Virtualization and Cloud Advisor

Expert analysis and advice on server virtualization technologies, deployments and management.

RSS
All Posts | RSS

Our blogger: Bernard Golden is CEO of consulting firm HyperStratus, which specializes in virtualization, cloud computing and related issues. He is also the author of "Virtualization for Dummies," the best-selling book on virtualization to date.

Thu, September 25, 2008

vApps May Ease App Migration, But Require Closer Security Scrutiny

By Edward L. Haletky

Keywords: VMware, vApp, ThinApp, virtualization, virtual OS, VDC-OS

CONNECTIONS
VMware
It's all about the vApps baby.

In VMware's new nomenclature, the new name for virtual machines is, apparently, vApps. In the big announcement of VMware's new Virtual Data Center Operating System (VDC-OS) the term virtual machine was almost entirely absent. But vApps abound.

There are vApps for security, vApps as a service, and the Open Virtual Machine (OVF) format specification defines a vApp encapsulation. At some point one will be able to buy a vApp in OVF form from vendors.

A vApp could contain one or more virtual machines, according to the descriptions we've seen so far.

But I wonder about being able to not only provide VMs via vApp, but to eventually use ThinApps as a part of the vApp delivery. I believe this is where VDC-OS will eventually go.

By packaging a virtual OS, registry, file system plus any DLLs or other components within the same application package, ThinApps bypass traditional Operating System models in favor of encapsulated applications that can run as a vApp.

However we are a long ways from that at the moment.

The interesting thing about the vApp is that it will become the link to various VMware APIs, to which other vendors write. A registered vApp will be able to connect to the vStorage, vNetwork, VMsafe APIs and be able to control them from within a virtual appliance.

Since the vApp is the lever in the process of leveraging the APIs, what is to protect the lever from being broken or discarded in favor of another vApp? Will vApps collide in management functionality?

There are several security related vApps being worked on today: Antivirus vendors and Cisco. Will the development of these vApps be limited to these rarefied heights or can the small security company get into the game as well?

Either way, these specialized vApps represent more attack points into the system. If these are also network aware vApps, upon what OS are they based? Or do you install an application within a Windows vApp.

I have found that treating something as an appliance is not always the best route to take when we are discussing security. Even appliance makers have multiple security layers within their devices, which can make things complex at best and less secure at worst.

I assume the same will be true for a vApp. Defense in depth, auditing, and monitoring of a vApp will now be extremely important. Will this functionality be provided by the vendor or VMware?

Virtualization expert Edward L. Haletky is the author of "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers," Pearson Education (2008.) He recently left Hewlett-Packard, where he worked in the Virtualization, Linux, and High-Performance Technical Computing teams. Haletky owns AstroArch Consulting, providing virtualization, security, and network consulting and development. Haletky is also a champion and moderator for the VMware discussion forums, providing answers to security and configuration questions.

More from IT Drilldown « Back to Virtualization
CASE STUDY
Bank Scores with Server Virtualization
They say old habits die hard. It's a adage that's certainly true for ICICI Bank's senior GM and the Group CTO, Pravir Vohra. As a man who was part of the team that popularized online banking and helped create a new revenue stream for ICICI Bank, Vohra is already known as an IT leader who can make a difference. Full Story »

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
Twenty-to-One Consolidation on Intel Architecture: New Tools for Virtualization and Workload Management
Consolidation isn't easy—especially considering the costs and risks that come with bringing multiple applications and operating systems together on a single mainframe or proprietary platform... Learn more »
Building the Virtualized Enterprise with VMware Infrastructure
Many organizations struggle with their legacy IT infrastructures which are often plagued by high costs, slow response times and inconsistent management... Learn more »
TECHNOLOGY ASSESSMENT: The Impact of Virtualization Software on Operating Environments
Virtualization is a potential game-changer for modern computing. This IDC Technology Assessment discusses how virtualization technologies impact operating environments, now and in the future... Learn more »
Reducing Server Total Cost of Ownership with VMware Virtualization Software
Technology purchases are often quantified simply by hardware and software costs. But there's more to it. This TCO study takes a holistic view—considering soft dollars too, like ongoing maintenance and... Learn more »
 
SPONSORED LINKS
 

Top 5 Questions to Ask about Server Virtualization

Virtual Storage Best Practices

Server Virtualization Benchmark Results

White Paper: The Roadmap to Data Center Automation

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

White Paper: Green Issues for Networking

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

New Benchmarks for VMware Among Major Storage Vendors

Virtualization Benchmark and TCO Analysis-Read Now

New IDG Survey Results on Data Center Automation

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: A Cohesive Network Security Approach

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Dramatically boost network capacity and speed-up to 600 Mbps

Learn how companies are changing how they reach out to their most profitable customers.

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Unified Communications & Collaboration: Game-Changing Business Results

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

 
 
RESOURCE CENTER