Visibility and Grouping of System Organizations in Tanzu Hub
search cancel

Visibility and Grouping of System Organizations in Tanzu Hub

book

Article ID: 445080

calendar_today

Updated On:

Products

VMware Tanzu Platform Core VMware Tanzu Platform - Hub

Issue/Introduction

Users or administrators may notice that system-level organizations (such as systemp-spring-cloud-gateway-service, or p-spring-cloud-services) are treated differently than standard tenant organizations in Tanzu Hub. Specifically:

  • Questions regarding whether these orgs can be included in Organization Groups.
  • Concerns that system orgs might be missing from the UI after "Group Simplification" updates.
  • Inability to manage or push applications to these specific organizations.

Cause

Initially, product architecture and management decided to exclude system organizations from logical groups because they are not intended for user management (editing, deleting, or application deployment).

However, with the implementation of Group Simplification in the Tanzu Hub UI—where the interface primarily displays groups rather than individual member orgs—excluding them would cause these critical system orgs to be omitted from the view entirely.

Resolution

System organizations are now included in organization groups to ensure they remain visible and accessible for monitoring within the Tanzu Hub.

Key Characteristics of System Orgs in Groups:

  1. Visibility: System orgs are included in groups so they appear in the Hub UI. Without this grouping, they would be filtered out of the standard management views.
  2. Read-Only Status: While visible, these orgs remain read-only. Users cannot modify the org properties, delete them, or manage their underlying infrastructure via the Hub UI.
  3. Application Restrictions: Security and architecture policies prevent customer applications from being pushed to these system orgs. They are reserved exclusively for platform services.
  4. Show/Hide Toggle: In newer versions of the platform (after 10.4), system orgs may be hidden by default to reduce clutter. Authorized administrators can use a visibility toggle within the UI to reveal these orgs when needed.

Subscribe to this article for updates on progress.

Additional Information

This behavior was confirmed through engineering discussions involving PM and Architecture to balance the need for a simplified UI with the requirement for platform transparency. System orgs must be part of the "group" logic to satisfy the UI's data model.

Categories: Administration, Configuration, User Interface