How to use Reservation Policy to place VMDKs across different datastores

Reservation policy is often unused feature and to some extend not fully understood. Primary reason could be that reservation policy creation process very simple and during policy creation we don’t glue pieces together. That being said there are very valid use cases for using reservation policy and comes very handy in VM Placement. One of the core principles of Software Defined Datacenter (SDDC) suggests we need to have policy based automation and common management platform across the entire infrastructure.

With reservation policy we address this requirement. It is my personal belief that features in any products are aimed to solve some or other business problems. All we should attempt is to find those relevant business case or help someone find them. In this blog I aim for later.

Continue here

Start to end tenant configuration in vCAC

After going through the FAQ post, I thought it is easier to construct a flow chart based on my understanding. I’m happy I can cover most of the tenant configurations using below flow chart.


First : You create tenant (right hand side by name HR Tenant). While creating tenant you must create Tenant and Infrastructure Administrator

Second: Infrastructure Administrator creates fabric. In simple words he maps ESXi cluster/s inside vCAC. On left hand side, I have a cluster dedicated for HR Business Unit (HRBU) by name HR Cluster.  While creating fabric you must create fabric administrator.

Third:  HR Fabric Admin creates reservation and assigns that to HR Business group. He also creates Machine Prefix. Machine prefix is pre-requisite to create business group. He also can optionally create network profiles and reservation policies. These can be mapped to blueprints

Fourth: Tenant Administrator creates business group but unless machine prefix is created business group cannot be created. NB: There is option for Tenant administrator to create machine prefix. Tenant administrator then creates Blueprints. He publishes blueprints. Published blueprint is referred as catalog item. He creates service and assign catalog item to service. Assign entitlements to service, catalog items and Entitled actions to catalog items.

Briefly it looks like below


Lets do the above exercise using example as it would be more relevant to us. In below flowchart blueprints, catalog item, services and Entitlements are shown


Left hand side –Blueprints will be published and they become catalog items (the middle light blue). You then create service. Add catalog to the service. Finally you put the entitlements around Catalog items, Services and entitlements needed.

Next post I will talk about naming conventions in vCAC.

Roles FAQ of vCAC –For Myself

Before I start on main topic of I would like to highlight vCAC as product has three main components which needs to be explore, blogged or documented very well


Reason we don’t see much on this yet, as it is evolving field. Not one person knows or have these skill sets. These components makes perfect orchestration layer but expects broad skill sets which are difficult to find. I’m mostly blogging on vCAC core stuff. But people expect a lot from vCAC Extensibility. It is skill which needs attention, understanding and has huge scope.

Below are frequently asked questions about various roles available in vCAC or I asked myself. This question helps me define Role Based Access control model for vCAC. Hope it also helps you too.

Who has rights to create blueprint?

It is Tenant Administrator role and Business group manager has rights to create blueprint

Who has rights to create reservations?

Fabric Administrator has rights to create reservation. Reservation can be shared between the tenant BUT only if the fabric is shared.

Below is the example of shared fabric. I created a single fabric (i.e. mapped three different cluster to it) which will allow fabric administrator to choose from the cluster (i.e. compute resources) and assign them to tenants.


In such model, reservations are visible across the tenants. It means Fabric administrator plays shared role in managing fabric.

Who has rights to create prefix?

Machine prefix are created by Fabric Administrator, can be created by tenant administrator.

Who has rights to create network profile?

Network profiles are created by Fabric Administrator

Who has rights to create business groups?

Business groups are created by Tenant Administrator

Who has rights to create fabric group?

Only Infrastructure administrator can create fabric group

Who has rights to create reservation policies?

Fabric administrator creates reservation policies

Who has rights to create & Published blueprints (a.k.a Catalog items)?

Tenant Administrator can create and publish blueprints.

Business group manager can only create blueprints

Who has rights to create services?

Only Tenant Administrator can create services

Who can creates approval policies?

Only tenant administrator can create approval policies

Who can create entitlements?

Tenant Administrator and Business group manager can create entitlements

Disclaimer: This above post based on my observation in my lab. I might be wrong. More than happy to be correct, from mistakes we learn

Case of Multiple tenants in vCAC

Before I start on the topic I wish to thank my readers. I’m blogging after more than four months, however I see my post is hitting consistently around 6000 hits per month. I’m surprised and pleased.

Disclaimer: This blog and any blog posts do not represent my current organization in any form.



Hope these are all genuine readers and getting most out of my blog.

When I thought about this post, I asked myself why we need multiple tenants. What are the use cases for the multiple tenants. Before we dive into use case, let’s first understand few roles and what they can do (a.k.a privileges).

  1. Tenant Administrator
  2. Infrastructure Administrator
  3. Fabric Administrator

When you first create tenant, you have to create two roles. Tenant Administrator and Infrastructure Administrator. At first thought I felt both these roles are unique to the tenant and responsible for managing tenants under which they are created. However it is not completely true. Tenant administrator controls tenant for which he is assigned but Infrastructure Administrator can control every other tenant’s infrastructure tab irrespective if he is infrastructure administrator for the tenant, all Infrastructure Administrators (of all tenants) can control infrastructure. In simple words, infrastructure administrator of any tenant can modify anything inside infrastructure tab.

However it is different discussing as to whether Infrastructure should do cross tenant administration. My first thoughts on this – Please do not mess with this one, however totally understand human errors behind this exposure. We make mistakes.

Another role we create is fabric Administrator, Fabric administrator again see infrastructure Tab and same principle applies as for infrastructure administrator.

Infrastructure Administrator role and Fabric Administrator role see common elements across the tenants


It is worth to note, Infrastructure tab is coming from IIS Web server of vCAC infrastructure.

Lets see what are these common elements are

For Infrastructure Administrators

  1. Under Endpoints –All endpoints you create/configure are visible to all infrastructure Administrator irrespective of tenants
  2. Under Endpoints -Endpoints Credentials – All endpoint credentials are visible all Infrastructure Administrator irrespective of tenants
  3. Monitoring (logs, Audit, Workflows) –Monitoring tab is visible across tenants to all infrastructure administrators
  4. Under Groups – Fabric is visible across tenants to all infrastructure administrators

Below is sample view of Infrastructure tab a Infrastructure administrator sees


Below flow chart I’m trying to explain where Infrastructure administrator spends most of the time



For Fabric Administrators

1. Reservations are visible across the tenants to all infrastructure administrators but you can do a little trick. Do no share fabric and it will give isolation at reservation level as well.

2. Machine Prefix – Machine prefix is visible across all the tenants to all infrastructure administrators. In below figure company-A fabric administrator can see company-B’s machine prefix and vice versa.


3. Manual Data collection requests option. This option is needed when you wish to update inventory of your vCenter into vCAC.

4. Network Profiles. These policies are visible across the tenants to all infrastructure administrators. It also means network policy created for company-A can be edited/deleted by fabric administrator of company-B


  5. Reservation Policies. I will explain the actual use of reservation policy in future posts


Below is sample view of Infrastructure tab a fabric administrator sees



Below flow chart I’m trying to explain where Fabric Administrator spends time



Everything after this is very specific to tenants. Following things are controlled by Tenant Administrators

  1. Tenant Administrator creates Blueprints
  2. Tenant Administrator creates Business groups
  3. Tenant Administrator creates services
  4. Tenant Administrator creates entitlement
  5. Tenant Administrator creates catalog
  6. Tenant Administrator creates Approval Policy
  7. Tenant Administrator creates & configure email servers (SMTP)

In below flow chart I’m trying to explain where tenant administrator spends most of this time


In below screen show Tenant A and Tenant B is controlled by Fabric, Tenant  and Infrastructure Administrators


Fabric Administrator and Infrastructure Administrator at both the ends can configure & control Tenants A & B and have full privileges across the tenants. Tenant A and Tenant B Administrator controls individual tenant configurations.

                                                                                                                                             HandyTips                                                                                                                              When you publish blueprint it become catalog. When you create service you add this catalog (published blueprint) to the service. Service can contain multiple catalog (published blueprints). Use firefox browser for better results with vCAC.


So you get true isolation/Multi-tenancy only at Blueprints, Services and catalog level. So answer to our main question is when we go for multiple tenants.

When we do NOT want Catalogs , blueprints and services to be shared.

vCloud Automation Center 6.0 and vCenter Orchestrator Advance Automation -Part03

Part1, Part2 are simple in some ways & parts. Next part is bit difficult to understand. At least it was for me. I will explain what I’m going to do at high level. I’ll get Machine Name. Then I will get Machine Property –> Machine Property will give me custom property ( VM Size which  user be selecting from drop down menu as referred here and Backup Selection referred here ) finally I will Invoke VCO workflow.  In this workflow which needs VM Name input and VM Size, Backup Choice as input – I will put VM Name which I get from Get Machine Name property and VM Size, Backup choice which I got from Get Machine Property


Now lets find where to do this and how to do this. Once you understand the basic concept it is way too simple. First open vCAC designer. In that first select load and then select “WFStubMachineProvisioned”. Why “WFStubMachineProvisioned”. Well, this workflow is called immediately when the status of VM is provisioned. More information is available in guide




In below screen double click on “Machine Provisioned


Scroll down till you find custom code and double click on the custom code


From left hand side “DynamicOps.Cdk.Activities” Drag “GetMachineName



I have defined two variable for this custom code

  1. vmname (to capture VM Name)
  2. VMSize (to capture VM size e.g. Large, Medium and Small in string format)
  3. VarBackupOption (To capture user selection Yes/No in string format)


Double click on GetMachineName


In Machine Id field put a pre-defined variable “VirtualMachineId”. This is standard value. Please do not change it. Under machine name put the variable vmname. This variable we have defined above.

Machine Name will pickup name from virtualmachineid and pass it to vmname. Finally variable vmname will hold the name of the vm. We are done with GetMachineName.

Click on the custom code as shown in above figure, it will take you back to custom code screen. Now from left hand side ”DynamicOps.Cdk.Activities” Drag “GetMachineProperty


GetMachineProperty reads the custom property you have defined and the value associated with that property in vCAC. In our case I have defined custom property with name VMSize and it’s value will come from value select from drop down menu. This value (e.g. Large, Medium or Small) will be taken by variable VMSize


You will notice VMSize property name is in Quotes however Property Value is without quotes. It is because VMSize in property value is variable which will be captured from user interaction in vCAC and VMSize in property name is coming from custom property defined in vCAC.

Conceptually this is how it is related



I repeated the same procedure for Backup choice and here is how it looks below


VarBackupOption will hold the user selection string value which would be either Yes or No and pass it to vCO workflow

Now we have Virtual machine name captured in VMName variable, VMSize captured in VMSize variable and BackupOption capture in VarBackupOption we are ready for next drag and drop Smile . Drag vCO workflow by name InvokeVcoWorkflow

Simply put VMName and VMSize as input to VCO workflow.



Now below is how entire workflow looks like


Now you are done with, simple Send and that updates the WFStubMachineProvisioned


This is all you need to do. Request Virtual Machine and you will get what you have configured.

Complete log of VM provisioning via vCAC and VCO is presented below with sequence of action.


vCloud Automation Center 6.0 and vCenter Orchestrator Advance Automation -Part02

If you have reached this post from Google, check this post first. That is where problem is discussed and this the second part of the solution. First thing you need is to pass three information from vCAC i.e. VM Name, Size of the VM and whether you need any backup. VM Name is parameter you will get from vCAC but for Backup Selection and VM Size selection I have created a custom property in build profile. Here is how I have created below

First go to infrastructure tab

In Infrastructure tab go to –> Blueprint –> Property Dictionary


Create a New Property Definition

Provide Name –VMSize

Display Name –Virtual Machine Size

Control Type – DropDownList

Please ensure Required check box is selected

Once done please click on green arrow.

Then click on Edit to edit Property Attributes


In the property attribute, select ValueList, Put same name “VM Sizes” and provide value as Large, Medium and Small which reflect the size of VM.


Similar exercise you follow for backup option

Here is how it looks when user selects the VM Size


For backup service selection this is how it looks below


Just ensure blueprint is updated as follows


This completes vCenter Automation Part at basic Level. Now comes the 3rd and final part. Follow third part here

vCloud Automation Center 6.0 and vCenter Orchestrator Advance Automation -Part01

This post is about extending vCAC in-built workflows. In last two post (Post1, Post2) I used vCenter Orchestrator (vCO) workflows and executed them using vCloud Automation Center’s (vCAC) advance service designer. It was like taking vCAC as front end to execute those workflows without taking any benefits of vCloud Automation Center’s product. vCAC was purely acting as front end.

Advance service designer doesn’t follow any reservation, policies configured for a particular tenant. It is purely taking inputs from whatever is configured in vCenter Orchestrator workflow and executing it. As I think of it is of help but then I miss all configuration, tracking ownership, multi-tenancy and metering in built in vCAC. In order to cover this I need to do additional scripting which is referred as day-2 operation. To cater this problem, vCAC provides you a way where you can modify in-built workflows. Basic details are provided into this document. I won’t repeat it here. But in order to understand this post you must read it.

To extend workflow you need vCAC designer. It is part of vCAC and can be downloaded from Install it. (it is next-next-next-Finish thing).

Problem Statement

User should be able to provision VM by selecting VM size within vCAC interface. Users should be able to understand what compute, storage details are provisioned when they select VM Size.

Here I’m going to modify my existing workflow which I created in post here. If you see the workflow there are three inputs needed

1. VM name

2. VM size

3. IP Address for the VM

If you review this post, 3rd point is automatically taken care. So I have to just focus on how to take two input (VM Name and VM Size) from vCAC and put in the vCO workflow. It was bit simple, just two inputs.

Cloning part will be taken care by vCAC but post provisioning task will be taken care by vCO workflow. So we need to only focus on creating a vCO workflow which will do the following

  1. Changing CPU count
  2. Change RAM
  3. Add Disk
  4. Add Backup Network if selected

If you execute this workflow from vCO or vCenter  VC:VirtualMachine as input is needed. But vCAC do not understand VC:VirtualMachine, it can only understand string input or can provide string output.  VC:VirtualMachine input is referred as complex object type. In order to deal with this input we need to put a wrapper around the workflow. How to put a wrapper around a workflow is explained by VCOTEAM.INFO. Thanks to this post. It is key post.

That post is a where you can start but that isn’t sufficient. You need more. If you refer below return type is array.


We need a VC:VirtualMachine as return type. I added script section and then I have created a new parameter with VC:VirtualMachine type with name as vm01 (referred in below screen)


In the first line of the script I converted array type i.e. Array/VC:VirtualMachine into VC:VirtualMachine and sent that as output. This is the core piece. If you understood this, you don’t need worry further. Everything else is straight forward. I thought so Winking smile

When I executed the VCO workflow from vCAC, it failed twice. First it failed with VMware tools not working and second time it failed with error “Hot add functionality” is disabled in VM.

First problem was when the provisioning activity was completed, my next workflow which was to shutdown the VM graceful was looking for VMware tools, it didn’t found vmware tools and abruptly failed. In order to shutdown VM gracefully VMware tools must be ready. So to address first problem I have to find a workflow which will check if VMware tools are ready. This can be easily checked by using “vim3WaitToolsStarted” action element. This workflow waits for VMware tools to be ready, as it is need to graceful shutdown VM.

Second problem was workflow didn’t wait for another workflow to be completed. After I shutdown VMs I have workflow which will change CPU count, then change RAM, Add Disk and finally powered ON the VM. So powered ON workflow didn’t wait to execute CPU count, Add Disk and RAM change workflow.  Therefore I use to get error about Hotplug not supported. It was like VM was started before even CPU and RAM change could be executed. So to solve this problem I added “vim3WaitTaskEnd” in-built workflow. This workflow checks previous tasks before executing next task.

With this additional work my final workflow was ready and shown below


NB: Except for the script section, everything in vCenter Orchestrator is in-built

Now next part is how to make vCAC to pick this VCO. I have discussed in next post here

Adding Backup vNetwork card in Bulk using vCenter Orchestrator

Last week I was given task to create a vCO workflow which will allow L1 sysadmins to add a network card to all VMs. I was arguing why not use Powershell? Powershell script was ready in minutes. IT manager was not comfortable with script as his experience were not good in the past and above all this task must be done by L1 during non-business hours. It should be easily executed by them.

I did took his point where in Level-1 won’t have sufficient knowledge to troubleshoot or understand the powershell script. But my point was workflow will take some time as I didn’t saw any built in workflow for it.

I started to search a better way to do it. simplest way was to use Onyx. Onyx didn’t  proved much of help here. Script given by Onyx is not at all workable. I spent lot of my time in understanding it. And some Google search. It wasn’t easy for me.

I took a powershell out from Onyx and started working on it. It gave me fare bit of idea how it should be achieved.


I have designed Workflow which could be seen above. In the workflow I first searched all the VMs in particular resource pool. You can search in the Custer, folder or other places. After I got the VMs, I have to add them network card. Since I’m expected to get more than one VM, I get all VMs in an array. To go through each VM, I used foreach loop.That is all.

User interface below only asks Level –I to select resource pool. Inside the resource pool all VMs will be added with additional network card.


In my case I selected TESTVMs resource pool as seen below


Press Submit and Booom, network cards are attached as seen below


Let me explain you the script. If you don’t read my comments go to the bottom of this post to download the script.

var managedObject = VM;<- VM is Virtual machine to which you wish to add network card
var spec = new VcVirtualMachineConfigSpec();<- You need to initialized virtual machine configuration spec
var myDeviceChange = new Array(); <- you also need to initialized a array to hold all changes.
var myVirtualMachineNICCard = new VcVirtualE1000(); <- you need to initialized  VcVirtualE1000 network card and below you fill all the required values
var configSpec = new VcVirtualDeviceConfigSpec(); <- initialized virtual machine device configuration specification

myVirtualMachineNICCard.key = 0;
myVirtualMachineNICCard.backing = new VcVirtualEthernetCardNetworkBackingInfo();
<- initialized virtual machine network backing information
myVirtualMachineNICCard.backing.deviceName = “VM Network”;
myVirtualMachineNICCard.connectable = new VcVirtualDeviceConnectInfo();
<- initialized virtual machine connectable information
myVirtualMachineNICCard.connectable.startConnected = true;
myVirtualMachineNICCard.connectable.allowGuestControl = true;
myVirtualMachineNICCard.connectable.connected = true;
myVirtualMachineNICCard.addressType = “generated”;
myVirtualMachineNICCard.wakeOnLanEnabled = true;
configSpec.operation = VcVirtualDeviceConfigSpecOperation.add;
<-since we want to add the network card, we use add
configSpec.device = myVirtualMachineNICCard
spec.deviceChange = myDeviceChange

Script is the most difficult part for this post. I tried my best to explain it. Hope it helps you all.

I also took opportunity to update my previous post and now workflow looks as shown below. User gets option to select backup network. In order to implement it I used decision workflow. If user has selected Backup Network required as Yes, then green line will be followed where network card will be added and next workflow will be executed. If he says No, add backup network workflow is skipped and next workflow is followed.



Hope it helps.

Anyone want to use or modify this script can download it from here.

And modified workflow can be downloaded from here

How to use vCenter Orchestrator to reduce your template maintenance overhead

When I choose to blog about this workflow I was bit hesitant if it is going to be really any value add to my readers. This is the extension of previous blog and it related to custom property post which I had done earlier. In custom property I raised the concern that with clone workflow you have very limited choice. As I explore in depth about integrating vCenter Orchestrator and vCenter Cloud Automation Center I found a better way to do. Clone workflow is the best workflow but vCloud Automation Center by default provides a limited customization it. I have not inclination to get into deploy mechanism of each and every OS e.g. WIM or any other method. So any thing extra I can do with cloning will be always a value add. In this post I explore this pain point.

