Академический Документы
Профессиональный Документы
Культура Документы
WARNING: We have seen some intermittent issues where NSX Manager Operating System
halts in a Boot process. For better experience and to prevent occurrence of the
issue, perform below steps after every login.
You open a Remote Desktop Protocol connection to the lab environment. After logging
in, you are introduced to the applications used in the labs.
After you are logged in to the student desktop, you do most of the work with
Internet Explorer and various Web consoles. Other systems might require the use of
either a third remote desktop connection from the student desktop to a lab system
or the use of PuTTY or similar utilities to make an SSH connection into a Linux-
based server.
You verify the license for the VMware vCenter Server® system, the VMware ESXi™
hosts, and the VMware NSX® Manager™ system.
Start the Internet Explorer browser and select vSphere Web Client from the
Infrastructure favorites menu.
If you see the There is a problem with this website’s security certificate
message, click Continue to this website (not recommended).
In vSphere Web Client, click the Home icon and select Hosts and Clusters.
Confirm that the ESXi hosts are connected to SA Compute-01 and SA Management
cluster.
If the ESXi hosts are disconnected, right-click each ESXi host and click
Connection > Connect.
Monitor the tasks in the Recent Tasks pane until all the ESXi hosts are
reconnected.
Confirm that the following virtual machines are running in the SA Management
cluster.
Border-ESG-0
Eng-DLR-0
Fin-DLR-0
NSX_Controller_GUID
RD-DLR-0
If any of these virtual machines are not running power on the virtual machine.
In vSphere Web Client, click the Home icon and select Networking &
Security.
On the Management tab in the right pane, select the single controller that
appears in the lower table.
If the controller status does not show a green check mark, select Update
the Controller State from the Actions menu under NSX Manager.
If the controller status does not show a green check mark, wait for one
minute and repeat the update action.
Wait till green check mark appears in Installation status with the agent
version 6.2.0.
You license VMware vRealize® Log Insight™ and confirm that VMware vSphere®
integration is configured.
Integration for vSphere and VMware vRealize® Operations™ is included in the base
vRealize Log Insight system. The vRealize Log Insight server is designed to
integrate with vCenter Server systems and attached ESXi hosts. When you configure
vRealize Log Insight, it modifies the configuration of vCenter Server systems and
ESXi hosts. The modified configuration enables vCenter Server systems to send
Syslog events to a vRealize Log Insight server.
In Internet Explorer, open a new tab and select LogInsight - Web Console from
the vRA favorites menu.
If you see the There is a problem with this website’s security certificate
message, click Continue to this website (not recommended).
Log in to the Log Insight user name admin and the password VMware1!.
Licenses
Select Administration from the system drop-down menu, located in the top
menu bar, to the right of the user name.
In the right pane, click Add New License Key, enter the vRealize Log
Insight license key in the text box, and click Add License Key.
Click the delete icon (red x) to the right of the expired license.
Click Remove.
Select vSphere under Integration in the left pane of the vRealize Log
Insight administration UI.
Hostname: sa-vcsa-01.vclass.local
Username: administrator@vsphere.local
Password: VMware1!
Verify that Collect vCenter Server events, tasks, and alarms is selected.
Keep Internet Explorer open and connected to the vRealize Log Insight
administration interface.
The construction and application of the agent script is a complex subject that is
beyond the scope of this training. The agent configuration script can be pieced
together using information provided in each content pack. The agent script that you
import was constructed by pasting relevant information from VMware vRealize®
Automation™, Microsoft Active Directory, and the Microsoft SQL Server content
packs.
Select Administration from the vRealize Log Insight system drop-down menu,
located in the top menu bar, to the right of your user name.
In the right pane, click Download Log Insight Agent Version 3.0.0.
Click the Windows MSI (32-bit/64-bit) link and click Save > Save As to save the
file in C:\Materials\Downloads.
Task 5: Install the vRealize Log Insight Agent on Critical Infrastructure Servers
You install the vRealize Log Insight agent on two critical Windows servers.
vRealize Log Insight can be integrated with every aspect of a deployed vRealize
Automation solution, including integration with authentication and database
servers, and vSphere assets.
You configure vSphere integration (the vRealize Log Insight server is already
receiving events) and upload content packs to extend vRealize Log Insight server
charting and analysis to other systems, including Active Directory servers,
Microsoft SQL Server hosts, and NSX for vSphere systems.
You complete integration of the Active Directory servers and Microsoft SQL Server
hosts by installing a vRealize Log Insight agent on each system. Integration with
most products and systems require the installation of a Windows or Linux agent. The
agent behavior is system dependent and further tuned using the agent configuration
script.
The installation of the Windows agent is simple and fast, taking no more than a
minute to complete.
Use the Remote Desktop Connection Manager in the taskbar to connect to the
DC.vclass.local server.
Select I accept the terms in the license agreement and click Next.
Click Finish.
Select I accept the terms in the license agreement and click Next.
Click Finish.
Licenses
In Internet Explorer, select vRA Appliance Console from the vRA favorites menu.
If you see the There is a problem with this website’s security certificate
message, click Continue to this website (not recommended).
Select Licensing.
Request a Service
Use Internet Explorer from the student desktop to log in to the VMware vRealize®
Automation™ system.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
If you see the There is a problem with this website’s security certificate
message, click Continue to the website (not recommended).
Log in to vclass.local domain as End user account user name QA-User13 and the
password VMware1!.
You request a service from vRealize Automation. vRealize Automation can provide
various kinds of services to users. The most common service is to deploy a virtual
machine. You ask vRealize Automation to deploy a Linux Web server.
The description can help you track the purpose of this request.
Click Submit.
Click OK.
You track the requested service from vRealize Automation. Requests must go through
a process. You deploy and customize a virtual machine from a template through a
cloning operation in VMware vSphere®.
The request should be the top item in the list. An initial status of In
Progress should appear.
You will see many requests listed that have a Failed status. These requests
involve an Expire operation. Do not be concerned about these requests. These errors
are caused by a problem in an expiration date.
Click the QA-DB virtual machine icon and examine the details.
Click to enlarge
Click the General tab and examine the configuration of the virtual machine.
Click the Storage tab and examine how many hard disks the virtual machine has.
Click OK.
If you see the There is a problem with this website’s security certificate
message, click Continue to the website (not recommended).
In the bottom-right corner of the Recent Tasks pane, click More Tasks.
Click the refresh icon at the top center of VMware vSphere® Web Client
periodically until you see the Customize virtual machine guest OS task completed
message in the Recent Tasks pane.
Click the vRealize Automation tab in the Internet Explorer browser to return to
the vRealize Automation console.
Click the refresh icon at the bottom of the Requests pane until the status of
the request changes to Successful.
The request should be listed in the Deployments list with today’s date in the
Date Created column. The name of the item should begin with the text string QA-DB,
followed by an eight-digit number.
Select the item but do not open it (click to the right of the deployment name
to highlight the line).
Examine the information and click Close in the lower right of the pane.
You order vRealize Automation to destroy the virtual machine. After an item is no
longer needed, you might be entitled to destroy it. Destroying unneeded items saves
resources.
Click Deployments.
Click to the right of the deployment name to select the item that you deployed.
Verify that this is the item you deployed by checking the Date Created column.
The date shown for this item should match today’s date.
Make sure you have only selected the item you just deployed. Do not destroy any
deployment except the deployment you just created.
Click Actions.
Select Destroy.
Click Submit.
Click OK.
You track the requested action from vRealize Automation. Actions such as Destroy
are requests and can be tracked like all other requests.
Track the request to destroy the virtual machine in vSphere Web Client and in
the vRealize Automation console.
When the virtual machine is powered off and deleted, log out of the vRealize
Automation console and vSphere Web Client.
Examine vSphere
You use VMware vSphere® Web Client to examine the VMware vSphere® architecture that
will support VMware vRealize® Automation™.
You examine the vRealize Automation support infrastructure that was preconfigured
in vSphere.
Expand SA Datacenter.
vRealize Automation should always have at least two clusters. The first cluster
is a management cluster.
Expand SA Management.
Email servers
Most of these systems exist in the lab environment. But due to the limitations
of the lab environment, they are not hosted on the management cluster.
Expand SA Compute-01.
Expand SA Datacenter.
The VRM folder is where vRealize Automation deploys virtual machines. Any
virtual machines in the VRM folder are managed by vRealize Automation. Do not use
vSphere Web Client to manage these machines unless a significant problem occurs in
vRealize Automation.
vRealize Automation can use virtual machine snapshots to create linked clones.
The requirement that both the host and the storage combination are part of the
fabric group is not a requirement for snapshots. As long as a snapshot is stored on
shared storage that is visible to the fabric group, which host the parent virtual
machine is assigned to does not matter.
The best practice for production environments is to use clones and templates
instead of snapshots and linked clones.
Expand SA Datacenter.
You examine the other Windows-based infrastructure servers that will support
vRealize Automation in the lab environment.
