This discussion will cover how to deploy Openstack Neutron using provider networking on top of a layer-3 clos network where layer-2 is terminated in each rack. In order to span the provider network across multiple racks we leveraged BGP-EVPN and VXLAN tunneling in the ToR switches. Our design allows us to scale a single Openstack region to 400 compute nodes and over 30,000 VMs. It also enables us to natively bridge bare-metal hosts into the same provider network. We are able to run PCI and non-PCI workloads on the same physical infrastructure using VRFs to segment the different security tiers. We will also present benchmarks on the performance and scale of BGP-EVPN.
Deployment model on how to scale Openstack to handle large enterprise workloads. Challenges and possible solutions on how to provide segmentation requirements for running highly secure and non-secure workloads on the same cloud infrastructure.