Intelligent Operations Management for VMware Cloud Foundation
VMware Cloud Foundation Operations (formerly vRealize Operations / Aria Operations) provides a centralized monitoring and alerting platform that delivers proactive management of system failures. The solution consists of an analytics cluster (primary + primary replica + data node, scale-out up to 8 nodes) for data analysis and storage, and VMware Cloud Proxy appliances that perform local metric collection per VMware Cloud Foundation instance and forward data to the analytics cluster. Data source integrations include VMware Cloud Foundation, NSX, vCenter Server, vSAN, Workspace ONE Access, and Ping. The design supports single-instance, multi-AZ, and multi-instance topologies.
Key Components: NSX, Aria Operations, Aria Automation, SDDC Manager, vCenter, ESXi, VCF Operations, Workspace ONE
Multi AZ: Analytics nodes run in first AZ. DRS VM/Host rule binds them to AZ1 host group. VMware Cloud Proxies also pinned to AZ1.
48 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| IOM-VAOPS-SEC-005 | ), custom vCenter role with minimum privileges for cloud account, NSX Principal Identity using clien | ManageabilitySecurity |
Decision: ), custom vCenter role with minimum privileges for cloud account, NSX Principal Identity using client certificate (Enterprise Admin role) for each NSX Local Manager — removes need to manage password. Rationale: Password ManagementRoot and admin passwords rotated via SDDC Manager UI or API (not through Aria Suite Lifecycle) since the product is in VCF mode. Implication: CertificatesCA-signed certificate with analytics and Cloud Proxy FQDNs in SAN; SHA-2 or higher; must be replaced when new nodes are add Component: VAOPS | ||
| IOM-VAOPS-CFG-001 | Deploy VCF Operations as a 3-node cluster (primary + primary replica + data node) in the default man | Manageability |
Decision: Deploy VCF Operations as a 3-node cluster (primary + primary replica + data node) in the default management vSphere cluster. Rationale: Scale capacity for up to 12,000 VMs/objects; supports scale-out. Implication: All nodes must be sized identically, increasing resource requirements. Component: VAOPS | ||
| IOM-VAOPS-CFG-002 | Deploy two VMware Cloud Proxy appliances in the default management vSphere cluster. | Manageability |
Decision: Deploy two VMware Cloud Proxy appliances in the default management vSphere cluster. Rationale: Removes metric collection load from analytics cluster. Implication: You must assign a collector group when configuring monitoring. Component: VAOPS | ||
| IOM-VAOPS-CFG-003 | Use the VMware Aria Suite Lifecycle instance in the corresponding VCF instance to deploy Operations. | Manageability |
Decision: Use the VMware Aria Suite Lifecycle instance in the corresponding VCF instance to deploy Operations. Rationale: Aria Suite Lifecycle manages product binaries; SDDC Manager auto-configures load balancer when in VCF mode. Implication: Must deploy Aria Suite Lifecycle via SDDC Manager. Component: VAOPS | ||
| IOM-VAOPS-CFG-004 | Protect all VCF Operations nodes with vSphere HA. | AvailabilityManageability |
Decision: Protect all VCF Operations nodes with vSphere HA. Rationale: Supports availability objective without manual intervention. Implication: No significant trade-offs identified for this decision. Component: VAOPS | ||
| IOM-VAOPS-CFG-005 | Apply DRS anti-affinity rule to analytics cluster VMs. | Manageability |
Decision: Apply DRS anti-affinity rule to analytics cluster VMs. Rationale: Prevents co-location on same ESXi host. Implication: Must be updated when data nodes are added; in a 4-host cluster only one host can be in maintenance at a time. Component: VAOPS | ||
| IOM-VAOPS-CFG-009 | Enable data persistence on all Cloud Proxy appliances. | AvailabilityManageability |
Decision: Enable data persistence on all Cloud Proxy appliances. Rationale: Provides buffering during connectivity issues. Implication: Monitor storage availability on each Cloud Proxy. Component: VAOPS | ||
| IOM-VAOPS-CFG-010 | In multi-AZ, add Operations VMs to first AZ VM group. | Manageability |
Decision: In multi-AZ, add Operations VMs to first AZ VM group. Rationale: Ensures VMs power on within AZ1 host group. Implication: If Operations deployed after stretched cluster creation, VM group must be updated. Component: VAOPS | ||
| IOM-VAOPS-CFG-011 | In multi-instance, deploy two Cloud Proxies per instance using first instance's Aria Suite Lifecycle | Manageability |