Click the Remote Desktop Connection Manager icon on the taskbar of the Student-
A desktop.
Click to enlarge
The Site-A Systems includes a SQL Server host and two IaaS servers.
The SQL Server system hosts databases for vRealize Automation (IaaS server) and
the VMware vCenter Server® system.
Two IaaS servers are included. The SA-IaaS-01 server is the IaaS server for
vRealize Automation. vRealize Automation IaaS runs on Windows servers. In the lab
architecture, this SA-IaaS-01server runs the IaaS Manager, the IaaS Web server, the
IaaS Distributed Execution Manager (DEM), and IaaS proxy agents. In a production
vRealize Automation environment, all of these IaaS components can be assigned to
individual servers.
In a production environment, all of these servers (DC, iSCSI, SQL Server, and
IaaS) would be hosted on the management cluster.
You examine the other Linux-based infrastructure servers that support vRealize
Automation in the lab environment.
Task 1: Explore the vRealize Automation UI for the IaaS Administrator Role
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system using the IaaS administrator role and explore the
components of the interface for this role.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
In the Fabric Groups pane, verify that the Engr-FG fabric group appears in the
list.
Click OK.
In the Log Viewer pane, select Error from the Severity drop-down menu.
Click to enlarge
The logs are sorted according to the [Severity] Equals ‘Error’ type, which
appears at the bottom of the Log View pane.
The logs are sorted according to the [Severity] Equals ‘Information’ type.
Task 2: Explore the vRealize Automation UI for the Fabric Administrator Role
You explore the vRealize Automation system using the fabric administrator role and
examine the various components of the interface for this role.
Select vRA Web Console - Eng Tenant from the vRA favorites menu and log in to
vclass.local domain as Fabric administrator account user name QA-User09 and the
password VMware1!.
ANSWER: Yes.
Click to enlarge
ANSWER: Yes.
Click to enlarge
Click Cancel.
ANSWER: No.
Task 3: Explore the vRealize Automation UI for the Tenant Administrator Role
You explore the vRealize Automation system using the tenant administrator role and
examine the various components of the interface for this role.
Select vRA Web Console - Eng Tenant from the vRA favorites menu and log in to
vclass.local domain as Tenant administrator account user name QA-User01 and the
password VMware1!.
In the left pane, select Users and Groups > Business Groups.
Click Edit.
Q. Which vclass.local group is defined in the group manager role and in the
support role?
ANSWER: QA-BGSuper@vclass.local
Click Cancel.
Task 4: Explore the vRealize Automation UI for the Software Architect Role
You explore the vRealize Automation system using the software architect role and
examine the various components of the interface for this role.
Select vRA Web Console - Eng Tenant from the vRA favorites menu and log in to
vclass.local domain as Software Architect account user name QA-User05 and the
password VMware1!.
ANSWER: No.
Click Cancel.
Click Logout.
Task 5: Explore the vRealize Automation UI for the Catalog Administrator Role
You explore the vRealize Automation system using the catalog administrator role and
examine the various components of the interface for this role.
Select vRA Web Console - Eng Tenant from the vRA favorites menu and log in to
vclass.local domain as Catalog administrator account user name QA-User03 and the
password VMware1!.
ANSWER: Yes.
Click Cancel.
Click Configure.
The Configure Catalog Item pane appears. The status of the catalog item should
be Active.
Click Cancel.
Click Logout.
You explore the Eng tenant configuration from the default tenant.
Select vRA Web Console - Default Tenant from the vRA favorites menu.
Click to enlarge
From the Select the domain drop-down menu, select vsphere.local and click Next.
Verify that the QA-ITSuper group appears in the Tenant administrators pane.
Verify that the QA-IaaS group appears in the IaaS administrators pane.
Click Cancel.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click to enlarge
From the Select the domain drop-down menu, select vclass.local and click Next.
Log in to vclass.local domain as IaaS account user name QA-User01 and the
password VMware1!.
Click the Browse icon to the right of the Credentials text box.
Click to enlarge
Click Cancel.
Click Cancel.
Point to vCenter and select View Compute Resources from the menu.
ANSWER: No.
Click Cancel.
Click Engr-FG.
ANSWER: One.
Click Cancel.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu in the Internet
Explorer browser.
From the goal navigator, select Fabric Configuration > Create Machine Prefixes.
Click to enlarge
Click to enlarge
In the Machine Prefixes pane, verify that the QAWin and QALin machine prefixes
appear.
Verify that the DNS suffix and DNS search suffix appear as vclass.local.
ANSWER: 101
Click Cancel.
ANSWER: Eng-RP
In the Edit Reservation - vSphere pane, verify that the Reservation policy
appears as Eng-RP.
Click Cancel.
Click Logout.
Lab 8 - Exploring Business Group Configuration
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
In the left pane, select Users & Groups > Business Groups.
ANSWER: qa-user10@vclass.local.
Verify that the Group Manager role pane contains the QA-BGSuper group.
ANSWER: QALin.
Click Cancel.
ANSWER: Zero.
Click Logout.
Create a Tenant and Assign Local User Tenant and IaaS Administrators
Sync Groups and Users and Assign Tenant and IaaS Administrators
Create Reservations
Task 1: Create a Tenant and Assign Local User Tenant and IaaS Administrators
The first step to configuring a tenant is to name the new tenant, add it to VMware
vRealize® Automation™, and create the tenant-specific access URL. Next, you specify
local users who can access the tenant and can assign the tenant and IaaS
administrator roles to the newly created users.
Select vRA Web Console - Default Tenant from the vRA favorites menu.
Click Next.
In the User Details window, specify values for the new user.
Option Action
First name
Enter Alex
Last name
Enter Morgan
Enter fin-admin@vclass.local
User name
Enter fin-admin@vsphere.local
Password
Enter VMware1!
Confirm password
Enter VMware1!
Click OK.
Verify that the local user Alex Morgan (fin-admin@vsphere.local) appears in the
Local Users pane.
Click Next.
In the Select users or groups to grant the Tenant administrator role text box,
enter fin-admin, press Enter, and select fin-admin@vsphere.local from the drop-down
menu of matching users.
Click to enlarge
In the Select users or groups to grant the IaaS administrator role text box,
enter fin-admin, press Enter, and select fin-admin@vsphere.local from the drop-down
menu of matching users.
Click Finish.
Click Logout.
Task 2: Sync Groups and Users and Assign Tenant and IaaS Administrators
You use the Directories Management feature to configure a link to Active Directory
to support user authentication and to select users and groups to sync with the
Directories Management directory. After configuration, you can edit the directory
to add additional users and groups.
In the Name text box, enter vRA Web Console - Fin Tenant.
Click Add.
Select vRA Web Console - Fin Tenant from the vRA favorites menu.
You must verify that the link is valid and opens to the Fin tenant.
Click Open.
Click Open.
Click Next.
Click Finish.
Changing the branding of the current tenant might cause problems for Internet
Explorer. If you see an error message, close the Internet Explorer browser. Then
restart Internet Explorer and log back in to the Finance tenant.
The Select the Domains pane appears after a few seconds. The vclass.local
domain should already be selected.
Click Next.
In the Map User Attributes pane, select Enter Custom Input from the drop-down
menu to the right of the manager attribute.
Click to enlarge
Click Next.
Click Next.
Click the green plus sign to the right of the Specify the user DNs title bar.
Click Next.
Click Edit.
The Edit button is to the right of the Sync Frequency page option.
Click to enlarge
Click Save.
The plus sign is to the right of the Specify the group DNs title bar.
Click to enlarge
Click Select.
Click to enlarge
From the Group DNs list, select the Domain Admins group and the Domain Users
group.
Click to enlarge
Click Save.
Click Logout.
Task 3: Assign Tenant and IaaS Administrator Roles to the Fin Tenant
You appoint tenant administrators and IaaS administrators from the identity stores
that you configured for the Fin tenant.
Select vRA Web Console - Default Tenant from the vRA favorites menu.
Click to enlarge
In the Select users or groups to grant the Tenant administrator role text box,
enter BL-ITSuper, press Enter, and select BL-ITSuper@vclass.local from the drop-
down menu of matching users.
In the Select users or groups to grant the Tenant administrator role text box,
enter BL-TA, press Enter, and select BL-TA@vclass.local from the drop-down menu of
matching users.
In the Select users or groups to grant the Tenant administrator role text box,
enter SL-ITSuper, press Enter, and select SL-ITSuper@vclass.local from the drop-
down menu of matching users.
In the Select users or groups to grant the Tenant administrator role text box,
enter SL-TA, press Enter, and select SL-TA@vclass.local from the drop-down menu of
matching users.
In the Select users or groups to grant the IaaS administrator role text box,
enter BL-ITSuper, press Enter, and select BL-ITSuper@vclass.local from the drop-
down menu of matching users.
In the Select users or groups to grant the IaaS administrator role text box,
enter BL-IaaS, press Enter, and select BL-IaaS@vclass.local from the drop-down menu
of matching users.
