Thursday, May 20, 2021

Free VMware vSAN Training - vSAN 7 Plan and Deploy / vSAN Fundamentals

To learn VMware vSAN Basics, Here is free 1 Day VMware vSAN Version 7 Training offered by VMware. It is renamed as vSAN Fundamentals now.

 


Enroll for this Free Training

 I hope this has been informative and thank you for reading! 

Friday, April 30, 2021

vSphere Virtual Machine Service ( vSphere 7 Update 2a release )

vSphere Virtual Machine Service (VM Service). Included in the vSphere 7 Update 2a release, the VM Service enables Kubernetes-native provisioning and management of virtual machines, for developers running modern apps on vSphere with Tanzu. The VM Service allows a developer (or any DevOps, platform operations, or Kubernetes user) to deploy and manage virtual machines using Kubernetes standard APIs, while simultaneously allowing the IT administrator to govern resource consumption and service availability.

 

This capability joins the Network Service and Storage Service that have been available since VMware originally released vSphere with Tanzu last year, collectively giving developers self-service access to the compute, network, and storage resources they need to run their applications, using a Kubernetes API surface. With the VM Service, vSphere with Tanzu further empowers organizations to modernize their applications and enhance the cloud-native experience for their developers.


Boost Operational Efficiency

Whether you’re an application developer, an IT admin, or any other Kubernetes user or admin, the VM Service will make your life easier. For Kubernetes developers and users, you can self-provision and customize VMs whenever you need them. No need to call the IT help desk or submit an IT service request. For administrators, you no longer have to service those individual requests or create customized VMs for Kubernetes users.
Enforce Guardrails

As an IT admin, you want to make sure those new VMs stay within the boundaries you determine, based on the available infrastructure and capacity, as well as organizational policy. Pre-configure several VM classes for developers to choose from, each with unique CPU and memory limits optimized for different types of applications (data intensive, compute intensive, etc.). Keep your developers happy and collaborate better.

Cloud-native Experience

Modern applications often use a combination of containers and VMs. For example, it’s not uncommon for a containerized app to utilize a database hosted within a separate VM. The VM Service will allow developers and other Kubernetes users to easily define the structure of these applications (using a YAML specification) in a self-service manner. And because the VM Service uses a standard Kubernetes consumption model, it will work the same way everywhere.

Open-source Commitment

As a leading contributor in the Kubernetes open-source community, VMware continues to demonstrate its commitment to open-source with this announcement. As of today, the vSphere team has released the VM Operator repository on Github to the community. Want to take a look at our source code? You’re welcome to check it out. 

I hope this has been informative and thank you for reading!

Saturday, March 13, 2021

vSphere 7 Update 2 Release

VMware has released vSphere 7 Update 2. It is available to download right away, both through VMware Customer Connect and from within vSphere Lifecycle Manager itself.

What’s New in vSphere 7 Update 2

With the release of vSphere 7, we set the direction for the key focus areas where we are making investments in vSphere, incorporating feedback about what is most important for you and that will get you to your organizations’ goals now and in the future, leveraging the latest technology has to offer. We continue to double-down on these focus areas, to deliver to you the modern infrastructure platform for all your existing workloads and the new modern applications you are building, leveraging containers as well as artificial intelligence and machine learning (AI/ML).

These key areas are:

 
Deliver AI & Developer Ready Infrastructure

First off, we’re thrilled to share that VMware and NVIDIA are delivering the next step of the vision shared in the partnership announced at VMworld 2020 to democratize and unleash AI for every enterprise. With the unique combination of VMware vSphere 7 and NVIDIA AI Enterprise suite, both companies are jointly delivering a powerful AI-Ready Enterprise Platform.

NVIDIA AI Enterprise software suite is an end-to-end cloud-native suite of AI tools and frameworks, optimized and exclusively certified by NVIDIA to run on VMware vSphere.

 

 
 
VMware vSphere 7 Update 2 delivers:

  •  Support for the latest generation of GPUs from NVIDIA, their Ampere family, with the A100 GPU delivering up to 20X better performance from the previous generation.Support for NVIDIA MIGs
  •  Support for NVIDIA GPUDirect RDMA for vGPUs, for enhanced performance.
  •  Support for the latest spatial partitioning based NVIDIA multi-instance GPUs (MIGs):
  •  vSphere is the ONLY virtualization platform that enables live migration (using vMotion) for NVIDIA MIG vGPU powered VMs, simplifying infrastructure maintenance such as consolidation, expansion, or upgrades, and enabling non-disruptive operations
  • With the Distributed Resource Scheduler (DRS), vSphere provides automatic initial workload placement for AI infrastructure at scale for optimal resource consumption and avoiding performance bottlenecks.
  • Bitfusion 3.0, continuing to make GPU use flexible and operationally efficient

