VCF 9.1 Home Lab Series – Part 6: Configure Network Connectivity

Welcome to part 6 of the VCF-9.1 home lab series. The previous post in this series discussed the bringup process of the management domain. In this post, I will demonstrate setting up network connectivity in the management domain.

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: What’s New in VCF 9.1

2: VCF 9.1 High-Level Design

3: VCF 9.1 Pre-Deployment Planning

4: Setting up VCF 9.1 Offline Depot

5: VCF 9.1 Deploy Management Domain

Why Deploy an Edge Cluster in the Management Domain Even If You Run Nothing There?

The Management Domain Edge Cluster in VCF 9.1 is the network spine of the entire software-defined fabric — it carries transit, external, and inter-VPC traffic even though no workload VMs run on it. Think of it less as a compute resource and more as a dedicated routing/NAT appliance for the whole VCF environment.… Read the rest

VCF 9.1 Home Lab Series – Part 5: Management Domain Bringup

Welcome to part 5 of the VCF-9.1 home lab series. The previous post in this series discussed setting up an offline depot. In this post, I will demonstrate deploying the VCF 9.1 management domain.

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: Whats New in VCF 9.1

2: VCF 9.1 High-Level Design

3: VCF 9.1 Pre-Deployment Planning

4: Setting up VCF 9.1 Offline Depot

After you configure the depot settings and download the installation binaries to the VCF installer appliance, you start the deployment by clicking the deployment wizard button and selecting the option VCF.

On the introduction page, the very first page is About the deployment wizard, and it provides a high-level overview of the VCF fleet and VCF instances.

The next screen presents the different deployment paths supported in VCF 9.1. If this is a greenfield deployment, you must select the first option to deploy to a new VCF fleet.… Read the rest

VCF 9.1 Home Lab Series – Part 4: VCF Offline Depot

Welcome to part 4 of the VCF-9.1 home lab series. The previous post in this series discussed the pre-deployment planning and checklist. In this post, I will demonstrate setting up an offline depot for deploying a VCF 9.1 fleet.

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: Whats New in VCF 9.1

2: VCF 9.1 High-Level Design

3: VCF 9.1 Pre-Deployment Planning

The very first step after deploying the VCF installer is to connect it to a depot from where it can pull the installation binaries. The VCF Installer depot supports the following connection modes.

Connection Mode Description
Online Depot Internet connection is available (either directly or through a proxy server) for binary downloads.
Offline Depot Dark site/Air gapped environment, and internet connectivity is not available.
Manual Transfer The VCF Installer appliance cannot connect to an online or offline depot.
Read the rest

VCF 9.1 Home Lab Series – Part 3: Pre-Deployment Planning

Welcome to part 3 of the VCF-9.1 home lab series. The previous post in this series discussed the VCF 9.1 high-level design and lab best practices. In this post, I will discuss the planning and preparation for deploying a VCF 9.1 fleet.

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: Whats New in VCF 9.1

2: VCF 9.1 High-Level Design

After you have understood the VCF deployment models and the design is ready in your mind, the next step is to get familiar with the VCF Planning and Preparation Workbook. If you have been working on the VCF platform for quite some time, you already understand the importance of this workbook. The workbook is an Excel file that helps you gather the inputs required for deploying a VCF fleet. The v9.1 workbook can be downloaded from here

The VCF Installer is a ruthless validator.… Read the rest

VCF 9.1 Home Lab Series – Part 2: High-Level Design

Welcome to part 2 of the VCF-9.1 home lab series. The previous post in this series discussed the platform capabilities. In this post, I will talk about the VCF 9.1 architecture.

Understanding the architectural building blocks before you provision anything is the difference between a learning environment and a misconfigured platform you’ll rebuild three times.

The Fleet Model

VCF 9.x introduces the concept of a Fleet as the top-level organizational construct. A Fleet is managed by a common instance of VCF Operations and VCF Automation. Within a fleet, you can have one or more VCF instances, each containing one management domain and zero or more workload domains.

For a home lab, your fleet is a single-region, single-instance deployment. But architecting it with fleet semantics in mind—proper naming conventions, network segmentation, and IP allocation strategies—prepares you for realistic multi-instance designs. To learn more about the deployment topologies in VCF 9, see my previous blog here.… Read the rest

VCF 9.1 Home Lab Series – Part 1: Introduction

VCF 9.1 was released last week and created quite a buzz in the VMware community worldwide. If VCF 9.0 was the architectural reset, 9.1 is the optimization layer — the release where the new constructs introduced in 9.0 get hardened, scaled, and made operationally practical.

