Health Reporting and Monitoring for VMware Cloud Foundation
Provides operational insights across availability, health, and compliance for VCF via HTML reports (PowerShell Module for VCF Reporting) and custom dashboards/alerts/notifications in VMware Cloud Foundation Operations (formerly vRealize Operations) via a Python Module for VCF Health Monitoring. Deploys a host VM in the management domain hosting both modules, which collect data from the VCF Support & Serviceability (SoS) utility and SDDC component APIs.
Key Components: NSX, SDDC Manager, vCenter, ESXi, VCF Operations
External dependencies: Host virtual machine (Photon OS or Microsoft Windows Server)
12 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| HRM-VM-NET-001 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: HRM-VM-NET-002Allocate statically assigned IP from management VLAN.Stability + simpler mgmt.Precise IPAM. Component: VM | ||
| HRM-VM-NET-002 | JustificationImplication | Security |
Decision: JustificationImplication Rationale: See source document for rationale Implication: HRM-VM-NET-003Configure forward+reverse DNS for host VM.FQDN-based access.DNS records; firewall to DNS. Component: VM | ||
| HRM-VM-NET-003 | JustificationImplication | Security |
Decision: JustificationImplication Rationale: See source document for rationale Implication: HRM-VM-NET-005Configure NTP on host VM.Prevents time drift; correlate logs/metrics.Multiple NTP servers; firewall rules. Component: VM | ||
| HRM-VM-NET-004 | JustificationImplication | Security |
Decision: JustificationImplication Rationale: See source document for rationale Implication: HRM-VM-NET-005Configure NTP on host VM.Prevents time drift; correlate logs/metrics.Multiple NTP servers; firewall rules. Component: VM | ||
| HRM-VM-CFG-001 | Deploy host VM with supported guest OS (Photon OS or Windows Server). | AvailabilityManageabilitySecurity |
Decision: Deploy host VM with supported guest OS (Photon OS or Windows Server). Rationale: Dedicated VM ensures isolation of PS/Python modules from production components. Implication: VM is deployed, configured, and maintained outside VCF automation, adding a manually lifecycled component to day-2 operations. Component: VM | ||
| HRM-VM-CFG-002 | Deploy host VM in default management vSphere cluster. | AvailabilityManageability |
Decision: Deploy host VM in default management vSphere cluster. Rationale: Required connectivity to SDDC Manager and VCF Operations. Implication: Must be able to connect to SDDC Manager and VCF Operations. Component: VM | ||
| HRM-VM-CFG-003 | Protect host VM with vSphere HA. | Availability |
Decision: Protect host VM with vSphere HA. Rationale: Availability objective without manual intervention during ESXi failure. Implication: None. Component: VM | ||
| HRM-VM-CFG-004 | Place host VM in a designated VM folder.Inventory organization.Must create folder during deployment. | Manageability |
Decision: Place host VM in a designated VM folder.Inventory organization.Must create folder during deployment. Rationale: HRM-VM-CFG-005When using 2 AZs, add host VM to VM group of first AZ.Primary AZ hosts group placement.After second AZ implementation, update VM group to include host VM. Implication: HRM-VM-CFG-006In multi-VCF, deploy host VM in mgmt cluster in first VCF instance.Required connectivity to all SDDC Managers and VCF Operations.Must connect to all instances. Component: VM | ||
| HRM-PY-CFG-001 | Install Python 3.x on host VM. | Manageability |
Decision: Install Python 3.x on host VM. Rationale: Python 3 required for the script. Implication: In multi-VCF, multiple Python module copies — each corresponding to a VCF instance. Component: PY | ||
| HRM-PY-CFG-002 | Install Nagini client (Python binding for VCF Operations). | Manageability |
Decision: Install Nagini client (Python binding for VCF Operations). Rationale: Nagini enables sending data to VCF Ops. Implication: Manual install depends on host OS. Component: PY | ||
| HRM-PY-CFG-003 | Schedule daily runs of Python module to collect health data from SDDC Manager and send to VCF Operat | ManageabilitySecurity |
Decision: Schedule daily runs of Python module to collect health data from SDDC Manager and send to VCF Operations.Automation.Manual setup depends on host OS. Rationale: HRM-PY-CFG-004Default log retention for Python module logs = 30 days.Auto-cleanup of send-data-to-vrops.py logs to save disk.Set log_retention_in_days in env.json. Implication: Information Security Component: PY | ||
| HRM-VM-LCM-001 | Manage host VM guest OS updates using organization's tools/processes.Security/critical fixes timely. | ManageabilitySecurity |
Decision: Manage host VM guest OS updates using organization's tools/processes.Security/critical fixes timely.Not managed by SDDC Manager. Rationale: HRM-LCM-001Manually update PowerShell Module for VCF Reporting when new versions released.Latest features and bug fixes.None. Implication: HRM-LCM-002Manually update Python Module for VCF Health Monitoring in VCF Operations.Latest features and bug fixes.None. Component: VM | ||
Prerequisites
- VCF version listed in Support Matrix
- Environment configured per Before You Apply This Guidance
- Health Reporting and Monitoring tab completed in VCF Planning and Preparation Workbook
- VCF instance healthy and fully operational
- DNS forward/reverse records
- AD DCs available and service accounts created
- VCF integrated with AD over LDAP (see IAM validated solution)
- VCF integrated with Intelligent Operations (VCF Operations deployed)
- PowerShell Automation
- Workflow
Implementation Procedure
Implementation
Install PowerShell modules (PowerCLI 13.2.1+, vSphere.SsoAdmin 1.3.9+, ImportExcel 7.8.5+, PowerVCF 2.4.0+, PowerValidatedSolutions 2.11.0+)
Import-Module PowerValidatedSolutions; Test-PowerValidatedSolutionsPrereq
Create folder structure (validatedSolutions, certificates, binaries, generatedJsons)
Run Start-ValidatedSolutionMenu with workbook
Main menu 11. (HRM) Health Reporting and Monitoring
Sub-option 01. Generate JSON Specification File
Sub-option 02. Verify Prerequisites
Sub-option 05. End-to-End Deployment (note: PowerShell handles VCF preparation; Host VM and VCF Operations configuration must be manual via UI)
Note
Automated PowerShell implementation supports only preparing the VCF instance; Host VM configuration and VCF Operations configuration must be done manually via UI.
External Services / Integration Points
Active Directory (AD)
DNS
NTP
Open Source Prereqs
Networking
- Host VM connectivity to SDDC Manager of each VCF instance
- Host VM connectivity to VCF Operations
- Power Shell
- Supported guest OS
- Supported PowerShell version
- Python
- Python 3.x installed
- Required Python libraries installed
- Implementation Options
- MethodDesc
- PowerShell automationEnd-to-end automated via PowerValidatedSolutions menu
- UI / component interfacesManual deployment and configuration
- Host VM Configuration
Day-2 Operations Tasks
Operations
As neededPersonas
As neededPersona: Site Resiliency Engineer (SRE)
As neededPersonaSite Resiliency Engineer (SRE)
As neededResponsibilityGenerate HTML reports; perform admin actions (excluding user/cluster management)
As neededMapping
As neededSDDC ManagerADMIN
As neededVCF OperationsPowerUser
As neededOperational Verification
As neededCertificate Management
As neededMonitoring Points
- Verify host VM is online and accessible via FQDN
- Verify PowerShell module generates HTML reports against current VCF inventory
- Verify Python module daily run succeeds; metrics land in VCF Operations as custom metrics on corresponding objects
- Verify VCF Health dashboards populate correctly; drill into VCF Health Rollup
- Verify alerts/notifications trigger when thresholds exceeded
- MonitoringThis solution IS the monitoring; integrates natively with VCF Operations for dashboards/alerts/notifications
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Single host VM per multi-VCF deployment with multiple Python module copies — simpler than multiple VMs, with trade-off on blast radius.
Chosen:
Justification:
Trade-Offs Analysis
Chosen:
Justification:
Quiz — Health Monitoring
- PowerShell Module for VCF Reporting
- Python Module for VCF Health Monitoring in VCF Operations
- PowerVCF
- ImportExcel
- 2 vCPU, 4 GB RAM, 60 GB disk
- 1 vCPU, 2 GB RAM, 662 MB thin/16 GB thick
- 4 vCPU, 8 GB RAM, 100 GB disk
- 1 vCPU, 1 GB RAM, 20 GB disk
- VCF Version Health
- VCF Compute Health
- VCF Connectivity Health
- VCF Hardware Compatibility
- One, always — it aggregates all instances
- One per VCF instance
- One per vCenter
- Two — primary and standby
- HRM-VM-CFG-003 (HA)
- HRM-VM-CFG-005 (VM group for first AZ)
- HRM-VM-CFG-004 (VM folder)
- HRM-VM-NET-001 (mgmt VLAN)
- System overview, Health, Alert, Configuration, Upgrade precheck
- Only Health report
- Only Configuration report
- Compliance only
- 7
- 14
- 30
- 90
- PyVmomi
- Nagini
- PowerShell Core
- Ansible
- SDDC Manager default
- VMware Marketplace management pack
- Predefined dashboards installed by the Python module
- Built into VCF Operations
- VCF Networking Health
- VCF Connectivity Health
- VCF Compute Health
- VCF DNS Health
- SDDC Manager
- ESXi hosts
- vCenter Server
- External Active Directory
- On demand only
- Continuous real-time streaming
- Scheduled daily runs
- Every 5 minutes
- 04. (IAM)
- 05. (DRI)
- 11. (HRM)
- 12. (ILA)
- Automated by SDDC Manager
- Automated by VCF Operations
- Manual (HRM-LCM-001)
- Handled by ImportExcel
- Only Photon OS
- Only Windows Server
- Photon OS or Microsoft Windows Server
- Any Linux
Flashcards — Health Monitoring
Labs
Lab 1: Deploy Host VM and Install PowerShell Reporting Module
Deploy a Photon OS host VM in management domain, install PowerShell Module for VCF Reporting, generate a Health report.
Starting State: VCF 5.2 management domain operational; Photon OS OVA downloaded; AD service account with SDDC Manager ADMIN role; DNS/NTP configured.
Lab 2: Install Python Health Monitoring Module and Import VCF Health Dashboards to VCF Operations
Install Python module on host VM, configure env.json, schedule daily run, import dashboards into VCF Operations.
Starting State: Host VM from Lab 1; VCF Operations deployed and AD-integrated; service account with ADMIN role in VCF Operations.
Lab 3: Configure Alerts and Notifications for VCF Certificate Expiry
Use VCF Health Certificate Health data to configure an alert definition that emails administrators 30 days before cert expiry.
Starting State: VCF Health dashboards installed; VCF Operations with SMTP configured.