CVO HA deployment fails with "Timeout reach waiting for floating IPs"
Applies to
- NetApp Console
- Cloud Volumes ONTAP (CVO) on AWS
Issue
During deployment of a new CVO HA pair in AWS via NetApp Console, the operation fails with errors such as:
Error: Timeout reached while waiting for floating IPs to be added to route tablesand in logs:
failed to send request with status: 401 and error: {"error":{"code":"6691623","message":"User is not authorized."}}...com.amazonaws.services.ec2.model.AmazonEC2Exception: You are not authorized to perform this operation. User: arn:aws:sts::<account>:assumed-role/@SVC_OCCM/<instance> is not authorized to perform: ec2:RunInstances ... with an explicit deny in a service control policy...- The deployment audit log shows failed connectivity checks to ports 443, 3000.
- The mediator is unable to update AWS VPC route tables with floating IPs.
- The UI may show the deployment as failed or stuck.
- The error persists after confirming that IAM policies are attached and SCPs appear not to block required permissions.
