diff --git a/docs/api/workflows/projects.md b/docs/api/workflows/projects.md index ea4b6fe66f3..7b7ced1e6d0 100644 --- a/docs/api/workflows/projects.md +++ b/docs/api/workflows/projects.md @@ -49,6 +49,10 @@ EOF Setting the `field.cattle.io/creatorId` field allows the cluster member account to see project resources with the `get` command and view the project in the Rancher UI. Cluster owner and admin accounts don't need to set this annotation to perform these tasks. +Setting the `field.cattle.io/creator-principal-name` annotation to the user's principal preserves it in a projectroletemplatebinding automatically created for the project owner. + +If you don't want the creator to be added as the owner member (e.g. if the creator is a cluster administrator) to the project you may set the `field.cattle.io/no-creator-rbac` annotation to `true`, which will prevent the corresponding projectroletemplatebinding from being created. + ### Creating a Project With a Resource Quota Refer to [Kubernetes Resource Quota](https://kubernetes.io/docs/concepts/policy/resource-quotas/). @@ -91,6 +95,77 @@ spec: limitsMemory: 100Mi requestsCpu: 50m requestsMemory: 50Mi +EOF +``` + +## Adding a Member to a Project + +Look up the project ID to specify the `metadata.namespace` field and `projectName` field values. + +```bash +kubectl --namespace c-m-abcde get projects +``` + +Look up the role template ID to specify the `roleTemplateName` field value (e.g. `project-member` or `project-owner`). + +```bash +kubectl get roletemplates +``` + +When adding a user member specify the `userPrincipalName` field: + +```bash +kubectl create -f - <