Site icon

ACI Fabric in Google Cloud

Table of Contents:

  1. Introduction
  2. Theory behind ACI / Cloud Integration
    2a. Google ACI Fabric differences from AWS/Azure ACI Fabrics
  3. References

Introduction

It has been possible to integrate Cloud APIC in Google Cloud and create a ACI Fabric in Google Cloud since September of 2021. The latest image avaialable in Google Cloud Marketplace as of today April 2022 for cAPIC is release 25.0(3k)

Building ACI Cloud Fabrics in AWS and Azure and also integrating with the Physical ACI OnPrem Fabric has been supported for a long time now. In addtion Brownfield Integration and nonACI external data center integration into this mix is also supported. Google Cloud can also be integrated into the mix now.

In this writeup, I will discuss the theory behind the Google Cloud integration, some architectural differences compared to AWS/Azure ACI Fabric Integration. I will cover how to install, GCP ACI Fabric, Tenants and orchestrate with GCP Cloud ACI fabric in the mix in future writeups (as time permits).

Theory behind ACI / Cloud Integration

Now that everyone has a cloud presence and also onPrem Data Center Presence there is a need to seemlessly integrate all the Data Centers onPrem and clouds.

Every Cloud Provider has it’s own set of APIs. Thus if you were going to do the integration manually, you would have to use different methods of doing the integration for each cloud. In addition, you would have to do the orchestraton of the Infrastructure using different methods.

Cisco ACI Physical APICS ( the onPrem controllers) and Cloud APICs ( the cloud ACI Fabric controllers) each know the APIs and objects needed for it’s respective domain. Each of these APICs can orchestrate in it’s own domain.

Cisco Nexus Dashboard Orchestrator (NDO) is the glue that ties all these ACI Fabric Domains together. NDO sends a common set of API commands to each APIC controller and each APIC controller knows the native APIs required to program it’s own domain and does the job. At the end you have a single pane of glass for orchestration ! The figure below gives you an illustration of this.


Figure 1: High Level overview of ACI Fabric

As mentioned earlier, each cloud provider has it’s own set of apis and objects. The APICs (physical and cloud) use a common set of ACI objects and do the respective translation in each domain. So, as long as you are familiar with the ACI objects, the APICs do their job for their domain.
Let’s take as an example of a high level Tenant Object. The following will be the objects in their respective domains.

Domain ACI Object Corresponding Domain Object
onPrem ACI Fabric Tenant Tenant
AWS ACI Fabric Tenant AWS Account
Azure ACI Fabric Tenant Azure Subscription
GCP ACI Fabric Tenant GCP Project

It’s imporant to remember that:

The diagram below is very handy for comparision of objects in the different domains.

Figure 2: Comparing ACI Fabric Object mappings to it’s corresponding Domain

Google ACI Fabric differences from AWS/Azure ACI Fabrics

The 2 high level diagram illustrate these concepts.

Figure 3: High Level model on how interconnect works.


Figure 4: High Level Model on how interconnect works with Direct Gateway.

The implications of not supporting BGP EVPN Control Plane and VXLAN Data Plane for GCP ACI Fabric ( this feature will come in around June/July 2022 time-frame)

A depiction of this is shown in the figure below.


Figure 5: A Depiction of Connectivity between Sites with Route Leaking

References

Getting Started with Cisco Application Centric Infrastructure
Cisco Cloud APIC for Google Cloud Installation Guide, Release 25.0(x)
Go To TOP

Exit mobile version