There has been considerable discussion about when VMware Cloud Foundation 9.0 will be released and what new features it will include. Well, wait no more as it’s here. It was highly anticipated due to its promise to bring about a significant change, rather than just another release, and I think it fits the brief.
vExperts received early access to what’s coming. And there’s plenty to talk about – particularly if you’re looking to simplify cloud operations, boost efficiency, and modernise your infrastructure at scale.
In this post, I’ll summarise the key updates in VCF 9.0 that stood out to me, which I hope will provide enough information for you to select the updates you would like to explore in more detail. Roger did say that he hopes to have more sessions in the coming weeks to dive deeper into each of these, so I’ll look forward to attending those sessions and bringing you that detail.
VMware Cloud Foundation has been around for several years now and has powered both customer-managed and provider-managed deployments during that time. However, it didn’t feel like a truly integrated environment, and it was a work in progress to consolidate the “technical zoo of different products” (as Sabina Anja calls it
).
VCF 9.0 is the result of those efforts and is built around the idea of delivering a true private cloud experience, offering a single interface for both operations and consumption. It’s one interface if you’re dealing with VMs, Kubernetes workloads, or Private AI use cases; the platform now enables seamless management across all of them.
There are several improvements of note that have been made to the core infrastructure that VMware promises efficiency gains in:
As always, there are some considerations, some of which are outlined at the bottom right of the included slide.
VCF 9.0 features security and resilience as embedded components, providing comprehensive coverage at every layer.
The VCF Operations Console and the new installer introduce a guided, simplified deployment experience. So much so that there were a couple of customer quotes shown, and here’s the one that really shows what a difference the improvements have made:
“Once all information was fed into the UI, the deployment was seamless and quite slick. Enabling other components like VCF, VC, and NSX for SSO was very intuitive and simple.”
Fear not, the spreadsheet method and automation remain, but the wizard-based approach offers an option for those who prefer a manual and more straightforward approach.
Other key updates and services of note include:
So, should one upgrade to it straight away? Well, VMware would say yes, and if you’re already on VCF 5.x with updated components (such as vSphere, vSAN, Aria 8.x, and NSX 4.x), you’re good to go. But anything earlier than that (especially 3.x and early 4.x) will require an upgrade path to reach VCF 9.0.
Also note:
I am including the “Ecosystem Checklist” for reference, as it also includes a few other items.
Seriously speaking, like most of you, I’d wait a little before committing to the upgrade. As always, time spent on extensive planning pays dividends in terms of the success of an upgrade.
What’s clear to me is that it’s not just a cosmetic refresh. From improved TCO and deeper AI integrations to intuitive cloud operations and security-by-default, VCF 9.0 feels like it has matured into a genuine private cloud platform rather than just a bundled stack. There are many things to discuss, and I couldn’t include them all in this post, but keep tuned in as more will come in the near future – I am sure!
There’s always room for improvement – say, for newer features like multi-tenancy – but this release lays a solid foundation (no pun intended) for what comes next and for that reason, VCF 9.0 is definitely worth evaluating.
]]>
After attending VMworld/VMware Explore in person for the first time in 2013 in Barcelona, I was hooked, and since then, I could never bear the thought of not attending it. I broadened my circle of friends, which we affectionately call the vCommunity, by attending that event. Since then, VMworld/VMware Explore in Barcelona was where everyone from the EMEA VMware community congregated and caught up with each other. I consider those people as my friends and those friendships are so important to me that I always attended this event, even when work didn’t send me, i.e., on my own expense.
When it was announced that Explore would only be in Las Vegas from this year, there was initial sadness about not having that pilgrimage to Barcelona anymore, mainly because of the familiar journeys, night events, tapas, architecture, etc. However, it also opens the opportunity to experience something different.
Here are some of the reasons you should consider:
I attended VMworld in Las Vegas in 2018. The one thing I appreciated was the ability to meet so many people I knew from following them on X (formerly Twitter), but had never met in person, as they never attended the Barcelona event. It expanded my view of the community, which wouldn’t have been possible without attending the Las Vegas event. Who knows (as there’s only this one large event now), you might still see some familiar attendees. Let’s say I’ll be shocked if you don’t see Marc Huppert there!
All the great things we enjoy about Explore are still true for Las Vegas —take Networking, for example. Some of my most cherished memories from attending this event are the people I’ve met in those years. I know many occasions where those people helped me with a problem, and vice versa. I was given an attendee pass by a generous friend – again, the same community. There are countless examples of someone helping another community friend progress in their career. Given the challenging job situation we find ourselves in these days, the relationships you develop by meeting in person are even more critical than ever.
