Users may experience an inability to assign or manage vSphere tags for nodes within a VMware vSphere Kubernetes Service (VKS) cluster.
When attempting to perform tagging operations via the vSphere Client or PowerShell, the operation fails with the following error:
(vmodl.fault.SecurityError) {faultCause = null, faultMessage = null}
This behavior persists even when the user account possesses standard administrative privileges or is assigned as a namespace owner for the cluster.
Product: VMware vSphere Kubernetes Service (VKS)
Version: 3.X v1.3X
The standard 'Administrators' group membership and 'Namespace Owners' group privileges do not confer the specific permissions required at the Supervisor Cluster level to manage tags on VKS-managed objects.
Managing these objects requires the 'Tagging Admin' role and membership in the 'ServiceProviderUsers' group in order for the Tagging Admin privileges to apply for VKS nodes.
Configure the user account with the necessary roles and group memberships using the following steps:
vCenter-assigned tags are ephemeral in nature. Manually assigned tags may be lost or overwritten during node updates or re-rollouts.
The use of Kubernetes labels is the recommended method for tagging VKS resources, as they provide persistence across lifecycle events and are managed natively by the cluster controller.
Reference:
To speak with a customer representative or a Support Engineer see Contact Support (Link: ).
Scroll to the bottom of the page and click on your respective region.