| Unique Visitors |
On Wednesday 14th May (NZST) I sat the VMware Advanced Professional – Cloud Infrastructure Administration (VCAP-CIA) exam. After receiving my results on Saturday 17th, only 3 days after sitting the exam, I was very relieved to have passed. I would like to thank VMware and the hard work by people including Joshua Andrews and the certification team for getting the results through so fast. This is a massive improvement over previous advanced live lab exams. I had already passed VCAP-CID during the exam beta process, so for me this puts me one step closer to VCDX-Cloud, which is my goal. This article will cover my exam experience and tips and recommendations for others that wish to attempt the exam.
To give you some background, I have architected about half a dozen cloud environments prior to sitting VCAP-CID and VCAP-CIA. Half were enterprise clouds and half were public clouds based on VMware vCloud Director or VMware vSphere. So I had quite a bit of experience with the solution stack that makes up a VMware Cloud environment, in addition to my VCDX Datacenter Virtualization. But I still try to approach any exam with the same methodology.
Exam Prep Method
My usual exam prep method is to review the exam blueprint and do an analysis of where I’m strong and where I need to study further to increase my knowledge. This exam was no different. There are quite a lot of areas to cover as there are a lot of technologies that are included in VMware’s cloud stack and with VMware vCloud Director. I found some additional areas to study and I made sure I reviewed the documentation, reviewed the vCloud Architecture Toolkit (vCAT), and set up a lab environment (using virtual ESXi hosts) to test things and get hands on. It’s important to be familiar with the command line inside your vCD Cells just as it is knowing how to navigate the GUI’s of the various tools. So make sure you’re prepared. Know the VCD cells intimately, the logs, the config files, the config tools, troubleshooting. Know vApps, Networking, configuration, resources and all the underlying infrastructure like the back of your hand. You will have to fix some broken things and you don’t have much time. vCD lends itself to this type of exam, and they cover the blueprint areas well. When it comes to your lab environment make sure you have all of the vCD stack components, including Chargeback, vCNS with VXLAN, vCD etc.
My First Attempt
This is a tale of how not to do it. I arrive back in Auckland, New Zealand after a business trip at around midnight with the VCAP-CIA exam the following morning. I got about two hours sleep as my youngest son wasn’t sleeping well. I didn’t read the first question correctly and instead of having to fix something, I really fixed it by corrupting the cell. I tried for about 20 minutes to troubleshoot it and get it working. I eventually gave up and just went as fast as I could through the questions I did know. Unfortunately time was very much against me and I wasn’t thinking straight due to having little sleep. Tip: Get plenty of sleep the night before the exam and read the questions carefully.
My Second Attempt
Fortunately when I failed the exam the first time there was a free retry voucher available. So I booked the exam, but due to work commitments had to keep putting it off as I would never get time to study it correctly. 14th May 2014 I sat the exam again. This time I had gotten a good rest the night before and I was much more prepared. But unfortunately the connection from the testing centre wasn’t as prepared as I was. Latency was my enemy, as was the speed of the vCD environment responding to my inputs. I performed the required tasks as fast as I could but I found I could only think about two or three questions at a time so I couldn’t get too far ahead. I had been moving forward and backward to do multiple questions at the same time to try and compensate for the performance of the vCD environment and also the latency challenges. But this strategy can only achieve so much. You have to keep track of all these questions in your head and where each part of the environment is at. In my opinion this makes the exam very challenging, especially with such limited time. By the time I had run out of time I had not even attempted about 5 or 6 questions, so I was just hoping I’d done enough in the rest of the exam to get a pass.
The Results
4 days was all I had to wait for the official results and the news that I’d passed the VCAP-CIA exam. One of the guys behind the test scoring automation reached out to me to let me know that there had been a lot of work going on behind the scenes on automating the exam scoring. It still wasn’t as fast as they’d like, so they were still looking to improve it. Given this quick turnaround the torture that is the advanced exams is made quite a bit better. At least you know where you’re at a lot sooner. In the future they plan to make the results much faster. So I hope you get an even faster experience when you sit the VCAP exams. I can also tell you there are plans to improve the interface to largely eliminate the lags and delays that we experience when doing these live lab exams from all over the world. This is great news, as the exams are hard enough without the latency, and VMware need more people sitting advanced exams to build a pipeline for VCDX and to ensure customers have access to skilled professionals to provide integrated solutions across all of VMware and ecosystem partner solutions.
Update: Joshua Andrews has just posted an article regarding the great improvements in exam marking time that VMware has implemented. Now you might receive your score for DCA and DTA in the same day. CIA will also see improvements. Check out the article titled Improved VCAP DCA DTA Score Reporting.
Final Word
Overall I really like the live lab exam format and the way they deeply test your abilities to administer and troubleshoot an advanced environment. The latency does make it hard, but it is possible to pass with the right approach, which hopefully this article helps you with. vCD is still my preferred Cloud tool while it’s supported as it solves a lot of problems that vCAC doesn’t yet, and it’s also more relevant for service providers, which is a market I understand after working at an ISP for so many years and architecting a few public clouds. I would encourage people who are in an organisation with vCD or working for a Cloud Service Provider to give VCAP-CIA a go. My plan now is to brush up a vCloud design I did a while ago and submit it for VCDX-Cloud. If I’m successful hopefully I’ll be in the first five double VCDX’s.
—
This post appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2014 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
You might recognise the title in different terms. It’s very similar to “The King is dead, long live the King!”. As Wikipedia explains the original phrase was translated from the French Le roi est mort, vive le roi !, which was first declared upon the accession to the French throne of Charles VII after the death of his father Charles VI in 1422. In France, the declaration was traditionally made by the duc d’Uzès, a senior peer of France, as soon as the coffin containing the remains of the previous king descended into the vault of Saint Denis Basilica. So what’s this got to do with VMware vCloud Director I hear you ask?
Has VMware killed vCloud Director? What should you do if you have vCloud Director or if you’re thinking about implementing it? What does this mean for the vCloud Director based certifications such as VCP-Cloud, VCAP-CIA, VCAP-CID and VCDX-Cloud. I’ll give you my opinion of the answers to these questions in this article. It’s all about the Software Defined Datacenter.
This year, in August at VMworld USA in San Francisco, vCloud Director was pretty much completely missing from the event. Except of course my session on running Databases at Maximum Performance in a Software Defined Datacenter – VAPP4683 (Presented with Mark Achtemichuk in San Francisco and Andrew Mitchell in Barcelona). Many customers and partners were lamenting the death of vCloud Director. This wasn’t quite what VMware was doing, as I’ll explain during this article. Needless to say some customers and partners I spoke to at the event were not at all happy with the decision. Some customers had invested multiple millions of dollars in vCloud Director projects for Private Clouds.
For anyone that is not familiar with VMware vCloud Director, it’s a software solution that allows any company or service provider to implement a software defined datacenter, or at least a good number of components of it. It allows for self service automated provisioning of virtual machines and virtual applications into a private or public cloud. So you can deploy your applications whenever you want and within minutes they’ll be available. The best use case for private clouds in my opinion is to streamline the software development lifecycle and greatly improve the economics of software development projects. But it also has benefits for production workloads as well, as it takes away a lot of the manual tasks and decisions that administrators would have traditionally had to make when provisioning new applications. I have had customers that have reduced their project development and testing time by 50% using vCloud Director. In addition to reducing the test and development time customers have reduced their defect rate by orders of magnitude, which means their software is more reliable and they find many less defects after the solution has gone into production, which in term improves availability, performance and lowers ongoing maintenance costs.
During VMworld VMware announced a new strategic direction, and vCloud Director wasn’t it, at lest not for Enterprises. The new direction was vCloud Automation Center (vCAC) for Enterprises (private cloud), which was introduced with one of the best integrated demo’s I think I’ve ever seen during the main keynote on day two (called the Mother of all Demo’s). What this meant is that vCloud Director was for only going to be for cloud service providers (public cloud). As part of this change of direction VMware announced that vCloud Director 5.5 (which was released shortly after VMworld) would be supported through to Q3 2017 (4 years instead of the usual 2), and vCloud Networking and Security (Formally vShield) would be supported through to Q3 2016. Neither would be available for sale separately from September 2013, you’d have to have the vCloud Suite. A version of vCloud Automation Center is available and was added to every edition of the vCloud Suite, dependant on the edition purchased. So everyone with vCloud Suite, get vCAC.
vCloud Director is Dead?
So is VMware killing or has killed vCloud Director? No! Far from it. VMware is investing more in vCloud Director, but is focusing the investment on public cloud service provider requirements and the requirements of the VMware vCloud Hybrid Service (vCHS). This is why the title of this article if vCloud Director is Dead, Long Live vCloud Director. It will be around for a long time to come and will deliver ever more value to the world, with a slightly changed focus. VMware will be making the functionality from vCloud Director that is for Enterprise available through a combination of vCloud Automation Center and vCenter, some features of vCloud Director not applicable to Enterprise use cases will not be making the transition (primarily multi-tenancy and multiple authentication domains).
So does this mean you all have to rush out and implement vCloud Automation Center (vCAC) or migrate to vCloud Automation Center or that you have just seen your investment in vCloud Director flushed down the toilet? No! The change in strategic direction isn’t like turning on a light switch and everything is working. Just because marketing might say vCAC is the new way to go doens’t mean it’s actually reality today. Your investment is protected and you get support through to Q3 2017 (vCloud Director 5.5), plenty of time to get a massive ROI, and you’ll get bug fixes and patches during this time. This change in direction from VMware will take place over a number of years, and you will be given time to adapt, and the migration tools to do it. Why is vCloud Networking and Security support ending a year earlier that vCloud Director, I have no idea, especially seeing it’s an important part of a vCloud Director environment.
Right now vCloud Automation Center isn’t even feature equivalent to vCloud Director yet (based on version 5.2). If you’re using vCloud Director for self service development and test environment provisioning and automation, or self service catalog, it’s either going to be difficult, extremely hard, or impossible to get the same functionality out of vCloud Automation Center, at least the current shipping version and probably the next one also, especially if you don’t want to spend a lot on services (Remember Lab Manager vs vCloud Director 1.0?). VMware also needs time to create migration tools for customers to make the transition to the new way of doing Software Defined Datacenter for the enterprise, as there is no in-place upgrade path possible for vCloud Director to vCloud Automation Center. Getting the full migration strategy in place for customers is going to take time and it isn’t there yet.
vCloud Director isn’t dead, but what should I do now if I have it?
Firstly, don’t panic! If you’re an existing vCloud Director customer, whether the project has been delivered and is in use, or still in flight, I would highly recommend you continue down the vCloud Director path. Especially if your use case is self service catalog, self service provisioning of isolated test and dev environments, and you’re going to be using vCloud Director primarily for streamlining your SDLC. I would not recommend throwing in the towel with vCloud Director right now, it is an excellent solution for the right use cases and the right requirements. Having designed and implemented about a dozen private clouds and around half a dozen public clouds with vCloud Director I’ve seen the value it can deliver.
I would further recommend that when the next version of vCloud Automation Center (whatever comes after 5.2) is released that you consider implementing that along side but separately from vCloud Director for self service provisioning of production workloads, or in a test environment so you can at least get used to it. It goes without saying that if you’re not on vCloud Suite licenses you should get there as soon as possible, it’s the best solution for delivering a software defined datacenter and it’s incredibly cost effective compared to purchasing the equivalent licenses separately. vCloud Suite licenses will be a worthwhile investment, and will get you the optimal ROI.
What if I’m a net new customer looking at building a software defined datacenter with vCloud Director?
