Architecture & Component Topology โ VCF 9.1
9.1
Platform Release
33+
BOM Components
11
New Features (Major)
4
Patch Sub-Releases
โธ VCF 9.1 Full-Stack Architecture (Click components for details)
Bill of Materials (BOM) โ VCF 9.1.0.0 ยท GA: 12 MAY 2026
| Component | Category | VCF SKU | vSF SKU | Version | Build Number |
|---|---|---|---|---|---|
| VCF Installer / SDDC Manager | Core | โ | โ | 9.1.0.0 | 25371088 |
| ESX Hypervisor | Core | โ | โ | 9.1.0.0 | 25370933 |
| vCenter Server | Core | โ | โ | 9.1.0.0 | 25370922 |
| vSAN ESA Witness | Storage | โ | โ | 9.1.0.0 | 25370927 |
| vSAN File Services | Storage | โ | โ | 9.1.0.0 | 25370922 |
| vSAN OSA Witness | Storage | โ | โ | 9.1.0.0 | 25370925 |
| NSX (Networking) | Network | โ | โ | 9.1.0.0 | 25318225 |
| Supervisor (vSphere Supervisor) | Supervisor | โ | โ | 9.1.0.0 | 25370922 |
| VKS Standard Packages | Supervisor | โ | โ | 3.6.0+20260211 | N/A |
| vSphere Kubernetes Releases | Supervisor | โ | โ | 1.34.2+vmware.2-vkr.2 | N/A |
| VMware Kubernetes Service (VKS) | Supervisor | โ | โ | 3.6.1+v1.35 | N/A |
| Harbor (Supervisor Service) | Sup. Service | โ | โ | 9.1.0.0 | 25220498 |
| Argo CD Supervisor Service | Sup. Service | โ | โ | 9.1.0.0 | 25100889 |
| CA Cluster Issuer Supervisor Service | Sup. Service | โ | โ | 9.1.0.0 | 25317155 |
| Contour Supervisor Service | Sup. Service | โ | โ | 9.1.0.0 | 25276585 |
| External DNS Supervisor Service | Sup. Service | โ | โ | 9.1.0.0 | 25276584 |
| Supervisor Management Proxy | Sup. Service | โ | โ | 9.1.0.0 | 25317170 |
| VCF Operations | Operations | โ | โ | 9.1.0.0 | 25346025 |
| Cloud Proxy | Operations | โ | โ | 9.1.0.0 | 25346033 |
| VCF Operations for Networks | Operations | โ | โ | 9.1.0.0 | 25318550 |
| VCF Operations HCX | Operations | โ | โ | 9.1.0.0 | 25318520 |
| VCF Operations Orchestrator | Operations | โ | โ | 9.1.0.0 | 25346069 |
| VCF Automation | Automation | โ | โ | 9.1.0.0 | 25370929 |
| Fleet Lifecycle NEW | Mgmt Svc | โ | โ | 9.1.0.0 | 25371109 |
| Identity Broker | Mgmt Svc | โ | โ | 9.1.0.0 | 25368698 |
| License Server | Mgmt Svc | โ | โ | 9.1.0.0 | 25346031 |
| Log Management | Mgmt Svc | โ | โ | 9.1.0.0 | 25346055 |
| Real-Time Metrics | Mgmt Svc | โ | โ | 9.1.0.0 | 25346020 |
| Real-Time Metrics Store | Mgmt Svc | โ | โ | 9.1.0.0 | 25346020 |
| Salt RaaS | Mgmt Svc | โ | โ | 9.1.0.0 | 25346036 |
| Salt Master | Mgmt Svc | โ | โ | 9.1.0.0 | 25346036 |
| SDDC Lifecycle | Mgmt Svc | โ | โ | 9.1.0.0 | 25371107 |
| Software Depot | Mgmt Svc | โ | โ | 9.1.0.0 | 25371105 |
| Telemetry | Mgmt Svc | โ | โ | 9.1.0.0 | 25181946 |
| VCF Services Runtime NEW | Mgmt Svc | โ | โ | 9.1.0.0 | 25370367 |
| VCF Download Tool | Mgmt Svc | โ | โ | 9.1.0.0 | 25371089 |
| Secret Store Service | VCF Svc | โ | โ | 9.1.0.0 | 25367485 |
| Migration Service Engine | VCF Svc | โ | โ | 9.1.0.0 | 25370929 |
| VKS Cluster Management | VCF Svc | โ | โ | 9.1.0.0 | 25370929 |
| Configuration Service | VCF Svc | โ | โ | 9.1.0.0 | 25303350 |
| DSM Data Services (Add-on) | VCF Svc | โ | โ | 9.1.0.0 | 25367580 |
| Encryption Management | VCF Svc | โ | โ | 9.1.0.0 | 25370929 |
| Metrics Aggregator Package | VCF Svc | โ | โ | 9.1.0.0 | 25317134 |
| Protection and Recovery (Add-on) | VCF Svc | โ | โ | 9.1.0.0 | 25367487 |
| Harbor (VCF Svc) | VCF Svc | โ | โ | 9.1.0.0 | 25370929 |
| VMware Remote Console | Tools | โ | โ | 13.1.0.0 | 25236164 |
| VMware Tools | Tools | โ | โ | 13.1.0.0 | 25294452 |
| VCF Consumption CLI | Tools | โ | โ | 9.1.0.0 | 25296329 |
| VCF Consumption CLI Plugins & DB | Tools | โ | โ | 9.1.0.0 | 25305443 |
| Deep Learning VM | Add-on | โ | โ | 9.1.0.0 | 25217931 |
| VMware Data Services Manager | Add-on | โ | โ | 9.1.0.0 | 25367580 |
| Protection and Recovery | Add-on | โ | โ | 9.1.0.0 | 25367487 |
| Avi Load Balancer | Add-on | โ | โ | 32.1.1 | 25377988 |
| Private AI Services | Add-on | โ | โ | 2.0.89 | Separate |
โก VCF = VMware Cloud Foundation SKU | vSF = vSphere Foundation SKU | Build 9.1.0.0 GA date: 12 MAY 2026
What's New in VCF 9.1 โ By Component
๐ Security & Hypervisor
๐ก๏ธ User-Level Monitor (ULM) โ GA Defaultโธ
ULM is now the default VM monitor for all VMs. Completely reimplements the VMM for ESX, significantly reducing hypervisor code in privileged mode โ reduced attack surface for guest escapes.
๐ AMD SEV-SNP โ General Availabilityโธ
Hardware-based Trusted Execution Environment (TEE). Adds memory integrity protection against data re-play and memory re-mapping attacks. Remote attestation support. Compatible with AMD EPYC Zen 3 (Milan) and later.
๐ Intel TDX โ General Availabilityโธ
Hardware-based TEE with attestation. Compatible with Intel Xeon Gen 5 (Emerald Rapids) and later. Integrity + confidentiality for critical workloads.
โก Quick Boot for Confidential VMsโธ
Quick Boot now supports hosts running confidential VMs. Bypasses full power cycle/firmware initialization. Significantly reduces upgrade time and maintenance windows.
๐ Performance & Hardware
๐ง NVMe Memory Tiering โ Enhancedโธ
Hypervisor tiers active pages to DRAM, cold pages to local NVMe. Expands effective memory capacity without additional DRAM. Includes software-based mirroring and cost savings analysis.
๐ฎ NVIDIA ConnectX-7 + BlueField-3 Enhanced DirectPathโธ
vSphere vMotion, Storage vMotion, Live Patch, Hot-Add/Remove virtual hardware support with passthrough for AI/HPC. Enhanced operational flexibility.
๐ฎ AMD MI350 GPU โ Enhanced DirectPathโธ
New GPU support for AI/HPC workloads. Supports Live Patch, Storage vMotion, Hot-Add/Remove. Hugging Face + PyTorch + OPEA + UALink partnerships for optimized AI performance.
๐ป Intel NIC E825 (Xeon Gen 6 Granite Rapids-D)โธ
Support for Intel NIC E825 as LAN on Motherboard (LOM) NIC in Intel Xeon Gen 6 (Granite Rapids-D) platform. Expands hardware compatibility.
๐ AMD IOMMU Virtualization for DirectPathโธ
IOMMU virtualization for AMD hosts with DirectPath devices. Near-native hardware access performance, improved security and memory isolation.
๐ Guest OS, APIs & Operations
๐ Zero Touch Provisioning (ZTP) โ ESX Installโธ
Secure UEFI + HTTPS-based network boot provisioning at scale. No PXE/TFTP infrastructure required. Static network config on bare metal. Forward-looking replacement for Auto Deploy (deprecated in 9.0).
๐ง Live Patching for ESX (TPM-enabled hosts)โธ
Patches applied to running kernel memory. VMs continue running with no maintenance window. Covers up to 80% of patches. Requires TPM-enabled hosts.
๐ New Guest OS Support in ESX 9.1โธ
New: Ubuntu 26.04 LTS ยท SUSE Linux Enterprise 16 ยท Debian 13.0 ยท FreeBSD 15.0 ยท Pardus 25.0 ยท CentOS Stream 10 (Tech Preview) ยท CentOS Stream 9 (Tech Preview).
Terminated: RHEL 4.x ยท Oracle Linux 5.x ยท CentOS 4.x/5.x ยท SLES 10 SP4 ยท Debian 7.x ยท Asianux 3.x/4.x.
Terminated: RHEL 4.x ยท Oracle Linux 5.x ยท CentOS 4.x/5.x ยท SLES 10 SP4 ยท Debian 7.x ยท Asianux 3.x/4.x.
๐ Guest Customization API Updatesโธ
IPv6-Only Support (deactivate IPv4). Partial network customization (network fields only). Expanded account management (root pwd on Linux). Live network customization for powered-on VMs. Windows script execution support.
๐ฅ๏ธ vCenter: vSphere Cluster Services (vCLS) Deactivated by Defaultโธ
Starting vCenter 9.1: vCLS deactivated by default. Cannot be re-activated. APIs/configs not supported โ removed in next major release. Port 514 (UDP/TCP, unencrypted syslog) blocked โ use port 1514 (TLS).
๐ CBT Enhancement for Snapshot Operationsโธ
Change Block Tracking (CBT) enablement removes VM unresponsiveness during snapshot operations. VM responsiveness maintained throughout snapshot; overall snapshot time unchanged but unresponsiveness window eliminated.
๐ vSAN ESA Auto RAID-6 (Default)โธ
vSAN clusters now use RAID-6 as the default RAID level. Automatic configuration removes manual selection. Superior data protection with no performance impact.
๐ vSAN ESA Global Deduplicationโธ
Cluster-wide, post-processing deduplication setting. Encryption support included. Increases storage space savings, reduces consumption without impacting performance.
๐ Cyber Recovery vSAN Storage Clusterโธ
New cyber recovery vSAN storage cluster deployable via vCenter Quickstart. Integrated EDR + vDefend push-button network isolation. Immutable snapshots. On-premises clean room recovery.
โฉ Seeding for vSAN Replicationโธ
Optimizes data transfer using existing replicas. Avoids full synchronization on new replications. Syncs only incremental changes โ saves time and bandwidth.
๐ท๏ธ Tag-Based VM Membership for Protection Groupsโธ
Protection group membership via VM tags. Automatically protects new workloads based on assigned metadata. No manual intervention required for newly deployed VMs.
๐
Multiple Retention Schedules for vSAN Snapshotsโธ
Daily, weekly, and monthly snapshot schedules. Supports long-term cyber recovery strategies. Operational recovery for day-to-day needs.
๐ก vSAN Replication from Any Source Siteโธ
Extends vSAN replication to support workloads on any storage (using vSAN ESA as target). Dynamic protection groups, immutable snapshots, integrated vCenter UI across broader workloads.
๐ฆ vSAN ESA Compression Enhancementsโธ
Improved vSAN ESA compression delivers better storage efficiency. Increased space savings vs previous releases. Storage consumption reduced without performance impact.
๐ VPC & Networking
โ๏ธ Avi LB Integration with VPC + Distributed Transit GWโธ
Avi load balancers now supported with VPCs and Transit Gateways with distributed VLAN connection. Full self-service from provider management portal.
๐ก Distributed VLAN Connection for Supervisor + VCF Automationโธ
Virtual Network Appliance (VNA) integration adds services to enable Distributed Transit Gateway for Supervisor. VCF Automation connects to DC via simple VLAN โ eliminates complex networking prerequisites.
๐ IPSec VPN on Centralized Transit Gatewayโธ
IPSec VPN service now supported for VPC using centralized external connectivity. Enables secure VPN for VPC-based workloads without additional infrastructure.
โ๏ธ L4 Load Balancer on Virtual Network Applianceโธ
VPCs now support L4 LB functionality via Virtual Networking Appliance (VNA). Full L4 load balancing, dedicated appliance ensures scalability and service isolation.
๐ก๏ธ Security & Platform
๐ Extended vCenter Integration (Transit GW / VPC)โธ
Transit Gateway visible + fully configurable from vCenter. Subnet extension to VLAN in vCenter. Full IPAM visibility + IP allocation. Extended Topology views + Traceflow from vCenter. DHCP server/relay configurable from vCenter.
๐ง Terraform Extended Coverage (TGW + VPC)โธ
NSX Terraform Provider evolves with new capabilities: multiple TGW, advanced connectivity options, improved IPAM, VLAN Extension, VPC features.
๐ Real-Time Metrics APIs (Prometheus/PromQL)โธ
High-granularity (up to 2-second) metrics across ESX, vCenter, vSAN, NSX stack. Native Grafana integration. Built-in collection profiles: Essentials, Standard, Verbose. Single API call configuration replaces complex legacy model.
๐ NSX UI Reorganization for VPC/IPAMโธ
Extended VPC section with per-feature views (subnet, NAT). Full IP allocation workflow. Re-organized Networking tabs: VPC objects (TGW) vs Segment objects (Tier-1, segments) clearly delineated.
๐ VCF Installer โ New Capabilities
๐๏ธ Default Component Deployment (Day 0)โธ
VCF Installer now deploys a default set of VCF Management Services during new deployment: VCF Services Runtime, Fleet Lifecycle, Identity Broker, Software Depot, Salt RaaS, Telemetry, License Server. Critical services available from Day 0.
๐ Integrated Planning Workflowโธ
Define deployment topology + component selection in UI. VCF Installer generates CPU, Memory, Storage, VLAN, and FQDN requirements. Validates against target infrastructure prior to deployment.
๐ LACP Configuration via Native UIโธ
Native UI controls for configuring LACP on vSphere Distributed Switches during management domain deployment. Includes validation prechecks for physical network fabric. Previously API-only.
๐ Auto-Generated Passwords During Deploymentโธ
VCF Installer auto-generates complex passwords for system-managed and break-glass accounts. Credentials retrieved post-deployment. Reduces risk from static/shared passwords during initial config.
โ๏ธ SDDC Manager โ New Capabilities
๐ Dual Stack (IPv4/IPv6) Networking Supportโธ
Native support for Dual Stack networking for management and workload domains. New deployments: configure with IPv4 or Dual Stack. Existing: after upgrade to 9.1, configure SDDC Manager for Dual Stack โ deploy new workload domains in Dual Stack mode.
๐ ๏ธ Out-of-Band Operations in vCenterโธ
New operations supported in vCenter without impacting SDDC Manager: vDS changes (add/remove/teaming/MTU/PNICs), primary datastore changes, datastore changes, manual vCenter upgrade.
๐ Custom Networking for VCF Operations/Automation Deploymentโธ
VCF Installer UI supports deployment of VCF Operations and VCF Automation on custom network configurations: separate VDS, DVPGs, VPCs, NSX Segments.
๐ Convergence: vCenter 8.0 U3a+ with NSX 4.2+ Supportedโธ
Convergence/import now supported for: existing vCenter 8.0 U3a+ with NSX 4.2+ (no manual upgrades). vCenter 8.0 U3a+ without NSX (manual vCenter upgrade to 9.1 required). vCenter instances in NSX Federation configurations.
๐๏ธ Build Capabilities
๐ Fleet Lifecycle (Replaces Fleet Management Appliance)โธ
Standalone Fleet Management Appliance is replaced by Fleet Lifecycle component. Streamlines lifecycle management of VCF management components. Fetches inventory from legacy Fleet management appliance on deployment.
๐ UI Support for LACPโธ
Native UI controls for LACP on vSphere Distributed Switches during workload domain deployment. Includes validation prechecks for physical network fabric. Previously API-only capability.
๐ฆ Workload Domain Without vSphere Clusterโธ
New workflow: deploy vCenter + new/existing NSX Manager without a vSphere Cluster. Warning: Cannot patch/upgrade components until cluster is added. Domains sharing NSX with a clusterless domain are also blocked from patch/upgrade.
๐ Operate & Protect
๐ก๏ธ Security Posture Management (Replaces Compliance)โธ
Compliance feature deprecated โ replaced by Security Posture Management. Enhanced assessment and remediation capabilities. Continuous compliance enforcement. Unified security posture management for VCF stack.
๐ Real-Time Metrics API (VODAP) โ Newโธ
High-granularity (up to 2-second) Prometheus-compatible APIs. Covers ESX, vCenter, vSAN, NSX. Native Grafana/PromQL support. Built-in profiles: Essentials, Standard, Verbose. Replaces legacy vStats Tech-Preview APIs.
๐ vCenter Group Federated API (VGFA)โธ
Single unified API endpoint for managing all vCenter instances in a group. View/manage inventory across multiple vCenters as one. No changes to existing API integrations. Enables from VCF Operations UI with SSO + vCenter group config.
๐ค Provider Management
๐ Migration Tool (VCD โ VCF Automation)โธ
In-place migration from VMware Cloud Director (VCD) to VCF Automation. Contact Broadcom representative for access. Full provider management transition support.
๐ก๏ธ vDefend DFW + Gateway Firewall Integrationโธ
Provider admins can delegate vDefend Firewall services to org admins. Control over vDefend Gateway for Transit Gateway Firewall and DFW. Out-of-the-box security profiles for VPCs. RBAC labeling for dynamic security groups.
โ๏ธ Full Avi Load Balancer Self-Serviceโธ
Delegate LB creation/management to All Apps org. Set quotas (SE limits, app limits). Provision namespaces with Avi LB. Full VIP, pool, health monitors, persistence profiles. Also supported for VM Apps orgs.
๐ข Organization Management
๐ Multiple External Connections per Orgโธ
Multiple exit points for external communication per organization. Supports centralized connections (NSX Tier-0/VRF) and distributed VLAN connections. Previously limited to single provider gateway.
๐ Shared VLAN Extension Subnetsโธ
Configure VLAN extension NSX subnets + share with one or multiple orgs. Enables workloads to directly connect to devices on VLAN. Provider Management UI control.
๐ External IP Blocks with Multiple CIDRsโธ
IP spaces renamed to external IP blocks. Multiple CIDRs per block. Included/excluded custom IP ranges. NSX + Infoblox External IPAM integration. Option to hide IP block content from consuming orgs.
