воскресенье, 7 мая 2023 г.

100 Active Directory terms

1. Active Directory (AD): Directory service for managing Windows-based networks and resources.
2. Domain Controller (DC): Server that hosts Active Directory services and authenticates users.
3. Forest: Highest level of logical grouping in Active Directory, containing one or more domains.
4. Domain: Logical group of network objects within an AD forest, sharing a common namespace.
5. Organizational Unit (OU): Container for organizing AD objects like users, groups, and computers.
6. Group Policy: Centralized management of settings and configurations for users and computers.
7. Group Policy Object (GPO): Collection of policy settings linked to OUs, domains, or sites.
8. Security Group: Group of users, computers, or other groups used for access control.
9. Distribution Group: Group used for email distribution in Microsoft Exchange environments.
10. Global Catalog (GC): Centralized index of AD objects, used for searches and logins.
11. LDAP: Lightweight Directory Access Protocol, used to access and manage AD information.
12. DNS: Domain Name System, resolves domain names to IP addresses, critical for AD functionality.
13. Sites: Represents physical locations in AD, helps optimize network traffic.
14. Subnet: IP address range associated with a specific site.
15. Site Link: Represents network connection between sites, used for replication traffic.
16. Replication: Process of synchronizing AD data across domain controllers.
17. FSMO: Flexible Single Master Operations, specialized roles held by DCs for specific tasks.
18. RID Master: Assigns unique relative IDs for new objects, one of the FSMO roles.
19. PDC Emulator: Emulates Primary Domain Controller, handles password changes and time sync.
20. Infrastructure Master: Maintains cross-domain references, one of the FSMO roles.
21. Domain Naming Master: Manages addition and removal of domains in a forest.
22. Schema Master: Controls updates to the AD schema, one of the FSMO roles.
23. Global Catalog Server: DC with a full copy of all objects in the forest.
24. Trust Relationship: Enables resource sharing and authentication between domains.
25. Kerberos: Authentication protocol used by AD to verify user and service identity.
26. Ticket Granting Ticket (TGT): Kerberos ticket for access to services within a domain.
27. Service Ticket: Kerberos ticket for a specific service.
28. SPN: Service Principal Name, uniquely identifies a service in a domain.
29. NTLM: NT LAN Manager, older authentication protocol used as a fallback for Kerberos.
30. SID: Security Identifier, unique identifier for security objects in AD.
31. RID: Relative Identifier, unique within a domain, combined with the domain SID to form a full SID.
32. USN: Update Sequence Number, used to track changes and replication in AD.
33. Tombstone: Deleted AD object that remains in the database for a specified period.
34. dcpromo: Deprecated utility for promoting and demoting domain controllers.
35. AD DS: Active Directory Domain Services, the main AD component for managing resources.
36. AD LDS: Active Directory Lightweight Directory Services, a lightweight AD variant.
37. AD FS: Active Directory Federation Services, enables single sign-on across applications.
38. AD RMS: Active Directory Rights Management Services, secures sensitive data.
39. GMSA: Group Managed Service Account, automates password management for service accounts.
40. Password policy: Configures password requirements and settings for users.
41. Fine-Grained Password Policy: Applies different password policies to specific users/groups.
42. CSVDE: Command-line tool for importing/exporting AD objects using CSV files.
43. LDIFDE: Command-line tool for importing/exporting AD objects using LDIF files.
44. REPADMIN: Command-line tool for diagnosing and managing replication in AD.
45. DCDIAG: Command-line tool for diagnosing and troubleshooting domain controller issues.
46. NLTEST: Command-line tool for testing domain trust relationships and locating DCs.
47. Ntdsutil: Command-line tool for managing AD databases, performing metadata cleanup, and more.
48. ADSI Edit: Graphical tool for managing AD objects and attributes at a low level.
49. Attribute Editor: Tab in the AD Users and Computers console for editing object attributes.
50. Group Policy Management Console (GPMC): Centralized interface for managing Group Policy.
51. Resultant Set of Policy (RSoP): Tool for analyzing the cumulative effect of applied GPOs.
52. Delegation of Control: Assigning limited administrative privileges to specific users or groups.
53. Read-Only Domain Controller (RODC): DC with read-only AD database, used in branch offices.
54. SYSVOL: Shared folder on DCs containing scripts, GPOs, and other AD-related files.
55. FRS: File Replication Service, deprecated replication technology for SYSVOL.
56. DFS-R: Distributed File System Replication, used for replicating SYSVOL in modern AD.
57. UPN: User Principal Name, user identifier format resembling an email address.
58. Netlogon: Service on DCs for authenticating users and handling domain-related tasks.
59. SAM: Security Accounts Manager, stores local user and group information on Windows systems.
60. Local Security Authority (LSA): Component responsible for enforcing security policies.
61. Security Token: Data structure containing user's security identifier and group memberships.
62. AD Recycle Bin: Feature for easily recovering accidentally deleted AD objects.
63. Active Directory Administrative Center (ADAC): Graphical management tool for AD.
64. PowerShell: Command-line scripting environment, with AD-specific cmdlets for management.
65. PSOs: Password Settings Objects, used to define fine-grained password policies.
66. Authentication Silos: Groups of users or computers with restricted authentication scope.
67. Shadow Groups: Dynamic groups that mirror the membership of another group or attribute.
68. Active Directory Users and Computers (ADUC): Management console for AD objects.
69. Domain functional level: Minimum domain controller OS version within a domain.
70. Forest functional level: Minimum domain controller OS version across all domains in a forest.
71. Active Directory Sites and Services: Management console for AD sites, subnets, and replication.
72. Schema: Set of rules defining AD object classes, attributes, and their relationships.
73. DirSync: Directory synchronization tool for syncing on-premises AD with Azure AD.
74. Azure AD Connect: Tool for integrating on-premises AD with Azure AD.
75. ADFS Proxy: Server that enables external access to AD FS for single sign-on.
76. Home Folder: Personal network storage location for users, typically mapped as a network drive.
77. Roaming Profiles: User profiles stored on a server, enabling consistent settings across devices.
78. Folder Redirection: Redirects user folders to network locations for centralized storage.
79. Universal Group: AD group type that can contain members from any domain in a forest.
80. Domain Local Group: AD group type that can have members from the same domain.
81. Global Group: AD group type that can contain members from its own domain only.
82. Security Principal: AD object that can be assigned permissions, such as users, groups, or computers.
83. Object Class: Defines a type of object in AD, such as user, group, or computer.
84. Object Attribute: Property of an AD object, such as name, description, or email address.
85. LDAP Query: Search filter used to locate specific objects or attributes in AD.
86. LDAPS: LDAP over SSL, a secure version of LDAP for encrypting communication with AD.
87. SACL: System Access Control List, defines auditing settings for AD objects.
88. DACL: Discretionary Access Control List, defines access permissions for AD objects.
89. ACE: Access Control Entry, individual permission entry in a DACL or SACL.
90. ACL: Access Control List, a collection of ACEs defining access permissions or audit settings.
91. Inheritance: Permission propagation from parent objects to child objects in AD hierarchy.
92. AGDLP: Account-Global-Domain Local-Permission, a best practice for granting permissions in AD.
93. AGUDLP: Account-Global-Universal-Domain Local-Permission, a best practice for multi-domain environments.
94. AAD: Azure Active Directory, Microsoft's cloud-based identity and access management service.
95. Hybrid Identity: Integration of on-premises AD and Azure AD for single sign-on and management.
96. Azure AD B2B: Business-to-business collaboration feature in Azure AD for external users.
97. Azure AD B2C: Business-to-customer identity management in Azure AD for customer-facing apps.
98. MFA: Multi-Factor Authentication, additional security layer requiring more than one verification method.
99. Conditional Access: Azure AD feature for enforcing access policies based on user context.
100. IdP: Identity Provider, a system responsible for authenticating and authorizing users.

