<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://leecox.pro/feed.xml" rel="self" type="application/atom+xml" /><link href="https://leecox.pro/" rel="alternate" type="text/html" /><updated>2026-08-09T03:05:47-05:00</updated><id>https://leecox.pro/feed.xml</id><title type="html">Lee Cox</title><subtitle>Cloud migration, AI infrastructure, OS engineering, and the occasional dragon — from the workbench of a principal enterprise architect.</subtitle><author><name>Lee Cox</name></author><entry><title type="html">The factory tow hitch Tesla says doesn’t exist</title><link href="https://leecox.pro/garage/the-factory-tow-hitch-tesla-says-doesnt-exist/" rel="alternate" type="text/html" title="The factory tow hitch Tesla says doesn’t exist" /><published>2026-08-09T00:05:00-05:00</published><updated>2026-08-09T00:05:00-05:00</updated><id>https://leecox.pro/garage/the-factory-tow-hitch-tesla-says-doesnt-exist</id><content type="html" xml:base="https://leecox.pro/garage/the-factory-tow-hitch-tesla-says-doesnt-exist/"><![CDATA[<p>This one started at a Tesla service center in 2023, when I asked about
adding the factory tow package to my 2021 Model S and was told, in
person, that they had the parts and the procedure but hadn’t been given
clearance to install a hitch on the Model S. A year into it, a service
advisor gave me the blunter version, with a straight face: “Model S
doesn’t support a tow hitch.”</p>

<p>Which is interesting, because the Model S service manual contains the
retrofit instructions. The parts catalog contains the hitch. The SOP16
wiring schematics contain a complete trailer circuit. Europe gets the
hitch as an option. What Tesla means is <em>“we’d rather not”</em> — and
“we’d rather not” is not a wiring diagram. So began a quest that’s
coming up on three years, and since I documented the whole thing across a
long-running forum thread as it happened, this post is the assembled
story. Fair warning: there are part numbers ahead. That’s the good part.</p>

<h2 id="the-archaeology">The archaeology</h2>

<p>The Model S left-hand body harness is the nervous system of the car’s
whole left side, and it’s where the factory tow wiring lives — when it
lives anywhere. Digging through the parts catalog turned up six harness
variants, and three of them carry the designation that matters: <strong>TW01</strong>,
the towing electrical connector in the SOP16 schematics.</p>

<table>
  <thead>
    <tr>
      <th>Part</th>
      <th>My read</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>2486394-00-C</td>
      <td>HW3 harness, no tow</td>
    </tr>
    <tr>
      <td>2486394-01-C</td>
      <td>HW3 with TW01 — likely the Rev1 “two connector” tow wiring</td>
    </tr>
    <tr>
      <td>2486394-71-C</td>
      <td>HW3 with TW01 — likely the Rev2 “single connector” version</td>
    </tr>
    <tr>
      <td>2486394-00-D / -01-D</td>
      <td>The HW4 equivalents</td>
    </tr>
    <tr>
      <td>3486394-01-B</td>
      <td>The Plaid harness, no tie-breaker listed</td>
    </tr>
  </tbody>
</table>

<p>Rev1 versus Rev2 matters: Tesla changed the hitch’s electrical interface
mid-life. The service documentation spells it out once you know to look —
hitch part numbers <strong>J and above are Rev2; H and below are Rev1.</strong> If you
ever buy one of these off eBay, ignore the model year in the listing and
read the suffix. That one sentence has already saved at least one person
I’ve corresponded with from buying the wrong revision.</p>

<h2 id="the-part-that-ships-but-doesnt-exist">The part that ships but doesn’t exist</h2>

<p>Armed with the numbers, I did the obvious thing: ordered both HW3 TW01
harnesses and let Tesla’s parts system tell me the truth.</p>

<p>The <strong>-71-C never shipped.</strong> Months of waiting, then nothing. The
<strong>-01-C did ship</strong> — six months of waiting, and when I opened the box,
it was a -00-C wearing a -01-C label. The tow wiring and connectors
simply weren’t in it. My best guess: there was a plan to support harness
retrofits, somebody killed it late, and the part numbers survived while
the actual copper didn’t. At this point my standing advice is blunt:
<strong>if you want the factory tow harness, you’re pulling it off a wreck.</strong></p>

<h2 id="unicorn-hunting">Unicorn hunting</h2>

<p>Here’s where it gets fun. While chasing paperwork, I found evidence that
some cars <em>left the factory with the tow wiring installed</em> — an early
Plaid whose owner needed nothing but the Rev1 hitch itself, bolt-on and
program. There appear to be more unicorns out there in North America.</p>

<p>The five-minute check if you own a Palladium S: pop the driver’s sill
trim and look in the bottom front corner, next to the left-hand body
controller. If there’s a trailer-brake-controller plug and wiring
sitting there unused, congratulations — you’re holding a winning lottery
ticket Tesla never told you about.</p>

<p>And the software side confirms the car is willing: I set the trailer
configuration on my own 2021 LR through a Toolbox session. No errors.
The car <em>knows how</em> to tow. It’s the copper that’s missing.</p>

<h2 id="the-build">The build</h2>

<p>So: no orderable harness, a proprietary Tesla-specific controller
connector on the S/X side that’s very hard to order (I never found a
source), and a car that’s software-ready.
The engineering answer is a <strong>hybrid jumper harness</strong>, and the unlock
came from the Model Y parts bin: the HW4 Model Y uses the <em>same hitch
controller</em> with a different Molex connector at the trunk, served by a
cheap sub-harness (a $50 part) that carries the controller connectors
and the hitch connector. Graft that Y sub-harness onto Model S/X Rev2
controller wiring, follow the pin/terminal/wire-size documentation that
exists on both sides of the graft, and you have a factory-electrics tow
installation Tesla never sold you.</p>

<p>It’s slow going (this is the kind of project where a connector spends
weeks on a boat), and it’s probably a 1:1 solution rather than
something repeatable. But I think it’s fun, and the documentation trail
means the next person starts from mile 20 instead of mile zero.</p>

<p>A few hard-won practicals if you attempt any version of this: the
service center will let you <em>order</em> hitch parts but won’t <em>install</em>
them (“Model S doesn’t support a tow hitch,” remember), and they won’t
put an X-specific part on an S even where the part itself lists Model S
specs. If you go the simpler taillight-signal route instead, run your
connections through the boot at the right-hand lower storage area —
untape the boot from the harness, fish the wires, retape. Cleanest
installation you’ll get. And ship hitches with the controller, wiring,
and 7-pin receptacle removed and packed separately — I’ve had to send
one back because the shipping weight beat the attached parts to death.</p>

<h2 id="why-bother">Why bother?</h2>

<p>Somewhere in year two, a reasonable person asks: for towing a small
trailer, why not just buy the perfectly good third-party hitch? For most
people that’s honestly the right answer. What’s on my car today is the
factory hitch itself, installed but not yet wired (controller taped off,
waiting on the harness). But “the factory did it this way, therefore it
can be done this way” is a hill I’ve been climbing since I was flashing
AS-BUILT data into Fords (that’s <a href="/garage/asking-cars-to-do-things-they-werent-ordered-with/">its own story</a>),
and there’s a real difference between bolting an accessory onto the car
and putting back what the factory designed in. I want the second one.</p>

<p>The car supports a tow hitch. It says so right there in the manual
nobody at the counter has read.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="garage" /><summary type="html"><![CDATA[A three-year-ish quest through Tesla's parts catalog: TW01 harnesses, unicorn cars, a relabeled part after a six-month wait, and the hybrid jumper harness I'm building because the right connector is nearly impossible to order.]]></summary></entry><entry><title type="html">The accidental parts supplier</title><link href="https://leecox.pro/garage/the-accidental-parts-supplier/" rel="alternate" type="text/html" title="The accidental parts supplier" /><published>2026-08-08T10:00:00-05:00</published><updated>2026-08-08T10:00:00-05:00</updated><id>https://leecox.pro/garage/the-accidental-parts-supplier</id><content type="html" xml:base="https://leecox.pro/garage/the-accidental-parts-supplier/"><![CDATA[<p>Nobody sets out to become a parts supplier from their garage. It happens
one step at a time. You do a retrofit on your own car, you solve a
connector problem the factory never intended you to solve, someone on
the forum asks “hey, can you make me one of those?” — and eighteen
months later you’re de-pinning connectors at the kitchen table wondering
where the evenings go.</p>

<p>This is the story of how the <a href="/garage/asking-cars-to-do-things-they-werent-ordered-with/">Matrix headlight retrofit</a>
turned me into a very small, very accidental parts vendor, and what
running even a tiny hardware operation teaches you.</p>

<h2 id="it-starts-with-an-unobtainable-connector">It starts with an unobtainable connector</h2>

<p>The retrofit itself is straightforward in principle: the newer Matrix
headlights use a different connector than the older cars, so you either
splice the factory harness (reversible: no; warranty-friendly: also no)
or you build an adapter that sits between the car and the light. The
adapter is clearly the right answer. The problem is that you cannot walk
into a store and buy the connectors it needs.</p>

<p>The workaround came from an unlikely donor: eBay is full of headlight
pigtails for other European cars (Audi, VW, even Porsche Cayenne
harnesses) that carry the right connector families. Buy the donor
pigtail, de-pin the connectors you don’t need, cut back the opposite
end, and crimp up the adapter you actually want. With a proper crimp
tool and a set of de-pinning tools it takes about an hour per set. The
first one I built was for my own car. The second one was for a forum
member who asked nicely. You can guess how it went from there.</p>

<h2 id="what-quality-control-means-at-kitchen-table-scale">What quality control means at kitchen-table scale</h2>

<p>Making the same part more than a handful of times teaches you things
the first build never does. The lesson I’d pass along to anyone doing
small-batch automotive parts: <strong>the failure modes live in the tolerances
between manufacturers.</strong> The connectors have small alignment tabs inside
(four of them, purple and pink), and because the aftermarket shells and
the factory shells come from different molds, those tabs can catch and
keep a connector from fully seating. They cause nothing but problems,
so now they come out of every set I make before it ships. That’s the
kind of thing you only learn by being the person people come back to
when it doesn’t click home.</p>

<p>And they do come back, which brings me to the day a customer sent me a
photo of his adapter and the wire colors were backwards. (The three-pin
end has an order — red, blue, black — and this one read like it had been
assembled in a mirror.) There’s only one right answer in that moment,
and I gave it: if that set is mine, I’ll tell you how to fix it in five
minutes, and I’ll refund you or overnight you a new one — your choice.
Standing behind the work is the entire difference between “guy who sells
adapters” and “guy you’d let near your car.” It costs a set of parts
now and then. It’s worth it.</p>

<h2 id="the-group-buy-or-economics-on-a-slow-boat">The group buy, or: economics on a slow boat</h2>

<p>The other way you accidentally become a supplier is the group buy. For
the RGB ambient lighting project, the kits come from overseas, minimums
apply, and somebody has to be the person who fronts the order and
distributes the parts. That somebody learns two things. First, the boat
is slow: the original order took more than six months to arrive, which
is a long time to hold other people’s enthusiasm (and money) in a
cardboard box by the door. Second, demand is a spike, not a line: the
day a popular video about the mod dropped, every spare kit I had left
sold out at once.</p>

<p>These days, when someone asks, I mostly point them to the established
vendors (EVOffer, EVMod — as a fellow forum member put it, it’s all the
same kit). That isn’t me being coy about competition. It’s the honest
math: a vendor with inventory serves people better than a guy with a
group buy that lands in Q3, and the low-hundreds of cars that have done
these conversions deserve a supply chain sturdier than my kitchen
table.</p>

<h2 id="why-stay-tiny-then">Why stay tiny, then?</h2>

<p>So why keep making adapter sets at all? Partly because some corners of
these retrofits are still too niche for any real vendor to bother with.
Partly because being hands-in-the-connectors is how I stay current on
the platform (the parts knowledge in <a href="/topics/garage/">the tow hitch quest</a>
came directly from this bench time). And partly, honestly, because
there’s a specific satisfaction in a stranger in another state turning
on headlights that work because of something you crimped correctly.
It’s the same reason I answer the DMs, and occasionally spend a Saturday
helping a local owner with an install: the forum gave me the retrofit
in the first place. Making a few parts is how I pay the toll.</p>

<p>Next up from the garage, sooner or later: the media-converter rental
economy (return it on time, or the $75 rental stops being $75), and
what “programming” actually means when the part finally clicks in.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="garage" /><summary type="html"><![CDATA[How making one adapter harness for my own headlight retrofit turned into a tiny parts operation — and what running it taught me about QA, group buys, and standing behind your work.]]></summary></entry><entry><title type="html">Sixteen years of asking cars to do things they weren’t ordered with</title><link href="https://leecox.pro/garage/asking-cars-to-do-things-they-werent-ordered-with/" rel="alternate" type="text/html" title="Sixteen years of asking cars to do things they weren’t ordered with" /><published>2026-08-07T10:00:00-05:00</published><updated>2026-08-07T10:00:00-05:00</updated><id>https://leecox.pro/garage/asking-cars-to-do-things-they-werent-ordered-with</id><content type="html" xml:base="https://leecox.pro/garage/asking-cars-to-do-things-they-werent-ordered-with/"><![CDATA[<p>Every car I’ve owned has eventually faced the same question: <em>what else
were you built to do?</em> Not modified in the fast-and-loud sense (I’ve
never cut a spring or glued on a wing). I mean the quieter obsession:
the factory designed this platform to support features my particular
car didn’t ship with, the wiring or the software or the mounting points
are often still there, and somewhere in a service document is the proof.
The build sheet records a purchase decision somebody made at a
dealership years ago. It doesn’t have to be the last word on what the
car can do.</p>

<p>This is the origin-story post for the Garage section, because the
current project (a factory tow hitch Tesla insists doesn’t exist — that
story is coming in its own post),
makes more sense once you know it’s the third generation of the same
instinct.</p>

<h2 id="2010-the-f250-navigation-unit">2010: the F250 navigation unit</h2>

<p>It started with a 2010 Ford Escape XLT and a navigation head unit pulled
from a 2009 F250. Same corporate parts bin, very different
window stickers. The physical part of the swap only takes a Saturday.
The electrical part was the real project, because the truck radio and
the little SUV had never been introduced to each other.</p>

<p>The key was Ford’s <strong>AS-BUILT data</strong> (the per-vehicle configuration
record that tells every module what the car is and what it’s allowed to
do). Load the AS-BUILT values from a donor vehicle whose build <em>did</em>
include the feature, and the electronics stop arguing. I fed my Escape
a section of a 2010 Escape Limited’s configuration, and the nav unit
woke up believing it had always lived there. Drop it in reverse and the
camera screen came up, ready and waiting — for a camera I hadn’t
actually wired in yet. The pigtails and the custom wiring came later,
but as far as the modules were concerned, that camera had been ticked
at the factory.</p>

<p>That swap taught me the foundational lesson of all of this: <strong>modern
vehicle features are parts + wiring + configuration</strong>, and the
configuration is just data. Data can be read, understood, and (done
carefully, with the service documentation open) rewritten.</p>

<h2 id="2013-the-tow-package-that-lincoln-forgot">2013: the tow package that Lincoln forgot</h2>

<p>Next platform, same move, more copper. The 2010 Lincoln MKT EcoBoost
(my beloved black-on-black sleeper) shares its bones with the Ford Flex,
and the platform supported a factory tow package mine didn’t ship with.
So it gained one: the real thing, factory parts, factory routing,
documented on the owner forums as I went. Along the way that car turned
into a rolling seminar on the rest of the discipline: talking other
owners through retraining the collision-warning sensor after bodywork,
EcoBoost charge-air plumbing, and the eternal truth that the parts
catalog knows more than the sales brochure ever admitted.</p>

<p>The MKT era added the second lesson: <strong>the factory’s own engineering is
usually the best aftermarket kit you can buy.</strong> It fits, it lasts, and
the documentation (diagrams, torque specs, connector part numbers)
already exists. You just have to be willing to read like it’s your job.</p>

<h2 id="2022-feature-flags-on-wheels">2022: feature flags on wheels</h2>

<p>Then came a 2021 Model S. Does a Tesla even have an AS-BUILT record?
The short answer is no, not in the Ford sense. What it has is a
<strong>gateway config</strong>: a file of feature flags living in the gateway
controller inside the MCU, telling the car’s software what hardware it
believes it has. Change the config (through Tesla’s own Toolbox, these
days with a paid day pass), redeploy, and capabilities appear exactly
the way my Escape’s camera screen did sixteen years ago.</p>

<p>The architecture is genuinely elegant (zonal controllers, smart
devices on LIN and CAN buses, one config to rule them), and it’s made
possible things the Ford era couldn’t dream of: matrix headlights on a
car sold with the lesser lights, a passenger-lumbar retrofit done over
a weekend on my wife’s Model Y, tail lamps from a later revision, the
tow-hitch project. The <em>instinct</em> is unchanged. The difference is the
posture of the manufacturer: Ford published AS-BUILT structure openly
enough that a guy with a laptop could learn it in 2010. Tesla treats
the equivalent layer as theirs, on a car I own (an approach I once
described on a forum as very Apple, and I didn’t mean it entirely as a
compliment). The capability being <em>in there</em>, behind a flag I’m not
supposed to flip, changes the project: the engineering is still the
engineering, but now there’s a negotiation with the manufacturer
sitting on top of it.</p>

<h2 id="what-sixteen-years-of-this-actually-teaches">What sixteen years of this actually teaches</h2>

<p><strong>Read the service documentation first, opinions second.</strong> Every one of
these projects began in a wiring diagram or a parts catalog, not a
YouTube thumbnail. The documents don’t care what the counter says is
possible.</p>

<p><strong>The gap between trims is where the fun lives.</strong> Manufacturers build
one platform and sell it as five cars. The wiring for the car you
didn’t buy is frequently sleeping in the car you did.</p>

<p><strong>Configuration is the modern crowbar.</strong> In 2010 it was AS-BUILT hex
values. In 2026 it’s gateway feature flags. In both cases, the
difference between “your car can’t do that” and a working feature was
never metal — it was a few bytes of permission.</p>

<p><strong>And know when you’re done.</strong> Not every gap is worth closing; some
retrofits turn out to be a lot bigger than they look on paper, and the
fog-light adapter that once cost me a tow truck (a story for another
post) taught me the price of forgetting that. The discipline isn’t
doing everything; it’s knowing what the platform supports, and
choosing.</p>

<p>The Garage section will mostly be these stories: current Tesla
projects, the occasional MKT flashback, and the tooling that makes it
all go. If your car’s build sheet has ever felt like a suggestion,
you’re among friends here.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="garage" /><summary type="html"><![CDATA[From an F250 nav unit in a 2010 Escape, to a factory tow package on a Lincoln MKT, to Tesla gateway configs — one instinct, three generations of vehicle architecture.]]></summary></entry><entry><title type="html">I audited my backlog with 13 AI agents (and deleted a quarter of it)</title><link href="https://leecox.pro/ai-engineering/i-audited-my-backlog-with-13-ai-agents/" rel="alternate" type="text/html" title="I audited my backlog with 13 AI agents (and deleted a quarter of it)" /><published>2026-08-05T10:00:00-05:00</published><updated>2026-08-05T10:00:00-05:00</updated><id>https://leecox.pro/ai-engineering/i-audited-my-backlog-with-13-ai-agents</id><content type="html" xml:base="https://leecox.pro/ai-engineering/i-audited-my-backlog-with-13-ai-agents/"><![CDATA[<p>Every project of any age carries a backlog that is part roadmap, part
archaeology. Items written by past-you, for reasons past-you understood,
in a codebase that has since moved on. You <em>know</em> some of it is stale.
You also know that verifying a couple hundred items by hand is a full week
of unglamorous work, which is why nobody ever does it.</p>

<p>This is a story about doing it anyway. It took an afternoon and a raid
group of 13 AI agents.</p>

<h2 id="the-setup">The setup</h2>

<p>My current OS side project had accumulated just over 200 backlog items
across several documents. Some
dated back to the first week of design. The codebase had been through a
compositor rewrite and a licensing cleanup since. I no longer trusted the
list, and an untrusted backlog is worse than no backlog, because you stop
reading it.</p>

<p>So I gave an agentic coding tool a job description instead of a task list:
take every item, go read the actual repository, and classify it. Is this
<strong>done</strong> (the code exists and works)? <strong>Stale</strong> (the premise no longer
exists)? <strong>Still real</strong> (verified gap)? Each agent took a slice, and each
had to cite the files it checked. No citations, no verdict.</p>

<h2 id="the-part-that-matters-adversarial-verification">The part that matters: adversarial verification</h2>

<p>Here’s the thing I’d tell any engineering leader looking at agentic
workflows: <strong>the first pass is not the product.</strong> The first pass is a
hypothesis. Language models behave like enthusiastic interns. They work
fast and they never get tired, but every so often one of them is
confidently wrong about something important.</p>

<p>So the second pass was a different set of agents whose only job was to
<em>attack</em> the first set’s conclusions. Take a “this is done” verdict and try
to prove it wrong. Take a “stale” classification and check whether the
premise actually still exists under a renamed identifier. The adversarial
pass caught real misses — including items marked done where the code
existed but the <em>verification</em> didn’t, which in my shop means it isn’t
done.</p>

<h2 id="the-results">The results</h2>

<ul>
  <li><strong>53 items were stale-done</strong> (marked done or claimed complete, but no
longer matching reality). A quarter of the backlog was noise.</li>
  <li>The survivors got reorganized into a short <strong>Now</strong> queue (25 items),
a Deferred pile, and (my favorite artifact) a <code class="language-plaintext highlighter-rouge">not-doing.md</code> file that
records what I’ve <em>decided not to build</em> and why. Decisions rot slower
when you write down the reasoning.</li>
  <li>Total wall-clock time: an afternoon, most of it me reviewing verdicts
rather than producing them.</li>
</ul>

<h2 id="what-i-actually-learned">What I actually learned</h2>

<p><strong>The short answer is:</strong> agents didn’t replace my judgment; they changed
where I spend it. I went from <em>producing</em> claims (“is this done?”) to
<em>reviewing</em> them — and reviewing is where a couple decades of scar tissue
actually pays off.</p>

<p><strong>The long answer</strong> has a rule in it, and the rule is the whole post:
<em>never accept an agent’s claim that isn’t verifiable against the tree.</em>
Citations or it didn’t happen. The same discipline I’d apply to a vendor’s
migration assessment applies to an AI’s backlog audit: an assessment earns
my trust when I can check it against the tree myself, no matter how
confident it sounds.</p>

<p>More in this series soon: the CI gates that keep AI-written code honest,
and what “proven fail-then-pass” means when the intern types faster than
you can read.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="ai-engineering" /><summary type="html"><![CDATA[What happened when I pointed a small raid group of AI agents at 200+ backlog items and told them to verify every claim against the actual code.]]></summary></entry><entry><title type="html">The job search runs on agents so I don’t have to</title><link href="https://leecox.pro/career/the-job-search-runs-on-agents/" rel="alternate" type="text/html" title="The job search runs on agents so I don’t have to" /><published>2026-08-01T10:00:00-05:00</published><updated>2026-08-01T10:00:00-05:00</updated><id>https://leecox.pro/career/the-job-search-runs-on-agents</id><content type="html" xml:base="https://leecox.pro/career/the-job-search-runs-on-agents/"><![CDATA[<p>Microsoft cut our entire Infrastructure GBB organization in early July
(<a href="/career/the-architects-seat/">the longer story</a>). Within a week, every
well-meaning person in my life had told me the
same thing: “job searching is a full-time job.” And they’re right, but
nobody ever asks <em>which parts</em> of that job actually deserve full-time
attention. Most of a modern job search is mechanical: tailoring documents,
formatting, tracking, drafting yet another polite follow-up. Mechanical
work is what I have agents for. So the first thing I built after the
layoff wasn’t a spreadsheet of openings. It was a harness.</p>

<p>Same deal as <a href="/workbench/agentic-management-of-a-personal-home-lab/">the home lab</a>:
this post is the setup (the harness, the agents, the process, and what
it’s produced) and then the actual point, which is what all of it buys.</p>

<h2 id="the-harness">The harness</h2>

<p>The search lives in a project directory that’s structured like an
engineering repo, because it is one: resumes, cover letters,
correspondence, imported conversations, and a build pipeline. The agent
works inside it with full context; nothing lives in my head or a random
Downloads folder.</p>

<p><strong>Resume-as-code.</strong> There’s one archetype resume (the maintained,
canonical account of the career) and it never ships. What ships is a
build: a Node pipeline using the <code class="language-plaintext highlighter-rouge">docx</code> library that produces a tailored
Word document and PDF per application. Formatting bugs got fixed once, in
code. When a posting demands a different emphasis, the delta is a
tailoring pass, not an hour of fighting Word’s list indentation at
midnight.</p>

<p><strong>A fact base with usage rules.</strong> Underneath everything sits a performance
record (every deal, metric, and win from the career, compiled once and
kept internal) with hard rules the agents must draft against: numbers
come only from the record, opportunities are never written as bookings,
losses are stated as pursuits, customer names stay generalized unless
there’s a release. In other words: the resume can’t inflate, because the
data layer refuses. I’d love to claim this was a character decision, but
honestly it’s just good engineering (the same reason you validate at the
schema and not in the UI).</p>

<p><strong>A voice profile.</strong> The strangest and most valuable piece. The agents
draft correspondence in <em>my</em> voice, trained not on vibes but on my actual
sent mail, and refined the way you’d tune any model: by diffing what the
agent drafted against what I actually sent, and folding every correction
back into the profile. It has learned things about my writing I hadn’t
noticed myself: that I thank people for specific things rather than in
general, that I’d rather hand someone a menu of options than an
open-ended ask. The drafts land close enough now that my edit pass is
minutes.</p>

<h2 id="the-process">The process</h2>

<p>The loop per application is boring, which (like the lab) is the point:</p>

<ol>
  <li><strong>Intake:</strong> posting comes in; an agent maps its language against the
record. Where there’s a truthful match, the resume mirrors the
posting’s exact terms. Where there isn’t, it doesn’t (see rules above).</li>
  <li><strong>Build:</strong> tailored resume and cover letter compile out of the
pipeline. I review a diff, not a document.</li>
  <li><strong>Correspond:</strong> replies, scheduling notes, thank-yous, warm-network
messages get drafted in-voice with the full thread as context. <strong>I
send everything myself.</strong> The agent has no send button, and it never
will — the harness stops at the edge of every relationship.</li>
  <li><strong>Track:</strong> state lives in the repo. “Where are we with X?” is a
question the directory can answer.</li>
</ol>

<h2 id="the-self-jd-scoring-the-search-in-both-directions">The Self-JD: scoring the search in both directions</h2>

<p>The piece of the harness I’d recommend even to someone who automates
nothing else: before I applied to a single posting, I wrote <strong>the job
description for the role I would post for myself.</strong> Scope, altitude,
domain, the customer-facing/engineering mix, location and travel shape,
and the markers of the places I’ve done my best work. It forces the
“what do I actually want” conversation out of your head and into a
document that can be argued with.</p>

<p>Then it becomes a scoring system, and the weighting is where most people
(me included, first pass) get it wrong. The temptation is to weight the
shiny factors (brand, title, the comp headline). The fix is evidence:
go back through your own history, role by role, and ask what actually
correlated with thriving versus what correlated with leaving. Those
factors get the heavy weights. My own record says autonomy and problem
quality predicted every good year I’ve had, and title predicted nothing;
the weights now reflect that, whatever the shiny part of my brain thinks
on a given Tuesday.</p>

<p>Every posting that comes in gets scored two directions:</p>

<ul>
  <li><strong>The role against my Self-JD:</strong> weighted fit, does this deserve
pipeline space at all. A posting that can’t clear the bar doesn’t get
a tailored resume, however good the note that came with it felt to read.</li>
  <li><strong>Me against the role:</strong> requirement by requirement. And here’s the
rule that makes it worth doing: <strong>every claim needs a receipt from the
record.</strong> “I can do this” doesn’t score; “I did this, here, with this
outcome” scores. The same discipline as everything else in the
harness, and it cuts both ways. It catches the
impostor reflex that undersells real evidence, and it catches the
stretch fantasy where I talk myself into a fit that’s really three
gaps in a trench coat. What’s left is an honest gap list, which is
exactly the interview-prep syllabus and the cover letter’s talking
points.</li>
</ul>

<p>And it’s a living system: <strong>refinement and rescoring.</strong> After every
conversation and every loop, what I learned goes back in: a weight was
wrong, a requirement on paper turned out not to matter in the room, a
“dream fit” revealed a travel load the posting never mentioned. The
agents rerun the scoring across the whole pipeline, and the ranking
reshuffles without sentiment. Sunk cost doesn’t get a vote; the
month-old conversation gets rescored like it walked in today.</p>

<h2 id="the-outcomes">The outcomes</h2>

<p>The honest scorecard, a month in: the mechanical layer of an application
(the part that used to eat an evening per posting) now takes minutes of my
attention. The documents going out are fact-checked to a standard no tired
human at 11 PM holds himself to: nothing ships that the record can’t back.
And the pipeline is doing what a pipeline should: several active
conversations running, interview loops in motion. No outcomes to announce
yet; when there’s one, this thread will hear about it.</p>

<h2 id="the-actual-point">The actual point</h2>

<p>Here’s the thing the harness is really for, and it isn’t efficiency for
its own sake. Everything above exists to protect the hours that matter,
because the parts of a job search that produce a job were never the
documents:</p>

<p><strong>Networking.</strong> Every conversation that has moved my search forward has
come through an actual person rather than a portal. The harness means
that when someone offers me twenty minutes, my prep is done and my
follow-up is thoughtful and same-day; the machine handles the ceremony
so I can show up prepared and actually present.</p>

<p><strong>Interview prep.</strong> Loops at the principal level are won in the room.
The reclaimed evenings go to the actual work: systems thinking, stories
with numbers I can defend, whiteboards.</p>

<p><strong>Self-reflection.</strong> The least automatable task on the list: figuring out
what the next decade should actually be, rather than sprinting into the
first thing that looks like the last thing. The Self-JD is where that
thinking gets written down, but the thinking itself happens on long
walks, away from any terminal. A layoff hands you a rare, unwelcome gift
(a forced pause with real stakes), and it would be a waste to spend it
fighting Word.</p>

<p>That’s the design, then: the agents handle the search’s mechanics, and
the human parts stay human. If you’re in the same boat (and this
industry has put a lot of good people in this boat lately), build the
harness once, and then go spend yourself where it counts.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="career" /><summary type="html"><![CDATA[How I built an agentic harness around my job search (the resume pipeline, the fact-checked record, the voice profile) so the human hours go to networking, interview prep, and figuring out what comes next.]]></summary></entry><entry><title type="html">The VMware bill came due. Now what?</title><link href="https://leecox.pro/migration/the-vmware-bill-came-due/" rel="alternate" type="text/html" title="The VMware bill came due. Now what?" /><published>2026-07-26T10:00:00-05:00</published><updated>2026-07-26T10:00:00-05:00</updated><id>https://leecox.pro/migration/the-vmware-bill-came-due</id><content type="html" xml:base="https://leecox.pro/migration/the-vmware-bill-came-due/"><![CDATA[<p>If you run enterprise infrastructure, you’ve either had this meeting or
you’re scheduled for it: the virtualization renewal comes in, the number
has grown a multiple, the licensing model has changed shape, and somebody
upstairs wants a plan on their desk by Friday.</p>

<p>I’ve spent the last several years of my career in exactly these meetings
(across Retail, Manufacturing, Healthcare, and Financial Services), and the
first thing I tell every team is the same: you have more options than you
think, but you don’t have forever to pick one. The second thing I tell them
is that panic-migrating everything is how you turn a licensing problem into
an outage problem.</p>

<p>So what do you actually tell the person who wants the plan by Friday? It’s
a fair question.</p>

<h2 id="the-actual-decision-tree">The actual decision tree</h2>

<p>Every estate is different, but the branches are not. There are four, and
you’ll probably use more than one of them.</p>

<p><strong>Option 1: Pay, and buy time deliberately.</strong>
Sometimes the right answer for <em>this renewal</em> is to pay — but pay for a
shorter term than procurement wants, and spend that term executing one of
the other options. The mistake isn’t renewing; it’s renewing for three
years and then doing nothing for two and a half of them. If you take this
branch, the renewal <em>is</em> the deadline for the rest of the plan.</p>

<p><strong>Option 2: Swap the hypervisor, keep the datacenter.</strong>
Hyper-V, Proxmox, Nutanix, OpenShift Virtualization — the field is real
and I’ve seen each of them hold production weight. The honest trade-off:
you’re re-training your ops team and re-plumbing your backup, DR, and
monitoring stack no matter which one you pick. The replacement hypervisor
is rarely the expensive part of the swap; the retooling around it is where
the money actually goes. Budget for the ecosystem.</p>

<p><strong>Option 3: Lift the estate to cloud, mostly as-is.</strong>
Every major cloud will happily run your VMs, and for workloads with a
limited remaining lifespan this is often the right call: you’re buying
yourself a way out of the datacenter. Be clear-eyed about what it is,
though. Your cost model shifts from a big renewal every few years to a
bill every month, and if you treat cloud like a rented datacenter
<em>permanently</em>, you’ll pay rented-datacenter prices permanently. This
branch works if you actually keep moving once you land.</p>

<p><strong>Option 4: Re-platform what actually deserves it.</strong>
Some fraction of your estate (usually smaller than the modernization
deck claims) genuinely benefits from moving to managed services,
containers, or PaaS. The way to find that fraction is not a vendor’s
assessment tool defaulting to “yes.” It’s asking, per application: who
maintains this, what breaks if we touch it, and what do we get for the
effort? “It’s technically possible” doesn’t answer any of those questions.</p>

<h2 id="what-actually-decides-bake-offs">What actually decides bake-offs</h2>

<p>Having sat on the vendor side of plenty of these evaluations, let me tell
you what separates the teams that land well from the teams that don’t. It
isn’t the platform choice. It’s three unglamorous things:</p>

<ol>
  <li><strong>A real inventory.</strong> And I don’t mean the CMDB. I mean the <em>actual</em>
estate, including the forgotten VMs that turn out to run the badge
readers. Every difficult migration I’ve ever seen got difficult in the
discovery gap.</li>
  <li><strong>A named owner per workload.</strong> Migrations stall when no one in
particular owns an app; everyone’s job ends up at the bottom of
everyone’s list.</li>
  <li><strong>A definition of done that includes operations.</strong> “It boots in the new
place” is not done. Backup, DR, monitoring, patching, and the on-call
runbook are done.</li>
</ol>

<p>There’s no vendor-neutral answer to “where should it all go,” and anyone
who gives you one before seeing your estate is selling something. But
there’s always a <em>sequenced</em> answer — this workload now, that one at
renewal, those three never. The order you move things in matters more
than the destination you picked.</p>

<p>I’ll go deeper on each branch in future posts, including the hybrid
patterns for the workloads that genuinely can’t leave the building. Data
residency, latency-pinned manufacturing floors, and regulators all exist,
and a plan that ignores them only works on the slide.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="migration" /><summary type="html"><![CDATA[The honest decision tree I walk enterprises through when the virtualization renewal lands and the number has changed.]]></summary></entry><entry><title type="html">The architect’s seat</title><link href="https://leecox.pro/career/the-architects-seat/" rel="alternate" type="text/html" title="The architect’s seat" /><published>2026-07-19T10:00:00-05:00</published><updated>2026-07-19T10:00:00-05:00</updated><id>https://leecox.pro/career/the-architects-seat</id><content type="html" xml:base="https://leecox.pro/career/the-architects-seat/"><![CDATA[<p>Job titles in enterprise tech are terrible at describing jobs. Mine have
included Customer Engineer, Solutions Architect, Principal Consultant,
Cloud Solution Architect, and Principal Solution Engineer. Functionally,
they were all versions of the same seat: the person in the room who has to
turn “what should we do?” into an architecture, and an architecture into a
decision someone will actually fund.</p>

<p>This thread of the blog is about that seat. Consider this the origin story
post.</p>

<h2 id="the-long-road-version-compressed">The long road version, compressed</h2>

<p>I started in network closets, in healthcare IT, pulling cable and keeping
small hospital systems alive. Went to HP and worked my way through
mission-critical support into presales architecture for big compute deals.
Did a stretch at Ericsson designing carrier-grade virtualized network
functions, where “five nines” stops being a slide and starts being a
contract (with penalty clauses). Landed at HPE architecting hosted cloud
for service providers right as the industry was deciding what “private
cloud” even meant. Then nearly a decade at Microsoft, with the last
six-plus years in the Global Black Belt organization, the specialist
overlay that works the hardest migrations and the most skeptical accounts.</p>

<p>The through-line isn’t a technology. It’s altitude-shifting: being able to
talk to the CIO at nine, the storage admin at ten, and mean the same thing
in both rooms. That skill (not any certification) is the job.</p>

<h2 id="what-the-seat-actually-teaches-you">What the seat actually teaches you</h2>

<p>A few things the briefing rooms and datacenter floors have taught me that
I never got from a course:</p>

<p><strong>Trust compounds faster than expertise.</strong> The most valuable sentence in my
vocabulary has always been “honestly, our product isn’t the right fit for
that.” I’ve told customers to stay on a competitor. Some of those accounts
came back years later and bought more than they ever would have the first
time around, because when I said something <em>was</em> a fit, they believed me.</p>

<p><strong>The technical answer is maybe forty percent of the job.</strong> The rest is
sequencing, budget reality, org politics you’re polite about, and finding
the one person in the customer’s shop who actually knows where the bodies
are buried. Most of the failed projects I’ve watched had a perfectly fine
architecture diagram.</p>

<p><strong>Writing is a superpower in a slideware industry.</strong> The architects who get
listened to are the ones whose documents survive being forwarded. If your
recommendation can’t be understood without you in the room, it isn’t
really a recommendation yet. You were just presenting.</p>

<h2 id="the-part-where-the-org-chart-gets-deleted">The part where the org chart gets deleted</h2>

<p>In early July, Microsoft eliminated our entire Infrastructure GBB
organization. It wasn’t performance-based; it was structural. The whole
org went away at once, my seat included.</p>

<p>I’m not going to dress that up, and I’m also not going to perform grief
about it. It’s the industry we work in. The same forces that made my last
several years fascinating (cloud economics, AI capital reallocation)
draw the org charts, and sometimes they erase yours. If it happens to you,
my early field notes: file the paperwork the same week, tell your network
plainly and without shame, and get specific fast about what you want next.
Vague availability helps nobody, including you.</p>

<p>So, what do I want next? The short answer is: a place doing serious
infrastructure work (cloud, hybrid, AI platforms) where I can spend a good
long while, ideally the kind of tenure I’ve had before. The longer answer
is a post of its own. The conversations are happening. In the meantime, I
have a garage full of projects and years of field notes to publish, which
is what this site is.</p>

<p>More in <a href="/topics/career/">this thread</a>: how executive briefings actually work, what
competitive bake-offs look like from the inside, and the unreasonable
career value of being the person who writes things down.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="career" /><summary type="html"><![CDATA[What a field architect actually does, how I got here from a network closet, and what happens when the org chart gets deleted out from under you.]]></summary></entry><entry><title type="html">From BIOS to first token: standing up an NVIDIA A2 at the edge</title><link href="https://leecox.pro/ai-infra/from-bios-to-first-token/" rel="alternate" type="text/html" title="From BIOS to first token: standing up an NVIDIA A2 at the edge" /><published>2026-06-22T10:00:00-05:00</published><updated>2026-06-22T10:00:00-05:00</updated><id>https://leecox.pro/ai-infra/from-bios-to-first-token</id><content type="html" xml:base="https://leecox.pro/ai-infra/from-bios-to-first-token/"><![CDATA[<p>Everyone’s AI infrastructure story starts in a datacenter with a rack of
DGXs and a power bill that needs its own approval chain. Mine starts in a
22U rack next to the water heater, with a Lenovo SE350 (a ruggedized edge
server about the size of a large hardcover book) and a single <strong>NVIDIA
A2</strong> — 16 GB of GDDR6, low-profile, sipping around 40–60 watts. The
Warthog of GPUs. Nobody writes keynotes about it, but it goes everywhere,
survives everything, and it’s the vehicle you actually drive through the
whole campaign.</p>

<p>I’ve spent years advising enterprises on GPU platform strategy from the
architect’s seat (factory-floor vision systems, store-edge inference at
national scale), and the honest truth is that if you count the sites
instead of the FLOPs, far more enterprise AI <em>deployments</em> run on cards
like the A2 than on anything that gets a launch event. So when it came
time to build the edge-inference tier of
<a href="/workbench/agentic-management-of-a-personal-home-lab/">my home lab</a>, I
wanted the real experience: bare metal to generated token, every step
scripted, every gotcha documented. This post is that story.</p>

<h2 id="the-stack-and-why-each-layer-won">The stack, and why each layer won</h2>

<p><strong>Ubuntu 24.04 LTS.</strong> Yes, the decade-ish-at-Microsoft guy put Ubuntu on
it. (This box spent its previous tour running AKS with Azure Linux, as
described in the lab post; that build got wiped for this one, because I
wanted the vendor’s happy path from bare metal.) The short answer is
that <strong>the support matrix is the boss.</strong> NVIDIA
publishes exactly which OS/kernel combinations are validated for the A2
and which rows of the GPU Operator’s driver-container matrix get
<em>precompiled</em> images: 24.04 on the 6.8 kernel is the happy path, 22.04 on
the same kernel falls back to a slower DKMS build, and the shiny new
26.04 LTS isn’t in the matrix yet at all. When the vendor hands you a
validated-configurations table, you read it and you obey it. I tell
customers this weekly; it would be poor form to ignore my own advice in
my own rack.</p>

<p><strong>k3s.</strong> Single-node edge Kubernetes with the operational weight of a
sandwich. The enterprise version of this conversation involves fleet
management and a fleet-scale distro, but the Kubernetes API is the
Kubernetes API — which is the entire point of the exercise.</p>

<p><strong>NVIDIA GPU Operator.</strong> If you haven’t watched it work: the Operator can
own the entire GPU enablement stack, driver included — hand it a bare
node and it will do the rest. In my build the driver lands on the host
first (script 01 of my pipeline — old habits from years of hand-built
nodes), so the Operator runs with <code class="language-plaintext highlighter-rouge">driver.enabled=false</code> and manages
everything above it: container toolkit, device plugin, DCGM monitoring,
all as Kubernetes-native objects it keeps healthy. (If you let the
Operator own the driver too, the install-order gospel below relaxes —
that’s half of why the Operator exists.) Either way, the first time
<code class="language-plaintext highlighter-rouge">nvidia-smi</code> runs <em>in a throwaway CUDA pod you didn’t hand-configure</em>,
you get the same small thrill as the first ping across a network you
built. Validation is scripted: if the pod can’t see the silicon, the
pipeline stops, loudly.</p>

<p><strong>KAITO, in bring-your-own-GPU mode.</strong> Microsoft’s Kubernetes AI
Toolchain Operator, pointed at my own node instead of provisioning cloud
GPUs — exercising its workspace CRD against hardware I already own,
which is the part enterprises with existing GPU fleets actually care
about. And the Microsoft-operator-managing-NVIDIA-silicon crossover
episode felt like required viewing given my résumé.</p>

<p><strong>NVIDIA Dynamo, fronting a vLLM worker.</strong> The serving layer: Dynamo’s
frontend with a single vLLM worker (the <code class="language-plaintext highlighter-rouge">vllm-runtime:1.3.0</code> image from
NGC, serving a small Qwen3 model to prove the plumbing). Is a
datacenter-scale serving framework overkill for one 60-watt-ish card?
Completely. That’s the point — the <em>shape</em> of the deployment is the
shape enterprises run at scale, so the frontend, the worker lifecycle,
and the deployment topology all transfer when one worker becomes forty.
(With one worker, the fancy disaggregated prefill/decode split stays
strictly theoretical — I know exactly which Dynamo features need a
bigger fleet than mine.) Plus a Hugging Face model served through TGI on
the same box — not at the same moment, mind you: the device plugin hands
out the card whole, and vLLM books most of the 16 GB the second it wakes
up, so the serving stacks are roommates who take turns. Kicking the
tires on two of them on identical hardware is exactly the kind of thing
this lab exists for.</p>

<h2 id="the-gotchas-collect-them-all">The gotchas (collect them all)</h2>

<p>A few things between power-on and first token that the quickstarts don’t
mention:</p>

<ol>
  <li><strong>Secure Boot will eat your driver install</strong> if you let it. The prep
script checks for it <em>first</em>, because discovering it <em>after</em> the
driver “installed successfully” is a rite of passage I only needed
once.</li>
  <li><strong>Order is everything — in a host-managed-driver build.</strong> Driver
readiness before Kubernetes, Kubernetes before Helm, GPU Operator
before any workload dares mention a GPU. My scripts are numbered <code class="language-plaintext highlighter-rouge">00</code>
through <code class="language-plaintext highlighter-rouge">09</code> because the dependencies are genuinely that linear — and
each one checks current state before acting, so re-running anything
is safe. Idempotence is the difference between automation and a very
fast way to break things twice.</li>
  <li><strong>16 GB is a budget, not a suggestion.</strong> The A2 will happily serve a
small quantized model, vision workloads, or embeddings all day on a
thermal envelope that doesn’t require explaining anything to the
power company. Ask it for more and it will politely decline. Edge
inference is mostly an exercise in living inside the VRAM you
brought.</li>
  <li><strong>Remote management is step nine, not step zero-point-nine.</strong> Once the
GPU tier worked, the box got the full treatment (SSH hardening,
Tailscale, Cockpit, k9s) and joined the
<a href="/workbench/agentic-management-of-a-personal-home-lab/">agent-managed lab</a>
like everything else in the rack.</li>
</ol>

<h2 id="why-this-matters-beyond-my-water-heater">Why this matters beyond my water heater</h2>

<p>So what does a hobby box next to a water heater have to do with
enterprise AI strategy? It’s a fair question. In the enterprise
engagements I’ve worked (automotive plants, national retail footprints),
the edge AI conversation is <em>never</em> about the biggest GPU. It’s about
exactly what this build practices: modest silicon in hostile places,
driver lifecycle you don’t hand-touch, Kubernetes as the control plane,
and a serving layer whose shape scales from one worker to hundreds
without changing the architecture. The SE350 + A2 combo is my one-node
rehearsal of a pattern I’ve watched deploy at real fleet scale.</p>

<p>The useful lesson for the platform-strategy crowd: the stack above mixes
NVIDIA’s operator and serving layers, a Microsoft AI operator, an
open-source inference engine, and a community Linux — and the <em>support
matrix</em>, not the logo, decided every layer. That’s the actual state of
enterprise AI infrastructure in 2026, and the architects who accept it
early save their customers a lot of money (and a lot of awkward vendor
meetings).</p>

