VCF Automation and Self-Service Consumption in VCF 9.1 A Day 0/1/2 Field Guide

Self-service is what application teams expect from a private cloud now. VCF Automation in 9.1 makes that real if you architect the tenancy model, quotas, and Infrastructure Policies correctly. Here’s

Share

Self-service is no longer a differentiator for a private cloud; it’s the baseline expectation. Application teams expect to provision a VM, a Kubernetes cluster, a network segment, or an object storage bucket without raising a ticket. VCF Automation in 9.1 delivers that experience if the underlying tenancy model, quotas, and Infrastructure Policies are architected correctly.

A Broadcom customer survey (March 2026, n=44) found organisations using VCF Automation cut time-from-request to ready-to-use environment by 49%, and reduced manual effort per application lifecycle by 49%. VCF 9.1 builds on that with new capabilities: Infrastructure Policies, network mutability, snapshots, VM Groups, region quota mechanics, and tenant cost visibility. This piece walks through Day 0/1/2 for VCF Automation.

Day 0 Designing the Tenancy and Consumption Model

The Day 0 design decisions for VCF Automation revolve around tenancy specifically, who consumes what, with which guardrails, and how cost flows.

• Organisation → Region → Zone model the VCF Automation tenancy hierarchy. Organisations represent tenants (business units, customers, environments). Regions map to physical locations. Zones map to clusters or vSphere zones. Design this hierarchy with the operational model in mind.

• Region quota allocation VCF 9.1 introduces fully allocated region quota (100% of region to a tenant) plus zonal-specific allocations. Decide whether tenants get whole regions or zonal slices.

• Infrastructure Policies VM-Host affinity rules expressed at the VCF Automation layer that bridge to vSphere Compute Policies in vCenter. Use for license optimisation (e.g. Windows workloads pinned to specific hosts), regulatory compliance (data residency), and tenant isolation.

• Self-service blueprint catalog VM Service, Container Service (CaaS), Kubernetes Service (VKS). Decide which is exposed to which tenant role.

• Cost model tenant-visible cost data is a VCF 9.1 enhancement. Decide whether tenants see infrastructure cost (showback) or are billed (chargeback). Build the model at Day 0.

Infrastructure Policies are the architectural lever that most customers miss at Day 0. They allow administrators to dynamically govern VM placement pinning Windows workloads to specific hosts for licence optimisation, ensuring data sovereignty by pinning EU workloads to EU-region hosts, isolating regulated workloads to specific clusters. The policy is enforced continuously; if a VM’s attributes change to match a different policy, VCF Automation will migrate it. Design the policy catalogue at Day 0 alongside the tenancy hierarchy.

Day 1 Deploying VCF Automation

VCF Automation is deployed as part of the VCF Installer workflow alongside vSphere, NSX, and VCF Operations. The Day 1 deployment is straightforward, but tenancy onboarding is where architects spend time.

• Deploy 3× VCF Automation HA cluster within the Management Domain. Sizing follows the Planning and Preparation Workbook.

• Configure VCF Operations integration VCF Automation pulls capacity and cost data from VCF Operations; the integration is mandatory.

• Configure Identity Broker federation tenant users authenticate via federated SSO. Per-tenant IdP federation is supported for MSP patterns.

• Create the first Organisation → Region → Zone hierarchy start with one tenant, validate the consumption flow, then scale out.

• Build the Infrastructure Policy catalog in vCenter, create the underlying VM-Host affinity Compute Policies (using host tags). In VCF Automation, create the Infrastructure Policies referencing them via the Criteria Builder (e.g. GuestOSFamily IS_EQUAL “Linux”).

• Apply policies to region quotas mandatory policies can only be applied to region quotas without existing namespaces, so do this before tenant onboarding.

• Onboard tenants create Organisation, assign region quota, attach optional policies, expose blueprint catalog.

Network mutability is a key Day 1 enabler in VCF 9.1: consumers can independently modify CPU, memory, storage, and network configurations post-deployment, including network changes, snapshots, and VM Groups. This eliminates the administrative bottleneck of “IT modifies the VM on tenant’s behalf.” Configure the relevant tenant role permissions Day 1 so consumers have the autonomy without requiring escalation.

Self-service networking deployment at Day 1: VCF 9.1 enables tenants to independently pre-allocate IP addresses (with multiple CIDR support, Infoblox integration), configure VPN deployment, expose private networks, and deploy Gateway Firewalls. Architect the network self-service boundary explicitly what tenants can do without IT touch, and what still requires platform team review.

Day 2 Operating Self-Service at Scale

Day 2 operations of VCF Automation are about continuous governance and the steady cadence of tenant onboarding, capacity adjustment, and policy evolution.

Continuous Policy Evaluation

VCF Automation evaluates infrastructure policies continuously. If a VM’s attributes change (e.g. an Infrastructure Policy assignment), the system ensures the workload remains compliant with placement rules migrating it if necessary. For Day 2 operations, this means policy compliance is a background process, not a periodic audit. The architect should provide an exception process for the rare cases where a policy needs override.

Tenant Cost Awareness

VCF 9.1 enables consumers to view costs associated with their deployed resources. Admins receive proactive email notifications without manually monitoring the system. The cultural shift is significant: tenants who can see their own cost become self-regulating. Make sure cost visibility is enabled for tenants at Day 1; expecting cost-aware behaviour at Day 365 without exposing the data is wishful thinking.

Day 2 Modifications and Lifecycle

Consumers can independently modify CPU, memory, storage, and network configurations post-deployment, plus snapshots and VM Groups. This shifts the operations team’s attention from “ticket processing” to “platform health.” The operational rhythm becomes: monitor capacity, evolve the blueprint catalogue, adjust Infrastructure Policies as workload patterns shift, refine the quota model based on actual consumption.

Quota and Allocation Evolution

Region quota mechanics in VCF 9.1 allow admins to add reservations or reduce quota from the full region to specific limits on Day 2. This makes the tenancy model elastic a tenant can start with broad allocation and tighten as workloads mature, or vice versa. The architect should provide a quarterly capacity-versus-quota review process; many customers leave this implicit and end up with stranded capacity.

The maturity end-state is platform-as-product. The VCF Automation deployment evolves; tenants self-serve within guardrails; the platform team focuses on capability evolution rather than ticket processing. Customers that get this right report the 49% time-to-environment improvement Broadcom’s March 2026 survey identified. Customers that bolt automation onto a non-tenanted operating model see much less benefit.

Architect’s Takeaway

VCF Automation in VCF 9.1 is the platform layer that turns infrastructure into self-service product. The architectural decisions that matter tenancy hierarchy, Infrastructure Policies, region quota allocation, cost visibility are all Day 0 decisions. Day 1 deployment is straightforward; tenant onboarding is the work. Day 2 operations should be steady-state platform evolution, not ticket processing. The customers seeing the 49% improvement are the ones who treated VCF Automation as a product platform rather than a provisioning tool. Architect it that way from Day 0 and the operational dividend compounds.

Sources

Broadcom Accelerate, Streamline, and Control Your Self-Service Private Cloud with VCF 9.1

Broadcom Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1

Broadcom VMware Cloud Foundation Automation: Consume and Deploy VMs and Kubernetes Clusters

Broadcom VCF 9.1: The Secure, Cost-Effective Private Cloud Platform for Production AI

Broadcom Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience