mirror of
https://github.com/fscotto/infra.git
synced 2026-10-03 13:29:58 +00:00
Keep Atlas SMB and NFS namespaces separate
This commit is contained in:
@@ -250,9 +250,9 @@ successfully. The first monthly scrub remains a runtime check.
|
||||
- [ ] Add the Atlas-initiated least-privilege Prometheus backup pull: Prometheus exposes only prepared
|
||||
read-only dumps through a dedicated account and Atlas retains the private SSH key, pinned host key,
|
||||
atomic pull, verification, retention and systemd service/timer.
|
||||
- [ ] Decide whether a common SMB/NFS namespace is required. `Archive` (SMB) and `photobook` (NFS) are
|
||||
intentionally distinct today; only if a shared namespace is selected, finalize its UID/GID, group,
|
||||
and POSIX ACL model and test the same files through both protocols.
|
||||
- [x] Decide whether a common SMB/NFS namespace is required: no. `Archive` (SMB) and `photobook` (NFS)
|
||||
remain intentionally distinct; `docs/atlas-sharing-decision.md` records the decision. No ACL or export
|
||||
change is authorized by this decision.
|
||||
|
||||
### Priority 3 - Service expansion
|
||||
- [ ] After data protection and recovery are validated, populate `/zpool/media/music` and validate Navidrome.
|
||||
|
||||
20
docs/atlas-sharing-decision.md
Normal file
20
docs/atlas-sharing-decision.md
Normal file
@@ -0,0 +1,20 @@
|
||||
# Atlas SMB/NFS namespace decision
|
||||
|
||||
Decision date: 2026-09-30. Keep the current namespaces **separate**.
|
||||
|
||||
- `/zpool/archive` is the SMB3 `Archive` share for authorized Samba accounts.
|
||||
- `/zpool/media/photobook` is the Aegis-only NFSv4 export, `all_squash`-mapped
|
||||
to UID/GID `1100`.
|
||||
- No new dual-protocol namespace, broad export, group, or ACL model is needed.
|
||||
Existing permissions and client access remain unchanged.
|
||||
|
||||
The two paths serve different ownership and exposure needs. A common namespace
|
||||
would expand the permissions design and require same-file SMB/NFS interoperability
|
||||
testing without a present requirement. Revisit only when a specific workflow
|
||||
needs both protocols on the same files; then decide UID/GID, group, POSIX ACL,
|
||||
SELinux policy and client behavior before changing exports or permissions.
|
||||
|
||||
Read-only Atlas verification on 2026-09-30 confirmed that Samba `Archive` points
|
||||
to `/zpool/archive`, NFS exports `/zpool/media/photobook` only to
|
||||
`192.168.178.54` with `all_squash` and anonymous UID/GID `1100`, both datasets
|
||||
are distinct, and `zpool` is healthy. No sharing configuration was changed.
|
||||
Reference in New Issue
Block a user