<p>Next up in this series: what a 16 GB card can honestly do — model sizes,
quantization trade-offs, and where the A2 taps out versus its bigger
siblings. The token counter is running.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="ai-infra" /><summary type="html"><![CDATA[Bringing up a 16 GB NVIDIA A2 in a Lenovo SE350 edge server — GPU Operator, KAITO, Dynamo with a vLLM worker, and every gotcha between power-on and the first generated token.]]></summary></entry><entry><title type="html">Agentic management of a personal home lab running Windows Server, Azure Linux, and Azure Local</title><link href="https://leecox.pro/workbench/agentic-management-of-a-personal-home-lab/" rel="alternate" type="text/html" title="Agentic management of a personal home lab running Windows Server, Azure Linux, and Azure Local" /><published>2026-06-15T14:00:00-05:00</published><updated>2026-06-15T14:00:00-05:00</updated><id>https://leecox.pro/workbench/agentic-management-of-a-personal-home-lab</id><content type="html" xml:base="https://leecox.pro/workbench/agentic-management-of-a-personal-home-lab/"><![CDATA[<p>Every home lab has the same dirty secret: the gap between what’s racked and
what’s <em>managed</em>. The gear accumulates faster than the discipline. Firmware
drifts, the documentation lives in your head, and the network diagram
exists mostly as a feeling. I’ve run labs for a couple of decades and made
peace with the truth that a lab is a second job that pays in knowledge and
charges in weekends.</p>

<p>This year I changed the deal: I gave an AI agent a seat in the lab as
operations staff. Not a chatbot to ask questions — GitHub Copilot in agent
mode, with a terminal inside the lab, a documentation repo, and a steadily
growing set of responsibilities. It works well enough that this post is a
<strong>how-to</strong>. Stream of consciousness ahead (fair warning). Read the
whole thing before you touch anything.</p>

<p><strong><em>General Disclaimer</em></strong> — <strong>You’re on your own.</strong> You are about to give a
language model a shell inside your network. Done the way I describe, the
blast radius is contained and the lab stays isolated from the internet. Done
lazily (tunnel on your domain controller, auto-approve everything), you’ve
built a very enthusiastic intruder. Don’t go complaining to me, GitHub, or
Microsoft when it deletes a VM you loved.</p>

<h2 id="the-lab-so-you-can-calibrate">The lab (so you can calibrate)</h2>

<p>Mine is seven physical nodes, 768 GB RAM total, in (and around) a 22U
rack: a two-node
<strong>Azure Local 2603</strong> cluster on Lenovo SE350 edge servers, a standalone
<strong>Windows Server 2025</strong> Hyper-V box on an EPYC 4464P build (with a pair of
HPE DL360 Gen9s staged behind it — <em>cough</em> — old habits), a Lenovo MX1021
queued up for its slot, and an SE350 carrying an <strong>NVIDIA A2</strong>, currently
being stood up as the edge-inference node (that build — and the Kubernetes
flavor it lands on — gets its own post). Arc-enabled everywhere, because half the point is
living with the same management plane I’d recommend to a customer. None of
this is required — the pattern works on two NUCs. What matters is the
topology, so let’s start there.</p>

<h2 id="step-1-topology--isolation-is-the-whole-foundation">Step 1: Topology — isolation is the whole foundation</h2>

<p>The security model of everything below rests on one fact: <strong>the lab is its
own island.</strong> Mine runs on its own internet connection and its own network,
physically separate from the network my family and my work machines live
on. Yours doesn’t need a second ISP — a dedicated VLAN with deny-by-default
rules to your home network accomplishes the same thing. The requirements:</p>

<ol>
  <li><strong>No inbound ports from the internet. None.</strong> Everything below works on
outbound connections only.</li>
  <li><strong>A management VM inside the lab.</strong> This is the agent’s body — a plain
Windows Server VM on the Hyper-V host (Linux works fine too). Install
the tools an admin would have: RSAT, the PowerShell modules for your
stack, kubectl, git. This box has line-of-sight to the nodes.</li>
  <li><strong>Out-of-band management stays out of reach.</strong> BMCs (iLO, XCC, iDRAC)
live on a management network the agent’s VM <strong>cannot route to</strong>. The
agent never needs to reflash firmware, and neither does an intruder.
Same for your identity infrastructure and firewall administration.
Humans only. This is the line I do not move.</li>
</ol>

<h2 id="step-2-vs-code-remote-tunnels--the-drawbridge">Step 2: VS Code Remote Tunnels — the drawbridge</h2>

<p>You need to reach that management VM from wherever you are, without opening
a single port. That’s exactly what <strong>VS Code Remote Tunnels</strong> do: the VM
makes an <em>outbound</em> connection to the tunnel service, authenticated through
your GitHub account, and your VS Code client (or vscode.dev in a browser)
connects through it.</p>

<p>On the management VM (pick your own tunnel name; I’ll use <code class="language-plaintext highlighter-rouge">lab-mgmt</code> in
the examples):</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>winget install Microsoft.VisualStudioCode.CLI
code tunnel user login --provider github
code tunnel service install --accept-server-license-terms --name lab-mgmt
</code></pre></div></div>

<p>The login command hands you a device code to sign in with, and the last
command registers the tunnel as a service so it survives reboots. From
anywhere in the world, VS Code → Remote Explorer → <code class="language-plaintext highlighter-rouge">lab-mgmt</code>, and you
have a terminal <em>inside</em> the lab. Protect the GitHub account like the crown jewels it now is:
hardware-key 2FA, because whoever holds that account holds your drawbridge.</p>

<p>Two gotchas that cost me time so they don’t cost you any: run the service
as an account with the admin rights you actually want the agent to have
(service install defaults are conservative), and if the tunnel name doesn’t
appear, check that the service actually started — Windows will happily
install it stopped.</p>

<h2 id="step-3-github-copilot--hiring-the-staff">Step 3: GitHub Copilot — hiring the staff</h2>

<p>Open the tunnel session, sign in to <strong>GitHub Copilot</strong>, and switch to
<strong>agent mode</strong> — the mode where it can run terminal commands, read files,
and iterate, not just complete lines. Now the important part, because the
default settings are wrong for this job:</p>

<ul>
  <li><strong>Do NOT blanket-auto-approve terminal commands.</strong> Copilot will ask
before running commands; keep it that way for anything mutating. I
allowlist a small set of obviously read-only patterns (<code class="language-plaintext highlighter-rouge">Get-*</code>,
<code class="language-plaintext highlighter-rouge">kubectl get</code>, <code class="language-plaintext highlighter-rouge">git status</code>) and approve everything else by hand.</li>
  <li>Approvals are per-workspace. Set them in the <em>lab workspace</em>, not user
settings, so the posture travels with the repo.</li>
</ul>

<p>CAN you auto-approve everything and let it rip? Sure. You can also hand a
new hire domain admin on day one. The lab might even survive it. “Might”
is doing a lot of work in that sentence.</p>

<h2 id="step-4-the-docs-repo--ground-truth-the-agent-reads-and-writes">Step 4: The docs repo — ground truth the agent reads and writes</h2>

<p>Create a <strong>private</strong> repo (mine has a suitably boring name) and open it
as the workspace in every tunnel session. Structure it the
way you’d brief a new admin. Mine:</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>00-lab-overview.md        # what this place is, quick stats, diagram
01-hardware-inventory.md  # every node: model, CPU, RAM, storage, NICs, role
02-network-topology.md    # subnets, VLANs, switch ports
03-clusters-workloads.md  # what runs where and why
04-identity-security.md   # accounts, the rules, what's off-limits
05-management-access.md   # how humans (and the agent) get in
06-ip-reference.md        # assignments and reservations
</code></pre></div></div>

<p><strong>Keep credentials out of it.</strong> Names and addresses of things, yes. Secrets,
never — the agent doesn’t handle credentials at all in this design; it runs
as the identity you gave the tunnel service, and that identity has exactly
the rights you chose. The repo stays private either way: your rack layout
is nobody’s business (yes, I just told you mine, but the difference is
that I picked what to share).</p>

<p>Every agent task starts from these docs instead of rediscovering the
network, and (this is the part I didn’t see coming) <strong>the agent
maintains them.</strong> Repatch a switch port, retire a VM, and the doc updates
in the same session, same commit. Twenty years of “I’ll document it later”
ended the month the documentation became something my staff needed to do
their job.</p>

<h2 id="step-5-skill-development--the-part-everyone-skips">Step 5: Skill development — the part everyone skips</h2>

<p>Out of the box, the agent is a talented generalist who knows nothing about
your lab and has no manners. Both problems are fixed the same way:
<strong>instruction files</strong> — and treating them like a skill you’re developing,
not a config you set once.</p>

<p>Start with <code class="language-plaintext highlighter-rouge">.github/copilot-instructions.md</code> in the docs repo. Mine boils
down to house rules:</p>

<ul>
  <li>Read the relevant doc before touching anything; cite what you checked.</li>
  <li>Read-only is free. <strong>Propose mutations before running them</strong> — exact
commands, expected effect, rollback.</li>
  <li>Never touch BMCs, identity, or firewall config. Don’t ask.</li>
  <li>Verification before “done”: show the hotfix list, the validation output,
the pod states. A summary is not evidence.</li>
  <li>Update the docs in the same session as the change.</li>
</ul>

<p>Then grow a library of <strong>prompt files</strong> — reusable skills for routines:
<code class="language-plaintext highlighter-rouge">patch-scan.prompt.md</code> (inventory update status across the Azure Local
cluster and the Hyper-V host, report only), <code class="language-plaintext highlighter-rouge">health-check.prompt.md</code>,
<code class="language-plaintext highlighter-rouge">doc-sync.prompt.md</code> (walk the inventory, verify it against reality, flag
drift). The development loop is simple: <strong>every time the agent does
something wrong or dumb, the correction goes into the instructions.</strong> It
misread which node was the cluster witness once; the docs got a clarifying
line and it never happened again. That’s the skill (yours and its)
compounding in the repo, in version control, reviewable like everything
else.</p>

<h2 id="step-6-execution--what-a-working-day-looks-like">Step 6: Execution — what a working day looks like</h2>

<p>With the pieces in place, the rhythm is almost boring, which is the point:</p>

<ul>
  <li><strong>Questions are free.</strong> “Which nodes are behind on updates?” “What’s
eating the storage pool?” A sentence goes in and a cited answer comes
out, and nothing needed approval because nothing mutated.</li>
  <li><strong>Changes are proposals.</strong> “Stage the June updates on the Azure Local
cluster” produces a plan (order, commands, expected reboots) and then
waits. I approve, it executes, and it shows receipts before the word
“done” appears.</li>
  <li><strong>The long tail is where it shines.</strong> Arc extension quirks, AKS node
image updates, the research-then-do work I used to burn evenings on —
the kind of thing the posts I wrote for
<a href="/topics/gbbcore/">our team blog</a> were made of, now executed by staff
while I review.</li>
  <li><strong>First of everything gets watched.</strong> The first time a new task type
shows up, I babysit it. The second time I spot-check. By about the
fifth time, it has become a prompt file.</li>
</ul>

<h2 id="the-honest-close">The honest close</h2>

<p>Is this more setup than pointing a chatbot at your lab? Yes, by a lot.
But it’s also the difference between a party trick and an operating model. The
pattern is isolated network, outbound-only access, docs as ground truth,
skills in version control, humans holding approvals and identity, and
verification as a gate. I think that’s the shape enterprise operations is
drifting toward. The lab is where I get to find the sharp edges first, on
hardware where the worst case is my weekend instead of someone’s business.</p>

<p>Next up in this thread: the SE350 + NVIDIA A2 edge inference build, from
BIOS to first token, and what a 16 GB GPU can honestly do at the edge.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="workbench" /><summary type="html"><![CDATA[The full setup guide: an isolated lab, VS Code Remote Tunnels, GitHub Copilot in agent mode, and the skill-building that turns an AI into a competent junior admin for your rack.]]></summary></entry><entry><title type="html">Build 2026 post-mortem: fog, first tokens, and a badge that says EXPERT</title><link href="https://leecox.pro/career/build-2026-post-mortem/" rel="alternate" type="text/html" title="Build 2026 post-mortem: fog, first tokens, and a badge that says EXPERT" /><published>2026-06-07T15:00:00-05:00</published><updated>2026-06-07T15:00:00-05:00</updated><id>https://leecox.pro/career/build-2026-post-mortem</id><content type="html" xml:base="https://leecox.pro/career/build-2026-post-mortem/"><![CDATA[<p>I’m writing this from the couch, properly wrecked, with a conference
badge on the counter that says <strong>EXPERT</strong> in a reassuring shade of blue.
(The badge printer doesn’t know about impostor syndrome. The badge
printer simply believes.) Build 2026 is in the books, and since the
whole week was equal parts teaching, booth duty, and staring at the
Golden Gate Bridge between sessions, it deserves a proper post-mortem.</p>

<p><img src="/assets/img/build2026/badge-and-bottle.jpg" alt="Microsoft Build EXPERT badge for Lee Cox, Azure GBB, next to a black water bottle with the Golden Gate Bridge rendered in ASCII art" /></p>
<p class="small">The badge believes in you. The bottle is elite swag — that's the Golden Gate in ASCII.</p>

<h2 id="the-venue-fort-mason-which-cheats">The venue: Fort Mason, which cheats</h2>

<p>This year’s Build ran on the San Francisco waterfront, in the old pier
buildings at Fort Mason — and let’s be clear, it’s unfair to put a tech
conference somewhere this pretty. Walk out of a session and the Golden
Gate is <em>right there</em>, doing its postcard routine over the water.
Alcatraz sat moodily in the fog behind the stacks of road cases like it
had been art-directed. At one point a flotilla of kayakers paddled into
the lagoon between the piers, flags up, just to watch the circus. Ten
years of convention centers did not prepare me for a venue with
seagulls and a view.</p>

<h2 id="lab-510-running-a-model--production-readiness">Lab 510: running a model ≠ production readiness</h2>

<p>My main job for the week: proctoring <strong>Lab 510 — taking LLMs from
prototype to production on AKS</strong>. The session’s opening slide is the
whole thesis, and I’d staple it to a few conference-room whiteboards
if facilities would let me: <em>running a model is not production
readiness.</em> The lab
walks through the five things that close that gap: repeatability,
routing, observability, scaling, and a consumer-friendly endpoint.
Then it makes attendees earn each one on a live cluster.</p>

<p>Proctoring is its own discipline. You’re not presenting; you spend the
session walking rows of monitors, watching a room full of people hit a
room full of <em>different</em> walls, and the walls are the curriculum.
Watching where people actually
get stuck in a hands-on AI lab is the best field research there is:
almost nobody struggles with the model. They struggle with everything
<em>around</em> the model — the plumbing, the endpoints, the “why can’t the
cluster see my deployment” moments. Which is to say: the production
part. The slide is right, and the room proved it all session, every
session.</p>

<h2 id="booth-duty-explaining-azure-linux-until-my-voice-gave-out">Booth duty: explaining Azure Linux until my voice gave out</h2>

<p>Between lab sessions I worked the showroom floor at the <strong>Azure Linux</strong>
booth with my teammate Carlos, who is both excellent company and the
kind of colleague who can hold three technical conversations while
pointing a fourth person toward coffee. Booth duty at Build is speed
chess: forty-five seconds to figure out if the person in front of you
wants the elevator answer (“it’s Microsoft’s own Linux distribution —
it runs under more of Azure than you’d guess”) or the real
conversation, which at this show was AKS node pools, edge deployments,
and a surprising number of people quietly asking about the same
small-GPU inference patterns I bang against in my own rack. The
distance between my day job and my hobby has never been shorter, and
booth conversations are where you feel it.</p>

<p><img src="/assets/img/build2026/booth-with-carlos.jpg" alt="Lee and Carlos smiling at the Azure Linux booth on the Build showroom floor" /></p>
<p class="small">Booth crew at the Azure Linux station. Note the Tux pin on the lanyard; the penguin worked the booth too.</p>

<h2 id="the-satya-and-jensen-show">The Satya-and-Jensen show</h2>

<p>Keynote highlight, no contest: <strong>Satya Nadella in person</strong>, with Jensen
Huang beaming in ten feet tall on the side screens, for the
announcement of the <strong>RTX Spark line</strong>. I’ve watched a decade of these
keynotes from home with coffee; being in the room when the NVIDIA and
Microsoft logos came up side by side hits different.</p>

<p><img src="/assets/img/build2026/satya-nvidia-stage.jpg" alt="Satya Nadella on stage in front of NVIDIA and Microsoft logos, with Jensen Huang on the side screens" /></p>
<p class="small">Satya on stage, Jensen ten feet tall on the side screens, and two logos that spend a lot of time together in my rack.</p>

<p>Whatever else you want to say about this industry’s current moment, the
two companies whose stacks I spend my days (and, let’s be honest, my
nights) wiring together were on one stage pointing the same direction.
I’ll have more to say about the small-end-of-the-GPU-market implications
once I’ve digested the announcements properly — the edge-inference
corner of my brain was taking notes the whole time.</p>

<h2 id="the-city-all-of-it">The city, all of it</h2>

<p>Two more San Francisco notes, because a post-mortem should be honest
about the whole week and not just the badge-scanned parts.</p>

<p><strong>The protesters were part of the week too.</strong> On the hill above the
venue, demonstrators hung banners about AI datacenters and the
company’s business, and you could see them from the piers all week.
I’m not going to
pretend they weren’t there, and I’m not going to pretend a conference
about deploying AI at scale has nothing to do with the questions being
raised. You can believe in the work and still believe the hard
questions deserve to ride along. They walked with me to the lab more
than once.</p>

<p><strong>And the Waymos.</strong> First ride of my life early in the week; by Friday
I’d stopped counting. I’m the guy who <a href="/topics/garage/">reprograms his own
cars</a>, so understand the gravity of this
sentence: I got into a car with no driver, no steering input from me,
and no gateway config I was allowed to touch, and within four minutes
it was the most normal thing in the world. The lane discipline is
genuinely better than half of Nashville. I have a hundred car-guy
questions about the sensor stack, but honestly I spent most of the
rides just looking out the window at the hills. I want to go back.</p>

<h2 id="the-take-homes">The take-homes</h2>

<p>A water bottle with the Golden Gate rendered in ASCII (elite swag,
whoever approved that gets a raise), a voice that needed two days of
rest, a phone full of pier photos, and the same conviction I brought
home from the lab room: the models are the easy part now. The
production engineering (the repeatability, the routing, the
observability, all the boring plumbing) is where the actual work
lives, at every scale from my SE350 to the clusters those keynote
slides were built on.</p>

<p>It was a great week with a great team in a frankly ridiculous venue,
and I’ll have more soon from the rack.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="career" /><summary type="html"><![CDATA[A week at Microsoft Build on the San Francisco waterfront — proctoring Lab 510, booth duty for Azure Linux, Satya and Jensen sharing a stage, and my first rides in cars with nobody in them.]]></summary></entry><entry><title type="html">Hello, world (again)</title><link href="https://leecox.pro/hello-world-again/" rel="alternate" type="text/html" title="Hello, world (again)" /><published>2026-05-24T10:00:00-05:00</published><updated>2026-05-24T10:00:00-05:00</updated><id>https://leecox.pro/hello-world-again</id><content type="html" xml:base="https://leecox.pro/hello-world-again/"><![CDATA[<p>Every tech blog starts with one of these posts, and most tech blogs
quietly stop posting a month or two later. I’m aware of the odds. Let’s
do it anyway.</p>

<p>I’m Lee Cox. I’m an enterprise architect at Microsoft by day, and by
night (and the occasional weekend that gets away from me) I’m a home lab
operator, a car tinkerer, and a person who cannot leave well enough
alone when a piece of hardware says “no user-serviceable parts inside.”
I’ve written plenty over the years for work — team blogs, whitepapers,
the odd conference talk — but this site is the personal one. The “(again)”
in the title is doing some work there.</p>

<p>So what goes here? Musings, mostly. On tech, on the business side of
tech (twenty-plus years in the field gives you opinions whether you
wanted them or not), on cars (a couple of projects are always in flight
in my garage), and on tinkering in general — the home lab, the tools,
the small stubborn projects that teach you more than the big planned
ones do.</p>

<p>No content calendar, no niche strategy, no promises. Posts land when
something is worth writing down. If that sounds like your kind of
corner of the internet, grab the <a href="/feed.xml">RSS feed</a> and pull up a
chair.</p>

<p>Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><summary type="html"><![CDATA[A personal corner of the internet for musings on tech, business, cars, and tinkering.]]></summary></entry><entry><title type="html">VMware Migration Quest with Microsoft</title><link href="https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft-2/" rel="alternate" type="text/html" title="VMware Migration Quest with Microsoft" /><published>2025-03-07T15:29:19-06:00</published><updated>2025-03-07T15:29:19-06:00</updated><id>https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft-2</id><content type="html" xml:base="https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft-2/"><![CDATA[<p class="has-large-font-size wp-block-paragraph"><strong>Part 2: Charting a new way</strong></p>



<p class="wp-block-paragraph">In <a href="https://gbbcore.wordpress.com/2025/02/28/vmware-migration-quest-with-microsoft/">Part 1</a> of this series, we discussed many of the motivators, needs, and planning for a VMware migration to Microsoft solutions. We also covered the quickest paths to accomplishing that type of migration into Azure for time sensitive needs. However, as we know not every workload can move to Azure. Some for governance and compliance reasons and some for technical reasons. But you’ve been asked to find ways to optimize your environment and reduce your spend. There are a bunch of ways Microsoft can help you there in Azure. And a few we can help you with outside of Azure while maintaining the advantages of cloud management.</p>



<p class="has-tertiary-background-color has-background wp-block-paragraph"><em>This post, and the one after it, will be a bit different than the first. In the first post, the options are straightforward, and the patterns well established. It’s an easier read because cloud solutions have a simpler adoption curve. Microsoft Adaptive Cloud solutions are straightforward but also nuanced and, like all on-prem solutions, have more moving parts leading to added complexity. I’ll do my best to give you the design intent, theory of operation and implementation for the options, but ultimately only you can decide what works, or doesn’t, within your organization.</em></p>



<p class="wp-block-paragraph">After taking our quick wins with the fastest path to migration with Azure, we now set off on a different leg of our migration quest, an on-premises transformation. On this path, we’ll pick up a few new party members and train some new skills while honing some older ones. The terrain is different, if familiar, and there are some steep climbs. If <a href="https://learn.microsoft.com/en-us/azure/azure-vmware/introduction">Azure VMware Solutions (AVS)</a> and <a href="https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-iaas/?msockid=11f1dd0df0d965a93706c8aaf17e64ec">Azure IaaS</a> are like Fast Travel to the best parts of the game, On-prem transformations are like grinding your favorite dungeons to level up!</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>All roads lead to Arc</strong></p>



<p class="wp-block-paragraph">The end state is important to understand to have context for the journey. Microsoft believes strongly in a single pane of glass for management. That single pane of glass is the Azure control plane powered by <a href="https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/overview">Azure Resource Manager (ARM)</a>. Azure native services benefit from the <a href="https://learn.microsoft.com/en-us/azure/azure-monitor/overview">monitoring</a>, <a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-setup-guide/monitoring-reporting?tabs=AzureMonitor">reporting</a>, <a href="https://learn.microsoft.com/en-us/azure/automation/overview">automation</a>, <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/overview">identity</a> and <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/overview">security</a> of the <a href="https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-overview">Azure Portal</a> and <a href="https://learn.microsoft.com/en-us/rest/api/azure/">API</a> experience. Resources outside of Azure weren’t really able to take advantage of these management tools in a holistic way before the advent of <a href="https://learn.microsoft.com/en-us/azure/azure-arc/overview">Azure Arc</a>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="591" data-attachment-id="1865" data-permalink="https://gbbcore.wordpress.com/2025/03/07/vmware-migration-quest-with-microsoft-2/image-52/" data-orig-file="/assets/archive/gbbcore/41887943-image-1.png" data-orig-size="1552,896" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/41887943-image-1.png" src="/assets/archive/gbbcore/41887943-image-1.png" alt="" class="wp-image-1865" /></figure>



