Configuring an LDAP Name Service
Hammerspace 5.3 and later can use one or more existing LDAP directories to resolve Unix user and group identities (UIDs and GIDs) on the NFS data path. Each directory you configure is called an LDAP name service. You can add a name service from the GUI, the Admin CLI (name-service-config), or the REST API. When you configure more than one, you set the order in which Hammerspace queries them.
After you add an LDAP name service, users in that directory can access files on NFSv4.2 mounts with the permissions their UID and GID grant.
Hammerspace does the lookups through SSSD (the System Security Services Daemon) on the Anvil nodes — the metadata servers of the cluster. Hammerspace writes and manages the SSSD configuration for you; you do not configure SSSD yourself.
In Hammerspace 5.3, an LDAP name service and Active Directory cannot be configured on the same cluster. See Important Information.
|
This feature is distinct from the identity provider (IdP) used to log in to the Hammerspace management GUI, Admin CLI, and API. If you want LDAP for both NFS identity resolution and administrator login, configure the directory twice — once in (covered here) and once in . The two configurations are independent. |
This section includes the following subsections: