update vmware with VUM

dedri
dedri used Ask the Experts™
on
I upgraded one of our vmware cluster with customised HP ESXi ISO to the esxi 6.5 build:8294253 ( this is the latest HP custom ISO that is provided). Because this is not the latest version and I can see that there are several updates after this release I need to patch my servers now. I will use the VUM, but in VUM I can see all updates for version 6.5 and I am a little bit confused how to create my baseline, what to include in this baseline, which patches should I add.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
There are 3 updates available since  build:8294253, the latest is ESXi-6.5.0-20181004001-standard (Build 10175896).

You should be able to add these patches and re mediate or stage.

Author

Commented:
Could you specify how to do it, I am a little bit confused. Here is a screenshot of the VUM and filtered patches for esxi 6.5. What should I include in the baseline from this patches.  Or should I do it with some other way. As I can see some of the patches are repeated.
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
You should include the  latest patch in the base line.

Please see my EE Article as a guide

HOW TO: Update (Patch) VMware ESXi 6.0.0 GA to ESXi 6.0.0b with VMware Update Manager (VUM)
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Hello Andrew,
can you see the attached screenshot. Should I choose only first two patches from 2 October 2018, or I should choose all patches released after Update2( in a picture from 28 June to 02 october). My current build is esxi 6.5 build:8294253
VMWareUpdates.png
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
All patches are cumulative.

So you need to look at the  Web Link - BG document, and apply the latest patch. (which can usually be found on the date)

otherwise, you will be applying build x, and then build y, and build z....

when you only need to apply build z.

Author

Commented:
Hi Andrew,
As I understand you correctly I need to apply first two patches from 02 October from the picture that I attached.
Also I need to apply patches "cpu-microcode VIB" and "esxi-ui VIB" from 14 September.
Is this correct?
VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017
Commented:

Author

Commented:
very good article Andrew.
So I understand you correctly, I need to apply first two patches from 02 October seen in VUM and additionally patches "cpu-microcode VIB" and "esxi-ui VIB" from 14 September.
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
Yes, but also be very cautious, and understand the Rollups and Patches and what they do.... and also if they require vCenter Server to be updated first, otherwise you could end up updating the hosts, and then having no management of them, because VC should have been done first.

and also following all the Spectre, Meltdown, T1 security issues and also maybe updating Host Firmware and BIOS!

Author

Commented:
thanks for reminder, I've already update the vcenter server, firmware and BIOS of the hosts.
Also you told me about the T1 process of patching the host in my other question.
Till now I haven't used the customised ISO. In the past I always install vmware image, and my patching process is to download the latest iso from vmware site, upload it in vmware update manager, create a baseline on this imported image, and remediate hosts, because I know that they are cumulative. And now I am confused with this customised iso, should i patch the sever with vum patches, should i use my old way of performing patch process. I am wondering if i download the latest iso from vmware and patch the hosts, what happens to HP drivers installed with the hp iso, are they gone. With vmware update manager you don't have an options what to choose "install" or "update", as you can do with the command line. this is still not clear to me even though i wrote the article
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
Install the OEM HPE version, and then patch....

you can also add the HPE depot for patches as well.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial