6.7

Table Of Contents
Virtual volumes are objects exported by a compliant storage system and typically correspond one-to-one
with a virtual machine disk and other VM-related files. A virtual volume is created and manipulated out-of-
band, not in the data path, by a VASA provider.
A VASA provider, or a storage provider, is developed through vSphere APIs for Storage Awareness. The
storage provider enables communication between the ESXi hosts, vCenter Server, and the
vSphere Client on one side, and the storage system on the other. The VASA provider runs on the storage
side and integrates with the vSphere Storage Monitoring Service (SMS) to manage all aspects of Virtual
Volumes storage. The VASA provider maps virtual disk objects and their derivatives, such as clones,
snapshots, and replicas, directly to the virtual volumes on the storage system.
The ESXi hosts have no direct access to the virtual volumes storage. Instead, the hosts access the virtual
volumes through an intermediate point in the data path, called the protocol endpoint. The protocol
endpoints establish a data path on demand from the virtual machines to their respective virtual volumes.
The protocol endpoints serve as a gateway for direct in-band I/O between ESXi hosts and the storage
system. ESXi can use Fibre Channel, FCoE, iSCSI, and NFS protocols for in-band communication.
The virtual volumes reside inside storage containers that logically represent a pool of physical disks on
the storage system. On the vCenter Server and ESXi side, storage containers are presented as Virtual
Volumes datastores. A single storage container can export multiple storage capability sets and provide
different levels of service to different virtual volumes.
Watch the video for information about Virtual Volumes architecture.
Virtual Volumes Part 2: Architecture
(http://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_vvols_part2_architecture)
Virtual Volumes and VMware Certificate Authority
vSphere includes the VMware Certificate Authority (VMCA). By default, the VMCA creates all internal
certificates used in vSphere environment. It generates certificates for newly added ESXi hosts and
storage VASA providers that manage or represent Virtual Volumes storage systems.
Communication with the VASA provider is protected by SSL certificates. These certificates can come from
the VASA provider or from the VMCA.
n
Certificates can be directly provided by the VASA provider for long-term use. They can be either self-
generated and self-signed, or derived from an external Certificate Authority.
n
Certificates can be generated by the VMCA for use by the VASA provider.
When a host or VASA provider is registered, VMCA follows these steps automatically, without
involvement from the vSphere administrator.
1 When a VASA provider is first added to the vCenter Server storage management service (SMS), it
produces a selfsigned certificate.
2 After verifying the certificate, the SMS requests a Certificate Signing Request (CSR) from the VASA
provider.
vSphere Storage
VMware, Inc. 282