vcenter server architecture and deployment deep...

39
vCenter Server Architecture and Deployment Deep Dive INF2311 Justin King, VMware Harish Niddagatta, VMware Robert Perugini, VMware

Upload: others

Post on 22-Jan-2020

39 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

vCenter Server Architecture and Deployment Deep Dive

INF2311

Justin King, VMwareHarish Niddagatta, VMwareRobert Perugini, VMware

Page 2: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

Disclaimer• This presentation may contain product features that are currently under development.

• This overview of new technology represents no commitment from VMware to deliver these features in any generally available product.

• Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind.

• Technical feasibility and market demand will affect final delivery.

• Pricing and packaging for any new technologies or features discussed or presented have not been determined.

CONFIDENTIAL 2

Page 3: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 3

Agenda

vCenter Server 5.5• VMware Services Evolution

• Deployment Configurations

• Install & Upgrade

vCenter Server Tech Preview• VMware Services Evolution

• Deployment Configurations

• Install & Upgrade

Q & A

Page 4: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

vCenter Server 5.5

Page 5: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 5

vCenter Server Configuration Options

ISSSO Web

1 VM/Host

2 VMs/Hosts

ISWebSSO

ISSSO Web

4 VMs/Hosts

Sufficient for most environmentsEasiest to maintain and deploy

Large customers with numerous vCenter Servers Reduces footprint by sharing SSO across vCenter Servers

Most complex to maintain and deploySome customers have experienced performance issues with Inventory Service and vCenter in separate VMs

5.1 and 5.5

5.0One configuration for all environments

Page 6: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 6

Configuration #1 - Single vCenter Server 5.5

VC Database

vCenter Server Host or VM

vCenterServer

SSO Server

Web Client

Inventory Service

Use Simple InstallerInstalls / Upgrades core components with a single virtual machine

1. vCenter Single Sign-On

2. vSphere Web Client

3. vCenter Inventory Service

4. vCenter Server

No change to architecture All services are local

• Reduced complexity

Supports 1-1000 Hosts / 1-10,000 Virtual Machines

Page 7: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 7

Configuration #1 - Multiple vCenter Server 5.5

By Default Each site is independent Does not provide a single pane of glass view SSO builtin replication SSO Users & Groups SSO Policies Identity sources

Use custom installer to expend vSphere.local domain

Linked Mode Maintains single pane of glass Replicates Licenses, permissions and roles

vCenter Server

vCenterServer

New York

vCenter Server

vCenterServer

Miami

vCenter Server

vCenterServer Web Client

Inventory Svc

SSO Server – vsphere.local

Los Angeles

Web Client

Inventory Svc

Web Client

Inventory Svc

SSO Site 1 SSO Site 2 SSO Site 3Single SSO Authentication Domain

Page 8: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 8

Configuration #2 – Centralized Single Sign-On Server 5.5A Datacenter with 3 or more solutions

Centralized SSO authentication– Same Physical location

Availability (Required)– vSphere HA– Network Load Balancer

Solution 2

vCenterServer 5.5

SSOServer

Web ClientvCenter SSO

Server 5.5

DatabaseServer

VCDB1,VCDB2

Solution 3

vCloudAutomation

Center

Solution 1

vCenterServer 5.1

Inventory Svc

Backwards compatible to vCenter Server 5.1for staging of upgrades

Web Client Web ClientInventory Svc

Page 9: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 9

Upgrading 5.1 Architecture when Distributed

Upgrade the current vCenter Single Sign-On 5.1 to 5.5Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual machine specifying that vCenter Single Sign-On is an additional instance placing it in the already created vsphere.local security domainOn the vCenter Server install the vSphere Web Client 5.5 using the local vCenter Single Sign-On instanceOn the vCenter Server install the vCenter Inventory Service using the local vCenter Single Sign-On instanceOn the vCenter Server install the vCenter Server using the local vCenter Single Sign-On instancePower off and remove the original separate vCenter Single Sign-On instance

Host or VM

SSO

Host or VM

Web Client

Host or VM

vCenter

IS

Host or VM

vCenter

SSO

Web Client

IS

Page 10: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 10

Utilize a Management Cluster1. Run multiple vCenter components together on same

virtual machine• Database excluded (for performance)

2. Recommendations– 3 vSphere Hosts (minimum)– Enable vSphere HA

• Enable VM Monitoring

– Enable DRS• Affinity / Anti Affinity Rules

– Understand and configure service dependency order

vCenter Server (2)

vSphere Update

Manager

Site Recovery Manager

Management Cluster

vCenter Server (1)

Database Server

vCenter Operations

Log Insight

vCenter Orchestrato

r

vCAC

Page 11: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 11

Page 12: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 12

Page 13: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 13

Simple Install • Simple Install Changes– Added Web Client – Installer Order changes

5.1

Single Sign-On

Inventory Service

vCenter

5.5

Single Sign-On

vSphere WebClient

Inventory Service

vCenter

Why?• In the rare case SSO goes wrong, users can log into Web

Client and troubleshoot• Simple Install puts all components in a single server

• VMware’s suggested best practice

Page 14: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 14

Custom Install • Why would you run this?– Distribute services across

multiple servers

• Customize location

• Advanced configurations• E.g. additional vCenter servers

1 2 3 4

Order of Installation

Page 15: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 15

vCenter Single Sign-On Recomendations• Embedded vCenter Single Sign-On reduces complexity

– Up to 8 instances peer to peer– 12ms Latency

• Same vSphere.local domain– Single point of administration

• Centralized vCenter Single Sign-On– 3 or more Solutions (vCenter, vCAC, etc)– Redundancy required (HA, NLB)– Single pane of glass (per central instance)

• All configurations– Backup each instance– Recovery of additional instances may require manual re-sync (if changes were made)

• Worst case, redeploy new and reregister solutions

Page 16: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 16

Choose the correct deployment option!The installation choices of the vCenter Single Sign-On will dictate how SSO functions

• Middle Radio Button – Merges Lookup Services – For SSO HA, requires loadbalancer

• Bottom Radio Button – Configures new Lookup Services – For multiple deployments• http://kb.vmware.com/kb/2058239 and http://kb.vmware.com/kb/2058249

Page 17: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 17

What Is the vCenter Server Inventory Service?

Maintains a cache of the vCenter Server inventory

– (VMs, Hosts, etc)Reduces the load on VPXD by offloading client requestsInstalls locally to vCenter Server (do not install to a separate virtual machine)

– Separate spindles or SSD (better)

Enables use of Tags Enables Storage Based Policy Management

– Remember to backup Inventory service data files to provide recovery of tags and SBPM

Inventory Service provides a query service for the web client

Page 18: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 18

vSphere Clients

vSphere Web Client (use this)– Primary client for vSphere administrators– Matched functionality to legacy VI Client– New functionality available only thru the Web Client– Browser based on Windows and Mac– Install local to vCenter Server

• If installing to alternative drive, enable 8.3 paths

vSphere Client (not this)– Available with legacy features– Use it for all supported host client functionalities– Update Manager Remediation– Added HW10 support (5.5 Update 2)

Page 19: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

vCenter Server Tech Preview

Page 20: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 20

VMware Platform Services

ISSSO Web

1 VM/Host

2 VMs/Hosts

ISWebSSO

ISSSO Web

4 VMs/Hosts

Single Sign-On (SSO)5.1 – 1st release of platform services (SSO 1.0)5.5 – 2nd release of platform services (SSO 2.0)

5.1 and 5.5

5.0No Platform Services

Page 21: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 21

VMware Platform Services ControllerWe’re adding additional services

No longer just Single Sign-On

Platform Services Controller includes a set of common infrastructure services that are used by the vCloud Suite (vCenter, vCAC, vCOPS, etc)

• Single Sign-On (SSO)

• Licensing

• Certificate Authority

• Certificate Store

• Service (Product) Registration

• Other Services will be added in future releases

Platform Services Controller supports data replication

Platform Services

Controller Platform Services

Controller

Platform Services

Controller

Page 22: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 22

vCenter Server – Embedded PSC vs. External PSCvCenter Server with Embedded PSC• Sufficient for most environments

• Easiest to maintain and deploy

• Supports up to 8 vCenter Servers

• Supports embedded & external vCenter DB

• Supports Windows & Appliance

vCenter Server with External PSC• For larger customers with numerous vCenter

Servers

• Reduces footprint by sharing Platform Services Controller across several vCenter Servers

