VCF Automation 9.1 introduces declarative infrastructure management through Kubernetes-native APIs, enabling organizations to provision infrastructure automatically via desired-state specifications rather than imperative scripts. The platform provides Containers as a Service (CaaS) for lightweight container workloads without full Kubernetes cluster overhead, while supporting full Kubernetes clusters for complex orchestration needs. Enhanced service management allows providers to centrally control and publish platform services to tenants, with project-level content libraries enabling self-service environment deployment. App stack formation through namespace capture allows administrators to generate infrastructure-as-code blueprints from existing environments, facilitating rapid, consistent deployment across projects. This automation layer transforms traditional infrastructure operations into cloud-like self-service experiences, where developers can provision resources independently while maintaining policy-based governance.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Self-Service Infrastructure with VCF Automation 9.1
Added:[music] [music] [music] Hey, welcome to the virtually speaking podcast. My name is Pete Fletcher and joining me as always is not John Nicholson, but my good friend Jad.
Jad, how you doing, sir?
>> Hey, Pete. Good. Doing good. Just dealing with some smog. It's about 100 degrees outside and the Ottawa fires have made their way to DC area and um we're not allowed outside.
>> So that's been fun. But uh [laughter] yeah, but other than that, doing good.
Doing good. Looking forward to uh one of my favorite topics today.
>> Yeah, this is a great topic. I'm looking forward to it, too. Like man, as you know, we've been covering VCF 9.1. We've gone through so many things. Like we've gone through all of the compute, the storage, the networking. We even covered some security. We did some uh life cycle management. We've we've been covering a lot of the infrastructure aspects, but I feel like, you know, it's nice to move up the stack a little bit and talk about something that's probably more interesting and certainly to, you know, engineers, developers. Uh I I think automation in general is is definitely a much more exciting topic. Uh VCF automation specifically, uh there's a lot to cover and there's a lot that happened in 9.1. And so I'm excited to announce for the first time on virtually speaking and I'm gonna try and pronounce this properly. Maher Alasar Mah Mahair, welcome to the podcast. How'd I do by the way?
>> No, you did great. [snorts] >> Excellent. Excellent. So Mahar, tell us a little bit about yourself. I know you work in the VCF division. Uh what's your role in this?
>> Yeah, so my title today is product marketing engineer. It's really uh everything around technical marketing when it comes to VCF automation. I've joined uh VMware in 2013. So I've been here uh for some time and that's all I did is focus on VCF automation as a as a component.
>> Oh okay.
>> How you know Jad?
>> Yeah. M and I go way back. We're brothers from another mother as they say as the kids say. Um, no, I uh for for those who have uh have kept track, um I've spent a lot of significant amount of my career at VMware on automation.
Although, if you were to check my blog, the last update I had uh was on 7.3, which I'm quite ashamed of, [laughter] but for some reason it still gets hit.
So, I'm I'm not touching it. But anyways, >> dude, I still get I still get messages from blogs that I've written about like VSAN, you know, many many many versions ago. Like, hey, VCM work. I'm like, look, I don't do that anymore.
>> I I just don't know how to respond. I was like, you're asking a question on a product that you shouldn't be on anymore. But uh [laughter] but anyways, um Maher is is uh is basically uh the the go-to um especially inside of our company. Um but uh huge track record and huge following in his videos and everything he does. So I'm super excited to have you on Maher.
>> Thank you.
>> And [clears throat] um what we're going to talk about is al also some of my favorite features coming into um VCF 91 or that came into VCF 91. So >> should talk.
>> Yeah. But before we even get into what happened in 9.1, why don't we set the level uh and just talk a little bit high highest level like what exactly is VCFA and how does it all fit into VCF?
>> Yeah, sure. Um I'm just going to put it really uh simply. uh VCF automation uh which we used to call uh prior Arya automation is really the automation >> and V realize automation realiz before that and >> yeah exactly >> but anyway yeah >> uh is really the automation platform that is built into VMware cloud foundation today and uh basically it provides the self-provisioning of infrastructure automation it leverage that Kubernetes native API uh in the new features we'll talk about that in a second it has policy based governance it provides also day2 life cycle operations and this is all to help instead of uh c to help customers instead of opening tickets instead of waiting for the administrator to you know email you back uh infrastructure basically can be requested and provisioned automatically uh compared to what some uh companies still do today, which is the traditional model to to to provision uh things like virtual machine networks uh using VSCenter or using manual workflows or scripts or ticketing systems and which ultimately leads to things like where the request takes really long times. environments are slightly different u from how was provisioned yesterday for example compared to how it was provisioned today. So automation becomes really difficult to maintain overall and this is where VCF automation shines really >> you know and M I I don't know if we share the same feeling on this but um back in my automation days um Vra or VCF automation was really about automation right it was um event based triggers and and just kicks off pipelines and does all this stuff and >> um and it also helped us get in front of customers and and colleagues and say Look, look, if you could automate it, if it's if it's got an API, if it's got a workflow, if it's got an orchestrator workflow, we could automate it. Right.
>> Right.
>> But but the in since VCF, especially since 9091, I feel like automation is just one of the things that VCFA is really focused on because we've seen a lot come into it. uh you know namely in in life cycle management which I guess could be automation but but uh even more so um on the Kubernetes stuff on um you know in container management and things we're going to talk about hopefully today but you know how do you feel about sticking to the name automation and do you think it still fits do you think there's opportunity for us to maybe evolve that one day >> yeah I mean uh it it it does I mean there is a uh big big industry shift happening today. Uh so we're moving from like let me call it click ops or manual operations or imperative scripting towards this declarative infrastructure and VCF9 allows us to uh to go to that uh specific uh way of or shift I might say which is declarative infrastructure.
So instead of saying hey do these 25 steps we simply say okay this is the desired state and then the platform itself figures out how to achieve it. So it's still automation but also the really biggest take is that uh we're following one of the biggest trends in the industry and that's is Kubernetes is not just for containers anymore. It's becoming the universal language or control plane to provision infrastructure as well. Uh um things like virtual machines as Kubernetes objects. Uh still everything becomes Kubernetes object and becomes declarative. Um so I think still it it is it is a big part of automation and the infrastructure as code and the get githops operations in general.
>> Yeah. And you know you were talking about containers uh and I know that's one of the things that came out in 9.1 was the containers as a service you know which is already adding to the existing VM services and the VKS runtimes but tell me a little bit about why do why do you think we need this containers so much as a service? Yeah. So container service was always supported in uh on the supervisor side and uh through the command line. Uh but it wasn't it wasn't uh u available in the in the UI itself within VCF automation and we brought that in the UI in u in 91. Uh so running Kubernetes and running containers um are not really the same thing if you think about it and there's very different use cases here. But why would you run a full Kubernetes cluster with its overhead for example when all you need is a simple container? So as a cloud >> Yeah.
>> Yeah. I'm sorry. I mean that's some of the feedback we got because you know we got behind VKS um and and there was a there was a lot of investment in getting VKS built in here and getting out there and and as as you know as capable as a Kubernetes that Kubernetes life cycle and management is into VCFA we always went back to the basic C that you know the customers like well what about containers you know we still have to do that in vsenter we do it directly um you know when when can I bring containers into the same exact pipeline or workflow or or even just under the capabilities of VCFA. So, um I was surprised to see it come in this quickly. Um which which I I think was refreshing to a lot of our customers as well.
>> Yeah. And and and the UI con uh uh sort of aspect of the of the service came into VCF automation. Like I mentioned, it was always there that you would be able to provision vSphere pods uh directly within the vSphere namespace.
But now in VCF automation 9.1 as a cloud consumer you would use the container service via the UI the command line uh or use it via any CI/CD tool when you need the speed and the portability of a container but without having that like like I said manage the a full Kubernetes cluster and there's a lot of benefits when it comes to the container service itself we hide a lot of the complexity and make it really easy. So you don't have to be a Kubernetes expert to be able to use and provision containers.
They're secure, isolated runtime.
They're super fast uh in startup and scale. Um so they're pretty much optimized for low latency provisioning uh near instant startup. It's super fast. I can't even tell you how fast these vsere pods comes up. But in a nutshell, they're they run in a VMbacked sandbox if you will and uh provides isolation if you would compare it to upstream Kubernetes.
