Aller au contenu principal

07 — Workbook Client — Informations à Collecter

Usage : Ce document doit être complété par le client avant tout déploiement ou migration
Responsable : Ingénieur Broadcom en charge du projet
À fournir au minimum 5 jours ouvrés avant la date d'intervention


Section 0 — Identification du projet

ChampValeur
Nom du client
Nom du projet
Ingénieur Broadcom
Date d'intervention prévue
Scénario de déploiementGreenfieldBrownfield (Aria 8.x) ☐ Upgrade VCF 9.0→9.1
Topologie VCF Automation☐ Single Node ☐ Cluster 3 nœuds
Sizing sélectionné☐ Small ☐ Medium ☐ Large
Sites concernésSite Principal : ________ Site DR : ________

Section 1 — Infrastructure Réseau

1.1 VLANs / Sous-réseaux

RéseauVLAN IDSous-réseau (CIDR)GatewayDNS
Management
vMotion
vSAN
NSX TEP (Overlay)
Workload / VM Network
Uplink Nord-Sud
SFTP (si isolé)

1.2 Paramètres réseau généraux

ParamètreValeur
Serveurs DNS primaire
Serveurs DNS secondaire
Serveurs NTP
Domaine DNSex: domain.local
Proxy HTTP (si applicable)
No-Proxy exceptions
MTU Management Network☐ 1500 ☐ 9000 (Jumbo Frames)

Section 2 — Adresses IP et FQDNs — VCF Automation

⚠️ Toutes les entrées DNS (A + PTR) doivent être créées AVANT l'installation

2.1 Topologie Single Node

ComposantFQDNIPDNS A crééDNS PTR créé
VCF Automation Node
(même que VIP dans ce cas)

2.2 Topologie Cluster 3 Nœuds

ComposantFQDNIPDNS A crééDNS PTR créé
VCF Automation FQDN (LB)
Node 1 (Primary VIP)
Node 2 (Additional VIP)
Node 3 (Additional VIP)
Node Pool IP 1 (nouvelle VM)
Node Pool IP 2 (nouvelle VM)
Node Pool IP 3 (nouvelle VM)
Node Pool IP 4 (nouvelle VM)
Load Balancer VIP
Cluster CIDR (plage K8s interne)N/A — ne pas router/24 recommandé

💡 Pour Brownfield : les IPs Node 1/2/3 = IPs des anciennes VMs Aria Automation
Les IPs Node Pool 1-4 sont les nouvelles IPs des VMs Kubernetes


Section 3 — VCF Services Runtime (Greenfield / VCF 9.1 uniquement)

ParamètreValeur
VCF Services Runtime CIDRPlage min. 12 IPs contigus (ex: 192.168.50.0/26)
VCF Services Runtime FQDNex: vcf-runtime.domain.local
Fleet Components FQDNex: fleet.domain.local
Instance Components FQDNex: instance.domain.local
idbroker FQDNex: idbroker.domain.local
licserver FQDNex: licserver.domain.local
VCF Services Runtime Size☐ Small ☐ Medium ☐ Large

DNS pour VCF Services Runtime

FQDNIPDNS ADNS PTR
VCF Services Runtime FQDN
Fleet Components FQDN
Instance Components FQDN
Identity Broker FQDN
License Server FQDN

Section 4 — Comptes et Mots de Passe

⚠️ Sécurité : Transmettre ces informations via un canal sécurisé (coffre-fort de mots de passe, chiffrement)

4.1 Comptes d'infrastructure requis

CompteDescriptionDroits requisValeur
vCenter AdminPour créer/gérer VMsAdministrator@vsphere.local ou équivalent
NSX AdminPour créer segments/LBEnterprise Admin NSX
vSAN DatastoreEspace disque requisAccès en écriture
SDDC Manager AdminPour install VCF Mgmt ServicesSDDC Admin
VCF Operations AdminPour Fleet ManagementAdmin

4.2 Comptes à créer pendant l'installation

CompteDescriptionNotes
admin@vsp.localAdmin provider VCF Automation⚠️ Sauvegarder — non récupérable
vmware-system-userBreak-glass SSH access⚠️ Sauvegarder — non récupérable

4.3 Serveur SFTP (backup obligatoire)

ParamètreValeur
Hôte SFTP (FQDN ou IP)
Port SFTP22
Utilisateur SFTP
Méthode auth☐ Mot de passe ☐ Clé SSH
Mot de passe / Clé SSH
Répertoire destinationex: /backup/vcf-automation
Espace disponibleMin. recommandé : cf. 05_sizing_ha_multisite.md §8
Test connectivité effectué☐ Oui ☐ Non

Section 5 — Certificats

ParamètreValeur
PKI disponible☐ CA interne (Microsoft CA, etc.) ☐ CA externe ☐ Auto-signé
Modèle de certificatex: Wildcard *.domain.local ou individuel par FQDN
Format attenduPEM (.crt + .key)
Autorité de certificationFQDN de la CA
CRL/OCSP disponible☐ Oui ☐ Non
Certificat Aria Automation 8.x actuel (Brownfield)Date d'expiration : _________
Certificat vIDM actuel (Brownfield)Date d'expiration : _________

⚠️ Brownfield : Si le certificat vIDM expire dans moins de 6 mois → le renouveler AVANT la migration via Aria Suite Lifecycle "Replace Certificate"


Section 6 — Source d'identité (Active Directory / LDAP)

ParamètreValeur
Type☐ Active Directory ☐ LDAP ☐ OKTA ☐ PING ☐ Autre
Nom du domaine ADex: corp.domain.local
LDAP/LDAPS☐ LDAP (389) ☐ LDAPS (636)
Serveur(s) LDAP
Base DNex: DC=corp,DC=domain,DC=local
Compte de service (bind DN)ex: svc-vcfauto@corp.domain.local
Mot de passe compte de service
Groupe(s) Admins VCF Automationex: GG-VCF-Admins
Groupe(s) Utilisateurs VCF Automationex: GG-VCF-Users

Section 7 — Infrastructure Source (Brownfield uniquement)

7.1 Environnement Aria Automation 8.x existant

ParamètreValeur
Version Aria Automationex: 8.18.1 (minimum 8.18.1 requis)
Topologie☐ Simple (1 nœud) ☐ Cluster (3 nœuds)
FQDN Aria Automation
IP(s) Aria AutomationNode 1: _____ Node 2: _____ Node 3: _____
Load Balancer VIP (si cluster)
FQDN Aria Suite Lifecycle
IP Aria Suite Lifecycle
Version Aria Suite Lifecycle
FQDN VMware Identity Manager
IP VMware Identity Manager
Version VMware Identity Manager
Date expiration cert Aria Automation
Date expiration cert vIDM

7.2 Cloud Accounts existants (à vérifier contre KB 389563)

Cloud AccountTypeFQDN/EndpointStatus KB 389563
☐ vCenter ☐ NSX ☐ AWS ☐ Azure ☐ GCP ☐ Autre☐ Supporté ☐ Non supporté
☐ vCenter ☐ NSX ☐ AWS ☐ Azure ☐ GCP ☐ Autre☐ Supporté ☐ Non supporté
☐ vCenter ☐ NSX ☐ AWS ☐ Azure ☐ GCP ☐ Autre☐ Supporté ☐ Non supporté
☐ vCenter ☐ NSX ☐ AWS ☐ Azure ☐ GCP ☐ Autre☐ Supporté ☐ Non supporté

⚠️ Les cloud accounts non supportés dans VCF Automation 9.x (cf. KB 389563) doivent être supprimés d'Aria Automation 8.x avant l'import.


Section 8 — Configuration Load Balancer (Cluster uniquement)

ParamètreValeur
Type de LB☐ NSX LB ☐ F5 ☐ HAProxy ☐ Citrix ☐ Autre : _______
VIP LB (adresse)
Algorithme☐ Round Robin ☐ Least Connections
SSL☐ Pass-through ☐ Terminaison SSL
Health Check URLhttps://<node>/health
Timeout session300s recommandé
Responsable configuration LB

Section 9 — Matériel / Hôtes ESXi

CritèreValeur
Nombre d'hôtes Management Domain
CPU par hôte
RAM par hôte
CPU utilisé actuel (%)
RAM utilisée actuelle (%)
Capacité vSAN / Stockage
Espace vSAN libre
Version ESXi actuelle
Modèle hôtes
Validation HCL Broadcom☐ Validé ☐ À vérifier → compatible.broadcom.com

Section 10 — Prérequis réseau — Validation

VérificationResponsableStatut
DNS direct configuré pour tous les FQDNsÉquipe réseau client
DNS inverse (PTR) configuréÉquipe réseau client
NTP accessible depuis le réseau ManagementÉquipe réseau client
Ports firewall ouverts (cf. Section 06)Équipe sécurité/réseau
Serveur SFTP accessible depuis ManagementÉquipe système client
LB configuré et VIP accessibleÉquipe réseau client
Pas de chevauchement du Cluster CIDRÉquipe réseau client
Pas de chevauchement du VCF Services Runtime CIDRÉquipe réseau client
Accès Broadcom depot (internet ou offline)Équipe système client

Section 11 — Contacts projet

RôleNomEmailTéléphone
Ingénieur Broadcom (chef de projet)
Architecte Broadcom
Responsable IT client
Administrateur vSphere client
Administrateur réseau/sécurité client
Administrateur DNS/AD client
Responsable backup/SFTP client

Annexe A — Exemple de remplissage (référence)

Exemple fictif pour orientation :

Client: ACME Corp
Scénario: Brownfield (Aria Automation 8.18.2 → VCF Automation 9.1)
Topologie: Cluster 3 nœuds
Sizing: Medium

VCF Automation FQDN: vcfa.acme.local → 10.10.50.100 (LB VIP)
Node 1: vcfa-node1.acme.local → 10.10.50.51 (ex-vRA node 1)
Node 2: vcfa-node2.acme.local → 10.10.50.52 (ex-vRA node 2)
Node 3: vcfa-node3.acme.local → 10.10.50.53 (ex-vRA node 3)
Node Pool: 10.10.50.54, .55, .56, .57

VCF Services Runtime CIDR: 10.10.51.0/26 (64 IPs, contigus)
VCF Services Runtime FQDN: vcf-rt.acme.local
Fleet FQDN: fleet.acme.local
Instance FQDN: instance.acme.local
Identity Broker FQDN: idbroker.acme.local
License Server FQDN: licserver.acme.local

SFTP: sftp.acme.local:22 → /backup/vcfa
DNS: 10.10.1.10, 10.10.1.11
NTP: 10.10.1.20
Domaine: acme.local

📖 Termes spécifiques VCF 9 : GLOSSARY.md

Précédent → 06_ports_network.md
Suivant → 08_testing_validation.md