Skip to content

Latest commit

Β 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

VMware Cloud Foundation (VCF) 9.1 in a Box

Deploy a fully functional VMware Cloud Foundation 9.1 environment on one, two or three physical ESX hosts, optimized for development and lab use. This setup enables users to explore the full capabilities of VCF 9.1, ranging from Fleet Management, Self-Service Automation with Multi-Tenancy to running modern container and AI workloads, all while using minimal compute and storage resources.

πŸ“’ This deployment does not use Nested ESX and instead runs directly on physical hosts, in contrast to the VCF Holodeck solution.

Table of Contents

Changelog

  • 05/28/2026
    • Initial Release

Bill of Materials (BOM)

πŸ“’ The above BOM is just an example. You can certainly swap out full systems and/or components that you might already have or prefer alternatives. Just know that you are responsible for adjusting any configuration that may differ from the referenced BOM.

Prerequisites

  • Minimum 5 VLANs (e.g. 30, 40, 50, 60, 70) for VCF Fleet Deployment

    • VLAN 30 - Management
    • VLAN 40 - vMotion
    • VLAN 50 - vSAN
    • VLAN 60 - ESX/NSX Edge TEP
    • VLAN 70
      • Tier 0 Uplink for Centralized Transit Gateway (Optional)
      • External Connectivity for Distributed Transit Gateway (Optional)
  • Here are the IP addresses and DNS entries that you will need for initial setup (NSX Edge/VNA and vSphere Supervisor are optional)

Hostname FQDN IP Address Function
esx01 esx01.vcf.lab 172.30.0.10 Physical ESX-1 Server
esx02 esx02.vcf.lab 172.30.0.11 Physical ESX-2 Server
esx03 esx03.vcf.lab 172.30.0.12 Physical ESX-3 Server
sddcm01 sddcm01.vcf.lab 172.30.0.18 VCF Installer / SDDC Manager
vc01 vc01.vcf.lab 172.30.0.19 vCenter Server for Management Domain
vcf01 vcf01.vcf.lab 172.30.0.20 VCF Operations
vcf-msr01 vcf-msr01.vcf.lab 172.30.0.21 VCF Management Services Runtime
vcf-flt01 vcf-flt01.vcf.lab 172.30.0.22 VCF Fleet Components FQDN
vcf-int01 vcf-int01.vcf.lab 172.30.0.23 VCF Instance Components FQDN
vcf-lic01 vcf-lic01.vcf.lab 172.30.0.24 VCF License Server
vcf-log01 vcf-log01.vcf.lab 172.30.0.26 VCF Operations for Logs (Optional)
vcf-idb01 vcf-idb01.vcf.lab 172.30.0.27 VCF Identity Broker
172.30.0.32/28 172.30.0.33-172.30.0.46 VCF Management Services Runtime Node IP Pool
nsx01 nsx01.vcf.lab 172.30.0.48 NSX Manager VIP for Management Domain
nsx01a nsx01a.vcf.lab 172.30.0.49 NSX Manager for Management Domain
edge01a edge01a.vcf.lab 172.30.0.50 NSX Edge 1a for Management Domain (Optional)
edge01b edge01b.vcf.lab 172.30.0.51 NSX Edge 1b for Management Domain (Optional)
vna01a vna01a.vcf.lab 172.30.0.52 NSX VNA 1a for Management Domain
vna01b vna01b.vcf.lab 172.30.0.53 NSX VNA 1b for Management Domain (Optional)
172.30.0.54 NSX Edge VIP (Optional)
vcf-proxy01 vcf-proxy01.vcf.lab 172.30.0.55 VCF Operations Proxy Collector
vcf-asr01 vcf-asr01.vcf.lab 172.30.0.56 VCF Automation Services Runtime
auto01 auto01.vcf.lab 172.30.0.57 VCF Automation
172.30.0.64/29 172.30.0.65-172.30.0.70 VCF Automation Services Runtime Node IP Pool
sv01 sv01.vcf.lab 172.30.0.80-172.30.0.85 vSphere Supervisor Node IP Pool

