| copyright |
|
||
|---|---|---|---|
| lastupdated | 2026-08-04 | ||
| keywords | kubernetes, openshift | ||
| subcollection | openshift |
{{site.data.keyword.attribute-definition-list}}
{: #icks_map}
This page lists all ibmcloud oc commands as they are structured in the CLI. For more details on a specific command, click the command or see the {{site.data.keyword.openshiftlong_notm}} CLI reference.
{: #icks_map_api}
View the current API endpoint. {: shortdesc}
* [`ibmcloud oc api`](/docs/openshift?topic=openshift-kubernetes-service-cli#api-cli)
{: #icks_map_api-key}
View information about the API key for a cluster or reset it to a new key. {: shortdesc}
* [`ibmcloud oc api-key info`](/docs/openshift?topic=openshift-kubernetes-service-cli#api-key-info-cli)
* [`ibmcloud oc api-key reset`](/docs/openshift?topic=openshift-kubernetes-service-cli#api-key-reset-cli)
{: #icks_map_cluster}
View and modify cluster and cluster service settings. {: shortdesc}
cluster addon: View, enable, update, and disable cluster add-ons.cluster ca: Manage the Certificate Authority (CA) certificates of a cluster.cluster create: Create a classic or VPC cluster.cluster image-security: Manage image security enforcement in your cluster.cluster master: View and modify the master for a cluster.cluster pull-secret: Manage image pull secrets for the cluster to access images in IBM Cloud Container Registry.cluster service: View, bind, and unbind IBM Cloud services on a cluster.cluster subnet: Add and create portable subnets for a classic cluster.ibmcloud oc cluster addon disable acmibmcloud oc cluster addon disable alb-oauth-proxyibmcloud oc cluster addon disable cluster-autoscaleribmcloud oc cluster addon disable debug-tool- Beta
ibmcloud oc cluster addon disable headlamp ibmcloud oc cluster addon disable hpcs-router- Beta
ibmcloud oc cluster addon disable ibm-storage-operator ibmcloud oc cluster addon disable image-key-synchronizeribmcloud oc cluster addon disable istio- Deprecated
ibmcloud oc cluster addon disable istio-extras - Deprecated
ibmcloud oc cluster addon disable istio-sample-bookinfo ibmcloud oc cluster addon disable knativeibmcloud oc cluster addon disable kube-terminalibmcloud oc cluster addon disable openshift-data-foundationibmcloud oc cluster addon disable static-routeibmcloud oc cluster addon disable vpc-block-csi-driveribmcloud oc cluster addon enable acmibmcloud oc cluster addon enable alb-oauth-proxyibmcloud oc cluster addon enable cluster-autoscaleribmcloud oc cluster addon enable debug-tool- Beta
ibmcloud oc cluster addon enable headlamp ibmcloud oc cluster addon enable hpcs-router- Beta
ibmcloud oc cluster addon enable ibm-storage-operator ibmcloud oc cluster addon enable image-key-synchronizeribmcloud oc cluster addon enable istio- Deprecated
ibmcloud oc cluster addon enable istio-extras - Deprecated
ibmcloud oc cluster addon enable istio-sample-bookinfo ibmcloud oc cluster addon enable openshift-data-foundationibmcloud oc cluster addon enable static-routeibmcloud oc cluster addon enable vpc-block-csi-driveribmcloud oc cluster addon getibmcloud oc cluster addon lsibmcloud oc cluster addon optionsibmcloud oc cluster addon update acmibmcloud oc cluster addon update alb-oauth-proxyibmcloud oc cluster addon update cluster-autoscaleribmcloud oc cluster addon update debug-tool- Beta
ibmcloud oc cluster addon update headlamp ibmcloud oc cluster addon update hpcs-router- Beta
ibmcloud oc cluster addon update ibm-storage-operator ibmcloud oc cluster addon update image-key-synchronizeribmcloud oc cluster addon update istio- Deprecated
ibmcloud oc cluster addon update istio-extras - Deprecated
ibmcloud oc cluster addon update istio-sample-bookinfo ibmcloud oc cluster addon update knativeibmcloud oc cluster addon update kube-terminalibmcloud oc cluster addon update openshift-data-foundationibmcloud oc cluster addon update static-routeibmcloud oc cluster addon update vpc-block-csi-driveribmcloud oc cluster addon versionsibmcloud oc cluster ca createibmcloud oc cluster ca getibmcloud oc cluster ca rotateibmcloud oc cluster ca statusibmcloud oc cluster configibmcloud oc cluster create classicibmcloud oc cluster create satelliteibmcloud oc cluster create vpc-classicibmcloud oc cluster create vpc-gen2ibmcloud oc cluster getibmcloud oc cluster image-security disableibmcloud oc cluster image-security enableibmcloud oc cluster lsibmcloud oc cluster master audit-webhook getibmcloud oc cluster master audit-webhook setibmcloud oc cluster master audit-webhook unsetibmcloud oc cluster master console-oauth-access getibmcloud oc cluster master console-oauth-access setibmcloud oc cluster master pod-security getibmcloud oc cluster master pod-security policy disableibmcloud oc cluster master pod-security policy enableibmcloud oc cluster master pod-security policy getibmcloud oc cluster master pod-security setibmcloud oc cluster master pod-security unset- Deprecated
ibmcloud oc cluster master private-service-endpoint allowlist add - Deprecated
ibmcloud oc cluster master private-service-endpoint allowlist disable - Deprecated
ibmcloud oc cluster master private-service-endpoint allowlist enable - Deprecated
ibmcloud oc cluster master private-service-endpoint allowlist get - Deprecated
ibmcloud oc cluster master private-service-endpoint allowlist rm ibmcloud oc cluster master private-service-endpoint enableibmcloud oc cluster master public-service-endpoint disableibmcloud oc cluster master public-service-endpoint enableibmcloud oc cluster master refreshibmcloud oc cluster master satellite-service-endpoint allowlist addibmcloud oc cluster master satellite-service-endpoint allowlist disableibmcloud oc cluster master satellite-service-endpoint allowlist enableibmcloud oc cluster master satellite-service-endpoint allowlist getibmcloud oc cluster master satellite-service-endpoint allowlist rmibmcloud oc cluster master updateibmcloud oc cluster pull-secret applyibmcloud oc cluster rmibmcloud oc cluster service bindibmcloud oc cluster service lsibmcloud oc cluster service unbindibmcloud oc cluster subnet addibmcloud oc cluster subnet createibmcloud oc cluster subnet detach
{: #icks_map_credential}
Set and unset credentials that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account. {: shortdesc}
credential set: Set credentials that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account. This command applies to the targeted resource group, or to the default resource group if no resource group is targeted.
{: #icks_map_experimental}
[Expires on 2026-10-21] Experiment with new commands. IMPORTANT: Commands here will retire after the [date] in their description. {: shortdesc}
experimental trusted-profile: [Expires on 2026-10-21] View and set the trusted profile on a cluster or the default trusted profile for clusters created in a resource-group.experimental vni: [Deactivated on 2026-05-20! Useibmcloud ks vniinstead] Attach, detach, and list Virtual Network Interfaces on worker nodes.ibmcloud oc experimental trusted-profile default getibmcloud oc experimental trusted-profile default setibmcloud oc experimental trusted-profile getibmcloud oc experimental trusted-profile setibmcloud oc experimental vni attach baremetalibmcloud oc experimental vni attach virtualibmcloud oc experimental vni detachibmcloud oc experimental vni ls
{: #icks_map_flavor}
Getting flavor related information. Flavors determine how much virtual CPU, memory, and disk space is available to each worker node. {: shortdesc}
* [`ibmcloud oc flavor get`](/docs/openshift?topic=openshift-kubernetes-service-cli#flavor-get-cli)
* [`ibmcloud oc flavor ls`](/docs/openshift?topic=openshift-kubernetes-service-cli#flavor-ls-cli)
{: #icks_map_infra-permissions}
View information about infrastructure permissions that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account. {: shortdesc}
* [`ibmcloud oc infra-permissions get`](/docs/openshift?topic=openshift-kubernetes-service-cli#infra-permissions-get-cli)
{: #icks_map_ingress}
View and modify Ingress services and settings {: shortdesc}
ingress alb: View and configure an Ingress application load balancer (ALB).ingress domain: Manage a cluster's Ingress domains.ingress instance: Manage registered instances of the IBM Cloud Secrets Manager.ingress load-balancer: Modify load balancers that expose Ingress ALBs in your cluster.ingress secret: Manage Ingress secrets in a cluster.ingress security: Modify the ingress security configuration for your cluster.ingress status-report: View and configure Ingress status reports.ibmcloud oc ingress alb autoscale getibmcloud oc ingress alb autoscale setibmcloud oc ingress alb autoscale unsetibmcloud oc ingress alb autoupdate disableibmcloud oc ingress alb autoupdate enableibmcloud oc ingress alb autoupdate getibmcloud oc ingress alb create classicibmcloud oc ingress alb create vpc-gen2ibmcloud oc ingress alb disableibmcloud oc ingress alb enable classicibmcloud oc ingress alb enable vpc-gen2ibmcloud oc ingress alb getibmcloud oc ingress alb health-checker disableibmcloud oc ingress alb health-checker enableibmcloud oc ingress alb health-checker getibmcloud oc ingress alb lsibmcloud oc ingress alb updateibmcloud oc ingress alb versionsibmcloud oc ingress domain createibmcloud oc ingress domain default replaceibmcloud oc ingress domain getibmcloud oc ingress domain lsibmcloud oc ingress domain rmibmcloud oc ingress domain secret regenerateibmcloud oc ingress domain secret rmibmcloud oc ingress domain updateibmcloud oc ingress instance default setibmcloud oc ingress instance default unsetibmcloud oc ingress instance getibmcloud oc ingress instance lsibmcloud oc ingress instance registeribmcloud oc ingress instance unregisteribmcloud oc ingress load-balancer backend setibmcloud oc ingress load-balancer getibmcloud oc ingress load-balancer proxy-protocol disableibmcloud oc ingress load-balancer proxy-protocol enableibmcloud oc ingress secret createibmcloud oc ingress secret field addibmcloud oc ingress secret field lsibmcloud oc ingress secret field rmibmcloud oc ingress secret getibmcloud oc ingress secret lsibmcloud oc ingress secret rmibmcloud oc ingress secret updateibmcloud oc ingress security port80 disableibmcloud oc ingress security port80 enableibmcloud oc ingress security port80 getibmcloud oc ingress status-report disableibmcloud oc ingress status-report enableibmcloud oc ingress status-report getibmcloud oc ingress status-report ignored-errors addibmcloud oc ingress status-report ignored-errors lsibmcloud oc ingress status-report ignored-errors rm
{: #icks_map_kms}
View and configure Key Management Service integrations. {: shortdesc}
kms crk: List and configure the root keys for a Key Management Service instance.kms instance: View and configure available Key Management Service instances.
{: #icks_map_locations}
List supported IBM Cloud Kubernetes Service locations. {: shortdesc}
* [`ibmcloud oc locations`](/docs/openshift?topic=openshift-kubernetes-service-cli#locations-cli)
{: #icks_map_logging}
Forward logs from your cluster. {: shortdesc}
logging autoupdate: Manage automatic updates of the Fluentd add-on in a cluster.logging config: View or modify log forwarding configurations for a cluster.logging filter: View or modify log filters for a cluster.ibmcloud oc logging autoupdate disableibmcloud oc logging autoupdate enableibmcloud oc logging autoupdate getibmcloud oc logging config createibmcloud oc logging config getibmcloud oc logging config rmibmcloud oc logging config updateibmcloud oc logging filter createibmcloud oc logging filter getibmcloud oc logging filter rmibmcloud oc logging filter updateibmcloud oc logging refresh
{: #icks_map_messages}
View the current user messages. {: shortdesc}
* [`ibmcloud oc messages`](/docs/openshift?topic=openshift-kubernetes-service-cli#messages-cli)
{: #icks_map_nlb-dns}
Create and manage host names for network load balancer (NLB) IP addresses in a cluster and health check monitors for host names. {: shortdesc}
nlb-dns create: Create a DNS host name.nlb-dns monitor: Create and manage health check monitors for network load balancer (NLB) IP addresses and host names in a clusternlb-dns rm: Remove an NLB IP or load balancer host name from an NLB host name.nlb-dns secret: Manage the secret for an NLB subdomain.ibmcloud oc nlb-dns addibmcloud oc nlb-dns create classicibmcloud oc nlb-dns create vpc-gen2ibmcloud oc nlb-dns getibmcloud oc nlb-dns lsibmcloud oc nlb-dns monitor configureibmcloud oc nlb-dns monitor disableibmcloud oc nlb-dns monitor enableibmcloud oc nlb-dns monitor getibmcloud oc nlb-dns monitor lsibmcloud oc nlb-dns replaceibmcloud oc nlb-dns rm classicibmcloud oc nlb-dns rm vpc-gen2ibmcloud oc nlb-dns secret regenerateibmcloud oc nlb-dns secret rm
{: #icks_map_quota}
View the quota and limits for cluster-related resources in your IBM Cloud account. {: shortdesc}
* [`ibmcloud oc quota ls`](/docs/openshift?topic=openshift-kubernetes-service-cli#quota-ls-cli)
{: #icks_map_script}
Rewrite scripts that call IBM Cloud Kubernetes Service plug-in commands. Legacy-structured commands are replaced with beta-structured commands. {: shortdesc}
* [`ibmcloud oc script update`](/docs/openshift?topic=openshift-kubernetes-service-cli#script-update-cli)
{: #icks_map_security-group}
Run operations against a security group. {: shortdesc}
* [`ibmcloud oc security-group ls`](/docs/openshift?topic=openshift-kubernetes-service-cli#security-group-ls-cli)
* [`ibmcloud oc security-group reset`](/docs/openshift?topic=openshift-kubernetes-service-cli#security-group-reset-cli)
* [`ibmcloud oc security-group sync`](/docs/openshift?topic=openshift-kubernetes-service-cli#security-group-sync-cli)
{: #icks_map_storage}
View and modify storage resources. {: shortdesc}
storage attachment: View and modify storage volume attachments of worker nodes in your cluster.storage volume: View a list of storage volumes.
{: #icks_map_subnets}
List available portable subnets in your IBM Cloud infrastructure account. {: shortdesc}
* [`ibmcloud oc subnets`](/docs/openshift?topic=openshift-kubernetes-service-cli#subnets-cli)
{: #icks_map_versions}
List all the container platform versions that are available for IBM Cloud Kubernetes Service clusters. {: shortdesc}
* [`ibmcloud oc versions`](/docs/openshift?topic=openshift-kubernetes-service-cli#versions-cli)
{: #icks_map_vlan}
List public and private VLANs for a zone and view the VLAN spanning status. {: shortdesc}
vlan spanning: View the VLAN spanning status for your IBM Cloud classic infrastructure account.
{: #icks_map_vni}
Attach, detach, and list Virtual Network Interfaces on worker nodes. {: shortdesc}
vni attach: Attach a Virtual Network Interface to a worker node.
{: #icks_map_vpc}
Get information about VPCs and manage VPC clusters. {: shortdesc}
vpc outbound-traffic-protection: Change the outbound traffic protection for a Secure By Default VPC cluster.vpc secure-by-default: Modify Secure By Default Network settings for a VPC cluster.
{: #icks_map_webhook-create}
Register a webhook in a cluster. {: shortdesc}
* [`ibmcloud oc webhook-create`](/docs/openshift?topic=openshift-kubernetes-service-cli#webhook-create-cli)
{: #icks_map_worker}
View and modify worker nodes for a cluster. {: shortdesc}
* [`ibmcloud oc worker get`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-get-cli)
* [`ibmcloud oc worker ls`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-ls-cli)
* [`ibmcloud oc worker reboot`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-reboot-cli)
* [`ibmcloud oc worker reload`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-reload-cli)
* [`ibmcloud oc worker replace`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-replace-cli)
* [`ibmcloud oc worker rm`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-rm-cli)
* [`ibmcloud oc worker update`](/docs/openshift?topic=openshift-kubernetes-service-cli#worker-update-cli)
{: #icks_map_worker-pool}
View and modify worker pools for a cluster. {: shortdesc}
worker-pool create: Add a worker pool to a cluster. No worker nodes are created until zones are added to the worker pool.worker-pool label: Set and remove custom Kubernetes labels for all worker nodes in a worker pool.worker-pool operating-system: Manage the operating system of a worker pool.worker-pool taint: Set and remove Kubernetes taints for all worker nodes in a worker pool.ibmcloud oc worker-pool create classicibmcloud oc worker-pool create satelliteibmcloud oc worker-pool create vpc-classicibmcloud oc worker-pool create vpc-gen2ibmcloud oc worker-pool getibmcloud oc worker-pool label rmibmcloud oc worker-pool label setibmcloud oc worker-pool lsibmcloud oc worker-pool operating-system setibmcloud oc worker-pool rebalanceibmcloud oc worker-pool resizeibmcloud oc worker-pool rmibmcloud oc worker-pool taint rmibmcloud oc worker-pool taint setibmcloud oc worker-pool zones
{: #icks_map_zone}
List availability zones and modify the zones attached to a worker pool. {: shortdesc}
zone add: Add a zone to one or more worker pools in a cluster.