Category : VRealize Automation
Written by Christopher Lewis on January 11, 2017 .
Objective Overview
Objective 1.1 - Deploy and Manage a vRA Appliance and IaaS Server as single nodes
- Acquire IaaS installation media from the virtual appliance
- Perform initial configuration of appliance and IaaS
- Configure NTP server for vRealize Appliances
- Assign appropriate IP address to vRealize Appliance
- Enable Microsoft Distributed Transaction Coordinator (MSDTC) to communicate between all servers in deployment.
- Configure Windows Firewall to allow vRA components to communicate
Objective Prerequisites
The following prerequisites are assumed for this Objective:
Written by Christopher Lewis on January 10, 2017 .
This post is a part of a series of posts for preparation for the VCAP6-CMA Deploy exam. For the full exam prep resources check here .
Prerequisites
- Deploy the VMware vRealize Automation Appliance from OVA.
- Power On the vRealize Automation Appliance.
Configuration Overview
The high level configuration steps for this appliance are:
- Connect to the Automation Appliance VAMI
- Configure the Time/NTP settings
- Confirm the Network Settings
- Configure the Host Settings
- Configure the SSO Settings
- Configure Licensing
- Confirm vRealize Automation Services Status
- Logon to the vRealize Automation Portal
Step by Step Instructions
Connect to the Identity Appliance VAMI
- Using a web browser, navigate to VAMI of the Automation Appliance (
https://automation-appliance.fqdn:5480
)
- Click Advanced and then click Proceed to automation-appliance.fqdn (unsafe).
- Enter root into the User name text field and the password for the root account into the Password text field. Click Login.
Configure the Time / NTP Settings
- Click the Admin Tab and then the Time Settings Tab.
- Select Use Time Server from the Time Sync. Mode dropdown and enter the time server(s) in the text field(s) and click Save Settings.
Note:
It is important to use the same consistent time source throughout the implementation of vRealize Automation.
Written by Christopher Lewis on January 10, 2017 .
This post is a part of a series of posts for preparation for the VCAP6-CMA Deploy exam. For the full exam prep resources check here .
Step by Step Instructions
- Within the VMware vSphere Web Client, right click and select Deploy OVF Template.
- Click Browse, navigate to the location of the Identity Appliance OVA, select it and then click Open.
- Click Next.
- Enter the Identity Appliance name into the the Name text field and then select the Datacentre or folder location to deploy the Identity Appliance.
- Click Next
- Select the appropriate cluster, host or resource pool and then click Next.
- Click Next.
- Click Accept and then click Next.
- Select the appropriate storage location and then click Next.
- Choose the correct Port Group from the Destination Network dropdown and click Next.
- Check the Enable SSH service in the appliance checkbox (this can be disabled later), enter the FQDN of the Identity Appliance into the Hostname text field and enter (then confirm) the root password in the Enter password and Confirm password text fields.
- Click on Networking Properties to expand the options and scroll down to expose the new fields to complete.
- Enter the IP Address(es) of the DNS Server(s) into the DNS Text field, enter the gateway address into the Default Gateway field, enter the Appliance IP Address into the Network 1 IP Address text field and finally add the Netmask into the Network 1 Netmask text field.
- Click Next.
- Review the configuration information and then Click Finish to deploy the Identity Appliance.
Written by Christopher Lewis on January 10, 2017 .
This post is a part of a series of posts for preparation for the VCAP6-CMA Deploy exam. For the full exam prep resources check here .
Prerequisites
Configuration Overview
The high level configuration steps for this appliance are:
- Connect to the Identity Appliance VAMI
- Configure the Time/NTP settings
- Confirm the Network Settings
- Configure the SSO Administrator Password
- Configure the SSO Hostname
- Configure the SSL Certificate
- Join the Identity Appliance to Active Directory
Step by Step Instructions
Connect to the Identity Appliance VAMI
- Using a web browser, navigate to VAMI of the Identity Appliance
https://identity-appliance.fqdn:5480
.
- Click Advanced and then click Proceed to
identity-appliance.fqdn
(unsafe).
- Enter root into the User name text field and the password for the root account into the Password text field. Click Login.
Configure the Time / NTP Settings
- Click the Admin Tab and then the Time Settings Tab.
- Select Use Time Server from the Time Sync. Mode dropdown and enter the time server(s) in the text field(s) and click Save Settings.
Confirm the Network Settings
- Click the Network Tab to confirm the network settings of the Identity Appliance are correct.
Note:
If the settings are incorrect, click the Address Tab, update the relevant settings, click Save Settings and then reboot the appliance.
Written by Christopher Lewis on January 9, 2017 .
This post is a part of a series of posts for preparation for the VCAP6-CMA Deploy exam. For the full exam prep resources check here .
Step by Step Instructions
Deploying the VMware vRealize Automation Appliance
Within the VMware vSphere Web Client, right click and select Deploy OVF Template.
Click Browse, navigate to the location of the vRealize Automation OVA, select it and then click Open.
Click Next.
Enter the vRealize Automation Appliance name into the the Name text field and then select the Datacentre or folder location to deploy the Appliance.
Written by Christopher Lewis on December 22, 2016 .
Objective Overview
Objective 3.2 - Deploy and Manage Certificates and Access Control
- Create/add/modify users and groups for specific roles.
- Assign new administrative users to different Business Groups.
- Create custom groups that grant users/groups multiple roles.
- Assign a user to specific Custom Groups and Business Groups.
- Configure user access to Identity Store Groups, Custom Groups, Business Groups, and Entitled Items according to a deployment plan.
- Generate new certificate requests.
- Deploy and Update certificates for multiple vRealize appliances.
- Replace self-signed certificates with signed certificates.
Note: I have moved the above items around to better group the items in this Objective.
Written by Christopher Lewis on November 22, 2016 .
At last! As announced at VMworld Europe, VMware vRealize Automation 7.2 has finally arrived!
The key updates/features for this release are:
- Native integration for Microsoft Azure adding to the already supported endpoints of vSphere, KVM, Hyper-V, AWS, OpenStack, vCD and vCloudAir)
- Native integration with** ServiceNow** and their Service Catalog
- Container Management!
This makes this version of VMware vRealize Automation the first one that could be called a true broker of Hybrid Clouds.
Written by Christopher Lewis on November 15, 2016 .
The task of deploying VMware vRealize Automation 7.x is now mainly completed by the Deployment Wizard (unless you actually like pain) but before you can run the deployment wizard you need to install the VMware vRealize Automation Management Agent onto the IaaS Servers that you will be using within your deployment.
So I can hear you asking:
- What happens when you want to deploy new IaaS components into you vRealize Automation environment?
- What happens when you want to scale you DEMs horizontally (onto new servers) rather than vertically (deploying more DEMs per server)?
- What happens if you want to add another vCenter Proxy Agent for High Availability or a new vCenter Instance?
Well, I’m glad you asked!
Written by Christopher Lewis on November 5, 2016 .
The Series
- Configuring SSL certificates for vRA 7.x (inc vRO)
- Replacing the Appliance Management Site Certificate for vRealize Automation
- Replacing the Control Center Certificate on an embedded vRO instance
- Replacing the Package Signing Certificate in vRO 7
Replacing the Certificate
This is the third post in a series tackling the extra certificates you may want to replace once you have deployed vRealize Automation.
There are plenty of articles on changing the SSL certificate for this website https://vra-fqdn:8283/vco-vcoconfigurator on an External instance of vRealize Orchestrator, most notably is @SpasKaloferov ’s post http://kaloferov.com/blog/how-to-change-the-ssl-certificate-of-a-vro-appliance-7-x/
VMware vRealize Automation vRealize Orchestrator Certificates
Written by Christopher Lewis on November 5, 2016 .
The Series
- Configuring SSL certificates for vRA 7.x (inc vRO)
- Replacing the Appliance Management Site Certificate for vRealize Automation
- Replacing the Control Center Certificate on an embedded vRO instance
- Replacing the Package Signing Certificate in vRO 7
Replacing the Certificate
This is the second post in a series tackling the extra certificates you may want to replace once you have deployed vRealize Automation.
After a quick look around the VMware Documentation Center and I found the article for replacing the VAMI certificate ( https://vra.fqdn:5480 ). The VAMI certificate can be replaced using the same SAN certificate used for the vRA Virtual Appliance during the installation wizard, but it will need to be converted to Privacy Enhanced Mail (PEM) format to do so.
- Operating a Private Cloud - Part 3: Creating a Pricing Card in VMware Aria Automation
- Operating a Private Cloud - Part 2: Creating a Pricing Card in VMware Aria Operations
- Operating a Private Cloud - Part 1: Understanding Pricing Cards in VMware Aria
- Zero2Hero - Using Aria Automation to Deploy Multiple Machines with Multiple Disks - Part 5
- Zero2Hero - Using Aria Automation to Deploy Multiple Machines with Multiple Disks - Part 4