Category: platform architecture

  • Self-service without guardrails is just delegated infrastructure access with a nicer interface. In this post I look at guardrails in the VCF Automation 9.1 All Apps model, and how organizations, quotas, namespaces, networking, policies, and extensibility work together to make private cloud consumption safer and more repeatable.

  • In my previous article, I reflected on what I would design differently if I were building an NSX platform today. That piece focused on architectural choices — fewer abstractions, clearer boundaries, stronger defaults. But design decisions are only part of the story. What ultimately matters is who carries responsibility for how the platform behaves over…

  • When I started designing large NSX platforms, most of the hard problems were technical. How far could we push microsegmentation?How much overlay networking could we introduce?How flexible could we make the design so it would survive future requirements? At the time, that made a lot of sense. Today, the situation is different. NSX is mature,…