Reason: ReconcileFailed. Message: kapp: Error: waiting on reconcile deployment/cci-service (apps/v1) namespace: svc-cci-service-domain-c#: Finished unsuccessfully (Deployment is not progressing: ProgressDeadlineExceeded (message: ReplicaSet "cci-service-<ID>" has timed out progressing.)).
Cannot complete the operation. See the event log for details. Error downloading plug-in. URL is unreachable. status code: 502, reason phrase: Bad Gateway
The Consumption Interface installation files are downloaded from projects.packages.broadcom.com from your vSphere Supervisor's Workload network. If your Workload network is unable to communicate with projects.packages.broadcom.com over HTTPS (port 443) for any reason, the installation of the Consumption Interface will fail. Some reasons include:
Allow the vSphere Supervisor Workload network to connect to the following domain names over HTTPS (port 443):
If the Consumption Interface is an error state when networking changes above are put in place, you will need to perform the following steps to get the Consumption Interface service into a Configured state:
To verify this issue:
[timestamp] time="[timestamp]" level=info msg="trying next host" error="failed to do request: Head \"https://projects.packages.broadcom.com/v2/vcf_cci_service/###-#########-##-#######/manifests/sha256:XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\": dial tcp ##.###.###.##:443: i/o timeout" host=projects.packages.broadcom.com
Note that the IP address referenced in guest.log may change so firewall rules must be based on the domain names in the Resolution and not IP addresses.