πŸ“’ For Distributed Transit Gateway (DTGW) configuration, we can optimize the VLAN 70 network and carve it up into smaller /26 networks rather than consuming an entire block when enabling vSphere Supervisor

  • 172.30.70.0/26
  • 172.30.70.64/26
  • 172.30.70.128/26
  • 172.30.70.192/26

Installation

  1. Update your hardware to the latest vendor firmware

    • For MS-A2 owners, please follow these instructions for firmware
    • Apply these these instructions for network optimizations if you are doing a manual installation (already incorporated into ESX kickstart examples)
  2. Set up a VCF Offline Depot using the new VCF Download Tool by following the Broadcom documentation

After downloading the required metadata/binaries, you should have a directory structure like the following:

PROD
β”œβ”€β”€ COMP
β”‚Β Β  β”œβ”€β”€ DEPOT_SERVICE
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vcf-fleet-depot-9.1.0.0.25371105.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vcf-fleet-depot-9.1.0.0.25371105.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vcf-fleet-depot-9.1.0.0.25371105.tgz
β”‚Β Β  β”‚Β Β  └── vcf-fleet-depot-plugin-9.1.0.0.25371105.tgz
β”‚Β Β  β”œβ”€β”€ ESX_HOST
β”‚Β Β  β”‚Β Β  └── VMware-VMvisor-Installer-9.1.0.0.25370933.x86_64.iso
β”‚Β Β  β”œβ”€β”€ NSX_T_MANAGER
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ nsx-unified-appliance-9.1.0.0.25318227.ova
β”‚Β Β  β”‚Β Β  └── VMware-NSX-T-9.1.0.0.25318227.vlcp
β”‚Β Β  β”œβ”€β”€ SDDC_MANAGER_VCF
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ Compatibility
β”‚Β Β  β”‚Β Β  β”‚Β Β  └── VmwareCompatibilityData.json
β”‚Β Β  β”‚Β Β  └── VCF-SDDC-Manager-Appliance-9.1.0.0.25371088.ova
β”‚Β Β  β”œβ”€β”€ TELEMETRY_ACCEPTOR
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-telemetry-acceptor-9.1.0.0.25181946.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-telemetry-acceptor-9.1.0.0.25181946.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ telemetry-acceptor-9.1.0.0.25181946.tgz
β”‚Β Β  β”‚Β Β  └── telemetry-acceptor-plugin-9.1.0.0.25181946.tgz
β”‚Β Β  β”œβ”€β”€ VCENTER
β”‚Β Β  β”‚Β Β  └── VMware-VCSA-all-9.1.0.0.25370922.iso
β”‚Β Β  β”œβ”€β”€ VCF_FLEET_LCM
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vcf-fleet-lcm-9.1.0.0.25371109.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vcf-fleet-lcm-9.1.0.0.25371109.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vcf-fleet-lcm-9.1.0.0.25371109.tgz
β”‚Β Β  β”‚Β Β  └── vcf-fleet-lcm-plugin-9.1.0.0.25371109.tgz
β”‚Β Β  β”œβ”€β”€ VCF_LICENSE_SERVER
β”‚Β Β  β”‚Β Β  └── Vcf-License-Server-9.1.0.0.25346031.ova
β”‚Β Β  β”œβ”€β”€ VCF_OPS_CLOUD_PROXY
β”‚Β Β  β”‚Β Β  └── Operations-Cloud-Proxy-9.1.0.0.25346033.ova
β”‚Β Β  β”œβ”€β”€ VCF_SALT
