Resolving vmodl.fault.SecurityError When Tagging VMware vSphere Kubernetes Service Nodes
search cancel

Resolving vmodl.fault.SecurityError When Tagging VMware vSphere Kubernetes Service Nodes

book

Article ID: 451813

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

Users may experience an inability to assign or manage vSphere tags for nodes within a VMware vSphere Kubernetes Service (VKS) cluster.
When attempting to perform tagging operations via the vSphere Client or PowerShell, the operation fails with the following error:

(vmodl.fault.SecurityError) {faultCause = null, faultMessage = null}

This behavior persists even when the user account possesses standard administrative privileges or is assigned as a namespace owner for the cluster.

Environment

Product: VMware vSphere Kubernetes Service (VKS)
Version: 3.X v1.3X

Cause

The standard 'Administrators' group membership and 'Namespace Owners' group privileges do not confer the specific permissions required at the Supervisor Cluster level to manage tags on VKS-managed objects.
Managing these objects requires the 'Tagging Admin' role and membership in the 'ServiceProviderUsers' group in order for the Tagging Admin privileges to apply for VKS nodes. 

Resolution

Configure the user account with the necessary roles and group memberships using the following steps:

  1. Log into the vCenter appliance with an accoun tthat has Administrator privileges. 
  2. Create or identify the user account which will be assigning tags
  3. Navigate to Administration > Access Control > Global Permissions.
  4. Assign the Tagging Admin role, or a role that contains the Tagging Admin privileges, to the target user.
  5. Navigate to Administration > Single Sign-On > Users and Groups.
  6. Select the Groups tab and locate the ServiceProviderUsers group.
  7. Add the target user account as a member of this group.
  8. Log out of the vSphere Client and log back in with the updated account to apply the changes.
  9. Attempt to assign a tag to a VKS node to verify the operation succeeds.

 

Additional Information

vCenter-assigned tags are ephemeral in nature. Manually assigned tags may be lost or overwritten during node updates or re-rollouts.
The use of Kubernetes labels is the recommended method for tagging VKS resources, as they provide persistence across lifecycle events and are managed natively by the cluster controller.

Reference:

To speak with a customer representative or a Support Engineer see Contact Support (Link: https://support.broadcom.com/web/ecx/contact-support).
Scroll to the bottom of the page and click on your respective region.