Skip to main content
Connect your vCenter Server to let CloudThinker agents inventory VMs, hosts, clusters, and datastores, audit snapshots and capacity, and run VM changes after you approve them. vCenter authenticates with a user name and password, and the role you give that user sets what agents can do.

Prerequisites

  • A vCenter Server that CloudThinker can reach over HTTPS, by hostname or IP address. The default port is 443.
  • A dedicated vCenter user for CloudThinker with the Read-only role.
  • A CloudThinker workspace where VMware vCenter is not already connected.
CloudThinker supports one VMware vCenter connection per workspace. A vCenter that sits on a private network CloudThinker cannot reach will fail to connect.

Setup

1

Create a vCenter user

In the vSphere Client, open Administration → Single Sign On → Users and Groups. Select the vsphere.local domain, open the Users tab, click Add, and enter a user name and password such as cloudthinker. A new user starts with no privileges.
2

Give the user the Read-only role

Open Administration → Access Control → Global Permissions and click Add. Choose the domain, search for the user, select the Read-only role, and select Propagate to children. Click OK.
3

Add the connection in CloudThinker

Navigate to Connections → VMware vCenter and enter:
  • VMWARE_HOST: your vCenter address, such as vcenter.example.com
  • VMWARE_USERNAME: the user name with its domain, such as cloudthinker@vsphere.local
  • VMWARE_PASSWORD: the user’s password
  • VMWARE_PORT: leave 443 unless vCenter listens elsewhere
  • VMWARE_VERIFY_SSL: leave Verify SSL certificate selected
Click Connect. CloudThinker signs in to vCenter and shows a Connected status.
A global permission applies to every object in every inventory hierarchy, and without Propagate to children the user cannot see the objects below the root. To share less, give the role on only the inventory objects you want agents to see.

Connection details

There is no field for a custom certificate authority. If your vCenter uses a certificate CloudThinker does not trust, Skip SSL verification is the only way to connect, and it removes protection against someone impersonating your vCenter. Prefer a certificate from a trusted authority.

Required permissions

The Read-only role is the least-privilege starting point. vSphere describes it this way: users with the role “are allowed to view the state of the object and details about the object”, and all actions through the menus and toolbars are disallowed. If a question fails with a permission error, add only the privilege vCenter names. Agent changes such as powering a VM off or removing a snapshot need a role with those privileges, and each change still waits for your approval in CloudThinker.
Start with Read-only. Switch the user to a broader role only when you want agents to make approved changes, and give it on as few objects as you can.

Agent capabilities

Answers cover only what the user’s role can see. See Approval for how gated changes work.

Verify the connection

Example prompts

Troubleshooting

CloudThinker could not sign in to vCenter. Check that the user name includes its domain, the password is current, and the address and port are reachable from CloudThinker. A certificate CloudThinker does not trust also fails here unless Skip SSL verification is selected.
The address has a scheme, a path, or an unbracketed IPv6 value. Enter only the host, such as vcenter.example.com, 192.0.2.10, or [2001:db8::10].
The port contains letters or is out of range. Enter a number such as 443.
The address field is empty. Enter your vCenter hostname or IP address and connect again.
This workspace already has a VMware vCenter connection. Edit the existing one or disconnect it first.
The user’s role does not cover that object. Confirm the global permission has Propagate to children selected, or grant the role on the object.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Use a dedicated user — a separate vCenter user keeps this access visible and easy to revoke without affecting people.
  • Keep certificate checks on — Skip SSL verification is for lab systems with self-signed certificates.

Kubernetes Connection

Workload analysis, resource optimization, and cluster operations

Approval

How approval-gated actions work