Este contenido no está disponible en el idioma seleccionado.

Chapter 3. Using token-based service accounts with remediation plans


If you use Red Hat Ansible Automation Platform (AAP) to view, download, and execute remediation plans, you can configure a token-based service account for use with both Red Hat Lightspeed and AAP. This configuration provides a more secure, scalable, and automation-friendly integration. In addition, you can view the remediation plans associated with the service account in both Red Hat Lightspeed and AAP.

3.1. About service accounts

Once you have configured the service account and set up User Access in Red Hat Lightspeed, the service account can securely access all remediation plans connected to that service account. You can also view, download, and execute playbooks for remediations from within AAP.

Note

Token-based service accounts replace Basic Authentication, which is no longer supported for connecting to the Red Hat Hybrid Cloud Console and Red Hat Lightspeed APIs.

3.2. Configuring the service account

You can create a new token-based service account in the Red Hat Hybrid Cloud Console to integrate with both Red Hat Lightspeed and AAP, or you can select an existing service account.

Prerequisites

  • You are logged into the Red Hat Hybrid Cloud Console as an Organization administrator.

Procedure

  1. In the Red Hat Hybrid Cloud Console, navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > Service Accounts.
  2. Create a token-based service account, or select an existing service account. For more information about creating service accounts, see Creating a service account.

    Important

    If you create a new service account, make sure to save the Client ID and Client secret to a safe location. If you select an existing service account, ensure that you have access to the Client ID and Client secret.

  3. Create a User Access group to associate to the service account, or assign the service account to an existing User Access group that has the required permissions. For more information about creating User Access groups, see Managing group access with roles and members.
  4. Assign the following permissions to the group, if the group does not already have them. For more information about how to add roles and permissions to a User Access group, see Adding a role to a group.

    • inventory:hosts:read (included in the Inventory Hosts viewer role)
    • patch:*:read* (included in the Patch viewer role)
    • remediations:remediation:read and playbook-dispatcher:run:read (included in the Remediations User role)

      Note

      You can also grant the RHEL viewer role to the service account in the User Access group. The RHEL viewer role includes the correct permissions for inventory:hosts:read and remediations:remediation:read.

      For more information about assigning a service account to a User Access group, see Adding service accounts to a User Access group.

      Note

      If your organization uses Workspaces, ensure that your User Access group has the necessary permissions for full visibility into your inventory in AAP. For more information about workspaces, see Workspaces.

3.3. Configuring credentials in the Ansible Automation Platform

Once you have configured the service account and User Access in the Red Hat Hybrid Cloud Console, you can create credentials in AAP.

Prerequisites

  • The Client ID and Client secret for the service account, which you obtained when you created or selected a service account in the Red Hat Hybrid Cloud Console.
  • Access to the Ansible Automation Platform (AAP) interface.

Procedure

  1. Create a new credential in AAP. The Create credential screen displays. For more information about how to create and configure credentials in AAP, see Creating Red Hat Insights credentials.
  2. In the Credential Type drop-down menu, select Insights as the credential type.
  3. Paste the Client ID and Client secret for the service account into the respective fields in the Type Details section.
  4. Click Create credential.

After you set up the service account in both Red Hat Lightspeed and AAP, you can view the remediation plans associated to the service account in Red Hat Lightspeed.

Prerequisites

  • You are logged in to the Red Hat Hybrid Cloud Console as an Organization Administrator.

Procedure

Additional resources

Red Hat logoGithubredditYoutubeTwitter

Aprender

Pruebe, compre y venda

Comunidades

Acerca de la documentación de Red Hat

Ayudamos a los usuarios de Red Hat a innovar y alcanzar sus objetivos con nuestros productos y servicios con contenido en el que pueden confiar. Explore nuestras recientes actualizaciones.

Hacer que el código abierto sea más inclusivo

Red Hat se compromete a reemplazar el lenguaje problemático en nuestro código, documentación y propiedades web. Para más detalles, consulte el Blog de Red Hat.

Acerca de Red Hat

Ofrecemos soluciones reforzadas que facilitan a las empresas trabajar en plataformas y entornos, desde el centro de datos central hasta el perímetro de la red.

Theme

© 2026 Red Hat
Volver arriba