7.3 Host Profiles & Cluster Quickstart

Key Takeaways

  • Host Profiles capture an ESXi host's entire configuration blueprint—including networking, storage multipathing, NTP, syslog, security, and advanced VMkernel parameters—into an exportable XML template.

  • Host Profiles distinguish between cluster-wide uniform configurations (such as NTP servers and syslog targets) and host-specific parameters (such as IP addresses and iSCSI IQNs), which are managed through Answer Files.

  • Remediating an ESXi host against an attached Host Profile enforces compliance by applying configuration changes; modifications affecting virtual switches, storage paths, or security daemons require host Maintenance Mode.

  • Host Profiles integrate with VMware Auto Deploy to facilitate stateless ESXi provisioning, automatically applying network and identity configurations upon PXE boot.

  • Cluster Quickstart provides a streamlined 3-step workflow (Cluster basics, Add hosts, Configure cluster) that automates HA, DRS, vSAN, Distributed Switch uplinks, and VMkernel interfaces across new clusters.

Last updated: September 2026

7.3 Host Profiles & Cluster Quickstart

Maintaining consistent configuration across dozens or hundreds of ESXi hosts is paramount for enterprise stability, security, and compliance. Even minor configuration discrepancies—such as an inconsistent NTP server address, a mismatched syslog target, an unconfigured firewall rule, or a divergent storage multipathing policy—can lead to split-brain conditions, failed vMotion migrations, or audit failures.

To solve this challenge, vSphere provides two complementary management frameworks: Host Profiles, an enterprise policy framework that automates declarative configuration compliance across ESXi hosts, and Cluster Quickstart, an intelligent guided provisioning wizard that accelerates cluster creation and standardization.


Host Profiles Architecture & Operational Lifecycle

A Host Profile is an encapsulated, declarative configuration blueprint created from a designated Golden Reference Host. The profile encapsulates hypervisor configuration policies into a standardized XML structure managed natively by vCenter Server (requiring vSphere Enterprise Plus licensing).

+-------------------------------------------------------------------------+
|                       Host Profiles Sub-Profile Tree                    |
|                                                                         |
|  [ Networking ]        [ Storage ]          [ Security ]    [ System ]  |
|  - vDS / VSS Switches  - PSP / SATP Rules   - Firewall      - NTP       |
|  - Port Groups         - iSCSI Initiators   - Root Password - Syslog    |
|  - VMkernel Interfaces - Pluggable Storage  - Lockdown Mode - Advanced  |
+-------------------------------------------------------------------------+

Sub-Profile Hierarchy

A Host Profile is structured into modular sub-profiles representing hypervisor subsystems:

  • Networking Sub-Profile: Governs vSphere Standard Switches (VSS), vSphere Distributed Switch (vDS) proxy uplinks, port groups, VLAN IDs, MTU jumbo frames, teaming and failover policies, and VMkernel adapters (vmk0, vmk1).
  • Storage Sub-Profile: Standardizes Pluggable Storage Architecture (PSA) multipathing configurations, Native Multipathing Plugin (NMP) Path Selection Policies (PSP) like Round Robin (VMW_PSP_RR), Storage Array Type Policies (SATP), and software iSCSI initiator parameters.
  • Security & Service Configuration: Controls ESXi firewall rule sets, SSH daemon startup behavior, the ESXi Direct Console User Interface (DCUI) accessibility, root account password complexity, and Strict/Normal Lockdown Mode policies.
  • System & Advanced Settings: Enforces NTP server synchronizations, system log locations (Syslog.global.logHost), scratch partition paths, core dump partition mappings, and power management CPU governors.

The Complete Host Profile Lifecycle Workflow

  1. Configure Reference Host: An administrator manually configures a single ESXi host to absolute architectural perfection, verifying network uplinks, NTP servers, firewall rules, and advanced parameters.
  2. Extract Host Profile: In the vSphere Client, right-click the reference host, navigate to Host Profiles, and select Extract Host Profile. vCenter reads the host's configuration and compiles the XML blueprint.
  3. Edit Profile Policies: The administrator reviews the profile policies, disabling sub-profiles that should not be enforced (e.g., local storage device mappings) and configuring user-input prompts for host-unique parameters.
  4. Attach Profile: The profile is attached to target entities—individual ESXi hosts, entire clusters, or inventory folders.
  5. Check Compliance: vCenter executes a compliance scan comparing each host's running state against the attached profile. Hosts are classified as:
    • Compliant: The host matches all policies in the profile.
    • Non-Compliant: Configuration drift has occurred. vCenter displays a detailed hierarchical comparison tree highlighting exact parameter variances (e.g., NTP server 192.168.1.10 missing).
  6. Edit Host Customizations (Answer Files): When a profile contains policies requiring host-unique parameters (such as static IP addresses), the administrator populates the host's Answer File.
  7. Remediate: The administrator triggers remediation. vCenter pushes configuration instructions to the host's hostd daemon, aligning the physical configuration with the profile.
Loading diagram...
Host Profiles Compliance & Answer File Remediation Workflow

Uniform Policies vs. Host Customizations (Answer Files)

An architectural strength of Host Profiles is its ability to differentiate between cluster-wide uniform configurations and host-specific parameters.

Uniform configurations apply identically across every host in the cluster. If you specify NTP servers time.corp.local and time2.corp.local, that configuration applies uniformly. However, networking and identity configurations cannot be uniform: two ESXi hosts in the same cluster cannot share the same management IP address, FQDN, or iSCSI Qualified Name (IQN) without causing immediate IP conflicts and storage corruption.

To accommodate host-specific variables, Host Profiles utilize Host Customizations, stored internally as Answer Files.

How Answer Files Function

When a Host Profile policy is configured with the expression "User Specified" (or "Prompt user for value"), vCenter flags that parameter as requiring a host customization:

  • When the profile is attached to a host, vCenter checks whether an Answer File exists with valid responses for all user-specified policies.
  • If any user-specified values are missing, the host displays a status of Host Customizations Incomplete / Answer File Invalid.
  • The administrator right-clicks the host and selects Host Profiles -> Edit Host Customizations. A form displays prompting for the host's specific parameters.
  • Once entered, the Answer File transitions to a Valid status, enabling remediation to proceed.
Configuration CategoryScopeHandled ByExample Parameters
Uniform PolicyCluster-WideHost Profile Base TemplateNTP servers, Syslog target IP, DNS domain, vDS uplink port groups, firewall rules, root password policy
Host CustomizationHost-UniqueAnswer File (Host-specific XML)Management IP address, vMotion IP, vSAN IP, Subnet masks, Hostname, iSCSI Initiator IQN, MAC mappings

Remediation Impact & Maintenance Mode Requirements

Applying host profile configurations can alter fundamental system state. The administrative impact depends on which sub-profiles require adjustment:

  • Disruptive Remediation (Requires Maintenance Mode): Modifications affecting physical network uplinks, vSphere Distributed Switch migrations, VMkernel interface assignments, storage multipathing SATP/PSP claims, or core service daemons require the host to enter Maintenance Mode. If an administrator attempts to remediate a non-compliant host without placing it in maintenance mode, vCenter will fail the remediation task if any queued change requires hypervisor isolation.
  • Dynamic / Non-Disruptive Remediation: Minor updates—such as synchronizing an NTP server list, adjusting an advanced kernel parameter (Syslog.global.logHost), or opening a firewall port—can often be applied dynamically without taking the host offline.

VMware Auto Deploy Integration

Host Profiles serve as the foundational configuration engine for VMware Auto Deploy. In a stateless Auto Deploy topology:

  1. Bare-metal physical servers boot over the network using PXE and TFTP/HTTP.
  2. Auto Deploy serves a minimal ESXi Image Profile directly into the server's RAM.
  3. As the VMkernel initializes, Auto Deploy queries vCenter, matches an Auto Deploy Rule, attaches the designated Host Profile, and injects the host's specific Answer File.
  4. The host configures its networking, storage paths, and management agents entirely in memory without ever writing to local boot media, achieving zero-touch stateless provisioning.

Cluster Quickstart: Streamlined Cluster Provisioning

Prior to the introduction of Cluster Quickstart, provisioning a production-grade vSphere cluster required navigating across dozens of disparate vCenter menus: creating the cluster object, enabling DRS, enabling HA, manually creating a vSphere Distributed Switch, adding hosts individually, accepting SSL thumbprints, configuring VMkernel ports, claiming disks for vSAN, and standardizing NTP settings. This fragmented workflow frequently resulted in human configuration errors and non-standardized clusters.

Cluster Quickstart provides an integrated, guided 3-step workflow embedded directly in the vSphere Client that standardizes cluster creation from inception.

+-------------------------------------------------------------------------+
|                       Cluster Quickstart 3-Step Flow                    |
|                                                                         |
|   [ 1. Cluster Basics ]  -->  [ 2. Add Hosts ]  -->  [ 3. Configure ]   |
|   - Name Cluster              - Enter FQDNs / IPs    - Distributed Switch|
|   - Enable DRS                - Root Credentials     - VMkernel Adapters |
|   - Enable vSphere HA         - Verify Thumbprints   - vSAN Disk Groups  |
|   - Enable VMware vSAN        - Auto-Health Checks   - NTP & Host Config |
+-------------------------------------------------------------------------+

The 3-Step Quickstart Workflow

Step 1: Cluster Basics

The administrator defines the fundamental cluster identity and activates core platform services via checkboxes:

  • Cluster Name & Data Center Location
  • vSphere DRS (Distributed Resource Scheduler): Toggle DRS on or off, selecting the default automation level (Manual, Partially Automated, Fully Automated).
  • vSphere HA (High Availability): Toggle HA on, enabling host monitoring and failover admission control.
  • VMware vSAN: Toggle vSAN on (standard single-site cluster, two-node cluster, or stretched cluster).

Step 2: Add Hosts

Administrators batch-add physical ESXi hosts into the cluster inventory:

  • Enter IP addresses or fully qualified domain names (FQDNs) and root credentials for multiple hosts simultaneously.
  • Inspect and accept SSL certificate thumbprints in a consolidated modal.
  • Quickstart performs pre-validation health checks, verifying that the hosts are reachable, share compatible hypervisor build levels, and possess compatible CPU architectures.

Step 3: Configure Cluster

This is the orchestration engine of Quickstart. Clicking Configure launches a consolidated wizard that establishes the entire networking and storage infrastructure across all cluster hosts in parallel:

  • Distributed Networking (vDS): Prompts the administrator to configure a single vSphere Distributed Switch, select physical NIC uplinks (e.g., assigning vmnic0 and vmnic1 across all hosts), and configure port groups.
  • VMkernel Traffic Allocation: Configures dedicated VMkernel network adapters on the vDS for Management, vMotion, and vSAN traffic, providing automated IP address assignment via DHCP or sequential static IP pools.
  • vSAN Storage Configuration: Automatically scans attached physical storage across all hosts, presenting a visual disk claiming interface to designate NVMe/SSD cache tier disks and capacity tier disks.
  • Host Infrastructure Settings: Enforces uniform NTP server configurations and places hosts into maintenance mode sequentially to apply network switch migrations without dropping management connections.

Once configured, the Quickstart card displays a green checkmark indicating the cluster is fully configured and compliant.

Expanding the Cluster with Quickstart (4.18.3)

To grow the cluster later, use the Add hosts card again. Quickstart validates the new hosts and then prompts you to run Configure cluster for them. That step applies the same distributed switch uplink mapping, VMkernel adapters, and vSAN disk claiming, so the new hosts match the existing ones. If you skip the Quickstart configuration (or dismiss the workflow), you must configure new hosts manually.

Exam Trap: Remember that while Cluster Quickstart automates initial provisioning, it enforces a single consistent distributed switch and VMkernel configuration across all hosts. If your design requires complex, multi-switch asymmetric network topologies (e.g., separate distributed switches for IP storage vs. VM traffic using different physical NIC speeds), you must either customize the vDS after Quickstart completes or configure distributed networking manually.

Test Your Knowledge

A virtualization engineer extracts a Host Profile from a golden reference ESXi host and attaches it to a newly provisioned 8-host cluster. Before remediation can occur, the engineer notices that several hosts display an alert indicating that host customizations are missing. Which host-specific parameters are stored in an Answer File to satisfy this requirement?

A

NTP server IP addresses and syslog logging facility parameters

B

Host-specific management IP addresses, hostnames, and iSCSI initiator IQNs

C

The cluster-wide vSphere Distributed Switch uplink teaming policies

D

The ESXi firewall default incoming and outgoing connection rules

Test Your Knowledge

An administrator attaches a Host Profile to a non-compliant ESXi host to remediate divergent network switch uplinks and VMkernel adapter port mappings. Why does vCenter Server require the host to enter Maintenance Mode before applying this remediation task?

A

Host Profiles can only read configuration data while virtual machines are running, but require power-off to generate XML

B

ESXi hosts automatically reboot into the Direct Console User Interface (DCUI) whenever any Host Profile policy is evaluated

C

Remediation tasks that modify physical network uplinks, switch configurations, or storage paths disrupt hypervisor connectivity and mandate VM evacuation

D

VMware Auto Deploy must re-download the base ESXi image profile across the management network before every remediation

Test Your Knowledge

When provisioning a brand-new vSphere 8.0 cluster using the Cluster Quickstart wizard, which sequence of operations correctly reflects the three guided configuration steps?

A

Step 1: Cluster basics (DRS, HA, vSAN) -> Step 2: Add hosts (credentials, thumbprints) -> Step 3: Configure cluster (vDS, VMkernel networking, vSAN storage, NTP)

B

Step 1: Add hosts -> Step 2: Configure storage and vSAN -> Step 3: Enable DRS and HA licensing

C

Step 1: Create Distributed Switch -> Step 2: Configure Host Profiles -> Step 3: Add hosts to cluster

D

Step 1: Install ESXi base images -> Step 2: Extract reference host profile -> Step 3: Enable vSphere with Tanzu

Sections you finish are checked off in the contents.