VMware UK Limited

VMware Tanzu - Kubernetes Platform as a Service

VMware Tanzu provides a modular, application-aware platform to run your enterprise applications and microservices and provides a rich set of developer tooling with pre-paved paths to production that build and deploy software quickly and securely on any compliant public cloud or on-premises Kubernetes cluster

Features

  • Container creation from application code
  • Platform as a Service (PaaS)
  • Cloud native runtimes
  • Application high availability management
  • Application lifecycle management
  • Application and systems monitoring
  • Runs on all major Kubernetes providers
  • Container deployment
  • Microservices and Container Platform
  • Modern Application Platform

Benefits

  • Quickly create application containers using an automated process
  • Bootstrap developing your applications and deliver higher developer productivity
  • Deploying your applications & microservices in discoverable and repeatable ways
  • Automatically scale environments depending on demand
  • Deliver a superior developer experience on Kubernetes
  • Free developers to spend time writing applications, not container scripts
  • Securely manage apps & containers and scan for vulnerabilities
  • Reduce time to deploy and quickly make applications available

Pricing

£43.50 to £865,649.87 a unit a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.hardy@broadcom.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

6 1 5 1 8 8 1 7 7 6 7 3 8 0 2

Contact

VMware UK Limited Chris Hardy
Telephone: 07824 478092
Email: chris.hardy@broadcom.com

Service scope

Service constraints
The platform can run on any major Kubernetes (CNCF certified) distribution (Examples include: Tanzu Kubernetes Grid, Openshift, GKE, AKS, EKS, etc), on major public & private cloud providers, including, but not limited to, Amazon AWS, Google Cloud, Microsoft Azure and VMware based infrastructure.
System requirements
  • A container image registry, such as Harbor or Docker Hub
  • Registry credentials with read and write access made available
  • 10GB of storage recommended for Tanzu Build Service component
  • Optional DNS records you should allocate (See release notes)
  • Recent version of Chrome, Firefox, or Edge for GUI access
  • Installation requires Kubernetes cluster (See release notes)
  • 8CPUs for i9, or 12CPUs for i7 (or equivalent) available
  • 8GB of RAM across all nodes available
  • 12GB of RAM is available to build and deploy applications.
  • 70GB of disk space available per node

User support

Email or online ticketing support
Email or online ticketing
Support response times
Support is available. This is available 24 hours a day, 7 days a week, 365 days a year.
Critical (Severity 1) - 30 minutes or less (24x7)
Major (Severity 2) - 2 business hours (12x5)
Minor (Severity 3) - 8 business hours (12x5)
Cosmetic (Severity 4) - 1 business day (12x5)
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Premium Support Services are available for all VMware Tanzu customers as follows: Global, 24x7 support for Severity 1 issues, Fast response times for critical issues, Unlimited number of support tickets, Remote Support and Online access to documentation, technical resources, knowledge base, and discussion forums. Product updates and upgrades during the subscription period The cost is included in the Annual subscription for our software.

VMware can also provide, at extra cost, a designated Technical Account Manager (TAM) that can serve as a single point of escalation for VMware Tanzu Software support and can personally oversee your support experience. They are experts in advising on the best operational condition of platforms, making proactive recommendations and providing technical guidance. They will work with you to gain a deeper understanding of your environments, apps & challenges, and engage subject-matter experts when needed, driving toward more efficient resolution (including Root Cause Analysis) and enabling discussion of future plans, projects, or enhancements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
VMware Tanzu Labs Services are designed to accelerate your success with VMware Tanzu by pairing our experts with your people to plan, implement, customize, use, and scale the platform to meet your needs. By working together we improve project outcomes and maximize on-the-job skills enablement. An expert team from VMware Tanzu Platform Services will work with designated people from your organization on a prioritized backlog over a period of 3 or 6 weeks. Typically VMWare Tanzu Platform services are focused on deployment and testing concerns. Actual work is tailored against your objectives and actively prioritized by your Product Owner to ensure investments align to what’s most important.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data created by the system or its applications would still be stored in a customers provisioned storage in its native format. Customers therefore can simply continue to use the data connected to the database product that created it. Container builds are generally stored in an S3 compatible store, such as AWS S3. Customers therefore always have their own data under their own control, and not locked into the platform.
End-of-contract process
In the event of expiration of a Subscription License or any termination of the Agreement, Customer must remove and destroy all copies of Software, including all backup copies, from the server, virtual machine, and all computers and terminals on which Software (including copies) is installed or used and confirm the destruction of the Software. All support services cease. If the customer has created applications and services they are free to move or migrate these applications to other instances of VMware Tanzu or other platforms. The costs associated with doing this are borne by the user. VMware Tanzu Labs can provide consulting services to assist in this process. The costs associated with are dependent on the number, density and complexity of the applications.

