Unable to install supervisor services or change storage when the Supervisor Administrator role bound to a vSphere Client user
search cancel

Unable to install supervisor services or change storage when the Supervisor Administrator role bound to a vSphere Client user

book

Article ID: 430540

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

The Supervisor Administrator role is intended to give administrative controler over VKS supervisors. The role is intended to allow a user to perform various tasks, including assigning storage policies and installing services. However, when a user has the role assigned at the Namespaces folder and children objects, the EDIT STORAGE button in namespace view (in Supervisor Management) and the Add New Service button are not displayed or working.

Environment

VKS 9.x

Cause

This is a known condition with the Supervisor Administrator role, and will be modified in a future release of VKS 9.

 

Resolution

NOTE: Engineering is working to properly resolve the missing privileges. As a workaround, you can edit the Supervisor Administrator role to have the missing privileges and assign the role to root or as a global permission with propagate to children, however, please note this may lead to unintended control over the system. Please use the following workaround judiciously and with caution.

 

1) Edit the Supervisor Administrator role so that the following privileges are added to the role:

   - SupervisorServices.InstallSupervisorServices.Manage

   - Cns.Searchable

   - View storage policies.View VM storage policies

2) Right-click the root vCenter object in inventory and click "Add Permission".

3) Assign the desired user or group the Supervisor Administrator role and toggle "Propagate to children".

4) Click "OK".

 

Additional Information

Japanese KB: vSphere Clientのユーザにスーパーバイザー管理者ロールを割り当てた際に、スーパーバイザーサービスのインストールやストレージの変更ができない