Βの内容を示す図。
図 9 は図 6 中のステップ S 5 の実行後のデータベース C D D B i の内容を示す図。
図 1 0 は故障した計算機 C 1 が実行していたブ一 トイ メー ジを計算機 C 5 によって実行する こ とが可能となった状態を 示す図。
図 1 1 は本発明の第 2 の実施形態に係る計算機システムの 構成を示すブロ ック図。
図 1 2 は同第 2 の実施形態の主として故障計算機探索プロ 2004/006500
5 セス F P の処理手順を示すフロ一チヤ一卜。
図 1 3 は本発明の第 3 の実施形態に係る計算機システムの 構成を示すプロ ッ ク図。
図 1 4 は同第 3 の実施形態の主として故障計算機探索プロ セス F P 1 の処理手順を示すフローチヤ一卜。
図 1 5 は本発明の第 4 の実施形態に係る計算機システムの 構成を示すブロ ッ ク図。
図 1 6 は同第 4 の実施形態の主と して故障計算機探索プロ セス F P 1 の処理手順を示すフローチヤ一ト。
発明を実施するための最良の形態
以下、 本発明の実施の形態につき図面を参照して説明する。 図 1 は本発明の第 1 の実施形態に係る計算機システムの構成 を示すブロ ッ ク図である。 図 1 の計算機システムは、 5台の 計算機 C 1 乃至 C 5 から構成される。 計算機 C 1 乃至 C 5 は ネッ 卜 ワーク Nで相互に接続されている。 また計算機 C 1 乃 至 C 5 はス ト レージ · エリ ア · ネッ ト ワーク S A Nに接続さ れている。 このス ト レージ ' エリ ア · ネッ ト ワーク S A Nに は、 ス ト レ一ジ装置 S S も接続されている。 ス ト レ一ジ装置 S S には、 ディ スク (ディ スク ドライ ブ) D 1 乃至 D 4が設 けられている。 つま り、 計算機 C 1 乃至 C 5 とス ト レ一ジ装 置 S S 内のディ スク D 1 乃至 D 4 とはス ト レ一ジ ' エリ ア · ネッ 卜 ワーク S A Nで接続されている。
ディ スク D l, D 2, D 3 及び D 4 には、 それぞれホス ト 名 と して "host- 1" , " host-2" , " host-3" 及び "host-4" が割り 当てられる計算機のためのプ一 卜イ メージが予め保存 されている。 ディ スク D i ( i = 1 , 2 , 3 , 4 ) に保存さ れているブー トイ メージを " host-i" のブー 卜イ メージと呼 ぶ " host-i" のブー トイ メージは、 例えばオペ レーティ ン グシステム O S i 、 及び当該オペレーティ ングシステム O S i のも とで動作するアプリ ケーショ ンプログラムを含む。 つ ま り ディ スク D i は、 " host-i" のブー トディ ス ク と して用 レ られる。
図 1 には、 計算機 C 1 乃至 C 5 のう ちの計算機 C 1 乃至 C 4が、 各々ディ スク D 1 乃至 D 4が保存しているブー トィ メ ージを用いて起動して稼動している状態が示されている。 ま た、 図 1 には、 稼動中の計算機 C 1 乃至 C 4上で、 それぞれ オペレーティ ングシステム〇 S 1 乃至 O S 4 が動作している 状態も示されている。 これら稼動中の計算機 C 1 乃至 C 4 は、 自身のホス ト名を、 それぞれディ スク D 1 乃至 D 4のブー ト イ メージ中に記録された "host- 1" 乃至 "host-4" と認識し ているものとする。 一方、 計算機 C 1 乃至 C 5 のうちの残り の計算機 C 5 は、 図 1 の状態では、 プロ ビジョ ニングノー ド と呼ばれる予備計算機として配置されている。 つま り 計算機 C 5 には、 オペレーティ ングシステムを含むブー トイ メージ はロー ドされてお らず、 当該計算機 C 5 はブー トされていな い。 なお、 予備計算機は 1 台である必要はなく 、 複数の予備 計算機が配置される構成であっても構わない。
ス ト レージ装置 S S は、 デ一夕ベース D B D B を有する。 デ—夕ベース D B D Bは、 ス ト レージ装置 S S 内のディ スク D 1 乃至 D 4 と当該ディ スク D 1 乃至 D 4 をブー トディ スク P T/JP2004/006500
7 とする計算機 (ブー ト計算機) との対応関係を管理するため の管理テーブル (管理情報) を保持する。
稼動中の計算機 C 1 乃至 C 4では、 それぞれ、 予備計算機 探索ュニッ ト P P 1 乃至 P P 4 、 ブー トイ メージ設定ュニッ 卜 B S 1 乃至 B S 4、 及びブー トユニッ ト B B 1 乃至 B B 4 が動作する。 予備計算機探索ユニッ ト P P i ( i = 1 , 2, 3 , 4 ) は、 予備計算機を探索する。 予備計算機採索ュニッ ト P P i は、 データベース C D D B i を有する。 データべ一 ス C D D B i は、 図 1 の計算機システム内の各計算機 C 1 乃 至 C 5 の状態とディ スク D 1 乃至 D 4 との関係を管理するた めの管理テーブル (管理情報) を保持する。
ブー トイ メージ設定ユニッ ト B S i は、 ス ト レ一ジ装置 S S 内のディ スク D i に保存されているブー トイ メージが、 ホ ス ト名と して " host-i" が害 U り 当て られる計算機で実行され るよ う に、 当該ブー トイ メージと計算機との対応関係の設定
(こ こでは間接的設定) を行う。 このユニッ ト B S i による ブー トイ メージと計算機との対応関係の設定 (ブ一 トイ メ一 ジ設定) は、 故障計算機探索プロセス F Pからの指示に従つ て行われる 。 ブー ト ユニ ッ ト B B i は、 ホス ト 名 と して
" host-i" が割 り 当て られる計算機を、 ブー トイ メージ設定 ュニッ ト B S i によって設定されたブー トイ メージによ り ブ 一卜させる。
稼動中の計算機 C 1 乃至 C 4 のうちのいずれか 1 つ、 例え ば計算機 C 1 では、 故障計算機探索プロセス F Pが動作する。 故障計算機探索プロセス F P は、 データベース H D B を利用 して故障計算機を探索する故障計算機探索ュニッ 卜 として機 能する。 データベース H D B は、 " host- i " が割 り 当て られ ている計算機が稼動 (生存) しているかを管理するための管 理テーブル (管理情報) を保持する。
計算機 C i 上で動作する、 予備計算機探索ュニッ ト P P i 、 ブ一 トイ メージ設定ュニッ 卜 B S i 及びブー トュニッ 卜 B B i は、 例えばプログラムユニッ トである。 本実施形態では、 各プログラムュニッ トは故障計算機代替制御プログラムに含 まれている。 ユニッ ト P P i , B S i 及び B B i は、 故障計 算機代替制御プログラムを計算機 C i (内の図示せぬ C P U ) が読み取って実行する こ とによ り実現される。 計算機 C 1 上で動作する故障計算機探索プロセス F P も故障計算機代 替制御プログラムに含まれるプログラムュニッ トである。 探 索プロセス F P も、 故障計算機代替制御プログラムを計算機 C 1 が読み取って実行する こ とによ り実現される。 したがつ て、 計算機 C 1 以外の計算機で探索プロセス F Pが動作する こ ともあ り得る。
稼動中の計算機 C 1 乃至 C 4ではまた、 ク ラス夕制御ュニ ッ ト C C 1 乃至 C C 4が動作する。 ク ラスタ制御ュニッ ト C C 1 乃至 C C 4 は、 ネッ トヮ一ク Nを介して相互に通信を行 う こ とによ り、 障害が発生した計算機 (障害計算機) を検出 する。 こ こでは、 ク ラスタ制御ュニッ ト C C 1 乃至 C C 4 は、 ハー ド ビー ト信号と呼ばれる信号を相互に且つ定期的に送信 する。 ク ラス夕制御ユニッ ト C C 1 乃至 C C 4 は、 ハー ト ビ 一 卜信号が予め定め られた一定時間 (タイムアウ ト時間) を 超えて途絶えたこ とをもって、 対応するク ラスタ制御ュニッ トが存在する計算機での障害発生を判断する。 ク ラスタ制御 ュニッ ト C C 1 乃至 C C 4 は、 1 つの仮想的なク ラス夕制御 システム C C を構成する。 ク ラスタ制御システム C Cは、 障 害が検出された計算機 (つま り 障害計算機) で実行されてい たサービスを他の計算機に引き継がせるための制御を行う。 本実施形態では、 ク ラス夕制御システム C Cによ り制御され るサービスの 1 つとして、 故障計算機探索プロセス F Pが予 め定義されている。 つま り、 探索プロセス F P は、 当該プロ セス F Pが動作している計算機 (図 1 では計算機 C 1 ) が障 害等によ り停止した場合に、 他の計算機で起動されるよう に ク ラス夕制御システム C Cによ り制御される。
