Holodeck Toolkit Installation and Content Staging
Objectives
- Validate physical ESXi 8.0 Update 3 host meets minimum hardware requirements for Holodeck deployment
- Install and verify the Holodeck Toolkit PowerShell module
- Download and stage VCF content packs (ESXi ISO, OVAs, NSX bundles) to the correct directory structure
- Create and validate a Holodeck deployment configuration file with version-aligned parameters
- Execute a pre-flight checklist and establish a baseline snapshot for subsequent labs
Prerequisites
Clean single ESXi 8.0 Update 3 host with no existing Holodeck instances, sufficient resources (512 GB RAM, 64 cores, 2 TB SSD/NVMe storage), nested virtualization enabled in BIOS, network configured with one or more port groups supporting VLAN trunking, NTP and DNS resolvable from management network
Required skills:
- ESXi host installation and basic configuration
- PowerShell fundamentals — navigation, running cmdlets, importing modules
- JSON file editing and validation
- Network troubleshooting — PING, route commands, port group configuration
- Snapshot management in vSphere
Lab Environment
Single physical ESXi 8.0.x host. The lab does NOT deploy any VMs yet — it only installs the Holodeck Toolkit and stages content. The physical host's network is configured with port groups in VLAN trunking mode to support the nested environment that will be built in subsequent labs. Minimum topology: physical ESXi + management workstation or jump host with PowerShell + internet connectivity.
graph TB WST[Management Workstation] -->|HTTPS, SSH| PHESXI[Physical ESXi 8.0.x] WST -->|HTTPS| PBS[Broadcom Support Portal] PHESXI -->|Mgmt VLAN| VLAN1[VLAN 1644 Mgmt] PHESXI -->|vMotion VLAN| VLAN2[VLAN 1645 vMotion] PHESXI -->|vSAN VLAN| VLAN3[VLAN 1646 vSAN] PHESXI -->|NSX TEP VLAN| VLAN4[VLAN 1647 NSX Host TEP] PHESXI -->|NSX Edge TEP VLAN| VLAN5[VLAN 1648 NSX Edge TEP] PHESXI -->|Local SSD/NVMe| STORE[Content Staging Directory: /vmfs/volumes/datastore1/holodeck-content]
IP Addressing
| Network | Purpose | VLAN |
|---|---|---|
169.254.1.0/24 | Physical ESXi host out-of-band management (iDRAC, iLO, etc.) | Native/OOB |
10.1.1.0/20 | Reserved for future nested management network (will be configured in holodeck-02) | VLAN 1644 (assigned but not yet routed) |
10.1.1.0/24 | Reserved for future nested ESXi management (will be configured in holodeck-02) | VLAN 1644 (assigned but not yet routed) |
Credentials
| System | Username | Password |
|---|---|---|
| Physical ESXi Host | root | Set during ESXi 8.0 installation. Must be strong (length >= 8, mixed case, numbers, special chars). |
| Broadcom Support Portal | Your Broadcom support account email | Corporate SSO or personal Broadcom account — required to download VCF content packs |
| Management Workstation (for PowerShell) | Administrator | Windows administrator credentials if running PowerShell Core on Windows; sudo if on Linux/Mac |
Tasks
Task 1 Validate physical ESXi host hardware and nested virtualization
availabilityThe Holodeck Toolkit will fail silently or produce cryptic errors if the physical host doesn't meet minimum specs. VCDX candidates must understand the infrastructure constraints that underpin the lab environment — this mirrors the VCF Planning & Preparation Workbook checklist in production. Validating nested virtualization (vHV) up front prevents 2+ hours of wasted deployment attempts.
Connect to the physical ESXi host via SSH (or vSphere Client). Open a root shell: ssh root@<esxi-host-ip>
Verify ESXi version: esxcli system version get
Verify nested virtualization support (vHV): esxcli system settings kernel list | grep vmkAllowNested or check vSphere Client: ESXi host > Configure > System > Processors. Look for 'Nested Page Tables' (Intel EPT / AMD NPT).
Check total physical RAM: esxcli hardware memory get
Check CPU core count: esxcli hardware cpu global get (CPU Threads = logical cores)
Check available datastore space: esxcli storage filesystem list | grep vmfs or in vSphere Client: ESXi host > Storage > Datastores
Verify network configuration: Check port groups support VLAN trunking. In vSphere Client: ESXi host > Virtual Switches > (select vDS if using distributed switches). Confirm at least one port group with VLAN trunk allowed (VLAN 1-4094 or VLAN 1644-1648 range).
Verify NTP and DNS: esxcli system ntp get and esxcli system hostname get. Ensure NTP is synchronized and DNS resolvers are set.
Validation Gate
Check: Create a validation checklist: ESXi 8.0 U3+: YES/NO, vHV enabled: YES/NO, RAM >= 512GB: YES/NO, Cores >= 64: YES/NO, Free datastore >= 2TB: YES/NO, VLAN trunking configured: YES/NO, NTP synchronized: YES/NO, DNS resolving: YES/NO
Expected: All 8 items checked YES. If any is NO, document the gap and remediate before proceeding.
Common Errors
Task 2 Install and verify the Holodeck Toolkit PowerShell module
manageabilityThe Holodeck Toolkit is distributed as a PowerShell module. Installation and verification are trivial but critical — a malformed installation will cause every subsequent command to fail with ambiguous error messages. This task teaches the discipline of pre-flight module validation before running automation.
On your management workstation (with internet access and PowerShell 7.0+), download the Holodeck Toolkit. Option A (Recommended): Clone from GitHub: git clone https://github.com/vmware/Holodeck.git C:\Holodeck. Option B: Download from Broadcom support portal (requires account). Option C: If GitHub is unavailable, download from Broadcom Community: https://community.broadcom.com/vmware-cloud-foundation/ (search 'Holodeck')
Navigate into the Holodeck directory: cd C:\Holodeck (Windows) or cd ~/Holodeck (Mac/Linux with PowerShell Core)
Import the Holodeck module: Import-Module ./PowerShell/Holodeck.psm1 -Verbose
Verify the module is loaded: Get-Command -Module Holodeck | Measure-Object
Check Holodeck module version: Get-Module Holodeck | Select-Object -ExpandProperty Version
Verify connectivity to the physical ESXi host: Get-HoloDeckHealth -TargetHost <esxi-host-ip> -TargetHostUser root -TargetHostPassword <password> (alternatively, if prompts are preferred: Get-HoloDeckHealth will ask interactively)
Validation Gate
Check: Run: (Get-Command -Module Holodeck | Measure-Object).Count -ge 20, AND Get-Module Holodeck | Select-Object -ExpandProperty Version reports 9.0.2.19, AND Get-HoloDeckHealth passes.
Expected: All three checks pass. You are ready to stage content.
Common Errors
Task 3 Download and stage VCF content packs
manageabilityHolodeck orchestrates the deployment of nested infrastructure using pre-built ISOs and OVAs. These content packs are large (15+ GB total) and version-specific. Staging them correctly (right directory, right versions, verified checksums) is the single most common failure point in community forums. VCDX candidates must understand the content manifest as a bill of materials — in production, this parallels license manifest and hardware inventory documentation.
Create the content staging directory on your management workstation (or on the physical ESXi datastore for faster network performance). Recommended: /vmfs/volumes/<datastore>/holodeck-content or C:\Holodeck\content if staging locally first.
Download VCF 9.0.2 content pack from Broadcom support portal: https://support.broadcom.com (Search: 'VMware Cloud Foundation 9.0.2' or 'Holodeck'). Required files: (a) ESXi 8.0 Update 3 ISO (~670 MB), (b) vCenter Server OVA 8.0.x (~1.2 GB), (c) NSX Manager bundle 9.0.2 (~1.8 GB), (d) SDDC Manager OVA 9.0.2 (~1.2 GB), (e) Cloud Builder OVA 9.0.2 (~1.1 GB). Total: ~6-7 GB. Alternatively, if you have GitHub access: https://github.com/vmware/Holodeck/releases (pre-built manifest for 9.0.2)
Create a manifest file (manifest-9.0.2.json) in the content directory. Template: { 'vcfVersion': '9.0.2', 'components': [ { 'name': 'ESXi', 'filename': 'ESXi-8.0.3-XXXX.iso', 'sha256': '<hash>', 'size': 'XX GB' }, {...} ] }. For each file, compute its SHA256 hash: (Windows) certutil -hashfile <filename> SHA256 or (Linux/Mac) sha256sum <filename>
Verify manifest completeness: In PowerShell, run: $manifest = Get-Content ./manifest-9.0.2.json | ConvertFrom-Json; $manifest.components | ForEach-Object { if (!(Test-Path $_.filename)) { Write-Warning "Missing: $($_.filename)" } }
Verify manifest checksums: For each file, recompute its hash and compare against the manifest: (Powershell) (Get-FileHash 'ESXi-8.0.3-XXXX.iso' -Algorithm SHA256).Hash should match the sha256 field in manifest. Do this for all 5 files.
Optional but recommended: Move the content staging directory to the physical ESXi datastore to improve deployment performance. Example: scp -r C:\Holodeck\content root@<esxi-host>:/vmfs/volumes/datastore1/holodeck-content. Update the content path in config.json (Task 4) to reference the ESXi-local path.
Validation Gate
Check: List all files in content directory: ls -lah /vmfs/volumes/datastore1/holodeck-content. Verify: (1) all 5 files present, (2) manifest-9.0.2.json exists and is valid JSON, (3) all file sizes match expected (~6-7 GB total), (4) all SHA256 hashes match.
Expected: 5 content files staged, manifest validated, total size >= 6.5 GB
Common Errors
Task 4 Create and validate the Holodeck deployment configuration
manageabilityThe deployment configuration (config.json) is the source of truth for all Holodeck instances. Every IP address, hostname, VLAN, password, resource sizing, and version is defined here. This task mirrors the VCF Planning & Preparation Workbook — VCDX panelists will probe your ability to translate business requirements (performance, availability, licensing) into infrastructure parameters. A misconfigured config.json cascades into hours of deployment debugging.
Copy the Holodeck config template: Copy-Item ./PowerShell/templates/config-template.json ./templates/config.json or if template doesn't exist, manually create config.json with the structure shown in Holodeck documentation.
Edit config.json. Key fields to set: (a) targetHost: <physical-esxi-host-ip>, (b) targetHostUser: root, (c) targetHostPassword: <esxi-root-password>, (d) vcfVersion: '9.0.2', (e) contentManifestPath: './templates/manifest-9.0.2.json' (relative to Holodeck root), (f) holoRouterExternalIP: <accessible-ip-on-your-network> (e.g. 192.168.1.100 — must be routable from your workstation), (g) datastoreName: <name-of-esxi-datastore> (e.g. 'datastore1')
Configure management cluster resources. Locate the managementCluster section in config.json. Set: (a) hostCount: 4 (or 3 if your host has 48-63 cores), (b) cpuPerHost: 12, (c) memoryPerHostGb: 96. Verify total resource consumption: (hostCount cpuPerHost) + 8 (overhead) = total vCPU, and (hostCount memoryPerHostGb) + 64 (overhead) = total GB. Must not exceed 80% of physical resources.
Configure networking. Locate the network section. Set: (a) managementCIDR: '10.1.1.0/20', (b) managementVlan: 1644, (c) vlanRange: [1644, 1645, 1646, 1647, 1648], (d) holoRouterExternalIP: <your-network-accessible-IP>. Verify the VLAN range doesn't conflict with production networks. Verify the external IP is on a network you can route to.
Set passwords and credentials. Locate sections for esxiPassword, cbPassword, sddcPassword. Set strong passwords (>= 8 chars, mixed case, numbers, special chars). These will be used for nested ESXi, Cloud Builder, SDDC Manager, and vCenter access in subsequent labs. Document them securely (password manager, encrypted file, etc.).
Verify config.json completeness and syntax: $config = Get-Content ./templates/config.json | ConvertFrom-Json; Write-Host "vcfVersion: $($config.vcfVersion), Target Host: $($config.targetHost), Manifest: $($config.contentManifestPath)"
Optional: Run a dry-run validation without deploying: New-HoloDeckConfig -ConfigFile ./templates/config.json -ValidateOnly. This will check for obvious errors without allocating resources.
Validation Gate
Check: Checklist: (1) config.json is valid JSON, (2) vcfVersion = 9.0.2, (3) targetHost is reachable, (4) contentManifestPath file exists, (5) resource sizing <= 80% of physical host capacity, (6) VLAN range is clear, (7) holoRouterExternalIP is routable, (8) all passwords are set, (9) New-HoloDeckConfig -ValidateOnly passes (if supported by your Toolkit version)
Expected: All 9 items checked. Config is ready for Prepare phase in holodeck-02.
Common Errors
Task 5 Execute pre-flight checklist and create baseline snapshot
recoverabilityBefore deploying infrastructure, production operations always run a pre-flight checklist: power checks, cable verification, firmware versions, license availability, backup policies. This mirrors the VCF Planning & Preparation phase. Creating a baseline snapshot now ensures you can rollback to a known-good state if subsequent labs fail.
Document your Holodeck environment baseline. Create a file: deployment-baseline.txt with the following: (a) Physical ESXi version: esxcli system version get | grep Version, (b) Total RAM: esxcli hardware memory get | grep 'Physical Memory', (c) Total cores: esxcli hardware cpu global get, (d) Free datastore space: esxcli storage filesystem list | grep vmfs, (e) NTP status: esxcli system ntp get, (f) Holodeck Toolkit version: Get-Module Holodeck | Select-Object -ExpandProperty Version, (g) Content files checksums: Get all 5 content pack file hashes, (h) config.json content (redact passwords): Get-Content ./templates/config.json
Run final health check before Prepare: Get-HoloDeckHealth -TargetHost <esxi-ip> -TargetHostUser root. Verify all checks pass. If any check fails, remediate it before proceeding (e.g., start NTP, enable SSH).
Create a baseline snapshot of the physical ESXi host (optional but recommended): In vSphere Client, right-click the ESXi host VM (if it's a VM itself, which it isn't in production but may be in a nested lab scenario) or skip this step if it's a physical machine. If you can't snapshot the host itself, document that this is a physical machine with no pre-deployment snapshot available.
Review the pre-flight checklist below and sign off on each item. This is your contractual commitment that you've validated the environment. For each item, you should answer 'YES' with confidence. If any item is 'MAYBE' or 'NO', halt and fix it.
Execute the Holodeck Prepare phase (you are NOT running Start yet — Prepare only stages content and validates): New-HoloDeckInstance -ConfigFile ./templates/config.json -Verbose
Verify Prepare succeeded: Get-HoloDeckInstance | Format-Table -Property InstanceId, State, VcfVersion. Confirm State shows 'Prepared'.
Take a snapshot of the Holodeck state after successful Prepare: Get-VM -Name 'Holo-*' | New-Snapshot -Name 'holodeck-01-complete' -Description 'Post Prepare - content staged, HoloRouter ready, config validated' -Memory:$false
Validation Gate
Check: Checklist completed: (1) deployment-baseline.txt populated, (2) Get-HoloDeckHealth passes, (3) New-HoloDeckInstance completed successfully, (4) Get-HoloDeckInstance shows State=Prepared, (5) Snapshot 'holodeck-01-complete' exists on all Holodeck VMs
Expected: All items complete. Lab holodeck-01 is finished. You are ready for holodeck-02 (management domain deployment).
Common Errors
Final Validation
Holodeck Toolkit is installed, VCF 9.0.2 content packs are staged and verified, deployment configuration is created and validated, and a successful Prepare phase has completed. The physical ESXi host is confirmed ready for the management domain deployment (holodeck-02). A baseline snapshot is in place for rollback.
✓ Holodeck Toolkit version → 9.0.2.19, verified with Get-Module HoloDeck | Select-Object -ExpandProperty Version
✓ Physical ESXi host version → 8.0 Update 3 (build >= 22380479), verified with esxcli system version get
✓ Physical host resources → RAM >= 512 GB, Cores >= 64, Free datastore >= 2 TB, all verified
✓ Nested virtualization enabled → vHV enabled in BIOS and ESXi (vmkAllowNested, EPT/NPT supported)
✓ VCF content packs staged → 5 files in content directory (ESXi ISO, vCenter OVA, SDDC Manager OVA, Cloud Builder OVA, NSX bundle) with valid checksums
✓ Manifest file → manifest-9.0.2.json exists with all 5 components and SHA256 hashes
✓ Holodeck config.json → Valid JSON, all mandatory fields set, resources <= 80% of physical capacity, VLAN range clear
✓ Prepare phase completed → Get-HoloDeckInstance shows State: Prepared with matching VcfVersion: 9.0.2
✓ Baseline snapshot → holodeck-01-complete snapshot exists on all Holodeck VMs
Cleanup / Restore
Snapshot: holodeck-01-complete
• Snapshot has been created as 'holodeck-01-complete' on all Holodeck VMs
• Document the Instance ID from Get-HoloDeckInstance output — you'll need it for holodeck-02
• Document holoRouterExternalIP and config.json paths — they're referenced in holodeck-02
• Store deployment-baseline.txt safely — it's a reference artifact if things go wrong
Design Reflection (VCDX)
A VCDX panelist would probe: 'How did you validate that your lab infrastructure was ready before deploying VCF?' The answer should include the exact pre-flight checklist you completed (ESXi version, vHV, resources, NTP, DNS, datastore, VLAN). They will ask: 'What would you do if the physical host ran out of storage mid-deployment?' (Answer: Have a rollback plan — take snapshots, monitor datastore free space during Prepare and Start).
They will also ask: 'How does the Holodeck Toolkit installation process differ from deploying VCF in production?' (Answer: Holodeck is a PowerShell automation wrapper; in production, you'd run Cloud Builder manually or via Automation, and manage dependencies differently). Be ready to explain the assumptions you made (nested virtualization overhead, resource overhead calculations, VLAN naming scheme) and the risks (single physical host = single failure domain).
Requirements
- Physical infrastructure capable of running nested virtualization with minimum 512 GB RAM, 64 cores, 2 TB SSD/NVMe storage
- Holodeck Toolkit version 2.1.x compatible with VCF 9.0.2 content pack
- VCF 9.0.2 content packs (5 components) downloaded, staged, and checksummed
- Deployment configuration (config.json) created with resource sizing that doesn't exceed 80% of physical host capacity
- Pre-flight validation completed and baseline snapshot in place
Constraints
- Holodeck Toolkit runs only on Windows PowerShell 7.0+ or PowerShell Core on Mac/Linux
- Content pack versioning is strict — manifest mismatch with VCF version causes deployment failure
- Nested virtualization requires vHV support in CPU and BIOS (not available on older or budget hardware)
- Single physical host = single fault domain — entire lab is lost if the host fails. No HA, no redundancy.
- Network isolation via HoloRouter requires VLAN trunking and specific IP ranges (10.1.1.0/16) that may not match production network design
- Resource contention during deployment (background services, concurrent VMs) can cause timeouts or silent failures
Assumptions
- Physical ESXi host is a dedicated machine (not shared with production or other teams' labs)
- Internet connectivity is available for downloading content or offline depot is pre-staged
- Management workstation has PowerShell 7.0+, git, and SSH client installed
- Broadcom support account is active and has access to download VCF content packs
- VLAN trunking can be enabled on the ESXi port groups without impacting production networks
- Network documentation and VLAN allocation is up-to-date and shared with the lab operator
- NTP and DNS are synchronized across the lab and management networks
- Operator has root/administrative access to the physical ESXi host
Risks
- Content pack download interrupted or corrupted — IMPACT: silent deployment failure with cryptic error messages, MITIGATION: validate checksums immediately after download, implement retry loop
- config.json resource miscalculation causes resource exhaustion mid-deployment — IMPACT: cascade failures, VM crashes, full lab loss, MITIGATION: calculate resources conservatively (<=80%), monitor datastore during Prepare and Start phases
- Nested virtualization disabled in BIOS (common on new hardware) — IMPACT: deployment appears to start but nested VMs are extremely slow, MITIGATION: verify vHV in Task 1, save BIOS screenshots for reference
- Holodeck Toolkit version skew with content pack version — IMPACT: cryptic manifest errors, MITIGATION: align Toolkit version (2.1.x) with content pack (9.0.2) before starting
- Physical host clock skew or DNS failure — IMPACT: SSL certificate errors, bring-up failures in vCenter and NSX, MITIGATION: verify NTP sync and DNS resolution in pre-flight checks
- VLAN range conflict with production infrastructure — IMPACT: network routing failures, isolated nested environment, MITIGATION: document VLAN allocation and verify no conflicts with IT before deploying
Self-Assessment Discussion Prompts
- Why does the Holodeck Toolkit require a minimum of 512 GB RAM? What percentage of that is overhead (ESXi kernel, Holodeck services) vs. available for nested VMs?
- You modified config.json after a partial Prepare, and only the first nested ESXi host got the new settings. Explain what happened and how you'd fix it without re-downloading content.
- The pre-flight checklist includes NTP synchronization and DNS resolution. Why are these critical to a VCF deployment that depends on SSL certificates and time-synced services?
- Compare the content pack validation in this lab (manifest + SHA256 hashing) to how you'd validate infrastructure readiness in production VCF. What's the analog to the manifest in a physical deployment?
- You have a 48-core host (just under the 64-core minimum). How would you adjust config.json to make the deployment feasible? What functionality or capacity would you sacrifice?
- If the Prepare phase fails midway through, can you resume it, or do you need to start over? What's the difference between a transient failure (network timeout) and a permanent one (corrupted ISO)?
Extensions
Automate Content Pack Download and Validation
Write a PowerShell script that downloads VCF 9.0.2 content packs from Broadcom support portal (via API if available, or scraping), validates checksums, and generates the manifest.json automatically. This mirrors CI/CD practices for infrastructure-as-code and prepares you for production automation discussions.
harderDeploy Holodeck on a vSAN Cluster Instead of Single Host
Modify config.json to deploy Holodeck across a 4-node vSAN cluster (one nested Holodeck instance per node, or shared vSAN datastore). Document the differences in resource contention, network isolation, and recoverability compared to single-host deployment.
harderCreate a Multi-Version Content Manifest
Stage both VCF 9.0.2 and VCF 5.2.x content packs. Create two manifests (manifest-9.0.2.json and manifest-5.2.x.json) and document version-specific differences (component names, sizing, licensing). This prepares you for discussing upgrade paths and version coexistence.
sameImplement Content Pack Caching on a Network Share
Instead of storing content on the local ESXi datastore, configure a network-based cache (NFS share or SMB share) to store VCF content packs. Modify config.json to reference the network path. Measure deployment performance (Prepare time) with network-based vs. datastore-based content. This exercises VCDX-level infrastructure optimization thinking.
harder⚠ Known Pitfalls (from Community KB)
References
- VMware Cloud Foundation 9.0 Planning and Preparation GuideTier 1 — Official
Broadcom official documentation. Essential for understanding hardware requirements, network planning, and pre-deployment checklist. Tier 1 authority. - Holodeck Toolkit GitHub RepositoryTier 1 — Official
Official Holodeck source. Includes PowerShell module, templates, examples, and issue tracker with 15+ open issues. Clone this repo to get the latest Toolkit version. - Broadcom Support Portal — VCF 9.0.2 DownloadsTier 1 — Official
Official download source for VCF content packs, ISOs, OVAs, and NSX bundles. Requires Broadcom support account. All content is cryptographically signed. - VCF Holodeck Community ForumTier 1 — Official
Broadcom-hosted community forum with 63 threads captured in our Holodeck KB (holodeck-kb-normalized.json). Primary source for troubleshooting deployment failures. - William Lam — VCF Nested Lab Deployment GuideTier 3 — Expert Blog
William Lam is a VMware Staff Engineer and authoritative community voice. His blog covers Holodeck setup, nested VCF deployment best practices, and automation techniques.