惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
H
Heimdal Security Blog
罗磊的独立博客
B
Blog RSS Feed
WordPress大学
WordPress大学
The Register - Security
The Register - Security
N
Netflix TechBlog - Medium
美团技术团队
量子位
GbyAI
GbyAI
Recent Announcements
Recent Announcements
博客园 - 叶小钗
D
DataBreaches.Net
S
SegmentFault 最新的问题
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Troy Hunt's Blog
The Last Watchdog
The Last Watchdog
O
OpenAI News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
Webroot Blog
Webroot Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
V
V2EX
N
News and Events Feed by Topic
Jina AI
Jina AI
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
IT之家
IT之家
C
Check Point Blog
H
Hacker News: Front Page
爱范儿
爱范儿
Schneier on Security
Schneier on Security
Apple Machine Learning Research
Apple Machine Learning Research
P
Privacy & Cybersecurity Law Blog
L
LINUX DO - 最新话题
Forbes - Security
Forbes - Security
人人都是产品经理
人人都是产品经理
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Microsoft Azure Blog
Microsoft Azure Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Secure Thoughts
The Cloudflare Blog
Simon Willison's Weblog
Simon Willison's Weblog
Stack Overflow Blog
Stack Overflow Blog
腾讯CDC
MongoDB | Blog
MongoDB | Blog
V2EX - 技术
V2EX - 技术
AI
AI

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1 Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Simpler VPC Connectivity Control VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend VMware vSAN Protection and Recovery Enhancements for VCF 9.1 Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs What’s New with vSphere in VMware Cloud Foundation 9.1? Resizing VMware vCenter in VMware Cloud Foundation 9 Non-Disruptive VMware vCenter Patching in VMware Cloud Foundation 9.1 VMware vCenter Virtual Hardware Gets an Upgrade in vSphere with VCF 9.1 AI Has Changed the Threat Landscape. Is Your Infrastructure Ready? Simplifying Storage with the New Effective Capacity View in VMware vSAN for VCF 9.1 Auto-RAID in VMware vSAN for VCF 9.1 – Comprehensive System-Managed Data Resilience Introducing VMmark 4.1: Enhanced Power Efficiency Benchmarking for Private Cloud Infrastructure Advanced Memory Tiering Enhancements in VMware Cloud Foundation 9.1 VCF 9.1 Is Here. See It in Action. 博通發布 VMware Cloud Foundation 9.1 How Broadcom Is Helping Enterprises Win the AI Security Sprint How to Prepare for the World of AI Driven Exploits Avi Innovations for VCF 9.1: Powering Kubernetes, Agentic AI and VPC Workloads VCF 9.1: The Secure, Cost-Effective Private Cloud Platform for Production AI Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience Announcing VMware Cloud Foundation Edge 9.1: A Scalable, Autonomous Edge Platform Accelerate, Streamline, and Control Your Self-Service Private Cloud with VMware Cloud Foundation 9.1 Deploy Modern Apps Faster, Scale Smarter, and Lower Your TCO with VMware vSphere Kubernetes Service in VCF 9.1 Scale Smarter, Save More: Redefining Infrastructure Economics with VMware vSphere in VCF 9.1 AI with VCF 9.1 on AMD GPUs: Build with open frameworks and simplify management, at a lower TCO Streamline, Simplify and Protect all your AI workloads with VCF 9.1 Simplify Workload Connectivity and Enhance Network Scale and Performance with VCF 9.1 VMware and CrowdStrike Deliver New Integration for Cyber Recovery Workflows How Many Users Can Your LLM Server Really Handle? From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 2 The New Frontier: Leading the Cloud-Native Evolution Replicating VMware vSphere Configuration Profile Desired State Webinar Recap: Design and Architecture Considerations for VMware vSphere Kubernetes Service on VMware Cloud Foundation Kubernetes 1.36: What Actually Changed for Enterprise Platforms Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads Avi Load Balancer Analytics: Root Cause Application Performance Issues in Minutes Analyst Insight Series #3: Policy-Driven Governance and Multi-Tenant Control Post-Quantum Readiness on VMware Cloud Foundation Registration Is Live for Las Vegas | $ave with Early-Bird May 21, 2026: What’s New in VMware Tanzu Data Intelligence 10.4 From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 1 Stop Guessing: Advanced Monitoring and Troubleshooting for Data Services CPU, Disk, Network, and Memory Workload Profiles for DVD Store Database Testing How VMware Salt Automates Compliance Across Private Cloud Analyst Insight Series #2: Operational Scalability and Lifecycle Management MCP vs. APIs: Why You Need Both for AI Applications The Real Constraint on Enterprise AI isn’t GPUs; It’s Power Deploying Harbor Service in Air-Gapped VMware Cloud Foundation 9.0 Why Enhanced DirectPath Wins for High-Performance Apps Bridging the (.Local) Gap: A Split-Domain Design for VMware Cloud Foundation Deployment Observability on VMware vSphere Kubernetes Service VMware Cloud on AWS: Introducing the Usage Report APIs Converging VMware vSphere to VMware Cloud Foundation 9.0: The Top 10 Questions Answered May 6, 2026: What’s New in Tanzu Platform 10.4: Powering Agentic Apps at Scale VMware Tanzu RabbitMQ Powers the Modern Data Lakehouse with New Spark Integration and Enterprise Tooling Tanzu Data Intelligence 10.4 Delivers AI-Driven Analytics, Unified Real-Time Operations, and Sovereign Resilience Enterprise-Ready Agents Made Simple & Safe with VMware Tanzu Platform Agent Foundations Introducing Tanzu Platform 10.4: Extending Platform as a Service to Agentic Applications How AI-Assisted Analytics in Tanzu Data Intelligence Can Help Remove the SQL Bottleneck From Prototype to Production: Securing Database MCP at Enterprise Scale The Compelling Case for a Private Cloud Data Intelligence Platform The Unification Dividend: Consolidating Database Operations on VMware Cloud Foundation The Modern Spring Workflow Is Enterprise-Ready and AI-Boosted [TAM Blog] セキュアブート証明書の有効期限切れに関する注意点と対応について Accelerate Lateral Security and Ingress Load Balancing for Kubernetes Workloads From Platform to Data: Building a Cloud-Native Developer Experience On-Prem with VMware Cloud Foundation How VMware Cloud Foundation (VCF) Training Helps Keep Top Tech Talent in APJ Build Your Case for Attending VMware Explore 2026 Spring 開発元が提供する商用サポート「VMware Tanzu® Spring Essentials」とは VMware Cloud on AWS より i7i.metal-24xl インスタンスの提供開始 VMware Advanced Memory Tiering Tips for Success VMware Cloud Foundation Edge 9.0: Two-Host Edge Site Deployment with Brownfield Import Your Database Is About to Become an AI Tool. Is It Ready? Webinar Recap: Converging VMware vSphere to VMware Cloud Foundation 9.0
Applying GitOps Principles to Maintain Desired State Configuration using VMware vSphere Configuration Profile – Part 3
Jatin Purohit · 2026-04-02 · via VMware Blogs

