惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
Hacker News: Ask HN
Hacker News: Ask HN
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
The Exploit Database - CXSecurity.com
The Hacker News
The Hacker News
Security Latest
Security Latest
Attack and Defense Labs
Attack and Defense Labs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Scott Helme
Scott Helme
H
Heimdal Security Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
WordPress大学
WordPress大学
雷峰网
雷峰网
L
LangChain Blog
Y
Y Combinator Blog
I
Intezer
V
Vulnerabilities – Threatpost
Apple Machine Learning Research
Apple Machine Learning Research
The Last Watchdog
The Last Watchdog
Simon Willison's Weblog
Simon Willison's Weblog
W
WeLiveSecurity
P
Privacy International News Feed
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
AI
AI
博客园 - Franky
Hacker News - Newest:
Hacker News - Newest: "LLM"
Martin Fowler
Martin Fowler
K
Kaspersky official blog
U
Unit 42
S
Schneier on Security
Webroot Blog
Webroot Blog
Know Your Adversary
Know Your Adversary
T
Tor Project blog
aimingoo的专栏
aimingoo的专栏
Engineering at Meta
Engineering at Meta
G
GRAHAM CLULEY
美团技术团队
TaoSecurity Blog
TaoSecurity Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Google DeepMind News
Google DeepMind News
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
爱范儿
爱范儿
F
Fortinet All Blogs
有赞技术团队
有赞技术团队

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1 Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Simpler VPC Connectivity Control VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend VMware vSAN Protection and Recovery Enhancements for VCF 9.1 Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs What’s New with vSphere in VMware Cloud Foundation 9.1? Resizing VMware vCenter in VMware Cloud Foundation 9 Non-Disruptive VMware vCenter Patching in VMware Cloud Foundation 9.1 VMware vCenter Virtual Hardware Gets an Upgrade in vSphere with VCF 9.1 AI Has Changed the Threat Landscape. Is Your Infrastructure Ready? Simplifying Storage with the New Effective Capacity View in VMware vSAN for VCF 9.1 Auto-RAID in VMware vSAN for VCF 9.1 – Comprehensive System-Managed Data Resilience Introducing VMmark 4.1: Enhanced Power Efficiency Benchmarking for Private Cloud Infrastructure Advanced Memory Tiering Enhancements in VMware Cloud Foundation 9.1 VCF 9.1 Is Here. See It in Action. 博通發布 VMware Cloud Foundation 9.1 How Broadcom Is Helping Enterprises Win the AI Security Sprint How to Prepare for the World of AI Driven Exploits Avi Innovations for VCF 9.1: Powering Kubernetes, Agentic AI and VPC Workloads VCF 9.1: The Secure, Cost-Effective Private Cloud Platform for Production AI Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience Announcing VMware Cloud Foundation Edge 9.1: A Scalable, Autonomous Edge Platform Accelerate, Streamline, and Control Your Self-Service Private Cloud with VMware Cloud Foundation 9.1 Deploy Modern Apps Faster, Scale Smarter, and Lower Your TCO with VMware vSphere Kubernetes Service in VCF 9.1 Scale Smarter, Save More: Redefining Infrastructure Economics with VMware vSphere in VCF 9.1 AI with VCF 9.1 on AMD GPUs: Build with open frameworks and simplify management, at a lower TCO Streamline, Simplify and Protect all your AI workloads with VCF 9.1 Simplify Workload Connectivity and Enhance Network Scale and Performance with VCF 9.1 VMware and CrowdStrike Deliver New Integration for Cyber Recovery Workflows How Many Users Can Your LLM Server Really Handle? From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 2 The New Frontier: Leading the Cloud-Native Evolution Replicating VMware vSphere Configuration Profile Desired State Webinar Recap: Design and Architecture Considerations for VMware vSphere Kubernetes Service on VMware Cloud Foundation Kubernetes 1.36: What Actually Changed for Enterprise Platforms Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads Avi Load Balancer Analytics: Root Cause Application Performance Issues in Minutes Analyst Insight Series #3: Policy-Driven Governance and Multi-Tenant Control Post-Quantum Readiness on VMware Cloud Foundation Registration Is Live for Las Vegas | $ave with Early-Bird May 21, 2026: What’s New in VMware Tanzu Data Intelligence 10.4 From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 1 Stop Guessing: Advanced Monitoring and Troubleshooting for Data Services CPU, Disk, Network, and Memory Workload Profiles for DVD Store Database Testing How VMware Salt Automates Compliance Across Private Cloud Analyst Insight Series #2: Operational Scalability and Lifecycle Management MCP vs. APIs: Why You Need Both for AI Applications The Real Constraint on Enterprise AI isn’t GPUs; It’s Power Deploying Harbor Service in Air-Gapped VMware Cloud Foundation 9.0 Why Enhanced DirectPath Wins for High-Performance Apps Bridging the (.Local) Gap: A Split-Domain Design for VMware Cloud Foundation Deployment Observability on VMware vSphere Kubernetes Service VMware Cloud on AWS: Introducing the Usage Report APIs Converging VMware vSphere to VMware Cloud Foundation 9.0: The Top 10 Questions Answered May 6, 2026: What’s New in Tanzu Platform 10.4: Powering Agentic Apps at Scale VMware Tanzu RabbitMQ Powers the Modern Data Lakehouse with New Spark Integration and Enterprise Tooling Tanzu Data Intelligence 10.4 Delivers AI-Driven Analytics, Unified Real-Time Operations, and Sovereign Resilience Enterprise-Ready Agents Made Simple & Safe with VMware Tanzu Platform Agent Foundations Introducing Tanzu Platform 10.4: Extending Platform as a Service to Agentic Applications How AI-Assisted Analytics in Tanzu Data Intelligence Can Help Remove the SQL Bottleneck From Prototype to Production: Securing Database MCP at Enterprise Scale The Compelling Case for a Private Cloud Data Intelligence Platform The Unification Dividend: Consolidating Database Operations on VMware Cloud Foundation The Modern Spring Workflow Is Enterprise-Ready and AI-Boosted [TAM Blog] セキュアブート証明書の有効期限切れに関する注意点と対応について Accelerate Lateral Security and Ingress Load Balancing for Kubernetes Workloads From Platform to Data: Building a Cloud-Native Developer Experience On-Prem with VMware Cloud Foundation How VMware Cloud Foundation (VCF) Training Helps Keep Top Tech Talent in APJ Build Your Case for Attending VMware Explore 2026 Spring 開発元が提供する商用サポート「VMware Tanzu® Spring Essentials」とは VMware Cloud on AWS より i7i.metal-24xl インスタンスの提供開始 VMware Advanced Memory Tiering Tips for Success VMware Cloud Foundation Edge 9.0: Two-Host Edge Site Deployment with Brownfield Import Your Database Is About to Become an AI Tool. Is It Ready? Webinar Recap: Converging VMware vSphere to VMware Cloud Foundation 9.0
Applying GitOps Principles to Maintain Desired State Configuration using VMware vSphere Configuration Profile – Part 3
Jatin Purohit · 2026-04-02 · via VMware Blogs

