Skip to content

SSH Access Control

SLURM users get different SSH treatment depending on which host they're hitting — these are three independent sshd_config policies for three different roles, not layers stacked on one node.

Host Policy Why
Compute/worker nodes Deny SSH to Compute Nodes — block the slurmUsers group entirely Users reach compute resources through SLURM (salloc/srun/sbatch), never by SSHing into a node directly
Login node Pubkey Exception for a Blocked User — disable pubkey auth for slurmUsers, with one named exception Pubkey auth bypasses LDAP shadowExpire — see Enforce Expiration Dates. Password auth must stay available here since it's the one host users log into interactively
NFS server Allow SFTP, Deny SSH — chroot slurmUsers into SFTP-only, no shell Users need to transfer files to/from their home directory, but have no business with an interactive shell on the storage server itself

All three edit /etc/ssh/sshd_config on their respective host and require sudo systemctl restart sshd (or reload) to take effect.

Deny SSH to Compute Nodes

On compute/worker nodes, deny interactive SSH entirely for SLURM users.

sudo nano /etc/ssh/sshd_config

Add (slurmUsers is the LDAP group name used for SLURM accounts):

DenyGroups slurmUsers

After making this change, restart the SSH service:

sudo systemctl restart sshd

Pubkey Exception for a Blocked User

On the login node.

Why

Pubkey authentication bypasses LDAP shadowExpire enforcement (see Enforce Expiration Dates) — a user with an expired LDAP account can still log in via key even though password auth would reject them. Blocking pubkey for slurmUsers closes that bypass, with slurm_majedalshaibani excepted.

Rule of Thumb

sshd uses first match wins per directive across Match blocks, not last. Put specific user exceptions before broad group/default rules.

Correct Configuration

Match User slurm_majedalshaibani
    PubkeyAuthentication yes

Match Group slurmUsers
    PubkeyAuthentication no

Verify

sudo sshd -t
sudo sshd -T -C user=slurm_majedalshaibani,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
sudo sshd -T -C user=<other_slurm_user>,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth

slurm_majedalshaibani → yes, other slurmUsers members → no.

Reload after confirming:

sudo systemctl reload sshd

Allow SFTP, Deny SSH

On the NFS server.

  • Make sure /raid_storage/SLURM/ is only accessible by root.
  • chmod 755 /raid_storage/SLURM/home — users can then traverse the home directory and only enter their own.

Edit the config:

sudo nano /etc/ssh/sshd_config

Add:

Match Group slurmUsers
    ChrootDirectory /raid_storage/SLURM/home
    ForceCommand internal-sftp
    AllowTcpForwarding no
    X11Forwarding no
    PermitTTY no