Dieser Inhalt ist in der von Ihnen ausgewählten Sprache nicht verfügbar.
Chapter 2. OpenShift CLI (oc)
2.1. Getting started with the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
2.1.1. About the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
With the OpenShift CLI (oc
), you can create applications and manage Red Hat OpenShift Service on AWS projects from a terminal. The OpenShift CLI is ideal in the following situations:
- Working directly with project source code.
- Scripting Red Hat OpenShift Service on AWS operations
- Managing projects while restricted by bandwidth resources and the web console is unavailable.
2.1.2. Installing the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) either by downloading the binary or by using an RPM.
2.1.2.1. Installing the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) to interact with Red Hat OpenShift Service on AWS from a command-line interface. You can install oc
on Linux, Windows, or macOS.
If you installed an earlier version of oc
, you cannot use it to complete all of the commands in Red Hat OpenShift Service on AWS.
Download and install the new version of oc
.
2.1.2.1.1. Installing the OpenShift CLI on Linux Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on Linux by using the following procedure.
Procedure
- Navigate to the Download OpenShift Container Platform page on the Red Hat Customer Portal.
- Select the architecture from the Product Variant list.
- Select the appropriate version from the Version list.
- Click Download Now next to the OpenShift v4 Linux Clients entry and save the file.
Unpack the archive:
tar xvf <file>
$ tar xvf <file>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Place the
oc
binary in a directory that is on yourPATH
.To check your
PATH
, execute the following command:echo $PATH
$ echo $PATH
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Verification
After you install the OpenShift CLI, it is available using the
oc
command:oc <command>
$ oc <command>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
2.1.2.1.2. Installing the OpenShift CLI on Windows Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on Windows by using the following procedure.
Procedure
- Navigate to the Download OpenShift Container Platform page on the Red Hat Customer Portal.
- Select the appropriate version from the Version list.
- Click Download Now next to the OpenShift v4 Windows Client entry and save the file.
- Unzip the archive with a ZIP program.
Move the
oc
binary to a directory that is on yourPATH
.To check your
PATH
, open the command prompt and execute the following command:path
C:\> path
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Verification
After you install the OpenShift CLI, it is available using the
oc
command:oc <command>
C:\> oc <command>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
2.1.2.1.3. Installing the OpenShift CLI on macOS Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on macOS by using the following procedure.
Procedure
- Navigate to the Download OpenShift Container Platform on the Red Hat Customer Portal.
- Select the appropriate version from the Version drop-down list.
- Click Download Now next to the OpenShift v4 macOS Clients entry and save the file.
- Unpack and unzip the archive.
Move the
oc
binary to a directory on your PATH.To check your
PATH
, open a terminal and execute the following command:echo $PATH
$ echo $PATH
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Verification
Verify your installation by using an
oc
command:oc <command>
$ oc <command>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
2.1.2.2. Installing the OpenShift CLI by using the web console Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) to interact with Red Hat OpenShift Service on AWS clusters from a web console. You can install oc
on Linux, Windows, or macOS.
If you installed an earlier version of oc
, you cannot use it to complete all of the commands in Red Hat OpenShift Service on AWS. Download and install the new version of oc
.
2.1.2.2.1. Installing the OpenShift CLI on Linux using the web console Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on Linux by using the following procedure.
Procedure
From the web console, click ?.
Click Command Line Tools.
-
Select appropriate
oc
binary for your Linux platform, and then click Download oc for Linux. - Save the file.
Unpack the archive.
tar xvf <file>
$ tar xvf <file>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Move the
oc
binary to a directory that is on yourPATH
.To check your
PATH
, execute the following command:echo $PATH
$ echo $PATH
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
After you install the OpenShift CLI, it is available using the oc
command:
oc <command>
$ oc <command>
2.1.2.2.2. Installing the OpenShift CLI on Windows using the web console Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on Windows by using the following procedure.
Procedure
From the web console, click ?.
Click Command Line Tools.
-
Select the
oc
binary for Windows platform, and then click Download oc for Windows for x86_64. - Save the file.
- Unzip the archive with a ZIP program.
Move the
oc
binary to a directory that is on yourPATH
.To check your
PATH
, open the command prompt and execute the following command:path
C:\> path
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
After you install the OpenShift CLI, it is available using the oc
command:
oc <command>
C:\> oc <command>
2.1.2.2.3. Installing the OpenShift CLI on macOS using the web console Link kopierenLink in die Zwischenablage kopiert!
You can install the OpenShift CLI (oc
) binary on macOS by using the following procedure.
Procedure
From the web console, click ?.
Click Command Line Tools.
Select the
oc
binary for macOS platform, and then click Download oc for Mac for x86_64.NoteFor macOS arm64, click Download oc for Mac for ARM 64.
- Save the file.
- Unpack and unzip the archive.
Move the
oc
binary to a directory on your PATH.To check your
PATH
, open a terminal and execute the following command:echo $PATH
$ echo $PATH
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
After you install the OpenShift CLI, it is available using the oc
command:
oc <command>
$ oc <command>
2.1.2.3. Installing the OpenShift CLI by using an RPM Link kopierenLink in die Zwischenablage kopiert!
For Red Hat Enterprise Linux (RHEL), you can install the OpenShift CLI (oc
) as an RPM if you have an active Red Hat OpenShift Service on AWS subscription on your Red Hat account.
You must install oc
for RHEL 9 by downloading the binary. Installing oc
by using an RPM package is not supported on Red Hat Enterprise Linux (RHEL) 9.
Prerequisites
- Must have root or sudo privileges.
Procedure
Register with Red Hat Subscription Manager:
subscription-manager register
# subscription-manager register
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Pull the latest subscription data:
subscription-manager refresh
# subscription-manager refresh
Copy to Clipboard Copied! Toggle word wrap Toggle overflow List the available subscriptions:
subscription-manager list --available --matches '*OpenShift*'
# subscription-manager list --available --matches '*OpenShift*'
Copy to Clipboard Copied! Toggle word wrap Toggle overflow In the output for the previous command, find the pool ID for an Red Hat OpenShift Service on AWS subscription and attach the subscription to the registered system:
subscription-manager attach --pool=<pool_id>
# subscription-manager attach --pool=<pool_id>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Enable the repositories required by Red Hat OpenShift Service on AWS 4.
subscription-manager repos --enable="rhocp-4-for-rhel-8-x86_64-rpms"
# subscription-manager repos --enable="rhocp-4-for-rhel-8-x86_64-rpms"
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Install the
openshift-clients
package:yum install openshift-clients
# yum install openshift-clients
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Verification
-
Verify your installation by using an
oc
command:
oc <command>
$ oc <command>
2.1.2.4. Installing the OpenShift CLI by using Homebrew Link kopierenLink in die Zwischenablage kopiert!
For macOS, you can install the OpenShift CLI (oc
) by using the Homebrew package manager.
Prerequisites
-
You must have Homebrew (
brew
) installed.
Procedure
Install the openshift-cli package by running the following command:
brew install openshift-cli
$ brew install openshift-cli
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Verification
-
Verify your installation by using an
oc
command:
oc <command>
$ oc <command>
2.1.3. Logging in to the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
You can log in to the OpenShift CLI (oc
) to access and manage your cluster.
Prerequisites
- You must have access to a Red Hat OpenShift Service on AWS cluster.
-
The OpenShift CLI (
oc
) is installed.
To access a cluster that is accessible only over an HTTP proxy server, you can set the HTTP_PROXY
, HTTPS_PROXY
and NO_PROXY
variables. These environment variables are respected by the oc
CLI so that all communication with the cluster goes through the HTTP proxy.
Authentication headers are sent only when using HTTPS transport.
Procedure
Enter the
oc login
command and pass in a user name:oc login -u user1
$ oc login -u user1
Copy to Clipboard Copied! Toggle word wrap Toggle overflow When prompted, enter the required information:
Example output
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
If you are logged in to the web console, you can generate an oc login
command that includes your token and server information. You can use the command to log in to the OpenShift CLI (oc
) without the interactive prompts. To generate the command, select Copy login command from the username drop-down menu at the top right of the web console.
You can now create a project or issue other commands for managing your cluster.
2.1.4. Logging in to the OpenShift CLI using a web browser Link kopierenLink in die Zwischenablage kopiert!
You can log in to the OpenShift CLI (oc
) with the help of a web browser to access and manage your cluster. This allows users to avoid inserting their access token into the command line.
Logging in to the CLI through the web browser runs a server on localhost with HTTP, not HTTPS; use with caution on multi-user workstations.
Prerequisites
- You must have access to an Red Hat OpenShift Service on AWS cluster.
-
You must have installed the OpenShift CLI (
oc
). - You must have a browser installed.
Procedure
Enter the
oc login
command with the--web
flag:oc login <cluster_url> --web
$ oc login <cluster_url> --web
1 Copy to Clipboard Copied! Toggle word wrap Toggle overflow - 1
- Optionally, you can specify the server URL and callback port. For example,
oc login <cluster_url> --web --callback-port 8280 localhost:8443
.
The web browser opens automatically. If it does not, click the link in the command output. If you do not specify the Red Hat OpenShift Service on AWS server
oc
tries to open the web console of the cluster specified in the currentoc
configuration file. If nooc
configuration exists,oc
prompts interactively for the server URL.Example output
Opening login URL in the default browser: https://openshift.example.com Opening in existing browser session.
Opening login URL in the default browser: https://openshift.example.com Opening in existing browser session.
Copy to Clipboard Copied! Toggle word wrap Toggle overflow - If more than one identity provider is available, select your choice from the options provided.
-
Enter your username and password into the corresponding browser fields. After you are logged in, the browser displays the text
access token received successfully; please return to your terminal
. Check the CLI for a login confirmation.
Example output
Login successful. You don't have any projects. You can try to create a new project, by running oc new-project <projectname>
Login successful. You don't have any projects. You can try to create a new project, by running oc new-project <projectname>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
The web console defaults to the profile used in the previous session. To switch between Administrator and Developer profiles, log out of the Red Hat OpenShift Service on AWS web console and clear the cache.