ク ラス夕制御ユニッ ト C C i は、 ク ラスタ制御用のソフ ト ウェアプログラム (ク ラスタソフ トウェア) を計算機 C i が 読み取って実行する ことによ り実現される。 本実施形態では ク ラス夕ソ フ 卜ウェアと故障計算機代替制御プログラムとは それぞれ独立のプログラムである ものとする。 しかし、 例え ば故障計算機代替制御プログラムに相当するコー ド情報をク ラス夕ソフ トウエアに予め組み込むこ とも可能である。
図 2 は、 図 1 中のデ一夕ベース C D D B i ( i = 1 , 2 , 3 , 4 ) のデータ構造例を示す。 図 2 に示すよう に、 データ ベース C D D B i の各レコー ドは、 計算機、 当該計算機のス テータス、 及びディ スクの各情報を設定するための項目を含 む。 計算機の情報には、 当該計算機を識別するための計算機 識別子が用いられる。 ステータスは、 対応する計算機の状態 を示し、 "稼動 " ( S ) 、 "プロ ビジ ョ ニング " ( P ) 、 "ダウン " ( D ) または "リザーブ" ( R ) を表す。 ステー 夕スが "稼動 " ( S ) の場合、 対応する レコー ド中のディ ス クの項目には、 当該レコー ド中の計算機識別子で示される計 算機の起動に用い られたブー トイ メージを保存しているディ スク (ス ト レ一ジ装置) を識別するためのディ スク識別子が 設定される。
図 2 のデータベース C D D B i は、 図 1 の計算機システム の状態を示している。 まず、 計算機 C 1 乃至 C 4 は "稼動"
( S ) の状態、 つま り、 それぞれディ スク D 1 乃至 D 4 をブ ー トディ スク と して稼動している状態にある。 一方、 計算機 C 5 は "プロ ビジョニング" ( P ) の状態、 つま り予備計算 機の状態にある。
図 3 は、 計算機の状態の遷移を示す状態遷移図である。 こ こでは、 上記 4つの計算機状態の他に、 システムに物理的に 組み込まれていない状態 (一) が示されている。 図 3 に示す よう に、 本実施形態では、 "プロ ビジョ ニング" ( P ) の状 態にある計算機 (予備計算機) は、 "リザーブ" ( R ) の状 態を経て "稼動" ( S ) の状態に切り替え可能である。
図 4 は、 図 1 中のデータべ一ス D B D B のデータ構造例を 示す。 図 4 に示すよう に、 デ一夕ベース D B D Bの各レコー ドは、 ブー トイ メージを保存しているディ スク (ブー トディ スク) の情報 (例えばディ スク識別子) 、 及び当該ディ スク をブー トディ ス ク とする計算機の情報 (例えば計算機識別 子) を設定するための項目を含む。 P T/JP2004/006500
11 図 5 は、 図 1 中のデータベース H D B のデータ構造例を示 す。 図 5 に示すよう に、 データベース H D B の各レコー ドは、 ホス トを示す情報 (例えばホス 卜名) 、 及びカウン夕の情報 (カウンタ値) を設定するための項目を含む。 こ こでは、 ク ラス夕制御ュニッ ト C C i か らハー ト ビー ト信号がタイムァ ゥ 卜時間内に送信される毎に、 当該制御ュニッ 卜 C C i が動 作しているホス トに対応するカウンタが 1 イ ンク リ メ ン トさ れる。
次に、 図 1 の計算機システムにおける動作について、 図 6 を参照して説明する。 図 6 は主として故障計算機探索プロセ ス F Pの処理手順を示すフローチャー トである。 こ こでは、 故障計算機を検出し、 その故障計算機に適用 されていたブー 卜イメージを用いて予備計算機を起動する動作を例に挙げる。 今、 図 1 の計算機システムでは、 計算機 C 1 乃至 C 4が、 そ れぞれ "host-1" 乃至 "host-4" のブー トイ メージに従って 稼動している状態、 つま り "稼動" ( S ) の状態にある もの とする。 "hosい 1" 乃至 " host-4" のブー トイ メージは、 そ れぞれス ト レージ装置 S S 内のディ スク D 1 乃至 D 4 に保存 されている。 また、 計算機 C 5 は予備計算機と して計算機シ ステム内に配置されてお り、 "プロ ビジョ ニング " ( P ) の 状態にあるものとする。 この場合、 稼動状態にある計算機 C 1 乃至 C 4内の予備計算機探索ュニッ 卜 P P 1 乃至 P P 4が 有するデータベース C D D B 1 乃至 C D D B 4 の内容は、 い ずれも図 2 に示したよ う になっている。 また、 ス ト レージ装 置 S S 内のデータベース D B D Bの内容は、 図 4 に示したよ う になつている。
図 1 の計算機システムにおいて、 ク ラスタ制御システム C C 内の各ク ラス 夕制御ュニッ 卜 C C i ( i = 1 , 2 , 3 , 4 ) 、 即ち各計算機 C i 上で動作しているク ラス夕制御ュニ ッ ト C C i は、 相互にハー ト ビー 卜信号を送受信する。 ク ラ ス夕制御ュニッ ト C C i は他のク ラスタ制御ュニッ ト C C j ( j = 1 , 2 , 3 , 4、 但し からタイ ムアウ ト時間 内にハー ト ビー 卜信号を受信できた場合、 データベース H D B内のレコー ドのう ち、 ク ラス夕制御ュニッ ト C C j が動作 しているホス ト に対応する レコー ド中のカウンタを 1 イ ンク リ メ ン トする。 ク ラス夕制御システム C Cは、 ク ラス夕制御 ュニッ ト C C j からのハー ト ビー ト信号がタイムアウ ト時間 を超えて途絶えた場合、 当該ク ラスタ制御ユニッ ト C C j が 動作している計算機 C j の障害発生を判断する。
こ こでは、 ク ラス夕制御システム C Cによ り 障害発生と判 断された計算機 C j が、 故障計算機探索プロセス F Pが動作 している計算機 C l 、 即ちホス ト名 " host- 1 " が割り 当てら れている計算機 C 1 である ものとする。 本実施例において、 探索プロセス F P は、 当該プロセス F Pが動作している計算 機が障害発生計算機と判断された場合に、 他の計算機に引き 継ぐべき (フェイルオーバすべき) サービス と して定義され ている。 また、 本実施形態のよう に探索プロセス F Pが計算 機 C 1 で動作している場合、 計算機 C 2 乃至 C 4 は待機系計 算機として位置付けられる。 これによ り 、 計算機 C 1 が障害 発生計算機と判断された場合、 探索プロセス F P は計算機 C 2 乃至 C 4のいずれかに引き継がれる。 こ こでは、 探索プロ セス F P は、 図 7 に示すよう に、 障害発生計算機 C 1 から計 算機 C 2 に引き継がれるものとする。 以降、 探索プロセス F P は、 計算機 C 2 上で動作する。
さて、 計算機 C j の障害が発生して、 ク ラス夕制御ュニッ ト C C j からのハー ト ピー ト信号が途絶えた状態が長時間続 く ものとする。 この場合、 計算機 C j に対応する上記 H D B 内のカウン夕は長時間変化しない。 故障計算機探索プロセス F P は、 このような状態の検出と、 計算機 C j か ら予備計算 機への切り替えとを、 次の手順で実行する。
まず故障計算機探索プロセス F Pは、 起動される と、 予め 定められた一定時間ス リープする (ステッ プ S 1 ) 。 次に探 索プロセス F P は、 データベース H D B を参照して、 上記一 定時間の間にカウン夕が変化していないホス トを探す (ステ ップ S 2 ) 。 も し、 カウンタが変化していないホス 卜がない ならば、 つま り 各ホス トに対応するカウン夕がいずれも変化 しているならば、 探索プロセス F P は、 故障したホス トはな いものと判断する。 この場合、 採索プロセス F P はステッ プ S 1 に戻ってス リ ープする。 以降、 探索プロセス F P は、 力 ゥン夕が変化していないホス トがない限り 、 ステップ S 1 及 び S 2 の処理を繰り返す。
これに対し、 カウン夕が変化していないホス 卜があるなら ば、 探索プロセス F Pは、 当該ホス トのク ラスタ制御ュニッ 卜からのハー ト ビー ト信号が途絶えている要因を判別する。 この要因は、 ホス 卜が故障したためと、 当該ホス 卜がリ ブー 卜されるための何れかである。 探索プロセス F P は、 この要 因の判別のために、 リ ブー トに必要な一定時間ス リ ープする (ステッ プ S 3 ) 。 その後、 探索プロセス F P は、 改めてデ 一夕ベース H D B を参照する こ とによ り 、 先に、 変化してい ないと判定されたホス 卜のカウン夕が依然と して変化してい ないかを判定する (ステッ プ S 4 ) 。 も し、 上記カウンタが 依然と して変化していない場合には、 探索プロセス F Pは、 対応するホス トは生存してお らず、 したがって故障したもの と判定する。 こ こでは、 ホス ト名 " host- 1" が割 り 当てられ ている計算機 C 1 の故障が判定されるものとする。
このとき探索プロセス F P は、 ク ラス夕制御システム C C による制御で、 計算機 C 1 ではなく て計算機 C 2 で動作して いる (図 7 参照) 。 探索プロセス F P は、 計算機 C 1 の故障 を判定した場合、 予備計算機探索ュニッ 卜 P P 2 によ り予備 計算機 (プロ ビジョニングノー ド) を探させる。 この予備計 算機探索ユニッ ト P P 2 による予備計算機の探索は、 次のよ う に行われる。
まず予備計算機探索ユニッ ト P P 2 は、 データベース C D D B 2 を参照する。 そして探索ユニッ ト P P 2 は、 デ一夕べ —ス C D D B 2 力、 ら、 ステータスが "プロ ビジ ョ ニング "
( P ) の状態にある計算機の計算機識別子を取得する。 デ一 夕ベース C D D B 2 ( C D D B 1 乃至 C D D B 4 ) が図 2 の よ う になつ ている本実施形態では、 "プロ ビジ ョ ニング "
( P ) の状態にある計算機の計算機識別子は C 5 である。 こ の場合、 計算機 C 5が予備計算機と して検出 (選択) される。 探索ユニッ ト P P 2 は、 計算機 C 5 を予備計算機として検 出 (選択) する と、 データべ一ス C D D B 2 を次のよう に操 作する。 即ち探索ユニッ ト P P 2 は、 計算機 C 1 が故障計算 機で、 計算機 C 5 が予備計算機である場合、 故障計算機 C 1 及び予備計算機 C 5 のステータスを、 それぞれ、 "ダウン " ( D ) 及び "リ ザ一ブ " ( R ) に変更する。 この探索ュニッ ト P P 2 のデータベース操作内容は、 稼動状態にある他の計 算機 C 3 及び C 4 の探索ュニッ ト P P 3 及び P P 4が有する デ—夕ベース C D D B 3及び C D D B 4 に反映される。 これ によ り、 デ一夕ベース C D D B 3 及び C D D B 4 の内容が、 データベース C D D B 2 の内容に一致するよう に変更される。 この変更後のデータベース C D D B 2 乃至 C D D B 4 ( C D D B i ) の内容を図 9 に示す。
さて、 予備計算機 C 5 が検出 (選択) された場合、 故障計 算機探索プロセス F Pは、 故障した計算機 C 1 が使用 してい たブー トイ メージを当該予備計算機 C 5 に使用させるための 制御を行う。 こ こでは、 探索プロセス F Pは、 計算機 C 1 が 使用 していたブー トイ メージを予備計算機 C 5 で実行させる ために、 ス ト レ一ジ装置 S S 内のデータベース D B D B をブ 一卜イ メージ設定ユニッ ト B S 2 によ り操作させる (ステツ プ S 5 ) 。
ブー トイ メ一ジ設定ュニッ ト B S 2 は、 データベース D B D B 中の レコー ドのう ち、 故障計算機 C 1 がブー ト計算機と して設定されている レコー ド、 つま り 計算機 C 1 の情報 (計 算機識別子) を含むレコー ドを選択する。 この選択されたレ コー ド には、 図 4 か ら 明 らかなよ う に、 計算機 C 1 の情報 (計算機識別子) と対をなしてディ スク D 1 の情報 (デイ ス ク識別子) が設定されている。 したがって、 選択されたレコ — ドは、 故障計算機 C 1 をブー 卜するのに用い られていたブ 一 卜イ メージがディ スク D 1 に記憶されている こ とを表す。
次に、 ブー トイ メージ設定ユニッ ト B S 2 は、 ディ スク D 1 に記憶されているブー 卜イ メージを、 予備計算機 C 5 で実 行させるために、 選択されたレコー ドを次のよう に操作 (更 新) する。 即ち設定ユニッ ト B S 2 は、 選択されたレコー ド を対象に、 ディ スク D 1 の情報 (ディ スク識別子) と対をな すブー ト計算機の情報 (計算機識別子) を、 故障計算機 C 1 か ら予備計算機 C 5 の情報に変更する。 この設定ユニッ ト B S 2 によるレコー ドの更新操作、 つま りデータべ一ス D B D Bの更新操作は、 故障計算機 C 1 をブー 卜するのに用いられ ていたブ一 卜イ メージを、 予備計算機 C 5 をブー トするため のブー トイ メージと して選択する こ とと等価である。 つま り 、 設定ユニッ ト B S 2 は、 ブー トイ メージ選択ユニッ ト として 機能する。 この設定ユニッ ト B S 2 によるブー 卜イメージ選 択操作 (デ一夕ベース D B D Bの操作) によ り 、 故障計算機 C 1 で実行されていた " host-1" のブー トイメージ (デイ ス ク D 1 に記憶されているブー トイ メージ) が、 予備計算機 C 5 に間接的に設定された こ とになる。 このときのデ一夕べ一 ス D B D Bの内容を図 8 に示す。
故障計算機探索プロセス F Pは、 ブー 卜イ メージ設定ュニ ッ 卜 B S 2 を用いてステッ プ S 5 を実行する と、 ブー トュニ ッ 卜 B B 2 によ り、 予備計算機 C 5 を上記選択されたブー 卜 イ メージでブー トさせる (ステッ プ S 6 ) 。 以下、 この予備 計算機 C 5 をブー トする動作について詳述する。 まず、 予備 計算機 C 5 は、 図示しないイ ンタフェース回路を持っている < このイ ン夕フェース回路は、 ネッ ト ワーク Nと接続するため の制御回路として動作する。 このイ ンタフェース回路は、 ネ ッ 卜 ワーク Nから 自身宛に送信される特別なパケッ 卜の受信 をするために待機している。 そのためィ ン夕フェース回路に は、 常時スタンバイ電流が供給されている。 イ ンタフェース 回路は、 ネッ トワーク Nを介して自身宛の特別なパケッ トを 受信した場合に、 当該イ ンタフェース回路を持つ計算機 (こ こでは予備計算機 5 ) を起動 (ブー ト) するための機能を持 つ。 このようなイ ンタフェース回路を持った予備計算機 C 5 は、 常時起動可能な状態 (スタンバイ) 状態に設定されてい る。
ブー トュニッ ト B B 2 は、 予備計算機 C 5 を起動させるた めに、 ネッ ト ワーク Nを介して予備計算機 C 5 に特別なパケ ッ ト を送信する。 予備計算機 C 5 のイ ンタフェース回路は、 この特別なパケッ トを受信したこ とに基づいて、 予備計算機 C 5 に起動処理 (ブー 卜 ローダーの起動などの処理) を開始 させる。 この起動処理を開始した予備計算機 C 5 は、 自身を ブー 卜するためのブ一 トイ メージが記録されたディ スク を探 すために、 データベース D B D B を参照する。 予備計算機 C 5 は、 データベース D B D B を参照して予備計算機 C 5 の識 別子が設定されている レコー ドを探す。 予備計算機 C 5 は、 探した予備計算機 C 5 の識別子が設定されているレコー ドに 記録されたディ スク D 1 の識別子に従い、 ス ト レージ装置 S S 内のディ スク D 1 に保存されている " h o s t 一 1 " のブ — トイ メージを用いてブー トする。 なお、 上記のよう にネッ ト ワークを介して特別なバケツ 卜を特定な計算機に送信して その特定な計算機を起動させる技術は、 W a k e o n L A N (商標) という名称で広く 一般に知られている。
上述した予備計算機 C 5 をブー トする動作によ り、 故障し た計算機 C 1 が実行していた host- 1" のブー トイ メージを、 計算機 C 5 で実行する こ とが可能になる。 つま り 、 計算機 C 5 が "host-1" として起動される。 する とデータベース C D D B 2 が操作されて、 計算機 C 5 のステータスが " リ ザ一 ブ" ( R ) か ら "稼動" ( S ) の状態に変更される。 この結 果、 計算機 C 1 が故障するまで当該計算機 C 1 上で動作して いた、 オペレーティ ングシステム〇 S 1 、 予備計算機探索ュ ニッ ト P P 1 、 ブー トイ メージ設定ユニッ ト B S 1 、 ブ一 卜 ユニッ ト B B 1 及びク ラス夕制御ユニッ ト C C 1 が、 図 1 0 に示すよう に計算機 C 5 で動作するよう になる。
このよう に本実施形態では、 故障計算機探索プロセス F P が障害発生計算機 C 1 上で動作していても、 当該プロセス F Pが他の計算機 (こ こでは計算機 C 2 ) に引き継がれる。 こ のため、 探索プロセス F P によ り 計算機 C 1 の故障が確実に 判定できる。 また、 探索プロセス F Pの制御によ り 、 引き継 ぎ先の計算機上で動作する予備計算機探索ユニッ ト、 ブー 卜 イ メージ設定ユニッ ト及びブー 卜ユニッ ト ( こ こでは、 予備 計算機探索ユニッ ト P P 2 、 ブー 卜イ メージ設定ユニッ ト B S 2 及びブー トュニッ ト B B 2 ) を利用 して、 それぞれ、 予 備計算機の探索、 故障計算機 C 1 が使用 していたブー トィ メ ージを予備計算機が使用可能とするための設定及び予備計算 機のブー 卜の自動化を実現できる。
上記実施形態では、 ホス トの故障検出に、 ハー ト ビー ト信 号をタイムアウ ト時間内に受信する都度イ ンク リ メ ン トされ るカウンタを用いている。 しかし、 タイムアウ ト時間を経過 してもハ一 卜 ビー ト信号が依然として受信されない時間、 つ ま り タイムアウ ト時間 (第 1 のタイムアウ ト時間) からの経 過時間を監視する こ とによ り 、 対応するホス トの故障を判定 する ことも可能である。 こ こでは、 第 1 のタイムアウ ト時間 からの経過時間が予め定められた第 2 のタイ ムァゥ ト時間を 超えた場合に、 対応するホス トの故障を判定すればよい。
[第 2 の実施形態]
図 1 1 は本発明の第 2 の実施形態に係る計算機システムの 構成を示すブロ ッ ク図である。 図 1 1 において、 図 1 の計算 機システムと等価な構成要素には同一符号を付してある。 ま ず、 図 1 1 の計算機システムの構成について、 図 1 の計算機 と相異する点を中心に説明する。 図 1 1 の計算機システムに おいて、 ネッ ト ワーク Nには、 リ モー ト配布サーバ R D S が 接続されている。 リ モー ト配布サーバ R D S は、 ディ ス ク
(ディ スク ド ライ ブ) R l , R 2 , R 3及び R 4 を備えてい る。 このディ スク R 1 , R 2 , R 3 及び R 4 には、 それぞれ
" host- 1 " , " ho st-2 , host-3 及び " host-4 のブー 卜 イ メージが予め保存されている。 このディ スク R l , R 2 , R 3及び R 4 に保存されているブー トイ メージの所定位置に は、 ホス ト名 "host-l" , "host- 2" , "host- 3" 及び "host - 4" が記録されている。 こ こで、 ディ ス ク R l , R 2 , R 3 及び R 4 に保存されているブー トイ メージで、 計算機 C 1 , C 2 , C 3 及び C 4 をそれぞれブー 卜するものとする。 この 場合、 計算機 C l , C 2 , C 3及び C 4 のホス ト名は、 それ ぞれ "host-l" , " host-2" , " host-3" 及び " host- 4" とな る。
計算機 C l , C 2 , C 3 , C 4及び C 5 は、 それぞれディ スク (ローカルディ スク ドライ ブ) D 1 , D 2 , D 3 , D 4 及び D 5 を備えている。 ディ スク D l , D 2 , D 3及び D 4 には、 リ モー ト配布サーバ R D S のディ スク R l , R 2 , R
3及び R 4 の内容がそれぞれコ ピーされている。 この場合、 計算機 C l , C 2 , C 3 及び C 4 を起動する と、 "hos 1"
" host-2" , " host-3 及び "host- 4" で特定されるホス トが 起動する。
次に、 図 1 1 の計算機システムにおける動作について、 図 1 2 を参照して説明する。 図 1 2 は主として故障計算機探索 プロセス F P の処理手順を示すフローチャー トである。 こ こ では、 上記第 1 の実施形態と同様に、 故障計算機を検出し、 その故障計算機に適用されていたブー トイ メージを予備計算 機に設定して当該予備計算機を起動する動作を例に挙げる。 今、 計算機 C 1 乃至 C 4が、 それぞれ、 ディ スク D 1 乃至 D 4 にコ ピーされた " host-l" 乃至 " host- 4" のブ一 トイ メー ジに従って稼動している状態、 つま り "稼動" ( S ) の状態 にある ものとする。 また、 計算機 C 5 は予備計算機として計 算機システム内に配置されてお り 、 "プロ ビジ ョ ニング"
( P ) の状態にある ものとする。 更に、 計算機 C 1 上では、 故障計算機探索プロセス F Pが動作している ものとする。 探 索プロセス F P は、 計算機 C 1 乃至 C 4 のいずれにも障害が 発生しない通常状態では、 図 6 中のステップ S 1 及び S 2 に 相当する処理 (ステップ S 1 1 及び S 1 2 ) を繰り返す。
このような状態で、 上記第 1 の実施形態と同様に計算機 C 1 が故障したものとする。 この場合、 探索プロセス F P は、 図 6 中のステップ S I , S 2 , S 3 及び S 4 に相当する処理
(ステッ プ S l l , S 1 2 , S 1 3及び S 1 4 ) によ り、 計 算機 C 1 の故障を判断する。 探索プロセス F Pは、 次に述べ る段階で、 待機系計算機 C 2 乃至 C 4 の何れか、 例えば計算 機 C 2 に引き継がれる。 この段階とは、 計算機 C 1 上で動作 するク ラスタ制御ュニッ 卜 C C 1 からのハー ト ビー ト信号が タイムァゥ ト時間を越えて途絶えた結果、 ク ラスタ制御シス テム C Cによ り 当該計算機 C 1 の障害発生が検出された段階 である。
探索プロセス F P は、 計算機 C 1 の故障を判断する と、 予 備計算機探索ュニッ ト P P 2 によ り予備計算機を探させる。 こ こでは、 上記第 1 の実施形態と同様に、 計算機 C 5 が予備 計算機として見つけられた (選択された) ものとする。 する と、 探索プロセス F Pは、 故障した計算機 C 1 が使用 してい た "host- 1" のブー トイ メージを予備計算機 C 5 に使用 させ る ため の制御を行 う 。 こ こ では、 探索プロ セス F P は、 "host-1" のブー トイ メージを予備計算機 C 5 で実行させる ために、 当該ブー トイ メージを、 ブー トイ メージ設定ュニッ ト B S 2 によ り 当該予備計算機 C 5 のローカルディ スク D 5 にコ ピーさせる (ステッ プ S 1 5 ) 。 " host- 1" のブー トイ メ一ジは、 リ モー ト配布サ一パ R D S 内のディ スク R 1 に保 存されている。 そこで、 ブー トイ メージ設定ュニッ 卜 B S 2 は、 リ モー ト配布サーバ R D Sか らディ スク R 1 を選択する そしてブー トイ メ一ジ設定ュニッ ト B S 2 は、 ディ スク R 1 に保存されている "host-1" のブー トイ メージを、 予備計算 機 C 5 のローカルディ スク D 5 にコ ピーする (ステップ S 1 5 ) 。 このよう に本実施形態においては、 故障計算機 C 1 で 実行されていた " host-1" のブー トイ メージが、 故障計算機 探索プロセス F P によって検出 (選択) された予備計算機 C 5 に直接設定される。 この点で、 故障計算機 C 1 で実行され ていた " host- 1" のブー トイ メージが予備計算機 C 5 に間接 的に設定される上記第 1 の実施形態とは異なる。
次に探索プロセス F P は、 予備計算機 C 5 のディ スク D 5 にコ ピーされている " host- 1" のブー トイ メージに従って、 ブー トユニッ ト B B 2 によ り、 当該計算機 C 5 をブー トさせ る (ステッ プ S 1 6 ) 。 このブー トユニッ ト B B 2 による、 計算機 C 5 を対象とするブ一 卜操作は、 上記第 1 の実施形態 におけるブー ト操作と同様に行われる。 これによ り 、 計算機 C 5 は "host-1" と して起動される。 この結果、 計算機 C 1 が故障するまで当該計算機 C 1 上で動作していた、 オペレー ティ ングシステム O S 1 、 予備計算機探索ユニッ ト P P 1 、 ブー 卜イ メージ設定ュニッ ト B S 1 、 プ一 卜ュニッ ト B B 1 及びク ラスタ制御ュニッ 卜 C C 1 は、 当該計算機 C 5 で動作 するよう になる。
[第 3 の実施形態]
図 1 3 は本発明の第 3 の実施形態に係る計算機システムの 構成を示すブロ ッ ク図である。 図 1 3 において、 図 1 の計算 機システム と等価な構成要素には同一符号を付してある。 ま ず、 図 1 3 の計算機システムの構成について、 図 1 の計算機 と相異する点を中心に説明する。 図 1 3 の計算機システムに おいて、 計算機 C l , C 2 , C 3 及び C 4 は、 ス ト レージ装 置 S S 内のディ スク D l , D 2 , D 3 及び D 4 にそれぞれ保 存されている "host-1" , " host-2" , " host-3" 及び "host- 4" のブー トイ メ ージに従っ て稼動 している状態、 つ ま り
"稼動" ( S ) の状態にある ものとする。 この計算機 C l , C 2 , C 3 及び C 4上では、 故障計算機探索プロセス F P 1 : F P 2 , F P 3 及び F P 4が、 それぞれ並行して動作する。 探索プロセス F P 1 , F P 2 , F P 3 及び F P 4 は、 図 1 中 の探索プロセス F P に相当する。
故障計算機探索プロセス F P 1 , F P 2 , F P 3 及び F P 4 の特徴は、 それぞれホス 卜名が " host-1" , " host-2" ,
" host-3" 及び " host- 4" のプ一 トイ メージで起動されてい る計算機 (こ こでは計算機 C I , C 2 , C 3 及び C 4 ) で動 作する点にある。 この点で、 探索プロセス F P 1 , F P 2 , F P 3及び F P 4 は、 上記探索プロセス F P、 即ちシステム 内のいずれか 1 つの計算機上で唯一動作する探索プロセス F P と異なる。 また探索プロセス F P 1 , F P 2 , F P 3 及び F P 4の特徴は、 自身が動作すべき計算機を認識可能な点に もある。 つま り探索プロセス F P 1 , F P 2 , F P 3及び F P 4 は、 自身が動作している計算機に割り 当てられているホ ス ト名 (自身のホス ト名) を、 それぞれス ト レ一ジ装置 S S 内のディ スク D 1 , D 2 , D 3 及び D 4 に保存されているブ 一 ト イ メ 一 ジ 中 に 記録 さ れた " host- 1 " , " host-2 " , "host-3" 及び "host-4" である と認識している。 探索プロ セス F P 1, F P 2 , F P 3 及び F P 4 は、 ホス ト名の認識 機能を利用 して、 故障計算機を探索する。 このため探索プロ セス F P 1, F P 2 , F P 3 及び F P 4 は、 探索プロセス F P とは異なり 、 故障計算機の探索にデータベース H D B を必 要としない。
本実施形態では、 クラスタ制御システム C C によ り制御さ れるサ一ビス と して、 故障計算機探索プロセス F P 1 , F P 2, F P 3 及び F P 4が予め定義されている。 つま り、 探索 プロセス F P l , F P 2 , F P 3 及び F P 4 は、 当該プロセ ス F P 1, F P 2 , F P 3及び F P 4が動作している計算機 (図 1 3 では計算機 C 1 , C 2 , C 3 及び C 4 ) が障害等に よ り停止した場合に、 他の計算機で起動されるよう にク ラス 夕制御システム C C によ り制御される。
次に、 図 1 3 の計算機システムにおける動作について、 図 1 4 を参照して説明する。 図 1 4 は主として故障計算機探索 プロセス F P l ( F P i ) の処理手順を示すフロ一チヤ一 ト „〜™
PCT/JP2004/006500
25 である。 こ こでは、 故障計算機探索プロセス F P 1 が計算機
C 1 の故障を検出し、 その故障計算機 C 1 に適用されていた ブー トイメージを予備計算機に設定して当該予備計算機を起 動する動作を例に挙げる。
まず、 故障計算機探索プロセス F P 1 は、 起動される と、 自身が動作すべき計算機、 つま り ホス ト名が " host-1" の計 算機 C 1 で動作しているか否かを判定する (ステッ プ S 2 1 ) 。 通常は、 探索プロセス F P 1 は、 図 1 3 に示したよう に計算機 C 1 で動作している。 この場合、 探索プロセス F P 1 は、 次に起動されるまでス リ ープする (ステッ プ S 2 8 ) 。 今、 探索プロセス F P 1 が動作している計算機 C 1 で障害 が発生したものとする。 する と、 探索プロセス F P 1 が、 ク ラス夕制御システム C Cの制御によ り 、 障害発生計算機 C 1 から計算機システム内の他の計算機に移される (フェイルォ ーバされる) 。 つま り 、 探索プロセス F P 1 が起動される箇 所が、 障害発生計算機 C 1 か ら他の計算機に変更される。 こ れによ り 、 探索プロセス F P 1 は、 自身が動作すべきホス ト 名 "host-1" の計算機 ( C 1 ) とは異なる計算機で動作する こ とになる。 こ こでは、 探索プロセス F P 1 は、 ホス ト名が " host-2" の計算機 C 2 で起動されたものとする。
探索プロセス F P 1 は計算機 C 2 で起動された場合、 上記 ステ ッ プ S 2 1 にお いて、 自 身が動作すべきホス ト 名が "host-1" の計算機 C 1 ではない計算機 (ホス ト名が " hosts'' の計算機 C 2 ) で動作している ものと判断する。 する と 探索プロセス F P 1 は、 元々 自 身が動いていたホス ト名が " host- 1" の計算機 C 1 に障害が発生したこ とを認識する。 この場合、 探索プロセス F P 1 は、 例えば自身が現在動作し ている計算機 C 2上の予備計算機探索ュニッ ト P P 2 を用い て、 予備計算機を探す (ステッ プ S 2 2 , S 2 3 ) 。 この探 索ユニッ ト P P 2 による予備計算機の探索は、 上記第 1 の実 施形態と同様に、 データベース C D D B 2 を参照して、 ステ —タスが "プロ ビジョ ニング" ( P ) の状態にある計算機の 計算機識別子を取得する こ とで実現される。 も し、 "プロビ ジョ ニング" ( P ) の状態にある計算機が存在しない場合に は、 故障計算機探索プロセス F P 1 は、 一定時間ス リープし た後 (ステップ S 2 4 ) 、 予備計算機探索ユニッ ト P P 2 を 用いて再び予備計算機を探す (ステップ S 2 2 , S 2 3 ) 。
今、 データベース C D D B 2 ( C D D B i ) が図 2 のよう になっているものとする と、 計算機 C 5 が予備計算機として 検出される。 故障計算機探索プロセス F P 1 は予備計算機 C 5 が検出 (選択) された場合、 図 6 中のステッ プ S 5及び S 6 に相当する処理 (ステッ プ S 2 5及び S 2 6 ) を実行する 即ち探索プロセス F P 1 は、 故障した計算機 C 1 が使用 して いた "host-1" のブー トイ メージを予備計算機 C 5 に使用さ せるための制御を行う。 こ こでは、 探索プロセス F P 1 は、
"host-1" のブー トイ メージを予備計算機 C 5 で実行させる ために、 ス ト レ一ジ装置 S S 内のデータベース D B D B を、 例えば自身が現在動作している計算機 C 2 上のブー 卜ィ メー ジ設定ユニッ ト: B S 2 によ り操作させる (ステップ S 2 5 ) このデータベース D B D Bの操作によ り、 上記第 1 の実施形 態と同様に、 故障計算機 C 1 をブー トするのに用い られてい たブー トイ メージが、 予備計算機 C 5 をブー トするためのブ ― トイ メ一ジとして選択される こ とになる。 次に探索プロセ ス F P 1 は、 自身が現在動作している計算機 C 2 上のブー ト ユニッ ト B B 2 によ り 、 予備計算機 C 5 を上記選択された " host- 1" のブ一 卜イ メージでブー 卜 させる (ステッ プ S 2
6 ) 。 これに よ り 、 故障 し た計算機 C 1 が実行 してい た "host- 1" のブー トイ メージを、 計算機 C 5 で実行する こ と が可能となる。 即ち、 計算機 C 5 が " host- 1" と して起動さ れ、 計算機 C 1 が故障するまで当該計算機 C 1 上で動作して いた、 オペレーティ ングシステム O S 1 、 予備計算機探索ュ ニッ ト P P 1 、 ブー トイ メージ設定ユニッ ト B S 1 、 ブ一 卜 ュニッ ト B B 1 及びク ラス夕制御ュニッ 卜 C C 1 が、 当該計 算機 C 5 で動作するよう になる。
このよ う に、 故障した計算機 C 1 が実行していた " host- 1" のブー トイ メージで予備計算機 C 5 が起動されたものと する。 つま り 、 計算機 C 5 が "host-1" と して起動されたも のとする。 する と、 本来 "host-1" の計算機で動作すべき故 障計算機探索プロセス F P 1 が、 ホス ト名が " host-2" の計 算機 C 2 か ら 、 " host-1" と して起動された、 ホス ト名が "host-1" の計算機 C 5 に移さ (戻さ) れる (ステッ プ S 2
7 ) 。 この探索プロセス F P 1 を、 当該プロセス F P 1 が本 来動作すべきホス ト名が "host-1" の計算機に移す (戻す) 処理 (つま り フェイルバッ ク処理) は、 ク ラス夕制御システ ム C C によ り行われる。 その後、 探索プロセス F P 1 は、 次 PC漏 00藝 500
28 に起動されるまでス リ ープする (ステッ プ S 2 8 ) 。
上記第 3 の実施形態では、 予備計算機探索ユニッ ト P P 1 ( P P i ) 、 ブー トイメージ設定ユニッ ト B S 1 ( B S i ) 及びブー 卜ユニッ ト B B 1 ( B B i ) は故障計算機探索プロ セス F P 1 ( F P i ) から独立している。 しかし、 予備計算 機探索ユニッ ト P P I ( P P i ) 、 ブー トイ メージ設定ュニ ッ ト B S I ( B S i ) 及びブー トユニッ ト B B 1 ( B B i ) が故障計算機探索プロセス F P 1 ( F P i ) に付随する (含 まれる) 構成とする ことも可能である。 この構成では、 ク ラ ス夕制御システム C Cの制御によ り故障計算機探索プロセス F P 1 が計算機 C 1 から計算機 C 2 に移される際に、 予備計 算機探索ュニッ ト P P 1 、 ブー トイ メージ設定ュニッ ト B S 1 及びブー トユニッ ト B B 1 も計算機 C 2 に移される。 この 場合、 故障計算機探索プロセス F P 1 は、 図 1 4 のフ口一チ ヤー トに示す処理を、 予備計算機探索ユニッ ト P P 1 、 ブー トイ メージ設定ュニッ ト B S 1 及びブー トュニッ ト B B 1 を 用いて実行する。
また、 上記第 3 の実施形態では、 計算機 C 1 の一時的な障 害の場合にも、 故障計算機探索プロセス F P 1 が計算機 C 2 に移されて、 計算機 C 1 で実行されていたブ一 卜イ メージで 予備計算機 C 5 が起動される可能性がある。 そこでク ラスタ 制御システム C Cは、 故障計算機探索プロセス F P 1 ( F P i ) に関しては、 他のサ一ビス とは異なり 、 計算機障害の検 出に用い られるタイムァゥ ト時間よ り長いタイムァゥ ト時間 を用いて、 障害発生計算機か ら他の計算機への移動制御 (フ エイルオーゾ ) を行う とよい。
[第 4 の実施形態]
図 1 5 は本発明の第 4 の実施形態に係る計算機システムの 構成を示すブロ ッ ク図である。 図 1 5 において、 図 1 1 また は図 1 3 の計算機システムと等価な構成要素には同一符号を 付してある。 図 1 5 の計算機システムが第 3 の実施形態で適 用された図 1 3 の計算機システムと相異する点は、 第 2 の実 施形態で適用された図 1 1 の計算機システムが、 第 1 の実施 形態で適用された図 1 の計算機システムと相異する点に一致 する。 この図 1 5 の計算機システム内の故障計算機探索プロ セス F P 1 ( F P i ) の処理手順を図 1 6 のフロ一チャー ト に示す。 図 1 6 か ら明らかなよ う に、 故障計算機探索プロセ ス F P I ( F P i ) は、 第 3 の実施形態で適用された図 1 4 のフローチャー トのステップ S 2 1 乃至 S 2 8 に相当する処 理 (ステップ S 3 1 乃至 S 3 8 ) を実行する。 但し、 ステツ プ S 3 7 は、 図 1 4 中のステップ S 2 7 と同様に、 クラスタ 制御システム C C によ り実行される。 図 1 6 のフローチヤ一 卜が図 1 4 のフ ローチャー ト と相異するのは、 図 1 4 中のス テツプ S 2 5 に相当する処理 (ステッ プ S 3 5 ) である。 つ ま り、 故障計算機 C 1 が使用 していたブー トイ メージを予備 計算機 C 5 に使用させるための処理が異なる。 ステップ S 3 5 では、 故障計算機 C 1 が使用 していたブー トイ メージ、 即 ち リモー ト配布サーバ R D S 内のディ スク R 1 に保存されて いるブー トイ メージを、 予備計算機 C 5 のローカルディ スク D 5 にコ ピーする処理が行われる。 この処理は、 図 1 2 中の ステップ S 1 5 と同様である。
上記第 1 乃至第 4 の実施形態では、 あるブー トイ メージを 実行していた計算機が故障した場合に、 その計算機の故障検 出を ト リ ガとして、 当該計算機が実行していたブー 卜ィ メー ジで予備計算機を起動する技術が適用される。 この技術を応 用 して、 例えば計算機の負荷が基準値よ り大き く なつたこと を 卜 リ ガと して、 当該計算機が実行していたブー トイ メージ で予備計算機を起動する構成とする ことも可能である。 この 場合、 故障計算機探索プロセスの引き継ぎは必ずしも必要な い。 また、 予め定め られた時刻の到来を ト リ ガとして、 同一 計算機を、 時間帯によって異なるブー 卜イ メージで起動する 構成とする こ とも可能である。 つま り 、 同一計算機を、 例え ば昼間は第 1 のオペレーティ ングシステムを含む第 1 のブー トイ メージで起動し、 夜間は第 2 のオペレーティ ングシステ ムを含む第 2 のブ一 トイ メージで起動する こ とも可能である この構成は、 特に、 ブ一 トイ メージのコ ピーを必要としない 図 1 または図 1 3 に示した計算機システムに適する。
なお、 本発明は、 上記実施形態そのままに限定される もの ではなく、 実施段階ではその要旨を逸脱しない範囲で構成要 素を変形して具体化できる。 また、 上記実施形態に開示され ている複数の構成要素の適宜な組み合せによ り種々の発明を 形成できる。 例えば、 実施形態に示される全構成要素から幾 つかの構成要素を削除してもよい。 更に、 異なる実施形態に 亘る構成要素を適宜組み合せてもよい。
産業上の利用可能性 本発明によれば、 計算機が故障した場合に、 オペレータの 介在なしで、 予備計算機を故障した計算機の代わ り として使 用できるよう、 当該予備計算機にブー 卜イ メージを設定して 当該予備計算機を起動する こ とができる。

Claims

W° 2004/099990 PC聽 00纏 500 3 2 請 求 の 範 囲
1 . 予備計算機を含む複数の計算機を備えた計算機シス テム、 前記計算機システムは、
前記複数の計算機をブー 卜するための各ブー トイ メージを それぞれ個別に記憶する複数のス ト レージ装置と、
前記複数の計算機のステータスを記憶する第 1 の記憶ュニ ッ 卜 と、
前記複数のス ト レージ装置の各々 と当該ス ト レージ装置に 記憶されているブー トイ メージでブー 卜する計算機との対応 関係を表す情報を記憶する第 2 の記憶ュニッ ト と、
前記計算機システム内で故障した計算機を探索するよう に 構成された故障計算機探索ュニッ ト と、
前記故障計算機探索ュニッ 卜が故障した計算機を見つけた とき、 前記故障した計算機の代替として使用するための予備 計算機を、 前記第 1 の記憶ユニッ トに記憶されている前記複 数の計算機のステータスに従って選択するよ う に構成された 予備計算機探索ユニッ ト と、
前記故障計算機探索ュニッ 卜が故障した計算機を見つけた とき、 前記予備計算機探索ユニッ トが選択した予備計算機を ブ一 卜するためのブー トイ メージが記憶されたス ト レージ装 置を、 前記第 2 の記憶ュニッ トに記憶されている情報に従つ て選択するよう に構成されたブー トイ メージ選択ュニッ 卜 と 前記予備計算機探索ユニッ トが選択した予備計算機を、 前 記ブ一 トイ メージ選択ュニッ トが選択したス ト レージ装置に 記憶されているブ一 トイ メージを用いてブー トするよう に構 3 3 成されたブー トュニッ 卜 と
を具備する。
2 . 請求項 1 に従う計算機システムにおいて、 前記故障 計算機探索ユニッ トは、 前記複数の計算機の各々 について、 当該計算機が正常に稼動しているかを定期的に判定するよう に構成された第 1 の判定ユニッ ト と、 前記第 1 の判定ュニッ トによ り正常に稼動していないと判定された計算機が、 その 判定時点から一定時間を経過しても正常に稼動していない場 合に、 当該計算機が故障している と判定するよう に構成され た第 2 の判定ュニッ ト とを含む。
3 . 請求項 1 に従う計算機システムにおいて、 前記故障 計算機探索ユニッ トは、 前記複数の計算機のう ちの稼動状態 にあるいずれか 1 つの計算機で動作して、 前記計算機システ ム内で故障した計算機を探索するよう に構成された特定プロ セスであって、 当該プロセスが動作する計算機で障害が発生 した場合には、 前記予備計算機以外の他の計算機で動作する よう に構成された特定プロセスを含む。
4 . 請求項 3 に従う計算機システムにおいて、 前記計算 機システム内で障害が発生した計算機を検出し、 当該障害が 発生した計算機で実行されていたサ一ビスを前記予備計算機 以外の他の計算機に引き継がせるよう に構成されたク ラス夕 制御システムであって、 前記障害が発生した計算機が前記特 定プロセスが動作する計算機の場合に、 前記特定プロセスを 前記他の計算機に引き継がせるよう に構成されたク ラス夕制 御システムを更に具備する。 3 4
5 . 請求項 4 に従う計算機システムにおいて、 前記複数 のス ト レージ装置に記憶されている各ブー トイ メージでブ一 卜された計算機の各々が稼動しているかを管理するための管 理情報を記憶する第 3 の記憶ュニッ 卜を更に具備し、
前記ク ラスタ制御システムは、 前記複数のス ト レ一ジ装置 に記憶されている各ブー トイ メージでブー 卜 された計算機を 定期的に監視する こ とによ り、 前記第 3 の記憶ユニッ トに記 憶されている管理情報を更新し、
前記故障計算機探索ユニッ トは、 前記第 3 の記憶ュニッ 卜 に記憶されている管理情報に基づいて、 前記計算機システム 内で故障した計算機を探索する。
6 . 請求項 5 に従う計算機システムにおいて、 前記ク ラ スタ制御システムは、 前記複数の計算機のう ちの稼動状態に ある計算機でそれぞれ動作して相互に定期的に通信を行う こ とによ り 、 障害が発生した計算機を検出するよう に構成され た複数のク ラスタ制御ユニッ トであって、 前記通信の結果に 応じて前記第 3 の記憶ュニッ 卜 に記憶されている管理情報を 更新するよ う に構成された複数のク ラスタ制御ュニッ トを含 む。
7 . 請求項 1 に従う計算機システムにおいて、 前記故障 計算機採索ユニッ トは、 前記複数の計算機のうちの稼動状態 にある計算機でそれぞれ動作して、 前記計算機システム内で 故障した計算機を探索するよう に構成された複数の特定プロ セスであって、 当該プロセスが動作する計算機で障害が発生 した場合には、 前記予備計算機以外の他の計算機で動作する 3 5 よう に構成されている複数の特定プロセスを含む。
8 . 請求項 7 に従う計算機システムにおいて、 前記複数 の特定プロセスの各々は、 自身が前記複数の計算機のうちの いずれの計算機で動作すべきか認識可能であ り 、 自身が動作 すべき計算機で動作していない場合、 自身が動作すべき計算 機は故障している と判定する。
9 . 請求項 7 に従う計算機システムにおいて、 前記計算 機システム内で障害が発生した計算機を検出し、 当該障害が 発生した計算機で実行されていたサービスを前記予備計算機 以外の他の計算機に引き継がせるよう に構成されたクラスタ 制御システムであって、 前記障害が発生した計算機が前記特 定プロセスが動作する計算機の場合に、 前記特定プロセスを 前記他の計算機に引き継がせるよう に構成されたク ラス夕制 御システムを更に具備する。
1 0 . 請求項 9 に従う計算機システムにおいて、 前記ク ラス夕制御システムは、 前記複数の計算機のう ちの稼動状態 にある計算機でそれぞれ動作して相互に定期的に通信を行う こ とによ り 、 障害が発生した計算機を検出するよう に構成さ れた複数のク ラスタ制御ュニッ トを含む。
1 1 . 予備計算機を含む複数の計算機で構成される計算機 システムに適用される、 予備計算機を故障した計算機の代わ り として使用するための方法、 前記方法は、
前記計算機システム内で故障した計算機を探索する こ と と 前記探索する こ とによって、 故障した計算機が見つけられ たとき、 前記故障した計算機の代替として使用するための予 3 6 備計算機を、 第 1 の記憶ユニッ トに記憶されている前記複数 の計算機のステータスに従って選択する こ と と、
前記複数の計算機をブー 卜するための各ブー トイ メージを それぞれ個別に記憶する複数のス ト レージ装置の中から、 第 2 の記憶ュニッ 卜 に記憶されている、 前記複数のス ト レージ 装置の各々 と当該ス 卜 レージ装置に記憶されているブ一 トイ メージでブー 卜する計算機との対応関係を表す情報に従って. 前記故障した計算機の代替と して選択された予備計算機をブ — 卜するためのブー トイ メージが記憶されたス ト レージ装置 を選択する こ と と、
選択された予備計算機を、 選択されたス ト レージ装置に記 憶されているブ一 トイ メージを用いてブー 卜する ことと
を具備する。
1 2 . 請求項 1 1 に従う方法において、 前記探索する こ と は、 前記複数の計算機のうち稼動状態にあるいずれか 1 つの 計算機で動作する特定プロセスによ り実行される。
1 3 . 請求項 1 2 に従う方法において、 前記特定プロセス が動作する計算機で障害が発生した場合に、 前記特定プロセ スを前記予備計算機以外の他の計算機に移動する ことを更に 具備する。
1 4 . 請求項 1 1 に従う方法において、 前記探索する こ と は、 前記複数の計算機のうち稼動状態にある全ての計算機で それぞれ動作する複数の特定プロセスによ り実行される。
1 5 . 請求項 1 4 に従う方法において、 前記複数の計算機 のうちのいずれかの計算機で障害が発生した場合に、 当該障 害が発生した計算機で動作している特定プロセスを前記予備 計算機以外の他の計算機に移動する こ とを更に具備する。
1 6 . 請求項 1 5 に従う方法において、 前記探索する こ と は、 当該探索する こ とが実行されるべき計算機で実行されて いない場合に、 当該探索する こ とが実行されるべき計算機は 故障している と判定する ことを含む。
PCT/JP2004/006500 2003-05-09 2004-05-07 計算機システム及び同システムに適用される故障計算機代替制御方法 Ceased WO2004099990A1 (ja)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US10/556,051 US7478230B2 (en) 2003-05-09 2004-05-07 Computer system and failed computer replacing method to the same system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2003132117A JP3737810B2 (ja) 2003-05-09 2003-05-09 計算機システム及び故障計算機代替制御プログラム
JP2003-132117 2003-05-09

