Enable or Disable TLS
| Enabling or disabling TLS from the CLI carries the same disruption and client remount requirements as doing so from the GUI. See Workflow Overview before running either command. |
TLS is enabled and disabled cluster-wide using the cluster-config command.
To enable TLS and require mutual authentication on all NFS connections:
cluster-config --nfs-tls-required
To disable TLS and revert all NFS connections to plaintext:
cluster-config --nfs-tls-forbidden
Enabling or disabling TLS typically takes 2–3 minutes, and up to about 30 minutes when the DSX data-portal mounts are restarted during the change. Both commands start a background task and wait for it for up to 5 minutes. If the task has not finished by then, the command returns an error with the message cluster-config: Task-based operation still running after 5 minutes. To monitor progress, use: task-list --id <task-id>. The task (named cluster-update) keeps running. The change is complete when the task reports COMPLETED with the status message Updated: [nfsTransportPolicy → TLS_REQUIRED_WITH_MUTUAL_AUTH] (or TLS_FORBIDDEN).
While the change runs, the task’s status message shows its progress, for example Updating NFS transport policy: Configuring metadata server, Updating NFS transport policy: Restarting metadata server, and Updating NFS transport policy: Configuring product nodes. Hammerspace makes up to three attempts to configure any node that fails before the task fails.
To return immediately without waiting, add --async, and monitor the task separately:
cluster-config --nfs-tls-required --async
To check the current TLS policy, look for the NFS transport policy line in the output of:
cluster-config --view
The cluster-config command also includes options for managing the management plane HTTPS certificate used by the GUI and REST API (--server-certificate-chain, --server-private-key, --server-certificate-reset). These options are unrelated to NFS over TLS and are not covered in this document.
|