NFSv4 ACLs

From HPCWIKI
Revision as of 11:29, 17 July 2026 by Clara (talk | contribs) (Fix: remove --- horizontal lines (7 removed))
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Template:Status

Template:TOC

Overview

NFSv4 ACLs에 대한 기술 문서입니다.

Summary

  • 무엇인가? - NFSv4 ACLs
  • 왜 필요한가? - HPC 및 서버 환경에서 필수 개념
  • 언제 사용하는가? - 서버 구성, 성능 튜닝, 문제 해결 시


Purpose

이 문서가 존재하는 이유

  • Goal: NFSv4 ACLs에 대한 기술 정보 제공
  • Scope: NFSv4 ACLs의 개념, 사용법, 설정
  • Non-goals: 다른 주제로의 확장


Key Concepts

Concept Description Related
NFSv4 ACLs HPC/서버 환경에서 중요한 기술 개념 Linux, Server


Detailed Explanation

NFSv4 ACLs (Access Control Lists) are mechanism to manipulate access controls on network-mounted filesystems to supplement traditional Unix permissions.[1]

nfs4_setfacl to add, remove, or modify the ACL
  • -a – to add the specified Access Control Entry (ACE - defined below). Basically, this adds a new rule.
  • -x – to remove the specified control. Note that this needs to match the rule exactly. Usually, to remove a control, it is easier to invoke nfs4_setfacl with the -eswitch, or to use nfs4_getfacl, then copy/paste the line you'd like to remove.
  • -e – This switch, instead of directly modifying the ACL, puts you into a file editor with the ACL, so that you can add/remove/modify all the entries at once. Note that it puts you into whichever editor is specified in your EDITOR environment variable (run echo $EDITOR to see what yours is set to), or vi if none is specified. (See how to change system default editor on Ubuntu)

This option is also being used for troubleshooting incorrect ACLs Fixing permissions that have gotten out-of-whack

  • –test – This switch tells nfs4_setfacl to not actually modify the ACL, but print out what it would be once it applied the operation you specified.
nfs4_getfacl prints out the ACL of the file or directory

ACE structure format, [access type]:[flags]:[principal]:[permissions] Where,


Best Practices

  • 최신 버전 사용 권장
  • 공식 문서 참고
  • 테스트 환경에서 먼저 검증


References


Related Pages

Knowledge Graph

Related

NFSNetworkStorage