Vmware iconVmwareSep 30, 2026 ~6 min source read

A production-ready blueprint for CI/CD on vSphere Kubernetes Service using Harness, Wiz, Artifactory, Dynatrace and the VCF Secret Store

How VMware Cloud Foundation’s vSphere Kubernetes Service can be integrated with common DevOps tools to provide ephemeral build infrastructure, secure authentication, automated supply-chain scanning, and secret governance without reworking existing pipelines.

Streamlining CI/CD on VMware vSphere Kubernetes Service with Harness, Wiz, Artifactory, Dynatrace and the VCF Secret Store

Share this story

Send the public story page.

Useful takeaways from this story.

Use a dual-cluster topology: one VKS build cluster for ephemeral CI pods and a separate runtime cluster for applications to reduce attack surface and workspace pollution.

Replace static kubeconfig or long-lived tokens with short-lived OIDC identities for CI delegates to improve cluster credential security.

Combine toolchain components—GitHub, Harness, Artifactory, Wiz, Dynatrace, and the VCF Secret Store—to automate image storage, supply-chain scanning, secret injection, and application performance monitoring.

# Overview This technical brief summarizes a production-ready integration pattern for VMware Cloud Foundation (VCF) and vSphere Kubernetes Service (VKS). The goal is to enable enterprise DevOps teams to keep existing public-cloud pipelines and toolchains while moving workloads on-premises, and to remove common security and operational friction that appears when running CI/CD against internal clusters.

# The operational problems addressed Platform and security teams commonly face three issues when bringing cloud-native workloads on-premises:

  • Fragmented tooling and developer friction when pipelines must be reworked for private cloud.
  • Delivery security risks caused by static kubeconfig files or long-lived service account tokens stored in CI/CD variables.
  • Gaps in observability and secret governance when automated supply-chain scanning and runtime secret injection are not in place.

# Architectural approach

  • vSphere Supervisor exposes declarative Kubernetes CRDs at the vSphere control plane. Developers can submit standard YAML manifests and the Supervisor coordinates resource provisioning in vCenter without direct vCenter UI interaction.
  • Controllers such as the VKS Controller and VM Operator translate Cluster API specifications into vCenter calls to provision control plane and worker VMs. CSI controllers and network operators integrate storage and networking (vSAN, NSX, Avi) with guest clusters.

# Pipeline and security innovations Dual-cluster topology and ephemeral build pods

  • Harness CI runs builds on a dedicated VKS Build Cluster where build steps run as short-lived Kubernetes pods that auto-terminate. This prevents workspace pollution and reduces persistent attack surface.

Supply-chain scanning and observability

  • Artifactory is used for image management and artifact storage. Wiz provides supply-chain scanning for vulnerabilities and compliance during the pipeline. Dynatrace supplies closed-loop APM and runtime observability for deployed workloads.
  • Store is integrated into the flow to enable runtime secret injection and centralized secret governance rather than storing sensitive data in pipeline variables.

# Practical outcomes for platform teams

  • Reuse of existing public-cloud delivery pipelines with minimal changes because VCF maps public cloud native constructs to on-prem VKS.
  • Smaller Blast Radius: ephemeral build pods and short-lived credentials reduce persistent access points into clusters.
  • Automated, end-to-end software supply chain that includes artifact storage, scanning, secure delivery, secret injection, and runtime observability.

# Where to find the implementation assets Session resources and a reference implementation are available, including a VMware Explore session recording and a GitHub repository with the vks-consumption-models that demonstrate the ecosystem integration.

# Final note The blueprint focuses on operational practicality: integrate widely used DevOps tools with VKS using declarative infrastructure, ephemeral build infrastructure, OIDC-based CI authentication, centralized secret storage, automated scanning, and APM to move enterprise workloads on-premises without rebuilding developer workflows.

More context around this story.

Managing VKS Clusters at Scale: Improvements in VCF 9.1
Vmware iconVmwareSep 30, 2026

Managing VKS Clusters at Scale: Improvements in VCF 9.1

<div><img width="300" height="185" src="https://blogs.vmware.com/wp-content/uploads/2026/09/image_8d918d.png" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/09/image_8d918d.png 10

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app