Phoenix Software Ltd

VMware Tanzu - Kubernetes Runtime & Manage

VMware Tanzu provides a simplified, consistent approach to container
deployment, scaling, and management. Tools, automation, and data-driven insights supports infrastructure and application modernization. Tanzu simplifies multi-cloud Kubernetes deployment, centralizing management and governance for clusters and teams across on-premises, public-clouds, and edge.

Price packages starts with Tanzu Basic Edition

Features

  • Kubernetes control plane & lifecycle management
  • Multi-cloud Kubernetes Management
  • End-to-end connectivity & security with Service Mesh
  • High availability & Resilience
  • Full Stack Application & Infrastructure Observability
  • Container as a Service (CaaS)
  • Microservices and Container Platform
  • Integrated Load Balancing & Ingress
  • Secure apps and data end-to-end
  • Optimize operations with data driven insights

Benefits

  • Simplify platform operations across clouds
  • Simplify Kubernetes for developers & operators
  • Improve efficiency with centrally managed policy engine
  • Increase security with out-of-the-box security policies
  • Manage and deploy your preferred Kubernetes on multi-cloud
  • Run performant and reliable Kubernetes environments
  • Visibility across apps, micro-services, APIs, and data
  • Helps you transform legacy VMs into containers

Pricing

£865.50 a licence a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccs@phoenixs.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

4 7 3 5 6 6 0 7 2 6 5 0 2 5 7

Contact

Phoenix Software Ltd Jonny Scott
Telephone: 01904 562200
Email: ccs@phoenixs.co.uk

Service scope

Service constraints
Tanzu works with any major Kubernetes (CNCF certified) distribution (For
example, VMware's Tanzu Kubernetes Grid or other vendors, such as
Openshift, GKE, AKS, EKS, etc) on major public & private cloud providers,
including, but not limited to, Amazon AWS, Google Cloud, Microsoft Azure and
VMware based infrastructure.
System requirements
  • User accounts with correct privileges
  • Sufficient quotas to support the management cluster and workload clusters
  • Access to VMware Cloud to download Tanzu CLI
  • Ensure correct supported component matrix

User support

Email or online ticketing support
Email or online ticketing
Support response times
Support is available. This is available 24 hours a day, 7 days a week, 365 days a
year. Critical (Severity 1) - 30 minutes or less (24x7) Major (Severity 2) - 2
business hours (12x5) Minor (Severity 3) - 8 business hours (12x5) Cosmetic
(Severity 4) - 1 business day (12x5)
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Premium Support Services are available for all VMware Tanzu customers as
follows: Global, 24x7 support for Severity 1 issues, Fast response times for
critical issues, Unlimited number of support tickets, Remote Support and Online
access to documentation, technical resources, knowledge base, and discussion
forums. Product updates and upgrades during the subscription period The cost is
included in the Annual subscription for our software. VMware can also provide, at
extra cost, a designated Technical Account Manager (TAM) that can serve as a
single point of escalation for VMware Tanzu Software support and can personally
oversee your support experience. They are experts in advising on the best
operational condition of platforms, making proactive recommendations and
providing technical guidance. They will work with you to gain a deeper
understanding of your environments, apps & challenges, and engage subjectmatter experts when needed, driving toward more efficient resolution (including
Root Cause Analysis) and enabling discussion of future plans, projects, or
enhancements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
VMware Tanzu Labs Services are designed to accelerate your success with
VMware Tanzu by pairing our experts with your people to plan, implement,
customize, use, and scale the platform to meet your needs. By working
together we improve project outcomes and maximize on-the-job skills
enablement. An expert team from VMware Tanzu Platform Services will
work with designated people from your organization on a prioritized
backlog over a period of 3 or 6 weeks. Typically VMWare Tanzu Platform
services are focused on deployment and testing concerns. Actual work is
tailored against your objectives and actively prioritized by your Product
Owner to ensure investments align to what’s most important.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data created by the system or its applications would still be stored in a
customers provisioned storage in its native format. Customers therefore
can simply continue to use the data connected to the database product
that created it. Container builds are generally stored in an S3 compatible
store, such as AWS S3. Customers therefore always have their own data
under their own control, and not locked into the platform.
End-of-contract process
In the event of expiration of a Subscription License or any termination of
the Agreement, Customer must remove and destroy all copies of Software,
including all backup copies, from the server, virtual machine, and all
computers and terminals on which Software (including copies) is installed
or used and confirm the destruction of the Software. All support services
cease. If the customer has created applications and services they are free
to move or migrate these applications to other instances of VMware Tanzu
or other platforms. The costs associated with doing this are borne by the
user. VMware Tanzu Labs can provide consulting services to assist in this
process. The costs associated with are dependent on the number, density
and complexity of the applications.

