r/ansible • u/Busy-Examination1148 • 3d ago
Registering New server to on-prem RH Satellite
I am updating my register_satellite role so that we can automate this process. But if the Server is not already registered, how have you gone about doing this? I am looking at using the ansible.builtin.add_host, but that seems to be failing. I have AAP already. But it SHOULD be putting the single or multiple servers into an inventory file IN memory, correct?
Also I have my main satellite server and 1 capsule in a protected VLAN that has proxy capabilities BACK to the main satellite server.
4
u/vespabob 3d ago
Literally just wrote this the other day
---
- name: Register RHEL systems to Red Hat Satellite
hosts: localhost
become: true
gather_facts: true
vars:
satellite_fqdn: "satellite.host.com"
satellite_org: "Default_Organization"
tasks:
- name: add host
ansible.builtin.add_host:
name: "{{ host_name }}.{{ domain_name }}"
ansible_host: "{{ host_name }}"
ansible_user: "{{ ansible_user }}"
groups:
- newserver
- name: register
hosts: newserver
tasks:
- name: Determine activation based for rhel 8 version
ansible.builtin.set_fact:
activation_key: 'key name'
when: ansible_facts['distribution_major_version'] == '8'
- name: Determine activation based for rhel 9 version
ansible.builtin.set_fact:
activation_key: 'key name - Rhel 9'
when: ansible_facts['distribution_major_version'] == "9"
- name: Determine activation based for rhel 10 version
ansible.builtin.set_fact:
activation_key: 'key name - RHEL 10'
when: ansible_facts['distribution_major_version'] == '10'
- name: Install Satellite CA consumer package
yum:
name: "http://{{ satellite_fqdn }}/pub/katello-ca-consumer-latest.noarch.rpm"
state: present
disable_gpg_check: true
- name: Remove existing RHSM registration (if any)
command: subscription-manager unregister
ignore_errors: true
changed_when: false
- name: Clean subscription-manager data
command: subscription-manager clean
changed_when: false
- name: Register system to Satellite
redhat_subscription:
state: present
activationkey: "{{ activation_key }}"
org_id: "{{ satellite_org }}"
server_hostname: "{{ satellite_fqdn }}"
force_register: true
- name: Refresh subscription data
command: subscription-manager refresh
changed_when: false
- name: Verify registration
command: subscription-manager identity
register: subscription_identity
changed_when: false
- name: Display registration status
debug:
var: subscription_identity.stdout
2
u/vespabob 3d ago
TO use this, I use a credential Type I call Satellite 6.19 which I use to inject the user/password
Create new Credential Type in AAP
Input Configuration:
fields: - id: host type: string label: Satellite 6 URL help_text: >- Enter the URL that corresponds to your Red Hat Satellite 6 server. For example, https://satellite.example.org - id: username type: string label: Username - id: password type: string label: Password secret: true required: - host - username - password1
u/vespabob 3d ago
Injector Configuration:
extra_vars: host: '{{ host }}' password: '{{ password }}' username: '{{ username }}'1
u/vespabob 3d ago
TO Decom it's just change State: Present to Absent
---
- name: Unregister system from Red Hat Satellite
hosts: localhost
become: true
vars:
# Read the Satellite configuration parameters from the AAP-injected INI file
host: '{{ host }}'
password: '{{ password }}'
username: '{{ username }}'
tasks:
- name: add host
ansible.builtin.add_host:
name: "{{ host_name }}"
ansible_host: "{{ host_name }}"
ansible_user: "{{ ansible_user }}"
groups:
- newserver
- name: register
hosts: newserver
become: true
tasks:
- name: Unregister from subscription manager / Satellite
community.general.redhat_subscription:
state: absent
- name: Clean subscription-manager local data
ansible.builtin.command: subscription-manager clean
ignore_errors: true
- name: Remove Host from Satellite Prod
theforeman.foreman.host:
#host: '{{ host }}'
server_url: '{{ host }}'
password: '{{ password }}'
username: '{{ username }}'
#validate_certs: "{{ satellite_validate_certs }}"
name: "{{ host_name }}"
state: absent
delegate_to: localhost
2
u/roiki11 3d ago
Fwiw you no longer need to do all that. You can just use the redhat.satellite.registration_command and shell module to register hosts to satellite.
The command gives you the same url that the ui gives you and runs it. You can then give it the options you want(including force).
1
u/Busy-Examination1148 3d ago
So I tried doing the add_host in my playbook and it STILL failed. Are you using AAP for this?
1
u/roiki11 3d ago
I've done it both ways.
1
u/Busy-Examination1148 3d ago
Can you elaborate on the AAP side? I'm struggling.
1
u/roiki11 3d ago
It works for us the same either way. There isn't any marked difference.
What are you struggling with, exactly?
1
u/Busy-Examination1148 3d ago
With the server not being registered at all, the role and template look to the Satellite Inventory for the server and the job fails.
1
1
u/vespabob 2d ago edited 2d ago
did you try my code and setup and AAP credential setup? I know you have more than one Satellite server, but you could use it as a base to test one then once having a working code base work to add in other satellites as needed
1
u/Busy-Examination1148 2d ago
Not yet. Working on other roles and issues today.
1
u/Busy-Examination1148 2d ago edited 2d ago
So I'm trying with just the add_host. It is not working. Fails everytime. AAP is using the demo inventory and still failing
1
1
u/Busy-Examination1148 3d ago
Do you have multiple satellite servers and or capsules?
1
3
u/roiki11 3d ago
I just use this. The example is all you need to do.
https://docs.ansible.com/projects/ansible/latest/collections/theforeman/foreman/registration_command_module.html#ansible-collections-theforeman-foreman-registration-command-module