# NeuralMesh™ by WEKA documentation

Version 5.1

Welcome to the NeuralMesh documentation portal, your comprehensive guide to the latest version of NeuralMesh by WEKA. Whether you're a newcomer or a seasoned user, explore topics from system fundamentals to advanced optimization strategies for AI and data-intensive workloads.

{% hint style="info" %}
**Terminology and deployment model**

NeuralMesh™ by WEKA introduces a new deployment approach built on the WEKA data platform.

In this documentation, references to WEKA denote the underlying software components and interfaces used by NeuralMesh. Core functionality, APIs, and packages remain consistent.
{% endhint %}

{% hint style="warning" %}
**Important:** This documentation applies to the **latest minor version** (5.1.**X**). For information on new features and supported prerequisites released with each minor version, refer to the relevant release notes available at [get.weka.io](https://get.weka.io/).

Check the release notes for details about any updates or changes accompanying the latest releases.
{% endhint %}

Select your version from the dropdown menu located at the top of the left-hand navigation bar.

<div align="left" data-with-frame="true"><figure><img src="/files/h5qL2rQysSZq6RUmYLWr" alt="" width="169"><figcaption></figcaption></figure></div>

## Get answers from Ask AI

Use the built-in **Ask AI** feature to get answers directly from the documentation. Select **Ask or search** at the top right of any page, type your question, and Ask AI returns a detailed answer based on the documentation content.

Each answer includes:

* **Follow-up questions** to help you explore related topics.
* **Source links** at the bottom of the answer panel, pointing to the documentation pages used to generate the response.

For the best results, ask clear, specific questions.

<details>

<summary>See how it works</summary>

{% embed url="<https://youtu.be/K_Bogag0vKI>" %}

</details>

{% hint style="info" %}
Ask AI is built into the documentation to support your search experience. It might provide inaccurate information. Always verify answers by following the source links included in each response.
{% endhint %}

## About NeuralMesh documentation

This portal encompasses all documentation essential for comprehending and operating NeuralMesh, the software-only, high-performance, container-native storage system built for AI and data-intensive workloads at scale. It covers a range of topics:

**System overview:** Delve into the fundamental components, principles, and architectural elements constituting NeuralMesh, including the Core, Accelerate, Deploy, Enterprise Services, and Observe components that work in unison to power demanding AI pipelines.

**Planning and installation:** Discover prerequisites, compatibility details, and installation procedures for NeuralMesh clusters on bare metal, AWS, GCP, Azure, and Oracle Cloud environments.

**NeuralMesh Axon:** Learn about NeuralMesh Axon converged deployment and maintenance.

**Getting started with NeuralMesh:** Initiate your NeuralMesh journey by learning the basics of managing file systems through the GUI and CLI, executing initial IOs, and exploring the REST API.

**Performance:** Explore the results of FIO performance tests on the NeuralMesh filesystem, ensuring optimal system performance for AI training, inference, and data-intensive workloads.

**Filesystems & object stores:** Understand the role and management of file systems, object stores, file system groups, and key-management systems within NeuralMesh configurations. Learn about integrated tiering, the single namespace architecture, and the data catalog for indexing and querying filesystem metadata at scale.

**Additional protocols:** Learn about the supported protocols—NFS, SMB, and S3—for accessing data stored in a WEKA filesystem.

**Security:** Learn about the supported security features and recommended configurations to protect sensitive data, comply with industry regulations, and reduce the risk of unauthorized access.

**Licensing:** Gain insights into the system licensing options.

**Operation guide:** Navigate through various system operations, including events, statistics, user management, multi-tenancy, upgrades, expansion, and more.

**Monitor the cluster:** Use NeuralMesh Observe to validate performance, monitor cluster health, plan capacity, and troubleshoot your WEKA estate. Local WEKA Home collects telemetry from clusters and clients to support troubleshooting.

**Kubernetes**: The Kubernetes guides cover deploying and managing the WEKA Data Platform. Learn how to use the WEKA Operator for high-performance storage deployment and handle day-2 operations including scaling, hardware management, and performance optimization.

**WEKApod:** Explore the WEKApod Data Platform Appliance Guide for step-by-step instructions on setting up and configuring the WEKApod™. This turnkey solution, designed for NVIDIA DGX SuperPOD, features pre-configured storage and software for quick deployment and faster value.

**AWS solutions**: Learn how to integrate the system with Amazon SageMaker HyperPod to enable high-performance distributed training of large language and foundation models. Explore best practices for configuring storage, optimizing performance, and scaling machine learning workloads in AWS environments.

**Azure solutions**: Learn how to integrate the system with Azure CycleCloud and SLURM scheduler for streamlined HPC cluster management. Learn configuration steps, performance optimization, and architectural patterns for running AI, machine learning, and analytics workloads at scale in Azure environments.

**Best practice guides:** Explore our carefully selected guides, starting with WEKA and Slurm integration, to discover expert-recommended strategies and insights for optimizing your system and achieving peak performance in various scenarios.

**Support:** Find guidance on obtaining support for the system and effectively managing diagnostics.

**Appendices:** Explore the Appendices for various topics, including the CSI Plugin, which connects Kubernetes worker nodes to NeuralMesh, and other tools and procedures that can enhance your work with the system.

{% hint style="info" %}
For maintenance and troubleshooting articles, search the WEKA Knowledge Base in the [WEKA support portal](https://support.weka.io/s/) or contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contacting-weka-technical-support-team).

For product training and certification, see [Register for WEKAdemy](/support/register-for-wekademy).
{% endhint %}

### Conventions

* The documentation marks the CLI mandatory parameters with an asterisk (\*).
* New additions are marked with two asterisks (\*\*) in the relevant topics.

### Documentation feedback

We welcome your feedback to improve our documentation. Include the document version and topic title with your suggestions and email them to <documentation@weka.io>. For technical inquiries, contact our [Customer Success Team](/support/getting-support-for-your-weka-system). Thank you for helping us maintain high-quality resources.


# Documentation revision history

<table><thead><tr><th width="122.96484375">WEKA version</th><th width="609.5859375">Description of changes</th></tr></thead><tbody><tr><td>5.1.31</td><td><p><strong>Multi-tenancy:</strong></p><ul><li><strong>Dedicated POSIX endpoints:</strong> Network spaces now provide isolated POSIX datapath endpoints that support DPDK and RoCE. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/v1U5nVCgcSkCr7CE8puP#network-isolation-through-network-spaces">>></a></li><li><strong>S3 connectivity:</strong> S3 access is available through the cluster default network and each tenant-specific VLAN. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/v1U5nVCgcSkCr7CE8puP#network-isolation-through-network-spaces">>></a></li><li><strong>Multi-tenant S3:</strong> Tenant-scoped S3 buckets and objects use each tenant's security policies and capacity limits. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/v1U5nVCgcSkCr7CE8puP#weka-native-multi-tenancy-key-concepts">>></a></li></ul></td></tr><tr><td>5.1.30</td><td><ul><li><strong>S3 object lock:</strong> New topic. Enable S3 Object Lock to apply write-once-read-many (WORM) protection, preventing objects from being deleted or overwritten for a defined retention period. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/957b163bde22b0ed29a502b73287e87da1265aa8">>></a></li><li><strong>S3 object versioning:</strong> New topic. Enable S3 object versioning to retain multiple versions of an object in a bucket and recover from accidental overwrites or deletions. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/3fd4704ab28202230a4b89ed84b94a1f13867df5">>></a></li><li><strong>S3 health readiness:</strong> Added health readiness for load-based traffic routing, directing client traffic to S3 endpoints based on their current load and health. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/-McsEfIPr09rCb-cDk8_#load-balancer-configuration">>></a></li><li><strong>Data catalog:</strong> New topic. Added Compare storage insights to compare a filesystem between two points in time, showing what changed and which directories drove the change. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/AJ1l2cpE4xTZw8UoPeNY#compare-storage-insights">>></a></li><li><strong>Quota management:</strong> Added REST API endpoints and equivalent CLI commands to create and manage user (UID) and group (GID) quotas. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/-MNHl-A73zrRftNBsDnu">>></a></li><li><strong>NFS:</strong> Changed the default global authentication type from <code>None, SYS</code> to <code>SYS</code>. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/SGog3l6YxJgW0VwWKOmN#configure-the-nfs-global-settings">>></a></li><li><strong>Multi-tenancy:</strong> Added the ability to view alerts scoped to a tenant, so tenant administrators see only the alerts relevant to their tenant. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/LpDveB73QfhozRMle1uo">>></a></li><li><strong>Upgrade:</strong> Added a data catalog index cleanup step that runs before an upgrade to clear stale index data. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/-LHgHMlGaFYAdvqj8D1W#before-you-begin">>></a></li><li><strong>Alerts, events, and statistics:</strong> Updated the alerts, events, and statistics references with the additions and changes introduced in 5.1.30. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/trFdESB8hJk48RMrwFYn">>></a></li><li><strong>CLI reference guide:</strong> Updated the CLI reference guide to reflect new and changed commands. <a href="/spaces/ZW262oqYA8pNNfGvXjHa/pages/sTcAtEp307LVMQGXVNn4">>></a></li></ul></td></tr><tr><td></td><td><p><strong>Local WEKA Home 5.0:</strong></p><ul><li>Added resource-preset and storage-sizing guidance for K3s and Kubernetes deployments. K3s <a href="/pages/WCG8kRpB7jFoBpZ5oXLs">>></a> K8s <a href="/pages/2H0OPjwxZbmrgMmjnpto">>></a></li><li>Updated queue architecture guidance for stats and forwarding.</li><li>Added K3s health-check and diagnostic collection guidance. <a href="/pages/YgiOJhUNAegpzzheL0fu">>></a></li><li>Added a topic export cluster metrics from LWH to Prometheus. <a href="/pages/eE1DzDSUTkVEv80TpQA5">>></a></li><li>Removed the Local WEKA Home on Minikube topic.</li></ul></td></tr><tr><td></td><td><ul><li><strong>WEKAmon:</strong> Removed the WEKAmon documentation. Use Observe for a centralized dashboard. <a href="/pages/PWZaYnt5dP3ULY4pscEm">>></a></li></ul></td></tr><tr><td></td><td><ul><li><strong>WEKA Operator:</strong> Restructures and expands the WEKA Operator documentation. Splits the content into separate concept and task topics, adds an architecture overview, documents the custom resources and their fields, and clarifies the upgrade order. <a href="/pages/Ip3olDFKHcOxqz3gw17w">>></a></li></ul></td></tr><tr><td></td><td><ul><li><strong>CoreWeave SUNK:</strong> New topic. Configure Kubernetes and WEKA for CoreWeave SUNK. <a href="/pages/0OzKEVfLVnQ0DJAs5LG0">>></a></li></ul></td></tr><tr><td>5.1.22</td><td><ul><li><strong>Networking:</strong> Added NVIDIA Mellanox CX-8 as a supported network adapter for backends and clients. <a href="/pages/-MWO-Mez3gxBgmiUml_U#networking-ethernet">>></a></li></ul></td></tr><tr><td>5.1.21</td><td><ul><li><strong>Internal proxy subnet for multi-tenancy:</strong> Added information about the default internal NAT subnet, <code>198.18.0.0/16</code>, used for network spaces. <a href="/pages/UbGXEH3CPHQhJ1yJuBSh#create-a-network-space">>></a></li><li><strong>Per-tenant S3 settings:</strong> Tenant configuration now includes a dedicated S3 settings section with two new per-tenant parameters: a default filesystem used as the fallback when buckets are created through the S3 API, and an anonymous UID/GID for POSIX identity assignment on anonymous or public S3 access. Both were previously configurable only at the cluster level. <a href="/pages/UbGXEH3CPHQhJ1yJuBSh#configure-tenant-s3-settings">>></a></li><li><strong>S3 user management:</strong> Added GUI support to generate and display S3 access keys on S3 user creation, reset S3 credentials from the user actions menu, and clarify that password changes do not rotate S3 API credentials. <a href="/pages/TPmiltxRmEXWWIRSOpD3#reset-s3-credentials">>></a></li><li><strong>Container state and status fields:</strong> New topic. Clarified how to interpret <code>state</code> and <code>status</code> in container and process output from the CLI and REST API. <a href="/pages/3OGIgByEeceipNUzr2tb">>></a></li></ul></td></tr><tr><td></td><td><ul><li><strong>NeuralMesh Observe:</strong> New topic. Validate performance, monitor cluster health, and troubleshoot your WEKA estate from a single SaaS observability interface. <a href="/pages/PWZaYnt5dP3ULY4pscEm">>></a></li></ul></td></tr><tr><td>5.1.20</td><td><ul><li><strong>WEKA native multi-tenancy:</strong> New topic replacing the organizations topics. Logically separate users and resources on a single WEKA cluster with independent LDAP, KMS, and QoS per tenant. <a href="/pages/v1U5nVCgcSkCr7CE8puP">>></a></li><li><strong>Data catalog:</strong> New topic. Manage, index, and query filesystem metadata for macro-level insights and granular data discovery at scale. <a href="/pages/luYpgIxgTeIL6DIzardl">>></a></li><li><strong>Quota management:</strong> Added user and group level quotas. Assign quotas per user (UID) or group (GID) to limit total capacity consumed across the entire filesystem. When user, group, and directory quotas all apply, the most restrictive limit is enforced. <a href="/pages/-MNHl-A73zrRftNBsDnu">>></a></li><li><strong>S3 OIDC:</strong> New topic. Configure S3 OIDC authentication to let users and applications authenticate with your identity provider and receive temporary S3 credentials, without static access keys. <a href="/pages/dbbc5b86fd339e03e635c23287b9b5f7b2b1d48b">>></a></li><li><strong>S3:</strong> Added support for URLs as valid object keys, for example <code>https://company.com/id</code>, expanding compatibility with AWS S3-native applications. <a href="/pages/-MccbmCmuJ3cB9-70C6S#url-formatted-object-keys-in-weka-s3">>></a></li><li><strong>S3:</strong> Removed the default filesystem from the installation. Removed the <code>key</code> and <code>secret</code> parameters.</li><li><strong>KMS:</strong> Added OpenBao Vault 2.5.1 or later as a supported KMS type. References to HashiCorp Vault throughout the documentation also apply to OpenBao Vault.</li><li><strong>CIDR policies:</strong> Added squash mode. Squash mode defines how the storage system maps incoming UIDs and GIDs to manage access permissions. <a href="/pages/Hb098q8l9Df52NhIH5dx">>></a></li></ul></td></tr><tr><td></td><td><ul><li><strong>GCP:</strong> Added the Z3 machine types support to backends and clients with gVNIC. <a href="/pages/HiMwWwYb2B4bonvgIuVW">>></a></li><li><strong>LWH integrations:</strong> Added Syslog (RFC 5424) integration to send events and alerts. Applies to Local WEKA Home version 4.4.1 and higher. <a href="/pages/HiMwWwYb2B4bonvgIuVW">>></a></li><li><strong>WEKA Operator:</strong> Added new topic on migrating standalone CSI to WEKA Operator-embedded. <a href="/pages/BQDn7RnYBDNsSjIZlqqX">>></a></li><li><strong>WEKA Operator operations:</strong> Updated Cluster Maintenance with instructions for pausing and resuming clusters and canceling cluster deletion. <a href="/pages/QNv3k9RvXhD865vSmZJQ#pause-and-resume-weka-cluster-for-maintenance">>></a></li><li><strong>LWH stats:</strong> Added new topic covering sizing and performance optimization guidelines. <a href="/pages/Kp4Ainxgvm0tFSMStjHU">>></a></li><li><strong>NeuralMesh AXON:</strong> Added new topic on maximizing GPU infrastructure resilience. <a href="/pages/5yh0ZGuAi8JFetUh9uq8">>></a></li><li><strong>KMS:</strong> Added OpenBao 2.5.1 to the supported KMS list. It is fully compatible with HashiCorp Vault.</li></ul></td></tr><tr><td>5.1</td><td><ul><li><strong>Alerts:</strong> Expanded mute capabilities to include global suppression by alert type and targeted suppression by component, process, container, or server.</li><li><strong>Drives sharing:</strong> Added a new topic on drive sharing configuration. Configure drive sharing across multiple Drive IO processes to improve performance and enable multi-tenancy in the storage cluster.</li><li><strong>Networking:</strong> Updated port range requirements from 100 to 60 and added advanced network configuration for stateless clients, including IPv6 support.</li><li><strong>Snapshots/diff REST API:</strong> Simplified the feature setup by removing the manual debug override prerequisite. The DiffList feature is now enabled by default.</li><li><strong>Local WEKA Home:</strong> Added a new topic on remote debugging management through <code>homecli</code> for K3s deployments. Added the <code>remote-access</code> command group to enable secure, real-time troubleshooting sessions with the WEKA Customer Success Team.</li><li><strong>Platform:</strong> Removed the cgroup v2 limitation for backends and protocol clients. WEKA now supports cgroup v2 on backends and clients, including protocol cluster deployments.</li><li><strong>WEKA Operator:</strong> Updated HugePages calculation guidelines for worker nodes and optimized port pool management, reducing the default port allocation from 500 to 260 per cluster, starting at port 35000.</li><li><strong>NFS:</strong> Added new topic on setting host-based LDAP resolution for NFS group membership using the <code>weka nfs ldap setup-onhostldap</code> command.</li></ul></td></tr></tbody></table>


# Introduction

Discover how NeuralMesh delivers a software-only, high-performance, container-native storage system built for AI and data-intensive workloads at scale.

## Overview

NeuralMesh™ by WEKA is a software-only, high-performance, container-native storage system built for AI and data-intensive workloads at scale. It delivers low-latency, high-throughput data access with a microservices-based architecture that scales linearly and becomes more efficient as system size grows.

NeuralMesh redefines storage solutions by eliminating the performance bottlenecks inherent in legacy architectures. Built entirely from scratch as a fully distributed parallel filesystem, it runs on standard x86 and ARM infrastructures across on-premises, public cloud, and hybrid cloud environments without the need for custom hardware configurations. This software-only approach allows seamless integration of technological advancements without disruptive upgrades.

The design philosophy behind NeuralMesh was to create a single storage architecture that delivers the performance of all-flash arrays, the simplicity and feature set of Network-Attached Storage (NAS), and the scalability and economics of the cloud in a single unified system.

Use cases span demanding environments requiring shareable storage with low-latency, high-performance, and cloud scalability, including:

* AI/ML Inferencing and Training
* Agentic AI
* Life Sciences (genomics, Cryo-EM, pharmacometrics)
* Financial Trading
* Risk Analysis
* Engineering DevOps
* EDA
* Media Rendering
* Industrial/CAE (including computational chemistry and quantum chemistry simulations)
* HPC (tightly-coupled workloads)
* HTC (high throughput computing for loosely-coupled workloads, grid computing, and batch jobs)
* GPU pipeline acceleration.

By leveraging existing technologies in new ways and augmenting them with engineering innovations, NeuralMesh delivers a more powerful and simpler solution that traditionally would have required several disparate storage systems. The resulting software solution delivers high performance for all workloads—big and small files, reads and writes, random, sequential, and metadata-heavy operations. For example, before a read or write can happen, a file must be opened—and this open operation is a metadata operation that NeuralMesh handles efficiently alongside data operations.

NeuralMesh leverages NVMe Flash for the highest performance file services and integrates seamlessly with object storage, combining near memory-like flash performance with cost-effective economics. This transparent integration extends the namespace, enabling use cases like archiving and data protection without requiring manual data migration, external tools, or complex scripting. An intuitive graphical user interface allows a single administrator to manage exabytes of data quickly and easily without specialized storage training.

Benefits include high performance across all IO profiles, linear scalability, robust security, hybrid cloud support, private/public cloud backup, and cost-effective flash-object storage combination. NeuralMesh ensures a cloud-like experience, seamlessly transitioning between on-premises and cloud environments.

### NeuralMesh architecture components

NeuralMesh is composed of containerized microservices running within a Linux container (LXC), managed through the Kubernetes Operator. The system is organized into five key architectural components working in unison:

**Core – distributed, resilient, and self-optimizing:** The foundation that intelligently distributes data and metadata across the system, automatically balancing I/O to prevent hotspots. With built-in auto-healing, auto-scaling, and rapid rebuild capabilities, Core ensures high availability and durability at petabyte scale and beyond.

**Accelerate – consistent high-performance data access:** Establishes ultra-low latency, direct paths between compute and data by distributing both data and metadata across the entire system. This eliminates performance bottlenecks, ensures linear scalability, and maximizes GPU utilization.

**Deploy – run anywhere, scale everywhere:** Ensures the data layer can go wherever AI runs, whether building AI Factories on bare metal, deploying across multi-cloud environments, or scaling inference at the edge, with full architectural consistency. NeuralMesh can be deployed as dedicated storage servers or with NeuralMesh™ Axon™, which runs directly on GPU servers to leverage unused CPU cores and NVMe drives, eliminating external storage requirements while reducing footprint and power consumption.

**Enterprise services – secure, optimized, and feature-rich:** Delivers advanced security, encryption, data protection, and data management features, including performance-enhancing capabilities like zero-copy and zero-tuning data access.

**Observe – intelligent, scalable observability:** Provides deep, real-time insight into system performance, I/O behavior, and resource utilization for proactive issue resolution and efficient optimization.

<div data-with-frame="true"><figure><img src="/files/M8qvgNptIeNetkwr9aUG" alt=""><figcaption><p>The NeuralMesh architecture components</p></figcaption></figure></div>

### NeuralMesh software-based storage architecture

The system comprises the following software components:

* **Frontend (FE) processes:** Manage multi-protocol connectivity for POSIX, NFS, SMB, and S3 client access, and handle I/O communication to compute and drive processes
* **Compute processes:** Manage data distribution, data protection, filesystem metadata services, clustering, and tiering
* **Drive processes:** Transform SSDs into efficient networked devices, managing I/O to and from physical drives
* **Management processes:** Manage events, CLI, statistics, and system monitoring
* **Telemetry processes:** Handle auditing and logging

By running in user space within Linux containers and bypassing the kernel, NeuralMesh achieves faster, lower-latency performance that is portable across bare-metal, VM, containerized, and cloud environments. Efficient resource consumption minimizes latency and optimizes CPU usage, offering flexibility in shared or dedicated environments.

<div data-with-frame="true"><figure><img src="/files/lxIftqSQHFAPiYCwHBGK" alt=""><figcaption><p>NeuralMesh software-based storage architecture</p></figcaption></figure></div>

NeuralMesh's design departs from traditional NAS solutions by introducing multiple filesystems within a global namespace that share the same physical resources. Each filesystem has its unique identity, allowing customization of snapshot policies, tiering, role-based access control (RBAC), quota management, and more. Unlike other solutions, filesystem capacity adjustments are dynamic, enhancing scalability without disrupting I/O.

NeuralMesh offers a robust, distributed, and highly scalable storage solution, allowing multiple application servers to access shared filesystems efficiently with strong consistency and full POSIX compliance.

**Related information**

[NeuralMesh by WEKA Architecture White Paper](https://www.weka.io/resources/white-paper/wekaio-architectural-whitepaper/)

### NeuralMesh Axon

NeuralMesh Axon is the specialized converged deployment mode engineered for large-scale AI and agentic workloads. By co-locating storage and compute services directly on GPU servers, Axon leverages unused CPU cores and local NVMe drives to eliminate external storage footprints. This configuration is optimized for microsecond-level latency and massive throughput, ensuring high performance for distributed GPU environments.

**Related information**

[NeuralMesh Axon overview](/neuralmesh-axon/neuralmesh-axon-overview)

### Standard converged deployment

In addition to the AI-optimized NeuralMesh Axon, the system offers a standard converged deployment configuration for general-purpose workloads. This option is ideal for environments that require the full breadth of NeuralMesh connectivity features, including NFS, SMB, and S3 protocols. which are not available in the specialized Axon configuration.

In this configuration, NeuralMesh clients installed on application servers access the storage cluster while simultaneously hosting backend processes and local SSDs. These backend processes function collectively as a single, distributed, and scalable filesystem that shares the same physical infrastructure as the user applications.

**Key considerations**

* **Resource efficiency:** Combining storage and compute maximizes infrastructure utilization.
* **Flexibility:** The cluster can be heterogeneous, comprising some servers with both storage processes and clients, and others with clients only.
* **Availability and durability:** Even in the event of an application server reboot or failure, the system's robust N+2 and N+4 protection schemes seamlessly maintain data availability and durability. With RAFT-9 support, the architecture can tolerate up to 4 concurrent node failures without losing cluster availability, ensuring that the co-located storage backend remains resilient without disrupting operations.

This deployment mode mirrors the functionality of the standard dedicated architecture, delivering the same robust features for data protection, failure domains, and linear scalability.

***

## NeuralMesh system functionality features

NeuralMesh offers a range of powerful functionalities designed to enhance data protection, scalability, and efficiency, making it a versatile solution for various storage requirements.

### Protection

NeuralMesh employs N+2 or N+4 data protection, ensuring data protection even in the face of concurrent drive or backend failures. This distributed protection scheme is determined during cluster formation and can vary, offering configurations starting from 5+2 up to 16+4 for larger clusters. The system protects data at the failure domain level, typically a single server, with data broken into 4KB chunks aligned with NVMe SSDs and distributed across failure domains.

### Distributed network scheme

NeuralMesh incorporates an any-to-any protection scheme that ensures rapid recovery of data in the event of a backend failure. Unlike traditional storage architectures where redundancy is established across backend servers, NeuralMesh leverages distributed data stripes to protect one another within the entire cluster of backends.

**How it works:**

**Data recovery process:** If a backend within the cluster experiences a failure, NeuralMesh initiates a rebuilding process using all other operational backends. These healthy backends work collaboratively to recreate the data that originally resided on the failed backend. Importantly, all this occurs in parallel, with multiple backends simultaneously reading and writing data.

**Speed of rebuild:** This approach results in a speedy rebuild process. In traditional storage setups, only a small subset of backends or drives actively participate in rebuilding, often leading to slow recovery. In contrast, with NeuralMesh, all but the failed backend are actively involved, ensuring swift recovery and minimal downtime.

**Scalability benefits:** The advantages of this distributed network scheme become even more apparent as the cluster size grows. In larger clusters, the rebuild process is further accelerated. The highly randomized data placement methodology means that as cluster size grows, the probability of any two failure domains sharing a chunk of the same data stripe goes down exponentially, making NeuralMesh more resilient as it scales—an ideal choice for organizations handling substantial data volumes without sacrificing data availability.

In summary, NeuralMesh's distributed network scheme transforms data recovery by involving all available backends in the rebuild process, ensuring speedy and efficient recovery. This efficiency scales with larger clusters, making it a robust and scalable solution for data storage and protection.

### Efficient component replacement

In NeuralMesh, a virtual hot spare is configured within the cluster to provide the additional capacity needed for full recovery after a rebuild across the entire cluster. This differs from traditional approaches where specific physical components are designated as hot spares. For instance, in a 100-backend cluster, sufficient capacity is allocated to rebuild the data and restore full redundancy even after two failures. Depending on the protection policy and cluster size, the system can withstand additional failures.

This strategy for replacing failed components does not compromise system reliability. In the event of a system failure, there's no immediate need to physically replace a failed component to recreate the data. Instead, data is promptly regenerated, while replacing the failed component with a working one is a background process.

### Enhanced fault tolerance with failure domains

In NeuralMesh, failure domains are groups of backends that could fail due to a single underlying issue. For instance, if all servers within a rack rely on a single power circuit or connect through a single ToR switch, that entire rack can be considered a failure domain. Imagine a scenario with ten racks, each containing five NeuralMesh backends, resulting in a cluster of 50 backends.

To enhance fault tolerance, you can configure a protection scheme, such as 6+2 protection, during cluster setup. This makes NeuralMesh aware of these possible failure domains and creates a protection stripe across the racks. This means the 6+2 stripe is distributed across different racks, ensuring that the system remains operational even in case of a complete rack failure, preventing data loss.

It's important to note that the stripe width must be less than or equal to the count of failure domains. For instance, if there are ten racks and one rack represents a single point of failure, having a 16+4 cluster protection is not feasible. Therefore, the level of protection and support for failure domains depends on the stripe width and the chosen protection scheme.

### Prioritized data rebuild process

In the event of a failure in NeuralMesh, the data recovery process begins by reading all affected data stripes, reconstructing the lost data, and restoring full protection. If multiple failures occur, the affected stripes can be categorized as follows:

* Stripes unaffected by any of the failed components, requiring no action
* Stripes affected by one of the failed components
* Stripes affected by multiple failed components

Typically, the number of stripes affected by multiple failed components is significantly smaller than those affected by a single failed component. However, if any of these multi-affected stripes remain unrecovered, additional failures could lead to data loss.

To mitigate this risk, NeuralMesh employs a prioritized rebuild process. The system first restores stripes affected by the greatest number of failed components, as these are fewer in number and can be recovered quickly. Once these high-risk stripes are rebuilt, the system proceeds with restoring stripes impacted by fewer failures. This structured approach ensures that the probability of data loss remains low while maintaining system performance and availability.

### Seamless distribution, scaling, and enhanced performance

In NeuralMesh, every client installed on an application server directly connects to the relevant backends that store the required data. There's no intermediary backend that forwards access requests. Each NeuralMesh client maintains a synchronized map specifying which backend holds specific data types, creating a unified configuration shared by all clients and backends.

When a NeuralMesh client attempts to access a particular file or offset in a file, a cryptographic hash function guides it to the appropriate backend containing the needed data. This unique mechanism enables NeuralMesh to achieve linear performance growth, synchronizing scaling size with scaling performance for remarkable efficiency.

For instance, when new backends are added to double the cluster's size, the system instantly redistributes part of the filesystem data between the backends, resulting in an immediate performance increase. Complete data redistribution is unnecessary even in modest cluster growths, such as moving from 100 to 110 backends. Only a fraction (10% in this example) of the existing data is copied to the new backends, ensuring a balanced distribution and active participation of all backends in read operations.

The speed of these seamless operations depends on the capacity of the backends and network bandwidth. Importantly, ongoing operations remain unaffected, and the system's performance improves as data redistribution occurs. The finalization of the redistribution process optimizes both capacity and performance, making NeuralMesh an ideal choice for scalable and high-performance storage solutions.

### Efficient data reduction

NeuralMesh offers a cluster-wide data reduction feature that can be activated for individual filesystems. This capability employs block-variable differential compression and advanced similarity-based deduplication techniques across all filesystems to significantly reduce the storage capacity required for user data, resulting in substantial cost savings.

The effectiveness of the compression ratio depends on the specific workload. It is particularly efficient when applied to text-based data, large-scale unstructured datasets, log analysis, databases, code repositories, sensor data, and AI workloads. NeuralMesh's real-time compression utilizes dynamic dictionaries and similarity hashes to deliver efficient, low-overhead data processing, achieving compression ratios up to 8x for workloads like EDA and 10x for AI Inferencing, while maintaining consistent performance with minimal latency impact.


# Cluster capacity and redundancy management

Effective cluster capacity and redundancy management are crucial for ensuring data protection, availability, and optimal performance in WEKA systems. This involves understanding key capacity metrics, redundancy configurations, and the system's mechanisms for handling failures.

## Key capacity terms

Understanding the terminology related to storage capacity is fundamental:

* **Raw capacity**: This represents the total physical storage capacity of all SSDs assigned to a WEKA cluster. For example, if a cluster has 10 SSDs, each with 1 terabyte of capacity, the raw capacity is 10 terabytes. This figure automatically adjusts when more servers or SSDs are integrated into the cluster.
* **Net (usable) capacity**: This is the actual space available on the SSDs for storing user data. The net capacity is derived from the raw capacity and is influenced by several factors:
  * The chosen stripe width and protection level, which dedicate some capacity to system protection.
  * The allocation for hot spares, reserved for redundancy and rebuilds.
  * The WEKA cluster reserved capacity, allocated for internal system operations.
* **Provisioned capacity**: This refers to the total capacity that has been assigned to filesystems within the WEKA cluster. It includes capacity from both SSDs and any configured object stores.
* **Available capacity**: This is the remaining net capacity that can be used to allocate additional capacity to existing filesystems and create new filesystems . It is calculated by subtracting the provisioned capacity from the net capacity.

## Redundancy and protection levels

WEKA employs a distributed RAID system that supports a range of redundancy configurations. These are based on a **D+P model**, where D represents the number of data blocks and P represents the number of parity blocks. Common configurations are denoted as N+2, N+3, or N+4, where N is the number of data blocks. A critical rule is that the number of data blocks must always be greater than the number of parity blocks (for example, a 3+3 configuration is not allowed).

The selection of an appropriate redundancy level is a balance between fault tolerance, usable storage capacity, and system performance:

* **N+2**: This is the recommended level for most environments, providing a standard degree of fault tolerance. A system with protection level 2 can survive up to 2 simultaneous drive or server failures.
* **N+3**: This level offers increased data protection and is suitable for environments with higher availability requirements. A system with protection level 3 can survive up to 3 simultaneous drive or 2 simultaneous server failures.
* **N+4**: Designed for very large-scale clusters (typically 100+ backend servers) or for scenarios involving critical data that demands maximum redundancy. Protection level 4 can withstand up to 4 simultaneous drive failures or 2 simultaneous server failures.

Higher protection levels inherently provide better data durability and availability. However, they also consume more raw storage space for parity blocks and can potentially impact system performance due to the additional processing.

The protection level for a WEKA cluster is determined at the time of its formation and **cannot be changed later**. If no specific protection level is configured, the system defaults to protection level 2.

## Stripe width

**Stripe width** refers to the total number of blocks, both data and parity, that constitute a common protection set. In a WEKA cluster, the stripe width can range from 5 to 20 blocks. This total is composed of 3 to 16 data blocks and 2 to 4 parity blocks. For instance, a stripe width of 18 could represent a configuration of 16 data blocks and 2 parity blocks (16+2).

WEKA uses a **distributed any-to-any protection** scheme. This means that instead of data and parity blocks being confined to fixed protection groups, for example, a specific set of drives, they are distributed across multiple servers in the cluster. For example, in a configuration with a stripe width of 8 (6 data blocks and 2 parity blocks), these 8 blocks are spread across various servers to enhance resilience.

Like the protection level, the stripe width is also determined during the initial cluster formation and **cannot be altered subsequently**. The stripe width has a direct impact on both system performance (especially write throughput) and the usable storage capacity. Larger stripe widths generally improve write throughput because they reduce the proportion of parity overhead in write operations. This is particularly beneficial for high-ingest workloads, such as initial data loading or applications where most of the work involves writing new data.

## Hot spare capacity

WEKA clusters proactively reserve a portion of the total storage space as **virtual hot spare capacity** to ensure that resources are immediately available for data rebuilds in the event of component failures. By default, WEKA allocates 1/N of the total space for this purpose. For example, a 3+2 redundancy configuration is effectively deployed as 3+2+1, meaning one-sixth of the cluster's capacity is reserved as hot spare.

The hot spare capacity represents the number of failure domains the system can afford to lose and still successfully perform a complete data rebuild while maintaining the system's net capacity. All failure domains in the cluster actively contribute to data storage, and this hot spare capacity is evenly distributed among them.

If not explicitly configured by the administrator, the hot spare value is automatically set to 1. While a higher hot spare count provides greater flexibility for IT maintenance and hardware replacements, it also necessitates additional hardware to achieve the same net usable capacity.

## WEKA cluster reserved capacity ratio

After accounting for the capacity dedicated to data protection (parity) and hot spares, an additional **10 percent** of the remaining capacity is reserved for WEKA cluster internal use.

## Failure domains

A **failure domain** is defined as a set of WEKA servers that are susceptible to simultaneous failure due to a single root cause. This could be, for example, a shared power circuit or a common network switch malfunction.

A WEKA cluster can be configured with either:

* **Explicit failure domains**: In this setup, blocks that provide mutual protection for each other (i.e., data and its corresponding parity) are deliberately distributed across distinct, administrator-defined failure domains.
* **Implicit failure domains**: In this configuration, data and parity blocks are distributed across multiple servers, and each server is implicitly considered a separate failure domain. Additional failure domains and servers can be integrated into existing or new failure domains.

{% hint style="info" %}
The documentation generally assumes a homogeneous WEKA system deployment, meaning an equal number of servers and identical SSD capacities per server in each failure domain. For guidance on heterogeneous configurations, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}

## SSD net storage capacity calculation

The formula for calculating the SSD net storage capacity is:

<div data-with-frame="true"><figure><img src="/files/gKhDMFvczAgQDV9CJN3D" alt=""><figcaption></figcaption></figure></div>

**Examples**:

**Scenario 1**: A homogeneous system of 10 servers, each with 1 terabyte of raw SSD capacity (total 10TB raw capacity). The system is configured with 1 hot spare and a protection scheme of 6+2 (6 data blocks, 2 parity blocks).

<div data-with-frame="true"><figure><img src="/files/AMweY8d0IfOEv15QfvZa" alt="" width="563"><figcaption></figcaption></figure></div>

**Scenario 2**: A homogeneous system of 20 servers, each with 1 terabyte of raw SSD capacity (total 20TB raw capacity). The system is configured with 2 hot spares and a protection scheme of 16+2 (16 data blocks, 2 parity blocks).

<div data-with-frame="true"><figure><img src="/files/FVBixENVaz5drhUpzCn3" alt="" width="563"><figcaption></figcaption></figure></div>

## Performance and resilience during failures

### **Data rebuilds**

When a component like a drive or server fails, WEKA initiates a rebuild process to reconstruct the missing data. Rebuild operations are primarily **read-intensive**, as the system reads data from the remaining drives in the affected stripes to reconstruct the lost information.

While read performance may experience a slight degradation during this process, **write performance generally remains unaffected**, as the system can continue writing to the available backend servers.

A critical optimization in WEKA's rebuild process is its behavior when a failed component comes back online. If a failed drive or server returns to an operational state *after* a rebuild has commenced, the rebuild process is **automatically aborted**.

This intelligent approach prevents unnecessary data movement and allows the system to quickly restore normal operations, especially in cases of transient failures (for example, servers returning from a brief maintenance window). This significantly differentiates WEKA from traditional systems that often continue lengthy rebuild processes even after the underlying fault has been resolved.

### **Resilience to serial failures**

Beyond the configured simultaneous failure protection (N+2, N+3, or N+4), a WEKA cluster also exhibits resilience to [**serial failures**](#user-content-fn-1)[^1] of additional failure domains. This means that as long as each data rebuild operation completes successfully and there is sufficient free NVMe capacity in the cluster, the system can tolerate subsequent individual server failures.

For example, consider a cluster of 20 servers with a stripe width of 18 (16+2). After successfully rebuilding from a simultaneous failure of 2 servers, the cluster is still resilient to two additional simultaneous server failures. If further serial server failures occur, the system attempts to rebuild its data stripes using the remaining healthy servers to maintain the required stripe width (for example, 18).

This process can continue, subject to sufficient NVMe space, until a lower limit of healthy servers is reached (for example, 9 servers in the 16+2 example). Failures beyond this critical threshold will result in the filesystem going offline.

In the event of serial server failures coupled with insufficient NVMe capacity to complete rebuilds, the cluster attempts to **tier data** that currently resides on NVMe out to its configured object stores. This is called [**backpressure mode**](#user-content-fn-2)[^2] where the tiering does not consider the age of the data (unlike normal, orderly tiering) but instead tiers data in an approximately random fashion. This process prioritizes data integrity by offloading data to an object store when NVMe available capacity is critically low.

### Minimum required healthy servers

The stripe data width and the protection level (number of data and parity blocks) determine the minimum number of healthy servers required for the cluster to remain operational. This can be represented by the following formula:

<div data-with-frame="true"><figure><img src="/files/edAiMVRomcxIr4pWeb29" alt="" width="531"><figcaption></figcaption></figure></div>

**Examples:**

| Stripe data width + protection level | Minimum required healthy servers |
| ------------------------------------ | -------------------------------- |
| 5+2                                  | 4                                |
| 16+2                                 | 9                                |
| 5+4                                  | 3                                |
| 16+4                                 | 5                                |

### Failure domain folding

In scenarios where hardware failures persist and components are not replaced promptly, WEKA employs a process called **failure domain folding** to maintain write availability. This process temporarily relaxes the standard requirement that each RAID stripe must span only distinct failure domains (for example, one block per backend storage server within a stripe).

By allowing a single failure domain to effectively appear multiple times within a newly allocated stripe, the system can continue to allocate new stripes and accept write operations even when in a degraded state.

Failure domain folding is automatically triggered when the number of active (healthy) failure domains becomes insufficient to satisfy the original stripe width requirement. This typically occurs due to server deactivation or the loss of multiple drives. This adaptive approach ensures that the system can remain operational and continue to accept writes during extended fault conditions, without necessitating immediate hardware replacement.

The process can be visualized in three stages:

1. **Stage A: Normal operation (all drives active)**: In the initial state, all backend storage servers are operational. Each server is treated as a distinct failure domain. RAID stripes, consisting of data (yellow blocks) and parity (purple blocks), span horizontally across all available failure domains. New stripe allocations proceed normally, utilizing free space across all failure domains. The system is configured with hot spare capacity (equivalent to two full servers) allocated across the system.
2. **Stage B: write blocking after a drive failure**: When a single drive fails, any new stripe that must span all failure domains can no longer be allocated if any one domain lacks sufficient space due to the failure. Even though only one drive has failed, this strict allocation requirement can effectively block new writes. This results in a disproportionate loss of writable capacity relative to the actual size of the failure, particularly noticeable in systems with fewer drives per server.
3. **Stage C: Write recovery through failure domain folding**: To mitigate the blocked write condition, the affected storage server (failure domain) can be manually deactivated. This allows WEKA to apply failure domain folding. The system relaxes the one-domain-per-stripe rule, permitting the reuse of the same failure domain within a newly allocated stripe. This mechanism restores write capability without requiring immediate hardware replacement, ensuring continued system operation under degraded conditions.

<div data-with-frame="true"><figure><img src="/files/81uEe1ZTCuy1IdtKwxRa" alt=""><figcaption><p>Failure domain in action (example)</p></figcaption></figure></div>

[^1]: **Serial failures:** Refers to a sequence where each data rebuild finishes before another server fails, ensuring one-at-a-time failure handling.

[^2]: Backpressure mode is an emergency response that helps a system continue functioning by offloading data to secondary storage when primary storage is insufficient.


# Filesystems, object stores, and filesystem groups

Learn how filesystems, object stores, and filesystem groups work together to organize storage capacity, tiering, and policy in a WEKA cluster.

## Storage entities overview

Filesystems, object stores, and filesystem groups define how WEKA organizes storage capacity, data placement, and policy. A filesystem presents data to applications. A filesystem group defines the shared capacity and tiering boundaries for its member filesystems. An object store extends capacity for tiered data and snapshot workflows.

* **Filesystem:** A logical storage namespace that distributes data across the cluster.
* **Object store:** An external storage tier that stores warm data and snapshots.
* **Filesystem group:** A shared policy boundary that controls how member filesystems use capacity and tiering.

Every filesystem belongs to one filesystem group. Tiered filesystems can attach object store buckets according to the policies and limits defined for that group.

### Thin provisioning **in** WEKA filesystems

Thin provisioning is a method of SSD capacity allocation where administrators define two key values for each filesystem:

* A minimum guaranteed capacity.
* A maximum capacity limit (which can virtually exceed the available physical SSD capacity).

The system automatically manages capacity between these bounds:

* When a filesystem exceeds its minimum capacity, it can grow up to the maximum capacity limit, provided physical SSD space is available.
* When data is deleted or transferred, unused space is automatically reclaimed and made available to other filesystems that need it.

This approach benefits several scenarios:

* **Tiered filesystems:** Available SSD capacity provides performance benefits and can be released to the object store when other filesystems need it.
* **Auto-scaling groups:** The filesystem's SSD capacity automatically expands and shrinks between the defined minimum and maximum values when using auto-scaling groups.
* **Filesystems separation per project:** Administrators can create separate filesystems for each project with defined minimum capacities. Each filesystem can grow beyond its minimum (up to its maximum) based on available physical SSD capacity, enabling efficient resource sharing when not all filesystems need their maximum capacity simultaneously.

### WEKA filesystem limits

* **Number of filesystems:** up to 1024
* **Number of files or directories:** Up to 6.4 trillion (6.4 \* 10^12)
* **Number of files in a single directory:** Up to 6.4 billion (6.4 \* 10^9)
* **Total capacity with object store:** Up to 14 EiB
* **Total SSD capacity:** Up to 1 EiB
* **File size:** Up to 4 PiB

### Data reduction **in** WEKA filesystems

Data reduction is a cluster-wide feature that you can activate for individual filesystems. This feature uses block-variable differential compression and advanced deduplication techniques across all enabled filesystems. The result is a significant reduction in the storage capacity required for user data, which can lead to substantial cost savings. The capacity savings from a data reduction-enabled filesystem are returned to the cluster, not to the filesystem itself.

The effectiveness of the data reduction ratio depends on the workload. It is particularly effective for text-based data, large-scale unstructured datasets, log analysis, databases, code repositories, and sensor data.

Data reduction applies only to user data, not metadata, on a per-filesystem basis.

For example, the image below shows a cluster with a total physical SSD capacity of 979.2 TB. Thanks to data reduction, the cluster achieves a Data Reduction Ratio of 2.78:1, which results in 574.6 TB of saved capacity. This saving allows the cluster to have 1.6 PB of provisioned space, which is 159% of the actual physical capacity.

<div data-with-frame="true"><figure><img src="/files/AvYtdVg0LtpS1TJaIuRq" alt="" width="422"><figcaption><p>Data reduction capacity saving</p></figcaption></figure></div>

#### Prerequisites

To enable data reduction on a filesystem, the following conditions must be met:

* The filesystem is thin-provisioned.
* The filesystem is non-tiered.
* The filesystem is not encrypted.
* The cluster has a valid Data Efficiency Option (DEO) license.

#### How data reduction operates

Data reduction is a post-process, background activity with a lower priority than user I/O requests. When new data is written to a filesystem with data reduction enabled, it is initially stored uncompressed. The reduction process begins automatically as a background task once a sufficient amount of data accumulates.

The data reduction process during write involves the following tasks:

1. **Fingerprinting and ingestion:** As data is written, the system performs fingerprinting by calculating similarity hashes. A background ingest task then uses these hashes to find similar data blocks across all filesystems that have data reduction enabled. This technique, known as clusterization, operates at the 4K block level to identify similarities.
2. **Compression:** The system reads the similar and unique data blocks and compresses them. The newly compressed data is then written back to the filesystem.
3. **Defragmentation:** After data is successfully compressed, the original, uncompressed blocks are marked for deletion. A defragmentation process waits for a sufficient number of these blocks to be invalidated and then permanently deletes them, freeing up SSD capacity.

<div data-with-frame="true"><figure><img src="/files/VcqeVYBOPRuYUD1mqp5r" alt=""><figcaption><p>Data reduction process during write at a glance</p></figcaption></figure></div>

The data reduction process during read involves decompressio&#x6E;**.** When a client reads compressed data, the system performs decompression inline as part of the read operation. This decompression is handled by the drive containers.

#### Performance monitoring

You can monitor the performance and impact of data reduction using a dedicated Grafana dashboard. This dashboard provides insights into the resources being used and the efficiency of the reduction process.

Key monitoring panels include:

* **CPU Time % in background fibers:** Shows the percentage of CPU capacity used by background tasks, including data reduction.
* **Data Reduction Ingest Rate:** Tracks the rate (in blocks) at which data is being ingested for reduction.
* **Fingerprints - Performed FP Calcs:** Displays the rate of fingerprint calculations being performed per second.
* **Fingerprints - Skipped FP Calcs:** Shows the rate of fingerprint calculations that were skipped. An increase in skipped calculations can indicate a high system load.

<div data-with-frame="true"><figure><img src="/files/joRkeNPczVLOuZlHrIJF" alt=""><figcaption><p>Cluster CPU statistics</p></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="/files/oEL2kkAhyv46XTkgkgkG" alt=""><figcaption><p>Data reduction fingerprints and ingest rate</p></figcaption></figure></div>

### Encrypted filesystems in WEKA

WEKA ensures security by offering encryption for data at rest (residing on SSD and object store) and data in transit. This security feature is activated by enabling the filesystem encryption option. The decision on whether a filesystem should be encrypted is crucial during the filesystem creation process.

To create encrypted filesystems, deploying a Key Management System (KMS) is imperative, reinforcing the protection of sensitive data.

{% hint style="info" %}
Data encryption settings can only be configured during the initial creation of a filesystem, emphasizing the importance of making this decision from the beginning.
{% endhint %}

**Related topics**

[Manage KMS](/security/kms-management)

### Metadata limitations **in** WEKA filesystems

In addition to the capacity constraints, each filesystem in WEKA has specific limitations on metadata. The overall system-wide metadata cap depends on the SSD capacity allocated to the WEKA system and the RAM resources allocated to the WEKA system processes.

WEKA carefully tracks metadata units in RAM. If the metadata units approach the RAM limit, they are intelligently paged to the SSD, triggering alerts. This proactive measure allows administrators sufficient time to increase system resources while sustaining IO operations with minimal performance impact.

By default, the metadata limit linked to a filesystem correlates with the filesystem's SSD size. However, users have the flexibility to override this default by defining a filesystem-specific `max-files` parameter. This logical limit empowers administrators to regulate filesystem usage, providing the flexibility to update it as needed.

The cumulative metadata memory requirements across all filesystems can surpass the server’s RAM capacity. In potential impact scenarios, the system optimizes by paging the least recently used units to disk, ensuring operational continuity with minimal disruption.

#### Metadata units calculation <a href="#metadata-calculations" id="metadata-calculations"></a>

Every metadata unit within the WEKA system demands 4 KB of SSD space (excluding tiered storage) and occupies 20 bytes of RAM.

Throughout this documentation, the restriction on metadata per filesystem is denoted as the `max-files` parameter. This parameter includes the files' count and respective sizes.

The following table outlines the requisite metadata units based on file size. These specifications apply to files stored on SSDs or tiered to object stores.

<table><thead><tr><th width="152.34501597463696">File size</th><th width="237">Number of metadata units</th><th>Example</th></tr></thead><tbody><tr><td>&#x3C; 0.5 MB</td><td>1</td><td>A filesystem containing 1 billion files, each sized at 64 KB, requires 1 billion metadata units.</td></tr><tr><td>0.5 MB - 1 MB</td><td>2</td><td>A filesystem containing 1 billion files, each sized at 750 KB, requires 2 billion metadata units.</td></tr><tr><td>> 1 MB</td><td>2 for the first 1 MB plus<br>1 per MB for the rest MBs</td><td><ul><li>A filesystem containing 1 million files, each sized at 129 MB, requires 130 million metadata units. This calculation includes 2 units for the first 1 MB and an additional unit per MB for the subsequent 128 MB.</li><li>A filesystem containing 10 million files, each sized at 1.5 MB, requires 30 million metadata units.</li><li>A filesystem containing 10 million files, each sized at 3 MB, requires 40 million metadata units.</li></ul></td></tr></tbody></table>

{% hint style="info" %}
Each directory requires two metadata units instead of one for a small file.
{% endhint %}

**Related topics**

[Plan hardware requirements](/planning-and-installation/bare-metal/planning-a-weka-system-installation#memory-resource-planning)

### Filesystem Extended Attributes considerations

The maximum size for extended attributes (xattr) of a file or directory is 1024 bytes. This attribute space is used by Access Control Lists (ACLs) and Alternate Data Streams (ADS) within an SMB cluster and when configuring SELinux. When using Windows clients, named streams in smb-w are saved in the file’s xattr.

Given its finite capacity, exercise caution when using lengthy or complex ACLs and ADS on a WEKA filesystem.

When encountering a message indicating the file size exceeds the limit allowed and cannot be saved, carefully decide which data to retain. Strategic planning and selective use of ACLs and ADS contribute to optimizing performance and stability.

### Quality of Service (QoS)

Quality of Service (QoS) is a set of mechanisms that manages and prioritizes system resources, ensuring consistent performance and preventing any single entity from overwhelming cluster resources.

**QoS control levels**

WEKA provides multiple resource management layers to prevent noisy neighbors from impacting critical workloads:

* **Tenant level:** Administrators can configure the QoS after tenant creation. QoS ensures a specific tenant is capped at a defined performance threshold, regardless of how many filesystems the tenant owns.
* **Filesystem level:** Administrators can define QoS settings when adding or updating a filesystem. Use this to prioritize specific project or department workloads.
* **Client level:** Limits can be set at the client level through mount options, though the client's own network hardware may constrain these limits.

**Related topics**

* [Manage tenant QoS in multi-tenancy](/operation-guide/weka-native-multi-tenancy-management/multi-tenancy-cluster-level-administration#manage-tenant-quality-of-service): Set tenant-wide `--max-throughput` and `--max-iops` limits.
* [Manage filesystem QoS using the CLI](/weka-filesystems-and-object-stores/managing-filesystems/managing-filesystems-1#filesystem-qos-using-the-cli): Use `--max-throughput` and `--max-iops` when you create or update a filesystem.
* [Manage client QoS mount options](/weka-filesystems-and-object-stores/mounting-filesystems#client-qos-mount-options): Use `qos_max_ops`, `qos_max_throughput_mbps`, and `qos_preferred_throughput_mbps` for stateless clients.

**Performance parameters**

QoS is configured through two CLI parameters: one that limits the total number of I/O operations per second (IOPS), and one that limits bandwidth (throughput). Both parameters apply as aggregate limits across read and write operations, which cannot be restricted independently.

**Enforcement and throttling**

When a filesystem or tenant reaches its defined QoS limit, the system throttles traffic to keep it within the configured parameters.

* **Dynamic adjustment:** Setting a limit to `0` removes the cap, allowing unlimited performance based on available physical resources.
* **Hierarchical enforcement:** If a tenant and a filesystem both have QoS limits, the system enforces the more restrictive limit. For example, the total throughput of all filesystems within a tenant cannot exceed the tenant's overall QoS limit.

**Fair distribution**

When multiple clients or processes are throttled simultaneously, the system applies a fairness logic that divides available performance capacity equally among all active participants. This ensures that lower-demand processes receive their fair share of allocated bandwidth or IOPS, rather than distributing resources proportionally to demand.

**Considerations**

* **Bursting:** QoS supports bursting control, allowing a filesystem to temporarily exceed its defined limit. This is useful in scenarios where multiple clients start simultaneously and require short-term additional throughput.
* **Interface availability:** QoS settings are fully manageable through the CLI, but are not available in the WEKA GUI or the REST API.

## Object stores overview

Within the WEKA system, object stores are an optional external storage medium strategically designed to store warm data. These object stores, employed in tiered WEKA system configurations, can be cloud-based, located in the same location as the WEKA cluster, or at a remote location.

WEKA extends support for object stores, leveraging their capabilities for tiering (both tiering and local snapshots) and backup (snapshots only). Both tiering and backup functionalities can be concurrently used for the same filesystem, enhancing flexibility.

The optimal usage of object store buckets comes into play when a cost-effective data storage tier is imperative and traditional server-based SSDs prove insufficient in meeting the required price point.

An object store bucket definition comprises crucial components: the object store DNS name, bucket identifier, and access credentials. The bucket must remain dedicated to the WEKA system, ensuring exclusivity and security by prohibiting access from other applications.

Moreover, the connectivity between filesystems and object store buckets extends beyond essential storage. This connection proves invaluable in data lifecycle management and facilitates the innovative Snap-to-Object features, offering a holistic approach to efficient data handling within the WEKA system.

**Related topics**

[Manage object stores](/weka-filesystems-and-object-stores/managing-object-stores)

[Data lifecycle management overview](/weka-system-overview/data-storage)

[Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj)

## Filesystem groups overview

Within the WEKA system, the organization of filesystems takes place through the creation of filesystem groups, with a maximum limit set at eight groups.

Each of these filesystem groups comes equipped with tiering control parameters. When filesystems are tiered and have associated object stores, the tiering policy remains consistent for all tiered filesystems residing within the same filesystem group. This unification ensures streamlined management and unified control over tiering strategies within the WEKA system.

**Related topics**

[Manage filesystem groups](/weka-filesystems-and-object-stores/managing-filesystem-groups)


# Cluster and filesystem capacity counter definitions

Understand the key capacity counters for effective storage management, including space utilization, availability, and data reduction across SSDs and object storage.

## Cluster and filesystem capacity counter definitions

* **SSD capacity counters**:
  * **USED SSD**: Total SSD space currently in use, including both data and metadata.
  * **USED SSD (DATA)**: Space on SSDs occupied by actual file data.
  * **USED SSD (META)**: Space on SSDs used for storing filesystem metadata.
  * **FREE SSD**: Available unused space on SSDs.
  * **AVAILABLE SSD (META)**: Remaining SSD space available for storing filesystem metadata.
  * **AVAILABLE SSD**: Total SSD space provisioned to the filesystem by the user.
* [**Total**](#user-content-fn-1)[^1] **capacity counters**:
  * **USED TOTAL**: Total space used across both SSD and object store for filesystem data and metadata.
  * **USED TOTAL (DATA)**: Total space consumed by file data across the entire filesystem.
  * **FREE TOTAL**: Remaining space available in the filesystem for storing data and metadata.
  * **AVAILABLE TOTAL**: Total allocated space across both SSD and object store tiers.
* **Data reduction counters:**
  * **DATA REDUCTION RATIO (DRR):** Data reduction efficiency, calculated as:\
    USED SSD (DATA) / REDUCED SIZE OF DATA.
  * **USED SSD PENDING DATA REDUCTION:** Amount of data written to SSD that is awaiting data reduction processing.
  * **REDUCED SIZE OF PROCESSED DATA:** Total SSD space occupied post data reduction processing.
  * **REDUCED SIZE OF DATA:** Total SSD space consumed by the filesystem after all data reduction operations are complete.
  * **PROCESSED DATA REDUCTION RATIO:** Storage efficiency that shows actual space savings achieved through data reduction and deduplication. Calculated as:\
    (USED SSD (DATA) - USED SSD PENDING DATA REDUCTION) / REDUCED SIZE OF PROCESSED DATA
* **Other counters**:
  * **THIN PROVISIONED MINIMUM SSD**: Minimum guaranteed space.
  * **THIN PROVISIONED MAXIMUM SSD**: Maximum limit of space that can be dynamically allocated.
  * **USED SSD (WRITECACHE)**: SSD space consumed by modified data, possibly pending tiering to object store.
  * **USED SSD (READCACHE)**: Total SSD space used for caching data that also exists in the object store, based on filesystem group tiering policies.

### Example scenarios

#### Thin provisioned filesystem (no data reduction)

```bash
FILESYSTEM NAME: fs_example1
THIN PROVISIONED: true
THIN PROVISIONED MINIMUM SSD: 100 TB
THIN PROVISIONED MAXIMUM SSD: 500 TB
USED SSD: 150 TB
USED SSD (DATA): 145 TB
USED SSD (META): 5 TB
FREE SSD: 350 TB
```

#### Filesystem with active data reduction

```bash
FILESYSTEM NAME: fs_example2
DATA REDUCTION: Enabled
USED SSD: 200 TB
USED SSD (DATA): 150 TB
PENDING DATA REDUCTION: 50 TB
REDUCED SIZE OF PROCESSED DATA: 40 TB
DATA REDUCTION FACTOR: 3.75
```

**Related topics**

[Filesystems, object stores, and filesystem groups](/weka-system-overview/filesystems-object-stores-and-filesystem-groups)

[Data lifecycle management overview](/weka-system-overview/data-storage)

[Manage filesystems](/weka-filesystems-and-object-stores/managing-filesystems)

[^1]: **Total**: Represents the amount used by the filesystem, not across storage tiers. SSD cache usage changes as data moves between SSD and OBS.


# Networking

Explore network technologies in WEKA, including DPDK, SR-IOV, CPU-optimized networking, UDP mode, high availability, and RDMA/GPUDirect Storage, with configuration guidelines.

## Overview

The WEKA system supports the following types of networking technologies:

* ‌InfiniBand (IB)
* Ethernet

‌The networking infrastructure dictates the choice between the two. If a WEKA cluster is connected to both infrastructures, it is possible to connect WEKA clients from both networks to the same cluster.

The WEKA system networking can be configured as *performance-optimized* or *CPU-optimized*. In [performance-optimized](#performance-optimized-networking-dpdk) networking, the CPU cores are dedicated to WEKA, and the networking uses DPDK. In [CPU-optimized](#cpu-optimized-networking-udp-mode) networking, the CPU cores are not dedicated to WEKA, and the networking uses DPDK (when supported by the NIC drivers) or in-kernel (UDP mode).

### Performance-optimized networking (DPDK)

For performance-optimized networking, the WEKA system does not use standard kernel-based TCP/IP services but a proprietary infrastructure based on the following:

* Use [DPDK](#dpdk) to map the network device in the user space and use it without any context switches and with zero-copy access. This bypassing of the kernel stack eliminates the consumption of kernel resources for networking operations. It applies to backends and clients and lets the WEKA system saturate network links (including, for example, 200 Gbps or 400 Gbps).
* Implementing a proprietary WEKA protocol over UDP, i.e., the underlying network, may involve routing between subnets or any other networking infrastructure that supports UDP.

The use of DPDK delivers operations with extremely low latency and high throughput. Low latency is achieved by bypassing the kernel and sending and receiving packages directly from the NIC. High throughput is achieved because multiple cores in the same server can work in parallel without a common bottleneck.

Before proceeding, it is important to understand several key terms used in this section, namely DPDK and SR-IOV.

#### DPDK

‌[Data Plane Development Kit (DPDK)](http://dpdk.org/) is a set of libraries and network drivers for highly efficient, low-latency packet processing. This is achieved through several techniques, such as kernel TCP/IP bypass, NUMA locality, multi-core processing, and device access via polling to eliminate the performance overhead of interrupt processing. In addition, DPDK ensures transmission reliability, handles retransmission, and controls congestion.

DPDK implementations are available from several sources. OS vendors like [Red Hat](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/virtualization_deployment_and_administration_guide/sect-pci_devices-pci_passthrough) and [Ubuntu](https://help.ubuntu.com/lts/serverguide/DPDK.html) provide DPDK implementations through distribution channels. [Mellanox OpenFabrics Enterprise Distribution for Linux](https://www.mellanox.com/page/products_dyn?product_family=26) (Mellanox OFED), a suite of libraries, tools, and drivers supporting Mellanox NICs, offers its own DPDK implementation.

The WEKA system relies on the DPDK implementation provided by Mellanox OFED on servers equipped with Mellanox NICs.

#### SR-IOV

Single Root I/O Virtualization (SR-IOV) extends the PCI Express (PCIe) specification that enables PCIe virtualization. It allows a PCIe device, such as a network adapter, to appear as multiple PCIe devices or *functions*.

There are two function categories:

* Physical Function (PF): PF is a full-fledged PCIe function that can also be configured.
* Virtual Function (VF): VF is a virtualized instance of the same PCIe device created by sending appropriate commands to the device PF.

Typically, there are many VFs, but only one PF per physical PCIe device. Once a new VF is created, it can be mapped by an object such as a virtual machine, container, or, in the WEKA system, by a 'compute' process.

To take advantage of SR-IOV technology, the software and hardware must be supported. The Linux kernel provides SR-IOV software support. The computer BIOS and the network adapter provide hardware support (by default, SR-IOV is disabled and must be enabled before installing WEKA).

### CPU-optimized networking

For CPU-optimized networking, WEKA can yield CPU resources to other applications. That is useful when the extra CPU cores are needed for other purposes. However, the lack of CPU resources dedicated to the WEKA system comes with the expense of reduced overall performance.

#### DPDK without the core dedication

For CPU-optimized networking, when [mounting filesystems using stateless clients](/weka-filesystems-and-object-stores/mounting-filesystems#mounting-filesystems-using-stateless-clients), it is possible to use DPDK networking without dedicating cores. This mode is recommended when available and supported by the NIC drivers. The DPDK networking uses RX interrupts instead of dedicating the cores in this mode.

{% hint style="info" %}
This mode is supported in most NIC drivers. Consult [https://doc.dpdk.org/guides/nics/overview.html](https://doc.dpdk.org/guides-18.11/nics/overview.html) for compatibility.

AWS (ENA drivers) does not support this mode. Hence, in CPU-optimized networking in AWS, use the [UDP mode](#udp-mode).
{% endhint %}

#### UDP mode

WEKA can also use in-kernel processing and UDP as the transport protocol. This operation mode is commonly referred to as *UDP mode*.

UDP mode is compatible with older platforms that lack support for kernel offloading technologies (DPDK) or virtualization (SR-IOV) due to its use of in-kernel processing. This includes legacy hardware, such as the Mellanox CX3 family of NICs.

## Typical WEKA configuration

### Backend servers

In a typical WEKA system configuration, the WEKA backend servers access the network function in two different methods:

* Standard TCP/UDP network for management and control operations.
* High-performance network for data-path traffic.

{% hint style="info" %}
To run both functions on the same physical interface, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}

The high-performance network used to connect all the backend servers must be DPDK-based. This internal WEKA network also requires a separate IP address space. For details, see [Network planning](/planning-and-installation/bare-metal/planning-a-weka-system-installation#network-planning) and [Configure the networking](/planning-and-installation/bare-metal/setting-up-the-hosts#configure-the-networking).

The WEKA system maintains a separate ARP database for its IP addresses and virtual functions and does not use the kernel or operating system ARP services.

### Clients

While WEKA backend servers must include DPDK and SR-IOV, WEKA clients in application servers have the flexibility to use either DPDK or UDP modes. DPDK mode is the preferred choice for newer, high-performing platforms that support it. UDP mode is available for clients without SR-IOV or DPDK support or when there is no need for low-latency and high-throughput I/O.

### Configuration guidelines

* **DPDK backends and clients using NICs supporting shared networking (single IP):**
  * Require one IP address per client for data plane.
  * SR-IOV enabled is not required.
* **DPDK backends and clients using NICs supporting dedicated networking:**
  * IP address for management process on data plane: One per NIC (configured before WEKA installation).
  * IP address for data plane: One per [WEKA core](/planning-and-installation/bare-metal/planning-a-weka-system-installation#cpu-resource-planning) in each server (applied during cluster initialization).
  * [Virtual Functions](https://en.wikipedia.org/wiki/Network_function_virtualization) (VFs):
    * Ensure the device supports a maximum number of VFs greater than the number of physical cores on the server.
    * Set the number of VFs to match the cores you intend to dedicate to WEKA.
    * Note that some BIOS configurations may be necessary.
  * SR-IOV: Enabled in BIOS.
* **UDP clients:**
  * Use a shared networking (single IP) for all purposes.
* **Servers with mixed adapter roles (IP-only, IP and RDMA, or RDMA-only):**
  * IP address for data plane: Required only on adapters assigned the IP-only or IP and RDMA role.
  * RDMA-only adapters do not require an IP address in the WEKA data plane.
  * SR-IOV: Required only on adapters that carry DPDK-based IP traffic.

{% hint style="info" %}
Management IPs in these networking guidelines serve management processes on the data plane network. They do not serve external management interfaces such as the CLI or REST API.
{% endhint %}

## Network **High Availability** <a href="#high-availability" id="high-availability"></a>

Network High Availability (HA) in a WEKA cluster is designed to eliminate single points of failure by leveraging redundancy across network components. This configuration ensures the system remains operational even in the event of hardware or connection failures.

**Network redundancy**

To achieve HA, the WEKA system requires multiple network switches with servers connected to at least two interfaces of the same type. Dual connectivity is provided either through two independent interfaces or through Link Aggregation Control Protocol (LACP) in Ethernet environments (mode 4).

**Interface configuration**

* **Non-LACP configuration**: Each server uses two network interfaces for redundancy and bandwidth enhancement. This approach doubles the number of IP addresses required on backend containers and IO processes.
* **LACP configuration (Ethernet-only)**: LACP aggregates interfaces on a single Mellanox NIC for improved reliability and load balancing in Ethernet-only setups.

  Specifications and requirements:

  * LACP is not supported with Virtual Functions (VFs).
  * NIC must be set to `HW_LAG` (IEEE 802.3ad) with `queue_affinity` enabled and hashing disabled.
  * At least two WEKA processes must use DPDK.
  * Switch must support IEEE 802.3ad in active/active mode.

**Failover and load balancing**

Network HA ensures reliability and optimizes load balancing through failover and failback mechanisms. These mechanisms operate independently for InfiniBand and Ethernet networks. If an interface fails, another interface of the same type (InfiniBand or Ethernet) seamlessly takes over the workload.

{% hint style="info" %}
**Mixed-mode behavior:** In a cluster with servers equipped with both Ethernet and InfiniBand connections, the system remains operational even if a single server loses one of its connections. However, that server is excluded from participating in cluster-level operations. The cluster will continue I/O operations unless all servers lose connectivity on **either** the Ethernet or InfiniBand network; in that case, I/O operations will pause.
{% endhint %}

**Traffic optimization**

To optimize network traffic, the WEKA system can be configured to prioritize intra-switch communication over inter-switch links (ISL). This can be achieved by labeling connections using the `label` parameter in the `weka cluster container net add` command, which helps route data efficiently within the cluster.

## RDMA, RoCE, and GPUDirect Storage

RDMA, RoCE, and GPUDirect Storage (GDS) establish a direct data path between storage and memory (GPU memory in case of GDS) bypassing unnecessary data copies through the operating system. This approach allows Direct Memory Access (DMA) through the NIC to transfer data directly to or from application or GPU memory bypassing the operating system.

When RDMA and GDS are enabled, the WEKA system automatically uses the RDMA data path and GDS in supported environments. The system dynamically detects when RDMA is available—including in [RoCE v1](#user-content-fn-1)[^1], [RoCE v2](#user-content-fn-2)[^2], UDP, and DPDK modes—and applies it to workloads that can benefit from RDMA. Typically, RDMA is advantageous for I/O sizes of 32KB or larger for reads and 256KB or larger for writes.

By leveraging RDMA and GDS, you can achieve enhanced performance. A UDP client, which doesn't require dedicating a core to the WEKA system, can deliver significantly higher performance. Additionally, a DPDK client can experience an extra performance boost, or you can assign fewer cores to the WEKA system while maintaining the same level of performance in DPDK mode.

**Adapter roles for RDMA-capable interfaces**

When a server includes RDMA-capable network adapters, each adapter can be assigned one of the following roles that define how it handles traffic:

<table><thead><tr><th width="168">Role</th><th>Description</th></tr></thead><tbody><tr><td>IP-only</td><td>Handles management process and data-path IP traffic. RDMA is not used on this adapter.</td></tr><tr><td>IP and RDMA</td><td>Handles both IP traffic and RDMA operations.</td></tr><tr><td>RDMA-only</td><td>Dedicated exclusively to RDMA traffic. Does not carry IP traffic.</td></tr></tbody></table>

Assigning dedicated roles allows you to isolate RDMA traffic from IP traffic, improving network utilization and predictability. Adapters without RDMA capability can coexist on the same server when assigned to the IP-only role.

RDMA-capable adapters can be discovered and configured automatically during container setup using the `--scan-rdma` flag, without specifying device names explicitly.

### Requirements and considerations for RDMA and GDS support

RDMA, including RoCE, is enabled by default. To support RDMA and GDS technologies, the following requirements and considerations must be met:

* **Cluster requirements**
  * **RDMA networking:** Servers that use RDMA networking must include at least one RDMA-capable network adapter. Adapters without RDMA capability can coexist on the same server when explicitly assigned to the IP-only role.
* **Client requirements**
  * **GDS support:** The InfiniBand or Ethernet interfaces included in the GDS configuration must support RDMA networking.
  * **RDMA support:** All InfiniBand and Ethernet interfaces assigned the IP and RDMA or RDMA-only role must support RDMA networking. Interfaces assigned the IP-only role do not require RDMA capability.

**Fallback to standard I/O**

* GDS is not supported for encrypted filesystems.
* If any requirement for RDMA or GDS is not met, the system automatically reverts to standard I/O operations without RDMA or GDS acceleration.

{% hint style="info" %}
**Kernel bypass:** GDS bypasses the kernel and does not use the page cache. In contrast, standard RDMA clients continue to use the page cache.
{% endhint %}

#### Verification

To confirm RDMA usage, run the following command:

```
weka cluster processes
```

Example:

```bash
# weka cluster processes
PROCESS ID  HOSTNAME  CONTAINER   IPS         STATUS  ROLES       NETWORK      CPU  MEMORY   UPTIME
0           weka146   default     10.0.1.146  UP      MANAGEMENT  UDP                        16d 20:07:42h
1           weka146   default     10.0.1.146  UP      FRONTEND    DPDK / RDMA  1    1.47 GB  16d 23:29:00h
2           weka146   default     10.0.3.146  UP      COMPUTE     DPDK / RDMA  12   6.45 GB  16d 23:29:00h
3           weka146   default     10.0.1.146  UP      COMPUTE     DPDK / RDMA  2    6.45 GB  16d 23:29:00h
4           weka146   default     10.0.3.146  UP      COMPUTE     DPDK / RDMA  13   6.45 GB  16d 23:29:00h
5           weka146   default     10.0.1.146  UP      COMPUTE     DPDK / RDMA  3    6.45 GB  16d 22:28:58h
6           weka146   default     10.0.3.146  UP      COMPUTE     DPDK / RDMA  14   6.45 GB  16d 23:29:00h
7           weka146   default     10.0.3.146  UP      DRIVES      DPDK / RDMA  18   1.49 GB  16d 23:29:00h
8           weka146   default     10.0.1.146  UP      DRIVES      DPDK / RDMA  8    1.49 GB  16d 23:29:00h
9           weka146   default     10.0.3.146  UP      DRIVES      DPDK / RDMA  19   1.49 GB  16d 23:29:00h
10          weka146   default     10.0.1.146  UP      DRIVES      DPDK / RDMA  9    1.49 GB  16d 23:29:00h
11          weka146   default     10.0.3.146  UP      DRIVES      DPDK / RDMA  20   1.49 GB  16d 23:29:07h
12          weka147   default     10.0.1.147  UP      MANAGEMENT  UDP                        16d 22:29:02h
13          weka147   default     10.0.1.147  UP      FRONTEND    DPDK / RDMA  1    1.47 GB  16d 23:29:00h
14          weka147   default     10.0.3.147  UP      COMPUTE     DPDK / RDMA  12   6.45 GB  16d 23:29:00h
15          weka147   default     10.0.1.147  UP      COMPUTE     DPDK / RDMA  2    6.45 GB  16d 23:29:00h
16          weka147   default     10.0.3.147  UP      COMPUTE     DPDK / RDMA  13   6.45 GB  16d 23:29:00h
17          weka147   default     10.0.1.147  UP      COMPUTE     DPDK / RDMA  3    6.45 GB  16d 23:29:00h
18          weka147   default     10.0.3.147  UP      COMPUTE     DPDK / RDMA  14   6.45 GB  16d 23:29:00h
19          weka147   default     10.0.3.147  UP      DRIVES      DPDK / RDMA  18   1.49 GB  16d 23:29:00h
20          weka147   default     10.0.1.147  UP      DRIVES      DPDK / RDMA  8    1.49 GB  16d 23:29:00h
21          weka147   default     10.0.3.147  UP      DRIVES      DPDK / RDMA  19   1.49 GB  16d 23:29:07h
22          weka147   default     10.0.1.147  UP      DRIVES      DPDK / RDMA  9    1.49 GB  16d 23:29:00h
23          weka147   default     10.0.3.147  UP      DRIVES      DPDK / RDMA  20   1.49 GB  16d 23:29:07h
. . .
```

{% hint style="info" %}
GDS is automatically enabled and detected by the system. To enable or disable RDMA networking for the cluster or a specific client, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}

**Related topic**

[Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility#networking) (in the **Prerequisites and compatibility** topic)

[^1]: RoCE v1 (RDMA over Converged Ethernet) in a single subnet.

[^2]: RoCE v2 (RDMA over Converged Ethernet) across multiple single subnets.


# Data lifecycle management overview

Explore the principles for data lifecycle management and how data storage is managed in SSD-only and tiered WEKA system configurations.

The WEKA system provides flexible storage architectures that balance performance and cost by managing data across different storage media. Understanding how WEKA handles data placement helps you configure systems that deliver the performance characteristics your workloads require while controlling storage costs.

## Storage media options in WEKA systems

WEKA systems use two types of storage media, each serving distinct purposes based on its performance and cost characteristics:

* **Solid-state drives (SSDs):** Form the foundation of every WEKA system. These locally attached drives provide the high performance and low latency that make WEKA suitable for demanding workloads. SSDs are a required component of any WEKA configuration, and they deliver the exceptional IOPS and throughput that applications depend on for fast data access.
* **Object store systems:** Represent the second storage tier available in WEKA. These systems connect to WEKA externally and can be cloud-based services like AWS S3 or Azure Blob Storage, or on-premises installations using various third-party solutions. Object stores trade some performance and add latency compared to SSDs, but they provide virtually unlimited capacity at significantly lower cost per terabyte than solid-state storage.

### Configuration options: SSD-only vs tiered systems

WEKA supports two fundamental configuration approaches that serve different use cases and priorities:

* SSD-only configurations
* Tiered configurations

#### SSD-only configurations

SSD-only configurations store all data exclusively on solid-state drives. This approach maximizes performance by maintaining all data on the fastest storage media available.

Workloads that demand consistent low latency and high throughput for all data access, regardless of data age or access frequency, benefit from SSD-only configurations. The trade-offs include capacity limitations, where the SSD investment bounds the total storage, and a higher cost per terabyte stored.

In SSD-only configurations, WEKA can optionally use object store for the Snap-To-Object feature. This feature maintains backup copies of snapshots in object store for disaster recovery while keeping all active data on SSDs for performance.

#### Tiered configurations

Tiered configurations combine SSDs and object store into an integrated system where WEKA automatically manages data placement between the two media.

This approach optimizes storage cost and efficiency. Newly created and frequently accessed data stays on SSDs for fast access, while older or rarely accessed data moves to object store. WEKA automatically identifies the appropriate tier for the data and transparently moves it between tiers as access patterns change.

Tiered configurations allow the provisioning of a much larger total filesystem capacity than the SSD investment alone supports. For example, a system can configure 25 TB of SSDs but create a 100 TB filesystem, while WEKA manages which 25 TB resides on SSDs based on access patterns and configured policies.

## Data management in tiered configurations

Understanding data placement in a tiered system clarifies how WEKA balances performance and cost.

### **Metadata residency**

Metadata resides exclusively on SSDs and is never tiered to the object store. This includes directory structures, file attributes, timestamps, permissions, and internal indexes used to locate data.

Maintaining metadata on SSD ensures that filesystem traversal operations, such as listing directories, verifying file existence, and reading attributes, consistently deliver SSD-level performance. This applies regardless of whether the associated file data resides on SSD or in the object store.

This design enables efficient navigation of very large filesystems, including environments containing billions of files, while preserving predictable and low-latency metadata access.

### **Write operations**

Write operations in tiered systems always target SSDs first. Creating new files, appending to existing files, or modifying content occurs at SSD speeds.

WEKA never writes directly to object store to avoid high latency in the write path. Instead, writes complete quickly on SSD, and the system manages the background process of copying data to object store based on configured policies.

### **Read operations and promotion**

Read operations access data from either storage tier based on the data’s current location:

* **SSD resident data:** If the data resides on SSD (for example, because it has not been tiered or remains cached), the read operation completes at SSD performance.
* **Object store resident data:** If the requested data exists only in the object store (OBS), WEKA retrieves it from OBS to satisfy the read request. The system may cache the retrieved data on SSD to accelerate subsequent access, depending on current activity and resource availability. If the data is not cached (or only partially cached), subsequent reads are served directly from OBS.

The system performs coordinated reads by serving all locally available data from the SSD while simultaneously fetching any missing segments from the object store. In this model, the SSD acts as a transparent cache layer. The system does not wait for full promotion to complete before using the local fragments to accelerate the request.

### Intelligent chunk-level management

WEKA optimizes storage efficiency and performance by managing data at a sub-file granularity. The system uses data chunks to distribute data across different SSDs and organize tiering. It tracks the storage tier and access patterns for each chunk independently.

#### Optimize large file handling

The chunk-level approach enhances large file management. For database files where applications frequently modify specific regions, the system retains active chunks on the SSD for fast access. It tiers unchanged portions to the object store. The application perceives a single consistent file, regardless of the storage tier where specific parts reside.

#### Prevent unnecessary data movement

Chunk-level granularity minimizes data movement. Modifying a specific section of a file, such as 10 MB within a 100 GB file, triggers a rewrite only for the modified chunks. These chunks restart their lifecycle on the SSD. Unchanged chunks maintain their current lifecycle on the SSD or object store. This approach avoids the resource cost of reprocessing the entire file when only a small portion changes.

### Data placement conditions

In a tiered configuration, data progresses through three placement conditions that reflect where it currently resides across storage tiers.

These conditions apply at the data-chunk level rather than the file level. As a result, a single file may simultaneously contain chunks in different placement conditions.

* **SSD-only:** Represents newly created or recently modified data residing exclusively in the SSD tier. This is the initial placement for all data entering the system before it is copied to the object store tier.
* **SSD-cached:** Represents data that exists in both the SSD tier and the object store tier. After tiering copies data to the object store, the SSD copy continues to provide low-latency access, while the object store copy provides durable capacity storage. Data may remain in this condition for extended periods to optimize performance.
* **Object-store-only:** Represents data that has been removed from the SSD tier after its retention eligibility or capacity-based release. The data resides solely in the object store tier. Accessing this data requires retrieval from the object store, which may introduce initial read latency.

Understanding these placement conditions clarifies system behavior:

* Data present in the SSD tier supports low-latency reads.
* Data residing only in the object store tier must be retrieved before access performance returns to SSD-level speeds.
* Tiering continuously evaluates and adjusts data placement according to policy and system conditions.

### Tiering processes

Tiering is the automated mechanism that moves data between storage tiers. In an object-store configuration, tiering governs how data transitions between the SSD tier and the object store tier over time.

Object-store tiering consists of four core processes:

1. Write to SSD
2. Demotion
3. Release
4. Fetch

These processes operate automatically based on configured policies and real-time system conditions.

<div data-with-frame="true"><img src="/files/uqmX7aFlaqJJjiBxCK4Y" alt="Tiering processes"></div>

#### Write to SSD

All new data is written to the SSD tier. This ensures low-latency write performance and immediate availability. After write completion, data becomes eligible for tiering operations.

#### Demotion

Demotion copies data from the SSD tier to the object store tier while retaining the SSD copy. After demotion completes, data exists in both tiers.

The Tiering Cue policy controls when demotion begins. It defines the delay between write completion and initiation of the copy operation to the object store. This delay helps avoid unnecessary object-store writes for data that may be modified or deleted shortly after creation.

Demotion runs as a background process and does not interrupt data access.

#### Release

Release removes the SSD copy after the object store copy has been successfully created. Following release, data resides only in the object store tier.

Release may occur due to:

* SSD capacity requirements, or
* Expiration of the configured retention period.

These triggers operate independently and may act together.

#### Fetch

Fetch occurs when data residing only in the object store tier is accessed. The system retrieves the requested data to satisfy the read operation.

Depending on system conditions and policy, the retrieved data may be placed back on the SSD tier. This placement is opportunistic and intended to improve subsequent access performance.

## Role of SSDs in tiered systems

In tiered configurations, SSDs perform three critical functions beyond storage: metadata processing, write staging, and read caching.

#### **Metadata processing**

Filesystem metadata operations, such as creating files, modifying attributes, and updating directory listings, involve frequent, small random read and write operations. SSDs excel at this workload pattern, whereas object store performs poorly.

WEKA stores all metadata on SSDs. This ensures fast filesystem navigation and file operations, regardless of the total data volume or its location.

#### **Write staging**

SSDs act as a low-latency staging area for write operations. Direct writing to object store imposes high latency on applications. To mitigate this, WEKA accepts all writes on SSDs, allowing them to complete at local speeds. The application proceeds immediately while the system handles the background task of copying data to object store. This approach delivers consistent write performance while leveraging cost-effective long-term storage.

#### **Read caching**

SSDs function as a read cache for object-stored data. When the system tiers data to the object store, it retains a cached copy on the SSD. To manage this cache, the system applies a Least Recently Used (LRU) policy. This ensures that the most recently accessed data remains on the high-performance SSD, while the system clears the least active data to free up space. This strategy supports a working set significantly larger than the physical SSD capacity.

## Capacity considerations in tiered filesystems

In tiered systems, distinguishing between total filesystem capacity and SSD capacity is essential for proper configuration and interpretation of system behavior. These two metrics serve different purposes.

**Capacity definitions**

* **Total filesystem capacity:** Represents the maximum amount of data the filesystem can hold across both tiers (SSD and object store). For example, a 100 TB filesystem can store up to 100 TB of data, distributed between the tiers based on policies and access patterns.
* **SSD capacity:** Represents the working space allocated for recently written or frequently accessed data, metadata, and caching. This is typically significantly smaller than the total filesystem capacity. For example, a system might allocate 25 TB of SSD capacity within a 100 TB filesystem, relying on object store for the remaining 75 TB.

**Role of reserved SSD capacity**

SSD space remains reserved for essential functions, even when not fully utilized for data storage. This reservation ensures resources are available for:

* **Metadata processing:** Storing directory structures and file attributes.
* **Write staging:** Accepting new writes at high speed before tiering.
* **Read caching:** Accommodating data promoted from object store upon access.

## Data lifecycle management policies

WEKA provides time-based policies to control data movement between tiers. These policies enable tuning the system for specific workload patterns and balancing performance against storage costs.

#### Drive retention period

The drive retention period specifies the duration data remains cached on the SSD after the system tiers it to the object store. This setting controls the depth of the SSD cache relative to data history.

* **Longer retention:** Keeps more data accessible at SSD speeds but requires more SSD capacity.
* **Shorter retention:** Reduces SSD requirements but increases the likelihood of fetching data from the object store upon access.

This setting serves as a target. If data is written faster than the SSD capacity can accommodate within the configured retention period, the system releases data earlier to prevent SSD exhaustion.

#### Tiering cue

The tiering cue determines the wait time before the system begins copying data from the SSD to the object store. This buffer accommodates data modification patterns. For workflows involving file edits over several hours or days, setting a tiering cue that spans the editing window prevents the repeated tiering of changing data.

The minimum tiering cue is one-third of the retention period.

#### **Policy configuration strategy**

Configure lifecycle policies at the filesystem group level to align with specific workload characteristics. Effective configuration requires analyzing data generation rates, access patterns, and available SSD capacity.

**Workload strategies**

* **Active processing:** Assign a long retention period to maintain working data on the SSD for high-performance access.
* **Archival storage:** Assign a short retention period for rarely accessed data to optimize SSD usage.

**Configuration examples**

* **Log files:** For log files processed within a month but retained permanently, set a one-month retention period. Verify that the SSD capacity is sufficient to cache one month of data.
* **Research data:** For research data analyzed for three months before archiving, set a three-month retention period. This keeps active data on the SSD for fast access while moving completed projects to the object store.

### Bypassing standard lifecycle policies

While time-based policies govern typical tiering behavior, the system provides mechanisms for situations that require immediate or policy-independent data movement.

#### **Snap to Object**

Snap to Object forces data to tier immediately to the object store tier.

When triggered, the system uploads:

* All associated metadata, and
* Any data that is not yet present in the object store.

Metadata stored in the object store is not accounted toward object-store capacity usage.

Snap to Object is commonly used in backup or rapid-persistence workflows where data must be made durable in the object store immediately, without waiting for standard tiering delays.

#### **Object-store direct mount (`obs_direct`)**

Object-store direct mount modifies the standard tiering flow for specific mount points.

* **Write behavior:**

  * Data is written to the SSD tier first.
  * It is immediately scheduled for upload to the object store tier.
  * After successful upload, the data is promptly released from SSD.

  This minimizes SSD residency time while preserving the system’s write-path integrity.
* **Read behavior:**

  * Reads retrieve data directly from the object store tier.
  * Retrieved data is not promoted to the SSD tier.

  This mode is suitable for workflows such as large-scale data ingestion or bulk imports where SSD caching is not required and capacity efficiency is prioritized.

**Related topics**

[Manage data lifecycle for tiered systems](/weka-filesystems-and-object-stores/tiering)

[Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj)


# WEKA client and mount modes

Understanding the WEKA system client and possible mount modes of operation in relation to the page cache.

## The WEKA client

The WEKA client is a standard POSIX-compliant filesystem driver installed on application servers, facilitating file access to WEKA filesystems. Acting as a conventional filesystem driver, it intercepts and executes all filesystem operations, providing applications with local filesystem semantics and performance—distinct from NFS mounts. This approach ensures centrally managed, shareable, and resilient storage for WEKA.

Tightly integrated with the Linux Page Cache, the WEKA client leverages this transparent caching mechanism to store portions of filesystem content in the client's RAM. The Linux operating system maintains a page cache in the unused RAM, allowing rapid access to cached pages and yielding overall performance enhancements.

The Linux Page Cache, implemented in the Linux kernel, operates transparently to applications. Utilizing unused RAM capacity, it incurs minimal performance penalties, often appearing as "free" or "available" memory.

The WEKA client retains control over the Linux Page Cache, enabling cache information management and invalidation when necessary. Consequently, WEKA leverages the Linux Page Cache for high-performance data access, ensuring data consistency across multiple servers.

A filesystem can be mounted in one of two modes with the Linux Page Cache:

* [**Read cache mount mode**](#read-cache-mount-mode)**:** Only read operations use Linux Page Cache to sustain RAM-level performance for the frequently accessed data. WEKA ensures that the view of the data is coherent across various applications and clients.
* [**Write cache mount mode (default)**](#write-cache-mount-mode-default)**:** Both read and write operations use the Linux Page Cache, maintaining data coherency across servers and providing optimal data performance.

{% hint style="info" %}
Symbolic links are consistently cached in all modes.
{% endhint %}

## **R**ead cache mount mode

In Read Cache mode, the Linux Page Cache operates in *write-through* mode, meaning that write operations are acknowledged only after being securely stored on resilient storage. This applies to both data and metadata.

By default, data read or written by customer applications is stored in the local server's Linux Page Cache. The WEKA system monitors access to this data and invalidates the cache if another server attempts to read or write the same data. Cache invalidation occurs in the following scenarios:

* When one client writes to a file that another client is reading or writing.
* When one server writes to a file that another server is reading.

This approach ensures data coherence. The Linux Page Cache is fully used when a file is accessed by a single server or multiple servers in read-only mode. However, if multiple servers access a file and at least one server writes to it, the system bypasses the Linux Page Cache, and all I/O operations are handled by the backend servers.

{% hint style="info" %}
A server is considered to be "writing" to a file after the first write operation occurs, regardless of the read/write flags set by the open system call.

For workloads involving random reads of small blocks from large files, enabling the read cache and Linux prefetch mechanisms may not improve performance and could even be counterproductive. Assess whether enabling read-ahead aligns with your performance goals for truly random access patterns.
{% endhint %}

## Write cache mount mode (default)

In Write Cache mode, the Linux Page Cache operates in *write-back* mode rather than *write-through*. When a write operation occurs, it is immediately acknowledged by the WEKA client and temporarily stored in the kernel memory cache. The data is then written to resilient storage in the background.

This mode improves performance by reducing write latency while maintaining data coherence. If the same file is accessed by another server, the local cache is invalidated, ensuring a consistent view of the data.

To ensure all changes in the write cache are committed to storage, particularly before taking a snapshot, you can use system calls like `sync`, `syncfs`, and `fsync`. These commands force the filesystem to flush the write cache and synchronize data to resilient storage.

## Multiple mounts on a single server

The WEKA client allows multiple mount points for the same filesystem on a single server, supporting different mount modes. This is useful in containerized environments where various server processes require distinct read/write access or caching schemes.

Each mount point on the same server is treated independently for cache consistency. For example, two mounts with write cache mode on the same server may have different data simultaneously, accommodating diverse requirements for applications or workflows on that server.

## Metadata management

Unlike file data, file metadata is managed in the Linux operating system through the directory entry (Dentry) cache. While maximizing efficiency in handling directory entries, the Dentry cache is not strongly consistent across WEKA clients. For applications prioritizing metadata consistency, it is possible to configure metadata for strong consistency by mounting without a Dentry cache.

**Related topic**

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems#mount-command-options)


# Cluster architecture overview

Overview of container-based architecture, where interconnected processes within server-hosted containers provide scalable and resilient storage services in a cluster.

## Cluster architecture basics

In the NeuralMesh system, servers operate as cluster members, each server hosting multiple containers. These containers run software instances, referred to as processes, that collaborate and communicate within the cluster to deliver robust and efficient storage services. This architecture ensures scalability and fault tolerance by distributing storage functionality across interconnected containers.

### Process types and core requirements

The system uses different types of processes, each dedicated to specific functions:

* **Drive processes**: A backend process that manages SSD drives and handle IO operations to drives. These processes are fundamental to storage operations and each requires a dedicated core to ensure optimal performance.
* **Compute processes:** A backend process that handles filesystems, cluster-level functions, and IO from clients. Each compute process requires a dedicated core to ensure consistent processing power for these critical operations.
* **Frontend processes**: A client process that manages POSIX client access and coordinates IO operations with compute and drive processes. Each frontend process requires a dedicated core to maintain responsive client interactions.
* **Management process**: A backend process that oversees overall cluster operations. It has lower resource demands and can share cores. The process uses kernel networking and unallocated OS-available cores.

## Multi-container backend (MCB) architecture

Each server implements a multi-container backend architecture where containers are specialized by process type: drive, compute, or frontend.

<div data-with-frame="true"><figure><img src="/files/fXM9BgAMVrDz5YYNZjVw" alt="" width="563"><figcaption><p>MCB architecture</p></figcaption></figure></div>

## Benefits of MCB architecture

* **Non-Disruptive Upgrade (NDU) capabilities:**
  * Enables true non-disruptive upgrades where containers can run different software versions independently without system interruption
  * Supports individual container rollback without impacting cluster operations
  * Maintains continuous network control plane access throughout the upgrade process, ensuring uninterrupted client service
* **Optimized hardware utilization:**
  * Supports up to 512 cores per server
  * Multiple containers per process type
  * Flexible core allocation across containers
  * Up to 19 cores per container
* **Improved maintenance operations:**
  * Selective process management
  * Ability to maintain drive processes while stopping compute and frontend processes

## System limitations and specifications

### **Process limits**

* Total processes per cluster: 65,534 (includes all process types: management, drive, compute, and frontend).
* Maximum management processes: 32,767.
* Maximum drive processes: 62,244.

### **Server and container limits**

Each server has resource limits that affect how many containers it can run and how cores are allocated:

* Maximum cores per server: 512
* Maximum cores per container: 19
* Maximum containers of any type per server: 128
  * Within this total, the maximum frontend containers per server is 7.

{% hint style="info" %}
When the cluster is deployed on Kubernetes as a multi-tenant solution, the limits above apply per tenant.
{% endhint %}


# Glossary

## A

## **Access Time (atime)**

Access time, often called `atime`, is a file system metadata attribute that tracks the most recent instance when a file was accessed or read. This attribute is essential for monitoring and managing file usage, as it records when a file was last opened or viewed by a user or an application.

In the WEKA filesystem, the atime is updated locally on the container where the read operation took place, and this update is subsequently propagated to the cluster after the user closes the file. This update process doesn't occur immediately and may take up to 60 minutes to reflect the actual access time.

POSIX mount options that affect atime behavior, such as `relatime`, are supported. However, this updated atime still takes time to propagate, even if mounted with `strictatime`.

Directory atimes are currently not supported, therefore, listing a directory's contents does not update its atime.

### Agent

The WEKA agent is software installed on user application servers that need access to the WEKA file services. When using the Stateless Client feature, the agent ensures that the correct client software version is installed (depending on the cluster version) and that the client connects to the correct cluster.

## B

### Backend server

A backend server in the context of WEKA is a server equipped with SSD drives and running the WEKA software. These servers are dedicated to the WEKA system, offering services to clients. A storage cluster is formed by a group of such backend servers, collectively providing storage and processing capabilities within the WEKA infrastructure.

### Birth time (birthtime)

Birth time, often called `birthtime` or `btime`, is a file system metadata attribute that records the original creation time of a file. Unlike access time (`atime`), modification time (`mtime`), or change time (`ctime`), the birthtime typically records the original creation time and is not updated by normal read or metadata operations.

In the WEKA filesystem, `birthtime` provides a reliable timestamp that reflects when the file was first created. This attribute is particularly valuable for data management, migration, and auditing workflows that require the preservation of original creation metadata to ensure data integrity and accurate historical tracking.

Birthtime support depends on underlying system and tool compatibility. When available, it appears in the output of commands such as stat, alongside other file timestamps.

## C

### Client

The WEKA client is software installed on user application servers that need access to WEKA file services. The WEKA client implements a kernel-based filesystem driver and the logic and networking stack to connect to the WEKA backend servers and be part of a cluster. In general industry terms, "client" may also refer to an NFS, SMB, or S3 client that uses those protocols to access the WEKA filesystem. For NFS, SMB, and S3, the WEKA client is not required to be installed in conjunction with those protocols.

### Cluster

A collection of WEKA backend servers, together with WEKA clients installed on the application servers, forming one shareable, distributed, and scalable file storage system.

### Container

WEKA uses Linux containers (LXC) as the mechanism for holding one process or keeping multiple processes together. Containers can have different processes within them. They can have frontend processes and associated DPDK libraries within the container, compute processes, drive processes, a management process, and DPDK libraries, or NFS, SMB, or S3 services running within them. A server can have multiple containers running on it at any time.

### Converged deployment

A WEKA configuration in which WEKA backend containers run on the same server with applications.

## D

### Data retention period

The target period of time for tiered data to be retained on an SSD.

### Data stripe width

The number of data blocks in each logical data protection group.

### Dedicated deployment

A WEKA configuration that dedicates complete servers and all of their allocated resources to WEKA backends, as opposed to a converged deployment.

## F

### Failure domain

A collection of hardware components that can fail together due to a single root cause.

### Filesystem group

A collection of filesystems that share a common tiering policy to object-store.

### Frontend

It is the collection of WEKA software that runs on a client and accesses storage services and IO from the WEKA storage cluster. The frontend consists of a process that delivers IO to the WEKA driver, a DPDK library, and the WEKA POSIX driver.

## H

### Host

The term "host" is deprecated. See [#container](#container "mention").

### Hot data

Frequently used data (as opposed to warm data), usually residing on SSDs.

## L

### Leader

In distributed systems, a leader is a process that assumes a special role, often responsible for coordination, synchronization, and making decisions on behalf of the cluster. The leader plays a crucial role in maintaining consistency and order among the distributed processes or nodes in the system. If the leader fails or is replaced, a new leader is typically elected to ensure the continued operation of the distributed system.

Within the context of WEKA, at the cluster's core resides the cluster leader, serving as the singular WEKA management process within the cluster. This unique role grants the cluster leader the exclusive capability to initiate and disseminate configuration changes throughout the entire cluster.

## M

### Machine

The term "machine" is deprecated. See [#server](#server "mention").

## N

### Net capacity

Amount of space available for user data on SSDs in a configured WEKA system.

### Node

The term "node" is deprecated. See [#process](#process "mention").

## O

### **OBS**

Object Storage. WEKA uses object storage buckets to extend the WEKA filesystem and to store uploaded file system snapshots.

## P

### **POSIX**

POSIX (Portable Operating System Interface) is a set of standards established by the IEEE Computer Society to ensure compatibility across diverse operating systems. The WEKA client adheres to the POSIX specifications, ensuring that it interacts with the underlying operating system following the defined POSIX standard. This compliance ensures seamless interoperability and consistent behavior, making the WEKA client often referred to as the POSIX client or POSIX driver when discussing the broader storage system architecture.

### Process

A software instance that WEKA uses to run and manage the filesystem. Processes are dedicated to managing different functions such as (1) NVMe Drives and IO to the drives, (2) compute processes for filesystems and cluster-level functions and IO from clients, (3) frontend processes for POSIX client access and sending IO to the compute process and (4) management processes for managing the overall cluster.

### Provisioned capacity

The total capacity that is assigned to filesystems. This includes both SSD and object store capacity.

### Prefetch

Prefetch in WEKA involves proactively promoting data from an object store to an SSD based on predictions of future data access. This process anticipates and preloads data onto faster storage, optimizing performance by ensuring that relevant information is readily available when needed.

### Promoting

Promoting refers to the action of moving data from a lower-tier storage, typically an object store, to a more accessible storage medium, such as an SSD, when the data is required for active use. This process aims to enhance performance by ensuring that frequently accessed or critical data is readily available on a faster storage tier.

## R

### Raw capacity

Total SSD capacity owned by the user.

### Rehydrating

See [#promoting](#promoting "mention").

### Retention period

The designated time duration for data to be stored on SSDs before releasing from the SSDs to an object store.

### Releasing

Releasing, in the context of data tiering, refers to deleting the SSD copy of data that has been migrated to the object store.

## S

### Server

A physical or virtual server that has hardware resources allocated to it and software running on it that provides compute or storage services. WEKA uses backend servers in conjunction with clients to deliver storage services. In general industry terms, in a cluster of servers, sometimes the term node is used instead.

### SR-IOV

SR-IOV (Single Root I/O Virtualization) is a technology that enables a single physical resource to be leveraged as multiple virtual resources. In essence, SR-IOV facilitates the partitioning of a single hardware component into distinct virtual functions, each operating independently. Correspondingly, the term Virtual Function (VF) aligns with SR-IOV, referring to these individualized virtualized entities. This technology is particularly valuable in optimizing resource utilization and enhancing the efficiency of virtualized environments.

### Stem mode

Stem Mode in WEKA refers to the installed and running software that has not yet been attached to a cluster.

### Snap-To-Object

Snap-To-Object is a WEKA feature facilitating the uploading of snapshots to object stores.

## T

### Tiered WEKA configuration

A tiered WEKA configuration combines SSDs and object stores for data storage.

### Tiering

Tiering is the dynamic process of copying data from an SSD to an object store while retaining the original copy on the SSD. This optimization strategy balances performance and cost considerations by keeping frequently accessed data on the high-performance SSD and moving less accessed data to a more economical object store.

### Tiering cue

Tiering Cue refers to the minimum duration that must elapse before considering data migration from an SSD to an object store. This time threshold is crucial in the context of data tiering strategies, where the decision to move data between different storage tiers is based on factors such as access frequency, performance requirements, and cost considerations. The Tiering Cue helps establish a timeframe for evaluating whether data should be transitioned from the faster but potentially more expensive SSD storage to the object store, which may offer more cost-effective, albeit slower, storage.

## U

### Unprovisioned capacity

Unprovisioned capacity refers to the storage space that is currently unused and available for the creation of new filesystems or data storage allocations. This term indicates the portion of storage resources that have not been assigned or allocated to any specific purpose, making it ready and waiting to be provisioned for new file systems or data storage needs.

## V

### VF

Virtual Function (VF) in the context of WEKA typically denotes the creation of multiple virtual instances of a physical network adapter. This involves leveraging SR-IOV (Single Root I/O Virtualization) technology, where a single physical resource can be partitioned into distinct virtual functions, each capable of independent operation. In essence, both Virtual Function and SR-IOV are terms integral to WEKA's approach to optimizing resource allocation and enhancing the efficiency of virtualized network environments by enabling the creation of multiple independent virtual instances from a single physical network adapter.

## W

### Warm data

Warm data is less frequently accessed or utilized data, unlike hot data, and is typically stored in an object store. This term is used to describe information that is accessed less regularly but remains relevant for specific use cases. Storing warm data on an object store allows for efficient management of data resources, providing a balance between accessibility and storage costs.


# Prerequisites and compatibility

This page describes the prerequisites and compatibility for the installation of the WEKA system.

{% hint style="warning" %}
**Important:** The versions mentioned on the prerequisites and compatibility page apply to the WEKA system's **latest minor version** (5.1.**X**). For information on new features and supported prerequisites released with each minor version, refer to the relevant release notes available at [get.weka.io](https://get.weka.io/).

Check the release notes for details about any updates or changes accompanying the latest releases.
{% endhint %}

{% hint style="info" %}
In certain instances, WEKA collaborates with Strategic Server Partners to conduct platform qualifications alongside complementary components. If you have any inquiries, contact your designated WEKA representative.
{% endhint %}

## Minimal server configuration for a WEKA cluster

The minimal configuration for a new WEKA cluster installation is **8 servers**. This ensures optimal performance, resilience, and scalability for most deployments.

{% hint style="info" %}
For cloud-based installations, WEKA supports a minimal configuration of **6 servers** to accommodate the unique requirements of cloud environments.
{% endhint %}

## CPU

<table><thead><tr><th width="356">CPU family/architecture</th><th width="202">Supported on backends</th><th>Supported on clients</th></tr></thead><tbody><tr><td>Intel Xeon E5 v3 (Haswell) through Xeon 6 (Granite Rapids / Sierra Forest) with up to 256 total CPU cores</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>Dual-socket</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>Single-socket and dual-socket</td></tr><tr><td>AMD EPYC™ processor families 2nd (Rome) through 5th (Turin) Generations with up to 256 total CPU cores</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>Single-socket</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>Single-socket and dual-socket</td></tr><tr><td>ARM (AArch64) - NVIDIA Grace single or dual-processor with up to 144 total CPU cores</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>NVIDIA Grace</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f44d">👍</span><br>NVIDIA Grace</td></tr></tbody></table>

{% hint style="info" %}
The following requirements must be met:

* AES[^1] is enabled.
* [Secure Boot](#user-content-fn-2)[^2] is disabled.
* AVX2[^3] is enabled.
  {% endhint %}

## Memory

* Sufficient memory to support the WEKA system needs as described in [memory requirements](/planning-and-installation/bare-metal/planning-a-weka-system-installation#memory-resource-planning).
* More memory support for the OS kernel or any other application.

## Operating system

{% hint style="info" %}
Every effort is made to support upcoming releases of the operating systems in the lists within one quarter (three months) of their respective General Availability (GA) dates. When an operating system version is deprecated, WEKA will cease to ensure its software continues to work with that operating system version.
{% endhint %}

{% tabs %}
{% tab title="Support policy" %}
**Manage operating system and kernel lifecycle**

Maintain system reliability by following the WEKA support policy for Linux distributions. This policy applies to WEKA software on customer-managed Linux servers in on-premises and cloud environments.

{% hint style="info" %}
This policy excludes Linux distributions bundled as part of the WEKA Software Appliance (WSA).
{% endhint %}

**Lifecycle definitions**

* **End of Support (EoS):** The date a vendor stops providing routine updates and patches.
* **End of Life (EoL):** The date a vendor ceases all standard support and maintenance for a distribution or kernel version.

**Lifecycle stages**

* **General Availability (GA):** WEKA aims to support new GA releases within three months of the vendor release date. After addition to the supported list, these versions receive full support, including certification, ongoing validation, and defect remediation aligned to the [Release support and commitments](/support/release-support-and-commitments).
* **End of Support and End of Life:** After a vendor EoS date, WEKA stops active testing and validation. Field issues receive best-effort remediation. If vendor backports are unavailable, fixes may require upgrading to a supported version. Plan migrations before the vendor EoL date.

**Custom kernel support**

For custom kernel certification, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endtab %}

{% tab title="Backends" %}

* **Rocky Linux:**
  * 10 (x86 and ARM), 9, 8 Release lines
* **RHEL:**
  * 10, 9, 8 Release lines
* **CentOS Stream:**
  * 10, 9, 8 Release lines
* **AlmaLinux OS:**
  * 10, 9, 8 Release lines
* **Ubuntu:**
  * 24.04, 22.04, 20.04, 18.04
* **Amazon Linux:**
  * AL2023 (x86 and ARM), AMI 2018.03, AMI 2017.09, Amazon Linux 2 LTS
    {% endtab %}

{% tab title="Clients" %}

* **Rocky Linux:**
  * 10 (x86 and ARM), 9, 8 Release lines
* **RHEL:**
  * 10, 9, 8 Release lines
* **CentOS Stream:**
  * 10, 9, 8 Release lines
* **AlmaLinux OS:**
  * 10, 9, 8 Release lines
* **Ubuntu:**
  * 24.04, 22.04, 20.04, 18.04
* **Amazon Linux:**
  * AL2023 (x86 and ARM), AMI 2018.03, AMI 2017.09, Amazon Linux 2 LTS
* **SELS:**
  * 16, 15, 12
* **Oracle Linux:**
  * 9, 8.9
* **Debian:**
  * 13, 12 (with Linux kernel 6.6), 10
* **Proxmox Virtual Environment**:
  * 9, 8.2, 8.14
* **Azure Linux**
  * 3
    {% endtab %}

{% tab title="Configuration" %}
**General**

* All WEKA servers must be synchronized in date/time (NTP recommended)
* A watchdog driver should be installed in /dev/watchdog (hardware watchdog recommended); search the WEKA knowledge base in the [WEKA support portal](http://support.weka.io) for more information and how-to articles.
* If using `mlocate` or alike, it's advisable to exclude `wekafs` from `updatedb` filesystems lists; search the WEKA knowledge base in the [WEKA support portal](http://support.weka.io) for more information and how-to articles.

**SELinux**

* Supported only on clients.
* Supported in both `permissive` and `enforcing` modes.
  * `The targeted` policy is supported.
  * The `mls` policy is not supported yet.

{% hint style="info" %}

* To set the SELinux security context for files, use the `-o acl` in the mount command, and define the `wekafs` to use extended attributes in the SELinux policy configuration (`fs_use_xattr`).
* The maximum size for the Extended Attributes (xattr) is limited to 1024. This attribute is crucial in supporting Access Control Lists (ACL) and Alternate Data Streams (ADS) in SMB. Given its finite capacity, exercise caution when using ACLs and ADS on a filesystem using SELinux.
  {% endhint %}
  {% endtab %}
  {% endtabs %}

{% hint style="info" %}

* **Amazon Linux:** WEKA does not support **kernel** versions 5.15 and later.
* Disable automatic **kernel** updates to prevent upgrades to unsupported versions.
* **CentOS Stream 8:** Deprecated because the vendor ended support.
  {% endhint %}

## WEKA installation directory

* **Installation directory**:
  * Set the WEKA installation directory directly to `/opt/weka`.
  * Avoid using symbolic links. They are not supported.
  * Ensure `/opt/weka` resides on high-availability storage if it's shared.
* **Boot drive requirements**:
  * Type and quantity: 2 NVMe SSDs
  * Capacity: 960 GB each
  * Durability: 1 DWPD (Drive Writes Per Day)
  * Write throughput: 1 GB/s
* **Boot drive setup**:
  * Dedicate one boot drive for the OS and the other for the `/opt/weka` directory.
  * Do not share the boot drive.
  * Do not mount using NFS.
  * Do not use a RAM drive remotely.
  * Do not use software RAID to have two boot drives.
* **Storage space requirements**:
  * Ensure a minimum of 26 GB is available for the WEKA installation.
  * Allocate an additional 10 GB per core used by WEKA.
* **Filesystem configuration:**
  * Create a separate filesystem on a dedicated partition for `/opt/weka`.

## Networking

Adhere to the following considerations when choosing the adapters:

* [**LACP**](#user-content-fn-4)[^4]**:** LACP is supported when bonding ports from dual-port Mellanox NICs into a single Mellanox device but is not compatible when using Virtual Functions (VFs).
* [**MTU**](#user-content-fn-5)[^5]\
  It is recommended to set the MTU to at least 4k on the NICs of WEKA cluster servers and the connected switches.
* [**Jumbo Frames**](#user-content-fn-6)[^6]\
  If any network connection, irrespective of whether it’s InfiniBand or Ethernet, on a given backend possess the capability to transmit frames exceeding 4 KB in size, it is mandatory for all network connections used directly by WEKA on that same backend to have the ability to transmit frames of at least 4 KB.
* [**IOMMU**](#user-content-fn-7)[^7] **support**\
  WEKA automatically detects and enables IOMMU for the server and PCI devices. Manual enablement is not required.

{% hint style="info" %}
When the Linux operating system is configured with `iommu=1`, IOMMU is enabled system-wide, and all PCI devices operate under IOMMU control. It is not possible to selectively exclude specific PCI devices from IOMMU when this mode is active.
{% endhint %}

* **Single IP**\
  Single IP (also known as shared networking) allows a single IP address to be assigned to the Physical Function (PF) and shared across multiple Virtual Functions (VFs). This means that a single IP can be shared by every WEKA process on that server, while still being available to the host operating system.
* **SR-IOV VF**

  Single Root I/O Virtualization Virtual Functions enable direct hardware access for virtual machines, improving network performance by reducing CPU overhead.

{% hint style="info" %}
Shared networking configuration for NIC models:

* NVIDIA NICs: When implementing Shared Networking (Single IP), Virtual Functions (VFs) are not required.

* Broadcom NICs: VFs must be configured when deploying Shared Networking architecture.
  {% endhint %}

* **Mixed networks**

  A mixed network configuration connects a WEKA cluster to both InfiniBand and Ethernet networks.

  RDMA is supported in mixed networks on adapters that support both mixed networks and RDMA. Review the remaining limitations and supported settings:

  * **Non-supported features in mixed networks:**
    * VLAN
    * IPv6
  * **Supported MTU settings in mixed networks:**
    * Ethernet (9000) + InfiniBand (4K)
  * **Non-supported MTU settings in mixed networks:**
    * Ethernet (1500) + InfiniBand (4K)
    * Ethernet (9000) + InfiniBand (2K)

* **Routed network**

  Enables communication between subnets using Layer 3 routing, allowing WEKA clusters to span multiple network segments.

* **HA (High Availability)**

  Ensures system uptime through redundant components and automatic failover.

* **RX Interrupts**

  Receive interrupts that notify the CPU when network packets arrive, critical for optimizing network processing performance.

* **IP addressing for dataplane NICs**\
  Exclusively use static IP addressing. DHCP is not supported for dataplane NICs.

* **WEKA peer connectivity requires NAT-free networking**

  WEKA requires visibility and connectivity to all peers, without interference from networking technologies like Network Address Translation (NAT).

* **PKEY (Partition Key)**\
  A feature specific to InfiniBand networks that enables the creation of isolated virtual networks (partitions) on a single physical fabric, controlling which endpoints can communicate.

**Related topics**

[Networking](/weka-system-overview/networking-in-wekaio)

### Supported network adapters for backends and clients <a href="#networking-ethernet" id="networking-ethernet"></a>

The WEKA system is compatible with various network adapters for both backend servers and clients. The following table lists these adapters, detailing their protocol type and a breakdown of both supported and unsupported features.

Use this information to verify hardware compatibility and understand the specific capabilities of each adapter within a WEKA environment.

<table><thead><tr><th width="199">Adapter</th><th width="114">Protocol</th><th width="248">Supported features</th><th>Unsupported features</th></tr></thead><tbody><tr><td>Amazon ENA</td><td>Ethernet</td><td>✅ SR-IOV VF</td><td><p>❌ Single IP</p><p>❌ HA</p><p>❌ Routed network</p><p>❌ LACP</p><p>❌ Mixed networks</p><p>❌ RX interrupts</p><p>❌ RDMA</p><p>❌ IOMMU</p></td></tr><tr><td>NVIDIA Mellanox CX-8</td><td><p>Ethernet</p><p>InfiniBand</p></td><td><p>✅ Mixed networks</p><p>✅ Single IP</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ Routed network (ETH only)</p><p>✅ PKEY (IB only)</p><p>✅ IOMMU</p></td><td><p>❌ LACP</p><p>❌ SR-IOV VF</p></td></tr><tr><td>NVIDIA Mellanox CX-7 single-port</td><td>InfiniBand</td><td><p>✅ Single IP</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ PKEY</p><p>✅ IOMMU</p></td><td><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p><p>❌ Routed network</p></td></tr><tr><td>NVIDIA Mellanox CX-7 dual-port</td><td>InfiniBand</td><td><p>✅ Single IP</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ PKEY</p><p>✅ IOMMU</p></td><td><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p><p>❌ Routed network</p></td></tr><tr><td>NVIDIA Mellanox CX-7-ETH single-port</td><td>Ethernet</td><td><p>✅ Single IP</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ Routed network</p><p>✅ IOMMU</p></td><td><p>❌ LACP</p><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p><p>❌ RX interrupts</p></td></tr><tr><td>NVIDIA Mellanox CX-7-ETH dual-port</td><td>Ethernet</td><td><p>✅ LACP</p><p>✅ Single IP</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ Routed network</p><p>✅ IOMMU</p></td><td><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p><p>❌ RX interrupts</p></td></tr><tr><td>NVIDIA Mellanox CX-6 LX</td><td>Ethernet</td><td><p>✅ Single IP</p><p>✅ RDMA</p><p>✅ RX interrupts</p><p>✅ HA</p><p>✅ Routed network</p><p>✅ IOMMU</p></td><td><p>❌ LACP</p><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p></td></tr><tr><td>NVIDIA Mellanox CX-6 DX</td><td>Ethernet</td><td><p>✅ LACP</p><p>✅ Single IP</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ Routed network</p><p>✅ IOMMU</p></td><td><p>❌ Mixed networks</p><p>❌ SR-IOV VF</p></td></tr><tr><td>NVIDIA Mellanox CX-6</td><td>Ethernet InfiniBand</td><td><p>✅ Mixed networks</p><p>✅ Single IP</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ IOMMU</p></td><td><p>❌ Routed network</p><p>❌ LACP</p><p>❌ SR-IOV VF</p></td></tr><tr><td>NVIDIA Mellanox CX-5 EX</td><td>Ethernet InfiniBand</td><td><p>✅ Mixed networks</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ PKEY (IB only)</p><p>✅ IOMMU</p></td><td><p>❌ Single IP</p><p>❌ Routed network</p><p>❌ LACP</p><p>❌ SR-IOV VF</p><p>❌ RX interrupts</p></td></tr><tr><td>NVIDIA Mellanox CX-5 BF</td><td>Ethernet</td><td><p>✅ Mixed networks</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ IOMMU</p></td><td><p>❌ Single IP</p><p>❌ Routed network</p><p>❌ LACP</p><p>❌ SR-IOV VF</p><p>❌ RX interrupts</p></td></tr><tr><td>NVIDIA Mellanox CX-5</td><td>Ethernet InfiniBand</td><td><p>✅ Mixed networks</p><p>✅ RX interrupts</p><p>✅ RDMA</p><p>✅ HA</p><p>✅ Routed network (ETH only)</p><p>✅ PKEY (IB only)</p><p>✅ IOMMU</p></td><td><p>❌ Single IP</p><p>❌ LACP</p><p>❌ SR-IOV VF</p><p>❌ Routed network (IB)</p></td></tr><tr><td>VirtIO</td><td>Ethernet</td><td><p>✅ HA</p><p>✅ Routed network</p></td><td><p>❌ Mixed networks</p><p>❌ Single IP</p><p>❌ LACP</p><p>❌ RX interrupts</p><p>❌ SR-IOV VF</p><p>❌ IOMMU</p></td></tr></tbody></table>

{% hint style="info" %}
**NVIDIA Mellanox ConnectX-4 (CX-4 / CX-4 LX)**

This adapter is not supported starting with WEKA 5.1.0. DPDK support for ConnectX-4 was discontinued, and the adapter reached end-of-life in January 2022.
{% endhint %}

### Supported network adapters for clients-only

The following network adapters support Ethernet and SR-IOV VF for clients only:

* Intel X540
* Intel X550-T1 (avoid using this adapter in a single client connected to multiple clusters)
* Intel X710
* Intel X710-DA2
* Intel XL710
* Intel XL710-Q2
* Intel XXV710
* Intel 82599ES
* Intel 82599
* Broadcom BCM957508-P2100G
* Broadcom BCM957608-P2200G

{% hint style="info" %}
Broadcom NICs are unsupported for guest VMs on KVM or VMware.
{% endhint %}

### OFED drivers

OFED is not required for standard Ethernet deployments. OFED is required only when using LACP on a single NIC with dual ports to enable proper load balancing between the ports. This requirement is driven by the NIC networking stack, not by WEKA.

{% hint style="info" %}
OFED is not a WEKA dependency. When required, it is due to NIC driver behavior needed to support LACP load balancing.
{% endhint %}

### Ethernet drivers and configurations

{% tabs %}
{% tab title="Ethernet drivers" %}
**Supported Mellanox OFED versions for the Ethernet NICs:**

* 24.10
* 24.04
* 23.10
* 23.04

{% hint style="info" %}
Subsequent OFED minor versions are expected to be compatible with Nvidia hardware due to Nvidia's commitment to backward compatibility.
{% endhint %}

**Supported ENA drivers:**

* 1.0.2 - 2.0.2
* A current driver from an official OS repository is recommended

**Supported ixgbevf drivers:**

* 3.2.2 - 4.1.2
* A current driver from an official OS repository is recommended

**Supported Broadcom drivers**:

* 228: Minimum required for 100/200 Gbps 57508 NIC
* 231: Minimum required for 200/400 Gbps 57608 NIC
  {% endtab %}

{% tab title="Ethernet configurations" %}

* **NICs bonding:**
  * Supports bonding dual ports on the same NVIDIA Mellanox NIC using mode 4 (LACP) to enhance redundancy and performance.
* **Ethernet speeds:**
  * 400 GbE / 200 GbE / 100 GbE / 50GbE / 40 GbE / 25 GbE / 10 GbE.
* **IEEE 802.1Q VLAN encapsulation:**
  * Supports VLAN tagging with a single VLAN tag on NVIDIA Mellanox NICs.
* **VXLAN:**
  * Virtual Extensible LANs are not supported.
* **DPDK backends and clients using NICs supporting shared networking (single IP):**
  * Require one IP address per client for both management and data plane.
  * SR-IOV enabled is not required.
* **DPDK backends clients using NICs supporting non-shared networking:**
  * IP address for management: One per NIC (configured before WEKA installation).
  * IP address for data plane: One per [WEKA core](/planning-and-installation/bare-metal/planning-a-weka-system-installation#cpu-resource-planning) in each server (applied during cluster initialization).
  * [Virtual Functions](https://en.wikipedia.org/wiki/Network_function_virtualization) (VFs):
    * Ensure the device supports a maximum number of VFs greater than the number of physical cores on the server.
    * Set the number of VFs to match the cores you intend to dedicate to WEKA.
    * Note that some BIOS configurations may be necessary.
  * SR-IOV: Enabled in BIOS.
* **UDP clients:**
  * Use a single IP address for all purposes.

{% hint style="info" %}
When assigning a network device to the WEKA system, no other application can create VFs on that device.
{% endhint %}
{% endtab %}
{% endtabs %}

### InfiniBand drivers and configurations <a href="#networking-infiniband" id="networking-infiniband"></a>

{% tabs %}
{% tab title="InfiniBand drivers" %}
WEKA supports the following Nvidia major OFED versions for the InfiniBand adapters:

* 24.10
* 24.04
* 23.10
* 23.04

{% hint style="info" %}
Subsequent OFED minor versions are expected to be compatible with NVIDIA hardware due to Nvidia's commitment to backwards compatibility.
{% endhint %}
{% endtab %}

{% tab title="InfiniBand configurations" %}
WEKA supports the following InfiniBand configurations:

* InfiniBand speeds: Determined by the InfiniBand adapter supported speeds (FDR / EDR / HDR / NDR).
* Subnet manager: Configured to 4092.
* One WEKA system IP address for management and data plane.
* PKEYs: One partition key is supported by WEKA.
* Redundant InfiniBand ports can be used for both HA and higher bandwidth.

{% hint style="info" %}
If it is necessary to change PKEYs, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contacting-weka-technical-support-team).
{% endhint %}
{% endtab %}
{% endtabs %}

### Required ports

When configuring firewall ingress and egress rules the following access must be allowed.

{% hint style="info" %}
Right-scroll the table to view all columns.
{% endhint %}

<table><thead><tr><th width="211">Purpose</th><th width="124">Source</th><th width="142">Target</th><th width="228">Target Ports</th><th width="135">Protocol</th><th width="352">Comments</th></tr></thead><tbody><tr><td>WEKA server traffic for bare-metal deployments</td><td>All WEKA backend IPs</td><td>All WEKA backend IPs</td><td>14000-14059 (drives)<br>14200-14259 (frontend)<br>14300-14359 (compute)</td><td>TCP and UDP<br>TCP and UDP<br>TCP and UDP</td><td>These ports are the default for the Resources Generator for the first three containers. You can customize the ports.</td></tr><tr><td>WEKA client traffic</td><td>Client host IPs</td><td>All WEKA backend IPs</td><td>14000-14059 (drives)<br>14300-14359 (compute)</td><td>TCP and UDP<br>TCP and UDP</td><td>These ports are the default. You can customize the ports.</td></tr><tr><td>WEKA backend to client traffic</td><td>All WEKA backend IPs</td><td>Client host IPs</td><td>14000-14059 (frontend)</td><td>TCP and UDP</td><td>These ports are the default. You can customize the ports.</td></tr><tr><td>WEKA SSH management traffic</td><td>All WEKA backend IPs</td><td>All WEKA backend IPs</td><td>22</td><td>TCP</td><td></td></tr><tr><td>WEKA server traffic for cloud deployments</td><td>All WEKA backend IPs</td><td>All WEKA backend IPs</td><td><p>14000-14059 (drives)</p><p>15000-15059 (compute)</p><p>16000-16059 (frontend)</p></td><td>TCP and UDP<br>TCP and UDP<br>TCP and UDP</td><td>These ports are the default. You can customize the ports.</td></tr><tr><td>WEKA client traffic (on cloud)</td><td>Client host IPs</td><td>All WEKA backend IPs</td><td><p>14000-14059 (drives)</p><p>15000-15059 (compute)</p></td><td>TCP and UDP<br>TCP and UDP</td><td>These ports are the default. You can customize the ports.</td></tr><tr><td>WEKA backend to client traffic (on cloud)</td><td>All WEKA backend IPs</td><td>Client host IPs</td><td>14000-14059 (frontend)</td><td>TCP and UDP</td><td>These ports are the default. You can customize the ports.</td></tr><tr><td>WEKA GUI access</td><td>Admin workstation IPs</td><td>All WEKA management IPs</td><td>14000</td><td>TCP</td><td>User web browser IP</td></tr><tr><td>NFS</td><td>NFS client IPs</td><td>WEKA NFS backend IPs</td><td>2049<br>&#x3C;mountd port></td><td>TCP and UDP<br>TCP and UDP</td><td>You can set the <code>mountd</code> port using the command: <code>weka nfs global-config set --mountd-port</code></td></tr><tr><td>NFSv3 (used for locking)</td><td>NFS client IPs</td><td>WEKA NFS backend IPs</td><td><p>46999 (status monitor)<br>47000 (lock manager)</p><p>111 (rpcbind)</p></td><td>TCP and UDP</td><td></td></tr><tr><td>SMB/SMB-W</td><td>SMB client IPs</td><td>WEKA SMB backend IPs</td><td>139<br>445</td><td>TCP<br>TCP</td><td></td></tr><tr><td>SMB-W</td><td>All WEKA SMB-W backend IPs</td><td>All WEKA SMB-W backend IPs</td><td>2224</td><td>TCP</td><td>This port is required for internal clustering processes.</td></tr><tr><td>SMB/SMB-W</td><td>WEKA SMB backend IPs</td><td>All Domain Controllers for the selected Active Directory Domain</td><td><p>88</p><p>389<br>464<br>636<br>3268<br>3269</p></td><td>TCP and UDP<br>TCP and UDP<br>TCP and UDP<br>TCP and UDP<br>TCP and UDP<br>TCP and UDP</td><td>These ports are required for SMB/SMB-W to use Active Directory as the identity source. Furthermore, every Domain Controller within the selected AD domain must be accessible from the WEKA SMB servers.</td></tr><tr><td>SMB/SMB-W</td><td>WEKA SMB backend IPs</td><td>DNS servers</td><td>53</td><td>TCP and UDP</td><td></td></tr><tr><td>S3</td><td>S3 client IPs</td><td>WEKA S3 backend IPs</td><td>9000</td><td>TCP</td><td>This port is the default. You can customize the port.</td></tr><tr><td>wekatester</td><td>All WEKA backend IPs</td><td>All WEKA backend IPs</td><td>8501<br>9090</td><td>TCP<br>TCP</td><td>Port 8501 is used by wekanetperf.</td></tr><tr><td>WEKA Management Station</td><td>User web browser IP</td><td>WEKA Management Station IP</td><td><p>80 &#x3C;LWH></p><p>443 &#x3C;LWH></p><p>3000 &#x3C;mon></p><p>7860 &#x3C;admin UI></p><p>8760 &#x3C;deploy></p><p>8090 &#x3C;snap></p><p>8501 &#x3C;mgmt><br>9090 &#x3C;mgmt></p><p>9091 &#x3C;mon><br>9093 &#x3C;alerts></p></td><td><p>HTTP</p><p>HTTPS</p><p>TCP</p><p>TCP</p><p>TCP</p><p>TCP<br>TCP</p><p>TCP<br>TCP</p></td><td></td></tr><tr><td>Cloud WEKA Home, Local WEKA Home</td><td>All WEKA backend IPs</td><td><p>Cloud WEKA Home or</p><p>Local WEKA Home</p></td><td>80<br>443</td><td>HTTP<br>HTTPS</td><td><p>Open according to the directions in the deployment scenario:<br>- WEKA server IPs to CWH or LWH.<br>- LWH to CWH (if forwarding data from LWH to CWH)<br>Endpoint URLs:</p><ul><li><code>api.home.weka.io</code></li><li><code>get.weka.io</code></li></ul></td></tr><tr><td>Client telemetry and statistics</td><td>WEKA client IPs</td><td><p>Cloud WEKA Home or</p><p>Local WEKA Home</p></td><td>80<br>443</td><td>HTTP<br>HTTPS</td><td>Lack of connectivity prevents client-related statistics from being reported.<br></td></tr><tr><td>Troubleshooting by the Customer Success Team (CST)</td><td>All WEKA backend IPs</td><td>CST remote access</td><td>4000<br>4001</td><td>TCP<br>TCP</td><td></td></tr><tr><td>Traces remote viewer</td><td>All WEKA backend IPs</td><td>CST remote access</td><td>443</td><td>TCP</td><td></td></tr><tr><td>KMS: Vault or OpenBao</td><td>All WEKA backend IPs</td><td>Vault/OpenBao server</td><td>8200<br>8201</td><td>TCP<br>TCP</td><td>Default vault ports: 8200 is configurable for client requests, while 8201 (base_port+1) handles internal cluster communication.</td></tr><tr><td>KMS: KMIP</td><td>All WEKA backend IPs</td><td>KMIP server</td><td>5696</td><td>TCP</td><td>The default KMIP port, 5696, is configurable. Per the KMIP specification, servers must use this port when operating with the <a data-footnote-ref href="#user-content-fn-8">TTLV</a> encoding format.</td></tr></tbody></table>

## HA

See [Networking](/weka-system-overview/networking-in-wekaio#high-availability)

## SSD requirements

Review the requirements for SSDs used in a WEKA cluster.

* SSDs must support Power Loss Protection (PLP).
* Dedicate the entire SSD for WEKA system storage. Partitioning the drive is not supported.
* Use SSDs with a capacity of up to 30 TB.
* Maintain a capacity ratio of 8:1 or less between the smallest and largest SSDs in the cluster.
* Maintain a ratio of 8000:1 or less between the total SSD capacity and the total RAM of the cluster.

{% hint style="info" %}
To get the best performance, ensure [TRIM](https://en.wikipedia.org/wiki/Trim_\(computing\)) is supported by the device and enabled in the operating system.
{% endhint %}

## Object store

* API must be S3 compatible:
  * GET
    * Including byte-range support with expected performance gain when fetching partial objects
  * PUT
    * Supports any byte size of up to 65 MiB
  * DELETE
* Data consistency: [Amazon S3 consistency model](https://docs.aws.amazon.com/AmazonS3/latest/dev/Introduction.html#ConsistencyModel):
  * GET after a single PUT is strongly consistent
  * Multiple PUTs are eventually consistent

WEKA integrates with object stores for two primary purposes: extending the filesystem capacity with a lower-cost tier and creating remote backups for disaster recovery. Support for these functions varies by the object store provider and its specific configuration.

* **Tiering:** Moves inactive data from the high-performance SSD tier to a designated object store bucket. This frees up SSD capacity while keeping the data accessible within the unified filesystem namespace. Tiering requires high performance and consistency from the object store.
* **Snap-to-Object:** Sends immutable snapshots of a filesystem to a remote object store. This provides an efficient and secure method for remote backup and disaster recovery.

### Certified object stores and support status

The following table details the support status for certified object store solutions.

<table><thead><tr><th width="187.92578125">Object Store</th><th width="186.94921875">Storage Class / Version</th><th>Supportability notes</th></tr></thead><tbody><tr><td>Amazon S3</td><td><p>S3 Standard</p><p>S3 Intelligent-Tiering</p></td><td>Tiering and snap-to-object</td></tr><tr><td></td><td>S3 Standard-IA<br>S3 One Zone-IA<br>S3 Glacier Instant Retrieval</td><td>Snap-to-object supported; tiering not recommended (slow retrieval, storage period, access costs). Best for backups/DR. Use Intelligent-Tiering if unsure.</td></tr><tr><td>Azure Blob Storage</td><td></td><td>Tiering and snap-to-object</td></tr><tr><td>Cloudian HyperStore</td><td>7.3</td><td>Tiering and snap-to-object</td></tr><tr><td>CoreWeave AI Object Storage (CAIOS)</td><td></td><td>Snap-to-object; tiering not supported</td></tr><tr><td>Google Cloud Storage (GCS)</td><td></td><td>Tiering and snap-to-object</td></tr><tr><td>Dell EMC ECS</td><td>3.5</td><td>Tiering and snap-to-object</td></tr><tr><td>Dell PowerScale S3</td><td>9.8.0.0</td><td>Tiering and snap-to-object (all-flash models only)</td></tr><tr><td>HCP Classic</td><td>9.2+ (versioned buckets)</td><td>Tiering and snap-to-object</td></tr><tr><td>HCP for Cloud-Scale</td><td>2.x</td><td>Tiering and snap-to-object</td></tr><tr><td>IBM Cloud Object Storage</td><td>3.14.7</td><td>Tiering and snap-to-object</td></tr><tr><td>Lenovo MagnaScale</td><td>3</td><td>Tiering and snap-to-object</td></tr><tr><td>Quantum ActiveScale</td><td>5.5.1</td><td>Tiering and snap-to-object</td></tr><tr><td>Red Hat Ceph Storage</td><td>5</td><td>Tiering and snap-to-object</td></tr><tr><td>Scality Artesca</td><td>1.5.2</td><td>Tiering and snap-to-object</td></tr><tr><td>Scality RING S3 Connector</td><td>8.5</td><td>Tiering and snap-to-object</td></tr><tr><td>Scality RING WEKA Connector</td><td>9.5</td><td>Tiering and snap-to-object</td></tr><tr><td>SwiftStack</td><td>6.3</td><td>Tiering and snap-to-object</td></tr><tr><td>WEKA S3</td><td></td><td>Tiering and snap-to-object</td></tr></tbody></table>

### S3-Compatible object store requirements

To ensure stability, performance, and data integrity, any S3-compatible object store used with WEKA must meet the following minimum requirements.

**API requirements**

The object store must provide a fully S3-compatible API that supports the following operations:

* **GET**: Must include support for byte-range requests to allow for efficient fetching of partial objects.
* **PUT**: Must support uploads of any object size up to 65 MiB.
* **DELETE**: Must support standard object deletion.

**Data consistency requirements**

The object store must adhere to the [Amazon S3 data consistency model](https://docs.aws.amazon.com/AmazonS3/latest/dev/Introduction.html#ConsistencyModel):

* **Strong read-after-write consistency:** A `GET` request for an object that occurs after a successful `PUT` request has created that object must immediately return the new object's data.
* **Eventual consistency:** `PUT` requests that overwrite existing objects, or `DELETE` requests, are eventually consistent. This means that a subsequent `GET` request might temporarily return the older version of the data before the update or deletion has fully propagated across the system.

## Virtual Machines

This section outlines the use of virtual machines (VMs) with WEKA, covering backends, clients, VMware platforms, and cloud environments. While VMs can be used in certain configurations, there are specific limitations and best practices to follow.

### Backends

Virtual machines may be used as backends for internal training purposes only and are not recommended for production environments.

WEKA provides best-effort support for backends deployed on virtual machines, but full support is not guaranteed. Additionally, WEKA does not guarantee support for components or configurations outside of our documented and supported cloud environments, and performance may vary.

### Clients

Virtual Machines (VMs) can be used as clients. Ensure the following prerequisites are met for each client type:

* **UDP clients**:
  * Reserve CPU resources and dedicate a core to the client to prevent CPU starvation of the WEKA process.
  * Ensure the root filesystem supports a 3K IOPS load for the WEKA client.
* **DPDK clients**:
  * Meet all the requirements for UDP clients.
  * Additionally, verify that the virtual platform (hypervisor, NICs, CPUs, and their respective versions) fully supports DPDK and the required virtual network drivers.

### **VMware platform (**&#x63;lient only)

When using **vmxnet3** devices, do not enable the SR-IOV feature, because it disables the vMotion functionality. Each frontend process requires a dedicated **vmxnet3** device and IP address, with an additional device and IP for each client VM to support the management process.

Core dedication is required when using **vmxnet3** devices.

### VMs and instances on cloud environments

Refer to the cloud deployment sections for the most up-to-date list of supported virtual machines and instances in various cloud environments.

**Related topics**

AWS: [Supported EC2 instance types using Terraform](/planning-and-installation/aws/supported-ec2-instance-types)

Azure: [Supported virtual machine types](/planning-and-installation/weka-installation-on-azure/supported-virtual-machine-types)

GCP: [Supported machine types and storage](/planning-and-installation/weka-installation-on-gcp/supported-machine-types-and-storage)

\
**Related information**

For additional information and how-to articles, search the WEKA Knowledge Base in the [WEKA support portal](http://support.weka.io) or contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contacting-weka-technical-support-team).

## KMS

**Supported KMS types:**

* [**KMIP-compliant KMS**](http://docs.oasis-open.org/kmip/spec/v1.2/os/kmip-spec-v1.2-os.html)**:** Supports protocol versions 1.2 or later and 2.x. Only TTLV[^8] is supported as the messaging protocol. Supports commercial solutions such as Thales CipherTrust Manager.
* [**HashiCorp Vault**](https://www.hashicorp.com/products/vault/)**:** Supports versions 1.x.
* [**OpenBao Vault**](https://openbao.org/): Supports version 2.5.1 or later.

[^1]: **AES (Advanced Encryption Standard)** in BIOS settings refers to hardware acceleration for AES encryption. Enabled by default, it speeds up encryption tasks using AES-NI. Disabling it may affect performance in encryption-heavy applications.

[^2]: **Secure Boot** is a BIOS/UEFI feature that ensures only trusted software is loaded during startup. If Secure Boot is disabled, the system allows any software to run.

[^3]: **AVX2 (Advanced Vector Extensions 2)** is a CPU instruction set that enhances performance on floating-point and integer operations. It is enabled by default on supported hardware, but can be disabled in virtual machines, depending on the hypervisor configuration. Ensure your VM settings allow AVX2.

[^4]: LACP stands for "Link Aggregation Control Protocol." It is a networking protocol that enables the bundling of multiple network connections in parallel to increase bandwidth and provide redundancy.

[^5]: MTU (Maximum Transmission Unit) represents the maximum size of a data packet that can be transmitted over a network.

[^6]: Jumbo Frames refer to network frames that exceed the standard Maximum Transmission Unit (MTU) size, allowing for larger data packets to be transmitted over a network.

[^7]: The IOMMU (Input/Output Memory Management Unit) is a hardware component that manages and controls data transfers between devices (like graphics cards) and a computer's main memory, enhancing system security and performance.

[^8]: **TTLV (Tag-Length-Value)** is a binary encoding format used in KMIP for structured and efficient messaging between a KMS and its clients. It consists of a tag (data type), length (size), and value (data).


# System installation on bare metal servers

Explore the automated tools and workflow paths for installing and configuring WEKA software on a group of bare metal servers in an on-premises environment.

## Choose an installation path

WEKA supports two installation paths for bare metal servers:

* Path A: Automated installation with the WEKA Software Appliance (WSA).
* Path B: Manual installation with an operating system and tools of your choice.

### Path A: Automated installation with WSA

WEKA Software Appliance (WSA): a server image that includes a preconfigured operating system (Rocky Linux 8.10), drivers, WEKA software, and support tools.

WSA speeds up operating system deployment and WEKA software installation. Download WSA and install it on the servers. After installation, the server starts in STEM mode and is ready for configuration.

Use this path when the WSA operating system meets your deployment requirements. This is the fastest supported path from bare metal to a working WEKA cluster.

### Path B: Manual installation

Use this path if:

* You want to use a different operating system.
* You need a customized server image.
* You cannot use the WSA deployment model.

Download the WEKA software, install the operating system and WEKA software, and prepare the servers.

{% hint style="info" %}
The manual installation workflow requires deep knowledge of WEKA architecture. Visit WEKA U for training material. Sign-in is required.
{% endhint %}

## High-level deployment workflow

Review the deployment workflow for a group of bare metal servers.

<div data-with-frame="true"><figure><img src="/files/Uafwl1AlC3MpWaGxl9eD" alt="" width="563"><figcaption><p>High-level deployment workflow</p></figcaption></figure></div>

### Continue with cluster configuration

Once the servers are ready, choose the configuration method that matches your installation path:

* Path A: Run the WEKA Configurator. It is the simpler option for WSA-based deployment and generates the cluster configuration script.
* Path B: Run the WEKA Configurator for guided setup, or run the Resources Generator to generate the resource files required for manual container creation on the cluster servers.

All supported configuration methods lead to the same next step: completing post-configuration.

<details>

<summary>Frequently asked questions</summary>

1. What is the root password? Is this configurable, and can it be encrypted?
   * The default WSA root password is `WekaService`.
2. Can we choose the number of cores and containers to use?
   * Yes. Set them during cluster configuration.
3. Will the ISO setup mirror RAID on the dual-boot SSDs?
   * Yes, automatically.
4. Can I set up WEKA with 8 SSDs per node even though I have 12 installed?
   * Not automatically. Pull the drives or manually adjust the configuration before running it. Edit the `config.sh` output from `wekaconfig`.
5. What must be done to direct the ISO to set up for High Availability (HA)? How about no HA?
   * Set that during cluster configuration with `wekaconfig`.
6. If there are multiple NIC cards (for WEKA and Ceph), how do I choose the NICs to use for the WEKA backend server?
   * Configure the required dataplane interfaces and routes during cluster configuration.
7. With the ISO, are there different licensing processes? Or is it standard to get the cluster GUID and storage size, enter it on the WEKA webpage to get a license key, and enter that key on the command line?
   * Licensing has not changed.
8. Does the ISO configure the management or dataplane IP addresses?
   * No. Configure networking after the server reboots into STEM mode.
9. What needs to be configured for Ethernet or InfiniBand?
   * Set the network interfaces, IP addresses, routes, and related cluster settings during configuration.
10. What additional settings are required after the ISO installation?
    * Configure networking, validate the environment, and build the cluster.

</details>

## What to do next?

Go to [Plan hardware requirements](/planning-and-installation/bare-metal/planning-a-weka-system-installation).


# Plan hardware requirements

The planning of a WEKA system is essential before the actual installation process. It involves the planning of the following:

1. Total SSD net capacity and performance requirements
2. SSD resources
3. Memory resources
4. CPU resources
5. Network

{% hint style="info" %}
When implementing an AWS configuration, it is possible to go to the [Self-Service Portal in start.weka.io](broken://pages/-L7Tv_d53m7ZQP8937LL) to map capacity and performance requirements into various configurations automatically.
{% endhint %}

## Total SSD net capacity and performance planning

A WEKA system cluster runs on a group of servers with local SSDs. To plan these servers, the following information must be clarified and defined:

1. **Capacity:** Plan your net SSD capacity. The data management to object stores can be added after the installation. In the context of the planning stage, only the SSD capacity is required.
2. **Redundancy scheme:** Define the optimal redundancy scheme required for the WEKA system, as explained in [Selecting a Redundancy Scheme](/weka-system-overview/about#selecting-a-redundancy-scheme).
3. **Failure domains:** Determine whether to use failure domains (optional), and if yes, determine the number of failure domains and the potential number of servers in each failure domain, as described in [Failure Domains](broken://pages/-L7yY2QmpKSIOpgDhBFf#failure-domains-optional), and plan accordingly.
4. **Hot spare**: Define the required hot spare count (see [Cluster capacity and redundancy management](/weka-system-overview/cluster-capacity-and-redundancy-management#hot-spare-capacity)).

Once all this data is clarified, you can plan the SSD net storage capacity accordingly (see [Cluster capacity and redundancy management](/weka-system-overview/cluster-capacity-and-redundancy-management#ssd-net-storage-capacity-calculation)). Adhere to the following information, which is required during the installation process:

1. Cluster size (number of servers).
2. SSD capacity for each server, for example, 12 servers with a capacity of 6 TB each.
3. Planned protection scheme, for example, 6+2.
4. Planned failure domains (optional).
5. Planned hot spare.

{% hint style="info" %}
This is an iterative process. Depending on the scenario, some options can be fixed constraints while others are flexible.
{% endhint %}

## SSD resource planning

SSD resource planning involves how the defined capacity is implemented for the SSDs. For each server, the following has to be determined:

* The number of SSDs and capacity for each SSD (where the multiplication of the two should satisfy the required capacity per server).
* The selected technology, NVME, SAS, or SATA, and the specific SSD models have implications on SSD endurance and performance.

{% hint style="info" %}
For on-premises planning, it is possible to consult with the Customer Success Team to map between performance requirements and the recommended WEKA system configuration.
{% endhint %}

## Memory resource planning <a href="#memory-resource-planning" id="memory-resource-planning"></a>

### Backend servers memory requirements

The total per server memory requirements are the sum of the following requirements:

<table><thead><tr><th width="247">Purpose</th><th>Per-server memory</th></tr></thead><tbody><tr><td>Fixed</td><td>2.61 GiB</td></tr><tr><td>Frontend processes</td><td>2.05 GiB × # of Frontend processes</td></tr><tr><td>Compute processes</td><td>3.63 GiB × # of Compute processes</td></tr><tr><td>Drive processes</td><td>1.86 GiB × # of Drive processes</td></tr><tr><td>SSD capacity management</td><td>(Total SSD raw capacity in GiB ÷ Number of Servers ÷ 2,000) + (Number of Cores × 2.79 GiB)</td></tr><tr><td>Operating System</td><td>The maximum between 7.45 GiB and 2% of the total RAM</td></tr><tr><td>Additional protocols (NFS/SMB/S3)</td><td>14.9 GiB</td></tr><tr><td>RDMA</td><td>1.86 GiB</td></tr><tr><td>Metadata (pointers)</td><td>20 Bytes × # Metadata units per server<br>See <a href="/pages/3dgkHLifLyHWt3bxBSLr#metadata-calculations">Metadata units calculation</a>.</td></tr><tr><td>Dedicated Data Services container</td><td><p>If you intend to add a <a data-footnote-ref href="#user-content-fn-1">Data Services container for background tasks</a>, it requires additional memory:</p><ul><li>3.26 GiB (without dedicated core)</li><li>5.12 GiB (with dedicated core)</li></ul></td></tr></tbody></table>

{% hint style="warning" %}
Contact the Customer Success Team to explore options for configurations requiring more than 357.6 GiB of memory per server.
{% endhint %}

#### Example 1: A system with large files

A system with 16 servers with the following details:

* Fixed: 2.61 GiB\
  Number of Frontend processes: 1
* Number of Compute processes: 13
* Number of Drive processes: 6
* Total raw capacity: 915,490.1 GiB
* Total net capacity: 675,208.9 GiB
* NFS/SMB services
* RDMA
* Average file size: 1 MB (potentially up to 755 million files for all servers; \~47 million files per server)

Calculations:

* Frontend processes: 1 × 2.05 = 2.05 GiB
* Compute processes: 13 × 3.63 = 47.2 GiB
* Drive processes: 6 × 1.86 = 11.2 GiB
* SSD capacity management: 915,490.1 GiB ÷ 16 ÷ 2,000 + 20 × 2.79 GiB = \~84.5 GiB
* Additional protocols = 14.9 GiB
* RDMA = 1.86 GiB
* Metadata: 20 Bytes × 47 million files × 2 units = \~1.8 GiB

Total memory requirement per server = 2.61 + 2.05 + 47.2 + 11.2 + 84.5 + 14.9 + 1.86 + 1.8 = \~166.1 GiB

#### Example 2: A system with small files

For the same system as in example 1, but with smaller files, the required memory for metadata would be larger.

For an average file size of 64 KB, the number of files is potentially up to:

* \~12 billion files for all servers.
* \~980 million files per server.

Required memory for metadata: 20 Bytes × 980 million files × 1 unit = \~18.3 GiB

Total memory requirement per server = 2.61 + 2.05 + 47.2 + 11.2 + 84.5 + 14.9 + 1.86 + 18.3 = \~182.6 GiB

{% hint style="info" %}
The memory requirements are conservative and can be reduced in some situations, such as in systems with mostly large files or a system with files 4 KB in size. Contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team) to receive an estimate for your specific configuration.
{% endhint %}

### Client's memory requirements

The minimum memory requirement for a WEKA client is 5 GiB. This minimum supports a single frontend (FE) process with a minimal HugePages allocation, but limits the number of concurrent I/Os WEKA can perform.

For a typical client deployment, the total memory requirement is the sum of the following:

<table><thead><tr><th width="284">Purpose</th><th>Per-client memory</th></tr></thead><tbody><tr><td>Base</td><td>3 GiB</td></tr><tr><td>Frontend (FE) processes</td><td>2.5 GiB × number of FE processes</td></tr><tr><td>HugePages (configured)</td><td>Container HugePages</td></tr><tr><td>HugePages (default)</td><td>1.4 GiB × number of FE processes</td></tr><tr><td>OS and kernel cache</td><td>See note below</td></tr></tbody></table>

{% hint style="info" %}
The WEKA client uses the Linux kernel page cache to accelerate read and write operations. The kernel cache grows to fill available memory, so leaving additional RAM beyond the WEKA process requirements improves I/O performance. The recommended headroom matches the working set size of your workload, though this varies by application. Leave as much free RAM as the system allows.
{% endhint %}

**Example 1: Client with default HugePages**

A client with the following details:

* Number of FE processes: 2

Calculations:

* Base: 3 GiB
* FE processes: 2× 2.5 = 5 GiB
* HugePages: 1.4 x 2 = 2.8 GiB

Total WEKA process memory = 3 + 5 + 2.8 = **10.8 GiB**, plus additional RAM for OS and kernel cache.

**Example 2: Client with configured HugePages**

A client with the following details:

* Number of FE processes: 2
* Configured HugePages: 6 GiB

Calculations:

* Base: 3 GiB
* FE processes: 2 × 2.5 = 5 GiB

Total WEKA process memory = 3 + 5 + 6 = **14 GiB**, plus additional RAM for the OS and kernel cache.

{% hint style="warning" %}
Clients running workloads that consume all available RAM, such as Slurm jobs with no memory reservation, leave no RAM for the kernel cache. This results in degraded I/O performance even for workloads that are not I/O intensive. Reserve sufficient RAM for the OS and kernel cache outside of job schedulers. For Slurm specific guidance, see [WEKA and Slurm integration](/best-practice-guides/weka-and-slurm-integration).
{% endhint %}

## CPU resource planning

Learn about the CPU allocation strategy and resource planning for backend, additional protocols, and client processes.

### CPU allocation strategy

The WEKA system implements a Non-Uniform Memory Access (NUMA) aware CPU allocation strategy to maximize the overall performance of the system. The cores allocation uses all NUMAs equally to balance memory usage from all NUMAs.

Consider the following regarding the CPU allocation strategy:

* The code allocates CPU resources by assigning individual cores to tasks in a cgroup.
* Cores in a cgroup are not available to run any other user processes.

### Backend CPU usage

Plan the number of physical cores dedicated to the WEKA software according to the following guidelines and limitations:

* Dedicate at least one physical core to the operating system; the rest can be allocated to the WEKA software.
  * Generally, it is recommended to allocate as many cores as possible to the WEKA system.
  * A backend server can have as many cores as possible. However, a container within a backend server can have a maximum of 19 physical cores.
  * Leave enough cores for the container serving the protocol if it runs on the same server.
* Allocate enough cores to support performance targets.
  * Generally, use 1 drive process per SSD for up to 6 SSDs and 1 drive process per 2 SSDs for more, with a ratio of 2 compute processes per drive process.
  * For finer tuning, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
* Allocate enough memory to match core allocation, as discussed above.
* Running other applications on the same server (converged WEKA system deployment) is supported. For details, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).

### Additional protocols CPU usage

The SMB, NFS, and S3 protocol services run in dedicated protocol containers alongside frontend containers and consume CPU resources.

Allocating additional CPU cores to protocol and frontend containers generally improves protocol performance. However, CPU scaling is effective only up to the network limit.

For detailed sizing guidelines and performance tuning recommendations tailored to your specific protocol workloads, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).

### Client CPU usage

The WEKA client software requires one physical CPU core by default. When running on systems with hyper-threading enabled, WEKA consumes two logical cores.

In UDP networking, the operating system pins WEKA processes to specific CPU cores. These processes maintain guaranteed access to their assigned cores, but the operating system can still schedule other processes to run on the same cores. This contrasts with exclusive CPU allocation, where WEKA reserves cores solely for its processes.

## Network planning

### Backend servers

WEKA backend servers support connections to both InfiniBand and Ethernet networks, using [compatible network interface cards](/planning-and-installation/prerequisites-and-compatibility#networking-ethernet) (NICs). When deploying backend servers, ensure that all servers in the WEKA system are connected using the same network technology for each type of network.

InfiniBand connections are prioritized over Ethernet links for data traffic. Both network types must be operational to ensure system availability, so consider adding redundant ports for each network type.

Clients can connect to the WEKA system over either InfiniBand or Ethernet.

A network port can be dedicated exclusively to the WEKA system or shared between the WEKA system and other applications.

### Clients

Clients can be configured with networking as described above to achieve the highest performance and lowest latency; however, this setup requires compatible hardware and dedicated CPU core resources. If compatible hardware is not available or a dedicated CPU core cannot be allocated to the WEKA system, client networking can instead be configured to use the kernel’s UDP service. This configuration results in reduced performance and increased latency.

## What to do next?

[Obtain the installation packages](/planning-and-installation/bare-metal/obtaining-the-weka-install-file) (both paths)

[^1]: For details, see [Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks)


# Obtain the installation packages

Register on get.weka.io and download the installation package for the selected installation path.

## Register to get.weka.io

Create a [get.weka.io](https://get.weka.io/ui/dashboard) account before you download installation files. If you already have an account, skip this section.

**Procedure**

1. Go to the [get.weka.io](https://get.weka.io/ui/dashboard) download site, and select **Create an account.**

<div data-with-frame="true"><img src="/files/UVVqLaIlYmxerU0YYtti" alt="Create an account" width="425"></div>

The Send Registration Email page opens.

2\. Fill in your organization's email address (private mail is prohibited).\
Select **I’m not a robot**, and then select **Send Registration Email.**

3\. Check your inbox for a registration email from Weka.io.\
To confirm your registration, select the link.\
The Create Your Account page opens.

4\. Fill in your email address, full name, and password. Then, select **Create Account**.

Your request for access to [get.weka.io](http://get.weka.io) is sent to WEKA for review. Wait for a validation email. Once your registration is approved, you can sign in to [get.weka.io](http://get.weka.io).

## Download the WEKA installation packages

Download the package that matches your installation path.

* Automated installation with WSA. Download the WSA image from [get.weka.io](https://get.weka.io/ui/dashboard).
* Manual installation and configuration. Download the WEKA software tarball from [get.weka.io](https://get.weka.io/ui/dashboard).

You can only sign in and download the packages if you are a registered user.

**Procedure: Download from get.weka.io**

1. Go to the [get.weka.io](https://get.weka.io/ui/dashboard) download site, and sign in with your registered account.

<div data-with-frame="true"><figure><img src="/files/fEbDgmN43BuoOreQcNcz" alt=""><figcaption><p>get.weka.io dashboard</p></figcaption></figure></div>

2. Download the required package:
   * Select the package from the dashboard.
   * Or, select the **Releases** tab. Select the required release, then follow the download instructions.

The download-link token is intentionally blurred in the image.

<div data-with-frame="true"><figure><img src="/files/QCRWsYmIAFfLwXQagRvk" alt=""><figcaption><p>Releases download page</p></figcaption></figure></div>

## What to do next?

Depending on the installation path you follow, go to one of the following:

Path A: [Install WSA](/planning-and-installation/bare-metal/install-the-weka-cluster-using-the-wsa)

Path B: [Install OS and WEKA software](/planning-and-installation/bare-metal/manually-install-os-and-weka-on-servers)


# Install WSA

Use the WSA to simplify and accelerate WEKA software installation on bare metal servers.

Install WEKA on bare metal servers with the WEKA Software Appliance.

WSA includes the operating system image, network drivers, WEKA software, and diagnostic tools. It accelerates server preparation and standardizes the deployment environment.

Follow this page if you are using the automated installation with WSA path.

<div data-with-frame="true"><figure><img src="/files/wRBDYaI607h2Xk0hmwgK" alt=""><figcaption><p>WEKA cluster installation using the WSA</p></figcaption></figure></div>

{% hint style="warning" %}
Do not install the WSA using PXE boot. Boot the WSA image from virtual media, DVD, or USB media.
{% endhint %}

{% hint style="info" %}
WEKA releases WSA updates addressing critical security issues found in the underlying Linux distribution within five days of discovery and availability. Customers can update their WSA instance from the repository where these updates are provided. WEKA notifies customers when updates are available, enabling timely updates to minimize potential risks. For any questions, contact the Customer Success Team.
{% endhint %}

## WSA deployment prerequisites

A physical server that meets the following requirements:

* **Boot drives:** Two identical boot drives as an installation target.
* **Minimum boot drive capacity:** 125 GB (to support the pre-defined disk partition map).
* **Boot type:** UEFI.

## Before you begin

Before deploying the WSA, do the following:

* Download the latest release of the WSA package from [get.weka.io](https://get.weka.io/ui/dashboard) dashboard.
* The root password is `WekaService`
* The WEKA user password is `weka.io123`
* If errors occur during installation and the installation halts (no error messages appear), use the system console to review the logs in `/tmp`. The primary log is `/tmp/ks-pre.log`.
* To get a command prompt from the Installation GUI, do one of the following:
  * On macOS, type **ctrl+option+f2**
  * On Windows, type **ctrl+alt+f2**.

## WSA deployment workflow

1. [Install the WSA](#1.-install-the-wsa)
2. [Configure the WSA](#2.-configure-the-wsa)
3. [Test the environment](#3.-test-the-environment)
4. [Validate the WEKA software installation](#4.-validate-the-weka-software-installation)

### 1. Install the WSA

1. Boot the server from the WSA image. The following are some options to do that:

{% tabs %}
{% tab title="Copy to a mountable location" %}
Copy the WSA image to an appropriate location so that the server’s BMC can mount it to a virtual CDROM/DVD.

Depending on the server manufacturer, consult the documentation for the server’s BMC (for example, iLO, iDRAC, and IPMI) for detailed instructions on mounting and booting from a bootable WSA image, such as:

* A workstation or laptop sent to the BMC through the web browser.
* An SMB share in a Windows server or a Samba server.
* An NFS share.
  {% endtab %}

{% tab title="Create DVD or USB media" %}
Burn the WSA image to a DVD or USB stick and boot the server from this physical media.
{% endtab %}
{% endtabs %}

Once you boot the server, the WSA installs the operating system, drivers, WEKA software, and other packages automatically.

Depending on server and media performance, installation can take 10 to 60 minutes per server.

### 2. Configure the WSA

Once the WSA installation completes and the server reboots, configure the server.

1. Log-in to the server using one of the following methods:

* BMC's Console
* Cockpit web interface on port 9090

Username/password: `root`/`WekaService`.

{% tabs %}
{% tab title="BMC’s Console" %}
Run the OS through the BMC’s Console. See the specific manufacturer’s BMC documentation.
{% endtab %}

{% tab title="Cockpit Web Interface" %}
Run the OS through the Cockpit Web Interface on port 9090 of the OS management network.

If you don’t know the WSA hostname or IP address, go to the console and press the **Return** key a couple of times until it prompts the URL of the WSA OS Web Console (Cockpit) on port 9090.
{% endtab %}
{% endtabs %}

When the server boots for the first time, the WSA installs the WEKA software automatically.

After the reboot, the server runs with WEKA in STEM mode.

2. Set the following networking details:
   * Hostname
   * IP addresses for network interfaces, including:
     * Server management interface (typically a 1Gb interface on a management network) if not automatically set via DHCP.
     * Dataplane network interfaces (typically 1 or 2. Can be several up to 8).
   * DNS settings and/or an `/etc/hosts` file.
   * Network gateways and routing table adjustments as necessary.
   * Timeserver configuration.

{% hint style="info" %}
For detailed instructions on setting the configuration options, see general Linux documentation for RedHat-based Linux Distributions.
{% endhint %}

### 3. Test the environment

Each server has the WEKA Tools pre-installed in `/opt/tools`, including:

* `wekanetperf`: Runs `iperf` between servers to validate line rate.
* `wekachecker`: Checks network settings and other readiness items. For details, see Validate the system preparation.
* `bios_tool`: Helps set the required BIOS settings on servers.

### 4. Validate the WEKA software installation

Verify that the WEKA software is installed and running on the server.

Log in to the server and run:

```bash
weka status
```

The server provides a status report indicating the system is in STEM mode, and is ready for the cluster configuration.

<div data-with-frame="true"><figure><img src="/files/oBYPqPUlCUVv4brHKoAl" alt=""><figcaption><p>Example: weka status with STEM mode</p></figcaption></figure></div>

## What to do next?

Go to [Configure the cluster with WEKA Configurator](/planning-and-installation/bare-metal/configure-the-weka-cluster-using-the-weka-configurator).


# Install OS and WEKA software

Install a supported operating system and the WEKA software on each bare metal server when using the manual installation path.

Install a supported operating system and the WEKA software manually on each bare metal server.

Follow this page if you are using the manual installation and configuration path.

{% hint style="info" %}
For optimal server performance and configuration, use `bios_tool` to set BIOS settings on your servers.

For details, see [Use bios\_tool](/appendices/bios-tool).
{% endhint %}

**Procedure**

1. Follow the relevant Linux documentation to install the operating system, including the required packages.

**Required packages**

<table><thead><tr><th>RHEL and derivatives</th><th>Ubuntu</th></tr></thead><tbody><tr><td><pre><code>elfutils-libelf-devel
gcc
glibc-headers
glibc-devel
make
perl
rpcbind
xfsprogs
kernel-devel
sssd
</code></pre></td><td><pre><code>libelf-dev
linux-headers-$(uname -r)
gcc
make
perl
rpcbind
xfsprogs
sssd
</code></pre></td></tr></tbody></table>

<details>

<summary>Recommended packages for remote support and maintenance</summary>

**RHEL and derivatives**

```
@network-tools
@large-systems
@hardware-monitoring
bind-utils
elfutils
ipmitool
kexec-tools
nvme-cli
python3
yum-utils
sysstat
telnet
nmap
git
sshpass
lldpd
fio
numactl
numactl-devel
libaio-devel
hwloc
tmux
pdsh
pdsh-rcmd-ssh
pdsh-mod-dshgroup
tmate
iperf
htop
nload
screen
ice
```

**Ubuntu**

```
elfutils
fio
git
hwloc
iperf
ipmitool
kexec-tools
jq
ldap-client
libaio-dev
lldpd
nfs-client
nload
nmap
numactl
nvme-cli
pdsh
python3
sshpass
sysstat
tmate
```

</details>

2. Install the WEKA software.
   * Once the WEKA software tarball is downloaded from [get.weka.io](https://get.weka.io), run the untar command.
   * Run the installation command on each server, following the instructions in the **Install** tab of [get.weka.io](https://get.weka.io/ui/dashboard).
   * (Optional) Enable safe shutdown:

     To ensure data integrity during server reboots or shutdowns, you can enable the safe shutdown feature during installation. This is highly recommended for converged servers.

     For instructions, see [Safe server shutdown](/planning-and-installation/bare-metal/manually-install-os-and-weka-on-servers/safe-server-shutdown).

Once completed, the WEKA software is installed on all the allocated servers and runs in stem mode (no cluster is attached).

{% hint style="info" %}
If a failure occurs during the WEKA software installation process, an error message prompts detailing the source of the failure. Review the details and try to resolve the failure. If required, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}

**Related topic**

[Operating system prerequisites](/planning-and-installation/prerequisites-and-compatibility#operating-system)

## What to do next?

Go to [Prepare the system](/planning-and-installation/bare-metal/setting-up-the-hosts).


# Safe server shutdown

Explore the systemd-based mechanism that allows a server to shut down safely. This feature is particularly valuable for converged servers that users might terminate abruptly.

## How safe shutdown works

The **weka-agent** service installs a systemd shutdown hook. When the operating system receives a reboot or power-off signal, the hook triggers the agent’s **requested-action** workflow. This workflow stops the cluster containers in the correct order to ensure data integrity.

The systemd process waits until every container exits cleanly. If a container cannot shut down safely, the overall shutdown process stalls.

## Enable safe shutdown

You can enable the safe shutdown feature either during the initial software installation or on an existing system.

**During installation**

Enable the safe shutdown feature by adding the `WEKA_SYSTEMD_GRACEFUL_SHUTDOWN=true` flag to the installation command.

Example:

{% code overflow="wrap" %}

```
curl https://<token>@get.weka.io/dist/v1/install/5.0.4/5.0.4. | WEKA_SYSTEMD_GRACEFUL_SHUTDOWN=true sh
```

{% endcode %}

**After installation**

If WEKA is already installed, you can enable the feature on each server.

**Procedure**

1. Edit the `/etc/wekaio/service.conf` file and change the `graceful_shutdown` parameter to `true`.

   ```
   [systemd]
   graceful_shutdown=true
   ```
2. Restart the agent to apply the setting.

   ```
   weka agent restart
   ```

To check the safe shutdown status, run the following:

```
$ weka local status
...
Graceful shutdown via systemd: enabled
...
```

## Cloud provider considerations

Some cloud vendors replace or override default systemd shutdown hooks with a hard-kill process after a fixed timeout.

If you require fully safe shutdowns, disable those hooks or extend the timeout. Ensure your operations teams are aware of this behavior. For example, Oracle Cloud Infrastructure (OCI) is a cloud provider that might override default shutdown hooks.

**Related topics**

[Expand specific resources of a container](/operation-guide/expanding-and-shrinking-cluster-resources/expansion-of-specific-resources#graceful-container-management-ensuring-safe-actions) (requested-action workflow)

[Background tasks](/operation-guide/background-tasks)

[Upgrade WEKA versions](/operation-guide/upgrading-weka-versions)


# Prepare the system

Set the networking and other tasks before configuring the WEKA cluster.

Once the hardware and software prerequisites are met, prepare the backend servers and clients for the WEKA system configuration.

This preparation consists of the following steps:

1. Install NIC drivers
2. Enable SR-IOV (when required)
3. Set up ConnectX cards
4. Set custom kernel parameters
5. Configure the networking
6. Configure the HA networking
7. Verify the network configuration
8. Configure the clock synchronization
9. Enable kdump
10. Disable swap (if any)
11. Validate the system preparation

{% hint style="info" %}
Some of the examples contain version-specific information. The software is updated frequently, so the package versions available to you may differ from those presented here.
{% endhint %}

**Related topics**

[Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility)

## 1. Install NIC drivers <a href="#install-nic-drivers" id="install-nic-drivers"></a>

For Mellanox OFED setup, see NVIDIA Documentation.

## 2. Enable SR-IOV <a href="#enable-sr-iov" id="enable-sr-iov"></a>

SR-IOV only needs to be enabled if any of the following statements are true:

* If WEKA is running on a VM
* If WEKA data plane is running on Broadcom highspeed NICs

**Related topic**

[Enable the SR-IOV](/planning-and-installation/bare-metal/setting-up-the-hosts/sr-iov-enablement)

## 3. Set up ConnectX cards <a href="#set-up-connectx-cards" id="set-up-connectx-cards"></a>

1. **Configure firmware parameters:** All ConnectX ports used directly with WEKA servers and clients require specific firmware settings for optimal performance. Set the following non-default parameters:

   * `ADVANCED_PCI_SETTINGS=1`
   * `PCI_WR_ORDERING=1`

   Use the following command to apply these settings to all MLX devices:

   <pre data-overflow="wrap"><code>mst start &#x26;&#x26; for MLXDEV in /dev/mst/* ; do mlxconfig -d ${MLXDEV} -y set ADVANCED_PCI_SETTINGS=1 PCI_WR_ORDERING=1; done
   </code></pre>
2. **Set link type:** Certain ConnectX VPI cards require modification of the link type, to specifically set the port to use InfiniBand or Ethernet networking.\
   \
   If applicable, set the port mode with the following command, where 1=InfiniBand and 2=Ethernet:\
   `mlxconfig -y -d /dev/mst/<dev> set LINK_TYPE_P<1,2>=<1,2>`\
   \
   For example, the following command sets port 2 to InfiniBand: `mlxconfig -y -d /dev/mst/<dev> set LINK_TYPE_P2=1`<br>
3. **Reboot the system:** A reboot is required after applying the firmware settings to ensure the changes take effect.

**Related information**

For additional details, refer to the NVIDIA ConnectX documentation.

## 4. Set custom kernel parameters <a href="#set-custom-kernel-parameters" id="set-custom-kernel-parameters"></a>

To ensure optimal performance and stability, configure the Linux kernel with custom parameters that:

* Disable NUMA balancing to reduce latency (mandatory).
* Enable automatic reboots after kernel panic to minimize downtime.
* Optimize ARP behavior for improved network performance.

The recommended approach is to consolidate all custom kernel parameters into a single configuration file: `/etc/sysctl.d/99-weka.conf`. This ensures the settings persist across reboots, simplifies administration, and avoids conflicts with package updates.

#### Procedure

1. **Create the configuration file:** Open a new file under `/etc/sysctl.d/` to store all custom kernel parameters:

   ```bash
   sudo vi /etc/sysctl.d/99-weka.conf
   ```
2. **Add kernel parameter settings:** Insert the following lines into the file. Comments are included for clarity:

   <pre data-title="/etc/sysctl.d/99-weka.conf"><code># --- Disable NUMA balancing (Mandatory) ---
   kernel.numa_balancing = 0

   # --- Configure automatic reboot on kernel panic ---
   kernel.panic = 300

   # --- Minimal configuration per specific IB/Eth interface ---
   # Replace ib0 and ib1 with your specific interface names
   net.ipv4.conf.ib0.arp_announce = 2
   net.ipv4.conf.ib1.arp_announce = 2
   net.ipv4.conf.ib0.arp_filter = 1
   net.ipv4.conf.ib1.arp_filter = 1
   net.ipv4.conf.ib0.arp_ignore = 1
   net.ipv4.conf.ib1.arp_ignore = 1

   # --- Alternative network ARP settings for all interfaces ---
   net.ipv4.conf.all.arp_filter = 1
   net.ipv4.conf.default.arp_filter = 1
   net.ipv4.conf.all.arp_announce = 2
   net.ipv4.conf.default.arp_announce = 2
   net.ipv4.conf.all.arp_ignore = 1
   net.ipv4.conf.default.arp_ignore = 1
   net.ipv4.conf.all.ignore_routes_with_linkdown = 1
   </code></pre>
3. **Save the file and exit the editor.**
4. **Apply the new settings:** Reload all kernel parameters from configuration files without rebooting:

   ```bash
   sudo sysctl --system
   ```
5. **Verify configuration changes:**
   1. Verify NUMA balancing:

      ```bash
      sysctl kernel.numa_balancing
      ```

      Expected output:

      ```bash
      kernel.numa_balancing = 0
      ```
   2. Verify kernel panic timer:

      ```bash
      sysctl kernel.panic
      ```

      Expected output:

      ```bash
      kernel.panic = 300
      ```

## 5. Configure the networking <a href="#configure-the-networking" id="configure-the-networking"></a>

### Ethernet configuration

The following example of the `ifcfg` script is a reference for configuring the Ethernet interface.

{% code title="/etc/sysconfig/network-scripts/ifcfg-enp24s0" %}

```
TYPE="Ethernet"
PROXY_METHOD="none"
BROWSER_ONLY="no"
BOOTPROTO="none"
DEFROUTE="no"
IPV4_FAILURE_FATAL="no"
IPV6INIT="no"
IPV6_AUTOCONF="no"
IPV6_DEFROUTE="no"
IPV6_FAILURE_FATAL="no"
IPV6_ADDR_GEN_MODE="stable-privacy"
NAME="enp24s0"
DEVICE="enp24s0"
ONBOOT="yes"
NM_CONTROLLED=no
IPADDR=192.168.1.1
NETMASK=255.255.0.0
MTU=9000
```

{% endcode %}

MTU 9000 (jumbo frame) is recommended for the best performance. Refer to your switch vendor documentation for jumbo frame configuration.

Bring the interface up using the following command:

```
# ifup enp24s0
```

### InfiniBand configuration

{% tabs %}
{% tab title="Default partition" %}
InfiniBand network configuration normally includes Subnet Manager (SM), but the procedure involved is beyond the scope of this document. However, it is important to be aware of the specifics of your SM configuration, such as partitioning and MTU, because they can affect the configuration of the endpoint ports in Linux. For best performance, MTU of 4092 is recommended.

Refer to the following `ifcfg` script when the IB network only has the default partition, i.e., "no `pkey`":

{% code title="/etc/sysconfig/network-scripts/ifcfg-ib1" %}

```
TYPE=Infiniband
ONBOOT=yes
BOOTPROTO=static
STARTMODE=auto
USERCTL=no
NM_CONTROLLED=no
DEVICE=ib1
IPADDR=192.168.1.1
NETMASK=255.255.0.0
MTU=4092
```

{% endcode %}

Bring the interface up using the following command:

```
# ifup ib1
```

Verify that the “default partition” connection is up, with all the attributes set:

```
# ip a s ib1
4: ib1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 4092 qdisc mq state UP group default qlen 256
  link/infiniband 00:00:03:72:fe:80:00:00:00:00:00:00:24:8a:07:03:00:a8:09:48
brd 00:ff:ff:ff:ff:12:40:1b:ff:ff:00:00:00:00:00:00:ff:ff:ff:ff
    inet 10.0.20.84/24 brd 10.0.20.255 scope global noprefixroute ib0
       valid_lft forever preferred_lft forever
```

{% endtab %}

{% tab title="Non-default partition (PKEY)" %}
On an InfiniBand network with a non-default partition number, `p-key` must be configured on the interface if the InfiniBand ports on your network are members of an InfiniBand partition other than the default (`0x7FFF`). The p-key should associate the port as a full member of the partition (full members are those where the p-key number with the most-significant bit (MSB) of the 16-bits is set to 1).

{% hint style="success" %}
**Example:** If the partition number is `0x2`, the limited member p-key will equal the p-key itself, i.e.,`0x2`. The full member p-key will be calculated as the logical OR of `0x8000` and the p-key (`0x2`) and therefore will be equal to `0x8002`.
{% endhint %}

{% hint style="info" %}
**Note:** All InfiniBand ports communicating with the Weka cluster must be full members.
{% endhint %}

For each `pkey-ed IPoIB` interface, it's necessary to create two `ifcfg` scripts. To configure your own `pkey-ed IPoIB` interface, refer to the following examples, where a `pkey` of `0x8002` is used. You may need to manually create the child device.

{% code title="/etc/sysconfig/network-scripts/ifcfg-ib1" %}

```
TYPE=Infiniband
ONBOOT=yes
MTU=4092
BOOTPROTO=static
STARTMODE=auto
USERCTL=no
NM_CONTROLLED=no
DEVICE=ib1
```

{% endcode %}

{% code title="/etc/sysconfig/network-scripts/ifcfg-ib1.8002" %}

```
TYPE=Infiniband
BOOTPROTO=none
CONNECTED_MODE=yes
DEVICE=ib1.8002
IPV4_FAILURE_FATAL=yes
IPV6INIT=no
MTU=4092
NAME=ib1.8002
NM_CONTROLLED=no
ONBOOT=yes
PHYSDEV=ib1
PKEY_ID=2
PKEY=yes
BROADCAST=192.168.255.255
NETMASK=255.255.0.0
IPADDR=192.168.1.1
```

{% endcode %}

Bring the interface up using the following command:

```
# ifup ib1.8002
```

Verify the connection is up with all the non-default partition attributes set:

```
# ip a s ib1.8002
5: ib1.8002@ib0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 4092 qdisc mq state UP qlen 256
    link/infiniband 00:00:11:03:fe:80:00:00:00:00:00:00:24:8a:07:03:00:a8:09:48 brd 00:ff:ff:ff:ff:12:40:1b:80:02:00:00:00:00:00:00:ff:ff:ff:ff
    inet 192.168.1.1/16 brd 192.168.255.255 scope global noprefixroute ib1.8002
       valid_lft forever preferred_lft forever
```

{% endtab %}
{% endtabs %}

### Define the NICs with `ignore-carrier`

`ignore-carrier` is a NetworkManager configuration option. When set, it keeps the network interface up even if the physical link is down. It’s useful when services need to bind to the interface address at boot.

{% hint style="info" %}
The following is an example of configuring `ignore-carrier` on systems that use NetworkManager on Rocky Linux 8. The exact steps may vary depending on your operating system and its specific network configuration tools. Always refer to your system’s official documentation for accurate information.
{% endhint %}

1. Open the `/etc/NetworkManager/NetworkManager.conf` file to edit it.
2. Under the `[main]` section, add one of the following lines depending on the operating system:
   * For some versions of Rocky Linux, RHEL, and CentOS: `ignore-carrier=*`
   * For some other versions: `ignore-carrier=<device-name1>,<device-name2>`.\
     Replace `<device-name1>,<device-name2>` with the actual device names you want to apply this setting to.

Example for RockyLinux and RHEL 8.7:

{% code title="/etc/NetworkManager/NetworkManager.conf" %}

```
[main]
ignore-carrier=*
```

{% endcode %}

Example for some other versions:

```
[main]
ignore-carrier=ib0,ib1
```

3. Restart the NetworkManager service for the changes to take effect.

### RoCE configuration

Configure RoCE (RDMA over Converged Ethernet) when the data plane runs over Ethernet and RDMA traffic must be carried losslessly across it. Skip this section for InfiniBand fabrics.

{% hint style="info" %}
Follow NVIDIA's RoCE configuration procedure for your switch operating system and NIC. Apply the WEKA-required values below wherever the NVIDIA procedure asks for a traffic class, DSCP value, or priority.

NVIDIA owns and maintains this procedure, and updates it as switch operating system versions change. The links below may move or be replaced over time. If a link is broken or outdated, search NVIDIA's documentation site for the current RoCE configuration procedure matching your switch operating system version.
{% endhint %}

**Before you begin**

Confirm the switch operating system (NVIDIA Onyx or Cumulus Linux) and check NVIDIA's documentation for the procedure matching your switch software version:

* [RDMA Over Converged Ethernet (RoCE), NVIDIA Onyx documentation](https://networking-docs.nvidia.com/onyxum/3104606lts/rdma-over-converged-ethernet-roce)
* [RDMA over Converged Ethernet (RoCE), NVIDIA Cumulus Linux documentation](https://docs.nvidia.com/networking-ethernet-software/cumulus-linux-59/Layer-1-and-Switch-Ports/Quality-of-Service/RDMA-over-Converged-Ethernet-RoCE/)
* [Lossless RoCE configuration for Onyx switches in DSCP-based QoS mode, NVIDIA Enterprise Support](https://enterprise-support.nvidia.com/s/article/lossless-roce-configuration-for-mlnx-os-switches-in-dscp-based-qos-mode--advanced-mode-x)

**Required parameters for WEKA**

<table><thead><tr><th width="216.5859375">Parameter</th><th width="165.8515625">Value</th><th>Notes</th></tr></thead><tbody><tr><td>Marking method</td><td>Layer 3 (DSCP)</td><td>Required when WEKA traffic is routed across subnets. Layer 2 (TOS) marking works only when all servers share a subnet, but WEKA doesn't recommend it.</td></tr><tr><td>DSCP value</td><td>24</td><td>Register value 96 (DSCP x 4) on the NIC.</td></tr><tr><td>Traffic class, data</td><td>3</td><td>Maps to switch priority 3.</td></tr><tr><td>Traffic class, congestion notification (CNP)</td><td>6</td><td>Maps to switch priority 6.</td></tr><tr><td>PFC priority</td><td>3</td><td>Enable Priority Flow Control on this priority so RoCE traffic isn't dropped.</td></tr><tr><td>Congestion control</td><td>ECN</td><td>Enable alongside PFC.</td></tr></tbody></table>

Configure the switch first, using the `roce` macro (Onyx) or `nv set qos roce` (Cumulus Linux) from the NVIDIA procedure, then configure each server's NIC with `mlnx_qos` and `cma_roce_tos` using the values above.

After configuration, verify the network as described in step 7.

## 6. Configure dual-network links with policy-based routing <a href="#configure-dual-network-links-with-policy-based-routing" id="configure-dual-network-links-with-policy-based-routing"></a>

The following steps provide guidance for configuring dual-network links with policy-based routing on Linux systems. Adjust IP addresses and interface names according to your environment.

### **RHEL/Rocky/CentOS routing configuration using the network scripts**

{% hint style="info" %}
Network scripts are deprecated in RHEL/Rocky 8. For RHEL/Rocky 8 and onwards, use the Network Manager.
{% endhint %}

1. Navigate to `/etc/sysconfig/network-scripts/`.
2. Create the file `/etc/sysconfig/network-scripts/route-mlnx0` with the following content:

   ```bash
   10.90.0.0/16 dev mlnx0 src 10.90.0.1 table weka1
   default via 10.90.2.1 dev mlnx0 table weka1
   ```
3. Create the file `/etc/sysconfig/network-scripts/route-mlnx1` with the following content:

   ```bash
   10.90.0.0/16 dev mlnx1 src 10.90.1.1 table weka2
   default via 10.90.2.1 dev mlnx1 table weka2
   ```
4. Create the files `/etc/sysconfig/network-scripts/rule-mlnx0` and `/etc/sysconfig/network-scripts/rule-mlnx1` with the following content:

   ```bash
   table weka1 from 10.90.0.1
   table weka2 from 10.90.1.1
   ```
5. Open `/etc/iproute2/rt_tables` and add the following lines:

   ```bash
   100 weka1
   101 weka2
   ```
6. Save the changes.

### RHEL/Rocky 8+ routing configuration using the Network Manager

You can configure routing for your Ethernet or InfiniBand connections using Network Manager command-line interface (`nmcli`) commands.

**Configure ethernet routing**

To set up routing for Ethernet connections, use the following `nmcli` commands. In these commands, the first IP address of the route (`10.10.10.0/24`) represents the subnet of the network to which the NIC connects. The last address in the routing rule (`10.10.10.1` for `eth1`) is the IP address of the NIC you are configuring.

{% code overflow="wrap" %}

```bash
nmcli connection modify eth1 ipv4.routes "10.10.10.0/24 src=10.10.10.1 table=100" ipv4.routing-rules "priority 101 from 10.10.10.1 table 100"
nmcli connection modify eth2 ipv4.routes "10.10.10.0/24 src=10.10.10.101 table=200" ipv4.routing-rules "priority 102 from 10.10.10.101 table 200"
```

{% endcode %}

**Configure InfiniBand routing**

To set up routing for InfiniBand connections, use the following `nmcli` commands. The route's first IP address (`10.10.10.0/24`) signifies the network's subnet for the NIC. The last address in the routing rules (`10.10.10.1` for `ib0`) is the IP address of the NIC you are configuring.

{% code overflow="wrap" %}

```bash
nmcli connection modify ib0 ipv4.route-metric 100
nmcli connection modify ib1 ipv4.route-metric 101

nmcli connection modify ib0 ipv4.routes "10.10.10.0/24 src=10.10.10.1 table=100" 
nmcli connection modify ib0 ipv4.routing-rules "priority 101 from 10.10.10.1 table 100"
nmcli connection modify ib1 ipv4.routes "10.10.10.0/24 src=10.10.10.101 table=200" 
nmcli connection modify ib1 ipv4.routing-rules "priority 102 from 10.10.10.101 table 200"
```

{% endcode %}

**View network configuration**

Run the `nmcli` commands to view the current network configuration, including interfaces, IP addresses, routes, and DNS settings.

<table><thead><tr><th width="290.3636474609375">Goal</th><th>Command</th></tr></thead><tbody><tr><td>Full details (IP, DNS, routes)</td><td><code>nmcli device show</code></td></tr><tr><td>Brief status</td><td><code>nmcli device status</code></td></tr><tr><td>Active connections</td><td><code>nmcli connection show --active</code></td></tr><tr><td>Specific device</td><td><code>nmcli device show eth0</code></td></tr></tbody></table>

**Example**

```bash
eno12409: connected to eno12409
        "Mellanox MT2894"
        ethernet (mlx5_core), 50:00:E6:42:FC:27, hw, mtu 9000
        ip4 default
        inet4 10.10.35.140/25
        route4 10.10.35.128/25 metric 101
        route4 default via 10.10.35.129 metric 101
        inet6 fe80::207c:c202:d22f:d26b/64
        route6 fe80::/64 metric 1024

ens1: connected to ens1
        "Mellanox MT2910"
        ethernet (mlx5_core), 9C:63:C0:EB:7C:02, hw, mtu 9000
        inet4 10.10.50.1/24
        route4 10.10.50.0/24 metric 0
        route4 10.10.30.0/24 metric 0
        route4 10.10.37.0/25 via 10.10.50.1 metric 0
        inet6 fe80::f0d6:8ea:5be4:f4ed/64
        route6 fe80::/64 metric 1024

DNS configuration:
        servers: 10.219.59.120 10.211.188.61 10.211.188.73
        domains: example.net
        interface: eno12409
```

### **Ubuntu Netplan configuration**

Configure source-based routing for each data plane interface. This preserves the management default route in the main routing table.

Identify the data plane gateway and every remote network reachable from the data plane. Replace the example addresses, interface names, and additional network CIDRs.

1. Create or edit `/etc/netplan/10-weka.yaml`:

   <pre class="language-yaml" data-title="/etc/netplan/10-weka.yaml"><code class="lang-yaml"># Host: weka-node-01
   # Apply:  sudo netplan apply

   network:
     version: 2
     renderer: networkd
     ethernets:
       enp2s0:
         dhcp4: yes
         dhcp6: no
         nameservers:
           addresses: [8.8.8.8, 8.8.4.4]
         # Default route via DHCP — no SBR policy needed on management interface

       ib1:
         dhcp4: no
         dhcp6: no
         optional: true
         ignore-carrier: true  # configure even without physical link (IB/RDMA NICs may be slow to init)
         addresses:
           - 10.222.0.10/24
         routes:
           # Main table entries
           - to: 10.222.0.0/24
             scope: link
           # ── Additional subnets reachable via ib1 (main table) ──────────────
           # Add any other CIDRs that hosts/clients on this fabric need to reach.
           # Without a main-table entry, locally-originated traffic (e.g. weka
           # backend&#x3C;->backend, S3, SMB, NFS) may egress the wrong interface.
           # - to: &#x3C;ADDITIONAL_SUBNET>
           #   via: 10.222.0.1
           # Source-based routing table 101
           - to: 0.0.0.0/0
             via: 10.222.0.1
             table: 101
           - to: 10.222.0.0/24
             scope: link
             table: 101
         routing-policy:
           - from: 10.222.0.10/32
             table: 101
             priority: 1010

       ib2:
         dhcp4: no
         dhcp6: no
         optional: true
         ignore-carrier: true  # configure even without physical link (IB/RDMA NICs may be slow to init)
         addresses:
           - 10.222.0.20/24
         routes:
           # Main table entries
           - to: 10.222.0.0/24
             scope: link
           # ── Additional subnets reachable via ib2 (main table) ──────────────
           # Add any other CIDRs that hosts/clients on this fabric need to reach.
           # Without a main-table entry, locally-originated traffic (e.g. weka
           # backend&#x3C;->backend, S3, SMB, NFS) may egress the wrong interface.
           # - to: &#x3C;ADDITIONAL_SUBNET>
           #   via: 10.222.0.1
           # Source-based routing table 102
           - to: 0.0.0.0/0
             via: 10.222.0.1
             table: 102
           - to: 10.222.0.0/24
             scope: link
             table: 102
         routing-policy:
           - from: 10.222.0.20/32
             table: 102
             priority: 1020
   </code></pre>
2. Apply the configuration:

   ```bash
   sudo netplan apply
   ```

The source-based routing tables select the correct interface for traffic from each data plane IP. The main-table routes reach data plane networks when the data plane is not the default network.

### **SLES/SUSE configuration**

1. Create `/etc/sysconfig/network/ifrule-eth2` with:

   ```bash
   ipv4 from 192.168.11.21 table 100
   ```
2. Create `/etc/sysconfig/network/ifrule-eth4` with:

   ```bash
   ipv4 from 192.168.11.31 table 101
   ```
3. Create `/etc/sysconfig/network/scripts/ifup-route.eth2` with:

   ```bash
   ip route add 192.168.11.0/24 dev eth2 src 192.168.11.21 table weka1
   ```
4. Create `/etc/sysconfig/network/scripts/ifup-route.eth4` with:

   ```bash
   ip route add 192.168.11.0/24 dev eth4 src 192.168.11.31 table weka2
   ```
5. Add the weka lines to `/etc/iproute2/rt_tables`:

   ```bash
   100 weka1
   101 weka2
   ```
6. Restart the interfaces or reboot the machine:

   ```bash
   ifdown eth2; ifdown eth4; ifup eth2; ifup eth4
   ```

**Related topic**

[Networking](/weka-system-overview/networking-in-wekaio#high-availability-ha)

## 7. Verify the network configuration <a href="#verify-the-network-configuration" id="verify-the-network-configuration"></a>

Use a large-size ICMP ping to check the basic TCP/IP connectivity between the interfaces of the servers:

```
# ping -M do -s 8972 -c 3 192.168.1.2
PING 192.168.1.2 (192.168.1.2) 8972(9000) bytes of data.
8980 bytes from 192.168.1.2: icmp_seq=1 ttl=64 time=0.063 ms
8980 bytes from 192.168.1.2: icmp_seq=2 ttl=64 time=0.087 ms
8980 bytes from 192.168.1.2: icmp_seq=3 ttl=64 time=0.075 ms

--- 192.168.2.0 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 1999ms
rtt min/avg/max/mdev = 0.063/0.075/0.087/0.009 ms
```

The`-M do` flag prohibits packet fragmentation, which allows verification of correct MTU configuration between the two endpoints.

`-s 8972` is the maximum ICMP packet size that can be transferred with MTU 9000, due to the overhead of ICMP and IP protocols.

{% hint style="info" %}
All WEKA server interfaces within the same subnet must have connectivity and be able to ping each other.
{% endhint %}

## 8. Configure the clock synchronization <a href="#configure-the-clock-synchronization" id="configure-the-clock-synchronization"></a>

The synchronization of time on computers and networks is considered good practice and is vitally important for the stability of the WEKA system. Proper timestamp alignment in packets and logs is very helpful for the efficient and quick resolution of issues.

Configure the clock synchronization software on the backends and clients according to the specific vendor instructions (see your OS documentation), before installing the WEKA software.

## **9. (Optional) Enable kdump** <a href="#enable-kdump" id="enable-kdump"></a>

Enabling kdump ensures crash diagnostic data is captured (`/var/crash`).

1. Install kdump tools (if not exist): `sudo yum install kexec-tools crash`.
2. Enable the kdump service: `sudo systemctl enable kdump.service`.
3. Open the file located at: `/etc/kdump.conf`.
4. Set the crash dump path and size. Example:

```plaintext
path /var/crash
core_collector makedumpfile -c --message-level 1 -d 31
```

## 10. Disable swap

WEKA highly recommends that any servers used as backends have no swap configured. This is distribution-dependent but is often a case of commenting out any `swap` entries in `/etc/fstab` and rebooting.

## 11. Validate the system preparation

The `wekachecker` is a tool that validates the readiness of the servers in the cluster before installing the WEKA software.

The `wekachecker` performs the following validations:

* Dataplane IP, jumbo frames, and routing
* ssh connection to all servers
* Timesync
* OS release
* Sufficient capacity in /opt/weka
* Available RAM
* Internet connection availability
* NTP
* DNS configuration
* Firewall rules
* WEKA required packages
* OFED required packages
* Recommended packages
* HT/AMT is disabled
* The kernel is supported
* CPU has a supported AES, and it is enabled
* Numa balancing is disabled
* RAM state
* XFS FS type installed
* Mellanox OFED is installed
* IOMMU setting in all servers is consistent, either all enabled or all disabled.
* rpcbind utility is enabled
* SquashFS is enabled
* noexec mount option on /tmp

{% hint style="info" %}
The `wekachecker`tool applies to all WEKA versions. From V4.0, the following validations are not relevant, although the tool displays them:

* OS has SELinux disabled or in permissive mode.
* Network Manager is disabled.
  {% endhint %}

**Procedure**

1. Clone the the **tools** repository:\
   `git clone --depth 1` [`https://github.com/weka/tools.git`](https://github.com/weka/tools.git)
2. Change directory to **tools/install**.
3. From the **install** directory, run `./wekachecker <hostnames/IPs>`\
   Where:\
   The `hostnames/IPs` is a space-separated list of all the cluster hostnames or IP addresses connected to the **high-speed networking**.\
   Example:\
   `./wekachecker 10.1.1.11 10.1.1.12 10.1.1.4 10.1.1.5 10.1.1.6 10.1.1.7 10.1.1.8`
4. Review the output. If failures or warnings are reported, investigate them and correct them as necessary. Repeat the validation until no important issues are reported.\
   The `wekachecker` writes any failures or warnings to the file: **`test_results.txt`**.

Once the report has no failures or warnings that must be fixed, you can install the WEKA software.

<details>

<summary><strong>wekachecker report example</strong></summary>

```
Dataplane IP Jumbo Frames/Routing test                       [PASS]
Check ssh to all hosts                                       [PASS]
Verify timesync                                              [PASS]
Check if OS has SELinux disabled or in permissive mode       [PASS]
Check OS Release...                                          [PASS]
Check /opt/weka for sufficient capacity...                   [WARN]
Check available RAM...                                       [PASS]
Check if internet connection available...                    [PASS]
Check for NTP...                                             [PASS]
Check DNS configuration...                                   [PASS]
Check Firewall rules...                                      [PASS]
Check for WEKA Required Packages...                          [PASS]
Check for OFED Required Packages...                          [PASS]
Check for Recommended Packages...                            [WARN]
Check if HT/AMT is disabled                                  [WARN]
Check if kernel is supported...                              [PASS]
Check if CPU has AES enabled and supported                   [PASS]
Check if Network Manager is disabled                         [WARN]
Checking if Numa balancing is disabled                       [WARN]
Checking RAM state for errors                                [PASS]
Check for XFS FS type installed                              [PASS]
Check if Mellanox OFED is installed                          [PASS]
Check for consistent IOMMU                                   [PASS]
Check for rpcbind enabled                                    [PASS]
Check for squashfs enabled                                   [PASS]
Check for /tmp noexec mount                                  [PASS]

RESULTS: 21 Tests Passed, 0 Failed, 5 Warnings
```

</details>

## What to do next?

If you can use the WEKA Configurator, go to:

[Configure the cluster with WEKA Configurator](/planning-and-installation/bare-metal/configure-the-weka-cluster-using-the-weka-configurator)

Otherwise, go to:

[Configure the cluster with Resources Generator](/planning-and-installation/bare-metal/manually-configure-the-weka-cluster-using-the-resource-generator)


# Broadcom adapter setup for WEKA clients

To enable a WEKA client to use Broadcom adapters, ensure the server has the appropriate drivers and firmware downloaded from Broadcom's website.

## Broadcom NIC deployment guidelines and prerequisites

* **Deployment:** Only supported for **WEKA clients**.
* **Core limits:** Official support for configurations with a maximum of 40 cores.
* **Virtualization:** Not supported for guest VMs on KVM or VMware.
* **SR-IOV:** Ensure SR-IOV is enabled in both the BIOS and NIC settings. See [Enable the SR-IOV](/planning-and-installation/bare-metal/setting-up-the-hosts/sr-iov-enablement).

## **Set up the drivers and software**

**Procedure:**

1. **Download software bundle**: Access Broadcom's download center and download the software bundle onto the target server. Carefully review the instructions included in the bundle.
2. **Installation instructions:** Follow these steps to compile and install the required components:

   1. **bnxt\_en driver**:
      * Download the `bnxt_en` driver from the [Broadcom support portal](https://www.broadcom.com/support).
        * Follow the provided instructions to compile and install it.
        * Ensure you are using this version instead of the default driver from your Linux distribution.
   2. **SliFF driver**:
      * Compile and install according to the provided instructions.
   3. **NICCLI command line utility**:
      * Follow the specific instructions to compile and set up this utility.
   4. **Non-inbox driver**:
      * Ensure this driver is compiled and installed as per the given guidelines.

   Make sure each component is appropriately configured after installation for optimal functionality.
3. **Post-installation steps**: After installation, run one of the following commands based on the Linux distribution:
   * `dracut -f`
   * `update-initramfs -u`
4. **Reboot the server**: Reboot the server to apply the changes.

## **Install the firmware**

After installing Broadcom drivers and software, install the firmware included in the download bundle. Firmware files are typically named after the adapter they are intended for, such as `BCM957508-P2100G.pkg`.

**Procedure:**

1. **Identify the target adapter**: Use the command `niccli --list` to list Broadcom adapters and identify the target adapter by its decimal device number:

```shell
# niccli --list
----------------------------------------------------------------------------
Scrutiny NIC CLI v227.0.130.0 - Broadcom Inc. (c) 2023 (Bld-61.52.25.90.16.0) 
----------------------------------------------------------------------------
     BoardId     MAC Address        FwVersion    PCIAddr      Type   Mode
  1) BCM57508    84:16:0A:3E:0E:20  224.1.102.0  00:0d:00:00  NIC    PCI
  2) BCM57508    84:16:0A:3E:0E:21  224.1.102.0  00:0d:00:01  NIC    PCI
```

2. **Identify the device**: From the `niccli --list` output, choose the device identifier (for example, `1` for `BCM57508`).

```
# niccli --dev 1 install BCM957508-P2100G.pkg
```

3. **Confirm and complete the installation**: Follow the prompts to confirm and complete the firmware update.

{% code overflow="wrap" %}

```shell
Broadcom NetXtreme-C/E/S firmware update and configuration utility version v227.0.120.0
NetXtreme-E Controller #1 at PCI Domain:0000 Bus:3b Dev:00 Firmware on NVM - v224.1.102.0
NetXtreme-E Controller #1 will be updated to firmware version v227.1.111.0

Do you want to continue (Y/N)?y

NetXtreme-C/E/S Controller #1 is being updated....................................................
Firmware update is completed.
A system reboot is needed for the firmware update to take effect.
```

{% endcode %}

4. **Reboot the server**: Reboot the server to apply the firmware update.

## **Update NVM settings**

To enable WEKA system compatibility, configure certain NVM options to increase the number of Virtual Functions (VFs) and enable TruFlow.

**Procedure:**

1. **Increase the number of VFs to 64**: Run the following commands:

   ```shell
   niccli --dev 1 nvm --setoption enable_sriov --value 1
   niccli --dev 1 nvm --setoption number_of_vfs_per_pf --scope 0 --value 0x40
   niccli --dev 1 nvm --setoption number_of_vfs_per_pf --scope 1 --value 0x40
   ```
2. **Enable TruFlow**: Run the following commands:

   ```shell
   niccli --dev 1 nvm --setoption enable_truflow --scope 0 --value 1
   niccli --dev 1 nvm --setoption enable_truflow --scope 1 --value 1
   ```
3. **Additional configuration for BCM57508-P2100G**: Run the following command:

   ```shell
   niccli --dev 1 nvm --setoption afm_rm_resc_strategy --value 1
   ```
4. **Reboot the server**: Reboot the server to apply the changes.

The adapter is ready for use by the WEKA system.

## Configure Broadcom P2100G adapters for 200 Gbps operation

Convert a dual-port 100 Gbps Broadcom P2100G adapter into a single-port 200 Gbps configuration by consolidating both ports. This mode is optimal for high-throughput applications requiring maximum bandwidth on a single interface.

**Procedure**

1. **Determine NIC index:** Run the following command to list all installed NICs and determine the correct index (`<index>`) of the target P2100G adapter:

   ```
   niccli list
   ```
2. **Set link speed and port:** Use the Linux `niccli` tools to set the default link speed to 200G for both the driver (when the OS is running) and the firmware (PXE boot), and hide the second network port with the following commands:

   ```
   niccli -i <index> nvm --setoption firmware_link_speed_d0 --scope 0 --value 0x07
   niccli -i <index> nvm --setoption port_operation_mode --value 
   ```


# Enable the SR-IOV

Many hardware vendors ship their products with the SR-IOV feature disabled. The feature must be enabled on such platforms before installing the Weka system. Enabling the SR-IOV applies to the server BIOS.

If the SR-IOV is already enabled, it is recommended to verify the current state before proceeding with the installation of the WEKA system.

## Before you begin

Verify that the NIC drivers are installed and loaded successfully. If it still needs to be done, perform the [Install NIC drivers](/planning-and-installation/bare-metal/setting-up-the-hosts#install-nic-drivers) procedure.

## Enable SR-IOV in the server BIOS

The following procedure is a vendor-specific example and is provided as a courtesy. Depending on the vendor, the same settings may appear differently or be located elsewhere. Therefore, refer to your hardware platform and NIC vendor documentation for the latest information and updates.

{% tabs %}
{% tab title="1. Reboot server" %}
Reboot the server and enter the BIOS Setup.

<div data-with-frame="true"><figure><img src="/files/d3Oby3GtHFgNyhboaH0u" alt=""><figcaption><p>Main screen</p></figcaption></figure></div>
{% endtab %}

{% tab title="2. Select PCIe Configuration" %}
From the Advanced menu, select the PCIe Configuration to display its properties.

<div data-with-frame="true"><figure><img src="/files/QVNBNNtl20u0R3gZLIOB" alt=""><figcaption><p>Advanced screen</p></figcaption></figure></div>
{% endtab %}

{% tab title="3. Enable SR-IOV" %}
Select the SR-IOV support and enable it.

<div data-with-frame="true"><figure><img src="/files/6WyH9fEcBuv32amuzXJE" alt=""><figcaption><p>Enable SR-IOV</p></figcaption></figure></div>
{% endtab %}

{% tab title="4. Save and exit" %}
Save the configuration changes and exit.

<div data-with-frame="true"><figure><img src="/files/krXQoRj4hvPXgdXEiQgG" alt=""><figcaption><p>Save and Exit</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}


# Configure the cluster with WEKA Configurator

Detailed workflow for WEKA cluster installation in a multi-container backend architecture using the WEKA Configurator.

The WEKA Configurator tool facilitates cluster configuration. It performs the following:

* Scans your environment to detect the network, verifies various attributes such as hostnames, and discovers components such as gateway routers.
* Selects the servers that can be included in the cluster and verifies that all servers run the same WEKA version.
* Guides you through the configuration options.
* Generates a valid configuration file that you can apply to form a WEKA cluster from a group of servers.

## Before you begin

Adhere to the following concepts:

* **STEM mode:** STEM mode is the initial state before configuration. The term STEM comes from the concept of stem cells in biology, which are undifferentiated. In WEKA clusters, STEM mode carries the same connotation of being an undifferentiated state.
* **Reference host:** The `wekaconfig` normally runs on one of the servers designated as part of the final cluster. The server that `wekaconfig` runs on is called the reference host. When `wekaconfig` runs, it expects to find a group of servers in STEM mode. If the reference host is not in STEM mode, an error message is issued, and the program terminates.
* **Same networks:** It is assumed that all other servers forming the cluster are connected to the same networks as the `reference host` and have the same configuration (all servers have a homogeneous hardware configuration).
* **Homogeneous configuration:** Two or more servers with the same core count, RAM size, number and size of drives, and network configurations are considered homogeneous.
  * It is best practice to create the WEKA cluster from a group of homogeneous servers (it is typically the case because the hardware is typically purchased all at the same time). `wekaconfig` checks if the servers are homogeneous; if they are not, it points out the discrepancies (such as varying numbers of drives, RAM, or cores).
  * `wekaconfig` allows the configuration of heterogeneous clusters. However, because most times, the servers are supposed to be homogeneous, it can be an error that they are not. For example, if one of the drives is defective (DOA) from the factory or a memory stick is defective. These hardware issues are uncommon and can be difficult to discover in large clusters.
* **Passwordless ssh connection:** Enabling passwordless ssh between all the servers is very convenient and makes most tools work more smoothly. At a minimum, a regular user with passwordless `sudo` privileges and passwordless ssh is required for configuration. However, it is most convenient to have the `root` user has passwordless ssh, even if only temporarily during configuration.\
  Ensure you can ssh without a password by doing an ssh to each server.
* **Stripe width:** A RAID-like concept refers to the total width of the data stripe for data protection mechanisms. Typically, the DATA and PARITY combined are the stripe width. In WEKA terms, the stripe width must be less than the total number of servers in the cluster. For example, in a 10-server cluster, the stripe width can be 9 (7 data + 2 parity) plus 1 spare.

## Prerequisites

* **System preparation validation:**\
  Ensure the system preparation is validated using the `wekachecker` tool (on WSA installations this is already installed under `/opt/tools/install`). For additional details, refer to the [Validate the system preparation](https://docs.weka.io/planning-and-installation/bare-metal/pages/-LphBqhYb2cw5jEQa-63#id-11.-validate-the-system-preparation) section.
* **WEKA software installation on cluster servers:**\
  Verify that the WEKA software is installed on all cluster servers. If it is not installed through the WSA, follow the installation instructions provided in the **Install** tab of [get.weka.io](https://get.weka.io). Once the installation is complete, the WEKA software will be deployed on all allocated servers and running in STEM mode.

## Workflow

1. Access the WEKA tools.
2. Configure a WEKA cluster with the WEKA Configurator.
3. Apply the configuration (`config.sh`).

### 1. Access the WEKA tools

1. **If you do not use WSA or WEKApod**:\
   Download the WEKA tools repository to one of the servers by running the following command:

   ```bash
   git clone https://github.com/weka/tools
   ```
2. **If you use WSA or WEKApod**:\
   The tools are pre-installed and can be found at the following location:

   ```bash
   /opt/tools/install  
   ```

### 2. Configure a WEKA cluster with the WEKA Configurator

1. **Run the `wekaconfig` Tool:**
   1. Connect to one of the backend servers or the WMS server (if it exists) using SSH.
   2. Navigate to the tools directory directory:

      ```bash
      cd tools/install
      - or -
      cd opt/tools/install
      ```
   3. Run the `wekaconfig` tool:

      ```bash
      ./wekaconfig
      ```

The `wekaconfig` tool scans the environment, detects the servers, and evaluates whether the group of servers is homogeneous. The following example demonstrates a scenario where the servers do not have a homogeneous number of CPU cores.

<div data-with-frame="true"><figure><img src="/files/X496O1ZIeKIYvNVHYgNC" alt="" width="563"><figcaption><p>Example: <code>wekaconfig</code> detection results</p></figcaption></figure></div>

2. **Review the detection results:**
   1. If the detected configuration meets your requirements, press **Enter** to proceed.
   2. Navigate through the available tabs to configure the WEKA settings as needed.

{% tabs %}
{% tab title="1. DP Networks" %}
The `wekaconfig` displays the data plane networks (DP Networks) detected previously. The list under **Select DP Networks** reflects the high-speed (100Gb+) networks used for the WEKA storage traffic.

Verify that the list of networks, speed, and number of detected hosts are correct.

If the values are not as expected, such as an incorrect number of servers, incorrect or missing networks, investigate it and check the messages. Typically, network configuration issues are the source of the problem.

Select the required networks to configure WEKA POSIX protocol to run on.

Use the arrow and Tab keys to move between the fields and sections, and the space-bar to select the value.

**Note:** The green labels have entry fields. The yellow labels have read-only fields.

<div data-with-frame="true"><figure><img src="/files/az2xjGd0PRrrcbKXkRg4" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="2. HA and Multi-container" %}
Press Tab to move to the **Hosts** section.

`wekaconfig` pre-populated the hostnames of the servers that are on this network and running the same version of WEKA and are in STEM mode.

Use the arrow keys to move between the servers, and space bar to select or deselect specific servers. Press Tab to accept values and move to the next field: High Availability.

High Availability (HA) is used for networks with more than one network interface.

In this example, only one network is selected, so the HA default is No. When there are two or more networks selected, you can change the the HA option to suit your needs. Consult the WEKA Customer Success Team before changing this default value.

Press Tab to accept value and move to the next field: Multicontainer. The default is Yes and it is mandatory from WEKA version 4.1.

Press Tab to move to the lower-right. Use the arrow to move to **Next**. Then, press the space-bar.

<div data-with-frame="true"><figure><img src="/files/z4k62ZAFMxzWLJgmYWN7" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="3. BIAS and other read-only fields" %}
This page shows the following sections:

* Host Configuration Reference
* Bias
* Cores details

**Host Configuration Reference**

This section shows the `reference host` cores and drives configuration, and the total number of hosts (servers).

**Bias**

The Bias options determine the optimal CPU core and memory allocation scheme.

* **Enable Protocols:** If you intend to use the cluster for NFS, SMB, or S3 protocols, select this option. This option reserves some CPU and memory for the protocols.
* **Protocols are Primary:** If you intend to use the cluster primarily or heavily with NFS, SMB, or S3 protocols, select this option. It reserves more CPU and memory (then in the first option) for the protocols .
* **DRIVES over COMPUTE:** In high-core-count configurations (48+ cores), the standard algorithm for determining optimal core allocations may reduce the drive:core ratio in favor of additional COMPUTE cores. This bias setting favors a DRIVE core allocation of 1:1 (if possible) over additional COMPUTE cores. For advice on core allocations, consult with the Customer Success Team if you are configuring high-core-count systems.

**Core details**

`wekaconfig` suggests a reasonable set of core allocations (FE/COMPUTE/DRIVES) depending on your selections. You may override these values as needed.

* **Cores for OS:** The number of cores reserved for the OS (fixed at 2).
* **Cores for Protocols:** The number of cores reserved for protocols. It depends on the selected Bias option.
* **Usable Weka Cores:** The number of cores can be used for FE, COMPTE, and DRIVES processes.
* **Used Weka Cores:** The number of cores selected for use as FE, COMPUTE, or DRIVES cores.

The **Usable Weka Cores** and **Available Weka Cores** read-only fields are updated as you make changes so you can ensure you are not exceeding the number of available cores as you change any values. This is an advanced feature, and core allocation must not be changed without consulting the Customer Success Team.

<div data-with-frame="true"><figure><img src="/files/LfWq37DBCAfZxc4kvw3s" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="4. Cluster name" %}
Move to the Cluster Name field and set a unique name for your WEKA cluster.

<div data-with-frame="true"><figure><img src="/files/wx5qk0F41nPxFd6SW8YQ" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="5. Stripe and other settings" %}
The stripe and other settings include:

* **Data Drives:** The number of data members in the Stripe Width.
* **Parity Drives:** The number of parity members.
* **Hot Spares:** The number of Hot Spare members.
* **Reserved RAM per Host:** Extra RAM in GB reserved on each host for various purposes, like supporting Protocols or Applications.

These settings are in terms of servers, not SSDs. WEKA stripes over the entire servers, not over individual drives. For more details, see [Configure the cluster with Resources Generator](/planning-and-installation/bare-metal/manually-configure-the-weka-cluster-using-the-resource-generator).

The following example shows a stripe width of 6 (4+2) on 7 servers, and one hot spare.

<div data-with-frame="true"><figure><img src="/files/l4r0i52VWUT1LO3SgxQ5" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}

3. **Finalize the configuration:**

   After completing the WEKA configuration, use the arrow keys to select **Done** and press **Enter**.

   The `wekaconfig` tool generates the `config.sh` file based on your settings.

<details>

<summary><code>config.sh</code> output example</summary>

```bash
#!/bin/bash
usage() {
	echo "Usage: $0 [--no-parallel]"
	echo "  Use --no-parallel to prevent parallel execution"
	exit 1
}

para() {
	TF=$1; shift
	echo $*
	$* &
	#[ !$TF ] && { echo para waiting; wait; }
	[ $TF == "FALSE" ] && { echo para waiting; wait; }
}

PARA="TRUE"

# parse args
if [ $# != 0 ]; then
	if [ $# != 1 ]; then
		usage
	elif [ $1 == "--no-parallel" ]; then
		PARA="FALSE"
	else
		echo "Error: unknown command line switch - $1"
		usage
	fi
fi

echo starting - PARA is $PARA

# ------------------ custom script below --------------

echo Stopping weka on weka63
para ${PARA} scp -p ./resources_generator.py weka63:/tmp/
para ${PARA} ssh weka63 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka64
para ${PARA} scp -p ./resources_generator.py weka64:/tmp/
para ${PARA} ssh weka64 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka65
para ${PARA} scp -p ./resources_generator.py weka65:/tmp/
para ${PARA} ssh weka65 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka66
para ${PARA} scp -p ./resources_generator.py weka66:/tmp/
para ${PARA} ssh weka66 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka67
para ${PARA} scp -p ./resources_generator.py weka67:/tmp/
para ${PARA} ssh weka67 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka68
para ${PARA} scp -p ./resources_generator.py weka68:/tmp/
para ${PARA} ssh weka68 "sudo weka local stop; sudo weka local rm -f default"
echo Stopping weka on weka69
para ${PARA} scp -p ./resources_generator.py weka69:/tmp/
para ${PARA} ssh weka69 "sudo weka local stop; sudo weka local rm -f default"

wait
echo Running Resources generator on host weka63
para ${PARA} ssh weka63 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.63/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka64
para ${PARA} ssh weka64 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.64/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka65
para ${PARA} ssh weka65 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.65/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka66
para ${PARA} ssh weka66 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.66/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka67
para ${PARA} ssh weka67 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.67/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka68
para ${PARA} ssh weka68 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.68/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
echo Running Resources generator on host weka69
para ${PARA} ssh weka69 sudo /tmp/resources_generator.py -f --path /tmp --net ib0/10.1.1.69/16 --compute-dedicated-cores 15 --drive-dedicated-cores 6 --frontend-dedicated-cores 1
wait
echo Starting Drives container on server weka63
para ${PARA} ssh weka63 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka64
para ${PARA} ssh weka64 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka65
para ${PARA} ssh weka65 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka66
para ${PARA} ssh weka66 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka67
para ${PARA} ssh weka67 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka68
para ${PARA} ssh weka68 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"
echo Starting Drives container on server weka69
para ${PARA} ssh weka69 "sudo weka local setup container --name drives0 --resources-path /tmp/drives0.json"

wait

sudo weka cluster create weka63 weka64 weka65 weka66 weka67 weka68 weka69 --host-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 -T infinite
echo Starting Compute container 0 on host weka63
para ${PARA} ssh weka63 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.63
echo Starting Compute container 0 on host weka64
para ${PARA} ssh weka64 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.64
echo Starting Compute container 0 on host weka65
para ${PARA} ssh weka65 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.65
echo Starting Compute container 0 on host weka66
para ${PARA} ssh weka66 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.66
echo Starting Compute container 0 on host weka67
para ${PARA} ssh weka67 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.67
echo Starting Compute container 0 on host weka68
para ${PARA} ssh weka68 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.68
echo Starting Compute container 0 on host weka69
para ${PARA} ssh weka69 sudo weka local setup container --name compute0 --resources-path /tmp/compute0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.69
wait

para ${PARA} sudo weka cluster drive add 0 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 1 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 2 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 3 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 4 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 5 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 
para ${PARA} sudo weka cluster drive add 6 /dev/nvme0n1 /dev/nvme1n1 /dev/nvme2n1 /dev/nvme3n1 /dev/nvme4n1 /dev/nvme5n1 

wait
sudo weka cluster update --data-drives=4 --parity-drives=2
sudo weka cluster hot-spare 1
sudo weka cluster update --cluster-name=fred

echo Starting Front container on host weka63
para ${PARA} ssh weka63 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.63
echo Starting Front container on host weka64
para ${PARA} ssh weka64 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.64
echo Starting Front container on host weka65
para ${PARA} ssh weka65 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.65
echo Starting Front container on host weka66
para ${PARA} ssh weka66 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.66
echo Starting Front container on host weka67
para ${PARA} ssh weka67 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.67
echo Starting Front container on host weka68
para ${PARA} ssh weka68 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.68
echo Starting Front container on host weka69
para ${PARA} ssh weka69 sudo weka local setup container --name frontend0 --resources-path /tmp/frontend0.json --join-ips=10.1.1.63,10.1.1.64,10.1.1.65,10.1.1.66,10.1.1.67,10.1.1.68,10.1.1.69 --management-ips=10.1.1.69

wait
echo Configuration process complete
```

</details>

{% hint style="info" %}
Advanced users can customize the configuration by editing the `config.sh` file using a text editor such as `vim` or `nano`. If modifications are required, consult the Customer Success Team for guidance.

Regarding drive selection: it is not possible to manually select the data drives (NVMe SSDs) for inclusion in the configuration. WEKA clusters are typically dedicated to running WEKA services and are designed to be homogeneous. As a result, the `wekaconfig` tool automatically includes all NVMe drives that are larger than approximately 1.5 GB in size.

To modify the drives used in the cluster, manually edit the `config.sh` file. Refer to the example output for `config.sh` provided above for guidance.
{% endhint %}

### 2. Apply the configuration

* From the install directory, run `./config.sh`.

<div data-with-frame="true"><figure><img src="/files/EGz4liT6E7Nu3PECh5cE" alt="" width="563"><figcaption><p>Apply the configuration</p></figcaption></figure></div>

The configuration takes a few minutes and possibly longer for large clusters. See some examples of the configuration process and WEKA status.

{% tabs %}
{% tab title="Configuration starts" %}

<div data-with-frame="true"><figure><img src="/files/OUCfpZqgxBjw5yGRooSX" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="Configuration completes" %}

<div data-with-frame="true"><figure><img src="/files/aCwGeXj1A8vvbw7wiLgG" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="WEKA status (IO not started)" %}

<div data-with-frame="true"><figure><img src="/files/AKCr1JAOPtP7LYmbXXb7" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="WEKA status (IO started)" %}

<div data-with-frame="true"><figure><img src="/files/XbeTLCX5tmJWogWJRTrM" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}

## What to do next?

[Perform post-configuration](/planning-and-installation/bare-metal/perform-post-configuration-procedures)


# Configure the cluster with Resources Generator

Detailed workflow for manually configuring the WEKA cluster using the resource generator in a multi-container backend architecture.

Perform this workflow only if you are following the manual installation and configuration path.

Do not use this workflow if you are using the WSA or WEKA Configurator.

The resources generator generates three resource files on each server in the `/tmp` directory: `drives0.json`, `compute0.json`, and `frontend0.json`. Then, you create the containers using these generated files of the cluster servers.

## Before you begin

1. Download the resources generator from the GitHub repository to your local server: <https://github.com/weka/tools/blob/master/install/resources_generator.py>.

Example:

```
wget https://raw.githubusercontent.com/weka/tools/master/install/resources_generator.py

```

2. Copy the resources generator from your local server to all servers in the cluster.

Example for a cluster with 8 servers:

```
for i in {0..7}; do scp resources_generator.py weka0-$i:/tmp/resources_generator.py; done

```

2. To enable execution, change the mode of the resources generator on all servers in the cluster.

Example for a cluster with 8 servers:

```
pdsh -R ssh -w "weka0-[0-7]" 'chmod +x /tmp/resources_generator.py'

```

## Workflow

1. Remove the default container
2. Generate the resource files
3. Create a cluster
4. Configure the SSD drives
5. Create compute containers
6. Create frontend containers
7. Configure number of data and parity drives
8. Configure number of hot spares
9. Name the cluster

### 1. Remove the default container

**Command:** `weka local stop default && weka local rm -f default`

Stop and remove the auto-created default container created on each server.

### 2. Generate the resource files

**Command:** `resources_generator.py`

To generate the resource files for the drive, compute, and frontend processes, run the following command on each backend server:

`./resources_generator.py --net <net-devices> [options]`

The resources generator allocates the number of cores, memory, and other resources according to the values specified in the parameters.

The best practice for resources allocation is as follows:

* 1 drive core per NVMe device (SSD).
* 2-3 compute cores per drive core.
* 1-2 frontend cores if deploying a protocol container. If there is a spare core, it is used for a frontend container.
* Minimum of 1 core for the OS.

#### Example 1: according to the best practice

For a server with **24** cores and 6 SSDs, allocate 6 drive cores and 12 compute cores, and optionally you can use 2 cores of the remaining cores for the frontend container. The OS uses the remaining 4 cores.

Run the following command line:\
`./resources_generator.py --net eth1 eth2 --drive-dedicated-cores 6 --compute-dedicated-cores 12 --frontend-dedicated-cores 2`

#### Example 2: a server with a limited number of cores

For a server with **14** cores and 6 SSDs, allocate 6 drive cores and 6 compute cores, and optionally you can use 1 core of the remaining cores for the frontend container. The OS uses the remaining 1 core.

Run the following command line:\
`./resources_generator.py --net eth1 eth2 --drive-dedicated-cores 6 --compute-dedicated-cores 6 --frontend-dedicated-cores 1`

{% hint style="info" %}
Contact Professional Services for the recommended resource allocation settings for your system.
{% endhint %}

**Parameters**

<table><thead><tr><th width="307">Name</th><th width="292">Value</th><th>Default</th></tr></thead><tbody><tr><td><code>compute-core-ids</code></td><td>Specify the CPUs to allocate for the compute processes.<br>Format: space-separated numbers</td><td></td></tr><tr><td><code>compute-dedicated-cores</code></td><td>Specify the number of cores to dedicate for the compute processes.</td><td>The maximum available cores</td></tr><tr><td><code>compute-memory</code></td><td><p>Specify the total memory to allocate for the compute processes.</p><p>Format: value and unit without a space.</p><p>Examples: 1024B, 10GiB, 5TiB.</p></td><td>The maximum available memory</td></tr><tr><td><code>core-ids</code></td><td>Specify the CPUs to allocate for the WEKA processes.<br>Format: space-separated numbers.</td><td></td></tr><tr><td><code>drive-core-ids</code></td><td>Specify the CPUs to allocate for the drive processes.<br>Format: space-separated numbers.</td><td></td></tr><tr><td><code>drive-dedicated-cores</code></td><td>Specify the number of cores to dedicate for the drive processes.</td><td>1 core per each detected drive</td></tr><tr><td><code>drives</code></td><td><p>Specify the drives to use.</p><p>This option overrides automatic detection.<br>Format: space-separated strings.</p></td><td>All unmounted NVME devices</td></tr><tr><td><code>frontend-core-ids</code></td><td>Specify the CPUs to allocate for the frontend processes.<br>Format: space-separated numbers.</td><td>-</td></tr><tr><td><code>frontend-dedicated-cores</code></td><td>Specify the number of cores to dedicate for the frontend processes.</td><td>1</td></tr><tr><td><code>max-cores-per-container</code></td><td>Override the default maximum number of cores per container for IO processes (19). If provided, the new value must be lower.</td><td>19</td></tr><tr><td><code>minimal-memory</code></td><td>Set each container's hugepages memory to 1.4 GiB * number of IO processes on the container.</td><td></td></tr><tr><td><code>net</code>*</td><td>Specify the network devices to use.<br>Format: space-separated strings.</td><td></td></tr><tr><td><code>no-rdma</code></td><td>Don't take RDMA support into account when computing memory requirements.</td><td>False</td></tr><tr><td><code>num-cores</code></td><td>Override the auto-deduction of the number of cores.</td><td>All available cores</td></tr><tr><td><code>path</code></td><td>Specify the path to write the resource files.</td><td>'.'</td></tr><tr><td><code>spare-cores</code></td><td>Specify the number of cores to leave for OS and non-WEKA processes.</td><td>1</td></tr><tr><td><code>spare-memory</code></td><td><p>Specify the memory to reserve for non-WEKA requirements.</p><p>Argument format: a value and unit without a space.</p><p>Examples: 10GiB, 1024B, 5TiB.</p></td><td>The maximum between 8 GiB and 2% of the total RAM</td></tr><tr><td><code>weka-hugepages-memory</code></td><td><p>Specify the memory to allocate for compute, frontend, and drive processes.</p><p>Argument format: a value and unit without a space.</p><p>Examples: 10GiB, 1024B, 5TiB.</p></td><td>The maximum available memory</td></tr></tbody></table>

### 3. Create a cluster

Explore the two methods to create a new WEKA cluster.

#### Create the cluster (two-step method)

This method involves two main stages. First, you create the initial `drives0` container on each server. Second, you run a single command from one server to form the cluster using those initial containers.

**Procedure**

1. On each server that will be part of the cluster, run the `weka local setup container` command to create the initial `drives0` container.

   * Specify the path to the `drives0.json` resource file.
   * Do not include the `--join-ips` or `--clusterize` options at this stage.
   * `-n` sets the container name, in this example `drives0`. Otherwise, it uses the resource filename.

   ```
   weka local setup container -n drives0 --resources-path <resources-path>/drives0
   ```
2. From one of the servers, run the `weka cluster add` command.

   * Provide the hostnames of the servers and their corresponding management IP addresses.
   * You must provide at least five servers.

   ```
   weka cluster add <hostnames> [--host-ips <ips | ip+ip+ip+ip>]
   ```

   \
   **Example**

   ```
   weka cluster add weka{0..4} \
   --host-ips 10.108.121.124,10.108.168.90,10.108.163.203,10.108.67.242,10.108.67.205
   ```

**Parameters**

<table><thead><tr><th width="158.6484375">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>hostnames*</code></td><td>(Required) Hostnames or IP addresses, separated by spaces. If port 14000 is not the default for the drives, you can specify <code>hostnames:port</code> or <code>ips:port</code>.</td></tr><tr><td><code>host-ips</code></td><td><p>IP addresses of the management interfaces, separated by commas.</p><ul><li>Use a list of <code>ip+ip</code> address pairs for a high availability (HA) configuration.</li><li>If the cluster connects to both IB and Ethernet, you can specify up to four management IPs (<code>ip+ip+ip+ip</code>) for redundancy.</li><li>Default: IP of the first network device of the container.</li></ul></td></tr></tbody></table>

{% hint style="info" %}
The `host-ips` values identify management processes on the data plane network. They do not identify external management interfaces such as the CLI or REST API.
{% endhint %}

{% hint style="info" %}
**Notes:**

* The `weka local setup container` command uses pre-configured IP addresses from the generated resource file. It only modifies entries that are empty or contain the default `127.0.0.1` address. To force an overwrite of the `ips` field, use the `--overwrite_resource_ips` flag.
* If you use hostnames, ensure a reliable hostname-to-IP resolution mechanism is in place.
* For a high availability (HA) configuration, you must define at least two network cards for each container.
* After the command succeeds, the cluster enters an initialization phase. Some commands only run during this phase.
* After formation, each container receives a `container-ID`. Run `weka cluster container` to display the list of containers and their IDs.
  {% endhint %}

#### Create the cluster (single-step auto-clusterization)

This method uses a single command, run on all servers (for example, with a parallel shell utility), to auto-cluster. Containers start, discover peers using the join IPs, and automatically form the cluster.

**Before you begin**

* You must have a list of at least five management IP addresses from servers that will be part of the new cluster.

**Procedure**

1. On each server, run the `weka local setup container` command.

   * Include the `--join-ips` option and provide at least five management IPs that will be part of the new cluster.
   * Include the `--clusterize` option to trigger the auto-clusterization process.
   * For InfiniBand (IB) installations, the `--join-ips` parameter must specify the IP addresses of the IPoIB interfaces.
   * `-n` sets the container name, in this example `drives0`. Otherwise, it uses the resource filename.

   ```
   weka local setup container -n drives0 --resources-path drives0.json \
   --join-ips 10.108.121.124,10.108.168.90,10.108.163.203,10.108.67.242,10.108.67.205 \
   --clusterize
   ```

**High availability (HA) with auto-clusterization**

The `--join-ips` argument does not support the `+` notation for defining HA.

To configure HA with auto-clusterization, use the `--management-ips` argument when creating the container. You can provide multiple specific IPs or multiple network interface names.

Example using network interface names for HA:

```
weka local setup container -n drives --resources-path drives0.json \
--management-ips enp0s5,ens1 \
--join-ips 10.108.121.124,10.108.168.90,10.108.163.203,10.108.67.242,10.108.67.205 \
--clusterize
```

{% hint style="info" %}
The `--management-ips` option identifies management processes on the data plane network. It does not identify external management interfaces such as the CLI or REST API.
{% endhint %}

### 4. Configure the SSD drives

**Command:** `weka cluster drive add`

To configure the SSD drives on each server in the cluster, or add multiple drive paths, use the following command:

```
weka cluster drive add <container-id> <device-paths>
```

**Parameters**

<table><thead><tr><th width="195.71484375">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>container-id</code>*</td><td>The Identifier of the drive container to add the local SSD drives.</td></tr><tr><td><code>device-paths</code>*</td><td>List of block devices that identify local SSDs.<br>It must be a valid Unix network device name<strong>.</strong><br>Format: Space-separated strings.<br>Example, <code>/dev/nvme0n1 /dev/nvme1n1</code></td></tr></tbody></table>

### 5. Create compute containers

**Command:** `weka local setup container`

For each server in the cluster, create the compute containers using the resources generator output file `compute0.json`.

```
weka local setup container --join-ips <IP addresses> \
--resources-path <resources-path>/compute0.json
```

**Parameters**

<table><thead><tr><th width="217">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>resources-path</code>*</td><td>A valid path to the resource file.</td></tr><tr><td><code>join-ips</code></td><td><p><code>IP:port</code> pairs for the management processes to join the cluster. In the absence of a specified port, the command defaults to using the standard WEKA port 14000. Set the values, only if you want to customize the port.</p><p>To restrict the client’s operations to only the essential APIs for mounting and unmounting operations, connect to WEKA clusters through TCP base port + 3 (for example, 14003).</p><p>The <code>IP:port</code> value must match the value used to create the container.<br>Format: comma-separated IP addresses.<br>Example: <code>--join-ips 10.10.10.1,10.10.10.2,10.10.10.3:15000</code></p></td></tr></tbody></table>

### 6. Create frontend containers

**Command:** `weka local setup container`

For each server in the cluster, create the frontend containers using the resources generator output file `frontend0.json`.

```bash
weka local setup container --join-ips <IP addresses> \
--resources-path <resources-path>/frontend0.json
```

**Parameters**

<table><thead><tr><th width="187.9765625">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>resources-path</code>*</td><td>A valid path to the resource file.</td></tr><tr><td><code>join-ips</code></td><td>IP:port pairs for the management processes to join the cluster. In the absence of a specified port, the command defaults to using the standard WEKA port 14000. Set the values, only if you want to customize the port.<br>Format: comma-separated IP addresses.<br>Example: <code>--join-ips 10.10.10.1,10.10.10.2,10.10.10.3:15000</code></td></tr></tbody></table>

### 7. Configure the number of data and parity drives

**Command:** `weka cluster update --data-drives=<count> --parity-drives=<count>`

**Example:** `weka cluster update --data-drives=4 --parity-drives=2`

### 8. Configure the number of hot spares

**Command:** `weka cluster hot-spare <count>`

**Example:** `weka cluster hot-spare 1`

### 9. Name the cluster

**Command:** `weka cluster update --cluster-name=<cluster name>`

## What to do next?

Go to [Perform post-configuration](/planning-and-installation/bare-metal/perform-post-configuration-procedures).


# VLAN tagging in the WEKA system

WEKA tenant clusters use VLAN tagging to enable isolated network communication between clusters and their clients.

## Overview

WEKA support for IEEE 802.1Q VLAN encapsulation ("tagged VLAN IDs" or "tagged VLANs") enables isolation and segregation of network traffic while still granting connectivity between WEKA clients and backend servers.

A WEKA tenant cluster operates on a single VLAN ID, where all containers within that cluster must use the same VLAN ID. All clients connecting to a tenant cluster must use that cluster's assigned VLAN ID. When using the WEKA Kubernetes Operator, this VLAN ID consistency between the tenant cluster and its clients is automatically maintained.

In multi-cluster environments, each tenant cluster can operate on a different VLAN ID. For example, you can assign VLAN ID 100 to Tenant Cluster A and VLAN ID 200 to Tenant Cluster B, providing network isolation between clusters.

## **Enable WEKA tagged VLAN support**

To enable WEKA tagged VLAN support, add the desired VLAN IDs to the switch ports connected to WEKA backends. It is common to include one untagged VLAN and multiple tagged VLAN IDs.

After configuring the switch, update the Linux system interfaces to recognize the VLAN IDs and verify connectivity.

Use the following procedure on each WEKA backend and each WEKA stateful client. You do not need to perform this procedure on WEKA stateless clients because it is automatically applied during the mount command.

**Procedure**

1. Associate the VLAN with the network interface using one of the following methods based on your naming preference:

{% tabs %}
{% tab title="Option A" %}
Assign a tag to a specific device:

`weka local resources net add <nic> --vlan <tag>`

Example:

`weka local resources net add mlnx0 --vlan 501`
{% endtab %}

{% tab title="Option B" %}
Add a dedicated VLAN interface where the tag is inferred from the name:

`weka local resources net add vlan<tag>`

Example:

`weka local resources net add vlan501`
{% endtab %}
{% endtabs %}

2. Restart all containers on the server to apply the network configuration updates.

## Confirm which tagged VLAN is attached to the interfaces

To determine which tagged VLANs are configured, query the local resources of a container using a command like this:

```
weka local resources -C <containername>
```

Example:

```bash
weka local resources -C drives0
```

You can also display the cluster container network data with this command by requesting verbose output with `-v` to list the VLAN ID or by using syntax like `-o id,hostname,name,ips,vlan`:

```
weka cluster container net -v
```

## Mount filesystems with tagged VLANs

When running a mount command on a WEKA stateless client where the backends have a tagged VLAN, specify the same VLAN in the mount command as follows:

### **Basic VLAN tagging**

Mount a filesystem with a specified NIC and VLAN tag:

```bash
mount -o net=<nic>/vlan@<tag> <backendip/filesystem> <mountpoint>
```

Example:

```bash
mount -o net=mlnx0/vlan@501 10.10.0.10/default /mnt/weka
```

### **Extended network configuration**

Include gateway, IP, and netmask (in CIDR format) for advanced configurations:

{% code overflow="wrap" %}

```bash
mount -o net=<nic>/vlan@<tag>/gw@<gateway>/ip@<ip>/netmask@<netmask> <backendip/filesystem> <mountpoint>
```

{% endcode %}

Example:

{% code overflow="wrap" %}

```bash
mount -o net=mlnx0/vlan@501/gw@192.168.1.1/ip@192.168.1.10/netmask@22 10.10.0.10/default /mnt/weka
```

{% endcode %}

**Syntax guidelines:**

* Include additional named parameters (for example, `gw@`, `ip@`, `netmask@`) directly in the command syntax.
* Alternatively, use the legacy style by specifying name-value pairs after the positional parameters.
* Separate all parameters using `/`.

This syntax is also supported for the `weka local setup container --net ...` command.


# Perform post-configuration

Once the WEKA cluster is installed and configured, perform the following:

1. [Enable event notifications to the cloud (optional)](#id-1.-enable-event-notifications-to-the-cloud-optional).
2. [Set the license](#id-2.-set-the-license).
3. [Start the cluster IO service](#id-3.-start-the-cluster-io-service).
4. [Check the cluster configuration](#id-4.-check-the-cluster-configuration).
5. [Bypass the proxy server (optional)](#id-5.-bypass-the-proxy-server-optional).
6. [Configure default data networking (optional)](#id-6.-configure-default-data-networking-optional).

## 1. Enable event notifications to the cloud (optional)

Enable event notifications to the cloud for support purposes using one of the following options:

* Enable support through WEKA Home
* Enable support through a private instance of WEKA Home

### **Enable support through Weka Home**

**Command:** `weka cloud enable`

This command enables cloud event notification (via Weka Home), which allows the WEKA Customer Success Team to resolve any issues that may occur.

To learn more about this and how to enable cloud event notification, see [WEKA Home - The WEKA support cloud](/monitor-the-weka-cluster/the-wekaio-support-cloud).

### **Enable support through** Local WEKA Home

In closed environments, such as dark sites and private VPCs, it is possible to install Local WEKA Home, which is a private instance of WEKA Home.

**Command:** `weka cloud enable --cloud-url=http://<weka-home-ip>:<weka-home-port>`

This command enables the WEKA cluster to send event notifications to the Local WEKA Home.

{% hint style="info" %}
For details, see [Local WEKA Home overview](/monitor-the-weka-cluster/the-wekaio-support-cloud/local-weka-home-overview).
{% endhint %}

## 2. Set the license

**Command:** `weka cluster license set`

To run IOs against the cluster, a valid license must be applied. Obtain a valid license and apply it to the WEKA cluster. For details, see [Licensing overview](/licensing/overview).

## 3. Start the cluster IO service

**Command:** `weka cluster start-io`

To start the system IO and exit from the initialization state, use the following command line:

`weka cluster start-io`

## 4. Check the cluster configuration

### Check the cluster container

**Command:** `weka cluster container`

Use this command to display the list of containers and their details.

<details>

<summary>Example of a list of containers and their details</summary>

```bash
$ weka cluster container
HOST ID  HOSTNAME  CONTAINER  IPS             STATUS  RELEASE   FAILURE DOMAIN  CORES  MEMORY    LAST FAILURE  UPTIME
0        av299-0   drives0    10.108.79.121   UP      4.3.0     DOM-000         7      10.45 GB                1:08:30h
1        av299-1   drives0    10.108.115.194  UP      4.3.0     DOM-001         7      10.45 GB                1:08:30h
2        av299-2   drives0    10.108.2.136    UP      4.3.0     DOM-002         7      10.45 GB                1:08:29h
3        av299-3   drives0    10.108.165.185  UP      4.3.0     DOM-003         7      10.45 GB                1:08:30h
4        av299-4   drives0    10.108.116.49   UP      4.3.0     DOM-004         7      10.45 GB                1:08:29h
5        av299-5   drives0    10.108.7.63     UP      4.3.0     DOM-005         7      10.45 GB                1:08:30h
6        av299-6   drives0    10.108.80.75    UP      4.3.0     DOM-006         7      10.45 GB                1:08:29h
7        av299-7   drives0    10.108.173.56   UP      4.3.0     DOM-007         7      10.45 GB                1:08:30h
8        av299-8   drives0    10.108.253.194  UP      4.3.0     DOM-008         7      10.45 GB                1:08:29h
9        av299-9   drives0    10.108.220.115  UP      4.3.0     DOM-009         7      10.45 GB                1:08:29h
10       av299-0   compute0   10.108.79.121   UP      4.3.0     DOM-000         6      20.22 GB                1:08:08h
11       av299-1   compute0   10.108.115.194  UP      4.3.0     DOM-001         6      20.22 GB                1:08:08h
12       av299-2   compute0   10.108.2.136    UP      4.3.0     DOM-002         6      20.22 GB                1:08:09h
13       av299-3   compute0   10.108.165.185  UP      4.3.0     DOM-003         6      20.22 GB                1:08:09h
14       av299-4   compute0   10.108.116.49   UP      4.3.0     DOM-004         6      20.22 GB                1:08:09h
15       av299-5   compute0   10.108.7.63     UP      4.3.0     DOM-005         6      20.22 GB                1:08:08h
16       av299-6   compute0   10.108.80.75    UP      4.3.0     DOM-006         6      20.22 GB                1:08:09h
17       av299-7   compute0   10.108.173.56   UP      4.3.0     DOM-007         6      20.22 GB                1:08:08h
18       av299-8   compute0   10.108.253.194  UP      4.3.0     DOM-008         6      20.22 GB                1:08:09h
19       av299-9   compute0   10.108.220.115  UP      4.3.0     DOM-009         6      20.22 GB                1:08:08h
20       av299-0   frontend0  10.108.79.121   UP      4.3.0     DOM-000         1      1.47 GB                 1:06:57h
21       av299-1   frontend0  10.108.115.194  UP      4.3.0     DOM-001         1      1.47 GB                 1:06:57h
22       av299-2   frontend0  10.108.2.136    UP      4.3.0     DOM-002         1      1.47 GB                 1:06:57h
23       av299-3   frontend0  10.108.165.185  UP      4.3.0     DOM-003         1      1.47 GB                 1:06:56h
24       av299-4   frontend0  10.108.116.49   UP      4.3.0     DOM-004         1      1.47 GB                 1:06:57h
25       av299-5   frontend0  10.108.7.63     UP      4.3.0     DOM-005         1      1.47 GB                 1:06:56h
26       av299-6   frontend0  10.108.80.75    UP      4.3.0     DOM-006         1      1.47 GB                 1:06:57h
27       av299-7   frontend0  10.108.173.56   UP      4.3.0     DOM-007         1      1.47 GB                 1:06:56h
28       av299-8   frontend0  10.108.253.194  UP      4.3.0     DOM-008         1      1.47 GB                 1:06:57h
29       av299-9   frontend0  10.108.220.115  UP      4.3.0     DOM-009         1      1.47 GB                 1:06:56h
```

</details>

**Related topic**

[Container state and status fields](/operation-guide/expanding-and-shrinking-cluster-resources/container-state-and-status-fields)

### Check cluster container resources

**Command:** `weka cluster container resources`

Use this command to check the resources of each container in the cluster.

`weka cluster container resources <container-id>`

<details>

<summary>Example for a drive container resources output</summary>

```bash
$ weka cluster container resources 1
ROLES       NODE ID  CORE ID
MANAGEMENT  0        <auto>
DRIVES      1        4

NET DEVICE    IDENTIFIER    DEFAULT GATEWAY  IPS             NETMASK  NETWORK LABEL
0000:00:06.0  0000:00:06.0  10.108.0.1       10.108.115.194  UP  16

Allow Protocols           false
Bandwidth                 <auto>
Base Port                 14000
Dedicate Memory           true
Disable NUMA Balancing    true
Failure Domain            DOM-001
Hardware Watchdog         false
Management IPs            10.108.238.217
Mask Interrupts           true
Memory                    <dedicated>
Mode                      BACKEND
Non-Weka Reserved Memory  20
Set CPU Governors         PERFORMANCE
```

</details>

<details>

<summary>Example of a compute container resources output</summary>

```bash
$ weka cluster container resources 10
ROLES       NODE ID  CORE ID
MANAGEMENT  0        <auto>
COMPUTE     1        16
COMPUTE     2        4
COMPUTE     3        18
COMPUTE     4        26
COMPUTE     5        28
COMPUTE     6        10

NET DEVICE    IDENTIFIER    DEFAULT GATEWAY  IPS             NETMASK  NETWORK LABEL
0000:00:04.0  0000:00:04.0  10.108.0.1       10.108.145.137  16
0000:00:05.0  0000:00:05.0  10.108.0.1       10.108.212.87   16
0000:00:06.0  0000:00:06.0  10.108.0.1       10.108.199.231  16
0000:00:07.0  0000:00:07.0  10.108.0.1       10.108.86.172   16
0000:00:08.0  0000:00:08.0  10.108.0.1       10.108.190.88   16
0000:00:09.0  0000:00:09.0  10.108.0.1       10.108.77.31    16

Allow Protocols         false
Bandwidth               <auto>
Base Port               14300
Dedicate Memory         true
Disable NUMA Balancing  true
Failure Domain          DOM-000
Hardware Watchdog       false
Management IPs          10.108.79.121
Mask Interrupts         true
Memory                  20224982280
Mode                    BACKEND
Set CPU Governors       PERFORMANCE
```

</details>

<details>

<summary>Example of a frontend container resources output</summary>

```bash
$ weka cluster container resources 20
ROLES       NODE ID  CORE ID
MANAGEMENT  0        <auto>
FRONTEND    1        24

NET DEVICE    IDENTIFIER    DEFAULT GATEWAY  IPS             NETMASK  NETWORK LABEL
0000:00:13.0  0000:00:13.0  10.108.0.1       10.108.217.249  16

Allow Protocols         true
Bandwidth               <auto>
Base Port               14200
Dedicate Memory         true
Disable NUMA Balancing  true
Failure Domain          DOM-000
Hardware Watchdog       false
Management IPs          10.108.79.121
Mask Interrupts         true
Memory                  <dedicated>
Mode                    BACKEND
Set CPU Governors       PERFORMANCE
```

</details>

#### Check cluster drives

**Command:** `weka cluster drive`

Use this command to check all drives in the cluster.

<details>

<summary>Example</summary>

```bash
$ weka cluster drive
DISK ID  UUID                                  HOSTNAME  NODE ID  SIZE        STATUS  LIFETIME % USED  ATTACHMENT  DRIVE STATUS
0        d3d000d4-a76b-405d-a226-c40dcd8d622c  av299-4   87       399.99 GiB  ACTIVE  0                OK          OK
1        c68cf47a-f91d-499f-83c8-69aa06ed37d4  av299-7   143      399.99 GiB  ACTIVE  0                OK          OK
2        c97f83b5-b9e3-4ccd-bfb8-d78537fa8a6f  av299-1   23       399.99 GiB  ACTIVE  0                OK          OK
3        908dadc5-740c-4e08-9cc2-290b4b311f81  av299-0   7        399.99 GiB  ACTIVE  0                OK          OK
.
.
.
68       1c4c4d54-6553-44b2-bc61-0f0e946919fb  av299-4   84       399.99 GiB  ACTIVE  0                OK          OK
69       969d3521-9057-4db9-8304-157f50719683  av299-3   62       399.99 GiB  ACTIVE  0                OK          OK
```

</details>

### Check the Weka cluster status

**Command:** `weka status`

The `weka status` command displays the overall status of the WEKA cluster.

**Related topic**

[Manage the system using the WEKA CLI](/getting-started-with-weka/manage-the-system-using-weka-cli#cluster-status)

## 5. Bypass the proxy server (optional)

If the WEKA cluster is deployed in an environment with a proxy server, a WEKA client trying to mount or download the client installation from the WEKA cluster may be blocked by the proxy server. You can disable the proxy for specific URLs using the shell `no_proxy` environment variable.

#### Procedure

1. Connect to one of the WEKA backend servers (configuration changes made on this server are synchronized with all other servers in the cluster).
2. Open the `/etc/wekaio/service.conf` file.
3. In the `[downloads_proxy]` section, add to the `no_proxy` parameter a comma-separated list of IP addresses or qualified domain names of your WEKA clients and cluster backend servers. Do not use wildcards (\*).

   ```makefile
   [downloads_proxy]
   force_no_proxy=true
   proxy=
   no_proxy=<comma-separated list of IPs or domains>
   ```
4. Restart the agent service using the command:

   ```bash
   service weka-agent restart
   ```

## 6. Configure default data networking (optional)

**Command:** `weka cluster default-net set`

Instead of individually configuring IP addresses for each network device, WEKA supports dynamic IP address allocation. Users can define a range of IP addresses to create a dynamic pool, and these addresses can be automatically allocated on demand.

{% hint style="info" %}
**Mixed approach for Ethernet networking:** For Ethernet networking, a mixed approach is supported. Administrators can explicitly assign IP addresses for specific network devices, while others in the cluster can receive automatic allocations from the specified IP range. This feature is particularly useful in environments with automated client spawning.
{% endhint %}

Use the following command to configure default data networking:

`weka cluster default-net set --range <range> [--gateway=<gateway>] [--netmask-bits=<netmask-bits>]`

**Parameters**

<table><thead><tr><th width="158">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>range</code>*</td><td><p>A range of IP addresses reserved for dynamic allocation across the entire cluster..<br>Format: <code>A.B.C.D-E</code></p><p>Example: <code>10.10.0.1-100</code></p></td></tr><tr><td><code>netmask-bits</code>*</td><td>Number of bits in the netmask that define a network ID in CIDR notation.</td></tr><tr><td><code>gateway</code></td><td>The IP address assigned to the default routing gateway. It is imperative that the gateway resides within the same IP network as defined by the specified range and netmask-bits.<br>This parameter is not applicable to InfiniBand (IB) or Layer 2 (L2) non-routable networks.</td></tr></tbody></table>

**View current settings:** To view the current default data networking settings, use the command:\
`weka cluster default-net`

**Remove default data networking:** If a default data networking configuration was previously set up on a cluster and is no longer needed, you can remove it using the command:\
`weka cluster default-net reset`

**End of the installation and configuration for all workflow paths**

## **What do next?**

[Add clients](/planning-and-installation/bare-metal/adding-clients-bare-metal)


# Add clients

This page describes how to add clients to a bare-metal cluster.

## cgroups configuration

Clients run applications that access the WEKA filesystem but do not contribute CPUs or drives to the cluster. They connect solely to use the filesystems.

By default, WEKA uses cgroups to limit or isolate resources for its exclusive use, such as assigning specific CPUs.

cgroups (Control Groups) is a Linux kernel feature that allows you to limit, prioritize, and isolate a collection of processes' resource usage (CPU, memory, disk I/O, network). It helps allocate resources among user-defined groups of tasks and manage their performance effectively.

**Versions of cgroups:**

* **cgroupsV1**: Uses multiple hierarchies for different resource controllers, offering fine-grained control but with increased complexity.
* **cgroupsV2**: Combines all resource controllers into a single unified hierarchy, simplifying management and providing better resource isolation and a more consistent interface.

{% hint style="info" %}
**Hybrid mode**: If the OS is configured with hybrid mode (cgroupsV1 and cgroupsV2), WEKA defaults to using cgroupsV1.
{% endhint %}

**WEKA requirements:**

* **cgroups mode compatibility:** When setting up cgroups on clients or backends, ensure that the cgroups configuration (whether using cgroupsV1 or cgroupsV2) aligns with the operating system's capabilities and configuration.

### cgroups configuration and compatibility

The configuration of cgroups depends on the installed operating system, and it is important that the cluster server settings match the OS configuration to ensure proper resource management and compatibility.

Customers using a supported OS with cgroupsV2 or wanting to modify the cgroups usage can set the cgroups usage during the agent installation or by editing the service configuration file. The specified mode must match the existing cgroups configuration in the OS.

The cgroups setting includes the following modes:

* `auto`: WEKA tries using cgroupsV1 (default). If it fails, the cgroups is set to none automatically.
* `force`: WEKA uses cgroupsV1. If the OS does not support it, WEKA fails.
* `force_v2`: WEKA uses cgroupsV2. If the OS does not support it, WEKA fails.
* `none`: WEKA never uses cgroups, even if it runs on an OS with cgroupsV1.

### Set the cgroups mode during the client or backend installation

In the installation command line, specify the required cgroups mode (`WEKA_CGROUPS_MODE`).

Example:

```bash
curl http://Backend-1:14000/dist/v1/install | WEKA_CGROUPS_MODE=none sh
```

### Set the cgroups mode in the service configuration file

You can set the cgroups mode in the service configuration file for clients and backends.

1. Open the service configuration file `/etc/wekaio/service.conf` and add one of the following:
   * `cgroups_mode=auto`
   * `cgroups_mode=force`
   * `cgroups_mode=force_v2`
   * `cgroups_mode=none`
2. Restart the WEKA agent service: Run `service weka-agent restart`.
3. Restart the containers to apply the cgroups settings:
   * Run `weka local restart` to restart all containers, or specify a container, for example, `weka local restart client` for the client container. If WEKA is mounted, unmount it before restarting.
4. Verify the cgroups settings by running the `weka local status` command.

Example:

```bash
[root@weka-cluster] #weka local status
Weka v4.2.0 (CLI build 4.2.0)
cgroups: mode=auto, enabled=true

Containers: 1/1 running (1 weka)
Nodes: 2/2 running (2 READY)
Mounts: 1
```

## Add a stateless client to the cluster

A **stateless client** is a client that does not persistently store any software or configuration state locally. Instead, it dynamically installs the required software and configuration each time it interacts with the WEKA system. This approach simplifies client management by eliminating the need for persistent local installations, though the client still temporarily joins the cluster during operations. Stateless clients are particularly useful for deployment on lightweight, diskless servers.

To enable a stateless client to use the WEKA filesystem, the `mount` command is used. This command installs the WEKA software automatically and configures the client without requiring manual intervention.

**Before you begin**

Ensure each client has a unique IP address and a fully qualified domain name (FQDN) for proper cluster identification.

**Procedure**

1. **Install the WEKA agent (One-time setup):**\
   Install the WEKA agent from one of the backend instances. This step prepares the client to interact with the WEKA system. Run the following command (where `backend-1` resolves to the IP address of one of the WEKA backend servers):

   ```bash
   curl http://backend-1:14000/dist/v1/install | sh
   ```
2. **Create a mount point (one-time setup):**\
   Create a directory on the client system where the WEKA filesystem will be mounted. For example:

   ```bash
   mkdir -p /mnt/weka
   ```
3. **Mount the WEKA filesystem:**\
   Use the `mount` command to attach the WEKA filesystem to the client (where `my_fs` is the name of the WEKA filesystem). For example:

   ```bash
   mount -t wekafs -o net=eth0 backend-1/my_fs /mnt/weka
   ```

   * During the first mount, the required WEKA software is installed, and the client is configured automatically.

**Additional configuration**

* **Automatic mounting at boot:**\
  To configure the client OS to automatically mount the filesystem at boot time, you can use traditional methods or configure `autofs`. For more details, refer to the relevant documentation on [Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems#mounting-filesystems-using-stateless-clients) **Mount a filesystem using the traditional method** or **Mount filesystems using autofs**.
* **Diskless deployment:**\
  Stateless clients can be deployed on [diskless nodes](#user-content-fn-1)[^1] by storing the WEKA client software in RAM and using an NFS mount for traces. For assistance with this setup, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).

**Related topic**

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems#mounting-filesystems-using-stateless-clients) (for detailed mount and configuration options)

## Add a persistent client to the cluster

Add a persistent client for continuous POSIX filesystem access. A persistent client, also called a stateful client, remains joined to the cluster and supports persistent mounts.

**Before you begin**

Ensure the client can reach a backend server. Reserve the CPU cores, memory, and network device for the client container.

**Procedure**

1. **Install the WEKA agent:** Install the agent from a backend server. Replace `backend-1` with a backend server name that resolves on the client.

   ```bash
   curl http://backend-1:14000/dist/v1/install | sh
   ```
2. **Configure the client container:** Run `weka local setup client` with the required resources and network settings. The command designates the container as `frontend-dedicated`.

   The cluster removes an unreachable client container after one hour. The container rejoins automatically when connectivity returns.

{% hint style="info" %}
You can modify the automatic removal delay using `weka local resources auto-remove-timeout <auto-remove-timeout> [--container container]`. Specify the timeout value in seconds.
{% endhint %}

{% code overflow="wrap" %}

```bash
weka local setup client [--name name]
                        [--cores cores]
                        [--memory memory]
                        [--bandwidth bandwidth]
                        [--timeout timeout]
                        [--base-port base-port]
                        [--weka-version weka-version]
                        [--fqdn fqdn]
                        [--nvidia-vf-single-ip nvidia-vf-single-ip]
                        [--dedicated-mode dedicated-mode]
                        [--scan-rdma scan-rdma]
                        [--color color]
                        [--core-ids core-ids]...
                        [--management-ips management-ips]...
                        [--join-ips join-ips]...
                        [--net net]...
                        [--disable]
                        [--no-start]
                        [--allow-mix-setting]
                        [--restricted]
```

{% endcode %}

For example:

{% code overflow="wrap" %}

```bash
weka local setup client --name client --join-ips 10.108.81.144 --base-port 14000 --cores 1 --core-ids 2 --net ib1
```

{% endcode %}

#### Parameters

<table><thead><tr><th width="231">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>-n</code>, <code>--name</code></td><td>The name to give the container.</td></tr><tr><td><code>--cores</code></td><td>Number of CPU cores dedicated to WEKA.</td></tr><tr><td><code>--memory</code></td><td>Memory dedicated to WEKA in bytes. Set to <code>0</code> to let the system decide. Use decimal or binary units, such as <code>1GB</code> or <code>1GiB</code>.</td></tr><tr><td><code>--bandwidth</code></td><td>Bandwidth limit per second. Use <code>unlimited</code> or a decimal or binary value, such as <code>1GB</code> or <code>1GiB</code>.</td></tr><tr><td><code>-t</code>, <code>--timeout</code></td><td>Join command timeout. Use values such as <code>3s</code>, <code>2h</code>, <code>4m</code>, <code>1d</code>, <code>1d5h</code>, <code>1w</code>, <code>infinite</code>, or <code>unlimited</code>.</td></tr><tr><td><code>--base-port</code></td><td>First port used by the WEKA container. WEKA uses 100 ports starting at this port.</td></tr><tr><td><code>--weka-version</code></td><td>WEKA version used to start the container.</td></tr><tr><td><code>--fqdn</code></td><td>Fully qualified domain name used by other containers for TLS hostname verification.</td></tr><tr><td><code>--nvidia-vf-single-ip</code></td><td>Configures NVIDIA virtual functions to use a single IP address. Use <code>yes</code>, <code>no</code>, <code>true</code>, <code>false</code>, <code>on</code>, <code>off</code>, <code>y</code>, or <code>n</code>.</td></tr><tr><td><code>--dedicated-mode</code></td><td>Sets DPDK core dedication to <code>full</code> or <code>none</code>. <code>none</code> requires NIC driver support.</td></tr><tr><td><code>--scan-rdma</code></td><td>Scans for unused network devices and adds them for RDMA use. Use <code>off</code>, <code>ib</code>, <code>eth</code>, or <code>all</code>.</td></tr><tr><td><code>--color</code></td><td>Sets color output. Use <code>auto</code>, <code>disabled</code>, or <code>enabled</code>.</td></tr><tr><td><code>--core-ids</code>...</td><td>WEKA dedicated core IDs. Repeat the parameter or provide comma-separated values.</td></tr><tr><td><code>--management-ips</code>...</td><td>Management process IP addresses. Repeat the parameter or provide comma-separated values.</td></tr><tr><td><code>--join-ips</code>...</td><td>Management process IP:port pairs. If no port is specified, WEKA uses the default port. Repeat the parameter or provide comma-separated values.</td></tr><tr><td><code>--net</code>...</td><td>Network specification. Use a device name such as <code>ib1</code> or <code>eth1</code>, <code>&#x3C;device>/&#x3C;ip>/&#x3C;bits>/&#x3C;gateway></code>, <code>&#x3C;device>/rdma-only/inet4</code>, or <code>&#x3C;device>/rdma-only/inet6</code>. Use <code>udp</code> to force UDP mode. Repeat the parameter or provide comma-separated values.</td></tr><tr><td><code>--disable</code></td><td>Creates the container as disabled.</td></tr><tr><td><code>--no-start</code></td><td>Does not start the container after creation.</td></tr><tr><td><code>--allow-mix-setting</code></td><td>Allows specified core IDs when containers with automatic core-ID allocation run on the same server.</td></tr><tr><td><code>--restricted</code></td><td>Enables restricted client mode.</td></tr></tbody></table>

[^1]: A **diskless node** is a workstation or computer that lacks local disk drives and uses network booting to load its operating system from a server. For details, see <https://en.wikipedia.org/wiki/Diskless_node>


# Cloud Deployment Manager Web (CDM Web) User Guide

## Overview

The Cloud Deployment Manager Web (CDM Web) simplifies the deployment of WEKA clusters in the AWS, Azure, and GCP public cloud environments. Leveraging WEKA’s validated Terraform deployment modules, the CDM provides a user-friendly interface to guide users through the initial configuration process.

Key features of the CDM Web:

* **Streamlined deployment:** The CDM streamlines the deployment of WEKA clusters, making it easier for users to set up their infrastructure.
* **Web-hosted solution:** The CDM is fully web-hosted, eliminating the need for downloads or installations. Users can quickly begin configuring their WEKA clusters.
* **Terraform configuration file:** The CDM process results in the main Terraform configuration file `(main.tf)`, which can be directly applied when deploying WEKA.

## Access the CDM Web

To access the CDM Web, follow these steps:

1. Navigate to [cloud.weka.io](http://cloud.weka.io).
2. On the welcome page, select the cloud environment (AWS, Azure, or GCP) for your WEKA cluster deployment. (This guide uses Azure as an example, but the deployment workflow is similar across all supported cloud platforms.)

<div data-with-frame="true"><figure><img src="/files/0q9DuvnT01XWhwpnUeZ3" alt=""><figcaption><p>CDM Web welcome</p></figcaption></figure></div>

3. After selecting a public cloud, you are redirected to a login screen. Log in using your [get.weka.io](http://get.weka.io/) credentials. Internal WEKA users can use their Google SSO login to access CDM. Adhere to the following guidelines:
   * Ensure you have a get.weka.io token provisioned and available for a successful deployment.
   * If you are an internal WEKA user deploying a WEKA cluster for a customer, log in using the customer’s get.weka.io credentials. The signed-in user’s get.weka.io token automatically populates into the CDM configuration workflow.

<div data-with-frame="true"><figure><img src="/files/t2aCWXYDBmQrXjjjfYmE" alt=""><figcaption><p>CDM Web Login</p></figcaption></figure></div>

Once logged in, you are presented with the main configuration dashboard of the Cloud Deployment Manager.

<div data-with-frame="true"><figure><img src="/files/8yap22vqJZwAWE444dcL" alt=""><figcaption><p>CDM Web main dashboard</p></figcaption></figure></div>

## CDM Web dashboard overview

The CDM Web features a simple and clean configuration interface, offering the power and flexibility of our Terraform deployment modules. Below, each part of the interface is detailed for better understanding and usage.

The CDM dashboard consists of three main components:

* The workflow navigation panel (outlined in green)
* The configuration input panel (outlined in orange)
* The dynamic content sidebar (outlined in teal)

<div data-with-frame="true"><figure><img src="/files/KwNHz6z8Dl1rqCdAaVae" alt=""><figcaption><p>CDM Web dashboard main sections</p></figcaption></figure></div>

### Workflow navigation panel

The workflow navigation panel provides convenient access to various WEKA cluster configuration variables. You can switch between different aspects of cluster configuration and adjust settings according to their deployment needs.

The tabs within the panel correspond to primary configurable aspects for a WEKA cluster:

* Basic WEKA cluster configuration
* Cloud networking configuration
* Cloud security configuration
* Optional object storage (OBS) configuration
* Optional deployment of NFS protocol gateways
* Optional deployment of SMB protocol gateways
* Optional deployment of WEKA clients
* Optional advanced configuration (granular cluster-level adjustments)

To ensure completeness from a basic requirements perspective, specific fields within the configuration input panel are marked as mandatory based on the selected configuration options.

The workflow navigation panel visually indicates the completeness of the configuration. A green check or a red **x** appears next to each tab, helping users identify areas that require additional attention. For example, if both Basic Configuration and Security Configuration have fields that need attention, the panel reflects this.

You can navigate between different workflow pages and view associated configuration input panels by clicking the **Next** button or selecting the desired tab from the workflow navigation panel.

<div data-with-frame="true"><figure><img src="/files/BjuXpX77qHyulkuM5XLD" alt="" width="563"><figcaption><p>Basic configuration page</p></figcaption></figure></div>

### Configuration input panel

The configuration input panel provides a user-friendly interface for customizing input fields related to the WEKA cluster deployment. These fields correspond to variables in WEKA Terraform modules, which traditionally require manual formatting and entry into a `main.tf` file. With CDM, these variables are presented visually, streamlining the configuration process.

* You can tailor the input fields to match their needs and deployment objectives.
* Required fields are marked with a red asterisk.
* The following example illustrates the Basic Configuration workflow tab, where some required fields are populated, while others remain empty. Fields lacking input are highlighted in bright red, and the red outline disappears once the user provides the necessary information.

<div data-with-frame="true"><figure><img src="/files/rCS74OzJm8GYZJYpw7y6" alt="" width="375"><figcaption><p>Basic configuration required fields</p></figcaption></figure></div>

Certain fields within the configuration input panel require manual user input. Other fields, such as Instance Type, WEKA Version, and Region, are provided as selectable dropdown menus.

{% tabs %}
{% tab title="Instance Type" %}

<div data-with-frame="true"><figure><img src="/files/pJ8Q9EL1CR1SL9bfNdwP" alt="" width="290"><figcaption><p>Instance Type</p></figcaption></figure></div>
{% endtab %}

{% tab title="Region" %}

<div data-with-frame="true"><figure><img src="/files/MwWx8gQO5nEDlS2QUJ9j" alt="" width="290"><figcaption><p>Region</p></figcaption></figure></div>
{% endtab %}

{% tab title="WEKA Version" %}
The WEKA software release dropdown menu is designed to auto-populate with the most recent Long-Term Support (LTS) version by default. You can select the previous software release by opening the dropdown menu and choosing from the list. The top two entries in the dropdown are always LTS releases, while the bottom two are innovation releases.

To enter a WEKA software release that is not listed in the dropdown, click directly in the WEKA Version input field and type the desired release. This feature is particularly useful when deploying a WEKA cluster with a customer-specific software release.

<div data-with-frame="true"><figure><img src="/files/agG7I3QyaSA7Pn02oVxW" alt="" width="290"><figcaption><p>WEKA Version</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}

### Dynamic content sidebar

The dynamic content sidebar enhances user experience by displaying contextually relevant information during various activities within CDM. Its primary functions include:

#### Real-time configuration guidance

* **Purpose:** Assists users in understanding the role of specific variables or input fields in the configuration input panel.
* **Functionality:** Automatically displays pertinent information when an input field, such as the Terraform Module Release Version, is selected. This feature covers every input field for AWS, Azure, and GCP configurations.

<div data-with-frame="true"><figure><img src="/files/BUty7ebJOO5i3UK19Qco" alt=""><figcaption><p>Terraform Module Release Version</p></figcaption></figure></div>

#### Real-time file representation

* **Purpose:** Provides a preview of the file that will be generated for download once all configuration inputs are completed.
* **Functionality:** Next to the configuration guidance tab, a new tab labeled “tf file preview” showcases the file in real-time.

#### JSON and HCL format options for main.tf

* **Purpose:** Allows flexibility in file format based on deployment requirements.
* **Functionality:** Includes a toggle switch to change the main.tf file format between JSON and HCL.

#### Download finalized terraform configuration file

* **Purpose:** Enables users to download the completed configuration file for local use.
* **Functionality:** A **Download** button allows you to save the file locally, manually execute the relevant Terraform `plan`, and `apply` commands for WEKA cluster deployment.

<div data-with-frame="true"><figure><img src="/files/qFIl6mJQ77dZfXef5F23" alt=""><figcaption></figcaption></figure></div>

{% hint style="success" %}
All tabs in the workflow navigation panel display green status bubbles with check marks, indicating the configuration is complete and ready for a minimally viable WEKA deployment based on the user's selected parameters. Once all status bubbles are green, the dynamic content sidebar only shows the **TF File Preview** tab, **File Format** toggle, and **Download** button.
{% endhint %}

### Finalize the WEKA deployment

Once you download the CDM-generated Terraform file, manually execute the relevant Terraform commands to deploy their generated WEKA cluster configuration into the cloud of choice.

This means that Terraform, all its dependencies, relevant public cloud CLIs, and SDKs must exist, and the login uses an adequately privileged account before applying the Terraform file.

**Related topics**

[Deployment on AWS using Terraform](/planning-and-installation/aws/deployment-on-aws-using-terraform)

[Deployment on Azure using Terraform](/planning-and-installation/weka-installation-on-azure/deployment-on-azure-using-terraform)

[Deployment on GCP using Terraform](/planning-and-installation/weka-installation-on-gcp/deployment-on-gcp-using-terraform)


# WEKA installation on AWS

This section provides detailed instructions on installing a WEKA system on AWS.

## Overview

WEKA provides a ready-to-deploy Terraform package for installing the WEKA cluster on AWS Virtual Private Cloud (VPC).

The following diagram provides an overview of the various steps automated with the Terraform-driven provisioning of the WEKA cluster backend servers on AWS EC2 instances.

<div data-with-frame="true"><figure><img src="/files/pVEWz3zTpgjUpF9sl6ob" alt=""><figcaption><p>WEKA Terraform module deployment on AWS</p></figcaption></figure></div>

## Workflow description

* **Create AWS Placement Groups:** Create Cluster Placement Groups to reduce network latency between WEKA nodes. This configuration prioritizes performance over resilience and may reduce fault tolerance in the event of hardware failures.
* **Create AWS Launch Template and Auto Scaling Group for WEKA cluster expansion:** Create an AWS Launch Template and Auto Scaling Group to provision EC2 instances for the WEKA cluster.

  The launch template automates the deployment script to install and configure WEKA software during initial cluster creation and expand the cluster with additional instances.
* **Configure AWS Secrets Manager for secure WEKA cluster operations:** Create secrets in AWS Secrets Manager to facilitate secure communication between AWS Lambda functions and the WEKA cluster. This ensures smooth scale-out, scale-in, and auto-healing operations.
* **Configure DynamoDB for Terraform state:** Create state items in an Amazon DynamoDB table to effectively manage Terraform's declarative state.
* **Create CloudWatch log groups for WEKA cluster logs:** Create Amazon CloudWatch log groups to store logs generated by the WEKA cluster.
* **Deploy AWS Lambda functions for WEKA software configuration:** Create AWS Lambda functions to run after CloudWatch log groups are created. These functions assist in installing and configuring WEKA software on EC2 instances.
* **Create AWS Step Function for WEKA cluster scaling:** Create an AWS Step Function state machine to facilitate user-driven automated scale-out and scale-in operations for the WEKA cluster.
* **Create CloudWatch event rule for WEKA cluster monitoring:** Create a CloudWatch event rule to periodically check the state of the WEKA cluster and trigger healing or scaling actions as necessary.

## Before you begin

Ensure you are familiar with the following concepts and services that are used for the WEKA installation on AWS:

<details>

<summary>AWS IAM - Identity and access management</summary>

AWS Identity and Access Management (IAM) is a web service that helps you securely control access to AWS resources. With IAM, you can centrally manage permissions that control which AWS resources users can access. You use IAM to control who is authenticated (signed in) and authorized (has permissions) to use resources.

**Related information**

[What is IAM?](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html)

</details>

<details>

<summary>Amazon VPCs, subnets, and security groups</summary>

A *virtual private cloud* (VPC) is a virtual network dedicated to your AWS account. It is logically isolated from other virtual networks in the AWS Cloud. You can specify an IP address range for the VPC, add subnets and gateways, and associate security groups.

A *subnet* is a range of IP addresses in your VPC. You launch AWS resources, such as Amazon EC2 instances, into your subnets. Using route tables, you can connect a subnet to the internet, other VPCs, and your data centers and route traffic to and from your subnets.

A *security group* controls the traffic that is allowed to reach and leave the resources that it is associated with. For example, after you associate a security group with an EC2 instance, it controls the inbound and outbound traffic for the instance. You can associate a security group only with resources in the VPC for which it is created.

**Related information**

[What is Amazon VPC?](https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html)

[How Amazon VPC works](https://docs.aws.amazon.com/vpc/latest/userguide/how-it-works.html)

[Control traffic to your AWS resources using security groups](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-security-groups.html)

</details>

<details>

<summary>Amazon EC2 instances</summary>

Amazon Elastic Compute Cloud (Amazon EC2) is a web service that provides resizable computing capacity—literally, servers in Amazon's data centers—that you use to build and host your software systems.

Amazon EC2 provides different instance types to choose the CPU, memory, storage, and networking capacity you need to run your applications.

**Related information**

[What is Amazon EC2?](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/concepts.html)

</details>

<details>

<summary>Amazon EC2 key pairs for SSH</summary>

A key pair, consisting of a public key and a private key, is a set of security credentials you use to prove your identity when connecting to an Amazon EC2 instance. Amazon EC2 stores the public key on your instance, and you store the private key. The private key allows you to SSH into your instance securely for Linux instances.

**Related information**

[Amazon EC2 key pairs and Linux instances](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html)

</details>

<details>

<summary>Amazon S3 protocol and object store</summary>

Amazon Simple Storage Service (Amazon S3) is an object storage service that offers industry-leading scalability, data availability, security, and performance. It is used for tiering data from the WEKA cluster to Amazon object store buckets.

**Related information**

[What is Amazon S3?](https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html)

</details>

<details>

<summary>Terraform</summary>

Terraform is an open-source project from HashiCorp. It creates and manages resources on cloud platforms and on-premises environments. It interacts with numerous APIs from multiple platforms and services, providing a unified workflow for infrastructure management.

<img src="/files/wN5LMlxfVkG12fYKxT00" alt="" data-size="original">

**How does Terraform work?**

A deployment with Terraform involves three phases:

* **Write:** Define the infrastructure in configuration files and customize the project variables provided in the Terraform package.
* **Plan:** Review the changes Terraform will make to your infrastructure.
* **Apply:** Terraform provisions the infrastructure, including the EC2 instances, installs the WEKA software, and creates the cluster. Once completed, the WEKA cluster runs on AWS.

<img src="/files/QzY95rUxPdVcqa0RpRtK" alt="" data-size="original">

**Related information**

[Get Started with Terraform on AWS](https://developer.hashicorp.com/terraform/tutorials/aws-get-started)

</details>

To install WEKA on AWS, an AWS account is required. Visit the AWS site to create an [AWS account](https://aws.amazon.com/account/).


# Terraform-AWS-WEKA module description

The [Terraform-AWS-WEKA](https://registry.terraform.io/modules/weka/weka/aws/latest?tab=inputs) module is an open-source repository. It contains modules to customize the WEKA cluster installation on AWS. The default protocol deployed using the module is POSIX.

The Terraform-AWS-WEKA module supports public and private cloud deployments. All deployment types require passing the `get.weka.io` token to Terraform to download the WEKA release from the public [get.weka.io](https://get.weka.io) service.

{% hint style="info" %}
The WEKA release can only be downloaded over the internet if the private cloud network has NAT Gateway associated.
{% endhint %}

## Terraform-AWS-WEKA module components

The Terraform-AWS-WEKA module consists of the following components:

* **Required module:**
  * WEKA Root Module is located in the main Terraform module.
* **Optional sub-modules:**
  * **protocol\_gateways:** Enables creating dedicated WEKA Frontend servers for protocol access (NFS, SMB, or SMB-W).
  * **clients:** Enables creating stateless WEKA clients that automatically join the WEKA cluster during cluster creation. The WEKA clients host applications or workloads.
  * **endpoints:** Creates private network VPC endpoints, including EC2 VPC endpoints, S3 gateway, Lambda VPC endpoint, WEKA proxy VPC endpoint, and a security group to open port 1080 for the WEKA proxy VPC endpoint.
  * **IAM:** Creates IAM roles for EC2 instances, CloudWatch events, WEKA Lambda functions, and Step Function. IAM roles can be created in advance, or if module variables are unspecified, WEKA automatically creates them.
  * **network:** Creates VPC, Internet Gateway/NAT, public/private subnets, and so on if pre-existing network variables are not supplied in advance.
  * **security\_group:** Automatically creates the required security group if not provided in advance.

### Terraform-AWS-WEKA example

The following is a basic example in which you provide the minimum detail of your cluster, and the Terraform module completes the remaining required resources, such as VPC, subnets, security group, placement group, DNS zone, and IAM roles.

You can use this example as a reference to create the `main.tf` file.

```hcl
terraform {
  required_version = ">= 1.4.6"
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = ">= 5.5.0"
    }
  }
}

provider "aws" {
}

module "weka_deployment" {
  source             = "weka/weka/aws"
  version            = "1.0.1"  
  prefix             = "weka-tf"
  cluster_name       = "poc"
  availability_zones = ["eu-west-1c"]
  allow_ssh_cidrs    = ["0.0.0.0/0"]
  get_weka_io_token  = "Your get.weka.io token"
}

output "weka_deployment_output" {
  value = module.weka_deployment
}
```

{% hint style="info" %}
For the parameters' descriptions, refer to the [terraform-aws-weka](https://registry.terraform.io/modules/weka/weka/aws/latest?tab=inputs) module.
{% endhint %}


# Deployment on AWS using Terraform

## Create a main.tf file

The main Terraform configuration settings are included in the `main.tf` file. You can create it by following this procedure or using the WEKA Cloud Deployment Manager. See [Cloud Deployment Manager Web (CDM Web) User Guide](/planning-and-installation/weka-cdm-web-user-guide).

#### Before you begin

The [Terraform](https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli) must be installed on the workstation used for the deployment. Check the minimum required Terraform version specified in the [**Requirements**](https://registry.terraform.io/modules/weka/weka/aws/latest#requirements) section of the Terraform-AWS-WEKA module.

#### Procedure

1. Review the [Terraform-AWS-WEKA example](https://registry.terraform.io/modules/weka/weka/aws/latest/examples/public_network) and use it as a reference for creating the `main.tf` according to your deployment specifics on AWS.
2. Tailor the `main.tf` file to create SMB-W or NFS protocol clusters by adding the relevant code snippet. Adjust parameters like the number of gateways, instance types, domain name, and share naming:

* **SMB-W**

```makefile
smb_protocol_gateways_number = 3
smb_protocol_gateway_instance_type = "c5.2xlarge" 
smbw_enabled = true
smb_domain_name = "CUSTOMER_DOMAIN"
smb_share_name = "SPECIFY_SMB_SHARE_NAMING"
smb_setup_protocol = true
```

* **NFS**

```makefile
nfs_protocol_gateways_number = 1
nfs_protocol_gateway_instance_type = "c5.2xlarge"
nfs_setup_protocol = true
```

4. Add WEKA POSIX clients (optional)**:** If needed, add [WEKA POSIX clients](/weka-system-overview/weka-client-and-mount-modes) to support your workload by incorporating the specified variables into the `main.tf` file:

```makefile
clients_number = 2
client_instance_type = "c5.2xlarge"
```

## Apply the main.tf file

Once you complete the main.tf settings, apply it: Run `terraform apply`

{% hint style="info" %}
**Note:** Terraform creates a second password specifically for lambda functions, eliminating the need to create your own password.
{% endhint %}

## Set the license

To run IOs against the cluster, a valid license must be applied. Obtain a valid license and apply it to the WEKA cluster. For details, see [Licensing overview](/licensing/overview).

**Related topic**

[Manage users using the GUI](/operation-guide/user-management/user-management)


# Required services and supported regions

## Required services

The AWS region must support the following services used in WEKA on AWS.

* AWS EC2 Instances
* AWS Lambda
* AWS Step Functions
* AWS CloudWatch event rule
* AWS S3 (required for snap/tiering to object)

## Supported regions

| Code           | Name                      |
| -------------- | ------------------------- |
| us-east-1      | US East (N. Virginia)     |
| us-east-2      | US East (Ohio)            |
| us-west-1      | US West (N. California)   |
| us-west-2      | US West (Oregon)          |
| ap-south-1     | Asia Pacific (Mumbai)     |
| ap-northeast-1 | Asia Pacific (Tokyo)      |
| ap-northeast-2 | Asia Pacific (Seoul)      |
| ap-southeast-1 | Asia Pacific (Singapore)  |
| ap-southeast-2 | Asia Pacific (Sydney)     |
| ca-central-1   | Canada (Central)          |
| eu-central-1   | Europe (Frankfurt)        |
| eu-north-1     | Europe (Stockholm)        |
| eu-west-1      | Europe (Ireland)          |
| eu-west-2      | Europe (London)           |
| sa-east-1      | South America (São Paulo) |

**Related topic**

[Supported EC2 instance types using Terraform](/planning-and-installation/aws/supported-ec2-instance-types)

**Related information**

[Regions and Zones](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html#concepts-regions)


# Supported EC2 instance types using Terraform

## Backend EC2 instances

The following EC2 instance models can operate as **backend**, **client,** or **converged** instances. The default EC2 instance model for backends is **i3en.2xlarge**.

<table><thead><tr><th width="237">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>i8ge</td><td>i8ge.2xlarge, i8ge.3xlarge, i8ge.6xlarge, i8ge.12xlarge, i8ge.18xlarge, i8ge.24xlarge, i8ge.48xlarge</td></tr><tr><td>I3en</td><td>i3en.2xlarge, i3en.3xlarge, i3en.6xlarge, i3en.12xlarge, i3en.24xlarge</td></tr></tbody></table>

{% hint style="info" %}
Deployment on **i8ge** instance types are supported with Posix and S3 protocol.
{% endhint %}

## Client EC2 instances

The following EC2 instance models can operate as **client** instances. The default EC2 instance model for clients is **c5.2xlarge**.

{% hint style="info" %}

* Support for WEKA client over UDP mode is extended to any Intel or AMD CPU-based instance type, provided that the VM type meets the resource requirements specified in the [Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility) topic.
* Any backend instance can also be a client instance.
  {% endhint %}

### General purpose <a href="#general_purpose" id="general_purpose"></a>

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>M5</td><td>m5.xlarge, m5.2xlarge, m5.4xlarge, m5.8xlarge, m5.12xlarge, m5.16xlarge, m5.24xlarge</td></tr><tr><td>M5n</td><td>m5n.xlarge, m5n.2xlarge, m5n.4xlarge, m5n.8xlarge, m5n.12xlarge, m5n.16xlarge, m5n.24xlarge, m5dn.xlarge, m5dn.2xlarge, m5dn.4xlarge, m5dn.8xlarge, m5dn.12xlarge, m5dn.16xlarge, m5dn.24xlarge</td></tr><tr><td>M6a</td><td>m6a.xlarge, m6a.2xlarge, m6a.4xlarge, m6a.8xlarge, m6a.12xlarge, m6a.16xlarge, m6a24xlarge, m6a.32xlarge, m6a.48xlarge</td></tr><tr><td>M6g</td><td>m6g.xlarge, m6g.2xlarge, m6g.4xlarge, m6g.8xlarge, m6g.12xlarge, m6g.16xlarge</td></tr><tr><td>M6gd</td><td>m6gd.xlarge, m6gd.2xlarge, m6gd.4xlarge, m6gd.8xlarge, 1m6gd.2xlarge, m6gd.16xlarge</td></tr><tr><td>M6i</td><td>m6i.xlarge, m6i.2xlarge, m6i.4xlarge, m6i.8xlarge, m6i.12xlarge, m6i.16xlarge, m6i.24xlarge, m6i.32xlarge</td></tr><tr><td>M6id</td><td>m6id.xlarge, m6id.2xlarge, m6id.4xlarge, m6id.8xlarge, m6id.12xlarge, m6id.16xlarge, m6id.24xlarge, m6id.32xlarge</td></tr><tr><td>M6idn</td><td>m6idn.xlarge, m6idn.2xlarge, m6idn.4xlarge, m6idn.8xlarge, m6idn.12xlarge, m6idn.16xlarge, m6idn.24xlarge, m6idn.32xlarge</td></tr><tr><td>M6in</td><td>m6in.xlarge , m6in.2xlarge , m6in.4xlarge , m6in.8xlarge, m6in.12xlarge , m6in.16xlarge , m6in.24xlarge</td></tr><tr><td>M7a</td><td>m7a.xlarge , m7a.2xlarge, m7a.4xlarge, m7a.8xlarge, m7a.12xlarge, m7a.16xlarge, m7a.24xlarge, m7a.32xlarge, m7a.48xlarge</td></tr><tr><td>M7i</td><td>m7i.xlarge, m7i.2xlarge, m7i.4xlarge, m7i.8xlarge, m7i.12xlarge, m7i.16xlarge, m7i.24xlarge, m7i.48xlarge</td></tr><tr><td>M7g</td><td>m7g.xlarge, m7g.2xlarge, m7g.4xlarge, m7g.8xlarge, m7g.12xlarge, m7g.16xlarge</td></tr><tr><td>M7gd</td><td>m7gd.xlarge, m7gd.2xlarge, m7gd.4xlarge, m7gd.8xlarge, m7gd.12xlarge, m7gd.16xlarge</td></tr></tbody></table>

### Compute optimized <a href="#compute_optimized" id="compute_optimized"></a>

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>C5</td><td>c5.2xlarge, c5.4xlarge, c5.9xlarge, c5.12xlarge, c5.18xlarge, c5.24xlarge</td></tr><tr><td>C5a</td><td>c5a.2xlarge , c5a.4xlarge, c5a.8xlarge, c5a.12xlarge, c5a.16xlarge, c5a.24xlarge</td></tr><tr><td>C5ad</td><td>c5ad.2xlarge , c5ad.4xlarge, c5ad.8xlarge, c5ad.12xlarge, c5ad.16xlarge, c5ad.24xlarge</td></tr><tr><td>C5n</td><td>c5n.2xlarge, c5n.4xlarge, c5n.9xlarge, c5n.18xlarge</td></tr><tr><td>C6a</td><td>c6a.2xlarge, c6a.4xlarge, c6a.8xlarge, c6a.12xlarge, c6a.16xlarge, c6a.32xlarge, c6a.48xlarge</td></tr><tr><td>C6g</td><td>c6g.2xlarge, c6g.4xlarge, c6g.8xlarge, c6g.12xlarge, c6g.16xlarge</td></tr><tr><td>C6gd</td><td>c6gd.2xlarge, c6gd.4xlarge, c6gd.8xlarge, c6gd.12xlarge, c6gd.16xlarge</td></tr><tr><td>C6gn</td><td>c6gn.2xlarge, c6gn.4xlarge, c6gn.8xlarge, c6gn.12xlarge, c6gn.16xlarge</td></tr><tr><td>C6in</td><td>c6in.2xlarge, c6in.4xlarge, c6in.8xlarge, c6in.12xlarge, c6in.16xlarge, c6in.24xlarge, c6in.32xlarge</td></tr><tr><td>C7a</td><td>c7a.2xlarge, c7a.4xlarge, c7a.8xlarge, c7a.12xlarge, c7a.16xlarge, c7a.24xlarge, c7a.32xlarge, c7a.48xlarge</td></tr><tr><td>C7g</td><td>c7g.2xlarge, c7g.4xlarge, c7g.8xlarge, c7g.12xlarge, c7g.16xlarge</td></tr><tr><td>C7gd</td><td>c7gd.2xlarge, c7gd.4xlarge, c7gd.8xlarge, c7gd.12xlarge, c7gd.16xlarge</td></tr><tr><td>C7i</td><td>c7i.2xlarge, c7i.4xlarge, c7i.8xlarge, c7i.12xlarge, c7i.16xlarge, c7i.24xlarge, cC7i.48xlarge</td></tr></tbody></table>

### Memory optimized <a href="#memory_optimized" id="memory_optimized"></a>

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>R5</td><td>r5.xlarge, r5.2xlarge, r5.4xlarge, r5.8xlarge, r5.12xlarge, r5.16xlarge, r5.24xlarge</td></tr><tr><td>R5n</td><td>r5n.xlarge, r5n.2xlarge, r5n.4xlarge, r5n.8xlarge, r5n.12xlarge, r5n.16xlarge, r5n.24xlarge</td></tr><tr><td>R6a</td><td>r6a.xlarge, r6a.2xlarge, r6a.4xlarge, r6a.8xlarge, r6a.12xlarge, r6a.16xlarge, r6a.32xlarge, r6a.48xlarge</td></tr><tr><td>R6i</td><td>r6i.xlarge, r6i.2xlarge, r6i.4xlarge, r6i.8xlarge, r6i.12xlarge, r6i.16xlarge, r6i.24xlarge, r6i.32xlarge</td></tr><tr><td>R6id</td><td>r6id.xlarge, r6id.2xlarge, r6id.4xlarge, r6id.8xlarge, r6id.12xlarge, r6id.16xlarge, r6id.24xlarge, r6id.32xlarge</td></tr><tr><td>R6idn</td><td>r6idn.xlarge, r6idn.2xlarge, r6idn.4xlarge, r6idn.8xlarge, r6idn.12xlarge, r6idn.16xlarge, r6idn.24xlarge, r6idn.32xlarge</td></tr><tr><td>R6in</td><td>r6in.xlarge, r6in.2xlarge, r6in.4xlarge, r6in.8xlarge, r6in.12xlarge, r6in.16xlarge, r6in.24xlarge, r6in.32xlarge</td></tr><tr><td>R6g</td><td>r6g.xlarge, r6g.2xlarge, r6g.4xlarge, r6g.8xlarge, r6g.12xlarge, r6g.16xlarge</td></tr><tr><td>R6gd</td><td>r6gd.xlarge, r6gd.2xlarge, r6gd.4xlarge, r6gd.8xlarge, r6gd.12xlarge, r6gd.16xlarge</td></tr><tr><td>R7a</td><td>r7a.xlarge, r7a.2xlarge, r7a.4xlarge, r7a.8xlarge, r7a.12xlarge, r7a.16xlarge, r7a.24xlarge, r7a.32xlarge, r7a.48xlarge</td></tr><tr><td>R7iz</td><td>r7iz.xlarge, r7iz.2xlarge, r7iz.4xlarge, r7iz.8xlarge, r7iz.12xlarge, r7iz.16xlarge, r7iz.32xlarge</td></tr><tr><td>R7g</td><td>r7g.xlarge, r7g.2xlarge, r7g.4xlarge, r7g.8xlarge, r7g.12xlarge, r7g.16xlarge</td></tr><tr><td>R7gd</td><td>r7gd.xlarge, r7gd.2xlarge, r7gd.4xlarge, r7gd.8xlarge, r7gd.12xlarge, r7gd.16xlarge</td></tr><tr><td>X1</td><td>x1.16xlarge, x1.32xlarge</td></tr><tr><td>X1e</td><td>x1e.16xlarge, x1e.32xlarge</td></tr><tr><td>X2idn</td><td>x2idn.16xlarge, x2idn.24xlarge, x2idn.32xlarge</td></tr><tr><td>X2iedn</td><td>x2iedn.xlarge, x2iedn.2xlarge, x2iedn.4xlarge, x2iedn.8xlarge, x2iedn.16xlarge, x2iedn.24xlarge</td></tr><tr><td>Z1d</td><td>z1d.xlarge, z1d.2xlarge, z1d.3xlarge, z1d.6xlarge, z1d.12xlarge</td></tr></tbody></table>

### Accelerated computing <a href="#accelerated_computing" id="accelerated_computing"></a>

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>F1</td><td>f1.2xlarge, f1.4xlarge, f1.16xlarge</td></tr><tr><td>G3</td><td>g3.4xlarge, g3.8xlarge, g3.16xlarge</td></tr><tr><td>G4dn</td><td>g4dn.2xlarge, g4dn.4xlarge, g4dn.8xlarge, g4dn.12xlarge, g4dn.16xlarge</td></tr><tr><td>G5</td><td>g5.xlarge, g5.2xlarge, g5.4xlarge, g5.8xlarge, g5.12xlarge, g5.16xlarge</td></tr><tr><td>G5g</td><td>g5g.2xlarge, g5g.4xlarge, g5g.8xlarge, g5g.16xlarge</td></tr><tr><td>G6</td><td>g6.xlarge, g6.2xlarge, g6.4xlarge, g6.8xlarge, g6.12xlarge, g6.16xlarge, g6.24xlarge, g6.48xlarge</td></tr><tr><td>GR6</td><td>gr6.4xlarge, gr6.8xlarge</td></tr><tr><td>Inf1</td><td>inf1.2xlarge, inf1.6xlarge, inf1.24xlarge</td></tr><tr><td>Inf2</td><td>inf2.xlarge, inf2.8xlarge, inf2.24xlarge, inf2.48xlarge</td></tr><tr><td>P2</td><td>p2.xlarge, p2.8xlarge, p2.16xlarge</td></tr><tr><td>P3</td><td>p3.2xlarge, p3.8xlarge, p3.16xlarge</td></tr><tr><td>P4</td><td>p4d.24xlarge, p4de.24xlarge</td></tr><tr><td>P5</td><td>p5.48xlarge</td></tr><tr><td>Trn1</td><td>trn1.2xlarge, trn1.32xlarge , trn1n.32xlarge</td></tr></tbody></table>

### Storage optimized

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>I3en</td><td>i3en.xlarge, i3en.2xlarge, i3en.3xlarge, i3en.6xlarge, i3en.12xlarge, i3en.24xlarge</td></tr></tbody></table>

### HPC optimized <a href="#hpc_optimized" id="hpc_optimized"></a>

<table><thead><tr><th width="235">EC2 instance type</th><th>Supported instances</th></tr></thead><tbody><tr><td>HPc6</td><td>hpc6.48xlarge</td></tr><tr><td>HPc6a</td><td>hpc6a.48xlarge</td></tr><tr><td>HPc7a</td><td>hpc7a.12xlarge, hpc7a.48xlarge, hpc7a.96xlarge</td></tr></tbody></table>

**Related information**

[AWS instance types](https://aws.amazon.com/ec2/instance-types/)


# WEKA cluster auto-scaling in AWS

## Scale-out the WEKA cluster backend servers

Scale-out is the process of increasing the number of EC2 instances in the system to handle higher workloads or enhance redundancy.

Scale-out is essential to ensure a system can meet growing demands, maintain performance, and distribute workloads effectively. This proactive approach helps prevent overloads, reduce response times, and maintain high availability.

**Action**

* Increase the desired size of the Auto-Scaling Group (ASG) associated with your WEKA cluster. You can do this through the AWS Console or AWS CLI.

**Result**

* AWS automatically launches the new EC2 instance.
* AWS triggers the Lambda Function to create a `join` script that runs once as part of the instance user data and, subsequently, integrates the new EC2 instance into the existing WEKA cluster.

You can monitor the process in the AWS Step Function GUI.

## Scale-in the WEKA cluster backend servers

Scale-in is the process of reducing the number of EC2 instances of a system to align with decreased workloads or to optimize resource utilization.

Scale-in is essential for efficient resource management, cost reduction, and ensuring the appropriate allocation of resources. It helps prevent over-provisioning, lowers operational expenses, and safeguards against unintentional removal of EC2 instances from the existing WEKA cluster in AWS.

The cluster is configured with scale-in protection and instance termination protection to enhance the safety of this process.

**Action**

* Decrease the desired size of the Auto-Scaling Group (ASG) associated with your WEKA cluster. You can do this through the AWS Console, AWS CLI, or other compatible methods.

**Result**

* After modifying the desired size, it doesn't immediately impact the Auto Scaling Group (ASG). Instead, a Step Function continuously monitors the configuration.
* This Step Function runs every minute and identifies that the desired size is less than the current WEKA system's size.
* When this condition is met, it initiates a scale-in process, but only if certain conditions are met, such as having enough capacity on the filesystem.
* If the scale-down is successful, the Step Function subsequently removes the protection from the scaled-in instance, thereby allowing the Auto Scaling Group to proceed with removing it.


# Detailed deployment tutorial: WEKA on AWS using Terraform

## Introduction

Deploying WEKA in AWS requires knowledge of several technologies, including AWS, Terraform[^1], basic Linux operations, and the WEKA software. Recognizing that not all individuals responsible for this deployment are experts in each of these areas, this document aims to provide comprehensive, end-to-end instructions. This ensures that readers with minimal prior knowledge can successfully deploy a functional WEKA cluster on AWS.

#### Document scope

This document provides a guide for deploying WEKA in an AWS environment using Terraform. It is applicable for both POC and production setups. While no pre-existing AWS elements are required beyond an appropriate user account, the guide includes examples with some pre-created resources.

This document guides you through:

* General AWS requirements.
* Networking requirements to support WEKA.
* Deployment of WEKA using Terraform.
* Verification of a successful WEKA deployment.

{% hint style="info" %}
Images embedded in this document can be enlarged with a single click for ease of viewing and a clearer and more detailed examination.
{% endhint %}

## Terraform preparation and installation

HashiCorp Terraform is a tool that enables you to define, provision, and manage infrastructure as code. It simplifies infrastructure setup by using a configuration file instead of manual processes.

You describe your desired infrastructure in a configuration file using HashiCorp Configuration Language (HCL) or optionally JSON. Terraform then automates the creation, modification, or deletion of resources.

This automation ensures that your infrastructure is consistently and predictably deployed, aligning with the specifications in your configuration file. Terraform helps maintain a reliable and repeatable infrastructure environment.

Organizations worldwide use Terraform to deploy stateful infrastructure both on-premises and across public clouds like AWS, Azure, and Google Cloud Platform.

To install Terraform, we recommend following the [official installation guides](https://developer.hashicorp.com/terraform/install) provided by HashiCorp.

### Locate the AWS Account

1. Access the AWS Management Consol&#x65;**.**
2. In the top-right corner, search for **Account ID**.

<div data-with-frame="true"><figure><img src="/files/kI4phPX3JRqH2cFPQWlI" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}

* If deploying into a WEKA customer environment, ensure the customer understands their subscription structure.
* If deploying internally at WEKA and you don't see the Account ID or haven't been added to the correct account, contact the appropriate cloud team for assistance.
  {% endhint %}

### Confirm user account permissions

To ensure a successful WEKA deployment in AWS using Terraform, verify that the [AWS IAM user](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users.html) has the required permissions listed in [#appendix-b-terraforms-required-permissions](#appendix-b-terraforms-required-permissions "mention"). The user must have permissions to create, modify, and delete AWS resources as specified by the Terraform configuration files.

If the IAM user lacks these permissions, update their permissions or create a new IAM user with the necessary permissions.

**Procedure**

1. **Access the AWS Management Console:** Log in using the account intended for the WEKA deployment.
2. **Navigate to the IAM dashboard:** From the Services menu, select **IAM** to open the Identity and Access Management dashboard.

<div data-with-frame="true"><figure><img src="/files/3iBixVJV4vk5wkcOqHCa" alt=""><figcaption></figcaption></figure></div>

3. **Locate the IAM user:** Search for the IAM user or go to the **Users** section.

<div data-with-frame="true"><figure><img src="/files/yFmnMvcRzasKRUmjUzpH" alt=""><figcaption></figcaption></figure></div>

4. **Verify permissions.** Click on the user’s name to review their permissions. Ensure they have policies that grant the necessary permissions for managing AWS resources through Terraform.

<div data-with-frame="true"><figure><img src="/files/0L72ywqldidsgY1aF5zf" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
The user shown in the screenshot above has full administrative access to allow Terraform to deploy WEKA. However, it is recommended to follow the [principle of least privilege](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege) by granting only the necessary permissions listed in [#appendix-b-terraforms-required-permissions](#appendix-b-terraforms-required-permissions "mention").
{% endhint %}

### Set AWS Service Quotas

Before deploying WEKA on AWS using Terraform, ensure your AWS account has sufficient quotas for the necessary resources. Specifically, when deploying EC2 instances like the i3en for the WEKA backend cluster, manage quotas based on the vCPU count for each instance type or family.

**Requirements:**

* **EC2 Instance vCPU quotas:** Verify that your vCPU requirements are within your current quota limits. If not, adjust the quotas before running the Terraform commands (details are provided later in this document).
* **Cumulative vCPU count:** Ensure your quotas cover the total vCPU count needed for all instances. For example, deploying 10 i3en.6xlarge instances (each with 24 vCPUs) requires 240 vCPUs in total. Meeting these quotas is essential to avoid execution failures during the Terraform process, as detailed in the following sections.

**Procedure**

1. **Access Service Quotas:** Open the AWS Management Console at [AWS Service Quotas](https://us-east-1.console.aws.amazon.com/servicequotas/home/dashboard). Use the search bar to locate the **Service Quotas** service.

<div data-with-frame="true"><figure><img src="/files/E2UawBzRB2wnXWS1H6dz" alt=""><figcaption></figcaption></figure></div>

2. **Select Amazon EC2:** On the Service Quotas page, select **Amazon EC2**.

<div data-with-frame="true"><figure><img src="/files/gLLKxObDqn4OlLz2db8U" alt=""><figcaption></figcaption></figure></div>

3. **Identify instance type:** WEKA supports only i3en instance types for backend cluster nodes. Ensure you adjust the quota for the appropriate instance type (Spot, On-Demand, or Dedicated).

<div data-with-frame="true"><figure><img src="/files/gmmcSW5Z7jN3GRJZve3V" alt=""><figcaption></figcaption></figure></div>

4. **Request quota increase:** Choose the relevant instance type from the Standard categories (A, C, D, H, I, M, R, T, Z), then click **Request increase at account-level**.

<div data-with-frame="true"><figure><img src="/files/xOAVJovVW0kdR22kLBX8" alt=""><figcaption></figcaption></figure></div>

5. **Specify number of vCPUs:** In the Request quota increase form, specify the number of vCPUs you need. For example, if 150 vCPUs are required for the i3en instance family, enter this number and submit your request.

{% hint style="info" %}
Quota increase requests are typically processed immediately. However, requests for a large number of vCPUs or specialized instance types may require manual review by AWS support.\
Confirm that you have requested and obtained the necessary quotas for all instance types used for WEKA backend servers and any associated application servers running WEKA client software. WEKA supports i3en series instances for backend servers.
{% endhint %}

**Related topic**

[Supported EC2 instance types using Terraform](/planning-and-installation/aws/supported-ec2-instance-types)

## AWS resource prerequisites

The WEKA deployment requires several AWS components, including VPCs, Subnets, Security Groups, and Endpoints. These components can either be created during the Terraform process or be pre-existing if manually configured.

Minimum requirements:

* A Virtual Private Cloud (VPC)
* Two Subnets in different Availability Zones (AZs)
* A Security Group

### Networking requirements

If you choose not to have Terraform auto-create networking components, ensure your VPC configuration includes:

* Two subnets (either private or public) in separate AZs.
* A subnet that allows WEKA to access the internet, either through an Internet Gateway (IGW) with an Elastic IP (EIP), NAT gateway, proxy, or egress VPC.

Although the WEKA deployment is not multi-AZ, a minimum of two subnets in different AZs is required for the Application Load Balancer (ALB).

### **View AWS Network Access Control Lists (ACLs)**

AWS Network Access Control Lists (ACLs) enable basic firewalls that control inbound and outbound network traffic based on security rules. They apply to network interfaces (NICs), EC2 instances, and subnets.

By default, ACLs include rules that ensure basic connectivity, such as allowing outbound communication from all AWS resources and denying all inbound traffic from the internet. These default rules have high priority numbers, so custom rules can override them. The security groups created by `main.tf` handle most traffic restrictions and allowances.

**Procedure**

1. Go to the VPC details page and select **Main network AC**L.

<div data-with-frame="true"><figure><img src="/files/hEUCJ5GxhuF7UbjsKAmF" alt=""><figcaption></figcaption></figure></div>

2. From the Network ACLs page, select the **Inbound rules** and **Outbound rules**.

{% tabs %}
{% tab title="Inbound rules" %}

<div data-with-frame="true"><figure><img src="/files/o89Cy8074Qr4H1jjPJ6L" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="Outbound rules" %}

<div data-with-frame="true"><figure><img src="/files/EblxZAnllMHMrwzy3vmE" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}

**Related topic**

[#appendix-a-security-groups-network-acl-ports](#appendix-a-security-groups-network-acl-ports "mention") (ensure you have defined all the relevant ports before manually creating ACLs ).

## Deploy WEKA on AWS using Terraform

If using existing resources, collect their AWS IDs as shown in the following examples:

{% tabs %}
{% tab title="VPC" %}

<div data-with-frame="true"><figure><img src="/files/jhAbeP1gKb0tXhEe5V1l" alt=""><figcaption><p>VPC</p></figcaption></figure></div>
{% endtab %}

{% tab title="Subnet in VPC" %}

<div data-with-frame="true"><figure><img src="/files/NVk2CyLHe21OTQGMGefc" alt=""><figcaption><p>Subnet in VPC</p></figcaption></figure></div>
{% endtab %}

{% tab title="Security Group in EC2" %}

<div data-with-frame="true"><figure><img src="/files/WWB2VUqhFDwEzcBvAhfV" alt=""><figcaption><p>Security Group in EC2</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}

### Modules overview

This section covers modules for creating IAM roles, networks, and security groups necessary for WEKA deployment. If you do not provide specific IDs for security groups or subnets, the modules automatically create them.

#### **Network configuration**

* **Availability zones:** The `availability_zones` variable is required when creating a network and is currently limited to a single subnet. If no specific subnet is provided, it is automatically created.
* **Private network deployment:** To deploy a private network with NAT, set the `subnet_autocreate_as_private` variable to `true` and provide a private CIDR range. To prevent instances from receiving public IPs, set `assign_public_ip` to `false`.

#### **SSH access**

For SSH access, use the username `ec2-user`. You can either:

* Provide an existing key pair name, or
* Provide a public SSH key.

If neither is provided, the system creates a key pair and store the private key locally.

#### **Application Load Balancer (ALB)**

To create an ALB for backend UI and WEKA client connections:

* Set `create_alb` to `true`.
* Provide additional required variables.
* To integrate ALB DNS with your DNS zone, provide variables for the Route 53 zone ID and alias name.

#### **Object Storage (OBS)**

For S3 integration for tiered storage:

* Set `tiering_enable_obs_integration` to `true`.
* Provide the name of the S3 bucket.
* Optionally, specify the SSD cache percentage.

#### **Optional configurations**

* **Clients:** For automatically mounting clients to the WEKA cluster, specify the number of clients to create. Optional variables include instance type, number of network interfaces (NICs), and AMI ID.
* **NFS protocol gateways:** Specify the number of NFS protocol gateways required. Additional configurations include instance type and disk size.
* **SMB protocol gateways:** Create at least three SMB protocol gateways. Configuration options are similar to NFS gateways.

#### **Secret Manager**

Use the Secret Manager to store sensitive information, such as usernames and passwords. If you do not provide a secret manager endpoint, disable it by setting `secretmanager_use_vpc_endpoint` to `false`.

#### **VPC Endpoints**

Enable VPC endpoints for services like EC2, S3, or a proxy by setting the respective variables to `true`.

#### **Terraform output**

The Terraform module output includes:

* SSH username.
* WEKA password secret ID.
* Helper commands for learning about the clusterization process.

### Locate the user’s token on get.weka.io

The WEKA user token grants access to WEKA binaries and is required for accessing <https://get.weka.io> during installation.

**Procedure**

1. Open a web browser and navigate to [get.weka.io](https://get.weka.io).
2. In the upper right-hand corner, click the user’s name.
3. From the left-hand menu, select **API Tokens**.
4. The user’s API token displays on the screen. Use this token later in the installation process.

### Deploy WEKA in AWS with Terraform

The Terraform module facilitates the deployment of various AWS resources, including EC2 instances, DynamoDB tables, Lambda functions, and State Machines, to support WEKA deployment.

#### Procedure

1. Create a directory for the Terraform configuration files.

```bash
mkdir deploy
```

{% hint style="info" %}
All Terraform deployments must be separated into their own directories to manage state information effectively. By creating a specific directory for this deployment, you can duplicate these instructions for future deployments by naming the directory uniquely, such as `deploy1`.
{% endhint %}

2. Navigate to the directory.

```bash
cd deploy
```

3. Create the `main.tf` file.\
   The `main.tf` file defines the Terraform options. Create this file using the WEKA Cloud Deployment Manager (CDM). See [Cloud Deployment Manager Web (CDM Web) User Guide](/planning-and-installation/weka-cdm-web-user-guide) for assistance.
4. Authenticate the AWS CLI.

```bash
aws configure
```

* Fill in the required information and press **Enter**.

<div data-with-frame="true"><figure><img src="/files/9msmfzOei1MmXE3awYBA" alt="" width="563"><figcaption></figcaption></figure></div>

5. After creating and saving the `main.tf` file, initialize the Terraform directory to ensure the proper AWS resource files are available.

```json
terraform init
```

7. As a best practice, run the terraform plan to preview the changes.

```json
terraform plan
```

8. Execute the creation of AWS resources necessary to run WEKA.

```json
terraform apply
```

9. When prompt, type `yes` to confirm the deployment.

**Deployment output**

Upon successful completion, Terraform displays output similar to the following. If the deployment fails, an error message appears.

```json
Outputs:

weka_deployment = {
  "alb_alias_record" = null
  "alb_dns_name" = "internal-WEKA-Prod-lb-697001983.us-east-1.elb.amazonaws.com"
  "asg_name" = "WEKA-Prod-autoscaling-group"
  "client_ips" = null
  "cluster_helper_commands" = <<-EOT
  aws ec2 describe-instances --instance-ids $(aws autoscaling describe-auto-scaling-groups --auto-scaling-group-name WEKA-Prod-autoscaling-group --query "AutoScalingGroups[].Instances[].InstanceId" --output text) --query 'Reservations[].Instances[].PublicIpAddress' --output json
  aws lambda invoke --function-name WEKA-Prod-status-lambda --payload '{"type": "progress"}' --cli-binary-format raw-in-base64-out /dev/stdout
  aws secretsmanager get-secret-value --secret-id arn:aws:secretsmanager:us-east-1:459693375476:secret:weka/WEKA-Prod/weka-password-g9bH-T2og7D --query SecretString --output text
  
  EOT
  "cluster_name" = "Prod"
  "ips_type" = "PublicIpAddress"
  "lambda_status_name" = "WEKA-Prod-status-lambda"
  "local_ssh_private_key" = "/tmp/WEKA-Prod-private-key.pem"
  "nfs_protocol_gateways_ips" = tostring(null)
  "smb_protocol_gateways_ips" = tostring(null)
  "ssh_user" = "ec2-user"
  "weka_cluster_password_secret_id" = "arn:aws:secretsmanager:us-east-1:459693375476:secret:weka/WEKA-Prod/weka-password-g9bH-T2og7D"
}
weka_deployment_output = {
  "alb_alias_record" = null
  **"alb_dns_name" = "internal-WEKA-Prod-lb-697001983.us-east-1.elb.amazonaws.com"**
  "asg_name" = "WEKA-Prod-autoscaling-group"
  "client_ips" = null
  "cluster_helper_commands" = <<-EOT
  **aws ec2 describe-instances --instance-ids $(aws autoscaling describe-auto-scaling-groups --auto-scaling-group-name WEKA-Prod-autoscaling-group --query "AutoScalingGroups[].Instances[].InstanceId" --output text) --query 'Reservations[].Instances[].PublicIpAddress' --output json
  aws lambda invoke --function-name WEKA-Prod-status-lambda --payload '{"type": "progress"}' --cli-binary-format raw-in-base64-out /dev/stdout
  aws secretsmanager get-secret-value --secret-id arn:aws:secretsmanager:us-east-1:459693375476:secret:weka/WEKA-Prod/weka-password-g9bH-T2og7D --query SecretString --output text**
  
  EOT
  "cluster_name" = "Prod"
  "ips_type" = "PublicIpAddress"
  "lambda_status_name" = "WEKA-Prod-status-lambda"
  **"local_ssh_private_key" = "/tmp/WEKA-Prod-private-key.pem"**
  "nfs_protocol_gateways_ips" = tostring(null)
  "smb_protocol_gateways_ips" = tostring(null)
  **"ssh_user" = "ec2-user"**
  "weka_cluster_password_secret_id" = "arn:aws:secretsmanager:us-east-1:459693375476:secret:weka/WEKA-Prod/weka-password-g9bH-T2og7D"
}
```

9. Take note of the `alb_dns_name`, `local_ssh_private_key`, and `ssh_user` values. You need these details for SSH access to the deployed instances.\
   The output includes a `cluster_helper_commands` section, offering three AWS CLI commands to retrieve essential information.

**Core resources created:**

* **Database (DynamoDB):** Stores the state of the WEKA cluster.
* **EC2:** Launch templates for auto-scaling groups and individual instances.
* **Networking:** Includes a Placement Group, Auto Scaling Group, and an optional ALB for the UI and backends.
* **CloudWatch:** Triggers the state machine every minute.
* **IAM:** Roles and policies for various WEKA components.
* **Secret Manager:** Securely stores WEKA credentials and tokens.

**Lambda functions created:**

* **deploy:** Provides installation scripts for new machines.
* **clusterize:** Executes the script for cluster formation.
* **clusterize-finalization:** Updates the cluster state after cluster formation is completed.
* **report:** Reports the progress of cluster formation and machine installation.
* **status:** Displays the current status of cluster formation.

**State machine functions:**

* **fetch:** Retrieves cluster or autoscaling group details and passes them to the next stage.
* **scale-down:** Uses the retrieved information to manage the WEKA cluster, including deactivating drives or hosts. An error is triggered if an unsupported target, like scaling down to two backend instances, is provided.
* **terminate:** Shuts down deactivated hosts.
* **transient:** Handles and reports transient errors, such as if some hosts couldn't be deactivated, while others were, allowing the operation to continue.

### Deploy protocol servers

The Terraform deployment process allows for the easy addition of instances to serve as protocol servers for NFS or SMB. These protocol servers are separate from the instances specified for the WEKA backend cluster.

**Procedure**

1. Open the `main.tf` file for editing.
2. Add the required configurations to define the number of protocol servers for each type (NFS or SMB). Use the default settings for all other parameters.\
   Insert the configuration lines before the last closing brace (`}`) in the `main.tf` file.

   Example configurations:

   ```bash
   ## Deploying NFS Protocol Servers ##
   nfs_protocol_gateways_number = 2  # Minimum of two required

   ## Deploying SMB Protocol Servers ##
   smb_protocol_gateways_number = 3  # Minimum of three required
   ```
3. Save and close the file.

## Obtain access information about WEKA cluster

### **Determine the WEKA cluster IP address(es)**

1. Navigate to the EC2 Dashboard page in AWS and select **Instances (running)**.

<div data-with-frame="true"><figure><img src="/files/2aE6h8qTbrSIgi5rc80y" alt=""><figcaption></figcaption></figure></div>

2. Locate the instances for the WEKA backend servers, named `<prefix>-<cluster_name>-instance-backend`.

<div data-with-frame="true"><figure><img src="/files/TdMqfUDFRelpuN7iiX2A" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
The `prefix` and `cluster_name` correspond to the values specified in the `main.tf` file.
{% endhint %}

3. To access and manage the WEKA cluster, select any of the WEKA backend instances and note the IP address.

<div data-with-frame="true"><figure><img src="/files/8VqsoQHyuEs2w9gEVuSl" alt=""><figcaption></figcaption></figure></div>

4. If your subnet provides a public IP address (configured in EC2), it is listed. WEKA primarily uses private IPv4 addresses for communication. To find the primary private address, check the **Hostname type** and note the **IP address** listed.

### **Obtain WEKA cluster access password**

The password for your WEKA cluster is securely stored in AWS Secrets Manager. This password is crucial for managing your WEKA cluster.

You can retrieve the password using one of the following options:

* Run the `aws secretsmanager get-secret-value` command and include the arguments provided in the Terraform output. See the deployment output above.
* Use the AWS Management Console. See the following procedure.

**Procedure**

1. Navigate to the AWS Management Console.
2. In the search bar, type **Secrets Manager** and select it from the search results.
3. In the Secrets Manager, select **Secrets** from the left-hand menu.
4. Find the secret corresponding to your deployment by looking for a name that includes your deployment’s `prefix` and `cluster_name`, along with the word **password**.
5. Retrieve the password: Click the identified secret to open its details, and select the **Retrieve secret value** button.\
   The console displays the randomly generated password assigned to the WEKA user `admin`.\
   Store it securely and use it according to your organization's security policies.

### Access the WEKA cluster backend servers

To manage your WEKA cluster, you need to access the backend servers. This is typically done using SSH from a system that can communicate with the AWS subnet where the instances are located. If the backend instances lack public IP addresses, ensure that you connect from a system within the same network or use a [Jump Host](#user-content-fn-2)[^2] or [Bastion Host](#user-content-fn-3)[^3].

**Procedure**

1. **Prepare for SSH access**:
   * Identify the IP address of the WEKA backend server (obtained during the Terraform deployment).
   * Locate the SSH private key file used during the deployment. The key path is provided in the Terraform output.
2. **Connect to the backend server**:
   * If your system is within the AWS network or has direct access to the relevant subnet, proceed with the SSH connection.
   * If your system is outside the AWS network, set up a Jump Host or Bastion Host that can access the subnet.
3. **Execute the SSH command**:

   * Use the following SSH command to access the backend server:

   ```bash
   ssh -l ec2-user -i /path/to/private-key.pem <server-ip-address>
   ```

   * Replace `/path/to/private-key.pem` with the actual path to your SSH private key file.
   * Replace `<server-ip-address>` with the IP address of the WEKA backend server.

## **WEKA GUI Login and Review**

To manage your WEKA cluster through the GUI) you'll need access to a jump box (a system with a GUI) that is deployed in the same VPC and subnet as your WEKA cluster. This allows you to securely access the WEKA GUI through a web browser.

The following procedure provides an example of using a Windows 10 instance.

**Procedure**

1. **Set up the jump box**:
   * Deploy a Windows 10 instance in the same VPC, subnet, and security group as your WEKA cluster.
   * Assign a public IP address to the Windows 10 instance.
   * Modify the network security group rules to allow Remote Desktop Protocol (RDP) access to the Windows 10 system.
2. **Access the WEKA GUI**:
   * Open a web browser on the Windows 10 jump box.
   * Navigate to the WEKA GUI by entering the following URL:

     ```arduino
     https://<IP>:14000
     ```

     * Replace `<IP>` with the IP address of your WEKA cluster. For example: `https://10.5.0.11`.
   * The WEKA GUI login screen appears.
3. **Log In to the WEKA GUI**:
   * Log in using the username `admin` and the password obtained from AWS Secrets Manager (as described in the earlier steps).

<div data-with-frame="true"><figure><img src="/files/OedaENV6P3DMj0j7HuVt" alt=""><figcaption></figcaption></figure></div>

4. **Review the WEKA Cluster**:

* **Cluster home screen**: View the cluster home screen for an overview of the system status.

<div data-with-frame="true"><figure><img src="/files/4EUDo4rEg67Gwx4RYiOU" alt=""><figcaption></figcaption></figure></div>

* **Cluster Backends**: Review the status and details of the backend servers within the cluster (the server names may differ from those shown in examples).

<div data-with-frame="true"><figure><img src="/files/jBBAXek7mLx88qGdihLH" alt=""><figcaption></figcaption></figure></div>

* **Clients**: If there are any clients attached to the cluster, review their details and status.

<div data-with-frame="true"><figure><img src="/files/JcZ6ipkBS2F2zS3bcZhF" alt=""><figcaption></figcaption></figure></div>

* **Filesystems**: Review the filesystems associated with the cluster for their status and configuration.

<div data-with-frame="true"><figure><img src="/files/1MKxlNMga2UyLJlMuAwW" alt=""><figcaption></figcaption></figure></div>

## Scaling WEKA clusters with automated workflows

Scaling your WEKA cluster, whether scale-out (expanding) or scale-in (contracting), is streamlined using the AWS AutoScaling Group Policy set up by Terraform. This process leverages Terraform-created Lambda functions to manage automation tasks, ensuring that additional computing resources (new backend instances) are efficiently integrated or removed from the cluster as needed.

**Advantages of auto-scaling**

* **Integration with ALB:**
  * **Traffic distribution:** Auto Scaling Groups work seamlessly with an Application Load Balancer (ALB) to distribute traffic efficiently among instances.
  * **Health checks:** The ALB directs traffic only to healthy instances, based on results from the associated Auto Scaling Group's health checks.
* **Auto-healing:**
  * **Instance replacement:** If an instance fails a health check, auto-scaling automatically replaces it by launching a new instance.
  * **Health verification:** The new instance is only added to the ALB’s target group after passing health checks, ensuring continuous availability and responsiveness.
* **Graceful scaling:**
  * **Controlled adjustments:** Auto-scaling configurations can be customized to execute scaling actions gradually.
  * **Demand adaptation:** This approach prevents sudden traffic spikes and maintains stability while adapting to changing demand.

**Procedure**

1. Navigate to the AutoScaling Group page in the AWS Management Console.
2. Select **Edit** to adjust the desired capacity.

<div data-with-frame="true"><figure><img src="/files/QRtMOiTgnac9JHYKP6sc" alt=""><figcaption></figcaption></figure></div>

3. Set the capacity to your preferred cluster size (for example, increase from 6 to 10 servers).

<div data-with-frame="true"><figure><img src="/files/8q4wlamRFQUZibrQHhmQ" alt="" width="375"><figcaption></figcaption></figure></div>

4. Select **Update** to save the updated settings to initiate scaling operations.

## Test WEKA cluster self-healing functionality

Testing the self-healing functionality of a WEKA cluster involves decommissioning an existing instance and observing whether the Auto Scaling Group (ASG) automatically replaces it with a new instance. This process verifies the cluster’s ability to maintain capacity and performance despite instance failures or terminations.

**Procedure**

1. **Identify the old instance:** Determine the EC2 instance you want to decommission. Selection criteria may include age, outdated configurations, or specific maintenance requirements.
2. **Verify auto-scaling configuration:** Ensure your Auto Scaling Group is configured with a minimum of 7 instances (or more) and that the desired capacity is set to maintain the appropriate number of instances in the cluster.
3. **Terminate the old instance:** Use the AWS Management Console, AWS CLI, or SDKs to manually terminate the selected EC2 instance. This action prompts the ASG to initiate the replacement process.
4. **Monitor auto-scaling activities:** Track the ASG’s activities through the AWS Console or AWS CloudWatch. Confirm that the ASG recognizes the terminated instance and begins launching a new instance.
5. **Verify the new instance:** After it is launched, ensure it passes all health checks and integrates successfully into the cluster, maintaining overall cluster capacity.
6. **Check load balancer:**
   * If a load balancer is part of your setup, verify that it detects and registers the new instance to ensure proper load distribution across the cluster.
7. **Review auto-scaling logs:** Examine CloudWatch logs or auto-scaling events for any issues or errors related to terminating the old instance and introducing the new one.
8. **Document and monitor:** Record the decommissioning process and continuously monitor the cluster to confirm that it operates smoothly with the new instance.

## APPENDICES

### Appendix A: Security Groups / network ACL ports

See [Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility#required-ports)

### Appendix B: **Terraform’s r**equired permissions examples <a href="#appendix-b-terraforms-required-permissions" id="appendix-b-terraforms-required-permissions"></a>

The minimum IAM Policies needed are based on the assumption that the network, including VPC, subnets, VPC Endpoints, and Security Groups, is created by the end user. If IAM roles or policies are pre-established, some permissions may be omitted.

{% hint style="info" %}
The policy exceeds the 6144 character limit for IAM Policies, necessitating its division into two separate policies.
{% endhint %}

In each policy, replace the placeholders, such as `account-number`, `prefix`, and `cluster-name`, with the corresponding actual values.

<details>

<summary>IAM policy 1</summary>

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:GetObject"
            ],
            "Resource": [
                "arn:aws:s3:::weka-tf-aws-releases*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:DeletePlacementGroup"
            ],
            "Resource": "arn:aws:ec2:us-east-1:account-number:placement-group/prefix-cluster-name*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:DescribePlacementGroups"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeInstanceTypes"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:CreateLaunchTemplate",
                "ec2:CreateLaunchTemplateVersion",
                "ec2:DeleteLaunchTemplate",
                "ec2:DeleteLaunchTemplateVersions",
                "ec2:ModifyLaunchTemplate",
                "ec2:GetLaunchTemplateData"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "autoscaling:DescribeAutoScalingGroups",
                "autoscaling:DescribeScalingActivities"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "autoscaling:CreateAutoScalingGroup",
                "autoscaling:DeleteAutoScalingGroup",
                "autoscaling:UpdateAutoScalingGroup",
                "autoscaling:SetInstanceProtection",
                "autoscaling:SuspendProcesses",
                "autoscaling:AttachLoadBalancerTargetGroups",
                "autoscaling:DetachLoadBalancerTargetGroups"
            ],
            "Resource": [
                "arn:aws:autoscaling:*:account-number:autoScalingGroup:*:autoScalingGroupName/prefix-cluster-name-autoscaling-group"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "lambda:CreateFunction",
                "lambda:DeleteFunction",
                "lambda:GetFunction",
                "lambda:ListFunctions",
                "lambda:UpdateFunctionCode",
                "lambda:UpdateFunctionConfiguration",
                "lambda:ListVersionsByFunction",
                "lambda:GetFunctionCodeSigningConfig",
                "lambda:GetFunctionUrlConfig",
                "lambda:CreateFunctionUrlConfig",
                "lambda:DeleteFunctionUrlConfig",
                "lambda:AddPermission",
                "lambda:GetPolicy",
                "lambda:RemovePermission"
            ],
            "Resource": "arn:aws:lambda:*:account-number:function:prefix-cluster-name-*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "lambda:CreateEventSourceMapping",
                "lambda:DeleteEventSourceMapping",
                "lambda:GetEventSourceMapping",
                "lambda:ListEventSourceMappings"
            ],
            "Resource": "arn:aws:lambda:*:account-number:event-source-mapping:prefix-cluster-name-*"
        },
        {
            "Sid": "ReadAMIData",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeImages",
                "ec2:DescribeImageAttribute",
                "ec2:CopyImage"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:ImportKeyPair",
                "ec2:CreateKeyPair",
                "ec2:DeleteKeyPair",
                "ec2:DescribeKeyPairs"
            ],
            "Resource": "*"
        },
        {
            "Action": [
                "ec2:MonitorInstances",
                "ec2:UnmonitorInstances",
                "ec2:ModifyInstanceAttribute",
                "ec2:RunInstances",
                "ec2:CreateTags"
            ],
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Sid": "DescribeSubnets",
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeSubnets"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Sid": "DescribeALB",
            "Effect": "Allow",
            "Action": [
                "elasticloadbalancing:DescribeLoadBalancers",
                "elasticloadbalancing:DescribeTargetGroups",
                "elasticloadbalancing:DescribeListeners"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:CreatePlacementGroup"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "elasticloadbalancing:CreateLoadBalancer",
                "elasticloadbalancing:AddTags",
                "elasticloadbalancing:CreateTargetGroup",
                "elasticloadbalancing:ModifyLoadBalancerAttributes",
                "elasticloadbalancing:ModifyTargetGroupAttributes",
                "elasticloadbalancing:DeleteLoadBalancer",
                "elasticloadbalancing:DeleteTargetGroup",
                "elasticloadbalancing:CreateListener",
                "elasticloadbalancing:DeleteListener"
            ],
            "Resource": [
                "arn:aws:elasticloadbalancing:us-east-1:account-number:loadbalancer/app/prefix-cluster-name*",
                "arn:aws:elasticloadbalancing:us-east-1:account-number:targetgroup/prefix-cluster-name*",
                "arn:aws:elasticloadbalancing:us-east-1:account-number:listener/app/prefix-cluster-name*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "elasticloadbalancing:DescribeLoadBalancerAttributes",
                "elasticloadbalancing:DescribeTargetGroupAttributes",
                "elasticloadbalancing:DescribeTags"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeSecurityGroups",
                "ec2:DescribeVpcs",
                "ec2:DescribeLaunchTemplates",
                "ec2:DescribeLaunchTemplateVersions",
                "ec2:DescribeInstances",
                "ec2:DescribeTags",
                "ec2:DescribeInstanceAttribute",
                "ec2:DescribeVolumes"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Sid": "Statement1",
            "Effect": "Allow",
            "Action": [
                "states:Createcluster-nameMachine",
                "states:Deletecluster-nameMachine",
                "states:TagResource",
                "states:DescribeStateMachine",
                "states:ListStateMachineVersions",
                "states:ListStateMachines",
                "states:ListTagsForResource"
            ],
            "Resource": [
                "arn:aws:states:us-east-1:account-number:stateMachine:prefix-cluster-name*"
            ]
        },
        {
            "Sid": "Statement2",
            "Effect": "Allow",
            "Action": [
                "ec2:TerminateInstances"
            ],
            "Resource": [
                "*"
            ]
        }
    ]
}
```

</details>

<details>

<summary>IAM policy 2</summary>

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "secretsmanager:CreateSecret",
                "secretsmanager:DeleteSecret",
                "secretsmanager:DescribeSecret",
                "secretsmanager:GetSecretValue",
                "secretsmanager:ListSecrets",
                "secretsmanager:UpdateSecret",
                "secretsmanager:GetResourcePolicy",
                "secretsmanager:ListSecretVersionIds",
                "secretsmanager:PutSecretValue"
            ],
            "Resource": [
                "arn:aws:secretsmanager:*:account-number:secret:weka/prefix-cluster-name/*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "dynamodb:PutItem",
                "dynamodb:DeleteItem",
                "dynamodb:GetItem",
                "dynamodb:UpdateItem"
            ],
            "Resource": "arn:aws:dynamodb:*:account-number:table/prefix-cluster-name*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:CreatePolicy",
                "iam:CreateRole",
                "iam:DeleteRole",
                "iam:DeletePolicy",
                "iam:GetPolicy",
                "iam:GetRole",
                "iam:GetPolicyVersion",
                "iam:ListRolePolicies",
                "iam:ListInstanceProfilesForRole",
                "iam:PassRole",
                "iam:ListPolicyVersions",
                "iam:ListAttachedRolePolicies",
                "iam:ListAttachedGroupPolicies",
                "iam:ListAttachedUserPolicies"
            ],
            "Resource": [
                "arn:aws:iam::account-number:policy/prefix-cluster-name-*",
                "arn:aws:iam::account-number:role/prefix-cluster-name-*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:AttachRolePolicy",
                "iam:AttachGroupPolicy",
                "iam:AttachUserPolicy",
                "iam:DetachRolePolicy",
                "iam:DetachGroupPolicy",
                "iam:DetachUserPolicy"
            ],
            "Resource": [
                "arn:aws:iam::account-number:policy/prefix-cluster-name-*",
                "arn:aws:iam::account-number:role/prefix-cluster-name-*",
                "arn:aws:iam::account-number:role/ck-cluster-name-weka-iam-role"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:GetPolicy",
                "iam:ListEntitiesForPolicy"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:GetInstanceProfile",
                "iam:CreateInstanceProfile",
                "iam:DeleteInstanceProfile",
                "iam:AddRoleToInstanceProfile",
                "iam:RemoveRoleFromInstanceProfile"
            ],
            "Resource": "arn:aws:iam::*:instance-profile/prefix-cluster-name-*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "logs:CreateLogGroup",
                "logs:PutRetentionPolicy",
                "logs:DeleteLogGroup"
            ],
            "Resource": [
                "arn:aws:logs:us-east-1:account-number:log-group:/aws/lambda/prefix-cluster-name*",
                "arn:aws:logs:us-east-1:account-number:log-group:/aws/vendedlogs/states/prefix-cluster-name*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "events:TagResource",
                "events:PutRule",
                "events:DescribeRule",
                "events:ListTagsForResource",
                "events:DeleteRule",
                "events:PutTargets",
                "events:ListTargetsByRule",
                "events:RemoveTargets"
            ],
            "Resource": [
                "arn:aws:events:us-east-1:account-number:rule/prefix-cluster-name*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "dynamodb:CreateTable",
                "dynamodb:DescribeTable",
                "dynamodb:DescribeContinuousBackups",
                "dynamodb:DescribeTimeToLive",
                "dynamodb:ListTagsOfResource",
                "dynamodb:DeleteTable"
            ],
            "Resource": [
                "arn:aws:dynamodb:us-east-1:account-number:table/prefix-cluster-name*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "logs:DescribeLogGroups",
                "logs:ListTagsLogGroup"
            ],
            "Resource": [
                "*"
            ]
        }
        {
            "Effect": "Allow",
            "Action": "iam:CreateServiceLinkedRole",
            "Resource": "arn:aws:iam::*:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoscaling*",
            "Condition": {
                "StringLike": {
                    "iam:AWSServiceName": "autoscaling.amazonaws.com"
                }
            }
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:AttachRolePolicy",
                "iam:PutRolePolicy"
            ],
            "Resource": "arn:aws:iam::*:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoscaling*"
        }
    ]
}
```

</details>

**Parameters:**

* **DynamoDB**: Full access is granted as your setup requires creating and managing DynamoDB tables.
* **Lambda**: Full access is needed for managing various Lambda functions mentioned.
* **State Machine (AWS Step Functions)**: Full access is given for managing state machines.
* **Auto Scaling Group & EC2 Instances**: Permissions for managing Auto Scaling groups and EC2 instances.
* **Application Load Balancer (ALB)**: Required for operations related to load balancing.
* **CloudWatch**: Necessary for monitoring and managing CloudWatch rules and metrics.
* **Secrets Manager**: Access for managing secrets in AWS Secrets Manager.
* **IAM**: **`PassRole`** and **`GetRole`** are essential for allowing resources to assume specific roles.
* **KMS**: Permissions for Key Management Service, assuming you use KMS for encryption.

**Customization:**

1. **Resource Names and ARNs**: Replace **`"Resource": "*"`** with specific ARNs for your resources to tighten security. Use specific ARNs for KMS keys as well.
2. **Region and Account ID**: Replace **`region`** and **`account-id`** with your AWS region and account ID.
3. **Key ID**: Replace **`key-id`** with the ID of the KMS key used in your setup.

{% hint style="info" %}
**Important notes:**

* This is a broad policy for demonstration. It's recommended to refine it based on your actual resource usage and access patterns.
* You may need to add or remove permissions based on specific requirements of your Terraform module and AWS environment.
* Testing the policy in a controlled environment before applying it to production is advisable to ensure it meets your needs without overly restricting or exposing your resources.
  {% endhint %}

### Appendix C: IAM Policies required by WEKA

The following policies are essential for all components to function on AWS. Terraform automatically creates these policies as part of the automation process. However, you also have the option to create and define them manually within your Terraform modules.

<details>

<summary><strong>EC2 policies (Required for the backends that are part of the WEKA cluster)</strong></summary>

```json
{
"Statement": [
{
"Action": [
"ec2:DescribeNetworkInterfaces",
"ec2:AttachNetworkInterface",
"ec2:CreateNetworkInterface",
"ec2:ModifyNetworkInterfaceAttribute",
"ec2:DeleteNetworkInterface"
],
"Effect": "Allow",
"Resource": "*"
},
{
"Action": [
"lambda:InvokeFunction"
],
"Effect": "Allow",
"Resource": [
"arn:aws:lambda:*:*:function:prefix-cluster_name*"
]
},
{
"Action": [
"s3:DeleteObject",
"s3:GetObject",
"s3:ListBucket",
"s3:PutObject"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::prefix-cluster_name-obs/*"
]
},
{
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents",
"logs:DescribeLogStreams",
"logs:PutRetentionPolicy"
],
"Effect": "Allow",
"Resource": [
"arn:aws:logs:*:*:log-group:/wekaio/prefix-cluster_name*"
]
}
],
"Version": "2012-10-17"
}
```

</details>

<details>

<summary><strong>Lambda IAM policy</strong></summary>

```json
{
"Statement": [
{
"Action": [
"s3:CreateBucket"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::prefix-cluster_name-obs"
]
},
{
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Effect": "Allow",
"Resource": [
"arn:aws:logs:*:*:log-group:/aws/lambda/prefix-cluster_name*:*"
]
},
{
"Action": [
"ec2:CreateNetworkInterface",
"ec2:DescribeNetworkInterfaces",
"ec2:DeleteNetworkInterface",
"ec2:ModifyInstanceAttribute",
"ec2:TerminateInstances",
"ec2:DescribeInstances"
],
"Effect": "Allow",
"Resource": [
"*"
]
},
{
"Action": [
"dynamodb:GetItem",
"dynamodb:UpdateItem"
],
"Effect": "Allow",
"Resource": [
"arn:aws:dynamodb:*:*:table/prefix-cluster_name-weka-deployment"
]
},
{
"Action": [
"secretsmanager:GetSecretValue",
"secretsmanager:PutSecretValue"
],
"Effect": "Allow",
"Resource": [
"arn:aws:secretsmanager:*:*:secret:weka/prefix-cluster_name/*"
]
},
{
"Action": [
"autoscaling:DetachInstances",
"autoscaling:DescribeAutoScalingGroups",
"autoscaling:SetInstanceProtection"
],
"Effect": "Allow",
"Resource": [
"*"
]
}
],
"Version": "2012-10-17"
}
```

</details>

<details>

<summary><strong>State machine IAM policy</strong></summary>

```json
{
"Statement": [
{
"Action": [
"lambda:InvokeFunction"
],
"Effect": "Allow",
"Resource": [
"arn:aws:lambda:*:*:function:prefix-cluster_name-*-lambda"
]
},
{
"Action": [
"logs:CreateLogDelivery",
"logs:GetLogDelivery",
"logs:UpdateLogDelivery",
"logs:DeleteLogDelivery",
"logs:ListLogDeliveries",
"logs:PutLogEvents",
"logs:PutResourcePolicy",
"logs:DescribeResourcePolicies",
"logs:DescribeLogGroups"
],
"Effect": "Allow",
"Resource": [
"*"
]
}
],
"Version": "2012-10-17"
}
```

</details>

<details>

<summary><strong>CloudWatch IAM policy</strong></summary>

```
{
"Statement": [
{
"Action": [
"states:StartExecution"
],
"Effect": "Allow",
"Resource": [
"arn:aws:states:*:*:stateMachine:prefix-cluster_name-scale-down-state-machine"
]
}
],
"Version": "2012-10-17"
}
```

</details>

<details>

<summary><strong>Client instances IAM policy</strong></summary>

```
{
    "Statement": [
        {
            "Action": [
                "autoscaling:DescribeAutoScalingGroups"
            ],
            "Effect": "Allow",
            "Resource": [
                "*"
            ]
        },
      {
        "Action": [
          "ec2:DescribeNetworkInterfaces",
          "ec2:AttachNetworkInterface",
          "ec2:CreateNetworkInterface",
          "ec2:ModifyNetworkInterfaceAttribute",
          "ec2:DeleteNetworkInterface",
          "ec2:DescribeInstances",
          "ec2:CreateTags"
        ],
        "Effect": "Allow",
        "Resource": "*"
      },
      {
        "Action": [
          "logs:CreateLogGroup",
          "logs:CreateLogStream",
          "logs:PutLogEvents",
          "logs:DescribeLogStreams",
          "logs:PutRetentionPolicy"
        ],
        "Effect": "Allow",
        "Resource": [
          "arn:aws:logs:*:*:log-group:/wekaio/clients/prefix-cluster_name-client*"
        ]
      }
    ],
    "Version": "2012-10-17"
}
```

</details>

<details>

<summary><strong>Protocol gateway IAM policy</strong></summary>

```
{
  "Statement": [
    {
      "Effect": "Allow",
      "Action":
    [
      "ec2:DescribeNetworkInterfaces",
      "ec2:AttachNetworkInterface",
      "ec2:CreateNetworkInterface",
      "ec2:ModifyNetworkInterfaceAttribute",
      "ec2:DeleteNetworkInterface",
      "ec2:DescribeInstances",
      "ec2:DescribeTags",
      "ec2:AssignPrivateIpAddresses"
    ],
    "Resource":  "*",
    },
    {
      "Effect": "Allow",
      "Action":
    [
      "secretsmanager:GetSecretValue"
    ]
    "Resource":
    [
      "arn:aws:secretsmanager:*:*㊙weka/prefix-cluster_name/*"
    ]
    },
    {
      "Effect": "Allow",
      "Action":
    [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "logs:DescribeLogStreams",
      "logs:PutRetentionPolicy"
    ],
    "Resource":
    [
      "arn:aws:logs:*:*:log-group:/wekaio/clients/gateways_name*"
    ]
    },
    {
      "Effect": "Allow",
      "Action":
    [
      "autoscaling:DescribeAutoScalingGroups"
    ],
    "Resource":
    [
      "*"
    ]
    },
    {
      "Action": [
        "lambda:InvokeFunction"
      ],
      "Effect": "Allow",
      "Resource": [
        "arn:aws:lambda:*:*:function:prefix-cluster_name*"
      ]
    },
  ]
}
```

</details>

[^1]: Terraform is an infrastructure-as-code tool for provisioning manager.

[^2]: **Jump Host:** A secure intermediary server used to manage access to devices within a protected network zone, ensuring controlled and authenticated connections.

[^3]: **Bastion Host:** A hardened server positioned to manage external access to an internal network, offering secure gateway services with enhanced security measures.


# WEKA installation on Azure

This section aims at a system engineer familiar with the Azure fundamentals and experienced in using Terraform to deploy a system on Azure.

The WEKA® Data Platform on Microsoft Azure provides a fast and scalable platform for running performance-intensive applications and hybrid cloud workflows. It can also be used for object stores, tiering, and snapshots using the Azure Blob service, for example, to create backups and DR copies.

WEKA provides a ready-to-deploy Terraform package that you can customize for installing the WEKA cluster on Azure. The WEKA cluster is deployed with a multiple containers architecture, in which each container serves a single process type: Compute, Drives, or Frontend.

The WEKA cluster is deployed in a single virtual network (VNet, similar to VPC in other clouds), where peering is not required. Each VNet has a subnet, routers, firewalls, and an internal DNS. The networking supports MTU 3900. The VM includes 4 or 8 NICs, each NIC is mapped to a dedicated core to support DPDK.

Depending on the required security level, you can deploy the WEKA cluster using the Terraform package on one of the following subnet types:

* **Public subnets:** Use a single public subnet within your VNet with an internet gateway, and allow public IP addresses for your virtual machines.
* **Private subnets:** Use a single private subnet within your VNet with access to an APT repository containing the required deployment packages.

<div data-with-frame="true"><figure><img src="/files/zLjly85TVfsjSp3XZ7yL" alt=""><figcaption><p>WEKA cluster on Azure deployment</p></figcaption></figure></div>

<details>

<summary>Introduction to Azure fundamentals</summary>

Azure is a cloud computing platform with an ever-expanding set of services to help you build solutions to meet your business goals. Azure services range from simple web services for hosting your business presence in the cloud to running fully virtualized computers for you to run your custom software solutions.

Azure provides a wealth of cloud-based services like remote storage, database hosting, and centralized account management. Azure also offers new capabilities like AI and the Internet of Things (IoT).

To learn about Azure fundamentals, Microsoft provides learning modules at <https://learn.microsoft.com/en-us/training/>. You can start with the [Introduction to Azure fundamentals](https://learn.microsoft.com/en-us/training/modules/intro-to-azure-fundamentals/).

</details>

<details>

<summary>Terraform overview</summary>

Terraform is an open-source project from HashiCorp. It creates and manages resources on cloud platforms and on-premises environments. It interacts with numerous APIs from multiple platforms and services, providing a unified workflow for infrastructure management.

Terraform is the primary tool for deploying WEKA on Azure.

<img src="/files/wN5LMlxfVkG12fYKxT00" alt="" data-size="original">

**How does Terraform work?**

A deployment with Terraform involves three phases:

* **Write:** Define the infrastructure in configuration files and customize the project variables provided in the Terraform package.
* **Plan**: Review the changes Terraform will make to your infrastructure.
* **Apply:** Terraform provisions the infrastructure, including the VMs and instances, installs the WEKA software, and creates the cluster. Once completed, the WEKA cluster runs on Azure.

<img src="/files/QzY95rUxPdVcqa0RpRtK" alt="Terraform phases" data-size="original">

**Related information**

[Terraform Tutorials](https://developer.hashicorp.com/terraform/tutorials/azure-get-started)

[Terraform Installation](https://learn.hashicorp.com/tutorials/terraform/install-cli)

</details>

**Related topics**

[Cluster architecture overview](/weka-system-overview/weka-containers-architecture-overview)

**Related information**

[Weka® Data Platform on Microsoft Azure Marketplace](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/weka1652213882079.weka_data_platform?exp=ubp8\&tab=Overview)


# Azure-WEKA deployment Terraform package description

The [Azure-WEKA deployment Terraform package](https://registry.terraform.io/modules/weka/weka/azure/latest) contains customizable modules for deploying the WEKA cluster on Azure. The default protocol deployed using the module is POSIX. The module supports the following deployment types:

* **Public cloud deployments:** Require passing the `get.weka.io` token to Terraform for downloading the WEKA release from the public [get.weka.io](https://get.weka.io) service. The following examples are provided:
  * Public network.
  * Public network with existing object store.
* **Private cloud deployments:** Require uploading the WEKA release tar file into an Azure blob container from which the virtual machines can download the WEKA release. The following examples are provided:
  * Existing private network.
  * Existing private network with peering.

{% hint style="info" %}
WEKA deployment on Azure only supports Ethernet networking.
{% endhint %}

## Terraform-Azure-WEKA example

The following is a basic example in which you provide the minimum detail of your cluster, and the Terraform module completes the remaining required resources, such as VPC, subnets, security group, placement group, DNS zone, and IAM roles.

You can use this example as a reference to create the `main.tf` file.

```hcl
provider "azurerm" {
  subscription_id = var.subscription_id
  partner_id      = "f13589d1-f10d-4c3b-ae42-3b1a8337eaf1"
  features {
  }
}

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.75.0"
    }
  }
  required_version = ">= 1.3.7"
}


variable "get_weka_io_token" {}

variable "subscription_id" {}

module "weka_deployment" {
  source                         = "weka/weka/azure"
  version                         = "4.2.7.64"
  prefix                         = "my_prefix"
  rg_name                        = "example"

  
  subnet_prefix="10.3.2.0/24"
  address_space="10.3.0.0/16"
  logic_app_subnet_delegation_cidr="10.3.3.0/25"
  function_app_subnet_delegation_cidr="10.3.4.0/25"

  get_weka_io_token              = var.get_weka_io_token
  subscription_id                = var.subscription_id
  cluster_name                   = "my_cluster_name"
  tiering_enable_obs_integration = true
  cluster_size                   = 6
  allow_ssh_cidrs                = ["0.0.0.0/0"]
  allow_weka_api_cidrs           = ["0.0.0.0/0"]

}

output "weka_deployment_output" {
  value = module.weka_deployment
}
```

{% hint style="info" %}
For the descriptions of the parameters, refer to the [Azure-WEKA deployment Terraform package](https://registry.terraform.io/modules/weka/weka/azure/latest).
{% endhint %}


# Deployment on Azure using Terraform

This guide outlines the customization process for Terraform configurations to deploy the WEKA cluster on Azure. It is designed for system engineers with expertise in Azure and Terraform.

{% hint style="info" %}
If you are new to Azure and Terraform, refer to the [Detailed deployment tutorial: WEKA on Azure using Terraform](/planning-and-installation/weka-installation-on-azure/detailed-deployment-tutorial-weka-on-azure-using-terraform)
{% endhint %}

The Terraform package contains modules that can be tailored to suit your specific deployment requirements. The installation is based on applying the customized Terraform variables file to a predefined Azure subscription.

Applying the Terraform module performs the following:

* Creates resources in a predefined resource group, such as virtual machines, network interfaces, function apps, load balancer, and more.
* Deploys Azure virtual machines.
* Installs the WEKA software.
* Configures the WEKA cluste&#x72;**.**

The total deployment time is about 30 minutes. Half of that time is for resource deployment. The remainder is for the WEKA cluster installation and configuration.

## Prerequisites

Before installing the WEKA software on Azure, the following prerequisites must be met:

* The following must be installed on the workstation used for the deployment:
  * [Azure CLI](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli)
  * [Terraform](https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli) (check the minimum required Terraform version specified in the [**Requirements**](https://registry.terraform.io/modules/weka/weka/azure/latest#requirements) section of Azure-WEKA deployment Terraform package.
* For an ARM-based MAC workstation (for example, M1 or M2), see specific instructions below.
* Initialize the Terraform-Azure-WEKA module using `terraform init` from the local directory. This command initializes a new or existing Terraform working directory by creating initial files, loading any remote state, downloading modules, and more.
* Required permissions on Azure:
  * Privileged Role Administrator
  * Storage Blob Data Owner
  * Storage Account Contributor
  * Key Vault Administrator
* To login to the Azure account using Azure CLI, use the **az login** command.
* You need to create an Azure resource group within your subscription, which includes the Azure region.

<details>

<summary>Arm-based Mac workstation additional requirements</summary>

Follow these additional requirements to get Terraform working on an Arm-based Mac:

1. Run `brew install tfenv`
2. Run `TFENV_ARCH=amd64 tfenv install 1.3.7`
3. Run `tfenv use 1.3.7`
4. Run `brew install kreuzwerker/taps/m1-terraform-provider-helper`

</details>

## **Create a main.tf file**

The main Terraform configuration settings are included in the `main.tf` file. You can create it by following this procedure or using the WEKA Cloud Deployment Manager. See [Cloud Deployment Manager Web (CDM Web) User Guide](/planning-and-installation/weka-cdm-web-user-guide).

**Procedure**

1. Review the [Terraform-Azure-WEKA example](/planning-and-installation/weka-installation-on-azure/azure-weka-terraform-package-description#terraform-azure-weka-example) and use it as a reference for creating the `main.tf` according to your Azure deployment specifics.
2. Tailor the `main.tf` file to create SMB-W or NFS protocol clusters by adding the relevant code snippet. Adjust parameters like the number of gateways, instance types, domain name, and share naming:

* **SMB-W**

<pre><code><strong>smb_protocol_gateways_number = 3
</strong>smb_protocol_gateway_instance_type = "Standard_L48s_v3" 
smbw_enabled = true
smb_domain_name = "CUSTOMER_DOMAIN"
smb_share_name = "SPECIFY_SMB_SHARE_NAMING"
smb_setup_protocol = true
</code></pre>

* **NFS**

```
nfs_protocol_gateways_number = 1
nfs_protocol_gateway_instance_type = "Standard_L48s_v3"
nfs_setup_protocol = true
```

4. Add WEKA POSIX clients (optional)**:** If needed, add [WEKA POSIX clients](/weka-system-overview/weka-client-and-mount-modes) to support your workload by incorporating the specified variables into the `main.tf` file:

```makefile
clients_number = 2
client_instance_type = "Standard_L48s_v3"
```

## Apply the main.tf file

Once you complete the main.tf settings, apply it: Run `terraform apply`

## Cluster help commands

The system displays the cluster help commands enabling you to perform the following:

* Get the clusterization status
* Get the cluster status
* Fetch the WEKA cluster password
* View the path to SSH keys
* View the virtual machine IP addresses
* Resize the cluster

<details>

<summary>Cluster help commands output example</summary>

In the following example, the prefix is `v41`, and the cluster name is `jack`.

```
get-cluster-helpers-commands = <<EOT
########################################## Get clusterization status #####################################################################
function_key=$(az functionapp keys list --name v41-jack-function-app --resource-group jackm-rg --subscription d2f248b9-d054-477f-b7e8-413921532c2a --query functionKeys -o tsv)
curl --fail  -H "Content-Type:application/json" -d '{"type": "progress"}'

########################################## Get cluster status ############################################################################
function_key=$(az functionapp keys list --name v41-jack-function-app --resource-group jackm-rg --subscription d2f248b9-d054-477f-b7e8-413921532c2a --query functionKeys -o tsv)
curl --fail 

######################################### Fetch weka cluster password ####################################################################
az keyvault secret show --vault-name v41-jack-key-vault --name weka-password | jq .value

########################################## Download ssh keys command from blob ###########################################################
 az keyvault secret download --file private.pem --encoding utf-8 --vault-name  v41-jack-key-vault --name private-key --query "value"
 az keyvault secret download --file public.pub --encoding utf-8 --vault-name  v41-jack-key-vault --name public-key --query "value"

############################################## Path to ssh keys  ##########################################################################
/tmp/v41-jack-public-key.pub
 /tmp/v41-jack-private-key.pem

################################################ Vms ips ##################################################################################
az vmss list-instance-public-ips -g jackm-rg --name v41-jack-vmss --subscription <azure subscription id> --query "[].ipAddress"


########################################## Resize cluster #################################################################################
function_key=$(az functionapp keys list --name v41-jack-function-app --resource-group jackm-rg --subscription <azure subscription id> --query functionKeys -o tsv)
curl --fail  -H "Content-Type:application/json" -d '{"value":ENTER_NEW_VALUE_HERE}'

EOT
```

</details>

**Related topic**

[Azure-WEKA deployment Terraform package description](/planning-and-installation/weka-installation-on-azure/azure-weka-terraform-package-description)

[Troubleshooting](/planning-and-installation/weka-installation-on-azure/troubleshooting)

## Check the deployment progress

Once Terraform applies the configuration and deploys all the required resources, you can use the cluster help commands to check the progress of the cluster deployment.

The following is the command syntax for checking the cluster status during the deployment progress:

{% code overflow="wrap" %}

```bash
curl --fail https://<prefix>-<cluster name>-function-app.azurewebsites.net/api/status?code=$function_key
```

{% endcode %}

### Example

Explore the following phases to check the deployment progress:

<details>

<summary>Preparation</summary>

Once the VM starts, it prepares all the required objects, such as setting the partition to `/opt/weka`, downloading the Weka release, and deploying the container drives.

You can track the progress of the preparation, which can take about 10 minutes.

1. Get your function key by running the command:

```
function_key=$(az functionapp keys list --name v41-jack-function-app --resource-group jackm-rg --subscription <your Azure subscription id> --query functionKeys -o tsv)

```

2. Track the preparation progress by running the command:

```
curl --fail https://v41-jack-function-app.azurewebsites.net/api/status?code=$function_key -H "Content-Type:application/json" -d '{"type": "progress"}'

```

Response example:

```
{
  "ready_for_clusterization": [],
  "progress": {
    "v41-jack-backend000001": [
      "10:02:55 UTC: Running init script",
      "10:03:17 UTC: Installing weka"
    ],
    "v41-jack-backend000002": [
      "10:02:56 UTC: Running init script",
      "10:03:18 UTC: Installing weka"
    ],
    "v41-jack-backend000003": [
      "10:02:54 UTC: Running init script",
      "10:03:16 UTC: Installing weka",
      "10:08:32 UTC: Weka installation completed",
      "10:08:34 UTC: Setting deletion protection authorization error, going to sleep for 2M"
    ],
    "v41-jack-backend000004": [
      "10:02:57 UTC: Running init script",
      "10:03:27 UTC: Installing weka",
      "10:09:07 UTC: Weka installation completed",
      "10:09:09 UTC: Setting deletion protection authorization error, going to sleep for 2M"
    ],
    "v41-jack-backend000005": [
      "10:02:55 UTC: Running init script",
      "10:03:17 UTC: Installing weka"
    ],
    "v41-jack-backend000006": [
      "10:02:54 UTC: Running init script",
      "10:03:24 UTC: Installing weka"
    ]
  },
  "errors": null
}
```

</details>

<details>

<summary>C<strong>luster formation status update</strong></summary>

Once the preparation phase completes, the list of requested virtual machines appears. The number of servers ready for clusterization depends on the required cluster size.

Run the following command to track the clusterization status:

```
curl --fail https://v41-jack-function-app.azurewebsites.net/api/status?code=$function_key -H "Content-Type:application/json" -d '{"type": "progress"}'

```

The `"ready for clusterization"` section provides the list of virtual machines to be clusterized. In the following response example, the last backend `v41-jack-vmss_3` runs the cluster formation:

```
{
  "ready_for_clusterization": [
    "v41-jack-vmss_4:v41-jack-backend000004:20.228.235.225",
    "v41-jack-vmss_6:v41-jack-backend000006:20.228.234.98",
    "v41-jack-vmss_1:v41-jack-backend000001:20.228.234.225",
    "v41-jack-vmss_5:v41-jack-backend000005:20.228.236.6",
    "v41-jack-vmss_2:v41-jack-backend000002:20.228.235.126",
    "v41-jack-vmss_3:v41-jack-backend000003:20.228.235.38"
  ],
  "progress": {
    "v41-jack-backend000001": [
      "10:02:55 UTC: Running init script",
      "10:03:17 UTC: Installing weka",
      "10:09:43 UTC: Weka installation completed",
      "10:09:46 UTC: Setting deletion protection authorization error, going to sleep for 2M",
      "10:11:47 UTC: Deletion protection was set successfully"
    ],
    
    .
    .
    .
    
    "v41-jack-backend000006": [
      "10:02:54 UTC: Running init script",
      "10:03:24 UTC: Installing weka",
      "10:09:20 UTC: Weka installation completed",
      "10:09:23 UTC: Setting deletion protection authorization error, going to sleep for 2M",
      "10:11:23 UTC: Deletion protection was set successfully"
    ]
  },
  "errors": null
  
```

</details>

<details>

<summary><strong>Cluster formation</strong></summary>

Run the following command to check the cluster status:

```
$ curl https://v41-jack-function-app.azurewebsites.net/api/status?code=$function_key

```

In the following response example, the cluster formation is completed as shown in the third line `"clusterized": true`:

```
{
  "initial_size": 6,
  "desired_size": 6,
  "clusterized": true,
  "weka_status": {
    "hot_spare": 1,
    "io_status": "STARTED",
    "drives": {
      "active": 6,
      "total": 6
    },
    "name": "jack",
    "io_status_changed_time": "2023-04-16T10:15:53.35355Z",
    "io_nodes": {
      "active": 18,
      "total": 18
    },
    "cloud": {
      "enabled": true,
      "healthy": true,
      "proxy": "",
      "url": "https://api.home.weka.io"
    },
    "release_hash": "9756a1524e629d6c02c91bfb63d8239a2b4cce5f",
    "hosts": {
      "active_count": 18,
      "backends": {
        "active": 18,
        "total": 18
      },
      "clients": {
        "active": 0,
        "total": 0
      },
      "total_count": 18
    },
    "stripe_data_drives": 3,
    "release": "4.1.0.71",
    "active_alerts_count": 2,
    "capacity": {
      "total_bytes": 5182871000000,
      "hot_spare_bytes": 1036429300000,
      "unprovisioned_bytes": 0
    },
    "is_cluster": true,
    "status": "OK",
    "stripe_protection_drives": 2,
    "guid": "d4363615-bbae-416b-92f8-2d7304904996",
    "nodes": {
      "black_listed": 0,
      "total": 36
    },
    "licensing": {
      "io_start_eligibility": true,
      "usage": {
        "drive_capacity_gb": 11522,
        "usable_capacity_gb": 5182,
        "obs_capacity_gb": 0
      },
      "mode": "Unlicensed"
    }
  }

```

</details>

{% hint style="success" %}
You can also track the cluster formation progress on the last backend by opening the `/tmp/cluster_creation.log` file.
{% endhint %}

## **Validate the deployment**

Once the deployment is completed, access the WEKA cluster GUI using the URL: `http://<backend server DNS name or IP address>:14000` and get started with the WEKA cluster.

**Related topics**

[Manage the system using the WEKA GUI](/getting-started-with-weka/manage-the-system-using-weka-gui)

[Manage the system using the WEKA CLI](/getting-started-with-weka/manage-the-system-using-weka-cli)

[Perform a basic IO sanity check](/getting-started-with-weka/performing-the-first-io)

## **Update the admin user** password

When deploying a WEKA cluster on the cloud using Terraform, a default username (admin) is automatically generated, and Terraform creates the password. Only the password is stored in the Key Vault of the Azure console. This user facilitates communication between the cloud and the WEKA cluster, particularly during scale-up and scale-down operations.

As a best practice, it’s recommended to update the admin password in the WEKA cluster and the [Azure Key Vault](#user-content-fn-1)[^1].

**Procedure**

1. In the WEKA cluster, update the admin user's password.
2. In the **Azure console**, navigate to **Key Vault**.
3. Update the `weka_password` service with the newly updated password.
4. Validate the changes by checking the results in the [Azure Logic Apps](#user-content-fn-2)[^2] platform and ensuring they pass successfully.

**Related topic**

[Manage users using the GUI](/operation-guide/user-management/user-management#change-a-local-user-password)

## Set the license

To run IOs against the cluster, a valid license must be applied. Obtain a valid license and apply it to the WEKA cluster. For details, see [Licensing overview](/licensing/overview).

## Set up the WEKA cluster to work with your Azure Blob storage

If you create an Azure Blob storage without using Terraform, you can set up the WEKA cluster to work with it.

**Procedure**

1. Gather the following details from your Azure account (refer to the Azure documentation for guidance):
   * Storage account name
   * Storage account container name
   * Storage account access key
2. Connect to one of the instances in your WEKA cluster and run the following command line, replacing the placeholders with your storage account details:

{% code overflow="wrap" %}

```bash
weka fs tier s3 add azure-obs --site local --obs-name default-local --obs-type AZURE --hostname <Storage account name>.blob.core.windows.net --port 443 --bucket <Storage account container name> --access-key-id <Storage account name> --secret-key <Storage account access key> --protocol https --auth-method AWSSignature4
```

{% endcode %}

**Related information**

[Official Azure documentation](https://learn.microsoft.com/en-us/azure/storage/blobs/blob-containers-portal)

## **Clean up the** deployment

If the WEKA cluster is no longer required on Azure or you need to clean up the deployment, use the `terraform destroy` action (a token from [get.weka.io](https://get.weka.io/) is required). The object storage and storage account are not deleted.

{% hint style="warning" %}
The destroy command does not work properly if the Terraform deployment fails for any reason, such as dependencies not being present and Azure resource starvation. Manually remove any resources created at the beginning of the Terraform script using the Azure console or Azure CLI before re-running the Terraform script.
{% endhint %}

{% hint style="info" %}
If you need to preserve your data, create a snapshot using [snap-to-object](/weka-filesystems-and-object-stores/snap-to-obj).
{% endhint %}

[^1]: Azure Key Vault safeguards cryptographic keys and other secrets used by cloud apps and services.\
    For details, see <https://azure.microsoft.com/en-us/products/key-vault>

[^2]: Azure Logic Apps is a cloud platform where you can create and run automated workflows with little to no code. By using the visual designer and selecting from prebuilt operations, you can quickly build a workflow that integrates and manages your apps, data, services, and systems.\
    For details, see <https://learn.microsoft.com/en-us/azure/logic-apps/logic-apps-overview>.


# Required services and supported regions

The region must support the services used in WEKA on Azure. The following sections list these services and the current regions that support them. See the related information below for updates.

## Required services used in WEKA on Azure

* [Lsv3-series](https://learn.microsoft.com/en-us/azure/virtual-machines/lsv3-series) (VM type)
* [Functions](https://learn.microsoft.com/en-us/azure/azure-functions/)
* [Virtual Machine Scale Sets](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/) (VMSS)
* [Key Vault](https://learn.microsoft.com/en-us/azure/key-vault/general/)
* [Zone-redundant storage](https://learn.microsoft.com/en-us/azure/storage/common/storage-redundancy#zone-redundant-storage) (ZRS) Blobs
* [Virtual Network](https://learn.microsoft.com/en-us/azure/virtual-network/)
* [Load Balancer](https://learn.microsoft.com/en-us/azure/load-balancer/) (LB)
* [Logic App](https://learn.microsoft.com/en-us/azure/logic-apps/)
* [Elastic Premium EP2](https://learn.microsoft.com/en-us/azure/azure-functions/functions-premium-plan?tabs=portal) (service plan for the Logic App)

## Supported regions

* **Americas**
  * Brazil South
  * Canada Central
  * Central US
  * East US
  * East US 2
  * North Central US
  * South Central US
  * West US 2
  * West US 3
* **Europe**
  * France Central
  * Germany West Central
  * North Europe
  * West Europe
  * UK South
  * Sweden Central
* **Middle East**
  * Qatar Central
* **Asia**
  * Australia East
  * Australia Southeast
  * Central India
  * Japan East
  * East Asia
  * Southeast Asia

{% hint style="info" %}
Australia Southeast, Canada East, and North Central US do not include the Zone-redundant storage (ZRS) blob. If the snap-to-object feature is required, use a bucket from a different region or a lower durability blob such as the Locally-redundant storage (LRS) blob.
{% endhint %}

**Related information**

[Azure Products available by region](https://azure.microsoft.com/en-us/explore/global-infrastructure/products-by-region/?products=storage)

[Azure regions with availability zone support](https://learn.microsoft.com/en-us/azure/reliability/availability-zones-service-support#azure-regions-with-availability-zone-support)


# Supported virtual machine types

## Supported VM sizes for backends

On Azure, WEKA is deployed in a multi-container architecture using the storage-optimized Lsv3-series and Lasv3-series Azure Virtual Machines (Azure VMs). These VMs feature high throughput, low latency, and directly mapped local NVMe storage.

Each VM size has a specific number of NICs, but only one is used for all traffic in UDP mode through the management interface.

The following table lists the VM sizes applied by the Terraform package on the backends:

<table><thead><tr><th width="200">VM size</th><th width="79">vCPU</th><th width="139">Memory (GiB)</th><th>NVMe disks</th><th width="103">Max NICs</th><th>BW (Mbps)</th></tr></thead><tbody><tr><td>Standard_L8s_v3</td><td>8</td><td>64</td><td>1x1.92 TB</td><td>4</td><td>12500</td></tr><tr><td>Standard_L16s_v3</td><td>16</td><td>128</td><td>2x1.92 TB</td><td>8</td><td>12500</td></tr><tr><td>Standard_L32s_v3</td><td>32</td><td>256</td><td>4x1.92 TB</td><td>8</td><td>16000</td></tr><tr><td>Standard_L48s_v3</td><td>48</td><td>384</td><td>6x1.92 TB</td><td>8</td><td>24000</td></tr><tr><td>Standard_L64s_v3</td><td>64</td><td>512</td><td>8x1.92 TB</td><td>8</td><td>30000</td></tr><tr><td>Standard_L80s_v3</td><td>80</td><td>640</td><td>10x1.92 TB</td><td>8</td><td>32000</td></tr><tr><td>Standard_L8as_v3</td><td>8</td><td>64</td><td>1x1.92 TB</td><td>4</td><td>12500</td></tr><tr><td>Standard_L16as_v3</td><td>16</td><td>128</td><td>2x1.92 TB</td><td>8</td><td>12500</td></tr><tr><td>Standard_L32as_v3</td><td>32</td><td>256</td><td>4x1.92 TB</td><td>8</td><td>16000</td></tr><tr><td>Standard_L48as_v3</td><td>48</td><td>384</td><td>6x1.92 TB</td><td>8</td><td>24000</td></tr><tr><td>Standard_L64as_v3</td><td>64</td><td>512</td><td>8x1.92 TB</td><td>8</td><td>32000</td></tr><tr><td>Standard_L80as_v3</td><td>80</td><td>640</td><td>10x1.92 TB</td><td>8</td><td>32000</td></tr></tbody></table>

{% hint style="info" %}
Using the Azure Console, the client instances can have different virtual machine types provisioned separately from the WEKA cluster.
{% endhint %}

**Related information**

[Lsv3-series](https://learn.microsoft.com/en-us/azure/virtual-machines/lsv3-series) and [Lasv3-series](https://learn.microsoft.com/en-us/azure/virtual-machines/lasv3-series) (Azure learning site)

### Mapped cores to processes

In each virtual machine size, the cores are mapped to a specific number of the compute, drive, and frontend processes. For example, in the Standard\_L16s\_v3 size, the cores are mapped to the following processes:

* Compute: 4
* Drive: 2
* Frontend: 1

<div data-with-frame="true"><figure><img src="/files/vWcDBfoiO64JC8iWXYCd" alt="" width="563"><figcaption><p>Mapped WEKA processes for a standard_L16s_v3</p></figcaption></figure></div>

<table><thead><tr><th>VM size</th><th width="180"># of compute cores</th><th width="161"># of drive cores</th><th># of frontend cores</th></tr></thead><tbody><tr><td>Standard_L8s_v3</td><td>1</td><td>1</td><td>1</td></tr><tr><td>Standard_L16s_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L32s_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L48s_v3</td><td>3</td><td>3</td><td>1</td></tr><tr><td>Standard_L64s_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L80s_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L8as_v3</td><td>1</td><td>1</td><td>1</td></tr><tr><td>Standard_L16as_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L32as_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L48as_v3</td><td>3</td><td>3</td><td>1</td></tr><tr><td>Standard_L64as_v3</td><td>4</td><td>2</td><td>1</td></tr><tr><td>Standard_L80as_v3</td><td>4</td><td>2</td><td>1</td></tr></tbody></table>

## Supported VM sizes for clients

### General purpose virtual machine sizes <a href="#general-purpose-virtual-machine-sizes" id="general-purpose-virtual-machine-sizes"></a>

<table><thead><tr><th width="134">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>Dsv3</td><td>Standard_D4s_v3, Standard_D8s_v3, Standard_D16s_v3</td></tr><tr><td>Dasv4</td><td>Standard_D2as_v4, Standard_D4as_v4, Standard_D8as_v4</td></tr><tr><td>Ddsv4</td><td>Standard_D16ds_v4</td></tr><tr><td>Dasv4</td><td>Standard_D4as_v4, Standard_D16as_v4, Standard_D32as_v4, Standard_D96as_v4</td></tr><tr><td>Dv5</td><td>Standard_D8_v5</td></tr><tr><td>Dsv5</td><td>Standard_D4s_v5 ,Standard_D16s_v5, Standard_D48s_v5 , Standard_D64s_v5</td></tr><tr><td>Dadsv5</td><td>Standard_D4ads_v5, Standard_D16ads_v5, Standard_D48ads_v5, Standard_D96ads_v5</td></tr><tr><td>Dcsv2</td><td>Standard_DC4s_v2 (UDP only)</td></tr><tr><td>Dasv5</td><td>Standard_D2as_v5, Standard_D8as_v5</td></tr><tr><td>Dpldsv5</td><td>Standard_D8plds_v5, Standard_D32plds_v5, Standard_D64plds_v5</td></tr><tr><td>Dpsv5</td><td>Standard_D4ps_v5, Standard_D8ps_v5, Standard_D16ps_v5, Standard_D32ps_v5, Standard_D48ps_v5, Standard_D64ps_v5</td></tr></tbody></table>

### Memory optimized virtual machine sizes

<table><thead><tr><th width="143">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>Edsv4</td><td>Standard_E16ds_v4, Standard_E16-8ds_v4, Standard_E32ds_v4,</td></tr><tr><td>Easv4</td><td>Standard_E32-16as_v4</td></tr><tr><td>Easv5</td><td>Standard_E32-16as_v5</td></tr><tr><td>Edsv4</td><td>Standard_E32-16ds_v4, Standard_E48ds_v4</td></tr><tr><td>Eadsv5</td><td>Standard_E96ads_v5</td></tr><tr><td>Mdmsv2</td><td>Standard_M64dms_v2</td></tr><tr><td>Msv2</td><td>Standard_M208s_v2</td></tr><tr><td>Mmsv2</td><td>Standard_M208ms_v2, Standard_M416ms_v2</td></tr><tr><td>Epsv5</td><td>Standard_E4ps_v5, Standard_E8ps_v5, Standard_E16ps_v5, Standard_E20ps_v5, Standard_E32ps_v5</td></tr></tbody></table>

### Compute optimized virtual machine sizes

<table><thead><tr><th width="143">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>FXmds</td><td>Standard_FX48mds</td></tr><tr><td>Fsv2</td><td>Standard_F8s_v2, Standard_F32s_v2, Standard_F64s_v2, Standard_F72s_v2</td></tr></tbody></table>

### Storage optimized virtual machine sizes

<table><thead><tr><th width="143">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>Lsv3</td><td>Standard_L8s_v3, Standard_L16s_v3, Standard_L32s_v3, Standard_L48s_v3, Standard_L64s_v3, Standard_L80s_v3</td></tr></tbody></table>

### High performance optimized

<table><thead><tr><th width="143">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>HBv4</td><td>Standard_HB176rs_v4, Standard_HB176-24rs_v4, Standard_HB176-96rs_v4</td></tr><tr><td>HBv3</td><td>Standard_HB120rs_v3</td></tr></tbody></table>

### GPU - accelerated compute

<table><thead><tr><th width="143">VM series</th><th>VM size</th></tr></thead><tbody><tr><td>NGads V620</td><td>Standard_NG8ads_V620_v1, Standard_NG16ads_V620_v1, Standard_NG32ads_V620_v1</td></tr><tr><td>NVadsA10</td><td>Standard_NVadsA10_v5</td></tr></tbody></table>

**Related information**

[Sizes for virtual machines in Azure](https://learn.microsoft.com/en-us/azure/virtual-machines/sizes) (Azure site)


# Auto-scale virtual machines in Azure

WEKA provides a resize API to scale up or down the cluster. You must use only this API to resize the cluster. Do not use any other option for resizing.

{% hint style="info" %}
The cluster name prefix, resource group name, and Azure subscription id appear in the `Resize cluster` section of the [Cluster help commands](/planning-and-installation/weka-installation-on-azure/deployment-on-azure-using-terraform#cluster-help-commands) output.
{% endhint %}

**Procedure:**

1. Get the resize API (function-app).\
   Run the command:

```
function_key=$(az functionapp keys list --name <cluster name prefix>-function-app --resource-group <resource group name> --subscription <Azure subscription id> --query functionKeys -o tsv)

```

2. Resize the cluster.\
   Enter the value of the required number of virtual machines instead of `ENTER_NEW_VALUE_HERE` (the minimum value is `6`), and run the command:

```
curl --fail https://<cluster name prefix>-function-app.azurewebsites.net/api/resize?code=$function_key -H "Content-Type:application/json" -d '{"value":ENTER_NEW_VALUE_HERE}'

```

3. Track the resize progress using the commands provided in the [Check the deployment progress](/planning-and-installation/weka-installation-on-azure/deployment-on-azure-using-terraform#check-the-deployment-progress) section.


# Add clients to a WEKA cluster on Azure

When deploying a WEKA cluster, it is possible to create clients using Terraform. After completing this step, you can expand the number of clients in your WEKA system by performing the following procedure.

## Before you begin

* Create a client VM using one of the following methods:
  * **Using the Azure Console:** Create the client VM that meets the following requirements:
    * The *Accelerated Networking* feature must be enabled in the NICs.
    * The NICs must be configured with at least MTU 3900.
    * Ensure a supported OFED is installed.
    * Remove the secondary default gateway from the routing table.
    * If working with a different security type than the standard, for example, trusted launch virtual machines, clear the **Enable secure boot** option in the **Configure security features**.
  * **Using a custom image of a WEKA client:**
    * In the Azure console, search for the community image named **weka** with ID `WekaIO-d7d3f308-d5a1-4c45-8e8a-818aed57375a`. The **weka** custom image includes ubuntu 20.04 with kernel 5.4 and ofed 5.8-1.1.2.1.
    * Enable the *Accelerated Networking* feature in the NICs.
    * Configure the NICs to operate with at least MTU 3900.
* Ensure the client has enough available IP addresses in the selected subnet. Each core allocated to WEKA requires a NIC (and IP address).

## Mount the filesystem

1. Create a mount point (only once):

```
mkdir /mnt/weka
```

1. Install the WEKA agent on your client machine (only once):

```bash
curl <backend server IP address>:14000/dist/v1/install | sh
```

Example:

```bash
curl http://10.0.0.7:14000/dist/v1/install | sh
```

2. Detect the existing network configuration. Run the command: `ip a`.

<details>

<summary><code>ip a</code> command output example</summary>

<pre class="language-bash" data-overflow="wrap"><code class="lang-bash"><strong>root@jack:~# ip a
</strong>1: lo: &#x3C;LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: &#x3C;BROADCAST,MULTICAST,UP,LOWER_UP> mtu 3900 qdisc mq state UP group default qlen 1000
    link/ether 00:0d:3a:8e:3a:67 brd ff:ff:ff:ff:ff:ff
    inet 10.0.0.30/24 brd 10.0.0.255 scope global eth0
       valid_lft forever preferred_lft forever
    inet6 fe80::20d:3aff:fe8e:3a67/64 scope link
       valid_lft forever preferred_lft forever
3: eth1: &#x3C;BROADCAST,MULTICAST,UP,LOWER_UP> mtu 4038 qdisc mq state UP group default qlen 1000
    link/ether 00:0d:3a:8b:d9:bd brd ff:ff:ff:ff:ff:ff
    inet 10.0.0.31/24 brd 10.0.0.255 scope global eth1
       valid_lft forever preferred_lft forever
    inet6 fe80::20d:3aff:fe8b:d9bd/64 scope link
       valid_lft forever preferred_lft forever
4: enP18334s1np0: &#x3C;BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 3900 qdisc mq master eth0 state UP group default qlen 1000
    link/ether 00:0d:3a:8e:3a:67 brd ff:ff:ff:ff:ff:ff
5: enP39539s2np0: &#x3C;BROADCAST,MULTICAST,SLAVE,UP,LOWER_UP> mtu 4038 qdisc mq master eth1 state UP group default qlen 1000
    link/ether 00:0d:3a:8b:d9:bd brd ff:ff:ff:ff:ff:ff
6: dtap0: &#x3C;BROADCAST,MULTICAST,UP,LOWER_UP> mtu 4038 qdisc multiq state UNKNOWN group default qlen 1000
    link/ether 00:0d:3a:8b:d9:bd brd ff:ff:ff:ff:ff:ff
    inet6 fe80::20d:3aff:fe8b:d9bd/64 scope link
       valid_lft forever preferred_lft forever
</code></pre>

</details>

3. Once the WEKA cluster runs, you can mount clients to the filesystem using the following command:

{% code overflow="wrap" %}

```bash
mount -t wekafs <backend-server-IP-address>/<filesystem-name> -o net=<VF interface>/<synthetic network interface IP address>/mask -o mgmt_ip=<Management-IP> /mnt/weka
```

{% endcode %}

Where:

* `<VF interface>/<synthetic network interface IP address>/mask`: The VF interface and synthetic network interface are automatically paired and act as a single interface in most aspects used by applications. The synthetic interface always has a name in the form `eth\<n\>`.\
  You can identify the VF interface and synthetic network interface pair by their common MAC address. In the example above, the VF interface is `enP39539s2np0` (item 5), and the synthetic network interface is `eth1` (item 3), which has the IP address and mask 10.0.0.31/24.
* `<Management-IP>`: In the example above, it the `eth0` management IP `10.0.0.30`.

{% hint style="info" %}
The `mgmt_ip` option identifies management processes on the data plane network. It does not identify external management interfaces such as the CLI or REST API.
{% endhint %}

Example:

{% code overflow="wrap" fullWidth="false" %}

```bash
mount -t wekafs 10.0.0.7/default -o net=enP39539s2np0/10.0.0.31/24 -o mgmt_ip=10.0.0.30 /mnt/weka

```

{% endcode %}

{% hint style="info" %}
Using the Azure Console, the client instances are provisioned separately from the WEKA cluster.
{% endhint %}

**Related topics**

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems)


# Troubleshooting

During the deployment process, errors may occur. You can use the Azure Console tools to verify the resource status and the Azure quota limitations.

For additional Terraform logs during the WEKA cluster deployment, you can run the Terraform with the option `TF_LOG variable=ERROR`.

The following is a partial list of errors and the corrective actions that may occur during the deployment:

### Error when creating virtual machines

When deploying the WEKA cluster, an error indicates that more virtual machines have been requested than the quota limit in your Azure subscription.

**Resolution:**

Submit a quota increase to Microsoft Azure using the URL specified in the error message.

For more details, see [Increase VM-family vCPU quotas](https://learn.microsoft.com/en-us/azure/quotas/per-vm-quota-requests) on the Microsoft site.

### The storage account name is already taken

Creating a storage account name must be unique across the Azure environment.

**Resolution:**

In the Terraform variables file, ensure the `prefix` and `cluster_name` variables are unique.

The specified resource group in the Terraform variables file was not found because it was not created (as part of the prerequisites).

**Resolution:**

Create the Azure resource group before applying the Terraform file using the Azure console or Azure CLI.

In Azure CLI, use the following command:

`az group create --name <myResourceGroup> --location <region>`

Example:

`az group create --name weka-jack-rg --location eastus`

**Related topics**

[Deployment on Azure using Terraform](/planning-and-installation/weka-installation-on-azure/deployment-on-azure-using-terraform#prerequisites)


# Detailed deployment tutorial: WEKA on Azure using Terraform

This guide provides step-by-step instructions for deploying the WEKA Data Platform on Microsoft Azure using Terraform, tailored for customers, partners, and WEKA teams.

## Introduction

Deploying WEKA in Azure involves familiarity with Microsoft Azure Cloud, Terraform (for infrastructure-as-code provisioning), basic Linux operations, and WEKA software. Recognizing that not all individuals responsible for this deployment may have experience in every area, this document offers a comprehensive, step-by-step guide to successfully deploying a WEKA cluster in Azure, even with minimal prior knowledge.

**Document scope**

This document provides guidance on deploying WEKA in an Azure environment with an existing networking configuration. For Proof of Concept (POC) or production deployments, the process involves using the customer's existing Azure Virtual Network (VNet), subnet, and Network Security Group.

This document guides you through:

* General Azure requirements.
* Azure networking requirements necessary for WEKA.
* Deployment of WEKA using Terraform.
* Verification of a successful of WEKA deployment.

{% hint style="info" %}
The images embedded in this document may appear small when viewed in-line. Double-clicking on an image enlarges it to its original size for easier viewing.
{% endhint %}

## Administrative prerequisites

Before deploying WEKA in Microsoft Azure, ensure that the target environment is properly configured. Several key components must be set up before deploying WEKA using Terraform to ensure a successful outcome. The following subsections provide a step-by-step guide for configuring each component according to WEKA requirements.

### Identify your Azure Subscription

Azure environments are organized within a Subscription[^1], which serves as the primary construct containing resource groups, VNets, subnets, security groups, virtual machine instances, and other resources. The initial step in deploying WEKA in Azure is to identify the subscription where the WEKA resources will be deployed.

**Procedure**

1. Navigate to the Microsoft Azure Portal. Search for **Subscriptions** and select it.

<div data-with-frame="true"><figure><img src="/files/ETJo96zWuCUnq8KdKR7B" alt=""><figcaption></figcaption></figure></div>

2. On the **Subscriptions** page, locate the subscription you plan to use for deploying WEKA.

   Ensure you understand the Azure Subscription structure for your environment before proceeding with the deployment.

<div data-with-frame="true"><figure><img src="/files/fta4vylN3IFxC92Td820" alt=""><figcaption></figcaption></figure></div>

### Verify user privileges assignment

To successfully deploy WEKA in Microsoft Azure, ensure the account used is a Subscription Contributor. If the user lacks this role, the deployment steps will fail. If an existing user cannot be used, create a new user with the necessary rights within the Subscription.

**Procedure**

1. Log in to the Azure Portal using the account intended for the WEKA deployment. Search for **Users** and select it.

<div data-with-frame="true"><figure><img src="/files/JLaG8bKZNtVFGNEBltMO" alt=""><figcaption></figcaption></figure></div>

2. Locate the user by typing part of their username and select their name from the list.

<div data-with-frame="true"><figure><img src="/files/HZuXRq47ikd2c3NNJhP1" alt=""><figcaption></figcaption></figure></div>

3. On the user page, select **Azure Role Assignments**.

<div data-with-frame="true"><figure><img src="/files/3USiRzTb7JFWFJ99mq1d" alt=""><figcaption></figcaption></figure></div>

4. Verify the user's roles to ensure they are assigned as an **Owner** or **Contributor** for the Subscription used for WEKA deployment.

<div data-with-frame="true"><figure><img src="/files/nFhh9qAMfWA5c5eVc46y" alt=""><figcaption></figcaption></figure></div>

After confirming the user's permissions, verify the resource quotas.

### Verify resource quotas

When deploying resources in Microsoft Azure, ensure sufficient quotas are set for the specific resources needed. For instance, when deploying Lsv3 virtual instances for the WEKA backend cluster, configure an adequate vCPU quota for the Lsv3 instance type. Azure specifies quotas on a per-instance or per-instance-family basis.

If you or your customer have not used a particular instance type before, you must set a sufficient quota to avoid failures during deployment with Terraform. The minimum quota required is equal to the total number of vCPUs needed for the deployment.

**Procedure**

1. In the Azure Portal, search for **Quotas** and select it.

<div data-with-frame="true"><figure><img src="/files/klIeAstQlpngHTDsbMUz" alt=""><figcaption></figcaption></figure></div>

2. On the quotas page, select **Compute**.

<div data-with-frame="true"><figure><img src="/files/BYfQO2k0bMtlvesz5rwe" alt=""><figcaption></figcaption></figure></div>

3. Search for the instance family or specific instance for which you need to set or check the quota. For example, Dsv5 instances.

<div data-with-frame="true"><figure><img src="/files/L7KIulZojBWYX5eKoPHN" alt=""><figcaption></figcaption></figure></div>

4. Select the checkbox next to the desired instance type, open the **Request quota increase** dropdown, and **Enter a new limit**.

<div data-with-frame="true"><figure><img src="/files/q0FHgUKU4ad51dv1Lql1" alt=""><figcaption></figcaption></figure></div>

5. In the Request quota increase section, enter the desired number of vCPUs for the instance type or family. For instance, request a new vCPU quota of 150 for the Standard Dsv5 family. Select **Submit**.

<div data-with-frame="true"><figure><img src="/files/83PLuhpuJ2zY9zfwnGtv" alt=""><figcaption></figcaption></figure></div>

6. Most quota increase requests are approved in real-time, without needing Azure support. However, if requesting a large number of vCPUs or a specialized instance, contacting Azure support may be necessary. The example demonstrates a successful vCPU increase request.

<div data-with-frame="true"><figure><img src="/files/1B6dmzL1dOY66dkplUV4" alt=""><figcaption></figcaption></figure></div>

7. Ensure quotas are set for all instances required for the deployment. For WEKA backends, set the quota for the Lsv3 instance family, and any other instance families used for WEKA clients. For a complete listing of available instance sizes, see [Supported virtual machine types](/planning-and-installation/weka-installation-on-azure/supported-virtual-machine-types).

## Azure resource prerequisites

Running WEKA in Azure requires Azure cloud resources for compute, storage, networking, and security. For internal testing, customer POC, or production deployment, a minimum resource configuration is necessary for successful operation.

Many customers may have pre-existing Azure environments that include the required resources, though confirmation is necessary. The following steps assume WEKA is being deployed into a “[blank slate](#user-content-fn-2)[^2]” Azure environment. These instructions also help navigate a customer’s existing environment to ensure WEKA prerequisites are met.

### Create a Resource Group

A Microsoft Azure Resource Group is a fundamental organizational unit that acts as a logical container for resources within an Azure Subscription. It holds resources such as virtual machines, VNets, security groups, and storage accounts. A Resource Group must be available for deploying WEKA and its dependencies.

{% hint style="info" %}
If corporate policies require separating WEKA compute or client instances from network resources, Terraform deployment scripts can accommodate this, as detailed in a later section.
{% endhint %}

**Procedure**

1. In the Azure Portal, search for **Resource groups** and select it.

<div data-with-frame="true"><figure><img src="/files/3SyzdiTNNNmGSu1uOR9v" alt=""><figcaption></figcaption></figure></div>

2. On the Resource groups page, select **Create**.

<div data-with-frame="true"><figure><img src="/files/CPLDEdNKSqNobZhZS3rJ" alt=""><figcaption></figcaption></figure></div>

3. On the Create resource group page, enter the required details, ensuring you select the correct subscription and region. Select **Review + create**.\
   (Once named, a Resource Group cannot be renamed.)

<div data-with-frame="true"><figure><img src="/files/j6KsPKSt1bXTUg5W5Vga" alt=""><figcaption></figcaption></figure></div>

4. Select **Create** to confirm.

<div data-with-frame="true"><figure><img src="/files/osBDykdC2Fzyk6m4Lf2Y" alt=""><figcaption></figcaption></figure></div>

5. Review the newly created Resource Group.

<div data-with-frame="true"><figure><img src="/files/DWBMhgv6d4WmpPyNXW6E" alt=""><figcaption></figcaption></figure></div>

### Create a VNet

A Virtual Network (VNet) in Microsoft Azure is essential for secure communication between Azure resources, such as virtual machines (VMs), and for connecting to the internet and on-premises networks.

A VNet provides logical isolation within the Azure cloud, dedicated to a subscription, and includes subnets that allocate IP address space to VMs.

For WEKA deployment, both management and DPDK traffic must use VNets, with all WEKA cluster backends and POSIX clients placed within the same VNet and subnet. Contact the the [Customer Successes Team](/support/getting-support-for-your-weka-system) for additional guidance.

**Procedure**

1. In the Azure Portal, search for **Virtual networks** and select it.

<div data-with-frame="true"><figure><img src="/files/HDenMGqTYQzsDYTmAYIJ" alt=""><figcaption></figcaption></figure></div>

2. On the Virtual networks page, Select **Create**.

<div data-with-frame="true"><figure><img src="/files/Iy6BHudWaNZ4eK8Aj190" alt=""><figcaption></figcaption></figure></div>

3. On the Create virtual network page, enter the VNet configuration details, including the subscription and resource group from the previous step. Provide a VNet name and region, then Select **Next: IP Addresses**.

<div data-with-frame="true"><figure><img src="/files/qDlRQfGoQsEaoE3ta1EF" alt=""><figcaption></figcaption></figure></div>

4. In the IP Addresses section, specify the IP address space and adjust the default subnet configuration as needed. Select **Review + create** when done.

<div data-with-frame="true"><figure><img src="/files/OENoVNDNvpD0dCzt7FTQ" alt=""><figcaption></figcaption></figure></div>

5. Select **Creat**e to confirm.

<div data-with-frame="true"><figure><img src="/files/lWGFQ3D5UTVEaGCNNsu9" alt=""><figcaption></figcaption></figure></div>

6. After creation, review the confirmation page and verify the new VNet.

<div data-with-frame="true"><figure><img src="/files/Pys03uliNL0FvfFtP8Di" alt=""><figcaption></figcaption></figure></div>

### Create a Network Security Group (NSG)

A Network Security Group (NSG) manages network traffic to Azure resources by applying security rules to control ingress (incoming) and egress (outgoing) traffic. It functions as a firewall for network interfaces (NICs), virtual machines (VMs), and subnets.

{% hint style="info" %}
NSGs start with default rules for basic connectivity, such as allowing outbound communication and denying all inbound traffic from the internet. Custom rules can override these defaults.
{% endhint %}

**Procedure**

1. In the Azure Portal, search for **Network security groups** and select it.

<div data-with-frame="true"><figure><img src="/files/kTU3J61sMQReBfExhUhR" alt=""><figcaption></figcaption></figure></div>

2. On the Network security groups page, Select **Create**.

<div data-with-frame="true"><figure><img src="/files/BUHOY96cZxsGL4Lv4IE3" alt=""><figcaption></figcaption></figure></div>

3. On the Create network security group page, enter the required details, including the subscription and resource group from earlier steps. Ensure the region matches other resources. Select **Review + create**.

<div data-with-frame="true"><figure><img src="/files/7AtYpnJBKXfio9wvolDX" alt=""><figcaption></figcaption></figure></div>

4. Select **Create** to confirm.

<div data-with-frame="true"><figure><img src="/files/7dsTcOGnl4qlT7dVr3GZ" alt=""><figcaption></figcaption></figure></div>

5. After creation, review the confirmation page and verify the new Network Security Group.

<div data-with-frame="true"><figure><img src="/files/UF7cnwBfUwyqGLQMPCeB" alt=""><figcaption></figcaption></figure></div>

### Associate a Network Security Group with a Subnet

Azure Network Security Groups (NSGs) must be associated with either a subnet or a network interface card (NIC) to be effective. In this deployment example, associate the NSG with the subnet created earlier.

In a customer environment, it might be necessary to adapt these associations based on the existing network architecture and security requirements.

**Procedure**

1. Search for **Virtual networks** in the Azure Portal and select it.

<div data-with-frame="true"><figure><img src="/files/HDenMGqTYQzsDYTmAYIJ" alt=""><figcaption></figcaption></figure></div>

2. Select the relevant virtual network from the list.

<div data-with-frame="true"><figure><img src="/files/BN5ll1rONzpAzeeDD2SH" alt=""><figcaption></figcaption></figure></div>

3. In the virtual network configuration screen, Select **Subnets**.

<div data-with-frame="true"><figure><img src="/files/6ADK4VpD97e5GvJ5X9k3" alt=""><figcaption></figcaption></figure></div>

4. Select the relevant subnet (in this example, the default subnet).

<div data-with-frame="true"><figure><img src="/files/Qfb8EluFXk5xxZDY8CNA" alt=""><figcaption></figcaption></figure></div>

5. On the subnet configuration screen, locate the **Network security group** dropdown and select the previously created NSG.

<div data-with-frame="true"><figure><img src="/files/zrBEbBN00qOMYrZEJln6" alt=""><figcaption></figcaption></figure></div>

6. Confirm the selection and select **Save**.

<div data-with-frame="true"><figure><img src="/files/UsVFf9w8qzTyDEAPcKrs" alt=""><figcaption></figcaption></figure></div>

### Create and associate a NAT Gateway

Azure NAT (Network Address Translation) Gateway simplifies outbound-only Internet connectivity for virtual networks. It translates private IP addresses of VMs or other resources to a public IP address, allowing outbound internet access without exposing resources to inbound traffic.

For WEKA deployments, the NAT Gateway provides outbound internet access needed to reach repositories and obtain installation binaries, enhancing security by avoiding public IP assignments on individual instances.

In environments with restricted internet access, alternative solutions are covered later in this document.

NAT Gateways must be created and associated with the subnet needing outbound internet access. The creation wizard facilitates both steps in one process.

**Procedure**

1. In the Azure Portal, search for **NAT gateways** and select it.

<div data-with-frame="true"><figure><img src="/files/G63JdpNOh2McMFJc3hR9" alt=""><figcaption></figcaption></figure></div>

2. On the NAT gateways page, select **Create**.

<div data-with-frame="true"><figure><img src="/files/1nNvLxOX8XEkyC0KSP2N" alt=""><figcaption></figcaption></figure></div>

3. On the Create network address translation (NAT) gateway page, enter the required details. Select the correct subscription and resource group, specify a name and region, and select **Next: Outbound IP**.

<div data-with-frame="true"><figure><img src="/files/hk1FZQyxqB9RwP9815L8" alt=""><figcaption></figcaption></figure></div>

4. In the Outbound IP section, select **Create a new public IP address**, enter a name for the public IP, and select **OK**.

<div data-with-frame="true"><figure><img src="/files/jiPAgooJsnsIukZnaCNk" alt=""><figcaption></figcaption></figure></div>

5. Ensure the Public IP address dropdown displays the newly created IP name. Select **Next: Subnet**.

<div data-with-frame="true"><figure><img src="/files/PbbQImcUCSt8TWpZpaW8" alt=""><figcaption></figcaption></figure></div>

6. In the Subnet section, select the previously created VNet and subnet. Select **Review + create**.

<div data-with-frame="true"><figure><img src="/files/0MY6cbPo7JjXRDDR8zRM" alt=""><figcaption></figcaption></figure></div>

7. Select **Create** to confirm.

<div data-with-frame="true"><figure><img src="/files/E7KBFODX6dwCOpSairez" alt=""><figcaption></figcaption></figure></div>

8. Upon completion, review the newly created NAT Gateway on the confirmation page.

<div data-with-frame="true"><figure><img src="/files/kVIL4BtMwRSo3Dq2b4aL" alt=""><figcaption></figcaption></figure></div>

#### Install AzureCLI

Terraform uses Azure CLI to pass commands to Azure. It is recommended to install the latest version. The following steps use version 2.50, which is current at the time of writing.

**Procedure**:

1. Open a terminal and run the following command to install Azure CLI through Homebrew:

```bash
brew update && brew install azure-cli
```

<figure><img src="https://github.com/weka/docs-weka-io/blob/4.4/.gitbook/assets/azure_cli_install.png" alt=""><figcaption></figcaption></figure>

2. Wait for the installation to complete.

<div data-with-frame="true"><figure><img src="/files/nUeQF4L4HnZtRSNNZ2k5" alt=""><figcaption></figcaption></figure></div>

3. To confirm the installation, run:

```bash
az version
```

The installed version of Azure CLI is displayed.

<figure><img src="https://github.com/weka/docs-weka-io/blob/4.4/.gitbook/assets/azure_cli_installed.png" alt=""><figcaption></figcaption></figure>

### Log in to Azure CLI

Terraform uses Azure CLI to perform operations within an Azure subscription.

**Before you begin**

Before running Terraform, the Azure user must authenticate through the Azure CLI. See [#identify-your-azure-subscription](#identify-your-azure-subscription "mention")

**Procedure:**

1. Open a terminal session and enter the command:

```bash
az login
```

<div data-with-frame="true"><figure><img src="/files/Gczosvn1wpjpaY4ehB2Y" alt=""><figcaption></figcaption></figure></div>

2. A web browser opens, prompting the user to select an account for authentication. Select the user or enter the credentials.

After successful authentication, a confirmation message appears.

<figure><img src="https://github.com/weka/docs-weka-io/blob/4.4/.gitbook/assets/azure_login.png" alt=""><figcaption></figcaption></figure>

3. Return to the terminal, where the authentication status of Azure CLI is displayed.

<div data-with-frame="true"><figure><img src="/files/e2Dbudnh5OPsTjP2JULq" alt=""><figcaption></figcaption></figure></div>

## Deploy WEKA in Azure using Terraform Registry

The **Terraform Registry** is a repository of modules and resources that simplifies the deployment process by providing reusable components.

Before deploying WEKA in Azure with Terraform, several prerequisites must be met. These requirements depend on the type of deployment—whether you're integrating with an existing Azure network and resources or allowing the WEKA Terraform package to automatically create the necessary infrastructure.

The following section outlines the required Azure dependencies for Terraform, explaining each in the context of a successful WEKA deployment.

### Terraform dependencies and constructs

When deploying WEKA in Azure using Terraform, several Azure resources must be created either automatically by Terraform or manually in advance, depending on your deployment method. These resources include:

* **Virtual Machine Scale Set (VMSS):** Azure's VMSS service enables the deployment and management of identical virtual machine instances that scale automatically based on demand. In a WEKA deployment, the VMSS hosts all backend instances and uses Placement Groups to optimize performance.
* **Placement Groups:** These groups control the distribution of VM instances within a scale set, optimizing network traffic and providing fault tolerance. For WEKA, only single-placement groups are supported, allowing up to 100 VM instances in a backend cluster.
* **Resource Groups:** Azure Resource Groups act as logical containers for cloud resources. A Resource Group must be available to organize and deploy all WEKA and Azure dependencies, including virtual machines, VNets, and security components.
* **Virtual Network (VNet):** A VNet is a core networking component that allows secure communication between Azure resources and external networks. WEKA uses VNets for management and DPDK traffic to ensure optimal performance. VNets also contain subnets, which assign IP addresses to virtual machines.
* **Subnet:** Subnets are IP address ranges within a VNet, providing network segmentation to organize and secure resources in a structured manner.
* **Delegated Subnets:** Delegated subnets allow specific Azure services to create resources within a designated subnet. In WEKA deployments, these are used for function and logic apps that enable cluster scaling and auto-healing.
* **Network Security Group (NSG):** An NSG acts as a firewall, filtering network traffic to and from Azure resources based on security rules. For WEKA, a self-referencing rule is recommended to facilitate secure communication within the network.
* **Private DNS Zone:** This zone provides DNS resolution within Azure VNets for private network environments. In a WEKA deployment, it enables name resolution for VMs, application services, and WEKA components connected to the VNets.

### Deployment prerequisites

Before deploying WEKA using Terraform, ensure that any required resources are pre-created if Terraform will not be provisioning them automatically. For example, if you plan to use an existing VNet, it must be created in advance. In most customer environments, many of these resources are likely already available.

The steps in this guide are educational and serve as general guidelines for creating Azure prerequisites, as previously outlined.

#### Navigate the Terraform Registry and obtain the files

Using the Terraform Registry simplifies managing the latest Terraform releases, ensures clean version control, and requires only one `main.tf` file for configuration.

1. Access the WEKA namespace on the Terraform Registry: [Terraform Registry WEKA Namespace](https://registry.terraform.io/namespaces/weka).
2. Select **weka/weka** module to create weka cluster on Azure using TF.
3. From the **Examples** options, select the deployment type (`public_network` in this example).
4. Select the **GitHub source code** link.
5. On the GitHub page, select the `main.tf` file for the **public\_network** example.
6. Click **Download raw file** to save the `main.tf` file.

{% hint style="info" %}
Examples serve as a starting point. Customize the variables to match your specific deployment needs. Do not use the example "as is" expecting it to deliver the exact outcome for your environment.
{% endhint %}

#### Resources and guidance in the Terraform Registry page

This module provides extensive resources and guidance, divided into several sections:

* **README:** Serves as a detailed guide on how the module works, replacing the traditional GitHub README file.
* **Inputs:** Lists all configurable variables, such as VNet selection, resource groups, and instance types. This is where you tailor your WEKA deployment.
* **Outputs:** Lists outputs available after running `terraform apply`, such as cluster status, auto-created WEKA password retrieval from KeyVault, and SSH keys.
* **Dependencies:** Describes provider dependencies automatically installed during `terraform init`.
* **Resources:** Lists Azure resources the module may create, depending on user-configured variables.

### Locate the user’s token in get.weka.io

The user's token in get.weka.io provides access to WEKA binaries and is required during installation.

**Procedure:**

1. Visit [get.weka.io](https://get.weka.io/ui/dashboard), and select the user’s name in the upper-right corner.
2. From the left-hand menu, select **API Tokens**. The user's API token is displayed on the screen and will be used later in the installation process.

### Select variables and edit the main.tf

To configure the deployment, open the downloaded `main.tf` file in your preferred code editor. Follow these steps to customize the necessary variables for your environment:

1. **Under provider "azurerm":**
   * Replace `subscription_id` with the Azure subscription ID for your deployment environment.
   * Leave the `partner_id` as `f13589d1-f10d-4c3b-ae42-3b1a8337eaf1` (this identifies WEKA as a partner for Azure resource spend).
2. **Under module "weka\_deployment":**
   * Set `source = "../../"` to specify the module source location.
   * Update `prefix = "weka"` to define the cluster prefix for Azure resources.
   * Set `rg_name = "weka-rg"` to reference the pre-created Azure resource group.
   * Replace `get_weka_io_token = var.get_weka_io_token` with your unique WEKA software download token from [get.weka.io](https://get.weka.io).
   * Ensure `subscription_id = var.subscription_id` is set to your Azure subscription ID.
   * Change `cluster_name = "poc"` to your desired custom cluster name (this will be appended to the prefix).
   * Set `tiering_enable_obs_integration = true` to enable object tiering if required.
   * Adjust `cluster_size = 6` to define the number of WEKA backend members for the cluster.
   * Set `allow_ssh_cidrs = ["0.0.0.0/0"]` to allow SSH access to cluster members from a defined WAN address range (since this is a public network).
   * Set `allow_weka_api_cidrs = ["0.0.0.0/0"]` to allow API access to WEKA from a defined WAN address range.

Several default example variables will be modified, and others will be added to align with this guide's deployment into an existing public network.

{% hint style="info" %}
**Important note:**\
Many of the Terraform variables listed on the [Terraform Registry page for the Azure WEKA module](https://registry.terraform.io/modules/weka/weka/azure/latest) under the [Inputs](https://registry.terraform.io/modules/weka/weka/azure/latest?tab=inputs) section have pre-set default values. If a variable is not explicitly defined in your `main.tf`, the defaults automatically apply. It is recommended to review these variables to ensure that the defaults meet your deployment needs.
{% endhint %}

<div data-with-frame="true"><figure><img src="/files/mJA5w5o6nz8ulqj707Tp" alt=""><figcaption></figcaption></figure></div>

#### **Customized `main.tf` example**

The following is a customized version of the `main.tf` file, which will be used in this guide to deploy a WEKA cluster.

<div data-with-frame="true"><figure><img src="/files/inoxv2BFwHh7Mpt6HNEU" alt=""><figcaption></figcaption></figure></div>

**Variable descriptions of the customized `main.tf` example:**

* **Under provider "azurerm":**
  * `subscription_id = "azure_subscription_id_here"`: Fill this in with the Azure subscription associated with your deployment environment.
* **Under module "weka\_deployment":**
  * `source = "weka/weka/azure"`: Specifies the Terraform Registry module source for WEKA on Azure.
  * `version = "4.0.5"`: Sets the version of the WEKA Terraform module.
  * `prefix = "weka"`: Prefix for the Azure resources created (customizable).
  * `rg_name = "bgcadv"`: The name of the existing Azure resource group for deployment.
  * `vnet_name = "bgcadv"`: The existing VNet where WEKA resources will be deployed.
  * `subnet_name = "default"`: The existing subnet within the VNet for WEKA deployment.
  * `get_weka_io_token = "your_token_here"`: WEKA download token.
  * `subscription_id = "azure_subscription_id_here"`: The Azure subscription ID for deployment.
  * `cluster_name = "bgcadv0"`: Name for the deployed cluster (appended to the prefix).
  * `tiering_enable_obs_integration = false`: Disables object integration.
  * `instance_type = "Standard_L8s_v3"`: Specifies the Azure instance type for WEKA backend servers.
  * `cluster_size = 6`: Defines the number of WEKA backends for deployment.
  * `allow_ssh_cidrs = ["0.0.0.0/0"]`: Allows SSH access to the cluster from any WAN address.
  * `allow_weka_api_cidrs = ["0.0.0.0/0"]`: Allows API access from any WAN address.
  * `clients_number = 2`: Specifies the number of WEKA clients to deploy and mount automatically.
  * `client_instance_type = "Standard_D4_v4"`: Sets the instance type for the automatically deployed WEKA clients.
* The final entry instructs Terraform to output useful information for verifying the WEKA cluster's deployment and connection:

  ```hcl
  output "get-cluster-helpers-commands" {
     value = module.weka_deployment
  }
  ```

### Initialize and run Terraform

Once the `main.tf` file is customized, do the following:

1. Open a terminal window on your local machine (or the machine where Terraform will be run).
2. Navigate to the directory containing the edited `main.tf` file.
3. Run the following command to initialize Terraform:

```bash
terraform init
```

This action downloads the necessary WEKA Azure Terraform modules and provider plugins.

<figure><img src="/files/8fHWiTlAads07aRUpU8M" alt=""><figcaption></figcaption></figure>

4. After initialization, run the following command to perform a dry run:

```bash
terraform plan
```

This action checks the deployment configuration for issues but cannot account for quota limitations or naming conflicts (for example, KeyVault).

<figure><img src="/files/cp7QU5QClsL1yZzLq1iv" alt=""><figcaption></figcaption></figure>

5. Apply the deployment by running:

```bash
terraform apply
```

A successful deployment displays an output similar to the following example, including the `get-cluster-helpers-commands` output for connecting to and verifying the WEKA cluster.

<figure><img src="/files/J0dul1wo5Dt5vfsxtIrQ" alt=""><figcaption></figcaption></figure>

#### Locate and copy the WEKA Cluster SSH Key to Azure Jump Box

The WEKA cluster SSH key created during terraform deployment is required to access the WEKA cluster backend members, as well as any WEKA clients that were deployed via terraform.

**Procedure**

1. Navigate to the `/tmp/` directory.

<figure><img src="/files/dM0TPqUUDO54H7PRnpKF" alt=""><figcaption></figcaption></figure>

2. Locate both the public (.pub) and private (.pem) key files.
3. Use SCP to transfer the private key (.pem) file from the local machine’s `/tmp/` directory to the Azure linux jump box. Text highlighted in purple should be copied and used directly for your specific SCP command. Text in green should be customized to your unique values.\
   \
   `azureuser` is the default user account created when creating a new virtual machine instance in Azure. It is recommended to keep this default. The first path highlighted in green is the path to the private key for your Azure jump box. The second path is for the private key for the newly created WEKA cluster you’d like to transfer to the Azure jump box. The IP address should be changed to the Azure public IP of your jump box. The WEKA cluster private key should be transferred to the `.ssh` directory in the default azureuser’s home directory on the jump box.

<figure><img src="/files/90rcmJE9PCF74OkdUX3U" alt=""><figcaption></figcaption></figure>

If the command has been configured correctly, an output similar to below should be printed to the terminal upon completion of private key transfer.

#### Monitor deployment status

When deploying into a customer’s Azure environment, it’s likely they’ll already have some means of connectivity to the vnet and subnet into which WEKA has been deployed. This could be by way of a VPN, [bastion host](https://azure.microsoft.com/en-us/products/azure-bastion), or preconfigured jump box. If the customer doesn’t have any means of accessing the WEKA cluster on the isolated subnet, they’ll need to configure one of the methods mentioned above. In this example, a preconfigured Ubuntu linux jump box with a publicly assigned IP will be used. The jump box is in the same vnet, network security group, and subnet as the WEKA cluster, though inbound access rules have been applied to the network security group to facilitate access from the outside on SSH port 22.

Some form of access to the WEKA cluster will be crucial for monitoring the deployment progress and ensuring everything completes successfully.

**Procedure**

1. Navigate to Virtual Machines in the Azure portal. Locate the virtual machine instance with the suffix `clusterizing` . The `clusterizing` suffix is only visible in the Azure portal to denote the WEKA backend cluster member that runs post resource deployment clusterization scripts. Note that the virtual machine’s actual name is `demo-bgc-backend-5`.
2. Identify the local network IP address of the `clusterizing` instance’s management interface. Take note of the IP address, as it will be used in the next step.

<figure><img src="/files/diNR2v0ttrCbwQZphmhP" alt=""><figcaption></figcaption></figure>

3. SSH to the Azure linux jump box using the applicable private key and public IP address. This private key is **not** the WEKA cluster SSH private key saved to the `/tmp/` directory by terraform. The jump box private key would’ve been specified or created and downloaded at the time the jump box was manually created in the Azure portal.
4. Once connected to the jump box, use the local IP address of the `clusterizing` instance identified in the previous step to SSH into the `clusterizing` instance, also known as `demo-bgc-backend-5`.

{% hint style="info" %}
The \`clusterizing\` instance will always be the last node of the cluster. For instance, if a 6 node cluster is deployed, the instances will have suffixes \`0-5\`. Instance \`5\` will be the \`clusterizing\` instance. If an 18 node cluster is deployed, the instances will have suffixes \`0-17\`. Instance \`17\` will be the \`clusterizing\` instance.
{% endhint %}

<figure><img src="/files/KAOMhxNHjpySddQiotb4" alt=""><figcaption></figcaption></figure>

5. Once connected to the `clusterizing` instance, navigate to the `/var/log` directory. Locate the `cloud-init-output.log` file highlighted in purple. Run the command `tail -f cloud-init-output.log` to tail the logfile to check the status of the deployment. In the example below, the `tail` command was run while WEKA binaries were being downloaded from `get.weka.io`.

<figure><img src="/files/5jsGsGnltM32IWYM3mTw" alt=""><figcaption></figcaption></figure>

The WEKA containers are being configured as the WEKA installation continues.

<figure><img src="/files/NtV3VasA0cQw9dg3DhTk" alt=""><figcaption></figcaption></figure>

The install script will start-io. At this point, i-nodes and WEKA buckets will begin coming online.

<figure><img src="/files/itQzhKVbup2Jb2iDWQ41" alt=""><figcaption></figcaption></figure>

Finally, the file system group `default` and file system `default` will be created. The date and time of cluster creation completion will be printed in UTC. The number of seconds required to perform clusterization is printed. This signifies that the WEKA installation and clusterization processes are complete.

<figure><img src="/files/mNR1m05fbQDmWinJon5q" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Stay logged into \`backend-5\` for the next section.
{% endhint %}

#### Weka Status and Client Status

To confirm that the WEKA cluster is up and running, issue a `weka status` command on the `backend-5` cluster member. If the cluster is indeed up and running, an output identical to the below should be outputted.

{% hint style="info" %}
Note the \`status\`, \`protection\`, and \`io status\`.
{% endhint %}

When the terraform `main.tf` file was configured for this deployment, two clients were specified for deployment in addition to the WEKA cluster backend members. Note that when `weka status` is initially run immediately following `cloud-init` script completion, those clients aren’t acknowledged. Note the entry for `clients: 0 connected`. **This is expected behavior**, as the clients are the last components to initialize. Depending on the number of clients deployed, 15 minutes can elapse before all clients are registered.

<figure><img src="/files/HALVpkn2T9OqWjbnlEhC" alt=""><figcaption></figcaption></figure>

The following example shows that the two clients are successfully connected to the cluster three minutes after cluster io starts.

<figure><img src="/files/vLebptjqGKCrjbBRGjzM" alt=""><figcaption></figcaption></figure>

### Cluster helper commands

The cluster helper commands are executed through a terminal and a web browser. The function app, created during deployment, processes these commands, retrieves the necessary information, and returns it to the user.

#### **Retrieve clusterization status**

1. Under the **Get Clusterization Status** section, copy the first line of code.

<figure><img src="/files/Td4r5CZh4b27D32ZTna5" alt=""><figcaption></figcaption></figure>

2. Paste the copied code into the terminal, and run. No output will appear—this is expected behavior.

<figure><img src="/files/Izan4hoLol2644tYRmux" alt=""><figcaption></figcaption></figure>

3. Copy the second line of code from the **Get Clusterization Status** section.

<figure><img src="/files/jw5j70f7wZ0mzMfq7hjH" alt=""><figcaption></figcaption></figure>

4. Paste the copied URL into the terminal, and run. The command returns an error message along with a URL. The curl command is designed to fail, providing the URL needed to check the clusterization status.

<figure><img src="/files/tjev18p9dyDwLSUTcowx" alt=""><figcaption></figcaption></figure>

5. Copy the URL and paste it into a web browser. The clusterization status of the deployed WEKA cluster displays. Review the returned data to confirm the cluster deployment.

<figure><img src="/files/hqi3anPSeCm7v9UPhIdB" alt=""><figcaption></figcaption></figure>

#### **Check cluster status**

1. Follow the same steps as retrieving the clusterization status to check the cluster status. This process returns the same information once clusterization completes.

**Retrieve the WEKA cluster password**

1. Ensure the `jq` tool is installed. `jq` is a lightweight command-line tool for processing JSON data, commonly used in system administration. On a Mac, install it using Homebrew by running the following command:

```
brew install jq
```

<figure><img src="/files/V53uLHPewtqgI816gZSN" alt=""><figcaption></figcaption></figure>

The process of installing `jq` begins. Installation completes once a command prompt is returned.

<figure><img src="/files/6g72mFLRF5G0n7INTYag" alt=""><figcaption></figcaption></figure>

2. After `jq` installation, under the **Fetch WEKA Cluster Password** section, copy the command.

<figure><img src="/files/5nFzT1ydN6Borahv3oZj" alt=""><figcaption></figcaption></figure>

3. Paste the copied command into the terminal, and run it. The WEKA cluster password appears.

<figure><img src="/files/TIk1lYpX5NXm0leGXDgt" alt=""><figcaption></figcaption></figure>

#### **Retrieve WEKA backend IP addresses**

Retrieve the IP addresses of the WEKA backend instances. For a public network deployment, WAN addresses appear. If using a private network, LAN IP addresses are retrieved.

1. Copy the helper command for listing the IP addresses of the VMSS (Virtual Machine Scale Set) that contains the WEKA backend instances.

<figure><img src="/files/wu9t1Jq6F9GgU9BVLHja" alt=""><figcaption></figcaption></figure>

2. Paste the copied command into the terminal, and run it. The public IP addresses display.

<figure><img src="/files/ZCtq0Ec4vXpzFCPmNZiT" alt=""><figcaption></figcaption></figure>

## **Access the WEKA web interface**

1. Select one of the backend IP addresses, paste it into the browser's address bar, append `:14000`, and press Enter. The WEKA web interface loads.
2. Log in using the default username `admin` and the password retrieved in the earlier step.

<figure><img src="/files/q5fGYQUl6YyobKZujxgl" alt=""><figcaption></figcaption></figure>

In the examples below, a Windows 10 instance with a public IP address was deployed in the same vnet, subnet, and security group as the WEKA cluster. Network security group rules were added to allow RDP explicit access to the Windows 10 system.

3. Open a browser in the Windows 10 jump box and visit `https://<cluster-backend-ip>:14000`. The WEKA GUI login screen should appear. After changing the default password, login.

<figure><img src="/files/H2HCTA81ni8ckztdEPcw" alt=""><figcaption></figcaption></figure>

4. View the cluster GUI home screen.

<figure><img src="/files/OtLscZWbG6r1NbwT9DaO" alt=""><figcaption></figcaption></figure>

5. Review the cluster backends.

<figure><img src="/files/7NaqdUnsfDCqhZRM3HWf" alt=""><figcaption></figcaption></figure>

6. Review the clients attached to the cluster as part of the terraform deployment process.

<figure><img src="/files/3HMXG6kpSp47itkgADPw" alt=""><figcaption></figcaption></figure>

7. Review the file system `default` created as part of the terraform deployment process.

<figure><img src="/files/0cTwL9d0fCX7NCvZXMPh" alt=""><figcaption></figcaption></figure>

8. In the Azure portal Virtual Machines page, view the WEKA cluster instance resources.

<figure><img src="/files/CBWXqlKLHf3cwgEwtUeK" alt=""><figcaption></figcaption></figure>

[^1]: An Azure subscription acts as a legal and payment agreement tied to an Azure offer, defines scale limits for resources, and serves as an administrative boundary for managing security and policies. For details, see [Azure subscription purposes](https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/considerations/fundamental-concepts#azure-subscription-purposes).

[^2]: A "blank slate" refers to a newly set-up Azure environment with no pre-existing configurations or resources.


# WEKA installation on GCP

This section aims at a system engineer familiar with the GCP concepts and experienced in using Terraform to deploy a system on GCP.

## WEKA on GCP overview

Leveraging GCP's advantages, WEKA offers a customizable **terraform-gcp-weka** module for deploying the WEKA cluster on GCP. In GCP, WEKA operates on instances, each capable of using up to eight partitions of drives on the connected physical server (without direct drive usage). These drives can be shared among partitions for other clients on the same server.

WEKA requires either four or seven VPC networks, depending on which instance type is being used for the WEKA backends. This configuration aligns with the four key WEKA processes: Management, Drive, Compute and optionally Frontend, with each process requiring a dedicated network interface as follows:

* eth0: Management vpc-0
* eth1: Drive vpc-1
* eth2: Compute vpc-2
* eth3: Frontend vpc-3

For a WEKA instance using seven NICs, the alignment is as follows:

* eth0: Management vpc-0
* eth1: Drive vpc-1
* eth2: Compute vpc-2
* eth3: Compute vpc-3
* eth4: Compute vpc-4
* eth5: Compute vpc-5
* eth6: Frontend vpc-6

If the frontend container is not deployed, then its core is instead used by the compute process.

VPC peering facilitates communication between the WEKA processes, each using its NIC. The maximum allowable number of peers within a VPC is limited to 25 by GCP (you can request GCP to increase the quota, but it depends on the GCP resources availability).

<div data-with-frame="true"><figure><img src="/files/slPnKtQ4HZf17m5XEeCM" alt=""><figcaption><p>Server infrastructure in GCP</p></figcaption></figure></div>

<details>

<summary>Terraform overview</summary>

Terraform is an open-source project from HashiCorp. It creates and manages resources on cloud platforms and on-premises environments. It interacts with numerous APIs from multiple platforms and services, providing a unified workflow for infrastructure management.

The GCP Console is already installed with Terraform by default. It is the primary tool for deploying WEKA on GCP. Terraform can be used outside of GCP or independent of GCP Console.

<img src="/files/wN5LMlxfVkG12fYKxT00" alt="" data-size="original">

**How does Terraform work?**

A deployment with Terraform involves three phases:

* **Write:** Define the infrastructure in configuration files and customize the project variables provided in the Terraform package.
* **Plan**: Review the changes Terraform will make to your infrastructure.
* **Apply:** Terraform provisions the infrastructure, including the VMs and instances, installs the WEKA software, and creates the cluster. Once completed, the WEKA cluster runs on GCP.

<img src="/files/QzY95rUxPdVcqa0RpRtK" alt="Terraform phases" data-size="original">

**Related information**

[Terraform Tutorials](https://learn.hashicorp.com/terraform?track=gcp)

[Terraform Installation](https://learn.hashicorp.com/tutorials/terraform/install-cli)

</details>


# WEKA project description

The WEKA project uses internal GCP resources. A basic WEKA project includes a cluster with multiple virtual private clouds (VPCs), virtual machines (VMs), a load balancer, DNS, cloud storage, a secret manager, and other components for managing cluster resizing. Peering between all virtual networks enables functions to run across them, with each VPC connected to every other VPC in a full mesh.

<div data-with-frame="true"><figure><img src="/files/zZV07mUNkTU3gnE57Wtq" alt=""><figcaption><p>WEKA project on the GCP</p></figcaption></figure></div>

### Resize cloud function operation

A resize cloud function in vpc-0 and a workload listener are deployed for auto-scale instances in GCP. Once a user sends a [request for resizing](/planning-and-installation/weka-installation-on-gcp/auto-scale-instances-in-gcp) the number of instances in the cluster, the workload listener checks the *cluster state* file in the cloud storage and triggers the resize cloud function if a resize is required. The cluster state file is an essential part of the resizing decision. It indicates states such as:

* Readiness of the cluster.
* The number of existing instances.
* The number of requested instances.

The secret manager retains the user name (usually *admin*) and the Terraform-generated password. The resize cloud function uses the user name and password to operate on the cluster instances.

## GCP internet connectivity

During WEKA deployment, the instances require access to a YUM repository and the WEKA software. This can be achieved through one of the following methods:

* **External IPs:** Allow an external IP address in VPC0 for each instance. This enables direct connection to public internet resources such as a YUM repository and get.weka.io.
* **NAT gateway:** Add a NAT Gateway to VPC0 to allow the instances to connect to the public internet resources through the gateway.
* **Private YUM repository:** If connecting to an external YUM repository and get.weka.io is impossible, specify an internal YUM repository and a private download link for the WEKA software.


# GCP-WEKA deployment Terraform package description

WEKA provides a ready-to-deploy [GCP-WEKA deployment Terraform package](https://registry.terraform.io/modules/weka/weka/gcp/latest) you can customize to install the WEKA cluster on GCP.

The Terraform package contains the following modules:

* **setup\_network**: includes vpcs, subnets, peering, firewall, and health check.
* **service\_account**: includes the service account used for deployment with all necessary permissions.
* **deploy\_weka**: includes the actual WEKA deployment, instance template, cloud functions, workflows, job schedulers, secret manager, buckets, and health check.
* **shared\_vpcs** (*optional*): includes VPC sharing the WEKA deployment network with another hosting project. For example, when deploying a private network.

Refer to the [terraform-gcp-weka](https://github.com/weka/terraform-gcp-weka) module for more details.

## GCP-WEKA deployment Terraform package supported types

The Terraform package supports the following deployment types:

* **Public cloud deployments:** Require passing the `get.weka.io` token to Terraform to download the WEKA release from the public [get.weka.io](https://get.weka.io/) service. The following examples are provided:
  * Public VPC
  * Public VPC with creating a worker pool
  * Public VPC with an existing public network
  * Public VPC with multiple clusters
  * Public VPC with a shared VPC
  * Public VPC with an existing worker pool and VPC
* **Private cloud deployments:** Require placing the WEKA release tar file in a URL-accessible location for internal access (instances can download the WEKA release from this location). The following examples are provided:
  * Private VPC with creating a worker pool
  * Private VPC with an existing network
  * Private VPC with an existing worker pool and VPC
  * Private VPC with multiple clusters
  * Private VPC with a shared VPC

## Terraform example

The following is a basic example where you provide minimal details about your cluster, and the Terraform module completes the remaining required resources, such as cluster size, machine type, and networking parameters.

This example can be used as a reference when creating the main.tf file for a c2-standard-8 with 4 VPCs.

```hcl
provider "google" {
  region  = "europe-west1"
  project = "PROJECT_ID"
}

module "weka_deployment" {
  source                         = "weka/weka/gcp"
  version                        = "4.0.9"
  cluster_name                   = "my_cluster_name"
  project_id                     = "PROJECT_ID"
  prefix                         = "my_prefix"
  region                         = "europe-west1"
  zone                           = "europe-west1-b"
  cluster_size                   = 7
  nvmes_number                   = 2
  get_weka_io_token              = "getwekatoken"
  machine_type                   = "c2-standard-8"
  subnets_range                  = ["10.222.0.0/24", "10.223.0.0/24", "10.224.0.0/24", "10.225.0.0/24"]
  allow_ssh_cidrs                = ["0.0.0.0/0"]
  allow_weka_api_cidrs           = ["0.0.0.0/0"]

}
output "weka_cluster" {
  value = module.weka_deployment
}
```

{% hint style="info" %}
For the descriptions of the parameters, refer to the [GCP-WEKA deployment Terraform package](https://registry.terraform.io/modules/weka/weka/gcp/latest).
{% endhint %}

This example can be used as a reference when creating the `main.tf` file for a c2-standard-16 with 7 VPCs.

```
provider "google" {
  region  = "europe-west1"
  project = "PROJECT_ID"
}

module "weka_deployment" {
  source                         = "weka/weka/gcp"
  version                        = "4.0.9"
  cluster_name                   = "my_cluster_name"
  project_id                     = "PROJECT_ID"
  prefix                         = "my_prefix"
  region                         = "europe-west1"
  zone                           = "europe-west1-b"
  cluster_size                   = 7
  nvmes_number                   = 2
  get_weka_io_token              = "getwekatoken"
  machine_type                   = "c2-standard-16"
  subnets_range                  = ["10.222.0.0/24", "10.223.0.0/24", "10.224.0.0/24", "10.225.0.0/24", "10.226.0.0/24", "10.227.0.0/24", "10.228.0.0/24"]
  allow_ssh_cidrs                = ["0.0.0.0/0"]
  allow_weka_api_cidrs           = ["0.0.0.0/0"]

}
output "weka_cluster" {
  value = module.weka_deployment
}
```

## Private network considerations

To deploy a private network, the parameter `private_network = true` on the `setup_network` and `deploy_weka` modules level.

Depending on the required network topology, the following parameters are optional for private networking:

* To download the WEKA release from a local bucket, set the local bucket location in the `install_weka_url` parameter on the `deploy_weka` module level.
* For Centos7 only, a distributive repository is required to download kernel headers and additional build software. To auto-configure yum to use a distributive repository, run `yum_repo_server`.
* If a custom image is required, use `source_image_id`.

## Object store integration

The Terraform package can automate the addition of a Google Cloud Storage bucket for use as object storage.

**Procedure**

1. In the `main.tf` file, add the following fields:
   * `tiering_enable_obs_integration:` Set the value to `true`.
   * `tiering_obs_name:` Match the value to an existing bucket in Google Cloud Storage.
   * `tiering_enable_ssd_percent:` Set the percentage to your desired value.

Example:

```hcl
tiering_enable_obs_integration=true 
tiering_obs_name="myBucketName"
tiering_enable_ssd_percent=20
```

{% hint style="info" %}
If you do not specify the name of an existing bucket using `tiering_obs_name` but specify `tiering_enable_obs_integration=true` then a new Cloud Storage bucket is created automatically.\
The name format of the new bucket is:\
`<project_id>-<prefix>-<cluster_name>-obs`
{% endhint %}


# Deployment on GCP using Terraform

The Terraform package includes a `main.tf` file you create according to your deployment needs.

Applying the created `main.tf` file performs the following:

* Creates VPC networks and subnets on the GCP project.
* Deploys GCP instances.
* Installs the WEKA software.
* Configures the WEKA cluste&#x72;**.**
* Additional GCP objects.

## Prerequisites

Before installing the WEKA software on GCP, the following prerequisites must be met:

* [Install the gcloud CLI](https://cloud.google.com/sdk/docs/install): It is pre-installed if you use the Cloud Shell.
* Log in to gcloud: `gcloud auth application-default login`
* [Install Terraform](https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli): It is pre-installed if you use the Cloud Shell. Ensure the Terraform version meets the minimum required version specified in the [**Requirements**](https://registry.terraform.io/modules/weka/weka/gcp/latest#requirements) section of the GCP-WEKA deployment Terraform package.
* Initialize the Terraform module using `terraform init` from the local directory. This command initializes a new or existing Terraform working directory by creating initial files, loading any remote state, downloading modules, and more.
* The **Compute Engine** and **Workflows API** services must be enabled to allow the following services:

  ```
  artifactregistry.googleapis.com
  cloudbuild.googleapis.com
  cloudfunctions.googleapis.com
  cloudresourcemanager.googleapis.com
  cloudscheduler.googleapis.com
  compute.googleapis.com
  dns.googleapis.com
  eventarc.googleapis.com
  iam.googleapis.com
  secretmanager.googleapis.com
  servicenetworking.googleapis.com
  serviceusage.googleapis.com
  vpcaccess.googleapis.com
  workflows.googleapis.com
  ```
* The user running the Terraform module requires the following roles to run the `terraform apply`:

  ```
  roles/cloudfunctions.admin
  roles/cloudscheduler.admin
  roles/compute.admin
  roles/compute.networkAdmin
  roles/compute.serviceAgent
  roles/dns.admin
  roles/iam.serviceAccountAdmin
  roles/iam.serviceAccountUser
  roles/pubsub.editor
  roles/resourcemanager.projectIamAdmin 
  roles/secretmanager.admin
  roles/servicenetworking.networksAdmin
  roles/storage.admin 
  roles/vpcaccess.admin
  roles/workflows.admin
  ```

## **Create a main.tf file**

The main Terraform configuration settings are included in the `main.tf` file. You can create it by following this procedure or using the WEKA Cloud Deployment Manager. See [Cloud Deployment Manager Web (CDM Web) User Guide](/planning-and-installation/weka-cdm-web-user-guide).

**Procedure**

1. Review the [Terraform-GCP-WEKA example](/planning-and-installation/weka-installation-on-gcp/gcp-terraform-package-description#terraform-gcp-weka-example) and use it as a reference for creating the `main.tf` according to your deployment specifics on GCP.
2. Tailor the `main.tf` file to create SMB-W or NFS protocol clusters by adding the relevant code snippet. Adjust parameters like the number of gateways, instance types, domain name, and share naming:

* **SMB-W**

<pre><code><strong>smb_protocol_gateways_number = 3
</strong>smb_protocol_gateway_instance_type = "c2-standard-8" 
smbw_enabled = true
smb_domain_name = "CUSTOMER_DOMAIN"
smb_share_name = "SPECIFY_SMB_SHARE_NAMING"
smb_setup_protocol = true
</code></pre>

* **NFS**

```
nfs_protocol_gateways_number = 2
nfs_protocol_gateway_instance_type = "c2-standard-8"
nfs_setup_protocol = true
```

4. Add WEKA POSIX clients (optional)**:** If needed, add [WEKA POSIX clients](/weka-system-overview/weka-client-and-mount-modes) to support your workload by incorporating the specified variables into the `main.tf` file:

```makefile
clients_number = 2
client_instance_type = "c2-standard-8"
```

## Apply the main.tf file

Once you complete the `main.tf` settings, apply it: Run `terraform apply`.

### **Additional configuration post-Terraform** apply

After applying the `main.tf`, the Terraform module updates the configuration as follows:

1. **Service account creation:**\
   Format of the service account name: `<prefix>-deployment@<project name>.iam.gserviceaccount.com`\
   Assigned roles:

```
roles/cloudfunctions.developer
roles/compute.serviceAgent
roles/compute.loadBalancerServiceUser
roles/pubsub.subscriber
roles/secretmanager.secretAccessor
roles/vpcaccess.serviceAgent
roles/workflows.invoker
```

2. **Additional roles can be assigned to the created service account (if working with relevant resources):**

* To create a worker pool:

  ```
  roles/compute.networkAdmin
  roles/servicenetworking.networksAdmin
  roles/cloudbuild.workerPoolOwner
  ```
* To create a new bucket (for Terraform state and WEKA OBS):

  ```jsx
  roles/storage.admin
  ```
* To use an existing bucket (for Terraform state and WEKA OBS):

  ```jsx
  roles/storage.objectAdmin
  ```

## Set the license

To run IOs against the cluster, a valid license must be applied. Obtain a valid license and apply it to the WEKA cluster. For details, see [Licensing overview](/licensing/overview).

## **Upgrade the WEKA version**

Upgrading the WEKA version on the cloud is similar to the standard WEKA upgrade process. However, in a cloud configured with auto-scaling, the new instances created by the scale-up must be configured with the new WEKA version.

**Before you begin**

Ensure the cluster does not undergo a scale-up or scale-down process before and during the WEKA version upgrade.

**Procedure**

1. Perform the upgrade process. See [Upgrade WEKA versions](/operation-guide/upgrading-weka-versions).
2. Update the `weka_version` parameter in the `main.tf` file.
3. Run `terraform apply`.

## Removal or rollback of the WEKA cluster

If a rollback is required or the WEKA cluster is no longer required on GCP, first terminate the WEKA cluster and then use the `terraform destroy` action.

The termination of the WEKA cluster can also be used if you need to retain the GCP resources (such as VPCs and cloud functions to save time on the next deployment) and then deploy a new WEKA cluster when you are ready.

{% hint style="info" %}
If you need to preserve your data, first create a snapshot using [snap-to-object](/weka-filesystems-and-object-stores/snap-to-obj).
{% endhint %}

To terminate the WEKA cluster, run the following command (replace the `trigger_url` with the actual trigger URL and `Cluster_Name` with the actual cluster name):

{% code overflow="wrap" %}

```bash
curl -m 70 -X POST ${google_cloudfunctions_function.terminate_cluster_function.https_trigger_url} \
-H "Authorization:bearer $(gcloud auth print-identity-token)" \
-H "Content-Type:application/json" \
-d '{"name":"Cluster_Name"}'
```

{% endcode %}

If you do not know the trigger URL or cluster name, run the `terraform output`command to display them.

Once the WEKA cluster is terminated, you can deploy a new WEKA cluster or run the `terraform destroy` action.


# Required services and supported regions

The region must support the services used in WEKA on GCP. The following sections list these services and the regions that support them.

## Required services used in WEKA on GCP

* Cloud Build API
* Cloud Deployment Manager V2 API
* Cloud DNS API
* Cloud Functions API
* Cloud Logging API
* Cloud Resource Manager API
* Cloud Scheduler API
* Compute Engine API
* Secret Manager API
* Serverless VPC Access API
* Service Usage API
* Workflow Executions API
* Workflows API

Other services used or enabled:

* App Engine
* IAM
* Google Cloud Storage

## Supported regions

To ensure support for a specific region, it must meet the requirements listed [above](#required-services-used-in-weka-on-gcp).

{% hint style="info" %}
If the region you want to deploy in is not on the supported list, verify the availability of these services in that region. If they are available and your region is not listed, contact the WEKA [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team) for validation.
{% endhint %}

### Americas

| Region Name             | Region Description            |
| ----------------------- | ----------------------------- |
| northamerica-northeast1 | Montréal, Canada              |
| southamerica-east1      | São Paulo, Brazil             |
| southamerica-west1      | Santiago, Chile               |
| us-central1             | Iowa, United States           |
| us-east1                | South Carolina, United States |
| us-east4                | Virginia, United States       |
| us-east5                | Columbus, United States       |
| us-west1                | Oregon, United States         |
| us-west2                | Los Angeles, United States    |
| us-west3                | Salt Lake City, United States |
| us-west4                | Las Vegas, United States      |

### Asia Pacific

| Region name          | Region Description      |
| -------------------- | ----------------------- |
| asia-east1           | Changhua County, Taiwan |
| asia-east2           | Hong Kong               |
| asia-northeast1      | Tokyo, Japan            |
| asia-northeast2      | Osaka, Japan            |
| asia-northeast3      | Seoul, South Korea      |
| asia-south1          | Mumbai, India           |
| asia-south2          | Delhi, India            |
| asia-southeast1      | Jurong West, Singapore  |
| asia-southeast2      | Jakarta, Indonesia      |
| australia-southeast1 | Sydney, Australia       |

### Europe

| Region Name     | Region Description     |
| --------------- | ---------------------- |
| europe-north1   | Hamina, Finland        |
| europe-west1    | St. Ghislain, Belgium  |
| europe-west2    | London, England        |
| europe-west3    | Frankfurt, Germany     |
| europe-west4    | Eemshaven, Netherlands |
| europe-west6    | Zurich, Switzerland    |
| europe-central2 | Warsaw, Poland         |

**Related information**

[Regions and zones](https://cloud.google.com/compute/docs/regions-zones)

[Cloud locations](https://cloud.google.com/about/locations)


# Supported machine types and storage

## Supported machine types for backends

The following table provides the supported machine types (VM instance) for backends (and clients) applied by the Terraform package:

<table><thead><tr><th width="183">Machine series</th><th>Machine types</th></tr></thead><tbody><tr><td>C2</td><td>c2-standard-8, c2-standard-16</td></tr><tr><td>N2</td><td>n2-standard-8, n2-standard-16</td></tr><tr><td>Z3</td><td>z3-highmem-8-highlssd, z3-highmem-16-highlssd, z3-highmem-22-highlssd, z3-highmem-32-highlssd, z3-highmem-44-highlssd, z3-highmem-88-highlssd</td></tr></tbody></table>

{% hint style="info" %}

* WEKA supports deploying the C2 machine type with 2, 4, or 8 local SSD drives and the N2 machine type with 2, 4, 8 or 16 local SSD drives. Each drive has 375 GB (maximum 3 TB per instance). These drives are not individual SSDs but partitions locally to the physical server.
* The data in a WEKA cluster is protected with N+2 or N+4. However, use snap-to-object if the data needs further protection from multiple server failures.
* The C2 series may not be available in your chosen [GCP region](https://cloud.google.com/compute/docs/regions-zones).
  {% endhint %}

## Supported machine types for clients

Explore the two key technologies in network virtualization: **VirtIO in DPDK mode** and **gVNIC in UDP and DPDK modes**.

### Supported machine types for clients over VirtIO in DPDK mode

VirtIO in DPDK mode enables high-performance network interfaces within virtual machines, making it an ideal choice for applications requiring low-latency, high-throughput networking in virtualized environments.

<table><thead><tr><th width="169">Machine series</th><th>Machine type</th></tr></thead><tbody><tr><td>A2</td><td>a2-highgpu-1g, a2-highgpu-2g, a2-highgpu-4g, a2-highgpu-8g,<br>a2-megagpu-16g, a2-ultragpu-1g</td></tr><tr><td>C2</td><td>c2-standard-8, c2-standard-16</td></tr><tr><td>C2D</td><td>c2d-standard-4, c2d-standard-8, c2d-standard-16, c2d-standard-32, c2d-standard-56, c2d-standard-112, c2d-highmem-56</td></tr><tr><td>E2</td><td>e2-standard-4, e2-standard-8, e2-standard-16, e2-highmem-4, e2-highcpu-8</td></tr><tr><td>N2</td><td>n2-standard-4, n2-standard-8, n2-standard-16, n2-standard-32,<br>n2-standard-48, n2-standard-96, n2-standard-128, n2-highmem-32</td></tr><tr><td>N2D</td><td>n2d-standard-32, n2d-standard-64, n2d-highmem-32, n2d-highmem-64</td></tr></tbody></table>

### Supported machine types for clients over gVNIC in DPDK and UDP modes

* **gVNIC in DPDK Mode**: Delivers high-performance network interfaces in virtual machines, similar to VirtIO, with optimized performance for demanding network workloads.
* **gVNIC in UDP Mode**: Provides reliable, high-speed network connectivity, leveraging the UDP protocol to balance performance and dependability.

<table><thead><tr><th width="167">Machine series</th><th>Machine type</th></tr></thead><tbody><tr><td>A2</td><td><p>a2-highgpu-1g, a2-highgpu-2g, a2-highgpu-4g, a2-highgpu-8g,</p><p>a2-megagpu-16g, a2-ultragpu-1g</p></td></tr><tr><td>A3</td><td>a3-highgpu-8g</td></tr><tr><td>C2</td><td>c2-standard-8, c2-standard-16, c2-standard-30, c2-standard-60</td></tr><tr><td>C2D</td><td>c2d-standard-4, c2d-standard-8, c2d-standard-16, c2d-standard-32, c2d-standard-56, c2d-standard-112, c2d-highmem-56</td></tr><tr><td>C3</td><td>c3-standard-4, c3-standard-8, c3-standard-22, c3-standard-44, c3-standard-88, c3-standard-176, c3-highcpu-4, c3-highcpu-8, c3-highcpu-22, c3-highcpu-44, c3-highcpu-88, c3-highcpu-176, c3-highmem-4, c3-highmem-8, c3-highmem-22, c3-highmem-44, c3-highmem-88, c3-highmem-176, c3-standard-4-lssd, c3-standard-8-lssd, c3-standard-22-lssd, c3-standard-44-lssd, c3-standard-88-lssd, c3-standard-176-lssd</td></tr><tr><td>C3D</td><td>c3d-standard-4, c3d-standard-8, c3d-standard-16, c3d-standard-30, c3d-standard-60, c3d-standard-90, c3d-standard-180, c3d-standard-360, c3d-highcpu-4, c3d-highcpu-8, c3d-highcpu-16, c3d-highcpu-30, c3d-highcpu-60, c3d-highcpu-90, c3d-highcpu-180, c3d-highcpu-360, c3d-highmem-4, c3d-highmem-8, c3d-highmem-16, c3d-highmem-30, c3d-highmem-60, c3d-highmem-90, c3d-highmem-180, c3d-highmem-360, c3d-standard-8-lssd, c3d-standard-16-lssd, c3d-standard-30-lssd, c3d-standard-60-lssd, c3d-standard-90-lssd, c3d-standard-180-lssd, c3d-standard-360-lssd, c3d-highmem-8-lssd, c3d-highmem-16-lssd, c3d-highmem-30-lssd, c3d-highmem-60-lssd, c3d-highmem-90-lssd, c3d-highmem-180-lssd, c3d-highmem-360-lssd</td></tr><tr><td>C4</td><td>c4-standard-4, c4-standard-8, c4-standard-16, c4-standard-32, c4-standard-48, c4-standard-96, c4-standard-192, c4-highcpu-4, c4-highcpu-8, c4-highcpu-16, c4-highcpu-32, c4-highcpu-48, c4-highcpu-96, c4-highcpu-192, c4-highmem-4, c4-highmem-8, c4-highmem-16, c4-highmem-32, c4-highmem-48, c4-highmem-96, c4-highmem-192</td></tr><tr><td>G2</td><td>g2-standard-4, g2-standard-8, g2-standard-12, g2-standard-16, g2-standard-24, g2-standard-32, g2-standard-48, g2-standard-96</td></tr><tr><td>M3</td><td>m3-ultramem-32, m3-ultramem-64, m3-ultramem-128, m3-megamem-64, m3-megamem-128</td></tr><tr><td>N2</td><td>n2-standard-4, n2-standard-8, n2-standard-16, n2-standard-32, n2-standard-48, n2-standard-64, n2-standard-80, n2-standard-96, n2-standard-128, n2-highmem-4, n2-highmem-8, n2-highmem-16, n2-highmem-32, n2-highmem-48, n2-highmem-64, n2-highmem-80, n2-highmem-96, n2-highmem-128, n2-highcpu-8, n2-highcpu-16, n2-highcpu-32, n2-highcpu-48, n2-highcpu-64, n2-highcpu-80, n2-highcpu-96</td></tr><tr><td>N2D</td><td>n2d-standard-4, n2d-standard-8, n2d-standard-16, n2d-standard-32, n2d-standard-48, n2d-standard-64, n2d-standard-80, n2d-standard-96, n2d-standard-224, n2d-highmem-4, n2d-highmem-8, n2d-highmem-16, n2d-highmem-32, n2d-highmem-48, n2d-highmem-64, n2d-highmem-80, n2d-highmem-96, n2d-highcpu-8, n2d-highcpu-16, n2d-highcpu-32, n2d-highcpu-48, n2d-highcpu-64, n2d-highcpu-80, n2d-highcpu-96, n2d-highcpu-128, n2d-highcpu-224</td></tr><tr><td>N4</td><td>n4-standard-4, n4-standard-8, n4-standard-16, n4-standard-32, n4-standard-48, n4-standard-64, n4-standard-80, n4-highcpu-4, n4-highcpu-8, n4-highcpu-16, n4-highcpu-32, n4-highcpu-48, n4-highcpu-64, n4-highcpu-80, n4-highmem-4, n4-highmem-8, n4-highmem-16, n4-highmem-32, n4-highmem-48, n4-highmem-64, n4-highmem-80</td></tr><tr><td>Z3</td><td>z3-highmem-8-highlssd, z3-highmem-16-highlssd, z3-highmem-22-highlssd, z3-highmem-32-highlssd, z3-highmem-44-highlssd, z3-highmem-88-highlssd</td></tr></tbody></table>

**Related information**

[Machine families resource and comparison guide](https://cloud.google.com/compute/docs/machine-resource)


# Auto-scale instances in GCP

Once the Terraform modules are applied, two workflows are running every minute. One for scale-up and the other for scale-down.

WEKA provides a cloud function for scale-up or scale-down of the number of compute engine instances (cluster size). Terraform automatically creates the cluster according to the specified target value in a few minutes.

To change the cluster size (up or down), specify the link to the resize cloud function on GCP and the resize target value for the number of compute engine instances in the following command and run it:

```bash
curl -m 70 -X POST  https://<resize_cloud_function_name> \
-H "Authorization:bearer $(gcloud auth print-identity-token)" \
-H "Content-Type:application/json" \
-d '{"value":<Resize_target_value>}'
```

Example:

```bash
curl -m 70 -X POST  https://europe-west1-wekaio-qa.cloudfunctions.net/weka-test \
-H "Authorization:bearer $(gcloud auth print-identity-token)" \
-H "Content-Type:application/json" \
-d '{"value":7}'
```

**Related topics**

[WEKA project description](/planning-and-installation/weka-installation-on-gcp/weka-project-description#resize-cloud-function-operation)


# Add clients to a WEKA cluster on GCP

WEKA supports client instances with at least two NICs, one for management and one for the frontend data. It is possible to add more NICs for redundancy and higher performance.

A client with the same VPC networks and subnets as the cluster can connect without additional configuration. If a client is on another VPC network, peering is required between the VPC networks.

The client instance must be in the same region as the WEKA cluster on GCP.

## Mount the filesystem

1. Create a mount point (only once):

```
mkdir /mnt/weka
```

2. Install the WEKA agent (only once):

```bash
curl <backend server http address>:14000/dist/v1/install | sh
```

Example:

```bash
curl http://10.20.0.2:14000/dist/v1/install | sh
```

3. Mount a stateless client on the filesystem. In the mount command, specify all the NICs of the client.

{% hint style="info" %}
The `mgmt_ip` option identifies management processes on the data plane network. It does not identify external management interfaces such as the CLI or REST API.
{% endhint %}

* **DPDK mount with four NICs:**

{% code overflow="wrap" %}

```bash
mount -t wekafs -o net=eth1/IP/NETMASK/GATEWAY -o net=eth2/IP/NETMASK/GATEWAY -o net=eth3/IP/NETMASK/GATEWAY -o mgmt_ip=<management IP (eth0)> -o num_cores=4 -o dpdk_base_memory_mb=32 <backend server IP address>/<filesystem name> /mnt/weka
```

{% endcode %}

Example:

{% code overflow="wrap" %}

```bash
mount -t wekafs -o net=eth1/10.20.30.101/24/10.20.30.1 -o net=eth2/10.20.31.102/24/10.20.31.1 -o net=eth3/10.20.32.103/24/10.20.32.1 -o mgmt_ip=10.20.33.100 -o num_cores=4 -o dpdk_base_memory_mb=32 10.20.30.40/fs1 /mnt/weka
```

{% endcode %}

* **UDP mount:**

{% code overflow="wrap" %}

```bash
mount -t wekafs -o net=udp -o num_cores=0 -o mgmt_ip=<management IP (eth0)> <backend server IP address>/<filesystem name> /mnt/weka
```

{% endcode %}

Example:

{% code overflow="wrap" %}

```bash
mount -t wekafs -o net=udp -o num_cores=2 -o mgmt_ip=10.20.30.100 10.20.30.40/fs1 /mnt/weka
```

{% endcode %}

**Related topics**

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems)


# Troubleshooting

The GCP Console has a [Logs Explorer](https://cloud.google.com/logging/docs/view/logs-explorer-interface) interface in which you can view the cloud function logs related to the WEKA cluster activities, such as when scaling instances up or down. In addition, the cluster state file retained in the cloud storage provides you with the status of the operations in the WEKA project.

**Typical troubleshooting flow if the resize cloud function does not resize the cluster**

1. Open the cluster state file and check that the `desired_size` is as expected and the `clusterized` value is `true`. The cluster state file is in the cloud storage, and its name comprises the `prefix` and `cluster_name` provided in the [terraform variables file](https://docs.weka.io/planning-and-installation/weka-installation-on-gcp/pages/fI7TuJD8EqLARnWSa6fQ#tf.tfvars-example-public-vpc).
2. Check the scale-up workflow (or scale-down workflow). Check the function that didn't work and its related logs in the Logs Explorer of the GCP Console.


# Detailed deployment tutorial: WEKA on GCP using Terraform

This guide provides step-by-step instructions for deploying the WEKA Data Platform on GCP using Terraform, tailored for customers, partners, and WEKA teams.

## Introduction

Deploying WEKA on GCP requires proficiency in several technologies, including GCP, Terraform[^1], basic Linux operations, and the WEKA software itself. Recognizing that not all individuals responsible for this deployment are experts in each of these areas, this document aims to provide comprehensive, end-to-end instructions. This ensures that readers with minimal prior knowledge can successfully deploy a functional WEKA cluster on GCP.

### **Document scope**

This document specifically addresses the deployment of WEKA in a GCP environment using Terraform, applicable for both proof-of-concept (POC) and production settings. While no pre-existing GCP elements are necessary beyond an appropriate user account, the guide demonstrates the use of some pre-existing components, as many environments already have these in place.

The reader is guided through:

* General GCP requirements.
* Networking requirements to support WEKA.
* Deployment of WEKA using Terraform.
* Verification of a successful WEKA deployment.

{% hint style="info" %}
Images embedded in this document can be enlarged with a single click for ease of viewing and a clearer and more detailed examination.
{% endhint %}

## Terraform preparation and installation

HashiCorp Terraform is a powerful tool that allows you to define, provision, and manage infrastructure as code. You can specify your infrastructure setup in a configuration file using a declarative configuration language, HashiCorp Configuration Language (HCL), or JSON. Terraform then uses this file to automatically create, modify, or delete resources, ensuring consistent and predictable deployment of your infrastructure components such as servers, databases, and networks.

This document outlines the process for automating the deployment of the WEKA Data Platform on Google Cloud Platform (GCP) using Terraform. Terraform's widespread adoption and prominence in the Infrastructure as Code (IaC) domain drive its choice. Organizations of all sizes globally leverage Terraform to deploy persistent infrastructure both on-premises and across public clouds like AWS, Azure, and Google Cloud Platform.

To install Terraform, we recommend following the [official installation guides](https://developer.hashicorp.com/terraform/install) provided by HashiCorp. Additionally, Terraform can be run directly from the GCP Cloud Terminal, which comes with Terraform pre-installed, as illustrated in this guide.

### GCP account

It is essential for the customer to understand their subscription structure for deployments within a WEKA customer environment. If you are deploying internally at WEKA and cannot locate an Account ID or have not been added to the appropriate account, contact the relevant cloud team for assistance.

### User account privileges

Ensure that the GCP IAM user has the permissions outlined in [Appendix A](/4.3/planning-and-installation/weka-installation-on-gcp/detailed-deployment-tutorial-weka-on-gcp-using-terraform#appendix-a-required-permissions-that-terraform-needs) to perform the necessary operations for a successful WEKA deployment on GCP using Terraform. The IAM user must be able to create, modify, and delete GCP resources as specified by the Terraform configuration files used in the WEKA deployment.

If the current IAM user lacks the permissions detailed in [Appendix A](/4.3/planning-and-installation/weka-installation-on-gcp/detailed-deployment-tutorial-weka-on-gcp-using-terraform#appendix-a-required-permissions-that-terraform-needs), either update the user's permissions or create a new IAM user with the required privileges.

**Verify GCP IAM user permissions**

1. Navigate to the GCP Management Console.
2. Log in using the account intended for the WEKA deployment.
3. In the GCP Console, go to the Services menu and select **IAM** to access the Identity and Access Management dashboard.

<div data-with-frame="true"><figure><img src="/files/o7I4R4EEi6VLL1mZu7Dx" alt=""><figcaption></figcaption></figure></div>

4. Within the IAM dashboard, locate the relevant IAM user by searching for their account.

<div data-with-frame="true"><figure><img src="/files/DSjiRyhD3e0NAc2yUPNS" alt=""><figcaption></figcaption></figure></div>

5. Click on the user's **Security insights** to review their permissions.
6. Ensure that the user possesses the permissions listed in [Appendix A](/4.3/planning-and-installation/weka-installation-on-gcp/detailed-deployment-tutorial-weka-on-gcp-using-terraform#appendix-a-required-permissions-that-terraform-needs), which are necessary for managing GCP resources through Terraform.

<div data-with-frame="true"><figure><img src="/files/Dw7PP23Qg6vul9VHQbNB" alt=""><figcaption></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="/files/Tf4HeIR9ATBb0eaznx07" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
While this user has full administrative access to enable Terraform to deploy WEKA, it is recommended to follow the principle of [applying the least-privilege permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege). Grant only the specific permissions outlined in Appendix A to ensure security best practices.
{% endhint %}

### GCP quotas

For a successful WEKA deployment on GCP using Terraform, ensure your GCP project has the necessary quotas for the required resources. When setting up compute instances, such as the c2 type for the WEKA backend cluster, manage quotas based on the CPU count for each compute instance type or family.

Before deploying WEKA, confirm that your compute instance's CPU sizing requirements (determined in partnership with WEKA) can be met within the existing quota limits. If not, increase the quotas in your GCP project before executing the Terraform commands detailed later in this document.

The required minimum quota is the total CPU count for all instances (for example, deploying 10 c2.standard-8 instances requires 80 CPUs just for the cluster). Ensuring sufficient quotas prevents failures during the execution of Terraform commands, as discussed in subsequent sections.

#### Set service quotas

1. Navigate to the [GCP Console](https://console.cloud.google.com/) and search for the service **Quotas & System Limits**.

<div data-with-frame="true"><figure><img src="/files/JlSVhyN0Z4vokQp3eCPc" alt=""><figcaption></figcaption></figure></div>

2. On the Quotas page, search for **CPU** and select the compute instance type family, in this case, **c2**.

<div data-with-frame="true"><figure><img src="/files/jIxyOZwCGYQmWj3wNwyS" alt=""><figcaption></figcaption></figure></div>

3. Locate the region where you intend to deploy WEKA and confirm that there are sufficient available CPUs of the specified family type. If not, adjust the quota accordingly.

<div data-with-frame="true"><figure><img src="/files/fFGSTYXIYKtkiqSArfm4" alt=""><figcaption></figcaption></figure></div>

## GCP Resource Prerequisites

The WEKA deployment incorporates several GCP components, including VPCs, Subnets, Security Groups, Endpoints, and others. These elements can be either generated by the WEKA Terraform modules or exist beforehand if manually creating components to use.

Four VPCs (Virtual Private Clouds), each with at least one Subnet and a Security Group, are required at minimum. This guide assumes that Terraform generates these items for WEKA within the environment.

### Networking requirements

The Terraform deployment can automatically establish VPC peering connections from the new VPCs to your current VPC, which is utilized by the application servers consuming WEKA storage. Considering how GCP handles compute instances with multiple vNICs, it is advisable to allow Terraform to create the required networking for WEKA.

This guide assumes an already deployed VPC and the necessity of adding four WEKA-specific VPCs. This requirement arises from GCP networking constraints, where each VM instance can only have one vNIC per VPC. However, WEKA mandates a minimum of four vNICs per instance. Ensure that you have the CIDR information for the four subnets created in the new VPCs to prevent conflicts.

<div data-with-frame="true"><figure><img src="/files/50RONZTCh2jr7veBauFj" alt=""><figcaption><p>GCP networking</p></figcaption></figure></div>

## Deploy WEKA in GCP using Terraform

The WEKA Terraform modules establish peering connections between the newly created VPCs for WEKA and an existing VPC within the environment. Therefore, the initial networking step involves identifying the VPC to peer with.

**VPC**

<div data-with-frame="true"><figure><img src="/files/JSRWuad0MXXu6yxIay9Y" alt=""><figcaption></figcaption></figure></div>

**Subnet (in VPC)**

<div data-with-frame="true"><figure><img src="/files/TseHXKlIuWJPGBq3Exjr" alt=""><figcaption></figcaption></figure></div>

### Locate the WEKA user token

The WEKA user token provides access to the WEKA binaries and is used to access get.weka.io during installation.

1. In a web browser, navigate to [get.weka.io](https://get.weka.io/).
2. Select the user's name located in the upper right-hand corner of the page.
3. From the column on the left-hand side of the page, select **API Tokens**. The user’s API token is displayed. Note it for using it later in the installation process.

### Deploy WEKA in GCP with Terraform: private VPCs example

The following demonstrates deploying WEKA into Virtual Private Clouds (VPCs) and Subnets without exposing the instances to Internet access.

The [Terraform module package](https://registry.terraform.io/modules/weka/weka/gcp/latest) is designed for deploying various GCP resources essential for WEKA deployment on GCP, including Compute instances, cloud functions, and VPCs.

#### Description of sub-modules in the module package

* **IAM roles, networks, and security groups:** These modules create the necessary IAM roles, networks, and security groups for WEKA deployment. If specific IDs for security groups or subnets are not provided, the modules generate them automatically.
* **Service account:** This module automatically creates a service account that the WEKA deployment functions and services use.
* **Network:** To deploy a private network with Network Address Translation (NAT), certain variables need to be set, such as create\_nat\_gateway to true and providing a private CIDR range. To prevent instances from obtaining public IPs, set assign\_public\_ip to false.
* **Shared\_VPCs and VPC\_Peering:** These modules handle the peering of VPCs to each other and existing VPCs if provided.
* **Clients (optional):** This module automatically mounts clients to the WEKA cluster. Users can specify the number of clients to create along with optional variables such as instance type, number of network interfaces (NICs), and AMI ID.
* **Protocol\_Gateways NFS/SMB (optional):** Similar to the client's module, this module allows users to specify the number of protocol gateways per protocol. Additional configuration details, such as instance type and disk size, can also be provided.
* **Worker\_Pool:** This module creates a private pool to build GCP cloud functions.

#### Prepare the main.tf file

1. Sign in to Google Cloud Platform and access the **Cloud Shell**.

<div data-with-frame="true"><figure><img src="/files/X91VYAoeVeDljvSw8PcO" alt=""><figcaption></figcaption></figure></div>

2. If the Terminal is not associated with the project intended for WEKA deployment, close it, switch to the correct project, and reopen it.

<figure><img src="/files/671flnwBJSI3oBKCl3NH" alt=""><figcaption></figcaption></figure>

#### Organize the structure of the Terraform configuration files

1. Create a directory specifically for the Terraform configuration files.\
   To maintain state information, it's essential to keep each Terraform deployment separate.\
   Other deployments can be executed by duplicating these instructions and naming the directory appropriately, such as **deploy1** or another unique identifier.

```bash
mkdir deploy
```

2. Navigate to the created directory.

```bash
cd deploy
```

3. To display accessible output data on the screen during the process, create an **output.tf** file in the deploy directory, and insert the following content:

```json
output "weka_deployment_output" {
  value = module.weka_deployment
}
```

4. Save the **output.tf** file.
5. Define the Terraform options by creating the main.tf file using your preferred text editor. Use the following template and replace the placeholders `< >` with the values specific to your deployment environment:

```json
provider "google" {
  project     = "<your_project>"
  region      = "<your_region>"
  zone        = "<your_zone>"
}
module "weka_deployment" {
  source                   = "weka/weka/gcp"
  version                  = "4.0.6"
  cluster_name             = "<name_for_the_cluster>"
  project_id               = "<your_project_id>"
  region                   = "<your_region>"
  zone                     = "<your_zone>"
  cluster_size             = 7
  nvmes_number             = 2
  get_weka_io_token        = "<your_wekaio_token>"
  private_dns_name         = "weka.private.net."
  tiering_enable_obs_integration = true
  assign_public_ip               = false
  create_nat_gateway       = true
  vpcs_to_peer_to_deployment_vpc = ["<your_existing_vpc"]
  subnets_range            = ["<CIDR_for_subnet_for_wekavpc1>", "<CIDR_for_subnet_for_wekavpc2>", "<CIDR_for_subnet_for_wekavpc3>", "<CIDR_for_subnet_for_wekavpc4>"]
```

<details>

<summary>Main.tf file with example values</summary>

This Main.tf file includes example values. Do not copy and paste it directly for your deployment.

```jsx
provider "google" {
  project     = "wekaio-public"
  region      = "us-east1"
  zone        = "us-east1-b"
}
module "weka_deployment" {
  source                   = "weka/weka/gcp"
  version                  = "4.0.6"
  cluster_name             = "gcp-weka"
  project_id               = "wekaio-public"
  region                   = "us-east1"
  zone                     = "us-east1-b"
  cluster_size             = 7
  nvmes_number             = 2
  weka_version             = "4.3.0"
  get_weka_io_token        = "LB9ciQ7aDpHihJXc"
  private_dns_name         = "weka.private.net."
  tiering_enable_obs_integration = true
  assign_public_ip               = false
  create_nat_gateway       = true
  vpcs_to_peer_to_deployment_vpc = ["default-POC"]
  subnets_range            = ["10.100.0.0/24", "10.101.0.0/24", "10.102.0.0/24", "10.103.0.0/24"]
```

</details>

{% hint style="info" %}
Authentication is managed through the Google Cloud Terminal.
{% endhint %}

6. After creating and saving the main.tf file, execute the following command in the same directory. This ensures that the required Terraform resource files from GCP are downloaded and accessible to the system.

```json
terraform init
```

7. Before applying or destroying a Terraform configuration file, it's recommended to run the following:

```json
terraform plan
```

If GCP requires authentication, grant permission accordingly.

8. To initiate the deployment of WEKA in GCP, run the following command:

```json
terraform apply
```

This command initiates the creation of GCP resources essential for WEKA. When prompted, confirm the deployment of resources by typing **yes**.

Upon completing the Terraform GCP resource deployment process, a summary of the outcome is displayed. In the event of an unsuccessful deployment, an error message indicating failure is shown instead.

```json
Outputs:

weka_deployment_output = {
  "client_ips" = []
  "cluster_helper_commands" = <<-EOT
  ########################################## get cluster status ##########################################
  curl -m 70 -X POST "https://weka-gcp-weka-status-t6p6clcama-ue.a.run.app" \
  -H "Authorization:bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type:application/json" -d '{"type":"progress"}'
  # for fetching cluster status pass: -d '{"type":"status"}'
  
  ########################################## resize cluster command ##########################################
  curl -m 70 -X POST "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=resize" \
  -H "Authorization:bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type:application/json" \
  -d '{"value":ENTER_NEW_VALUE_HERE}'
  
  
  ########################################## pre-terraform destroy, cluster terminate function ################
  
  # replace CLUSTER_NAME with the actual cluster name, as a confirmation of the destructive action
  # this function needs to be executed before terraform destroy
  curl -m 70 -X POST "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=terminate_cluster" \
  -H "Authorization:bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type:application/json" \
  -d '{"name":"CLUSTER_NAME"}'
  
  
  ################################# get weka password secret login ############################################
  
  gcloud secrets versions access 1 --secret=weka-gcp-weka-password  --project wekaio-public --format='get(payload.data)' | base64 -d
  
  ############################################## get backend ips ##############################################
  
  gcloud compute instances list --filter="labels.weka_cluster_name=gcp-weka" --format "get(networkInterfaces[0].networkIP)" --project wekaio-public
  
  
  EOT
  "cluster_name" = "gcp-weka"
  "functions_url" = {
    "destroy" = {
      "body" = {
        "name" = "gcp-weka"
      }
      "url" = "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=terminate_cluster"
    }
    "progressing_status" = {
      "body" = {
        "type" = "progress"
      }
      "url" = "https://weka-gcp-weka-status-t6p6clcama-ue.a.run.app"
    }
    "resize" = {
      "body" = {
        "value" = 7
      }
      "url" = "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=resize"
    }
    "status" = {
      "body" = {
        "type" = "status"
      }
      "url" = "https://weka-gcp-weka-status-t6p6clcama-ue.a.run.app"
    }
  }
  "get_cluster_status_uri" = "https://weka-gcp-weka-status-t6p6clcama-ue.a.run.app"
  "lb_url" = "gcp-weka.weka.private.net"
  "nfs_protocol_gateways_ips" = tostring(null)
  "private_ssh_key" = "/tmp/weka-gcp-weka-private-key.pem"
  "project_id" = "wekaio-public"
  "resize_cluster_uri" = "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=resize"
  "smb_protocol_gateways_ips" = tostring(null)
  "terminate_cluster_uri" = "https://weka-gcp-weka-weka-functions-t6p6clcama-ue.a.run.app?action=terminate_cluster"
  "vm_username" = "weka"
  "weka_cluster_password_secret_id" = "weka-gcp-weka-password"
}
```

{% hint style="info" %}
Refer to the `Get WEKA Password Secret Login` section for future reference. This section contains the necessary information to retrieve the WEKA password.
{% endhint %}

#### Additional commands in the output

The output includes several other commands to allow you to view information or modify the deployment, in addition to a command to look up the WEKA admin password.

* Get cluster status
* Resize cluster command
* Pre-terraform destroy, cluster terminate function
* Get backend ips

Run the `get cluster status` command to verify the state of the WEKA deployment.

```jsx
  curl -m 70 -X POST "https://weka-gcp-weka-status-t6p6clcama-ue.a.run.app" \
  -H "Authorization:bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type:application/json" -d '{"type":"status"}'
```

Here is the output from the example

{% code overflow="wrap" %}

```jsx

{"initial_size":7,"desired_size":8,"clusterized":true,"weka_status":{"hot_spare":1,**"io_status":"STARTED"**,"drives":{"active":16,"total":16},"name":"gcp-weka","io_status_changed_time":"2024-05-13T13:43:50.740546Z","io_nodes":{"active":24,"total":24},"cloud":{"enabled":true,"healthy":true,"proxy":"","url":"https://api.home.weka.io"},"release_hash":"f94d361cf0e465a4f04214064b5f019b9149baf3","hosts":{"active_count":24,"backends":{"active":24,"total":24},"clients":{"active":0,"total":0},"total_count":24},"stripe_data_drives":4,"release":"4.3.0","active_alerts_count":2,"capacity":{"total_bytes":3376488600000,"hot_spare_bytes":482217460000,"unprovisioned_bytes":482217460000},"is_cluster":true,"status":"OK","stripe_protection_drives":2,"guid":"603d3b67-03ce-49af-8833-4f2e6a985b1e","nodes":{"black_listed":0,"total":48},"licensing":{"io_start_eligibility":true,"usage":{"drive_capacity_gb":6442,"usable_capacity_gb":3376,"obs_capacity_gb":0},"mode":"Unlicensed"}}}
```

{% endcode %}

The section **`"io_status":"STARTED"`** shows that the cluster is fully up and running and ready for access.

### Deploy protocol servers (NFS and SMB)

The Terraform deployment simplifies the process of deploying additional compute instances to serve as protocol servers (protocol gateways) for NFS or SMB. These protocol gateways are separate from the instances designated for the WEKA backend cluster.

To deploy protocol gateways, add more information to the `main.tf` file.

The simplest approach is to specify the number of protocol gateways for each type (NFS and SMB) and use default settings for the other parameters. If you plan to distribute your NFS or SMB connections across multiple protocol servers manually, you can adjust these numbers according to your needs. For instance, if you have three projects, each requiring its own bandwidth for NFS, you can deploy three protocol gateways. Assign each project the IP address or DNS entry of its respective gateway to use as the NFS server.

Add the following before the last `‘}’` of the main.tf file.

```bash
## Protocol gateways ##

## For deploying NFS protocol gateways ##
nfs_protocol_gateways_number = 2 # A minimum of two is required

## For deploying SMB protocol gateways ##
smb_protocol_gateways_number = 3 # A minimum of three is required 
```

## Collect login access information about the WEKA cluster

### **Obtain the WEKA cluster IP addresses**

To obtain the IP addresses of your WEKA cluster, follow these steps:

1. Visit the GCP Compute Engine VM instances dashboard.

<div data-with-frame="true"><figure><img src="/files/XoLhewoBbRBmBQ5WBRYw" alt=""><figcaption></figcaption></figure></div>

2. Identify the WEKA backend servers. The instance names follow the format: `<cluster_name>-<Timestamp>`, where `<cluster_name>` corresponds to the value specified in the `main.tf` file.

<div data-with-frame="true"><figure><img src="/files/vz7l8F42DD59pYEDQwRt" alt=""><figcaption></figcaption></figure></div>

3. Select any WEKA backend instance and note the IP address of `nic0`.

This IP address is used if your subnet assigns a public IP address to the instance (that is if the VM instance is configured accordingly). WEKA uses only private IPv4 addresses for all interface IP addresses for communication.

#### Retrieve the **WEKA cluster access password**

The WEKA cluster password is securely stored in the Google Cloud Platform (GCP) Secret Manager. You can retrieve it using the `gcloud` command from the Terraform output or through the GCP console. Follow these steps to access the password through the GCP console:

1. Open the GCP console and search for **Secret Manager**.

<div data-with-frame="true"><figure><img src="/files/Es2Lg9EUwADS0nDetFZ4" alt=""><figcaption></figcaption></figure></div>

2. Navigate to the **Secrets** section within the Secret Manager.

<div data-with-frame="true"><figure><img src="/files/H4Z5FJhjfEi3wXiK5ewW" alt=""><figcaption></figcaption></figure></div>

3. Locate and select the secret named `weka_<cluster_name>_password` corresponding to your deployment.
4. Select the Actions option and select **View secret value**.

<div data-with-frame="true"><figure><img src="/files/HsBAA4kDFVtlfkXDZUV4" alt=""><figcaption></figcaption></figure></div>

The system displays the randomly generated password assigned to the WEKA user admin.

<div data-with-frame="true"><figure><img src="/files/gwVcSoA2DdXyfGuFZYX9" alt=""><figcaption></figcaption></figure></div>

### Access the WEKA cluster backends

You can access the WEKA cluster backend instances through SSH directly from the GCP browser window. This method allows you to run WEKA CLI commands and gather logs as needed.

Follow these steps to connect to the backend instances:

1. Open the GCP console.
2. Navigate to the Compute Engine section.
3. Select the instance you wish to access.
4. Select the SSH button to open a browser-based SSH session.

<div data-with-frame="true"><figure><img src="/files/RNldZeZXzJ6XsgXBl9AD" alt=""><figcaption></figcaption></figure></div>

## Access and review the WEKA GUI

To access the WEKA GUI, use a jump host with a GUI deployed within the same VPC and subnet as the WEKA cluster.

### Access the WEKA GUI

In the following examples, a Windows 10 instance with a public IP address is deployed in the same VPC, subnet, and security group as the WEKA cluster. The network security group rules are added to allow RDP explicit access to the Windows 10 system.

1. Open a browser in the Windows 10 jump box.
2. Visit https\://\<cluster-backend-ip>:14000. The WEKA GUI sign-in screen appears.
3. Sign in as user **admin** and use the password retrieved earlier ( see [#retrieve-the-weka-cluster-access-password](#retrieve-the-weka-cluster-access-password "mention")).

{% hint style="info" %}
The provided examples are for reference. The values shown below may differ from those of your cluster.
{% endhint %}

<div data-with-frame="true"><figure><img src="/files/4kc6wwtMa4QvToBVBN6n" alt=""><figcaption></figcaption></figure></div>

### Review the WEKA GUI

1. View the cluster GUI home screen.

<div data-with-frame="true"><figure><img src="/files/IvD6EtArJ5d9KVqLbncX" alt=""><figcaption></figcaption></figure></div>

2. Review the cluster backends. Check the status and details of the backend instances.

<div data-with-frame="true"><figure><img src="/files/brlumlmzOitEEeN1p3QF" alt=""><figcaption></figcaption></figure></div>

3. Review the clients, if any, attached to the cluster.

<div data-with-frame="true"><figure><img src="/files/CfXmXSeViSuPWoqAN8na" alt=""><figcaption></figcaption></figure></div>

4. Review the filesystems.

<div data-with-frame="true"><figure><img src="/files/oCoKG0MxJc2Pp35njkVk" alt=""><figcaption></figcaption></figure></div>

## Automated scale-out and scale-in of the WEKA backend cluster

The WEKA backend cluster can be scaled out and scaled in using an API call through the GCP Cloud terminal.

The WEKA backend cluster can be dynamically scaled out and scaled in using API calls through the GCP Cloud terminal. The process is managed by Terraform-created functions that automatically trigger when a new instance is initiated or retired. These functions execute the necessary automation processes to adjust the cluster's computing resources.

To scale out from the initial deployment, use the CLI command provided in the Terraform output.

<div data-with-frame="true"><figure><img src="/files/DwP0yWmCQvtnUiqcoUkM" alt=""><figcaption><p>Example: Scale-out from 7 backends to 8</p></figcaption></figure></div>

### Benefits of auto-scaling

* **Replace unhealthy instances:**
  * Auto Scaling automatically initiates the replacement of instances that fail health checks. It launches new instances and incorporates them into the WEKA cluster, ensuring continuous availability and responsiveness.
  * This process mitigates the impact of instance failures by promptly integrating the new instance into the cluster and service.
* **Graceful scaling:**
  * Auto-scaling configurations can be adjusted to perform scaling actions gradually. This prevents sudden spikes in traffic and minimizes application disruptions.
  * This measured approach maintains a balanced and stable environment, effectively adapting to changes in demand without causing abrupt changes.

## **Test WEKA cluster self-healing functionality (optional)**

To validate the self-healing functionality of the WEKA cluster, you can decommission an old instance and allow the Auto Heal feature to launch a new one. Follow this brief guide:

1. **Identify the old instance:** Locate the GCP VM instance you want to decommission. This can be based on factors such as age, outdated configurations, or other criteria.
2. **Terminate the old instance:** Manually terminate the identified GCP VM instance using the GCP Management Console, gcloud CLI, or SDKs. This action triggers the Auto Heal process.
3. **Verify the new instance:** Ensure the new instance is successfully launched, passes the health checks, and joins the cluster. Confirm that the cluster's overall capacity remains unchanged.
4. **Document and monitor:** Record the decommissioning process and monitor the cluster to ensure it continues to operate smoothly with the new instance in place.

## APPENDICES

### Appendix A: Required permissions that Terraform needs

The **Compute Engine** and **Workflows API** services must be enabled to allow the following services:

* artifactregistry.googleapis.com
* cloudbuild.googleapis.com
* cloudfunctions.googleapis.com
* cloudresourcemanager.googleapis.com
* cloudscheduler.googleapis.com
* compute.googleapis.com
* dns.googleapis.com
* eventarc.googleapis.com
* iam.googleapis.com
* secretmanager.googleapis.com
* servicenetworking.googleapis.com
* serviceusage.googleapis.com
* vpcaccess.googleapis.com
* workflows.googleapis.com

The user running the Terraform module requires the following roles to run the `terraform apply`:

* roles/cloudfunctions.admin
* roles/cloudscheduler.admin
* roles/compute.admin
* roles/compute.networkAdmin
* roles/compute.serviceAgent
* roles/dns.admin
* roles/iam.serviceAccountAdmin
* roles/iam.serviceAccountUser
* roles/pubsub.editor
* roles/resourcemanager.projectIamAdmin
* roles/secretmanager.admin
* roles/servicenetworking.networksAdmin
* roles/storage.admin
* roles/vpcaccess.adminroles/workflows.admin

[^1]: Terraform is an infrastructure-as-code tool for provisioning manager.


# Google Kubernetes Engine and WEKA over POSIX deployment

A step-by-step guide to setting up Google Kubernetes Engine (GKE) with WEKA on Google Cloud Platform (GCP), enhancing storage and scalability for demanding Kubernetes workloads.

## Introduction

Google Kubernetes Engine (GKE) is a managed Kubernetes service for deploying, managing, and scaling containerized applications. WEKA is a high-performance, scalable storage platform that integrates seamlessly with Kubernetes clusters to provide persistent storage for demanding containerized applications and workflows.

Combining GKE and WEKA results in an easily automated and managed Kubernetes environment, delivering best-in-class performance at scale.

## Requirements for WEKA over POSIX with GKE

* GKE must be deployed in [Standard mode](https://cloud.google.com/kubernetes-engine/docs/concepts/choose-cluster-mode#why-standard).
* GKE Worker nodes must be configured with Ubuntu OS.

{% hint style="info" %}
If [GPUDirect-TCPX](https://cloud.google.com/compute/docs/gpus/gpudirect) (supported on GKE only with Google Container Optimized OS) is required, configure WEKA over NFS. For details, see [Manage the NFS protocol](/additional-protocols/nfs-support).
{% endhint %}

## Workflow

1. Deploy GKE in Standard mode with Ubuntu OS.
2. Set up WEKA client on existing GKE worker nodes.
3. Configure automated WEKA setup client on worker nodes.
4. Install and configure the WEKA CSI plugin.
5. Set up WEKA storage for GKE pods.

### 1. Deploy GKE in Standard mode with Ubuntu OS

Follow these steps to deploy GKE in Standard mode with Ubuntu OS for the worker nodes. For complete GKE documentation, visit the [GCP documentation](https://cloud.google.com/kubernetes-engine/docs).

**Procedure:**

1. Go to the GCP menu, select **Kubernetes Engine**, and then **Clusters**.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXe7js2-Za8ecCfalw-w36aPDcOhr0hYENsQqgUSppY_F7Pe9or1s4f1v66IIiwubpUticNNcYa_Tmg6CyWD_4RvOoDzzT_9LQKaPgly-ZRGf6PxtKYc4MGHLsFh2Fdt-WEyVLn3vDATLtXCNftjPy114YmK7pzHsCaC2OE42Q?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

2. Click **CREATE** to create a new cluster.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXeWrY0z7zDdleUBG99xAOsY3l-cUgE21EWBxc1dnzumZL_vM0EzG0KJ3Br7KQYKri89UPX4-SAlT6Le48jCsXrBrdjhRNwheoug6LdqwE-Gmp8Od853-Wi2ntIcwfPTJ_Mt4E_dyrbr6_mRVevEdW1vdL3BY-rv9_lBnZ_-IQ?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

3. If prompted, click **SWITCH TO STANDARD CLUSTER.** This mode also enables SSH access to worker nodes, which is necessary for installing the WEKA POSIX clients.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdl3dWZ_WebOkRZtf0POFi5hXdG2x9HuBCNs65FcGPO65iIE1xvS6GqrqR8a8ANamnog77o-LrSWxBew7I6DHfHjTipsPMzO27DfeqsUlp1SWneMQtF-V1f65u8yNX8vxnH0cvMYtj3z2RxqEgqQXEJfDT2ZBnGPR77tqdo?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdiqiPkERPHqtfvdnG-0Rc4CO81EKFALcIxkq14TSSBNZZJKsrMWWrdygnag4VArNi2D9sKYuRsYPoB5dEbAndQwNMIO4MW7uNUnSSrr511U9WAXzZtB2Ywe5yB4wbiTus7SOEsjUcT8ly9soro9WIUoTyDk6D0SL3ZaMP6qQ?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

4. Change from a regional to a zonal setup. Select the zone where the WEKA Cluster management IPs are located to ensure optimal communication and performance. This step ensures seamless communication between GKE and the WEKA cluster.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdWO4qd8vt3kllEoS8tNKUe205TcI0eE_hCSKtrhCx_aS4H5yKUY_vDlioa4P_1vZrBjRjyEuyTCYbR1E9Rc1QTqmIztZcy-gVBwEqAtSJ74mK0itx3PWWBj7OFE1-sjKf_HOfYIvbKtsHAe6goKNvCngssARLIYQ_Vxz7pfA?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

5. Adjust the node pool settings: Go to **Nodes** within the **default-pool** under **NODE POOLS** in the GKE console, and change the **Image type** to **Ubuntu with containerd (ubuntu\_containerd)**.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXfYSvYN_gCungoz6cPuIxzppBGbC9RSvMlrgr3fbtCKMKplWi6hZLmEGNWzV1qBCJGB9JF-WekXnz4xRlQxiDoeDdvmB-jmbUjNQZaQRfnsbCZKzb66IK99WE0NmDxkUWIMvM1l-vq6fzqJZqp5vgso58hH8x5-pe6MIdSxNA?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

6. Ensure worker nodes meet a minimum configuration of 8 vCPUs and 32 GB RAM. The WEKA client requires a minimum of 2 vCPUs and 5 GB of RAM.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXcjUHQIwEBPTZABA5tgX7d8XV53-88z5b8epKIc_fX9Q9qZuRcLPpiKLsKAoCrPZmE3Hj9Se5-VNLQvFWgrb6hATRyV9UikVxUn8gfqtWZ-CLdy3CdaFQDVpAJ8q7w1OZp6MVGUDIuTr2RlnLDFOAZELVqx2nOZvlG8u5qw?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

7. If the GKE cluster was set up in advance, deploy the WEKA cluster to the same networking VPC and subnet. Otherwise, ensure that the GKE cluster networking is configured within the same VPC and subnet as the WEKA management IPs. Aligning networking elements per the recommendation will ensure optimal performance.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXc5P1eisd6vPHVpzOSOaqtDPiZ9PxkOgozRt0oDCkKB-TXCusX3_gQQcIwHNYkU6ag-G0BaDGpPhCQZAsVEUzHYON0wfu7RIQXpiJpaBW_PKxWtcCz9_MkPgtIXpqrlAtYazbfP-pnEMlAGROKPEM_XG_iDUtVwQ3tpKfQV5Q?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXfaaCA6140795DaNo8a0WRhUPIuVQk_hHDd1GZ8UHYlxGubV9rSC2YMYSmvA7I8RuxJA_4grBFyRldoeWv5_XJ_pT2ncMbGiRUNrXazd0gP54FK2hMLJrS5PgR1JSfA2YFU5uJ32RmJ8X5pZOh9czYvZ7X1UiBKtX2DCmt13Q?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

8. Click **CREATE** to create the cluster.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXed4i-476nzMh0I-oJuiijDuDO4i7TguldIN-boK_Y2piO2y5coz8h4yzYJg_rPA8Z1K57ksz7IeIuTvya6x-0yuJRdSknbcazfrWSNa95FLpLCSwGO0DOsmT4Gv82mvH1l-ipYgL3WVdXlZucIFCpIeVmN9wYqtsiSyu9h7g?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

9. Wait for the cluster status to indicate **Ready** or **Green** before proceeding with further configuration or deployment tasks.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdVazQ4v1lXR7yEZAKt9Rqdt8YsPuBzOfjb0WAqW6H4U3AK-oJveh1wkOoHoLQwFl4E1UyRt1O_S4PcOwwY2S4_g_Llo1alkSPZvg37jAVt3m3I5uF8eAM2nGJ6lZ_E1tSx_iRYtV2_xwaDOAbaEMYBHuYdo7VWMELChHNEXQ?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

### 2. Set up WEKA client on existing GKE worker nodes

Perform this procedure for each GKE worker node individually.

{% hint style="info" %}
Any new GKE worker nodes added later will require these steps for WEKA client installation unless the following automation steps are implemented.
{% endhint %}

**Before You Begin**

Ensure SSH access to the GKE worker nodes is available to install the WEKA client.

**Procedure:**

1. Identify the names of the GKE worker nodes where the WEKA client will be installed.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXf3Aik8MJkbu4UFVBH-Mfcc4YAUm-OFES2z5UHuDkv0KbWOn3mC7K5V0CaBw_BoSwWYhot70uiOQPuHSUb7KPGnkEc6mwbwQWXG6YGYWEsJ4uABlvtAnMt1KRXXoK7xe4gxXbKIICcwVXgTWEPNVQpOpumzH4FW36iOkTWo?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

2. Go to **Google Cloud Platform > Compute Engine > VM Instance** console. Locate the identified GKE worker node, select **SSH connect** from the dropdown menu, and choose **Open in browser window** to initiate the SSH connection.

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXfaFLru7kgPoKpFe9FplHvpt-yQs4oWT0FlnD8zwt6U7kRx9Krn1ezVpn7H6yWmiQkn8BqEQWsUPGyzbWF8LeW5XMnLh9R3Y2Uw5x4hJMYqdyfjQ-IRaw2cutTjJCJsJj7J8hxw-wAf27wa0U_yyrtevScRS8aJN84zEvcueQ?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>

3. To avoid CPU pinning conflicts with GKE, start the WEKA client using a stateless client mount. Authorize the SSH connection, then add the WEKA client from the existing WEKA cluster. For details, see the [Add clients](/planning-and-installation/bare-metal/adding-clients-bare-metal) procedure.

{% tabs %}
{% tab title="Transferring SSH keys to the VM" %}

<div data-with-frame="true"><figure><img src="/files/XPEtOFqViG6GgJJjmEe2" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="Authorize" %}

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdOp0Ga1pI1vr5uFQNTGoRd-Vxc2Kig6p-AMKetPUs_oYktzIXZnwQwxyotjie0sYL5SYS0umYQ1OUeZzVSjJSZVV755o8bFCTFeavWJQwsdIkwug3lPgIzFO1Dng--jJENpgTn053f5CzNgJZt8heLv5TCy_nw6eU3Kndo?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="Install a WEKA client" %}

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdI8lv7DFfl-Y3ouYTikT3NHuvjSze6uWaG9pyUvEYGwAEenqVuxK2TN5P2senW4pUPMnlrp88pDFCFwGQ6ni2BohKU-AxaSFWFPrl46Hfju3Vx3QPuHRXYE5ZrTDzAciwaduSpazZgSYYRda_VAKmbQ15MXYgH1nVIRCIrQg?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="Make directory and mount" %}

<div data-with-frame="true"><figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXd4h1rADicmGaJrhqe50gVcvmSoNxYeI_takFqIVELuqJ8oVB8p-PuNTgIBwIJPu-EFOoN9E89xJkfQs-Hy2237Gqf9vZKeZyw7JHZpdMrpZKnuqZDrkKWA-VZqm134DEmC3VqizjvG1f0_YH3i4IcJMiqVurUKR44TOuZv?key=pmcWhfRW5GQA1x-KXJSIuA" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}

### 3. Configure automated WEKA setup client on worker nodes

Google Cloud Platform (GCP) allows the addition of startup scripts at the project level, ensuring each new instance runs the script. By using metadata lookups, the WEKA client installation you can restrict to GKE cluster systems.

With auto-scaling enabled, GKE automatically adds and sets up the WEKA client on each new worker node.

**Procedure:**

1. In the GCP **Compute Engine** console, scroll to the bottom of the left-side menu.
2. Select **Metadata** under the **Settings** section.
3. Click **EDIT**, then select **+ ADD ITEM**.
4. Set the key name to **startup-script** (no spaces), and paste the following GKE WEKA client install script into the **Value** field. Replace the following input values according to your environment:
   * WEKA\_FS (line 11)
   * WEKA\_HOSTS (line 17)
   * GKE\_CLUSTER\_NAME (line 99)

<details>

<summary>GKE WEKA client install script</summary>

{% code lineNumbers="true" %}

```bash
curl -sS -H 'Metadata-Flavor: Google' 'http://metadata.google.internal/computeMetadata/v1/instance/?recursive=true&alt=json' | jq '.attributes."cluster-name"' -r

(
    #!/usr/bin/env bash

    set -euo pipefail

    DEBIAN_FRONTEND=noninteractive
    ROOT_MOUNT_DIR="${ROOT_MOUNT_DIR:-/root}"
    
    export WEKA_FS="default"

    # Mount point for weka filesystem
    export WEKA_MOUNT="/mnt/gkeclient"
    
    # Its good to add 2-3 servers in case one is not available 
    export WEKA_HOSTS="10.0.0.8,10.0.0.9,10.0.0.10"
    
    # Timeout for how long the client is inaccessible before being removed from the cluster
    
    # Default is 86400 (24hrs) in a more dynamic environment it can be lower. 
    export WEKA_CLIENTTIMEOUNT="3600"
    
    # Number of cores to add to WEKA FrontEnd.
    export WEKA_FRONTENDCORES=2
    
    # First IP taken from WEKA_HOSTS list to download the client from.
    export WEKA_DOWNLOADIP=$(echo "$WEKA_HOSTS" | cut -d',' -f1)
  
  
    echo "Installing dependencies"
    apt-get update
    apt-get install -y apt-transport-https curl gnupg lsb-release jq

    echo "Installing gcloud SDK"
    snap install google-cloud-sdk --classic

    echo "Getting node metadata"
    ALL_METADATA="$(curl -sS -H 'Metadata-Flavor: Google' 'http://metadata.google.internal/computeMetadata/v1/instance/?recursive=true&alt=json')"
    NODE_NAME="$(curl -sS http://metadata.google.internal/computeMetadata/v1/instance/name -H 'Metadata-Flavor: Google')"
    ZONE="$(curl -sS http://metadata.google.internal/computeMetadata/v1/instance/zone -H 'Metadata-Flavor: Google' | awk -F  "/" '{print $4}')"

    echo "Setting up disks"
    DISK_NAME="$NODE_NAME-wekadir"

    if ! gcloud compute disks list --filter="name:$DISK_NAME" | grep "$DISK_NAME" > /dev/null; then
        echo "Creating $DISK_NAME"
        gcloud compute disks create "$DISK_NAME" --size=$(( 1024*20 )) --zone="$ZONE"
    else
        echo "$DISK_NAME already exists"
    fi

    if ! gcloud compute instances describe "$NODE_NAME" --zone "$ZONE" --format '(disks[].source)' | grep "$DISK_NAME" > /dev/null; then
        echo "Attaching $DISK_NAME to $NODE_NAME"
        gcloud compute instances attach-disk "$NODE_NAME" --device-name=sdb --disk "$DISK_NAME" --zone "$ZONE"
    else
        echo "$DISK_NAME is already attached to $NODE_NAME"
    fi
    function create_wekaio_partition() {
        echo "--------------------------------------------"
        echo " Creating local filesystem on WekaIO volume "
        echo "--------------------------------------------"

        wekaiosw_device="/dev/sdb"
        if mount | grep -w $wekaiosw_device | grep -w /opt/weka; then
          echo "Weka volume is already mounted"
        else
          echo "Formatting and mounting Weka trace volume"
          mkfs.ext4 -L wekaiosw ${wekaiosw_device} || return 1
          mkdir -p /opt/weka || return 1
          mount $wekaiosw_device /opt/weka || return 1
          echo "LABEL=wekaiosw /opt/weka ext4 defaults 0 2" >>/etc/fstab
        fi
    }
    function prepare_weka_env() {
        echo "--------------- ENV ---------------"
        env
        echo "--------------- ENV ---------------"
        create_wekaio_partition || logger -s -t weka.install "Failed creating wekaio partition"
    }

    function start_weka_client() {
        prepare_weka_env
        if ! which weka; then
          echo "Installing agent from ${WEKA_DOWNLOADIP}"
          curl --fail --max-time 10 "http://${WEKA_DOWNLOADIP}:14000/dist/v1/install" | sh || logger -s -t weka.install "Failed installing agent from the first backend"
        else
          echo "Weka seems already installed, skipping agent install"
        fi
        mkdir -p ${WEKA_MOUNT}
        if mount | grep -w ${WEKA_MOUNT}; then
          echo "Weka filesystem seems already mounted on endpoint, skipping mount"
        else          
          mount -t wekafs ${WEKA_HOSTS}/${WEKA_FS} ${WEKA_MOUNT} -o remove_after_secs=${WEKA_CLIENTTIMEOUNT},num_cores=${WEKA_FRONTENDCORES},net=udp || logger -s -t weka.install "Error mounting filesystem"
        fi
    }

## Update to the name of the GKE cluster
GKE_CLUSTER_NAME=my-gke-cloud-name
GKE_METADATA_CLUSTER_NAME=$(curl -sS -H 'Metadata-Flavor: Google' 'http://metadata.google.internal/computeMetadata/v1/instance/?recursive=true&alt=json' | jq '.attributes."cluster-name"' -r)

if [ "$GKE_CLUSTER_NAME" != "GKE_METADATA_CLUSTER_NAME" ]; then
    echo "Instance does not belong to GKE cluster $GKE_CLUSTER_NAME. Skipping installation"
else
    echo "Instance belongs to GKE cluster, initializing Weka client installation"
    start_weka_client
fi

) >/root/startup.out 2>/root/startup.err
```

{% endcode %}

</details>

5. After adding the startup script, click **SAVE** at the bottom of the page.
6. Test the script:
   * Increase the Node Pools node count.
   * Check the client list in WEKA UI to verify that the new clients have been added.

### 4. Install and configure the WEKA CSI plugin

To install and configure the WEKA CSI plugin, follow the procedures in the [WEKA CSI Plugin](/appendices/weka-csi-plugin) section.

{% hint style="info" %}
You may need to adjust the steps according to your specific setup and requirements.
{% endhint %}

### 5. Set up WEKA storage for GKE pods

To set up WEKA storage for use by GKE pods, follow the procedures in the[Dynamic and static provisioning](/appendices/weka-csi-plugin/dynamic-and-static-provisioning) section, in the CSI Plugin section.


# WEKA installation on OCI

WEKA Data Platform deployment on Oracle Cloud Infrastructure (OCI) follows bare-metal installation with cloud-specific considerations.

## Overview

The WEKA Data Platform deployment on OCI follows a process similar to bare-metal installation, with adaptations for cloud-specific architecture. This implementation allows you to leverage WEKA's high-performance storage capabilities within Oracle's cloud environment.

OCI provides the necessary infrastructure components for WEKA deployment, including bare-metal compute shapes, virtual networking, and storage options. However, certain limitations exist compared to on-premises deployments, particularly regarding network configuration flexibility.

<div data-with-frame="true"><figure><img src="/files/9MsIkXmvbTqbIkimY6mG" alt=""><figcaption><p>WEKA cluster on OCI deployment</p></figcaption></figure></div>

## Workflow

The deployment process includes the following main phases:

1. Prepare OCI bare metal infrastructure for WEKA.
2. Install add-ons using templates for OCI HPC Images.
3. Install WEKA on the OCI bare metal infrastructure.
4. Configure the WEKA cluster.
5. Add clients.

{% hint style="warning" %}
WEKA strongly recommends that you coordinate and obtain approval from OCI personnel before deploying any WEKA systems on OCI. This coordination ensures your deployment will be compatible with OCI's architecture and comply with cloud resource management policies.
{% endhint %}

### 1. Prepare OCI bare metal infrastructure for WEKA

Establish the foundational infrastructure required before installing the WEKA Data Platform software.

**Procedure**

1. **Verify resource compartment access:**
   1. Sign in to <https://cloud.oracle.com>.
   2. Search for and select **compartments** from the **Services** section.
   3. Locate and click your designated **resource compartment** link.

{% hint style="info" %}
If you see "Nothing here? Possible reasons..." message, you lack proper access permissions. Contact your cloud team for access before proceeding.
{% endhint %}

2. **Verify IAM policy statements:**

   Navigate to <https://cloud.oracle.com/identity/domains/policies> and verify your login has these permissions:

   * allow group \<identity group> to manage **compute-management-family** in compartment \<resource compartment>
   * allow group \<identity group> to manage **virtual-network-family** in compartment \<resource compartment>
   * allow group \<identity group> to manage **instance-family** in compartment \<resource compartment>
   * allow group \<identity group> to manage **volume-family** in compartment \<resource compartment>
   * allow group \<identity group> to manage **object-family** in compartment \<resource compartment>

   Replace terms in angle brackets with your company's specific names.
3. **Create cloud network:**
   1. Search for and select **VCN** from the **Services** section.
   2. Ensure the designated VCN has:
      * Subnet with sufficient addresses for admin/management access to each server.
      * Subnet with sufficient addresses for high-performance access to each server.
      * Subnet with sufficient addresses for high-performance clients mounting WEKA.

{% hint style="info" %}
VCN capacity planning must account for both WEKA Data Platform and high-performance clients, as client mount connections cannot traverse firewalls or NAT-gateways.
{% endhint %}

4. **Deploy bare-metal servers:**
   1. Search for and select **Instances** from the **Services** section.
   2. Select the computer image:
      * Find your preferred OS version on [Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility#operating-system).
      * Select a matching image from the OCI instance image gallery.
   3. Select the appropriate server shape. Supported shapes:
      * BM.Optimized3.36
      * BM.DenseIO.E5.128
      * BM.HPC.E5.144
      * BM.GPU.H100, BM.GPU.H200, and BM.GPU.A100
   4. Configure the boot volume:
      * Access the **Size and Performance** settings panel for the boot volume.
      * Switch to **Custom Configuration** mode.
      * Using the performance slider, set the VPUs/GB ratio to a minimum of **40**. Consider increasing this value beyond 40 VPUs/GB during periods of elevated cluster activity, because performance traces are stored on this boot volume.
   5. Configure network interfaces.

### 2. Install add-ons using templates for OCI HPC Images

Provision compute instances using a supported Oracle Cloud Infrastructure (OCI) system image. This ensures compatibility and a consistent baseline for deployment.

Supported images:

* Oracle Linux 8
* Ubuntu 22.04
* Ubuntu 24.04

### 3. Install WEKA on the OCI bare metal infrastructure

1. Download the WEKA software. See [Obtain the installation packages](/planning-and-installation/bare-metal/obtaining-the-weka-install-file).
2. Install the WEKA software.

   * Once the WEKA software tarball is downloaded from [get.weka.io](https://get.weka.io/), run the untar command.
   * Run the `install.sh` command on each server, following the instructions in the **Install** tab of [get.weka.io](https://get.weka.io/ui/dashboard).

   Once completed, the WEKA software is installed on all the allocated servers and runs in stem mode (no cluster is attached).

### 4. Configure the WEKA cluster

1. Use the resources generator to create configuration files (`drives0.json`, `compute0.json`, and `frontend0.json`) in the **/tmp** directory of each server.
2. Create containers using these configuration files on all cluster servers.
3. Complete essential post-configuration:
   * Apply your license.
   * Activate the IO service.
   * Verify your configuration.
   * Consider enabling event notifications if needed.

Refer to the related topics for detailed instructions on each step.

**Related topics**

[Configure the cluster with Resources Generator](/planning-and-installation/bare-metal/manually-configure-the-weka-cluster-using-the-resource-generator)

[Perform post-configuration](/planning-and-installation/bare-metal/perform-post-configuration-procedures).

### 5. Add clients or use converged mode

Depending on your deployment mode, you can choose one of the following options to access the WEKA filesystem:

* **Client-server mode:** In this configuration, client functionality is deployed on dedicated client servers, similar to a bare-metal WEKA cluster. This setup separates client and backend functionality. For detailed instructions, refer to [Add clients](/planning-and-installation/bare-metal/adding-clients-bare-metal).
* **Converged mode:** In this configuration, client functionality is integrated with the backend servers. You can create a filesystem and mount it directly on each of the WEKA backend servers.

### What to do next

Proceed to [Getting Started with NeuralMesh](/getting-started-with-weka/manage-the-system-using-weka-gui), which serves as your entry point for using the WEKA system. Start by familiarizing yourself with the graphical user interface (GUI) and command-line interface (CLI). Once you are comfortable, you can perform your first I/O operations using the WEKA filesystem. This includes creating a filesystem and mounting it on the appropriate client or backend servers, depending on your chosen deployment mode.


# NeuralMesh Axon overview

Explore the high-performance, co-located architecture and unified namespace model of the NeuralMesh Axon storage solution.

## Introduction

NeuralMesh Axon is a high-performance, Linux-native storage platform engineered for large-scale AI and agentic workloads requiring microsecond-level latency and exceptional IOPS throughput. The system exposes a POSIX-compliant parallel filesystem designed to support massive datasets while maintaining consistent, low-latency access across distributed GPU-accelerated environments.

A defining characteristic of NeuralMesh Axon is its co-located deployment model, in which storage and compute services run on the same physical infrastructure. Rather than relying on external storage appliances, NeuralMesh services operate directly on the CPUs and NVMe SSDs inside the GPU servers. This integrated design reduces hardware footprint and power consumption while improving availability, performance predictability, and data locality.

All NeuralMesh Axon components execute within isolated Linux containers. These containers operate with predefined CPU, memory, network, and NVMe resource assignments, ensuring clear separation between storage services and application workloads while enabling consistent performance across the fleet.

NeuralMesh Axon is optimized for extremely large-scale GPU server deployments, leveraging unused CPU cores and locally attached NVMe SSDs to deliver a cost-efficient, high-performance distributed storage layer.

Minimum deployment requirements include:

* **Server count:** 32 servers (minimum)
* **Data protection scheme:** 16 data + 4 parity failure domains (fixed configuration)

## Deployment model

NeuralMesh Axon uses a distributed, co-located architecture in which each server contributes both compute resources and local NVMe capacity to the storage cluster.

The following model is reflected in the architecture illustration:

* Application workloads run on the same servers that host NeuralMesh storage containers.
* CPU and SSD resources are shared between application and storage functions but remain isolated at the software level through containerization.
* Each server hosts a NeuralMesh backend service and NeuralMesh POSIX client.
* All servers participate in a single, globally shared namespace, enabling uniform access to data regardless of node boundary.
* Local SSDs on each server form the aggregate flash pool for the entire cluster.

This co-located model delivers high efficiency by ensuring data resides physically close to the GPU workloads that consume it, minimizing latency and eliminating the need for external storage fabrics.

<div data-with-frame="true"><figure><img src="/files/Nct43YsE2z3xDdBqYpuZ" alt=""><figcaption><p>NeuralMesh Axon deployments with compute and storage on the same infrastructure</p></figcaption></figure></div>

## Solution component architecture

NeuralMesh Axon is structured as five integrated components. Each component contributes specific capabilities to the distributed storage system while maintaining a consistent operational model across both Linux-native and Kubernetes-orchestrated environments.

### 1. NeuralMesh Axon Core (required)

NeuralMesh Axon Core provides the foundational infrastructure required for all deployments. It includes three primary containerized functions deployed on each participating server:

* **Drives containers:** Manage and aggregate locally attached NVMe SSDs into the global distributed storage pool.
* **Compute containers:** Execute storage operations such as data placement, metadata handling, replication, rebuilds, and backend processing tasks.
* **Client / Frontend containers:** Provide the access interfaces used by applications.

Together, these containers implement the distributed filesystem that spans all servers into a single namespace, consistent with the architecture illustration.

### 2. NeuralMesh Axon Accelerate

NeuralMesh Axon Accelerate is an optional performance enhancement layer that creates a high-speed, low-latency data tier optimized for GPU-driven workloads. It combines local memory and flash storage to maximize efficiency.

Designed for co-located deployment, Accelerate leverages direct paths between GPU resources and the NeuralMesh backend containers on the same server.

Capabilities include:

* **RDMA-based data paths:** Establishes direct GPU-to-storage communication.
* **Low latency:** Delivers microsecond-level access latency.
* **Improved TTFT:** Enhances time-to-first-token (TTFT) performance.
* **Reduced variance:** Stabilizes high-throughput, small-block AI access patterns.

### 3. NeuralMesh Axon Deploy

NeuralMesh Axon Deploy provides automation and lifecycle management for Kubernetes environments. It ensures consistent orchestration across clusters.

NeuralMesh Axon Deploy includes the following capabilities:

* **WEKA Operator:** Deploys and manages NeuralMesh Custom Resource Definitions (CRDs).
* **Slurm environment support:** Manages installation and lifecycle within Slurm-based environments.
* **Automated provisioning:** Provisions Core containers across server fleets.
* **Standardized workflows:** Facilitates scaling, upgrading, and resource allocation.

### 4. NeuralMesh Axon Observe

NeuralMesh Axon Observe ensures comprehensive observability for the entire storage cluster. It supports operational oversight in large-scale, co-located deployments where application and storage roles coexist on each server.

Features include:

* **System-wide telemetry collection:** Aggregates data across the entire system.
* **Real-time performance dashboards:** Visualizes critical performance metrics instantly.
* **Health and event monitoring:** Tracks status across backends and access interfaces.
* **Operational insights:** Provides visibility into resource usage, and rebuild operations.

### 5. NeuralMesh Axon Enterprise Services

NeuralMesh Axon Enterprise Services provide the advanced functionality required for production environments. These capabilities apply uniformly across the single namespace.

Capabilities include:

* **Filesystem encryption:** Encrypts data at the filesystem level.
* **Enhanced data protection:** Provides advanced features to safeguard data.
* **Enterprise integration:** Includes compliance and audit capabilities.

## Architectural summary

NeuralMesh Axon unifies storage and compute resources into a single, scalable, high-performance system deployed directly on the same infrastructure as GPU applications. The combination of containerized isolation, local NVMe integration, and a single global namespace delivers a flexible and efficient architecture for modern AI workloads.

The component model: Core, Accelerate, Deploy, Observe, and Enterprise Services, provides the modular structure required for performance optimization, automation, observability, and enterprise readiness at scale.


# NeuralMesh Axon deployment

Deploy NeuralMesh Axon and integrate with orchestration services like Kubernetes and SLURM. For partners and skilled customers performing independent installations.

## NeuralMesh Axon deployment overview

NeuralMesh Axon offers a flexible deployment model, supporting both Slurm and Kubernetes runtime environments. regardless of the deployment method, specific infrastructure configurations are required to ensure high performance and stability.

### Infrastructure prerequisites

Before deploying software, the physical and network environment must be prepared:

* **Network:** The topology must be non-blocking with zero over-subscription. Jumbo frames (9k MTU for Ethernet, 4k for InfiniBand) and Source Based Routing policies are required.
* **Hardware:** Servers require AMD or Intel CPUs with contention-free allocation per NUMA domain and NVMe storage with Power Loss Protection (PLP).
* **Linux configuration:** All deployments require specific Linux kernel settings, including disabling swap partitions, disabling kernel NUMA balancing, and setting `noexec` on `/tmp`. BIOS settings must disable hyperthreading and enable maximum performance.
* **Firewall:** Ensure traffic is allowed on essential ports, such as 14000-16100 (Core traffic), 443 (Traces), and 8200-8201 (Vault).

### Deployment options

Administrators can choose between a Kubernetes-native deployment or a direct installation on servers running Slurm.

**Option A: Kubernetes deployment**

This method uses the WEKA Operator to manage lifecycle and automation via Custom Resource Definitions (CRDs).

* **WEKA Operator and CSI:** The WEKA Operator and CSI plugin are installed through Helm charts to manage the cluster state.
* **Node preparation:** Kubernetes nodes are labeled (`weka.io/supports-backends=true` and `weka.io/supports-clients=true`) to control pod placement.
* **SELinux:** For Kubernetes clusters, a specific SELinux policy (`container_use_wekafs`) must be installed on nodes if SELinux support is enabled.
* **Custom Resources:** The cluster is defined and deployed by applying `WekaCluster` and `WekaClient` CRDs, which specify container counts and resources.

**Option B: Slurm deployment (without Kubernetes)**

This method involves manual distribution and scripting on the servers running on Slurm.

* **Distribution:** The software release tarball is downloaded and distributed to all cluster servers using tools like `pdcp`.
* **Installation:** An installation script configures the container topology (Drives, Compute, and Frontend containers), binding specific CPU cores and NICs to NeuralMesh processes.
* **Service management:** Systemd overrides are created to ensure graceful shutdown, and the cluster IO is started manually via CLI (`weka cluster start-io`).

### Workload integration

NeuralMesh Axon integrates with schedulers to optimize resource usage. To prevent resource conflicts with Slurm, configure `slurm.conf` to exclude the specific CPU cores and memory reserved for NeuralMesh Axon using `CpuSpecList` and `MemSpecLimit`.

### Multi-tenancy

Subdivide the cluster into Organizations to support multi-tenancy. Security policies enforce boundaries based on user roles and network CIDRs.

## NeuralMesh Axon deployment requirements

### System requirements overview

NeuralMesh Axon requires specific infrastructure configurations for both Linux servers and Kubernetes runtime environments.

* **Network infrastructure:** Configure the following network settings:
  * Non-blocking network topology with zero over-subscribed segments.
  * Jumbo frames enabled: 9k MTU for Ethernet, 4k MTU for Infiniband.
  * Source Based Routing policies applied to each dataplane network device.
* **Hardware requirements:** Deploy servers that meet these specifications:
  * **CPU architecture**: AMD (single socket required), Intel (dual-socket supported), or NVIDIA Grace (ARM).
  * **CPU allocation**: Contention-free CPU allocation for each NUMA domain.
  * **Memory**: Sufficient RAM to allocate [HugeTLB pages](#user-content-fn-1)[^1] at runtime. For details, see [Plan hardware requirements](/planning-and-installation/bare-metal/planning-a-weka-system-installation#memory-resource-planning).
  * **Storage**: Adequate NVME capacity for the selected protection scheme.
* **Software prerequisites:** Install and configure these software components:
  * Unified CGROUPs or CGROUP v2 enabled.
  * Linux kernel headers matching the booted kernel version.
* **Additional Linux server configuration requirements:** see [#linux-system-configuration](#linux-system-configuration "mention").

### Kubernetes-specific requirements

Ensure your Kubernetes environment meets specific driver and security configurations before deployment to guarantee optimal performance and compatibility.

#### NIC driver requirements

Review the supported drivers and specific version requirements for Ethernet and InfiniBand configurations.

**Mellanox OFED Ethernet and InfiniBand drivers**

Kubernetes deployments use NeuralMesh Axon Core releases that are one major version behind Slurm deployments. Consequently, these releases require the installation of Mellanox OFED drivers rather than using the drivers bundled in the Core codebase.

* **Core versions 5.0 and later:** No OFED driver installation is required as the code is bundled with Core.
* **Core versions before 5.0:** You must install a qualified OFED driver.
  * Latest date-versioned release: OFED 24.04-0.7.0.0.
  * Latest semantic-versioned release: OFED 5.9-0.5.6.0.

For more details, see [Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility#ethernet-drivers-and-configurations)\
and [Prerequisites and compatibility](/planning-and-installation/prerequisites-and-compatibility#networking-infiniband).

**ENA drivers**

* **Supported versions:** 1.0.2 through 2.0.2.
* **Recommendation:** Use the current driver from the official OS repository.

**ixgbevf drivers**

* **Supported versions:** 3.2.2 through 4.1.2.
* **Recommendation:** Use the current driver from the official OS repository.

#### Enable SELinux support for NeuralMesh Axon on Kubernetes

Configure SELinux support for NeuralMesh Axon clusters hosted in a Kubernetes runtime environment. This process requires installing a specific SELinux policy on each participating Kubernetes node and updating the deployment configuration.

**Procedure:**

1. **Install the SELinux policy on the Kubernetes nodes:** Apply the policy package to each node participating in the NeuralMesh Axon system using the files from the public GitHub repository.
   1. Clone the repository:\
      `git clone https://github.com/weka/csi-wekafs.git`
   2. Copy the SELinux files to the relevant nodes (example using `pdcp`):\
      `pdcp -w neuralmesh-axon-[001-200] -r csi-wekafs/selinux ~/`
   3. Install the SELinux module (example using `pdsh`):\
      `pdsh -w neuralmesh-axon-[001-200] "sudo semodule -i ~/selinux/csi-wekafs.pp"`\
      This command defines a new SELinux boolean labeled `container_use_wekafs`.\
      If the `container_use_wekafs` boolean does not appear in the list, compile the policy package that matches the target Linux server. See [Add SELinux support](/appendices/weka-csi-plugin/add-selinux-support#install-a-custom-selink-p).
   4. Enable the SELinux boolean:\
      `pdsh -w neuralmesh-axon-[001-200] "sudo setsebool container_use_wekafs=on"`
2. **Update the WEKA Operator definition:** Update the definition file with the SELinux support flag set to either `mixed` or `enforced`.

   Run the following Helm command to upgrade the plugin, for example, with the enforced setting:

   ```bash
   helm install --upgrade csi-wekafsplugin csi-wekafs/csi-wekafsplugin /
   --namespace csi-wekafsplugin --create-namespace --set selinuxSupport=enforced
   ```

### SSD requirements

* **SSD configuration:** Determine these specifications for each server:
  * Number of SSDs required.
  * Capacity per SSD (total capacity = number × capacity per SSD).
* **SSD feature requirements:** Verify that SSDs provide:
  * Power Loss Protection (PLP).
  * Capacity up to 30 TB.
  * Capacity ratio between smallest and largest SSDs not exceeding 8:1 across the cluster.

### Network configuration

Configure firewall rules to allow these ports and protocols on all cluster servers:

<table><thead><tr><th width="236">Port/NodePort</th><th width="116">Protocol</th><th>Purpose</th></tr></thead><tbody><tr><td>14000-14100, 15000-15100, 16000-16100</td><td>TCP + UDP</td><td>NeuralMesh Axon Core container traffic</td></tr><tr><td>443</td><td>TCP</td><td>NeuralMesh Axon Core traces remote viewer</td></tr><tr><td>22</td><td>TCP</td><td>SSH management access</td></tr><tr><td>123</td><td>TCP</td><td>NTP management access</td></tr><tr><td>8200, 8201</td><td>TCP</td><td>Hashicorp Vault traffic</td></tr><tr><td>5696</td><td>TCP</td><td>KMIP traffic</td></tr></tbody></table>

### CPU core management

NeuralMesh Axon co-locates with AI workloads on shared computational hardware.

For non-Kubernetes/bare-metal deployments, allocate dedicated CPU cores to both NeuralMesh Axon and the job-scheduling service to prevent CPU starvation.

For Kubernetes deployments, CPU core allocation is not required.

### Linux system configuration

Apply these configurations to all NeuralMesh Axon deployments, regardless of deployment type.

* **CPU and memory settings:**
  * Balance CPU cores across NUMA domains containing dataplane network devices.
  * Install Linux kernel header package matching the booted kernel version.
  * Disable NUMA balancing by setting `kernel.numa_balancing = 0` and add the entry to the `/etc/sysctl.conf` file to ensure persistence.
* **Network configuration:**
  * Configure Source Based Routing policies for every dataplane NIC on every dataplane subnet in the OS network scripts to enable access without specifying bind/outbound interfaces.
  * Configure ARP settings for each dataplane network device by setting the following parameters in the `/etc/sysctl.conf` file, replacing `<device>` with the actual network interface name.

    ```
    net.ipv4.conf.<device>.arp_announce = 2
    net.ipv4.conf.<device>.arp_filter = 1
    net.ipv4.conf.<device>.arp_ignore = 0
    ```
* **System services and settings:** Configure these system requirements:
  * Disable swap partitions.
  * Run NTP with synchronized date and time across all cluster servers.
  * Install and enable `rpcbind`, `XFS`, and `SquashFS`.
  * Maintain consistent IOMMU settings (BIOS and bootloader) across all cluster servers.
  * Apply `noexec` mount option to `/tmp`.
* **BIOS configuration:** Flash BIOS using WEKA's [bios\_tool](https://github.com/weka/bios_tool/tree/master) to:
  * Select maximum power and performance settings.
  * Disable hyperthreading (HT).
  * Disable Active Management Technology (AMT).

## Install NeuralMesh Axon on a Kubernetes environment

The installation of NeuralMesh Axon on a Kubernetes environment consists of a WEKA Operator that simplifies the installation, management, and scaling of NeuralMesh Axon deployments within a Kubernetes cluster.

The WEKA Operator uses Kubernetes Custom Resource Definitions (CRDs) to provide resilience, scalability, and automation for each cluster. It provides a cluster-wide service that monitors each Kubernetes namespace containing NeuralMesh Axon custom resources.

When the WEKA Operator detects that the state of the deployed resources does not match the declared state in the resource definition file, it performs one of the following actions:

* Logs clear and useful messages in the WEKA Operator controller pod.
* Bootstraps the resource to return it to the desired state, provided the change is additive and non-destructive.

The WEKA Operator automation never makes subtractive or destructive changes to deployed resources.

#### Compatibility

Verify the environment meets the following minimum version requirements:

* **Kubernetes:** Version 1.25 or higher.
* **OpenShift:** Version 4.17 or higher.

#### Network requirements

The following Kubernetes nodePorts are required. These ports use default ranges unless defined differently in the definition files. These ports are not hard-coded into the source code and can be adjusted to match the target Kubernetes cluster service topology.

| **Purpose**        | **Source Container(s)** | **Destination Container(s)** | **Default Port Ranges** | **Protocol** |
| ------------------ | ----------------------- | ---------------------------- | ----------------------- | ------------ |
| Client connections | Client                  | Compute, Drives              | 45000-65000             | TCP/UDP      |
| Cluster allocation | Operator                | Compute, Drives, Client      | 35000-35499             | TCP/UDP      |
| Core traffic       | Compute, Drives         | Compute, Drives              | 35000-35499             | TCP/UDP      |

### Workflow

1. Configure Kubelet settings.
2. Install NeuralMesh Axon.
3. Label the nodes.
4. Create registry secrets.
5. Install the WEKA Operator and CSI Plugin.
6. Deploy driver and discovery services.
7. Deploy NeuralMesh Axon Custom Resources.

#### 1. Configure Kubelet settings

Configure the Kubelet with static CPU management to enable exclusive CPU allocation for NeuralMesh Axon performance.

1. **Define the CPU management policy:** Configure the Kubelet with the following settings:

   ```yaml
   reservedSystemCPUs: "0"
   cpuManagerPolicy: static
   ```
2. **Identify the active Kubelet configuration:** Check which configmap holds the current Kubelet configuration.

   ```bash
   kubectl get cm -A|grep kubelet
   ```

   If multiple Kubelet configurations exist, modify the configuration specifically for the worker nodes.
3. **Apply the CPU settings:** Edit the Kubelet config map to add the required CPU settings.

   ```bash
   kubectl edit cm -n kube-system kubelet-config
   ```

#### 2. Install NeuralMesh Axon

The installation of a NeuralMesh Axon cluster in a Kubernetes environment is an automated process. The solution uses three collections of Kubernetes namespaces:

* Global namespace for the NeuralMesh Axon WEKA Operator.
* Global namespace for the CSI-WekaFS CSI plugin.
* Individual namespaces for each NeuralMesh Axon cluster.

Reliable pod scheduling for these services requires specific Kubernetes labels and selectors on both nodes and resources.

#### 3. Label the nodes

Apply Kubernetes node labels to assign the CSI and NeuralMesh Axon Core cluster pods to specific nodes. Ensure the labels applied to the nodes match the `nodeSelector` definitions in the Custom Resource Definitions (CRDs).

The following commands demonstrate how to label nodes using the example values `supports-clients` and `supports-backends`:

1. **Label nodes for the CSI:**

   ```bash
   kubectl label nodes <node name> weka.io/supports-clients=true
   ```
2. **Label nodes for the NeuralMesh Axon Core cluster:**

   ```bash
   kubectl label nodes <node name> weka.io/supports-backends=true
   ```

#### 4. Create registry secrets

Create a `docker-registry` secret in the global namespace for the WEKA Operator and in each namespace hosting a Core cluster.

The following commands are examples.

1. **Export the required variables:**

   ```bash
   export QUAY_USERNAME='QUAY_USERNAME' # Replace with the actual value
   export QUAY_PASSWORD='QUAY_PASSWORD' # Replace with the actual value
   export QUAY_SECRET_NAME='QUAY_SECRET_NAME' # Replace with a meaningful name
   ```
2. **Create the namespace and secret for the WEKA Operator:**

   ```bash
   # Create the namespace for the WEKA Operator
   kubectl create ns weka-operator-system

   # Create the docker-registry secret for NeuralMesh Axon Deploy
   kubectl create secret docker-registry $QUAY_SECRET_NAME \
     --docker-server=quay.io \
     --docker-username=$QUAY_USERNAME \
     --docker-password=$QUAY_PASSWORD \
     --docker-email=$QUAY_USERNAME \
     --namespace=weka-operator-system
   ```
3. **Create the secret for NeuralMesh Axon Core:**

   ```bash
   # Create the docker-registry secret for NeuralMesh Axon Core
   kubectl create secret docker-registry $QUAY_SECRET_NAME \
     --docker-server=quay.io \
     --docker-username=$QUAY_USERNAME \
     --docker-password=$QUAY_PASSWORD \
     --docker-email=$QUAY_USERNAME \
     --namespace=default
   ```

#### 5. Install the WEKA Operator and CSI Plugin

Install the WEKA Operator and CSI plugin using Helm to enable storage lifecycle management. This installation sets up the required Custom Resource Definitions (CRDs) and deploys the operator within the specified namespace.

{% hint style="info" %}
The version numbers in the following commands are examples. Verify the latest version at <https://get.weka.io/ui/operator> and update the `WEKA_OPERATOR_VERSION` variable before execution.
{% endhint %}

1. **Set the WEKA Operator version:**

   ```bash
   export WEKA_OPERATOR_VERSION='v1.8.7'
   ```
2. **Pull the Helm chart and apply the CRDs:**

   ```bash
   helm pull oci://quay.io/weka.io/helm/weka-operator \
   --untar --version $WEKA_OPERATOR_VERSION
   kubectl apply -f weka-operator/crds
   ```
3. **Install the WEKA Operator and CSI Plugin:**

   ```bash
   helm upgrade --create-namespace \
       --install weka-operator oci://quay.io/weka.io/helm/weka-operator \
       --namespace weka-operator-system \
       --version $WEKA_OPERATOR_VERSION \
       --set csi.installationEnabled=true
   ```

#### 6. Deploy driver and discovery services

1. **Deploy the Driver Distribution Service:** Prepare the variables and apply the configuration.

   ```yaml
   export WEKA_IMAGE_VERSION='VERSION' # Replace with the latest version from https://get.weka.io/ui/releases
   export QUAY_SECRET_NAME='QUAY_SECRET_NAME' # Replace with a meaningful name

   cat <<EOF | kubectl apply -f -
   apiVersion: weka.weka.io/v1alpha1
   kind: WekaPolicy
   metadata:
     name: weka-drivers
     namespace: weka-operator-system
   spec:
     image: quay.io/weka.io/weka-in-container:${WEKA_IMAGE_VERSION}
     imagePullSecret: "${QUAY_SECRET_NAME}"
     payload:
       driverDistPayload: {}
       interval: 1m
     type: enable-local-drivers-distribution
   EOF
   ```
2. **Deploy the Drive Signer Service:**

   ```yaml
   export WEKA_IMAGE_VERSION='VERSION' # Replace with the latest version from https://get.weka.io/ui/releases
   export QUAY_SECRET_NAME='QUAY_SECRET_NAME' # Replace with a meaningful name

   cat <<EOF | kubectl apply -f -
   apiVersion: weka.weka.io/v1alpha1
   kind: WekaManualOperation
   metadata:
     name: discover-drives
     namespace: weka-operator-system
   spec:
     action: "discover-drives"
     image: quay.io/weka.io/weka-in-container:${WEKA_IMAGE_VERSION}
     imagePullSecret: "${QUAY_SECRET_NAME}"
     payload:
       discoverDrivesPayload:
         nodeSelector:
           weka.io/supports-backends: "true"
   EOF
   ```

#### 7. Deploy NeuralMesh Axon Custom Resources

Install the Custom Resources for the WekaCluster and WekaClient.

1. **Deploy WekaCluster:** Update the dynamicTemplate values to match the target cluster size.

   ```yaml
   export WEKA_IMAGE_VERSION='VERSION' # Replace with the latest version from https://get.weka.io/ui/releases
   export QUAY_SECRET_NAME='QUAY_SECRET_NAME' # Replace with a meaningful name

   cat <<EOF | kubectl apply -f -
   apiVersion: weka.weka.io/v1alpha1
   kind: WekaCluster
   metadata:
     name: axon-cluster
     namespace: default
   spec:
     template: dynamic
     dynamicTemplate: # Replace values with the actual size of your cluster
       computeContainers: 256
       computeCores: 16
       driveContainers: 256
       driveCores: 32
       numDrives: 8
     image: quay.io/weka.io/weka-in-container:${WEKA_IMAGE_VERSION}
     nodeSelector:
       weka.io/supports-backends: "true"
     driversDistService: "https://weka-drivers-dist.weka-operator-system.svc.cluster.local:60002"
     imagePullSecret: "${QUAY_SECRET_NAME}"
     network:
       ethDevice: enp0
   EOF
   ```
2. **Deploy WekaClient:**

   ```yaml
   export WEKA_IMAGE_VERSION='VERSION' # Replace with the latest version from https://get.weka.io/ui/releases 
   export QUAY_SECRET_NAME='QUAY_SECRET_NAME' # Replace with a meaningful name

   cat <<EOF | kubectl apply -f -
   apiVersion: weka.weka.io/v1alpha1
   kind: WekaClient
   metadata:
     name: axon-cluster-clients
   spec:
     image: quay.io/weka.io/weka-in-container:${WEKA_IMAGE_VERSION}
     imagePullSecret: "${QUAY_SECRET_NAME}"
     driversDistService: "https://weka-drivers-dist.weka-operator-system.svc.cluster.local:60002"
     portRange:
       basePort: 46000
     nodeSelector:
       weka.io/supports-clients: "true"
     wekaSecretRef: axon-cluster
     targetCluster:
       name: axon-cluster
       namespace: default
     network:
       ethDevice: enp0
   EOF
   ```

## Install NeuralMesh Axon without Kubernetes

Installing the NeuralMesh Axon software involves downloading the installer, configuring system reliability settings, and running an automated script to deploy the cluster topology.

### Server configuration prerequisites

Verify the hardware and resource requirements to ensure optimal cluster performance.

The following table outlines the required networking, storage, resources, and protection scheme configurations.

<table><thead><tr><th width="208">Component</th><th>Requirement</th></tr></thead><tbody><tr><td>Networking</td><td>Two dataplane network devices (without HA configuration).</td></tr><tr><td>Storage</td><td>2, 4, or 8 NVMe drives per server.</td></tr><tr><td>Resources</td><td><p>One Drive core per NVMe drive (up to 8 cores).</p><p>Two Compute cores per Drive core (up to 16 cores).</p><p>Twelve Frontend cores (regardless of number of drives).</p></td></tr><tr><td>Protection scheme</td><td>16+4 protection (16 stripe width, 4 parity) with 2 hot spares.</td></tr></tbody></table>

**NUMA alignment guidelines**

Apply the following logic to ensure correct NUMA alignment:

* Distribute CPU core IDs evenly across NUMA domains that contain a dataplane network device.
* If hyperthreading is enabled, do not assign sibling cores to the Axon cluster. Exclude them from customer workloads.

### Workflow

1. Download and distribute the WEKA release.
2. Configure graceful shutdown.
3. Deploy the cluster.
4. Finalize the installation.

#### 1. Download and distribute the WEKA release

Begin by downloading the NeuralMesh Axon Core software and distributing it to all servers in the cluster.

1. **Download the release:** Replace `YOUR_WEKA_TOKEN` with your assigned download token and `WEKA_RELEASE` with the specific release version.

   ```bash
   curl -LO https://YOUR_WEKA_TOKEN@get.weka.io/dist/v1/pkg/WEKA_RELEASE.tar
   ```
2. **Distribute and install the software:** Use `pdcp` and `pdsh` to copy the tarball to the servers, extract it, and run the installation script.

   ```bash
   pdcp -w neuralmesh-axon-[001-200] WEKA_RELEASE.tar /root/WEKA_RELEASE.tar
   pdsh -w neuralmesh-axon-[001-200] 'tar -xvf /root/WEKA_RELEASE.tar'
   pdsh -w neuralmesh-axon-[001-200] \
   'cd /root/WEKA_RELEASE; \
   WEKA_SYSTEMD_GRACEFUL_SHUTDOWN=true WEKA_CGROUPS_MODE=force_v2 ./install.sh'
   ```

#### 2. Configure graceful shutdown

Configure a systemd override to ensure the system handles shutdowns gracefully by enforcing a specific timeout and reboot action.

1. **Create the configuration file:** Create the `override.conf` file locally.

   ```
   cat <<EOF | tee -a /tmp/override.conf
   [Unit]
   JobTimeoutSec=30s
   JobTimeoutAction=reboot
   EOF
   ```
2. **Apply the configuration to all servers:** Distribute the file to the `poweroff.target.d` directory on all cluster servers and reload the systemd daemon.

   ```bash
   pdsh -w neuralmesh-axon-[001-200] 'sudo mkdir -p /etc/systemd/system/poweroff.target.d'
   pdcp -w neuralmesh-axon-[001-200] /tmp/override.conf /tmp
   pdsh -w neuralmesh-axon-[001-200] \
   'sudo cp /tmp/override.conf /etc/systemd/system/poweroff.target.d'
   pdsh -w neuralmesh-axon-[001-200] 'systemctl daemon-reexec'
   ```

#### 3. Deploy the Axon Core cluster

Customize and execute the following installation script to deploy the NeuralMesh Axon Core cluster. This script automates the creation of containers (Drives, Compute, Frontend), forms the cluster, configures data protection, and assigns NVMe drives.

<details>

<summary>Example installation script</summary>

```bash
#!/bin/bash

##
# This script is an example. To convert this example to a valid
# installation script, edit the variables in the section below.
##

##
# Cluster configuration parameters:
# - 2x dataplane network devices (not configured for WEKA-HA)
# - 8x NVMe drives
# - 1x DRIVE container using 8 cores
# - 1x COMPUTE container using 16 cores
# - 16+4+2 protection scheme
#   --> 16: stripe width
#   -->  4: data parity count
#   -->  2: virtual hotspare count
##

##
# NUMA alignment notes:
# - Distribute CPU core-IDs evenly across NUMA domains containing a
#   dataplane network device.
# - If hyperthreading is enabled, exclude daughter/sibling cores from
#   the Axon cluster and ensure they are not used for customer workloads.
##

# --- Cluster Parameters (Edit these values) ---

## NeuralMesh Axon Core cluster name
CLUSTER_NAME="your cluster name here"

## Unique identifier for data drives (from output of: nvme list)
## Examples: "kioxia", "3.2TB"
DRIVE_MATCH="your NVMe unique drive identifier here"

## Protection: integers from 3 to 16, inclusive
PROTECTION=16
## Parity: integers from 2 to 4, inclusive
PARITY=4
## Hotspares: any positive integer starting from zero
HOT_SPARES=2

## Compute Container Configuration
## Actual core-IDs depend on the platform's NUMA domains
COMPUTE_CORES='48,54,60,66,72,78,84,90,47,53,59,65,71,77,83,89'
COMPUTE_NICS='enp1,enp2'
COMPUTE_MEM=56     ## 3.5 GB RAM/CORE * 16 cores

## Drive Container Configuration
## Actual core-IDs depend on the platform's NUMA domains
DRIVE_CORES='24,30,36,42,23,29,35,41'
DRIVE_NICS='enp1,enp2'
DRIVE_MEM=20       ## 2.5 GB RAM/CORE * 8 cores

## Frontend Container Configuration
## Actual core-IDs depend on the platform's NUMA domains
FE_CORES='42,43'
FE_NICS='enp1,enp2'
FE_MEM=5           ## 2.5 GB RAM/CORE * 2 cores

# --- End of Parameters ---

## Axon hostnames must be defined in /etc/hosts on all servers
LINUX_HOST_NAMES="`cat /etc/hosts | grep -i axon | awk '{print $2}' | tr '\n' ' ' | sed 's/.$//'`"
LINUX_HOST_ADDRS="`cat /etc/hosts | grep -i axon | awk '{print $1}' | tr '\n' ',' | sed 's/.$//'`"
AXON_IP="`echo ${LINUX_HOST_ADDRS} | tr ',' '\n' | head -n 1`"
JOIN_ME="`echo ${LINUX_HOST_ADDRS} | tr ',' '\n' | head -n 5 | tr '\n' ',' | sed 's/.$//'`"

## Remove any prior WEKA containers (e.g., 'default' container)
pdsh -f 120 -w ${LINUX_HOST_ADDRS} "sudo weka local stop -f; echo"
pdsh -f 120 -w ${LINUX_HOST_ADDRS} "sudo weka local rm --all -f; echo"

## Setup the DRIVES container on all Linux storage servers
cmd="sudo weka local setup container --name drives0 --only-drives-cores --base-port 14000 --net ${DRIVE_NICS} --cores 8 --core-ids ${DRIVE_CORES} --memory ${DRIVE_MEM}GB --failure-domain"
cmd+=' $(hostname -s)'
pdsh -f 120 -w ${LINUX_HOST_ADDRS} "${cmd}"
sleep 10

## Create the cluster
[cite_start]ssh ${AXON_IP} "sudo weka cluster create ${LINUX_HOST_NAMES} --host-ips=${LINUX_HOST_ADDRS}" # [cite: 464]
sleep 10

## Configure the protection scheme
[cite_start]ssh ${AXON_IP} "sudo weka cluster update --data-drives ${PROTECTION} --parity-drives ${PARITY} --cluster-name ${CLUSTER_NAME}" # [cite: 468]
ssh ${AXON_IP} "sudo weka cluster hot-spare ${HOT_SPARES}"
sleep 10

## Add the NVMe drives from each server to the correct DRIVES container
while read server_name;
do
  drives_data="`ssh -n ${server_name} "sudo nvme list | grep ${DRIVE_MATCH}"`"
  drives_list="`echo "${drives_data}" | tr '\n' ' '`"
  container_data="`ssh -n ${AXON_IP} "sudo weka cluster container --no-header | grep -i ${server_name} | grep -i drives0"`"
  container_id="`echo ${container_data} | awk '{print $1}'`"
  echo "${server_name}: weka cluster drive add ${container_id} ${drives_list}"
  [cite_start]ssh -n ${AXON_IP} "sudo weka cluster drive add ${container_id} ${drives_list}" # [cite: 495]
done < <( echo -e "${LINUX_HOST_NAMES}" | tr ' ' '\n' )
sleep 10

## Setup the COMPUTE containers on all Linux storage servers
cmd="sudo weka local setup container --name compute0 --only-compute-cores --base-port 15000 --net ${COMPUTE_NICS} --cores 16 --core-ids ${COMPUTE_CORES} --memory ${COMPUTE_MEM}GB --failure-domain"
cmd+=' $(hostname -s)'
cmd+=" --join-ips ${JOIN_ME}"
pdsh -f 120 -w ${LINUX_HOST_ADDRS} "${cmd}"

## Setup the FRONTEND containers on all Linux storage servers
cmd="sudo weka local setup container --name frontend0 --client --only-frontend-cores --base-port 16000 --net ${FE_NICS} --cores 2 --core-ids ${FE_CORES} --memory ${FE_MEM}GB --failure-domain"
cmd+=' $(hostname -s)'
cmd+=" --join-ips ${JOIN_ME}"
pdsh -f 120 -w ${LINUX_HOST_ADDRS} "${cmd}"
```

</details>

**Prerequisites**

* Ensure `pdsh` is installed and configured for passwordless access to all target servers.
* Verify all target servers are listed in `/etc/hosts` with a common identifier (e.g., `axon`) to facilitate hostname parsing.

