VMware vRealise Operations – What’s New

Last week I was fortunate enough to be briefed by VMware on there new “Intelligent Operations” offering, and given a view of what’s new, and the rationale about the changes. The changes are spread amongst the vRealise suite/portfolio of products including:

  • vRealise Operation 6.6
  • vRealise Log Insight 4.5
  • vRealise Business of Cloud 7.3 (Standard Edition)
  • vRealise Network Insight 3.4 (Actually, isn’t included as part of the vRealise/vCloud Suite)

Highlights: vRealise Operations 6.6

Read the rest of this entry »


Posted by on June 6, 2017 in vCOPS

Comments Off on VMware vRealise Operations – What’s New

Reading the Runes with Runecast Analyzer

A runestone is typically a raised stone with a runic inscription, but the term can also be applied to inscriptions on boulders and on bedrock. The tradition began in the 4th century and lasted into the 12th century, but most of the runestones date from the late Viking Age. Most runestones are located in Scandinavia, but there are also scattered runestones in locations that were visited by Norsemen during the Viking Age. Runestones are often memorials to dead men. Runestones were usually brightly coloured when erected, though this is no longer evident as the colour has worn off.


This week I was fortunate to have a briefing with Stan Markov (VCDX #74 and VCI), the CEO of Runecast. In case you don’t know Runecast Analyzer is a tool that gathers info from your vSphere environment and compares it to the VMware KB, Best Practices and the Security Hardening guide. The idea is it makes you proactively act on what it discovers to reduce the time spent reactively acting to events as they happening – in that typical “firefighting manner”.

Typically, we are so busy in the IT world we tend to respond to situations as they arise, and hope that by following design best practice we reduce these events to a minimum. In recent years a number of software vendors have been developing tools to break this cycle of behavior. Despite bold attempts to “automate all the things”, you’d be surprised how many people still are using a combination of Excel spreadsheets and Googling to both keep a track of changes, or respond to new issues as VMware finds them. And, of course, those pesky things called “default settings” that often are left as is, and never reviewed.

When the poop hits the fan such admins are forced into “Cutting and Pasting” cryptic log entries into Google, in the hope that a narrowly defined string will reduce the long list of false positives – it’s become a skill in it’s own right, scrolling through search results and translating the verbiage of KB articles to see if it answers your problem. And I can speak of situations first hand where I’ve had to “stitch together” KB articles to fix an issue. It’s this sort of first-hand pain that the folks at Runecast are addressing.

I was given an NFR license for a year (thank you) and spent yesterday getting my lab environment up and running to ingest their offer. I spent most my time making the lab work again replacing my expired vSphere license! The Runecast Analyzer appliance (in a OVF format) took less time to setup, than it did to download. I pointed at it my vCenter and I was up and running.

Note: As with any lab based evaluation I used my administrator@vsphere.local account. Runecast say a read-only account will cover about 90% of the analysis, but there are some higher-level privileges required to collect 100% of the data needed.

As you might gather with the lab being down for more than a year, it’s not been patched in ages, and also I’ve never bothered with any security hardening. So my results will not be reflective of most production environments (or will it?). As you’ve probably gathered, Runecast Analyzer is an on-premises appliance, and although it pulls data down from Runecast Central Repository, which in turn keeps a track on the VMware KB, nothing is pushed out of your environment. Runecast Analyzer does support offline patch-management for those people who require an air gap between themselves and the outside world for compliance purposes.

Read the rest of this entry »


Posted by on June 2, 2017 in vSphere

Comments Off on Reading the Runes with Runecast Analyzer

Amazon AWS Summit – London, ExCel – 28th June

I’ve bitten the bullet and decided to attend the Amazon AWS Summit in London on the 28th June. Both the London VMUG and this event are for “FREE” the only cost is getting there and back. I’ve spent the money on the train ticket and that pretty much commits me to going! It’s funny with free events – your commitment can vary depending on the mood. But once you put money down it rather clarifies the situation!

If you live in London I guess these events are ‘easier’ to do from a financial perspective, its more whether you have the time to do them. There’s precious little in terms of agenda – but I hope it will be technical and learning oriented and less on the old marketing side. The key note looks mercifully short – so know 2.5hrs sat on your button with you mind being numbed – just 1hr of being sat on your butt with your mind numbed.



