Using the VCF CLI with CCI context to manage VCFA provisioned databases

In a post from last year, I demonstrated how one could use the VCF CLI to troubleshoot the underlying vSphere Kubernetes Service (VKS) on which a VMware Data Services Manager (DSM) database is provisioned. In this follow up post, we will look at how we can use the VCF CLI to fine tune the database itself. This blog post stemmed from a request by one of our customers who wished to modify the backup retention policy and reduce the number of days that a backup is retained. Now you might be wondering why using the VCF CLI is necessary to…

Introducing PostgreSQL Read Replicas in DSM 9.1.1

In my introduction post to VMware Data Services (DSM) 9.1.1, I mentioned a new feature called PostgreSQL read replicas. In a nutshell, PostgreSQL databases provisioned by DSM can now be scaled for read workloads by adding additional Read Replicas. Previously, a PostgreSQL database cluster was limited to just 3 nodes, a primary, a single replica and a monitor. In DSM 9.1.1, we can now scale PostgreSQL databases through the addition of read replicas. As I mentioned in the introduction to DSM 9.1.1, DSM now uses the term read replica instead of secondary to refer to remote PostgreSQL database instances. They…

How to enable SSH on DSM Appliance when deployed via VCFA 9.1.1

In my initial post introducing VMware Data Services Manager (DSM) 9.1.1 features, I mentioned that DSM can now be deployed directly from VCF Automation. As part of a concerted effort to make Data Services (and the VCF platform) highly secure, SSH access is not automatically enabled on the DSM 9.1.1 appliance. In this post, I will show you how to enable it should you need SSH access to the DSM appliance. The first step is to gain SSH Access to the vCenter server. The steps are outlined in this Knowledge Base article on troubleshooting. Once you’ve managed to get a…

Bucket Policies in VCFA 9.1.1 for Native Object Storage

In an earlier post on object storage, we look at the role privieges that VCF Automation users could be assigned within an organization. Since the scope of object storage privileges is at the project level, we also looked at the role of Project Admins and Project Advanced Users. within a project. We saw how a Project Admin could grant access control to different Project Users, creating access control policies to control which s3 actions and which s3 resource that a user was allowed in a given project. In this post, I wanted to take this a little further. As mentioned,…

Identity Providers and Access Controls in VCFA 9.1.1 for Native Object Storage

In a previous post, I highlighted how to get started with Native Object Storage which is in tech preview in VMware Cloud Foundation (VCF) version 9.1.1. In that post, we saw the role of the Provider Admin and the Organization Admin in VCF Automation (VCFA). We saw that the Provider Admin could create object storage on behalf of the tenant users within an organization, but could not actually create or view the buckets on the object store, nor see the access controls or anything else associated with the object store for that matter. We saw that the Org Admin had…

SQL Server enhancements in Data Services Manager version 9.1.1

VMware introduced support for Microsoft SQL Server as a data service in VMware Data Services Manager version 9.1. In version 9.1.1, there are a number of enhancements, some of which I will highlight in this post. If you want to get the full list of enhancements, check out the VMware Data Services Manager 9.1.1. Release Notes. One of the major changes in version 9.1.1 is to enable the VCF Automation (VCFA) Provider Administrators to provision the SQL Server instances / engines directly from VCFA, rather than context switching back to the DSM UI to do it. Once the SQL Server…

Data Services Manager version 9.1.1 Network Security

One of the interesting new features of VMware Data Services Manager when it is integrated with VCF automation is the Network Security feature. In a nutshell, what this feature does is implement both distributed firewall rules and gateway firewall rules for each DSM database deployed via VCF Automation. Let’s take a closer look. By default, Net work Security is disabled. The VCFA Provider Admin will need to activate it. Navigate to VCF Services > Data Services. In the Data Services Manager menu, select Advanced. Here you will find the button to activate Network Security. When the Activate button is clicked,…