, ,

How to Deploy Avi Load Balancer in VCF 9.1 (VCF 9.1 Deployment Series, Part 10)

A step by step guide to deploying the Avi Load Balancer controller cluster in VCF 9.1 from VCF Operations, with prerequisites, controller sizing, the install wizard, NSX Cloud configuration, verification, and fixes.

VCF 9.1 Deployment · Part 10 of 17

Status in a VCF 9.1 deployment: Optional. Deploy Avi Load Balancer when you need load balancing as a service, virtual services for applications, or the load balancer that vSphere Supervisor and VKS consume.

What it does: Deploys the Avi Load Balancer Controller cluster and its Service Engines, giving your workload domains L4 and L7 load balancing, WAF, and GSLB under one control plane.

Depends on: A healthy VCF instance with VCF Operations, a workload or management domain with a registered vCenter and NSX Manager, Avi binaries in the depot, a Service Engine management network, and a local Content Library in vCenter.

TL;DR

  • Avi Load Balancer is optional. Deploy it when applications, VCF Automation, or vSphere Supervisor and VKS need load balancing.
  • In VCF 9.1 you deploy and lifecycle manage Avi entirely from VCF Operations. There is no separate OVA import step.
  • Prerequisites: a registered vCenter and NSX Manager, Avi binaries 32.1.1 or higher in the depot, a Service Engine management segment, an IP method for Service Engines, and a local Content Library.
  • Controller sizes are Small (6 vCPU, 32 GB, 512 GB disk), Large (16 vCPU, 48 GB, 1.4 TB), and XLarge (16 vCPU, 64 GB, 1.75 TB). Use one node for a lab and three nodes for production.
  • You set two break glass accounts during deployment, admin and vcfops-admin, plus the controller node IPs and a cluster FQDN that resolves to the cluster VIP.
  • Key steps: download the binary, open Manage Components, select version and form factor, enter controller settings, click Finish, then configure the Avi NSX Cloud and upload the management packs.

This part shows you how to deploy Avi Load Balancer in VCF 9.1 using the guided workflow in VCF Operations. You will download the Avi binary into the depot, deploy the Controller cluster into a domain, set the break glass passwords, and then configure the Avi NSX Cloud so Service Engines can serve traffic. Avi Load Balancer is optional. If no application in your environment needs L4 or L7 load balancing, and you are not enabling vSphere Supervisor or VKS, you can skip this part and add Avi later.

One change matters before you start. In VCF 9.1, VCF Operations owns the full lifecycle of Avi Load Balancer, including deployment, upgrades, certificate and password rotation, and configuration drift detection. You do not import an OVA by hand. Confirm that VCF Operations is set up and healthy first, and that the target domain already has a registered vCenter and NSX Manager. If you have not built the workload domain yet, complete the VI workload domain build before you deploy Avi into it.

Prerequisites

Confirm every item below before you open VCF Operations, because the install wizard runs compatibility and download checks and blocks if anything is missing. VCF Operations and the VCF Installer supply several of these when they build a domain.

RequirementWhat to confirm
InfrastructureA registered vCenter and NSX Manager for the domain that will host Avi and its workloads.
VCF Operations accessAn account with the VI administrator or provider administrator role.
Avi binariesAvi Load Balancer 32.1.1 or higher available in the depot for VCF version 9.1.
Controller addressingNode IP addresses for each controller, plus a cluster FQDN registered in DNS that resolves to the cluster VIP.
Service Engine networkA dedicated VLAN or overlay segment for Service Engine management traffic, with connectivity to the controller.
Service Engine IPsA DHCP scope on the management segment, or a static IP pool defined in the controller.
Content LibraryA local Content Library in vCenter to store and manage the Service Engine images.
Ordering for SupervisorIf Avi will serve vSphere Supervisor or VCF Automation, deploy the controller cluster before you activate Supervisor in the domain.

Pick a controller form factor from the table below. A single node is fine for a lab or evaluation. Production uses a three node cluster where all nodes are identical in CPU, memory, and disk.

Form factorvCPUMemoryMinimum diskService Engine scale
Small632 GB512 GB0 to 200
Large1648 GB1.4 TB200 to 500
XLarge1664 GB1.75 TB200 to 500

A demo or evaluation controller can run on a single node with 6 vCPU, 32 GB memory, and a 128 GB disk. Controller virtual hard drives are provisioned as thick, lazy zeroed, and the controller does not support CPU or memory hot add, so size the node correctly before you deploy.

VCF Operations lifecycle deploy and manage Management domain Controller 1 Controller 2 Controller 3 Cluster VIP and FQDN NSX Cloud connector Workload domain Service Engine Service Engine app virtual services app virtual services

Step 1 confirm vCenter and NSX Manager are ready

Avi uses dedicated service accounts to talk to vCenter and NSX Manager, so both must be registered and healthy for the domain first. This groundwork comes from the NSX work in the NSX Edge cluster part and the domain build.

  1. Log in to the VCF Operations portal at https://vcf_operations_fqdn as a user with the Administrator role.
  2. Open Fleet Management and confirm the target VCF instance and its domain report a healthy state.
  3. Confirm the domain vCenter is reachable and its inventory is visible.
  4. Confirm NSX Manager for the domain is deployed and green.
  5. Confirm you can reach the DNS record you reserved for the Avi cluster FQDN.

Step 2 prepare networks, addressing and the Content Library

Service Engines need a management network and a way to get IP addresses, and vCenter needs a Content Library to hold the Service Engine image. Set these up before deployment so the NSX Cloud configuration later has everything it needs.

  1. Identify a dedicated VLAN or an overlay segment for Service Engine management traffic that can reach the controller.
  2. Decide how Service Engines get management IPs, either a DHCP scope on that segment or a static IP pool you will define in the controller.
  3. Reserve the controller node IP addresses, one per node, on the management domain network.
  4. Register the Avi cluster FQDN in DNS with forward and reverse records that resolve to the cluster VIP.
  5. In the domain vCenter, go to Content Libraries and create a local Content Library, for example avi-se-images.

Step 3 download the Avi Load Balancer binaries

Pull the Avi binary into the depot from VCF Operations so it is available to the install wizard.

  1. In VCF Operations, navigate to Build, then Lifecycle, then VCF instances.
  2. Select your VCF instance name, then click the Binary Management tab.
  3. Select 9.1 for VCF Version, then click Install Binaries.
  4. Select Avi Load Balancer 32.1.1 or higher from the component table.
  5. Click Download to fetch the binaries from the online depot.
  6. Wait for the download to report complete before you move on.

Step 4 start the Manage Components install

Open the domain where Avi will run and start the install from the Avi Load Balancer card.

  1. Navigate to Build, then Lifecycle, then VCF instances, and click the same VCF instance.
  2. Select the specific domain name where you want to deploy Avi and host your running workloads.
  3. Click the Components Versions tab.
  4. Click Manage Components.
  5. On the Avi Load Balancer card, click Install.

Step 5 select the version and form factor

Choose a compatible binary version, clear the automatic checks, then pick a controller size. A Resource Availability table shows required and available capacity for memory, CPU, and disk as you choose.

  1. On the Select version page, select the compatible version from the drop down, then click Next.
  2. Let the download check confirm the binary is available. If it is not, click Download to fetch it.
  3. Let the compatibility check confirm the version matches the deployed vCenter and NSX Manager. If it does not, upload version 32.1.1 or higher before you continue.
  4. On the Form Factor page, select a controller size of Small, Large, or XLarge based on your Service Engine scale.
  5. Read the Resource Availability table and confirm the domain has enough memory, CPU, and disk space.

Step 6 enter the controller settings and finish

On the Settings page you set the two break glass accounts and the cluster identity. Your admin account logs in to the controller, and the vcfops-admin account lets VCF Operations manage the fleet. Enter the fields shown in the table, then finish.

FieldWhat to enter
Admin PasswordPassword for the admin account used to log in to the Avi Load Balancer Controller.
VCF Ops Admin PasswordPassword for the vcfops-admin account that integrates Avi with VCF Operations for fleet management.
Node IP AddressesThe IP addresses of the nodes for the controller. Enter one for a single node, three for a cluster.
Cluster FQDNThe DNS name of the Avi cluster. It must resolve to the cluster VIP of the controller.
Cluster NameA name for the Avi Load Balancer cluster.
  1. Enter the Admin Password.
  2. Enter the VCF Ops Admin Password.
  3. Enter the Node IP Addresses, one per controller node.
  4. Enter the Cluster FQDN that resolves to the cluster VIP.
  5. Enter the Cluster Name, then click Next.
  6. On the Finish page, review the configuration, then click Finish to install the controller cluster.

Step 7 verify the controller cluster task

VCF Operations tracks the install as a task. Watch it to completion before you log in to the controller.

  1. Navigate to Build, then Lifecycle, then VCF Management.
  2. Click the Tasks tab.
  3. Find the Avi Load Balancer cluster installation task.
  4. Confirm it shows a completed status.

Step 8 set the welcome admin screen and passphrase

Your first login to the controller sets a passphrase that encrypts configuration exports and backups. Keep this passphrase safe, because a restore needs it.

  1. Open the Avi Load Balancer Controller at the cluster FQDN in a browser.
  2. Log in as admin with the password you set during deployment.
  3. Set the backup passphrase when prompted, and record it in your password store.
  4. Confirm the administrator email and any DNS or NTP values on the welcome screen.
  5. Save the welcome screen to reach the controller dashboard.

Step 9 configure the Avi NSX Cloud

The NSX Cloud connector lets the controller, vCenter, ESXi hosts, and Service Engines talk to each other. Its status stays in an error state until you finish this configuration, which is expected during setup.

  1. In the controller, navigate to Infrastructure, then Clouds.
  2. Select the name of the NSX cloud from the drop down.
  3. Select Edit from the vertical three dots menu of the NSX cloud.
  4. Configure the Management Network by providing the Transport Zone for Service Engines to reach the controller. For an overlay zone, select a Tier 1 logical router and an overlay segment. For a VLAN zone, select a VLAN backed segment.
  5. Verify that the Enable VPC checkbox is selected.
  6. Configure the Data Networks by providing a Transport Zone. It does not need to match the management zone, but it must exist in the transport node profile for the hosts that run the Service Engines.
  7. Select the local Content Library in vCenter where the Service Engine images will be deployed.
  8. In the IPAM/DNS section, add an IPAM profile if you use non VPC networking with VIP auto allocation, and add a DNS profile if you want Avi to create DNS records for virtual services.
  9. Click Save.

Step 10 upload the management packs into VCF Operations

Two management packs bring Avi into VCF Operations. One automates infrastructure tasks such as password management and certificate rotation. One aggregates Avi dashboards, metrics, and alerts into a single view. Upload both to finish the integration.

  1. In VCF Operations, open the Avi Load Balancer administration area under Build, then Lifecycle.
  2. Locate the Upload Management Packs action.
  3. Upload the Avi lifecycle management pack and confirm it activates.
  4. Upload the Avi monitoring management pack and confirm it activates.
  5. Open the Avi dashboards in VCF Operations and confirm metrics begin to populate.

Deployment flow at a glance

flowchart TD
A[Confirm vCenter and NSX Manager] --> B[Prepare SE network and Content Library]
B --> C[Download Avi binary to depot]
C --> D[Open Manage Components and Install]
D --> E[Select version and form factor]
E --> F[Enter controller settings and Finish]
F --> G[Verify cluster task completed]
G --> H[Set welcome screen and passphrase]
H --> I[Configure Avi NSX Cloud]
I --> J[Upload management packs]

Verify the deployment

Confirm the controller, the cluster, and the cloud connector from VCF Operations and the controller itself.

  1. In VCF Operations, on the Tasks tab, confirm the Avi cluster installation shows completed.
  2. Browse to the cluster FQDN and confirm the controller login page loads over the cluster VIP.
  3. In the controller, open Administration, then Controller, then confirm all nodes report Up for a three node cluster.
  4. In the controller, open Infrastructure, then Clouds, and confirm the NSX cloud status turns green after you save the configuration.
  5. In VCF Operations, open the Avi dashboards and confirm metrics and inventory appear.

Once the cloud status is green and metrics flow, the controller is ready to place Service Engines and serve virtual services. From here, applications consume load balancing through VCF Automation, and vSphere Supervisor and VKS can use Avi for their control plane and ingress.

Common errors and fixes

SymptomCause and fix
Compatibility check blocks the installThe selected Avi version does not match the vCenter and NSX Manager versions. Upload version 32.1.1 or higher, then run the check again.
Download check fails on the version pageThe binary is not in the depot. Return to Binary Management, select 9.1, and download Avi Load Balancer before you retry.
Controller deploys but the cluster VIP does not answerThe cluster FQDN does not resolve to the VIP, or reverse DNS is missing. Fix the forward and reverse records, then confirm the FQDN resolves to the VIP.
NSX cloud stays in an error state after SaveA transport zone, segment, or Content Library is missing, or the license is not applied. Recheck each field in the NSX cloud edit form and confirm a license is added to the controller.
Not enough capacity to place the controllerA controller reserves its full CPU, memory, and disk, provisioned thick lazy zeroed. Free capacity or choose a smaller form factor, then retry.

Common questions

Is Avi Load Balancer mandatory in VCF 9.1. No. It is optional. Deploy it when applications need L4 or L7 load balancing, when you use VCF Automation load balancing as a service, or when vSphere Supervisor and VKS need a load balancer.

How many controller nodes should I deploy. Use one node for a lab or evaluation, and three identical nodes for production so the cluster survives a node failure.

Do I still import an Avi OVA by hand. No. In VCF 9.1, VCF Operations deploys and lifecycle manages Avi, so you download the binary and run the guided install instead.

When must Avi be deployed relative to vSphere Supervisor. Deploy the Avi controller cluster before you activate vSphere Supervisor in a domain when Avi provides the Supervisor load balancer.

What are the admin and vcfops-admin accounts for. The admin account logs in to the controller, and the vcfops-admin account lets VCF Operations perform fleet lifecycle actions such as upgrades and rotation.

References

About The Author


Discover more from Journal of Intelligent Infrastructure

Subscribe to get the latest posts sent to your email.

Leave a Reply

Your email address will not be published. Required fields are marked *

Architect’s Toolkit

About the Author

Dr. Pranay Jha is a Cloud and AI Consultant with 18+ years of experience in hybrid cloud, virtualization, and enterprise infrastructure transformation. He specializes in VMware technologies, multi-cloud strategy, and Generative AI solutions. He holds a PhD in Computer Applications with research focused on Cloud and AI, has published multiple research papers, and has been a VMware vExpert since 2016 and a VMUG Community Leader.

Discover more from Journal of Intelligent Infrastructure

Subscribe now to keep reading and get access to the full archive.

Continue reading