How Hammerspace Manages SSSD on the Anvils
Hammerspace writes the SSSD configuration on the Anvils itself, from the name services and Active Directory settings you configure. This section explains what the configuration looks like in each state, so that you can tell a normal state from a fault when you or Hammerspace Support inspect an Anvil.
Configuration Files
Hammerspace manages two files in /etc/sssd on each Anvil:
-
/etc/sssd/sssd.conf— the SSSD configuration. When Hammerspace generates it from your LDAP name services, its first line is# hammerspace-managed-by = nameservice. It has one[domain/<domain name>]section per name service, listed in resolution order. The file is readable byrootonly, and a bind secret in it is obfuscated. -
/etc/sssd/target-sssd-state— containsenabledordisabled, the state Hammerspace wants SSSD to be in.
Do not edit either file. Hammerspace rewrites sssd.conf whenever the configuration changes and also once a day, and a manual change is lost.
Configuration States
| What is configured | /etc/sssd/sssd.conf |
SSSD |
|---|---|---|
One or more LDAP name services |
Generated by Hammerspace, with the |
Running on the primary Anvil |
No LDAP name service; Active Directory joined with the RFC2307 or RFC2307BIS schema |
Written by the Active Directory integration ( |
Running |
No LDAP name service, and Active Directory not joined or joined without an ID-mapping schema |
Absent, or left from an earlier Active Directory join (see below) |
Stopped and disabled |
An absent sssd.conf is correct in the last state; it does not by itself indicate a fault. When you remove the last LDAP name service, Hammerspace removes the file and stops SSSD.
In Hammerspace 5.3, SSSD runs only on the primary Anvil while LDAP name services are configured. The other Anvils receive the same sssd.conf, but SSSD is not started on them, so finding SSSD stopped on a secondary Anvil is expected. SSSD is started on the new primary Anvil after a failover, and lookups resume as soon as the management service is available there, typically within a few minutes.
After you leave Active Directory, sssd.conf can still contain the Active Directory domain’s section. This is expected in 5.3: SSSD is stopped when you leave, and the file is replaced when you add an LDAP name service.
When a Sync Fails
If Hammerspace cannot copy the configuration to an Anvil, or cannot start SSSD with it, it raises an SSSD_CONFIG_SYNC_FAILED event naming that Anvil and retries every 2 minutes. The event clears when a retry succeeds. See Limitations for what happens to lookups meanwhile.