Posted by on May 23, 2017 in Amazon

Comments Off on Amazon AWS Summit – London, ExCel – 28th June


Well, I’m all registered for my first VMUG in aaaaaages. It will be good opportunity to network and catch-up with all my fellow vMUGGERS as I like to call them!

Its literally being a “yonks” since I was active in the community. A yonk being measure of time that starts with a career break, and ends when you return. Of particular note – Frank Dennenman will be presenting on the subject of VMware on Amazon. A topic that intrigues me greatly since I’ve been dabbling with Amazon recently as away of getting the little grey IT braincells working again.

Also worthy of note, my pal Julian Wood will presenting on the subject of “Can I order some servers for my serverless, please”. You can relie on Julian for good dosh of “wake up and smell the vBacon”. So I will relish that session.

There’s vBeers, and without sponsors we all know they’d be no vBeers. Just kiddin’ ya 🙂

It’s the usual suspect, but two new vendors who have never previous crossed by radar before…. So Alain Geenrits, Solutions Architect, EMEA for Bluemedora will be there, as will SIOS…

Now all I have to do is sort my training ticket out to get there… Book early to avoid disappointment!

Register here!


Posted by on May 23, 2017 in VMUG

Comments Off on LONDON VMUG – JUNE 22ND 2017

It makes me WannaCry….

You don’t know how to ease my pain
You don’t know…
You don’t know how to ease my pain
Don’t you hear any voices cryin’?
You don’t know how to play the game
You cheat…
You lie…
You don’t even know how to say goodbye…
You make me want to cry….

It’s rare that the world of IT impinges on my friends day-to-day lives in the scale it has in recent days, and rarer still that I feel compelled to address political issues on my tech based blog. That’s mainly because I think people  visit to learn something new about tech or to read one of my blogposts where I got something to work, and they are looking to find out how to do the same. I do have a political blog called “The Age of Rage” and I offload my venom there – I only wish more people did this instead of filling Linkedin, Twitter and Facebook with political opinions they think everyone else will agree with – only to be upset, offended or abusive when they are shocked to discover the world doesn’t uniformly agree with them. However, the outbreak of the “WannaCry” ransomware represents for me unique situation where these worlds do collide. However, I want to talk about these issues in a non-partisan, non-party political way, because frankly there’s enough of that guff around already from our policial class.

Before I “go positive” and speak about the positive steps that can be taken by all stakeholders (users, vendors, governments, agencies of the state). I feel compelled to draw your attention to some artful media management and outright charlatanism that typifies how this adverted crisis is playing out in the media, especially here in the UK. It’s from this I hope to outline how we can collectively take responsibility, but that some organisations have more responsibility than others because of the power and/or financial muscle.

Read the rest of this entry »


Posted by on May 15, 2017 in ThinkPiece

Comments Off on It makes me WannaCry….

Using Amazon Route53 and Google Apps Together using Domain Aliases to complete SSL Certificate Requests!


I’ve got nearly 25 years experience in the IT game with a range of skills that take in this task – DNS, Email, Web-Servers. However, for the last 15 years or more I’ve more or less outsourced the management of this to a third-party, or it simply hasn’t been my job. Once I used to teach Active Directory DNS to students when I was a Microsoft Certified Trainer, but that was way, way, way back in 1996-2003. Of course, there’s nothing new under the sun, as the Great Bard once said – and so I have gotten by ever since with core fundamentals. So this is both old and new too me, and if I was to be honest I’m not sure if the solution to my problem was the best or easiest. I might have just taken a sledgehammer to drive home a thumb tack. I’d be interesting hear if this process could made infinitely more simpler.

I think the ‘order’ of my process is good – especially as you need valid emails to confirm the transfer and setup of certain domains. But I’d also be interested that is this is the best way of doing it – could it have been done more efficiently in fewer steps. Finally, I’d be interested to know if this the ‘right’ way from a security and best practise perspective as well.