You can now create a project or issue other commands for managing your cluster.
2.1.5. Using the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
Review the following sections to learn how to complete common tasks using the CLI.
2.1.5.1. Creating a project Link kopierenLink in die Zwischenablage kopiert!
Use the oc new-project
command to create a new project.
oc new-project my-project
$ oc new-project my-project
Example output
Now using project "my-project" on server "https://openshift.example.com:6443".
Now using project "my-project" on server "https://openshift.example.com:6443".
2.1.5.2. Creating a new app Link kopierenLink in die Zwischenablage kopiert!
Use the oc new-app
command to create a new application.
oc new-app https://github.com/sclorg/cakephp-ex
$ oc new-app https://github.com/sclorg/cakephp-ex
Example output
--> Found image 40de956 (9 days old) in imagestream "openshift/php" under tag "7.2" for "php" ... Run 'oc status' to view your app.
--> Found image 40de956 (9 days old) in imagestream "openshift/php" under tag "7.2" for "php"
...
Run 'oc status' to view your app.
2.1.5.3. Viewing pods Link kopierenLink in die Zwischenablage kopiert!
Use the oc get pods
command to view the pods for the current project.
When you run oc
inside a pod and do not specify a namespace, the namespace of the pod is used by default.
oc get pods -o wide
$ oc get pods -o wide
Example output
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE cakephp-ex-1-build 0/1 Completed 0 5m45s 10.131.0.10 ip-10-0-141-74.ec2.internal <none> cakephp-ex-1-deploy 0/1 Completed 0 3m44s 10.129.2.9 ip-10-0-147-65.ec2.internal <none> cakephp-ex-1-ktz97 1/1 Running 0 3m33s 10.128.2.11 ip-10-0-168-105.ec2.internal <none>
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE
cakephp-ex-1-build 0/1 Completed 0 5m45s 10.131.0.10 ip-10-0-141-74.ec2.internal <none>
cakephp-ex-1-deploy 0/1 Completed 0 3m44s 10.129.2.9 ip-10-0-147-65.ec2.internal <none>
cakephp-ex-1-ktz97 1/1 Running 0 3m33s 10.128.2.11 ip-10-0-168-105.ec2.internal <none>
2.1.5.4. Viewing pod logs Link kopierenLink in die Zwischenablage kopiert!
Use the oc logs
command to view logs for a particular pod.
oc logs cakephp-ex-1-deploy
$ oc logs cakephp-ex-1-deploy
Example output
--> Scaling cakephp-ex-1 to 1 --> Success
--> Scaling cakephp-ex-1 to 1
--> Success
2.1.5.5. Viewing the current project Link kopierenLink in die Zwischenablage kopiert!
Use the oc project
command to view the current project.
oc project
$ oc project
Example output
Using project "my-project" on server "https://openshift.example.com:6443".
Using project "my-project" on server "https://openshift.example.com:6443".
2.1.5.6. Viewing the status for the current project Link kopierenLink in die Zwischenablage kopiert!
Use the oc status
command to view information about the current project, such as services, deployments, and build configs.
oc status
$ oc status
Example output
2.1.5.7. Listing supported API resources Link kopierenLink in die Zwischenablage kopiert!
Use the oc api-resources
command to view the list of supported API resources on the server.
oc api-resources
$ oc api-resources
Example output
NAME SHORTNAMES APIGROUP NAMESPACED KIND bindings true Binding componentstatuses cs false ComponentStatus configmaps cm true ConfigMap ...
NAME SHORTNAMES APIGROUP NAMESPACED KIND
bindings true Binding
componentstatuses cs false ComponentStatus
configmaps cm true ConfigMap
...
2.1.6. Getting help Link kopierenLink in die Zwischenablage kopiert!
You can get help with CLI commands and Red Hat OpenShift Service on AWS resources in the following ways:
Use
oc help
to get a list and description of all available CLI commands:Example: Get general help for the CLI
oc help
$ oc help
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Example output
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Use the
--help
flag to get help about a specific CLI command:Example: Get help for the
oc create
commandoc create --help
$ oc create --help
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Example output
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Use the
oc explain
command to view the description and fields for a particular resource:Example: View documentation for the
Pod
resourceoc explain pods
$ oc explain pods
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Example output
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
2.1.7. Logging out of the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
You can log out the OpenShift CLI to end your current session.
Use the
oc logout
command.oc logout
$ oc logout
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Example output
Logged "user1" out on "https://openshift.example.com"
Logged "user1" out on "https://openshift.example.com"
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
This deletes the saved authentication token from the server and removes it from your configuration file.
2.2. Configuring the OpenShift CLI Link kopierenLink in die Zwischenablage kopiert!
2.2.1. Enabling tab completion Link kopierenLink in die Zwischenablage kopiert!
You can enable tab completion for the Bash or Zsh shells.
2.2.1.1. Enabling tab completion for Bash Link kopierenLink in die Zwischenablage kopiert!
After you install the OpenShift CLI (oc
), you can enable tab completion to automatically complete oc
commands or suggest options when you press Tab. The following procedure enables tab completion for the Bash shell.
Prerequisites
-
You must have the OpenShift CLI (
oc
) installed. -
You must have the package
bash-completion
installed.
Procedure
Save the Bash completion code to a file:
oc completion bash > oc_bash_completion
$ oc completion bash > oc_bash_completion
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Copy the file to
/etc/bash_completion.d/
:sudo cp oc_bash_completion /etc/bash_completion.d/
$ sudo cp oc_bash_completion /etc/bash_completion.d/
Copy to Clipboard Copied! Toggle word wrap Toggle overflow You can also save the file to a local directory and source it from your
.bashrc
file instead.
Tab completion is enabled when you open a new terminal.
2.2.1.2. Enabling tab completion for Zsh Link kopierenLink in die Zwischenablage kopiert!
After you install the OpenShift CLI (oc
), you can enable tab completion to automatically complete oc
commands or suggest options when you press Tab. The following procedure enables tab completion for the Zsh shell.
Prerequisites
-
You must have the OpenShift CLI (
oc
) installed.
Procedure
To add tab completion for
oc
to your.zshrc
file, run the following command:Copy to Clipboard Copied! Toggle word wrap Toggle overflow
Tab completion is enabled when you open a new terminal.
2.2.2. Accessing kubeconfig by using the oc CLI Link kopierenLink in die Zwischenablage kopiert!
You can use the oc
CLI to log in to your OpenShift cluster and retrieve a kubeconfig file for accessing the cluster from the command line.
Prerequisites
- You have access to the Red Hat OpenShift Service on AWS web console or API server endpoint.
Procedure
Log in to your OpenShift cluster by running the following command:
oc login <api-server-url> -u <username> -p <password>
$ oc login <api-server-url> -u <username> -p <password>
1 2 3 Copy to Clipboard Copied! Toggle word wrap Toggle overflow - 1
- Specify the full API server URL. For example:
https://api.my-cluster.example.com:6443
. - 2
- Specify a valid username. For example:
kubeadmin
. - 3
- Provide the password for the specified user. For example, the
kubeadmin
password generated during cluster installation.
Save the cluster configuration to a local file by running the following command:
oc config view --raw > kubeconfig
$ oc config view --raw > kubeconfig
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Set the
KUBECONFIG
environment variable to point to the exported file by running the following command:export KUBECONFIG=./kubeconfig
$ export KUBECONFIG=./kubeconfig
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Use
oc
to interact with your OpenShift cluster by running the following command:oc get nodes
$ oc get nodes
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
If you plan to reuse the exported kubeconfig
file across sessions or machines, store it securely and avoid committing it to source control.
2.3. Usage of oc and kubectl commands Link kopierenLink in die Zwischenablage kopiert!
The Kubernetes command-line interface (CLI), kubectl
, can be used to run commands against a Kubernetes cluster. Because Red Hat OpenShift Service on AWS is a certified Kubernetes distribution, you can use the supported kubectl
binaries that ship with Red Hat OpenShift Service on AWS, or you can gain extended functionality by using the oc
binary.
2.3.1. The oc binary Link kopierenLink in die Zwischenablage kopiert!
The oc
binary offers the same capabilities as the kubectl
binary, but it extends to natively support additional Red Hat OpenShift Service on AWS features, including:
Full support for Red Hat OpenShift Service on AWS resources
Resources such as
DeploymentConfig
,BuildConfig
,Route
,ImageStream
, andImageStreamTag
objects are specific to Red Hat OpenShift Service on AWS distributions, and build upon standard Kubernetes primitives.- Authentication
Additional commands
The additional command
oc new-app
, for example, makes it easier to get new applications started using existing source code or pre-built images. Similarly, the additional commandoc new-project
makes it easier to start a project that you can switch to as your default.
If you installed an earlier version of the oc
binary, you cannot use it to complete all of the commands in Red Hat OpenShift Service on AWS . If you want the latest features, you must download and install the latest version of the oc
binary corresponding to your Red Hat OpenShift Service on AWS server version.
Non-security API changes will involve, at minimum, two minor releases (4.1 to 4.2 to 4.3, for example) to allow older oc
binaries to update. Using new capabilities might require newer oc
binaries. A 4.3 server might have additional capabilities that a 4.2 oc
binary cannot use and a 4.3 oc
binary might have additional capabilities that are unsupported by a 4.2 server.
X.Y ( |
X.Y+N [a] ( | |
X.Y (Server) |
|
|
X.Y+N [a] (Server) |
|
|
[a]
Where N is a number greater than or equal to 1.
|
Fully compatible.
oc
client might not be able to access server features.
oc
client might provide options and features that might not be compatible with the accessed server.
2.3.2. The kubectl binary Link kopierenLink in die Zwischenablage kopiert!
The kubectl
binary is provided as a means to support existing workflows and scripts for new Red Hat OpenShift Service on AWS users coming from a standard Kubernetes environment, or for those who prefer to use the kubectl
CLI. Existing users of kubectl
can continue to use the binary to interact with Kubernetes primitives, with no changes required to the Red Hat OpenShift Service on AWS cluster.
