vLCM baselines to images: how to convert vSphere clusters before 9.x, and the errors that stop it
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Broadcom’s VCF 9.0 support notes (29 September 2026) say managing clusters with baselines “is no longer supported in vCenter 9.0”; per KB 379388 an existing baseline cluster can still patch 8.x hosts within 8.x, but ISO upgrades, 9.x patching and new baseline clusters or standalone hosts are blocked
- A vLCM image is an ESX base image, its only mandatory element, plus an optional vendor add-on, firmware and drivers add-on from the server maker’s hardware support manager, and components; only images can be validated before remediation, update firmware and use ESX Live Patching
- Hosts must be stateful and run ESXi 7.0 or later under vCenter 8.0, or 8.0 or later under vCenter 9.0, without VIBs of unintegrated solutions; standalone VIBs missing from the image are deleted at remediation, and clusters with hosts from different vendors reach ESX 9 first, then convert to a composite image
- The switch starts on the Updates tab, Image (8.0) or Image Setup (9.0), with the image taken from a host, a JSON file or a manual setup, then Validate, Save and Finish image setup; it cannot be reversed, and a vCenter restored from a backup taken before the switch puts the cluster back on baselines
- Baselines are not supported in VCF 9.0 or later; VCF 5.2.2 and 9.0 switch clusters through SDDC Manager by PowerShell script or API (KB 385617), Supervisor clusters after the vCenter upgrade and before the ESX upgrade, and the VCF Installer 9.0 rejects baseline clusters (KB 443265)
Eurokommerz × Vixen.UNO: VMware Optimisation Talk to an expert →
Converting vLCM baselines to images before vSphere 9
To convert a cluster from vSphere Lifecycle Manager (vLCM) baselines to an image, open its Updates tab in the vSphere Client, click Image on vCenter 8.0 or Image Setup on vCenter 9.0, take the image from a host, a JSON file or a manual definition, then validate, save and finish the image setup. The hosts change only when you remediate them, and the cluster cannot go back to baselines. Broadcom’s vSphere support notes for VCF 9.0 (29 September 2026) say that managing clusters with baselines and baseline groups “is no longer supported in vCenter 9.0”. The switch can run on vCenter 8.0 or after the upgrade to vCenter 9.0, before the hosts move to ESX 9, with one documented exception for mixed hardware.
Broadcom deprecated baselines with vSphere 8.0 (KB 322186), and KB 379388 lists what vCenter 9.0 still allows. An existing baseline cluster of 8.x hosts can be patched within 8.x, but “ISO based upgrade is blocked for any ESX host version”, 9.x hosts cannot be patched with baselines, and new clusters and standalone hosts get images by default. Broadcom’s VCF 9.0 documentation (29 September 2026) adds that baselines “are not supported with VMware Cloud Foundation 9.0 or later”. The dates and the upgrade order are in our vSphere 8 end of support guide.
What a vLCM image contains
An image declares the software that every host in a cluster, or one standalone host, should run, and “the base image is the only mandatory element”. The base image is the ESX image that comes with every ESX release. Server makers package their components, such as drivers and patches, as a vendor add-on. A firmware and drivers add-on needs the server maker’s hardware support manager, a vCenter plug-in whose “deployment method, entitlement and licensing” the server maker determines. Independent components add third-party software such as drivers; on GPU hosts, the NVIDIA vGPU Manager, a host driver, goes into the image as well, as our guide to GPUs in vSphere describes.
In vSphere 9.0, a composite image serves a cluster “that has hosts from different vendors or from the same vendor but different generations, family, or model”. Its images share the base image and solutions, while vendor and firmware add-ons may differ.
vLCM image vs baseline under vCenter 9
The table compares both methods under vCenter 9.0.
| TASK | BASELINES, VCENTER 9 | IMAGES |
|---|---|---|
| Patch 8.x hosts | allowed, with 8.x rollup bulletins | yes |
| Patch 9.x hosts | blocked | yes |
| Upgrade 8.x to 9.x | ISO upgrade blocked, ISO import removed | new base image, then remediation |
| New clusters and hosts | not possible: images by default | default |
| Firmware updates | not supported | firmware and drivers add-on |
| Hardware compatibility check | host-level check only | cluster and host level, against the Broadcom Compatibility Guide |
| Validate before applying | not supported | supported |
| Reuse elsewhere | same vCenter only, no export | export, also to another vCenter; Image Library |
| ESX Live Patching, DPU hosts | not supported | supported; DPU hosts only with images |
Broadcom KB 379388 and KB 419331, as read in October 2026; vSphere 9.0 Lifecycle Manager guide, comparison of images and baselines and host-level hardware compatibility checks (24 August 2026).
