0

VMware Horizon View: App Volumes

  1. Configuring App Volumes Manager 8

Verify License 8

Configuring and Using Active Directory    9 Active Directory Domains Page 10 Connecting Securely to Active Directory 11

Adding and Configuring Domain Controller Hosts 12 Register an Active Directory Domain 14

Assigning and Managing Roles and Privileges  17 Monitoring Active Directory Entities 22

View Active Directory Entities 22 Sync Entities with Active Directory 23

Types of Hypervisor Connections and Machine Manager Configurations 24 Configure and Register the Machine Manager 26

Configuring App Volumes Manager for VMware Cloud on AWS 27 Configuring Security Protocols and Cipher Suites 28

Configure TLS Connections in App Volumes Manager 28 TLS v1.0 Protocol Communication 29

Configure Cipher Suites in App Volumes Manager 29 Configuring Storage 30

Support for Shared Datastores 30 Configure Storage For Packages 31 Configure Storage For AppStacks (2.x) 32 Configure Storage for Writable Volumes 33 Upload Templates 35

Configure VHD In-Guest Storage 37

Configure Asynchronous Mounting on App Volumes Manager and Agent 37 Enable Asynchronous Mounting On The App Volumes Agent 38

Enable Asynchronous Mounting On App Volumes Manager 38 App Volumes Manager Configuration Settings Page 39

Register App Volumes Manager Server 42 Remove an App Volumes Manager Server 43 View Status of App Volumes Manager Servers 44 Activate Registration Security 44

Configuring SSL Certificates for Machine Managers 45 Establishing a Secure SQL Server Connection    45 Establish a Secure vCenter Server Connection   46

Managing SSL Between App Volumes Manager and Agent 47 Replace the Self-Signed Certificate with CA-signed Certificate                                          47 Import Default Self-Signed Certificate     48

Disable SSL Certificate Validation in App Volumes Agent   49 Enable HTTP in App Volumes Manager           50

Disable SSL in App Volumes Agent   52 Check for SSL Certificate Revocation                                                               53

Create an Application   54

Import an Application to App Volumes   55 Rescan Applications         56

Assign an Application to an Entity   56 Understanding Assignment Types 57

Unassign an Application from an Entity   57 Create a Package for an Application         58

Lifecycle of a Package 59 Edit an Application      59 Delete an Application                              59

Package an Application 61

Preparing a Packaging Virtual Machine 62 Best Practices for Packaging Applications 63

Update a Package 64

Set the CURRENT Marker on a Package 64 Unset the CURRENT Marker on a Package 65 Edit a Package 65

Move a Package 65 Delete a Package 66

Features of Writable Volumes 68

Assigning and Attaching Writable Volumes 69 View Writable Volumes Information 70 Create a Writable Volume 70

Import Writable Volumes 73

Enable a Writable Volume 74 Update Writable Volumes 74 Edit a Writable Volume 75 Rescan Writable Volumes 76 Expand a Writable Volume 76 Disable a Writable Volume 77 Delete a Writable Volume 77

Move, Back Up, and Restore Writable Volumes 78 Move a Writable Volume 79

Back Up a Writable Volume 80 Restore a Writable Volume 82

Writable Volume Exclusions 83

Specify Exclusions in a Writable Volume (Configuration File) 84 Protecting Writable Volumes 85

View Programs 87

View Attachments 88

View Assignments   89

  1. Perform App Volumes 2.x Management Tasks 90

Enable VOLUMES (2.X)   91

  1. Working with Volumes and the 2.x App Volumes Agent 92

Working with AppStacks   93

Creating and Provisioning AppStacks 93 Assigning and Attaching AppStacks 97 Edit an AppStack 102

Update an AppStack 103

Import AppStacks to App Volumes 103

Check Datastores for Available AppStacks 104 Unassign an AppStack 104

AppStacks Precedence 105

Delete AppStacks 105

Working with Writable Volumes (2.x)   106 Create a Writable Volume (2.x) 106 Import Writable Volumes (2.x) 109

Enable a Writable Volume (2.x) 110 Update Writable Volumes (2.x) 110 Edit a Writable Volume (2.x) 111 Rescan Writable Volumes (2.x) 112 Expand a Writable Volume (2.x) 112

Reassign a Writable Volume (2.x) to a Computer 113 Disable a Writable Volume (2.x) 114

Delete a Writable Volume (2.x) 114 Move a Writable Volume (2.x) 115 Back Up a Writable Volume (2.x) 116 Restore a Writable Volume (2.x) 118

Specify Exclusions in a Writable Volume (2.x) (Configuration File) 119 Working with Attachments 120

View Attachments (2.x) 120 Working with Assignments 120 View Assignments (2.x) 120

Configuring visibility and management of App Volumes Manager 2.x UI 121

  1. Configure Infrastructure 122

View Managed Machines 122

View Managed Storage Locations 123 Configure Storage     123

Configure Storage Groups 124

  1. Advanced App Volumes Configuration 126

Policy Files and Scripts 126 Batch Script Files 127

Configure Batch File Timeouts 127 Configuring SVdriver and SVservice 127

Configuring the SVdriver Parameters 129 Parameters for Configuring SVservice 130

Create a Custom vCenter Server Role 132

Create a Custom vCenter Server Role Using PowerCLI 134

  1. Troubleshooting App Volumes 136

Configure the Interval of Background Jobs 137 Background Jobs in App Volumes Manager 137

Create a Troubleshooting Archive 139 Remove a Troubleshooting Archive 139

Reduce App Volumes Login Time on Windows 10 140

Default Storage Location on the Storage Page in the App Volumes Manager UI Is Displayed as Not Configured 140

Verify License

You must enter the App Volumes license information before configuring other components. A valid license is required to activate and use App Volumes.

Prerequisites

Ensure that you have downloaded and installed the App Volumes license file. The production license file can be downloaded from the VMware App Volumes product download page.

Procedure

  1. From the App Volumes Manager console, click CONFIGURATION > License.
  • Verify the license information that is displayed.

If you have an evaluation license, you can use App Volumes until the expiration date.

  • (Optional) To apply a different license, click Edit and browse to the location of the license you want to upload.
  • Click Upload to upload the App Volumes license file.
  • Click Next and follow on-screen instructions.

Configuring and Using Active Directory

App Volumes uses Active Directory to add domains and assign applications and Writable Volumes to users, groups, computers, and Organizational Units (OUs).

As an administrator with full access to App Volumes Manager, you can configure and work with Active Directory domains and users in many ways:

  • Add multiple Active Directory domains and assign unique credentials and administrator access to users from these domains.
  • Assign Writable Volumes to a specific user.
  • Filter entities based on their domain
  • Search across multiple Active Directory domains
  • Manage assignments for any user, group, or computer from any configured Active Directory domain.
  • Add multiple domain controller hosts.
  • Connect securely to Active Directory and optionally, validate the certificate.

Active Directory Objects Lookup

App Volumes Manager looks up Active Directory objects by their GUID instead of UPN (User Principal Name). Using GUID enables administrators to move users across domains and organizational units (OUs) and even rename users and computers without affecting their Applications, Packages, AppStacks, or Writable Volumes assignments.

Automatic Active Directory Synchronization

App Volumes Manager maintains a database record for any Active Directory that is seen by an App Volumes Manager agent or assigned to an Application, Package, AppStack, or a Writable Volume.

A background job runs every hour to synchronize up to 100 entities in the Active Directory. If there are more than 100 objects, then the next batch of 100 objects is synchronized in the hour after the first batch of objects has been synchronized.

Note GUID synchronization from Active Directory servers might take up to a week and it varies based on the number of objects that are present in the system.

Active Directory Synchronization

When a user is removed and the same user logon name is added again to Active Directory, and App Volumes has not yet synchronized the directory, conflicting Writable Volumes entries might get created. The conflicted entries are displayed in the App Volumes Manager until the Active Directory is synced.

When Packages, AppStacks, or Writable Volumes are attached to a user who was removed and added again to the directory, the user is considered as a new Active Directory user, and only the assignments for this user are tracked and displayed. Any old assignments are removed (if the directory was synced) or are shown as conflicted entries.

Go to DIRECTORY > Users > Sync to synchronize and view the latest list of users.

Multiple Active Directories with Universal Security Groups

When multiple Active Directory domains are used with Universal Security Groups for Applications, Packages, AppStacks, or Writable Volumes assignments, or for administrative access either directly or using nested group membership, all the domain controllers that are accessible by App Volumes Manager must host the Global Catalog (GC). In a default setup, this means all the domain controllers in the domain must have GC enabled. If this is not possible, configure specific domain controllers in the App Volumes Manager configuration. For more details, see the User Security Attributes section for Active Directories on the Microsoft Developer Network site.

Active Directory Domains Page

The Active Directory Domains page in the App Volumes Manager shows information about the configured domains and displays the list of configured domain controllers.

Navigate to CONFIGURATION > AD Domains to view following information about the configured domains:

  • Active Directory Domain Name
  • Netbios
  • LDAP Base
  • Username
  • Security (secure or insecure communication and if certificate validation was skipped in case of secure communication)
  • Port
  • Domain Controllers
  • Date and time of creation of the domain

Click View DCs to see information about the configured and discovered domain controller hosts:

  • Name
  • connection status
  • Date and time the host last connected
  • Date and time the connection failed
  • Failure count

Connecting Securely to Active Directory

As an App Volumes administrator, you can choose to connect to Active Directory over a secure or insecure LDAP connection.

  • Secure LDAP (LDAPS) – Connect to Active Directory over a dedicated LDAPS port. The default port number for LDAPS is 636. If you choose to validate the root certificate of the domain, you must have already downloaded the CA certificate. App Volumes uses this certificate to trust the connection.
  • LDAP over TLS – Connect to Active Directory over TLS. The default port number for LDAP is

389. If you choose to validate the root certificate of the domain, you must have already downloaded the CA certificate. App Volumes uses this certificate to trust the connection.

  • LDAP (insecure) – Connect to Active Directory over an insecure connection over plain LDAP.

Note The initial binding however, occurs over GSS-SPNEGO.

The Disable certificate validation(insecure) checkbox enables you to connect securely to Active Directory over LDAPS or LDAP over TLS without validating a domain certificate. Depending on whether you are upgrading from an older version of App Volumes, and if you had connected securely to Active Directory in your earlier installation of App Volumes, or if you are performing a fresh installation, the Disable certificate validation(insecure) box may be checked or unchecked in the latest version of App Volumes.

Note The Disable certificate validation(insecure) checkbox is visible only if you select LDAPS or LDAP over TLS.

Configure CA Certificates in App Volumes Manager

You must configure the root domain CA certificates if you want to connect securely to Active Directory and also validate the certificate.

Prerequisites

  • You must have downloaded root certification authority (CA) certificates of the Active Directory domains. If the certificates are not in PEM (Base64 encoded) format, see the OpenSSL or similar documentation to convert the file to PEM format.

Note When you have multiple root certificates from different domains, you can combine all the PEM formatted certificates into a single file by copying the contents of each file one by one to a single .pem file.

  • In App Volumes Manager, domain controller host names that are specified in the domain controller hosts field must match the certificate host names.

Procedure

  1. Ensure the name of the PEM formatted certificate file is adCA.pem.
  2. On each App Volumes Manager server, copy the adCA.pem file to the /config directory where the App Volumes Manager is installed.

The default installation location for App Volumes Manager is C:\Program Files (x86)\Cloud Volumes\Manager.

  • Restart the App Volumes Manager servers.

What to do next

Use App Volumes Manager to connect securely to Active Directory Connection using LDAP over SSL (LDAPS) or StartTLS (LDAP over TLS).

Adding and Configuring Domain Controller Hosts

You can add a single domain controller host or multiple hosts when you register an Active Directory (AD).

You might configure multiple domain controller hosts to ensure redundancy and failover operations. If the primary domain controller that App Volumes Manager is connected to becomes unavailable, then App Volumes Manager can perform a failover and switch to a different host.

This redundancy ensures that App Volumes users are unaffected by the downtime and can continue their operations without interruption.

You can select how App Volumes Manager detects domain controllers. Consider the following when you add domain controllers:

  • If you provide a list of domain controllers, App Volumes Manager looks for a domain controller only in the list you provided. If the domain controllers in the list are all down, App Volumes Manager connects to the AD with the domain as the host. But the manager will continue to try to connect to one of the domain controllers in the list every 5 minutes. This process slows down the system.
  • Connecting to domain controller using the domain as a host only works with LDAP(insecure). The connection will fail if you use LDAPS or “LDAP over TLS” with certificate validation.
  • If you do not provide a list of domain controllers, App Volumes Manager detects domain controllers automatically and also assigns a priority to them.
  • App Volumes Manager will search for and try to connect to domain controllers from the same site. Domain controllers from other sites are also added in order of binding time.
  • Do not include non-ASCII characters in the domain controller name.
  • Domain controllers in the same site always have higher priority over the DCs from different sites.

You can view the list of domain controllers and their connectivity status under CONFIGURATION

>   AD Domains.

Refresh Domain Controllers

The list of available domain controllers is refreshed every 480 minutes (8 hours). Use the environment variable, TIME_TO_REFRESH_DOMAIN_CONTROLLERS, to change the default time of 8 hours. You must set the time in minutes.

NTLM Authentication

NTLM (NT LAN Manager) authentication is used to make the communication between App Volumes Manager and agent more secure.

Note Domain Controller failover is not supported for NTLM-based authentication. If the first available domain controller is down, then NTLM authentication fails. However, if the App Volumes agent logs out and logs in again, NTLM authentication will go through since the App Volumes manager again queries for the first available domain controller.

Disable Microsoft Windows NTLM Authentication

When an App Volumes agent make an HTTP request to the App Volumes Manager, NTLM is used to authenticate the user and user account with the entry in the Active Directory.

You can disable NTLM by defining a system environment variable on the machine where App Volumes Manager is installed.

See https://technet.microsoft.com/en-us/library/jj852241(v=ws.11).aspx to understand the implications of disabling NTLM.

Procedure

  1. Log in as administrator to the machine where App Volumes Manager is installed.
  2. Open Control Panel and click System > Advanced System Settings > Environment Variables
    1. New.

The New System Variable window appears.

  • In the Variable name text box, enter AVM_NTLM_DISABLED.
  • In the Variable value text box, enter 1.
  • Restart the computer.

The App Volumes Manager service also restarts.

Register an Active Directory Domain

Configure and register an Active Directory domain. You can assign applications to users, computers, groups, and organizational units (OUs) using Active Directory.

Prerequisites

Procedure

  1. From App Volumes Manager, go to CONFIGURATION > AD Domains.
  2. Click Register Domain.
  3. Enter the Active Directory information on the Register Active Directory Domain page.
ParameterDescription
Active Directory Domain NameA fully qualified domain name of the Active Directory domain where users and target computers are residing, for example corp.example.com.
Domain Controller Hosts (Optional)IP address (10.98.87.67) or FQDN (dc01.corp.example.com). You can also provide the virtual IP address of a load balancer that is used as the front-end server of the domain controller. This option provides High Availability (HA) capability for connections to Active Directory.   Note Do not include any non-ASCII characters in the domain controller name. You can add multiple domain controller hosts; use commas to separate the names of the hosts.   Important If you do not add a domain controller host, the system detects the hosts that are available and connect to the nearest domain controller.
  
LDAP Base (Optional)Distinct name of the Active Directory container or organizational unit that stores required entities (if you want to limit the scope of enumeration). By default, App Volumes Manager enumerates all users, groups, OUs, and computer objects within Active Directory. Example: OU=Engineering, DC=corp, DC=vmware, DC=com
UsernameThe user name of the service account that has access to the target Active Directory domain. For example, admin-1. The user can be an administrator with read-only permissions.
PasswordThe password for the service account. Ensure that domain policies do not enforce password expiration for the service account.
SecuritySelect one of the following options from the drop-down menu to configure the LDAP connection: Secure LDAP (LDAPS) – Select this option if you want to connect to Active Directory over SSL.LDAP over TLS – Connect to Active Directory over LDAP using TLS. You must have installed a trusted certificate from a certificate authority.(Optional) Disable certificate validation (insecure) – Displayed only if you choose LDAPS or LDAP over TLS. Check the box to connect securely without validating the certificate using the root CA certificate.LDAP (insecure) – Connect to Active Directory without using a secure connection.
Port (Optional)A port number other than the default. The default port is used if this text box is left blank.
  • Click Register.

Edit an Active Directory

You can update and change the configuration information for a registered Active Directory.

Procedure

  1. From App Volumes Manager, go to CONFIGURATION > AD Domains. A list of configured domains is displayed.
  2. Select a domain from the list and click Edit.
  3. Update the information on the Edit Active Directory Domain page.
ParameterDescription
Active Directory Domain NameA fully qualified domain name of the Active Directory domain where users and target computers are residing, for example corp.example.com.
Domain Controller Hosts (Optional)IP address (10.98.87.67) or FQDN (dc01.corp.example.com). You can also provide the virtual IP address of a load balancer that is used as the front-end server of the domain controller. This option provides High Availability (HA) capability for connections to Active Directory. You can add multiple domain controller hosts; use commas to separate the names of the hosts.   Important If you do not add a domain controller host, the system detects the hosts that are available and connect to the nearest domain controller.
  
LDAP Base (Optional)Distinct name of the Active Directory container or organizational unit that stores required entities (if you want to limit the scope of enumeration). By default, App Volumes Manager enumerates all users, groups, OUs, and computer objects within Active Directory. Example: OU=Engineering, DC=corp, DC=vmware, DC=com
UsernameThe user name of the service account that has access to the target Active Directory domain. For example, admin-1. The user can be an administrator with read-only permissions.
PasswordThe password for the service account. Ensure that domain policies do not enforce password expiration for the service account.
SecuritySelect one of the following options from the drop-down menu to configure the LDAP connection: Secure LDAP (LDAPS) – Select this option if you want to connect to Active Directory over SSL.LDAP over TLS – Connect to Active Directory over LDAP using TLS. You must have installed a trusted certificate from a certificate authority.(Optional) Disable certificate validation (insecure) – Displayed only if you select LDAPS or LDAP over TLS. Select the box to connect securely without validating the certificate using the root CA certificate.LDAP (insecure) – Connect to Active Directory without using a secure connection.
Port (Optional)A port number other than the default. The default port is used if this text box is left blank.
  • Click Update.

Remove an Active Directory

Remove an Active Directory.

Procedure

  1. From App Volumes Manager, go to CONFIGURATION > AD Domains. A list of configured domains is displayed.
  2. Select a domain from the list and click Remove.
  3. Click Remove on the Confirm Remove window.

Handling Authentication Failures

App Volumes uses Active Directory to add domains and assign applications and Writable Volumes to users, groups, computers, and Organizational Units (OUs). App Volumes thus inherits the authentication and account policies of Active Directory.

Authentication Overview and Group Policy Settings

Active Directory implements authentication measures such as inserting random delays between failed authentications, configuring the number of failed authentication attempts and so on.

See https://docs.microsoft.com/en-us/windows-server/security/windows-authentication/ windows-authentication-overview for an authentication overview and https:// technet.microsoft.com/en-us/library/dn751050(v=ws.11).aspx for information about Group Policy Settings of Active Directory.

Assigning and Managing Roles and Privileges

You can assign built-in roles or custom roles to Active Directory groups. All users within the group will inherit the privileges that have been defined for the role.

You can assign the following built-in roles from the App Volumes Manager:

  • Administrators – Has permission to perform all operations including adding and settings permissions for other administrators.
  • AppStacks Administrators
    • Can perform all operations related to AppStacks such as create, import, rescan, update, and so on.
    • Has only viewing access to other resources such as Directory or Infrastructure.
    • Does not have access to Configuration or Writable Volumes.
  • Inventory Administrators
    • Can perform operations related to Applications such as create, import, rescan, update, and so on.
    • Can perform operations related to Writable Volumes and Writable Volumes (2.x) such as create, import, update, rescan, and so on.
    • Has only viewing access to other resources such as Directory or Infrastructure.
    • Does not have access to Configuration resources.
  • Administrators (Read only) – Can only view the resources but cannot make any modifications or perform other tasks.
  • Security Administrators
    • Has permission to manage roles such as create, update, and delete custom roles.
    • Manage and change role assignments.
  • Writables Administrators
    • Can perform all operations related to Writable Volumes and Writable Volumes (2.x) such as create, import, update, back up, and so on.
    • Has only view access to other resources such as AppStacks, Directory, Infrastructure, Storage Groups and so on.
    • Does not have access to Configuration resource.

Note To view the privileges assigned to a role, go to CONFIGURATION > Admin Roles > Manage Roles, select a built-in role or a custom role, and click Show.

Custom Roles

Note the following about custom roles and assigning multiple roles.

  • You can create custom roles with specific privileges and assign them to groups. Whenever privileges are changed for the custom roles, they are dynamically updated and the members of the group receive the updated privileges immediately.
  • You can assign multiple roles to a group. In such a case, the group will get the union of the privileges of the different roles assigned to it.

Note

  • When a new role is assigned to a group, the users of the group must log out and log in again to the system before they can get the privileges offered by the role.

  • When creating custom administrator roles, granting view privilege to either AppStacks or applications will effectively grant view privileges to both functions.

Administrators (Read only)

A read-only administrator can only view the resources and configuration information but cannot perform any other tasks. Specifically, a read-only administrator cannot perform the following functions:

  1. Make configuration changes to the App Volumes Manager.
  2. Create or import Application Packages.
  3. Create or import AppStacks.
  4. Make storage configuration changes.
  5. Add or remove Active Directory domains.
  6. Add or remove Machine Managers.
  7. Create, import, or update writable volumes.

A read-only administrator can be added only by an existing administrator who has complete access to the App Volumes Manager functionality.

As an administrator, you can add a read-only account to a group of users that belong to a particular domain. For example, if you have created a domain xyz.com, then you can create a read-only account belonging to the domain xyz.com.

Note You cannot create a read-only account for a single user.

Assign a Role

You can assign built-in or custom roles to Active Directory groups. All users of the group inherit the privileges offered by the role.

An Active Directory group can have more than one role assigned to it.

Prerequisites

You must have already added the member or group to the Active Directory database.

Procedure

  1. From App Volumes Manager, click CONFIGURATION > Admin Roles > Assign Role.
  2. Select the type of role you want to add from the drop-down menu. If you had previously added a custom role, the custom role is also displayed in the drop-menu.
OptionDescription
AdministratorsAn administrator with access to all the functions in the App Volumes Manager.
AppStacks AdministratorsAn administrator to manage AppStacks.
Administrators (Read only)An administrator who can only log in to App Volumes Manager and monitor the App Volumes configuration details. The read-only administrator cannot make any modifications.
Security AdministratorsAn administrator who can manage custom and built-in roles.
Writables AdministratorsAn administrator who can manage Writable Volumes.
  • Search the domain for the administrator or group that you want to add. Select All to search in all domains or select a specific domain from the drop-down menu.
  • Enter a string to search for the administrator in the configured Active Directory Groups and click Search.

You can filter the search query by Contains, Begins, Ends, or Equals.

You can also leave the search field blank and click Search. The complete list of groups is displayed.

a   (Optional) Select the Search all domains in the Active Directory forest box to search all domains in the entire Active Directory forest.

A drop-down menu with a list of groups matching your search query is displayed.

  • Select the Active Directory group from the list.
  • Click Assign.

Results

The selected role is assigned to the group and you can view the updated list on the Administrator Roles page.

Update Assigned Roles for an Active Directory Group

Update the privileges for an Active Directory group by changing the assigned role. You can also select a new group and assign a role to the group.

If there is only group that is assigned the Administrators role, you cannot remove the Administrators role for that group. However, you can add other built-in or custom roles to the group.

Procedure

  1. From App Volumes Manager, click CONFIGURATION > Admin Roles. A list of groups and associated roles is displayed.
  2. Select the group whose privileges you want to edit and click Edit.
  3. Select a new role on the Administrator Roles page.
  4. (Optional) If you want to change the group, search and select the new group.

The selected role is assigned to the new group, and the original role is unassigned from the current group.

  • Click Update.

Remove an Assigned Role

You can remove privileges from an Active Directory group by removing the role that was assigned to the group.

If only one group is assigned the Administrators role, you cannot remove that role since at least one administrator must be configured at all times.

Note If you remove a custom role that is assigned to a group, you are only removing the assignment of the role and not the role itself.

Procedure

  1. From App Volumes Manager, go to CONFIGURATION > Admin Roles. A list of groups and associated roles is displayed.
  2. Select the group for which you want to remove the role and click Remove.
  3. Confirm the removal and click Remove.

Manage Roles

View detailed information about the existing roles and edit a custom role.

Procedure

  1. From App Volumes Manager, click CONFIGURATION > Admin Roles > Manage Roles. A list of built-in roles and any custom roles that you have created is displayed.
  2. Select the role and click Show to view information about the role. The Show button is visible only after you select a role.

A description of the role and the privileges associated with the role is displayed.

  • (Optional) If you select a custom role, click Edit to edit the privileges of the role.

Create a Custom Role

If you do not want to use the built-in roles with the pre-assigned privileges, you can create custom roles where you select specific privileges and assign them to the Active directory groups.

For example, you can create a role that gives privileges to perform all actions on Writable Volumes (such as create, enable, disable, rescan, and so on) and also view the online directory of users. You can edit the privileges later and the updated privileges is dynamically allocated to the members of the assigned group. That is, the members do not have to log out and log in to the system to get the new privileges.

Procedure

  1. From App Volumes Manager, click CONFIGURATION > Admin Roles > Manage Roles. A list of roles that have been created is displayed.
  2. Click Create Custom Role and provide the following information:
OptionDescription
NameName of the role.
DescriptionA detailed description of the custom role.
PrivilegesSelect the list of privileges you want to assign to the role from the following top-level categories. When a top-level privilege is selected, all the privileges under it are automatically assigned to a custom role. You can also choose specific privileges under a top-level privilege, and do not have to select all the privileges.

You can also navigate from each of the categories within a top-level privilege and choose specific individual privileges from the available subcategories.


For example, if you select Inventory as a top-level privilege, you can select any of the privileges within Inventory such as Applications, Application Assignments, and so on. If you have selected Applications, you can further select specific individual privileges such as View, Create, and so on.

  • Click Create.

Results

The new role is displayed on the Manage Roles page.

Remove a Custom Role

You can remove any custom roles you created.

Prerequisites

Ensure that the custom role is not assigned to any group.

Procedure

  1. From App Volumes Manager, click CONFIGURATION > Admin Roles > Manage Roles. A list of groups and associated roles is displayed.
  2. Select the custom role you want to remove and click Remove.

The Remove button is displayed only for a custom role. You cannot remove built-in roles, you can only see the privilege details pertaining to a built-in role.

  • Confirm the removal and click Remove.

Monitoring Active Directory Entities

The DIRECTORY tab lists Active Directory entities such as Users, Computers, Groups, and OUs (Organizational Units). An entity can be available for both App Volumes 4.0 Agent and App Volumes 2.x Agent. You can use the Entity page to view information such as packages attached to an entity, Applications and Appstacks assigned to the entity, and 2.x and 4.0 Writable Volumes created for the entity.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

If a User (entity) is assigned Applications or AppStacks and has both 4.0 Writable Volumes and

2.x and 4.0 Writable Volumes, then you can view the list of Application Assignments, AppStack Assignments, Writable Volumes (for 4.0) and Writable Volumes (2.x) on the Entity details page.

You can also view information about the entity such as entity name, entity login information, entity status, and so on.

The DIRECTORY tab also provides information about Active Directory entities that are online.

View Active Directory Entities

You can view a list of Active Directory entities and information about the entities such as Users who have logged into a managed computer, Computers to which Writable Volumes are attached, and Groups and OUs (Organizational Units) that have been assigned Applications and AppStacks. Entities can be Users, Computers, Groups, or OUs.

To understand the entity information available on the Managed <Entity> page, seeMonitoring Active Directory Entities.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent

2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

Procedure

  1. From App Volumes Manager, go to DIRECTORY > Entity.

Entity can be Users, Computers, Groups, or OUs.

  • On the Managed Entity page, view the list of entities.
  • Click the entity name to view entity details and list of Package attachments, Application and AppStack assignments, and Writable Volumes.
  • (Optional) On the Entity page, you can perform the following assign and unassign tasks for an entity:
    • To assign an Application for an entity, click Assign Application and follow the UI prompts.

Only Application Packages marked CURRENT can be assigned to an entity from the Entity

page.

  • To unassign an Application from an entity, on the Entity page, select the Application and click Unassign.

On the Entity page, all Applications assigned to the entity are displayed.

  • To assign an AppStack for an entity, click Assign AppStack and follow the UI prompts.

Only AppStacks in the Enabled status can be assigned to the entity from the Entity page. d       To unassign an AppStack from an entity, on the Entity page, select the AppStack and

click Unassign.

On the Entity page, all AppStacks assigned to the entity are displayed.

Sync Entities with Active Directory

You can view the updated list of entities by using the Sync functionality. The Sync button synchronizes all entities with the Active Directory. An entity can be a User, Computer, Group, or OUs (Organizational Units).

Procedure

  1. From App Volumes Manager, click DIRECTORY.
  2. Click the desired Entity tab.

Entity can be Users, Computers, Groups, or OUs.

  • Click Sync.
  • On the Confirm Sync window, click Sync.

Types of Hypervisor Connections and Machine Manager Configurations

The App Volumes operation mode is determined by configuring the Machine Manager. The Machine Manager determines the type of hypervisor connection.

Three types of hypervisor connections are available. You can configure the hypervisor to connect to one of the following hosts using the App Volumes Manager console. See Establish a Secure vCenter Server Connection to learn how to set up a secure connection to vCenter Server.

Note If you are configuring App Volumes Manager on VMware Cloud on AWS, and you select vCenter Server as the hypervisor, you must check the vCenter on VMware Cloud on AWS option. See Configuring App Volumes Manager for VMware Cloud on AWS for more information.

Table 1-1. Hypervisor Connection Types
Hypervisor Connection TypeDescription
VMware vCenter ServerPreferred connection type for mid-to-large environments. Enables the use of VMDK Direct Attached operation mode. When using this connection type, you can assign Applications, Packages, AppStacks, and Writable Volumes to the virtual machines running on multiple hypervisor hosts.
Single ESXi HostEnables the use of VMDK Direct Attached Operation Mode, but only for a single ESXi host. Use this connection type for small deployments and proofs of concepts. You can assign Applications, Packages, AppStacks, and Writable Volumes to the virtual machines running on a single hypervisor host.
VHD In-Guest ServicesDisables other hypervisor connections and enables the use of VHD In-Guest operation mode. Use this connection type to assign Applications, Packages, AppStacks, and Writable Volumes either to virtual machines running on an unsupported third-party hypervisor or to the physical computers. See Configure VHD In-Guest Storage.

Note You cannot change the operation mode after you configure the Machine Manager. However, if you have configured vCenter Server as the first Machine Manager, additional vCenter Server instances can be added and configured.

Reconfigure vCenter Server

If you regenerate new certificates for ESXi hosts and you have selected vCenter Server as your machine manager, with the Mount on Host option, you must reconfigure your vCenter Server.

See Regenerate Certificates for an ESXi Host section in the VMware vSphere ESXi and vCenter Server 5 Documentation.

vCenter Server Permissions

The following permissions are required if you are configuring a vCenter Server as the machine manager.

You also require these permissions if you choose the Mount on Host option when you are configuring the machine manager.

Note Datastore browsing must be enabled for the App Volumes Manager to enumerate volumes on the datastore. Check the enableHttpDatastoreAccess parameter under C:\ProgramData\VMware\VMware VirtualCenter\vpxd.cfg in the vCenter Server. If it is set to false, change this to true and restart the vCenter Server service.

  
 Permissions
DatastoreAllocate spaceBrowse datastoreLow level file operationsRemove fileUpdate virtual machine files
GlobalCancel task
HostLocal Operations -> Reconfigure virtual machine
SessionsView and stop sessions
TasksCreate task
Virtual machineConfigurationAdd existing diskAdd new diskAdd or remove deviceQuery unowned filesChange resourceRemove diskSettingsAdvancedInventoryCreate newMoveRegisterRemoveUnregisterProvisioningPromote disks

Configure and Register the Machine Manager

App Volumes operation mode is determined by configuring a machine manager. You cannot change the operation mode of App Volumes after you configure the machine manager.

Prerequisites

Ensure that the domain policies do not enforce password expiration for the service account on the machine manager to be configured.

Important If you are configuring a vCenter Server as the machine manager, ensure that you have the required vCenter Server permissions.

Procedure

  1. From the App Volumes Manager console, click CONFIGURATION > Machine Managers.
2              Click Register Machine Manager.
  • Select and configure the type of machine manager.
Connection TypeDescription
vCenter ServerEnter the host name, user name, and password details. If you select a vCenter Server instance as the first configured machine manager, you can add and configure additional servers.   Note If the App Volumes Manager connects to the vCenter Server via an IPv6 connection, then you must provide the DNS of the vSphere as the host name.
  
ESXi (Single Host)Enter the host name, user name, and password for the ESXi host.
VHD In-GuestDoes not require any credentials.

To view the permissions required by the service account, click Required vCenter Permissions.

  • Provide the following additional information:
OptionDescription
HostnameThe host name of the Machine Manager. For example, server.your-domain.local. For App Volumes on VMware Cloud on AWS, the host name must be of the form vcenter.sddc-xx.xxx-x- xx.vmc.vmware.com
UsernameThe user name to access the machine. For example,YOURDOMAIN \administrator.
PasswordThe password for the user name.
Mount ESXiWhen mounting, connect directly to ESXi servers.   Note This option is not applicable for App Volumes on VMware Cloud on AWS.
Mount LocalSelect this option if your VM’s datastore has local copies of volumes and you want to mount the local copies.
Mount QueueSelect this option to queue requests to the VM host. Decreases the number of active connections to vCenter Server and ESXi. This results in increased performance and decreases the burden on the vCenter Server.
Mount AsyncWait for the mount request to complete in the background. Increases App Volumes Manager server throughput. Requires the Mount Queue option to be selected.
Mount ThrottleLimits the number of actively processing mount requests. Decreases load on the vCenter Server or ESXi servers. Requires the Mount Queue option to be selected.
Maximum number of concurrent mount operations per queueThe maximum number of concurrent mount operations per queue. Use the servers entry in clock.yml to configure this field. Default value is 5.   Note Each vCenter Server and ESXi server uses a separate queue for every manager process.
  • Click Save.

The configured machine manager is displayed on the Machine Managers page.

What to do next

See Establish a Secure vCenter Server Connection to connect App Volumes Manager securely to a vCenter Server.

You can also create a custom role on the vCenter Server. See Create a Custom vCenter Server Role Using PowerCLI.

Configuring App Volumes Manager for VMware Cloud on AWS

You can configure App Volumes Manager on VMware Cloud on AWS. You can also transfer volumes using your vSphere Client to VMware Cloud on AWS.

Configure App Volumes Manager for VMware Cloud on AWS

After adding the vCenter SDDC machine manager, go to the Machine Managers tab, and click the “+” sign under the newly added machine manager to verify the details.

  • Select the default storage as a Workload datastore and not as a vSAN datastore. You can edit the default storage settings under CONFIGURATION > Storage. See Configuring Storage.

Transfer Writable Volumes from vSphere to VMware Cloud on AWS

You can transfer volumes using your vSphere client to the VMware Cloud on AWS environment in a two-step process:

For migration or Business Continuity Disaster Recover (BCDR) purposes, you can transfer your AppStacks or user Writable Volumes from On-Premises to the VMware Cloud on AWS environment using your vSphere client. This is a two-step process:

From the vSphere client:

  1. Create a VM with thin provisioning and attach the volume that you want to transfer to the VM.
  2. Select the VM and export it as an OVF template from File > Export to OVF Template. From the VMware Cloud on AWS web client:
1               Click Actions > Deploy OVF Template.
  • Follow on-screen instructions and when you have to select the storage format, select Thin provision.

Once the VM is created, browse the datastore where the OVF was exported and move the VMDK file with its metadata to the cloudvolumes directory.

Ensure that you change the template location in the metadata file to point to the new datastore.

Configuring Security Protocols and Cipher Suites

You can configure the security protocols and cipher suites for App Volumes Manager so that only the TLS connections that you have specified are accepted by App Volumes Manager.

You can also configure cipher suites to add ciphers and disable weak ciphers.

Configure TLS Connections in App Volumes Manager

You can modify the Nginx configuration file to ensure that App Volumes Manager accepts connections only from specified TLS versions.

App Volumes Manager uses SSL and TLS to communicate with servers and App Volumes agents. See Chapter 3 Using SSL Certificates with App Volumes Manager.

Prerequisites

  • You must have administrator privileges on the machine where App Volumes Manager is installed.
  • Locate the nginx.conf file and create a backup of the file. The default location for

nginx.conf is C:\Program Files (x86)\CloudVolumes\Manager\nginx\conf\.

Procedure

  1. Log in to the machine where App Volumes Manager is installed.
  2. Identify the ssl_protocols line in the nginx.conf file and retain only the TLS versions that you want App Volumes Manager to connect with.

For example, if you include TLSv1.1 and TLSv1.2 in the ssl_protocols line, App Volumes Manager will accept connections only from these TLS versions.

  • Restart the App Volumes Manager service.

Example: Configure TLS v1.1 and TLS v1.2 Protocols

In this example, App Volumes Manager will accept connections only from agents that use TLS v1.1 and TLS v1.2 protocols, as specified in the ssl_protocols entry in the Nginx configuration file.

TLS v1.0 Protocol Communication

TLS v1.0 protocol communications from App Volumes agents is disabled. All communication from the agent is done through TLS v1.1 and TLS v1.2 protocols.

App Volumes Manager can communicate with older agents only if the Allow TLS v1.0 protocol (Not recommended) box is selected. This box is deselected by default.

You can enable TLS v 1.0 support for App Volumes Manager during App Volumes Manager installation. Select the Allow TLS v1.0 protocol (Not recommended) box when you install App Volumes Manager. See the Install App Volumes Manager section in the App Volumes Installation Guide.

Configure Cipher Suites in App Volumes Manager

You can modify the Nginx configuration file to add ciphers or remove weak ciphers.

Prerequisites

  • You must have administrator privileges on the machine where App Volumes Manager is installed.
  • You must use the format that is defined in https://www.openssl.org/docs/man1.0.2/apps/ ciphers.html under the section CIPHER LIST FORMAT while adding the ciphers. The ciphers are specified as a list separated by colons, spaces, or commas.
  • Locate the nginx.conf file and create a back up of the file. nginx.conf is located at

C:\Program Files (x86)\CloudVolumes\Manager\nginx\conf\.

Procedure

  1. Log in to the machine where App Volumes Manager is installed.
  2. Identify the line starting with ssl_ciphers in the nginx.conf file.

Add the list of ciphers before the existing list of ciphers; the order of ciphers matters.

For example, add ECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH to the existing list of ciphers.

  • (Optional) To disable any ciphers, remove the ciphers from the list.
  • Restart the App Volumes Manager service.

Configuring Storage

You can configure storage for Packages, Writable Volumes, AppStacks (2.x), and Writable Volumes (2.x) by specifying the default storage and template paths.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

You can use the Upload Templates functionality to upload templates to the datastore. You can also configure VHD In-Guest Storage to use with App Volumes.

Support for Shared Datastores

App Volumes Manager is now aware of the shared physical datastores (storage) across multiple vCenter Servers that are used to connect to the datastore.

What Is a Shared Datastore

A shared datastore or location is a physical datastore that is connected to different vCenter Servers, and visible across the vCenter Servers. The datastore is identified based on the UUID of the filesystem.

A non-shared datastore, by contrast is not visible across multiple vCenter Servers. This storage might be a local storage or a LUN accessible to only one vCenter Server.

You can view a list of all the shared physical datastores from App Volumes Manager.

Identifying a Shared Datastore

You can identify a shared datastore by a unique identifier such as UUID. From App Volumes Manager, go to INFRASTRUCTURE > Storages and click the “+” sign next to a storage LUN. Some of the details displayed are as follows: Number of AppStacks, Number of Packages, Number of Writables (aggregate of Writable Volumes and Writable Volumes (2.x)), and UUID.

Writable Volumes and Shared Datastores

When you import Writable Volumes, any Writable Volumes that are present in a shared datastore are considered to be the same Writable Volumes but from different locations. For example, when a Writable Volume is available from multiple vCenter Servers, the volume is not considered as a duplicate.

When a Writable Volume is created in a datastore, it gets created in all shared locations.

When a user logs in to a desktop, any Writable Volume that is assigned to the user can be attached from a shared datastore provided the location is reachable.

You must have a shared datastore between the source and destination vCenter Server to move and back up volumes across different vCenter Servers and if the source volumes are located in a non-shared datastore.

To back up a Writable Volume across different vCenter Servers, with the volume located in a non-shared datastore, you must first move the volume to a shared datastore, and then back up the volume to the destination datastore.

Supported Datastores

The following datastores types are supported:

  • VMFS (version 3, 5, and 6)
  • NFS (version 3 and 4.1)

Note When using an NFS datastore, if the same version of the datastore is not used to mount in all the vCenter Servers, then those storage locations are not considered as shared locations.

Configure Storage For Packages

You can configure storage for Packages by selecting the default storage locations and paths.