You can install the supported kubectl
binary by following the steps to Install the OpenShift CLI. The kubectl
binary is included in the archive if you download the binary, or is installed when you install the CLI by using an RPM.
For more information, see the kubectl documentation.
2.4. Managing CLI profiles Link kopierenLink in die Zwischenablage kopiert!
A CLI configuration file allows you to configure different profiles, or contexts, for use with the CLI tools overview. A context consists of a Red Hat OpenShift Service on AWS server information associated with a nickname.
2.4.1. About switches between CLI profiles Link kopierenLink in die Zwischenablage kopiert!
Contexts allow you to easily switch between multiple users across multiple Red Hat OpenShift Service on AWS servers, or clusters, when using CLI operations. Nicknames make managing CLI configurations easier by providing short-hand references to contexts, user credentials, and cluster details. After a user logs in with the oc
CLI for the first time, Red Hat OpenShift Service on AWS creates a ~/.kube/config
file if one does not already exist. As more authentication and connection details are provided to the CLI, either automatically during an oc login
operation or by manually configuring CLI profiles, the updated information is stored in the configuration file:
CLI config file
- 1
- The
clusters
section defines connection details for Red Hat OpenShift Service on AWS clusters, including the address for their master server. In this example, one cluster is nicknamedopenshift1.example.com:8443
and another is nicknamedopenshift2.example.com:8443
. - 2
- This
contexts
section defines two contexts: one nicknamedalice-project/openshift1.example.com:8443/alice
, using thealice-project
project,openshift1.example.com:8443
cluster, andalice
user, and another nicknamedjoe-project/openshift1.example.com:8443/alice
, using thejoe-project
project,openshift1.example.com:8443
cluster andalice
user. - 3
- The
current-context
parameter shows that thejoe-project/openshift1.example.com:8443/alice
context is currently in use, allowing thealice
user to work in thejoe-project
project on theopenshift1.example.com:8443
cluster. - 4
- The
users
section defines user credentials. In this example, the user nicknamealice/openshift1.example.com:8443
uses an access token.
The CLI can support multiple configuration files which are loaded at runtime and merged together along with any override options specified from the command line. After you are logged in, you can use the oc status
or oc project
command to verify your current working environment:
Verify the current working environment
oc status
$ oc status
Example output
List the current project
oc project
$ oc project
Example output
Using project "joe-project" from context named "joe-project/openshift1.example.com:8443/alice" on server "https://openshift1.example.com:8443".
Using project "joe-project" from context named "joe-project/openshift1.example.com:8443/alice" on server "https://openshift1.example.com:8443".
You can run the oc login
command again and supply the required information during the interactive process, to log in using any other combination of user credentials and cluster details. A context is constructed based on the supplied information if one does not already exist. If you are already logged in and want to switch to another project the current user already has access to, use the oc project
command and enter the name of the project:
oc project alice-project
$ oc project alice-project
Example output
Now using project "alice-project" on server "https://openshift1.example.com:8443".
Now using project "alice-project" on server "https://openshift1.example.com:8443".
At any time, you can use the oc config view
command to view your current CLI configuration, as seen in the output. Additional CLI configuration commands are also available for more advanced usage.
If you have access to administrator credentials but are no longer logged in as the default system user system:admin
, you can log back in as this user at any time as long as the credentials are still present in your CLI config file. The following command logs in and switches to the default project:
oc login -u system:admin -n default
$ oc login -u system:admin -n default
2.4.2. Manual configuration of CLI profiles Link kopierenLink in die Zwischenablage kopiert!
This section covers more advanced usage of CLI configurations. In most situations, you can use the oc login
and oc project
commands to log in and switch between contexts and projects.
If you want to manually configure your CLI config files, you can use the oc config
command instead of directly modifying the files. The oc config
command includes a number of helpful sub-commands for this purpose:
Subcommand | Usage |
---|---|
| Sets a cluster entry in the CLI config file. If the referenced cluster nickname already exists, the specified information is merged in. oc config set-cluster <cluster_nickname> [--server=<master_ip_or_fqdn>]
|
| Sets a context entry in the CLI config file. If the referenced context nickname already exists, the specified information is merged in. oc config set-context <context_nickname> [--cluster=<cluster_nickname>]
|
| Sets the current context using the specified context nickname. oc config use-context <context_nickname>
|
| Sets an individual value in the CLI config file. oc config set <property_name> <property_value>
The |
| Unsets individual values in the CLI config file. oc config unset <property_name>
The |
| Displays the merged CLI configuration currently in use. oc config view
Displays the result of the specified CLI config file. oc config view --config=<specific_filename>
|
Example usage
-
Log in as a user that uses an access token. This token is used by the
alice
user:
oc login https://openshift1.example.com --token=ns7yVhuRNpDM9cgzfhhxQ7bM5s7N2ZVrkZepSRf4LC0
$ oc login https://openshift1.example.com --token=ns7yVhuRNpDM9cgzfhhxQ7bM5s7N2ZVrkZepSRf4LC0
- View the cluster entry automatically created:
oc config view
$ oc config view
Example output
- Update the current context to have users log in to the desired namespace:
oc config set-context `oc config current-context` --namespace=<project_name>
$ oc config set-context `oc config current-context` --namespace=<project_name>
- Examine the current context, to confirm that the changes are implemented:
oc whoami -c
$ oc whoami -c
All subsequent CLI operations uses the new context, unless otherwise specified by overriding CLI options or until the context is switched.
2.4.3. Load and merge rules Link kopierenLink in die Zwischenablage kopiert!
You can follow these rules, when issuing CLI operations for the loading and merging order for the CLI configuration:
CLI config files are retrieved from your workstation, using the following hierarchy and merge rules:
-
If the
--config
option is set, then only that file is loaded. The flag is set once and no merging takes place. -
If the
$KUBECONFIG
environment variable is set, then it is used. The variable can be a list of paths, and if so the paths are merged together. When a value is modified, it is modified in the file that defines the stanza. When a value is created, it is created in the first file that exists. If no files in the chain exist, then it creates the last file in the list. -
Otherwise, the
~/.kube/config
file is used and no merging takes place.
-
If the
The context to use is determined based on the first match in the following flow:
-
The value of the
--context
option. -
The
current-context
value from the CLI config file. - An empty value is allowed at this stage.
-
The value of the
The user and cluster to use is determined. At this point, you may or may not have a context; they are built based on the first match in the following flow, which is run once for the user and once for the cluster:
-
The value of the
--user
for user name and--cluster
option for cluster name. -
If the
--context
option is present, then use the context’s value. - An empty value is allowed at this stage.
-
The value of the
The actual cluster information to use is determined. At this point, you may or may not have cluster information. Each piece of the cluster information is built based on the first match in the following flow:
The values of any of the following command-line options:
-
--server
, -
--api-version
-
--certificate-authority
-
--insecure-skip-tls-verify
-
- If cluster information and a value for the attribute is present, then use it.
- If you do not have a server location, then there is an error.
The actual user information to use is determined. Users are built using the same rules as clusters, except that you can only have one authentication technique per user; conflicting techniques cause the operation to fail. Command-line options take precedence over config file values. Valid command-line options are:
-
--auth-path
-
--client-certificate
-
--client-key
-
--token
-
- For any information that is still missing, default values are used and prompts are given for additional information.
2.5. Extending the OpenShift CLI with plugins Link kopierenLink in die Zwischenablage kopiert!
You can write and install plugins to build on the default oc
commands, allowing you to perform new and more complex tasks with the OpenShift CLI.
2.5.1. Writing CLI plugins Link kopierenLink in die Zwischenablage kopiert!
You can write a plugin for the OpenShift CLI in any programming language or script that allows you to write command-line commands. Note that you can not use a plugin to overwrite an existing oc
command.
Procedure
This procedure creates a simple Bash plugin that prints a message to the terminal when the oc foo
command is issued.
Create a file called
oc-foo
.When naming your plugin file, keep the following in mind:
-
The file must begin with
oc-
orkubectl-
to be recognized as a plugin. -
The file name determines the command that invokes the plugin. For example, a plugin with the file name
oc-foo-bar
can be invoked by a command ofoc foo bar
. You can also use underscores if you want the command to contain dashes. For example, a plugin with the file nameoc-foo_bar
can be invoked by a command ofoc foo-bar
.
-
The file must begin with
Add the following contents to the file.
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
After you install this plugin for the OpenShift CLI, it can be invoked using the oc foo
command.
2.5.2. Installing and using CLI plugins Link kopierenLink in die Zwischenablage kopiert!
After you write a custom plugin for the OpenShift CLI, you must install the plugin before use.
Prerequisites
-
You must have the
oc
CLI tool installed. -
You must have a CLI plugin file that begins with
oc-
orkubectl-
.
Procedure
If necessary, update the plugin file to be executable.
chmod +x <plugin_file>
$ chmod +x <plugin_file>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Place the file anywhere in your
PATH
, such as/usr/local/bin/
.sudo mv <plugin_file> /usr/local/bin/.
$ sudo mv <plugin_file> /usr/local/bin/.
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Run
oc plugin list
to make sure that the plugin is listed.oc plugin list
$ oc plugin list
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Example output
The following compatible plugins are available: /usr/local/bin/<plugin_file>
The following compatible plugins are available: /usr/local/bin/<plugin_file>
Copy to Clipboard Copied! Toggle word wrap Toggle overflow If your plugin is not listed here, verify that the file begins with
oc-
orkubectl-
, is executable, and is on yourPATH
.Invoke the new command or option introduced by the plugin.
For example, if you built and installed the
kubectl-ns
plugin from the Sample plugin repository, you can use the following command to view the current namespace.oc ns
$ oc ns
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Note that the command to invoke the plugin depends on the plugin file name. For example, a plugin with the file name of
oc-foo-bar
is invoked by theoc foo bar
command.