Welcome back to the third blog post in the Automating vSphere Configuration Profile (VCP) workflows series. In the first post, we explored the VCP APIs and the set of APIs required to work with vSphere Configuration Profiles. The second post focused on consuming these APIs using PowerCLI and the Unified SDK for Python, demonstrating how they can be integrated into your Python and PowerCLI scripts. I highly recommend going through both of these posts to build the foundational understanding of VCP and its real-world use cases.

What is Infrastructure as Code (IaC)?

Maintaining infrastructure configuration is a top priority for cloud architects and administrators. While the vSphere Client gives you a great high-level view of your environment, it becomes difficult to maintain consistency when managing configurations at scale, especially across multiple locations and clusters.

Infrastructure as Code (IaC) solves this problem by allowing you to define and document infrastructure using code instead of manual UI operations. With IaC, you can:

  • Version your configurations
  • Apply consistent configurations across the entire SDDC
  • Track configuration drifts

In short, your infrastructure becomes repeatable, auditable, and automated.

The Scenario

As a cloud administrator, you likely manage multiple VMware Cloud Foundation (VCF) instances, each with several workload domains and clusters. Your goal is simple but critical:

  • Maintain a consistent desired configuration across all clusters
  • Document the configuration for future reference
  • Ensure changes are controlled and traceable

The Solution: GitOps Powered by VCP APIs

VCP APIs are REST-based and work with JSON configuration documents. They provide capabilities such as:

  • Schema validation
  • Configuration document versioning
  • Import and export of workflows
  • Lifecycle operations to manage configurations

When you combine these APIs with Git, you unlock a GitOps-driven workflow. To achieve this, you need reliable source control backed by a Git repository. 

  • GitHub repository → Stores configuration documents (version control)
  • GitHub Actions → Automates workflows when changes occur
  • PowerShell scripts → Interact with VCP APIs and orchestrate operations

Whenever a configuration is updated in Git, automation triggers and applies it in a controlled way. To implement a true GitOps model, the repository must clearly separate:

  1. Global Intent → Which vCenter servers and clusters should be managed
  2. Specific State → The actual vSphere configuration profile JSON for each cluster

GitHub Repository Structure

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

/configprofile

   README.md

   vcp_managed_clusters.yaml #Add Cluster you want to manage using VCP

├───.github

   └───workflows #Github Action Workflows

           Initialize_Configprofile.yml #VCP Enablement Workflow

           Update_ConfigProfile.yml #Configuration Update Workflow

├───scripts #PowerShell Scripts used by workflow

       enable_vcp.ps1 #Script to enable VCP

       update_config.ps1 #Script to update VCP config profile

├───template #Template Folder

       clusterAdd.yaml #Sample Yaml Schema to add clusters

├───vc-mgmt-a.site-a.vcf.lab #Auto generated VC Folder

       cluster-mgmt-01a.json #Cluster Config for cluster-mgmt-01

       cluster-mgmt-02a.json #Cluster Config for cluster-mgmt-02

       cluster-mgmt-03a.json #Cluster Config for cluster-mgmt-03

       cluster-mgmt-04a.json #Cluster Config for cluster-mgmt-04

└───vc-wld01-a.site-a.vcf.lab

        cluster-wld01-01a.json #Cluster Config for cluster-wld01-a-01

        cluster-wld01-02a.json #Cluster Config for cluster-wld01-a-02

Understanding Github Repository

Global Intent File (vcp_managed_clusters.yaml)

This file defines high-level intent of which clusters you want to manage using VCP and GitOps.

  • vCenter
  • Cluster name
  • Reference host

Update vcp_managed_clusters.yaml using schema defined in /template/clusterAdd.yaml as below

vcName:

  clusters:

    - name: "clusterName"

      managedByVCP: true

      refHost: "reference ESX Hostname"

Managed Folders (vc-*/)

These folders are auto-generated and named after vCenter FQDNs for easier parsing.

Config JSON (*.json)

These are raw exports from the VCP APIs once the configuration profile is enabled. 

Configuration Profile

They represent the exact configuration applied to each cluster.

Under the Hood: How Automation Works

Let’s break down what happens behind the scenes.

Smart Change Detection

The workflow is smartly tuned to only update the cluster configurations which are modified. We do it by understanding the difference in the git repository and fetch the *json files which are modified. 

$changedFiles = git diff --name-only HEAD^ HEAD | Where-Object { $_ -like "vc-*/*.json" }

This allows GitHub Actions to trigger Update_ConfigProfile.yaml on required clusters. 

Asynchronous Lifecycle Management

VCP operations are asynchronous. The enable_vcp.ps1 script follows a lifecycle:

  • Eligibility Check
    Invoke-CheckEligibilityClusterConfigurationTransitionAsync
  • Import Configuration
    Invoke-ImportFromHostClusterConfigurationTransitionAsync
  • Export Configuration
    Pulls raw JSON and stores it in Git using:

    [System.IO.File]::WriteAllText

    This avoids formatting or escaping issues.

Safety First: Run Draft Validation 

The safety mechanism is already built into VCP API workflows. You can not apply a draft configuration without draft configuration pre-check and validation. The update workflow executes as follows:

  1. Create a temporary configuration draft in vCenter
  2. Validate it using:

    Invoke-ValidateClusterConfigurationDraftAsync

  3. If validation fails:
    • GitHub Action fails
    • Production remains untouched
  4. If validation succeeds
    • Applies the draft configuration

Sample Run: End-to-End Workflow

Onboarding a Cluster

Add a cluster entry in vcp_managed_clusters.yaml and push changes to main branch.

What happens next:

  • Initialize_ConfigProfile.yaml workflow triggers
  • VCP is enabled on the cluster
  • A new folder for vCenter Server and Cluster configuration JSON file are auto-generated
  • GitHub bot commits them back to the repository

The cluster is now under GitOps management.

Day-2 Operations – Update/Modify Cluster Configuration

Let us assume that you want to update or modify the current cluster configuration.

  1. Open cluster-04.json in VS Code
  2. Modify the configuration
  3. Push changes
  4. Raise PR and merge the code into main

Result:

  • Update_ConfigProfile.yaml workflow triggers
  • Draft configuration created in vCenter
  • Validation runs
  • Draft configuration is applied

Implementation Note

To implement GitOps this repository leverages GitHub Action Self-Hosted Runner. With a self-hosted runner, you have secure access to your VCF environment, no exposure to public internet and you can also enforce enterprise security policies to your runners. 

You can set up Windows, Linux, and MacOS as a GitHub action runner. Please make sure you have the following components installed in your runner machine:

  • PowerShell 7
  • PowerCLI 13+
  • powershell-yaml module
  • Git CLI

Follow the GitHub instructions to know more about setting up the GitHub runners. 

Conclusion

By applying GitOps to vSphere Configuration Profiles, we move from reactive infrastructure management to automated intent-driven operations.

With GitOps, your infrastructure becomes:

  • Version controlled
  • Auditable
  • Consistent across environments
  • Safe to update
  • Fully automated

Instead of manually managing configurations, you now manage intent in Git and let the automation handle the rest. The example here demonstrates the usage of PowerCLI and GitHub Action. You can implement similar solutions in Python, Java, and Terraform since the VCP API bindings are available across all these languages and ready to use. 

VCP is one such example of how VCF is delivering a modern private cloud stack with the API-first approach. You can replicate the same approach to other VCF services as well out of the box by integrating VCF APIs with the tools you are already using in your environment. 

Demo

Important Links

Config Profile – GitHub Action Repository 

Automating Desired State Configuration using vSphere Configuration Profile APIs – Part 1

Automating vSphere Configuration Profile APIs – Part 2 – PowerCLI and Python Sample Code


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.