Welcome back to the third blog post in the Automating vSphere Configuration Profile (VCP) workflows series. In the first post, we explored the VCP APIs and the set of APIs required to work with vSphere Configuration Profiles. The second post focused on consuming these APIs using PowerCLI and the Unified SDK for Python, demonstrating how they can be integrated into your Python and PowerCLI scripts. I highly recommend going through both of these posts to build the foundational understanding of VCP and its real-world use cases.

What is Infrastructure as Code (IaC)?

Maintaining infrastructure configuration is a top priority for cloud architects and administrators. While the vSphere Client gives you a great high-level view of your environment, it becomes difficult to maintain consistency when managing configurations at scale, especially across multiple locations and clusters.

Infrastructure as Code (IaC) solves this problem by allowing you to define and document infrastructure using code instead of manual UI operations. With IaC, you can:

  • Version your configurations
  • Apply consistent configurations across the entire SDDC
  • Track configuration drifts

In short, your infrastructure becomes repeatable, auditable, and automated.

The Scenario

As a cloud administrator, you likely manage multiple VMware Cloud Foundation (VCF) instances, each with several workload domains and clusters. Your goal is simple but critical:

  • Maintain a consistent desired configuration across all clusters
  • Document the configuration for future reference
  • Ensure changes are controlled and traceable

The Solution: GitOps Powered by VCP APIs

VCP APIs are REST-based and work with JSON configuration documents. They provide capabilities such as:

  • Schema validation
  • Configuration document versioning
  • Import and export of workflows
  • Lifecycle operations to manage configurations

When you combine these APIs with Git, you unlock a GitOps-driven workflow. To achieve this, you need reliable source control backed by a Git repository. 

  • GitHub repository → Stores configuration documents (version control)
  • GitHub Actions → Automates workflows when changes occur
  • PowerShell scripts → Interact with VCP APIs and orchestrate operations

Whenever a configuration is updated in Git, automation triggers and applies it in a controlled way. To implement a true GitOps model, the repository must clearly separate:

  1. Global Intent → Which vCenter servers and clusters should be managed
  2. Specific State → The actual vSphere configuration profile JSON for each cluster

GitHub Repository Structure

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

/configprofile

   README.md

   vcp_managed_clusters.yaml #Add Cluster you want to manage using VCP

├───.github

   └───workflows #Github Action Workflows

           Initialize_Configprofile.yml #VCP Enablement Workflow

           Update_ConfigProfile.yml #Configuration Update Workflow

├───scripts #PowerShell Scripts used by workflow

       enable_vcp.ps1 #Script to enable VCP

       update_config.ps1 #Script to update VCP config profile

├───template #Template Folder

       clusterAdd.yaml #Sample Yaml Schema to add clusters

├───vc-mgmt-a.site-a.vcf.lab #Auto generated VC Folder

       cluster-mgmt-01a.json #Cluster Config for cluster-mgmt-01

       cluster-mgmt-02a.json #Cluster Config for cluster-mgmt-02

       cluster-mgmt-03a.json #Cluster Config for cluster-mgmt-03

       cluster-mgmt-04a.json #Cluster Config for cluster-mgmt-04

└───vc-wld01-a.site-a.vcf.lab

        cluster-wld01-01a.json #Cluster Config for cluster-wld01-a-01

        cluster-wld01-02a.json #Cluster Config for cluster-wld01-a-02

Understanding Github Repository

Global Intent File (vcp_managed_clusters.yaml)

This file defines high-level intent of which clusters you want to manage using VCP and GitOps.

