, ,

VCF 9.1 Day-2 Operations Overview and Operating Model (VCF 9.1 Day-2 Operations Step by Step Guide, Part 1)

Start here for VCF 9.1 Day-2 operations. See the operating model, the phase map of every operational task, and how to confirm your fleet is ready before you begin.

VCF 9.1 Day-2 Operations · Part 1 of 20
Foundational overview. This part introduces the series and the VCF 9.1 operating model. Day-2 operations are the tasks you run after the fleet is built, meaning upgrades, patching, certificate and password rotation, backup and restore, scale changes, and health and security work. It depends on a deployed and validated VCF 9.1 fleet with VCF Operations reachable.
Before you begin. Confirm the fleet is fully deployed and every precheck passed. If any component is still incomplete, finish the build first with the VCF 9.1 Deployment complete guide and clear the VCF 9.x pre-installation checklist, then return to this series.
TL;DR
  • Day-2 operations run through VCF Operations, which now owns fleet lifecycle, SDDC lifecycle, certificates, passwords and the software depot.
  • Every VCF 9.1 upgrade starts by upgrading VCF Operations, then SDDC Manager, then the VCF management services.
  • Routine tasks (upgrade, patch, cert rotation, password rotation, backup) apply to every fleet. Optional tasks (Live Recovery, external storage, NSX Federation) apply only when you need them.
  • Back up SDDC Manager, vCenter and NSX Manager on a schedule, and test a restore before you rely on it.
  • Prerequisites: admin access to VCF Operations and SDDC Manager, an SFTP backup target, an NTP source, and current depot access.
  • Use the phase map below to pick the task you need, or read the parts in order.

You have a running VMware Cloud Foundation 9.1 fleet. This series covers what comes next: keeping it current, recoverable, secure, and correctly sized as demand grows. Each part is a plain task you can follow end to end, with the exact screens, fields and commands. This first part gives you the map, so you can see how the tasks fit together and decide which ones your environment needs.

In VCF 9.1, most operational work is centralized in VCF Operations. Fleet lifecycle and SDDC lifecycle, certificate management, password management, and the software depot all run from one place. That changes how you think about Day-2 work compared with older releases, so this part sets the model before the task parts go deep.

VCF Operations Fleet lifecycle SDDC lifecycle Software depot vCenter NSX Manager ESXi hosts
VCF Operations sits at the center of Day-2 work and drives lifecycle, certificates, passwords and the depot across every managed component.

Prerequisites

Confirm the following before you run any task in this series.

ItemRequirement
VCF versionA deployed VCF 9.0 or 9.1 fleet with VCF Operations reachable
AccessAdministrator credentials for VCF Operations and SDDC Manager
Backup targetAn SFTP server reachable from the management network for scheduled backups
Time and name resolutionWorking NTP and forward and reverse DNS for every appliance
Depot accessOnline depot connectivity, or an offline depot for isolated sites

How the operating model works

VCF Operations is the fleet manager. It holds the inventory of every vCenter, NSX Manager and cluster, and it drives the two lifecycle engines. Fleet lifecycle handles the VCF Operations family and the management services. SDDC lifecycle handles vCenter, NSX and ESXi. When you plan an upgrade, apply a patch, rotate a certificate or change a password, you start in VCF Operations and it coordinates the change across the managed components.

Because the lifecycle engines read from a software depot, depot health matters for every patching task. An online depot pulls bundles from Broadcom. An offline depot mirrors those bundles into an isolated environment. Part 4 covers the offline depot in detail, and the upgrade and patch parts assume the depot is already reachable.

Confirm your fleet is ready

Run this quick check in VCF Operations before you begin any task, so you start from a known good state.

  1. Log in to the VCF Operations UI with an administrator account.
  2. Open the Fleet Management area.
  3. Select Lifecycle and note the current VCF version for each domain.
  4. Open Inventory and confirm every vCenter, NSX Manager and cluster shows a healthy status.
  5. Click Administration, then Certificates, and check that no certificate is close to expiry.
  6. Click Administration, then Passwords, and confirm no credential is flagged as out of policy.

What each phase covers

PhaseTasks it coversType
Lifecycle and patchingUpgrade to 9.1, async patches, offline depotRoutine
Certificates and identityCertificate rotation, password rotation, identity providersRoutine
Backup and recoverySDDC Manager and fleet backup, vCenter and NSX backup, restore, Live RecoveryRoutine and optional
Scale and capacityAdd hosts, add clusters, decommission, vSAN ESA, external storage, host replacementScenario
Health and securityFleet health monitoring, hardening, NSX FederationRoutine and optional
Plan Patch Protect Scale Monitor
Day-2 work is a loop: plan a change, patch or apply it, protect the fleet with backups, scale as demand grows, then monitor and repeat.

Verify the fleet baseline

You are ready to start the task parts when VCF Operations reports a healthy inventory, the lifecycle view shows a consistent version across the domain, no certificate or password is flagged, and at least one successful backup exists for SDDC Manager. If any of those is not true, resolve it first. The backup parts (8 through 10) and the certificate and password parts (5 and 6) are the ones to run before you attempt an upgrade.

Common errors and fixes

SymptomCause and fix
Lifecycle view shows no available versionsThe depot is unreachable or not configured. Confirm depot connectivity, or set up an offline depot as in Part 4, then refresh.
Inventory item shows a red or disconnected statusVCF Operations lost contact with the component. Check the appliance is powered on, DNS resolves, and the service account password is current.
Certificate warning on the VCF Operations UIA certificate is near or past expiry. Rotate it using the steps in Part 5 before it blocks other tasks.
No backup listed for SDDC ManagerScheduled backups are not configured. Set up an SFTP target and schedule as in Part 8 before any lifecycle change.

Common questions

Which tasks are mandatory for every fleet
Upgrades, patching, certificate rotation, password rotation, and backup apply to every environment. Treat them as routine. Live Recovery, external storage, hardening baselines and NSX Federation are optional and depend on your requirements.

Do I need to read the parts in order
No. Each task part stands on its own with its own prerequisites. The phase map above lets you jump straight to the task you need.

Where does VCF Operations fit against SDDC Manager
VCF Operations is the fleet manager and drives lifecycle, certificates and passwords. SDDC Manager still runs domain level operations such as adding hosts and clusters. Several tasks touch both, and each part names the exact console to use.

What should I run first after deployment
Configure backups, confirm certificate and password health, then set your patch cadence. That order gives you a recoverable, current fleet before you make larger changes.

References

VCF 9.1 Day-2 Operations · Part 1 of 20
Complete Guide  |  Next: Part 2 »

About The Author


Discover more from Journal of Intelligent Infrastructure

Subscribe to get the latest posts sent to your email.

Leave a Reply

Your email address will not be published. Required fields are marked *

Architect’s Toolkit

About the Author

Dr. Pranay Jha is a Cloud and AI Consultant with 18+ years of experience in hybrid cloud, virtualization, and enterprise infrastructure transformation. He specializes in VMware technologies, multi-cloud strategy, and Generative AI solutions. He holds a PhD in Computer Applications with research focused on Cloud and AI, has published multiple research papers, and has been a VMware vExpert since 2016 and a VMUG Community Leader.

Discover more from Journal of Intelligent Infrastructure

Subscribe now to keep reading and get access to the full archive.

Continue reading