Skip to content

Does Gatekeeper Really Supports Cloud and/or Virtualized Environment? #714

Answered by AltraMayor
hzc12321 asked this question in Q&A
Discussion options

You must be logged in to vote

Short answer

You should deploy Gatekeeper on bare metal, no matter your deployment's size or purpose.

Long answer

Several challenges in virtual environments make these environments unsuitable for deploying Gatekeeper.

Virtual NICs. While Gatekeeper has software fallbacks for NICs lacking hardware support for some features, Gatekeeper requires NICs to support multiqueues and RSS over source and destination IP addresses. I'm not aware of a virtual NIC that meets this minimum requirement. If a virtual NIC supports multiqueues, a workaround is to have a single instance of the GK functional block. However, this solution comes with serious performance drawbacks when it works.

Network limitations.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@hzc12321
Comment options

Answer selected by hzc12321
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants