User and Group Management
builtin-group-user-add
builtin-group-user-add [options]
Add user to a builtin group
Options
--group
Group name to be added to (Required)
--help
Display this help and exit
--username
The username to be added (Required)
builtin-group-user-list
builtin-group-user-list [options]
List users of a builtin group
Options
--group
The group name to be listed (Required)
--help
Display this help and exit
builtin-group-user-remove
builtin-group-user-remove [options]
Remove user from a builtin group
Options
--group
Group name to be removed from (Required)
--help
Display this help and exit
--username
The username to be removed (Required)
login-policy-config
login-policy-config [options]
Configure the system login policies
Options
--allowed-networks
Space separated list of allowed networks in CIDR notation (i.e. 10.50.100.0/24)
--allowed-networks-clear
Allow access from all remote networks
--help
Display this help and exit
--lock-after-failures
The number of consecutive login failures after which an account will be locked. When not set, the account lockout feature is disabled
--lock-after-failures-clear
Clears all login failure lock attributes. Resets failure counts for all users
--lock-failure-interval
The time in seconds between failed login attempts that constitutes consecutive failures. When not set, the default is 15 minutes. Requires that lock-after-failures is, or has been set
--lockout-time
The amount of time in seconds an account remains locked due to too many consecutive login failures. When not set, the default is 10 minutes. Requires that lock-after-failures is, or has been set
--view
View the default login policies
role-create
role-create [options]
Create a user role with access permissions
role-create --name graham --acl "ANY:+c+r+u+d"
Available OBJECT_TYPEs include ANY,EVENT,NODE,DATA_MOVER,NETWORK_IF,SHARE,USER,USER_GROUP,ROLE,TASK,SMTP,NOTIFICATION_RULE,HEARTBEAT,NTP,LOGICAL_VOLUME,LDAP,CLUSTER,ELEMENTAL_OBJECTIVE,OBJECTIVE,SCHEDULE,SNAPSHOT_RETENTION,FILE_SNAPSHOT,OBJECT_STORAGE_VOLUME,CLOUD_MOVER,OBJECT_STORE_LOGICAL_VOLUME,SNMP,SW_UPDATE_TASK,CTDB,SHARE_SNAPSHOT,BACKUP,SAMBA_AD,DOMAIN_IDMAP,DATA_PORTAL,DNS,VOLUME_GROUP
Options
--acl
ACL, in the format: {OBJECT_TYPE}:{+{grant permissions}}{-{revoke permissions}}. Possible permissions: 'c'-create, 'r'-read, 'u'-update, 'd'-delete (Required)
--help
Display this help and exit
--idle-timeout
This role’s idle timeout for user interfaces (Web UI, CLI). When not specified, the default is 1 hour. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed
--name
The role name (Required)
--no-idle-timeout
Disables this role’s idle timeout for user interfaces
role-delete
role-delete [options]
Remove a user role
Options
--help
Display this help and exit
--id
The ID of the role to be deleted. Required unless "--name" is specified
--name
The name of the role to be deleted. Required unless "--id" is specified
role-list
role-list [options]
List user roles
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the role to list
--name
The name of the role to list
role-update
role-update [options]
Update an existing user role
role-update --name graham --acl "ANY:+c+r+u-d"
Available OBJECT_TYPEs include ANY,EVENT,NODE,DATA_MOVER,NETWORK_IF,SHARE,USER,USER_GROUP,ROLE,TASK,SMTP,NOTIFICATION_RULE,HEARTBEAT,NTP,LOGICAL_VOLUME,LDAP,CLUSTER,ELEMENTAL_OBJECTIVE,OBJECTIVE,SCHEDULE,SNAPSHOT_RETENTION,FILE_SNAPSHOT,OBJECT_STORAGE_VOLUME,CLOUD_MOVER,OBJECT_STORE_LOGICAL_VOLUME,SNMP,SW_UPDATE_TASK,CTDB,SHARE_SNAPSHOT,BACKUP,SAMBA_AD,DOMAIN_IDMAP,DATA_PORTAL,DNS,VOLUME_GROUP
Options
--acl
ACL, in the format: {OBJECT_TYPE}:{+{grant permissions}}{-{revoke permissions}}. Possible permissions: 'c'-create, 'r'-read, 'u'-update, 'd'-delete
--help
Display this help and exit
--id
The ID of the role to update. Required unless "--name" is specified
--idle-timeout
This role’s idle timeout for user interfaces (Web UI, CLI). May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed
--idle-timeout-clear
Disables this role’s idle timeout for user interfaces
--name
The name of the role to update. Required unless "--id" is specified
user-create
user-create [options]
Create a system user
Options
--data-access-role
Data access role(s) assigned to user. Required unless any of the following is specified: --mgmt-role-name, --mgmt-role-id Possible values: SMB | S3.
