Juju部署vSphere控制器遇权限问题,咨询所需用户权限
Since you’ve already confirmed your user can import customization specs, the issue is likely missing permissions specifically tied to creating and configuring virtual machines (which lines up with the error in createvm.go line 319). Here’s a clear breakdown of the exact permissions your vSphere user needs, organized by category:
Virtual Machine Permissions (Critical for Your Error)
These directly map to the VM creation flow Juju uses when setting up a controller:
- Create: Allows Juju to spin up a new virtual machine for the controller (this is the core operation failing in your case)
- Customize: Lets Juju apply the customization specification you’ve already imported to the new VM
- Configure: Enables adjusting VM hardware parameters (CPU, memory, disks) and guest OS settings
- Power On: Required to start the controller VM after it’s created
- Provisioning > Deploy Template: Mandatory if you’re using a VM template as the base for your controller
Datastore Permissions
Juju needs to manage storage resources for the controller VM:
- Browse Datastore: Access the datastore to locate or create VM-related files
- Low Level File Operations: Create, modify, and delete VM files on the datastore
- Allocate Space: Reserve storage capacity for the new controller VM
Network Permissions
Ensure the controller can connect to your vSphere network properly:
- Assign Network: Attach the controller VM to your specified vSphere network
- Configure IP Settings: Works with the customization spec to set up network connectivity (static or DHCP)
Inventory & Resource Permissions
Juju needs to navigate and utilize your vSphere infrastructure:
- Inventory > Read: Access the vCenter inventory to locate clusters, resource pools, and hosts
- Resource > Assign Virtual Machine to Resource Pool: Assign the controller VM to your target resource pool
- Folder > Create (Optional): If you want Juju to organize controllers in a dedicated folder, this permission is needed
Quick Tip
Instead of assigning individual permissions one by one, create a custom vSphere role with all the above permissions, then bind this role to your user (or user group) at the data center or cluster level. This ensures proper permission inheritance across all relevant objects and avoids missing edge-case permissions that might cause issues later.
内容的提问来源于stack exchange,提问作者Sune Kjærgård

