VMware’s vSphere 6.0: Faster, smarter, more resilient

Reviews
Jun 1, 20158 mins

fast speed
Credit: Shutterstock

VMware’s vSphere 6 pays more attention to high availability and large deployment than prior editions—with a kick to the throttle in terms of overall speed of scale, not just size of scale. This comes with a mixture of incremental upgrades, and a bit of administrative thoughtfulness.

This latest cut of VMware is almost finger-snappy fast. What really got our attention, however, is that it understands faults, more of them, more quickly, with more options. It also doesn’t require manually installing everything. It’s not completely perfect, but the defects were minor.

Were we to offer a single reason to plunk down upgrade money, it would be the advent of high availability and fault tolerance failover options plus the enhanced speed over VMware 5.

+ ALSO ON NETWORK WORLD Citrix edges VMware, Microsoft in VDI face-off +

It’s now also designed to move VMs a long distance, out of the data center if need be, via vMotion without worry. This means that transfers are more flexible, provided you have reasonable bandwidth and pipes. Our transcontinental test using broadband from California to our hosted data center in Indiana worked four times out of five over less-than-optimum connectivity.

What you get

The first deliverable is homogenous payload rather than Lego pieces. No longer is it necessary to install vCenter, vCenter Web Client, and the host ESXi base hypervisor individually. It just does it. Boom. No need to manually provision separate tenants or clusters, which saves time.

Upgrades will search for existing infrastructure before overwriting, but you’ll want the new stuff, which is compatible back to VMware 5.1. This takes less time, we feel, even though our hardware platforms are under seemingly constant speed updates. Don’t go earlier than 5.X to upgrade without consulting what will need to be changed.

A small complaint: When we deployed on HP blades, it was unreasonably difficult to find the right ISOs and payloads to make it work on our HP Gen8/9 hardware. Apparently, HP server hardware requires custom drivers not found in the omnibus vSphere 6.0 payload.

VMware combines its Single Sign-On (SSO) into the Platform Services Controller (PSC) as an appliance, subsuming the SSO in an upgrade. As a part of the overall strategy to improve speed in smaller installations, the PSC can also be combined into a single VM appliance.

It works. Inside the combined appliance is the entire nexus for licensing, SSO, and the Holy Grail, a VMware CA. The Certificate Authority, which can be root or subsidiary, is a luxury. Prior editions that relied on outside certificate authorities, and or the auspices of Microsoft’s certificate authorities, could drive IT admins somewhat insane, especially in highly dynamic or multi-tenant infrastructures. It led us, and others, to avoid using external certificate authorities with VMware. It’s much easier now and makes SSO so much the better.

VSphere 6 also contains a revised content catalog of templates and images. It permits a central repository of checked/authenticated images that allows replication (for geographically dispersed locales) that can be throttled according to bandwidth needs (e.g., replication can be timed for off hours).

This has replaced the internal NFS share that was wonky to use. We need to praise this for several reasons, as prior repositories were difficult to use, and the chain of authorities needed for highly dynamic scale-outs—needed to guarantee safe VM builds—must be mandatory.

Systems security demands the capacity to know your source materials are safe, and up to specific build/patch levels, prior to these builds being deployed. The repositories are designed for multiple geographically disperse locations, and synched when bandwidth is available, perhaps in planned or available temporal lulls in activity.

Other OS and hypervisor platform makers have had a handle on this for a while, but VMware’s caught up, and when used in conjunction with the aforementioned CA services, it’s almost pain-free, even when using the certificate authority as a subsidiary CA to another root. Well done, and even more important when VMware soon starts to support container services, which need local image repository libraries for rapid container image sources. Scale will suffer without it.

Testing

Long distance vMotion was the largest part of the agenda, but installation was a fascinating departure. The certificate authority setup takes a while, but needs to be done only once. We set the certificate authority as a root, and in that capacity, our troubles were few. Although we didn’t test Horizon View, which has optional heavy integration with a certificate authority, we were pleased in its simplicity. You need to understand certificates first, and we do, making this a comparative breeze.

We setup a simple Samsung notebook as a server behind a Comcast broadband connection in Berkeley, Calif., then used this as our circuit to our NOC at Expedient in Indianapolis/Carmel, Ind. The initial VM we used was a Windows 2012 R2/updates server running SQL Server Light.

We used an IPSec VPN connection between sites as the baseline, Layer 2 circuit, which took more time to setup than the VMware vCenter link between the two hosts. The vMotion took an average of 208 seconds across the link. Back/forth traffic was about the same with little variance, done during the daytime.

The server size was admittedly small (4G of memory, 1vCPU, 30GB disk) in our first trial. In our second trial, we increased the size to a VM using 8GB, 2vCPU (you can use up to four vCPUs in VMware 6.0, something new) and a 40GB disk; this only increased the time for a server transfer by about 40 seconds, and while this seemed non-linear, results were consistent.

The conclusion is that moving VMs between data centers using vMotion appears less prone to latency issues, and while we didn’t move them transcontinentally, we note that there were no surprises or warnings, and the VM still lives, updating and erasing a record, weeks after the test. Jitter –perhaps dreaded Netflix traffic —prevented one transfer, and it simply died, allowing us to do a retry, which succeeded.

What’s missing

We found no serious updates to the vSwitching fabric. There are new business partners found in VMware’s cadre of software add-on/in wares, but these weren’t tested. HP had not updated its vCenter add-in at press time and so we weren’t able to test depth of control plane and fault management with the HP servers in our NOC. There is no localized, in place, encrypted storage options, but such things are left to third-party providers.

We’d like to see one image set, and recipes for miniscule settings needed for various hardware hosts and storage components. There’s enough variety these days that the devil of details regarding specific models, or general settings mandated to make things work well, be listed clearly.

Summary

It’s faster, it scales, it’s easier to deploy, it’s snappier, and seems to address a wishlist of small sins. Attention to the actual worklife of systems engineers has given a smoother flow and feel, not to mention consolidated payloads, and removing the time between UI refreshes. The real value, however, is more astute failover and high-availability controls. The repository is just icing on the cake.

How We Tested vSphere 6.0

We installed VMware ISOs as a fresh installation or upgrade into several hosts, including Lenovo RD630s and RD660s as well as HP DL 560 G8 and HP BL-660 Gen8 and BL-640 Gen9 blades. We also installed into a Samsung NP470RSE notebook (16GB, 750GB disk, GBE, Core i7) and used Xfinity broadband connections to test long-distance vMotion between a small business installation and our core NOC at Expedient in Carmel/Indianapolis, Ind.,—a high performance cable, not fiber, interface. We moved VMs 5x in each direction for each of two tests.

We also deployed VMware’s repository and populated with test ISO images onto a VM that booted onto our SAN. We deployed the VMware CA as a root Certificate Authority, and did not connect it to our root certificate, as we discovered (oops) it’s expired.

NOC components were connected via our 10Gigiabit Ethernet Extreme Summit Series L2/L3 switch backplane to Expedient’s core routers or our 4GB Fibre Channel switch to FC resources in our ancient Compellent SAN (which also houses iSCSI connectivity).

Web interface to resources, primarily updates to VMware vCenter, were noticeably much faster than the VMware 5.5 versions. We didn’t time them, just enjoyed them and became used to them to the extent that we noticed the 5.5 version crawled, by comparison.

Tom Henderson runs ExtremeLabs, in Bloomington, Ind. He can be reached at kitchen-sink@extremelabs.com.