Prerequisites
- A vCenter Server that CloudThinker can reach over HTTPS, by hostname or IP address. The default port is
443. - A dedicated vCenter user for CloudThinker with the Read-only role.
- A CloudThinker workspace where VMware vCenter is not already connected.
CloudThinker supports one VMware vCenter connection per workspace. A vCenter that sits on a private network CloudThinker cannot reach will fail to connect.
Setup
1
Create a vCenter user
In the vSphere Client, open Administration → Single Sign On → Users and Groups. Select the
vsphere.local domain, open the Users tab, click Add, and enter a user name and password such as cloudthinker. A new user starts with no privileges.2
Give the user the Read-only role
Open Administration → Access Control → Global Permissions and click Add. Choose the domain, search for the user, select the Read-only role, and select Propagate to children. Click OK.
3
Add the connection in CloudThinker
Navigate to Connections → VMware vCenter and enter:
- VMWARE_HOST: your vCenter address, such as
vcenter.example.com - VMWARE_USERNAME: the user name with its domain, such as
cloudthinker@vsphere.local - VMWARE_PASSWORD: the user’s password
- VMWARE_PORT: leave
443unless vCenter listens elsewhere - VMWARE_VERIFY_SSL: leave Verify SSL certificate selected
A global permission applies to every object in every inventory hierarchy, and without Propagate to children the user cannot see the objects below the root. To share less, give the role on only the inventory objects you want agents to see.
Connection details
Required permissions
The Read-only role is the least-privilege starting point. vSphere describes it this way: users with the role “are allowed to view the state of the object and details about the object”, and all actions through the menus and toolbars are disallowed. If a question fails with a permission error, add only the privilege vCenter names. Agent changes such as powering a VM off or removing a snapshot need a role with those privileges, and each change still waits for your approval in CloudThinker.Agent capabilities
Answers cover only what the user’s role can see. See Approval for how gated changes work.
Verify the connection
Example prompts
Troubleshooting
Failed to connect to VMware vCenter
Failed to connect to VMware vCenter
CloudThinker could not sign in to vCenter. Check that the user name includes its domain, the password is current, and the address and port are reachable from CloudThinker. A certificate CloudThinker does not trust also fails here unless Skip SSL verification is selected.
VMWARE_HOST must be a DNS hostname, IPv4, or bracketed IPv6
VMWARE_HOST must be a DNS hostname, IPv4, or bracketed IPv6
The address has a scheme, a path, or an unbracketed IPv6 value. Enter only the host, such as
vcenter.example.com, 192.0.2.10, or [2001:db8::10].VMWARE_PORT must be an integer between 1 and 65535
VMWARE_PORT must be an integer between 1 and 65535
The port contains letters or is out of range. Enter a number such as
443.Invalid VMware connection configuration
Invalid VMware connection configuration
The address field is empty. Enter your vCenter hostname or IP address and connect again.
Connection 'vmware' already exists. Only one instance is allowed.
Connection 'vmware' already exists. Only one instance is allowed.
This workspace already has a VMware vCenter connection. Edit the existing one or disconnect it first.
An agent cannot see a VM, host, or datastore
An agent cannot see a VM, host, or datastore
The user’s role does not cover that object. Confirm the global permission has Propagate to children selected, or grant the role on the object.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Use a dedicated user — a separate vCenter user keeps this access visible and easy to revoke without affecting people.
- Keep certificate checks on — Skip SSL verification is for lab systems with self-signed certificates.
Related
Kubernetes Connection
Workload analysis, resource optimization, and cluster operations
Approval
How approval-gated actions work