As VMware cloud foundation 4.3 is around for a while and 4.3.1 is already available, I thought I should write this piece on how to design and deploy step by step. So with out wasting any time lets directly jump on to the product. VMware cloud foundation is available for some time now and many enterprises are adopting it because of ease of management it provides, in terms of a complete suite which includes all required/necessary products for a true software defined datacenter. But if you are new to VMware Cloud Foundation then be aware VMware cloud foundation is a VMware validated suite of products such as vSphere for compute virtualization, vSAN for storage virtualization and NSX for network virtualization along with other products to ease day 2 operations. Interoperability of these products is extensively tested by VMware and finally made available for general use. It is based on VMware validated designs so all solution designing principle are accounted for.
If you are installing it fresh or you need to upgrade from a previous version of VCF I would recommend reading the release notes. Below are few sections I focus.
What's new
- Flexibility in Application Virtual Networks (AVN): Application Virtual Networks (AVN)s, which include the NSX Edge Cluster and NSX network segments, are no longer deployed and configured during bring-up. Instead they are implemented as a Day-N operations in SDDC Manager, providing greater flexibility.
- FIPS Support: You can enable FIPS mode during bring-up, which will enable it on all the VMware Cloud Foundation components that support FIPS.
- Scheduled Automatic Password Rotations: In addition to the on-demand password rotation capability, it is now possible to schedule automatic password rotations for accounts managed through SDDC Manager (excluding ESXi accounts). Automatic password rotation is enabled by default for service accounts.
- SAN in Certificate Signing Requests (CSR) : You can now add a Subject Alternative Name (SAN) when you generate a Certificate Signing Request (CSR) in SDDC Manager.
- Improvements for vSphere Lifecycle Manager images: For workload domains that use vSphere Lifecycle Manager images, this release includes several improvements. These include: prechecks to proactively identify issues that may affect upgrade operations; enabling concurrent upgrades for NSX-T Data Center components; and enabling provisioning and upgrade of Workload Management.
- Add vSphere Clusters in Parallel: You can add up to 10 vSphere clusters to a workload domain in parallel, improving the performance and speed of the workflow.
- Add and Remove NSX Edge Nodes in NSX Edge Clusters: For NSX Edge clusters deployed through SDDC Manager or the VMware Cloud Foundation API, you can expand and shrink NSX Edge clusters by adding or removing NSX Edge nodes from the cluster.
- Guidance for Day-N operations in NSX Federated VCF environments: You can federate NSX-T Data Center environments across VMware Cloud Foundation instances. You can manage federated NSX-T Data Center environments with a single pane of glass, create gateways and segments that span VMware Cloud Foundation instances, and configure and enforce firewall rules consistently across instances. Guidance is also provided for password rotation, certificate management, backup and restore, and lifecycle management for federated environments.
- Backup Enhancements: You can now configure an SDDC Manager backup schedule and retention policy from the SDDC Manager UI.
- VMware Validated Solutions: VMware Validated Solutions are a series of technical reference validated implementations designed to help customers build secure, high-performing, resilient, and efficient infrastructure for their applications and workloads deployed on VMware Cloud Foundation. Each VMware Validated Solution will come with detailed design with design decisions, implementation guidance consisting of manual UI-based step-by-step procedures and, where applicable, automated steps using infrastructure as code. These solutions based on VMware Cloud Foundation will be available on core.vmware.com. The first set of validated solutions, that can be applied on vSAN ReadyNodes, include the following:
- Identity and Access Management for VMware Cloud Foundation
- Developer Ready Infrastructure for VMware Cloud Foundation
- Advanced Load Balancing for VMware Cloud Foundation
- Private Cloud Automation for VMware Cloud Foundation
- Intelligent Operations Management for VMware Cloud Foundation
- Intelligent Logging and Analytics for VMware Cloud Foundation
- Documentation Enhancements: The content from VMware Validated Design documentation has now been unified with core VMware Cloud Foundation documentation or has been integrated into a VMware Validated Solution. Additional documentation enhancements include:
- Design Documents for VMware Cloud Foundation foundational components with design decisions
- Design for the Management Domain
- Design for the Virtual Infrastructure Workload Domain
- Design for vRealize Suite Lifecyle and Access Management
- Getting Started with VMware Cloud Foundation publication
- Procedure enhancements through unification of content between VMware Validated Design and VMware Cloud Foundation publications
- Capacity Planner tool: Administrators can use the VCF Capacity Planner online tool to model and generate a Software Defined Data Center build of materials. This interactive tool generates detailed guidance of hyper-converged server, storage, network, and cloud software SKUs required to successfully deploy an on-premises cloud.
