You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在RHEL虚拟机创建Admin Workstation时vCenter登录验证失败求助

问题

在RHEL虚拟机上创建GKE On-Prem Admin Workstation时,执行命令./gkeadm create admin-workstation [--auto-create-service-accounts]加载admin-ws-config.yaml文件,出现vCenter身份验证错误:

Credentials: Failed to login. Check credentials or network settings

已确认可通过浏览器正常登录vSphere客户端,配置文件内容如下:

gcp:
  # Path of the component access service account's JSON key file
  componentAccessServiceAccountKeyPath: "/root/component-access-key.json"
# Specify which vCenter resources to use
vCenter:
  # The credentials and address GKE On-Prem should use to connect to vCenter
  credentials:
    address: https://10.31.4.95/
    username: "administrator@vsphere.local"
    password: "Password@123"
  datacenter: "Google Anthos - Implementation"
  datastore: "MLOPS"
  cluster: "Anthos-cluster"
  network: "LabNetwork"
  # vSphere vm folder to deploy vms into. defaults to datacenter top level folder
  folder: "vCLS"
  resourcePool: "Anthos-cluster/Resources"
  # Provide the path to vCenter CA certificate pub key for SSL verification
  caCertPath: "/root/vcenter.pem"

# The URL of the proxy for the jump host
proxyUrl: ""
adminWorkstation:
  name: "gke-admin-ws-221111-164725"
  cpus: 4
  memoryMB: 8192
  # The boot disk size of the admin workstation in GB. It is recommended to use a
  # disk with at least 100 GB to host images decompressed from the bundle.
  diskGB: 100
  # Name for the persistent disk to be mounted to the home directory (ending in .vmdk).
  # Any directory in the supplied path must be created before deployment.
  dataDiskName: gke-on-prem-admin-workstation-data-disk/gke-admin-ws-221111-164725-data-disk.vmdk
  # The size of the data disk in MB.
  dataDiskMB: 512
  network:
    # The IP allocation mode: 'dhcp' or 'static'
    ipAllocationMode: "static"
    # The host config in static IP mode. Do not include if using DHCP
    hostConfig:
      # The IPv4 static IP address for the admin workstation
      ip: "10.54.122.96"
      # The IP address of the default gateway of the subnet in which the admin workstation is to be created
      gateway: "10.54.127.254"
      # The subnet mask of the network where you want to create your admin workstation
      # (e.g. 255.255.255.0)
      netmask: "255.255.248.0"
      # The list of DNS nameservers to be used by the admin workstation
      dns:
      - "10.154.248.9"
      - "10.154.248.10"
  # The URL of the proxy for the admin workstation
  proxyUrl: ""
  ntpServer: "10.255.255.240"

根本原因排查方向

结合场景和配置文件,可能的原因包括以下几点:

1. SSL证书验证失败

配置中指定了caCertPath: "/root/vcenter.pem",但存在以下可能:

  • 证书文件不存在或路径错误,导致gkeadm无法验证vCenter的SSL证书
  • 证书内容不正确(如过期、不是vCenter当前使用的CA证书)
  • 浏览器访问时会自动信任自签证书,但gkeadm需要明确导入正确的CA证书才能建立安全连接

2. 网络连通性问题(API端口未开放)

浏览器能登录vSphere客户端仅说明HTTP/HTTPS端口(443)可访问,但gkeadm需要调用vCenter的SOAP/REST API,需确认:

  • RHEL虚拟机到vCenter地址10.31.4.95的443端口是否连通,可执行curl -v https://10.31.4.95/sdk测试
  • RHEL本地防火墙(firewalld/iptables)是否拦截了出站443请求
  • 网络路由是否正常,RHEL虚拟机与vCenter所在网段是否互通

3. 凭证解析或格式错误

  • 密码包含特殊字符@,配置文件中的双引号若为HTML转义的"而非标准YAML双引号,会导致gkeadm读取到错误的密码内容
  • 可尝试临时更换为无特殊字符的密码进行测试,或确认配置文件中的引号为标准双引号

4. vCenter地址格式问题

配置中address字段末尾带有斜杠/,可能导致API请求路径解析错误,建议修改为https://10.31.4.95(去掉末尾斜杠)

5. 权限或API访问限制

  • 虽然administrator@vsphere.local是管理员账号,但vCenter可能禁用了该账号的API访问权限,或限制了SOAP API的使用
  • 需确认vCenter是否启用了必要的API服务(如vSphere Web Services SDK)

6. 文件权限问题

  • /root/vcenter.pem或/root/component-access-key.json的权限设置不当,导致gkeadm无法读取文件内容(即使以root身份执行,也需确保文件权限为可读)

内容的提问来源于stack exchange,提问作者Sonali Das

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 09:15:59