Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
5acf2d4
iam: sample policies for cluster admin + cluster user (SSM)
DaisukeMiyamoto Jun 10, 2026
2745132
iam: ship as CloudFormation templates with 1-click Deploy buttons
DaisukeMiyamoto Jun 10, 2026
00ddddc
deploy-all: tighten parameters — auto-derive EFA interface count, def…
DaisukeMiyamoto Jun 11, 2026
19ee3fe
feat: add optional OpenLDAP multi-user directory on login node
DaisukeMiyamoto Jun 16, 2026
eecbcbb
docs: add USER-MANAGEMENT.md — OpenLDAP multi-user operations guide
DaisukeMiyamoto Jun 16, 2026
e1ff8c2
fix: point LDAP script URLs at fork branch (pre-merge)
DaisukeMiyamoto Jun 16, 2026
129900d
fix: apt-get update before slapd install + add multi-user test suite
DaisukeMiyamoto Jun 16, 2026
17e12ba
fix: SSSD min_id=1001 (GID 3000 was out of range) + persist admin pw …
DaisukeMiyamoto Jun 16, 2026
62d4e1d
feat: wire DeployDirectory into deploy-all + template structure diagram
DaisukeMiyamoto Jun 16, 2026
599a9d7
refactor: rename DeployDirectory → DirectoryService (enum: none | Ope…
DaisukeMiyamoto Jun 16, 2026
b2d1c0a
ROADMAP: track DeployMonitoring → MonitoringStack rename for next minor
DaisukeMiyamoto Jun 16, 2026
f4fdb60
fix: revert unintended Default:'false'→'none' on 4 boolean params
DaisukeMiyamoto Jun 16, 2026
9ccdbb4
security: store LDAP admin password in SSM Parameter Store, not on sh…
DaisukeMiyamoto Jun 16, 2026
d2426a9
refactor: merge setup-openldap-server.sh + setup-ldap-client.sh → set…
DaisukeMiyamoto Jun 16, 2026
ce0e2ac
refactor: replace MonitoringRole-based directory branching with dedic…
DaisukeMiyamoto Jun 16, 2026
0ca1cb9
feat: fetch scripts from S3 instead of GitHub raw URLs
DaisukeMiyamoto Jun 16, 2026
cdb97b1
move scripts/ → assets/scripts/ so prod S3 sync covers them automatic…
DaisukeMiyamoto Jun 16, 2026
c759491
docs: add DEPLOY-TESTING.md — development deploy procedures
DaisukeMiyamoto Jun 16, 2026
e008f9c
docs: rewrite USER-MANAGEMENT.md for LDAP-unfamiliar admins + update …
DaisukeMiyamoto Jun 16, 2026
55de8c1
fix: update all stale path/param references after scripts/ relocation
DaisukeMiyamoto Jun 16, 2026
2a6c72c
README: separate boot scripts from helper scripts, add parallelcluste…
DaisukeMiyamoto Jun 16, 2026
03db98b
fix: move directory setup from MIME shellscript to runcmd block (PCS …
DaisukeMiyamoto Jun 16, 2026
74705e0
tests: add accounting-test.md + gpu-healthcheck-test.md
DaisukeMiyamoto Jun 16, 2026
5423e7f
tests: split README.md (842 lines) into category-based files
DaisukeMiyamoto Jun 16, 2026
cb0e86f
README: add §11 User Management section with link to USER-MANAGEMENT.md
DaisukeMiyamoto Jun 16, 2026
1da9571
fix: move runcmd comment inside list item (YAML comment outside - | b…
DaisukeMiyamoto Jun 16, 2026
58a0b8e
README: restructure — group advanced features under §8, simplify sect…
DaisukeMiyamoto Jun 16, 2026
649d566
deploy-all: reorganize ParameterGroups — separate monitoring/director…
DaisukeMiyamoto Jun 16, 2026
6a06230
deploy-all: move monitoring params to §7, Developer §8 keeps only S3 …
DaisukeMiyamoto Jun 16, 2026
b7b65b2
feat: SSHAccessCidr + DeployMonitoring→MonitoringStack + GrafanaPubli…
DaisukeMiyamoto Jun 16, 2026
7f068f3
fix: remove --region from s3 cp (AWS CLI auto-resolves via IMDS crede…
DaisukeMiyamoto Jun 16, 2026
d7dfdf1
feat: dedicated directory-role tag, helper-script install, multi-AZ s…
DaisukeMiyamoto Jun 16, 2026
2fe7d11
deploy-all: forward AdditionalSubnetAZ2/3 to prerequisites (multi-AZ …
DaisukeMiyamoto Jun 16, 2026
e7d72f8
feat: wire multi-user directory into GPU templates (p5/p6-b200/p6-b300)
DaisukeMiyamoto Jun 16, 2026
ce6e5a5
docs: update README/PARAMETERS/ROADMAP for renamed + new params
DaisukeMiyamoto Jun 16, 2026
987ee0d
fix: setup-directory.sh waits for apt/dpkg lock (first-boot unattende…
DaisukeMiyamoto Jun 16, 2026
465e0cd
docs: finish param-rename sweep + add LDAP discovery / multi-VPC notes
DaisukeMiyamoto Jun 16, 2026
1b7d1bf
feat: bring in IAM policy stacks from feat/aws-pcs-updates
DaisukeMiyamoto Jun 16, 2026
fdd87f9
Merge branch 'feat/aws-pcs-updates' into feat/multi-user
DaisukeMiyamoto Jun 16, 2026
b5bd563
fix: install sssd-tools so deleted/modified LDAP users propagate (sss…
DaisukeMiyamoto Jun 16, 2026
d64e690
tests: record major-update e2e validation matrix (run on real hardware)
DaisukeMiyamoto Jun 16, 2026
647c810
docs: fix USER-MANAGEMENT accuracy (verified against live accounting …
DaisukeMiyamoto Jun 17, 2026
5a7ca7b
tests: accounting + multi-user (Test 12) verified end-to-end on real …
DaisukeMiyamoto Jun 17, 2026
cd498a9
docs: reorder Advanced Features by priority, consolidate IAM into doc…
DaisukeMiyamoto Jun 17, 2026
aa1ffbe
docs: clarify OnDemandEfaInterfaceCount auto-derive to avoid EFA conf…
DaisukeMiyamoto Jun 17, 2026
372df82
refactor: collapse OnDemandEnableEfa into OnDemandEfaInterfaceCount (…
DaisukeMiyamoto Jun 17, 2026
a8556d7
fix: remove VPCName param from deploy-all + clear stale OnDemandEnabl…
DaisukeMiyamoto Jun 17, 2026
e84906c
fix: VPC Name tag uses VPCName param (was hardcoded 'ML Cluster VPC')
DaisukeMiyamoto Jun 17, 2026
5cc8a8a
tests: add region coverage matrix (us-east-1/2, us-west-2, ap-northea…
DaisukeMiyamoto Jun 17, 2026
98b8d9f
tests: record p6-b200 x4 NCCL all_reduce busbw (peak 377 GB/s over EF…
DaisukeMiyamoto Jun 17, 2026
be8d968
tests: record FSDP distributed-training readiness on 32 B200 GPUs (Mu…
DaisukeMiyamoto Jun 17, 2026
422ed2f
fix: split PCS instance-role perms inline by feature; drop ManagedPolicy
DaisukeMiyamoto Jun 17, 2026
fe49d00
tests: refine FSDP result — distributed stack proven; c4 streaming bl…
DaisukeMiyamoto Jun 17, 2026
5f5fbf6
docs(IAM): refresh verification matrix against major-update templates
DaisukeMiyamoto Jun 17, 2026
04dc0b2
tests: record EFA OSU real-traffic numbers (hpc8a: osu_bw 26.3 GB/s, …
DaisukeMiyamoto Jun 17, 2026
6318d4d
docs(IAM): record admin-only-role delete-stack teardown (DELETE_COMPL…
DaisukeMiyamoto Jun 17, 2026
c2a325e
tests: record GPU health check 4/4 PASS on B200 (Mumbai p6-b200)
DaisukeMiyamoto Jun 17, 2026
d32b606
tests: list all 18 PCS launch regions in coverage matrix (5 tested, 1…
DaisukeMiyamoto Jun 17, 2026
a4bcf89
feat: PostInstallScriptUrl accepts s3:// (instance-role fetch) — work…
DaisukeMiyamoto Jun 17, 2026
d4678c9
docs: fix stale 'PostInstallScriptUrl empty = skip' wording + DcgmExp…
DaisukeMiyamoto Jun 17, 2026
41f5f35
tests: add docs-consistency lint (tests/lint-docs.sh) as pre-merge Te…
DaisukeMiyamoto Jun 17, 2026
0c53c9f
tests: add NCCL busbw validity note (377 GB/s is reasonable, not peak…
DaisukeMiyamoto Jun 17, 2026
25305f5
tests: move p6-b200 NCCL/FSDP results out of README into their own te…
DaisukeMiyamoto Jun 17, 2026
2ad22ee
tests: rebuild region-coverage table + record s3:// PostInstall and O…
DaisukeMiyamoto Jun 17, 2026
0412a3d
tests: add Megatron-LM GPT-3 (Test 7b) + intensive GPU health check r…
DaisukeMiyamoto Jun 17, 2026
2815919
docs(roadmap): add targeted ODCR support for GPU node groups
DaisukeMiyamoto Jun 17, 2026
231ed95
docs(readme): user-facing cleanup — surface new params, fix accuracy,…
DaisukeMiyamoto Jun 17, 2026
50993ee
docs: fix OpenZFS throughput values, note Slurm-version paths, drop s…
DaisukeMiyamoto Jun 17, 2026
90cab6b
docs: align README config order with deploy-all, refresh features/arc…
DaisukeMiyamoto Jun 17, 2026
621cb9e
docs: drop multi-AZ/Region key-feature bullet, note GPU column is fro…
DaisukeMiyamoto Jun 17, 2026
e91c9e1
docs(readme): keep Key Features concise — drop param names, link to d…
DaisukeMiyamoto Jun 17, 2026
ff66f10
docs(readme): tidy §4 intro — single concise lead-in, group separator…
DaisukeMiyamoto Jun 17, 2026
d59fce8
deploy-all: regroup params — fold Container Runtime into Additional, …
DaisukeMiyamoto Jun 17, 2026
0cd9c1b
docs(readme): tighten Architecture/Monitoring, link GPU health check …
DaisukeMiyamoto Jun 17, 2026
1c13036
docs(readme): split §4 config table into small per-group tables
DaisukeMiyamoto Jun 17, 2026
6ae6ad6
docs(readme): number §4 config groups, move Storage to Advanced §8.1 …
DaisukeMiyamoto Jun 17, 2026
b692f7e
docs: drop test-profile flags, align PARAMETERS with deploy-all group…
DaisukeMiyamoto Jun 17, 2026
14727df
docs(readme): fold FSx-over-EFA (GDS) into §8.1 Storage as a subsection
DaisukeMiyamoto Jun 17, 2026
5a96257
docs(readme): add §8.7 pointing to DEPLOY-TESTING.md for unpublished-…
DaisukeMiyamoto Jun 17, 2026
1efef89
docs(readme): fix §4 group 5 heading/content mismatch
DaisukeMiyamoto Jun 17, 2026
147f6aa
docs(readme): drop the redundant note under §4 group 5
DaisukeMiyamoto Jun 17, 2026
338ee1e
docs(readme): match §4 group headings to the deploy-all ParameterGrou…
DaisukeMiyamoto Jun 17, 2026
0ade772
docs(tests): fix stale PostInstallScriptUrl caveat
DaisukeMiyamoto Jun 17, 2026
56bf60c
docs(tests): remove private test-bucket name from infra-test.md
DaisukeMiyamoto Jun 17, 2026
41fb46f
docs: add Deploy buttons to IAM role table; move custom-AMI detail to…
DaisukeMiyamoto Jun 17, 2026
b077f57
docs(iam): use the Launch-stack image for the policy Deploy buttons, …
DaisukeMiyamoto Jun 17, 2026
9c69bc4
docs(readme): use the Launch-stack image for all §9 template Deploy b…
DaisukeMiyamoto Jun 17, 2026
1510bc7
docs(readme): add Launch-stack Deploy buttons to §8.4 IAM Permissions
DaisukeMiyamoto Jun 17, 2026
e582e65
docs: pre-PR polish — number test headings to match the matrix, clari…
DaisukeMiyamoto Jun 17, 2026
d4da5f9
docs(readme): drop the Capacity Block billing note (cost is out of sc…
DaisukeMiyamoto Jun 17, 2026
b1d393c
Merge remote-tracking branch 'origin/main' into feat/multi-user
DaisukeMiyamoto Jun 17, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
459 changes: 298 additions & 161 deletions architectures/aws-pcs/README.md

Large diffs are not rendered by default.

79 changes: 76 additions & 3 deletions architectures/aws-pcs/assets/add-cng-p5.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -203,8 +203,8 @@ Parameters:
Description: >-
Optional URL of a post-install script to download and run on each node at
first boot (PCS equivalent of ParallelCluster OnNodeConfigured). Leave
empty to skip. To install Enroot/Pyxis, point this at scripts/install-enroot-pyxis.sh.
Must be an HTTP(S) URL (e.g. a GitHub raw URL); S3 public hosting is not allowed.
empty to skip. To install Enroot/Pyxis, point this at assets/scripts/install-enroot-pyxis.sh.
Accepts an s3:// URL (instance-role fetch; private bucket OK) or an http(s):// URL (curl; public only). For Enroot/Pyxis point at scripts/install-enroot-pyxis.sh in the templates bucket.
Default: ''

PostInstallScriptArgs:
Expand All @@ -224,6 +224,49 @@ Parameters:
- '25.05'
- '25.11'

DirectoryService:
Type: String
Description: >-
Multi-user directory service. 'none' = single ubuntu user (default,
unchanged). 'OpenLDAP-LoginNode' = deploy slapd on the login node (DB on shared
/home/ldap-db), compute nodes configure SSSD as LDAP clients. Future
options (SimpleAD, ManagedAD) will be added as AllowedValues.
Default: 'none'
AllowedValues:
- 'none'
- 'OpenLDAP-LoginNode'

DirectoryDomainSuffix:
Type: String
Description: >-
LDAP domain suffix (e.g. dc=cluster,dc=internal). Only used when
DirectoryService != none.
Default: 'dc=cluster,dc=internal'

DirectoryRole:
Type: String
Description: >-
This CNG's role in the directory service. 'server' = install and run
the directory (slapd on login node). 'client' = configure SSSD to
resolve users from the directory server. 'none' = skip directory setup.
deploy-all sets this automatically (login=server, compute=client) when
DirectoryService != none.
Default: 'none'
AllowedValues:
- 'none'
- 'server'
- 'client'

S3BucketName:
Type: String
Description: S3 bucket where scripts are stored (same as nested templates bucket)
Default: 'awsome-distributed-ai'

S3KeyPrefix:
Type: String
Description: S3 key prefix for scripts (e.g. templates/)
Default: 'templates/'

Conditions:
# EFA interface count is derived from the instance type: p5en.48xlarge has 16
# network cards, p5.48xlarge / p5e.48xlarge have 32. So "use 32 interfaces"
Expand All @@ -237,6 +280,7 @@ Conditions:
# tag (monitoring-role=login) and excludes them from EC2 service discovery.
IsMonitoringRoleSet: !Not [!Equals [!Ref MonitoringRole, 'none']]
HasAmiId: !Not [!Equals [!Ref AmiId, ""]]
DirectoryEnabled: !Not [!Equals [!Ref DirectoryRole, 'none']]

Resources:

Expand Down Expand Up @@ -336,6 +380,16 @@ Resources:
- Key: monitoring-role
Value: !Ref MonitoringRole
- !Ref AWS::NoValue
# Directory (multi-user) role tag, independent of monitoring-role.
# Emitted for both server (login) and client (compute) nodes when
# DirectoryRole != none. Compute clients discover the OpenLDAP
# server by querying for directory-role=server (NOT monitoring-role,
# which is owned by the monitoring stack). See setup-directory.sh.
- !If
- DirectoryEnabled
- Key: directory-role
Value: !Ref DirectoryRole
- !Ref AWS::NoValue
MetadataOptions:
HttpEndpoint: enabled
HttpPutResponseHopLimit: 4
Expand All @@ -356,7 +410,10 @@ Resources:
- |
if [ -n "${PostInstallScriptUrl}" ]; then
echo "Downloading post-install script from ${PostInstallScriptUrl}..." | tee /var/log/pcs-post-install.log
curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh
case "${PostInstallScriptUrl}" in
s3://*) aws s3 cp "${PostInstallScriptUrl}" /tmp/pcs-post-install.sh >> /var/log/pcs-post-install.log 2>&1 ;;
*) curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh ;;
esac
chmod +x /tmp/pcs-post-install.sh
echo "Executing post-install script..." | tee -a /var/log/pcs-post-install.log
# Tell the script this cluster's Slurm version (it can't discover it at
Expand Down Expand Up @@ -396,6 +453,22 @@ Resources:
bash /tmp/post-install.sh ${MonitoringVersion} ${MonitoringRepo} 2>&1 | tee /var/log/monitoring-install.log
echo "Monitoring installation complete"
fi
- |
# Multi-user directory setup (optional, DirectoryRole != none)
if [ "${DirectoryRole}" != "none" ]; then
export LDAP_DOMAIN_SUFFIX="${DirectoryDomainSuffix}"
export LDAP_DOMAIN=$(echo "${DirectoryDomainSuffix}" | sed 's/dc=//g; s/,/./g')
export LDAP_ADMIN_PASSWORD=$(openssl rand -base64 16)
export CLUSTER_ID="${ClusterId}"
export DIRECTORY_DNS_IPS=""
# Pass the script source so the server role can install the
# ldap-add-user.sh helper onto /usr/local/bin from the same bucket.
export S3_BUCKET="${S3BucketName}"
export S3_KEY_PREFIX="${S3KeyPrefix}"
aws s3 cp s3://${S3BucketName}/${S3KeyPrefix}scripts/setup-directory.sh /tmp/setup-directory.sh
chmod +x /tmp/setup-directory.sh
bash /tmp/setup-directory.sh "${DirectoryRole}" 2>&1 | tee /var/log/directory-setup.log
fi

--==MYBOUNDARY==
NetworkInterfaces:
Expand Down
79 changes: 76 additions & 3 deletions architectures/aws-pcs/assets/add-cng-p6-b200.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -194,8 +194,8 @@ Parameters:
Description: >-
Optional URL of a post-install script to download and run on each node at
first boot (PCS equivalent of ParallelCluster OnNodeConfigured). Leave
empty to skip. To install Enroot/Pyxis, point this at scripts/install-enroot-pyxis.sh.
Must be an HTTP(S) URL (e.g. a GitHub raw URL); S3 public hosting is not allowed.
empty to skip. To install Enroot/Pyxis, point this at assets/scripts/install-enroot-pyxis.sh.
Accepts an s3:// URL (instance-role fetch; private bucket OK) or an http(s):// URL (curl; public only). For Enroot/Pyxis point at scripts/install-enroot-pyxis.sh in the templates bucket.
Default: ''

PostInstallScriptArgs:
Expand All @@ -215,6 +215,49 @@ Parameters:
- '25.05'
- '25.11'

DirectoryService:
Type: String
Description: >-
Multi-user directory service. 'none' = single ubuntu user (default,
unchanged). 'OpenLDAP-LoginNode' = deploy slapd on the login node (DB on shared
/home/ldap-db), compute nodes configure SSSD as LDAP clients. Future
options (SimpleAD, ManagedAD) will be added as AllowedValues.
Default: 'none'
AllowedValues:
- 'none'
- 'OpenLDAP-LoginNode'

DirectoryDomainSuffix:
Type: String
Description: >-
LDAP domain suffix (e.g. dc=cluster,dc=internal). Only used when
DirectoryService != none.
Default: 'dc=cluster,dc=internal'

DirectoryRole:
Type: String
Description: >-
This CNG's role in the directory service. 'server' = install and run
the directory (slapd on login node). 'client' = configure SSSD to
resolve users from the directory server. 'none' = skip directory setup.
deploy-all sets this automatically (login=server, compute=client) when
DirectoryService != none.
Default: 'none'
AllowedValues:
- 'none'
- 'server'
- 'client'

S3BucketName:
Type: String
Description: S3 bucket where scripts are stored (same as nested templates bucket)
Default: 'awsome-distributed-ai'

S3KeyPrefix:
Type: String
Description: S3 key prefix for scripts (e.g. templates/)
Default: 'templates/'

Conditions:
UseCapacityBlock: !Not [!Equals [!Ref CapacityReservationId, ""]]
UseOnDemand: !Equals [!Ref CapacityReservationId, ""]
Expand All @@ -224,6 +267,7 @@ Conditions:
# tag (monitoring-role=login) and excludes them from EC2 service discovery.
IsMonitoringRoleSet: !Not [!Equals [!Ref MonitoringRole, 'none']]
HasAmiId: !Not [!Equals [!Ref AmiId, ""]]
DirectoryEnabled: !Not [!Equals [!Ref DirectoryRole, 'none']]

Resources:

Expand Down Expand Up @@ -323,6 +367,16 @@ Resources:
- Key: monitoring-role
Value: !Ref MonitoringRole
- !Ref AWS::NoValue
# Directory (multi-user) role tag, independent of monitoring-role.
# Emitted for both server (login) and client (compute) nodes when
# DirectoryRole != none. Compute clients discover the OpenLDAP
# server by querying for directory-role=server (NOT monitoring-role,
# which is owned by the monitoring stack). See setup-directory.sh.
- !If
- DirectoryEnabled
- Key: directory-role
Value: !Ref DirectoryRole
- !Ref AWS::NoValue
MetadataOptions:
HttpEndpoint: enabled
HttpPutResponseHopLimit: 4
Expand All @@ -343,7 +397,10 @@ Resources:
- |
if [ -n "${PostInstallScriptUrl}" ]; then
echo "Downloading post-install script from ${PostInstallScriptUrl}..." | tee /var/log/pcs-post-install.log
curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh
case "${PostInstallScriptUrl}" in
s3://*) aws s3 cp "${PostInstallScriptUrl}" /tmp/pcs-post-install.sh >> /var/log/pcs-post-install.log 2>&1 ;;
*) curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh ;;
esac
chmod +x /tmp/pcs-post-install.sh
echo "Executing post-install script..." | tee -a /var/log/pcs-post-install.log
# Tell the script this cluster's Slurm version (it can't discover it at
Expand Down Expand Up @@ -397,6 +454,22 @@ Resources:
done
echo "Monitoring installation complete (exit $rc)" >> /var/log/monitoring-install.log
fi
- |
# Multi-user directory setup (optional, DirectoryRole != none)
if [ "${DirectoryRole}" != "none" ]; then
export LDAP_DOMAIN_SUFFIX="${DirectoryDomainSuffix}"
export LDAP_DOMAIN=$(echo "${DirectoryDomainSuffix}" | sed 's/dc=//g; s/,/./g')
export LDAP_ADMIN_PASSWORD=$(openssl rand -base64 16)
export CLUSTER_ID="${ClusterId}"
export DIRECTORY_DNS_IPS=""
# Pass the script source so the server role can install the
# ldap-add-user.sh helper onto /usr/local/bin from the same bucket.
export S3_BUCKET="${S3BucketName}"
export S3_KEY_PREFIX="${S3KeyPrefix}"
aws s3 cp s3://${S3BucketName}/${S3KeyPrefix}scripts/setup-directory.sh /tmp/setup-directory.sh
chmod +x /tmp/setup-directory.sh
bash /tmp/setup-directory.sh "${DirectoryRole}" 2>&1 | tee /var/log/directory-setup.log
fi

--==MYBOUNDARY==
NetworkInterfaces:
Expand Down
79 changes: 76 additions & 3 deletions architectures/aws-pcs/assets/add-cng-p6-b300.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -197,8 +197,8 @@ Parameters:
Description: >-
Optional URL of a post-install script to download and run on each node at
first boot (PCS equivalent of ParallelCluster OnNodeConfigured). Leave
empty to skip. To install Enroot/Pyxis, point this at scripts/install-enroot-pyxis.sh.
Must be an HTTP(S) URL (e.g. a GitHub raw URL); S3 public hosting is not allowed.
empty to skip. To install Enroot/Pyxis, point this at assets/scripts/install-enroot-pyxis.sh.
Accepts an s3:// URL (instance-role fetch; private bucket OK) or an http(s):// URL (curl; public only). For Enroot/Pyxis point at scripts/install-enroot-pyxis.sh in the templates bucket.
Default: ''

PostInstallScriptArgs:
Expand All @@ -218,6 +218,49 @@ Parameters:
- '25.05'
- '25.11'

DirectoryService:
Type: String
Description: >-
Multi-user directory service. 'none' = single ubuntu user (default,
unchanged). 'OpenLDAP-LoginNode' = deploy slapd on the login node (DB on shared
/home/ldap-db), compute nodes configure SSSD as LDAP clients. Future
options (SimpleAD, ManagedAD) will be added as AllowedValues.
Default: 'none'
AllowedValues:
- 'none'
- 'OpenLDAP-LoginNode'

DirectoryDomainSuffix:
Type: String
Description: >-
LDAP domain suffix (e.g. dc=cluster,dc=internal). Only used when
DirectoryService != none.
Default: 'dc=cluster,dc=internal'

DirectoryRole:
Type: String
Description: >-
This CNG's role in the directory service. 'server' = install and run
the directory (slapd on login node). 'client' = configure SSSD to
resolve users from the directory server. 'none' = skip directory setup.
deploy-all sets this automatically (login=server, compute=client) when
DirectoryService != none.
Default: 'none'
AllowedValues:
- 'none'
- 'server'
- 'client'

S3BucketName:
Type: String
Description: S3 bucket where scripts are stored (same as nested templates bucket)
Default: 'awsome-distributed-ai'

S3KeyPrefix:
Type: String
Description: S3 key prefix for scripts (e.g. templates/)
Default: 'templates/'

Conditions:
UseCapacityBlock: !Not [!Equals [!Ref CapacityReservationId, ""]]
UseOnDemand: !Equals [!Ref CapacityReservationId, ""]
Expand All @@ -227,6 +270,7 @@ Conditions:
# tag (monitoring-role=login) and excludes them from EC2 service discovery.
IsMonitoringRoleSet: !Not [!Equals [!Ref MonitoringRole, 'none']]
HasAmiId: !Not [!Equals [!Ref AmiId, ""]]
DirectoryEnabled: !Not [!Equals [!Ref DirectoryRole, 'none']]

Resources:

Expand Down Expand Up @@ -326,6 +370,16 @@ Resources:
- Key: monitoring-role
Value: !Ref MonitoringRole
- !Ref AWS::NoValue
# Directory (multi-user) role tag, independent of monitoring-role.
# Emitted for both server (login) and client (compute) nodes when
# DirectoryRole != none. Compute clients discover the OpenLDAP
# server by querying for directory-role=server (NOT monitoring-role,
# which is owned by the monitoring stack). See setup-directory.sh.
- !If
- DirectoryEnabled
- Key: directory-role
Value: !Ref DirectoryRole
- !Ref AWS::NoValue
MetadataOptions:
HttpEndpoint: enabled
HttpPutResponseHopLimit: 4
Expand All @@ -346,7 +400,10 @@ Resources:
- |
if [ -n "${PostInstallScriptUrl}" ]; then
echo "Downloading post-install script from ${PostInstallScriptUrl}..." | tee /var/log/pcs-post-install.log
curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh
case "${PostInstallScriptUrl}" in
s3://*) aws s3 cp "${PostInstallScriptUrl}" /tmp/pcs-post-install.sh >> /var/log/pcs-post-install.log 2>&1 ;;
*) curl -fsSL "${PostInstallScriptUrl}" -o /tmp/pcs-post-install.sh ;;
esac
chmod +x /tmp/pcs-post-install.sh
echo "Executing post-install script..." | tee -a /var/log/pcs-post-install.log
# Tell the script this cluster's Slurm version (it can't discover it at
Expand Down Expand Up @@ -400,6 +457,22 @@ Resources:
done
echo "Monitoring installation complete (exit $rc)" >> /var/log/monitoring-install.log
fi
- |
# Multi-user directory setup (optional, DirectoryRole != none)
if [ "${DirectoryRole}" != "none" ]; then
export LDAP_DOMAIN_SUFFIX="${DirectoryDomainSuffix}"
export LDAP_DOMAIN=$(echo "${DirectoryDomainSuffix}" | sed 's/dc=//g; s/,/./g')
export LDAP_ADMIN_PASSWORD=$(openssl rand -base64 16)
export CLUSTER_ID="${ClusterId}"
export DIRECTORY_DNS_IPS=""
# Pass the script source so the server role can install the
# ldap-add-user.sh helper onto /usr/local/bin from the same bucket.
export S3_BUCKET="${S3BucketName}"
export S3_KEY_PREFIX="${S3KeyPrefix}"
aws s3 cp s3://${S3BucketName}/${S3KeyPrefix}scripts/setup-directory.sh /tmp/setup-directory.sh
chmod +x /tmp/setup-directory.sh
bash /tmp/setup-directory.sh "${DirectoryRole}" 2>&1 | tee /var/log/directory-setup.log
fi

--==MYBOUNDARY==
NetworkInterfaces:
Expand Down
Loading