<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CormacHogan.com</title>
	<atom:link href="https://cormachogan.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cormachogan.com/</link>
	<description>Storage, Data, Virtualization, Container Orchestration</description>
	<lastBuildDate>Wed, 23 Sep 2026 07:06:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/cormachogan.com/wp-content/uploads/2013/01/CH-Logo-tiny.jpg?fit=32%2C30&#038;ssl=1</url>
	<title>CormacHogan.com</title>
	<link>https://cormachogan.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">39287099</site>	<item>
		<title>How to enable SSH on DSM Appliance when deployed via VCFA 9.1.1</title>
		<link>https://cormachogan.com/2026/09/21/how-to-enable-ssh-on-dsm-appliance-when-deployed-via-vcfa-9-1-1/</link>
					<comments>https://cormachogan.com/2026/09/21/how-to-enable-ssh-on-dsm-appliance-when-deployed-via-vcfa-9-1-1/?noamp=mobile#respond</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 13:00:05 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[Data Services Manager. DSM]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33214</guid>

					<description><![CDATA[<p>In my initial post introducing VMware Data Services Manager (DSM) 9.1.1 features, I mentioned that DSM can now be deployed directly from VCF Automation. As part of a concerted effort to make Data Services (and the VCF platform) highly secure, SSH access is not automatically enabled on the DSM 9.1.1 appliance. In this post, I will show you how to enable it should you need SSH access to the DSM appliance. The first step is to gain SSH Access to the vCenter server. The steps are outlined in this Knowledge Base article on troubleshooting. Once you&#8217;ve managed to get a&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/21/how-to-enable-ssh-on-dsm-appliance-when-deployed-via-vcfa-9-1-1/">How to enable SSH on DSM Appliance when deployed via VCFA 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" decoding="async" class="alignleft wp-image-30383" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="(max-width: 151px) 100vw, 151px" /></a>In my initial post <a href="https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/" target="_blank" rel="noopener">introducing VMware Data Services Manager (DSM) 9.1.1 features</a>, I mentioned that DSM can now be deployed directly from VCF Automation. As part of a concerted effort to make Data Services (and the VCF platform) highly secure, SSH access is not automatically enabled on the DSM 9.1.1 appliance. In this post, I will show you how to enable it should you need SSH access to the DSM appliance.</p>
<p style="text-align: justify;">The first step is to gain SSH Access to the vCenter server. The steps are outlined in this <a href="https://knowledge.broadcom.com/external/article/323407/troubleshooting-vsphere-with-tanzu-tkgs.html" target="_blank" rel="noopener">Knowledge Base article on troubleshooting</a>. Once you&#8217;ve managed to get a shell open on your vCenter server, the following commands can be used to retrieve the root password to gain access to the Supervisor.</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Command&gt; <strong>shell</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Shell access is granted to root</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@sfo-w01-vc01 [ ~ ]# <strong>cd /usr/lib/vmware-wcp/</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@sfo-w01-vc01 [ /usr/lib/vmware-wcp ]# <strong>./decryptK8Pwd.py</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Read key from file</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Connected to PSQL</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Cluster: domain-c9:09ddf26c-f7e2-4333-b023-aa4a36024b79</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">IP: <em>192.168.1.200</em></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PWD: <em>AbCdEfGhIj</em></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">------------------------------------------------------------</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@sfo-w01-vc01 [ /usr/lib/vmware-wcp ]# <strong>sshpass -p '<em>AbCdEfGhIj</em>' ssh -o \
stricthostkeychecking=no root@192.168.1.200</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Last login: Fri Sep 18 10:45:31 2026 from 192.168.1.130</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">===============================================================================</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">EXERCISE EXTREME CAUTION when accessing a vSphere Supervisor control plane VM.</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">When running commands on a Supervisor control plane VM, you are acting with</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">elevated permissions that BYPASS PROTECTIONS. You may cause DATA LOSS, disrupt</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">running workloads, or PERMANENTLY DAMAGE the Supervisor, Supervisor Services</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">including the vSphere Kubernetes Service (VKS), or VKS Clusters.</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Graceful recovery from changes made with these elevated permissions may not</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">be possible; it may be necessary to REDEPLOY THE ENTIRE SUPERVISOR, recreate</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">all VKS clusters, and redeploy all workloads.</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">===============================================================================</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">08:09:45 up 12 days, 22:03,<span class="Apple-converted-space">  </span>0 users,<span class="Apple-converted-space">  </span>load average: 7.72, 6.12, 5.87</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">tdnf update info not available yet!</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]#</span></pre>
<p style="text-align: justify;">Once successfully logged onto the Supervisor, query the Data Service Manager deployment. In VCFA 9.1.1, the DSM is deploying using the VM Service feature. The follow commands can be used to check the name of the appliance and the opened ports on it. Note that on the Control Plane VM (Supervisor), the <em>kubectl</em> command is aliased to a simple &#8216;k&#8217;.</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get vm -A | grep dsm</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">svc-dsm-provider-operator-r77bq <span class="Apple-converted-space">  </span>dsm-appliance <span class="Apple-converted-space">                    </span>PoweredOn <span class="Apple-converted-space">    </span>10d</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get vmservice -n svc-dsm-provider-operator-r77bq</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">NAME<span class="Apple-converted-space">                          </span>TYPE <span class="Apple-converted-space">          </span>AGE</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-internal<span class="Apple-converted-space">        </span>ClusterIP<span class="Apple-converted-space">      </span>10d</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-lb<span class="Apple-converted-space">              </span>LoadBalancer <span class="Apple-converted-space">  </span>10d</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get vmservice -n svc-dsm-provider-operator-r77bq \
dsm-appliance-lb -o yaml</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">apiVersion: vmoperator.vmware.com/v1alpha5</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">kind: VirtualMachineService</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">metadata:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>creationTimestamp: "2026-09-10T13:25:35Z"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>finalizers:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- vmoperator.vmware.com/virtualmachineservice</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>generation: 1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>name: dsm-appliance-lb</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>namespace: svc-dsm-provider-operator-r77bq</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>ownerReferences:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- apiVersion: provider.dataservices.vmware.com/v1alpha1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>blockOwnerDeletion: true</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>controller: true</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>kind: DSMAppliance</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>name: dsm-appliance</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>uid: 14347c54-628d-4a35-ad8d-802d02ea23bc</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>resourceVersion: "2065849"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>uid: a25607df-b720-4e58-bb86-cee6525ea006</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">spec:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>ports:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- name: <strong>https</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>port: <strong>443</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>protocol: <strong>TCP</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>targetPort: <strong>443</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>selector:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>dsm.vmware.com/appliance-name: dsm-appliance</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>type: LoadBalancer</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">status:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>loadBalancer:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>ingress:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>- ip: <strong>192.168.41.72</strong></span></pre>
<p style="text-align: justify;">By default, the DSM appliance is only servicing the https port, 443. This allows administrator to connect to the DSM UI via a browser using the loadBalancer IP address, but no other ports are accessible via that address. To allow SSH access (port 22), create a new YAML manifest similar to the above for an additional VM Service on the DSM Appliance. A sample manifest will look something similar to the following:</p>
<pre class="p2"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">apiVersion: vmoperator.vmware.com/v1alpha5</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">kind: VirtualMachineService</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">metadata:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>name: dsm-appliance-lb-additional</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>namespace: svc-dsm-provider-operator-r77bq</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">spec:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>ports:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- name: ssh</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>port: 22</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>protocol: TCP</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>targetPort: 22</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>selector:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>dsm.vmware.com/appliance-name: dsm-appliance</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>type: LoadBalancer</span></pre>
<p style="text-align: justify;">Apply the manifest. This creates a new VM Service. Note that the SSH port 22 is opened on a different IP address compared to the IP address associated with the https port above. However both redirect to the same DSM appliance:</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]#<strong> k apply -f dsm-ssh.yaml</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">virtualmachineservice.vmoperator.vmware.com/dsm-appliance-lb-additional created</span>


<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get vmservice -n svc-dsm-provider-operator-r77bq</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">NAME                          TYPE            AGE</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-internal        ClusterIP       10d</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-lb              LoadBalancer    10d</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-lb-additional   LoadBalancer    14s</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">

root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get vmservice -n svc-dsm-provider-operator-r77bq dsm-appliance-lb-additional -o yaml</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">apiVersion: vmoperator.vmware.com/v1alpha5</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">kind: VirtualMachineService</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">metadata:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>annotations:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>kubectl.kubernetes.io/last-applied-configuration: |</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">      </span>{"apiVersion":"vmoperator.vmware.com/v1alpha5","kind":"VirtualMachineService","metadata":{"annotations":{},"name":"dsm-appliance-lb-additional","namespace":"svc-dsm-provider-operator-r77bq"},"spec":{"ports":[{"name":"ssh","port":22,"protocol":"TCP","targetPort":22}],"selector":{"dsm.vmware.com/appliance-name":"dsm-appliance"},"type":"LoadBalancer"}}</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>creationTimestamp: "2026-09-21T08:27:34Z"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>finalizers:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- vmoperator.vmware.com/virtualmachineservice</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>generation: 1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>name: dsm-appliance-lb-additional</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>namespace: svc-dsm-provider-operator-r77bq</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>resourceVersion: "16164207"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>uid: ae4a417c-bedc-4d08-bd6b-b11264b47751</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">spec:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>ports:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>- name: <strong>ssh</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>port: <strong>22</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>protocol: <strong>TCP</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>targetPort: <strong>22</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>selector:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>dsm.vmware.com/appliance-name: dsm-appliance</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>type: LoadBalancer</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">status:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">  </span>loadBalancer:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>ingress:</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>- ip: <strong>192.168.41.73</strong></span></pre>
<p style="text-align: justify;">At this point, SSH is opened to the DSM appliance via a new loadBalancer IP address. This means that we should be able to SSH to it. However, in order to be able to login as the root user, the root password must also be retrieved. This is help in a secret called <em>dsm-appliance-root-cred</em> in the same namespace. Here is just one example of how to retrieve it.</p>
<pre class="p2"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get secrets -n svc-dsm-provider-operator-r77bq</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">NAME <span class="Apple-converted-space">                                </span>TYPE <span class="Apple-converted-space">                            </span>DATA <span class="Apple-converted-space">  </span>AGE</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-appliance-root-cred<span class="Apple-converted-space">              </span>Opaque <span class="Apple-converted-space">                          </span>1<span class="Apple-converted-space">      </span>10d</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-po-values<span class="Apple-converted-space">                        </span>Opaque <span class="Apple-converted-space">                          </span>1<span class="Apple-converted-space">      </span>10d</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dsm-provider-operator-pull-regcred <span class="Apple-converted-space">  </span>kubernetes.io/dockerconfigjson <span class="Apple-converted-space">  </span>1<span class="Apple-converted-space">      </span>10d</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>k get secrets -n svc-dsm-provider-operator-r77bq \
dsm-appliance-root-cred --template='{{.data.root_password}}' | base64 -d; echo</strong></span>
<em><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">9L0b^9Lu%V@8mXl</span></em>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]#</span></pre>
<p style="text-align: justify;">Now we have SSH opened, we have the IP address to reach the DSM appliance and we have the root password. Let&#8217;s see if we can successfully access it.</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@423789b3f055e8e9961d56e456f323d6 [ ~ ]# <strong>ssh root@192.168.41.73</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Welcome to Photon 5.0 (\m) - Kernel \r (\l)</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">(root@192.168.41.73) Password: <em>9L0b^9Lu%V@8mXl</em></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@photon-6ca473c9efbb [ ~ ]# <strong>docker ps</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">CONTAINER ID <span class="Apple-converted-space">  </span>IMAGE<span class="Apple-converted-space">                                                  </span>COMMAND<span class="Apple-converted-space">                  </span>CREATED <span class="Apple-converted-space">      </span>STATUS <span class="Apple-converted-space">      </span>PORTS<span class="Apple-converted-space">                      </span>NAMES</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">dc797efaaa57 <span class="Apple-converted-space">  </span>dsm-tsql-provisioner:9.1.1.0.25641961<span class="Apple-converted-space">                  </span>"/provisioner --conf…" <span class="Apple-converted-space">  </span>5 days ago<span class="Apple-converted-space">    </span>Up 5 days <span class="Apple-converted-space">                              </span>dsm-tsql-provisioner-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">77121de7aacd <span class="Apple-converted-space">  </span>vc-session-manager:9.1.1.0.25641961<span class="Apple-converted-space">                    </span>"/vc-session-manager…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>vc-session-manager-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">e155538f05d9 <span class="Apple-converted-space">  </span>telegraf:v1.38.4_vmware.1<span class="Apple-converted-space">                              </span>"/bin/sh -c 'telegra…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>dsm-telegraf-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">c50cdede22b4 <span class="Apple-converted-space">  </span>provider-update-service:9.1.1.0.25641960 <span class="Apple-converted-space">              </span>"/bin/sh -c '/usr/ja…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>provider-update-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">8ecc8312b858 <span class="Apple-converted-space">  </span>provider-monitoring-service:9.1.1.0.25641960 <span class="Apple-converted-space">          </span>"/bin/sh -c '/usr/ja…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>monitoring-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2ddc5884de06 <span class="Apple-converted-space">  </span>registry:3 <span class="Apple-converted-space">                                            </span>"/entrypoint.sh /etc…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>docker-registry</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">1297b75df54e <span class="Apple-converted-space">  </span>simplified-gateway:9.1.1.0.25641961<span class="Apple-converted-space">                    </span>"/gateway --v=5 --ds…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days <span class="Apple-converted-space">  </span>127.0.0.1:5443-&gt;6443/tcp <span class="Apple-converted-space">  </span>sgw-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">554efa07f087 <span class="Apple-converted-space">  </span>dsm/cluster-api-controller:1.13.2_vmware.2 <span class="Apple-converted-space">            </span>"/manager --leader-e…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>kubernetes-service-capi-1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aee34cb51ecf <span class="Apple-converted-space">  </span>dsm/kubeadm-bootstrap-controller:1.13.2_vmware.2 <span class="Apple-converted-space">      </span>"/manager --leader-e…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>kubernetes-service-kadm-1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">234b8a29a113 <span class="Apple-converted-space">  </span>dsm/cluster-api-ipam-provider-in-cluster:1.1.0 <span class="Apple-converted-space">        </span>"/manager --leader-e…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>kubernetes-service-caip-1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">3d0d49c989fe <span class="Apple-converted-space">  </span>dsm/kubeadm-control-plane-controller:1.13.2_vmware.2 <span class="Apple-converted-space">  </span>"/manager --leader-e…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>kubernetes-service-kcp-1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">1718cea3e5e0 <span class="Apple-converted-space">  </span>dsm/cluster-api-vsphere-controller:1.16.1_vmware.2 <span class="Apple-converted-space">    </span>"/manager --leader-e…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>kubernetes-service-capv-1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">cf767b7526af <span class="Apple-converted-space">  </span>kubernetes-service:9.1.1.0.25641963<span class="Apple-converted-space">                    </span>"/opt/moneta/kuberne…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days <span class="Apple-converted-space">  </span>0.0.0.0:6443-&gt;6443/tcp <span class="Apple-converted-space">    </span>kubernetes-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">a2b5b3972550 <span class="Apple-converted-space">  </span>provider-service:9.1.1.0.25641960<span class="Apple-converted-space">                      </span>"/usr/bin/bash -c 'v…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>provider-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">3f4d4399ee9d <span class="Apple-converted-space">  </span>bitnami-influxdb:1.12.4-photon-5 <span class="Apple-converted-space">                      </span>"/bin/sh -c 'influxd…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days<span class="Apple-converted-space">                              </span>influxdb-service</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">85df57a66487 <span class="Apple-converted-space">  </span>provider-ui:9.1.1.0.25641967 <span class="Apple-converted-space">                          </span>"/bin/sh -c '/usr/sb…" <span class="Apple-converted-space">  </span>10 days ago <span class="Apple-converted-space">  </span>Up 10 days <span class="Apple-converted-space">  </span>0.0.0.0:443-&gt;8443/tcp<span class="Apple-converted-space">      </span>provider-ui</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
root@photon-6ca473c9efbb [ ~ ]# <strong>kg get postgresclusters -A</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">NAMESPACE <span class="Apple-converted-space">                  </span>NAME <span class="Apple-converted-space">                </span>STATUS <span class="Apple-converted-space">  </span>STORAGE <span class="Apple-converted-space">  </span>VERSION<span class="Apple-converted-space">                </span>AGE</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">7b6916-tenant-03-ns-g8krt <span class="Apple-converted-space">  </span>tenant-03-pg-db-01 <span class="Apple-converted-space">  </span>Ready<span class="Apple-converted-space">    </span>20Gi<span class="Apple-converted-space">      </span>18.4+vmware.v9.1.1.0 <span class="Apple-converted-space">  </span>10d</span></pre>
<p style="text-align: justify;">Everything looks to be working as expected. Remember that once you are finished with your troubleshooting on the DSM appliance, remove the VM Service that was created earlier. This will ensure that SSH access to the DSM appliance is once again removed. Retain the YAML manifest though, as you can re-apply it when you need to open SSH access once again.</p>
<p>The post <a href="https://cormachogan.com/2026/09/21/how-to-enable-ssh-on-dsm-appliance-when-deployed-via-vcfa-9-1-1/">How to enable SSH on DSM Appliance when deployed via VCFA 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/21/how-to-enable-ssh-on-dsm-appliance-when-deployed-via-vcfa-9-1-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33214</post-id>	</item>
		<item>
		<title>Bucket Policies in VCFA 9.1.1 for Native Object Storage</title>
		<link>https://cormachogan.com/2026/09/18/bucket-policies-in-vcfa-9-1-1-for-native-object-storage/</link>
					<comments>https://cormachogan.com/2026/09/18/bucket-policies-in-vcfa-9-1-1-for-native-object-storage/?noamp=mobile#respond</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 13:00:10 +0000</pubDate>
				<category><![CDATA[Native Object Storage]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[VSAN]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33177</guid>

