API keys in IBM Cloud
Satellite uses IBM Cloud IAM API keys to authorize various requests.
Satellite API key
Satellite automatically creates an IBM Cloud IAM API key for you, that impersonates the permissions of the user that creates the location. The API key name is formatted as satellite-<LOCATION_NAME>.
Container service API key
Satellite uses the Red Hat OpenShift on IBM Cloud API key specific to the resource group and region managing the Satellite location.
The API key name is in the format containers-kubernetes-key. The account owner can reset the API key by logging in to a region and resource group and running ibmcloud ks api-key reset.
This API key is used to authorize actions to various IBM Cloud services, such as one of the following.
- Red Hat OpenShift on IBM Cloud for clusters.
- IBM Cloud Container Registry for images.
- Service-to-service authorization in IAM for any Satellite-enabled IBM Cloud services that you add to your location.
For more information, see the Red Hat OpenShift on IBM Cloud documentation.
Infrastructure provider credentials
When creating a Satellite location from a template, Satellite checks an API key for permissions to create a location, including IBM Cloud Schematics access.