Workload Domain Provisioning — Traditional vs Stretched
Objectives
- Plan a workload domain deployment: network pools, host commissioning prerequisites, licensing, and resource capacity analysis
- Provision a traditional (single-site) workload domain using SDDC Manager and VCF Operations Manager, including NSX T0/T1 gateway configuration
- Understand stretched cluster architecture: witness host deployment, fault domains, quorum model, and cross-site network requirements
- Provision a stretched workload domain with multi-site replication and validate witness host quorum
- Execute workload domain lifecycle operations: add hosts, expand cluster, shrink cluster, and validate placement policies
- Compare traditional and stretched domain trade-offs (RTO, complexity, failure domain, cost)
Prerequisites
VCF 9.0.x management domain deployed and operational. SDDC Manager accessible. 8+ uncommissioned ESXi hosts available in two physical sites (4 hosts per site for stretched topology, or 4+ hosts in single site for traditional). NSX Manager and Cloud Builder operational. Lab account must have SDDC Manager Administrator role. Network infrastructure must support multiple VLAN segments for host management, vMotion, vSAN, and edge TEP networks.
Prior labs: holodeck-02
Required skills:
- VCF management domain architecture (SDDC Manager, vCenter, NSX Manager)
- ESXi host commissioning and network configuration (VMkernel, vMotion, vSAN)
- NSX-T fundamentals: Tier-0 and Tier-1 gateways, segments, overlay networking
- vSAN design: fault domains, stretched cluster quorum, witness host role
- Network topology design: IP planning, VLAN allocation, BGP peering with NSX edges
- VCDX-level understanding of failure domains, availability zones, and disaster recovery models
Lab Environment
VCF 9.0.x management domain with 8-12 commissioning-ready ESXi 8.0.x hosts. For traditional WLD lab: 4 hosts in single site. For stretched WLD lab (extension): 4 hosts in Site A, 3 hosts in Site B, 1 witness host. All hosts have: iLO/IPMI for out-of-band management, 10Gbps+ network connectivity, vSAN-capable storage (local NVMe), and configured for vMotion/vSAN trunk port groups.
Traditional WLD: graph TB SDDC[Management Domain] SDDC -->|vCenter Cluster 1| WLD-A[Workload Domain A: 4 hosts, vSAN] SDDC -->|Network| T0A[NSX T0 Gateway] T0A -->|Uplink| PAS[Physical Access Switch] Stretched WLD: graph TB SDDC[Management Domain] SDDC -->|vCenter Stretched| WLD-S[Stretched WLD: Site A 4h + Site B 3h + Witness] SDDC -->|Network L3| Site-A[Site A Network] SDDC -->|Network L3| Site-B[Site B Network] Site-A -->|Witness Isolation| Witness[Witness Host] Site-A -->|vSAN Replication| Site-B
IP Addressing
| Network | Purpose | VLAN |
|---|---|---|
Management | Management domain (SDDC Manager, vCenter, NSX Manager) | 1644 |
Workload Host Management | WLD ESXi host VMkernel (one VLAN per host group) | 1650-1659 |
vMotion | vMotion VMkernel (for live migrations within WLD) | 1660-1669 |
vSAN | vSAN RDMA network (for disk group replication) | 1670-1679 |
NSX Host TEP | Host Tunnel End Point (TEP) for NSX overlay | 1680-1689 |
NSX Edge TEP | Edge node TEP for edge-based services | 1690-1699 |
Witness Isolation (Stretched only) | Witness host isolated from data traffic — read-only vSAN participation | 1710 |
Credentials
| System | Username | Password |
|---|---|---|
| SDDC Manager | administrator@vsphere.local | Set during VCF bring-up |
| ESXi Hosts (to be commissioned) | root | Set during host onboarding |
| vCenter (new WLD vCenter if applicable) | administrator@vsphere.local | Set during WLD provisioning |
| NSX Manager | admin | Set during management domain bring-up |
Tasks
Task 1 Plan and prepare for workload domain provisioning
manageabilityPre-deployment planning is where VCDX candidates demonstrate rigor. You must validate that the infrastructure is ready before initiating a 2+ hour provisioning operation. This mirrors production change management: plan, validate, execute, document.
