
Overview
- Projects (namespaces) are the primary resource boundary for applications and resources in OpenShift.
- Users are created by the cluster using an identity provider. In Minishift demo environments the
anypasswordprovider is often enabled so users can be created directly from the web console. - The CLI (
oc) and web console show different sets of projects depending on the authenticated user’s privileges.
1) Log in as the cluster administrator
Start by logging into the cluster as the cluster administratorsystem:admin from the CLI:
myproject).
2) List users known to the cluster
To list the cluster users:IDENTITIES column shows the identity provider and the identity string. In this example the provider is anypassword.
Minishift uses the
anypassword identity provider by default. With anypassword any username can be created by signing into the web console and any password will be accepted for that username. This is convenient for demos and local testing but should never be used in production.3) Create users via the web console (example: developer2)
If you sign into the web console as a new user (for example,developer2) and supply any password, OpenShift will create that user automatically. After creating the user, listing users again shows the new account:
4) Create a project from the web console as a developer
When logged into the web console as a non-admin user (for example,developer), you can create a project that will be visible only to users who have access to it:
- Click “Create Project”.
- Provide a unique project name and optionally a display name and description.
- Click “Create”.
default, kube-system, and openshift generally require cluster-admin privileges to view in the console; kube-public is readable by all users at the API level but may not be shown to non-admins in the web console.
5) View system projects in the web console — create a cluster-admin web-console user
The built-in Kubernetessystem:admin account has full privileges but is not usable to sign into the OAuth web console. To view system projects from the web console, create a new web-console user and grant it the cluster-admin role.
- Sign into the web console as a new username (for example,
administrator). Withanypasswordenabled, this will create theadministratoruser automatically. - Confirm the user is present in the CLI:
- Grant the
cluster-adminrole to theadministratoruser:
- Sign into the web console as
administrator. You will now see all projects, including default system projects, and can browse their configuration and resources.
Granting
cluster-admin provides full control over the cluster. Only assign this role to trusted accounts and remove it when no longer needed. Do not use anypassword or temporary demo accounts for production administrative access.Quick reference — common commands
Default projects (common in new clusters)
Links and references
- OpenShift documentation: https://docs.openshift.com/
- Kubernetes concepts: https://kubernetes.io/docs/concepts/overview/what-is-kubernetes/
- Minishift documentation: https://github.com/minishift/minishift