I am trying to use terraform to create a Service Fabric Cluster via combination of VMSS, VNETs, NSGs, etc. Unfortunately there isn't an official terraform provider for service fabric, so I am using an ARM template via azurerm_template_deployment.
All resources get created successfully via terraform apply and I am able to RDP into one of the VMs in the scale set. Unfortunately, even after 30-60 minutes, the Azure Portal for Service Fabric resource Status reads Waiting for nodes with no nodes showing up in the table.
When I RDP into the VM, I see several warning/error events in Event Viewer. All events come from ServiceFabricNodeBootstrapAgent:
1.
Info: Bootstrapping local node
2.
Info: PUT https://westus.servicefabric.azure.com/runtime/clusters/GUID_redacted/nodes/node_name_redacted
{"nodeTypeRef":"fronend","ipAddress":"192.168.0.8","faultDomain":"fd:/4","upgradeDomain":"4"}
3. Info
Using client certificate: [Version]
V3
[Subject]
CN=AzureServiceFabric-AnonymousClient
Simple Name: AzureServiceFabric-AnonymousClient
DNS Name: AzureServiceFabric-AnonymousClient
[Issuer]
CN=AzureServiceFabric-AnonymousClient
Simple Name: AzureServiceFabric-AnonymousClient
DNS Name: AzureServiceFabric-AnonymousClient
... etc ...
4.
ERROR: System.Net.WebException: The remote server returned an error: (401) Unauthorized.
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Azure.ServiceFabric.Extension.Core.RestClient.Invoke(Uri requestUri, String method, String requestBody, X509Certificate2 clientCertificate)
5.
System.Exception: System.Net.WebException: The remote server returned an error: (401) Unauthorized.
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Azure.ServiceFabric.Extension.Core.RestClient.Invoke(Uri requestUri, String method, String requestBody, X509Certificate2 clientCertificate)
at Microsoft.Azure.ServiceFabric.Extension.Core.RestClient.Invoke(Uri requestUri, String method, String requestBody, List`1 clientCertificates)
at Microsoft.Azure.ServiceFabric.Extension.Core.RestClient.Invoke(Uri requestUri, String method, String requestBody, List`1 clientCertificates)
at Microsoft.Azure.ServiceFabric.Extension.Core.WrpTopologyService.UpdateNodeInfo(String machineName, NodeDescription nodeDescription)
at System.Threading.Tasks.Task.Execute()
6.
ERROR: Microsoft.Azure.ServiceFabric.Extension.Core.AgentException: Unable to send node information
at Microsoft.Azure.ServiceFabric.Extension.Core.NodeBootstrapAgent.<RunOnce>d__11.MoveNext()
It seems that ServiceFabricNodeBootstrapAgent, a Windows service gets installed, but that's it. None of the service fabric runtime services ever get installed and I am not sure even why that API is used, or why it is returning 401. Anyone out there seen this problem?
Creating a cluster from the marketplace as well as via exported ARM template with powershell works just fine.