I would have liked to have a more exciting title to this blogpost – and one infinitely shorter!  Being a Hunter S Thompson fan, I had thought of adding “A Strange and Terrible Saga”. But I actually I want to avoid the rabbit of an extended rant, and the convoluted shaggy-dog story of my experiences on Friday. It took me 6hrs to get this working, and I’m still mopping up the blood spatter today. This should have taken 30min-60mins tops including waiting for DNS caches to expire, and DNS records to be propagated on the interweb. However, I will spare you my personal grief this time, and just focus on the back-story, use-case, solution and workarounds in the hope that anyone facing similar heartache in the future will stumble upon this post and I will save them a bag of time. I’m just nice like that – after all I first got started with VMware, by just trying to be helpful. It takes you a long way in life I think.

Advice: If you are budding wannabe blogger who just wants your own domain, linked to Google Apps for email etc – together with your own WordPress setup. Don’t bother with this approach. It’s overkill. I would sign up to any number of hosted WordPress packages online, that will handle all of this for you in a nice simple easy enrollment process. This blog is hosted with Dreamhost.

The Problem – Back-story/Use-case:

As part of my endeavours to learn more about public cloud I’ve been looking at Amazon AWS. I’ve already put together an environment that leverages Amazon Router53 (DNS) together with multi-region Elastic Load-Balancer (ELB) together with IIS web-based instances running on ‘public’ subnets. I thought it would be good experience to do this using SSL certificates. I established a new DNS domain, registered and hosted with Amazon Route53, and then opted for for .net domain because that allows for the possibility of making my WHOIS information private, whereas this option did not exist for a domain. Privacy is important to me, and I don’t think my postal address should be online for all and sundry to see. This is important to note, as it impacts on the SSL certificate enrollment. Registering the domain with Amazon Route 53 and Requesting an SSL certificate was relatively easy.

Where I became unstuck however – was In order for my SSL Provider to verify me and send me certificate they needed a valid email listed under WHOIS. This became tricky because that information as a.) private b.) the email used under the WHOIS information did not match the emails they would usually “expect” to use. That was tricky for me to easily provide because all I have is the raw DNS domain name, with none of the ancillary services that would normally surround it such as web-servers resolving to or any email infrastructure. Nor did I feel inclined to waste precious time putting together such services merely for a one-off email and verification process.

This process would have been relatively simple had I been requesting a certificate for where those pieces of the puzzle were are in place, and much of the verification process had already been undertaken. However, I specifically wanted to use SSL with Amazon AWS and have it all in that environment, rather than doing the DNS work through dreamhost. Dreamhost is the company that hosts this blog. They are very good by the way.


So I hit upon the idea of associating my existing Google Apps subscription which supports my domain, to also provide email services to my new domain. It is possible to register the domain as “alias” to Once recognised by Google I would be able to create an user within my subscription with google. After that I can then update my WHOIS information at Amazon Route53. And then contact my SSL provider to complete the verification process. Of course, working out HOW do this took time. I’m a pretty tech savvy – but this requires an area of skills, often using interfaces and procedures which are different to ones I’ve used in the past. So you need:

  • DNS knowledge (with Amazon Route 53)
  • Certificate Request Knowledge (Many routes – I used IIS 10 to create a CSR request)
  • An account with Google, and knowledge of their Domain Registration/Validation process
  • Further updates to Route 53 and the WHOIS information to change default settings

I don’t intend to write something step-by-step because as soon as I do – the UI’s will change. I’ve often found that Google help does NOT keep up with their many changes. Amazon on other hand appear to have a better handle on documentation – so there is no point in me trying to compete with Amazon or Google in the documentation stakes. It does illustrate the challenges of them managing such an “agile”  environment compared to conventional shrink-wrapped software company. The documentation gets out of sync with the product…. To be honest I still don’t know WHY some processes provided by Google DID NOT work. And I still dont’ really know if the WAY I have done it the best or most efficient. It does HOWEVER, work. And that to me is what counts. BUT, if anyone can figure out what went wrong or suggest simple/easier way I would be indebted to them for that guidance.

