Holodeck Environment Discovery Playbook
Objectives
- Systematically discover all components of an existing Holodeck VCF deployment using a 4-phase methodology
- Use Holodeck Toolkit cmdlets to query network, DNS, IP pools, and BGP configuration
- Authenticate to SDDC Manager API, vCenter REST API, and NSX Manager API
- Map the complete vCenter object hierarchy (datacenters, folders, hosts, VMs, datastores)
- Document deployment architecture for team handoff or VCDX design validation
Prerequisites
Access to an existing Holodeck VCF lab environment (shared or inherited) with all management domain components running (SDDC Manager, vCenter, NSX Manager)
Required skills:
- PowerShell Core 7.x fundamentals
- REST API authentication (Basic auth, Bearer tokens)
- Basic understanding of VCF SDDC Manager, vCenter, and NSX
- kubectl CLI basics for Kubernetes pod management
Lab Environment
Existing Holodeck VCF lab (management + workload domains deployed). Read-only discovery — no modifications. HoloRouter (10.1.1.1) provides DNS, DHCP, BGP routing as K8s pods. Standard Holodeck NAT: 10.1.x.x (management) and 172.16.x.x (overlay). DNS resolution issues with FQDNs in PowerShell — use IP addresses for all API calls. Holodeck Toolkit cmdlets require Import-HoloDeckConfig before querying.
Credentials
| System | Username | Password |
|---|---|---|
| HoloRouter SSH | root | VMware123! |
| SDDC Manager API | administrator@vsphere.local | Master password doubled: VMware123!VMware123! |
| vCenter REST API | administrator@vsphere.local | Master password doubled: VMware123!VMware123! |
| NSX Manager API | admin | Master password doubled: VMware123!VMware123! |
| ESXi hosts | root | Master password doubled: VMware123!VMware123! |
Tasks
Task 1 Phase 1: HoloRouter Discovery
SSH into HoloRouter — Connect to the HoloRouter VM via SSH. Default credentials: root / VMware123!
ssh root@10.1.1.1Query Kubernetes Pods — HoloRouter runs Kubernetes internally. List all pods across all namespaces to discover core services (SDDC Manager, vCenter, NSX Manager, dnsmasq, etc.).
kubectl get pods -AExamine HoloRouter Startup Configuration — Review the startup script to understand how HoloRouter provisions the lab environment, including which versions of VCF, NSX, and ESXi are deployed.
cat /holodeck-runtime/startup_script.sh | head -100Inspect DNS Configuration — Check the HoloRouter's DNS resolver configuration to understand how components find each other by FQDN.
cat /etc/resolv.confValidation Gate
✓ Successfully SSH'd into HoloRouter (10.1.1.1)
✓ Identified at least 5 major pods (sddc-manager, vcenter, nsx-manager, dnsmasq-dns, etc.)
✓ Located and reviewed /holodeck-runtime/startup_script.sh
✓ Confirmed DNS resolver pointing to dnsmasq-dns service
✓ Documented HoloRouter IP and kubectl availability
Task 2 Phase 2: Holodeck Toolkit Discovery
Import Holodeck Toolkit Module — Load the Holodeck Toolkit PowerShell module. This module is pre-installed on the HoloRouter or available via PowerShell Gallery.
Import-Module HoloDeckToolkit -Force; Get-Module HoloDeckToolkitQuery Holodeck Config — Get the Holodeck configuration metadata. This tells you the instance ID and config file location.
Get-HoloDeckConfigImport Holodeck Configuration — CRITICAL STEP: Import the Holodeck config using the ConfigID from step 2. All subsequent queries depend on this import.
$ConfigID = (Get-HoloDeckConfig).ConfigID; Import-HoloDeckConfig -ConfigID $ConfigIDRetrieve Holodeck Instance Details — Get detailed information about the Holodeck instance, including deployment topology and component versions.
$InstanceID = (Get-HoloDeckConfig).InstanceID; Get-HoloDeckInstance -InstanceID $InstanceIDQuery Management Network Topology — Discover the management network(s): gateway, VLAN, subnet, and reserved IP ranges.
Get-HoloDeckSubnetQuery Application Network Configuration — Get application-level network configuration: segments, IP pools for workload VMs.
Get-HoloDeckAppNetworkQuery BGP Configuration — Discover Border Gateway Protocol settings for NSX edge connectivity and multi-site scenarios.
Get-HoloDeckBGPConfigQuery Overlay Network Subnets — Discover NSX overlay network subnets and VNI assignments.
Get-HoloDeckOverlaySubnetQuery Service IP Pools — Get IP pool assignments for NSX services (NAT, DHCP, DNS relay, etc.).
