Red Hat OpenShift: Difference between revisions

From wiki.vacula.xyz
Line 74: Line 74:
|Requires the rsync binary on both host and pod container
|Requires the rsync binary on both host and pod container
|-
|-
|
|oc expose
|
|Create a service for a deployment
|
|
|-
|-
Line 116: Line 116:
|Simpler
|Simpler
|-
|-
|oc create service
|
|
|
|oc expose
|
|
|
|}
|}
Line 148: Line 148:
|Create a set of unique pods
|Create a set of unique pods
|Databases
|Databases
|
|No
|-
|-
|DaemonSet
|DaemonSet
Line 185: Line 185:
|No
|No
|-
|-
|
|EndpointSlices
|
|IPs or FQDNs used by a service
|
|
|
|
Line 196: Line 196:
* Can include multiple containers  
* Can include multiple containers  
* Containers within the pod can share storage/networking
* Containers within the pod can share storage/networking
=== Pod Networking ===
* Every container in a pod shares IP and MAC addresses
* Every container in a pod can access other containers via loopback addresses (localhost)
* By default, every pod can communicate with every other pod in the cluster
=== Services ===
* Fixes issues of direct-to-IP communication by adding a stable proxy-IP address that will update dynamically as the backing pods come and go
* Services use `selector` fields to identify which pods are included. The pods themselves use `labels`.


== Networking ==
== Networking ==

Revision as of 15:39, 5 August 2026

Commands

Command Used for... Notes
oc whoami See who you are logged in as
oc login Log in to the cluster Defaults to using a web login, but user/pass can be provided over the command line
oc new-project Create a new project (namespace)
oc describe Get detailed information on a resource instance
oc explain Get documentation on a resource object
oc api-resources Get a list of all API resources --api-group can be used to limit to certain API groups
oc adm top Get resource usage on pods and similar --sum will show a sum of resource usage
oc events Get high-level logs Helpful for things like image pull or pvc issues
oc debug Open a shell session in the pod or node Uses the first container by default, but as a copy; can also be used to log in to physical nodes
oc rsh Open a shell session in a pod Simpler version of `oc exec`
oc attach -it Connect and create an interactive session with a pod
oc port-forward Expose a pod's port on the localhost
oc image Get info about an image
oc edit Make an edit to a resource's YAML and apply it Useful for modifying the resource easily or in multiple ways
oc patch Make an edit to a resource's field and apply it Useful for very specific edits
oc cp Copy a file into or out of a pod
oc rsync Copy a file into or out of a pod Requires the rsync binary on both host and pod container
oc expose Create a service for a deployment
skopeo list-tags List all tags for a given image
skopeo inspect Get image info like env variables and tags

Commands to avoid using:

Command Used for Use instead Because
oc run Create a single pod oc create deployment Includes replicas and other stuff
oc exec -it /bin/bash Open remote connection oc rsh Simpler
oc create service oc expose

Important Resource Types

Resource Description Useful for... OS Only?
template YAML manifest of multiple resources creating multiple resources at once Yes
pod One or more containers; represents a single app No
Deployment Represents pod templates along with replica sets Deploying pods with replicas No
StatefulSet Create a set of unique pods Databases No
DaemonSet Runs copies of pods on every node storage daemons, log collectors, monitoring No
project OpenShift's namespaces RBAC Yes
service pod-to-pod networking + DNS No
PersistentVolumeClaim persistent storage No
Secret Configs or other data that needs to be kept secure SSH keys, API keys, OAuth tokens, passwords No
Job One-off tasks Initialize database, create/restore from backup No
CronJob Scheduled tasks Backups No
EndpointSlices IPs or FQDNs used by a service

Pods

  • Runs a single app
  • Can include multiple containers
  • Containers within the pod can share storage/networking

Pod Networking

  • Every container in a pod shares IP and MAC addresses
  • Every container in a pod can access other containers via loopback addresses (localhost)
  • By default, every pod can communicate with every other pod in the cluster

Services

  • Fixes issues of direct-to-IP communication by adding a stable proxy-IP address that will update dynamically as the backing pods come and go
  • Services use `selector` fields to identify which pods are included. The pods themselves use `labels`.

Networking

Anki Questions

  1. What is <resource>?
  2. What command should be used to <action>?
  3. Where is <resource> useful compared to similar ones?