**Procedure**

1. Copy the example installation script to a file (for example, `install_axon.sh`).
2. Edit the **Cluster Parameters** section to match your hardware configuration:
   * **Core IDs:** Align `COMPUTE_CORES`, `DRIVE_CORES`, and `FE_CORES` with your specific NUMA topology.
   * **NICs:** Update `COMPUTE_NICS`, `DRIVE_NICS`, and `FE_NICS` with the correct interface names.
   * **Drive identifier:** Update `DRIVE_MATCH` with a unique string (model or size) that identifies your NVMe drives.
3. Make the script executable and run it:

   ```bash
   chmod +x install_axon.sh
   ./install_axon.sh
   ```

#### 4. Finalize the installation

After the cluster deployment script completes, enable the observation service and start the IO services.

1. **Enable the Axon Observe service:**

   ```shell
   weka cloud enable
   ```
2. **Start the cluster IO services:**

   ```bash
   weka cluster start-io
   ```

## NeuralMesh Axon workload integration with Slurm

Slurm is an open-source cluster management and job scheduling system tailored for Linux clusters. It manages resource access, workload execution, and monitoring.

In a NeuralMesh Axon architecture, Slurm compute servers often function as NeuralMesh Axon Core clients, requiring a Frontend container to mount the local storage service. Additionally, Compute and Drive containers may run on these servers in converged configurations.

To ensure optimal performance and stability, you must isolate CPU and memory resources for NeuralMesh Axon processes. This prevents conflicts with Slurm-managed user workloads or daemons.

<div data-with-frame="true"><figure><img src="/files/Nqn6oRK99XzZhWcpejoT" alt="" width="456"><figcaption><p>NeuralMesh Axon integration with Slurm</p></figcaption></figure></div>

#### Configure Slurm for resource isolation

Configure Slurm to isolate CPU and memory resources for WEKA processes. This prevents conflicts between Slurm services (primarily `slurmd`) and user workloads attempting to use the same cores. This configuration uses the `task/affinity` and `task/cgroup` plugins to control compute resource exposure and binds nodes to designated resources.

**Procedure**

1. **Edit the `slurm.conf` file to enable resource tracking and containment:** Add or modify the following settings:

   * **ProctrackType:** Set to `proctrack/cgroup` to use cgroups for process tracking.
   * **TaskPlugin:** Set to `task/affinity,task/cgroup` to enable resource binding and containment.
   * TaskPluginParam: Set to `SlurmdOffSpec` to prevent Slurm daemons from running on cores designated for WEKA.
   * **SelectType:** Set to `select/cons_tres` to track cores, memory, and GPUs as consumable resources.
   * **SelectTypeParameters**: Set to `CR_Core_Memory` to schedule workloads based on core and memory availability.
   * **PrologFlags:** Set to `Contain` to enforce cgroup containment for all user nodes.
   * **JobAcctGatherType:** (Optional) Set to `jobacct_gather/cgroup` for metrics gathering.

   Example configuration snippet:

   ```bash
   ProctrackType=proctrack/cgroup
   TaskPlugin=task/affinity,task/cgroup
   TaskPluginParam=SlurmdOffSpec
   SelectType=select/cons_tres
   SelectTypeParameters=CR_Core_Memory
   JobAcctGatherType=jobacct_gather/cgroup
   PrologFlags=Contain
   ```
2. **Edit the `cgroup.conf` file to enforce resource constraints:** Ensure the following parameters are set:

   * **ConstrainCores:** Set to `yes`.
   * **ConstrainRamSpace:** Set to `yes`.

   ```bash
   ConstrainCores=yes
   ConstrainRamSpace=yes
   ```
3. **Define the compute nodes in `slurm.conf` to allocate exclusive resources:** Set the following parameters for each node definition:

   * [**`RealMemory`**](https://slurm.schedmd.com/slurm.conf.html#OPT_RealMemory)**:** The total available memory on the compute node.
   * [**`CpuSpecList`**](https://slurm.schedmd.com/slurm.conf.html#OPT_CpuSpecList)**:** The list of virtual CPU IDs reserved for system use (including WEKA processes). Slurm uses only the cores defined here; it excludes others from user jobs.
   * [**`MemSpecLimit`**](https://slurm.schedmd.com/slurm.conf.html#OPT_MemSpecLimit): The amount of memory (in MB) reserved for system use. This is required when `SelectTypeParameters` is set to `CR_Core_Memory`.

   Example node definition: This example reserves cores 47 through 95 for Slurm usage, leaving cores 0 through 46 available for WEKA.

   ```shellscript
   NodeName=compute-node-0 CPUs=96 Boards=1 SocketsPerBoard=2 CoresPerSocket=24 ThreadsPerCore=2 RealMemory=1360000 MemSpecLimit=5000 State=CLOUD CpuSpecList=47,95
   ```
4. **Mount the filesystem using the resources excluded from Slurm:** The following example mounts the filesystem using core 46, which is outside the `CpuSpecList` range (47-95) defined for Slurm.

   ```bash
   mount -t wekafs -o core=46 -o net=ib0 backend-host-0/fs1 /mnt/weka
   ```

## Integrate with Kubernetes

NeuralMesh Axon is a Kubernetes-native solution, delivering super-computing storage packaged as a Kubernetes application. You can manage the placement and prioritization of NeuralMesh Axon Core clusters directly from the point of installation using standard Kubernetes mechanisms.

#### **Manage placement and prioritization**

Utilize the following Kubernetes-native features to control where and how NeuralMesh Axon resources are deployed:

* **Selectors:** Target specific nodes for deployment.
* **Affinity rules:** Define complex rules for pod placement relative to other pods or nodes.
* **Priority classes:** Ensure critical NeuralMesh Axon components receive scheduling priority.
* **Resource requests:** Reserve the necessary compute and memory resources for optimal performance.

## NeuralMesh Axon Multi-tenancy

NeuralMesh Axon implements logical multi-tenancy by subdividing cluster controls and resources into secure authorization boundaries called Organizations.

#### Security enforcement

WEKA security policies enforce the boundaries created by Organizations. These policies use network CIDR information and Organization member roles to evaluate authorization for API calls and data operations.

#### Policy scope and evaluation

You can apply security policies to the entire cluster, a specific Organization, or individual filesystems within an Organization. To ensure fine-grained enforcement, the system evaluates the following:

* The authenticated user's Organization membership.
* The user's Organization permissions.
* The network CIDR from which the authenticated API call originated.

[^1]: **HugeTLB (Huge Table):** This refers to the Linux kernel's framework/API for managing large memory pages. It's the *mechanism* for reserving and allocating pages bigger than the standard 4KB. For more details, see <https://www.kernel.org/doc/html/v5.0/admin-guide/mm/hugetlbpage.html>


# NeuralMesh Axon maintenance

Manage NeuralMesh Axon performance: replace failed drives and perform server maintenance tasks like reboots.

## Drive replacement

Replace a failed drive in a NeuralMesh Axon cluster to restore full redundancy and capacity. This procedure applies to the storage drives managed by the cluster and does not apply to operating system drives.

**Prerequisites**

* A replacement drive is available.
* Identify the specific server and drive requiring replacement.

### Verify cluster health

Before replacing a drive, verify the overall health of the cluster and the rebuild status.

For Kubernetes-based systems, run the following commands:

1. **View the cluster status:**

   ```bash
   kubectl get pods –n <namespace>
   kubectl exec –it –n <namespace> <pod-name> -- bash –c “weka status”
   ```
2. **View the rebuild status:**

   ```bash
   kubectl exec –it –n <namespace> <pod-name> -- bash –c “weka status rebuild”
   ```
3. **View active alerts:**

   ```bash
   kubectl exec –it –n <namespace> <pod-name> -- bash –c “weka alerts”
   ```

### Replace the drive

1. **Deactivate and remove the drive:**
   1. Do one of the following:
      * **Kubernetes:** Use `kubectl` to access the shell of any pod in the cluster.
      * **Non-Kubernetes:** Access the shell of one of the servers running the Axon software.
   2. Run the commands to deactivate and remove the drive from the cluster management. See [Shrink a cluster](/operation-guide/expanding-and-shrinking-cluster-resources/shrinking-a-cluster#remove-only-some-drives-from-the-cluster).
2. **Physically replace the drive:** Remove the failed drive from the server chassis and insert the replacement drive.
3. **Verify drive detection:**
   1. Establish an SSH connection to the storage server.
   2. Run the `lsblk` command.
   3. Confirm the operating system recognizes the new drive.\
      The output displays only the new device and drives not used for the dataplane. The system unloads storage devices from the kernel to control them by SPDK.
4. **Integrate the new drive:**
   1. Access the shell of the server or pod running NeuralMesh Axon.
   2. Add the new drive device path to the Drives container on the specific storage server. See [/pages/GemoW3Hct7T9UFr1WAmL#id-4.-configure-the-ssd-drives](https://docs.weka.io/neuralmesh-axon/pages/GemoW3Hct7T9UFr1WAmL#id-4.-configure-the-ssd-drives "mention").

## Server maintenance

Perform server maintenance, such as rebooting or restarting networking services, by gracefully stopping services to prevent data unavailability.

### Manage server state in Kubernetes environments

For Kubernetes worker nodes running NeuralMesh Axon, cordon and drain the node before maintenance.

1. **Cordon the node:** Prevent new workloads from scheduling on the node.

   ```bash
   kubectl cordon <node-name>
   ```
2. **Drain the node:** Stop application pods running on the node.

   ```
   kubectl drain <node-name> --delete-emptydir-data --ignore-daemonsets
   ```
3. **Perform maintenance:** Complete the necessary hardware or software updates.
4. **Uncordon the node:** Return the node to service.

   ```bash
   kubectl uncordon <node-name>
   ```

### Manage server state in non-Kubernetes environments

For Slurm or bare-metal configurations, manage the server state using the CLI to ensure safe maintenance operations.

1. **Verify server status:** Ensure the server is not already in maintenance mode.

   ```bash
   weka cluster servers list
   ```

   Verify the `READY FOR MAINTENANCE` column shows `False`.\
   Example output:

   <div data-with-frame="true"><figure><img src="/files/dv2hbFCDgIwOgXxIk4ul" alt=""><figcaption></figcaption></figure></div>
2. **Request maintenance mode:** Request the server to stop gracefully.

   ```bash
   weka cluster servers requested-action stop --timeout=5m <server-name>
   ```

   The `--timeout=x` option aborts the command if the stop flow does not start within the specified duration. (The stop flow may start before the timeout expires but complete after it.)
3. **Monitor status:** Wait for the server to be ready for maintenance.

   ```bash
   weka cluster servers list
   ```

   Proceed when the `READY FOR MAINTENANCE` column shows `True`.\
   Example output:

   <div data-with-frame="true"><figure><img src="/files/qo2JhtKei621kpFpnpBG" alt=""><figcaption></figcaption></figure></div>
4. **Perform maintenance:** Complete the necessary hardware or software updates.
5. **Verify return to service:** The processes typically restart automatically after a reboot. If the processes do not start, or the status remains `READY FOR MAINTENANCE`, access the server shell and run:

   ```bash
   weka local start
   ```

   Confirm the server is active:

   ```bash
   weka cluster servers list
   ```


# Install the WEKA App Store

Set up the App Store on Kubernetes, configure access to NeuralMesh storage, and deploy AI applications through the browser.

Deploy the WEKA App Store on a Kubernetes cluster to install the WEKA Operator, the CSI storage driver, and the App Store GUI for browsing and deploying AI applications. This guide covers adding the Helm repository, installing the chart, and completing the setup wizard that connects the cluster to NeuralMesh storage.

## Before you begin

Gather the following information and access before starting. The setup wizard prompts for most of these values, so having them ready avoids interruptions partway through.

* A running Kubernetes cluster, version 1.24 or later, with `kubectl` configured on the workstation and cluster-admin access. Run `kubectl cluster-info` to confirm the connection.
* Helm version 3.10 or later. Run `helm version` to check the installed version. Install Helm from the official Helm documentation if needed.
* The NeuralMesh cluster endpoint addresses: the IP addresses (or hostnames) and port numbers of the NeuralMesh servers, for example `192.168.1.10:14000`. Collect at least one endpoint, though three or more improve resilience. The default WEKA port is `14000`.
* The WEKA software version running on the cluster, for example `5.1.0.605`. This value must match exactly. Find it by running `weka version` on a WEKA server, or in the WEKA management UI under **Configuration > Cluster Settings > General Information**.
* A WEKA user account with the CSI role. This is a dedicated service account for the storage driver, not a personal WEKA admin account. Ask a WEKA administrator to create one if it does not exist.
* A Quay.io login with access to WEKA container images. WEKA provides this at registration on get.weka.io. Contact WEKA Sales if access is missing.
* Root or sudo access to every Kubernetes worker node, to apply a one-time kubelet configuration change.
* Network connectivity from the Kubernetes worker nodes to the NeuralMesh cluster. Confirm the required ports are open between the Kubernetes nodes and the NeuralMesh servers. Refer to the WEKA documentation for the port list.

{% hint style="info" %}
Upgrading an existing installation? Run `helm repo update` before any upgrade to retrieve the latest available chart version.
{% endhint %}

## Step 1: Add the Helm repository

The WEKA App Store is distributed as a Helm chart hosted on GitHub Pages. Add the repository to the local Helm configuration once, before installing or upgrading the chart.

1. Register the repository and refresh the chart index:

   ```bash
   helm repo add weka-app-store https://weka.github.io/appstore-helm
   helm repo update
   ```
2. Confirm the repository is available:

   ```bash
   helm search repo weka-app-store
   ```

   The output lists `weka-app-store/weka-app-store-operator-chart` along with its current version.

## Step 2: Install the Helm chart

Installing the chart deploys the WEKA App Store operator and its web-based GUI on the cluster, and registers the `WekaAppStore` custom resource type that the operator uses to track every deployment it manages.

1. Create the namespace for the operator:

   ```bash
   kubectl create namespace weka-app-store
   ```
2. Create a Quay robot secret for image pull secret:

```bash
kubectl create secret docker-registry quay-appstore-pull \
  --docker-server=quay.io \
  --docker-username='weka.io+<robotname>' \
  --docker-password='<robot-token>' \
  --docker-email='not-used@weka.io' \
  -n weka-app-store
```

1. Install the chart, choosing an option based on how the GUI should be exposed.

   Option A: LoadBalancer (recommended for bare-metal clusters with MetalLB)

   ```bash
   helm install weka-app-store weka-app-store/weka-app-store-operator-chart \
     --namespace weka-app-store \
     --set service.type=LoadBalancer \
     --set 'imagePullSecrets[0].name=quay-appstore-pull'
   ```

   Option B: NodePort (when a load balancer is not available)

   ```bash
   helm install weka-app-store weka-app-store/weka-app-store-operator-chart \
     --namespace weka-app-store \
     --set service.type=NodePort \
     --set 'imagePullSecrets[0].name=quay-appstore-pull'
   ```

   Option C: ClusterIP only (access by port-forward)

   ```bash
   helm install weka-app-store weka-app-store/weka-app-store-operator-chart \
     --namespace weka-app-store \
     --set 'imagePullSecrets[0].name=quay-appstore-pull'
   ```

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>The chart installs a <code>ClusterRole</code> and <code>ClusterRoleBinding</code> that grant the operator broad permissions across the cluster, because the operator manages resources in multiple namespaces. Run <code>helm install</code> with cluster-admin privileges.</p></div>
2. Confirm the operator pod started:

   ```bash
   kubectl get pods -n weka-app-store
   ```

   A pod with a name starting with `weka-app-store` shows `Running` status.
3. Confirm the custom resource type registered:

   ```bash
   kubectl get crd wekaappstores.warp.io
   ```

   If both commands return results, the operator is ready.

## Step 3: Access the App Store

With the operator running, open the App Store GUI to start the setup wizard.

For LoadBalancer or NodePort installations, find the assigned address:

```bash
kubectl get svc -n weka-app-store
```

For LoadBalancer, use the address under `EXTERNAL-IP`. For NodePort, use any worker node's IP address with the high port number shown under `PORT(S)`.

For ClusterIP installations, open a temporary tunnel:

```bash
kubectl port-forward svc/wekaappstoregui-svc 8080:80 -n weka-app-store
```

Then open `http://localhost:8080` in a browser.

{% hint style="info" %}
Until the setup wizard is completed, every page in the App Store redirects back to the wizard. Complete the wizard before deploying blueprints or accessing the main interface.
{% endhint %}

## Step 4: Complete the setup wizard

The setup wizard runs once and configures the connection between the Kubernetes cluster and the NeuralMesh storage system, across six screens.

### Node prerequisites

Before WEKA can run as a containerised storage client on the Kubernetes nodes, the kubelet, the Kubernetes agent that runs on every node, needs specific settings applied. This screen displays the configuration to apply on every worker node before continuing.

{% hint style="warning" %}
Applying these settings requires SSH access to each worker node and causes the kubelet to restart on each node, briefly interrupting the Kubernetes agent on that node. Schedule this during a maintenance window on production clusters.
{% endhint %}

The wizard displays a ready-to-paste configuration snippet with the following settings.

<table><thead><tr><th width="204.17578125">Setting</th><th width="163.4765625">Value</th><th>Purpose</th></tr></thead><tbody><tr><td>CPU Manager Policy</td><td><code>static</code></td><td>Allows containers to request dedicated CPU cores instead of sharing them. WEKA's storage processes require exclusive access to specific cores for consistent performance.</td></tr><tr><td>Reserved CPUs</td><td><code>1000m</code> plus CPUs 0 and 1</td><td>Reserves one CPU core and two dedicated system CPUs for Kubernetes system processes, so WEKA does not compete with the operating system for CPU time.</td></tr><tr><td>Reserved Memory</td><td><code>1 GiB</code></td><td>Reserves RAM for Kubernetes system processes, separate from the memory WEKA itself uses.</td></tr><tr><td>Hugepages</td><td>25,000 x 2 MB (50 GB per node)</td><td>Reserves large memory regions that bypass normal operating system memory management, letting WEKA move data at high speed with minimal CPU overhead. Confirm each node has at least 50 GB of free RAM above what other workloads need.</td></tr></tbody></table>

Apply the configuration and restart the kubelet on every worker node, then select the confirmation checkbox and select **Next**.

### Quay credentials

WEKA's operator and client container images are stored in a private registry on Quay.io. This step creates a Kubernetes pull secret so the nodes can authenticate with Quay.io and download the images during installation.

<table><thead><tr><th width="187.51953125">Field</th><th width="165.08984375">Requirement</th><th>Description</th></tr></thead><tbody><tr><td>Quay Username</td><td>Required</td><td>The Quay.io account granted access to WEKA's private container images.</td></tr><tr><td>Quay Password</td><td>Required</td><td>The Quay.io password or robot token. A robot token is recommended for production environments: it can be rotated without affecting the main login, and it distinguishes a service credential from a personal one in audit logs.</td></tr><tr><td>Operator Version</td><td>Default: <code>v1.13.0</code></td><td>The version of the WEKA Kubernetes operator to install. Leave the default if unsure. The version must exist on Quay.io, entered as <code>v1.13.0</code> or <code>1.13.0</code>.</td></tr></tbody></table>

Use the Quay.io credentials from the WEKA portal account at get.weka.io.

### WEKA connection

This step tells the WEKA client, which runs as a DaemonSet on every node, how to find and connect to the NeuralMesh cluster.

<table><thead><tr><th width="206.94140625">Field</th><th width="133.578125">Requirement</th><th>Description</th></tr></thead><tbody><tr><td>WEKA Endpoints</td><td>Required</td><td>A comma-separated list of <code>host:port</code> entries for the NeuralMesh cluster servers. At least one entry is required; three or more allow the client to stay connected if one server is temporarily unavailable. Example: <code>10.0.1.10:14000,10.0.1.11:14000,10.0.1.12:14000</code></td></tr><tr><td>WEKA Image Version</td><td>Required</td><td>The exact WEKA software version running on the cluster. The containerized client version must match the version on the NeuralMesh servers: even a minor version mismatch prevents the client from connecting. Example: <code>5.1.0.605</code></td></tr><tr><td>Endpoint Scheme</td><td>Default: <code>http</code></td><td>The protocol used to reach the NeuralMesh cluster management API. Leave as <code>http</code> unless the NeuralMesh cluster has TLS enabled on its management API endpoint, in which case select <code>https</code>.</td></tr></tbody></table>

Find the endpoint addresses in the WEKA management UI under **Configure > Cluster Servers**, then select **Backends** from the server menu. The default port is `14000`. Find the image version by running `weka version` on a WEKA server, or under **Configuration > Cluster Settings > General Information** in the management UI.

### Networking

This step sets how the WEKA client transfers data between the Kubernetes nodes and the NeuralMesh cluster. The choice affects throughput and latency. Select **Auto** if unsure: the mode can be changed later.

<table><thead><tr><th width="239.40234375">Mode</th><th>Description</th></tr></thead><tbody><tr><td>Auto (recommended)</td><td>WEKA automatically selects the best available networking mode for the environment. The safest choice when the available NICs or supported modes are unclear.</td></tr><tr><td>DPDK (high performance)</td><td>Uses kernel-bypass networking for the highest throughput and lowest latency. Requires DPDK-capable network cards, typically Mellanox/NVIDIA ConnectX series or Intel adapters. Selecting DPDK reveals a field for the NIC device names: enter the storage network interface names, comma-separated, for example <code>ens3f0,ens3f1</code>. Find NIC names by running <code>ip link show</code> on a worker node and identifying the interfaces connected to the storage network.</td></tr><tr><td>UDP (compatibility mode)</td><td>Uses standard UDP-based software networking. Lower throughput than DPDK, but compatible with any network card and environment. Use this when DPDK is unavailable or maximum throughput is not required.</td></tr></tbody></table>

### WEKA credentials

These credentials let the WEKA CSI storage driver authenticate with the NeuralMesh cluster to create, delete, and manage storage volumes on behalf of Kubernetes workloads.

{% hint style="warning" %}
Use a dedicated service account for this step. Create a separate WEKA user with the CSI role assigned, rather than a personal admin account. If a personal account's password changes, storage stops working cluster-wide, and audit logs cannot distinguish operator actions from user actions.
{% endhint %}

<table><thead><tr><th width="183.484375">Field</th><th width="139.9453125">Requirement</th><th>Description</th></tr></thead><tbody><tr><td>WEKA Organization</td><td>Default: <code>Root</code></td><td>The WEKA organization the CSI user account belongs to. Leave as <code>Root</code> if the cluster does not use multi-tenancy, otherwise enter the organization name where the CSI service account was created.</td></tr><tr><td>WEKA Username</td><td>Required</td><td>The username of the WEKA CSI service account. The account must already exist in WEKA with the CSI role assigned.</td></tr><tr><td>WEKA Password</td><td>Required</td><td>The password for the WEKA CSI service account.</td></tr></tbody></table>

### Review and install

The final screen summarises every setting entered across the previous steps, with passwords masked. Review the endpoint addresses, version numbers, and networking mode, since these are the most common sources of installation errors.

Select **Install** to start a two-phase deployment with a live progress stream on the next screen.

<table><thead><tr><th width="269.08984375">Phase</th><th>Description</th></tr></thead><tbody><tr><td>Phase 1: WEKA integration</td><td>Installs the WEKA Kubernetes operator, deploys the CSI storage driver, sets up image pull secrets, launches the WEKA client DaemonSet on every worker node, and creates the storage classes Kubernetes uses to provision NeuralMesh-backed volumes.</td></tr><tr><td>Phase 2: Cluster initialization</td><td>Deploys the monitoring stack (Prometheus and Grafana), the NVIDIA NIM Operator for AI workloads, and the Envoy Gateway networking layer that routes external traffic to the App Store and other deployed applications. Phase 2 starts automatically once Phase 1 completes.</td></tr></tbody></table>

{% hint style="warning" %}
The live progress stream runs in the browser. Navigating away or refreshing the page loses the live view, though the installation continues in the background. Check pod status manually to track progress if this happens.
{% endhint %}

## Step 5: Monitor the installation

After selecting **Install**, the App Store shows a live progress screen with a row for every component being deployed. Each row updates in real time as the operator works through the installation sequence.

Most of the installation time is spent downloading container images to the nodes on the first install. On a standard internet connection, Phase 1 typically takes 10 to 20 minutes (up to 45 minutes on slow connections), and Phase 2 typically adds 5 to 10 minutes. Later installs on the same cluster complete faster, since most images are already cached on the nodes.

If a row shows a `Failed` status, check the operator log for the cause:

```bash
kubectl logs -n weka-app-store \
  -l app.kubernetes.io/name=weka-app-store-operator-chart \
  --tail=100
```

The log identifies which component failed and why. Common causes include incorrect endpoint addresses, version mismatches, image pull failures from incorrect Quay credentials, or network connectivity issues between the Kubernetes cluster and NeuralMesh.

## Step 6: Verify the installation

Once both phases complete, the App Store redirects to the main interface. Run the following checks to confirm everything is healthy.

Check that all pods are running:

```bash
kubectl get pods -n weka-operator-system   # WEKA Kubernetes operator
kubectl get pods -n csi-wekafs             # CSI storage driver
kubectl get pods -n monitoring             # Monitoring stack (Prometheus and Grafana)
```

All pods show `Running` or `Completed` status. Check a pod's events with `kubectl describe pod <name> -n <namespace>` if any are stuck in `Pending` or `CrashLoopBackOff`.

Check that the storage classes were created:

```bash
kubectl get storageclasses
```

Three WEKA storage classes are listed.

<table><thead><tr><th width="227.12890625">Storage class</th><th>Description</th></tr></thead><tbody><tr><td><code>wekafs-dir-api</code></td><td>The default storage class. Volumes are created as directories within a NeuralMesh filesystem. Deleting a Kubernetes PVC also deletes the data.</td></tr><tr><td><code>wekafs-dir-api-retain</code></td><td>The same as above, with a Retain reclaim policy. Data in NeuralMesh persists after the Kubernetes PVC is deleted. Use this for data that should outlive the workload's lifecycle.</td></tr><tr><td><code>wekafs-fs-api</code></td><td>Filesystem-backed volumes. Each volume gets a dedicated NeuralMesh filesystem instead of a directory within a shared filesystem, suited to workloads with filesystem-level isolation requirements.</td></tr></tbody></table>

The Kubernetes cluster is now connected to NeuralMesh storage. Open the App Store interface to deploy blueprints, including the WEKA AI Data Platform.


# Install the WEKA AI Data Platform

Deploy AIDP from the WEKA App Store, connect it to NeuralMesh storage, and configure identity federation for secure data access.

Deploy AIDP, WEKA's AI data pipeline that continuously transforms enterprise file data into AI-ready context, from the WEKA App Store catalogue. Complete a form and select **Deploy** to roll out the platform, with no terminal required.

## What AIDP deploys

The WEKA AI Data Platform watches a NeuralMesh filesystem continuously: every file created, updated, or deleted is captured through WEKA's snapshot-diff mechanism and reflected in the vector index in real time, without a scheduler, polling interval, or reindex cycle.

Selected files are parsed, chunked, and embedded using NVIDIA NIM models, then indexed into a vector database, with POSIX permissions captured at ingest and enforced at query time: a user who cannot see a file on the filesystem cannot see its vector either. Users interact with the results, including semantic search and agentic RAG, through a browser UI or API, without accessing the underlying pipeline directly.

On the installation side, a browser-managed control plane lets users create watchers that identify which NeuralMesh filesystem and folders to monitor. A Kubernetes operator turns each request into the storage and workload objects it needs. The full stack, including Keycloak identity, the NVIDIA Nemo Retriever (NIMs, Milvus, and the ingestion pipeline), observability, and the AI Data Platform's own services, ships as a single WEKA App Store application. Selecting it in the App Store catalogue and completing one form deploys everything as a `WekaAppStore` custom resource, which the operator reconciles component by component with automatic dependency ordering and readiness gating.

## Before you begin

Confirm the following before opening AIDP. The App Store GUI does not set these up.

* The WEKA App Store is installed and running on the cluster, with the NVIDIA GPU Operator, the WEKA CSI driver, and Envoy Gateway (with a `warp-edge-gateway` Gateway resource) already in place. See [Install the WEKA App Store](/weka-app-store/install-the-weka-app-store) for these prerequisites.
* Enough free GPU capacity. AIDP's default profile requires 12 RTX PRO 6000 SE GPUs (96 GB each) across 3 nodes, plus 32 CPU cores and 128 GiB of memory as a floor for the rest of the stack. The AIDP page's Cluster Compatibility panel checks this automatically before deployment.
* An NVIDIA NGC account and API key, for pulling NIM container images and downloading model weights. Obtain one from org.ngc.nvidia.com/setup/api-keys, then enter it in the App Store's credential manager.
* A NeuralMesh cluster with an S3-compatible bucket already created for the AI Data Platform's vector database traffic, plus WEKA S3 access and secret keys for that bucket.
* The cluster's S3 server IP addresses. Run `weka s3 cluster` on a WEKA server to list them, for entry into the install form so the built-in load balancer can reach them.
* WEKA REST API access: the management host or IP address, a username, and an API token or password with permission to manage filesystems. This becomes the platform's WEKA Storage credential.
* A Kubernetes load-balancer solution for the cluster. The WEKA App Store does not include or install one. See below for its role and requirements.
* A DNS zone configured for the Envoy routes AIDP creates. See below for the required configuration.

### Set up a DNS zone for Envoy routes

Every hostname the AI Data Platform uses, including Keycloak, its own GUI, the Attu admin UI, and observability, routes through one shared Envoy Gateway (`warp-edge-gateway`) that the WEKA App Store installs. That gateway is a single Kubernetes LoadBalancer service, and assigning it a real external IP depends entirely on the cluster already having a load-balancer solution configured: this is customer-provided infrastructure, not something the WEKA App Store installer sets up.

<div data-with-frame="true"><figure><img src="/files/3yhxNvBdJsfPImiFCj0z" alt=""><figcaption><p>The warp-edge-gateway LoadBalancer service with an external IP assigned by the cluster's load-balancer solution</p></figcaption></figure></div>

If the cluster does not already have one, provide it before continuing, for example MetalLB on a bare-metal cluster or a cloud provider's native load-balancer integration. Once in place, Envoy reads the `Host` header of each incoming request and routes it to the correct internal service. There is no separate IP per hostname, so every hostname in use must resolve to that single IP.

| Hostname          | Example                | Purpose                                                |
| ----------------- | ---------------------- | ------------------------------------------------------ |
| Keycloak FQDN     | `keycloak.example.com` | Sign-in and identity                                   |
| GUI base URL host | `aidp.example.com`     | The AI Data Platform's own web UI                      |
| Attu hostname     | `attu.example.com`     | The Milvus vector database admin UI                    |
| Cluster FQDN      | `example.com`          | Used to derive `phoenix.example.com` for observability |

Manage these as one DNS zone, either an existing organisational domain or a dedicated subdomain carved out for the cluster (for example, `aidp.yourcompany.com`). Within that zone, do one of the following:

* Wildcard record (recommended): a single `*.example.com` A record pointing to the gateway IP covers every hostname above automatically, along with any future hostname added later.
* Individual records: create one A record per hostname above, each pointing to the same gateway IP.

Obtain the Envoy Gateway's external IP from a cluster or network administrator before creating these records: it is the address the cluster's load-balancer solution assigned to `warp-edge-gateway`.

{% hint style="warning" %}
`warp-edge-gateway` serves plain HTTP, not HTTPS, and has no TLS termination configured out of the box. It listens on port 80 only. For HTTPS on these hostnames, place a TLS-terminating proxy or load balancer in front of the gateway. Otherwise, plan on accessing Keycloak, the GUI, and Attu over plain HTTP.
{% endhint %}

Confirm this DNS zone works before opening the install form. The Keycloak FQDN, GUI base URL, and Attu hostname fields must all resolve correctly for the Keycloak sign-in redirect to work once the platform is deployed.

## Step 1: Register credentials

The install form references two credentials by name rather than accepting secrets directly. Register both under **Settings > Credential Management** before starting AIDP.

<table><thead><tr><th width="237.90625">Credential</th><th>Steps</th></tr></thead><tbody><tr><td>NVIDIA NGC API Keys</td><td>Under <strong>NVIDIA NGC API Keys</strong>, select <strong>+ Add</strong>. Enter a display name and the NGC API key. The App Store derives the image-pull secret and the NIM model-download key from this entry.</td></tr><tr><td>WEKA Storage API Tokens</td><td>Under <strong>WEKA Storage API Tokens</strong>, select <strong>+ Add</strong>. Enter the WEKA management endpoint (host or IP address), a username, and an API token or password. This becomes the credential the AI Data Platform operator and Space Manager use to reach the cluster's REST API.</td></tr><tr><td>WEKA Quay Token</td><td>Under <strong>Quay Token</strong>, select <strong>+ Add</strong>. To pull images for AIDP from the WEKA Quay repository, you will need to enter your Quay Robot username and password. Failure to do this will produce imagepullerror on deployment.</td></tr></tbody></table>

Once saved, each credential shows a Ready status on the Settings page, making it selectable from a dropdown on the AIDP install form.

<div data-with-frame="true"><figure><img src="/files/qzcZgmMK49uojUnpLIXb" alt=""><figcaption><p>Settings → Credential Management, with both credentials registered and showing a Ready status</p></figcaption></figure></div>

## Step 2: Find the Application

From the App Store home page, select **Explore Blueprints** and open AIDP. The detail page shows a description of what it deploys and a Cluster Compatibility panel comparing the cluster's free CPU, memory, and GPU capacity against AIDP requirements.

<div data-with-frame="true"><figure><img src="/files/msFaGypfna57k9W7qpYX" alt="" width="563"><figcaption><p>The App Store catalog: AIDP listed under Browse by category</p></figcaption></figure></div>

{% hint style="info" %}
If the Cluster Compatibility panel shows a shortfall, the **Deploy** button stays disabled until the cluster has enough free GPU, CPU, or memory capacity. Free up capacity or add nodes before continuing.
{% endhint %}

## Step 3: Complete the install form

The installation form contains fields, including two credential dropdowns populated in Step 1. Enter or select the remaining values as described below.

<div data-with-frame="true"><figure><img src="/files/UZzCVaQmVPNddJVbKeTM" alt=""><figcaption><p>The AIDP detail page: Cluster Compatibility panel on the right, Configure form below it</p></figcaption></figure></div>

<table><thead><tr><th width="238.0546875">Field</th><th width="139.09375">Requirement</th><th>Description</th></tr></thead><tbody><tr><td>Namespace</td><td>Required</td><td>The Kubernetes namespace to deploy into, created automatically if it does not already exist. Select an existing namespace from the dropdown or enter a new name, for example <code>rag</code>.</td></tr><tr><td>NGC Credential</td><td>Credential</td><td>Dropdown of registered NVIDIA NGC credentials from step 1. Pulls NIM images from <code>nvcr.io</code> and supplies the NGC API key to the model-serving NIMs.</td></tr><tr><td>WEKA Credential</td><td>Credential</td><td>Dropdown of registered WEKA Storage credentials from step 1. Supplies the WEKA REST API token the AI Data Platform operator and Space Manager use to manage filesystems.</td></tr><tr><td>WEKA S3 Access Key</td><td>Required</td><td>Access key for the WEKA S3-compatible bucket, used by Milvus and the NVIDIA ingestion pipeline.</td></tr><tr><td>WEKA S3 Secret Key</td><td>Required</td><td>Secret key paired with the access key above.</td></tr><tr><td>WEKA S3 Bucket Name</td><td>Default:<br><code>aidp-bucket</code></td><td>Name of the S3 bucket Milvus and the ingestion pipeline use. This bucket must already exist on the cluster.</td></tr><tr><td>WEKA S3 Node IPs</td><td>Required</td><td>Comma or space-separated list of the cluster's S3 server IP addresses, across which the built-in load balancer distributes traffic. Get the list by running <code>weka cluster nodes --role S3</code> on a WEKA server. Example: <code>192.168.1.1, 192.168.1.2, 192.168.1.3</code></td></tr><tr><td>WEKA API Host</td><td>Required</td><td>The bare WEKA management IP address or hostname, without <code>http://</code> or a port (port 14000 is assumed). Example: <code>172.3.4.248</code></td></tr><tr><td>Keycloak FQDN</td><td>Required</td><td>External hostname for Keycloak sign-in, hostname only, without a scheme or path. Example: <code>keycloak.example.com</code></td></tr><tr><td>GUI Base URL</td><td>Required</td><td>Full external URL of the AI Data Platform GUI. The Keycloak OIDC redirect URI is derived from this value. Example: <code>https://aidp.example.com</code></td></tr><tr><td>Attu Hostname</td><td>Required</td><td>External hostname for the Milvus Attu admin UI, hostname only. Example: <code>attu.example.com</code></td></tr><tr><td>Cluster FQDN</td><td>Required</td><td>The general cluster domain, used to derive the observability hostname (<code>phoenix.&#x3C;domain></code>). Example: <code>example.com</code></td></tr><tr><td>Vector DB Filesystem Name</td><td>Required</td><td>The human-readable NeuralMesh name backing the vector database, exactly as shown in the WEKA console.</td></tr></tbody></table>

## Step 4: Deploy and monitor progress

Select **Deploy**. The App Store applies the underlying `WekaAppStore` resource and streams a live progress view with one row per component, updating in real time as the operator works through the dependency graph, the same experience as any other App Store application installation.

Budget 60 to 90 minutes for a cold install. Almost all of that time is spent on the NVIDIA RAG component downloading NIM model weights on the first deployment. Every other component, including Keycloak, the load balancer, the bootstrap jobs, and the AI Data Platform's own services, typically finishes within a few minutes each.

{% hint style="warning" %}
Keep the browser tab open. Navigating away loses the live view, though the installation continues running in the background.
{% endhint %}

AIDP installs active components in dependency order.

| Component                    | Purpose                                                                                                                        | Typical duration                                     |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------- |
| `aidp-site-config`           | Generates the site-config ConfigMap from the form answers                                                                      | Seconds                                              |
| `weka-s3-lb`                 | nginx load balancer distributing traffic across the WEKA S3 server IP addresses                                                | Seconds                                              |
| `aidp-bootstrap-secrets`     | Bootstrap secrets required by every downstream component                                                                       | Seconds                                              |
| `aidp-bootstrap-ngc-secrets` | Materializes the NGC image-pull and API-key secrets from the NGC credential                                                    | Under 1 minute                                       |
| `aidp-bootstrap-weka-token`  | Patches the WEKA REST API token from the WEKA Storage credential into the operator's secret                                    | Under 1 minute                                       |
| `aidp-keycloak-realm-config` | Prepares the Keycloak realm import (clients, roles, groups) for the AI Data Platform                                           | Under 1 minute                                       |
| `envoy-endpoint-discovery`   | Discovers the Envoy Gateway's ClusterIP for internal hostname resolution                                                       | Under 1 minute                                       |
| `embedding-gateway`          | Internal L7 proxy giving the ingestion pipeline a stable embedding endpoint                                                    | Under 1 minute                                       |
| `keycloak`                   | Deploys Keycloak and imports the AI Data Platform's identity realm                                                             | 5 to 10 minutes                                      |
| `keycloak-secret-sync`       | Fetches the client secrets Keycloak generates on realm import and syncs them into the AI Data Platform's secrets automatically | Under 1 minute                                       |
| `milvus`                     | Vector database for RAG, backed by the WEKA S3 bucket                                                                          | 10 to 15 minutes                                     |
| `aidp-observability`         | Logs, traces, and LLM prompt and completion visibility (Loki, Tempo, Phoenix)                                                  | 10 to 15 minutes                                     |
| `space-manager-postgres`     | Database backing the embedding-eviction service                                                                                | 5 minutes                                            |
| `nvidia-rag-blueprint`       | All NIM inference services, the ingestion pipeline, and the RAG server                                                         | Up to 60 minutes cold; faster once models are cached |
| `aidp`                       | The AI Data Platform's GUI, Operator, RAG Gateway, RAG Bridge, and Space Manager                                               | 5 minutes                                            |

## Step 5: Federate the identity provider

The WEKA AI Data Platform's core security promise, that a user who cannot see a file cannot see its vector, holds only if the platform knows who its users actually are. That identity must come from an existing source: Active Directory, LDAP, or an existing SSO provider. Federating Keycloak with that source lets the AI Data Platform enforce the organisation's existing access controls instead of introducing a second, disconnected set of accounts.

Every AI Data Platform component authenticates against one Keycloak realm, `rag-gateway`. Out of the box, that realm is an empty shell: the groups and roles already exist, but no connection to a real user directory exists yet. Until this step is complete, the only way into the AI Data Platform GUI is the built-in Keycloak admin account.

{% hint style="warning" %}
Rotate the default Keycloak admin password first. AIDP provisions a Keycloak admin account (`admin`) with a fixed default password, so the Admin Console is reachable immediately after deployment. Because that default ships in the AIDP source, treat it as public on day one: sign in at the configured Keycloak hostname (`/auth/admin/`) and change it under the account's **Credentials** tab before doing anything else.
{% endhint %}

### Realm groups

Every AI Data Platform login is evaluated against the `rag-gateway` realm, which ships with three groups already defined. Map federated users into the correct group; do not create new ones.

| Group             | Grants                                                                                                            |
| ----------------- | ----------------------------------------------------------------------------------------------------------------- |
| `/cluster-admins` | The `aidp-cluster-admin` role: full, cluster-wide visibility and management of every watcher regardless of owner. |
| `/admins`         | The `aidp-admin` role: full watcher management plus purge capability.                                             |
| `/users`          | The default group. No elevated role; members see and manage only the watchers they created.                       |

A user with no group assignment can still sign in, but lands in the same restricted, own-watchers-only view as `/users`. Mapping real users into the correct group determines what they can do, not just whether they can log in.

### POSIX UID and GID for ACL-enforced vector search

Groups control who can manage watchers. A separate pair of attributes controls whether a user's search results reflect the files they are actually allowed to see. The AI Data Platform's RAG Gateway and RAG Bridge look up each user's `uid` and `gids` from their Keycloak profile at query time and use them to filter vector search results against the same POSIX ownership and permissions enforced on NeuralMesh. This mechanism underlies the platform's core security promise, and it depends entirely on those two attributes holding the user's real identity.

<table><thead><tr><th width="126.1015625">Attribute</th><th>Description</th></tr></thead><tbody><tr><td><code>uid</code></td><td>The user's POSIX UID as it exists on NeuralMesh, a single numeric value, for example <code>1001</code>.</td></tr><tr><td><code>gids</code></td><td>Every POSIX GID the user belongs to, multi-valued, each a numeric value, for example <code>1001, 2010</code>.</td></tr></tbody></table>

{% hint style="warning" %}
Keycloak marks these fields optional. Treat them as required: declaring the fields does not populate them, and a user with no `uid` or `gids` set falls back to a shared default identity for vector search, which does not reflect their real file-level permissions. For deployments doing ACL-enforced search or retrieval, every user needs real values here.
{% endhint %}

Populate these values in one of two ways:

* Set them manually: in the Keycloak Admin Console, open **Users**, select a user, and add `uid` and `gids` values on the **Attributes** tab.
* Federate them automatically: for Active Directory or LDAP, add a `user-attribute-ldap-mapper` mapping the directory's `uidNumber` attribute to Keycloak's `uid`, and a second mapper for the GID source to `gids`. For SAML or OIDC, configure the identity provider to emit the user's numeric POSIX UID and GID as attributes or claims, then add an Attribute or Claim Importer mapper in Keycloak targeting the `uid` and `gids` user profile fields, following the same pattern used for groups below.

### Connect an identity source

Keycloak supports three ways to connect a real identity source. Configure only the one that matches the environment.

#### Option A: Active Directory or LDAP

1. In the Keycloak Admin Console, switch the realm selector to `rag-gateway`, open **User federation**, and select **Add Ldap providers**.
2. Set **Vendor** to **Active Directory** (or the specific LDAP vendor), then enter the **Connection URL** (for example `ldaps://dc.yourcompany.com:636`), **Bind DN**, and **Bind Credential** for a service account with read access to the directory.
3. Set **Users DN** to the base DN the users live under (for example `ou=People,dc=yourcompany,dc=com`), and **Username LDAP attribute** to `sAMAccountName` for Active Directory.
4. Select **Test connection** and **Test authentication**, then **Save**.
5. Open the new provider's **Mappers** tab and add a `group-ldap-mapper`. Point it at the DN the security groups live under (**LDAP Groups DN**), and set **Mode** to `READ_ONLY` so Keycloak treats the directory as the source of truth.
6. Name or map the AD/LDAP groups to match the realm's existing group names exactly (`cluster-admins`, `admins`), so the sync lands members directly in `/cluster-admins` and `/admins` instead of creating new top-level groups that require manual merging.
7. Trigger a sync (**Sync all users**) and confirm affected users appear under **Groups > cluster-admins / admins** in the Admin Console.

#### Option B: SAML 2.0 identity provider

1. In the `rag-gateway` realm, open **Identity providers > Add provider > SAML v2.0**.
2. If the identity provider (ADFS, PingFederate, Okta's SAML app type, and similar) can export metadata, use **Import from URL** or **Import from file** to auto-fill the SSO URL, entity ID, and signing certificate. Otherwise enter these manually from the identity provider's setup screens.
3. On the identity provider side, create a SAML application with its Assertion Consumer Service (ACS) URL set to the Keycloak hostname's realm broker endpoint for this provider, and its Audience or Entity ID set to the Keycloak hostname's `rag-gateway` realm URL.
4. Configure the identity provider to include a group-membership attribute in the SAML assertion, often called a Group Attribute Statement.
5. In Keycloak, open the identity provider's **Mappers** tab and add a SAML Attribute Importer mapper targeting a group, mapping the identity provider's group values to `/cluster-admins` and `/admins`.
6. Test with a real federated user and confirm they land in the correct group after their first login.

#### Option C: OpenID Connect (Okta, Entra ID, and similar)

1. In the `rag-gateway` realm, open **Identity providers > Add provider > OpenID Connect v1.0**.
2. Enter the provider's discovery endpoint (for Okta, the Okta domain plus `/.well-known/openid-configuration`). Keycloak auto-fills the authorization, token, and userinfo endpoints from it.
3. On the identity provider side, create an OIDC application (in Okta: **Applications > Create App Integration > OIDC - Web Application**) with its sign-in redirect URI set to the Keycloak hostname's realm broker endpoint for this provider.
4. Copy the Client ID and Client Secret the identity provider generates into Keycloak's provider configuration, then save.
5. Configure the identity provider to include a `groups` claim in its tokens (in Okta, under **Authorization Server > Claims**).
6. In Keycloak, open the identity provider's **Mappers** tab and add a Claim to Group mapper, mapping the incoming `groups` claim values to `/cluster-admins` and `/admins`.
7. Test with a real federated user and confirm they land in the correct group after their first login.

#### Option D: Local users (test and development only)

{% hint style="danger" %}
Do not use local users for production access. Local Keycloak users are not deprovisioned when someone leaves the organization, do not inherit the identity provider's MFA or conditional access policies, and their passwords live only in Keycloak. Use this option only to stand up a working login for early testing before a real AD/LDAP, SAML, or OIDC connection exists, then delete the account once federation (Options A through C) is in place.
{% endhint %}

1. In the Keycloak Admin Console, switch the realm selector to `rag-gateway`, open **Users**, and select **Add user**. Enter a username and select **Create**.
2. Open the new user's **Credentials** tab, select **Set password**, and enter a password. Toggle **Temporary** off to avoid forcing a password change on first login.
3. Open the **Attributes** tab and add `uid` and `gids` values matching a real POSIX identity on NeuralMesh. Without this, the test user's search results do not reflect real file permissions.
4. Open the **Groups** tab, select **Join Group**, and add the user to `/cluster-admins` or `/admins` depending on what to test. Leave the user ungrouped to test the default, own-watchers-only experience.
5. Sign in at the configured GUI base URL with the new username and password to confirm the account works end to end.

Until an identity source is federated, or a user is created locally and mapped into a group by hand, only the default Keycloak admin account can sign into the AI Data Platform GUI. Any user who signs in without landing in `/cluster-admins` or `/admins` sees only their own watchers, regardless of how they authenticated.

## Step 6: Verify the installation

Confirm the deployment from the browser; no terminal is required.

1. Confirm AIDP's status reads Ready. The App Store's deployment view shows every component with a green ready indicator once the rollout finishes. The **Blueprint Uninstall** panel under **Settings** lists `weka-aidp` as installed in the configured namespace (for example `rag`), with its install timestamp.
2. Open the AI Data Platform's GUI at the configured base URL. Confirm the login page redirects through Keycloak for sign-in and returns to the dashboard afterward.
3. Sign in and create a test watcher: select a NeuralMesh filesystem and a folder to monitor. If it moves from Provisioning to Active, storage, the operator, and the ingestion pipeline are wired up correctly end to end.
4. Open the configured Attu hostname to confirm the Milvus admin UI is reachable and shows a healthy collection.

The WEKA AI Data Platform is now deployed and connected to Keycloak, WEKA storage, and the RAG ingestion pipeline, entirely from the browser.

## Troubleshooting

Start with the App Store's live progress view: every component row that fails shows the operator's error message inline, which covers most install problems.

| Symptom                                        | Likely cause                                                                        | What to check                                                                                                                           |
| ---------------------------------------------- | ----------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| **Deploy** button stays disabled               | The Cluster Compatibility check is failing                                          | Recheck the panel on the AIDP page. The cluster needs free capacity for 12 RTX PRO 6000 SE-class GPUs, 32 cores, and 128 GiB of memory. |
| Credential dropdown is empty                   | No ready credential of that type exists yet                                         | Go to **Settings > Credential Management** and add one. The page shows a not-ready state until the credential validates.                |
| `nvidia-rag-blueprint` stuck over 60 minutes   | NIM model download stalled, often from an invalid NGC credential                    | Recheck the NGC credential's status on the Settings page. The live progress row shows the operator's own error if the download failed.  |
| `keycloak` or `aidp` component fails readiness | A hostname field does not resolve, or a DNS entry is not pointed at the cluster yet | Confirm the Keycloak FQDN, GUI base URL, Attu hostname, and cluster FQDN entered all have working DNS records.                          |
| Login redirects to Keycloak but then fails     | `keycloak-secret-sync` has not completed yet                                        | Wait for that row to show Ready in the progress view before testing login. It runs automatically right after Keycloak comes up.         |
| Ingestion jobs time out reaching WEKA S3       | Incorrect or incomplete WEKA S3 server IP list                                      | Reverify the IP list against `weka cluster nodes --role S3` on a WEKA server and recheck the form entry.                                |

A cluster administrator with `kubectl` access can investigate pod logs and events for the failing component's namespace as an advanced fallback.


# Manage the system using the WEKA GUI

WEKA GUI application enables you to configure, administer, and monitor the WEKA system. This page provides an overview of the primary operations, access to the GUI, and system dashboard.

## WEKA GUI overview

The WEKA GUI application is the administration tool for your WEKA system. Use this tool for system configuration, filesystems management, user management, and investigation of alarms, events, and statistics.

WEKA GUI application supports the following functions:

* **Configuration**:
  * Configure the cluster, such as data availability, license, security, and central monitoring.
  * Configure the backend containers and expose the data in different protocols.
  * Manage local users and set up the user directory.
  * Create and manage organizations and their quotas.
* **Management**:
  * Manage the filesystems, including tiering, thin provisioning, and encryption.
  * Manage snapshots.
  * Manage the object store buckets.
  * Manage the filesystem protocols: SMB, S3, and NFS.
  * Manage directory quotas.
* **Investigation**:
  * Investigate events.
  * Investigate overtime statistics, such as total operations, R/W throughput, CPU usage, and read or write latency.
* **Monitoring**:
  * View the cluster protection and availability.
  * View the R/W throughput.
  * View the backend and client top consumers.
  * View alarms.
  * View the used, provisioned, and total capacity.
  * View the frontend, compute, and drive cores usage.
  * View the hardware components (active/total).

<div data-with-frame="true"><img src="/files/0h3YWspT4RGfGlTPuhtK" alt="WEKA GUI overview"></div>

## Access the WEKA GUI

WEKA GUI is a web application you can access using an already configured account and has the appropriate rights to configure, administer, or view.

You can access the WEKA GUI with any standard browser using the address:\
`https://<weka system or server name>:14000`

For example: `https://WekaProd:14000` or `https://weka01:14000`.

**Before you begin**

Make sure that port 14000 is open in the firewall of your organization.

**Procedure**

1. In your browser, go to `https://<weka system or server name>:14000`.\
   The sign-in page opens.

<div data-with-frame="true"><img src="/files/UcgifWH16AAm9rHbVMRv" alt="Sign in to the WEKA GUI"></div>

2. Sign in with the username and password of an account with cluster administration or\
   organization administration privileges. For details about the account types, see\
   \&#xNAN;*User management* in the related topics.

The system dashboard opens.

{% hint style="info" %}
The initial default username and password are *admin* and *admin*[.](/operation-guide/user-management) In the first sign-in, WEKA GUI enforces changing the admin password.
{% endhint %}

**Related topics**

[User management](/operation-guide/user-management)

## System Dashboard

The system dashboard contains widgets that provide an overview of the WEKA system, including an overall status, R/W throughput, top consumers, alerts, capacity, core usage, and hardware.

The system dashboard opens by default when you sign in. If you select another menu and want to display the dashboard again, select **Monitor > System Dashboard**, or click the **WEKA** logo.

<div data-with-frame="true"><img src="/files/1XaIj6IQbXLmcZBquHkS" alt="System Dashboard"></div>

### Cluster Protection and Availability widget

This widget shows the overall status of the system's health and protection state.

The overall status widget includes the following indications:

* **Protection state:** The possible protection states include:
  * OK: The system operates properly.
  * UNKNOWN: The protection state is unknown.
  * UNINITIALIZED: The system still needs to complete the cluster configuration and run the first IOs.
  * REBUILDING: When a failure occurs, the data rebuild process reads all the stripes where the failure occurred, rebuilds the data, and returns the system to full protection.
  * PARTIALLY\_PROTECTED: Some or all of the data is not fully protected. The reported number of protections indicates the cluster's failure resilience.
  * UNPROTECTED: The data is not protected against any failure.
  * UNAVAILABLE: Too many parallel failures occur in the system that can cause system unavailability.
  * REDISTRIBUTING: The system redistributes the data between servers and drives due to scale-up or scale-down.
* **Service Uptime**: The elapsed time since the I/O services started.
* **Data Protection**: The number of data drives and protection parity drives. The color of the protection parity drives indicates their status.
* **Virtual (Hot) Spares**: The number of failure domains the system can lose and still complete the data rebuild while maintaining the same net capacity.

<div data-with-frame="true"><img src="/files/TyD1RCnIMPF9gSCdD3fY" alt="Overall status widget"></div>

### R/W Throughput widget

This widget shows the current performance statistics aggregated across the cluster.

The R/W Throughput widget includes the following indications:

* **Throughput**: The total throughput.
* **Total Ops**: The number of cluster operations.
* **Latency**: The average latency of R/W operations.
* **Active clients**: The number of clients connected to the cluster.

<div data-with-frame="true"><img src="/files/kSFJKvNC94qchx4jbYHz" alt="R/W Throughput widget"></div>

{% hint style="info" %}
Selecting one of the R/W Throughput, Latency, and Total Ops titles displays the statistics page.

Selecting the Active clients title displays the clients tab.
{% endhint %}

### Top Consumers widget

This widget shows the top 5 backend servers and clients in the system. You can sort the list of servers by total IO operations per second or total throughput.

<div data-with-frame="true"><img src="/files/dzDXkRFgAWm5y8vFoq07" alt="Top Consumers widget"></div>

### Alerts widget

This widget shows the alerts that are not muted.

<div data-with-frame="true"><img src="/files/YKG1OGxeEptOpQiwvc3N" alt="Alerts widget"></div>

### Capacity widget

This widget shows an overview of the managed capacity.

The top bar indicates the total capacity provisioned for all filesystems and the used capacity. For tiered filesystems, the total capacity also includes the Object Store part.

The bottom bar indicates the total SSD capacity available in the system, the provisioned capacity, and the used capacity.

<div data-with-frame="true"><img src="/files/XOLCGFR2cBd8jLELZTPw" alt="Capacity widget"></div>

{% hint style="info" %}
Selecting the Capacity title displays the filesystems page.
{% endhint %}

### Core Usage widget

This widget shows the average usage and the maximum load level of the Frontend, Compute, and Drive cores. Hovering the maximum value displays the most active server and the NodeID number.

<div data-with-frame="true"><figure><img src="/files/focaBqpp2foKSejzaTmE" alt=""><figcaption><p>Core Usage widget</p></figcaption></figure></div>

### Hardware widget

This widget shows an overview of the hardware components (active/total).

The hardware components include:

* **Backends**: The number of backend servers.
* **Cores**: The number of cores configured for running processes in the backend servers.
* **Drives**: The number of drives.
* **OBS Buckets**: The number of the object store buckets.

<div data-with-frame="true"><img src="/files/EFt7xLSOpeTPdHGI2nmZ" alt="Hardware widget"></div>

{% hint style="info" %}
Selecting one of the Backends, Cores, or Drives titles displays the **backend servers** page.

Selecting the OBS Buckets title displays the **object store buckets** page.
{% endhint %}

## Switch the display time

Timestamps in events and statistics are logged internally in UTC. Weka GUI displays the timestamps in local or system time. You can switch between the local and system time.

Switching the display time may be required when the customer, WEKA support, and the WEKA system are in different time zones. In this situation, the customer and WEKA support can switch the display to system time instead of local time so both view the identical timestamps.

**Procedure**

1. On the top bar, point to the timestamp.
2. Depending on the displayed time, select **Switch to System Time** or **Switch to Local Time**.

<div data-with-frame="true"><img src="/files/VWiX9xeq5xnYRb6SZeWR" alt="Switch display time"></div>

## Switch the GUI between light and dark modes

You can switch the GUI between light and dark modes according to your preferences. The dark mode is a user interface for content that displays light text on a dark background. The dark mode is beneficial for viewing screens at night. The reduced brightness can reduce eye strain in low-light conditions.

**Procedure**

1. Depending on the current display mode, point to the sun or moon symbol on the top bar.
2. Select **Switch to the light mode** or **Switch to dark mode**.

<div data-with-frame="true"><img src="/files/vrNOQzmzjPJwqYEJXC2D" alt="Switch the GUI between light and dark modes"></div>

## Display servers in 3D view

You can switch the view of the servers to 3D for the backend servers, NFS servers, S3 servers, and SMB servers.

The 3D view provides the server components' status at a glance, including the drives, cores, protocols, and load. The colors indicate, for example, if the drives or processes failed or the container is down.

<div data-with-frame="true"><figure><img src="/files/DKGPH4ty2eeduqFjVtGi" alt=""><figcaption><p>Display servers in 3D view</p></figcaption></figure></div>

## Display tables

When managing filesystems, snapshots, and object stores, the displayed tables listing the rows have two behaviors in common.

* The table title also specifies the table's number of rows and the maximum number of rows the table can display.
* You can customize the columns displayed on the table using the column selector.

<div data-with-frame="true"><figure><img src="/files/nMoAHHuby0Q67UddzanY" alt=""><figcaption><p>Example: Display the filesystems table</p></figcaption></figure></div>

## Switch display units between Base 2 and Base 10

You can switch the display units for numeric values in the GUI between Base 2 (binary) and Base 10 (decimal). This option lets you view values, such as capacity sizes and metrics, in your preferred unit format.

To switch the display units, open the user profile menu and select either **Base 2 units** or **Base 10 units**.

<div data-with-frame="true"><figure><img src="/files/KDh5KZBHFLzk65oQRCPU" alt=""><figcaption></figcaption></figure></div>


# Manage the system using the WEKA CLI

The overview of the WEKA CLI includes top-level commands, command hierarchy, how to connect to another server, auto-completion, and how to check the status of the cluster.

The WEKA CLI is installed on each WEKA server and is available through the `weka` command. It's possible to connect to any of the servers using `ssh` and running the `weka` command. The `weka` command displays a list of all top-level commands.

## Top-level commands

The WEKA CLI is installed on each WEKA server and is available through the `weka` command. Running this command displays a list of all top-level commands:

```
$ weka -h
Usage:
    weka [--color color] [--help] [--build] [--version] [--legal]

Description:
    The base command for all weka related CLIs

Subcommands:
   agent             Commands that control the weka agent (outside the weka containers)
   alerts            List alerts in the Weka cluster
   audit             Commands used for audit in a weka cluster
   cloud             Cloud commands. List the cluster's cloud status, if no subcommand supplied.
   cluster           Commands that manage the cluster
   dataservice       Commands that manage dataservice
   diags             Diagnostics commands to help understand the status of the cluster and its environment
   driver            Manage Weka drivers
   events            List all events that conform to the filter criteria
   fs                List filesystems defined in this Weka cluster
   interface-group   List interface groups
   local             Commands that control weka and its containers on the local machine
   mount             Mounts a wekafs filesystem. This is the helper utility installed at /sbin/mount.wekafs.
   nfs               Commands that manage client-groups, permissions and interface-groups
   org               List organizations defined in the Weka cluster
   s3                Commands that manage Weka's S3 container
   security          Security commands.
   smb               Commands that manage Weka's SMB container
   stats             List all statistics that conform to the filter criteria
   status            Get an overall status of the Weka cluster
   telemetry         Commands that manage the telemetry gateway
   umount            Unmounts wekafs filesystems. This is the helper utility installed at /sbin/umount.wekafs.
   upgrade           Commands that control the upgrade precedure of Weka
   user              List users defined in the Weka cluster
   version           When run without arguments, lists the versions available on this machine. Subcommands
                     allow for downloading of versions, setting the current version and other actions to manage versions.

Options:
   --agent         Start the agent service
   --color         Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')
   -h, --help      Show help message
   --build         Prints the CLI build number and exits
   -v, --version   Prints the CLI version and exits
   --legal         Prints software license information and exits

```

The options that are common to many commands include:

<table><thead><tr><th width="260.17695965807206">Option</th><th>Description</th></tr></thead><tbody><tr><td><code>-J|--json</code></td><td>Prints the raw JSON value returned by the cluster.</td></tr><tr><td><code>-H|--hostname</code></td><td>Directs the CLI to communicate with the cluster through the specified hostname or IP.</td></tr><tr><td><code>--raw-units</code></td><td>Sets the units such as capacity and bytes to be printed in their raw format, as returned by the cluster.</td></tr><tr><td><code>--UTC</code></td><td>Sets the timestamps to be printed in UTC timezone, instead of the local time of the server running the CLI command.</td></tr><tr><td><code>-f|--format</code></td><td>Specifies the format to output the result (view, csv, markdown, or JSON).</td></tr><tr><td><code>-o|--output</code></td><td>Specifies the columns to include in the output.</td></tr><tr><td><code>-s|--sort</code></td><td>Specifies the order to sort the output. May include a '+' or '-' before the column name to sort by ascending or descending order.</td></tr><tr><td><code>-F| --filter</code></td><td>Specifies the filter values for a member (without forcing it to be in the output).</td></tr><tr><td><code>--no-header</code></td><td>Indicates that the column header should not be shown when printing the output.</td></tr><tr><td><code>-C|--CONNECT-TIMEOUT</code></td><td>Modifies the default timeout used for connecting to the system via the JRPC protocol.</td></tr><tr><td><code>-T|--TIMEOUT</code></td><td>Modifies the default timeout for which the commands wait for a response before giving up.</td></tr><tr><td><code>--color</code></td><td><p>Controls the usage of color in the outputs. Possible values: <code>enabled</code>, <code>disabled</code>, or <code>auto</code><strong>.</strong></p><p><strong>Default:</strong> <code>auto</code>. It automatically determines whether to enable color based on the output destination. If the output is a terminal that supports color, it is enabled; otherwise, it is disabled.</p></td></tr></tbody></table>

{% hint style="info" %}
Throughout the documentation, the CLI mandatory parameters are marked with an asterisk (\*).
{% endhint %}

## Commands hierarchy

Most WEKA system top-level commands are the default list command for their own collection. Additional sub-commands may be available under them.

**Example:** The `weka fs` command displays a list of all filesystems and is also the top-level command for all filesystems, filesystem groups, and snapshot-related operations. It is possible to use the `-h`/`--help` flags or the `help` command to display a list of available commands at each level, as shown below:

{% code fullWidth="false" %}

```
$ weka fs
| FileSystem | Name    | Group   | SSD Bu | Total  | Is re | Is creat | Is remov 
|  ID        |         |         | dget   | Budget | ady   | ing      | ing      
+------------+---------+---------+--------+--------+-------+----------+----------
| FSId: 0    | default | default | 57 GiB | 57 GiB | True  | False    | False
```

{% endcode %}

```
$ weka fs -h
Usage:
    weka fs [--name name]
            [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--format format]
            [--output output]...
            [--sort sort]...
            [--filter filter]...
            [--filter-color filter-color]...
            [--capacities]
            [--force-fresh]
            [--help]
            [--raw-units]
            [--UTC]
            [--no-header]
            [--verbose]

Description:
    List filesystems defined in this Weka cluster

Subcommands:
   add          Create a filesystem
   remove       Delete a filesystem
   download     Download a filesystem from object store
   group        List filesystem groups
   kms-rewrap   Rewrap the key of Filesystem
   protection   Commands used to manage file system protection
   quota        Commands used to control directory quotas
   reserve      Thin provisioning reserve for organizations
   restore      Restore filesystem content from a snapshot
   security     Manage filesystem security
   snapshot     List snapshots
   tier         Show object store connectivity for each node in the cluster
   update       Update a filesystem

Options:
   --name                  Filesystem name
   --color                 Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')
   -H, --HOST              Specify the host. Alternatively, use the WEKA_HOST env variable
   -P, --PORT              Specify the port. Alternatively, use the WEKA_PORT env variable
   -C, --CONNECT-TIMEOUT   Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w,
                           infinite/unlimited)
   -T, --TIMEOUT           Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w,
                           infinite/unlimited)
   --profile               Name of the connection and authentication profile to use
   -f, --format            Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or
                           'oldview')
   -o, --output            Specify which columns to output. May include any of the following:
                           uid,id,name,group,usedSSD,usedSSDD,usedSSDM,freeSSD,availableSSDM,availableSSD,usedTotal,usedTotalD,freeTotal,availableTotal,maxFiles,status,encrypted,stores,auth,thinProvisioned,thinProvisioningMinSSDBudget,thinProvisioningMaxSSDBudget,usedSSDWD,usedSSDRD,reductionRatio,pendingReduction,dataReduction,reducedProcessedSize,reducedSize,kmsKey,kmsNamespace,kmsRole,processedReductionRatio
                           (may be repeated or comma-separated)
   -s, --sort              Specify which column(s) to take into account when sorting the output. May include a '+' or
                           '-' before the column name to sort in ascending or descending order respectively. Usage:
                           [+|-]column1[,[+|-]column2[,..]] (may be repeated or comma-separated)
   -F, --filter            Specify what values to filter by in a specific column. Usage:
                           column1=val1[,column2=val2[,..]] (may be repeated or comma-separated)
   --filter-color          Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)
   --capacities            Display all capacity columns
   --force-fresh           Refresh the capacities to make sure they are most updated
   -h, --help              Show help message
   -R, --raw-units         Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in
                           human-readable format, e.g 1KiB 234MiB 2GiB.
   -U, --UTC               Print times in UTC. When not set, times are converted to the local time of this host.
   --no-header             Don't show column headers when printing the output
   -v, --verbose           Show all columns in output

```

## Connect to another server

Most WEKA system commands deliver the same result on all cluster servers. However, it is sometimes necessary to run a command on a specific server. To do this, use the `-H/--hostname` option and specify the hostname or IP address of the target server.

## CLI auto-completion

Using `bash` you can use auto-completion for CLI commands and parameters. The auto-completion script is automatically installed.

To disable the auto-completion script, run `weka agent autocomplete uninstall`

To (re-)install the script on a server, run `weka agent autocomplete install` and re-enter your shell session.

You can also use `weka agent autocomplete export` to get the bash completions script and write it to any desired location.

## Standardized CLI command actions and entities

`weka` commands with different names but similar meanings have been standardized. Preferred names are now documented, while aliases remain for backward compatibility. Most commands now accept both singular and plural forms.

#### Standardized commands

The first name in each list is the documented one, followed by its aliases. Aliases ensure existing commands and scripts remain functional.

* **Actions:**
  * `add` (`create`, `new`)
  * `remove` (`destroy`, `delete`)
  * `attach` (`assign`)
  * `detach` (`unassign`)
  * `reset` (`unset`)
  * `update` (`updates`)
* **Entities:**
  * `drive` (`drives`)
  * `driver` (`drivers`)
  * `container` (`containers`)
  * `alerts` (`alert`)
  * `task` (`tasks`)
  * `process` (`node`, `processes`, `nodes`)
  * `resources` (`resource`)
  * `hot-spare` (`hot-spares`, `hotspare`, `hotspares`)
  * `bucket` (`buckets`)
  * `events` (`event`)
  * `denylist` (`blacklist`)
  * `permission` (`permissions`)
  * `client-group` (`client-groups`, `clientgroup`, `client-groups`)
  * `interface-group` (`interface-groups`, `interfacegroup`, `interfacegroups`)
  * `service-account` (`service-accounts`, `serviceaccount`, `serviceaccounts`)
  * `share` (`shares`)
  * `list` (`lists`)
  * `group` (`groups`)
  * `snapshot` (`snapshots`)
  * `user` (`users`)
  * `policy` (`policies`)

## WEKA CLI command output colors

The `weka status` command and various commands that return tables, such as `weka cluster buckets`, support colored output by default when executed in a terminal (tty). You can control the use of colors with the `--color` option or the `WEKA_CLI_COLOR` environment variable.

Colors are used sparingly and consistently to indicate status:

* Green: Indicates that the status is OK.
* Yellow: Represents a warning or a transient state, such as initializing or rebuilding.
* Red: Indicates an error or an issue that needs attention.

{% hint style="info" %}
Colors are only used when formatting in "human" formats (such as plain text). They are not applied when the output is in machine-readable formats such as JSON, CSV, or Markdown.
{% endhint %}

### `--color` option usage

The `--color` option controls the usage of color in the outputs. It expects one of the following values:

* **enabled**: Forces color output to be enabled, regardless of the output destination.
* **disabled**: Disables color output entirely.
* **auto**: Automatically determines whether to enable color based on the output destination. If the output is a terminal that supports color, it is enabled; otherwise, it is disabled. The **Default:** `auto`

When the `auto` value is selected, the [`NO_COLOR`](#user-content-fn-1)[^1] environment variable is also respected. If `NO_COLOR` is set in the environment, color output is disabled, regardless of the output destination.

### `WEKA_CLI_COLOR` environment variable usage

This environment variable can set the color output with the same possible values as the `--color` parameter (`enabled`, `disabled`, `auto`). However, if the `--color` parameter is specified, it overrides the `WEKA_CLI_COLOR` environment variable.

### CLI Boolean value aliases

The CLI supports aliases for Boolean options across all commands. This support accepts values like `yes`, `no`, `true`, `false`, `on`, `off`, `y`, or `n`. The system automatically converts these values to the internal true/false format.

Using aliases streamlines administrative operations and provides a consistent, flexible way to configure Boolean parameters. This eliminates the need to remember specific command-by-command requirements.

**Example**

The argument `<on>` accepts any of the supported Boolean aliases:

```
weka cluster container dedicate <container-id> <on>
```

Accepted values for a Boolean argument include: `yes`, `no`, `true`, `false`, `on`, `off`, `y`, or `n`.

## Cluster status

The `weka status` command displays the overall status of the WEKA cluster.

Examples:

{% tabs %}
{% tab title="1. Healthy" %}

<div data-with-frame="true"><figure><img src="/files/YZS1oA3WtPSxSYydaTAW" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="2. Partially protected" %}

<div data-with-frame="true"><figure><img src="/files/f8ApLcm5lHoZgXASpKV0" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="3. Rebuilding" %}

<div data-with-frame="true"><figure><img src="/files/Ls43O5Gba6hlRYUAgq2q" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="4. Unavailable" %}

<div data-with-frame="true"><figure><img src="/files/fpZfhHFmqd94QoBXqk8b" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}

[^1]: The `NO_COLO`R environment variable is a indicates that command-line applications should not produce any colored output. This is useful for users who prefer or require plain text output, such as in scripts or when using terminal environments that do not support colored text.


# WEKA CLI hierarchy

Explore the hierarchical structure of WEKA Command-Line Interface (CLI) commands for easy reference.

{% hint style="info" %}
CLI commands marked with two asterisks (\*\*) are new in version 5.1.21, compared to version 5.0.4.
{% endhint %}

### weka agent

```
weka agent
   |autocomplete
      |export
      |install
      |uninstall
   |install-agent
   |restart **
   |update-containers
   |uninstall
```

### **weka alerts**

```
weka alerts
   |describe
   |mute
      |add **
      |list **
      |remove **
   |types
   |unmute
```

### **weka audit**

```
weka audit
   |cluster
      |disable
      |enable
      |enhancer
         |disable
         |enable
      |resolve-paths
         |disable
         |enable
      |set-global-operations
      |stats
      |status
   |fs
      |disable
      |enable
      |set-operations
      |status
```

### **weka cloud**

```
weka cloud
   |disable
   |enable
   |proxy
   |status
   |update
   |upload-rate   
      |set
```

### weka catalog \*\*

```
weka catalog
   |cluster
      |add
      |remove
      |status
      |update
   |config
      |set
      |show
   |fs
      |disable
      |enable
      |status
   |metadata
      |delete
      |scan
      |show
```

### **weka cluster**

```
weka cluster
    |bucket
    |client-target-version
       |reset
       |set
       |show
    |container
       |activate
       |add
       |apply
       |auto-remove-timeout
       |bandwidth
       |clear-failure
       |cores
       |deactivate
       |deactivation-chec 
       |dedicate
       |failure-domain
       |info-hw
       |join-secret
       |management-ips
       |memory
       |net
          |add
          |remove
       |remove
       |requested-action
       |resources
       |restore
    |add
    |default-net
        |reset
        |set
        |update  
    |drive
        |activate
        |add
        |deactivate
        |remove
        |scan
        |identify **
    |failure-domain
    |hot-spare
    |license
        |reset
        |set
    |task
        |pause
        |resume
        |abort
        |limits
            |set
    |mount-defaults
        |reset
        |set
        |show   
    |network-space **
        |add
        |remove
        |show-usage
        |update
    |process
    |servers
        |list
        |requested-action
        |show
    |start-io
    |stop-io
    |task
        |abort
        |bucket
        |limits
        |pause
        |resume
        |throttle
    |update    
```

### weka dataservice

```
weka dataservice
    |global-config
        |set
        |show
    |s3-lifecycle-task **
        |disable
        |enable
        |set
        |show
```

### **weka diags**

```
weka diags
    |collect
    |list
    |rm
    |upload
```

### weka driver

```
weka driver
   |build
   |download
   |export
   |import
   |install
   |kernel
   |pack
   |ready
   |sign  
```

### **weka events**

```
weka events
    |list-local
    |list-types
    |trigger-event
```

### **weka fs**

```
weka fs
    |add
    |remove
    |download
    |group
        |add
        |remove
        |update
    |kms-rewrap
    |protection
        |snapshot-policy
            |attach
            |add
            |remove
            |detach
            |duplicate
            |export
            |list
            |run-once
            |show
            |update
     |quota
        |disable-users
        |enable-users
        |list
        |list-default
        |set
        |set-default
        |reset
        |unset-default
    |reserve
        |set
        |status
        |reset
    |restore
    |security
        |policy
            |attach
            |detach
            |list
            |reset
            |set
    |snapshot
        |access-point-naming-convention
            |status
            |update
        |copy
        |add
        |remove
        |download
        |update
        |upload
     |tier
        |capacity
        |fetch
        |location
        |obs
            |update
        |ops
        |release
        |s3
            |add
            |attach
            |remove
            |detach
            |snapshot
                |list
            |update
     |update    
```

### weka interface-group

```
weka interface-group
    |add
    |assignment
    |remove
    |ip-range
        |add
        |remove
    |port
        |add
        |remove
    |update
```

### **weka local**

```
weka local
    |diags
    |disable
    |drive **
       |identify
       |list
    |enable
    |events
    |extract-hostside
    |install-agent
    |monitoring
    |ps
    |reset-data
    |resources
        |apply
        |auto-remove-timeout
        |bandwidth
        |base-port
        |cores
        |dedicate
        |drive **
           |add
           |remove
           |scan
        |export
        |failure-domain
        |fqdn
        |hardware-monitor **
        |import
        |join-ips
        |join-secret
        |management-ips
        |memory       
        |net
            |add
            |remove
        |restore
    |restart
    |rm
    |run
    |setup
        |client
        |container
        |envoy
        |ssdproxy **
        |services
        |taskmon
        |telemetry
        |weka
    |start  
    |status
    |stop  
    |upgrade
```

### **weka mount**

```
weka mount
```

### **weka nfs**

```
weka nfs 
    |client-group
        |add
        |remove
    |clients
        |show
    |debug-level
        |set
        |show
    |global-config
        |set
        |show
    |interface-group
        |add
        |assignmment
        |remove
        |ip-range
            |add
            |remove
        |port
            |add
            |remove    
        |update
    |kerberos
        |registration
            |setup-ad
            |setup-mit
            |show
        |reset
        |service
            |setup
            |show
     |ldap
        |export-openldap
        |import-openldap
        |reset
        |setup-ad
        |setup-ad-nokrb
        |setup-onhostldap **
        |setup-openldap
        |show
    |permission
        |add
        |remove
        |update
    |rules
        |add
           |dns
           |ip
        |remove
           |dns
           |ip
```

### **weka s3**

```
weka s3
   |bucket
      |add
      |remove
      |etag-alg **
         |reset
         |set
      |integrity-mode **
         |set
      |lifecycle-rule
         |add
         |list
         |remove
         |reset
      |list
      |policy
         |get
         |get-json
         |set
         |set-custom
         |reset
      |quota
         |set
         |reset
      |sorting **
         |reset
         |set
   |cluster
      |audit-webhook
         |batch-config **
         |disable
         |enable
         |show
      |container
         |add
         |list
         |remove
      |add
      |remove
      |etag-alg **
         |reset
      |integrity-mode **
         |reset
      |notification-target
         |add
         |cert
            |add
            |list
            |remove
         |list
         |remove
         |show
         |status
         |update
      |performance-bucket **
      |oidc **
         |add **
         |remove **
         |show **
         |update **
      |setup **
         |show **
         |update **
      |sorting **
         |reset
      |status
      |update
         |performance-bucket **
  |policy
      |add
      |attach
      |detach
      |list
      |remove
      |show
   |service-account
      |add
      |list
      |remove
      |show
    |sts
      |assume-role
```

### **weka security**

```
weka security
   |ca-cert
      |download
      |set
      |status
      |reset
   |cors-trusted-sites
      |add
      |list
      |remove
      |remove-all
   |gui-idle-timeout **
      |restore-defaults
      |set
      |show
   |kms
      |rewrap
      |set
      |reset
   |lockout-config
      |reset
      |set
      |show
   |login-banner
      |disable
      |enable
      |reset
      |set
      |show
   |policy
      |add
      |remove
      |duplicate
      |join
          |attach
          |detach
          |list
          |reset
          |set
      |list
      |show
      |test
      |update     
   |tls
      |download
      |local
         |set
         |reset
      |set
      |status
      |reset
```

### **weka smb**

```
weka smb
   |cluster
      |container
         |add
         |remove
      |add
      |debug
      |remove
      |status
      |trusted-domains
         |add
         |remove
      |update
      |wait
   |domain
      |join
      |leave         
   |share
      |add
      |host-access
         |add
         |list
         |remove
         |reset
      |list
         |add
         |remove
         |reset
         |show
      |remove
      |update
```

### **weka stats**

```
weka stats
   |list-types
   |realtime
   |retention
      |restore-default
      |set
      |status
```

### **weka status**

```
weka status
   |rebuild
   |reduction
```

### weka telemetry <a href="#weka-telemetry" id="weka-telemetry"></a>

```
weka telemetry
   |exports
      |add
         |kafka
         |S3
         |splunk
      |attach
      |detach
      |disable
      |enable
      |list
      |remove
      |status
      |update
         |S3
         |splunk
```

### **weka** tenant \*\*

```
weka tenant
   |add
   |remove
   |network-space
      |add
      |remove
   |rename
   |security
      |policy
         |attach
         |detach
         |list
         |reset
         |set
      |revoke-tokens
   |set-qos
   |set-quota
   |update  
```

### weka umount

```
weka unmount
```

### **weka upgrade**

```
weka upgrade
   |pause
   |resume
   |supported-features
```

### **weka user**

```
weka user
   |add
   |change-role
   |remove
   |generate-token
   |ldap
      |disable
      |enable
      |refresh-imported **
      |reset
      |setup
      |setup-ad
      |update
   |login
   |logout
   |passwd
   |revoke-tokens
   |update
   |whoami
```

### **weka version**

```
weka version
   |current
   |get
   |prepare
   |rm
   |set
   |reset
```


# CLI reference guide

This CLI reference guide is generated from the output of running the weka command with the help option. It provides detailed descriptions of available commands, arguments, and options.

## weka

The base command for all weka related CLIs

```sh
weka [--color color] [--help] [--build] [--version] [--legal] [--opt-in]

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `--agent`         | Start the agent service                                                          |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`    | Show help message                                                                |
| `--build`         | Prints the CLI build number and exits                                            |
| `-v`, `--version` | Prints the CLI version and exits                                                 |
| `--legal`         | Prints software license information and exits                                    |
| `--opt-in`        | Opt in to the new CLI experience                                                 |

### weka agent

Commands that control the weka agent (outside the weka containers)

```sh
weka agent [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka agent autocomplete

Bash autocompletion utilities

```sh
weka agent autocomplete [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka agent autocomplete export**

Export bash autocompletion script

```sh
weka agent autocomplete export [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka agent autocomplete install**

Locally install bash autocompletion utility

```sh
weka agent autocomplete install [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka agent autocomplete uninstall**

Locally uninstall bash autocompletion utility

```sh
weka agent autocomplete uninstall [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka agent install-agent

Installs Weka agent on the machine the command is executed from

```sh
weka agent install-agent [--color color] [--no-update] [--no-start] [--systemd-graceful-shutdown] [--help]

```

| Parameter                     | Description                                                                      |
| ----------------------------- | -------------------------------------------------------------------------------- |
| `--color`                     | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--no-update`                 | Don't update the locally installed containers                                    |
| `--no-start`                  | Do not register the weka-agent service and start it after its creation           |
| `--systemd-graceful-shutdown` | Enable graceful shutdown via systemd                                             |
| `-h`, `--help`                | Show help message                                                                |

#### weka agent restart

Stop and start Weka agent on the server the command is executed from. If the agent is not running yet, it will be started

```sh
weka agent restart [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka agent uninstall

Deletes all Weka files, drivers, shared memory and any other remainder from the machine this command is executed from. WARNING - This action is destructive and might cause a loss of data!

```sh
weka agent uninstall [--color color] [--force] [--ignore-wekafs-mounts] [--keep-files] [--help]

```

| Parameter                | Description                                                                      |
| ------------------------ | -------------------------------------------------------------------------------- |
| `--color`                | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--force`                | Force the action to actually happen                                              |
| `--ignore-wekafs-mounts` | Proceed even with active wekafs mounts                                           |
| `--keep-files`           | Do not remove Weka version images and keep in installation directory             |
| `-h`, `--help`           | Show help message                                                                |

#### weka agent update-containers

Update the currently available containers and version specs to the current agent version. This command does not update weka, only the container's representation on the local machine.

```sh
weka agent update-containers [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

### weka alerts

List alerts in the Weka cluster

```sh
weka alerts [--severity severity]
            [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--format format]
            [--output output]...
            [--sort sort]...
            [--filter filter]...
            [--filter-color filter-color]...
            [--muted]
            [--inactive]
            [--help]
            [--no-header]
            [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                      |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--severity`              | Include event with equal and higher severity, default: WARNING (format: 'debug', 'warning', 'minor', 'major' or 'critical')                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                         |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                             |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: muted,type,severity,time,endTime,activeDuration,count,title,description,action,muteTimeRemaining,comment (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                          |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                            |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                         |
| `--muted`                 | List muted alerts alongside the unmuted ones                                                                                                                                                                     |
| `--inactive`              | List alerts that became inactive recently                                                                                                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                               |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                       |

#### weka alerts describe

Describe all the alert types that might be returned from the weka cluster (including explanations and how to handle them)

```sh
weka alerts describe [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--format format]
                     [--output output]...
                     [--sort sort]...
                     [--filter filter]...
                     [--filter-color filter-color]...
                     [--help]
                     [--no-header]
                     [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: type,title,action,severity (may be repeated or comma-separated)                                                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka alerts mute

Mute an alert-type. Muted alerts will not appear in the list of active alerts. It is required to specify a duration for the mute. Once the set duration concludes, the alert-type will automatically be unmuted.

```sh
weka alerts mute <alert-type>
                 <duration>
                 [--comment comment]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--process process]...
                 [--container container]...
                 [--hostname hostname]...
                 [--help]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `alert-type`\*            | Specifies the alert type to mute. Run `weka alerts types` to list all possible types.                                                                                                                                                                                                            |
| `duration`\*              | Sets the duration for the mute. Examples - 30m, 2h, 1d. (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                   |
| `--comment`               | Specifies a comment to provide context for the mute action.                                                                                                                                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                         |
| `--process`...            | Mutes alerts for specific process IDs. This parameter applies only to process-specific alerts. If omitted or used on a non-process alert, all alerts of this type are muted. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)       |
| `--container`...          | Mutes alerts for specific container IDs. This parameter applies only to container-specific alerts. If omitted or used on a non-container alert, all alerts of this type are muted. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated) |
| `--hostname`...           | Mutes alerts for specific server IDs. This parameter applies only to server-specific alerts. If omitted or used on a non-server alert, all alerts of this type are muted. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)          |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                |

**weka alerts mute add**

Add more items to the mute scope for an already muted alert-type. You can add more process/container/hostname items to the existing scope. Duration and comment remain unchanged.

```sh
weka alerts mute add <alert-type>
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--process process]...
                     [--container container]...
                     [--hostname hostname]...
                     [--help]

```

| Parameter                 | Description                                                                                                                                                                                                        |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `alert-type`\*            | Specifies the alert type to update mute scope for. Run `weka alerts types` to list all possible types.                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                           |
| `--process`...            | Adds more process IDs to the mute scope. This parameter applies only to process-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)     |
| `--container`...          | Adds more container IDs to the mute scope. This parameter applies only to container-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated) |
| `--hostname`...           | Adds more hostnames to the mute scope. This parameter applies only to server-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)        |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                  |

**weka alerts mute list**

List all currently muted alert types with their mute configurations

```sh
weka alerts mute list [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--help]
                      [--no-header]
                      [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: alertType,muteTimeRemaining,description,comment (may be repeated or comma-separated)                                 |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka alerts mute remove**

Remove specific items from the mute scope of an already muted alert-type. You can remove specific process/container/hostname items from the existing scope. If all items are removed, the alert will be completely unmuted.

```sh
weka alerts mute remove <alert-type>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--process process]...
                        [--container container]...
                        [--hostname hostname]...
                        [--help]

```

| Parameter                 | Description                                                                                                                                                                                                                 |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `alert-type`\*            | Specifies the alert type to remove from mute scope. Run `weka alerts types` to list all possible types.                                                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                    |
| `--process`...            | Removes specific process IDs from the mute scope. This parameter applies only to process-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)     |
| `--container`...          | Removes specific container IDs from the mute scope. This parameter applies only to container-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated) |
| `--hostname`...           | Removes specific hostnames from the mute scope. This parameter applies only to server-specific alerts. Provide a comma-separated list or repeat the parameter for multiple IDs. (may be repeated or comma-separated)        |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                           |

#### weka alerts types

List all alert types that can be returned from the Weka cluster

```sh
weka alerts types [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--help]
                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka alerts unmute

Unmute an alert-type which was previously muted.

```sh
weka alerts unmute <alert-type>
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `alert-type`\*            | An alert-type to unmute, use `weka alerts types` to list types                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka audit

Commands used for audit in a weka cluster

```sh
weka audit [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka audit cluster

Audit cluster CLI

```sh
weka audit cluster [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit cluster decrypt-filename**

Decrypt filename in audit telemetry

```sh
weka audit cluster decrypt-filename [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit cluster decrypt-filename disable**

Disable decrypting filename in audit telemetry

```sh
weka audit cluster decrypt-filename disable [--color color]
                                            [--HOST HOST]
                                            [--PORT PORT]
                                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                            [--TIMEOUT TIMEOUT]
                                            [--profile profile]
                                            [--help]
                                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster decrypt-filename enable**

Enable decrypting filename in audit telemetry

```sh
weka audit cluster decrypt-filename enable [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--help]
                                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster decrypt-fullpath**

Decrypt full file paths in audit telemetry

```sh
weka audit cluster decrypt-fullpath [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit cluster decrypt-fullpath disable**

Disable decrypting full file paths in audit telemetry

```sh
weka audit cluster decrypt-fullpath disable [--color color]
                                            [--HOST HOST]
                                            [--PORT PORT]
                                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                            [--TIMEOUT TIMEOUT]
                                            [--profile profile]
                                            [--help]
                                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster decrypt-fullpath enable**

Enable decrypting full file paths in audit telemetry

```sh
weka audit cluster decrypt-fullpath enable [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--help]
                                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster disable**

Disable audit logging cluster-wide

```sh
weka audit cluster disable [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster enable**

Enable audit logging cluster-wide

```sh
weka audit cluster enable [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster enhancer**

Audit cluster enhancer CLI

```sh
weka audit cluster enhancer [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit cluster enhancer disable**

Disable audit logging enhancement cluster-wide

```sh
weka audit cluster enhancer disable [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--help]
                                    [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster enhancer enable**

Enable audit logging enhancement cluster-wide

```sh
weka audit cluster enhancer enable [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster resolve-paths**

Resolve full file paths in audit telemetry

```sh
weka audit cluster resolve-paths [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit cluster resolve-paths disable**

Disable resolving full file paths in audit telemetry

```sh
weka audit cluster resolve-paths disable [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--help]
                                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster resolve-paths enable**

Enable resolving full file paths in audit telemetry

```sh
weka audit cluster resolve-paths enable [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]
                                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka audit cluster set-global-operations**

Define which operations to audit globally (can be 'All' or any subset)

```sh
weka audit cluster set-global-operations [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--help]
                                         [--json]
                                         [<operations>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `operations`...           | Audit operations to enable (e.g. 'All' or any from \[Open, Create, Read, ...]), replaces any previously enabled operations (format: 'none', 'open', 'create', 'read', 'modify', 'delete', 'rename', 'close', 'sessionmanagement' or 'all') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                      |

**weka audit cluster stats**

Audit logging cluster-wide stats

```sh
weka audit cluster stats [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--format format]
                         [--output output]...
                         [--sort sort]...
                         [--filter filter]...
                         [--filter-color filter-color]...
                         [--help]
                         [--raw-units]
                         [--UTC]
                         [--no-header]
                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: node,category,timestamp,stat,unit,value,containerId,container,hostname,roles (may be repeated or comma-separated)    |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka audit cluster status**

Audit logging cluster-wide status

```sh
weka audit cluster status [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka audit fs

Audit filesystems CLI

```sh
weka audit fs [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka audit fs disable**

Disable audit on a filesystem

```sh
weka audit fs disable <name>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Filesystem name                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka audit fs enable**

Enable audit on a filesystem

```sh
weka audit fs enable <name>
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Filesystem name                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka audit fs set-operations**

Override audit operations for a specific filesystem

```sh
weka audit fs set-operations <name>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]
                             [<operations>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                  |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Filesystem name                                                                                                                                                                                                                                                                              |
| `operations`...           | Audit operations to enable (e.g. 'All' or any subset of \[Open, Create, Read, Modify, Delete, Rename, Close, SessionManagement], replaces any previously enabled operations) (format: 'none', 'open', 'create', 'read', 'modify', 'delete', 'rename', 'close', 'sessionmanagement' or 'all') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                     |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                            |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                                                        |

**weka audit fs status**

List filesystems audit status

```sh
weka audit fs status [--name name]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--format format]
                     [--output output]...
                     [--sort sort]...
                     [--filter filter]...
                     [--filter-color filter-color]...
                     [--help]
                     [--raw-units]
                     [--UTC]
                     [--no-header]
                     [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Filesystem name                                                                                                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,name,audit,audit\_string (may be repeated or comma-separated)                                                 |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

### weka catalog

Manage the Data Catalog service and indexed filesystem data

```sh
weka catalog [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka catalog cluster

Manage the catalog cluster infrastructure and status

```sh
weka catalog cluster [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka catalog cluster add**

Create a catalog cluster

```sh
weka catalog cluster add <indexfs>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--containers containers]...
                         [--all-servers]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `indexfs`\*               | Name of the filesystem to store the catalog metadata                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--containers`...         | The dataservice containers that will be used to form catalog cluster (may be repeated or comma-separated)  |
| `--all-servers`           | Use all dataservice containers to form catalog cluster                                                     |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka catalog cluster remove**

Destroy the catalog cluster

```sh
weka catalog cluster remove [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--force]
                            [--json]

```

| Parameter                 | Description                                                                                                        |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)             |
| `--profile`               | Name of the connection and authentication profile to use                                                           |
| `-h`, `--help`            | Show help message                                                                                                  |
| `-f`, `--force`           | Force this action without further confirmation. This action will destroy the catalog cluster and cannot be undone. |
| `-J`, `--json`            | Format output as JSON                                                                                              |

**weka catalog cluster status**

Get catalog cluster status

```sh
weka catalog cluster status [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--format format]
                            [--output output]...
                            [--sort sort]...
                            [--filter filter]...
                            [--filter-color filter-color]...
                            [--help]
                            [--raw-units]
                            [--UTC]
                            [--no-header]
                            [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: servicename,id,hostname,container,ip,status,role (may be repeated or comma-separated)                                |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka catalog cluster update**

Update an existing catalog cluster

```sh
weka catalog cluster update [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--add-containers add-containers]...
                            [--remove-containers remove-containers]...
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--add-containers`...     | Add specific dataservice containers to the catalog cluster (may be repeated or comma-separated)            |
| `--remove-containers`...  | Remove specific dataservice containers from the catalog cluster (may be repeated or comma-separated)       |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka catalog config

Manage the configuration settings for the Data Catalog service

```sh
weka catalog config [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka catalog config show**

View the current catalog cluster settings and indexing policies

```sh
weka catalog config show [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka catalog config update**

Update catalog configuration including index policy

```sh
weka catalog config update [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--index-enabled index-enabled]
                           [--index-interval index-interval]
                           [--retention-period retention-period]
                           [--max-ingest-tasks max-ingest-tasks]
                           [--help]

```

| Parameter                 | Description                                                                                                                                                          |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                     |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                     |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                     |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                           |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                               |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                             |
| `--index-enabled`         | Enable or disable catalog indexing (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                   |
| `--index-interval`        | Index task execution interval. Default: 1 day. Supports time units: s (seconds), m (minutes), h (hours) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)       |
| `--retention-period`      | Retention period for index snapshots. Default: 30 days. Supports time units: m (minutes), h (hours), d (days) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--max-ingest-tasks`      | Maximum number of ingest tasks that can run in parallel (default: 2)                                                                                                 |
| `-h`, `--help`            | Show help message                                                                                                                                                    |

#### weka catalog fs

Manage filesystem catalog status and metadata

```sh
weka catalog fs [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka catalog fs status**

Show which filesystems have catalog enabled, which have metadata, last ingested time, and last ingest task errors

```sh
weka catalog fs status [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--help]
                       [--no-header]
                       [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,indexing,metadata,snapshots,latest,oldest,last\_ingest,error (may be repeated or comma-separated)               |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka catalog metadata

Manage catalog metadata on a per-filesystem basis

```sh
weka catalog metadata [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka catalog metadata remove**

Delete catalog metadata for a filesystem

```sh
weka catalog metadata remove <fs-name>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]
                             [--force]

```

| Parameter                 | Description                                                                                                                           |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| `fs-name`\*               | Filesystem name                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                              |
| `-h`, `--help`            | Show help message                                                                                                                     |
| `-J`, `--json`            | Format output as JSON                                                                                                                 |
| `-f`, `--force`           | Force this action without further confirmation. This action deletes all the catalog metadata for the filesystem and cannot be undone. |

**weka catalog metadata show**

Show ingestion history for a filesystem

```sh
weka catalog metadata show <fs-name>
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `fs-name`\*               | Filesystem name                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

### weka cloud

Cloud commands. List the cluster's cloud status, if no subcommand supplied.

```sh
weka cloud [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka cloud disable

Turn cloud features off

```sh
weka cloud disable [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cloud enable

Turn cloud features on

```sh
weka cloud enable [--cloud-url cloud]
                  [--cloud-stats on/off]
                  [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--help]

```

| Parameter                 | Description                                                                                                    |
| ------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--cloud-url`             | The base url of the cloud service                                                                              |
| `--cloud-stats`           | Enable or disable uploading stats to the cloud (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `--profile`               | Name of the connection and authentication profile to use                                                       |
| `-h`, `--help`            | Show help message                                                                                              |

#### weka cloud proxy

Get or set the HTTP proxy used to connect to cloud services

```sh
weka cloud proxy [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--set url]
                 [--help]
                 [--json]
                 [--unset]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-s`, `--set`             | Set a new proxy setting                                                                                    |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `-u`, `--unset`           | Remove the HTTP proxy setting                                                                              |

#### weka cloud quota-analytics

Quota analytics commands

```sh
weka cloud quota-analytics [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka cloud quota-analytics disable**

Turn quota analytics reporting off

```sh
weka cloud quota-analytics disable [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cloud quota-analytics enable**

Turn quota analytics reporting on

```sh
weka cloud quota-analytics enable [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cloud quota-analytics redact-paths**

Quota analytics path redaction commands

```sh
weka cloud quota-analytics redact-paths [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka cloud quota-analytics redact-paths off**

Turn quota analytics path redaction off

```sh
weka cloud quota-analytics redact-paths off [--color color]
                                            [--HOST HOST]
                                            [--PORT PORT]
                                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                            [--TIMEOUT TIMEOUT]
                                            [--profile profile]
                                            [--help]
                                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cloud quota-analytics redact-paths on**

Turn quota analytics path redaction on

```sh
weka cloud quota-analytics redact-paths on [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--help]
                                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cloud quota-analytics status**

Show quota analytics reporting and path redaction configuration

```sh
weka cloud quota-analytics status [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka cloud status

Show cloud connectivity status

```sh
weka cloud status [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--format format]
                  [--output output]...
                  [--sort sort]...
                  [--filter filter]...
                  [--filter-color filter-color]...
                  [--help]
                  [--no-header]
                  [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: host,health (may be repeated or comma-separated)                                                                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka cloud upload-rate

Get the cloud upload rate

```sh
weka cloud upload-rate [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--help]
                       [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cloud upload-rate set**

Set the cloud upload rate

```sh
weka cloud upload-rate set [--bytes-per-second bps]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--bytes-per-second`      | Maximum uploaded bytes per second                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka cluster

Commands that manage the cluster

```sh
weka cluster [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka cluster bucket

List the cluster buckets, logical compute units used to divide the workload in the cluster

```sh
weka cluster bucket [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--format format]
                    [--output output]...
                    [--sort sort]...
                    [--filter filter]...
                    [--filter-color filter-color]...
                    [--help]
                    [--raw-units]
                    [--UTC]
                    [--no-header]
                    [--verbose]
                    [<bucket-ids>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                         |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket-ids`...           | Only return these bucket IDs.                                                                                                                                                                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                    |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                    |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                    |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                          |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                              |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                            |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,leader,term,lastActiveTerm,state,council,previousLeader,uptime,leaderVersionSig,electableMode,sourceMembers,nonSourceMembers,fillLevel,rebuildTodo,rebuildTotal,failReason,activityFlags (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                             |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                               |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                            |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                   |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                   |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                               |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                  |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                          |

#### weka cluster client-target-version

Commands that manage the clients target version

```sh
weka cluster client-target-version [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka cluster client-target-version reset**

Clear cluster's client target version value

```sh
weka cluster client-target-version reset [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster client-target-version set**

Determine clients target version to be used in case of upgrade or a new mount (stateless client).

```sh
weka cluster client-target-version set <version-name>
                                       [--color color]
                                       [--HOST HOST]
                                       [--PORT PORT]
                                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                       [--TIMEOUT TIMEOUT]
                                       [--profile profile]
                                       [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `version-name`\*          | The version to set                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster client-target-version show**

Show clients target version to be used in case of upgrade or a new mount (stateless client).

```sh
weka cluster client-target-version show [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster container

List the cluster containers

```sh
weka cluster container [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--local]
                       [--council]
                       [--backends]
                       [--clients]
                       [--leadership]
                       [--leader]
                       [--help]
                       [--raw-units]
                       [--UTC]
                       [--no-header]
                       [--verbose]
                       [<container-ids>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `container-ids`...        | Only return these container IDs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,hostname,container,machineIdentifier,ips,status,requestedAction,software,release,mode,fd,fdName,fdType,fdId,cores,feCores,driveCores,coreIds,memory,bw,scrubberLimit,dedicated,autoRemove,leadership,uptime,failureText,failure,failureTime,failureCode,requestedActionFailureText,requestedActionFailure,requestedActionFailureTime,requestedActionFailureCode,added,cloudProvider,availabilityZone,instanceType,instanceId,hypervisorType,kernelName,kernelRelease,kernelVersion,platform,tlsStrictnessLevel,hardwareMonitoring (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `--local`                 | Get result from local weka host                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `--council`               | Get result from cluster leadership members                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `-b`, `--backends`        | Only return backend containers                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `-c`, `--clients`         | Only return client containers                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `-l`, `--leadership`      | Only return containers that are part of the cluster leadership                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `-L`, `--leader`          | Only return the cluster leader                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

**weka cluster container activate**

Activate the supplied containers, or all containers (if none supplied)

```sh
weka cluster container activate [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--no-wait]
                                [--skip-resource-validation]
                                [--skip-activate-drives]
                                [--help]
                                [<container-ids>]...

```

| Parameter                    | Description                                                                                                    |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `container-ids`...           | A list of container ids to activate                                                                            |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                               |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                               |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                               |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `--profile`                  | Name of the connection and authentication profile to use                                                       |
| `--no-wait`                  |                                                                                                                |
| `--skip-resource-validation` | Skip verifying that the cluster will still have enough RAM and SSD resources after deactivating the containers |
| `--skip-activate-drives`     | Do not activate the drives of the container                                                                    |
| `-h`, `--help`               | Show help message                                                                                              |

**weka cluster container add**

Add a container to the cluster

```sh
weka cluster container add <hostname>
                           [--ip ip]
                           [--host-fqdn host-fqdn]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--no-wait]
                           [--help]
                           [--json]
                           [--raw-units]
                           [--UTC]

```

| Parameter                 | Description                                                                                                                                        |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| `hostname`\*              | Management network hostname                                                                                                                        |
| `--ip`                    | Management IP; If both FQDN and IP are empty, the hostname is resolved; If container is highly-available or mixed-networking, use IP set '++...+'; |
| `--host-fqdn`             | Management fully qualified domain name; If both FQDN and IP are empty, hostnames will be resolved;                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                           |
| `--no-wait`               | Skip waiting for the container to be added to the cluster                                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                                  |
| `-J`, `--json`            | Format output as JSON                                                                                                                              |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                  |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                              |

**weka cluster container apply**

Apply the staged resources of the supplied containers, or all containers

```sh
weka cluster container apply [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--skip-resource-validation]
                             [--all]
                             [--force]
                             [--help]
                             [<container-ids>]...

```

| Parameter                    | Description                                                                                                                                  |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-ids`...           | A list of container ids for which to apply resources config                                                                                  |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                             |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                             |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                             |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                   |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                       |
| `--profile`                  | Name of the connection and authentication profile to use                                                                                     |
| `--skip-resource-validation` | Skip verifying that the cluster will still have enough RAM and SSD resources after deactivating the containers                               |
| `--all`                      | Apply resources on all the containers in the cluster. This will cause all backend containers in the entire cluter to restart simultaneously! |
| `-f`, `--force`              | Force this action without further confirmation.                                                                                              |
| `-h`, `--help`               | Show help message                                                                                                                            |

**weka cluster container bandwidth**

Limit weka's bandwidth for the container

```sh
weka cluster container bandwidth <container-id>
                                 <bandwidth>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]

```

| Parameter                 | Description                                                                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                                                                                                          |
| `bandwidth`\*             | New bandwidth limitation per second (format: either "unlimited" or bandwidth per second in binary or decimal values: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                                                                          |

**weka cluster container clear-failure**

Clear the last failure fields for all supplied containers

```sh
weka cluster container clear-failure [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--help]
                                     [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids for which to clear the last failure                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container cores**

Dedicate container's cores to weka

```sh
weka cluster container cores <container-id>
                             <cores>
                             [--frontend-dedicated-cores frontend-dedicated-cores]
                             [--drives-dedicated-cores drives-dedicated-cores]
                             [--compute-dedicated-cores compute-dedicated-cores]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--core-ids core-ids]...
                             [--no-frontends]
                             [--only-drives-cores]
                             [--only-compute-cores]
                             [--only-frontend-cores]
                             [--allow-mix-setting]
                             [--help]

```

| Parameter                    | Description                                                                                                     |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------- |
| `container-id`\*             | Container ID as shown in `weka cluster container`                                                               |
| `cores`\*                    | Number of CPU cores dedicated to weka - If set to 0 - no drive could be added to this container                 |
| `--frontend-dedicated-cores` | Number of cores dedicated to weka frontend (out of the total )                                                  |
| `--drives-dedicated-cores`   | Number of cores dedicated to weka drives (out of the total )                                                    |
| `--compute-dedicated-cores`  | Number of cores dedicated to weka compute (out of the total )                                                   |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)      |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)          |
| `--profile`                  | Name of the connection and authentication profile to use                                                        |
| `--core-ids`...              | Specify the ids of weka dedicated cores. (may be repeated or comma-separated)                                   |
| `--no-frontends`             | Do not create any processes with a frontend role                                                                |
| `--only-drives-cores`        | Create only processes with a drives role                                                                        |
| `--only-compute-cores`       | Create only processes with a compute role                                                                       |
| `--only-frontend-cores`      | Create only processes with a frontend role                                                                      |
| `--allow-mix-setting`        | Allow specified core-ids even if there are running containers with AUTO core-ids allocation on the same server. |
| `-h`, `--help`               | Show help message                                                                                               |

**weka cluster container deactivate**

Deactivate the supplied container(s)

```sh
weka cluster container deactivate [--allow-reduced-resilience-to allow-reduced-resilience-to]
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--no-wait]
                                  [--skip-resource-validation]
                                  [--allow-unavailable]
                                  [--help]
                                  [<container-ids>]...

```

| Parameter                       | Description                                                                                                    |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `container-ids`...              | A list of container ids to deactivate                                                                          |
| `--allow-reduced-resilience-to` | Allow deactivation even if cluster resilience would drop to this level (0 = no minimum)                        |
| `--color`                       | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                               |
| `-H`, `--HOST`                  | Specify the host. Alternatively, use the WEKA\_HOST env variable                                               |
| `-P`, `--PORT`                  | Specify the port. Alternatively, use the WEKA\_PORT env variable                                               |
| `-C`, `--CONNECT-TIMEOUT`       | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `-T`, `--TIMEOUT`               | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `--profile`                     | Name of the connection and authentication profile to use                                                       |
| `--no-wait`                     |                                                                                                                |
| `--skip-resource-validation`    | Skip verifying that the cluster will still have enough RAM and SSD resources after deactivating the containers |
| `--allow-unavailable`           | Allow the container to be unavailable while it is deactivated which skips setting its local resources          |
| `-h`, `--help`                  | Show help message                                                                                              |

**weka cluster container deactivation-check**

Check if the provided containers can be deactivated

```sh
weka cluster container deactivation-check [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]
                                          [--json]
                                          [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids for which to set flow                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cluster container dedicate**

Set the container as dedicated to weka. For example it can be rebooted whenever needed, and configured by weka for optimal performance and stability

```sh
weka cluster container dedicate <container-id>
                                <on>
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                                                           |
| `on`\*                    | Set the container as weka dedicated, off unsets container as weka dedicated (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                           |

**weka cluster container failure-domain**

Set the container failure-domain

```sh
weka cluster container failure-domain <container-id>
                                      [--name name]
                                      [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--auto]
                                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                          |
| `--name`                  | Add this container to a named failure-domain. A failure-domain will be created if it doesn't exist yet.    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--auto`                  | Set this container to be a failure-domain of its own                                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container info-hw**

Show hardware information about one or more containers

```sh
weka cluster container info-hw [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--info-type info-type]...
                               [--help]
                               [--json]
                               [--raw-units]
                               [--UTC]
                               [<hostnames>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `hostnames`...            | A list of containers to query (by hostnames or IPs). If no container is supplied, all of the cluster containers will be queried   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `--info-type`...          | Specify what information to query: version                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka cluster container join-secret**

Set secret this container will use when joining or validating other backends

```sh
weka cluster container join-secret <container-id>
                                   <secret>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                          |
| `secret`\*                | Cluster join secret                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container management-ips**

Set the container's management process IPs. Setting 2 IPs will turn this containers networking into highly-available mode

```sh
weka cluster container management-ips <container-id>
                                      [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--help]
                                      [<management-ips>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                          |
| `management-ips`...       | New IPs for the management processes                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container memory**

Dedicate a set amount of RAM to weka

```sh
weka cluster container memory <container-id>
                              <memory>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]

```

| Parameter                 | Description                                                                                                                                                                              |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                                                                                                        |
| `memory`\*                | Memory dedicated to weka in bytes, set to 0 to let the system decide (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                         |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                         |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                         |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                               |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                   |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                 |
| `-h`, `--help`            | Show help message                                                                                                                                                                        |

**weka cluster container net**

List Weka dedicated networking devices in a container

```sh
weka cluster container net [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--format format]
                           [--output output]...
                           [--sort sort]...
                           [--filter filter]...
                           [--filter-color filter-color]...
                           [--help]
                           [--raw-units]
                           [--UTC]
                           [--no-header]
                           [--verbose]
                           [<container-ids>]...

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | Container IDs to get the network devices of                                                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,name,id,host,hostname,device,ips,netmask,gateway,cores,owner,vlan,netlabel (may be repeated or comma-separated)  |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka cluster container net add**

Allocate a dedicated networking device on a container (to the cluster).

```sh
weka cluster container net add <container-id>
                               <device>
                               [--ips-type ips-type]
                               [--gateway gateway]
                               [--netmask netmask]
                               [--name name]
                               [--label label]
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--ips ips]...
                               [--rdma-off]
                               [--rdma-only]
                               [--inet6]
                               [--help]
                               [--json]
                               [--raw-units]
                               [--UTC]

```

| Parameter                 | Description                                                                                                                                                                                                  |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `container-id`\*          | The container's id                                                                                                                                                                                           |
| `device`\*                | Network device pci-slot/mac-address/interface-name(s)                                                                                                                                                        |
| `--ips-type`              | IPs type: POOL: IPs from the default data networking IP pool would be used, USER: configured by the user (format: 'pool' or 'user')                                                                          |
| `--gateway`               | Default gateway IP. In AWS this value is auto-detected, otherwise the default data networking gateway will be used.                                                                                          |
| `--netmask`               | Netmask in bits number. In AWS this value is auto-detected, otherwise the default data networking netmask will be used.                                                                                      |
| `--name`                  | If empty, a name will be auto generated.                                                                                                                                                                     |
| `--label`                 | The name of the switch or network group to which this network device is attached                                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                     |
| `--ips`...                | IPs to be allocated to cores using the device. If not given - IPs may be set automatically according the interface's IPs, or taken from the default networking IPs pool (may be repeated or comma-separated) |
| `--rdma-off`              | The device will not be used for RDMA data transfers                                                                                                                                                          |
| `--rdma-only`             | The device will be explicitly configured for RDMA                                                                                                                                                            |
| `--inet6`                 | Use IPv6 for RoCE v2 RDMA. The default is IPv4, not required and ignored for Infiniband.                                                                                                                     |
| `-h`, `--help`            | Show help message                                                                                                                                                                                            |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                        |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                            |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                        |

**weka cluster container net remove**

Undedicate a networking device in a container.

```sh
weka cluster container net remove <container-id>
                                  <name>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | The container's id                                                                                         |
| `name`\*                  | Net device name, e.g. container0net0                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container non-datapath-cores**

Set CPU cores reserved for non-datapath operations (management). Only supported when cgroups are disabled (None groups mode). Pass no core IDs to clear the list.

```sh
weka cluster container non-datapath-cores <container-id>
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--core-ids core-ids]...
                                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--core-ids`...           | CPU core IDs to reserve for non-datapath use (may be repeated or comma-separated)                          |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container remove**

Remove a container from the cluster

```sh
weka cluster container remove <container-id>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--no-wait]
                              [--no-unimprint]
                              [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | The container ID of the container to be removed                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--no-wait`               | Don't wait for the container removal to complete, return immediately                                       |
| `--no-unimprint`          | Don't remotely unimprint the container, just remove it from the cluster configuration                      |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster container requested-action**

Set the requested action of the supplied containers to one of: STOP, RESTART, APPLY\_RESOURCES to gracefully stop, restart or apply resources to the containers.

```sh
weka cluster container requested-action <requested_action>
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]
                                        [<container-ids>]...

```

| Parameter                 | Description                                                                                                        |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| `requested_action`\*      | The requested action to set the containers to (format: 'none', 'stop', 'restart', 'apply\_resources' or 'upgrade') |
| `container-ids`...        | A list of container ids for which to set flow                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)             |
| `--profile`               | Name of the connection and authentication profile to use                                                           |
| `-h`, `--help`            | Show help message                                                                                                  |

**weka cluster container resources**

Get the resources of the supplied container

```sh
weka cluster container resources <container-id>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--stable]
                                 [--help]
                                 [--json]
                                 [--raw-units]
                                 [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `container-id`\*          | Container ID as shown in `weka cluster container`                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `--stable`                | List the resources from the last successfull container boot                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka cluster container restore**

Restore staged resources of the supplied containers, or all containers, to their stable state

```sh
weka cluster container restore [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--all]
                               [--help]
                               [<container-ids>]...

```

| Parameter                 | Description                                                                                                                                  |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids for which to apply resources config                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                     |
| `--all`                   | Apply resources on all the containers in the cluster. This will cause all backend containers in the entire cluter to restart simultaneously! |
| `-h`, `--help`            | Show help message                                                                                                                            |

#### weka cluster add

Form a Weka cluster from hosts that just had Weka installed on them

```sh
weka cluster add [--admin-password admin-password]
                 [--join-secret join-secret]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--host-ips host-ips]...
                 [--host-fqdn host-fqdn]...
                 [--overwrite_resource_ips]
                 [--help]
                 [--json]
                 [<host-hostnames>]...

```

| Parameter                  | Description                                                                                                                                                                                           |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `host-hostnames`...        | A list of hostnames to be included in the new cluster                                                                                                                                                 |
| `--admin-password`         | The password for the cluster admin user; will be set to the default password if not provided                                                                                                          |
| `--join-secret`            | Initial join secret                                                                                                                                                                                   |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                      |
| `-H`, `--HOST`             | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                      |
| `-P`, `--PORT`             | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                      |
| `-C`, `--CONNECT-TIMEOUT`  | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                            |
| `-T`, `--TIMEOUT`          | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                |
| `--profile`                | Name of the connection and authentication profile to use                                                                                                                                              |
| `--host-ips`...            | Management IP addresses; If both FQDN and IPs are empty, the hostnames will be resolved; If hosts are highly-available or mixed-networking, use IP set '++...+'; (may be repeated or comma-separated) |
| `--host-fqdn`...           | Management fully qualified domain name; If both FQDNs and IPs are empty, hostnames will be resolved; (may be repeated or comma-separated)                                                             |
| `--overwrite_resource_ips` | overwrite pre-set ips in host's resource file with --host-ips set up provided by user or resolved from DNS                                                                                            |
| `-h`, `--help`             | Show help message                                                                                                                                                                                     |
| `-J`, `--json`             | Format output as JSON                                                                                                                                                                                 |

#### weka cluster default-net

List the default data networking configuration

```sh
weka cluster default-net [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]
                         [--json]
                         [--raw-units]
                         [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka cluster default-net reset**

Reset the default data networking configuration

```sh
weka cluster default-net reset [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster default-net set**

Set the default data networking configuration

```sh
weka cluster default-net set [--range range]
                             [--gateway gateway]
                             [--netmask-bits netmask-bits]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--range`                 | IP range                                                                                                   |
| `--gateway`               | Default gateway IP                                                                                         |
| `--netmask-bits`          | Subnet mask bits (0..32)                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster default-net update**

Update the default data networking configuration

```sh
weka cluster default-net update [--range range]
                                [--gateway gateway]
                                [--netmask-bits netmask-bits]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--range`                 | IP range                                                                                                   |
| `--gateway`               | Default gateway IP                                                                                         |
| `--netmask-bits`          | Subnet mask bits (0..32)                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster drive

List the cluster's drives

```sh
weka cluster drive [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--format format]
                   [--container container]...
                   [--output output]...
                   [--sort sort]...
                   [--filter filter]...
                   [--filter-color filter-color]...
                   [--show-removed]
                   [--help]
                   [--raw-units]
                   [--UTC]
                   [--no-header]
                   [--verbose]
                   [<uuids>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `uuids`...                | A list of DriveIds or UUIDs to list. If no ID is specified, all drives are listed.                                                                                                                                                                                                                                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                                                                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                                                                                        |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                                                                                            |
| `--container`...          | Only return the drives of these container IDs, if not specified, all drives are listed (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                     |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,uuid,host,hostname,node,path,size,status,stime,fdName,fdId,writable,used,nvkvused,attachment,vendor,firmware,serial,model,added,removed,block,remain,threshold,pool,drive\_status\_message,pci\_vid,pci\_id,pci\_ssvid,pci\_ssid,location,needsPhaseOut,hardDeactivate,autoEjectReason,lastFailure,lastFailureCode,lastFailureTime,fail\_reports,fail\_reporters (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                                                                                         |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                           |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                        |
| `--show-removed`          | Show drives that were removed from the cluster                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                                                                               |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                                                                                           |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

**weka cluster drive activate**

Activate the supplied drive, or all drives (if none supplied)

```sh
weka cluster drive activate [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--raw-units]
                            [--UTC]
                            [<uuids>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `uuids`...                | A list of DriveIds or UUIDs to activate. If no ID is supplied, all inactive drives will be activated.                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka cluster drive add**

Add the given drive

```sh
weka cluster drive add <container-id>
                       [--pool pool]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--force]
                       [--allow-format-non-wekafs-drives]
                       [--help]
                       [--raw-units]
                       [--UTC]
                       [--no-header]
                       [--verbose]
                       [<device-paths>]...

```

| Parameter                          | Description                                                                                                                                                                             |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `container-id`\*                   | The container the drive attached to (given by ids)                                                                                                                                      |
| `device-paths`...                  | Device paths of the drives to add, or UUIDs of partitions pre-signed by weka                                                                                                            |
| `--pool`                           | Specify disk pool to add into (format: 'auto', 'iu4k', 'iubig' or 'legacy')                                                                                                             |
| `--color`                          | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`                     | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`                     | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT`          | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`                  | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`                        | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`                   | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...                | Specify which columns to output. May include any of the following: path,uuid (may be repeated or comma-separated)                                                                       |
| `-s`, `--sort`...                  | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...                | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...                | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `--force`                          | Force formatting the drive for weka, avoiding all safety checks!                                                                                                                        |
| `--allow-format-non-wekafs-drives` | Allow reuse of drives formatted by another versions                                                                                                                                     |
| `-h`, `--help`                     | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`                | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`                      | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`                      | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`                  | Show all columns in output                                                                                                                                                              |

**weka cluster drive deactivate**

Deactivates one or more SSD drives, taking them offline.

```sh
weka cluster drive deactivate [--allow-reduced-resilience-to allow-reduced-resilience-to]
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--skip-resource-validation]
                              [--hard]
                              [--force]
                              [--help]
                              [<driveIdentifiers>]...

```

| Parameter                       | Description                                                                                                        |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| `driveIdentifiers`...           | Specifies the drive or space separated list of drives to deactivate.                                               |
| `--allow-reduced-resilience-to` | Allow deactivation even if cluster resilience would drop to this protection level (0 = no minimum)                 |
| `--color`                       | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                   |
| `-H`, `--HOST`                  | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                   |
| `-P`, `--PORT`                  | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                   |
| `-C`, `--CONNECT-TIMEOUT`       | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)         |
| `-T`, `--TIMEOUT`               | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)             |
| `--profile`                     | Name of the connection and authentication profile to use                                                           |
| `--skip-resource-validation`    | Skip verifying that the configured hot spare capacity will remain available after deactivating the drives          |
| `--hard`                        | Remove drive without phasing out                                                                                   |
| `-f`, `--force`                 | Force this action without further confirmation. This action may impact performance while the drive is phasing out. |
| `-h`, `--help`                  | Show help message                                                                                                  |

**weka cluster drive identify**

Turn a drive's identify LED on or off

```sh
weka cluster drive identify <uuid>
                            <state>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `uuid`\*                  | A DriveId or UUID to identify.                                                                             |
| `state`\*                 | Set the drive's identify LED as on or off (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster drive remove**

Remove the supplied drive(s)

```sh
weka cluster drive remove [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--force]
                          [--help]
                          [<driveIdentifiers>]...

```

| Parameter                 | Description                                                                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `driveIdentifiers`...     | Specifies the drive or a space separated list of drives to remove, identified by the system-assigned DriveId or the persistent UUID. For example: 'abcdef12-1234-abcd-1234-1234567890ab'. |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                  |
| `-f`, `--force`           | Force this action without further confirmation. To undo the removal, add the drive back and re-scan the drives on the host local to the drive.                                            |
| `-h`, `--help`            | Show help message                                                                                                                                                                         |

**weka cluster drive scan**

Scan for provisioned drives on the cluster's containers

```sh
weka cluster drive scan [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--raw-units]
                        [--UTC]
                        [<container-ids>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids to scan for drives                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

#### weka cluster failure-domain

List the Weka cluster failure domains

```sh
weka cluster failure-domain [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--format format]
                            [--output output]...
                            [--sort sort]...
                            [--filter filter]...
                            [--filter-color filter-color]...
                            [--show-removed]
                            [--help]
                            [--raw-units]
                            [--UTC]
                            [--no-header]
                            [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                   |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                       |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,fd,active\_drives,failed\_drives,total\_drives,removed\_drives,containers,total\_containers,drive\_proces,total\_drive\_proces,compute\_proces,total\_compute\_proces,capacity (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                    |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                      |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                   |
| `--show-removed`          | Show drives that were removed from the cluster                                                                                                                                                                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                          |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                          |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                      |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                         |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                 |

#### weka cluster hot-spare

Get or set the number of hot-spare failure-domains in the cluster. If param is not given, the current number of hot-spare FDs will be listed

```sh
weka cluster hot-spare [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--skip-resource-validation]
                       [--help]
                       [--json]
                       [--raw-units]
                       [--UTC]
                       [<count>]...

```

| Parameter                    | Description                                                                                                                       |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `count`...                   | The number of failure-domains                                                                                                     |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`                  | Name of the connection and authentication profile to use                                                                          |
| `--skip-resource-validation` | Skip verifying that the cluster has enough RAM and SSD resources allocated for the hot-spare                                      |
| `-h`, `--help`               | Show help message                                                                                                                 |
| `-J`, `--json`               | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`          | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`                | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

#### weka cluster license

Get information about the current license status, how much resources are being used in the cluster and whether or not your current license is valid.

```sh
weka cluster license [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--help]
                     [--json]
                     [--raw-units]
                     [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka cluster license reset**

Removes existing license information, returning the cluster to an unlicensed mode

```sh
weka cluster license reset [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster license set**

Set the cluster license

```sh
weka cluster license set <license>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `license`\*               | The new license to set to the system                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster mount-defaults

Commands for editing default mount options

```sh
weka cluster mount-defaults [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka cluster mount-defaults reset**

Reset default mount options

```sh
weka cluster mount-defaults reset [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--qos-max-throughput]
                                  [--qos-preferred-throughput]
                                  [--qos-max-ops]
                                  [--help]

```

| Parameter                    | Description                                                                                                 |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------- |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                            |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                            |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                            |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)  |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)      |
| `--profile`                  | Name of the connection and authentication profile to use                                                    |
| `--qos-max-throughput`       | qos-max-throughput is the maximum throughput allowed for the client for either receive or transmit traffic. |
| `--qos-preferred-throughput` | qos-preferred-throughput is the throughput that gets preferred state (NORMAL instead of LOW) in QoS.        |
| `--qos-max-ops`              | qos-max-ops is the maximum number of operations of any kind for the client                                  |
| `-h`, `--help`               | Show help message                                                                                           |

**weka cluster mount-defaults set**

Set default mount options.

```sh
weka cluster mount-defaults set [--qos-max-throughput qos-max-throughput]
                                [--qos-preferred-throughput qos-preferred-throughput]
                                [--qos-max-ops qos-max-ops]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]

```

| Parameter                    | Description                                                                                                 |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------- |
| `--qos-max-throughput`       | qos-max-throughput is the maximum throughput allowed for the client for either receive or transmit traffic. |
| `--qos-preferred-throughput` | qos-preferred-throughput is the throughput that gets preferred state (NORMAL instead of LOW) in QoS.        |
| `--qos-max-ops`              | qos-max-ops is the maximum number of operations of any kind for the client                                  |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                            |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                            |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                            |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)  |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)      |
| `--profile`                  | Name of the connection and authentication profile to use                                                    |
| `-h`, `--help`               | Show help message                                                                                           |

**weka cluster mount-defaults show**

View default mount options

```sh
weka cluster mount-defaults show [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--json]
                                 [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster network-space

List the cluster's network-spaces. Optionally filter by tenant.

```sh
weka cluster network-space [--tenant tenant]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--format format]
                           [--output output]...
                           [--sort sort]...
                           [--filter filter]...
                           [--filter-color filter-color]...
                           [--help]
                           [--raw-units]
                           [--UTC]
                           [--no-header]
                           [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--tenant`                | Filter by tenant name or ID                                                                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: nid,netspaceName,rangeFront,rangeEnd,vlan,gateway,netmaskBits (may be repeated or comma-separated)                   |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka cluster network-space add**

Add new Network Space and corresponding VLAN and IP Pool for BE Cluster use

```sh
weka cluster network-space add <name>
                               [--vlan vlan]
                               [--range range]
                               [--gateway gateway]
                               [--netmask-bits netmask-bits]
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | network-space name                                                                                         |
| `--vlan`                  | Vlan Id (1..4094)                                                                                          |
| `--range`                 | IP range                                                                                                   |
| `--gateway`               | Default gateway IP for the network-space.                                                                  |
| `--netmask-bits`          | Subnet mask bits (1..32) - Defaults to 16 if unspecified                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster network-space remove**

Remove a Network Space

```sh
weka cluster network-space remove <name>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--force]
                                  [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | network-space name                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Allow operation even when clients are bound to this network space.                                         |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster network-space show-usage**

Show network space IP usage. Defaults to backend containers only; use --include-clients to also show mounted clients.

```sh
weka cluster network-space show-usage [--name name]
                                      [--id id]
                                      [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--format format]
                                      [--output output]...
                                      [--sort sort]...
                                      [--filter filter]...
                                      [--filter-color filter-color]...
                                      [--backends]
                                      [--clients]
                                      [--include-clients]
                                      [--help]
                                      [--raw-units]
                                      [--UTC]
                                      [--no-header]
                                      [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | network-space name                                                                                                                                                                      |
| `--id`                    | network-space id                                                                                                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: idx,ip,hostId,containerName,hostname,device,networkLabel,proxy (may be repeated or comma-separated)                  |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-b`, `--backends`        | Only return backend containers                                                                                                                                                          |
| `-c`, `--clients`         | Only return client containers                                                                                                                                                           |
| `--include-clients`       | Also show client containers mounted on this netspace (rendered in a separate section)                                                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka cluster network-space update**

Update new Network Space and corresponding VLAN and IP Pool for BE Cluster use

```sh
weka cluster network-space update <id>
                                  [--name name]
                                  [--vlan vlan]
                                  [--range range]
                                  [--gateway gateway]
                                  [--netmask-bits netmask-bits]
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--force]
                                  [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `id`\*                    | network-space id                                                                                           |
| `--name`                  | network-space name                                                                                         |
| `--vlan`                  | Vlan Id (1..4094)                                                                                          |
| `--range`                 | IP range                                                                                                   |
| `--gateway`               | Default gateway IP for the network-space.                                                                  |
| `--netmask-bits`          | Subnet mask bits (1..32) - Defaults to 16 if unspecified                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Allow operation even when clients are bound to this network space.                                         |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster process

List the cluster processes

```sh
weka cluster process [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--format format]
                     [--container container]...
                     [--role role]...
                     [--output output]...
                     [--sort sort]...
                     [--filter filter]...
                     [--filter-color filter-color]...
                     [--local]
                     [--council]
                     [--backends]
                     [--clients]
                     [--leadership]
                     [--leader]
                     [--help]
                     [--raw-units]
                     [--UTC]
                     [--no-header]
                     [--verbose]
                     [<process-ids>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `process-ids`...          | Only return these processes IDs.                                                                                                                                                                                                                                                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                       |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                       |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                       |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                             |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                 |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                               |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                   |
| `--container`...          | Only return the processes of these container IDs, if not specified the weka-processes for all the containers will be returned (may be repeated or comma-separated)                                                                                                                                                                                                                     |
| `--role`...               | Only return processes with these roles (format: 'management', 'frontend', 'compute', 'drives' or 'dataserv', may be repeated or comma-separated)                                                                                                                                                                                                                                       |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,containerId,slot,hostname,container,ips,status,software,release,role,mode,netmode,cpuId,core,socket,numa,cpuModel,memory,uptime,fdName,fdId,traceHistory,fencingReason,joinRejectReason,failureText,failure,failureTime,failureCode,blackListingReason,blackListingTime (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                  |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                               |
| `--local`                 | Get result from local weka host                                                                                                                                                                                                                                                                                                                                                        |
| `--council`               | Get result from cluster leadership members                                                                                                                                                                                                                                                                                                                                             |
| `-b`, `--backends`        | Only return backend containers                                                                                                                                                                                                                                                                                                                                                         |
| `-c`, `--clients`         | Only return client containers                                                                                                                                                                                                                                                                                                                                                          |
| `-l`, `--leadership`      | Only return containers that are part of the cluster leadership                                                                                                                                                                                                                                                                                                                         |
| `-L`, `--leader`          | Only return the cluster leader                                                                                                                                                                                                                                                                                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                      |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                      |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                  |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                     |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                             |

#### weka cluster servers

Commands for physical servers

```sh
weka cluster servers [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka cluster servers list**

List the cluster servers

```sh
weka cluster servers list [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--format format]
                          [--role role]...
                          [--output output]...
                          [--sort sort]...
                          [--filter filter]...
                          [--filter-color filter-color]...
                          [--help]
                          [--raw-units]
                          [--UTC]
                          [--no-header]
                          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                    |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                       |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                           |
| `--role`...               | Only list machines with specified roles. Possible roles: (format: 'backend', 'client', 'nfs', 'smb' or 's3', may be repeated or comma-separated)                                                                                                               |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: hostname,uid,ip,roles,deployment\_mode,status,up\_since,cores,memory,drives,nodes,load,ready\_for\_maintenance,requested\_action,versions,architecture (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                        |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                          |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                              |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                              |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                          |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                             |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                     |

**weka cluster servers requested-action**

Set the requested action for all backend containers on the supplied servers to one of: STOP, RESTART, APPLY\_RESOURCES to gracefully stop, restart or apply resources to the backend containers on the servers.

```sh
weka cluster servers requested-action <requested_action>
                                      [--timeout timeout]
                                      [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--help]
                                      [<server-identifiers>]...

```

| Parameter                 | Description                                                                                                                        |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| `requested_action`\*      | The requested action to set for all containers on the servers (format: 'none', 'stop', 'restart', 'apply\_resources' or 'upgrade') |
| `server-identifiers`...   | A list of server identifiers (hostnames or IPs) for which to set the requested action                                              |
| `--timeout`               | Timeout for the requested action (optional) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                  |

**weka cluster servers show**

Show a single server overview according to given server uid

```sh
weka cluster servers show <uid>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--json]
                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `uid`\*                   | The Server UID                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster start-io

Start IO services

```sh
weka cluster start-io [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka cluster stop-io

Stop IO services

```sh
weka cluster stop-io [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--brutal-no-flush]
                     [--keep-external-containers]
                     [--force]
                     [--help]
                     [--json]

```

| Parameter                    | Description                                                                                                                                                                                 |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                            |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                            |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                      |
| `--profile`                  | Name of the connection and authentication profile to use                                                                                                                                    |
| `--brutal-no-flush`          | Force stopping IO services immediately without graceful flushing of ongoing operations. Using this flag may cause data-loss if used without explicit guidance from WekaIO customer support. |
| `--keep-external-containers` | Keep external containers(S3, SMB, NFS) running                                                                                                                                              |
| `-f`, `--force`              | Force this action without further confirmation. This action will disrupt operation of all connected clients. To restore IO service run 'weka cluster start-io'.                             |
| `-h`, `--help`               | Show help message                                                                                                                                                                           |
| `-J`, `--json`               | Format output as JSON                                                                                                                                                                       |

#### weka cluster task

List the currently running background tasks and their status

```sh
weka cluster task [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--format format]
                  [--output output]...
                  [--sort sort]...
                  [--filter filter]...
                  [--filter-color filter-color]...
                  [--show-waiting]
                  [--show-catalog]
                  [--help]
                  [--raw-units]
                  [--UTC]
                  [--no-header]
                  [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,type,state,phase,progress,paused,desc,time,throttle (may be repeated or comma-separated)                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `--show-waiting`          | Show waiting tasks                                                                                                                                                                      |
| `--show-catalog`          | Show catalog tasks                                                                                                                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka cluster task abort**

Abort a currently running background task

```sh
weka cluster task abort <task-id>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `task-id`\*               | Id of the task to abort                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster task bucket**

List the status of a background task on specific buckets

```sh
weka cluster task bucket [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--format format]
                         [--task task]...
                         [--bucket bucket]...
                         [--output output]...
                         [--sort sort]...
                         [--filter filter]...
                         [--filter-color filter-color]...
                         [--help]
                         [--raw-units]
                         [--UTC]
                         [--no-header]
                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `--task`...               | Only return these task IDs. (may be repeated or comma-separated)                                                                                                                        |
| `-b`, `--bucket`...       | Only return these bucket IDs. (may be repeated or comma-separated)                                                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: bucket\_id,task\_id,type,phase,progress,lastProgress,stuck,pausedAtGeneration (may be repeated or comma-separated)   |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka cluster task limits**

List the current limits for background tasks

```sh
weka cluster task limits [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka cluster task limits set**

Set the limits for background tasks

```sh
weka cluster task limits set [--cpu-limit cpu-limit]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--cpu-limit`             | Percent of the CPU resources to dedicate to background tasks (format: 0..100)                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster task pause**

Pause a currently running background task

```sh
weka cluster task pause <task-id>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `task-id`\*               | Id of the task to pause                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster task resume**

Resume a currently paused background task

```sh
weka cluster task resume <task-id>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `task-id`\*               | Id of the task to resume                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka cluster task throttle**

Slow down the rate of progress of a currently running background task

```sh
weka cluster task throttle <task-id>
                           [--throttle throttle]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `task-id`\*               | Id of the task to throttle                                                                                 |
| `--throttle`              | Percentage by which to throttle the task (between 0 and 100) (format: 0..100)                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka cluster update

Update cluster configuration

```sh
weka cluster update [--cluster-name cluster-name]
                    [--data-drives data-drives]
                    [--parity-drives parity-drives]
                    [--scrubber-bytes-per-sec scrubber-bytes-per-sec]
                    [--bucket-raft-size bucket-raft-size]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--help]

```

| Parameter                  | Description                                                                                                                                                    |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--cluster-name`           | Cluster name                                                                                                                                                   |
| `--data-drives`            | Number of RAID data drives                                                                                                                                     |
| `--parity-drives`          | Number of RAID protection parity drives                                                                                                                        |
| `--scrubber-bytes-per-sec` | Rate of RAID scrubbing in units per second (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--bucket-raft-size`       | Number of members in the buckets raft group                                                                                                                    |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                               |
| `-H`, `--HOST`             | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                               |
| `-P`, `--PORT`             | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                               |
| `-C`, `--CONNECT-TIMEOUT`  | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                     |
| `-T`, `--TIMEOUT`          | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                         |
| `--profile`                | Name of the connection and authentication profile to use                                                                                                       |
| `-h`, `--help`             | Show help message                                                                                                                                              |

### weka dataservice

Commands that manage dataservice

```sh
weka dataservice [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka dataservice global-config

Dataservice Global Configuration

```sh
weka dataservice global-config [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka dataservice global-config set**

Set Dataservice global configuration options

```sh
weka dataservice global-config set [--config-fs config-fs]
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--config-fs`             | config filesystem name, use "" to invalidate                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka dataservice global-config show**

Show the Dataservice global configuration

```sh
weka dataservice global-config show [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--help]
                                    [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka dataservice s3-lifecycle-task

Commands to manage S3 lifecycle tasks

```sh
weka dataservice s3-lifecycle-task [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka dataservice s3-lifecycle-task disable**

Disable the S3 lifecycle task manager

```sh
weka dataservice s3-lifecycle-task disable [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka dataservice s3-lifecycle-task enable**

Enable the S3 lifecycle task manager

```sh
weka dataservice s3-lifecycle-task enable [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka dataservice s3-lifecycle-task set**

Set S3 lifecycle task manager settings

```sh
weka dataservice s3-lifecycle-task set [--max-tasks max-tasks]
                                       [--interval interval]
                                       [--color color]
                                       [--HOST HOST]
                                       [--PORT PORT]
                                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                       [--TIMEOUT TIMEOUT]
                                       [--profile profile]
                                       [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--max-tasks`             | Maximum number of concurrent tasks                                                                         |
| `--interval`              | Interval between lifecycle task manager runs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka dataservice s3-lifecycle-task show**

Show S3 lifecycle task manager status and settings

```sh
weka dataservice s3-lifecycle-task show [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]
                                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

### weka diags

Diagnostics commands to help understand the status of the cluster and its environment

```sh
weka diags [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka diags collect

Collect diags from all cluster containers to a directory on the container running this command

```sh
weka diags collect [--id id]
                   [--timeout timeout]
                   [--output-dir output-dir]
                   [--core-limit core-limit]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--color color]
                   [--container-id container-id]...
                   [--clients]
                   [--backends]
                   [--tar]
                   [--verbose]
                   [--help]
                   [--raw-units]
                   [--UTC]
                   [--json]

```

| Parameter                 | Description                                                                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-i`, `--id`              | Optional ID for this dump, if not specified a random ID is generated                                                                                          |
| `-m`, `--timeout`         | How long to wait when downloading diags from all containers. Default is 10 minutes, 0 means indefinite (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-d`, `--output-dir`      | Directory to save the diags dump to, default: /opt/weka/diags                                                                                                 |
| `-c`, `--core-limit`      | Limit to processing this number of core dumps, if found (default: 1)                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                        |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                              |
| `--container-id`...       | Container IDs to collect diags from, can be used multiple times. This flag causes --clients to be ignored. (may be repeated or comma-separated)               |
| `--clients`               | Collect diags from client containers only (by default diags are only collected from backends)                                                                 |
| `--backends`              | Collect diags from backend containers (to be used in combination with --clients to collect from all containers)                                               |
| `-t`, `--tar`             | Create a TAR of all collected diags                                                                                                                           |
| `-v`, `--verbose`         | Print results of all diags, including successful ones                                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                             |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                         |
| `-J`, `--json`            | Format output as JSON                                                                                                                                         |

#### weka diags list

Prints results of a previously collected diags report

```sh
weka diags list [--color color] [--verbose] [--help] [<id>]...

```

| Parameter         | Description                                                                                                  |
| ----------------- | ------------------------------------------------------------------------------------------------------------ |
| `id`...           | ID of the dump to show or a path to the diags dump. If not specified a list of all collected diags is shown. |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                             |
| `-v`, `--verbose` | Print results of all diags, including successful ones                                                        |
| `-h`, `--help`    | Show help message                                                                                            |

#### weka diags rm

Stop a running instance of diags, and cancel its uploads.

```sh
weka diags rm [--HOST HOST]
              [--PORT PORT]
              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
              [--TIMEOUT TIMEOUT]
              [--profile profile]
              [--color color]
              [--all]
              [--help]
              [<id>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `id`...                   | ID of the diags to cancel. Must be specified unless the all option is set.                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `--all`                   | Delete all.                                                                                                |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka diags upload

Collect and upload diags from all cluster containers to Weka's support cloud

```sh
weka diags upload [--timeout timeout]
                  [--core-limit core-limit]
                  [--dump-id dump-id]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--color color]
                  [--container-id container-id]...
                  [--clients]
                  [--backends]
                  [--no-tar]
                  [--help]
                  [--json]

```

| Parameter                 | Description                                                                                                                                     |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| `-m`, `--timeout`         | How long to wait for diags to upload. Default is 10 minutes, 0 means indefinite (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)          |
| `-c`, `--core-limit`      | Limit to processing this number of core dumps, if found (default: 1)                                                                            |
| `--dump-id`               | ID of an existing dump to upload. This dump ID has to exist on this local server. If an ID is not specified, a new dump is created.             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                |
| `--container-id`...       | Container IDs to collect diags from, can be used multiple times. This flag causes --clients to be ignored. (may be repeated or comma-separated) |
| `--clients`               | Collect diags from client containers only (by default diags are only collected from backends)                                                   |
| `--backends`              | Collect diags from backend containers (to be used in combination with --clients to collect from all containers)                                 |
| `--no-tar`                | Do not tar and compress local files                                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                               |
| `-J`, `--json`            | Format output as JSON                                                                                                                           |

### weka driver

Manage Weka drivers

```sh
weka driver [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka driver build

Compiles drivers for the machine where this command is executed.

```sh
weka driver build [--color color] [--version version] [--help]

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-V`, `--version` | Weka version for drivers.                                                        |
| `-h`, `--help`    | Show help message                                                                |

#### weka driver download

Downloads drivers from a distribution server.

```sh
weka driver download [--color color] [--version version] [--kernel-signature kernel-signature] [--from from]... [--help]

```

| Parameter                  | Description                                                                                                                                                                                                                                                                                         |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                    |
| `-V`, `--version`          | Weka version for drivers.                                                                                                                                                                                                                                                                           |
| `-K`, `--kernel-signature` | Kernel signature for drivers.                                                                                                                                                                                                                                                                       |
| `--from`...                | Download from this distribution server (can be given multiple times). Otherwise distribution servers are taken from the $WEKA\_DIST\_SERVERS environment variable, the /etc/wekaio/dist-servers file, or /etc/wekaio/service.conf in that order of precedence. (may be repeated or comma-separated) |
| `-h`, `--help`             | Show help message                                                                                                                                                                                                                                                                                   |

#### weka driver export

Exports drivers from this machine to an archive.

```sh
weka driver export <path> [--color color] [--version version] [--kernel-signature kernel-signature] [--help]

```

| Parameter                  | Description                                                                      |
| -------------------------- | -------------------------------------------------------------------------------- |
| `path`\*                   | Path of the output archive, will be in .zip format.                              |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-V`, `--version`          | Weka version for drivers.                                                        |
| `-K`, `--kernel-signature` | Kernel signature for drivers.                                                    |
| `-h`, `--help`             | Show help message                                                                |

#### weka driver import

Imports drivers from a previously exported archive to this machine.

```sh
weka driver import <path> [--color color] [--overwrite] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `path`\*       | The path of the importing tar file                                               |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--overwrite`  | Overwrite existing drivers                                                       |
| `-h`, `--help` | Show help message                                                                |

#### weka driver install

Installs drivers on the machine where this command is executed.

```sh
weka driver install [--color color] [--version version] [--help]

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-V`, `--version` | Weka version for drivers.                                                        |
| `-h`, `--help`    | Show help message                                                                |

#### weka driver kernel

Shows the kernel signature of the system. This signature is used to identify the specific kernel.

```sh
weka driver kernel [--color color] [--help] [--json]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |
| `-J`, `--json` | Format output as JSON                                                            |

#### weka driver pack

Creates driver package.

```sh
weka driver pack [--color color]
                 [--version version]
                 [--kernel-signature kernel-signature]
                 [--environment environment]...
                 [--help]

```

| Parameter                  | Description                                                                      |
| -------------------------- | -------------------------------------------------------------------------------- |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-V`, `--version`          | Weka version for drivers.                                                        |
| `-K`, `--kernel-signature` | Kernel signature for drivers.                                                    |
| `-e`, `--environment`...   | Environment variable to add (may be repeated)                                    |
| `-h`, `--help`             | Show help message                                                                |

#### weka driver ready

Checks if kernel drivers are loaded and ready for Weka.

```sh
weka driver ready [--color color] [--version version] [--help] [--json] [--quiet]

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-V`, `--version` | Weka version for drivers.                                                        |
| `-h`, `--help`    | Show help message                                                                |
| `-J`, `--json`    | Format output as JSON                                                            |
| `-q`, `--quiet`   | Checks quietly (exit status 0 if drivers are ready, 1 otherwise).                |

#### weka driver sign

Signs drivers with a private key.

```sh
weka driver sign <key>
                 [cert]
                 [--hash hash]
                 [--color color]
                 [--version version]
                 [--kernel-signature kernel-signature]
                 [--pack]
                 [--help]

```

| Parameter                  | Description                                                                                                                                         |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `key`\*                    | Path to the private key file.                                                                                                                       |
| `cert`                     | Path to the certificate file.                                                                                                                       |
| `passwd`\*                 | Password for private key file. (may also be supplied by $WEKA\_SIGNING\_KEY\_PASSWORD, or in the file named by $WEKA\_SIGNING\_KEY\_PASSWORD\_FILE) |
| `--hash`                   | Hash algorithm used for signing modules. (format: 'sha256', 'sha384' or 'sha512')                                                                   |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                    |
| `-V`, `--version`          | Weka version for drivers.                                                                                                                           |
| `-K`, `--kernel-signature` | Kernel signature for drivers.                                                                                                                       |
| `--pack`                   | Sign driver package.                                                                                                                                |
| `-h`, `--help`             | Show help message                                                                                                                                   |

### weka events

List all events that conform to the filter criteria

```sh
weka events [--num-results num-results]
            [--start-time <start>]
            [--end-time <end>]
            [--severity severity]
            [--direction direction]
            [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--format format]
            [--type-list type-list]...
            [--exclude-type-list exclude-type-list]...
            [--category-list category-list]...
            [--output output]...
            [--show-internal]
            [--cloud-time]
            [--help]
            [--raw-units]
            [--UTC]
            [--no-header]
            [--verbose]

```

| Parameter                      | Description                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-n`, `--num-results`          | Get up to this number of events, default: 50                                                                                                                                                                                                                                                                                                                         |
| `--start-time`                 | Include events occurred in this time point and later (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00)                                                                                                                                                    |
| `--end-time`                   | Include events occurred not later then this time point (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00)                                                                                                                                                  |
| `--severity`                   | Include event with equal and higher severity, default: INFO (format: 'debug', 'info', 'warning', 'minor', 'major' or 'critical')                                                                                                                                                                                                                                     |
| `-d`, `--direction`            | Fetch events from the first available event (forward) or the latest created event (backward), default: backward (format: 'forward' or 'backward')                                                                                                                                                                                                                    |
| `--color`                      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                     |
| `-H`, `--HOST`                 | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                     |
| `-P`, `--PORT`                 | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                     |
| `-C`, `--CONNECT-TIMEOUT`      | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                           |
| `-T`, `--TIMEOUT`              | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                               |
| `--profile`                    | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                             |
| `-f`, `--format`               | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                 |
| `-t`, `--type-list`...         | Filter events by type, can be used multiple times (use 'weka events list-types' to see available types) (may be repeated or comma-separated)                                                                                                                                                                                                                         |
| `-x`, `--exclude-type-list`... | Remove events by type, can be used multiple times (use 'weka events list-types' to see available types) (may be repeated or comma-separated)                                                                                                                                                                                                                         |
| `-c`, `--category-list`...     | Include only events matches to the category\_list. Category can be Events, Node, Raid, Drive, ObjectStorage, System, Resources, Clustering, Network, Filesystem, Upgrade, NFS, Config, Cloud, InterfaceGroup, Tenant, User, Alerts, Licensing, Custom, Kms, Smb, Telemetry, Traces, S3, Security, Agent, Environment or Catalog (may be repeated or comma-separated) |
| `-o`, `--output`...            | Specify which columns to output. May include any of the following: time,cloudTime,node,category,severity,type,entity,desc (may be repeated or comma-separated)                                                                                                                                                                                                       |
| `-i`, `--show-internal`        | Show internal events                                                                                                                                                                                                                                                                                                                                                 |
| `-l`, `--cloud-time`           | Sort by cloud time instead of local timestamp                                                                                                                                                                                                                                                                                                                        |
| `-h`, `--help`                 | Show help message                                                                                                                                                                                                                                                                                                                                                    |
| `-R`, `--raw-units`            | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                    |
| `-U`, `--UTC`                  | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                |
| `--no-header`                  | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                   |
| `-v`, `--verbose`              | Show all columns in output                                                                                                                                                                                                                                                                                                                                           |

#### weka events list-local

List recent events that happened on the machine running this command

```sh
weka events list-local [--start-time <start>]
                       [--end-time <end>]
                       [--next next]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--stem-mode]
                       [--show-internal]
                       [--help]
                       [--raw-units]
                       [--UTC]
                       [--no-header]
                       [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                         |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--start-time`            | Include events occurred in this time point and later (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00)   |
| `--end-time`              | Include events occurred not later then this time point (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00) |
| `--next`                  | Token for the next page of events                                                                                                                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                    |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                    |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                    |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                          |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                              |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                            |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: time,category,severity,permission,type,entity,node,hash (may be repeated or comma-separated)                                                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                             |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                               |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                            |
| `--stem-mode`             | List stem mode events                                                                                                                                                                                               |
| `--show-internal`         | Show internal events                                                                                                                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                   |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                   |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                               |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                  |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                          |

#### weka events list-types

Show the event type definition information

```sh
weka events list-types [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--category category]...
                       [--type type]...
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--show-internal]
                       [--help]
                       [--no-header]
                       [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                    |
| `-c`, `--category`...     | List only the events that fall under one of the following categories: Events, Node, Raid, Drive, ObjectStorage, System, Resources, Clustering, Network, Filesystem, Upgrade, NFS, Config, Cloud, InterfaceGroup, Tenant, User, Alerts, Licensing, Custom, Kms, Smb, Telemetry, Traces, S3, Security, Agent, Environment or Catalog (may be repeated or comma-separated) |
| `-t`, `--type`...         | List only events of the specified types (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                            |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: type,category,severity,description,format,permission,parameters,dedup,dedupParams (may be repeated or comma-separated)                                                                                                                                                                               |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                 |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                |
| `--show-internal`         | Show internal events                                                                                                                                                                                                                                                                                                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                              |

#### weka events trigger-event

Trigger a custom event with a user defined parameter

```sh
weka events trigger-event <message>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `message`\*               | User defined text to trigger as the events parameter                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka fs

List filesystems defined in this Weka cluster

```sh
weka fs [--name name]
        [--color color]
        [--HOST HOST]
        [--PORT PORT]
        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
        [--TIMEOUT TIMEOUT]
        [--profile profile]
        [--format format]
        [--output output]...
        [--sort sort]...
        [--filter filter]...
        [--filter-color filter-color]...
        [--capacities]
        [--force-fresh]
        [--help]
        [--raw-units]
        [--UTC]
        [--no-header]
        [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Filesystem name                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,name,group,usedSSD,usedSSDD,usedSSDM,freeSSD,availableSSDM,availableSSD,usedTotal,usedTotalD,freeTotal,availableTotal,maxFiles,status,encrypted,stores,auth,thinProvisioned,thinProvisioningMinSSDBudget,thinProvisioningMaxSSDBudget,usedSSDWD,usedSSDRD,reductionRatio,pendingReduction,dataReduction,reducedProcessedSize,reducedSize,kmsKey,kmsNamespace,kmsRole,processedReductionRatio,dataReductionSavings,indexEnabled,permissions,ownerGuid,maxThroughput,maxIops (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                                                                                                                                                                                                   |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `--capacities`            | Display all capacity columns                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `--force-fresh`           | Refresh the capacities to make sure they are most updated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

#### weka fs add

Create a filesystem

```sh
weka fs add <name>
            <group-name>
            <total-capacity>
            [--obs-name obs-name]
            [--ssd-capacity ssd-capacity]
            [--thin-provision-min-ssd thin-provision-min-ssd]
            [--thin-provision-max-ssd thin-provision-max-ssd]
            [--audit-enabled audit-enabled]
            [--kms-key-identifier kms-key-identifier]
            [--kms-namespace kms-namespace]
            [--kms-role-id kms-role-id]
            [--kms-secret-id kms-secret-id]
            [--index-enabled index-enabled]
            [--max-throughput max-throughput]
            [--max-iops max-iops]
            [--auth-required auth-required]
            [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--encrypted]
            [--allow-no-kms]
            [--data-reduction]
            [--help]
            [--json]
            [--raw-units]
            [--UTC]

```

| Parameter                  | Description                                                                                                                                                                                                                                                               |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                   | Filesystem name                                                                                                                                                                                                                                                           |
| `group-name`\*             | Group name                                                                                                                                                                                                                                                                |
| `total-capacity`\*         | Total capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                        |
| `--obs-name`               | Object Store bucket name. Mandatory for tiered filesystems                                                                                                                                                                                                                |
| `--ssd-capacity`           | SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                          |
| `--thin-provision-min-ssd` | Thin provisioned minimum SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                 |
| `--thin-provision-max-ssd` | Thin provisioned maximum SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                 |
| `--audit-enabled`          | Enable audit logging for this filesystem. Takes effect only if audit is enabled cluster-wide (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                              |
| `--kms-key-identifier`     | Customize KMS key identifier for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                     |
| `--kms-namespace`          | Customize KMS namespace for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--kms-role-id`            | Customize KMS role-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                            |
| `--kms-secret-id`          | Customize KMS secret-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--index-enabled`          | Enable catalog indexing for this filesystem (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                               |
| `--max-throughput`         | Limit throughput per second (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                           |
| `--max-iops`               | Limit IOs/s                                                                                                                                                                                                                                                               |
| `--auth-required`          | Require the mounting user to be authenticated for mounting this filesystem. This flag is only effective in the root tenant, users in non-root tenants must be authenticated to perform a mount operation. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                          |
| `-H`, `--HOST`             | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                          |
| `-P`, `--PORT`             | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT`  | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                |
| `-T`, `--TIMEOUT`          | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                    |
| `--profile`                | Name of the connection and authentication profile to use                                                                                                                                                                                                                  |
| `--encrypted`              | Creates an encrypted filesystem                                                                                                                                                                                                                                           |
| `--allow-no-kms`           | Allow (insecurely) creating an encrypted filesystem without a KMS configured                                                                                                                                                                                              |
| `--data-reduction`         | Enable data reduction                                                                                                                                                                                                                                                     |
| `-h`, `--help`             | Show help message                                                                                                                                                                                                                                                         |
| `-J`, `--json`             | Format output as JSON                                                                                                                                                                                                                                                     |
| `-R`, `--raw-units`        | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                         |
| `-U`, `--UTC`              | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                     |

#### weka fs remove

Delete a filesystem

```sh
weka fs remove <name>
               [--color color]
               [--HOST HOST]
               [--PORT PORT]
               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
               [--TIMEOUT TIMEOUT]
               [--profile profile]
               [--purge-from-obs]
               [--force]
               [--help]

```

| Parameter                 | Description                                                                                                          |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Filesystem name                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                     |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                     |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                     |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)           |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)               |
| `--profile`               | Name of the connection and authentication profile to use                                                             |
| `--purge-from-obs`        | Delete filesystem's objects from the local writable Object Store, making all locally uploaded snapshots unusable     |
| `-f`, `--force`           | Force this action without further confirmation. This action DELETES ALL DATA in the filesystem and cannot be undone. |
| `-h`, `--help`            | Show help message                                                                                                    |

#### weka fs download

Download a filesystem from object store

```sh
weka fs download <name>
                 <group-name>
                 <total-capacity>
                 <ssd-capacity>
                 <obs-bucket>
                 <locator>
                 [--audit-enabled audit-enabled]
                 [--auth-required auth-required]
                 [--additional-obs-bucket additional-obs-bucket]
                 [--snapshot-name snapshot-name]
                 [--access-point access-point]
                 [--kms-key-identifier kms-key-identifier]
                 [--kms-namespace kms-namespace]
                 [--kms-role-id kms-role-id]
                 [--kms-secret-id kms-secret-id]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--skip-resource-validation]
                 [--help]
                 [--json]
                 [--raw-units]
                 [--UTC]

```

| Parameter                    | Description                                                                                                                                                                                                                                                               |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                     | Filesystem name                                                                                                                                                                                                                                                           |
| `group-name`\*               | Group name                                                                                                                                                                                                                                                                |
| `total-capacity`\*           | Total capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                        |
| `ssd-capacity`\*             | SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                          |
| `obs-bucket`\*               | Object Store bucket                                                                                                                                                                                                                                                       |
| `locator`\*                  | Locator                                                                                                                                                                                                                                                                   |
| `--audit-enabled`            | Enable audit logging for this filesystem. Takes effect only if audit is enabled cluster-wide (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                              |
| `--auth-required`            | Require the mounting user to be authenticated for mounting this filesystem. This flag is only effective in the root tenant, users in non-root tenants must be authenticated to perform a mount operation. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--additional-obs-bucket`    | Additional Object Store bucket                                                                                                                                                                                                                                            |
| `--snapshot-name`            | Downloaded snapshot name (default: uploaded name)                                                                                                                                                                                                                         |
| `--access-point`             | Downloaded snapshot access point (default: uploaded access-point)                                                                                                                                                                                                         |
| `--kms-key-identifier`       | Customize KMS key name for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                           |
| `--kms-namespace`            | Customize KMS namespace for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--kms-role-id`              | Customize KMS role-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                            |
| `--kms-secret-id`            | Customize KMS secret-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                          |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                          |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                    |
| `--profile`                  | Name of the connection and authentication profile to use                                                                                                                                                                                                                  |
| `--skip-resource-validation` | Skip verifying that the cluster has enough RAM and SSD resources allocated for the downloaded filesystem                                                                                                                                                                  |
| `-h`, `--help`               | Show help message                                                                                                                                                                                                                                                         |
| `-J`, `--json`               | Format output as JSON                                                                                                                                                                                                                                                     |
| `-R`, `--raw-units`          | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                         |
| `-U`, `--UTC`                | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                     |

#### weka fs group

List filesystem groups

```sh
weka fs group [--color color]
              [--HOST HOST]
              [--PORT PORT]
              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
              [--TIMEOUT TIMEOUT]
              [--profile profile]
              [--format format]
              [--output output]...
              [--sort sort]...
              [--filter filter]...
              [--filter-color filter-color]...
              [--help]
              [--raw-units]
              [--UTC]
              [--no-header]
              [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,group,name,retention,demote (may be repeated or comma-separated)                                                 |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs group add**

Create a filesystem group

```sh
weka fs group add <name>
                  [--target-ssd-retention target-ssd-retention]
                  [--start-demote start-demote]
                  [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--help]
                  [--json]
                  [--raw-units]
                  [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The filesystem group name to be created                                                                                           |
| `--target-ssd-retention`  | Period of time to keep an SSD copy of the data (format: 3s, 2h, 4m, 1d, 1d5h, 1w)                                                 |
| `--start-demote`          | Period of time to wait before copying data to the Object Store (format: 3s, 2h, 4m, 1d, 1d5h, 1w)                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs group remove**

Delete a filesystem group

```sh
weka fs group remove <name>
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The name of the filesystem group to be deleted                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka fs group update**

Update a filesystem group

```sh
weka fs group update <name>
                     [--new-name new-name]
                     [--target-ssd-retention target-ssd-retention]
                     [--start-demote start-demote]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The filesystem group name to be created                                                                    |
| `--new-name`              | Updated name of the specified filesystem group                                                             |
| `--target-ssd-retention`  | Period of time to keep an SSD copy of the data (format: 3s, 2h, 4m, 1d, 1d5h, 1w)                          |
| `--start-demote`          | Period of time to wait before copying data to the Object Store (format: 3s, 2h, 4m, 1d, 1d5h, 1w)          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka fs kms-rewrap

Rewrap the key of Filesystem

```sh
weka fs kms-rewrap <name>
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Filesystem name                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka fs protection

Commands used to manage file system protection

```sh
weka fs protection [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs protection snapshot-policy**

Snapshot policy management commands

```sh
weka fs protection snapshot-policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs protection snapshot-policy attach**

Attach existing filesystems to snapshot policy

```sh
weka fs protection snapshot-policy attach <name>
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]
                                          [--raw-units]
                                          [--UTC]
                                          [<filesystems>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The snapshot policy name                                                                                                          |
| `filesystems`...          | A list of filesystems you want to attach to the policy                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs protection snapshot-policy add**

Create a new snapshot policy

```sh
weka fs protection snapshot-policy add <name>
                                       <path>
                                       [--description description]
                                       [--enabled enabled]
                                       [--color color]
                                       [--HOST HOST]
                                       [--PORT PORT]
                                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                       [--TIMEOUT TIMEOUT]
                                       [--profile profile]
                                       [--help]
                                       [--json]
                                       [--raw-units]
                                       [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The snapshot policy name (up to 12 alphanumeric characters, hyphens (-), underscores (\_), and periods (.))                       |
| `path`\*                  | The path to the snapshot policy file, must be in JSON format                                                                      |
| `--description`           | Policy description (up to 128 characters)                                                                                         |
| `--enabled`               | Set snapshot policy status, can be true/false , default is true (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs protection snapshot-policy remove**

Delete a snapshot policy

```sh
weka fs protection snapshot-policy remove <name>
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--force]
                                          [--help]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Existing snapshot policy name                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `-f`, `--force`           | Force this action without further confirmation. This action deletes the snapshot policy and cannot be undone. |
| `-h`, `--help`            | Show help message                                                                                             |

**weka fs protection snapshot-policy detach**

Detach existing filesystems from the snapshot policy

```sh
weka fs protection snapshot-policy detach <name>
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--remove-waiting-tasks]
                                          [--help]
                                          [--raw-units]
                                          [--UTC]
                                          [--force]
                                          [<filesystems>]...

```

| Parameter                 | Description                                                                                                                           |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The snapshot policy name                                                                                                              |
| `filesystems`...          | A list of filesystems you want to detach from the policy                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                              |
| `--remove-waiting-tasks`  | Allow to delete all waiting tasks corresponding to the filesystems.                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                     |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.     |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                 |
| `-f`, `--force`           | Force this action without further confirmation. This action detach existing filesystem from the snapshot policy and cannot be undone. |

**weka fs protection snapshot-policy duplicate**

Duplicates an existing snapshot policy, creating a new one.

```sh
weka fs protection snapshot-policy duplicate <policyName>
                                             <name>
                                             [--description description]
                                             [--include-attached-filesystems include-attached-filesystems]
                                             [--color color]
                                             [--HOST HOST]
                                             [--PORT PORT]
                                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                             [--TIMEOUT TIMEOUT]
                                             [--profile profile]
                                             [--help]
                                             [--json]

```

| Parameter                        | Description                                                                                                               |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| `policyName`\*                   | Name of the snapshot policy to duplicate.                                                                                 |
| `name`\*                         | Name of the new snapshot policy. (up to 12 alphanumeric characters, hyphens (-), underscores (\_), and periods (.))       |
| `--description`                  | Policy description (up to 128 characters)                                                                                 |
| `--include-attached-filesystems` | Define whether or not to include the attached filesystems (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                          |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                          |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                          |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                    |
| `--profile`                      | Name of the connection and authentication profile to use                                                                  |
| `-h`, `--help`                   | Show help message                                                                                                         |
| `-J`, `--json`                   | Format output as JSON                                                                                                     |

**weka fs protection snapshot-policy export**

Export snapshot policy configuration, use policy sys-default to export the cluster default configuration

```sh
weka fs protection snapshot-policy export <name>
                                          <path>
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | The snapshot policy you want to export                                                                     |
| `path`\*                  | The path where export policy file will be located                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka fs protection snapshot-policy list**

List snapshot policies

```sh
weka fs protection snapshot-policy list [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--format format]
                                        [--output output]...
                                        [--sort sort]...
                                        [--filter filter]...
                                        [--filter-color filter-color]...
                                        [--help]
                                        [--raw-units]
                                        [--UTC]
                                        [--no-header]
                                        [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,name,enable,description,filesystems (may be repeated or comma-separated)                                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs protection snapshot-policy run-once**

Runs the snapshot policy schedule once immediately.

```sh
weka fs protection snapshot-policy run-once <name>
                                            <schedule-type>
                                            [--color color]
                                            [--HOST HOST]
                                            [--PORT PORT]
                                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                            [--TIMEOUT TIMEOUT]
                                            [--profile profile]
                                            [--help]
                                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Name of the snapshot policy                                                                                |
| `schedule-type`\*         | Schedule type to be run once (format: 'periodic', 'hourly', 'daily', 'weekly' or 'monthly')                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka fs protection snapshot-policy show**

Show snapshot policy configuration

```sh
weka fs protection snapshot-policy show <name>
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]
                                        [--raw-units]
                                        [--UTC]
                                        [--json]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Policy name                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |
| `-J`, `--json`            | Format output as JSON                                                                                                             |

**weka fs protection snapshot-policy update**

Update a snapshot policy

```sh
weka fs protection snapshot-policy update <name>
                                          [--new-name new-name]
                                          [--description description]
                                          [--path path]
                                          [--enabled enabled]
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Existing snapshot policy name                                                                                 |
| `--new-name`              | New policy name (up to 12 alphanumeric characters, hyphens (-), underscores (\_), and periods (.))            |
| `--description`           | New policy description (up to 128 characters)                                                                 |
| `--path`                  | The path to the new/modified snapshot policy file, must be in JSON format                                     |
| `--enabled`               | Set snapshot policy status, can be true/false (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `-h`, `--help`            | Show help message                                                                                             |

#### weka fs quota

Commands used to control directory quotas

```sh
weka fs quota [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs quota disable-users**

Disable user quota accounting for a filesystem

```sh
weka fs quota disable-users <filesystem>
                            [--snap-name snap-name]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name                                                                                            |
| `--snap-name`             | Optional snapshot name                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka fs quota enable-users**

Enable user quota accounting for a filesystem

```sh
weka fs quota enable-users <filesystem>
                           [--snap-name snap-name]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--force]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name                                                                                            |
| `--snap-name`             | Optional snapshot name                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Skip version compatibility checks                                                                          |
| `-h`, `--help`            | Show help message                                                                                          |

**weka fs quota list**

List filesystem quotas (directory, user, or group quotas, by default only exceeding directory quotas)

```sh
weka fs quota list [filesystem]
                   [--snap-name snap-name]
                   [--type type]
                   [--path path]
                   [--under under]
                   [--over over]
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--format format]
                   [--output output]...
                   [--sort sort]...
                   [--filter filter]...
                   [--filter-color filter-color]...
                   [--all]
                   [--quick]
                   [--help]
                   [--raw-units]
                   [--UTC]
                   [--no-header]
                   [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                  |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `filesystem`              | Filesystem name                                                                                                                                                                                              |
| `--snap-name`             | Optional snapshot name                                                                                                                                                                                       |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                                                                                                                  |
| `-p`, `--path`            | Show this path only                                                                                                                                                                                          |
| `-u`, `--under`           | List under (and including) this path only                                                                                                                                                                    |
| `--over`                  | Show only quotas over this percentage of usage (format: 0..100)                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                     |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                         |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: quotaId,name,path,used,dblk,mblk,soft,hard,usage,owner,grace\_seconds,time\_over\_soft\_limit,status (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                      |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                        |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                     |
| `--all`                   | Show all (not only exceeding) quotas                                                                                                                                                                         |
| `-q`, `--quick`           | Skip resolving inodes to paths                                                                                                                                                                               |
| `-h`, `--help`            | Show help message                                                                                                                                                                                            |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                            |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                        |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                           |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                   |

**weka fs quota list-default**

List filesystem default quotas

```sh
weka fs quota list-default [filesystem]
                           [--snap-name snap-name]
                           [--path path]
                           [--type type]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--format format]
                           [--output output]...
                           [--sort sort]...
                           [--filter filter]...
                           [--filter-color filter-color]...
                           [--help]
                           [--raw-units]
                           [--UTC]
                           [--no-header]
                           [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`              | Filesystem name                                                                                                                                                                         |
| `--snap-name`             | Optional snapshot name                                                                                                                                                                  |
| `-p`, `--path`            | Show this path only                                                                                                                                                                     |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: inodeId,fs,name,path,soft,hard,owner,grace (may be repeated or comma-separated)                                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs quota set**

Set a directory quota in a filesystem

```sh
weka fs quota set [path]
                  [--type type]
                  [--id id]
                  [--soft soft]
                  [--hard hard]
                  [--grace grace]
                  [--owner owner]
                  [--name name]
                  [--filesystem filesystem]
                  [--snap-name snap-name]
                  [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--help]
                  [--json]

```

| Parameter                 | Description                                                                                                                                                          |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `path`                    | Path in the filesystem                                                                                                                                               |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                                                                          |
| `--id`                    | user or group ID                                                                                                                                                     |
| `--soft`                  | Soft limit for the directory, or 0 for unlimited (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--hard`                  | Hard limit for the directory, or 0 for unlimited (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--grace`                 | Soft limit grace period (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                       |
| `--owner`                 | Quota owner (e.g., email)                                                                                                                                            |
| `--name`                  | Quota name (filesystem-unique label)                                                                                                                                 |
| `--filesystem`            | Filesystem name                                                                                                                                                      |
| `--snap-name`             | Name of the writable snapshot                                                                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                     |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                     |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                     |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                           |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                               |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                                                    |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                |

**weka fs quota set-default**

Set a default quota in a filesystem

```sh
weka fs quota set-default [path]
                          [--type type]
                          [--soft soft]
                          [--hard hard]
                          [--grace grace]
                          [--owner owner]
                          [--name name]
                          [--filesystem filesystem]
                          [--snap-name snap-name]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `path`                    | Path in the filesystem (required for directory type)                                                                           |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                                    |
| `--soft`                  | Soft limit (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--hard`                  | Hard limit (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--grace`                 | Soft limit grace period (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                 |
| `--owner`                 | Quota owner (e.g., email)                                                                                                      |
| `--name`                  | Quota name (filesystem-unique label)                                                                                           |
| `--filesystem`            | Filesystem name (required for user/group type)                                                                                 |
| `--snap-name`             | Name of the writable snapshot                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |

**weka fs quota reset**

Unsets a directory quota in a filesystem

```sh
weka fs quota reset [path]
                    [--type type]
                    [--id id]
                    [--generation generation]
                    [--filesystem filesystem]
                    [--snap-name snap-name]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--help]
                    [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `path`                    | Path in the filesystem                                                                                     |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                |
| `--id`                    | user or group ID                                                                                           |
| `--generation`            | Remove a specific generation of quota                                                                      |
| `--filesystem`            | Filesystem name                                                                                            |
| `--snap-name`             | Name of the writable snapshot                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka fs quota unset-default**

Unsets a default quota in a filesystem

```sh
weka fs quota unset-default [path]
                            [--type type]
                            [--filesystem filesystem]
                            [--snap-name snap-name]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `path`                    | Path in the filesystem (required for directory type)                                                       |
| `--type`                  | Quota type: 'directory', 'user', or 'group'                                                                |
| `--filesystem`            | Filesystem name (required for user/group type)                                                             |
| `--snap-name`             | Name of the writable snapshot                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka fs reserve

Thin provisioning reserve for tenants

```sh
weka fs reserve [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs reserve set**

Set a tenant's thin provisioning SSD reserve

```sh
weka fs reserve set <ssd-capacity>
                    [--tenant tenant]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--help]
                    [--json]
                    [--raw-units]
                    [--UTC]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `ssd-capacity`\*          | SSD capacity to reserve (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--tenant`                | Tenant name or ID                                                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                           |
| `-J`, `--json`            | Format output as JSON                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.           |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                       |

**weka fs reserve status**

Thin provisioning reserve for tenants

```sh
weka fs reserve status [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--help]
                       [--raw-units]
                       [--UTC]
                       [--no-header]
                       [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,name,ssdReserve (may be repeated or comma-separated)                                                              |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs reserve reset**

Unset a tenant's thin provisioning SSD's reserve

```sh
weka fs reserve reset [--tenant tenant]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]
                      [--raw-units]
                      [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--tenant`                | Tenant name or ID                                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

#### weka fs restore

Restore filesystem content from a snapshot

```sh
weka fs restore <filesystem>
                <source-name>
                [--preserved-overwritten-snapshot-name preserved-overwritten-snapshot-name]
                [--preserved-overwritten-snapshot-access-point preserved-overwritten-snapshot-access-point]
                [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--force]
                [--help]
                [--json]

```

| Parameter                                       | Description                                                                                                                                            |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `filesystem`\*                                  | The name of the filesystem to be restored                                                                                                              |
| `source-name`\*                                 | The name of the source snapshot                                                                                                                        |
| `--preserved-overwritten-snapshot-name`         | Name of a snapshot to create with the old content of the filesystem                                                                                    |
| `--preserved-overwritten-snapshot-access-point` | Access point of the preserved overwritten snapshot                                                                                                     |
| `--color`                                       | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                       |
| `-H`, `--HOST`                                  | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                       |
| `-P`, `--PORT`                                  | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                       |
| `-C`, `--CONNECT-TIMEOUT`                       | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                             |
| `-T`, `--TIMEOUT`                               | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                 |
| `--profile`                                     | Name of the connection and authentication profile to use                                                                                               |
| `-f`, `--force`                                 | Force this action without further confirmation. This action replaces all data in the filesystem with the content of the snapshot and cannot be undone. |
| `-h`, `--help`                                  | Show help message                                                                                                                                      |
| `-J`, `--json`                                  | Format output as JSON                                                                                                                                  |

#### weka fs security

Manage filesystem security

```sh
weka fs security [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs security policy**

Manages filesystem security policies.

```sh
weka fs security policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs security policy attach**

Attaches new security policies to a filesystem, adding them to the existing policies.

```sh
weka fs security policy attach <filesystem>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]
                               [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name.                                                                                           |
| `policies`...             | Security policies to add for filesystem.                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka fs security policy detach**

Removes security policies from a filesystem.

```sh
weka fs security policy detach <filesystem>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]
                               [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name.                                                                                           |
| `policies`...             | Security policies to remove from filesystem.                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka fs security policy list**

Lists filesystem security policies.

```sh
weka fs security policy list <filesystem>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--format format]
                             [--output output]...
                             [--sort sort]...
                             [--filter filter]...
                             [--filter-color filter-color]...
                             [--help]
                             [--raw-units]
                             [--UTC]
                             [--no-header]
                             [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name.                                                                                                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: position,uid,id,name (may be repeated or comma-separated)                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs security policy reset**

Removes all security policies from a filesystem.

```sh
weka fs security policy reset <filesystem>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name.                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka fs security policy set**

Sets security policies for a filesystem, replacing the existing list of policies.

```sh
weka fs security policy set <filesystem>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]
                            [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Filesystem name.                                                                                           |
| `policies`...             | Security Policies to set for filesystem.                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka fs snapshot

List snapshots

```sh
weka fs snapshot [--filesystem filesystem]
                 [--name name]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--format format]
                 [--output output]...
                 [--sort sort]...
                 [--filter filter]...
                 [--filter-color filter-color]...
                 [--help]
                 [--raw-units]
                 [--UTC]
                 [--no-header]
                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--filesystem`            | Filesystem name                                                                                                                                                                                                                                                                                                                                                                                                    |
| `--name`                  | Snapshot name                                                                                                                                                                                                                                                                                                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                           |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                               |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,filesystem,name,access,writeable,created,local\_upload\_size,remote\_upload\_size,local\_object\_status,local\_object\_progress,local\_object\_locator,remote\_object\_status,remote\_object\_progress,remote\_object\_locator,removing,prefetched,est\_reclaimable\_size,metadata\_size,dependants (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                            |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                              |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                  |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                              |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                 |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                         |

**weka fs snapshot access-point-naming-convention**

Access point naming convention

```sh
weka fs snapshot access-point-naming-convention [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs snapshot access-point-naming-convention status**

Show access point naming convention

```sh
weka fs snapshot access-point-naming-convention status [--color color]
                                                       [--HOST HOST]
                                                       [--PORT PORT]
                                                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                                       [--TIMEOUT TIMEOUT]
                                                       [--profile profile]
                                                       [--help]
                                                       [--json]
                                                       [--raw-units]
                                                       [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs snapshot access-point-naming-convention update**

Update access point naming convention

```sh
weka fs snapshot access-point-naming-convention update <access-point-naming-convention>
                                                       [--color color]
                                                       [--HOST HOST]
                                                       [--PORT PORT]
                                                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                                       [--TIMEOUT TIMEOUT]
                                                       [--profile profile]
                                                       [--help]

```

| Parameter                          | Description                                                                                                |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `access-point-naming-convention`\* | access point naming configuration (format: 'date' or 'name')                                               |
| `--color`                          | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`                     | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`                     | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT`          | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`                  | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`                        | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`                     | Show help message                                                                                          |

**weka fs snapshot copy**

Copy one snapshot over another

```sh
weka fs snapshot copy <filesystem>
                      <source-name>
                      <destination-name>
                      [--preserved-overwritten-snapshot-name preserved-overwritten-snapshot-name]
                      [--preserved-overwritten-snapshot-access-point preserved-overwritten-snapshot-access-point]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]
                      [--raw-units]
                      [--UTC]

```

| Parameter                                       | Description                                                                                                                       |
| ----------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*                                  | Source filesystem name                                                                                                            |
| `source-name`\*                                 | Source snapshot name                                                                                                              |
| `destination-name`\*                            | Destination snapshot name                                                                                                         |
| `--preserved-overwritten-snapshot-name`         | Name of a snapshot to create with the old content of the destination                                                              |
| `--preserved-overwritten-snapshot-access-point` | Access point of the preserved overwritten snapshot                                                                                |
| `--color`                                       | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`                                  | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`                                  | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT`                       | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`                               | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`                                     | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`                                  | Show help message                                                                                                                 |
| `-J`, `--json`                                  | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`                             | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`                                   | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs snapshot add**

Create a snapshot

```sh
weka fs snapshot add <filesystem>
                     <name>
                     [--access-point access-point]
                     [--source-snapshot source-snapshot]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--format format]
                     [--output output]...
                     [--sort sort]...
                     [--filter filter]...
                     [--filter-color filter-color]...
                     [--is-writable]
                     [--help]
                     [--raw-units]
                     [--UTC]
                     [--no-header]
                     [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Source filesystem name                                                                                                                                                                  |
| `name`\*                  | Target snapshot name                                                                                                                                                                    |
| `--access-point`          | Access point                                                                                                                                                                            |
| `--source-snapshot`       | Source snapshot                                                                                                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,name,access,writeable,created (may be repeated or comma-separated)                                                |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `--is-writable`           | Writable                                                                                                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs snapshot remove**

Delete a snapshot

```sh
weka fs snapshot remove <filesystem>
                        <name>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--force]
                        [--help]

```

| Parameter                 | Description                                                                                                               |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Source filesystem name                                                                                                    |
| `name`\*                  | Snapshot name                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                  |
| `-f`, `--force`           | Force this action without further confirmation. This action deletes all data stored by the snapshot and cannot be undone. |
| `-h`, `--help`            | Show help message                                                                                                         |

**weka fs snapshot download**

Download a snapshot into an existing filesystem

```sh
weka fs snapshot download <filesystem>
                          <locator>
                          [--name name]
                          [--access-point access-point]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--allow-non-chronological]
                          [--allow-divergence]
                          [--help]
                          [--json]
                          [--raw-units]
                          [--UTC]

```

| Parameter                   | Description                                                                                                                       |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*              | Filesystem name                                                                                                                   |
| `locator`\*                 | Locator                                                                                                                           |
| `--name`                    | Snapshot name (default: uploaded name)                                                                                            |
| `--access-point`            | Access point (default: uploaded access point)                                                                                     |
| `--color`                   | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`              | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`              | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT`   | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`           | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`                 | Name of the connection and authentication profile to use                                                                          |
| `--allow-non-chronological` | Allow downloading snapshots in non-chronological order. This is not recommended, as it will incur high data overhead.             |
| `--allow-divergence`        | Allow downloading snapshots which are not descendants of the last downloaded snapshot.                                            |
| `-h`, `--help`              | Show help message                                                                                                                 |
| `-J`, `--json`              | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`         | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`               | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs snapshot update**

Update snapshot parameters

```sh
weka fs snapshot update <filesystem>
                        <name>
                        [--new-name new-name]
                        [--access-point access-point]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--json]
                        [--raw-units]
                        [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Source filesystem name                                                                                                            |
| `name`\*                  | Snapshot name                                                                                                                     |
| `--new-name`              | Updated snapshot name                                                                                                             |
| `--access-point`          | Access point                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs snapshot upload**

Upload a snapshot to object store

```sh
weka fs snapshot upload <filesystem>
                        <snapshot>
                        [--site site]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--allow-non-chronological]
                        [--help]
                        [--json]
                        [--raw-units]
                        [--UTC]

```

| Parameter                   | Description                                                                                                                                |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| `filesystem`\*              | Filesystem name                                                                                                                            |
| `snapshot`\*                | Snapshot name                                                                                                                              |
| `--site`                    | The site of the Object Store to upload to (format: 'local' or 'remote')                                                                    |
| `--color`                   | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                           |
| `-H`, `--HOST`              | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                           |
| `-P`, `--PORT`              | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                           |
| `-C`, `--CONNECT-TIMEOUT`   | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                 |
| `-T`, `--TIMEOUT`           | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                     |
| `--profile`                 | Name of the connection and authentication profile to use                                                                                   |
| `--allow-non-chronological` | Allow uploading snapshots to remote object-store in non-chronological order. This is not recommended, as it will incur high data overhead. |
| `-h`, `--help`              | Show help message                                                                                                                          |
| `-J`, `--json`              | Format output as JSON                                                                                                                      |
| `-R`, `--raw-units`         | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.          |
| `-U`, `--UTC`               | Print times in UTC. When not set, times are converted to the local time of this host.                                                      |

#### weka fs tier

Show object store connectivity for each node in the cluster

```sh
weka fs tier [--color color]
             [--HOST HOST]
             [--PORT PORT]
             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
             [--TIMEOUT TIMEOUT]
             [--profile profile]
             [--format format]
             [--output output]...
             [--sort sort]...
             [--filter filter]...
             [--filter-color filter-color]...
             [--help]
             [--raw-units]
             [--UTC]
             [--no-header]
             [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: obsBucket,statusUpload,statusDownload,statusRemove,nodesDown,errors (may be repeated or comma-separated)             |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs tier capacity**

List capacities for object store buckets attached to filesystems

```sh
weka fs tier capacity [--filesystem filesystem]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--force-fresh]
                      [--help]
                      [--raw-units]
                      [--UTC]
                      [--no-header]
                      [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--filesystem`            | Filesystem name                                                                                                                                                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                  |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: fsUid,fsName,bucketUid,bucketName,totalConsumedCapacity,UsedCapacity,reclaimable,reclaimableLowThreshold,reclaimableHighThreshold (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                   |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                     |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                  |
| `--force-fresh`           | Refresh the capacities to make sure they are most updated                                                                                                                                                                                 |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                         |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                         |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                     |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                        |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                |

**weka fs tier fetch**

Fetch object-stored files to SSD storage

```sh
weka fs tier fetch [--non-existing non-existing]
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--verbose]
                   [--help]
                   [--raw-units]
                   [--UTC]
                   [<path>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `path`...                 | A file path to fetch to SSD storage. Multiple paths can be passed, e.g. \`find ...                                                |
| `--non-existing`          | Behavior for non-existing files (default: error) (format: 'error', 'warn' or 'ignore')                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-v`, `--verbose`         | Verbose output, showing fetch requests as they are submitted                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs tier location**

Show data storage location for a given path

```sh
weka fs tier location <path>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--help]
                      [--raw-units]
                      [--UTC]
                      [--no-header]
                      [--verbose]
                      [<paths>]...

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `path`\*                  | Path to get information about                                                                                                                                                           |
| `paths`...                | Extra paths to get information about                                                                                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: path,type,size,ssdWrite,ssdRead,obsBytes,remoteBytes,remoteClusterBytes (may be repeated or comma-separated)         |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka fs tier obs**

List object stores configuration and status

```sh
weka fs tier obs [--name name]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--format format]
                 [--output output]...
                 [--sort sort]...
                 [--filter filter]...
                 [--filter-color filter-color]...
                 [--help]
                 [--raw-units]
                 [--UTC]
                 [--no-header]
                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Name of the Object Store                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                                                       |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                                                           |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,name,site,bucketsCount,uploadBucketsUp,downloadBucketsUp,removeBucketsUp,protocol,hostname,port,auth,region,access,secret,downloadBandwidth,uploadBandwidth,remove3Bandwidth,downloads,uploads,removals,maxUploadExtents,maxUploadSize,enableUploadTags,maxUploadRam,stsOperationType,stsRoleArn,stsRoleSessionName,stsDuration (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                                                        |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                          |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                                              |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                                                          |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                                             |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                                                     |

**weka fs tier obs update**

Edit an existing object store

```sh
weka fs tier obs update <name>
                        [--new-name new-name]
                        [--hostname hostname]
                        [--port port]
                        [--protocol protocol]
                        [--auth-method auth-method]
                        [--region region]
                        [--access-key-id access-key-id]
                        [--secret-key secret-key]
                        [--bandwidth bandwidth]
                        [--download-bandwidth download-bandwidth]
                        [--upload-bandwidth upload-bandwidth]
                        [--remove-bandwidth remove-bandwidth]
                        [--max-concurrent-downloads max-concurrent-downloads]
                        [--max-concurrent-uploads max-concurrent-uploads]
                        [--max-concurrent-removals max-concurrent-removals]
                        [--max-extents-in-data-blob max-extents-in-data-blob]
                        [--max-data-blob-size max-data-blob-size]
                        [--upload-memory-limit upload-memory-limit]
                        [--enable-upload-tags enable-upload-tags]
                        [--sts-operation-type sts-operation-type]
                        [--sts-role-arn sts-role-arn]
                        [--sts-role-session-name sts-role-session-name]
                        [--sts-session-duration sts-session-duration]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--raw-units]
                        [--UTC]

```

| Parameter                       | Description                                                                                                                                                                                        |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                        | Name of the Object Store                                                                                                                                                                           |
| `--new-name`                    | New name                                                                                                                                                                                           |
| `--hostname`                    | Hostname (or IP) of the entrypoint to the bucket                                                                                                                                                   |
| `--port`                        | Port of the entrypoint to S3 (single Accesser or Load-Balancer)                                                                                                                                    |
| `--protocol`                    | One of: HTTP (default), HTTPS, HTTPS\_UNVERIFIED                                                                                                                                                   |
| `--auth-method`                 | Authentication method. S3AuthMethod can be None, AWSSignature2 or AWSSignature4                                                                                                                    |
| `--region`                      | Name of the region we are assigned to work with (usually empty)                                                                                                                                    |
| `--access-key-id`               | Access Key ID for AWS Signature authentications                                                                                                                                                    |
| `--secret-key`                  | Secret Key for AWS Signature authentications                                                                                                                                                       |
| `--bandwidth`                   | Bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                                                       |
| `--download-bandwidth`          | Download bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                                              |
| `--upload-bandwidth`            | Upload bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                                                |
| `--remove-bandwidth`            | Remove bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                                                |
| `--max-concurrent-downloads`    | Maximum number of downloads we concurrently perform on this object store in a single IO node (format: 1..64)                                                                                       |
| `--max-concurrent-uploads`      | Maximum number of uploads we concurrently perform on this object store in a single IO node (format: 1..64)                                                                                         |
| `--max-concurrent-removals`     | Maximum number of removals we concurrently perform on this object store in a single IO node (format: 1..64)                                                                                        |
| `--max-extents-in-data-blob`    | Maximum number of extents' data to upload to an object store data blob                                                                                                                             |
| `--max-data-blob-size`          | Maximum size to upload to an object store data blob (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                            |
| `--upload-memory-limit`         | Maximum RAM to allocate for concurrent uploads to this object store (per node) (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--enable-upload-tags`          | Enable tagging of uploaded objects (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                 |
| `--sts-operation-type`          | AWS STS operation type to use. Default: none (format: 'assume\_role' or 'none')                                                                                                                    |
| `--sts-role-arn`                | The Amazon Resource Name (ARN) of the role to assume. Mandatory when setting sts-operation to ASSUME\_ROLE                                                                                         |
| `--sts-role-session-name`       | An identifier for the assumed role session. Length constraints: Minimum length of 2, maximum length of 64.                                                                                         |
| `owed characters: upper and lo` | wer-case alphanumeric characters with no spaces.                                                                                                                                                   |

**weka fs tier ops**

List all the operations currently running on an object store from all the hosts in the cluster

```sh
weka fs tier ops [name]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--format format]
                 [--output output]...
                 [--sort sort]...
                 [--filter filter]...
                 [--filter-color filter-color]...
                 [--help]
                 [--raw-units]
                 [--UTC]
                 [--no-header]
                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`                    | Name of the Object Store bucket                                                                                                                                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                        |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                      |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                          |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: node,obsBucket,key,type,execution,phase,previous,start,size,results,errors,lastHTTP,concurrency,inode (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                       |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                         |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                             |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                         |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                            |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                    |

**weka fs tier release**

Release object-stored files from SSD storage

```sh
weka fs tier release [--non-existing non-existing]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--verbose]
                     [--help]
                     [--raw-units]
                     [--UTC]
                     [<path>]...

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `path`...                 | A file path to release from SSD storage. Multiple paths can be passed, e.g. \`find ...                                            |
| `--non-existing`          | Behavior for non-existing files (default: error) (format: 'error', 'warn' or 'ignore')                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-v`, `--verbose`         | Verbose output, showing release requests as they are submitted                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs tier s3**

List S3 object store buckets configuration and status

```sh
weka fs tier s3 [--obs-name obs-name]
                [--name name]
                [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--format format]
                [--output output]...
                [--sort sort]...
                [--filter filter]...
                [--filter-color filter-color]...
                [--help]
                [--raw-units]
                [--UTC]
                [--no-header]
                [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--obs-name`              | Name of the Object Store                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `--name`                  | Name of the Object Store bucket                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,obsId,obsName,id,name,site,statusUpload,statusDownload,statusRemove,nodesUpForUpload,nodesUpForDownload,nodesUpForRemove,nodesDownForUpload,nodesDownForDownload,nodesDownForRemove,nodesUnknownForUpload,nodesUnknownForDownload,nodesUnknownForRemove,errors,protocol,hostname,port,bucket,auth,region,access,secret,status,up,downloadBandwidth,uploadBandwidth,removeBandwidth,errorsTimeout,prefetch,downloads,uploads,removals,maxUploadExtents,maxUploadSize,enableUploadTags,dataStorageClass,metadataStorageClass,stsOperationType,stsRoleArn,stsRoleSessionName,stsDuration (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |

**weka fs tier s3 add**

Create a new S3 object store bucket connection

```sh
weka fs tier s3 add <name>
                    [--site site]
                    [--obs-name obs-name]
                    [--hostname hostname]
                    [--port port]
                    [--bucket bucket]
                    [--auth-method auth-method]
                    [--region region]
                    [--access-key-id access-key-id]
                    [--secret-key secret-key]
                    [--protocol protocol]
                    [--obs-type obs-type]
                    [--bandwidth bandwidth]
                    [--download-bandwidth download-bandwidth]
                    [--upload-bandwidth upload-bandwidth]
                    [--remove-bandwidth remove-bandwidth]
                    [--errors-timeout errors-timeout]
                    [--prefetch-mib prefetch-mib]
                    [--max-concurrent-downloads max-concurrent-downloads]
                    [--max-concurrent-uploads max-concurrent-uploads]
                    [--max-concurrent-removals max-concurrent-removals]
                    [--max-extents-in-data-blob max-extents-in-data-blob]
                    [--max-data-blob-size max-data-blob-size]
                    [--enable-upload-tags enable-upload-tags]
                    [--data-storage-class data-storage-class]
                    [--metadata-storage-class metadata-storage-class]
                    [--sts-operation-type sts-operation-type]
                    [--sts-role-arn sts-role-arn]
                    [--sts-role-session-name sts-role-session-name]
                    [--sts-session-duration sts-session-duration]
                    [--gcp-auth-token-file gcp-auth-token-file]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--dry-run]
                    [--skip-verification]
                    [--verbose-errors]
                    [--help]
                    [--json]
                    [--raw-units]
                    [--UTC]

```

| Parameter                       | Description                                                                                                                                                             |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                        | Name of the Object Store bucket                                                                                                                                         |
| `--site`                        | The site of the Object Store, default: local (format: 'local' or 'remote')                                                                                              |
| `--obs-name`                    | Name of the Object Store to associate this new bucket to                                                                                                                |
| `--hostname`                    | Hostname (or IP) of the entrypoint to the storage                                                                                                                       |
| `--port`                        | Port of the entrypoint to S3 (single Accesser or Load-Balancer)                                                                                                         |
| `--bucket`                      | Name of the bucket we are assigned to work with                                                                                                                         |
| `--auth-method`                 | Authentication method. S3AuthMethod can be None, AWSSignature2 or AWSSignature4                                                                                         |
| `--region`                      | Name of the region we are assigned to work with (usually empty)                                                                                                         |
| `--access-key-id`               | Access Key ID for AWS Signature authentications                                                                                                                         |
| `--secret-key`                  | Secret Key for AWS Signature authentications                                                                                                                            |
| `--protocol`                    | One of: HTTP (default), HTTPS, HTTPS\_UNVERIFIED                                                                                                                        |
| `--obs-type`                    | One of: AWS (default), AZURE                                                                                                                                            |
| `--bandwidth`                   | Bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                            |
| `--download-bandwidth`          | Download bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                   |
| `--upload-bandwidth`            | Upload bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                     |
| `--remove-bandwidth`            | Remove bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                     |
| `--errors-timeout`              | If the Object Store bucket link is down for longer than this, all IOs that need data return with an error (format: duration between 1 minute and 15 minutes)            |
| `--prefetch-mib`                | How many MiB of data to prefetch when reading a whole MiB on object store. Default Value is 128MiB (format: 0..600)                                                     |
| `--max-concurrent-downloads`    | Maximum number of downloads we concurrently perform on this object store in a single IO node (format: 1..64)                                                            |
| `--max-concurrent-uploads`      | Maximum number of uploads we concurrently perform on this object store in a single IO node (format: 1..64)                                                              |
| `--max-concurrent-removals`     | Maximum number of removals we concurrently perform on this object store in a single IO node (format: 1..64)                                                             |
| `--max-extents-in-data-blob`    | Maximum number of extents' data to upload to an object store data blob                                                                                                  |
| `--max-data-blob-size`          | Maximum size to upload to an object store data blob (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--enable-upload-tags`          | Enable tagging of uploaded objects (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                      |
| `--data-storage-class`          | The AWS storage class / Azure access tier to use for uploaded data blobs                                                                                                |
| `--metadata-storage-class`      | The AWS storage class / Azure access tier to use for uploaded data blobs                                                                                                |
| `--sts-operation-type`          | AWS STS operation type to use. Default: none (format: 'assume\_role' or 'none')                                                                                         |
| `--sts-role-arn`                | The Amazon Resource Name (ARN) of the role to assume. Mandatory when setting sts-operation to ASSUME\_ROLE                                                              |
| `--sts-role-session-name`       | An identifier for the assumed role session. Length constraints: Minimum length of 2, maximum length of 64.                                                              |
| `owed characters: upper and lo` | wer-case alphanumeric characters with no spaces.                                                                                                                        |

**weka fs tier s3 attach**

Attach a filesystem to an existing Object Store

```sh
weka fs tier s3 attach <filesystem>
                       <obs-name>
                       [--mode mode]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--help]
                       [--raw-units]
                       [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Name of the Filesystem                                                                                                            |
| `obs-name`\*              | Name of the Object Store bucket to attach                                                                                         |
| `--mode`                  | The operation mode for the Object Store bucket (format: 'writable' or 'remote')                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka fs tier s3 remove**

Delete an existing S3 object store connection

```sh
weka fs tier s3 remove <name>
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Name of the Object Store bucket                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka fs tier s3 detach**

Detach a filesystem from an attached object store

```sh
weka fs tier s3 detach <filesystem>
                       <obs-name>
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--help]
                       [--force]

```

| Parameter                 | Description                                                                                                                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | Name of the Filesystem                                                                                                                                                                                                            |
| `obs-name`\*              | Name of the Object Store bucket to detach                                                                                                                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                 |
| `-f`, `--force`           | Force this action without further confirmation. This process might take a while to complete and it cannot be aborted. The data will remain intact on the object store, and you can still use the uploaded snapshots for recovery. |

**weka fs tier s3 snapshot**

Commands used to display info about uploaded snapshots

```sh
weka fs tier s3 snapshot [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka fs tier s3 snapshot list**

List and show info about snapshots uploaded to Object Storage

```sh
weka fs tier s3 snapshot list <name>
                              [--locator locator]
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--format format]
                              [--output output]...
                              [--sort sort]...
                              [--filter filter]...
                              [--filter-color filter-color]...
                              [--help]
                              [--raw-units]
                              [--UTC]
                              [--no-header]
                              [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                         |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Name of the Object Store bucket                                                                                                                                                                                                                     |
| `--locator`               | Locator                                                                                                                                                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                    |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                    |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                    |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                          |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                              |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                            |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: guid,fsId,snapId,origFsId,fsName,snapName,accessPoint,totalMetaData,totalSize,ssdCapacity,totalCapacity,maxFiles,numGuids,compatibleVersion (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                             |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                               |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                            |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                   |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                   |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                               |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                  |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                          |

**weka fs tier s3 update**

Edit an existing S3 object store bucket connection

```sh
weka fs tier s3 update <name>
                       [--new-name new-name]
                       [--new-obs-name new-obs-name]
                       [--hostname hostname]
                       [--port port]
                       [--protocol protocol]
                       [--bucket bucket]
                       [--auth-method auth-method]
                       [--region region]
                       [--access-key-id access-key-id]
                       [--secret-key secret-key]
                       [--bandwidth bandwidth]
                       [--download-bandwidth download-bandwidth]
                       [--upload-bandwidth upload-bandwidth]
                       [--remove-bandwidth remove-bandwidth]
                       [--prefetch-mib prefetch-mib]
                       [--errors-timeout errors-timeout]
                       [--max-concurrent-downloads max-concurrent-downloads]
                       [--max-concurrent-uploads max-concurrent-uploads]
                       [--max-concurrent-removals max-concurrent-removals]
                       [--max-extents-in-data-blob max-extents-in-data-blob]
                       [--max-data-blob-size max-data-blob-size]
                       [--enable-upload-tags enable-upload-tags]
                       [--data-storage-class data-storage-class]
                       [--metadata-storage-class metadata-storage-class]
                       [--sts-operation-type sts-operation-type]
                       [--sts-role-arn sts-role-arn]
                       [--sts-role-session-name sts-role-session-name]
                       [--sts-session-duration sts-session-duration]
                       [--gcp-auth-token-file gcp-auth-token-file]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--dry-run]
                       [--skip-verification]
                       [--verbose-errors]
                       [--help]
                       [--raw-units]
                       [--UTC]
                       [--no-header]
                       [--verbose]

```

| Parameter                       | Description                                                                                                                                                             |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                        | Name of the Object Store bucket                                                                                                                                         |
| `--new-name`                    | New name                                                                                                                                                                |
| `--new-obs-name`                | New Object Store name                                                                                                                                                   |
| `--hostname`                    | Hostname (or IP) of the entrypoint to the storage                                                                                                                       |
| `--port`                        | Port of the entrypoint to S3 (single Accesser or Load-Balancer)                                                                                                         |
| `--protocol`                    | One of: HTTP (default), HTTPS, HTTPS\_UNVERIFIED                                                                                                                        |
| `--bucket`                      | Name of the bucket we are assigned to work with                                                                                                                         |
| `--auth-method`                 | Authentication method. S3AuthMethod can be None, AWSSignature2 or AWSSignature4                                                                                         |
| `--region`                      | Name of the region we are assigned to work with (usually empty)                                                                                                         |
| `--access-key-id`               | Access Key ID for AWS Signature authentications                                                                                                                         |
| `--secret-key`                  | Secret Key for AWS Signature authentications                                                                                                                            |
| `--bandwidth`                   | Bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                            |
| `--download-bandwidth`          | Download bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                   |
| `--upload-bandwidth`            | Upload bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                     |
| `--remove-bandwidth`            | Remove bandwidth limitation per core (Mbps) (format: 1..4294967295)                                                                                                     |
| `--prefetch-mib`                | How many MiB of data to prefetch when reading a whole MiB on object store. Default Value is 128MiB (format: 0..600)                                                     |
| `--errors-timeout`              | If the Object Store bucket link is down for longer than this, all IOs that need data return with an error (format: duration between 1 minute and 15 minutes)            |
| `--max-concurrent-downloads`    | Maximum number of downloads we concurrently perform on this object store in a single IO node (format: 1..64)                                                            |
| `--max-concurrent-uploads`      | Maximum number of uploads we concurrently perform on this object store in a single IO node (format: 1..64)                                                              |
| `--max-concurrent-removals`     | Maximum number of removals we concurrently perform on this object store in a single IO node (format: 1..64)                                                             |
| `--max-extents-in-data-blob`    | Maximum number of extents' data to upload to an object store data blob                                                                                                  |
| `--max-data-blob-size`          | Maximum size to upload to an object store data blob (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--enable-upload-tags`          | Enable tagging of uploaded objects (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                      |
| `--data-storage-class`          | The AWS storage class / Azure access tier to use for uploaded data blobs                                                                                                |
| `--metadata-storage-class`      | The AWS storage class / Azure access tier to use for uploaded data blobs                                                                                                |
| `--sts-operation-type`          | AWS STS operation type to use. Default: none (format: 'assume\_role' or 'none')                                                                                         |
| `--sts-role-arn`                | The Amazon Resource Name (ARN) of the role to assume. Mandatory when setting sts-operation to ASSUME\_ROLE                                                              |
| `--sts-role-session-name`       | An identifier for the assumed role session. Length constraints: Minimum length of 2, maximum length of 64.                                                              |
| `owed characters: upper and lo` | wer-case alphanumeric characters with no spaces.                                                                                                                        |

#### weka fs update

Update a filesystem

```sh
weka fs update <name>
               [--new-name new-name]
               [--total-capacity total-capacity]
               [--ssd-capacity ssd-capacity]
               [--thin-provision-min-ssd thin-provision-min-ssd]
               [--thin-provision-max-ssd thin-provision-max-ssd]
               [--audit-enabled audit-enabled]
               [--data-reduction data-reduction]
               [--auth-required auth-required]
               [--kms-key-identifier kms-key-identifier]
               [--kms-namespace kms-namespace]
               [--kms-role-id kms-role-id]
               [--kms-secret-id kms-secret-id]
               [--index-enabled index-enabled]
               [--max-throughput max-throughput]
               [--max-iops max-iops]
               [--color color]
               [--HOST HOST]
               [--PORT PORT]
               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
               [--TIMEOUT TIMEOUT]
               [--profile profile]
               [--use-cluster-kms-key-identifier]
               [--help]

```

| Parameter                          | Description                                                                                                                                                                                                                                                               |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                           | Filesystem name                                                                                                                                                                                                                                                           |
| `--new-name`                       | New name                                                                                                                                                                                                                                                                  |
| `--total-capacity`                 | Total capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                        |
| `--ssd-capacity`                   | SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                          |
| `--thin-provision-min-ssd`         | Thin provision minimum SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                   |
| `--thin-provision-max-ssd`         | Thin provision maximum SSD capacity (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                   |
| `--audit-enabled`                  | Enable audit logging for this filesystem. Takes effect only if audit is enabled cluster-wide (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                              |
| `--data-reduction`                 | Enable data reduction (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                     |
| `--auth-required`                  | Require the mounting user to be authenticated for mounting this filesystem. This flag is only effective in the root tenant, users in non-root tenants must be authenticated to perform a mount operation. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--kms-key-identifier`             | Customize KMS key identifier for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                     |
| `--kms-namespace`                  | Customize KMS namespace for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--kms-role-id`                    | Customize KMS role-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                            |
| `--kms-secret-id`                  | Customize KMS secret-id for this filesystem (currently only for HashiCorp Vault)                                                                                                                                                                                          |
| `--index-enabled`                  | Enable catalog indexing for this filesystem (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                               |
| `--max-throughput`                 | Limit throughput per second (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                           |
| `--max-iops`                       | Limit IOs/s                                                                                                                                                                                                                                                               |
| `--color`                          | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                          |
| `-H`, `--HOST`                     | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                          |
| `-P`, `--PORT`                     | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT`          | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                |
| `-T`, `--TIMEOUT`                  | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                    |
| `--profile`                        | Name of the connection and authentication profile to use                                                                                                                                                                                                                  |
| `--use-cluster-kms-key-identifier` | Use cluster KMS configuration for this filesystem, removes the custom KMS configuration for this filesystem                                                                                                                                                               |
| `-h`, `--help`                     | Show help message                                                                                                                                                                                                                                                         |

### weka interface-group

List interface groups

```sh
weka interface-group [--name name]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--format format]
                     [--output output]...
                     [--sort sort]...
                     [--filter filter]...
                     [--filter-color filter-color]...
                     [--help]
                     [--no-header]
                     [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,name,mask,gateway,type,status,ips,ports,allowManageGids (may be repeated or comma-separated)                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka interface-group add

Create an interface group

```sh
weka interface-group add <name>
                         <type>
                         [--subnet subnet]
                         [--gateway gateway]
                         [--allow-manage-gids allow-manage-gids]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--format format]
                         [--output output]...
                         [--sort sort]...
                         [--filter filter]...
                         [--filter-color filter-color]...
                         [--help]
                         [--no-header]
                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                                                                                                                            |
| `type`\*                  | Group type                                                                                                                                                                                                                                                      |
| `--subnet`                | subnet mask in the 255.255.0.0 format                                                                                                                                                                                                                           |
| `--gateway`               | gateway ip                                                                                                                                                                                                                                                      |
| `--allow-manage-gids`     | Allow to use manage-gids in exports. With manage-gids, the list of group ids received from the client will be replaced by a list of group ids determined by an appropriate lookup on the server (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                        |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                            |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,mask,gateway,type,status,ips,ports,allowManageGids (may be repeated or comma-separated)                                                                                                 |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                         |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                           |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                               |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                              |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                      |

#### weka interface-group assignment

List the currently assigned interface for each floating-IP address in the given interface-group. If is not supplied, assignments for all floating-IP addresses will be listed

```sh
weka interface-group assignment [--name name]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--format format]
                                [--output output]...
                                [--sort sort]...
                                [--filter filter]...
                                [--filter-color filter-color]...
                                [--help]
                                [--no-header]
                                [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: ip,host,port,group (may be repeated or comma-separated)                                                              |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka interface-group remove

Delete an interface group

```sh
weka interface-group remove <name>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--force]
                            [--help]

```

| Parameter                 | Description                                                                                                                                                    |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                       |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected clients and can be undone by re-creating the interface group. |
| `-h`, `--help`            | Show help message                                                                                                                                              |

#### weka interface-group ip-range

Commands that manage interface-groups' ip-ranges

```sh
weka interface-group ip-range [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka interface-group ip-range add**

Add an ip range to an interface group

```sh
weka interface-group ip-range add <name>
                                  <ips>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `ips`\*                   | IP range                                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka interface-group ip-range remove**

Delete an ip range from an interface group

```sh
weka interface-group ip-range remove <name>
                                     <ips>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--force]
                                     [--help]

```

| Parameter                 | Description                                                                                                                                             |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                    |
| `ips`\*                   | IP range                                                                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected clients and can be undone by re-creating the IP range. |
| `-h`, `--help`            | Show help message                                                                                                                                       |

#### weka interface-group port

Commands that manage interface-groups' ports

```sh
weka interface-group port [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka interface-group port add**

Add a server port to an interface group

```sh
weka interface-group port add <name>
                              <server-id>
                              <port>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `server-id`\*             | Server ID on which the port resides                                                                        |
| `port`\*                  | Port's device. (e.g. eth1)                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka interface-group port remove**

Delete a server port from an interface group

```sh
weka interface-group port remove <name>
                                 <server-id>
                                 <port>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--force]
                                 [--help]

```

| Parameter                 | Description                                                                                                                                       |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                              |
| `server-id`\*             | Server ID on which the port resides                                                                                                               |
| `port`\*                  | Port's device. (e.g. eth1)                                                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected clients and can be undone by re-adding the port. |
| `-h`, `--help`            | Show help message                                                                                                                                 |

#### weka interface-group update

Update an interface group

```sh
weka interface-group update <name>
                            [--subnet subnet]
                            [--gateway gateway]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `--subnet`                | subnet mask in the 255.255.0.0 format                                                                      |
| `--gateway`               | gateway ip                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka local

Commands that control weka and its containers on the local machine

```sh
weka local [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka local diags

Collect diagnostics from the local machine

```sh
weka local diags [--id id]
                 [--output-dir output-dir]
                 [--core-dump-limit core-dump-limit]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--collect-cluster-info]
                 [--tar]
                 [--verbose]
                 [--help]

```

| Parameter                      | Description                                                                                                            |
| ------------------------------ | ---------------------------------------------------------------------------------------------------------------------- |
| `-i`, `--id`                   | A unique identifier for this dump                                                                                      |
| `-d`, `--output-dir`           | Directory to save the diags dump to, default: /opt/weka/diags                                                          |
| `-c`, `--core-dump-limit`      | Limit to processing this number of core dumps, if found (default: 1)                                                   |
| `--color`                      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                       |
| `-H`, `--HOST`                 | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                       |
| `-P`, `--PORT`                 | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                       |
| `-C`, `--CONNECT-TIMEOUT`      | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)             |
| `-T`, `--TIMEOUT`              | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                 |
| `--profile`                    | Name of the connection and authentication profile to use                                                               |
| `-s`, `--collect-cluster-info` | Collect cluster-related information. Warning: Use this flag on one container at a time to avoid straining the cluster. |
| `-t`, `--tar`                  | Create a TAR of all collected diags                                                                                    |
| `-v`, `--verbose`              | Print results of all diags, including successful ones                                                                  |
| `-h`, `--help`                 | Show help message                                                                                                      |

#### weka local disable

Disable containers by not launching them on machine boot. This does not affect the current running status of the container. In order to change the current status, use the "weka local start/stop" commands. If no container names are specified, this command runs on all containers.

```sh
weka local disable [--color color] [--type type]... [--help] [<container>]...

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `container`...    | The container to disable                                                         |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-t`, `--type`... | The container types to disable (may be repeated or comma-separated)              |
| `-h`, `--help`    | Show help message                                                                |

#### weka local drive

Manage local drives

```sh
weka local drive [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka local drive identify**

Turn a drive's identify LED on or off

```sh
weka local drive identify <serialNumber> <state> [--color color] [--help]

```

| Parameter        | Description                                                                                            |
| ---------------- | ------------------------------------------------------------------------------------------------------ |
| `serialNumber`\* | The serial number of the drive                                                                         |
| `state`\*        | Set the drive's identify LED on or off (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--color`        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                       |
| `-h`, `--help`   | Show help message                                                                                      |

**weka local drive list**

List local drives

```sh
weka local drive list [--color color]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--help]
                      [--raw-units]
                      [--UTC]
                      [--no-header]
                      [--verbose]

```

| Parameter           | Description                                                                                                                                                                             |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-f`, `--format`    | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`... | Specify which columns to output. May include any of the following: name,serial,capacity,status,manufacturer,model,location,refresh,component (may be repeated or comma-separated)       |
| `-s`, `--sort`...   | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`... | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`... | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`      | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units` | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`       | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`       | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`   | Show all columns in output                                                                                                                                                              |

#### weka local enable

Enable monitoring for the requested containers so they automaticlly start on machine boot. This does not affect the current running status of the container. In order to change the current status, use the "weka local start/stop" commands. If no container names are specified, this command runs on all containers.

```sh
weka local enable [--color color] [--type type]... [--help] [<container>]...

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `container`...    | The container to enable                                                          |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-t`, `--type`... | The container types to enable (may be repeated or comma-separated)               |
| `-h`, `--help`    | Show help message                                                                |

#### weka local events

List the events saved to the local drive. This command does not require authentication and can be used when Weka is turned off.

```sh
weka local events [--path path]
                  [--container-name container-name]
                  [--color color]
                  [--format format]
                  [--output output]...
                  [--sort sort]...
                  [--filter filter]...
                  [--filter-color filter-color]...
                  [--help]
                  [--raw-units]
                  [--UTC]
                  [--no-header]
                  [--verbose]

```

| Parameter           | Description                                                                                                                                                                             |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--path`            | Path to where local events are stored                                                                                                                                                   |
| `--container-name`  | Name of the container whose events will be collected (default default)                                                                                                                  |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-f`, `--format`    | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`... | Specify which columns to output. May include any of the following: time,uuid,category,severity,permission,type,entity,node,parameters,hash (may be repeated or comma-separated)         |
| `-s`, `--sort`...   | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`... | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`... | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`      | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units` | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`       | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`       | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`   | Show all columns in output                                                                                                                                                              |

#### weka local install-agent

Installs Weka agent on the machine the command is executed from

```sh
weka local install-agent [--color color] [--no-update] [--no-start] [--systemd-graceful-shutdown] [--help]

```

| Parameter                     | Description                                                                      |
| ----------------------------- | -------------------------------------------------------------------------------- |
| `--color`                     | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--no-update`                 | Don't update the locally installed containers                                    |
| `--no-start`                  | Do not register the weka-agent service and start it after its creation           |
| `--systemd-graceful-shutdown` | Enable graceful shutdown via systemd                                             |
| `-h`, `--help`                | Show help message                                                                |

#### weka local monitoring

Turn monitoring on/off for the given containers, or all containers if none are specified. When a container is started, it's always monitored. When a container is monitored, it will be restarted if it exits without being stopped through the CLI.

```sh
weka local monitoring <enabled> [--color color] [--type type]... [--help] [<container>]...

```

| Parameter         | Description                                                                                            |
| ----------------- | ------------------------------------------------------------------------------------------------------ |
| `enabled`\*       | Whether monitoring should be on or off (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `container`...    | The container to disable                                                                               |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                       |
| `-t`, `--type`... | The container types to disable (may be repeated or comma-separated)                                    |
| `-h`, `--help`    | Show help message                                                                                      |

#### weka local ps

List the Weka containers running on the machine this command is executed from

```sh
weka local ps [--color color]
              [--format format]
              [--output output]...
              [--sort sort]...
              [--filter filter]...
              [--filter-color filter-color]...
              [--help]
              [--raw-units]
              [--UTC]
              [--no-header]
              [--verbose]

```

| Parameter           | Description                                                                                                                                                                                                                                                                                      |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                 |
| `-f`, `--format`    | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                             |
| `-o`, `--output`... | Specify which columns to output. May include any of the following: name,containerId,state,status,uptime,unjoinedProcesses,pid,port,versionName,validLease,failure,failureText,failureTime,running,disabled,monitoring,persistent,managementIps,upgradeState (may be repeated or comma-separated) |
| `-s`, `--sort`...   | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                          |
| `-F`, `--filter`... | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                            |
| `--filter-color`... | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                         |
| `-h`, `--help`      | Show help message                                                                                                                                                                                                                                                                                |
| `-R`, `--raw-units` | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                                |
| `-U`, `--UTC`       | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                            |
| `--no-header`       | Don't show column headers when printing the output                                                                                                                                                                                                                                               |
| `-v`, `--verbose`   | Show all columns in output                                                                                                                                                                                                                                                                       |

#### weka local reset-data

Resets the data directory for a given container, making the host no longer aware of the rest of the cluster

```sh
weka local reset-data [--container container] [--color color] [--clean-unused] [--force] [--help] [<version-name>]...

```

| Parameter           | Description                                                                                                                  |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| `version-name`...   | The versions to remove                                                                                                       |
| `-C`, `--container` | The container to run in                                                                                                      |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                             |
| `--clean-unused`    | Delete all container data directories for versions which aren't the current set version                                      |
| `-f`, `--force`     | Force this action without further confirmation. This action is destructive and can potentially lose all data in the cluster. |
| `-h`, `--help`      | Show help message                                                                                                            |

#### weka local resources

List and control container resources

```sh
weka local resources [--container container] [--color color] [--stable] [--help] [--json] [--raw-units] [--UTC]

```

| Parameter           | Description                                                                                                                       |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                                                                                |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `--stable`          | List the resources from the last successful container boot                                                                        |
| `-h`, `--help`      | Show help message                                                                                                                 |
| `-J`, `--json`      | Format output as JSON                                                                                                             |
| `-R`, `--raw-units` | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`       | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

**weka local resources apply**

Apply changes to resources locally

```sh
weka local resources apply [--container container] [--timeout timeout] [--color color] [--help] [--force]

```

| Parameter           | Description                                                                                                               |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                                                                        |
| `--timeout`         | Maximum time for CLI to wait for resources to apply (default: 20m) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                          |
| `-h`, `--help`      | Show help message                                                                                                         |
| `-f`, `--force`     | Force this action without further confirmation. This action will restart the container on this host and cannot be undone. |

**weka local resources auto-remove-timeout**

Configure the auto-remove-timeout (in seconds) to remove inactive client containers.

```sh
weka local resources auto-remove-timeout <auto-remove-timeout>
                                         [--container container]
                                         [--color color]
                                         [--force]
                                         [--help]

```

| Parameter               | Description                                                                                                                                  |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `auto-remove-timeout`\* | The auto-remove timeout in seconds to remove inactive client containers.                                                                     |
| `-C`, `--container`     | The container name                                                                                                                           |
| `--color`               | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                             |
| `-f`, `--force`         | Force this action without further confirmation. This would cause a non-client container to become a client and this action is irreversible.. |
| `-h`, `--help`          | Show help message                                                                                                                            |

**weka local resources bandwidth**

Limit weka's bandwidth for the host

```sh
weka local resources bandwidth <bandwidth> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                                                                                                                                |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `bandwidth`\*       | New bandwidth limitation per second (format: either "unlimited" or bandwidth per second in binary or decimal values: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `-C`, `--container` | The container name                                                                                                                                                                         |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                           |
| `-h`, `--help`      | Show help message                                                                                                                                                                          |

**weka local resources base-port**

Change the port-range used by the container. Weka containers require 100 ports to operate.

```sh
weka local resources base-port <base-port> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                          |
| ------------------- | ------------------------------------------------------------------------------------ |
| `base-port`\*       | The first port that will be used by the Weka container, out of a total of 100 ports. |
| `-C`, `--container` | The container name                                                                   |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')     |
| `-h`, `--help`      | Show help message                                                                    |

**weka local resources cores**

Change the core configuration of the host

```sh
weka local resources cores <cores>
                           [--container container]
                           [--frontend-dedicated-cores frontend-dedicated-cores]
                           [--drives-dedicated-cores drives-dedicated-cores]
                           [--compute-dedicated-cores compute-dedicated-cores]
                           [--color color]
                           [--core-ids core-ids]...
                           [--no-frontends]
                           [--only-drives-cores]
                           [--only-compute-cores]
                           [--only-frontend-cores]
                           [--allow-mix-setting]
                           [--help]

```

| Parameter                    | Description                                                                                                     |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------- |
| `cores`\*                    | Number of CPU cores dedicated to weka - If set to 0 - no drive could be added to this host                      |
| `-C`, `--container`          | The container name                                                                                              |
| `--frontend-dedicated-cores` | Number of cores dedicated to weka frontend (out of the total )                                                  |
| `--drives-dedicated-cores`   | Number of cores dedicated to weka drives (out of the total )                                                    |
| `--compute-dedicated-cores`  | Number of cores dedicated to weka compute (out of the total )                                                   |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                |
| `--core-ids`...              | Specify the ids of weka dedicated cores (may be repeated or comma-separated)                                    |
| `--no-frontends`             | Don't allocate frontend nodes                                                                                   |
| `--only-drives-cores`        | Create only nodes with a drives role                                                                            |
| `--only-compute-cores`       | Create only nodes with a compute role                                                                           |
| `--only-frontend-cores`      | Create only nodes with a frontend role                                                                          |
| `--allow-mix-setting`        | Allow specified core-ids even if there are running containers with AUTO core-ids allocation on the same server. |
| `-h`, `--help`               | Show help message                                                                                               |

**weka local resources dedicate**

Set the host as dedicated to weka. For example it can be rebooted whenever needed, and configured by weka for optimal performance and stability

```sh
weka local resources dedicate <on> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                                                                       |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `on`\*              | Set the host as weka dedicated, off unsets host as weka dedicated (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `-C`, `--container` | The container name                                                                                                                |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-h`, `--help`      | Show help message                                                                                                                 |

**weka local resources drive**

List or specify settings for drives managed in resources

```sh
weka local resources drive [--container container] [--color color] [--help] [--json]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |
| `-J`, `--json`      | Format output as JSON                                                            |

**weka local resources drive add**

Add drive UUIDs that are to be exposed by the container

```sh
weka local resources drive add [--container container] [--color color] [--drive-uuids drive-uuids]... [--help]

```

| Parameter           | Description                                                                                                              |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| `-C`, `--container` | The container name                                                                                                       |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                         |
| `--drive-uuids`...  | UUIDs of signed storage drives to add to be used when the container joins a cluster (may be repeated or comma-separated) |
| `-h`, `--help`      | Show help message                                                                                                        |

**weka local resources drive remove**

Remove drive UUIDs that are to be exposed by the container

```sh
weka local resources drive remove [--container container] [--color color] [--drive-uuids drive-uuids]... [--help]

```

| Parameter           | Description                                                                                                                         |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                                                                                  |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `--drive-uuids`...  | UUIDs of signed storage drives to remove from consideration when the container joins a cluster (may be repeated or comma-separated) |
| `-h`, `--help`      | Show help message                                                                                                                   |

**weka local resources drive scan**

Turn scanning drives on start on or off

```sh
weka local resources drive scan <scan-drives> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                                                |
| ------------------- | ---------------------------------------------------------------------------------------------------------- |
| `scan-drives`\*     | Scan for signed drives on container start. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `-C`, `--container` | The container name                                                                                         |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-h`, `--help`      | Show help message                                                                                          |

**weka local resources export**

Export stable resources to file

```sh
weka local resources export <path> [--container container] [--color color] [--staging] [--stable] [--help]

```

| Parameter           | Description                                                                                     |
| ------------------- | ----------------------------------------------------------------------------------------------- |
| `path`\*            | Path to export resources                                                                        |
| `-C`, `--container` | The container name                                                                              |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                |
| `--staging`         | List the resources from the currently staged resources that were not yet applied                |
| `--stable`          | List the resources from the currently stable resources, which are the last known good resources |
| `-h`, `--help`      | Show help message                                                                               |

**weka local resources failure-domain**

Set the host failure-domain

```sh
weka local resources failure-domain [--container container] [--name name] [--scope scope] [--color color] [--help]

```

| Parameter           | Description                                                                                                                                                                                                                                         |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                                                                                                                                                                                                  |
| `--name`            | Add this host to a named failure-domain. A failure-domain will be created if it doesn't exist yet.                                                                                                                                                  |
| `--scope`           | Automatic failure domain scope: 'server' (each server is its own FD), 'rack' (switch discovery via LLDP or InfiniBand SMP), or 'chassis' (SMBIOS chassis serial, for multi-node enclosures such as BigTwin) (format: 'server', 'rack' or 'chassis') |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                    |
| `-h`, `--help`      | Show help message                                                                                                                                                                                                                                   |

**weka local resources fqdn**

Configure the fqdn to be used by other containers for TLS hostname verification when interacting with the cluster.

```sh
weka local resources fqdn <fqdn> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                                                                            |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| `fqdn`\*            | The Fully Qualified Domain Name (FQDN) to be used by other containers for TLS hostname verification when interacting with the cluster. |
| `-C`, `--container` | The container name                                                                                                                     |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                       |
| `-h`, `--help`      | Show help message                                                                                                                      |

**weka local resources hardware-monitor**

Configure hardware monitoring for the local chassis

```sh
weka local resources hardware-monitor [--container container]
                                      [--bmc-url bmc-url]
                                      [--bmc-username bmc-username]
                                      [--bmc-password bmc-password]
                                      [--color color]
                                      [--enable]
                                      [--disable]
                                      [--help]

```

| Parameter           | Description                                                                        |
| ------------------- | ---------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                                 |
| `--bmc-url`         | The hostname or IP address of the BMC. Use 'default' to use the default value.     |
| `--bmc-username`    | The username to use to connect to the BMC. Use 'default' to use the default value. |
| `--bmc-password`    | The password to use to connect to the BMC. Use 'default' to use the default value. |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')   |
| `--enable`          | Enable hardware monitoring.                                                        |
| `--disable`         | Disable hardware monitoring.                                                       |
| `-h`, `--help`      | Show help message                                                                  |

**weka local resources import**

Import resources from file

```sh
weka local resources import <path> [--container container] [--color color] [--with-identifiers] [--help] [--force]

```

| Parameter            | Description                                                                                                                                      |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `path`\*             | Path of file to import resources from                                                                                                            |
| `-C`, `--container`  | The container name                                                                                                                               |
| `--color`            | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                 |
| `--with-identifiers` | Import net device unique identifiers                                                                                                             |
| `-h`, `--help`       | Show help message                                                                                                                                |
| `-f`, `--force`      | Force this action without further confirmation. This action will override any resource changes that have not been applied, and cannot be undone. |

**weka local resources join-ips**

Set the IPs and ports of all hosts in the cluster. This will enable the host to join the cluster using these IPs.

```sh
weka local resources join-ips [--container container]
                              [--color color]
                              [--join-fqdns join-fqdns]...
                              [--restricted]
                              [--help]
                              [<management-ips>]...

```

| Parameter           | Description                                                                                                                                      |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `management-ips`... | New IP:port pairs for the management processes. If no port is used the command will use the default Weka port                                    |
| `-C`, `--container` | The container name                                                                                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                 |
| `--join-fqdns`...   | FQDN:port pairs for the management processes. If no port is used the command will use the default Weka port (may be repeated or comma-separated) |
| `--restricted`      | Join using restricted client port                                                                                                                |
| `-h`, `--help`      | Show help message                                                                                                                                |

**weka local resources join-secret**

Configure the secret used when joining a cluster as a backend

```sh
weka local resources join-secret <secret> [--container container] [--color color] [--purge] [--help]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `secret`\*          | Cluster join secret                                                              |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--purge`           | Purge previous join secrets                                                      |
| `-h`, `--help`      | Show help message                                                                |

**weka local resources management-ips**

Set the host's management node IPs. Setting 2 IPs will turn this hosts networking into highly-available mode

```sh
weka local resources management-ips [--container container] [--color color] [--help] [<management-ips>]...

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `management-ips`... | New IPs for the management nodes                                                 |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |

**weka local resources management-nets**

Set the host's management network interfaces used to auto detect the management IPs

```sh
weka local resources management-nets [--container container] [--color color] [--help] [<management-nets>]...

```

| Parameter            | Description                                                                      |
| -------------------- | -------------------------------------------------------------------------------- |
| `management-nets`... | Network interfaces used to auto detect the management IPs                        |
| `-C`, `--container`  | The container name                                                               |
| `--color`            | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`       | Show help message                                                                |

**weka local resources memory**

Dedicate a set amount of RAM to weka

```sh
weka local resources memory <memory> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                                                                                                                              |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `memory`\*          | Memory dedicated to weka in bytes, set to 0 to let the system decide (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `-C`, `--container` | The container name                                                                                                                                                                       |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                         |
| `-h`, `--help`      | Show help message                                                                                                                                                                        |

**weka local resources net**

List and control container resources

```sh
weka local resources net [--container container] [--color color] [--stable] [--rdma] [--help] [--json]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--stable`          | List the resources from the last successful container boot                       |
| `--rdma`            | Include RDMA devices in the resources list                                       |
| `-h`, `--help`      | Show help message                                                                |
| `-J`, `--json`      | Format output as JSON                                                            |

**weka local resources net add**

Allocate a dedicated networking device on a host (to the cluster).

```sh
weka local resources net add <device>
                             [--container container]
                             [--gateway gateway]
                             [--netmask netmask]
                             [--name name]
                             [--label label]
                             [--vfs vfs]
                             [--vlan vlan]
                             [--color color]
                             [--ips ips]...
                             [--rdma-off]
                             [--rdma-only]
                             [--inet6]
                             [--help]

```

| Parameter           | Description                                                                                                                                                                                                  |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `device`\*          | Network device pci-slot/mac-address/interface-name(s)                                                                                                                                                        |
| `-C`, `--container` | The container name                                                                                                                                                                                           |
| `--gateway`         | Default gateway IP. In AWS this value is auto-detected, otherwise the default data networking gateway will be used.                                                                                          |
| `--netmask`         | Netmask in bits number. In AWS this value is auto-detected, otherwise the default data networking netmask will be used.                                                                                      |
| `--name`            | If empty, a name will be auto generated.                                                                                                                                                                     |
| `--label`           | The name of the switch or network group to which this network device is attached                                                                                                                             |
| `--vfs`             | The number of VFs to preallocate (default is all supported by NIC)                                                                                                                                           |
| `--vlan`            | The VLAN to use (802.1Q, Ethernet only, 1-4094)                                                                                                                                                              |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                             |
| `--ips`...          | IPs to be allocated to cores using the device. If not given - IPs may be set automatically according the interface's IPs, or taken from the default networking IPs pool (may be repeated or comma-separated) |
| `--rdma-off`        | The device will not be used for RDMA data transfers                                                                                                                                                          |
| `--rdma-only`       | The device will be explicitly configured for RDMA                                                                                                                                                            |
| `--inet6`           | Use IPv6 for RoCE v2 RDMA. The default is IPv4, not required and ignored for Infiniband.                                                                                                                     |
| `-h`, `--help`      | Show help message                                                                                                                                                                                            |

**weka local resources net remove**

Undedicate a networking device in a host.

```sh
weka local resources net remove <name> [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `name`\*            | Net device name or identifier as appears in `weka local resources net`           |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |

**weka local resources non-datapath-cores**

Set the list of CPU cores reserved for non-datapath operations (e.g. management tasks). Pass no core IDs to clear the list.

```sh
weka local resources non-datapath-cores [--container container] [--color color] [--help] [<core-ids>]...

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `core-ids`...       | CPU core IDs to mark as non-datapath                                             |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |

**weka local resources restore**

Restore resources from Stable resources

```sh
weka local resources restore [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `-C`, `--container` | The container name                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |

#### weka local restart

Restart a Weka container

```sh
weka local restart [--wait-time wait-time]
                   [--timeout timeout]
                   [--color color]
                   [--type type]...
                   [--dont-restart-dependent-containers]
                   [--force]
                   [--help]
                   [<container>]...

```

| Parameter                             | Description                                                                                                                          |
| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| `container`...                        | The container to restart                                                                                                             |
| `-w`, `--wait-time`                   | How long to wait for the container to start (default: 15m) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                    |
| `--timeout`                           | Maximum time for CLI to wait for restart operation to complete (default: 20m) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`                             | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                     |
| `-t`, `--type`...                     | The container types to restart (may be repeated or comma-separated)                                                                  |
| `--dont-restart-dependent-containers` | Do not restart dependent containers                                                                                                  |
| `-f`, `--force`                       | Skip the check for active mounts and perform an ungraceful restart                                                                   |
| `-h`, `--help`                        | Show help message                                                                                                                    |

#### weka local rm

Delete a Weka container from the machine this command is executed from (this removed the data associated with the container, but retains the downloaded software)

```sh
weka local rm [--color color] [--all] [--force] [--help] [<containers>]...

```

| Parameter       | Description                                                                                                                                                   |
| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `containers`... | The containers to remove                                                                                                                                      |
| `--color`       | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                              |
| `--all`         | Remove all containers                                                                                                                                         |
| `-f`, `--force` | Force this action without further confirmation. This would delete all data associated with the container(s) and can potentially lose all data in the cluster. |
| `-h`, `--help`  | Show help message                                                                                                                                             |

#### weka local run

Execute a command inside a new container that has the same mounts as the given container. If no container is specified, either "default" or the only defined container is selected. If no command is specified, opens an interactive shell.

```sh
weka local run [--container container] [--in in] [--color color] [--environment environment]... [--help] [<command>]...

```

| Parameter                | Description                                                                      |
| ------------------------ | -------------------------------------------------------------------------------- |
| `-C`, `--container`      | The container to run in                                                          |
| `--in`                   | The container version to run the command in                                      |
| `--color`                | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-e`, `--environment`... | Environment variable to add (may be repeated)                                    |
| `-h`, `--help`           | Show help message                                                                |

#### weka local setup

Container setup commands

```sh
weka local setup [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka local setup client**

Setup a local weka client container

```sh
weka local setup client [--name name]
                        [--cores cores]
                        [--memory memory]
                        [--bandwidth bandwidth]
                        [--timeout timeout]
                        [--base-port base-port]
                        [--weka-version weka-version]
                        [--fqdn fqdn]
                        [--nvidia-vf-single-ip nvidia-vf-single-ip]
                        [--dedicated-mode dedicated-mode]
                        [--scan-rdma scan-rdma]
                        [--color color]
                        [--core-ids core-ids]...
                        [--management-ips management-ips]...
                        [--management-net management-net]...
                        [--join-ips join-ips]...
                        [--net net]...
                        [--disable]
                        [--no-start]
                        [--allow-mix-setting]
                        [--restricted]
                        [--help]

```

| Parameter               | Description                                                                                                                                                                              |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-n`, `--name`          | The name to give the container                                                                                                                                                           |
| `--cores`               | Number of CPU cores dedicated to weka                                                                                                                                                    |
| `--memory`              | Memory dedicated to weka in bytes, set to 0 to let the system decide (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--bandwidth`           | bandwidth limitation per second (format: either "unlimited" or bandwidth per second in binary or decimal values: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)   |
| `-t`, `--timeout`       | Join command timeout in seconds (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                   |
| `--base-port`           | The first port that will be used by the Weka container, out of a total of 100 ports.                                                                                                     |
| `--weka-version`        | Use the specified version to start the container in                                                                                                                                      |
| `--fqdn`                | The Fully Qualified Domain Name (FQDN) to be used by other containers for TLS hostname verification when interacting with the cluster                                                    |
| `--nvidia-vf-single-ip` | Nvidia VFs work as Single IP (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                             |
| `--dedicated-mode`      | Determine whether DPDK networking dedicates a core (full) or not (none). none can only be set when the NIC driver supports it. (format: 'full' or 'none')                                |
| `--scan-rdma`           | Scan for unused net devices and add them for RDMA only use. (format: 'off', 'ib', 'eth' or 'all')                                                                                        |
| `--color`               | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                         |
| `--core-ids`...         | Specify the ids of weka dedicated cores (may be repeated or comma-separated)                                                                                                             |
| `--management-ips`...   | New IPs for the management nodes (may be repeated or comma-separated)                                                                                                                    |
| `--management-net`...   | Net interface used to auto configure management IPs (may be repeated or comma-separated)                                                                                                 |
| `--join-ips`...         | New IP:port pairs for the management processes. If no port is used the command will use the default Weka port (may be repeated or comma-separated)                                       |
| `--net`...              | Network specification - /\[ip]/\[bits]/\[gateway], or /rdma-only/\[inet4                                                                                                                 |
| `--disable`             | Should the container be created as disabled                                                                                                                                              |
| `--no-start`            | Do not start the container after its creation                                                                                                                                            |
| `--allow-mix-setting`   | Allow specified core-ids even if there are running containers with AUTO core-ids allocation on the same server.                                                                          |
| `--restricted`          | Restricted client mode functionality only                                                                                                                                                |
| `-h`, `--help`          | Show help message                                                                                                                                                                        |

**weka local setup container**

Setup a local weka container

```sh
weka local setup container [--name name]
                           [--cores cores]
                           [--frontend-dedicated-cores frontend-dedicated-cores]
                           [--drives-dedicated-cores drives-dedicated-cores]
                           [--compute-dedicated-cores compute-dedicated-cores]
                           [--memory memory]
                           [--bandwidth bandwidth]
                           [--failure-domain failure-domain]
                           [--failure-domain-scope failure-domain-scope]
                           [--timeout timeout]
                           [--container-id container-id]
                           [--base-port base-port]
                           [--resources-path resources-path]
                           [--weka-version weka-version]
                           [--fqdn fqdn]
                           [--auto-remove-timeout auto-remove-timeout]
                           [--nvidia-vf-single-ip nvidia-vf-single-ip]
                           [--dedicated-mode dedicated-mode]
                           [--scan-rdma scan-rdma]
                           [--color color]
                           [--core-ids core-ids]...
                           [--management-ips management-ips]...
                           [--join-ips join-ips]...
                           [--join-fqdns join-fqdns]...
                           [--net net]...
                           [--management-net management-net]...
                           [--drive-uuids drive-uuids]...
                           [--disable]
                           [--no-start]
                           [--no-frontends]
                           [--only-drives-cores]
                           [--only-compute-cores]
                           [--only-frontend-cores]
                           [--only-dataserv-cores]
                           [--allow-mix-setting]
                           [--dedicate]
                           [--force]
                           [--ignore-used-ports]
                           [--skip-management-ips-check]
                           [--client]
                           [--restricted]
                           [--clusterize]
                           [--scan-drives]
                           [--help]

```

| Parameter                     | Description                                                                                                                                                                                                                                         |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-n`, `--name`                | The name to give the container                                                                                                                                                                                                                      |
| `--cores`                     | Number of CPU cores dedicated to weka                                                                                                                                                                                                               |
| `--frontend-dedicated-cores`  | Number of cores dedicated to weka frontend (out of the total )                                                                                                                                                                                      |
| `--drives-dedicated-cores`    | Number of cores dedicated to weka drives (out of the total )                                                                                                                                                                                        |
| `--compute-dedicated-cores`   | Number of cores dedicated to weka compute (out of the total )                                                                                                                                                                                       |
| `--memory`                    | Memory dedicated to weka in bytes, set to 0 to let the system decide (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                            |
| `--bandwidth`                 | bandwidth limitation per second (format: either "unlimited" or bandwidth per second in binary or decimal values: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                              |
| `--failure-domain`            | Add this container to a named failure-domain. A failure-domain will be created if it doesn't exist yet. If not specified, an automatic failure domain will be assigned.                                                                             |
| `--failure-domain-scope`      | Automatic failure domain scope: 'server' (each server is its own FD), 'rack' (switch discovery via LLDP or InfiniBand SMP), or 'chassis' (SMBIOS chassis serial, for multi-node enclosures such as BigTwin) (format: 'server', 'rack' or 'chassis') |
| `-t`, `--timeout`             | Join command timeout in seconds (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                              |
| `--container-id`              | Designate a container-id that will be used when the container joins the cluster                                                                                                                                                                     |
| `--base-port`                 | The first port that will be used by the Weka container, out of a total of 100 ports.                                                                                                                                                                |
| `--resources-path`            | Import the container's resources from a file (additional command-line flags specified will override the resources in the file)                                                                                                                      |
| `--weka-version`              | Use the specified version to start the container in                                                                                                                                                                                                 |
| `--fqdn`                      | The Fully Qualified Domain Name (FQDN) to be used by other containers for TLS hostname verification when interacting with the cluster                                                                                                               |
| `--auto-remove-timeout`       | Set the timeout (in seconds) to remove inactive client containers. Applies only with the --client flag.                                                                                                                                             |
| `--nvidia-vf-single-ip`       | Nvidia VFs work as Single IP (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                        |
| `--dedicated-mode`            | Determine whether DPDK networking dedicates a core (full) or not (none). none can only be set when the NIC driver supports it. (format: 'full' or 'none')                                                                                           |
| `--scan-rdma`                 | Scan for unused net devices and add them for RDMA only use. (format: 'off', 'ib', 'eth' or 'all')                                                                                                                                                   |
| `--color`                     | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                    |
| `--core-ids`...               | Specify the ids of weka dedicated cores (may be repeated or comma-separated)                                                                                                                                                                        |
| `--management-ips`...         | New IPs for the management nodes (may be repeated or comma-separated)                                                                                                                                                                               |
| `--join-ips`...               | New IP:port pairs for the management processes. If no port is used the command will use the default Weka port (may be repeated or comma-separated)                                                                                                  |
| `--join-fqdns`...             | FQDN:port pairs for the management processes. If no port is used the command will use the default Weka port (may be repeated or comma-separated)                                                                                                    |
| `--net`...                    | Network specification - /\[ip]/\[bits]/\[gateway], or /rdma-only/\[inet4                                                                                                                                                                            |
| `--management-net`...         | Net interface used to auto configure management IPs (may be repeated or comma-separated)                                                                                                                                                            |
| `--drive-uuids`...            | UUIDs of signed storage drives to be used when the container forms/joins a cluster (may be repeated or comma-separated)                                                                                                                             |
| `--disable`                   | Should the container be created as disabled                                                                                                                                                                                                         |
| `--no-start`                  | Do not start the container after its creation                                                                                                                                                                                                       |
| `--no-frontends`              | Don't allocate frontend nodes                                                                                                                                                                                                                       |
| `--only-drives-cores`         | Create only nodes with a drives role                                                                                                                                                                                                                |
| `--only-compute-cores`        | Create only nodes with a compute role                                                                                                                                                                                                               |
| `--only-frontend-cores`       | Create only nodes with a frontend role                                                                                                                                                                                                              |
| `--only-dataserv-cores`       | Create only nodes with a dataserv role                                                                                                                                                                                                              |
| `--allow-mix-setting`         | Allow specified core-ids even if there are running containers with AUTO core-ids allocation on the same server.                                                                                                                                     |
| `--dedicate`                  | Set the host as weka dedicated                                                                                                                                                                                                                      |
| `--force`                     | Create a new container even if a container with the same name exists, disregarding all safety checks!                                                                                                                                               |
| `--ignore-used-ports`         | Allow container to start even if the required ports are used by other processes                                                                                                                                                                     |
| `--skip-management-ips-check` | Skip The enforcement of management IPs                                                                                                                                                                                                              |
| `--client`                    | Create persistent client container                                                                                                                                                                                                                  |
| `--restricted`                | Restricted client mode functionality only                                                                                                                                                                                                           |
| `--clusterize`                | Form a cluster with the --join-ips supplied                                                                                                                                                                                                         |
| `--scan-drives`               | Scan for signed drives and add them to the cluster during container start                                                                                                                                                                           |
| `-h`, `--help`                | Show help message                                                                                                                                                                                                                                   |

**weka local setup envoy**

Setup a local envoy container

```sh
weka local setup envoy [--name name] [--color color] [--disable] [--no-start] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `-n`, `--name` | The name to give the container                                                   |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--disable`    | Should the container be created as disabled                                      |
| `--no-start`   | Do not start the container after its creation                                    |
| `-h`, `--help` | Show help message                                                                |

**weka local setup ssdproxy**

Setup a local SSD Proxy container

```sh
weka local setup ssdproxy [--name name]
                          [--memory memory]
                          [--max-drives max-drives]
                          [--expected-max-drive-size expected-max-drive-size]
                          [--expected-max-vid-num-per-drive expected-max-vid-num-per-drive]
                          [--base-port base-port]
                          [--color color]
                          [--disable]
                          [--no-start]
                          [--enable-ssdproxy-nginx]
                          [--help]

```

| Parameter                          | Description                                                                                                                                                                                                                       |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-n`, `--name`                     | The name to give the container                                                                                                                                                                                                    |
| `--memory`                         | Memory dedicated to ssdproxy in bytes; overrides auto-calculation from --max-drives/--expected-max-drive-size (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--max-drives`                     | Set max drives supported in proxy up to 40                                                                                                                                                                                        |
| `--expected-max-drive-size`        | Set max drive size for proxy chunkdb memory sizing; ignored when --memory is set (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                              |
| `--expected-max-vid-num-per-drive` | Set max number of VIDs per drive for proxy DPDK memory sizing (default: proxy decides)                                                                                                                                            |
| `--base-port`                      | The first port that will be used by the SSD Proxy container (currently uses 2 ports: base\_port and base\_port+50 for tracing)                                                                                                    |
| `--color`                          | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                  |
| `--disable`                        | Should the container be created as disabled                                                                                                                                                                                       |
| `--no-start`                       | Do not start the container after its creation                                                                                                                                                                                     |
| `--enable-ssdproxy-nginx`          | Enable nginx server for SSD Proxy viewer (default: disabled)                                                                                                                                                                      |
| `-h`, `--help`                     | Show help message                                                                                                                                                                                                                 |

**weka local setup taskmon**

Setup a local taskmon container

```sh
weka local setup taskmon [--color color] [--disable] [--no-start] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--disable`    | Should the container be created as disabled                                      |
| `--no-start`   | Do not start the container after its creation                                    |
| `-h`, `--help` | Show help message                                                                |

**weka local setup telemetry**

Setup a local telemetry container

```sh
weka local setup telemetry [--dependent-container-name dependent-container-name]
                           [--color color]
                           [--disable]
                           [--no-start]
                           [--help]

```

| Parameter                            | Description                                                                      |
| ------------------------------------ | -------------------------------------------------------------------------------- |
| `-dep`, `--dependent-container-name` | The name of the container that the telemetry container depends on                |
| `--color`                            | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--disable`                          | Should the container be created as disabled                                      |
| `--no-start`                         | Do not start the container after its creation                                    |
| `-h`, `--help`                       | Show help message                                                                |

**weka local setup weka**

Setup a local weka container

```sh
weka local setup weka [--name name] [--color color] [--disable] [--no-start] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `-n`, `--name` | The name to give the container                                                   |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--disable`    | Should the container be created as disabled                                      |
| `--no-start`   | Do not start the container after its creation                                    |
| `-h`, `--help` | Show help message                                                                |

#### weka local start

Start a Weka container

```sh
weka local start [--wait-time wait-time]
                 [--color color]
                 [--type type]...
                 [--skip-start-and-enable-dependent]
                 [--help]
                 [<container>]...

```

| Parameter                           | Description                                                                                                       |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| `container`...                      | The container to start                                                                                            |
| `-w`, `--wait-time`                 | How long to wait for the container to start (default: 15m) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`                           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                  |
| `-t`, `--type`...                   | The container types to start (may be repeated or comma-separated)                                                 |
| `--skip-start-and-enable-dependent` | Skip starting and enabling dependent containers when starting containers by name                                  |
| `-h`, `--help`                      | Show help message                                                                                                 |

#### weka local status

Show the status of a Weka container

```sh
weka local status [--color color] [--type type]... [--verbose] [--help] [--json] [<container>]...

```

| Parameter         | Description                                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| `container`...    | The container to display it's status                                             |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-t`, `--type`... | The container types to show (may be repeated or comma-separated)                 |
| `-v`, `--verbose` | Verbose mode                                                                     |
| `-h`, `--help`    | Show help message                                                                |
| `-J`, `--json`    | Format output as JSON                                                            |

#### weka local stop

Stop a Weka container

```sh
weka local stop [--reason reason]
                [--timeout timeout]
                [--color color]
                [--type type]...
                [--force]
                [--help]
                [<container>]...

```

| Parameter         | Description                                                                                                                      |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `container`...    | The container to stop                                                                                                            |
| `--reason`        | The reason weka was stopped, will be presented to the user during 'weka status'                                                  |
| `--timeout`       | Maximum time for CLI to wait for stop operation to complete (default: 2h) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                 |
| `-t`, `--type`... | The container types to stop (may be repeated or comma-separated)                                                                 |
| `-f`, `--force`   | Skip the check for active mounts and perform an ungraceful stop                                                                  |
| `-h`, `--help`    | Show help message                                                                                                                |

#### weka local upgrade

Upgrade a Weka Host Container to its cluster version

```sh
weka local upgrade [--container container]
                   [--target-version target-version]
                   [--upgrade-container-timeout upgrade-container-timeout]
                   [--prepare-container-timeout prepare-container-timeout]
                   [--container-action-timeout container-action-timeout]
                   [--use-requested-action use-requested-action]
                   [--color color]
                   [--allow-not-ready]
                   [--dont-upgrade-agent]
                   [--upgrade-dependents]
                   [--all]
                   [--help]

```

| Parameter                     | Description                                                                                                                                |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| `-C`, `--container`           | The container name                                                                                                                         |
| `-t`, `--target-version`      | Specify a specific target version for upgrade, instead of upgrading to the backend's version.                                              |
| `NOTE - This parameter is`    | DANGEROUS, use with caution. Incorrect usage may cause upgrade failure.                                                                    |
| `--upgrade-container-timeout` | How long to wait for the container to upgrade. default is 120s (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                      |
| `--prepare-container-timeout` | How long to wait for the container to prepare for upgrade. default is 900s (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)          |
| `--container-action-timeout`  | How long to wait for the container action to run before timing out and retrying 30s (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--use-requested-action`      | Use requested action mechanism to drain containers during upgrade (true/false)                                                             |
| `--color`                     | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                           |
| `--allow-not-ready`           | Allow starting local upgrade while the container is not fully up                                                                           |
| `--dont-upgrade-agent`        | Don't upgrade the weka agent                                                                                                               |
| `--upgrade-dependents`        | Upgrade dependent containers                                                                                                               |
| `--all`                       | Upgrade all containers                                                                                                                     |
| `-h`, `--help`                | Show help message                                                                                                                          |

### weka mount

Mounts a wekafs filesystem. This is the helper utility installed at /sbin/mount.wekafs.

```sh
weka mount <source>
           <target>
           [--option option]
           [--type type]
           [--color color]
           [--no-mtab]
           [--sloppy]
           [--fake]
           [--verbose]
           [--help]
           [--raw-units]
           [--UTC]

```

| Parameter           | Description                                                                                                                       |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `source`\*          | Source filesystem to mount                                                                                                        |
| `target`\*          | Location to mount the source filesystem on                                                                                        |
| `-o`, `--option`    | Mount options                                                                                                                     |
| `-t`, `--type`      | The filesystem type                                                                                                               |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-n`, `--no-mtab`   | Mount without writing in /etc/mtab. This is necessary for example when /etc is on a read-only filesystem                          |
| `-s`, `--sloppy`    | Tolerate sloppy mount options rather than failing                                                                                 |
| `-f`, `--fake`      | Causes everything to be done except for the actual system call                                                                    |
| `-v`, `--verbose`   | Verbose mode                                                                                                                      |
| `-h`, `--help`      | Show help message                                                                                                                 |
| `-R`, `--raw-units` | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`       | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

### weka nfs

Commands that manage client-groups, permissions and interface-groups

```sh
weka nfs [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka nfs client-group

Lists NFS client groups

```sh
weka nfs client-group [--name name]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--help]
                      [--no-header]
                      [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,name,rules (may be repeated or comma-separated)                                                                  |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs client-group add**

Create an NFS client group

```sh
weka nfs client-group add <name>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--format format]
                          [--output output]...
                          [--sort sort]...
                          [--filter filter]...
                          [--filter-color filter-color]...
                          [--help]
                          [--no-header]
                          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,rules (may be repeated or comma-separated)                                                                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs client-group remove**

Delete an NFS client group

```sh
weka nfs client-group remove <name>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--force]
                             [--help]

```

| Parameter                 | Description                                                                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                        |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected NFS clients and can be undone by re-creating the client group. |
| `-h`, `--help`            | Show help message                                                                                                                                               |

#### weka nfs clients

NFS Clients usage information

```sh
weka nfs clients [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs clients show**

Show NFS Clients usage information. If no options are given, all NFS Ganesha containers will be selected.

```sh
weka nfs clients show [--interface-group interface-group]
                      [--container-id container-id]
                      [--fip fip]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--fsnames fsnames]...
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--help]
                      [--no-header]
                      [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                  |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--interface-group`       | interface-group-name                                                                                                                                                                                         |
| `--container-id`          | container-id                                                                                                                                                                                                 |
| `--fip`                   | floating-ip                                                                                                                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                     |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                         |
| `--fsnames`...            | A comma-separated list of filesystems. If no options are given, all NFS exported filesystems will be selected. (may be repeated or comma-separated)                                                          |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: hostid,fsname,client\_ip,idle\_time,num\_v3\_ops,num\_v4\_ops,num\_v4\_open\_ops,num\_v4\_close\_ops (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                      |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                        |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                     |
| `-h`, `--help`            | Show help message                                                                                                                                                                                            |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                           |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                   |

#### weka nfs debug-level

Manage debug level for nfs servers.

```sh
weka nfs debug-level [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs debug-level list**

Lists nfs server supported components/levels for setting debug levels.

```sh
weka nfs debug-level list <what>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--format format]
                          [--output output]...
                          [--sort sort]...
                          [--filter filter]...
                          [--filter-color filter-color]...
                          [--full-list]
                          [--help]
                          [--no-header]
                          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `what`\*                  | The debug level list, can be one of these: components, levels                                                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name (may be repeated or comma-separated)                                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `--full-list`             | Show the full list of names (default: false)                                                                                                                                            |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs debug-level set**

Set debug level for nfs servers. Set to default (EVENT) when finished debugging.

```sh
weka nfs debug-level set <level>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--nfs-hosts nfs-hosts]...
                         [--nfs-components nfs-components]...
                         [--full-list]
                         [--help]

```

| Parameter                 | Description                                                                                                                           |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| `level`\*                 | The debug level, can be one of supported levels                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                              |
| `--nfs-hosts`...          | Only return these host IDs (pass weka's host id as a number). All hosts as default (may be repeated or comma-separated)               |
| `--nfs-components`...     | Only return these component levels (pass component names as a string). All components as default (may be repeated or comma-separated) |
| `--full-list`             | Select the full list of components if no component is selected (default: false)                                                       |
| `-h`, `--help`            | Show help message                                                                                                                     |

**weka nfs debug-level show**

Get debug level for nfs servers.