Using the service

Web browser interface
Yes
Using the web interface
Options within the platform can be configured or controlled via the Web interface, via the Tanzu CLI or APIs.
Web interface accessibility standard
WCAG 2.1 AA or EN 301 549
Web interface accessibility testing
We have been using industry-standard tools to test WCAG 2.1 AA standards
API
Yes
What users can and can't do using the API
VMware Tanzu web interfaces and command-line interfaces are built on the same RESTful API layer. All functions of the platform can be accessed via an API. This is a HTTPS and JSON based API. Many customers integrate their own scripts and CI/CD pipelines with the VMware Tanzu REST API.
API automation tools
  • Ansible
  • Chef
  • SaltStack
  • Terraform
  • Puppet
  • Other
Other API automation tools
Concourse
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
Using the command line interface
All functionality of the platform is available either via a web based user interface and a command line interface. An API layer under pins and is common to these two access mechanisms. Many customers use this interface to integrate their CI/CD platforms. It is a RESTful HTTPS and JSON based set of services. All APIs are documented publicly on our website

Scaling

Scaling available
Yes
Scaling type
  • Automatic
  • Manual
Independence of resources
You can install Tanzu in various topologies to reflect your existing landscape.
Usage notifications
Yes
Usage reporting
  • API
  • Email

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • HTTP request and response status
  • Memory
  • Number of active instances
  • Other
Other metrics
Observability
Reporting types
  • API access
  • Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
The method used will depend upon the underlying Infrastructure as a Service (IaaS) used. Many customers will use vSphere in their own infrastructure, in which case the controls are customer defined.
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Backup and recovery

Backup and recovery
Yes
What’s backed up
  • Application replicas
  • Database replicas
  • Platform configuration
Backup controls
Scheduling of different backup actions can be accomplished individually. Data can be backed up separately using tooling,
Datacentre setup
  • Multiple datacentres with disaster recovery
  • Multiple datacentres
  • Single datacentre with multiple copies
  • Single datacentre
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Tanzu is configurable in a variety of ways to meet scalability and availability requirements as necessary. Our Platform services teams can also advise on the best way to set up our software to maintain high levels of availability.
Approach to resilience
Tanzu can place deployed applications across different availability zones to ensure resilience and actively monitors and manages applications and services to ensure a specified number of instances are available at any one time.

Tanzu can be configured to auto-scale application instances up and down depending upon the workload on each application at the time, saving departments money.

Documentation describing how we enable resiliency is available on request. This includes the information relating to the resilience of the Tanzu platform and applications installed within it.
Outage reporting
There is a "live view" dashboard that allows the current state of an application and supporting metrics to be viewed and reviewed visually. Tanzu actively monitors applications, services, and its own components. Alerts can also be configured if required.

Identity and authentication

User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google apps)
  • Username or password
  • Other
Other user authentication
The exact network interconnects available will depend upon the customer's own preferred infrastructure as a service (IaaS), be they AWS, GCP, Microsoft Azure, or their own private infrastructure using VMware vSphere.
Access restrictions in management interfaces and support channels
VMware Tanzu restricts access to named user accounts working on behalf of customers or ourselves. Separate administration roles are available for different administration tasks. Tanzu offers the flexibility to create customized roles and permissions to meet business needs
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Devices users manage the service through
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
Yes
Any other security certifications
NIST 800-53(r4)/(r5) controls are documented for VMware Tanzu

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
A mapping of NCSC cloud security guidance and CIS benchmarks onto Tanzu features and a reference architecture for Official and Secret is available. A NIST 800.53r4 controls mapping is available.
We are Cyber Essential plus certified and a number of our Tanzu solutions are ISO 27001 certified
Information security policies and processes
VMware Tanzu Information Security Policies are based on ISO/IEC 27001:2013. The policies have been published on the company’s internal portal and are reviewed periodically and approved by the Chief Security Officer. All users are provided with appropriate security awareness training to ensure policies are followed. The Information Security Team is led by the Chief Security Officer. The security organization is comprised of 3 distinct yet collaborative teams - (1) Governance, Risk and Compliance (2) Information Security and (3) Physical Security.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Every VMware Tanzu software upgrade is pre-tested against our own security pipeline and alongside other components in the platform before it is shipped to customers via the VMware Tanzu Network. We perform additional vulnerability scanning of our software and dependencies using third party scanning software. Every code change to a component is linked to a requirement and has tests written for it before it is accepted into the next release. This provides tracking of every change back to the specific user need that it was required for, alongside the output of the tests.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Regular testing is done against all our software. In addition, when a CVE is disclosed in the third party component or dependency, we take the latest fix and test it and ship it as soon as possible after the upstream project releases a fix. We also routinely harden software components to minimise the attack surface.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Service and application component logs are aggregated into a log stream allowing analysis of activity within an installation. How quickly a response occurs depends on the customer's own incident management processes and policies.
Incident management type
Supplier-defined controls
Incident management approach
How quickly a response occurs depends on the customer's own incident management processes and policies. Should a problem be discovered in the Tanzu platform, our support staff will respond within the SLA agreed timings.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
VMware
How shared infrastructure is kept separate
Tanzu offers the flexibility to create customized roles and permissions to meet business needs and help you bring consistency in setting up permissions for users and the service. Kubernetes is an inherently multi-tenant system. VMware Tanzu further simplifies the operation of Kubernetes for multi-cloud deployment.

Energy efficiency

Energy-efficient datacentres
No

Social Value

Fighting climate change

Fighting climate change

Sustainable growth for VMware’s business requires decoupling our company growth from carbon emissions. To this end, we’ve accelerated our focus on decarbonization and received third-party validation from the Science Based Target Initiative (SBTi) on our science-based targets. Since 2018, we have maintained our certified CarbonNeutral® company status, in accordance with The CarbonNeutral Protocol. Since 2019, we have sourced 100 percent of our power in our global facilities from renewable sources, in accordance with RE100 Reporting Guidance.

● VMware’s net zero emissions goal builds on approved science-based targets and expands the scope of our climate commitments. For us, a net zero goal means reducing emissions for our entire carbon footprint. We are focused on prioritizing energy efficiency within our operations through our commitment to green buildings, working with our suppliers to reduce their emissions, and supporting distributed workforces through our Future of Work initiative. Through carbon financing, we support low carbon sustainable development projects that enable carbon avoidance to offset our remaining emissions. In line with the leading net zero guidance, we are developing our strategy to include carbon removal projects to address residual emissions.

● In FY22, we furthered climate transition planning at VMware, guided by Taskforce on Climate-related Financial Disclosures (TCFD) recommendations. As VMware continues to learn more about climate risks, we can build longer time horizon risks into our strategy to become even more sustainable and resilient.
Covid-19 recovery

Covid-19 recovery

Decisive action by VMware during the early days of the COVID-19 pandemic led to a company-wide remote workforce, which our customers were able to implement as well through VMware’s Workspace solutions.

