Red Hat OpenShift: Difference between revisions
From wiki.vacula.xyz
(→Pods) |
|||
| Line 74: | Line 74: | ||
|Requires the rsync binary on both host and pod container | |Requires the rsync binary on both host and pod container | ||
|- | |- | ||
| | |oc expose | ||
| | |Create a service for a deployment | ||
| | | | ||
|- | |- | ||
| Line 116: | Line 116: | ||
|Simpler | |Simpler | ||
|- | |- | ||
|oc create service | |||
| | | | ||
| | |oc expose | ||
| | | | ||
|} | |} | ||
| Line 148: | Line 148: | ||
|Create a set of unique pods | |Create a set of unique pods | ||
|Databases | |Databases | ||
| | |No | ||
|- | |- | ||
|DaemonSet | |DaemonSet | ||
| Line 185: | Line 185: | ||
|No | |No | ||
|- | |- | ||
| | |EndpointSlices | ||
| | |IPs or FQDNs used by a service | ||
| | | | ||
| | | | ||
| Line 196: | Line 196: | ||
* Can include multiple containers | * Can include multiple containers | ||
* Containers within the pod can share storage/networking | * Containers within the pod can share storage/networking | ||
=== Pod Networking === | |||
* Every container in a pod shares IP and MAC addresses | |||
* Every container in a pod can access other containers via loopback addresses (localhost) | |||
* By default, every pod can communicate with every other pod in the cluster | |||
=== Services === | |||
* Fixes issues of direct-to-IP communication by adding a stable proxy-IP address that will update dynamically as the backing pods come and go | |||
* Services use `selector` fields to identify which pods are included. The pods themselves use `labels`. | |||
== Networking == | == Networking == | ||
Revision as of 15:39, 5 August 2026
Commands
| Command | Used for... | Notes |
|---|---|---|
| oc whoami | See who you are logged in as | |
| oc login | Log in to the cluster | Defaults to using a web login, but user/pass can be provided over the command line |
| oc new-project | Create a new project (namespace) | |
| oc describe | Get detailed information on a resource instance | |
| oc explain | Get documentation on a resource object | |
| oc api-resources | Get a list of all API resources | --api-group can be used to limit to certain API groups |
| oc adm top | Get resource usage on pods and similar | --sum will show a sum of resource usage |
| oc events | Get high-level logs | Helpful for things like image pull or pvc issues |
| oc debug | Open a shell session in the pod or node | Uses the first container by default, but as a copy; can also be used to log in to physical nodes |
| oc rsh | Open a shell session in a pod | Simpler version of `oc exec` |
| oc attach -it | Connect and create an interactive session with a pod | |
| oc port-forward | Expose a pod's port on the localhost | |
| oc image | Get info about an image | |
| oc edit | Make an edit to a resource's YAML and apply it | Useful for modifying the resource easily or in multiple ways |
| oc patch | Make an edit to a resource's field and apply it | Useful for very specific edits |
| oc cp | Copy a file into or out of a pod | |
| oc rsync | Copy a file into or out of a pod | Requires the rsync binary on both host and pod container |
| oc expose | Create a service for a deployment | |
| skopeo list-tags | List all tags for a given image | |
| skopeo inspect | Get image info like env variables and tags |
Commands to avoid using:
| Command | Used for | Use instead | Because |
|---|---|---|---|
| oc run | Create a single pod | oc create deployment | Includes replicas and other stuff |
| oc exec -it /bin/bash | Open remote connection | oc rsh | Simpler |
| oc create service | oc expose |
Important Resource Types
| Resource | Description | Useful for... | OS Only? |
|---|---|---|---|
| template | YAML manifest of multiple resources | creating multiple resources at once | Yes |
| pod | One or more containers; represents a single app | No | |
| Deployment | Represents pod templates along with replica sets | Deploying pods with replicas | No |
| StatefulSet | Create a set of unique pods | Databases | No |
| DaemonSet | Runs copies of pods on every node | storage daemons, log collectors, monitoring | No |
| project | OpenShift's namespaces | RBAC | Yes |
| service | pod-to-pod networking + DNS | No | |
| PersistentVolumeClaim | persistent storage | No | |
| Secret | Configs or other data that needs to be kept secure | SSH keys, API keys, OAuth tokens, passwords | No |
| Job | One-off tasks | Initialize database, create/restore from backup | No |
| CronJob | Scheduled tasks | Backups | No |
| EndpointSlices | IPs or FQDNs used by a service |
Pods
- Runs a single app
- Can include multiple containers
- Containers within the pod can share storage/networking
Pod Networking
- Every container in a pod shares IP and MAC addresses
- Every container in a pod can access other containers via loopback addresses (localhost)
- By default, every pod can communicate with every other pod in the cluster
Services
- Fixes issues of direct-to-IP communication by adding a stable proxy-IP address that will update dynamically as the backing pods come and go
- Services use `selector` fields to identify which pods are included. The pods themselves use `labels`.
Networking
Anki Questions
- What is <resource>?
- What command should be used to <action>?
- Where is <resource> useful compared to similar ones?