Lustre driver¶
The Lustre driver creates shares as sub-directories on a pre-provisioned Lustre parallel filesystem. Capacity is enforced with project quotas and access control uses nodemaps for IP-based client isolation.
The driver operates in DHSS=False mode only (the Lustre filesystem must be provisioned and mounted before Manila starts).
Prerequisites¶
Lustre >= 2.16 (required for RBAC nodemaps and
root_prj_enable).A mounted Lustre client on the manila-share host.
Project quotas enabled on all MDTs and OSTs.
Nodemap feature activated on the MGS.
lfsandlctlutilities available on the manila-share host.
For details on installing and configuring a Lustre filesystem, see the Lustre Operations Manual.
Supported operations¶
The driver supports the LUSTRE protocol with IP access rules.
Create and delete a share
Extend and shrink a share
Allow and deny share access (IP type, RW and RO)
Manage and unmanage an existing share
Restrictions¶
Only
ipaccess type is supported.Snapshots are not supported (Lustre does not have filesystem-level snapshots).
Share groups and replication are not supported.
IPv6 access rules are not currently supported.
Back-end configuration¶
Add LUSTRE to the enabled share protocols:
[DEFAULT]
enabled_share_protocols = LUSTRE
Create a backend section in manila.conf:
[lustre1]
share_driver = manila.share.drivers.lustre.driver.LustreShareDriver
driver_handles_share_servers = False
share_backend_name = LUSTRE1
lustre_share_export_ip = 10.0.0.5
lustre_mount_point = /mnt/lustre
lustre_fs_name = lustrefs
Add the backend to enabled_share_backends:
[DEFAULT]
enabled_share_backends = lustre1
When the MGS or MDS is on a different host, configure SSH access:
[lustre1]
lustre_mgs_ip = 10.0.0.10
lustre_mds_ip = 10.0.0.11
lustre_ssh_username = root
lustre_ssh_private_key_path = /etc/manila/lustre_ssh_key
When both MGS and MDS run on the manila-share host, omit
lustre_mgs_ip and lustre_mds_ip and the driver will use
oslo.privsep for privileged operations.
Project ID range¶
Each share is assigned a unique Lustre project ID for quota
enforcement. The range is controlled by lustre_project_id_start
(default 10000) and lustre_project_id_end (default 60000).
Ensure this range does not overlap with project IDs used by other
applications on the same filesystem.
Access control¶
The driver creates a Lustre nodemap per access rule, mapping the
client IP (or CIDR) to the share’s sub-directory. Read-only rules
set readonly_mount=1 on the nodemap. Nodemaps persist on the
MGS across reboots.
See Lustre Nodemap documentation for background on how nodemaps enforce client identity and permissions.
Driver options¶
All configuration options for the Lustre driver are documented in the Configuration Reference.