---
title: Simple Content Access entitlements with Insights Operator
---

# Simple Content Access entitlements with Insights Operator {#insights-operator-simple-access}

Insights Operator automates the import of Simple Content Access (SCA) entitlement certificates every 8 hours. These Red Hat Subscription Management (RHSM) certificates allow the cluster to authenticate with the Red Hat Content Delivery Network (CDN) to access subscription-governed content.

SCA supports multi-architecture clusters by generating architecture-specific secrets, such as `amd64` or `arm64`, in the `openshift-config-managed` namespace to ensure compatibility across all worker node types.

**Additional resources**
{._additional-resources}

- [About simple content access](https://access.redhat.com/documentation/en-us/subscription_central/2021/html-single/getting_started_with_simple_content_access/index#assembly-about-simplecontent)
- [Using Red Hat subscriptions in builds](/openshift-docs-markdown/cicd/builds/running-entitled-builds#builds-running-entitled-builds-with-sharedsecret-objects_running-entitled-builds)

## Simple Content Access entitlement synchronization {#insights-operator-sca-entitlement-synchronization_remote-health-reporting-from-restricted-network}

Simple Content Access (SCA) simplifies subscription management by removing the requirement to manually attach entitlement keys to individual nodes. Insights Operator facilitates this by automatically retrieving and storing certificates as secrets within the `openshift-config-managed` namespace. These certificates allow the cluster to authenticate with Red Hat content repositories for operations such as entitled builds.

Entitlement secrets refresh automatically every 8 hours. While older configurations used a support secret in the `openshift-config` namespace, Insights Operator now prioritizes the `insights-config` `ConfigMap` in the `openshift-insights` namespace if both exist.

> [!NOTE]
> Simple content access must be enabled in Red Hat Subscription Management for the importing to function.

## Architecture-specific entitlement secrets {#insights-operator-architecture-based-entitlement-secrets_remote-health-reporting-from-restricted-network}

The certificates generated by the Insights Operator are based on the worker node architectures that are detected within the cluster. The two types of supported clusters include single-architecture clusters and multi-architecture clusters.

**Single-architecture clusters:** When all worker nodes use the same architecture, a single secret named `etc-pki-entitlement` is created.

**Multi-architecture clusters:** When worker nodes use different architectures, such as a mix of `x86_64` and `aarch64`, a secret is created for each architecture present. These secrets use architecture-specific suffixes, such as `etc-pki-entitlement-amd64` or `etc-pki-entitlement-arm64`.

## Verify and manage entitlement secrets {#insights-operator-verify-manage-entitlement-secrets_remote-health-reporting-from-restricted-network}

To verify the imported entitlement secrets, list architecture-specific secrets and change the import behavior with the {insights_Operator} configuration.

**Prerequisites**

- You have cluster-admin permissions for the OpenShift Container Platform cluster.
- You have set Simple Content Access (SCA) to **Enabled** in the Red Hat Hybrid Cloud Console or your Red Hat Satellite instance.
- You have registered the cluster with Red Hat OpenShift Cluster Manager and have an active connection to the internet or a proxy to reach Red Hat services.
- You have confirmed that the `insights-config` `ConfigMap` exists in the `openshift-insights` namespace.

**Procedure**

- To list the secrets in the `openshift-config-managed` namespace, run the following command in a terminal:

  ```terminal
  $ oc get secrets -n openshift-config-managed | grep etc-pki-entitlement
  ```

**Verification**

- Verify that the secrets match the cluster architecture (for example, `-amd64` or `-arm64`) by checking the output of the list command to ensure the relevant secrets are present. The output shows secrets that include the name of the cluster’s architecture, and look similar to the following:

  ```terminal
  etc-pki-entitlement                 Opaque                    2      28h
  etc-pki-entitlement-amd64           Opaque                    2      88s
  etc-pki-entitlement-arm64           Opaque                    2      88s
  ```

## Configuring simple content access import interval {#insights-operator-configuring-sca_remote-health-reporting-from-restricted-network}

You can configure how often the Insights Operator imports the simple content access (sca) entitlements by using the `insights-config` `ConfigMap` object in the `openshift-insights` namespace. The entitlement import normally occurs every eight hours, but you can shorten this sca interval if you update your simple content access configuration in the `insights-config` `ConfigMap` object.

This procedure describes how to update the import interval to two hours (2h). You can specify hours (h) or hours and minutes, for example: 2h30m.

**Prerequisites**

- Remote health reporting is enabled, which is the default.
- You are logged in to the OpenShift Container Platform web console as a user with the `cluster-admin` role.
- The **insights-config** `ConfigMap` object exists in the `openshift-insights` namespace.

**Procedure**

1. Go to **Workloads** → **ConfigMaps** and select **Project: openshift-insights**.
2. Click on the **insights-config** `ConfigMap` object to open it.
3. Click **Actions** and select **Edit ConfigMap**.
4. Click the **YAML view** radio button.
5. Set the `sca` attribute in the file to `interval: 2h` to import content every two hours.

   ```yaml
   apiVersion: v1
   kind: ConfigMap
   # ...
   data:
     config.yaml: |
       sca:
         interval: 2h
   # ...
   ```
6. Click **Save**. The **insights-config** config-map details page opens.
7. Verify that the value of the `config.yaml` `sca` attribute is set to `interval: 2h`.

### Disabling simple content access import {#insights-operator-disabling-sca_remote-health-reporting-from-restricted-network}

You can disable the importing of simple content access entitlements by using the `insights-config` `ConfigMap` object in the `openshift-insights` namespace.

**Prerequisites**

- Remote health reporting is enabled, which is the default.
- You are logged in to the OpenShift Container Platform web console as `cluster-admin`.
- The `insights-config` `ConfigMap` object exists in the `openshift-insights` namespace.

**Procedure**

1. Go to **Workloads** → **ConfigMaps** and select **Project: openshift-insights**.
2. Click the **insights-config** `ConfigMap` object to open it.
3. Click **Actions** and select **Edit ConfigMap**.
4. Click **YAML view**.
5. In the file, set the `sca` attribute to `disabled: true`.

   ```yaml
   apiVersion: v1
   kind: ConfigMap
   # ...
   data:
     config.yaml: |
       sca:
         disabled: true
   # ...
   ```
6. Click **Save**. The **insights-config** config-map details page opens.
7. Verify that the value of the `config.yaml` `sca` attribute is set to `disabled: true`.

### Enabling a previously disabled simple content access import {#insights-operator-enabling-sca_remote-health-reporting-from-restricted-network}

If the importing of simple content access entitlements is disabled, the Insights Operator does not import simple content access entitlements. You can change this behavior.

**Prerequisites**

- Remote health reporting is enabled, which is the default.
- You have logged in to the OpenShift Container Platform web console as a user with the `cluster-admin` role.
- The `insights-config` `ConfigMap` object exists in the `openshift-insights` namespace.

**Procedure**

1. Go to **Workloads** → **ConfigMaps** and select **Project: openshift-insights**.
2. Click on the **insights-config** `ConfigMap` object to open it.
3. Click **Actions** and select **Edit ConfigMap**.
4. Click the **YAML view** radio button.
5. In the file, set the `sca` attribute to `disabled: false`.

   ```yaml
   apiVersion: v1
   kind: ConfigMap
   # ...
   data:
     config.yaml: |
       sca:
         disabled: false
   # ...
   ```
6. Click **Save**. The **insights-config** config-map details page opens.
7. Verify that the value of the `config.yaml` `sca` attribute is set to `disabled: false`.
