Skip to main content

Add Subscribers

A SIM is declared to the network, not to a core. You create a Secret holding its keys and a Subscriber naming the IMSI; the core controller provisions it into the selected core provider and reports the outcome. Which core runs, and how it stores subscribers, is the provider's business (Open5GS keeps them in its mongodb on a persistent claim; an External Core is yours to provision).

Declare One​

Both objects live in racora-system, where the core controller reads Secrets; a Subscriber elsewhere is never reconciled. The example:

apiVersion: v1
kind: Secret
metadata:
name: sim-1
namespace: racora-system
type: Opaque
stringData:
k: "00112233445566778899aabbccddeeff"
opc: "63bfa50ee6523365ff14c1f45f88737d"
---
apiVersion: racora.io/v1alpha1
kind: Subscriber
metadata:
name: sim-1
namespace: racora-system
spec:
imsi: "901700000000001"
credentialsSecretRef:
name: sim-1

The Secret's keys: k (the subscriber key, 32 hex digits) and opc (32 hex digits) — or op instead of opc — and optionally amf (the authentication management field, 4 hex digits, default 8000). The values in the example are the public test-SIM keys the bundled core seeds; a real SIM's are yours. The Subscriber may also set qci (the default bearer's QoS class), dnn (the data network name the UE requests for its default session; Open5GS's default is internet), staticIp (an address in the provider's UE pool) and slices (default: the network identity's). The slices are handed to the provider's adapter; the Open5GS adapter provisions slice sst 1 whatever is declared.

Save it as subscriber-1.yaml, put your SIM's keys in, and apply it:

kubectl apply -f subscriber-1.yaml
kubectl -n racora-system get sim
NAME IMSI PHASE PROVIDER AGE
sim-1 901700000000001 Provisioned open5gs 4s

What the Status Means​

Provisioned is the SIM in the core. Pending means the provider is not ready or its adapter failed and the core controller is retrying; Error means the Secret or the provider's declaration is wrong; Unmanaged means the selected provider has no subscriber adapter (an external core) and the SIM is yours to provision. Every phase and reason, with its cause and fix, is in Troubleshoot; whether the phone then attaches is The Phone Does Not Attach, and a phone that attaches without data is the entry after it.

The IMSI is not checked against the network's PLMN: a SIM from another PLMN is provisioned and roams onto the network as far as the core allows.

Keep, Change, Remove​

  • Every Subscriber is re-applied periodically (racora-controller.coreController.resyncSeconds, default 300). A core database that was wiped or restored converges to what is declared.
  • Change the spec and the next reconcile updates the entry. Secrets are not watched: a changed Secret lands at the next periodic re-apply.
  • Delete the Subscriber and the core controller removes the entry from the core; a provider that is gone never blocks the deletion.
  • Subscribers the core knows that you did not declare — Open5GS's seeded bootstrap SIM, entries added through its WebUI — are never touched.

How It Works​

Each core provider declares how a subscriber gets in, and the core controller runs that adapter without knowing which core it is talking to; the mechanism is How Core Providers Work. When a subscriber does not reach Provisioned, Troubleshoot lists every phase and reason.