Powerful virtual machine software for the technical professional (326 pages)
Summary of Contents for VMware CLOUD DIRECTOR 1.0
Page 1
Cloud Director Administrator's Guide Cloud Director 1.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this document, see http://www.vmware.com/support/pubs. EN-000343-00...
Page 2
VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
Page 4
Configure the Public Web URL 89 Configure the Public Console Proxy Address 89 Configure the Public REST API Base URL 90 Monitoring Cloud Director 91 Viewing Tasks and Events 91 View Usage Information for a Provider vDC 93 VMware, Inc.
Page 5
View Usage Information for an Organization vDC 93 Using Cloud Director's JMX Service 93 Viewing the Cloud Director Logs 94 Cloud Director and Cost Reporting 94 Monitoring Quarantined Files 94 Roles and Rights 97 Predefined Roles and Their Rights 97 Index 101 VMware, Inc.
Page 6
Cloud Director Administrator's Guide VMware, Inc.
Linux, Windows, IP networks, and VMware vSphere. VMware Technical Publications Glossary VMware Technical Publications provides a glossary of terms that might be unfamiliar to you. For definitions of terms as they are used in VMware technical documentation, go to http://www.vmware.com/support/pubs.
Page 8
Cloud Director Administrator's Guide Services provides offerings to help you assess, plan, build, and manage your virtual environment. To access information about education classes, certification programs, and consulting services, go to http://www.vmware.com/services. VMware, Inc.
14 Overview of Cloud Director Administration VMware Cloud Director is a software product that provides the ability to build secure, multi-tenant clouds by pooling virtual infrastructure resources into virtual datacenters and exposing them to users through Web- based portals and programmatic interfaces as a fully-automated, catalog-based service.
Page 10
Most users with access to a vApp can create and manage their own vApp networks. Working with vApp networks is described in the VMware Cloud Director User's Guide. VMware, Inc.
Log In to the Web Console You can access the Cloud Director user interface by using a Web browser. For a list of supported browsers, see the VMware Cloud Director Installation and Configuration Guide. Prerequisites You must have the system administrator user name and password that you created during the system setup.
Copy the Sysprep binary files for each operating system to a convenient location on a Cloud Director server host. Each operating system requires its own folder. Folder names are case-sensitive. Guest OS Copy Destination Windows 2000 SysprepBinariesDirectory /win2000 Windows 2003 (32-bit) SysprepBinariesDirectory /win2k3 Windows 2003 (64-bit) SysprepBinariesDirectory /win2k3_64 VMware, Inc.
SysprepBinariesDirectory command. For example, /opt/vmware/cloud-director/deploymentPackageCreator/createSysprepPackage.sh / root/MySysprepFiles Use the command to restart the Cloud cell. service vmware-vcd restart If you have multiple Cloud cells, copy the package and properties file to all Cloud cells. scp /opt/vmware/cloud-director/guestcustomization/vcloud_sysprep.properties /opt/vmware/cloud-director/guestcustomization/windows_deployment_package_sysprep.cab root@ next_cell_IP :/opt/vmware/cloud-director/guestcustomization Restart each Cloud cell to which you copy the files.
Cloud Director Administrator's Guide If you have multiple Cloud cells, stop each cell and copy the package and properties file to each cell. scp /opt/vmware/cloud-director/guestcustomization/vcloud_sysprep.properties /opt/vmware/cloud-director/guestcustomization/windows_deployment_package_sysprep.cab root@ next_cell_IP :/opt/vmware/cloud-director/guestcustomization Restart each Cloud cell to which you copy the files. Set User Preferences You can set certain display and system alerts preferences that take effect every time you log in to the system.
For information about Cloud Director system requirements and supported versions of vCenter Server and ESX/ESXi see the VMware Cloud Director Installation and Configuration Guide. Attach a vCenter Server Attach a vCenter Server to make its resources available for use with Cloud Director. After you attach a vCenter Server, you can assign its resource pools, datastores, and networks to a provider virtual datacenter.
Page 16
Before you attach the new vCenter Server, review the settings you entered. Procedure Review the settings for the vCenter Server and vShield Manager. (Optional) Click Back to modify the settings. Click Finish to accept the settings and attach the vCenter Server. VMware, Inc.
Enter the license key, enter an optional label for the key, and click OK. Use the vShield for VMware Cloud Director license key you received when you purchased Cloud Director. You can use this license key in multiple vCenter Servers.
Cloud Director Administrator's Guide If you plan to add a resource pool that is part of a cluster that uses VMware HA, you should make sure you are familiar with how VMware HA calculates slot size. For more information about slot sizes and customizing VMware HA behavior, see the VMware vSphere Availability Guide.
You can create a network pool that is backed by Cloud isolated networks. A Cloud isolated network spans hosts, provides traffic isolation from other networks, and is the best source for vApp networks. An isolation-backed network pool does not require pre-existing port groups in vSphere. Prerequisites An available vSphere vNetwork distributed switch. VMware, Inc.
Page 20
Review the network pool settings and click Finish. What to do next You can now create an organization network that is backed by the network pool or associate the network pool with an organization vDC and create vApp networks. VMware, Inc.
Page 21
When both the virtual machine guest operating system and the underlying physical infrastructure are configured with the standard MTU (1500 bytes), then the VMware network isolation protocol will fragment frames. To avoid frame fragmentation, you should increase the MTU to at least 1524 bytes for both the network pool and the underlying physical network.
Page 22
Cloud Director Administrator's Guide VMware, Inc.
“Configure Organization Lease, Quota, and Limit Settings,” on page 27. Users can configure email notification to receive a message before a runtime or storage lease expires. See “Set User Preferences,” on page 14 for information about lease expiration preferences. VMware, Inc.
Open the New Organization wizard to start the process of creating an organization. Procedure Click the Manage & Monitor tab and then click Organizations in the left pane. Click the New Organization button. The New Organization wizard starts. VMware, Inc.
You can import any LDAP group from the system LDAP root. However, only users who are in both the OU and the imported group can log in to the organization. Click Next and enter the custom LDAP settings for the organization. Custom LDAP service VMware, Inc.
Select a catalog publishing option. Option Description The organization administrator cannot publish catalogs for users outside of Cannot publish catalogs the organization. The organization administrator can publish catalogs for users in all Allow publishing catalogs to all organizations. organizations Click Next. VMware, Inc.
Select the limits for resource intensive operations. Certain Cloud Director operations, for example copy and move, are more resource intensive than others. Limits prevent resource intensive operations from affecting all the users in an organization and also provide a defense against denial-of-service attacks. VMware, Inc.
Cloud Director Administrator's Guide Select the number of simultaneous VMware Remote Console connections for each virtual machine. You may want to limit the number of simultaneous connections for performance or security reasons. This setting does not affect Virtual Network Computing (VNC) or Remote Desktop Protocol (RDP) connections.
Page 29
All of the resources you allocate are immediately committed to the Reservation Pool organization vDC. Users in the organization can control overcommitment by specifying reservation, limit, and priority settings for individual virtual machines. Click Next. VMware, Inc.
Page 30
3-3. Table 3-1. How Allocation Pool Settings Affect Resource Pool Settings Allocation Pool Allocation Pool Setting Value Resource Pool Setting Resource Pool Value CPU Allocation 25 GHz CPU Limit 25 GHz CPU % Guarantee CPU Reservation 2.5 GHz VMware, Inc.
Page 31
Procedure Select a network pool or select None. If you select None, you can add a network pool later. Enter the maximum number of networks that the organization can provision from the network pool. Click Next. VMware, Inc.
Procedure Type a name and optional description. You can use the name and description fields to indicate the vSphere functionality available to the organization vDC, for example, VMware HA. Click Next. Confirm Settings and Create the Organization vDC Before you create the organization vDC, review the settings you entered.
Page 33
You can deselect the Only use networks accessible by this organization check box to view external networks that are not currently available to the organization through its organization vDCs. This enables you to choose an arbitrary network and later create an organization vDC that can access the network. VMware, Inc.
Page 34
57. Add an Internal Organization Network You can add an internal organization network that only this organization can access. It provides the organization with an internal network to which multiple vApps can connect. Prerequisites A network pool. VMware, Inc.
Page 35
Use the default network settings or type your own and click Next. Type a name and optional description and click Next. Review the settings for the organization network. Click Finish to accept the settings and create the organization network, or click Back to modify the settings. VMware, Inc.
Page 36
Cloud Director Administrator's Guide VMware, Inc.
Create a Catalog Create a catalog to contain uploaded and imported vApp templates and media files. An organization can have multiple catalogs and control access to each catalog individually. Prerequisites An organization in which to create a catalog. VMware, Inc.
Select an organization vDC and catalog and click Upload. What to do next Make sure that VMware Tools is installed on the virtual machines in the vApp. VMware Tools is required to support guest customization. See the VMware Cloud Director User's Guide for more information.
10 Click OK. What to do next Make sure that VMware Tools is installed on the virtual machines in the vApp. VMware Tools is required to support guest customization. See the VMware Cloud Director User's Guide for more information. Upload a Media File You can upload an ISO or FLP file to make the media available to other users.
On the Catalogs tab, right-click the catalog name and select Publish. On the Publishing tab, select Published to Organizations and click OK. The catalog and all of its contents appear under Public Catalogs for all organizations in the Cloud Director installation. VMware, Inc.
If there are other provider vDCs available and enabled, you must disable the provider vDC, delete all of its organization vDCs, and then reset any organization networks that depend on the provider vDC. VMware, Inc.
Page 42
Type a new name or description and click OK. You can use the name and description fields to indicate the vSphere functionality available to the provider vDC, for example, VMware HA. Enable or Disable a Provider vDC Host You can disable a host to prevent vApps from starting up on the host. Virtual machines that are already running on the host are not affected.
Page 43
You can add storage capacity to a provider vDC by adding one or more datastores. Procedure Click the Manage & Monitor tab and click Provider vDCs in the left pane. Right-click the provider vDC name and select Open. Click the Datastores tab. VMware, Inc.
Page 44
NFS datastores may appear. Do not add these datastores to your provider vDC. VMware recommends that you use only shared storage. VMware DRS cannot migrate virtual machines on local storage.
Open the New Organization vDC Wizard Open the New Organization vDC wizard to start the process of creating an organization vDC. Procedure Click the Manage & Monitor tab and click Organization vDCs in the left pane. Click the New vDC button. VMware, Inc.
All of the resources you allocate are immediately committed to the Reservation Pool organization vDC. Users in the organization can control overcommitment by specifying reservation, limit, and priority settings for individual virtual machines. Click Next. VMware, Inc.
5-3. Table 5-1. How Allocation Pool Settings Affect Resource Pool Settings Allocation Pool Allocation Pool Setting Value Resource Pool Setting Resource Pool Value CPU Allocation 25 GHz CPU Limit 25 GHz CPU % Guarantee CPU Reservation 2.5 GHz VMware, Inc.
Procedure Select a network pool or select None. If you select None, you can add a network pool later. Enter the maximum number of networks that the organization can provision from the network pool. Click Next. VMware, Inc.
Procedure Type a name and optional description. You can use the name and description fields to indicate the vSphere functionality available to the organization vDC, for example, VMware HA. Click Next. Confirm Settings and Create the Organization vDC Before you create the organization vDC, review the settings you entered.
Page 50
On the General tab, type a new name and description and click OK. You can use the name and description fields to indicate the vSphere functionality available to the organization vDC, for example, VMware HA. Edit Organization vDC Allocation Model Settings You cannot change the allocation model for an organization vDC, but you can change some of the settings of the allocation model that you specified when you created the organization vDC.
Before you can delete an external network, you must delete all of the organization networks that rely on it. Procedure Click the Manage & Monitor tab and click External Networks in the left pane. Right-click the external network name and select Delete Network. VMware, Inc.
Internet. The organization connects directly to this network. Prerequisites An external network. Procedure Click the Manage & Monitor tab and then click Organization Networks in the left pane. Click the Add Network button. The Create Organization Network wizard starts. VMware, Inc.
Page 53
This enables you to choose an arbitrary network or network pool and later create an organization vDC that can access it. Use the default network settings or type your own and click Next. VMware, Inc.
Page 54
You can configure network services, such as DHCP, firewalls, and network address translation (NAT) for certain organization networks. Organization administrators can also configure some network services for their organization networks. Table 5-5 lists the network services that Cloud Director provides to each type of organization network. VMware, Inc.
Page 55
Prerequisites An external NAT-routed organization network. Procedure Click the Manage & Monitor tab and click Organization Networks in the left pane. Right-click the organization network name and select Configure Services. Click the Firewall tab and select Enable firewall. VMware, Inc.
Page 56
Before you can configure external IP mapping for an organization network, you must add one or more external IP addresses. Only a system administrator can add external IP addresses to an organization network. Prerequisites An external NAT-routed organization network. VMware, Inc.
Page 57
If the network services, such as DHCP settings, firewall settings, and so on, that are associated with an organization network are not working as expected, reset the network. Before you delete a provider vDC, you should reset the organization networks that depend on it. No network services are available while an organization network resets. VMware, Inc.
Page 58
Click the Manage & Monitor tab and click Organization Networks in the left pane. Right-click the organization network name and select Properties. On the Network Specification tab, type an IP address or a range of IP addresses in the text box and click Add. Click OK. VMware, Inc.
Click the Manage & Monitor tab and click Network Pools in the left pane. Right-click the network pool name and select Edit Network Pool. On the Network Pool Settings tab, select a port group, click Add, and click OK. VMware, Inc.
You manage cloud cells mostly from the Cloud Director server host on which the cell resides, but you can delete a cloud cell from the Cloud Director Web console. Table 5-6 lists the basic commands for controlling a cloud cell. VMware, Inc.
Page 61
To add cloud cells to a Cloud Director installation, install the Cloud Director software on additional Cloud Director server hosts in the same Cloud Director cluster. For more information, see the VMware Cloud Director Installation and Configuration Guide. Delete a Cloud Cell If you want to remove a cloud cell from your Cloud Director installation, in order to reinstall the software, or for some other reason, you can delete the cell.
Page 62
When you are finished performing maintenance on a cell and ready to restart the cell, you can turn off the maintenance message. Procedure Run the command. /opt/vmware/cloud-director/bin/vmware-vcd-cell stop Start the cell using the command. service vmware-vcd start Users can now access the cell using a browser or the vCloud API. VMware, Inc.
If Cloud Director loses it connection to a vCenter Server, or if you change the connection settings, you can try to reconnect. Procedure Click the Manage & Monitor tab and click vCenters in the left pane. Right-click the vCenter Server name and select Reconnect vCenter. Read the informational message and click Yes to confirm. VMware, Inc.
Click the Manage & Monitor tab and click Hosts in the left pane. Right-click the host name and select Enable Host or Disable Host. Cloud Director enables or disables the host for all provider vDCs that use its resources. VMware, Inc.
Page 65
Cloud Director installs agent software on each ESX/ESXi host in the installation. If you upgrade your ESX/ESXi hosts, you also need to upgrade your ESX/ESXi host agents. Procedure Click the Manage & Monitor tab and click Hosts in the left pane. Right-click the host name and select Upgrade Host. VMware, Inc.
In some situations, Cloud Director may not be able to delete the object in vSphere, in which case, the object becomes stranded. You can view a list of stranded items and try again to delete them, or you can use the vSphere Client to delete the stranded objects in vSphere. VMware, Inc.
Page 67
“Delete a Stranded Item,” on page 67. Procedure Click the Manage & Monitor tab and click Stranded Items in the left pane. Right-click a stranded item and select Force Delete. Cloud Director removes the item from the stranded items list. VMware, Inc.
Page 68
Cloud Director Administrator's Guide VMware, Inc.
Right-click the organization name and select Enable or Disable. Delete an Organization Delete an organization to permanently remove it from Cloud Director. Prerequisites Before you can delete an organization, you must disable it and delete or change ownership of all objects that the organization users own. VMware, Inc.