You must have had heard VM sprawl. Have you heard of Gold templates sprawl. I have experienced it a lot. We created as many VM template as we had service type and again for each OS. Currently our VM sizing looks like below


There are total nine templates I have to maintain. Maintenance includes patching these VMs every time new patches are released. This is very common problem with MS OS. Upgrading VM tools, Upgrade VM hardware. If either of this is left it created huge incompliance in VM hardware, vmware tools and patches.

We always have searched a better solution for this. One was to use PowerShell but it was really clumsy and support was not using it at all.

Using this post I also wish to focused on resolving this problem.

Support wanted a complete automated method where in either end user (non-IT) provision the VM and he gets the VM as per the size he has selected or IT provision them

So they were looking for end to end automatic provisioning a VM without any additional effort to customize the existing deployment method. Cloning was the only option. So I felt cloning existing VM and changing the CPU, Memory and Disk size would be the best way to resolve it. vCenter Orchestrator is wonderful product. It just helps you do it without any effort as long as you know the tips and tricks about it.

All the Workflows are in-built in vCO. All I did is put them in right place.


Crux of this entire workflow is script section.


Script section is very simple. Let me explain it you

First I created a input parameter by name VMService. I have added property to it with pre-defined answers Large, Medium and Small. This create a drop down menu where user selects VM size

Second I created three attributes by name. Remember attributes gets there value from somewhere else

  1. vmNbOfCpus (type number)
  2. vmMemorySize (type number)
  3. AdditionalDisk (type number)

I used “If else” loop. So when user select VMService as Large, script under curly bracket will be executed i.e. it is take value for vCPU=4, MemorySize=4096MB and Disk size=40 GB. All I have to pass these values to next workflow. In this case they are

  1. ChangeCPUcount gets vmNbOfCpus  as 4
  2. ChangeRAM gets vmMemorySize as 4096 MB
  3. Add Data disk gets 40 GB
  4. Change the custom attribute

End User gets below screen to provision VM. Just select IP address, VM Name and Size of the VM. That is all end user has to worry. VM will be ready within 15-20 minutes.


Below is the example of workflow logs


And Below is the example of VM which was created.


As part of workflow I also added custom attribute to VM based on the size created. VM size provisioned below is Medium.


This has been achieved using vCenter Orchestrator Video training available freely at this location.

If you wish to integrate this workflow with vCloud Automation Center you should use advance workflow designer feature. I have discussed it here. Process is more or less similar.

Note: In cloning workflow vim3WaitDnsNameInTools was behaving abnormally. This action element reads DNS name of the VM. Once it read DNS name of the VM using VMware tools, it takes this as trigger to end sysprep operation and proceed next workflow. In my case I got quite varying results. While searching a bit I came across new plug-in introduced for vCenter 5.5.1. Please use latest plug-in which is right now under Technical Preview as I post this.

Integrating vCenter Orchestrator with vCloud Automation Center–Advance Service Design

In the Last post we saw how to use vCenter Orchestrator (vCO) to create service based VM. In this post we will look at how to import the vCenter Orchestrator workflow into the vCloud Automation center (vCAC). Integration process is straight provided as long as you know some unknown bugs or workarounds. To do this we have to use Advanced Service Designer. Once integration is done we can publish vCenter Orchestrator workflow as catalog items, include them in the services and publish the services in the catalog.

Little Background Information

vCenter orchestrator comes embedded with vCAC appliance.


If you use embedded vCenter orchestrator (referred as default orchestrator server) and also if you use identity appliance, vCenter Orchestrator will register itself with Identity appliance. As result vCenter orchestrator can be accessed only using SSO user i.e. administrator@vsphere.local. If you try to register the vCenter orchestrator with vCenter SSO or LDAP, vCenter orchestrator breaks. It keeps saying “Node is not active”. I don’t know yet what is the solution for this.

I simply removed identity appliance and started using SSO the one which comes with vCenter. As a result we have one SSO. vCenter orchestrator register itself to vCenter’s SSO and I can access vCO using any domain account. However if you wish to register this vCenter Orchestrator via vCAC it doesn’t work. It works only if external vCO is register using LDAP rather SSO as shown below.


Primary reason I want to highlight as I have spent almost a week on this problem and I have built vCAC environment twice. Hope it saves my reader’s time .

Lets go back to the main topic. Lets make vCenter Orchestrator vCO talk to each other.

Now we have made the connection. Next steps are simpler. Foundation is already created in the last post. All we need to do make vCAC aware of it.

Configure External vCenter Orchestrator

I preferred using external vCenter Orchestrator as it gives more flexibility in operating and managing than the embedded and looks more stable. Go to Administration Tab using Tenant Administration credentials

1. Select Server Configuration

2. Select Radio Button “Use an external Orchestrator server

3. Field details are explained below.


Most of the screen of vCloud Automation Center Provides test option. It makes things really helpful to troubleshoot. Above Test Connection button confirms if the connection is made or not. After testing connection don’t forget to press Update

As vCloud Automation Center Administrator you also have option to configure each tenant to specific folder insider vCenter Orchestrator. This is simplest way to achieve multi-tenancy inside vCAC but it still leaves you exposed at vCenter Orchestrator level.

Login as administrator to default tenant which is vsphere.local. Go to Advanced Services select Default Orchestrator Folder and edit the path as shown in screen next to below this screen


In below screen I’m selecting path for Coca-Cola Tenant. In below screen tree structured is actually being exposed by vCenter Orchestrator. Therefore folders you see below are pre-created by me.


In above screen you also see Server Configuration tab. In this tab have option to configure vCenter Orchestrator for all tenants. I have not used this.

Now lets create a custom resource

Create Custom Resources

Login with a user who has privileges of service architect. In the Advanced Services tab go to the Custom Resources tab and select the Inventory type . These inventory type are vCenter Orchestrator Objects exposed through the API of vCenter Orchestrator connection we just established above


Give Name to this inventory type. This is something you should be able to relate. This name will be needed during Service Blueprints configuration as resource you will be provisioning.


In the Details Form tab I haven’t touched anything, just left it default. Below is the screen for reference.


Service blueprints

Service blueprints allow us to publish vCenter Orchestrator workflows (pre-defined or customized) as catalog items.


Next screen you see vCenter Orchestrator’s tree structure of workflow. Select the workflow of your choice. Since I have created customized workflow in previous post, I’ve selected Coca Cola Services


On the right hand side of above screen you get to see all the parameter we have defined in the workflow. You can rename the parameter. In above screen VMName01 doesn’t make complete sense, so I will rename it as we proceed. Review and then select Next. In the Details tab put the name for the service and put some meaningful description as it presented to the customer when you request service as shown by arrow . See below how Description is reflected in catalog request form


In below screen in Blueprint form tab you’ve lot of option. e.g. you can change the order of tab. Simply drag and drop as per your requirement.


In each display items like Services, VMName01 and Backup you have ability to control default values, select whether value is required. Simply select Edit button to make modifications. Let me change the name of VMName01.


You also see Constraints tab in above figure. Below is the Constraints screen. All values are picked from the workflow e.g. I have kept VM Name to be have minimum length of string as 5.


You can change these values as per your requirement. In request form I have shown that error control is invoked when the length of string is less than 5


After Blueprint Form tab is filled, press Next in Provisioned Resource tab select the custom resource we have created earlier.


Press Add to create Service Blueprint. After Service Blueprint is created it is in draft stage. You must publish so that this is available as a catalog item while creating service.


Creating services is explained in depth in my previous posts here and here . Follow all steps in those two articles, you will be ready with service.

Login as user and select the service to be published


Fill in the details as requested below.


Press Next to go to Step tab.

Select Name of the Virtual Machine

Select Services

Select if you need Backup ( I selected Yes)


After the service is successfully provisioned, in vCenter we can see HR-Gold-009 is provisioned as expected


Conclusion: If you know vCO and vCAC I think you can do wonderful orchestration that too without have very little development background.

I’m thankful to post of  Viktor van den Berg (VCDX121) for this post on Advance Service Designer Post-I and Post-II