VCF Operations for vSphere Foundation
Objectives
- Navigate VCF Operations Console Launchpad and inventory tree in VVF context
- Monitor vSAN health and capacity using vSAN Insights and Storage Operations Dashboard
- Use Infrastructure Security and Log Analysis tools available in VVF
- Identify which VCF Operations capabilities unlock when upgrading from VVF to VCF
- Configure log-based alerts and diagnostic bundle transfer via Log Assist
- Understand GPU monitoring capabilities in VVF environments
Prerequisites
Active Holodeck VCF 9.0 lab or access to VCF Operations documentation
Prior labs: vcffts9-02, vcffts9-07
Required skills:
- Basic VMware terminology
- Web UI navigation
Tasks
Task 1 VCF Operations Console Navigation for VVF
Learn the VCF Operations Console as the primary management interface for VVF, understanding what is visible and what is absent compared to full VCF.
Access VCF Operations Console at https://<vcf-ops-fqdn>. The Launchpad is the landing page showing quick-access tiles for common operations. In VVF, the Launchpad is simplified: tiles for vCenter management, vSAN monitoring, VKS cluster management, and system health. Compare: full VCF Launchpad adds tiles for NSX monitoring, SDDC Manager operations, fleet management, and VCF Automation. Document which tiles are present and which are absent.
Navigate to the Inventory section in the left navigation pane. VVF inventory tree shows: vCenter instances (one or more), Clusters, Hosts, VMs, Datastores, and Networks (standard/distributed port groups only). Absent in VVF: NSX Manager nodes, Transport Zones, Logical Switches, Edge clusters, SDDC Manager. This reflects the VVF component scope: vSphere, vSAN, VKS, VCF Operations only.
Explore the monitoring dashboards available in VVF: Overview Dashboard (environment health summary), Compute Dashboard (CPU/memory utilization across hosts), Storage Dashboard (vSAN capacity and performance), Network Dashboard (limited to DVS monitoring, no NSX overlay metrics). Each dashboard provides real-time and historical data. Document the refresh interval and data retention period.
Navigate to Administration settings. Configure: (a) data collection interval for metrics, (b) alert notification targets (email, webhook), (c) user access management (local users and AD/LDAP integration), (d) certificate management for VCF Operations. Document: VCF Operations in VVF does not have fleet management capabilities (managing multiple VVF/VCF instances from a single console — this requires full VCF).
Validation Gate
Check: Complete navigation of VCF Operations Console with VVF-specific documentation
Expected: All VVF-available sections documented, absent VCF-only sections identified.
Common Errors
Task 2 vSAN Monitoring & Storage Operations
Use VCF Operations vSAN-specific monitoring tools to assess storage health, capacity planning, and performance in the VVF environment.
Navigate to vSAN Insights in VCF Operations. This dashboard provides: cluster health overview (green/yellow/red), disk health status for all devices, object compliance status (FTT policy adherence), and capacity trending. Key metrics to monitor: used capacity percentage (alert at 70%), disk health SMART indicators, resync activity (indicates ongoing rebuild), and deduplication/compression savings ratio. Document current values for each metric.
Access the Storage Operations Dashboard for detailed vSAN analytics. Available views: (a) capacity breakdown (raw, used, free, slack, metadata), (b) IOPS and throughput per datastore, (c) latency metrics (read/write average and peak), (d) per-VM storage consumption (thin provisioning actual vs provisioned), (e) storage policy compliance (which VMs meet their assigned FTT policy). Use this dashboard for capacity planning: project when the cluster will reach 70% based on current growth rate.
Run vSAN health checks from VCF Operations (complements the vSphere Client vSAN health view). Check categories: Network (vSAN VMkernel connectivity between hosts), Physical Disk (device health, firmware currency), Data (object health, component placement), Limits (maximum components per host, maximum hosts per cluster). Document any warnings and create remediation plans for each.
Use VCF Operations capacity tools to forecast vSAN growth. Steps: (a) review historical capacity usage (30/60/90 day trends), (b) identify growth rate (GB/month), (c) project when cluster will reach 70% threshold, (d) calculate hosts needed for expansion (each host adds X TB raw capacity). Document the capacity forecast and expansion timeline. In full VCF, Aria Operations provides more advanced what-if analysis; in VVF, manual calculation based on VCF Operations data is required.
Validation Gate
Check: Complete vSAN monitoring assessment with capacity forecast
Expected: vSAN health verified, current metrics documented, capacity forecast with expansion timeline created.
Common Errors
Task 3 Security, Logging & GPU Monitoring
Use the security monitoring, log analysis, and GPU capabilities available in VVF Operations to maintain operational visibility.
Navigate to Infrastructure Security in VCF Operations. In VVF, security monitoring covers: ESXi host security posture (SSH access, lockdown mode, password policy), vCenter security configuration (SSO policies, certificate status, role assignments), and vSAN encryption status (if enabled). Compare: full VCF adds NSX DFW security monitoring, micro-segmentation compliance, and network traffic flow analysis. Document current security posture and any findings that need remediation.
Access Log Analysis tools in VCF Operations. Available capabilities: (a) centralized log collection from vCenter and ESXi hosts, (b) log search with filters (time range, source, severity), (c) log-based alert creation (trigger alerts based on specific log patterns), (d) Log Assist for creating and transferring diagnostic bundles to VMware support. Configure a sample log-based alert: trigger when vCenter shows 'vpxd crash' pattern in logs. Set notification to email.
Practice using Log Assist for troubleshooting workflows. Log Assist: (a) collects logs from multiple VVF components (vCenter, ESXi hosts, VCF Operations), (b) packages into a diagnostic bundle, (c) enables secure transfer to VMware/Broadcom support for SR analysis. Steps: select components to include, define time range for log collection, generate bundle, download or transfer. Document: bundle size, components included, and transfer options.
If GPU-equipped hosts exist in the VVF environment, navigate to GPU Metrics dashboard. Available metrics: GPU utilization percentage, GPU memory usage, GPU temperature, VM-to-GPU assignment mapping. GPU monitoring is available in both VVF and VCF. For environments without GPUs, document: what GPU monitoring would show if GPUs were present, and which workloads benefit from GPU acceleration (AI/ML inference, VDI graphics, scientific computing).
Access the Security Operations Dashboard for aggregated security status. Review: (a) overall security compliance score, (b) hosts with security findings (SSH enabled, lockdown mode disabled), (c) certificate expiry tracking, (d) vulnerability assessment status. Create a security remediation plan: prioritize findings by severity, assign remediation actions, set target dates. Document: VVF security monitoring focuses on infrastructure hardening; VCF adds network security (NSX DFW) and application-level security monitoring.
Validation Gate
Check: Security assessment completed, log alerts configured, diagnostic bundle tested
Expected: Infrastructure security posture documented, log-based alert active, Log Assist bundle generated.
Common Errors
Task 4 VVF to VCF Operations Expansion & VCDX Context
Understand exactly what additional VCF Operations capabilities unlock when upgrading from VVF to full VCF, and position this in VCDX design context.
Document the VCF Operations capabilities that unlock after VVF-to-VCF converge: (a) NSX monitoring — transport node health, DFW rule effectiveness, overlay network performance, (b) SDDC Manager monitoring — workflow status, lifecycle management health, compliance drift, (c) Fleet management — manage multiple VCF instances from a single VCF Operations console, (d) VCF Automation integration — catalog item usage analytics, project quota monitoring, tenant health, (e) Unified tag management — consistent tagging across vSphere, NSX, and Aria Suite for governance.
Analyze how VCF upgrade changes daily operations: (a) monitoring scope expands (more components = more alerts = more operational overhead), (b) troubleshooting complexity increases (NSX adds overlay network layer to diagnose), (c) security monitoring deepens (DFW micro-segmentation adds granular visibility), (d) lifecycle management automates (SDDC Manager handles patching and upgrades). Net assessment: VCF requires more skilled staff but provides more automation and visibility.
Identify monitoring gaps in VVF that VCF addresses: (a) no east-west traffic visibility (no DFW, no IPFIX flow monitoring), (b) no overlay network monitoring (no Geneve tunnel health), (c) no automated lifecycle monitoring (no SDDC Manager workflow tracking), (d) no multi-instance fleet view (each VVF instance monitored independently). For each gap, assess: is this gap acceptable for the current environment? At what scale or compliance requirement does this gap become unacceptable?
Prepare design recommendations: (a) VVF Operations is sufficient for single-site, single-cluster environments without compliance-driven micro-segmentation monitoring, (b) VCF Operations is required when: multiple workload domains need unified monitoring, NSX security compliance requires DFW effectiveness reporting, fleet management across sites is needed, or self-service portal analytics are required. Document as design decision: D-OPS-001 with RCAR format justifying VVF Operations vs VCF Operations selection.
Design the operations team transition plan for VVF-to-VCF upgrade: (a) pre-upgrade: train team on NSX concepts, SDDC Manager workflow management, (b) during upgrade: expand monitoring dashboards, configure new alert policies for NSX and SDDC Manager, (c) post-upgrade: establish new operational runbooks covering NSX troubleshooting, SDDC Manager lifecycle operations, and expanded security monitoring. Document training requirements and timeline.
Validation Gate
Check: VCF Operations expansion analysis complete with VCDX design positioning
Expected: Capabilities comparison documented, monitoring gaps assessed, transition plan created, design decision D-OPS-001 prepared.
Common Errors
Final Validation
Complete VCF Operations for VVF with monitoring, security, and VCF expansion analysis
✓ Console navigation mastered → All VVF sections explored, absent VCF sections identified
✓ vSAN monitoring configured → Health checks, capacity forecast, and alerts documented
✓ Security assessment complete → Infrastructure security posture reviewed, log alerts configured
✓ VCF expansion understood → Capabilities unlocked by VCF upgrade documented
✓ VCDX design prepared → Design decision D-OPS-001 with monitoring gap analysis
Cleanup / Restore
• Save security assessment report
• Document VCF Operations configuration settings
• Export dashboard screenshots for study notes
• Revert to snapshot if configuration changes were made
Design Reflection (VCDX)
VCF Operations scope analysis demonstrates understanding of operational monitoring requirements at different VCF deployment scales. The monitoring gap analysis maps directly to compliance and operational maturity requirements. This is a key VCDX competency: matching tooling to requirements.
Requirements
- R-001: Operational monitoring must cover all deployed VCF/VVF components
- R-002: Security monitoring must meet organizational compliance requirements
- R-003: Capacity planning must provide 90-day forecasting capability
Constraints
- VVF Operations lacks NSX and SDDC Manager monitoring
- VVF does not support fleet management across multiple instances
- Log-based alerts are the primary proactive monitoring mechanism in VVF
Assumptions
- Current VVF environment does not require micro-segmentation monitoring
- Operations team has basic vSphere monitoring skills
- Compliance requirements will expand to include network security monitoring within 12 months
Risks
- Monitoring gaps in VVF may delay detection of security incidents — assess risk vs compliance requirements
- Operations team unfamiliar with expanded VCF monitoring may miss critical alerts after upgrade
- VVF capacity planning tools are less sophisticated than Aria Operations — manual forecasting introduces human error
Self-Assessment Discussion Prompts
- At what point do VVF monitoring limitations become a compliance risk?
- How would you bridge the VVF monitoring gap without upgrading to VCF?
- What is the minimum operations team size for managing VVF vs VCF?
- How does VCF Operations fleet management change the architecture for multi-site deployments?
Extensions
Custom Dashboard Creation
Create a custom VCF Operations dashboard for VVF that combines vSAN health, compute utilization, and security posture in a single view. Practice dashboard design for executive stakeholders vs operations team audiences.
Aria Operations Comparison
If access to Aria Operations is available, compare its monitoring capabilities with VCF Operations for VVF. Document which features Aria Operations adds beyond VCF Operations: advanced analytics, what-if capacity modeling, custom metrics, and third-party integrations.
Automated Health Reporting
Build an automated weekly health report using VCF Operations data. Include: vSAN health summary, capacity trending, security findings, and recommended actions. Export as PDF or email format for stakeholder distribution.
⚠ Known Pitfalls (from Community KB)
References
- VMware VCF Operations 9.0 Administration Guide — Console Navigation and Configuration
- VMware VCF Operations for vSphere Foundation — Feature Scope Documentation
- vSAN 9.0 Monitoring Guide — vSAN Insights and Health Checks
- VMware VCF 9.0 Security Hardening Guide — Infrastructure Security Best Practices
- VMware Log Assist Documentation — Diagnostic Bundle Collection and Transfer