VCF Automation does not block region creation for a pre-existing HAProxy (VDS)-based Supervisor after a non-VCF-to-VCF conversion, causing Supervisor Service installation failures
search cancel

VCF Automation does not block region creation for a pre-existing HAProxy (VDS)-based Supervisor after a non-VCF-to-VCF conversion, causing Supervisor Service installation failures

book

Article ID: 453697

calendar_today

Updated On:

Products

VCF Automation

Issue/Introduction

A non-VCF environment running vCenter Server 8.0 Update p08 and ESXi 8.0 Update p04 has a pre-existing vSphere Supervisor configured with HAProxy/VDS-based networking. The environment is subsequently converted to VMware Cloud Foundation (VCF) using Auto Deploy with NSX 9.1.1. As part of the conversion, VMware Cloud Foundation Automation (VCFA) is deployed; however, the existing Supervisor remains configured with HAProxy/VDS-based networking and is not configured with NSX.

Following the conversion, VCFA does not detect or validate the existing Supervisor networking configuration when a Region is created against the converted vCenter Server. As a result, the Region can be successfully created even though the Supervisor uses HAProxy/VDS-based networking instead of the NSX-based networking expected by the VCFA Region.

No warning or validation error is presented during Region creation to indicate the networking configuration mismatch. Subsequently, attempts to install Supervisor Services, such as Harbor, from VCFA on the newly created Region fail.

Symptoms:
  1. VCFA allows a Region to be created against a vCenter Server with an existing Supervisor configured for HAProxy/VDS-based networking.
  2. VCFA does not detect or flag the mismatch between the Supervisor’s existing networking configuration and the NSX-based networking expected by the Region.
  3. No warning or validation error is displayed during Region creation.
  4. Subsequent attempts to install Supervisor Services, such as Harbor, from VCFA fail.

Environment

VCF Automation 9.1.1

Cause

During Region creation, VCFA only validates that the target vCenter Server is associated with an NSX Manager; it does not independently verify the networking type of an already-existing Supervisor on that vCenter. As a result, when a vCenter is later associated with NSX (e.g., via VCF conversion) but its pre-existing Supervisor is still configured with VDS/HAProxy-based networking, VCFA has no way to detect the mismatch and proceeds as if the Supervisor were NSX-based. This leads to failures later, when Supervisor Services that require NSX networking are installed.

Resolution

This issue is currently being investigated and will be fixed in future release.

Workaround:

  1. Before creating a Region in VCFA against a vCenter Server that has a pre-existing Supervisor, manually confirm that the Supervisor's networking type is NSX-based (not VDS/HAProxy-based).
  2. Do not proceed with Region creation or Supervisor Service installation in VCFA if the existing Supervisor uses VDS/HAProxy-based networking, as installation of Supervisor Services will fail.

Note: subscribe to this article. For instructions on how to subscribe, see Subscribe to Knowledge Articles.