1OC(1) June 2016 OC(1)
2
3
4
6 oc adm - Tools for managing a cluster
7
8
9
11 oc adm [OPTIONS]
12
13
14
16 Administrative Commands
17
18
19 Commands for managing a cluster are exposed here. Many administrative
20 actions involve interaction with the command-line client as well.
21
22
23
25 --allow_verification_with_non_compliant_keys=false
26 Allow a SignatureVerifier to use keys which are technically
27 non-compliant with RFC6962.
28
29
30 --alsologtostderr=false
31 log to standard error as well as files
32
33
34 --application_metrics_count_limit=100
35 Max number of application metrics to store (per container)
36
37
38 --as=""
39 Username to impersonate for the operation
40
41
42 --as-group=[]
43 Group to impersonate for the operation, this flag can be repeated
44 to specify multiple groups.
45
46
47 --azure-container-registry-config=""
48 Path to the file containing Azure container registry configuration
49 information.
50
51
52 --boot_id_file="/proc/sys/kernel/random/boot_id"
53 Comma-separated list of files to check for boot-id. Use the first
54 one that exists.
55
56
57 --cache-dir="/builddir/.kube/http-cache"
58 Default HTTP cache directory
59
60
61 --certificate-authority=""
62 Path to a cert file for the certificate authority
63
64
65 --client-certificate=""
66 Path to a client certificate file for TLS
67
68
69 --client-key=""
70 Path to a client key file for TLS
71
72
73 --cloud-provider-gce-lb-src-cidrs=130.211.0.0/22,209.85.152.0/22,209.85.204.0/22,35.191.0.0/16
74 CIDRs opened in GCE firewall for LB traffic proxy health checks
75
76
77 --cluster=""
78 The name of the kubeconfig cluster to use
79
80
81 --container_hints="/etc/cadvisor/container_hints.json"
82 location of the container hints file
83
84
85 --containerd="unix:///var/run/containerd.sock"
86 containerd endpoint
87
88
89 --context=""
90 The name of the kubeconfig context to use
91
92
93 --default-not-ready-toleration-seconds=300
94 Indicates the tolerationSeconds of the toleration for
95 notReady:NoExecute that is added by default to every pod that does not
96 already have such a toleration.
97
98
99 --default-unreachable-toleration-seconds=300
100 Indicates the tolerationSeconds of the toleration for unreach‐
101 able:NoExecute that is added by default to every pod that does not
102 already have such a toleration.
103
104
105 --docker="unix:///var/run/docker.sock"
106 docker endpoint
107
108
109 --docker-tls=false
110 use TLS to connect to docker
111
112
113 --docker-tls-ca="ca.pem"
114 path to trusted CA
115
116
117 --docker-tls-cert="cert.pem"
118 path to client certificate
119
120
121 --docker-tls-key="key.pem"
122 path to private key
123
124
125 --docker_env_metadata_whitelist=""
126 a comma-separated list of environment variable keys that needs to
127 be collected for docker containers
128
129
130 --docker_only=false
131 Only report docker containers in addition to root stats
132
133
134 --docker_root="/var/lib/docker"
135 DEPRECATED: docker root is read from docker info (this is a fall‐
136 back, default: /var/lib/docker)
137
138
139 --enable_load_reader=false
140 Whether to enable cpu load reader
141
142
143 --event_storage_age_limit="default=24h"
144 Max length of time for which to store events (per type). Value is a
145 comma separated list of key values, where the keys are event types
146 (e.g.: creation, oom) or "default" and the value is a duration. Default
147 is applied to all non-specified event types
148
149
150 --event_storage_event_limit="default=100000"
151 Max number of events to store (per type). Value is a comma sepa‐
152 rated list of key values, where the keys are event types (e.g.: cre‐
153 ation, oom) or "default" and the value is an integer. Default is
154 applied to all non-specified event types
155
156
157 --global_housekeeping_interval=0
158 Interval between global housekeepings
159
160
161 --housekeeping_interval=0
162 Interval between container housekeepings
163
164
165 --httptest.serve=""
166 if non-empty, httptest.NewServer serves on this address and blocks
167
168
169 --insecure-skip-tls-verify=false
170 If true, the server's certificate will not be checked for validity.
171 This will make your HTTPS connections insecure
172
173
174 --kubeconfig=""
175 Path to the kubeconfig file to use for CLI requests.
176
177
178 --log-flush-frequency=0
179 Maximum number of seconds between log flushes
180
181
182 --log_backtrace_at=:0
183 when logging hits line file:N, emit a stack trace
184
185
186 --log_cadvisor_usage=false
187 Whether to log the usage of the cAdvisor container
188
189
190 --log_dir=""
191 If non-empty, write log files in this directory
192
193
194 --logtostderr=true
195 log to standard error instead of files
196
197
198 --machine_id_file="/etc/machine-id,/var/lib/dbus/machine-id"
199 Comma-separated list of files to check for machine-id. Use the
200 first one that exists.
201
202
203 --match-server-version=false
204 Require server version to match client version
205
206
207 -n, --namespace=""
208 If present, the namespace scope for this CLI request
209
210
211 --request-timeout="0"
212 The length of time to wait before giving up on a single server
213 request. Non-zero values should contain a corresponding time unit (e.g.
214 1s, 2m, 3h). A value of zero means don't timeout requests.
215
216
217 -s, --server=""
218 The address and port of the Kubernetes API server
219
220
221 --stderrthreshold=2
222 logs at or above this threshold go to stderr
223
224
225 --storage_driver_buffer_duration=0
226 Writes in the storage driver will be buffered for this duration,
227 and committed to the non memory backends as a single transaction
228
229
230 --storage_driver_db="cadvisor"
231 database name
232
233
234 --storage_driver_host="localhost:8086"
235 database host:port
236
237
238 --storage_driver_password="root"
239 database password
240
241
242 --storage_driver_secure=false
243 use secure connection with database
244
245
246 --storage_driver_table="stats"
247 table name
248
249
250 --storage_driver_user="root"
251 database username
252
253
254 --token=""
255 Bearer token for authentication to the API server
256
257
258 --user=""
259 The name of the kubeconfig user to use
260
261
262 -v, --v=0
263 log level for V logs
264
265
266 --version=false
267 Print version information and quit
268
269
270 --vmodule=
271 comma-separated list of pattern=N settings for file-filtered log‐
272 ging
273
274
275
277 oc(1), oc-adm-build-chain(1), oc-adm-ca(1), oc-adm-certificate(1),
278 oc-adm-completion(1), oc-adm-config(1), oc-adm-cordon(1), oc-adm-cre‐
279 ate-api-client-config(1), oc-adm-create-bootstrap-policy-file(1),
280 oc-adm-create-bootstrap-project-template(1), oc-adm-create-error-tem‐
281 plate(1), oc-adm-create-key-pair(1), oc-adm-create-kubeconfig(1),
282 oc-adm-create-login-template(1), oc-adm-create-master-certs(1),
283 oc-adm-create-node-config(1), oc-adm-create-provider-selection-tem‐
284 plate(1), oc-adm-create-server-cert(1), oc-adm-create-signer-cert(1),
285 oc-adm-diagnostics(1), oc-adm-drain(1), oc-adm-groups(1),
286 oc-adm-ipfailover(1), oc-adm-manage-node(1), oc-adm-migrate(1),
287 oc-adm-new-project(1), oc-adm-options(1), oc-adm-pod-network(1),
288 oc-adm-policy(1), oc-adm-prune(1), oc-adm-registry(1),
289 oc-adm-release(1), oc-adm-router(1), oc-adm-taint(1), oc-adm-top(1),
290 oc-adm-uncordon(1), oc-adm-verify-image-signature(1),
291
292
293
295 June 2016, Ported from the Kubernetes man-doc generator
296
297
298
299Openshift Openshift CLI User Manuals OC(1)