在RHEL虚拟机创建Admin Workstation时vCenter登录验证失败求助
问题
在RHEL虚拟机上创建GKE On-Prem Admin Workstation时,执行命令./gkeadm create admin-workstation [--auto-create-service-accounts]加载admin-ws-config.yaml文件,出现vCenter身份验证错误:
Credentials: Failed to login. Check credentials or network settings
已确认可通过浏览器正常登录vSphere客户端,配置文件内容如下:
gcp: # Path of the component access service account's JSON key file componentAccessServiceAccountKeyPath: "/root/component-access-key.json" # Specify which vCenter resources to use vCenter: # The credentials and address GKE On-Prem should use to connect to vCenter credentials: address: https://10.31.4.95/ username: "administrator@vsphere.local" password: "Password@123" datacenter: "Google Anthos - Implementation" datastore: "MLOPS" cluster: "Anthos-cluster" network: "LabNetwork" # vSphere vm folder to deploy vms into. defaults to datacenter top level folder folder: "vCLS" resourcePool: "Anthos-cluster/Resources" # Provide the path to vCenter CA certificate pub key for SSL verification caCertPath: "/root/vcenter.pem" # The URL of the proxy for the jump host proxyUrl: "" adminWorkstation: name: "gke-admin-ws-221111-164725" cpus: 4 memoryMB: 8192 # The boot disk size of the admin workstation in GB. It is recommended to use a # disk with at least 100 GB to host images decompressed from the bundle. diskGB: 100 # Name for the persistent disk to be mounted to the home directory (ending in .vmdk). # Any directory in the supplied path must be created before deployment. dataDiskName: gke-on-prem-admin-workstation-data-disk/gke-admin-ws-221111-164725-data-disk.vmdk # The size of the data disk in MB. dataDiskMB: 512 network: # The IP allocation mode: 'dhcp' or 'static' ipAllocationMode: "static" # The host config in static IP mode. Do not include if using DHCP hostConfig: # The IPv4 static IP address for the admin workstation ip: "10.54.122.96" # The IP address of the default gateway of the subnet in which the admin workstation is to be created gateway: "10.54.127.254" # The subnet mask of the network where you want to create your admin workstation # (e.g. 255.255.255.0) netmask: "255.255.248.0" # The list of DNS nameservers to be used by the admin workstation dns: - "10.154.248.9" - "10.154.248.10" # The URL of the proxy for the admin workstation proxyUrl: "" ntpServer: "10.255.255.240"
根本原因排查方向
结合场景和配置文件,可能的原因包括以下几点:
1. SSL证书验证失败
配置中指定了caCertPath: "/root/vcenter.pem",但存在以下可能:
- 证书文件不存在或路径错误,导致gkeadm无法验证vCenter的SSL证书
- 证书内容不正确(如过期、不是vCenter当前使用的CA证书)
- 浏览器访问时会自动信任自签证书,但gkeadm需要明确导入正确的CA证书才能建立安全连接
2. 网络连通性问题(API端口未开放)
浏览器能登录vSphere客户端仅说明HTTP/HTTPS端口(443)可访问,但gkeadm需要调用vCenter的SOAP/REST API,需确认:
- RHEL虚拟机到vCenter地址
10.31.4.95的443端口是否连通,可执行curl -v https://10.31.4.95/sdk测试 - RHEL本地防火墙(firewalld/iptables)是否拦截了出站443请求
- 网络路由是否正常,RHEL虚拟机与vCenter所在网段是否互通
3. 凭证解析或格式错误
- 密码包含特殊字符
@,配置文件中的双引号若为HTML转义的"而非标准YAML双引号,会导致gkeadm读取到错误的密码内容 - 可尝试临时更换为无特殊字符的密码进行测试,或确认配置文件中的引号为标准双引号
4. vCenter地址格式问题
配置中address字段末尾带有斜杠/,可能导致API请求路径解析错误,建议修改为https://10.31.4.95(去掉末尾斜杠)
5. 权限或API访问限制
- 虽然
administrator@vsphere.local是管理员账号,但vCenter可能禁用了该账号的API访问权限,或限制了SOAP API的使用 - 需确认vCenter是否启用了必要的API服务(如vSphere Web Services SDK)
6. 文件权限问题
/root/vcenter.pem或/root/component-access-key.json的权限设置不当,导致gkeadm无法读取文件内容(即使以root身份执行,也需确保文件权限为可读)
内容的提问来源于stack exchange,提问作者Sonali Das
相关产品推荐
相关产品推荐