● Through VMware’s unique Citizen Philanthropy approach to giving, we empower every VMware employee—wherever they are—to be active, engaged citizens, contributing to what matters most to them in their own communities. Throughout the pandemic, VMware people delivered food to neighbours in need, made masks and donated resources to frontline workers and relief efforts, and helped nonprofit organizations strengthen their IT operations so they can focus on supporting their communities. VMware also supported GlobalGiving’s Coronavirus Relief Fund and TechSoup’s COVID-19 Response Fund and raised the limit on matching gifts available to all VMware people.
Tackling economic inequality

Tackling economic inequality

VMware IT Academy partners directly with more than 2,500 educational institutions, governments and nonprofits globally to empower learners through coursework, labs and experiences. To enrich learning and help jump-start careers, our partner academic institutions can also access the latest suite of VMware software solutions and use them in a hands-on educational environment. VMware IT Academy is key to our 2030 goal of upskilling 15 million people through our educational offerings and creates a pipeline of diverse talent that is available to advance companies’ digital journeys and deploy VMware solutions.

● VMware donates our technology to academic institutions, enabling learners with access to technical training and labs across technology solutions and companies through Academic Cloud.

● VMware IT Academy partners with the Rochester Institute of Technology (RIT) for their Cybersecurity Bootcamp, an immersive, 15-week hands-on training course to reskill or upskill unemployed individuals, including minorities and veterans.

● VMinclusion Taara offers free technical education on VMware products & technology that enable digital business transformation, addressing the gender gap in the Indian IT sector and empowering women with financial and social independence.

● VMware Responsible Sourcing supports sustainability, diversity and accessibility across our supply chain. VMware has committed to working with 75% of our suppliers (by spend) to set their own science-based targets by the end of 2024. We are also prioritizing the sourcing of goods and services through diverse businesses and have committed to spending $1.5B with diverse suppliers through 2030. Our definition of diverse supplier includes: small-business enterprises, minority-owned enterprises, women-owned enterprises, and businesses owned by other underrepresented groups such as LGBTQ, veterans, and proprietors with disabilities.
Equal opportunity

Equal opportunity

VMware joined the Valuable 500, a global business collective that is igniting systemic change and unlocking the business, social and economic value of more than 1 billion people with disabilities around the world. From ensuring the technology we develop is accessible for all to empowering our employees through accessible, inclusive and innovative engagement and wellbeing programs, our company remains committed to driving meaningful impact on disability, wellness and neurodiversity inclusion.

● As a leading software company, user accessibility is top of mind at VMware. One of our ESG goals by 2030 is to ensure the technology that we develop, and source within our supply chain, is accessible for all. We created internal Accessibility Guidelines within VMware and committed to assess all new software and events suppliers for accessibility standards aligned with our own guidelines.

● Employee Resource Groups at VMware are called Power of Difference communities (“PODs”), and they play a strategic role in building a culture of belonging. We are focused on driving a culture that is inclusive of all forms of diversity, including supporting employees with disabilities. In 2021, VMware was named a Best Place to Work for Disability Inclusion by the Disability Equality Index (DEI).
Wellbeing

Wellbeing

At VMware, we enrich lives at work, at home and in the community, because we believe that empowering our people to bring their authentic selves to work drives business excellence and enables us to achieve our business goals. We prioritize employee wellbeing and work hard to foster a culture that is ethical and respectful, kind and compassionate, which is defined by our EPIC2 values — Execution, Passion, Integrity, Customers and Community.

● Employee wellbeing at VMware is a top priority as we believe people are the key to our success, and we are always striving to make it easier for employees to pursue well-being on their own terms, which will also help them perform well at work. We recognize that VMware has a responsibility to help support our employees manage the added complexities of their work and family situations since the start of the COVID-19 pandemic. Our well-being benefits include: four supplemental days off (our “EPIC2” days), life coaching and emotional support, work-life services for employees and their families, and a wellbeing allowance.

Pricing

Price
£43.50 to £865,649.87 a unit a year
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
There is a free 90 day time-limited and usage limited version that can be used for testing and evaluation purposes.

VMware also offers Tanzu Community Edition which is a full-featured, easy-to-manage Kubernetes platform for learners and users. It's a freely available, community-supported, open-source distribution of VMware Tanzu.
Link to free trial
https://tanzucommunityedition.io/

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.hardy@broadcom.com. Tell them what format you need. It will help if you say what assistive technology you use.