Troubleshooting
Problem
A user was added to NMS, but it is not able to access Data Insight and does not show up in the Data Insight users list on a multi-node Data Insight cluster.
Cause
An incomplete kubernetes certificate rotation in Data Insight multi-node clusters (where there is a control node with one or more worker nodes) can cause the user-sync job to fail when it runs on one or more of the worker nodes.
Diagnosing The Problem
1. Determine if this is a multi-node cluster by logging into the Data Insight appliance via SSH and running:
kubectl get nodes -o wide
If it is a mult-node cluster, then you will see a list of nodes with one designated as the 'control-plane,master'.
2. Login to the worker nodes via SSH and check the status of the k3s-agent service by running:
systemctl status k3s-agent
Look for errors with messages like "NetworkPolicy: Unauthorized", "Endpoints: Unauthorized", and "EndpointSlice: Unauthorized"
Resolving The Problem
Restart the k3s-agent service on each worker node that has the 'Unauthorized' errors by running:
systemctl restart k3s-agent
Document Location
Worldwide
[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSUWLY","label":"IBM SevOne Network Performance Management"},"ARM Category":[{"code":"a8m3p0000000rgYAAQ","label":"Deployments"}],"ARM Case Number":"TS019293378","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0.0"}]
Was this topic helpful?
Document Information
Modified date:
27 June 2025
UID
ibm17238378