2.6. OpenShift CLI developer command reference Link kopierenLink in die Zwischenablage kopiert!
This reference provides descriptions and example commands for OpenShift CLI (oc
) developer commands.
Run oc help
to list all commands or run oc <command> --help
to get additional details for a specific command.
2.6.1. OpenShift CLI (oc) developer commands Link kopierenLink in die Zwischenablage kopiert!
2.6.1.1. oc annotate Link kopierenLink in die Zwischenablage kopiert!
Update the annotations on a resource
Example usage
2.6.1.2. oc api-resources Link kopierenLink in die Zwischenablage kopiert!
Print the supported API resources on the server
Example usage
2.6.1.3. oc api-versions Link kopierenLink in die Zwischenablage kopiert!
Print the supported API versions on the server, in the form of "group/version"
Example usage
Print the supported API versions
# Print the supported API versions
oc api-versions
2.6.1.4. oc apply Link kopierenLink in die Zwischenablage kopiert!
Apply a configuration to a resource by file name or stdin
Example usage
2.6.1.5. oc apply edit-last-applied Link kopierenLink in die Zwischenablage kopiert!
Edit latest last-applied-configuration annotations of a resource/object
Example usage
Edit the last-applied-configuration annotations by type/name in YAML
# Edit the last-applied-configuration annotations by type/name in YAML
oc apply edit-last-applied deployment/nginx
# Edit the last-applied-configuration annotations by file in JSON
oc apply edit-last-applied -f deploy.yaml -o json
2.6.1.6. oc apply set-last-applied Link kopierenLink in die Zwischenablage kopiert!
Set the last-applied-configuration annotation on a live object to match the contents of a file
Example usage
2.6.1.7. oc apply view-last-applied Link kopierenLink in die Zwischenablage kopiert!
View the latest last-applied-configuration annotations of a resource/object
Example usage
View the last-applied-configuration annotations by type/name in YAML
# View the last-applied-configuration annotations by type/name in YAML
oc apply view-last-applied deployment/nginx
# View the last-applied-configuration annotations by file in JSON
oc apply view-last-applied -f deploy.yaml -o json
2.6.1.8. oc attach Link kopierenLink in die Zwischenablage kopiert!
Attach to a running container
Example usage
2.6.1.9. oc auth can-i Link kopierenLink in die Zwischenablage kopiert!
Check whether an action is allowed
Example usage
2.6.1.10. oc auth reconcile Link kopierenLink in die Zwischenablage kopiert!
Reconciles rules for RBAC role, role binding, cluster role, and cluster role binding objects
Example usage
Reconcile RBAC resources from a file
# Reconcile RBAC resources from a file
oc auth reconcile -f my-rbac-rules.yaml
2.6.1.11. oc auth whoami Link kopierenLink in die Zwischenablage kopiert!
Experimental: Check self subject attributes
Example usage
Get your subject attributes
# Get your subject attributes
oc auth whoami
# Get your subject attributes in JSON format
oc auth whoami -o json
2.6.1.12. oc autoscale Link kopierenLink in die Zwischenablage kopiert!
Autoscale a deployment config, deployment, replica set, stateful set, or replication controller
Example usage
Auto scale a deployment "foo", with the number of pods between 2 and 10, no target CPU utilization specified so a default autoscaling policy will be used
# Auto scale a deployment "foo", with the number of pods between 2 and 10, no target CPU utilization specified so a default autoscaling policy will be used
oc autoscale deployment foo --min=2 --max=10
# Auto scale a replication controller "foo", with the number of pods between 1 and 5, target CPU utilization at 80%
oc autoscale rc foo --max=5 --cpu-percent=80
2.6.1.13. oc cancel-build Link kopierenLink in die Zwischenablage kopiert!
Cancel running, pending, or new builds
Example usage
2.6.1.14. oc cluster-info Link kopierenLink in die Zwischenablage kopiert!
Display cluster information
Example usage
Print the address of the control plane and cluster services
# Print the address of the control plane and cluster services
oc cluster-info
2.6.1.15. oc cluster-info dump Link kopierenLink in die Zwischenablage kopiert!
Dump relevant information for debugging and diagnosis
Example usage
2.6.1.16. oc completion Link kopierenLink in die Zwischenablage kopiert!
Output shell completion code for the specified shell (bash, zsh, fish, or powershell)
Example usage
2.6.1.17. oc config current-context Link kopierenLink in die Zwischenablage kopiert!
Display the current-context
Example usage
Display the current-context
# Display the current-context
oc config current-context
2.6.1.18. oc config delete-cluster Link kopierenLink in die Zwischenablage kopiert!
Delete the specified cluster from the kubeconfig
Example usage
Delete the minikube cluster
# Delete the minikube cluster
oc config delete-cluster minikube
2.6.1.19. oc config delete-context Link kopierenLink in die Zwischenablage kopiert!
Delete the specified context from the kubeconfig
Example usage
Delete the context for the minikube cluster
# Delete the context for the minikube cluster
oc config delete-context minikube
2.6.1.20. oc config delete-user Link kopierenLink in die Zwischenablage kopiert!
Delete the specified user from the kubeconfig
Example usage
Delete the minikube user
# Delete the minikube user
oc config delete-user minikube
2.6.1.21. oc config get-clusters Link kopierenLink in die Zwischenablage kopiert!
Display clusters defined in the kubeconfig
Example usage
List the clusters that oc knows about
# List the clusters that oc knows about
oc config get-clusters
2.6.1.22. oc config get-contexts Link kopierenLink in die Zwischenablage kopiert!
Describe one or many contexts
Example usage
List all the contexts in your kubeconfig file
# List all the contexts in your kubeconfig file
oc config get-contexts
# Describe one context in your kubeconfig file
oc config get-contexts my-context
2.6.1.23. oc config get-users Link kopierenLink in die Zwischenablage kopiert!
Display users defined in the kubeconfig
Example usage
List the users that oc knows about
# List the users that oc knows about
oc config get-users
2.6.1.24. oc config new-admin-kubeconfig Link kopierenLink in die Zwischenablage kopiert!
Generate, make the server trust, and display a new admin.kubeconfig
Example usage
Generate a new admin kubeconfig
# Generate a new admin kubeconfig
oc config new-admin-kubeconfig
2.6.1.25. oc config new-kubelet-bootstrap-kubeconfig Link kopierenLink in die Zwischenablage kopiert!
Generate, make the server trust, and display a new kubelet /etc/kubernetes/kubeconfig
Example usage
Generate a new kubelet bootstrap kubeconfig
# Generate a new kubelet bootstrap kubeconfig
oc config new-kubelet-bootstrap-kubeconfig
2.6.1.26. oc config refresh-ca-bundle Link kopierenLink in die Zwischenablage kopiert!
Update the OpenShift CA bundle by contacting the API server
Example usage
2.6.1.27. oc config rename-context Link kopierenLink in die Zwischenablage kopiert!
Rename a context from the kubeconfig file
Example usage
Rename the context 'old-name' to 'new-name' in your kubeconfig file
# Rename the context 'old-name' to 'new-name' in your kubeconfig file
oc config rename-context old-name new-name
2.6.1.28. oc config set Link kopierenLink in die Zwischenablage kopiert!
Set an individual value in a kubeconfig file
Example usage
2.6.1.29. oc config set-cluster Link kopierenLink in die Zwischenablage kopiert!
Set a cluster entry in kubeconfig
Example usage
2.6.1.30. oc config set-context Link kopierenLink in die Zwischenablage kopiert!
Set a context entry in kubeconfig
Example usage
Set the user field on the gce context entry without touching other values
# Set the user field on the gce context entry without touching other values
oc config set-context gce --user=cluster-admin
2.6.1.31. oc config set-credentials Link kopierenLink in die Zwischenablage kopiert!
Set a user entry in kubeconfig
Example usage
2.6.1.32. oc config unset Link kopierenLink in die Zwischenablage kopiert!
Unset an individual value in a kubeconfig file
Example usage
Unset the current-context
# Unset the current-context
oc config unset current-context
# Unset namespace in foo context
oc config unset contexts.foo.namespace
2.6.1.33. oc config use-context Link kopierenLink in die Zwischenablage kopiert!
Set the current-context in a kubeconfig file
Example usage
Use the context for the minikube cluster
# Use the context for the minikube cluster
oc config use-context minikube
2.6.1.34. oc config view Link kopierenLink in die Zwischenablage kopiert!
Display merged kubeconfig settings or a specified kubeconfig file
Example usage
2.6.1.35. oc cp Link kopierenLink in die Zwischenablage kopiert!
Copy files and directories to and from containers
Example usage
2.6.1.36. oc create Link kopierenLink in die Zwischenablage kopiert!
Create a resource from a file or from stdin
Example usage
2.6.1.37. oc create build Link kopierenLink in die Zwischenablage kopiert!
Create a new build
Example usage
Create a new build
# Create a new build
oc create build myapp
2.6.1.38. oc create clusterresourcequota Link kopierenLink in die Zwischenablage kopiert!
Create a cluster resource quota
Example usage
Create a cluster resource quota limited to 10 pods
# Create a cluster resource quota limited to 10 pods
oc create clusterresourcequota limit-bob --project-annotation-selector=openshift.io/requester=user-bob --hard=pods=10
2.6.1.39. oc create clusterrole Link kopierenLink in die Zwischenablage kopiert!
Create a cluster role
Example usage
2.6.1.40. oc create clusterrolebinding Link kopierenLink in die Zwischenablage kopiert!
Create a cluster role binding for a particular cluster role
Example usage
Create a cluster role binding for user1, user2, and group1 using the cluster-admin cluster role
# Create a cluster role binding for user1, user2, and group1 using the cluster-admin cluster role
oc create clusterrolebinding cluster-admin --clusterrole=cluster-admin --user=user1 --user=user2 --group=group1
2.6.1.41. oc create configmap Link kopierenLink in die Zwischenablage kopiert!
Create a config map from a local file, directory or literal value
Example usage
2.6.1.42. oc create cronjob Link kopierenLink in die Zwischenablage kopiert!
Create a cron job with the specified name
Example usage
Create a cron job
# Create a cron job
oc create cronjob my-job --image=busybox --schedule="*/1 * * * *"
# Create a cron job with a command
oc create cronjob my-job --image=busybox --schedule="*/1 * * * *" -- date
2.6.1.43. oc create deployment Link kopierenLink in die Zwischenablage kopiert!
Create a deployment with the specified name
Example usage
2.6.1.44. oc create deploymentconfig Link kopierenLink in die Zwischenablage kopiert!
Create a deployment config with default options that uses a given image
Example usage
Create an nginx deployment config named my-nginx
# Create an nginx deployment config named my-nginx
oc create deploymentconfig my-nginx --image=nginx
2.6.1.45. oc create identity Link kopierenLink in die Zwischenablage kopiert!
Manually create an identity (only needed if automatic creation is disabled)
Example usage
Create an identity with identity provider "acme_ldap" and the identity provider username "adamjones"
# Create an identity with identity provider "acme_ldap" and the identity provider username "adamjones"
oc create identity acme_ldap:adamjones
2.6.1.46. oc create imagestream Link kopierenLink in die Zwischenablage kopiert!
Create a new empty image stream
Example usage
Create a new image stream
# Create a new image stream
oc create imagestream mysql
2.6.1.47. oc create imagestreamtag Link kopierenLink in die Zwischenablage kopiert!
Create a new image stream tag
Example usage
Create a new image stream tag based on an image in a remote registry
# Create a new image stream tag based on an image in a remote registry
oc create imagestreamtag mysql:latest --from-image=myregistry.local/mysql/mysql:5.0
2.6.1.48. oc create ingress Link kopierenLink in die Zwischenablage kopiert!
Create an ingress with the specified name
Example usage
2.6.1.49. oc create job Link kopierenLink in die Zwischenablage kopiert!
Create a job with the specified name
Example usage
2.6.1.50. oc create namespace Link kopierenLink in die Zwischenablage kopiert!
Create a namespace with the specified name
Example usage
Create a new namespace named my-namespace
# Create a new namespace named my-namespace
oc create namespace my-namespace
2.6.1.51. oc create poddisruptionbudget Link kopierenLink in die Zwischenablage kopiert!
Create a pod disruption budget with the specified name
Example usage
2.6.1.52. oc create priorityclass Link kopierenLink in die Zwischenablage kopiert!
Create a priority class with the specified name
Example usage
2.6.1.53. oc create quota Link kopierenLink in die Zwischenablage kopiert!
Create a quota with the specified name
Example usage
Create a new resource quota named my-quota
# Create a new resource quota named my-quota
oc create quota my-quota --hard=cpu=1,memory=1G,pods=2,services=3,replicationcontrollers=2,resourcequotas=1,secrets=5,persistentvolumeclaims=10
# Create a new resource quota named best-effort
oc create quota best-effort --hard=pods=100 --scopes=BestEffort
2.6.1.54. oc create role Link kopierenLink in die Zwischenablage kopiert!
Create a role with single rule
Example usage
2.6.1.55. oc create rolebinding Link kopierenLink in die Zwischenablage kopiert!
Create a role binding for a particular role or cluster role
Example usage
Create a role binding for user1, user2, and group1 using the admin cluster role
# Create a role binding for user1, user2, and group1 using the admin cluster role
oc create rolebinding admin --clusterrole=admin --user=user1 --user=user2 --group=group1
# Create a role binding for service account monitoring:sa-dev using the admin role
oc create rolebinding admin-binding --role=admin --serviceaccount=monitoring:sa-dev
2.6.1.56. oc create route edge Link kopierenLink in die Zwischenablage kopiert!
Create a route that uses edge TLS termination
Example usage
2.6.1.57. oc create route passthrough Link kopierenLink in die Zwischenablage kopiert!
Create a route that uses passthrough TLS termination
Example usage
2.6.1.58. oc create route reencrypt Link kopierenLink in die Zwischenablage kopiert!
Create a route that uses reencrypt TLS termination
Example usage
2.6.1.59. oc create secret docker-registry Link kopierenLink in die Zwischenablage kopiert!
Create a secret for use with a Docker registry
Example usage
If you do not already have a .dockercfg file, create a dockercfg secret directly
# If you do not already have a .dockercfg file, create a dockercfg secret directly
oc create secret docker-registry my-secret --docker-server=DOCKER_REGISTRY_SERVER --docker-username=DOCKER_USER --docker-password=DOCKER_PASSWORD --docker-email=DOCKER_EMAIL
# Create a new secret named my-secret from ~/.docker/config.json
oc create secret docker-registry my-secret --from-file=path/to/.docker/config.json
2.6.1.60. oc create secret generic Link kopierenLink in die Zwischenablage kopiert!
Create a secret from a local file, directory, or literal value
Example usage
2.6.1.61. oc create secret tls Link kopierenLink in die Zwischenablage kopiert!
Create a TLS secret
Example usage
Create a new TLS secret named tls-secret with the given key pair
# Create a new TLS secret named tls-secret with the given key pair
oc create secret tls tls-secret --cert=path/to/tls.crt --key=path/to/tls.key
2.6.1.62. oc create service clusterip Link kopierenLink in die Zwischenablage kopiert!
Create a ClusterIP service
Example usage
Create a new ClusterIP service named my-cs
# Create a new ClusterIP service named my-cs
oc create service clusterip my-cs --tcp=5678:8080
# Create a new ClusterIP service named my-cs (in headless mode)
oc create service clusterip my-cs --clusterip="None"
2.6.1.63. oc create service externalname Link kopierenLink in die Zwischenablage kopiert!
Create an ExternalName service
Example usage
Create a new ExternalName service named my-ns
# Create a new ExternalName service named my-ns
oc create service externalname my-ns --external-name bar.com
2.6.1.64. oc create service loadbalancer Link kopierenLink in die Zwischenablage kopiert!
Create a LoadBalancer service
Example usage
Create a new LoadBalancer service named my-lbs
# Create a new LoadBalancer service named my-lbs
oc create service loadbalancer my-lbs --tcp=5678:8080
2.6.1.65. oc create service nodeport Link kopierenLink in die Zwischenablage kopiert!
Create a NodePort service
Example usage
Create a new NodePort service named my-ns
# Create a new NodePort service named my-ns
oc create service nodeport my-ns --tcp=5678:8080
2.6.1.66. oc create serviceaccount Link kopierenLink in die Zwischenablage kopiert!
Create a service account with the specified name
Example usage
Create a new service account named my-service-account
# Create a new service account named my-service-account
oc create serviceaccount my-service-account
2.6.1.67. oc create token Link kopierenLink in die Zwischenablage kopiert!
Request a service account token
Example usage
2.6.1.68. oc create user Link kopierenLink in die Zwischenablage kopiert!
Manually create a user (only needed if automatic creation is disabled)
Example usage
Create a user with the username "ajones" and the display name "Adam Jones"
# Create a user with the username "ajones" and the display name "Adam Jones"
oc create user ajones --full-name="Adam Jones"
2.6.1.69. oc create useridentitymapping Link kopierenLink in die Zwischenablage kopiert!
Manually map an identity to a user
Example usage
Map the identity "acme_ldap:adamjones" to the user "ajones"
# Map the identity "acme_ldap:adamjones" to the user "ajones"
oc create useridentitymapping acme_ldap:adamjones ajones
2.6.1.70. oc debug Link kopierenLink in die Zwischenablage kopiert!
Launch a new instance of a pod for debugging
Example usage
2.6.1.71. oc delete Link kopierenLink in die Zwischenablage kopiert!
Delete resources by file names, stdin, resources and names, or by resources and label selector
Example usage
2.6.1.72. oc describe Link kopierenLink in die Zwischenablage kopiert!
Show details of a specific resource or group of resources
Example usage
2.6.1.73. oc diff Link kopierenLink in die Zwischenablage kopiert!
Diff the live version against a would-be applied version
Example usage
Diff resources included in pod.json
# Diff resources included in pod.json
oc diff -f pod.json
# Diff file read from stdin
cat service.yaml | oc diff -f -
2.6.1.74. oc edit Link kopierenLink in die Zwischenablage kopiert!
Edit a resource on the server
Example usage
2.6.1.75. oc events Link kopierenLink in die Zwischenablage kopiert!
List events
Example usage
2.6.1.76. oc exec Link kopierenLink in die Zwischenablage kopiert!
Execute a command in a container
Example usage
2.6.1.77. oc explain Link kopierenLink in die Zwischenablage kopiert!
Get documentation for a resource
Example usage
2.6.1.78. oc expose Link kopierenLink in die Zwischenablage kopiert!
Expose a replicated application as a service or route
Example usage
2.6.1.79. oc extract Link kopierenLink in die Zwischenablage kopiert!
Extract secrets or config maps to disk
Example usage
2.6.1.80. oc get Link kopierenLink in die Zwischenablage kopiert!
Display one or many resources
Example usage
2.6.1.81. oc get-token Link kopierenLink in die Zwischenablage kopiert!
Experimental: Get token from external OIDC issuer as credentials exec plugin
Example usage
Starts an auth code flow to the issuer URL with the client ID and the given extra scopes
# Starts an auth code flow to the issuer URL with the client ID and the given extra scopes
oc get-token --client-id=client-id --issuer-url=test.issuer.url --extra-scopes=email,profile
# Starts an auth code flow to the issuer URL with a different callback address
oc get-token --client-id=client-id --issuer-url=test.issuer.url --callback-address=127.0.0.1:8343
2.6.1.82. oc idle Link kopierenLink in die Zwischenablage kopiert!
Idle scalable resources
Example usage
Idle the scalable controllers associated with the services listed in to-idle.txt
# Idle the scalable controllers associated with the services listed in to-idle.txt
$ oc idle --resource-names-file to-idle.txt
2.6.1.83. oc image append Link kopierenLink in die Zwischenablage kopiert!
Add layers to images and push them to a registry
Example usage
2.6.1.84. oc image extract Link kopierenLink in die Zwischenablage kopiert!
Copy files from an image to the file system
Example usage
2.6.1.85. oc image info Link kopierenLink in die Zwischenablage kopiert!
Display information about an image
Example usage
2.6.1.86. oc image mirror Link kopierenLink in die Zwischenablage kopiert!
Mirror images from one repository to another
Example usage
2.6.1.87. oc import-image Link kopierenLink in die Zwischenablage kopiert!
Import images from a container image registry
Example usage
2.6.1.88. oc kustomize Link kopierenLink in die Zwischenablage kopiert!
Build a kustomization target from a directory or URL
Example usage
2.6.1.89. oc label Link kopierenLink in die Zwischenablage kopiert!
Update the labels on a resource
Example usage
2.6.1.90. oc login Link kopierenLink in die Zwischenablage kopiert!
Log in to a server
Example usage
2.6.1.91. oc logout Link kopierenLink in die Zwischenablage kopiert!
End the current server session
Example usage
Log out
# Log out
oc logout
2.6.1.92. oc logs Link kopierenLink in die Zwischenablage kopiert!
Print the logs for a container in a pod
Example usage
2.6.1.93. oc new-app Link kopierenLink in die Zwischenablage kopiert!
Create a new application
Example usage
2.6.1.94. oc new-build Link kopierenLink in die Zwischenablage kopiert!
Create a new build configuration
Example usage
2.6.1.95. oc new-project Link kopierenLink in die Zwischenablage kopiert!
Request a new project
Example usage
Create a new project with minimal information
# Create a new project with minimal information
oc new-project web-team-dev
# Create a new project with a display name and description
oc new-project web-team-dev --display-name="Web Team Development" --description="Development project for the web team."
2.6.1.96. oc observe Link kopierenLink in die Zwischenablage kopiert!
Observe changes to resources and react to them (experimental)
Example usage
2.6.1.97. oc patch Link kopierenLink in die Zwischenablage kopiert!
Update fields of a resource
Example usage
2.6.1.98. oc plugin Link kopierenLink in die Zwischenablage kopiert!
Provides utilities for interacting with plugins
Example usage
List all available plugins
# List all available plugins
oc plugin list
# List only binary names of available plugins without paths
oc plugin list --name-only
2.6.1.99. oc plugin list Link kopierenLink in die Zwischenablage kopiert!
List all visible plugin executables on a user’s PATH
Example usage
List all available plugins
# List all available plugins
oc plugin list
# List only binary names of available plugins without paths
oc plugin list --name-only
2.6.1.100. oc policy add-role-to-user Link kopierenLink in die Zwischenablage kopiert!
Add a role to users or service accounts for the current project
Example usage
Add the 'view' role to user1 for the current project
# Add the 'view' role to user1 for the current project
oc policy add-role-to-user view user1
# Add the 'edit' role to serviceaccount1 for the current project
oc policy add-role-to-user edit -z serviceaccount1
2.6.1.101. oc policy scc-review Link kopierenLink in die Zwischenablage kopiert!
Check which service account can create a pod
Example usage
2.6.1.102. oc policy scc-subject-review Link kopierenLink in die Zwischenablage kopiert!
Check whether a user or a service account can create a pod
Example usage
2.6.1.103. oc port-forward Link kopierenLink in die Zwischenablage kopiert!
Forward one or more local ports to a pod
Example usage
2.6.1.104. oc process Link kopierenLink in die Zwischenablage kopiert!
Process a template into list of resources
Example usage
2.6.1.105. oc project Link kopierenLink in die Zwischenablage kopiert!
Switch to another project
Example usage
Switch to the 'myapp' project
# Switch to the 'myapp' project
oc project myapp
# Display the project currently in use
oc project
2.6.1.106. oc projects Link kopierenLink in die Zwischenablage kopiert!
Display existing projects
Example usage
List all projects
# List all projects
oc projects
2.6.1.107. oc proxy Link kopierenLink in die Zwischenablage kopiert!
Run a proxy to the Kubernetes API server
Example usage
2.6.1.108. oc registry login Link kopierenLink in die Zwischenablage kopiert!
Log in to the integrated registry
Example usage
Log in to the integrated registry
# Log in to the integrated registry
oc registry login
# Log in to different registry using BASIC auth credentials
oc registry login --registry quay.io/myregistry --auth-basic=USER:PASS
2.6.1.109. oc replace Link kopierenLink in die Zwischenablage kopiert!
Replace a resource by file name or stdin
Example usage
2.6.1.110. oc rollback Link kopierenLink in die Zwischenablage kopiert!
Revert part of an application back to a previous deployment
Example usage
2.6.1.111. oc rollout Link kopierenLink in die Zwischenablage kopiert!
Manage the rollout of a resource
Example usage
2.6.1.112. oc rollout cancel Link kopierenLink in die Zwischenablage kopiert!
Cancel the in-progress deployment
Example usage
Cancel the in-progress deployment based on 'nginx'
# Cancel the in-progress deployment based on 'nginx'
oc rollout cancel dc/nginx
2.6.1.113. oc rollout history Link kopierenLink in die Zwischenablage kopiert!
View rollout history
Example usage
View the rollout history of a deployment
# View the rollout history of a deployment
oc rollout history deployment/abc
# View the details of daemonset revision 3
oc rollout history daemonset/abc --revision=3
2.6.1.114. oc rollout latest Link kopierenLink in die Zwischenablage kopiert!
Start a new rollout for a deployment config with the latest state from its triggers
Example usage
Start a new rollout based on the latest images defined in the image change triggers
# Start a new rollout based on the latest images defined in the image change triggers
oc rollout latest dc/nginx
# Print the rolled out deployment config
oc rollout latest dc/nginx -o json
2.6.1.115. oc rollout pause Link kopierenLink in die Zwischenablage kopiert!
Mark the provided resource as paused
Example usage
Mark the nginx deployment as paused
# Mark the nginx deployment as paused
# Any current state of the deployment will continue its function; new updates
# to the deployment will not have an effect as long as the deployment is paused
oc rollout pause deployment/nginx
2.6.1.116. oc rollout restart Link kopierenLink in die Zwischenablage kopiert!
Restart a resource
Example usage
2.6.1.117. oc rollout resume Link kopierenLink in die Zwischenablage kopiert!
Resume a paused resource
Example usage
Resume an already paused deployment
# Resume an already paused deployment
oc rollout resume deployment/nginx
2.6.1.118. oc rollout retry Link kopierenLink in die Zwischenablage kopiert!
Retry the latest failed rollout
Example usage
Retry the latest failed deployment based on 'frontend'
# Retry the latest failed deployment based on 'frontend'
# The deployer pod and any hook pods are deleted for the latest failed deployment
oc rollout retry dc/frontend
2.6.1.119. oc rollout status Link kopierenLink in die Zwischenablage kopiert!
Show the status of the rollout
Example usage
Watch the rollout status of a deployment
# Watch the rollout status of a deployment
oc rollout status deployment/nginx
2.6.1.120. oc rollout undo Link kopierenLink in die Zwischenablage kopiert!
Undo a previous rollout
Example usage
2.6.1.121. oc rsh Link kopierenLink in die Zwischenablage kopiert!
Start a shell session in a container
Example usage
2.6.1.122. oc rsync Link kopierenLink in die Zwischenablage kopiert!
Copy files between a local file system and a pod
Example usage
Synchronize a local directory with a pod directory
# Synchronize a local directory with a pod directory
oc rsync ./local/dir/ POD:/remote/dir
# Synchronize a pod directory with a local directory
oc rsync POD:/remote/dir/ ./local/dir
2.6.1.123. oc run Link kopierenLink in die Zwischenablage kopiert!
Run a particular image on the cluster
Example usage
2.6.1.124. oc scale Link kopierenLink in die Zwischenablage kopiert!
Set a new size for a deployment, replica set, or replication controller
Example usage
2.6.1.125. oc secrets link Link kopierenLink in die Zwischenablage kopiert!
Link secrets to a service account
Example usage
Add an image pull secret to a service account to automatically use it for pulling pod images
# Add an image pull secret to a service account to automatically use it for pulling pod images
oc secrets link serviceaccount-name pull-secret --for=pull
# Add an image pull secret to a service account to automatically use it for both pulling and pushing build images
oc secrets link builder builder-image-secret --for=pull,mount
2.6.1.126. oc secrets unlink Link kopierenLink in die Zwischenablage kopiert!
Detach secrets from a service account
Example usage
Unlink a secret currently associated with a service account
# Unlink a secret currently associated with a service account
oc secrets unlink serviceaccount-name secret-name another-secret-name ...
2.6.1.127. oc set build-hook Link kopierenLink in die Zwischenablage kopiert!
Update a build hook on a build config
Example usage
2.6.1.128. oc set build-secret Link kopierenLink in die Zwischenablage kopiert!
Update a build secret on a build config
Example usage
2.6.1.129. oc set data Link kopierenLink in die Zwischenablage kopiert!
Update the data within a config map or secret
Example usage
2.6.1.130. oc set deployment-hook Link kopierenLink in die Zwischenablage kopiert!
Update a deployment hook on a deployment config
Example usage
2.6.1.131. oc set env Link kopierenLink in die Zwischenablage kopiert!
Update environment variables on a pod template
Example usage
2.6.1.132. oc set image Link kopierenLink in die Zwischenablage kopiert!
Update the image of a pod template
Example usage
2.6.1.133. oc set image-lookup Link kopierenLink in die Zwischenablage kopiert!
Change how images are resolved when deploying applications
Example usage
2.6.1.134. oc set probe Link kopierenLink in die Zwischenablage kopiert!
Update a probe on a pod template
Example usage
2.6.1.135. oc set resources Link kopierenLink in die Zwischenablage kopiert!
Update resource requests/limits on objects with pod templates
Example usage
2.6.1.136. oc set route-backends Link kopierenLink in die Zwischenablage kopiert!
Update the backends for a route
Example usage
2.6.1.137. oc set selector Link kopierenLink in die Zwischenablage kopiert!
Set the selector on a resource
Example usage
Set the labels and selector before creating a deployment/service pair.
# Set the labels and selector before creating a deployment/service pair.
oc create service clusterip my-svc --clusterip="None" -o yaml --dry-run | oc set selector --local -f - 'environment=qa' -o yaml | oc create -f -
oc create deployment my-dep -o yaml --dry-run | oc label --local -f - environment=qa -o yaml | oc create -f -
2.6.1.138. oc set serviceaccount Link kopierenLink in die Zwischenablage kopiert!
Update the service account of a resource
Example usage
Set deployment nginx-deployment's service account to serviceaccount1
# Set deployment nginx-deployment's service account to serviceaccount1
oc set serviceaccount deployment nginx-deployment serviceaccount1
# Print the result (in YAML format) of updated nginx deployment with service account from a local file, without hitting the API server
oc set sa -f nginx-deployment.yaml serviceaccount1 --local --dry-run -o yaml
2.6.1.139. oc set subject Link kopierenLink in die Zwischenablage kopiert!
Update the user, group, or service account in a role binding or cluster role binding
Example usage
2.6.1.140. oc set triggers Link kopierenLink in die Zwischenablage kopiert!
Update the triggers on one or more objects
Example usage
2.6.1.141. oc set volumes Link kopierenLink in die Zwischenablage kopiert!
Update volumes on a pod template
Example usage
2.6.1.142. oc start-build Link kopierenLink in die Zwischenablage kopiert!
Start a new build
Example usage
2.6.1.143. oc status Link kopierenLink in die Zwischenablage kopiert!
Show an overview of the current project
Example usage
2.6.1.144. oc tag Link kopierenLink in die Zwischenablage kopiert!
Tag existing images into image streams
Example usage
2.6.1.145. oc version Link kopierenLink in die Zwischenablage kopiert!
Print the client and server version information
Example usage
2.6.1.146. oc wait Link kopierenLink in die Zwischenablage kopiert!
Experimental: Wait for a specific condition on one or many resources
Example usage
2.6.1.147. oc whoami Link kopierenLink in die Zwischenablage kopiert!
Return information about the current session
Example usage
Display the currently authenticated user
# Display the currently authenticated user
oc whoami
2.7. OpenShift CLI administrator command reference Link kopierenLink in die Zwischenablage kopiert!
This reference provides descriptions and example commands for OpenShift CLI (oc
) administrator commands. You must have cluster-admin
or equivalent permissions to use these commands.
For developer commands, see the OpenShift CLI developer command reference.
Run oc adm -h
to list all administrator commands or run oc <command> --help
to get additional details for a specific command.
2.7.1. OpenShift CLI (oc) administrator commands Link kopierenLink in die Zwischenablage kopiert!
2.7.1.1. oc adm build-chain Link kopierenLink in die Zwischenablage kopiert!
Output the inputs and dependencies of your builds
Example usage
2.7.1.2. oc adm catalog mirror Link kopierenLink in die Zwischenablage kopiert!
Mirror an operator-registry catalog
Example usage
2.7.1.3. oc adm certificate approve Link kopierenLink in die Zwischenablage kopiert!
Approve a certificate signing request
Example usage
Approve CSR 'csr-sqgzp'
# Approve CSR 'csr-sqgzp'
oc adm certificate approve csr-sqgzp
2.7.1.4. oc adm certificate deny Link kopierenLink in die Zwischenablage kopiert!
Deny a certificate signing request
Example usage
Deny CSR 'csr-sqgzp'
# Deny CSR 'csr-sqgzp'
oc adm certificate deny csr-sqgzp
2.7.1.5. oc adm copy-to-node Link kopierenLink in die Zwischenablage kopiert!
Copy specified files to the node
Example usage
Copy a new bootstrap kubeconfig file to node-0
# Copy a new bootstrap kubeconfig file to node-0
oc adm copy-to-node --copy=new-bootstrap-kubeconfig=/etc/kubernetes/kubeconfig node/node-0
2.7.1.6. oc adm cordon Link kopierenLink in die Zwischenablage kopiert!
Mark node as unschedulable
Example usage
Mark node "foo" as unschedulable
# Mark node "foo" as unschedulable
oc adm cordon foo
2.7.1.7. oc adm create-bootstrap-project-template Link kopierenLink in die Zwischenablage kopiert!
Create a bootstrap project template
Example usage
Output a bootstrap project template in YAML format to stdout
# Output a bootstrap project template in YAML format to stdout
oc adm create-bootstrap-project-template -o yaml
2.7.1.8. oc adm create-error-template Link kopierenLink in die Zwischenablage kopiert!
Create an error page template
Example usage
Output a template for the error page to stdout
# Output a template for the error page to stdout
oc adm create-error-template
2.7.1.9. oc adm create-login-template Link kopierenLink in die Zwischenablage kopiert!
Create a login template
Example usage
Output a template for the login page to stdout
# Output a template for the login page to stdout
oc adm create-login-template
2.7.1.10. oc adm create-provider-selection-template Link kopierenLink in die Zwischenablage kopiert!
Create a provider selection template
Example usage
Output a template for the provider selection page to stdout
# Output a template for the provider selection page to stdout
oc adm create-provider-selection-template
2.7.1.11. oc adm drain Link kopierenLink in die Zwischenablage kopiert!
Drain node in preparation for maintenance
Example usage
Drain node "foo", even if there are pods not managed by a replication controller, replica set, job, daemon set, or stateful set on it
# Drain node "foo", even if there are pods not managed by a replication controller, replica set, job, daemon set, or stateful set on it
oc adm drain foo --force
# As above, but abort if there are pods not managed by a replication controller, replica set, job, daemon set, or stateful set, and use a grace period of 15 minutes
oc adm drain foo --grace-period=900
2.7.1.12. oc adm groups add-users Link kopierenLink in die Zwischenablage kopiert!
Add users to a group
Example usage
Add user1 and user2 to my-group
# Add user1 and user2 to my-group
oc adm groups add-users my-group user1 user2
2.7.1.13. oc adm groups new Link kopierenLink in die Zwischenablage kopiert!
Create a new group
Example usage
2.7.1.14. oc adm groups prune Link kopierenLink in die Zwischenablage kopiert!
Remove old OpenShift groups referencing missing records from an external provider
Example usage
2.7.1.15. oc adm groups remove-users Link kopierenLink in die Zwischenablage kopiert!
Remove users from a group
Example usage
Remove user1 and user2 from my-group
# Remove user1 and user2 from my-group
oc adm groups remove-users my-group user1 user2
2.7.1.16. oc adm groups sync Link kopierenLink in die Zwischenablage kopiert!
Sync OpenShift groups with records from an external provider
Example usage
2.7.1.17. oc adm inspect Link kopierenLink in die Zwischenablage kopiert!
Collect debugging data for a given resource
Example usage
2.7.1.18. oc adm migrate icsp Link kopierenLink in die Zwischenablage kopiert!
Update imagecontentsourcepolicy file(s) to imagedigestmirrorset file(s)
Example usage
Update the imagecontentsourcepolicy.yaml file to a new imagedigestmirrorset file under the mydir directory
# Update the imagecontentsourcepolicy.yaml file to a new imagedigestmirrorset file under the mydir directory
oc adm migrate icsp imagecontentsourcepolicy.yaml --dest-dir mydir
2.7.1.19. oc adm migrate template-instances Link kopierenLink in die Zwischenablage kopiert!
Update template instances to point to the latest group-version-kinds
Example usage
Perform a dry-run of updating all objects
# Perform a dry-run of updating all objects
oc adm migrate template-instances
# To actually perform the update, the confirm flag must be appended
oc adm migrate template-instances --confirm
2.7.1.20. oc adm must-gather Link kopierenLink in die Zwischenablage kopiert!
Launch a new instance of a pod for gathering debug information
Example usage
2.7.1.21. oc adm new-project Link kopierenLink in die Zwischenablage kopiert!
Create a new project
Example usage
Create a new project using a node selector
# Create a new project using a node selector
oc adm new-project myproject --node-selector='type=user-node,region=east'
2.7.1.22. oc adm node-image create Link kopierenLink in die Zwischenablage kopiert!
Create an ISO image for booting the nodes to be added to the target cluster
Example usage
2.7.1.23. oc adm node-image monitor Link kopierenLink in die Zwischenablage kopiert!
Monitor new nodes being added to an OpenShift cluster
Example usage
2.7.1.24. oc adm node-logs Link kopierenLink in die Zwischenablage kopiert!
Display and filter node logs
Example usage
2.7.1.25. oc adm ocp-certificates monitor-certificates Link kopierenLink in die Zwischenablage kopiert!
Watch platform certificates
Example usage
Watch platform certificates
# Watch platform certificates
oc adm ocp-certificates monitor-certificates
2.7.1.26. oc adm ocp-certificates regenerate-leaf Link kopierenLink in die Zwischenablage kopiert!
Regenerate client and serving certificates of an OpenShift cluster
Example usage
Regenerate a leaf certificate contained in a particular secret
# Regenerate a leaf certificate contained in a particular secret
oc adm ocp-certificates regenerate-leaf -n openshift-config-managed secret/kube-controller-manager-client-cert-key
2.7.1.27. oc adm ocp-certificates regenerate-machine-config-server-serving-cert Link kopierenLink in die Zwischenablage kopiert!
