How it works

How ExoVM reaches a private vCenter without exposing it

ExoVM splits the job in two. The panel lives in the cloud, where your team and your customers can reach it from any browser. The connector lives inside your network, next to vCenter, and does all the talking to it.

In short

ExoVM is a two-part system: a web panel hosted by ExoVM and a small Docker connector that you run next to vCenter inside your private network. The connector opens outbound connections to the ExoVM cloud, receives commands in real time and calls the vSphere APIs locally, so vCenter never has to be reachable from the internet. VM consoles are relayed by the connector host over TLS on port 443.

Last updated:

How ExoVM connects to a private vCenter Your team and your customers use the ExoVM panel in their browsers. Inside your private network, the ExoVM connector opens outbound connections to the ExoVM cloud to receive commands and calls vCenter’s vSphere APIs on the internal network. Nothing on the internet connects to vCenter. VM console streams are served over TLS from the connector host on port 443. Your private network Firewall Browsers Your team & your customers Your team Your customers HTTPS Console (TLS, port 443) ExoVM cloud app.exovm.com Outbound HTTPS ExoVM connector Docker · next to vCenter Internal network vCenter / ESXi Never exposed No inbound access to vCenter How ExoVM connects to a private vCenter Your team and your customers use the ExoVM panel in their browsers. Inside your private network, the ExoVM connector opens outbound connections to the ExoVM cloud to receive commands and calls vCenter’s vSphere APIs on the internal network. Nothing on the internet connects to vCenter. VM console streams are served over TLS from the connector host on port 443. Browsers Your team & your customers Your team Your customers HTTPS ExoVM cloud app.exovm.com Your private network Outbound HTTPS ExoVM connector Docker · next to vCenter Internal network vCenter / ESXi Never exposed
Outbound HTTPS Console (TLS, port 443) No inbound access to vCenter

Architecture

Two parts, one direction

The connector is the only part of ExoVM that touches your VMware environment, and it is the one that dials out.

  • The ExoVM panel (SaaS). The web panel your team and customers sign in to. It stores users, VM assignments, tickets and the audit log. It never connects to vCenter.

  • The ExoVM connector (Docker, on your network). A small container on a host next to vCenter. It holds the vCenter credentials in its environment, connects outbound to the ExoVM cloud, and calls the vSphere APIs on your internal network.

  • Your vCenter and ESXi hosts. Unchanged. No inbound access from the internet, and no agents installed inside your VMs.

A command, step by step

What happens when you click “Power on”

  1. You click Power on in the panel.

  2. The command is queued in the ExoVM cloud.

  3. Your connector, already connected outbound, receives it in real time.

  4. The connector calls the vSphere API on vCenter, inside your network.

  5. The new power state syncs back to the panel. Your request is already in the audit log, with the user and the time.

At no point does anything on the internet open a connection to vCenter.

The console path

How the in-browser console works

  1. A user clicks Console on a VM they’re allowed to see.

  2. The panel asks your connector for a console session.

  3. The connector requests console access from vSphere and issues a short-lived, single-use ticket.

  4. The user’s browser opens a TLS (wss) connection to your connector host on port 443 with that ticket.

  5. The connector relays the console stream. The browser never connects to vCenter.

ExoVM’s console is an HTML5 client that runs in the browser with no plugin. Console behaviour depends on your ESXi hosts and guest configuration, so we validate compatibility for your environment during onboarding.

Network

Every connection ExoVM needs

Network connections in an ExoVM deployment
From To Purpose Notes
Connector ExoVM cloud Receive commands, sync inventory Outbound HTTPS and secure WebSocket, started by the connector
Connector vCenter / ESXi vSphere API calls, console relay Stays on your internal network
Browser ExoVM panel Use the panel HTTPS
Browser Connector host VM console streams only TLS (wss) on port 443
Internet vCenter / ESXi Nothing Never required

Multiple sites

One connector per vCenter, one panel for all of them

Run one connector per vCenter, in as many locations as you need. Every site shows up in the same panel, with the same users, assignments and audit log.

Requirements

What you need to get started

  • A host inside your network that can run a Docker container
  • Network access from that host to vCenter, and to your ESXi hosts on port 443 for consoles
  • Outbound HTTPS from that host to the ExoVM cloud
  • A DNS name and TLS certificate for the connector host, so browsers can open consoles on port 443
  • A vCenter account for the connector, with API access for the actions you want to use

We go through each of these with you during onboarding.

Onboarding

How early-access onboarding works

  1. Demo

    We walk through the panel and your environment together.

  2. Connector

    You run the connector on a Docker host next to vCenter, with its credentials in its environment.

    docker compose up -d
  3. Targets

    You add the connector and its vCenter target in the admin panel, and inventory syncs.

  4. Users

    You create customer users, assign VMs and set quotas.

  5. Console check

    We validate console compatibility for your environment together.

Request a demo

Questions about the architecture

Does the connector need any inbound access?

The connector talks to the ExoVM cloud over outbound connections only. The one inbound need is for consoles: VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443. vCenter itself is never exposed.

Can the ExoVM cloud reach into my network?

No. The ExoVM cloud never opens connections to your network. Your connector connects out, receives commands and runs them against vCenter locally.

Does ExoVM work in a network with no internet access at all?

No. The connector needs outbound HTTPS to the ExoVM cloud. vCenter and ESXi don’t need internet access; only the connector host does.

Want to see it on a real network diagram?

Tell us how your sites are laid out and we’ll show you where the connector goes.