• Recommended for 3+ vCenter Servers per site

• Supports embedded & external vCenter DB

• Supports Windows & Appliance

PSC vCenter

vCenterPSC

Page 23: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 23

vCenter Server – Embedded Configuration

5.1 & 5.5

vSphere Tech Preview

Configuration isn’t changing, we’re just adding more services

VCSSO VCSSO VCSSOVCSSO

VCPSC VCPSC VCPSCVCPSC

Page 24: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 24

vCenter Server – External Configurations

vSphere Tech Preview

Configuration isn’t changing, we’re just adding more services

5.1 & 5.5

SSO

VC VC VCVC VC

PSC

VC VC VCVC VC

Page 25: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 25

vCloud Suite Embedded And External Configurations

Embedded PSC

External PSC

Extending this concept to the rest of the vCloud Suite

VCPSC vCACPSC

PSC

VC vCOPs VCOVC vCAC

Page 26: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 26

Growth – Transition from “Embedded PSCs” to “External PSCs”• Supports “Embedded” and “External” in the same SSO Domain• Hybrid configuration – Windows and Appliance

SAN FRANCISCOSAN FRANCISCO

VC

PSC

vCAC

VCPSC

vCOpsPSC

vCACPSC

VCPSC

NEW YORK LONDON SINGAPORE

VCPSC

VCPSC

VC

LONDON

Page 27: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 27

vCenter Server Tech Preview - Install and Upgrade

vCenter Server for Windows

Page 28: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 28

vCenter Server Tech Preview - Install and Upgrade

vCenter Server for Windows

vCenter Server Appliance

Page 29: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 29

vCenter Server Tech Preview - Install For Windows

One installer

Choose deployment type

All input up front & validated

Pre-Check functionality• Min CPU/Memory/Disk

requirements

• Internal/External Ports Availability

• OS/DB support check

Scripted Install for Advanced Administrators

Page 30: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 30

vCenter Server Tech Preview - Appliance Install

New Guided Install

Choose deployment type

All input up front & validated

Pre-Check functionality

Scripted Install for Advanced Administrators

Page 31: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 31

vCenter Server Upgrade: 5.0 to Tech Preview5.0 Tech Preview

Tech Preview5.0

vCenter PSC

To External PSC(pre-requisite: PSC must exist)

Step 1: Install PSC

vCenter PSCTo Embedded PSC

Step 2: Upgrade 5.0 to .Next

Page 32: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 32

vCenter Server – 5.1 / 5.5 Upgrade to Tech Preview

5.1 / 5.5 Tech Preview

ISSSO Web

1 VM/Host

To Embedded PSC

To External PSC

Step 1: Upgrade SSO to PSC

Step 2: vCenter Server to Tech Preview

vCenter PSC

2 VMs/Hosts

ISWebSSO vCenter PSC

Separate Web Client and Inventory Service migrated to vCenter

ISSSO Web

4 VMs/Hosts

vCenter PSC

Page 33: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 33

vCenter Server Appliance Improvements

Metric Windows Appliance*Hosts per VC 1k ✔

Powered on VMs per VC 10k ✔

Hosts per cluster 64 ✔

VMs per cluster 6k ✔

Linked Mode 10 ✔

* Single instance VC with embedded vPostgres

Page 34: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 34

Comparing Linked Mode (LM) and Enhanced Linked Mode (ELM)vSphere 5.5 (LM) Tech Preview (ELM)

vCenter for Windows Yes YesvCenter Server Appliance No YesSingle Sign On Yes YesSingle Inventory View Yes YesSingle Inventory Search Yes YesReplication Technology Microsoft ADAM Native• Roles and Permissions Yes Yes• Licenses Yes Yes• Policies No Yes• Tags No Yes

Page 35: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

CONFIDENTIAL 35

Clients Update

Use case vSphere Web Client vSphere Client

vCenter management ✔ ✔

Host management ✔ ✔

ESXi patch updates ✖ ✔

Hardware version 9-11 ✔ ✔*

New features ✔ ✖

* Read only access

Page 36: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

Q & A

Sign uphttp://tinyurl.com/vSphereBeta

Page 37: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

Thank You

Page 38: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

Fill out a surveyEvery completed survey is entered

into a drawing for a $25 VMware company store gift certificate

Page 39: vCenter Server Architecture and Deployment Deep Divedownload3.vmware.com/vmworld/2014/downloads/... · Deploy a new vCenter Single Sign-On server to the vCenter Server or single virtual

vCenter Server Architecture and Deployment Deep Dive

INF2311

Harish NiddagattaSr. Product Manager, vCenter Install And [email protected]

Bob Perugini, Sr. Product Manager, Suite Install And [email protected]

Justin KingArchitect, Technical Product [email protected]