100 VMware, vCenter and ESXi terms

1. vCenter Server: Centralized management platform for VMware vSphere environments.
2. ESXi: VMware's hypervisor, allowing virtualization of physical servers.
3. VM: Virtual machine, a virtualized computing environment.
4. vSphere: VMware's suite for managing virtualized data centers.
5. vMotion: Live migration of VMs between hosts without downtime.
6. DRS: Distributed Resource Scheduler, balances workloads across hosts.
7. HA: High Availability, restarts VMs on other hosts if a host fails.
8. SSO: Single Sign-On, central authentication for VMware products.
9. VUM: vSphere Update Manager, manages updates and patches for vSphere components.
10. vSAN: Virtual SAN, software-defined storage solution.
11. VDS: vSphere Distributed Switch, centralized network management for VMs.
12. vSwitch: Virtual switch, network switch for VMs on a host.
13. Resource pool: Group of VMs sharing resources like CPU and memory.
14. Datastore: Storage location for VM files, shared among hosts.
15. OVF: Open Virtualization Format, standard for packaging VMs.
16. Hot-add: Adding resources to a running VM without downtime.
17. Snapshot: Point-in-time copy of a VM's state.
18. Templates: Pre-configured VMs for fast deployment.
19. vApp: Container for managing multiple VMs with shared configurations.
20. VCHA: vCenter High Availability, protects vCenter Server against failures.
21. VAMI: vSphere Appliance Management Interface, manages vCenter Server Appliance.
22. Host profile: Configuration template for ESXi hosts.
23. Auto Deploy: Automates deployment of ESXi hosts using PXE boot.
24. VMFS: Virtual Machine File System, filesystem for storing VMs.
25. NFS: Network File System, file sharing protocol for datastores.
26. Fault Tolerance: Provides continuous availability by running two synchronized VMs.
27. vSphere Replication: VM replication for disaster recovery.
28. Storage vMotion: Live migration of VM storage without downtime.
29. VAAI: vSphere APIs for Array Integration, offloads storage tasks to storage arrays.
30. VASA: vSphere APIs for Storage Awareness, enables storage visibility and management.
31. EVC: Enhanced vMotion Compatibility, allows vMotion between hosts with different CPUs.
32. VCAP: vSphere Client plug-in, extends vCenter functionality with third-party applications.
33. Proactive HA: Predictive High Availability, relocates VMs based on hardware health alerts.
34. vSphere Lifecycle Manager: Simplifies lifecycle management for vSphere infrastructure.
35. Content Library: Centralized repository for VM templates, ISO images, and scripts.
36. Linked Mode: Connecting multiple vCenter Servers for centralized management.
37. VMkernel: Operating system layer of ESXi, responsible for resource management.
38. vSphere Web Client: Browser-based interface for managing vSphere environments.
39. vSphere Client (HTML5): Modern, HTML5-based interface for managing vSphere environments.
40. Storage I/O Control: Balances storage I/O resources among VMs on shared storage.
41. Network I/O Control: Balances network I/O resources among VMs and system traffic.
42. Storage DRS: Storage Distributed Resource Scheduler, balances storage capacity and I/O.
43. VADP: vSphere APIs for Data Protection, enables third-party backup and recovery solutions.
44. Affinity rules: Define VM placement preferences to improve performance or availability.
45. Alarms: Monitors and alerts for vSphere components based on predefined conditions.
46. Permissions: Control access to vSphere components through user and group roles.
47. Tags: Metadata for organizing and searching vSphere objects.
48. Custom attributes: Custom metadata fields for annotating vSphere objects.
49. VM-Host affinity rules: Define VM-host placement preferences for better resource utilization.
50. Nested virtualization: Running a VM inside another VM, typically for lab or testing purposes.
51. VIB: vSphere Installation Bundle, a package containing drivers or software for ESXi.
52. Paravirtualization: Technique to improve VM performance by using specialized virtual hardware.