Eligibility checks before you convert a cluster
The image setup starts with an eligibility check. Three conditions stop the switch: a host that is not stateful, meaning it does not boot from a disk; a host below ESXi 7.0 under vCenter 8.0, or below 8.0 under vCenter 9.0; and VIBs of an unintegrated solution, which must be deactivated first. Warnings concern software outside the image. A standalone VIB whose component is in the depot has to be added to the image; an unknown VIB, with no component in the depot, has to be imported, or remediation deletes it. Broadcom also asks you to confirm with each third-party vendor “whether the respective solution works with vSphere Lifecycle Manager”.
A single image needs hosts from one hardware vendor. On vCenter 8.0, taking the image from a host also needs ESXi 7.0 Update 2 and vCenter 8.0 Update 3. Clusters with NSX need a connected NSX compute manager and a transport node profile (KB 445081, KB 447693). Take a file-based backup of vCenter just before the switch, after reading the rollback limits below; schedules and restores are in our guide to vCenter file-based backup and restore.
Depot content: download tokens, UMDS and offline bundles
An image can only use what the vLCM depot holds. KB 379388 says vLCM “will no longer be able to download updates from internet facing VMware by Broadcom public repositories”. The new address, per KB 390121, is a dl.broadcom.com URL with a per-customer download token, which “only users with the Product Administrator role” can create in the Broadcom Support Portal (KB 390098).
Without Internet access, content comes from the Update Manager Download Service (UMDS) or offline bundles. UMDS installs “only on Linux-based operating systems”, downloads components as well as legacy bulletins, and hands them over on portable media or through a web server. It needs the download token too; without it, the download jobs fail with “HTTP Error Code: 403” (KB 390123). Its version has to match vLCM (“vSphere Lifecycle Manager 9.0 is compatible and can work only with UMDS 9.0”), so UMDS is upgraded together with vCenter. Offline bundles, the ZIP files from Broadcom or the server maker, are imported into the depot, while “Starting with vCenter 9.0, Lifecycle Manager no longer supports importing ISO files” (KB 419331). For branch sites with limited connectivity to vCenter, a depot override points a cluster or standalone host at a local depot.
How to convert a cluster from baselines to an image
The order below is ours; the labels come from Broadcom’s 8.0 and 9.0 guides, updated between July and September 2026, and match the 9.1 guide of 29 September 2026.
- Import the base image of the hosts’ current build, the vendor add-on and the third-party components into the depot; register the hardware support manager if the image is to include firmware.
- Select the cluster, open the Updates tab and click Image (vCenter 8.0) or Image Setup (vCenter 9.0); the eligibility check runs first.
- Choose the source: a host’s image with Proceed with selected image (8.0) or Proceed with this image (9.0), a JSON file, an Image Library image on 9.0, or Set up image manually.
- Make the image match what runs today: ESXi Version, vendor add-on, firmware and drivers add-on, and the components under Show details and Add components.
- Click Validate, then Save; a compliance check follows, and on 9.0 the Step 2: Check Image Compliance card offers Check compliance.
- Click Finish image setup and confirm with Yes, finish image setup; from here the cluster stays on images.
- Run the remediation pre-check, remediate one selected host in a maintenance window, check it, then remediate the rest.
- Repeat the switch for every standalone host, vSAN witness hosts included, with Use image on host or a manual image.
Our VMware optimisation service modernises vSphere, vSAN and NSX in agreed maintenance windows, step by step, with a rollback plan at every stage. Tell us how many clusters still run on baselines and which server models each one holds.
Unable to convert a cluster from baseline to image: errors and fixes
Broadcom’s knowledge base documents these errors for vCenter 8.x or VCF 5.2 environments. KB 444420, whose title begins “Unable to convert cluster from baseline to vLCM image due to NSX-T validation error”, covers the first row; its full message begins “Cannot determine whether NSX-T Data Center is enabled on this cluster.”
| MESSAGE (EXCERPT) | CAUSE | FIX |
|---|---|---|
| “enable bidirectional trust” | an NSX-T extension still registered in vCenter after NSX Manager was decommissioned (KB 444420) | unregister the extension in the vCenter Managed Object Browser, then retry |
| “Transport Node Profile” | NSX compute manager disconnected, for example after an SSO password or certificate change (KB 445081) | reconnect vCenter in NSX under System, Fabric, Compute Managers; check the profile; retry |
| “checksum mismatch” | a VIB on the host, in Broadcom’s example a driver, differs from the depot copy (KB 419651) | set up the image manually instead of extracting it from a host |
| “Orphan vibs found” | the HA agent vmware-fdm is not part of the base image (KB 443602) | proceed; once the cluster uses an image, vCenter adds the agent back |
| “DRAFT_ | regular expressions or CIDR notation in vCenter’s NO_PROXY list; vCenter itself reports “Cannot download offline depot” (KB 446633) | domain suffixes and explicit IP addresses in the proxy file, then restart the proxy and vLCM services |
| “HTTP Error Code: 403” | vLCM still uses the old public depot addresses (KB 390121) | generate a download token and set the dl.broadcom.com depot URL |
Broadcom KB 444420, 445081, 419651, 443602, 446633 and 390121, as read in October 2026.
For the fix in KB 446633, sign in to the vCenter appliance as root over SSH, edit /etc/sysconfig/proxy, then run /etc/init.d/proxy restart and vmon-cli -r updatemgr.
VCF, mixed hardware, Supervisor and standalone hosts
In VCF, clusters and standalone hosts that SDDC Manager manages must switch “by SDDC Manager supported mechanisms only”. KB 385617 points to a PowerShell script, which Broadcom recommends, and the SDDC Manager API, both for VCF 5.2.2 and 9.0.x. The script’s README adds Supervisor clusters from VCF 9.0 and standalone hosts from 9.1. After SDDC Manager reaches 9.0, every cluster in the management and workload domains moves to images before ESX 9.0; where that is not possible, or where vSphere Supervisor is enabled, Broadcom places the switch after the vCenter upgrade and before the ESX upgrade.
On VCF 9.0.x, vCenter shows the banner “Transition from vLCM Baselines to vLCM Images in a VCF environment should be performed via SDDC manager only.” KB 422298 describes how to turn it off in SDDC Manager, for instance on VCF 9.1 greenfield installations, where it can appear although no cluster uses baselines. In a standard vCenter environment, KB 341192 says, “it is entirely safe to proceed with this transition”. The VCF Installer 9.0 refuses baseline clusters with “Cluster is not vSphere Lifecycle Manager (vLCM) image based” (KB 443265), which matters for the converge route in our VVF vs VCF comparison.
For mixed hardware, Broadcom’s 9.0 guide says “Such clusters must be upgraded to ESX 9.0 first, then converted to images, and managed with a composite image”, while vCenter 9 blocks ISO upgrades on baselines. KB 424294 gives two ways to lift the restriction on Update Manager for a time: a VCF PowerCLI script or a call from the API Explorer in vCenter’s Developer Center. The change lasts until “the service is restarted or the vCenter appliance is rebooted”, and after the ESX 9 upgrade Broadcom says to move these clusters to images “immediately”. Which hosts can run ESX 9 is in our ESX 9 hardware requirements guide. The vSAN witness host, serving one stretched cluster or up to 64 two-node clusters, is switched and upgraded like any other standalone host.
Our estate and licence audit takes a full inventory of your VMware estate: versions, subscriptions, actual resource usage and risk profile. Describe your vCenter instances and clusters in the form below, with SDDC Manager, NSX or Supervisor where they run.
After the conversion: compliance, remediation and rollback limits
Finishing the setup leaves the hosts as they are: “The mere action of changing the management method does not alter the hosts in the cluster or the standalone host.” The Image Compliance card then shows each host as compliant, non-compliant, incompatible (the image “cannot be applied to the host”) or unknown. Hosts are “remediated sequentially by default” and enter maintenance mode if the update requires it; a failed host stops the cluster’s remediation unless parallel remediation is configured. The first remediation deletes standalone VIBs and the agents of non-integrated solutions.
The cluster has no way back to baselines. If vCenter is restored from a backup taken before the switch, Broadcom’s 9.0 guide says the restored instance contains the cluster “but you must again use baselines to manage it”. A restore that predates an image upgrade leaves the hosts incompatible with the older image, and “Because you cannot downgrade ESX”, the fix is to raise the cluster image to what the hosts run. Export each image after the switch and take a new vCenter backup. vCenter 9.0 manages ESX 8.0 hosts (KB 424129), so an image-managed cluster can stay on an ESXi 8.0 Update 3 base image until its hosts are upgraded or replaced.
What we do
Eurokommerz holds the contract; engineering is by our partner Vixen.UNO. Under VMware optimisation, the switch from baselines to images is part of the modernisation of vSphere, vSAN, NSX and VCF, carried out in agreed maintenance windows with a rollback plan at every stage. The first call is free of charge; the paid technical assessment, its price fixed before work begins, delivers a report, a TCO and ROI model and an action plan ahead of renewal and end of support, with dates. After the project, support continues under an agreed SLA.
FAQ
How do I convert a vSphere cluster from baselines to a vLCM image?
Are vSphere Lifecycle Manager baselines deprecated in vSphere 9?
What is the difference between a vLCM image and a baseline?
Why am I unable to convert a cluster from baseline to image?
Can I switch a cluster back from a vLCM image to baselines?
How do I convert baseline clusters to images in VMware Cloud Foundation?
Send us your vCenter and ESXi builds, the clusters and standalone hosts still on baselines with the server vendor and model in each, and where NSX, vSAN, vSphere Supervisor or SDDC Manager run. We reply within one business day and arrange a first call, free of charge, from which you leave with 2 to 3 possible scenarios for the switch and the 9.x upgrade.
Talk to an expertWe reply within one business day