Configure vRealize Automation 7.3 appliance
From Notes_Wiki
Home > VMWare platform > vRealize Automation or VMWare Cloud > Configure vRealize Automation 7.3 appliance
- Open vra portal in web browser (eg https://vra.rnd.com) and click on "vRealize Automation console"
- Login as configurationadmin (Created during - create initial content) page
- ENDPOINTS
- Go to Infrastructure -> Endpoints and add a Virtual -> vSphere (vCenter) endpoint.
- Give Name as vCenter. This must match exactly as name given during vra deployment on Agents page.
- Example adddress for vcenter is https://vcenter.rnd.com/sdk.
- Give vcenter username administrator@vsphere.local and password.
- Click "Test connection".
- On Security alert click ok to accept certificate.
- After successful test click ok to add endpoint.
- FABRIC GROUPS
- Go to Infrastructure -> Fabric Groups.
- Create "New Fabric Group". Give desired name eg fabricgroup1 and select configurationadmin as fabric administrator. Click ok to create fabricgroup. Wait for 4-5 minutes and again open created fabric group as edit. Clusters should appear. Select clusters to be managed by vra and click ok.
- AD/LDAP INTEGRATION (Optionally)
- If you want users and groups to come from AD go to Administrtion -> Directories Management -> Directories.
- Choose "Add Directory -> Active Directory over LDAP/IWA".
- Use values as follows:
- On "Add directory page":
- Directory Name
- Desired (eg dc.rnd.com)
- Rest all can be left as it is. Typical defaults are:
- Choose
- "Active Directory over LDAP"
- Sync Connector
- vra.rnd.com
- Authentication - Do you want this Connector to also perform authentication?
- Yes
- Directory Search Attribute
- sAMAccuntName
- Base DN
- Desired (Eg cn=users,dc=rnd,dc=com)
- Bind DN
- Desried (Eg cn=administrator,cn=users,dc=rnd,dc=com)
- Bind DN Password
- redacted
- Then click "Test connection to test connection"
- If connection is successful click "Save & Next"
- On "Select the Domains" page select appropriate domains and click next
- On "Map User Attributes" page change only displayName to name. Leave all others as it is and click next.
- On "Select the groups (users) you want to sync page:
- Click "+" on top right corner.
- Type the base DN (eg dc=rnd,dc=com) to find groups to sync by clicking "Find groups" button. The number of groups found would be shown.
- We can select all of them or a selected of them to sync. Eg we can select Administrators, Domain Admins, Users and Domain Users.
- Click save and click next.
- (To search group dn "dsquery group -name "groupname" can be used on cmd on ad server. To list all groups just use "dsquery group").
- On "Select the users you want to sync page":
- Leave administrator as it is. Give dn of all AD users to sync.
- Member of the selected groups need to be added explicitly. To find dn of users on AD server use: dsquery user dc=rnd,dc=com -name "User readable name"
- (Eg dsquery user dc=example,dc=com -name "firstname lastname"). To list all users use "dsquery user" on AD server. The output might get limited to first 100 users.
- Click next once all DNs are added
- On "Review page" verify number of users and groups are being reflected. If numbers are different click "Sync Directory". After a file sync would finish and the latest number of users and groups synced would be shown.
- TENANT CONFIGURATION
- Once AD users are added some of them can be made IAAS and tenant administrator. For that login as administrator and add desried AD users as IAAS or Tenant administrator for vsphere.local tenant.
- MACHINE PREFIXES
- Go to Infrastructure –> Administration –> Machine Prefixes.
- Add a new machine-prefix with desired name (eg gbbrnd), number of digits (eg 3) and next number (eg 1).
- Finally click green right check button to save.
- BUSINESS GROUPS
- Go to Administration -> Users and groups -> Business Group.
- Add a new business group with desired name (Eg rndbg1), manager email id (eg saurabh@rnd.com) and click next.
- Add various group managers (Can manage BG users), support users (Can request items on behalf of other users), shared access role (Can access resources deployed by other users) and user.
- After adding various users into various roles click next.
- Remember to add configurationadmin as Manager for this businessgroup.
- Select "Machine Prefix" created earlier
- Click "Finish" to complete creating Business Group.
- RESERVATIONS
- Go to Infrastructure –> Reservations -> Reservations.
- Click New -> vSphere (vCenter) to add new reservation.
- Choose appropriate values such as:
- Under General:
- Name
- gbbres1
- Tenant
- vsphere.local
- Business group
- gbbgb1
- Priority
- 1
- Enable this reservation
- Checked
- Under Resources:
- Compute Resource
- DC-cluster1
- Machine quota
- Leave unlimited
- Memory
- Desried number (We can give large number than current memory for overprovision)
- Storage
- Select only storages that are available to entire cluster selected under compute resource.
- Do not select Local datastores. Give reservation. The value can be larger than current total for overprovision/future use also.
- Resource Pool
- Leave blank
- Under Network:
- Select Networks that allowed as part of this BG. If network profile is not created so far then option wont appear for selecting network profile for the selected networks. In this case the networks must have external DHCP for IP address assignment and vra will not manage the IPs for the corresponding networks. This is useful when migrating from one stack to VMWare and we want to keep the IPs same. In BlueField deployments we can create network profiles and let vra manage the IPs for us.
- Leave properties and alerts as it is. Click ok to complete creating the reservation.
- SERVICES
- Go to Administration tab –> Catalog Management –> Services.
- Create a new service with desired name (Eg Suse). Other optional items can also be selected. Click ok to create service.
- CUSTOM GROUPS
- By default even Tenant and IAAS administrators have limited options and cannot access Design page to create Blueprints. To give various users "Super administrator" permissions go to Administration -> Users and Groups -> Custom Groups.
- Create New group with desired name (Eg super administrator) and select desired roles (Eg all) and click next.
- Add various tenant and IAAS administrator or other desired users to this group and click ok.
- Do not forget to add "configurationadmin" to this group else configurationadmin also wont be able to publish blueprints.
This is enough as part of one time configuration. Now opertionally create Blueprints, Entitlements, Add blueprints to existing or new services and deploy some blueprints.
Refer:
Home > VMWare platform > vRealize Automation or VMWare Cloud > Configure vRealize Automation 7.3 appliance