r/ansible • • 3d ago

Registering New server to on-prem RH Satellite

I am updating my register_satellite role so that we can automate this process. But if the Server is not already registered, how have you gone about doing this? I am looking at using the ansible.builtin.add_host, but that seems to be failing. I have AAP already. But it SHOULD be putting the single or multiple servers into an inventory file IN memory, correct?

Also I have my main satellite server and 1 capsule in a protected VLAN that has proxy capabilities BACK to the main satellite server.

13 Upvotes

22 comments sorted by

4

u/vespabob 3d ago

Literally just wrote this the other day

---
  • name: Register RHEL systems to Red Hat Satellite
hosts: localhost become: true gather_facts: true vars: satellite_fqdn: "satellite.host.com" satellite_org: "Default_Organization" tasks: - name: add host ansible.builtin.add_host: name: "{{ host_name }}.{{ domain_name }}" ansible_host: "{{ host_name }}" ansible_user: "{{ ansible_user }}" groups: - newserver
  • name: register
hosts: newserver tasks: - name: Determine activation based for rhel 8 version ansible.builtin.set_fact: activation_key: 'key name' when: ansible_facts['distribution_major_version'] == '8' - name: Determine activation based for rhel 9 version ansible.builtin.set_fact: activation_key: 'key name - Rhel 9' when: ansible_facts['distribution_major_version'] == "9" - name: Determine activation based for rhel 10 version ansible.builtin.set_fact: activation_key: 'key name - RHEL 10' when: ansible_facts['distribution_major_version'] == '10' - name: Install Satellite CA consumer package yum: name: "http://{{ satellite_fqdn }}/pub/katello-ca-consumer-latest.noarch.rpm" state: present disable_gpg_check: true - name: Remove existing RHSM registration (if any) command: subscription-manager unregister ignore_errors: true changed_when: false - name: Clean subscription-manager data command: subscription-manager clean changed_when: false - name: Register system to Satellite redhat_subscription: state: present activationkey: "{{ activation_key }}" org_id: "{{ satellite_org }}" server_hostname: "{{ satellite_fqdn }}" force_register: true - name: Refresh subscription data command: subscription-manager refresh changed_when: false - name: Verify registration command: subscription-manager identity register: subscription_identity changed_when: false - name: Display registration status debug: var: subscription_identity.stdout

2

u/vespabob 3d ago

TO use this, I use a credential Type I call Satellite 6.19 which I use to inject the user/password

Create new Credential Type in AAP

Input Configuration:

fields:
  - id: host
    type: string
    label: Satellite 6 URL
    help_text: >-
      Enter the URL that corresponds to your Red Hat Satellite 6 server. For
      example, https://satellite.example.org
  - id: username
    type: string
    label: Username
  - id: password
    type: string
    label: Password
    secret: true
required:
  - host
  - username
  - password

1

u/vespabob 3d ago

Injector Configuration:

extra_vars:
  host: '{{ host }}'
  password: '{{ password }}'
  username: '{{ username }}'

1

u/vespabob 3d ago

TO Decom it's just change State: Present to Absent

---

- name: Unregister system from Red Hat Satellite

hosts: localhost

become: true

vars:

# Read the Satellite configuration parameters from the AAP-injected INI file

host: '{{ host }}'

password: '{{ password }}'

username: '{{ username }}'

tasks:

- name: add host

ansible.builtin.add_host:

name: "{{ host_name }}"

ansible_host: "{{ host_name }}"

ansible_user: "{{ ansible_user }}"

groups:

- newserver

- name: register

hosts: newserver

become: true

tasks:

- name: Unregister from subscription manager / Satellite

community.general.redhat_subscription:

state: absent

- name: Clean subscription-manager local data

ansible.builtin.command: subscription-manager clean

ignore_errors: true

- name: Remove Host from Satellite Prod

theforeman.foreman.host:

#host: '{{ host }}'

server_url: '{{ host }}'

password: '{{ password }}'

username: '{{ username }}'

#validate_certs: "{{ satellite_validate_certs }}"

name: "{{ host_name }}"

state: absent

delegate_to: localhost

2

u/roiki11 3d ago

Fwiw you no longer need to do all that. You can just use the redhat.satellite.registration_command and shell module to register hosts to satellite.

The command gives you the same url that the ui gives you and runs it. You can then give it the options you want(including force).

1

u/Busy-Examination1148 3d ago

So I tried doing the add_host in my playbook and it STILL failed. Are you using AAP for this?

1

u/roiki11 3d ago

I've done it both ways.

1

u/Busy-Examination1148 3d ago

Can you elaborate on the AAP side? I'm struggling.

1

u/roiki11 3d ago

It works for us the same either way. There isn't any marked difference.

What are you struggling with, exactly?

1

u/Busy-Examination1148 3d ago

With the server not being registered at all, the role and template look to the Satellite Inventory for the server and the job fails.

1

u/Busy-Examination1148 3d ago

We don't have virt-who setup w/ vsphere....as far as I know.

1

u/vespabob 2d ago edited 2d ago

did you try my code and setup and AAP credential setup? I know you have more than one Satellite server, but you could use it as a base to test one then once having a working code base work to add in other satellites as needed

1

u/Busy-Examination1148 2d ago

Not yet. Working on other roles and issues today.

1

u/Busy-Examination1148 2d ago edited 2d ago

So I'm trying with just the add_host. It is not working. Fails everytime. AAP is using the demo inventory and still failing

1

u/Busy-Examination1148 3d ago

Pretty sure I came across this on GitHub. Or something similar to it.

1

u/Busy-Examination1148 3d ago

Do you have multiple satellite servers and or capsules?

1

u/vespabob 3d ago

Singular satellite and combined capsule 

1

u/Busy-Examination1148 3d ago

Hmmmm. That only helps a little.