
vcfa-all-apps-iaas
Build a Governed IaaS Service with VCF Automation 9.1 All Apps
A practical journey for building, integrating, governing, and testing a VM service with Blueprints, VM Service, Event Broker, and Orchestrator.
Open seriesCloud, DevOps and infrastructure topics organized as guided article paths.
Each series groups related articles into a reading path.

vcfa-all-apps-iaas
A practical journey for building, integrating, governing, and testing a VM service with Blueprints, VM Service, Event Broker, and Orchestrator.
Open series
vcfa-brownfield-migration
A nine-part brownfield series covering post-upgrade stabilization, All Apps construction, wave-based migration, App Stack Formation, and legacy retirement.
Open series
finops-cloud-native
Cost visibility, rightsizing and multi-cloud cost models for Kubernetes and VCF platforms.
Open series
k8s-security-prod
The production security baseline for Kubernetes: RBAC, network policies, supply chain controls and runtime detection.
Open series
vcf-identity-zero-trust
Identity federation, SSO and workload firewalling patterns for a zero-trust VCF platform.
Open series
vsan-esa-memory-tiering
What ESA changes for performance, density and capacity planning in modern VCF environments.
Open series
live-patching-lcm
Operational patterns for ESXi live patching, non-disruptive vSAN upgrades and VCF lifecycle workflows.
Open series
private-ai-vcf
A practical path for running private AI on VCF, from architecture to GPU pooling, vector databases and production RAG.
Open series
vcf-9-1
A four-part series decoding VMware Cloud Foundation 9.1: infrastructure efficiency, networking, Kubernetes self-service, security and resilience.
Open series
observability-vcf-k8s
Metrics, logs and traces for VCF and VKS: Prometheus, Grafana, Loki, OpenTelemetry and Aria Operations to instrument your platform end-to-end.
Open series
vks
Architecture, networking, first cluster, day-2 operations and GitOps for VMware Kubernetes Service on VCF 9.
Open seriesThe full back catalogue, newest first — including standalone pieces that belong to no series.
An EKS cluster-hour, an AKS tier, a GKE Pod request and depreciated VCF hardware are not four values of one variable. What each platform bills, and what VCF calculates instead.
The NetworkPolicy API ships with Kubernetes; enforcing it is the CNI's job. What Cilium adds, what stays standard, and how to reach default-deny by watching real flows before blocking any.
Every one of these pitfalls is published on kubernetes.io. What is missing is the ordering — and the path that leads from a vSphere Namespace straight to cluster-admin.
Falco and Tetragon both collect through eBPF. What separates them lies elsewhere: event scope, rule model, and above all what each one can actually prevent.
Kubernetes verifies no image signature on its own. Signing with Sigstore, inventorying with an SBOM, refusing at admission — and what each of those verbs actually covers.
Least-privilege policy per vNIC, built on dynamic groups and tags rather than IP addresses — and the honest boundary where federated identity stops and the firewall starts.