+ All Categories
Home > Documents > VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute &...

VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute &...

Date post: 23-Jun-2020
Category:
Upload: others
View: 5 times
Download: 0 times
Share this document with a friend
19
1 VMware HCI Introductions Hyper-Converged Infrastructure VMware’s Software: ESXi & vSAN & vCenter vSAN Overview & Technical vSAN Features Partner Stephen Tuomey Sr. Systems Engineer – Hyper-Converged Infrastructure [email protected]
Transcript
Page 1: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

1

VMware HCI Introductions Hyper-Converged Infrastructure VMware’s Software: ESXi & vSAN & vCenter

vSAN Overview & Technical vSAN Features Partner

Stephen TuomeySr. Systems Engineer – Hyper-Converged [email protected]

Presenter
Presentation Notes
Tech Deck
Page 2: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

VMware’s Software Defined Data Center (SDDC)

2

Convergedcompute & memory & storage

INDUSTRY-STANDARD HARDWARE

ANY APPLICATION / ANY DEVICEHYPER-CONVERGED INFRASTRUCTURE

Horizon / Workspace One: End user access to virtual desktops, applications and secure data on a variety of endpoint devices

AirWatch: Enterprise Mobility Management

VMWARE CLOUD FOUNDATION

Management vCenter: Centralized management of the virtual environment

Compute ESXi: Industry-leading, purpose-built bare-metal hypervisor

Storage vSAN: Radically simple, enterprise-class shared

HW Management SDDC Manager:Hardware lifecycle management

Networking NSX:Network virtualization

INFRASTRUCTURE MANAGEMENT

vRealize Suite:• vRealize Operations: {Single Pane of Glass}

• vRealize Automation: {Rapid Deployment}

• vRealize Business: {IT financial management}

• vRealize Log Insight: {Log Aggregation}

Page 3: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

VMware vSAN: Radically Simple Storage

3

vSphere + vSAN

• Efficient hypervisor – x86 converged solution

– Cache - SSD / NVMe / Optane

– Capacity - SSD / NVMe / HDD (hybrid)

• Enterprise-level features:

– Deduplication, Compression (All-Flash)

– Erasure Coding (RAIDN 5/6) (All-Flash)

– Encryption

– Availability, Scalability and Performance

• Dynamic Scale (no service interruption)

– 2 to 64 nodes

– Per node

• 1 to 5 cache drives

• 1 to 35 capacity drives

• Policy-based Management

– Dynamic & Applied at the VM level

Overview

vSAN Datastore

Storage Designed for Business

Cache

Capacity

Page 4: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

26

• Separate storage controllers with their own OS to manage

• All storage I/O traverse multiple hardware / software layers

• Minimal management & policy integration with hypervisor

• Scaling requires “shelf” or controller purchase

Traditional SAN/NAS Approach

4• Separate storage virtual appliances with their

own OS to manage• All storage I/O traverse multiple software layers

• Lack networking and security virtualization

• Lack management & policy integration with hypervisor

• Scaling requires expensive node purchase

Other “Converged” Approaches

TieringDedupeCompressionSnapshotsClonesReplicationRebalanceData Protection

(RAID)

TieringDedupeCompressionSnapshotsClonesReplicationRebalance

Presenter
Presentation Notes
Hyperconverged storage solutions require the installation of a virtual storage appliance on each host. However, in the case of VSAN, because it is embedded in the ESXi kernel, all the Virtual SAN smarts are already built in to the hypervisor and there are no additional components to install. Just 2 clicks and it can be enabled. There is no separate virtual appliance and no additional management overheads. Because it is embedded in the hypervisor VSAN provides the shortest path for I/O, making storage operations optimally efficient and does not consume CPU resources unnecessarily. Even during maintenance operations and VM migrations, storage operations are seamlessly handled.
Page 5: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

vSAN Is Integrated within vSphere• Critical services converged in hypervisor kernel

• High performance, low latency & low resource requirements• No physical or virtual appliances to manage• Minimal software for reliability• Direct I/O path from VMs to hardware

• Management & Policy integration - vCenter• Capacity, Performance & Health Information

integrated into vCenter• Per VM(vmdk) policy capabilities

• Easy scale-up & scale-out

26

SnapshotsClonesReplicationData Protection (RAID)Cache Reservation

DedupeCompressionEncryption

Presenter
Presentation Notes
Hyperconverged storage solutions require the installation of a virtual storage appliance on each host. However, in the case of VSAN, because it is embedded in the ESXi kernel, all the Virtual SAN smarts are already built in to the hypervisor and there are no additional components to install. Just 2 clicks and it can be enabled. There is no separate virtual appliance and no additional management overheads. Because it is embedded in the hypervisor VSAN provides the shortest path for I/O, making storage operations optimally efficient and does not consume CPU resources unnecessarily. Even during maintenance operations and VM migrations, storage operations are seamlessly handled.
Page 6: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Greater Consolidation Ratio Lowers Cost per VM

vSphere

Storage VM(per server)

Typical HCI vSAN In-Kernel HCI

Storage VM consumes resourcesData paths are inefficientAdditional management bolted on

2x CPU and 3x memory efficiencyNative vMotion and DRSSimple, single management pane

vSphere / vSAN

12

3 4

5

1 23&4* Network

1* Network

Page 7: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

7

vSAN 5.5March 2014

vSAN 6.0March 2015

All Flash64 Node ClusterX2 Hybrid PerformanceVSAN SnapshotsVSAN ClonesRack Awareness

vSAN 6.2March 2016

vSAN 6.1September 2015

Stretched ClusterReplication - 5 Min RPORoot Cause AnalysisHealth Monitoring

DeduplicationCompressionErasure Coding (RAID 5/6)Quality of Service Performance & Capacity MonitoringExpanded Virtual SAN Ready Nodes

VMware Storage:A history of data integrity, data availability & data resiliency

vSAN – Continued Innovation

vSAN 6.5December 2016

iSCSI Target2 Node Direct Connect512e Disk SupportCloud Automation

vSAN 6.6April 2017

EncryptionEnhanced Stretched ClusterEnhanced RebuildSimplified Networking

VxRail 4.0

VxRail 4.5

VxRail 3.5

Page 8: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Secure Data with vSAN Data-at-Rest Encryption

• Datastore level, data-at-rest encryption for all objects on vSAN Datastore

• Enabled at cluster level, supporting hybrid, all-flash, and stretched clusters

• No need for self encrypting drives (SEDs), reducing cost and complexity

• Works with all vSAN features, including deduplication and compression

• Integrates with all KMIP compliant key management technologies, including SafeNet, Hytrust, Thales, Vormetric, etc.

vSphere vSAN

vSAN Datastore

Presenter
Presentation Notes
Key Message/Talk track: Addressing changes in requirements can be a challenge, and a potential risk for data center administrators. Requirements around security can often make compliance a much more challenging endeavor. By addressing concerns such as security of data natively in the hypervisor one can have the confidence that VMware vSphere running vSAN can address those concerns efficiently and effectively using software that they already know. This is exactly what vSAN 6.6 offers. Data at rest encryption that is built right into vSAN, easily enabled by a few clicks of a mouse. ---------------------------------- Overview: Datastore level, data at rest encryption for all objects on vSAN datastore Enabled at cluster level, supporting hybrid, all-flash, and stretched clusters No need for self encrypting drives! (SEDs) Reducing cost and complexity Works with all vSAN features Integrate with all KMIP compliant key management technologies, including SafeNet, Hytrust, Thales, Vormetric, etc. ---------------------------------- Details: No vCenter dependency Cluster wide setting that provides encryption of all data at rest. (data in flight is transmitted unencrypted) All core dumps are encrypted Works with all vSAN features Hybrid and All Flash Space Efficiency technologies such as dedup & compression, RAID5/6 QoS, Checksum Stretched clusters (Witness VM is not encrypted. No data is stored on witness, and not encrypting reduces attack matrix) Transparent to other vSphere features. (e.g. vMotion, vSphere Replication, etc.) Encryption occurs in last step for highest level of protection. Encryption at final step achieves highest level of protection with AES-256. Encrypting earlier would require running ECB degraded mode, not acceptable in financial institutions. FIPS certification pending (In progress at this time). Uses same modules as “VM Encryption.” The OpenSSL is in progress: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140InProcess.pdf The VM Kernel module is listed: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140IUT.pdf Integration with major central key management technologies that are KMIP compliant Configured in UI Tested with SafeNet, Hytrust, Thales, Vormetric, but other KMIP should work. Supports KMS servers running as KMS clusters to ensure high availability Encrypted vSAN must have KMS available in order to boot. vSAN datastore must upgraded to the vSAN on-disk format version 5.0, as a part of vSAN 6.6 Enabling encryption requires that all disks in disk group to be reformatted vSAN disk groups are not usable without keys vSAN encryption a part of Enterprise licensing Encryption needs CPU resources, and can introduce some levels of CPU overhead. The amount will be dependent on the type and volume of I/O activity. Witness host is not encrypted. Why? It is more secure to not encrypt the witness node. If the witness node is encrypted, it has to store all the credentials to get the secret key from the Key Management Server (KMS). These credentials become another attack surface that we have to protect. However, since witness runs in a virtual environment, it is easier to be attacked than regular hosts which run in physical environments. Not encrypting witness node reduced attack surface and makes the system more secure. What can be leaked on the witness node includes number and size of each vSAN object, their log sequence number, and policy. None of these are sensitive user data. ---------------------------------- Definitions: FIPS PUB 140-2: “Federal Information Processing Standard” (FIPS) Publication 140-2, is a U.S. government computer security standard used to accredit cryptographic modules. AES: Advanced Encryption Standard (AES), is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology (NIST) in 2001
Page 9: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Supporting a Broad Variety of Use Cases

Business Critical Apps (SAP, DMZ)

Virtual Desktops (VDI)

DR / DA

Cloud Native AppsDatabases (SQL/Oracle)

ROBOManagementClusters

Containers Solutions TBA Q2 FY19

vSAN

CH2M, Telecomuting

University of South Carolina , Rent-A-Center

(CINgroup, COOP, Whirlpool)

(Cincinnati Bell, Century Link)

(Yellow Page Canada, Sugar Creek Packing)

Work Space One – VDI Reference Architecture

(Peter Cremer NorthAm, Discovery )

Presenter
Presentation Notes
Summary: Customer facing Use Case slide with active web links to the associate white papers.
Page 10: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Reduce reliance on special skills and expertise

10

Built-in tools, designed to deliver Virtual SAN management from the vSphere Web Client.

• Built-in performance monitoring• Health & Performance APIs/SDK• Storage capacity reporting• And many more health checks…

Performance & Capacity Monitoring

• Cluster Health• Network Health• Data Health• Limits Health• Physical Disk Health

Advanced Troubleshooting & Health Reporting

• Cluster Configuration• Drive Assignment• Fault Domains /

Stretched Clusters

Simple Management via vSphere Web Client

• Availability• Protection Method• Performance • Reserve Cache• Reserve Capacity

Set Storage Policies per VM or virtual disk

Page 11: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

ElasticGrow or shrink on demand

GranularAdd single nodes or disks

vSAN Enables Elastic Scaling of Performance and CapacityNo More Complex Forecasting & Large Upfront Investments

11

Non-disruptive No app downtime

>150,000 IOPs / Node Linear scalability

Page 12: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

vSAN Investment Protection & Next-Generation Hardware

vSAN vSANAll Flash / Next

vSAN leverages next-gen hardwareHigh performance

Consistent low latency

All FlashHigh performance

Consistent low latency

vSANHybrid

High performance

Continuous re-platforming leverages next-gen hardwareto deliver the lowest $/Gig and $/IOPS

Page 13: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Broadest Deployment Options from HCI to SDDC Built on Industry-Leading VMware Hyper-Converged Software (HCS)

Certified SolutionsvSAN Ready Nodes

Engineered AppliancesVxRail

Virtual SAN Ready Nodes

Build Your OwnDell “Servers”

Virtual SAN Hardware Compatibility

Lifecycle Management

EMC Federation HCI Appliance

VMware HCSVirtual SAN + vSphere + vCenter

VMware HCSVirtual SAN + vSphere + vCenter

VMware HCSVirtual SAN + vSphere + vCenter

Disk Controller SSD HDD

Cloud FoundationVxRack, EHC

Certified PartnerHardware

NSX

vRealize

VMware HCSVirtual SAN + vSphere + vCenter

SDDC Manager

Presenter
Presentation Notes
Summary: The consumption models. We are all expected to lead with VxRail. It is the easiest of the consumption choices, but not always the most suitable solution. vSAN – DIY – Your customer takes on the responsibility vSAN Ready Nodes – Certified Solutions – but there is still significant engineering that the customer will be responsible VxRail – Not plug & Play, but totally engineered appliance NSX & Cloud – Final step to Software Defined Data Center with a path to the public cloud.
Page 14: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Simplicity, Scale, & Savings.

Turnkey hyper-converged VMware appliance

Quality of Service Data ProtectionData Efficiency Services

VxRailMarket

Cloud Storage

Presenter
Presentation Notes
VxRail comes fully loaded with everything included: RecoverPoint for VMs provides Replication, data protection, and advanced disaster recovery , and 5 licenses of RecoverPoint for VMs comes with each appliance node. VMware Data Protection and optional Data Domain for centralized de-duplicated backup and recovery EMC CloudArray allowing for storage capacity expansion from the appliance with scalable cloud-based storage to the public cloud (our own or others). 1TB appliance storage comes with each appliance. And, a Market where pre-loaded applications exist for customers to extend the value of their appliance, and will be populated over time with more and more applications.
Page 15: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

vSAN Licensing

Page 16: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

$127K

16Q1 16Q2 16Q3 16Q4 18Q1 18Q2 18Q3U***S

$207K$34K $114K

16Q3 16Q4 18Q1 18Q2 18Q3 18Q4 19Q1SP****P

$7K $100K $11K

16Q3 16Q4 18Q1 18Q2 18Q3 18Q4 19Q1B***s

16Q1 16Q2 16Q3 16Q4 18Q1 18Q2 18Q3S***M$210K $340K $64K

16Q2 16Q3 16Q4 18Q1 18Q2 18Q3 18Q4N****s

$24K $19K $21K

14Q2 14Q3 14Q4 15Q1 15Q2 15Q3 15Q4B2***

$13K $7K $20K $32K $3K

vSAN & VxRail: Guaranteed Annuity

$51K $120K

vSAN VxRail (vSAN Portion)

$9K $62K $22K$60K

$339K $339K $5K $42K $14K

Presenter
Presentation Notes
Summary : Despite our competitors opposing view vSAN IS a mature product and it has become a mature product in a very short time period. The VMware vSAN Product Team continues to deliver advancements in scalability, performance, security and lower costs to support an agile, software-defined data center. *** Important*** Understand that VxRail is an appliance product utilizing vSAN (other VMware software products) and Dell EMC hardware validated and certified to enhance the customer experience by minimize storage complexity. So there will be a lag from General Availability (GA) of vSAN software revisions and validation and acceptance of the latest revisions applied to VxRail products. *** Explanation of the process *** Response from Product Group: We have a policy to pick up major new releases (to VxRail) at Update 1 - but, after that point, we are averaging less than 20 calendar days to validate and release post VMware GA.  We are working hard to reduce this time and have an aspirational goal to get to the same day - but there is no commitment
Page 17: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

vSAN/VxRail Salient Characteristic

• Storage management integrated into hypervisor

• No additional software installation required– No additional training required

• Approved for DoD use under DISA STIG Framework– Certificate of Networthiness (CoN) from U.S. Army

• Native encryption of data-at-rest (no need for Self Encrypting Drives (SEDs))

• Support for Storage Policy Based Management

• Integration with multiple Public Cloud Providers

Differentiators for RFIs, RFQs and RFPs

Presenter
Presentation Notes
Summary : These are simply lockout specs for RFP/RFQ responses
Page 18: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Next Steps to Get Started with vSAN & VxRail

Start with vSAN Assessment

• Understand the needs of your environment in just one week!

• Contact your VMware Partner, SEs or Rep for a free vSAN assessment

Additional on-line resourcesVMware Hands-On Labs CatalogCormac Hogan VMware vSAN BlogVMware Storage and Availability Technical Documents

StorageHub – Demos and Guideswww.storagehub.vmware.comFree Hands-On Labsvmware.com/go/vsanlabVirtual Blocks – vSAN Blogblogs.vmware.com/virtualblocks/vSAN Sales [email protected] Test Drive – No ChargeFull Agenda & Registration Portal

Presenter
Presentation Notes
As you look to extend your virtualization strategy to storage and beyond, we have additional information to help you on that journey. You can start with a free vSAN Assessment to quickly understand how vSAN could fit in your environment today. If you’re looking to do some research on your own, then check out our resources on StorageHub or get your hands on vSAN through one of our free, online Hands-On Labs. For the latest news and information, stay plugged in to Virtual Blocks, a blog focused on all things vSAN from our product experts.
Page 19: VMware HCI - Carahsoft · VMware’s Software Defined Data Center (SDDC) 2 Converged compute & memory & storage INDUSTRY-STANDARD HARDWARE. HYPER-CONVERGED INFRASTRUCTURE. ANY APPLICATION

Thank You

Stephen [email protected]

At a glance resourceshttp://labs.hol.vmware.com/http://cormachogan.com/http://storagehub.vmware.comhttp://www.vmware.com/products/virtual-san.html


Recommended