53. vGPU: Virtual Graphics Processing Unit, sharing physical GPU resources among VMs.
54. NIOC: Network I/O Control, prioritizes and allocates network resources for VMs.
55. Admission Control: Ensures sufficient resources are available for VM failover in HA clusters.
56. VMCI: Virtual Machine Communication Interface, allows fast communication between VMs and hosts.
57. DPM: Distributed Power Management, powers hosts on/off based on resource demand.
58. Storage Profiles: Define storage capabilities and requirements for VM placement.
59. Storage Policy-Based Management: VM storage provisioning based on defined policies.
60. VM Encryption: Protects VM data by encrypting VM files at rest.
61. Instant Clone: Rapidly creates VM copies without the need for full clones.
62. vSphere Trust Authority: Enhances security by establishing a trusted relationship with hosts.
63. Secure Boot: Ensures only digitally signed software runs on ESXi hosts and VMs.
64. Per-VM EVC: Enables EVC at the VM level, allowing migration across different CPU generations.
65. Resource allocation settings: Configure shares, reservations, and limits for VM resources.
66. Transparent Page Sharing: Memory-saving technique by sharing identical memory pages.
67. Memory Ballooning: Reclaims unused memory from VMs to allocate to others.
68. CPU Ready: Metric indicating a VM's CPU time waiting to be scheduled.
69. Lockstep: Technique used by Fault Tolerance to keep primary and secondary VMs in sync.
70. Image Builder: Creates custom ESXi images by adding or removing VIBs from base images.
71. SCSI Reservation: Lock mechanism for coordinating access to shared storage resources.
72. LUN Masking: Restricts access to storage LUNs for specific hosts.
73. iSCSI: Internet Small Computer System Interface, IP-based protocol for storage area networks.
74. RDM: Raw Device Mapping, direct access to a physical storage device from a VM.
75. Thin Provisioning: Allocates storage space to VMs on-demand, conserving storage resources.
76. Thick Provisioning: Allocates entire storage space to VMs upfront, improving performance.
77. IOPS: Input/Output Operations Per Second, measures storage performance.
78. Latency: Time delay between a storage request and response, impacts performance.
79. NUMA: Non-Uniform Memory Access, optimizes memory access in multi-processor systems.
80. vNUMA: Virtual NUMA, exposes NUMA architecture to VMs for performance optimization.
81. DVS Health Check: Monitors vSphere Distributed Switch configuration for consistency.
82. LACP: Link Aggregation Control Protocol, combines multiple network links for redundancy.
83. Port Group: Logical grouping of network ports on a vSwitch or VDS.
84. PVLAN: Private VLAN, isolates VM network traffic within the same VLAN.
85. VXLAN: Virtual Extensible LAN, overlay network that extends Layer 2 across Layer 3.
86. SR-IOV: Single Root I/O Virtualization, enables direct access to physical network devices.
87. NSX: VMware's network virtualization and security platform.
88. vSphere Integrated Containers: Runs containerized applications natively on vSphere infrastructure.
89. Virtual Hardware Version: Represents the virtual hardware features available to a VM.
90. VMware Tools: Suite of utilities to enhance VM performance and management.
91. vSphere SDK: Software Development Kit for building custom applications for vSphere.
92. OVA: Open Virtual Appliance, a single file package of an OVF.
93. vRealize Operations: Performance monitoring and capacity management for vSphere environments.
94. vRealize Log Insight: Log analytics and troubleshooting tool for vSphere.
95. vRealize Automation: Automates provisioning and management of applications and infrastructure.
96. vCloud Director: Manages and provisions multi-tenant cloud resources.
97. vCloud Suite: Integrated set of VMware's cloud management tools.
98. vSphere ROBO: Remote Office Branch Office, simplifies management of remote sites.
99. vSphere Essentials Kit: All-in-one solution for small businesses, includes core vSphere features.
100.vSphere Standard/Enterprise/Enterprise Plus: Different editions of vSphere with varying features.