Regenerate the machine config operator certificates in an OpenShift cluster
Example usage
Regenerate the MCO certs without modifying user-data secrets
# Regenerate the MCO certs without modifying user-data secrets
oc adm ocp-certificates regenerate-machine-config-server-serving-cert --update-ignition=false
# Update the user-data secrets to use new MCS certs
oc adm ocp-certificates update-ignition-ca-bundle-for-machine-config-server
2.7.1.28. oc adm ocp-certificates regenerate-top-level Link kopierenLink in die Zwischenablage kopiert!
Regenerate the top level certificates in an OpenShift cluster
Example usage
Regenerate the signing certificate contained in a particular secret
# Regenerate the signing certificate contained in a particular secret
oc adm ocp-certificates regenerate-top-level -n openshift-kube-apiserver-operator secret/loadbalancer-serving-signer-key
2.7.1.29. oc adm ocp-certificates remove-old-trust Link kopierenLink in die Zwischenablage kopiert!
Remove old CAs from ConfigMaps representing platform trust bundles in an OpenShift cluster
Example usage
Remove a trust bundled contained in a particular config map
# Remove a trust bundled contained in a particular config map
oc adm ocp-certificates remove-old-trust -n openshift-config-managed configmaps/kube-apiserver-aggregator-client-ca --created-before 2023-06-05T14:44:06Z
# Remove only CA certificates created before a certain date from all trust bundles
oc adm ocp-certificates remove-old-trust configmaps -A --all --created-before 2023-06-05T14:44:06Z
2.7.1.30. oc adm ocp-certificates update-ignition-ca-bundle-for-machine-config-server Link kopierenLink in die Zwischenablage kopiert!
Update user-data secrets in an OpenShift cluster to use updated MCO certfs
Example usage
Regenerate the MCO certs without modifying user-data secrets
# Regenerate the MCO certs without modifying user-data secrets
oc adm ocp-certificates regenerate-machine-config-server-serving-cert --update-ignition=false
# Update the user-data secrets to use new MCS certs
oc adm ocp-certificates update-ignition-ca-bundle-for-machine-config-server
2.7.1.31. oc adm policy add-cluster-role-to-group Link kopierenLink in die Zwischenablage kopiert!
Add a role to groups for all projects in the cluster
Example usage
Add the 'cluster-admin' cluster role to the 'cluster-admins' group
# Add the 'cluster-admin' cluster role to the 'cluster-admins' group
oc adm policy add-cluster-role-to-group cluster-admin cluster-admins
2.7.1.32. oc adm policy add-cluster-role-to-user Link kopierenLink in die Zwischenablage kopiert!
Add a role to users for all projects in the cluster
Example usage
Add the 'system:build-strategy-docker' cluster role to the 'devuser' user
# Add the 'system:build-strategy-docker' cluster role to the 'devuser' user
oc adm policy add-cluster-role-to-user system:build-strategy-docker devuser
2.7.1.33. oc adm policy add-role-to-user Link kopierenLink in die Zwischenablage kopiert!
Add a role to users or service accounts for the current project
Example usage
Add the 'view' role to user1 for the current project
# Add the 'view' role to user1 for the current project
oc adm policy add-role-to-user view user1
# Add the 'edit' role to serviceaccount1 for the current project
oc adm policy add-role-to-user edit -z serviceaccount1
2.7.1.34. oc adm policy add-scc-to-group Link kopierenLink in die Zwischenablage kopiert!
Add a security context constraint to groups
Example usage
Add the 'restricted' security context constraint to group1 and group2
# Add the 'restricted' security context constraint to group1 and group2
oc adm policy add-scc-to-group restricted group1 group2
2.7.1.35. oc adm policy add-scc-to-user Link kopierenLink in die Zwischenablage kopiert!
Add a security context constraint to users or a service account
Example usage
Add the 'restricted' security context constraint to user1 and user2
# Add the 'restricted' security context constraint to user1 and user2
oc adm policy add-scc-to-user restricted user1 user2
# Add the 'privileged' security context constraint to serviceaccount1 in the current namespace
oc adm policy add-scc-to-user privileged -z serviceaccount1
2.7.1.36. oc adm policy remove-cluster-role-from-group Link kopierenLink in die Zwischenablage kopiert!
Remove a role from groups for all projects in the cluster
Example usage
Remove the 'cluster-admin' cluster role from the 'cluster-admins' group
# Remove the 'cluster-admin' cluster role from the 'cluster-admins' group
oc adm policy remove-cluster-role-from-group cluster-admin cluster-admins
2.7.1.37. oc adm policy remove-cluster-role-from-user Link kopierenLink in die Zwischenablage kopiert!
Remove a role from users for all projects in the cluster
Example usage
Remove the 'system:build-strategy-docker' cluster role from the 'devuser' user
# Remove the 'system:build-strategy-docker' cluster role from the 'devuser' user
oc adm policy remove-cluster-role-from-user system:build-strategy-docker devuser
2.7.1.38. oc adm policy scc-review Link kopierenLink in die Zwischenablage kopiert!
Check which service account can create a pod
Example usage
2.7.1.39. oc adm policy scc-subject-review Link kopierenLink in die Zwischenablage kopiert!
Check whether a user or a service account can create a pod
Example usage
2.7.1.40. oc adm prune builds Link kopierenLink in die Zwischenablage kopiert!
Remove old completed and failed builds
Example usage
2.7.1.41. oc adm prune deployments Link kopierenLink in die Zwischenablage kopiert!
Remove old completed and failed deployment configs
Example usage
Dry run deleting all but the last complete deployment for every deployment config
# Dry run deleting all but the last complete deployment for every deployment config
oc adm prune deployments --keep-complete=1
# To actually perform the prune operation, the confirm flag must be appended
oc adm prune deployments --keep-complete=1 --confirm
2.7.1.42. oc adm prune groups Link kopierenLink in die Zwischenablage kopiert!
Remove old OpenShift groups referencing missing records from an external provider
Example usage
2.7.1.43. oc adm prune images Link kopierenLink in die Zwischenablage kopiert!
Remove unreferenced images
Example usage
2.7.1.44. oc adm prune renderedmachineconfigs Link kopierenLink in die Zwischenablage kopiert!
Prunes rendered MachineConfigs in an OpenShift cluster
Example usage
2.7.1.45. oc adm prune renderedmachineconfigs list Link kopierenLink in die Zwischenablage kopiert!
Lists rendered MachineConfigs in an OpenShift cluster
Example usage
List all rendered MachineConfigs for the worker MachineConfigPool in the cluster
# List all rendered MachineConfigs for the worker MachineConfigPool in the cluster
oc adm prune renderedmachineconfigs list --pool-name=worker
# List all rendered MachineConfigs in use by the cluster's MachineConfigPools
oc adm prune renderedmachineconfigs list --in-use
2.7.1.46. oc adm reboot-machine-config-pool Link kopierenLink in die Zwischenablage kopiert!
Initiate reboot of the specified MachineConfigPool
Example usage
2.7.1.47. oc adm release extract Link kopierenLink in die Zwischenablage kopiert!
Extract the contents of an update payload to disk
Example usage
2.7.1.48. oc adm release info Link kopierenLink in die Zwischenablage kopiert!
Display information about a release
Example usage
2.7.1.49. oc adm release mirror Link kopierenLink in die Zwischenablage kopiert!
Mirror a release to a different image registry location
Example usage
2.7.1.50. oc adm release new Link kopierenLink in die Zwischenablage kopiert!
Create a new OpenShift release
Example usage
2.7.1.51. oc adm restart-kubelet Link kopierenLink in die Zwischenablage kopiert!
Restart kubelet on the specified nodes
Example usage
2.7.1.52. oc adm taint Link kopierenLink in die Zwischenablage kopiert!
Update the taints on one or more nodes
Example usage
2.7.1.53. oc adm top images Link kopierenLink in die Zwischenablage kopiert!
Show usage statistics for images
Example usage
Show usage statistics for images
# Show usage statistics for images
oc adm top images
2.7.1.54. oc adm top imagestreams Link kopierenLink in die Zwischenablage kopiert!
Show usage statistics for image streams
Example usage
Show usage statistics for image streams
# Show usage statistics for image streams
oc adm top imagestreams
2.7.1.55. oc adm top node Link kopierenLink in die Zwischenablage kopiert!
Display resource (CPU/memory) usage of nodes
Example usage
Show metrics for all nodes
# Show metrics for all nodes
oc adm top node
# Show metrics for a given node
oc adm top node NODE_NAME
2.7.1.56. oc adm top persistentvolumeclaims Link kopierenLink in die Zwischenablage kopiert!
Experimental: Show usage statistics for bound persistentvolumeclaims
Example usage
2.7.1.57. oc adm top pod Link kopierenLink in die Zwischenablage kopiert!
Display resource (CPU/memory) usage of pods
Example usage
2.7.1.58. oc adm uncordon Link kopierenLink in die Zwischenablage kopiert!
Mark node as schedulable
Example usage
Mark node "foo" as schedulable
# Mark node "foo" as schedulable
oc adm uncordon foo
2.7.1.59. oc adm upgrade Link kopierenLink in die Zwischenablage kopiert!
Upgrade a cluster or adjust the upgrade channel
Example usage
View the update status and available cluster updates
# View the update status and available cluster updates
oc adm upgrade
# Update to the latest version
oc adm upgrade --to-latest=true
2.7.1.60. oc adm verify-image-signature Link kopierenLink in die Zwischenablage kopiert!
Verify the image identity contained in the image signature
Example usage
2.7.1.61. oc adm wait-for-node-reboot Link kopierenLink in die Zwischenablage kopiert!
Wait for nodes to reboot after running oc adm reboot-machine-config-pool
Example usage
2.7.1.62. oc adm wait-for-stable-cluster Link kopierenLink in die Zwischenablage kopiert!
Wait for the platform operators to become stable
Example usage
Wait for all cluster operators to become stable
# Wait for all cluster operators to become stable
oc adm wait-for-stable-cluster
# Consider operators to be stable if they report as such for 5 minutes straight
oc adm wait-for-stable-cluster --minimum-stable-period 5m