Managing a vSphere With Tanzu workload cluster using a TMC Proxy Configuration Object with Custom root/CA certificate is Failing
search cancel

Managing a vSphere With Tanzu workload cluster using a TMC Proxy Configuration Object with Custom root/CA certificate is Failing

book

Article ID: 376801

calendar_today

Updated On:

Products

VMware vSphere 7.0 with Tanzu

Issue/Introduction

  • Managing a vSphere With Tanzu cluster workload cluster using a  Proxy Configuration Object with custom root/CA certificate is faling with error:

"This proxy has a custom root/CA certificate. This is only supported for Tanzu Kubernetes Grid Clusters and Attached Clusters are not supported for Tanzu Kubernetes Grid Service (TKGS) Clusters."

  • The workload cluster was created using a TanzuKubernetesCluster (TKC) base cluster with on of the following Provisioning API :
  • API Kind vCenter version
    v1alpha3 TanzuKubernetesCluster vCenter 8+
    v1alpha2 TanzuKubernetesCluster vCenter 7 U3
    v1alpha1 TanzuKubernetesCluster vCenter 7 U1, U2

 

Environment

VMware Tanzu Mission Control.

vSphere With Tanzu.

 

Cause

 

  • Managing/Creating a vSphere With Tanzu workload cluster using a  Tanzu Mission Control Proxy Configuration Object that include a Custom CA certificates is not supported, if the workload cluster was created using a TanzuKubernetesCluster (TKC) base cluster  

Resolution

Option 1:

  • Set your Proxy Server to not use SSL inspection.
  • Create the Tanzu Mission Control Proxy Configuration Object without  Custom root/CA certificate.
  • Manage/Create the vSphere With Tanzu  TanzuKubernetesCluster (TKC) base cluster using the Proxy Configuration Object.

Option 2:

  • Create a new vSphere With Tanzu  workload cluster with ClusterClass manifest with v1beta1 API
  • Supported in vCenter 8+.
  • Create the Tanzu Mission Control Proxy Configuration Object with Custom root/CA certificate.
  • Manage/Create the vSphere With Tanzu workload cluster.

Additional Information

Note: Other operations where  Tanzu Mission Control Proxy Configuration Object with CA certificates are not supported:

  • Registering a Supervisor in TMC for vSphere with Tanzu versions prior to vSphere 7.0.3.
  • Lifecycle management of Tanzu Kubernetes Grid Service clusters running in vSphere with Tanzu versions prior to vSphere 8.

See Create a Proxy Configuration Object Doc