> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# VMware vCenter

> Connect VMware vCenter to CloudThinker for read-only inventory of VMs, hosts, clusters, and datastores, with approval-gated VM changes

Connect your vCenter Server to let CloudThinker agents inventory VMs, hosts, clusters, and datastores, audit snapshots and capacity, and run VM changes after you approve them. vCenter authenticates with a **user name and password**, and the role you give that user sets what agents can do.

## Prerequisites

* A **vCenter Server** that CloudThinker can reach over HTTPS, by hostname or IP address. The default port is `443`.
* A **dedicated vCenter user** for CloudThinker with the **Read-only** role.
* A CloudThinker workspace where VMware vCenter is not already connected.

<Info>
  CloudThinker supports one VMware vCenter connection per workspace. A vCenter that sits on a private network CloudThinker cannot reach will fail to connect.
</Info>

## Setup

<Steps>
  <Step title="Create a vCenter user">
    In the vSphere Client, open **Administration → Single Sign On → Users and Groups**. Select the `vsphere.local` domain, open the **Users** tab, click **Add**, and enter a user name and password such as `cloudthinker`. A new user starts with no privileges.
  </Step>

  <Step title="Give the user the Read-only role">
    Open **Administration → Access Control → Global Permissions** and click **Add**. Choose the domain, search for the user, select the **Read-only** role, and select **Propagate to children**. Click **OK**.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → VMware vCenter** and enter:

    * **VMWARE\_HOST**: your vCenter address, such as `vcenter.example.com`
    * **VMWARE\_USERNAME**: the user name with its domain, such as `cloudthinker@vsphere.local`
    * **VMWARE\_PASSWORD**: the user's password
    * **VMWARE\_PORT**: leave `443` unless vCenter listens elsewhere
    * **VMWARE\_VERIFY\_SSL**: leave **Verify SSL certificate** selected

    Click **Connect**. CloudThinker signs in to vCenter and shows a **Connected** status.
  </Step>
</Steps>

<Note>
  A global permission applies to every object in every inventory hierarchy, and without **Propagate to children** the user cannot see the objects below the root. To share less, give the role on only the inventory objects you want agents to see.
</Note>

## Connection details

| Field | Description | Example |
| - | - | - |
| **VMWARE\_HOST** | vCenter hostname, IPv4 address, or IPv6 address in brackets. No `https://` and no path | `vcenter.example.com` |
| **VMWARE\_USERNAME** | vCenter user name, including the domain | `cloudthinker@vsphere.local` |
| **VMWARE\_PASSWORD** | Password of that user | — |
| **VMWARE\_PORT** | Port vCenter listens on. Defaults to `443` | `443` |
| **VMWARE\_VERIFY\_SSL** | **Verify SSL certificate** (default) or **Skip SSL verification** | **Verify SSL certificate** |

<Warning>
  There is no field for a custom certificate authority. If your vCenter uses a certificate CloudThinker does not trust, **Skip SSL verification** is the only way to connect, and it removes protection against someone impersonating your vCenter. Prefer a certificate from a trusted authority.
</Warning>

## Required permissions

The **Read-only** role is the least-privilege starting point. vSphere describes it this way: users with the role "are allowed to view the state of the object and details about the object", and all actions through the menus and toolbars are disallowed.

If a question fails with a permission error, add only the privilege vCenter names. Agent changes such as powering a VM off or removing a snapshot need a role with those privileges, and each change still waits for your approval in CloudThinker.

<Tip>
  Start with **Read-only**. Switch the user to a broader role only when you want agents to make approved changes, and give it on as few objects as you can.
</Tip>

## Agent capabilities

| Capability | Description |
| - | - |
| **Inventory** | List datacenters, clusters, hosts, VMs, datastores, and networks, and inspect one of them in detail |
| **Tags** | Read tag categories and the objects they are attached to |
| **Right-sizing** | Find over-provisioned and idle VMs from CPU usage history |
| **Snapshots** | List snapshots by VM and flag stale ones |
| **Datastore capacity** | Show used and free space and flag datastores running low |
| **Drift** | Review host settings such as NTP, syslog, SSH service, and lockdown mode, and port group security options |
| **Changes** | Power, reconfigure, migrate, snapshot, or delete VMs — each change **requires approval** |

Answers cover only what the user's role can see. See [Approval](/guide/approval) for how gated changes work.

### Verify the connection

```text theme={null}
Summarize my vCenter inventory: datacenters, clusters, hosts, VMs, and datastores
```

### Example prompts

```text theme={null}
Which powered-on VMs have used under 15% CPU recently and have 8 or more vCPUs?
List snapshots older than 7 days, grouped by VM
Which datastores are above 85% full?
```

## Troubleshooting

<Accordion title="Failed to connect to VMware vCenter">
  CloudThinker could not sign in to vCenter. Check that the user name includes its domain, the password is current, and the address and port are reachable from CloudThinker. A certificate CloudThinker does not trust also fails here unless **Skip SSL verification** is selected.
</Accordion>

<Accordion title="VMWARE_HOST must be a DNS hostname, IPv4, or bracketed IPv6">
  The address has a scheme, a path, or an unbracketed IPv6 value. Enter only the host, such as `vcenter.example.com`, `192.0.2.10`, or `[2001:db8::10]`.
</Accordion>

<Accordion title="VMWARE_PORT must be an integer between 1 and 65535">
  The port contains letters or is out of range. Enter a number such as `443`.
</Accordion>

<Accordion title="Invalid VMware connection configuration">
  The address field is empty. Enter your vCenter hostname or IP address and connect again.
</Accordion>

<Accordion title="Connection 'vmware' already exists. Only one instance is allowed.">
  This workspace already has a VMware vCenter connection. Edit the existing one or disconnect it first.
</Accordion>

<Accordion title="An agent cannot see a VM, host, or datastore">
  The user's role does not cover that object. Confirm the global permission has **Propagate to children** selected, or grant the role on the object.
</Accordion>

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Use a dedicated user** — a separate vCenter user keeps this access visible and easy to revoke without affecting people.
- **Keep certificate checks on** — **Skip SSL verification** is for lab systems with self-signed certificates.

## Related

<CardGroup cols={2}>
  <Card title="Kubernetes Connection" icon="https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/kubernetes.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=7c03292954ff635a1994623a5c39971b" href="/guide/connections/kubernetes" width="24" height="24" data-path="images/icons/kubernetes.svg">
    Workload analysis, resource optimization, and cluster operations
  </Card>

  <Card title="Approval" icon="shield-check" href="/guide/approval">
    How approval-gated actions work
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.