Skip to content

Investigate the compatibility of containerVM with NSX #4097

@amandafeng001

Description

@amandafeng001

User Statement:

As a VIC User I want to be able to use NSX to achieve network micro-segmentation and provide the same as what docker network supports.

In order to achieve this, we need to investigate the compatibility of our containerVMs with NSX: can we use NSX security groups and policies with current VIC implementation.

Details:
Our goals are:

  1. container VMs in the same container network can talk to each other
  2. container VMs in different container networks cannot talk to each other by default
  3. one container VM can be added to different container networks

Our first investigation shows:

Acceptance Criteria:
An investigation document which answers the following questions:

  1. why NSX security policy cannot work if security group membership is identified by security tag?
  2. how much changes are needed (or is it possible) in current VIC implementation to make NSX able to identify container VMs?
  3. Is there any other way to achieve our goals with NSX?

Metadata

Metadata

Assignees

Labels

area/vsphereIntergration and interoperation with vSpherecomponent/portlayer/networkkind/investigationA scoped effort to learn the answers to a set of questions which may include prototypingproduct/govmomiRelated to the Go library for interacting with VMware vSphere APIs

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions