Unable to view and manage VKS Supervisor namespaces with VCF SSO users
search cancel

Unable to view and manage VKS Supervisor namespaces with VCF SSO users

book

Article ID: 446586

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service VMware Cloud Foundation

Issue/Introduction

  • When signed into a  workload vCenter with a VCF SSO user account, the Namespaces menu is missing from the inventory, and Supervisor resources (Namespaces, VMs) are not visible.
  • Supervisor VMs are not visible in the cluster inventory.
  • VCF SSO users with the 'VCF Administrator' role cannot manage Supervisor resources without manual permission

 

Environment

  • VMware Cloud Foundation 9.1.x
  • VMware vSphere Kubernetes Service
  • vCenter 9.x

Cause

An integration gap exists between the VCF 9.1 Identity Federation architecture and the Workload Control Plane permission synchronization mechanism. Federated VCF SSO Administrators map to a reserved group ([email protected]) which lacks explicit permissions on the root "Namespaces" folder. Because explicit child permissions override inherited permissions in vSphere, visibility for these users is blocked.

Resolution

This issue is a known defect.
 
The workaround is to add user/groups to Administrators group
  1. Log in to the vSphere Client as a local SSO administrator
  2. Navigate to Administration > Single Sign-On > Users and Groups > Groups.
  3. Select the Administrators group under the vsphere.local domain.
  4. Add your VCF SSO administrator group or the specific federated user accounts to this group.

Namespaces and Supervisor node now showing as expected.