Decision: In multi-instance, deploy two Cloud Proxies per instance using first instance's Aria Suite Lifecycle. Rationale: Localizes collection; consistent deployment. Implication: Must assign collector groups. Component: VAOPS | ||
| IOM-VAOPS-CFG-014 | Deploy analytics nodes as medium-size appliances. | AvailabilityManageability |
Decision: Deploy analytics nodes as medium-size appliances. Rationale: Capacity for 12,000 objects with HA active; metrics from vCenter, ESXi, NSX, Aria Automation, Aria Operations for Logs. Implication: Requires 24 vCPU / 96 GB total; ESXi hosts need 8+ cores per socket; scale up via Aria Suite Lifecycle when > 12,000 objects. Component: VAOPS | ||
| IOM-VAOPS-CFG-016 | Increase initial storage per analytics node by 700 GB. | Manageability |
Decision: Increase initial storage per analytics node by 700 GB. Rationale: Supports 12,000 objects, 20% growth, 6-month retention. Implication: No significant trade-offs identified for this decision. Component: VAOPS | ||
| IOM-VAOPS-CFG-017 | Deploy each Cloud Proxy as small-size. | Manageability |
Decision: Deploy each Cloud Proxy as small-size. Rationale: Supports up to 8,000 objects per proxy; proxies don't store data. Implication: 2 vCPUs/8 GB RAM reserved per proxy. Component: VAOPS | ||
| IOM-VAOPS-CFG-018 | Configure outbound SMTP mail server for notifications. | Manageability |
Decision: Configure outbound SMTP mail server for notifications. Rationale: Email delivery of system events. Implication: Must maintain an SMTP server. Component: VAOPS | ||
| IOM-VAOPS-CFG-019 | Set the currency in Operations global options based on organization requirements. | Manageability |
Decision: Set the currency in Operations global options based on organization requirements. Rationale: Ensures accurate costing; Aria Automation integration uses this currency. Implication: Currency cannot be changed after initial configuration. Component: VAOPS | ||
| IOM-VAOPS-NET-001 | Place analytics nodes on cross-instance NSX segment. | Manageability |
Decision: Place analytics nodes on cross-instance NSX segment. Rationale: Supports multi-instance DR growth. Implication: Requires NSX overlay implementation. Component: VAOPS | ||
| IOM-VAOPS-NET-002 | Place Cloud Proxies on local-instance NSX segment. | Manageability |
Decision: Place Cloud Proxies on local-instance NSX segment. Rationale: Collect metrics locally per VCF instance. Implication: Requires NSX overlay implementation. Component: VAOPS | ||
| IOM-VAOPS-NET-008 | Use small-size NSX load balancer on dedicated Tier-1 gateway (shared with Workspace ONE Access). | Manageability |
Decision: Use small-size NSX load balancer on dedicated Tier-1 gateway (shared with Workspace ONE Access). Rationale: Deploys Operations analytics cluster with distributed UI access. Implication: Must use the NSX LB configured by SDDC Manager. Component: VAOPS | ||
| IOM-VAOPS-NET-009 | Do NOT use a load balancer for Cloud Proxies. | Manageability |
Decision: Do NOT use a load balancer for Cloud Proxies. Rationale: Proxies must directly access monitored systems; don't require public access. Implication: No significant trade-offs identified for this decision. Component: VAOPS | ||
| IOM-VAOPS-LCM-001 | Use VMware Aria Suite Lifecycle for all LCM of Operations. | Manageability |
Decision: Use VMware Aria Suite Lifecycle for all LCM of Operations. Rationale: Manages product binaries and upgrades. Implication: Must deploy Aria Suite Lifecycle via SDDC Manager; includes patches, updates, hotfixes. Component: VAOPS | ||
| IOM-VAOPS-CFG-020 | Activate VMware Cloud Foundation integration in Operations. | Manageability |
Decision: Activate VMware Cloud Foundation integration in Operations. Rationale: Enables cloud accounts for SDDC Manager, vCenter, vSAN, NSX. Implication: Manual activation. Component: VAOPS | ||
| IOM-VAOPS-CFG-021 | Activate VMware Identity Manager integration. | Manageability |
Decision: Activate VMware Identity Manager integration. Rationale: Operations communicates with Workspace ONE Access. Implication: Installed/activated by SDDC Manager. Component: VAOPS | ||
| IOM-VAOPS-CFG-022 | Activate VMware Infrastructure Health integration. | Manageability |
Decision: Activate VMware Infrastructure Health integration. Rationale: Unified operations view and health of management components. Implication: Must configure a VCF cloud account first; manual activation. Component: VAOPS | ||
| IOM-VAOPS-CFG-023 | Activate Ping integration. | Availability |
Decision: Activate Ping integration. Rationale: Endpoint availability metrics. Implication: Manual activation. Component: VAOPS | ||
| IOM-VAOPS-CFG-024 | Remove the existing vCenter Server cloud account created by SDDC Manager. | Manageability |
Decision: Remove the existing vCenter Server cloud account created by SDDC Manager. Rationale: Not used when using the VCF integration. Implication: Must manually remove. Component: VAOPS | ||
| IOM-VAOPS-CFG-025 | Remove existing Principal Credential for vCenter created by SDDC Manager. | Manageability |
Decision: Remove existing Principal Credential for vCenter created by SDDC Manager. Rationale: Replaced by service-account-based credential. Implication: Must manually remove. Component: VAOPS | ||
| IOM-VAOPS-CFG-026 | Configure SDDC Manager credential per VCF instance using least-privilege AD service account. | Manageability |
Decision: Configure SDDC Manager credential per VCF instance using least-privilege AD service account. Rationale: Required to collect SDDC Manager domain and metric data. Implication: Maintain lifecycle of service account. Component: VAOPS | ||
| IOM-VAOPS-CFG-027 | Configure a VCF cloud account per VCF instance assigned to local-instance collector group. | Manageability |
Decision: Configure a VCF cloud account per VCF instance assigned to local-instance collector group. Rationale: Metric collection for SDDC Manager and workload domains. Implication: Manual creation. Component: VAOPS | ||
| IOM-VAOPS-CFG-028 | Configure Principal Credential for each workload domain vCenter using least-privilege AD service acc | Manageability |
Decision: Configure Principal Credential for each workload domain vCenter using least-privilege AD service account. Rationale: Required to collect vCenter metric data. Implication: Maintain service account lifecycle. Component: VAOPS | ||
| IOM-VAOPS-CFG-029 | Configure vCenter cloud account per workload domain assigned to local-instance collector group. | Manageability |
Decision: Configure vCenter cloud account per workload domain assigned to local-instance collector group. Rationale: Metric collection for vCenter. Implication: Manual creation. Component: VAOPS | ||
| IOM-VAOPS-CFG-030 | Enable vSAN cloud account per workload domain. | Manageability |
Decision: Enable vSAN cloud account per workload domain. Rationale: Metric collection from vSAN clusters. Implication: Shared service account increases connectivity fault risk. Component: VAOPS | ||
| IOM-VAOPS-CFG-031 | Configure NSX Client Certificate credential per NSX Manager with least privilege. | ManageabilitySecurity |
Decision: Configure NSX Client Certificate credential per NSX Manager with least privilege. Rationale: Required to collect NSX metrics. Implication: Manage certificates and private keys. Component: VAOPS | ||
| IOM-VAOPS-CFG-032 | Configure NSX cloud account per workload domain NSX Manager assigned to local-instance collector gro | Manageability |
Decision: Configure NSX cloud account per workload domain NSX Manager assigned to local-instance collector group. Rationale: Metric collection for NSX Manager. Implication: Manual credential addition. Component: VAOPS | ||
| IOM-VAOPS-CFG-033 | Configure VMware Identity Manager cloud account for clustered Workspace ONE Access using default col | Manageability |
Decision: Configure VMware Identity Manager cloud account for clustered Workspace ONE Access using default collector group. Rationale: Metric collection from WS1 Access. Implication: Configured by SDDC Manager. Component: VAOPS | ||
| IOM-VAOPS-CFG-034 | Configure Ping cloud account for analytics cluster nodes (default collector group). | Availability |
Decision: Configure Ping cloud account for analytics cluster nodes (default collector group). Rationale: Availability metrics for analytics cluster. Implication: Manual addition. Component: VAOPS | ||
| IOM-VAOPS-CFG-035 | Configure Ping cloud account for Cloud Proxy appliances (local-instance collector group). | Availability |
Decision: Configure Ping cloud account for Cloud Proxy appliances (local-instance collector group). Rationale: Availability metrics for proxies. Implication: Manual addition. Component: VAOPS | ||
| IOM-VAOPS-CFG-037 | Define alerts for application/VM/container, VI/ESXi host, SDN, and storage. | Manageability |
