Search the docs

Workflow Overview

Enabling TLS on an Existing Cluster

Use this workflow when enabling TLS on a Hammerspace cluster that is already configured with backend storage and clients.

This workflow is fully disruptive to normal platform operations. Schedule this procedure during a maintenance window. While the operation is in progress, the Hammerspace cluster, clients, and backend storage volumes will be offline for normal data operations.
  1. Enable TLS in the Hammerspace Management GUI.

  2. Upload trust certificates for clients and backend storage systems to Hammerspace.

  3. Download the cluster CA certificate and install it on storage systems that require it for trust, if needed.

  4. On each Linux client, ensure a client certificate exists (generate one if necessary) and upload it to Hammerspace.

  5. Configure tlshd on each client with the client certificate, private key, and CA trust store.

  6. Remount each client using xprtsec=mtls.

If you are deploying a new Hammerspace cluster that will use TLS from the start, complete setup in this order to minimize disruption:

  1. Install Hammerspace. Do not add third-party backing stores yet. See the Hammerspace 5.3 Installation and Licensing Guide.

  2. Enable TLS using the procedure in this document.

  3. Configure third-party backing stores and clients. See the Hammerspace 5.3 Configuration Guide.

  4. Add or assimilate data from the configured backing stores. See the Assimilation Solution Field Guide on the Support Portal.