Academy/VCAP — VCF Automation (3V0-21.25)/Lab: Build Complete GitOps Pipeline for VCF Automation
This lab targets VCF 9.0

Lab: Build Complete GitOps Pipeline for VCF Automation

VCF 9.0Intermediatevcap-advanced⏱ 135 min

Objectives

  • Create end-to-end GitOps: Git repo with cloud templates + Terraform, GitHub Actions CI/CD with validation + testing, Terraform Cloud remote state, auto-deploy to dev.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Advanced VCF 9.0 Automation

Tasks

Task 1 Lab: Build Complete GitOps Pipeline for VCF Automation

Create end-to-end GitOps: Git repo with cloud templates + Terraform, GitHub Actions CI/CD with validation + testing, Terraform Cloud remote state, auto-deploy to dev.

Step 1

Create GitHub repo with directory structure: cloud-templates/, terraform/, abx-actions/

Step 2

Add GitHub Actions workflow: validate YAML, tflint, checkov, run unit tests

Step 3

Set up Terraform Cloud organization and connect to GitHub repo

Step 4

Create Terraform module for org, project, cloud template

Step 5

Store VCF API token in Terraform Cloud Sensitive Variables

Step 6

Configure S3 remote backend with DynamoDB locking

Step 7

Create feature branch, modify template, submit PR

Step 8

Verify CI/CD runs validation, Terraform plan shows changes

Step 9

Merge PR, auto-deploy to dev org via terraform apply

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

GitOps pipeline without branch protection
Fix: Cloud Templates stored in Git should use branch protection: main branch requires PR review, direct commits blocked. Without this, a developer can push a broken template directly to production catalog. Use feature branches → PR review → merge to main → auto-sync to VCF Automation.
Not versioning Cloud Templates
Fix: VCF Automation supports template versioning. Always create a new version for changes rather than editing the current version. This enables rollback if a template change causes deployment failures. Version numbering should follow semver (major.minor.patch).
Missing CI/CD validation for template changes
Fix: Template YAML validation should run automatically in CI/CD pipeline before merge. Syntax errors, missing required inputs, and invalid resource references should be caught before the template reaches the catalog.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

GitOps for infrastructure demonstrates modern operational practices. VCDX designs that include IaC pipelines score higher on manageability.

⚠ Known Pitfalls (from Community KB)

Pushing template changes directly to main without review — one syntax error breaks the entire catalog.
Not validating templates in CI/CD — broken templates reach production catalog.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.