In the Select users or groups to grant the IaaS administrator role text box,
enter SL-ITSuper, press Enter, and select SL-ITSuper@vclass.local from the drop-
down menu of matching users.
In the Select users or groups to grant the IaaS administrator role text box,
enter SL-IaaS, press Enter, and select SL-IaaS@vclass.local from the drop-down menu
of matching users.
Click Finish.
Click Logout.
You create a fabric group for the Fin tenant and assign fabric administrators to
manage the resources in the fabric group.
Select vRA Web Console - Fin Tenant from the vRA favorites menu.
From the Select the domain drop-down menu, select vclass.local and click Next.
In the goal navigator, select Fabric Configuration > Create Fabric Groups.
In the Fabric administrators text box, enter BL-Fabric, press Enter, and select
BL-Fabric@vclass.local from the drop-down menu of matching users.
In the Fabric administrators text box, enter BL-ITSuper, press Enter, and
select BL-ITSuper@vclass.local from the drop-down menu of matching users.
In the Fabric administrators text box, enter SL-Fabric, press Enter, and select
SL-Fabric@vclass.local from the drop-down menu of matching users.
In the Fabric administrators text box, enter SL-ITSuper, press Enter, and
select SL-ITSuper@vclass.local from the drop-down menu of matching users.
Click OK.
Do not logout.
You log in to the vRealize Automation server as a fabric administrator and create
machine prefixes.
If you are not logged out from the previous session, go to step 5.
Select vRA Web Console - Fin Tenant from the vRA favorites menu.
NOTE: You might need to press F5 to see the option to create machine prefixes.
On the left side of the window, click the green save icon.
Click to enlarge
In the Description text box, enter Reservation Policy for the Finance Tenant.
Click OK.
In the Description text box, enter Network Profile for the existing BL-
Application network.
Click New.
In the Description text box, enter IP Range for the BL-Application Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the existing BL-Data
network.
Click New.
In the Description text box, enter IP Range for the BL-Data Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Application
network.
Click New.
In the Description text box, enter IP Range for the SL-Application Network.
Click OK.
The list of IP addresses is populated in the IP Addresses pane.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Data network.
Click New.
In the Description text box, enter IP Range for the SL-Data Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the existing BL-
Application network.
Click New.
In the Description text box, enter IP Range for the BL-Application Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the existing BL-Data
network.
Click New.
In the Description text box, enter IP Range for the BL-Data Network.
Click OK.
The list of IP addresses is populated in the IP Addresses pane.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Application
network.
Click New.
In the Description text box, enter IP Range for the SL-Application Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Data network.
Click New.
In the Description text box, enter IP Range for the SL-Data Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the existing BL-
Application network.
Click New.
In the Description text box, enter IP Range for the BL-Application Network.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the existing BL-Data
network.
Click New.
In the Description text box, enter IP Range for the BL-Data Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Application
network.
Click New.
In the Description text box, enter IP Range for the SL-Application Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Description text box, enter Network Profile for the SL-Data network.
Click New.
In the Description text box, enter IP Range for the SL-Data Network.
Click OK.
Click OK.
Verify that the external network appears in the Network Profiles pane.
In the Goal Navigator, click Back to My Goals > Tenant Configuration > Create
Business Group and click New.
In the Description text box, enter Billing group for the Finance tenant.
Click Next.
In the Group manager role text box, enter BL-BGMGRs, press Enter, and select
BL- BGMGRs@vclass.local from the drop-down menu of matching users.
In the Support role text box, enter BL-BGMGRs, press Enter, and select BL-
BGMGRs@vclass.local from the drop-down menu of matching users.
In the User role text box, enter BL-User, press Enter, and select BL-
User@vclass.local from the drop-down menu of matching users.
Click Next.
Click Finish.
Verify that the business group appears on the Business Groups page.
Click New.
In the Description text box, enter Sales group for the Finance tenant.
Click Next.
In the Group manager role text box, enter SL-BGMGRs, press Enter, and select
SL- BGMGRs@vclass.local from the drop-down menu of matching users.
In the Support role text box, enter SL-BGMGRs, press Enter, and select SL-
BGMGRs@vclass.local from the drop-down menu of matching users.
In the User role text box, enter SL-User, press Enter, and select SL-
User@vclass.local from the drop-down menu of matching users.
Click Next.
Verify that the business group appears on the Business Groups page.
Click Reservations.
If the tenant is not Fin, select Fin from the drop-down menu.
Click OK.
From the Network Profile drop-down menu to the right of the network path,
select BL-Data-NP.
From the Network Profile drop-down menu to the right of the network path,
select BL-Application-NP.
Click OK.
In the Reservations pane, select New > vSphere.
If the tenant is not Fin, select Fin from the drop-down menu.
Click OK.
From the Network Profile drop-down menu to the right of the network path,
select SL-Application-NP.
From the Network Profile drop-down menu to the right of the network path,
select SL-Data-NP.
Click OK.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click Blueprints.
Click New.
In the Description text box, enter Linux Application Server for RD.
Click OK.
From the Categories pane, drag the vSphere Machine component to the design
canvas.
In the Machine Resources tab, specify the resource values for the blueprint.
Option Action
CPUs
Memory (MB)
Enter 1024 in the Minimum box and 1056 in the Maximum box.
Storage (GB)
Click Save.
Click a blank space on the design canvas to close the vSphere machine dialog
box.
Select RD-Data-NP.
Click OK.
Click a blank spot in the design canvas to close the Network dialog.
The vSphere Machine component is selected and the Design information panel
appears.
Click New.
Click OK.
Click Save.
Click Finish.
You publish the Linux blueprint so that you can configure it as catalog item or use
it as a blueprint component in the design canvas.
You must select the blueprint, not click its name. Clicking the name of a
blueprint opens the blueprint for editing.
Click Publish.
Click Logout.
You create a blueprint for one virtual machine connected to an existing network.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click Blueprints.
Click New.
In the Description text box, enter Linux Web Server for RD.
Click OK.
From the Categories pane, drag the vSphere Machine component to the design
canvas.
In the Description text box, enter Linux Web Server for RD.
In the Machine Resources tab, specify the resource values for the blueprint.
Option Action
CPUs
Memory (MB)
Enter 1024 in the Minimum box and 1056 in the Maximum box.
Storage (GB)
Click Save.
Click a blank space on the design canvas to close the vSphere machine dialog
box.
Select RD-Data-NP.
Click OK.
Click a blank space on the design canvas to close the network dialog box.
The vSphere Machine component is selected and the design panel appears.
Click New.
Click OK.
Click Save.
Click Finish.
Click Publish.
You combine two blueprints with one machine each to create a blueprint with
multiple machines.
In the Description text box, enter Web and DB Multi-Machine App for RD.
Click OK.
Click Save.
Click a clear spot on the design canvas to close the vSphere Machine dialog
box.
Click Save.
Click a clear spot on the design canvas to close the vSphere Machine dialog
box.
Click Finish.
Click Publish.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click New.
Select Linux.png.
Click Open.
In the Owner text box, enter RD-BGMGRs, press Enter, and select RD-
BGMGRs@vclass.local from the list.
In the Support Team text box, enter RD-BGMGRs, press Enter, and select RD-
BGMGRs@vclass.local from the list.
Click OK.
Click Configure.
Click Finish.
You create and configure an entitlement for the service that you configured.
In the Description text box, enter Entitlement for RD Linux App Server.
In the Users & Groups text box, enter RD-User, press Enter, and select RD-
User@vclass.local from the list.
Click Next.
Click the green plus sign (+) next to Entitled Services.
Click OK.
Click OK.
In the Add Actions dialog box, select actions from the list.
Name Type
Create Snapshot
Virtual Machine
Delete Snapshot
Virtual Machine
Destroy
Virtual Machine
Register VDI
Virtual Machine
Revert To Snapshot
Virtual Machine
Unregister VDI
Virtual Machine
Click OK.
Click Finish.
Click Logout.
You log in as a business group manager and request a new service to deploy a new
Linux database server virtual machine on behalf of one of the employees.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Log in to vclass.local domain as Business Group Manager account user name QA-
User02 and the password VMware1!.
In the On behalf of text box, enter QA-User13, press Enter, and select QA-
user13@vclass.local from the list.
In the All Service pane, click Request for the QA-DB service.
In the Reason for request text box, enter QA-user13 database test.
Click Submit.
Click OK.
Click Refresh.
Click to enlarge
Monitor the status of the virtual machine request until Status changes to
Successful.
The deployment takes about 5 minutes. You might need to click Refresh
periodically.
As a business group manager, you manage one of the employee’s machines by modifying
virtual machine settings and changing the power state of the machine.
The virtual machine that you deployed in task 1 appears in the deployments
pane.
In the Machines pane, select, but do not open, the virtual machine.
Click Submit.
Click OK.
Click the refresh icon at the bottom of the right pane and monitor Status until
it changes to Off.
This operation takes about 1 minute to complete. You might need to click the
refresh icon periodically.
The view changes to the Items tab and a New Request to Reconfigure a machine
pane appears.
In the General tab, modify the resource values for the blueprint.
Option Action
CPUs
Enter 2.
Memory (MB)
Enter 1040.
Click Submit.
Click OK.
Click Submit.
Click OK.
Click the refresh icon and monitor Status until it changes to On.
This operation takes about 1 minute to complete. You might need to click the
refresh icon periodically.
As a business group manager, you manage one of the employee’s machines and create
and delete a snapshot.
In the Snapshot name text box, click the X to the right of the text box.
You might have to click the text box to make the X appear.
In the Snapshot name text box, enter Snapshot 001 before DB upgrade.
Click Submit.
Click OK.
Click the refresh icon and monitor the request until Status changes to
Successful.
This operation takes about 1 minute to complete.You might need to click the
refresh icon periodically.
Click Items.
Refresh the browser if Delete Snapshot option doesn't appear in the Actions
pane
Click Select.
This snapshot is the snapshot whose name you recorded in step 14.
Click Select.
Click Submit.
Click OK.
Click Submit.
Click OK.
This operation takes about 2 minutes to complete.You might need to click the
refresh icon periodically.
Click Close.
You might have to scroll down on the screen to see the Close button.
Click Logout.
You assign an approval policy administrator to the tenant. The approval policy
administrator creates approval policies for use in the tenant when a user requests
a virtual machine with more memory.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click New.
In the New Approval Policy dialog box, scroll down and select Service-Catalog-
Catalog Item Request-Virtual Machine.
Click OK.
In the Description text box, enter Approval needed for virtual machines with
more RAM.
In the Description text box, enter Any request for a virtual machine with more
RAM than 1024MB requires approval.
From the drop-down menu that appears to the right of the Memory (MB) text box,
select > (the greater-than sign).
In the search box under Approvers, enter QA-BGSuper, press Enter, and select
QA-BGSuper@vclass.local from the search results.
Click OK.
Click OK.
Click Entitlements.
Click Edit.
Under Entitled Items, select Modify Policy from the drop-down menu to the right
of the QA-DB text box.
From the Apply this policy drop-down menu, select QA-MoreRAM [Service Catalog -
Catalog Item Request - Virtual Machine].
Click OK.
Click Finish.
Click Logout.
You submit a request from the catalog as a user. You verify that the request enters
a pending state as a business group administrator and you approve the request.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Log in to vclass.local domain as no administrator roles account user name QA-
User13 and the password VMware1!.
In the Reason for request text box, enter DB required with larger memory
requirements.
In the left pane under the QA-DB blueprint, click the QA-DB virtual machine.
Click to enlarge
In the Memory (MB) box, click the up arrow to increase the value of memory to
1056.
Click to enlarge
Click Submit.
Click OK.
Q. Who is the approver for this request listed on the left side of the pane?
ANSWER: QA-BGSuper
Click OK.
Click Logout.
You log in as the assigned approver. You then process and approve a request for a
virtual machine with increased memory, according to the approval policy. Finally,
you log in as the user who requested the virtual machine with increased memory to
verify that the request is approved.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click the number of the approval request (approval request number 1).
In the Approvals pane, verify that Requester matches the user that requested
the QA-DB blueprint.
Click the QA-DB virtual machine in the left pane of the Request details dialog
box.
Q. Does the Memory (MB) value match the amount previously requested?
ANSWER: Yes.
In the Justification text box, enter Approved, this machine requires increased
memory.
Click Approve.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click Refresh and monitor the status of the request until Status appears as
Successful.
This operation might take up to 3 minutes to complete. You might have to click
Refresh several times.
Ignore any Expire error messages. These messages relate to a expiration problem
that will be corrected in a later lab.
Verify that Approver matches the user that you used to approve the request and
click OK.
Click Logout.
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Use Internet Explorer to select vRA Web Console - Eng Tenant from the vRA
favorites menu.
Click New.
Enter the name of the property definition exactly as specified. The name of the
property definition is used in blueprints and in VMware vRealize® Orchestrator™
workflows.
In the Description text box, enter Allow end users to select which network they
will connect to their virtual machine.
You must enter the value exactly as specified. The text that you enter in the
Value text box must match the name of a vRealize Automation network profile. The
value is case-sensitive.
Click OK.
Click OK.
Click OK.
Click OK.
Click New.
In the Description text box, enter Allow end users to select the disk format of
their virtual machine.
Click OK.
Do not logout.
Lab 16 - Creating a Property Group
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Click New.
In the Description text box, enter Group together the custom properties that
users will need to deploy virtual machines.
You must enter the name exactly as specified. The text that you enter in the
Name text box must match the name of an existing custom property. The name is case-
sensitive. Many custom property names also have periods in the names for
readability. These periods must be entered exactly as specified.
As you enter text, you see the names of similar custom properties appear below
the Name text box. Only properties defined in the property dictionary appear. This
feature helps you enter the name correctly. You can click the correct value and
press Enter to load it into the Name text box.
Do not enter a value in the Value text box and do not click OK.
Click OK.
Click OK.
Click OK.
Click Logout.
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
If a security certificate warning appears, click Continue to this website.
Click Copy.
In the Description text box, enter Linux DB Server for QA that uses custom
properties.
Click OK.
Click Add.
Select QA.VMProperties.
Click OK.
Click a clear area in the Design Canvas to close the virtual machine dialog
box.
Click Yes.
Click Save.
Click Finish.
Click Publish.
If the Administration pane shows Property Dictionary menu items, you must click
<Administration to see Catalog Management in the main Administration menu.
Click Services.
Click New.
In the Description text box, enter A collection of Linux virtual machines for
QA.
Click Browse and select the Linux.png icon from the C:\Materials\Graphics
directory.
In the Owner text box, enter QA-B and click the search icon.
Select QA-BGMGRs.
In the SupportTeam text box, enter QA-S and click the search icon.
Select QA-Support.
Click OK.
Click Close.
Click Entitlements.
Click New.
In the Users & Groups text box, enter QA-U and click the search icon.
Select QA-User.
Click Next.
Click OK.
Click Finish.
Click QA-General-Services.
A red asterisk next to QA-DB indicates that the item requires user input.
Click Requests and monitor the progress of the request until the status is
Successful.
Click the Execution Information icon in the upper right corner of the pane.
Click to enlarge
Select vSphere Web Client from the Infrastructure favorites menu and log in as
administrator@vsphere.local with the password VMware1!.
Expand SA Datacenter.
The type of the hard disk should be Thick provision lazy zeroed because you
selected No on the custom property controlling thin disk provisioning in task 5.
Click Cancel.
The network that the virtual machine is connected to should be the QA-
Application network that you specified when you requested this virtual machine.
Click Submit.
Click OK.
Click the Requests tab and monitor the progress of the request until the status
is Successful.
Copy a Blueprint
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Select vRA Web Console - Default Tenant from the vRA favorites menu.
You create a network profile in the vRealize Automation default tenant. Before you
can add an on-demand network address translation network to a blueprint, you must
have a NAT network profile in the default tenant.
Click Reservations.
Click New.
Select NAT.
In the Description text box, enter Network profile for on-demand NAT network in
the RD business group.
Primary DNS
172.20.11.10
DNS suffix
vclass.local
vclass.local
Click New.
In the Ending IP address text box, enter 10.10.108.50 and click OK.
Click OK.
You use Internet Explorer from the student desktop to log in to the vRealize
Automation system.
In Internet Explorer, select vRA Web Console - Eng Tenant from the vRA
favorites menu.
Click Copy.
From the Routed gateway reservation policy drop-down menu, select Eng-RP and
click OK.
You remove the existing network from this blueprint and add VMware NSX® on-demand
NAT network.
In the Categories panel, select On-Demand NAT Network and drag it to the design
canvas.
Click OK.
Click Save.
Click a blank spot in the design canvas to close the network dialog box.
Select the RDLin machine prefix in the Machine prefix drop-down menu.
Click New.
Click OK.
Click Save.
Click Finish.
You add a service and an entitlement to enable users to deploy virtual machines and
on-demand networks from their catalog.
Click Services.
Click New.
In the Description text box, enter Linux VM with on-demand NAT network
connected to the Production network.
Click Browse and select the Linux.png graphic icon from the
C:\Materials\Graphics directory.
In the Owner text box, enter RD-B and click the search icon.
Select RD-BGMGRs.
In the Support Team text box, enter RD-S and click the search icon.
Select RD-Support.
Click OK.
Click Entitlements.
Click New.
In the Users & Groups text box, enter RD-U and click the search icon.
Select RD-User.
Click Next.
Click OK.
Click Finish.
Request a Service
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
If you are still logged in to the vRealize Automation console, skip to task 2.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Log in to vclass.local domain with RD-User group account user name RD-User01
and the password VMware1!.
The description can help you track the purpose of this request.
The request should be the top item in the list. An initial status of In
Progress should be displayed.
If you do not have an Internet Explorer tab open with the VMware vSphere® Web
Client, then open a tab.
Select vSphere Web Client from the Infrastructure favorites menu and log in
as administrator@vsphere.local with the password VMware1!.
Click the Home icon and select VMs and Templates.
In the bottom-right corner of the Recent Tasks pane, click More Tasks.
Click the refresh icon at the top center of vSphere Web Client periodically
until you see the Customize virtual machine guest OS task complete message in the
Recent Tasks pane.
Do not change any of the settings on the new NSX Edge device.
The Start IP should be set to 10.10.108.60. and the End IP should be set to
10.10.108.80.
Open a remote console to the virtual machine that you just deployed.
Use ifconfig -a command to confirm that this virtual machine has an IP address
from the DHCP range of 10.10.108.60 to 10.10.108.80.
Click the vRealize Automation tab in the Internet Explorer browser to return to
the vRealize Automation console.
Click the refresh icon at the bottom of the Requests pane until the status of
the request changes to Successful.
The request should be the bottom item in the Deployments list. The name of the
item should begin with the text string RD-DB-On-Demand-NAT, followed by an eight-
digit number.
Examine the information and click Close in the lower right of the pane.
The components should include an NSX Edge device and a VMware NSX® network.
You order vRealize Automation to destroy the virtual machine and on-demand network.
The request should be the bottom item in the Deployments list. The name of the
item should begin with the text string RD-DB-On-Demand-NAT, followed by an eight-
digit number.
Click Actions.
Select Destroy.
Click Submit.
Click OK.
This Destroy action powers off and destroys all of the items included in this
deployment. Destroyed items include the virtual machine, the new NSX Edge device,
and the new distributed port group on the SA Production network.
You track the requested action from vRealize Automation. Actions such as Destroy
can be tracked like requests.
Using what you have learned, track the request to destroy the virtual machine
in vSphere Web Client and in the vRealize Automation console.
When the virtual machine is powered off and deleted, log out of the vRealize
Automation console and vSphere Web Client.
Copy a Blueprint
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Select vRA Web Console - Default Tenant from the vRA favorites menu.
You create a network profile in the vRealize Automation default tenant. Before you
can add an on-demand routed network to a blueprint, you must have a network profile
in the default tenant for the transport network that the on-demand network will
connect to.
Click New.
Select External.
Click OK.
You create a network profile in the vRealize Automation default tenant. Before you
can add an on-demand routed network to a blueprint, you must have a routed network
profile in the default tenant.
Select Routed.
In the Description text box, enter Network profile for on-demand Routed network
in the RD business group.
Primary DNS
172.20.16.1
DNS suffix
vclass.local
vclass.local
In the Ending IP address text box, enter 10.10.110.126 and click OK.
Click New.
In the Ending IP address text box, enter 10.10.110.254 and click OK.
Click OK.
You modify the reservation for the RD business group. The network profile for the
transport network and the routed network must be identified in the reservation
before you can use them.
Click Reservations.
Click RD-Res.
Use the Network Profile drop-down menu to select the RD-Transport-NP network
profile.
Click to enlarge
Use the Network Profile drop-down menu to select the RD-Transport-NP network
profile.
Click to enlarge
Click OK.
Click Logout.
If you open this blueprint instead of selecting it, click Cancel and discard
the changes.
Click Copy.
From the Routed gateway reservation policy drop-down menu, select Eng-RP and
click OK.
You remove the existing network from this blueprint and add a VMware NSX® on-demand
NAT network.
In the Categories panel, select an On-Demand Routed Network and drag it to the
design canvas.
Select RD-Routed-NP.
Click OK.
Click Save.
Click a blank space on the design canvas to close the network dialog box.
In the design canvas, select the QA-DB virtual machine.
Click New.
Click OK.
Click Save.
Click Finish.
You add a service and an entitlement to enable users to deploy virtual machines and
on-demand networks from their catalog.
Click Services.
Click New.
In the Description text box, enter Linux VM with on-demand Routed network.
Click Browse and select the Linux.png graphic icon from the
C:\Materials\Graphics directory.
In the Owner text box, enter RD-B and click the search icon.
Select RD-BGMGRs.
In the Support Team text box, enter RD-S and click the search icon.
Select RD-Support.
Click OK.
Click Close.
Click Entitlements.
Click New.
In the Description text box, enter Entitlement for Linux VM with on-demand
routed network.
In the Users & Groups text box, enter RD-U and click the search icon.
Select RD-User.
Click Next.
Click OK.
Click Finish.
Lab 21 - Deploying a Virtual Machine That Includes a VMware NSX On-Demand Routed
Network
Request a Service
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
If you are already logged in to the vRealize Automation console, skip to task
2.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
The description can help you track the purpose of this request.
The request should be the top item in the list. An initial status of In
Progress should be displayed.
Click the refresh icon at the bottom of the Requests pane until the status of
the request changes to Successful.
Select vSphere Web Client from the Infrastructure favorites menu and log in as
administrator@vsphere.local with the password VMware1!.
The network that the virtual machine is connected to should be a long name that
contains the string RDRoutedNP
Click to enlarge
Examine the summary of the virtual machine. You should see a hardware address
that is in the 10.10.110.0/24 network.
Log in to the virtual machine with the root user name and a password of
VMware1!.
ping 172.20.11.10
You order vRealize Automation to destroy the virtual machine and on-demand network.
The request should be listed in the Deployments list. The name of the item
should begin with the text string RD-DB-On-Demand-Routed, followed by an eight-
digit number.
Click Actions.
Select Destroy.
Click Submit.
Click OK.
Lab 22 - Creating Software Blueprints
Add a Service
Add an Entitlement
You prepare a template to use with a combined blueprint for applications in VMware
vRealize® Automation™.
Use Internet Explorer to start VMware vSphere® Web Client from the
Infrastructure favorites menu and Log in as user administrator@vsphere.local and
the password VMware1!.
After the Centos-Temp-Noguest virtual machine starts up, open a remote console.
At this point you would use the yum install –y Red_Hat_package_name command to
install the following packages:
openssh
wget
perl
telnet
nc
In the lab environment this Linux template already has these packages
installed.
nano /etc/sysconfig/selinux
Download the guest agent prepare script from the vRealize Automation appliance.
wget https://sa-vra-
01.vclass.local:5480/service/software/download/prepare_vra_template.sh --no-check-
certificate
chmod +x prepare_vra_template.sh
./prepare_vra_template.sh
Task 3: Modify the vRealize Automation Agent Configuration for Red Hat
You modify the vRealize Automation agent configuration to support CentOS, which is
a Red Hat version of the Linux operating system.
nano /opt/vmware-appdirector/agent-bootstrap/vmware_vra_software_agent
Use the down arrow key to scroll until you locate the following lines.
if [ -f /etc/rc.d/init.d/functions ]; then
. /etc/rc.d/init.d/functions
. /etc/init.d/functions
fi
Delete the symbolic link and replace it with the new agent.
rm /etc/init.d/vmware_vra_software_agent
cp /opt/vmware-appdirector/agent-bootstrap/vmware_vra_software_agent
/etc/init.d/vmware_vra_software_agent
You must enter th cp command on a single line. What looks like a slash (/)
followed by a carriage return is /etc/init.d/vmware_vra_software_agent.
Click to enlarge
Right-click the Centos-Temp-Noguest virtual machine and select Power > Shutdown
Guest OS and click Yes when prompted.
Do not change the name of the template. The name of the template must remain
Centos-Temp-Noguest. This template name is registered in the vRealize Automation
inventory. If you change the name, you will have to rerun data collection on the
vSphere inventory.
Open a new tab in internet explorer and select vRA Web Console - Eng Tenant
from the vRA favorites menu.
Enter This is an Apache Web server for CentOS Linux machines in the Description
text box.
Click Next.
Click Next.
Confirm that Bash is selected from all four ScriptType drop-down menus.
#!/bin/bash
The script should take two lines and look exactly like the script in the
screenshot.
Click to enlarge
Click OK.
The script appears like a single line, but the script is still two lines.
#!/bin/bash
Click OK.
#!/bin/bash
yum remove -y httpd
Click OK.
When you finish entering all three scripts, the Actions pane should look like
the screenshot.
Click to enlarge
Scripts are unique to each operating system. In Windows systems, you use batch
command scripts and Windows PowerShell scripts. In some versions of Linux, the
scripts are bash commands, but the commands might vary. For example, in Ubuntu
Linux systems you use apt-get install -y apache2 to install the Apache Web server
instead of yum install -y httpd. The best practice is to always have a unique
software blueprint for each operating system, even if you are installing exactly
the same software.
Click Next.
Click Finish.
Click Publish.
You create a software components blueprint to install the Apache Web server.
In the internet explorer, select vRA Web Console - Eng Tenant from the vRA
favorites menu
Select Blueprints.