If your use case for vCloud Director is primarily for production workloads and provisioning and managing the lifecycle of production systems, and you’re a net new user (no existing vCloud Director), then I would recommend you work closely with VMware to plan an implementation of vCloud Automation Center as soon as the next version is available. The reason for this is there is no in-place upgrade path from vCloud Automation Center 5.2 to the next version, it will be a migration. So you might as well wait for the next version to become available if you can, or be prepared to stay on vCAC 5.2 for a while until the migration process is well defined and the tools are there to make it straight forward (or as much as it can be). I know a couple of customers that are on vCAC 5.2 and are happy with it for now for their use cases. Like vCloud Director, vCAC is a great solution for the right use case and the right requirements, and of course it’s part of the vCloud Suite.
If your use case for vCloud Director is making your SDLC, Dev/Test greatly more efficient and streamlined, and you’ve got no current vCloud Director environment, then I’d recommend you go with vCloud Director and the vCloud Suite. It can be implemented fairly quickly (with competent and skilled people), and you’ll get good use out of it till 2017. This’ll give VMware time to get vCloud Automation Center and vCenter sorted out to be feature equivalent (or close enough) to vCloud Director, and for the migration tools to become available and mature. You should work closely with your VMware partner and VMware to plan an eventual transition to vCAC, when the time is right, and once you’ve got your ROI.
If you’re not an enterprise, but a cloud service provider instead, then the choice and long term solution is easy, it’s vCloud Director. vCloud Director is here to stay and will be developed for the service provider market.
What does this mean for the VMware vCloud Director based Certifications?
The vCloud Director based certifications, such as VCP-Cloud, VCAP-Cloud Infrastructure Design, VCAP-Cloud Infrastructure Administration, and VCDX-Cloud will all continue. They will continue to have value to customers that are running vCloud Director, and they’ll have a lot of value for public cloud service providers. VCDX-Cloud will probably be valuable only to public cloud service providers in the future, or to VMware Partners that are providing consulting and services around private and public clouds. It’s likely that VCDX-Cloud will adapt to non-vCloud Director technologies, especially as vCloud Automation Center and OpenStack become more a part of the VMware landscape. I’m in the process of working towards VCDX-Cloud, and this change of direction by VMware has not altered that plan. I would encourage anyone that is working for a public cloud provider or is planning to work for a public cloud provider (based on VMware vCloud Director technology) to go through the vCloud Director based certifications.
Final Word
There are probably many reasons why VMware has chosen this new path for vCloud Director Enterprise customers. vCloud Director was hard to integrate with the other VMware solutions, such as Site Recovery Manager. Partners were very slow to support backing up and restoring vCloud Director, especially the tenant objects (this can be done now with partner provided solutions). If you can’t easily and efficiently protect the data inside the solution it’s hardly suitable for an enterprise production workload right? The adoption rate was probably less than expected, but what do you expect when vCloud Director originally wasn’t feature equivalent to the product it was meant to replace (Lab Manager), had no migration path, and had no training for a long time. vCloud Director was complicated and had lots of moving parts, was hard to understand (I don’t agree with this, but I know some people have this opinion). Maybe many people didn’t understand and couldn’t articulate the value proposition for vCloud Director as it was very different to a traditional infrastructure or virtualization solution. What business problems was it actually going to solve, what was the ROI and what were the benefits (hint: refer to the start of this article for some)?
Whatever the reasons are I think this change is a good thing. It will allow VMware to deliver solutions (over time) that solves the Enterprise and Service Provider use cases, is simpler and more automated, more focused. For Enterprises the solution will have much easier integration into the wider VMware product stack. For Service Providers they’ll be able to more seamlessly integrate with their customers, be more scalable, and have significantly more easier and less disruptive cloud maintenance. It will be easier to deliver the Software Defined Datacenter Vision and Hybrid Cloud. All the while protecting existing investments and providing massive value.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
VMware’s vCloud Director is a very good way for organisations to start to take advantage of cloud computing, including private, public and hybrid models. Cloud computing can offer new efficiencies and cost savings for organisations that optimise it’s use. But where do you start? If you go searching for best practices, design considerations and references for designing and building a vCloud Director environment you will find plenty for large scale deployments. But it might seem difficult to find much in the way of design considerations for starting off with a small vCloud Director environment, such as for a proof of concept, small lab or pilot. I have previously written about Considerations For Designing a Small vCloud Director Environment – Allocation Models, which discusses takes you through which allocation models there are and which ones you might want to use. In this article I hope to offer some advice that will allow you to dip your toes in the water and get up and running quickly without much complication, while allowing you to scale up in the future. This article is a continuation in the series and looks at the different options for storage at a high level and offers some recommendations that you might want to consider. Future article will discuss the rest of the components you need to consider.
Even if designing for a small environment one resource I highly recommend you review if the vCloud Architecture Toolkit (vCAT), which is a VMware Validated Architecture for Cloud Computing and supporting tools. The vCAT is fully supported by VMware, so if you leverage the design considerations and guidance contained within it you know you can get support.
This article focuses on Storage Design in vCloud Director. In future articles I will cover additional design considerations.
Pre-requisites and assumptions
Classes of Storage and Provider Virtual Datacenters
In versions prior to 5.1 of vCloud Director your storage design and storage allocation would have had a major impact on how many Provider Virtual Datacenters (PvDC’s) and Clusters or resource pools you would require. This is because each PvDC could have only a single tier or class of storage. So the storage tier or class became directly linked (tightly coupled) to the overall service definition of the PvDC, i.e. the characteristics that define what a particular class of service is made up of, such as standard, enhanced or premium (Bronze, Silver, Gold) etc. As an example in your Standard PvDC you might have had 2.4GHz Xeon CPU’s, 96GB RAM (1066MHz) per Host and NFS Datastores backed by SATA disks (RAID 6 or RAID DP). In your Enhanced PvDC you might have had 2.93GHz Xeon CPU’s, 256GB RAM (1333MHz), and FC Connected SAN with FC 10K disks in RAID 5. As soon as you wanted to offer another tier of storage you would have needed to offer another PvDC, even if the rest of the service model wasn’t changing.
