Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Introduction

Currently connecting multiple

Intro

Within an availability zone when application / user resources need to be shared / connected between VPC's it makes sense to connect VPC's together via SDN enabled inter-VPC routing or together can basically be achieved by using inter VPC routing via Privategateways or via VPN tunnels.

The current way of enabling inter-VPC's routing connectivity between VPC's in CloudStack (4.6) is via a PrivateGateway and adding one or multiple static route(s).  The Creating a privategateway api call however is however not available/permitted for subdomain admin domain admins or non-admin users within CloudStackby the API.  This puts a burden on the root-admins to enable privategateways on VPC's that users have created. Another aspect is that domain admins or non-admin users of subdomains in CloudStack do not always have the right information, such as gateway address, vlan, and ip, to use a createprivategateway create privategateway function even if users would be allowed to.  

From a usability and efficiency perspective it also does not make sense to require cloud users to a) provide this information, and b) to have to enable a privategateway and to add a static route on each VPC to be connected while a single request per connection to connect VPC X to Y and perhaps Z to X could suffice.

This design aims to propose a more functional, and for the user more simplified and efficient way of connecting multiple VPC's. The functionality would be called VPC Peering and would aim to provide a simple and efficient yet powerful interface for users to connect 2 or more VPC's to each other that effectively creates layer 3 reachability between VPC's.

Requirements & limits

...

Use case

Requirements 

Procesflow

Domain model

Authorization

...

Implementation

  • UI

  • API
  • Datamodel
  • Marvin / Cloudmonkey

...

  • VMWare NSX
  • OVS
  • Physical (VLAN based)

...

Tests