Using the service

Web browser interface
Yes
Using the web interface
Options within the platform can be configured or controlled via the Web
interface, via the Tanzu CLI or APIs.
Web interface accessibility standard
WCAG 2.1 AA or EN 301 549
Web interface accessibility testing
We have been using industry-standard tools to test WCAG 2.1 AA standards
API
Yes
What users can and can't do using the API
VMware Tanzu web interfaces and command-line interfaces are built on the
same RESTful API layer. All functions of the platform can be accessed via an
API. This is a HTTPS and JSON based API. Many customers integrate their own
scripts and CI/CD pipelines with the VMware Tanzu REST API
API automation tools
  • Ansible
  • Chef
  • SaltStack
  • Terraform
  • Puppet
  • Other
Other API automation tools
Concourse
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
Using the command line interface
All functionality of the platform is available either via a web based user
interface and a command line interface. An API layer under pins and is
common to these two access mechanisms. Many customers use this interface
to integrate their CI/CD platforms. It is a RESTful HTTPS and JSON based set
of services. All APIs are documented publicly on our website

Scaling

Scaling available
Yes
Scaling type
  • Automatic
  • Manual
Independence of resources
You can install Tanzu in various topologies
to reflect your existing landscape.
Usage notifications
Yes
Usage reporting
  • API
  • Email

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • HTTP request and response status
  • Memory
  • Number of active instances
  • Other
Other metrics
Observability
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
VMware

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
The method used will depend upon the underlying Infrastructure
as a Service (IaaS) used. Many customers will use vSphere in
their own infrastructure, in which case the controls are customer
defined.
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Backup and recovery

Backup and recovery
Yes
What’s backed up
  • Application replicas
  • Database replicas
  • Platform configuration
Backup controls
Scheduling of different backup actions can be
accomplished individually. Data can be backed up
separately using tooling,
Datacentre setup
  • Multiple datacentres with disaster recovery
  • Multiple datacentres
  • Single datacentre with multiple copies
  • Single datacentre
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Tanzu is configurable in a variety of ways to meet scalability and availability
requirements as necessary. Our Platform services teams can also advise on
the best way to set up our software to maintain high levels of availability.
Approach to resilience
Tanzu can place deployed applications across different availability zones to
ensure resilience and actively monitors and manages applications and
services to ensure a specified number of instances are available at any one
time. Tanzu can be configured to auto-scale application instances up and
down depending upon the workload on each application at the time, saving
departments money. Documentation describing how we enable resiliency is
available on request. This includes the information relating to the resilience
of the Tanzu platform and applications installed within it.
Outage reporting
There is a "live view" dashboard that allows the current state of an
application and supporting metrics to be viewed and reviewed visually.
Tanzu actively monitors applications, services, and its own components.
Alerts can also be configured if required.

Identity and authentication

User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google apps)
  • Username or password
  • Other
Other user authentication
The exact network interconnects available will depend upon the customer's own preferred infrastructure as a service (IaaS), be they AWS, GCP, Microsoft Azure, or their own private infrastructure using VMware vSphere
Access restrictions in management interfaces and support channels
VMware Tanzu restricts access to named user accounts working on behalf of customers or ourselves. Separate administration roles are available for different administration tasks. Tanzu offers the flexibility to create customized roles and permissions to meet business needs
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Devices users manage the service through
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
Yes
Any other security certifications
NIST 800-53(r4)/(r5) controls are documented for VMware Tanzu

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
A mapping of NCSC cloud security guidance and CISbenchmarks onto Tanzu features and a reference architecturefor Official and Secret is available. A NIST 800.53r4 controlsmapping is available. We are Cyber Essential plus certified anda number of our Tanzu solutions are ISO 27001 certified
Information security policies and processes
VMware Tanzu Information Security Policies are based onISO/IEC 27001:2013. The policies have been published on thecompany’s internal portal and are reviewed periodically andapproved by the Chief Security Officer. All users are providedwith appropriate security awareness training to ensure policiesare followed. The Information Security Team is led by the ChiefSecurity Officer. The security organization is comprised of 3distinct yet collaborative teams - (1) Governance, Risk andCompliance (2) Information Security and (3) Physical Security.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Every VMware Tanzu software upgrade is pre-tested against our own security pipeline and alongside other components in the platform before it is shipped to customers via the VMware Tanzu Network. We perform additional vulnerability scanning of our software and dependencies using third party scanning software. Every code change to a component is linked to a requirement and has tests written for it before it is accepted into the next release. This provides tracking of every change back to the specific user need that it was required for, alongside the output of the tests
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Regular testing is done against all our software. In addition, when a CVE is disclosed in the third party component or dependency, we take the latest fix and test it and ship it as soon as possible after the upstream project releases a fix. We also routinely harden software components to minimise the attack surface.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Service and application component logs are aggregated into a log stream allowing analysis of activity within an installation. How quickly a response occurs depends on the customer's own incident management processes and policies
Incident management type
Supplier-defined controls
Incident management approach
How quickly a response occurs depends on the customer's own incident management processes and policies. Should a problem be discovered in the Tanzu platform, our support staff will respond within the SLA agreed timings.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
VMware
How shared infrastructure is kept separate
Tanzu offers the flexibility to create customized roles and permissions tomeet business needs and help you bring consistency in setting uppermissions for users and the service. Kubernetes is an inherently multi-tenant system. VMware Tanzu further simplifies the operation ofKubernetes for multi-cloud deployment

Energy efficiency

Energy-efficient datacentres
No

Social Value

Fighting climate change

Fighting climate change

Phoenix is Carbon Neutral - eight years ahead of government targets. We have achieved this by offsetting our operational emissions with carbon credit-approved schemes. By 2026 we will have further reduced our emissions by 50%, and by 2040 we will be Carbon Net-Zero.

We are ISO 14001 certified and hold IEMA membership. In addition, we have developed a Sustainability Carbon Accounting System, which is updated monthly and work closely with suppliers to ensure compliance and best practice throughout our supply chain and operations.

Contract waste will be minimised by recycling wherever possible, removing any general waste we create, and most crucially using cloud technology:

Our clean air low carbon initiatives reduce the impact of our car emissions on the environment and support people's health:

• All company cars are electric vehicles
• Car Share programmes
• Flexible working hours for public transport timetables
• Electric vehicle charging points in the car park for all employees to use on personal or company vehicles
• Use of public transport centrally arranged and promoted for customer visits as the preferred choice of travel
• Hybrid working environment with staff only required to travel to the office 2-3 times a week.
• No 'car idling' policy

To support customers on G-Cloud in fighting climate change, we will deliver the following sustainability workshops free of charge:

• Explore how Microsoft technology can help you record, report, and reduce your carbon emissions in one platform
• Understand how to procure ICT kit for a circular economy, accounting and mitigating for the carbon cost of your hardware
• Discover how you can implement ISO 14001 principles for robust environmental governance and compliance
• Learn how to engage your workforce and change their behaviours to work in greener ways, reducing paper and mileage
Covid-19 recovery

Covid-19 recovery

NA
Tackling economic inequality

Tackling economic inequality

Phoenix takes our responsibilities seriously around our supply chain to tackle economic inequality, increase resilience and capacity, and create new business, new jobs, and new skills.

We are committed to working with a diverse supply chain to provide a route to market, with over 70% of our services supply chain represented by SMEs. In addition, Phoenix is a signatory of the Prompt Payment Code to show our dedication to driving change towards fair payment terms and boosting the economy.

A member of our Alliances Team works with each partner to give them the necessary support to help them achieve their goals. We operate open-book pricing models with most of our partners to ensure fair margin allocation and encourage implementing improvements for mutual gain-share.

Phoenix ensures its suppliers are treated fairly, ensuring invoices are paid on time as well as promoting fair commercial arrangements. Phoenix encourages all suppliers that the products they supply are from sustainable sources and have excellent quality and environmental practices. This includes ensuring that human rights are adhered to throughout the supply chain. Phoenix is an ethical employer and is committed to raising its staff's well-being, living standards, skills, and health.

These values are upheld in our Supplier Code of Conduct (www.phoenixs.co.uk/about-us/corporate-policies/supplier-code-of-conduct) with our suppliers audited for compliance to ensure our customers are confident they are working with an ethical, social and sustainable supply chain.
Equal opportunity

Equal opportunity

We are committed to ensuring equality, diversity, and inclusion throughout our workforce and eliminating unlawful discrimination. You can read our Diversity and Inclusion Policy at www.phoenixs.co.uk/about-us/corporate-policies/equality-diversity-and-inclusion-policy.

We are passionate about helping women to advance in the IT industry by providing them with access to and support from other women working within the industry, as well as flexible working for every employee and an enhanced parental leave package. This commitment has proved hugely successful with 32% of positions at Phoenix held by women – well above the 20% industry average.

We have also begun our grassroots work by speaking in schools to highlight the roles available within the tech industry and encourage more women to consider careers in tech from an early age.

We are proud to be an accredited Living Wage Employer, supporting an important socially responsible policy and investing in our people.In addition to this, when establishing partnerships with parnters, and suppliers, we also check their living wage status to ensure that the message is heard and acted upon by all.

We are a proud signatory on the Race at Work Charter which underpins our commitment to take practical steps to ensure that we are tackling barriers that people face in recruitment and progression.

We work with our customers and employees to ensure that they can utilise the accessibility options available to them within the technology, apps, and services we all use daily. Whether this is the device they use, the accessibility checker within Outlook or Word, or live captions that can be added to all Microsoft Teams meetings, we ensure that how we work is as inclusive as possible.

We are a Disability Confident Committed employer, this scheme supports organisations like Phoenix to make the most of the talents people with disabilities bring to the workplace.
Wellbeing

Wellbeing

We are committed to creating a compassionate workplace where all employees feel supported personally and professionally by challenging the stigma surrounding mental health, raising awareness, and offering education opportunities. In 2020, we signed Mind’s ‘Time to Change Employer Pledge’ to back our commitment.

We ensure that our team are supported, remain in communication with management and each other, and understand that they can speak openly to their managers about their health and wellbeing to encourage discussion about how we can help them. Our programme of activities is run by our internal mental health and wellbeing ambassadors to help promote positive mental health and embed it into the culture of the organisation.

We hold internal monthly calls where employees are invited to openly discuss mental health and wellbeing, covering topics such as: loneliness, body image, Pride month, menopause support, and parental wellbeing. The aim of these sessions is to remove the stigma often associated with mental health by providing a platform that encourages open and honest conversations about mental wellbeing.

Each employee at Phoenix is given one hour a month on a Wednesday, to do something that supports their wellbeing.That’s 3,732 hours across the entire company each year dedicated to wellbeing.

We have undertaken research and engaged in internal conversations about menopause in the workplace to understand how we can better support our employees with the physical and emotional symptoms of the menopause.

We use the Microsoft Viva platform to help our employees manage their digital well-being and understand how they can change how they work to improve well-being across the organisation.

We have eight mental health first aiders across the business who are professionally trained to provide mental health support and guidance to members of our team who require it.

Pricing

Price
£865.50 a licence a year
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
There is a free 90 day time-limited and usage limited version that can be used for testing and evaluation purposes.
VMware also offers Tanzu Community Edition which is a full-featured, easy-to-manage Kubernetes platform for learners and users. It's a freely available, community-supported, open-source distribution of VMware Tanzu
Link to free trial
https://tanzucommunityedition.io/

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccs@phoenixs.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.