--email
The user’s email address
--first-name
The user’s first name
--gid
Group identifier
--help
Display this help and exit
--last-name
The user’s last name
--mgmt-role-id
The management role ID to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --mgmt-role-name, --data-access-role
--mgmt-role-name
The management role name to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --mgmt-role-id, --data-access-role
--password
The user’s password. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric. (Required)
--public-key
The user’s public encryption key
--uid
User identifier
--username
The username that will be used to identify the user in the system. Valid usernames contain the following characters: a-z, A-Z, 0-9, '-'. '_', '.', and can optionally end with a '$'. Valid usernames must start with a-z, A-Z, or '_'. (Required)
user-delete
user-delete [options]
Delete a system user
Options
--help
Display this help and exit
--id
The ID of the user to delete. Required unless "--name" is specified
--name
The name of the user to delete. Required unless "--id" is specified
user-import
user-import [options]
Imports users from CSV file
Example of a CSV file:
username,password,uid,gid,role,groups,public-key,first-name,last-name,email,data-access-roles
user1,P@ssword1,0,0,,"group1,group2",,John,Doe,john@example.com,"S3,SMB"
Options
--help
Display this help and exit
--uri
The URI for the CSV file containing users details. For example: file:/tmp/user.csv (Required)
user-list
user-list [options]
List all existing users
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the user to list
--name
The name of the user to list
user-password-update
user-password-update [options]
Update a user password
Options
--help
Display this help and exit
--id
The ID of the user whose password will be updated. Required unless "--name" is specified
--name
The name of the user whose password will be updated. Required unless "--id" is specified
--new-password
The new password. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric. (Required)
--old-password
The user’s old password
user-update
user-update [options]
Update the user’s properties, including the applied user role. If a new role is provided it overwrites the current user’s role
Options
--data-access-role-add
Add a data access role to the user. May be repeated. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id Possible values: SMB | S3.
--data-access-role-clear
Remove all data access roles. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--data-access-role-remove
Remove a data access role from the user. May be repeated. Required unless any of the following is specified: --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id Possible values: SMB | S3.
--disable
Disable the user. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--email
The user’s email address. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--enable
Enable the user. Required unless any of the following is specified: --data-access-role-remove, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--first-name
The user’s first name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --gid-clear, --mgmt-role-id
--first-name-clear
Clear the first name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--gid
Group identifier
--gid-clear
Clear the group identifier. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --mgmt-role-id
--help
Display this help and exit
--id
The ID that identifies the user in the system. Required unless "--name" is specified
--last-name
The user’s last name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--last-name-clear
Clear the last name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--mgmt-role-clear
Clear the management role. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--mgmt-role-id
The management role ID to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --mgmt-role-name, --last-name, --first-name, --gid-clear
--mgmt-role-name
The management role name to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --first-name, --gid-clear, --mgmt-role-id
--name
The username that identifies the user in the system. Required unless "--id" is specified
--password
Password to assign to user being updated. Required if adding SMB data access role. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric
--public-key
The user’s public encryption key. Required unless any of the following is specified: --data-access-role-remove, --enable, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--public-key-clear
Clear the public key. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id
--uid
User identifier
--uid-clear
Clear the user identifier. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id