Repository navigation
VMware Cloud Director
Since 3.1.0 Β· Contributed by Andrew Turbay (@turbay-a) in PR #167 Β· How it works underneath: Proxmox and Cloud Director β Developer Guide
FreeITSM reads the VMs from one or more VMware Cloud Director (vCloud Director) servers, with their network cards, addresses and disks, and the edge gateways with their uplink addresses. The VMs are listed under Asset Management β Servers, next to vCenter. It only reads: nothing is ever changed in Director.
You can add several servers. Each syncs on its own schedule, and its data is kept apart.
β οΈ Not yet tested against a real Director. The sync has been tested against a stand-in that answers the way Director's API is documented to. The first real run is worth watching: if something is missing, the sync's message says what, and an issue with that message helps a great deal.
- A Director user with read access to the organization whose VMs you want.
- The address of the Director portal, e.g.
https://vcd.example.com. - The FreeITSM server able to reach it.
| Case | Organization | User |
|---|---|---|
| One organization | its name, e.g. acme
|
a user with Organization Administrator, or a read-only role |
| Every organization (a provider) | System |
a provider administrator |
The organization is its name, not its display name: the one in the address when you sign in to it (β¦/tenant/acme means acme), or the Name column under Administration β Organizations.
An Organization Administrator can read everything, but can also change it. To let FreeITSM only read: Administration β Roles β New role in the organization, with the rights to view virtual machines, networks and edge gateways and none to create, change or delete. Then a user with that role. The exact rights differ between Director versions; if a sync reports a refused request, add the right it names.
| Director | API version |
|---|---|
| 10.5 | 38.0 |
| 10.3 | 36.2 |
If Test fails with an HTTP error about the request, try the other one.
Asset Management β Settings β VMware Cloud Director servers β Add server:
| Field | Value |
|---|---|
| Name | anything, e.g. vcd-prod
|
| Server address |
https://<vcd-host>. https only: the password travels with the login |
| Organization | from step 1 |
| User | from step 1, without @organization (FreeITSM adds it) |
| Password | stored encrypted, never shown again; leave it empty when editing to keep it |
| API version | from step 3 |
| Sync every (minutes) | 5 to 10080 |
| Verify certificate | ticked unless the portal has a self-signed certificate |
| Active | ticked |
Save, then Test, which names the organization and checks the VM list can be read. Then Sync now and Show VMs: each VM with its vApp, organization VDC, status, resources and addresses, and the edge gateways below.
- Sync hypervisors on the Servers page syncs vCenter, every active Proxmox server and every active Director server, with one result line each. Anyone who can use Asset Management can press it; adding, changing and testing servers needs the VMware Cloud Director servers settings permission.
-
On a schedule,
cron/vcloud_sync.phpsyncs every active server whose interval has passed:
*/5 * * * * php /var/www/html/cron/vcloud_sync.php >> /var/log/freeitsm-vcloud.log 2>&1
In Docker: docker exec <app container> php /var/www/html/cron/vcloud_sync.php, from the host's cron. Command line only.
Each sync logs in, reads, and logs out again, so scheduled runs don't leave sessions open on Director.
- A VM is removed only after every page of the VM list was read. If one page fails, nothing is removed that time, not even a VM missing from a page that did come back.
- FreeITSM counts the VMs that actually arrived, not the page size it asked for, so a Director whose administrator has lowered the maximum page size is still read to the end.
- The safety guard: fewer than half of the known VMs seen in one sync means nothing is removed.
- Edge gateways follow the same rule: removed only after all their pages were read.
A VM keeps its identity by UUID, so renaming it or moving it between vApps updates it rather than adding a second one.
| What you see | Likely cause |
|---|---|
| "Use an https:// address" | The address starts http://. |
| "refused the login (HTTP 401)" | Wrong user or password, or the organization's display name instead of its name. |
| "refused the login (HTTP 403)" | The user is locked, or can't sign in to that organization. |
| "did not return a session" | The wrong address, or a proxy that drops Director's session header. |
| "Logged in, but the VM inventory could not be read" | The API version is wrong for this Director, or the user can't view VMs. Check the version first. |
| "Could not reach the vCloud Director server: β¦" | The address is wrong, or a firewall is in the way. |
| A VM has no IP address | Its network card is disconnected, or it has no address yet. |
| "only partly readable; nothing was removed" | A page of the VM list failed. The next sync tries again. |
| "SAFETY GUARD" | Nothing was deleted. Usually the user lost rights, or the organization changed. |
Related: Proxmox VE Β· Proxmox and Cloud Director β Developer Guide Β· Assets
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: Projects
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
- π Projects
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ πΌοΈ Logo and courses broke on Apache with PHP-FPM
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96