OnCallReady

Lesson 30.29 · OpenShift · 13 min read

A working day on OpenShift: the translation table

In plain words

Imagine moving to a country where they speak a language close to yours. Most words are the same, but a few everyday ones differ: "bin" is "basket", "flat" is "apartment". Carry a small card in your pocket with just those differences, and within a week you stop reaching for it.

This lesson is that card for moving from kubectl on AKS or the kubeadm lab to OpenShift. oc login instead of az aks get-credentials, oc new-project instead of kubectl create ns, oc expose svc/x instead of Ingress YAML, oc rsh, oc debug node/x then chroot /host, oc status for an overview, OperatorHub instead of helm install for add-ons. Everything that is plain kubectl works unchanged.

Your kubectl muscle memory, translated

Day one on a work OpenShift cluster: someone asks you to "deploy the new image, give Ana edit rights in the project and check why the route is down". You know how to do each of those in Kubernetes. This lesson is the cheat sheet that turns each habit into its OpenShift form, plus the few commands that only exist here.

What you need to know already: kubectl and kubeconfig (15.1, 15.3), Deployments, Services and Ingress (15.16, 16.1, 16.19), RBAC role bindings (17.30), Helm (25.19); from this chapter: oc login and projects (30.2, 30.4), SCCs (30.7, 30.9), Routes (30.13, 30.15), builds and ImageStreams (30.18), operators (30.23) and cluster operations (30.26).

Most of what you type is still kubectl - through oc, which contains all of kubectl. The table below is the part that changes. Left column: the job; middle: how you did it in chapters 15-19 and 22-24; right: the OpenShift way.

taskon the kubeadm lab / AKSon OpenShift
get credentialsaz aks get-credentials, copy admin.confoc login https://api.<cluster>:6443 (or Copy login command in the console)
who am Ikubectl auth whoamioc whoami; -t token, --show-context, --show-console
new namespacekubectl create ns x (cluster rights)oc new-project x (self-service, you become admin)
switch namespacekubectl config set-context --current --namespace=xoc project x
list my namespaceskubectl get nsoc projects / oc get projects (only yours)
deploy an imagekubectl create deploymentsame, or oc new-app --image=... (adds ImageStream + Service)
deploy from Gitbuild in CI, push, applyoc new-app builder~repo (BuildConfig + ImageStream + Deployment + Service)
expose over HTTPIngress YAML + ingress classoc expose svc/x (Route), `oc create route edgepassthroughreencrypt`
TLS for a Service inside the clustercert-managerannotate the Service for the service CA
shellkubectl exec -it pod -- shoc rsh pod (or deploy/x)
debug a crash-looping podkubectl debug --copy-tooc debug deploy/x (a copy with sh as the command; not simulated in the lab)
node shellkubectl debug node/x -it --image=busybox, SSHoc debug node/x, then chroot /host
grant a role in a namespacekubectl create rolebinding ...oc policy add-role-to-user edit alice
why is my pod not allowedPSA warningsSCC: `oc get pod -o yamlgrep openshift.io/scc, oc adm policy scc-subject-review`
what is running herekubectl get alloc status (+ oc get all)
install an add-onhelm installan Operator from OperatorHub (Subscription), or Helm
upgrade the clusterkubeadm, node by nodeoc adm upgrade --to=...
support bundlekubectl cluster-info dumpoc adm must-gather

Everything in the right column that is not an OpenShift API (the kubectl verbs, jsonpath, --dry-run=client -o yaml, auth can-i, rollout, top) works exactly as in chapters 15-19. A few right-column commands are new here:

oc status

The fastest overview of a project. Where kubectl get all prints flat lists, oc status draws the chain Route -> Service -> Deployment -> BuildConfig, and lists what is broken:

$ oc status
In project shop on server https://api.ocp.lab:6443

https://web-shop.apps.ocp.lab (redirects) to pod port http (svc/web)
  deployment/web deploys istag/web:latest <-
    bc/web source builds https://github.com/sclorg/nodejs-ex.git on openshift/nodejs:22-ubi9
  deployment #3 running for 2m - 2 pods

svc/legacy - 10.96.141.22:80
  deployment/legacy deploys docker.io/library/nginx:1.27
  deployment #1 running for 12m - 0/2 pods growing to 2

1 error, 0 warnings, 1 info identified, use 'oc status --suggest' to see details.

