# Persistent Storage on a vSphere storage

**URL:** <https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301>\
**Category:** SUSE Rancher Prime\
**Created:** [November 9, 2018, 5:48pm UTC](https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301 "2018-11-09T17:48:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![olc](https://avatars.discourse-cdn.com/v4/letter/o/b9bd4f/32.png) [@olc](https://forums.suse.com/u/olc)\
**Post date:** [November 9, 2018, 5:48pm UTC](https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301/1 "2018-11-09T17:48:26Z")

</div>

I am currently taking my first steps with Rancher. I have a VmWare vCenter server and I’d like to rely on the vSphere storage for providing persistent volumes. My cluster nodes are deployed manually: when provisioning the cluster in Rancher I select “From my own existing nodes” with a “Custom Cloud provider”. I manually provide the “cloud\_provider” configuration to the cluster options in YAML. The cluster node is installed without problem that way.

After that, I configure a storage class using the “VMWare vSphere Volume” provisioner via the Rancher web. So far, so good.

Then, I try to add a volume to my cluster but it does not work. The status of the PVC stays to a “Pending” state: an x509 certificate problem actually prevents PV to be created.

```
$ admin@node01:~$ docker logs -f kube-controller-manager
I1109 11:01:13.436871 1 event.go:221] Event(v1.ObjectReference{Kind:"PersistentVolumeClaim", Namespace:"default", Name:"my-vsphere-volume", UID:"b88f14f8-e40e-11e8-a513-005056a3f168", APIVersion:"v1", ResourceVersion:"2441", FieldPath:""}): type: 'Warning' reason: 'ProvisioningFailed' Failed to provision volume with StorageClass "sphere-storage": Post https://192.168.86.38.xip.io:443/sdk: x509: certificate signed by unknown authority

```

In fact, my vCenter uses a self signed certificate that Rancher does not trust. I can workaround the problem adding manually the vCenter ca-certificate into the /etc/ssl/certs/ca-certificates.crt file into the “kube-controller-manager” container but this is not the way to go.

I found the doc at [https://rancher.com/docs/rancher/v2.x/en/admin-settings/custom-ca-root-certificate/](https://rancher.com/docs/rancher/v2.x/en/admin-settings/custom-ca-root-certificate/) but I don’t understand how to do the same for “kube-controller-manager”.

I go round in circles from days with that! Is there something stupid (or not) I missed? Any help/pointer would be greatly welcome.

PS: I’m not yet so familiar with docker nor rancher, please be indulgent! 🙂

Thanks in anticipation.

## Best,

Olivier

---

<div class="post-metadata">

**Author:** ![Aaron\_Jaeger](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/aaron_jaeger/32/5358_2.png) [@Aaron\_Jaeger](https://forums.suse.com/u/Aaron_Jaeger)\
**Post date:** [June 28, 2019, 7:52pm UTC](https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301/2 "2019-06-28T19:52:56Z")

</div>

I am having the same issue.

---

<div class="post-metadata">

**Author:** ![itu](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/itu/32/5580_2.png) [@itu](https://forums.suse.com/u/itu)\
**Post date:** [September 12, 2019, 10:41am UTC](https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301/3 "2019-09-12T10:41:34Z")

</div>

From the documentation

[https://rancher.com/docs/rke/latest/en/config-options/cloud-providers/vsphere/](https://rancher.com/docs/rke/latest/en/config-options/cloud-providers/vsphere/)

### global

The main purpose of global options is to be able to define a common set of configuration parameters that will be inherited by all vCenters defined under the `virtual_center` directive unless explicitly defined there.

Accordingly, the `global` directive accepts the same configuration options that are available under the `virtual_center` directive. Additionally it accepts a single parameter that can only be specified here:

---

<div class="post-metadata">

**Author:** ![anthony](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anthony](https://forums.suse.com/u/anthony)\
**Post date:** [September 19, 2019, 7:45pm UTC](https://forums.suse.com/t/persistent-storage-on-a-vsphere-storage/12301/4 "2019-09-19T19:45:13Z")

</div>

```
cloud_provider:
  name: vsphere
  vsphereCloudProvider:
    global:
      insecure-flag: true

```

Same doc: [https://rancher.com/docs/rke/latest/en/config-options/cloud-providers/vsphere/](https://rancher.com/docs/rke/latest/en/config-options/cloud-providers/vsphere/)
