From: "Eric S. Johansson" <esj@harvee.org>
To: mark.williamson@cl.cam.ac.uk
Cc: xen-devel@lists.sourceforge.net
Subject: Re: will this clever plan work?
Date: Thu, 11 Nov 2004 11:34:02 -0500 [thread overview]
Message-ID: <4193947A.6050600@harvee.org> (raw)
In-Reply-To: <200411111619.25796.mark.williamson@cl.cam.ac.uk>
Mark A. Williamson wrote:
>>I thought of two applications for Xen that could be amusing. First is
>>as a base for a firewall. The idea would be that in order to upgrade to
>>the next release of the firewall, you would create a new virtual machine
>>image and disable (but not necessarily expire) the previous version.
>
>
> It should be possible to build something like that on top of Xen. It'd be
> quite cute too ;-)
and if I could make it run out of flash memory, it would be the cat's ass[1]
> One nice way to set this up would be:
> * admin software in dom0 (accessed via console or dedicated NIC)
> * a separate domain for the firewall software, controlling the NICs directly
> * when you upgrade, kill the old domain and build a new one (this can be
> scripted and should be a very quick process with minimal downtime)
can the two domains communicate over a virtual NIC? the reason I ask is
that since most of the control is by a Web interface, we would need to
tickle the control system in dom0 or at least proxy to it.
>>My fantasy is that I will be able to build a single disk image for all
>>of the basic OS and application to be shared between multiple virtual
>>machines. Update that single core image using Gentoo magic and be able
>>to have separate partitions holding my application data.
>
>
> Yes, you should be able to do that. If you're using VBDs (not NFS), the
> standard caveats for shared data apply:
> * domains can't write to the shared data
> * you can't update the shared data while the domains are running (otherwise
> you'll confuse them)
I really need to learn how the whole storage metaphor is organized.. I
don't know enough to ask the right questions yet. I probably should
just set up a system with a real standard disk image and partitioning
and start breaking it.
on a humorous aside, VBD used to refer to people who are so insecure in
their manhood that they used proxies like expensive cars, trophy wives,
etc. to show that they had a VBD.
---eric
[1] well, since our feline buddies are always waving their butts in our
faces like it was the best thing on the face the planet, if it's good,
it must be the cat's ass ;-)
--
President Nixon: Now more than ever
-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
next prev parent reply other threads:[~2004-11-11 16:34 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-11-11 15:52 will this clever plan work? Eric S. Johansson
2004-11-11 16:19 ` Mark A. Williamson
2004-11-11 16:34 ` Eric S. Johansson [this message]
2004-11-11 16:58 ` Mark A. Williamson
-- strict thread matches above, loose matches on Subject: below --
2004-11-11 4:29 Eric S. Johansson
2004-11-12 8:35 ` Keir Fraser
2004-11-12 14:04 ` Eric S. Johansson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4193947A.6050600@harvee.org \
--to=esj@harvee.org \
--cc=mark.williamson@cl.cam.ac.uk \
--cc=xen-devel@lists.sourceforge.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.