Private AI Workload Domain: GPU Nodes, AI Kubernetes, and Private AI Services

Private AI Workload Domain: GPU Nodes, AI Kubernetes, and Private AI Services

Introduction “Run AI on our own infrastructure” sounds like a single project. With VMware Private AI Foundation with NVIDIA (PAIF) on VCF 9.1.x it isn’t, there are three different ways to use your GPUs, and the one you pick changes what you build before the first workload runs. Add a licensing model where two vendors each sell you a different piece, and the planning decisions matter more than the deployment steps. This post covers the fundamentals, what the domain is made of, the three ways to consume it, and what you need to license. ...

October 11, 2026 · Mohamed Rabiee
DR & Ransomware Recovery: Isolated Recovery, Protection and Recovery, and VPC Isolation

DR & Ransomware Recovery: Isolated Recovery, Protection and Recovery, and VPC Isolation

Introduction Disaster recovery and ransomware recovery get planned in the same conversation more often than not, same team, same budget line, sometimes the same runbook with a different label on it. Broadcom’s own architecture disagrees with that framing. Operational DR assumes your primary environment is healthy but unreachable or impaired, the priority is RTO, automation, and minimal data loss. Cyber recovery assumes your primary environment is compromised, every action requires forensic isolation, immutability, and an air-gap mentality. Same team can run both. Structurally, they’re not the same discipline, and VCF 9.1’s tooling treats them as genuinely separate. ...

October 3, 2026 · Mohamed Rabiee
Day-2 Operations: Lifecycle, Patching, and Compliance via VCF Operations

Day-2 Operations: Lifecycle, Patching, and Compliance via VCF Operations

Introduction Day-2 in most infrastructure conversations gets reduced to one word: patching. VCF 9.1 treats it as two separate, ongoing jobs that happen to share a control plane. The first is applying fixes without breaking anything that’s running. The second is proving, continuously, that what’s running still matches what you intended to deploy. Broadcom built genuinely different tooling for each, and conflating them is a good way to think you’re covered on one when you’ve only handled the other. ...

September 26, 2026 · Mohamed Rabiee
Bundle Management: Online vs Offline/Air-Gapped

Bundle Management: Online vs Offline/Air-Gapped

Introduction “Air-gapped” gets treated as a single scenario in most VCF conversations, you either have internet access or you don’t. VCF 9.1’s software depot architecture disagrees: it defines three distinct connection modes, and the two that cover no-internet environments, Offline Depot and Disconnected, are genuinely different operational models, not two names for the same workaround. Picking the wrong one, or assuming they’re interchangeable, is a common source of confused prechecks during upgrade planning. ...

September 6, 2026 · Mohamed Rabiee
VCF 9 Identity Broker: Retiring VMware Identity Manager for Unified Fleet Authentication

VCF 9 Identity Broker: Retiring VMware Identity Manager for Unified Fleet Authentication

Introduction If Fleet collapsed three consoles into one control plane, the Identity Broker does the same job for authentication. VMware Identity Manager (vIDM) is superseded in VCF 9 by a fleet-native component called the Identity Broker. The new component takes over VCF single sign-on going forward, though Broadcom doesn’t force a rip-and-replace cutover: existing vIDM instances can keep running (still managed via VMware Aria Suite Lifecycle 8.x) as an authentication source for components like VCF Automation while you migrate the rest of the fleet on your own schedule. This post covers what the Identity Broker actually is, the two ways you can deploy it, and what a real migration from vIDM looks like, based on Broadcom’s official 9.1 documentation. ...

August 30, 2026 · Mohamed Rabiee
VCF 9 Security and Compliance: DFW, VPC Isolation, and Hardened Operations

VCF 9 Security and Compliance: DFW, VPC Isolation, and Hardened Operations

Introduction Security is a foundational concern in any private cloud deployment. VMware Cloud Foundation 9 delivers a layered security architecture that spans from the physical network underlay through the workload networking and compute layers, with VCF Operations providing centralized visibility into the security posture of all domains. In this post, we explore the VCF 9 security architecture, focusing on the Distributed Firewall design, VPC-level isolation, the Gateway Firewall default behavior change, and how VCF Operations handles security compliance monitoring. ...

August 23, 2026 · Mohamed Rabiee
vSAN ESA vs OSA: Storage Architecture Decisions

vSAN ESA vs OSA: Storage Architecture Decisions

Introduction vSAN’s storage architecture choice gets made before a single VM is ever placed – it’s a hardware and cluster-topology decision baked in at workload domain creation. VCF 9.1 supports two architectures side by side, Express Storage Architecture (ESA) and the Original Storage Architecture (OSA), and they claim disks in fundamentally different ways. Picking the wrong one for your hardware, or your operational model, is expensive to unwind later. Architectural Overview OSA: Cache and Capacity, Organized in Disk Groups Under the Original Storage Architecture, every host contributing storage needs at least one cache device and at least one capacity device, organized into one or more disk groups. Cache devices are SAS/SATA SSD or PCIe flash, and for hybrid configurations the cache tier needs to be sized at roughly 10% of anticipated capacity storage. Capacity devices differ by configuration: hybrid clusters use SAS/NL-SAS magnetic disks, all-flash clusters use SAS/SATA SSD or PCIe flash. OSA also requires a storage controller – a SAS/SATA HBA or RAID controller running in passthrough or RAID-0 mode – and host memory is sized based on how many disk groups and devices each host carries, typically worked out with the vSAN Sizer tool. ...

August 16, 2026 · Mohamed Rabiee
NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

Introduction Every workload domain eventually needs to talk to the outside world, and in NSX that conversation happens at the edge. The NSX Edge cluster is where policy meets physical: it hosts the Tier-0 gateway that peers with your physical network, terminates VPN tunnels, and enforces the firewall rules that decide what’s allowed to cross the north-south boundary. Get the Edge cluster’s HA design wrong and you inherit asymmetric routing, dropped stateful sessions, or a firewall that silently fails open on a node switchover. This post breaks down the Tier-0/Tier-1 split, the HA modes that govern them, and how VPN and firewall services layer on top. ...

August 9, 2026 · Mohamed Rabiee
VI Workload Domains: Shared vs Dedicated NSX

VI Workload Domains: Shared vs Dedicated NSX

Introduction Every VI workload domain you stand up in VCF asks the same networking question: does it join an existing NSX Manager, or get its own? The Networking page of the workload domain creation wizard boils this down to two buttons – “Join Existing NSX Manager Instance” and “Create New NSX Manager Instance” – but the operational consequences run much deeper than a single click. This is a per-domain decision, not a fleet-wide one, and a VCF instance scaling toward its 25-domain ceiling will likely end up with a mix of both. ...

August 2, 2026 · Mohamed Rabiee
Workload Domain Creation: Greenfield vs Import Existing vCenter

Workload Domain Creation: Greenfield vs Import Existing vCenter

Introduction Every VI workload domain in a VCF instance got there one of two ways: it was built from scratch through the workload domain wizard, or it was an existing vCenter environment that VCF Operations absorbed as-is. These aren’t just two UI paths to the same result – they carry different prerequisites, different day-one side effects, and different long-term upgrade constraints. Picking the wrong one for your situation doesn’t just cost time in the wizard; it can lock a workload domain out of upgrade paths for its entire lifecycle. ...

July 25, 2026 · Mohamed Rabiee