Early access

vCenter web panel and VMware client portal: Faster VMware control for your team. A self-service panel for your customers.

ExoVM lets you manage VMs on private vCenter and ESXi servers from one browser tab. No VPN, no jump host, and vCenter never faces the internet: a small connector inside your network does the talking.

Early access: now onboarding hosting providers, MSPs and IT teams. Pricing quoted per environment.

Last updated:

What is ExoVM?

ExoVM is a web-based control panel for VMware vCenter and ESXi that lets operators manage their virtual machines from one browser tab and give their own customers a self-service panel, while vCenter stays on the private network behind a small Docker connector. The connector opens outbound connections to the ExoVM cloud, so vCenter never has to be reachable from the internet. Your team gets power, console, snapshots and an audit log without a VPN; your customers get a clean panel with only their VMs.

How ExoVM connects to a private vCenter Your team and your customers use the ExoVM panel in their browsers. Inside your private network, the ExoVM connector opens outbound connections to the ExoVM cloud to receive commands and calls vCenter’s vSphere APIs on the internal network. Nothing on the internet connects to vCenter. VM console streams are served over TLS from the connector host on port 443. Your private network Firewall Browsers Your team & your customers Your team Your customers HTTPS Console (TLS, port 443) ExoVM cloud app.exovm.com Outbound HTTPS ExoVM connector Docker · next to vCenter Internal network vCenter / ESXi Never exposed No inbound access to vCenter How ExoVM connects to a private vCenter Your team and your customers use the ExoVM panel in their browsers. Inside your private network, the ExoVM connector opens outbound connections to the ExoVM cloud to receive commands and calls vCenter’s vSphere APIs on the internal network. Nothing on the internet connects to vCenter. VM console streams are served over TLS from the connector host on port 443. Browsers Your team & your customers Your team Your customers HTTPS ExoVM cloud app.exovm.com Your private network Outbound HTTPS ExoVM connector Docker · next to vCenter Internal network vCenter / ESXi Never exposed
Outbound HTTPS Console (TLS, port 443) No inbound access to vCenter

How ExoVM is built

  • vCenter stays private
  • Outbound connector, runs in Docker
  • Agentless: nothing installed in your VMs
  • Works with vCenter Server
  • Multi-vCenter, multi-site
  • Customers see only their assigned VMs
  • Panel in English and Turkish

The problem

Reaching one VM shouldn’t take a VPN, a jump host and a heavy client.

Most VMware teams get to their VMs the same way. Connect the VPN. Hop through a jump host. Wait for vSphere Client. Find the VM. It works, but every task pays that toll, and none of it works for your customers.

  • VPNs and jump hosts add steps to every task and one more system to patch and maintain.

  • Exposing vCenter to the internet would remove those steps, but it puts your most sensitive management interface in reach of anyone. Few teams will accept that.

  • vSphere Client is built for administrators, not for a customer who needs to reboot one VM.

  • Customers ask for console access, and every request becomes a ticket, a screen share or a vCenter account you’d rather not create.

  • VMware Cloud Director is a full cloud platform for a job that is often “let customers see and control their VMs”. Since Broadcom moved VMware to subscription-only licensing and made its cloud provider program invitation-only, many smaller providers no longer have an easy path to it.

Sources: RCPmag, 13 December 2023; The Register, 16 July 2025

How it works

Three steps from private vCenter to one fast panel

  1. Run the connector

    Start the ExoVM connector as a Docker container on a host next to vCenter. Its vCenter credentials live in its environment on your host and are never stored in the ExoVM cloud.

    docker compose up -d
  2. Connect and sync

    The connector opens an outbound connection to the ExoVM cloud and syncs your VM inventory into the panel. Add more vCenters or sites whenever you need to.

  3. Assign and hand over

    Create customer users, assign them specific VMs and set quotas. Your team and your customers sign in to the same panel and each sees exactly what they’re allowed to see.

See how it works

One panel, two audiences

Speed for your team. Self-service for your customers.

For your team

Stop tunnelling into each site. Every VM you run is one click away.

  • Every vCenter, ESXi host and site in one VM list
  • Power on, power off and guest reboot from the browser
  • VM console without a VPN or vSphere Client
  • Snapshots, ISO mount and notes per VM
  • Assign VMs, set per-user quotas and answer tickets in the same place
  • An audit log of who did what, and when

For your customers

Give each customer a clean panel of their own, without giving them vCenter.

  • Only the VMs you’ve assigned to them
  • CPU, RAM, disk, guest OS, IP and power state at a glance
  • Browser console, power on/off and guest reboot
  • Support tickets without leaving the panel
  • No vCenter account, no VPN, no vSphere Client
  • Panel in English or Turkish

Explore all features

Features

Everything you need to run VMs day to day

  • VM inventory

    The connector syncs VMs from vCenter into the panel. See CPU, RAM, guest OS, IP and power state on one screen.

  • Power operations

    Power on, power off and guest reboot, from the VM page.

  • In-browser console

    An HTML5 console in the browser, brokered by your connector with short-lived, single-use tickets. No plugin, no vSphere Client.

  • Snapshots

    List, create, revert and delete snapshots from the VM page.

  • ISO mount

    Mount an ISO image from a datastore to a VM’s virtual drive.

  • Notes

    Notes so your team knows what a VM is for.

  • Assignment and quotas

    Assign specific VMs to specific users and set per-user quotas.

  • Support tickets

    Customers open tickets inside the panel. Your team answers in the same place.

  • Audit log

    Power, console, snapshot and ISO requests, VM assignments and role changes are recorded with the user, the action and the time.

