Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Nux!
ity > group while the Instance is running. > > Wido > >> >> [1] https://github.com/apache/cloudstack/pull/1297 >> >> -- >> Sent from the Delta quadrant using Borg technology! >> >> Nux! >> www.nux.ro >> >> - Original Me

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Wido den Hollander
adrant using Borg technology! > > Nux! > www.nux.ro > > - Original Message - >> From: "Wido den Hollander" >> To: dev@cloudstack.apache.org >> Sent: Wednesday, 6 January, 2016 15:37:39 >> Subject: Re: KVM: Security grouping through libvirt instead of Python

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Nux!
e.org > Sent: Wednesday, 6 January, 2016 15:37:39 > Subject: Re: KVM: Security grouping through libvirt instead of Python > On 06-01-16 16:20, Nux! wrote: >> That's great! Fine by me then, but we need to be careful and not mess up the >> SG >> bits for XenServer. >

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Wido den Hollander
udstack.apache.org >> Sent: Wednesday, 6 January, 2016 14:38:17 >> Subject: Re: KVM: Security grouping through libvirt instead of Python > >> On 06-01-16 13:12, Nux! wrote: >>> Hi Wido, >>> >>> +1 for using more libvirt and less custom stuff, but what d

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Nux!
den Hollander" > To: dev@cloudstack.apache.org > Sent: Wednesday, 6 January, 2016 14:38:17 > Subject: Re: KVM: Security grouping through libvirt instead of Python > On 06-01-16 13:12, Nux! wrote: >> Hi Wido, >> >> +1 for using more libvirt and less custom stuff, but w

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Wido den Hollander
ian > > -- > Sent from the Delta quadrant using Borg technology! > > Nux! > www.nux.ro > > - Original Message - >> From: "Wido den Hollander" >> To: dev@cloudstack.apache.org >> Sent: Wednesday, 6 January, 2016 10:02:31 >> Subject:

Re: KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Nux!
Nux! www.nux.ro - Original Message - > From: "Wido den Hollander" > To: dev@cloudstack.apache.org > Sent: Wednesday, 6 January, 2016 10:02:31 > Subject: KVM: Security grouping through libvirt instead of Python > Hi, > > A while back I opened CLOUDSTACK-1

KVM: Security grouping through libvirt instead of Python

2016-01-06 Thread Wido den Hollander
Hi, A while back I opened CLOUDSTACK-1164 [0] since I think that we should use as much features of libvirt as possible. libvirt supports network filtering [1] which basically controls ebtables, iptables and ip6tables (IPv6 support!). Using a XML definition you can create a filter and than use th