HPE Morpheus Software Agent Install Troubleshooting¶
When provisioning an Instance, there are network and configuration requirements to consider in order to successfully install the HPE Morpheus Software Agent. Typically, when a VM Instance is still in the provisioning phase long after the VM is up, the Instance is unable to reach HPE Morpheus Software. Depending on the Agent install mode, it could also mean HPE Morpheus Software is unable to reach the Instance.
The most common reason an Agent install fails is the provisioned Instance cannot reach the HPE Morpheus Software Appliance via the Appliance URL set in Administration > Settings over port 443. When an Instance is provisioned from HPE Morpheus Software, it must be able to reach the HPE Morpheus Software appliance via the Appliance URL or the Agent will not be installed.
In addition to the main Appliance URL in Administration > Settings, additional Appliance URLs can be set per Cloud in the Advanced Options section of the Cloud configuration modal when creating or editing a Cloud. When this field is populated, it will override the main Appliance URL for anything provisioned into that Cloud.
Tip
The HPE Morpheus Software UI current log, located at /var/log/morpheus/morpheus-ui/current, is very helpful when troubleshooting Agent installations.
Agent Install Methods¶
Morpheus Agent installation supports multiple install methods.
SSH/WinRM
VM Tools
Cloud-Init & Cloudbase-Init
Windows Unattended
Manual
For All Agent Install Methods¶
When an Instance is provisioned and the Agent does not install, verify the following for any Agent install mode:
The HPE Morpheus Software Appliance URL (Administration > Settings) is both reachable and resolvable from the provisioned node
Note
Be sure to use https:// even when using an IP address for the appliance.
Inbound connectivity access to the HPE Morpheus Software appliance from provisioned VMs and container hosts on port 443 (needed for Agent communication)
Private (non-HPE Morpheus Software provided) VM images and templates must have their credentials stored. These can be entered or edited in the section by clicking the Actions dropdown on an image detail page and selecting Edit.
Note
Administrator user is required for Windows Agent install.
The Instance does not have an IP address assigned. For scenarios without a DHCP server, static IP information must be entered by selecting the Network Type: Static in the Advanced Options section during provisioning. IP Pools can also be created in the Infrastructure > Networks > IP Pools section and added to Cloud network sections for IPAM
DNS is not configured and the node cannot resolve the appliance. If DNS cannot be configured, the IP address of the HPE Morpheus Software appliance can be used as the main or Cloud appliance
Endpoint Security Interference¶
EDR, antivirus, application control, and host firewall products can interrupt different stages of Agent setup. A blocked download or script affects delivery; a denied package manager or file write affects installation; a quarantined morphd process affects startup; and a denied outbound HTTPS/WSS session affects registration and ongoing communication. An Agent upgrade can encounter the same controls again even when the previous version was permitted.
Record the failed stage, timestamp, installation output, and the relevant entry from
/var/log/morpheus/morpheus-ui/current. On the target, collect Agent logs from/var/log/morpheus-nodeand the security product’s prevention or quarantine event.Confirm DNS resolution and TCP 443 connectivity to the configured Appliance URL. If these checks succeed but the Agent cannot connect, have the security team inspect TLS/websocket filtering and process-specific network policy.
Correlate the event with
morphd, themorpheus-node-runsvdirservice,/opt/morpheus-node,/etc/morpheus/morpheus-node.yaml, and/var/log/morpheus-node. Permit only the exact package, process, path, action, or destination shown to be blocked, using the security vendor’s approved allowlisting mechanism.Retry the failed installation or upgrade and verify that the Agent starts, reconnects, and reports in HPE Morpheus Software. Preserve the evidence if the targeted rule does not resolve the failure.
Do not prescribe a permanent exclusion for the entire Agent directory, all scripts, all child processes, or all traffic. If temporary security-control disablement is the only available diagnostic, obtain security-policy approval, isolate the test to the affected host and shortest practical interval, re-enable protection immediately, and verify both Agent health and security-control health. Escalate with the collected evidence rather than leaving protection disabled.
SSH¶
Port 22 is open for Linux images, and SSH is enabled
Credentials set on the image if using a custom or synced image. Credentials can be entered on images in the section
WinRM¶
Port 5985 must be open and WinRM enabled for Windows images
Credentials have been entered on the image if using a custom or synced image. Credentials can be entered on images in the section
Note
Administrator user is required for Windows Agent install.
VMware Tools (vmtools)¶
VMware Tools is installed on the template(s)
Credentials have been entered on the image if using custom or synced image. Credentials can be entered on images in the section
Sudo privileges required for Linux
Administrator User required for Windows (SID 500)
Cloud-Init¶
Cloud-Init settings configured in section
Cloud-Init installed on Virtual Image
Cloud-Initenabled on Virtual Image config
Cloudbase-Init¶
Windows Administrator Password defined in section
Cloudbase-Init installed on Virtual Image
Cloud-Initenabled on Virtual Image configCloudbase-Init is only required for OpenStack Cloud types
Note
Unattend Agent Installation and customizations are recommended over Cloudbase-Init
Windows Unattended¶
Windows Administrator Password defined in section
VMware:
Force Guest Customizationsset to forced on Virtual Image config when using DHCP (Static Assignment will already force Guest Customizations)Nutanix & SCVMM: Virtual Image is sysprepped and shutdown,
Sysprep Enabledflagged on Virtual Image config
Manual¶
Agent Install scripts can be downloaded from HPE Morpheus Software by selecting Actions > Download Agent Script from an Server detail page, then run manually on the target host when required for a given managed resource. Please note the script will be unique per managed resource and should not be saved to run as needed on any arbitrary resources in the future.
When installing on Windows, continue with the steps below to complete manual installation:
Open powershell as an administrator
Run the
unblock-file cmdletagainst the download agent installation script:Unblock-File -Path C:\Users\User01\Documents\Downloads\agentInstall.ps1 Get-ExecutionPolicy Set-ExecutionPolicy -ExecutionPolicy Unrestricted -Scope CurrentUserAfter running the powershell script, ensure the script downloaded the msi and the Agent service started correctly:
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
Following setup, verify that the Agent is reporting back to the HPE Morpheus Software appliance.
Restarting the HPE Morpheus Software Agent¶
In some situations, it may necessary to restart the HPE Morpheus Software Agent on the host to re-sync communication from the Agent to the HPE Morpheus Software appliance.
Linux¶
On the target host, run sudo morpheus-node-ctl restart morphd and the HPE Morpheus Software agent will restart. morpheus-node-ctl status will also show the agent status.
Windows¶
The HPE Morpheus Software Windows Agent service can be restarted in Administrative Tools > Services.
Tip
The HPE Morpheus Software Remote Console is not dependent on Agent communication and can be used to install or restart the HPE Morpheus Software agent on an Instance.
Uninstall HPE Morpheus Software Agent¶
Linux Agents¶
You can use the following to uninstall the linux agent (contains commands for both rpm and deb agents)
sudo rm /etc/apt/sources.list.d/morpheus.list \
sudo morpheus-node-ctl kill \
sudo apt-get -y purge morpheus-node \
sudo apt-get -y purge morpheus-vm-node \
sudo yum -y remove morpheus-node \
sudo yum -y remove morpheus-vm-node \
sudo yum clean all \
sudo systemctl stop morpheus-node-runsvdir \
sudo rm -f /etc/systemd/system/morpheus-node-runsvdir.service \
sudo systemctl daemon-reload \
sudo rm -rf /var/run/morpheus-node \
sudo rm -rf /opt/morpheus-node \
sudo rm -rf /etc/morpheus \
sudo rm -rf /var/log/morpheus-node \
sudo pkill runsv \
sudo pkill runsvdir \
sudo pkill morphd \
sudo usermod -l morpheus-old morpheus-node \
Windows Agents¶
$app = Get-WmiObject -Class Win32_Product -Filter "Name = 'Morpheus Windows Agent'"
$app.Uninstall()
CentOS/RHEL 7 Images¶
For custom CentOS 7 images we highly recommend setting up Cloud-Init and fixing the network device names. More information for custom CentOS images can be found in the CentOS 7 image guide.