Select Eng-RP from the Routed gateway reservation policy drop-down menu.
Click OK.
Existing Network
Select ProductionNP
vSphere Machine ID
Enter QA-Apache-Web-Server
Reservation Policy
Select Eng-RP
Machine prefix
Select QALin
Select Clone
Clone from
Select Centos-Temp-Noguest
Customization Spec
Enter Lin-Cust
Network
Select ProductionNP
Select Static IP
Network Address
Drag the Apache Web Server component into the QA-Apache-Web-Server machine.
Click Save.
The combined blueprint should look like the blueprint in the screenshot.
Click to enlarge
Click Finish.
Select Services.
Add a service.
Name
Enter QA-Apache-Web-Server-Service
Description
Icon
Browse to C:\materials\graphics\vCAC6IconPack\OperatingSystems\centos-logo-
200.png
Status
Select Active
Owner
Enter QA-BGSuper
Support Team
Enter QA-Support
Click OK.
Click OK.
Select Entitlements.
Add an entitlement.
Name
Enter QA-Apache-Web-Server-Entitlement
Description
Status
Select Active
Business Group
Select QA
Enter QA-User
Entitled Services
Click QA-Apache-Web-Server-Service
Entitled Items
Click QA-Apache-Web-Server
Entitled Actions
Click Finish.
You deploy a Web server by requesting a service from VMware vRealize® Automation™.
If you are not logged in, log in to the vRealize Automation console.
Use Internet Explorer on the student desktop and select vRA Web Console -
Eng Tenant from the vRA favorites menu
Click Submit.
Click OK.
When the request is successful and a State changed to On message appears in the
Audit Log, go to task 2.
View the Details column to determine the name of the created virtual machine.
Click to enlarge
The test Web page of the new Web server should appear.
Click to enlarge
You uninstall the Web server while leaving the virtual machine intact.
Switch to the vRealize Automation Web console for the Eng tenant.
If you are not still logged in as QA-User01 with the password VMware1!, log
back in.
Expand the QA-Apache-Web-Server deployment until you can see the Apache Web
Server component.
Click to enlarge
Click Actions.
Select Destroy.
Click Submit.
Click to enlarge
Click OK.
Switch to the tab on Internet Explorer where you tested the Web server’s
default page in task 2.
Verify that the virtual machine still exists and is still running.
Run the service httpd status command to verify the uninstallation of the http
daemon.
You should also see a message that indicates that the httpd service is not
found ( Reason: No such file or directory) and that the httpd service is inactive
(dead).
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
If you are already logged in to the vRealize Automation console in the Eng
tenant, log out.
Use Internet Explorer and select vRA Web Console - Default Tenant from the vRA
favorites menu.
You analyze the amount of resources that are already allocated in reservations.
Click Reservations.
Click Reservations.
If resources are not available, requests will fail. To fulfill the request, the
assigned reservation must have enough machines, quota, memory, and storage
available to process the request.
Click IP Ranges.
Examine the listed IP addresses.
Click <Infrastructure.
Click Monitoring.
The monitoring panes (Audit Log, DEM Status, Log, and Workflow History) are
available only to users who are assigned the IaaS administrator role.
In the Name text box, enter Workflow failed and click Save.
From the Filter drop-down menu, select Clear.
The Log Viewer pane includes log information of various types from multiple
sources, including Distributed Execution Manager (DEM) workers, agents, vRealize
Orchestrator, and various vRealize Automation subsystems. This information is some
of the most comprehensive and valuable information for troubleshooting
configuration and communications problems in vRealize Automation.
The audit log in the Audit Log Viewer pane provides details about the status of
managed virtual machines and activities performed on these machines during
reconfiguration. The log includes information about machine provisioning,
reclamation, and reconfigure actions.
You use the system administrator role to analyze vRealize Automation system-level
events.
Start Internet Explorer on the student desktop and select vRA Web Console -
Default Tenant from the vRA favorites menu.
The system administrator event logs cover high-level events in the vRealize
Automation system. Only users with system administrator-level authority can examine
these events.
Click OK.
Destroy a Machine
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Use Internet Explorer on the student desktop and select vRA Web Console - Eng
Tenant from the vRA favorites menu.
Click Reclamation.
Click the expansion icon (double down arrow) in the upper-right part of the
pane to display the advanced search options.
ANSWER: The machine has expired but is not scheduled to be destroyed yet.
Deselect all machines.
Select QALin006.
Enter We are low on resources. Are you using this? in the reason for Request
text box.
Click Submit.
Click Close.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Log in to vclass.local domain as user account name QA-User13 and the password
VMware1!.
Click Inbox.
In the right pane, click on the number of the reclamation request to open it.
Click Logout.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
Log in to vclass.local domain as user account name QA-User01 and the password
VMware1!.
Click Reclamation.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
The business manager of a business group has the power to modify the leases of
deployed machines and to destroy deployed machines.
Click Deployments.
Click Deployments.
Select a machine.
It is owned by QA-User13.
Click Submit.
Click OK.
Click Logout.
You configure Windows PowerShell settings on the domain controller. The domain
controller is also the local DNS server.
Start the Remote Desktop Connection Manager from the shortcut on the taskbar.
Unencrypted communication means that vRealize Orchestrator can use the HTTP
protocol instead of the HTTPS protocol while communicating with the Windows
PowerShell host. Encrypted communication requires an exchange of valid digital
certificates.
set-executionpolicy bypass
Enter Y.
The shortcut is on the desktop. If you have any other applications open, for
example, Internet Explorer, you will have to minimize those applications first.
Verify that Run is selected from the VMware vRealize Orchestrator mode drop-
down menu.
Expand Library > PowerShell > Configuration and select Add a PowerShell host.
In the top of the right pane, click the Start workflow icon (green triangle).
Click Next.
Leave the Host Type drop-down menus set to their default selections.
Option Default Selection
WinRM
Transport protocol
HTTP
Authentication
Basic
Click Next.
Click Submit.
When the workflow runs successfully, you should see a green check mark in the
left pane next to Add a PowerShell host. If you do not see a green check mark,
repeat the steps 6 through to 17.
You create a vRealize Orchestrator workflow to add a DNS host record to a DNS
domain.
Enter vRA Custom Workflows in the Folder name text box and click OK.
Right-click the vRA Custom Workflows folder in the left pane and select New
Workflow.
Enter Add DNS-Host in the Workflow name text box and click OK.
Click the Inputs tab.
Click arg_in_0.
Enter hostName in the Choose attribute name text box and click OK.
Use camel case for all parameter and attribute names in vRealize Orchestrator.
To use the supplied script later in this lab, you must use the precise name
that is specified for each parameter. The name is case-sensitive. If you do not use
the precise name provided, the workflow does not work.
Enter a description of IP address of new host in DNS and DNS zone name for
the ipAddress and zoneName parameters.
In the VMware vRealize® Automation™ UI, most panels have an OK button which
must be clicked to save changes. In vRealize Orchestrator, the UI does not have an
OK or Finish button on many windows. After you make changes or enter new parameters
and attributes, you can click another tab without losing the work.
You have to scroll down to the bottom of the window to see the Attributes
panel.
Click to enlarge
Click OK.
Drag a scriptable task from the left pane to the center of the new workflow in
the right pane, placing the scriptable task element between the green start element
and the end element.
Click to enlarge
The VMware vRealize Orchestrator window opens for the scriptable task.
Click the IN tab in the VMware vRealize Orchestrator scriptable task window.
Select hostName.
Select ipAddress.
Select zoneName.
Select cmdletName.
Click to enlarge
Click Select.
Click Select.
Click Scripting.
The objective is to create a command that is a single string. The use of single
and double quotation marks with variables should produce a command string that
looks like the model.
Assume, for example, that the input parameters have the following values:
hostname = "QALin007"
zoneName = "vclass.local"
ipAddress = "172.20.11.192"
The command that goes to Windows PowerShell looks like the following example:
Instead of trying to enter this complicated script, you will copy and paste it
in the following steps.
Click Close.
Click the File Explorer icon on the taskbar of the student A desktop.
Go to C:\Materials\Powershell.
Click Edit.
Press Ctrl+C.
Variables and parameters appear in purple. String items appear in green. the
script should look like the example.
pshellCommand = cmdletName +' -Name "' + hostName + '" -ZoneName "' + zoneName
+ '" -CreatePtr -IPv4Address "'+ipAddress+'"'
Click Close.
Click Save.
Drag a workflow element from the left pane to the schema, placing the workflow
element between the Build Command icon and the End workflow element.
Click Setup on the question, Do you want to add the activity’s parameters as
input/output to the current workflow?.
Before you add values in this pane it is a good idea to increase the size of
the window. Carefully move the mouse to the bottom-right corner and click the
corner. Then grab the corner and drag to the lower right to increase the size of
the window.
Click Select.
Click Promote.