โ Java SDK
- New components: NSX, VCF Ops Log Mgmt, Ops for Networks, Fleet Lifecycle, SDDC Lifecycle
- VODAP OpenAPI specifications now available
- New samples for VCF Installer, vCenter, NSX, VCF Operations, SDDC workflows
- Build system changed: Gradle โ Maven
- Code samples shipped as separate .ZIP
๐ Python SDK
- New components: NSX, VCF Ops Log Mgmt, Ops for Networks, Fleet Lifecycle, SDDC Lifecycle
- VODAP OpenAPI specifications now available
- New samples: VCF Installer, vCenter, NSX, VCF Operations, SDDC workflows
- Code samples shipped as separate .ZIP
โก PowerCLI 9.1
- High-performance storage capabilities
- Advanced networking features
- Critical security capabilities
- VCF PowerCLI Changelog tracked separately
๐ New REST API Capabilities
- Real-Time Metrics APIs (VODAP): Prometheus-compatible, up to 2-sec granularity, Grafana-native
- vCenter Utilization API: Monitor vCenter capacity, connections, service request limits; configurable thresholds + alarms
- vCenter Group Federated API (VGFA): Single endpoint for multi-vCenter management
- Query API: Fast vSphere inventory retrieval, server-side filtering, pagination, projections, entity counts
- vSAN Data Protection API: 17 new operations for vSAN protection workflows
Upgrade Sequence & Paths to VCF 9.1
โ ๏ธ STRICT UPGRADE SEQUENCE REQUIRED
Upgrading to 9.1 requires a strict component upgrade sequence. Incorrect sequence results in errors. Follow upgrade path exactly as documented.
Path A: VCF 5.2.x โ 9.1
VCF 5.2.x
โ
Identity Broker
โ
VCF Operations 9.1
โ
SDDC Manager 9.1
โ
Mgmt Services
โ
vCenter+NSX 9.1
โ
ESX 9.1
โ
NSX Edge 9.1
โ
vDS Upgrade
โ
vSAN On-Disk
Path B: VCF 9.0.x โ 9.1
VCF 9.0.x
โ
Redeploy Identity Broker
โ
VCF Operations 9.1
โ
SDDC Manager 9.1
โ
Core Components
๐ง Pre-Req: Identity Broker 9.0.x
Must redeploy VCF Identity Broker 9.0.x to supported network/datastore before upgrading to 9.1.
Path C: vSphere Foundation โ 9.1
vSF 5.2.x / 9.0.x
โ
Deploy Mgmt Services + License Server
โ
vSphere 9.1
Path D: vSphere 8 + Aria Ops 8 โ 9.1
vSphere 8
โ
Phase 1: Follow Upgrade Order
โ
Aria Ops 8 โ VCF Ops 9.1
โ
vSphere 9.1
โ๏ธ VCF Installer to vSphere LCM Images Transition (Critical Pre-Req)
- vSphere LCM Baseline โ Image transition required before ESX 9.1 upgrade
- Methods: PowerShell Script (menu-driven or CLI) or SDDC Manager API
- API workflows: Cluster API workflow or Standalone Hosts API workflow
- PowerShell script has CLI options: cluster, standalone hosts, verbose mode
- NSX Upgrade Checklist: Pre-upgrade tasks + manage unsupported features
- Two NSX upgrade modes: Optimized (parallel) or Sequential
- NSX Edge Cluster upgrades finalize AFTER NSX Manager upgrade
- vDS + vSAN On-Disk format upgrades AFTER ESX upgrade
- VCF Automation SSO migration: vIDM โ Identity Broker required
API Changelog Summary โ VCF 9.1
๐ฅ๏ธ vSphere APIs
Virtual Infrastructure JSON API
48
New Ops
0
Deprecated
0
Deleted
vSphere Automation API
101
New Ops
28
Deprecated
28
Deleted
๐ NSX APIs
| Spec | ๐ข New | ๐ก Dep | ๐ด Del |
|---|---|---|---|
| NSX Policy API | 264 | 6 | 9 |
| NSX Global Policy API | 58 | 3 | 0 |
| NSX Manager API | 31 | 11 | 17 |
| NSX Autonomous Edge API | 9 | 0 | 1 |
๐ VCF Operations & Management APIs
| Spec | ๐ข New | ๐ก Dep | ๐ด Del |
|---|---|---|---|
| VCF Operations API | 134 | 0 | 0 |
| Log Management API | 23 | 0 | 136 |
| SDDC Manager API | 48 | 21 | 0 |
| VCF Fleet LCM Service APIs | 51 | 0 | 0 |
| VCF SDDC LCM Service APIs | 26 | 0 | 0 |
| VCF Ops Orchestrator API | 7 | 0 | 1 |
| VCF Ops for Networks API | 5 | 22 | 1 |
๐ Identity, Installer, Protection APIs
| Spec | ๐ข New | ๐ก Dep | ๐ด Del |
|---|---|---|---|
| VMware Identity Broker - vCenter API | 9 | 0 | 0 |
| VCF Installer API | 5 | 0 | 0 |
| vSAN Data Protection API | 17 | 0 | 0 |
| All Apps Org - Access Control | 77 | 0 | 32 |
Deprecations & End of Support โ VCF 9.1
| Component | Feature/Item | Status | Notes |
|---|---|---|---|
| ESX | USB and SD boot devices | DEPRECATED โ Next Major | Support deprecated, removed in next major release |
| ESX | ESX without persistent system storage (OSDATA) | DEPRECATED โ Next Major | Devices < 32GB also deprecated |
| ESX | APIs for reconfiguring system storage locations | DEPRECATED โ Next Major | Part of system storage deprecation |
| ESX | Suspend-to-RAM during ESX upgrades | DEPRECATED โ Future | Use suspend-resume or vSphere vMotion in maintenance mode |
| ESX | Marvell/Aquantia (Atlantic) NIC drivers (10GbE USB/PCIe) | DEPRECATED โ Future | Commonly used in home labs |
| ESX | AMD Solarflare 8000 and X2 series Ethernet adapters | DEPRECATED โ Future | โ |
| ESX | SHA1-based cryptographic algorithms | DEPRECATED โ Future | โ |
| ESX | Marvell E3/E4 Drivers (FastLinQ 57800/41000 series) | DEPRECATED โ Future Major | CNAs: FastLinQ 57800/57810/57811, 41000/45000 series |
| ESX | Cisco VIC 1200/1300 Series | DEPRECATED โ Future Major | Lack of support for Enhanced Data Path (EDP) |
| ESX | First Class Disk on NFS v3 (>128 hosts) | NOT SUPPORTED | FCD/IVD in NFS v3 datastores shared by >128 ESX hosts |
| vCenter | IPFIX on VDS Uplink Port Group + LagIpfixConfig | DEPRECATED โ Future Major | Upgrade blocked if IPFIX active on uplink ports โ remove before upgrading |
| vCenter | Syslog Port 514 (UDP/TCP unencrypted) | BLOCKED in 9.1 | Use port 1514 (TLS). Use syslog.ext.tls.port for scripted installs |
| vCenter | vSphere Cluster Services (vCLS) | REMOVED โ Deactivated by Default | Cannot be re-activated. APIs removed in next major release. vCLS decoupled from DRS/HA in 9.0 |
| NSX | LagIpfixConfig + overwrite port policy Netflow | DEPRECATED | VDS IPFIX backed by NSX Connection Track IPFIX; uplink port not supported |
| NSX | Logical MP API for port mirroring | REMOVED in 9.1 | No longer supported |
| VCF Installer | vSphere Cluster Services (vCLS) in SDDC Manager UI | ALL vCLS UI REMOVED | In 9.0 vCLS was decoupled from DRS/HA; in 9.1 all UI removed |
| VCF Operations | Compliance feature | DEPRECATED โ Replaced | Replaced by Security Posture Management |
| VCF Operations HCX | PhotonOS-based appliances | DEPRECATED | New NSX Edge-based stack introduced (better performance) |
| VCF Operations | Legacy cluster expansion method (via newly deployed node) | DEPRECATED in 9.1 | โ |
| Ops for Networks | Microsoft Azure + Amazon AWS as data sources | DEPRECATED | โ |
| Ops for Networks | Bundled OpenSSL in VCF Ops for Logs Agent | DEPRECATED | โ |
| Auto Deploy | Legacy Auto Deploy (PXE/TFTP-based) | DEPRECATED in 9.0 | Replaced by Zero Touch Provisioning (ZTP) in 9.1 |
| APIs | Legacy vStats Tech-Preview APIs | DEPRECATED | Replaced by Real-Time Metrics APIs (VODAP / Prometheus-compatible) |
Critical Notes, Warnings & Key Considerations
๐ Microsoft Secure Boot Certificates Expiration
Microsoft UEFI + KEK CA 2011 certs expire June 2026. Windows Production PCA 2011 expires October 2026. ESX 9.1 is multi-signed: Microsoft UEFI CA 2011 + 2023 + VMware Secure Boot. Host Secure Boot of ESX 9.1 NOT affected. Complex effects on Windows/Linux guest VMs โ see KB article 423893.
โ ๏ธ Workload Domain Without vSphere Cluster โ Patch Blocker
Creating a workload domain without a vSphere cluster blocks patch/upgrade until a cluster is added. All workload domains sharing NSX with a clusterless domain are also blocked.
๐ VCF Automation SSO Migration Required
Must migrate VCF Automation SSO config from VMware Identity Manager (vIDM) to VCF Identity Broker before completing upgrade. Complex multi-step migration involving user groups, accounts, and OIDC connections.
๐ฆ VCF Versioning Not Applicable to External Dependencies
OEM driver add-ons, ESX device drivers, UI plugins, and Kubernetes versions maintain their own external versioning. VCF 9.1 versioning does not apply to these. Clusters without active VMware Supervisor supported but cannot use key VCF capabilities (VCF Automation workflows).
โน๏ธ Non-ASCII Input Not Supported
Components of VMware Cloud Foundation 9.1 do not accept non-ASCII input. This applies across the platform.
โน๏ธ VCF Installer Default Component Deployment (Day 0)
New deployments now automatically deploy: VCF Services Runtime, Fleet Lifecycle, Identity Broker, Software Depot, Salt RaaS, Telemetry, License Server. No additional configuration required.
โน๏ธ Live Patch Requirement
Live Patching for ESX requires TPM-enabled hosts. Covers up to 80% of patches. VMs continue running with no maintenance window.
โน๏ธ Avi Load Balancer 32.1.1 โ Separate BOM Version
Avi LB ships at version 32.1.1 (Build 25377988) โ separate versioning scheme from VCF 9.1 components. Not included in VCF or vSphere Foundation SKU; add-on only.
โน๏ธ Private AI Components โ Separate Delivery
VMware Deep Learning VM 9.1 (Build 25217931) and Private AI Services 2.0.89 delivered separately from VCF 9.1 software bits. Guided deployment workflow and AI catalog items included in VCF software.
โน๏ธ VCF Login URL Format
When logging in to VCF Operations, use https://<IP> or FQDN โ not plain IP.
๐ ๏ธ Critical Technical Parameters & Limits
- ESX system storage min: 32 GB (USB/SD deprecated)
- NFS v3 FCD host limit: 128 ESX hosts max
- Live Patch coverage: Up to 80% of patches
- vCenter syslog port: 1514 (TLS); 514 blocked
- Grafana metrics granularity: Up to 2 seconds (VODAP)
- VCF supported languages: English, Japanese, Spanish, French
- SEV-SNP compatibility: AMD EPYC Zen 3 (Milan)+
- Intel TDX compatibility: Intel Xeon Gen 5 (Emerald Rapids)+
- ConnectX-7/BlueField-3: Enhanced DirectPath in 9.1
- AMD MI350: Enhanced DirectPath in 9.1
- Patch sub-releases tracked: 9.1.0.x (4 sub-releases)
- SDDC Manager patch count: 4 tracked (0100-0400)
- ZTP imaging: UEFI + HTTPS; static network config on bare metal
- vCLS: Deactivated by default; cannot be re-enabled in 9.1
- vSAN RAID default: RAID-6 (ESA, automatic in 9.1)