Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vic-machine firewall configuration #3979

Closed
7 tasks done
andrewtchin opened this issue Feb 16, 2017 · 4 comments
Closed
7 tasks done

vic-machine firewall configuration #3979

andrewtchin opened this issue Feb 16, 2017 · 4 comments
Assignees
Labels
area/vsphere Intergration and interoperation with vSphere component/install priority/p2
Milestone

Comments

@andrewtchin
Copy link
Contributor

andrewtchin commented Feb 16, 2017

User Statement:

As a customer of VIC, I want the ESX firewall to be properly configured during the install process with minimal effort.

Details:
Parent/epic: #3643
Use firewall ruleset vSPC for each host (ComputeResource.Hosts())
https://github.com/vmware/govmomi/blob/master/object/host_firewall_system.go

Acceptance Criteria:

@karthik-narayan
Copy link

This as an alternate option to VIBs makes a lot of sense.

Couple of questions/concerns:

  • If this is pointed at a cluster, will it open up all outbound TCP on all hosts in that cluster?
  • In either case, can we prompt the user to accept (y/n) before we make the change?

As I understand it, if we open all outbound TCP then it isn't great, but in environments where customers want to quickly test vSphere Integrated Containers, this will work pretty well and remove the initial barrier to getting up and running. Once we have the VIB option, this could be a good stop-gap solution in lab environments.

@andrewtchin
Copy link
Contributor Author

We have concluded that this should have priority over the firewall VIB in #3801/#3927

@andrewtchin
Copy link
Contributor Author

added doc info to #3991

@andrewtchin
Copy link
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/vsphere Intergration and interoperation with vSphere component/install priority/p2
Projects
None yet
Development

No branches or pull requests

2 participants