Explore all features

Security

vCenter stays private. Here’s exactly how.

ExoVM was designed around one rule: nothing on the internet should need to reach vCenter.

  • Outbound only, from your side. The connector connects out to the ExoVM cloud to receive commands. vCenter and ESXi never accept connections from the internet.

  • Browsers never talk to vCenter. Every action goes through the panel and your connector.

  • Credentials stay with you. vCenter credentials live in the connector’s environment on your host. They are never stored in the ExoVM cloud.

  • Scoped customer access. Each customer only sees the VMs assigned to them.

  • Single-use console tickets. Each console session uses a short-lived ticket that works once.

  • An audit log. User, action and time for VM and access changes.

Read the security model

Compare

How ExoVM compares

The usual ways to give people access to VMware VMs, side by side. No prices, just trade-offs.

ExoVM compared with VPN + vSphere Client, VMware Cloud Director and building your own portal
Criterion ExoVM VPN + vSphere Client VMware Cloud Director Build your own portal
vCenter exposure Not exposed. The connector connects outbound; consoles are served from the connector host on 443. Reachable by everyone on the VPN. vCenter stays behind the Cloud Director cells, which are the internet-facing part. Depends on your design.
Customer self-service Yes. Assigned VMs, console, power and tickets. Only by giving customers vCenter accounts. Yes, a full tenant portal. Whatever you build and maintain.
Setup effort Low. One Docker connector per vCenter, then add targets and users in the panel. Medium. VPN accounts, client access and vCenter permissions per person. High. A full platform to deploy, integrate and operate. High. Ongoing development and maintenance.
Licence needed ExoVM, with pricing quoted per environment. Works with the vCenter and ESXi you already run. Your VPN and existing VMware licences. Broadcom licensing through its cloud provider program, now invitation-only. None, but your engineering time.
Multi-vCenter Yes. One connector per vCenter, every site in one panel. Per-vCenter access unless you set up linked vCenters. Yes. If you build it.
Console in browser Yes. HTML5, in the browser; compatibility validated during onboarding. Yes, inside vSphere Client, for users with vCenter access. Yes. You integrate one yourself.

VMware Cloud Director does far more than ExoVM: virtual data centres, tenant networking, catalogues. If you need a full self-service cloud, it’s built for that. ExoVM is for teams that need fast control and a clean customer panel on the vCenter and ESXi they already run.

Compare with vCloud Director

Key facts

  • ExoVM is a two-part system: a web panel hosted by ExoVM and a small Docker connector that you run next to vCenter inside your private network.

  • The connector opens outbound connections to the ExoVM cloud, receives commands in real time and calls the vSphere APIs locally. vCenter and ESXi never accept connections from the internet, and browsers never talk to vCenter directly.

  • vCenter credentials live in the connector’s environment on your host and are never stored in the ExoVM cloud.

  • VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443. vCenter itself is never exposed.

  • ExoVM’s console is an HTML5 client that runs in the browser with no plugin. Console behaviour depends on your ESXi hosts and guest configuration, so we validate compatibility for your environment during onboarding.

  • Works with vCenter Server, with one connector per vCenter. Standalone ESXi hosts without vCenter aren’t supported yet.

  • In ExoVM, each customer user only sees the VMs an admin has assigned to them.

  • Agentless: nothing is installed inside your VMs; ExoVM talks to the vSphere APIs.

  • Panel in English and Turkish.

  • ExoVM is onboarding early-access customers now. Pricing is quoted per environment.

FAQ

Questions operators ask first

Does vCenter have to be reachable from the internet?

No. The ExoVM connector runs inside your network and opens outbound connections to the ExoVM cloud to receive commands. vCenter and ESXi never accept connections from the internet, and browsers never talk to vCenter directly.

Secure vCenter access without VPN for enterprise IT

How can I manage vCenter VMs remotely without a VPN?

Put a panel in front of vCenter instead of a VPN. ExoVM’s Docker connector runs next to vCenter and connects outbound to the ExoVM cloud, so you can power VMs on and off, reboot guests and open consoles from any browser while vCenter accepts no connections from the internet. Browsers that open consoles must be able to reach the connector host on port 443. For cluster, storage and network administration you still use vCenter itself.

What does my firewall need to allow?

The connector needs outbound HTTPS to the ExoVM cloud and access to vCenter and your ESXi hosts on your internal network. One honest caveat: VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443. vCenter itself is never exposed.

Will the in-browser console work with my VMs?

ExoVM’s console is an HTML5 client, brokered by the connector with short-lived, single-use tickets, so nobody needs a plugin or vSphere Client. Console behaviour depends on your ESXi hosts and guest configuration, so we validate compatibility for your environment during onboarding.

Can my customers see each other’s VMs?

No. In ExoVM, a customer user only sees the VMs an admin has assigned to them.

VMware self-service portal for hosting providers

Does ExoVM work with standalone ESXi and multiple vCenters?

ExoVM works with vCenter Server. Run one connector per vCenter, at as many sites as you need, and manage them from one panel. Standalone ESXi hosts without vCenter aren’t supported yet.

Multi-site VMware client portal for MSPs

How much does ExoVM cost?

ExoVM is onboarding early-access customers now. Pricing is quoted per environment. Request a demo, tell us about your setup, and we’ll send you a quote.

Read the full FAQ

One panel for your team and your customers

We’re onboarding early-access customers now. Book a demo and we’ll walk through your setup: which vCenter, how many sites, and who needs access. Pricing is quoted per environment.