WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

VCF 9.1.1: Adopting the Reduced VCF Management Services (VCFMS) Footprint After an Upgrade

09.03.2026 by William Lam // 7 Comments

When VCF Management Services (VCFMS) was introduced in VCF 9.1.0, its virtual machine sizing was optimized to accommodate the largest optional Day-N service. This reduced the likelihood of requiring a rollout to a larger VM size as additional services were enabled. However, for environments that did not deploy these optional Day-N services, some VCFMS virtual machines could be larger than necessary.

With VCF 9.1.1, VCFMS sizing has been optimized for the initial Day-0 deployment. In addition, individual VCFMS components have been further right-sized to ensure that each service reserves only the resources it requires, improving overall resource utilization. For example, a Simple (non-HA) deployment, you will now have one less VCFMS Worker Node (12 vCPU / 24GB memory).


It is important to note that the right-sized VCFMS worker nodes and component sizing are automatically applied for new VCF 9.1.1 deployments, but they are not automatically applied to existing deployments that are upgraded to VCF 9.1.1.

With that said, users who upgrade to VCF 9.1.1 can still realize the benefits of the reduced VCFMS footprint by running a post-upgrade script that produces the same end state as a new VCF 9.1.1 deployment. For those interested, you can also use the VCF Inspector Fling which will include the post-upgrade script workflow, so you can simply perform that using that tool as well.
[Read more...]

Categories // VMware Cloud Foundation Tags // VCF 9.1.1

Configuring OIDC with PKCE in Keycloak for VCF Private AI Services

08.26.2026 by William Lam // Leave a Comment

I have taken a short hiatus from playing with my NVIDIA RTX 4000, which fits perfectly inside a Minisforum MS-A2 and is what I use to run VMware Cloud Foundation (VCF) 9.1. While redeploying my environment to test an upcoming release of VCF Private AI Services (PAIS), I was reminded that the deployment requires an OIDC provider that supports the Authorization Code grant flow with PKCE (Proof Key for Code Exchange).

When I originally deployed PAIS with VCF 9.0, I used Authentik as my identity provider (IdP). With my VCF Infrastructure Services (VIS) Appliance which provides a number of services including Keycloak as an OIDC provider, I wanted to figure out the required Keycloak configuration to satisfy the PAIS OIDC requirements, especially as this can help accelerate Lab/PoC deployments.

After some trial and error, and with the help of OpenAI Codex to debug my live environment, I now have Keycloak successfully configured with PAIS, along with a script to generate the access token required to interact with a PAIS Model Endpoint! 🥳

[Read more...]

Categories // Private AI Services, VMware Cloud Foundation Tags // PAIS, VCF 9.1

VCF 9.1 - Understanding VCF Converge & Import Scenarios for vCenter Server Without NSX

08.24.2026 by William Lam // 2 Comments

When converging or importing a vCenter Server environment that does not already include NSX, VMware Cloud Foundation (VCF) will automatically deploy NSX as part of the converge or import workflow. While the deployed NSX version will be compatible with the existing environment, it may have implications for future VCF upgrade paths.

The current behavior in VCF 9.1.0 is to deploy the latest NSX version that is compatible with the source vCenter Server version. However, depending on when the converge or import workflow is performed, that NSX version could be a back-in-time release that does not have a direct upgrade path to the current version of VCF.

Below is an example to help illustrate the current behavior. Let us assume we are starting with a vCenter Server 8.0 Update 3c environment. As of this blog post, the Interoperability Matrix, which is the source used to determine component compatibility, shows NSX 4.2.4.1 as the latest compatible version.


Reference: https://interopmatrix.broadcom.com/Interoperability?col=912,&row=2,18560&isHidePatch=false&isHideLegacyReleases=false

[Read more...]

Categories // NSX, VMware Cloud Foundation Tags // VCF 9.1

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 78
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • VCF 9.1.1 - Connecting Pi Coding Agent to VCF Private AI Services (PAIS) 09/17/2026
  • Quick Tip - Automating vDefend Security Services Platform (SSP) 5.2.0 Installer OVA Deployment 09/16/2026
  • VCF 9.1.1 - Simplified vSphere Kubernetes Service (VKS) using VLAN-Backed VPCs without NSX Tunnel Endpoints (TEPs) 09/15/2026
  • VCF 9.1.1 - Using VCF Private AI Services (PAIS) Models with AI Assistant for VCF 09/11/2026
  • VCF 9.1.1 - Deploying Your Own AI Models with VCF Private AI Services (PAIS) 3.0 09/10/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026

Loading Comments...