$ oc adm pod-network join-projects --to=<project1> <project2> <project3>
When your cluster is configured to use the multitenant isolation mode for the OpenShift SDN CNI plug-in, each project is isolated by default. Network traffic is not allowed between Pods or services in different projects in multitenant isolation mode.
You can change the behavior of multitenant isolation for a project in two ways:
You can join one or more projects, allowing network traffic between Pods and services in different projects.
You can disable network isolation for a project. It will be globally accessible, accepting network traffic from Pods and services in all other projects. A globally accessible project can access Pods and services in all other projects.
You must have a cluster configured to use the OpenShift SDN Container Network Interface (CNI) plug-in in multitenant isolation mode.
You can join two or more projects to allow network traffic between Pods and services in different projects.
Install the OpenShift CLI (oc
).
You must log in to the cluster with a user that has the cluster-admin
role.
Use the following command to join projects to an existing project network:
$ oc adm pod-network join-projects --to=<project1> <project2> <project3>
Alternatively, instead of specifying specific project names, you can use the
--selector=<project_selector>
option to specify projects based upon an
associated label.
Optional: Run the following command to view the pod networks that you have joined together:
$ oc get netnamespaces
Projects in the same pod-network have the same network ID in the NETID column.
You can isolate a project so that Pods and services in other projects cannot access its Pods and services.
Install the OpenShift CLI (oc
).
You must log in to the cluster with a user that has the cluster-admin
role.
To isolate the projects in the cluster, run the following command:
$ oc adm pod-network isolate-projects <project1> <project2>
Alternatively, instead of specifying specific project names, you can use the
--selector=<project_selector>
option to specify projects based upon an
associated label.
You can disable network isolation for a project.
Install the OpenShift CLI (oc
).
You must log in to the cluster with a user that has the cluster-admin
role.
Run the following command for the project:
$ oc adm pod-network make-projects-global <project1> <project2>
Alternatively, instead of specifying specific project names, you can use the
--selector=<project_selector>
option to specify projects based upon an
associated label.