# Overview This technical brief summarizes a production-ready integration pattern for VMware Cloud Foundation (VCF) and vSphere Kubernetes Service (VKS). The goal is to enable enterprise DevOps teams to keep existing public-cloud pipelines and toolchains while moving workloads on-premises, and to remove common security and operational friction that appears when running CI/CD against internal clusters.
# The operational problems addressed Platform and security teams commonly face three issues when bringing cloud-native workloads on-premises:
- Fragmented tooling and developer friction when pipelines must be reworked for private cloud.
- Delivery security risks caused by static kubeconfig files or long-lived service account tokens stored in CI/CD variables.
- Gaps in observability and secret governance when automated supply-chain scanning and runtime secret injection are not in place.
# Architectural approach
- vSphere Supervisor exposes declarative Kubernetes CRDs at the vSphere control plane. Developers can submit standard YAML manifests and the Supervisor coordinates resource provisioning in vCenter without direct vCenter UI interaction.
- Controllers such as the VKS Controller and VM Operator translate Cluster API specifications into vCenter calls to provision control plane and worker VMs. CSI controllers and network operators integrate storage and networking (vSAN, NSX, Avi) with guest clusters.
# Pipeline and security innovations Dual-cluster topology and ephemeral build pods
- Harness CI runs builds on a dedicated VKS Build Cluster where build steps run as short-lived Kubernetes pods that auto-terminate. This prevents workspace pollution and reduces persistent attack surface.
Supply-chain scanning and observability
- Artifactory is used for image management and artifact storage. Wiz provides supply-chain scanning for vulnerabilities and compliance during the pipeline. Dynatrace supplies closed-loop APM and runtime observability for deployed workloads.
- Store is integrated into the flow to enable runtime secret injection and centralized secret governance rather than storing sensitive data in pipeline variables.
# Practical outcomes for platform teams
- Reuse of existing public-cloud delivery pipelines with minimal changes because VCF maps public cloud native constructs to on-prem VKS.
- Smaller Blast Radius: ephemeral build pods and short-lived credentials reduce persistent access points into clusters.
- Automated, end-to-end software supply chain that includes artifact storage, scanning, secure delivery, secret injection, and runtime observability.
# Where to find the implementation assets Session resources and a reference implementation are available, including a VMware Explore session recording and a GitHub repository with the vks-consumption-models that demonstrate the ecosystem integration.
# Final note The blueprint focuses on operational practicality: integrate widely used DevOps tools with VKS using declarative infrastructure, ephemeral build infrastructure, OIDC-based CI authentication, centralized secret storage, automated scanning, and APM to move enterprise workloads on-premises without rebuilding developer workflows.