Service: tkg.vsphere.vmware.com
Reason: ReconcileFailed
Message: vendir: Error: Syncing directory '0': Syncing directory '.' with imgpkgBundle contents: Fetching image: Error while preparing a transport
to talk with the registry: Unable to create round tripper:
Get "https://depot.kube-system.svc/v2/": ForbiddenReason: ReconcileFailed. Message: vendir: Error: Syncing directory '0': Syncing directory '.' with imgpkgBundle contents: Fetching image: Error while preparing a transport to talk with the registry: Unable to create round tripper: Get "https://depot.kube-system.svc/v2/": dial tcp: lookup depot.kube-system.svc on 127.0.0.53:53: no such hostThis issue occurs for two different reasons:
(depot.kube-system.svc). Because this internal depot is not available or resolvable in older architectures, it results in registry authentication and name resolution failures.(projects.packages.broadcom.com).e.g., vsphere-kubernetes-service-legacy-3.6.2+v1.35.yaml): Points to the public 'projects.packages.broadcom.com' instance via its imgpkgBundle. This must only be used for vCenter versions 9.0 and lower, or within air-gapped vCenter 9.1 (or newer) environments.e.g., vsphere-kubernetes-service-3.6.2+v1.35.yaml): Points to the VCF Operations Software Depot via its imgpkgBundle. This must be used for internet-connected vCenter versions 9.1 and newer.
DO NOT USE THIS OPTION FOR VCF/VVF 9.1.0 NON-AIR-GAPPED ENVIRONMENTS
To resolve this issue, use the override-package-image.sh script to correct the image repository URL for the imgpkg bundle and force reconciliation.
Note: These steps are strictly for updating the registry reference for the same service version and should not be used for any rollbacks.
override-package-image.sh script is already present under the /usr/lib/vmware-wcp directory. For older versions, manually copy the provided script in this KB onto the Supervisor into the /usr/lib/vmware-wcp directory.If you manually copy the script, grant execution permissions by running the following command:chmod +x /usr/lib/vmware-wcp/override-package-image.sh
Retrieve the VKS package name by running the following command:kubectl get package -n vmware-system-supervisor-services | grep tkg | grep <target version>
Note the package name from the output (e.g., tkg.vsphere.vmware.com.3.6.2+v1.35).
Perform a dry-run of the script to preview the configuration updates. Replace the package name in the command below if yours differs:/usr/lib/vmware-wcp/override-package-image.sh -p <package name from the above command output> -i projects.packages.broadcom.com/vsphere/iaas/vsphere-kubernetes-service/3.#.#/vsphere-kubernetes-service:3.#.# --dry-run
[/usr/lib/vmware-wcp]# /usr/lib/vmware-wcp/override-package-image.sh -p tkg.vsphere.vmware.com.3.6.2+v1.35 -i projects.packages.broadcom.com/vsphere/iaas/vsphere-kubernetes-service/3.6.2/vsphere-kubernetes-service:3.6.2 --dry-run
/usr/lib/vmware-wcp/override-package-image.sh -p <package name from the above command output> -i projects.packages.broadcom.com/vsphere/iaas/vsphere-kubernetes-service/3.#.#/vsphere-kubernetes-service:3.#.#[/usr/lib/vmware-wcp]# /usr/lib/vmware-wcp/override-package-image.sh -p tkg.vsphere.vmware.com.3.6.2+v1.35 -i projects.packages.broadcom.com/vsphere/iaas/vsphere-kubernetes-service/3.6.2/vsphere-kubernetes-service:3.6.2
override-package-image.sh script can also be used to resolve ReconcileFailed errors for other Supervisor Services if the error indicates an inability to reach the image depot. When doing so, adjust the grep filter in the command from Step 3 of the Resolution to search for the specific package name you are troubleshooting.Script usage: To view the full usage instructions and available options for the script, run the following command with the -h flag:/usr/lib/vmware-wcp/override-package-image.sh -h
If the following error message returns when attempting to run the script, it indicates the script contains carriage returns (CRLF) that has to be removed in order for the script to run successfully./bin/bash^M: bad interpreter: No such file or directory
In order to resolve this error, run the following sed command to remove the CRLF carriage returns.sed -i 's/\r$//' /usr/lib/vmware-wcp/override-package-image.sh