Academy/VVS/Health Monitoring
This solution targets VCF 5.2

Health Reporting and Monitoring for VMware Cloud Foundation

VCF 5.2architectvcdxadminautomationPages 111-138

Provides operational insights across availability, health, and compliance for VCF via HTML reports (PowerShell Module for VCF Reporting) and custom dashboards/alerts/notifications in VMware Cloud Foundation Operations (formerly vRealize Operations) via a Python Module for VCF Health Monitoring. Deploys a host VM in the management domain hosting both modules, which collect data from the VCF Support & Serviceability (SoS) utility and SDDC component APIs.

Key Components: NSX, SDDC Manager, vCenter, ESXi, VCF Operations

External dependencies: Host virtual machine (Photon OS or Microsoft Windows Server)

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

12 design decisions

DD-IDDecisionQuality
HRM-VM-NET-001JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: HRM-VM-NET-002Allocate statically assigned IP from management VLAN.Stability + simpler mgmt.Precise IPAM.

Component: VM

HRM-VM-NET-002JustificationImplicationSecurity

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: HRM-VM-NET-003Configure forward+reverse DNS for host VM.FQDN-based access.DNS records; firewall to DNS.

Component: VM

HRM-VM-NET-003JustificationImplicationSecurity

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: HRM-VM-NET-005Configure NTP on host VM.Prevents time drift; correlate logs/metrics.Multiple NTP servers; firewall rules.

Component: VM

HRM-VM-NET-004JustificationImplicationSecurity

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: HRM-VM-NET-005Configure NTP on host VM.Prevents time drift; correlate logs/metrics.Multiple NTP servers; firewall rules.

Component: VM

HRM-VM-CFG-001Deploy host VM with supported guest OS (Photon OS or Windows Server).AvailabilityManageabilitySecurity

Decision: Deploy host VM with supported guest OS (Photon OS or Windows Server).

Rationale: Dedicated VM ensures isolation of PS/Python modules from production components.

Implication: VM is deployed, configured, and maintained outside VCF automation, adding a manually lifecycled component to day-2 operations.

Component: VM

HRM-VM-CFG-002Deploy host VM in default management vSphere cluster.AvailabilityManageability

Decision: Deploy host VM in default management vSphere cluster.

Rationale: Required connectivity to SDDC Manager and VCF Operations.

Implication: Must be able to connect to SDDC Manager and VCF Operations.

Component: VM

HRM-VM-CFG-003Protect host VM with vSphere HA.Availability

Decision: Protect host VM with vSphere HA.

Rationale: Availability objective without manual intervention during ESXi failure.

Implication: None.

Component: VM

HRM-VM-CFG-004Place host VM in a designated VM folder.Inventory organization.Must create folder during deployment.Manageability

Decision: Place host VM in a designated VM folder.Inventory organization.Must create folder during deployment.

Rationale: HRM-VM-CFG-005When using 2 AZs, add host VM to VM group of first AZ.Primary AZ hosts group placement.After second AZ implementation, update VM group to include host VM.

Implication: HRM-VM-CFG-006In multi-VCF, deploy host VM in mgmt cluster in first VCF instance.Required connectivity to all SDDC Managers and VCF Operations.Must connect to all instances.

Component: VM

HRM-PY-CFG-001Install Python 3.x on host VM.Manageability

Decision: Install Python 3.x on host VM.

Rationale: Python 3 required for the script.

Implication: In multi-VCF, multiple Python module copies — each corresponding to a VCF instance.

Component: PY

HRM-PY-CFG-002Install Nagini client (Python binding for VCF Operations).Manageability

Decision: Install Nagini client (Python binding for VCF Operations).

Rationale: Nagini enables sending data to VCF Ops.

Implication: Manual install depends on host OS.

Component: PY

HRM-PY-CFG-003Schedule daily runs of Python module to collect health data from SDDC Manager and send to VCF OperatManageabilitySecurity

Decision: Schedule daily runs of Python module to collect health data from SDDC Manager and send to VCF Operations.Automation.Manual setup depends on host OS.

Rationale: HRM-PY-CFG-004Default log retention for Python module logs = 30 days.Auto-cleanup of send-data-to-vrops.py logs to save disk.Set log_retention_in_days in env.json.

Implication: Information Security

Component: PY

HRM-VM-LCM-001Manage host VM guest OS updates using organization's tools/processes.Security/critical fixes timely.ManageabilitySecurity

Decision: Manage host VM guest OS updates using organization's tools/processes.Security/critical fixes timely.Not managed by SDDC Manager.

Rationale: HRM-LCM-001Manually update PowerShell Module for VCF Reporting when new versions released.Latest features and bug fixes.None.

Implication: HRM-LCM-002Manually update Python Module for VCF Health Monitoring in VCF Operations.Latest features and bug fixes.None.

Component: VM

Prerequisites

  • VCF version listed in Support Matrix
  • Environment configured per Before You Apply This Guidance
  • Health Reporting and Monitoring tab completed in VCF Planning and Preparation Workbook
  • VCF instance healthy and fully operational
  • DNS forward/reverse records
  • AD DCs available and service accounts created
  • VCF integrated with AD over LDAP (see IAM validated solution)
  • VCF integrated with Intelligent Operations (VCF Operations deployed)
  • PowerShell Automation
  • Workflow

Implementation Procedure

Implementation

Install PowerShell modules (PowerCLI 13.2.1+, vSphere.SsoAdmin 1.3.9+, ImportExcel 7.8.5+, PowerVCF 2.4.0+, PowerValidatedSolutions 2.11.0+)

Import-Module PowerValidatedSolutions; Test-PowerValidatedSolutionsPrereq

Create folder structure (validatedSolutions, certificates, binaries, generatedJsons)

Run Start-ValidatedSolutionMenu with workbook

Main menu 11. (HRM) Health Reporting and Monitoring

Sub-option 01. Generate JSON Specification File

Sub-option 02. Verify Prerequisites

Sub-option 05. End-to-End Deployment (note: PowerShell handles VCF preparation; Host VM and VCF Operations configuration must be manual via UI)

Note

Automated PowerShell implementation supports only preparing the VCF instance; Host VM configuration and VCF Operations configuration must be done manually via UI.

External Services / Integration Points

Active Directory (AD)

DNS

NTP

Open Source Prereqs

Networking

  • Host VM connectivity to SDDC Manager of each VCF instance
  • Host VM connectivity to VCF Operations
  • Power Shell
  • Supported guest OS
  • Supported PowerShell version
  • Python
  • Python 3.x installed
  • Required Python libraries installed
  • Implementation Options
  • MethodDesc
  • PowerShell automationEnd-to-end automated via PowerValidatedSolutions menu
  • UI / component interfacesManual deployment and configuration
  • Host VM Configuration

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

Persona: Site Resiliency Engineer (SRE)

As needed

PersonaSite Resiliency Engineer (SRE)

As needed

ResponsibilityGenerate HTML reports; perform admin actions (excluding user/cluster management)

As needed

Mapping

As needed

SDDC ManagerADMIN

As needed

VCF OperationsPowerUser

As needed

Operational Verification

As needed

Certificate Management

As needed

Monitoring Points

  • Verify host VM is online and accessible via FQDN
  • Verify PowerShell module generates HTML reports against current VCF inventory
  • Verify Python module daily run succeeds; metrics land in VCF Operations as custom metrics on corresponding objects
  • Verify VCF Health dashboards populate correctly; drill into VCF Health Rollup
  • Verify alerts/notifications trigger when thresholds exceeded
  • MonitoringThis solution IS the monitoring; integrates natively with VCF Operations for dashboards/alerts/notifications

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Not applying vSphere HA — loss of host VM during ESXi failure
Impact:
Mitigation:
Hard-coding credentials with excessive privilege — breaches least privilege
Impact:
Mitigation:
Ignoring certificate trust — Python/PowerShell connections fail on cert rotation
Impact:
Mitigation:
vSphere HA protects host VM across ESXi failures
Impact:
Mitigation:
Scheduled run fails silently
Impact:
Mitigation:

Trade-off Analysis

Single host VM per multi-VCF deployment with multiple Python module copies — simpler than multiple VMs, with trade-off on blast radius.

Chosen:

Justification:

Trade-Offs Analysis

Chosen:

Justification:

