clush (cluster_admin Access)¶
Grants the controller's clush cluster_admin key access to this node — copied from clush, kept in sync there. Do this after the controller-side setup (key generation) is done.
Create cluster_admin User¶
SSH Key Directory¶
ssh jrcai_admin@jrcai23 'sudo mkdir -p /etc/ssh-keys/cluster_admin && sudo chmod 700 /etc/ssh-keys/cluster_admin && sudo chown cluster_admin:cluster_admin /etc/ssh-keys/cluster_admin'
Add sshd Match Block¶
ssh jrcai_admin@jrcai23 'echo -e "\nMatch User cluster_admin\n AuthorizedKeysFile /etc/ssh-keys/cluster_admin/authorized_keys" | sudo tee -a /etc/ssh/sshd_config && sudo sshd -t && sudo systemctl restart sshd'
(If the service is ssh not sshd, adjust the systemctl restart line.)
Distribute cluster_admin Public Key¶
Run this from the controller, where the key was generated:
KEY=$(sudo cat /root/.ssh/cluster_admin_key.pub)
ssh -t jrcai_admin@jrcai23 "echo 'from=\"10.22.154.100\" $KEY' | sudo tee /etc/ssh-keys/cluster_admin/authorized_keys && sudo chmod 600 /etc/ssh-keys/cluster_admin/authorized_keys && sudo chown cluster_admin:cluster_admin /etc/ssh-keys/cluster_admin/authorized_keys"
NOPASSWD Sudoers¶
ssh -t jrcai_admin@jrcai23 'echo "cluster_admin ALL=(ALL) NOPASSWD:ALL" | sudo tee /etc/sudoers.d/cluster_admin && sudo chmod 440 /etc/sudoers.d/cluster_admin'
Verify¶
From the controller: