Compute Core Concepts — ESXi Host Architecture
Objectives
- Describe ESXi host architecture, security features, and boot bank layout
- List hardware requirements for ESX 9.0 and vSAN
- Perform ESXi host preparation for VCF (network, certificates, NTP)
- Explain vCenter Appliance architecture and the vpxd→vpxa→hostd communication chain
- Describe vCenter SSO and Enhanced Linked Mode (up to 15 vCenter instances)
- Differentiate VSS from VDS and explain NIOC
- Identify snapshot types by datastore (VMFSsparse, SEsparse, vsanSparse)
- Explain vMotion including vGPU migration (up to 60 Gbps)
- Describe vSphere Lifecycle Manager image-based management in 9.0
Prerequisites
Active Holodeck VCF 9.0 lab or access to VCF documentation
Required skills:
- Basic VMware terminology
Tasks
Task 1 ESXi Host Architecture & Configuration
Understand ESXi architecture, HW requirements, and VCF-specific host preparation
ESX is a bare-metal hypervisor. Security features: host-based firewall, memory hardening, kernel module integrity, TPM 2.0, UEFI secure boot, encrypted core dumps. Boot bank layout: /bootbank, /altbootbank (dual-bank for patching), /productLocker (VMware Tools ISOs), /var/core (core dumps). Small disk footprint with quick boot for faster patching.
ESX 9.0 minimum requirements: supported server platform (check VMware Compatibility Guide), 2+ CPU cores, 8GB RAM (12GB production recommended), 1+ GbE NIC, 32GB persistent boot disk. For vSAN: disks and controllers must be compatible per VMware Compatibility Guide. Memory Tiering: PCIe NVMe devices can serve as second memory layer for more in-memory computing.
[HOLODECK NOTE] In Holodeck, ESXi runs as nested VMs on a physical host. Hardware compatibility checks (VMware Compatibility Guide) do not apply — nested ESXi uses virtual hardware. CPU features are passed through from the physical host. Memory is allocated from the physical host's RAM pool — plan 64GB+ physical RAM for a minimal VCF deployment in Holodeck.
For management domain: interactive ESX installation on all hosts. Post-install config via DCUI and Host Client: (1) Management network — adapter selection, VLAN ID, IPv4/IPv6, hostname, DNS; (2) VM Network port group — set VLAN ID on vSS for Cloud Builder connectivity; (3) Certificate regeneration — run /sbin/generate-certificates then restart hostd/vpxa/rhttpproxy; (4) NTP configuration (UDP 123) or PTP (UDP 319/320 for microsecond accuracy). Ensure no Custom DNS Suffixes defined.
ESX firewall activated by default — blocks all except enabled services. SSH and Shell managed by admin users. Lockdown mode: host accessible only via DCUI or through vCenter (no direct remote login). Services management: START/STOP/RESTART, startup policy (manual, start with host, start/stop with port usage).
Validation Gate
Check: Verify ESXi host is VCF-ready: FQDN matches DNS (forward + reverse), certificates regenerated, NTP synchronized, no Custom DNS Suffix
Expected: All four checks pass. Host is ready for Cloud Builder commissioning.
Common Errors
Task 2 vCenter Architecture & Management
Understand vCenter Appliance architecture, services, and SSO
vCenter Appliance = prepackaged Linux VM: Photon OS + PostgreSQL database + vCenter services. All services on single VM. Services include: vCenter, vSphere Client, Authentication Services, License service, Content Library, vSphere Lifecycle Manager. Deploy on existing ESX host, select appliance size for environment + storage size for DB.
Communication chain: vSphere Client → vpxd (vCenter) → vpxa (host agent, auto-started when host added) → hostd (host daemon). hostd manages all local operations: VM creation, power state, storage visibility. Direct host access (bypassing vCenter) communicates with hostd directly via VMware Host Client.
SSO provides centralized authentication: identity sources (AD, LDAP, local OS), security tokens, site/domain concepts. Enhanced Linked Mode: up to 15 vCenter instances in single SSO domain for unified inventory, role management, and search across data centers. IMPORTANT: Enhanced Linked Mode (ELM) is DEPRECATED in vCenter 9.0 and will be removed in a future release. ELM is still supported in VCF 9.0 only to allow smooth upgrades of existing deployments. New deployments should use VCF Operations Fleet Management for multi-instance management instead of ELM.
Validation Gate
Check: Trace a VM power-on request from vSphere Client through vpxd, vpxa, and hostd
Expected: vSphere Client → vpxd (vCenter service, validates permissions, updates DB) → vpxa (host agent on target ESXi, receives task) → hostd (executes power-on, updates VM state) → status propagates back up the chain
Common Errors
Task 3 vSphere Networking, VMs & Clusters
Cover networking constructs, VM operations, and cluster capabilities
VSS (Standard Switch): per-host, manual config. VDS (Distributed Switch): centrally managed across hosts, supports port groups spanning hosts, NetFlow, port mirroring, LACP. VMkernel adapters for: management, vMotion, vSAN, fault tolerance logging, provisioning traffic. NIC teaming: load-based, source port ID, source MAC hash, explicit failover. Network I/O Control (NIOC): bandwidth shares and reservations per traffic type.
[HOLODECK NOTE] Holodeck uses virtual switches on the physical host to provide connectivity to nested ESXi. VDS in nested ESXi connects to virtual port groups on the physical host's vSwitch. NIC teaming policies in nested ESXi operate on virtual NICs — failover and load balancing behavior differs from physical multi-NIC configurations. NIOC bandwidth reservations have no real effect in nested environments.
VM files: .vmx (config), .vmdk (disk descriptor), -flat.vmdk (data), .nvram (BIOS/EFI), .vmsd (snapshot list), .vmsn (snapshot state), .vmem (memory state). Snapshot types by datastore: VMFSsparse (VMFS5 <2TB, 512-byte blocks), SEsparse (VMFS6, 4KB blocks, space-efficient with unmap), vsanSparse (vSAN ESA, delta objects, 4MB blocks). CBT (Changed Block Tracking): VMkernel feature for incremental backups — tracks changed blocks, reduces restore time.
Cluster: up to 96 ESX hosts (64 with vSAN). DRS: automated load balancing. HA: host monitoring, admission control, VM restart on failure. vMotion: live migration with zero downtime. vGPU vMotion: multi-parallel TCP connections up to 60 Gbps (6x faster), zero-copy technique, precopy for minimal downtime. EVC (Enhanced vMotion Compatibility): CPU feature masking for heterogeneous clusters. Migration types: compute only, storage only, both, cross-vCenter export.
[HOLODECK NOTE] In Holodeck's nested environment: vMotion works but bandwidth is limited by virtual NIC throughput, not physical 25GbE. The 60 Gbps vGPU vMotion figure applies to bare-metal with dedicated NICs — Holodeck nested NICs will not approach this. vSAN cluster limits (64 hosts) are theoretical — Holodeck typically runs 3-4 nested hosts due to RAM constraints.
Content libraries: local (admin-controlled), published (available for subscription), subscribed (sync from publisher). Templates stored as OVF or VM templates. vSphere 9.0: library migration to new datastore supported. vSphere Lifecycle Manager: image-based management (no more baselines in 9.0), desired state model — cluster image includes base ESXi + vendor add-on + components + firmware.
Validation Gate
Check: Name the snapshot type for each datastore: VMFS5, VMFS6, vSAN ESA
Expected: VMFS5 (<2TB): VMFSsparse (512-byte blocks). VMFS6: SEsparse (4KB blocks, space-efficient with UNMAP). vSAN ESA: vsanSparse (4MB blocks, delta objects within vSAN object model).
Common Errors
Design Reflection (VCDX)
Compute architecture forms the foundation of every VCF design. VCDX panelists test whether you understand ESXi host sizing, cluster limits, and lifecycle management. The shift to image-based management in vSphere 9.0 is a frequent discussion point.
Requirements
- Understand ESXi architecture, security features, and VCF preparation
- Master vCenter communication chain for troubleshooting
- Know cluster limits, migration types, and snapshot behavior
Constraints
- ESXi 9.0 requires image-based lifecycle management (no baselines)
- ELM deprecated — use Fleet Management for multi-instance
- Cluster limit: 96 hosts (64 with vSAN)
Assumptions
- Hardware meets VMware Compatibility Guide requirements
- NTP, DNS, and certificates are configured correctly before bring-up
Risks
- Snapshot chain growth causing I/O performance degradation
- Certificate mismatch blocking host commissioning
- Confusing nested lab performance with production benchmarks
⚠ Known Pitfalls (from Community KB)
References
- ESXi 9.0 Installation and Setup GuideTier 1 — Official
- vSphere Lifecycle Manager Image-Based ManagementTier 1 — Official