TECHNICAL GUIDE
Platform Deployment · PD-K8S-05

Create the Worker Enrollment Secret

Obtain the controller CA and STRATUM worker enrollment token.

PROCEDURE

Two pieces are required

A worker needs the controller CA so it can trust the controller and the STRATUM enrollment token so it can enroll. Copy the CA from the running controller and obtain the enrollment token from the STRATUM interface.

DETAIL

Store them as a Secret

Create or update the Kubernetes Secret using the supplied filenames. Re-running the dry-run/apply form is safe for updating the Secret without hand-editing a live object.

COMMANDS

Commands

Replace example node, registry, namespace, and endpoint values with the values for the target environment.

shell
oc cp -n stratum -c stratum \
  stratum-stratum-controller-0:/stratum/proxy/certs/ca.crt \
  ./controller-ca.crt
shell
oc -n stratum create secret generic stratum-worker-enrollment \
  --from-file=stratum-enroll=./stratum-enroll \
  --from-file=controller-ca.crt=./controller-ca.crt \
  --dry-run=client -o yaml | oc apply -f -
RESULT

The outcome you should see

The worker-enrollment Secret contains both the controller CA and the current STRATUM enrollment token.