For more information about entering custom LDAP settings, see “Configuring the System LDAP Settings,” page 85. Procedure Click the Manage & Monitor tab and click Organizations in the left pane. Right-click the organization name and select Properties. Click the LDAP Options tab. VMware, Inc.
For users who are currently logged in to the organization, changes to the catalog publishing policy do not take effect until the cache for their current session expires or they log out and log in again. VMware, Inc.
Leases provide a level of control over an organization's storage and compute resources by specifying the maximum amount of time that vApps can be running and that vApps and vApp templates can be stored. You can also specify what happens to vApps and vApp templates when their storage lease expires. VMware, Inc.
For information about removing an organization vDC, see “Delete an Organization vDC,” on page 49. For information about modifying the resources available to an existing organization vDC, see “Edit Organization vDC Allocation Model Settings,” on page 50, and “Edit Organization vDC Storage Settings,” page 50. VMware, Inc.
LDAP users, and LDAP groups to the organization. For more information about adding users and groups to an organization, see the VMware Cloud Director User's Guide. Managing Organization vApps There are a couple of tasks related to managing organization vApps that can only be performed by a system administrator.
Page 75
Chapter 7 Managing Organizations Click the My Cloud tab and click vApps in the left pane. Right-click the running vApp and select Force Stop. Click Yes. VMware, Inc.
Page 76
Cloud Director Administrator's Guide VMware, Inc.
Cloud Director and all of its organizations. Procedure Click the Administration tab and click Users in the left pane. Click the Add User button. Type the account information for the new user and click OK. VMware, Inc.
You can only edit account information for non-LDAP users. Procedure Click the Administration tab and click Users in the left pane. Right-click the user name and select Properties. Type the new information for the user account and click OK. VMware, Inc.
Click the Administration tab and click Groups in the left pane. Click the Import Group button. Type a full or partial name in the text box and click Search Groups. Select the groups to import and click Add. Click OK. VMware, Inc.
Procedure Click the Administration tab and click Roles in the left pane. Click the New Role button. Type a name and optional description for the role. Select the rights for the role and click OK. VMware, Inc.
Assign a new role to all users with the role you want to delete. Procedure Click the Administration tab and click Roles in the left pane. Right-click a role and select Delete Role. Click Yes to confirm the deletion. VMware, Inc.
Page 82
Cloud Director Administrator's Guide VMware, Inc.
Table 9-1. General System Settings Name Category Description Synchronization Start Time LDAP Synchronization Time of day to start LDAP synchronization. Synchronization Interval LDAP Synchronization The number of hours between LDAP synchronizations. VMware, Inc.
Select the check box if you want to add external networks Networks that run on the same network segment. You should only enable this setting if you are using non- VLAN-based methods (for example, VMware vShield Manager) to isolate your external networks. Enable Upload Quarantine with a Miscellaneous...
Windows 2003 Active Directory Kerberos Windows 2003 Active Directory Kerberos SSL Windows 2008 Active Directory Simple Windows 7 (2008 R2) Active Directory Simple Windows 7 (2008 R2) Active Directory Simple SSL Windows 7 (2008 R2) Active Directory Kerberos VMware, Inc.
Page 86
For LDAP, the default port number is 389. For LDAP over SSL (LDAPS), the default port number is 636. Type the base distinguished name (DN). The base DN is the location in the LDAP directory where Cloud Director connects. VMware recommends connecting at the root. Type the domain components only, for example,...
Page 87
After you configure an LDAP connection, you can test its settings to make sure that user and group attributes are mapped correctly. Prerequisites You must configure an LDAP connection before you can test it. Procedure Click the Administration tab and click LDAP in the left pane. Click Test LDAP Settings. VMware, Inc.
You can customize the branding of the Cloud Director client UI and some of the links that appear on the Cloud Director Home login screen. For a sample .css template with information about the styles that Cloud Director supports for custom themes, see http://kb.vmware.com/kb/1026050. Procedure Click the Administration tab and click Branding in the left pane.
This can be the address of the load balancer or some other machine that can route traffic to the remote console proxy IP. Click Apply. Remote console session tickets sent to the HTTP service IP address return the public console proxy address. VMware, Inc.
This can be the address of the load balancer or some other machine that can route traffic to the HTTP service IP. Click Apply. XML responses from the REST API include the base URL and the transfer service uses the base URL as the upload target. VMware, Inc.
To view information about organization-level tasks, see “View Ongoing and Completed Organization Tasks,” on page 92. The log can also include debug information, depending on your Cloud Director settings. See “General System Settings,” on page 83. VMware, Inc.
Page 92
View Organization Events View the log for an organization to monitor organization-level events. You can find and troubleshoot failed events and view events by user. To view information about system-level events, see “View System Events,” on page 92. VMware, Inc.
Access the JMX Service by Using JConsole You can use any JMX client to access the Cloud Director JMX service. JConsole is an example of a JMX client. For more information about the MBeans exposed by Cloud Director, see http://kb.vmware.com/kb/1026065. Prerequisites The host name of the Cloud Director host to which you connect must be resolvable by DNS using forward and reverse lookup of the fully-qualified domain name or the unqualified hostname.
You can use any text editor/viewer or third-party tool to view the logs. Cloud Director and Cost Reporting You can use VMware vCenter Chargeback 1.5 to configure a cost reporting system for VMware Cloud Director. See the VMware vCenter Chargeback User's Guide for more information.
Page 95
. The default port is 8999. example.com:8999 Type a Cloud Director system administrator user name and password and click Connect. Click the MBeans tab and browse to the org.apache.activemq > uuid > Queue > com.vmware.vcloud.queues.transfer.server.QuarantineRequest > Operations node. Select the operation. browseMessages() Copy the text of the message to which you want to respond.
Page 96
. The default port is 8999. example.com:8999 Type a Cloud Director system administrator user name and password and click Connect. Click the MBeans tab and browse to the org.apache.activemq > uuid > Queue > com.vmware.vcloud.queues.transfer.server.QuarantineResponse > Operations node. Select the operation. sendTextMessage(string, string, string) Paste the response message from your text editor in the first field and type a Cloud Director system administrator user name and password in the other fields.
Administrator Author vApp Author vApp User Only vApp: Create a vApp vApp: Delete a vApp vApp: Edit vApp Properties vApp: Start/Stop/ Suspend/Reset a vApp vApp: Share a vApp vApp: Copy/ Move a vApp vApp: Access to VM Console VMware, Inc.
Page 98
Catalog: Share a Catalog Catalog: View Private and Shared Catalogs Catalog: View Published Catalogs Catalog: Change Owner Catalog Item: Edit vApp Template/Media Properties Catalog Item: Create/Delete/ Upload a vApp Template or Media Catalog Item: Download a vApp Template VMware, Inc.
Page 99
Organization: Edit Organization Network Properties Organization: View Organization Networks Organization: Edit Leases Policy Organization vDC: View Organization vDCs User: Create/ Import/Delete Group or User User: Edit Group or User Properties User: View Group or User General: Send Notification VMware, Inc.
Page 100
Cloud Director Administrator's Guide Table 11-1. Default Rights for the Predefined Roles (Continued) System Organization Catalog Console Access Administrator Administrator Author vApp Author vApp User Only General: Administrator Control General: Administrator View VMware, Inc.
44, 79, 85 load balancer 89, 90 email settings 84 logging in 11 ESX/ESXi hosts logs 94 enabling and disabling 42, 64 Lost & Found 79 moving virtual machines 65 preparing and unpreparing 42, 65 MBeans 93 VMware, Inc.
Page 102
31, 48 enabling or disabling 41 allocation model settings 50 managing 41 allocation models 30, 47 monitoring usage 93 changing description 50 publishing catalogs 37, 40 changing name 50 confirm settings 32, 49 creating 29, 45 VMware, Inc.
Page 103
67 vNetwork distributed switches, setting the force deleting 67 MTU 21 system vShield, licensing 17 monitoring tasks 91 vShield for VMware Cloud Director license 17 roles and rights 80 vShield Manager system administrators connecting 16 creating accounts 77 settings 64...
Page 104
Cloud Director Administrator's Guide VMware, Inc.