Blog · 2 October 2026

OpenShift RBAC Explained

OpenShift uses Kubernetes RBAC unchanged, but adds convenience commands under oc adm policy and a few default cluster roles you will use constantly: admin, edit, view and self-provisioner.

Local vs cluster bindings

A RoleBinding grants permissions inside one project, even when it references a ClusterRole. A ClusterRoleBinding grants them everywhere.

oc adm policy add-role-to-user edit dev1 -n payments
oc adm policy add-role-to-group view qa-team -n payments
oc adm policy add-cluster-role-to-group cluster-admin platform-admins

Always verify

oc auth can-i create deployment --as=dev1 -n payments
oc get rolebindings -n payments -o wide

Restricting project creation

Self-provisioning is granted to all authenticated users by the self-provisioners cluster role binding. Removing that group from the binding — and setting the autoupdate annotation to false so it is not restored — is a classic exam task covered step by step in the study guide.

Red Hat OpenShift Administration EX280 Study Guide

Red Hat OpenShift Administration EX280 Study Guide

Hands-On Labs, Practice Tasks, and Exam Strategies for the Red Hat Certified OpenShift Administrator

Get the book