WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

VCF 9.1 - Understanding VCF Converge & Import Scenarios for vCenter Server Without NSX

08.24.2026 by William Lam // 2 Comments

When converging or importing a vCenter Server environment that does not already include NSX, VMware Cloud Foundation (VCF) will automatically deploy NSX as part of the converge or import workflow. While the deployed NSX version will be compatible with the existing environment, it may have implications for future VCF upgrade paths.

The current behavior in VCF 9.1.0 is to deploy the latest NSX version that is compatible with the source vCenter Server version. However, depending on when the converge or import workflow is performed, that NSX version could be a back-in-time release that does not have a direct upgrade path to the current version of VCF.

Below is an example to help illustrate the current behavior. Let us assume we are starting with a vCenter Server 8.0 Update 3c environment. As of this blog post, the Interoperability Matrix, which is the source used to determine component compatibility, shows NSX 4.2.4.1 as the latest compatible version.


Reference: https://interopmatrix.broadcom.com/Interoperability?col=912,&row=2,18560&isHidePatch=false&isHideLegacyReleases=false

[Read more...]

Categories // NSX, VMware Cloud Foundation Tags // VCF 9.1

VCF 9.1 - Configuring Harbor to use VCF Identity Broker (IDB) for External Identity Federation

08.19.2026 by William Lam // 1 Comment

Similar to Configuring vSphere Supervisor to use VMware Cloud Foundation (VCF) Identity Broker (IDB) for external identity federation, Harbor also supports OpenID Connect (OIDC) identity providers (IdPs). This would allow Harbor or any components that support OIDC-based IdP to leverage our existing VCF IDB instance that is already integrated with VCF Single Sign-On (SSO), reducing the need to create an additional OIDC client configurations from the IdP itself.

Since I already had VCF Single Sign-On (SSO) configured with Keycloak using my VCF Infrastructure Services (VIS) Appliance Fling, it was easy for me to validate and demonstrate this integration after coming across a question about it this morning in one of our internal Google channels 🙂

[Read more...]

Categories // VMware Cloud Foundation Tags // Harbor, VCF 9.1

Quick Tip: Reducing High CPU Utilization in VCF Automation (VCFA) on AMD Zen4/Zen5 CPUs

08.12.2026 by William Lam // 4 Comments

A couple of weeks ago, I received an interesting email from a reader who had observed high CPU utilization after upgrading VCF Automation (VCFA) to the latest VCF 9.1 release. They were running VCF 9.1 on the popular Minisforum MS-A2 platform, which uses AMD Zen4/Zen5 (Ryzen) consumer processors which are not supported on the Broadcom Compatibility Guide (BCG). As I have covered previously (here and here), these processors have been known to exhibit slower entropy generation that can lead to higher than expected CPU utilization without the appropriate optimizations.

With the help of Claude to analyze the issue, the reader arrived at the following conclusion:

Five JVM-based services were dying repeatedly during startup because FIPS_MODE=strict was slowing down TLS handshakes (both database and internal service-to-service HTTPS) enough to occasionally exceed connection timeouts. Every restart meant a full JVM boot: Spring context initialization, Liquibase migrations, Hibernate, index rebuilding, which is expensive. The crash loop itself became the CPU load. Setting FIPS_MODE=disabled on the affected deployments stopped the crash loop entirely, and CPU usage returned to near-idle.

Interestingly, around the same time, I also heard from an internal colleague who had independently observed that disabling FIPS for specific VCFA services significantly reduced CPU utilization. Since FIPS is enabled by default for VCF 9.1 deployments, and there are known performance implications with FIPS and OpenSSL 3.x, these effects can be amplified on AMD Zen4/Zen5 (Ryzen) consumer processors due to their slower entropy generation, resulting in higher than expected CPU utilization.

Fortunately, both individuals had identified workarounds for the issue, but their recommendations did not completely overlap. Before sharing the guidance more broadly, I wanted to spend some time validating the solution to identify the minimal set of changes required to consistently achieve the same outcome.

[Read more...]

Categories // VCF Automation, VMware Cloud Foundation Tags // VCF 9.1

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 21
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Automate Inventory of vSphere Supervisor Clusters & vSphere Kubernetes Service (VKS) Guest Clusters 10/02/2026
  • VCF 9.1.1 - OCuLink External Graphics (eGPU) Dock with integrated PSU for GPU Passthrough with VKS 10/01/2026
  • VCF 9.1.1 - Single ESX Host for VCF Fleet, VCF Workload Domain or VCF Cluster 09/30/2026
  • Bypassing Minimum Unique Flows & Metric Collection Period for vDefend Security Services Platform (SSP) 5.2 Lab Deployments 09/28/2026
  • PowerShell Module for vDefend Security Services Platform (SSP) 5.2 Installer Configuration and Instance Deployment 09/24/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026

Loading Comments...