What is Azure VMware Solution?
Azure VMware Solution provides you with private clouds that contain VMware vSphere clusters built from dedicated bare-metal Azure infrastructure. Azure VMware Solution is available in Azure Commercial and in Azure Government. The minimum initial deployment is three hosts, but more hosts can be added, up to a maximum of 16 hosts per cluster. All provisioned private clouds have VMware vCenter Server, VMware vSAN, VMware vSphere, and VMware NSX-T Data Center. As a result, you can migrate workloads from your on-premises environments, deploy new virtual machines (VMs), and consume Azure services from your private clouds. For information about the SLA, see the Azure service-level agreements page.
Azure VMware Solution is a VMware validated solution with ongoing validation and testing of enhancements and upgrades. Microsoft manages and maintains the private cloud infrastructure and software. It allows you to focus on developing and running workloads in your private clouds to deliver business value.
The diagram shows the adjacency between private clouds and VNets in Azure, Azure services, and on-premises environments. Network access from private clouds to Azure services or VNets provides SLA-driven integration of Azure service endpoints. ExpressRoute Global Reach connects your on-premises environment to your Azure VMware Solution private cloud.
AV36P and AV52 node sizes available in Azure VMware Solution
The new node sizes increase memory and storage options to optimize your workloads. The gains in performance enable you to do more per server, break storage bottlenecks, and lower transaction costs of latency-sensitive workloads. The availability of the new nodes allows for large latency-sensitive services to be hosted efficiently on the Azure VMware Solution infrastructure.
AV36P key highlights for Memory and Storage optimized Workloads:
- Runs on Intel® Xeon® Gold 6240 Processor with 36 Cores and a Base Frequency of 2.6Ghz and Turbo of 3.9Ghz.
- 768 GB of DRAM Memory
- 19.2 TB Storage Capacity with all NVMe based SSDs
- 1.5TB of NVMe Cache
AV52 key highlights for Memory and Storage optimized Workloads:
- Runs on Intel® Xeon® Platinum 8270 with 52 Cores and a Base Frequency of 2.7Ghz and Turbo of 4.0Ghz.
- 1.5 TB of DRAM Memory
- 38.4TB storage capacity with all NVMe based SSDs
- 1.5TB of NVMe Cache
Hosts, clusters, and private clouds
Azure VMware Solution clusters are based upon hyper-converged infrastructure. The following table shows the CPU, memory, disk and network specifications of the host.
|Host Type||CPU (Cores/GHz)||RAM (GB)||vSAN Cache Tier (TB, raw)||vSAN Capacity Tier (TB, raw)||Network Interface Cards||Regional availability|
|AV36||Dual Intel Xeon Gold 6140 CPUs (Skylake microarchitecture) with 18 cores/CPU @ 2.3 GHz, Total 36 physical cores (72 logical cores with hyperthreading)||576||3.2 (NVMe)||15.20 (SSD)||4x 25 Gb/s NICs (2 for management & control plane, 2 for customer traffic)||All product regions|
|AV36P||Dual Intel Xeon Gold 6240 CPUs (Cascade Lake microarchitecture) with 18 cores/CPU @ 2.6 GHz / 3.9 GHz Turbo, Total 36 physical cores (72 logical cores with hyperthreading)||768||1.5 (Intel Cache)||19.20 (NVMe)||4x 25 Gb/s NICs (2 for management & control plane, 2 for customer traffic)||Selected regions (*)|
|AV52||Dual Intel Xeon Platinum 8270 CPUs (Cascade Lake microarchitecture) with 26 cores/CPU @ 2.7 GHz / 4.0 GHz Turbo, Total 52 physical cores (104 logical cores with hyperthreading)||1,536||1.5 (Intel Cache)||38.40 (NVMe)||4x 25 Gb/s NICs (2 for management & control plane, 2 for customer traffic)||Selected regions (*)|
An Azure VMware Solution cluster requires a minimum number of three hosts. You can only use hosts of the same type in a single Azure VMware Solution private cloud. Hosts used to build or scale clusters come from an isolated pool of hosts. Those hosts have passed hardware tests and have had all data securely deleted before being added to a cluster.
(*) details available via the Azure pricing calculator.
You can deploy new or scale existing private clouds through the Azure portal or Azure CLI.
Azure VMware Solution offers a private cloud environment accessible from on-premises sites and Azure-based resources. Services such as Azure ExpressRoute, VPN connections, or Azure Virtual WAN deliver the connectivity. However, these services require specific network address ranges and firewall ports for enabling the services.
When you deploy a private cloud; private networks for management, provisioning, and vMotion get created. You'll use these private networks to access VMware vCenter Server and VMware NSX-T Data Center NSX-T Manager and virtual machine vMotion or deployment.
ExpressRoute Global Reach is used to connect private clouds to on-premises environments. It connects circuits directly at the Microsoft Enterprise Edge (MSEE) level. The connection requires a virtual network (vNet) with an ExpressRoute circuit to on-premises in your subscription. The reason is that vNet gateways (ExpressRoute Gateways) can't transit traffic, which means you can attach two circuits to the same gateway, but it won't send the traffic from one circuit to the other.
Each Azure VMware Solution environment is its own ExpressRoute region (its own virtual MSEE device), which lets you connect Global Reach to the 'local' peering location. It allows you to connect multiple Azure VMware Solution instances in one region to the same peering location.
For locations where ExpressRoute Global Reach isn't enabled, for example, because of local regulations, you have to build a routing solution using Azure IaaS VMs. For some examples, see Azure Cloud Adoption Framework - Network topology and connectivity for Azure VMware Solution.
Virtual machines deployed on the private cloud are accessible to the internet through the Azure Virtual WAN public IP functionality. For new private clouds, internet access is disabled by default.
For more information, see Networking concepts.
Access and security
Azure VMware Solution private clouds use vSphere role-based access control for enhanced security. You can integrate vSphere SSO LDAP capabilities with Azure Active Directory. For more information, see the Access and Identity concepts page.
vSAN data-at-rest encryption, by default, is enabled and is used to provide vSAN datastore security. For more information, see Storage concepts.
Data Residency and Customer Data
Azure VMware Solution doesn't store customer data.
VMware software versions
The VMware solution software versions used in new deployments of Azure VMware Solution private cloud clusters are:
|VMware vCenter Server||7.0 U3k|
|VMware ESXi||7.0 U3k|
|VMware vSAN||7.0 U3|
|VMware vSAN on-disk format||15|
|VMware NSX-T Data Center
NOTE: VMware NSX-T Data Center Advanced is the only supported version of NSX Data Center.
The current running software version is applied to new clusters added to an existing private cloud.
Host and software lifecycle maintenance
Regular upgrades of the Azure VMware Solution private cloud and VMware software ensure the latest security, stability, and feature sets are running in your private clouds. For more information, see Host maintenance and lifecycle management.
Monitoring your private cloud
Once you’ve deployed Azure VMware Solution into your subscription, Azure Monitor logs are generated automatically.
In your private cloud, you can:
- Collect logs on each of your VMs.
- Download and install the MMA agent on Linux and Windows VMs.
- Enable the Azure diagnostics extension.
- Create and run new queries.
- Run the same queries you usually run on your VMs.
Monitoring patterns inside the Azure VMware Solution are similar to Azure VMs within the IaaS platform. For more information and how-tos, see Monitoring Azure VMs with Azure Monitor.
You can find service issues, planned maintenance, health advisories, and security advisories notifications published through Service Health in the Azure portal. You can take timely actions when you set up activity log alerts for these notifications. For more information, see Create Service Health alerts using the Azure portal.
Azure VMware Solution Responsibility Matrix - Microsoft vs Customer
Azure VMware Solution implements a shared responsibility model that defines distinct roles and responsibilities of the two parties involved in the offering: Customer and Microsoft. The shared role responsibilities are illustrated in more detail in following two tables.
The shared responsibility matrix table shows the high-level responsibilities between a customer and Microsoft for different aspects of the deployment and management of the private cloud and the customer application workloads.
The following table provides a detailed list of roles and responsibilities between the customer and Microsoft, which encompasses the most frequent tasks and definitions. For further questions, contact Microsoft.
|Microsoft - Azure VMware Solution||Physical infrastructure
(optional) VMware HCX deploys with fully configured compute profile on cloud side as add-on
(optional) SRM deploys, upgrade, and scale up/down
Support - SDDC platforms and VMware HCX
|Customer||Request Azure VMware Solution host quote with Microsoft
Plan and create a request for SDDCs on Azure portal with:
Add or delete hosts requests to cluster from Portal
Deploy/lifecycle management of partner (third party) solutions
|Partner ecosystem||Support for their product/solution. For reference, the following are some of the supported Azure VMware Solution partner solution/product:
The next step is to learn key private cloud and cluster concepts.