Unable to see workload domain within the vCenter Private AI Extension
search cancel

Unable to see workload domain within the vCenter Private AI Extension

book

Article ID: 449363

calendar_today

Updated On:

Products

VCF Private AI Services VCF Operations

Issue/Introduction

  • After deploying a workload domain for VMware Private AI Foundation (PAIF), the domain is not visible within the vCenter Private AI Extension.
  • The setup steps within the extension appear greyed out or restricted.
  • The issue persists even when logged in as a local administrator of the management vCenter or as a VCF SSO user.
  • Only management vCenter is shown on Menu

Environment

VCF 9.x

Cause

This issue occurs when administrative permissions are not correctly scoped across the VCF management stack.

  1. Local vs. Global Permissions: Permissions assigned at the local vCenter root level with "This object and its children" do not propagate to linked instances or cross-domain extensions.
  2. SDDC Manager Authorization: The user account or group lacks the necessary administrative membership within the SDDC Manager security groups.

Resolution

To resolve this issue, ensure the administrative user or group has the correct global scope by following these steps:

  1. Configure Global Permissions in vCenter:

    • Log in to the vSphere Client as an Administrator.
    • Navigate to Administration > Access Control > Global Permissions.
    • Add the required User/Group and assign the Administrator role.
    • Ensure the permission is defined as a Global Permission to ensure it extends across the VCF environment.
  2. Configure SDDC Manager Permissions:

    • Log in to SDDC Manager.
    • Ensure the administrative user/group is added to the SDDC Manager Admin group.

Additional Information

https://techdocs.broadcom.com/us/en/vmware-cis/private-ai/foundation-with-nvidia/9-0/private-ai-foundation-9-x/deploying-private-ai-foundation-with-nvidia/guided-private-ai-deployment-in-the-vsphere-client.html