Reading Time: 3 minutesMeltdown and Spectre remediations can imply not only performance degradation, but also some management issues. For example in how EVC works as described in VMware KB 52085 (Hypervisor-Assisted Guest Mitigation for Branch Target injection).
An ESXi host that is running a patched vSphere hypervisor with updated microcode will see new CPU features that were not previously available. These new features will be exposed to all Virtual Hardware Version 9+ VMs that are powered-on by that host. Because these virtual machines now see additional CPU features, vMotion to an ESXi host lacking the microcode or hypervisor patches applied will be prevented.
The vCenter patches enable vMotion compatibility to be retained within an EVC cluster. In order to maintain this compatibility, the new features are hidden from guests within the cluster until all hosts in the cluster are properly updated. At that time, the cluster will automatically upgrade its capabilities to expose the new features. Unpatched ESXi hosts will no longer be admitted into the EVC cluster.
continue reading…