Advertisements

Virtualization, Cloud, Infrastructure and all that stuff in-between

My ramblings on the stuff that holds it all together

Category Archives: Uncategorized

POSH1Liner: Set NTP server on all hosts attached to a vCenter

Connect-VIServer L2-mgt-vcsa01.theborg.int
Get-VMHost | Add-VMHostNtpServer -ntpserver “pool.ntp.org”
Get-VMHost | Get-VMHostFirewallException | where {$_.Name -eq “NTP client”} | Set-VMHostFirewallException -Enabled:$true
Get-VMHost | Get-VmHostService | Where-Object {$_.key -eq “ntpd”} | Start-VMHostService
Get-VMhost | Get-VmHostService | Where-Object {$_.key -eq “ntpd”} | Set-VMHostService -policy “automatic”

Original script from this blog post Modified to add -ntpserver parameter and public NTP server name incase you don’t have your own

Advertisements

POSH1Liner:Deploy VM from template

Populate variables

$targetdisk = Get-Datastore -name vd03*
$target = get-vmhost -name l1-mgt-slotXX.theborg.int

#Deploy VM from template
new-vm -name L2-C2-NXX -Template TPL_vESXI -vmhost $target -Datastore $targetdisk -runasync

#rinse & repeat

Posh1Liner – Add ESX Host to vCenter

#Connect to vCenter server
$vc = connect-viserver -name l2-mgt-vcsa01.theborg.int
Add-VMHost -server $vc -name L2-C1-N4.theborg.int -location theBORG -user root -Password YourPassword -force -RunAsync

#then add to cluster L2-C1
Move-VMHost L2-C1-N1.theborg.int -destination L2-C1

#Add a bunch of hosts to vCenter 1 liner
for($i=99; $i -le 102; $i++) {$runline= “L2-C2-N” + $i +”.theborg.int” ; Add-VMHost -server $vc -name $runline -location theBORG -user root -Password VMware1! -force -RunAsync}

#put hosts following a naming pattern into maintenance mode
get-vmhost -name L2-c2* | set-vmhost -state maintenance

#move ESX host called L2-C2-N$i to L2-C2 cluster

for($i=2; $i -le 8; $i++) {$runline= “l2-c2-n” + $i +”.theborg.int” ; move-VMHost $runline -server $vc -destination L2-C2}

Clicking Configure to bind with a Google Android for Work account in Azure InTune doesn’t do anything

I hit this and scratched my head for ages. I was using a Mac (so I’ve not tried this in IE or Edge, where I would expect it to work).

if i hit the configure button under “device enrolment” / “Android for Work enrolment” it does nothing in Chrome or Safari (my 2 normal browsers)

spent ages disabling plugins, Private mode etc. however, weirdly – it worked 1st time in FireFox…

So if you hit the same issue and have found this via Google – try that.

online UI and docs are moving quickly for InTune as it’s absorbed into Azure.

weird.

Password sync Warning: no recent synchronization on Office365

If you manage an Office365 tenant like I do for my lab, and are security minded you may decide to change the password of the account you configured AAD Connect to use to talk to your on-prem Active Directory. For example if maybe you were lazy and used the default domain administrator account in your lab…. tut, tut :)) you need to update AAD Connect to reflect the new password otherwise you’ll get “Password sync Warning: no recent synchronization” on your admin page and no password changes will sync to Office365.

*I* thought you did this by running the Azure AD Connect tool and re-entering the password there, refreshing the directory. nope and other error logging is a bit sparse, other than the warning in the o365 tenant admin portal.

Password sync Warning: no recent synchronization on Office365

There are some excellent PowerShell utils for debugging this stuff in this post

in my case I got an error back like the following;

AAD Tenant - MyTenant.onmicrosoft.com
Password hash synchronization cloud configuration is enabled

AD Connector - MyDomain.tld
Password hash synchronization is enabled
No password hash synchronization heartbeat is detected

Connectivity:
=============
Directory Partition - MyDomain.tld
Password synchronization agent had a problem to resolve a domain controller in the domain "MyDomain.tld" at: 07/
11/2017 16:38:19 UTC
Please make sure AD Connector account username and password are correct
Only Use Preferred Domain Controllers: False
Checking connectivity to the domain...
Domain "MyDomain.tld" is reachable

Would you like to diagnose single object issues? [y/n]: n

For more help:
+ Please see - https://go.microsoft.com/fwlink/?linkid=847231 or
+ Open a service request through Azure Portal or Office 365 Admin Portal.