- Private APIs: Access to private APIs that use basic authentication is deprecated in this release. You must switch to using public APIs.
- BOM updates: Updated Bill of Materials with new product versions.
Bill of Materials (BOM)
If you are upgrading from previous version then please check Installation and Upgrade Information Section.
Resolved and known Issues:
Host Creation
Preparing Deployment parameter sheet.
Setting number of NSX-T managers for lab deployment.
If you did not download parameter sheet from VMware website then you can download it now and populate it.
Once you move next it will start validating and converting the excel file into json, hence wait for JSON Spec validation task to complete.
Once task is complete connect to Cloud builder using WINSCP and navigate to "/tmp" directory, you will find one excel and one JSON file, but as you are logged in using admin account you will not have access on it.
Now login to cloud builder using ssh with admin credentials. Elevate privileges to root with command sudo -s and navigate to /tmp directory, list all files, select json file and change permission to allow all with command "chmod 777 <filename>".
Once file is downloaded its time to clean up current execution task. Use these commands to clean up current execution. Same commands can be used to clean up cloud builder if you frequently deploy it for your customers and use same cloud builder for bringup.
Now edit the JSON file for defining number of NSXT managers appliances. In JSON file search for "nsxtspec" and you will find below output with IP schema you have mentioned in excel sheet.
Hi
ReplyDeleteCan you share file excel file becasue in picture on this post very small.
Thanks
Link for planning and preparation workbook https://docs.vmware.com/en/VMware-Cloud-Foundation/4.3/vcf-planning-and-preparation-workbook.zip
DeleteLink to download deployment parameters sheet for version 4.3 https://download2.vmware.com/software/vi/vcf431/vcf-ems-deployment-parameter.xlsx?HashKey=5fc9fa840d8b0dfd1b317dbb96e1c5da¶ms=%7B%22custnumber%22%3A%22dGRkanBodyV3ZQ%3D%3D%22%2C%22sourcefilesize%22%3A%2292.10+KB%22%2C%22dlgcode%22%3A%22VCF431%22%2C%22languagecode%22%3A%22en%22%2C%22source%22%3A%22DOWNLOADS%22%2C%22downloadtype%22%3A%22manual%22%2C%22eula%22%3A%22Y%22%2C%22downloaduuid%22%3A%2269ff8d40-990b-456e-912f-7a03fb8cbf7e%22%2C%22purchased%22%3A%22Y%22%2C%22dlgtype%22%3A%22Product+Binaries%22%2C%22productversion%22%3A%224.3.1%22%2C%22productfamily%22%3A%22VMware+Cloud+Foundation%22%7D&AuthKey=1636999907_5406d746cae6c3fab82662a99b671341
Thank, I downloaed your link, but in picture in this post, in tab " Credentials, Host and Networks and deploy parameters" very small. I can't see paramter in picture.
DeleteI follow your homelab, i see you using gateway .254 but picture this post you gateway .253.
If you can sent samaple excel or json file for LAB. You can delete license key before share.
Thanks
Hi , I'm trying to follow your steps but in 4.4 , I cannot get the Joison file to update it with the NSX but I cannot get it from WinSCP , and my LAB crashed because of 3 NSX nods
ReplyDeleteHi Mosab,
ReplyDeleteYou will have to first upload excel and start validation, once validation is started you will get the files in the specified directory.
Very fine
ReplyDelete