1.5 Users, roles and access
Where BCM keeps users, how to add one so they can log in, and where to manage them.
Key points
LDAP is a directory service that stores user accounts centrally. BCM runs one on the head nodes, so a user added once works across the cluster. You can also connect an external LDAP server.
What NVIDIA says (2)
“Out of the box, BCM runs its own LDAP service to help manage users and groups.”
“This centralized LDAP service runs on the head nodes of the BCM managed cluster.”
cmsh holds changes locally until you commit them. Users without a password also cannot log in.
What NVIDIA says (2)
“Whenever any changes are made using cmsh , it is important to remember to commit them or else they will not go into effect.”
“Users with unset passwords cannot log in.”
Base View groups user and group management under Identity Management. cmsh and Base View give the same results. One is a CLI, the other a GUI.
What NVIDIA says (2)
“Within Base View, follow the navigation path Identity-Management > Users to manage users.”
“Using cmsh or Base View to manage users and groups will provide the same results.”
Key terms
- Base View: The BCM web interface for monitoring and managing the cluster in a browser.
- cmsh: The BCM cluster management shell, a command line with modes such as device, category and user; changes take effect on commit.
- LDAP: Lightweight Directory Access Protocol: the directory service BCM runs on its head nodes to store users and groups.
Sample question
Out of the box, where does BCM keep cluster users and groups?
Show the answer
Answer: In its own LDAP service on the head nodes
LDAP is a directory service that stores user accounts centrally. BCM runs one on the head nodes, so a user added once works across the cluster. You can also connect an external LDAP server.
What NVIDIA says (2)
“Out of the box, BCM runs its own LDAP service to help manage users and groups.”
“This centralized LDAP service runs on the head nodes of the BCM managed cluster.”
Practice 1.5 (3 questions) Full Installation and Deployment guide
← 1.4 Patches, firmware and image sync · 1.6 Node, DPU and switch networking →