Digital concept illustrate of modern technology and innovative processes, networking and big data.3d rendering
Home Page

Upgrade to VMware Cloud Foundation 9.1 and Express Patching Webinar Top 10 Questions Answered

Thank you to everyone who joined our recent technical webinar on upgrading to VMware Cloud Foundation (VCF) 9.1 and applying Express Patches in modern private cloud environments. During the session, attendees submitted questions on security compliance, lifecycle management, upgrade paths, live patching, and automation.

To help infrastructure architects, system administrators, and security teams, we have selected and expanded on the top 10 technical questions from the webinar, grouped into five categories below.

Security, Compliance, and Vulnerability Management

Question 1: How can we conduct a security audit across VCF components to verify STIG compliance?

Broadcom provides a STIG Automation Appliance, available through your account team, to help automate auditing and hardening of STIG security controls across the VCF stack, following the STIG Readiness Guides.

If you are not required to meet STIG requirements, Broadcom maintains the VCF Security Configuration and Hardening Guidelines alongside open-source scripts and API sample code to programmatically verify and enforce security baselines based on your organizational requirements. You can access these automation scripts and hardening guides on GitHub in the VCF Security and Compliance Guidelines Repository.

VCF Professional Services offers a STIG readiness assessment to analyze your current configuration and assist with automated gap remediation to reach a hardened target state.

Industry-standard third-party vulnerability management tools can scan and discover vulnerabilities across VMware environments.

Both types of scans have their own benefits, and generally both should be run. Authenticated (credentialed) scans log directly into appliances and VMware ESX hosts to audit patch build numbers, internal package configurations, and security settings. They may provide more complete findings and simulate an insider threat or trusted user perspective. Keep in mind, though, that you are giving privileged access to a scanner and other people inside your organization. Our recommendations are always to keep SSH disabled, and follow least-privilege practices. In contrast, non-authenticated (network) scans probe listening network ports and external services. They simulate an external attacker probing the perimeter without internal system access.

Question 3: How should organizations handle severe security advisories (for example, VMSA-2026-0006) when hardware vendors delay custom ESX image releases?

vSphere Lifecycle Manager allows you to include vendor-specific components directly as an add-on to a standard ESX image, rather than waiting for the hardware vendor to ship an ISO. This lets you stay on a base image, and we recommend it because you can pick the components you need rather than taking everything the vendor ships.

That said, if a component is only available in the custom image, you will have to wait for the vendor to ship their image.

vLCM Hardware Integration and Host Remediation

Question 4: Is combining ESX base images, OEM add-ons, and hardware management plugins (such as Dell OMEVV or HPE OneView) supported in vLCM for VCF?

Yes. VCF 9.1 requires the use of vSphere Lifecycle Manager images. This lets the administrator define the image along with any firmware and other add-ons specific to the hardware. This unified approach is supported and is a best practice, because vSphere Lifecycle Manager images unify the management of your environment.

Detailed instructions on setting up firmware baselines and vendor integration are available in the Broadcom TechDocs for vSphere Lifecycle Manager Firmware Updates documentation.

Upgrade Paths and Upgrade Sequence Logic

Question 5: What are the supported upgrade paths for VxRail hyperconverged infrastructure to VCF 9.1?

Upgrading VxRail environments is a Dell-supported process. There are various upgrade paths available, and we recommend opening a ticket with Dell Support for guidance on VxRail deployments.

Question 6: Why are the “Configure” buttons grayed out during the SDDC Manager upgrade sequence, and how is this resolved?

There are several reasons the Configure button could be grayed out. The most common is that you are in the middle of an upgrade sequence. Until you complete the previous steps, the buttons remain grayed out. For example, in a three-step process, steps 2 and 3 are grayed out until step 1 is completed.

If there is an error in the workflow, you could also see the Configure button grayed out until the failure is corrected or the workflow state is cleared, which usually happens after a few minutes.

Question 7: Is it possible to upgrade an environment consisting of two physical hosts to VCF 9.1?

Small two-node environments can be upgraded. Success depends on host compute and memory capacity, because one host must temporarily sustain the entire workload while the other host is in maintenance mode. If there is insufficient capacity, you may need to shut workloads down. Storage availability policies (such as vSAN storage rules and witness host communication) must also be verified before placing a host in maintenance mode.

Question 8: When moving to VCF 9.1, can I go greenfield for the VCF management domain with a new VCF Operations instance and vCenter, then pull in a subset of clusters from an existing vCenter 8 instance while leaving the remaining clusters in the old vCenter?

No. When you converge a vCenter instance into VCF, all of its clusters are imported; there is no cluster selection option. Convergence operates on the vCenter instance as a whole, not on individual clusters.

If you want a new vCenter instance, you would need to deploy the new environment, create clusters in that new instance, and migrate workloads as appropriate.

Alternatively, you could first separate the clusters into different vCenter instances according to your requirements, then run the import workflow on each vCenter instance, resulting in multiple workload domains.

Question 9: How does ESX Live Patching affect host upgrades when virtual machines are pinned to hosts and cannot be migrated?

ESX Live Patching allows eligible Express Patches to be applied to running ESX hosts without a reboot or VM evacuation. The host is placed into partial maintenance mode and patched, and VMs remain powered on during a Live Patch cycle and are updated as part of the process.

There are restrictions. Patches that are not eligible for Live Patching (such as major updates or driver modifications) still require standard maintenance mode, which means powering off pinned workloads that cannot be moved with vMotion.

Infrastructure Automation and Ecosystem Integration

Question 10: Are there limitations or best practices when managing VMware Cloud Foundation with Terraform?

At the time of writing, there is no Terraform provider that includes support for VCF 9.1, just 9.0, but please check back.

Resources and Next Steps

Upgrading to VMware Cloud Foundation 9.1 and using Express Patches gives enterprise infrastructure faster security vulnerability remediation with less operational downtime.

For additional technical resources, please refer to the official Broadcom Documentation Portal and the VCF Upgrade Planner.

Need help upgrading and preparing your environment to take advantage of Express Patching? Contact your Broadcom Account Manager to learn how VCF Professional Services can help. If you missed it, watch our webinar replay now.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.