So what is the impact of adding another PvDC if you want to add another class or tier of storage? Well if you were to follow standard VMware Design Guidance (this is the new term that has replaced best practice), then you would have to set up an entirely new cluster of hosts. Each PvDC should be backed by a Cluster of 2 or more hosts with HA and DRS enabled. In theory it is possible to use a single host in a PvDC, but then you can’t test HA or DRS functionality with vCD. You may be able to see a problem here for a small environment that will be used for a Pilot, PoC or Lab.
The answer to this conundrum in versions of vCD prior to 5.1 is to use resource pools inside of a cluster of 2 or more hosts, instead of using different clusters of hosts, to back your PvDC’s. Each PvDC is then mapped to one of these resource pools. The different tiers or classes of storage are allocated to all hosts in the cluster and the allocated to the correct PvDC. OrgVDC’s are then created in the correct PvDC to consume the different classes of storage. There was and still is no option (as of vCloud Director 5.1) to have a single VM utilise resource from multiple service tiers or classes of storage.
Using resource pools instead of clusters does have drawbacks. Firstly there is the resource pool priority-pie paradox, which may impact the allocation of resource for any given VM or sibling resource pool. Secondly a resource pool is not allowed to consume 100% of the parent resource pools resources. Depending on versions of vSphere backing the resource pool it might only be able to consume 94% of the parents resource pool. This will potentially leave 6% unallocated. You’re also not able to segment service definitions by different type of compute characteristics as resource pools span the cluster, which isn’t a problem if you’re doing this for the sole reason of allowing multiple classes of storage. Multiple PvDC’s may be competing for resources though. It will be more complicated when you come to expand out the environment, for example if you wanted to move a PvDC to another cluster.
The workaround to provide different tiers or classes of storage to a single cluster is only required in versions of vCloud Director prior to 5.1. From vCloud Director 5.1 you can assign multiple storage tiers to a single PvDC and even use Storage Profiles, Storage Clusters and Storage DRS, which was also not possible prior to vCD 5.1. Thus the class or tier of storage is now not required to be coupled or linked to the overall service definition. You can now have multiple storage service definitions per service class, such as Big Data (SATA) and Fast Data (15K FC), in standard, enhanced and premium PvDC’s. This means you can have a single PvDC in a single cluster of 2 hosts, and still have multiple tiers of storage. This is a very good reason for using vCloud Director 5.1 for your vCloud environment.
The above assumes that you are not using Auto Tiering on your arrays to automatically allocate the different tiers of storage. If you are using Auto Tiering then you would only have multiple service tiers and therefore PvDC’s (prior to vCD 5.1) or Storage Clusters and Storage Profiles (vCD 5.1 and later) if you are offering different auto tiering policies. When using array auto tiering with vSphere 5.1 and vCloud Director 5.1 it is recommended that IO load balancing be disabled. This is because the array is handling that for you and SDRS may make false recommendations.
Datastore Sizing
Because of the somewhat unpredictable size of VM’s in a vCD environment it’s generally recommended to size datastores to be fairly large and have fewer of them. In a normal vSphere environment you may have had datastore sizes of 292GB, 512GB or 1TB etc for enterprise workloads, however in vCD you might want to use 2TB or 4TB sizes (or larger), and have fewer. This allows better placement of VM’s when the size of each VM varies a lot. This also helps a lot when using Fast Provisioning (Linked-Clone Technology) explained below. The lager size datastores also help reduce the risk of running out of space during rapid growth. This guidance is generally applicable to test/dev, pilot, PoC or lab environments and is what I’ve found generally works well. Having the larger size datastores allows potentially more efficient use of storage, especially when combined with thin and fast provisioning (explained below) but may trade off ultimate performance. A lot will still come down to the storage technology you’re using.
Thin Provisioning and Fast Provisioning
Thin Provisioning and Fast Provisioning are both techniques that when implemented allow for more efficient use of storage resources and for the potential of storage overcommit. Provided you take care both can be used safely and allow for significantly better storage economics. Like all techniques that allow improved efficiency due to overcommitment the underlying assumption is that not everything needs the same scarce resources all at the same time. I’ll briefly explain how they work and what you need to watch out for.
Thin Provisioning works by only allocating blocks to a VM as they are needed by the guest operating system, unlike a thick provisioning which allocates all storage assigned to a VM up front. This means that in cases where you know 20% or 30% of allocated storage is only there ‘just in case’ or ‘because the OS said we had to’, you can effectively use that elsewhere for other VM’s. Provided not all of the VM’s that are using thin provisioning need all their storage all at once you can get effective overcommitment of the underlying datastore and this boosts your ROI. All without any significant performance penalty (assuming modern hardware environment). Using Thin Provisioning can introduce an additional management overhead as you have to ensure your datastores don’t run out of space. Storage DRS in vCloud and vSphere 5.1 environment can help with this though and reduce the management overhead. Even with the additional management overhead in many cases the improved economics can far outweigh the risks.
Fast Provisioning is the vCD term for Linked-Clones (Similar to vCD’s predecessor Lab Manager and VMware View). With Fast Provisioning you have a parent image (a.k.a. Shadow VM) and multiple children are linked back to the parent. So you effectively have only one main copy of a VM, each other VM is only a set of configuration files and delta files. The parent image is read only and any changes are written to the delta files. You could think of this similarly to single instance storage in an email system, where only one copy of an email is stored on disk and multiple mailboxes link back to the main copy. If you’re linked clones have a parent image that contains the OS and base applications and don’t change much you could literally have hundreds of copies with only a fraction of the assigned storage used. When using Fast Provisioning each parent image can have up to 30 linked clone images. Once you get past this limit another parent image is cloned and the linked clone chain starts again. There are also considerations when your chains need to cross datastores. All of which is explained in the vCD documentation so I won’t go into it here. The potential storage efficiency gains by using Fast Provisioning’s linked-clone technology are stagering. 10x storage overcommitment is possible based on my experience, which is like reducing your storage investment by 90%, or reducing the cost of storage 90%. But like all things there are tradeoffs and risks.
A couple of things to note about Fast Provisioning. Firstly disk alignment is an issue. Images are initially aligned, and the parent image is aligned, but as the images start to grow the IO’s will be unaligned. This will have an impact on performance. Secondly as the parent image is shared by all the linked clones is on VMFS and you’re using a version of vSphere prior to 5.1 your cluster size will be limited to 8 hosts. This is because the maximum number of hosts that can have the same file open is 8 on VMFS prior to vSphere 5.1. This is not a problem with NFS storage, or with VMFS in vSphere 5.1 and later, both of which support cluster sizes up to the maximum of 32. In saying this though, it’s not going to be an issue for a small environment of a couple of hosts, which is what we’re discussing here.
Both Thin Provisioning and Fast Provisioning can be used together and complement each other. By using both you can massively improve the efficiency of your storage and boost your return on investment. But because of the potential for up to 10x storage efficiency or overcommitment when both thin provisioning and fast provisioning are combined (based on my experience in a number of vCD environments) there are risks that need to be managed. You should seriously consider having burst capacity available to cater for any peak demands and also pay careful attention to how much storage is allocated to each OrgVDC.
Recommendations
If you are using vCD prior to 5.1 then I recommend you implement PvDC’s based on resource pools in your small cluster of 2 hosts so that you can demonstrate the use of multiple classes or tiers of storage. This allows you to keep the environment simple and small for Pilot, PoC, or Lab use. If you are using vCloud Director 5.1 then you don’t have to create multiple PvDC’s and assign them to resource pools. You can simple create a single PvDC and assign the entire cluster to it. You can then use Storage Profiles, Storage Clusters, and Storage DRS to present the different classes or tiers of storage.
For detailed explanation and considerations of using clusters or resource pools to back PvDC’s I recommend you read Frank Denneman’s article Provider VDC – Cluster or Resource Pool.
Size your datastores so you have fewer of them but they are generally large (2TB to 4TB is fairly common). This allows the best storage utilization and efficiency, especially when using Fast Provisioning and Thin Provisioning. Start out with a small number of datastores and then grow as required.
Use thin provisioning to make the most efficient use of your storage, there is no significant performance impact for doing so, but beware of the risk of sudden growth and plan accordingly. Use Fast Provisioning for dev/test workloads and for situations where storage space efficiency is more important than performance. There is a performance overhead to using Fast Provisioning’s linked-clone technology, but the economics are compelling in a lot of cases.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
VMware’s vCloud Director is a very good way for organisations to start to take advantage of cloud computing, including private, public and hybrid models. Cloud computing can offer new efficiencies and cost savings for organisations that optimise it’s use. But where do you start? If you go searching for best practices, design considerations and references for designing and building a vCloud Director environment you will find plenty for large scale deployments. But it might seem difficult to find much in the way of design considerations for starting off with a small vCloud Director environment, such as for a proof of concept, small lab or pilot. In this article I hope to offer some advice that will allow you to dip your toes in the water and get up and running quickly without much complication, while allowing you to scale up in the future. This article looks at the different allocation models. Future article will discuss the rest of the components you need to consider.
Even if designing for a small environment one resource I highly recommend you review if the vCloud Architecture Toolkit (vCAT), which is a VMware Validated Architecture for Cloud Computing and supporting tools. The vCAT is fully supported by VMware, so if you leverage the design considerations and guidance contained within it you know you can get support.
This article focuses on Resource Allocation Models in vCloud Director. In future articles I will cover additional design considerations.
Pre-requisites and assumptions
Allocation Models
vCloud Director allows resources to be allocated from a Provider Virtual Datacenter (PvDC) to Organisation Virtual Datacenters (OrgvDC) for consumers to use. The allocation is done in accordance with three different models. Pay as You Go (PAYG), Allocation Pool, and Reservation Pool.
The advantage with PAYG is that you get a defined reserved amount of resource per VM when the VM’s are powered on only, so they don’t consume any resources from the OrgVDC or PvDC while they are powered off. The system admin defines the overcommitment and service levels for compute resources. New in vCloud Director 5.1 the PAYG Virtual Datacenter can have a limit set to prevent one OrgVDC consuming all cloud resources.
With Allocation Pool the OrgVDC consumes the guaranteed portion from the PvDC regardless if VM’s are powered on, but this at least gives them a defined amount of resources. Each VM then is set a reservation equal to the percent that is guaranteed and the VM’s deployed can consume the resources up to the defined limit of the allocation model. Powered Off VM’s don’t consume resources from the OrgVDC. The system admin defines the overcommitment and service levels for compute resources. New in vCloud Director 5.1 all vCPU’s have a defined limit set which will impact how many VM’s can be powered on within an OrgVDC. This vCPU limit is defined by the System Administrators.
With the reservation pool the you set a defined limit and then it’s up to the tenant of the OrgVDC to define the level of overcommitment and how much resources are reserved for each VM/vApp. You guarantee the resources from the PvDC to the OrgVDC and the OrgVDC consumes those resources regardless if a vApp is powered on. VM’s or vApps can have different reservations or no reservation. It’s up to the tenant to choose. But the catch is the tenant or consumer can cause performance problems within their OrgVDC if they overcommit too aggressively. The tenant needs to take some care with capacity planning around their usage.
In some ways an Allocation Pool with 100% guaranteed is superior to a Reservation Pool, as the system admin / provider is defining the SLA of the pool and VM’s to be 100% guaranteed, I.e. Allocation = Reservation. The tenant then can’t get themselves into trouble as easily. It’s up to the system admin to manage capacity.
The Allocation Pool and Reservation Pool offer more predictability of billing to the tenant, but are less efficient from a service provider perspective in terms of resource utilization. PAYG offers less predictable billing to the tenant, but more efficient resource utilization potentially, and more flexibility in a small environment.