 Boost Infrastructure and Data Security

With security being a huge area of focus for organizations of all types and sizes worldwide, vSphere 7 Update 2 delivers some key new capabilities:

  •     Introducing vSphere Native Key Provider, a mechanism fully within vSphere to enable data-at-rest protections like vSAN Encryption, VM Encryption, and vTPM out of the box, making it a lot easier for customers to take advantage of these security features and improve overall security posture for VM environments.
  •     Confidential Containers for vSphere Pods, leveraging the AMD SEV-ES memory and CPU data encryption on AMD EPYC platforms for modern and easy-to-use data-in-use protections.
  •     ESXi Configuration Encryption, using software and hardware Trusted Platform Module (TPM) support to protect ESXi secrets on the hosts themselves and making hardware lifecycle, reprovisioning, and decommissioning easier.
  •     ESXi Key Persistence, offering more options for data-at-rest protections on standalone hosts, edge computing deployments, and removing dependency loops from system designs.
  •     Updated baseline security guidance in the vSphere Security Configuration Guide for customers designing new systems or looking for ways to improve their existing security in the face of changing threats.
  •     Updated vSphere Product Audit Guides, together with FIPS validation of vCenter Server services. Together these make it easier for customers to meet regulatory requirements, as well as helping to ease audits by supplying an explanation of how vSphere security controls meet particular compliance controls.

The latest vSphere 7 Update 2 release further highlights vSphere as the industry’s leading compute virtualization platform that transforms bare metal server, CPU, and GPU-based hardware into virtual machines and containers. vSphere optimizes performance, increases availability, tightens security, and streamlines maintenance to create an agile, efficient, resilient, and intrinsically secure infrastructure platform to support existing workloads and next-gen applications such as AI.

I hope this has been informative and thank you for reading!

Saturday, February 20, 2021

VMware vSphere Security Configuration Guides


vSphere Security Configuration Guides for all supported versions of vSphere. For vSphere 6.5 and 6.7 the changes are minor, and make some recommendations based on improvements to those products (service disablement, and the deprecation of the svga vga Only guidance). Most installations of vSphere 6.5 and 6.7 are fairly mature, and we didn’t want to “rock the boat” as the saying goes. If a vSphere Admin has to spend political capital to make changes in older environments I’d rather they did it on patching first. After all, patching and good access control hygiene are commonly accepted as the two biggest ways to improve security.

vSphere 7 is different. Most customers are building new environments based on vSphere 7, and as they work through system designs they use tools like the Security Configuration Guide as a input into their designs. With the Security Configuration Guide released with vSphere 7 Update 1 we took the opportunity to be more prescriptive about best practices in all parts of a vSphere implementation. Today’s update takes that a bit further. Isolating management networks, disabling SSH, better firewall, better security practices, and even leaving behind some old security controls that cause more problems than they solve nowadays. Security is always a tradeoff, usually against usability, and making good choices about where to spend your time is a huge part of getting ahead. This fact is also what resonates with many of us at VMware as we develop guidance and products. How do we help organizations get back to their own work faster? How do we help vSphere Admins and their colleagues prioritize the risks? Tools like Carbon Black Workload Protection demonstrate some of that thinking in action.

If you’re interested in the vSphere Security Configuration guides you can download them at https://core.vmware.com/security-configuration-guide

What Changed with the Security Configuration Guide 7

The vSphere Security Configuration Guide 7 has been updated with quite a bit of cumulative feedback. Thank you for all of it. The document inside the kit .zip file tells you how to submit feedback..

  • Corrected errors in the PowerCLI guidance for auditing VMs (I’d mis-pasted Get-VMHost instead of Get-VM)
  • The first vSphere SCG 7 introduced spreadsheet tabs for ESXi, vCenter Server, VMs, and In-Guest controls. This version adds a tab for “Deprecated.” A big question that has always loomed over us is “where did a security control go?” It is our intention that, moving forward, when something isn’t a good idea anymore we put it out to pasture in the Deprecated tab. This keeps it visible, and allows us to document WHY we are making that change.
  • Moved the svga.vgaOnly control to the Deprecated tab. That control limits a VM to only VGA resolutions, and many modern guest OSes do not like that. It’s a source of friction and confusion and the cause of a lot of calls to support (ours and others). Beyond that, though, modern guest OSes sometimes don’t display anything at all when they can’t get the video mode they like, and that means important diagnostic information may go unobserved. Security is a tradeoff, and the meager benefits we might get from this control are completely outweighed by the problems the control causes. You can certainly use the control if you want, but we don’t recommend it for general use anymore.
  • Added and updated guidance for disabling SLP and CIM service daemons on ESXi. Security advisories are often good opportunities to assess the state of things, and most customers do not use these protocols. No VMware products use these protocols, either. We now have good methods and guidance for disabling them.
  • Added controls for network isolation. It’s been commonly held as a sort of “tribal knowledge” that you should isolate management, vMotion, and vSAN. We finally wrote it down. We also include guidance about extending that down into hardware. Out-of-band management controllers like Xclarity, iLO, and iDRAC are wonderful, but they can sometimes be configured in ways that present opportunities to attackers, and we’d like you to think about that as part of your system designs.
  • Added guidance to close a loophole in the SCG. For years we have included guidance about patching, because many organizations use the SCG as a checklist, and we’d like everyone to check off the “I’m Patched!” box because patching is the only way to remove vulnerabilities. However, the way it is phrased makes it possible to be running an unsupported version of vSphere, be completely patched, and still be able to check that box. Rewording it created other issues so we simply added esxi-7.supported and vcenter-7.supported controls to highlight that an organization still should be running software that has not reached end-of-life.
  • Added guidance about procuring and enabling Trusted Platform Modules, or TPMs. TPM 2.0 is an inexpensive way to get some very advanced security out of VMware vSphere and ESXi, and we feel strongly that you should not be acquiring new hardware without these. Even our friends at Microsoft agree — the Windows Server 2022 certifications require them, too (BTW, great use of the virtual TPM feature in vSphere when the time comes).
  • Re-added the vm-7.pci-passthrough guidance with updated guidance. Any time you allow a VM to directly access hardware you increase the risk that an attacker on that VM will be able to do something to the hardware. The PCIe bus was designed with certain assumptions in mind, and attackers can exploit those assumptions to cause disruptions on hosts (BTW, great reason to use vSphere HA, too).
  • Added guidance about disabling the DCLI interfaces if you aren’t using them on vCenter Server. If you’re using them — great! They’re wonderful. But if not, shut it off like you’ve shut SSH off, too (BTW, with all the new APIs in vSphere 7 you don’t need SSH enabled anywhere — shut it off and save a lot of compliance headache with scanning).

Again, you can download the vSphere Security Configuration guides at https://core.vmware.com/security-configuration-guide (and the main vmware.com Hardening Guide page is being updated as we speak). Also feel free to look around at other security resources at https://core.vmware.com/security or our Compliance resources at https://core.vmware.com/compliance.

I hope this has been informative and thank you for reading!

Monday, January 25, 2021

Advanced Cross vCenter Server vMotion Capability

 The Advanced Cross vCenter Server vMotion (XVM) capability was one of the most popular VMware Flings. A lot of customers were anxious to see this capability being an integrated part of vSphere. With the vSphere 7 Update 1c release, the XVM capability is embedded into the vSphere Client!

XVM helps to migrate virtual workloads between vCenter Server instances, without the requirement for Enhanced Linked Mode (ELM) or Hybrid Linked Mode (HLM).  This means it’s possible to migrate virtual machines (VMs) between vCenter Servers that are in different Single Sign-On (SSO) domains.

A common scenario of this is workload migrations from an on-prem vSphere infrastructure to VMC on AWS. Migrating without being constrained by vCenter Server configurations allows for a lot of migration ‘freedom’. XVM can be used for single VMs or bulk migrations.

From within the vSphere Client, two workflows are available to migrate workloads between vCenter Servers. Either using the ‘import VMs’ option  in the Hosts and Cluster view to import VMs from a target  vCenter Server Appliance (VCSA), or by selecting VMs and opt for ‘Migrate’ in the menu.
Cross vCenter Server Export
 

Cross vCenter Server Export

Regular manual vMotion operations, you can select the ‘Migrate’ option for one or multiple VMs. Next to the familiar options to change the compute resource, and/or the storage location for that VM, there’s a new option listed. Choose the new ‘Cross vCenter Server export’ option to use the XVM functionality.
 


 The same known options for the live migration operations apply, with an extra configurable that is the target vCenter Server instance.

This is where you configure the target vCenter Server. Either a new vCenter Server is connected, or a saved connection is chosen in the same user-session. Saved vCenter Server entries are not persisted but retained only for the current user session. This is particularly convenient when you need to execute multiple migration operations.

The other wizard options are similar to compute resource and storage vMotion tasks. Selecting the compute resource lists the target vCenter Server datacenters, clusters, and hosts. With XVM integrated into the vSphere Client, the compatibility checks are processed with each step to ensure a successful migration.    


During this wizard, you’ll have the ability to select the correct destination storage. It might be necessary to change the VM(s) networks to match the target configuration. Once everything checks out and the appropriate resources are selected, the migration is ready to kick off.

The Importing VMs Option

The menu on a cluster or host level provides the new option to ‘Import VMs’. Selecting this option opens a wizard to walk you through the import process.


To import VMs from a remote vCenter Server, the source vCenter Server needs to be connected. The option to save the vCenter Server address helps with future migrations as you can just select previous saved vCenter Server instances.


After successfully logging in to the remote vCenter Server, the migration batch is further configured. Either one VM or multiple VMs can be selected and migrated in one go.


The rest of the wizard is similar to the Migrate option with XVM, as shown in the previous chapter.

I hope this has been informative and thank you for reading!

Monday, December 21, 2020

VMware HCX Capabilities in VMware Cloud on AWS

VMware HCX for expanding into VMware Cloud on AWS to seamlessly migrating your workloads and re-balancing them between your on-premises datacenters and the cloud, or between different public clouds.

The list of features included in this single VMware HCX generally available offering for VMware Cloud on AWS are: Replication Assisted vMotion, Mobility Optimized Networking, Mobility Groups with VMware vRealize Network Insight integration and Traffic Engineering features -TCP Flow Conditioning and Application Path Resiliency.


Replication Assisted vMotion (RAV)

RAV uses a combination of VMware replication and vMotion technologies for large-scale, parallel migrations with no service interruption with the ability to specify a switchover window. It means you can now create a migration schedule during which a large set of VMs (200 at this time) can move live (without any downtime) to VMware Cloud on AWS at the scheduled migration window.

Mobility Optimized Networking (MON)

For VMs migrated using VMware HCX from a source location to VMware Cloud on AWS, this capability enables the cloud-side VMs on the HCX extended network to route traffic optimally through the cloud-side first-hop gateway instead of being routed through the source environment router. This helps you avoid a hairpin or trombone effect. Policy routes will allow control over which traffic is routed locally using the cloud gateway versus traffic that goes out through the source gateway.

Mobility groups and integration with VMware vRealize Network Insight (vRNI)

Mobility groups enable you to structure migration waves based on business requirements. You can assemble one or more VMs into logical sets for execution and monitoring of migrations as a group. When combined with the vRealize Network Insight integration (available as a separate license), mobility groups give you the flexibility to manage migrations for sets of VMs by application, network, pod or other aspects of your environment.

Traffic engineering features


VMware HCX provides settings for optimizing network traffic for HCX Interconnect and Network Extension services:

  • TCP Flow Conditioning – This service dynamically adjusts the segment size during the TCP connection handshake between end points across the Network Extension, which optimizes the average packet size to reduce fragmentation and lower the overall packet rate.
  • Application Path Resiliency – This service creates multiple tunnel flows for both Interconnect and Network Extension traffic, so they can follow multiple paths across the network infrastructure from the source to the destination data centers. The service then intelligently forwards traffic over the optimal path and dynamically switches between tunnels depending on traffic conditions.

VMware HCX  in VMware Cloud on AWS helps accelerate your organization’s cloud adoption by facilitating workload mobility across a variety of destinations running a Software-Defined Data Center stack. Now you can eliminate all downtime associated with those large scale migrations, plan migration waves and fine tune mobility traffic in an optimally planned way.

I hope this has been informative and thank you for reading!

Friday, November 20, 2020

VMware Cloud on AWS reference architectures

VMware Cloud on AWS is an integrated cloud offering jointly developed by Amazon Web Services (AWS) and VMware. You can deliver a highly scalable and secure service by migrating and extending your on-premises VMware vSphere-based environments to the AWS Cloud running on Amazon Elastic Compute Cloud (Amazon EC2).

 
vSphere in a software-defined data center like your VMware Cloud on AWS SDDC works in the same way that your on-premises vSphere does. In the SDDC, some vSphere components are owned and managed by VMware, so some of the on-premises administrative workflows that you're familiar with aren't needed in VMC. 

VMware Cloud on AWS reference architectures
 
The designed to show non-VMware architects how to use VMware Cloud technologies to create a single, high-functioning environment that spans an on-premises data center and AWS.  


 The reference architectures address a broad range of topics including:
  •    How to create a secure network to support integration of an on-premises and AWS environment
  •   How to easily take advantage of AWS cloud services as part of a hybrid cloud that includes AWS
  •   How to deploy VMware Horizon across a hybrid cloud with desktops running both on-premises and in AWS
  •   Leveraging VMware technologies that make it easy to move workloads to AWS and back to the on-premises data center

VMware Cloud on AWS reference architectures link

I hope this has been informative and thank you for reading!

What is FinOps in VMware Cloud Foundation?

FinOps (Financial Operations) is all about helping IT teams and business leaders understand, control, and optimize cloud spending. VMware Cl...