VAST Cluster supports provider-based authentication when accessing cluster CNodes through SSH.
Users that are members of Active Directory or LDAP group(s) specified for the role will be able to log in to the VAST OS running on CNodes with the same permissions as the vastdata user.
Caution
Consider security implications before granting SSH access to the CNodes.
To take advantage of this feature:
Ensure that the cluster has joined Active Directory.
Associate an administrative role with one or more Active Directory or LDAP groups for which you want to provide SSH access to the CNodes.
In VAST Web UI, open role settings (Administrators -> Administrative Roles -> choose to create or edit a role) and enter the name of the Active Directory or LDAP group in the Active Directory/LDAP groups field. You can supply multiple groups if needed.
Configure the role to enable SSH access for to CNodes using Active Directory or LDAP groups:
In VAST Web UI, toggle the role's Enable OS SSH Login option on (Administrators -> Administrative Roles -> choose to create or edit a role).
Verify that the role create or update task has completed successfully (in the Activities page of VAST Web UI).
The following requirements and limitations apply:
This feature requires that all CNodes are running VAST OS version 12.15.55-2529260 or later.
This feature is not available on DNodes or ENodes.