					<description><![CDATA[<p>In an earlier post on object storage, we look at the role privieges that VCF Automation users could be assigned within an organization. Since the scope of object storage privileges is at the project level, we also looked at the role of Project Admins and Project Advanced Users. within a project. We saw how a Project Admin could grant access control to different Project Users, creating access control policies to control which s3 actions and which s3 resource that a user was allowed in a given project. In this post, I wanted to take this a little further. As mentioned,&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/18/bucket-policies-in-vcfa-9-1-1-for-native-object-storage/">Bucket Policies in VCFA 9.1.1 for Native Object Storage</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" decoding="async" class="alignleft wp-image-33151 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?resize=198%2C224&#038;ssl=1" alt="" width="198" height="224" /></a>In <a href="https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/" target="_blank" rel="noopener">an earlier post</a> on object storage, we look at the role privieges that VCF Automation users could be assigned within an organization. Since the scope of object storage privileges is at the project level, we also looked at the role of Project Admins and Project Advanced Users. within a project. We saw how a Project Admin could grant access control to different Project Users, creating access control policies to control which s3 actions and which s3 resource that a user was allowed in a given project. In this post, I wanted to take this a little further. As mentioned, the scope of a user&#8217;s privileges is the project. But suppose I had a user who was in two different projects in the same organisation. And I wanted this user to be able to copy contents between their buckets that are in the different projects. By default, this is not allowed. But it is possible to construct a bucket policy that will allow the user to copy between those different project buckets. Let&#8217;s see how to do that in this post.</p>
<p style="text-align: justify;">Let&#8217;s use an LDAP user. In this case, my LDAP user is called <strong>tenant01</strong>. At the organisation level, this user is an org user with object store privileges. At the project level, this user has been given the role of Project Administrator in two projects in my organisation. The projects are called default-project and shared-project. This user also has a bucket in each project, built on the same object storage, <em>proj-admin-bucket-01-def-proj</em> (default-project) and <em>proj-admin-bucket-02-shared-proj</em> (shared-project). I am going to use the aws cli to demonstrate how it is not possible to copy from one bucket to another bucket, and then configure Native Object Storage bucket policies to show how it can be achieved. I will show you where to retrieve the account id shortly. I will also show you how to create the profiles for the user so that they can be used with the aws cli.</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>Organization</strong></td>
<td style="text-align: center;" colspan="2">tenant-01-org</td>
</tr>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>LDAP User</strong></td>
<td style="width: 33.3333%; text-align: center;" colspan="2">tenant01</td>
</tr>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>Project</strong></td>
<td style="width: 33.3333%; text-align: center;">default-project</td>
<td style="width: 33.3333%; text-align: center;">shared-project</td>
</tr>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>Account ID</strong></td>
<td style="width: 33.3333%; text-align: center;">38925014951642977</td>
<td style="width: 33.3333%; text-align: center;">67271507534621802</td>
</tr>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>Bucket</strong></td>
<td style="width: 33.3333%; text-align: center;">proj-admin-bucket-01-def-proj</td>
<td style="width: 33.3333%; text-align: center;">proj-admin-bucket-02-shared-proj</td>
</tr>
<tr>
<td style="width: 33.3333%; border-style: solid; border-color: #000000; text-align: center;"><strong>Profile</strong></td>
<td style="width: 33.3333%; text-align: center;">tenant01-default-project</td>
<td style="width: 33.3333%; text-align: center;">tenant01-shared-project</td>
</tr>
</tbody>
</table>
<h2>Initial setup</h2>
<p style="text-align: justify;">If using the aws cli, some configuration and credential files need to be created first. I am using an Ubuntu Linux jump-box, and have install the aws cli <a href="https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html#getting-started-install-instructions" target="_blank" rel="noopener">found here</a>. I created a <span style="font-family: 'courier new', courier, monospace;">.aws/config</span> and a <span style="font-family: 'courier new', courier, monospace;">.aws/credentials</span> for my LDAP user <strong>tenant01</strong>. Note the relationship between the profile name used in the <span style="font-family: 'courier new', courier, monospace;">.aws/config</span> and the entries in the credentials file. It is important to make these match. In the config file, the<strong> ca_bundle</strong> is optional. You can use <span style="font-family: 'courier new', courier, monospace;">&#8211;no-verify-ssl</span> on the command line if you prefer. The CA file is the same CA that was used to sign the certificate for the object storage wildcard certificate when it was created in VCFA. The <strong>endpoint_url</strong> points to my object store. In the <span style="font-family: 'courier new', courier, monospace;">.aws/credentials</span>, the key and secret can be obtain from the Native Object Storage UI in VCF Automation.</p>
<h4>.aws/config</h4>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[profile tenant01-default-project]</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">region = cork-region</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ca_bundle = /home/cormac/s3/ca-cert.pem</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ignore_configure_endpoints_urls = true</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">endpoint_url = https://storage-tenant-01-obj-store-01.rainpole.io/</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[profile tenant01-shared-project]</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">region = cork-region</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ca_bundle = /home/cormac/s3/ca-cert.pem</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ignore_configure_endpoints_urls = true</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">endpoint_url = https://storage-tenant-01-obj-store-01.rainpole.io/</span></pre>
<h4><strong>.aws/credentials</strong></h4>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[tenant01-default-project]</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws_access_key_id = TWM9F73VC7HDK9VUJ0ND</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws_secret_access_key = IXE9vVPHzzaqGXMvh2yOPLDBDsc33heHBPfwjYdy</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[tenant01-shared-project]</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws_access_key_id = 5XYCB3GMJIPPBYEI3KDB</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws_secret_access_key = hWzoJV5GaQ3W1ClWJQctsjCnYcTSc8hB68iX2CVN</span></pre>
<h2>Test bucket access</h2>
<p style="text-align: justify;">We can now try to simple commands to list the contents of the buckets. We can start with the <strong>tenant01</strong> LDAP user added to the default-project, and see if this user can use their default-project credentials to list the contents of their bucket in the default-project and then in the shared-project.</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 ls s3://proj-admin-bucket-01-def-proj --summarize --human-readable --recursive \
--profile tenant01-default-project</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_151358.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_152130.csv</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Objects: 2</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Size: 264 Bytes</span></pre>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 ls s3://proj-admin-bucket-02-shared-proj --summarize --human-readable --recursive \
--profile tenant01-default-project</strong></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws: [ERROR]: An error occurred (AccessDenied) when calling the ListObjectsV2 operation: Access denied</span>
</pre>
<p style="text-align: justify;">As expected, they can only list bucket contents in the. default-project as that is the project that the credentials are associated with. Let&#8217;s try this the other way around, and check if the LDAP user tenant01, who is also a project admin in the shared-project, can access the bucket contents in the default-project.</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ </span><strong><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws s3 ls s3://proj-admin-bucket-02-shared-proj --summarize --human-readable --recursive \
--profile tenant01-shared-project</span></strong>
<strong><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 14:42:21 26.4 KiB supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml</span></strong>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Objects: 1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Size: 26.4 KiB</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
$ <strong>aws s3 ls s3://proj-admin-bucket-01-def-proj --summarize --human-readable --recursive \
--profile tenant01-shared-project</strong></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws: [ERROR]: An error occurred (AccessDenied) when calling the ListObjectsV2 operation: Access denied</span></pre>
<p style="text-align: justify;">So as expected, the same issue occurs. The <strong>tenant01</strong> user who has credentials on the <em>default-project</em> cannot list objects in the <em>shared-project</em> since privileges on object storage are scoped at the project level. And vice-versa. The <strong>tenant01</strong> user who has credentials on the <em>shared-project</em> cannot list objects in the <em>default-project</em>. Let&#8217;s see how we can build a policy that will allow the default-project user <strong>tenant01</strong> access the <span style="font-family: 'courier new', courier, monospace;">proj-admin-bucket-02-shared-project</span> bucket created in <em>shared-project</em>.</p>
<h2 style="text-align: justify;">Build a bucket policy</h2>
<p style="text-align: justify;">To allow users from a remote project to access a bucket in a local bucket, a bucket policy must be created to allow it. The first thing you will need to retrieve before building a bucket policy is the account id of the project. We captured this in the table earlier. You can get this from the VCFA UI, as it is shown next to the Project name under the Native Object Storage view.</p>
<p>The default-project id is <strong>38925014951642977</strong>:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-def-389.png?ssl=1"><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-33182" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-def-389.png?resize=506%2C150&#038;ssl=1" alt="" width="506" height="150" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-def-389.png?w=506&amp;ssl=1 506w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-def-389.png?resize=300%2C89&amp;ssl=1 300w" sizes="(max-width: 506px) 100vw, 506px" /></a></p>
<p>The shared-project id is <strong>67271507534621802</strong>:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-shared-672.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-full wp-image-33183" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-shared-672.png?resize=488%2C143&#038;ssl=1" alt="" width="488" height="143" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-shared-672.png?w=488&amp;ssl=1 488w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/acc-id-shared-672.png?resize=300%2C88&amp;ssl=1 300w" sizes="auto, (max-width: 488px) 100vw, 488px" /></a></p>
<p style="text-align: justify;">You can use the aws cli to check that there is no existing bucket policy in place, making sure you use the correct credentials to do the query.</p>
<p style="text-align: justify;"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3api get-bucket-policy &#8211;bucket proj-admin-bucket-02-shared-proj \</strong><br />
<strong>&#8211;profile tenant01-shared-project</strong> </span><br />
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">aws: [ERROR]: An error occurred (NoSuchBucketPolicy) when calling the GetBucketPolicy operation: The bucket policy does not exist</span></p>
<p style="text-align: justify;">We now want to set a bucket policy that allows users from the default-project ( account id beginning 389 ) to access a bucket (<span style="font-family: 'courier new', courier, monospace;">proj-admin-bucket-02-shared-project)</span>in the shared-project. We can do this via the API /CLI or via Object Storage UI in VCF Automation. We want users from the remote project to be able to access the bucket read-only, so we are only allowing actions to list the bucket, get objects from the bucket and get the tags on these objects. We are not letting the remote users write anything to the bucket. The bucket policy, in JSON format, will look something like this:</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">{</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>"Version": "2012-10-17",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>"Statement": [{</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Sid": "AllowListBucket",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Effect": "Allow",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Principal": {</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">            </span>"AWS": "arn:aws:iam::38925014951642977:root"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>},</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Action": "s3:ListBucket",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Resource": "arn:aws:s3:::proj-admin-bucket-02-shared-proj"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>}, {</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Sid": "AllowGetObjects",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Effect": "Allow",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Principal": {</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">            </span>"AWS": "38925014951642977"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>},</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Action": ["s3:GetObject"],</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Resource": "arn:aws:s3:::proj-admin-bucket-02-shared-proj/*"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>}, {</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Sid": "AllowGetTags",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Effect": "Allow",</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Principal": {</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">            </span>"AWS": "arn:aws:iam::38925014951642977:root"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>},</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Action": ["s3:GetObjectTagging"],</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">        </span>"Resource": "arn:aws:s3:::proj-admin-bucket-02-shared-proj"</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><span class="Apple-converted-space">    </span>}]</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">}</span></pre>
<p style="text-align: justify;">Most of it is probably easy to understand, but the Principal might need a bit more explaining. Let&#8217;s break down the ARN in more detail:</p>
<ul>
<li>
<p style="text-align: justify;" data-path-to-node="4,0,0"><b data-path-to-node="4,0,0" data-index-in-node="0"><code data-path-to-node="4,0,0" data-index-in-node="0">arn:aws:</code></b> Amazon Resource Name (usually in the public AWS cloud).</p>
</li>
<li style="text-align: justify;">
<p data-path-to-node="4,1,0"><b data-path-to-node="4,1,0" data-index-in-node="0"><code data-path-to-node="4,1,0" data-index-in-node="0">iam:</code></b> The AWS service involved. In this case, Identity and Access Management.</p>
</li>
<li style="text-align: justify;">
<p data-path-to-node="4,2,0"><b data-path-to-node="4,2,0" data-index-in-node="0"><code data-path-to-node="4,2,0" data-index-in-node="0">38925014951642977:</code></b> The Account ID. <i data-path-to-node="4,2,0" data-index-in-node="49">(Note: Standard AWS account IDs are 12 digits long but ours are 17 digits).</i></p>
</li>
<li>
<p style="text-align: justify;" data-path-to-node="4,3,0"><b data-path-to-node="4,3,0" data-index-in-node="0"><code data-path-to-node="4,3,0" data-index-in-node="0">root</code></b> This does <b data-path-to-node="4,3,0" data-index-in-node="18">not</b> literally mean the root user. Instead, in a policy context, it acts as a placeholder for the <b data-path-to-node="4,3,0" data-index-in-node="175">entire account</b>. It basically <b data-path-to-node="11" data-index-in-node="54">delegates permission management</b> to the administrator of that target account. It means: <i data-path-to-node="11" data-index-in-node="141">&#8220;I trust this account. The administrator of that account can now use their own IAM policies to grant their specific IAM users / roles to my S3 bucket.&#8221;</i></p>
</li>
</ul>
<p style="text-align: justify;">To create this policy via the API, run the following aws cli commands, where <span style="font-family: 'courier new', courier, monospace; font-size: 12pt;">&#8211;policy file:// </span>points to the JSON file above:</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3api put-bucket-policy --bucket proj-admin-bucket-02-shared-proj \</strong>
<strong>--policy file://enable-cross-bucket-iam-from-acc-38925014951642977-tenant01.json \</strong>
<strong>--profile tenant01-shared-project</strong></span></pre>
<p style="text-align: justify;">If no error is returned, the policy has successfully taken effect. If you want to do this via the VCFA UI, login to the Organization where the Object Store has been created. Go to Build &amp; Deploy &gt; Object Storage. Select the project where you wish to apply the bucket policy, e.g., <span style="font-family: 'courier new', courier, monospace;">shared-project</span>.  Click on the bucket to which the policy is to be applied. In this case, it is <span style="font-family: 'courier new', courier, monospace;">tenant-admin-bucket-02-shared-proj</span>. Select Policy, and the Click Here to apply a bucket policy. Click JSON, and paste the bucket policy content created earlier.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33196 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?resize=769%2C842&#038;ssl=1" alt="" width="769" height="842" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?w=819&amp;ssl=1 819w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?resize=274%2C300&amp;ssl=1 274w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?resize=768%2C841&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-json.png?resize=769%2C842&amp;ssl=1 769w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Apply the bucket policy via the UI by clicking on Save. After saving, click Expand All to see the policy details. Note that this view will be available either way &#8211; if you applied the policy via the API or UI, it will appear here:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-details.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33197 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-details.png?resize=740%2C919&#038;ssl=1" alt="" width="740" height="919" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-details.png?w=740&amp;ssl=1 740w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/bucket-policy-details.png?resize=242%2C300&amp;ssl=1 242w" sizes="auto, (max-width: 740px) 100vw, 740px" /></a></p>
<p style="text-align: justify;">Now use the aws cli once more to see if it the bucket policy has taken effect.<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;"><br />
</span></p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3api get-bucket-policy --bucket proj-admin-bucket-02-shared-proj \</strong>
<strong>--profile tenant01-shared-project</strong> 
{
"Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"AllowListBucket\",
\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::38925014951642977:root\"},
\"Action\":\"s3:ListBucket\",\"Resource\":\"arn:aws:s3:::proj-admin-bucket-02-shared-proj\"},
{\"Sid\":\"AllowGetObjects\",\"Effect\":\"Allow\","Principal\":{\"AWS\":\"arn:aws:iam::38925014951642977:root\"},
\"Action\":[\"s3:GetObject\"],\"Resource\":\"arn:aws:s3:::proj-admin-bucket-02-shared-proj/*\"},
{\"Sid\":\"AllowGetObjectTags\",\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::38925014951642977:root\"},
\"Action\":[\"s3:GetObjectTagging\"],\"Resource\":\"arn:aws:s3:::proj-admin-bucket-02-shared-proj/*\"}]}"
}
</span></pre>
<p style="text-align: justify;">This looks good. Now see if the LDAP user tenant01, i.e., the project admin user from the default-project, can list the contents of the bucket that has been created on the same object storage but in a different project.</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 ls s3://proj-admin-bucket-02-shared-proj --summarize \</strong>
<strong>--human-readable --recursive --profile tenant01-default-project
</strong></span>2026-09-14 14:42:21 26.4 KiB supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml

Total Objects: 1
Total Size: 26.4 KiB</pre>
<p style="text-align: justify;">Success! The user from the default-project can list the bucket contents of the shared-project bucket which resides in a different project, something this user could not do before the bucket policy was applied. Let&#8217;s now try to copy the contents of the bucket in the shared-project to a bucket in the default-project.</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 cp s3://proj-admin-bucket-02-shared-proj s3://proj-admin-bucket-01-def-proj \</strong>
<strong>--recursive --profile tenant01-default-project</strong>
copy: s3://proj-admin-bucket-02-shared-proj/supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml to s3://proj-admin-bucket-01-def-proj/supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml
</span></pre>
<p>Let&#8217;s check if the file made it over to the default-project bucket:</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 ls s3://proj-admin-bucket-01-def-proj --summarize --human-readable \
--recursive --profile tenant01-default-project</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_151358.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_152130.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-16 09:06:38 26.4 KiB supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Objects: 3</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Size: 26.7 KiB</span></pre>
<p style="text-align: justify;">Once again, success! If you have some issues, you can run some commands to check that access to the local bucket is working as expected. One useful command is checking if it is possible to upload a simple local file to the destination bucket from the jump-box using your locla project credentials. This will verify that the user has credentials to write to the local bucket.</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>aws s3 ls s3://proj-admin-bucket-01-def-proj --profile tenant01-default-project</strong> 
</span><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_151358.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_152130.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-16 09:06:38 26.4 KiB supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Objects: 3</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Size: 26.7 KiB</span>


