VMware Cloud Foundation 9.0 – The Smarter Way to Operate Private Cloud
Effectively managing a large-scale Private Cloud environment demands robust operational strategies to effectively operate a large-scale private cloud. VMware Cloud Foundation Operations delivers these capabilities, enabling IT teams to ensure consistent access, security, lifecycle management as well as performance, cost efficiency, resource utilization, and infrastructure and application health Whether you’re an experienced VCF administrator or beginning your VCF journey, you’ll leave this session equipped to confidently operate and optimize VMware Cloud Foundation at enterprise scale.
The presentation highlights the new innovative features available with VCF operations and VMware Cloud Foundation 9.0, focusing on fleet management and chargeback capabilities. Fleet management includes a unified single sign-on (SSO) capability via the VCF Identity Broker (VIDB), centralized certificate and password management, configuration drift updates, and simplified lifecycle management for applying patches and upgrades. The goal is to reduce the number of UIs and management points, providing a seamless operating experience from VCF operations, also with automation and API improvements.
The chargeback feature streamlines FinOps processes by integrating financial management with operational processes, enabling cost transparency and accountability. Key capabilities include defining rate cards for compute, storage, and networking, generating bills on demand or via scheduling, and sharing bills with tenants who can view detailed cost breakdowns within the automation console of VCF. The chargeback feature complements VCF’s showback capabilities, which provide visibility into the total cost of ownership, potential savings opportunities, and resource optimization. The demonstration illustrates the cost-saving opportunities through resource reclamation, rightsizing, and transparent resource cost.
Presented by Kelcey Lemon, Sr. Technical Marketing Manager, Broadcom, and Kyle Gleed, Staff Technical Marketing Architect, Broadcom, as part of VMware Cloud Foundation 9.0 Showcase – Modern Private Cloud. Watch the entire presentation at https://techfieldday.com/appearance/vcf9showcase/ or https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation for more information.
Transcript
So welcome. My name is Kyle Glee, and with me I have Kelsey Lemon. And we're gonna take the next few minutes to talk to you about some of the new innovative features available with VCF operations and VMware Cloud Foundation nine.
Uh, I'm gonna kick us off with a quick overview of a new capability brought into the VCF operations we call fleet management. And then Kelsey will follow up with a introduction into some new capabilities, primarily around chargeback and some of the new, uh, features of new enhancements around VCF operations, uh, for some of those core capabilities that you're already familiar with. So with that, let's go ahead and jump in.
So, uh, looking at the fleet management capability, so within VCF operations, if you, uh, are familiar with the older versions of Cloud Foundation and familiar with the Aria suite, you'll remember we had a component called the Aria Suite Lifecycle Manager. Um, and this component was, uh, deployed in the environment, and you use this component to then deploy and manage your VCF operations, VCF logs, VCF automation and other, uh, components that make up that, uh, what used to be known as the RES suite. Uh, with Cloud Foundation nine, we've, uh, taken that RES Suite Lifecycle Manager, and we've now bundled that appliance in with VCF operations, and we give it a new name called Fleet Management.
And with that change, we're moving a lot of the functionality that was traditionally in the Aria Suite Lifecycle Manager, together with some of the functionality that was in the vm, the V-C-F-S-D-D-C manager. And we're bringing those capabilities into the VCF operations. Thus, we're making good on our commitment to help reduce the number of UIs to help reduce the number of management points, and to help provide this, uh, best in class private cloud with a seamless experience, uh, that you can operate and manage directly from VCF operations.
So I'm gonna talk about a few features here. We'll get into a demo at the end, and then I'll hand off to Kelsey who will then, um, pick up from there. So, uh, you'll see here on the slide, we're gonna be talking about a unified, um, um, we're gonna be talking about a, a, a new single sign-on capability for administrator access.
We're gonna be talking about centralized password and management, uh, centralized certificate and password management. Uh, I'll touch briefly on some config drift updates, and, uh, we'll talk about the lifecycle management and how we can apply patches and upgrades all from VCF operations. So let's go ahead and jump into the presentation.
So, uh, as I mentioned, VCF operations has been around for a while. It's something that we've had for a while, and it's, it's, uh, got a lot of capabilities built into it, primarily around health and performance monitoring, uh, observability troubleshooting. And with VCF nine, we have extended these capabilities out to include this new section referred to as fleet management.
And in fleet management, we have a number of new capabilities, uh, primarily around identity access management, and like I mentioned, certificate, password management configuration, drift lifecycle. And so I'm gonna be focusing here on what's on the right hand side of the screen as we go through these next few slides. So one of the first things we've done with VCF nine, uh, in the terms of fleet management and VCF operations is we've introduced a single, uh, identity management source for the entire private cloud.
So where before we had separate identity management capabilities for the different components, we, we lacked having a unified identity management source for the full stack. And so with VCF operations, we've introduced this new capability. We call it the VIDB, and you see that here on the slide, uh, the vSphere identity, the VCF identity broker.
And what this is, is, is a new identity broker. Um, you, it can be deployed in one of two options. Um, it comes embedded with the vCenter server.
And, uh, if you're a larger environment, you need to scale out, you can actually deploy an external instance, um, on a highly available, uh, set of three appliances in A-V-I-D-B cluster. Um, once it's deployed, you can then point all the cloud foundation components to this VIDB instance and use it for a single source for identity management. And then you configure your VIDB to point to an external identity source.
And now you can basically go in and set up your, uh, authentication, uh, using, uh, you know, uh, open ID connect or SAML or active directory or, or LDAP or whatever your, your, uh, method of authentication, whatever that, uh, choice your preference is for that method of authentication. You can set that up. And then you can log to, uh, across the stack.
So you can log into vSphere, you can log into NSX, you can log in, operate, all using the single, uh, I, uh, single login all configured through the, uh, VCF identity broker. Uh, for customers that are, you know, migrating an existing infrastructure, not deploying in Greenfield. So they have a different identity setup now and their existing vSphere or VCF environment.
What is the transition to the identity broker look like in terms of, uh, you know, any, you know, disruption or risk associated with making that change at all? Or is it pretty seamless? Is it automated?
How do they adopt VIDB as with as little disruption to production environment as possible? Yeah, it's, it's pretty seamless. Um, after you deploy Cloud Foundation and after you've instantiated VCF operations, you'll log into fleet management and there is a new section, um, under the single sign-on, uh, where you'll go in and you'll configure the VIDB where you basically go in and tell the VIDB what your external identity, uh, source identity management source is, and then you'll go in and you'll register each component to use that.
And then once you've register those components, um, it, it's pretty, it's pretty much go from there. Um, so it's, I'll have a demo, I'll show a little bit on that, uh, when we get to the demo. But yeah, it's, it's pretty seamless.
It's pretty straightforward. It's just an extra step to go into VCF operations, uh, after the deployment to set up the VIDB and then point the different products to that, uh, and then, uh, set up the necessary role-based access controls inside each component product. So, so pretty straightforward.
Kyle, it seems like a no-brainer, like in a, in a very important ad. Is there anything out of scope within the whole ecosystem? Like, is there anything else I'm gonna need to log into separately or just VIDB really cover all the necessary components?
It covers all the, the necessary components. Uh, you know, some of the add-on components, uh, you know, you, you may have to still, uh, manage separately, but everything that's part of your VCF license, so you'll see here on the slide, we have the vCenter server, we got the NSX manager, we got the operations, we've got the automation. You know, you see down here, you also got ops for networks A CX logs, um, all configured on the VIDB.
So, um, everything you see here on the slide, it's, it's pretty comprehensive. But, you know, that's not to say that there won't be some add-on components that are, are still trailing a little bit, that still might have a separate identity management. Um, I, I can't think of anything right now, but I don't want to commit to a hundred percent 'cause I I do suspect there might be one or two, uh, things still lagging out there.
Get our feature requests ready now. Yes, Uh, um, I see that there is, um, integration with, uh, almost all as, as, as Scott told, uh, almost all the, the components. And I can also see that it's, uh, it could be integrated with the active directory.
Uh, so my question is, I already see two domains here. Uh, but what if, uh, the domain is, um, is on several sites or maybe more than one domain? Uh, could, uh, could we use the same, the ITB or we should deploy, uh, the ITB, uh, in for every B center in every, uh, region?
Uh, let me, sorry, let me talk, uh, as a cloud service provider point of view, um, working for them, I always work with for them. So let's imagine our deployment with the regions and, uh, availability results. As far as MDC inside the say region, I can use the same, the ITB, uh, for all the, uh, IAZ, uh, but could it be federated on all the regions?
Uh, I'm not aware of any federation capability. Uh, we, with VCF nine, we've introduced this new concept referred to as a VCF fleet. Um, and so when you deploy vcf, uh, when you deploy your very first VCF instance, uh, you'll need to instantiate what we call a VCF fleet.
And what that fleet means is there are certain components through our fleet level. So, uh, VCF operations, VVCF automation, um, uh, and, and the fleet manager itself are examples of those fleet level components. And so you can deploy those in like a region, and then you can have multiple VCF instances deployed, uh, uh, and, and connected to those fleet level components.
So I could have an instance of VCF operations with the VC instance of VCF automation, and I could have multiple VCF instances all registered, uh, with those, those components, um, within a a region. And the, the, um, the single sign-on this, uh, VIDB capability, since it runs at the operations level, it's a fleet level component. So you could have one instance of VIDB, um, and in your example where you're gonna have, you know, multiple kind of clients kind of sharing this, you'd want to have an external instance most likely, but you can have multiple instances of, uh, VCF kind of connected to this single VIDB.
So, um, you can definitely do that. Now in terms of if you wanted to actually deploy and have separate fleets across different customers, have separate instances of automation and operations, then you would have a separate VIDB for each fleet. So, um, so it kind of just depends on your topology and how you're managing your fleet level components and whether you're gonna have, uh, components sharing those fleet objects or whether you're gonna have, uh, separate fleets for each, uh, end user or each customer.
Um, but you'd have A-V-I-D-B instance for each, um, uh, yeah, for each fleet. It's a matter, it's a matter of design. And, uh, yes, yes.
Yeah. Thank you. All right.
So thanks for the questions. So let's go ahead and move on. Uh, so another feature that's part of the fleet management in VCF operations is centralized certificate and password management.
Now, if you're familiar with, uh, VCF, uh, the five point X and the prior versions, you'll know this was a capability that was part of the SDDC manager. And so with VCF nine, uh, something we're, uh, working on, and this is a first step towards that, is we're trying to reduce the number of UIs and we're trying to consolidate. And so what you're seeing is, uh, with the SDC manager, we're taking a lot of that SDC manager capability from the UI perspective and moving that into VCF operations.
Some of it moves into VCF operations, some of it moves into the vSphere client, and we do have plans to deprecate the SST DC manager ui. Now note, the SDC manager appliance is still, uh, something that gets deployed and still used, but it becomes a backend and the UI to access it is driven through, uh, primarily through VCF Ops and the, um, fleet management capabilities. And so here we see an example where we've moved that centralized certificate management into VCF operations, and along with moving this functionality, and we've made a couple of enhancements.
So you'll notice here on the screenshot, you see we have this option for doing automated renewal or, you know, automatic, um, renewal certificates. And then we also have, um, ability to go in and to, to update those certificates, of course. And we also have the ability to go in and manage certificates for the ESX host.
2 days, uh, that are new in VCF nine. So in addition to seeing the certificate, the centralized certificate management capabilities moved into VCF operations under fleet management, you'll see the ability to now manage ESX certificates as well as to set up automatic renewal. And, uh, when I get to the demo, we'll go through this in a little bit more detail.
And I have a question around automated renewal, and you may just tell me it's gonna be in the demo. Uh, it would be around like how that is accomplished, uh, like with certain CAS and whatnot, uh, that may or may not support protocols like Acme. Like is that gonna be what's in use?
Or, or how, how is, how can it be automated? Uh, Um, yeah. So, um, our ability to automate is tied to, uh, under this option here to configure a certificate authority.
We have two options for configuring a certificate authority. You can do a, a Microsoft ca, or you can do an open SSL, uh, ca, uh, and, um, you can do one of those two options. And as long as those, uh, supported CAS match your requirements, then you can enable the automatic renewal.
And then what we'll do is you configure your local ca as kind of a sub ca from, you know, whatever your parent is. And then anything assigned will be trusted. And then we can basically use that to set that up.
If you don't have, if the, if, uh, if the available ca don't support your needs, uh, we do have the ability to create the, the, the c certificate signing request and send them off to an external entity to be signed and then brought back in and, and applied. So we can still, uh, automate the, uh, updating of the certificate, but obviously we wouldn't be able to do the automatic renewal because there would be that intermediate step of sending off to that higher level ca. So depending on what you're looking for and, uh, whether or not the, uh, the default like Microsoft ca can, can meet your needs, um, it may work for you, or you may still have to go out to an upstream if there's additional capabilities that aren't available.
Hey, Kyle, a little bit of a, a non-sequitur, so if you want to hold the answer for later, I understand, but just as you're talking about kind of moving the UI and consolidating in the ui, I think that's really important for operations teams and, and, and great to see that happening here with the certificate management. I, I'm also curious about API improvements and automation capabilities, uh, that are new in VCF nine for operations teams. And maybe that's something you'll get to later and don't want to answer now, and that's fine, but just wanted to make sure we talk about it.
Um, yeah, I don't really get into that in the slides. Um, we do have a full API, um, we do have everything that I show through the UI and the gui. You know, there is an API behind the scenes that can be leveraged.
Um, you know, everything from deploying Cloud Foundation through the VCF installer to going in and setting up, um, creating workload domains and, and configuring this almost everything, um, has an API in the back end, and it's all publicly available. Um, so, so I won't get into the discussion of the APIs, but they are there. And so if you're looking to, um, automate things and to leverage the API, um, those, those are available to you, um, across the whole VCF stack, really.
Fair enough. Thanks. All right.
So along with the certificate management, of course, password management, uh, and here, you know, we basically, we take the, uh, the primary accounts for each component. So the root level accounts, the admin accounts, the administrative accounts, those kind of break glass accounts that, uh, get deployed. Uh, typically when you deploy cloud foundation, you're deploying multiple components.
Each of those components is gonna have that local, um, admin type role. Um, those aren't accounts you want to use on a day-to-day basis. Those are accounts you want to basically, um, you know, set the password to something hard and vault and put them away in a safe place so that, uh, they only get pulled out when you need them.
Um, and to help make it easy as you, uh, deploy Cloud Foundation, and especially as you start to increase the number of workload domains, of course, the number of these accounts can increase. So having a centralized place to manage them and to manage the passwords, you know, all your NSX manager passwords, all your ESX host passwords and those, those types of things, to have a central place to manage all those is nice. And so we do have that as part of the, uh, the fleet manager.
And again, this is another capability that, you know, has been in the, uh, SDC manager that is being moved over. And we'll see this, uh, when we get to the demo as well. Um, as, uh, another feature we have is as, uh, we deploy out a private cloud.
And as you scale out your private cloud, of course you're gonna have multiple vCenter servers, uh, managing multiple workload domains. You'll have multiple clusters behind those vCenter servers. And as we start to scale out, of course, uh, monitoring configuration, making sure we're compliant with, uh, prescribed settings and setting those policies and making sure things like SSH is disabled and make sure that, uh, access is logged down and make sure that our VM kernel, uh, adapters are all configured correctly, uh, you know, as the environment scales out, the efforts to keep up with all those things, um, increases as well.
So what we have added as part of fleet management is this new ability to basically create these configuration profiles and basically say, Hey, this is what I want my vCenter configurations to look like, and I can apply that, uh, configuration profile to all my vCenter servers, and then I can also create cluster profiles and I can apply those to my vSphere clusters. And then over time, if, uh, somebody logs in and maybe does something like, uh, changes a VM kernel port, or goes in and enables SSH, um, vvc, uh, VCF operations will detect that because it will no longer match the, the assigned profile. And you'll get that notification that, hey, there's drift detected.
And so this can really help you to be able to, uh, manage at scale and to keep on top of those configuration changes that may creep in and help to avoid that config drift that will, that that can prop up. And so, again, we have this capability right now in VCF nine. It's focused on basically setting up a vCenter profile and a cluster profile, and to be able to assign those and to be able to help monitor and track any configuration drift and stay on top of that.
Um, along with the things I've talked about so far, uh, lifecycle management is a big part of the private cloud. Uh, we use this term a lot in, within Broadcom. Uh, we had the Aria Suite Lifecycle manager, we had the STDC manager, lifecycle Manager, uh, with VCF nine.
We brought those together as part of fleet management. So all the lifecycle management for both the, um, the REA components or what formerly known as the RA components, things like operations automation, logs, fleet management, that's all done through fleet management in addition to the ability to go in and to update and patch the core building blocks of the private cloud, vSphere, vsan, N-S-X-E-S-X, as well as the STDC manager. So you'll see that's all now part of the, um, the fleet management capabilities, uh, within, you know, VCF operations as well.
And so with that, lemme go ahead and let's jump over to a quick demo where I'll actually just log into VCF nine, uh, operations nine, and we'll just kinda look at some of these features. All right, so here we're logged into VCF operations. You'll see we got our fleet management section here with the, the features we've been talking about.
And the first thing I wanna just show you is that identity access. There was a question about, Hey, how we hard is it to set this up? Uh, what is the experience?
So you see, it's very easy to go in. You see here, I have identity access set up. Um, you know, with my, uh, V-C-F-S-S-O, I have my vCenter servers, my NSX managers from my two workload domains already there.
If I want to go in and look at the configuration, I can come in here into my VCF instances, and I can see here, this is where I set up my identity source. You can see here where I've set up, um, the information on the external identity broker that it's, uh, going to point to. In this particular example, we are using the embedded model.
So this is, uh, built in with vCenter server. So we go in, we set this up, we basically tell it, uh, what that, uh, identity source is, and then we go in and we register our components. And here you can see where I've registered my, uh, my V centers and my, um, NSX instances for my manager domain and my first, uh, VI workload domain.
Uh, once those are set up, um, you wanna go in and you wanna maybe set up VCF automation to also use this identity broker. Lemme show you what that looks like. You go under here, under VCF Management, here's my automation appliance.
You'll see by default it's not, uh, set up to use the V-C-F-S-S-O to do this. I simply click continue. I pointed to that identity broker running on that management vCenter server, and that's pretty much it.
Now, uh, of course, you will have to go in and set up your roll base access controls, and that's what this Blue Information box is reminding us about. Uh, you will need to set that up. But as you can see, very easy to go in and set up a single identity source, um, across the stack, and to be able to point the different components to use that for authentication.
Now, as I navigate through, when I click on the different, uh, components, once I'm authenticated, instead of having to provide my username and password, uh, multiple times, I can just basically use this, uh, single sign on to basically, uh, get into each of the different, uh, UIs as needed. Uh, under password management, again, password manager, pretty straightforward. This is where we have password manage for those route admin accounts.
Um, you'll see there's too much two basic operations. We can update passwords, we can remediate passwords, updating a password, basically just setting the password. Uh, re remediating the password is when you go in and, uh, say the password gets changed outside of the SDS manager or outside of ECF, and you need to basically, uh, update the password that we have to the new password.
You can just do the remediation. Um, under certificates, you'll see here we have, um, listed all the certificates in our environment, and you'll see here the type and the expiration date. Uh, you'll notice here I have a toggle button.
Now we can now manage certificates for the ESX host. So if I toggle that on, we see our certificates for our E ESX host, um, up here under configure ca, this is where I can, uh, set up my Microsoft ca or my open SSLC, uh, certificate authority. I, I can basically set that up here, save that, and then once I set that up, now I can go in and automate, automate that activated, uh, activate that auto renewal, because now I can go in and do things like go in here and basically create a certificate signing request, and then I can go ahead and, um, replace this certificate.
And you see it's just point and click. Um, what you create the request, you apply request, and now I have an updated certificate running on the C XX host, and I can go in now and if I wanna make sure that they always get updated, I can go ahead and just enable the auto renewal. Alright?
So, um, so that's the, the, the core capabilities here. You know, as I mentioned, config, drift and lifecycle are also in here. Um, I, I won't go into detail on those, uh, simply because of time.
But, uh, again, configuration is how I can go in and set those policies and I can monitor the configuration across multiple V centers, across multiple domains to identify any, uh, config drift that may potentially creep into the environment. I can do the same thing for my vSphere clusters. And then under Lifecycle, this is of course where I would go download those updates, uh, download the binaries, download the patches, download the updates, I would plan those out and I would apply those all from, um, here in VCF operations in a very automated way.
And so with that, uh, so with that, we'll go ahead and hand it off to Kelsey and he'll talk to us about, uh, cost management and, uh, some showback. Hello everyone. I'm Kelsey Lemon.
I'm a technical marketing manager for the VCF division here at Broadcom. And I wanna welcome you today to our session where I'm gonna be highlighting how CFS thin ops processes are actually streamlined by its newly integrated chargeback capabilities, right? And so with that, right, you know, just for some context, you know, the latest release of VCF, you know, powered by its operations console really focuses on streamlining, you know, management across these three pillars that you see here.
You know, first obviously there's the fleet management piece, um, that Kyle talked about, which really just contains features that really enable customers to build and deploy their VCF environments, you know, with scalability and consistency in mind, right? Um, then there's the operations management pillar, uh, which features, um, are really built on supporting things around visibility and troubleshooting. And then that third pillar, right?
Which is around security management. And that really just includes features around, you know, various tools for compliance and vulnerability analysis and things along those lines. And as you can see here, you know, with VCF, you know, and its finops capabilities, you know, the focal point is really around this operations management pillar.
So before I go into too deep about it, right, I just wanted to take a moment to really define what finops is. And as you probably already know, you know, finops is really short for financial operations. And what it really does, what it really encompasses is just really the integration of financial management with operational processes, right?
So it really involves the collaboration between, you know, finance and IT and operations team to really just drive cost transparency and accountability, you know, when it comes to tracking, forecasting, and really optimizing their spending on it, uh, resources and services, right? So, and that's why it's really, really closely related to, um, capacity management, which is also in that bucket. And so as I go through the demo, you're gonna see how all these pieces sort of come together here.
And so, you know, moving forward here, right? You know, um, let's just talk about finops and chargeback, right? So as you can imagine, you know, when working with multiple teams to really achieve that business goal, really streamlining and reducing costs, obviously it could be very, very challenging.
You know, you have to balance, um, operational efficiency and fairness, right? You know, across the various departments, the different lines of businesses and even tenants, right? That are really leveraging the infrastructure and the services that you're managing.
And obviously without the proper tools in place, you know, optimizing costs and reducing strains on resources, or even just recouping those costs by doing chargebacks, you know, it could be a very manual, time consuming, very tedious process that not only impacts, um, operational efficiency, but can also, quite frankly, just lead to disputes with tenants who may not necessarily have the transparency that they need to truly understand their bill. And so I'm happy to say that the chargeback feature in VCF alleviates these challenges with the following capabilities that you can see here on the screen. And so now providers can, you know, more easily generate chargebacks with a streamlined user experience inside of VCF.
And a big part of this update is really the ability to define rate cards that calculate metering rates for compute, for storage, for networking, as well as any other agreed upon cost for any org or region combination. Uh, providers can also generate bills for tenants on demand as well as, um, automate their creation with its scheduling capability. And then finally, right?
You know, last but not least, you know, providers can actually share generated bills with their tenants. And once that bill is generated, you know, they can actually view a detailed breakdown of their costs in the, within the automation console of VCF. And so I'm gonna be covering the bulk of these chargeback capabilities in the demo, but I do want to take a moment just to sort of highlight just the amount of work, um, that was taken to really simplify the customer experience sort of visually here.
And so with that being said, right, you know, this is what the chargeback process used to look like before VCF nine, you know, and while effective, a lot of configuration needed to be done upfront, right? You know, providers had to configure and integrate area operations with, um, cloud director via Management pacs and plugins, just to really get them to communicate with each other, you know, then providers would then enter their cost drivers for internal showback reports that really allowed them to see how much, you know, their infrastructure was costing them, as well as sort of just to get insight right into ways that they could reduce costs by optimizing capacity and even reducing resource, um, strain. And so, and at the same time, you know, this pricing information would be entered for the tenants who could then leverage cloud director to access their bills.
You know, fast forward to the day, right? You know, now DCF, you know, when it's configured, the chargeback capabilities, they just work, um, because the multiple components that comprise, um, BCF, they're automatically integrated, you know, namely the operations console where providers can again, enter their cost and their pricing information. And then there's that automation console, which actually replaces cloud director, and this is where tenants can now log in and view their bills.
And so with both the operations console and the automation console working together, you know, they're automatically configured and they're talking to each other again upon configuration. So for customers who may not be very big consumers of VCF automation, for example, because their environment's very static and they don't have consumers necessarily that are want to make changes on their own, and they're just nor used to doing things through vSphere, and then they want to do some kind of chargeback in billing to cut to their customers, the internal business units is use of VCF automation required to achieve that outcome? No, it's not.
If you're just working across various lines of businesses, there's native, um, chargeback, um, capabilities that you can actually just generate reports and you can send them directly to your various lines of businesses if you're doing it within, um, your own organization. And so those capabilities still do exist. Okay.
And, um, you know, this is more so for like the larger or the broader service provider, um, type customer profile where they're actually running it lock of business. Gotcha. Thanks.
To clarify, uh, you, you told us, uh, every channel can, uh, download the, the, the, the, his bill and and so on. Uh, is it possible to do it in, um, real time? So, uh, not just downloading, but, but the question is, is it multi-tenant so that that tenant can take under control their costs and not downloading maybe every, uh, month?
Uh, just the, the bill. Alright. There is a, and I'm gonna be showing this in the demo.
Yeah, you can actually log in and see your, your current prices. So yes. Okay.
All right. I'll, I'll, I'll hold the details for the demo, but just in general, um, do you, do you have any like, best practice information on setting pricing and, and determining costs? I mean, I think, I think it'd be fairly arbitrary, but, uh, you have a large customer base, like what are you seeing that could be useful to other people that wanna actually implement this?
Right? And so with that being said, you know, there are cost drivers, um, that are enabled right out of the box that are based off of standards that have been already defined. And so you can actually go in there and take advantage of those right out of the gate.
So you can even customize them, um, according to your own standards and whatever works best for your practice. And I'm gonna be showing you how you can actually go in and configure, um, pricing cards and things along those lines as well. And so you could have a customer profile that's set up for like a small to medium sized business or, or a, an enterprise type customer where you can actually make those, um, prices and those rates work depending on the customer profile.
And so, with that being said, right, you know, we're talking about chargeback and one of the things that I just wanted to make sure that we're all on the same page about is that, you know, you really can't have a conversation about chargeback without talking about showback, right? And seeing how I've already mentioned it a few times, I just wanna make sure that we're on the same page as far as the definitions, you know, because they're close related, uh, but there's some key differences, right? You know, so showback or cost is basically obviously how much you're spending on your infrastructure to run in a vm, you know, and those costs are reflected in a showback report.
You know, things like total cost of ownership, and these are the things that you can use to show management or your internal departments that, you know, this is how much it's costing to running your VMs, you know? So showback doesn't necessarily mean you're going to give the user a bill per se, you know, it's more, um, just try to influence behavior by saying, Hey, you know what, this is how much it's costing a company to run this vm. So, you know, try to be a good consumer of our resources and minimize your costs as much as possible.
So, and obviously this is especially true when VMs are oversized and using more capacity than necessary. Um, so showback isn't necessarily a, an enforcement per se, it's more of an educational type of thing, whereas chargeback or price is how much you want to charge the owner of that VM to run that vm, right? And that could be based on different things like rate factors or allocation with additional prices added as needed.
And so, and of course, you know, like I said, these prices are reflected in a chargeback report that you can actually present the user as a bill. And so at this point, obviously, you know, you're running it like a business and you're recouping a lot of your operational costs via chargeback, um, Um, about, uh, finops, they will be very, very happy if, uh, they could have kind of forecast based on, on the, uh, this case of the showback, um, to plan the, the future. So is it, um, uh, is it, does it exist or maybe is in plans to do something like this, Right?
Okay. So, and that's a great question. And so within VCF, you know, you have the ability to sort of apply cost to capacity, and you're able to see where things currently are in terms of where things are currently costing you in terms of price.
And along those lines, and with the capacity engine, you can actually project into the future not only when you're gonna run out of capacity, but you can also see, um, the current costs as well as the opportunities to recoup a lot of those costs in terms of just optimizing and, and, and seeing some potential there in terms of realizing savings. And I'm actually gonna be showing this in the demo here in a moment. And so with that said, right, you know, this is where I'm gonna just really show how the newly integrated chargeback capabilities, again, just sort of help streamlines that finops process by really just complimenting CFS showback capabilities.
And it's also being influenced by, um, CFS capacity management capabilities, right? And so here we are within the operations console, right? And one of the things that I just want to point out is that, like I said, visibility is one of the key components of it.
And as I log into VCF and I can see my, um, operations view, I get a lot of visibility into like things like configuration drifts, you know, the state of my workload operations. I can also see things related to any alerts that I may need to address, as well as this whole idea around overall cost and how things are really costing me and my organization at this particular point in time. And as I click on the view cost, right?
You know, again, this is essentially our showback, right? You know, with this visibility here, you know, I got this single pane of glass where I can see things like total cost of ownership. I can see how much things are costing me from a capacity point of view.
I can see how my cost drivers are impacting, um, things related to, um, my host, my os, you know, my maintenance, my networking, all those different types of things. Uh, I can also see within VCF potential savings opportunity in terms of addressing things like along the lines of idle VMs, oversized, um, VMs, snapshots that could be deleted, that could help me, um, reduce my total cost of ownership. And if I were to act on vvcs, um, recommendations to do things like delete, um, snapshots or power off VMs or things along those lines that will be manifested in terms of this realized savings here, right?
And so one of the things that's really, really great about VCF is that we can actually improve our total cost of ownership just by reducing, um, a lot of the cost just by simply optimizing a lot of the things that VCF is pointing out. And so what I'm gonna do here is I'm actually gonna go in and just sort of talk about some of the ways that we can actually reduce costs by reclaiming, you know, resources like idle dms. And so one of the things that's being pointed out here is that I've got the potential to save $117 a month across five VMs that could be reclaimed or some orphan discs here, and you can actually see the overall capacity that we can actually reclaim as well.
And of that $117 per month that we can really improve or realize some savings. A lot of this is related to our idle VMs here. And so if I were to sort of click this, I get a breakdown of all the VMs in terms of how much it's costing me per month.
I can see the reclaimable capacity and everything along these lines here. And so what's really, really great about this is that right out of the gate, I can automate, um, a lot of that reclamation just by clicking on this and I can schedule a action. So I could do this in real time.
I don't have to go into vSphere and do any of this. I can do this all within the operations console. Um, very similarly, if I were to right size, um, I can go in here and I can see some of the right sizing opportunities as well.
I can see the number of VMs that are, um, eligible to be downsized. If they're oversized, I can see, um, the undersized VMs as well. And so if I were to focus specifically on my, um, oversized VMs, I could expand this, I could see all the different opportunities in terms of some of the, um, allocated CPUs and what the recommended allocation should be, right?
And so like, if I were to click on this, one of the great things about um, VCF is that you actually get rationale behind this recommendation. So you're not just acting blindly and just sort of just simply saying, you know, what VCF is saying, do it. Um, I'm just gonna do it.
Now you've got this rationale. So it's telling you this is the current state, this is the recommended state, and this is why, um, we are making that recommendation. So that rationale just really, really helps to increase that customer sort of, um, competence behind the recommendations.
And so at this particular point, right, you know, we've actually optimized our costs and we can recoup a lot of those costs, um, from our tenants that even pass savings onto them via our chargeback capabilities. And so what I'm gonna do right now is I'm actually gonna go into my cost piece and I'm gonna go into chargeback. And one of the great things about this here is that I can see all of my different lines of businesses or my tenants, and I can see all the different organizations here.
I can get an overview of the capacity that they're using. I can get, um, in this particular case, there's only one organization, but you can imagine that there could be multiple organizations here where I can see all the different details. And so if I wanted to drill down on an organization level, I can see in this particular case, we've got an organization named Acme.
It's brought up, it's broken up across, um, Acme, east and West. And I can actually see from a larger overall organization view, or I can see it from a regional view as well. Um, and what's really, really great about this is that we can actually go even further and drill down and see what's happening on a project level.
