Generating Telemetry Publisher access credentials

Steps for generating access credentials that enable communication between your Workload clusters and Cloudera Observability.

Describes how to create the access key and private key for Cloudera Manager's Telemetry Publisher, which collects and sends your workload information to Cloudera Observability. You are required to provide these values when you enable the telemetry network communication for Cloudera Observability.

Telemetry Publisher access credentials authenticate your on premises Workload cluster with Cloudera Observability. You can generate these credentials yourself in the Cloudera Observability web UI or in the Management Console UI.

Verify the following:
  • You have access to the Cloudera Control Plane for your organization.
  • You can log in to either:
    • Cloudera Observability web UI, or
    • Management Console with permission to generate access keys.
  • You have a supported web browser.
  • You have a secure location to store the Access Key ID and private key file. The private key is displayed only once and cannot be retrieved after you close the credentials dialog.

To use the credentials in Cloudera Manager, you also need the Databus endpoint URLs for your cloud region. For information, see Enabling the telemetry network communication for Cloudera Observability.

Required roles:

Cloudera Observability:

To generate credentials from the Cloudera Observability UI, you must be a Cloudera Observability administrator (ObservabilityClusterAdmin, formerly WXMClusterAdmin).

Management Console:

Users who have the IAMUser role can generate an API access key from their own account page. As a Cloudera administrator or PowerUser, you can generate an API access key for all user accounts.

Choose a credential generation method

Use one of the following methods to generate Telemetry Publisher access credentials.

Method When to use
From Cloudera Observability You are connecting a Workload cluster to Cloudera Observability for the first time and want a guided flow from the Observability UI.
From Management Console You prefer to generate credentials manually, need credentials for a specific user account, or cannot access the Observability Connect Cluster workflow.

Both methods produce credentials that you register in Cloudera Manager as Telemetry Publisher external accounts. You cannot retrieve the private key after you close or refresh the page. Store the credentials before you navigate away.

Generate credentials from Cloudera Observability

Use this method when you want Cloudera Observability to generate credentials as part of the cluster connection workflow.
  1. Verify that you are logged in to the Cloudera Observability web UI.
  2. From the Cloudera Observability Environments page, in the top right corner, click Connect Cluster to generate an altus key for Cloudera Observability.
  3. On the Add New Cluster Connection page, click Generate Access Credentials to add your Cloudera Observability account to Cloudera Manager.

    The Telemetry Publisher Altus Access Key ID and Altus Private Key credentials are created and their respective fields are populated with the credential text. You can record these values to connect Cloudera Manager to Cloudera Observability.

  4. Manually save the access credentials:
    1. Record the Altus Access Key ID credential text and store it somewhere safe. You will be required to supply this value when you enable the Telemetry Publisher service on your Workload Cluster.
    2. In a new text file, copy and paste the Altus Private Key credential text exactly as provided without trailing spaces and then name and save the file somewhere safe. You will be required to supply this file when you enable the Telemetry Publisher service on your Workload Cluster.
  5. To set up the external accounts, log in to Cloudera Manager and use the Altus Access Key ID and Altus Private Key stored in Step 4. For information on setting up the external accounts, see Enabling the telemetry network communication for Cloudera Observability.

Generate credentials from Management Console

Use this method when you want to generate credentials manually from the Management Console. You can generate credentials from your own user profile or, if you have sufficient permissions, for another user in User management.

Generate credentials from your Profile
  1. In a supported web browser, log in to Cloudera Control Plane.
  2. From the Your Enterprise Data Cloud landing page, select the Management Console tile.

    The Management Console home page opens.

  3. From the Management Console navigation panel, click your user name, and then select Profile.

    Your Profile page opens.

  4. Select the Access Keys tab.
  5. Click Generate Access Key.

    The Generate Access Key dialog box opens.

  6. Click Generate an old format access key.

    Telemetry Publisher requires an old format access key. Do not use the default (new format) access key option. Select Generate an old format access key if you are generating an access key to use with Cloudera Observability.

    The Telemetry Publisher Access Key ID and Private Key credentials are created and their respective fields are populated with the credential text.

  7. Manually save the access credentials:
    • Record the Altus Access Key ID credential text and store it somewhere safe. You will be required to supply this value when you enable the Telemetry Publisher service on your Workload Cluster.
    • In a new text file, copy and paste the Altus Private Key credential text exactly as provided without trailing spaces and then name and save the file somewhere safe. You will be required to supply this file when you enable the Telemetry Publisher service on your Workload Cluster.
  8. To set up the external accounts, log in to Cloudera Manager and use the Altus Access Key ID and Altus Private Key stored in Step 7. For information on setting up the external accounts, see Enabling the telemetry network communication for Cloudera Observability.

Generate credentials from User management

Use this procedure when you have permission to manage users and generate access keys on their behalf.

  1. In a supported web browser, log in to Cloudera Control Plane.
  2. From the Your Enterprise Data Cloud landing page, select the Management Console tile.

    The Management Console home page opens.

  3. In the left navigation pane, click User management.

    The Users page opens.

  4. Select the user for whom you want to generate credentials.

    The user details page opens.

  5. Select the Access Keys tab.
  6. Click Generate Access Key.

    The Generate Access Key dialog box opens.

  7. Click Generate an old format access key.

    Telemetry Publisher requires an old format access key. Do not use the default (new format) access key option. Select Generate an old format access key if you are generating an access key to use with Cloudera Observability.

    The Telemetry Publisher Access Key ID and Private Key credentials are created and their respective fields are populated with the credential text.

  8. Manually save the access credentials:
    • Record the Altus Access Key ID credential text and store it somewhere safe. You will be required to supply this value when you enable the Telemetry Publisher service on your Workload Cluster.
    • In a new text file, copy and paste the Altus Private Key credential text exactly as provided without trailing spaces and then name and save the file somewhere safe. You will be required to supply this file when you enable the Telemetry Publisher service on your Workload Cluster.
  9. To set up the external accounts, log in to Cloudera Manager and use the Altus Access Key ID and Altus Private Key stored in Step 8. For information on setting up the external accounts, see Enabling the telemetry network communication for Cloudera Observability.

What to do next:

After you save the credentials, register them in Cloudera Manager and enable network communication between Telemetry Publisher and Cloudera Observability. For information, see Enabling the telemetry network communication for Cloudera Observability.