In SDDC Manager, navigate to Administration > Inventory. Review the list of all ESXi hosts that are NOT yet assigned to a workload domain. Verify each host status: should be 'Commissioned' and 'Connected'. You need 4+ uncommissioned hosts for this lab (or 8+ if doing stretched topology extension).
Verify network infrastructure readiness for the WLD. For each proposed ESXi host in the WLD, validate: (a) Port group for host management (VMkernel) exists and is on dedicated VLAN, (b) Port group for vMotion exists, (c) Port group for vSAN exists, (d) Port group for NSX Host TEP exists, (e) All port groups are VLAN-enabled and do NOT have vLAN trunking misconfigured. Document the VLAN and IP range for each function.
Create a workload domain specification document. Define: (a) WLD Name (e.g., 'Workload-Domain-01'), (b) Compute Cluster Name (e.g., 'WLD-Cluster-01'), (c) Host list (esxi-05, esxi-06, esxi-07, esxi-08), (d) vSAN configuration (Single-Fault Tolerance FTT=1, or Dual-Fault FTT=2?), (e) vSAN network pool (which segment for vSAN RDMA?), (f) vCenter credentials (will reuse management vCenter or deploy WLD-specific vCenter?), (g) NSX Tier-0 gateway (which uplink VLAN and BGP peers?), (h) License tier (Standard, Enterprise, or Ent Plus?).
Validate licensing. In SDDC Manager, navigate to Administration > System Configuration > Licensing. Check current licenses: total seats, available seats, and per-workload-domain capacity. Ensure you have enough licenses for 4 hosts + overhead. Document any license constraints (e.g., 'License pool allows 8 hosts, planning 4 for WLD-01 and 4 for WLD-02 — at capacity').
Validate infrastructure capacity. Calculate resource overhead: (a) vCenter Server VM (Small: 4 vCPU, 21 GB RAM) per WLD or shared with management, (b) NSX Edge cluster (typically 2-4 edge nodes × 4 vCPU, 8 GB RAM each), (c) vSAN witness appliance (if stretched, 2 vCPU, 8 GB RAM). Total the resources and verify against available physical capacity. In SDDC Manager, Inventory > System Capacity, check total host resources available.
Create a provisioning checklist: (1) All 4 ESXi hosts status 'Commissioned' and 'Connected', (2) Network VLANs verified on physical switches and port groups created on each host, (3) Licensing capacity confirmed, (4) vSAN datastore pool planned (which disk groups per host?), (5) NSX T0 gateway uplink VLAN and BGP peering planned, (6) vCenter specifications (shared or WLD-specific?), (7) Risk mitigation: snapshot management domain before provisioning. Walk through each item. Check off as complete.
Validation Gate
Check: Planning documents complete: WLD specification, networking validation, licensing check, capacity calculation, provisioning checklist. All items signed off.
Expected: Pre-provisioning readiness confirmed. No blockers identified. Ready to proceed to Task 2 (traditional WLD provisioning).
Common Errors
Task 2 Provision a traditional (single-site) workload domain
availabilityExecute the WLD provisioning workflow using SDDC Manager. You'll orchestrate host commissioning, cluster creation, NSX deployment, and vCenter integration — all automated by SDDC Manager. Understand the sequence and where human intervention is required.
In SDDC Manager, navigate to Workload Domains > Create New Workload Domain. Fill in: (a) Name: 'Workload-Domain-01' (or your chosen name), (b) Cluster Name: 'WLD-Cluster-01', (c) Type: 'VI Workload Domain' (traditional vSphere cluster), (d) Network Pool: select the pool with IP ranges for host management, vMotion, vSAN, and NSX TEP (created in Task 1).
In the Hosts section, select the 4 ESXi hosts to be commissioned into this WLD (esxi-05, esxi-06, esxi-07, esxi-08). Verify each host shows status 'Ready for Commissioning'. Configure per-host properties: (a) Host name (FQDN), (b) Management VMkernel IP (will be auto-assigned from network pool), (c) vMotion IP, (d) vSAN IP, (e) NSX TEP IP.
Configure vSAN for the cluster. Select: (a) vSAN Fault Tolerance: 'FTT=1 (RAID-1)' for lab (or FTT=2 if larger cluster). (b) vSAN Network: select the vSAN VLAN/segment. (c) Disk Groups: specify which local disks on each host will be vSAN storage. In a Holodeck lab, each ESXi host may have 1 NVMe drive allocated for cache and 1 SSD for capacity. (d) Deduplication: disable for lab (use for larger production environments).
Configure NSX T0 Gateway for the WLD. (a) Name: 'WLD-T0-01'. (b) Uplink Profile: select NSX-managed T0 or Edge-based T0 (Edge-based is more common for WLDs). (c) Uplink VLAN: which VLAN will edge nodes use to reach the external router/ToR? (d) BGP Peering: enable BGP and specify: BGP neighbor IP (physical router), BGP neighbor ASN, local ASN for this WLD. (e) Tier-1 segments: configure default T1 for tenant overlay traffic.
Specify vCenter configuration for this WLD. Option 1: Reuse management vCenter (simplifies operations, vCenter scales to manage both management domain and WLD clusters). Option 2: Deploy WLD-specific vCenter (more isolation, higher licensing cost). For this lab, choose Option 1 (Reuse management vCenter). SDDC Manager will register the new cluster to the existing vCenter.
Review the WLD provisioning summary. SDDC Manager displays the complete provisioning plan: Hosts, Networks, vSAN, NSX, vCenter. Verify all settings are correct. Click 'Validate' to run pre-flight checks. Watch for any validation failures (VLAN not reachable, IP conflicts, insufficient capacity). If validation passes, click 'Provision'.
Monitor provisioning progress in SDDC Manager. Navigate to Workload Domains > Workload-Domain-01 > Status. Watch the detailed task list. Key milestones: (a) 'Commissioning ESXi hosts' (5-10 min per host), (b) 'Creating vSAN cluster' (10-15 min), (c) 'Configuring NSX transport nodes' (5-10 min per host), (d) 'Registering cluster with vCenter' (2-3 min), (e) 'Final validation' (5 min).
Validation Gate
Check: SDDC Manager: Workload Domains > Workload-Domain-01 status shows 'Active'. vCenter: navigate to https://10.0.0.6, login, verify new cluster 'WLD-Cluster-01' appears with 4 hosts connected. ESXi hosts status: 'Connected'. vSAN status: 'Healthy' (green). NSX: verify 4 transport nodes in Fabric > Nodes.
Expected: Traditional WLD fully provisioned and healthy. 4 ESXi hosts connected, vSAN cluster operational, NSX fabric integrated, vCenter managing the cluster.
Common Errors
Task 3 Validate workload domain placement and network connectivity
manageabilityA provisioned domain is not yet production-ready. You must validate that workloads can be placed, networks are segmented correctly, and edge nodes can route to external networks. This task covers the post-deployment checklist.
In vCenter, navigate to Hosts and Clusters. Click on the new 'WLD-Cluster-01' cluster. Verify: (a) 4 hosts are connected and green, (b) No alarms on the cluster, (c) Resource summary shows total CPU and memory available.
Validate vSAN health. In vSAN, navigate to Monitor > vSAN > Cluster > Health. Check: (a) Object health: all objects Compliant (no degraded), (b) Disk health: all disk groups Healthy, (c) Network latency: <1ms between hosts (shown in latency matrix).
Test workload placement. Deploy a test VM into the new cluster. In vCenter, create a new VM: (a) Name: 'wld-test-01', (b) Datastore: select vSAN datastore of WLD-Cluster-01, (c) Network: select an NSX segment (if Tier-1 was created during provisioning) or default VLAN, (d) Size: 2 vCPU, 8 GB RAM. Power on the VM.
Validate NSX connectivity. In NSX Manager, navigate to Fabric > Nodes > Host Transport Nodes. Verify all 4 WLD hosts appear and show Configuration State: 'Success' and Transport Node Status: 'Up'. Click on each host to view: (a) TEP IP address (should be from the NSX TEP pool, e.g., 10.2.3.5), (b) VLAN associations (Management, vMotion, vSAN, TEP), (c) No connectivity warnings.
Validate NSX Tier-0 gateway. In NSX Manager, navigate to Networking > Tier-0 Gateways > WLD-T0-01. Verify: (a) Gateway status: 'Realized' (not Error), (b) Uplink segment: has an IP and is connected to physical network, (c) BGP status: neighbor relationship is 'Established' (if BGP is enabled), (d) Tier-1 gateways are attached and have routes.
Test end-to-end connectivity. From the test VM (wld-test-01), ping an external IP (e.g., SDDC Manager 10.0.0.4 or a physical router 10.100.0.1). If the ping succeeds, NSX routing and the WLD network integration are working end-to-end.
Validation Gate
Check: vCenter: WLD-Cluster-01 shows 4 hosts, resources available, no alarms. vSAN: all objects compliant, network latency <1ms. NSX: 4 transport nodes Success/Up, T0 gateway Realized, test VM connectivity working.
Expected: WLD is validated and production-ready for workload placement. All infrastructure components (compute, storage, network) verified.
Common Errors
Task 4 Understand stretched cluster architecture and plan multi-site deployment
availabilityStretched clusters are the VCDX-level topology: multiple sites, witness quorum, fault domains, cross-site replication. This task is architecture and planning; the actual stretched WLD deployment is Extension 1. Understanding the design constraints is critical for VCDX panelists.
Review stretched cluster quorum model. In your lab notes, document: (a) Stretched cluster components: Site A (4 ESXi hosts), Site B (3 ESXi hosts), Witness Host (1 host, isolated on separate VLAN). (b) Quorum calculation: (4 + 3 + 1) = 8 nodes. Quorum = 4 nodes (majority). (c) Failure scenarios: If Site A loses 2 hosts, it has 2 + 1 (witness) = 3 (< quorum) and becomes read-only. If Site B loses 2 hosts, it has 1 + 1 (witness) = 2 (< quorum) and becomes read-only. (d) Write winning site: the site with >50% of active nodes wins the quorum and can write. Document this in a table.
Understand witness host role and placement. The witness host does NOT participate in I/O — it only votes in quorum decisions. Placement: must be in a third location (third data center) or isolated network to avoid being partitioned along with one of the primary sites. In the lab, the witness can be on the same physical host as management, but on an isolated VLAN to simulate geographic separation. Document: (a) Witness host role: storage quorum voting, (b) Witness network isolation: separate VLAN with no data traffic, (c) Witness disk: typically a small disk (10-50 GB) used only for quorum metadata, not data storage.
Design the stretched cluster network topology. For a 2-site stretched cluster: (a) Intra-site network latency: <1ms (within a data center, same network switch), (b) Inter-site network latency: <10ms (acceptable for vSAN replication), (c) Inter-site bandwidth: minimum 10 Gbps dedicated (25 Gbps recommended), RTT ≤5 ms (vSAN Stretched Cluster Guide). (d) Failure scenarios: if inter-site link fails, both sites enter read-only mode until the link is restored (network partition). Document the network design.
Understand fault domains. In a stretched cluster, fault domains are used to ensure replicas are spread across sites. Configure: (a) Site A hosts assigned to Fault Domain A, (b) Site B hosts assigned to Fault Domain B, (c) Witness assigned to Fault Domain C. (d) Replication policy: vSAN enforces that a copy of data resides in each fault domain (RAID-1 across sites). Document the placement policy.
Compare traditional vs stretched tradeoffs. Create a comparison table: Traditional (single-site WLD) vs Stretched (2-site WLD). Rows: RTO (recovery time objective if site fails), RPO (recovery point objective — data loss), complexity (operational overhead), cost (extra site, WAN bandwidth), failure scenarios.
