VMware Cloud Community
JiGang
Contributor
Contributor

403 while request a Composite blueprint

Hi All:

I have a composite blueprint below.   Right now my problem is: for the user to consume the blueprint, it must have ‘Application Architecture’ role, which I think is the ‘View Composite …..’ permission matters.

But if I give user this role, he will be able to see the ‘Design’ tab. Otherwise, he will see the 403 error when provision from this blueprint.

Did anyone have similar concern before?  How can I manage the entitlements to avoid this?

Thanks a lot in advance.

blueprint.png

Request Error.png

Entitilement.png

Reply
0 Kudos
7 Replies
bdamian
Expert
Expert

Is "Customize VM" the only XaaS component it the Blueprint? If it is, could you remove it or create a new blueprint without XaaS components on it and try again without Application Architecture role?

D.

---
Damián Bacalov
vExpert 2017-2023 (7 years)
https://www.linkedin.com/in/damianbacalov/
https://tecnologiaimasd.blogspot.com/
twitter @bdamian
Reply
0 Kudos
JiGang
Contributor
Contributor

Thanks bdamian.

basically, besides JumpBox, all the other 3 are XAAS blueprints.   is there anything you may think cause the issue?

Thanks again.

Reply
0 Kudos
bdamian
Expert
Expert

The vRealize Orchestrator registration under Administration > vRO server, is per session or per user?

If is per session, could you try to set it per user and use vRO administration credentials for a test?

---
Damián Bacalov
vExpert 2017-2023 (7 years)
https://www.linkedin.com/in/damianbacalov/
https://tecnologiaimasd.blogspot.com/
twitter @bdamian
Reply
0 Kudos
JiGang
Contributor
Contributor

Thanks bdamian. i am running vra7.5,  but seems like i don't have these option.

vro.png

Reply
0 Kudos
bdamian
Expert
Expert

Ok, "Basic" is the per user option. So, is not the problem this case. I will try to reproduce this and, if I found something, I'll let you know.

---
Damián Bacalov
vExpert 2017-2023 (7 years)
https://www.linkedin.com/in/damianbacalov/
https://tecnologiaimasd.blogspot.com/
twitter @bdamian
Reply
0 Kudos
JiGang
Contributor
Contributor

Thank you very much

Reply
0 Kudos
bdamian
Expert
Expert

I've created a similar blueprint with a vCetner VM and a XaaS component linked to the VM:

pastedImage_0.png

I've also created a new business group with his reservation and add 1 user with no additional role.

The blueprint is in a new Service, the XaaS Blueprint is in no Service but marked as a Component.

The blueprint worked just fine so I assume is not a bug. I've tested on vRA 7.3.1.

Something in your configuration must be wrong. Is there any error in Administration > Events > Event Log or Infrastructure > Monitoring > Log related to the blueprint execution?

D.

---
Damián Bacalov
vExpert 2017-2023 (7 years)
https://www.linkedin.com/in/damianbacalov/
https://tecnologiaimasd.blogspot.com/
twitter @bdamian
Reply
0 Kudos