New imported workload domain does not populate inventory in VCF Operations due to vCenter service account remediation failure on SDDC Manager
search cancel

New imported workload domain does not populate inventory in VCF Operations due to vCenter service account remediation failure on SDDC Manager

book

Article ID: 448807

calendar_today

Updated On:

Products

VMware SDDC Manager / VCF Installer

Issue/Introduction

  • Workload domain brownfield import completes successfully on the SDDC Manager.

  • vCenter Server exists in SDDC Manager inventory.

  • However, in VCF Operations, under Inventory -> Workload domain, the Inventory tree (vCenter / Datacenter / Cluster / Hosts) is missing.

  • Under Administration -> Integrations -> Accounts -> VMware Cloud Foundation, editing the affected workload domain configuration's vCenter adapter and performing 'VALIDATE CONNECTION' task fails with error:

    'Can't create system managed credential'

  • On the SDDC Manager, the password remediation for SDDC Manager's vCenter service account (svc-####@vsphere.local) fails with the following error:

    "Password remediation for resource :<vCenter_FQDN>, user : svc-####@vsphere.local and credential type : SSO"

Environment

VMware Cloud Foundation 9.x

Cause

The password utility on the vCenter Server generates service account passwords containing special characters that SDDC Manager does not support. This failure prevents successful credential management and inventory synchronization between SDDC Manager and VCF Operations.

Resolution

This is a known issue and Broadcom engineering is working on this.

Workaround:

 Perform a manual password rotation to generate a compliant password and restore synchronization:

  1. Log in to SDDC Manager.
  2. Navigate to the password management dashboard.
  3. Locate the affected vCenter SSO service account (e.g., svc-####@vsphere.local) showing a failed remediation status.
  4. Initiate a manual Password Rotation for the account.
  5. Log in to VCF Operations.
  6. Navigate to Operate -> Administration -> Integrations -> Accounts.
  7. Select the vCenter adapter for the affected workload domain and click Edit.
  8. Ensure System Managed Credential is selected and click Validate Connection.
  9. Save the changes.
  10. Under Operate -> Administration -> Integrations -> Accounts -> VMware Cloud Foundation, select the VCF instance that manages the affected vCenter. Click on the three dots and click Start Collecting All.