VMware Bridges Private Cloud and GitOps with Native Argo CD Integration in VCF 9.1.1
Broadcom announced the release of VMware Cloud Foundation (VCF) 9.1.1, introducing a native Argo CD-based GitOps service for VCF Automation organization users in Tech Preview. Building upon the core Argo CD supervisor service established in vCenter, this release enables provider administrators to orchestrate Argo CD operators across regions and allows tenant teams to provision Argo CD instances directly into vSphere Namespaces and VMware Kubernetes Service (VKS) clusters. The integration automatically binds VCF Automation OpenID Connect (OIDC) authentication and maps target Kubernetes workloads to eliminate manual cluster connectivity setup.
For enterprise platform and infrastructure engineers, this integration addresses a persistent Day 2 challenge: operational fragmentation. While GitOps has become the standard continuous delivery paradigm for cloud-native applications, managing Argo CD at enterprise scale often devolves into running dozens of disconnected controller instances or over-privileged hub-and-spoke models. Platform teams have historically spent significant effort building custom automation to onboard developer tenants, enforce RBAC, and wire identity providers. Embedding Argo CD as a first-class private cloud service within VCF provides a unified delivery plane, reducing custom scaffolding and eliminating configuration drift across hybrid footprints.
This move mirrors a wider trend across enterprise cloud management platforms, where open-source GitOps engines are being integrated directly into vendor control planes rather than maintained as separate standalone tooling. As organizations modernize on-premises environments into cloud-operating models, infrastructure and application delivery must share the same lifecycle management framework. Standardizing on CNCF-graduated Argo CD rather than proprietary delivery orchestrators ensures compatibility with upstream Kubernetes tooling, Helm charts, and Kustomize overlays while leveraging native enterprise identity.
In practice, platform operators should evaluate this Tech Preview within staging environments to assess how VCF Automation's OIDC mapping aligns with existing tenant isolation and least-privilege policies. Because the new tenant-facing GitOps service is in Tech Preview—while the underlying vCenter supervisor service remains production-supported—teams should maintain clear boundaries between experimental self-service deployments and production cluster controllers. Organizations operating hybrid multi-region clusters should specifically test automated target attachment for vSphere Namespaces to validate whether automated secret generation and network routing eliminate the need for manual credential distribution.
Read original source