After upgrading to VCF 9.1, configuration of the instanced VCF Single Sign-On (SSO) fails with the error: "An identity broker instance is not available for configuring Single Sign-On."
search cancel

After upgrading to VCF 9.1, configuration of the instanced VCF Single Sign-On (SSO) fails with the error: "An identity broker instance is not available for configuring Single Sign-On."

book

Article ID: 443943

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • After upgrading VMware Cloud Foundation (VCF) from version 9.0.x to 9.1.0, the Identity Broker component may not appear under Build > Lifecycle > VCF Management > Components in VCF Operations. In such cases, the Identity Broker component is manually added and deployed.
  • When trying to configure Instanced Single Sign-On (SSO) under Fleet Management > Identity & Access > VCF SSO Overview > Configure VCF SSO > Choose Deployment Mode, users may encounter the following error:
    "An identity broker instance is not available for configuring Single Sign-On. If the identity broker in instance mode has not been deployed, navigate to the Lifecycle page to initiate its deployment."
    Message stating: "No compatible VCF Instance".

  • "Eligible VIDB version" is blank for the Instanced VIDB as reported in  /storage/log/vcops/log/vcops-bridge<ID>.log in VCF Operations:
    YYYY-MM-DD INFO vcfops-bridge 5375 [ops@4413 threadId="####" threadName="ServerConnection on port 10000 Thread 55" operationId="##################"] [com.vmware.vcops.bridge.server.vidb.persistence.VidbCurrentIDPConfigService.getByVidbId] - Fetching the IDP config by the vidb id: ########-####-####-##############
    YYYY-MM-DD INFO vcfops-bridge 5375 [ops@4413 threadId="####" threadName="ServerConnection on port 10000 Thread 55" operationId="##################"] [com.vmware.vcops.bridge.server.vidb.vcf.VCFInstanceHelper.retrieveVersion] - Eligible VIDB version:

  • New CUSTOMER tenant is not created as part of the 9.1 VIDB component deployment confirming a stale record of the 9.0.x VIDB configuration.
    /storage/log/vcops/log/adapters/ManagementAdapter/ManagementAdapter.log
    YYYY-MM-DD ERROR ManagementAdapter 6192 [ops@4413 threadId="###" threadName="pool-17-thread-1" instanceId="####"] [(####) com.vmware.adapter.management.components.iam.state.impl.VCFIAMSettingsSyncHandler.updateConfig] - Failed to update IAM settings for endpoint <VIDB_FQDN>
    com.vmware.adapter.management.components.iam.exception.HttpResponseStatusException: API call https://<VIDB_FQDN>/acs/t/CUSTOMER/token failed with status 401 and error {"error":"invalid_client","error_description":"Client is not authorized to perform this operation."}

  • The embedded VIDB configuration remains available and can be configured successfully.

Environment

  • VMware Cloud Foundation (VCF) 9.1

Cause

This issue occurs because the SSH password for the VMSP service account had expired. As a result, Fleet Lifecycle Management was unable to complete the automated cleanup and import of the existing Identity Broker configuration from VCF 9.0.x during the upgrade process.

Resolution

To resolve this, clean up the stale VIDB component in VCF Operations and re-register the 9.1.0 Identity Broker. Open a ticket with Broadcom Support.