<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>echo "test" &gt; test.txt</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
$ <strong>aws s3 cp test.txt s3://proj-admin-bucket-01-def-proj/ --profile tenant01-default-project</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">upload: ./test.txt to s3://proj-admin-bucket-01-def-proj/test3.txt</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
$ <strong>aws s3 ls s3://proj-admin-bucket-01-def-proj --profile tenant01-default-project
</strong>2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_151358.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-14 09:47:53 132 Bytes credentials_admin_20260910_152130.csv</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-16 09:06:38 26.4 KiB supervisor-service-contour-legacy-v1.33.1_vmware.2-25276585.yml</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2026-09-16 09:11:41 5 Bytes test.txt</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Objects: 4</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Total Size: 26.7 KiB</span></pre>
<h2>Summary</h2>
<p style="text-align: justify;">Although still a tech preview in VMware Cloud Foundation version 9.1.1, Native Object Store has many production-ready features, especially around multi-tenancy. Whilst Object Storage is enabled at the scope of a Region, meaning that it is available to all organizations in a given region, the object stores themselves are organisation specific. Within an organisation, projects share the same underlying object store, but the access controls are set at the project level. As we have seen, an LDAP user who has been added to two projects may be allowed or denied access to the object store on a per project basis. Project Administrators decide which users are allowed to create, delete and access buckets, and the actions they can carry out on a bucket through the access control settings. Cross-Project bucket access can be also configured by a Project Admin through bucket policies, as seen above, to allow or deny remote access to buckets. Lots of nice granular controls in Native Object Storage.</p>
<p>The post <a href="https://cormachogan.com/2026/09/18/bucket-policies-in-vcfa-9-1-1-for-native-object-storage/">Bucket Policies in VCFA 9.1.1 for Native Object Storage</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/18/bucket-policies-in-vcfa-9-1-1-for-native-object-storage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33177</post-id>	</item>
		<item>
		<title>Identity Providers and Access Controls in VCFA 9.1.1 for Native Object Storage</title>
		<link>https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/</link>
					<comments>https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/?noamp=mobile#comments</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 13:00:11 +0000</pubDate>
				<category><![CDATA[Native Object Storage]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[VSAN]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33117</guid>

					<description><![CDATA[<p>In a previous post, I highlighted how to get started with Native Object Storage which is in tech preview in VMware Cloud Foundation (VCF) version 9.1.1. In that post, we saw the role of the Provider Admin and the Organization Admin in VCF Automation (VCFA). We saw that the Provider Admin could create object storage on behalf of the tenant users within an organization, but could not actually create or view the buckets on the object store, nor see the access controls or anything else associated with the object store for that matter. We saw that the Org Admin had&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/">Identity Providers and Access Controls in VCFA 9.1.1 for Native Object Storage</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-33151 alignleft" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?resize=198%2C224&#038;ssl=1" alt="" width="198" height="224" /></a>In a previous post, I highlighted <a href="https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/" target="_blank" rel="noopener">how to get started with Native Object Storage</a> which is in tech preview in VMware Cloud Foundation (VCF) version 9.1.1. In that post, we saw the role of the Provider Admin and the Organization Admin in VCF Automation (VCFA). We saw that the Provider Admin could create object storage on behalf of the tenant users within an organization, but could not actually create or view the buckets on the object store, nor see the access controls or anything else associated with the object store for that matter. We saw that the Org Admin had to log in directly to the organization in order to be able to work with the Object Store. In this post, I want to look at the relationship between Object Storage and some other VCFA organization personas, such as the Project Admin and the Project Advanced User. We will add some users to VCFA using LDAP, give them a role in VCFA (organization users to begin with), and then give them roles in the project itself to see the different behaviours. The assumption is that Native Object Storage is already configured, so we will implement the following steps:</p>
<ol style="text-align: justify;">
<li>As the Provider Admin, configure LDAP as an Identity Provider</li>
<li>As an Provider Admin, add the &#8216;Provider&#8217; configured LDAP to an Organization</li>
<li>As an Org Admin, add LDAP user as an organization user</li>
<li>As an Org Admin, assign user a Project Admin role</li>
<li>As a Project Admin, observe Object Storage behaviour</li>
<li>As an Org Admin, create a new organization role to include additional object store privileges</li>
<li>As an Org Admin, change role of organization user (Project Admin)</li>
<li>As a Project Admin, login to organization and observe change in Object Storage behaviour</li>
<li>As an Org Admin, add a new LDAP user as organization user with additional object store privileges</li>
<li>As an Org Admin, assign Project Advanced User role to new LDAP user</li>
<li>As a Project Admin, assign Object Storage Access Controls to LDAP user</li>
<li>As an Project Advanced User, login to organization and observe Object Storage behaviour</li>
</ol>
<p style="text-align: justify;">At the end of this post, we should have a pretty good idea about how Native Object Storage access controls work for the different VCFA personas.</p>
<h2>Step 1: Configure LDAP/Active Directory  on Provider</h2>
<p style="text-align: justify;">Begin by configuring LDAP as an Identity Provider for VCFA as the Provider Admin. You may get a &#8216;trust certificate&#8217; popup similar to what I see here during testing. Once configured, it is worthwhile doing a quick test on some of the users to ensure you can query your LDAP Server / Active Directory successfully.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33120 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?resize=769%2C509&#038;ssl=1" alt="" width="769" height="509" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?resize=1024%2C678&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?resize=300%2C199&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?resize=768%2C508&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?resize=769%2C509&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.45.49.png?w=1068&amp;ssl=1 1068w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">To do a user test, click on the <strong>Test</strong> icon, provide the password of the user used to configure LDAP in the first place, and then add the LDAP/AD user that you want to test. This will return a list of attribute and whether or not the are configured. If you are happy that LDAP is working, we can proceed to the Organization where Object Storage is configured. Below is an example of a Test output, displaying which user attributes are configured and which are not.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.46.36.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33121" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.46.36.png?resize=512%2C577&#038;ssl=1" alt="" width="512" height="577" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.46.36.png?w=508&amp;ssl=1 508w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/Screenshot-2026-09-02-at-14.46.36.png?resize=266%2C300&amp;ssl=1 266w" sizes="auto, (max-width: 512px) 100vw, 512px" /></a></p>
<h2>Step 2: Configure LDAP on Organization</h2>
<p style="text-align: justify;">Login to your Organization as the Provider Admin. Select the <strong>Administer</strong> tab, and then select <strong>Identity Providers</strong>. Next, select LDAP and then the <strong>Configure</strong> button, as shown below.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33122 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?resize=769%2C474&#038;ssl=1" alt="" width="769" height="474" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?resize=1024%2C631&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?resize=300%2C185&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?resize=768%2C473&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?resize=769%2C474&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-select-LDAP.png?w=1172&amp;ssl=1 1172w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">In the LDAP source selection list, choose<strong> VCF Automation system LDAP service</strong>, which is what was configured in step 1. Add a distinguished name for the Org. Save the settings.</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33124" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?resize=769%2C505&#038;ssl=1" alt="" width="769" height="505" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?resize=1024%2C673&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?resize=300%2C197&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?resize=768%2C504&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?resize=769%2C505&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-use-provider-ldap.png?w=1119&amp;ssl=1 1119w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Step 3: Import LDAP user as Organization User</h2>
<p style="text-align: justify;">Let&#8217;s import an LDAP user into our organization. You can do this as a Provider Admin, or you can log out and log in as the Org Admin. Return to the Administer section of the Organization but now select <strong>Access Control</strong> from the left hand menu list. At present there is only a single user, the tenant-03-admin. This is the first user that was added during the creation of the organization. Click on the <strong>Import Users</strong> button to add a new users from LDAP.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-import-users-1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33125" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-import-users-1.png?resize=769%2C459&#038;ssl=1" alt="" width="769" height="459" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-import-users-1.png?w=633&amp;ssl=1 633w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-import-users-1.png?resize=300%2C179&amp;ssl=1 300w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">The Org Admin adds LDAP user &#8216;sadaf&#8217;. The Org Admin is also going to assign a role of &#8220;Organization User&#8221;. Click <strong>Import</strong>.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33126 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?resize=769%2C602&#038;ssl=1" alt="" width="769" height="602" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?resize=1024%2C801&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?resize=300%2C235&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?resize=768%2C601&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?resize=769%2C602&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-add-sadaf-with-org-user-privs.png?w=1086&amp;ssl=1 1086w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Step 4: Add LDAP user to Project as Project Admin</h2>
<p style="text-align: justify;">Now navigate to the Manage &amp; Govern tab in the Organization. Select Projects, then click on the Project (e.g., default-project) that you wish to assign users to.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.5-default-project.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-full wp-image-33128" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.5-default-project.png?resize=666%2C373&#038;ssl=1" alt="" width="666" height="373" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.5-default-project.png?w=666&amp;ssl=1 666w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.5-default-project.png?resize=300%2C168&amp;ssl=1 300w" sizes="auto, (max-width: 666px) 100vw, 666px" /></a></p>
<p style="text-align: justify;">Click on <strong>Users</strong>, then <strong>Add Users</strong>. In the Users list, type in the LDAP User that was previously added to the organization, i.e., &#8220;sadaf&#8221;. Assign a Project Role. In this case, &#8220;sadaf&#8221; is assigned the role of Project Administrator. Click Add, and then make sure you click on the <strong>Save</strong> button located at the bottom of the window. I have missed this on a number of occasions, so be sure to do that step.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-add-sadaf-to-project-as-admin.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-full wp-image-33127" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-add-sadaf-to-project-as-admin.png?resize=768%2C490&#038;ssl=1" alt="" width="768" height="490" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-add-sadaf-to-project-as-admin.png?w=768&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-add-sadaf-to-project-as-admin.png?resize=300%2C191&amp;ssl=1 300w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Check the users on the project and ensure that user &#8216;sadaf&#8217; is listed as a Project Admin.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33130 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?resize=769%2C201&#038;ssl=1" alt="" width="769" height="201" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?resize=1024%2C268&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?resize=300%2C79&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?resize=768%2C201&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?resize=769%2C201&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-sadaf-is-proj-admin.png?w=1107&amp;ssl=1 1107w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Looks good. Let&#8217;s proceed to trying to manage Native Object Storage as a Project Admin.</p>
<h2>Step 5: Check Project Admin access to Native Object Storage</h2>
<p style="text-align: justify;">Log out of the organization as the provider admin / organization admin, and log back into this organization as &#8216;sadaf&#8217;, the Project Admin. From the Build &amp; Deploy tab, select Object Storage. You should now observe something identical to this &#8220;Unable to Load Object Stores&#8221; message:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33131" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=769%2C225&#038;ssl=1" alt="" width="769" height="225" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=1024%2C300&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=300%2C88&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=768%2C225&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=1536%2C451&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?resize=769%2C226&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-org-users-cannot-view-o-bj-stores.png?w=1650&amp;ssl=1 1650w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">The reason for this is because, in tech preview in version 9.1.1, the &#8220;Organization User&#8221; role does not have sufficient privileges to either View or Manage object storage. We are going to have to create a new organization role with additional privileges to access the object storage. Let&#8217;s do that next.</p>
<h2>Step 6: Create New Org Role with Object Storage Privileges</h2>
<p style="text-align: justify;">Log out of the tenant organization as the Project Admin and log back in as the Org Admin. Now, let&#8217;s take a look at the privileges associated with the Organization User. In the Organization, navigate to the Administer tab (which is only visible to Org Admins), and select Access Control once more from the left hand menu. Select <strong>Roles</strong>, then click on the Organization User to see the privileges/rights associated with that role. As you can see below there are no <strong>Object Store</strong> or <strong>vSAN Data Services</strong> privileges selected. Those are the ones needed for Object Storage.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33133 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?resize=769%2C464&#038;ssl=1" alt="" width="769" height="464" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?resize=1024%2C618&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?resize=300%2C181&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?resize=768%2C463&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?resize=769%2C464&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-privileges.png?w=1338&amp;ssl=1 1338w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">We can now go ahead and clone the organization user role to a new role where we can edit the privileges. In the role listing, click on the 3 dots in front of the Organization User roles and select <strong>Clone</strong>.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33134" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?resize=769%2C342&#038;ssl=1" alt="" width="769" height="342" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?resize=1024%2C455&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?resize=300%2C133&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?resize=768%2C341&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?resize=769%2C341&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/clone-org-user.png?w=1241&amp;ssl=1 1241w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Edit the new role, giving it a recognisable name, but more importantly, ensuring that the necessary <strong>Object</strong> <strong>Store</strong> and <strong>vSAN Data Service</strong> privileges are enabled. Note that in this case, I am selecting both management and view permissions. You may not want to do this, and instead only select View permissions for your Project Admins and Users. If you grant this role both sets of permissions, then anyone with this role will also be able to delete Object Stores in the Organisation, something you may not want to provide. Once the permsisions are selected, save this new Role.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33135 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?resize=769%2C582&#038;ssl=1" alt="" width="769" height="582" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?resize=1024%2C775&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?resize=300%2C227&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?resize=768%2C581&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?resize=769%2C582&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/org-user-with-obj-stor-privs.png?w=1033&amp;ssl=1 1033w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Step 7: Assign new role to LDAP User</h2>
<p style="text-align: justify;">Staying in Access Control, select the Users view. Click the three dots before user &#8216;sadaf&#8217; and select Edit. In the Assigned Roles section, remove the Organization User Role and add the new role with the object store privileges that you just cloned, in this case &#8220;Organization User with Object Store. Save the User settings.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33137" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?resize=768%2C618&#038;ssl=1" alt="" width="768" height="618" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?w=774&amp;ssl=1 774w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?resize=300%2C241&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?resize=768%2C618&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-sadaf-with-new-role.png?resize=769%2C619&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p>Now log back into the Organization as the Project Admin &#8216;sadaf&#8217; and see if the behaviour has changed with respect to Object Storage.</p>
<h2>Step 8: Observe change in Object Storage behaviour</h2>
<p style="text-align: justify;">Now when Project Admin &#8216;sadaf&#8217; logs into the organisation, navigates to Build &amp; Deploy, and then select Object Storage from the left hand menu, she is immediately offered an access key and secret. This is much better than previous behaviour. Keep in mind that this is because &#8216;sadaf&#8217; has already been added as a Project Admin to the default-project by the Org Admin, but now also has permissions to access to the object store. If multiple projects existed, and a different project other than default-project was selected, &#8216;sadaf&#8217; would not have access to the object storage from that project unless the Org Admin adds &#8216;sadaf&#8217; as a user to the project. &#8216;sadaf&#8217; has only been given access to the default-project and no other projects. <em>Access to the object store is scoped at the project level in VCF Automation</em>.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33138" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=769%2C355&#038;ssl=1" alt="" width="769" height="355" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=1024%2C473&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=300%2C139&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=768%2C355&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=1536%2C710&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?resize=769%2C356&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-Object-Store-view-with-new-role.png?w=1646&amp;ssl=1 1646w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">After saving the key and secret somewhere safe, and closing the welcome popup, the Project Admin can proceed with other activities, such as bucket creation and assigning additional project users access to the object storage.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33139" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=769%2C188&#038;ssl=1" alt="" width="769" height="188" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=1024%2C251&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=300%2C73&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=768%2C188&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=1536%2C376&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?resize=769%2C188&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-bucket-create-success.png?w=1646&amp;ssl=1 1646w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">A Project Admin has access to Security Credentials, Access Control and Service Accounts in this Project. As a Project Admin, this user &#8216;sadaf&#8217; can now control access to the Object Storage on behalf of other Project Users. Let&#8217;s look at that next.</p>
<h2>Step 9: Import a new LDAP User as Project Advanced User</h2>
<p style="text-align: justify;">We have already seen how to do this. This will have to be done as the Org Admin (or Provider Admin). It cannot be done by a Project Admin, as the Project Admin does not have access to the Administer tab (as you can see in the previous screenshot in step 8). This time, when importing the user &#8216;paudie&#8217; into the organization, ensure that the role is the org user + object storage privileges that we created earlier.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33141 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=769%2C408&#038;ssl=1" alt="" width="769" height="408" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=1024%2C543&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=300%2C159&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=768%2C408&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=1536%2C815&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?resize=769%2C408&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-add-paudie-as-obj-store-priv.png?w=1649&amp;ssl=1 1649w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Step 10: Add new LDAP User as Project Advanced User</h2>
<p style="text-align: justify;">Next, add user &#8220;paudie&#8221; to the Project (default-project) as a Project Advanced User. This can be done by the Organization admin or as the Project admin.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33140" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?resize=769%2C232&#038;ssl=1" alt="" width="769" height="232" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?resize=1024%2C309&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?resize=300%2C91&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?resize=768%2C232&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?resize=769%2C232&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-paudie-added-as-proj-adv-user.png?w=1106&amp;ssl=1 1106w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Let&#8217;s login to the organisation and see if our newly added Project Advanced User &#8220;paudie&#8221; has access to the object store. The answer is no. They currently only have access to the Project, but not to Object Storage within the Project. Note that you are redirected to the Project Admin to resolve this access issue.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33142" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=769%2C365&#038;ssl=1" alt="" width="769" height="365" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=1024%2C486&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=300%2C142&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=768%2C365&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=1536%2C729&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?resize=769%2C365&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-no-perms-as-proj-adv-user-by-default.png?w=1649&amp;ssl=1 1649w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Step 11: Assign Object Storage Access Controls</h2>
<p style="text-align: justify;">Log out as Project Advanced User &#8216;paudie&#8217;, and login as Project Admin &#8216;sadaf&#8217;. Once logged in as a Project Admin, check the Access Controls associated with the Object Store. All policies and their users are displayed. As we can see, only the Org Admin (the first Org user created with the organisation) and user &#8221;sadaf&#8217; (Project Admin) have policies designed to give access to the object store in this project. Project Advanced User &#8216;paudie&#8217; does not have any access to the object store.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33143 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=769%2C183&#038;ssl=1" alt="" width="769" height="183" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=1024%2C244&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=300%2C71&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=768%2C183&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=1536%2C365&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?resize=769%2C183&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-login-as-proj-adm-list-current-users.png?w=1648&amp;ssl=1 1648w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Project Admin &#8216;sadaf&#8217; can now go ahead and create some access rules for Project Advanced User &#8216;paudie&#8217;. We are not going to deal with granular rules here, but of course there are a range of actions that can be controlled, where we can grant or deny access to particular actions and to particular buckets. To keep things, simple, we are going to give the user &#8216;paudie&#8217; access to all actions on all buckets on this object store. Give the policy a name, select the user to which it applies, and then setup your statement to allow or deny actions on buckets. Then click Create. Below is an example of an access control policy where &#8216;paudie&#8217; is given access to all actions on all buckets on the object store in this project.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33144" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?resize=768%2C551&#038;ssl=1" alt="" width="768" height="551" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?w=979&amp;ssl=1 979w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?resize=300%2C215&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?resize=768%2C551&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-create-policy-for-paudie-full-access.png?resize=769%2C552&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">The policy will now be visible and can be viewed under Access Control. Note that this is only on the default-project only. This access control policy does not apply to other projects consuming the same object store.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33145" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?resize=768%2C342&#038;ssl=1" alt="" width="768" height="342" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?w=881&amp;ssl=1 881w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?resize=300%2C133&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?resize=768%2C342&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-access-policy-detail.png?resize=769%2C342&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<h2>Step 12: Observe change in Object Storage behaviour</h2>
<p style="text-align: justify;">Let&#8217;s log in to the organization once again as user &#8216;paudie&#8217; and see if access to the Object Storage has changed now that this user has been granted access control via a new policy.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33146" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=769%2C196&#038;ssl=1" alt="" width="769" height="196" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=1024%2C261&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=300%2C76&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=768%2C195&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=1536%2C391&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?resize=769%2C196&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-paudie-create-buckets-note-no-acess-control-.png?w=1647&amp;ssl=1 1647w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Success. Project Advanced User &#8216;paudie&#8217; can now access the object store, has access to buckets and can manage his own Security Credentials, i.e., create additional credentials. However, since this user is not a Project Admin, &#8216;paudie&#8217; does not have the ability to manage or change the Access Controls, nor does he have access to Service Accounts. These controls are only available to the Project Admin. Thus, user &#8216;paudie&#8217; is not able to onboard any more project users to enable them to access Object Storage. This has to be done by &#8216;sadaf&#8217; who has Project Admin privileges (or by the Organization admin).</p>
<h2>Summary</h2>
<p style="text-align: justify;">That completes the post. I hope it has gone some way to explain how VCF Automation roles and Project roles are used to implement Access Controls on Native Object Storage in the VCF 9.1.1 Technical Preview. This table should provide a useful recap. Note that many of the Org Admin tasks listed below could also be done by the Provider Admin:</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 11.1379%;"><strong>Role</strong></td>
<td style="width: 55.5287%;"><strong>Actions</strong></td>
</tr>
<tr>
<td style="width: 11.1379%;">Provider Admin</td>
<td style="width: 55.5287%;">
<ul>
<li><span style="font-size: 12pt;">Install &amp; Configure Native Object Storage</span></li>
<li><span style="font-size: 12pt;">Configure LDAP for VCF Private Cloud</span></li>
<li><span style="font-size: 12pt;">Create Object Stores for Organization (optional &#8211; delegate to Org Admin)</span></li>
<li><span style="font-size: 12pt;">Configure LDAP for Organization</span></li>
</ul>
</td>
</tr>
<tr>
<td style="width: 11.1379%;">Org Admin</td>
<td style="width: 55.5287%;">
<ul>
<li><span style="font-size: 12pt;">Create Object Stores for Organization</span></li>
<li><span style="font-size: 12pt;">Create Organization Role for Object Storage Users</span></li>
<li><span style="font-size: 12pt;">Import LDAP Users into Organization</span></li>
<li><span style="font-size: 12pt;">Assign Organization Role to LDAP Users</span></li>
<li><span style="font-size: 12pt;">Add Organization Users to Projects (optional &#8211; delegate to Project Admin)</span></li>
<li><span style="font-size: 12pt;">Create Access role for Project Users (optional &#8211; delegate to Project Admin)</span></li>
<li><span style="font-size: 12pt;">Create Projects (optional &#8211; delegate to Project Admin)</span></li>
<li><span style="font-size: 12pt;">Add Organization Users to Projects (optional &#8211; delegate to Project Admin)</span></li>
<li><span style="font-size: 12pt;">Create Access role for Project Users  (optional &#8211; delegate to Project Admin)</span></li>
<li><span style="font-size: 12pt;">Create and Consume buckets</span></li>
<li><span style="font-size: 12pt;">Create Security Credentials</span></li>
</ul>
</td>
</tr>
<tr>
<td style="width: 11.1379%;">Project Admin</td>
<td style="width: 55.5287%;">
<ul>
<li><span style="font-size: 12pt;">Create Projects</span></li>
<li><span style="font-size: 12pt;">Add Organization Users to Projects</span></li>
<li><span style="font-size: 12pt;">Create Access role for Project Users</span></li>
<li><span style="font-size: 12pt;">Create and Consume buckets</span></li>
<li><span style="font-size: 12pt;">Create Security Credentials</span></li>
</ul>
</td>
</tr>
<tr>
<td style="width: 11.1379%;">Project Advanced User</td>
<td style="width: 55.5287%;">
<ul>
<li><span style="font-size: 12pt;">Create and Consume Buckets</span></li>
<li><span style="font-size: 12pt;">Create Security Credentials</span></li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>The post <a href="https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/">Identity Providers and Access Controls in VCFA 9.1.1 for Native Object Storage</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/16/identity-providers-and-access-controls-in-vcfa-9-1-1-for-native-object-storage/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33117</post-id>	</item>
		<item>
		<title>SQL Server enhancements in Data Services Manager version 9.1.1</title>
		<link>https://cormachogan.com/2026/09/14/sql-server-enhancements-in-data-services-manager-version-9-1-1/</link>
					<comments>https://cormachogan.com/2026/09/14/sql-server-enhancements-in-data-services-manager-version-9-1-1/?noamp=mobile#respond</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 08:13:50 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[Data Services Manager. DSM]]></category>
		<category><![CDATA[MS SQL Server]]></category>
		<category><![CDATA[MS SQL Server for Linux]]></category>
		<category><![CDATA[TDE]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33070</guid>