Finally, I dare say Google Domains/Apps could be replaced with a different vendor if you subscription is with some other email supplier other than gmail. For instance I’m sure such a configuration could be achieved with Office360. Of course, any ordinary mortal just wanting a blog with their own domain, and bit of SSL to protect the login would be better of getting a hosting company to orchestrate all this – its much less heartache!

1,000 Foot View:

This is a simple number list that serves as a check-list to anyone (well mainly me) wanting to do this style of configuration…

  1. Register new domain with Amazon Route 53
  2. Login to Google Domains and create a New Domain Alias
  3. Use the cname record method to verify your domain
  4. Populate the Route 53  with the MX records for Google Mail servers
  5. Create a new user in Google Console for your preferred contact for the new domain
  6. Login to the new account, and (optionally) forward all email to an email address you do actually use!
  7. In Amazon Route 53 update your WHOIS information for the new ‘admin” email. receive a flurry of confirmation and validation emails!
  8. Generate a CSR for your domain (various methods)
  9. Submit CSR for your single host certificate (aka or domain wild card certificate *
  10. Use your new certificate as you see fit. In my case attached to two region specific ELB’s which act the SSL endpoint for inbound https requests – thus offloading the SSL process to ELB and away from your web-servers.
  11. Punch the air – and say wow, did I really do that. I must be some sort Cloud God loading over the Olympus of the Internet. Sit back. Have a cup of tea. Feel a little less full of yourself. It’s only software you know… 😉

NOTE: I won’t be covering step 8-11 as they are specific to your environment, and will vary from vendor to vendor. And mainly because this post will be LONG enough without adding that level of detail. My main interest is the interoperability between Amazon Route 53 and Google Apps to get this working.

Now in a LOT more detail…

Read the rest of this entry »


Posted by on May 15, 2017 in Amazon

Comments Off on Using Amazon Route53 and Google Apps Together using Domain Aliases to complete SSL Certificate Requests!

Fluffy Cloudy Amazon Web Services Thoughts (Part N of N)

Disclaimer: I’m not an AWS Expert. I’m learning. I regard myself as a novice. Therefore I reserve the right to make idiotic statements now, which I will later retract. My thoughts on AWS are very much a work in progress. So please don’t beat me up if you don’t agree with me. I’m just as like to respond with “Gee, I hadn’t thought of that – you have a point!”

Well, okay the title of this post is a bit of a joke at my expense. Just before I joined VMware in 2012, I embarked on a series of blogposts about vCloud Director [yes, just as the company change strategy towards vRealise Automation!]. It became quite a series of posts. I dubbed it my “vCloud Journey Journal”, and it ended up with a whopping 73 posts, in what almost became like writing a book through the medium of a blog. Just so you know, this is NOT a good idea as the two formats are totally incompatible with each other. So anyway I don’t want to make the same mistake this time around. And my intention is to write stuff as I learn.

After vCD, I dabbled with vRealise Automation (which was once the vCloud Automation product if you remember, which was aquired via DynamicOps). That product was fine but it was very much about creating and powering up VMs (or Instances as AWS likes to call them). I didn’t feel I was really using the public cloud “properly” but merely extending virtualization features up into the public cloud rather than consuming stuff in the -as-a-service kind of way. Sorry to my former VMware colleagues if this is a massive misconception on my behalf – the last time I touched vRealise Automation is nearly four years ago – and things can and do move on. Plus I’ve been out of the loop for 12 months.

The last couple of weeks have modified my experience, and as consequence got me thinking all over again about what public cloud is, means, or is defined. Sadly, this has became a very boring and tired parlour game in the industry many years ago. I personally think the game of “definitions” of “What is public, private, cloud?” are a bit moot for the community. But they kind of matter to me as the typical in-house, on-premises type who made a name for herself by helping other setup, configure, troubleshoot the virtualization stack from around 2003-2015. But even I feel that the debate moved on long, long ago – and this is me playing catch-up.

Read the rest of this entry »


Posted by on May 9, 2017 in Amazon

Comments Off on Fluffy Cloudy Amazon Web Services Thoughts (Part N of N)

VMware {code} Briefing: What’s New with VMware PowerCLI 6.5.1

VMware PowerCLI 6.5.1 was released on April 20th and it contained some significant improvements and changes! Whether you’re an occasional PowerCLI user or a power user, you’re not going to want to miss this special briefing!


