Academy/VCF 9.0 Support (2V0-15.25)/VCF Operations Console — Monitoring Storage, Compute & Security
This lab targets VCF 9.0

VCF Operations Console — Monitoring Storage, Compute & Security

VCF 9.0Intermediatesupportadmin⏱ 75 min

VCFFTS9 course content — VCF 9.0 focused

Objectives

  • Navigate VCF Operations console (Launchpad, Inventory Tree, Navigation Pane)
  • Describe VCF Identity Broker and supported identity providers
  • Explain centralized certificate and password management in VCF 9.0
  • Use unified tag management across vCenter and NSX
  • Monitor compute, storage, GPU, and security health
  • Use Log Assist to generate and transfer diagnostic bundles to support

Prerequisites

Active Holodeck VCF 9.0 lab or access to VCF documentation

Required skills:

  • Basic VMware terminology

Tasks

Task 1 VCF Operations Console Navigation & Fleet Management

VCF Operations Console provides a unified view across storage, compute, and security health. Understanding which metrics and alerts matter for proactive operations — and which are noise — is essential for Day-2 operational maturity.

Navigate VCF Operations and understand fleet management capabilities

Step 1
VCF Operations Console Overview

Central management interface for: licensing, identity providers, vCenter groups, health monitoring, events/logs, tag management, lifecycle management, configuration drift. Navigation: Launchpad (quick-start tiles), Inventory Tree (hierarchical view of vCenter instances), left navigation pane for all features.

[HOLODECK NOTE] VCF Operations in Holodeck monitors nested ESXi hosts and virtual infrastructure. Health metrics (CPU, memory, storage) reflect nested VM resource usage, not physical host health. Alert thresholds may trigger differently due to resource contention on the physical host. Log Assist can generate bundles but uploading to Broadcom support portal requires internet connectivity from the VCF Operations appliance.

Step 2
Fleet Management Capabilities

Unified operations experience spanning: (1) Identity & Access — VCF Identity Broker replaces vIDM, embedded (on vCenter) or external appliance cluster, supports AD FS/Entra ID/Ping Identity/Okta/AD over LDAP/SAML 2.0/OIDC; (2) Certificate Management — centralized, auto-renewal with Microsoft CA or VMCA, one-click Renew Now, nondisruptive replacement; (3) Password Management — centralized, service accounts auto-provisioned (eliminates manual password management), Update/Remediate operations; (4) Unified Tag Management — 6000 categories + 8000 tags per vCenter, 90000 categories + 120000 tags in VCF Ops.

Step 3
Lifecycle Management & Config Drift

LCM: software upgrades managed through fleet management UI. Sequential upgrade process for VCF components. Configuration drift: detect and remediate configuration variants across fleet components. Ensures consistent configuration and policies across the environment.

Step 4
Certificate Management Deep Dive

Certificate management in VCF Operations covers 5 exam-relevant areas: (1) Certificate replacement — replace expiring or compromised certificates for vCenter, NSX, SDDC Manager via VCF Operations console; (2) Auto-renewal — VCF Operations can automatically renew certificates before expiry when configured with an internal CA; (3) Certificate Authority configuration — configure Microsoft Active Directory Certificate Services CA or VMCA (VMware Certificate Authority) as the signing authority; (4) External certificate import — import third-party CA-signed certificates using the import certificate functionality; (5) CSR generation — generate Certificate Signing Requests from VCF Operations for submission to external CAs. Troubleshooting focus: expired certificates cause service communication failures (vpxd, NSX Manager API, SDDC Manager); certificate trust chain issues prevent SSO authentication; time skew between hosts and CA causes validation failures. VCF 9.0 also introduces signed certificates for ESX hosts (previously self-signed only), supporting strict compliance environments. Certificate management integrates with VCF Operations alerts for proactive expiry notifications.

Step 5
Password Management & Identity Broker Detail

VCF Operations centralizes password management: centralized password management with auto-provisioned service accounts for intercomponent communication (eliminating manual password management for interservice accounts), password update and remediation operations, password complexity policy enforcement, and timely alerts when passwords approach expiration. Password operations: Update Password (reset forgotten passwords via UI) and Remediate Password (synchronize passwords changed outside VCF). vCenter solution accounts are replaced with managed service accounts — VCF Operations auto-provisions these, eliminating manual service account password management. Identity Broker replaces legacy vIDM — supports modern IdPs: Okta (OIDC/SAML), Microsoft AD FS (OIDC/SAML), Microsoft Entra ID, Ping Identity, and directory-based AD/LDAP and OpenLDAP. User provisioning via SCIM, JIT (Just-In-Time), or AD/LDAP sync. Troubleshooting focus: IdP connectivity failures (firewall, DNS), SAML assertion mismatches (clock skew, audience URI), LDAP bind failures (credentials, base DN, search filter), and certificate trust between Identity Broker and IdP.

Validation Gate

Check: Name three vSAN health checks that should be monitored proactively and their impact if ignored

Expected: 1. Disk balance (>30% imbalance reduces rebuild capacity). 2. Network health/MTU (mismatch causes vSAN I/O failures). 3. Software state (version mismatch after partial upgrade causes inconsistent behavior).

Common Errors

Ignoring vSAN health warnings until they become critical
Fix: vSAN health check runs automatically. Common warnings: 'Software state health' (vSAN version mismatch after partial upgrade), 'Network health' (MTU mismatch on vSAN VMKNIC), 'Disk balance' (capacity imbalance >30%). Address warnings proactively — a warning-level disk balance issue becomes critical during a host failure when rebuild needs the imbalanced capacity.
Not configuring alert thresholds for the specific environment
Fix: Default alert thresholds are generic. For example, CPU utilization alert at 90% may be too late for latency-sensitive workloads. Customize thresholds: EHR/database VMs should alert at 75% CPU, general workloads at 85%. Use VCF Operations alert profiles per workload domain.
Relying solely on VCF Operations for security monitoring
Fix: VCF Operations monitors infrastructure security (certificate expiry, host compliance, configuration drift). It does NOT replace a SIEM for security event monitoring. NSX IDS/IPS events, DFW blocked flows, and authentication failures should be forwarded to a dedicated SIEM for security operations.

Task 2 Health Monitoring & Security

Effective monitoring requires understanding the difference between VCF Operations dashboards (trending, capacity planning) and SDDC Manager health checks (real-time component status). Both are needed for comprehensive operations.

Monitor compute, storage, network, and security health through VCF Operations

Step 1
Compute & Storage Health

Compute: CPU/memory utilization, DRS status, HA status across clusters. Storage: vSAN health checks (disk status, resyncing status), storage operations dashboard, vSAN Insights. GPU: GPU metrics dashboard for AI/ML workloads.

Step 2
Security & Compliance Monitoring

Infrastructure security monitoring: Security Operations Dashboard for overall security posture. Configuration compliance checking. Integration with VCF Policies for enforcement.

Step 3
Log Analysis & Log Assist

Log analysis tools: log-based dashboards, custom queries, filters by criteria/grouping, visualization modes (charts). Log-based alerts for proactive monitoring. Log Assist: generate diagnostic log bundles from VCF Operations console. Prerequisites: deploy advanced cloud proxies mapped to components. Supported components: vCenter, ESX, NSX, SDDC Manager, VCF Operations, Log Insight, Lifecycle Manager. Transfer logs directly to Broadcom Support portal with Party Site ID + Case ID.

Step 4
VCF Operations Log Analysis, Alerts & Dashboards

VCF Operations includes Log Analysis for advanced troubleshooting: log-based dashboards with query filters, grouping, and visualization charts; live monitoring across all VCF components; custom filter creation to focus analysis. The Operations Log Appliance must be deployed and integrated with VCF Operations to use log analysis and diagnostic features. Log-based alerts: define alerts based on log entries across vSphere components, triggered based on log events over configurable time intervals with threshold-based notifications. Unified alerts combine metrics and log queries for comprehensive monitoring. VCF Operations for Networks provides network visibility and troubleshooting (note: detailed network operations capabilities are supplementary to the lecture manual — consult VMware documentation for VCF Operations for Networks specifics). For exam: understand how to create a dashboard to monitor cluster health, configure alerts for storage capacity thresholds, and use Log Assist to generate and upload diagnostic bundles to Broadcom support.

Validation Gate

Check: What is the difference between VCF Operations and SDDC Manager for monitoring?

Expected: VCF Operations: fleet-level trending, capacity planning, performance analytics, multi-instance visibility. SDDC Manager: instance-level real-time health checks, lifecycle management, component deployment status. Both are needed — VCF Operations for strategic, SDDC Manager for tactical.

Common Errors

Not integrating VCF Operations with external monitoring systems
Fix: VCF Operations supports outbound integrations: SNMP traps, syslog forwarding, webhook notifications, REST API. Production environments should forward critical alerts to the organization's existing monitoring/paging system (PagerDuty, ServiceNow, etc.) rather than relying on operators checking the VCF Operations console manually.
Confusing VCF Operations fleet-level view with domain-level health
Fix: VCF Operations provides fleet-level dashboards showing aggregate health across all instances and domains. A 'green' fleet status can mask a 'yellow' domain if the issue is localized. Always drill down from fleet → instance → domain → cluster for accurate health assessment.

Design Reflection (VCDX)

Operations and monitoring architecture is a VCDX defense topic. Panelists test whether your design includes Day-2 operational maturity — alert thresholds, integration with existing monitoring, and proactive health management. A design without operations planning is incomplete.

Requirements

  • Configure VCF Operations monitoring for storage, compute, and security health
  • Customize alert thresholds per workload domain and workload type
  • Integrate with external monitoring and paging systems

Constraints

  • VCF Operations is infrastructure monitoring, not a SIEM
  • Default alert thresholds are generic — must be customized
  • Fleet-level dashboards can mask domain-level issues

Assumptions

  • Organization has existing monitoring infrastructure for integration
  • Operations team reviews dashboards and responds to alerts

Risks

  • Alert fatigue from uncustomized thresholds
  • Security blind spots from relying solely on VCF Operations without SIEM
  • Missed domain-level issues masked by fleet-level green status

⚠ Known Pitfalls (from Community KB)

Presenting a VCDX design with no operations monitoring section — panelists consider this a significant gap in design maturity.
Treating VCF Operations as a SIEM replacement — it monitors infrastructure health, not security events.

References

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.