Eyeglass and PowerScale Compliance Mode
Introduction
When Compliance Mode is enabled on a PowerScale cluster, it prevents users from modifying or deleting files for compliance purposes. This page covers the changes required to manage a compliance mode cluster with Eyeglass: registering the cluster with the compadmin account, preparing SmartLock compliance directories on both clusters, and the SyncIQ limitations that apply to them.
Register the Cluster with the compadmin Account
Follow the Installation Guide up to the Add Clusters section. When you add each PowerScale cluster to Eyeglass, use the compadmin user account to register it.
A cluster with compliance mode active does not allow files owned by root to be modified. In a regular installation, Eyeglass registers the cluster with the eyeglass service account, which needs only minimum privileges, and the sudoers file is edited to add that account. In compliance mode the sudoers file cannot be edited to add the eyeglass account, so the compadmin user is required to register the cluster.
SmartLock Directory Types
PowerScale supports two types of SmartLock directories:
- Enterprise: protects files without restricting the cluster with the SEC 17a-4 regulation rule.
- Compliance: protects files with the SEC 17a-4 regulation rule, and deletion is not available.
This page focuses on compliance directories.
Requirements for SyncIQ Replication
Meet the following requirements before you create a SyncIQ policy for a compliance directory:
- Create the SmartLock compliance directory on the target cluster before the SyncIQ policy runs. If the compliance directory does not exist on the target, the replication job fails.
- SmartLock directory settings are not replicated. If you change a setting on the source, make the same change on the target.
- Configure the SyncIQ policy and the SmartLock compliance directory at the same root directory level. A SmartLock compliance directory cannot be nested inside a SyncIQ policy.
Set the Compliance Clock
The compliance clock must be configured before you create SmartLock compliance directories. Follow Dell best practices when enabling compliance mode, and configure NTP on all nodes of the source and target clusters so that all node clocks stay synchronized.
-
Start an SSH session to the PowerScale cluster and log in with the
compadminuser account. -
Set the compliance clock:
isi worm cdate set -
Confirm that the compliance clock is running:
isi worm cdate view
Create a SmartLock Compliance Directory
After you create a SmartLock directory, you can commit files in that directory to the WORM (write once, read many) state. Create the directory on the source cluster and, before the first replication, on the target cluster.
To create a directory in the OneFS web administration interface, go to File System > SmartLock > WORM, select Create Domain, set the type to Compliance, and enter the directory path. You can also define the default retention period, the minimum and maximum retention periods, and an autocommit time period.
To create a directory from the CLI:
-
Open an SSH connection to any node in the cluster and log in.
-
Run the
isi worm domains createcommand. The following example creates a compliance directory with a default retention period of 5 years, a minimum retention period of 4 years, a maximum retention period of 6 years, and an autocommit time period of 30 minutes:isi worm domains create /ifs/compliance/dir1 --type compliance --default-retention 5Y --min-retention 4Y --max-retention 6Y --autocommit-offset 30m
View SmartLock Directory Settings
-
Open an SSH connection to any node in the cluster and log in.
-
List the SmartLock directories:
isi worm domains list -
View the details of a single SmartLock directory:
isi worm domains view <domain-directory>
View the WORM Status of a File
-
Start an SSH session to the PowerScale cluster and log in.
-
Check the WORM status of the file:
isi worm files view <file>
Failover and Failback
Follow the Failover Guide that matches your environment and failover type. Before you run a failover or failback, review the Failover Planning guidance.
Failover and failback operations that run with the compadmin account have known restrictions on system permissions and privileges. Contact Superna Support if a failover or failback step fails on a compliance mode cluster.