How to Create Service Virtual Machines on the Private Cloud Appliance by using Internal Networks (Doc ID 2017593.1)

Last updated on MAY 26, 2017

Applies to:

Private Cloud Appliance - Version 1.0.1 and later
Linux x86-64

Goal

The Private Cloud Appliance (PCA) uses servers that are exclusively on networks that are internal to the appliance unit. By default, datacenter network access is restricted to the management servers and virtual machines. This design provides network isolation and enhances security, but complicates monitoring, administering, and backing up the appliance contents. The management nodes are on the public datacenter networks, and can be used as bastion hosts for those purposes. However, that does not offer a browser or GUI interface, and would require tunneling or that extra management software be installed on the management nodes, with possible side-effects, and be reinstalled every time the appliance is upgraded. A flexible alternative is to deploy 'service virtual machines', also called appliance or utility virtual machines, for administrative functions.   

Virtual machines are on the public datacenter network, typically vm_public_vlan, and potentially on internal networks as described in this note. That lets them be used as administrative appliances by providing concurrent access to the external networks and the servers on the PCA internal networks. This adds function without having to add new software to the management nodes. They can even be backed up and distributed to other PCA environments.  This approach can host customer-selected management software, provide access to the ZFS appliance browser GUI interface, to GUI access to the compute nodes ILOMs, and to access NFS exports of the Oracle VM repository.

Appliance VM Use Cases

Example appliance VM applications

The method is not necessary for command line access to the management nodes, compute nodes, or other components. For that use case, the administrator can login to the management node, which is always available as a bastion host. Nonetheless, utility VMs may be useful even for capabilities that could technically be done on the management node, since it provides functionality without adding more work and user access to the management nodes. NOTE: Contact Oracle if you are not sure if the use case you have will be safe in this environment.

 

Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms