SlideShare a Scribd company logo
BBVA Bank on 
OpenStack 
OpenStack Summit 
Paris, November 2014 
Jose Maria San José, 
Jose Luis Lucas, 
Daniel Chavero,
1Introduction
Bbva bank on Open Stack
Vision 
Why hasn’t a bank 1B customers? 
Because we can’t
2Vision
Vision: Let’s go Cloud! 
● Cloud sets up self provisioning infrastructure 
● Hybrid Cloud allows unlimited elasticity (no constraints) 
● Active-Active Hybrid Cloud boosts resilience 
● Hybrid data model (sensitive aware) ensures privacy 
● Programmable automation simplifies management
BBVA BBVA 
It's a Cloud World 
BBVA Datacenter 
BBVA DMZ 
ES MX US 
physical constraints 
Z 
Long 
term 
transfer 
Amazon 
Google 
Manage-ment 
& 
Support 
no constraints 
business 
model 
constraints
New lifecycle 
SecDevOps 
Cooperation 
Deployment 
Package 
Tested 
Deployment 
Package 
Evolved 
Deployment 
Package 
Development Testing Production Maintenance 
Cloud Catalog (Virtual Machines, SW packages, SW Developments)
Strategic Roadmap 
Private Cloud 
Cultural engagement. 
Assure sustainability of IT 
DevOps Adoption 
Improve speed of development and deployment without flaws. 
Hybrid Cloud 
Internet-scale infrastructure. 
High Value Applications 
Web-scale applications on top of Liberty and Hydra. 
Cloud Consolidation 
Migrate internal process and applications to internal cloud.
3OpenStack
3 - OpenStack: the beginnings. 
● Our goals. 
● Previous experience in public clouds. 
● Why OpenStack? 
● Why RedHat? 
● How are we planning to use it?
3 - OpenStack: there we go! 
● Environments: PRE and PRO. 
● Enclosures with Virtual Connects 
o HP Blades, Proliant BL 660c 
o Intel Xeon E5-2660 
● Cloud Controller & Compute & Admin: 
o 256Gb RAM 
● Swift: 
o 64Gb RAM & 12 HDD 1,2Tb 
● Cinder & Glance: 
o NetApp NFS
3 - OpenStack: there we go! 
● Infrastructure deployment: Foreman + Puppet (Staypuft)
3 - OpenStack: there we go! 
● Infrastructure deployment: Foreman + Puppet
3 - OpenStack: technical details 
Router 
Inet B 
Router 
Inet A 
Internet 
OpenStack
Firewall 
Foreman 
Management OpenStack 
BBVA 
Internal Management 
NFS 
Storage 
Migration 
RHEV - NFS 
Nagios 
Internet 
Security 
stuff 
DMZ/Endpoint 
Log 
collector 
Firewall 
Route 
r 
Service subnet 
RHEV 
DNS/NTP
Firewall 
Foreman 
OpenStack components: 
Swift 
Management OpenStack 
BBVA 
Internal Management 
NFS 
Storage 
RHEV - NFS 
Nagios 
Internet 
Security 
stuff 
Swift 
DMZ/Endpoint 
Log 
collector 
Firewall 
Route 
r 
Service subnet 
RHEV 
● Cinder 
● Glance 
● Swift 
DNS/NTP 
Migration
Firewall 
Foreman 
Swift 
Management OpenStack 
BBVA 
Internal Management 
WAF 
NFS 
Storage 
RHEV - NFS 
Nagios 
Internet 
Security 
stuff 
Cloud 
Controller 
Endpoint API 
Swift 
DMZ/Endpoint 
Horizon 
Load 
Balancer 
Log 
collector 
Firewall 
Route 
r 
Load 
Balancer 
Service subnet 
OpenStack components: 
● Cinder 
● Glance 
● Swift 
● Horizon 
● Keystone 
● Cloud Controller 
DNS/NTP 
MySQL 
RabbitMQ 
RHEV 
Migration
Firewall 
Foreman 
Swift 
Management OpenStack 
BBVA 
Internal Management 
WAF 
NFS 
Storage 
RHEV - NFS 
Nagios 
Internet 
Security 
stuff 
Cloud 
Controller 
Endpoint API 
Swift 
DMZ/Endpoint 
Horizon 
Load 
Balancer 
Log 
collector 
Firewall 
Route 
r 
Load 
Balancer 
Service subnet 
RHEV 
Hey!… what 
about Neutron? 
OpenStack components: 
● Cinder 
● Glance 
● Swift 
● Horizon 
● Keystone 
● Cloud Controller 
● Nova 
● Neutron??? 
DNS/NTP 
Nova 
Compute + 
KVM + VRS 
MySQL 
RabbitMQ 
Migration
4SDN
4 - SDN: Motivation 
● Security Team needs to enforce security at all deployment 
stages automatically. 
● Programmability of network functions to automate 
deployments. 
● Growth capabilities between data centers. 
● It’s a good point to introduce SDN into the organization.
4 - SDN: Why Nuage? 
● Domain Templates. 
● Users roles. 
● Automation. 
● Consumable via REST API. 
● Openstack integration via neutron plugin. 
● dVRS (Distributed Routing and Switching). 
● Hypervisor agnostic solution.
4 - SDN: Openstack integration 
● Virtualized Services Platform (VSP): 
○ Virtualized Services Directory (VSD). 
○ Virtualized Services Controller (VSC). 
○ Virtual Routing and Switching (VRS). 
○ Virtualized Services Gateway (VSG). 
● Neutron plugin. 
● Basic vs. Advanced mode integration. 
● Floating-IPs. 
● Horizon customization.
4 - SDN: Openstack integration. 
Firewall 
VSG 
Internet 
Data 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
Transit network 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin
4 - SDN: Openstack integration (VSD). 
Firewall 
VSG 
Internet 
Data 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
REST API / WEB GUI 
... 
Neutron 
Plugin 
Transit network
4 - SDN: Openstack integration (VSD). 
Firewall 
VSG 
Internet 
Data 
XMPP 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
Transit network
4 - SDN: Openstack integration (VSC). 
Firewall 
VSG 
Internet 
Data 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
Open Flow 
Transit network
4 - SDN: Openstack integration (VSC). 
Firewall 
VSG 
Internet 
Data 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
MP-BGP 
Transit network
4 - SDN: Openstack integration (VRS). 
Firewall 
VSG 
Internet 
Data 
Transit network 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
VXLAN
4 - SDN: Openstack integration (VSG). 
Firewall 
VSG 
Internet 
Data 
Break out 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
VXLAN
4 - SDN: Openstack integration (Plugin) 
Firewall 
VSG 
Internet 
Data 
Cloud Controller Nova Compute 
DMZ 
VSC 
Management OpenStack 
Router 
VSD 
Load Balancer 
+ 
WAF 
VRS 
VRS 
Nova Compute 
... 
Neutron 
Plugin 
REST API 
Transit network
4 - SDN: Openstack integration (Custom)
4 - SDN: Openstack integration (Custom)
4 - SDN: Openstack integration (Custom)
4 - SDN: Openstack integration (Custom)
4 - SDN Security based on Nuage 
● ACL and policies applied on different network levels. 
● Service chaining.
5Lesson Learned 
& 
Next Steps
5 - Lessons learned. 
● Internal process to be adapted to consume the Openstack 
services. 
● Difficult to deploy with department silos, is better a “one-team” 
approach, multi disciplinar.
5 - Next steps 
● Icehouse > Juno or kilo 
● Dockers 
● Ceph 
● ...
5 - One Team, SecDevOps Crew ;) 
● Alberto Morgante Medina (Security) 
● Leticia García Martín (Security) 
● Mariano Ruiz Muñoz (Storage) 
● German Moya Olmedo (IT) 
● Vicente Miranda Cagigas (IT) 
● Alberto Martín (IT) 
● Helena Cornic Giron (Networking) 
● Cesar Martinez Segura (Networking) 
● Enrique Garcia Pablos (Innovation) 
● Karim Boumedhel (RedHat) 
● Oscar Martin Vega (Nuage Networks) 
● Francisco Alcantara Hernandez (Nuage Networks) 
● Phillipe Jeurissen (Nuage Networks)
Thank you!
Full presentation in youtube: 
http://www.youtube.com/watch?v=PESWFDPbexs 
Summary keynote: 
http://www.youtube.com/watch?v=Pp2TiOKjWLY

More Related Content

PDF
Securing the Software Supply Chain with TUF and Docker - Justin Cappos and Sa...
PDF
Netflix and Containers: Not A Stranger Thing
PDF
Building microservices web application using scala & akka
PDF
Integracia security do ci cd pipelines
PDF
Cncf storage-final-filip
PDF
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
PDF
Don't Assume Your API Gateway is Ready for Microservices
PPTX
NSX with OpenNebula - upcoming 5.10
Securing the Software Supply Chain with TUF and Docker - Justin Cappos and Sa...
Netflix and Containers: Not A Stranger Thing
Building microservices web application using scala & akka
Integracia security do ci cd pipelines
Cncf storage-final-filip
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
Don't Assume Your API Gateway is Ready for Microservices
NSX with OpenNebula - upcoming 5.10

What's hot (20)

PDF
OpenNebulaConf2019 - Crytek: A Video gaming Edge Implementation "on the shoul...
PDF
Promise of DevOps
PDF
Things You MUST Know Before Deploying OpenStack: Bruno Lago, Catalyst IT
PPTX
LlinuxKit security, Security Scanning and Notary
PDF
DevOpsDays Taipei 2021 - How FinTech Embrace Change Management
PDF
Netflix Cloud Platform and Open Source
PPTX
Cloud Solution Day 2016: Service Mesh for Kubernetes
PPT
Sebastien goasguen cloud stack and docker
PPTX
Openstack and Reddwarf Overview
PDF
OSMC 2017 | Building a Monitoring solution for modern applications by Martin ...
PDF
Triangle Devops Meetup 10/2015
PDF
OpenNebulaConf2017US: Welcome and project update by Ignacio M. Llorente and R...
PDF
Groovy there's a docker in my application pipeline
PDF
KURMA - A Containerized Container Platform - KubeCon 2016
PDF
Continuous Packaging is also Mandatory for DevOps
PDF
2017 Microservices Practitioner Virtual Summit: Microservices at Squarespace ...
PDF
Rohit yadav cloud stack internals
PDF
20140708 - Jeremy Edberg: How Netflix Delivers Software
PDF
Living with microservices at Pipedrive
PDF
Netflix Open Source Meetup Season 3 Episode 2
OpenNebulaConf2019 - Crytek: A Video gaming Edge Implementation "on the shoul...
Promise of DevOps
Things You MUST Know Before Deploying OpenStack: Bruno Lago, Catalyst IT
LlinuxKit security, Security Scanning and Notary
DevOpsDays Taipei 2021 - How FinTech Embrace Change Management
Netflix Cloud Platform and Open Source
Cloud Solution Day 2016: Service Mesh for Kubernetes
Sebastien goasguen cloud stack and docker
Openstack and Reddwarf Overview
OSMC 2017 | Building a Monitoring solution for modern applications by Martin ...
Triangle Devops Meetup 10/2015
OpenNebulaConf2017US: Welcome and project update by Ignacio M. Llorente and R...
Groovy there's a docker in my application pipeline
KURMA - A Containerized Container Platform - KubeCon 2016
Continuous Packaging is also Mandatory for DevOps
2017 Microservices Practitioner Virtual Summit: Microservices at Squarespace ...
Rohit yadav cloud stack internals
20140708 - Jeremy Edberg: How Netflix Delivers Software
Living with microservices at Pipedrive
Netflix Open Source Meetup Season 3 Episode 2
Ad

Viewers also liked (10)

PPTX
Disruption trends
PDF
[El comercio]php zend framework (speech)
PDF
Automated conflict resolution - enabling masterless data distribution (Rune S...
PDF
BBVA Arquitectura - Demo DevOps
PDF
BBVA - Thinking Ahead
PDF
Consul: Microservice Enabling Microservices and Reactive Programming
PDF
BBVA Digital Banking
PPTX
Service Discovery using etcd, Consul and Kubernetes
PPTX
OpenStack Introduction
PDF
Conflict Free Replicated Data-types in Eventually Consistent Systems - Joel J...
Disruption trends
[El comercio]php zend framework (speech)
Automated conflict resolution - enabling masterless data distribution (Rune S...
BBVA Arquitectura - Demo DevOps
BBVA - Thinking Ahead
Consul: Microservice Enabling Microservices and Reactive Programming
BBVA Digital Banking
Service Discovery using etcd, Consul and Kubernetes
OpenStack Introduction
Conflict Free Replicated Data-types in Eventually Consistent Systems - Joel J...
Ad

Similar to Bbva bank on Open Stack (20)

PDF
State of the OpenDaylight Union
PDF
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
PDF
Cloud computing OpenStack_discussion_2014-05
PDF
VNG/IRD - Cloud computing & Openstack discussion 3/5/2014
PDF
Getting Safe Swiss Cloud up and running with CloudStack
PDF
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
PDF
Red hat NFV Roadmap - OpenStack Summit 2016/Red Hat NFV Mini Summit
PDF
OpenStack as an Infrastructure
PDF
Quantum - Virtual networks for Openstack
PDF
Sven Vogel: Running CloudStack and OpenShift with NetApp on KVM
PDF
The Future of SDN in CloudStack by Chiradeep Vittal
PPTX
M.Tech Internet of Things Unit - IV.pptx
PPTX
Openstack Summit Tokyo 2015 - Building a private cloud to efficiently handle ...
PPTX
Cloudify 4.6 highlights webinar
PDF
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
PPT
Lessons Learned during IBM SmartCloud Orchestrator Deployment at a Large Tel...
PDF
VMware - Openstack e VMware: la strana coppia
PPTX
VIO30 Technical Overview
PDF
20141111_SOS3_Gallo
PDF
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking
State of the OpenDaylight Union
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
Cloud computing OpenStack_discussion_2014-05
VNG/IRD - Cloud computing & Openstack discussion 3/5/2014
Getting Safe Swiss Cloud up and running with CloudStack
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
Red hat NFV Roadmap - OpenStack Summit 2016/Red Hat NFV Mini Summit
OpenStack as an Infrastructure
Quantum - Virtual networks for Openstack
Sven Vogel: Running CloudStack and OpenShift with NetApp on KVM
The Future of SDN in CloudStack by Chiradeep Vittal
M.Tech Internet of Things Unit - IV.pptx
Openstack Summit Tokyo 2015 - Building a private cloud to efficiently handle ...
Cloudify 4.6 highlights webinar
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
Lessons Learned during IBM SmartCloud Orchestrator Deployment at a Large Tel...
VMware - Openstack e VMware: la strana coppia
VIO30 Technical Overview
20141111_SOS3_Gallo
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking

Recently uploaded (20)

PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Cloud computing and distributed systems.
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Approach and Philosophy of On baking technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
sap open course for s4hana steps from ECC to s4
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Chapter 3 Spatial Domain Image Processing.pdf
The AUB Centre for AI in Media Proposal.docx
Digital-Transformation-Roadmap-for-Companies.pptx
Cloud computing and distributed systems.
The Rise and Fall of 3GPP – Time for a Sabbatical?
Approach and Philosophy of On baking technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
“AI and Expert System Decision Support & Business Intelligence Systems”
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
sap open course for s4hana steps from ECC to s4
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx

Bbva bank on Open Stack

  • 1. BBVA Bank on OpenStack OpenStack Summit Paris, November 2014 Jose Maria San José, Jose Luis Lucas, Daniel Chavero,
  • 4. Vision Why hasn’t a bank 1B customers? Because we can’t
  • 6. Vision: Let’s go Cloud! ● Cloud sets up self provisioning infrastructure ● Hybrid Cloud allows unlimited elasticity (no constraints) ● Active-Active Hybrid Cloud boosts resilience ● Hybrid data model (sensitive aware) ensures privacy ● Programmable automation simplifies management
  • 7. BBVA BBVA It's a Cloud World BBVA Datacenter BBVA DMZ ES MX US physical constraints Z Long term transfer Amazon Google Manage-ment & Support no constraints business model constraints
  • 8. New lifecycle SecDevOps Cooperation Deployment Package Tested Deployment Package Evolved Deployment Package Development Testing Production Maintenance Cloud Catalog (Virtual Machines, SW packages, SW Developments)
  • 9. Strategic Roadmap Private Cloud Cultural engagement. Assure sustainability of IT DevOps Adoption Improve speed of development and deployment without flaws. Hybrid Cloud Internet-scale infrastructure. High Value Applications Web-scale applications on top of Liberty and Hydra. Cloud Consolidation Migrate internal process and applications to internal cloud.
  • 11. 3 - OpenStack: the beginnings. ● Our goals. ● Previous experience in public clouds. ● Why OpenStack? ● Why RedHat? ● How are we planning to use it?
  • 12. 3 - OpenStack: there we go! ● Environments: PRE and PRO. ● Enclosures with Virtual Connects o HP Blades, Proliant BL 660c o Intel Xeon E5-2660 ● Cloud Controller & Compute & Admin: o 256Gb RAM ● Swift: o 64Gb RAM & 12 HDD 1,2Tb ● Cinder & Glance: o NetApp NFS
  • 13. 3 - OpenStack: there we go! ● Infrastructure deployment: Foreman + Puppet (Staypuft)
  • 14. 3 - OpenStack: there we go! ● Infrastructure deployment: Foreman + Puppet
  • 15. 3 - OpenStack: technical details Router Inet B Router Inet A Internet OpenStack
  • 16. Firewall Foreman Management OpenStack BBVA Internal Management NFS Storage Migration RHEV - NFS Nagios Internet Security stuff DMZ/Endpoint Log collector Firewall Route r Service subnet RHEV DNS/NTP
  • 17. Firewall Foreman OpenStack components: Swift Management OpenStack BBVA Internal Management NFS Storage RHEV - NFS Nagios Internet Security stuff Swift DMZ/Endpoint Log collector Firewall Route r Service subnet RHEV ● Cinder ● Glance ● Swift DNS/NTP Migration
  • 18. Firewall Foreman Swift Management OpenStack BBVA Internal Management WAF NFS Storage RHEV - NFS Nagios Internet Security stuff Cloud Controller Endpoint API Swift DMZ/Endpoint Horizon Load Balancer Log collector Firewall Route r Load Balancer Service subnet OpenStack components: ● Cinder ● Glance ● Swift ● Horizon ● Keystone ● Cloud Controller DNS/NTP MySQL RabbitMQ RHEV Migration
  • 19. Firewall Foreman Swift Management OpenStack BBVA Internal Management WAF NFS Storage RHEV - NFS Nagios Internet Security stuff Cloud Controller Endpoint API Swift DMZ/Endpoint Horizon Load Balancer Log collector Firewall Route r Load Balancer Service subnet RHEV Hey!… what about Neutron? OpenStack components: ● Cinder ● Glance ● Swift ● Horizon ● Keystone ● Cloud Controller ● Nova ● Neutron??? DNS/NTP Nova Compute + KVM + VRS MySQL RabbitMQ Migration
  • 20. 4SDN
