Using remote health reporting in a restricted network¶
You can manually gather and upload Insights Operator archives to diagnose issues from a restricted network.
To use the Insights Operator in a restricted network, you must complete the following tasks:
- Create a copy of your Insights Operator archive.
- Upload the Insights Operator archive to the Red Hat Hybrid Cloud Console.
Additionally, you can select to obfuscate the Insights Operator data before data upload.
Additional resources
Running an Insights Operator gather operation¶
You must run a gather operation to create an Insights Operator archive.
Prerequisites
- You are logged in to OpenShift Container Platform as
cluster-admin.
Procedure
-
Create a file named
gather-job.yamlusing this template:
apiVersion: batch/v1 kind: Job metadata: name: insights-operator-job annotations: config.openshift.io/inject-proxy: insights-operator spec: backoffLimit: 6 ttlSecondsAfterFinished: 600 template: spec: restartPolicy: OnFailure serviceAccountName: operator nodeSelector: beta.kubernetes.io/os: linux node-role.kubernetes.io/master: "" tolerations: - effect: NoSchedule key: node-role.kubernetes.io/master operator: Exists - effect: NoExecute key: node.kubernetes.io/unreachable operator: Exists tolerationSeconds: 900 - effect: NoExecute key: node.kubernetes.io/not-ready operator: Exists tolerationSeconds: 900 volumes: - name: snapshots emptyDir: {} - name: service-ca-bundle configMap: name: service-ca-bundle optional: true initContainers: - name: insights-operator image: quay.io/openshift/origin-insights-operator:latest terminationMessagePolicy: FallbackToLogsOnError volumeMounts: - name: snapshots mountPath: /var/lib/insights-operator - name: service-ca-bundle mountPath: /var/run/configmaps/service-ca-bundle readOnly: true ports: - containerPort: 8443 name: https resources: requests: cpu: 10m memory: 70Mi args: - gather - -v=4 - --config=/etc/insights-operator/server.yaml containers: - name: sleepy image: quay.io/openshift/origin-base:latest args: - /bin/sh - -c - sleep 10m volumeMounts: [{name: snapshots, mountPath: /var/lib/insights-operator}] ```
-
Copy your
insights-operatorimage version:Example outputapiVersion: apps/v1 kind: Deployment metadata: name: insights-operator namespace: openshift-insights # ... spec: template: # ... spec: containers: - args: # ... image: registry.ci.openshift.org/ocp/4.15-2023-10-12-212500@sha256:a0aa581400805ad0... # ...The
spec.template.spec.containers.imagefield specifies yourinsights-operatorimage version. -
Paste your image version in
gather-job.yaml:apiVersion: batch/v1 kind: Job metadata: name: insights-operator-job # ... spec: # ... template: spec: initContainers: - name: insights-operator image: image: registry.ci.openshift.org/ocp/4.15-2023-10-12-212500@sha256:a0aa581400805ad0... terminationMessagePolicy: FallbackToLogsOnError volumeMounts:Replace the value of
spec.template.initContainers.imagewith yourinsights-operatorimage version. -
Create the gather job:
-
Find the name of the job pod:
Example outputName: insights-operator-job Namespace: openshift-insights # ... Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal SuccessfulCreate 7m18s job-controller Created pod: insights-operator-job-<your_job>Replace
insights-operator-job-<your_job>with the name of the pod. -
Verify that the operation has finished:
-
Save the created archive:
-
Clean up the job:
Uploading an Insights Operator archive¶
You can manually upload an Insights Operator archive to console.redhat.com to diagnose potential issues.
Prerequisites
- You are logged in to OpenShift Container Platform as
cluster-admin. - You have a workstation with unrestricted internet access.
- You have created a copy of the Insights Operator archive.
Procedure
-
Download the
dockerconfig.jsonfile: -
Copy your
"cloud.openshift.com""auth"token from thedockerconfig.jsonfile: -
Upload the archive to console.redhat.com:
$ curl -v -H "User-Agent: insights-operator/one10time200gather184a34f6a168926d93c330 cluster/_<cluster_id>_" -H "Authorization: Bearer _<your_token>_" -F "upload=@_<path_to_archive>_; type=application/vnd.redhat.openshift.periodic+tar" https://console.redhat.com/api/ingress/v1/uploadwhere:
<cluster_id>- Specifies the cluster ID.
<your_token>- Specifies the token from your pull secret.
<path_to_archive>- Specifies the path to the Insights Operator archive. If the operation is successful, the command returns a
"request_id"and"account_number":
Verification
-
Log in to https://console.redhat.com/openshift.
-
Click the Cluster List menu in the left pane.
-
To display the details of the cluster, click the cluster name.
-
Open the Red Hat Lightspeed Advisor tab of the cluster.
If the upload was successful, the tab displays one of the following:
- Your cluster passed all recommendations, if the Red Hat Lightspeed advisor service did not identify any issues.
- A list of issues that the Red Hat Lightspeed advisor service has detected, prioritized by risk (low, moderate, important, and critical).
Enabling Insights Operator data obfuscation¶
You can enable obfuscation to mask sensitive and identifiable IPv4 addresses and cluster base domains that the Insights Operator sends to console.redhat.com.
Warning
Although this feature is available, Red Hat recommends keeping obfuscation disabled for a more effective support experience.
Obfuscation assigns non-identifying values to cluster IPv4 addresses, and uses a translation table that is retained in memory to change IP addresses to their obfuscated versions throughout the Insights Operator archive before uploading the data to console.redhat.com.
For cluster base domains, obfuscation changes the base domain to a hardcoded substring. For example, cluster-api.openshift.example.com becomes cluster-api.<CLUSTER_BASE_DOMAIN>.
The following procedure enables obfuscation using the support secret in the openshift-config namespace.
Prerequisites
- You are logged in to the OpenShift Container Platform web console as
cluster-admin.
Procedure
- Navigate to Workloads → Secrets.
- Select the openshift-config project.
- Search for the support secret using the Search by name field. If it does not exist, click Create → Key/value secret to create it.
- Click the Options menu
, and then click Edit Secret. - Click Add Key/Value.
- Create a key named
enableGlobalObfuscationwith a value oftrue, and click Save. - Navigate to Workloads → Pods
- Select the
openshift-insightsproject. - Find the
insights-operatorpod. - To restart the
insights-operatorpod, click the Options menu
, and then click Delete Pod.
Verification
-
Navigate to Workloads → Secrets.
-
Select the openshift-insights project.
-
Search for the obfuscation-translation-table secret using the Search by name field.
If the
obfuscation-translation-tablesecret exists, then obfuscation is enabled and working.Alternatively, you can inspect
/insights-operator/gathers.jsonin your Insights Operator archive for the value"is_global_obfuscation_enabled": true.
Additional resources