Work

VMware HA for an FPSO platform

Offshore HA cluster on dual SC5020 arrays.

August–October 2020. We deployed and configured a VMware virtualization environment for an FPSO intelligent management platform.

Architecture

The platform uses three virtualization hosts, two shared storage arrays, one-way data collection, and an active–active sea–shore data pair. Six layers:

LayerStackKey figures
HardwareDELL R840 four-socket servers ×3; DELL SC5020 dual-controller arrays ×2; switches; industrial optical diode; MOXA serial servers192 physical cores, 768 GB RAM; 10 GbE iSCSI storage network
Local storageInternal SAS disks in RAID 5, configured via iDRAC4 × 1.8 TB hot-swap SAS, 10K RPM
Shared storageSC5020 dual controllers, fault domains, and logical volumes, mapped over iSCSI as ESXi datastores15 × 2.4 TB SAS (12 Gb / 10K) per array; 128 GB cache; eight 10 GbE iSCSI ports
VirtualizationVMware ESXi 7.0.0 ×3; vCenter Server; offshore two-node HA cluster; vSphere StandardAll VM files on shared storage — the precondition for live failover
Network and securityIndustrial optical diode (one-way import); hardware firewall whitelist; firewalld trusted zoneNo direct path from the platform to the control network; data only flows in one direction
Data and applicationsMySQL sea–shore master–master sync; daily full backups kept 90 days; industrial real-time database21 business VMs; critical components in dual instances

Hardware and storage

Three Dell R840 servers provide 192 physical cores and 768 GB of memory. Each of the two SC5020 arrays holds fifteen 2.4 TB SAS disks and presents shared storage to the hosts over 10 GbE iSCSI. Each server has a dual-port 10 GbE NIC for storage traffic and a four-port 1 GbE NIC for business and management — storage and business networks are physically separate.

Local disks carry ESXi only, in RAID 5. The hypervisor volume can survive a single disk failure. Business data sits entirely on the SC5020 arrays. The two failure domains are independent.

Shared storage is the hinge of the design: VM files live on the array, not on local disks, so failover is possible. Each SC5020 has two controllers with separate management ports, configured in Dell Storage Manager Client.

vCenter and HA

vCenter Server sits above the ESXi hosts as the management plane. Install vCenter, open the UI, create a datacenter, add each host by address and credentials, then enable cluster features. vCenter gives one view of capacity, VM lifecycle, and cluster switches.

The two offshore R840s form an HA cluster on the same SC5020 datastore. If one host fails, its VMs register and start on the other host with the same IP and the same access path. Nothing changes for the application. The shore node is a single physical machine and is not in the cluster; its redundancy is MySQL replication with the offshore primary.

Network and isolation

Sea and shore use separate address ranges. A contiguous block at each site is reserved for VMs.

Users reach the platform from the office network. A real-time database sits inside the platform. Live data comes from the DCS through a one-way isolation device: traffic can flow from the control system into the real-time database, not the other way. The platform has no direct link onto the industrial network.

A hardware firewall with a whitelist sits between the office network and the platform. Host-side allow lists use Linux firewalld trusted zone: add permitted source addresses, reload, and the rule takes effect.

MySQL sync and backup

Four-node sea–shore layout. Offshore and shore primaries replicate to each other (master–master). A full logical backup runs daily at both sites, so each location keeps its own copy.

Real-time data

MOXA serial servers convert live signals to Modbus TCP. A time-series store holds the data, then publishes it over OPC UA and MQTT.

Get started

Discuss a similar project

Tell us what is in China, what is remote, and what done looks like. We reply by email or WhatsApp.

  • On-site anywhere in China
  • Remote everywhere else
  • 24/7 on-call for incidents