Get-HoloDeckAppIpPoolsExamine Runtime Configuration Files — Inspect the on-disk configuration files to verify cmdlet output and discover additional metadata.
ls -la /holodeck-runtime/config/Review Configuration JSON — Parse the configuration JSON to extract detailed networking, credentials, and topology.
cat /holodeck-runtime/config/config.json | jq '.network' | head -50Examine Network YAML Specification — Review the network YAML file for high-level topology overview.
cat /holodeck-runtime/config/network.yamlReview Specifications File — Check the specs.yaml file for a human-friendly summary of deployment configuration.
cat /holodeck-runtime/config/specs.yamlValidation Gate
✓ Successfully imported HoloDeck Toolkit module
✓ Ran Get-HoloDeckConfig and captured ConfigID and InstanceID
✓ Imported config with Import-HoloDeckConfig
✓ Queried and documented all Holodeck cmdlets: Instance, Subnet, AppNetwork, BGP, Overlay, AppIpPools
✓ Reviewed runtime config files: config.json, network.yaml, specs.yaml
✓ Created a table with at least: Management subnets, Overlay subnets, App networks, BGP settings, Service IP pools
Task 3 Phase 3: VCF API Discovery
Prepare Authentication Payload — Create a PowerShell hashtable with the correct SDDC Manager credentials. CRITICAL: The password must be DOUBLED (e.g., 'VMware123!VMware123!').
$sddc_ip = '10.1.1.5'; $username = 'administrator@vsphere.local'; $password = 'VMware123!VMware123!'; $body = @{ username = $username; password = $password } | ConvertTo-Json; Write-Host $bodyAuthenticate and Get Bearer Token — POST to /v1/tokens endpoint to obtain a bearer token for subsequent API calls.
$response = Invoke-RestMethod -Uri "https://$sddc_ip/v1/tokens" -Method Post -Body $body -ContentType 'application/json' -SkipCertificateCheck; $token = $response.accessToken; Write-Host "Token: $token"Create Authorization Header — Build the Authorization header for all subsequent API calls using the bearer token.
$headers = @{ Authorization = "Bearer $token" }Query System Information — Get high-level VCF system information: version, build, deployment status, etc.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/system" -Headers $headers -SkipCertificateCheck | ConvertTo-JsonQuery SDDC Manager Instances — Discover all SDDC Manager nodes in the deployment (HA cluster).
Invoke-RestMethod -Uri "https://$sddc_ip/v1/sddc-managers" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query VCF Domains — Get all VCF domains (workload domains and management domain).
Invoke-RestMethod -Uri "https://$sddc_ip/v1/domains" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Clusters Per Domain — Discover all clusters within each domain.
$domains = Invoke-RestMethod -Uri "https://$sddc_ip/v1/domains" -Headers $headers -SkipCertificateCheck; $domains | ForEach-Object { Invoke-RestMethod -Uri "https://$sddc_ip/v1/domains/$($_.id)/clusters" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10 }Query Hosts — Discover all ESXi hosts across all clusters.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/hosts" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10 | head -200Query vCenter Instances — Discover all vCenter instances managed by SDDC Manager.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/vcenters" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query NSX Clusters — Discover NSX Manager clusters and their managers.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/nsxt-clusters" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Network Pools — Discover IP pools available for new workload domains or clusters.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/network-pools" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Credentials — Discover stored credentials used by VCF (vCenter, NSX, host passwords, etc.).
Invoke-RestMethod -Uri "https://$sddc_ip/v1/credentials" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query DNS Configuration — Discover DNS settings for the VCF system and NSX.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/system/dns-configuration" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query NTP Configuration — Discover NTP (time sync) servers used by VCF.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/system/ntp-configuration" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Task History — Review recent VCF tasks (domain creations, host commissions, etc.) to understand deployment timeline.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/tasks?filter=status%3DSUCCESSFUL" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10 | head -100Query Backup Configurations — Discover backup settings and schedules.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/backup-configurations" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Bundle Information — Discover installed software bundles and their versions.
Invoke-RestMethod -Uri "https://$sddc_ip/v1/bundles" -Headers $headers -SkipCertificateCheck | ConvertTo-Json -Depth 10Validation Gate
✓ Successfully authenticated to SDDC Manager API (10.1.1.5)
✓ Obtained bearer token with doubled password (VMware123!VMware123!)