Posted by on May 8, 2017 in Announcements

Comments Off on VMware {code} Briefing: What’s New with VMware PowerCLI 6.5.1

My Amazon AWS Certification Plan with @pluralsight and @ekhnaser (Part God Knows!)

So I’ve played about with AWS in my time at VMware, but really only dipped my toes. Like many people I like to have a goal to work towards – so it felt reasonable to think about going through the steps to prepare for certification. For me the important thing is the learning process and getting the old IT Brain working again. So I may or may not end up doing the eggzams for AWS, but thought the structure around that prep could help frame my learning. I took a look at the certs on Amazons websites:

The above link is pretty good for generic info – if you want more detail for the AWS Certified Solutions Architect – Associate certification this – a much better location –

And I can tell I need to do the “asssociate’ stuff before I do anything ‘profesisonal’ – and given my background the Administrator/Architect path is one that suits me. I’ve spent most of my career training, education and teaching sysadmins how to manage systems – and AWS isn’t going to be any different to that. I’m not about to morph into a developer at my advanced age. You can can teach a dog new tricks, but you can’t teach an old dog to be a cat.

According to Amazon – Step1 is take a training class. As understand it authorised training is not a requirement, only recommendation. So unlike some (ahem) certification tracks that mandate authorised training, that’s NOT the case with AWS. Yippee. That means I can spend my plentiful time instead of my limited cash on training.

As vExpert (2009-2017) I bagged a free 1-year subscription to Pluralsight so it makes sense to use it as alternative to authorised training from a recognised training partner. As rule I prefer classroom training with an instructor is who alive (as opposed to dead). But given the finances I will make do with the passivity that is online training. Pluralsight does have a course entiteld “AWS Certified Solutions Architect – Associate” which fits the bill. It’s created by Elias Khnaser. I know Elias though Linkedin and Twitter, so intend to be little cheeky monkey and ask him questins directly. Although to be kind, I’ll probably store them up until the end of the course. There’s nothing worse for an instructor to be asked questions in Module1, that is answered in Module2, right?

Right out of the bat, Elias recommends attending another course to the above if your a novice. I’ve never been one to skip steps in learning process so I opted to do that first.

If you are going to do the fundmentals course first – I would recommend skipping to Module3: Introduction to AWS Global Infastructure, if you have been in the industry a while like myself. The course is itself feels pretty up to date (I notice there’s no date of creation) and isn’t going date that much because its fundmentals. But you will spot little changes – for instance the course states that there are 10 Regions plus GovCloud. Actually, its now stands at 16 regions with another 3 planned. So long as you follow the URLs in the course you should be able to see these difference. For a more up to date list of the Global Infrastructure – you need this page:

My plan once I’ve gone through both courses is double back to Amazons 8-Step program outline on their webpages. Both courses are about 8hrs in duration… and I would recommend perhaps going through each one twice. One of the decide benefits of online training like this is the “rewind button”. Something that is decidedly lacking in instructor-led training – although I believe some vendors do allow access to online versions of their training material AFTER you have passed the exam. Although in my personal opinion I imagine few people can spare their time out of the bizzy schedules to re-do a course all over again. The benefit I think is “refreshing” yourself on a particular topic or subject you found tough.



Posted by on April 11, 2017 in Amazon

Comments Off on My Amazon AWS Certification Plan with @pluralsight and @ekhnaser (Part God Knows!)


What Next?

So I’m back from my family holiday in Wales with my Mum and Big Brother (no relation to George Orwell). And my thoughts have been turning to what I do next with my time, now that my grown-up gap year feels properly over. I’m not the kind of person who likes to sit on my big fat butt waiting for opportunities to wash up on my shore. So I’ve been thinking about what I can do to ease my way back into the world of work, after my time way. I guess this is always a concern or anxiety that anyone would have during time away from gainful employment. So it’s not just finances that stop people from taking time out from work, as well as those other commitments – mortgage and family usually!

For some months I’ve been volunteering in my local area. Volunteering is a great way to give back to wider society whilst giving your week a focus, not least getting you out and about in the big wide world. I currently volunteer at Derby Museum as well as a local National Trust site called Eyam Hall. I’ve been asked by some what this work is like. The work at the museum started by supporting their recent exhibition on the History of Children’s TV. That was a fun exhibition as we got all age groups coming through, and it really was a little snapshot of how British Culture has changed. My role there as a “Volunteer Ambassador” was just to meet and greet people, and ideally engage with them about the exhibits. It makes such a difference to persons visit- to have a chat with someone, rather than walking through silently through a gallery speaking to no-one. Eyam Hall on the other hand is different kettle of fish. It’s a National Trust property and built around the 16th Century in a village that cut itself off from the world when the plague hit the country. The NT’s approach is to let people wonder and discover, and not ‘impose’ an interpretation on visitors – but its great when folks do ask questions as that means I get the chance to do my best Lucy Worsley impersonation!  My last piece of volunteer work is for local charity called Aquabox. My role there is more work-from-home – in finding new source for fund-raising. So far I’ve managed to get Aquabox listed on the VMware Foundation (and I’m on the look out for other corporate style foundations to add to the list) and applying to official bodies like UK-AID. Anyway, the moral is simple one. If you seeking new employment after being out of the circuit for a while – get volunteering. There are no shortage of areas or opportunities. When I do find employment again – I will probably reduce the time I spend volunteering and move them to the weekend. If you are an employee of big company remember lots of these business now have programs that encourage you taking ‘service hours’ to help good causes. For instance VMware calls this “Service Learning” – For the moment – my plan is to ring-fence Thursday and Friday as my volunteering days (these are always times when there is a shortage of people), and use the remainder of the week doing something more IT related.

So one questions I’ve been asking myself is what do on the technical front. Things have moved on since I’ve been away, but they also moved on whilst I was at VMware. If you have a full-time job with a large software vendor – it’s full-time job just keeping up to date with your own responsibilities, never mind peaking over the cube to look at what the rest of the company is doing. So there question has been – do I throw myself in learning more VMware stuff and refreshing existing knowledge OR do I branch out and do something totally different give myself an entirely virgin field to explore? I mean I don’t want to lose my connections with VMware because that’s been such an important technology and company to me in the last 14 years (2003 is when I opened my first VMTN communities account!). But if I’m going to learning its important to learn some brand new to me. The other consideration as well as ever to someone who is on their own and learning without the backing of an employer is what pre-reqs (physical, virtual, software, knowledge) are needed. Do you play to strengths or try to plug gaps in your knowledge that may not be your strengths?

One thing I’ve noticed in the community is significant rise in folks working towards the AWS Certifications. I guess that’s testament to Amazon’s dominance in the Public Cloud space, but also reflects that fact that many in the enterprise world are users of VMware on-premises and Amazon in the off-premises (is that actually word? it feels so odd to type it!). The other interesting thing to me that happened last year – was the collaboration between VMware and Amazon that was announced last year ( This is currently in a techpreview format, and I think it’s an interesting pivot. There have been lots of different partnerships of this ilk over the years – but I do think this one is significant. The appeal to me is the possibility of cross-over of skills. As we all know find someone who is equally strong in two areas is tricky – and being someone who can comfortable talk about VMware and Amazon with equal authority could be an interest area.

Right now my knowledge of Amazon is pretty thin. Like many I had an account for testing purposes usually of things like VMware vRealise Automation, but also test products that leverage AWS as it related to VMware technologies Revello (now owned by Oracle) and Velostrata. On the plus side, as recent vExpert I have as benefit access to PluralSight’s library of courses. So plan is to use my Mon/Tue/Wed to work through these course, and maybe do the exams associated with Amazon certification. I don’t suspect that this will lead or even relate directly to finding a new role – but what’s important to me is getting my “IT Brain” moving again. The other thought I had is that learning something new will inspire some blogging on my part as well, and that blogging will help (re)build my presence in the community. But also In the spirit of –  learning something new can never hurt….


Posted by on April 10, 2017 in Amazon, Announcements

Comments Off on What Next?