IBM Support

Why aren't my NMS users syncing to a multi-node Data Insight cluster?

Troubleshooting


Problem

A user was added to NMS, but it is not able to access Data Insight and does not show up in the Data Insight users list on a multi-node Data Insight cluster.

Cause

An incomplete kubernetes certificate rotation in Data Insight multi-node clusters (where there is a control node with one or more worker nodes) can cause the user-sync job to fail when it runs on one or more of the worker nodes.

Diagnosing The Problem

1. Determine if this is a multi-node cluster by logging into the Data Insight appliance via SSH and running:
kubectl get nodes -o wide
If it is a mult-node cluster, then you will see a list of nodes with one designated as the 'control-plane,master'.
2. Login to the worker nodes via SSH and check the status of the k3s-agent service by running:
systemctl status k3s-agent
Look for errors with messages like "NetworkPolicy: Unauthorized", "Endpoints: Unauthorized", and "EndpointSlice: Unauthorized"

Resolving The Problem

Restart the k3s-agent service on each worker node that has the 'Unauthorized' errors by running:
systemctl restart k3s-agent

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSUWLY","label":"IBM SevOne Network Performance Management"},"ARM Category":[{"code":"a8m3p0000000rgYAAQ","label":"Deployments"}],"ARM Case Number":"TS019293378","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0.0"}]

Document Information

Modified date:
27 June 2025

UID

ibm17238378