Academy/VCDX Defense Preparation/Lab C4: Design Scenario — Sovereign Cloud Provider (Saudi Arabia PIF Style)
This lab targets VCF 9.0

Lab C4: Design Scenario — Sovereign Cloud Provider (Saudi Arabia PIF Style)

VCF 9.0Intermediatevcdx-distinguished⏱ 90 min

Objectives

  • Design a multi-tenant VCF 9.0 sovereign cloud with HCX-based onboarding.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for VCDX Defense Preparation

Tasks

Task 1 Lab C4: Design Scenario — Sovereign Cloud Provider (Saudi Arabia PIF Style)

Design a multi-tenant VCF 9.0 sovereign cloud with HCX-based onboarding.

Step 1

Design Instance/Fleet topology for 5 customer tenants with hard isolation.

Step 2

Choose tenancy model: Private Cloud per tenant vs shared infra with DFW isolation.

Step 3

Design HCX service mesh for mass onboarding with RAV migration at scale.

Step 4

Design VCF Automation catalog for tenant self-service with governance.

Step 5

Write a cost model: CapEx + OpEx for 5 tenants over 3 years.

Step 6

Draft SLA: 99.95% per tenant; define RTO/RPO and DR strategy.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

Sovereign cloud design without data residency controls
Fix: Saudi Arabia (and UAE, EU, etc.) have data sovereignty requirements: certain data categories must remain within the country's borders. Design must include: workload placement policies (DRS rules preventing cross-border vMotion), network controls (DFW rules preventing data egress), and audit trails proving data residency compliance.
Multi-tenant isolation relying solely on RBAC without network segmentation
Fix: RBAC controls WHO can access resources but doesn't prevent network-level data leakage between tenants. Sovereign cloud designs need: NSX VPC per tenant (network isolation), vSAN per-VM encryption with per-tenant keys (storage isolation), AND RBAC (administrative isolation). All three layers are required.
Not addressing data classification in the design
Fix: Sovereign cloud designs must classify data: public (can leave the country), internal (must stay within country but not restricted), restricted (must stay within specific infrastructure with audit). Each classification maps to different storage, network, and encryption policies in the design.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Sovereign cloud design demonstrates awareness of geopolitical and regulatory constraints beyond technology. VCDX panelists test data residency, multi-tenant isolation, and how you ensure compliance at the infrastructure level.

⚠ Known Pitfalls (from Community KB)

Designing multi-tenancy with RBAC alone — network and storage isolation are equally important.
Not addressing data classification — sovereign cloud without data classification has no enforcement framework.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.