1.The system prevents the "service-account-tango-blueprint-serviceaccount" from creating resources in VCFA namespace with below errorError creating resource: virtualmachineservices.vmoperator.vmware.com is forbidden: User "service-account-tango-blueprint-serviceaccount" cannot create resource "virtualmachineservices" in API group "vmoperator.vmware.com"
2.This catalog deployment previously succeeded prior to the removal of the external OIDC provider in VKS.
3.VCFA OIDC services generated a new identity provider when the old identity provider is removed in VKS, however the old OIDC client ID still exists in the supervisor rolebindings that can verify this by runningļ¼
kubectl describe rolebindings -n <VCFA namespace> <rolebinding name of VCFA account >
VMware Cloud Foundation Automation 9.0.2