How to add new user into CVM? | Nutanix Community
Skip to main content
Question

How to add new user into CVM?

  • September 14, 2022
  • 7 replies
  • 1990 views

Forum|alt.badge.img

Hello Team,

I am new to Nutanix, could you please suggest how to add a new user in CVM via putty? 

 

Thanks,

Rajkumar

7 replies

bcaballero
Forum|alt.badge.img+5
  • Guardian
  • 186 replies
  • September 14, 2022

Hi @rajkumar.miriyala 

 

You shall not create new users on the CVM, please check de Non configurable AHV Components https://portal.nutanix.com/page/documents/details?targetId=AHV-Admin-Guide-v6_5:ahv-nonconfigurable-components-r.html

 

 

Hope this helps

 

Regards!


JeroenTielen
Forum|alt.badge.img+8
  • Vanguard
  • 1349 replies
  • September 14, 2022

SSH to a CVM is done via the nutanix or admin user, not via others user accounts.

 

You can, however, use cluster lockdown to create specific certificates for specific users who need access to the console if you dont want to give the passwords or want to secure ssh access more.


Forum|alt.badge.img

Hi @bcaballero @JeroenTielen ,

Thanks for your quick response, we would like to manage the passwords with CyberArk, so they are asking us to provide another account for the reconciliation task. 

 

Thanks,

Rajkumar


Sergei Ivanov
Nutanix Employee
Forum|alt.badge.img+5
  • Nutanix Employee
  • 108 replies
  • September 20, 2022

It is not supported to create any additional users on the CVMs or AHV hosts. 

Technically, it is possible to use traditional Linux tools (useradd) to create a user, but such user will be quite useless, because most of the Nutanix services and internal tools are bound to nutanix/admin users. Moreover, if you create any user on a CVM, that user will be deleted by the upgrade process next time you upgrade the AOS.


Forum|alt.badge.img

Thanks everyone for your response, I will update the same to the customer.

 

Regards,

Rajkumar


Kcmount
Forum|alt.badge.img+7
  • Vanguard
  • 367 replies
  • October 5, 2022

Hello Rajkumar,

 

I hope you're well.

I too am working with a customer who uses CyberArk and we've had this discussion too!

In the end we agreed to use cluster lockdown and a managed ssh key (private held only within CyberArk) that is brokered on the user requesting behalf. We did raise this with Nutanix and CyberArk too so it will be on their radar.

It's not great and it is something I feel Nutanix could improve upon but it should be quite rare for BAU teams to need to log in via SSH unless investigating a problem.

Prism Pro is plenty helpful for most BAU tasks.

 

Take care,

 

Kim


qamarabbas
Forum|alt.badge.img+4
  • Vanguard
  • 117 replies
  • October 31, 2022

All the services are running under nutanix / admin users , creating any other user is useless.


Reply