Creating Auto Scale Group fails with error "The access to the resource metadata_item with id statsFeederCollectorJob.repeat.interval.seconds is forbidden" in VMware Cloud Director
search cancel

Creating Auto Scale Group fails with error "The access to the resource metadata_item with id statsFeederCollectorJob.repeat.interval.seconds is forbidden" in VMware Cloud Director

book

Article ID: 436594

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • In the VMware Cloud Director Tenant Portal, attempting to create a new Auto Scale Group fails.
  • The UI may display a blank screen or a generic error.
  • Reviewing the Chrome Developer Tools (F12) Network tab shows a 403 Forbidden error on a request related to metadata_item.
  • The error message in the response body contains: "The access to the resource metadata_item with id statsFeederCollectorJob.repeat.interval.seconds is forbidden"

Environment

VMware Cloud Director 10.6.x

Cause

This issue occurs because the required VMWARE:SCALEGROUP rights bundle has not been published to the tenant, or the tenant user lacks the necessary permissions to access the underlying scale group metadata settings.

Resolution

Resolution To resolve this issue, perform the following steps as a System Administrator:

  1. Publish the Auto Scale Entitlement Bundle: Ensure the VMWARE:SCALEGROUP rights bundle is published to the specific tenant organization.

    Log in to the VCD Provider Portal.
    Navigate to Resources > Tenants.
    Select the affected Organization and click Rights Bundles.
    Ensure the Auto Scale rights bundle is assigned/published.
    Reference: Publish the Auto Scale Rights Bundle

    https://techdocs.broadcom.com/us/en/vmware-cis/cloud-director/vmware-cloud-director/10-6/vmware-cloud-director-service-provider-portal-guide-10-6/managing-system-settings-admin/auto-scale-groups-admin/publish-the-auto-scale-rights-bundle-admin.html

  2. Assign Rights to Tenant User: Ensure the user has the appropriate roles within the organization.
    Navigate to the Organization Administrator roles for that tenant.
    Assign the VMWARE:SCALEGROUP rights to the role used by the tenant user.
    Verify the user is using a role that includes these newly added rights.
  3. Create Auto Scale Group again.

Additional Information

System administrator andorganization administrator roles have full control over the VMs in the scale groups. The other global tenant roles can view the VMs and access the VM Web Console but cannot delete, edit, perform power operations, and so on.

https://techdocs.broadcom.com/us/en/vmware-cis/cloud-director/vmware-cloud-director/10-6/map-for-vmware-cloud-director-tenant-portal-guide-10-6/working-with-virtual-machines-tenant/auto-scaling-groups-tenant.html#GUID-C179B853-709B-455D-94CA-2D5159D70A49-en