Decision: Define alerts for application/VM/container, VI/ESXi host, SDN, and storage. Rationale: Detect conditions endangering workloads, infrastructure, NSX, vSAN/disk storage. Implication: Individual alerts may need manual creation/maintenance. Component: VAOPS | ||
| IOM-VAOPS-SEC-001 | Activate Operations integration with corporate identity via clustered Workspace ONE Access. | ManageabilityRecoverabilitySecurity |
Decision: Activate Operations integration with corporate identity via clustered Workspace ONE Access. Rationale: Enables AD authentication (incl. MFA) and authorization via roles. Implication: Must deploy clustered WS1 Access. Component: VAOPS | ||
| IOM-VAOPS-SEC-002 | Assign Administrator, ContentAdmin, ReadOnly roles to Active Directory security groups. | ManageabilitySecurity |
Decision: Assign Administrator, ContentAdmin, ReadOnly roles to Active Directory security groups. Rationale: Managed access, auditability. Implication: Maintain AD security groups outside SDDC stack. Component: VAOPS | ||
| IOM-VAOPS-SEC-006 | Define custom vCenter role with minimum privileges for vCenter cloud account. | Manageability |
Decision: Define custom vCenter role with minimum privileges for vCenter cloud account. Rationale: Least privilege. Implication: Maintain role; apply to each SSO domain if multiple. Component: VAOPS | ||
| IOM-VAOPS-SEC-007 | Assign custom vCenter role to AD service account per workload domain vCenter. | Manageability |
Decision: Assign custom vCenter role to AD service account per workload domain vCenter. Rationale: Integration and data collection with minimal privileges. Implication: Maintain service account. Component: VAOPS | ||
| IOM-VAOPS-SEC-008 | Use vCenter service account also for vSAN data collection (no separate credentials). | Manageability |
Decision: Use vCenter service account also for vSAN data collection (no separate credentials). Rationale: vSAN uses vCenter credentials. Implication: No significant trade-offs identified for this decision. Component: VAOPS | ||
| IOM-VAOPS-SEC-009 | Create NSX Principal Identity with Enterprise Admin role per NSX Local Manager. | ManageabilitySecurity |
Decision: Create NSX Principal Identity with Enterprise Admin role per NSX Local Manager. Rationale: Certificate-based auth removes password management. Implication: Manage certificates and private keys. Component: VAOPS | ||
| IOM-VAOPS-SEC-010 | Configure password expiration, complexity, and account lockout policies on Operations and Cloud Prox | Manageability |
Decision: Configure password expiration, complexity, and account lockout policies on Operations and Cloud Proxy appliances. Rationale: Align with organizational/compliance standards; applies only to local users. Implication: Manage via appliance console or SSH. Component: VAOPS | ||
| IOM-VAOPS-SEC-013 | Change Operations and Cloud Proxy root password on schedule via SDDC Manager UI/API. | Manageability |
Decision: Change Operations and Cloud Proxy root password on schedule via SDDC Manager UI/API. Rationale: In VCF mode, root password is managed by SDDC Manager, not Aria Suite Lifecycle. Implication: Use SDDC Manager for rotation. Component: VAOPS | ||
| IOM-VAOPS-SEC-014 | Change Operations admin account password via SDDC Manager UI/API. | Manageability |
Decision: Change Operations admin account password via SDDC Manager UI/API. Rationale: Admin password managed by SDDC Manager in VCF mode. Implication: Routine rotation via SDDC Manager. Component: VAOPS | ||
| IOM-VAOPS-SEC-015 | Use CA-signed certificate with analytics and Cloud Proxy FQDNs in SAN when deploying Operations. | ManageabilitySecurity |
Decision: Use CA-signed certificate with analytics and Cloud Proxy FQDNs in SAN when deploying Operations. Rationale: Encrypts external UI/API traffic. Implication: Must replace when adding nodes. Component: VAOPS | ||
| IOM-VAOPS-SEC-016 | Use SHA-2 or higher. | Manageability |
Decision: Use SHA-2 or higher. Rationale: SHA-1 deprecated. Implication: Not all CAs support SHA-2. Component: VAOPS | ||
| IOM-VAOPS-LOG-001 | Use Aria Operations for Logs content pack; forward logs to VAOL VIP using ingestion API port 9000 wi | ManageabilitySecurity |
Decision: Use Aria Operations for Logs content pack; forward logs to VAOL VIP using ingestion API port 9000 with ssl=no; dedicated Photon OS agent group. Rationale: Enables cross-instance log forwarding during DR without certificate mismatch issues. Implication: Log transmission is unencrypted. Component: VAOPS | ||
Prerequisites
- VCF version listed in Support Matrix (5.2.1, 5.2.0, 5.1.1, 5.1.0).
Implementation Procedure
Implementation
Captured parameters in Intelligent Operations Management tab of the VCF Planning & Preparation Workbook.
Downloaded Workspace ONE Access OVA, VMware Cloud Foundation Operations OVA, and Cloud Proxy OVA from Broadcom Support Portal.
Aria Suite Lifecycle or VCF Operations license with sufficient quantity.
Required forward/reverse DNS records created.
Active Directory Domain Controllers, service accounts, and security groups created.
Microsoft Certificate Authority available; OpenSSL 3.0+ installed for PowerShell module execution.
PowerShell 7.2+ for automated implementation.
Implementation Methods
Powershell
Install-Module PowerValidatedSolutions (+ PowerCLI, SsoAdmin, PowerVCF, ImportExcel). Run Start-ValidatedSolutionMenu; choose '07. (IOM) Intelligent Operations Management'. Submenu options: 01 Generate JSON Spec, 02 Verify Prerequisites, 03 Generate Certificate from Microsoft CA, 05 End-to-End Deployment, 07 Configuration (interoperability).
UI
Per VCF version-specific table (VCF 5.2.1 shown): 1) Download Aria Suite Lifecycle 8.18.0 install bundle via SDDC Manager (or Bundle Transfer Utility for disconnected). 2) Deploy Aria Suite Lifecycle via SDDC Manager. 3) Replace Aria Suite Lifecycle certificate with CA-signed. 4) Apply PSPACK3 to Aria Suite Lifecycle. 5) Create vSphere Content Library to host Operations OVA. 6) Configure cross-instance datacenter + management vCenter in Aria Suite Lifecycle. 7) Import Workspace ONE Access certificate. 8) Add Workspace ONE Access passwords. 9) Deploy clustered Workspace ONE Access via Aria Suite Lifecycle (3-node global environment). 10) Configure anti-affinity rule and VM group for WS1 Access. 11-12) Configure NTP, domain, domain search. 13) Configure AD identity source. 14) Add WS1 Access nodes as identity provider connectors. 15-16) Assign AD groups to WS1 Access and Aria Suite Lifecycle roles.
Then create Content Library for Operations, import Operations OVA/OVF, deploy Operations cluster from Aria Suite Lifecycle (which triggers SDDC Manager to configure the NSX LB). Deploy Cloud Proxies, configure cloud accounts (SDDC Manager, vCenter, NSX using Principal Identity cert, vSAN, WS1 Access, Ping), activate integrations (VCF, VMware Identity Manager, VMware Infrastructure Health, Ping), configure notifications, costing, alerts.
External Services / Integration Points
Active Directory (AD)
DNS
NTP
Microsoft Certificate Authority (CA)
SMTP
LLDP or CDP on network devices
Configuration Values
Load Balancer Monitor URL/suite-api/api/deployment/node/status?services=api&services=adminui&services=ui
Session Persistence Timeout1800 seconds (30 minutes)
Notification FlowAlert Definitions → Notifications → Standard Email Plug-In (outbound SMTP) → payload template
vSphere Content LibraryUsed to synchronize the Operations OVA across VI workload domains for image mapping by Aria Automation (cross-solution)
Power Shell Menu ID07
Additional Instance
For additional VCF instance, extend the Operations implementation by deploying two additional Cloud Proxy appliances in each additional instance. Steps: (1) Prepare NSX Principal Identity in each NSX Manager. (2) Configure credentials for SDDC components. (3) Create cloud accounts assigned to the instance's local collector group. (4) Configure integrations. (5) Add Ping adapters for the new nodes.
Day-2 Operations Tasks
Operations
As neededPersonas
As neededNameRole
As neededCloud AdminVCF Operations Administrator
As neededAdministratorVCF Operations Administrator
As neededContent AdministratorVCF Operations Content Admin — dashboards/views/reports/groups
As neededRead-only UserVCF Operations Read Only
As neededOperational Verification
As neededCertificate Management
As neededGenerate CA-signed cert via PowerValidatedSolutions; add to Aria Suite Lifecycle locker; replace on Operations; if Aria Automation is integrated, re-t
As neededMonitoring Points
- Authenticate with local admin — verify Cluster Status = Online, HA = Activated.
- Authenticate via AD user through vIDMAuthSource — verify access matches role.
- Verify Authentication Sources → clustered WS1 Access shows successful Test connection.
- Verify each adapter Status = OK: VCF cloud account, vCenter, vSAN, NSX, WS1 Access, Ping.
- Verify Capacity → Assess shows 'All clusters have sufficient capacity'.
Troubleshooting
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Trade-Offs Analysis
Chosen:
Justification:
Managing root password via Aria Suite Lifecycle UI instead of SDDC Manager when in VCF mode.
Chosen:
Justification:
Quiz — Intelligent Ops Management
- Two nodes: one primary, one data
- Three nodes: one primary, one primary replica, one data
- Four nodes: two primary, two data
- One monolithic node with HA
- 9543 with ssl=yes
- 9000 with ssl=no (cfapi)
- 514 with ssl=yes
- 443 with ssl=auto
- It's the only timezone that Aria Suite Lifecycle supports
- VMware Aria Automation supports only UTC
- NSX requires UTC for logging
- vSAN requires UTC
- Small — 4 vCPU / 16 GB
- Medium — 8 vCPU / 32 GB
- Large — 16 vCPU / 48 GB
- Extra Large — 24 vCPU / 128 GB
- Manually via NSX UI
- Automatically by SDDC Manager when deployed via Aria Suite Lifecycle in VCF mode
- Via a PowerCLI script
- Via a Terraform module
- Local admin password
- NSX Principal Identity with client certificate
- Active Directory account
- API token
- 5,000 objects
- 8,000 objects
- 12,000 objects
- 20,000 objects
- Same cross-instance NSX segment
- Local-instance NSX segment in each VCF instance
- Management VLAN
- DMZ VLAN
- 4,000
- 8,000
- 15,000
- 40,000
- Aria Suite Lifecycle
- SDDC Manager UI/API
- vCenter Server
- Directly on the appliance
- /health
- /api/status
- /suite-api/api/deployment/node/status?services=api&services=adminui&services=ui
- /admin/status
- Auditor
- Network Admin
- Enterprise Admin
- Security Admin
- Redeploy Operations
- Re-Trust With Identity Manager in Aria Suite Lifecycle (Environments → cross-instance → Operations tab)
- Reissue NSX cert
- Nothing
- IOM-VAOPS-SEC-009
- IOM-VAOPS-SEC-008
- IOM-VAOPS-CFG-027
- IOM-VAOPS-CFG-030
- 500 GB
- 700 GB
- 1 TB
- 2 TB
Flashcards — Intelligent Ops Management
Labs
Deploy and verify VCF Operations cluster with NSX load balancer
Deploy a 3-node Medium analytics cluster + 2 Cloud Proxies via Aria Suite Lifecycle and validate SDDC Manager-automated NSX LB.
Starting State: Healthy VCF 5.2 instance with Aria Suite Lifecycle and clustered WS1 Access deployed; PSPACK3 applied; DNS/NTP in place.
Configure NSX Principal Identity and rotate certificate
Create an NSX Principal Identity with client certificate for Operations, then rotate the certificate before expiry.
Starting State: Operations deployed; NSX Local Manager accessible; SDDC Manager SSH available.
Add a second VCF instance and extend Operations monitoring
Deploy two local-instance Cloud Proxies in a second VCF instance and integrate with the existing analytics cluster.
Starting State: Primary VCF instance with analytics cluster operational; second VCF instance bring-up complete; Aria Suite Lifecycle already managing first instance.