Skip to main content

Managed SMB with Active Directory – Administrator Guide

Contents

  1. Purpose and safety
  2. Prerequisites
  3. 1. Verify cluster and Ceph
  4. 2. Verify the drive
  5. 3. Configure the IP Group
  6. 4. Join Active Directory
  7. 5. Create or verify the share
  8. 6. Client acceptance
  9. 7. Controlled failover
  10. Monitoring
  11. Troubleshooting
  12. Rollback

Purpose and safety

For Linux, storage and Windows administrators providing CephFS through eEKAS-managed SMB with Microsoft Active Directory.

Important / Wichtig: Domain join, DNS/time changes, gateway recreation and VIP moves affect access. Use a maintenance window, verify backups and record current VIP placement.

Prerequisites

Item Requirement
Cluster Three healthy nodes with quorum
Ceph HEALTH_OK; PGs active+clean
Drive Healthy CephFS drive with capacity
Network Static node addresses and unused VIPs
AD Resolvable realm; reachable DNS/KDC/LDAP/SMB; delegated join account and OU
Time Every node can synchronize with the DC
Clients SMB3 and reachability to every VIP

Record realm, NetBIOS domain, DC/DNS addresses, OU, IP Group, node order, VIPs, drive, share, capacity and access policy. Never record passwords.

1. Verify cluster and Ceph

  1. Open Cluster Management → Cluster Status.
  2. Confirm all nodes Online and Ceph Server Active.
  3. Confirm Ceph is optimal and all PGs active+clean.
  4. Do not continue with inactive, peering, undersized or degraded PGs.
Healthy three-node cluster before changes.
Figure 1. Healthy three-node cluster before changes.

2. Verify the drive

  1. Open Cluster Drive Management.
  2. Confirm the drive exists and assigned pools are Clean.
  3. Confirm zero Down/Out OSDs and adequate usable capacity.
  4. After creating storage, wait for Ceph health before continuing.
Drive1 and its clean pools.
Figure 2. Drive1 and its clean pools.

3. Configure the IP Group

  1. Open Cluster Management → IP Groups.
  2. Add the eligible gateway nodes and define their preferred order.
  3. Add one unused client-subnet service address. Add further addresses only when connections should be distributed.
  4. Use keep-together for a single address or simple active/passive placement; use distributed placement when multiple addresses should run on different nodes.
  5. Check mask, routing, VLAN and address conflicts.
IPGroup1 example with two distributed service addresses and share1.
Figure 3. IPGroup1 example with two distributed service addresses and share1.

4. Join Active Directory

  1. Open Domain and Workgroup management.
  2. Enter the FQDN realm, delegated join user, password, DNS/DC and computer OU.
  3. Start the cluster join and do not interrupt it.
  4. The workflow synchronizes peers, joins every node, stores the eEKAS-managed SMB profile and recreates the managed gateways in AD mode.
  5. Run Domain Diagnostics; require Joined, DNS/Communication Reachable, healthy time and SMB Available on every node.
Important / Wichtig: Kerberos normally fails beyond five minutes of skew. If peer time synchronization fails, fix DNS/connectivity before retrying.
Successful join and enabled eEKAS-managed SMB domain integration.
Figure 4. Successful join and enabled eEKAS-managed SMB domain integration.

5. Create or verify the share

  1. Open Share Management.
  2. Select Create Share and the CephFS drive; set unique name and capacity.
  3. Select SMB/CIFS and the intended IP Group.
  4. Assign AD users/groups; prefer groups.
  5. Confirm drive, IP Group, protocol and runtime status.
share1 exported through IPGroup1.
Figure 5. share1 exported through IPGroup1.

6. Client acceptance

From an authorized domain workstation, open the service address in the operating system file browser. Confirm that the expected share is visible, create a neutral test file, read it, rename it and delete it. Repeat through every published service address. Test both allowed and denied access.

7. Controlled failover

  1. Confirm HEALTH_OK, all nodes online, CTDB healthy and a successful pre-test write.
  2. Record every VIP owner.
  3. Move one VIP or place its owner in planned maintenance in the GUI.
  4. Wait until the VIP appears on another eligible node.
  5. Reconnect to the same VIP and read the pre-test file.
  6. Create/delete a file through another active VIP.
  7. End maintenance/clear the move; confirm preferred placement and health.

Acceptance criterion: the same namespace and AD authorization remain available after reconnect. Test application retry behavior separately.

Monitoring

Check Healthy result
Cluster All nodes Online; quorum
Ceph HEALTH_OK; PGs active+clean
MDS Active plus standby
eEKAS-managed SMB Expected gateway count running
CTDB Recovery mode NORMAL; all nodes OK
AD Join is OK; diagnostics healthy
DNS/time AD DNS reachable; offset in tolerance
IP Group VIPs on eligible nodes
Share Correct drive/protocol/IP Group/ACL

Troubleshooting

Symptom Likely cause GUI action
Share missing Wrong endpoint/resource/gateway Check Share Management, Cluster Status and the assigned IP Group
Logon fails DNS/time/trust/ACL Run Domain Diagnostics; verify realm DNS, time, trust and group
VIP reachable; I/O fails CephFS/MDS/OSD/ACL Check Ceph Status, Cluster Drive Management, share access and system logs
VIP does not move Node, gateway or network health Check IP Groups, Cluster Status, maintenance state and alerts
Adoption warning Gateway recreation/CTDB stabilization Review the detailed GUI message, restore Ceph health and retry
PGs peer after time change Clock inconsistency Synchronize all nodes to one DC; wait for healthy Cluster Status

Rollback

If adoption of the eEKAS-managed SMB service fails, preserve Ceph health, review the detailed GUI message and retry the supported workflow. Leaving the domain requires downtime because every node and managed gateway changes.

After rollback verify Ceph, CTDB, VIP placement, share enumeration and read/write access in the GUI and from a client workstation.

euroNAS GmbH · eEKAS-managed SMB with Active Directory · August 2026