> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Demo Projects and Users

> Explains OpenShift projects and users, how to inspect them with oc, create web console users in Minishift, and grant cluster admin to view system projects.

Welcome. This lesson covers how OpenShift manages projects and users, how to inspect them from the CLI, and how to create and promote web-console users so they can view system projects.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/1i2YcqiBKQjc0R77/images/OpenShift-3-for-the-Absolute-Beginners/OpenShift-Concepts-Projects-and-Users/Demo-Projects-and-Users/red-hat-openshift-projects-users-gradient.jpg?fit=max&auto=format&n=1i2YcqiBKQjc0R77&q=85&s=f172a11b8de790b8aa10a69455ee0ffa" alt="A Red Hat OpenShift demo webpage header with a pink-to-purple gradient and the title &#x22;Projects and Users.&#x22; A small inset photo shows hands typing at a keyboard and a monitor with code." width="1920" height="1080" data-path="images/OpenShift-3-for-the-Absolute-Beginners/OpenShift-Concepts-Projects-and-Users/Demo-Projects-and-Users/red-hat-openshift-projects-users-gradient.jpg" />
</Frame>

## Overview

* Projects (namespaces) are the primary resource boundary for applications and resources in OpenShift.
* Users are created by the cluster using an identity provider. In Minishift demo environments the `anypassword` provider is often enabled so users can be created directly from the web console.
* The CLI (`oc`) and web console show different sets of projects depending on the authenticated user's privileges.

## 1) Log in as the cluster administrator

Start by logging into the cluster as the cluster administrator `system:admin` from the CLI:

```console theme={null}
c:\minishift-1.16.1-windows-amd64>oc login -u system:admin
Logged into "https://192.168.99.102:8443" as "system:admin" using existing credentials.

You have access to the following projects and can switch between them with 'oc project <projectname>':

    default
    kube-public
    kube-system
  * myproject
    openshift
    openshift-infra
    openshift-node
    openshift-web-console

Using project "myproject".

c:\minishift-1.16.1-windows-amd64>
```

The output shows the default system projects created when the cluster was provisioned and any projects you created (for example, `myproject`).

## 2) List users known to the cluster

To list the cluster users:

```console theme={null}
c:\minishift-1.16.1-windows-amd64>oc get users
NAME        UID                                  FULL NAME    IDENTITIES
developer   758ed92d-4c3b-11e8-8098-e2e0de05d311              anypassword:developer

c:\minishift-1.16.1-windows-amd64>
```

The `IDENTITIES` column shows the identity provider and the identity string. In this example the provider is `anypassword`.

<Callout icon="lightbulb" color="#1CB2FE">
  Minishift uses the `anypassword` identity provider by default. With `anypassword` any username can be created by signing into the web console and any password will be accepted for that username. This is convenient for demos and local testing but should never be used in production.
</Callout>

## 3) Create users via the web console (example: developer2)

If you sign into the web console as a new user (for example, `developer2`) and supply any password, OpenShift will create that user automatically. After creating the user, listing users again shows the new account:

```console theme={null}
c:\minishift-1.16.1-windows-amd64>oc get users
NAME        UID                                  FULL NAME    IDENTITIES
developer   758ed92d-4c3b-11e8-8098-e2e0de05d311              anypassword:developer
developer2  ba585475-4c43-11e8-8098-e2e0de05d311              anypassword:developer2

c:\minishift-1.16.1-windows-amd64>
```

## 4) Create a project from the web console as a developer

When logged into the web console as a non-admin user (for example, `developer`), you can create a project that will be visible only to users who have access to it:

* Click "Create Project".
* Provide a unique project name and optionally a display name and description.
* Click "Create".

Open the newly created project to inspect the applications and resources inside it.

Note: Non-administrative users typically only see projects they created or that have been shared with them. System projects like `default`, `kube-system`, and `openshift` generally require cluster-admin privileges to view in the console; `kube-public` is readable by all users at the API level but may not be shown to non-admins in the web console.

## 5) View system projects in the web console — create a cluster-admin web-console user

The built-in Kubernetes `system:admin` account has full privileges but is not usable to sign into the OAuth web console. To view system projects from the web console, create a new web-console user and grant it the `cluster-admin` role.

1. Sign into the web console as a new username (for example, `administrator`). With `anypassword` enabled, this will create the `administrator` user automatically.
2. Confirm the user is present in the CLI:

```console theme={null}
c:\minishift-1.16.1-windows-amd64>oc get users
NAME           UID                                FULL NAME    IDENTITIES
administrator  4343778b-4c44-11e8-8098-e2e0de05d311              anypassword:administrator
developer      758ed92d-4c3b-11e8-8098-e2e0de05d311              anypassword:developer
developer2     ba585475-4c43-11e8-8098-e2e0de05d311              anypassword:developer2

c:\minishift-1.16.1-windows-amd64>
```

3. Grant the `cluster-admin` role to the `administrator` user:

```console theme={null}
c:\minishift-1.16.1-windows-amd64>oc adm policy add-cluster-role-to-user cluster-admin administrator
cluster role "cluster-admin" added: "administrator"

c:\minishift-1.16.1-windows-amd64>
```

4. Sign into the web console as `administrator`. You will now see all projects, including default system projects, and can browse their configuration and resources.

<Callout icon="warning" color="#FF6B6B">
  Granting `cluster-admin` provides full control over the cluster. Only assign this role to trusted accounts and remove it when no longer needed. Do not use `anypassword` or temporary demo accounts for production administrative access.
</Callout>

## Quick reference — common commands

| Command | Purpose |
| - | - |
| `oc login -u system:admin` | Authenticate CLI as the static cluster administrator (`system:admin`). |
| `oc get users` | List users known to the cluster and their identities. |
| `oc project <name>` | Switch the current CLI project/namespace. |
| `oc adm policy add-cluster-role-to-user cluster-admin <user>` | Grant the `cluster-admin` role to a user. |

## Default projects (common in new clusters)

| Project name | Typical purpose |
| - | - |
| `default` | Default project/namespace for workloads without an explicit namespace. |
| `kube-public` | Readable by all users; used for cluster-wide public information. |
| `kube-system` | System components for Kubernetes. |
| `openshift` | OpenShift platform components and resources. |
| `openshift-infra` | OpenShift infrastructure components (older versions). |
| `openshift-web-console` | Web console components. |

## Links and references

* OpenShift documentation: [https://docs.openshift.com/](https://docs.openshift.com/)
* Kubernetes concepts: [https://kubernetes.io/docs/concepts/overview/what-is-kubernetes/](https://kubernetes.io/docs/concepts/overview/what-is-kubernetes/)
* Minishift documentation: [https://github.com/minishift/minishift](https://github.com/minishift/minishift)

This concludes the walkthrough for projects and users in OpenShift.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/openshift-3-for-the-absolute-beginners/module/fc026f6f-53db-4f6f-ae06-6297528ce081/lesson/85ba4e36-5027-41bc-9062-9b10b6c5c6b2" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.