✓ Queried and documented: System, SDDC Managers, Domains, Clusters, Hosts, vCenters, NSX Clusters
✓ Queried and documented: Network Pools, Credentials, DNS, NTP, Tasks, Backups, Bundles
✓ Created a VCF deployment architecture diagram: domains → clusters → hosts
✓ Noted any failed tasks in task history
✓ Confirmed FQDN of SDDC Manager as 'sddcmanager-a' (no hyphen)
Task 4 Phase 4: vCenter and NSX Deep Dive
Prepare vCenter Authentication — Create authentication header for vCenter REST API. Use Basic auth with doubled password.
$vcenter_ip = '10.1.1.6'; $username = 'administrator@vsphere.local'; $password = 'VMware123!VMware123!'; $auth = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes("$username`:$password")); $headers_vc = @{ Authorization = "Basic $auth"; Accept = 'application/json' }Authenticate to vCenter and Get Session ID — POST to /api/session to create a vCenter session and obtain a session ID.
$session_response = Invoke-RestMethod -Uri "https://$vcenter_ip/api/session" -Method Post -Headers $headers_vc -SkipCertificateCheck; $session_id = $session_response; Write-Host "Session ID: $session_id"Create vCenter API Header with Session — Build header for subsequent vCenter API calls using the session ID.
$headers_vc_session = @{ 'vmware-api-session-id' = $session_id }Query Datacenters — Discover all datacenters in the vCenter hierarchy.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/datacenter" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Folders — Discover the folder hierarchy (resource organization).
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/folder" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Hosts — Discover all ESXi hosts visible in vCenter.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/host" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Resource Pools — Discover resource pools for VM placement and resource limits.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/resource-pool" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Datastores — Discover all datastores (storage) in vCenter.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/datastore" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query Virtual Machines — Discover all VMs in the vCenter inventory.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/vm" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10 | head -100Query Networks — Discover vSphere networks (port groups, virtual switches).
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/network" -Headers $headers_vc_session -SkipCertificateCheck | ConvertTo-Json -Depth 10Query vSAN Health (if available) — Check vSAN cluster health. Note: This endpoint may not be available in vCenter 8.0.3.
Invoke-RestMethod -Uri "https://$vcenter_ip/api/vcenter/vsan/clusters" -Headers $headers_vc_session -SkipCertificateCheck -ErrorAction SilentlyContinue | ConvertTo-Json -Depth 10Prepare NSX Authentication — Create Basic auth header for NSX Manager API. Use doubled password.
$nsx_ip = '10.1.1.7'; $username = 'admin'; $password = 'VMware123!VMware123!'; $auth_nsx = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes("$username`:$password")); $headers_nsx = @{ Authorization = "Basic $auth_nsx"; Accept = 'application/json' }Query NSX Transport Zones — Discover NSX transport zones (overlay and VLAN transport zones).
Invoke-RestMethod -Uri "https://$nsx_ip/api/v1/transport-zones" -Headers $headers_nsx -SkipCertificateCheck | ConvertTo-Json -Depth 10Query NSX Transport Node Profiles — Discover transport node profiles (configuration templates for hosts).
Invoke-RestMethod -Uri "https://$nsx_ip/policy/api/v1/infra/sites/default/enforcement-points/default/transport-node-profiles" -Headers $headers_nsx -SkipCertificateCheck | ConvertTo-Json -Depth 10Query NSX Segments — Discover logical segments (NSX L2/L3 networks).
Invoke-RestMethod -Uri "https://$nsx_ip/policy/api/v1/infra/segments" -Headers $headers_nsx -SkipCertificateCheck | ConvertTo-Json -Depth 10 | head -100Query DNS Zone Records — Extract all pre-provisioned DNS records from dnsmasq pod. This reveals the FQDN and IP mapping for all components.
kubectl exec -n kube-system -it dnsmasq-dns-pod -- cat /etc/hosts | head -50Compile Final Inventory Documentation — Aggregate all discovery data into a comprehensive inventory document or spreadsheet.
# Create summary tables (pseudocode — adapt to your format):
# 1. Components table: FQDN, IP, type (SDDC Manager, vCenter, NSX), status, version
# 2. Hosts table: FQDN, IP, cluster, vSAN status, power state
# 3. Networks table: Name, type (management, overlay, app), subnet, gateway
# 4. Datastores table: Name, type, capacity, free space, usage %
# 5. Key credentials: username, type (administrator, service), last rotated, expiry
# 6. DNS zones: all ~160 records extracted from /etc/hostsValidation Gate
✓ Successfully authenticated to vCenter REST API (10.1.1.6) with doubled password
✓ Successfully authenticated to NSX Manager API (10.1.1.7) with doubled password
✓ Queried and documented: Datacenters, Folders, Hosts, Resource Pools, Datastores, VMs, Networks
✓ Queried and documented: NSX Transport Zones, Transport Node Profiles, Segments
✓ Extracted DNS zone records from dnsmasq pod (confirmed ~160 pre-provisioned records)
✓ Compiled comprehensive inventory document with all components, networks, credentials, and FQDNs
✓ Verified that all IPs and FQDNs from Phases 1-3 appear in vCenter and NSX queries
Final Validation
Comprehensive Holodeck VCF Environment Inventory Document
Components & Infrastructure
• All component FQDNs (sddcmanager-a, vcenter, nsx-manager, holodeck-holomaster, mgmt-esx-01, etc.) with corresponding IP addresses
• SDDC Manager nodes: hostname, primaryIp, version, status
• vCenter instances: FQDN, primaryIp, version, managed domains
• NSX Manager cluster: node count, manager IPs, version, status
VCF Domains & Clusters
• Domain inventory: Management domain (MGMT) and all workload domains (WLD-01, etc.) with cluster counts
• Cluster inventory per domain: cluster name, type (management/workload/edge), host count, cluster status
• All ESXi hosts: hostname, IP, cluster membership, CPU/memory specs, vSAN participation status
Network Topology
• Management networks: subnets, VLANs, gateways (e.g., 10.1.1.0/24, 10.1.2.0/24, etc.)
• Overlay networks: VLAN range, VNI pool, encapsulation type
• Application networks: segment names, CIDR blocks, DHCP/Static pools, isolation level
• BGP configuration: AS number, router ID, neighbors, route leaking policies
Storage & Compute
• Datastores: name, type (vSAN/VMFS/NFS), capacity, free space, usage percentage
• vSAN configuration: disk groups, capacity tier, license level, health status
• Resource pools per cluster: name, CPU allocation, memory allocation, shares
• vCenter inventory count: total VMs, powered-on count, templates, system VMs
Credentials & Security
• All credential types managed by VCF: service accounts (vCenter, NSX, SDDC Manager, ESXi), their last rotation date, and expiry status
• Master password status (note: Holodeck default is VMware123!VMware123! — doubled)
• Certificate status: SDDC Manager, vCenter, NSX Manager SSL certificates and expiry dates
• Permissions audit: administrator accounts, service account roles
System Configuration
• DNS servers and search domains configured in VCF
• NTP servers and time sync status
• Backup configurations: enabled/disabled, frequency, retention policy
• Syslog configuration: syslog servers, log levels
Deployment Timeline & History
• VCF deployment date (extracted from task history)
• Recent major tasks (domain creations, host commissions) with timestamps and status
• Any failed tasks with error messages
• Last system update/patch date
DNS Zone Map
• All ~160 DNS records from /etc/hosts in dnsmasq pod, organized by component type
• Naming convention analysis: IP scheme (10.1.x.x patterns), FQDN patterns (e.g., mgmt-esx-01.mgmt.local, nsx-manager.nsx.local, etc.)
✓ Document is comprehensive and machine-readable (markdown, spreadsheet, or JSON format acceptable)
✓ All component FQDNs and IPs are cross-referenced: SDDC Manager API ↔ vCenter API ↔ NSX API ↔ DNS records should all align
✓ All 4 discovery phases are represented in the document
✓ No contradictions in IP assignments or FQDN resolution
✓ Document is suitable for team handoff or VCDX design panel review
Cleanup / Restore
No cleanup needed — this is a read-only discovery exercise. All queries are informational; no VCF, vCenter, or NSX configurations were modified.
Design Reflection (VCDX)
A VCDX panelist might ask: 'You inherited this VCF environment — walk me through how you assessed its current state before proposing changes.' This lab builds exactly that skill — systematic discovery without assumptions. By the end, you've documented every component, network, and credential. You know the deployment version, topology, and health status. You can confidently brief a team on what you found and propose improvements based on observed state, not speculation.
Self-Assessment Discussion Prompts
- How would you verify the health of a VCF environment you didn't deploy? What would you look for first?
- What risks exist when inheriting a VCF environment where credentials have been rotated and you don't have the new passwords?
- How does the discovery methodology differ between production VCF and nested Holodeck? What assumptions can you make about Holodeck that might not apply to production?
- If you discovered that DNS records in /etc/hosts are inconsistent with vCenter's registered FQDNs, what would be your troubleshooting approach?
- How would you use the Holodeck Toolkit cmdlets as a starting point to build a self-service discovery tool for your team?
References
- Vcf Api DocsTier 1 — Official
- Vcenter Rest ApiTier 1 — Official
- Nsx Policy ApiTier 1 — Official
- Holodeck ToolkitTier 1 — Official
- Vcf Security HardeningTier 1 — Official