Keep Atlas SMB and NFS namespaces separate

This commit is contained in:
Fabio Scotto di Santolo
2026-09-30 21:20:15 +02:00
parent 8844d00e24
commit 3d2ef02c98
2 changed files with 23 additions and 3 deletions

View File

@@ -250,9 +250,9 @@ successfully. The first monthly scrub remains a runtime check.
- [ ] Add the Atlas-initiated least-privilege Prometheus backup pull: Prometheus exposes only prepared - [ ] Add the Atlas-initiated least-privilege Prometheus backup pull: Prometheus exposes only prepared
read-only dumps through a dedicated account and Atlas retains the private SSH key, pinned host key, read-only dumps through a dedicated account and Atlas retains the private SSH key, pinned host key,
atomic pull, verification, retention and systemd service/timer. atomic pull, verification, retention and systemd service/timer.
- [ ] Decide whether a common SMB/NFS namespace is required. `Archive` (SMB) and `photobook` (NFS) are - [x] Decide whether a common SMB/NFS namespace is required: no. `Archive` (SMB) and `photobook` (NFS)
intentionally distinct today; only if a shared namespace is selected, finalize its UID/GID, group, remain intentionally distinct; `docs/atlas-sharing-decision.md` records the decision. No ACL or export
and POSIX ACL model and test the same files through both protocols. change is authorized by this decision.
### Priority 3 - Service expansion ### Priority 3 - Service expansion
- [ ] After data protection and recovery are validated, populate `/zpool/media/music` and validate Navidrome. - [ ] After data protection and recovery are validated, populate `/zpool/media/music` and validate Navidrome.

View File

@@ -0,0 +1,20 @@
# Atlas SMB/NFS namespace decision
Decision date: 2026-09-30. Keep the current namespaces **separate**.
- `/zpool/archive` is the SMB3 `Archive` share for authorized Samba accounts.
- `/zpool/media/photobook` is the Aegis-only NFSv4 export, `all_squash`-mapped
to UID/GID `1100`.
- No new dual-protocol namespace, broad export, group, or ACL model is needed.
Existing permissions and client access remain unchanged.
The two paths serve different ownership and exposure needs. A common namespace
would expand the permissions design and require same-file SMB/NFS interoperability
testing without a present requirement. Revisit only when a specific workflow
needs both protocols on the same files; then decide UID/GID, group, POSIX ACL,
SELinux policy and client behavior before changing exports or permissions.
Read-only Atlas verification on 2026-09-30 confirmed that Samba `Archive` points
to `/zpool/archive`, NFS exports `/zpool/media/photobook` only to
`192.168.178.54` with `all_squash` and anonymous UID/GID `1100`, both datasets
are distinct, and `zpool` is healthy. No sharing configuration was changed.