WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

Quick Tip: Reducing High CPU Utilization in VCF Automation (VCFA) on AMD Zen4/Zen5 CPUs

08.12.2026 by William Lam // Leave a Comment

A couple of weeks ago, I received an interesting email from a reader who had observed high CPU utilization after upgrading VCF Automation (VCFA) to the latest VCF 9.1 release. They were running VCF 9.1 on the popular Minisforum MS-A2 platform, which uses AMD Zen4/Zen5 (Ryzen) consumer processors which are not supported on the Broadcom Compatibility Guide (BCG). As I have covered previously (here and here), these processors have been known to exhibit slower entropy generation that can lead to higher than expected CPU utilization without the appropriate optimizations.

With the help of Claude to analyze the issue, the reader arrived at the following conclusion:

Five JVM-based services were dying repeatedly during startup because FIPS_MODE=strict was slowing down TLS handshakes (both database and internal service-to-service HTTPS) enough to occasionally exceed connection timeouts. Every restart meant a full JVM boot: Spring context initialization, Liquibase migrations, Hibernate, index rebuilding, which is expensive. The crash loop itself became the CPU load. Setting FIPS_MODE=disabled on the affected deployments stopped the crash loop entirely, and CPU usage returned to near-idle.

Interestingly, around the same time, I also heard from an internal colleague who had independently observed that disabling FIPS for specific VCFA services significantly reduced CPU utilization. Since FIPS is enabled by default for VCF 9.1 deployments, and there are known performance implications with FIPS and OpenSSL 3.x, these effects can be amplified on AMD Zen4/Zen5 (Ryzen) consumer processors due to their slower entropy generation, resulting in higher than expected CPU utilization.

Fortunately, both individuals had identified workarounds for the issue, but their recommendations did not completely overlap. Before sharing the guidance more broadly, I wanted to spend some time validating the solution to identify the minimal set of changes required to consistently achieve the same outcome.

[Read more...]

Categories // VCF Automation, VMware Cloud Foundation Tags // VCF 9.1

VCF 9.1 - Quick Tip: Optimized Workflow for Configuring Distributed Transit Gateway (DTGW) with NSX Virtual Network Appliance (VNA)

08.11.2026 by William Lam // Leave a Comment

With VMware Cloud Foundation (VCF) 9.1, the Distributed Transit Gateway (DTGW) connectivity model now supports NSX stateful network services through the Virtual Network Appliance (VNA) cluster. This makes it easy for VI Admins to provision Virtual Private Clouds (VPCs), which can then be used to deploy vSphere Kubernetes Service (VKS) workloads using either vCenter Server or VCF Automation (VCFA).

One of the most underappreciated benefits is the ability to complete various NSX workflows including an entire VNA cluster deployment and DTGW configuration directly from vCenter Server, without having to switch to the NSX Manager UI. While NSX Manager still provides the underlying micro-frontend interfaces that are integrated into the vSphere UI, I appreciate having the flexibility to perform these workflows from either the vCenter Server or NSX Manager interface, depending on your roles and responsibilities within an organization.

While there are a number of community blog posts covering DTGW and VNA deployments, they typically start in the vSphere UI for the initial VNA deployment before switching to the NSX Manager UI to complete the remaining configuration, which is perfectly valid. Personally, I prefer using the vSphere UI for as many workflows as possible, especially since enabling vSphere Supervisor and vSphere Kubernetes Service (VKS) is also performed through the vSphere UI.

[Read more...]

Categories // NSX, VMware Cloud Foundation, vSphere Kubernetes Service, vSphere Supervisor

Quick Tip: Selective ESX Host Patching in VCF 9.1

08.10.2026 by William Lam // 2 Comments

Prior to VMware Cloud Foundation (VCF) 9.1, users could choose whether to apply an ESX update across all or a selected set of vSphere Clusters, but there was no additional granularity for selecting specific ESX hosts within a cluster. This has been a frequently requested capability, especially for excluding specific ESX hosts from an update or performing a controlled rollout across one or more vSphere Clusters.

Fleet Lifecycle Management in VCF 9.1 has been enhanced with a new custom host selection capability that allows users to select specific ESX hosts within a vSphere Cluster for patching.

[Read more...]

Categories // ESXi, VMware Cloud Foundation Tags // VCF 9.1

  • 1
  • 2
  • 3
  • …
  • 620
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Quick Tip: Reducing High CPU Utilization in VCF Automation (VCFA) on AMD Zen4/Zen5 CPUs 08/12/2026
  • VCF 9.1 - Quick Tip: Optimized Workflow for Configuring Distributed Transit Gateway (DTGW) with NSX Virtual Network Appliance (VNA) 08/11/2026
  • Quick Tip: Selective ESX Host Patching in VCF 9.1 08/10/2026
  • Playing with Zero Touch Provisioning (ZTP) in vSphere 9.1 using an ASUS NUC 08/07/2026
  • Quick Tip: Automating ESX System Resource Pool Workaround Prior to 8.0 Update 3g 08/06/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026