Skip to main content
Welcome. This lesson covers how OpenShift manages projects and users, how to inspect them from the CLI, and how to create and promote web-console users so they can view system projects.
A Red Hat OpenShift demo webpage header with a pink-to-purple gradient and the title "Projects and Users." A small inset photo shows hands typing at a keyboard and a monitor with code.

Overview

  • Projects (namespaces) are the primary resource boundary for applications and resources in OpenShift.
  • Users are created by the cluster using an identity provider. In Minishift demo environments the anypassword provider is often enabled so users can be created directly from the web console.
  • The CLI (oc) and web console show different sets of projects depending on the authenticated user’s privileges.

1) Log in as the cluster administrator

Start by logging into the cluster as the cluster administrator system:admin from the CLI:
The output shows the default system projects created when the cluster was provisioned and any projects you created (for example, myproject).

2) List users known to the cluster

To list the cluster users:
The IDENTITIES column shows the identity provider and the identity string. In this example the provider is anypassword.
Minishift uses the anypassword identity provider by default. With anypassword any username can be created by signing into the web console and any password will be accepted for that username. This is convenient for demos and local testing but should never be used in production.

3) Create users via the web console (example: developer2)

If you sign into the web console as a new user (for example, developer2) and supply any password, OpenShift will create that user automatically. After creating the user, listing users again shows the new account:

4) Create a project from the web console as a developer

When logged into the web console as a non-admin user (for example, developer), you can create a project that will be visible only to users who have access to it:
  • Click “Create Project”.
  • Provide a unique project name and optionally a display name and description.
  • Click “Create”.
Open the newly created project to inspect the applications and resources inside it. Note: Non-administrative users typically only see projects they created or that have been shared with them. System projects like default, kube-system, and openshift generally require cluster-admin privileges to view in the console; kube-public is readable by all users at the API level but may not be shown to non-admins in the web console.

5) View system projects in the web console — create a cluster-admin web-console user

The built-in Kubernetes system:admin account has full privileges but is not usable to sign into the OAuth web console. To view system projects from the web console, create a new web-console user and grant it the cluster-admin role.
  1. Sign into the web console as a new username (for example, administrator). With anypassword enabled, this will create the administrator user automatically.
  2. Confirm the user is present in the CLI:
  1. Grant the cluster-admin role to the administrator user:
  1. Sign into the web console as administrator. You will now see all projects, including default system projects, and can browse their configuration and resources.
Granting cluster-admin provides full control over the cluster. Only assign this role to trusted accounts and remove it when no longer needed. Do not use anypassword or temporary demo accounts for production administrative access.

Quick reference — common commands

Default projects (common in new clusters)

This concludes the walkthrough for projects and users in OpenShift.

Watch Video