Create a namespace in your Red Hat OpenShift Container Platform (RHOCP) environment to isolate the service pods for your Red Hat OpenStack Services on OpenShift (RHOSO) deployment.
Before you begin
- You are logged on to a workstation that has access to the RHOCP cluster, as a user with
cluster-admin privileges.
Procedure
-
Create the
openstack project for the deployed RHOSO environment:
$ oc new-project openstack
-
Ensure the
openstack namespace is labeled to enable privileged pod creation by the OpenStack Operators:
$ oc get namespace openstack -ojsonpath='{.metadata.labels}' | jq
{
"kubernetes.io/metadata.name": "openstack",
"pod-security.kubernetes.io/enforce": "privileged",
"security.openshift.io/scc.podSecurityLabelSync": "false"
}
If the security context constraint (SCC) is not "privileged", use the following commands to change it:
$ oc label ns openstack security.openshift.io/scc.podSecurityLabelSync=false --overwrite
$ oc label ns openstack pod-security.kubernetes.io/enforce=privileged --overwrite
-
Optional: To remove the need to specify the namespace when executing commands on the
openstack namespace, set the default namespace to openstack: