The issue is observed after upgrade from 22.1.4 patch 2p7 to 30.2.2, The SE creation was failing despite of all permissions allowed on the Venter level.
Cloud: NSX-T, Vcenter
Version: Upgrade from 22.1.x to 30.2.x
We see that the managed object ID of the folder was saved in earlier versions, after upgrade we are trying to create folder with that managed object ID as folder name
The issue has been fixed on the following versions:
31.1.1, 22.1.7-2p4, 30.2.3
Workaround:
To immediately unblock the "User", we should explicitly update the affected SEGroups using Avi CLI and configure the exact folder name with path hierarchy would resolve this issue.
[admin:10-x-x-x]: > configure serviceenginegroup <SE-Group name>[admin:10-x-x-x]: serviceenginegroup> vcenters index 1[admin:110-x-x-x]: serviceenginegroup:vcenters> vcenter_folderAviSeFolder/NSXCloud/MySEGroupFolder| vcenters[1] | || vcenter_ref | vcserver || vcenter_folder | AviSeFolder/NSXCloud/MySEGroupFolder |