Convert RH Satellite from Disconnected to Connected?
Due to the long time it takes to get updated ISO content, install it, and needing to patch our RHEL servers quickly, we've decided to switch from a Disconnected Red Hat Satellite to a Connected Red Hat Satellite.
With this being said, I have a few ideas on what we will need to do:
-
Generate a new manifest
-
Re-register the Satellite again to RHSM
-
Re-register all clients to the RH Satellite
I might be missing other things too, however these are other questions that I have on this based on security and securely download content as well.
I'm not sure what daemon talks back to RHSM/CDN and I can't find anything in any RH Sat 6.1.10 documentation. However what is the name of the daemon?
Can we run this daemon as another user not root, in order to not have this connection go out of our network as something being ran by root?
Can we control when this daemon runs so it runs when we want it to run not something that automatically runs daily and then downloads the content.
Overall we want to control of when and how it downloads content, along with not running this at root, however we have to be able to grab content quicker then a Disconnected Satellite in order to keep our organization secure.
thanks
Responses
Christopher,
I am not an expert by any means, but here is what I understand.
The syncing process is done by the foreman-tasks service and is run by the user foreman, a non-login account.
You can initiate a sync/download manually at any time. However, syncing manually is done either one repository at a time, or by selecting multiple repositories and selecting "Synchronize Now."
For automatic syncing, you can create multiple sync plans. Unfortunately, the scheduling of the plan is a bit limited. Your choices are hourly, daily, or weekly. You can select the time of day, but that is about all.
You do not have to have all the repositories on the same plan. We currently have both a weekly and a daily plan, with some repositories in one plan and others in the other plan. You can even have multiple daily plans that download at different times of the day. If you wanted to run only once or twice a month, you would need to create a plan with all the repositories you wanted, disable it, and manually enable/run the plan at the time you wanted.
Hope that helps.
Yes, we did speak with the networking team when first setting up. We were asked to schedule our initial sync overnight at a time when network traffic was lighter. After the initial sync, packages come in ones and twos, unless there is a minor OS update (7.2 -> 7.3). It is larger than normal, but still much less than the initial sync. We still do our sync during the night when there is less traffic, but it is no longer a requirement. We have even added a repository or two and performed the initial sync on that repository during the day. We haven't had any troubles with overloading the network.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
