OnCallReady

Chapter 30 OpenShift

Only the deltas from vanilla Kubernetes: the oc CLI and logins, Projects, SecurityContextConstraints and why images that run as root fail, Routes and the router, Builds, ImageStreams and the internal registry, DeploymentConfig vs Deployment, Operators and OLM, cluster upgrades, oc debug node and must-gather.

In plain words

Imagine two cars built on the same engine. One is a kit car: you pick the seats, the radio, the alarm, and you bolt everything on yourself. The other comes from a dealer: same engine, but it arrives with seatbelts that won't unlock while driving, an alarm already fitted, and the dealer services it for you, including the engine, on a schedule. Driving feels the same; the rules are stricter.

Kubernetes is the engine; OpenShift is Red Hat's dealer car. Same pods, Deployments and Services, same YAML, but with oc, Projects, SecurityContextConstraints that run every pod as a random non-root UID, Routes served by a built-in router (HAProxy, a proxy program), builds and ImageStreams, Operators (programs that run one product for you) installed through OLM (the Operator Lifecycle Manager), and a Cluster Version Operator that upgrades the whole cluster, the nodes' operating system included.

Why it matters on call

Many banks, including the kind you are targeting, run their container platform on OpenShift, often on-prem, and Romanian job ads for platform roles ask for it by name. The Kubernetes you learned transfers, but the defaults break things in ways that look mysterious if you only know AKS: a Helm chart that worked everywhere gets no pods, nginx crash-loops with Permission denied, a Route returns "Application is not available".

This chapter turns those into two-minute diagnoses: read the SCC rejection, fix the image for arbitrary UIDs instead of granting anyuid, check a Route's targetPort, approve a pending InstallPlan, run oc debug node and must-gather. It also gives you the translation table from kubectl habits to oc, so your first week on an OpenShift team is productive. "Why does my pod work on AKS but not on OpenShift?" is the classic interview question, and you will answer it precisely.

Lessons

  1. What OpenShift adds to Kubernetes
  2. The oc CLI and logging in
  3. Projects vs namespaces
  4. SecurityContextConstraints I: what restricted-v2 does to your pod
  5. SecurityContextConstraints II: selection, rejections, and fixing images
  6. Routes and the router
  7. Route TLS: edge, passthrough, reencrypt
  8. Builds, Source-to-Image and ImageStreams
  9. DeploymentConfig vs Deployment
  10. Operators, OperatorHub and OLM
  11. Cluster operations: upgrades, cluster operators, node debugging, must-gather
  12. A working day on OpenShift: the translation table

22 hands-on labs (missions, incidents and drills) run in the terminal: Open this chapter in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.

Questions people ask

Is OpenShift just Kubernetes?

It is a certified Kubernetes distribution: the same API server, objects and kubectl behaviour, so standard manifests and Helm charts work. On top it adds opinions and APIs: Projects, SecurityContextConstraints, Routes and a built-in router, Builds and ImageStreams, an integrated registry, its own OAuth login server, OLM for operators, nodes running RHCOS (Red Hat's immutable OS) and cluster-managed upgrades. The differences are mostly in defaults, security and day-2 operations, not in the core API.

What is the difference between OCP, OKD, ARO and ROSA?

OCP, OpenShift Container Platform, is the supported product you install on bare metal, vSphere or clouds. OKD is the community distribution OCP is built from, with no support. ARO, Azure Red Hat OpenShift, is jointly managed by Microsoft and Red Hat on Azure; ROSA is the equivalent on AWS. OpenShift Dedicated is Red Hat-managed on either cloud. The Developer Sandbox is a free project on a shared cluster for learning.

Can I use kubectl on OpenShift?

Yes. oc contains kubectl's commands with the same flags, and oc login writes a standard kubeconfig that kubectl reads. Scripts and tools written for kubectl keep working. oc adds the OpenShift-specific commands: login, new-project, project, new-app, expose for Routes, rsh, start-build, debug node, and the oc adm administration commands.

Why do so many Docker Hub images fail on OpenShift?

Because the default SCC, restricted-v2, runs every container as a random non-root UID from the project's range, with group 0, all capabilities dropped and no privilege escalation. Images that assume root, for example writing under /var/cache, running chown at startup or binding port 80, fail with Permission denied. The fix is a portable image: non-root, listening above 1024, writable directories owned by group 0.

Which OpenShift version maps to which Kubernetes version?

Each OpenShift minor pins one Kubernetes minor: OpenShift 4.21 is Kubernetes 1.34, with CRI-O as the container runtime. Minors ship roughly every four months, versions are 4.<minor>.<z>, and even minors such as 4.18, 4.20 and 4.22 are Extended Update Support (EUS) releases, supported for longer, that large companies standardise on. oc version shows the client, server and Kubernetes versions.