Details
-
Improvement
-
Resolution: Fixed
-
Minor
-
Lustre 2.14.0
-
9223372036854775807
Description
RHEL8 ships with restrictive firewalld rules out of the box. This prevents servers and clients from connecting to each other. Add a lustre.xml service file, so that it is possible to use something like "firewall-cmd --permanent --zone=public --service=lustre" to add the Lustre service ports with minimal difficulty.
It would be good if this was run automatically when the RPMs are installed, or when mount.lustre is run, but it isn't clear what is good/safe/correct in all cases. At least having the service file will be a starting point to make this easier for admins.
It would be even better if the Lustre service rules were restricted to accepting only new connections, and clients would only accept requests from the MGS initially and then dynamically add ports for servers as they are configured, but this is beyond my firewalld-fu.