VCF Operations Console — Monitoring Storage, Compute & Security
Objectives
- Navigate VCF Operations console (Launchpad, Inventory Tree, Navigation Pane)
- Describe VCF Identity Broker and supported identity providers
- Explain centralized certificate and password management in VCF 9.0
- Use unified tag management across vCenter and NSX
- Monitor compute, storage, GPU, and security health
- Use Log Assist to generate and transfer diagnostic bundles to support
Prerequisites
Active Holodeck VCF 9.0 lab or access to VCF documentation
Required skills:
- Basic VMware terminology
Tasks
Task 1 VCF Operations Console Navigation & Fleet Management
Navigate VCF Operations and understand fleet management capabilities
Central management interface for: licensing, identity providers, vCenter groups, health monitoring, events/logs, tag management, lifecycle management, configuration drift. Navigation: Launchpad (quick-start tiles), Inventory Tree (hierarchical view of vCenter instances), left navigation pane for all features.
[HOLODECK NOTE] VCF Operations in Holodeck monitors nested ESXi hosts and virtual infrastructure. Health metrics (CPU, memory, storage) reflect nested VM resource usage, not physical host health. Alert thresholds may trigger differently due to resource contention on the physical host. Log Assist can generate bundles but uploading to Broadcom support portal requires internet connectivity from the VCF Operations appliance.
Unified operations experience spanning: (1) Identity & Access — VCF Identity Broker replaces vIDM, embedded (on vCenter) or external appliance cluster, supports AD FS/Entra ID/Ping Identity/Okta/AD over LDAP/SAML 2.0/OIDC; (2) Certificate Management — centralized, auto-renewal with Microsoft CA or VMCA, one-click Renew Now, nondisruptive replacement; (3) Password Management — centralized, service accounts auto-provisioned (eliminates manual password management), Update/Remediate operations; (4) Unified Tag Management — 6000 categories + 8000 tags per vCenter, 90000 categories + 120000 tags in VCF Ops.
LCM: software upgrades managed through fleet management UI. Sequential upgrade process for VCF components. Configuration drift: detect and remediate configuration variants across fleet components. Ensures consistent configuration and policies across the environment.
Certificate management in VCF Operations covers 5 exam-relevant areas: (1) Certificate replacement — replace expiring or compromised certificates for vCenter, NSX, SDDC Manager via VCF Operations console; (2) Auto-renewal — VCF Operations can automatically renew certificates before expiry when configured with an internal CA; (3) Certificate Authority configuration — configure Microsoft Active Directory Certificate Services CA or VMCA (VMware Certificate Authority) as the signing authority; (4) External certificate import — import third-party CA-signed certificates using the import certificate functionality; (5) CSR generation — generate Certificate Signing Requests from VCF Operations for submission to external CAs. Troubleshooting focus: expired certificates cause service communication failures (vpxd, NSX Manager API, SDDC Manager); certificate trust chain issues prevent SSO authentication; time skew between hosts and CA causes validation failures. VCF 9.0 also introduces signed certificates for ESX hosts (previously self-signed only), supporting strict compliance environments. Certificate management integrates with VCF Operations alerts for proactive expiry notifications.
VCF Operations centralizes password management: centralized password management with auto-provisioned service accounts for intercomponent communication (eliminating manual password management for interservice accounts), password update and remediation operations, password complexity policy enforcement, and timely alerts when passwords approach expiration. Password operations: Update Password (reset forgotten passwords via UI) and Remediate Password (synchronize passwords changed outside VCF). vCenter solution accounts are replaced with managed service accounts — VCF Operations auto-provisions these, eliminating manual service account password management. Identity Broker replaces legacy vIDM — supports modern IdPs: Okta (OIDC/SAML), Microsoft AD FS (OIDC/SAML), Microsoft Entra ID, Ping Identity, and directory-based AD/LDAP and OpenLDAP. User provisioning via SCIM, JIT (Just-In-Time), or AD/LDAP sync. Troubleshooting focus: IdP connectivity failures (firewall, DNS), SAML assertion mismatches (clock skew, audience URI), LDAP bind failures (credentials, base DN, search filter), and certificate trust between Identity Broker and IdP.
Validation Gate
Check: Name three vSAN health checks that should be monitored proactively and their impact if ignored
Expected: 1. Disk balance (>30% imbalance reduces rebuild capacity). 2. Network health/MTU (mismatch causes vSAN I/O failures). 3. Software state (version mismatch after partial upgrade causes inconsistent behavior).
Common Errors
Task 2 Health Monitoring & Security
Monitor compute, storage, network, and security health through VCF Operations
Compute: CPU/memory utilization, DRS status, HA status across clusters. Storage: vSAN health checks (disk status, resyncing status), storage operations dashboard, vSAN Insights. GPU: GPU metrics dashboard for AI/ML workloads.
Infrastructure security monitoring: Security Operations Dashboard for overall security posture. Configuration compliance checking. Integration with VCF Policies for enforcement.
Log analysis tools: log-based dashboards, custom queries, filters by criteria/grouping, visualization modes (charts). Log-based alerts for proactive monitoring. Log Assist: generate diagnostic log bundles from VCF Operations console. Prerequisites: deploy advanced cloud proxies mapped to components. Supported components: vCenter, ESX, NSX, SDDC Manager, VCF Operations, Log Insight, Lifecycle Manager. Transfer logs directly to Broadcom Support portal with Party Site ID + Case ID.
VCF Operations includes Log Analysis for advanced troubleshooting: log-based dashboards with query filters, grouping, and visualization charts; live monitoring across all VCF components; custom filter creation to focus analysis. The Operations Log Appliance must be deployed and integrated with VCF Operations to use log analysis and diagnostic features. Log-based alerts: define alerts based on log entries across vSphere components, triggered based on log events over configurable time intervals with threshold-based notifications. Unified alerts combine metrics and log queries for comprehensive monitoring. VCF Operations for Networks provides network visibility and troubleshooting (note: detailed network operations capabilities are supplementary to the lecture manual — consult VMware documentation for VCF Operations for Networks specifics). For exam: understand how to create a dashboard to monitor cluster health, configure alerts for storage capacity thresholds, and use Log Assist to generate and upload diagnostic bundles to Broadcom support.
Validation Gate
Check: What is the difference between VCF Operations and SDDC Manager for monitoring?
Expected: VCF Operations: fleet-level trending, capacity planning, performance analytics, multi-instance visibility. SDDC Manager: instance-level real-time health checks, lifecycle management, component deployment status. Both are needed — VCF Operations for strategic, SDDC Manager for tactical.
Common Errors
Design Reflection (VCDX)
Operations and monitoring architecture is a VCDX defense topic. Panelists test whether your design includes Day-2 operational maturity — alert thresholds, integration with existing monitoring, and proactive health management. A design without operations planning is incomplete.
Requirements
- Configure VCF Operations monitoring for storage, compute, and security health
- Customize alert thresholds per workload domain and workload type
- Integrate with external monitoring and paging systems
Constraints
- VCF Operations is infrastructure monitoring, not a SIEM
- Default alert thresholds are generic — must be customized
- Fleet-level dashboards can mask domain-level issues
Assumptions
- Organization has existing monitoring infrastructure for integration
- Operations team reviews dashboards and responds to alerts
Risks
- Alert fatigue from uncustomized thresholds
- Security blind spots from relying solely on VCF Operations without SIEM
- Missed domain-level issues masked by fleet-level green status
⚠ Known Pitfalls (from Community KB)
References
- VCF Operations Administration GuideTier 1 — Official