August–October 2020. We deployed and configured a VMware virtualization environment for an FPSO intelligent management platform.
Architecture
The platform uses three virtualization hosts, two shared storage arrays, one-way data collection, and an active–active sea–shore data pair. Six layers:
| Layer | Stack | Key figures |
|---|---|---|
| Hardware | DELL R840 four-socket servers ×3; DELL SC5020 dual-controller arrays ×2; switches; industrial optical diode; MOXA serial servers | 192 physical cores, 768 GB RAM; 10 GbE iSCSI storage network |
| Local storage | Internal SAS disks in RAID 5, configured via iDRAC | 4 × 1.8 TB hot-swap SAS, 10K RPM |
| Shared storage | SC5020 dual controllers, fault domains, and logical volumes, mapped over iSCSI as ESXi datastores | 15 × 2.4 TB SAS (12 Gb / 10K) per array; 128 GB cache; eight 10 GbE iSCSI ports |
| Virtualization | VMware ESXi 7.0.0 ×3; vCenter Server; offshore two-node HA cluster; vSphere Standard | All VM files on shared storage — the precondition for live failover |
| Network and security | Industrial optical diode (one-way import); hardware firewall whitelist; firewalld trusted zone | No direct path from the platform to the control network; data only flows in one direction |
| Data and applications | MySQL sea–shore master–master sync; daily full backups kept 90 days; industrial real-time database | 21 business VMs; critical components in dual instances |
Hardware and storage
Three Dell R840 servers provide 192 physical cores and 768 GB of memory. Each of the two SC5020 arrays holds fifteen 2.4 TB SAS disks and presents shared storage to the hosts over 10 GbE iSCSI. Each server has a dual-port 10 GbE NIC for storage traffic and a four-port 1 GbE NIC for business and management — storage and business networks are physically separate.
Local disks carry ESXi only, in RAID 5. The hypervisor volume can survive a single disk failure. Business data sits entirely on the SC5020 arrays. The two failure domains are independent.
Shared storage is the hinge of the design: VM files live on the array, not on local disks, so failover is possible. Each SC5020 has two controllers with separate management ports, configured in Dell Storage Manager Client.
vCenter and HA
vCenter Server sits above the ESXi hosts as the management plane. Install vCenter, open the UI, create a datacenter, add each host by address and credentials, then enable cluster features. vCenter gives one view of capacity, VM lifecycle, and cluster switches.
The two offshore R840s form an HA cluster on the same SC5020 datastore. If one host fails, its VMs register and start on the other host with the same IP and the same access path. Nothing changes for the application. The shore node is a single physical machine and is not in the cluster; its redundancy is MySQL replication with the offshore primary.
Network and isolation
Sea and shore use separate address ranges. A contiguous block at each site is reserved for VMs.
Users reach the platform from the office network. A real-time database sits inside the platform. Live data comes from the DCS through a one-way isolation device: traffic can flow from the control system into the real-time database, not the other way. The platform has no direct link onto the industrial network.
A hardware firewall with a whitelist sits between the office network and the platform. Host-side allow lists use Linux firewalld trusted zone: add permitted source addresses, reload, and the rule takes effect.
MySQL sync and backup
Four-node sea–shore layout. Offshore and shore primaries replicate to each other (master–master). A full logical backup runs daily at both sites, so each location keeps its own copy.
Real-time data
MOXA serial servers convert live signals to Modbus TCP. A time-series store holds the data, then publishes it over OPC UA and MQTT.