вторник, 21 февраля 2023 г.

Extract ESXi iDrac and BIOS versions and their IPs with PowerCLI

 cls

$viserver = "vCenter"

$User = "USER"

$Pass = "PASSWORD"

Disconnect-VIServer * -Confirm:$false -ErrorAction SilentlyContinue | Out-Null

$UnsortedVMHosts = (Get-VMHost).name

$VMHostNames = $UnsortedVMHosts | sort #  | select -First 3

$Array = @()

Write-Host


foreach($ESXiName in $VMHostNames)

    {

    Connect-VIServer -Server $viserver -User $User -Password $Pass

    $OneLineArray = New-Object "PSCustomObject"

    

    $ESXiName

    $VMHost = Get-VMHost $ESXiName

    $VMView = $VMHost | Get-View

    $BiosInfo = $VMView.Hardware.BiosInfo

        

    $Vendor = $VMHost.ExtensionData.Hardware.SystemInfo.Vendor

    $Model = $VMHost.ExtensionData.Hardware.SystemInfo.Model

    $BiosVersion = $BiosInfo.BiosVersion

    $ReleaseDate = $BiosInfo.ReleaseDate

    $EsxIP = (Get-VMHostNetworkAdapter -VMHost $VMHost -VMKernel -Name vmk0).IP

    $EsxiVer = $VMHost.ExtensionData.Config.Product.FullName

    $vCenter = $VMHost.ExtensionData.Client.ServiceContent.About.FullName


    Disconnect-VIServer * -Confirm:$false -ErrorAction SilentlyContinue

    Connect-VIServer -Server $ESXiName -User root -Password "PASSWORD" # | Out-Null

    Connect-VIServer -Server $ESXiName -User Administrator -Password "PASSWORD" # | Out-Null

    $esxcli = Get-EsxCli -VMHost $ESXiName -V2

    $iDracIP = $esxcli.hardware.ipmi.bmc.get.Invoke().IPv4Address

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "ESXiName" -Value $ESXiName

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "Vendor" -Value $Vendor

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "Model" -Value $Model

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "BiosVersion" -Value $BiosVersion

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "ReleaseDate" -Value $ReleaseDate

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "EsxIP" -Value $EsxIP

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "iDracIP" -Value $iDracIP

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "EsxiVer" -Value $EsxiVer

    $OneLineArray | Add-Member -MemberType NoteProperty -Name "vCenter" -Value $vCenter

    $Array += $OneLineArray

    }

$Array | OGV -Title "ESXi Hosts"

$Array | Export-Csv "C:\Temp\ESXiHosts-report.csv" -NoTypeInformation -UseCulture

ii "C:\Temp\report.csv"

    

Import VMs from vCenter to vCloud vApp with PowerCLI

cls

#  Import VMs from vCenter to vCloud vApp with PowerCLI

$SourceFolder = "SOURCE"

$DestVApp = "DEST_VAPP"

$VIserver = 'VCENTER.DOMAIN.COM"

$CIserver = 'VCLOUD.DOMAIN.COM"

$UVI = "VCENTER_USER"

$PVI = "VCENTER_PASSWORD"

$UCI = "VCLOUD_USER"

$PCI = "VCLOUD_PASSWORD"

Disconnect-VIServer * -Confirm:$false -ErrorAction SilentlyContinue | Out-Null

Connect-VIServer -Server $VIserver -User $UVI -Password $PVI

Disconnect-CIServer * -Confirm:$false -ErrorAction SilentlyContinue

Connect-CIServer -Server $CIserver -User $UCI -Password $PCI

$VMs = Get-Folder $SourceFolder | Get-VM | sort 

$CIvappObj = Get-CIVApp $DestVApp

foreach ($VM in $VMs) 

    {

    $VM.name

    $CIvappObj | Import-CIVApp -VM $vm -NoCopy:$False -RunAsync -Confirm $false

    }


среда, 1 февраля 2023 г.

wget-in-Windows

Sometimes we want to use Linux command in Windows.

One of them is wget - an easy way to download sites and pages from the Internet.
There is also cURL.

Do we have them in Windows?
Natively, no, but...

The 1st way - PowerShell has command Invoke-WebRequest.

# Using PowerShell for getting a Google page:
Invoke-WebRequest http://www.google.com/ -OutFile c:\google.html
# or
Invoke-WebRequest http://www.google.com/ | -OutFile c:\google.html

# Using wget as an alias for Invoke-WebRequest (not a real wget)
wget http://www.google.com/ -OutFile c:\google.html
wget http://www.google.com/ | -OutFile c:\google.html

# Showing the results
ii c:\google.html

The 2nd way - we can install wget as a regular program - as an exe file or with Chocolatey.
Chocolatey is an extremely powerful tool with a large range of features and options.
Here is a good site about Chocolatey:
https://howchoo.com/chocolatey/install-pc-programs-using-powershell-and-chocolatey

Let's see the installation with Chocolatey.

# First install Chocolatey with PowerShell (what you see is one long line in PowerShell):
Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))

This will tell your system to download Chocolatey from the web and install it.
You can upgrade Chocolatey itself by running this command:
choco upgrade chocolatey



Then you can install wget with Chocolatey from PowerShell or even from a regular CMD.
choco install wget

# Use wget to pull a website to your local machine
wget --mirror --convert-links --adjust-extension --page-requisites c:\google.html





Installing Chocolatey

Chocolatey is a program or method for installing packages/programs/application in Windows in the simple way.

For installing Chocolatey we need to use PowerShell command:

 Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))

All this is one long line.



четверг, 7 июля 2022 г.

Deleting Entry in vCloud PostgreSQL

If you're familiar with vCloud Director, you know that occasionally there can be stubborn, outdated entries. This happens when a VM, vApp, or template won't respond to the standard GUI methods. When this happens, many people turn to the VMware helpdesk for assistance. However, did you know that you can tackle this issue yourself, even if you're not a DBA? All you need is to take a backup or snapshot of the vCloud VM and make a backup of the Postgre DB with SSH/CLI. So, let's dive in!

1. First go in the GUI to the VM and take IDs of vApp and VM.

VM
e8b68b96-8c8a-4e2c-bf35-17ddc534e451
vApp
a893f027-6bee-4e54-8125-b09c04319c72

2. First enter to the vCloud PhotonOS with SSH (putty, MobaXterm).


4. Then enter to vCloud PostgreSQL with this command:
sudo -i -u postgres psql vcloud
(where postgres is a user, and vcloud is a DB)


5. =Deleting VM=
VM id: e8b68b96-8c8a-4e2c-bf35-17ddc534e451

delete from vapp_vm where id = ' 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451'';
XXX
ERROR:  update or delete on table "vapp_vm" violates foreign key constraint "fk_vap_vm_scl_me2vapp_vm" on table "vapp_vm_sclass_metrics"
DETAIL:  Key (id)=(ac706161-1b79-4a41-a2d8-abfff0754758) is still referenced from table "vapp_vm_sclass_metrics".

We need to delete the VM from the referenced table vapp_vm_sclass_metrics, 
instead of id we will use vapp_vm_id.
select * from vapp_vm_sclass_metrics where vapp_vm_id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';
delete from vapp_vm_sclass_metrics where vapp_vm_id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';

delete from vapp_vm where id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';

Again we have referenced table

select * from guest_personalization_info where vapp_vm_id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';

delete from guest_personalization_info where vapp_vm_id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';


delete from vapp_vm where id = 'e8b68b96-8c8a-4e2c-bf35-17ddc534e451';

In GUI

We see that there is no VM, but again we cannot to delete the vApp.
Success for VM, but still not for vApp.

6. =VAPP=

We are taking vApp id: 'a893f027-6bee-4e54-8125-b09c04319c72'

https://vcloud.algotec.co.il/tenant/support/vdcs/7f306f1b-a035-4015-81d8-d3783b5a3128/vapp/vapp-a893f027-6bee-4e54-8125-b09c04319c72/vcd-vapp-vms

Now we can work with sg_id, which is more relaible than a name.

select * from vm_container where sg_id='a893f027-6bee-4e54-8125-b09c04319c72';
We see the vApp still exists:


Now we will try to delete the vApp.
delete from vm_container where sg_id = 'a893f027-6bee-4e54-8125-b09c04319c72';


We cannot delete the vApp because of another table that contains vApp id - "vapp_logical_resource".
Let's go there.
select * from vapp_logical_resource where vapp_id='a893f027-6bee-4e54-8125-b09c04319c72';


Now deleting.
delete from vapp_logical_resource where vapp_id='a893f027-6bee-4e54-8125-b09c04319c72';


Good, let's check in DB.
select * from vapp_logical_resource where vapp_id='a893f027-6bee-4e54-8125-b09c04319c72';


Now we return back to the original place in trial to delete the vApp.
First, little check:
select * from vm_container where sg_id='a893f027-6bee-4e54-8125-b09c04319c72';
Now the actual deleing:
delete from vm_container where sg_id='a893f027-6bee-4e54-8125-b09c04319c72';


Seems we have deleted the vApp!..., but let's check that it is a real thing:
select * from vm_container where sg_id='a893f027-6bee-4e54-8125-b09c04319c72';

Now we sure it is deleted, but let's check in GUI too:


Bravo!