Creating a project as another user

Impersonation allows you to create a project as a different user.

API impersonation

You can configure a request to the OKD API to act as though it originated from another user. For more information, see User impersonation in the Kubernetes documentation.

Impersonating a user when you create a project

You can impersonate a different user when you create a project request. Because system:authenticated:oauth is the only bootstrap group that can create project requests, you must impersonate that group.

Procedure

  • To create a project request on behalf of a different user:

    1. $ oc new-project <project> --as=<user> \
    2. --as-group=system:authenticated --as-group=system:authenticated:oauth