VCF Operations HCX 9.1 installation is failing with the error "Failed to create role in vCenter"
search cancel

VCF Operations HCX 9.1 installation is failing with the error "Failed to create role in vCenter"

book

Article ID: 448265

calendar_today

Updated On:

Products

VCF Operations VMware HCX

Issue/Introduction

  • Installation of VCF Operations HCX 9.1 fails with the error in VCF Operations :

Message: Failed to create role in vCenter <vCenter_FQDN>

Remediation Message:

Reference Token: ######

Cause: Failed to create role HCX to vCenter Service Account Role in vCenter <vCenter_FQDN> Error while creating role HCX to vCenter Service Account Role A specified parameter was not correct: privIds

  • On SDDC Manager, /var/log/vmware/vcf/domainmanager/domainmanager.log : 

    YYYY-MM-DDTHH:MM:SSZ DEBUG [vcf_dm,################################,####] [c.v.e.s.v.contract.CreateVcRoles,dm-exec-####]  Progress message added: Create user role HCX to vCenter Service Account Role with privileges VirtualMachine.Config.AddRemoveDevice, VirtualMachine.Inventory.Delete, VApp.Suspend, Network.Delete, Sessions.TerminateSession, Resource.QueryVMotion, Folder.Create, VirtualMachine.Provisioning.Clone, Datastore.UpdateVirtualMachineMetadata, VirtualMachine.State.CreateSnapshot, VirtualMachine.Provisioning.FileRandomAccess, Network.Move, VirtualMachine.Config.Annotation, VirtualMachine.Config.RawDevice, VirtualMachine.Config.ToggleForkParent, VirtualMachine.Namespace.ModifyContent, Resource.CreatePool, VirtualMachine.Interact.SetCDMedia, Global.Licenses, DVSwitch.Vspan, Profile.Delete, VirtualMachine.DataSets.DataSetEntryGet ... in cluster <vCenter_FQDN>
    YYYY-MM-DDTHH:MM:SSZ ERROR [vcf_dm,################################,####] [c.v.e.s.c.c.v.vsphere.VcManagerBase,dm-exec-####]  Error while creating role HCX to vCenter Service Account Role
    com.vmware.vim.binding.vmodl.fault.InvalidArgument: A specified parameter was not correct: privIds
            at java.base/jdk.internal.reflect.DirectConstructorHandleAccessor.newInstance(DirectConstructorHandleAccessor.java:62)
    YYYY-MM-DDTHH:MM:SSZ ERROR [vcf_dm,################################,####] [c.v.e.s.v.contract.CreateVcRoles,dm-exec-####]  Failed to configure roles in vCenter <vCenter_FQDN>
    YYYY-MM-DDTHH:MM:SSZ ERROR [vcf_dm,################################,####] [c.v.e.s.o.model.error.ErrorFactory,dm-exec-####]  [UNAA7O] CREATE_ROLE_FAILED Failed to create role  in vCenter <vCenter_FQDN>
    com.vmware.evo.sddc.orchestrator.exceptions.OrchTaskException: Failed to create role  in vCenter <vCenter_FQDN>
            at com.vmware.evo.sddc.vsphere.contract.CreateVcRoles.execute(CreateVcRoles.java:61)
            at com.vmware.evo.sddc.vsphere.contract.CreateVcRoles.execute(CreateVcRoles.java:23)
    Caused by: com.vmware.evo.sddc.orchestrator.exceptions.OrchTaskException: Failed to create role HCX to vCenter Service Account Role in vCenter <vCenter_FQDN>
            at com.vmware.evo.sddc.vsphere.contract.CreateVcRoles.createRole(CreateVcRoles.java:100)
    Caused by: com.vmware.evo.sddc.common.client.vmware.vsphere.VsphereOperationException: Error while creating role HCX to vCenter Service Account Role
            at com.vmware.evo.sddc.common.client.vmware.vsphere.VcManagerBase.createRole(VcManagerBase.java:12139)
    Caused by: com.vmware.vim.binding.vmodl.fault.InvalidArgument: A specified parameter was not correct: privIds

  • On vCenter Server (VCSA), /var/log/vmware/vpxd/vpxd.log :

    YYYY-MM-DDTHH:MM:SSZ error vpxd[#####] [Originator@6876 sub=Default opID=########] [VpxLRO] -- ERROR lro-######## -- ########-####-####-####-############(########-####-####-####-############) -- AuthorizationManager -- vim.AuthorizationManager.addRole: :vmodl.fault.InvalidArgument
    --> Result:
    --> (vmodl.fault.InvalidArgument) {
    -->    faultCause = (vmodl.MethodFault) null,
    -->    faultMessage = <unset>,
    -->    invalidProperty = "privIds"
    -->    msg = ""
    --> }
    --> Args:
    -->
    --> Arg name:
    --> "HCX to vCenter Service Account Role"
    --> Arg privIds:
  • This issue is only seen in the environments where a new VCF Operations HCX 9.1.x is being deployed on VCSA 9.0.x. In environments where an existing VCF Operations HCX is present on the VCSA, the upgrade of VCF Operations HCX to 9.1.x will be successful.

 

Environment

VCF Operations 9.1.x

VCF Operations HCX 9.1.x

vCenter Server 9.0.x

 

Cause

This issue is caused by the absence of a privilege ID within the target VCSA 9.0 environment during the HCX 9.1 installation process, which arises  due to installing the version of HCX higher than the version specified in BOM of VCF.

Resolution

  • Validate the BOM of VCF.
  • Install the VCF Operations HCX of the version mentioned in the BOM of the VCF 9.0.x

Additional Information

Bill of Materials (BOM) for VCF 9.0.2 : Bill of Materials