Simple Content Access entitlements with Insights Operator
Insights Operator automates the import of Simple Content Access (SCA) entitlement certificates every 8 hours. These Red Hat Subscription Management (RHSM) certificates allow the cluster to authenticate with the Red Hat Content Delivery Network (CDN) to access subscription-governed content.
SCA supports multi-architecture clusters by generating architecture-specific secrets, such as amd64 or arm64, in the openshift-config-managed namespace to ensure compatibility across all worker node types.
Additional resources
Simple Content Access entitlement synchronization
Simple Content Access (SCA) simplifies subscription management by removing the requirement to manually attach entitlement keys to individual nodes. Insights Operator facilitates this by automatically retrieving and storing certificates as secrets within the openshift-config-managed namespace. These certificates allow the cluster to authenticate with Red Hat content repositories for operations such as entitled builds.
Entitlement secrets refresh automatically every 8 hours. While older configurations used a support secret in the openshift-config namespace, Insights Operator now prioritizes the insights-config ConfigMap in the openshift-insights namespace if both exist.
Simple content access must be enabled in Red Hat Subscription Management for the importing to function.
Architecture-specific entitlement secrets
The certificates generated by the Insights Operator are based on the worker node architectures that are detected within the cluster. The two types of supported clusters include single-architecture clusters and multi-architecture clusters.
Single-architecture clusters: When all worker nodes use the same architecture, a single secret named etc-pki-entitlement is created.
Multi-architecture clusters: When worker nodes use different architectures, such as a mix of x86_64 and aarch64, a secret is created for each architecture present. These secrets use architecture-specific suffixes, such as etc-pki-entitlement-amd64 or etc-pki-entitlement-arm64.
Verify and manage entitlement secrets
To verify the imported entitlement secrets, list architecture-specific secrets and change the import behavior with the {insights_Operator} configuration.
Prerequisites
- You have cluster-admin permissions for the OpenShift Container Platform cluster.
- You have set Simple Content Access (SCA) to Enabled in the Red Hat Hybrid Cloud Console or your Red Hat Satellite instance.
- You have registered the cluster with Red Hat OpenShift Cluster Manager and have an active connection to the internet or a proxy to reach Red Hat services.
- You have confirmed that the
insights-configConfigMapexists in theopenshift-insightsnamespace.
Procedure
- To list the secrets in the
openshift-config-managednamespace, run the following command in a terminal:$ oc get secrets -n openshift-config-managed | grep etc-pki-entitlement
Verification
- Verify that the secrets match the cluster architecture (for example,
-amd64or-arm64) by checking the output of the list command to ensure the relevant secrets are present. The output shows secrets that include the name of the cluster’s architecture, and look similar to the following:etc-pki-entitlement Opaque 2 28hetc-pki-entitlement-amd64 Opaque 2 88setc-pki-entitlement-arm64 Opaque 2 88s
Configuring simple content access import interval
You can configure how often the Insights Operator imports the simple content access (sca) entitlements by using the insights-config ConfigMap object in the openshift-insights namespace. The entitlement import normally occurs every eight hours, but you can shorten this sca interval if you update your simple content access configuration in the insights-config ConfigMap object.
This procedure describes how to update the import interval to two hours (2h). You can specify hours (h) or hours and minutes, for example: 2h30m.
Prerequisites
- Remote health reporting is enabled, which is the default.
- You are logged in to the OpenShift Container Platform web console as a user with the
cluster-adminrole. - The insights-config
ConfigMapobject exists in theopenshift-insightsnamespace.
Procedure
- Go to Workloads → ConfigMaps and select Project: openshift-insights.
- Click on the insights-config
ConfigMapobject to open it. - Click Actions and select Edit ConfigMap.
- Click the YAML view radio button.
- Set the
scaattribute in the file tointerval: 2hto import content every two hours.apiVersion: v1kind: ConfigMap# ...data:config.yaml: |sca:interval: 2h# ... - Click Save. The insights-config config-map details page opens.
- Verify that the value of the
config.yamlscaattribute is set tointerval: 2h.
Disabling simple content access import
You can disable the importing of simple content access entitlements by using the insights-config ConfigMap object in the openshift-insights namespace.
Prerequisites
- Remote health reporting is enabled, which is the default.
- You are logged in to the OpenShift Container Platform web console as
cluster-admin. - The
insights-configConfigMapobject exists in theopenshift-insightsnamespace.
Procedure
- Go to Workloads → ConfigMaps and select Project: openshift-insights.
- Click the insights-config
ConfigMapobject to open it. - Click Actions and select Edit ConfigMap.
- Click YAML view.
- In the file, set the
scaattribute todisabled: true.apiVersion: v1kind: ConfigMap# ...data:config.yaml: |sca:disabled: true# ... - Click Save. The insights-config config-map details page opens.
- Verify that the value of the
config.yamlscaattribute is set todisabled: true.
Enabling a previously disabled simple content access import
If the importing of simple content access entitlements is disabled, the Insights Operator does not import simple content access entitlements. You can change this behavior.
Prerequisites
- Remote health reporting is enabled, which is the default.
- You have logged in to the OpenShift Container Platform web console as a user with the
cluster-adminrole. - The
insights-configConfigMapobject exists in theopenshift-insightsnamespace.
Procedure
- Go to Workloads → ConfigMaps and select Project: openshift-insights.
- Click on the insights-config
ConfigMapobject to open it. - Click Actions and select Edit ConfigMap.
- Click the YAML view radio button.
- In the file, set the
scaattribute todisabled: false.apiVersion: v1kind: ConfigMap# ...data:config.yaml: |sca:disabled: false# ... - Click Save. The insights-config config-map details page opens.
- Verify that the value of the
config.yamlscaattribute is set todisabled: false.