You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/guides/rbac-for-users/readme.md
+30Lines changed: 30 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -68,6 +68,7 @@ The kubeconfig file should be placed in a location where HPE employees have read
68
68
The next step is to create ClusterRole and ClusterRoleBinding resources. The ClusterRole provided allows viewing all cluster and namespace scoped resources, but disallows creating, deleting, or modifying any resources.
69
69
70
70
ClusterRole
71
+
71
72
```yaml
72
73
apiVersion: rbac.authorization.k8s.io/v1
73
74
kind: ClusterRole
@@ -80,6 +81,7 @@ rules:
80
81
```
81
82
82
83
ClusterRoleBinding
84
+
83
85
```yaml
84
86
apiVersion: rbac.authorization.k8s.io/v1
85
87
kind: ClusterRoleBinding
@@ -138,6 +140,7 @@ If the "flux" user requires only the normal WLM permissions, then create and app
138
140
The `dws-workload-manager role is defined in [workload_manager_role.yaml](https://github.com/DataWorkflowServices/dws/blob/master/config/rbac/workload_manager_role.yaml).
139
141
140
142
ClusterRoleBinding for WLM permissions only:
143
+
141
144
```yaml
142
145
apiVersion: rbac.authorization.k8s.io/v1
143
146
kind: ClusterRoleBinding
@@ -158,6 +161,7 @@ If the "flux" user requires the normal WLM permissions as well as some of the NN
158
161
The `nnf-workload-manager` role is defined in [workload_manager_nnf_role.yaml](https://github.com/NearNodeFlash/nnf-sos/blob/master/config/rbac/workload_manager_nnf_role.yaml).
159
162
160
163
ClusterRoleBinding for WLM and NNF permissions:
164
+
161
165
```yaml
162
166
apiVersion: rbac.authorization.k8s.io/v1
163
167
kind: ClusterRoleBinding
@@ -173,4 +177,30 @@ roleRef:
173
177
apiGroup: rbac.authorization.k8s.io
174
178
```
175
179
180
+
If the "flux" user also requires "get" access to pods and their logs in the "default" namespace, then there is also a namespaced Role resource to provide that access. Create a RoleBinding to associate the "flux" user with the "nnf-workload-manager-coregrp" Role. The "flux" user will be bound to access the NNF resources, across all namespaces, via the ClusterRoleBinding above and it will be bound to access the pod resources, in only the "default" namespace, via this RoleBinding.
181
+
182
+
```console
183
+
kubectl get role -n default nnf-workload-manager-coregrp
184
+
```
185
+
186
+
The `nnf-workload-manager-coregrp` role is defined in [workload_manager_nnf_role_ns.yaml](https://github.com/NearNodeFlash/nnf-sos/blob/master/config/rbac-ns/workload_manager_nnf_role_ns.yaml).
187
+
188
+
RoleBinding for pod permissions:
189
+
190
+
```yaml
191
+
kind: RoleBinding
192
+
apiVersion: rbac.authorization.k8s.io/v1
193
+
metadata:
194
+
name: flux
195
+
namespace: default
196
+
subjects:
197
+
- kind: User
198
+
name: flux
199
+
apiGroup: rbac.authorization.k8s.io
200
+
roleRef:
201
+
kind: Role
202
+
name: nnf-workload-manager-coregrp
203
+
apiGroup: ""
204
+
```
205
+
176
206
The WLM should then use the kubeconfig file associated with this "flux" user to access the DataWorkflowServices API and the Rabbit system.
Copy file name to clipboardExpand all lines: docs/guides/storage-profiles/readme.md
+15Lines changed: 15 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -302,12 +302,17 @@ In general, `scale` gives a simple way for users to get a filesystem that has pe
302
302
- `$VG_NAME`- expands to a volume group name that is controlled by Rabbit software.
303
303
- `$DEVICE_LIST`- expands to a list of space-separated `/dev/<path>` devices. This list will contain the devices that were iterated over for the pvcreate step.
304
304
- `$DEVICE_NUM`- expands to the count of devices in `$DEVICE_LIST`
305
+
- `$DEVICE_NUM-1`- expands to the count of devices in `$DEVICE_LIST` minus 1
306
+
- `$DEVICE_NUM-2`- expands to the count of devices in `$DEVICE_LIST` minus 2
307
+
- `$DEVICE`- expands to the name of a new device. This is used by `vgextend` when repairing a RAID device
305
308
306
309
### LVM LV Commands
307
310
308
311
- `$VG_NAME`- see vgcreate above.
309
312
- `$LV_NAME`- expands to a logical volume name that is controlled by Rabbit software.
310
313
- `$DEVICE_NUM`- expands to a number indicating the number of devices allocated for the volume group.
314
+
- `$DEVICE_NUM-1`- expands to a number indicating the number of devices allocated for the volume group minus 1.
315
+
- `$DEVICE_NUM-2`- expands to a number indicating the number of devices allocated for the volume group minus 2.
311
316
- `$DEVICE1, $DEVICE2, ..., $DEVICEn`- each expands to one of the devices from the `$DEVICE_LIST` above.
312
317
- `$PERCENT_VG`- expands to the size that each LV should be based on a percentage of the total VG size
313
318
- `$LV_SIZE`- expands to the size of the LV in kB in the format expected by `lvcreate`
@@ -330,6 +335,16 @@ In general, `scale` gives a simple way for users to get a filesystem that has pe
330
335
- `$DEVICE_NUM`- expands to a number indicating the number of devices allocated for this storage request.
331
336
- `$DEVICE1, $DEVICE2, ..., $DEVICEn`- each expands to one of the devices from the `$DEVICE_LIST` above.
332
337
338
+
### zpool replace
339
+
340
+
- `$DEVICE_NUM`- expands to a number indicating the number of devices allocated for this storage request.
341
+
- `$DEVICE_NUM-1`- expands to a number indicating the number of devices allocated for this storage request minus 1.
342
+
- `$DEVICE_NUM-2`- expands to a number indicating the number of devices allocated for this storage request minus 2.
343
+
- `$DEVICE_LIST`- expands to a list of space-separated `/dev/<path>` devices. This list will contain the devices that were allocated for this storage request.
344
+
- `$POOL_NAME`- expands to a pool name that is controlled by Rabbit software.
345
+
- `$OLD_DEVICE`- expands to the name of a device that is degraded
346
+
- `$NEW_DEVICE`- expands to the name of a new device that can replace the degraded device
347
+
333
348
### lustre mkfs
334
349
335
350
- `$FS_NAME`- expands to the filesystem name that was passed to Rabbit software from the workflow's #DW line.
0 commit comments