Which led me to think maybe AAD Connect was still using the old password.

To actually change the password and configure more details there is another utility outside of the Azure Connect wizard called “Synchronization service” which resides under “Azure AD Connect” on your start menu, run this. select the connectors to MyDomain.tld hit properties/Connect to AD Forest and update the password for the account you use to connect to on-prem AD.

You can also use this utility to configure a preferred domain controller if you don’t want it to follow the normal DC discovery process (useful if you have a segregated environment)

Blogged for when I have to do this again and invariably forget how..

Where there are geeks, there are gadgets – a cautionary vBeers tale

At the London VMUG we’ve held social beers in a pub after the event for over 10 years, in what has become known as vBeers.

In all that time I’m pleased to say that we’ve never had any problems, it’s all been good social fun. As you’d expect most of our attendees come with gadgets. Laptops, tablets, phones, watches etc. and we’ve never had any issues – other than the occasional identical bag or phone picked up by mistake. but quickly resolved.

Unfortunatley at our most recent event we were targetted by an oportunist thief who helped themselves to a selecton of gadgets from the bag pile – directly under the pub CCTV system.

The pub think they have identified the thief on CCTV and will be handing it over to the police.

Hopefully that won’t detract from future events or discourage you from attending some crime is unfortunatley inevitable in a large city like London but please do be careful and don’t make yourself a target. Keep an eye on your bag as you never know who is keeping an eye on your bag for you.

London and UK VMUG Dates 2016 and 2017

Dates for your diary for our future events, keep an eye on http://vmug.com/london for details of the agenda – Also feel free to join our LinkedIn group or follow our London VMUG Twitter feed and UKVMUG Feed to be kept up to date, we will post/tweet when the agenda and registration link is live as well as any logistical info.
2016

23 June at TechUK in London – followed by Luxury vBeers at a brewery
November 17th National Motorcycle Museum for the national UKVMUG

2017

19 January TechUK, London
6 April TechUK, London
22 June at TechUK, London
#UKVMUG 16th November at the National Motorcycle Museum, Solihull (Near Birmingham)

We (the committee) pride ourselves on promoting community content, we’re all about the U in VMUG – if you have an idea for a session at one of these events – you can use our handy call for papers form

Look forward to seeing you at a future meeting

 

How much do VMUG leaders contribute to VMUG globally

I’ve just attended the 1st annual VMware User Group Leader Summit, a day and a half event hosted at the VMware campus in Palo Alto to share best practice amongst the various groups around the world to better the organisation which was an excellent event.

The event was an impressive showing of commitment from VMware to the community in terms of the focus it has, but was more impressive was the scale of effort that the VMUG leaders put into their events – there aren’t many real rewards for being a VMUG leader other than some kudos and a pat on the back and it’s a very clear sign of people’s passion for the technology that they give this time freely.

Some leaders are self-employed or work full-time for an employer – but generally the time they give is their own personal, unpaid time as vacation time or work time that has to be made-up in personal time.

The London VMUG group of which I’m a leader in is currently going through a transition to a new team of leaders (I’m staying on but 3 leaders are stepping down after many years of service) and we’ve spent some time trying to quantify how much effort is required to run a VMUG group so we can set expectations appropriately for our new incoming leaders;

This is based on our experiences running 3 London (~100 attendees) and 1 UK national event (~600 attendees) each year.

Disclaimer this is very finger in the air analysis (and a little bit of fun) – but I do think it’s interesting to look at the opportunity cost of such activities (info on opportunity cost here) and other interesting {honest!} economics stuff here

Between the 4 of us we have 4 full-day meetings, so 4 man-days** contributed per meeting which we attend*, plus on average 2hrs of calls per month = 24hrs = 3 man-days/yr. (@8hrs/day) – so individually each leader contributes 7 man-days per year of effort to manage and run our events.

*I’ve not managed to sit through and enjoy a session at the London or UK VMUG meetings since I became a leader, because there is always something that needs doing, cats to herd, things to organise – not complaining, but – that’s the truth!

Our leadership team consists of 4 people, if we said the average group is 3 leaders (some have 7+, some have just 1!).

I don’t have access to all the details of the global VMUG chapters, but if you work on the basis that there was 1 leader invited from each active VMUG globally to the summit, there were 93 leaders in-attendance so let’s base our numbers on 93 ‘active’ groups – although I appreciate there are probably more as not everyone would be able to attend.

if we said an average of 3 leaders per ‘active’ group, each contributing 7 man-days per annum that’s 1,953 man-days per annum contributed by leaders to the VMUG community events. (3 x (4+3) ) x 93 = 1,953 man-days

Given there is an average of 251 working days per year that’s 7.7 man-years

Now, to make this more interesting, if we said the average salary of a VMware administrator was $80k USD (sort-of based on this article, and assuming that an VMUG leader will generally have more than 2 years of experience under their belt and will generally be in a senior-type role, the majority of VMUG leaders are in the US and salaries outside the US will obviously differ, but most VMUGs exist in well-developed 1st-word countries, rather than 2nd/3rd world emerging countries)

That would mean a VMUG leader globally earns an average of $318 per day before tax, multiply that out by the number of man-days given per year, that represents an opportunity cost that the VMUG leaders contribute to the VMware community & VMware itself of…..(drum-roll)

$622,470.12 USD.

Not too shabby 🙂 VMware, I hope you appreciate it 🙂

Anyways – just a bit of fun and not to be taken too seriously, but do go and hug a VMUG leader at your next meeting… (ok, don’t do that!)

 

 

**Yes, there are also many women who are VMUG leaders.. but man-days is an accepted term, and it’s shorter to type than person-years, apologies if it offends, it’s not meant to!

 

Making your OS X Terminal more useful for DOS refugees

I’m a DOS/Windows old-timer, but have been using a Mac for a number of years.. I find the OS X terminal (which is the *NIX bash shell) very flexible, but needs some tweaks to help me with my embedded DOS muscle memory – this is probably very basic and old-hat for *NIX types, but it’s here for my reference as I keep forgetting when I move to a new Mac.

If you look in your home dir “cd ~” you need to create (or edit, if it already exists) the “.bash_profile” file – you can do this with TextEdit, or use nano (“nano .bash_profile”)

Paste in the following contents

———–

export CLICOLOR=1
export LSCOLORS=GxFxCxDxBxegedabagaced
alias dir=”ls -ahl”

———–

Save the file (CTRL-X, yes, enter) in nano

then type “source .bash_profile” to load the changes (or start a new terminal session)

You now have a more DOS-like prompt with the full path in it, colour coding for different types of files and a “dir” command which shows the contents of the current directory by aliasing the “ls” command and adding some parameters to show it list-like.

Some really helpful references here http://natelandau.com/my-mac-osx-bash_profile/

Also – in terminal, terminal->preferences/profiles and you can set the “pro” profile as default by hitting the “default” button at the bottom of the pick list – also remember to check “Antialias Text” for sharper text.

POSH1Liner: Find all hosts with less RAM than you expect

If you have a cluster where maybe there are some hosts with spared out RAM due to a fault or a non-standard amount of RAM you can quickly find them with this command

get-vmhost | where {$_.MemoryTotalGB -lt THE_AMOUNT_YOU_EXPECT}

For example; to find all hosts with less than 512GB of RAM

get-vmhost | where {$_.MemoryTotalGB -lt 512}

“-lt” is “less than” which is slightly less intuitive than the usual < <= operators you'd use in other languages – but handy reference here http://ss64.com/ps/syntax-compare.html

As I go deeper with PowerShell (POSH) I like convenient things like the $_. syntax – makes it dead simple to come up with useful one-liners like this.