You can add available storage only when App Volumes Manager is configured in the VHD In- Guest mode. Otherwise, the list of storage locations and datastores is populated from vCenter Server. See Configure VHD In-Guest Storage.

Note Ensure that the paths for the default locations and the templates are separate from each other.

Prerequisites

Use a storage location that is accessible to all virtual machine host servers. When using VMDK Direct Attach Operation Mode, the App Volumes Manager requires local or shared storage to be configured on the hypervisor.

Procedure

  1. From the App Volumes Manager, click CONFIGURATION > Storage.

If you have configured the storage options, click Edit to change the configuration.

  • Enter the default storage information for Packages:
OptionDescription
Default Storage LocationStorage Location in VC
Default Storage PathFor example, /appvolumes/packages
Templates PathFor example,/appvolumes/packages_templates
  • Confirm your storage settings and click Save.
  • On the Confirm Storage Settings window, choose when you want to import the volumes:
    • Import volumes in the background – App Volumes Manager dispatches a background job to import the volume and the display goes back to the manager console immediately.
    • Import volumes immediately – App Volumes Manager waits for the import to be completed and the console is not responsive until either the process is complete or 10 minutes have elapsed.

Configure Storage For AppStacks (2.x)

You can configure storage for AppStacks (2.x) by selecting the default storage locations and paths.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

Volumes are attached only for virtual machines on the host. You can add available storage only when App Volumes Manager is configured in the VHD In-Guest mode. Otherwise, the list of storage locations and datastores is populated from vCenter Server. See Configure VHD In-Guest Storage.

Note Ensure that the paths for the default locations and the templates are separate from each other.

Prerequisites

Use a storage location that is accessible to all virtual machine host servers. When using VMDK Direct Attach Operation Mode, the App Volumes Manager requires local or shared storage to be configured on the hypervisor.

Procedure

  1. From the App Volumes Manager, click CONFIGURATION > Storage.

If you have configured the storage options, click Edit to change the configuration.

  • Enter the default storage information for AppStacks (2.x):
OptionDescription
Default Storage LocationStorage Location in VC
Default Storage PathFor example, /cloudvolums/apps
Templates PathFor example,/cloudvolumes/apps_templates
  • Confirm your storage settings and click Save.
  • On the Confirm Storage Settings window, choose when you want to import the volumes:
    • Import volumes in the background – App Volumes Manager dispatches a background job to import the volume and the display goes back to the manager console immediately.
    • Import volumes immediately – App Volumes Manager waits for the import to be completed and the console is not responsive until either the process is complete or 10 minutes have elapsed.

Configure Storage for Writable Volumes

Configure storage for Writable Volumes and Writable Volumes (2.x) by selecting the default storage locations and paths.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

If local host storage is used, volumes are attached only for virtual machines on that host.

Prerequisites

Use a storage location that is accessible to all virtual machine host servers. When using VMDK Direct Attach Operation Mode, the App Volumes Manager requires local or shared storage to be configured on the hypervisor.

Note You cannot use the same storage path for Writable Volumes and Writable Volumes (2.x).

Procedure

  1. From the App Volumes Manager, click CONFIGURATION > Storage.

If you have configured the storage options, click Edit to change the configuration.

  • Enter the following information:
OptionDescription
Writable VolumesDefault Storage Location Storage Location in VC Default Storage Path For example, /appvolumes/writables Templates Path For example,/appvolumes/writables_templates Default Backup Path For example,/appvolumes/writables_backup
Writable Volumes (2.x)Default Storage Location Storage Location in VC Default Storage Path For example, /cloudvolumes/writable Templates Path For example,/cloudvolumes/writable_templates Default Backup Path For example,/cloudvolumes/writable_backup
  • Confirm your storage settings and click Save.
  • On the Confirm Storage Settings window, choose when you want to import the volumes:
    • Import volumes in the background – App Volumes Manager dispatches a background job to import the volume and the display goes back to the manager console immediately.
    • Import volumes immediately – App Volumes Manager waits for the import to be completed and the console is not responsive until either the process is complete or 10 minutes have elapsed.

Upload Templates

You must upload the templates to the datastore in certain scenarios. The scenarios can be as follows: you have upgraded from the previous version and want to use the latest templates, you have changed the destination of the template path, accidentally deleted, or moved a template from the datastore.

To upload the templates, use the Upload Templates page. On this page, you can view templates for Packages, Writable Volumes, AppStacks (2.x), and Writable Volumes (2.x).

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

For information about types of Writable Volume templates, see Types of Writable Volume Templates.

Prerequisites

  • Ensure that you have the details and login credentials of the ESX host to which you want to upload the volumes.
  • Ensure that you are aware of the considerations regarding templates.

For understanding different types of templates used in App Volumes, see Understanding Templates used in App Volumes.

Procedure

  1. From the App Volumes Manager, click CONFIGURATION > Storage.
  2. Click Upload Templates.
  3. On the Upload Templates page, provide the following information:
OptionDescription
StorageSelect a storage location from the drop-down menu.
HostSelect a host from the drop-down menu.
ESX UsernameUser name for the ESX host.
ESX PasswordPassword for the user to log in to the ESX host.
  • Select a source template for the volumes to be uploaded.

The Type field indicates the type of volume. This could be a Package, Writable Volume, AppStack, or Writable Volume (2.x)

The Exists field indicates whether the template is present at the destination path (Templates Path) and the value of this field is Yes or No accordingly.

  • Click Upload.
  • On the Confirm Upload Templates window, click Upload.

Understanding Templates used in App Volumes

You must specify a template when you create a volume or when you upload volumes packaged with your instance of App Volumes Manager to the selected datastore.

Note AppStacks and Writable Volumes (2.x) can be created only by using App Volumes Agent


2.x and uploading the appropriate templates. Any information related to these volumes can be viewed only when the VOLUMES (2.X) tab is visible in the App Volumes Manager UI. If you have installed the latest version of App Volumes Manager and want to explore App Volumes 2.x, see Chapter 10 Perform App Volumes 2.x Management Tasks.

Some of the considerations regarding templates are as follows:

  • packages_templates and writables_templates are used while creating Application Packages and Writable Volumes for a user accessing a virtual machine installed with App Volumes 4.0 Agent.
  • apps_templates and writables_templates (for 2.x template type) are used while creating AppStacks (2.x) and Writable Volumes for a user accessing a virtual machine installed with App Volumes 2.x Agent.
  • Templates for Writable Volumes and Writable Volumes (2.x) are not compatible with each other.
  • Template path for Writable Volumes and Writable Volumes (2.x) should be different.

Types of Writable Volume Templates

There are three types of Writable Volume templates available in App Volumes: Profile-only, UIA only, and UIA+profile.

The following helps you understand the types of Writable Volume templates and their usage:

  • Profile-only – Captures only the profile information of the users and does not include any configuration information related to user-installed applications in the Writable Volumes. The profile is delivered early in the boot process and considered only a local profile delivery. Additional profile tools like roaming profiles and VMware Dynamic Environment Manager still apply and work as expected. Use this template if a profile solution is not in place.
  • UIA only – Captures all user-installed applications but does not capture any data that is written to the user profile. You can use this template with a third-party profile solution or VMware Dynamic Environment Manager.
  • UIA+profile – Includes all user-installed applications and user profile data. The user profile data is only a local profile and is not a roaming profile or other managed user profiles.

Configure VHD In-Guest Storage

To use App Volumes with VHD In-Guest Operation mode, the machines where the App Volumes Manager and agents are installed require special permissions on the CIFS file share.

Procedure

  1. On a file server, create a new empty folder.
  2. Copy the contents of the Hypervisor\In-Guest VHD folder from the App Volumes installation media to the new folder.
  3. Share the folder and grant full access permissions on the file share to everyone.
  4. Configure NTFS permissions as described below.

An Active Directory domain group might be used to manage permissions for the following roles:

  • Managers: App Volumes Manager
    • Agents: Machines that receive App Volumes and writable volumes assignments
    • Capture Agents: Machines that are used for provisioning new App Volumes agents
Table 1-2. NTFS folder permissions required for each role
FolderManagersAgentsCapture Agents
appsFullReadWrite
apps_templatesReadNoneNone
writableFullWrite or None   Note Write permissions are required by Agents when Dynamic Permissions are not enabled.None
    
writable_templatesReadNoneNone

Configure Asynchronous Mounting on App Volumes Manager and Agent

You can configure asynchronous mounting on App Volumes Manager and agent to enable App Volumes Manager to handle a large number of login requests within a short time and improve scalability.

When you attach Packages, Writable Volumes, or AppStacks, the App Volumes Manager has to keep a number of HTTP connections open until the volumes are all mounted. When asynchronous mounting is enabled, App Volumes Manager does not have to wait until all the volumes are mounted and can handle other requests concurrently.

Important

  • When you perform a fresh installation of App Volumes, by default, asynchronous mounting is enabled on both the App Volumes Manager and agent .

  • If this setting is disabled for any reason, such as, when you upgrade App Volumes, you must change the settings on both the App Volumes Manager and the agent to enable it.

Enable Asynchronous Mounting On The App Volumes Agent

Enable asynchronous mounting on the App Volumes agent.

The asynchronous mount setting is enabled by default. If it has been disabled for any reason, follow the instructions below to enable this setting.

You can also change the default time (30 seconds) the agent takes to send the mount status requests to the manager.

Procedure

  1. Log in as administrator where the App Volumes agent is installed and change the registry key settings.
Registry SettingValue
PathHKLM\SYSTEM\CurrentControlSet\Services\svservice\Parameters
KeyAsyncmount
TypeDWORD
Value1
  • (Optional) Change the default time (30 seconds) the agent takes to send the mount status requests to the manager.
OptionDescription
PathHKLM\SYSTEM\CurrentControlSet\Services\svservice\Parameters
KeyVolMountConfirmationReqFrequency
TypeDWORD
Valuenew-time-in-seconds

Enable Asynchronous Mounting On App Volumes Manager

Enable asynchronous mounting on App Volumes Manager.

The asynchronous mount setting is enabled by default. If it has been disabled for any reason, follow the instructions below to enable this setting on the App Volumes Manager.

Procedure

  1. Log in as administrator to App Volumes Manager.
  • Set the environment variable AVM_ALLOW_ASYNC_MOUNT to 1.

App Volumes Manager Configuration Settings Page

You can configure some of the settings directly from the Settings page, and others through the environment variables.

Configuration Settings

Go toCONFIGURATION > Settings to view and edit the settings.

TypeValueDescription
General SettingsUI Session TimeoutThe number of seconds App Volumes Manager remains active after the user logs in. The default value is 30 minutes. Set via the system environment variable SESSION_TIMEOUT.
General SettingsCertificate Authority FilePath of the certificate file used by machine managers. Set via the system environment variable SSL_CERT_FILE.
Volume MountingAPI MountingEnable the user to log in even if a Writable Volume or an AppStack cannot be attached to the user at the time of login. Set via the system environment variable AVM_ALLOW_API_MOUNT (or CV_ALLOW_API_MOUNT).
Writable VolumesDelete ProtectionProtect volumes from getting deleted directly from storage. Set via the system environment variable AVM_NO_PROTECT (or CV_NO_PROTECT).
Writable VolumesForce Reboot on ErrorIf a Writable Volume is assigned to a user, and the volume does not get attached to the user, the user has the option to reboot the machine. Set via the system environment variable AVM_WRITABLE_REBOOT.   Note  The AVM_WRITABLE_REBOOT does not apply to Writable Volumes conflicts. Writable Volumes conflicts are handled by the the Block user login setting. See Create a Writable Volume (2.x) for information about this setting.
Writable Volume BackupsRegular backupsToggle the slider to enable or disable regular backups for Writable Volumes. If enabled, Writable Volumes are backed up on a regular basis based on the recurrent interval. For example, if the recurrent interval is set to 7 days, a Writable Volume will be backed up if 7 days have elapsed since the last back up. Back up is only performed for Writable Volumes that have been used at least once since the last backup.
Active DirectoryAllow or DisallowThe App Volumes Manager expects Computer and User accounts to be members of a registered Active Directory domain. Computer startups and user logins using local accounts are normally ignored. If non-domain entities are allowed, the Manager will create a record for local entities when they are first seen. That entity can then have AppStacks assigned to it from the Directory tab.
Writable Volume BackupsStorage LocationThe location where the volumes are backed up. For example, [xxx]AV-LUN.
Writable Volume BackupsStorage PathThe folder name and path where the volumes are backed up. For example, cloudvolumes/ writable_volumes_backup
Advanced SettingsDisable Agent Session CookieToggle the slider to enable or disable Agent Session Cookie. App Volumes uses a session cookie to optimize the communication between the App Volumes Manager and App Volumes Agent. If you have Agent session issues, you can use this setting to disable the session cookies.
Advanced SettingsDisable Volume CacheToggle the slider to enable or disable volume cache. App Volumes caches AppStack or application objects to improve performance. However, if you experience increased memory usage, consider disabling volume caching.
Advanced SettingsDisable Token AD queryToggle the slider to enable or disable token AD query. App Volumes queries for Active Directory group membership using cached object SIDs. Previous versions of App Volumes performed group membership queries against Active Directory domains directly and recursively. Disable token AD query to revert to the previous implementation.
Advanced SettingsEnable Volumes (2.x)Toggle the slider to enable or disable the VOLUMES (2.X) tab. VOLUMES (2.X) tab is for working with AppStacks and Writable Volumes along with App Volumes Agent 2.x. For upgraded deployments, this setting can be disabled after the AppStacks and Writable Volumes are completely migrated.

If you have newly installed App Volumes Manager, for more information about this setting, see Chapter 10 Perform App Volumes 2.x Management Tasks.


If you have upgraded to the latest version of App Volumes Manager, for more information about this setting, see Configuring visibility and management of App Volumes Manager 2.x UI.

Sandeep Kumar & Shaswati Mukherjee

Leave a Reply

Your email address will not be published. Required fields are marked *