Reading it: line 1 is the project and API server. Then one block per app: the Route URL ((redirects) = edge TLS with HTTP redirected to HTTPS, 30.15) pointing at svc/web; the Deployment it feeds, which deploys the ImageStreamTag web:latest (<- = an image change trigger, 30.18); the BuildConfig that builds that tag from a repository on a Node.js builder image; and "deployment #3 ... 2 pods" (third rollout, healthy). legacy has no Route and is stuck at 0/2 pods. The last line counts the problems.

--suggest expands the errors. For a crash-looping image it prints the famous advice to grant anyuid - read it as "this image needs root" and fix the image (30.9).

oc get all is not all

$ oc get all

It looks like it lists everything in the project. It does not: all is a category (a group name some resource types sign up to): pods, services, deployments, replicasets, statefulsets, daemonsets, jobs, cronjobs, and on OpenShift also routes, buildconfigs, builds, imagestreams and deploymentconfigs. It never includes ConfigMaps, Secrets, PVCs, RoleBindings, NetworkPolicies, ServiceAccounts or operator CRs. When you clean up or copy a project, list those explicitly: oc get cm,secret,pvc,rolebinding,networkpolicy,sa.

Templates

Before Helm (25.19) and operators, OpenShift packaged apps as Templates (template.openshift.io): a list of objects with ${PARAMETER} placeholders.

The three commands below: list the templates the cluster ships (in the openshift namespace); render a template file, filling two parameters with -p NAME=value, and pipe the YAML into oc apply -f - (- = read stdin, 1.7); or let oc new-app do both in one step from a template already on the cluster.

$ oc get templates -n openshift | head -3
$ oc process -f postgres-template.yaml -p DATABASE_NAME=orders -p VOLUME_CAPACITY=5Gi | oc apply -f -
$ oc new-app --template=postgresql-persistent -p POSTGRESQL_DATABASE=orders

oc process renders a template to plain YAML (a poor man's helm template). You will find them in older projects and in the openshift namespace; new work uses Helm charts or operators. (simulator) Templates and oc process are not in the lab.

The console

Every cluster has a web console (oc whoami --show-console). Worth knowing its Developer perspective (topology view of your project, build logs, a pod terminal) and Administrator perspective (OperatorHub, cluster settings and upgrades, the Observe > Alerting and Metrics pages backed by the built-in Prometheus). Anything you click creates the same objects you would write as YAML - the YAML tab on every page shows them, which is a good way to learn the fields. Treat the console as a viewer and keep changes in Git.

Monitoring you get for free

openshift-monitoring runs Prometheus (27.2), Alertmanager (28.7), the node exporter and Thanos Querier (a front end that queries several Prometheus servers as one) for the platform. User workload monitoring (enabled by an admin in the cluster-monitoring-config ConfigMap) lets your ServiceMonitors (27.4) in your projects be scraped by a second Prometheus in openshift-user-workload-monitoring, and the console's Observe pages query both. Chapters 27-29's PromQL works there unchanged.

What to practise on a real cluster

The lab covers the behaviour; a real cluster adds the scale and the console. On the free Developer Sandbox (a project on a shared cluster - no admin rights) you can do:

  1. oc login with the console's Copy login command, oc whoami -t, oc projects.
  2. Deploy nginx:1.27 and watch it crash-loop; read the logs; redeploy nginxinc/nginx-unprivileged on 8080. See openshift.io/scc: restricted-v2 and your UID.
  3. oc new-app nodejs~https://github.com/sclorg/nodejs-ex.git, follow the build, expose it, curl it, oc start-build again and watch the trigger.
  4. Routes: edge with Redirect, a path route, a Route with a 503 you caused on purpose.
  5. Read-only: oc get csv in your namespace (operators installed cluster-wide show up as copied CSVs), oc get clusterversion (often allowed read-only).

At work, ask for a project on the non-production cluster and repeat 2-4 there; then read the platform team's project template (oc get project <yours> -o yaml, oc get quota,limits)

the local rules this chapter's defaults get tightened with.

What you can now do

Why it helps

Your first week on an OpenShift team will be spent translating habits, and this table shortens that to a day. oc status gives you the Route to Service to Deployment to BuildConfig chain of an unfamiliar project in one command, with errors flagged. Knowing that oc get all skips ConfigMaps, Secrets, PVCs, RoleBindings and NetworkPolicies prevents the classic incomplete project copy or cleanup.

The console, user workload monitoring and templates are things you will be asked about by developers: yes, your ServiceMonitors can be scraped once an admin enables user workload monitoring, and your PromQL from the previous chapters works there. The practice list for the Developer Sandbox and a non-production project at work gives you hands-on evidence to mention in interviews, which matters when your current job has no OpenShift exposure.

Commands in this lesson

oc

FAQ

What does oc status show that oc get all does not?

oc status draws the relationships in a project: which Route exposes which Service, which Deployment backs it, which ImageStream tag it deploys and which BuildConfig builds that, plus rollout state and pod counts. It also lists errors and warnings, such as crash-looping pods, with --suggest for details. oc get all just lists objects of certain kinds without showing how they connect or what is wrong.

Why doesn't oc get all show my ConfigMaps and Secrets?

all is a category of resource types, not literally everything. It covers pods, services, deployments, replicasets, statefulsets, daemonsets, jobs, cronjobs, and on OpenShift also routes, builds, buildconfigs, imagestreams and deploymentconfigs. It excludes ConfigMaps, Secrets, PVCs, RoleBindings, NetworkPolicies, ServiceAccounts and operator custom resources. List those explicitly, for example oc get cm,secret,pvc,rolebinding,networkpolicy,sa.

Can I use my own Prometheus rules and ServiceMonitors on OpenShift?

Yes, once a cluster admin enables user workload monitoring in the cluster-monitoring-config ConfigMap in openshift-monitoring. Then a second Prometheus in openshift-user-workload-monitoring scrapes ServiceMonitors and PodMonitors in your projects and evaluates your PrometheusRules, and the console's Observe pages query both platform and user metrics. The platform monitoring stack itself is managed; do not modify it.

What are OpenShift Templates and should I use them?

Templates (template.openshift.io) are OpenShift's older packaging format: a list of objects with ${PARAMETER} placeholders, rendered with oc process or instantiated with oc new-app --template. They predate Helm and operators. You will find them in older projects and the openshift namespace. New work should use Helm charts, kustomize or operators, which are portable and better supported by GitOps tooling.

Should I make changes in the web console?

Use the console to view and learn: the Developer perspective's topology, build logs and pod terminals, the Administrator perspective's OperatorHub, upgrade status and Observe pages, and the YAML tab that shows the exact objects behind each page. For changes to anything that matters, prefer manifests in git applied by a pipeline or Argo CD, so they are reviewed, reproducible and not reverted as drift.

In an interview Mid

What are the most useful oc commands for day-to-day work on OpenShift, coming from kubectl?

oc contains all of kubectl - get, describe, logs, apply, rollout, auth can-i work unchanged. What changes:

And a trap: oc get all is a category - it leaves out ConfigMaps, Secrets, PVCs, RoleBindings, NetworkPolicies and ServiceAccounts. List those explicitly.

Also asked: You join a team that runs everything on OpenShift, coming from AKS. What do you check in your first week? · What does oc status show that kubectl get all does not? · What are OpenShift Templates and what replaced them?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.