I once encountered an interesting NFS permissions issue on NetApp ONTAP.
Users belonged to the required UNIX group, and their membership was present in LDAP. Yet they could not access the directories or perform the expected operations.
The important clue appeared when we checked the user’s resolved identity on ONTAP: the expected supplementary GID was missing.
The directory contained the membership, but ONTAP’s view did not reflect it.
Refreshing the relevant cached information allowed the missing group to appear and restored access.
Check the identity before changing permissions
The user’s UID.
Their primary GID.
Their supplementary GIDs, which may grant access through additional groups.
Group membership is part of the user’s identity. File and directory ownership is a separate check.
Check the cached NFS credentials
Enter advanced privilege mode and inspect the affected user’s NFS credentials on the relevant serving node:
set -privilege advanced
vserver nfs credentials show -node node* -vserver svm -unix-user-name userRefresh stale NFS credentials
If fresh name-service lookups return the correct groups but the NFS credentials remain stale, flush the affected user’s NFS credentials on the relevant node:
set -privilege advanced
vserver nfs credentials flush -node node* -vserver svm -unix-user-name userReplace node1, svm1 and user1 with the appropriate values. The specified node must have active data interfaces for that SVM.
Repeat the node-specific credential flush on other relevant serving nodes if needed.
A broader alternative clears NFS credentials for the entire SVM on a specified node:
vserver nfs credentials flush -node node* -vserver svmThis affects more users and triggers credential rebuilding, so start with the individual user.
Retry access and verify that the expected supplementary GIDs are present in the rebuilt credentials. Then return to admin privilege:
set -privilege adminAn NFS credential flush does not clear the separate name-service group-membership cache. If fresh lookups still lack the group, investigate the name-service lookup before treating this as an NFS credential-cache issue.
*=could be any number of nodes.
The lesson: check what ONTAP sees before changing permissions.
-Ash
Reference: NetApp ONTAP command reference—NFS credentials flush. Command syntax was checked against published documentation; these examples were not tested on a live cluster for this article.
Comments
Post a Comment