๐Ÿ—๏ธ Architecture & Component Topology โ€” VCF 9.1
9.1
Platform Release
33+
BOM Components
11
New Features (Major)
4
Patch Sub-Releases
โ–ธ VCF 9.1 Full-Stack Architecture (Click components for details)
CONSUMPTION MANAGEMENT CONTROL PLN COMPUTE PHYSICAL CONSUMPTION LAYER VCF Automation VM Apps / All Apps Orgs v9.1.0.0 ยท Build 25370929 vSphere Supervisor VKS / CNF / Private AI v9.1.0.0 ยท vK8s 1.34.2 VCF Operations Build/Manage/Operate/Protect v9.1.0.0 ยท Build 25346025 VCF SDKs & APIs Java ยท Python ยท PowerCLI Terraform ยท REST APIs Identity Broker SAML ยท OIDC ยท AD/LDAP v9.1.0.0 ยท Build 25368698 License Server Connected/Disconnected v9.1.0.0 ยท Build 25346031 VCF MANAGEMENT SERVICES (NEW IN 9.1 โ€” Default Deployed) SDDC Manager VCF Orchestration 25371088 Fleet Lifecycle Replaces Fleet Mgmt 25371109 SDDC Lifecycle Domain LCM Engine 25371107 Log Management Centralized Logging 25346055 Real-Time Metrics Prometheus/PromQL 25346020 Salt RaaS/Master Config Automation 25346036 Software Depot Binary Management 25371105 Services Runtime Unified Svc Runtime 25370367 CONTROL PLANE โ€” NSX / vCenter / vSAN Control NSX Manager Cluster (3-Node) v9.1.0.0 ยท Build 25318225 NSX Policy API +264 New Ops vDefend FW ATP / DFW NSX Global Mgr Federation vCenter Server v9.1.0.0 ยท Build 25370922 vSphere LCM Images Mode vCenter Group VGFA API vSAN ESA / OSA v9.1.0.0 ยท Witness 25370927 ESA Auto-RAID6 Default in 9.1 Cyber Recovery On-prem Clean Rm Ops for Networks v9.1.0.0 ยท 25318550 Flow Analytics NetOps Visibility VCF Ops HCX v9.1.0.0 ยท 25318520 Workload Mobility HCX NSX-Edge stack COMPUTE LAYER โ€” ESX Hypervisor + Workload Domains Management Domain Min: 4 ESX Hosts ยท Shared Infra Services ESX Host 9.1.0.0 ZTP Boot ULM Default Live Patch ESX Host NVMe Tier EDP/RDMA ESX Host SEV-SNP Intel TDX ESX Host GPU/AI AMD MI350 VI Workload Domain(s) Multiple vSphere Clusters ยท Per-Domain vCenter ยท Shared/Dedicated NSX vSAN ESA Cluster Global Dedup + RAID-6 Data-in-Transit Enc vSAN Replication NVMe Tiering NEW NSX Edge Cluster Tier-0/1 Gateways VPC + Transit GW Avi LB ยท L4/L7 VNA Cluster NEW Edge / Specialty Domains Far Edge ยท Government ยท Manufacturing ยท Private AI VCF Edge 10 Patterns 2-Node vSAN Private AI GPU Clusters AMD MI350 vGPU/DirectPath Stretched Dual AZ NSX Edge HA vSAN Witness PHYSICAL INFRASTRUCTURE ToR Switch (25/100G) Spine/Leaf Fabric NVMe/SSD/FC SAN NTP ยท DNS ยท DHCP SFTP Backup Target CA (MSCA/HashiVault) NVIDIA/AMD GPU HW TPM 2.0 LEGEND: VCF Core (vSphere/vCenter) NSX Networking vSAN Storage VCF Automation Supervisor Platform Mgmt Services (NEW) Click components for detail โ†‘ โšก FIPS 140-3 supported across ESX ยท vCenter ยท NSX ยท vSAN ยท SDDC Manager ๐ŸŒ Languages: English ยท Japanese ยท Spanish ยท French | No non-ASCII input VCF 9.1.0.0 GA: 12 MAY 2026 ยท Patches: 9.1.0.x series | SDDC Mgr max 4 patches tracked
๐Ÿ“ฆ Bill of Materials (BOM) โ€” VCF 9.1.0.0 ยท GA: 12 MAY 2026
Component Category VCF SKU vSF SKU Version Build Number
VCF Installer / SDDC ManagerCoreโœ…โœ…9.1.0.025371088
ESX HypervisorCoreโœ…โœ…9.1.0.025370933
vCenter ServerCoreโœ…โœ…9.1.0.025370922
vSAN ESA WitnessStorageโœ…โœ…9.1.0.025370927
vSAN File ServicesStorageโœ…โœ…9.1.0.025370922
vSAN OSA WitnessStorageโœ…โœ…9.1.0.025370925
NSX (Networking)Networkโœ…โ€”9.1.0.025318225
Supervisor (vSphere Supervisor)Supervisorโœ…โœ…9.1.0.025370922
VKS Standard PackagesSupervisorโœ…โœ…3.6.0+20260211N/A
vSphere Kubernetes ReleasesSupervisorโœ…โœ…1.34.2+vmware.2-vkr.2N/A
VMware Kubernetes Service (VKS)Supervisorโœ…โœ…3.6.1+v1.35N/A
Harbor (Supervisor Service)Sup. Serviceโœ…โœ…9.1.0.025220498
Argo CD Supervisor ServiceSup. Serviceโœ…โœ…9.1.0.025100889
CA Cluster Issuer Supervisor ServiceSup. Serviceโœ…โœ…9.1.0.025317155
Contour Supervisor ServiceSup. Serviceโœ…โœ…9.1.0.025276585
External DNS Supervisor ServiceSup. Serviceโœ…โœ…9.1.0.025276584
Supervisor Management ProxySup. Serviceโœ…โœ…9.1.0.025317170
VCF OperationsOperationsโœ…โœ…9.1.0.025346025
Cloud ProxyOperationsโœ…โœ…9.1.0.025346033
VCF Operations for NetworksOperationsโœ…โ€”9.1.0.025318550
VCF Operations HCXOperationsโœ…โ€”9.1.0.025318520
VCF Operations OrchestratorOperationsโœ…โœ…9.1.0.025346069
VCF AutomationAutomationโœ…โ€”9.1.0.025370929
Fleet Lifecycle NEWMgmt Svcโœ…โœ…9.1.0.025371109
Identity BrokerMgmt Svcโœ…โ€”9.1.0.025368698
License ServerMgmt Svcโœ…โœ…9.1.0.025346031
Log ManagementMgmt Svcโœ…โœ…9.1.0.025346055
Real-Time MetricsMgmt Svcโœ…โ€”9.1.0.025346020
Real-Time Metrics StoreMgmt Svcโœ…โ€”9.1.0.025346020
Salt RaaSMgmt Svcโœ…โœ…9.1.0.025346036
Salt MasterMgmt Svcโœ…โœ…9.1.0.025346036
SDDC LifecycleMgmt Svcโœ…โœ…9.1.0.025371107
Software DepotMgmt Svcโœ…โœ…9.1.0.025371105
TelemetryMgmt Svcโœ…โœ…9.1.0.025181946
VCF Services Runtime NEWMgmt Svcโœ…โœ…9.1.0.025370367
VCF Download ToolMgmt Svcโœ…โœ…9.1.0.025371089
Secret Store ServiceVCF Svcโœ…โ€”9.1.0.025367485
Migration Service EngineVCF Svcโœ…โ€”9.1.0.025370929
VKS Cluster ManagementVCF Svcโœ…โ€”9.1.0.025370929
Configuration ServiceVCF Svcโœ…โ€”9.1.0.025303350
DSM Data Services (Add-on)VCF Svcโ€”โ€”9.1.0.025367580
Encryption ManagementVCF Svcโœ…โ€”9.1.0.025370929
Metrics Aggregator PackageVCF Svcโœ…โ€”9.1.0.025317134
Protection and Recovery (Add-on)VCF Svcโ€”โ€”9.1.0.025367487
Harbor (VCF Svc)VCF Svcโœ…โ€”9.1.0.025370929
VMware Remote ConsoleToolsโœ…โœ…13.1.0.025236164
VMware ToolsToolsโœ…โœ…13.1.0.025294452
VCF Consumption CLIToolsโœ…โœ…9.1.0.025296329
VCF Consumption CLI Plugins & DBToolsโœ…โœ…9.1.0.025305443
Deep Learning VMAdd-onโœ…โœ…9.1.0.025217931
VMware Data Services ManagerAdd-onโ€”โ€”9.1.0.025367580
Protection and RecoveryAdd-onโœ…โœ…9.1.0.025367487
Avi Load BalancerAdd-onโ€”โ€”32.1.125377988
Private AI ServicesAdd-onโ€”โ€”2.0.89Separate
โšก VCF = VMware Cloud Foundation SKU  |  vSF = vSphere Foundation SKU  |  Build 9.1.0.0 GA date: 12 MAY 2026
โœจ What's New in VCF 9.1 โ€” By Component
๐Ÿ”’ Security & Hypervisor
๐Ÿ›ก๏ธ User-Level Monitor (ULM) โ€” GA Defaultโ–ธ
ULM is now the default VM monitor for all VMs. Completely reimplements the VMM for ESX, significantly reducing hypervisor code in privileged mode โ†’ reduced attack surface for guest escapes.
