The Qlustar releases 12.0.0.5-b542f1391 and 11.0.1.9-b543f1392 are ready
including a number of security/bug fixes and improvements. In
particular, they include a fix for the Sequoia local root exploit bug
https://www.qualys.com/2021/07/20/cve-2021-33909/sequoia-local-privilege-es…
Please check the following web pages for details about all security fixes
and special update instructions:
https://qlustar.com/qsa/2021/0724211https://qlustar.com/qsa/2021/0724212
The following non-security related enhancements/bug fixes are included:
For 12.0 only:
- ntpd is replaced by systemd-timesyncd as the daemon to sync system time
between head-node(s) and netboot nodes.
A number of new Qlustar features were completed recently and published
together with the latest security updates.
QluMan 12.0.3.1 has the following new capabilities:
- PRE-SYSTEMD NODE CUSTOMIZATION has been introduced via a new config
class [1]. Files and scripts placed in a particular path may be
transferred to the booting node, and scripts being subsequently
executed. This is a powerful and flexible new dynamic node
customization feature.
- ACTIVE DIRECTORY USER IMPORT into the Qlustar LDAP server is now
possible via the GUI [2]. This allows for an AD integration without
compromising HPC features also on large clusters.
- QLUMAN MONITORING 1.0: This is the first milestone of the upcoming
new Qlustar monitoring architecture [3] eventually replacing Nagios. It
implements a filesystem-based check/trigger mechanism controlled by
QluMan execd. First usage example: Start slurmd only once checks are
successful and drain/undrain if they fail/recover later.
- Support for DHCP-less boot (see below).
- SUPPORT FOR ROUTED NETWORKS as primary boot networks and in
NetworkFSMounts was added.
Other new features:
- Update from CENTOS 8.3 to 8.4 with integration of OPENHPC 2.3.
- DHCP-LESS BOOT: DHCP is now only used during the initial
BIOS/UEFI/PXE stage. All necessary node configuration data
previously provided by DHCP is now provided via QluMan in the
pre-systemd boot phase.
- To control user access by ssh on slurm nodes, a new UNIX group
_node-ssh_ was introduced. Members of this group are always allowed
to ssh into a node, even without slurm job.
- A new image module VIRTUALGL was added for experimental usage. Using
it in a node image, Qlustar can provide 3D remote visualization on
nodes with the required hardware.
[1] https://docs.qlustar.com/Qlustar/12.0/ClusterOS/qluman-guide/Other-Configs.…
[2] https://docs.qlustar.com/Qlustar/12.0/ClusterOS/qluman-guide/components/lda…
[3] https://docs.qlustar.com/Qlustar/12.0/ClusterOS/administration-manual/monit…
The Qlustar releases 12.0.0.4-b542f1382 and 11.0.1.8-b543f1384 are ready
including a number of security/bug fixes and improvements. Please check
the following web pages for details about security fixes and special
update instructions:
https://qlustar.com/qsa/2021/0706211https://qlustar.com/qsa/2021/0706212
The following non-security related enhancements/bug fixes are included:
For 12.0 only:
- QluMan 12.0.3.1 (GUI update to 12.0.3.1 needed as well)
* Add pre-systemd node customization via new config class
* Add AD user import functionality in GUI (final)
* Add support for DHCP-less boot
* Add PrologFlags=X11 to default slurm config
* Add support for routed networks as primary boot networks and in
NetworkFSMounts
* Exexd now sets the correct time in pre-systemd boot phase
* Don't show slurm stuff in GUI if slurm is not installed
* Ignore mouse wheel events in comboboxes to prevent accidental changes
* SlurmJobManagement: Simplify customizing columns
* Drop obsolete torque pam support
* Fix version update check
- slurm module
* Introduce group 'node-ssh'. Members of this group are always
allowed to make a node ssh login, even without slurm job.
- Added virtualGL image modules (experimental)
For 11.0/12.0:
- Move CentOS 8 edge platform to 8.4 + OpenHPC 2.3