How it works
How ExoVM reaches a private vCenter without exposing it
ExoVM splits the job in two. The panel lives in the cloud, where your team and your customers can reach it from any browser. The connector lives inside your network, next to vCenter, and does all the talking to it.
In short
ExoVM is a two-part system: a web panel hosted by ExoVM and a small Docker connector that you run next to vCenter inside your private network. The connector opens outbound connections to the ExoVM cloud, receives commands in real time and calls the vSphere APIs locally, so vCenter never has to be reachable from the internet. VM consoles are relayed by the connector host over TLS on port 443.
Last updated:
Architecture
Two parts, one direction
The connector is the only part of ExoVM that touches your VMware environment, and it is the one that dials out.
-
The ExoVM panel (SaaS). The web panel your team and customers sign in to. It stores users, VM assignments, tickets and the audit log. It never connects to vCenter.
-
The ExoVM connector (Docker, on your network). A small container on a host next to vCenter. It holds the vCenter credentials in its environment, connects outbound to the ExoVM cloud, and calls the vSphere APIs on your internal network.
-
Your vCenter and ESXi hosts. Unchanged. No inbound access from the internet, and no agents installed inside your VMs.
A command, step by step
What happens when you click “Power on”
-
You click Power on in the panel.
-
The command is queued in the ExoVM cloud.
-
Your connector, already connected outbound, receives it in real time.
-
The connector calls the vSphere API on vCenter, inside your network.
-
The new power state syncs back to the panel. Your request is already in the audit log, with the user and the time.
At no point does anything on the internet open a connection to vCenter.
The console path
How the in-browser console works
-
A user clicks Console on a VM they’re allowed to see.
-
The panel asks your connector for a console session.
-
The connector requests console access from vSphere and issues a short-lived, single-use ticket.
-
The user’s browser opens a TLS (wss) connection to your connector host on port 443 with that ticket.
-
The connector relays the console stream. The browser never connects to vCenter.
ExoVM’s console is an HTML5 client that runs in the browser with no plugin. Console behaviour depends on your ESXi hosts and guest configuration, so we validate compatibility for your environment during onboarding.
Network
Every connection ExoVM needs
| From | To | Purpose | Notes |
|---|---|---|---|
| Connector | ExoVM cloud | Receive commands, sync inventory | Outbound HTTPS and secure WebSocket, started by the connector |
| Connector | vCenter / ESXi | vSphere API calls, console relay | Stays on your internal network |
| Browser | ExoVM panel | Use the panel | HTTPS |
| Browser | Connector host | VM console streams only | TLS (wss) on port 443 |
| Internet | vCenter / ESXi | Nothing | Never required |
Requirements
What you need to get started
- A host inside your network that can run a Docker container
- Network access from that host to vCenter, and to your ESXi hosts on port 443 for consoles
- Outbound HTTPS from that host to the ExoVM cloud
- A DNS name and TLS certificate for the connector host, so browsers can open consoles on port 443
- A vCenter account for the connector, with API access for the actions you want to use
We go through each of these with you during onboarding.
Onboarding
How early-access onboarding works
-
Demo
We walk through the panel and your environment together.
-
Connector
You run the connector on a Docker host next to vCenter, with its credentials in its environment.
docker compose up -d -
Targets
You add the connector and its vCenter target in the admin panel, and inventory syncs.
-
Users
You create customer users, assign VMs and set quotas.
-
Console check
We validate console compatibility for your environment together.
Questions about the architecture
Does the connector need any inbound access?
The connector talks to the ExoVM cloud over outbound connections only. The one inbound need is for consoles: VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443. vCenter itself is never exposed.
Can the ExoVM cloud reach into my network?
No. The ExoVM cloud never opens connections to your network. Your connector connects out, receives commands and runs them against vCenter locally.
Does ExoVM work in a network with no internet access at all?
No. The connector needs outbound HTTPS to the ExoVM cloud. vCenter and ESXi don’t need internet access; only the connector host does.
Want to see it on a real network diagram?
Tell us how your sites are laid out and we’ll show you where the connector goes.