2026
vDefend Distributed Firewall: zero trust at the workload level
Least-privilege policy per vNIC, built on dynamic groups and tags rather than IP addresses — and the honest boundary where federated identity stops and the firewall starts.
VCF Identity Broker: where VCF 9.1 single sign-on actually stops
VCF Identity Broker federates login across the VCF consoles, but the documented perimeter is narrower than the pitch. We map what it covers, what stays local, and the break-glass path.
Federating VCF identity: Okta, Entra ID, and the generic path
Four identity providers are documented by name, each with its own protocol path. Everything else goes through generic SAML 2.0 — a route that works without being a support statement.
Capacity planning: ESA vs OSA, what really changes
Switching from OSA to ESA changes how you size a vSAN cluster. We compare the two models side by side: usable capacity, headroom, and the new rules.
NVMe memory tiering: 2x VM density, and what it costs
At the recommended 1:1 ratio, Broadcom reports 2x VM density with a 5–10% HammerDB performance loss; this guide defines the eligibility conditions.
RAID-5/6 on vSAN ESA: what replaces the write penalty
ESA replaces read-modify-write with a durable log and aligned full-stripe writes, while vSAN 9.1 still documents a possible RAID-1 advantage.
VCF LCM: end-to-end workflows and failure recovery
When a VCF 9.1 lifecycle batch fails, read real state before retrying. Map fleet, instance and domain recovery, prechecks and resource locks.
vSAN upgrades without downtime: ESA rolling patterns
Roll ESX upgrades through vSAN ESA one host at a time: choose an evacuation mode, control resync, and stop safely when capacity or policy blocks progress.
ESXi live patching: kernel updates without reboot
ESXi live patching lets you ship CVE fixes without evacuating hosts. We dig into how it works, what it does NOT cover, and where it changes your patch SLA.
RAG in production: from POC to scale on VCF
Most RAG POCs die between demo and production. We walk through the gap — chunking, freshness, evals, observability — on VCF and VKS.
Vector databases on VKS: pgvector, Milvus, Weaviate
RAG needs a vector store. We compare pgvector, Milvus and Weaviate on VKS — index quality, ops surface, and which one actually fits your team.
GPU pooling on VCF: NVIDIA vGPU + MIG in practice
Sharing GPUs across tenants is the only way private AI math works. We walk through vGPU profiles, MIG slicing, and the pitfalls of mixed-workload scheduling.
Private AI on VCF: the architecture that fits in your DC
VCF Private AI Foundation is the stack Broadcom proposes for hosting LLMs and inference in your own DC. We dissect it, layer by layer, seams visible.
Aria Operations meets open source: unified observability for VCF
Connect VMware Aria Operations to Prometheus via remote_write, enrich Grafana with vSphere infrastructure metrics, and build unified dashboards that correlate VCF infra with Kubernetes workloads.
Centralised logging with Loki and Fluent Bit on VCF
Build the PLG logging stack on VCF and VKS: deploy Fluent Bit as a DaemonSet, configure its pipeline stages, ship logs to Loki, and query them with LogQL.
Observability foundations for VCF: metrics, logs and traces
The three pillars of observability defined by the OpenTelemetry specification, why they matter for VCF and VKS, and how to choose the right tool for each.
Prometheus & Grafana on VKS: the production monitoring stack
Deploy kube-prometheus-stack on VKS, configure ServiceMonitors and PodMonitors, set up alerting, and integrate with Grafana dashboards — an annotated production guide.
Day-2 ops on VKS: lifecycle, upgrades, observability
From creation to upgrade through backup and observability — operating a VKS cluster on VCF 9 without surprises. CAPI, VKr, Prom/Graf/Loki, and VCF Operations.
Networking in VCF 9: from vDS to pod, the packet path explained
How a packet travels from the virtual switch to a VKS pod — vDS, NSX segments, T0/T1, NSX ALB and their trade-offs. The architect's networking guide.
The new VCF 9 architecture explained to architects
VCF 9 is not a minor upgrade: it's a complete overhaul of the operational model. What a cloud architect must understand before any adoption project.
Deploying your first VKS cluster on VCF 9: An architect's guide
VKS is not TKG renamed. Architecture, consumption paths, annotated YAML, day-2 ops, and real limitations — the architect's guide to VCF 9.