SSH Access Control¶
SLURM users get different SSH treatment depending on which host they're hitting — these are three independent sshd_config policies for three different roles, not layers stacked on one node.
| Host | Policy | Why |
|---|---|---|
| Compute/worker nodes | Deny SSH to Compute Nodes — block the slurmUsers group entirely |
Users reach compute resources through SLURM (salloc/srun/sbatch), never by SSHing into a node directly |
| Login node | Pubkey Exception for a Blocked User — disable pubkey auth for slurmUsers, with one named exception |
Pubkey auth bypasses LDAP shadowExpire — see Enforce Expiration Dates. Password auth must stay available here since it's the one host users log into interactively |
| NFS server | Allow SFTP, Deny SSH — chroot slurmUsers into SFTP-only, no shell |
Users need to transfer files to/from their home directory, but have no business with an interactive shell on the storage server itself |
All three edit /etc/ssh/sshd_config on their respective host and require sudo systemctl restart sshd (or reload) to take effect.
Deny SSH to Compute Nodes¶
On compute/worker nodes, deny interactive SSH entirely for SLURM users.
Add (slurmUsers is the LDAP group name used for SLURM accounts):
After making this change, restart the SSH service:
Pubkey Exception for a Blocked User¶
On the login node.
Why¶
Pubkey authentication bypasses LDAP shadowExpire enforcement (see Enforce Expiration Dates) — a user with an expired LDAP account can still log in via key even though password auth would reject them. Blocking pubkey for slurmUsers closes that bypass, with slurm_majedalshaibani excepted.
Rule of Thumb¶
sshd uses first match wins per directive across Match blocks, not last. Put specific user exceptions before broad group/default rules.
Correct Configuration¶
Match User slurm_majedalshaibani
PubkeyAuthentication yes
Match Group slurmUsers
PubkeyAuthentication no
Verify¶
sudo sshd -t
sudo sshd -T -C user=slurm_majedalshaibani,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
sudo sshd -T -C user=<other_slurm_user>,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
slurm_majedalshaibani → yes, other slurmUsers members → no.
Reload after confirming:
Allow SFTP, Deny SSH¶
On the NFS server.
- Make sure
/raid_storage/SLURM/is only accessible by root. chmod 755 /raid_storage/SLURM/home— users can then traverse the home directory and only enter their own.
Edit the config:
Add: