After deploying or redeploying VNA appliances in a VMware Cloud Foundation 9.1 environment, the SDDC Manager credential store does not immediately reflect the current, accurate passwords for those appliances. Specifically:
This article explains the expected discovery and synchronization workflow for VNA appliance credentials, clarifies which operations are and are not affected by the delay, and describes how to reduce the synchronization interval if required.
Symptoms
One or more of the following may be observed following the deployment, redeployment, or out-of-band password change of VNA appliances:
VMware NSX 9.1
VMware Cloud Foundation 9.1
VMware SDDC 9.1
This behavior is expected and is a function of how SDDC Manager discovers VNA appliances. It is not a defect in credential synchronization, and it is not generic to all newly deployed appliance types, the delay is specific to VNA.
The contributing factors are:
1. VNA appliances are discovered only by the automated background sync. Because the VNA appliances are deployed through the vCenter workflow rather than through SDDC Manager, SDDC Manager has no immediate awareness of them. It discovers these appliances only during its automated background inventory synchronization job, which runs every 3 hours by default.
2. Manual Inventory Sync does not apply to VNA appliances. Manually triggered sync operations do not cover VNA discovery and will not force an update. This is why repeated manual resyncs in the field produce no change and why the credential store only refreshes on the scheduled interval. The eventual ~3 hour update reflects the next scheduled run of the background job, not the manual syncs.
3. Inventory sync does not reconcile out-of-band password changes. None of the inventory sync operations, automated or manual, automatically update stored credentials when a password has been changed out-of-band directly on the VNA appliance. This explains why SDDC Manager continued to display pre-change passwords after the appliance-side change and subsequent resync. A separate credential remediation operation is required in SDDC Manager to reconcile out-of-band password changes, and that operation is only possible after the initial automated inventory sync has completed and the node is present in inventory.
4. Redeployment with reused names/FQDNs. Where a cluster is removed and redeployed with the same names and FQDNs before the background sync has run, SDDC Manager's inventory still holds the prior cluster's records. Credentials retrieved during this window will therefore correspond to the removed cluster. The records are reconciled on the next scheduled background sync.
This is expected product behavior in VCF 9.1 VNA node deployments. No corrective action is required to obtain accurate credentials the credential store populates correctly once the automated background inventory sync completes.
No. The 3-hour delay is a one-time condition specific to the period immediately following deployment, while the appliance is not yet present in SDDC Manager inventory.
Once the VNA node appears in the SDDC Manager inventory, future password rotations occur immediately, on demand, at the administrator's discretion. Scheduled or compliance-driven password rotations performed after initial discovery are not subject to any multi-hour delay.
Other out-of-band topology changes continue to be picked up only on the scheduled background sync interval. This includes, but is not limited to:
Changes of this type should be expected to reflect in SDDC Manager within one background sync cycle (3 hours by default).
For password management after SDDC Manager sync, refer to
https://techdocs.broadcom.com/