Document the provisioning steps for stretched WLD (you will execute in Extension 1 if time permits). Steps: (1) Plan fault domains and network topology, (2) Commission hosts from both sites, (3) Configure inter-site network (L3 reachability, latency validate), (4) Deploy witness host on isolated VLAN, (5) Provision stretched WLD specifying fault domain assignments, (6) Configure vSAN stretch sync settings (e.g., change rebuild timeout from 30 min to 60 min for remote replication), (7) Validate quorum with network partition test (disable inter-site link, confirm read-only state, re-enable link, confirm quorum recovery).
Validation Gate
Check: Quorum model explained with failure scenarios. Witness host role and placement documented. Network topology designed with latency/bandwidth specs. Fault domains defined. Traditional vs stretched comparison table complete. Stretched provisioning checklist ready.
Expected: Comprehensive understanding of stretched cluster architecture and design constraints. Ready to architect or deploy a stretched WLD in production.
Common Errors
Task 5 Execute workload domain lifecycle operations: add hosts, expand cluster, and validate placement
manageabilityPost-deployment, WLDs require day 2 operations: adding hosts to scale out, removing hosts for decommissioning, expanding storage. This task covers the operational commands and validation steps.
Plan to add a 5th host to the traditional WLD (Workload-Domain-01). Ensure the host (esxi-09) is commissioned and ready. In SDDC Manager, navigate to Workload Domains > Workload-Domain-01 > Edit. In the Host List section, click 'Add Host'. Select esxi-09. Assign the same network IPs as the other hosts (management, vMotion, vSAN, TEP — auto-assigned from pool).
Click 'Save' to start the host addition operation. SDDC Manager will: (1) Commission esxi-09 (similar to initial commissioning), (2) Join it to the vSAN cluster, (3) Register transport node with NSX. Monitor progress in Workload Domains > Workload-Domain-01 > Status. Estimated time: 15-30 minutes.
In vCenter, navigate to Hosts and Clusters > WLD-Cluster-01. Verify the 5th host (esxi-09) is now connected and green. Check vSAN health: it should show '5 nodes, 20 components (5 x 4 original)' — data is still on the original 4 nodes until rebalance is triggered.
Trigger a vSAN rebalance to distribute the data across all 5 hosts. In vCenter, navigate to vSAN > Monitor > Cluster > Rebalance. Click 'Start Rebalance'. Watch the progress. This operation: (1) Reads data from original 4 hosts, (2) Redistributes to the 5th host, (3) Maintains fault tolerance (FTT=1, so 1 failure tolerated at all times). Estimated time: 30-60 minutes depending on data volume.
While rebalance is in progress, test workload placement policies. In vCenter, create a VM Storage Policy (in the Workload-Domain-01 vCenter): (a) Name: 'vSAN-FTT1-Balanced', (b) Fault Tolerance Objects: RAID-1 (FTT=1), (c) Storage Placement: prefer all 5 hosts equally. Apply this policy to the test VM (wld-test-01). vCenter will now manage VM placement to spread data evenly.
Validate the expanded cluster. In vSAN Monitor > Cluster > Health, confirm: (a) All 5 nodes are active, (b) No compliance violations, (c) Rebalance completed (100% migrated), (d) Data is spread evenly across 5 hosts (each host has 20% of data). Document the final state.
Validation Gate
Check: SDDC Manager: Workload-Domain-01 shows 5 hosts. vCenter: 5 hosts connected in WLD-Cluster-01. vSAN: 5 nodes active, rebalance complete, data distributed evenly.
Expected: WLD scaled out successfully. Day 2 operations (add host, rebalance) demonstrated and validated.
Common Errors
Final Validation
You have planned and provisioned a traditional workload domain, validated network connectivity and placement, understood stretched cluster architecture including witness quorum and fault domains, and executed day 2 operations (host addition and rebalance). You can now architect workload domain topologies at the VCDX level, making data-driven decisions between traditional and stretched topologies based on RTO, RPO, cost, and complexity tradeoffs.
✓ Pre-provisioning Planning → Spec document, network validation, licensing check, capacity calculation, provisioning checklist — all complete
✓ Traditional WLD Provisioning → Workload-Domain-01 deployed with 4 hosts, vSAN healthy, NSX fabric integrated, vCenter managing cluster
✓ WLD Validation → vSAN cluster compliant, NSX transport nodes Success/Up, test VM deployed and connected, T0 gateway realized, end-to-end connectivity verified
✓ Stretched Cluster Architecture → Quorum model documented, witness host role explained, fault domains designed, traditional vs stretched comparison table completed
✓ Day 2 Operations → 5th host added, vSAN rebalance executed, data distributed evenly, storage policy applied, cluster validated at new size
Cleanup / Restore
Snapshot: vcp-admin-08-complete
• Power off test VM (wld-test-01): vCenter > VMs > right-click > Power Off > Remove from Inventory
• Document the WLD configuration: cluster name, host list, vSAN settings, NSX T0 configuration, IP pools used. Save to your lab notebook for future reference.
• Take a final snapshot: 'vcp-admin-08-complete — Traditional WLD fully provisioned and validated, 5 hosts after expansion, vSAN rebalanced, Day 2 operations completed.'
• If performing Extension 1 (stretched WLD), do NOT revert yet. Keep management domain and traditional WLD intact for stretched deployment.
Design Reflection (VCDX)
A VCDX panelist examining your WLD design would ask: Why choose traditional vs stretched topology for a given business case? What is the actual RTO/RPO if Site A fails (all 4 hosts down)? How does the witness host quorum work, and what if the witness host fails? Why is inter-site latency <10ms critical? Can you expand the cluster from 4 to 5 hosts without downtime? How does NSX scale with WLD cluster size? What is the blast radius of a vSAN failure? Be prepared to architect a multi-site WLD that balances availability, cost, and operational complexity for a real enterprise use case.
Requirements
- Workload domain must provide dedicated compute for tenant workloads with performance and availability guarantees isolated from the management domain
- Cluster must scale from initial size (4 hosts) to larger size (8-16 hosts) without downtime or data loss
- Availability: single-site WLD must tolerate 1 host failure (FTT=1); stretched WLD must tolerate entire site failure
- Network connectivity: WLD hosts must reach external networks via NSX T0 gateway with redundant uplinks
Constraints
- vSAN requires <1ms intra-site latency and <10ms inter-site latency — cannot stretch WLD across distant data centers
- Witness host for stretched cluster must be in third location (or isolated network) to avoid being partitioned with primary site
- vSAN rebalance is I/O intensive and disruptive — must be scheduled during maintenance windows
- NSX scale: Tier-0 gateway capacity depends on edge node resources; edge nodes compete for compute in the cluster
- Licensing: each WLD requires proportional VCF licenses; stretched topology may require additional licensing (e.g., Site Recovery Manager for automated failover)
Assumptions
- All ESXi hosts have sufficient local storage for vSAN disk groups (minimum 200 GB per host for lab, 1+ TB for production)
- Network infrastructure supports dedicated VLANs for management, vMotion, vSAN, NSX TEP, and uplink traffic with adequate bandwidth (10 Gbps minimum per host for vSAN)
- Operator has SDDC Manager Administrator role and understands vSphere, NSX, and vSAN administration
- For stretched topology: inter-site network link is stable and redundant (2+ independent paths); witness host has guaranteed isolation from primary sites
Risks
- vSAN cluster quorum loss if majority of nodes are down simultaneously — IMPACT: entire cluster becomes read-only, MITIGATION: over-provision hosts and monitor quorum health
- Inter-site network partition on stretched cluster — IMPACT: both sites become read-only until link is restored, MITIGATION: design L3 redundancy, avoid single-point-of-failure link
- vSAN rebalance triggers cascading failures if hosts are near capacity — IMPACT: cluster becomes unhealthy, MITIGATION: maintain 20-30% free space on vSAN datastore
- Witness host failure in stretched cluster — IMPACT: quorum tilts to the physically co-located site (if witness is placed there), MITIGATION: place witness in true third location or use multiple witness nodes
- NSX T0 uplink failure isolates WLD from external networks — IMPACT: workloads lose external connectivity, MITIGATION: use redundant edge nodes and multiple uplink connections
Self-Assessment Discussion Prompts
- You are designing a WLD for an e-commerce platform. Business requires <1 minute RTO if a single host fails and <1 hour RTO if entire data center fails. Which topology (traditional or stretched) would you recommend, and why?
