openshift中创建账户的默认角色是self-provisioner,而该角色是拥有创建project权限的。
https://docs.openshift.com/container-platform/4.2/authentication/using-rbac.html
但我们并不希望每个用户都拥有该权限,故需要对此进行调整。
oc describe clusterrole.rbac self-provisioner #查看self-provisioner信息
oc edit clusterrole.rbac self-provisioner #修改self-provisioner配置信息,Verb : The action itself: get, list, create, update, delete, deletecollection, or watch
oc describe clusterrolebinding.rbac #获取用户绑定信息