VMware Cloud Foundation 9.1.1 is now available

VMware Cloud Foundation 9.1.1.0 is now generally available. This is a maintenance release where the features it delivers are mostly focused on improving the supportability of the product.
Release notes: VMware Cloud Foundation 9.1.1.0 Release Notes
Per-component release notes are published for vCenter, ESX, vSAN, NSX, VCF Installer, VCF Operations, and VCF Automation, all at 9.1.1.0.
Getting to VCF 9.1.1.0
The release notes set out the order in which components are patched. You begin applying the 9.1.1.0 maintenance release in your 9.1.0.x environment by patching the VCF management services fleet lifecycle component to 9.1.1.0 before any other VCF component.
After that, the remaining components can be patched simultaneously, with a few dependencies to observe:
- Patching the software depot blocks the patching of other components.
- The identity broker requires the runtime to be patched first.
- Salt RaaS requires the runtime to be patched first.
- The migration service engine requires VCF Automation to be patched first.
The complete details are in the Getting to VCF 9.1.1.0 section of the release notes — worth reading in full before you begin.
VCF Automation 9.1.1
Release notes: VCF Automation 9.1.1.0 Release Notes
What's new
The headline item is support for VLAN-backed VPCs consumed through VCF Automation. Traffic flows directly on physical VLANs without overlay encapsulation. Note the limitation: this model does not support Private networks, because the IP scheme is tied to the physical VLAN CIDRs.
Resolved issues worth knowing
Provider Management
- Storage classes containing datastore clusters reported incorrect total capacity in regions — the vCenter listener was ignoring storage pod events, so the datastore table never got populated.
- Region quota update tasks failed with a generic exception when stale or missing content libraries were detected. The error never told you which library was at fault.
Organization Management
- Saving a VCF cloud account associated with a deleted NSX cloud account failed with "Failed to find associated internal NSX account for VCF." This one was nastier than it looks — deleting a shared NSX account that multiple VCF accounts were still using removed it anyway, corrupting data on the accounts left behind.
VCF Services Runtime (shared with VCF Operations)
- Upgrades from 9.0 to 9.1 could freeze at the backup stage for up to 120 minutes showing only a generic timeout. It now fails fast with a clear error.
- Mixed-case hostnames and FQDNs caused install, upgrade, and import failures due to case-sensitive DNS and certificate matching. Mixed case is now supported.
- Services sometimes failed to resume after a cluster power-on and needed manual recovery. They now recover automatically.
- Fluentd log buffers and backup chunks accumulated until the logging disk filled and health checks failed.
Known issues to plan around
Upgrade — two items to check before you start:
- Custom profiles cause upgrade failure. Custom configuration overlays from 9.0.1, 9.0.2.x, or 9.1.0.x will block the upgrade due to artifact incompatibility. Follow Broadcom KB 451147.
- Upgrade fails with an internal error during DNS resolution, surfacing as
VirtualMachineNotFound. Restart the automation services and confirm stable DNS resolution; if it persists, work through KB 441333 before retrying.
Provider Management
- Subscribed content library sync and creation both fail with HTTP 401 against password-protected vCenter content libraries. For creation there is a workaround — remove the password protection first. For sync of an already-subscribed library, there is none.
- Deleting a region quota that existed before a 9.0.x → 9.1.1 upgrade fails and the quota stays visible. Storage class config migrates to the new format but the old copy lingers and conflicts. No workaround. Quotas created after the upgrade are fine.
- The vksm service installation fails post-upgrade if a previous version was left incompletely uninstalled. Clean up through Provider Management (Uninstall, then Delete) before reinstalling.
- Region creation fails intermittently on VLAN-backed network stacks with "Following zones of the specified supervisors don't have a network stack configured," caused by incomplete NSX population. Refresh the vCenter connection (UI, or POST with an empty payload to the refresh endpoint) and retry.
- A newly created VM class is not visible in Provider Management in mixed-tenancy environments unless the Mixed Tenancy Mode feature flag is enabled.
