- Day-2 operations run through VCF Operations, which now owns fleet lifecycle, SDDC lifecycle, certificates, passwords and the software depot.
- Every VCF 9.1 upgrade starts by upgrading VCF Operations, then SDDC Manager, then the VCF management services.
- Routine tasks (upgrade, patch, cert rotation, password rotation, backup) apply to every fleet. Optional tasks (Live Recovery, external storage, NSX Federation) apply only when you need them.
- Back up SDDC Manager, vCenter and NSX Manager on a schedule, and test a restore before you rely on it.
- Prerequisites: admin access to VCF Operations and SDDC Manager, an SFTP backup target, an NTP source, and current depot access.
- Use the phase map below to pick the task you need, or read the parts in order.
You have a running VMware Cloud Foundation 9.1 fleet. This series covers what comes next: keeping it current, recoverable, secure, and correctly sized as demand grows. Each part is a plain task you can follow end to end, with the exact screens, fields and commands. This first part gives you the map, so you can see how the tasks fit together and decide which ones your environment needs.
In VCF 9.1, most operational work is centralized in VCF Operations. Fleet lifecycle and SDDC lifecycle, certificate management, password management, and the software depot all run from one place. That changes how you think about Day-2 work compared with older releases, so this part sets the model before the task parts go deep.
Prerequisites
Confirm the following before you run any task in this series.
| Item | Requirement |
|---|---|
| VCF version | A deployed VCF 9.0 or 9.1 fleet with VCF Operations reachable |
| Access | Administrator credentials for VCF Operations and SDDC Manager |
| Backup target | An SFTP server reachable from the management network for scheduled backups |
| Time and name resolution | Working NTP and forward and reverse DNS for every appliance |
| Depot access | Online depot connectivity, or an offline depot for isolated sites |
How the operating model works
VCF Operations is the fleet manager. It holds the inventory of every vCenter, NSX Manager and cluster, and it drives the two lifecycle engines. Fleet lifecycle handles the VCF Operations family and the management services. SDDC lifecycle handles vCenter, NSX and ESXi. When you plan an upgrade, apply a patch, rotate a certificate or change a password, you start in VCF Operations and it coordinates the change across the managed components.
Because the lifecycle engines read from a software depot, depot health matters for every patching task. An online depot pulls bundles from Broadcom. An offline depot mirrors those bundles into an isolated environment. Part 4 covers the offline depot in detail, and the upgrade and patch parts assume the depot is already reachable.
Confirm your fleet is ready
Run this quick check in VCF Operations before you begin any task, so you start from a known good state.
- Log in to the VCF Operations UI with an administrator account.
- Open the Fleet Management area.
- Select Lifecycle and note the current VCF version for each domain.
- Open Inventory and confirm every vCenter, NSX Manager and cluster shows a healthy status.
- Click Administration, then Certificates, and check that no certificate is close to expiry.
- Click Administration, then Passwords, and confirm no credential is flagged as out of policy.
What each phase covers
| Phase | Tasks it covers | Type |
|---|---|---|
| Lifecycle and patching | Upgrade to 9.1, async patches, offline depot | Routine |
| Certificates and identity | Certificate rotation, password rotation, identity providers | Routine |
| Backup and recovery | SDDC Manager and fleet backup, vCenter and NSX backup, restore, Live Recovery | Routine and optional |
| Scale and capacity | Add hosts, add clusters, decommission, vSAN ESA, external storage, host replacement | Scenario |
| Health and security | Fleet health monitoring, hardening, NSX Federation | Routine and optional |
Verify the fleet baseline
You are ready to start the task parts when VCF Operations reports a healthy inventory, the lifecycle view shows a consistent version across the domain, no certificate or password is flagged, and at least one successful backup exists for SDDC Manager. If any of those is not true, resolve it first. The backup parts (8 through 10) and the certificate and password parts (5 and 6) are the ones to run before you attempt an upgrade.
Common errors and fixes
| Symptom | Cause and fix |
|---|---|
| Lifecycle view shows no available versions | The depot is unreachable or not configured. Confirm depot connectivity, or set up an offline depot as in Part 4, then refresh. |
| Inventory item shows a red or disconnected status | VCF Operations lost contact with the component. Check the appliance is powered on, DNS resolves, and the service account password is current. |
| Certificate warning on the VCF Operations UI | A certificate is near or past expiry. Rotate it using the steps in Part 5 before it blocks other tasks. |
| No backup listed for SDDC Manager | Scheduled backups are not configured. Set up an SFTP target and schedule as in Part 8 before any lifecycle change. |
Common questions
Which tasks are mandatory for every fleet
Upgrades, patching, certificate rotation, password rotation, and backup apply to every environment. Treat them as routine. Live Recovery, external storage, hardening baselines and NSX Federation are optional and depend on your requirements.
Do I need to read the parts in order
No. Each task part stands on its own with its own prerequisites. The phase map above lets you jump straight to the task you need.
Where does VCF Operations fit against SDDC Manager
VCF Operations is the fleet manager and drives lifecycle, certificates and passwords. SDDC Manager still runs domain level operations such as adding hosts and clusters. Several tasks touch both, and each part names the exact console to use.
What should I run first after deployment
Configure backups, confirm certificate and password health, then set your patch cadence. That order gives you a recoverable, current fleet before you make larger changes.
References
How to Upgrade to VMware Cloud Foundation 9.1, VCF Blog
Scale, Simplify and Secure Your Private Cloud Operations with VCF 9.1, VCF Blog
Password rotation in VCF 9, Broadcom support

