Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • VMware vRealize Orchestrator Cookbook
  • Toc
  • feedback
VMware vRealize Orchestrator Cookbook

VMware vRealize Orchestrator Cookbook

By : Langenhan
4.3 (10)
close
VMware vRealize Orchestrator Cookbook

VMware vRealize Orchestrator Cookbook

4.3 (10)
By: Langenhan

Overview of this book

If you are a VMware administrator who is interested in automating your infrastructure, this book is for you. An understanding of basic programming concepts is advised. No previous knowledge of Orchestrator is required, although some previous knowledge of it will allow you to get started more easily.
Table of Contents (9 chapters)
close
8
Index

Integrating Orchestrator into SSO and vSphere Web Client

Integrating Orchestrator into the vCenter Web Client enables vCenter Server users to directly run Orchestrator workflows just by right-clicking vCenter objects. The vRA-integrated Orchestrator is already configured with the SSO that vRA uses.

Getting ready

vCO 5.5 (and higher) requires an SSO server 5.5, as it won't work with an SSO 5.1 server.

We need an up-and-running Orchestrator as well as access to vCenter Web Client.

Make sure that you set the Orchestrator Network configuration (see the Configuring the network section in the Important Orchestrator base configurations recipe)

You should be comfortable with using one of the methods described in the Two ways to configure Orchestrator recipe.

You should have an AD group for your vCOAdministrators with at least one user in it. You can use the precreated SSO group [email protected]. The account [email protected] is a member of this group.

How to do it...

Again both configuration methods are shown. Choose the one you're most comfortable with.

Registering Orchestrator with SSO

If you are using the Orchestrator installation that came with vCenter, you can skip this step.

Using the Orchestrator Configuration tool

  1. Open the Orchestrator Configuration tool.
  2. Click on the Network section and then on SSL Trust Manager.
  3. Enter [IP or FQDN of SSO server]:7444 as the URL and click on Import.
  4. Acknowledge the import by clicking on Import.
  5. Repeat steps 2 to 4 and register the SSL certificate for vCenter with port 443.
  6. Click on the Authentication section.
  7. Select the authentication mode as SSO Authentication.
  8. Enter the SSO server FQDN.
  9. Enter an SSO administrative user (for example, [email protected]).
  10. Click on Register Orchestrator.
    Using the Orchestrator Configuration tool
  11. This registration registers a new application user in SSO.
  12. Select from the drop-down menu the group you would like to use for Orchestrator administrators.
  13. Click on Accept Orchestrator Configuration.
    Using the Orchestrator Configuration tool

Using the workflow

  1. Open the Orchestrator Client.
  2. Navigate to Library | Configuration | SSL Trust Manager.
  3. Right-click on the Import a certificate from URL workflow and select Start Workflow.
  4. Enter [IP or FQDN of SSO server]:7444 as the URL.
  5. Select Yes to accept the SSL Certificate even if there are warnings and click on Submit.
  6. Wait till the workflow has successfully finished.
  7. Navigate to Library | Configuration | Authentication | SSO.
  8. Right-click on the workflow Configure SSO and select Start Workflow.
  9. Enter [IP or FQDN of SSO server]:7444 as the URL.
  10. Enter an SSO administrative user (for example, [email protected]).
  11. Enter the SSO Admin Group (ignore if it says domain/group). The existing SSO default group is called VCOAdministrators (case-sensitive).
  12. Click on Submit and wait until the workflow is completed successfully.
    Using the workflow

Configuring the vCenter Server plugin

The integration of Orchestrator with vCenter Web Client requires us to also configure the vCenter Server plugin.

Using the Orchestrator Configuration tool

  1. Open the Orchestrator Configuration tool.
  2. Click on the vCenter Server plugin.
  3. Click on New vCenter Server Host.
  4. Enter your vCenter FQDN.
  5. If you are using Windows, you can define a domain; the Linux appliance doesn't have this selection. You can leave it empty.
  6. Enter a vCenter Server administrative user and click on Apply changes.
    Using the Orchestrator Configuration tool

Using the workflow

  1. Open Orchestrator Client.
  2. Navigate to Library | vCenter | Configuration.
  3. Right-click on the Add a vCenter Server instance workflow and select Start Workflow.
  4. Enter your vCenter FQDN.
  5. Select that you would like to orchestrate this instance as well and that you would like to accept SSL certificates even if they are self-signed.
  6. Click on Next.
  7. Enter a vCenter Server administrative user and the password.
  8. You can define a domain name, or leave it empty. Click on Submit.
    Using the workflow

Wait until the workflow is successfully finished.

Configuring the connection between vCenter Server and Orchestrator

In the Web Client only one Orchestrator Server can be paired to each vCenter Server. To configure the pairing, follow these steps:

  1. Open vSphere Web Client.
  2. Click on vCenter Orchestrator and then on Manage.
  3. Mark vCenter Server and click on Edit Configuration.
  4. The server that you have integrated should show up in the Registered as VC extension selection. If this is not the case, you can try to enter its FQDN or IP.
  5. Click on Test Connection and make sure it works. If it doesn't, this indicates that the integration hasn't worked correctly.
  6. Click on OK.
    Configuring the connection between vCenter Server and Orchestrator

How it works...

Since vCenter Server 5.1, vSphere Web Client is (or better, should be) the main method for accessing vCenter. Orchestrator completely integrates with vSphere Web Client, making it possible for Orchestrator workflows to be executed directly from vSphere Web Client.

How it works...

You can configure which workflows can be run from the vSphere Web Client. We will discuss this configuration in detail in the Orchestrator and vSphere Web Client recipe in Chapter 5, Basic Orchestrator Operations.

Using SSO for Orchestrator login requires that you log in into Orchestrator Client or vSphere Web Client using a user that is a member of the group you defined as vCOAdmins. If you used the [email protected] group, you can add other SSO and AD groups or users to this group via the SSO group membership configuration.

How it works...

See also

To learn more about Orchestrator user management, see the User management recipe in Chapter 5, Basic Orchestrator Operations.

To configure Orchestrator workflows in vSphere Web Client, see the Orchestrator and vSphere Web Client recipe in Chapter 5, Basic Orchestrator Operations.

bookmark search playlist font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete