Error: "vim.fault.NoPermission" when assigning image to host in vSphere Lifecycle Manager (vLCM)
search cancel

Error: "vim.fault.NoPermission" when assigning image to host in vSphere Lifecycle Manager (vLCM)

book

Article ID: 449056

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Symptoms

  • Attempting to assign an ESXi image to a host within a cluster via vSphere Lifecycle Manager (vLCM) fails.
  • The vSphere Client displays the error: vim.fault.NoPermission. There may be a failing task in SDDC that has similar messaging.
  • Tasks in vCenter show the operation failed due to insufficient privileges, even when using an administrative account.
  • During VUM to vLCM transition, the error is thrown on the "Extract Image" vCenter task. Failing task can be initiated by SDDC API call (see Transition to vSphere Lifecycle Manager Images Using the SDDC Manager API) or VRLO automation.
  • The "NoPermission" failure can be found in vpxd.log in vCenter, and domainmanager.log in SDDC.

Environment

  • VMware vCenter Server 8.x, 9.x
  • vSphere Lifecycle Manager (vLCM)
  • ESXi 8.x, 9.x
  • SDDC Manager 9.x
  • SDDC Manager 9.1.x
  • VCF 9.x
  • VCF 9.1.x

Cause

This issue can occur due to inconsistent permission propagation at the cluster or host level when vLCM attempts to attach a software specification to a host that is currently part of a managed cluster.

Resolution

To resolve this issue, use the following workaround to manually associate the image with the host:

  1. Move the affected ESXi host out of the cluster into the parent Datacenter or a temporary non-vLCM cluster.
  2. Assign the desired ESXi image/software specification to the standalone host.
  3. Move the host back into the original cluster.
  4. Run a cluster pre-check to ensure compatibility.
  5. Remediate the host as part of the cluster.

Additional Information

For more information on host remediation, see Remediating a Cluster or a Standalone Host Against a Single Image

If the issue persists, ensure the user has the required vLCM privileges. Reference: vSphere Lifecycle Manager Privileges

If you need to speak with a customer representative or a Support Engineer, see Contact Support. Scroll to the bottom of the page and click on your respective region.