  • vCenter
  • Cluster name
  • Reference host

Update vcp_managed_clusters.yaml using schema defined in /template/clusterAdd.yaml as below

vcName:

  clusters:

    - name: "clusterName"

      managedByVCP: true

      refHost: "reference ESX Hostname"

Managed Folders (vc-*/)

These folders are auto-generated and named after vCenter FQDNs for easier parsing.

Config JSON (*.json)

These are raw exports from the VCP APIs once the configuration profile is enabled. 

Configuration Profile

They represent the exact configuration applied to each cluster.

Under the Hood: How Automation Works

Let’s break down what happens behind the scenes.

Smart Change Detection

The workflow is smartly tuned to only update the cluster configurations which are modified. We do it by understanding the difference in the git repository and fetch the *json files which are modified. 

$changedFiles = git diff --name-only HEAD^ HEAD | Where-Object { $_ -like "vc-*/*.json" }

This allows GitHub Actions to trigger Update_ConfigProfile.yaml on required clusters. 

Asynchronous Lifecycle Management

VCP operations are asynchronous. The enable_vcp.ps1 script follows a lifecycle:

  • Eligibility Check
    Invoke-CheckEligibilityClusterConfigurationTransitionAsync
  • Import Configuration
    Invoke-ImportFromHostClusterConfigurationTransitionAsync
  • Export Configuration
    Pulls raw JSON and stores it in Git using:

    [System.IO.File]::WriteAllText

    This avoids formatting or escaping issues.

Safety First: Run Draft Validation 

The safety mechanism is already built into VCP API workflows. You can not apply a draft configuration without draft configuration pre-check and validation. The update workflow executes as follows:

  1. Create a temporary configuration draft in vCenter
  2. Validate it using:

    Invoke-ValidateClusterConfigurationDraftAsync

  3. If validation fails:
    • GitHub Action fails
    • Production remains untouched
  4. If validation succeeds
    • Applies the draft configuration

Sample Run: End-to-End Workflow

Onboarding a Cluster

Add a cluster entry in vcp_managed_clusters.yaml and push changes to main branch.

What happens next:

  • Initialize_ConfigProfile.yaml workflow triggers
  • VCP is enabled on the cluster
  • A new folder for vCenter Server and Cluster configuration JSON file are auto-generated
  • GitHub bot commits them back to the repository

The cluster is now under GitOps management.

Day-2 Operations – Update/Modify Cluster Configuration

Let us assume that you want to update or modify the current cluster configuration.

  1. Open cluster-04.json in VS Code
  2. Modify the configuration
  3. Push changes
  4. Raise PR and merge the code into main

Result:

  • Update_ConfigProfile.yaml workflow triggers
  • Draft configuration created in vCenter
  • Validation runs
  • Draft configuration is applied

Implementation Note

To implement GitOps this repository leverages GitHub Action Self-Hosted Runner. With a self-hosted runner, you have secure access to your VCF environment, no exposure to public internet and you can also enforce enterprise security policies to your runners. 

You can set up Windows, Linux, and MacOS as a GitHub action runner. Please make sure you have the following components installed in your runner machine:

  • PowerShell 7
  • PowerCLI 13+
  • powershell-yaml module
  • Git CLI

Follow the GitHub instructions to know more about setting up the GitHub runners. 

Conclusion

By applying GitOps to vSphere Configuration Profiles, we move from reactive infrastructure management to automated intent-driven operations.

With GitOps, your infrastructure becomes:

  • Version controlled
  • Auditable
  • Consistent across environments
  • Safe to update
  • Fully automated

Instead of manually managing configurations, you now manage intent in Git and let the automation handle the rest. The example here demonstrates the usage of PowerCLI and GitHub Action. You can implement similar solutions in Python, Java, and Terraform since the VCP API bindings are available across all these languages and ready to use. 

VCP is one such example of how VCF is delivering a modern private cloud stack with the API-first approach. You can replicate the same approach to other VCF services as well out of the box by integrating VCF APIs with the tools you are already using in your environment. 

Demo

Important Links

Config Profile – GitHub Action Repository 

Automating Desired State Configuration using vSphere Configuration Profile APIs – Part 1

Automating vSphere Configuration Profile APIs – Part 2 – PowerCLI and Python Sample Code


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.