Skip to content

docs: Connecting tenant VPCs to non-DPU endpoints (storage & shared services) #2441

@benhuntley

Description

@benhuntley

How would you describe the priority of this documentation request

High

Describe the future/missing documentation

Gap: No guidance for connecting a tenant VPC to endpoints not behind a NICo-managed DPU — high-performance storage (e.g. VAST), shared services, and a customer's existing/reference-design DC network. This is the most recurring networking question in the field.

Raised by: Lenovo, SpectroCloud, Reliance (VAST).

Docs needed:

  • The storage/shared-service tenancy options: (1) endpoint on its own DPU = full NICo isolation; (2) VLAN-capable, no VXLAN/ACL termination = VLAN↔VXLAN stitching on the storage/border leaf; (3) no VLANs = app-level isolation.
  • Reaching a shared resource from many isolated VPCs via a common route-target imported into each tenant VRF, and where VXLAN is decapsulated (the leaf — the storage node never sees the VNI).
  • Where VTEPs live for non-DPU endpoints, and what is operator-managed vs NICo-managed.

Related: #1939, #1972, #1313.

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions