ErrImagePull or ImagePullBackOff state. kubectl describe pod <pod-name> reveals the following DNS resolution failure during sidecar image acquisition:This issue is officially resolved in VCF 9.1.1 / VKS 3.7.1. Upgrading to release 9.1.1 automatically resolves the proxy domain mapping and registry endpoints for Regional Harbor deployments.
If an immediate upgrade to VCF 9.1.1 is not feasible, implement one of the following validated workarounds:
Override the default sidecar image path and configure the required Vault agent annotations at the application workload level to point directly to your accessible Regional Harbor image repository.
Add the annotation to your application's Pod specification :
Rather than relying on guest cluster automated package synchronization in VCF 9.1, install/deploy the Vault Injector service directly through the vCenter Server (VC) Management UI / Supervisor Services catalog. This ensures registry proxy bindings are properly assigned to external endpoints.