[ Applies to ] StorageGuard 9.x and later / NetApp StorageGRID / Grid Manager and Tenant Manager
StorageGuard collects configuration data from NetApp StorageGRID by opening a secure HTTPS connection to the Admin Node and running read-only Grid Management API calls. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| Admin Node address | The network name or IP address of the StorageGRID Admin Node. |
| Credentials | A user name and password. |
| Role and permissions | The account needs an unlimited read-only role that can run GET API requests for the Grid Manager and the Tenant Manager, such as GET api/v3/grid/ntp-servers, GET api/v3/grid/identity-source, GET api/v3/org/identity-source, and GET api/v3/private/gateway-config. |
| Network access | HTTP or HTTPS (port 443) connectivity from the StorageGuard server to the Admin Node. |
Create a scan account
Choose the option that matches what you want StorageGuard to scan:
| Option | What StorageGuard scans | Account type |
|---|---|---|
| Option 1 | Grid Manager only | A local Grid Manager admin user |
| Option 2 | Grid Manager and Tenant Manager | A federated user from your identity source (IdP), in matching Grid Manager and Tenant Manager groups |
Admin group settings
Both options use a Grid Manager admin group with these settings:
| Setting | Value |
|---|---|
| Access mode | Read-only |
| Management permissions (required) | Root access, ILM, Metrics query, Tenant accounts, Other grid configuration, Storage appliance administrator, Maintenance, Manage alerts |
| Management permissions (optional, recommended) | Grid topology page configuration, Object metadata lookup, Acknowledge alarms (legacy) |
Option 1: Grid Manager only
- Log in to the Grid Manager.
- Select Configuration > Access control > Admin users.
- Select Create user, and enter the user details. Make sure the user has access to the Grid Management API.
- Select Continue.
- Assign the user to a group with the admin group settings above.
- Select Create user, and then select Finish.
Option 2: Grid Manager and Tenant Manager
In your identity source (IdP):
- In the identity federation source configured for StorageGRID, create a scan user, and add it to a designated IdP group.
In the Grid Manager:
- Select Configuration > Access control > Admin groups.
- Create or select the group that matches the designated IdP group.
- Apply the admin group settings above.
In the Tenant Manager:
- Select Access management > Groups.
- Create or select the group that matches the designated IdP group's unique name. For Active Directory, this is the sAMAccountName attribute. For OpenLDAP, it's the uid attribute.
- Set Access mode to Read-only, and Management permissions to Root access.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.