Skip to content

Commit ba06e41

Browse files
committed
set locked mem limits on user nodes, configure login access
1 parent 440d6f5 commit ba06e41

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed

ansible/roles/compute_init/files/compute-init.yml

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -244,6 +244,27 @@
244244
cmd: "cvmfs_config setup"
245245
when: enable_eessi
246246

247+
- name: Set locked memory limits on user-facing nodes
248+
lineinfile:
249+
path: /etc/security/limits.conf
250+
regexp: '\* soft memlock unlimited'
251+
line: "* soft memlock unlimited"
252+
253+
- name: Configure sshd pam module
254+
blockinfile:
255+
path: /etc/pam.d/sshd
256+
insertafter: 'account\s+required\s+pam_nologin.so'
257+
block: |
258+
account sufficient pam_access.so
259+
account required pam_slurm.so
260+
261+
- name: Configure login access control
262+
blockinfile:
263+
path: /etc/security/access.conf
264+
block: |
265+
+:adm:ALL
266+
-:ALL:ALL
267+
247268
# NB: don't need conditional block on enable_compute as have already exited
248269
# if not the case
249270
- name: Write Munge key

0 commit comments

Comments
 (0)