<p class="wp-block-paragraph"><em>Azure Arc Landing Page</em></p>



<p class="wp-block-paragraph">Azure Arc in its simplest form is a projection service. It allows “things” that exist outside of Azure to be seen within Azure. That one VERY simple concept is really powerful when you consider all the class leading management capabilities and services available within Azure. It allows the same organization benefits of <a href="https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/manage-resource-groups-portal#what-is-a-resource-group">Resource Groups</a>, <a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/resource-naming-and-tagging-decision-guide">Tagging</a>, <a href="https://learn.microsoft.com/en-us/graph/use-the-api">Azure Graph</a> and <a href="https://www.geeksforgeeks.org/microsoft-azure-using-the-global-search/">Search</a> customers enjoy with Azure VMs, IaaS, PaaS services to work on things that aren’t “IN” Azure. It also provides the same security benefits with <a href="https://learn.microsoft.com/en-us/entra/fundamentals/whatis">EntraID</a> and <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/identity-management-best-practices">Identity Access Management (IAM)</a> integration. Those are just the start though. You’ll pick up a ton of additional benefits as you start to use other Azure services. Things like <a href="https://learn.microsoft.com/en-us/azure/azure-arc/servers/concept-log-analytics-extension-deployment">Azure Monitor</a>, <a href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines">Defender for Cloud</a>, <a href="https://learn.microsoft.com/en-us/azure/update-manager/workflow-update-manager">Azure Update Management</a>, <a href="https://techcommunity.microsoft.com/blog/itopstalkblog/manage-certificates-on-your-hybrid-servers-using-azure-arc-key-vault-extension/2142265">Key Vault</a>, <a href="https://learn.microsoft.com/en-us/azure/iot-operations/overview-iot-operations">IoT Services</a>, and the list goes on.</p>



<p class="wp-block-paragraph">Azure Arc works with on-prem platforms like <a href="https://techcommunity.microsoft.com/blog/azurearcblog/introducing-azure-local-cloud-infrastructure-for-distributed-locations-enabled-b/4296017">Azure Local</a>, <a href="https://learn.microsoft.com/en-us/azure/azure-arc/vmware-vsphere/overview">VMware</a>, <a href="https://learn.microsoft.com/en-us/azure/azure-arc/system-center-virtual-machine-manager/overview">SCVMM</a> and <a href="https://learn.microsoft.com/en-us/azure/azure-arc/kubernetes/overview">Kubernetes</a> clusters. It provides visibility at the OS level too not just with <a href="https://learn.microsoft.com/en-us/azure/azure-arc/servers/windows-server-management-overview?tabs=portal">Windows</a>, but also all the popular flavors of <a href="https://learn.microsoft.com/en-us/azure/azure-arc/servers/prerequisites">Linux</a>. This isn’t restricted to Virtual Machines either, physical servers are supported as well. It also helps to future proof your existing on-prem and legacy workloads by connecting them to cloud management services and concepts. This is all done through outbound connectivity over encrypted connections. It can also communicate over <a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/hybrid/arc-enabled-servers/eslz-arc-servers-connectivity">proxy, ExpressRoute, VPN and Private Endpoints</a>.</p>



<p class="wp-block-paragraph">Arc started as a single agent-based connection and has grown into an entire portfolio of services customers can consume to manage their large sprawling estates. vSphere and SCVMM have a single VM Kubernetes cluster called an <a href="https://learn.microsoft.com/en-us/azure/azure-arc/resource-bridge/overview">Arc Resource Bridge(ARB)</a> which feeds environment information into Azure. We have customers with thousands of systems being managed by Azure Arc today either centrally in a datacenter or in a distributed edge environments. All of this being done for some of their most business critical workloads.</p>



<p class="wp-block-paragraph">So, what does this have to do with on-prem VMware migration with Microsoft? It’s a fair question. The answer is <em><u>everything</u></em>. Microsoft’s on-prem solutions use Azure Arc integration as a bridge to Azure. If you want to transform your environment over to Microsoft solutions, the north-star for us is Azure. How are all of these things managed? The answer is <strong><em><u>Azure</u></em></strong>. Even the latest and greatest versions of <a href="https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-windows-server">Windows Server</a> and <a href="https://learn.microsoft.com/en-us/system-center/vmm/whats-new-in-vmm?view=sc-vmm-2025">SCVMM</a> offer direct access to Azure Arc out of the box. Microsoft also helps our customers take advantage of many Azure services through the Arc portfolio completely free if you have an active Software Assurance agreement.</p>



<p class="wp-block-paragraph">Let’s look at the first option for your on-prem workload’s that can’t go to cloud.</p>



<p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/azure/azure-local/overview"><strong>Azure Local</strong></a><strong></strong></p>



<p class="wp-block-paragraph"><strong>Price: ***</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Deploy: **</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Migrate: **</strong></p>



<p class="wp-block-paragraph"><strong>Pros: On-Prem Azure managed OEM hardware for legacy and modern apps</strong></p>



<p class="wp-block-paragraph"><strong>Cons:</strong></p>



<ul class="wp-block-list">
<li><strong>Net new hardware required</strong></li>



<li><strong>Not a datacenter virtualization replacement</strong></li>



<li><strong>Deployment and VMware workload transformation can be lengthy</strong></li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="576" data-attachment-id="1863" data-permalink="https://gbbcore.wordpress.com/2025/03/07/vmware-migration-quest-with-microsoft-2/image-51/" data-orig-file="/assets/archive/gbbcore/a88f53b9-image.png" data-orig-size="1560,878" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/a88f53b9-image.png" src="/assets/archive/gbbcore/a88f53b9-image.png" alt="" class="wp-image-1863" /><figcaption class="wp-element-caption"><em>Azure Local Solution Overview</em></figcaption></figure>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<p class="has-tertiary-background-color has-background wp-block-paragraph"><em>Given the directional nature of the solution information provided, and attempting to write for brevity, this won’t be an all-inclusive review of Azure Local or its capabilities. There is plenty of that content already available. Nor should it be treated as a substitute for official Microsoft documentation. Writers are fallible and solution options and capabilities can change over time. Please refer to the official Azure information sources linked in this post for detailed and up-to-date information.</em></p>



<p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/azure/azure-local/overview?view=azloc-24112">Azure Local</a> is a newly announced portfolio of on-prem OEM partner hardware solutions that connect directly into the Azure control-plane through Azure Arc. Today, we have a single “Connected Servers” option that was formerly known as Azure Stack HCI. It’s built from the ground up on the Azure Kernel code-base to offer an ever improving set of services and solution offerings. Over time the other two options in the family will become available. The Low-End Hardware option will be single or multiple node options with either an <a href="https://en.wikipedia.org/wiki/Azure_Linux">Azure Linux</a> deployment or Azure Local (Windows Kernel) deployment all driven from Azure. The Disconnected option will have a local management service control-plane that allows you to deploy and run Azure Local completely disconnected from Azure public cloud.</p>



<p class="wp-block-paragraph">Yeah, I know… there’s a lot there. So let’s break down what you can get right now and how. The middle “Connected Servers” options is currently the only one <a href="https://www.azuremdm.com/2024/11/06/understanding-the-azure-service-lifecycle-public-preview-and-general-availability/">Generally Available (GA)</a>, meaning you can purchase, deploy, and get support for the product. You’ll contact your preferred OEM, after looking at your options in the <a href="https://aka.ms/AzureStackHCICatalog">Azure Local Catalog</a>, who you’ll work with to size an environment. They’ll offer one or more different types of solutions. Azure Local comes in today:</p>



<ul class="wp-block-list">
<li>Validated Nodes</li>



<li>Integrated Systems</li>



<li>Premier Solutions</li>
</ul>
</div>



<p class="wp-block-paragraph">Validated nodes are the roll your own option for customers. The OEM has tested the hardware nodes and developed a driver package to work with Azure Local, making it available for customers to use. It’s supported by them. If you have an issue you’ll need them to troubleshoot it. The Integrated Systems are a step up and offer solution level support from Microsoft and the OEM with testing multiple times per year. There are also optional support and delivery services uplifts the OEMs will usually provide. The Premier Solutions are co-engineered with Microsoft and offer a bunch of coordinated service offerings, OPEX purchase options, and advanced capabilities. Pricing and budgets will increase, around 10-20% per tier list price, as you move to the right. Please check with your OEMs for detailed pricing information.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="576" data-attachment-id="1864" data-permalink="https://gbbcore.wordpress.com/2025/03/07/vmware-migration-quest-with-microsoft-2/image-51/" data-orig-file="/assets/archive/gbbcore/3bfb2ab6-image-2.png" data-orig-size="1560,878" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/3bfb2ab6-image-2.png" src="/assets/archive/gbbcore/3bfb2ab6-image-2.png" alt="" class="wp-image-1864" /><figcaption class="wp-element-caption"><em>Detailed Azure Local Offering options</em></figcaption></figure>



<p class="wp-block-paragraph"><strong>Going Rouge</strong></p>



<p class="wp-block-paragraph">It’s important to point out that Azure Local does <strong><em><u>not</u></em></strong> have any ability leverage existing or reuse existing hardware. Its greenfield only. Our OEMs have worked very hard to offer solutions aligned with the latest and greatest hardware capabilities available with Azure for CPUs, GPUs, and Disk performance of the VMs and other services you deploy across Azure Local and Azure public cloud. Mismatched capabilities often leads to a poor customer experience (and performance), which no one wants.</p>



<p class="wp-block-paragraph">Sure, you CAN cobble something together if you have a vendor’s bill of materials for Azure Local, access to their firmware/drivers and pull down the image from the Azure portal, but it WILL bite you in a few ways. First, very few OEMs use or make available for customers their general CTO/BTO server SKUs for Azure Local. Most OEMs preload the OS onto the systems, level set the firmware for you, and configure optional firmware settings for an Azure Local deployment. In doing so, they typically publish different SKUs compared to the normal stuff you buy from them or get through a distributor. Even if it’s based off the same hardware platform. This causes a supportability mis-match when you put an Azure Local image on a normal server. The second issue is the config. Azure Local is a Hyperconverged solution which means specific NICs, storage controllers and discs in a very specific configuration chosen by the manufacturer were tested, validated, and approved by Microsoft. Trying to back into those selections is a hard road. Thirdly, the support matrix for Azure Local and Windows Server IS different making finding the compatible parts, firmware, and drivers much more difficult. CAN you do it? Sure. Will it be supported? Please check with your OEM before you start, but most likely <strong><em><u>No</u></em></strong>. So… that effort could be good for lab testing and kicking the tires, bad for production. That said, you can learn SO much from that Awful, Horrible, No Good, Very Bad path. Trust me.</p>



<p class="has-tertiary-background-color has-background wp-block-paragraph">GEEK warning! (Things are about to get VERY technical)</p>



<p class="wp-block-paragraph"><strong>Origin Story</strong></p>



<p class="wp-block-paragraph">The Azure Local Hypervisor is an Azure Windows kernel branch specifically designed to deliver hyperconverged services for Compute, Storage and Networking. This is a Hyper-V based solution as almost all Azure solutions are. It uses mostly similar Failover Clustering, Storage Spaces Direct, and optionally Microsoft’s SDN stack found in Windows Server 2025. This is all derived from the original <a href="https://www.microsoft.com/en-us/windows-server/blog/2018/02/20/the-technical-value-of-wssd-validated-hci-solutions-part-1">Microsoft WSSD reference architecture</a> published for Windows Server 2016. That was the foundation for the very first Azure Stack products too. There have been a BUNCH of changes/enhancements/rationalizations since that initial architecture release.</p>



<p class="wp-block-paragraph">Why is it important that this comes from an Azure branch vs say the Windows Server branch of the kernel if they use the same technologies?</p>



<p class="wp-block-paragraph">There are a few reasons:</p>



<ul class="wp-block-list">
<li>Azure dev cycles allow for more rapid enhancements than every couple of years for boxed products</li>



<li>We can decouple the OS build version from the feature capabilities and iterate</li>



<li>Azure support is provided with Azure solutions directly in the portal</li>
</ul>



<p class="wp-block-paragraph">Microsoft’s first pass at an Azure managed solution was called Azure Stack, later renamed <a href="https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-overview?view=azs-2501">Azure Stack Hub</a>. It spawned a family of offerings culminating in <a href="https://azure.microsoft.com/en-us/blog/announcing-azure-stack-hci-a-new-member-of-the-azure-stack-family/?msockid=10cd038de33c6c4527d41625e23d6d08">Azure Stack HCI</a>. Azure Local is an improved version of that product family. What we found with Azure Stack was customers needed greater velocity from us to enhance product capabilities. Faster even than every six months or a year. As a result, Microsoft has since moved away from the Windows Server and Client OS release cadence of Azure Stack HCI such as <a href="https://support.microsoft.com/en-au/topic/release-notes-for-azure-stack-hci-version-21h2-5c5e6adf-e006-4a29-be22-f6faeff90173">21H2</a>, <a href="https://learn.microsoft.com/en-us/azure/azure-local/release-information?view=azloc-24113">22H2</a>, 23H2, etc. being the major releases. Those are still included from a Core OS perspective, but the solution enhancements are now done on Azure release train cadences of every few months. Similar to how the original Azure Stack (Hub) product is developed. You can go here to learn more about the changes: <a href="https://learn.microsoft.com/en-us/azure/azure-local/release-information-23h2?view=azloc-24112">Azure Local, version 23H2 release information &#8211; Azure Local | Microsoft Learn</a></p>



<p class="wp-block-paragraph"><strong>Back to the Future</strong></p>



<p class="wp-block-paragraph">The platform is being enhanced much more rapidly on this new release cadence. In fact, upgrading from an Azure Stack HCI releases like 22H2 to the current build moves you directly into the new Azure Local release train with all those new features. Also 23H2 and the Azure Local name change should be treated like a new version of the product by adopting this methodology. As a result, these enhancements will need to be adopted by your organization as the product evolves. This is a VERY different requirement than version changes to vSphere products. If that makes you uncomfortable, we completely understand. Adopting features at a fast clip can be jarring and require different testing and roll out plans. It’s worth the time to discuss this internally and decide if adopting change at the speed of Azure is right for your business. Here are some of the big things you’ll get in just over a years’ time if so:</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1871" data-permalink="https://gbbcore.wordpress.com/2025/03/07/vmware-migration-quest-with-microsoft-2/roadmap-2/" data-orig-file="/assets/archive/gbbcore/21fbdb55-roadmap-1.jpg" data-orig-size="644,364" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Roadmap" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/21fbdb55-roadmap-1.jpg" src="/assets/archive/gbbcore/21fbdb55-roadmap-1.jpg" alt="" class="wp-image-1871" /><figcaption class="wp-element-caption"><em>Azure Local public roadmap &#8211; March 2025</em></figcaption></figure>



<p class="wp-block-paragraph"><strong>Deployment</strong></p>



<p class="wp-block-paragraph">Azure Local is cloud deployed and managed from the start. Where Azure Stack HCI was connected to Azure as one of the final deployment steps. It’s not possible to run this product without connecting to Azure. The Azure Local deployment process is a set of ARM templates or an Azure portal based wizard experience that will build, validate, and deploy the infrastructure remotely. There’s a clear separation of the hardware deployment actions and the solution deployment actions. This allows greater flexibility and separation of roles for our customers.</p>



<p class="wp-block-paragraph">All of the nodes will need to have an identical configuration. They will need to be installed, cabled, and powered on. Someone will connect to them and register with Azure Arc. Please don’t deviate from the documented deployment process. Installing Non-OEM 3<sup>rd</sup> party software on the hosts is not supported. In fact, outside of installing drivers and firmware or configuring a hostname, IP, DNS (proxy if required) and Azure Arc registration. Do nothing else locally. After the nodes show in Azure, you go straight into the deployment wizard to form the cluster. There’s a lot of flexibility in how you configure the networking topology and storage configuration. Many customers chose to replicate their vSphere node connectivity. Just know that the storage network should be redundant and it doesn’t need to have unique IPs or a gateway per cluster, but the broadcast (L2) space should be for one cluster only. Make sure not to get your wires crossed in the process! There are also built-in defaults available for security and storage to help first time users deploy in a secure and scalable solution.</p>



<p class="wp-block-paragraph"><strong>Day 2 Operations</strong></p>



<p class="wp-block-paragraph">Management of the cluster and workloads can all be done within the Azure portal under the Arc landing page. We have a bunch of tools outside of just the deployment workflows though. We’ve integrated cluster management with <a href="https://learn.microsoft.com/en-us/azure/azure-local/manage/vm?view=azloc-24113">Windows Admin Center (WAC)</a> directly in the portal. We’ve connected <a href="https://learn.microsoft.com/en-us/azure/azure-local/update/azure-update-manager-23h2?view=azloc-24113&amp;tabs=azureupdatemanager">Azure Update Manager</a> with a cluster specific view which will perform a coordinated update process across the nodes to keep workloads running. We’ve worked with our OEMs to integrate their updates into those update workflows as well. You can also deploy VMs the same way you do within Azure (<a href="https://learn.microsoft.com/en-us/azure/azure-local/manage/create-arc-virtual-machines?view=azloc-24113&amp;tabs=azurecli">Portal, API, CLI and Automation</a>) using Azure images to your own locations. You can manage those <a href="https://learn.microsoft.com/en-us/azure/azure-local/manage/manage-arc-virtual-machines?view=azloc-24113&amp;tabs=windows">VMs directly within the portal</a> as if they are Azure VMs (because they are, they run on an Azure platform). What isn’t able to be done today is cluster management operations via command line or programmatically within Azure Resource Manager (ARM). Those can be done interactively within the WAC, but if you want to automate something related to the cluster you’ll need to drop back to PowerShell or a PowerShell integrated automation tool, at least for the time being. This is being worked on, but it’s not available today. WAC within the Azure portal isn’t the only management option available. You can also deploy WAC locally for management should it be required. This can be helpful if your environment become disconnected from Azure. It’s the same web based experience just running locally. Don’t worry, all your running workloads will continue to operate without the cloud control plane. Azure Local can run disconnected from Azure for up to 30 days. <a href="https://learn.microsoft.com/en-us/system-center/vmm/manage-azure-stack-hci?view=sc-vmm-2025&amp;source=recommendations">SCVMM</a> is also an option for our System Center customers to managed Azure Local. It offers scalable cluster management across a large number of Azure Local clusters.</p>



<p class="wp-block-paragraph"><strong>Do’s and Don’ts</strong></p>



<p class="wp-block-paragraph">Another thing to note, Azure Local isn’t a product primarily targeted for datacenter virtualization or high concentration compute. The published <a href="https://learn.microsoft.com/en-us/azure/azure-local/concepts/system-requirements-23h2?view=azloc-24113#machine-and-storage-requirements">maximum cluster size</a> is 16 nodes. The practical limit, which is determined by our OEMs, is really around 6-8 nodes per cluster. The majority though are being deployed as 2-3 node clusters for point compute needs in edge locations or for appliance like workloads. Why 6-8 instead 16? It’s a matter of physics and money.</p>



<p class="wp-block-paragraph">Almost all of these Azure Local clusters purchased today are deployed with NVME storage. The solution being a hyperconverged design where all the disks are managed by the CPUs in a pool across the cluster storage network fabric. NVME transmits data at PCIE speed replicating across a cluster disks in real-time. It makes the solution very performant, but with each node added, the network traffic increases exponentially. Throw in VM migration traffic between the nodes and network requirements can easily approach or exceed the limits of 100Gb ethernet with higher node counts. It can get expensive quickly. Microsoft has designed a lower cost option though, 2-4 Nodes can be <a href="https://learn.microsoft.com/en-us/azure/azure-local/plan/three-node-switchless-two-switches-two-links?view=azloc-24113">directly connected</a> without switches. This saves you money and network complexity. Azure Local also doesn’t support any SAN attached, SAS, or MPIO storage or perform any type of integrated SAN fabric management by default.</p>



<p class="wp-block-paragraph">Another factor is management, the solution being Azure managed means there’s a management controller deployed automatically when the cluster is created. This controller is the same type used for SCVMM and vSphere, the <a href="https://learn.microsoft.com/en-us/azure/azure-arc/resource-bridge/release-notes">Arc Resource Bridge</a>. Today, there’s a 1:1 mapping for the ARB and Azure Local cluster resource. This creates a single island of &nbsp;management per cluster. It can be really good for remote or distributed sites, a little unwieldy within the datacenter.</p>



<p class="wp-block-paragraph">As an example, consider a datacenter with 8-10 racks in a single row. You can fit two clusters in each rack or spread them across racks for redundancy. That would be up to 20 different Azure management endpoints per row! There are practical management limits at play here. This is the primary <a>reason why</a> we also support SCVMM as a management option for Azure Local.</p>



<p class="wp-block-paragraph">So, if you don’t put Azure Local in a datacenter, where do you put it? The most common customer demand we see is for deployments outside of the datacenter. These would be small to medium size businesses, distribution centers, field offices, retail, manufacturing, and medical facilities are all good candidates. You CAN deploy in a datacenter, however it’s not intended to replace any existing datacenter virtualization layer. The most common use for datacenter deployments are <a href="https://learn.microsoft.com/en-us/azure/aks/aksarc/aks-whats-new-23h2">Kubernetes clusters</a>, <a href="https://learn.microsoft.com/en-us/azure/virtual-desktop/azure-local-overview">VDI/DaaS workloads</a>, <a href="https://learn.microsoft.com/en-us/azure/iot-operations/overview-iot-operations">IoT workloads</a>, <a href="https://techcommunity.microsoft.com/blog/azurearcblog/extending-azures-ai-platform-with-an-adaptive-cloud-approach/4303589">AI workloads</a> and applications that need to live next to other system types that can’t leave the datacenter like Mainframes, Midframes and the like. In other words, contained use cases where you need a specific compute profile.</p>



<p class="wp-block-paragraph">If you’ve made it this far congrats! I usually lose some players a few paragraphs back. If you decide that you want to try out Azure Local, what does that look like? The most direct path is to go here: <a href="https://jumpstart.azure.com/azure_jumpstart_hcibox/getting_started">Azure Arc Jumpstart: Azure Local HCIBox</a>. This will give you the general look and feel that you can deploy today. You can also review the relevant <a href="https://learn.microsoft.com/en-us/azure/azure-local/?view=azloc-24113">documentation</a>, <a href="https://learn.microsoft.com/en-us/azure/azure-local/release-information-23h2?view=azloc-24113#azure-local-release-information-summary">release notes</a>, and <a href="https://learn.microsoft.com/en-us/azure/azure-local/whats-new?view=azloc-24113">enhancements</a>. Once you’ve kicked the tires a bit, reach out to your reseller, OEM rep, or Microsoft Partner to get started on the path.</p>



<p class="wp-block-paragraph">Depending on the selections you make, installation services may be optional or included for your deployment. I highly recommend you take advantage of them. Implementation of a cloud controlled infrastructure is a VERY different thing than a VMware vSphere environment. There is a lot of planning required. Depending on your organization it could take a while to get the needed approvals for a purchase and working through the Azure endpoint requirements, setting up proxy exceptions, or Private Endpoint DNS configuration. There are also services in preview for Azure like the Azure Arc Gateway which can help, but those require configuration and planning also.</p>



<p class="wp-block-paragraph"><strong>Just say no</strong></p>



<p class="wp-block-paragraph">A note on a VMware head-to-head evaluations. When we get requests for these, I actively avoid them. As do many others I know. Azure Local is a different animal than VMware Cloud Foundation (VCF) or standard vSphere. Sure, they both host VMs and Containers, can be had as an HCI configuration, and they are both offered through OEMs as a packaged solution. Walk like a Duck, talk like a Duck and all. That’s really where the similarities end though. This is all a matter of the perspective and history of each offering. VMware has spent decades perfecting the on-prem virtualization space. Differentiating themselves with a bunch of solution capabilities unique to them. There are tons of features it will have which Azure Local simply won’t. Microsoft has spent decades perfecting our cloud virtualization platform (Azure) and offering bundled virtualization capabilities with Windows Server Hyper-V. There’s tons of stuff we can do that VMware can’t. And, I know what you’re thinking, “Great, just give the list for each or product comparison matrix.” Unfortunately, there isn’t one. At least not one published by Microsoft. These products aren’t direct competitors. It really is an Apples and Oranges comparison.</p>



<p class="wp-block-paragraph">&nbsp;I always encourage our customers to focus on business and hard technical requirements.</p>



<ul class="wp-block-list">
<li>What do you need it to do?</li>



<li>How do you need it to perform?</li>



<li>Does it meet your resiliency needs?</li>



<li>Do the solutions meet those requirements?</li>



<li>What’s the CAPEX or OPEX cost to implement the solution?</li>



<li>How is it to manage?</li>



<li>How much of your environment is in the cloud or moving there soon?</li>
</ul>



<p class="wp-block-paragraph">We know you love VMware. That’s why it’s a successful product run by almost <a>all of</a> our customers. If your evaluation is for a feature-by-feature VMware replacement, I’ll save you a bunch of time. Azure Local won’t succeed. If you look at Azure Local as a cloud managed on-prem <a>compute</a> platform, it does that really well. It’s your business critical local compute for when everything else is moved to Azure.</p>



<p class="wp-block-paragraph"><strong>The End</strong></p>



<p class="wp-block-paragraph">Seismic market shifts, like the one we’re in now, are an opportunity to re-evaluate the long-term solution strategy for your business. We think that Azure Local does a great job of helping our customers accelerate their transition to cloud while addressing those portions of the business which can’t be easily moved.</p>



<p class="wp-block-paragraph">There are a whole set of other topics which come up after a customer decides to move down this path. How can I migrate my workloads, what are the costs involved, how can we move quickly with as little disruption as possible? Or alternatively, you convinced me that Azure Local isn’t quite right for me but how about that Hyper-V thing you guys used to talk about all the time? What does that path look like?</p>



<p class="wp-block-paragraph">Those topics and a few others will be included in the next part of this series. Thanks so much for reading! I hope you found it valuable.</p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Part 2: Charting a new way In Part 1 of this series, we discussed many of the motivators, needs, and planning for a VMware migration to Microsoft solutions. We also covered the quickest paths to accomplishing that type o]]></summary></entry><entry><title type="html">VMware Migration Quest with Microsoft</title><link href="https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft/" rel="alternate" type="text/html" title="VMware Migration Quest with Microsoft" /><published>2025-02-28T15:37:59-06:00</published><updated>2025-02-28T15:37:59-06:00</updated><id>https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft</id><content type="html" xml:base="https://leecox.pro/gbbcore/vmware-migration-quest-with-microsoft/"><![CDATA[<p class="has-large-font-size wp-block-paragraph"><strong>Part 1: The fastest path to victory</strong></p>



<p class="wp-block-paragraph">Your leaders are asking you to perform a miracle, but to do it you’ll have to embark on an ambitious quest. We know, you’re stuck between a rock and a hard place. The relationship is changing, and costs are rising. You’re trying to find a path forward for your existing environment.</p>



<p class="wp-block-paragraph">So, what are your options with Microsoft? Luckily, you have a bunch of different ways to skin this particular dragon. The first step in any direction is to assess the terrain. Where are you now and what tools do you have at your disposal without spending any gold? Free <a href="https://en.wikipedia.org/wiki/Loot_(video_games)">loot</a> will always beat merchant bought when it comes to solutions. This goes for software, hardware, human resources, and swords. Take stock of what you’re running, where, and how long you need to operate it.</p>



<p class="has-large-font-size wp-block-paragraph"><strong><em>Failing to Plan… (</em></strong><a href="https://www.youtube.com/watch?v=mLyOj_QD4a4"><strong><em>Leeroy….Jenkins</em></strong></a><strong><em>!)</em></strong></p>



<p class="wp-block-paragraph">You can’t find a solution without first understanding what the goal should be. You need a plan your journey. The first part of a good plan is to understand your organizational goals, needs and requirements. What does victory look like when you get to the end? Start with that and work backwards. The solutions and technologies selected will be support characters (<a href="https://en.wikipedia.org/wiki/Non-player_character">NPCs</a>) in your party along your VMware Migration Quest. And you can’t start a quest without some good <a href="https://www.youtube.com/watch?v=ztP1RknUpd4">music</a>!</p>



<p class="wp-block-paragraph">Is there stuff you’ve been putting off? You know, things that you just never got around to taking care of? A bunch of tools and materials you never cleared out weighing you down? I find when I need to do one big thing, it’s always better to find a way to do three or more smaller ones at the same time. The payoff is bigger, and the value is greater. So, look around your organization for all those extra things and put them on the board. Work in as many as you can to sweeten the pot. Don’t let them turn into long boring <a href="https://en.wiktionary.org/wiki/sidequest">sidequests</a> though.</p>



<ul class="wp-block-list">
<li>Do you need to decommission systems?</li>



<li>Co-location or DR contracts that you need to evaluate?</li>



<li>Is there planned spending for a hardware refresh you can reallocate?</li>
</ul>



<p class="wp-block-paragraph">Rationalizing the organization’s needs and determining what can, should, or shouldn’t be moved is a great first step. Once you have a handle on that, start looking at the hard/soft dates you need to transition. Can you run without support for your perpetual licenses or purchase 3<sup>rd</sup> Party support as a bridge? This will build out the roadmap and you can layer resourcing on top.</p>



<p class="wp-block-paragraph">Also, this can’t be understated, the best migration/transition is the one you don’t have to make. So, what’s the number? What is the company willing to accept to keep the status quo? It can’t just be a few % less than the current renewal, or maybe it can. Take some time and have the discussion internally to understand if you’re willing to continue the relationship now that it’s evolving. If you are, great! That’s the right decision for your organization. Trust me, we won’t be upset. We’ll probably <em>NEVER </em>know. It will be very difficult to capture and hold the attention of any technology partner who may feel as though you’re just going through the motions. We do see these situations quite often and we talk to our account teams about customer commitment as a qualifying factor for engagement and investment.</p>



<p class="wp-block-paragraph">Up to now, I’ve sounded like a therapist (and <a href="https://en.wikipedia.org/wiki/Massively_multiplayer_online_role-playing_game">MMORG</a> player), <em>I KNOW</em>. There’s a good reason for it. A lot of customers we talk to are reacting to a vendor relationship going sour. We see them go through the stages of grief in real-time. Microsoft needs to know what that <em>Acceptance</em> stage looks like for your company and so do you. Once that is known, we can have a VERY productive conversation about the options available.</p>



<p class="wp-block-paragraph">We often recommend starting discussions with business owners and technical stakeholders in a workshop, <a href="https://www.microsoft.com/en-us/hub">Innovation Hub</a> or EBC session, to understand the objectives, requirements, and help educate us on your estate. Sometimes there’s resistance to this because it requires time from us and you. In other words, commitment! It can be difficult to make time investments if you’re unsure of the path. If this level of engagement is too much for any reason, it can be informative on its own. You can save a bunch of time by cutting that check to Broadcom and going about your day.</p>



<p class="wp-block-paragraph">If you do choose to spend that time with us, thank you! We’ll start by understanding your needs, goals and business outcomes. This will usually involve an assessment and connecting a few systems, like your vCenter instance, into a tool we call <a href="https://learn.microsoft.com/en-us/azure/migrate/migrate-services-overview">Azure Migrate</a>. Then we’ll start looking at the data along with an <a href="https://www.robware.net/home">RVTools</a> export to understand the current state for planning the migration. There are a few different primary paths the conversation can go down and one or more solutions may be the right answer for your specific needs and goals.</p>



<p class="has-large-font-size wp-block-paragraph"><strong><em>Choosing a path for the journey</em></strong></p>



<p class="wp-block-paragraph">Microsoft has made significant investments in our public cloud platform, <a href="https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-azure">Azure</a>, to deliver the best-in-class experience for our customers. We’ve delivered <a href="https://learn.microsoft.com/en-us/entra/fundamentals/whatis">identity</a>, <a href="https://learn.microsoft.com/en-us/azure/governance/management-groups/azure-management">management</a>, <a href="https://learn.microsoft.com/en-us/azure/azure-monitor/overview">monitoring</a>, <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/overview">security</a>, and <a href="https://learn.microsoft.com/en-us/azure/automation/overview">automation</a> for operating and moving your workload quickly and efficiently into the cloud. These investments help to deliver tangible business and operational advantages for our customers compared to continuing to run their environment on their own. They include using an orchestrator and API driven platform called <a href="https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/overview">Azure Resource Manager</a> to collect various services and deploy them through a template based system.</p>



<p class="wp-block-paragraph">The declarative nature of the platform allows customers to move quickly, working in minutes and hours what used to take weeks and months. Time is money as they say. You can also respond in a more dynamic way with the service capacity in Azure. Instead of planning for peak usage, you can plan for temporary additional capacity. Allowing you to right size the workload for the business instead of planning for the worst. This is why rationalization that I mentioned previously is so important. If not done, you end up running the same as before with a bigger bill. Azure also frees up valuable time for your resources to focus on business needs instead of physical plant <a href="https://www.gartner.com/en/information-technology/glossary/mac-moves-adds-and-changes?form=MG0AV3">MAC</a> activities. Azure is an Always on Programmable Infrastructure with millions of combinations.</p>



<p class="wp-block-paragraph">There’s also a bunch of great ways to get started with Azure leveraging the power of our <a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/">Azure Landing Zones</a> and <a href="https://azure.microsoft.com/en-us/solutions/cloud-enablement/cloud-adoption-framework">Cloud Adoption Frameworks</a> to get started and scale. Now, let’s look at some of the solution options available for this VMware Migration Quest.</p>



<p class="wp-block-paragraph" style="font-size:clamp(17.905px, 1.119rem + ((1vw - 3.2px) * 1.278), 28px);"><a href="https://learn.microsoft.com/en-us/azure/azure-vmware/introduction"><strong>Azure VMware Solution</strong></a><strong></strong></p>



<p class="wp-block-paragraph"><strong>Price: ****</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Deploy: ****</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Migrate: ****</strong></p>



<p class="wp-block-paragraph"><strong>Pros: Fastest Solution Deployment and Migration Path</strong></p>



<p class="wp-block-paragraph"><strong>Cons: No workload modernization and limited hardware configurations</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="602" data-attachment-id="1846" data-permalink="https://gbbcore.wordpress.com/2025/02/28/vmware-migration-quest-with-microsoft/image-49/" data-orig-file="/assets/archive/gbbcore/af5ae479-image-2.png" data-orig-size="1560,918" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/af5ae479-image-2.png" src="/assets/archive/gbbcore/af5ae479-image-2.png" alt="" class="wp-image-1846" /></figure>



<p class="wp-block-paragraph">The first option on our journey is the fastest path to value. An as-is move into Azure with Azure VMware Solution. It’s like taking a portal to a part of the game you’ve already played and knowing all the best places to level up and get to loot. It’s a straightforward and efficient way to migrate your existing environment without much of a lift. It requires a few steps in the portal to deploy the infrastructure, usually within a few hours. It will spin up a VMware vSphere environment with the required number of ESXi nodes, vSAN, vCenter, and NSX-T. From there, you get to use all the tools you know and love from VMware to replicate the VMs into your new AVS cluster(s).</p>



<p class="wp-block-paragraph">Your account team will likely engage an SME in the service to help you understand the sizing options, vSphere services available, and provide a consumption estimate from the <a href="https://azure.microsoft.com/en-us/pricing/calculator">Azure Pricing Calculator</a> to help you get an idea of the service cost. The more detail you provide, the better we can estimate so please engage in as much detail as possible. No one likes going into a conversation expecting X price and then being surprised with Y price as the conversation evolves and things get added.</p>



<p class="wp-block-paragraph">Your account team and the Azure Specialist will go over things like the recommended over-subscription rate for the solution, reserved instances, and rationalization all to help you maximize the usage and minimize the cost.</p>



<p class="wp-block-paragraph">We have many customers who choose to go down this path. Especially if they can move their entire VMware environment. It’s business as usual with Azure as your datacenter. There is a lot of value that can been driven once those workloads are in Azure with our other Azure services like AI, Security, and PaaS offerings. We see a lot of customers start to move components into other Azure services once they are running on AVS to further optimize. It’s a smoother transition if all the data is in the same place on the same network.</p>



<p class="has-large-font-size wp-block-paragraph"><strong><em>Going Native</em></strong></p>



<p class="wp-block-paragraph" style="font-size:clamp(17.905px, 1.119rem + ((1vw - 3.2px) * 1.278), 28px);"><a href="https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-iaas"><strong>Azure IaaS</strong></a><strong></strong></p>



<p class="wp-block-paragraph"><strong>Price: ****</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Deploy: ****</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Migrate: ***</strong></p>



<p class="wp-block-paragraph"><strong>Pros: Limitless hardware options and granular cost controls</strong></p>



<p class="wp-block-paragraph"><strong>Cons: No workload modernization and slower migration time</strong></p>



<p class="wp-block-paragraph">The next path is a direct migration to Azure IaaS infrastructure. You can start on this path now in the Azure portal through our free Azure Migrate service. Simply click the Icon and start your first project. You’ll need to deploy the data collector, then it will ingest a lot of information from your vSphere environment. Once the data collection is up and running you can build detailed assessments to determine the cost, size, and tools to make a move into Azure IaaS VMs.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="626" height="447" data-attachment-id="1845" data-permalink="https://gbbcore.wordpress.com/2025/02/28/vmware-migration-quest-with-microsoft/image-48/" data-orig-file="/assets/archive/gbbcore/aa1329d8-image-3.png" data-orig-size="626,447" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/aa1329d8-image-3.png" src="/assets/archive/gbbcore/aa1329d8-image-3.png" alt="" class="wp-image-1845" /></figure>



<p class="wp-block-paragraph">We see a few customers choose the IaaS path if they have specific requirements which aren’t met within AVS. Maybe you need <a href="https://azure.microsoft.com/en-us/blog/azure-virtual-machines-with-ampere-altra-arm-based-processors-generally-available">ARM VMs</a>, a bunch of <a href="https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction">Blob storage</a>, direct access to <a href="https://learn.microsoft.com/en-us/azure/virtual-machines/sizes/overview?tabs=breakdownseries%2Cgeneralsizelist%2Ccomputesizelist%2Cmemorysizelist%2Cstoragesizelist%2Cgpusizelist%2Cfpgasizelist%2Chpcsizelist#gpu-accelerated">GPUs</a>, or <a href="https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/overview">Scale Sets</a>. You may want to take advantage of best-in-class solutions like <a href="https://learn.microsoft.com/en-us/azure/aks/what-is-aks">Azure Kubernetes Service</a> moving off Tanzu. Things like those would fall outside of standard AVS deployments. Those workloads can still be moved into Azure; you’ll just migrate them into Azure directly vs running within vSphere. That’s the power and flexibility with using Azure vs running on-prem. All of this comes on a single monthly bill.</p>



<p class="wp-block-paragraph" style="font-size:clamp(17.905px, 1.119rem + ((1vw - 3.2px) * 1.278), 28px);"><a href="https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-paas"><strong>Azure PaaS</strong></a><strong></strong></p>



<p class="wp-block-paragraph"><strong>Price: ***</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Deploy: ****</strong></p>



<p class="wp-block-paragraph"><strong>Speed to Migrate: **</strong></p>



<p class="wp-block-paragraph"><strong>Pros: Low overhead for workload deployment and lowest cost</strong></p>



<p class="wp-block-paragraph"><strong>Cons: Resource intensive to refactor applications and less flexible than IaaS</strong></p>



<p class="wp-block-paragraph">If you’re willing to do some additional leg work and shed the hypervisor layer completely. Customers can further optimize their environments by looking at any number of our PaaS services. Azure Migrate will make recommendations and provide you with options for some of these also. You can use <a href="https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/sql-managed-instance-paas-overview?view=azuresql">Azure SQL MI</a>, <a href="https://learn.microsoft.com/en-us/azure/app-service/overview">Azure App Services</a>, <a href="https://learn.microsoft.com/en-us/fabric/fundamentals/microsoft-fabric-overview">Azure Fabric</a>, <a href="https://learn.microsoft.com/en-us/azure/ai-services/what-are-ai-services">AI</a> or <a href="https://azure.microsoft.com/en-us/solutions/iot">IoT solutions</a>. These are for those workloads which are well understood and documented within your organization. Not everything can go down this path for a variety of reasons, but we do see customers skip the IaaS steps and go straight to PaaS services for the right workloads. The big contributor to success here is availability, timing, data and skills. Refactoring an application isn’t for the faint of heart even in the best of times… and these aren’t those times.</p>



<p class="wp-block-paragraph"><strong>It’s all about the timing…</strong></p>



<p class="wp-block-paragraph">If you need to get off your existing VMware licensing in say less than 6 months, then AVS is really the best bet. We’ve seen some VERY motivated customers move even faster. If you have more time, at least 6-12 months to pilot, plan and test. Then you might consider a set of IaaS or even PaaS services to run some of your applications. There isn’t one right answer here and it depends on your specific environment and requirements. You can take a mixed approach as time allows. Moving the big rocks, purchasing a fixed amount with additional capacity bolted on that will sunset is also an option if time allows.</p>



<p class="wp-block-paragraph">These are the short paths to victory. Azure is a set of ready-made solutions to help you along the way. You know the old saying, “You can have it Fast, Cheap, or Easy. Pick two.” That very much applies here as well for the different solution options. Azure has some very cool cost-saving features for our customers. We offer discounts for <a href="https://learn.microsoft.com/en-us/marketplace/azure-consumption-commitment-benefit">Azure commitments</a>, <a href="https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/understand-vm-reservation-charges">Reserved Instances</a>, <a href="https://azure.microsoft.com/en-us/pricing/offers/savings-plan-compute">Savings Plans</a>, <a href="https://learn.microsoft.com/en-us/windows-server/get-started/azure-hybrid-benefit?tabs=azure">Azure Hybrid Benefits</a>, pricing and estimating tools with our <a href="https://azure.microsoft.com/en-us/pricing/calculator">Azure Pricing Calculator</a>, <a href="https://learn.microsoft.com/en-us/azure/migrate/migrate-services-overview">Azure Migrate</a> and built-in cost analysis tooling within your subscriptions to help control your spending. Reach out to your Microsoft Account Team to learn more.</p>



<p class="wp-block-paragraph">I hope this first part of the series has helped you understand the quickest way to get to the end goal of your VMware Migration Quest. There’s a lot in here and a lot of ground covered. We do know that cloud won’t always be an option for everyone or every workload. In the next part, we’ll discuss our <a href="https://azure.microsoft.com/en-us/solutions/adaptive-cloud">Adaptive Cloud</a> options that exist outside of Azure and how Microsoft can help there too. There are several ways you can win the day and emerge victoriously. You might just have to pick your battles along the way!</p>



<p class="wp-block-paragraph">Thanks for reading!</p>



<p class="wp-block-paragraph"></p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Part 1: The fastest path to victory Your leaders are asking you to perform a miracle, but to do it you’ll have to embark on an ambitious quest. We know, you’re stuck between a rock and a hard place. The relationship is c]]></summary></entry><entry><title type="html">Roll your own AVD on HCI deployment – Part 4: Turn it up!</title><link href="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/" rel="alternate" type="text/html" title="Roll your own AVD on HCI deployment – Part 4: Turn it up!" /><published>2024-04-01T14:54:02-05:00</published><updated>2024-04-01T14:54:02-05:00</updated><id>https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up</id><content type="html" xml:base="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/"><![CDATA[<p class="wp-block-paragraph">Lee Cox &#8211; Advanced Migration GBB</p>



<p class="wp-block-paragraph">Welcome back to Part 4 of our Blog series. Thanks for taking the time to follow along. So? How did it go? Did you get through the whole thing with only one pass? I know I didn&#8217;t… 😉</p>



<h2 class="wp-block-heading"><strong>Post-Deployment Shenanigans</strong></h2>



<p class="wp-block-paragraph">Once you are done, you&#8217;ll have a bunch of new elements within your Resource Group. Here&#8217;s an idea of what it should look like:</p>



<figure class="wp-block-image size-full is-resized"><img data-attachment-id="1673" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-1-8/" data-orig-file="/assets/archive/gbbcore/f1ebc11a-image-1.jpg" data-orig-size="710,757" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/f1ebc11a-image-1.jpg" src="/assets/archive/gbbcore/f1ebc11a-image-1.jpg" alt="" class="wp-image-1673" style="aspect-ratio:1;width:840px;height:auto" /></figure>



<p class="wp-block-paragraph">The <strong>HCICluster</strong> element is your main player from now on. He&#8217;s got all the goods on the nodes, storage, and where you can go to get monitoring info and performance stats. There are a few things to do here so let&#8217;s click on him and go for a tour!</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="485" data-attachment-id="1674" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-2-8/" data-orig-file="/assets/archive/gbbcore/0b8331c0-image-2.jpg" data-orig-size="3120,1478" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-2" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/0b8331c0-image-2.jpg" src="/assets/archive/gbbcore/0b8331c0-image-2.jpg" alt="" class="wp-image-1674" /></figure>



<p class="wp-block-paragraph">Go into <strong>Windows Admin Center</strong> and deploy the Admin Center Extension to enable that feature. Super handy for cluster management, real time reporting metrics, and networking/storage config. It will take a while for it to deploy the Extensions and enable the feature.</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1675" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-3-6/" data-orig-file="/assets/archive/gbbcore/2a978cac-image-3.jpg" data-orig-size="343,449" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-3" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/2a978cac-image-3.jpg" src="/assets/archive/gbbcore/2a978cac-image-3.jpg" alt="" class="wp-image-1675" /></figure>



<p class="wp-block-paragraph">Next lets go back to the main Cluster blade and select <strong>VM Images</strong>. VM Images is the local repository for VM disk images we want to deploy from on the HCI Cluster.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="338" data-attachment-id="1677" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-4-8/" data-orig-file="/assets/archive/gbbcore/d25b3d9a-image-4.jpg" data-orig-size="1032,341" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-4" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/d25b3d9a-image-4.jpg" src="/assets/archive/gbbcore/d25b3d9a-image-4.jpg" alt="" class="wp-image-1677" /></figure>



<p class="wp-block-paragraph">Now we want to select Add VM Image. Here we can add Images from several places. The most common is the Marketplace, but if you have custom images in your Azure environment or on a local file share you can add those here too. Just remember these images need to be compatible with <strong>Azure</strong> to be useful. You can always pull-down one from the Marketplace and customize it for your needs then save that for reuse.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="145" data-attachment-id="1678" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-5-8/" data-orig-file="/assets/archive/gbbcore/5dd753ca-image-5.jpg" data-orig-size="2582,367" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-5" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/5dd753ca-image-5.jpg" src="/assets/archive/gbbcore/5dd753ca-image-5.jpg" alt="" class="wp-image-1678" /></figure>



