Este conteúdo não está disponível no idioma selecionado.

Chapter 1. Remediations overview


After identifying the highest remediation priorities in your Red Hat Enterprise Linux (RHEL) infrastructure, you can create and execute remediation plans to fix those issues.

Remediations enables you to address the following on your connected RHEL systems:

  • Advisor recommendations
  • Content advisories
  • Vulnerability CVEs
  • Failed compliance rules found by Red Hat Insights

You can remediate a single issue or a related group of issues by using a pathway in Insights. Pathways group multiple advisor recommendations under common actions for better efficiency. For more information, see Remediating pathways in Assessing RHEL Configuration Issues Using the Red Hat Insights Advisor Service.

For some issues, Red Hat Insights provides several different remediation paths.

When you create a remediation plan, Insights generates an Ansible Playbook to implement the required remediation actions and apply any required patches on affected systems in your RHEL infrastructure.

Some issues require a manual fix and cannot be resolved by executing a remediation plan in Insights. You can determine whether it’s possible to remediate a problem within Insights by checking the Resolution type value of the issue or recommendation.

Resolution types

In Insights, an issue or recommendation for remediation can be one of two types:

  • Manual: Red Hat Insights provides the manual remediation steps needed to fix or address all issues and recommendations, including whether the system requires a reboot for the remediation to take effect.
  • Playbook: For many issues, Insights also provides a pre-built remediation playbook automating the required resolution steps, which you can either:

    • Run on your systems from within Insights
    • Download and run externally in your Ansible Playbooks environment

Insights remediations workflow

  • Choose an issue or recommendation

    • The first step to creating a remediation plan is to choose an issue or recommendation that Red Hat Insights has detected on one or more of your RHEL systems.
  • Review the recommended resolution path

    • Determine which versions of RHEL are affected and whether or not a playbook is available. You can only create a remediation plan in Red Hat Insights if a pre-built playbook exists.
  • Decide which RHEL systems to remediate

    • When you have reviewed the recommended resolution steps and determined whether a playbook is available to remediate the issue, choose which systems to include in the plan.

      Important

      To create a remediation plan for a group of systems, you must ensure that all systems in the group are running the same RHEL major and minor versions to ensure that the resolution applied by the Red Hat Insights-generated playbook is compatible.

  • Create a remediation plan

    • The Insights UI provides a wizard to help you create a remediation plan, which is accessible from the advisor, compliance, vulnerability, and patch service pages. You can start the wizard for creating a remediation plan by clicking Plan remediation after you have selected at least one system and an issue or recommendation for remediation. You can also create a remediation plan from the details page of a system, provided Insights has detected issues that impact the system.
  • Decide how you want to execute your remediation plan

    • You can execute a remediation plan from within Insights on directly connected Red Hat Enterprise Linux systems without additional subscriptions or tools. You can also download and run the associated playbook on your organization’s Ansible Automation Platform (AAP) workflow.

Subscription requirements

  • Red Hat Insights for Red Hat Enterprise Linux is included with every RHEL subscription. No additional subscriptions are required to use Insights remediation features.

User requirements

  • By default, all Insights users automatically have access to read, create, and manage remediation plans.
  • To remediate your Red Hat Enterprise Linux systems from Insights, you also need:

    • Access to Insights for Red Hat Enterprise Linux on the Red Hat Hybrid Cloud Console (Hybrid Cloud Console).
    • If using Red Hat Satellite, access to Satellite-managed systems on the console or in the Satellite application UI.
    • The required Hybrid Cloud Console User Access roles for managing and executing remediation plans.
Important

While all Insights users automatically have access to read, create, and manage remediation plans, to execute a remediation plan in Insights, you need the Remediations administrator predefined User Access role. User Access roles can be granted by your Organization Administrator in Identity & Access Management settings on the Hybrid Cloud Console.

Remote host connectivity

To execute remediations, you must set up and enable the remote host configuration (rhc) within Insights.

You will also need to permit Insights users to execute remediation playbooks on rhc-connected systems, which can be done by enabling the Remote Host Configuration Manager (rhc) setting in Insights, provided you have the required administrative permissions.

1.1. Getting started with remediations by using an interactive quick start

To help you get started with remediations, an interactive quick start is available in Insights on the Hybrid Cloud Console. The Creating and executing remediation plans quick start guides you through the process in under 10 minutes and provides links to additional resources.

Prerequisites

  • You must have a Red Hat Hybrid Cloud Console account and be subscribed to the Insights for Red Hat Enterprise Linux services.

Procedure

  1. Log on to Red Hat Hybrid Cloud Console and then navigate to the Insights services.
  2. To access the quick start, use one of the following steps:

1.2. User Access settings in the Red Hat Hybrid Cloud Console

User Access is the Red Hat implementation of role-based access control (RBAC). Your Organization Administrator uses User Access to configure what users can see and do on the Red Hat Hybrid Cloud Console (the console):

  • Control user access by organizing roles instead of assigning permissions individually to users.
  • Create groups that include roles and their corresponding permissions.
  • Assign users to these groups, allowing them to inherit the permissions associated with their group’s roles.

1.2.1. Predefined User Access groups and roles

To make groups and roles easier to manage, Red Hat provides two predefined groups and a set of predefined roles:

  • Predefined groups

    The Default access group contains all users in your organization. Many predefined roles are assigned to this group. It is automatically updated by Red Hat.

    Note

    If the Organization Administrator makes changes to the Default access group its name changes to Custom default access group and it is no longer updated by Red Hat.

    The Default admin access group contains only users who have Organization Administrator permissions. This group is automatically maintained and users and roles in this group cannot be changed.

    On the Hybrid Cloud Console navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > Identity & Access Management > User Access > Groups to see the current groups in your account. This view is limited to the Organization Administrator.

  • Predefined roles assigned to groups

    The Default access group contains many of the predefined roles. Because all users in your organization are members of the Default access group, they inherit all permissions assigned to that group.

    The Default admin access group includes many (but not all) predefined roles that provide update and delete permissions. The roles in this group usually include administrator in their name.

    On the Hybrid Cloud Console navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > Identity & Access Management > User Access > Roles to see the current roles in your account. You can see how many groups each role is assigned to. This view is limited to the Organization Administrator.

1.2.2. Access permissions

The Prerequisites for each procedure list which predefined role provides the permissions you must have. As a user, you can navigate to Red Hat Hybrid Cloud Console > the Settings icon (⚙) > My User Access to view the roles and application permissions currently inherited by you.

If you try to access Insights for Red Hat Enterprise Linux features and see a message that you do not have permission to perform this action, you must obtain additional permissions. The Organization Administrator or the User Access administrator for your organization configures those permissions.

Use the Red Hat Hybrid Cloud Console Virtual Assistant to ask "Contact my Organization Administrator". The assistant sends an email to the Organization Administrator on your behalf.

Additional resources

For more information about user access and permissions, see User Access Configuration Guide for Role-based Access Control (RBAC).

1.3. User Access roles for creating and executing remediation plans

To fix issues on your systems by using the Red Hat Insights remediation features, become familiar with the roles that provide the required access permissions for creating, managing, and executing remediation plans.

The following user access roles provide standard or enhanced access to remediation features in Insights:

  • Remediations user: The Remediations user role is included in the default access group. With this role, a user has permissions to:

    • View existing remediation plans
    • Create a remediation plan
    • Delete a remediation plan
  • Remediations administrator: With this role, a user has permissions to:

    • Do everything that a Remediations user can do
    • Execute remediation plans on connected remote host systems from within Insights

For more information about user access and permissions, see User Access Configuration Guide for Role-based Access Control (RBAC).

Voltar ao topo
Red Hat logoGithubredditYoutubeTwitter

Aprender

Experimente, compre e venda

Comunidades

Sobre a documentação da Red Hat

Ajudamos os usuários da Red Hat a inovar e atingir seus objetivos com nossos produtos e serviços com conteúdo em que podem confiar. Explore nossas atualizações recentes.

Tornando o open source mais inclusivo

A Red Hat está comprometida em substituir a linguagem problemática em nosso código, documentação e propriedades da web. Para mais detalhes veja o Blog da Red Hat.

Sobre a Red Hat

Fornecemos soluções robustas que facilitam o trabalho das empresas em plataformas e ambientes, desde o data center principal até a borda da rede.

Theme

© 2025 Red Hat