Over the years, if I’ve been preparing for some certifications or even to gauge my readiness, I’ve taken the opportunity to sit in VCAP or VCP certifications at VMworld/VMware Explore events. They’re typically half the price; many people use that chance to test their knowledge instantly. Thankfully, on all occasions bar one, I’ve been able to clear them. Just make sure to have your jacket handy, though, as it gets really cold in that room, especially given the duration of a VCAP exam!
If you’re already well-travelled, you may have seen Las Vegas many times, and this point doesn’t apply. But I added a few days after the event and discovered Las Vegas properly. It still wasn’t enough, and I had to leave some exploration for my next visit, which is still waiting. There have been some developments since my last visit that I would like to see, e.g. the Sphere and the F1 track route, etc. If you’ve been waiting for a good reason to visit Las Vegas, this is probably it!
All the new product announcements have always been at the US event, and being there gives you the chance to query the experts first-hand. Given all the advancements and talk of AI, I am sure there will be Private AI announcements too. Access to that many architects and engineers at the event’s various booths is invaluable and allows you to pick their brains as those announcements or roadmap items are revealed. On top of that, new Hands-On Labs are typically first built and introduced at this event, and it takes some time for them to become available widely to the world. Sometimes, they showcase the new products and services too; if so, you get your hands on them first.
These are some of the reasons I would still attend VMware Explore in Las Vegas if I could, and I am sure others have plenty more good reasons, too. If some of them make sense to you, get your event pass as soon as there’s early bird pricing until June 16th, 2025. Depending on what’s important to you, some great pricing options are available this year. It goes without saying that while you’re at it, book travel and accommodation quickly before they become more expensive.
If you’re looking to level up your skills, discover what’s new in the world of VMware, or want to meet the vCommunity people you’ve always wanted to meet, VMware Explore is still the conference for you!
]]>As it was the weekend, I decided to have some fun with it too. Being close to dinner time, I thought it would be good to have an application that asks what I’d like to have for dinner and once known, tells me about the ingredients required, cooking time, and any allergen information – along with what it looks like.
The process is so easy that it took me about 5 minutes to create that. So, I started thinking about what else to add. It occurred to me that having the capability to ask a few questions about the dish – before I decide to make it – would be useful. While adding that capability, I thought it would be funny if it was the food answering questions about itself.
So, the “Cheeky and Chatty Dinner Decider” was created. Go ahead and have a play with it. It may ask you to log in first using your preferred method.
While trying it out, I had a “chat with the food” I was thinking of and the results were indeed quite funny. Here’s what happened when I chatted with Fish and Chips.
I also enjoyed my chat with “Smoked Salmon and Avocado Sushi” very much!
You get the idea – not only can you get the recipe information but also get tips on variations, the dish’s origin/history etc. A couple of other “chats” I enjoyed were with “Jacket Potatoes” and “Hawaiian Pizza“.
All of that was done in about 15 minutes so you can see how easy it is to play with this amazing tool and have Generative AI with Amazon Bedrock at your disposal to build and learn about this rapidly evolving technology.
I would highly recommend that you give PartyRock a go. Look at the guidance on the page below and try out some of the accompanying examples that are already there. You can also “Remix” my app and enhance it to suit your taste. Jeff Barr has also written an introductory blog post that goes through the basics.
So, what are you waiting for – go build!
]]>NSX is no different and VMware has been working behind the scenes on that capability. The fruit of that labour is what VMware is calling NSX+ which is a SaaS (Software as a Service) deployment and aims to provide 5 “as-a-service” services:
Policy Management allows customers to define and deploy consistent security and network policies across all locations.
Application Visibility provides network flow recommendations for applications so that more efficient and accurate application mappings can be created. Essentially, it allows you to create a zero-trust micro-segmentation environment so that all unexpected traffic can be dropped, thereby improving the security posture.
Network Detection & Response provides the capability to triage and block/isolate incoming threats in your environment
ALB Controller capability allows the AVI controllers to be deployed and run from the cloud, and finally,
Hybrid Cloud Extension service allows organisations to migrate virtual machines between whichever cloud deployment they might have.
All of these services will be available as SaaS under the NSX+ umbrella and organisations will be able to subscribe to them as per their needs. At launch, NSX+ will provide consistent policy management to on-premises environments, with support for VMware Cloud on AWS coming soon.
In this post, I will pick two key capabilities that I see making a positive impact on NSX’s ease of management and therefore, adoption.
A cool capability that NSX+ introduces is multi-tenancy for self-service cloud consumption. The mechanism works by defining the various tenants in the environment and calling them “Projects”. That part is done by the Enterprise Administrator.
Those projects are then assigned to application owners – with appropriate user rights – to be managed by them on a self-service basis. They become the “Project Administrators”.
From then on, those projects are treated as an entity on their own and the project administrators can configure them as per their needs, with their own logging and monitoring arrangements, amongst other functions. As you can see from the slide, different lines of business areas can have their own project administrator and they can configure their part independently, without affecting each other and best of all, without involving the Enterprise Administrators.
With NSX+, the projects can also span locations which allows those project administrators to keep the policies and configurations consistent across the organisation. If you remember Federation capabilities in NSX, think of NSX+ Multi-Tenant Self-Serivce Policy Management as “federation on steroids” which will allow you to manage all your locations from a single management console.
I am also excited about this new capability of creating virtual private clouds in NSX. Public clouds have had this capability for a while but providing it in NSX, will simplify and accelerate the deployment of standard configurations inside projects.
Defining a VPC will be similar to how you do it in the public cloud today i.e., the interface will ask the project admin about the subnet needs with connectivity configuration and NSX will create that isolated environment for consumption by that project.
As always, you’ll get to see more information on these two key feature enhancements (and the other SaaS components of NSX+) so keep a close eye on upcoming blogs from VMware on it. It will be interesting to see all the use cases that organisations enable using these new capabilities!
]]>
This is an important one! The product in its original offering is well-known and has offered the well-trusted VMware SDDC software – offered on top of bare-metal EC2 instances, controlled by vCenter. To migrate workloads to the platform, HCX is also bundled with the offering.
But with VMware Cloud on AWS, VMware is making the deal even sweeter! VMware is announcing the VMware Cloud on AWS: Advanced, which is effectively the same bundle that you’ve known + Aria Services + Advanced Networking and Security products bundled at no extra cost!
If you look at the components shown in blue text on the right, they represent the additional products that will be bundled with the product at no extra cost – when it becomes available generally.
Please note that these will be available on new SDDC deployments and will only be offered on the i3en.metal and i4i,metal instances only.
There is a bunch of included networking and security capabilities that customers will get once VMware Cloud on AWS: Advanced becomes available too.
Context-Aware microsegmentation isolates and protects applications by providing granular security policies, specific to each application. This is invaluable as in case of a security breach, the effects of it are limited.
As the name suggests, distributed FQDN Filtering granular control over FQDN-based firewall rules which also integrates with DNS-based threat intelligence mechanisms and that protection follows the VM wherever it goes.
User Identity-based Firewall does exactly what it says on the tin! Using it, admins can define user-centric access control policies which can be used in conjunction with a zero-trust security deployment.
NSX+ Policy Management, which should become available with the SDDC version 1.24 release, simplifies security policy management by providing consistent network controls across the board, regardless of the location of that cloud.
As mentioned above, NSX+ should become available with VMware Cloud on AWS with the SDDC version 1.24 release. Once it does, it will offer its services as a (Software as a Service) deployment and will provide 5 “as-a-service” services:
Policy Management allows customers to define and deploy consistent security and network policies across all locations.
Application Visibility provides network flow recommendations for applications so that more efficient and accurate application mappings can be created. Essentially, it allows you to create a zero-trust micro-segmentation environment so that all unexpected traffic can be dropped, thereby improving the security posture.
Network Detection & Response provides the capability to triage and block/isolate incoming threats in your environment
ALB Controller capability allows the AVI controllers to be deployed and run from the cloud, and finally,
HCX Workload Mobility service allows organisations to migrate virtual machines between whichever cloud deployment they might have.
All of these services will be available as SaaS under the NSX+ umbrella and organisations will be able to subscribe to them as per their needs.
This is another one that I’ve been eagerly waiting for. We all know about the storage efficiency and performance benefits that ESA brings to vSAN but so far, it hasn’t made it to the VMware Cloud on AWS SDDC.
Well, that’s about to change! It is set to be made available on greenfield deployments later this year. With the better compression algorithm and performance enhancements, vSAN with ESA on VMware Cloud on AWS will enable even more performance-orientated workload use cases to be run on it.
Please note that vSAN ESA will only be available on i4i.metal nodes only.
As designs and customer requirements evolved since the introduction of VMware Cloud on AWS, external storage options have become available and are now an essential part of an SDDC design, due to the cost-efficiencies they bring with them.
Amazon FSx on NetApp ONTAP is a flexible, scalable, and performant storage option for VMware Cloud on AWS that adds external storage to an SDDC in the form of NFS datastores and it’s available in multi and single-availability zone configurations.
Until now, the only supported connectivity option for this service was to go through a VMware Transit Gateway. While it worked well from connectivity and performance points of view, in cases where there’s a lot of data flowing between the two VPCs, egress data charges could potentially build up very quickly. In such cases, it could cause significant cost swings unexpectedly – which can be a major concern for organizations.
Enter the VPC Peering Connectivity option! It allows a direct connection between the two VPCs to allow traffic to pass without the need to traverse the Transit Gateway. The NFS Datastore connection bypasses NSX and is directly between ESXi and the NFS Storage.
If you’re thinking about adding Amazon FSx on NetApp ONTAP as external storage in the near future or already have it deployed, please have a look at my separate post on the topic: VMware Cloud on AWS: VPC Peering Enables Cost-Efficient External Storage – for more details and some considerations. It will have a significant positive impact on the overall cost of your external storage charges.
As I said at the beginning, this post does not cover the entire list of new announcements for VMware Cloud on AWS at VMware Explore but these are my picks that I think are the most important from my point of view. Please keep an eye on all the various blogs and VMware websites for all the announcements throughout this week.
]]>However, storage is an area where VMware Cloud on AWS has seen the most enhancements, from capability, performance, and cost points of view. Amazon FSx for NetApp ONTAP, in particular, provides a flexible, scalable, and performant storage option for VMware Cloud on AWS – both for multi and single-availability zone configurations.
For customers to be able to scale their storage requirements on VMware Cloud on AWS, regardless of the compute and memory needs, provides a cost-effective way to flex their environment exactly how they see fit.
Here are some excellent blogs on how you can also start using this external storage option with your VMware Cloud on AWS deployments:
In the SDDC version 1.22 release, an enhancement was introduced which allows the vSphere NFS client to open multiple network connections to each datastore mount. These connections are used on a round-robin basis and allow each vSphere host to increase the per datastore throughput.
Currently, 2 connections are supported in this configuration, allowing up to 1000 MB/s going towards each host. That capability may get more enhancements in the future so keep an eye on it.
All of the above is available and you can take advantage of it if you are running VMware Cloud on AWS today. However, I am most excited about the “VPC Peering” capability that is being announced for connectivity between VMware Cloud on AWS and Amazon FSx on NetApp ONTAP because this connectivity option will make Amazon FSx for NetApp ONTAP storage option much more cost-effective for its consumers.
A little bit of background: Since the service became available for consumption, connectivity of a VMware Cloud on AWS SDDC to Amazon FSx for NetApp ONTAP has been through a VMware Transit Connect Gateway. While it works well from connectivity and performance points of view, in cases where there’s a lot of data flowing between the two VPCs (where these services reside), egress data charges can build up quickly – as depicted in the slide below.
As data transfer charges are dependent on activity, it can cause significant cost swings unexpectedly – which can be a major concern for organizations. This VPC Peering connectivity enhancement will remove those associated costs and make the solution far more cost-effective for its users.
There are a few technical considerations to keep in mind:
Remember that at the time of writing, this connectivity option is only being announced but you should be able to get it by the end of the year. Do keep checking with your VMware account manager to confirm when you can have it if you want to use Amazon FSx on NetApp ONTAP as external storage for your SDDC and more importantly, if you have a deployment in use already because it will reduce your running costs for the solution.
While it should become a self-serve option going forward, initially, you will need to raise a ticket with VMware Cloud on AWS Support to have the connectivity configured for you. For pre-existing deployments, once the VPC peering connectivity is established, the traffic will automatically start taking the new route to reach the SDDC and you should see the data transfer activity disappearing from the relevant VMware Transit Connect attachments.
I am excited about this VPC Peering connectivity option and it will remove a major cost concern for customers who want to take advantage of this brilliant storage option for VMware Cloud on AWS – a big win for its customers!
]]>
However, one would be wrong here as there are a few updates that I am sure will be extremely attractive for customers considering their move towards VMware Cloud on AWS.
There are three key updates:
Let’s discuss those in turn…
I first wrote about this service going into preview back in March and the news is that now, it’s generally available for consumption.
As I wrote in that post mentioned above, the barrier to entry for interested customers has always been the cost and that’s especially true for storage-heavy workloads. Having this service generally available will reduce that cost significantly for most workloads and should have a positive effect on the subscription levels.
A reminder that this storage is not as performant as the native vSAN storage but then, such performance is not always required. Also, the native storage is still available as before for workloads that require performance so nothing to worry about there.
The service hasn’t changed from the time I wrote about it so this will do for now. Do check it out if you’re looking to move storage-heavy workloads to VMware Cloud on AWS – resulting in a higher number of hosts. You might just be able to reduce that number now and therefore, the cost.
Like all VMware Cloud on AWS solutions, this one is also a jointly engineered solution which is AWS managed but an external NFS datastore running on NetApp’s ONTAP file storage system and is generally available now.
Virtualisation and storage admins are well-familiar with NetApp storage systems for years. For that reason, its interface and capabilities are familiar to storage admins and so, this feature goes a long way in alleviating any storage management concerns.
So, this is yet another option that helps scale VM datastore storage independently to the number of hosts in the clusters and keeps the cost increment in check. It is a multi-tenant and multi-protocol storage environment, so it provides all the popular protocols e.g. NFS 3/4.1, iSCSI or SMB.
Another key capability is its ability to provide a synchronous mirror across availability zones and that’s one popular ask from most customers I talk to frequently. For mission-critical workloads, that’s one solution that provides peace of mind. Amazon FSx for ONTAP is distributed across availability zones so it’s resilient against a single-AZ failure. Of course, that also means that the service will only be available where multi-AZ Amazon FSx services are available.
Note that in this case, we’re not going through the “connected VPC”. This environment is connected via a Transit Gateway but then also allows multiple VPC to be connected, one of them hosting the Amazon FSx for ONTAP service too.
There’s also clear demarcation in terms of support:
It’s primarily supported by the customer but if things go wrong, VMware is the first point of call. As you would expect, they are responsible for SDDC, NFS clients and the virtualisation side in general. If it’s all clear on that side then VMware will request the customer to open a case with AWS, who will look at the underlying services such as Amazon FSx for NetApp Service and ONTAP configuration issues etc.
Talking about the cost being the barrier to entry for VMware Cloud on AWS environments: Despite the reduction in minimum cluster sizes over the years – a minimum of 2 now – customers have always had to buy i3 or i3en instances as a whole.
With VMware Cloud Flex Compute now, VMware will be partitioning its hosts into smaller flex compute units, which are essentially resource pools of compute, storage, networking etc. Customers will be able to buy as many flexible compute units as they need and increase or decrease them as their computing needs change – which happens within minutes.
This is significant for smaller customers who have found the starting costs of VMware Cloud on AWS to be too high for their budgets. I am confident that it will (once generally available) provide the solution to customers who couldn’t possibly consider moving their VMware workloads to the cloud, due to its starting cost.
VMware is starting the early access program for it so if you are interested, do send a mail to the address listed in the slide above.
It is no surprise that all these updates are geared towards lowering the barrier to entry for new customers and allowing the ability to scale VMware Cloud on AWS datastore storage independently of compute – which is a major source of cost inflation once workloads start running on the platform.
These updates are exactly what most customers (and partners for that matter!) were looking for and I am sure this will result in an uptick in organisations moving their workloads to VMware Cloud on AWS.
]]>vSAN 8 is the result of all that effort and brings a completely new way to take advantage of capable hardware to deliver the performance the modern workloads demand.
I’ll leave a deeper dive into the technology for a later post and cover the most important aspects of this release that caught my attention in this one.
VMware has fundamentally rearchitected how vSAN works with the new generation of devices while keeping the operational aspects for the user the same or as close as possible.
That change has unleashed a lot of performance and capacity enhancements, some of which will be covered in the following sections.
ESA is an optional new capability that you can enable on vSphere 8 deployments i.e. you can keep running the traditional vSAN setup if you want as ESA requires compatible/supported hardware to function. Look out for vSAN Ready Nodes that are already capable in your new hardware purchases to future-proof your hardware.
VMware is calling the architecture currently in use: Original Storage Architecture (OSA). With that in mind, how do the two architectures compare?
With OSA, we’ve become accustomed to having a cache disk per disk group that all the writes primarily go to, before being flushed out to the capacity drives. To increase performance and resilience, one adds more disk groups and the debate on whether to add more disks or disk groups, always generates some passionate discussion. Being around for a while, it supports a wide range of hardware too so the hardware compatibility list (HCL) for OSA is long!
In comparison, with ESA, forget about cache devices and disk groups – it’s all single-tier from here! ESA relies on NVMe-based flash devices and all of them go into a storage pool. The rest is the familiar vSAN software and logic magic that enables flexible data placement, thereby providing flexible configuration, resulting in the performance and resilience levels required.
Of course, the transition to this architecture will be gradual as more supported hosts become available. Once in place and added to a vCenter 8 controlled cluster, it’s simply a matter of Storage vMotioning to the new cluster.
When I wrote about VMware Flex Cloud Storage a few months ago, I mentioned the Log-Structured File System (LFS) briefly. Remember that name as it will feature a lot in vSphere 8 announcements and is the main technology behind most of the storage innovations this time.
The new capabilities of ESA are also built upon LFS. There are still performance/capacity parts within the system, called “Performance Leg” and “Capacity Leg”, respectively. As you would expect, the Performance Leg is responsible for making temporary fast writes to a durable log, with the metadata and sending a fast write acknowledgement. Then the Capacity Leg kicks in and writes large full stripes efficiently to the storage which minimises I/O amplification and reduces the number of write operations in general.
The architecture is designed so that each device in a datastore store all three components i.e. the Performance and Capacity logs as well as the metadata components. That means all devices are claimed into a storage pool and participate in the performance and capacity levels independently, therefore, the concept of disk groups is eliminated.
This is significant as this change means that the failure domain now effectively shrinks down to a single disk. As the data stored on it (depending on the storage policy) is stored redundantly, it removes some of the failure scenarios that occurred due to the failure of a disk group.
So how is vSAN 8 able to improve upon how data is written to the disks? The answer becomes obvious once you consider where the compression, encryption, and checksum i.e. data services are handled in OSA.
As those operations are handled later in the write cycle, it results in inefficiencies in I/O operations in an OSA architecture. ESA, in comparison, takes care of all those services at data ingestion, which enables parallelised and efficient full stripe writes to the capacity space.
As you can tell, it reduces the amount of data that needs to be sent to other hosts, reducing the load on the network but also reduces the number of CPU cycles the destinations host needs to spend before writing that data to the disk – as the data services have already been executed on the data component.
Administrators of smaller clusters are often torn between the resilience of RAID1 and the space efficiency of RAID 5 (or 6). vSphere 8 brings the good news that they may not have to anymore!
In vSphere 8, there are two new configurations of RAID5, and the secret is in how the data is distributed between the hosts. In this scheme, the storage policy automatically adjusts the data placement scheme (it may take about 24 hours before switching to it) to either a “4+1” or “2 + 1” scheme, depending on the number of hosts in the cluster.
That allows administrators to go for RAID5 with fewer hosts and without compromising on the data resilience of the storage.
As mentioned earlier, in vSAN 8, the data services have been moved higher up the stack so they only need to occur once. That is no different for encryption services too.
In OSA, the data needs to be decrypted and encrypted back again, to apply compression and deduplication etc. Performing those operations earlier in the write cycle means that this extra step does not need to occur, resulting in minimising CPU and network impact. At the same time, it reduces I/O amplification as well.
Due to the complete architectural change of vSAN, VMware had the chance to review and improve on how snapshots are taken and consolidated. While the real performance improvements will start coming out soon after to see from our own eyes, I can’t wait to see them already!
With vSAN 8, VMware has made improvements in how snapshots are consolidated. Snapshots have always relied on redo logs and the performance degradation of VMs as the number of snapshots increases is caused by them. They are also responsible for the performance limitations of most VADP backup solutions too.
For ESA, the performance levels have changed dramatically and according to VMware, they’ve seen tens or even a hundred times performance improvements in terms of snapshot consolidation, making the impact of snapshots on VM performance, negligible. That is an enormous achievement and should result in greater possibilities when it comes to backup and restore options.
As a side benefit (as shown in the slide), now one can track how much storage a snapshot is consuming – a capability that was sorely missed before.
Well, indeed there’s something for your beloved original vSAN architecture as well. There’s the ability now to increase the cache tier up to 1.6 TB, as compared to the 600 GB that is the current limit. That is almost 3 times as much cache as is currently possible.
It must be enabled manually and only applies to all-flash configurations but it’s a welcome change and will improve performance and reduce I/O demand on the systems in general as the cache will be able to hold larger working sets.
In my experience, most hosts already contain 1.6 TB cache disks (or above) so enabling it once the hosts are upgraded to vSphere 8, seems like a free performance upgrade that one should not miss.
I was expecting Data Processing Units (DSUs) to feature in vSAN 8 enhancements as well, but we’ll have to wait a bit for those it seems. However, as someone who is quite interested in storage and its performance, I am still excited about these changes in vSAN and hope that supporting hardware starts shipping soon.
There are so many other enhancements that I wanted to cover but there are space and time limitations today. I do plan to cover them as soon as I get the chance. In the meantime, enjoy reading more about these features as more in-depth details are released during VMware Explore.
]]>With vSphere 8, VMware has focussed on four key areas from a features’ perspective:
In the remainder of this post, I’ll talk about my favourite among all the computing announcements for vSphere 8.
Let’s start with the vSphere infrastructure capability I was most looking forward to. If you remember “Project Monterey“, this is formally it!
Get used to this technology as VMware plans to move most infrastructure services to DPUs so that the CPU remains available to serve more applications. Doing so, also improves on security, something that I will talk about in a future article.
With a DPU already in a host, the hypervisor places another copy of ESXi on the DPU itself, which allows it to move the infrastructure services to be served from the DPU card seamlessly – where those services can run faster and separately. Starting with vSphere 8, VMware will be supporting greenfield deployments of NSX running from supported DPUs, such as Pensando and NVIDIA BlueField.
The lifecycle manager will take care of managing the upgrades of the copy of ESXi on the DPUs as well, so no extra management is required there. In fact, it will ensure that the ESXi versions running on the main host and the DPU are kept in sync.
Once the hypervisor has knowledge of the DPU, it is amazingly simple to start making use of it, by selecting the correct DPU from a drop-down list. That enables the offloading of network functions to the DPU and in addition, provides enhanced visibility of the network traffic and security features.
Firstly, I am sure you’ll be glad to hear that with vSphere 8, VMware is consolidating all the various Tanzu editions. There will be a single runtime called “Tanzu Kubernetes Grid” – version 2.0 – which is the same runtime that is used when vSphere with Tanzu is deployed, including the one on public clouds.
Along with the unified runtime, VMware is also introducing a capability that, I think, is a natural progression: “Workload Availability Zones”
As you can see from the slide, Workload Availability Zones allow Supervisor and Workload clusters to span vSphere clusters. Naturally, this is a huge improvement in terms of availability and allows Kubernetes clusters to be resilient across availability zones.
For now, 3 availability zones are required for the availability mechanism to function, and at creation, one can choose either the pre-existing clusters or choose the workload availability zones option. There’s also a one-to-one mapping between an availability zone and a vSphere cluster for now, but I do expect that to change in the future.
Another welcome addition to the capabilities is the introduction of the ClusterClass (which is part of the open-source upstream conformant ClusterAPI) that provides declarative lifecycle management capabilities to Kubernetes workloads. Typically, it’s managed using the management cluster but for Tanzu, that responsibility will be fulfilled by the supervisor clusters.
Not only does ClusterClass allow the definition of the basic deployment, but it also defines the initial state of the deployed clusters in terms of infrastructure packages, network connectivity, storage, authentication mechanisms etc.
Authentication for Tanzu workload and supervisor clusters has traditionally been provided using the vSphere SSO. While that capability remains, the integration of Pinniped with VMware vSphere with Tanzu is also present as an option now. That is an extremely useful addition which will provide seamless enterprise authentication integration with multiple external federated identity providers (IDP).
Pods for Pinniped are automatically deployed on the supervisor and workload clusters as required. Once in place, Pinniped takes over the authentication mechanism for the clusters in question and provides complete independence from the vSphere SSO. Another big tick in the box!
To start, note that vSphere 8 will be the last release to support vSphere Update Manager’s baseline-driven lifecycle management. It is still supported, however, it’s time to remove any dependencies on that mechanism as vSphere Lifecycle Manager will completely take over from it going forward.
Among many, there are a couple of lifecycle enhancements that I would like to highlight in this section. The first is the staging of cluster images to speed up remediation.
Staging does take a fair bit of time when remediating hosts and some updates do suffer when image transfer fails during the process for whatever reason. In vSphere 8, one gets to “Stage All” of the images before remediation starts, making it a much more dependable update. Of course, staging does not require the hosts to be in maintenance mode so separating it out of the remediation process, helps shorten the maintenance windows.
That combined with the new ability to remediate many hosts in parallel, reduces the maintenance window even further. To remediate in parallel, the administrator does need to define how many can be done together as all those will need to go into maintenance mode – affecting availability. By default, all hosts that are in maintenance mode can be remediated together but the administrator can change that number to something different.
Is it really that big a deal given we’ve had vMotion and DRS for years? I’d say yes because these capabilities improve the uptime metrics, and the workloads don’t have to be shifted from one host to another as many times.
Now, this one is probably my favourite of the lot when it comes to lifecycle management and availability.

We all are aware of the pain we go through, trying to protect the vCenter servers, given they’re the brains of a particular environment. We back them up religiously, even if we don’t have a reliable way to test their restoration and pray that they’ll come good if God forbid, we need to restore them for whatever reason. While backups and restores are reliable with vCenter, they don’t remove the challenge that restoration of your vCenter from backup, rolls you back to the state it was in when the last backup was taken – which depending on the situation – could be weeks or even months in some cases.
With vSphere 8, vCenter’s cluster state is stored in a key-value store, distributed between the different hosts in the cluster. In case of a failure, that key-value store becomes the “source of truth” to reconcile all the changes made since the backup was taken, from which the vCenter was restored. For now, it’s just the host cluster membership state but more configuration items will be added soon.
With vSphere 8, VMware is introducing “vSphere Configuration Profiles” in Tech Preview, which is not surprising given the theme of configuration management is popular with this release and is something that’s a given in the developer community already.
Keep an eye on the development and release of this as it will eventually replace the “Host Profiles”. Unlike extraction of a previously configured host, tweaking it and then attaching it to a cluster, this mechanism allows you to define how you would like the cluster to look like in terms of settings, storage, networking and the cluster will configure itself to comply with your stated configuration. Also, in true configuration management fashion, it will also detect drift and in case of any change, will bring the configuration back to what it is supposed to be.
Definitely, something to play with in the lab!
There are quite a few enhancements in this area but let me pick a few.
For starters, there’s a new virtual hardware version which is 20 – we’ve come a long way, right?
Of course, there’s support for the latest generation of Intel and AMD processors and guest OSes but then there are more of device support numbers like support for up to 32 DirectPath I/O devices and 8 vGPU devices.
There are also new capabilities like “Device Virtualization Extensions” that allow vendors to create hardware-backed virtual devices which for supported hardware, allow dynamic direct path I/O with the support of vSphere DRS, HA and even vMotion. In addition, the VMs containing such supported devices can also be suspended/resumed and snapshotted. Such capabilities are vendor-dependent/specific so I will look out for the devices to emerge on the back of this capability.
Windows 11 has been supported on vSphere for a while and the support goes back to vSphere 6.7. If you’ve worked with it, you might have noticed the requirement for Windows 11 to have a vTPM device. However, when organisations want to deploy Windows 11 VMs via templates, a challenge is introduced that the vTPM device is also cloned as it’s also a part of the virtual machine definition, thereby introducing a potential security risk.
For that reason, vSphere 8 is introducing a provisioning policy option that can replace the vTPM device when a Windows 11 template is cloned. Of course, the old policy of copying is still retained as one might want to clone an exact copy of the virtual machine but for larger automated and templated deployments, the policy exists that enables the replacement of vTPM.
We commonly come across situations where the precise configuration of virtual NUMA is important to get the best performance out of a virtual machine. Up until now, however, it has been a tad challenging to configure, through advanced settings and/or CLI etc.
The good news with vSphere 8 is that if you go for virtual hardware 20, then virtual NUMA-related settings become available in the management console for you. Not only that, but you also get a whole tile containing the “CPU Topology” from which you can set or edit the vNUMA settings for a VM with ease. Great, isn’t it?
There are other enhancements to talk about too! Like “Migration-Aware Applications” where applications can be notified of an impending migration event and can take recommended steps in advance, rather than acting on them just before migration. Also, if your VM is based on Virtual Hardware Version 20, it allows you to set hyperthreaded applications to be scheduled on the same physical CPU core now, which helps with the performance of multi-threaded latency-sensitive applications.
I know there’s a lot to digest here and I haven’t covered all the features but do check out all these features in detail as they’re my pick for this release. This major version has brought a lot of new capabilities and features – along with some major infrastructure changes – that make me quite happy as an architect due to their potential.
However, this post was all about the compute side of things. For my picks for vSAN 8, see my next post!
]]>
Are you coming to VMware Explore? I am hoping that I can find a way to attend it as I’ve not missed the in-person VMworld Europe events for the past decade and have even attended both the US and Europe versions in one of those years as well. While I have attended the virtual events for the past couple of years, I think we can agree that they severely lack the best part of attending VMworld/Explore: Meeting and catching up with all the people from my beloved VMware community.
Regardless of the primary reason for VMworld’s existence, for me, it has always been about that (metaphorically speaking, of course!) yearly pilgrimage towards the mecca of the VMware community where I catch up with all my friends in one place and meet new ones too. The place to be is always the ” VM Village” (or whatever it’s called that year) because all the cool kids gather there in the mornings and in between sessions. That’s also the place where I end my event and am always one of the last attendees to walk out of the venue – after getting some stern looks from the security personnel.
Sometimes, I deliver a session but also get to heckle… I mean support my colleagues while they deliver theirs. Another major activity for me is to go to the Solutions Exchange – as that’s where all the vendors enthusiastically display their current and upcoming products and that’s my chance to get quality time with them (read: grill them) to get a deeper level of information than one can get from sales/marketing collateral.
There are also a few events that I try not to miss: The vRockstar party and VMUnderground events that act as “warm-up” events. On the day, we’ve been having vBreakfast for the past few years and then the VMworld party brings proceedings to an end. There are also many vendor parties in between every night, giving you the chance to chill after a busy day of sessions and visiting/hosting vendor stalls. All of these are your chance to mingle with your kind even more and catch up in a relaxed atmosphere.
The reminiscing and jokes aside, all this is what I treasure most about VMworld. If you wonder why VMware has such a close-knit and helpful community, I credit VMworld and related events for being the main reason. Attendees get to put faces to names and develop deep relationships – even friendships – and that has a major positive impact on one’s career. I know that for a fact because I’ve been a beneficiary myself and have also tried to help as many colleagues as I can over the years. I also see examples of it every day on Twitter, Slack, LinkedIn and other platforms. Everyone has each other’s back and even in tough times like job uncertainties or loss of it – the community bands together to get them back up and running in a new place quickly.
As we know the branding of VMworld has changed to VMware Explore for this year. Everyone from the community I know is hoping that the general format of the event remains the same. For me, all that matters is if everyone and more importantly, the vendors treat it the same way as they have before because if so, VMware Explore should be the same experience as it has been for me and everyone who thinks similarly about this event.
So, if you haven’t made up your mind yet, I would highly recommend you try to attend it if you can – even if this would be your first time. I am confident that the hardcore attendees will try to keep the atmosphere the same – in fact, VMunderground is planning to be there at least for the US event. If you also value all the things I mentioned above, you won’t regret it. Whether or not I will be there, will depend on the powers to be but rest assured, I will try my best to be there too!
]]>