VMware Aria Suite Lifecycle upgrade fails during snapshot removal with error LCMVSPHERECONFIG1000026
search cancel

VMware Aria Suite Lifecycle upgrade fails during snapshot removal with error LCMVSPHERECONFIG1000026

book

Article ID: 452846

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

When you perform an environment upgrade in VMware Aria Suite Lifecycle (for example, upgrading VMware Aria Operations for Logs), the process completes up to step 8 (removing snapshots) and fails.

The failure may occur intermittently on a subset of nodes within a cluster (for example, successfully deleting snapshots on four nodes but failing on the remaining four).

The following error appears in the UI:

Error Code: LCMVSPHERECONFIG1000026

Runtime exception occurred in vsphere environment.

Permission denied due to security policy

Environment

  • VMware Aria Suite Lifecycle
  • Entrust CloudControl (Security Proxy)
  • VMware vCenter Server

Cause

The error message Permission denied due to security policy is the default proxy denial message generated by Entrust CloudControl. When VMware Aria Suite Lifecycle issues the API call to vCenter to delete the snapshot during the upgrade workflow, the request routes through the CloudControl proxy. The proxy evaluates the service account's permissions against its own Role-Based Access Control (RBAC) and denies the operation.

The intermittent failure across nodes within the same cluster occurs because CloudControl policies are not uniformly applied. This typically happens when virtual machines reside on different ESXi hosts, clusters, or datacenters, or have different PolicyTags assigned within CloudControl, resulting in the service account lacking uniform permissions.

Resolution

To resolve this issue, coordinate with your security or infrastructure team to ensure uniform permissions in the third-party proxy:

  1. Verify the vCenter endpoint configuration in VMware Aria Suite Lifecycle to confirm if it points directly to vCenter or to an Entrust CloudControl proxy VIP.
  2. Authenticate to the CloudControl management interface.
  3. Review the Log Viewer for denied RemoveSnapshot_Task operations generated by the VMware Aria Suite Lifecycle service account.
  4. Adjust the RBAC permissions or PolicyTags within CloudControl to ensure the service account holds the necessary rights to execute snapshot deletions uniformly across all nodes in the target cluster.
  5. Once permissions are synchronized, retry the failed upgrade operation in VMware Aria Suite Lifecycle.

Additional Information

Subscribe to this knowledge article to get updates on this issue.