[ Applies to ] StorageGuard 9.x and later / Dell PowerScale and Isilon storage systems / OneFS
StorageGuard collects configuration data from Dell PowerScale (formerly Isilon) storage systems by running read-only OneFS commands over SSH. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| System address | The network name or IP address of each PowerScale storage system. |
| Credentials | An array user name and password for each PowerScale storage system. |
| Role and permissions | The account needs an unlimited read-only role that can run all list and view commands and other read-only OneFS commands, such as isi auth users list -v, isi services -l, isi_log_server list, and isi_ntp_config list. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to each PowerScale system. |
Create a scan account
The following procedure is a suggested way to create a user, a custom role with read-only privileges, and the sudo rights the scan needs. The examples use cntuser and cntrole; you can use any names.
Create the user and role
- Log in to the PowerScale cluster over SSH as root or another account that can manage users and roles.
-
Create the user and the role, and add the user to the role. Replace
<password>with the account password:isi auth users create cntuser --password <password> isi auth roles create cntrole isi auth roles modify cntrole --add-user cntuser -
Grant the role read-only access (
--add-priv-ro) to each privilege:isi auth roles modify cntrole --add-priv-ro ISI_PRIV_ANTIVIRUS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_AUDIT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_AUTH isi auth roles modify cntrole --add-priv-ro ISI_PRIV_CERTIFICATE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_CLOUDPOOLS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_CLUSTER isi auth roles modify cntrole --add-priv-ro ISI_PRIV_DEVICES isi auth roles modify cntrole --add-priv-ro ISI_PRIV_ESRS_DOWNLOAD isi auth roles modify cntrole --add-priv-ro ISI_PRIV_EVENT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_FILE_FILTER isi auth roles modify cntrole --add-priv-ro ISI_PRIV_FTP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_GET_SET isi auth roles modify cntrole --add-priv-ro ISI_PRIV_HARDENING isi auth roles modify cntrole --add-priv-ro ISI_PRIV_HDFS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_HTTP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_IFS_BACKUP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_IFS_RESTORE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_JOB_ENGINE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_LICENSE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_LOGIN_CONSOLE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_LOGIN_PAPI isi auth roles modify cntrole --add-priv-ro ISI_PRIV_LOGIN_SSH isi auth roles modify cntrole --add-priv-ro ISI_PRIV_MONITORING isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NDMP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NETWORK isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NFS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NS_IFS_ACCESS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NS_TRAVERSE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_NTP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_PERFORMANCE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_QUOTA isi auth roles modify cntrole --add-priv-ro ISI_PRIV_REMOTE_SUPPORT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_ROLE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SMARTPOOLS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SMB isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SNAPSHOT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SNMP isi auth roles modify cntrole --add-priv-ro ISI_PRIV_STATISTICS isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SWIFT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SYNCIQ isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SYS_SUPPORT isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SYS_TIME isi auth roles modify cntrole --add-priv-ro ISI_PRIV_SYS_UPGRADE isi auth roles modify cntrole --add-priv-ro ISI_PRIV_VCENTER isi auth roles modify cntrole --add-priv-ro ISI_PRIV_WORM
Grant sudo rights
- Open
/etc/mcp/override/sudoersfor editing. -
Add the following line, as a single line:
cntuser ALL=(ALL) NOPASSWD: /usr/bin/isi_ntp_config list, /usr/sbin/isi_log_server list, /usr/bin/isi status, /usr/bin/isi version, /usr/bin/isi networks list interfaces -w, /usr/bin/isi networks list subnets, /usr/bin/isi license status, /usr/bin/isi license list --format csv, /usr/bin/isi services -l, cat /etc/ifs/array.xml
cntuser at the start of the sudoers line.[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.