VMware Cloud Community
vcitrainer
Contributor
Contributor

vSphere With Tanzu

Error from server (Forbidden): error when creating "gitlab-admin-service-account.yaml": serviceaccounts is forbidden: User "sso:Administrator@vsphere.local" cannot create resource "serviceaccounts" in API group "" in the namespace "kube-system"

Error from server (Forbidden): error when retrieving current configuration of:

Resource: "rbac.authorization.k8s.io/v1beta1, Resource=clusterrolebindings", GroupVersionKind: "rbac.authorization.k8s.io/v1beta1, Kind=ClusterRoleBinding"

Name: "gitlab-admin", Namespace: ""

from server for: "gitlab-admin-service-account.yaml": clusterrolebindings.rbac.authorization.k8s.io "gitlab-admin" is forbidden: User "sso:Administrator@vsphere.local" cannot get resource "clusterrolebindings" in API group "rbac.authorization.k8s.io" at the cluster scope

Reply
0 Kudos
1 Reply
pkvmw
VMware Employee
VMware Employee

Hi,

I'd kindly ask you to provide more background, questions or notes for your log excerpts in the future. IMHO it's not really polite to quickly just throw a few log lines in a forum and letting everyone, who's replying in their free-time, to guess what you want to tell us.

From what the messages tell I guess you want to deploy/create some YAML files for using it for a GitLab CI. The WCP/SupervisorCluster is not intended for this and best-practise (and the only way to get this working) is to deploy a TKC/GuestCluster for this. See: https://docs.vmware.com/en/VMware-vSphere/7.0/vmware-vsphere-with-tanzu/GUID-B1034373-8C38-4FE2-9517...

Regards,
Patrik

 

Reply
0 Kudos