data:image/s3,"s3://crabby-images/da7b0/da7b08400d8fc9efedeb6fa7159108818d3244f4" alt="Cray Urika-GX Administration Manual Download Page 206"
●
ux-tenant-add-user
- add specified users to the authorized user list and to tenant membership.
●
ux-tenant-relax
- change user access to relaxed for specified users.
●
ux-tenant-restrict
- change user access to restricted for specified users.
●
ux-tenant-list-users
- produce a list of users and their attributes in the authorized user list.
●
ux-tenant-remove-user
- remove a user from tenant membership or from the authorized user list.
●
usm-sync-users
- enable Urika-GX to discover new users (that have been added via site-specific
procedures) and create Mesos and Kerberos credentials for them. This command also removes secrets of
user accounts that are no longer authorized.
●
usm-recreate-secret
- assign a new set of Mesos and Kerberos credentials to a user.
The
ux-tenant-add-user
command is used both to add users to the authorized user list and to assign users
tenant membership within the authorized user list. For more details on command line options and arguments, see
the
ux-tenant-add-user
man page.
The following examples show how to manage the authorized user list.
Add a User to the Authorized User List
Use the
ux-tenant-add-user
command to add a user to the authorized list of users.
#
ux-tenant-add-user -u bob
In this example,
bob
is added to the authorized user list, but is not assigned tenant membership,
which would permit him from logging on to a tenant VM. By default,
bob
is added to the list as a
restricted access user, so he cannot log on to Urika-GX.
For more information, refer to the
ux-tenant-add-user
man page.
Add User to a Tenant VM
Add a user to a tenant using the
ux-tenant-add-user
command, specifying a tenant VM:
#
ux-tenant-add-user -u bob mytenant
At this point,
bob
will be allowed to log into the tenant VM named
mytenant
.
For more information, refer to the
ux-tenant-add-user
man page.
Assign Relaxed Access to a User
Assign relaxed access to a user or list of users using the
ux-tenant-relax
command. The
following shows an administrator assigning the relaxed access mode to
bob
:
#
ux-tenant-relax -s /bin/bash bob
Note that relaxed or restricted access is based on the setting of the
crayLoginShell
attribute
in the authorized user list. This attribute determines what shell will be provided for
bob
when he
logs into a physical node (if he logs into a tenant VM he will use his normal Linux login shell). The
above command explicitly sets the
crayLoginShell
attribute for
bob
to
/bin/bash
, which is
Security
S3016
206