These uh containers uh eliminates the shared kernel model and really reduce the risk from like noisy neighbors or containers escapes. So, so at what point do you think this container service, you know, fully outgrows itself and and then you need a full VKS cluster?
>> Yeah, that's a that's a great question.
Um usually uh the container service uh and its framework is for simple workloads and when a simple workload becomes uh a real application platform where now you need orchestration or you need full orchestration or contain container orchestration you need scale you need resiliency you need Kubernetes operators or thirdparty tooling then it is time to move to a VKS cluster um So that would be when you would realize that okay uh so I've I've used the container now I'm going to go to something bigger where I need orchestration and that would be the uh primary reason for moving from the container service to VKS.
No, I I've heard and I don't agree with this, but I've heard some folks say like, "Oh, well, you know, you use containers for your sandboxing, you're playing around making sure there's validation." Um, and then, you know, when when it grows up and uh um and is ready to be a full functional enterprise app, that's when Kubernetes comes in.
But, but technically, Cass um is a production level service. You agree?
>> It is. I I totally agree. I mean remember uh it depends on the architecture of the supervisor that's backing that that container service as you know supervisor can be deployed in a high availability cross zones multiple zones these zones can be backed by one or more uh vSphere clusters so if you're a supervisor behind the scene that's running these services are already in an HA um I don't see a reason why these containers can't run production applications. I'll give you a really fun um uh exercise that I did um uh while I was testing uh 91. And usually this is what I do. So if I wanted a really quick command line like VCF CLI >> uh today, for example, if you want to set up your VCF CLI, you have to like I like to use Linux personally. Uh so uh I would have a Linux VM and then I would download the uh the binaries for the VCF CLI, copy it over, install it, install the tools that I use, things like cubectl, arg command lines, all the command lines that you would need for example. So I actually used the container service and created my own image where I bootstrapped all these the VCF CLI all the plug the plugins it uses and I made it available internally uh in our private registry and anytime I want the VCF CLI all I have to do is docker pull or even run it run it using the container service. So just basically point to the OCI that I uploaded which is a Docker compliant uh container image and I would in seconds I would have a prompt where I can use the VCF CLI right away without having to go through the setup of that VCF CLI.
>> That's a it's actually a pretty great use case. Now, do you do that is it a does when you spin one of those up, do they are they there permanently? Um or do you use it more like a serverless type of capability where you spin one up with an application and use it temporarily or >> Yeah, I mean dedicated jump box.
>> Yeah, I mean if you have the resources, you can keep it on and you can use it uh permanently basically. Uh, but the nice thing about it is that I can spin it up for a few minutes, uh, do whatever I need to do, create my context, test something out really quick, and then get rid of it. Um, if I need it for that for if I know I'm going to need it, I can just uh, keep it. And also the container service is backed by the um, infrastructure services like the storage volume or like the volume service or the networking load balancing. So for example the when you provision a container automatically it's going to be on a private uh VPC and so I would uh instantiate or install along with the container service a load balancer anytime you create a load balancer using the load balancer service it's going to right away uh get an external IP and then that's how I can SSH into that container right away via the load balancer. So all the uh infrastructure sort of support uh service supported services I call them uh like uh uh uh storage networking uh load balancing uh those are all available uh as well with the service.
>> Yeah. By the way, you're not one of those Linux guys that used to play with Gen two, are you? [laughter] >> Maybe.
I kind of figured.
Yeah. Yeah. one of those hardcore Linux guys that wants to do everything, you know, naked, bare, you know, completely secure. Yeah, I get it.
>> I mean, if you just want a command line, I mean, Linux is the perfect uh and also for container when when you're actually create creating your container images, you can use uh very uh small footprint OS, >> uh Photon, uh Ubuntu.
Um yeah.
>> Yeah. Well, you were talking about service management and I know there's been some enhanced uh service management that was announced in 9.1 and I'd love to hear more about that because I feel like this is an area that's probably not so well understood in the VCF community.
So maybe we can just start by just covering sort of this whole you know you know this whole idea of enhanced service and then talk about what's new in 91.
>> Yeah absolutely. I mean in VCF uh automation 9 we started with the service uh uh management framework. Uh so as a provider and in the provider portal you as an enterprise I or I mean if you're if you're a managed services uh vendor or ISP or MSP or however you call it today [snorts] um or enterprise IT in an organization you can control what services that you want to make available on a region level. So for example um let me step back for a second like when you set up uh when you enable the control plane which is a supervisor in vSphere uh out of the box you have all these core services like the virtual machine service the the kubernetes service the volume service the network service these are there out of the box and built into the platform but also the platform or as a supervisor is very extendable so you can extend that platform form beyond just those core services. So historically to add a uh an extended service like let's say docker as a private registry you had to go to the vsenter side and you had to have credentials to access venter as the virtual infrastructure and deploy those manifests to enable or extend the platform to support and be able to instantiate let's say a harbor instance where you can store your private images for your containers. So now the services framework uh or services management framework within the provider it's uh you control who gets access to that service uh as a tenant or an organization. So and uh in what region you want to make that service available and all that can be done now from the service provider in VCF automation you deploy the service. We do have VCF services that are there out of the box like for example all the monitoring stuff those are automatically deployed the minute you create a region uh and uh for those that don't know what a region is NVCF automation is basically a collection of supervisors so this is where we uh consume our resources like CPU memory storage and then uh share these resources accordingly to the different tenants that we're managing so once the region is created these out of the box services like for example uh monitoring uh like for example autoattach with uh the VKS cluster management uh at the same token we have uh services that are uh available out of the box but not necessarily installed like for example the secret store service the harbor service so if you as a provider want to make that service available and you want to extend the supervisor platform to support additional services you can do that now from the provider portal as a enter as as the enterprise IT in your organization or as a uh service provider >> so the service is like just not enabled is that what it is or it's just there but it's just not enabled >> yeah so they will be there like uh and uh we keep adding more services with every uh u uh version that we release uh but yeah so for example an example uh an example of services that are there out of the box but not uh installed by default is the docker uh sorry is the uh not docker is the harbor service and the uh secret store service >> also [snorts] the I think the encryption management the bk that was introduced in 9.1 um >> that's also available DSM uh data service manager is another one uh when you want to enable uh database as a service >> yeah and I think the benefit is that while it's not pre-installed per se, it is instantly available, >> right? So, we don't have to do what you said, the whole setup, the the separate the separate motions. You just basically turn it on and it becomes installed >> and then it can be assigned and used.
Yeah, that's that's cool. So, uh Pete, I think we should put a link to um some of the content that I think Maher, but as well as some of our other colleagues have put out there on the services that are included. Um I think that'll be a good attach for this session. Yeah, I mean I have a we've released u u the VCF9.1 automation series. You can find that on the VCF uh on the VMware Cloud Foundation YouTube channel.
>> I sleep I sleep to that every night.
Mah, it helps me [laughter] go. I love it and I wake up just thinking. Great ideas. [laughter] >> Thank you.
>> Got that DJ voice. It's It's wonderful.
>> It's like It's like ASMR but only with VCFX. [laughter] >> Exactly. Yes. It's as mahar. No, doesn't work.
>> No, it doesn't work.
>> Centralized service delivery.
>> Yeah. Yeah, >> exactly.
>> I like it.
>> Um, so I mean I think I think this was a really a good example of a followup from customer beefs, right? They we we made all these announcements in 9.0 like the centralized services, but it was like in Vsenter. So it really broke it really broke the model that we were really trying to portray.
>> Yeah.
>> And uh it was good to see 9.1 we we took the we made the effort to to fix it and centralize um how services are are you know brought in, how they're published, how they're made available and >> their life cycle.
>> Yeah. Yeah. So that was that's another good one. Um I personally haven't uh deployed too many services in my environment. I'm still um playing with just some of the core stuff uh based on the work I'm doing, but um but yeah, I got to get I got to get a little bit deeper into how to quickly build out that ecosystem with just what's in in the box or out of the box.
>> Yeah. And you'll see us uh in uh future releases more and more of these services are going to be easier and easier to deploy and make available to and share with uh one or more tenants or organizations managed by a BCF automation.
