NETWORK MANAGEMENT SERVICES MANAGING HETEROGENEOUS GROUPS OF DATACENTERS
Some embodiments provide a method for a network management service operating in a first public cloud. The method receives a definition of a group of datacenters to manage. The group of datacenters includes (i) a virtual datacenter implemented in a second public cloud for an entity and (ii) a physical on-premises datacenter of the entity. The method receives a network policy configuration defining a logical network spanning the group of datacenters. The method provides logical network configuration data to local network managers at each of the datacenters at the group of datacenters.
1 . A method comprising:
at a network management service operating in a first public cloud:
receiving a definition of a group of datacenters to manage, wherein the group of datacenters comprises (i) a virtual datacenter implemented in a second public cloud for an entity and (ii) a physical on-premises datacenter of the entity;
receiving a network policy configuration defining a logical network spanning the group of datacenters; and
providing logical network configuration data to local network managers at each of the datacenters at the group of datacenters.
2 . The method of claim 1 , wherein the group of datacenters further comprises a native virtual private cloud (VPC) of a third public cloud.
3 . The method of claim 2 , wherein the second and third public clouds belong to the same public cloud provider.
4 . The method of claim 1 , wherein the first and second public clouds are different geographic locations for a same public cloud provider.
5 . The method of claim 1 , wherein the network policy configuration defines logical forwarding elements that span the datacenters of the group of datacenters.
6 . The method of claim 1 , wherein the network policy configuration defines security policy for logical network communication between network endpoints located in the datacenters of the group of datacenters.
7 . The method of claim 1 , wherein the network management service is implemented in a container cluster within the first public cloud.
8 . The method of claim 7 , wherein the network management service comprises a plurality of microservices in the container cluster.
9 . The method of claim 8 , wherein a first set of microservices receives the definition of the group of datacenters and deploys a second set of microservices for managing the group of datacenters of the entity.
10 . The method of claim 9 , wherein the second set of microservices receives the network policy configuration and provides the logical network configuration data to the local network managers.
11 . A non-transitory machine-readable medium storing a network management service for execution by at least one processing unit, the network management service operating in a first public cloud and comprising sets of instructions for:
receiving a definition of a group of datacenters to manage, wherein the group of datacenters comprises (i) a virtual datacenter implemented in a second public cloud for an entity and (ii) a physical on-premises datacenter of the entity;
receiving a network policy configuration defining a logical network spanning the group of datacenters; and
providing logical network configuration data to local network managers at each of the datacenters at the group of datacenters.
12 . The non-transitory machine-readable medium of claim 11 , wherein the group of datacenters further comprises a native virtual private cloud (VPC) of a third public cloud.
13 . The non-transitory machine-readable medium of claim 12 , wherein the second and third public clouds belong to the same public cloud provider.
14 . The non-transitory machine-readable medium of claim 11 , wherein the first and second public clouds are different geographic locations for a same public cloud provider.
15 . The non-transitory machine-readable medium of claim 11 , wherein the network policy configuration defines logical forwarding elements that span the datacenters of the group of datacenters.
16 . The non-transitory machine-readable medium of claim 11 , wherein the network policy configuration defines security policy for logical network communication between network endpoints located in the datacenters of the group of datacenters.
17 . The non-transitory machine-readable medium of claim 11 , wherein the network management service is implemented in a container cluster within the first public cloud.
18 . The non-transitory machine-readable medium of claim 17 , wherein the network management service comprises a plurality of microservices in the container cluster.
19 . The non-transitory machine-readable medium of claim 18 , wherein a first set of microservices receives the definition of the group of datacenters and deploys a second set of microservices for managing the group of datacenters of the entity.
20 . The non-transitory machine-readable medium of claim 19 , wherein the second set of microservices receives the network policy configuration and provides the logical network configuration data to the local network managers.