And so in this particular case, we've got Acme, they've got two projects up and running. You know, they've got a, um, let's say something in a, a project called Mbu that's already in production and they're getting ready to maybe spin up something in a test dev environment as well. But in any case, you can actually sort of get a idea of what things are costing, um, in terms of some of the trends and compare that against the price as well.
But what's really, really great about this is that billing capability, like I talked about, you know, we can generate bills on demand. So going back to that question around real time, um, can be done simply by clicking on the view bill. I can click on and just walk through these fields here.
I can put in my start and my end dates. Um, I can take my billing objects like, so I can drag and drop them, and then I can click create. And what's really, really great about this is that again, I get a detailed sort of breakdown in terms of how things are costing in terms of, um, sending this bill to our tenant or our line of business in terms of just showing them what their usage is and what their price is.
So this is really around that accountability and that transparency. Um, but also what's really, really great about this is that I can also schedule billing on a, um, any particular timeframe. So let's just say here, if I wanted to generate a bill on a monthly basis, again, I can just walk through this very, very guided process.
Um, I can again, take my information and drag and drop here in terms of my billing objects. I can click next. Let's say I'm gonna use today's date and just say, you know what?
Every month on the 18th, we're gonna automatically send our line of businesses or our tenants to bill. If I were to create this, um, I've already created a job, it goes within our automation console, and tenants are automatically gonna be getting this, um, every month. And so with that being said, you know, the, the million dollar question, right?
You know, well, where are these prices coming from, right? And again, you know, one of the things that I've talked about earlier was the improvement around rate cards. And so what I wanna show you really, really quickly is by clicking on configurations here, uh, a lot of the rates are being defined by the policies that are coming out of VCF.
And so if I were to go on my policy definition and edit my default policy here, you're gonna see provider pricing. And as I sort of walk through this, you know, one of the key takeaways is just, I just wanna point out just the level of granularity, um, that VCF allows you to do when you're done. Um, configuring costs for compute and storage and network, and some of that go through each one of these, you know, when someone asked a question around, you know, best practices and things along those lines.
So again, going back to the scenario where you may have a a, a policy created for like a small to medium sized business, you may have a policy set up for like a, like an enterprise. And so based off of the policy and the different types of profiles, you can literally go in here and just do a lot of different things in terms of just assigning prices around network, around guest os, around V center tag rates. You can do one time fixed costs where maybe you're setting up a VM and you can associate a price with that, or you can simply say, you know what?
I wanna add a maybe a 25% markup on just whatever it's costing me. You know, whatever the thing you want to do here. These rate cards will allow you to customize those prices based off of whatever, um, best practices or standards that you've established for your own company here.
And so with that being said, I want to just talk about the tenant experience. You know, if you go back to that diagram that I showed earlier where the customer can actually log into the automation console and see their current state, you know, this is again, that same view, but this is from the customer side where you can see, again, Acme's got their two projects. You see Mbu here is, um, one of the projects that's currently active.
It's currently in production, and so you can see all the usage and, um, all that information there. And that same bill that I as a providers just created, um, tenant can actually go in here and see that same bill, um, like sell. And so again, this is again, that same bill, but this is from the, um, tenants point of view as well.
And so again, this is how these two pieces basically come together in terms of just how chargeback just really, really, um, streamlines that whole, um, finops process. If you'll, Hey Kelsey, uh, Chris Gruman here. Does this, um, the, the chargeback and kinda the tenant view and, and this kind of this side of things, is there any differences, um, either you know, functionally that are required or, or recommended between a service writer environment or an enterprise environment, um, where you're, you know, charging back to application teams and that kind of thing?
Um, no, I mean, they're essentially the same workflow, so you don't have to go through and do anything specifically different. Um, if you wanted to again, um, set up different prices like a small medium or large or small to medium business to an enterprise business, that would be set up within the actual, um, policy. And so in this particular case, I had just had one policy set up for everyone, but you could literally customize policies depending on the agreement that you've set up with your, um, tenant or line of business.
That's great. And ki kind of a follow up maybe on a little bit different path, um, you know, in this UI here, which is great, by the way, I I'm definitely seeing that the, you know, the pricing policies and the rate cards are supporting kinda the latest VCF licensing models. I wonder if you could talk a little bit about how that differs from the kind of VM based charging that we saw before.
Like, you know, how do people need to wrap their heads around, um, how this works today? Yeah, and so quite frankly though, there really isn't that much of a difference in terms of, um, you know, you've got the different ping policies and again, it's very, very customizable. And so I personally, I don't really see that much of a difference.
I don't think there's gonna be an adoption barrier in terms of just saying, you know what, this is a brand new way of doing things. I think this is more so just a, a slight incremental sort of update, if you will. And quite frankly, I think it's, um, more streamlined, better.
And with that, I wanna thank everyone for their time. I hope you found this very, very informative.