SER1963BE Technical Overview of VMware ESXi Host Lifecycle Management with Update Manager, Auto Deploy, and Host Profiles VMworld 2017 Content: Not for publication Eric Gray @eric_gray #VMworld #SER1963BE
How do I patch custom OEM images? Are ESXi patches cumulative? VMworld 2017 Do stateless hosts keep SSH & SSL identities after reboot? With Auto Deploy, is DHCP a single point of failure? Content: Not for publication When do I need to upgrade a host profile? 3
Update Sequence for vsphere 6.5 and Compatible Products Mastering the VMware Tools Lifecycle in Your vsphere Data Center [SER1957BE] Wednesday 11:00 KB 2147289 4
End of General Support Is Here for ESXi Releases Prior to 5.5 ESXi 6.5 Recently Extended! 5
VMware ESXi Despite the CLI, It s NOT Linux 6
Understanding the ESXi Disk Partitioning Scheme 250 MB bootbank 250 MB altbootbank 286 MB store 4 GB n GB scratch VMFS 7
Host Updates Are Applied to the Unused Bootbank bootbank altbootbank :~] cat bootbank/boot.cfg bootstate=0 build=6.0.0-2.37.3825889 updated=10 :~] cat altbootbank/boot.cfg bootstate=0 build=6.0.0-2.34.3620759 updated=9 8
9
VIB Details are Available Through esxcli 10
Build numbers and versions of VMware ESXi KB 2143832 11
Access My.VMware to Download Patch Releases Only the latest download is required ESXi patches are cumulative 12
Demystifying VMware ESXi Patch Release Contents Patch Release: ESXi650-201703001 ESXi650-201703401-BG Category: Bugfix Severity: VIB #1 Critical VIB VIB #1 VIB #1#2 VIB VIB VIB #2 #2 #3 VIB VIB #3 #3 VMworld 2017 Bulletins ESXi-6.5.0-20170304001-standard VIB #1 VIB #2 VIB #3 VIB #4 VIB #5 VIB #6 Image Profiles VIB #7 VIB #8 VIB #9 Content: Not for publication ESXi650-201703001.zip Each item above has a corresponding KB article 13
Optimized OEM Custom Images from VMware Partners ISO or offline bundle from your favorite server vendor Optimized drivers and management agents From My.VMware or partner support sites 14
But how can I patch OEM images? Update Manager applies patches to all images VMworld 2017 Content: Not for publication Create new image with PowerCLI or GUI Image Builder 15
16
17
But how can patches be cumulative with such varying sizes? 18
Security-only Profiles Without Other Enhancements or Fixes 19
These s Profiles Include Two Variations of Certain VIBs Same release dates, Different versions 20
Select an Update Approach Based on Desired Optimizations Simple ISO KS CLI Automated Scripts Interactive VUM VMworld 2017 Content: Not for Auto Deploy publication Scalable 21
Update Manager Automates the Patching Process VUM downloads ESXi patches via the Internet Administrators create and attach patch baselines DRS enables rolling updates with zero downtime 22
Intelligent Integration with vsan Clusters in vsphere 6.5 U1 VUM Determines Best vsan Upgrade VMworld 2017 Content: Not for publication Generates Baseline and Downloads Software 23
Update Manager Patches are Bulletins, not Image Profiles 24
VUM Can Patch or Upgrade Multiple ESXi Releases 6.5 6.0 5.5 Remediation Supported by VUM 6.5 PATCH PATCH or UPGRADE PATCH or UPGRADE 25
VUM Architecture Improvements in vsphere 6.5 vcenter Server 6.0 or 6.5 on Windows Update Manager on Windows Additional Windows VM for VUM Extra configuration & DB dependency Sizing and latency considerations VMworld 2017 Content: Not for No inherent backup or failover VCSA 6.5 with Integrated VUM Integrated and enabled by default publication Zero setup; embedded DB Scalable and low impact on resources Leverages VCSA HA and backup Migration Support! 26