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-salt-9.1.0.0.25346036.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-salt-9.1.0.0.25346036.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ salt-9.1.0.0.25346036.tgz
β”‚Β Β  β”‚Β Β  └── salt-plugin-9.1.0.0.25346036.tgz
β”‚Β Β  β”œβ”€β”€ VCF_SALT_RAAS
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-salt-raas-9.1.0.0.25346036.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-salt-raas-9.1.0.0.25346036.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ salt-raas-9.1.0.0.25346036.tgz
β”‚Β Β  β”‚Β Β  └── salt-raas-plugin-9.1.0.0.25346036.tgz
β”‚Β Β  β”œβ”€β”€ VCF_SDDC_LCM
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vcf-sddc-lcm-9.1.0.0.25371107.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vcf-sddc-lcm-9.1.0.0.25371107.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vcf-sddc-lcm-9.1.0.0.25371107.tgz
β”‚Β Β  β”‚Β Β  └── vcf-sddc-lcm-plugin-9.1.0.0.25371107.tgz
β”‚Β Β  β”œβ”€β”€ VCF_SERVICE_VCD_MIGRATION_BACKEND
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vcd-migrator-9.1.0.0.25370929.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vcd-migrator-9.1.0.0.25370929.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vcd-migrator-9.1.0.0.25370929.tgz
β”‚Β Β  β”‚Β Β  └── vcd-migrator-plugin-9.1.0.0.25370929.tgz
β”‚Β Β  β”œβ”€β”€ VIDB
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vidb-9.1.0.0.25368698.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vidb-9.1.0.0.25368698.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vidb-9.1.0.0.25368698.tgz
β”‚Β Β  β”‚Β Β  └── vidb-upgrade-plugin-9.1.0.0.25368698.tgz
β”‚Β Β  β”œβ”€β”€ VRA
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ configuration-schema-vcfa-bundle-9.1.0.0.25370929.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ depot-manifest-vcfa-bundle-9.1.0.0.25370929.yaml
β”‚Β Β  β”‚Β Β  β”œβ”€β”€ vcfa-bundle-9.1.0.0.25370929.tar
β”‚Β Β  β”‚Β Β  └── vcfa-plugin-9.1.0.0.25370929.tgz
β”‚Β Β  β”œβ”€β”€ VROPS
β”‚Β Β  β”‚Β Β  └── Operations-Appliance-9.1.0.0.25346025.ova
β”‚Β Β  └── VSP
β”‚Β Β      β”œβ”€β”€ configuration-schema-vmsp-platform-9.1.0.0.25370367.yaml
β”‚Β Β      β”œβ”€β”€ depot-manifest-vmsp-platform-9.1.0.0.25370367.yaml
β”‚Β Β      β”œβ”€β”€ vcf-services-platform-template-9.1.0.0.25370367.ova
β”‚Β Β      β”œβ”€β”€ vmsp-cli-9.1.0.0.25370367.tar.gz
β”‚Β Β      β”œβ”€β”€ vmsp-platform-9.1.0.0.25370367.tar
β”‚Β Β      └── vmsp-plugin-9.1.0.0.25370367.tgz
β”œβ”€β”€ metadata
β”‚Β Β  β”œβ”€β”€ manifest
β”‚Β Β  β”‚Β Β  └── v1
β”‚Β Β  β”‚Β Β      └── vcfManifest.json
β”‚Β Β  └── productVersionCatalog
β”‚Β Β      └── v1
β”‚Β Β          β”œβ”€β”€ productVersionCatalog.json
β”‚Β Β          └── productVersionCatalog.sig
└── vsan
    └── hcl
        β”œβ”€β”€ all.json
        └── lastupdatedtime.json

