Getting Started with Red Hat Insights with FedRAMP


Red Hat Insights 1-latest

How to start using Red Hat Insights

Red Hat Customer Content Services

Abstract

This document provides starting points and resources for registering and installing Red Hat Insights for Red Hat Enterprise Linux and Red Hat OpenShift Container Platform with FedRAMP®.
Red Hat is committed to replacing problematic language in our code, documentation, and web properties. We are beginning with these four terms: master, slave, blacklist, and whitelist. Because of the enormity of this endeavor, these changes will be implemented gradually over several upcoming releases. For more details, see our CTO Chris Wright's message.

Chapter 1. About Red Hat Insights

Powered by predictive analytics, Red Hat Insights gets smarter with every additional piece of intelligence and data. It can automatically discover relevant insights, recommend tailored, proactive, next actions, and even automate tasks. Using Red Hat Insights, customers can benefit from the experience and technical knowledge of Red Hat Certified Engineers, making it easier to identify, prioritize and resolve issues before business operations are affected.

As a SaaS offering, Red Hat Insights is regularly updated. Regular updates expand the Insights knowledge archive in real time to reflect new IT challenges that can impact the stability of mission-critical systems.

Chapter 2. Installing Red Hat Insights for Red Hat Enterprise Linux (RHEL)

This document provides starting points and resources for registering systems to Red Hat Insights for Red Hat Enterprise Linux.

Installation of Red Hat Insights typically involves installing the Insights client, then registering systems for use with Insights. You can use different methods to register and install Insights. A registration assistant is also available to guide you through the process of registering and installing Insights. You can also use the Remote Host Configuration (RHC) tool. The installation method you use can depend on conditions such as,

  • Whether you are connecting to Red Hat for the first time
  • Whether you use a certain version of RHEL
  • Whether you want to do an automated installation or manual install
  • Other factors

2.1. Installing Red Hat Insights on Red Hat Enterprise Linux Satellite-managed hosts

To install Insights on Red Hat Enterprise Linux hosts managed by Red Hat Satellite, see:

2.2. Registering and configuring Satellite Server integration with FedRAMP

Before you can use Insights with your server, you need to connect your servers to the Satellite Server. The Satellite Server enables your servers to communicate with Red Hat Insights.

An IP address-based allow list restricts network access to the Insights service. This ensures that only the servers and ports that you specify can connect to the Satellite Server.

Note

Red Hat Insights subscription services are currently not available in the FedRAMP environment. Red Hat continuously evaluates service offerings, and will announce any updates or expansions to the FedRAMP environment as they become available.

Note

The following requirements are in addition to existing Satellite Server connectivity requirements to the Red Hat Content Delivery Network and Red Hat Subscription Management (RHSM) for software updates. For more information about connectivity requirements, refer to How to access Red Hat Subscription Manager (RHSM) through a firewall or proxy.

Prerequisites

  • The Satellite Server must be able to connect to the domain mtls.console.stage.openshiftusgov.com, using the HTTPS protocol on port 443.
  • You must provide a static public egress IP address (or address range) from which Satellite traffic will originate.

    Note

    Contact Red Hat Support to set up the public egress IP address.

    The public egress IP address is an additional IP address on the primary network interface of your server.

  • You are logged in to the Hybrid Cloud Console (https://console.openshiftusgov.com) as an Organization Administrator.
  • You have administrator ssh access to the Satellite server.
  • You are logged in to the Satellite Server using ssh.

Procedure

  1. From the main menu, navigate to Inventory > Configure Satellites. The Configure Satellites page displays.
  2. Click Generate Token to create the registration token for your organization.
  3. Copy the token.
  4. Open a terminal window on your Satellite Server and enter the following command:

    Copy to Clipboard Toggle word wrap
    # hammer organization list

    The system returns your organization ID. Make note of it for the next step.

  5. Copy the command shown in Step 3 on the Configure Satellites page. Paste it into the terminal. Substitute the organization ID for <organization_id>.

    Copy to Clipboard Toggle word wrap
    # SATELLITE_RH_CLOUD_URL=https://mtls.console.openshiftusgov.com org_id=<organization_id> foreman-rake rh_cloud:hybridcloud_register

    The system returns a prompt for the token that you generated.

  6. Paste the generated token that you copied at the prompt and press Enter.

    The system returns a success message. You can now register the system with Satellite and run insights-client.

2.3. Managing trusted IP addresses with an IP allowlist

Before you can connect Insights to your Satellite servers, you need to configure an allowlist that contains a trusted IP address (or range of IP addresses). You can configure the allowlist in two ways:

  • Provide the trusted IP address (or addresses) to Red Hat stateside support during onboarding. Support uses the IP addresses to configure an allowlist for Insights. This allowlist allows network traffic from your Satellite-controlled environment into Insights. To configure the allowlist, contact stateside support through ServiceNow and mention that you want to connect your satellite servers to Insights.
  • If you have not created the allowlist during onboarding, use the IP allowlist in the Manage Satellites page in the Red Hat Hybrid Cloud Console to manually add trusted IP addresses.

2.3.1. Adding trusted IP addresses to an allowlist

You can use Manage Satellites to create an allowlist, or add an IP address (or a range of IP addresses) to an existing allowlist. Adding IP addresses enables additional FedRAMP users in your organization to access the Red Hat Hybrid Cloud Console.

Note

Manage Satellites allows only IPv4 addresses. It does not support IPv6 addresses.

To add a range of IP addresses, use CIDR notation (for example, 226.167.71.76/32).

Prerequisites

  • You have Organization Administrator permissions.
  • You are logged in to the Hybrid Cloud Console.

Procedure

  1. Click Manage Satellites. The Manage Satellites page displays.
  2. Scroll down the page to the IP Address Allowlist section at the bottom.

    IP Address Allowlist on Managed Satellites page
  3. Click Add IP Addresses. The Add IP Addresses to Allowlist dialog box displays.

    Add IP Addresses to Allowlist dialog box
  4. Type an IP address (or range of IP addresses) and click Submit. The IP addresses appear on the allowlist.

    IP address range shown in allowlist

2.3.2. Removing IP addresses from the allowlist

Prerequisites

  • You have Organization Administrator permissions.
  • You are logged in to the Hybrid Cloud Console.
  • You have an IP allowlist configured.
  • You have added at least one IP address (or range of IP addresses) to the allowlist.

Procedure

  1. Click Manage Satellites. The Manage Satellites page displays.
  2. Scroll down the page to the IP Address Allowlist section at the bottom.
  3. Select the IP address you want to remove, and then click Remove. The Remove IP Addresses from Allowlist dialog box displays.

    Remove IP Addresses dialog box
  4. Click Remove, and then click Submit.

Additional resources

Chapter 3. User Access settings in the Red Hat Hybrid Cloud Console

User Access is the Red Hat implementation of role-based access control (RBAC). Your Organization Administrator uses User Access to configure what users can see and do on the Red Hat Hybrid Cloud Console (the console):

  • Control user access by organizing roles instead of assigning permissions individually to users.
  • Create groups that include roles and their corresponding permissions.
  • Assign users to these groups, allowing them to inherit the permissions associated with their group’s roles.

All users on your account have access to most of the data in Insights for Red Hat Enterprise Linux.

3.1. Predefined User Access groups and roles

To make groups and roles easier to manage, Red Hat provides two predefined groups and a set of predefined roles.

3.1.1. Predefined groups

The Default access group contains all users in your organization. Many predefined roles are assigned to this group. It is automatically updated by Red Hat.

Note

If the Organization Administrator makes changes to the Default access group its name changes to Custom default access group and it is no longer updated by Red Hat.

The Default admin access group contains only users who have Organization Administrator permissions. This group is automatically maintained and users and roles in this group cannot be changed.

On the Hybrid Cloud Console navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > Identity & Access Management > User Access > Groups to see the current groups in your account. This view is limited to the Organization Administrator.

3.1.2. Predefined roles assigned to groups

The Default access group contains many of the predefined roles. Because all users in your organization are members of the Default access group, they inherit all permissions assigned to that group.

The Default admin access group includes many (but not all) predefined roles that provide update and delete permissions. The roles in this group usually include administrator in their name.

On the Hybrid Cloud Console navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > Identity & Access Management > User Access > Roles to see the current roles in your account. You can see how many groups each role is assigned to. This view is limited to the Organization Administrator.

3.2. Access permissions

The Prerequisites for each procedure list which predefined role provides the permissions you must have. As a user, you can navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > My User Access to view the roles and application permissions currently inherited by you.

If you try to access Insights for Red Hat Enterprise Linux features and see a message that you do not have permission to perform this action, you must obtain additional permissions. The Organization Administrator or the User Access administrator for your organization configures those permissions.

Additional resources

For more information about user access and permissions, see User Access Configuration Guide for Role-based Access Control (RBAC) with FedRAMP.

Providing feedback on Red Hat documentation

We appreciate and prioritize your feedback regarding our documentation. Provide as much detail as possible, so that your request can be quickly addressed.

Prerequisites

  • You are logged in to the Red Hat Customer Portal.

Procedure

To provide feedback, perform the following steps:

  1. Click the following link: Create Issue
  2. Describe the issue or enhancement in the Summary text box.
  3. Provide details about the issue or requested enhancement in the Description text box.
  4. Type your name in the Reporter text box.
  5. Click the Create button.

This action creates a documentation ticket and routes it to the appropriate documentation team. Thank you for taking the time to provide feedback.

Legal Notice

Copyright © 2025 Red Hat, Inc.
The text of and illustrations in this document are licensed by Red Hat under a Creative Commons Attribution–Share Alike 3.0 Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is available at http://creativecommons.org/licenses/by-sa/3.0/. In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shadowman logo, the Red Hat logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other countries.
Node.js® is an official trademark of Joyent. Red Hat is not formally related to or endorsed by the official Joyent Node.js open source or commercial project.
The OpenStack® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.
All other trademarks are the property of their respective owners.
Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat, Inc.