๐Ÿ” AMD SEV-SNP โ€” General Availabilityโ–ธ
Hardware-based Trusted Execution Environment (TEE). Adds memory integrity protection against data re-play and memory re-mapping attacks. Remote attestation support. Compatible with AMD EPYC Zen 3 (Milan) and later.
๐Ÿ” Intel TDX โ€” General Availabilityโ–ธ
Hardware-based TEE with attestation. Compatible with Intel Xeon Gen 5 (Emerald Rapids) and later. Integrity + confidentiality for critical workloads.
โšก Quick Boot for Confidential VMsโ–ธ
Quick Boot now supports hosts running confidential VMs. Bypasses full power cycle/firmware initialization. Significantly reduces upgrade time and maintenance windows.
๐Ÿš€ Performance & Hardware
๐Ÿง  NVMe Memory Tiering โ€” Enhancedโ–ธ
Hypervisor tiers active pages to DRAM, cold pages to local NVMe. Expands effective memory capacity without additional DRAM. Includes software-based mirroring and cost savings analysis.
๐ŸŽฎ NVIDIA ConnectX-7 + BlueField-3 Enhanced DirectPathโ–ธ
vSphere vMotion, Storage vMotion, Live Patch, Hot-Add/Remove virtual hardware support with passthrough for AI/HPC. Enhanced operational flexibility.
๐ŸŽฎ AMD MI350 GPU โ€” Enhanced DirectPathโ–ธ
New GPU support for AI/HPC workloads. Supports Live Patch, Storage vMotion, Hot-Add/Remove. Hugging Face + PyTorch + OPEA + UALink partnerships for optimized AI performance.
๐Ÿ’ป Intel NIC E825 (Xeon Gen 6 Granite Rapids-D)โ–ธ
Support for Intel NIC E825 as LAN on Motherboard (LOM) NIC in Intel Xeon Gen 6 (Granite Rapids-D) platform. Expands hardware compatibility.
๐Ÿ”€ AMD IOMMU Virtualization for DirectPathโ–ธ
IOMMU virtualization for AMD hosts with DirectPath devices. Near-native hardware access performance, improved security and memory isolation.
๐Ÿ“‹ Guest OS, APIs & Operations
๐ŸŒ Zero Touch Provisioning (ZTP) โ€” ESX Installโ–ธ
Secure UEFI + HTTPS-based network boot provisioning at scale. No PXE/TFTP infrastructure required. Static network config on bare metal. Forward-looking replacement for Auto Deploy (deprecated in 9.0).
๐Ÿ”ง Live Patching for ESX (TPM-enabled hosts)โ–ธ
Patches applied to running kernel memory. VMs continue running with no maintenance window. Covers up to 80% of patches. Requires TPM-enabled hosts.
๐Ÿ“‹ New Guest OS Support in ESX 9.1โ–ธ
New: Ubuntu 26.04 LTS ยท SUSE Linux Enterprise 16 ยท Debian 13.0 ยท FreeBSD 15.0 ยท Pardus 25.0 ยท CentOS Stream 10 (Tech Preview) ยท CentOS Stream 9 (Tech Preview).
Terminated: RHEL 4.x ยท Oracle Linux 5.x ยท CentOS 4.x/5.x ยท SLES 10 SP4 ยท Debian 7.x ยท Asianux 3.x/4.x.
๐Ÿ”Œ Guest Customization API Updatesโ–ธ
IPv6-Only Support (deactivate IPv4). Partial network customization (network fields only). Expanded account management (root pwd on Linux). Live network customization for powered-on VMs. Windows script execution support.
๐Ÿ–ฅ๏ธ vCenter: vSphere Cluster Services (vCLS) Deactivated by Defaultโ–ธ
Starting vCenter 9.1: vCLS deactivated by default. Cannot be re-activated. APIs/configs not supported โ†’ removed in next major release. Port 514 (UDP/TCP, unencrypted syslog) blocked โ€” use port 1514 (TLS).
๐Ÿ”— CBT Enhancement for Snapshot Operationsโ–ธ
Change Block Tracking (CBT) enablement removes VM unresponsiveness during snapshot operations. VM responsiveness maintained throughout snapshot; overall snapshot time unchanged but unresponsiveness window eliminated.
๐Ÿ”„ vSAN ESA Auto RAID-6 (Default)โ–ธ
vSAN clusters now use RAID-6 as the default RAID level. Automatic configuration removes manual selection. Superior data protection with no performance impact.
๐ŸŒ vSAN ESA Global Deduplicationโ–ธ
Cluster-wide, post-processing deduplication setting. Encryption support included. Increases storage space savings, reduces consumption without impacting performance.
๐Ÿ”’ Cyber Recovery vSAN Storage Clusterโ–ธ
New cyber recovery vSAN storage cluster deployable via vCenter Quickstart. Integrated EDR + vDefend push-button network isolation. Immutable snapshots. On-premises clean room recovery.
โฉ Seeding for vSAN Replicationโ–ธ
Optimizes data transfer using existing replicas. Avoids full synchronization on new replications. Syncs only incremental changes โ†’ saves time and bandwidth.
๐Ÿท๏ธ Tag-Based VM Membership for Protection Groupsโ–ธ
Protection group membership via VM tags. Automatically protects new workloads based on assigned metadata. No manual intervention required for newly deployed VMs.
๐Ÿ“… Multiple Retention Schedules for vSAN Snapshotsโ–ธ
Daily, weekly, and monthly snapshot schedules. Supports long-term cyber recovery strategies. Operational recovery for day-to-day needs.
๐Ÿ“ก vSAN Replication from Any Source Siteโ–ธ
Extends vSAN replication to support workloads on any storage (using vSAN ESA as target). Dynamic protection groups, immutable snapshots, integrated vCenter UI across broader workloads.
๐Ÿ“ฆ vSAN ESA Compression Enhancementsโ–ธ
Improved vSAN ESA compression delivers better storage efficiency. Increased space savings vs previous releases. Storage consumption reduced without performance impact.
๐ŸŒ VPC & Networking
โ˜๏ธ Avi LB Integration with VPC + Distributed Transit GWโ–ธ
Avi load balancers now supported with VPCs and Transit Gateways with distributed VLAN connection. Full self-service from provider management portal.
๐Ÿ“ก Distributed VLAN Connection for Supervisor + VCF Automationโ–ธ
Virtual Network Appliance (VNA) integration adds services to enable Distributed Transit Gateway for Supervisor. VCF Automation connects to DC via simple VLAN โ€” eliminates complex networking prerequisites.
๐Ÿ”’ IPSec VPN on Centralized Transit Gatewayโ–ธ
IPSec VPN service now supported for VPC using centralized external connectivity. Enables secure VPN for VPC-based workloads without additional infrastructure.
โš–๏ธ L4 Load Balancer on Virtual Network Applianceโ–ธ
VPCs now support L4 LB functionality via Virtual Networking Appliance (VNA). Full L4 load balancing, dedicated appliance ensures scalability and service isolation.
๐Ÿ›ก๏ธ Security & Platform
๐ŸŒ Extended vCenter Integration (Transit GW / VPC)โ–ธ
Transit Gateway visible + fully configurable from vCenter. Subnet extension to VLAN in vCenter. Full IPAM visibility + IP allocation. Extended Topology views + Traceflow from vCenter. DHCP server/relay configurable from vCenter.
๐Ÿ”ง Terraform Extended Coverage (TGW + VPC)โ–ธ
NSX Terraform Provider evolves with new capabilities: multiple TGW, advanced connectivity options, improved IPAM, VLAN Extension, VPC features.
๐Ÿ“Š Real-Time Metrics APIs (Prometheus/PromQL)โ–ธ
High-granularity (up to 2-second) metrics across ESX, vCenter, vSAN, NSX stack. Native Grafana integration. Built-in collection profiles: Essentials, Standard, Verbose. Single API call configuration replaces complex legacy model.
๐Ÿ”„ NSX UI Reorganization for VPC/IPAMโ–ธ
Extended VPC section with per-feature views (subnet, NAT). Full IP allocation workflow. Re-organized Networking tabs: VPC objects (TGW) vs Segment objects (Tier-1, segments) clearly delineated.
๐Ÿš€ VCF Installer โ€” New Capabilities
๐Ÿ—๏ธ Default Component Deployment (Day 0)โ–ธ
VCF Installer now deploys a default set of VCF Management Services during new deployment: VCF Services Runtime, Fleet Lifecycle, Identity Broker, Software Depot, Salt RaaS, Telemetry, License Server. Critical services available from Day 0.
๐Ÿ“‹ Integrated Planning Workflowโ–ธ
Define deployment topology + component selection in UI. VCF Installer generates CPU, Memory, Storage, VLAN, and FQDN requirements. Validates against target infrastructure prior to deployment.
๐Ÿ”— LACP Configuration via Native UIโ–ธ
Native UI controls for configuring LACP on vSphere Distributed Switches during management domain deployment. Includes validation prechecks for physical network fabric. Previously API-only.
๐Ÿ” Auto-Generated Passwords During Deploymentโ–ธ
VCF Installer auto-generates complex passwords for system-managed and break-glass accounts. Credentials retrieved post-deployment. Reduces risk from static/shared passwords during initial config.
โš™๏ธ SDDC Manager โ€” New Capabilities
๐Ÿ”€ Dual Stack (IPv4/IPv6) Networking Supportโ–ธ
Native support for Dual Stack networking for management and workload domains. New deployments: configure with IPv4 or Dual Stack. Existing: after upgrade to 9.1, configure SDDC Manager for Dual Stack โ†’ deploy new workload domains in Dual Stack mode.
๐Ÿ› ๏ธ Out-of-Band Operations in vCenterโ–ธ
New operations supported in vCenter without impacting SDDC Manager: vDS changes (add/remove/teaming/MTU/PNICs), primary datastore changes, datastore changes, manual vCenter upgrade.
๐ŸŒ Custom Networking for VCF Operations/Automation Deploymentโ–ธ
VCF Installer UI supports deployment of VCF Operations and VCF Automation on custom network configurations: separate VDS, DVPGs, VPCs, NSX Segments.
๐Ÿ”„ Convergence: vCenter 8.0 U3a+ with NSX 4.2+ Supportedโ–ธ
Convergence/import now supported for: existing vCenter 8.0 U3a+ with NSX 4.2+ (no manual upgrades). vCenter 8.0 U3a+ without NSX (manual vCenter upgrade to 9.1 required). vCenter instances in NSX Federation configurations.
๐Ÿ—๏ธ Build Capabilities
๐Ÿ”„ Fleet Lifecycle (Replaces Fleet Management Appliance)โ–ธ
Standalone Fleet Management Appliance is replaced by Fleet Lifecycle component. Streamlines lifecycle management of VCF management components. Fetches inventory from legacy Fleet management appliance on deployment.
๐ŸŒ UI Support for LACPโ–ธ
Native UI controls for LACP on vSphere Distributed Switches during workload domain deployment. Includes validation prechecks for physical network fabric. Previously API-only capability.
๐Ÿ“ฆ Workload Domain Without vSphere Clusterโ–ธ
New workflow: deploy vCenter + new/existing NSX Manager without a vSphere Cluster. Warning: Cannot patch/upgrade components until cluster is added. Domains sharing NSX with a clusterless domain are also blocked from patch/upgrade.
๐Ÿ“Š Operate & Protect
๐Ÿ›ก๏ธ Security Posture Management (Replaces Compliance)โ–ธ
Compliance feature deprecated โ†’ replaced by Security Posture Management. Enhanced assessment and remediation capabilities. Continuous compliance enforcement. Unified security posture management for VCF stack.
๐Ÿ“Š Real-Time Metrics API (VODAP) โ€” Newโ–ธ
High-granularity (up to 2-second) Prometheus-compatible APIs. Covers ESX, vCenter, vSAN, NSX. Native Grafana/PromQL support. Built-in profiles: Essentials, Standard, Verbose. Replaces legacy vStats Tech-Preview APIs.
๐Ÿ” vCenter Group Federated API (VGFA)โ–ธ
Single unified API endpoint for managing all vCenter instances in a group. View/manage inventory across multiple vCenters as one. No changes to existing API integrations. Enables from VCF Operations UI with SSO + vCenter group config.
๐Ÿค– Provider Management
๐Ÿ”„ Migration Tool (VCD โ†’ VCF Automation)โ–ธ
In-place migration from VMware Cloud Director (VCD) to VCF Automation. Contact Broadcom representative for access. Full provider management transition support.
๐Ÿ›ก๏ธ vDefend DFW + Gateway Firewall Integrationโ–ธ
Provider admins can delegate vDefend Firewall services to org admins. Control over vDefend Gateway for Transit Gateway Firewall and DFW. Out-of-the-box security profiles for VPCs. RBAC labeling for dynamic security groups.
โš–๏ธ Full Avi Load Balancer Self-Serviceโ–ธ
Delegate LB creation/management to All Apps org. Set quotas (SE limits, app limits). Provision namespaces with Avi LB. Full VIP, pool, health monitors, persistence profiles. Also supported for VM Apps orgs.
๐Ÿข Organization Management
๐Ÿ”— Multiple External Connections per Orgโ–ธ
Multiple exit points for external communication per organization. Supports centralized connections (NSX Tier-0/VRF) and distributed VLAN connections. Previously limited to single provider gateway.
๐ŸŒ Shared VLAN Extension Subnetsโ–ธ
Configure VLAN extension NSX subnets + share with one or multiple orgs. Enables workloads to directly connect to devices on VLAN. Provider Management UI control.
๐Ÿ“Š External IP Blocks with Multiple CIDRsโ–ธ
IP spaces renamed to external IP blocks. Multiple CIDRs per block. Included/excluded custom IP ranges. NSX + Infoblox External IPAM integration. Option to hide IP block content from consuming orgs.
โ˜• Java SDK
  • New components: NSX, VCF Ops Log Mgmt, Ops for Networks, Fleet Lifecycle, SDDC Lifecycle
  • VODAP OpenAPI specifications now available
  • New samples for VCF Installer, vCenter, NSX, VCF Operations, SDDC workflows
  • Build system changed: Gradle โ†’ Maven
  • Code samples shipped as separate .ZIP
๐Ÿ Python SDK
  • New components: NSX, VCF Ops Log Mgmt, Ops for Networks, Fleet Lifecycle, SDDC Lifecycle
  • VODAP OpenAPI specifications now available
  • New samples: VCF Installer, vCenter, NSX, VCF Operations, SDDC workflows
  • Code samples shipped as separate .ZIP
โšก PowerCLI 9.1
  • High-performance storage capabilities
  • Advanced networking features
  • Critical security capabilities
  • VCF PowerCLI Changelog tracked separately
๐Ÿ”Œ New REST API Capabilities
  • Real-Time Metrics APIs (VODAP): Prometheus-compatible, up to 2-sec granularity, Grafana-native
  • vCenter Utilization API: Monitor vCenter capacity, connections, service request limits; configurable thresholds + alarms
  • vCenter Group Federated API (VGFA): Single endpoint for multi-vCenter management
  • Query API: Fast vSphere inventory retrieval, server-side filtering, pagination, projections, entity counts
  • vSAN Data Protection API: 17 new operations for vSAN protection workflows
๐Ÿ”ผ Upgrade Sequence & Paths to VCF 9.1
โš ๏ธ STRICT UPGRADE SEQUENCE REQUIRED
Upgrading to 9.1 requires a strict component upgrade sequence. Incorrect sequence results in errors. Follow upgrade path exactly as documented.
Path A: VCF 5.2.x โ†’ 9.1
VCF 5.2.x
โ†’
Identity Broker
โ†’
VCF Operations 9.1
โ†’
SDDC Manager 9.1
โ†’
Mgmt Services
โ†’
vCenter+NSX 9.1
โ†’
ESX 9.1
โ†’
NSX Edge 9.1
โ†’
vDS Upgrade
โ†’
vSAN On-Disk
Path B: VCF 9.0.x โ†’ 9.1
VCF 9.0.x
โ†’
Redeploy Identity Broker
โ†’
VCF Operations 9.1
โ†’
SDDC Manager 9.1
โ†’
Core Components
๐Ÿ”ง Pre-Req: Identity Broker 9.0.x
Must redeploy VCF Identity Broker 9.0.x to supported network/datastore before upgrading to 9.1.
Path C: vSphere Foundation โ†’ 9.1
vSF 5.2.x / 9.0.x
โ†’
Deploy Mgmt Services + License Server
โ†’
vSphere 9.1
Path D: vSphere 8 + Aria Ops 8 โ†’ 9.1
vSphere 8
โ†’
Phase 1: Follow Upgrade Order
โ†’
Aria Ops 8 โ†’ VCF Ops 9.1
โ†’
vSphere 9.1
โš™๏ธ VCF Installer to vSphere LCM Images Transition (Critical Pre-Req)
  • vSphere LCM Baseline โ†’ Image transition required before ESX 9.1 upgrade
  • Methods: PowerShell Script (menu-driven or CLI) or SDDC Manager API
  • API workflows: Cluster API workflow or Standalone Hosts API workflow
  • PowerShell script has CLI options: cluster, standalone hosts, verbose mode
  • NSX Upgrade Checklist: Pre-upgrade tasks + manage unsupported features
  • Two NSX upgrade modes: Optimized (parallel) or Sequential
  • NSX Edge Cluster upgrades finalize AFTER NSX Manager upgrade
  • vDS + vSAN On-Disk format upgrades AFTER ESX upgrade
  • VCF Automation SSO migration: vIDM โ†’ Identity Broker required
๐Ÿ”Œ API Changelog Summary โ€” VCF 9.1
๐Ÿ–ฅ๏ธ vSphere APIs
Virtual Infrastructure JSON API
48
New Ops
0
Deprecated
0
Deleted
vSphere Automation API
101
New Ops
28
Deprecated
28
Deleted
๐ŸŒ NSX APIs
Spec๐ŸŸข New๐ŸŸก Dep๐Ÿ”ด Del
NSX Policy API26469
NSX Global Policy API5830
NSX Manager API311117
NSX Autonomous Edge API901
๐Ÿ“Š VCF Operations & Management APIs
Spec๐ŸŸข New๐ŸŸก Dep๐Ÿ”ด Del
VCF Operations API13400
Log Management API230136
SDDC Manager API48210
VCF Fleet LCM Service APIs5100
VCF SDDC LCM Service APIs2600
VCF Ops Orchestrator API701
VCF Ops for Networks API5221
๐Ÿ” Identity, Installer, Protection APIs
Spec๐ŸŸข New๐ŸŸก Dep๐Ÿ”ด Del
VMware Identity Broker - vCenter API900
VCF Installer API500
vSAN Data Protection API1700
All Apps Org - Access Control77032
โš ๏ธ Deprecations & End of Support โ€” VCF 9.1
Component Feature/Item Status Notes
ESXUSB and SD boot devicesDEPRECATED โ†’ Next MajorSupport deprecated, removed in next major release
ESXESX without persistent system storage (OSDATA)DEPRECATED โ†’ Next MajorDevices < 32GB also deprecated
ESXAPIs for reconfiguring system storage locationsDEPRECATED โ†’ Next MajorPart of system storage deprecation
ESXSuspend-to-RAM during ESX upgradesDEPRECATED โ†’ FutureUse suspend-resume or vSphere vMotion in maintenance mode
ESXMarvell/Aquantia (Atlantic) NIC drivers (10GbE USB/PCIe)DEPRECATED โ†’ FutureCommonly used in home labs
ESXAMD Solarflare 8000 and X2 series Ethernet adaptersDEPRECATED โ†’ Futureโ€”
ESXSHA1-based cryptographic algorithmsDEPRECATED โ†’ Futureโ€”
ESXMarvell E3/E4 Drivers (FastLinQ 57800/41000 series)DEPRECATED โ†’ Future MajorCNAs: FastLinQ 57800/57810/57811, 41000/45000 series
ESXCisco VIC 1200/1300 SeriesDEPRECATED โ†’ Future MajorLack of support for Enhanced Data Path (EDP)
ESXFirst Class Disk on NFS v3 (>128 hosts)NOT SUPPORTEDFCD/IVD in NFS v3 datastores shared by >128 ESX hosts
vCenterIPFIX on VDS Uplink Port Group + LagIpfixConfigDEPRECATED โ†’ Future MajorUpgrade blocked if IPFIX active on uplink ports โ€” remove before upgrading
vCenterSyslog Port 514 (UDP/TCP unencrypted)BLOCKED in 9.1Use port 1514 (TLS). Use syslog.ext.tls.port for scripted installs
vCentervSphere Cluster Services (vCLS)REMOVED โ€” Deactivated by DefaultCannot be re-activated. APIs removed in next major release. vCLS decoupled from DRS/HA in 9.0
NSXLagIpfixConfig + overwrite port policy NetflowDEPRECATEDVDS IPFIX backed by NSX Connection Track IPFIX; uplink port not supported
NSXLogical MP API for port mirroringREMOVED in 9.1No longer supported
VCF InstallervSphere Cluster Services (vCLS) in SDDC Manager UIALL vCLS UI REMOVEDIn 9.0 vCLS was decoupled from DRS/HA; in 9.1 all UI removed
VCF OperationsCompliance featureDEPRECATED โ†’ ReplacedReplaced by Security Posture Management
VCF Operations HCXPhotonOS-based appliancesDEPRECATEDNew NSX Edge-based stack introduced (better performance)
VCF OperationsLegacy cluster expansion method (via newly deployed node)DEPRECATED in 9.1โ€”
Ops for NetworksMicrosoft Azure + Amazon AWS as data sourcesDEPRECATEDโ€”
Ops for NetworksBundled OpenSSL in VCF Ops for Logs AgentDEPRECATEDโ€”
Auto DeployLegacy Auto Deploy (PXE/TFTP-based)DEPRECATED in 9.0Replaced by Zero Touch Provisioning (ZTP) in 9.1
APIsLegacy vStats Tech-Preview APIsDEPRECATEDReplaced by Real-Time Metrics APIs (VODAP / Prometheus-compatible)
๐Ÿšจ Critical Notes, Warnings & Key Considerations
๐Ÿ” Microsoft Secure Boot Certificates Expiration
Microsoft UEFI + KEK CA 2011 certs expire June 2026. Windows Production PCA 2011 expires October 2026. ESX 9.1 is multi-signed: Microsoft UEFI CA 2011 + 2023 + VMware Secure Boot. Host Secure Boot of ESX 9.1 NOT affected. Complex effects on Windows/Linux guest VMs โ€” see KB article 423893.
โš ๏ธ Workload Domain Without vSphere Cluster โ€” Patch Blocker
Creating a workload domain without a vSphere cluster blocks patch/upgrade until a cluster is added. All workload domains sharing NSX with a clusterless domain are also blocked.
๐Ÿ”„ VCF Automation SSO Migration Required
Must migrate VCF Automation SSO config from VMware Identity Manager (vIDM) to VCF Identity Broker before completing upgrade. Complex multi-step migration involving user groups, accounts, and OIDC connections.
๐Ÿ“ฆ VCF Versioning Not Applicable to External Dependencies
OEM driver add-ons, ESX device drivers, UI plugins, and Kubernetes versions maintain their own external versioning. VCF 9.1 versioning does not apply to these. Clusters without active VMware Supervisor supported but cannot use key VCF capabilities (VCF Automation workflows).
โ„น๏ธ Non-ASCII Input Not Supported
Components of VMware Cloud Foundation 9.1 do not accept non-ASCII input. This applies across the platform.
โ„น๏ธ VCF Installer Default Component Deployment (Day 0)
New deployments now automatically deploy: VCF Services Runtime, Fleet Lifecycle, Identity Broker, Software Depot, Salt RaaS, Telemetry, License Server. No additional configuration required.
โ„น๏ธ Live Patch Requirement
Live Patching for ESX requires TPM-enabled hosts. Covers up to 80% of patches. VMs continue running with no maintenance window.
โ„น๏ธ Avi Load Balancer 32.1.1 โ€” Separate BOM Version
Avi LB ships at version 32.1.1 (Build 25377988) โ€” separate versioning scheme from VCF 9.1 components. Not included in VCF or vSphere Foundation SKU; add-on only.
โ„น๏ธ Private AI Components โ€” Separate Delivery
VMware Deep Learning VM 9.1 (Build 25217931) and Private AI Services 2.0.89 delivered separately from VCF 9.1 software bits. Guided deployment workflow and AI catalog items included in VCF software.
โ„น๏ธ VCF Login URL Format
When logging in to VCF Operations, use https://<IP> or FQDN โ€” not plain IP.
๐Ÿ› ๏ธ Critical Technical Parameters & Limits
  • ESX system storage min: 32 GB (USB/SD deprecated)
  • NFS v3 FCD host limit: 128 ESX hosts max
  • Live Patch coverage: Up to 80% of patches
  • vCenter syslog port: 1514 (TLS); 514 blocked
  • Grafana metrics granularity: Up to 2 seconds (VODAP)
  • VCF supported languages: English, Japanese, Spanish, French
  • SEV-SNP compatibility: AMD EPYC Zen 3 (Milan)+
  • Intel TDX compatibility: Intel Xeon Gen 5 (Emerald Rapids)+
  • ConnectX-7/BlueField-3: Enhanced DirectPath in 9.1
  • AMD MI350: Enhanced DirectPath in 9.1
  • Patch sub-releases tracked: 9.1.0.x (4 sub-releases)
  • SDDC Manager patch count: 4 tracked (0100-0400)
  • ZTP imaging: UEFI + HTTPS; static network config on bare metal
  • vCLS: Deactivated by default; cannot be re-enabled in 9.1
  • vSAN RAID default: RAID-6 (ESA, automatic in 9.1)