  • 21. 4 - SDN: Motivation ● Security Team needs to enforce security at all deployment stages automatically. ● Programmability of network functions to automate deployments. ● Growth capabilities between data centers. ● It’s a good point to introduce SDN into the organization.
  • 22. 4 - SDN: Why Nuage? ● Domain Templates. ● Users roles. ● Automation. ● Consumable via REST API. ● Openstack integration via neutron plugin. ● dVRS (Distributed Routing and Switching). ● Hypervisor agnostic solution.
  • 23. 4 - SDN: Openstack integration ● Virtualized Services Platform (VSP): ○ Virtualized Services Directory (VSD). ○ Virtualized Services Controller (VSC). ○ Virtual Routing and Switching (VRS). ○ Virtualized Services Gateway (VSG). ● Neutron plugin. ● Basic vs. Advanced mode integration. ● Floating-IPs. ● Horizon customization.
  • 24. 4 - SDN: Openstack integration. Firewall VSG Internet Data Cloud Controller Nova Compute DMZ VSC Management OpenStack Router Transit network VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin
  • 25. 4 - SDN: Openstack integration (VSD). Firewall VSG Internet Data Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute REST API / WEB GUI ... Neutron Plugin Transit network
  • 26. 4 - SDN: Openstack integration (VSD). Firewall VSG Internet Data XMPP Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin Transit network
  • 27. 4 - SDN: Openstack integration (VSC). Firewall VSG Internet Data Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin Open Flow Transit network
  • 28. 4 - SDN: Openstack integration (VSC). Firewall VSG Internet Data Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin MP-BGP Transit network
  • 29. 4 - SDN: Openstack integration (VRS). Firewall VSG Internet Data Transit network Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin VXLAN
  • 30. 4 - SDN: Openstack integration (VSG). Firewall VSG Internet Data Break out Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin VXLAN
  • 31. 4 - SDN: Openstack integration (Plugin) Firewall VSG Internet Data Cloud Controller Nova Compute DMZ VSC Management OpenStack Router VSD Load Balancer + WAF VRS VRS Nova Compute ... Neutron Plugin REST API Transit network
  • 32. 4 - SDN: Openstack integration (Custom)
  • 33. 4 - SDN: Openstack integration (Custom)
  • 34. 4 - SDN: Openstack integration (Custom)
  • 35. 4 - SDN: Openstack integration (Custom)
  • 36. 4 - SDN Security based on Nuage ● ACL and policies applied on different network levels. ● Service chaining.
  • 37. 5Lesson Learned & Next Steps
  • 38. 5 - Lessons learned. ● Internal process to be adapted to consume the Openstack services. ● Difficult to deploy with department silos, is better a “one-team” approach, multi disciplinar.
  • 39. 5 - Next steps ● Icehouse > Juno or kilo ● Dockers ● Ceph ● ...
  • 40. 5 - One Team, SecDevOps Crew ;) ● Alberto Morgante Medina (Security) ● Leticia García Martín (Security) ● Mariano Ruiz Muñoz (Storage) ● German Moya Olmedo (IT) ● Vicente Miranda Cagigas (IT) ● Alberto Martín (IT) ● Helena Cornic Giron (Networking) ● Cesar Martinez Segura (Networking) ● Enrique Garcia Pablos (Innovation) ● Karim Boumedhel (RedHat) ● Oscar Martin Vega (Nuage Networks) ● Francisco Alcantara Hernandez (Nuage Networks) ● Phillipe Jeurissen (Nuage Networks)
  • 42. Full presentation in youtube: http://www.youtube.com/watch?v=PESWFDPbexs Summary keynote: http://www.youtube.com/watch?v=Pp2TiOKjWLY

Editor's Notes