Friday, July 28, 2017

vSAN 6.6.1 with VUM Integration

This is a timeless idea that could not be more true when it comes to software design.  It’s one of the reasons why so many IT organizations are looking to replace complex infrastructures requiring the expertise of storage, networking and compute professionals with HCI solutions like VMware vSAN. This concept of simplicity being the “ultimate sophistication” was the first thing I thought of when I learned about the integration of VMware vSphere Update Manager (VUM) in vSAN 6.6.1.

Today’s IT admins understand the complexity of keeping infrastructures up to date. This has traditionally been a manual task with multiple sources of truth to get to the right update/upgrade, patch, driver levels; a complex, manual task with high risk of human error.

vSphere Update Manager (VUM) performs zero-downtime patching and upgrading of VMware ESXi clusters and is a very popular update tool for many VMware environments. VMware engineers decided to integrate VUM into vSAN with one goal in mind: Simplicity. As a result, vSAN patch and version management is not only a process now fully integrated in vSAN but the VUM process itself has been drastically simplified.

VUM High Level Architecture


vSAN 6.6.1 and later provides a seamless automated update process to ensure a vSAN cluster is up to date with the best available release to keep your hardware in a supported state. vSAN version recommendations are automatically generated using information from the VMware Compatibility Guide, the vSAN Release Catalog, and awareness of the underlying hardware configuration. This also includes the necessary drivers and patch updates for the recommended release in its system baseline. vSAN build recommendations will make sure that the clusters will remain at the current hardware compatibility status or better. In cases, where the existing cluster is not on HCL, vSAN will recommend users upgrade to the latest release. The key point here is that this vSAN baseline will only be updated to the highest level of compatibility based on your environment, making the upgrade process a much more predictable experience.

Configuring vSphere Update Manager

The first step is to add your my.vmware.com credentials to the vSAN Build Recommendation Engine. After successful login vSAN will generate a baseline group of recommended updates for each vSAN cluster. vSAN system baselines are listed in the Baselines pane of the Baselines and Groups tab.


vSAN Build Recommendation

For hosts running 6.0 Update 1 and earlier, use the Ruby vSphere Console to enter the My VMware credentials. To enter My VMware credentials from RVC, run the following command: vsan.login_iso_depot -u <username> -p <password>

vSAN Build Recommendations in vSphere Update Manager

vSAN build recommendations are provided through vSAN system baselines for Update Manager. In Figure 3 the 7 hosts in my vSAN cluster are running 6.0 Update 2. After checking the VMware Compatibility Guide and the vSAN Release Catalog, using the vSAN baseline, Update Manager determined there is a recommended update available.  As a result, all 7 hosts are non-compliant. The next step is to remediate.


Note: vSAN baselines are read-only and managed by vSAN.  They exist alongside user created baselines. Users can continue to create and remediate their own baselines as they wish. All baselines can either be remediated on a per-host or a per-cluster basis.

Updating a vSAN Cluster

To update the vSAN cluster, simply use the remediate feature of Update Manager. The Remediate wizard offers several options to customize the upgrade:

  • Select the desired hosts as the target of your remediation.
  • Schedule the upgrade to run immediately or at a later date and time.
  • Specify Maintenance Mode options (i.e. VM power state, removable media handling and ESXi patch settings)
  • Specify cluster remediation options. When remediating a cluster, you should temporarily disable certain cluster features. Update Manager will automatically re-enable the features after remediation.
After selecting the desired options, Update Manager will perform a rolling upgrade of each host, non-disruptively migrating your VMs to other hosts during the upgrade. While the host is offline vSAN marks all components on the host as absent. To ensure availability, if for some reason, the patched host does not come back online within 60 minutes (default CLOM timer delay), vSAN will start rebuilding these components on other hosts just like it would in any other host-offline situation. Upon completion of the upgrade you will notice each host is now placed in the Compliant tab.

Before using Update Manager in vSAN 6.6.1 be sure to verify the following:

  • If running a Windows-based vCenter Server, verify Update Manager is installed and configured.
  • vSAN requires Internet access to update release metadata, to check the VMware Compatibility Guide, and to download ISO images from My VMware.
  • vSAN requires valid My VMware (my.vmware.com) credentials to download ISO images for upgrades.
I hope this has been informative and thank you for reading!

Thursday, July 20, 2017

VMware vSAN 6.6

VMware vSAN 6.6 is the industry-leading software powering Hyper-Converged Infrastructure (HCI) solutions. vSAN is optimized for VMware vSphere virtual machines and natively integrated with vSphere . Since drives internal to the vSphere hosts are used to create a vSAN datastore, there is no dependency on expensive, difficult to manage, external shared storage.

vSAN already integration with vSphere and the VMware ecosystem makes it the ideal storage platform for business-critical applications, disaster recovery sites, remote office and branch office (ROBO) implementations, test and development environments, management clusters, security zones, and virtual desktop infrastructure (VDI). Today, customers of all industries and sizes trust vSAN to run their most important applications.

All-flash configurations provide the highest levels of performance with very low latencies for demanding business-critical applications. Space efficiency features such as inline deduplication and compression minimize capacity consumption, which reduces capital expenditures. Per-virtual machine (VM) storage policy-based management lowers operational expenditures by enabling administrators to manage performance, availability, and capacity consumption with ease and precision. This means no more LUN management.

Many deployment options are available for vSAN. These options range from single, 2-node clusters for small implementations to multiple clusters each with as many as 64 nodes—all centrally managed by vCenter Server. Stretched clusters can easily be configured to enable cross-site protection with no downtime for disaster avoidance and rapid, automated recovery from entire site failure.

vSAN 6.6, the sixth generation of vSAN, is designed to help customers modernize their infrastructure by addressing three key IT needs: higher security, lower costs, and faster performance. For example, vSAN 6.6 further lowers total cost of ownership by providing more resilient, economical stretched clusters that are easy to deploy and maintain.

New Features

  • vSAN Encryption
  • Stretched Cluster with Local Site Protection
  • Removal of Multicast Support Unicast Networking (Cloud-friendly Networking with Unicast)
  • ESXi Host Client (HTML-5) management and monitoring functionality
  • Enhanced rebalancing
  • Enhanced repairs
  • Enhanced resync
  • Resync throttling
  • Maintenance Pre-Check
  • Stretched Cluster Witness Replacement UI
  • API enhancements
  • vSAN Easy Install
  • Enhanced Health Monitoring


The industry’s first native HCI encryption solution and a highly available control plane is delivered in vSAN 6.6 to help customers evolve without risk without sacrificing flash storage efficiencies. Operational costs are reduced with 1-click firmware and driver updates, as well as, proactive cloud-connected health checks for real-time support.

vSAN has been enhanced with up to 50% greater flash performance enabling customers to scale to tomorrow’s IT demands. vSAN storage services are integrated with the Photon Platform with full API management to support container technologies and take advantage of DevOps efficiency.

I hope this has been informative and thank you for reading!

vSphere 8 Security Configuration & Hardening

    The VMware vSphere Security Configuration & Hardening Guide (SCG) has evolved significantly over the past fifteen years, remaining...