WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

Enhancement in VCF 5.2.2 to bypass vSAN ESA HCL Check

09.05.2025 by William Lam // Leave a Comment

When vSAN Express Storage Architecture (ESA) is selected as the primary storage for deploying VMware Cloud Foundation (VCF) 5.x, the Cloud Builder Appliance will validate the system against the vSAN ESA HCL and will block the deployment if the hardware components are non-compliant.


For a production deployment, this should be the default experience but for non-production or proof-of-concept (POC), this can be annoying if you wish to accept the risk and proceed with using non-certified vSAN ESA hardware.

Today, the most viable workaround is to install the vSAN ESA Hardware Mock VIB , which will allow users to proceed with the deployment but it does require the additional installation step for each ESXi host.

Having spoken with VCF Engineering about this topic awhile back, they have introduced a nice enhancement with the latest release of VCF 5.2.2 that will allow users to easily bypass the vSAN ESA HCL check without requiring additional ESXi configurations changes.

[Read more...]

Categories // VMware Cloud Foundation, VSAN Tags // VMware Cloud Foundation, VSAN

Automated VMware Cloud Foundation (VCF) 9.0 Lab Deployment Script

09.02.2025 by William Lam // 4 Comments

Now that VMware Explore Las Vegas has concluded, I finally have a small breather to publish my Automated VMware Cloud Foundation (VCF) 9.0 Lab Deployment Script, which utilizes Nested ESXi running on an existing physical vSphere environment, as shown in the diagram below.


I know many of you have used previous versions of my automated lab deployment scripts, so this should feel quite familiar along with some enhancements including the ability to externalize the environment configuration parameters from the actual deployment script.

You can find all the details and documentation at the following Github repo:

[Read more...]

Categories // VMware Cloud Foundation Tags // VCF 9.0

VCF Automation Provider Organization as an OIDC Identity Provider for VCFA Tenant Organizations?

08.19.2025 by William Lam // 4 Comments

VCF 9.0 Automation (VCF) contains two types of organizations, one for the Provider (also referred to System) and one for the tenants, which are just called Organizations. Both types of VCFA Organizations can be connected to an external Identity Provider (IdP) including OIDC, LDAP and SAML.

The VCFA Provider Organization can be configured to use the new VCF Single-Sign (SSO) feature, which is a capability of VCF Operations and utilizes a deployment of vIDB (Embedded or External) which is the identity broker to your desired external IdP like PingFederate or Okta as an example. While you can connect the VCFA Provider Organization directly to an external IdP, by using VCF SSO, administrators can now seamlessly login to all VCF management components, assuming you have been granted the appropriate permissions within each component.

For VCFA Tenant Organizations, where each organization could represent a completely different customer, such as in a service provider model, each individual VCFA organization can connect to their own independent external IdP, as represented in the diagram below.


For a typical Enterprise, you might only have a single IdP that you would use for both the Provider and Tenant Organizations. If you are using an OIDC IdP, you would need to create one OIDC Client for VCF SSO and then one additional OIDC Client for each organization that you would like to connect to the same OIDC IdP as shown below.


Instead of creating multiple OIDC Clients, could we just leverage the Provider Organization as the OIDC IdP for the VCF Tenant Organizations?

Note: Depending on your external IdP capabilities, you might need to have separate OIDC Clients for controlling multi-factor authentication (MFA) or customized login screen as I have demonstrated with using Keycloak as my external IdP.

[Read more...]

Categories // VCF Automation, VMware Cloud Foundation Tags // VCF 9.0, VCF Automation

  • « Previous Page
  • 1
  • …
  • 40
  • 41
  • 42
  • 43
  • 44
  • …
  • 78
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • VCF 9.1.1 - Connecting Pi Coding Agent to VCF Private AI Services (PAIS) 09/17/2026
  • Quick Tip - Automating vDefend Security Services Platform (SSP) 5.2.0 Installer OVA Deployment 09/16/2026
  • VCF 9.1.1 - Simplified vSphere Kubernetes Service (VKS) using VLAN-Backed VPCs without NSX Tunnel Endpoints (TEPs) 09/15/2026
  • VCF 9.1.1 - Using VCF Private AI Services (PAIS) Models with AI Assistant for VCF 09/11/2026
  • VCF 9.1.1 - Deploying Your Own AI Models with VCF Private AI Services (PAIS) 3.0 09/10/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026

Loading Comments...