Cannot change the Management Network portgroup for an active Supervisor in VMware Cloud Foundation 9
search cancel

Cannot change the Management Network portgroup for an active Supervisor in VMware Cloud Foundation 9

book

Article ID: 431656

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • The system administrator needs to change the Management Network portgroup or VLAN for the Supervisor Control Plane after it has been deployed and activated in VMware Cloud Foundation (VCF) 9.
  • The user interface does not provide an option to modify the underlying Distributed Port Group (DVPG) or its associated IP subnet.

Environment

  • VMware Cloud Foundation (VCF) 9.x
  • vSphere Supervisor
  • VMware vSphere Kubernetes Service (VKS)

Cause

  • During the initial enablement phase, the Supervisor Control Plane VMs are statically bound to a specific Distributed Port Group (DVPG) and assigned an IP subnet.
  • Modifying the underlying Management Network portgroup and its associated IP block post-deployment is currently unsupported by the VCF/Supervisor architecture.

Resolution

To associate the Supervisor and its dependent VMware vSphere Kubernetes Service (VKS) components with a different Management Network portgroup or VLAN, the cluster must be redeployed. 

  1. Deactivate the Supervisor cluster.
    **Note:** This action removes the Control Plane VMs and destroys any running VKS clusters and associated workloads.
  2. Re-enable the Supervisor cluster using the target portgroup and new IP address allocation.

Additional Information

  • The Management Network portgroup is immutable post-deployment, other parameters such as DNS servers, NTP servers, and DNS search domains can be modified dynamically.
  • Additionally, Workload Networks (which provide networking for the VKS namespaces and Tanzu Kubernetes Grid clusters) can be added or modified without deactivating the Supervisor.