summaryrefslogtreecommitdiffstats
path: root/nova/context.py
diff options
context:
space:
mode:
authorSoren Hansen <soren.hansen@rackspace.com>2010-10-12 20:28:43 +0000
committerTarmac <>2010-10-12 20:28:43 +0000
commit8896e712e90330ae42c13367fd79b1a18b56c0a0 (patch)
tree42cdf8d374ca917854fd279c3f74ab55a91c6e08 /nova/context.py
parent4f529fe118283164ccb2756f2001805c69c1cc4a (diff)
parent84ec303828095fc105b287b2858021604cfcea32 (diff)
downloadnova-8896e712e90330ae42c13367fd79b1a18b56c0a0.tar.gz
nova-8896e712e90330ae42c13367fd79b1a18b56c0a0.tar.xz
nova-8896e712e90330ae42c13367fd79b1a18b56c0a0.zip
This patch adds support for EC2 security groups using libvirt's nwfilter mechanism, which in turn uses iptables and ebtables on the individual compute nodes.
This has a number of benefits: * Inter-VM network traffic can take the fastest route through the network without our having to worry about getting it through a central firewall. * Not relying on a central firewall also removes a potential SPOF. * The filtering load is distributed, offering great scalability. Caveats: * It only works with libvirt and only with libvirt drivers that support nwfilter (qemu (and thus kvm) and uml, at the moment)
Diffstat (limited to 'nova/context.py')
0 files changed, 0 insertions, 0 deletions