HCX Manager misconfiguration causes password policy operations to fail
search cancel

HCX Manager misconfiguration causes password policy operations to fail

book

Article ID: 453932

calendar_today

Updated On:

Products

VMware HCX VCF Operations

Issue/Introduction

  • When an HCX Manager integration is added to VCF Operations without the correct admin role granted on the HCX appliance, VCF Operations still accepts the integration and shows it as healthy — no warning is shown that anything is misconfigured.
  • The problem only shows up later, on the Password Policy page:
    • The VCF Management components row is missing from the Compliance Status table.
    • Applying a password policy fails with an error similar tothe following:

      "Exception occurred while apply password policy Cannot invoke \"java.util.List.stream()\" because the return value of \"com.vmware.vcops.bridge.server.vcf.password.policy.VcfPasswordPolicyManager.getVCFManagementComponentsFromvRops()\" is null" 

Environment

  • VCF Operations 9.1.1
  • VCF HCX

Cause

The required admin role for the integration user was never assigned on the HCX appliance.

VCF Operations does show a warning about the missing role when the integration is added, but it does not block the integration from being saved, and the integration continues to appear healthy afterward. It's only when the Password Policy feature later tries to read information about the HCX component that the missing permissions causes it to fail. The components section of the page and any Apply Policy operations are all in a broken state.

Resolution

Configure the required roles for the integration user on the HCX appliance as described in the HCX role configuration steps doc. Once the roles are added, re-add the integration into VCF Ops and try again.

Configure the HCX role