- VCF Operations is mandatory in every VCF 9.x deployment. Bring up deploys the analytics node, the fleet management appliance, and the Unified Cloud Proxy collector, so this part configures what bring up leaves for you.
- Prerequisites: VCF Operations 9.1 online, SDDC Manager 9.1, the license server reachable, forward and reverse DNS, NTP, and an admin password of 15 characters or more.
- Sizing: use Small only for a lab or proof of concept, and Medium or larger for production analytics nodes. A witness node for continuous availability needs 2 vCPU and 8 GB.
- Key steps: confirm the passwords, sign in, apply the fleet license, register the Unified Cloud Proxy, add the management vCenter as a cloud account, and confirm the adapter is collecting.
- Optional scale out: add a data node and activate high availability, then add a witness node for a continuous availability cluster across two zones.
- Entry points: Manage then Licensing for the fleet license, Operate then Administration then Integrations for cloud accounts, and Build then Lifecycle then VCF Management for node scale out.
This part shows you how to set up VCF Operations in a VMware Cloud Foundation 9.1 fleet after the management domain is built. In VCF 9.1 the VCF Installer deploys the VCF Operations appliances for you as part of management domain bring up, so you do not run a separate OVA import for the primary analytics node. What remains is configuration. You set the passwords, apply the license held by the fleet license server, connect the Unified Cloud Proxy collector, and register the management vCenter so the platform starts collecting metrics. If you want background on what this product does before you configure it, read what VCF Operations is in VCF 9.
Before you begin, confirm that VCF Operations 9.1 is powered on and reachable by FQDN, that SDDC Manager 9.1 and the license server are online, and that both forward and reverse DNS records resolve for every appliance. Have the admin password ready at 15 characters or more, and decide now whether this fleet runs a single analytics node or a high availability cluster, because adding nodes later restarts the cluster. You configured the license authority in the previous part, VCF Management Services and the license server, and VCF Operations draws its entitlement from there.
Prerequisites
Confirm each item below before you sign in. VCF Operations validates DNS, reachability, and credentials as you connect data sources, so a missing reverse record or an unreachable proxy stops collection rather than the sign in itself.
| Requirement | Value | Notes |
|---|---|---|
| VCF Operations | 9.1, online | Deployed by bring up in the management domain cluster. |
| SDDC Manager | 9.1, online | Required for lifecycle and component actions. |
| License server | Reachable by FQDN | Single license authority for the fleet. |
| Unified Cloud Proxy | Deployed, resolves in DNS | Collector that reaches vCenter, NSX, and SDDC Manager. |
| Forward and reverse DNS | A and PTR records | Every appliance IP resolves back to its FQDN. |
| NTP | Synced source | Clock skew breaks certificate and metric timing. |
| Admin password | 15 characters or more | Shorter values are rejected by the platform. |
| Browser access | Port 443 | Chrome, Edge, or Firefox to the VCF Operations FQDN. |
Pick a node size before you scale out. Small builds are for a lab or proof of concept, and production analytics nodes start at Medium. Log nodes and witness nodes have their own floors, shown below.
| Node role | Size | When to use |
|---|---|---|
| Analytics node | Small | Lab or proof of concept only, not production. |
| Analytics node | Medium or larger | Production baseline, scale by adding data nodes. |
| Witness node | 2 vCPU, 8 GB | Continuous availability across two fault domains. |
| Log node | Medium or larger | Each large log node ingests up to 15000 events per second. |
Step 1, confirm the VCF Operations credentials
Management domain bring up either sets the VCF Operations passwords from values you typed into the VCF Installer or auto generates them. Confirm you hold both the console root password and the UI admin password before you sign in.
- Open the VCF Installer UI that you used for management domain bring up.
- Go to the deployment summary and open credentials panel for the fleet.
- Copy the admin password for VCF Operations and store it in your password vault.
- If you deployed a node manually instead, open the vSphere Client, right click the VCF Operations virtual machine, and select Launch Web Console.
- Sign in to the console as root, then set a root password of 15 characters or more when prompted, because SSH is disabled by default on a new appliance.
- Confirm the admin password meets the 15 character minimum, since VCF Operations rejects anything shorter.
Console root and UI admin are two separate accounts with two separate passwords. Record both, because the console root account is your only recovery path if the UI admin password is lost.
Step 2, sign in to the VCF Operations UI
You drive licensing, cloud accounts, and adapters from the VCF Operations user interface.
- Browse to https://your-vcf-operations-fqdn in Chrome, Edge, or Firefox.
- Select Local Users on the sign in page.
- Enter admin as the user name and the admin password you confirmed in Step 1.
- Click Login.
- Accept the end user license agreement if it appears on first sign in.
- Confirm the home page loads and the top navigation shows the Build, Manage, Operate, and Protect pillars.
Step 3, apply the fleet license
VCF Operations must carry a valid VCF 9.1 license, and in a fleet the license server is the single authority that holds it.
- In the VCF Operations UI, open Manage, then Licensing, then Licenses and Registration.
- Confirm this instance is registered with the VCF Business Services console, because that registration is what syncs your entitlement to the fleet.
- Click Add License to open the Add Licenses to a VCF Operations Instance wizard.
- Select the licenses you want to add from the list the license server supplies.
- Click Save and Next and finish the wizard.
- Confirm the Licenses and Registration page lists the applied license with a future expiry date and the correct capacity.
In VCF 9.1 the license model is unified. You add one VCF license to both the license server and the VCF Operations instance that you registered with the VCF Business Services console at vcf.broadcom.com, and VCF Operations then acts as the license manager for the whole stack. A newly assigned vCenter license can take up to 15 minutes to appear on the License tab.
Step 4, register the Unified Cloud Proxy
The Unified Cloud Proxy is the collector that reaches vCenter, NSX, and SDDC Manager on behalf of VCF Operations. Register it before you add any cloud account.
- Confirm the Unified Cloud Proxy appliance deployed during bring up is powered on and resolves in DNS by short and long FQDN.
- Confirm the proxy can reach the VCF Operations nodes and the target vCenter over port 443.
- To add another proxy for high availability or load balancing, open Build, then Lifecycle, then VCF Management, and select VCF Operations.
- Under Actions, select Add cloud proxy, then enter the FQDN, size, VCF Operations admin password, and a new proxy password, and pick the VCF Instance.
- Click Add and wait for the cloud proxy to appear as an available collector.
- Note the collector or group name, because you select it as the Cloud Proxy / Group when you add the vCenter account.
Size the proxy to the fleet. A Unified Small cloud proxy covers up to 16000 VMs on 4 vCPU and 16 GB, and a Unified Standard covers 16000 to 80000 VMs on 8 vCPU and 48 GB. In VCF 9.1 every cloud proxy runs in FIPS mode, and two or more proxies form a group for high availability.
Step 5, add the management vCenter account
Adding the management vCenter as a cloud account is what starts metric collection for the management domain. Validation runs from the cloud proxy, not from your browser, so the FQDN you enter must resolve and route from the proxy.
- In the VCF Operations UI, open Operate, then Administration, then Integrations.
- On the Accounts tab, click Add.
- On the Accounts Type page, click vCenter.
- Enter a display name such as mgmt-vcenter and a short description.
- Select the Physical Data Center you want to associate with this account, or add a new one.
- In the vCenter field, enter the FQDN of the management vCenter, for example vcenter-mgmt.example.com.
- Under Credential, click the Add icon and enter a service account and its password.
- From the Cloud Proxy / Group drop-down, select the Unified Cloud Proxy that collects for this vCenter.
- Click Validate Connection, then review the certificate in the Review and Accept Certificate dialog and click OK.
- Click Add to save the account.
- On the Accounts tab, find the account, click the vertical ellipsis, and click Start Collecting, because a new account does not collect automatically.
| Field | Example value | Notes |
|---|---|---|
| Name | mgmt-vcenter | Free text label shown in the account list. |
| vCenter | vcenter-mgmt.example.com | Must resolve and route from the cloud proxy. |
| Cloud Proxy / Group | Unified Cloud Proxy | The proxy registered in Step 4. |
| Credential | svc-vcfops account | A service account with read access to the vCenter. |
| Certificate | Accepted thumbprint | Compare against the vCenter certificate before you accept. |
New vCenter accounts do not start collecting on their own. After you save the account, open the vertical ellipsis on the Accounts tab and click Start Collecting. A standard collection cycle then runs every 5 minutes, so the first objects and metrics can take a cycle or two to appear.
Step 6, verify adapters are collecting
Collection can take several minutes to populate. Confirm objects and metrics appear before you move on. For adapter and cloud proxy detail beyond this step, see deploying and connecting VCF Operations.
- Open the Operate pillar, then Environment, and browse the vSphere hosts and clusters.
- Confirm the management vCenter, its cluster, and each ESX host appear as objects.
- Open a host object and check the Metrics tab shows recent data points with current timestamps.
- Open Operate, then Administration, then Integrations, and confirm the vCenter account on the Accounts tab shows a green Collecting status with zero collection errors.
- Open Operate, then Administration, then Inventory, and confirm the object count matches the hosts and virtual machines in the management domain.
Step 7, scale out to a high availability cluster
A single analytics node is fine for a lab, but production fleets add data nodes for high availability. This step is optional for a proof of concept and recommended for production. Adding nodes restarts the cluster, so schedule a maintenance window first.
- Update the VCF Operations certificate first so it includes the FQDN of every node you plan to add, or the scale out fails.
- In the VCF Operations UI, open Build, then Lifecycle, then VCF Management, and select VCF Operations.
- Under Actions, select the Node Management action, then choose to add a replica or a data node.
- Enter the fully qualified domain name for the new node.
- Enter the VCF Operations admin password, then set a node password of 15 characters or more.
- Click Add and wait for the node to deploy and reach a Running state.
- Add a replica node to give the primary a standby, which is what activates high availability for the cluster.
- Confirm the cluster restart when prompted, since bringing a replica online restarts the analytics cluster.
- For a continuous availability design across two fault domains, add a witness node sized at 2 vCPU and 8 GB in a third location.
Step 8, connect VCF Operations for Logs
VCF Operations for Logs collects syslog and appliance logs for the fleet and belongs to the same platform. Connect it so the management domain sends its logs to one place.
- Confirm the Log management appliance for VCF is installed, since it must be present before VCF Operations can collect and analyze logs.
- Open Operate, then Administration, then Integrations, and edit the management vCenter account.
- Turn on Activate Log Collection for the account so its appliance logs flow to the central log cluster.
- Point any remaining management domain appliances at the log cluster over syslog on port 514, or the secure port 1514.
- Size log nodes at Medium or larger, since each large node ingests up to 15000 events per second.
- Open the Operate pillar and confirm log events appear in the log search view with current timestamps.
With the license applied, the cloud proxy collecting, the management vCenter added, and logs flowing, VCF Operations is set up for the management domain. Every workload domain you build later is added the same way, as a vCenter account on the same cloud proxy or a new one, so the pattern in this part repeats across the fleet. Before you move on, confirm the account reads Collecting with no errors, the inventory count matches the domain, and the fleet license reads as valid. From here you can shape dashboards, alerts, and policies for the fleet, which the later parts of this series build on.


DrJha