<p class="wp-block-paragraph">After you&#8217;ve added a few images to the system, say Windows Server 2022 Azure edition and Windows 11 with M365 from the Azure Marketplace they will show as images you can select in the VM deployment flow.</p>



<p class="wp-block-paragraph">After adding the images and letting the rest of the deployments complete, you should now be able to connect to Windows Admin Center. Let&#8217;s go there and click <strong>Connect.</strong> Once the &#8220;WAC&#8221; interface loads up navigate down the left-hand side to the <strong>Network ATC</strong> option and Click on <strong>Deploy Network ATC Network HUD</strong>. This lets us see and manipulate the Network Intents we defined when we deployed. This will take a few seconds but once done you should see all the network interfaces and intents they are deployed on:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="243" data-attachment-id="1679" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-6-8/" data-orig-file="/assets/archive/gbbcore/518142ce-image-6.jpg" data-orig-size="2653,630" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-6" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/518142ce-image-6.jpg" src="/assets/archive/gbbcore/518142ce-image-6.jpg" alt="" class="wp-image-1679" /></figure>



<p class="wp-block-paragraph">Ensure that the proper interfaces are matching the correct intent on the servers. Also, make note of the Compute Virtual Switch name for later!</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="445" data-attachment-id="1680" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-7-6/" data-orig-file="/assets/archive/gbbcore/a8e79401-image-7.jpg" data-orig-size="2762,1202" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-7" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/a8e79401-image-7.jpg" src="/assets/archive/gbbcore/a8e79401-image-7.jpg" alt="" class="wp-image-1680" /></figure>



<p class="wp-block-paragraph">Next, I go into the cluster <strong>Settings</strong> then to <strong>Storage Spaces and pools</strong> and I select <strong>Thin</strong> for the default provisioning type. This will reduce the storage consumption on the S2D Volumes for the VMs deployed.</p>



<p class="wp-block-paragraph">Finally, I&#8217;ll check the <strong>Updates</strong> area on the cluster, and <strong>Enable Cluster Aware Updating</strong>. Once I&#8217;m finished up in here, I&#8217;ll drop back to the main HCI Cluster Blade and leave WAC.</p>



<p class="wp-block-paragraph">Now, select <strong>Logical Networks</strong> on the left-hand side and define one. On my home network, I have a predefined DHCP scope deployed already so I selected that to be my network in the HCI environment.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="699" data-attachment-id="1681" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-8-6/" data-orig-file="/assets/archive/gbbcore/0c9d40f4-image-8.jpg" data-orig-size="1577,1077" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-8" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/0c9d40f4-image-8.jpg" src="/assets/archive/gbbcore/0c9d40f4-image-8.jpg" alt="" class="wp-image-1681" /></figure>



<p class="wp-block-paragraph">Very quick to setup a DHCP Logical Network. Nothing to enter! Except! That <strong>Virtual switch name</strong> from <strong>WAC &#8211; Network Intents</strong> page, yes the whole weird thing the deployment named it. Some of the services you can deploy onto your new HCI environment do require a DHCP Logical Network.</p>



<p class="wp-block-paragraph">&nbsp;Next, go down to the Operations section and select <strong>Updates</strong></p>



<figure class="wp-block-image size-full"><img data-attachment-id="1682" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-9-6/" data-orig-file="/assets/archive/gbbcore/365ce1a3-image-9.jpg" data-orig-size="462,206" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-9" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/365ce1a3-image-9.jpg" src="/assets/archive/gbbcore/365ce1a3-image-9.jpg" alt="" class="wp-image-1682" /></figure>



<p class="wp-block-paragraph">If when you get into the Azure Update Manager area, there are no pending updates then you&#8217;re done! It will look something like this:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="200" data-attachment-id="1683" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-10-6/" data-orig-file="/assets/archive/gbbcore/092be625-image-10.jpg" data-orig-size="1994,391" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-10" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/092be625-image-10.jpg" src="/assets/archive/gbbcore/092be625-image-10.jpg" alt="" class="wp-image-1683" /></figure>



<p class="wp-block-paragraph">If however, it looks like this:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="208" data-attachment-id="1684" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-11-4/" data-orig-file="/assets/archive/gbbcore/66873e56-image-11.jpg" data-orig-size="1990,406" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-11" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/66873e56-image-11.jpg" src="/assets/archive/gbbcore/66873e56-image-11.jpg" alt="" class="wp-image-1684" /></figure>



<p class="wp-block-paragraph">Then you select <strong>One-time update</strong> and step through the wizard to complete the install.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="338" data-attachment-id="1685" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-12-4/" data-orig-file="/assets/archive/gbbcore/0e6d7df2-image-12.jpg" data-orig-size="2074,685" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-12" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/0e6d7df2-image-12.jpg" src="/assets/archive/gbbcore/0e6d7df2-image-12.jpg" alt="" class="wp-image-1685" /></figure>



<p class="wp-block-paragraph">Here we have a completed monthly update of the system.</p>



<p class="wp-block-paragraph">After you&#8217;ve run through and completed the updates to the system, you&#8217;re done with the Day 1 and 2 activities to deploy the Azure Stack HCI solution. Woohoo! Now we can start deploying VMs and Services onto the cluster!</p>



<h2 class="wp-block-heading"><strong>Deploying AVD on HCI</strong></h2>



<p class="wp-block-paragraph">We&#8217;ve had a &#8220;bit&#8221; of work getting here, but our cluster is now humming along and ready to accept Azure services! You can deploy regular VMs, AKS on HCI, and AVD on HCI right out of the box with some minor config. Arc enabled services can be layered on top of AKS for PaaS DB, App, AI/ML solutions as well.</p>



<p class="wp-block-paragraph">Given that I work with AVD on a regular basis, I thought I&#8217;d cover what that deployment experience is like with the HCI. Azure Stack HCI can run the host pool for the Azure Virtual Desktop solution. One critical point to make here is the control place for AVD is still hosted in Azure. You can however use RDP Shortpath to have local users direct connect to the session host over UDP on HCI after authentication and authorization through the AVD control plane in Azure.</p>



<p class="wp-block-paragraph">There are a few prerequisites here to point out that are important to understanding how AVD on Azure Stack HCI runs:</p>



<ul class="wp-block-list">
<li><em>You need a <strong>Hybrid Identity</strong> Setup with <strong>EntraID</strong> federated to your on-prem host pool AD environment.</em> Today, AVD on HCI doesn&#8217;t support EntraID Only joined domain hosts. However, if you remember all the way back at the beginning where I proposed the idea of a Fabric Identity, you aren&#8217;t limited to the domain used to deploy HCI. As I mentioned then, the HCI cluster identity and the workload identity can be separate domains. So, your user identity space can be the one you deploy with AVD.</li>
</ul>



<ul class="wp-block-list">
<li><em>Azure Stack HCI and the AVD Host Pool must be registered within the <strong>same EntraID tenant</strong></em>. I know this will be confusing based on the first one but hang with me. Azure Arc underpins all of this, and Arc resources can be registered with <strong>ANY</strong> EntraID tenant. The local identity and the cloud identity are separate things with Azure Arc. So, while your local HCI cluster might be on <em>azurestack.local</em> AD domain, and your users might be on <em>contoso.com.</em> Your EntraID cloud identity domain might need to be hybrid joined to <em>contoso.com</em>, if that&#8217;s your <strong>User</strong> domain. The <em>azurestack.local</em> isn&#8217;t connected to anything at all, but we have registered the HCI hosts into Azure Arc within an EntraID tenant. Your AVD Host Pool that gets deployed onto the target cluster needs to be in the same Tenant of <em>contoso.onmicrosoft.com</em> and in the same subscription.</li>
</ul>



<p class="wp-block-paragraph">See this graphic below to help illustrate:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="539" data-attachment-id="1686" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-13-4/" data-orig-file="/assets/archive/gbbcore/c0ec6a9b-image-13.jpg" data-orig-size="2002,1055" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-13" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/c0ec6a9b-image-13.jpg" src="/assets/archive/gbbcore/c0ec6a9b-image-13.jpg" alt="" class="wp-image-1686" /></figure>



<p class="wp-block-paragraph">Here you can see your AVD Host Pool VMs are connected into the AD Domain <em>contoso.com</em> which is Hybrid Connected to EntraID tenant <em>contoso.onmicrosoft.com</em>. Your HCI nodes are connected into <em>azurestack.local</em> AD domain and are also registered into your subscription under <em>contoso.onmicrosoft.com</em> EntraID Tenant as well. Now, you don&#8217;t have to deploy it this way. Your Fabric domain and User Domain can be the same. But if you need this level of sophistication, it&#8217;s possible. </p>



<ul class="wp-block-list">
<li>You need to have a Windows Server 2022 or Windows 10/11 Image deployed to the HCI cluster to deploy the Session Host Pool. (Remember from above?)</li>



<li>You need to deploy a Logical Network <strong><em>with DHCP</em></strong> to create session hosts today. (We did this one too!)</li>
</ul>



<p class="wp-block-paragraph">You can verify that your HCI Cluster is prepared and meets the AVD Requirements by going to the HCI Cluster element in the Portal and looking under the <strong>Getting Started</strong> section.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="484" data-attachment-id="1687" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-14-3/" data-orig-file="/assets/archive/gbbcore/5f85edae-image-14.jpg" data-orig-size="1577,746" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-14" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/5f85edae-image-14.jpg" src="/assets/archive/gbbcore/5f85edae-image-14.jpg" alt="" class="wp-image-1687" /></figure>



<p class="wp-block-paragraph">If you have the green check mark, you&#8217;re good to go. (Provided you&#8217;ve connected the workload/user identity domain to EntraID as explained above, this checker won&#8217;t validate that given the complexity.) If you have a red X, then click on the hyperlink and see what you&#8217;re missing.</p>



<p class="wp-block-paragraph">Let&#8217;s select <strong>Deploy</strong> to go to the AVD Host Pool deployment wizard. It will open a new browser window and authenticate you.</p>



<p class="wp-block-paragraph">Right away you&#8217;ll see that the deployment experience for AVD on HCI is the same as any Host Pool creation flow.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="846" height="1023" data-attachment-id="1688" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-15-3/" data-orig-file="/assets/archive/gbbcore/39b0b8db-image-15.jpg" data-orig-size="1436,1738" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-15" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/39b0b8db-image-15.jpg" src="/assets/archive/gbbcore/39b0b8db-image-15.jpg" alt="" class="wp-image-1688" /></figure>



<p class="wp-block-paragraph">Select the relevant parameters for your environment and then select <strong>Next: Virtual Machines</strong></p>



<p class="wp-block-paragraph">This part of the deployment is where we diverge from a standard AVD deployment. Select the radio button to <em>&#8220;Add virtual machines&#8221; </em><strong>Yes</strong>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="922" height="1023" data-attachment-id="1689" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-16-3/" data-orig-file="/assets/archive/gbbcore/5891999b-image-16.jpg" data-orig-size="1405,1560" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-16" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/5891999b-image-16.jpg" src="/assets/archive/gbbcore/5891999b-image-16.jpg" alt="" class="wp-image-1689" /></figure>



<p class="wp-block-paragraph">Complete the rest of the required information to perform an Azure Stack HCI deployment by making selections and scrolling to the bottom of the screen:</p>



<ul class="wp-block-list">
<li>Give the VMs a Prefix name: IE AVD, POOL, etc…</li>



<li>Tick the radio button for <strong>Azure Stack HCI virtual machine</strong></li>



<li>Select the HCI Cluster Customer Location</li>



<li>Select an Image (or if you didn&#8217;t add one yet, add one!)</li>



<li>Specify the VM configuration you want on the HCI cluster and the number of VMs to deploy.
<ul class="wp-block-list">
<li>It&#8217;s worth pausing here to mention this will impact cost. VMs are meter at .01 per vCPU per hour or 7.30/month roughly. So for the example below that has 3 VMs with 4 vCPUs per, it&#8217;s almost $90/Month at list price.</li>



<li>Also, if you&#8217;d like to make your life easy, line up the VM config to Azure based VMs from the same CPU family. It will help with performance expectations of your users. Below that’s roughly a D4s v3 with the Broadwell based gear I&#8217;m deploying onto.</li>
</ul>
</li>



<li>Specify the Logical Network you defined <em>with DHCP</em> previously. (You did that right?)</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" width="984" height="1024" data-attachment-id="1690" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-17-3/" data-orig-file="/assets/archive/gbbcore/2e1be186-image-17.jpg" data-orig-size="1414,1472" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-17" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/2e1be186-image-17.jpg" src="/assets/archive/gbbcore/2e1be186-image-17.jpg" alt="" class="wp-image-1690" /></figure>



<ul class="wp-block-list">
<li>Provide the Active Directory environment you want the HCI VMs to join. Remember no EntraID only!
<ul class="wp-block-list">
<li>The User Account needs to be able to connect to domain and add systems.</li>



<li>The DHCP scope needs to refer to the proper DNS for the Domain to reach it.</li>



<li>If you want to specific the OU to drop the hosts into that information it needs to be in the proper format without &#8220;quotes&#8221;.</li>
</ul>
</li>



<li>Finally define the local admin information for the VMs with a password and click <strong>Next: Workspace</strong></li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="264" data-attachment-id="1691" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-18-3/" data-orig-file="/assets/archive/gbbcore/194418b0-image-18.jpg" data-orig-size="1407,363" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-18" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/194418b0-image-18.jpg" src="/assets/archive/gbbcore/194418b0-image-18.jpg" alt="" class="wp-image-1691" /></figure>



<p class="wp-block-paragraph">Here click, the radio button to add the VMs into a default desktop application group, then either create a workspace or select an existing one. Once done, click <strong>Next: Advanced</strong> at the bottom.</p>



<p class="wp-block-paragraph">Enable diagnostics if you like and select a workspace to send the data if you so choose. Then click <strong>Next: Tags</strong> to continue.</p>



<p class="wp-block-paragraph">Add relevant tags and information here for the resources the deployment wizard will create if needed. Then finally click <strong>Review + create</strong>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="690" height="1023" data-attachment-id="1692" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-19-3/" data-orig-file="/assets/archive/gbbcore/d0ced7e4-image-19.jpg" data-orig-size="1089,1616" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-19" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/d0ced7e4-image-19.jpg" src="/assets/archive/gbbcore/d0ced7e4-image-19.jpg" alt="" class="wp-image-1692" /></figure>



<p class="wp-block-paragraph">The validation should come back good if you&#8217;ve provided all the required information. This process will take a while. Don&#8217;t forget to download the template should you need to redeploy or add it to your Automation workflows for the future!</p>



<p class="wp-block-paragraph">The deployment might fail due to resource constraints, missing or incorrect domain information, and exhausted DHCP scope, missing DNS info for the VMs to pick up domain info. Point being there may be some troubleshooting to get a successful deployment. Give it a few tries, dig into the logs and generally bang it out. </p>



<p class="wp-block-paragraph">Once Azure Resource Manager notifies you the deployment is complete, you should see the VMs under the HCI VM list:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="265" data-attachment-id="1693" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-20-3/" data-orig-file="/assets/archive/gbbcore/3365e4f0-image-20.jpg" data-orig-size="2055,533" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-20" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/3365e4f0-image-20.jpg" src="/assets/archive/gbbcore/3365e4f0-image-20.jpg" alt="" class="wp-image-1693" /></figure>



<p class="wp-block-paragraph">And the AVD Control Plane within Host Pools:</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1694" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-21-3/" data-orig-file="/assets/archive/gbbcore/a1c12f1e-image-21.jpg" data-orig-size="1379,614" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-21" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/a1c12f1e-image-21.jpg" src="/assets/archive/gbbcore/a1c12f1e-image-21.jpg" alt="" class="wp-image-1694" /></figure>



<p class="wp-block-paragraph">Here you can see I have two Hosts running on my cluster and they show in the AVD Host Pool. They are deployed to my Fabric Identity. I&#8217;m only using this for testing and due to the quirk of me deploying into a Microsoft Corporate tenant, I can&#8217;t actually Hybrid connect to the EntraID tenant. So, this is good to see the deployment workflow functions, but otherwise may not be representative of your environment requirements. </p>



<p class="wp-block-paragraph">From here, you also can go through the process of deploying the <strong>Remote Desktop App</strong> or the <strong>Windows App</strong> from the Microsoft Store. The Windows App is the new unified client for all RDP connections.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="297" data-attachment-id="1695" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-22-3/" data-orig-file="/assets/archive/gbbcore/39bbef42-image-22.jpg" data-orig-size="1822,530" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-22" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/39bbef42-image-22.jpg" src="/assets/archive/gbbcore/39bbef42-image-22.jpg" alt="" class="wp-image-1695" /></figure>



<p class="wp-block-paragraph">Once you download it, just sign into the App with the <strong>EntraID </strong>connected to the Host Pool environment and you&#8217;ll see the Workspace assigned with the Desktop or published RemoteApps.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="632" data-attachment-id="1696" data-permalink="https://gbbcore.wordpress.com/2024/04/01/roll-your-own-avd-on-hci-deployment-part-4-turn-it-up/image-23-4/" data-orig-file="/assets/archive/gbbcore/6ba63e7c-image-23.jpg" data-orig-size="2344,1448" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-23" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/6ba63e7c-image-23.jpg" src="/assets/archive/gbbcore/6ba63e7c-image-23.jpg" alt="" class="wp-image-1696" /></figure>



<p class="wp-block-paragraph">That&#8217;s all you have to do to start hosting the AVD workload on Azure Stack HCI! </p>



<h2 class="wp-block-heading">Final Thoughts</h2>



<p class="wp-block-paragraph">We&#8217;ve reached the end of this series. We built an environment from the ground up and deployed a workload to the on-prem cluster. There is a lot more you can test and validate outside of the AVD on HCI solution with Azure Stack HCI.</p>



<p class="wp-block-paragraph">Here are a few thoughts around cost optimizations with Azure Stack HCI in a Test/Dev environment. While Azure Stack HCI has an entitlement to use Azure Hybrid Use Benefit to exchanging physical cores of Windows Server Datacenter licensing with SA and for Azure Stack HCI consumption-based cores. It isn&#8217;t always efficient to use that on an environment like this. You do have a 60 day free trial from the time you register the cluster. You also have the ability to join the Preview Channel for the HCI system builds to get the latest versions. Since Preview Channel systems can&#8217;t be used in production, and these nodes aren&#8217;t production ready either give the old/obsolete nature of the gear, those two seem to pair up nicely. I won&#8217;t go into the workload licensing here as that too still needs to be entitled, but you have a few options to run this solution for a while and kick the tires. Then decomm it again or recycle it as you see fit. If you&#8217;ve collected all your work, you can even replay that on more gear later or get a jump start on a production build working with your OEM of choice. (You <strong>DO</strong> remember you can&#8217;t run this in production, right?)</p>



<p class="wp-block-paragraph">I hope that you found this blog series helpful and insightful on how to stand-up Azure Stack HCI and get a service deployed. It&#8217;s several hours of work to roll your own HCI environment, but you&#8217;ll have a nice understanding of the fundamentals and a greater appreciation of all the work that went into&nbsp;the automated HCIBox virtual environment we&#8217;ve built into the portal. There are plenty of OEM solution offers to leverage once you&#8217;re ready to scale. Having a test environment like what we built will help you clear the path on all the environmental challenges to operationalize Azure Stack HCI. </p>



<p class="wp-block-paragraph">Which brings us back to the beginning. If all this work doesn&#8217;t seem worthwhile, you can always leverage the other test/deployment methods available for HCI. You can and should work with an OEM to get a cluster environment with services for your initial deployment. This blog series is for when all of the other paths won&#8217;t meet your use case, budget, timeline. I want to again thank all of those who helped to put this together. Whether that was excellent existing documentation, sorely needed collaboration building my environment, or outstanding peer review of the posts. Thanks to: <strong>Michael Godfrey, Thomas Maurer, Flo Fox, </strong>and<strong> Kevin Sullivan</strong> I couldn&#8217;t have done this without them!</p>



<p class="wp-block-paragraph">And thank you so much for choosing to spend your time here!</p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Lee Cox – Advanced Migration GBB Welcome back to Part 4 of our Blog series. Thanks for taking the time to follow along. So? How did it go? Did you get through the whole thing with only one pass? I know I didn’t… 😉 Post-D]]></summary></entry><entry><title type="html">Roll your own AVD on HCI deployment – Part 3: The Deployment</title><link href="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/" rel="alternate" type="text/html" title="Roll your own AVD on HCI deployment – Part 3: The Deployment" /><published>2024-03-29T12:33:15-05:00</published><updated>2024-03-29T12:33:15-05:00</updated><id>https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-3-the-deployment</id><content type="html" xml:base="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/"><![CDATA[<p class="wp-block-paragraph">Lee Cox &#8211; Advanced Migration GBB</p>



<p class="wp-block-paragraph">Welcome to Part 3 of this series of Rolling your own Azure Stack HCI environment! Congrats and thanks for sticking with me. Today is the day! We&#8217;re finally here. Now we get to load some code and make this HCI &#8220;thing&#8221; happen.</p>



<p class="wp-block-paragraph">Let&#8217;s review what you should have done at this point.</p>



<ol class="wp-block-list">
<li>We&#8217;ve prepped the hardware with the latest firmware.</li>



<li>We&#8217;ve collected and injected drivers into the 23H2 HCI build.</li>



<li>We&#8217;ve created/prepped the on-prem and cloud identity space, rights assignments, and users.</li>
</ol>



<p class="wp-block-paragraph">That&#8217;s a lot, it isn&#8217;t a trivial amount of work and lays the foundation for a straightforward installation process. Well, as straightforward as it can be using unapproved hardware for a Dev/Test solution environment. 🙂</p>



<p class="wp-block-paragraph">The steps here are the same-ish as what you did to install Windows Server 2022.</p>



<ol class="wp-block-list">
<li>Power off the systems</li>



<li>Insert your USB Key with HCI on it into the USB port</li>



<li>Power on the system and one time boot to the USB key</li>



<li>Tell the setup process to install the HCI image</li>



<li>Selecting &#8220;Custom&#8221; install process so we can clean the drives</li>



<li>Delete all the existing partitions on the OS drive and select &#8220;New&#8221;</li>



<li>Continue the install process</li>



<li>Wait…</li>



<li>Wait Some more</li>



<li>Set a local Administrator password across the systems &#8211; (Be mindful of Complexity Requirements)</li>



<li>Then boot into Sconfig for a few more changes</li>
</ol>



<p class="wp-block-paragraph">You&#8217;ll be greeted by this lovely screen when you drop into the &#8220;Desktop&#8221; on the HCI server:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="535" data-attachment-id="1661" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-1-2-3/" data-orig-file="/assets/archive/gbbcore/983b42c5-image-1-2.jpg" data-orig-size="4190,2192" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-1-2" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/983b42c5-image-1-2.jpg" src="/assets/archive/gbbcore/983b42c5-image-1-2.jpg" alt="" class="wp-image-1661" /></figure>



<ul class="wp-block-list">
<li>When we get here, go into 2 and set the proper node name. When it asks to reboot, say no.</li>



<li>Then go into 8 and verify you have IP information if you&#8217;re running DHCP (which you should have a scope for on your network). Set the <strong>Static IP</strong> and DNS Server of your <strong>Domain Controller</strong> here.</li>



<li>Go into 9 and verify a time source. It should match your domain controller.</li>



<li>I then do other housekeeping for the systems:
<ul class="wp-block-list">
<li>Enable RDP</li>



<li>Enable Required Telemetry</li>



<li>Then go into 6 and Install All Quality Updates</li>
</ul>
</li>



<li>Once the updates are done, you&#8217;ll reboot and rerun the updates. There may be driver updates in here too.</li>
</ul>



<p class="wp-block-paragraph">When the system stops installing updates and requiring a reboot, you have a few options here based on what you know of your hardware. You can select 15 and drop into the command line, navigate to your driver folder on the USB key and load any additional software or drivers that didn&#8217;t slipstream. If you&#8217;re not sure, you can load up a Windows Admin Center instance and import the servers with the Administrator user account on the system, then go into Devices to see if there are any &#8220;Unknown&#8221; devices without drivers in the list. This is like going into the Device Manager on a regular Windows system. It also only takes a few minutes to setup. Then use the PowerShell interface within Windows Admin Center to load up the additional software and drivers.</p>



<p class="wp-block-paragraph">On my system I needed to install the iLo Drivers and config software for the OS to correctly interface with the hardware. Other OEMs have similar requirements with Dell/EMC, Lenovo, Cisco, DataOn, Intel etc.</p>



<p class="wp-block-paragraph">Once you&#8217;re done with these steps, you should replay the work on any other nodes in the same order to get the same end result. You can do all this work in the OOB interface, RDP, or WAC. Whatever makes you feel comfortable.</p>



<p class="wp-block-paragraph">Depending on how many interfaces you&#8217;ve connected and plan to provision, what you plan to use on the system, and what it was used for before, there are a few side quests you may need to complete.</p>



<ul class="wp-block-list">
<li>Clean Your Disks: As mentioned previously we need data disks for this to work. Mine were used in a vSAN configuration and I needed to clean them to use with S2D. You&#8217;ll need to remove any removable media from the system first. Here is a script to run on each node:</li>
</ul>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<pre class="wp-block-code"><code>Update-StorageProviderCache

&nbsp;&nbsp;&nbsp; Get-StoragePool | ? IsPrimordial -eq $false | Set-StoragePool -IsReadOnly:$false -ErrorAction SilentlyContinue

&nbsp;&nbsp;&nbsp; Get-StoragePool | ? IsPrimordial -eq $false | Get-VirtualDisk | Remove-VirtualDisk -Confirm:$false -ErrorAction SilentlyContinue

&nbsp;&nbsp;&nbsp; Get-StoragePool | ? IsPrimordial -eq $false | Remove-StoragePool -Confirm:$false -ErrorAction SilentlyContinue

&nbsp;&nbsp;&nbsp; Get-PhysicalDisk | Reset-PhysicalDisk -ErrorAction SilentlyContinue

&nbsp;&nbsp;&nbsp; Get-Disk | ? Number -ne $null | ? IsBoot -ne $true | ? IsSystem -ne $true | ? PartitionStyle -ne RAW | % {

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $_ | Set-Disk -isoffline:$false

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $_ | Set-Disk -isreadonly:$false

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $_ | Clear-Disk -RemoveData -RemoveOEM -Confirm:$false

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $_ | Set-Disk -isreadonly:$true

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $_ | Set-Disk -isoffline:$true

&nbsp;&nbsp;&nbsp; }

&nbsp;&nbsp;&nbsp; Get-Disk | Where Number -Ne $Null | Where IsBoot -Ne $True | Where IsSystem -Ne $True | Where PartitionStyle -Eq RAW | Group -NoElement -Property FriendlyName</code></pre>
</div>



<ul class="wp-block-list">
<li>Config the NICs: If you&#8217;re using more than one Interface card for your VM/Management traffic, which is pretty standard, you&#8217;ll need to disable DHCP on the other interfaces and remove the gateway. Here is some code to do that:</li>
</ul>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<pre class="wp-block-code"><code>Set-NetIPInterface -DHCP Disabled -InterfaceAlias "Nic-Name"

Remove-NetIPAddress -InterfaceAlias "Nic-Name" -Confirm:$false

Remove-NetRoute -InterfaceAlias "Nic-Name" -NextHop 192.168.0.1 -Confirm:$false</code></pre>
</div>



<p class="wp-block-paragraph">You&#8217;ll need to set the interface names and &#8220;-NextHop&#8221; address to the correct ones for your interfaces/network.</p>



<p class="wp-block-paragraph">After you get done here, it’s worth looking over your work and making sure you&#8217;ve got everything squared away. Before the next few steps. Everything should be up to date on HCI, drivers deployed, IP&#8217;ed, Network Interfaces properly connected/configured, Disks prepped. If you&#8217;re doing a switchless configuration, make sure your ethernet or DAC cables are connected to the same interface and port on both sides; Port 1 to Port 1, Port 2 to Port 2.</p>



<p class="wp-block-paragraph">You&#8217;ll want to deploy the Server Roles for HCI and reboot:</p>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<pre class="wp-block-code"><code>Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All -NoRestart

Restart-Computer -Force</code></pre>
</div>



<p class="wp-block-paragraph">We&#8217;ve now got all the nodes ready to join the team and work for Azure! Woohoo! There is an onboarding script that you can use below. Replace the sample information with your own for the variables.</p>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<pre class="wp-block-code"><code>$rg="TheRGNameYouCreated"

$AzureSubID = "TheAzureSubscriptionGUIDYoureUsing"

$tenant="YourAADEntraIDTenantGUID"

Write-Host "Installing Required Modules"

Set-PSRepository -Name PSGallery -InstallationPolicy Trusted

$ModuleNames="AzSHCI.ARCInstaller","Az.Resources","Az.Accounts","AzStackHci.EnvironmentChecker"

&nbsp; &nbsp; foreach ($ModuleName in $ModuleNames){

&nbsp; &nbsp; &nbsp; &nbsp; if (!(Get-InstalledModule -Name $ModuleName -ErrorAction Ignore)){

&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Install-Module -Name $ModuleName -Force

&nbsp; &nbsp; &nbsp; &nbsp; }

&nbsp; &nbsp; }

Connect-AzAccount -SubscriptionId $AzureSubID -TenantId $tenant

$armtoken = (Get-AzAccessToken).token

$id = (Get-AzContext).Account.Id

Write-Output "Initializing &amp; Registering Azure Stack HCI Arc Agent on Node"

Invoke-AzStackHciArcInitialization -SubscriptionID $AzureSubID -ResourceGroup $rg -TenantID $tenant -Region EastUS -Cloud "AzureCloud" -ArmAccessToken $armtoken -AccountID $id -Force</code></pre>



<p class="wp-block-paragraph">You&#8217;ll be prompted to sign-in to a system that has access to a browser and provide the device code. Good to do this step through RDP to copy/paste or in WAC. You&#8217;ll see a bunch of code scroll by and the systems will be connected to Azure through the Arc agent.</p>
</div>



<p class="wp-block-paragraph">Once complete, Let&#8217;s verify the config and the hardware before finishing the local side of the config. Run:</p>



<pre class="wp-block-code"><code><code>Invoke-AzStackHciHardwareValidation</code></code></pre>



<p class="wp-block-paragraph">Look for any errors in the system setup and follow the information in the error to resolve the issue.</p>



<p class="wp-block-paragraph">We&#8217;re now done with the nodes local configuration everything else can be done through Azure! Please note that if you purchase an Azure Stack HCI system from an OEM, all of this work is done for you. They&#8217;ll also walk you through the Azure and AD prep steps. </p>



<p class="wp-block-paragraph">In the Azure Portal, search for Azure Stack HCI and select it like we did before.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="528" data-attachment-id="1663" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-2-2-3/" data-orig-file="/assets/archive/gbbcore/a0086902-image-2-2.jpg" data-orig-size="1080,557" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;1&quot;}" data-image-title="image-2-2" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/a0086902-image-2-2.jpg" src="/assets/archive/gbbcore/a0086902-image-2-2.jpg" alt="" class="wp-image-1663" /></figure>



<p class="wp-block-paragraph">This time we want to select &#8220;<strong>Deploy Cluster</strong>&#8221; on the HCI landing page.</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1664" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-3-2-3/" data-orig-file="/assets/archive/gbbcore/2bdcbac7-image-3-2.jpg" data-orig-size="2680,2854" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-3-2" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/2bdcbac7-image-3-2.jpg" src="/assets/archive/gbbcore/2bdcbac7-image-3-2.jpg" alt="" class="wp-image-1664" /></figure>



<p class="wp-block-paragraph">Now we&#8217;ll land on the deployment wizard for Azure Stack HCI 23H2. It&#8217;s all portal driven and will then direct the Arc connected HCI nodes to complete the cluster build. You should see your Arc connected HCI nodes at the bottom. If you don&#8217;t, then they didn&#8217;t register correctly, or you tried to deploy and the need to clean up the install. </p>



<figure class="wp-block-image size-large"><img loading="lazy" width="869" height="1023" data-attachment-id="1665" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-4-1-2/" data-orig-file="/assets/archive/gbbcore/7c57b7c2-image-4-1.jpg" data-orig-size="2528,2978" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-4-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/7c57b7c2-image-4-1.jpg" src="/assets/archive/gbbcore/7c57b7c2-image-4-1.jpg" alt="" class="wp-image-1665" /></figure>



<p class="wp-block-paragraph">In the next set of steps, you&#8217;ll set and specify a bunch of information that was outlined during the planning and identity phase of this series. Remember when I said it would be a good idea to write things down? Yeah, this is where it gets used. Ensure you have the correct nodes and the right number of nodes before continuing. All of your information you enter is critically important, but the process is also forgiving.</p>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph">Tip: If there is a circled &#8220;i&#8221; next to a field, hover over it or click it to reveal the field tip. These can either be not helpful or very helpful to make sure you enter the information correctly. I always click on them the first time through a wizard like this.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="839" height="1024" data-attachment-id="1666" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-5-1-2/" data-orig-file="/assets/archive/gbbcore/426dc30f-image-5-1.jpg" data-orig-size="2436,2974" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-5-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/426dc30f-image-5-1.jpg" src="/assets/archive/gbbcore/426dc30f-image-5-1.jpg" alt="" class="wp-image-1666" /></figure>



<p class="wp-block-paragraph">You should define a new <strong>Key Vault</strong>, <strong>Storage Account</strong>, and anything else that requires new/other Azure services. You&#8217;re going to setup the <strong>Network Intents</strong> here with the interface mapping. You&#8217;ll want to set any <strong>VLAN IDs</strong> you might need for the networks like storage or VM traffic. You&#8217;ll need that block of <strong>IPs</strong> we were discussing before to deploy the clusters and configure the services we&#8217;ll run on HCI.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="947" height="1024" data-attachment-id="1667" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-6-1-2/" data-orig-file="/assets/archive/gbbcore/22c176ad-image-6-1.jpg" data-orig-size="2528,2734" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-6-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/22c176ad-image-6-1.jpg" src="/assets/archive/gbbcore/22c176ad-image-6-1.jpg" alt="" class="wp-image-1667" /></figure>



<p class="wp-block-paragraph">You need the <strong>Local Admin</strong> information, the <strong>Domain Information</strong>, and the <strong>User Account </strong>you had the AD Prep tool create in the previous blog. The <strong>OU</strong> info needs to be in the same format from the AD Prep tool.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="508" data-attachment-id="1668" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-8-4/" data-orig-file="/assets/archive/gbbcore/b85565d8-image-8.jpg" data-orig-size="2670,1325" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-8" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/b85565d8-image-8.jpg" src="/assets/archive/gbbcore/b85565d8-image-8.jpg" alt="" class="wp-image-1668" /></figure>



<p class="wp-block-paragraph">The final set of steps relates to <strong>security recommendations</strong> (good to accept the defaults if you can), <strong>storage config</strong> (let it create the recommended volumes if the config is typical), and <strong>tags</strong> (Tagging the environment will help with locating resources).&nbsp;</p>



<p class="wp-block-paragraph">Finally, the wizard will check your work for any errors:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="1008" data-attachment-id="1669" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-7-1-2/" data-orig-file="/assets/archive/gbbcore/ab49f773-image-7-1.jpg" data-orig-size="2134,2102" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-7-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/ab49f773-image-7-1.jpg" src="/assets/archive/gbbcore/ab49f773-image-7-1.jpg" alt="" class="wp-image-1669" /></figure>



<p class="wp-block-paragraph">And then click <strong>Start Validation</strong> to run checks on the systems to ensure it can deploy properly.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="850" height="1023" data-attachment-id="1670" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-9-4/" data-orig-file="/assets/archive/gbbcore/2127d70c-image-9.jpg" data-orig-size="1802,2170" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-9" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/2127d70c-image-9.jpg" src="/assets/archive/gbbcore/2127d70c-image-9.jpg" alt="" class="wp-image-1670" /></figure>



<p class="wp-block-paragraph">If at this step it runs into issues it will give you &#8220;Go Do&#8217;s&#8221; to correct before continuing. If you do get an error, the system will allow you to revalidate.</p>



<p class="wp-block-paragraph">Finally, you&#8217;ll be given the option to &#8220;<strong>Review + Create</strong>&#8221; where it will start the cluster build. It will also allow you to save the ARM template of the deployment for you to replay or create a template from for future deployments.</p>



<p class="wp-block-paragraph">The deployment <strong>WILL</strong> take a while. Up to 2-3 hours for a two-node cluster. So let it do its thing. You can monitor the deployment from the final step which will take you to the deployments section of the HCICluster element:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="780" data-attachment-id="1671" data-permalink="https://gbbcore.wordpress.com/2024/03/29/roll-your-own-avd-on-hci-deployment-part-3-the-deployment/image-10-4/" data-orig-file="/assets/archive/gbbcore/8f7b6ab6-image-10.jpg" data-orig-size="2646,2018" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-10" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/8f7b6ab6-image-10.jpg" src="/assets/archive/gbbcore/8f7b6ab6-image-10.jpg" alt="" class="wp-image-1671" /></figure>



<p class="wp-block-paragraph">If at any point it fails, you can <strong>Rerun deployment</strong> to pick up where you left off.</p>



<p class="wp-block-paragraph">This is a good place to pause for now. Get the Cluster up and running address anything that comes up like typos and any issues. I had a permission issue from not getting the rights correct on the Domain User account, entering the OU structure incorrectly, along with the User information being formatted incorrectly my first time through. It&#8217;s important to pay attention to the sample information that is provided and the field tips.</p>



<p class="wp-block-paragraph">Once you clear all of those common errors, you&#8217;ll be able to move on the next set of steps to get this turned up! I want to say thanks again to <strong>Michael Godfrey</strong> for the scripting samples here. Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Lee Cox – Advanced Migration GBB Welcome to Part 3 of this series of Rolling your own Azure Stack HCI environment! Congrats and thanks for sticking with me. Today is the day! We’re finally here. Now we get to load some c]]></summary></entry><entry><title type="html">Roll your own AVD on HCI deployment – Part 2: The Plan &amp;amp; Identity</title><link href="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity/" rel="alternate" type="text/html" title="Roll your own AVD on HCI deployment – Part 2: The Plan &amp;amp; Identity" /><published>2024-03-28T12:10:37-05:00</published><updated>2024-03-28T12:10:37-05:00</updated><id>https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity</id><content type="html" xml:base="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity/"><![CDATA[<p class="wp-block-paragraph">Lee Cox &#8211; Advanced Migration GBB</p>



<p class="wp-block-paragraph">Welcome back, and to Part 2 of this series. I hope that you found the first part helpful. Continuing on from the last Blog post you should have a few things sorted out now to begin our next set of deployment steps.</p>



<ol class="wp-block-list">
<li>You should have your hardware up to date with the latest available firmware.</li>



<li>The hardware should be set for TPM, SecureBoot, and the storage controller in IT mode (if required).</li>



<li>You should have a USB Key with the latest version of Azure Stack HCI 23H2 and the Driver/Software folder you created earlier on the root of the drive.</li>
</ol>



<h2 class="wp-block-heading"><strong>Planning</strong></h2>



<p class="wp-block-paragraph">Now is a good time to pause and recommend that you take some time to plan the environment you&#8217;re going to deploy. As they say,<em> &#8220;Failing to make a plan…&#8221;</em> Seriously, you need to make a few decisions with regard to structure of the solution in order to know how all this will play out. You need to understand the infrastructure network space your HCI servers will live in:</p>



<p class="wp-block-paragraph">How will they communicate with each other?</p>



<p class="wp-block-paragraph">Are there VLANs and/or Firewalls involved?</p>



<p class="wp-block-paragraph">What is the AD Domain you&#8217;ll connect to?</p>



<p class="wp-block-paragraph">Will you need to use a Proxy to talk to Azure?</p>



<p class="wp-block-paragraph">Private Endpoints?</p>



<p class="wp-block-paragraph">What naming convention will you use for the systems, cluster, users?</p>



<p class="wp-block-paragraph">Taking a few minutes (or more than a few) to review the network requirements. Documenting your config goes a long way in troubleshooting things later. I typically start a OneNote or Notepad doc and write down as much as I can as I go and refer to it later as needed. You can find the Network Requirements for HCI here: <a href="https://learn.microsoft.com/en-us/azure-stack/hci/concepts/physical-network-requirements?tabs=overview%2C23H2reqs">Physical network requirements for Azure Stack HCI &#8211; Azure Stack HCI | Microsoft Learn</a> But, this is just the tip of the iceberg. There is a bunch you can get lost in with this aspect of the documentation. I&#8217;m still trying to find my way out! My best advice is understand the physical topology of the environment, then look at the deployment options for the number of nodes you have referenced in the docs. Then look at the IP requirements for your chosen pattern.</p>



<p class="wp-block-paragraph">I have a co-worker Kevin who loves to say Firewalls, Firewalls, Firewalls. If there&#8217;s an issue with a hybrid or &#8220;Adaptive Cloud&#8221; solution, it&#8217;s almost always firewalls. So, have a look here: <a href="https://learn.microsoft.com/en-us/azure-stack/hci/concepts/firewall-requirements">Firewall requirements for Azure Stack HCI &#8211; Azure Stack HCI | Microsoft Learn</a> and make sure you can reach the endpoints, refer your NetSec team here too and discuss if these would be an issue. Most are common and known Microsoft endpoints but it&#8217;s helpful to be proactive. Another great tool that has been developed is the Environment Checker tool, Microsoft has spent a bunch of time making sure the Hybrid connectivity can be successful. You can use this: <a href="https://learn.microsoft.com/en-us/azure-stack/hci/manage/use-environment-checker?tabs=connectivity">Use Azure Stack HCI Environment Checker to assess deployment readiness for Azure Stack HCI, version 23H2. &#8211; Azure Stack HCI | Microsoft Learn</a> to make sure your network is ready to talk to Azure, if the Hardware is up to snuff, can the nodes talk to AD or Arc endpoints and the ports are open for all the needed traffic.</p>



<p class="wp-block-paragraph">In order to deploy an HCI infrastructure, you need 1 IP address per server, plus a minimum of 6 additional contiguous IPs for infrastructure that will be deployed during the cluster creation process. The first consumed will be the Cluster IP, the rest are various Failover Cluster services that will also be deployed within the solution. You may also need IPs for OOB management nics and IPs for a Domain controller or two if you are building a net new environment.</p>



<p class="wp-block-paragraph">Azure Stack HCI 23H2 changes the installation and cluster deployment process compared to earlier versions. In the past, you would build everything on-prem and register the cluster as a final step. Today, you install the hypervisor and do some minor personalization config, then you register the system with Azure Arc <strong><em>BEFORE</em></strong> you form the cluster, join the domain, etc… Azure will do those steps for you. It&#8217;s a <strong>BIG</strong> improvement over the old way and handles a bunch of steps for you. You should have all of these design decisions made before you move on. Write it all down! You will need it to go through the wizard later.</p>



<h2 class="wp-block-heading"><strong>Active Directory</strong></h2>



<p class="wp-block-paragraph">Also, with the release of 23H2, there is now a defined method of organizing your on-prem Active Directory environment resources and a PowerShell tool to help with the deployment. Let&#8217;s start there. You should have an AD environment running. This is a Prerequisite to get Azure Stack HCI going. If you&#8217;re uncomfortable adding this solution to your existing AD Domain, you can stand one up just for Azure Stack HCI. Flo Fox has written a great blog post on the concept of Fabric Identity here: <a href="https://petri.com/azure-stack-hci-fabric-domain-network/">Why You Should Have a Fabric Domain and Network for Azure Stack HCI (petri.com)</a></p>



<p class="wp-block-paragraph">The AD environment doesn&#8217;t have to be hybrid connected to EntraID to serve the needs of Azure Stack HCI. It&#8217;s used for the on-prem server identity space and the Failover Cluster configuration. Once you have the AD environment identified, we need to run the PowerShell utility to prep the environment. You should run this on a system that has access to the Active Directory environment. This wouldn&#8217;t be one of the HCI nodes, at least not yet. You can run it on a domain controller if that&#8217;s all you have. You also need to have a user account that can create an OU and User Accounts. You can pull down the PowerShell module by going to the command line and typing:</p>



<pre class="wp-block-code"><code><strong><code>Install-Module AsHciADArtifactsPreCreationTool -Repository PSGallery -Force</code></strong></code></pre>



<p class="wp-block-paragraph">Once you have the PowerShell module, now you need to decide what you want your OU name to be and Username. The Username should be <strong><em>JUST</em></strong> the name not a domain context as you&#8217;re already signed in to run the tool. Here is some handy code to get the objects created:</p>



<div class="wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained">
<pre class="wp-block-code"><code><strong>$password = ConvertTo-SecureString '&lt;password&gt;' -AsPlainText -Force

$user = "lcmuser"

$credential = New-Object System.Management.Automation.PSCredential ($user, $password)

New-HciAdObjectsPreCreation -AzureStackLCMUserCredential $credential -AsHciOUName "OU=ms309,DC=s31r1503,DC=microsoft,DC=com"</strong></code></pre>
</div>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph"><mark style="background-color:#abb8c3" class="has-inline-color">Tip: If you&#8217;re Password requires the $ symbol use &#8216;single&#8217; hashes instead of &#8220;quotes&#8221;.</mark></p>



<p class="wp-block-paragraph">You can validate the Domain Prep and configuration was successful by looking at the OU and User Account in <strong>Active Directory Users and Computers</strong> admin tool.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="333" data-attachment-id="1657" data-permalink="https://gbbcore.wordpress.com/2024/03/28/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity/image-1-1-2/" data-orig-file="/assets/archive/gbbcore/68a9841f-image-1-1.jpg" data-orig-size="2982,970" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-1-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/68a9841f-image-1-1.jpg" src="/assets/archive/gbbcore/68a9841f-image-1-1.jpg" alt="" class="wp-image-1657" /></figure>



<p class="wp-block-paragraph">In the OU, right click go into <strong>Properties</strong> and verify that Block Inheritance was enabled.</p>



<p class="wp-block-paragraph">Once you have a successful result, you&#8217;ve completed the required steps to prep the on-prem domain. Yay! You did it! High Five. See that wasn&#8217;t so bad. Now we can move on to the EntraID and Azure Subscription steps to prepare the cloud side of the deployment.</p>



<h2 class="wp-block-heading"><strong>Azure</strong></h2>



<p class="wp-block-paragraph">Login to the Azure Portal, if you&#8217;re using a dedicated EntraID tenant for your test environment you can switch to the right one in the upper right-hand side by selecting your username.</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1658" data-permalink="https://gbbcore.wordpress.com/2024/03/28/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity/image-2-1-2/" data-orig-file="/assets/archive/gbbcore/542ba861-image-2-1.jpg" data-orig-size="383,78" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-2-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/542ba861-image-2-1.jpg" src="/assets/archive/gbbcore/542ba861-image-2-1.jpg" alt="" class="wp-image-1658" /></figure>



<p class="wp-block-paragraph">The EntraID tenant you are currently in will be shown under your account. If this is correct, great! If not, click your user account and select the correct one. Also, while you&#8217;re in here click the <strong>Star</strong> next to the Tenant to make your default on sign-in and see at the top what the default subscription is at the top. If it&#8217;s the one you&#8217;re working with great! If not, you&#8217;ll need to change that later.</p>



<p class="wp-block-paragraph">Now, select the subscription under the EntraID tenant you intend to use for your HCI environment. In order to make the subscription and EntraID changes, you&#8217;ll need the rights within both to properly complete the steps. If you don&#8217;t have Owner/Contributor rights to the subscription or Admin rights within the EntraID you&#8217;ll need to work with someone who does or have them granted to you.</p>



<p class="wp-block-paragraph">We need to register Resource Providers into the Subscription to allow resources to be created. This only has to be done once per subscription. The most straightforward way to do this is within the Subscription element itself.</p>



<p class="wp-block-paragraph">Type in <strong>Subscription</strong> within the search box, navigate to the list of subscriptions, select the one you are using. Then within the Subscription blade scroll down on the left side to <strong>Resource Providers</strong>:</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="887" data-attachment-id="1659" data-permalink="https://gbbcore.wordpress.com/2024/03/28/roll-your-own-avd-on-hci-deployment-part-2-the-plan-identity/image-3-1-2/" data-orig-file="/assets/archive/gbbcore/68ea6832-image-3-1.jpg" data-orig-size="1600,1386" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-3-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/68ea6832-image-3-1.jpg" src="/assets/archive/gbbcore/68ea6832-image-3-1.jpg" alt="" class="wp-image-1659" /></figure>



<p class="wp-block-paragraph">You&#8217;ll want to register the following RPs:</p>



<p class="wp-block-paragraph"><strong><em>Microsoft.HybridCompute</em></strong></p>



<p class="wp-block-paragraph"><strong><em>Microsoft.GuestConfiguration</em></strong></p>



<p class="wp-block-paragraph"><strong><em>Microsoft.HybridConnectivity</em></strong></p>



<p class="wp-block-paragraph"><em><strong>Microsoft.AzureStackHCI</strong></em></p>



<p class="wp-block-paragraph">Select the RPs then click <strong>Register</strong> at the top. You don&#8217;t have to wait for this to complete. Azure Resource Manager is multithreaded and will work on each one until complete. You&#8217;ll need rights to do this in the subscription. Typically, <strong>Contributor</strong> is enough.</p>



<p class="wp-block-paragraph">While you&#8217;re in the subscription, also assign yourself a couple of permissions in IAM. Scroll up select <strong>IAM</strong> &#8211;&gt; Click &#8220;<strong>Add+</strong>&#8221; in the top left corner of the blade. Then select Add Role Assignment. Assign the following Roles:</p>



<p class="wp-block-paragraph"><strong>Azure Stack HCI Administrator</strong></p>



<p class="wp-block-paragraph"><strong>Reader</strong></p>



<p class="wp-block-paragraph">These will allow you to manage the HCI systems deployed within the subscription. Verify the Role Assignments are correct before moving on.</p>



<p class="wp-block-paragraph">Finally, we need to assign the required permissions to deploy the Azure Stack HCI resources. The best way to do that is to pre-create a Resource Group within the subscription. You &#8220;could&#8221; do this subscription wide, but that&#8217;s not a best practice and unless you are going to be creating 100s of clusters across dozens of RGs, it doesn&#8217;t really make sense. Even then, I&#8217;m not sure it does.</p>



<p class="wp-block-paragraph">Once you&#8217;ve completed assigning the RPs and your Subscription level IAM roles, scroll down to <strong>Resource Groups</strong> and create a new Resource Group. Call it whatever you like. Wait for this to complete then select the RG.</p>



<p class="wp-block-paragraph">Inside the RG, you&#8217;ll go to the <strong>IAM</strong> section on the left-hand side of the blade and on the right select &#8220;<strong>Add+</strong>&#8221; like before then Add Role Assignment. You&#8217;ll want to give yourself the following roles:</p>



<p class="wp-block-paragraph"><strong>Azure Connected Machine Onboarding</strong></p>



<p class="wp-block-paragraph"><strong>Azure Connected Machine Resource Manager</strong></p>



<p class="wp-block-paragraph"><strong>Key Vault Administrator</strong></p>



<p class="wp-block-paragraph"><strong>Key Vault Contributor</strong></p>



<p class="wp-block-paragraph"><strong>Key Vault Secrets User</strong></p>



<p class="wp-block-paragraph"><strong>Storage Account Contributor</strong></p>



<p class="wp-block-paragraph">There are programmatic and additional organizational methods to make these rights assignments work at scale. You could use Azure CLI or PowerShell or Cloud Shell to perform all of this. You can also create EntraID groups to organize the assignments or even create a Service Principal to manage all of the onboarding and limit rights assignments to only those who <strong>NEED</strong> to Manage or Troubleshoot all this. All of that can, and should be done if you&#8217;re going to scale this solution, but for a limited environment with very little infra, is that worth it? If so, you can have a look here:</p>



<p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/azure-stack/hci/deploy/deployment-arc-register-server-permissions">Register your Azure Stack HCI servers with Azure Arc and assign permissions for deployment &#8211; Azure Stack HCI | Microsoft Learn</a></p>



<p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-service-principal#azure-portal">Connect hybrid machines to Azure at scale &#8211; Azure Arc | Microsoft Learn</a></p>



<p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-manage-groups">How to manage groups &#8211; Microsoft Entra | Microsoft Learn</a></p>



<p class="wp-block-paragraph">You can use the user rights above and the role assignments with those links to construct a scalable Cloud Identity and Onboarding solution.</p>



<p class="wp-block-paragraph">At this point, we&#8217;ve completed the Identity portion of the solution, and we can begin to install the HCI Nodes. Thanks to <strong>Flo Fox</strong> and <strong>Michael Godfrey</strong> for all the documentation and scripts. Oh, and thanks to <strong>Kevin Sullivan</strong> for letting me use his catch phrase. Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Lee Cox – Advanced Migration GBB Welcome back, and to Part 2 of this series. I hope that you found the first part helpful. Continuing on from the last Blog post you should have a few things sorted out now to begin our ne]]></summary></entry><entry><title type="html">Roll your own AVD on HCI deployment – Part 1: The Gear</title><link href="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-1-the-gear/" rel="alternate" type="text/html" title="Roll your own AVD on HCI deployment – Part 1: The Gear" /><published>2024-03-27T09:34:22-05:00</published><updated>2024-03-27T09:34:22-05:00</updated><id>https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-1-the-gear</id><content type="html" xml:base="https://leecox.pro/gbbcore/roll-your-own-avd-on-hci-deployment-part-1-the-gear/"><![CDATA[<p class="wp-block-paragraph">Lee Cox &#8211; Advanced Migration GBB</p>



<p class="wp-block-paragraph">We often need to try things ourselves. While vendors can provide a test environment or POC gear, it can be faster to make your own setup and bang against it. Working with an OEM or Solution Provider can sometimes be slow, require a business justification that might not be immediately forthcoming or budget, especially in this day and age, that is non-existent. But you&#8217;ve got gear and your crafty. 🙂</p>



<p class="wp-block-paragraph"><em>Please read this in its entirety before taking <strong>any</strong> action. My stream of consciousness writing style isn&#8217;t for the faint of heart.</em></p>



<p class="wp-block-paragraph">Microsoft provides a bunch of ways to try Azure Stack HCI. The most readily available is HCIBox directly linked in the portal to get you a fully up and running environment with very minimal work. The challenge though is it runs on Azure and Azure running a big VM isn&#8217;t exactly cheap. Especially if you&#8217;re using US East/West 24/7. So, with these things in mind, I thought I’d work on a set of blog posts that will help you take gear you might already have and run a test/demo cluster to try out a bunch of interesting and exciting things Microsoft has been working on lately. Please consider this a loose guide vs a strict to-do list. Your mileage may vary, and I&#8217;ll provide a bit of my own experiences and tips along the way. I&#8217;ll try to clear the path as much as I can to make it a straightforward exercise. Yes, this is what it looks like when a Microsoft employee goes rouge-ish. There are very good reasons you shouldn&#8217;t do what I&#8217;m about to explain. Case in point:</p>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph">*** General Disclaimer***</p>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph">You know this isn&#8217;t going to be supported right? Like, you&#8217;re using old potentially out of warranty gear in the hopes to emulate a supported and new solution. Yeah, well just to make sure it&#8217;s said, <strong>You&#8217;re on your own.</strong> Don&#8217;t go complaining to the OEM or Microsoft should the server(s) burst into flames and burn down your House or Datacenter. We warned you. If you turn in a support request in the Azure portal, you will be, politely, told to pound sand.</p>



<p class="wp-block-paragraph">So, you&#8217;ve got some obsolete off lease/decomm&#8217;ed gear laying around and you want to give Azure Stack HCI a try. Awesome! Maybe it&#8217;s some old Haswell or Broadwell spec gear. Maybe it&#8217;s a newer workstation, or a KabyLake Intel NUC. Most anything will do in this type of scenario. It&#8217;s <strong><em>just</em></strong> Windows after all. One thing of note though is that Azure Stack HCI 23H2 isn&#8217;t <strong>strictly</strong> Windows. Azure Stack HCI comes out of the Azure Windows development branch and as such it&#8217;s HCL<strong> IS</strong> slightly different. It&#8217;s one of the many reasons Microsoft works with our OEMs to publish <em>Validated Nodes, Integrated Systems, and Premium Solutions.</em></p>



<p class="wp-block-paragraph">You can find out more about those here: <a href="https://azurestackhcisolutions.azure.microsoft.com/#/Learn">Azure Stack HCI Solutions | Microsoft</a></p>



<p class="wp-block-paragraph">Review the document here for system configuration ideas: <a href="https://learn.microsoft.com/en-us/azure-stack/hci/concepts/system-requirements-23h2#server-and-storage-requirements">System requirements for Azure Stack HCI, version 23H2 &#8211; Azure Stack HCI | Microsoft Learn</a> It&#8217;s your guide to the floor from a config perspective. Bad things <strong><em>will</em></strong> happen when you go below/outside of this.</p>



<p class="wp-block-paragraph">Pay particular attention to the Storage, Networking and CPU requirements. Also ensure that you have a TPM (2.0) and can use Secure Boot. You can run all of this on a single node, but the more you put on one system the slower it will run. Have a look at the HCIBox requirements for an idea of the resources needed. If it&#8217;s Single Node, you should use an all NVME/FLASH storage environment. If you do 2+ nodes, 10Gb RDMA networking is needed between the nodes for Storage Spaces Direct minimum. If you have more than one node. They all need to match from a hardware config perspective.</p>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph">Another special note: Don&#8217;t leave Fiber Channel cards in the server. It&#8217;s bad. HCI is a <em><strong>Hyper Converged Infrastructure</strong></em> solution. It doesn&#8217;t use them and doesn&#8217;t support them. One of the other ways it differs from Windows Server, no SAN disks! And since I mentioned disks, have some. OS Disk (No USB Keys/SD Cards or trying to run Azure Stack HCI on WindowsToGo), and Data Disks. Also ensure that your storage controller isn&#8217;t hiding your disks. It needs to be set to &#8220;IT&#8221; mode. Get IT?? 😀</p>



<p class="wp-block-paragraph">So, if it isn&#8217;t strictly Windows what does that mean? Well, for starters you might have problems booting the ISO Image. I have colleagues who&#8217;ve tried to set this up at home and they end up with BSOD because things that worked in Azure Stack HCI 22H2 aren&#8217;t working in 23H2. A lot was done in the branch to pare down older system support including removing inbox chipset and storage drivers that have been there since the beginning of time.</p>



<p class="wp-block-paragraph">What can I do about that, you say? Well, I&#8217;ll tell you how I get around these types of issues. I install Windows! At least, to begin with. The current Windows Server 2022 release is always a good base to begin with to get up and running and chasing down driver support: drive controllers, nics, OOB Controllers, etc.</p>



<p class="wp-block-paragraph">Go here: <a href="https://www.microsoft.com/en-us/evalcenter/download-windows-server-2022">Windows Server 2022 | Microsoft Evaluation Center</a> get the ISO, or download the latest Non-LTSC release from MSDN, and use Rufus or another method: <a href="https://www.thomasmaurer.ch/2021/11/create-an-usb-drive-for-windows-server-2022-installation/">Create an USB Drive for Windows Server 2022 Installation &#8211; Thomas Maurer</a> to create a bootable USB drive. Install this first on the system.</p>



<p class="wp-block-paragraph">I know what you&#8217;re thinking. &#8220;I&#8217;ve come here to learn how to setup Azure Stack HCI and this numskull is sending me on a wild goose chase!&#8221; Well, yes of sorts. (I prefer snipe hunts myself.) Installing the latest version of Windows does a couple of things for us.</p>



<ol class="wp-block-list">
<li>It gives us a known good OS (with a GUI!) that should work and validates the hardware is stable and able to run something &#8220;quirkier&#8221;.</li>



<li>It allows us to gather and validate all the firmware and drivers we need to move the hardware to a good current config.</li>
</ol>



<p class="wp-block-paragraph">A lot of times, when dealing with decomm&#8217;ed or older hardware it may not have been current when it was powered off or at least now that you&#8217;re powering it back on. We need to check it. The best way to check it is to start clean. Get rid of Linux, ESXi, or older versions of Windows and see what needs to be remediated. An hour on the front end of this adventure will save many more troubleshooting issues trying to get things running later. If the system has an out of band system controller like an iLo, DRAC, XClarity, etc&#8230; those often keep system component and firmware information you can reference to start.</p>



<p class="wp-block-paragraph">After installing Windows Server 2022 (GUI!) onto the system, boot into Windows and do the usual things. Give it a Password, set an IP that can access the Internet, and take inventory of the Device Manager driver situation on the machine. Go to the Manufacturers website under the support section, and search for relevant drivers for the last version of Windows supported on the hardware. Whether that&#8217;s WS2016, Windows 10 etc.. the newer the better. That&#8217;s a good driver baseline and a check against the age of the machine. If it doesn&#8217;t support either of those OSes, find something newer…</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="573" data-attachment-id="1646" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-1-5/" data-orig-file="/assets/archive/gbbcore/f103cee3-image-1.jpg" data-orig-size="3386,1896" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-1" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/f103cee3-image-1.jpg" src="/assets/archive/gbbcore/f103cee3-image-1.jpg" alt="" class="wp-image-1646" /></figure>



<p class="wp-block-paragraph">Key Firmware, Software, and Drivers to collect:</p>



<ul class="wp-block-list">
<li>CPU and Chipset Drivers</li>



<li>Storage Controller Drivers</li>



<li>NIC Drivers</li>



<li>Out of Band Management OS Interface Drivers</li>



<li>Latest/Last versions of System Firmware</li>



<li>OOB, NIC, Storage Firmware</li>
</ul>



<p class="wp-block-paragraph">Be really detailed here and check for any add-in cards within the system, collect those Firmware/Drivers also. The steps here are similar to the work OEMs do for you with the base image of Azure Stack HCI you&#8217;d receive pre-installed. There is often a recipe or Firmware/Driver Bundle published for the specific system that supports Azure Stack HCI. You&#8217;re building that bundle here. </p>



<p class="wp-block-paragraph">Once you&#8217;ve started collecting all that, create a folder on the system and dump the firmware and drivers/software in separate sub-folders. Unpack/Extract as much as you can so that you have *.inf and *.sys files for the drivers. It will help later.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="496" data-attachment-id="1647" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-2-6/" data-orig-file="/assets/archive/gbbcore/8092f315-image-2.jpg" data-orig-size="1959,949" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-2" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/8092f315-image-2.jpg" src="/assets/archive/gbbcore/8092f315-image-2.jpg" alt="" class="wp-image-1647" /></figure>



<p class="wp-block-paragraph"><em>Sample Folder Structure and Components</em></p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="304" data-attachment-id="1648" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-3-2/" data-orig-file="/assets/archive/gbbcore/3b7578c4-image-3.jpg" data-orig-size="1933,575" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-3" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/3b7578c4-image-3.jpg" src="/assets/archive/gbbcore/3b7578c4-image-3.jpg" alt="" class="wp-image-1648" /></figure>



<p class="wp-block-paragraph"><em>Sample Unpacked Drivers</em></p>



<p class="wp-block-paragraph">Run through the drivers first, then the firmware to get the system up to date. Reboot and then run through Windows Updates to see if it finds newer/better versions of anything. Reboot again. Run update again… you know the drill.</p>



<p class="wp-block-paragraph">Once you&#8217;re to a steady state, this system should be as good as it can be. You should validate that you can turn on and use 2 things before moving on. First, the system TPM NEEDS to be 2.0, it&#8217;s called out in the Requirements above. If it&#8217;s 1.2 check and see if the TPM can be swapped out.</p>



<p class="has-cyan-bluish-gray-background-color has-background wp-block-paragraph">Special Note: Some OEMs say that the TPM, which is a removable card, is now integrated into the mainboard and can&#8217;t be swapped. That isn&#8217;t strictly true. Some can be removed (sometimes easily, other times with pliers) and swapped with the 2.0 TPM option. *cough* HP Gen9 Servers *cough*</p>



<p class="wp-block-paragraph">Verify the TPM can be enabled, in Windows Server Admin PowerShell run:</p>



<p class="wp-block-paragraph"><code><strong>Get-TPM</strong></code></p>



<figure class="wp-block-image size-full"><img data-attachment-id="1650" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-4-5/" data-orig-file="/assets/archive/gbbcore/5fd1ecad-image-4.jpg" data-orig-size="581,644" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-4" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/5fd1ecad-image-4.jpg" src="/assets/archive/gbbcore/5fd1ecad-image-4.jpg" alt="" class="wp-image-1650" /></figure>



<p class="wp-block-paragraph">If you see a bunch of &#8220;True&#8221; on the output. You&#8217;re good. If it&#8217;s false, the TPM isn&#8217;t correctly configured in the BIOS/UEFI.</p>



<p class="wp-block-paragraph">Next verify the SecureBoot option is enabled and functional. In Windows Server Admin PowerShell run:</p>



<p class="wp-block-paragraph"><code><strong>Get-SecureBootPolicy</strong></code></p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="174" data-attachment-id="1651" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-5-5/" data-orig-file="/assets/archive/gbbcore/fd50c1b7-image-5.jpg" data-orig-size="1086,185" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;1&quot;}" data-image-title="image-5" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/fd50c1b7-image-5.jpg" src="/assets/archive/gbbcore/fd50c1b7-image-5.jpg" alt="" class="wp-image-1651" /></figure>



<p class="wp-block-paragraph">You should see a GUID and version number if it&#8217;s properly enabled.</p>



<p class="wp-block-paragraph">Check your BIOS/UEFI for both options. You might need to reset the system to factory defaults to properly clear old configs especially if you replace components, add new ones, or swap out the TPM.</p>



<p class="wp-block-paragraph">Once you&#8217;ve got everything ship shape, it&#8217;s time to collect your work. Using the Windows Server 2022 USB Drive you created in the beginning, collect all the driver and firmware files from the system. Put it in a folder named something relevant to the system you&#8217;re working on. If there are multiple nodes, replay this work on all the other nodes to get them healthy and on the same firmware, and UEFI config to move on from here. Yes, install Windows, install the drivers and firmware.</p>



<p class="wp-block-paragraph">The next thing to do is pull down Azure Stack HCI. At this point we need an Azure Subscription, you&#8217;ll have to have one later so, if you don&#8217;t have one. Go get one now. You can sign-up for Visual Studio Dev Essentials which comes with Free Azure Credits. Here: <a href="https://visualstudio.microsoft.com/dev-essentials/">Visual Studio Dev Essentials &#8211; Visual Studio (microsoft.com)</a></p>



<p class="wp-block-paragraph">Once you have your account. Go to: <a href="https://portal.azure.com/#home">Home &#8211; Microsoft Azure</a> and sign in.</p>



<p class="wp-block-paragraph">Once on the landing page, in Search type: Azure Stack HCI</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="525" data-attachment-id="1652" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-6-5/" data-orig-file="/assets/archive/gbbcore/3eadf176-image-6.jpg" data-orig-size="1086,557" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-6" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/3eadf176-image-6.jpg" src="/assets/archive/gbbcore/3eadf176-image-6.jpg" alt="" class="wp-image-1652" /></figure>



<p class="wp-block-paragraph">Select Azure Stack HCI to go to that landing page.</p>



<figure class="wp-block-image size-full"><img data-attachment-id="1653" data-permalink="https://gbbcore.wordpress.com/2024/03/27/roll-your-own-avd-on-hci-deployment-part-1-the-gear/image-7-4/" data-orig-file="/assets/archive/gbbcore/d5fc8baf-image-7.jpg" data-orig-size="999,444" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="image-7" data-image-description="" data-image-caption="" data-large-file="/assets/archive/gbbcore/d5fc8baf-image-7.jpg" src="/assets/archive/gbbcore/d5fc8baf-image-7.jpg" alt="" class="wp-image-1653" /></figure>



<p class="wp-block-paragraph">On that page go to &#8220;Step 2&#8221; and click to download the latest ISO.</p>



<p class="wp-block-paragraph">Once you&#8217;ve pulled down the ISO, now we&#8217;re going to build a new Azure Stack HCI USB install key. This can be the same as the Windows Server USB Key we started with, but we need to get the Driver/Firmware folder off the drive <strong><em>FIRST!</em></strong></p>



<p class="wp-block-paragraph">One way to smooth out the install process and make the drivers self-loaded, is to Slipstream the Azure Stack HCI ISO with the driver packages you&#8217;ve collected. To do this, Thomas Maurer has a great guide to help add those drivers programmatically. Go here: <a href="https://www.thomasmaurer.ch/2019/07/add-drivers-to-a-windows-server-2019-iso-image/">Add Drivers to a Windows Server 2019 ISO Image &#8211; Thomas Maurer</a></p>



<p class="wp-block-paragraph">Build out the directory structure he outlines and mount the HCI Image on your machine. You&#8217;ll substitute Windows Server 2019 with Azure Stack HCI 23H2, but still add the drivers to BOTH the <strong><em>Install.wim</em></strong> and <strong><em>Boot.wim</em></strong> before continuing. Once you have the drivers integrated, copy the contents of the ISO folder over to the USB Key. Then also copy over the Driver/Software/Firmware folder onto the USB Key. You shouldn&#8217;t need it, but if there is software or drivers that aren&#8217;t unpacked or don&#8217;t slipstream you can quickly add those to get things done. As an example, the HPE iLo CHIF driver doesn&#8217;t integrate well. Nor does the config tools for the storage controller and iLo.</p>



<p class="wp-block-paragraph">The main reason to slipstream is to add hardware specific boot drivers that might be missing in the base image especially those required during install and device detection.</p>



<p class="wp-block-paragraph">We&#8217;ll stop here as next step is the Planning and Identity Prep pieces. I want to take a minute and thank <strong><em>Thomas Maurer</em></strong> for the documentation links. His site is invaluable. Thanks for reading!</p>]]></content><author><name>Lee Cox</name></author><category term="gbbcore" /><summary type="html"><![CDATA[Part 1 of a 4 Part series on how to deploy Azure Virtual Desktop on Azure Stack HCI]]></summary></entry></feed>