Recommendation
When designing a small environment I generally recommend you start with PAYG resource models, especially where usage is unknown. This allows the best sharing of resources between OrgVDC’s and Organisations. PAYG provides a dynamic on demand environment, but can still have an upper limit set per OrgVDC. The PAYG model supports an Elastic VDC, which means it can grow across clusters. This makes it easy to expand the environment as and when needed. The Allocation Pool Model also supports elastic vDC from v5.1 with some restrictions, but it will depend which update version is actually being used on what functionality of the Allocation Pool model you receive.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
It’s great to see that a lot of people are starting to consider upgrading to vSphere 5.1 and are upgrading their lab environments. vCloud Networking and Security is one of the jewels in the crown for VMware and it’s expanded functionality, including high availability, means it is an even stronger candidate for enterprise firewall replacement in addition to it’s use cases with vCloud Director. I had used the previous version in an enterprise firewall replacement project and discussed that in Enterprise Firewall Replacement with vShield Edge and vShield App.
There are a number of considerations when upgrading to vSphere 5.1 covered in my article vSphere 5.1 Generally Available – Important Upgrade Considerations. However a specific issue has come up with some upgrades to vShield Manager 5.1 that you need to be aware of. This article will try and help address this particular issue.
A number of people have been reporting problems with vShield Manager after the upgrade to 5.1 with symptoms of a kernel panic after modifying the guest to 2 vCPU’s and 8GB RAM as recommended. The reason the kernel panic is occurring in most cases is that the vShield Manager is now 64bit and will require you to change the Guest OS type in vCenter from Other 32bit to Other 64bit. You will also have to change the vSCSI controller from BusLogic Parallel to LSI Logic Parallel. Failure to do this will render your vShield Manager VM inoperative. If you make these simple changes when you change the vCPU and RAM you should have no problems. Remember with vShield Manager 5.1 there are 3 different configuration types and it’s important to match the virtual hardware configuration to the correct configuration type. I would expect a KB article to be posted by VMware very shortly on this topic and when I know what the KB number is I will link through to it.
Based on the above and another issue that is discussed in KB 2035939 re vShield Edge Disk Full Error. I would recommend that you upgrade to vShield Manager 5.1.1 as soon as practicable.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
vSphere 5.1 was greatly anticipated by all of the VMware Customers that watched the VMworld keynote address and attended the early VMworld sessions and today it became generally available for download on the VMware web site. Even though this is a dot release for VMware it brings some important new features and functionality, not just for the core vSphere hypervisor, but also the other products that make up the core of the vCloud Suites, including vCloud Networking and Security, vCloud Director and Site Recovery Manager. This article will cover some important considerations that you need to consider when you are planning to upgrade to vSphere 5.1.
This article won’t go into detail on the new features of vSphere 5.1, but there are many. I will cover some of the key ones in a VMworld wrap up article. This objective of this article is to give you some brief highlights of some of the important things to consider (in my opinion) when planning an upgrade to vSphere 5.1 and highlight some important known issues. I would recommend that you review the What’s New in vSphere 5.1 document for all of the great new features and benefits. These considerations are not exhaustive.
I would like to thank VMware for getting out all of the core vSphere / vCloud suite components at the same time with this release and also getting out the minor compatibility releases for the management tools that integrate into them as well. This will make the upgrade planning and process much easier for customers overall and means that customers can take advantage of the additional benefits in vSphere 5.1 much earlier than was possible with previous releases. Keep up the great work, it is greatly appreciated.
VMware has put in considerable effort to advise customers of the various upgrade scenarios that are supported. The vSphere 5.1 Upgrade Guide is fairly comprehensive at 204 pages. I would highly recommend you read and understand it before attempting the upgrade in addition to going through all the product release notes that are relevant to your environment.
vRAM is gone! Now you have the option of a vCloud Suite License. If you choose this option you will license your environment by CPU socket, with unlimited cores, unlimited memory, and entitlement to run an unlimited number of the included suite software components (based on suite edition) on all licensed CPU sockets. An important thing to note is the vCloud Suite licenses can’t be split and their component parts. There are three suite editions available each with different software components included. I would recommend that you review and compare the editions.
As with vSphere 4.1 and 5.0 vCenter is supported on 64bit OS only. Now though there is the important addition of Single SignOn (SSO). This makes auditing and control of the environment much more robust, and at the same time creates an additional component and design considerations. VMware with the vSphere 5.1 release now allows for the Inventory Service, in addition to the SSO service to be split out for scalability and performance reasons. Note as of View 5.1 the View Composer service can also run on a separate server. However there is no guidance currently as to when it makes sense to run a split install of this nature. I’d recommend you check out my article vSphere 5.1 Gotcha with Single Sign On (SSO).
vCenter 5.1 features the new full function vSphere Next Generation Client, a.k.a. the vSphere Web Client. There is now more functionality in the web client than in the traditional C# client. However not all plug-ins and components are fully integrated to the new client, and not all plug-ins and components work with SSO currently. The scalability and usability of the web client has been greatly improved and this is overall a great improvement in the way vSphere environments are managed. Cisco Nexus 1000V 4.2(1) SV1(5.2) is required for vSphere 5.1 support.
Update Manager can be used to upgrade 4.x and 5.0 hosts to 5.1. Review the important known issues below and all the release notes. The behaviour of lockdown mode has changed again in vSphere 5.1 and there are important enhancements to the way AD Auth for vSphere hosts works, which allows greatly enhanced audit-ability (among other things). Check that you have the drivers you need and that your hosts are compatible and on the HCL as normal. There are some important new deployment possibilities for Auto Deploy, which now includes stateless caching and stateful install (think an easier way to install instead of using Kickstart scripts). Even if you don’t plan on using Auto Deploy my recommendation is to use Image Builder to create your upgrade image and include all the necessary drivers and OEM CIM providers and agent modules (such as vShield App, FDM, Nexus 1000v VEM etc) that you need. Some of the OEM vendors have already released their customized images that you can leverage to save some time, but you might want to pull out some of the modules to trim them down. Regardless if you’re using Auto Deploy or not consider using the image profile that doesn’t include VMware Tools. This will save about 50% storage for the hypervisor image, but beware you will need to create a VMware Tools locker location for all your hosts to be able to grab the VMware tools bundles (see Setting Up a Shared VMware Tools Directory).
