Skip to content

clush (cluster_admin Access)

Grants the controller's clush cluster_admin key access to this node — copied from clush, kept in sync there. Do this after the controller-side setup (key generation) is done.

Create cluster_admin User

ssh jrcai_admin@jrcai01 'sudo useradd -M -s /bin/bash cluster_admin'

SSH Key Directory

ssh jrcai_admin@jrcai01 'sudo mkdir -p /etc/ssh-keys/cluster_admin && sudo chmod 700 /etc/ssh-keys/cluster_admin && sudo chown cluster_admin:cluster_admin /etc/ssh-keys/cluster_admin'

Add sshd Match Block

ssh jrcai_admin@jrcai01 'echo -e "\nMatch User cluster_admin\n    AuthorizedKeysFile /etc/ssh-keys/cluster_admin/authorized_keys" | sudo tee -a /etc/ssh/sshd_config && sudo sshd -t && sudo systemctl restart sshd'

(If the service is ssh not sshd, adjust the systemctl restart line.)

Distribute cluster_admin Public Key

Run this from the controller, where the key was generated:

KEY=$(sudo cat /root/.ssh/cluster_admin_key.pub)
ssh -t jrcai_admin@jrcai01 "echo 'from=\"10.22.154.100\" $KEY' | sudo tee /etc/ssh-keys/cluster_admin/authorized_keys && sudo chmod 600 /etc/ssh-keys/cluster_admin/authorized_keys && sudo chown cluster_admin:cluster_admin /etc/ssh-keys/cluster_admin/authorized_keys"

NOPASSWD Sudoers

ssh -t jrcai_admin@jrcai01 'echo "cluster_admin ALL=(ALL) NOPASSWD:ALL" | sudo tee /etc/sudoers.d/cluster_admin && sudo chmod 440 /etc/sudoers.d/cluster_admin'

Verify

From the controller:

sudo clush -w jrcai01 -b 'whoami'
# Should return: cluster_admin

Info

Also add this node to the right group (e.g. RTX3090, A5000, A4500, A6000) in /etc/clustershell/groups.d/local.cfg on the controller — see Create Node Groups.