>> Yeah. Now what what are the like what backs the service store like how how are we able to to build these services into the the package? Do you have the >> the intimate details that you can share?
Um I mean uh to my knowledge uh and based on my discussions with engineering and uh product managers some of these services are uh available within the uh VCF automation itself and some of these are coming through the software the online depot. Uh so it's it's a mix right now but we're trying our best to standardize and uh really capitalize on centralizing uh all these services uh to make it easier to deploy to make it easier to maintain secure and uh entitle who needs the service uh from a tenant management perspective uh and make them available uh for you know the consumers such as developers, SRRES in terms of uh there is one really big uh announcement coming in in the next release which I I'm I'm not going to I can't talk about it here because this is uh it's still a road map item but you will uh watch out for the new announcement uh u to explore.
>> Yeah. [laughter] >> Now just to bridge the gap between the services that happen at the platform level and the services required at the for example VKS or Kubernetes cluster level.
>> Yes. there's there's a separate mechanism that allows the life cycle and management of of services at that level, right? That's built into VCFA. Can you talk a little bit more about add-on management? And >> yeah, so that's the uh so when it comes to uh services or packages or add-ons onto the Kubernetes clusters like VKS clusters, that's totally handled by the uh depot service within the VCF stack uh within within uh uh VMware cloud foundation. So uh one uh so the way it works is if you auto provision if you pro provision a VKS cluster today like a VKS cluster using VCFA uh this cluster will be autoattached to what we call Kubernetes management uh so this is where it's a central location to manage a fleet of VKS cluster and uh with the latest release of the Kubernetes service we are we introduced an add-on service so there are a set of core services that gets installed or packages uh I should say that gets installed on the VKS cluster things like let's say um u agents that we use for monitoring open source uh like telegraph prometheus um um those automatically can autoscaler for for the VKS cluster the minute the VKS cluster is autoattached to the Kubernetes management system within VCF automation these uh uh we automatically add the standard repo that holds these images and roll out uh any uh packages that we see uh any core packages that we need to install on the system. Uh of course you can add uh as a D2 operations um uh other packages like we support really a a long list of packages I think STTO and other like cert manager and other uh packages are available. uh those are can think of right away. Um those are uh all uh via the uh software depot uh that would be configured or VCF is using you can use an online depot uh if you're a connected site uh or internet connected site or if you're a dark site you can use offline uh software depots.
>> Yeah. Yeah. And that add-on management library, I mean, presumably it'll continue to grow as we keep uh doing what we're doing in the CNCF community, right? Um and and how we're, >> you know, positioning VKS and how we're aligning with that rest of that community.
>> Um I do know of many efforts to to validate and do some some scalability and and engineering level validation of these packages. And then essentially we'll see that add-on uh management library, the built-in one, continue to grow and grow. So it it takes the ease of of pushing packages to um to my Kubernetes clusters um and and then takes advantage of all the other things that we're doing in life cycle and and cluster management and everything and arbback and and so we have real fine controls and governance of of that whole process. So it makes it makes getting those packages on there um incredibly easy. Um and trustworthy actually.
>> Absolutely.
>> Very cool. Yeah. [snorts] >> Yeah. Well, another area that I one of the areas that I was first fascinated with back in the days of uh vrealize uh was blueprints just in general. I thought they were a cool concept and I know there's been a lot that's changed uh specifically appstack formation. So maybe we can talk a little bit about what's new in the area of uh appstack formation.
>> Yeah, abstract formation is the name of the use case. uh but in the product uh uh this is basically uh points to capturing a namespace with its workloads uh as a blueprint. So >> so Mah take a second to to describe what what a vSphere namespace is in this context um because that's a relatively new construct um that fits into all of this. So what is what is a vSphere namespace and what what could it hold?
What does it define?
Yeah. So it's a it's basically uh an environment. Uh it's really a vSphere namespace. So today uh if you go and access the uh the supervisor or within the vSphere client, you can uh create a vSphere namespace, add the certain uh VM classes that represents t-shirt sizing for uh for virtual machine workloads that you want to provision. uh you can attach content library and you can also uh control the amount of uh resources you want this name spaces to consume.
This same concept uh in vsenter today is is a onetoone mapping. So if I need to create a namespace I would have to go to the vsenter and create that namespace.
Now in VCFA uh it's uh since it's a higher abstraction uh and it's higher in the stack from a consumption perspective every project that you create in VCF automation today can own one or more namespaces and these namespaces can be placed across regions. Uh in a nutshell, when a namespace is created for a specific project, the project users can interact with the IAS services and deploy workloads into those namespaces.
This namespace has a specific network boundary, has a specific uh set of uh resource limits in terms of CPU, memory, and storage that they can consume. So it's really uh think of it as a as a as a playground or an environment where you can deploy uh your infrastructure in.
>> Yeah. I mean an important distinction I think would from vSphere namespace and Kubernetes namespace should be echoed right. I mean these are very different things but the takeaway is that the what we did in on the vSphere side is is really try to replicate um that those con the constructs of u of of the namespace and and treat it similarly but at a much higher abstraction layer. Um it does remind me of of some hybrid version of what a vap was in vsenter and the vap in vccloud director there's some combination of that got us to where we are today. And of course we've that IP has also gotten us to where we are today. So let's dig a little bit into that. So I've got my namespace. I've got um that name space namespace is established and it's running applications and it's got my storage and networking and policies and all that stuff.
>> Back to um AppStack. What what can I do at that point? Yeah, I mean in a in uh in in uh in simple terms uh uh today you have a namespace you have let's say uh for example a set of work uh a number of virtual machines you've configured those virtual machines within this namespace you configured your environment uh let's say you're an AI data scientist and you have access now to a number of virtual machines and you've set up all the tools uh all the uh uh language models all the controllers, all the uh inferencing uh uh applications you want to use and now you want to uh stamp it or um take a copy of that application and deploy many of those uh for other uh project users. So basically think of this uh depending of course on the capture I'll talk about the capture and and the different types of captures that available to you but you can basically take an identical copy of this namespace everything uh from the virtual machines what was configured on them the network they're connected to the IP address that they're configured with the volumes that they're they they're they're accessing uh the uh services and the load balancing uh uh that some of these VMs may may have access to because uh if you're doing identical capture uh you're pretty much on a private uh VPC and maybe one of those VMs or two of those VMs have load balancer where you can access them from the outside like jump boxes for example.
So the idea is that we go through some validation first to make sure things are uh set up right. There are prerequisites uh to the namespace capture for it to work. Uh but without going into too much details, the namespace once the namespace capture is is captured uh you need uh a content library, a special kind of conent library uh which is a a project level conent library. This is where we when we capture these uh virtual machines, we publish the images of those virtual machines into a writable uh project content library and we store those images there. Uh once the uh images are published, we actually take and generate. And this is amazing because if you never used blueprints before, uh you can actually learn from capturing a namespace and look at how the blueprint was kind of constructed and was generated >> reverse. Exactly. So you have YAML uh infrastructure as code that basically represents the name space that you just captured.
Now once you see the blueprint and you go into it and you go through and make all the modification if you wanted to like this is your opportunity to add more to the uh namespace capture like for example one of the things I'll I'll say here in 91 as of as of 91 uh we can't capture for example a namespace when it have when you when you deployed in a a kubernet cluster so uh uh as of today and in 91 one uh you can capture a namespace as as long as it only holds uh virtual machines as workloads. Uh so hopefully in the next release we'll we'll uh uh extend the the supportability to have it include VKS cluster but at this time uh if the blueprint let's say get generated you can add a VKS cluster element to it. You could add a container containers uh to it. You can uh modify uh any of the resource consumption uh if you wanted to. And then once you're ready and test test the blue gen the generated uh blueprint, you can publish it to the catalog.
>> And now you're ready to >> Yeah. And this does get us on par with what VCD did um before. Exactly.
>> A lot of this technology got folded in.
Right. Most level.
>> Yeah.
>> Yeah. I remember when you had a V app that you built in VCD and you set up your active directory and you've set all the different applications and now you want to make it available for the next person.
>> You would capture that V app and it would write that V app directly to the catalog. This is exactly >> pretty much the same kind of uh but done a little bit differently where we have infrastructure as code behind it backing it up.
