Creating a Restricted Administrator for ONTAP Cluster Mode
Adding an ONTAP cluster to Hammerspace requires an administrator account. The default cluster admin account works, but grants far more privilege than Hammerspace uses. This section creates a restricted account with read-only access to only the management APIs Hammerspace needs, plus write access to the two clone APIs required for offloaded cloning.
Verified against ONTAP 9.14.1 and 9.17.1 with Hammerspace 5.2.14.
Before You Begin
Two constraints determine how the account must be built.
The account must be cluster-scoped. Hammerspace calls system node show, storage aggregate show, and system license show, which exist only at cluster scope. Do not pass -vserver to security login create. Creating a role with -vserver produces a separate SVM-scoped role that a cluster-scoped account never consults, so such entries have no effect.
The account needs three applications. Hammerspace uses the ONTAP REST API for discovery, but offloaded cloning runs over the legacy ONTAPI (ZAPI) system-cli call, which opens a CLI session. The account therefore requires http, ontapi, and console. Omitting console makes cloning fail silently — see Offloaded Cloning Requires the console Application.
Log in to the cluster as a cluster administrator, and use the cluster management LIF address throughout.
Create the Role
Deny everything by default, then grant back only what Hammerspace needs.
security login role create -role hammerspace -access none -cmddirname DEFAULT
security login role create -role hammerspace -access readonly -cmddirname "vserver show"
security login role create -role hammerspace -access readonly -cmddirname "volume show"
security login role create -role hammerspace -access readonly -cmddirname "volume qtree show"
security login role create -role hammerspace -access readonly -cmddirname "network interface show"
security login role create -role hammerspace -access readonly -cmddirname "system node show"
security login role create -role hammerspace -access readonly -cmddirname "storage aggregate show"
security login role create -role hammerspace -access readonly -cmddirname "system license show"
security login role create -role hammerspace -access readonly -cmddirname "version"
security login role create -role hammerspace -access readonly -cmddirname "cluster identity show"
security login role create -role hammerspace -access all -cmddirname "volume file clone"
security login role create -role hammerspace -access all -cmddirname "system node run"
|
These commands produce warnings that additional commands are also being affected, for example |
Equivalent REST call, which returns HTTP 201:
curl -sk -u admin -X POST "https://<cluster-mgmt-ip>/api/security/roles" \
-H 'Content-Type: application/json' -d '{
"name": "hammerspace",
"owner": {"name": "<cluster-name>"},
"privileges": [
{"path": "DEFAULT", "access": "none"},
{"path": "vserver show", "access": "readonly"},
{"path": "volume show", "access": "readonly"},
{"path": "volume qtree show", "access": "readonly"},
{"path": "network interface show", "access": "readonly"},
{"path": "system node show", "access": "readonly"},
{"path": "storage aggregate show", "access": "readonly"},
{"path": "system license show", "access": "readonly"},
{"path": "version", "access": "readonly"},
{"path": "cluster identity show", "access": "readonly"},
{"path": "volume file clone", "access": "all"},
{"path": "system node run", "access": "all"}
]}'
Verify the role:
security login role show -role hammerspace
Create the User
security login create -user-or-group-name hsadmin -application http -authentication-method password -role hammerspace
security login create -user-or-group-name hsadmin -application ontapi -authentication-method password -role hammerspace
security login create -user-or-group-name hsadmin -application console -authentication-method password -role hammerspace
Enter a password when prompted. The CLI reads the password from the terminal and cannot be scripted; use the REST equivalent for automation:
curl -sk -u admin -X POST "https://<cluster-mgmt-ip>/api/security/accounts" \
-H 'Content-Type: application/json' -d '{
"name": "hsadmin",
"password": "<password>",
"role": {"name": "hammerspace"},
"applications": [
{"application": "http", "authentication_methods": ["password"]},
{"application": "ontapi", "authentication_methods": ["password"]},
{"application": "console", "authentication_methods": ["password"]}
]}'
Verify. The Vserver column must show the cluster name, not an SVM:
security login show -user-or-group-name hsadmin
Web Service Access
On ONTAP 9.11 and later, creating the role automatically binds it to the rest, ontapi, security, and sysmgr web services. No further action is required. Confirm with:
vserver services web access show -role hammerspace
On releases earlier than 9.11, bind the role manually:
vserver services web access create -vserver <cluster-name> -name rest -role hammerspace
vserver services web access create -vserver <cluster-name> -name ontapi -role hammerspace
Privilege Reference
| Command Directory | Access | Required For |
|---|---|---|
|
|
Deny-by-default baseline |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
ONTAPI |
The following are not required and may be omitted: cluster show, system node autosupport show, and security login role show-ontapi.
Verified against ONTAP 9.14.1 and 9.17.1. Note that ONTAP returns 200 with a field silently omitted when the role lacks the privilege behind that field, so verification must check response content, not just status codes.
Offloaded Cloning Requires the console Application
Offloaded cloning is performed by the ONTAPI system-cli call, which opens a CLI session to run volume file clone start. ONTAP authorizes that session against the account’s console application, independently of its role.
|
An account without |
Confirm with:
security login show -user-or-group-name hsadmin
console, http, and ontapi must all be listed.
Security Considerations
system node run -access all is required for offloaded cloning and cannot be narrowed — readonly is insufficient, because the ONTAPI system-cli call is classified as a write operation even when the command it carries is a read.
This privilege permits the account to open an ONTAP clustershell session and run commands there. Each command is still authorized individually against the role, so the account cannot exceed its other privileges — but this is real clustershell access, not a restricted nodeshell, and the account should be treated as more than read-only and its password protected accordingly.
system node run alone is not sufficient for cloning: without the console application the session cannot be opened at all, and the failure is silent (see above).
If site policy prohibits this privilege, omit both system node run and volume file clone. Discovery, volume add, read-write data access, and assimilation all continue to work; only offloaded cloning is unavailable, and clone operations fall back to host-side copy.