vmware cloud foundation
-
Using Kasm as a Browser-Based Jump Point for a VCF 9 Lab
Using Kasm as a browser-based access layer in front of a VCF lab turned out to be a useful pattern. With Keycloak providing authentication for both Kasm and VCF SSO, the lab gets a cleaner access flow without exposing every… Continue reading
-
Building the Foundation for a VCF Automation All Apps Landing Zone with Terraform
Terraform can describe parts of a VCF Automation 9.1 All Apps landing zone, but not the full model end to end. In this post I walk through the first layers of the landing zone foundation, including organization creation, identity provider… Continue reading
-
Using Keycloak as an OIDC Identity Provider for a VCF Automation Organization
I wanted to test organization-level OIDC authentication in VCF Automation 9.1 using Keycloak from my Provider Box setup. It worked in the end, but a few small details around group claims and claims mapping were easy to miss. Continue reading
-
Guardrails in VCF Automation 9.1
Self-service without guardrails is just delegated infrastructure access with a nicer interface. In this post I look at guardrails in the VCF Automation 9.1 All Apps model, and how organizations, quotas, namespaces, networking, policies, and extensibility work together to make… Continue reading
-
Owning the Platform on VCF 9
In my previous article, I reflected on what I would design differently if I were building an NSX platform today. That piece focused on architectural choices — fewer abstractions, clearer boundaries, stronger defaults. But design decisions are only part of… Continue reading


