NFSv4 ACLs: Difference between revisions
Jump to navigation
Jump to search
(Add categories: Server, Reference) |
(Template migration to LLM-Optimized Wiki Template) |
||
| Line 1: | Line 1: | ||
{{Status | |||
|status=Draft | |||
|owner=Knowledge Agent | |||
|last_update=2026-07-16 | |||
|review=Pending | |||
}} | |||
{{TOC}} | |||
== Overview == | |||
NFSv4 ACLs에 대한 기술 문서입니다. | |||
=== Summary === | |||
* 무엇인가? - NFSv4 ACLs | |||
* 왜 필요한가? - HPC 및 서버 환경에서 필수 개념 | |||
* 언제 사용하는가? - 서버 구성, 성능 튜닝, 문제 해결 시 | |||
--- | |||
== Purpose == | |||
이 문서가 존재하는 이유 | |||
* Goal: NFSv4 ACLs에 대한 기술 정보 제공 | |||
* Scope: NFSv4 ACLs의 개념, 사용법, 설정 | |||
* Non-goals: 다른 주제로의 확장 | |||
--- | |||
== Key Concepts == | |||
{| class="wikitable" | |||
! Concept | |||
! Description | |||
! Related | |||
|- | |||
| NFSv4 ACLs | |||
| HPC/서버 환경에서 중요한 기술 개념 | |||
| [[Linux]], [[Server]] | |||
|} | |||
--- | |||
== Detailed Explanation == | |||
NFSv4 ACLs (Access Control Lists) are mechanism to manipulate access controls on network-mounted filesystems to supplement traditional Unix permissions.<ref>https://www.osc.edu/book/export/html/4523</ref> | NFSv4 ACLs (Access Control Lists) are mechanism to manipulate access controls on network-mounted filesystems to supplement traditional Unix permissions.<ref>https://www.osc.edu/book/export/html/4523</ref> | ||
{| class="wikitable" | {| class="wikitable" | ||
|+ | |+ | ||
| Line 11: | Line 56: | ||
* <code>-x</code> – to '''remove''' the specified control. Note that this needs to match the rule ''exactly''. Usually, to remove a control, it is easier to invoke <code>nfs4_setfacl</code> with the <code>-e</code>switch, or to use <code>nfs4_getfacl</code>, then copy/paste the line you'd like to remove. | * <code>-x</code> – to '''remove''' the specified control. Note that this needs to match the rule ''exactly''. Usually, to remove a control, it is easier to invoke <code>nfs4_setfacl</code> with the <code>-e</code>switch, or to use <code>nfs4_getfacl</code>, then copy/paste the line you'd like to remove. | ||
* <code>-e</code> – This switch, instead of directly modifying the <abbr>ACL</abbr>, puts you into a file editor with the <abbr>ACL</abbr>, so that you can add/remove/modify all the entries at once. Note that it puts you into whichever editor is specified in your ''EDITOR'' environment variable (run <code>echo $EDITOR</code> to see what yours is set to), or <code>vi</code> if none is specified. (See [[Ubuntu tips and tricks#Set default text editor|how to change system default editor on Ubuntu]]) | * <code>-e</code> – This switch, instead of directly modifying the <abbr>ACL</abbr>, puts you into a file editor with the <abbr>ACL</abbr>, so that you can add/remove/modify all the entries at once. Note that it puts you into whichever editor is specified in your ''EDITOR'' environment variable (run <code>echo $EDITOR</code> to see what yours is set to), or <code>vi</code> if none is specified. (See [[Ubuntu tips and tricks#Set default text editor|how to change system default editor on Ubuntu]]) | ||
<u>This option is also being used for [[troubleshooting]] incorrect ACLs Fixing permissions that have gotten out-of-whack</u> | <u>This option is also being used for [[troubleshooting]] incorrect ACLs Fixing permissions that have gotten out-of-whack</u> | ||
* <code>–test</code> – This switch tells <code>nfs4_setfacl</code> to not actually modify the <abbr>ACL</abbr>, but print out what it would be once it applied the operation you specified. | * <code>–test</code> – This switch tells <code>nfs4_setfacl</code> to not actually modify the <abbr>ACL</abbr>, but print out what it would be once it applied the operation you specified. | ||
|- | |- | ||
| Line 20: | Line 63: | ||
| | | | ||
|} | |} | ||
ACE structure format, | ACE structure format, | ||
<big>[access type]:[flags]:[principal]:[permissions]</big> | <big>[access type]:[flags]:[principal]:[permissions]</big> | ||
Where, | |||
--- | |||
== Best Practices == | |||
* 최신 버전 사용 권장 | |||
* 공식 문서 참고 | |||
* 테스트 환경에서 먼저 검증 | |||
--- | |||
== References == | |||
=== | |||
* [https://wiki.hpcmate.com NFSv4 ACLs] | |||
--- | |||
== Related Pages == | |||
* [[Linux]] | |||
* [[Server]] | |||
* [[Hardware]] | |||
* [[Network]] | |||
--- | |||
[[Category: | [[Category:Linux]] | ||
[[Category:Configuration]] | |||
Revision as of 15:17, 16 July 2026
Overview
NFSv4 ACLs에 대한 기술 문서입니다.
Summary
- 무엇인가? - NFSv4 ACLs
- 왜 필요한가? - HPC 및 서버 환경에서 필수 개념
- 언제 사용하는가? - 서버 구성, 성능 튜닝, 문제 해결 시
---
Purpose
이 문서가 존재하는 이유
- Goal: NFSv4 ACLs에 대한 기술 정보 제공
- Scope: NFSv4 ACLs의 개념, 사용법, 설정
- Non-goals: 다른 주제로의 확장
---
Key Concepts
| Concept | Description | Related |
|---|---|---|
| NFSv4 ACLs | HPC/서버 환경에서 중요한 기술 개념 | Linux, Server |
---
Detailed Explanation
NFSv4 ACLs (Access Control Lists) are mechanism to manipulate access controls on network-mounted filesystems to supplement traditional Unix permissions.[1]
nfs4_setfacl
|
to add, remove, or modify the ACL |
This option is also being used for troubleshooting incorrect ACLs Fixing permissions that have gotten out-of-whack
|
nfs4_getfacl
|
prints out the ACL of the file or directory |
ACE structure format, [access type]:[flags]:[principal]:[permissions] Where,
---
Best Practices
- 최신 버전 사용 권장
- 공식 문서 참고
- 테스트 환경에서 먼저 검증
---
References
---
Related Pages
---