Task 6: Configure Binding for the Invoke a Windows PowerShell Workflow Element
You configure binding to properly handle input and output parameters in the new
workflow element.
Point to the line that connects script in the In Parameters pane to script in
the center pane.
Drag pshellCommand in the In Attributes pane to the script string in the center
pane.
Click the Validate icon (check mark) above the right pane.
Click Close.
Click the Remote Desktop Connection Manager icon on the student A desktop
taskbar.
Click the Start button on the dc.vclass.local desktop and select Administrative
Tools.
Double-click DNS.
In the right pane, click the Name column to sort the host records by name.
Scroll down the list of records and confirm that no Host (A) record for a host
named QALin777 exists.
Click the vRealize Orchestrator client icon on the student A desktop taskbar.
In the left pane, select the Add DNS-Host workflow in the vRA Custom Workflows
folder.
Enter QALin777
Enter vclass.local
Click Submit.
The workflow takes a few seconds to run. The end element (target) should turn
green.
Click the Remote Desktop Connection Manager icon on the student A desktop
taskbar.
Examine the vclass.local forward lookup zone and confirm that a Host (A) record
for QALin777 with an IP address of 172.20.11.57 exists.
You use Internet Explorer from the student desktop to log in to the vRealize
Automation system.
Use Internet Explorer on the student desktop and select vRA Web Console - Eng
Tenant from the vRA favorites menu.
Click XaaS.
Expand Orchestrator.
Click Next.
Enter This blueprint will add a DNS Host (A) record to the DNS server running
on dc.vclass.local in the Description text box.
Click Next.
Click Next.
Click Finish.
Add the Add DNS-Host blueprint catalog item to the Add DNS-Host service.
Task 10: Test the vRealize Orchestrator Workflow from the XaaS Blueprint
Click Next.
Enter QALin888
Enter 172.20.11.58
Enter vclass.local
Click Submit.
Click OK.
Track the request status and wait for its successful completion.
Click the Remote Desktop Connection Manager icon on the student A desktop
taskbar.
Examine the vclass.local forward lookup zone and confirm that a Host (A) record
for QALin888 with an IP address of 172.20.11.58 exists.
Click the Windows Explorer shortcut on the desktop taskbar to open Windows
Explorer.
Browse to C:\Materials\Downloads\VMware.
Click Extract.
Enter cloudclient.
Click the command prompt icon on the taskbar to open a Command Prompt window.
Enter cd c:\materials\cloudclient\bin.
Click the C:\ icon in the upper-left corner of the Command Prompt window to
change the properties of the Command Prompt window.
Click to enlarge
Select Properties.
Enter cloudclient.bat.
Press the spacebar multiple times to scroll through the license agreement.
Enter Y.
Cloudclient:
sa-vra-01.vclass.local
vRA username:
qa-user01@vclass.local
VMware1!
You might need to widen the Command Prompt window to clearly see the ID string
for each blueprint. If a width of 140 is not wide enough, try 160 or 180. You can
use the up arrow to repeat the vra content list command.
For example:
Click the Windows Explorer icon on the taskbar of the student A desktop.
Browse to c:\materials\cloudclient.
Click Extract.
Close WordPad.
Select WordPad.
ANSWER: QA-Data-NP
ANSWER: CloneWorkflow
Close WordPad.
Create a Workflow
Copy a Blueprint
You use the vRealize Orchestrator Client shortcut from the student desktop to log
in to the VMware vRealize® Orchestrator™ system.
You create a workflow to add a disk drive and more memory to a provisioned virtual
machine.
Expand the vRA ICM Class Workflows folder in the left pane.
Select No.
Click Submit.
You use Internet Explorer from the student desktop to log in to the VMware
vRealize® Automation™ system.
Select vRA Web Console - Eng Tenant from the vRA favorites menu.
You use Internet Explorer from the student desktop to log in to the vRealize
Automation system.
Click Design.
Click OK.
Click Save.
Click Finish.
Click Publish.
Click Services.
Click the green plus (+) to add a new catalog item to this service.
Select QA-DB-Day-2.
Click OK.
Click Close.
Click Entitlements.
Click QA-General-Entitlement.
Click Finish.
Click Design.
Click XaaS.
The input parameters here match the input parameters in the vRealize
Orchestrator workflow.
Click Next.
Verify that IaaS VC VirtualMachine is selected for the Resource type and vm for
Input parameter drop-down menu.
Click Next.
Enter Add a second disk drive and change the RAM setting on the virtual machine
in the Description text box.
You configure the target criteria for the XaaS resource action. This controls which
blueprints can use this action.
Click Next.
You configure the form for the XaaS resource action. The form is used to guide end
users on the selection of appropriate values.
In the right pane, scroll down and select Value... in the Default value box.
Select Constant.
Select Constant in the visible box and select No from the drop-down menu.
Click Apply
In the center pane, click Search in the Disk persistence mode box.
In the right pane scroll down and select Value... in the Default value box.
Select Constant.
Select No.
Click Apply.
In the center pane, click inside the SCSI controller bus number box.
In the right pane, scroll down and select Value... in the Default value box.
Select Constant.
Select No.
Click Apply.
Click Finish.
Click Publish.
Click Entitlements.
Click QA-General-Entitlement.
You deploy a new virtual machine to test the new resource action.
Click QA-General-Services.
Click Submit.
Click OK.
Wait for the status of the request to change from In Progress to Successful.
Click Next.
Click Select+ in the Datastore in which to put the virtual disk file box.
Click Select.
Click Submit.
Click OK.
Click the Requests tab.
Wait for the status of the request to change from In Progress to Successful.
If closed, open a new tab and select vSphere Web Client from Infrastructure
drop-down menu and log in with user name administrator@vsphere.local and the
password VMware1!.
Verify that you have a second hard disk of size 10 GB and that the RAM is now
set to 2048 MB.
You destroy the virtual machine you just requested to save resources.
Create a Workflow
Modify a Blueprint
Create a Subscription
Add Conditions to the Subscription
You use the VMware vRealize® Orchestrator™ client shortcut from the student desktop
to log in to the vRealize Orchestrator system.
To see the vRealize Orchestrator shortcut on the desktop, you might have to
minimize other items such as Internet Explorer.
Click Continue to proceed with an untrusted connection and wait for the login
window to appear.
Verify that Run is selected from the VMware vRealize Orchestrator drop-down
menu.
Click to enlarge
Expand the vRA ICM Class Workflows folder in the left pane.
Right-click the Copy of Add DNS Host workflow and select Duplicate workflow.
Enter EBS Add DNS-Host in the New workflow name text box.
Click Submit.
Verify that the EBS Add DNS-Host workflow is selected in the left pane and
click the edit icon (pencil) above the right pane.
If the value for the host attribute for PowerShell:PowerShellHost is Not Found,
set the PowerShell host.
Click to enlarge
Expand PowerShell.
Select DomainController.
Click Select.
You configure input parameters and attributes for the workflow to use it with the
event broker service.
Click the edit icon (pencil) in the right pane to edit the workflow.
Select the hostName parameter by clicking to the right of the parameter name.
Clicking the parameter name opens a dialog box that enables you to change the
name. Do not change the name of these parameters.
If you accidentally open the attribute name dialog box, click Cancel.
Click arg_in_0.
Enter payload in the Attribute name text box and click OK.
Click string.
This action converts the new payload input parameter from a string type
variable to a properties type variable. vRealize Automation requires a single input
parameter of a properties type to pass an array of custom properties from the event
broker service to vRealize Orchestrator when the workflow is called by the vRealize
Automation event broker subscription. The input parameter can have any name. In
this workflow, you use the name payload. There should only be one properties type
variable defined as an input parameter in a workflow that is called by the event
broker service.
Click Save.
You will see a message about errors. Ignore it. Those errors will be resolved
in the next task.
You modify the new workflow to use it with the event broker service by adding a new
scriptable task.
Drag a scriptable task from the left pane into the workflow and place it
between the start arrow and the Build Command scriptable task.
Click to enlarge
Point to the new scriptable task and click the pencil icon to open the task for
editing.
Select payload.
Select hostName.
Select ipAddress.
Click Select.
Select ipAddress.
Click Select.
Click Close.
The script must be entered exactly as shown. Use the text file on the student
desktop in C:\Materials\CutAndPaste\Lab24-LifecycleEBS.txt. You can copy and paste
the script from the text file into the Scripting pane.
vCACVMProperties = machine.get("properties") ;
NetworkName=vCACVMProperties.get("VirtualMachine.Network0.Name");
var
networkProfile=vCACVMProperties.get("VirtualMachine.Network0.NetworkProfileName");
ipAddress=vCACVMProperties.get("VirtualMachine.Network0.Address");
hostName=machine.get("name");
Click Close.
Click Validate.
Switch back to Internet Explorer and select vRA Web Console - Eng Tenant from
the vRA favorites menu.
Click Administration.
Click Cancel.