Publications (1)

Publication Number Publication Date
WO2004099990A1 true WO2004099990A1 (ja) 2004-11-18

Family

ID=33432153

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2004/006500 Ceased WO2004099990A1 (ja) 2003-05-09 2004-05-07 計算機システム及び同システムに適用される故障計算機代替制御方法

Country Status (4)

Country Link
US (1) US7478230B2 (ja)
JP (1) JP3737810B2 (ja)
CN (1) CN100382041C (ja)
WO (1) WO2004099990A1 (ja)

Families Citing this family (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2006043309A1 (ja) * 2004-10-18 2006-04-27 Fujitsu Limited 運用管理プログラム、運用管理方法および運用管理装置
DE602004027424D1 (de) * 2004-10-18 2010-07-08 Fujitsu Ltd Operationsverwaltungsprogramm, operationsverwaltun
EP1814027A4 (en) * 2004-10-18 2009-04-29 Fujitsu Ltd PROGRAM, METHOD AND INSTALLATION FOR OPERATIONAL MANAGEMENT
JP4462024B2 (ja) * 2004-12-09 2010-05-12 株式会社日立製作所 ディスク引き継ぎによるフェイルオーバ方法
JP2008533573A (ja) * 2005-03-10 2008-08-21 テレコム・イタリア・エッセ・ピー・アー 障害回復アーキテクチャー
JP4710518B2 (ja) 2005-09-28 2011-06-29 株式会社日立製作所 計算機システムとそのブート制御方法
JP4544146B2 (ja) * 2005-11-29 2010-09-15 株式会社日立製作所 障害回復方法
US8209417B2 (en) * 2007-03-08 2012-06-26 Oracle International Corporation Dynamic resource profiles for clusterware-managed resources
JP2008269352A (ja) * 2007-04-20 2008-11-06 Toshiba Corp アドレス変換装置及びプロセッサシステム
JP2010170351A (ja) * 2009-01-23 2010-08-05 Hitachi Ltd 計算機システムのブート制御方法
US8161142B2 (en) 2009-10-26 2012-04-17 International Business Machines Corporation Addressing node failure during a hyperswap operation
JP5150696B2 (ja) * 2010-09-28 2013-02-20 株式会社バッファロー 記憶処理装置及びフェイルオーバ制御方法
JP2012175574A (ja) * 2011-02-23 2012-09-10 Toshiba Corp 送信装置及び送信システム
JP5484434B2 (ja) * 2011-12-19 2014-05-07 株式会社日立製作所 ネットワークブート計算機システム、管理計算機、及び計算機システムの制御方法
JP5307223B2 (ja) * 2011-12-22 2013-10-02 テレコム・イタリア・エッセ・ピー・アー 障害回復アーキテクチャ
CN103973470A (zh) * 2013-01-31 2014-08-06 国际商业机器公司 用于无共享集群的集群管理方法和设备
JP6123375B2 (ja) * 2013-03-14 2017-05-10 日本電気株式会社 監視制御装置及び方法、組み込み制御装置、並びにコンピュータ・プログラム
US9880859B2 (en) * 2014-03-26 2018-01-30 Intel Corporation Boot image discovery and delivery

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH06231101A (ja) * 1993-01-29 1994-08-19 Natl Aerospace Lab 受信タイムアウト検出機構
JPH10105423A (ja) * 1996-09-27 1998-04-24 Nec Corp ネットワークサーバの障害監視方式
JP2001256071A (ja) * 2000-03-13 2001-09-21 Fuji Electric Co Ltd 冗長化システム

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5796934A (en) * 1996-05-31 1998-08-18 Oracle Corporation Fault tolerant client server system
US5852724A (en) * 1996-06-18 1998-12-22 Veritas Software Corp. System and method for "N" primary servers to fail over to "1" secondary server
FR2752631B1 (fr) * 1996-08-22 1999-01-22 Schneider Automation Procede de chargement d'un systeme d'exploitation
US5903717A (en) * 1997-04-02 1999-05-11 General Dynamics Information Systems, Inc. Fault tolerant computer system
US6363497B1 (en) * 1997-05-13 2002-03-26 Micron Technology, Inc. System for clustering software applications
US5996086A (en) * 1997-10-14 1999-11-30 Lsi Logic Corporation Context-based failover architecture for redundant servers
EP1035465A3 (en) * 1999-03-05 2006-10-04 Hitachi Global Storage Technologies Japan, Ltd. Disk storage apparatus and computer system using the same
US6609213B1 (en) * 2000-08-10 2003-08-19 Dell Products, L.P. Cluster-based system and method of recovery from server failures
JP2002222160A (ja) * 2001-01-26 2002-08-09 Fujitsu Ltd 中継装置
CN1319237C (zh) * 2001-02-24 2007-05-30 国际商业机器公司 超级计算机中通过动态重新划分的容错
GB0112781D0 (en) * 2001-05-25 2001-07-18 Global Continuity Plc Method for rapid recovery from a network file server failure
US6874103B2 (en) * 2001-11-13 2005-03-29 Hewlett-Packard Development Company, L.P. Adapter-based recovery server option

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH06231101A (ja) * 1993-01-29 1994-08-19 Natl Aerospace Lab 受信タイムアウト検出機構
JPH10105423A (ja) * 1996-09-27 1998-04-24 Nec Corp ネットワークサーバの障害監視方式
JP2001256071A (ja) * 2000-03-13 2001-09-21 Fuji Electric Co Ltd 冗長化システム

Also Published As

Publication number Publication date
JP2004334698A (ja) 2004-11-25
CN1802636A (zh) 2006-07-12
US20070067613A1 (en) 2007-03-22
JP3737810B2 (ja) 2006-01-25
CN100382041C (zh) 2008-04-16
US7478230B2 (en) 2009-01-13

Similar Documents

Publication Publication Date Title
JP4462024B2 (ja) ディスク引き継ぎによるフェイルオーバ方法
US10853056B2 (en) System and method for supporting patching in a multitenant application server environment
US7444502B2 (en) Method for changing booting configuration and computer system capable of booting OS
US7953831B2 (en) Method for setting up failure recovery environment
US7287186B2 (en) Shared nothing virtual cluster
US8010827B2 (en) Method and computer system for failover
US6134673A (en) Method for clustering software applications
JP3737810B2 (ja) 計算機システム及び故障計算機代替制御プログラム
EP1397744B1 (en) Recovery computer for a plurality of networked computers
US20010056554A1 (en) System for clustering software applications
JP4572250B2 (ja) 計算機切り替え方法、計算機切り替えプログラム及び計算機システム
JP2008097276A (ja) 障害回復方法、計算機システム及び管理サーバ
JP2007293422A (ja) ネットワークブート計算機システムの高信頼化方法
JP5316616B2 (ja) 業務引き継ぎ方法、計算機システム、及び管理サーバ
JP2003099146A (ja) 計算機システムの起動制御方式
JP5285045B2 (ja) 仮想環境における故障復旧方法及びサーバ及びプログラム
US7437445B1 (en) System and methods for host naming in a managed information environment
US7657734B2 (en) Methods and apparatus for automatically multi-booting a computer system
JP5131336B2 (ja) ブート構成変更方法
CN111427721B (zh) 异常恢复方法及装置
JP5484434B2 (ja) ネットワークブート計算機システム、管理計算機、及び計算機システムの制御方法
JP5267544B2 (ja) ディスク引き継ぎによるフェイルオーバ方法
JP2011086316A (ja) 引継方法、計算機システム及び管理サーバ
JP4877368B2 (ja) ディスク引き継ぎによるフェイルオーバ方法

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): BW GH GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 20048159436

Country of ref document: CN

122 Ep: pct application non-entry in european phase
WWE Wipo information: entry into national phase

Ref document number: 2007067613

Country of ref document: US

Ref document number: 10556051

Country of ref document: US

WWP Wipo information: published in national office

Ref document number: 10556051

Country of ref document: US