Update Manager and Update Manager Download Service only installs on 64bit Windows OS.
There are limited Storage Replication Adapters currently available. Ensure your array is currently supported at the time you go to upgrade your environment. The upgrade of SRM and vCenter Server go hand in hand. As of the date this article is published the product interoperability matrix has not yet been updated.
Optionally supports SSO for authentication. Storage Tiering within a single PvDC may change how you want to define your service offerings and pricing/charging within a PvDC. Org vDC Networks constrained within an Org vDC replace Organization wide networks as the default. There is an option to ‘share’ Org VDC networks to maintain compatibility and allow a smooth upgrade. VXLAN now integrated in vCloud Director and part of vSphere Distributed Switch (note name change). RHEL 6.2 now supported as a vCD Cell OS. You will have to upgrade vShield Manager as part of the upgrade process and this may require a change of virtual hardware configuration (see Kernel Panic in vShield Manager after Upgrade to 5.1 and KB 2035939).
If using previous version of vCenter Server Heartbeat you will be required to upgrade to 6.5 for vCenter 5.1 support. vCenter Server Heartbeat 6.5 supports the new vCenter components and all vCenter deployment architectures, including split install. vCenter Server Heartbeat is backwards compatible with previous versions of vCenter 4.x and 5.0. vCenter Server Heartbeat also supports protection of View Composer 3.0 in a separate server from vCenter. Consider the operational implications of having vCenter Server Heartbeat pairs for all of the supported components in a split install scenario, initially I would recommend that the components remain on the vCenter Server unless there is a good reason to split them out, and in that case consider if they need to be protected with vCenter Server Heartbeat.
VMware has published a separate guide to Replacing SSL Certificates in vCenter 5.1 and ESXi 5.1. I would highly recommend you DO NOT review this document if you are running trusted / CA signed SSL certificates in your environment. It will cause you more trouble than it’ll solve. I have published two articles on SSL certificates in vSphere 5.1 based on work I did with a wider VMware Team that got made into KB articles. We have tested the procedures. I would recommend that you use these articles – Updating CA SSL Certificates in vSphere 5.1 and Updating CA SSL Certificates in vSphere 5.1 vCenter Virtual Appliance. I expect VMware will review their official product documentation as part of the next release so that we don’t have to go through multiple KB’s.
There are minor point release updates to vCenter Operations Manager, Virtual Infrastructure Navigator, vCenter Configuration Manager, vCenter Chargeback Manager and other VMware management components that introduce compatibility with vSphere 5.1 and are available for download now.
Here is a selection of some of the known issues I think are important, there are others that are covered in the release notes, but these ones stood out for me.
You may not be able to access vCenter Server logged into the vSphere Web Client as the default SSO admin (admin@system-domain). This is by design. See my article vSphere 5.1 Gotcha with Single Sign On (SSO) for the reasons why and how to avoid being locked out of your vCenter.
Enabling or Disabling View Storage Accelerator in View 5.1 might cause ESXi 5.1 hosts to lose connectivity to vCenter Server – see vSphere 5.1 Release Notes. vSphere 5.1 does not currently support any version of VMware View. View 5.1 is explicitely not compatible with the GA release of vSphere 5.1. There has been an alert posted on the VMware Downloads page and referenced through to KB 2035268.
Update Manager 5.1 reports the compliance status as Incompatible when scanning or remediating ESXi 5.x hosts that belong to an HA cluster – see Update Manager 5.1 Release Notes
PowerPath/VE 5.7 and 5.7 P01 and vSphere 5.1 are not compatible. If you are using PowerPath/VE in your environment you will need PowerPath/VE 5.7 P02 and a vSphere patch that will be available from support – see VMware KB 2034796
Unicast Flooding with Multi-NIC vMotion – see The Good, The Great, and the Gotcha with Multi-NIC vMotion in vSphere 5
vShield Manager Upgrade Bundle may download as a .gz, which is unsupported in the Upload Upgrade Bundle section in vShield Manager 5.0. The file needs to be renamed .tar.gz to allow the upgrade to succeed. This appears to be a problem only with the Google Chrome Browser. If you don’t wish to rename the file after download you may choose to use an alternative browser.
CA Signed SSL Certificates may cause trouble with the upgrade process of vCenter. I have heard reports of difficulties with the upgrade process of vCenter particularly with registering Inventory Service and SSO with vCenter when using CA Signed SSL Certificates. As I’m using CA Signed Certificates in my lab environment I will update this article when I have completed my upgrade. If you want a way to fully manage the certificate lifecycle and replace certs automatically then you’ll want to check out vCert Manager – Changing VMware SSL Certs Made Easy. When released this aims to support vSphere 5.1 and will make the process as easy as clicking a button. In the meantime you can review Updating CA SSL Certificates in vSphere 5.1 and Updating CA SSL Certificates in vSphere 5.1 vCenter Virtual Appliance, which will guide you through the update process for SSL Certs.
Troubleshooting SSL certificate updates and Single Sign On (2033240)
vCenter Single Sign On installer reports: Error 29155. Identity source discovery error (2034374)
Kernel Panic in vShield Manager after Upgrade to 5.1
vCloud Director 5.1 Download Page
vCloud Networking and Security Download Page
Site Recovery Manager 5.1 Download Page
vCenter Server Heartbeat 6.5 Download Page
Understanding Stateless Caching and Stateful Installs with Auto Deploy (2032881)
Enabling vSphere Distributed Switch Health Check in the vSphere Web Client (2032878)
Understanding vSphere 5.1 Network Rollback and Recovery – Disabling Network Rollback (2032908)
vSphere 5.1 offers some great new features and benefits and an upgrade should be seriously considered. There are enhancements in a number of areas including (but not limited to) quality of service, reliability, scalability, audit-ability, management and performance. vSphere 5.1 continues the tradition of being the best place to run Business Critical Applications. But like all major infrastructure upgrades requires some through and planning. I have already completed the upgrade process for multiple clients successfully and for the most part everything has gone well (with proper planning and testing). I wish you luck with your upgrade process.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
VMware has just announced that all their security hardening guides now have a new home. A single page that customers and partners can visit for all the latest hardening guides for vSphere and other VMware products. The url is http://vmware.com/go/securityguides. I would suggest you bookmark this now and visit it regularly.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.
I’ve been doing a lot of work with vCenter Heartbeat recently, which is a product I really like and my customers appreciate and see a lot of value from. I was very fortunate to get an opportunity to speak to the product manager about the product in quite a lot of depth. While I can’t tell you anything that is covered by NDA, I can tell you some interesting and important information that has come out of these conversations. This is extremely relevant to vCloud Directory environments where SQL is being used as the database, and also Enterprise environments using vCenter Heartbeat that have other VMware Management Tools such as Site Recovery Manager.
VMware Best Practices and common sense both suggest it’s a good idea to build in availability for the databases that are the Achilles Heel of your virtual infrastructure, such as the databases for vCenter, vCloud Director, Site Recovery Manager, vCenter Configuration Manager, vCenter Chargeback etc. However in some cases for some of these products traditional DB high availability solutions such as SQL Mirroring or Failover Clustering are not supported by VMware. So you might choose to just protect the database server with VMware HA, and that might be fine in most cases, even though the operating system instance then becomes a single point of failure and has to go down when some OS patches are applied. If your database can get by with only 1 vCPU you could also consider VMware FT.
One option that some customers may think might be viable is using vCenter Heartbeat to not only protect the vCenter Database, but also the database of the other VMware Management Tools and components (like vCloud Director, Chargeback or Site Recovery Manager). This would eliminate costly complex solutions and the outages that can sometimes be associated with them. This also has the advantage of minimizing SQL licenses, and also using a common protection mechanism for the vCenter System and also it’s database and the related database of the other management tools. I know of a number of customers that have done just this and used vCenter Heartbeat to protect their vCenter, vCloud, Chargeback, and other VMware Product DB’s. You might think this sounds like a good idea, but you would be wrong!
So I am clear: This is not a supported configuration and this is explicitly against the VMware vCenter Server Heartbeat EULA. vCenter Heartbeat can only be used to protect the remote SQL Databases of vCenter, Update Manager, and View Composer and only if running on the same shared database instance and server.
So can you still run a single shared Database server for all the VMware SQL DB’s? Yes you can, but you must have two or more SQL instances installed on the shared SQL server. One instance for the Heartbeat Supported DB’s that can be protected by vCenter Heartbeat, and another SQL instance (or more) for the DB’s of the products that can’t be protected by vCenter Heartbeat. This might not be an optimal or feasible design choice, but it is supported. The only other alternative is completely separate DB servers for the vCenter Server Heartbeat supported SQL Database schemas (vCenter, Update Manager, View Composer), and one or more for everything else.
All of the supported plug-ins and components that can be protected are listed in the vCenter Heartbeat Installation Guide. You will not see the DB’s for Site Recovery Manager, Chargeback, vCloud Director, Configuration Manager or VMware Service Manager listed as supported, because they are not. You will also not see the View Events Database listed as supported either.
Perhaps the product marketing blurb on the VMware web site could be made more clear, I have quoted below and was current as at 30/03/2012 (03/30/2012):
“Ensure Availability and Disaster Recovery
VMware vCenter Server Heartbeat delivers high availability and disaster recovery for VMware vCenter Server and all of its components across the LAN or WAN, including the database and plug-ins like VMware vSphere Update Manager, eliminating costly, complex outages. VMware vCenter Server Heartbeat protects and recovers the VMware vCenter Server database instance, even if it’s installed on a separate server.”
It’s the “plug-ins like VMware vSphere Update Manager” statement that could be a little bit misleading. Just be aware this doesn’t mean you can use it for protecting the database of things like vCloud Director.
Another important thing to note about vCenter Heartbeat is that it only supports protecting SQL 2008 R2, not SQL 2008 R2 SP1, although it does support Windows 2008 R2 SP1. Some of the VMware Management tools also don’t yet support SQL 2008 R2 SP1. You should always check the Product Interoperability Matrix when designing solutions. Not every solution is listed and there have been times where it is not up to date (such as currently there are no supported DB’s listed for Chargeback 2.0.1), but this is fairly rare. If you think something doesn’t look right on there contact VMware and they are normally able to quickly resolve the problems.
SQL 2008 R2 (no SP) is the lowest common denominator currently supported by most of the VMware product range that supports SQL. Unless you want to get into a complex situation of supporting multiple variants of Database for different VMware products I would recommend you you stick with this for now.
Now on the topic of protecting the Database of vCloud Director specifically, which is an important database if you are a public cloud provider, what HA options are available? Well if you’re using MS SQL Server as your Database then the only currently supported option is VMware HA or FT to protect the DB VM. With the FT option your DB needs to be configured with only a single vCPU, which will likely only be viable in very small environments. MSCS Failover Clustering and SQL DB Mirroring are not supported in the current 1.5.1 release of vCloud Director. If you’re running Oracle then you have the option of an active/passive configuration of RAC where the service is only active on one node at a time, or VMware HA if you choose. This situation will likely be addressed in upcoming releases.
If you need to know if a particular form of DB high availability is supported you should check the product documentation or log a Service Request with VMware Support, if you can’t find it explicitly supported. Without an explicit statement of support in the product documentation it is likely unsupported.
—
This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.