SSP Deployment Fails during "Deploy Platform" Stage When Using Encrypted Storage Policies
search cancel

SSP Deployment Fails during "Deploy Platform" Stage When Using Encrypted Storage Policies

book

Article ID: 421318

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

During the SSP deployment, the process failed during the “Deploy Platform” stage with the following errors:

Failed 1/3 tasks: [Deploy platform] 20 deployments (authelia, authserver, cluster-api, common-agent, config-processing-service, debezium-onprem, druid-broker, druid-coordinator, druid-router, monitor, platform-ui-middleware, postgresql-ha-pgpool, pubsub, reputation-service, security-pov, sentinel, site-service, spark-job-manager-v2, telemetry, trust-manager), 9 statefulsets (app-discovery, druid-historical, fluentd, kafka-controller, minio, nsx-config-0, nsx-config-1, postgresql-ha-postgresql, redis-cluster), 1 daemonset (nsxi-platform-fluent-bit) failed

 

vCenter displayed repeated attach failures such as:

“Invalid configuration for device 0: An encrypted virtual disk device requires a key to be created on an encrypted VM.”

 

CSI controller pod logged several CNS/VSLM errors (k get pod -n vmware-system-csi) :

  • CnsFault / VSLM task failed
  • NotFound / AlreadyExists / NotRegistered
  • RPC errors during volume attach

Environment

SSP 5.0 , 5.1

Cause

When worker nodes are deployed with an encrypted storage policy, the following occurs:

  • CNS tries to attach dynamically created PV disks to worker nodes.
  • The worker VMs are not configured as encrypted VMs.
  • vCenter blocks the attach request because encrypted VMDKs require encrypted VMs.
  • CNS repeatedly attempts the attach and fails with VSLM and CnsFault errors.
  • This causes the entire SSP platform deployment to fail.

Resolution

(1) Use one of the supported options:

(a) Standard vCenter storage policy (non-encrypted)

(b) vSAN storage policy with Data-At-Rest encryption enabled
(Supported and recommended)

Link : deploy-installer-and-platform

 

(2) Redeploy SSP after applying the correct storage policy.