- vCenter is wrongly listed as Licensed while in evaluation mode. Trust the warning banner, not the Connections page, and license before the evaluation expires.
Organization Management
- Clicking a pod name under Kubernetes Management shows a blank page. Workaround is to append
/plus the namespace name to the URL. - Saving a valid network profile or cloud zone in VM Apps organizations pops an unexpected Discard Changes dialog. Click Discard and navigate back — the resource was actually created.
VCF Operations 9.1.1
Release notes: VCF Operations 9.1.1.0 Release Notes
VCF Operations gets the bulk of the changes in this release, and most of it lands in password and certificate management.
What's new
Operate
- SDDC Manager log configuration — log collection across all VCF components is now fully managed within VCF Operations, with filtering and volume control.
- Cloud proxy outbound proxy settings — you can route external traffic through a dedicated proxy when deploying the cloud proxy OVA.
- VMware Salt for VCF Components API — programmatic management of configuration across the stack using native Salt constructs.
Manage
- On-demand Active Directory lookup — real-time user and group search, with authentication based on current group membership at login.
- VCF roles enhancement — starting with vCenter 9.1.1.0, the VCF admin role and any custom VCF role including the vCenter admin role are automatically mapped to the local vCenter Administrators group.
- Expanded password management — now covers vCenter SSO, SDDC Manager root/admin and vcf accounts; supports password policy for VCF Automation and networks components; shows last password update dates and account lockout status; can update passwords on locked or expired accounts; and keeps a full audit trail. Note that the component's own UI becomes read-only once VCF Operations manages it.
- Expanded certificate management — now covers NSX (all appliances), cloud proxy, license server, collector nodes, STS, vSphere Supervisor, vSAN storage, and VCF Automation. You can replace with VMCA-signed certificates without an external CA, auto-replace expiring certificates without SSH access, and raise expiry alarms across all components.
- Tag management APIs across fleets, license server IPv6 support (static, DHCPv6, SLAAC), and improved licensing error messages.
- SAML SP metadata update — identity broker 9.1.1.0 adds an EncryptionMethod hint signaling RSA-OAEP with SHA-256 for assertion encryption. Re-importing SP metadata into your IdP is recommended.
Resolved issues worth knowing
Operate
- vCenter cloud account creation using the default collector group failed with an unhandled error when any collector in the group was offline.
- The UI failed to load when NTP was not synchronized.
- Telegraf agent content upgrade intermittently showed Failed despite succeeding, when the Salt minion went offline during a swap on HA collector groups.
- Windows agents reported unhealthy on non-English locales (Unicode decoding on service names), and intermittently due to a race collecting per-process CPU stats for exiting processes.
- Git sync, check-in, and check-out for configuration templates failed after a service restart.
- SuiteAPI
PUTon an application monitoring service failed with "Configuration already used" despite no real conflict. - Report generation threw an exception on characters with no glyph in the chosen font, and metric colorization did not render in PDF exports.
- The sticky bit was not set on temporary directories created by the
yarnuser, allowing any user to delete them.
Manage — mostly cost and licensing accuracy fixes:
- Host, socket, and core counts were doubled when a vCenter had multiple v8 license keys from the same product family.
- Removed license mappings kept contributing to the Monthly Host OS License Total Cost metric.
- ELA fixed costs were not applied to hosts during cost calculation.
- The Cluster CPU Base Rate used total capacity instead of usable capacity when "Cluster Usable Capacity after HA and Buffer" was selected.
- Cost calculation failed across a multi-data-center Standard Topology if any data center sat in a
Nonestate. - Windows Server 2025 VMs were miscategorized under "Others" instead of "Windows 2016 or later."
- API calls allowed VCF single sign-on configuration on vCenter and NSX instances already managed by a different VCF Operations instance. Eligibility checks were added.
- VCF adapter creation failed with a "Duplicate Key" error when CERTIFICATE_AUTHORITY type certificates were imported.
Known issues to plan around
The certificate-related ones are the cluster to watch, given how much certificate management expanded in this release.
Certificates
- Replace with VMCA fails when the CSR contains wildcard SAN entries — "Failed to generate certificate from CSR." Use an external CA, or provide every SAN FQDN explicitly with no wildcards.
- Certificate operations fail with "Unable to find end point" after a collector changes (load balancing or user-initiated) until the next VIM adapter collection. Workaround is to run Start Maintenance → wait 10 seconds → End Maintenance on each VMware Infrastructure Management adapter instance.
- NSX bulk certificate replacement fails with "Unable to obtain CSR ID from NSX" when the VIP is replaced before the cluster node in upgraded multi-node environments. Retry the failed component.
- Trust is not re-established after replacing a certificate on a VCF management component until the next inventory sync, so dependent tasks and inventory views fail in the meantime. Temporarily set
ops.platform.sync.cronto0 0 * * * *in the fleet build service, then revert to@daily. - Replacing the SSL certificate on an 8.x vCenter breaks trust and makes the SDDC Manager UI inaccessible with a truststore error. See KB 316056.
- vSphere Supervisor adapter stops collecting after a vCenter Machine SSL rotation and can move to Not Existing. Best practice: stop the Supervisor adapter before rotating, rotate, confirm the vCenter adapter is collecting, then start it again.
Deployment and upgrade
- Scaling VCF management services from Small to Small (HA) fails with "An error occurred while updating config" when Fleet Lifecycle is on 9.1.1 but SDDC Lifecycle is still on 9.1.0. Upgrade both before scaling, or scale to Medium/Large.
- Do not install Real-time Metrics, Log Management, and Operations for Networks in parallel — Real-time Metrics fails and the Networks install appears stuck for 3+ hours before failing. Install sequentially.
- Extra-large vCenter onboarding may hit a 504 Gateway Timeout on environments with 2,000+ hosts and 30,000+ VMs. Retry the Deploy operation, or fall back to the fleet management APIs (Validation then Import).
- The Small deployment size is missing from the HA selector in the deferred-components workflow. Use JSON input with the Small appliance size, or deploy Small as simple and add a replica afterward.
- Deploying to a VSP cluster using the VCF Operations load balancer FQDN fails; supply the master node hostname instead.
- A secondary VCF Instance deployed at a newer version than the existing VCF Operations instance will not show its SDDC Manager as a VCF adapter, because the cloud proxy fails to register. Match the versions.
HCX — several migration issues cluster around the 9.1.1.0 upgrade:
- OSAM migrations fail if HCX Manager is upgraded mid-migration. Complete in-progress migrations first and get the whole ecosystem — Manager, Interconnects, Sentinel agents — to 9.1.1.0.
- Pending or new Bulk and RAV migrations may fail after the Manager upgrade due to a certificate validation mismatch. Complete them before upgrading, then upgrade or redeploy the photon-based service mesh immediately.
- Data plane appliances stop sending logs to syslog after upgrading to 9.1.1.0+. Redeploy or update them.
- The
VMware.VimAutomation.HcxPowerCLI module shipped in all versions of VCF.PowerCLI is not compatible with HCX 9 — it only works with HCX 4.11.
Stretched clusters (applies to both Operations and Automation)
- Platform nodes deployed as a Day-N operation are not automatically added to AZ1 DRS host-affinity rules. Move them manually.
- Day-N deployment and scale-out operations fail after node VMs are relocated by vMotion to a new resource pool. Do not move these VMs; if they have already been moved, contact Broadcom Support to reconcile placement.
My take
If you are running 9.1.0.x, this is a nice maintenance release to pick up. The fixes around the upgrade backup stage, mixed-case FQDN handling, and services resuming after a power-on all make day-to-day operations smoother, and the expanded password and certificate management in VCF Operations is the most useful new capability here.
As with any upgrade, give the release notes a read first — the patching order, the VCF Automation upgrade notes, and the HCX section are the ones to look over for your environment.
Never miss a post
New guides on VMware Cloud Foundation, Aria Suite, and infrastructure automation. Follow along in your feed reader and new posts show up as soon as they are published.
Subscribe via RSS