The clustered Workspace ONE Access is distributed as an install bundle for SDDC Manager. A Workspace ONE Access appliance includes identity and access management services.
Deployment Type
You consider the deployment type, standalone or cluster, according to the design objectives for the availability and number of users that the system and integrated SDDC solutions must support. You deploy Workspace ONE Access on the default management vSphere cluster.
Deployment Type |
Number of Nodes |
Considerations |
---|---|---|
Standard |
1 |
|
Cluster (Recommended) |
3 |
|
This design uses the recommended cluster topology of Workspace ONE Access.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
VCF-VRS-WSA-CFG-001 |
Deploy Workspace ONE Access in a cluster configuration by using vRealize Suite Lifecycle Manager in VMware Cloud Foundation mode. |
|
None. |
VCF-VRS-WSA-CFG-002 |
Use the embedded PostgreSQL database cluster with Workspace ONE Access. |
Removes the need for external database services. vRealize Suite Lifecycle Manager configures a native PostgreSQL database cluster as part of the Workspace ONE Access cluster deployment. |
None. |
VCF-VRS-WSA-CFG-003 |
Protect all Workspace ONE Access nodes using vSphere High Availability (vSphere HA). |
Supports high availability for Workspace ONE Access without requiring manual intervention during an ESXi host failure event. |
None. |
VCF-VRS-WSA-CFG-004 |
Apply vSphere Distributed Resource Scheduler (vSphere DRS) anti-affinity rules for the Workspace ONE Access cluster nodes. |
Using vSphere DRS prevents the Workspace ONE Access cluster nodes from residing on the same ESXi host and risking the high availability of the deployment. |
|
VCF-VRS-WSA-CFG-005 |
Add a VM group for the Workspace ONE Access cluster nodes and set VM rules to restart the Workspace ONE Access VM group before any of the VMs that depend on it for authentication. |
You can define the startup order of virtual machines regarding the service dependency. The startup order ensures that vSphere HA powers on the Workspace ONE Access virtual machines in an order that respects product dependencies. |
None. |
Deployment of Workspace ONE Access in Multiple Availability Zones
Under normal operating conditions, the Workspace ONE Access cluster runs in the first availability zone. If a failure in occurs in the first availability zone, the Workspace ONE Access cluster is failed over to the second availability zone.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
VCF-VRS-WSA-CFG-006 |
Add the Workspace ONE Access cluster nodes to the VM group for the first availability zone. |
Ensures that, by default, the Workspace ONE Access cluster nodes are powered on a host in the first availability zone. |
If the Workspace ONE Access cluster is deployed after the creation of the stretched management cluster, you must add the cluster nodes to the VM group manually. |
Sizing Compute and Storage Resources
A Workspace ONE Access cluster deployment requires certain CPU, memory, and storage resources to support the maximum users and groups that can be synced.
Appliance Size |
Directory Sync of Users and Groups per Tenant |
CPU per Appliance |
Memory per Appliance |
Disk per Appliance |
---|---|---|---|---|
Extra Small |
Maximum:
|
4 vCPU |
8 GB |
100 GB |
Small |
Maximum:
|
6 vCPU |
10 GB |
100 GB |
Medium (Minimum requirement for vRealize Automation) |
Maximum:
|
8 vCPU |
16 GB |
100 GB |
Large |
Maximum:
|
10 vCPU |
16 GB |
100 GB |
Extra Large |
Maximum:
|
12 vCPU |
32 GB |
100 GB |
Extra Extra Large |
Maximum:
|
14 vCPU |
48 GB |
100 GB |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
VCF-VRS-WSA-CFG-007 |
Deploy each of the Workspace ONE Access node as a medium-size appliance. |
Supports scalability for a vRealize Automation cluster deployment. |
None. |