1. When creating CEPH pools if you do not copy the keys on the command line
What keys do you talk about here?
2. Will your implementation of Open vSwitch have some sort of IP filtering with it or will it be similar to your Linux bridge and rely on hardware firewall to protect VM's from each other? At the moment your current documentation states the use of a hardware firewall is recommended but this is only protecting the VM's from things outside the host and not protecting VM's from other VM's even on the same host machine.
There will be no firewall for OVS.