Private endpoint creation fails due to missing privateDnsZones read permission
Applies to
- NetApp Console Agent
- Cloud Volumes ONTAP (CVO)
- Microsoft Azure
- Azure Private Link
Issue
- New CVO is deployed successfully but the private endpoint is not automatically created.
- The following error appears in the logs:
ERROR [Create Vsa Working Environment] Simplicator request to http://localhost:8080/AzureProtocol/describePrivateDnsZone?resourceGroupName=xxxx&privateDnsZoneName=privatelink.blob.core.windows.net failed: The client 'xxx' with object id 'xxxx' does not have authorization to perform action 'Microsoft.Network/privateDnsZones/read' over scope '/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/<resource-group>/providers/Microsoft.Network/privateDnsZones/privatelink.blob.core.windows.net' or the scope is invalid. Code: AuthorizationFailed
