oc - OpenShift command-line client: kubectl plus the OpenShift APIs
oc [command] [TYPE] [NAME] [flags]
Options you will use
login [SERVER] -u USER | --token=sha256~...- log in through the OAuth server; writes a context <project>/<api-host:port>/<user> to ~/.kube/config
whoami [-t|--show-server|--show-context|--show-console]- the user (and token, API URL, context, console URL) of the current session
project [NAME] / projects / new-project NAME- show or switch the current project, list the ones you can see, request a new one
new-app BUILDER~REPO | REPO | IMAGE [--name=N]- create ImageStream + BuildConfig (from source) or ImageStream (from an image), a Deployment and a Service
new-build REPO [--strategy=docker]- only the ImageStream and the BuildConfig
start-build BC [--follow] [--wait] / cancel-build BUILD- run or stop a build; oc logs -f bc/NAME follows the latest one
expose svc/NAME [--hostname=H] [--port=P] [--path=/p]- create a plain HTTP Route. --port is the ENDPOINT (pod) port or the service port NAME
create route edge|passthrough|reencrypt NAME --service=S [--insecure-policy=Redirect|Allow|None] [--cert --key --ca-cert] [--dest-ca-cert]- a TLS route
tag SRC DEST [--alias] / tag -d IS:TAG- point an image stream tag at an image or at another tag (moves image triggers)
import-image IS:TAG --from=REF --confirm- import an external image into an image stream tag
set triggers deploy/NAME --from-image=IS:TAG -c CONTAINER- roll the Deployment whenever the tag moves
rsh POD- a shell in the pod (oc exec -it POD -- /bin/sh)
debug node/NODE [-- chroot /host CMD]- a privileged pod on the node with / at /host: chroot /host, then crictl, journalctl, systemctl
adm policy add-scc-to-user SCC -z SA [-n NS] / who-can use scc NAME / scc-subject-review -f FILE- SCC access and "which SCC would admit this pod"
adm upgrade [channel C | --to=V | --to-latest]- cluster version, update channel and recommended updates
adm must-gather [--dest-dir=DIR] / adm inspect ns/NAME- collect the support bundle
status [--suggest]- a summary of the project: routes -> services -> deployments -> builds, and what is broken
Examples
$ oc login https://api.ocp.lab:6443 -u developerlog in (prompts for the password)
$ oc new-app nodejs~https://github.com/sclorg/nodejs-ex.gitSource-to-Image build + deployment
$ oc create route edge web --service=web --insecure-policy=RedirectTLS at the router, http redirected
$ oc get pod POD -o jsonpath='{.metadata.annotations.openshift\.io/scc}{"\n"}'which SCC admitted a pod
$ oc debug node/worker-1 -- chroot /host journalctl -u kubelet -n 20kubelet journal without SSH
Gotchas
- Everything kubectl does, oc does with the same flags: oc get / describe / logs / exec / apply are the kubectl code.
- oc status --suggest will tell you to run oc adm policy add-scc-to-user anyuid for a crash-looping image. Fix the image instead.
Taught in
- 30.2 The oc CLI and logging in
- 30.4 Projects vs namespaces
- 30.9 SecurityContextConstraints II: selection, rejections, and fixing images
- 30.13 Routes and the router
- 30.18 Builds, Source-to-Image and ImageStreams
- 30.26 Cluster operations: upgrades, cluster operators, node debugging, must-gather
- 30.29 A working day on OpenShift: the translation table
Try oc in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.