					<description><![CDATA[<p>VMware introduced support for Microsoft SQL Server as a data service in VMware Data Services Manager version 9.1. In version 9.1.1, there are a number of enhancements, some of which I will highlight in this post. If you want to get the full list of enhancements, check out the VMware Data Services Manager 9.1.1. Release Notes. One of the major changes in version 9.1.1 is to enable the VCF Automation (VCFA) Provider Administrators to provision the SQL Server instances / engines directly from VCFA, rather than context switching back to the DSM UI to do it. Once the SQL Server&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/14/sql-server-enhancements-in-data-services-manager-version-9-1-1/">SQL Server enhancements in Data Services Manager version 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class=" wp-image-30383 alignleft" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>VMware introduced support for Microsoft SQL Server as a data service in VMware Data Services Manager version 9.1. In version 9.1.1, there are a number of enhancements, some of which I will highlight in this post. If you want to get the full list of enhancements, check out the <a href="https://techdocs.broadcom.com/us/en/vmware-cis/dsm/data-services-manager/9-1/release-notes/vmware-data-services-manager-911-release-notes.html" target="_blank" rel="noopener">VMware Data Services Manager 9.1.1. Release Notes.</a> One of the major changes in version 9.1.1 is to enable the VCF Automation (VCFA) Provider Administrators to provision the SQL Server instances / engines directly from VCFA, rather than context switching back to the DSM UI to do it. Once the SQL Server instance is deployed, data service policies can be created to allow the tenant users in different organization to provision SQL Server databases on the SQL Server instances to which their organization has access.</p>
<p style="text-align: justify;">Other enhancements include setting an AD user as the  SQL Server admin rather than a SQL user, and support for gMSA &#8211; Group Managed Service Accounts &#8211; to perform group refreshes and group membership of users. The latter feature is interesting as gMSAs improves security. gMSAs automatically generating complex, 128-character passwords for the account and rotate it automatically every 30 days (by default). Using a gMSA in place of a normal AD account also get automatically granted permissions to manage its own Service Principal Names (SPNs). When the SQL Server engine starts, a gMSA can automatically register and unregister its SPN.</p>
<h2>gMSA Support</h2>
<p style="text-align: justify;">Let&#8217;s look at how to set up a gMSA account during the creation of a SQL Server Instance through VCFA in more detail. This first screenshot shows where to create the SQL Server instances in VCF Automation. When you are logged into VCFA as a Provider Admin, navigate to the VCF Services &gt; Data Services Manager in the navigation toolbar on the left hand side. As you can see, the user experience has changed quite a bit from the previous release, so take some time to familiarise yourself with it.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33071 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=769%2C173&#038;ssl=1" alt="" width="769" height="173" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=1024%2C230&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=300%2C67&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=768%2C173&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=1536%2C346&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?resize=769%2C173&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-create-sql-servers-in-vcfa.png?w=1636&amp;ssl=1 1636w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">During the creation of a new SQL Server instance, you can now select to have a SQL user or an Active Directory user as the SQL Server administrator. If you choose a Windows Principal (AD user), provide the domain name as well as the user name, as shown below.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33072" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?resize=768%2C520&#038;ssl=1" alt="" width="768" height="520" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?w=831&amp;ssl=1 831w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?resize=300%2C203&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?resize=768%2C520&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-AD-user-as-Admin.png?resize=769%2C521&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">In the next section on Active Directory, a gMSA may be selected in place of an AD user account to handle database access. If gMSA is selected, then the AD Account Username must be populated with the gMSA &#8216;SamAccountName&#8217;. In many case, the SamAccountName has a trailing &#8216;$&#8217; sign, and this must be included. gMSAs automatically have privileges to Write Service Principal Names so this field is automatically set to on as is not configurable. You can still use the account to Write DNS Names, but you must ensure that your privileged used added to the gMSA has this privilege in Active Directory.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33073" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?resize=768%2C843&#038;ssl=1" alt="" width="768" height="843" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?w=891&amp;ssl=1 891w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?resize=273%2C300&amp;ssl=1 273w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?resize=768%2C843&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-gMSA.png?resize=769%2C844&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">If you want to test gMSA, here are the steps that I followed to create such as account in my active directory. These were run from a PowerShell window which I had opened with &#8216;Run as Administrator&#8217; privileges:</p>
<h4>1. Check that a Key Distribution Service (KDS) Root Key exists</h4>
<p style="text-align: justify;">Active Directory requires a Key Distribution Service (KDS) Root Key to generate encrypted gMSA passwords. Check to see if one exists. If it does not, you will have to create one.</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>Get-KdsRootKey</strong></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">AttributeOfWrongFormat :</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">KeyValue <span class="Apple-converted-space">              </span>: {74, 163, 251, 83...}</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">EffectiveTime<span class="Apple-converted-space">          </span>: 3/13/2026 11:30:05 PM</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">CreationTime <span class="Apple-converted-space">          </span>: 3/14/2026 9:30:05 AM</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">IsFormatValid<span class="Apple-converted-space">          </span>: True</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">DomainController <span class="Apple-converted-space">      </span>: CN=ARKHAM-DC01,OU=Domain Controllers,DC=arkham,DC=io</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ServerConfiguration<span class="Apple-converted-space">    </span>: Microsoft.KeyDistributionService.Cmdlets.KdsServerConfiguration</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">KeyId<span class="Apple-converted-space">                  </span>: 6b591c9e-7676-59cf-6d44-bb745f0040a0</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">VersionNumber<span class="Apple-converted-space">          </span>: 1</span></pre>
<h4 class="sequence-event-title gds-emphasized-body-l">2. Create a Security Group</h4>
<div class="sequence-event-subtitle gds-extended-caption ng-star-inserted" style="text-align: justify;">First, create an Active Directory security. This group will contain objects allowed to retrieve the gMSA password. The &#8220;`&#8221; allows the PowerShell command to follow-on to the next line.</div>
<div>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>New-ADGroup -Name "CJH-gMSA-Hosts" `
-GroupScope Global -GroupCategory Security</strong></span></pre>
</div>
<h4 class="sequence-event-title gds-emphasized-body-l">3. Create the gMSA Identity</h4>
<p class="ng-star-inserted" style="text-align: justify;">Create the actual gMSA account in Active Directory and assign the group permission to access its credentials. Note that the DNS Hostname can be anything in the following command:</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>New-ADServiceAccount -Name "cjh_sql_gmsa" `
-DNSHostname "cjh_sql_gmsa.arkham.io" `
-PrincipalsAllowedToRetrieveManagedPassword "CJH-gMSA-Hosts"</strong></span></pre>
<h4 style="text-align: justify;">4. Check that it the group managed service account was created successfully:</h4>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>Get-ADServiceAccount -Identity "cjh_sql_gmsa"</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">DistinguishedName : CN=cjh_sql_gmsa,CN=Managed Service Accounts,DC=arkham,DC=io</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Enabled <span class="Apple-converted-space">          </span>: True</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Name<span class="Apple-converted-space">              </span>: cjh_sql_gmsa</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ObjectClass <span class="Apple-converted-space">      </span>: msDS-GroupManagedServiceAccount</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ObjectGUID<span class="Apple-converted-space">        </span>: 890010fb-1b49-47d4-b2dc-552dc64e9bc0</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SamAccountName<span class="Apple-converted-space">    </span>: cjh_sql_gmsa$</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SID <span class="Apple-converted-space">              </span>: S-1-5-21-388335747-1197595944-2956950382-1608</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">UserPrincipalName :</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>(Get-ADServiceAccount -Identity "cjh_sql_gmsa" `
-Properties "msDS-GroupMSAMembership").'msDS-GroupMSAMembership'.access</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ActiveDirectoryRights : GenericAll</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">InheritanceType <span class="Apple-converted-space">      </span>: None</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ObjectType<span class="Apple-converted-space">            </span>: 00000000-0000-0000-0000-000000000000</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">InheritedObjectType <span class="Apple-converted-space">  </span>: 00000000-0000-0000-0000-000000000000</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ObjectFlags <span class="Apple-converted-space">          </span>: None</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">AccessControlType <span class="Apple-converted-space">    </span>: Allow</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">IdentityReference <span class="Apple-converted-space">    </span>: ARKHAM\CJH-gMSA-Hosts</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">IsInherited <span class="Apple-converted-space">          </span>: False</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">InheritanceFlags<span class="Apple-converted-space">      </span>: None</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PropagationFlags<span class="Apple-converted-space">      </span>: None</span></pre>
<h4 class="sequence-event-subtitle gds-extended-caption ng-star-inserted" style="text-align: justify;">5. Add your privileged AD user to the list of Group Members</h4>
<div class="sequence-event-subtitle gds-extended-caption ng-star-inserted" style="text-align: justify;">In my case, my privileged AD user is &#8216;cormac&#8217;. This is the same account that I used to add the Active Directory Domain to DSM so it can be used with SQL Server deployments. This account needs to have many privileges for a range of different tasks. It has to be able to write &#8220;servicePrincipalNames&#8221; for the auto-registration, it needs &#8220;create object/set owner&#8221; for the DNS writes and it needs to read the managed password of a gMSA (which is held as a list on the gMSA). For this managed password privilege, the domain&#8217;s privileges account must be added to that list for every gMSA you create.</div>
<div></div>
<div><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33077 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?resize=769%2C252&#038;ssl=1" alt="" width="769" height="252" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?resize=1024%2C336&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?resize=300%2C98&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?resize=768%2C252&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?resize=769%2C252&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-AD-Config.png?w=1320&amp;ssl=1 1320w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></div>
<div>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>Add-ADGroupMember-Identity "CJH-gMSA-Hosts" -Members "cormac"</strong></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>Get-ADGroupMember-Identity "CJH-gMSA-Hosts"</strong></span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">distinguishedName : CN=cormac,CN=Users,DC=arkham,DC=io</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">name: cormac</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">objectClass : user</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">objectGUID: b5a2bd65-8832-469b-b278-8fa2fa6fcaea</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SamAccountName: cormac</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SID : S-1-5-21-388335747-1197595944-2956950382-1602</span></pre>
</div>
<h4 style="text-align: justify;">6. Test the gMSA.</h4>
<p style="text-align: justify;">This command should return True. If there is a misconfiguration, this should report back the reason why.</p>
<pre class="p1"><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">PS C:\Users\Administrator&gt; <strong>Test-ADServiceAccount -Identity "cjh_sql_gmsa"</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">True</span></pre>
<p style="text-align: justify;">The account is now ready to be used when provisioning SQL Server instances via DSM Manager.</p>
<h2>Encrypted Backup and Transparent Data Encryption</h2>
<p style="text-align: justify;">I already mentioned some of these new SQL Server features in <a href="https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/" target="_blank" rel="noopener">my DSM version 9.1.1 announcement post</a>, but some are worth repeating here as I know a number of customers have requested them. We have now validated Backup Encryption and TDE, Transparent Data Encryption, on DSM provisioned SQL Server databases. Both features are available through the API. Encrypted Backups can be activated by adding a PFX file to the SQL Server instance specification. This PFX (Personal Information Exchange) file is password-protected and contains the SSL/TLS public key certificate and its matching private key. It is added to the <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.certificates</span> of the SQL Server instance, and then referenced via <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.backupEncryptionCertificate</span>. All databases created on the SQL Server instance will now have encrypted backups if this is configured. Note that if you wish to restore an encrypted database to a new SQL Server instance, the same certificate used to encrypt the backup must be imported onto the target SQL Server instance.</p>
<p style="text-align: justify;">Transparent Data Encryption also requires adding a certificate to the specification of the SQL Server instance, <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.certificates</span>, as seen previously. Then, on the user database, the db_owner (database owner) can use TSQL commands to create an encryption key. Finally, the db_owner can turn on encryption by performing ALTER DATABASE .. SET ENCRYPTION ON.</p>
<h2>Summary</h2>
<p style="text-align: justify;">I haven&#8217;t discussed some other important improvements such as support for SQL Server 2025 and on-demand backup for SQL Server databases. However, as mentioned at the outset, you will find the full set of enhancements in the release notes linked above. I am sure you will agree that this release contains plenty of SQL Server enhancements for those customers wishing to provide SQL Server Database as a Service (DBaaS) to their on-premises VMware Cloud Foundation customers.</p>
<p>The post <a href="https://cormachogan.com/2026/09/14/sql-server-enhancements-in-data-services-manager-version-9-1-1/">SQL Server enhancements in Data Services Manager version 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/14/sql-server-enhancements-in-data-services-manager-version-9-1-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33070</post-id>	</item>
		<item>
		<title>Data Services Manager version 9.1.1 Network Security</title>
		<link>https://cormachogan.com/2026/09/10/data-services-manager-version-9-1-1-network-security/</link>
					<comments>https://cormachogan.com/2026/09/10/data-services-manager-version-9-1-1-network-security/?noamp=mobile#respond</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 13:00:55 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[Data Services Manager. DSM]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33047</guid>

					<description><![CDATA[<p>One of the interesting new features of VMware Data Services Manager when it is integrated with VCF automation is the Network Security feature. In a nutshell, what this feature does is implement both distributed firewall rules and gateway firewall rules for each DSM database deployed via VCF Automation. Let&#8217;s take a closer look. By default, Net work Security is disabled. The VCFA Provider Admin will need to activate it. Navigate to VCF Services &#62; Data Services. In the Data Services Manager menu, select Advanced. Here you will find the button to activate Network Security. When the Activate button is clicked,&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/10/data-services-manager-version-9-1-1-network-security/">Data Services Manager version 9.1.1 Network Security</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-30383 " src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>One of the interesting new features of VMware Data Services Manager when it is integrated with VCF automation is the Network Security feature. In a nutshell, what this feature does is implement both distributed firewall rules and gateway firewall rules for each DSM database deployed via VCF Automation. Let&#8217;s take a closer look.</p>
<p style="text-align: justify;">By default, Net work Security is disabled. The VCFA Provider Admin will need to activate it. Navigate to VCF Services &gt; Data Services. In the Data Services Manager menu, select Advanced. Here you will find the button to activate Network Security.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33049 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=769%2C279&#038;ssl=1" alt="" width="769" height="279" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=1024%2C371&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=300%2C109&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=768%2C278&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=1536%2C556&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?resize=769%2C278&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/1.-dsm-net-sec-1.png?w=1751&amp;ssl=1 1751w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">When the Activate button is clicked, a pop-up will appear explaining what Network Security is setting out to do. It is basically going to implement a set of rules so that only the tenant that requested the database is able to access &#8220;from that tenant&#8221;. It cannot be access from any other tenant, or from an external ip address outside of VCF. It will do this by implementing a set of gateway and distributed firewall rules on the dedicated DSM organization where the database instance is instantiated.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33050 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?resize=769%2C284&#038;ssl=1" alt="" width="769" height="284" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?resize=1024%2C378&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?resize=300%2C111&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?resize=768%2C283&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?resize=769%2C284&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/2.-dsm-net-sec-2.png?w=1509&amp;ssl=1 1509w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Now, do note that by default, Transit Gateway (TGW) Firewalls are disabled. Therefore either the DSM Org Admin or the Provider Admin will need to open the DSM Org and enable the Transit Gateway Firewall. A shortcut to this point is to simply click on the &#8220;Manage Rules&#8221; link found in the Advanced View of the Data Services Manager Network Security section show above. If you fail to enable the TGW firewall step, the gateway rules will not be implemented and will be left in an &#8220;In Progress&#8221; state, as shown here:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33051 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=769%2C375&#038;ssl=1" alt="" width="769" height="375" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=1024%2C500&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=300%2C146&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=768%2C375&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=1536%2C750&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?resize=769%2C375&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/3.-dsm-net-gw-off.png?w=1751&amp;ssl=1 1751w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">To turn on the Transit Gateway Firewall, select the Settings tab, select the region and turn the firewall on.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33052 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=769%2C228&#038;ssl=1" alt="" width="769" height="228" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=1024%2C304&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=300%2C89&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=768%2C228&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=1536%2C456&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?resize=769%2C228&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/4.-dsm-net-turn-on-gw.png?w=1737&amp;ssl=1 1737w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Once the Gateway Firewall is enabled, the state should change to Success and any existing DSM provisioned databases should have their ruleset added to the firewalls on the dedicated DSM Org. Below are the transit gateway rules which only allow the configured IP addresses (Supervisor Control Plane VMs and DSM Provider) to communicate to the K8s API server of the database, and only allow the SNAT&#8217;ed IP address of the tenant ORG to communicate to the database port.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33054" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=769%2C348&#038;ssl=1" alt="" width="769" height="348" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=1024%2C464&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=300%2C136&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=768%2C348&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=1536%2C697&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?resize=769%2C349&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/5.-gw-rules.png?w=1755&amp;ssl=1 1755w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">So far, so good. Now let&#8217;s assume that someone outside of that tenant&#8217;s org wishes to access the database. Maybe it is an app running somewhere else on the infrastructure. In that case, all you have to do is to add the External IP Address to the database configuration, as shown here:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33056 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?resize=769%2C621&#038;ssl=1" alt="" width="769" height="621" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?w=1017&amp;ssl=1 1017w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?resize=300%2C242&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?resize=768%2C620&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/7.-extra-clients.png?resize=769%2C621&amp;ssl=1 769w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">And once the database reconciles with the new external client ip address, a new Transit Gateway Rule will be in place to allow the connection to succeed. As shown below, this is added to the list of IP addresses that can access the Postgres database but not the list of IP addresses that are allowed to access the database&#8217;s K8s API server.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33057" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=769%2C293&#038;ssl=1" alt="" width="769" height="293" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=1024%2C390&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=300%2C114&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=768%2C293&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=1536%2C586&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?resize=769%2C293&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/8.-gw-rules-change.png?w=1626&amp;ssl=1 1626w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">And to verify that we can now connect to the database from that IP address, run the following:</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">$ <strong>ip -f inet address show ens33</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">2: ens33: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc mq state UP group default qlen 1000</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">altname enp2s1</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">inet 10.13.10.200/24 brd 10.13.10.255 scope global ens33</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">valid_lft forever preferred_lft forever</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">
$ <strong>psql postgresql://pgadmin:43ux4ZwihNYooae00gUn5404ygLr0R@192.168.21.14:5432/ten2-pgdb</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">psql (16.15 (Ubuntu 16.15-0ubuntu0.24.04.1), server 16.14 (VMware Postgres 16.14.0))</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, compression: off)</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Type "help" for help.</span>

<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ten2-pgdb=# <strong>\c</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">psql (16.15 (Ubuntu 16.15-0ubuntu0.24.04.1), server 16.14 (VMware Postgres 16.14.0))</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, compression: off)</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">You are now connected to database "ten2-pgdb" as user "pgadmin".</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">ten2-pgdb=#</span></pre>
<p style="text-align: justify;">Everything looks good. The rules are allowing me to connect to the database from an external IP address.</p>
<p style="text-align: justify;">A note about remote replication. If remote replication is configured on a database and the read replica and the primary instances are in different regions, you must manually authorise the network for connectivity. Edit the Primary database &#8220;Extra Clients&#8221; field like we did earlier and add the SNAT IP of the organization VPC where the read replica instance is created. Now perform the same action on the read replica database, adding the SNAT IP of the organization VPC where the primary instance was created as an &#8220;Extra Client&#8221;. This will enable data synchronisation and ready it for both read scale out and disaster recovery scenarios.</p>
<p>The post <a href="https://cormachogan.com/2026/09/10/data-services-manager-version-9-1-1-network-security/">Data Services Manager version 9.1.1 Network Security</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/10/data-services-manager-version-9-1-1-network-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33047</post-id>	</item>
		<item>
		<title>A first look at Native Object Storage in VCF 9.1.1</title>
		<link>https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/</link>
					<comments>https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/?noamp=mobile#comments</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 13:00:17 +0000</pubDate>
				<category><![CDATA[Native Object Storage]]></category>
		<category><![CDATA[S3]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[VSAN]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33083</guid>

					<description><![CDATA[<p>Many readers may have read this blog article on Native Object Storage from my good pal, Pete Koehler. In that post, which was published back in May of this year and coincided with the VMware Cloud Foundation (VCF) version 9.1 release, Pete talked about a tech preview of Native Object Storage. Well, with the release of VCF 9.1.1, the tech preview has now begun. Although the tech preview of Native Object Storage is not open to everybody, we will be working with a select set of customers and gathering critical feedback. Our objective is to have a robust Native Object&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/">A first look at Native Object Storage in VCF 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-33151 alignleft" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/native-object-storage.webp?resize=198%2C224&#038;ssl=1" alt="" width="198" height="224" /></a>Many readers may have read <a href="https://blogs.vmware.com/cloud-foundation/2026/05/13/native-s3-compatible-object-storage-in-vmware-vsan-for-vcf-9-1/" target="_blank" rel="noopener">this blog article</a> on Native Object Storage from my good pal, Pete Koehler. In that post, which was published back in May of this year and coincided with the VMware Cloud Foundation (VCF) version 9.1 release, Pete talked about a tech preview of Native Object Storage. Well, with the release of VCF 9.1.1, the tech preview has now begun. Although the tech preview of Native Object Storage is not open to everybody, we will be working with a select set of customers and gathering critical feedback. Our objective is to have a robust Native Object Storage platform when it does become generally available to all our customers. For customers who may not be part of the tech preview, this post should give you an appreciation of how we have integrated Object Storage into VCF.</p>
<p style="text-align: justify;">In this post, I wanted to share some of the setup and initial configuration steps so that you can see what&#8217;s involved. I&#8217;ll show you how a Provider Admin enables Object Storage on their VCF Private Cloud. Next, we will see how either the Provider Admin or the Org Admin creates the Object Stores. Finally, I&#8217;ll take you to the point where tenant users in a VCF Automation organization can begin to provision their own S3 compatible buckets. In a future post, we&#8217;ll look at how a Project Admin can configure access control to the object storage buckets for different project users and assign different levels of privileges to the different project users.</p>
<p style="text-align: justify;">Be aware that by the time the service is generally available, the screenshots shown here may have changed. This post is simply to provide an overview, in the knowledge that the steps may be different in future releases.</p>
<h2>Prep vCenter and ESXi</h2>
<p style="text-align: justify;">For the tech preview, you will need to enable some advanced options on both ESXi and vCenter to enable Object Storage. You won&#8217;t need this step when Native Object Storage is generally available, but for the tech preview, you will need to enable these settings manually.</p>
<h4>1. ESXi &#8211; set /VSAN/VsanVBOSSEnabled to 1</h4>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[root@sfo01-w01-r01-esx01:~] <strong>esxcfg-advcfg -g /VSAN/VsanVBOSSEnabled</strong>
Value of VsanVBOSSEnabled is 0
[root@sfo01-w01-r01-esx01:~] <strong>esxcfg-advcfg -s 1 /VSAN/VsanVBOSSEnabled</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Value of VsanVBOSSEnabled is 1</span></pre>
<h4>2. ESXi &#8211; restart vsanmgmtd</h4>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[root@sfo01-w01-r01-esx01:~] <strong>/etc/init.d/vsanmgmtd restart</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Terminating vsanperfsvc with PID 2561654</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">vsanperfsvc stopped.</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">vsanperfsvc started.</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[root@sfo01-w01-r01-esx01:~] <strong>/etc/init.d/vsanmgmtd status</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">vsanperfsvc is running</span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">[root@sfo01-w01-r01-esx01:~]
</span></pre>
<h4>3. vCenter &#8211; enable Advanced Setting config.vpxd.vsan.vboss.enabled</h4>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33087 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?resize=769%2C430&#038;ssl=1" alt="" width="769" height="430" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?resize=1024%2C572&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?resize=300%2C167&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?resize=768%2C429&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?resize=769%2C429&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.0-enable-vcenter.png?w=1064&amp;ssl=1 1064w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h4>4. vCenter &#8211; restart vsan-health</h4>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">root@sfo-w01-vc01 [ ~ ]# <strong>vmon-cli -r vsan-health</strong></span>
<span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">Completed Restart service request.</span></pre>
<h2>Download &amp; Install Native Object Store Package</h2>
<p style="text-align: justify;">Tech preview customers will be provided with a run-book to step through how to download the necessary Native Object Storage package. You will need a Linux jump host. Once downloaded, the components need to be pushed up to VCF Automation VMSP Platform. Once that step is completed, tech preview customers can proceed with the installation of the Native Object Storage Service.</p>
<p style="text-align: justify;">Note, however, that you will first need to create a Region object in VCF Automation. Native Object Storage is scoped at a region level, and one or more regions need to be selected when Native Object Storage is installed. The following section has some more specifics on Region settings.</p>
<p style="text-align: justify;">To proceed with the installation, the VCFA Provider Admin used a new Native Object Store tile found under Services Management, as shown below. However, this tile is hidden in VCF 9.1.1 and only those customers participating in the tech preview will be provided with the steps to make it visible. Once the backend components for Object Storage are added to VCF, the VCF Automation Service Management tile for Native Object Storage can be used to do the registration and installation of the service at the Supervisor level.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33086" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?resize=769%2C411&#038;ssl=1" alt="" width="769" height="411" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?resize=1024%2C547&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?resize=300%2C160&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?resize=768%2C410&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?resize=769%2C411&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/0.-oss-tile.png?w=1367&amp;ssl=1 1367w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">With Native Object Storage installed, a new supervisor namespace called &#8216;svc-objectstore-xxx&#8217; is created. In this namespace, the Native Object Storage operator is deployed, watching for requests from different VCFA organisations to build object stores.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33090" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?resize=769%2C182&#038;ssl=1" alt="" width="769" height="182" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?resize=1024%2C243&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?resize=300%2C71&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?resize=768%2C182&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?resize=769%2C182&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/5.-oss-controller.png?w=1447&amp;ssl=1 1447w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">The operator has two network services associated with it, compatibility-api and controller manager.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33091" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?resize=769%2C150&#038;ssl=1" alt="" width="769" height="150" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?resize=1024%2C200&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?resize=300%2C59&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?resize=768%2C150&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?resize=769%2C150&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/6.-oss-setup-network.png?w=1449&amp;ssl=1 1449w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Once the install is complete, we can proceed with getting it ready for the tenant organizations.</p>
<h2>VCFA Region Settings</h2>
<p style="text-align: justify;">I mentioned previously that Native Object Storage is scoped at the region level. Thus, at least one region must exist before starting the installation. The region is comprised of one or more Supervisors, backed by one or more vSphere clusters. There must be a vSAN cluster on at least one of the vSphere clusters to enable Native Object Storage. The main item to ensure is selected in the region settings is the vSAN Object Store Policy in the Storage Class settings. This is the storage class which is used to create object store volumes on vSAN, both for the metadata and for the data.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33089 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?resize=769%2C216&#038;ssl=1" alt="" width="769" height="216" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?resize=1024%2C288&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?resize=300%2C84&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?resize=768%2C216&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?resize=769%2C216&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/1.-oss-setup-region-.png?w=1328&amp;ssl=1 1328w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Note that there is no capability to choose which organization gets access to object storage in the 9.1.1 tech preview. If an organization is using a region quota from a region which is scoped to use the Native Object Storage, then that organization has the ability to create an object store.</p>
<p style="text-align: justify;">Also note that if your region is a multi-zone, for example, the Supervisor is backed by multiple vSphere/vSAN clusters, the object store will only provision to the cluster placed in the first zone in the list. Tech Preview does not allow the provisioning of object storages across multiple zones.</p>
<h2>VCFA Organization Settings</h2>
<p style="text-align: justify;">Once we have confirmed that the region does indeed include the vSAN Object Store Policy, we can proceed with the creation of the organizations. The organization region quota includes the vSAN Object Storage Policy.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33092 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?resize=769%2C496&#038;ssl=1" alt="" width="769" height="496" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?resize=1024%2C661&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?resize=300%2C194&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?resize=768%2C496&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?resize=769%2C496&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/2.-org-setup-region-quota.png?w=1319&amp;ssl=1 1319w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">There will probably be many questions about networking when it comes to Native Object Storage. Whilst different configuration are possible, I am going to keep the Object Store and the tenant on the same VPC. When creating this organization, I am selecting a network configuration whereby a number of default configuration items are automatically implemented, including VPC, Transit Gateway (TGW), SNAT and connectivity profile. I will continue to use this default VPC when creating the Object Store, as we will see later.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33093 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?resize=769%2C511&#038;ssl=1" alt="" width="769" height="511" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?resize=1024%2C680&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?resize=300%2C199&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?resize=768%2C510&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?resize=769%2C511&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/3.-oss-org-setup-region-.png?w=1315&amp;ssl=1 1315w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">The final step in the Organization setup is to create a first user. In my case I am creating a first user who has the privileges of an Organisation Administrator. We will use this user later when we log onto the organisation we created.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33095" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?resize=768%2C570&#038;ssl=1" alt="" width="768" height="570" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?w=876&amp;ssl=1 876w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?resize=300%2C223&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?resize=768%2C570&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/4.-org-setup-first-user.png?resize=769%2C571&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">When the Organisation is created, we can launch the Organisation portal directly from the Provider / System organization, automatically connecting to it as the Provider Admin. This approach does have some restrictions. In particular, whilst it should be possible for a Provider Admin to create Object Stores on behalf of organisation users, the Provider Admin should not be able to have access to buckets or bucket contents on the object store.</p>
<h2>Create Object Store</h2>
<p style="text-align: justify;">As the Provider Admin in the tenant Organisation, I can select the Build &amp; Deploy tab, and observe that there is now an Object Storage menu item on the left hand side. Click this should take me to the option of creating an object store, as shown below.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33096 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?resize=769%2C282&#038;ssl=1" alt="" width="769" height="282" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?resize=1024%2C376&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?resize=300%2C110&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?resize=768%2C282&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?resize=769%2C282&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/7.-obj-store-create-1.png?w=1273&amp;ssl=1 1273w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Let&#8217;s look at the information that must be provided when building an object store. Obviously, give the object store a name and select which region it is to be placed. The region quote from this region, which includes the vSAN Object Storage class will be used to place the volumes for the object store. You must select a VPC. In this case, it is the default VPC for the organisation but it could be a completely different VPC if you wish. The VPC must exist before you start the object store create process; it is not possible to create a new VPC in this workflow like we have with namespace creation. Set the size of the object store (100Gb minimum), and decide if you want to enable secure HTTPS access or not to the endpoints. If you do want secure access (recommended), you will need to provide a wildcard certificate (e.g., *.rainpole.io) and a private key to enable secure access on the object store endpoints (IAM and storage). Lastly, select a performance class (resources) for the object store.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33098" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?resize=768%2C884&#038;ssl=1" alt="" width="768" height="884" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?w=830&amp;ssl=1 830w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?resize=261%2C300&amp;ssl=1 261w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?resize=768%2C884&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/8.-obje-store-create-2.png?resize=769%2C885&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">This will initiate the creation of a new Supervisor namespace for the object store, based on the name of the object store. Initially you should observe the &#8216;telegraf&#8217; and the &#8216;config manager&#8217; vSphere pods starting up.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33100" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=769%2C177&#038;ssl=1" alt="" width="769" height="177" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=1024%2C236&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=300%2C69&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=768%2C177&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=1536%2C354&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?resize=769%2C177&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/9.-obj-store-create-backend.png?w=1869&amp;ssl=1 1869w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">After a few moments, this should expand to 5 vSphere pods, and all should enter a running state if no issues are encountered.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33101" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=769%2C189&#038;ssl=1" alt="" width="769" height="189" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=1024%2C252&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=300%2C74&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=768%2C189&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=1536%2C378&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?resize=769%2C189&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/10.-obj-store-backend-running.png?w=1873&amp;ssl=1 1873w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">A number of network services and endpoints for the object store should also be created in the namespace:</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33102" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=769%2C164&#038;ssl=1" alt="" width="769" height="164" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=1024%2C219&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=300%2C64&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=768%2C164&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=1536%2C328&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?resize=769%2C164&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/11.-obj-store-backend-network.png?w=1876&amp;ssl=1 1876w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a>Checking back in VCFA, we should see the object store come online and healthy. Note that the IAM (Identity and Access Management) and storage endpoints should correlate to the LoadBalancer IP address of the Envoy service in the namespace network services view above. You should ensure that the object storage FQDN resolves to that IP address in your DNS.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33103" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=769%2C213&#038;ssl=1" alt="" width="769" height="213" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=1024%2C283&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=300%2C83&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=768%2C212&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=1536%2C425&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?resize=769%2C213&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/12.-obj-store-online.png?w=1645&amp;ssl=1 1645w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">As you are still connected to the organization as the Provider Admin, you can try to connect to the Object Store. You may need to accept the certificates depending on how they were created, and if your browser trusts the Certificate Authority used to build them.</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33104 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?resize=769%2C491&#038;ssl=1" alt="" width="769" height="491" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?resize=1024%2C654&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?resize=300%2C192&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?resize=768%2C490&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?resize=769%2C491&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/13.-connect-to-obj-store.png?w=1234&amp;ssl=1 1234w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a> But even after doing so, you should observe that your Provider Admin is not allowed to see any details regarding how the organization is using the object store. The Provider Admin cannot see any buckets or bucket contents, nor can they see Access Control info or any service accounts. This is by design. Let&#8217;s now try this step as an Org Admin.</p>
<h2>Access Object Store as Org Admin</h2>
<p style="text-align: justify;">Log out as the Provider Admin, change organizations to the tenant organisation where the object store is created and login as the Org Admin using the first user credentials created when the Org was created.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/15.-login-to-tenant-as-admin.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33106 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/15.-login-to-tenant-as-admin.png?resize=400%2C445&#038;ssl=1" alt="" width="400" height="445" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/15.-login-to-tenant-as-admin.png?w=400&amp;ssl=1 400w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/15.-login-to-tenant-as-admin.png?resize=270%2C300&amp;ssl=1 270w" sizes="auto, (max-width: 400px) 100vw, 400px" /></a></p>
<p style="text-align: justify;">Now when we connect, we can see the initial credentials pop up after accepting the certificates. This looks better than previous when we tried to use the Provider Admin to access the object store.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33107 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=769%2C379&#038;ssl=1" alt="" width="769" height="379" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=1024%2C505&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=300%2C148&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=768%2C379&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=1536%2C758&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?resize=769%2C379&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/16.-connect-successful-initial-creds.png?w=1644&amp;ssl=1 1644w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">And finally we are in a position to create buckets and manage access control and additional security credentials to said buckets. In a future post, I will go into more detail regarding access controls, and what access different roles within a project have when it comes to object storage.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33108 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=769%2C357&#038;ssl=1" alt="" width="769" height="357" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=1024%2C475&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=300%2C139&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=768%2C356&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=1536%2C712&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?resize=769%2C357&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/17.-good-to-go.png?w=1643&amp;ssl=1 1643w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Summary</h2>
<p style="text-align: justify;">That completes the post. I hope it has given you an idea of how we have architected Native Object Storage, using vSAN, into VCF version 9.1.1. I will be following up with some additional post to go deeper into some of the aspects here, notably how to control who has access to the buckets from within an organisation. We will also look into some CLI (since Native Object Storage supports the standard S3 API, we can do lots of cool things via tools such as the aws cli, for example). Thanks for reading this far. I am sure you will agree that this is a very interesting feature in VCF 9.1.1.</p>
<p>The post <a href="https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/">A first look at Native Object Storage in VCF 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/08/a-first-look-at-native-object-storage-in-vcf-9-1-1/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33083</post-id>	</item>
		<item>
		<title>Announcing VMware Data Services Manager 9.1.1</title>
		<link>https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/</link>
					<comments>https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/?noamp=mobile#comments</comments>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 13:00:11 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[9.1.1]]></category>
		<category><![CDATA[Data Services Manager. DSM]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33027</guid>

					<description><![CDATA[<p>As part of the latest VMware Cloud Foundation version 9.1.1 release (see this link for more details), it gives me great pleasure to announce that we also have a new 9.1.1 version of VMware Data Services Manager (DSM). This is a not just a patch release. It is a release that is chock-full of new features and enhancements. I will share the details with you in this post. This 9.1.1 DSM release is building on top of some of the cool features that we provided in DSM &#38; VCF version 9.1. In later posts, I will delve into some of&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/">Announcing VMware Data Services Manager 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-30383 " src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>As part of the latest VMware Cloud Foundation version 9.1.1 release (<a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes.html" target="_blank" rel="noopener">see this link for more details</a>), it gives me great pleasure to announce that we also have a new 9.1.1 version of VMware Data Services Manager (DSM). This is a not just a patch release. It is a release that is chock-full of new features and enhancements. I will share the details with you in this post. This 9.1.1 DSM release is building on top of some of the cool features that we provided in DSM &amp; VCF version 9.1. In later posts, I will delve into some of the newer features and enhancements in greater detail.</p>
<h2>Unified DSM Install Experience direct from VCF Automation</h2>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/DSM-Tile-9.1.1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-33029 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/DSM-Tile-9.1.1.png?resize=505%2C422&#038;ssl=1" alt="" width="505" height="422" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/DSM-Tile-9.1.1.png?w=505&amp;ssl=1 505w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/DSM-Tile-9.1.1.png?resize=300%2C251&amp;ssl=1 300w" sizes="auto, (max-width: 505px) 100vw, 505px" /></a>First and foremost, the installation experience for customers integrating their VMware Data Services Manager with VCF Automation (VCFA) has improved dramatically. Those of you who have been following my previous blogs on how to get started with DSM and VCFA will know that a number of context switches were required between different User Interfaces (UIs) &#8211; DSM, vSphere Client and VCFA &#8211; to get up and running. In VCF 9.1.1, Data Services Manager is a first-class VCF Service, so the deployment of DSM can be initiated directly from VCFA. This includes the rollout of the DSM Provider Appliance VM, the Consumption Operator on the Supervisor, connecting to a vCenter Server, setting up an initial DSM Admin account and selecting a dedicated DSM Organization in VCFA. Once the dedicated DSM Org is created, any namespaces created within this dedicated DSM organisation automatically become DSM Infrastructure Policies. This will speed up the deployment process considerably, and make it far easier for VCFA Provider Admins to do an initial setup. The DSM UI can also be launched directly from VCF Automation for additional configuration tasks. Here is a look at the Data Services Manager interface in VCF Automation. You can see additional enhancements such as the ability to create SQL Servers and setup Active Directory Domains directly from VCFA. Policies now represents what were previously called Data Service Policies, and control which organizations are allowed to access data services and their related resources.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33114 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?resize=769%2C324&#038;ssl=1" alt="" width="769" height="324" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?resize=1024%2C432&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?resize=300%2C126&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?resize=768%2C324&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?resize=769%2C324&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/09/dsm-in-vcfa-911.png?w=1402&amp;ssl=1 1402w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Higher Database Availability with Multi-Zone Support</h2>
<p style="text-align: justify;">A Supervisor can contain multiple vSphere Clusters, each of which can be configured as a supervisor zone. Namespaces can now be constructed to span multiple supervisor zones. Namespaces can also be created in the dedicated DSM Organization to be used as infrastructure policies for the provisioning of databases. If a multi-zone namespace-based infrastructure policy is chosen when provisioning a database, the database will be deployed with nodes placed in different zones. This also means that different database objects (e.g., for Postgres, this implies the primary, replica and monitor pods) are placed on different nodes in different zones. The end result is even higher availability for your DSM provisioned databases should a full zone failure occur. I know some customers have been waiting on this feature, so it is nice to see this fully available for DSM and VCF Automation version 9.1.1.</p>
<h2>Support for PostgreSQL version 18</h2>
<p style="text-align: justify;">DSM can now provision databases running PostgreSQL version 18. We have also retired the older PostgreSQL version 13. Our customers can now provision 5 different major versions of PostgreSQL, from version 14 all the way through to version 18.</p>
<h2>Support for additional PostgreSQL Read Replicas</h2>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/read-replica-instance.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-33041 " src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/read-replica-instance.png?resize=318%2C254&#038;ssl=1" alt="" width="318" height="254" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/read-replica-instance.png?w=366&amp;ssl=1 366w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/read-replica-instance.png?resize=300%2C239&amp;ssl=1 300w" sizes="auto, (max-width: 318px) 100vw, 318px" /></a>Although this features has been available in MySQL for some time, DSM version 9.1.1 introduces support to add additional read replicas to PostgreSQL databases. Note some changes in terminology though.  Beginning with version 9.1.1, DSM uses the term read replica instead of secondary to refer to remote PostgreSQL database instances that replicate data from a primary database. Read replicas now serve both disaster recovery and read-scaling use cases. Once Remote Replication is enabled on the PostgreSQL primary database, the same workflow used for DR is now used to enable the creation of additional PostgreSQL read replicas. This workflow is identical to the creation of a secondary database that we saw in prior releases. Once the read replica is created, it can be used by read-only workloads. This is a very useful feature for customers who wish to scale their databases for read intensive workloads.</p>
<h2>Support for SQL Server 2025 &amp; gMSAs</h2>
<p style="text-align: justify;">We announced support for SQL Server 2022 in DSM release 9.1. In this release, we are extending for SQL Server on Linux to include SQL Server 2025, along with recent Cumulative Updates. For VCF Automation customers, the main thing to note is that the SQL Server instance can now be provisioned from VCFA by the Provider Admin. DSM admins no longer need to do the SQL Server instance deployment via the DSM portal. VCFA Organization tenants can continue to provision SQL Server databases as before, so long as their respective Data Service Policy allows their organization to do so. This release also include support for gMSAs (Group Managed Service Accounts). These are domain accounts which are secure by design. They use strong, rotated passwords from Active Directory. These accounts can also manage their own Service Principal Names (SPNs) and allow encrypted network communication (Kerberos) to happen securely.</p>
<h2>Support for SQL Server Native Backup Encryption</h2>
<p style="text-align: justify;">A much sought after feature next. We&#8217;ve heard from customers that they want to be able to encrypt their SQL Server backups. In 9.1.1, this is now available through the API. This feature can be activated by adding a PFX file to the SQL Server instance specification. This PFX (Personal Information Exchange) file is password-protected and contains the SSL/TLS public key certificate and its matching private key. It is added to the <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.certificates</span> of the SQL Server instance, and then referenced via <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.backupEncryptionCertificate</span>. All databases created on the SQL Server instance will now have encrypted backups if this is configured. Note that if you wish to restore an encrypted database to a new SQL Server instance, the same certificate used to encrypt the backup must be imported onto the target SQL Server instance. A nice security feature for your SQL Server databases.</p>
<h2>Support for SQL Server Transparent Data Encryption (TDE)</h2>
<p style="text-align: justify;">Similarly, another security enhancement now available for SQL Server 9.1.1 is database-level encryption which is achieved by enabling Transparent Data Encryption (TDE). This once again requires adding a certificate to the specification of the SQL Server instance, <span style="font-family: 'courier new', courier, monospace;">spec.serverConfig.certificates</span>, as seen previously. Then, on the user database, the database owner can use TSQL commands to create an encryption key. Finally, the db_owner can turn on encryption by performing ALTER DATABASE .. SET ENCRYPTION ON. Another nice security feature for your SQL Server databases.</p>
<h2>Complete Disaster Recovery (DR) workflows in VCFA</h2>
<p style="text-align: justify;">This is something we have been working towards over the past several releases, but in version 9.1.1, I am pleased to say that we have full DSM database Disaster Recovery (DR) workflows plumbed in to VCF Automation. This means that administrators can initiate actions such as &#8220;Block Connections&#8221;, &#8220;Promote&#8221;, &#8220;Demote&#8221; and &#8220;Unblock Connections&#8221; directly from the database context in VCF Automation, and not have to context switch out to the DSM Provider UI to perform these tasks.</p>
<h2>Data Services Manager Network Security</h2>
<p style="text-align: justify;">As you can probably tell, security has been top of mind in this release. Some of these we have seen already, but this one is particularly interesting and applies to all databases. The DSM team has introduced a new network security feature for databases. Once activated, this feature automatically puts in place the necessary NSX gateway firewall rules and distributed firewall rules to ensure that the database is secured. The only ports and communication channels that remain open are a management path between the DSM Provider appliance and the database and a data path from the tenant&#8217;s namespace (the tenant who requested the database to be created) and the database. This feature is located in the Advanced Section of Data Services Manager in the VCF Automation Provider view.</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33030 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=769%2C195&#038;ssl=1" alt="" width="769" height="195" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=1024%2C260&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=300%2C76&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=768%2C195&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=1536%2C390&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?resize=769%2C195&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/08/database-rules-9.1.1.png?w=1580&amp;ssl=1 1580w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">If a client needs to connect to the database from an external IP address (outside of the tenant&#8217;s namespace and organization), then simply add it to the &#8220;Extra IP address&#8221; section of the database configuration. The Network Security features will automatically create the necessary rules to allow this client to connect to the database from the external IP address.</p>
<p style="text-align: justify;">Note that the Advanced view is also where you define the default DSM organization. Any namespaces created in this organization become infrastructure policies for the provisioning of databases.</p>
<h2 style="text-align: justify;">Locking down SSH Access</h2>
<p style="text-align: justify;">Continuing the security theme in DSM 9.1.1, there is no SSH interface to DSM appliance by default when provisioned via VCF Automation. The Provider Admin needs to configure SSH access. This is done by creating a new VirtualMachineService of type Load Balancer for the DSM Appliance. This task is done from the Supervisor using its Kubernetes API. This service must be configured to allow SSH on port 22. The root password is auto-created and stored in a K8s secret. This secret must also be retrieved and decoded. This is part of an ongoing effort to make VMware Data Services Manager more secure.</p>
<h2>PostgreSQL Extensions</h2>
<p style="text-align: justify;">Historically, DSM has always loaded the <span style="font-family: 'courier new', courier, monospace;">pg_stat_statements,</span> <span style="font-family: 'courier new', courier, monospace;">pgaudit</span> and <span style="font-family: 'courier new', courier, monospace;">pg_cron</span> extensions onto its Postgres databases even if customers were not using them. In DSM version 9.1.1, you can now optionally load these libraries using the PostgreSQL shared_preload_libraries mechanism.</p>
<p style="text-align: justify;">Another update in this space is that the <span style="font-family: 'courier new', courier, monospace;">set_user</span> extension is now included in DSM&#8217;s PostgreSQL distributions. This extension allows switching users and optional privilege escalation and adds logging when unprivileged users escalate themselves.</p>
<h2>Additional Metrics Target</h2>
<p style="text-align: justify;">In previous releases, it was possible to set up additional Metrics Targets, either VCF Operations or Prometheus. However, you could only send all metrics to one target, and per-namespace metrics to other target. In this release, it is now possible to send all metrics to multiple targets. The only requirement is that when you configure the metrics targets, they need to have a specific naming convention; the first must be called <strong>metrics-default</strong> and the other <strong>metrics-additional</strong>:</p>
<pre>root@photon-a526d7c1c992 [ ~ ]# kg get metricstargets -A
NAMESPACE    NAME                 STATUS
dsm-system   metrics-additional   Ready
dsm-system   metrics-default      Ready</pre>
<h2>Summary</h2>
<p style="text-align: justify;">As you can see, this is a very impactful release of VMware Data Services Manager. We have closed the gap on providing consistent feature parity for customers no matter which deployment model of DSM is used (standalone or VCFA). We have also added a bunch of new benefits around security and resilience, and also introduced some newer engine versions, reaffirming that VMware Data Services Manager is the best database as a service (DBaaS) solution for VMware Cloud Foundation.</p>
<p>The post <a href="https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/">Announcing VMware Data Services Manager 9.1.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://cormachogan.com/2026/09/04/announcing-vmware-data-services-manager-9-1-1/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33027</post-id>	</item>
		<item>
		<title>Configuring Email Alerts in Data Services Manager version 9.1</title>
		<link>https://cormachogan.com/2026/06/18/configuring-email-alerts-in-data-services-manager-version-9-1/</link>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 13:00:36 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[DSM]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCFA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=33001</guid>

					<description><![CDATA[<p>I was recently asked to assist with some troubleshooting of the Email Alerting mechanism in Data Services Manager (DSM). The first thing to note is that there are different types of alerts that can be raised and emailed in DSM. The first type are Global Alerts, and these are emailed to the DSM Admin. The second type are Database Alerts, and these are emailed to all of the DSM Users (permissions) who are part of the DSM Namespace where the database is provisioned. Those of you familiar with Data Services Manager will know DSM Users are granted permission to provision&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/06/18/configuring-email-alerts-in-data-services-manager-version-9-1/">Configuring Email Alerts in Data Services Manager version 9.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-30383" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>I was recently asked to assist with some troubleshooting of the Email Alerting mechanism in Data Services Manager (DSM). The first thing to note is that there are different types of alerts that can be raised and emailed in DSM. The first type are Global Alerts, and these are emailed to the DSM Admin. The second type are Database Alerts, and these are emailed to all of the DSM Users (permissions) who are part of the DSM Namespace where the database is provisioned. Those of you familiar with Data Services Manager will know DSM Users are granted permission to provision a database by associating the data service in question with a Namespace through a Data Service Policy. The net result is that all DSM Users in that Namespace get a notification if there is an alert raised on the database.</p>
<p style="text-align: justify;">Before looking at the email alerts, it is vitally important to ensure that your SMTP configuration is working correctly. When configuring SMTP in Data Services Manager, an attempt is made to send a test email to the DSM Admin account that is currently logged in to DSM and performing the SMTP configuration. If that DSM login is an LDAP/AD user, DSM attempts to fetch the email address from that LDAP/AD user object using attributes such as <code dir="ltr">mail</code> or <code dir="ltr">rfc822mailbox.</code>If that email address is not configured, the DSM Admin will not receive the test email, and won&#8217;t receive future Global Alert emails either. So ensure this is working first. If you have configured it correctly, as in the example shown here:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33003 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?resize=769%2C341&#038;ssl=1" alt="" width="769" height="341" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?resize=1024%2C454&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?resize=300%2C133&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?resize=768%2C341&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?resize=769%2C341&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Config.png?w=1147&amp;ssl=1 1147w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">You should receive a notification similar to the following:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33004" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?resize=768%2C500&#038;ssl=1" alt="" width="768" height="500" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?w=976&amp;ssl=1 976w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?resize=300%2C195&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?resize=768%2C500&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/DSM-SMTP-Test-Email.png?resize=769%2C501&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Let&#8217;s look at some of those alerts, and their corresponding emails now.</p>
<h2 style="text-align: justify;">Global Alerts</h2>
<p style="text-align: justify;">The full list of Global Alerts can be found in the <a href="https://techdocs.broadcom.com/us/en/vmware-cis/dsm/data-services-manager/9-1/getting-started-with-vmware-data-services-manager/troubleshooting-vmware-data-services-manager/global-alerts-reference.html" target="_blank" rel="noopener">official Data Services Manager documentation</a>. One Global Alert is root password expiry on the DSM appliance. I reproduced that issue to generate the alert and resulting email to the DSM Admin. In fact any user with the role DSM Admin will get the global alert email.</p>
<p style="text-align: justify;">Here is the alert:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33005 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?resize=769%2C77&#038;ssl=1" alt="" width="769" height="77" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?resize=1024%2C103&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?resize=300%2C30&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?resize=768%2C77&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?resize=769%2C77&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/2.-global-alert.png?w=1498&amp;ssl=1 1498w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">And here is the resulting email sent to the DSM Admin(s):</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-33006" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?resize=769%2C455&#038;ssl=1" alt="" width="769" height="455" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?resize=1024%2C606&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?resize=300%2C178&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?resize=768%2C455&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?resize=769%2C455&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/4.-email-alert.png?w=1204&amp;ssl=1 1204w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p>Let&#8217;s now look at the Database Alerts.</p>
<h2>Database Alerts</h2>
<p style="text-align: justify;">As mentioned, Database Alerts go to all DSM Users who have permissions in the namespace where the database is created. One caveat is that the Database Alerts are not going to DSM Admins. This is a caveat that we will address in a future release. It is currently listed as <a href="https://techdocs.broadcom.com/us/en/vmware-cis/dsm/data-services-manager/9-1/release-notes/vmware-data-services-manager-91-release-notes.html#GUID-a4243fd5-c7ce-449e-aaae-9ecb83ef7f77-en_id-164b56a1-7dfb-407b-b042-b0e3b5f45089" target="_blank" rel="noopener">a known issue in the Release Notes</a>.</p>
<p style="text-align: justify;">With that in mind, let&#8217;s look at a typical Database Alert. In this example, I remove access to the backup endpoint (S3 bucket) which meant that the Write Ahead Log (WAL) files for the Postgres database in question could not be written. This causes a Database Alert, Wal file health, as shown here:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33007 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?resize=769%2C242&#038;ssl=1" alt="" width="769" height="242" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?resize=1024%2C322&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?resize=300%2C94&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?resize=768%2C241&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?resize=769%2C242&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-alert.png?w=1393&amp;ssl=1 1393w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p>And this is the email sent to the DSM Users with Permissions in that Namespace:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33008 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email-1024x580.png?resize=769%2C436&#038;ssl=1" alt="" width="769" height="436" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?resize=1024%2C580&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?resize=300%2C170&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?resize=768%2C435&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?resize=1536%2C871&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?resize=769%2C436&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/wal-database-email.png?w=1632&amp;ssl=1 1632w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Additional Alert Email Recipients</h2>
<p style="text-align: justify;">There may be other users who are not part of the DSM Users who might need to receive Database Alerts as well. This can be done manually in the DSM UI by navigating to the database in question, selecting the Monitor tab, selecting Notifications and then Editing the Alert Email Notification section and adding a comma-separated list of email addresses. The email that is sent to DSM Users when an database alert occurs, as shown above, will also be sent to these users. Here is an example of where to add the additional emails:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/manual-add-email-db-alerts.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-33009 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/manual-add-email-db-alerts.png?resize=673%2C460&#038;ssl=1" alt="" width="673" height="460" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/manual-add-email-db-alerts.png?w=673&amp;ssl=1 673w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/06/manual-add-email-db-alerts.png?resize=300%2C205&amp;ssl=1 300w" sizes="auto, (max-width: 673px) 100vw, 673px" /></a></p>
<p style="text-align: justify;">In the Notifications section shown above, you will see the Auto Subscribed Namespace reference. This is how DSM Users which have their permissions associated with a namespace are discovered, and so have the Database Alerts sent to their respective emails. But for VCF Automation, those Supervisor namespace where the databases are provisioned do not have any DSM Users associated. Thus, Database Alerts from databases provisioned in VCF Automation are not sent to any users automatically, not even the VCFA organization users who have been assigned to the Project where the namespaces are created. Thus, to have users receive VCFA provisioned database alerts via email notifications, add those users to the Additional Alert Email Recipients section shown above. Unfortunately, there is no public API to automate this task at the time of writing, so the process is manual for now. The DSM team are working to address both of these limitations.</p>
<h2>Summary</h2>
<p style="text-align: justify;">I hope this has gone some way towards explaining the different alert types, and how they are sent to email addresses of the different personas within DSM. The important part in all of this is ensuring that the DSM Admins and DSM Users have their emails configured correctly, especially if the users are LDAP or Active Directory users &#8211; make sure that the test email is working before looking for any other emails! And if you are a VCF Automation user, database alerts email notifications can be configured via the DSM UI, adding the recipients email address to the appropriate databases.</p>
<p>The post <a href="https://cormachogan.com/2026/06/18/configuring-email-alerts-in-data-services-manager-version-9-1/">Configuring Email Alerts in Data Services Manager version 9.1</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33001</post-id>	</item>
		<item>
		<title>Using SQL Server Management Pack in VCF Operations with DSM provisioned SQL Server</title>
		<link>https://cormachogan.com/2026/05/21/using-sql-server-management-pack-in-vcf-operations-with-dsm-provisioned-sql-server/</link>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Thu, 21 May 2026 13:00:47 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[VCF Operations]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[DSM]]></category>
		<category><![CDATA[Microsoft SQL Server]]></category>
		<category><![CDATA[Microsoft SQL Server Management Pack]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCF 9.1]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=32967</guid>

					<description><![CDATA[<p>Many of my recent posts have focused on the new Microsoft SQL Server data service in the 9.1 version of VMware Data Services Manager (DSM). On the back of those posts, I had a query about whether it was possible to use the Microsoft SQL Server Management Pack for VCF Operations that is available on the  VCF Solutions Catalog with DSM provisioned SQL Servers. The short answer is yes, you can install this management pack in your VCF Operations and create a SQL Server account for it. The Management Pack for Microsoft SQL Server now connects to your Microsoft SQL&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/05/21/using-sql-server-management-pack-in-vcf-operations-with-dsm-provisioned-sql-server/">Using SQL Server Management Pack in VCF Operations with DSM provisioned SQL Server</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-30383 " src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>Many of <a href="https://cormachogan.com/dsm-data-services-manager/" target="_blank" rel="noopener">my recent posts</a> have focused on the new Microsoft SQL Server data service in the 9.1 version of VMware Data Services Manager (DSM). On the back of those posts, I had a query about whether it was possible to use the Microsoft SQL Server Management Pack for VCF Operations that is available on the  VCF Solutions Catalog with DSM provisioned SQL Servers. The short answer is yes, you can install this management pack in your VCF Operations and create a SQL Server account for it. The Management Pack for Microsoft SQL Server now connects to your Microsoft SQL Server instance (via JDBC using the jTDS driver) and executes SQL queries. SQL queries are executed in order to import health, performance, availability, capacity, and relationships data for your SQL server resources into VCF Operations. This allows your DBAs or IT team to gain critical actionable insight into <strong>database performance, query designs, and queries</strong> with access to <strong>250+ collected metrics, reports, dashboards, notifications, and alerts</strong> in the VCF Operations console. This will allow your DBAs to clearly understand how workloads are performing, where issues may occur, and their source. It will help them to write better queries and optimize query designs for faster information retrieval and reporting. Let&#8217;s see how to install it.</p>
<h2>Download the SQL Server Management Pack</h2>
<p style="text-align: justify;">In VCF Operations, select Administration &gt; Integrations &gt; Solutions Catalog. The database management packs are not available by default. You will need to download them from the VCF Solutions Catalog.  You can navigate to the VCF Solutions Catalog directly from VCF operations, or you can get to it from <a class="external-link" href="https://vcf.broadcom.com/vsc/services">https://vcf.broadcom.com/vsc/services</a>. Browse the Management Packs. Here you will find the Management Pack for SQL Server. You will need to sign in to download it. You will also have to create a &#8220;Signing Key&#8221; and then provide this when you install the Management Pack into VCF Operations. The latest version of the SQL Server Management Pack at the time of writing is 9.0.0.0100.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32969 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=769%2C350&#038;ssl=1" alt="" width="769" height="350" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=1024%2C466&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=300%2C136&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=768%2C349&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=1536%2C699&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?resize=769%2C350&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/vcf-catalog.png?w=1913&amp;ssl=1 1913w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h3 id="VCFOPs9.1SQLServerManagementPackInstallation-Step2:UploadSQLServerMgmtPacktoVCFOps" class="p2">Install SQL Server Management Pack</h3>
<p class="p2" style="text-align: justify;">In VCF Operations, select Operate / Integrations &gt; Solutions Catalog. You can see the downloaded management packs from there, as shown below. Once the management pack is downloaded into the catalog, <strong>install</strong> it. You will be prompted for the &#8220;Signing Key&#8221; created earlier as part of the install.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32970 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=769%2C260&#038;ssl=1" alt="" width="769" height="260" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=1024%2C346&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=300%2C101&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=768%2C259&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=1536%2C519&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?resize=769%2C260&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/VCF-Ops-9.1-Mgmt-Packs.png?w=1610&amp;ssl=1 1610w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2 class="p2">Create SQL Server Account</h2>
<p style="text-align: justify;">Microsoft SQL Server now appears as an available account type after the management pack has been successfully installed in your VCF Operations.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32971 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=769%2C213&#038;ssl=1" alt="" width="769" height="213" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=1024%2C283&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=300%2C83&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=768%2C212&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=1536%2C424&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?resize=769%2C212&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Add-Account.png?w=1912&amp;ssl=1 1912w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Add a SQL Server account. Provide the necessary information to connect to the SQL Server instance in the account. I am using the <strong>mssql-admin</strong> credentials that DSM created for the instance.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32972" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?resize=768%2C913&#038;ssl=1" alt="" width="768" height="913" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?w=844&amp;ssl=1 844w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?resize=252%2C300&amp;ssl=1 252w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?resize=768%2C913&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Adv-Settings.png?resize=769%2C914&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Validate the Connection as a test:</p>
<p class="p2"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32973" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?resize=768%2C432&#038;ssl=1" alt="" width="768" height="432" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?w=1005&amp;ssl=1 1005w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?resize=768%2C432&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Test-Connectivity.png?resize=769%2C432&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p class="p2" style="text-align: justify;">Soon after adding the account, you should see data getting collected from the SQL Server.</p>
<p class="p2"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32974 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=769%2C198&#038;ssl=1" alt="" width="769" height="198" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=1024%2C263&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=300%2C77&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=768%2C197&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=1536%2C394&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?resize=769%2C197&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/MSSQL-Collecting.png?w=1691&amp;ssl=1 1691w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Examine the SQL Server Dashboards</h2>
<p style="text-align: justify;">The SQL Server Management Pack includes some very useful dashboards &#8216;out of the box&#8217;. Navigate to dashboards in VCF Operations where you should see MS SQL Server metrics now displayed. This first one details the Query metrics.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32975 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=769%2C298&#038;ssl=1" alt="" width="769" height="298" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=1024%2C397&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=300%2C116&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=768%2C298&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=1536%2C596&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=2048%2C795&amp;ssl=1 2048w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash1.png?resize=769%2C299&amp;ssl=1 769w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p class="p2">You can also drill down into database specific resource consumption:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32976 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?resize=769%2C547&#038;ssl=1" alt="" width="769" height="547" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?resize=1024%2C728&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?resize=300%2C213&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?resize=768%2C546&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?resize=769%2C547&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash2.png?w=1535&amp;ssl=1 1535w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Note that on the initial install of the management pack, and the initial view of the dashboards, the Microsoft SQL Server dashboard was empty in my environment. It did not show any SQL Server instances. I therefore edited the dashboard to see what the inputs were. The inventory tree was correctly set to MS SQL Server Environment but there were no Objects. After adding the SQL Server instances to the Input data Objects as shown here, and saving the changes to the dashboard, everything started to work (this step may not be necessary in your environments, as the second time I tested the management pack installation and account creation, the Objects auto-filled correctly):</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32977" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?resize=768%2C534&#038;ssl=1" alt="" width="768" height="534" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?w=872&amp;ssl=1 872w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?resize=300%2C208&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?resize=768%2C534&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/widget-edit.png?resize=769%2C534&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Now the SQL Server instances are visible in the dashboard and can be selected to get more details on the deployment. To get this view, single click on the instance to open the interaction menu, and then select the internal view. The other item takes you back to the Query dashboard seen earlier.</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?ssl=1" target="_blank" rel="noopener"><br />
<img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32978 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=769%2C430&#038;ssl=1" alt="" width="769" height="430" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=1024%2C573&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=300%2C168&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=768%2C429&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=1536%2C859&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?resize=769%2C430&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/mssql-dash3.png?w=1658&amp;ssl=1 1658w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">This is a really nice dashboard to have because once you have selected the instance and database, you can begin to examine metrics like Longest Wait Types, which are essentially the internal indicators that record why a query thread has paused execution and what specific resource it is waiting for.</p>
<p style="text-align: justify;">One final note &#8211; there does appear to be some discrepancy in building relationships between the VMs and the SQL Server database nodes. This can  be seen in the Related Objects window of the final screenshot above. If VCF Operations is unable to resolve the SQL Server node name, then the relationships are not built in this version of the management pack 9.0.0.0100.  In the adapter logs, located on the VCF Ops 9.1 appliance in <span style="font-family: 'courier new', courier, monospace; font-size: 10pt;">/storage/log/vcops/log/adapters/MicrosoftSQLServerAdapter</span>, the logs will show the following:</p>
<pre role="code">Failed to add VirtualMachine resource with hostname "msql-vcfa-instance1-2" as parent of SqlAvailabilityGroup 
resource with name "DSMAG": Failed to create relationship with VM names ("msql-vcfa-instance1-2")</pre>
<p style="text-align: justify;">The reason is that the SQL Server nodename <strong>msql-vcfa-instance-2</strong> may not be the same as the hostname of the virtual machine/OS. In my case, the hostname of the VM was <strong>msql-vcfa-instance1-398432-4z2fl-czs9p </strong>as shown in the vCenter inventory. So this is why it cannot resolve, and why it cannot create the relationships. Basically, VCF Operations needs to be able to resolve the nodename of the SQL Server. A work-around is to simply add an alias in DNS for the SQL server nodename alongside the VM hostname, (i.e., have entries for both msql-vcfa-instance-2 and msql-vcfa-instance1-398432-4z2fl-czs9p in DNS pointing to the same IP address). This should allow the relationship between VM/OS hostname (plus other vSphere infra) and the SQL Server nodename to work, and the Relationship Objects view should reveal far more detail:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32991 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?resize=769%2C457&#038;ssl=1" alt="" width="769" height="457" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?resize=1024%2C609&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?resize=300%2C178&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?resize=768%2C457&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?resize=769%2C457&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/related-objects.png?w=1165&amp;ssl=1 1165w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">For further information on the SQL Server Management Pack, check out some of the official documentation <a href="https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations-for-integrations/management-packs/copy-of-getting-started-with-management-packs-for-vrealize-operations-management-packs/list-of-integrations.html" target="_blank" rel="noopener">here</a> and <a href="https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations-for-integrations/9-1/management-pack-for-microsoft-sql-server-9-1/management-pack-for-microsoft-sql-server.html" target="_blank" rel="noopener">here</a>.</p>
<p>The post <a href="https://cormachogan.com/2026/05/21/using-sql-server-management-pack-in-vcf-operations-with-dsm-provisioned-sql-server/">Using SQL Server Management Pack in VCF Operations with DSM provisioned SQL Server</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32967</post-id>	</item>
		<item>
		<title>Using VCF Automation 9.1 Blueprints to snapshot and clone DSM provisioned MySQL databases</title>
		<link>https://cormachogan.com/2026/05/19/using-vcf-automation-9-1-blueprints-to-snapshot-and-clone-dsm-provisioned-mysql-databases/</link>
		
		<dc:creator><![CDATA[Cormac]]></dc:creator>
		<pubDate>Tue, 19 May 2026 13:00:08 +0000</pubDate>
				<category><![CDATA[Data Services Manager]]></category>
		<category><![CDATA[snapshots]]></category>
		<category><![CDATA[VCF Automation]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Cloud Foundation (VCF)]]></category>
		<category><![CDATA[VSAN]]></category>
		<category><![CDATA[vSphere]]></category>
		<category><![CDATA[Data Service Manager]]></category>
		<category><![CDATA[DSM]]></category>
		<category><![CDATA[DSM 9.1]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[VCF]]></category>
		<category><![CDATA[VCF 9.1]]></category>
		<category><![CDATA[VCFA]]></category>
		<category><![CDATA[vSAN ESA]]></category>
		<guid isPermaLink="false">https://cormachogan.com/?p=32930</guid>

					<description><![CDATA[<p>In my VMware Data Services Manager 9.1 launch post, I mentioned that this release now has the ability to use vSAN ESA snapshots to create a copy of a MySQL database. I also mentioned that this snapshot could then be used to very quickly spin up additional copies of the database using the &#8220;clone from snapshot&#8221; feature. I also mentioned that this feature is not yet plumbed up into the VCF Automation UI, but that it is available via the API. And since that is the case, it is then possible to go ahead and create VCF Automation blueprint. The&#8230;</p>
<p>The post <a href="https://cormachogan.com/2026/05/19/using-vcf-automation-9-1-blueprints-to-snapshot-and-clone-dsm-provisioned-mysql-databases/">Using VCF Automation 9.1 Blueprints to snapshot and clone DSM provisioned MySQL databases</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class=" wp-image-30383 alignleft" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=151%2C122&#038;ssl=1" alt="" width="151" height="122" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=1024%2C831&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=300%2C244&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=768%2C623&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?resize=769%2C624&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2023/01/dsm-logo-icon.png?w=1386&amp;ssl=1 1386w" sizes="auto, (max-width: 151px) 100vw, 151px" /></a>In my <a href="https://cormachogan.com/2026/05/07/announcing-data-services-manager-version-9-1/" target="_blank" rel="noopener">VMware Data Services Manager 9.1 launch post</a>, I mentioned that this release now has the ability to use vSAN ESA snapshots to create a copy of a MySQL database. I also mentioned that this snapshot could then be used to very quickly spin up additional copies of the database using the &#8220;clone from snapshot&#8221; feature. I also mentioned that this feature is not yet plumbed up into the VCF Automation UI, but that it is available via the API. And since that is the case, it is then possible to go ahead and create VCF Automation blueprint. The blueprint can be made to request information from the user about the MySQL database that is to be snapshot&#8217;ed. And using this information, another blueprint could be created to clone a new MySQL database from this snapshot. In this blog post, I will show you how to do exactly that.</p>
<p style="text-align: justify;">First, you will need some simple scripts to get you started. If you are unfamiliar with blueprints, feel free to download some of my simple examples from <a href="https://github.com/cormachogan/vcfa-blueprints" target="_blank" rel="noopener">my GitHub repo here</a>. The blueprints that I will use in this post are the &#8220;create-mysql-snpshot.blp&#8221; and &#8220;create-mysql-from-snap.blp&#8221;.</p>
<p style="text-align: justify;">Next, we should discuss the personas that can be granted to VCF Automation Organization users. We have Project Admins, Project Advanced Users and Project Users. Only the Project Admins can do Blueprint designs. Project Advanced Users and Project Users do not have access to blueprint designs, but both can consume request blueprints from the catalog. These are the users in my organization:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32933 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=769%2C258&#038;ssl=1" alt="" width="769" height="258" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=1024%2C343&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=300%2C100&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=768%2C257&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=1536%2C514&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?resize=769%2C257&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/1.org-users-and-personas.png?w=1670&amp;ssl=1 1670w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Create MySQL Snapshot</h2>
<p style="text-align: justify;">Let&#8217;s start by creating the snapshot of an existing MySQL database. I will login to the organization as user &#8216;cormac&#8217; who is a project admin. Under Build &amp; Deploy, select Content Hub &gt; Blueprint Design. From the Blueprints &gt; &#8220;New From&#8221; dropdown, we can begin to import the blueprints downloaded from the GitHub repo mentioned earlier.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32935 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=769%2C235&#038;ssl=1" alt="" width="769" height="235" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=1024%2C313&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=300%2C92&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=768%2C234&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=1536%2C469&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?resize=769%2C235&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/3.-blp-import.png?w=1671&amp;ssl=1 1671w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Next, provide general information about the blueprint. Select the name, optional description, project, whether to share the blueprint with other projects in the organization, upload the downloaded blueprint, and optionally select an icon for the catalog item.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32936 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?resize=769%2C517&#038;ssl=1" alt="" width="769" height="517" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?resize=1024%2C688&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?resize=300%2C202&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?resize=768%2C516&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?resize=769%2C517&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/4.-general-settings.png?w=1143&amp;ssl=1 1143w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">The blueprint should now be visible.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32937 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=769%2C222&#038;ssl=1" alt="" width="769" height="222" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=1024%2C295&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=300%2C86&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=768%2C221&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=1536%2C442&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?resize=769%2C221&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/5.-blueprint-uploaded.png?w=1672&amp;ssl=1 1672w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">You can now begin to modify the blueprint to match your own environment. Click on the name of the blueprint to enter &#8216;edit&#8217; mode:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32938 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit-1024x597.png?resize=769%2C448&#038;ssl=1" alt="" width="769" height="448" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?resize=1024%2C597&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?resize=300%2C175&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?resize=768%2C448&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?resize=1536%2C896&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?resize=769%2C449&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/6.-blueprint-edit.png?w=1670&amp;ssl=1 1670w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">There are two sections to the blueprint code. First, you are setting up your inputs which will be used to prompt the user to provide information about the MySQL database to snapshot. The second is actually the piece of YAML code which matches the object your are trying to create. For us, this is a MySQL snapshot as defined in the DSM API. You can now fine-tune the code, correcting namespace names and other default values. When you are happy with the code, click on the &#8216;TEST&#8217; button in the lower left hand corner of the screen. This will launch the blueprint but will only check syntax &#8211; it does not do an actual test.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/7.-blueprint-test.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32939 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/7.-blueprint-test.png?resize=567%2C358&#038;ssl=1" alt="" width="567" height="358" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/7.-blueprint-test.png?w=567&amp;ssl=1 567w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/7.-blueprint-test.png?resize=300%2C189&amp;ssl=1 300w" sizes="auto, (max-width: 567px) 100vw, 567px" /></a></p>
<p style="text-align: justify;">If the test is successful, it will report back something similar to the following:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/8.-successful-blueprint-test.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32940 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/8.-successful-blueprint-test.png?resize=601%2C155&#038;ssl=1" alt="" width="601" height="155" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/8.-successful-blueprint-test.png?w=601&amp;ssl=1 601w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/8.-successful-blueprint-test.png?resize=300%2C77&amp;ssl=1 300w" sizes="auto, (max-width: 601px) 100vw, 601px" /></a></p>
<p style="text-align: justify;">To add the blueprint to the catalog, click on the VERSION button, and add a description, a change log and check the box to publish the blueprint to the catalog. Now, navigate to the Catalog in the left hand navigation menu, and the item should be available.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32941 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?resize=769%2C322&#038;ssl=1" alt="" width="769" height="322" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?resize=1024%2C429&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?resize=300%2C126&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?resize=768%2C322&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?resize=769%2C322&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/9.-catalog-item.png?w=1356&amp;ssl=1 1356w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Now you can request a deployment of the catalog item. A deployment name is needed so the request can be identified in the instances view. The other items relate to the Supervisor namespace where the MySQL database is deployed from, the name of the database and the name of the snapshot that you wish to create:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32943" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?resize=768%2C880&#038;ssl=1" alt="" width="768" height="880" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?w=845&amp;ssl=1 845w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?resize=262%2C300&amp;ssl=1 262w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?resize=768%2C880&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/10.-request-snapshot.png?resize=769%2C881&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Click Submit, and the name of the deployment will be displayed as in progress. If you then click on the name of the deployment (demo), and then the History view, you should be able to observer various events occurring as the snapshot is getting created. This is also a good place to check if the snapshot creation fails as it should report which part of the job the snapshot failed at.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32945 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=769%2C455&#038;ssl=1" alt="" width="769" height="455" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=1024%2C606&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=300%2C178&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=768%2C455&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=1536%2C910&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?resize=769%2C455&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/11.-snapshot-in-progress.png?w=1670&amp;ssl=1 1670w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Tasks will also be visible in the vSphere client as the snapshot is getting provisioned.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32946 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?resize=769%2C141&#038;ssl=1" alt="" width="769" height="141" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?resize=1024%2C188&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?resize=300%2C55&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?resize=768%2C141&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?resize=769%2C141&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/12.-vsphere-snapshot-tasks.png?w=1341&amp;ssl=1 1341w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Eventually, you should be able to observe that the request completed successfully and that the blueprint has been able to take a snapshot of an existing MySQL database.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-large wp-image-32947" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=769%2C326&#038;ssl=1" alt="" width="769" height="326" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=1024%2C434&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=300%2C127&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=768%2C326&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=1536%2C651&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?resize=769%2C326&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/13.-snapshot-completed.png?w=1649&amp;ssl=1 1649w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">It is also possible to check on the snapshot through the API or by logging into the DSM appliance as the root user and running the following command (kg is an alias for <em>kubectl</em> which points to the gateway KUBECONFIG):</p>
<pre><span style="font-family: 'courier new', courier, monospace; font-size: 12pt;"># <strong>kg get mysqlsnapshots -n b03cde-tenant-02-ns-01-5wtsk</strong> 
NAME                 CLUSTERNAME    STATUS   CREATED 
mysql-db01-snap-01   mysql-db01     Ready    24m</span></pre>
<h2>Clone MySQL Snapshot to new database</h2>
<p style="text-align: justify;">We can now start to look at the second part of the post, which is how to clone a snapshot to create a new MySQL database. Once more, we can begin by importing an existing blueprint to do the clone operation. This can once again be retrieved from <a href="https://github.com/cormachogan/vcfa-blueprints" target="_blank" rel="noopener">my GitHub repo</a>, and the process is identical to before.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32949 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?resize=769%2C518&#038;ssl=1" alt="" width="769" height="518" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?resize=1024%2C690&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?resize=300%2C202&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?resize=768%2C517&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?resize=769%2C518&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/14.-import-new-bp.png?w=1139&amp;ssl=1 1139w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Fine tune any code, and the default values to match your own environment. Again, items such as namespaces will need to be changed to reflect your setup. the only inputs this time are the name of the new database and the name of the snapshot. Many of the other parameters simply relate to the information that one would need to provide when creating a MySQL database. But you can tune the code for all of these entries. Use the TEST button once again to make sure that the fields are populating as expected.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/15.-test-clone.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32950 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/15.-test-clone.png?resize=568%2C615&#038;ssl=1" alt="" width="568" height="615" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/15.-test-clone.png?w=568&amp;ssl=1 568w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/15.-test-clone.png?resize=277%2C300&amp;ssl=1 277w" sizes="auto, (max-width: 568px) 100vw, 568px" /></a></p>
<p style="text-align: justify;">Use the VERSION button to upload a copy of the blueprint to the catalog when you are happy with the code and the tests are successful.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/16.-Version.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32951 size-full" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/16.-Version.png?resize=567%2C493&#038;ssl=1" alt="" width="567" height="493" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/16.-Version.png?w=567&amp;ssl=1 567w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/16.-Version.png?resize=300%2C261&amp;ssl=1 300w" sizes="auto, (max-width: 567px) 100vw, 567px" /></a></p>
<p style="text-align: justify;">Verify the item appears in the catalog alongside our snapshot entry:</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32952 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?resize=769%2C428&#038;ssl=1" alt="" width="769" height="428" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?resize=1024%2C570&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?resize=300%2C167&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?resize=768%2C427&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?resize=769%2C428&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/17.-updated-catalog.png?w=1321&amp;ssl=1 1321w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<p style="text-align: justify;">Once added to the catalog, you can make a request to clone a new MySQL database from an existing snapshot.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32953" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?resize=768%2C819&#038;ssl=1" alt="" width="768" height="819" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?w=906&amp;ssl=1 906w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?resize=281%2C300&amp;ssl=1 281w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?resize=768%2C819&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/18.-clone-request.png?resize=769%2C820&amp;ssl=1 769w" sizes="auto, (max-width: 768px) 100vw, 768px" /></a></p>
<p style="text-align: justify;">Again, you can monitor the clone request in the same way as you monitored the snapshot request. In fact, this can also be monitored from the DSM UI if you wish.</p>
<p style="text-align: justify;"><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32954 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=769%2C199&#038;ssl=1" alt="" width="769" height="199" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=1024%2C265&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=300%2C78&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=768%2C199&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=1536%2C398&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?resize=769%2C199&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/19.-monitor-clone-request.png?w=1652&amp;ssl=1 1652w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a>And if everything has gone smoothly, you can click on the deployment (clone-demo) to get further details, similar to what we saw with the snapshot. The new database should also be Ready under the Databases view in the tenant&#8217;s namespace, as shown below. The original database which the snapshot was taken from is also visible in this view.</p>
<p><a href="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?ssl=1" target="_blank" rel="noopener"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-32955 size-large" src="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=769%2C207&#038;ssl=1" alt="" width="769" height="207" srcset="https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=1024%2C275&amp;ssl=1 1024w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=300%2C81&amp;ssl=1 300w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=768%2C206&amp;ssl=1 768w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=1536%2C412&amp;ssl=1 1536w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?resize=769%2C206&amp;ssl=1 769w, https://i0.wp.com/cormachogan.com/wp-content/uploads/2026/05/20.-mysql-clone-form-snap-success.png?w=1650&amp;ssl=1 1650w" sizes="auto, (max-width: 769px) 100vw, 769px" /></a></p>
<h2>Summary</h2>
<p style="text-align: justify;">In Data Services Manager version 9.1, MySQL databases can now leverage the the new snapshot capability in vSAN ESA. Although not available for selection direction in the VCF Automation UI, the blueprint feature allows project admin users to create catalog items which can then be requested by other project users.</p>
<p style="text-align: justify;">Now, you might be thinking that this is all well and good, but it needs vSAN. You would be correct. But have you considered using your existing certified ESX hosts as vSAN ESA nodes by adding NVMe devices? Were you aware that you could do this? If so, and you were planning to do so, we would like to hear from you. Even if you&#8217;re not, we would still like to hear from you. You will find <a href="https://forms.gle/Z911Qz4y9uZASXFM8" target="_blank" rel="noopener">a short survey link here</a>.</p>
<p>The post <a href="https://cormachogan.com/2026/05/19/using-vcf-automation-9-1-blueprints-to-snapshot-and-clone-dsm-provisioned-mysql-databases/">Using VCF Automation 9.1 Blueprints to snapshot and clone DSM provisioned MySQL databases</a> appeared first on <a href="https://cormachogan.com">CormacHogan.com</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32930</post-id>	</item>
	</channel>
</rss>
