58424fccc7
- Split ObjectScale into UI, S3 API, and SSH tiles on OPS tab - Add docs/objectscale.md explaining 0.0.0.0/0 and lab ports - Dedicated Object Storage row in homepage layout
58 lines
2.0 KiB
Markdown
58 lines
2.0 KiB
Markdown
# Dell ObjectScale (ECS) — atc-objectscale
|
||
|
||
| Item | Value |
|
||
|------|-------|
|
||
| Hostname | `luna.local` / `atc-objectscale` |
|
||
| IP | `10.0.20.111` |
|
||
| SSH | `admin@10.0.20.111` (appliance; root via sudo keys) |
|
||
| Management UI | https://10.0.20.111/ (port **443**) |
|
||
| S3 API | http://10.0.20.111:**9020** |
|
||
| Container | `ecs-storageos` (`emccorp/ecs-software`) |
|
||
| Install config | `/opt/emc/ecs-install/deploy.yml` |
|
||
|
||
## What is `management_clients: 0.0.0.0/0`?
|
||
|
||
In `deploy.yml`, this setting controls **which client IP addresses may access ECS management ports** (admin API, node management, not the S3 data path).
|
||
|
||
| Value | Meaning |
|
||
|-------|---------|
|
||
| `0.0.0.0/0` | **Everyone on any network** — entire Internet can reach management ports if routed/firewall allows |
|
||
| `10.0.20.0/24` | Only hosts in `10.0.20.x` subnet |
|
||
| `10.0.21.45` | Only that single host |
|
||
|
||
**Lab default:** installer often sets `0.0.0.0/0` for convenience (= no IP whitelist).
|
||
**Production:** restrict to management subnet only, e.g.:
|
||
|
||
```yaml
|
||
management_clients:
|
||
- 10.0.10.0/24 # Proxmox / mgmt
|
||
- 10.0.20.0/24 # storage VLAN
|
||
- 10.0.21.0/24 # compute VLAN
|
||
```
|
||
|
||
Changing this requires editing `/opt/emc/ecs-install/deploy.yml` on the appliance and may need an ECS config apply — plan a maintenance window.
|
||
|
||
## S3 usage in this lab
|
||
|
||
| Consumer | Bucket / path | Config |
|
||
|----------|---------------|--------|
|
||
| Trino Iceberg | via `iceberg.properties` | `hive.s3.endpoint=http://10.0.20.111:9020` |
|
||
| Spark jobs | bucket `data` | `/opt/spark-jobs/*.py` on lake01 |
|
||
| AWS CLI | `aws --endpoint-url http://10.0.20.111:9020` | keys in Trino catalog (redacted in git) |
|
||
|
||
## Ports (reference)
|
||
|
||
| Port | Service |
|
||
|------|---------|
|
||
| 443 | ECS Management UI (HTTPS) |
|
||
| 9020 | S3 API |
|
||
| 4443 | ECS API (nginx) |
|
||
| 9021–9025 | Data head services (internal) |
|
||
|
||
## Health check
|
||
|
||
```bash
|
||
curl -sk -o /dev/null -w "%{http_code}\n" https://10.0.20.111/ # expect 200
|
||
curl -s -o /dev/null -w "%{http_code}\n" http://10.0.20.111:9020/ # expect 403 without auth (normal)
|
||
```
|