VCF Automation: Project user (OIDC) access to namespaces fails with "This namespace is not active" error
search cancel

VCF Automation: Project user (OIDC) access to namespaces fails with "This namespace is not active" error

book

Article ID: 441868

calendar_today

Updated On:

Products

VCF Automation

Issue/Introduction

  • Project administrators log in and see a warning banner: "This namespace is not active."
  • Under the Build and Deploy tab, only the "Overview" service is visible for the namespace, all other service options are missing.
  • Affected users are assigned to the project individually rather than via a group and are from an OIDC (OpenID Connect) Identity Provider
  • The same namespaces do not observe the issue when viewed by an Organization Administrator or by a user assigned via group.

Environment

VCF Automation 9.x

Cause

 VCF Automation Tenant Manager attempts to match users by either their full email address (including domain) or by a substring of the username (without domain). If the username is not part of the email address then the project assignment can not be resolved and causing this issue.

Resolution

To resolve this issue, reconfigure the OIDC mapping in the Identity Provider to ensure the username and email address fields match.

 

Workaround:  Assign users to the project via a Group rather than individual accounts. Group-based synchronization in the Tenant Manager resolves memberships differently and is not affected by individual username/email mismatches.