- In a stretched WLD with 4+3+1 (witness) configuration, the inter-site link fails for 2 hours. What is the state of each site? Which site can still write? What happens to VMs running on the read-only site?
- You plan to add 8 new hosts to an existing 4-node WLD (doubling capacity). The vSAN rebalance is projected to take 8 hours. How would you execute this to minimize workload disruption?
- Compare NSX scale in a traditional 4-node WLD vs stretched 7-node WLD. How many edge nodes would you deploy in each case, and where would they run?
- A security audit requires all VMs in the WLD to be separated by fault domain (no two replicas on the same host, no two replicas in same failure domain for stretched). How would you design vSAN FTT and storage policies to meet this requirement?
- Stretched WLD witness host has a hardware failure and cannot be replaced for 24 hours. What is the state of the WLD? Can VMs still run? Can new VMs be created?
Extensions
Provision a Stretched Workload Domain (2-site topology)
Extend the lab to provision a stretched WLD using the architecture and planning from Task 4. Deploy: Site A with 4 ESXi hosts, Site B with 3 ESXi hosts, witness host on isolated VLAN. Configure fault domains and vSAN replication across sites. Execute a network partition test (disable inter-site link) to validate quorum behavior. This is the advanced topology that VCDX candidates must master.
harderDesign and Validate a Multi-Tier NSX Network for Workload Domain
Create a multi-tier NSX network architecture for the WLD: Tier-0 gateway for external routing, multiple Tier-1 gateways for tenant segmentation, overlay segments for different application tiers (web, app, db). Create workloads on different segments, enforce micro-segmentation policies, and validate east-west traffic. This demonstrates VCDX-level NSX design.
harderCompare VCF 5.2 vs VCF 9.0 WLD Provisioning Workflows
If you have access to a VCF 5.2 lab, repeat the WLD provisioning (Task 2) in VCF 5.2. Document differences: SDDC Manager UI, provisioning automation maturity, NSX integration, vSAN configuration. Write a 2-page comparison addressing: what was improved in VCF 9.0, what was deprecated, and how the provisioning experience evolved.
sameDesign and Implement WLD Placement Policies for Multi-Tenant Isolation
Design a placement policy strategy for a multi-tenant environment: Tenant A VMs must not run on the same physical host as Tenant B, each tenant has dedicated storage quota, each tenant has dedicated NSX segment. Use vCenter VM groups, host groups, and affinity rules to enforce these policies. Validate that workload placement complies with multi-tenant constraints.
harderReferences
- VMware Cloud Foundation 9.0 Workload Domain Planning and Deployment GuideTier 1 — Official
Official Broadcom documentation covering WLD architecture, provisioning steps, networking, and vSAN configuration - SDDC Manager — Workload Domain Operations and Day 2 ManagementTier 1 — Official
Deep dive on WLD lifecycle operations: provisioning, host addition, cluster expansion, decommissioning - vSAN Stretched Cluster Design and DeploymentTier 1 — Official
Authoritative guide on stretched cluster architecture, witness host placement, quorum model, and failure scenarios - NSX-T Tier-0 and Tier-1 Gateway Configuration in VCFTier 1 — Official
NSX gateway design for workload domains, BGP peering, uplink redundancy - William Lam — VCF Workload Domain Deployment and AutomationTier 3 — Expert Blog
Community expert blog with hands-on WLD provisioning examples, troubleshooting, and Day 2 automation - VCDX Design Exam Scenario: Multi-Site Stretched VCF DeploymentTier 2 — VMware Press
VCDX exam blueprint highlighting multi-site, stretched, and high-availability topologies as key design patterns