Add Subscribers
A SIM is declared to the network, not to a core. You create a Secret holding its keys and a
Subscriber naming the IMSI; the core controller provisions it into the selected core
provider and reports the outcome. Which core runs, and how it stores subscribers, is the
provider's business (Open5GS keeps them in its mongodb on a persistent
claim; an External Core is yours to provision).
Declare One
Both objects live in racora-system, where the core controller reads Secrets; a
Subscriber elsewhere is never reconciled. The example:
apiVersion: v1
kind: Secret
metadata:
name: sim-1
namespace: racora-system
type: Opaque
stringData:
k: "00112233445566778899aabbccddeeff"
opc: "63bfa50ee6523365ff14c1f45f88737d"
---
apiVersion: racora.io/v1alpha1
kind: Subscriber
metadata:
name: sim-1
namespace: racora-system
spec:
imsi: "901700000000001"
credentialsSecretRef:
name: sim-1
The Secret's keys: k (the subscriber key, 32 hex digits) and opc (32 hex digits) — or
op instead of opc — and optionally amf (the authentication management field, 4 hex
digits, default 8000). The values in the example are the public test-SIM keys the bundled
core seeds; a real SIM's are yours. The Subscriber may also set qci (the default
bearer's QoS class), dnn (the data network name the UE requests for its default session;
Open5GS's default is internet), staticIp (an address in the provider's UE pool) and
slices (default: the network identity's). The slices are handed to the provider's
adapter; the Open5GS adapter provisions slice sst 1 whatever is declared.
Save it as subscriber-1.yaml, put your SIM's keys in, and apply it:
kubectl apply -f subscriber-1.yaml
kubectl -n racora-system get sim
NAME IMSI PHASE PROVIDER AGE
sim-1 901700000000001 Provisioned open5gs 4s
What the Status Means
Provisioned is the SIM in the core. Pending means the provider is not ready or its
adapter failed and the core controller is retrying; Error means the Secret or the
provider's declaration is wrong; Unmanaged means the selected provider has no subscriber
adapter (an external core) and the SIM is yours to provision. Every phase and reason, with
its cause and fix, is in Troubleshoot;
whether the phone then attaches is The Phone Does Not Attach,
and a phone that attaches without data is the entry after it.
The IMSI is not checked against the network's PLMN: a SIM from another PLMN is provisioned and roams onto the network as far as the core allows.
Keep, Change, Remove
- Every
Subscriberis re-applied periodically (racora-controller.coreController.resyncSeconds, default 300). A core database that was wiped or restored converges to what is declared. - Change the spec and the next reconcile updates the entry. Secrets are not watched: a changed Secret lands at the next periodic re-apply.
- Delete the
Subscriberand the core controller removes the entry from the core; a provider that is gone never blocks the deletion. - Subscribers the core knows that you did not declare — Open5GS's seeded bootstrap SIM, entries added through its WebUI — are never touched.
How It Works
Each core provider declares how a subscriber gets in, and the core controller runs that
adapter without knowing which core it is talking to; the mechanism is
How Core Providers Work. When a subscriber does not reach
Provisioned, Troubleshoot lists every phase and reason.