Quiz — Health Monitoring

0/15
Q1
Which module pushes health metrics to VMware Cloud Foundation Operations as custom metrics?
  • PowerShell Module for VCF Reporting
  • Python Module for VCF Health Monitoring in VCF Operations
  • PowerVCF
  • ImportExcel
Python Module uses the Nagini REST client to push metrics to corresponding VCF Operations objects.
Q2
What is the sizing requirement for a Photon OS host VM in this solution?
  • 2 vCPU, 4 GB RAM, 60 GB disk
  • 1 vCPU, 2 GB RAM, 662 MB thin/16 GB thick
  • 4 vCPU, 8 GB RAM, 100 GB disk
  • 1 vCPU, 1 GB RAM, 20 GB disk
Photon OS: 1 vCPU / 2 GB / 662 MB thin or 16 GB thick. Windows Server: 2 vCPU / 4 GB / 60 GB.
Q3
Which dashboard shows the results of component version drift detection against SDDC Manager inventory and BoM?
  • VCF Version Health
  • VCF Compute Health
  • VCF Connectivity Health
  • VCF Hardware Compatibility
VCF Version Health compares component version, SDDC Manager inventory, and BoM component versions.
Q4
How many copies of the Python module are installed in a multi-VCF-instance environment?
  • One, always — it aggregates all instances
  • One per VCF instance
  • One per vCenter
  • Two — primary and standby
HRM-PY-CFG-001 implication: in multi-VCF, multiple copies installed, each corresponding to a VCF instance. Host VM is deployed in first instance.
Q5
Which design decision enforces host VM placement in the primary AZ during multi-AZ deployments?
  • HRM-VM-CFG-003 (HA)
  • HRM-VM-CFG-005 (VM group for first AZ)
  • HRM-VM-CFG-004 (VM folder)
  • HRM-VM-NET-001 (mgmt VLAN)
HRM-VM-CFG-005: add host VM to VM group of the first AZ via DRS VM/Host rule.
Q6
Which reports can the PowerShell Module for VCF Reporting generate? (best answer)
  • System overview, Health, Alert, Configuration, Upgrade precheck
  • Only Health report
  • Only Configuration report
  • Compliance only
Module generates all five: System overview, Health, Alert, Configuration, Upgrade precheck.
Q7
What is the default log_retention_in_days for the Python module?
  • 7
  • 14
  • 30
  • 90
HRM-PY-CFG-004: default 30 days to prevent host VM local disk from filling.
Q8
Which Python client is used to send data to VCF Operations?
  • PyVmomi
  • Nagini
  • PowerShell Core
  • Ansible
Nagini is a Python binding/REST client for VCF Operations (HRM-PY-CFG-002).
Q9
Which content pack source provides the VCF Health dashboards?
  • SDDC Manager default
  • VMware Marketplace management pack
  • Predefined dashboards installed by the Python module
  • Built into VCF Operations
Python module installs predefined dashboards in VCF Health dashboard group in VCF Operations.
Q10
Which VCF Health dashboard covers Ping, SSH, and API connectivity between SDDC Manager and components?
  • VCF Networking Health
  • VCF Connectivity Health
  • VCF Compute Health
  • VCF DNS Health
VCF Connectivity Health — verifies Ping/SSH/API between SDDC Manager and underlying components.
Q11
Which component is NOT in scope of the Python module's inventory?
  • SDDC Manager
  • ESXi hosts
  • vCenter Server
  • External Active Directory
AD is an external service/prereq, not monitored by this solution. In scope: SDDC Manager, vCenter, vSAN, NSX, ESXi, VCF Operations.
Q12
What is the scheduling mechanism for the Python module's data collection?
  • On demand only
  • Continuous real-time streaming
  • Scheduled daily runs
  • Every 5 minutes
HRM-PY-CFG-003: daily scheduled runs collect health data and send to VCF Operations.
Q13
What PowerShell menu option corresponds to Health Reporting and Monitoring?
  • 04. (IAM)
  • 05. (DRI)
  • 11. (HRM)
  • 12. (ILA)
Main menu 11. (HRM) Health Reporting and Monitoring.
Q14
Lifecycle management of the PowerShell Module for VCF Reporting is...
  • Automated by SDDC Manager
  • Automated by VCF Operations
  • Manual (HRM-LCM-001)
  • Handled by ImportExcel
HRM-LCM-001: manually update module when new versions available; not in SDDC Manager scope.
Q15
What guest OS options are supported for the host VM?
  • Only Photon OS
  • Only Windows Server
  • Photon OS or Microsoft Windows Server
  • Any Linux
HRM-VM-CFG-001: Photon OS or Microsoft Windows Server.

Flashcards — Health Monitoring

Card 1 of 15
Host VM purpose
Hosts both PowerShell (VCF Reporting) and Python (VCF Health Monitoring) open-source modules; deployed in default mgmt cluster of management domain.

Labs

Lab 1: Deploy Host VM and Install PowerShell Reporting Module

Deploy a Photon OS host VM in management domain, install PowerShell Module for VCF Reporting, generate a Health report.

Starting State: VCF 5.2 management domain operational; Photon OS OVA downloaded; AD service account with SDDC Manager ADMIN role; DNS/NTP configured.

Lab 2: Install Python Health Monitoring Module and Import VCF Health Dashboards to VCF Operations

Install Python module on host VM, configure env.json, schedule daily run, import dashboards into VCF Operations.

Starting State: Host VM from Lab 1; VCF Operations deployed and AD-integrated; service account with ADMIN role in VCF Operations.

Lab 3: Configure Alerts and Notifications for VCF Certificate Expiry

Use VCF Health Certificate Health data to configure an alert definition that emails administrators 30 days before cert expiry.

Starting State: VCF Health dashboards installed; VCF Operations with SMTP configured.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.