Update Manager Scalability Increased in vsphere 6.5 Concurrent Operations 6.0 6.5 ESXi host scan 75 232 ESXi host patch / upgrade 71 232 VMware Tools / VM hw scan 90 200 VMware Tools / VM hw upgrade 75 200 2-3x increase 27
Why Stateless Compute Infrastructure? Unified Workflow Install Patch Upgrade Consistency VMworld 2017 Centralized Control Images Configuration Diagnostics Content: Not for publication Efficiency Faster deployments Reduced effort Speed 28
Configure Auto Deploy Hosts with Host Profiles CREATE Extract settings from a configured host UPDATE Copy from a host -or- Edit via GUI Use any combination of configuration tools: PowerCLI, esxcli, graphical interfaces Modified elements are part of profile Names and values are case-sensitive 29
Host Profiles are Forward Compatible VMware ESXi Host Profile 6.0 6.5 30
Upgrade Hosts First, then Update the Host Profile VMware ESXi Host Profile VMware ESXi 6.0 6.5 Host Profile 31
Hosts Also Require Unique Configuration Settings hostname vmk0 vmk1 root pass 32
Mandatory Customizations Must be Provided for Compliance hostname vmk0 vmk1 root pass host86.vcritical.com 10.197.34.86 255.255.255.0 172.24.10.86 255.255.0.0 ********** Host Customizations 33
or Provide host customizations in CSV file distribution 34
or Boost efficiency and maintain a config record! distribution 35
Unique Identifiers are Properly Handled for Stateless Hosts SSL Certificates SSH Keys 36
Catch a Glimpse of Zero-Touch Cluster Deployments 37
Side-by-Side Compliance Results Quickly determine course of action! VMworld 2017 Content: Not for publication 38
Rolling or Parallel Profile Remediation Reduces time spent monitoring remediation! 39
Easily Copy Settings From One Profile to Many Manage Multiple Host Profiles More Effectively! 40
If you want uptime, prepare for downtime Boot storms Auto Deploy backup Infrastructure dependencies Photo: Luis García 41
Auto Deploy Reverse Proxy Caching in vsphere 6.5 Improve host boot time & reduce impact on vcenter Server 42
Take Regular Backups of Auto Deploy Configuration New PowerCLI cmdlet in vsphere 6.5 exports config, database, SSL certs, cache, and more 43
Stateless Hosts Often Rely on Dynamic IP Addressing Single points of failure? VMworld 2017 Content: Not for Three approaches to improve DHCP resiliency publication NIC MAC Address Switch 44
Configure Redundant Physical Boot Interfaces and Switches 45
1) Redundant DHCP Reservations Associate two MAC addresses with one IP address VMkernel uses the boot MAC 46
2) DHCP Boot & Transition to Static IPs Use pool of DHCP addresses, No reservations Configure Host Profile with Static IP addresses 47
3) Dedicated DHCP Boot Network Operational Traffic on vds VLAN dedicated for PXE booting on-board NICs Host management interface is on vds DHCP or static 48
Multiple Approaches to vsphere Host Lifecycle Management 49
Host Lifecycle Management Takeaways VMware ESXi patches are cumulative! Patches, upgrades, and fresh installs result in a similar state Develop workflows to keep OEM images secure from exploits Choose the lifecycle management approach that is best for your data center Stateful with Update Manager applies patch bulletins Auto Deploy uses complete ESXi image profiles for all operations vsphere 6.5 enhancements boost manageability and reliability Embedded Update Manager with increased scale Bulk host customizations Simple reverse proxy setup Quick Auto Deploy configuration backup 50
Additional Resources and Opportunities to Interact Meet the Experts [MTE4718E] Wednesday 13:15 UX Design Studio ESXi Lifecycle https://calendy.com/vsphere-lifecycle/eu/ 51