docs/pbs-deployment: Phase 0 — explicit handling of root_squash
Current NFS exports on the Debian NAS (10.250.50.50) use root_squash, which blocks PBS from writing its datastore metadata (chunks, locks, GC state — all root-owned operations). Rest-server-ana worked around this by running its container as UID 1000, but PBS's service model doesn't accommodate that pattern cleanly. Solution baked into Phase 0: create a dedicated NFS export for the PBS-ANA datastore subtree, scoped to only the PBS-ANA VM's IP, with no_root_squash. Bounded exposure (single client), kept in a separate .exports file so Cockpit's File Sharing module doesn't clobber it. Flag world-scoped export on /mnt/pve-VMStorage as a non-blocking hygiene item for a later Cockpit pass.
This commit is contained in:
@@ -15,27 +15,53 @@ stop after any phase without leaving the fleet in a bad state.
|
|||||||
|
|
||||||
## Phase 0 — Prerequisites (one-time, before Phase 1)
|
## Phase 0 — Prerequisites (one-time, before Phase 1)
|
||||||
|
|
||||||
Check once:
|
### 0.1. Check current NFS exports
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Debian NAS (10.250.50.50) is exporting to pfi-pve already for
|
ssh -t 10.250.50.50 'sudo exportfs -v'
|
||||||
# rest-server-ana's /mnt/backup. We need to add a sibling export for
|
|
||||||
# PBS-ANA's datastore. SSH to the NAS:
|
|
||||||
ssh ana-nas 'cat /etc/exports'
|
|
||||||
```
|
```
|
||||||
|
|
||||||
Make sure `/mnt/backup` export allows pfi-pve (10.250.250.31) to mount
|
The existing broad exports (e.g. `/mnt/backup` → `10.0.0.0/8`) cover
|
||||||
read-write. If it does (which it should, per the existing
|
pfi-pve but use `root_squash` — which will **block** PBS from writing
|
||||||
rest-server-ana setup), we're good.
|
its datastore metadata. We need a dedicated, no-squash export scoped
|
||||||
|
to the PBS-ANA VM's IP.
|
||||||
|
|
||||||
Decide up front:
|
### 0.2. Create a dedicated export for PBS-ANA
|
||||||
|
|
||||||
- **PBS-ANA datastore path:** recommend `/mnt/backup/pbs-ana/` (sibling
|
Assign PBS-ANA its LAN IP (let's say `10.250.50.90` — Phase 1.1 uses
|
||||||
to `/mnt/backup/restic/`). Create the dir on the NAS with the user
|
this), then on the Debian NAS:
|
||||||
that PBS will run as (root in the VM maps to root on NFS if
|
|
||||||
`no_root_squash` is set — matches the rest-server-ana pattern).
|
```bash
|
||||||
- **PBS-NH3 datastore path:** local-only on nh3-pve. Recommend a new
|
ssh -t 10.250.50.50 '
|
||||||
Proxmox dir storage on a data disk; `/mnt/pbs-nh3/datastore/`.
|
sudo mkdir -p /mnt/backup/pbs-ana &&
|
||||||
|
sudo chown root:root /mnt/backup/pbs-ana &&
|
||||||
|
sudo chmod 755 /mnt/backup/pbs-ana &&
|
||||||
|
|
||||||
|
echo "/mnt/backup/pbs-ana 10.250.50.90(rw,sync,no_root_squash,no_subtree_check,sec=sys)" \
|
||||||
|
| sudo tee /etc/exports.d/pbs-ana.exports > /dev/null &&
|
||||||
|
|
||||||
|
sudo exportfs -ra &&
|
||||||
|
sudo exportfs -v | grep pbs-ana
|
||||||
|
'
|
||||||
|
```
|
||||||
|
|
||||||
|
Should print an `/mnt/backup/pbs-ana` line with `no_root_squash`.
|
||||||
|
|
||||||
|
The existing `cockpit-file-sharing.exports` is managed by Cockpit's
|
||||||
|
File Sharing module; keep the PBS-specific export in a separate file
|
||||||
|
so Cockpit doesn't clobber it.
|
||||||
|
|
||||||
|
### 0.3. Decide datastore paths
|
||||||
|
|
||||||
|
- **PBS-ANA datastore path:** `/mnt/backup/pbs-ana/` on the NAS, mounted
|
||||||
|
at `/mnt/pbs-datastore/` inside the PBS-ANA VM (Phase 1.3).
|
||||||
|
- **PBS-NH3 datastore path:** local-only on nh3-pve, mounted at
|
||||||
|
`/mnt/pbs-datastore/` inside the PBS-NH3 VM (Phase 5.3).
|
||||||
|
|
||||||
|
### 0.4. Side-note: `/mnt/pve-VMStorage` is exported to `<world>`
|
||||||
|
|
||||||
|
Not blocking PBS work but worth tightening during a Cockpit pass —
|
||||||
|
reduce to `10.0.0.0/8` or more specific. Open item, not blocker.
|
||||||
|
|
||||||
## Phase 1 — Provision PBS-ANA (VM on pfi-pve)
|
## Phase 1 — Provision PBS-ANA (VM on pfi-pve)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user