One more thing relating to this issue - even though we can't (as a tenant admin) see pcidevices via the harvester/rancher interface, we can modify the vm definition directly and add a hostDevices entry which WILL allow the nvidia gpu/pcidevice to be assigned to the vm in question (the interface shows that the virtual machine needs to be rebooted after which the pcidevice shows to be assigned) - has anyone else seen this issue where harvester is not showing the true state of pcidevice assignment to a vm/vmi?