Over the coming posts, we’ll build a full VCF 9.1 environment from scratch in a home lab, making deliberate architectural choices at every step and explaining why—not just how. I’ll cover the management domain build, workload domain deployment, NSX design decisions, vSAN ESA configuration, VKS (vSphere Kubernetes Service), VCFA automation, and lifecycle management.

Let’s start with the foundation: what changed in 9.1, what the high-level design looks like, and the practices that distinguish production-grade thinking from home lab shortcuts.

VCF Management Services: A Unified Control Plane Runtime

The headline architectural change in 9.1 is the introduction of VCF Management Services—a common runtime that unifies the platform’s lifecycle and operational capabilities.… Read the rest

Lessons from the Field: Recovering from Orphaned Avi Controllers in VCF-9

In a VCF environment, lifecycle operations are expected to be performed through SDDC Manager/VCF Operations. However, in real-world scenarios, operational mistakes occur—especially when components are modified directly in vCenter Server rather than through the VCF control plane.

In this blog, I will walk through a failure scenario involving NSX Advanced Load Balancer (Avi) in a VCF 9 environment, where Avi controller VMs were accidentally deleted from vCenter, leaving behind stale inventory references in SDDC Manager. I will cover the issue, impact, recovery approach, and key lessons.

The Problem Scenario

In a VCF-9 environment, Avi was deployed via SDDC Manager (integrated with NSX) and was running fine. During a troubleshooting session, Avi controller nodes were deleted directly from vCenter, leaving stale entries in the SDDC Manager UI and thus preventing the redeployment of Avi.

Result: SDDC Manager still believed Avi was deployed, and NSX integration references remained. The deletion option was grayed out in the SDDC manager UI.… Read the rest

How to Deploy Avi 30.x/31.x in VCF 9.x

By default, VCF 9 deploys the v22.x of Avi, which is too old. To use newer versions of Avi in the VCF 9.x setup, Broadcom provides a shell script. This script uploads the newer Avi OVA and updates the SDDC Manager manifest file so that the new Avi can be selected in the SDDC Manager UI.

The shell script and helper files can be downloaded from the Avi GitHub repo

This shell script performs the following tasks:

  • Uploading the Avi bundle to the SDDC manager.
  • Uploading the SDDC manager root certificate to the NSX manager as a trusted CA.
  • Registering the Avi enforcement point in NSX Manager.

Analyze the Shell Script

The shell script (vcf_tools.sh) contains 2 helper files:

1: pvc.json: This file contains the information of the Avi install bundle name and the build number. If the build number of the Avi installer bundle that you downloaded from Broadcom’s portal is not in the JSON file, update it.… Read the rest

VCF-9 – Part 10: Deploy VKS with NSX VPCs

Welcome to part 9 of the VCF-9 series. The previous post in this series discussed VPC networking in greater detail. In this post, I will demonstrate how to deploy vSphere Kubernetes Service (VKS) in an NSX VPC.

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: VCF-9 Architecture & Deployment Models

2: VCF Installer Walk-through

3: VCF-9 Networking Models

4: NSX Edge Cluster Deployment

5: ESXi Host Commission in VCF

6: Deploying a Workload Domain

7: Deploy VCF Operations for Logs

8: VPC Creation with Centralized Networking

9: VPC Networking Deep Dive

VKS, when integrated with NSX VPCs, enables self-service, secure, and automated network and security consumption for Kubernetes clusters within an NSX Virtual Private Cloud (VPC). This approach provides users with a simplified, self-service model to manage network segments, security policies, and external connectivity for their applications, all within predefined infrastructure guardrails set by the administrator.Read the rest

VCF-9 – Part 9: VPC Networking Deep Dive

Welcome to part 9 of the VCF-9 series. The previous post in this series discussed how to create Virtual Private Clouds (VPCs) with centralized network connectivity. In this post, I will dive deep into the fundamentals of VPC networking. 

If you are not following along, I encourage you to read the earlier parts of this series from the links below:

1: VCF-9 Architecture & Deployment Models

2: VCF Installer Walk-through

3: VCF-9 Networking Models

4: NSX Edge Cluster Deployment

5: ESXi Host Commission in VCF

6: Deploying a Workload Domain

7: Deploy VCF Operations for Logs

8: VPC Creation with Centralized Networking

Part 3 of this series discussed the networking models in VCF-9. In the previous post, I covered the concepts of default transit gateway and VPC gateway, as well as the types of subnets that can be created in a VPC. It is essential to recall these concepts to comprehend VPC networking. Read the rest