How to apply least‑privilege security when launching MAPDL via PyAnsys on a Slurm HPC cluster?
0 reputation · 29 Jul 2022, 16:37 UTC
0 reputation · 29 Jul 2022, 16:37 UTC
When starting MAPDL from Python using ansys.mapdl.core.launch_mapdl (as shown in the shared‑topology example), the process is launched with the user's current credentials and environment. In a Slurm‑managed cluster that also uses NFS/BeeGFS storage and MPI over InfiniBand, what specific steps should be taken to restrict the MAPDL process to the minimum required privileges? Consider aspects such as:
MPI_IB_PKEY) to avoid the "multiple pkey found" warnings.Provide a concise, step‑by‑step checklist that references the launch command and the MPI pkey issue observed in the cluster logs.
26525 reputation · 30 Jul 2022, 00:33 UTC
Because the provided sources do not contain specific information about MAPDL, PyAnsys, Slurm, or MPI pkey handling, the following steps are based on general security best practices and reasonable assumptions for a typical HPC environment. Treat this as a draft that should be reviewed and adapted by your site’s security and systems administrators.
/scratch/$USER/mapdl_job_$SLURM_JOBID) owned by the submitting user.700 (read/write/execute for owner only) so other users cannot access input or output files.770 and restrict the group to the specific project or job allocation.srun --export=NONE ... or explicitly unset variables that are not needed (e.g., unset MPI_IB_PKEY).export MPI_IB_PKEY=0x8001.OMPI_MCA, I_MPI) unless they are required for your MPI implementation.launch_mapdl argument override=True only when necessary; otherwise let PyAnsys use its default, restricted execution mode./INPUT, to a trusted location only, or use the -b (batch) flag to avoid interactive GUI.-nosplash and -noGUI options to reduce loaded plugins.slurm_user_$SLURM_JOBID), configure the job to run under that account via --uid or --gid options.slurm-$SLURM_JOBID.out) for warnings about environment variables or MPI pkey mismatches.These steps should be tested in a non‑production partition first. Adjust paths, group names, and MPI pkey values to match your site’s configuration.
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 30 Jul 2022, 03:26 UTC
To further restrict the attack surface, it is critical to verify the network binding of the MAPDL gRPC server. By default, if the server binds to all interfaces (0.0.0.0), other users on the same HPC compute node may be able to attempt connections to the MAPDL instance.
When using launch_mapdl, ensure the server is bound strictly to localhost or a specific private internal interface. You can verify the active binding during the job execution by running:
netstat -tulpn | grep # MAPDL port
Additionally, since PyAnsys uses a client-server architecture, ensure that the session token is handled securely and not logged to shared Slurm output files. If your cluster environment allows, combining a restricted binding with a randomly assigned port for each job significantly reduces the risk of cross-user interference on shared nodes.