>> And fun fact, it's also how we ran hands-on labs at Explore. Oh yeah, I would imagine that I'm sure hands-on labs is a big use case for that story and I'm sure there's others we can talk about, but um from a I always go back to storage. It's it's in my DNA. But when you're making these uh you know, are these essentially are almost like clones or stamps if you will? Like is is there a storage penalty for that or is it are these just like you know?
>> So it depends. Yeah, it depends on what you're capturing. Like if you have a VM that is utilizing I don't know like 100 gigabyte of storage, you're capturing 100 gig byte of storage. Uh so that that's how big is the image. So one of the things that uh uh to keep in mind if you're prepping uh or configuring a namespace to capture it as a let's say a sandbox environment or of some sort you have to keep that in mind to to make sure that things are and this is exactly the same kind of principle you would use if you were to use vloud director for example you don't want your images to be super big uh just enough to uh carry the functional functionality that these VMs needs to And once it's deployed, uh so this is the really the uh the the really um now that you defined the namespace and you generated a blueprint and you put it in a catalog and now you have multiple different project users deploying such an environment when they need it, they can always do uh and apply day-to-day operations on those workloads. So if a VM needs more storage, they can go and do that. It's a brand new environment, right? So that they just deploy it from let's say the source or the golden image.
>> So you make your your master copy or your the parent like the source image as efficient as possible and then and then make the the changes or inflate the disk etc. uh upstream. Yeah.
>> Exactly.
>> And and there's two kinds of captures if you will uh when it comes to namespace capture. Uh one being like I mentioned identical copy. This is great for let's like you said ho uh hands-on lab hos or if you're doing sandboxing like sandbox environment and you want multiple user to use it without a without a conflict as long as as uh remember when you're deploying these environment you're deploying it into uh in the context or in the realm of the project and how much resources that project have in terms of the name spaces they have. So everything is controlled from an org administration perspective. Um once you run out of uh CPU for example, you will pretty much know right away that you ran out of CPU and you can deploy more of those deployments. So it's not like u uh wild west. It's controlled by enterprise IT depending on the policies that you enforce on the organization that's using uh these features.
>> So the uh so you mentioned identical um the capture mode. So identical and customized, right?
>> And yeah, custom capture. The custom capture allows you to um uh expose, for example, let's say if you if one of the VMs is super small and uh the namespace cap the namespace or the source namespace have small, medium, and large.
as one of the options available to you when you're doing the capture. And before the generation of the blueprint, you can actually simply click a check a a check box to say, "Hey, expose and allow the requesttor to select different VM classes as long as they're supported within the source name space class that you uh captured. Um, so every namespace that you create gets created from a template. that template we call namespace class. Uh the namespace class holds all the configuration uh that uh gets applied on the uh on the namespace when it's provisioned from that uh namespace class. So for example, if you have a namespace class that is configured with 100 GHz of CPU, when you deploy a virtual when you deploy a namespace from this namespace class, you're going to get a namespace configured with 100 GHz of CPU and you can't go above it. Uh so with customization, uh similarly you can select and choose what VM classes you want to make available within the namespace. So if if the only uh t-shirt sizes you want to make available for the project users is small, medium and large then those are the name space uh those are the VM classes that would be available uh within the namespace but that not necessarily so if you have a VM that was provisioned with a small t-shirt sizing uh within the customization capture you can allow the user when they request this deployment to select medium for example or large or provide their own pass uh password for the um uh root user of the of of the virtual machine or the administrator account of the virtual machine if it's Windows.
>> Now, one more one more thing that that I actually really love um which is another HOL or whatever. So, when we do HOL, we have um domain controllers in there, DNS boxes, jump boxes, firewall. Those are going to be specific to like MAC addresses and IP addressing. And as you know, when you clone a VM, >> um it's going to get a new virtual MAC.
is going to get it possibly most likely a new um IP and so on. But to do what we're doing here in the identical capture and reprovision, we're really just taking a a a snapshot of the entire configuration including >> MAC addresses and stuff. So I can spin up like identical machines with the same virtual MACs fully encapsulated in what would be an isolated network obviously because we can't have those conflicts.
But I think that's a pretty awesome use case um and and how we would use it as well.
>> You can preserve MAC addresses, preserve IPs, preserve the names of the um uh virtual machines themselves and the name of the and preserve the name of the OS uh as well uh when you're doing identical capture.
>> Nice. I like it. [clears throat] Well, I want to be respectful of your time. I know we uh we're running short on time, but um the last thing I wanted to ask you was about uh the project content library. Now this is not a new concept.
This is this was in vSphere and VCFA.
But what what's new in 9.1?
>> Yeah. So project content library is actually new in VCFA 9.1. Prior to that we have the organization content library. Uh so organization content library was a content library that you can create uh uh as an or administrator assuming the provider gave you that permission. So uh uh actually let let me uh let's talk about conent library really quickly. A provider in VCF automation can create a content library and upload all the images or common images to it that would uh a tenant uh want to be uh wants to use to when provisioning virtual machine like Linux, Windows, Photon etc. Um if the provider uh creates a content library, it will automatically share it to all its tenants. So if the provider managing four different organizations, four different tenants, all four tenants will have access to that content library and its content. Uh so you don't have to manually go to vssenter and create these content libraries. It is automatically done behind the scenes. So once you create it from the provider portal, it'll automatically uh be created in the respected uh vsenter depending on the region you're creating the content uh library in. Now the org admin uh once they're handed the keys to the org that they're managing, they can create their own also content library. But that content library will will be available to all the projects if it's autoattached. So these things are when you create a content library there's a toggle that says hey do you want to make this content library available for existing and future name uh uh projects.
If the answer name spaces if the answer is yes which is the default it will be available to any namespace you create now and uh later on in the future. The project content library is a little bit uh unique in a sense. It's a project level content library and it cannot be shared with other projects and that's what uh uh is uh new in VCF 91. So if you're a small project and you want to create your own content library and you want to have the ability to write to it and publish images to it, you can do that in VCF automation 9.1. It happens to be the project content library happens to be one of the prerequisites to be able to capture a namespace. So um the namespace uh for namespace capture to work you need to have uh at least one project uh content library where the namespace you're capturing uh uh exists.
Now I think one of the big important pieces here is granularity when it comes to like arbback access. Who can write who can read? who has access to it.
>> Exactly.
>> Um and the other one is sprawl, right?
Instead of having to build these templates or or build these contact libraries that will work for everybody.
Um and for some people it's extra noise, for some people it's not enough.
>> You can be very particular um at the project level and who gets what and and who can see what, right?
>> Give them also some self-service capabilities.
>> I like it. I like it. Well, if you're listening to this, jump on over to the YouTube channel. We'll be sharing plenty of uh links. I will leave all links to um to all of the announcements for VCFA9.1 in the show notes of this podcast. But uh you know, Mar, you you've been a great uh guest here on Virtually Speaking. I want to leave you with the uh with your your closing thoughts. I'll give you the last word here.
>> Yeah. I mean, if you're a customer and you're deploying VMware Cloud Foundation today uh 9.1, don't stop. Please don't stop after deploying the infrastructure.
leverage VCF automation because that's where really the real value starts. Uh everything from self-service, Kubernetes native automation, infrastructure as code, let me see what else, get ops, policydriven uh governance, faster delivery, better developer experience and uh cloud-like operations on your own infrastructure in your own data centers.
>> Yeah. I I and and [laughter] I said I was going to leave you with the last word, but you definitely when you said that you made me think one more thing to ask you. Do you get that a lot from customers like like cuz I would imagine you know everyone you know you've got your VSAN you got your storage folks you got your networking folks you got your you know vSphere folks and they get everything together in VCF but I think is in your experience do c are there a lot of customers that they they struggle to get over that next level where this is where the real magic is? Yeah, exactly. I mean uh and this is the really natural next step uh once you set up VCF as a full stack uh uh private cloud uh operating model. This is where basically where VCF uh automation comes to shine. Um uh like I said uh there's no cloud if you will without VCF automation because without self-service can you can you really say I have a cloud?
>> I like that. I'm going to leave it on that. Thanks for joining us on virtually speaking.
>> My pleasure. Thanks.
>> Thanks, M. Always a pleasure, buddy.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23