27 directories, 56 files

You can host the VCF Offline Depot using a traditional HTTP Web Server (HTTPS is NOT required as the automation in 9.1 will support HTTP). Alternatively, you can simply use Python to serve up the directory (see this blog post) or even a Synology (see this blog post).

  1. Create a bootable ESX installer with the ESX ISO (VMware-VMvisor-Installer-9.1.0.0.25370933.x86_64.iso) using UNetbootin.

  2. We will perform a scripted installation of ESX (aka ESX Kickstart) to reduce the number of manual post-installation steps.

  3. Edit the relevant Kickstart Files and replace the following values with your own desired configurations.

πŸ’‘ To simplify the deployment of multiple ESX hosts using a single USB drive, you can create a custom UEFI boot menu for ESX, allowing you to select specific ESX kickstart configuration files.

πŸ“’ To identify the NVMe device label for the ESX installation (e.g. --disk=<ID>) and NVMe tiering device (e.g. NVME_TIERING_DEVICE=), boot the ESX installer initially, switch to the shell console (ALT+F1), and log in as root with a blank password (just press Enter). Enable SSH using /etc/init.d/SSH start, identify the IP address, SSH to the in-memory ESX host, and run vdq -q to list all storage devices.

In the example KS-ESX01.CFG, the ESX installation disk will be t10.NVMe____SKHynix_HFS512GEJ9X162N_________________AJEBN74041040C403___00000001 and NVMe Tiering disk will be t10.NVMe____MTFDLBA1T0THJ2D1BP15ABYY_________________5D19D3500175A000

After creating the bootable ESX installer on your USB device, copy your modified ESX kickstart file(s) into the root directory of the USB device (kickstart file names must be uppercase).

Now, navigate into the USB device under EFI/BOOT and edit BOOT.CFG updating the kernelopt so it matches the following which will run our KS-ESX01.CFG instead of the interactive installation:

bootstate=0
title=Loading ESXi installer
timeout=5
prefix=
kernel=/b.b00
kernelopt=ks=usb:/KS-ESX01.CFG
modules=/jumpstrt.gz --- /useropts.gz --- /features.gz --- /k.b00 --- /uc_intel.b00 --- /uc_amd.b00 --- /uc_hygon.b00 --- /vmx.v00 --- /vim.v00 --- /tpm.v00 --- /sb.v00 --- /s.v00 --- /atlantic.v00 --- /bcm_mpi3.v00 --- /bnxtnet.v00 --- /bnxtroce.v00 --- /cndi_igc.v00 --- /elxnet.v00 --- /i40en.v00 --- /iavmd.v00 --- /icen.v00 --- /igbn.v00 --- /intelgpi.v00 --- /ionic_cl.v00 --- /ionic_en.v00 --- /irdman.v00 --- /iser.v00 --- /ixgben.v00 --- /lpfc.v00 --- /lpnic.v00 --- /lsi_mr3.v00 --- /lsi_msgp.v00 --- /lsi_msgp.v01 --- /ne1000.v00 --- /nenic_en.v00 --- /nenic.v00 --- /nfnic.v00 --- /nhpsa.v00 --- /nipmi.v00 --- /nmlx5_cc.v00 --- /nmlx5_co.v00 --- /nmlx5_rd.v00 --- /ntg3.v00 --- /nvme_pci.v00 --- /nvmerdma.v00 --- /nvmetcp.v00 --- /nvmxnet3.v00 --- /nvmxnet3.v01 --- /pvscsi.v00 --- /qat.v00 --- /qcnic.v00 --- /qedentv.v00 --- /qedrntv.v00 --- /qfle3.v00 --- /qfle3f.v00 --- /qfle3i.v00 --- /rdmahl.v00 --- /rshim_ne.v00 --- /rshim.v00 --- /sfvmk.v00 --- /smartpqi.v00 --- /vmkata.v00 --- /vmksdhci.v00 --- /vmkusb.v00 --- /vmw_ahci.v00 --- /bmcal.v00 --- /clusters.v00 --- /crx.v00 --- /drivervm.v00 --- /btldr.v00 --- /dvfilter.v00 --- /esx_ui.v00 --- /esxupdt.v00 --- /tpmesxup.v00 --- /weaselin.v00 --- /xorg.v00 --- /esxio_co.v00 --- /infravis.v00 --- /loadesx.v00 --- /hpv2_hps.v00 --- /intelv2_.v00 --- /lsiv2_dr.v00 --- /nvme_pci.v01 --- /oem_dell.v00 --- /oem_leno.v00 --- /smartpqi.v01 --- /native_m.v00 --- /nsx_pyth.v01 --- /podvm_ro.v00 --- /qlnative.v00 --- /trx.v00 --- /vcls_pod.v00 --- /vdfs.v00 --- /vds_vsip.v00 --- /vmware_e.v00 --- /vmware_f.v00 --- /hbrsrv.v00 --- /vsan.v00 --- /vsanheal.v00 --- /vsanmgmt.v00 --- /tools.t00 --- /qp_esx_d.v00 --- /nsx_adf.v00 --- /nsx_cfga.v00 --- /nsx_cont.v00 --- /nsx_cpp_.v00 --- /nsx_esx_.v00 --- /nsx_expo.v00 --- /nsx_head.v00 --- /nsx_host.v00 --- /nsx_moni.v00 --- /nsx_mpa.v00 --- /nsx_nest.v00 --- /nsx_neto.v00 --- /nsx_opsa.v00 --- /nsx_plat.v00 --- /nsx_prot.v00 --- /nsx_prox.v00 --- /nsx_pyth.v00 --- /nsx_pyth.v02 --- /nsx_scx.v00 --- /nsx_sfhc.v00 --- /nsx_shar.v00 --- /nsx_snpr.v00 --- /nsxcli.v00 --- /vsipfwli.v00 --- /gc.v00 --- /imgdb.tgz --- /basemisc.tgz --- /resvibs.tgz --- /esxiodpt.tgz --- /imgpayld.tgz
build=9.1.0-0.25370933
updated=0

πŸ“’ If you are performing the installation on two or three physical ESX hosts, the only required change is to update the reference to kickstart file, so you know which file is being referenceed on the USB device.

  1. Plug the USB device into your system and power on to begin the ESX installation.

  2. Once ESX reboots (there is a secondary reboot as part of the ESX scripted installation), you should be able to log in to your ESX host using the FQDN and see something like the following:

  1. Deploy the VCF Installer appliance (VCF-SDDC-Manager-Appliance-9.1.0.0.25371088.ova) using the following shell script, deploy_vcf_installer.sh, which relies on OVFTool. Install OVFTool if you do not already have it on your local system.

  1. After the VCF Installer is up and running, we need to make a few configuration changes (credentials/networking). I have automated these changes, and you can run the following PowerShell script: setup_vcf_installer.ps1.

  1. Before we can deploy our VCF 9.1 environment, we need to connect to the VCF Offline Depot that you set up in Step 1.

Open your browser to the VCF Installer (e.g. https://sddcm01.vcf.lab/), log in with the password you configured in Step 8, and then click the DEPOT SETTINGS AND BINARY MANAGEMENT button.

If Step 8 successfully connected to your VCF Offline Depot, it should already have synced the VCF metadata, which shows the list of binaries available for download. Click the DOWNLOAD button to begin downloading the required VCF binaries and ensure each item listed in the table has a Success status.

  1. Navigate back to the VCF Installer homepage and click on DEPLOY USING JSON SPEC to begin your VCF deployment.

Upload your modified VCF deployment JSON and click Next to begin the validation.

πŸ“’ You may encounter pre-checks that require acknowledgment to continue. I have noticed that with certain MikroTik devices, even when Jumbo Frames (MTU=9K) are configured, validation can fail while deployment still succeeds. In that case, simply acknowledge the configuration.

Once you have fixed and/or acknowledged all applicable pre-checks, click DEPLOY to start the deployment.

πŸ“’ During deployment, the VCF Installer generates its own self-signed TLS certificate, which forces a browser refresh and displays a message like the following. This is expected. Simply click the reload button as shown in the screenshot below.

  1. The deployment will take a few hours. Once everything has been deployed, you should see a success page like the following:

You can log in to your new VCF 9.1 deployment by clicking the link to VCF Operations and using the admin credentials you specified in your deployment JSON, or simply copying the credentials from this screen.

Here is an example of single host deployment and total deployment duration for each component:

Post Installation

  1. There are a number of post-VCF deployment optimizations that should be run for lab environments. You can refer to the linked blog post and run the PowerShell script vcf-post-deploy-lab-tweaks.ps1.

  1. Additional optimization for those using AMD Zen4/5 CPUs.
  • Apply additional NSX optimization for reducing High CPU Utilization on NSX components (NSX Manager, Edges and Virtual Network Appliances) when using AMD Zen4/5 CPUs.
  • Apply additional VCFA optimization for reducing High CPU Utilization on VCVF Automation (VCFA) when using AMD Zen4/5 CPUs.

Additional Blog Resources

About

Minimal VMware Cloud Foundation (VCF) 9.1

Resources

Stars

8 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages