NASLORD is a multi-tenant management and chargeback appliance for Dell storage
platforms. It is distributed as a portable, ready-to-go virtual appliance (OVA) and
provides three integrated managers:
NASLORD Multi-Tenant Manager for Dell PowerScale
OneFS, the operating system running on PowerScale clusters, can isolate end-users
belonging to different tenants (up to fifty separate tenants per cluster, each with
their own subnet, routing, DNS, and security infrastructure). However, OneFS
administration remains centralized and cannot delegate per-Access-Zone management.
NASLORD fills this gap: administrators can delegate full Access Zone management to
designated “Tenant Administrators”, who get a simple and secure way to manage their
own Access Zones — browsing the file system and viewing/creating/editing/deleting
Quotas, Snapshot Schedules, NFS exports and SMB shares — across one or multiple
clusters.
NASLORD Retention Lock Manager for Dell PowerProtect DD
Retention Lock is a PowerProtect DD (Data Domain) feature that makes files immutable
(read-only) until their retention period expires, protecting backup copies even if the
backup server is compromised by ransomware. Most backup solutions cannot use Retention
Lock, or only support one mode of operations.
NASLORD makes Retention Lock usable with any backup application. It automates the
creation of Protected Copies (using the fast, space-efficient fastcopy feature), lets
the storage unit apply and enforce Retention Lock for the selected period, and
automatically deletes older copies whose retention has expired. Both Governance and
Compliance modes are supported.
NASLORD Chargeback Manager for Dell PowerScale and ECS/ObjectScale
ECS and ObjectScale clusters maintain statistics about disk capacity and API
utilisation, but offer no built-in system to define rates, calculate charges based on
actual usage, or produce meaningful reports. The same applies to PowerScale capacity
consumption.
NASLORD provides a comprehensive cost allocation and chargeback solution: it tracks,
manages, and allocates the costs associated with usage of Dell ECS/ObjectScale
namespaces and buckets and (new in 3.0) Dell PowerScale Access Zones, giving IT
administrators and service providers a transparent, detailed view of storage
consumption and enabling accurate and fair billing models for multi-tenant and
enterprise environments.
2.Release notes — what’s new in 3.0.0
Version 3.0.0 is a major release focused on turning the Chargeback Manager into a
complete, automated billing workflow, with first-class Tenant objects, budgets,
scheduled report delivery, and major platform improvements around security and
operations.
Tenant management
Tenants are now first-class objects in NASLORD. Each Tenant carries a name, contact
name, phone number, office address, e-mail address, a dedicated report e-mail
address, notes, an enabled/disabled flag, and a billing currency (USD, CAD, EUR,
GBP, or BRL).
Storage components are associated to Tenants: PowerScale Access Zones and
ObjectScale Namespaces can each be wired to a Tenant (Buckets inherit the Tenant of
their parent Namespace).
Per-tenant monthly reports can be enabled individually.
Chargeback for PowerScale
Chargeback is no longer limited to ECS/ObjectScale. PowerScale Access Zones can now
be charged using dedicated PowerScale Chargeback Profiles, with separate rates (and
rate tiers) for data capacity, protection overhead, and snapshot capacity.
Charge reports and dashboards
Monthly charge reports per Tenant (report period in YYYYMM format), with charge
details and consolidated dashboards for both administrators and tenant users.
Reports can be exported in multiple formats: PDF Summary, PDF Complete/Detailed,
CSV, JSON, and XML.
Reports can be generated in five languages: English, French, Spanish, German, and
Portuguese.
Automated report delivery
Report Destinations: deliver reports by SMTP (e-mail), SFTP, or HTTP POST (with
None/Basic/Bearer/API-Key authentication, custom headers, and TLS verification
options).
Report Routes: bind a Tenant (or all Tenants, globally) to a Destination, choosing
the formats and language; monthly scheduled delivery can be enabled per route, and
routes can also be triggered manually on demand.
Full delivery tracking: report runs and per-destination delivery attempts are
recorded and can be reviewed in the web interface.
Tenant budgets
Budgets can be defined per Tenant with monthly and yearly amounts, a configurable
fiscal-year start month, a start date, and an optional end date.
Budgets can be broken down into components with their own amounts.
Alert thresholds are created automatically at 85% (Warning) and 100% (Critical) of
the budget, and can be adjusted. Threshold crossings can generate e-mail
notifications.
A budget dashboard compares budget versus actual charges, and periodic budget
snapshots build a browsable history (exportable as JSON).
Authentication and security
LDAP authentication: external LDAP providers can be configured, and users can
authenticate locally or via LDAP. Tenants can be mapped to an LDAP base OU and an
LDAP administrator group DN.
Two-factor authentication (TOTP, compatible with standard authenticator apps, with
static backup tokens). 2FA can be enabled or disabled system-wide from the admin
interface.
Login auditing: last authentication timestamp and source IP address are recorded per
user.
Platform and operations
E-mail (SMTP) settings are configurable in the web interface, including a “send test
e-mail” function.
Timezone configuration from the web interface.
Scheduled jobs viewer with execution logs.
Database management: export/import of the configuration database, plus backup
download, restore, and deletion from the web interface.
In-app upgrade: upload a NASLORD upgrade package and apply it from the web
interface. Reboot and shutdown of the appliance can also be performed from the web
interface.
License management page for viewing the installed license and installing new license
keys.
3.Upgrade notes
Upgrading from 2.x: use the in-app upgrade (see section 10) or
deploy a fresh 3.0.0 OVA and re-add your Clusters, Appliances and VDCs.
Back up first. Before upgrading, export the configuration database:
Admin page → Database Management → Export Database. Download the
backup file and store it outside the appliance.
License compatibility: NASLORD validates the license against the product’s major
version. A license issued for version 2.x is not valid on 3.0.0 (unless the license
was issued for “any” version). Contact Gallium to obtain an updated license before
upgrading a production system.
New 3.0 features that send e-mail (report delivery by SMTP, budget threshold
notifications, monthly tenant reports) require SMTP settings to be configured after
the upgrade (Admin page → Email Settings).
4.Known behaviours and limitations
A valid license is required for charge reports. If the license is missing, expired,
or does not cover the relevant products, charge reports are generated
empty (all amounts show as zero). If reports unexpectedly show $0,
verify the license first (Admin page → License).
Demo license limits: one (1) PowerScale Cluster with up to three (3) enabled Access
Zones; one (1) PowerProtect DD Appliance with up to three (3) Primary MTrees; one
(1) ECS/ObjectScale VDC with up to three (3) enabled Namespaces. The demo license is
valid for 90 days. Production licenses have no such limits.
Monthly report timing: the report for the current month covers the period up to
yesterday, and is not available on the 1st day of the month (no data yet). Reports
cannot be generated for future periods.
Capacity charge rounding: ObjectScale capacity is billed per day (the monthly rate
divided by the number of days in the month), and each daily charge is rounded to the
cent. Monthly capacity totals may therefore differ from a simple (capacity × rate)
calculation by a few cents.
The “Default” chargeback profile ships preconfigured, can be modified, but cannot be
deleted. Components without an explicitly assigned profile use the Default profile.
PowerScale Access Zones are discovered automatically when a cluster is added, but
are disabled by default; they must be enabled before they appear
anywhere (including in charge reports).
After creating MTrees or changing Retention Lock parameters on the PowerProtect DD,
use “Refresh Cache”; if MTrees appear in the “Missing MTrees” column, use
“Synchronize MTrees”.
Chargeback profiles applied to a Tenant’s components must all use the Tenant’s
currency; NASLORD blocks mismatched assignments.
5.Requirements
NASLORD is distributed as a portable, ready-to-go appliance.
Virtual machine requirements
The NASLORD OVA requires:
VMware ESXi 6.5 or newer — Gallium recommends ESXi 8.0 or newer
4 GB RAM
16 GB hard disk
1 virtual network adapter
Network requirements
All connections are initiated from NASLORD to the various components,
except for NASLORD’s web interface (inbound HTTPS on port 443).
Network flows used by the NASLORD appliance.
Traffic
Port / protocol
Direction
Web interface (super-users and tenant administrators)
TCP/443
Inbound
DNS (every configured DNS server)
UDP/53
Outbound
PowerScale nodes (API)
TCP/8080 (default)
Outbound
PowerProtect DD appliances (SSH)
TCP/22 (default)
Outbound
PowerProtect DD appliances (API)
TCP/3009 (default)
Outbound
ECS/ObjectScale nodes (API)
TCP/4443 (default)
Outbound
Optional services (only if the corresponding feature is used)
SMTP server port (commonly TCP/25, TCP/465 or TCP/587, outbound) for e-mail delivery
of reports and notifications
TCP/22 (outbound) to SFTP servers used as report destinations
TCP/443 or TCP/80 (outbound) to HTTP POST report destinations
LDAP TCP/389 or LDAPS TCP/636 (outbound) to LDAP authentication servers
Choose the previously downloaded OVA file, enter the VM name and select the
destination folder.
Select the compute resource.
Select the destination storage.
Select the destination network for the virtual network adapter.
Click Next, review the settings, and click Finish.
Wait for the deployment to complete, then power on the virtual machine.
7.Initial configuration
Step 1 — Configure the basic VM settings (console)
In vCenter, click on the NASLORD virtual machine.
Select the “Summary” tab.
Open the VM console.
Log in as: root
Use the default password: changeme
Execute the following command: configure
The first prompt asks if you want to change the root password. Answer: y
— do not keep or reuse the default root password.
Enter the new root password (twice).
The next prompt asks if you want to change the network configuration. Answer: y
You will be asked if you want to use DHCP. Answer y or n —
for production use, Gallium recommends against using DHCP.
If you answered no (static configuration), answer the prompts: hostname (FQDN), IP
address, netmask bits (e.g. 24), default gateway, DNS servers (space-separated
list).
After changing the network settings, rebooting the VM is mandatory.
Execute the following command: reboot
Close the VM console.
Step 2 — First login to the web interface
Open a browser and access NASLORD using its hostname or IP address (HTTPS, port 443).
Log in as user admin. The default password is: changeme
Click on Change Password to set a new password immediately.
Step 3 — Recommended post-install configuration
In the Admin page, review the following before adding storage systems:
Timezone: set the appliance timezone.
Email Settings: configure the SMTP server and send a test e-mail
(required for report delivery by e-mail and budget notifications).
License: verify the license status (see section 8).
Two-Factor Authentication: enable system-wide 2FA if desired.
LDAP: configure an LDAP provider if users will authenticate against
a directory (see the LDAP Configuration Guide).
The appliance is now ready. Refer to the
NASLORD 3.0.0 Administration Guide to add
PowerScale Clusters, PowerProtect DD Appliances and ECS/ObjectScale VDCs, create
Tenants and users, and configure chargeback.
8.Licensing
A demo license is active after installation. The demo license is
valid for 90 days, after which you need to request a production license.
Demo license limits:
One (1) PowerScale Cluster, up to three (3) enabled Access Zones
One (1) PowerProtect DD Appliance, up to three (3) Primary MTrees
One (1) ECS/ObjectScale VDC, up to three (3) enabled Namespaces
Production licenses can be obtained without any Access Zone, Primary MTree or
Namespace limit.
To view the installed license or install a new license key: Admin page → License.
Important: charge reports are generated empty when the license is
missing, expired, or does not cover the product concerned.
To obtain a production license, contact Gallium (see section 12).
Navigate to Admin page → User Management → + Create Local User.
Enter the desired username, first name, last name, email and password.
Enable the “Super-user” checkbox.
Save the user.
Note. Super-users do not need to be explicitly granted access to any
specific Access Zones, MTrees or Namespaces. They automatically have access to all
active Access Zones, MTrees and Namespaces, across all Clusters, Appliances and VDCs
configured in NASLORD.
10.Upgrading NASLORD from the web interface
NASLORD 3.0 supports in-app upgrades:
Export the configuration database first (Admin page → Database Management →
Export Database) and download the backup.
Obtain the NASLORD upgrade package from Gallium.
Navigate to Admin page → Upgrade NASLORD and upload the package.
Review the confirmation screen, then apply the upgrade.
The appliance restarts its services; a reboot needs to be triggered from the web
interface.
If anything goes wrong, the exported database can be re-imported on a freshly deployed
appliance (Admin page → Database Management → Import Database).
11.Virtual machine reconfiguration
How to change the root password or network settings after installation:
Log on to the vCenter web UI.
Click on the NASLORD virtual machine.
Select the “Summary” tab.
Open the VM console.
Log in as root.
Execute the following command: configure
The first prompt asks if you want to change the root password. Answer y
or n; if you answered yes, enter the new root password (twice).
The next prompt asks if you want to change the network configuration. Answer y or n.
If you answered yes, you will be asked if you want to use DHCP. Answer y
or n — for production use, Gallium recommends against
using DHCP.
If you answered no (static configuration), answer the prompts: hostname (FQDN), IP
address, netmask bits (e.g. 24), default gateway, DNS servers (space-separated
list).
If you changed the network settings, reboot the VM: execute reboot.
If you only changed the root password, log out from the terminal: execute exit.
Close the VM console.
12.How to contact Gallium
To inquire about NASLORD or to obtain a quote for a licensed version, please contact us
directly: