OnCallReady

Commands

oc - OpenShift command-line client: kubectl plus the OpenShift APIs

oc [command] [TYPE] [NAME] [flags]

Options you will use

login [SERVER] -u USER | --token=sha256~...
log in through the OAuth server; writes a context <project>/<api-host:port>/<user> to ~/.kube/config
whoami [-t|--show-server|--show-context|--show-console]
the user (and token, API URL, context, console URL) of the current session
project [NAME] / projects / new-project NAME
show or switch the current project, list the ones you can see, request a new one
new-app BUILDER~REPO | REPO | IMAGE [--name=N]
create ImageStream + BuildConfig (from source) or ImageStream (from an image), a Deployment and a Service
new-build REPO [--strategy=docker]
only the ImageStream and the BuildConfig
start-build BC [--follow] [--wait] / cancel-build BUILD
run or stop a build; oc logs -f bc/NAME follows the latest one
expose svc/NAME [--hostname=H] [--port=P] [--path=/p]
create a plain HTTP Route. --port is the ENDPOINT (pod) port or the service port NAME
create route edge|passthrough|reencrypt NAME --service=S [--insecure-policy=Redirect|Allow|None] [--cert --key --ca-cert] [--dest-ca-cert]
a TLS route
tag SRC DEST [--alias] / tag -d IS:TAG
point an image stream tag at an image or at another tag (moves image triggers)
import-image IS:TAG --from=REF --confirm
import an external image into an image stream tag
set triggers deploy/NAME --from-image=IS:TAG -c CONTAINER
roll the Deployment whenever the tag moves
rsh POD
a shell in the pod (oc exec -it POD -- /bin/sh)
debug node/NODE [-- chroot /host CMD]
a privileged pod on the node with / at /host: chroot /host, then crictl, journalctl, systemctl
adm policy add-scc-to-user SCC -z SA [-n NS] / who-can use scc NAME / scc-subject-review -f FILE
SCC access and "which SCC would admit this pod"
adm upgrade [channel C | --to=V | --to-latest]
cluster version, update channel and recommended updates
adm must-gather [--dest-dir=DIR] / adm inspect ns/NAME
collect the support bundle
status [--suggest]
a summary of the project: routes -> services -> deployments -> builds, and what is broken

Examples

$ oc login https://api.ocp.lab:6443 -u developer

log in (prompts for the password)

$ oc new-app nodejs~https://github.com/sclorg/nodejs-ex.git

Source-to-Image build + deployment

$ oc create route edge web --service=web --insecure-policy=Redirect

TLS at the router, http redirected

$ oc get pod POD -o jsonpath='{.metadata.annotations.openshift\.io/scc}{"\n"}'

which SCC admitted a pod

$ oc debug node/worker-1 -- chroot /host journalctl -u kubelet -n 20

kubelet journal without SSH

Gotchas

Taught in

Try oc in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.