Verify that you have an existing QA.VMProperties group that matches this group:
Click to enlarge
Click Cancel.
You modify a blueprint to add DNS information to the DNS server after the virtual
machine is provisioned.
Click Design.
Click Copy.
Click OK.
Click the QA-DB virtual machine.
Click Add.
Select QA.VMProperties.
Click OK.
Click New.
Enter
Extensibility.Lifecycle.Properties.VMPSMasterWorkflow32.MachineProvisioned in the
Name text box.
Enter the name of the property exactly as specified. You can use the text file
on the student desktop in C:\Materials\CutAndPaste\Lab24-LifecycleEBS.txt. You can
copy and paste the text string in the Name text box.
This action passes all of the custom properties to this blueprint during the
VMPSMasterWorkflow32 workflow Machine Provisioned event.
Click OK.
Click Save.
Click any clear space in the design canvas to close the virtual machine in the
blueprint.
Click Yes.
This change leaves the blueprint with no network. The network is selected when
the service is requested.
Click Save.
Click Finish.
Click Publish.
Click Services.
Select QA-DB-Add-DNS.
Click OK.
Click Close.
Click Entitlements.
Click QA-General-Entitlement.
Click Finish.
You create a subscription to run the vRealize Orchestrator workflow after the
virtual machine is provisioned.
Click <Administration.
This action returns you from Catalog Management to the main Administration tab.
Click Events.
Click Subscriptions.
Click New.
Click Next.
Select Data > Lifecycle state > Lifecycle state name from the Clause drop-down
menu.
Click to enlarge
This operation should create a logical condition that is equivalent to Data >
Lifecycle state name equals VMPSMasterWorkflow32.MachineProvisioned.
From the Clause drop-down menu, select Data >Lifecycle state > State phase.
Select Data > Blueprint name from the Clause drop-down menu.
Click Next.
Select the Orchestrator > vRA Custom Workflows > EBS Add DNS-Host workflow.
Click Next.
Click Finish.
Click QA-General-Services.
Click QA-DB.
Click Submit.
Click OK.
Click the Requests tab and wait for the status of the request to change from In
Progress to Successful.
Click the Remote Desktop Connection Manager icon and return to the session with
DC.vclass.local.
Verify that an entry is present for the virtual machine and that it has an
address listed in the 10.10.103.0 subnet.
In the left pane, expand vRA Custom Workflows > EBS Add DNS-Host.
Select the EBS Add DNS-Host entry with the green check mark that indicates the
most recent completion of this workflow.
You might need to click the refresh icon in the vRealize Orchestrator client.
You should see output that reports the information that the script dumped using
the System.debug commands. The report should be similar to the screenshot.
Click to enlarge
Click the Remote Desktop Manager shortcut on the Student-A desktop taskbar.
When the Remote Desktop Manager completes the login, click the desktop of the
sa-IaaS-01 server.
Press Alt+F4.
Select Shut down from the drop-down menu and click OK.
Click Yes.
You shut down the vRealize Automation appliance. When the vRealize Automation
appliance is shut down, no interference is caused by this server when you install a
new configuration of vRealize Automation.
Examine the information on the desktop to verify that you are logged in to the
sa-IaaS-02 server with the User Name vra.service.
Click to enlarge
Connect to https://sa-vra-02.vclass.local:5480.
The first time anyone connects to the vRealize Automation appliance on port
5480, the installation wizard starts. As long as you have the prerequisites done on
IaaS, SQL Server, and Active Directory (including the creation and configuration of
the service account), the wizard steps you through the process.
Verify that the installation wizard is running. You should see this screen:
Click to enlarge
Click Next.
Select the I accept the terms of this agreement check box to accept the license
agreement.
Click Next.
You install the vRealize Automation management agent on the vRealize Automation
IaaS server.
Click vCAC-IaaSManagementAgent-Setup.msi.
Click Save.
Click Run.
Select the I accept the terms of this agreement check box to accept the license
agreement and click Next.
Select the I confirm the fingerprint matches the Management Site Service SSL
certificate check box.
Click Next.
Enter the password VMware1! for the VCLASS\vra.service user account and click
Next.
Click Install.
Click Yes to allow the management agent setup program to change the server.
Wait for the installation of the management agent to complete and click Finish.
Close the current Internet Explorer tab (labeled Certificate Error Navigation)
and return to the VMware vRealize Appliance tab.
This action should return you to the Installation Prerequisites page of the
vRealize Automation Installation wizard.
Click to enlarge
This address uses the vclass.local domain controller as the local network time
server.
Click Next.
Click Run to execute the prerequisite checker and wait for the host to trigger
the prerequisite check.
Click Run. Do not click Next. If you click Next instead of Run you will skip
the prerequisite checker.
The prerequisite checker will start. You might have to wait for five minutes
before you see changes.
When you see the status OK with a green check mark, click Next.
Enter sa-vra-02.vclass.local in the vRealize Address text box and click Next.
The password that you enter becomes the password of the vRealize Automation
system administration account in the default vsphere.local tenant. This password
should be entered carefully and recorded.
Click Next.
You must enter the account in the form domain-name\user-name. Do not use a
simple user name (with no domain). Do not enter the user name in the form user-
name@domain-name.
Failure to enter the user name in the correct format results in an installation
failure.
The database security passphrase must be carefully entered and recorded. You
cannot recover the database security passphrase if you lose it.
Click Next.
Do not use the default database name vra. A vra database already exists on this
SQL Server instance that was used in the earlier installation. You must create a
database for the this lab.
Accept the defaults for the Distributed Execution Managers and click Next.
The name that you use for the VMware vCenter Server® endpoint is critical.
Record the endpoint name. In several other places in vRealize Automation, you must
know the name that you assigned to the vCenter Server endpoint. The default
endpoint name is vCenter. But if you use multiple vCenter Server endpoints, each
endpoint must have a unique name.
Accept the other defaults for the agents and click Next.
Keep the default selection of Generate Certificate for the vRealize appliance
certificate.
The wizard generates a security certificate and changes the Certificate Action
selection from Generate Certificate to Keep Existing. Keep the default of the new
selection of Keep Existing.
Wait for the server to generate a security certificate and click Next.
Keep the default Generate Certificate selection for the Web certificate.
The wizard will generate a security certificate and change the Certificate
Action selection from Generate Certificate to Keep Existing. Keep the default of
the new selection of Keep Existing.
Wait for the server to generate a security certificate and click Next.
Click Validate.
The validation process can take up to 30 minutes. The progress bar does not
show smooth progress. Periods of no activity are followed by jumps of 10 to 30
percent. You should see the first progress update within 10 minutes.
Do not leave the session. If you are not present to respond when the validation
process finishes, the installation wizard can time out.
When the validation process completes and all items are listed with a green
check mark and the Succeeded status, click Next.
The installation process should take less time than the prerequisite checks,
but it can still take up to 45 minutes. You must use the scroll bar to monitor the
progress of the final steps in the installation.
Enter the new license key in the New License Key text box and click Submit Key.
Licenses
Click Next.
Deselect the Enable Customer Experience Improvement Program check box and click
Next.
Enter VMware1! in the Password text box to set the password for the
configurationadmin account.
Enter VMware1! in the Confirm password text box.
Click Create Initial Content and wait for the initial content configuration to
complete.
You are not required to use the Create Initial Content wizard for a successful
installation. You will use the Create Initial Content wizard in this lab to
demonstrate its capabilities.
Click Next.
Click Finish.
Use the vRA > Install Lab > vRA Web Console (vRA-02) - Default Tenant to
connect to https://sa-vra-02.vclass.local/vcac.
Select No from the Do you want to use the current tenant? drop-down menu.
Select Yes from the Do you want to create a new tenant? drop-down menu.
Enter a first name of the choice in the First name text box.
Enter a last name of the choice in the Last name text box.
Enter the email address prod-admin@vclass.local in the Email address text box.
Enter the password VMware1! in the Password text box and click Next.
This endpoint name must match the endpoint defined in the proxy agent. The
default endpoint name is vCenter, but this name can be changed to any name by
manually installing the proxy agent. In task 5, you should have used an endpoint
name of vcsa-endpoint.
You answer the manual user action request to complete the initial setup.
Use the refresh icon to periodically check for a new manual user action to
appear.
Select Centos-Template.
Select Win8-Template.
Scroll down and select SA-Shared-01 Remote from the Select reservation storage
drop-down menu.
From the Select reservation resource pool drop-down menu, select <None>.
From the Select reservation network drop-down menu, select pg-SA Production.
To see pg-SA Production, you might have to select a different network and then
click the Select reservation network drop-down menu a second time.
Click Submit.
Click the Requests tab and monitor the progress of the request.
You examine the initial setup that was created for you by the initial setup
workflow.
The login screen has no option to sign in to a different domain because the new
Production tenant is not yet connected to any other directory. Only the local
directory vsphere.local is available.
Click the Administration tab and select Catalog Management > Catalog Items.
ANSWER: No.