From 3d2ef02c98eba7875211e211f215845774fdceb2 Mon Sep 17 00:00:00 2001 From: Fabio Scotto di Santolo Date: Wed, 30 Sep 2026 21:20:15 +0200 Subject: [PATCH] Keep Atlas SMB and NFS namespaces separate --- AGENTS.md | 6 +++--- docs/atlas-sharing-decision.md | 20 ++++++++++++++++++++ 2 files changed, 23 insertions(+), 3 deletions(-) create mode 100644 docs/atlas-sharing-decision.md diff --git a/AGENTS.md b/AGENTS.md index 9adc333..d5a4929 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -250,9 +250,9 @@ successfully. The first monthly scrub remains a runtime check. - [ ] Add the Atlas-initiated least-privilege Prometheus backup pull: Prometheus exposes only prepared read-only dumps through a dedicated account and Atlas retains the private SSH key, pinned host key, atomic pull, verification, retention and systemd service/timer. -- [ ] Decide whether a common SMB/NFS namespace is required. `Archive` (SMB) and `photobook` (NFS) are - intentionally distinct today; only if a shared namespace is selected, finalize its UID/GID, group, - and POSIX ACL model and test the same files through both protocols. +- [x] Decide whether a common SMB/NFS namespace is required: no. `Archive` (SMB) and `photobook` (NFS) + remain intentionally distinct; `docs/atlas-sharing-decision.md` records the decision. No ACL or export + change is authorized by this decision. ### Priority 3 - Service expansion - [ ] After data protection and recovery are validated, populate `/zpool/media/music` and validate Navidrome. diff --git a/docs/atlas-sharing-decision.md b/docs/atlas-sharing-decision.md new file mode 100644 index 0000000..81bb9ea --- /dev/null +++ b/docs/atlas-sharing-decision.md @@ -0,0 +1,20 @@ +# Atlas SMB/NFS namespace decision + +Decision date: 2026-09-30. Keep the current namespaces **separate**. + +- `/zpool/archive` is the SMB3 `Archive` share for authorized Samba accounts. +- `/zpool/media/photobook` is the Aegis-only NFSv4 export, `all_squash`-mapped + to UID/GID `1100`. +- No new dual-protocol namespace, broad export, group, or ACL model is needed. + Existing permissions and client access remain unchanged. + +The two paths serve different ownership and exposure needs. A common namespace +would expand the permissions design and require same-file SMB/NFS interoperability +testing without a present requirement. Revisit only when a specific workflow +needs both protocols on the same files; then decide UID/GID, group, POSIX ACL, +SELinux policy and client behavior before changing exports or permissions. + +Read-only Atlas verification on 2026-09-30 confirmed that Samba `Archive` points +to `/zpool/archive`, NFS exports `/zpool/media/photobook` only to +`192.168.178.54` with `all_squash` and anonymous UID/GID `1100`, both datasets +are distinct, and `zpool` is healthy. No sharing configuration was changed.