The installation of the Supervisor Management Proxy Service version 0.4.1 fails during the image verification or reconciliation stage.
On the vSphere Client UI following error message is displayed:
Supervisor encountered an error while trying to reach the container image registry hosting Service Version 0.4.1 and its signatures cannot be verified: Connectivity to image
depot.kube-system.svc/vcf/supervisor-service-supervisor-management-proxy/ga/0.4.1/supervisor-management-proxy-bundle:0.4.1 cannot be verified: Get "https://depot.kube-system.svc/v2/": dial tcp: lookup depot.kube-system.svc on ##.##.##.##:53: no such host Please check that the container image registry is configured properly and can be reached from the Supervisor's network.
Running unverified services on user workloads has security risks. An unverified service has network access to user workloads, vSphere Pods, and exposed APIs.
In /varlog/vmware/wcp/wcpsvc.log shows the below events :
YYYY-MM-DDThh:mm:ss.270Z debug wcp [appplatform/kube_supervisor_service_version_carvel.go:350] [opID=6a062f4f] package signature is not trusted for serviceID supervisor-management-proxy.vmware.com, version 0.4.1 with message [{ERROR 0xc004b4d450} {ERROR 0xc004b4d4a0}]
YYYY-MM-DDThh:mm:ss.270Z error wcp [appplatform/clustersupervisorservices.go:145] [opID=6a062f4f] failed to create supervisor service supervisor-management-proxy.vmware.com version 0.4.1 on cluster domain-c4776: Service supervisor-management-proxy.vmware.com version 0.4.1 is not a trusted service published by Broadcom and cannot be placed on the system VPC.
In supervisor, the vmware-system-appplatform-operator-system_vmware-system-appplatform-operator-mgr pod logs shows the below events:
YYYY-MM-DDThh:mm:ss.411517373Z stderr F E0522 hh:mm:ss.411457 1 controller.go:329] "msg"="Reconciler error" "error"="failed to verify images in Package: Connectivity to image depot.kube-system.svc/vcf/supervisor-service-supervisor-management-proxy/ga/0.4.1/supervisor-management-proxy-bundle:0.4.1 cannot be verified: Get \"https://depot.kube-system.svc/v2/\": dial tcp: lookup depot.kube-system.svc on ##.##.##.##:53: no such host" "controller"="carvelpackage-controller" "name"="supervisor-management-proxy.vmware.com.0.4.1" "namespace"="vmware-system-supervisor-services" "object"={"name":"supervisor-management-proxy.vmware.com.0.4.1","namespace":"vmware-system-supervisor-services"} "reconcileID"="273e3e09-0d42-4b94-945f-############"
YYYY-MM-DDThh:mm:ss.318459971Z stderr F E0522 hh:mm:ss.318388 1 image_verifier.go:124] "msg"="failed to get signed image reference" "error"="Get \"https://depot.kube-system.svc/v2/\": dial tcp: lookup depot.kube-system.svc on ##.##.##.##:53: no such host" "image"="depot.kube-system.svc/vcf/supervisor-service-supervisor-management-proxy/ga/0.4.1/supervisor-management-proxy-bundle:0.4.1" "logger"="image-verifier"
YYYY-MM-DDThh:mm:ss.323779673Z stderr F I0522 hh:mm:ss.323716 1 syncer.go:83] "msg"="Failed to verify images in Package" "logger"="signatureverification" "message"="Connectivity to image depot.kube-system.svc/vcf/supervisor-service-supervisor-management-proxy/ga/0.4.1/supervisor-management-proxy-bundle:0.4.1 cannot be verified: Get \"https://depot.kube-system.svc/v2/\": dial tcp: lookup depot.kube-system.svc on ##.##.##.##:53: no such host" "name"="supervisor-management-proxy.vmware.com.0.4.1"
The Supervisor Management Proxy Service version 0.4.1 is strictly incompatible with vCenter Server 9.0.2.0. Version 0.4.1 requires vSphere 9.1.0 or later. The incompatibility causes the package signature trust to fail, which incorrectly surfaces in the UI as a registry connectivity error.
Install the compatible service version of Supervisor Management Proxy i.e. version 0.4.0, which is compatible with vSphere 9.0.1 and 9.0.2.0.
Supervisor Services | vSphere Supervisor Services
Compatible versions based on the vSphere environment: