Search the docs

How Hammerspace Manages SSSD on the Anvils

Hammerspace writes the SSSD configuration on the Anvils itself, from the name services and Active Directory settings you configure. This section explains what the configuration looks like in each state, so that you can tell a normal state from a fault when you or Hammerspace Support inspect an Anvil.

Configuration Files

Hammerspace manages two files in /etc/sssd on each Anvil:

  • /etc/sssd/sssd.conf — the SSSD configuration. When Hammerspace generates it from your LDAP name services, its first line is # hammerspace-managed-by = nameservice. It has one [domain/<domain name>] section per name service, listed in resolution order. The file is readable by root only, and a bind secret in it is obfuscated.

  • /etc/sssd/target-sssd-state — contains enabled or disabled, the state Hammerspace wants SSSD to be in.

Do not edit either file. Hammerspace rewrites sssd.conf whenever the configuration changes and also once a day, and a manual change is lost.

Configuration States

What is configured /etc/sssd/sssd.conf SSSD

One or more LDAP name services

Generated by Hammerspace, with the hammerspace-managed-by line

Running on the primary Anvil

No LDAP name service; Active Directory joined with the RFC2307 or RFC2307BIS schema

Written by the Active Directory integration (id_provider = ad), without the hammerspace-managed-by line

Running

No LDAP name service, and Active Directory not joined or joined without an ID-mapping schema

Absent, or left from an earlier Active Directory join (see below)

Stopped and disabled

An absent sssd.conf is correct in the last state; it does not by itself indicate a fault. When you remove the last LDAP name service, Hammerspace removes the file and stops SSSD.

In Hammerspace 5.3, SSSD runs only on the primary Anvil while LDAP name services are configured. The other Anvils receive the same sssd.conf, but SSSD is not started on them, so finding SSSD stopped on a secondary Anvil is expected. SSSD is started on the new primary Anvil after a failover, and lookups resume as soon as the management service is available there, typically within a few minutes.

After you leave Active Directory, sssd.conf can still contain the Active Directory domain’s section. This is expected in 5.3: SSSD is stopped when you leave, and the file is replaced when you add an LDAP name service.

When a Sync Fails

If Hammerspace cannot copy the configuration to an Anvil, or cannot start SSSD with it, it raises an SSSD_CONFIG_SYNC_FAILED event naming that Anvil and retries every 2 minutes. The event clears when a retry succeeds. See Limitations for what happens to lookups meanwhile.