mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-24 20:18:18 +00:00
Edit projects page
This commit is contained in:
@@ -48,7 +48,7 @@ You can assign the following resources directly to namespaces:
|
||||
- [Registries]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/registries/)
|
||||
- [Secrets]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/secrets/)
|
||||
|
||||
To manage permissions in a vanilla Kubernetes cluster, cluster admins configure role-based access policies for each namespace. With Rancher user permissions are assigned on the project level instead and automatically inherited by any namespace owned by the particular project.
|
||||
To manage permissions in a vanilla Kubernetes cluster, cluster admins configure role-based access policies for each namespace. With Rancher, user permissions are assigned on the project level instead, and permissions are automatically inherited by any namespace owned by the particular project.
|
||||
|
||||
> **Note:** If you create a namespace with `kubectl`, it may be unusable because `kubectl` doesn't require your new namespace to be scoped within a project that you have access to. If your permissions are restricted to the project level, it is better to [create a namespace through Rancher]({{<baseurl>}}/rancher/v2.x/en/project-admin/namespaces/#creating-namespaces) to ensure that you will have permission to access the namespace.
|
||||
|
||||
@@ -56,24 +56,6 @@ For more information on creating and moving namespaces, see [Namespaces]({{<base
|
||||
|
||||
# About Projects
|
||||
|
||||
Within Rancher, a project can contain multiple namespaces and access control policies, making it possible to organize and isolate resources within the project.
|
||||
|
||||
A project is a concept introduced by Rancher that allows you manage multiple namespaces as a group and perform Kubernetes operations in them. The Rancher UI provides features for [project administration]({{<baseurl>}}/rancher/v2.x/en/project-admin/) and for [managing applications within projects.]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/)
|
||||
|
||||
This section covers the following topics:
|
||||
|
||||
- [Projects](#projects)
|
||||
- [Default project](#default-project)
|
||||
- [System project](#system-project)
|
||||
- [Authorization](#authorization)
|
||||
- [Pod security policies](#pod-security-policies)
|
||||
- [Creating projects](#creating-projects)
|
||||
- [Switching between clusters and projects](#switching-between-clusters-and-projects)
|
||||
- [Namespaces](#namespaces)
|
||||
|
||||
|
||||
# Projects
|
||||
|
||||
In terms of hierarchy:
|
||||
|
||||
- Clusters contain projects
|
||||
@@ -83,9 +65,9 @@ You can use projects to support multi-tenancy, so that a team can access a proje
|
||||
|
||||
In the base version of Kubernetes, features like role-based access rights or cluster resources are assigned to individual namespaces. A project allows you to save time by giving an individual or a team access to multiple namespaces simultaneously.
|
||||
|
||||
You can use projects to perform actions like:
|
||||
You can use projects to perform actions such as:
|
||||
|
||||
- Assign users access to a group of namespaces (i.e., [project membership]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/project-members)).
|
||||
- Assign users to a group of namespaces (i.e., [project membership]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/project-members)).
|
||||
- Assign users specific roles in a project. A role can be owner, member, read-only, or [custom]({{<baseurl>}}/rancher/v2.x/en/admin-settings/rbac/default-custom-roles/).
|
||||
- Assign resources to the project.
|
||||
- Assign Pod Security Policies.
|
||||
|
||||
@@ -18,9 +18,10 @@ Resources that you can assign directly to namespaces include:
|
||||
- [Registries]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/registries/)
|
||||
- [Secrets]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/secrets/)
|
||||
|
||||
Although you can assign role-based access to namespaces in the base version of Kubernetes, you cannot assign roles to namespaces in Rancher. Instead, assign role-based access at the project level.
|
||||
To manage permissions in a vanilla Kubernetes cluster, cluster admins configure role-based access policies for each namespace. With Rancher, user permissions are assigned on the project level instead, and permissions are automatically inherited by any namespace owned by the particular project.
|
||||
|
||||
> **Note:** If you create a namespace with `kubectl`, it may be unusable because `kubectl` doesn't require your new namespace to be scoped within a project that you have access to. If your permissions are restricted to the project level, it is better to [create a namespace through Rancher]({{<baseurl>}}/rancher/v2.x/en/project-admin/namespaces/#creating-namespaces) to ensure that you will have permission to access the namespace.
|
||||
|
||||
> **Note:** If you create a namespace with `kubectl`, it may be unusable because `kubectl` doesn't require your new namespace to be scoped within a project that you have access to. If your permissions are restricted to the project level, it is better to [create a namespace through Rancher](#creating-namespaces) to ensure that you will have permission to access the namespace.
|
||||
|
||||
### Creating Namespaces
|
||||
|
||||
|
||||
Reference in New Issue
Block a user