WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

VCF 9.1.1 - Simplified vSphere Kubernetes Service (VKS) using VLAN-Backed VPCs without NSX Tunnel Endpoints (TEPs)

09.15.2026 by William Lam // 1 Comment

As part of the VMware Cloud Foundation (VCF) 9.1.1 release, consuming NSX Virtual Private Cloud (VPC) has gotten simpler, especially for environments using traditional VLAN-backed networks. In VCF 9.1.0, users already had the ability to configure a VPC using a Distributed Transit Gateway (DTGW) and Distributed VLAN through the NSX Virtual Network Appliance (VNA), but this still required configuring NSX Tunnel Endpoints (TEPs) on each ESX host.

With VCF 9.1.1, the networking workflow has been further simplified with a new VLAN-backed VPC option. While it still uses DTGW and VNA, TEPs are no longer required, removing additional network requirements such as a larger MTU. As a result, environments that previously could not meet the networking requirements to configure a VPC can now deploy and consume services such as vSphere Kubernetes Service (VKS) and VCF Automation (VCFA).

It is also important to understand the different VPC consumption options and their constraints. The following table summarizes the capabilities and limitations of each option.


Note: DTGW with TEP was possible with VCF 9.0.0 but there was no support for VCFA until VCF 9.1.0.

[Read more...]

Categories // NSX, VMware Cloud Foundation Tags // VCF 9.1

10 Exciting Enhancements in VMware Cloud Foundation 9.1.1

09.03.2026 by William Lam // 18 Comments

This has been an exciting week as VMware Explore 2026 takes place in Las Vegas, where I have been meeting with customers and partners while delivering several technical breakout sessions and workshops. To coincide with the event, we have also announced the general availability of VMware Cloud Foundation (VCF) 9.1.1, the first maintenance release for VCF 9.1! 🥳

Note: While there is no defined patch sequence for maintenance and EPs, there is a special exception that you should be aware specifically for VCF 9.1.1 release which will have a couple of specific sequence that must be followed (pre-checks already built into the release). These exceptions will be removed in a future maintenance release, but just something to be aware of

  • Fleet LCM must be patched to 9.1.1 before updating other VCF components to 9.1.1
  • VCFMS must be updated to 9.1.1 before updating Identity broker, Salt Master/RaaS component to 9.1.1
  • VCF Automation (VCFA) must be updated to 9.1.1 before updating VCD Migrator component to 9.1.1

As a maintenance release, it includes all cumulative bug fixes and security updates from previous Express Patches (EPs), along with platform stability improvements and enhancements that simplify the journey to VCF 9.1.

While there are many improvements in this release, here are ten that I think are worth highlighting.

[Read more...]

Categories // VMware Cloud Foundation Tags // VCF 9.1

Configuring OIDC with PKCE in Keycloak for VCF Private AI Services

08.26.2026 by William Lam // Leave a Comment

I have taken a short hiatus from playing with my NVIDIA RTX 4000, which fits perfectly inside a Minisforum MS-A2 and is what I use to run VMware Cloud Foundation (VCF) 9.1. While redeploying my environment to test an upcoming release of VCF Private AI Services (PAIS), I was reminded that the deployment requires an OIDC provider that supports the Authorization Code grant flow with PKCE (Proof Key for Code Exchange).

When I originally deployed PAIS with VCF 9.0, I used Authentik as my identity provider (IdP). With my VCF Infrastructure Services (VIS) Appliance which provides a number of services including Keycloak as an OIDC provider, I wanted to figure out the required Keycloak configuration to satisfy the PAIS OIDC requirements, especially as this can help accelerate Lab/PoC deployments.

After some trial and error, and with the help of OpenAI Codex to debug my live environment, I now have Keycloak successfully configured with PAIS, along with a script to generate the access token required to interact with a PAIS Model Endpoint! 🥳

[Read more...]

Categories // Private AI Services, VMware Cloud Foundation Tags // PAIS, VCF 9.1

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 21
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Automate Inventory of vSphere Supervisor Clusters & vSphere Kubernetes Service (VKS) Guest Clusters 10/02/2026
  • VCF 9.1.1 - OCuLink External Graphics (eGPU) Dock with integrated PSU for GPU Passthrough with VKS 10/01/2026
  • VCF 9.1.1 - Single ESX Host for VCF Fleet, VCF Workload Domain or VCF Cluster 09/30/2026
  • Bypassing Minimum Unique Flows & Metric Collection Period for vDefend Security Services Platform (SSP) 5.2 Lab Deployments 09/28/2026
  • PowerShell Module for vDefend Security Services Platform (SSP) 5.2 Installer Configuration and Instance Deployment 09/24/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026

Loading Comments...