```sh
weka nfs debug-level show [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--format format]
                          [--nfs-hosts nfs-hosts]...
                          [--nfs-components nfs-components]...
                          [--output output]...
                          [--sort sort]...
                          [--filter filter]...
                          [--filter-color filter-color]...
                          [--full-list]
                          [--help]
                          [--no-header]
                          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `--nfs-hosts`...          | Only return these host IDs (pass weka's host id as a number). All hosts as default (may be repeated or comma-separated)                                                                 |
| `--nfs-components`...     | Only return these component levels (pass component names as a string). All components as default (may be repeated or comma-separated)                                                   |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: host,debugLevel,component (may be repeated or comma-separated)                                                       |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `--full-list`             | Select the full list of components if no component is selected (default: false)                                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka nfs global-config

NFS Global Configuration

```sh
weka nfs global-config [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs global-config set**

Set NFS global configuration options

```sh
weka nfs global-config set [--mountd-port mountd-port]
                           [--config-fs config-fs]
                           [--force-config-fs force-config-fs]
                           [--direct-io direct-io]
                           [--lockmgr-port lockmgr-port]
                           [--statmon-port statmon-port]
                           [--notify-port notify-port]
                           [--acl acl]
                           [--default-acl-type default-acl-type]
                           [--extended-stats extended-stats]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--default-supported-versions default-supported-versions]...
                           [--enable-auth-types enable-auth-types]...
                           [--no-restart]
                           [--help]
                           [--force]

```

| Parameter                         | Description                                                                                                                                                                                 |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--mountd-port`                   | Configure the port number of the mountd service                                                                                                                                             |
| `--config-fs`                     | config filesystem name, use "" to invalidate                                                                                                                                                |
| `--force-config-fs`               | forces config-fs update when locking is enabled (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                             |
| `--direct-io`                     | disable both readcache and writecache for reads and writes (default: true) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                  |
| `--lockmgr-port`                  | The alternate port for the nfs lock manager (default: 0 means any available port)                                                                                                           |
| `--statmon-port`                  | The alternate port for the nfs status monitor (default: 0 means any available port)                                                                                                         |
| `--notify-port`                   | The alternate port for notification used in NFSv3 (default: 0 means any available port)                                                                                                     |
| `--acl`                           | Enables or disables NFSv4 ACL support (default: On) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                         |
| `--default-acl-type`              | Specifies the default ACL type. Options are none, posix, nfsv4, or hybrid (default: posix) (format: 'none', 'posix', 'nfsv4' or 'hybrid')                                                   |
| `--extended-stats`                | enable or disable NFS stats collection for each client and permission (default: On) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                         |
| `--color`                         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                            |
| `-H`, `--HOST`                    | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                            |
| `-P`, `--PORT`                    | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT`         | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `-T`, `--TIMEOUT`                 | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                      |
| `--profile`                       | Name of the connection and authentication profile to use                                                                                                                                    |
| `--default-supported-versions`... | A comma-separated list of the default supported NFS versions for new permissions (format: 'v3' or 'v4', may be repeated or comma-separated)                                                 |
| `--enable-auth-types`...          | A comma-separated list of NFS authentication types -- none, sys, krb5, krb5i, krb5p for permissions (format: 'none', 'sys', 'krb5', 'krb5i' or 'krb5p', may be repeated or comma-separated) |
| `--no-restart`                    | Prevents the restart of NFS-W containers when applying changes (default: false)                                                                                                             |
| `-h`, `--help`                    | Show help message                                                                                                                                                                           |
| `-f`, `--force`                   | Force this action without further confirmation. This may cause a temporary disruption in the NFS service.                                                                                   |

**weka nfs global-config show**

Show the NFS global configuration

```sh
weka nfs global-config show [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka nfs interface-group

List interface groups

```sh
weka nfs interface-group [--name name]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--format format]
                         [--output output]...
                         [--sort sort]...
                         [--filter filter]...
                         [--filter-color filter-color]...
                         [--help]
                         [--no-header]
                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,name,mask,gateway,type,status,ips,ports,allowManageGids (may be repeated or comma-separated)                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs interface-group add**

Create an interface group

```sh
weka nfs interface-group add <name>
                             <type>
                             [--subnet subnet]
                             [--gateway gateway]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--format format]
                             [--output output]...
                             [--sort sort]...
                             [--filter filter]...
                             [--filter-color filter-color]...
                             [--help]
                             [--no-header]
                             [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                                                    |
| `type`\*                  | Group type. cli subnet type can be NFS                                                                                                                                                  |
| `--subnet`                | subnet mask in the 255.255.0.0 format                                                                                                                                                   |
| `--gateway`               | gateway ip                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,mask,gateway,type,status,ips,ports,allowManageGids (may be repeated or comma-separated)                         |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs interface-group assignment**

List the currently assigned interface for each floating-IP address in the given interface-group. If is not supplied, assignments for all floating-IP addresses will be listed

```sh
weka nfs interface-group assignment [--name name]
                                    [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--format format]
                                    [--output output]...
                                    [--sort sort]...
                                    [--filter filter]...
                                    [--filter-color filter-color]...
                                    [--help]
                                    [--no-header]
                                    [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Group name                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: ip,host,port,group (may be repeated or comma-separated)                                                              |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs interface-group remove**

Delete an interface group

```sh
weka nfs interface-group remove <name>
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--force]
                                [--help]

```

| Parameter                 | Description                                                                                                                                                        |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `name`\*                  | Interface group name                                                                                                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                           |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected NFS clients and can be undone by re-creating the interface group. |
| `-h`, `--help`            | Show help message                                                                                                                                                  |

**weka nfs interface-group ip-range**

Commands that manage nfs interface-groups' ip-ranges

```sh
weka nfs interface-group ip-range [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs interface-group ip-range add**

Add an ip range to an interface group

```sh
weka nfs interface-group ip-range add <name>
                                      <ips>
                                      [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `ips`\*                   | IP range                                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs interface-group ip-range remove**

Delete an ip range from an interface group

```sh
weka nfs interface-group ip-range remove <name>
                                         <ips>
                                         [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--force]
                                         [--help]

```

| Parameter                 | Description                                                                                                                                                 |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                        |
| `ips`\*                   | IP range                                                                                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                    |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected NFS clients and can be undone by re-creating the IP range. |
| `-h`, `--help`            | Show help message                                                                                                                                           |

**weka nfs interface-group port**

Commands that manage nfs interface-groups' ports

```sh
weka nfs interface-group port [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs interface-group port add**

Add a server port to an interface group

```sh
weka nfs interface-group port add <name>
                                  <server-id>
                                  <port>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `server-id`\*             | Server ID on which the port resides                                                                        |
| `port`\*                  | Port's device. (e.g. eth1)                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs interface-group port remove**

Delete a server port from an interface group

```sh
weka nfs interface-group port remove <name>
                                     <server-id>
                                     <port>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--force]
                                     [--help]

```

| Parameter                 | Description                                                                                                                                           |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                                                                  |
| `server-id`\*             | Server ID on which the port resides                                                                                                                   |
| `port`\*                  | Port's device. (e.g. eth1)                                                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                                              |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected NFS clients and can be undone by re-adding the port. |
| `-h`, `--help`            | Show help message                                                                                                                                     |

**weka nfs interface-group update**

Update an interface group

```sh
weka nfs interface-group update <name>
                                [--subnet subnet]
                                [--gateway gateway]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Interface group name                                                                                       |
| `--subnet`                | subnet mask in the 255.255.0.0 format                                                                      |
| `--gateway`               | gateway ip                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka nfs kerberos

NFS Kerberos Commands

```sh
weka nfs kerberos [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs kerberos registration**

NFS Kerberos service registration

```sh
weka nfs kerberos registration [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs kerberos registration setup-ad**

Register NFS Kerberos service with Microsoft Active Directory. Running this command with the `restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs kerberos registration setup-ad <nfs-service-name>
                                        <realm-admin-name>
                                        [realm-admin-passwd]
                                        [--base-ou base-ou]
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--force]
                                        [--restart]
                                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `nfs-service-name`\*      | NFS FQDN Service Name (Maximum 20 characters for hostname in FQDN                                          |
| `realm-admin-name`\*      | KDC Realm Admin Name                                                                                       |
| `realm-admin-passwd`      | KDC Realm Admin password                                                                                   |
| `--base-ou`               | LDAP base OU to use when creating an account e.g. OU=Weka,OU=Servers (default: CN=Computers)               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when the service is already registered (default: false)                                  |
| `--restart`               | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs kerberos registration setup-mit**

Register NFS Kerberos service with MIT KDC. Running this command with the `restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs kerberos registration setup-mit <nfs-service-name>
                                         <keytab-file>
                                         [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--force]
                                         [--restart]
                                         [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `nfs-service-name`\*      | NFS FQDN Service Name                                                                                      |
| `keytab-file`\*           | Path to keytab file                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when the service is already registered (default: false)                                  |
| `--restart`               | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs kerberos registration show**

Show NFS Kerberos service registration information

```sh
weka nfs kerberos registration show [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--format format]
                                    [--output output]...
                                    [--sort sort]...
                                    [--filter filter]...
                                    [--filter-color filter-color]...
                                    [--help]
                                    [--no-header]
                                    [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: nfs\_service\_name,kdc\_type,generation\_id,registration\_status (may be repeated or comma-separated)                |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka nfs kerberos reset**

Wipe out NFS Kerberos Service configuration information. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs kerberos reset [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--force]
                        [--no-restart]
                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action without further confirmation (default: false)                                            |
| `--no-restart`            | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs kerberos service**

NFS Kerberos service

```sh
weka nfs kerberos service [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs kerberos service setup**

Setup the NFS Kerberos Service information. Running this command with the `restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs kerberos service setup <kdc-realm-name>
                                <kdc-primary-server>
                                <kdc-admin-server>
                                [--kdc-secondary-server kdc-secondary-server]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--force]
                                [--restart]
                                [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `kdc-realm-name`\*        | KDC Realm Name                                                                                             |
| `kdc-primary-server`\*    | KDC Primary Server                                                                                         |
| `kdc-admin-server`\*      | KDC Admin Server                                                                                           |
| `--kdc-secondary-server`  | KDC Secondary Server                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when the service is already configured (default: false)                                  |
| `--restart`               | Restart the NFS-W containers to apply changes (default: false)                                             |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs kerberos service show**

Show NFS Kerberos service setup information

```sh
weka nfs kerberos service show [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--format format]
                               [--output output]...
                               [--sort sort]...
                               [--filter filter]...
                               [--filter-color filter-color]...
                               [--help]
                               [--no-header]
                               [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                        |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                           |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                               |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: realm\_name,primary\_server,secondary\_server,admin\_server,generation\_id,service\_status (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+            |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                              |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                                                                                  |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                 |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                         |

#### weka nfs ldap

NFS LDAP Commands

```sh
weka nfs ldap [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs ldap export-openldap**

Export in use configuration information for NFS to use OpenLDAP.

```sh
weka nfs ldap export-openldap <server-name>
                              <ldap-domain>
                              <sssd-conf-file>
                              <idmapd-conf-file>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `server-name`\*           | OpenLDAP Server Name                                                                                       |
| `ldap-domain`\*           | OpenLDAP Domain                                                                                            |
| `sssd-conf-file`\*        | Path to sssd configuration file                                                                            |
| `idmapd-conf-file`\*      | Path to idmapd configuration file                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap import-openldap**

Import configuration information for NFS to use OpenLDAP. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs ldap import-openldap <server-name>
                              <ldap-domain>
                              <sssd-conf-file>
                              <idmapd-conf-file>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--verify]
                              [--force]
                              [--no-restart]
                              [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `server-name`\*           | OpenLDAP Server Name                                                                                       |
| `ldap-domain`\*           | OpenLDAP Domain                                                                                            |
| `sssd-conf-file`\*        | Path to sssd configuration file                                                                            |
| `idmapd-conf-file`\*      | Path to idmapd configuration file                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--verify`                | verify connectivity with the OpenLDAP server (default: false)                                              |
| `--force`                 | Force this action when OpenLDAP client is already setup (default: false)                                   |
| `--no-restart`            | Don't restart NFS-W containers to apply changes (default: false)                                           |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap reset**

Wipe out NFS LDAP configuration information, This action may disrupt IO service for connected NFS clients if used without no-restart option

```sh
weka nfs ldap reset [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--force]
                    [--no-restart]
                    [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action without further confirmation (default: false)                                            |
| `--no-restart`            | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap setup-ad**

Setup configuration information for NFS to use Active Directory LDAP. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs ldap setup-ad [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--force]
                       [--no-restart]
                       [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when Active Directory LDAP client is already setup (default: false)                      |
| `--no-restart`            | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap setup-ad-nokrb**

Setup configuration information for NFS to use Active Directory LDAP for ACL only when kerberos is not used. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs ldap setup-ad-nokrb <server-name>
                             <ldap-domain>
                             <nfs-service-name>
                             <admin-user-name>
                             [admin-user-password]
                             [--base-ou base-ou]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--force]
                             [--no-restart]
                             [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `server-name`\*           | AD Server Name                                                                                             |
| `ldap-domain`\*           | AD Domain                                                                                                  |
| `nfs-service-name`\*      | NFS FQDN Service Name (Maximum 20 characters for hostname in FQDN                                          |
| `admin-user-name`\*       | AD Admin Name                                                                                              |
| `admin-user-password`     | AD Admin password                                                                                          |
| `--base-ou`               | LDAP base OU to use when creating an account e.g. OU=Weka,OU=Servers (default: CN=Computers)               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when Active Directory LDAP client is already setup (default: false)                      |
| `--no-restart`            | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap setup-onhostldap**

Setup configuration information for NFS to use on host LDAP Client. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs ldap setup-onhostldap <ldap-domain>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--force]
                               [--no-restart]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `ldap-domain`\*           | OnHostLDAPClient Domain                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--force`                 | Force this action when NFS is already setup to use LDAP client configured on host (default: false)         |
| `--no-restart`            | Don't restart the NFS-W containers to apply changes (default: false)                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs ldap setup-openldap**

Setup configuration information for NFS to use OpenLDAP. Running this command without the `no-restart` option can disrupt IO service for connected NFS clients.

```sh
weka nfs ldap setup-openldap <server-name>
                             <ldap-domain>
                             <reader-user-name>
                             [reader-user-password]
                             [--base-dn base-dn]
                             [--ldap-port-number ldap-port-number]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--force]
                             [--no-restart]
                             [--help]

```

| Parameter                   | Description                                                                               |
| --------------------------- | ----------------------------------------------------------------------------------------- |
| `server-name`\*             | OpenLDAP Server Name                                                                      |
| `ldap-domain`\*             | OpenLDAP Domain                                                                           |
| `reader-user-name`\*        | OpenLDAP Reader User Name (DN based name e.g. cn=readonly-user,dc=test,dc=example,dc=com) |
| `reader-user-password`      | OpenLDAP Reader User password                                                             |
| `--base-dn`                 | OpenLDAP Base DN (e.g. dc=myldapdomain,dc=example,dc=com)                                 |
| `--ldap-port-number O`      | penLDAP Port Number (default: 389)                                                        |
| `--color S`                 | pecify whether to use color in output (format: 'auto', 'disabled' or 'enabled')           |
| `-H`, `--HOST S`            | pecify the host. Alternatively, use the WEKA\_HOST env variable                           |
| `-P`, `--PORT S`            | pecify the port. Alternatively, use the WEKA\_PORT env variable                           |
| `-C`, `--CONNECT-TIMEOUT T` | imeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w,     |
| `i`                         | nfinite/unlimited)                                                                        |
| `-T`, `--TIMEOUT T`         | imeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w,         |
| `--profile N`               | ame of the connection and authentication profile to use                                   |
| `--force F`                 | orce this action when OpenLDAP client is already setup (default: false)                   |
| `--no-restart D`            | on't restart NFS-W containers to apply changes (default: false)                           |
| `-h`, `--help S`            | how help message                                                                          |

**weka nfs ldap show**

Show NFS LDAP setup information

```sh
weka nfs ldap show [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--format format]
                   [--output output]...
                   [--sort sort]...
                   [--filter filter]...
                   [--filter-color filter-color]...
                   [--help]
                   [--no-header]
                   [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                               |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                  |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: server\_type,domain,server\_name,server\_port,base\_dn,reader\_name,reader\_password,generation\_id,setup\_status (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                   |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                     |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                  |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                         |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                        |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                |

#### weka nfs permission

List NFS permissions for a filesystem

```sh
weka nfs permission [--filesystem filesystem]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--format format]
                    [--output output]...
                    [--sort sort]...
                    [--filter filter]...
                    [--filter-color filter-color]...
                    [--help]
                    [--no-header]
                    [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                           |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--filesystem`            | File system name                                                                                                                                                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                              |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                  |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,filesystem,group,path,type,squash,auid,agid,obsdirect,manageGids,options,customOptions,privilegedPort,priority,supportedVersions,enabledAuthTypes,aclType (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                               |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                 |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                              |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                     |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                    |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                            |

**weka nfs permission add**

Allow a client group to access a file system

```sh
weka nfs permission add <filesystem>
                        <group>
                        [--path path]
                        [--permission-type permission-type]
                        [--squash squash]
                        [--anon-uid anon-uid]
                        [--anon-gid anon-gid]
                        [--obs-direct obs-direct]
                        [--manage-gids manage-gids]
                        [--privileged-port privileged-port]
                        [--acl-type acl-type]
                        [--force-acl-type force-acl-type]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--supported-versions supported-versions]...
                        [--enable-auth-types enable-auth-types]...
                        [--no-restart]
                        [--force]
                        [--help]
                        [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                      |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | File system name                                                                                                                                                                                                                                                                 |
| `group`\*                 | Client group name                                                                                                                                                                                                                                                                |
| `--path`                  | path \[default: /]                                                                                                                                                                                                                                                               |
| `--permission-type`       | Permission type (format: 'ro' or 'rw')                                                                                                                                                                                                                                           |
| `--squash`                | Permission squashing. NOTE - The option 'all' can be used only on interface groups with --allow-manage-gids=on (format: 'none', 'root' or 'all')                                                                                                                                 |
| `--anon-uid`              | Anonymous UID to be used instead of root when root squashing is enabled                                                                                                                                                                                                          |
| `--anon-gid`              | Anonymous GID to be used instead of root when root squashing is enabled                                                                                                                                                                                                          |
| `--obs-direct`            | Obs direct (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                       |
| `--manage-gids`           | the list of group ids received from the client will be replaced by a list of group ids determined by an appropriate lookup on the server. NOTE - this only works with a interface group which allows manage-gids (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--privileged-port`       | Privileged port (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                  |
| `--acl-type`              | Specifies the ACL type. Options include none, posix, nfsv4, and hybrid. Default is determined by the NFS global configuration (format: 'none', 'posix', 'nfsv4' or 'hybrid')                                                                                                     |
| `--force-acl-type`        | Forces a change to the ACL type for existing permissions on the same filesystem (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                         |
| `--supported-versions`... | A comma-separated list of supported NFS versions (format: 'v3' or 'v4', may be repeated or comma-separated)                                                                                                                                                                      |
| `--enable-auth-types`...  | A comma-separated list of NFS authentication types -- none, sys, krb5, krb5i, krb5p (format: 'none', 'sys', 'krb5', 'krb5i' or 'krb5p', may be repeated or comma-separated)                                                                                                      |
| `--no-restart`            | Prevents the restart of NFS-W containers when applying changes (default: false), null, No.HideFromUsage                                                                                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. This action will affect all NFS users of this permission/export, Use it with caution and consult the Weka Customer Success team at need.                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                                            |

**weka nfs permission remove**

Delete a file system permission

```sh
weka nfs permission remove <filesystem>
                           <group>
                           [--path path]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--force]
                           [--help]

```

| Parameter                 | Description                                                                                                                                                              |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `filesystem`\*            | File system name                                                                                                                                                         |
| `group`\*                 | Client group name                                                                                                                                                        |
| `--path`                  | path \[default: /]                                                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                         |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                         |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                         |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                               |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                   |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                 |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected NFS clients and can be undone by re-creating the filesystem permission. |
| `-h`, `--help`            | Show help message                                                                                                                                                        |

**weka nfs permission update**

Edit a file system permission

```sh
weka nfs permission update <filesystem>
                           <group>
                           [--path path]
                           [--permission-type permission-type]
                           [--squash squash]
                           [--anon-uid anon-uid]
                           [--anon-gid anon-gid]
                           [--obs-direct obs-direct]
                           [--manage-gids manage-gids]
                           [--custom-options custom-options]
                           [--privileged-port privileged-port]
                           [--acl-type acl-type]
                           [--force-acl-type force-acl-type]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--supported-versions supported-versions]...
                           [--enable-auth-types enable-auth-types]...
                           [--force]
                           [--no-restart]
                           [--help]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                      |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `filesystem`\*            | File system name                                                                                                                                                                                                                                                                 |
| `group`\*                 | Client group name                                                                                                                                                                                                                                                                |
| `--path`                  | path \[default: /]                                                                                                                                                                                                                                                               |
| `--permission-type`       | Permission type (format: 'ro' or 'rw')                                                                                                                                                                                                                                           |
| `--squash`                | Permission squashing. NOTE - The option 'all' can be used only on interface groups with --allow-manage-gids=on (format: 'none', 'root' or 'all')                                                                                                                                 |
| `--anon-uid`              | Anonymous UID to be used instead of root when root squashing is enabled                                                                                                                                                                                                          |
| `--anon-gid`              | Anonymous GID to be used instead of root when root squashing is enabled                                                                                                                                                                                                          |
| `--obs-direct`            | Obs direct (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                       |
| `--manage-gids`           | the list of group ids received from the client will be replaced by a list of group ids determined by an appropriate lookup on the server. NOTE - this only works with a interface group which allows manage-gids (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--custom-options`        | Custom export options                                                                                                                                                                                                                                                            |
| `--privileged-port`       | Privileged port (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                  |
| `--acl-type`              | Specifies the ACL type. Options include none, posix, nfsv4, and hybrid. Default is determined by the NFS global configuration (format: 'none', 'posix', 'nfsv4' or 'hybrid')                                                                                                     |
| `--force-acl-type`        | Forces a change to the ACL type for existing permissions on the same filesystem (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                         |
| `--supported-versions`... | A comma-separated list of supported NFS versions (format: 'v3' or 'v4', may be repeated or comma-separated)                                                                                                                                                                      |
| `--enable-auth-types`...  | A comma-separated list of NFS authentication types -- none, sys, krb5, krb5i, krb5p (format: 'none', 'sys', 'krb5', 'krb5i' or 'krb5p', may be repeated or comma-separated)                                                                                                      |
| `--force`                 | Force this action without further confirmation                                                                                                                                                                                                                                   |
| `--no-restart`            | Prevents the restart of NFS-W containers when applying changes (default: false), null, No.HideFromUsage                                                                                                                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                |

#### weka nfs rules

Commands that manage NFS-rules

```sh
weka nfs rules [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs rules add**

Commands that add NFS-rules

```sh
weka nfs rules add [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs rules add dns**

Add a DNS rule to an NFS client group

```sh
weka nfs rules add dns <name>
                       <dns>
                       [--ip ip]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--help]
                       [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `dns`\*                   | DNS rule with \*?\[] wildcards rule                                                                        |
| `--ip`                    | IP with netmask or CIDR rule, in the 1.1.1.1/255.255.0.0 or 1.1.1.1/16 format                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka nfs rules add ip**

Add an IP rule to an NFS client group

```sh
weka nfs rules add ip <name>
                      <ip>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `ip`\*                    | IP with netmask or CIDR rule, in the 1.1.1.1/255.255.0.0 or 1.1.1.1/16 format                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka nfs rules remove**

Commands for deleting NFS-rules

```sh
weka nfs rules remove [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka nfs rules remove dns**

Delete a DNS rule from an NFS client group

```sh
weka nfs rules remove dns <name>
                          <dns>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `dns`\*                   | DNS rule with \*?\[] wildcards rule                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka nfs rules remove ip**

Delete an IP rule from an NFS client group

```sh
weka nfs rules remove ip <name>
                         <ip>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `ip`\*                    | IP with netmask or CIDR rule, in the 1.1.1.1/255.255.0.0 or 1.1.1.1/16 format                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka s3

Commands that manage Weka's S3 container

```sh
weka s3 [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka s3 bucket

S3 Cluster Bucket Commands

```sh
weka s3 bucket [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket add**

Create an S3 bucket

```sh
weka s3 bucket add <name>
                   [--policy policy]
                   [--policy-json policy-json]
                   [--hard-quota hard-quota]
                   [--existing-path existing-path]
                   [--fs-name fs-name]
                   [--fs-id fs-id]
                   [--type type]
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--object-locking-on]
                   [--force]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | bucket name to create                                                                                                                                                                                                                                                                                                                                                   |
| `--policy`                | Set an existing S3 policy for a bucket                                                                                                                                                                                                                                                                                                                                  |
| `--policy-json`           | Get S3 policy for bucket in JSON format                                                                                                                                                                                                                                                                                                                                 |
| `--hard-quota`            | Hard limit for the directory (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                                                                                                        |
| `--existing-path`         | existing path                                                                                                                                                                                                                                                                                                                                                           |
| `--fs-name`               | file system name                                                                                                                                                                                                                                                                                                                                                        |
| `--fs-id`                 | file system id                                                                                                                                                                                                                                                                                                                                                          |
| `--type`                  | Specifies the bucket type (default: STANDARD). STANDARD: A standard S3 bucket with full S3 compatibility. PERFORMANCE: A bucket optimized for high throughput and low latency. This type disables or modifies performance-intensive features like MD5 ETag generation, client integrity checks, and lexicographical LIST sorting. (format: 'standard' or 'performance') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                                |
| `--object-locking-on`     | Enable S3 Object Lock on the bucket (creation-time only; requires cluster-wide versioning support)                                                                                                                                                                                                                                                                      |
| `-f`, `--force`           | Force when existing-path has quota                                                                                                                                                                                                                                                                                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                                                       |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                                                                                                                                   |

**weka s3 bucket remove**

Destroy an S3 bucket

```sh
weka s3 bucket remove <name>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--unlink]
                      [--help]
                      [--json]
                      [--force]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | bucket name to destroy                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `--unlink`                | unlinks the bucket, but leave the data directory in place                                                     |
| `-h`, `--help`            | Show help message                                                                                             |
| `-J`, `--json`            | Format output as JSON                                                                                         |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected S3 clients.. |

**weka s3 bucket etag-alg**

Commands to manage ETag algorithm for a specific S3 Performance Bucket

```sh
weka s3 bucket etag-alg [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket etag-alg reset**

Reset the ETag algorithm for a specific S3 Performance Bucket to the global default setting. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket etag-alg reset <bucket-name>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]
                              [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 bucket etag-alg set**

Set the ETag algorithm for a specific S3 Performance Bucket, overriding the global default. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket etag-alg set <bucket-name>
                            <algorithm>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]
                            [--force]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                                           |
| `algorithm`\*             | ETag algorithm. md5: Standard, computes an MD5 hash (slower). uid: Generates a unique ID (faster, avoids hashing). (format: 'md5' or 'uid') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                           |
| `-J`, `--json`            | Format output as JSON                                                                                                                       |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance.              |

**weka s3 bucket integrity-mode**

Commands to manage integrity handling for a specific S3 Performance Bucket

```sh
weka s3 bucket integrity-mode [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket integrity-mode reset**

Reset the integrity handling for a specific S3 Performance Bucket to the global default setting. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket integrity-mode reset <bucket-name>
                                    [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--help]
                                    [--json]
                                    [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 bucket integrity-mode set**

Set the integrity handling for a specific S3 Performance Bucket, overriding the global default. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket integrity-mode set <bucket-name>
                                  <mode>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]
                                  [--force]

```

| Parameter                 | Description                                                                                                                                                                                                                  |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                                                                                                                            |
| `mode`\*                  | Integrity handling mode. client\_defined: Respects client checksum validation requests (standard behavior). disabled: Ignores client checksum requests (faster, reduces overhead). (format: 'client\_defined' or 'disabled') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                             |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                             |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                             |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                   |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                       |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                     |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                            |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                        |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance.                                                                                               |

**weka s3 bucket lifecycle-rule**

S3 Bucket Lifecycle

```sh
weka s3 bucket lifecycle-rule [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket lifecycle-rule add**

Add a lifecycle rule to an S3 Bucket

```sh
weka s3 bucket lifecycle-rule add <bucket>
                                  <expiry-days>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--prefix prefix]
                                  [--tags tags]
                                  [--help]
                                  [--json]
                                  [--noncurrent]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                             |
| `expiry-days`\*           | expiry days                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--prefix`                | prefix                                                                                                     |
| `--tags`                  | object tags                                                                                                |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `--noncurrent`            | apply expiry to noncurrent object versions only (not current versions)                                     |

**weka s3 bucket lifecycle-rule list**

List all lifecycle rules of an S3 bucket

```sh
weka s3 bucket lifecycle-rule list <bucket>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--format format]
                                   [--output output]...
                                   [--sort sort]...
                                   [--filter filter]...
                                   [--filter-color filter-color]...
                                   [--help]
                                   [--no-header]
                                   [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                                                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,expiry\_days,expiry\_date,noncurrent,prefix,tags (may be repeated or comma-separated)                             |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 bucket lifecycle-rule remove**

Remove a lifecycle rule from an S3 bucket

```sh
weka s3 bucket lifecycle-rule remove <bucket>
                                     <name>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--help]
                                     [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                             |
| `name`\*                  | rule name                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket lifecycle-rule reset**

Reset all lifecycle rules of an S3 bucket

```sh
weka s3 bucket lifecycle-rule reset <bucket>
                                    [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--help]
                                    [--json]
                                    [--force]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `-f`, `--force`           | Force this action without further confirmation. This action will delete the existing S3 bucket rules.      |

**weka s3 bucket list**

Show all the buckets on the S3 cluster

```sh
weka s3 bucket list [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--format format]
                    [--output output]...
                    [--sort sort]...
                    [--filter filter]...
                    [--filter-color filter-color]...
                    [--help]
                    [--raw-units]
                    [--UTC]
                    [--no-header]
                    [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                   |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                       |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,hard,used,path,fs,bucket\_type,etag,integrity,sorting,bucketVersioningState,objectLockEnabled (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                    |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                      |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                   |
| `-h`, `--help`            | Show help message                                                                                                                                                                                          |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                          |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                      |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                         |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                 |

**weka s3 bucket notification**

S3 bucket notification commands

```sh
weka s3 bucket notification [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket notification add**

Add an S3 Bucket Notification Target

```sh
weka s3 bucket notification add <bucket>
                                [--target-type target-type]
                                [--target-name target-name]
                                [--events events]
                                [--filter-prefix filter-prefix]
                                [--filter-suffix filter-suffix]
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]
                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                             |
| `--target-type`           | S3 Bucket Notification Target Type                                                                         |
| `--target-name`           | S3 Bucket Notification Target Name                                                                         |
| `--events`                | A comma-separated list of events to generate                                                               |
| `--filter-prefix`         | Filter prefix for object names to report                                                                   |
| `--filter-suffix`         | Filter suffix for object names to report                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket notification list**

Show all Notification targets for the S3 bucket

```sh
weka s3 bucket notification list <bucket>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--format format]
                                 [--output output]...
                                 [--sort sort]...
                                 [--filter filter]...
                                 [--filter-color filter-color]...
                                 [--help]
                                 [--no-header]
                                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                                                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: target\_type,target\_name,events,filter\_prefix,filter\_suffix (may be repeated or comma-separated)                  |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 bucket notification remove**

Remove an S3 Bucket Notification Target

```sh
weka s3 bucket notification remove <bucket>
                                   [--target-type target-type]
                                   [--target-name target-name]
                                   [--events events]
                                   [--filter-prefix filter-prefix]
                                   [--filter-suffix filter-suffix]
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket`\*                | S3 Bucket Name                                                                                             |
| `--target-type`           | S3 Bucket Notification Target Type                                                                         |
| `--target-name`           | S3 Bucket Notification Target Name                                                                         |
| `--events`                | Comma-separated list of events                                                                             |
| `--filter-prefix`         | Filter prefix                                                                                              |
| `--filter-suffix`         | Filter suffix                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket policy**

S3 bucket policy commands

```sh
weka s3 bucket policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket policy get**

Get S3 policy for bucket

```sh
weka s3 bucket policy get <bucket-name>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | full path to bucket to get policy for                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket policy get-json**

Get S3 policy for bucket in JSON format

```sh
weka s3 bucket policy get-json <bucket-name>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | full path to bucket to get policy for                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket policy set**

Set an existing S3 policy for a bucket, Available predefined options are : none|download|upload|public

```sh
weka s3 bucket policy set <bucket-name>
                          <bucket-policy>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | full path to bucket to set policy for                                                                      |
| `bucket-policy`\*         | Set an existing S3 policy. Available predefined options are: none                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket policy set-custom**

Set a custom S3 policy for bucket

```sh
weka s3 bucket policy set-custom <bucket-name>
                                 <policy-file>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]
                                 [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Full path to bucket to set policy for                                                                      |
| `policy-file`\*           | Path of the file containing the policy rules                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket policy reset**

Unset the configured S3 policy for bucket

```sh
weka s3 bucket policy reset <bucket-name>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | full path to bucket to unset the policy for                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket quota**

S3 Bucket Quota, configure the hard limit of bucket disk usage

```sh
weka s3 bucket quota [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket quota set**

Set the hard limit of bucket's disk usage

```sh
weka s3 bucket quota set <name>
                         <hard-quota>
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]

```

| Parameter                 | Description                                                                                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `name`\*                  | bucket name                                                                                                                                      |
| `hard-quota`\*            | Hard limit for the directory (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                |

**weka s3 bucket quota reset**

Remove the hard limit on bucket's disk usage

```sh
weka s3 bucket quota reset <name>
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | bucket name                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 bucket sorting**

Commands to manage LIST operation sorting for a specific S3 Performance Bucket

```sh
weka s3 bucket sorting [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket sorting reset**

Reset the sorting preference for a specific S3 Performance Bucket to the global default setting. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket sorting reset <bucket-name>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]
                             [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 bucket sorting set**

Set the sorting preference for a specific S3 Performance Bucket, overriding the global default. This command only applies to S3 Performance Buckets. To create one, use: weka s3 bucket add --type PERFORMANCE

```sh
weka s3 bucket sorting set <bucket-name>
                           <mode>
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--json]
                           [--force]

```

| Parameter                 | Description                                                                                                                                                                                                          |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Name of the S3 Performance Bucket                                                                                                                                                                                    |
| `mode`\*                  | LIST operation sorting mode. sorted: Returns objects in standard lexicographical order (slower). unsorted: Returns objects as they appear in the filesystem (significantly faster). (format: 'sorted' or 'unsorted') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                     |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                     |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                     |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                           |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                               |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                    |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance.                                                                                       |

**weka s3 bucket versioning**

S3 bucket versioning commands

```sh
weka s3 bucket versioning [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 bucket versioning enable**

Enables versioning for an S3 bucket

```sh
weka s3 bucket versioning enable <bucket-name>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]
                                 [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Bucket name                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket versioning get**

Get the versioning mode of an S3 bucket

```sh
weka s3 bucket versioning get <name>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Bucket name                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 bucket versioning suspend**

Suspends versioning for an S3 bucket

```sh
weka s3 bucket versioning suspend <bucket-name>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `bucket-name`\*           | Bucket name to suspend versioning for                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka s3 cluster

View info about the S3 cluster managed by weka

```sh
weka s3 cluster [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--verbose]
                [--help]
                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-v`, `--verbose`         | Verbose mode                                                                                               |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster audit-webhook**

S3 Cluster Audit Webhook Commands

```sh
weka s3 cluster audit-webhook [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster audit-webhook batch-config**

Configure batch settings for audit webhook without restart

```sh
weka s3 cluster audit-webhook batch-config [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--batch-mode batch-mode]
                                           [--batch-size batch-size]
                                           [--batch-count batch-count]
                                           [--batch-time batch-time]
                                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--batch-mode`            | Batch mode for audit logging (e.g., Splunk)                                                                |
| `--batch-size`            | Batch size for audit logging (bytes)                                                                       |
| `--batch-count`           | Batch count for audit logging (number of events)                                                           |
| `--batch-time`            | Batch time threshold for audit logging (e.g., 500ms)                                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 cluster audit-webhook disable**

Disable the Audit Webhook

```sh
weka s3 cluster audit-webhook disable [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 cluster audit-webhook enable**

Enable/Disable the S3 audit webhook on the S3 Cluster

```sh
weka s3 cluster audit-webhook enable [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--endpoint endpoint]
                                     [--auth-token auth-token]
                                     [--help]
                                     [--verify]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--endpoint`              | The webhook endpoint                                                                                       |
| `--auth-token`            | The webhook authentication token                                                                           |
| `-h`, `--help`            | Show help message                                                                                          |
| `--verify`                | verification to apply configuration                                                                        |

**weka s3 cluster audit-webhook show**

Show the S3 Audit Webhook configuration

```sh
weka s3 cluster audit-webhook show [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster container**

Commands that manage Weka's S3 cluster's containers

```sh
weka s3 cluster container [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster container add**

Add S3 containers to S3 cluster

```sh
weka s3 cluster container add [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | The containers to add to the S3 cluster                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 cluster container list**

Lists containers in S3 cluster

```sh
weka s3 cluster container list [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster container remove**

Remove S3 containers from S3 cluster

```sh
weka s3 cluster container remove [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]
                                 [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | The containers to remove from the S3 cluster                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 cluster add**

Create an S3 cluster managed by weka

```sh
weka s3 cluster add [--default-fs-name default-fs-name]
                    [--port port]
                    [--max-buckets-limit max-buckets-limit]
                    [--anonymous-posix-uid anonymous-posix-uid]
                    [--anonymous-posix-gid anonymous-posix-gid]
                    [--domain domain]
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--container container]...
                    [--all-servers]
                    [--allow-versioning]
                    [--force]
                    [--help]
                    [<config-fs-name>]...

```

| Parameter                 | Description                                                                                                                                                                                                 |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `config-fs-name`...       | S3 config filesystem name                                                                                                                                                                                   |
| `--default-fs-name`       | S3 default filesystem name                                                                                                                                                                                  |
| `--port`                  | S3 service port                                                                                                                                                                                             |
| `--max-buckets-limit`     | Limit the number of buckets that can be created                                                                                                                                                             |
| `--anonymous-posix-uid`   | POSIX UID for anonymous users                                                                                                                                                                               |
| `--anonymous-posix-gid`   | POSIX GID for anonymous users                                                                                                                                                                               |
| `--domain`                | Virtual host-style comma seperated domains                                                                                                                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                    |
| `--container`...          | The containers that will serve via the S3 protocol (pass weka's container ID as a number) (may be repeated or comma-separated)                                                                              |
| `--all-servers`           | Install S3 on all servers                                                                                                                                                                                   |
| `--allow-versioning`      | Enable S3 versioning (default off, cannot be disabled once enabled)                                                                                                                                         |
| `-f`, `--force`           | Force this action without further confirmation. Be aware that this will impact all S3 buckets within the S3 service. Exercise caution and consult the WEKA Customer Success team if assistance is required. |
| `-h`, `--help`            | Show help message                                                                                                                                                                                           |

**weka s3 cluster remove**

Destroy the S3 cluster managed by weka. This will not delete the data, just stop exposing it via S3

```sh
weka s3 cluster remove [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--force]
                       [--help]

```

| Parameter                    | Description                                                                                                                                             |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                        |
| `-H`, `--HOST`               | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                        |
| `-P`, `--PORT`               | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                        |
| `-C`, `--CONNECT-TIMEOUT`    | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                              |
| `-T`, `--TIMEOUT`            | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                  |
| `--profile`                  | Name of the connection and authentication profile to use                                                                                                |
| `-f`, `--force`              | Force this action without further confirmation.                                                                                                         |
| `troying the S3 cluster r`   | emoves the S3 service and its associated configuration, including IAM policies, buckets, and ILM rules. access will no longer be available for clients. |
| `s operation does not aut`   | omatically delete the data stored within the buckets.                                                                                                   |
| `ever`, `internal users wit` | h S3 roles will be permanently removed from the system..                                                                                                |
| `-h`, `--help`               | Show help message                                                                                                                                       |

**weka s3 cluster etag-alg**

Commands to manage ETag algorithm for all S3 Performance Buckets

```sh
weka s3 cluster etag-alg [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster etag-alg reset**

Reset the ETag algorithm for *all* S3 Performance Buckets, forcing them to inherit the cluster's global default

```sh
weka s3 cluster etag-alg reset [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]
                               [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 cluster group**

Manage S3 IAM groups

```sh
weka s3 cluster group [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster group add**

Create a new S3 IAM group

```sh
weka s3 cluster group add <name>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster group list**

List all S3 IAM groups

```sh
weka s3 cluster group list [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--format format]
                           [--output output]...
                           [--sort sort]...
                           [--filter filter]...
                           [--filter-color filter-color]...
                           [--help]
                           [--no-header]
                           [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,policy (may be repeated or comma-separated)                                                                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 cluster group remove**

Delete an S3 IAM group

```sh
weka s3 cluster group remove <name>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Group name                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster integrity-mode**

Commands to manage integrity handling for all S3 Performance Buckets

```sh
weka s3 cluster integrity-mode [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster integrity-mode reset**

Reset the integrity handling mode for *all* S3 Performance Buckets, forcing them to inherit the cluster's global default

```sh
weka s3 cluster integrity-mode reset [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--help]
                                     [--json]
                                     [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 cluster notification-target**

S3 cluster notification-target commands

```sh
weka s3 cluster notification-target [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster notification-target add**

Add an S3 Bucket Notification Target

```sh
weka s3 cluster notification-target add [--type type]
                                        [--name name]
                                        [--topic topic]
                                        [--brokers brokers]
                                        [--kafka-version kafka-version]
                                        [--tls tls]
                                        [--tls-cert tls-cert]
                                        [--tls-skip-verify tls-skip-verify]
                                        [--sasl sasl]
                                        [--sasl-username sasl-username]
                                        [--sasl-password sasl-password]
                                        [--sasl-mechanism sasl-mechanism]
                                        [--queue-dir queue-dir]
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]
                                        [--json]

```

| Parameter                 | Description                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------- |
| `--type`                  | Notification target type                                                                                        |
| `--name`                  | Notification target name                                                                                        |
| `--topic`                 | KAFKA topic for generated messages                                                                              |
| `--brokers`               | List of 1-8 KAFKA brokers to which events will be sent                                                          |
| `--kafka-version`         | Kafka KAFKA topic for generated messages                                                                        |
| `--tls`                   | Enable/disable TLS (default: true) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')              |
| `--tls-cert`              | Certificate object for TLS                                                                                      |
| `--tls-skip-verify`       | Enable/disable TLS skip verify (default: false) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--sasl`                  | Enable/disable SASL (default: false) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')            |
| `--sasl-username`         | SASL username                                                                                                   |
| `--sasl-password`         | SASL password                                                                                                   |
| `--sasl-mechanism`        | SASL mechanism (one of sha512, sha256, or plain; default: plain) (format: 'plain', 'sha256' or 'sha512')        |
| `--queue-dir`             | Queue directory path for storing messages                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)          |
| `--profile`               | Name of the connection and authentication profile to use                                                        |
| `-h`, `--help`            | Show help message                                                                                               |
| `-J`, `--json`            | Format output as JSON                                                                                           |

**weka s3 cluster notification-target cert**

S3 cluster notification-target certificate management commands

```sh
weka s3 cluster notification-target cert [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster notification-target cert add**

Add S3 notification-target certificate

```sh
weka s3 cluster notification-target cert add <cert-name>
                                             [--target-type target-type]
                                             [--client-tls-cert client-tls-cert]
                                             [--client-tls-key client-tls-key]
                                             [--color color]
                                             [--HOST HOST]
                                             [--PORT PORT]
                                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                             [--TIMEOUT TIMEOUT]
                                             [--profile profile]
                                             [--help]
                                             [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `cert-name`\*             | Certificate object name                                                                                    |
| `--target-type`           | Notification target type                                                                                   |
| `--client-tls-cert`       | File containing client certificate                                                                         |
| `--client-tls-key`        | File containing client private key                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster notification-target cert list**

Show S3 notification-target certificates

```sh
weka s3 cluster notification-target cert list [--target-type target-type]
                                              [--color color]
                                              [--HOST HOST]
                                              [--PORT PORT]
                                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                              [--TIMEOUT TIMEOUT]
                                              [--profile profile]
                                              [--format format]
                                              [--output output]...
                                              [--sort sort]...
                                              [--filter filter]...
                                              [--filter-color filter-color]...
                                              [--help]
                                              [--no-header]
                                              [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--target-type`           | Notification target type                                                                                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name (may be repeated or comma-separated)                                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 cluster notification-target cert remove**

Remove S3 notification-target certificate

```sh
weka s3 cluster notification-target cert remove <cert-name>
                                                [--target-type target-type]
                                                [--color color]
                                                [--HOST HOST]
                                                [--PORT PORT]
                                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                                [--TIMEOUT TIMEOUT]
                                                [--profile profile]
                                                [--help]
                                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `cert-name`\*             | Certificate object name                                                                                    |
| `--target-type`           | Notification target type                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster notification-target list**

Show all Bucket Notification targets for the cluster

```sh
weka s3 cluster notification-target list [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--format format]
                                         [--output output]...
                                         [--sort sort]...
                                         [--filter filter]...
                                         [--filter-color filter-color]...
                                         [--help]
                                         [--no-header]
                                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name,topic,brokers (may be repeated or comma-separated)                                                              |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 cluster notification-target remove**

Remove an S3 Bucket Notification Target

```sh
weka s3 cluster notification-target remove [--type type]
                                           [--name name]
                                           [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--force]
                                           [--help]
                                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--type`                  | Notification target type                                                                                   |
| `--name`                  | notification target name                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-f`, `--force`           | Force this action without further confirmation.                                                            |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster notification-target show**

Show the details of a Bucket Notification Target

```sh
weka s3 cluster notification-target show [--type type]
                                         [--name name]
                                         [--color color]
                                         [--HOST HOST]
                                         [--PORT PORT]
                                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                         [--TIMEOUT TIMEOUT]
                                         [--profile profile]
                                         [--help]
                                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--type`                  | Notification target type                                                                                   |
| `--name`                  | Notification target name                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster notification-target status**

Show all Bucket Notification status per target for the entire cluster

```sh
weka s3 cluster notification-target status [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--format format]
                                           [--output output]...
                                           [--sort sort]...
                                           [--filter filter]...
                                           [--filter-color filter-color]...
                                           [--help]
                                           [--no-header]
                                           [--verbose]

```

| Parameter                 | Description                                                                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                  |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: host\_id,name,topic,queue\_percentage,kafka\_lost\_events,kafka\_failures\_events (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+   |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                     |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                  |
| `-h`, `--help`            | Show help message                                                                                                                                                                         |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                        |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                |

**weka s3 cluster notification-target update**

Update an S3 Bucket Notification Target

```sh
weka s3 cluster notification-target update [--type type]
                                           [--name name]
                                           [--brokers brokers]
                                           [--topic topic]
                                           [--kafka-version kafka-version]
                                           [--tls tls]
                                           [--tls-cert tls-cert]
                                           [--tls-skip-verify tls-skip-verify]
                                           [--sasl sasl]
                                           [--sasl-username sasl-username]
                                           [--sasl-password sasl-password]
                                           [--sasl-mechanism sasl-mechanism]
                                           [--queue-dir queue-dir]
                                           [--color color]
                                           [--HOST HOST]
                                           [--PORT PORT]
                                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                           [--TIMEOUT TIMEOUT]
                                           [--profile profile]
                                           [--help]
                                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--type`                  | Notification target type                                                                                   |
| `--name`                  | notification target name                                                                                   |
| `--brokers`               | List of 1-8 KAFKA brokers to which events will be sent                                                     |
| `--topic`                 | KAFKA topic for generated messages                                                                         |
| `--kafka-version`         | Kafka KAFKA topic for generated messages                                                                   |
| `--tls`                   | Enable/disable TLS (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                         |
| `--tls-cert`              | Certificate object for TLS                                                                                 |
| `--tls-skip-verify`       | Enable/disable TLS skip verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')             |
| `--sasl`                  | Enable/disable SASL (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                        |
| `--sasl-username`         | SASL username                                                                                              |
| `--sasl-password`         | SASL password                                                                                              |
| `--sasl-mechanism`        | SASL mechanism (format: 'plain', 'sha256' or 'sha512')                                                     |
| `--queue-dir`             | Queue directory path for storing messages                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster oidc**

Manage OIDC (OpenID Connect) configuration for S3 authentication (e.g., Entra ID)

```sh
weka s3 cluster oidc [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster oidc add**

Configure OIDC (OpenID Connect) authentication for S3, enabling integration with identity providers like Microsoft Entra ID or Keycloak

```sh
weka s3 cluster oidc add [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--config-url config-url]
                         [--type type]
                         [--claim-name claim-name]
                         [--client-id client-id]
                         [--groups-claim-name groups-claim-name]
                         [--client-secret client-secret]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--config-url`            | OIDC Configuration URL (required for JWT validation)                                                       |
| `--type`                  | Identity provider type (generic, azure, keycloak) (format: 'generic', 'azure' or 'keycloak')               |
| `--claim-name`            | JWT claim name for policy mapping (default: roles)                                                         |
| `--client-id`             | OIDC client ID                                                                                             |
| `--groups-claim-name`     | JWT claim name for groups (default: groups)                                                                |
| `--client-secret`         | Client secret (required for type=azure)                                                                    |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster oidc remove**

Remove OIDC configuration from the S3 cluster

```sh
weka s3 cluster oidc remove [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster oidc show**

Display the OIDC configuration

```sh
weka s3 cluster oidc show [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster oidc update**

Update existing OIDC configuration. At least one parameter must be provided

```sh
weka s3 cluster oidc update [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--config-url config-url]
                            [--claim-name claim-name]
                            [--type type]
                            [--client-id client-id]
                            [--groups-claim-name groups-claim-name]
                            [--client-secret client-secret]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--config-url`            | OIDC Configuration URL                                                                                     |
| `--claim-name`            | JWT claim name for policy mapping (default: roles)                                                         |
| `--type`                  | Identity provider type (generic, azure, keycloak) (format: 'generic', 'azure' or 'keycloak')               |
| `--client-id`             | OIDC client ID                                                                                             |
| `--groups-claim-name`     | JWT claim name for groups (default: groups)                                                                |
| `--client-secret`         | Client secret (required for type=azure)                                                                    |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster performance-bucket**

Display existing global settings for WEKA S3 performance buckets

```sh
weka s3 cluster performance-bucket [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster setup**

S3 cluster setup commands

```sh
weka s3 cluster setup [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster setup show**

Show the current S3 cluster setup configuration

```sh
weka s3 cluster setup show [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 cluster setup update**

Update S3 cluster setup configuration

```sh
weka s3 cluster setup update [--default-fs-name default-fs-name]
                             [--anonymous-posix-uid anonymous-posix-uid]
                             [--anonymous-posix-gid anonymous-posix-gid]
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--clear-default-fs]
                             [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--default-fs-name`       | S3 default filesystem name                                                                                 |
| `--anonymous-posix-uid`   | POSIX UID for anonymous users                                                                              |
| `--anonymous-posix-gid`   | POSIX GID for anonymous users                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--clear-default-fs`      | Clear the default filesystem for this tenant                                                               |
| `-h`, `--help`            | Show help message                                                                                          |

**weka s3 cluster sorting**

Commands to manage LIST operation sorting for all S3 Performance Buckets

```sh
weka s3 cluster sorting [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 cluster sorting reset**

Reset the sorting preference for *all* S3 Performance Buckets, forcing them to inherit the cluster's global default

```sh
weka s3 cluster sorting reset [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]
                              [--force]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance. |

**weka s3 cluster status**

Show which of the containers are ready.

```sh
weka s3 cluster status [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--format format]
                       [--output output]...
                       [--sort sort]...
                       [--filter filter]...
                       [--filter-color filter-color]...
                       [--help]
                       [--no-header]
                       [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                         |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                             |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,hostname,statusTitle,slbStatus,ip,port,versions,uptime,requests,lastError,failureTime (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+          |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                            |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                                                                |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                               |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                       |

**weka s3 cluster update**

Update an S3 cluster

```sh
weka s3 cluster update [--port port]
                       [--anonymous-posix-uid anonymous-posix-uid]
                       [--anonymous-posix-gid anonymous-posix-gid]
                       [--domain domain]
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--container container]...
                       [--all-servers]
                       [--allow-versioning]
                       [--force]
                       [--help]

```

| Parameter                 | Description                                                                                                                                                                                                 |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--port`                  | S3 service port                                                                                                                                                                                             |
| `--anonymous-posix-uid`   | POSIX UID for anonymous users                                                                                                                                                                               |
| `--anonymous-posix-gid`   | POSIX GID for anonymous users                                                                                                                                                                               |
| `--domain`                | Virtual host-style comma seperated domains. Empty to disable                                                                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                    |
| `--container`...          | The containers that will serve via the S3 protocol (may be repeated or comma-separated)                                                                                                                     |
| `--all-servers`           | Install S3 on all servers                                                                                                                                                                                   |
| `--allow-versioning`      | Enable S3 versioning (default off, cannot be disabled once enabled)                                                                                                                                         |
| `-f`, `--force`           | Force this action without further confirmation. Be aware that this will impact all S3 buckets within the S3 service. Exercise caution and consult the WEKA Customer Success team if assistance is required. |
| `-h`, `--help`            | Show help message                                                                                                                                                                                           |

**weka s3 cluster update performance-bucket**

Set the default performance settings for all S3 Performance Buckets

```sh
weka s3 cluster update performance-bucket [--etag-alg etag-alg]
                                          [--integrity-mode integrity-mode]
                                          [--sorting sorting]
                                          [--color color]
                                          [--HOST HOST]
                                          [--PORT PORT]
                                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                          [--TIMEOUT TIMEOUT]
                                          [--profile profile]
                                          [--help]
                                          [--json]
                                          [--force]

```

| Parameter                 | Description                                                                                                                                                                                                                                    |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--etag-alg`              | Sets the default ETag generation algorithm. md5: Standard, computes an MD5 hash (slower). uid: Generates a unique ID (faster, avoids hashing). (format: 'md5' or 'uid')                                                                        |
| `--integrity-mode`        | Sets the default integrity handling mode. client\_defined: Respects client checksum validation requests (standard behavior). disabled: Ignores client checksum requests (faster, reduces overhead). (format: 'client\_defined' or 'disabled')  |
| `--sorting`               | Sets the default sorting behavior for LIST operations. sorted: Returns objects in standard lexicographical order (slower). unsorted: Returns objects as they appear in the filesystem (significantly faster). (format: 'sorted' or 'unsorted') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. Changing this setting could significantly affect the WEKA cluster performance.                                                                                                                 |

#### weka s3 policy

S3 policy commands

```sh
weka s3 policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 policy add**

Add an S3 IAM policy

```sh
weka s3 policy add <policy-name>
                   <policy-file>
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policy-name`\*           | The policy name                                                                                            |
| `policy-file`\*           | Path of the file containing the policy rules                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 policy attach**

Attach an S3 policy to a user or group

```sh
weka s3 policy attach <policy>
                      [username]
                      [--user user]
                      [--group group]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Policy name to attach                                                                                      |
| `username`                | User name to attach policy to                                                                              |
| `--user`                  | User name to attach policy to (alternative to positional argument)                                         |
| `--group`                 | Group name to attach policy to (mutually exclusive with user)                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 policy detach**

Detach an S3 policy from a user or group

```sh
weka s3 policy detach [username]
                      [--user user]
                      [--group group]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`                | User name to detach policy from                                                                            |
| `--user`                  | User name to detach policy from (alternative to positional argument)                                       |
| `--group`                 | Group name to detach policy from (mutually exclusive with user)                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 policy list**

Print a list of the existing S3 IAM policies

```sh
weka s3 policy list [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--format format]
                    [--output output]...
                    [--sort sort]...
                    [--filter filter]...
                    [--filter-color filter-color]...
                    [--help]
                    [--no-header]
                    [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: name (may be repeated or comma-separated)                                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 policy remove**

Remove an S3 IAM policy

```sh
weka s3 policy remove <policy>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Policy name to remove                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 policy show**

Show the details of an S3 IAM policy

```sh
weka s3 policy show <policy-name>
                    [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--help]
                    [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policy-name`\*           | Policy name to show                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka s3 service-account

S3 service account commands. Should be run only with an S3 user role

```sh
weka s3 service-account [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 service-account add**

Add an S3 service account

```sh
weka s3 service-account add [--policy-file policy-file]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--policy-file`           | Policy file path                                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 service-account list**

Print a list of the user's S3 service accounts

```sh
weka s3 service-account list [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--format format]
                             [--output output]...
                             [--sort sort]...
                             [--filter filter]...
                             [--filter-color filter-color]...
                             [--help]
                             [--no-header]
                             [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: accessKey (may be repeated or comma-separated)                                                                       |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka s3 service-account remove**

Remove an S3 service account

```sh
weka s3 service-account remove <access_key>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `access_key`\*            | Access key of the service account to remove                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka s3 service-account show**

Show the details of an S3 service account

```sh
weka s3 service-account show <access_key>
                             [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `access_key`\*            | Access key of the service account to show                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka s3 sts

S3 security token commands

```sh
weka s3 sts [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 sts assume-role**

Generate a temporary security token with an assumed role using existing user credentials

```sh
weka s3 sts assume-role [--access-key access-key]
                        [--secret-key secret-key]
                        [--policy-file policy-file]
                        [--duration duration]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--access-key`            | Access key                                                                                                 |
| `--secret-key`            | Secret key                                                                                                 |
| `--policy-file`           | Policy file path                                                                                           |
| `--duration`              | Duration, valid values: 15 minutes to 52 weeks and 1 day (format: 3s, 2h, 4m, 1d, 1d5h, 1w)                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka s3 user

Commands that manage S3 users

```sh
weka s3 user [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka s3 user keys-generate**

Generate or rotate an S3 API access/secret key pair for S3 data path operations

```sh
weka s3 user keys-generate [--user user]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--json]

```

| Parameter                 | Description                                                                                                                |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| `--user`                  | Target S3 username for credential generation/rotation. Restriction: Only available to Tenant Admin or Cluster Admin users. |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                   |
| `-h`, `--help`            | Show help message                                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                                      |

### weka security

Security commands.

```sh
weka security [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka security ca-cert

Commands handling custom CA signed certificate

```sh
weka security ca-cert [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security ca-cert download**

Download the Weka cluster custom certificate, if such certificate was set

```sh
weka security ca-cert download <path>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `path`\*                  | Path to output file                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security ca-cert set**

Add a custom certificate to the certificates list. If a custom certificate is already set, this command updates it.

```sh
weka security ca-cert set [--cert-file cert-file]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--cert-file`             | Path to certificate file                                                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security ca-cert status**

Show the Weka cluster CA-cert status and certificate

```sh
weka security ca-cert status [--color color]
                             [--HOST HOST]
                             [--PORT PORT]
                             [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                             [--TIMEOUT TIMEOUT]
                             [--profile profile]
                             [--help]
                             [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security ca-cert reset**

Unsets custom CA signed certificate from cluster

```sh
weka security ca-cert reset [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka security cors-trusted-sites

Commands for handling Cross Origin Resource Sharing weka apis

```sh
weka security cors-trusted-sites [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security cors-trusted-sites add**

Add a trusted site to list, provide url with http or https prefix and port number if not a standard port.

```sh
weka security cors-trusted-sites add <site>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `site`\*                  | Trusted site                                                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security cors-trusted-sites list**

Lists the set of trusted sites where CORS in configured

```sh
weka security cors-trusted-sites list [--color color]
                                      [--HOST HOST]
                                      [--PORT PORT]
                                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                      [--TIMEOUT TIMEOUT]
                                      [--profile profile]
                                      [--help]
                                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security cors-trusted-sites remove**

Remove the specified site from the trusted list.

```sh
weka security cors-trusted-sites remove <site>
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `site`\*                  | Site to remove from the trusted list                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security cors-trusted-sites remove-all**

Removes all trusted sites for Cross Origin Resource Sharing

```sh
weka security cors-trusted-sites remove-all [--color color]
                                            [--HOST HOST]
                                            [--PORT PORT]
                                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                            [--TIMEOUT TIMEOUT]
                                            [--profile profile]
                                            [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka security gui-idle-timeout

Manage GUI session idle timeout settings

```sh
weka security gui-idle-timeout [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security gui-idle-timeout restore-defaults**

Restores the GUI idle timeout to the default value (30 minutes)

```sh
weka security gui-idle-timeout restore-defaults [--color color]
                                                [--HOST HOST]
                                                [--PORT PORT]
                                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                                [--TIMEOUT TIMEOUT]
                                                [--profile profile]
                                                [--help]
                                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security gui-idle-timeout set**

Sets the user idle timeout for the GUI

```sh
weka security gui-idle-timeout set <timeout>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `timeout`\*               | Idle time before automatic logout. Values allowed between 1 minute and 1 day (format: 61s, 2h, 4m, 1h5m) (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                                               |
| `-J`, `--json`            | Format output as JSON                                                                                                                                           |

**weka security gui-idle-timeout show**

Shows the current GUI idle timeout setting

```sh
weka security gui-idle-timeout show [--color color]
                                    [--HOST HOST]
                                    [--PORT PORT]
                                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                    [--TIMEOUT TIMEOUT]
                                    [--profile profile]
                                    [--help]
                                    [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka security kms

List the currently configured key management service settings

```sh
weka security kms [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--help]
                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security kms rewrap**

Rewraps all the master filesystem keys using the configured KMS. This can be used to rewrap with a rotated KMS key, or to change wrapping to the newly-configured KMS.

```sh
weka security kms rewrap [--new-key-uid new-key-uid]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--all]
                         [--convert-to-cluster-key-on-fs]
                         [--help]
                         [--json]

```

| Parameter                        | Description                                                                                                |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--new-key-uid`                  | (KMIP-only) Unique identifier for the new key to be used to wrap filesystem keys                           |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`                      | Name of the connection and authentication profile to use                                                   |
| `--all`                          | rewrap all the filesystem keys                                                                             |
| `--convert-to-cluster-key-on-fs` | Convert all encrypted filesystems to use cluster key                                                       |
| `-h`, `--help`                   | Show help message                                                                                          |
| `-J`, `--json`                   | Format output as JSON                                                                                      |

**weka security kms set**

Configure the active KMS

```sh
weka security kms set [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security kms set kmip**

Configure the active KMS to use KMIP

```sh
weka security kms set kmip <address>
                           <key-identifier>
                           [--client-cert client-cert]
                           [--client-key client-key]
                           [--ca-cert ca-cert]
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]
                           [--convert-to-cluster-key-on-fs]

```

| Parameter                        | Description                                                                                                |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `address`\*                      | Server address, usually a hostname:port or a URL                                                           |
| `key-identifier`\*               | Key uid to secure the filesystem keys with                                                                 |
| `--client-cert`                  | Path to the client certificate PEM file                                                                    |
| `--client-key`                   | Path to the client key PEM file                                                                            |
| `--ca-cert`                      | Path to the CA certificate PEM file                                                                        |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`                      | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`                   | Show help message                                                                                          |
| `--convert-to-cluster-key-on-fs` | Convert all encrypted filesystems to use cluster key                                                       |

**weka security kms set vault**

Configure the active KMS to use Vault

```sh
weka security kms set vault <address>
                            <key-name>
                            [--namespace namespace]
                            [--transit-path transit-path]
                            [--auth-path auth-path]
                            [--token token]
                            [--role-id role-id]
                            [--secret-id secret-id]
                            [--kubernetes-role kubernetes-role]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--convert-to-cluster-key-on-fs]

```

| Parameter                        | Description                                                                                                |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `address`\*                      | Server address, usually a hostname:port or a URL                                                           |
| `key-name`\*                     | Key name to secure the filesystem keys with                                                                |
| `--namespace`                    | Namespace (Vault, optional)                                                                                |
| `--transit-path`                 | Use a custom transit path                                                                                  |
| `--auth-path`                    | Use a custom auth path                                                                                     |
| `--token`                        | auth: API token to access the KMS                                                                          |
| `--role-id`                      | auth: AppRole role ID to access the KMS                                                                    |
| `--secret-id`                    | auth: AppRole secret ID to access the KMS                                                                  |
| `--kubernetes-role`              | auth: Kubernetes role                                                                                      |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`                      | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`                   | Show help message                                                                                          |
| `--convert-to-cluster-key-on-fs` | Convert all encrypted filesystems to use cluster key                                                       |

**weka security kms reset**

Remove external KMS configurations. This will fail if there are any encrypted filesystems that rely on the KMS.

```sh
weka security kms reset [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--allow-downgrade]
                        [--force]
                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--allow-downgrade`       | Allows downgrading existing encrypted filesystems to local encryption instead of a KMS                     |
| `-f`, `--force`           | Force removal of tenant KMS, switching encrypted filesystems to use the cluster-wide KMS                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka security lockout-config

Commands used to interact with the account lockout config parameters

```sh
weka security lockout-config [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security lockout-config reset**

Reset the number of failed attempts before lockout and the duration of lock to their defaults

```sh
weka security lockout-config reset [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security lockout-config set**

Configure the number of failed attempts before lockout and the duration of lock

```sh
weka security lockout-config set [--failed-attempts failed-attempts]
                                 [--lockout-duration lockout-duration]
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]

```

| Parameter                 | Description                                                                                                              |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| `--failed-attempts`       | Number of consecutive failed logins before user account locks out                                                        |
| `--lockout-duration`      | How long the account should be locked out for after failed logins (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                         |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                         |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                         |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)               |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                   |
| `--profile`               | Name of the connection and authentication profile to use                                                                 |
| `-h`, `--help`            | Show help message                                                                                                        |

**weka security lockout-config show**

Show the current number of attempts needed to lockout and how long the lockout is for

```sh
weka security lockout-config show [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka security login-banner

Commands used to view and edit the login banner

```sh
weka security login-banner [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security login-banner disable**

Disable the login banner

```sh
weka security login-banner disable [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security login-banner enable**

Enable the login banner

```sh
weka security login-banner enable [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security login-banner reset**

Resets the login banner back to the default state (empty)

```sh
weka security login-banner reset [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security login-banner set**

Set the login banner

```sh
weka security login-banner set <login-banner>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `login-banner`\*          | Text banner to be displayed before the user logs into the web UI                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security login-banner show**

Show the current login banner

```sh
weka security login-banner show [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]
                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka security policy

Manages security policies.

```sh
weka security policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security policy add**

Creates a new security policy.

```sh
weka security policy add <name>
                         [--description description]
                         [--action action]
                         [--read-only read-only]
                         [--squash-mode squash-mode]
                         [--anon-uid anon-uid]
                         [--anon-gid anon-gid]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--ips ips]...
                         [--roles roles]...
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                             |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                  | Name of the new security policy. (up to 64 alphanumeric characters, hyphens (-), underscores (\_), and periods (.), starting with a letter)                                                                                                             |
| `--description`           | Description of the security policy. (up to 256 characters)                                                                                                                                                                                              |
| `--action`                | Whether access is granted or denied when the security policy matches. (format: 'allow' or 'deny')                                                                                                                                                       |
| `--read-only`             | The security policy allows read-only mounts only. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                       |
| `--squash-mode`           | Dictates whether user and group IDs accessing mounted filesystems are squashed. If 'root', then accesses by root (UID 0/GID 0) are converted to the anonymous UID and GID. If 'all', then all accesses are converted. (format: 'none', 'root' or 'all') |
| `--anon-uid`              | Anonymous user ID to which accesses are squashed. (default: 65534)                                                                                                                                                                                      |
| `--anon-gid`              | Anonymous group ID to which accesses are squashed. (default: 65534)                                                                                                                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                |
| `--ips`...                | IP address ranges to which the security policy applies. (format: IP or IP/CIDR or IP1-IP2 or A.B.C.D-E, may be repeated or comma-separated)                                                                                                             |
| `--roles`...              | User roles to which the security policy applies. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi', may be repeated or comma-separated)                                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                       |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                   |

**weka security policy remove**

Deletes a security policy.

```sh
weka security policy remove <policy>
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--force]

```

| Parameter                 | Description                                                                                                       |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Name or ID of security policy.                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)            |
| `--profile`               | Name of the connection and authentication profile to use                                                          |
| `-h`, `--help`            | Show help message                                                                                                 |
| `-f`, `--force`           | Force this action without further confirmation. Security policy details will be lost with no chance for recovery. |

**weka security policy duplicate**

Duplicates an existing security policy, creating a new one.

```sh
weka security policy duplicate <policy>
                               <name>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]
                               [--json]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Name or ID of the security policy to duplicate.                                                                                             |
| `name`\*                  | Name of the new security policy. (up to 64 alphanumeric characters, hyphens (-), underscores (\_), and periods (.), starting with a letter) |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-h`, `--help`            | Show help message                                                                                                                           |
| `-J`, `--json`            | Format output as JSON                                                                                                                       |

**weka security policy join**

Manages security policies related to cluster joining.

```sh
weka security policy join [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security policy join attach**

Adds new security policies applied when joining cluster, adding them to the existing policies.

```sh
weka security policy join attach [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--client]
                                 [--backend]
                                 [--force]
                                 [--help]
                                 [--json]
                                 [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policies`...             | Security policy names or IDs to attach to cluster join process.                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-c`, `--client`          | Apply policies to clients.                                                                                 |
| `-b`, `--backend`         | Apply policies to backends.                                                                                |
| `-f`, `--force`           | Force update, bypassing safeguards (may disrupt cluster members!)                                          |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security policy join detach**

Removes security policies applied when joining cluster.

```sh
weka security policy join detach [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--client]
                                 [--backend]
                                 [--force]
                                 [--help]
                                 [--json]
                                 [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policies`...             | Security policy names or IDs to remove from cluster join process.                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-c`, `--client`          | Apply policies to clients.                                                                                 |
| `-b`, `--backend`         | Apply policies to backends.                                                                                |
| `-f`, `--force`           | Force update, bypassing safeguards (may disrupt cluster members!)                                          |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security policy join list**

Lists security policies applied when joining containers.

```sh
weka security policy join list [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--format format]
                               [--output output]...
                               [--sort sort]...
                               [--filter filter]...
                               [--filter-color filter-color]...
                               [--client]
                               [--backend]
                               [--help]
                               [--raw-units]
                               [--UTC]
                               [--no-header]
                               [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: mode,policyNames,policyIds (may be repeated or comma-separated)                                                      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-c`, `--client`          | List policies for clients.                                                                                                                                                              |
| `-b`, `--backend`         | List policies for backends.                                                                                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka security policy join reset**

Removes all security policies applied when joining cluster.

```sh
weka security policy join reset [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--client]
                                [--backend]
                                [--help]
                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-c`, `--client`          | Reset policies applied to clients.                                                                         |
| `-b`, `--backend`         | Reset policies applied to backends.                                                                        |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security policy join set**

Sets security policies for joining cluster, replacing the existing set of policies.

```sh
weka security policy join set [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--client]
                              [--backend]
                              [--force]
                              [--help]
                              [--json]
                              [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policies`...             | Security policy names or IDs applied to cluster join process.                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-c`, `--client`          | Apply policies to clients.                                                                                 |
| `-b`, `--backend`         | Apply policies to backends.                                                                                |
| `-f`, `--force`           | Force update, bypassing safeguards (may disrupt cluster members!)                                          |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security policy list**

List security policies defined in the Weka cluster.

```sh
weka security policy list [--action action]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--format format]
                          [--roles roles]...
                          [--ips ips]...
                          [--output output]...
                          [--sort sort]...
                          [--filter filter]...
                          [--filter-color filter-color]...
                          [--help]
                          [--raw-units]
                          [--UTC]
                          [--no-header]
                          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--action`                | Lists security policies that match a specific action. (format: 'allow' or 'deny')                                                                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                    |
| `--roles`...              | Lists security policies that include specific roles. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi', may be repeated or comma-separated)                                                                  |
| `--ips`...                | Lists security policies that include specific IP address ranges. (format: IP or IP/CIDR or IP1-IP2 or A.B.C.D-E, may be repeated or comma-separated)                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,name,refCount,description,action,roles,ips,readonly,squashMode,anonUid,anonGid,createdBy,createdAt,modifiedBy,modifiedAt (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                 |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                              |

**weka security policy show**

Displays information about a specific security policy.

```sh
weka security policy show <policy>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--json]
                          [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Name or ID of security policy.                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-J`, `--json`            | Format output as JSON                                                                                      |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security policy test**

Simulates the effect of one or more security policies.

```sh
weka security policy test [--role role]
                          [--ip ip]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--join]
                          [--help]
                          [--json]
                          [<policy>]...

```

| Parameter                 | Description                                                                                                                                       |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| `policy`...               | Policies to evaluate, with access verified in the order listed.                                                                                   |
| `--role`                  | Simulate effect of policies on API access from the given user role. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi') |
| `--ip`                    | IP address to evaluate as the source address.                                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                                          |
| `--join`                  | Simulate effect of policies when joining the cluster.                                                                                             |
| `-h`, `--help`            | Show help message                                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                                             |

**weka security policy update**

Updates the settings of an existing security policy.

```sh
weka security policy update <policy>
                            [--description description]
                            [--action action]
                            [--new-name new-name]
                            [--read-only read-only]
                            [--squash-mode squash-mode]
                            [--anon-uid anon-uid]
                            [--anon-gid anon-gid]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--roles roles]...
                            [--add-roles add-roles]...
                            [--remove-roles remove-roles]...
                            [--ips ips]...
                            [--add-ips add-ips]...
                            [--remove-ips remove-ips]...
                            [--force]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                             |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `policy`\*                | Name or ID of security policy.                                                                                                                                                                                                                          |
| `--description`           | Updates the description of the security policy. (up to 256 characters)                                                                                                                                                                                  |
| `--action`                | Changes whether access is granted when the security policy matches. (format: 'allow' or 'deny')                                                                                                                                                         |
| `--new-name`              | New name of the security policy. (up to 64 alphanumeric characters, hyphens (-), underscores (\_), and periods (.), starting with a letter)                                                                                                             |
| `--read-only`             | The security policy allows read-only mounts only. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                       |
| `--squash-mode`           | Dictates whether user and group IDs accessing mounted filesystems are squashed. If 'root', then accesses by root (UID 0/GID 0) are converted to the anonymous UID and GID. If 'all', then all accesses are converted. (format: 'none', 'root' or 'all') |
| `--anon-uid`              | Anonymous user ID to which accesses are squashed. (default: 65534)                                                                                                                                                                                      |
| `--anon-gid`              | Anonymous group ID to which accesses are squashed. (default: 65534)                                                                                                                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                |
| `--roles`...              | User roles to which the security policy applies. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi', may be repeated or comma-separated)                                                                                      |
| `--add-roles`...          | User roles to append to the security policy. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi', may be repeated or comma-separated)                                                                                          |
| `--remove-roles`...       | User roles to remove from the security policy. (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi', may be repeated or comma-separated)                                                                                        |
| `--ips`...                | IP address ranges to which the security policy applies. (format: IP or IP/CIDR or IP1-IP2 or A.B.C.D-E, may be repeated or comma-separated)                                                                                                             |
| `--add-ips`...            | IP address ranges to append to the security policy. (format: IP or IP/CIDR or IP1-IP2 or A.B.C.D-E, may be repeated or comma-separated)                                                                                                                 |
| `--remove-ips`...         | IP address ranges to remove from the security policy. (format: IP or IP/CIDR or IP1-IP2 or A.B.C.D-E, may be repeated or comma-separated)                                                                                                               |
| `-f`, `--force`           | Force update, bypassing safeguards (may disrupt cluster members!)                                                                                                                                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                       |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                   |

#### weka security tls

TLS commands.

```sh
weka security tls [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security tls download**

Download the Weka cluster TLS certificate

```sh
weka security tls download <path>
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `path`\*                  | Path to output file                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security tls local**

TLS local configuration commands

```sh
weka security tls local [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka security tls local set**

Make HTTP server use local TLS configuration. If local TLS already configured, updates the configuration.

```sh
weka security tls local set [--private-key private-key]
                            [--certificate certificate]
                            [--ca-cert ca-cert]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--all]
                            [--help]
                            [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids to apply local TLS configuration                                                   |
| `--private-key`           | Path to TLS private key pem file                                                                           |
| `--certificate`           | Path to TLS certificate pem file                                                                           |
| `--ca-cert`               | Path to TLS CA certificate pem file                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--all`                   | Apply TLS configuration on all the backend containers in the cluster                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security tls local reset**

Removes the local TLS configuration.

```sh
weka security tls local reset [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--private-key]
                              [--ca-cert]
                              [--all]
                              [--help]
                              [<container-ids>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `container-ids`...        | A list of container ids to apply local TLS configuration                                                   |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--private-key`           | Remove local TLS private key and associated certificate                                                    |
| `--ca-cert`               | Remove local TLS CA certificate                                                                            |
| `--all`                   | Apply TLS configuration on all the backend containers in the cluster                                       |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security tls set**

Make Ngnix use TLS when accessing UI. If TLS already set this command updates the key and certificate.

```sh
weka security tls set [--private-key private-key]
                      [--certificate certificate]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--private-key`           | Path to TLS private key pem file                                                                           |
| `--certificate`           | Path to TLS certificate pem file                                                                           |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka security tls status**

Show the Weka cluster TLS status and certificate

```sh
weka security tls status [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka security tls reset**

Make Ngnix not use TLS when accessing UI

```sh
weka security tls reset [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

### weka smb

Commands that manage Weka's SMB container

```sh
weka smb [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka smb cluster

View info about the SMB cluster managed by weka

```sh
weka smb cluster [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--help]
                 [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb cluster container**

Update an SMB cluster containers

```sh
weka smb cluster container [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka smb cluster container add**

Update an SMB cluster

```sh
weka smb cluster container add [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--container-ids container-ids]...
                               [--help]
                               [--force]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `--container-ids`...      | The SMB containers being added (pass weka's host id as a number) (may be repeated or comma-separated)         |
| `-h`, `--help`            | Show help message                                                                                             |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients. |

**weka smb cluster container remove**

Update an SMB cluster

```sh
weka smb cluster container remove [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--container-ids container-ids]...
                                  [--help]
                                  [--force]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `--container-ids`...      | The SMB containers being removed (pass weka's container id as a number) (may be repeated or comma-separated)  |
| `-h`, `--help`            | Show help message                                                                                             |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients. |

**weka smb cluster add**

Create a SMB cluster managed by weka

```sh
weka smb cluster add <netbios-name>
                     <domain>
                     <config-fs-name>
                     [--symlink symlink]
                     [--domain-netbios-name domain-netbios-name]
                     [--idmap-backend idmap-backend]
                     [--default-domain-mapping-from-id default-domain-mapping-from-id]
                     [--default-domain-mapping-to-id default-domain-mapping-to-id]
                     [--joined-domain-mapping-from-id joined-domain-mapping-from-id]
                     [--joined-domain-mapping-to-id joined-domain-mapping-to-id]
                     [--encryption encryption]
                     [--scale-out-mode scale-out-mode]
                     [--smb-conf-extra smb-conf-extra]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--container-ids container-ids]...
                     [--smb-ips-pool smb-ips-pool]...
                     [--smb-ips-range smb-ips-range]...
                     [--help]

```

| Parameter                          | Description                                                                                                                                                                                                                                                                                                                                                 |
| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `netbios-name`\*                   | The netbios name to give to the SMB cluster                                                                                                                                                                                                                                                                                                                 |
| `domain`\*                         | The domain to join the SMB cluster to                                                                                                                                                                                                                                                                                                                       |
| `config-fs-name`\*                 | SMB config filesystem name                                                                                                                                                                                                                                                                                                                                  |
| `--symlink`                        | Enable or disable symbolic link (symlink) support for the SMB-W cluster. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                                    |
| `--domain-netbios-name`            | The domain netbios name; If not given, the default will be the first part of the given domain name                                                                                                                                                                                                                                                          |
| `--idmap-backend`                  | The SMB domain backend type (rid, rfc2307, etc.). Note that rfc2307 requires uid/gid configuration on the Active Directory and is persistent, while rid does not require any Active Directory configuration but in case of range changes uids/gids could break.                                                                                             |
| `--default-domain-mapping-from-id` | The SMB default domain first id                                                                                                                                                                                                                                                                                                                             |
| `--default-domain-mapping-to-id`   | The SMB default domain last id                                                                                                                                                                                                                                                                                                                              |
| `--joined-domain-mapping-from-id`  | The joined domain first id                                                                                                                                                                                                                                                                                                                                  |
| `--joined-domain-mapping-to-id`    | The joined domain last id                                                                                                                                                                                                                                                                                                                                   |
| `--encryption`                     | Encryption (format: 'enabled', 'disabled', 'desired' or 'required')                                                                                                                                                                                                                                                                                         |
| `--scale-out-mode`                 | Controls the sync level between the SMB-W servers. Possible values: 'full' (Default), 'partial'. The default value is 'full,' but you can use 'partial' if shared access to files is unnecessary. Be cautious when deviating from the default setting; consult the documentation or Customer Success to avoid misuse. (format: 'none', 'full' or 'partial') |
| `--smb-conf-extra`                 | Extra smb configuration options                                                                                                                                                                                                                                                                                                                             |
| `--color`                          | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                                            |
| `-H`, `--HOST`                     | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                                            |
| `-P`, `--PORT`                     | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT`          | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                  |
| `-T`, `--TIMEOUT`                  | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                                      |
| `--profile`                        | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                                                    |
| `--container-ids`...               | The containers that will serve via the SMB protocol (pass weka's container id as a number) (may be repeated or comma-separated)                                                                                                                                                                                                                             |
| `--smb-ips-pool`...                | IPs used as floating IPs for samba to server SMB in a HA manner. Then should not be assigned to any container on the network (may be repeated or comma-separated)                                                                                                                                                                                           |
| `--smb-ips-range`...               | IPs used as floating IPs for samba to server SMB in a HA manner. Then should not be assigned to any container on the network (may be repeated or comma-separated)                                                                                                                                                                                           |
| `-h`, `--help`                     | Show help message                                                                                                                                                                                                                                                                                                                                           |

**weka smb cluster debug**

Set debug level in an SMB container

```sh
weka smb cluster debug <level>
                       [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--container-ids container-ids]...
                       [--help]
                       [--json]

```

| Parameter                 | Description                                                                                                           |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| `level`\*                 | The debug level                                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                |
| `--profile`               | Name of the connection and authentication profile to use                                                              |
| `--container-ids`...      | Hosts to set debug level (pass weka's host id as a number). All hosts as default (may be repeated or comma-separated) |
| `-h`, `--help`            | Show help message                                                                                                     |
| `-J`, `--json`            | Format output as JSON                                                                                                 |

**weka smb cluster remove**

Destroy the SMB cluster managed by weka. This will not delete the data, just stop exposing it via SMB

```sh
weka smb cluster remove [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--force]
                        [--help]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients. |
| `-h`, `--help`            | Show help message                                                                                             |

**weka smb cluster status**

Show which of the containers are ready.

```sh
weka smb cluster status [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb cluster trusted-domains**

List all trusted domains

```sh
weka smb cluster trusted-domains [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--format format]
                                 [--output output]...
                                 [--sort sort]...
                                 [--filter filter]...
                                 [--filter-color filter-color]...
                                 [--help]
                                 [--no-header]
                                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,domain,idmap,from,to (may be repeated or comma-separated)                                                         |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka smb cluster trusted-domains add**

Add a new trusted domain

```sh
weka smb cluster trusted-domains add <domain-name>
                                     <from-id>
                                     <to-id>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--force]
                                     [--help]
                                     [--json]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `domain-name`\*           | The name of the domain being added                                                                                                          |
| `from-id`\*               | The first id                                                                                                                                |
| `to-id`\*                 | The last id                                                                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients and modify existing uids/gids. |
| `-h`, `--help`            | Show help message                                                                                                                           |
| `-J`, `--json`            | Format output as JSON                                                                                                                       |

**weka smb cluster trusted-domains remove**

Remove a trusted domain

```sh
weka smb cluster trusted-domains remove <trusteddomain-id>
                                        [--color color]
                                        [--HOST HOST]
                                        [--PORT PORT]
                                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                        [--TIMEOUT TIMEOUT]
                                        [--profile profile]
                                        [--force]
                                        [--help]

```

| Parameter                 | Description                                                                                                                                 |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `trusteddomain-id`\*      | The id of the domain to remove                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                      |
| `--profile`               | Name of the connection and authentication profile to use                                                                                    |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients and modify existing uids/gids. |
| `-h`, `--help`            | Show help message                                                                                                                           |

**weka smb cluster update**

Update an SMB cluster

```sh
weka smb cluster update [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--encryption encryption]
                        [--smb-ips-pool smb-ips-pool]...
                        [--smb-ips-range smb-ips-range]...
                        [--help]

```

| Parameter                 | Description                                                                                                                                           |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                                              |
| `--encryption`            | Encryption (format: 'enabled', 'disabled', 'desired' or 'required')                                                                                   |
| `--smb-ips-pool`...       | IPs used as floating IPs for SMB to serve in a HA manner. Then should not be assigned to any host on the network (may be repeated or comma-separated) |
| `--smb-ips-range`...      | IPs used as floating IPs for SMB to serve in a HA manner. Then should not be assigned to any host on the network (may be repeated or comma-separated) |
| `-h`, `--help`            | Show help message                                                                                                                                     |

**weka smb cluster wait**

Wait for SMB cluster to become ready

```sh
weka smb cluster wait [--timeout timeout]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `-t`, `--timeout`         | Timeout (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka smb domain

View info about the domain

```sh
weka smb domain [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--help]
                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb domain join**

Join cluster to Active Directory domain

```sh
weka smb domain join <username>
                     [password]
                     [--server server]
                     [--create-computer create-computer]
                     [--extra-options extra-options]
                     [--timeout timeout]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--debug]
                     [--help]
                     [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | The name of the administrator user to join the domain using it                                             |
| `password`                | The administrator user password                                                                            |
| `--server`                | Specifies the remote domain controller for SMB-W domain join commands.                                     |
| `--create-computer`       | Creates an SMB cluster computer account in AD under a specified OU.                                        |
| `--extra-options`         | Consult with SMB 'net ads join' manual for extra options                                                   |
| `-t`, `--timeout`         | Join command timeout in seconds (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--debug`                 | Run the command in debug mode                                                                              |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb domain leave**

Leave Active Directory domain

```sh
weka smb domain leave <username>
                      [password]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--debug]
                      [--force]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | The name of the administrator user to leave the domain using it                                            |
| `password`                | The administrator user password                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--debug`                 | Run the command in debug mode                                                                              |
| `-f`, `--force`           | Force to leave the domain. Use when Active Directory is unresponsive                                       |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka smb share

List all shares exposed via SMB

```sh
weka smb share [--color color]
               [--HOST HOST]
               [--PORT PORT]
               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
               [--TIMEOUT TIMEOUT]
               [--profile profile]
               [--format format]
               [--output output]...
               [--sort sort]...
               [--filter filter]...
               [--filter-color filter-color]...
               [--help]
               [--no-header]
               [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                                                                            |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                                                       |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                                                                       |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                                                                       |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                             |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                                                                 |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                                                                               |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                                                                   |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,share,filesystem,description,path,fmask,dmask,acls,options,additional,direct,Sensitivity,encryption,validUsers,invalidUsers,readonlyUsers,readwriteUsers,readonlyShare,allowGuestAccess,hidden,vfsZerocopyRead,namedStreams (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                                                                |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                                                                  |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                                                               |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                                                                      |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                                                                                     |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                                                                                             |

**weka smb share add**

Add a new share to be exposed by SMB

```sh
weka smb share add <share-name>
                   <fs-name>
                   [--description description]
                   [--internal-path internal-path]
                   [--file-create-mask file-create-mask]
                   [--directory-create-mask directory-create-mask]
                   [--acl acl]
                   [--map-acls map-acls]
                   [--case-sensitivity case-sensitivity]
                   [--obs-direct obs-direct]
                   [--encryption encryption]
                   [--read-only read-only]
                   [--user-list-type user-list-type]
                   [--allow-guest-access allow-guest-access]
                   [--enable-ADS enable-ADS]
                   [--hidden hidden]
                   [--vfs-zerocopy-read vfs-zerocopy-read]
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--users users]...
                   [--force]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                                                            |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `share-name`\*            | The name of the share being added                                                                                                                                                                                                                                                      |
| `fs-name`\*               | Filesystem name to share                                                                                                                                                                                                                                                               |
| `--description`           | A description for SMB to show regarding the share                                                                                                                                                                                                                                      |
| `--internal-path`         | The path inside the filesystem to share                                                                                                                                                                                                                                                |
| `--file-create-mask`      | POSIX mode mask files will be created with. E.g. "0744"                                                                                                                                                                                                                                |
| `--directory-create-mask` | POSIX mode mask directories will be created with. E.g. "0755"                                                                                                                                                                                                                          |
| `--acl`                   | Enable Windows ACLs on the share. Will also be translated (as possible) to POSIX ACLs. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                 |
| `--map-acls`              | Map ACL (format: 'posix', 'windows', 'hybrid' or 'none')                                                                                                                                                                                                                               |
| `--case-sensitivity`      | Enable or disable case sensitivity for the specified SMB share. When enabled, the share distinguishes between files with the same name but different capitalization. This option applies exclusively to SMB-W cluster. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--obs-direct`            | Mount share in obs-direct mode (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                         |
| `--encryption`            | Encryption (format: 'cluster\_default', 'desired' or 'required')                                                                                                                                                                                                                       |
| `--read-only`             | Mount share as read-only (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                               |
| `--user-list-type`        | The list type to which users are added to (format: 'read\_only', 'read\_write', 'valid' or 'invalid')                                                                                                                                                                                  |
| `--allow-guest-access`    | Allow guests to access the share (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                       |
| `--enable-ADS`            | Enables the use of Alternate Data Streams (ADS) on a specified SMB share. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                              |
| `--hidden`                | Hidden (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                                                                 |
| `--vfs-zerocopy-read`     | Enable zero-copy reads if supported. Default: true (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                                                                                                                                                     |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                       |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                       |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                       |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                             |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                 |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                                               |
| `--users`...              | Users to add (may be repeated or comma-separated)                                                                                                                                                                                                                                      |
| `-f`, `--force`           | Force this action without further confirmation. This action will affect all SMB users of this share, Use it with caution and consult the Weka Customer Success team at need.                                                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                                      |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                                                                  |

**weka smb share host-access**

Show host access help

```sh
weka smb share host-access [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka smb share host-access add**

Add hosts IPs to host access list

```sh
weka smb share host-access add <share-id>
                               <mode>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--ips ips]...
                               [--help]
                               [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share                                                                                        |
| `mode`\*                  | allow/deny host access (format: 'allow' or 'deny')                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--ips`...                | ips to add (may be repeated or comma-separated)                                                            |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb share host-access list**

Show host access list

```sh
weka smb share host-access list [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--format format]
                                [--output output]...
                                [--sort sort]...
                                [--filter filter]...
                                [--filter-color filter-color]...
                                [--help]
                                [--no-header]
                                [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,share,mode,IP (may be repeated or comma-separated)                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka smb share host-access remove**

Remove hosts IPs from a user list

```sh
weka smb share host-access remove <share_id>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]
                                  [<hosts>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share_id`\*              | The id of the share being removed from                                                                     |
| `hosts`...                | Hosts IPs to remove                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb share host-access reset**

Reset host access lists

```sh
weka smb share host-access reset <share-id>
                                 <mode>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--force]
                                 [--help]
                                 [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share                                                                                        |
| `mode`\*                  | allow/deny host access (format: 'allow' or 'deny')                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-f`, `--force`           | Force this action without further confirmation. This action will delete all host access ips.               |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb share list**

Show lists help

```sh
weka smb share list [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka smb share list add**

Add users to a user list

```sh
weka smb share list add <share-id>
                        <user-list-type>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--users users]...
                        [--help]
                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share                                                                                        |
| `user-list-type`\*        | The list type (format: 'read\_only', 'read\_write', 'valid' or 'invalid')                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--users`...              | Users to add (may be repeated or comma-separated)                                                          |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb share list remove**

Remove users from a user list

```sh
weka smb share list remove <share_id>
                           <user-list-type>
                           [--color color]
                           [--HOST HOST]
                           [--PORT PORT]
                           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                           [--TIMEOUT TIMEOUT]
                           [--profile profile]
                           [--users users]...
                           [--help]
                           [--json]

```

| Parameter                 | Description                                                                                                 |
| ------------------------- | ----------------------------------------------------------------------------------------------------------- |
| `share_id`\*              | The id of the share being removed from                                                                      |
| `user-list-type`\*        | The list type from which users are removed from (format: 'read\_only', 'read\_write', 'valid' or 'invalid') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                            |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                            |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                            |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)  |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)      |
| `--profile`               | Name of the connection and authentication profile to use                                                    |
| `--users`...              | Users to remove (may be repeated or comma-separated)                                                        |
| `-h`, `--help`            | Show help message                                                                                           |
| `-J`, `--json`            | Format output as JSON                                                                                       |

**weka smb share list reset**

Reset a user list

```sh
weka smb share list reset <share-id>
                          <user-list-type>
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share                                                                                        |
| `user-list-type`\*        | The list type (format: 'read\_only', 'read\_write', 'valid' or 'invalid')                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka smb share list show**

Show user lists

```sh
weka smb share list show [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--format format]
                         [--output output]...
                         [--sort sort]...
                         [--filter filter]...
                         [--filter-color filter-color]...
                         [--help]
                         [--no-header]
                         [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,id,share,readonly,validusers,invalidusers,readonlyusers,readwriteusers (may be repeated or comma-separated)      |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka smb share remove**

Remove a share exposed by SMB

```sh
weka smb share remove <share-id>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--force]
                      [--help]

```

| Parameter                 | Description                                                                                                   |
| ------------------------- | ------------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share to remove                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)        |
| `--profile`               | Name of the connection and authentication profile to use                                                      |
| `-f`, `--force`           | Force this action without further confirmation. This action may disrupt IO service for connected SMB clients. |
| `-h`, `--help`            | Show help message                                                                                             |

**weka smb share update**

Update an SMB share

```sh
weka smb share update <share-id>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--encryption encryption]
                      [--read-only read-only]
                      [--allow-guest-access allow-guest-access]
                      [--hidden hidden]
                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `share-id`\*              | The id of the share to update                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--encryption`            | Encryption (format: 'cluster\_default', 'desired' or 'required')                                           |
| `--read-only`             | Mount as read-only (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                         |
| `--allow-guest-access`    | Allow Guest Access (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                         |
| `--hidden`                | Hidden (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                     |
| `-h`, `--help`            | Show help message                                                                                          |

### weka stats

List all statistics that conform to the filter criteria

```sh
weka stats [--start-time <start>]
           [--end-time <end>]
           [--interval interval]
           [--resolution-secs <secs>]
           [--role role]
           [--aggregate-by aggregate-by]
           [--query-timeout <seconds>]
           [--color color]
           [--HOST HOST]
           [--PORT PORT]
           [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
           [--TIMEOUT TIMEOUT]
           [--profile profile]
           [--format format]
           [--category category]...
           [--stat stat]...
           [--process-ids process-ids]...
           [--param param]...
           [--exclude-process-ids exclude-process-ids]...
           [--output output]...
           [--sort sort]...
           [--filter filter]...
           [--filter-color filter-color]...
           [--accumulated]
           [--per-process]
           [--per-role]
           [--no-zeros]
           [--show-internal]
           [--skip-validations]
           [--help]
           [--raw-units]
           [--UTC]
           [--no-header]
           [--verbose]

```

| Parameter                  | Description                                                                                                                                                                                                                                                                                 |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--start-time`             | Query for stats starting at this time (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00)                                                                                          |
| `--end-time`               | Query for stats up to this time point (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00)                                                                                          |
| `--interval`               | Period (in seconds) of time of the report                                                                                                                                                                                                                                                   |
| `--resolution-secs`        | Length of each interval in the report period                                                                                                                                                                                                                                                |
| `--role`                   | Limit the report to processes with the specified role                                                                                                                                                                                                                                       |
| `--aggregate-by`           | Aggregate statistics by the specified component (format: 'none', 'process', 'container' or 'server')                                                                                                                                                                                        |
| `--query-timeout`          | Per-container timeout in seconds for retrieving query output (default: 5)                                                                                                                                                                                                                   |
| `--color`                  | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                            |
| `-H`, `--HOST`             | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                                            |
| `-P`, `--PORT`             | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                                            |
| `-C`, `--CONNECT-TIMEOUT`  | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                  |
| `-T`, `--TIMEOUT`          | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                                      |
| `--profile`                | Name of the connection and authentication profile to use                                                                                                                                                                                                                                    |
| `-f`, `--format`           | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                                        |
| `--category`...            | Retrieve only statistics of the specified categories (may be repeated or comma-separated)                                                                                                                                                                                                   |
| `--stat`...                | Retrieve only the specified statistics (may be repeated or comma-separated)                                                                                                                                                                                                                 |
| `--process-ids`...         | Limit the report to the specified processes (may be repeated or comma-separated)                                                                                                                                                                                                            |
| `--param`...               | For parameterized statistics, retrieve only the instantiations where the specified parameter is of the specified value. Multiple values can be supplied for the same key, e.g. '--param method:putBlocks --param method:initBlock'. (format: key:value, may be repeated or comma-separated) |
| `--exclude-process-ids`... | Limit the report to all processes except the specified ones (may be repeated or comma-separated)                                                                                                                                                                                            |
| `-o`, `--output`...        | Specify which columns to output. May include any of the following: node,category,timestamp,stat,unit,value,containerId,container,hostname,roles (may be repeated or comma-separated)                                                                                                        |
| `-s`, `--sort`...          | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                                     |
| `-F`, `--filter`...        | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                                       |
| `--filter-color`...        | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                                                    |
| `--accumulated`            | Show accumulated statistics, not rate statistics                                                                                                                                                                                                                                            |
| `--per-process`            | Do not aggregate statistics across processes                                                                                                                                                                                                                                                |
| `--per-role`               | Aggregate statistics by role                                                                                                                                                                                                                                                                |
| `-Z`, `--no-zeros`         | Do not retrieve results where the value is 0                                                                                                                                                                                                                                                |
| `--show-internal`          | Show internal statistics                                                                                                                                                                                                                                                                    |
| `--skip-validations`       | Skip category/stat name validations                                                                                                                                                                                                                                                         |
| `-h`, `--help`             | Show help message                                                                                                                                                                                                                                                                           |
| `-R`, `--raw-units`        | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                                           |
| `-U`, `--UTC`              | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                                       |
| `--no-header`              | Don't show column headers when printing the output                                                                                                                                                                                                                                          |
| `-v`, `--verbose`          | Show all columns in output                                                                                                                                                                                                                                                                  |

#### weka stats list-types

Show the statistics definition information

```sh
weka stats list-types [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--format format]
                      [--output output]...
                      [--sort sort]...
                      [--filter filter]...
                      [--filter-color filter-color]...
                      [--show-internal]
                      [--help]
                      [--raw-units]
                      [--UTC]
                      [--no-header]
                      [--verbose]
                      [<name-or-category>]...

```

| Parameter                 | Description                                                                                                                                                                                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `name-or-category`...     | Filter by these names or categories                                                                                                                                                                                                              |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                 |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                 |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                 |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                       |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                           |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                         |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                             |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: category,clabel,identifier,description,label,type,unit,params,realted,permission,ntype,accumulate,histogram,histogramUnit,factor,counter (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                          |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                            |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                         |
| `--show-internal`         | Show internal statistics                                                                                                                                                                                                                         |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                            |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                               |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                       |

#### weka stats realtime

Get performance related stats which are updated in a one-second interval.

```sh
weka stats realtime [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--format format]
                    [--output output]...
                    [--sort sort]...
                    [--filter filter]...
                    [--filter-color filter-color]...
                    [--help]
                    [--raw-units]
                    [--UTC]
                    [--show-total]
                    [--no-header]
                    [--verbose]
                    [<process-ids>]...

```

| Parameter                 | Description                                                                                                                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `process-ids`...          | Only show realtime stats of these processes                                                                                                                                                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                          |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                          |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                          |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                    |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                  |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                      |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: node,hostname,role,mode,writeps,writebps,wlatency,readps,readbps,rlatency,ops,cpu,l6recv,l6send,upload,download,rdmarecv,rdmasend (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                   |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                     |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                  |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                         |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                         |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                     |
| `--show-total`            | Show each column's sum of values in the real-time statistics output                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                        |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                |

#### weka stats retention

Configure retention for statistics

```sh
weka stats retention [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka stats retention restore-default**

Restore default retention for statistics

```sh
weka stats retention restore-default [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--dry-run]
                                     [--help]
                                     [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--dry-run`               | Only test the command, don't affect the system                                                             |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka stats retention set**

Choose how long to keep statistics for

```sh
weka stats retention set [--days days]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--dry-run]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--days`                  | Number of days to keep the statistics                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `--dry-run`               | Only test the command, don't affect the system                                                             |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka stats retention status**

Show configured statistics retention

```sh
weka stats retention status [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--help]
                            [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

### weka status

Get an overall status of the Weka cluster

```sh
weka status [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--detailed-capacity]
            [--help]
            [--json]
            [--raw-units]
            [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `--detailed-capacity`     | Include more detailed capacity information                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

#### weka status rebuild

Show the cluster phasing in/out progress, and protection per fault-level

```sh
weka status rebuild [--color color]
                    [--HOST HOST]
                    [--PORT PORT]
                    [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                    [--TIMEOUT TIMEOUT]
                    [--profile profile]
                    [--help]
                    [--json]
                    [--raw-units]
                    [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

#### weka status reduction

Show cluster data reduction information'

```sh
weka status reduction [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]
                      [--raw-units]
                      [--UTC]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB. |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                             |

### weka telemetry

Commands that manage the telemetry gateway

```sh
weka telemetry [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka telemetry exports

Commands that manage the telemetry exports

```sh
weka telemetry exports [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka telemetry exports add**

Add a telemetry export to weka

```sh
weka telemetry exports add [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka telemetry exports add kafka**

Add a kafka telemetry export to weka

```sh
weka telemetry exports add kafka <name>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--target target]
                                 [--ca-cert ca-cert]
                                 [--allow-unverified-certificate allow-unverified-certificate]
                                 [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                 [--topic topic]
                                 [--use-sasl use-sasl]
                                 [--sasl-mechanism sasl-mechanism]
                                 [--sasl-username sasl-username]
                                 [--sasl-password sasl-password]
                                 [--key-field key-field]
                                 [--sources sources]...
                                 [--help]
                                 [--json]
                                 [--disabled]
                                 [--without-sources]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                         | Name of the telemetry export                                                                                                        |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--topic`                        | Specifies the topic for telemetry kafka export.                                                                                     |
| `--use-sasl`                     | Enables SASL authentication for kafka telemetry export. (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')             |
| `--sasl-mechanism`               | Defines the SASL authentication mechanism for kafka export. Supported options: PLAIN, SCRAM-SHA-256, SCRAM-SHA-512.                 |
| `--sasl-username`                | Sets the SASL username for kafka telemetry authentication.                                                                          |
| `--sasl-password`                | Sets the SASL password for kafka telemetry authentication.                                                                          |
| `--key-field`                    | Kafa uses a hash of the key to choose the partition or uses round-robin if the record has no key.                                   |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |
| `--disabled`                     | start the telemetry export in disabled Mode                                                                                         |
| `--without-sources`              | Force creation of export without sources                                                                                            |

**weka telemetry exports add s3**

Add a s3 telemetry export to weka

```sh
weka telemetry exports add s3 <name>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--target target]
                              [--ca-cert ca-cert]
                              [--allow-unverified-certificate allow-unverified-certificate]
                              [--verify-with-cluster-cacert verify-with-cluster-cacert]
                              [--bucket-name bucket-name]
                              [--access-key-id access-key-id]
                              [--secret-key secret-key]
                              [--region region]
                              [--sources sources]...
                              [--help]
                              [--json]
                              [--disabled]
                              [--without-sources]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                         | Name of the telemetry export                                                                                                        |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--bucket-name`                  | Bucket name for the telemetry export                                                                                                |
| `--access-key-id`                | Access key ID for the telemetry export                                                                                              |
| `--secret-key`                   | Secret access key for the telemetry export                                                                                          |
| `--region`                       | Region for s3                                                                                                                       |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |
| `--disabled`                     | start the telemetry export in disabled Mode                                                                                         |
| `--without-sources`              | Force creation of export without sources                                                                                            |

**weka telemetry exports add splunk**

Add a splunk telemetry export to weka

```sh
weka telemetry exports add splunk <name>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--target target]
                                  [--ca-cert ca-cert]
                                  [--allow-unverified-certificate allow-unverified-certificate]
                                  [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                  [--auth-token auth-token]
                                  [--sources sources]...
                                  [--help]
                                  [--json]
                                  [--disabled]
                                  [--without-sources]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                         | Name of the telemetry export                                                                                                        |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--auth-token`                   | Token for the telemetry export                                                                                                      |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |
| `--disabled`                     | start the telemetry export in disabled Mode                                                                                         |
| `--without-sources`              | Force creation of export without sources                                                                                            |

**weka telemetry exports add syslog**

Add a syslog telemetry export to weka

```sh
weka telemetry exports add syslog <name>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--target target]
                                  [--ca-cert ca-cert]
                                  [--allow-unverified-certificate allow-unverified-certificate]
                                  [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                  [--mode mode]
                                  [--rfc rfc]
                                  [--facility facility]
                                  [--sources sources]...
                                  [--help]
                                  [--json]
                                  [--disabled]
                                  [--without-sources]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                         | Name of the telemetry export                                                                                                        |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--mode`                         | Transport mode for syslog export. Supported options: tcp, udp. Default: tcp.                                                        |
| `--rfc`                          | Syslog message format. Supported options: rfc5424, rfc3164. Default: rfc5424.                                                       |
| `--facility`                     | Syslog facility level. Supported options: local0-local7. Default: local0.                                                           |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |
| `--disabled`                     | start the telemetry export in disabled Mode                                                                                         |
| `--without-sources`              | Force creation of export without sources                                                                                            |

**weka telemetry exports attach**

Add a telemetry export source to weka

```sh
weka telemetry exports attach <export-id>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]
                              [<sources>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `export-id`\*             | ID of the telemetry export                                                                                 |
| `sources`...              | Sources to add to telemetry export (format: audit)                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka telemetry exports detach**

Remove a telemetry export source from weka

```sh
weka telemetry exports detach <export-id>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]
                              [--force]
                              [<sources>]...

```

| Parameter                 | Description                                                                                                                                   |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `export-id`\*             | ID of the telemetry export                                                                                                                    |
| `sources`...              | Sources to remove from telemetry export (format: audit)                                                                                       |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                              |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                              |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                              |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                    |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                        |
| `--profile`               | Name of the connection and authentication profile to use                                                                                      |
| `-h`, `--help`            | Show help message                                                                                                                             |
| `-J`, `--json`            | Format output as JSON                                                                                                                         |
| `-f`, `--force`           | Force this action without further confirmation. This action will remove the telemetry export source from weka, it will no longer be exported. |

**weka telemetry exports disable**

Disable a telemetry export in weka

```sh
weka telemetry exports disable <export-id>
                               [--color color]
                               [--HOST HOST]
                               [--PORT PORT]
                               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                               [--TIMEOUT TIMEOUT]
                               [--profile profile]
                               [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `export-id`\*             | ID of the telemetry export                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka telemetry exports enable**

Enable a telemetry export in weka

```sh
weka telemetry exports enable <export-id>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `export-id`\*             | ID of the telemetry export                                                                                 |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

**weka telemetry exports list**

List telemetry exports, and their current config

```sh
weka telemetry exports list [--name name]
                            [--type type]
                            [--color color]
                            [--HOST HOST]
                            [--PORT PORT]
                            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                            [--TIMEOUT TIMEOUT]
                            [--profile profile]
                            [--format format]
                            [--output output]...
                            [--sort sort]...
                            [--filter filter]...
                            [--filter-color filter-color]...
                            [--help]
                            [--no-header]
                            [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--name`                  | Fliter telemetry exports by name                                                                                                                                                        |
| `--type`                  | Filter telemetry exports by type (format: 'file', 'splunk', 's3', 'vector', 'kafka' or 'syslog')                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,name,enabled,export\_type,target,sources (may be repeated or comma-separated)                                     |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka telemetry exports remove**

Remove a telemetry export from weka

```sh
weka telemetry exports remove <export-id>
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--force]

```

| Parameter                 | Description                                                                                                                         |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `export-id`\*             | ID of the telemetry export                                                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`               | Name of the connection and authentication profile to use                                                                            |
| `-h`, `--help`            | Show help message                                                                                                                   |
| `-f`, `--force`           | Force this action without further confirmation. This action will remove the telemetry export from weka, and all associated sources. |

**weka telemetry exports status**

Report the status of a telemetry exports

```sh
weka telemetry exports status [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka telemetry exports update**

Update a telemetry export in weka

```sh
weka telemetry exports update [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka telemetry exports update s3**

Update a S3 telemetry export in weka

```sh
weka telemetry exports update s3 <export-id>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--name name]
                                 [--target target]
                                 [--ca-cert ca-cert]
                                 [--allow-unverified-certificate allow-unverified-certificate]
                                 [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                 [--bucket-name bucket-name]
                                 [--access-key-id access-key-id]
                                 [--secret-key secret-key]
                                 [--region region]
                                 [--clear-tls-settings clear-tls-settings]
                                 [--sources sources]...
                                 [--help]
                                 [--json]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `export-id`\*                    | ID of the telemetry export                                                                                                          |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--name`                         | Name of the telemetry export                                                                                                        |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--bucket-name`                  | Bucket name for the telemetry export                                                                                                |
| `--access-key-id`                | Access key ID for the telemetry export                                                                                              |
| `--secret-key`                   | Secret access key for the telemetry export                                                                                          |
| `--region`                       | Region for s3                                                                                                                       |
| `--clear-tls-settings`           | (optional) clear TLS settings (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                       |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |

**weka telemetry exports update splunk**

Update a splunk telemetry export in weka

```sh
weka telemetry exports update splunk <export-id>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--name name]
                                     [--target target]
                                     [--ca-cert ca-cert]
                                     [--allow-unverified-certificate allow-unverified-certificate]
                                     [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                     [--auth-token auth-token]
                                     [--clear-tls-settings clear-tls-settings]
                                     [--sources sources]...
                                     [--help]
                                     [--json]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `export-id`\*                    | ID of the telemetry export                                                                                                          |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--name`                         | Name of the telemetry export                                                                                                        |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--auth-token`                   | Token for the telemetry export                                                                                                      |
| `--clear-tls-settings`           | (optional) clear TLS settings (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                       |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |

**weka telemetry exports update syslog**

Update a syslog telemetry export in weka

```sh
weka telemetry exports update syslog <export-id>
                                     [--color color]
                                     [--HOST HOST]
                                     [--PORT PORT]
                                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                     [--TIMEOUT TIMEOUT]
                                     [--profile profile]
                                     [--name name]
                                     [--target target]
                                     [--ca-cert ca-cert]
                                     [--allow-unverified-certificate allow-unverified-certificate]
                                     [--verify-with-cluster-cacert verify-with-cluster-cacert]
                                     [--mode mode]
                                     [--rfc rfc]
                                     [--facility facility]
                                     [--clear-tls-settings clear-tls-settings]
                                     [--sources sources]...
                                     [--help]
                                     [--json]

```

| Parameter                        | Description                                                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `export-id`\*                    | ID of the telemetry export                                                                                                          |
| `--color`                        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                   | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                   | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`        | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`                | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                      | Name of the connection and authentication profile to use                                                                            |
| `--name`                         | Name of the telemetry export                                                                                                        |
| `--target`                       | Target of the telemetry export                                                                                                      |
| `--ca-cert`                      | (optional) Path to the CA certificate PEM file                                                                                      |
| `--allow-unverified-certificate` | (optional) Allow accessing without verifying the target certificate (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--verify-with-cluster-cacert`   | (optional) Use cluster CA certificate to verify (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                     |
| `--mode`                         | Transport mode for syslog export. Supported options: tcp, udp. Default: tcp.                                                        |
| `--rfc`                          | Syslog message format. Supported options: rfc5424, rfc3164. Default: rfc5424.                                                       |
| `--facility`                     | Syslog facility level. Supported options: local0-local7. Default: local0.                                                           |
| `--clear-tls-settings`           | (optional) clear TLS settings (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                       |
| `--sources`...                   | Sources to add to telemetry export (format: audit, may be repeated or comma-separated)                                              |
| `-h`, `--help`                   | Show help message                                                                                                                   |
| `-J`, `--json`                   | Format output as JSON                                                                                                               |

### weka tenant

List tenants defined in the Weka cluster

```sh
weka tenant [--color color]
            [--HOST HOST]
            [--PORT PORT]
            [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
            [--TIMEOUT TIMEOUT]
            [--profile profile]
            [--format format]
            [--output output]...
            [--sort sort]...
            [--filter filter]...
            [--filter-color filter-color]...
            [--help]
            [--raw-units]
            [--UTC]
            [--no-header]
            [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                                                                                            |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                       |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                       |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                       |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                             |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                 |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                               |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                                                                                                   |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: id,name,allocTotal,quotaTotal,pctAllocated,qos,enforceFsAuth,enforceNetspace,policyNames,uid,allocSSD,quotaSSD,pctAllocatedSSD,maxThroughput,maxIops,policyIds (may be repeated or comma-separated) |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+                                                                                |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                                                                                                  |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                                                                                               |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                      |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                                                                                      |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                                                                                                  |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                                                                                     |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                                                                                             |

#### weka tenant add

Create a new tenant in the Weka cluster

```sh
weka tenant add <name>
                <username>
                [--ssd-quota ssd-quota]
                [--total-quota total-quota]
                [--enforce-fs-authentication enforce-fs-authentication]
                [--enforce-mount-netspace-access enforce-mount-netspace-access]
                [--max-throughput max-throughput]
                [--max-iops max-iops]
                [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--network-spaces network-spaces]...
                [--help]
                [--json]

```

| Parameter                         | Description                                                                                                                                                                                                                                                              |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `name`\*                          | Tenant name                                                                                                                                                                                                                                                              |
| `username`\*                      | Username of tenant admin                                                                                                                                                                                                                                                 |
| `password`\*                      | Password of tenant admin                                                                                                                                                                                                                                                 |
| `--ssd-quota`                     | SSD quota (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                            |
| `--total-quota`                   | Total quota (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB)                                                                                                                                          |
| `--enforce-fs-authentication`     | Enforce every filesystem created under this tenant requires authentication                                                                                                                                                                                               |
| `--enforce-mount-netspace-access` | Enforce every mount requested coming from netspace belonging to this tenant                                                                                                                                                                                              |
| `--max-throughput`                | The maximum total throughput allowed for the tenant per second. Use a number with capacity units in Decimal or Binary: for example, 200GiB or 500GB. (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--max-iops`                      | The maximum total I/O operations allowed for the tenant per second. Use a number without units: for example, 500000.                                                                                                                                                     |
| `--color`                         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                         |
| `-H`, `--HOST`                    | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                         |
| `-P`, `--PORT`                    | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                         |
| `-C`, `--CONNECT-TIMEOUT`         | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                               |
| `-T`, `--TIMEOUT`                 | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                   |
| `--profile`                       | Name of the connection and authentication profile to use                                                                                                                                                                                                                 |
| `--network-spaces`...             | Network space names to assign to the tenant (may be repeated or comma-separated)                                                                                                                                                                                         |
| `-h`, `--help`                    | Show help message                                                                                                                                                                                                                                                        |
| `-J`, `--json`                    | Format output as JSON                                                                                                                                                                                                                                                    |

#### weka tenant remove

Delete a tenant

```sh
weka tenant remove <tenant>
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--force]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| `tenant`\*                | Tenant name or ID                                                                                                                          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                 |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                     |
| `--profile`               | Name of the connection and authentication profile to use                                                                                   |
| `-f`, `--force`           | Force this action without further confirmation. This action will DELETE ALL DATA stored in this tenant's filesystems and cannot be undone. |
| `-h`, `--help`            | Show help message                                                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                                                      |

#### weka tenant network-space

List network spaces assigned to a tenant. Defaults to the current user's tenant.

```sh
weka tenant network-space [--tenant tenant]
                          [--color color]
                          [--HOST HOST]
                          [--PORT PORT]
                          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                          [--TIMEOUT TIMEOUT]
                          [--profile profile]
                          [--help]
                          [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--tenant`                | Tenant name or ID (default: current user's tenant)                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant network-space add**

Add network spaces to a tenant. Defaults to the current user's tenant.

```sh
weka tenant network-space add [--tenant tenant]
                              [--color color]
                              [--HOST HOST]
                              [--PORT PORT]
                              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                              [--TIMEOUT TIMEOUT]
                              [--profile profile]
                              [--help]
                              [--json]
                              [<network-spaces>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `network-spaces`...       | Network space names to add to the tenant                                                                   |
| `--tenant`                | Tenant name (default: current user's tenant)                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant network-space remove**

Remove network spaces from a tenant. Defaults to the current user's tenant.

```sh
weka tenant network-space remove [--tenant tenant]
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--help]
                                 [--json]
                                 [<network-spaces>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `network-spaces`...       | Network space names to remove from the tenant                                                              |
| `--tenant`                | Tenant name (default: current user's tenant)                                                               |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka tenant rename

Change a tenant name

```sh
weka tenant rename <tenant>
                   <new-name>
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]
                   [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Current tenant name or ID                                                                                  |
| `new-name`\*              | New tenant name                                                                                            |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka tenant security

Manages tenant security

```sh
weka tenant security [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka tenant security policy**

Manages tenant security policies

```sh
weka tenant security policy [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

**weka tenant security policy attach**

Attaches new security policies to a tenant, adding them to the existing policies

```sh
weka tenant security policy attach <tenant>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]
                                   [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                         |
| `policies`...             | Security policy names or IDs to attach to the tenant.                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant security policy detach**

Removes security policies from a tenant

```sh
weka tenant security policy detach <tenant>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--json]
                                   [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                         |
| `policies`...             | Security policy names or IDs to remove from the tenant.                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant security policy list**

List tenant security policies

```sh
weka tenant security policy list <tenant>
                                 [--color color]
                                 [--HOST HOST]
                                 [--PORT PORT]
                                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                 [--TIMEOUT TIMEOUT]
                                 [--profile profile]
                                 [--format format]
                                 [--output output]...
                                 [--sort sort]...
                                 [--filter filter]...
                                 [--filter-color filter-color]...
                                 [--help]
                                 [--raw-units]
                                 [--UTC]
                                 [--no-header]
                                 [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                                                                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: position,uid,id,name (may be repeated or comma-separated)                                                            |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                       |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                   |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

**weka tenant security policy reset**

Removes all security policies from a tenant

```sh
weka tenant security policy reset <tenant>
                                  [--color color]
                                  [--HOST HOST]
                                  [--PORT PORT]
                                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                  [--TIMEOUT TIMEOUT]
                                  [--profile profile]
                                  [--help]
                                  [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant security policy set**

Sets security policies for a tenant, replacing the existing list of policies

```sh
weka tenant security policy set <tenant>
                                [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]
                                [--json]
                                [<policies>]...

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                         |
| `policies`...             | Security policy names or IDs to assign to the tenant.                                                      |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka tenant security revoke-tokens**

Revokes all API tokens issued for this tenant

```sh
weka tenant security revoke-tokens <tenant>
                                   [--color color]
                                   [--HOST HOST]
                                   [--PORT PORT]
                                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                   [--TIMEOUT TIMEOUT]
                                   [--profile profile]
                                   [--help]
                                   [--force]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `tenant`\*                | Tenant name or ID.                                                                                         |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. This action will log all users out of the tenant.          |

#### weka tenant stats

Show I/O statistics per tenant (equivalent to 'weka stats --category=tenant\_stats --param tenant:\*'). Use --tenant to filter to a specific tenant.

```sh
weka tenant stats [--color color]
                  [--HOST HOST]
                  [--PORT PORT]
                  [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                  [--TIMEOUT TIMEOUT]
                  [--profile profile]
                  [--tenant tenant]
                  [--start-time <start>]
                  [--end-time <end>]
                  [--interval interval]
                  [--resolution-secs <secs>]
                  [--aggregate-by aggregate-by]
                  [--query-timeout <seconds>]
                  [--format format]
                  [--stat stat]...
                  [--param param]...
                  [--process-ids process-ids]...
                  [--output output]...
                  [--sort sort]...
                  [--filter filter]...
                  [--filter-color filter-color]...
                  [--help]
                  [--raw-units]
                  [--UTC]
                  [--accumulated]
                  [--per-process]
                  [--no-zeros]
                  [--per-role]
                  [--show-internal]
                  [--no-header]
                  [--verbose]

```

| Parameter                 | Description                                                                                                                                                                                        |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                           |
| `--tenant`                | Filter by tenant name or ID                                                                                                                                                                        |
| `--start-time`            | Query for stats starting at this time (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00) |
| `--end-time`              | Query for stats up to this time point (format: 5m, -5m, -1d, -1w, 1:00, 01:00, 18:30, 18:30:07, 2018-12-31 10:00, 2018/12/31 10:00, 2018-12-31T10:00, 2019-Nov-17 11:11:00.309, 9:15Z, 10:00+2:00) |
| `--interval`              | Period (in seconds) of time of the report                                                                                                                                                          |
| `--resolution-secs`       | Length of each interval in the report period                                                                                                                                                       |
| `--aggregate-by`          | Aggregate statistics by the specified component (format: 'none', 'process', 'container' or 'server')                                                                                               |
| `--query-timeout`         | Per-container timeout in seconds for retrieving query output (default: 5)                                                                                                                          |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                               |
| `--stat`...               | Retrieve only the specified statistics (may be repeated or comma-separated)                                                                                                                        |
| `--param`...              | For parameterized statistics, filter by additional key:value pairs (e.g. --param method:read). --tenant is shorthand for --param tenant:. (format: key:value, may be repeated or comma-separated)  |
| `--process-ids`...        | Limit the report to the specified processes (may be repeated or comma-separated)                                                                                                                   |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: timestamp,stat,value (may be repeated or comma-separated)                                                                       |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+            |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                              |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                                                                                  |
| `-R`, `--raw-units`       | Print values in raw units (bytes, seconds, etc.). When not set, sizes are printed in human-readable format, e.g 1KiB 234MiB 2GiB.                                                                  |
| `-U`, `--UTC`             | Print times in UTC. When not set, times are converted to the local time of this host.                                                                                                              |
| `--accumulated`           | Show accumulated statistics, not rate statistics                                                                                                                                                   |
| `--per-process`           | Do not aggregate statistics across processes                                                                                                                                                       |
| `-Z`, `--no-zeros`        | Do not retrieve results where the value is 0                                                                                                                                                       |
| `--per-role`              | Aggregate statistics by role                                                                                                                                                                       |
| `--show-internal`         | Show internal statistics                                                                                                                                                                           |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                                 |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                                         |

#### weka tenant update

Update tenant options

```sh
weka tenant update <tenant>
                   [--new-name new-name]
                   [--enforce-fs-authentication enforce-fs-authentication]
                   [--enforce-mount-netspace-access enforce-mount-netspace-access]
                   [--max-throughput max-throughput]
                   [--max-iops max-iops]
                   [--color color]
                   [--HOST HOST]
                   [--PORT PORT]
                   [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                   [--TIMEOUT TIMEOUT]
                   [--profile profile]
                   [--help]
                   [--json]

```

| Parameter                         | Description                                                                                                                                                                                                                                                              |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `tenant`\*                        | Tenant name or ID                                                                                                                                                                                                                                                        |
| `--new-name`                      | New tenant name                                                                                                                                                                                                                                                          |
| `--enforce-fs-authentication`     | Enforce filesystem authentication                                                                                                                                                                                                                                        |
| `--enforce-mount-netspace-access` | Enforce mount netspace access                                                                                                                                                                                                                                            |
| `--max-throughput`                | The maximum total throughput allowed for the tenant per second. Use a number with capacity units in Decimal or Binary: for example, 200GiB or 500GB. (format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB) |
| `--max-iops`                      | The maximum total I/O operations allowed for the tenant per second. Use a number without units: for example, 500000.                                                                                                                                                     |
| `--color`                         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                         |
| `-H`, `--HOST`                    | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                         |
| `-P`, `--PORT`                    | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                         |
| `-C`, `--CONNECT-TIMEOUT`         | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                               |
| `-T`, `--TIMEOUT`                 | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                   |
| `--profile`                       | Name of the connection and authentication profile to use                                                                                                                                                                                                                 |
| `-h`, `--help`                    | Show help message                                                                                                                                                                                                                                                        |
| `-J`, `--json`                    | Format output as JSON                                                                                                                                                                                                                                                    |

### weka umount

Unmounts wekafs filesystems. This is the helper utility installed at /sbin/umount.wekafs.

```sh
weka umount <target>
            [--type type]
            [--color color]
            [--verbose]
            [--no-mtab]
            [--lazy-unmount]
            [--force]
            [--readonly]
            [--help]

```

| Parameter              | Description                                                                                                                             |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| `target`\*             | The target mount point to unmount                                                                                                       |
| `-t`, `--type`         | Indicate that the actions should only be taken on file systems of the specified type                                                    |
| `--color`              | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                        |
| `-v`, `--verbose`      | Verbose mode                                                                                                                            |
| `-n`, `--no-mtab`      | Unmount without writing in /etc/mtab                                                                                                    |
| `-l`, `--lazy-unmount` | Detach the filesystem from the filesystem hierarchy now, and cleanup all references to the filesystem as soon as it is not busy anymore |
| `-f`, `--force`        | Force unmount                                                                                                                           |
| `-r`, `--readonly`     | In case unmounting fails, try to remount read-only                                                                                      |
| `-h`, `--help`         | Show help message                                                                                                                       |

### weka upgrade

Commands that control the upgrade precedure of Weka

```sh
weka upgrade [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |

#### weka upgrade backends

Run upgrade using a specific CLI version. This is a simplified alias for `weka local run upgrade --in <target>` and supports only a minimal set of flags.

```sh
weka upgrade backends [--container container]
                      [--mode mode]
                      [--target-release target-release]
                      [--use-requested-action use-requested-action]
                      [--color color]
                      [--allow-alerts allow-alerts]...
                      [--environment environment]...
                      [--prepare-only]
                      [--distribute-version]
                      [--can-run]
                      [--expect-stopped-io]
                      [--skip-alerts-check]
                      [--enable-upgrade-prompt]
                      [--help]
                      [<target>]...

```

| Parameter                 | Description                                                                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `target`...               | The CLI version to run the upgrade command in                                                                                                                                              |
| `-C`, `--container`       | The container to run in                                                                                                                                                                    |
| `--mode`                  | The type of upgrade to perform                                                                                                                                                             |
| `--target-release`        | The target release to upgrade to. This is a release string, and should be in the format of X.Y.Z.                                                                                          |
| `--use-requested-action`  | Use requested action mechanism to drain containers during upgrade (true/false)                                                                                                             |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                           |
| `--allow-alerts`...       | Allow a specific alert type to be active when starting the upgrade - Prefer using this flag to allow specific alerts instead of skipping alerts check (may be repeated or comma-separated) |
| `-e`, `--environment`...  | Environment variable (KEY=VALUE) to forward into the upgrade container (may be repeated)                                                                                                   |
| `--prepare-only`          | Checks we can upgrade, downloads and prepares the version on all hosts, but doesn't actually start the upgrade process                                                                     |
| `--distribute-version`    | Only downloads and prepares the version on all hosts, but doesn't actually start the upgrade process                                                                                       |
| `--can-run`               | Is the system ready for the upgrade to run                                                                                                                                                 |
| `--expect-stopped-io`     | Expect the system to already be in a stopped IO state                                                                                                                                      |
| `--skip-alerts-check`     | Skip the check making sure there are no active alerts                                                                                                                                      |
| `--enable-upgrade-prompt` | Enable prompts between host upgrades                                                                                                                                                       |
| `-h`, `--help`            | Show help message                                                                                                                                                                          |

#### weka upgrade supported-features

List upgrade features supported by the running cluster

```sh
weka upgrade supported-features [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]
                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

### weka user

List users defined in the Weka cluster

```sh
weka user [--color color]
          [--HOST HOST]
          [--PORT PORT]
          [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
          [--TIMEOUT TIMEOUT]
          [--profile profile]
          [--format format]
          [--output output]...
          [--sort sort]...
          [--filter filter]...
          [--filter-color filter-color]...
          [--help]
          [--include-tenants]
          [--no-header]
          [--verbose]

```

| Parameter                 | Description                                                                                                                                                                             |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                        |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                        |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                        |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                              |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                  |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                                                                    |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: uid,tenantId,tenant,user,source,role,s3Policy,posix\_uid,posix\_gid (may be repeated or comma-separated)             |
| `-s`, `--sort`...         | Specify which column(s) to take into account when sorting the output. May include a '+' or '-' before the column name to sort in ascending or descending order respectively. Usage: \[+ |
| `-F`, `--filter`...       | Specify what values to filter by in a specific column. Usage: column1=val1\[,column2=val2\[,..]] (may be repeated or comma-separated)                                                   |
| `--filter-color`...       | Filter rows with specific colors (red/yellow/green) (may be repeated or comma-separated)                                                                                                |
| `-h`, `--help`            | Show help message                                                                                                                                                                       |
| `--include-tenants`       | Include users from all tenants (ClusterAdmin only, ignored for other users)                                                                                                             |
| `--no-header`             | Don't show column headers when printing the output                                                                                                                                      |
| `-v`, `--verbose`         | Show all columns in output                                                                                                                                                              |

#### weka user add

Create a new user in the Weka cluster

```sh
weka user add <username>
              <role>
              [--posix-uid posix-uid]
              [--posix-gid posix-gid]
              [--color color]
              [--HOST HOST]
              [--PORT PORT]
              [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
              [--TIMEOUT TIMEOUT]
              [--profile profile]
              [--help]
              [--json]

```

| Parameter                 | Description                                                                                                                                                                                                                                     |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `username`\*              | Username of the new user to create                                                                                                                                                                                                              |
| `role`\*                  | The role of the new user (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi')                                                                                                                                          |
| `password`\*              | Password for the new user: must contain at least 8 characters, and have at least one uppercase letter, one lowercase letter, and one number or special character. Typing special characters as arguments to this command might require escaping |
| `--posix-uid`             | POSIX UID for user (S3 Only)                                                                                                                                                                                                                    |
| `--posix-gid`             | POSIX GID for user (S3 Only)                                                                                                                                                                                                                    |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                      |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                          |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                        |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                               |
| `-J`, `--json`            | Format output as JSON                                                                                                                                                                                                                           |

#### weka user change-role

Change the role of an existing user.

```sh
weka user change-role <username>
                      <role>
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | Username of user to change the role of                                                                     |
| `role`\*                  | New role to set for the user (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka user remove

Delete user from the Weka cluster

```sh
weka user remove <username>
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | User's name                                                                                                |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka user generate-token

Generate an access token for the current logged in user for use with REST API

```sh
weka user generate-token [--access-token-timeout access-token-timeout]
                         [--color color]
                         [--HOST HOST]
                         [--PORT PORT]
                         [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                         [--TIMEOUT TIMEOUT]
                         [--profile profile]
                         [--help]
                         [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--access-token-timeout`  | In how long should the access token expire (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)          |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka user ldap

Show current LDAP configuration used for authenticating users

```sh
weka user ldap [--color color]
               [--HOST HOST]
               [--PORT PORT]
               [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
               [--TIMEOUT TIMEOUT]
               [--profile profile]
               [--help]
               [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka user ldap disable**

Disable authentication through the configured LDAP server

```sh
weka user ldap disable [--color color]
                       [--HOST HOST]
                       [--PORT PORT]
                       [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                       [--TIMEOUT TIMEOUT]
                       [--profile profile]
                       [--force]
                       [--help]
                       [--json]

```

| Parameter                 | Description                                                                                                                    |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                               |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                               |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                               |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                     |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                         |
| `--profile`               | Name of the connection and authentication profile to use                                                                       |
| `-f`, `--force`           | Force this action without further confirmation. This would prevent all LDAP users from logging-in until LDAP is enabled again. |
| `-h`, `--help`            | Show help message                                                                                                              |
| `-J`, `--json`            | Format output as JSON                                                                                                          |

**weka user ldap enable**

Enable authentication through the configured LDAP server (has no effect if LDAP server is already enabled)

```sh
weka user ldap enable [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka user ldap refresh-imported**

Refreshes all users imported from an LDAP S3 source, updating their UID, GID, and S3 policy to match the values in the LDAP directory.

```sh
weka user ldap refresh-imported [--color color]
                                [--HOST HOST]
                                [--PORT PORT]
                                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                                [--TIMEOUT TIMEOUT]
                                [--profile profile]
                                [--help]
                                [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

**weka user ldap reset**

Delete all LDAP settings from the cluster

```sh
weka user ldap reset [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--force]
                     [--help]
                     [--json]

```

| Parameter                 | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                  |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                  |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                  |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                        |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                            |
| `--profile`               | Name of the connection and authentication profile to use                                                                          |
| `-f`, `--force`           | Force this action without further confirmation. This would prevent all LDAP users from logging-in until LDAP is configured again. |
| `-h`, `--help`            | Show help message                                                                                                                 |
| `-J`, `--json`            | Format output as JSON                                                                                                             |

**weka user ldap setup**

Setup an LDAP server for user authentication

```sh
weka user ldap setup <server-uri>
                     <base-dn>
                     <user-object-class>
                     <user-id-attribute>
                     <group-object-class>
                     <group-membership-attribute>
                     <group-id-attribute>
                     <reader-username>
                     [--cluster-admin-group cluster-admin-group]
                     [--tenant-admin-group tenant-admin-group]
                     [--regular-group regular-group]
                     [--readonly-group readonly-group]
                     [--start-tls start-tls]
                     [--ignore-start-tls-failure ignore-start-tls-failure]
                     [--server-timeout-secs server-timeout-secs]
                     [--protocol-version protocol-version]
                     [--user-uuid-attribute user-uuid-attribute]
                     [--user-revocation-attribute user-revocation-attribute]
                     [--color color]
                     [--HOST HOST]
                     [--PORT PORT]
                     [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                     [--TIMEOUT TIMEOUT]
                     [--profile profile]
                     [--help]
                     [--json]

```

| Parameter                      | Description                                                                                                                         |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- |
| `server-uri`\*                 | LDAP server URI (\[ldap\://]hostname\[:port] or ldaps\://hostname\[:port])                                                          |
| `base-dn`\*                    | Base DN                                                                                                                             |
| `user-object-class`\*          | User object class                                                                                                                   |
| `user-id-attribute`\*          | User ID attribute                                                                                                                   |
| `group-object-class`\*         | Group object class                                                                                                                  |
| `group-membership-attribute`\* | Group membership attribute                                                                                                          |
| `group-id-attribute`\*         | Group ID attribute                                                                                                                  |
| `reader-username`\*            | Reader username                                                                                                                     |
| `reader-password`\*            | Reader password                                                                                                                     |
| `--cluster-admin-group`        | LDAP group of users that should get ClusterAdmin role (this role is only available for the root tenant to configure)                |
| `--tenant-admin-group`         | LDAP group of users that should get TenantAdmin role                                                                                |
| `--regular-group`              | LDAP group of users that should get Regular role                                                                                    |
| `--readonly-group`             | LDAP group of users that should get ReadOnly role                                                                                   |
| `--start-tls`                  | Issue StartTLS after connecting (should not be used with ldaps\://) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--ignore-start-tls-failure`   | Ignore start TLS failure (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                            |
| `--server-timeout-secs`        | LDAP connection timeout in seconds                                                                                                  |
| `--protocol-version`           | LDAP protocol version                                                                                                               |
| `--user-uuid-attribute`        | LDAP attribute name for user UUID (default: entryUUID)                                                                              |
| `--user-revocation-attribute`  | User revocation attribute: If provided, updating this attribute in the LDAP server automatically revokes all user tokens.           |
| `--color`                      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                 | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                 | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`      | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`              | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                    | Name of the connection and authentication profile to use                                                                            |
| `-h`, `--help`                 | Show help message                                                                                                                   |
| `-J`, `--json`                 | Format output as JSON                                                                                                               |

**weka user ldap setup-ad**

Setup an Active Directory server for user authentication

```sh
weka user ldap setup-ad <server-uri>
                        <domain>
                        <reader-username>
                        [--cluster-admin-group cluster-admin-group]
                        [--tenant-admin-group tenant-admin-group]
                        [--regular-group regular-group]
                        [--readonly-group readonly-group]
                        [--start-tls start-tls]
                        [--ignore-start-tls-failure ignore-start-tls-failure]
                        [--server-timeout-secs server-timeout-secs]
                        [--user-revocation-attribute user-revocation-attribute]
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--json]

```

| Parameter                     | Description                                                                                                                         |
| ----------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `server-uri`\*                | LDAP server URI (\[ldap\://]hostname\[:port] or ldaps\://hostname\[:port])                                                          |
| `domain`\*                    | Domain                                                                                                                              |
| `reader-username`\*           | Reader username                                                                                                                     |
| `reader-password`\*           | Reader password                                                                                                                     |
| `--cluster-admin-group`       | LDAP group of users that should get ClusterAdmin role (this role is only available for the root tenant to configure)                |
| `--tenant-admin-group`        | LDAP group of users that should get TenantAdmin role                                                                                |
| `--regular-group`             | LDAP group of users that should get Regular role                                                                                    |
| `--readonly-group`            | LDAP group of users that should get ReadOnly role                                                                                   |
| `--start-tls`                 | Issue StartTLS after connecting (should not be used with ldaps\://) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--ignore-start-tls-failure`  | Ignore start TLS failure (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                                            |
| `--server-timeout-secs`       | LDAP connection timeout in seconds                                                                                                  |
| `--user-revocation-attribute` | User revocation attribute: If provided, updating this attribute in the LDAP server automatically revokes all user tokens.           |
| `--color`                     | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`     | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`             | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                   | Name of the connection and authentication profile to use                                                                            |
| `-h`, `--help`                | Show help message                                                                                                                   |
| `-J`, `--json`                | Format output as JSON                                                                                                               |

**weka user ldap update**

Edit LDAP server configuration

```sh
weka user ldap update [--server-uri server-uri]
                      [--base-dn base-dn]
                      [--user-object-class user-object-class]
                      [--user-id-attribute user-id-attribute]
                      [--group-object-class group-object-class]
                      [--group-membership-attribute group-membership-attribute]
                      [--group-id-attribute group-id-attribute]
                      [--reader-username reader-username]
                      [--reader-password reader-password]
                      [--cluster-admin-group cluster-admin-group]
                      [--tenant-admin-group tenant-admin-group]
                      [--regular-group regular-group]
                      [--readonly-group readonly-group]
                      [--start-tls start-tls]
                      [--ignore-start-tls-failure ignore-start-tls-failure]
                      [--server-timeout-secs server-timeout-secs]
                      [--protocol-version protocol-version]
                      [--user-uuid-attribute user-uuid-attribute]
                      [--user-revocation-attribute user-revocation-attribute]
                      [--color color]
                      [--HOST HOST]
                      [--PORT PORT]
                      [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                      [--TIMEOUT TIMEOUT]
                      [--profile profile]
                      [--help]
                      [--json]

```

| Parameter                      | Description                                                                                                                         |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- |
| `--server-uri`                 | LDAP server URI (\[ldap\://]hostname\[:port] or ldaps\://hostname\[:port])                                                          |
| `--base-dn`                    | Base DN                                                                                                                             |
| `--user-object-class`          | User object class                                                                                                                   |
| `--user-id-attribute`          | User ID attribute                                                                                                                   |
| `--group-object-class`         | Group object class                                                                                                                  |
| `--group-membership-attribute` | Group membership attribute                                                                                                          |
| `--group-id-attribute`         | Group ID attribute                                                                                                                  |
| `--reader-username`            | Reader username                                                                                                                     |
| `--reader-password`            | Reader password                                                                                                                     |
| `--cluster-admin-group`        | LDAP group of users that should get ClusterAdmin role (this role is only available for the root tenant to configure)                |
| `--tenant-admin-group`         | LDAP group of users that should get TenantAdmin role                                                                                |
| `--regular-group`              | LDAP group of users that should get Regular role                                                                                    |
| `--readonly-group`             | LDAP group of users that should get ReadOnly role                                                                                   |
| `--start-tls`                  | Issue StartTLS after connecting (should not be used with ldaps\://) (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n') |
| `--ignore-start-tls-failure`   | Ignore certificate verification errors (format: 'yes', 'no', 'true', 'false', 'on', 'off', 'y' or 'n')                              |
| `--server-timeout-secs`        | LDAP connection timeout in seconds                                                                                                  |
| `--protocol-version`           | LDAP protocol version                                                                                                               |
| `--user-uuid-attribute`        | LDAP attribute name for user UUID (default: entryUUID)                                                                              |
| `--user-revocation-attribute`  | User revocation attribute: If provided, updating this attribute in the LDAP server automatically revokes all user tokens.           |
| `--color`                      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                    |
| `-H`, `--HOST`                 | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                    |
| `-P`, `--PORT`                 | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                    |
| `-C`, `--CONNECT-TIMEOUT`      | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                          |
| `-T`, `--TIMEOUT`              | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                              |
| `--profile`                    | Name of the connection and authentication profile to use                                                                            |
| `-h`, `--help`                 | Show help message                                                                                                                   |
| `-J`, `--json`                 | Format output as JSON                                                                                                               |

#### weka user login

Logs a user into the Weka cluster. If login is successful, the user credentials are saved to the user homedir.

```sh
weka user login [username]
                [password]
                [--tenant tenant]
                [--path path]
                [--color color]
                [--HOST HOST]
                [--PORT PORT]
                [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                [--TIMEOUT TIMEOUT]
                [--profile profile]
                [--help]

```

| Parameter                 | Description                                                                                                                                                                                                                                                           |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `username`                | User's username                                                                                                                                                                                                                                                       |
| `password`                | User's password                                                                                                                                                                                                                                                       |
| `-g`, `--tenant`          | Tenant name or ID                                                                                                                                                                                                                                                     |
| `-p`, `--path`            | The path where the login token will be saved (default: \~/.weka/auth-token.json). This path can also be specified using the WEKA\_TOKEN environment variable. After logging-in, use the WEKA\_TOKEN environment variable to specify where the login token is located. |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                      |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                                                      |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                                                      |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                            |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                                                                |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                                                              |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                                                     |

#### weka user logout

Logs the current user out of the Weka cluster by removing the user credentials from WEKA\_TOKEN if exists, or otherwise from the user homedir

```sh
weka user logout [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka user passwd

Set a user's password. If the currently logged-in user is an admin, it can change the password for all other users in the tenant.

```sh
weka user passwd [--username username]
                 [--current-password current-password]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--help]

```

| Parameter                 | Description                                                                                                                                                                                                                        |
| ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `password`\*              | New password: must contain at least 8 characters, and have at least one uppercase letter, one lowercase letter, and one number or special character. Typing special characters as arguments to this command might require escaping |
| `--username`              | Username to change the password for, by default password is changed for the current user                                                                                                                                           |
| `--current-password`      | User's current password. Only necessary if changing current user's password                                                                                                                                                        |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                   |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                                                                                                                   |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                                                                                                                   |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                         |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                                                                                                             |
| `--profile`               | Name of the connection and authentication profile to use                                                                                                                                                                           |
| `-h`, `--help`            | Show help message                                                                                                                                                                                                                  |

#### weka user revoke-tokens

Revoke all existing login tokens of an internal user

```sh
weka user revoke-tokens <username>
                        [--color color]
                        [--HOST HOST]
                        [--PORT PORT]
                        [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                        [--TIMEOUT TIMEOUT]
                        [--profile profile]
                        [--help]
                        [--json]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | Username of user to revoke the tokens for                                                                  |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |
| `-J`, `--json`            | Format output as JSON                                                                                      |

#### weka user update

Change parameters of an existing user.

```sh
weka user update <username>
                 [--posix-uid posix-uid]
                 [--posix-gid posix-gid]
                 [--role role]
                 [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--help]

```

| Parameter                 | Description                                                                                                |
| ------------------------- | ---------------------------------------------------------------------------------------------------------- |
| `username`\*              | Username of user to update                                                                                 |
| `--posix-uid`             | POSIX UID for user (S3 Only)                                                                               |
| `--posix-gid`             | POSIX GID for user (S3 Only)                                                                               |
| `--role`                  | New role to set for the user (format: 'clusteradmin', 'tenantadmin', 'regular', 'readonly', 's3' or 'csi') |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                           |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                           |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                           |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited) |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)     |
| `--profile`               | Name of the connection and authentication profile to use                                                   |
| `-h`, `--help`            | Show help message                                                                                          |

#### weka user whoami

Get information about currently logged-in user

```sh
weka user whoami [--color color]
                 [--HOST HOST]
                 [--PORT PORT]
                 [--CONNECT-TIMEOUT CONNECT-TIMEOUT]
                 [--TIMEOUT TIMEOUT]
                 [--profile profile]
                 [--format format]
                 [--output output]...
                 [--help]
                 [--no-header]
                 [--verbose]

```

| Parameter                 | Description                                                                                                                            |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| `--color`                 | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                       |
| `-H`, `--HOST`            | Specify the host. Alternatively, use the WEKA\_HOST env variable                                                                       |
| `-P`, `--PORT`            | Specify the port. Alternatively, use the WEKA\_PORT env variable                                                                       |
| `-C`, `--CONNECT-TIMEOUT` | Timeout for connecting to cluster, default: 10 secs (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                             |
| `-T`, `--TIMEOUT`         | Timeout to wait for response, default: 1 minute (format: 3s, 2h, 4m, 1d, 1d5h, 1w, infinite/unlimited)                                 |
| `--profile`               | Name of the connection and authentication profile to use                                                                               |
| `-f`, `--format`          | Specify in what format to output the result (format: 'view', 'csv', 'markdown', 'json' or 'oldview')                                   |
| `-o`, `--output`...       | Specify which columns to output. May include any of the following: orgId,orgName,user,source,role (may be repeated or comma-separated) |
| `-h`, `--help`            | Show help message                                                                                                                      |
| `--no-header`             | Don't show column headers when printing the output                                                                                     |
| `-v`, `--verbose`         | Show all columns in output                                                                                                             |

### weka version

When run without arguments, lists the versions available on this machine. Subcommands allow for downloading of versions, setting the current version and other actions to manage versions.

```sh
weka version [--color color] [--full] [--help] [--json]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--full`       | Show only fully installed versions                                               |
| `-h`, `--help` | Show help message                                                                |
| `-J`, `--json` | Format output as JSON                                                            |

#### weka version current

Prints the current version. If no version is set, a failure exit status is returned.

```sh
weka version current [--container container] [--color color] [--help]

```

| Parameter           | Description                                                                      |
| ------------------- | -------------------------------------------------------------------------------- |
| `-C`, `--container` | Get the version for a specific container                                         |
| `--color`           | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`      | Show help message                                                                |

#### weka version get

Download a Weka version to the machine this command is executed from

```sh
weka version get <version>
                 [--color color]
                 [--from from]...
                 [--set-current]
                 [--no-progress-bar]
                 [--set-dist-servers]
                 [--client-only]
                 [--driver-only]
                 [--help]

```

| Parameter            | Description                                                                                                                                                                                                                                                                                        |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `version`\*          | Version to download                                                                                                                                                                                                                                                                                |
| `--color`            | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                                                                                                                                                                                                                   |
| `--from`...          | Download from this distribution server (can be given multiple times). Otherwise distribution servers are taken from the $WEKA\_DIST\_SERVERS environment variable, the /etc/wekaio/dist-servers file, or /etc/wekaio/service.conf in that order of precedence (may be repeated or comma-separated) |
| `--set-current`      | Set the downloaded version as the current version. Will fail if any containers are currently running.                                                                                                                                                                                              |
| `--no-progress-bar`  | Don't render download progress bar                                                                                                                                                                                                                                                                 |
| `--set-dist-servers` | Override the default distribution servers upon successful download                                                                                                                                                                                                                                 |
| `--client-only`      | Only download components required for client                                                                                                                                                                                                                                                       |
| `--driver-only`      | Only download components required for compiling drivers                                                                                                                                                                                                                                            |
| `-h`, `--help`       | Show help message                                                                                                                                                                                                                                                                                  |

#### weka version prepare

Prepare the version for use. This includes things like compiling the version drivers for the local machine.

```sh
weka version prepare <version-name> [--color color] [--help] [<containers>]...

```

| Parameter        | Description                                                                      |
| ---------------- | -------------------------------------------------------------------------------- |
| `version-name`\* | The version to prepare                                                           |
| `containers`...  | The containers to prepare the version for                                        |
| `--color`        | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help`   | Show help message                                                                |

#### weka version rm

Delete a version from the machine this command is executed from

```sh
weka version rm [--color color] [--clean-unused] [--force] [--help] [<version-name>]...

```

| Parameter         | Description                                                                                              |
| ----------------- | -------------------------------------------------------------------------------------------------------- |
| `version-name`... | The versions to remove                                                                                   |
| `--color`         | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled')                         |
| `--clean-unused`  | Delete all versions which aren't the current set version, or the version of any of the containers        |
| `-f`, `--force`   | Force this action without further confirmation. This action may be undone by re-downloading the version. |
| `-h`, `--help`    | Show help message                                                                                        |

#### weka version set

Set the current version. Containers must be stopped before setting the current version and the new version must have already been downloaded.

```sh
weka version set <version>
                 [--container container]
                 [--color color]
                 [--allow-running-containers]
                 [--default-only]
                 [--agent-only]
                 [--set-dependent]
                 [--client-only]
                 [--help]

```

| Parameter                    | Description                                                                      |
| ---------------------------- | -------------------------------------------------------------------------------- |
| `version`\*                  | The version name to use                                                          |
| `-C`, `--container`          | The container to set the version for                                             |
| `--color`                    | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `--allow-running-containers` | Do not verify that all containers are stopped                                    |
| `--default-only`             | Only set the default version used for creating containers                        |
| `--agent-only`               | Only set the agent version                                                       |
| `--set-dependent`            | Set the version for all containers depending on the specified container          |
| `--client-only`              | Only set the client version                                                      |
| `-h`, `--help`               | Show help message                                                                |

#### weka version reset

Unset the current version. Containers must be stopped before setting the current version and the new version must have already been downloaded.

```sh
weka version reset [--color color] [--help]

```

| Parameter      | Description                                                                      |
| -------------- | -------------------------------------------------------------------------------- |
| `--color`      | Specify whether to use color in output (format: 'auto', 'disabled' or 'enabled') |
| `-h`, `--help` | Show help message                                                                |


# Perform a basic IO sanity check

Use this procedure to perform a basic input/output (IO) sanity check on a newly installed WEKA cluster to confirm it is operational.

Use this procedure to perform a basic input/output (IO) sanity check on a newly installed WEKA cluster. This check involves creating a filesystem, mounting it, and writing a small amount of data to confirm the system is operational.

After completing this sanity check, you can proceed to validate that the WEKA cluster and your IT environment are configured for optimal performance.

## Create a filesystem

To create a filesystem, you first create a filesystem group and then create the filesystem within that group.

**Procedure**

1. Create a filesystem group. A filesystem must reside in a group.

   ```bash
   $ weka fs group create my_fs_group
   FSGroupId: 0
   ```
2. View the existing filesystem groups to confirm the creation.

   ```bash
   $ weka fs group
   FileSystem Group ID | Name        | target-ssd-retention | start-demote
   FSGroupId: 0          | my_fs_group | 1d 0:00:00h          | 0:15:00h
   ```
3. Create a filesystem within the new group.

   ```bash
   $ weka fs create new_fs my_fs_group 1TiB
   FSId: 0
   ```
4. View the existing filesystems to confirm the creation

   ```bash
   $ weka fs
   Filesystem ID | Filesystem Name | Group       | Used SSD (Data) | Used SSD (Meta) | Used SSD | Free SSD | Available SSD (Meta) | Available SSD | Used Total (Data) | Used Total | Free Total | Available Total | Max Files | Status | Encrypted | Object Storages | Auth Required
   +-------------+-----------------+-------------+-----------------+-----------------+----------+----------+----------------------+---------------+-------------------+------------+------------+-----------------+-----------+--------+-----------+-----------------+---------------+
   0             | new_fs          | my_fs_group | 0 B             | 4.09 KB         | 4.09 KB  | 1.09 TB  | 274.87 GB            | 1.09 TB       | 0 B               | 4.09 KB    | 1.09 TB    | 1.09 TB         | 22107463  | READY  | False     |                 | False
   ```

{% hint style="info" %}
On WEKA systems installed in AWS through the [self-service portal,](https://start.weka.io/) a `default` filesystem group and a `default` filesystem are created automatically. The `default` filesystem uses the entire available SSD capacity.

To create an additional filesystem, first reduce the size of the `default` filesystem.

```
# Reduce the size of the default filesystem
$ weka fs update default --total-capacity 1GiB

# Create a new filesystem in the default group
$ weka fs create new_fs default 1GiB

# View the existing filesystems
$ weka fs
Filesystem ID | Filesystem Name | Group   | Used SSD (Data) | Used SSD (Meta) | Used SSD | Free SSD | Available SSD (Meta) | Available SSD | Used Total (Data) | Used Total | Free Total | Available Total | Max Files | Status | Encrypted | Object Storages | Auth Required
--------------+-----------------+---------+-----------------+-----------------+----------+----------+----------------------+---------------+-------------------+------------+------------+-----------------+-----------+--------+-----------+-----------------+--------------
0             | default         | default | 0 B             | 4.09 KB         | 4.09 KB  | 1.07 GB  | 268.43 MB            | 1.07 GB       | 0 B               | 4.09 KB    | 1.07 GB    | 1.07 GB         | 21589     | READY  | False     |                 | False
1             | new_fs          | default | 0 B             | 4.09 KB         | 4.09 KB  | 1.09 TB  | 274.87 GB            | 1.09 TB       | 0 B               | 4.09 KB    | 1.09 TB    | 1.09 TB         | 22107463  | READY  | False     |                 | False
```

{% endhint %}

## Mount the filesystem

To mount the filesystem, create a mount point directory on your server and use the `mount` command.

**Procedure**

1. Create a directory to serve as the mount point and mount the filesystem.

   ```bash
   $ sudo mkdir -p /mnt/weka
   $ sudo mount -t wekafs new_fs /mnt/weka
   ```
2. Verify that the filesystem is mounted.

   ```bash
   $ mount | grep new_fs
   new_fs on /mnt/weka type wekafs (rw,relatime,writecache,inode_bits=64,dentry_max_age_positive=1000,dentry_max_age_negative=0)
   ```

{% hint style="info" %}
On WEKA systems installed in AWS through the [self-service portal](https://start.weka.io/), the `default` filesystem is already mounted under `/mnt/weka`.
{% endhint %}

## Write data to the filesystem

Write a test file to the mounted filesystem to confirm that IO operations are working correctly.

**Procedure**

1. Use the `dd` command to write a small file to the mount point.

   ```bash
   $ sudo dd if=/dev/urandom of=/mnt/weka/my_first_data bs=4096 count=10000
   10000+0 records in
   10000+0 records out
   40960000 bytes (41 MB) copied, 4.02885 s, 10.2 MB/s
   ```
2. List the contents of the directory to see the new file.

   ```bash
   $ ls -l /mnt/weka
   total 40000
   -rw-r--r-- 1 root root 40960000 Oct 30 11:58 my_first_data
   ```
3. View the filesystem details to see the change in used SSD capacity.

   ```bash
   $ weka fs
   Filesystem ID | Filesystem Name | Group   | Used SSD (Data) | Used SSD (Meta) | Used SSD  | Free SSD | Available SSD (Meta) | Available SSD | Used Total (Data) | Used Total | Free Total | Available Total | Max Files | Status | Encrypted | Object Storages | Auth Required
   +-------------+-----------------+---------+-----------------+-----------------+-----------+----------+----------------------+---------------+-------------------+------------+------------+-----------------+-----------+--------+-----------+-----------------+---------------+
   0             | default         | default | 40.95 MB        | 180.22 KB       | 41.14 MB  | 1.03 GB  | 268.43 MB            | 1.07 GB       | 40.95 MB          | 41.14 MB   | 1.03 GB    | 1.07 GB         | 21589     | READY  | False     |                 | False
   ```

   This completes the basic sanity check.

## Validate the cluster configuration

To ensure the WEKA cluster and your IT environment are optimally configured, run benchmark tests using a tool such as FIO. A properly configured environment should produce performance results similar to those documented in the official WEKA performance tests.

If your benchmark results differ significantly from the expected values, contact the Customer Success Team for assistance before running production workloads on the cluster.

**Related topics**

[Filesystems & Object Stores](/weka-filesystems-and-object-stores/managing-object-stores)

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems)

[System performance tests](/performance/testing-weka-system-performance)

[Get support for your WEKA system](/support/getting-support-for-your-weka-system#contact-customer-success-team)


# Getting started with WEKA REST API

The WEKA system provides a RESTful API that allows you to automate operations and integrate them into your workflows or monitoring systems. A solid understanding of the relevant WEKA CLI commands and parameters is important when working with the REST API. For example, when creating a filesystem using the `POST /fileSystems` service, refer to the corresponding CLI documentation for guidance.

## Access the REST API

You can access the REST API using one of the following methods:

* **Direct access:** Use port 14000 and the URL `/api/v2`.
* **Through the cluster:** Browse to `https://<cluster name or IP>:14000/api/v2/docs`.
* **Through the WEKA GUI:** Select the three dots on the upper right menu and select **REST API**.\ <img src="/files/KkxnzDlvx7szC7bvsboB" alt="" data-size="original">
* **WEKA static API:** Browse to [api.docs.weka.io](https://api.docs.weka.io/) and select the required REST API version from the definition selector. You can also generate client code by using the OpenAPI client generator with the corresponding .json definition file.<br>

  <div data-with-frame="true"><figure><img src="/files/Zo5AWpkqlDaDL5jrHo0d" alt=""><figcaption></figcaption></figure></div>

## Explore the REST API through the GUI

<div data-with-frame="true"><figure><img src="/files/zG3MmnfLu71qXPgkrNof" alt=""><figcaption><p>Explore the REST API through the GUI</p></figcaption></figure></div>

## Obtain an access token

To use the WEKA REST API, provide an access or refresh token.

You can generate an access or refresh for the REST API usage through the CLI or the GUI.\
See [Obtain authentication tokens](/security/obtain-authentication-tokens).

You can also call the login API to obtain access or refresh tokens through the API, providing it with a `username` and `password`.

If you already obtained a refresh token, you can use the `login/refresh` API to refresh the access token.

{% tabs %}
{% tab title="Login" %}
{% code title="Python example calling the login API" %}

```python
import requests

url = "https://weka01:14000/api/v2/login"

payload="{\n    \"username\": \"admin\",\n    \"password\": \"admin\"\n}"
headers = {
  'Content-Type': 'application/json'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)

```

{% endcode %}
{% endtab %}

{% tab title="Refresh" %}
{% code title="Python example calling the login refresh API" %}

```python
import requests

url = "https://weka01:14000/api/v2/login/refresh"

payload="{\n    \"refresh_token\": \"REPLACE-WITH-REFRESH-TOKEN\"\n}"
headers = {
  'Content-Type': 'application/json'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)

```

{% endcode %}
{% endtab %}
{% endtabs %}

The response includes the access token (valid for 5 minutes) to use in the other APIs requiring token authentication, along with the refresh token (valid for 1 year), for getting additional access tokens without using the username/password.

{% code title="Login/Refresh Response" %}

```python
{
  "data": [
    {
      "access_token": "ACCESS-TOKEN",
      "token_type": "Bearer",
      "expires_in": 300,
      "refresh_token": "REFRESH-TOKEN"
    }
  ]
}
```

{% endcode %}

## Call the REST API

Once you obtain an access token, you can call WEKA REST API commands with it. For example, you can query the cluster status:

{% code title="Python example calling cluster status API" %}

```python
import requests

url = "https://weka01:14000/api/v2/cluster"

payload={}
headers = {
  'Authorization': 'Bearer REPLACE-WITH-ACCESS-TOKEN'
}

response = requests.request("GET", url, headers=headers, data=payload)

print(response.text)

```

{% endcode %}

**Related topics**

[REST API Reference Guide](https://api.docs.weka.io/)


# WEKA REST API and equivalent CLI commands

To use the REST API effectively, review the comprehensive documentation, which provides detailed guidance on all available methods. Each REST API method corresponds to a CLI command, and most CLI parameters are also supported through the REST API. Use the CLI command help to view parameter details. This alignment ensures a consistent experience across both interfaces.

**Related topic**

[Getting started with WEKA REST API](/getting-started-with-weka/getting-started-with-weka-rest-api)

{% hint style="info" %}
New REST APIs in version 5.1.30, compared to 5.0.4, are marked with two asterisks (\*\*).
{% endhint %}

## Active directory

Related information: [User management](/operation-guide/user-management)

| Task                                                                                                                                                                                                                               | REST API                                                                                                              | CLI                       |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------- |
| **Update the Active Directory configuration:** Configures the integration with an Active Directory server for user management. This allows for authenticating users and mapping their group memberships to the cluster user roles. | [PUT ​/activeDirectory](https://api.docs.weka.io/?urls.primaryName=5.1#/Active%20directory/updateLdapActiveDirectory) | `weka user ldap setup-ad` |

## Alerts

Related information: [Alerts](/operation-guide/alerts)

| Task                                                                                                                                                                                                                                                                                                                           | REST API                                                                                                              | CLI                                        |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| **Get all cluster alerts:** Returns a list of active cluster alerts to monitor the system's health. The list includes silenced alerts and can be filtered by severity level.                                                                                                                                                   | [GET ​/alerts](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/getAlerts)                                      | `weka alerts`                              |
| **List all possible alert types:** Returns a comprehensive list of all possible alert types that the system can generate.                                                                                                                                                                                                      | [GET ​/alerts​/types](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/getAlertsTypes)                          | `weka alerts types`                        |
| **List alert descriptions and recommended actions:** Returns detailed descriptions and recommended troubleshooting actions for all possible alert types.                                                                                                                                                                       | [GET ​/alerts​/description](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/getAlertDescription)               | `weka alerts describe`                     |
| **List all active alert mute rules:** Returns all currently active alert mute rules. Muted alerts do not generate notifications.                                                                                                                                                                                               | [GET ​/alerts​/muteList](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/getAlertMutes) \*\*                   | `weka alerts mute list`                    |
| <p><strong>Mute alerts by type:</strong> Creates a rule to temporarily mute a specific type of alert. This is useful for preventing notifications during maintenance or for known, non-critical issues.</p><p>The mute can be applied globally to an alert type or filtered to specific servers, containers, or processes.</p> | [PUT ​/alerts​/{alert\_type}​/mute](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/muteAlertByType) \*\*      | `weka alerts mute <alert-type> <duration>` |
| **Add parameters to an alert mute:** Expands the scope of an existing alert mute by adding specific processes, containers, or servers. This action allows for granular suppression of notifications for a particular alert type without modifying the entire entry.                                                            | [PUT ​/alerts​/{alert\_type}/muteAdd](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/muteAlertAdd) \*\*       | `weka alerts mute add`                     |
| **Remove parameters from alert mute:** Selectively restore alerts for processes, containers, or servers by removing them from an active alert mute. This action reactivates notifications for the specified identifiers while keeping other components under the same alert type silenced.                                     | [PUT ​/alerts​/{alert\_type}/muteRemove](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/muteAlertRemove) \*\* | `weka alerts mute remove`                  |
| **Unmute alerts by type:** Removes all active mute rules for a specific alert type, causing it to generate notifications again.                                                                                                                                                                                                | [PUT ​/alerts​/{alert\_type}​/unmute](https://api.docs.weka.io/?urls.primaryName=5.1#/Alerts/unmuteAlertByType)       | `weka alerts unmute <alert-type>`          |

## Catalog

Related information: [Data catalog](/weka-filesystems-and-object-stores/data-catalog)

Use the Catalog REST APIs to manage and query filesystem metadata for detailed data analysis and insights.

{% hint style="info" %}
The `weka catalog` CLI commands do not apply to these analytics REST APIs.
{% endhint %}

<table><thead><tr><th>Task</th><th width="249">REST API</th></tr></thead><tbody><tr><td><strong>Run catalog query with nested filters:</strong> Execute a catalog query over the catalog view with nested AND/OR criteria.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/postCatalogQuery">POST /catalog/query</a>**</td></tr><tr><td><strong>Compare two point-in-time snapshots and return differences:</strong> Powers Comparison Insights. Shows what changed between two snapshots using <code>FsOperationType</code> values.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/postCatalogQueryDiff">POST /catalog/query/diff</a>**</td></tr><tr><td><strong>Get filesystem usage statistics by user:</strong> Query filesystem usage statistics grouped by user.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogUsageByUser">GET /catalog/stats/usageByUser</a>**</td></tr><tr><td><strong>Get filesystem usage statistics by group:</strong> Query filesystem usage statistics grouped by group name.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogUsageByGroup">GET /catalog/stats/usageByGroup</a> **</td></tr><tr><td><strong>Get list of snapshot metadata available for a filesystem in the catalog:</strong> Retrieve a list of snapshot metadata available for a filesystem in the catalog.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getFilesystemSnapshots">GET /catalog/snapshots/{fs_uuid}</a> **</td></tr><tr><td><strong>Get file distribution by extension:</strong> Query file count distribution grouped by file extension.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogDistributionByExtension">GET /catalog/stats/distributionByExtension</a> **</td></tr><tr><td><strong>Get files by size buckets:</strong> Query file distribution grouped by size ranges (for example: 0-1KB, 1TB-10TB, 10TB+).</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogFilesBySize">GET /catalog/stats/filesBySize</a> **</td></tr><tr><td><strong>Get capacity by file age:</strong> Query total file capacity grouped by file age based on modification time (for example: &#x3C; 1 week, 1-3 months, 2-5 years, 5+ years).</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogCapacityByFileAge">GET /catalog/stats/capacityByFileAge</a> **</td></tr><tr><td><strong>Get dashboard statistics:</strong> Get combined statistics including quick stats, top users, and file types.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogDashboard">GET /catalog/stats/dashboard</a> **</td></tr><tr><td><strong>Get hierarchical directory tree with size statistics:</strong> Retrieve directory tree showing multiple levels with direct and recursive size aggregations. All sizes returned in bytes.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getCatalogDirectoryTree">GET /catalog/stats/directoryTree </a>**</td></tr><tr><td><strong>Get filesystem capacity metadata history:</strong> Query filesystem capacity metadata showing SSD and total capacity trends over time.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getFilesystemMetadata">GET /catalog/filesystem/metadata </a>**</td></tr><tr><td><p><strong>Get point-in-time filesystem capacity metadata:</strong> Query filesystem capacity metadata for a specific snapshot access point or the latest metadata.</p><p>If <code>access_point</code> is provided: returns metadata for that specific snapshot.</p><p>If <code>access_point</code> is not provided: returns the latest (most recent) metadata.</p></td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Catalog/getPointInTimeFilesystemMetadata">GET /catalog/filesystem/metadata/point-in-time</a> **</td></tr></tbody></table>

## WEKA Home

Related information: [WEKA Home - The WEKA support cloud](/monitor-the-weka-cluster/the-wekaio-support-cloud)

| Task                                                                                                 | REST API                                                                                                        | CLI                                                            |
| ---------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |
| **Get WEKA Home configuration:** Returns the current configuration for the WEKA Home cloud service.. | [GET ​/wekaHome](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/getCloud)                          | `weka cloud status`                                            |
| **Get WEKA Home proxy URL:** Returns the configured proxy URL for accessing WEKA Home.               | [GET ​/wekaHome​/proxy](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/getCloudProxy)              | `weka cloud proxy`                                             |
| **Set WEKA Home proxy URL:** Sets or updates the proxy URL used for accessing WEKA Home.             | [POST ​/wekaHome​/proxy](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/setCloudProxy)             | `weka cloud proxy --set <proxy_url>`                           |
| **Get WEKA Home upload rate:** Returns the current data upload rate limit for WEKA Home.             | [GET ​/wekaHome​/uploadRate](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/getCloudUploadRate)    | `weka cloud upload-rate`                                       |
| **Set WEKA Home upload rate:** Sets the maximum data upload rate to WEKA Home in bytes per second.   | [PUT ​/wekaHome​/uploadRate](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/updateCloudUploadRate) | `weka cloud upload-rate set --bytes-per-second <bps>`          |
| **Get WEKA Home URL:** Returns the base URL for the WEKA Home cloud service.                         | [GET ​/wekaHome​/url](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/getCloudUrl)                  | `weka cloud status`                                            |
| **Enable WEKA Home:** Enables and configures the connection to the WEKA Home cloud service.          | [POST ​/wekaHome​/enable](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/enableCloud)              | `weka cloud enable --cloud-url <cloud> --cloud-stats <on/off>` |
| **Disable WEKA Home:** Disables the connection to the WEKA Home cloud service.                       | [POST ​/wekaHome​/disable](https://api.docs.weka.io/?urls.primaryName=5.1#/Weka%20home/disableCloud)            | `weka cloud disable`                                           |

## Cluster

Related information: [System installation on bare metal servers](/planning-and-installation/bare-metal)

<table><thead><tr><th width="240.984375">Task</th><th width="207.8046875">REST API</th><th>CLI</th></tr></thead><tbody><tr><td><strong>Create a cluster:</strong> Forms a new WEKA cluster from a list of specified servers.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Cluster/createCluster">POST ​/cluster</a></td><td><code>weka cluster add &#x3C;host-hostnames></code></td></tr><tr><td><strong>Update cluster configuration:</strong> Modifies the configuration settings of an existing cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Cluster/updateCluster">PUT ​/cluster</a></td><td><code>weka cluster update</code></td></tr><tr><td><strong>Get cluster status:</strong> Returns a comprehensive status report for the cluster, including health, performance metrics, and capacity.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Cluster/getClusterStatus">GET ​/cluster</a></td><td><code>weka status --json</code></td></tr><tr><td><strong>Get capacity reduction details:</strong> Returns data reduction statistics for the cluster, including the total saved bytes and the reduction ratio.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Cluster/getClusterCapacityReduction">GET /cluster/capacity_reduction</a></td><td><code>weka status reduction</code></td></tr></tbody></table>

## Containers

Related information:

* [Expand and shrink cluster resources](/operation-guide/expanding-and-shrinking-cluster-resources)
* [Container state and status fields](/operation-guide/expanding-and-shrinking-cluster-resources/container-state-and-status-fields)

| Task                                                                                                                                                                                                | REST API                                                                                                                                | CLI                                                          |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| **Get containers:** Returns a list of all containers in the cluster.                                                                                                                                | [GET ​/containers](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getContainers)                                            | `weka cluster container`                                     |
| **Add a container:** Adds a new container to the cluster. The container configuration must be applied to activate it.                                                                               | [POST ​/containers](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/addContainer)                                            | `weka cluster container add <hostname>`                      |
| **Get container details:** Returns the details, including resources, `state`, and `status`, for a specific container.                                                                               | [GET ​/containers​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getSingleContainer)                                | `weka cluster container <container-ids>`                     |
| **Update container configuration:** Updates the staged configuration for a specific container. Any resource configuration change, such as memory or cores, requires an apply action to take effect. | [PUT ​/containers​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/updateContainer)                                   | `weka cluster container <container-ids> <subcommand>`        |
| **Remove a container:** Deactivates and removes a container from the cluster.                                                                                                                       | [DELETE ​/containers​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/removeContainer)                                | `weka cluster container remove <container-ids>`              |
| **Perform action on protocol containers:** Performs an action, such as a restart, on specified protocol containers.                                                                                 | [POST​/containers​/manageProtoContainers](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/manageProtoContainers)             | `weka local restart <container>`                             |
| **Apply configuration updates to multiple containers:** Applies staged configuration changes to a specified list of containers.                                                                     | [POST ​/containers​/apply](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/applyContainers)                                  | `weka cluster container apply`                               |
| **Apply configuration updates to a container:** Applies staged configuration changes to a specific container.                                                                                       | [POST ​/containers​/{uid}​/apply](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/applyContainer)                            | `weka cluster container apply <container-ids>`               |
| **Clear last failure for a container:** Resets the last failure reason for a specific container.                                                                                                    | [DELETE ​/containers​/lastFailureReason​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/clearContainerFailure)       | `weka cluster container clear-failure<container-ids>`        |
| **Get container resources:** Returns the resource allocation (CPU, memory) for a specific container.                                                                                                | [GET ​/containers​/{uid}​/resources](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getContainersResources)                 | `weka cluster container resources <container-ids>`           |
| **Activate containers:** Activates a list of specified containers, bringing them online.                                                                                                            | [POST ​/containers​/activate](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/activateContainers)                            | `weka cluster container activate`                            |
| **Activate a container:** Activates a specific container, bringing it online.                                                                                                                       | [POST ​/containers​/{uid}​/activate](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/activateContainer)                      | `weka cluster container activate <container-ids>`            |
| **Deactivate containers:** Deactivates a list of specified containers.                                                                                                                              | [POST ​/containers​/deactivate](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/deactivateContainers)                        | `weka cluster container deactivate`                          |
| **Perform container deactivation check:** Simulates container deactivation to assess whether the operation can be performed safely without impacting the cluster.                                   | [POST​/containers​/deactivation-check](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/deactivateContainers%20check)         | `weka cluster container deactivation-check <container-ids>`  |
| **Deactivate a container:** Deactivates a specific container.                                                                                                                                       | [POST ​/containers​/{uid}​/deactivate](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/deactivateContainer)                  | `weka cluster container deactivate <container-ids>`          |
| **Get network devices for all containers:** Returns the network device configurations for all containers in the cluster.                                                                            | [GET ​/containers​/netdevs](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getAllContainersNetwork)                         | `weka cluster container net`                                 |
| **Get network devices for a container:** Returns the network device configurations for a specific container.                                                                                        | [GET ​/containers​/{uid}​/netdevs](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getContainerNetwork)                      | `weka cluster container net <container-ids>`                 |
| **Add a dedicated network device to a container:** Allocates a dedicated network device to a specific container. The change must be applied to take effect.                                         | [POST ​/containers​/{uid}​/netdevs](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/createContainerNetwork)                  | `weka cluster container net add <container-ids>`             |
| **Remove a dedicated network device:** Removes a dedicated network device from a container. The change must be applied to take effect.                                                              | [DELETE ​/containers​/{uid}​/netdevs​/{netdev\_uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/removeContainerNetwork) | `weka cluster container net remove <container-ids>`          |
| **Get container hardware information:** Returns hardware information for one or more containers, specified by IP or hostname.                                                                       | [POST ​/containers​/infos](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/getContainersInfo)                                | `weka cluster container info-hw`                             |
| **Set a requested action on containers:** Sets a requested action, such as STOP or RESTART, to be performed on one or more containers.                                                              | [PUT /containers/requestedAction](https://api.docs.weka.io/?urls.primaryName=5.1#/Containers/setContainerRequestedAction)               | `weka cluster requested-action set <requested_action> []...` |

## DataService

Related information: [Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks)

| Task                                                                                                                                                     | REST API                                                                                              | CLI |
| -------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | --- |
| **List Data Service features:** Returns a list of background tasks managed by the Data Services container. Currently, this includes only quota coloring. | [GET​/dataService​/features](https://api.docs.weka.io/?urls.primaryName=5.1#/DataService/getFeatures) | N/A |

## Default network

Related information: [/pages/ospkBUXCQGIqEwyRlWwn#id-6.-configure-default-data-networking-optional](https://docs.weka.io/getting-started-with-weka/pages/ospkBUXCQGIqEwyRlWwn#id-6.-configure-default-data-networking-optional "mention")

| Task                                                                                                                                                              | REST API                                                                                                     | CLI                               |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | --------------------------------- |
| **List default network settings:** Returns the predefined network properties for container deployments, including the IP address range, gateway, and subnet mask. | [GET ​/defaultNet](https://api.docs.weka.io/?urls.primaryName=5.1#/Default%20network/getDefaultNetwork)      | `weka cluster default-net`        |
| **Set default network settings:** Defines the IP address range, gateway, and subnet mask for future container network assignments.                                | [POST ​/defaultNet](https://api.docs.weka.io/?urls.primaryName=5.1#/Default%20network/setDefaultNetwork)     | `weka cluster default-net set`    |
| **Update default network settings:** Modifies existing default network settings, such as the IP range, gateway, or subnet mask.                                   | [PUT ​/defaultNet](https://api.docs.weka.io/?urls.primaryName=5.1#/Default%20network/updateDefaultNetwork)   | `weka cluster default-net update` |
| **Reset default network settings:** Removes custom default network settings and reverts to the initial system baseline.                                           | [DELETE ​/defaultNet](https://api.docs.weka.io/?urls.primaryName=5.1#/Default%20network/resetDefaultNetwork) | `weka cluster default-net reset`  |

## Drives

Related information: [Expand and shrink cluster resources](/operation-guide/expanding-and-shrinking-cluster-resources)

| Task                                                                                                                                                                                                   | REST API                                                                                                  | CLI                                                    |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| **List all drives:** Returns a list of all SSD drives in the cluster and provides details such as size, UUID, and status.                                                                              | [GET ​/drives](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/getDrives)                           | `weka cluster drive`                                   |
| **Add a drive:** Attaches an SSD drive to a specific container to expand its resources.                                                                                                                | [POST ​/drives](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/provisionDrives)                    | `weka cluster drive add <container-id> <device-paths>` |
| **Get drive details:** Returns detailed information for a specific SSD drive.                                                                                                                          | [GET ​/drives​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/getSingleDrive)               | `weka cluster drive <uuids>`                           |
| **Remove a drive:** Detaches a specified SSD drive from the cluster, making it unavailable.                                                                                                            | [DELETE ​/drives​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/deleteDrive)               | `weka cluster drive remove <uuids>`                    |
| **Identify a drive:** Locate a physical drive by controlling its indicator LED. This operation enables or disables the LED for a specific drive to assist with maintenance or hardware identification. | [POST ​/drives​/{uid}/identify](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/identifyDrive) \*\* | `weka cluster drive identify`                          |
| **Activate drives:** Activates one or more inactive SSD drives, making them available for use.                                                                                                         | [POST ​/drives​/activate](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/activateDrives)           | `weka cluster drive activate <uuids>`                  |
| **Deactivate drives:** Deactivates one or more SSD drives, preventing their use while preserving the data on them.                                                                                     | [POST ​/drives​/deactivate](https://api.docs.weka.io/?urls.primaryName=5.1#/Drive/deactivatesDrives)      | `weka cluster drive deactivate <uuids>`                |

## Events

Related information: [Events](/operation-guide/events)

| **List events:** Returns a list of all cluster events, with options to filter by severity, category, and time range.                                               | [GET ​/events](https://api.docs.weka.io/?urls.primaryName=5.1#/Events/getEvents)                      | `weka events`                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |
| **List event types and descriptions:** Returns a list of all event types and provides a detailed description for each, including its meaning and potential causes. | [GET ​/events​/describe](https://api.docs.weka.io/?urls.primaryName=5.1#/Events/getEventsDescription) | `weka events list-types`                                            |
| **Aggregate events by time:** Aggregates events over a specified time interval to show event frequency and trends.                                                 | [GET ​/events​/aggregate](https://api.docs.weka.io/?urls.primaryName=5.1#/Events/getAggregateEvents)  | `weka events --start-time <start> --end-time <end> --show-internal` |
| **List local server events:** Returns a list of events generated only by the server that receives the API request, which is useful for targeted troubleshooting.   | [GET ​/events​/local](https://api.docs.weka.io/?urls.primaryName=5.1#/Events/getLocalEvents)          | `weka events list-local`                                            |
| **Create a custom event:** Creates and records a custom event with a user-defined message for enhanced monitoring and logging.                                     | [POST /events/custom](https://api.docs.weka.io/?urls.primaryName=5.1#/Events/triggerCustomEvent)      | `weka events trigger-event`                                         |

## Failure domains

Related information: [Cluster capacity and redundancy management](/weka-system-overview/cluster-capacity-and-redundancy-management)

| Task                                                                                                                                                                          | REST API                                                                                                                | CLI                                      |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------------------- |
| **List failure domains:** Returns a list of failure domains in the cluster. A failure domain is a set of hardware components that can fail together from a single root cause. | [GET ​/failureDomains](https://api.docs.weka.io/?urls.primaryName=5.1#/Failure%20domains/getFailureDomains)             | `weka cluster failure-domain`            |
| **Get failure domain details:** Returns details for a specific failure domain, including its resources and capacity.                                                          | [GET ​/failureDomains​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Failure%20domains/getSingleFailureDomain) | `weka cluster container <container-ids>` |

## Filesystem

Related information:

* [Filesystems, object stores, and filesystem groups](/weka-system-overview/filesystems-object-stores-and-filesystem-groups)
* [Manage filesystems](/weka-filesystems-and-object-stores/managing-filesystems)
* [Attach or detach object store buckets](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems)

<table><thead><tr><th width="246">Task</th><th width="269">REST API</th><th>CLI</th></tr></thead><tbody><tr><td><strong>List all filesystems:</strong> Returns a list of all filesystems in the cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/getFileSystems">GET ​/fileSystems</a></td><td><code>weka fs</code></td></tr><tr><td><strong>Create filesystem:</strong> Creates a new filesystem in the cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/createFileSystem">POST ​/fileSystems</a></td><td><code>weka fs add</code></td></tr><tr><td><strong>Get filesystem details:</strong> Returns detailed information about a specific filesystem, such as its size, quota, and usage.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/getFileSystem">GET ​/fileSystems​/{uid}</a></td><td><code>weka fs --name &#x3C;name></code></td></tr><tr><td><strong>Update a filesystem:</strong> Updates the settings of an existing filesystem.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/updateFileSystem">PUT ​/fileSystems​/{uid}</a></td><td><code>weka fs update &#x3C;name></code></td></tr><tr><td><strong>Remove a filesystem:</strong> Removes a specified filesystem and its data from the cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/deleteFileSystem">DELETE ​/fileSystems​/{uid}</a></td><td><code>weka fs remove &#x3C;name></code></td></tr><tr><td><strong>Obtain mount token for filesystem:</strong> Generates a long-lived authentication token to mount a specific filesystem. This token enables persistent access and supports controlled permissions, such as read-only access or defined expiration periods.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/getMountToken">POST /fileSystems/{uid}/mountToken </a>**</td><td>N/A</td></tr><tr><td><strong>Attach an object store bucket:</strong> Links an object store bucket to a filesystem, allowing tiered data access.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/attachObsBucketToFs">POST ​/fileSystems​/{uid}​/objectStoreBuckets</a></td><td><code>weka fs tier s3 attach &#x3C;fs-name></code></td></tr><tr><td><strong>Get path by inode ID:</strong> Returns the full path of a file or directory using its inode ID.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/filesystemResolveInode">GET ​/fileSystems​/{inode_id}​/getPath</a></td><td><code>weka debug fs resolve-inode</code></td></tr><tr><td><strong>Detach object store bucket from filesystem:</strong> Disconnects an object store bucket from a filesystem, separating their data access.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/detachObsBucketFromFS">DELETE ​/fileSystems​/{uid}​/objectStoreBuckets​/{obs_uid}</a></td><td><code>weka fs tier s3 detach &#x3C;fs-name> &#x3C;obs-name></code></td></tr><tr><td><strong>Download filesystem from object store:</strong> Creates a new filesystem based on a saved snapshot stored in an object store bucket.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/downloadFS">POST ​/fileSystems​/download</a></td><td><code>weka fs download</code></td></tr><tr><td><strong>Get thin-provisioning reserve status:</strong> Returns the existing allocated thin-provisioning space reserved for your organization within the cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/getFileSystemsThinProvisionReserveStatus">GET ​/fileSystems​/thinProvisionReserve</a></td><td><code>weka fs reserve status</code></td></tr><tr><td><strong>Reserve guaranteed SSD for your organization:</strong> Set the thin-provisioning space for your organization's filesystems.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/setFileSystemsThinProvisionReserve">PUT ​/fileSystems​/thinProvisionReserve​/{org_uid}</a></td><td><code>weka fs reserve set &#x3C;ssd-capacity></code></td></tr><tr><td><strong>Remove thin-provisioning reserve:</strong> Removes the existing reserved thin-provisioning space allocated for your organization's filesystems.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/deleteFileSystemsThinProvisionReserve">DELETE ​/fileSystems​/thinProvisionReserve​/{org_uid}</a></td><td><code>weka fs reserve unset --org &#x3C;org></code></td></tr><tr><td><strong>Remove all security policies from a filesystem:</strong> Detaches all security policies from a specific filesystem.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/resetFsSecurityPolicies">DELETE ​/fileSystems​/{uid}​/securityPolicy</a></td><td><code>weka fs security policy reset</code></td></tr><tr><td><strong>Get security policies for a filesystem:</strong> Returns a list of all security policies attached to a specific filesystem.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/getFsSecurityPolicies">GET ​/fileSystems​/{uid}​/securityPolicy</a></td><td><code>weka fs security policy list</code></td></tr><tr><td><strong>Set filesystem security policies:</strong> Replaces all security policies on a filesystem with a new, specified set of policies.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/setFsSecurityPolicies">PUT ​/fileSystems​/{uid}​/securityPolicy</a></td><td><code>weka fs security policy set</code></td></tr><tr><td><strong>Attach security policies to a filesystem:</strong> Adds one or more security policies to a filesystem's existing policy list.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/attachFsSecurityPolicies">POST​ /fileSystems​/{uid}​/securityPolicy​/attach</a></td><td><code>weka fs security policy attach</code></td></tr><tr><td><strong>Detach security policies from a filesystem:</strong> Removes one or more specified security policies from a filesystem.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem/detachFsSecurityPolicies">POST ​/fileSystems​/{uid}​/securityPolicy​/detach</a></td><td><code>weka fs security policy detach</code></td></tr></tbody></table>

## Quota

Related information [Quota management](/weka-filesystems-and-object-stores/quota-management)

| Task                                                                                                                                                                        | REST API                                                                                                                      | CLI                                                                                    |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| **List directory quotas:** Returns all quotas for directories within a specific filesystem..                                                                                | [GET ​/fileSystems​/{uid}​/quota](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/listQuotas)                           | `weka fs quota list <fs-name>`                                                         |
| **List default directory quotas:** Returns all default quotas for directories within a specific filesystem.                                                                 | [GET ​/fileSystems​/{uid}​/quota​/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/listDefaultQuotas)           | `weka fs quota list-default`                                                           |
| **Get directory quota details:** Returns the quota parameters for a specific directory.                                                                                     | [GET ​/fileSystems​/{uid}​/quota​/{inode\_id}](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/getQuota)                | `weka fs quota list <fs-name> --path <path>`                                           |
| **Set a quota for a directory:** Sets a quota for a directory. If Data Service is not enabled, use the CLI to set a quota for a non-empty directory.                        | [PUT ​/fileSystems​/{uid}​/quota​/{inode\_id}](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/putQuota)                | `weka fs quota set <path>`                                                             |
| **Update directory quota:** Modifies specific settings, such as the grace period or limits, for an existing directory quota.                                                | [PATCH ​/fileSystems​/{uid}​/quota​/{inode\_id}](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/patchQuota)            | `weka fs quota set <path> --soft <soft> --hard <hard> --grace <grace> --owner <owner>` |
| **Remove directory quota:** Removes a quota from a specific directory. If the Data Service is not enabled, use the CLI to remove a quota from a non-empty directory.        | [DELETE ​/fileSystems​/{uid}​/quota​/{inode\_id}](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/deleteQuota)          | `weka fs quota unset <path>`                                                           |
| **Set or update a default directory quota:** Establishes or changes the default quota that applies to all newly created subdirectories within a specified parent directory. | [PUT ​/fileSystems​/quota​/{inode\_id}](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/putDefaultQuota)                | `weka fs quota set-default <path>`                                                     |
| **Remove default quota from a directory:** Removes the default quota from a directory, preventing new subdirectories from inheriting its settings.                          | [DELETE ​/fileSystems​/quota​/{inode\_id}​/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/deleteDefaultQuota) | `weka fs quota unset-default <path>`                                                   |
| **Resolve path to inode ID:** ReturnsReturns the unique inode ID for a specified file or directory path.                                                                    | [GET​/fileSystems​/{uid}​/resolvePath](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/resolvePath)                     | N/A                                                                                    |

### User quotas

| Task                                                                                                                                                         | REST API                                                                                                                         | CLI                                                                                           |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| **List user quotas:** Returns all user (UID) quotas for a specific filesystem.                                                                               | [GET /fileSystems/{uid}/quota/user](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/listUserQuotas) \*\*                   | `weka fs quota list <fs-name> --type user --all`                                              |
| **Set a user quota:** Sets or updates the quota for a specific user on a filesystem.                                                                         | [POST /fileSystems/{uid}/quota/user](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/setUserQuota) \*\*                    | `weka fs quota set --type user --id <UID> --soft <soft> --hard <hard> --filesystem <fs-name>` |
| **Remove a user quota:** Removes the quota for a specific user on a filesystem.                                                                              | [DELETE /fileSystems/{uid}/quota/user](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/unsetUserQuota) \*\*                | `weka fs quota reset --type user --id <UID> --filesystem <fs-name>`                           |
| **Get default user quota:** Returns the default quota applied to new users on a filesystem.                                                                  | [GET /fileSystems/{uid}/quota/user/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/getDefaultUserQuota) \*\*      | `weka fs quota list-default <fs-name> --type user`                                            |
| **Set default user quota:** Sets or updates the default quota applied to new users on a filesystem.                                                          | [POST /fileSystems/{uid}/quota/user/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/setDefaultUserQuota) \*\*     | `weka fs quota set-default <path> --type user --soft <soft> --hard <hard>`                    |
| **Remove default user quota:** Removes the default user quota from a filesystem.                                                                             | [DELETE /fileSystems/{uid}/quota/user/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/unsetDefaultUserQuota) \*\* | `weka fs quota unset-default <path> --type user --filesystem <fs-name>`                       |
| **Enable user quota accounting:** Enables quota accounting on a filesystem and triggers the background coloring task. Applies to both user and group quotas. | [POST /fileSystems/{uid}/quota/user/enable](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/enableUserQuotas) \*\*         | `weka fs quota enable-users <fs-name>`                                                        |
| **Disable user quota accounting:** Disables quota accounting on a filesystem. Applies to both user and group quotas.                                         | [POST /fileSystems/{uid}/quota/user/disable](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/disableUserQuotas) \*\*       | `weka fs quota disable-users <fs-name>`                                                       |
| **Get user quota accounting status:** Returns the quota accounting state for a filesystem.                                                                   | [GET /fileSystems/{uid}/quota/user/status](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/getUserQuotasStatus) \*\*       | N/A                                                                                           |

### Group quotas

| Task                                                                                                  | REST API                                                                                                                           | CLI                                                                                            |
| ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| **List group quotas:** Returns all group (GID) quotas for a specific filesystem.                      | [GET /fileSystems/{uid}/quota/group](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/listGroupQuotas) \*\*                   | `weka fs quota list <fs-name> --type group --all`                                              |
| **Set a group quota:** Sets or updates the quota for a specific group on a filesystem.                | [POST /fileSystems/{uid}/quota/group](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/setGroupQuota) \*\*                    | `weka fs quota set --type group --id <GID> --soft <soft> --hard <hard> --filesystem <fs-name>` |
| **Remove a group quota:** Removes the quota for a specific group on a filesystem.                     | [DELETE /fileSystems/{uid}/quota/group](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/unsetGroupQuota) \*\*                | `weka fs quota reset --type group --id <GID> --filesystem <fs-name>`                           |
| **Get default group quota:** Returns the default quota applied to new groups on a filesystem.         | [GET /fileSystems/{uid}/quota/group/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/getDefaultGroupQuota) \*\*      | `weka fs quota list-default <fs-name> --type group`                                            |
| **Set default group quota:** Sets or updates the default quota applied to new groups on a filesystem. | [POST /fileSystems/{uid}/quota/group/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/setDefaultGroupQuota) \*\*     | `weka fs quota set-default <path> --type group --soft <soft> --hard <hard>`                    |
| **Remove default group quota:** Removes the default group quota from a filesystem.                    | [DELETE /fileSystems/{uid}/quota/group/default](https://api.docs.weka.io/?urls.primaryName=5.1#/Quota/unsetDefaultGroupQuota) \*\* | `weka fs quota unset-default <path> --type group --filesystem <fs-name>`                       |

## Filesystem group

Related information: [Manage filesystem groups](/weka-filesystems-and-object-stores/managing-filesystem-groups)

| Task                                                                                                                | REST API                                                                                                                     | CLI                           |
| ------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ----------------------------- |
| **Get filesystem groups:** Returns a list of all filesystem groups in the cluster.                                  | [GET ​/fileSystemGroups](https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem%20group/getFileSystemGroups)             | `weka fs group`               |
| **Create a filesystem group:** Creates a new group to manage policies and settings for a collection of filesystems. | [POST ​/fileSystemGroups](https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem%20group/createFileSystemGroup)          | `weka fs group add`           |
| **Get a specific filesystem group:** Returns the properties of a specific filesystem group by providing its UID.    | [GET ​/fileSystemGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem%20group/getFileSystemGroup)       | N/A                           |
| **Update a filesystem group:** Modifies the properties of an existing filesystem group.                             | [PUT ​/fileSystemGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem%20group/updateFileSystemGroup)    | `weka fs group update <name>` |
| **Delete a filesystem group:** Removes a filesystem group from the cluster.                                         | [DELETE ​/fileSystemGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Filesystem%20group/deleteFileSystemGroup) | `weka fs group remove <name>` |

## Health

Related information: [Manage the system using the WEKA GUI](/getting-started-with-weka/manage-the-system-using-weka-gui#cluster-protection-and-availability-widget)

| Task                                                                  | REST API                                                                                    | CLI |
| --------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | --- |
| **Check REST API status:** Verifies the availability of the REST API. | [GET ​/healthcheck](https://api.docs.weka.io/?urls.primaryName=5.1#/Health/getApiHealth)    | N/A |
| **Check GUI status:** Verifies the availability of the GUI.           | [GET ​/ui​/healthcheck](https://api.docs.weka.io/?urls.primaryName=5.1#/Health/getUIHealth) | N/A |

## Interface group

Related information: [Manage the NFS protocol](/additional-protocols/nfs-support)

| Task                                                                                                                                                                                                                                      | REST API                                                                                                                                                           | CLI                                                                                                |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------- |
| **Get interface groups:** Returns a list of all interface groups that manage floating IPs for NFS server resiliency.                                                                                                                      | [GET ​/interfaceGroups](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/getInterfaceGroups)                                                      | `weka nfs interface-group`                                                                         |
| **Create an interface group:** Creates an interface group to manage floating IPs for NFS resiliency. An interface group defines a collection of servers, network ports, and floating IPs that work together to ensure continuous service. | [POST ​/interfaceGroups](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/createInterfaceGroup)                                                   | `weka nfs interface-group add`                                                                     |
| **Get interface group details:** Returns the details of a specific interface group, including its assigned servers, ports, and floating IP ranges.                                                                                        | [GET ​/interfaceGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/getInterfaceGroup)                                                | `weka nfs interface-group --name <name>`                                                           |
| **Delete an interface group:** Removes an interface group, including its collection of servers, ports, and floating IPs.                                                                                                                  | [DELETE ​/interfaceGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/deleteInterfaceGroup)                                          | `weka nfs interface-group remove <name>`                                                           |
| **Update an interface group:** Modifies the gateway and subnet of an existing interface group.                                                                                                                                            | [PUT ​/interfaceGroups​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/updateInterfaceGroup)                                             | `weka nfs interface-group update <name>`                                                           |
| **Add IP range to interface group:** Adds a range of floating IP addresses to an interface group. These IPs can migrate between servers in the group to maintain service availability.                                                    | [POST ​/interfaceGroups​/{uid}​/ips](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/crateInterfaceGroupIp)                                      | `weka nfs interface-group ip-range add <name> <ips>`                                               |
| **Add a port to an interface group:** Assigns a network port from a specific container to an interface group, making that container a potential host for the group's floating IPs.                                                        | [POST ​/interfaceGroups​/{uid}​/ports​/{container\_uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/addPortToInterfaceGroup)                | `weka nfs interface-group port add <name> <server-id> <port>`                                      |
| **Remove an IP range from an interface group:** Removes a container's network port from an interface group, preventing it from hosting the group's floating IPs.                                                                          | [DELETE ​/interfaceGroups​/{uid}​/ports​/{container\_uid}​/{port}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/deletePortFromInterfaceGroup) | `weka nfs interface-group port remove <name> <port>`                                               |
| **Remove an IP range from an interface group:** Removes a floating IP address range from an interface group.                                                                                                                              | [DELETE ​/interfaceGroups​/{uid}​/ips​/{ips}](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/deleteIpRangeFromInterfaceGroup)                   | `weka nfs interface-group ip-range remove <name> <ips>`                                            |
| **Get floating IPs:** Returns a list of all floating IPs and shows which container and port in the interface group currently host each IP.                                                                                                | [GET ​/interfaceGroups​/listAssignment](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/getInterfaceGroupsListAssignment)                        | `weka nfs interface-group assignment`                                                              |
| **Add a port to an interface group:** Assigns a port to be accessible by the specified interface group.                                                                                                                                   | [POST ​/interfaceGroups​/port](https://api.docs.weka.io/?urls.primaryName=5.1#/Interface%20group/interfaceGroupAddPort)                                            | <p><code>weka nfs interface-group port add \<name></code><br><code>\<server-id> \<port></code></p> |

## KMS

Related information: [Manage KMS](/security/kms-management)

| Task                                                                                                        | REST API                                                                               | CLI                                                       |
| ----------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | --------------------------------------------------------- |
| **Get KMS configuration:** Returns the Key Management Service (KMS) configuration.                          | [GET ​/kms](https://api.docs.weka.io/?urls.primaryName=5.1#/KMS/getKms)                | `weka security kms`                                       |
| **Set KMS configuration:** Sets a new Key Management Service (KMS) configuration (Hashicorp Vault or KMIP). | [POST ​/kms](https://api.docs.weka.io/?urls.primaryName=5.1#/KMS/setKms)               | `weka security kms set <type> <address> <key-identifier>` |
| **Delete KMS configuration:** Removes the KMS configuration if it is not used by any encrypted filesystems. | [DELETE ​/kms](https://api.docs.weka.io/?urls.primaryName=5.1#/KMS/deleteKms)          | `weka security kms unset`                                 |
| **Get KMS type:** Returns the configured KMS type (HashiCorp Vault or KMIP).                                | [GET ​/kms​/type](https://api.docs.weka.io/?urls.primaryName=5.1#/KMS/getKmsType)      | `weka security kms`                                       |
| **Rewrap KMS key:** Updates the encryption keys for existing filesystems with a new KMS master key.         | [POST ​/kms​/rewrap](https://api.docs.weka.io/?urls.primaryName=5.1#/KMS/rewrapKmsKey) | `weka security kms rewrap`                                |

## LDAP

Related information: [User management](/operation-guide/user-management)

| Task                                                                                          | REST API                                                                         | CLI                      |
| --------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | ------------------------ |
| **Get LDAP configuration:** ReturnsReturns the LDAP configuration.                            | [GET ​/ldap](https://api.docs.weka.io/?urls.primaryName=5.1#/LDAP/getLdap)       | `weka user ldap`         |
| **Update LDAP configuration:** Modifies the configuration for connecting to your LDAP server. | [PUT ​/ldap](https://api.docs.weka.io/?urls.primaryName=5.1#/LDAP/updateLdap)    | `weka user ldap setup`   |
| **Disable LDAP:** Deactivates the integration with your LDAP server for user authentication.  | [DELETE ​/ldap](https://api.docs.weka.io/?urls.primaryName=5.1#/LDAP/deleteLdap) | `weka user ldap disable` |

## License

Related information: [Licensing overview](/licensing/overview)

| Task                                                                                                                                                        | REST API                                                                                 | CLI                                  |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ------------------------------------ |
| **Get license details:** Returns details about the configured cluster license, including resource usage and validity.                                       | [GET ​/license](https://api.docs.weka.io/?urls.primaryName=5.1#/License/getLicense)      | `weka cluster license`               |
| **Set license:** Installs a new cluster license for continued operation. The license is a text-based file generated via get.weka.io for a specific cluster. | [POST ​/license](https://api.docs.weka.io/?urls.primaryName=5.1#/License/setLicense)     | `weka cluster license set <license>` |
| **Remove license:** Deactivates the existing license and returns the cluster to unlicensed mode.                                                            | [DELETE ​/license](https://api.docs.weka.io/?urls.primaryName=5.1#/License/resetLicense) | `weka cluster license reset`         |

## Lockout policy

Related information: [Manage account lockout threshold policy](/security/account-lockout-threshold-policy-management)

| Task                                                                                                          | REST API                                                                                                      | CLI                                  |
| ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ------------------------------------ |
| **Get lockout policy:** Returns the account lockout threshold policy details                                  | [GET ​/lockoutPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Lockout%20policy/getLockoutPolicy)      | `weka security lockout-config show`  |
| **Update lockout policy:** Modifies the account lockout threshold policy.                                     | [PUT ​/lockoutPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Lockout%20policy/setLockoutPolicy)      | `weka security lockout-config set`   |
| **Reset lockout policy:** Clears the failed login attempts counter and unlocks any currently locked accounts. | [DELETE ​/lockoutPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Lockout%20policy/resetLockoutPolicy) | `weka security lockout-config reset` |

## Login

Related information: [Obtain authentication tokens](/security/obtain-authentication-tokens)<br>

| Task                                                                                                                                                                                                                                                   | REST API                                                                                    | CLI               |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------- | ----------------- |
| **Log in to the cluster:** Authenticates and grants access to the cluster using valid credentials. Securely save user credentials in the user's home directory upon successful login.                                                                  | [POST ​/login](https://api.docs.weka.io/?urls.primaryName=5.1#/Login/login)                 | `weka user login` |
| **Retrieve access token:** Obtains a new access token using an existing refresh token. The system creates an authentication token file and saves it in `~/.weka/auth-token.json`. The token file contains both the access token and the refresh token. | [POST ​/login​/refresh](https://api.docs.weka.io/?urls.primaryName=5.1#/Login/refreshToken) | `weka user login` |

## Mounts Defaults

Related information:

* [Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems)
* [Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems#set-mount-option-default-values)

| Task                                                                                                                       | REST API                                                                                                       | CLI                                 |
| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------- |
| **Get default mount options:** Returns the configured default mount options applied to all filesystems across the cluster. | [GET ​/mountDefaults](https://api.docs.weka.io/?urls.primaryName=5.1#/Mounts%20Defaults/getMountDefaults)      | `weka cluster mount-defaults show`  |
| **Set default mount options:** Configures default mount options applied to all filesystems across the cluster.             | [PUT ​/mountDefaults](https://api.docs.weka.io/?urls.primaryName=5.1#/Mounts%20Defaults/setMountDefaults)      | `weka cluster mount-defaults set`   |
| **Reset default mount options:** Reverts the default mount options to initial settings for all filesystems in the cluster. | [DELETE ​/mountDefaults](https://api.docs.weka.io/?urls.primaryName=5.1#/Mounts%20Defaults/resetMountDefaults) | `weka cluster mount-defaults reset` |

## NFS

Related information: [Manage the NFS protocol](/additional-protocols/nfs-support)

<table><thead><tr><th>Task</th><th width="248">REST API</th><th>CLI</th></tr></thead><tbody><tr><td><strong>Get all permissions:</strong> Returns a list of NFS permissions for client groups across all filesystems.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsPermissions">GET ​/nfs​/permissions</a></td><td><code>weka nfs permission</code></td></tr><tr><td><strong>Create an NFS permission:</strong> Grants a client group access to an NFS share by creating a new permission rule.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/addNfsPermission">POST ​/nfs​/permissions</a></td><td><code>weka nfs permission add &#x3C;fs_name> &#x3C;client-group-name></code></td></tr><tr><td><strong>Get a specific NFS permission:</strong> Returns the access control rules for a specific NFS permission, identified by its unique identifier (UID).</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsPermission">GET ​/nfs​/permissions​/{uid}</a></td><td><code>weka nfs permission --filesystem &#x3C;fs_name></code></td></tr><tr><td><strong>Update an NFS permission:</strong> Modifies an existing NFS permission to change access controls for a client group.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/updateNfsPermission">PUT ​/nfs​/permissions​/{uid}</a></td><td><code>weka nfs permission update &#x3C;fs_name> &#x3C;client-group-name></code></td></tr><tr><td><strong>Remove and NFS permission:</strong> Revokes a client group's access to a filesystem by removing a specific NFS permission.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/deleteNfsPermission">DELETE ​/nfs​/permissions​/{uid}</a></td><td><code>weka nfs permission delete &#x3C;fs_name> &#x3C;client-group-name></code></td></tr><tr><td><strong>Get all client groups:</strong> Returns a list of all client groups used for managing NFS access controls.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getClientGroups">GET ​/nfs​/clientGroups</a></td><td><code>weka nfs client-group</code></td></tr><tr><td><strong>Create an NFS client group:</strong> Create a new client group to manage access controls for NFS mounts.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/createClientGroup">POST ​/nfs​/clientGroups</a></td><td><code>weka nfs client-group add &#x3C;group-name></code></td></tr><tr><td><strong>Get a specific NFS client group:</strong> Returns the details of a specific NFS client group.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getClientGroup">GET ​/nfs​/clientGroups​/{uid}</a></td><td><code>weka nfs client-group --name &#x3C;client-group-name></code></td></tr><tr><td><strong>Remove an NFS client group:</strong> Removes an existing NFS client group.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/deleteClientGroup">DELETE ​/nfs​/clientGroups​/{uid}</a></td><td><code>weka nfs client-group delete &#x3C;client-group-name></code></td></tr><tr><td><strong>Create a rule for an NFS client group:</strong> Adds a DNS or IP-based rule to a client group. Clients matching the rule are granted access.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/addClientGroupRule">POST ​/nfs​/clientGroups​/{uid}​/rules</a></td><td><code>weka nfs rules add dns &#x3C;client-group-name> &#x3C;dns-rule></code></td></tr><tr><td><strong>Remove a rule from an NFS client group:</strong> Removes a DNS or IP-based rule from an NFS client group.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/deleteClientGroupRule">DELETE ​/nfs​/clientGroups​/{uid}​/rules​/{rule_uid}</a></td><td><code>weka nfs rules delete dns &#x3C;client-group-name> &#x3C;dns-rule></code></td></tr><tr><td><strong>Update the global NFS configuration:</strong> Modifies cluster-wide NFS parameters, including ports, the configuration filesystem, supported versions, and ACL settings.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/updateNfsGlobalConfig">PUT ​/nfs​/globalConfig</a></td><td><code>weka nfs global-config set</code></td></tr><tr><td><strong>Get the global NFS configuration:</strong> Returns the cluster-wide NFS configuration, including ports, the configuration filesystem, and supported versions.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsGlobalConfig">GET ​/nfs​/globalConfig</a></td><td><code>weka nfs global-config show</code></td></tr><tr><td><strong>Get the NFS debug level:</strong> Returns the logging verbosity level for the container processes in the NFS cluster.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNFSDebugLevel">GET ​/nfs​/debug</a></td><td><code>weka nfs debug-level show</code></td></tr><tr><td><strong>Set the NFS debug level:</strong> Adjusts the logging verbosity for container processes in the NFS cluster to control the level of detail in logs.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNFSDebugLevel">POST ​/nfs​/debug</a></td><td><code>weka nfs debug-level set &#x3C;debug-level></code></td></tr><tr><td><strong>Set up the NFS-Kerberos service</strong>: Configures the NFS-Kerberos service. Integrating NFS with Kerberos enhances security by allowing mounts only from clients with valid Kerberos tickets.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setupNfsKerberosService">PUT​/nfs​/kerberosService</a></td><td><code>weka nfs kerberos service setup</code></td></tr><tr><td><strong>Get the NFS-Kerberos service configuration:</strong> Returns the NFS-Kerberos service configuration details. Integrating NFS with Kerberos enhances security by allowing mounts only from clients with valid Kerberos tickets.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsKerberosService">GET​/nfs​/kerberosService</a></td><td><code>weka nfs kerberos service show</code></td></tr><tr><td><strong>Register NFS with MIT Kerberos:</strong> Registers NFS Kerberos service with MIT KDC. Running this endpoint with the restart option can disrupt the IO service for connected NFS clients.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsMitKerberosRegistration">PUT​/nfs​/kerberosMitRegistration</a></td><td><code>weka nfs kerberos registration setup-mit</code></td></tr><tr><td><strong>Register NFS with Active Directory Kerberos:</strong> Registers NFS Kerberos service with Microsoft Active Directory (AD). Running this endpoint with the restart option can disrupt the IO service for connected NFS clients.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsAdKerberosRegistration">PUT​/nfs​/kerberosActiveDirectoryRegistration</a></td><td><code>weka nfs kerberos registration setup-ad</code></td></tr><tr><td><strong>Get the NFS-Kerberos registration configuration:</strong> Returns the NFS-Kerberos service registration details.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsKerberosRegistration">GET​/nfs​/kerberosRegistration</a></td><td><code>weka nfs kerberos registration show</code></td></tr><tr><td><strong>Reset the Kerberos configuration for NFS:</strong> Removes the Kerberos service configuration data, allowing for a new integration to be set up.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/resetNfsKerberosConfiguration">PUT​/nfs​/kerberosReset</a></td><td><code>weka nfs kerberos reset</code></td></tr><tr><td><strong>Set up host-based LDAP resolution for NFS:</strong> Enables NFS group resolution through the server's LDAP client. This supports over 16 groups by using host providers like SSSD.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsOpenLdapConfiguration">PUT /nfs/useOnHostLdapClient</a> **</td><td><code>weka nfs ldap setup-onhostldap</code></td></tr><tr><td><strong>Set up NFS with OpenLDAP:</strong> Configures NFS to use an OpenLDAP service for user and group information, typically used with an MIT Kerberos integration.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsOpenLdapConfiguration">PUT​/nfs​/openLdapService</a></td><td><code>weka nfs ldap setup-openldap</code></td></tr><tr><td><strong>Set up NFS with Active Directory LDAP:</strong> Configures NFS to use the LDAP service within Active Directory (AD) for user and group lookups.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsAdLdapConfiguration">PUT​/nfs​/activeDirectoryLdapService</a></td><td><code>weka nfs ldap setup-ad</code></td></tr><tr><td><strong>Set up Active Directory LDAP for ACLs (without Kerberos):</strong> Configures NFS to use LDAP for ACLs when Kerberos authentication is not in use.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/setNfsAdNoKrbLdapConfiguration">PUT​/nfs​/activeDirectoryNoKrbLdapService</a></td><td><code>weka nfs ldap setup-ad-nokrb</code></td></tr><tr><td><strong>Get the LDAP configuration:</strong> Returns the LDAP configuration for the NFS service.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/getNfsLdapService">GET​/nfs​/ldapService</a></td><td><code>weka nfs ldap show</code></td></tr><tr><td><strong>Reset the LDAP configuration:</strong> Removes the NFS-LDAP configuration from the system.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/resetNfsLdapConfiguration">PUT​/nfs​/ldapReset</a></td><td><code>weka nfs ldap reset</code></td></tr><tr><td><strong>Import an LDAP configuration:</strong> Imports an OpenLDAP configuration from a file and applies it to the NFS service.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/importNfsLdapConfiguration">PUT​/nfs​/ldapImport</a></td><td><code>weka nfs ldap import-openldap</code></td></tr><tr><td><strong>Export the LDAP configuration:</strong> Exports the OpenLDAP configuration for the NFS service to a file for backup or migration.</td><td><a href="https://api.docs.weka.io/?urls.primaryName=5.1#/NFS/exportNfsLdapConfiguration">POST​/nfs​/ldapExport</a></td><td><code>weka nfs ldap export-openldap</code></td></tr></tbody></table>

## Object store

Related information: [Manage object stores](/weka-filesystems-and-object-stores/managing-object-stores)

| Task                                                                                                                                                                                                                                                                                                                                   | REST API                                                                                                               | CLI                                  |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ------------------------------------ |
| **Update a specific object store:** Updates the connection details for an existing object store.                                                                                                                                                                                                                                       | [PUT ​/objectStores​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store/updateObs)                  | `weka fs tier obs update <obs-name>` |
| **Get OBS bucket capacity utilization information:** Retrieves capacity usage details for object store buckets. This includes total consumed bytes, active user data, and reclaimable space percentages per filesystem. Use this endpoint to monitor tiered storage health and trigger data refreshes for accurate capacity reporting. | [PUT ​/objectStores​/capacities](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store/getObsCapacities) \*\* | `weka fs tier capacity`              |

## Object store bucket

Related information: [Manage object stores](/weka-filesystems-and-object-stores/managing-object-stores)

| Task                                                                                                                                                         | REST API                                                                                                                                | CLI                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| **Get object store bucket configurations:** Returns a list of all object store bucket configurations and status.                                             | [GET ​/objectStoreBuckets](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/getAllObsBuckets)                    | `weka fs tier s3`                                            |
| <p><strong>Create an object store bucket configuration:</strong></p><p>Establishes a new object store bucket configuration.</p>                              | [POST ​/objectStoreBuckets](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/createObsBucket)                    | `weka fs tier s3 add <obs-name>`                             |
| **Get a specific object store bucket configuration:** Returns a specific object store bucket configuration and status.                                       | [GET ​/objectStoreBuckets​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/getObsBuckets)                | `weka fs tier s3 --obs-name <obs-name> --name <bucket-name>` |
| **Delete an object store bucket configuration:** Removes an existing object store bucket configuration if the bucket is not attached to a filesystem.        | [DELETE ​/objectStoreBuckets​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/deleteObsBucket)           | `weka fs tier s3 delete <obs-name>`                          |
| **Update an object store bucket configuration:** Modifies an existing object store bucket configuration.                                                     | [PUT ​/objectStoreBuckets​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/updateObsBucket)              | `weka fs tier s3 update <bucket-name>`                       |
| **Get object store bucket operations:** Returns a list of live, low-level I/O operations (such as uploads and downloads) for a specific object store bucket. | [GET ​/objectStoreBuckets​/{uid}​/operations](https://api.docs.weka.io/?urls.primaryName=5.1#/Object%20store%20bucket/getObsOperations) | `weka fs tier ops`                                           |

## Processes

Related information: [Cluster architecture overview](/weka-system-overview/weka-containers-architecture-overview)

| Task                                                                                                                                                                   | REST API                                                                                       | CLI                                  |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ------------------------------------ |
| **Get a list of all processes:** Returns information about all running processes within the cluster. The list can be filtered by type, container, process ID, or role. | [GET ​/processes](https://api.docs.weka.io/?urls.primaryName=5.1#/Processes/getProcesses)      | `weka cluster process`               |
| **Get a specific process:** Returns information about a specific running process, identified by its UID.                                                               | [GET ​/processes​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Processes/getProcess) | `weka cluster process <process-ids>` |

## S3

Related information: [Manage the S3 protocol](/additional-protocols/s3)

| Task                                                                                                                                                                                                                                                 | REST API                                                                                                                             | CLI                                                              |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------- |
| **Get S3 cluster information:** Returns details about the S3 cluster managed by the system.                                                                                                                                                          | [GET ​/s3](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3Cluster)                                                          | `weka s3 cluster`                                                |
| **Create an S3 cluster:** Establishes a new S3 cluster.                                                                                                                                                                                              | [POST ​/s3](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/createS3Cluster)                                                      | `weka s3 cluster add`                                            |
| **Update an S3 cluster:** Modifies the configuration of an existing S3 cluster.                                                                                                                                                                      | [PUT ​/s3](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/updateS3Cluster)                                                       | `weka s3 cluster update`                                         |
| **Delete an S3 cluster:** Removes an S3 cluster.                                                                                                                                                                                                     | [DELETE ​/s3](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/deleteS3Cluster)                                                    | `weka s3 cluster destroy`                                        |
| **Get S3 settings for the calling tenant:** Returns the calling tenant's effective S3 default filesystem and anonymous POSIX UID/GID. Default filesystem falls back to the cluster-wide default when no tenant override is set.                      | [GET /s3/tenantSetup](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3TenantSetup) \*\*                                      | `weka s3 cluster setup show`                                     |
| **Update S3 settings for the calling tenant:** Sets the calling tenant's S3 default filesystem and/or anonymous POSIX UID/GID. UID and GID must be set together. At least one parameter must be provided.                                            | [PUT /s3/tenantSetup](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/updateS3TenantSetup) \*\*                                   | `weka s3 cluster setup update`                                   |
| **Get S3 buckets:** Returns a list of all buckets within an S3 cluster.                                                                                                                                                                              | [GET ​/s3​/buckets](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3Buckets)                                                 | `weka s3 bucket list`                                            |
| **Add an S3 bucke**t: Adds a new bucket within an S3 cluster.                                                                                                                                                                                        | [POST ​/s3​/buckets](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/createS3Bucket)                                              | `weka s3 bucket add`                                             |
| **Get S3 user policies:** Returns a list of S3 user policies.                                                                                                                                                                                        | [GET ​/s3​/userPolicies](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getuserPolicies)                                         | `weka s3 bucket policy`                                          |
| **Delete an S3 bucket:** Removes a specified S3 bucket.                                                                                                                                                                                              | [DELETE ​/s3​/buckets​/{bucket}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/destroyS3Bucket)                                 | `weka s3 bucket delete <bucket-name>`                            |
| **Get S3 IAM policies:** Returns a list of S3 IAM policies.                                                                                                                                                                                          | [GET ​/s3​/policies](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3Policies)                                               | `weka s3 policy list`                                            |
| **Add an S3 IAM policy:** Adds a new S3 IAM policy.                                                                                                                                                                                                  | [POST ​/s3​/policies](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/createS3Policy)                                             | `weka s3 policy add`                                             |
| **Get S3 IAM policy details:** Returns details about a specific S3 IAM policy.                                                                                                                                                                       | [GET ​/s3​/policies​/{policy}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3Policy)                                       | `weka s3 policy show <policy-name>`                              |
| **Delete an S3 IAM policy:** Removes an S3 IAM policy.                                                                                                                                                                                               | [DELETE ​/s3​/policies​/{policy}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/deleteS3Policy)                                 | `weka s3 policy remove <policy-name>`                            |
| **Attach an S3 IAM policy to a user:** Assigns an S3 IAM policy to a user.                                                                                                                                                                           | [POST ​/s3​/policies​/attach](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/attachS3Policy)                                     | `weka s3 policy attach <policy> <user>‌`                         |
| **Detach an S3 IAM policy from a user:** Unassigns an S3 IAM policy from a user.                                                                                                                                                                     | [POST ​/s3​/policies​/detach](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/detachS3Policy)                                     | `weka s3 policy detach <user>‌‌`                                 |
| **Get service accounts:** Returns the S3 service accounts added by the S3 user, including their access keys.                                                                                                                                         | [GET ​/s3​/serviceAccounts](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3ServiceAccounts)                                 | `weka s3 service-account list`                                   |
| **Add an S3 service account:** Adds a new S3 service account.                                                                                                                                                                                        | [POST ​/s3​/serviceAccounts](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/createS3ServiceAccount)                              | `weka s3 service-account add <policy-file>`                      |
| **Get S3 service account details:** Returns a specific S3 service account.                                                                                                                                                                           | [GET ​/s3​/serviceAccounts​/{access\_key}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getServiceAccount)                     | `weka s3 service-account show <access-key>`                      |
| **Delete an S3 service account:** Removes an S3 service account.                                                                                                                                                                                     | [DELETE ​/s3​/serviceAccounts​/{access\_key}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/deleteS3ServiceAccount)             | `weka s3 service-account remove <access-key>`                    |
| **Create an S3 STS token:** Creates an S3 STS token with an assumed role.                                                                                                                                                                            | [POST ​/s3​/sts](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/s3StsCreate)                                                     | `weka s3 sts assume-role`                                        |
| **Add lifecycle rule:** Creates a new lifecycle rule for an S3 bucket.                                                                                                                                                                               | [POST ​/s3​/buckets​/{bucket}​/lifecycle​/rules](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/s3CreateLifecycleRule)           | `weka s3 bucket lifecycle-rule add <bucket-name>`                |
| **Delete lifecycle rules:** Removes all lifecycle rules for an S3 bucket.                                                                                                                                                                            | [DELETE ​/s3​/buckets​/{bucket}​/lifecycle​/rules](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/s3DeleteAllLifecycleRules)     | `weka s3 bucket lifecycle-rule reset <bucket-name>`              |
| **Get lifecycle rules:** Returns a list of all lifecycle rules for an S3 bucket.                                                                                                                                                                     | [GET ​/s3​/buckets​/{bucket}​/lifecycle​/rules](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/s3ListAllLifecycleRules)          | `weka s3 bucket lifecycle-rule list <bucket-name>`               |
| **Delete lifecycle rule:** Removes a specific lifecycle rule from an S3 bucket.                                                                                                                                                                      | [DELETE ​/s3​/buckets​/{bucket}​/lifecycle​/rules​/{rule}](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/s3DeleteLifecycleRule) | `weka s3 bucket lifecycle-rule remove <bucket-name> <rule-name>` |
| **Get S3 bucket policy:** Returns the policy attached to an S3 bucket.                                                                                                                                                                               | [GET ​/s3​/buckets​/{bucket}​/policy](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3BucketPolicy)                          | `weka s3 bucket policy get <bucket-name>`                        |
| **Set S3 bucket policy:** Assigns a policy to an S3 bucket.                                                                                                                                                                                          | [PUT ​/s3​/buckets​/{bucket}​/policy](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/setS3BucketPolicy)                          | `weka s3 bucket policy set <bucket-name> <bucket-policy>`        |
| **Get S3 bucket policy (JSON):** Returns the bucket policy in JSON format.                                                                                                                                                                           | [GET ​/s3​/buckets​/{bucket}​/policyJson](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3BucketPolicyJson)                  | `weka s3 bucket policy get-json <bucket-name>`                   |
| **Set S3 bucket policy (JSON):** Sets the bucket policy using a JSON file.                                                                                                                                                                           | [PUT ​/s3​/buckets​/{bucket}​/policyJson](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/setS3BucketPolicyJson)                  | `weka s3 bucket policy set-custom <bucket-name> <policy-file>`   |
| **Set S3 bucket quota:** Defines a storage quota for an S3 bucket.                                                                                                                                                                                   | [PUT ​/s3​/buckets​/{bucket}​/quota](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/setS3BucketQuota)                            | `weka s3 bucket quota set <bucket-name> <hard-quota>`            |
| **Unset S3 bucket quota:** Removes a storage quota from an S3 bucket.                                                                                                                                                                                | [DELETE ​/s3​/buckets​/{bucket}​/quota](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/unsetS3BucketQuota)                       | `weka s3 bucket quota unset <bucket-name>`                       |
| **Get container readiness:** Returns the readiness status of containers within the S3 cluster.                                                                                                                                                       | [GET ​/s3​/containersAreReady](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/gets3ContainersAreReady)                           | `weka s3 cluster status`                                         |
| **Add container to S3 cluster:** Adds a container to the S3 cluster.                                                                                                                                                                                 | [POST ​/s3​/containers](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/addS3Containers)                                          | `weka s3 cluster container add <container-ids>`                  |
| **Remove containers:** Removes containers from the S3 cluster.                                                                                                                                                                                       | [DELETE ​/s3​/containers](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/deleteS3Containers)                                     | `weka s3 cluster container remove <container-ids>`               |
| **Get logging verbosity:** Returns the logging level for container processes within the S3 cluster.                                                                                                                                                  | [GET ​/s3​/debug](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/gets3DebugLevel)                                                | `weka s3 log-level get`                                          |
| **Set logging verbosity:** Adjusts the logging level for container processes within the S3 cluster.                                                                                                                                                  | [POST ​/s3​/debug](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/sets3DebugLevel)                                               | `weka s3 log-level set <log-level>`                              |
| **Enable S3 audit webhook:** Activates the S3 audit webhook.                                                                                                                                                                                         | [POST ​/s3​/auditWebhook​/enable](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/enableS3AuditWebhook)                           | `weka s3 cluster audit-webhook enable`                           |
| **Disable S3 audit webhook:** Deactivates the S3 audit webhook.                                                                                                                                                                                      | [POST ​/s3​/auditWebhook​/disable](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/disableS3AuditWebhook)                         | `weka s3 cluster audit-webhook disable`                          |
| **Get S3 audit webhook configuration:** Returns details about the S3 audit webhook configuration.                                                                                                                                                    | [GET ​/s3​/auditWebhook](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3AuditWebhook)                                       | `weka s3 cluster audit-webhook show`                             |
| **Add S3 OIDC configuration:** Adds OIDC (OpenID Connect) configuration for S3 authentication.                                                                                                                                                       | [POST /s3/oidc](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/addS3OIDC) \*\*                                                   | `weka s3 cluster oidc add`                                       |
| **Update S3 OIDC configuration:** Updates existing OIDC configuration.                                                                                                                                                                               | [PUT /s3/oidc](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/updateS3OIDC) \*\*                                                 | `weka s3 cluster oidc update`                                    |
| **Remove S3 OIDC configuration:** Removes the OIDC configuration.                                                                                                                                                                                    | [DELETE /s3/oidc](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/removeS3OIDC) \*\*                                              | `weka s3 cluster oidc remove`                                    |
| **Get S3 OIDC configuration:** Returns the current OIDC configuration.                                                                                                                                                                               | [GET /s3/oidc](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/getS3OIDC) \*\*                                                    | `weka s3 cluster oidc show`                                      |
| <p><strong>Import LDAP user for S3 access:</strong> Provisions S3 access for an existing LDAP user in tenant 0.</p><p>Use <code>/s3/{tenantId}/ldapImportUser</code> for other tenants.</p>                                                          | [POST ​/s3​/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapCreateS3User) \*\*                                | N/A                                                              |
| <p><strong>Update an S3 user through LDAP authentication:</strong> Updates an S3 user's credentials and policy through LDAP authentication in tenant 0.</p><p>Use <code>/s3/{tenantId}/ldapImportUser</code> for other tenants.</p>                  | [PUT ​/s3​/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapUpdateS3User) \*\*                                 | N/A                                                              |
| <p><strong>Remove an S3 user through LDAP username:</strong> Deletes an S3 user authenticated through LDAP in tenant 0.</p><p>Use <code>/s3/{tenantId}/ldapImportUser</code> for other tenants.</p>                                                  | [DELETE ​/s3​/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapDeleteS3User) \*\*                              | N/A                                                              |
| **Import LDAP user for S3 access in specific tenant:** Provisions S3 access for an existing LDAP user. It authenticates the user against the configured LDAP directory for the specified tenant and generates unique S3 access and secret keys.      | [POST /s3/{tenantId}/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapCreateS3UserForTenant) \*\*              | N/A                                                              |
| **Updates an S3 user through LDAP authentication in specific tenant:** Updates an S3 user's credentials and policy through LDAP authentication for the specified tenant.                                                                             | [PUT /s3/{tenantId}/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapUpdateS3UserForTenant) \*\*               |                                                                  |
| **Remove an S3 user through LDAP authentication in specific tenant:** Deletes an S3 user authenticated through LDAP for the specified tenant.                                                                                                        | [DELETE /s3/{tenantId}/ldapImportUser](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/ldapDeleteS3UserForTenant) \*\*            |                                                                  |
| **Refresh all LDAP S3 users:** Synchronizes UID, GID, and S3 policies for all LDAP-imported users to ensure cluster permissions match the current directory state. This operation updates existing identities and reports success or failure counts. | [PUT ​/s3​/refresh-imported](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/refreshS3ImportedUsers) \*\*                         | N/A                                                              |
| **Refresh all LDAP S3 users for a specific tenant:** Synchronizes UID, GID, and S3 policies for all LDAP-imported users in the specified tenant.                                                                                                     | [PUT ​/s3/{tenantId}/refresh-imported](https://api.docs.weka.io/?urls.primaryName=5.1#/S3/refreshS3ImportedUsersForTenant) \*\*      |                                                                  |

## Security

Related information: [Security overview](/security/security)

| Task                                                                                                                                                                                                                                                                                                                                                                                         | REST API                                                                                                                                            | CLI                                             |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------- |
| **Get token expiration configuration:** Returns the configured default and maximum expiration times for access and refresh tokens. Token expiration ensures authentication credentials remain valid for a limited time, reducing risks such as unauthorized access and token misuse.                                                                                                         | [GET ​/security​/defaultTokensExpiry](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/getTokensExpiry)                                     | `weka security token-expiry show`               |
| **Configure token expiration setting:** Configures the default and maximum expiration times for access and refresh tokens to maintain a secure, policy-aligned authentication environment. Best practices recommend setting access tokens to 5 minutes and refresh tokens to 2 weeks to balance security and usability.                                                                      | [POST ​/security​/defaultTokensExpiry](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/setTokensExpiry)                                    | `weka security token-expiry set`                |
| **Get login banner configuration:** Returns the current login banner text and enabled status. The login banner displays a customizable legal or security message on the GUI sign-in page to warn against unauthorized access and inform authorized users of their responsibilities and acceptable use policies.                                                                              | [GET ​/security​/banner](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/getLoginBanner)                                                   | `weka security login-banner show`               |
| **Set or update the login banner:** Creates or modifies the login banner containing a security statement or legal message displayed on the sign-in page. The statement can warn potential intruders about illegal activities while advising authorized users of their obligations regarding acceptable system use.                                                                           | [PUT ​/security​/banner](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/setLoginBanner)                                                   | `weka security login-banner set <login-banner>` |
| <p><strong>Enable the login banner:</strong></p><p>Activates the login banner so it displays on the GUI sign-in page, presenting the configured security or legal message to all users attempting to access the system.</p>                                                                                                                                                                  | [POST ​/security​/banner​/enable](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/enableLoginBanner)                                       | `weka security login-banner enable`             |
| **Disable the login banner:** Deactivates the login banner so it no longer displays on the GUI sign-in page. The banner text is preserved and can be re-enabled at any time.                                                                                                                                                                                                                 | [POST ​/security​/banner​/disable](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/disableLoginBanner)                                     | `weka security login-banner disable`            |
| **Upload custom CA certificate for cluster authentication:** Uploads a custom Certificate Authority (CA) certificate to be used for secure cluster authentication with external services such as Vault. This certificate enables the cluster to verify the identity of external systems using TLS/SSL. If a certificate is already configured, this operation replaces it.                   | [PUT ​/security​/caCert](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/setCaCert)                                                        | `weka security ca-cert set`                     |
| **Remove custom CA certificate from cluster:** Removes the configured custom CA certificate from the cluster. After removal, the cluster will revert to using the default certificate validation mechanism.                                                                                                                                                                                  | [DELETE ​/security​/caCert](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/unsetCaCert)                                                   | `weka security ca-cert unset`                   |
| **Get CA certificate details and status:** Returns comprehensive information about the cluster's currently configured CA certificate, including its status, certificate metadata, and content. Use this endpoint to verify certificate configuration and expiration dates.                                                                                                                   | [GET ​/security​/caCert](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/showCaCert)                                                       | `weka security ca-cert status`                  |
| **Create a CIDR-based security policy:** Creates a new security policy to regulate access to cluster management and POSIX data services. These policies strengthen security by permitting or blocking connections from specific client IP address ranges without requiring user authentication. Policies are evaluated in order of attachment, and updates do not affect active connections. | [POST​/security​/policies](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/post_security_policies)                                         | `weka security policy create`                   |
| **List all security policies**: Returns a comprehensive list of all CIDR-based security policies defined in the cluster. These policies control access to cluster management and POSIX data services based on client IP ranges.                                                                                                                                                              | [GET​/security​/policies](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/listSecPolicies)                                                 | `weka security policy list`                     |
| **Get a specific security policy:** Returns detailed configuration information for a specific security policy identified by its UUID. This includes the policy's name, description, action, roles, IP ranges, and read-only status.                                                                                                                                                          | [GET​/security​/policies​/{policy}](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/getSecPolicy)                                          | `weka security policy show`                     |
| **Delete a security policy:** Permanently removes a security policy from the system. This operation does not affect currently active connections. The policy will no longer be evaluated for new connection attempts.                                                                                                                                                                        | [DELETE​/security​/policies​/{policy}](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/deleteSecPolicy)                                    | `weka security policy delete`                   |
| **Update an existing security policy:** Modifies the configuration of an existing security policy. You can replace entire role or IP lists, or incrementally add/remove specific entries. Changes take effect immediately for new connections but do not impact existing active sessions.                                                                                                    | [PATCH​/security​/policies​/{policy}](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/patch_security_policies__policy_)                    | `weka security policy update`                   |
| **Duplicate an existing security policy:** Creates a new security policy by copying all configuration settings from an existing policy. The new policy requires a unique name but inherits all other properties including description, action, roles, IP ranges, and read-only status.                                                                                                       | [POST​/security​/policies​/{policy}​/duplicate](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/post_security_policies__policy__duplicate) | `weka security policy duplicate`                |
| **Test security policy evaluation:** Simulates how one or more security policies would evaluate a connection attempt for API access or cluster joining. Returns the resulting action (Allow/Deny), whether it was explicitly matched, and details of the matched policy. Use this endpoint to validate policy configurations before deployment.                                              | [GET​/security​/policies​/test](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/testJoinSecurityPolicies)                                  | `weka security policy test`                     |
| **Remove all security policies from cluster join configuration:** Removes all security policies currently applied to the cluster join process for the specified mode (backend or client). This allows any container to join the cluster without IP-based security policy restrictions. The join secret authentication, if configured, remains active.                                        | [DELETE​/security​/join​/{mode}​/securityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/resetJoinSecurityPolicies)                | `weka security policy join reset`               |
| **Get security policies for cluster joining**: Returns the list of security policies currently applied when containers or clients attempt to join the cluster for the specified mode. These policies work in conjunction with join secret authentication to secure cluster membership.                                                                                                       | [GET​/security​/join​/{mode}​/securityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/getJoinSecurityPolicies)                     | `weka security policy join list`                |
| **Set cluster join security policies:** Configures the complete set of security policies for containers or clients joining the cluster, replacing any existing policy configuration. These policies are evaluated to determine whether a join attempt from a specific IP address should be allowed or denied. Works in conjunction with join secret authentication.                          | [PUT​/security​/join​/{mode}​/securityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/setJoinSecurityPolicies)                     | `weka security policy join set`                 |
| **Attach security policies to cluster join configuration:** Adds one or more security policies to the existing list of policies applied during cluster joining for the specified mode. The new policies are appended to the end of the evaluation order. Use this endpoint to incrementally build up join security without replacing the entire policy set.                                  | [POST​/security​/join​/{mode}​/securityPolicy​/attach](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/attachJoinSecurityPolicies)         | `weka security policy join attach`              |
| **Detach security policies from cluster join configuration:** Removes specific security policies from the list of policies applied during cluster joining for the specified mode. Other policies in the join configuration remain active and continue to be evaluated in their original order.                                                                                               | [POST​/security​/join​/{mode}​/securityPolicy​/detach](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/detachJoinSecurityPolicies)         | `weka security policy join detach`              |
| **Get GUI idle timeout configuration:** Returns the currently configured idle timeout duration for the graphical user interface. The GUI idle timeout automatically logs out users after a specified period of inactivity, reducing the risk of unauthorized access from unattended sessions.                                                                                                | [GET/Security/guiIdleTimeout](https://api.docs.weka.io/?urls.primaryName=5.1#/Security/guiIdleTimeout) \*\*                                         | `weka security gui-idle-timeout show`           |

## Servers

Related information: [Expand and shrink cluster resources](/operation-guide/expanding-and-shrinking-cluster-resources)

| Task                                                                                                                                                                                                                                                                                                                                                                                                                          | REST API                                                                                                           | CLI                                     |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ | --------------------------------------- |
| <p><strong>Get cluster server inventory:</strong></p><p>Returns a comprehensive list of all servers within the cluster. Supports optional filtering by server role to narrow results to specific server types or functions within the cluster topology.</p>                                                                                                                                                                   | [GET ​/servers](https://api.docs.weka.io/?urls.primaryName=5.1#/Servers/getServers)                                | `weka cluster servers list`             |
| **Get individual server information:** Returns detailed configuration, status, and operational information for a specific server identified by its unique identifier.                                                                                                                                                                                                                                                         | [GET ​/servers​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Servers/getSingleServer)                    | `weka cluster servers show`             |
| <p><strong>Run action on multiple servers:</strong> Initiates a specified action across one or more servers in the cluster.<br>This endpoint allows administrators to perform coordinated operations such as stopping, restarting, or applying<br>resource configuration changes to containers running on the targeted servers.<br>Actions are queued and executed based on cluster policies and operational constraints.</p> | [PUT ​/Servers/requestedAction](https://api.docs.weka.io/?urls.primaryName=5.1#/Servers/setServersRequestedAction) | `weka cluster servers requested-action` |

## SMB

Related information: [Manage the SMB protocol](/additional-protocols/smb-support)

| Task                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | REST API                                                                                                                       | CLI                                                                       |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------- |
| <p><strong>Get SMB cluster configuration:</strong></p><p>Returns comprehensive details about the existing SMB cluster, including domain membership status, container assignments, ID mapping configuration, encryption settings, and feature enablement flags.</p><p>Use this endpoint to audit the current cluster state or verify configuration changes.</p>                                                                                                                                                                                                  | [GET ​/smb](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/getSamba)                                                      | `weka smb cluster`                                                        |
| <p><strong>Create a new SMB cluster:</strong> Creates a new SMB cluster and establishes its foundational configuration. This includes setting the domain association, assigning containers to serve the SMB protocol, and defining security policies.</p><p>This operation creates the cluster structure but does not join it to an Active Directory domain. After the cluster is created, use the <code>POST /smb/activeDirectory</code> endpoint to complete the domain integration.</p>                                                                      | [POST ​/smb](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSamba)                                                     | `weka smb cluster add <netbios-name> <domain> <config-fs-name>`           |
| **Modify SMB cluster settings:** Updates cluster-wide configuration parameters for an existing SMB deployment.Supports modification of encryption policy and floating IP address assignments. Changing the encryption policy affects new connections. Existing connections maintain their original encryption state until reconnection.                                                                                                                                                                                                                         | [PUT ​/smb](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/updateSamba)                                                   | `weka smb cluster update`                                                 |
| <p><strong>Remove SMB cluster configuration:</strong> Disables the SMB cluster and removes its configuration. This action terminates all active client sessions, removes associated floating IPs, and automatically disconnects the cluster from its Active Directory domain, if joined.</p><p>The underlying filesystem data is preserved. This operation only removes network access through the SMB protocol.</p>                                                                                                                                            | [DELETE ​/smb](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/clearSamba)                                                 | `weka smb cluster destroy`                                                |
| <p><strong>Get trusted domain list:</strong></p><p>Returns all trusted domains configured within the SMB cluster.</p><p>Trusted domains enable cross-domain authentication and resource access in multi-domain Active Directory environments. Each domain includes ID mapping range specifications.</p>                                                                                                                                                                                                                                                         | [GET ​/smb​/domains](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSambaDomains)                                      | `weka smb cluster trusted-domains`                                        |
| **Add trusted domain to cluster:** Registers a new trusted domain with the SMB cluster and configures its ID mapping range. Trusted domains allow users and groups from additional Active Directory domains to access SMB resources. This operation automatically restarts SMB services to apply the new trust configuration, which may cause a brief service interruption. Ensure the specified ID mapping range (`mapping_from_id`–`mapping_to_id`) does not overlap with existing domain ranges.                                                             | [POST ​/smb​/domains](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/addSambaDomain)                                      | `weka smb cluster trusted-domains add`                                    |
| **Get filesystem mount options:** Returns the array of mount options applied to SMB cluster filesystem operations. These options control caching behavior (`readcache`, `writecache`), coherence modes, and other performance characteristics affecting data access patterns.                                                                                                                                                                                                                                                                                   | [GET ​/smb​/mount](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSambaMountOptions)                                   | N/A                                                                       |
| **Get all SMB shares:** Returns a comprehensive list of all shares configured within the SMB cluster. Each share includes access permissions, encryption settings, filesystem mappings, user access lists, and configuration parameters.                                                                                                                                                                                                                                                                                                                        | [GET ​/smb​/shares](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSambaShares)                                        | `weka smb share`                                                          |
| **Add SMB share:** Provisions a new share within the SMB cluster, mapping a filesystem path to a network-accessible share. The share becomes immediately available to authorized users upon creation. For access control, use the `user_list_type` and users parameters to define initial access permissions. After creating a user, additional users can be added using the `POST /smb/users` endpoint. For ACL options, use the `map_acls` parameter to determine how Windows ACLs are translated to filesystem permissions (posix, windows, or hybrid mode). | [POST ​/smb​/shares](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/addShareToSamba)                                      | `weka smb share add <share-name> <fs-name>`                               |
| <p><strong>Join Active Directory domain:</strong><br>Joins the SMB cluster to the Active Directory domain specified during the initial cluster creation. This operation creates the necessary computer account in Active Directory, establishes trust, and enables authentication for domain users and groups.</p><p>Before using this endpoint, you must first create the SMB cluster using <code>POST /smb</code>.</p>                                                                                                                                        | [POST ​/smb​/activeDirectory](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSambaActiveDirectory)                     | `weka smb domain join <username> <password>`                              |
| <p><strong>Disconnect from Active Directory domain:</strong> Disconnects the SMB cluster from the Active Directory domain. This action deletes the cluster account from Active Directory and terminates domain-based authentication, making shares immediately inaccessible to all domain users.</p><p>Before leaving the domain, configure an alternative authentication method if you require continued access to the shares. Administrator credentials may be necessary to complete the operation.</p>                                                       | [PUT ​/smb​/activeDirectory](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/deleteSambaActiveDirectory)                   | `weka smb domain leave <username>`                                        |
| <p><strong>Configure SMB container logging verbosity:</strong></p><p>Adjusts the debug logging level for SMB container processes on specified containers. Higher debug levels increase logging verbosity, which is useful for troubleshooting but may impact performance.</p>                                                                                                                                                                                                                                                                                   | [POST ​/smb​/debug](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/setSambaDebug)                                         | `weka smb cluster debug <level>`                                          |
| **Modify share configuration:** Updates operational parameters for an existing SMB share. Changes take effect immediately and apply to new client connections. Active sessions may need to reconnect to observe changes. Only a subset of share properties can be modified after creation. To change immutable properties (for example, filesystem, sub\_path), delete and recreate the share.                                                                                                                                                                  | [PUT ​/smb​/shares​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/updateSambaShare)                               | `weka smb share update <share-id>`                                        |
| **Remove SMB share:** Removes an SMB share from the cluster, terminating network access to the associated filesystem path. Active client connections to this share are forcibly disconnected. Underlying filesystem data remains intact. Only the SMB network share configuration is removed.                                                                                                                                                                                                                                                                   | [DELETE ​/smb​/shares​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/deleteSambaShare)                            | `weka smb share remove <share-id>`                                        |
| <p><strong>Remove trusted domain:</strong> Removes a trusted domain from the SMB cluster, revoking authentication and access rights for all users and groups within that domain.</p><p>This operation triggers a background restart of the SMB services, which may cause a brief service interruption. Before removing a domain, ensure no active share permissions reference its users or groups.</p>                                                                                                                                                          | [DELETE ​/smb​/domains​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/deleteSambaDomain)                          | `weka smb cluster trusted-domains remove`                                 |
| <p><strong>Grant share access to users:</strong></p><p>Adds specified users or groups to a share's access control list with designated permission level.</p><p>Users can be Active Directory users, groups, or domain aliases.</p>                                                                                                                                                                                                                                                                                                                              | [POST ​/smb​/users​/{share\_uid}​/{user\_type}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/addUserToSamba)            | `weka smb share lists add <share-id> <user-list-type> --users <users>`    |
| <p><strong>Remove all users from the access list:</strong> Removes all users and groups from the specified access permission category for a given share. This is a bulk operation that clears the entire user list for the specified category.</p><p>Useful when reconfiguring share permissions from scratch or removing all entries before applying a new access control policy. To remove individual users, use <code>DELETE /smb/users/{share\_uid}/{user\_type}/{user}</code> instead.</p>                                                                 | [DELETE ​/smb​/users​/reset​/{share\_uid}​/{user\_type}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/resetSambaUsers)  | `weka smb share lists reset <share-id> <user-list-type>`                  |
| <p><strong>Remove specific user from share access:</strong></p><p>Removes an individual user or group from the specified access permission category.</p><p>The user immediately loses the associated permissions, but may retain access through other permission categories or group memberships.</p>                                                                                                                                                                                                                                                           | [DELETE ​/smb​/users​/{share\_uid}​/{user\_type}​/{user}](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/deleteSambaUser) | `weka smb share lists remove <share-id> <user-list-type> --users <users>` |
| <p><strong>Verify SMB container readiness:</strong> Checks the operational readiness of all containers participating in the SMB cluster.</p><p>The response indicates whether each container's SMB process is fully operational and ready to serve client requests. Use this endpoint to monitor cluster health or to verify that configuration changes have been applied successfully.</p>                                                                                                                                                                     | [GET ​/smb​/containersAreReady](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/getSambaContainersAreReady)                | `weka smb cluster status`                                                 |
| <p><strong>Add SMB cluster containers:</strong></p><p>Expands the SMB cluster by adding containers to distribute the SMB service load.</p><p>Newly added containers immediately handle SMB requests and participate in HA failover.</p><p>Requires properly configured hosts and sufficient floating IPs.</p><p>Used to scale SMB capacity for increased load or improved fault tolerance.</p>                                                                                                                                                                  | [PUT ​/smb​/servers](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/addSambaServers)                                      | `weka smb cluster containers add --containers-id <containers-id>`         |
| <p><strong>Remove containers from SMB cluster:</strong></p><p>Removes specified containers from the SMB cluster. Client connections on the removed containers migrate to the remaining active containers in the cluster.</p><p>Use this operation to decommission containers for maintenance or to reduce the cluster size during periods of low demand.</p><p>Before proceeding, ensure that at least one container remains in the cluster and that the removal does not violate the cluster's minimum redundancy requirements.</p>                            | [DELETE ​/smb​/servers](https://api.docs.weka.io/?urls.primaryName=5.1#/SMB/deleteSambaServers)                                | `weka smb cluster containers remove --containers-id <containers-id>`      |

## Snapshot policy

Related information: [Snapshot policies](/weka-filesystems-and-object-stores/snapshot-policies)

| Task                                                                                                                                                                                                                          | REST API                                                                                                                                         | CLI                                            |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------- |
| **Create snapshot policy:** Creates a new snapshot policy with specified scheduling parameters, retention rules, and configuration settings for automated point-in-time data copies.                                          | [POST​/snapshotPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/createSnapshotPolicy)                                   | `weka fs protection snapshot-policy add`       |
| **Get all snapshot policies**: Returns a complete list of all snapshot policies configured in the cluster with their current settings and status.                                                                             | [GET​/snapshotPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/listSnapPolicies)                                        | `weka fs protection snapshot-policy list`      |
| <p><strong>Get a snapshot policy</strong>:</p><p>Returns detailed configuration for a specific snapshot policy, including schedule definitions, retention parameters, and attached filesystem associations.</p>               | [GET​/snapshotPolicy​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/showSnapshotPolicy)                               | `weka fs protection snapshot-policy show`      |
| **Update snapshot policy**: Updates configuration settings for an existing snapshot policy, including name, description, schedule parameters, retention rules, and activation status.                                         | [PUT​/snapshotPolicy​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/updateSnapshotPolicy)                             | `weka fs protection snapshot-policy update`    |
| **Delete snapshot policy:** Permanently removes a snapshot policy from the system. All filesystems must be detached from the policy before deletion can proceed.                                                              | [DELETE​/snapshotPolicy​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/deleteSnapshotPolicy)                          | `weka fs protection snapshot-policy remove`    |
| **List filesystems attached to a snapshot policy**: Returns a list of all filesystem identifiers currently associated with a specific snapshot policy.                                                                        | [GET​/snapshotPolicy​/{uid}​/filesystems](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/listFsAttachedToSnapshotPolicy)      | `weka fs protection snapshot-policy show`      |
| **Attach filesystems to snapshot policy**: Associates one or more filesystems with a snapshot policy, applying the policy's scheduling and retention rules to the specified filesystems.                                      | [POST​/snapshotPolicy​/{uid}​/filesystems​/attach](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/attachFsToSnapshotPolicy)   | `weka fs protection snapshot-policy attach`    |
| **Detach filesystems from snapshot policy**: Removes the association between a snapshot policy and one or more filesystems, discontinuing automated snapshot operations for those filesystems.                                | [POST​/snapshotPolicy​/{uid}​/filesystems​/detach](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/detachFsFromSnapshotPolicy) | `weka fs protection snapshot-policy detach`    |
| **Duplicate a snapshot policy:** Creates a copy of an existing snapshot policy with its configuration settings, optionally including filesystem associations. Useful for establishing similar policies with minor variations. | [POST/snapshotPolicy/{uid}/duplicate](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/duplicateSnapshotPolicy)                 | `weka fs protection snapshot-policy duplicate` |
| **Run the snapshot policy schedule once:** Runs a specified schedule type immediately, creating snapshots for all attached filesystems without waiting for the scheduled time.                                                | [POST/snapshotPolicy/{uid}/runOnce](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot%20Policy/runSnapshotPolicyScheduleOnce)             | `weka fs protection snapshot-policy run-once`  |

## Snapshots

Related information:

* [Snapshots](/weka-filesystems-and-object-stores/snapshots)
* [Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj)

| Task                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | REST API                                                                                                                               | CLI                                                                    |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| **List all snapshots:** Returns a list of all filesystem snapshots in the system. Snapshots are point-in-time copies used for backup, archiving, and testing. Filter results by filesystem using the query parameter.                                                                                                                                                                                                                                                                                       | [GET ​/snapshots](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/getSnapshots)                                              | `weka fs snapshot`                                                     |
| <p><strong>Create a new snapshot:</strong></p><p>Creates a point-in-time snapshot of an existing filesystem. Snapshots are read-only by default and do not impact system performance. Writable snapshots enable data modification for testing environments.</p><p>Snapshots consume minimal space based on 4KB granularity differences. Once created as writable, a snapshot cannot be converted to read-only.</p>                                                                                          | [POST ​/snapshots](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/createSnapshot)                                           | `weka fs snapshot add <file-system> <snapshot-name>`                   |
| **Get snapshot details:** Returns detailed information about a specific snapshot, including creation timestamp, parent filesystem, size, and writability status.                                                                                                                                                                                                                                                                                                                                            | [GET ​/snapshots​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/getSnapshot)                                        | `weka fs snapshot --name <snapshot-name>`                              |
| **Update snapshot configuration:** Modifies snapshot name or access point. The snapshot's data and point-in-time state remain unchanged.                                                                                                                                                                                                                                                                                                                                                                    | [PUT ​/snapshots​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/updateSnapshot)                                     | `weka fs snapshot update <file-system> <snapshot-name>`                |
| <p><strong>Delete a snapshot:</strong></p><p>Permanently removes a snapshot from the system and frees storage space consumed by its unique data.</p><p>If the snapshot has been downloaded to another filesystem, deletion may cause that filesystem to malfunction. Ensure downloaded snapshots are un-tiered or migrated before deletion.</p>                                                                                                                                                             | [DELETE ​/snapshots​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/deleteSnapshot)                                  | `weka fs snapshot remove <file-system> <snapshot-name>`                |
| <p><strong>Create a copy of a snapshot:</strong></p><p>Creates a duplicate of an existing snapshot within the same filesystem.</p><p>Useful for creating multiple versions or preserving snapshot state.</p>                                                                                                                                                                                                                                                                                                | [POST ​/snapshots​/{uid}​/copy](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/copySnapshot)                                | `weka fs snapshot copy <file-system> <source-name> <destination-name>` |
| <p><strong>Upload snapshot to object store:</strong> Transfers a snapshot to object storage using the Snap-To-Object feature.</p><p>Consolidates all snapshot data, including filesystem metadata and files, for backup, archiving, or disaster recovery.</p><p>Only read-only snapshots can be uploaded. Upload snapshots in chronological order for optimal efficiency.</p>                                                                                                                               | [POST ​/snapshots​/{uid}​/upload](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/uploadSnapshot)                            | `weka fs snapshot upload <file-system> <snapshot-name>`                |
| <p><strong>Download snapshot from object store:</strong> Downloads a previously uploaded snapshot from object storage to a filesystem. Enables data restoration, disaster recovery, and filesystem migration.</p><p>Snapshots are incrementally reconstructed on the target filesystem.</p><p>Apply snapshots in chronological order for optimal consistency. Use the locator obtained during snapshot upload.</p><p>Downloading snapshots from object stores within the same cluster is not supported.</p> | [POST ​/snapshots​/download](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/downloadSnapshot)                               | `weka fs snapshot download`                                            |
| <p><strong>Restore filesystem from snapshot</strong>: Restores a filesystem to a previous state using a specified snapshot. This operation overwrites the current filesystem content.</p><p>Warning: This operation is destructive. Ensure appropriate backups exist before proceeding. Consider creating a snapshot of the current filesystem state first.</p>                                                                                                                                             | [POST ​/snapshots​/{fs\_uid}​/{uid}​/restore](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/restoreFileSystemFromSnapshot) | `weka fs snapshot download <file-system> <snapshot-locator>`           |
| **Get snapshot metadata from object store:** Returns detailed metadata about a snapshot stored in object storage using its locator string. Queries the object store directly without requiring the snapshot to be downloaded.                                                                                                                                                                                                                                                                               | [POST​/snapshots​/locatorInfo](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshot/locatorInfo)                                   | N/A                                                                    |
| <p><strong>Initialize snapshot differential analysis:</strong> Prepares the system for computing differences between two snapshots by generating processing tokens (cookies).</p><p>This is the first step in a two-phase operation for identifying changed, added, or deleted files.</p><p>The operation divides the comparison workload into parallel chunks based on the requested parallelism.</p><p>Use the returned cookies in subsequent <code>getResults</code> calls.</p>                          | [POST/snapshots​/diff​/prepare](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/diffPrepare)                                 | N/A                                                                    |
| <p><strong>Get snapshot differential results:</strong> Retrieves the actual differences between two snapshots, including changed, added, and deleted files.</p><p>Must be called after preparing the differential analysis using the prepare endpoint.</p><p>Supports efficient pagination through resume and stop tokens. Use <code>resume\_token</code> from previous responses to continue where you left off.</p>                                                                                       | [POST/snapshots/diff/getResults](https://api.docs.weka.io/?urls.primaryName=5.1#/Snapshots/diffList)                                   | N/A                                                                    |

## Stats

Related information: [Statistics](/operation-guide/statistics)

| Task                                                                                                                                             | REST API                                                                                              | CLI                                             |
| ------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------- | ----------------------------------------------- |
| **Get statistics:** Returns statistics related to the cluster's performance and resource usage.                                                  | [GET ​/stats](https://api.docs.weka.io/?urls.primaryName=5.1#/Stats/getStats)                         | `weka stats`                                    |
| **Get statistic descriptions:** Returns detailed information about the statistics.                                                               | [GET ​/stats​/description](https://api.docs.weka.io/?urls.primaryName=5.1#/Stats/getStatsDescription) | `weka stats list-types`                         |
| **Get real-time statistics:** Returns live statistics for the cluster.                                                                           | [GET ​/stats​/realtime](https://api.docs.weka.io/?urls.primaryName=5.1#/Stats/getRealTimeStats)       | `weka stats realtime`                           |
| **Get statistics retention and disk usage:** Returns the retention period of statistics and the estimated disk space required for their storage. | [GET ​/stats​/retention](https://api.docs.weka.io/?urls.primaryName=5.1#/Stats/getStatsDiskUsage)     | `weka stats retention status`                   |
| **Set statistics retention:** Sets the duration for which statistics are retained in storage.                                                    | [POST ​/stats​/retention](https://api.docs.weka.io/?urls.primaryName=5.1#/Stats/getStatsRetention)    | `weka stats retention set --days <num-of-days>` |

## System IO

Related information: [Perform post-configuration](/planning-and-installation/bare-metal/perform-post-configuration-procedures)

| Task                                                                            | REST API                                                                                | CLI                     |
| ------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | ----------------------- |
| **Start cluster IO services:** Initiates IO services across the entire cluster. | [POST ​/io​/start](https://api.docs.weka.io/?urls.primaryName=5.1#/System%20IO/startIO) | `weka cluster start-io` |
| **Stop cluster IO services:** Shuts down IO services across the entire cluster. | [POST ​/io​/stop](https://api.docs.weka.io/?urls.primaryName=5.1#/System%20IO/stopIO)   | `weka cluster stop-io`  |

## Tasks

Related information: [Background tasks](/operation-guide/background-tasks)

| Task                                                                                                                                | REST API                                                                                        | CLI                                  |
| ----------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------ |
| **Get background tasks:** Returns all background tasks currently running in the cluster, with optional filtering for waiting tasks. | [GET ​/tasks](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/getTasks)                   | `weka cluster task‌`                 |
| **Resume paused task:** Resumes execution of a previously paused background task.                                                   | [POST ​/tasks​/{uid}​/resume](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/resumeTask) | `weka cluster task resume <task-id>` |
| **Pause a running task:** Temporarily pauses a running background task. The task can be resumed later without losing progress.      | [POST ​/tasks​/{uid}​/pause](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/pauseTasks)  | `weka cluster task pause <task-id>`  |
| **Abort a running task:** Permanently terminates a background task and discards any incomplete work. This action cannot be undone.  | [POST ​/tasks​/{uid}​/abort](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/abortTasks)  | `weka cluster task abort <task-id>`  |
| **Get task resource limits:** Returns the current CPU resource limits configured for background task execution.                     | [GET ​/tasks​/limits](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/getTasksLimit)      | `weka cluster task limits`           |
| **Update task resource limits:** Configures the maximum CPU resources that can be allocated to background tasks cluster-wide.       | [PUT ​/tasks​/limits](https://api.docs.weka.io/?urls.primaryName=5.1#/Tasks/setTasksLimit)      | `weka cluster task limits set`       |

## Telemetry

Related information: [Audit and forwarding management](/operation-guide/audit-and-forwarding-management)

| **Get telemetry configuration:** Returns the cluster-wide telemetry configuration, including audit and forwarding settings.                                  | [GET /telemetry](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/getTelemetryStatus)                                       | `weka audit cluster status`                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------- |
| **Update telemetry configuration:** Modifies cluster-wide telemetry settings, including enabling/disabling audit logging and configuring tracked operations. | [POST /telemetry](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/updateTelemetryStatus)                                   | <p><code>weka audit cluster enable</code></p><p><code>weka audit cluster disable</code></p> |
| **Get all telemetry exports:** Returns all configured export destinations for telemetry data (for example, Splunk, S3, Kafka).                               | [GET /telemetry/exports](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/getTelemetryExports)                              | `weka telemetry exports list`                                                               |
| **Create a telemetry export:** Configures a new export destination to forward telemetry events to an external system.                                        | [PUT /telemetry/exports](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/createTelemetryExport)                            | `weka telemetry exports add`                                                                |
| **Get a telemetry export:** Returns the configuration and status of a specific export destination.                                                           | [GET /telemetry/exports/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/getTelemetryExport)                         | `weka telemetry exports show <export-name>`                                                 |
| **Update a telemetry export:** Modifies the configuration of an existing export destination (for example, endpoint URL, authentication credentials).         | [POST /telemetry/exports/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/updateTelemetryExport)                     | `weka telemetry exports update <export-name>`                                               |
| **Delete a telemetry export**: Removes an export destination, stopping all telemetry forwarding to that endpoint.                                            | [DELETE /telemetry/exports/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/removeTelemetryExport)                   | `weka telemetry exports remove`                                                             |
| **Attach data sources to export:** Associates one or more data sources (for example, 'Audit') with an export destination to begin forwarding that data type. | [PUT /telemetry/exports/{uid}/sources](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/attachTelemetrySourceToExport)      | `weka telemetry exports attach --sources audit`                                             |
| **Detach data sources from export:** Removes one or more data sources from an export destination, stopping the forwarding of that data type.                 | [DELETE /telemetry/exports/{uid}/sources](https://api.docs.weka.io/?urls.primaryName=5.1#/Telemetry/detachTelemetrySourceFromExport) | `weka telemetry exports detach <export-name> --sources audit`                               |

## Tenant

Related information: [WEKA native multi-tenancy management](/operation-guide/weka-native-multi-tenancy-management)

| Task                                                                                                                                                                   | REST API                                                                                                                                         | CLI                                                  |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------- |
| **Check if multiple tenants exist:** Checks if more than one tenant is configured in the cluster. This is useful for determining if multi-tenancy is active.           | [GET ​/tenants​/multipleTenantsExist](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/getMultipleTenantsExist) \*\*                       | `weka tenant`                                        |
| **Get a list of all tenants:** Returns a list of all tenants configured in the cluster.                                                                                | [GET ​/tenants](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/getTenants) \*\*                                                          | `weka tenant`                                        |
| **Create a new tenant:** Creates a new tenant within the cluster. A tenant is a logical partition that isolates users and data for multi-tenancy.                      | [POST ​/tenants](https://api.docs.weka.io/?urls.primaryName=5.1#/tenants/createTenant) \*\*                                                      | `weka tenant add`                                    |
| **Get a specific tenant:** Returns the details of a specific tenant, identified by its UID.                                                                            | [GET ​/tenants​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/getTenant) \*\*                                                    | `weka tenant <tenant name or ID>`                    |
| **Delete a specific tenant:** Removes a specific tenant from the cluster. This operation is only possible if the tenant does not contain any resources.                | [DELETE ​/tenants/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/deleteTenant) \*\*                                               | `weka tenant delete <tenant name or ID>`             |
| **Rename a tenant:** Updates the name of a specific tenant.                                                                                                            | [PUT ​/Tenant​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/updateTenant) \*\*                                                  | `weka tenant rename <tenant name or ID> <new-name>`  |
| **Set or update tenant quotas:** Sets or updates the storage capacity quotas for a specific tenant.                                                                    | [PUT ​/tenants/{uid}​/limits](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/setTenantLimit) \*\*                                        | `weka tenant set-quota <tenant name or ID>`          |
| **Update tenant options:** Updates enforcement options for a specific tenant, such as filesystem authentication and mount network space access enforcement.            | [PUT ​/tenants/{uid}​/options](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/setTenantOptions) \*\*                                     | `weka tenant update <tenant name or ID>`             |
| **Get network spaces for a tenant:** Returns a list of network spaces assigned to a specific tenant.                                                                   | [GET /tenants/{uid}/networkSpaces](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/getTenantNetworkSpaces) \*\*                           | `weka tenant network-space [--tenant tenant]`        |
| **Add network spaces to a tenant:** Assigns one or more network spaces to a specific tenant without affecting existing assignments.                                    | [POST /tenants/{uid}/networkSpaces/add](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/addTenantNetworkSpaces) \*\*                      | `weka tenant network-space add [--tenant tenant]`    |
| **Remove network spaces from a tenant:** Removes one or more network spaces from a specific tenant.                                                                    | [POST /tenants/{uid}/networkSpaces/remove](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/removeTenantNetworkSpaces) \*\*                | `weka tenant network-space remove [--tenant tenant]` |
| **Revoke all user tokens for a tenant:** Immediately invalidates all active login sessions (GUI, CLI, API) for all users within a specific tenant.                     | [DELETE /Tenant/{uid}/revoke](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/revokeTenantTokens) \*\*                                    | `weka tenant security revoke-tokens`                 |
| **Reset security policies for a tenant**: Removes all attached security policies from a specific tenant.                                                               | [DELETE​/Tenants​/{uid}​/securityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/resetTenantSecurityPolicies) \*\*                | `weka tenant security reset`                         |
| **Get security policies for a tenant:** Returns a list of all security policies attached to a specific tenant.                                                         | [GET​/Tenant​/{uid}​/getTenantSecurityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Organization/getOrganizationSecurityPolicies) \*\* | `weka tenant security list`                          |
| **Set security policies for a tenant:** Replaces all existing security policies on a tenant with a new set. Any policies not included in the request will be detached. | [PUT​/Tenant/{uid}​/setTenantSecurityPolicy](https://api.docs.weka.io/?urls.primaryName=5.1#/Organization/setOrganizationSecurityPolicies) \*\*  | `weka tenant security set`                           |
| **Attach security policies to a tenant:** Attaches one or more security policies to a specific tenant without affecting existing attachments.                          | [POST​/Tenant​/{uid}​/securityPolicy​/attach](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/attachTenantSecurityPolicies) \*\*          | `weka tenant security attach`                        |
| **Detach security policies from a tenant**: Detaches one or more security policies from a specific tenant.                                                             | [POST​/Tenant​/{uid}​/securityPolicy​/detach](https://api.docs.weka.io/?urls.primaryName=5.1#/Tenant/detachTenantSecurityPolicies) \*\*          | `weka tenant security detach`                        |

## TLS

Related information: [Manage TLS certificates](/security/tls-certificate-management)

| Task                                                                                                 | REST API                                                                                        | CLI                          |
| ---------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ---------------------------- |
| **Get TLS status:** Returns the current TLS configuration, including certificate details and status. | [GET ​/tls](https://api.docs.weka.io/?urls.primaryName=5.1#/TLS/getTls)                         | `weka security tls status`   |
| **Configure TLS certificate:** Uploads and enables a new TLS certificate and key for the cluster.    | [POST ​/tls](https://api.docs.weka.io/?urls.primaryName=5.1#/TLS/enableTls)                     | `weka security tls set`      |
| **Disable TLS certificate:** Removes the current TLS certificate configuration from the cluster.     | [DELETE ​/tls](https://api.docs.weka.io/?urls.primaryName=5.1#/TLS/disableTls)                  | `weka security tls unset`    |
| **Get TLS certificate:** Returns the full TLS certificate configured for the cluster.                | [GET ​/tls​/certificate](https://api.docs.weka.io/?urls.primaryName=5.1#/TLS/getTlsCertificate) | `weka security tls download` |

## Traces

Related information: [Traces management](/support/diagnostics-management/traces-management)

| Task                                                                                                                                                                                                                                                                                                               | REST API                                                                                            | CLI                              |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------- | -------------------------------- |
| **Get traces configuration:** Returns the current trace collection settings, including status and storage limits for both server and client traces.                                                                                                                                                                | [GET ​/traces](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/getTracesStatus)              | `weka debug traces status`       |
| **Set traces collection:** Configures and initiates the collection of trace data.                                                                                                                                                                                                                                  | [PUT ​/traces](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/updateTracesConfigure)        | `weka debug traces start`        |
| **Reset trace configuration to defaults:** Restores all trace collection settings to their factory default values, including storage limits and collection status.                                                                                                                                                 | [DELETE ​/traces](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/restoreTracesDefaults)     | `weka debug traces stop`         |
| **Get trace freeze period:** Returns the configured freeze period during which trace data is preserved and protected from automatic deletion to support troubleshooting and investigation activities.                                                                                                              | [GET ​/traces​/freeze](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/getTracesFreeze)      | `weka debug traces freeze show`  |
| **Set trace freeze period:** Configures a time range during which trace data is preserved and protected from deletion. This ensures diagnostic data remains available for analysis and troubleshooting of specific incidents or issues.                                                                            | [PUT ​/traces​/freeze](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/updateTracesFreeze)   | `weka debug traces freeze set`   |
| **Clear frozen traces:** Removes the active trace freeze configuration and allows frozen trace data to be subject to normal retention policies. This action clears all freeze period settings and releases preserved traces.                                                                                       | [DELETE ​/traces​/freeze](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/resetTracesFreeze) | `weka debug traces freeze reset` |
| **Set trace verbosity level:** Adjusts the granularity of trace data collection. LOW level captures essential information suitable for routine troubleshooting with minimal storage impact. HIGH level captures comprehensive diagnostic details required for complex issue analysis and root cause investigation. | [PUT ​/traces​/level](https://api.docs.weka.io/?urls.primaryName=5.1#/Traces/updateTracesLevel)     | `weka debug traces level set`    |

## User

Related information: [User management](/operation-guide/user-management)

| Task                                                                                                                                                                                              | REST API                                                                                             | CLI                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -------------------------------------------- |
| **Get all local users:** Returns all local user accounts on the system.                                                                                                                           | [GET ​/users](https://api.docs.weka.io/?urls.primaryName=5.1#/User/getUsers)                         | `weka user`                                  |
| **Create a new local user:** Creates a new local user account with the specified credentials and permissions.                                                                                     | [POST ​/users](https://api.docs.weka.io/?urls.primaryName=5.1#/User/createUser)                      | `weka user add <username> <role> <password>` |
| **Update user details:** Modifies role and POSIX settings for an existing local user.                                                                                                             | [PUT ​/users​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/User/updateUser)                | `weka user update <username>`                |
| **Delete a local user:** Permanently removes a local user account and associated data from the system.                                                                                            | [DELETE ​/users​/{uid}](https://api.docs.weka.io/?urls.primaryName=5.1#/User/deleteUser)             | `weka user delete <username>`                |
| **Set user password (admin):** Assigns a new password to a local user without requiring the current password. Requires administrative privileges.                                                 | [PUT ​/users​/password](https://api.docs.weka.io/?urls.primaryName=5.1#/User/updateUserPassword)     | `weka user passwd`                           |
| **Change user password:** Updates a user's password. Users can change their own password with their current credentials. Administrators can change any user's password within their organization. | [PUT ​/users​/{uid}​/password](https://api.docs.weka.io/?urls.primaryName=5.1#/User/setUserPassword) | `weka user passwd <username>`                |
| **Get current user informatio**&#x6E;**:** Returns profile information for the authenticated user making the request.                                                                             | [GET ​/users​/whoami](https://api.docs.weka.io/?urls.primaryName=5.1#/User/whoAmI)                   | `weka user whoami`                           |
| **Revoke user tokens:** Immediately invalidates all active authentication tokens for the specified user, terminating all GUI, CLI, and API sessions.                                              | [DELETE ​/users​/{uid}​/revoke](https://api.docs.weka.io/?urls.primaryName=5.1#/User/revokeUser)     | `weka user revoke-tokens`                    |

**Related information**

[REST API Reference Guide](https://api.docs.weka.io/)


# System performance tests

Measure the key performance metrics of a storage system—latency, IOPS, and bandwidth—using standardized testing procedures.

## Overview

When evaluating a storage system’s performance, three primary metrics are considered:

* **Latency:** The time between the initiation and completion of an I/O operation.
* **IOPS:** The number of I/O operations (read, write, or metadata) that the system can process per second.
* **Bandwidth:** The amount of data transferred per second during I/O operations.

Each metric applies to read, write, or mixed workloads. Performance characteristics may vary depending on the mount mode and network configuration (for example, user-space DPDK vs. kernel UDP).

It is important to distinguish between single-client and aggregated performance. A single client may be limited by its local resources, so for accurate cluster-wide measurements, run tests from multiple clients simultaneously.

To ensure that results reflect the filesystem’s true capabilities rather than client-side caching, all benchmarks use direct I/O (O\_DIRECT) and clear Linux caches between tests.

## Test performance with wekatester

Use the `wekatester` command-line utility to perform manual performance testing across multiple client hosts. The tool runs FIO (Flexible I/O) workloads on client systems, also referred to as compute nodes, that are connected to a shared network filesystem.

This approach enables consistent, reproducible, and comparable (“apples-to-apples”) performance benchmarking across different storage systems.

{% hint style="info" %}
Unlike previous versions, automatic cluster and client discovery (`wekatester -c`) is no longer available.

All servers must now be specified manually when running tests.
{% endhint %}

#### **Before you begin**

Ensure that FIO is installed on all client hosts participating in the tests.

FIO is included in most Linux distributions and can typically be installed using your system’s package manager, for example:

```
dnf install fio
# or
apt install fio
```

For more information on installation and usage, see [FIO documentation](https://fio.readthedocs.io/en/latest/fio_doc.html).

#### **Procedure**

1. Log in to a client with access to the system under test.
2. Clone the tools repository:

```bash
   git clone --depth 1 https://github.com/weka/tools.git
```

3. Navigate to the `wekatester` directory:

```bash
cd tools/wekatester
```

3. Run the performance test manually using the following syntax:

```bash
./wekatester.py -d <directory> [-w <workload>] [--fio-bin <path>] [server ...]
```

#### **Command properties**

All command properties are optional except the `server` property.

<table><thead><tr><th width="192.7734375">Option</th><th>Description</th></tr></thead><tbody><tr><td><code>server</code>*</td><td>Required. One or more server hostnames or IPs to use as workers.</td></tr><tr><td><code>-d, --directory</code></td><td><p>Target directory on the workers where test files will be created. The target filesystem must be mounted at this directory or at a parent directory.</p><p>Default: <code>/mnt/weka</code>.</p></td></tr><tr><td><code>-w, --workload</code></td><td><p>Specifies the workload definition directory from the <code>fio-jobfiles</code> subdirectory structure.</p><p>Default: <code>default</code></p><p>Built-in workload options:</p><ul><li><strong><code>default</code></strong>: Four-corners test suite covering read/write bandwidth, latency, and IOPS</li><li><strong><code>mixed</code></strong>: 70/30 read/write mixed workload patterns</li></ul><p>You can create custom workload directories under <code>fio-jobfiles/</code> and reference them with this option.</p><p>Example:</p><pre class="language-bash"><code class="lang-bash">./wekatester.py -d /mnt/weka -w mixed server1 server2 server3
</code></pre></td></tr><tr><td><code>--fio-bin</code></td><td><p>Specifies the path to the <code>fio</code> binary on target servers.</p><p>Default: <code>/usr/bin/fio</code></p><p>Use this option when <code>fio</code> is installed in a non-standard location or when you want to use a specific <code>fio</code> version.</p><p>Example:</p><pre class="language-bash"><code class="lang-bash">./wekatester.py -d /mnt/weka --fio-bin /opt/fio/bin/fio server1 server2
</code></pre></td></tr><tr><td><code>-v, --verbosity</code></td><td><p>Increases output verbosity for debugging and detailed monitoring.</p><p>Verbosity levels:</p><ul><li><code>-v</code>: Basic verbose output</li><li><code>-vv</code>: Detailed verbose output</li><li><code>-vvv</code>: Maximum verbosity with debug information</li></ul></td></tr><tr><td><code>-V, --version</code></td><td>Displays the <code>wekatester</code> version number.</td></tr></tbody></table>

#### Example default usage

```bash
./wekatester server1 server2 server3... 
```

During execution, `wekatester` distributes and runs FIO workloads on the specified servers, collects performance data, and summarizes the results.

#### Example output

The command displays a summary of the performance results, providing a clear overview of the cluster's capabilities.

```
starting test run for job 011-bandwidthR.job on <hostname> with <n> workers:
    read bandwidth: 9.37 GiB/s
    total bandwidth: 9.37 GiB/s
    average bandwidth: 2.34 GiB/s per host

starting test run for job 012-bandwidthW.job on <hostname> with <n> workers:
    write bandwidth: 7.72 GiB/s
    total bandwidth: 7.72 GiB/s
    average bandwidth: 1.93 GiB/s per host

starting test run for job 021-latencyR.job on <hostname> with <n> workers:
    read latency: 237 us

starting test run for job 022-latencyW.job on <hostname> with <n> workers:
    write latency: 180 us
```

Raw FIO results are stored as JSON files, for example:

```
results_2025-10-07_1112.json
```

These files contain the full FIO output for detailed analysis.

### Wekatester FIO job definitions

The `wekatester` tool uses a standardized set of Flexible I/O (FIO) tester jobs to ensure consistent and comparable results. These job definitions are provided for users who want to review the testing methodology or run the tests manually.

All jobs use a 2G file size for testing consistency.

#### **Read throughput job definition**

This job measures the maximum read bandwidth.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=32

[fio-createfiles-00]
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-bandwidthSR-00]
stonewall
description='Sequential Read bandwidth workload'
blocksize=1Mi
rw=read
iodepth=1
```

#### **Write throughput job definition**

This job measures the maximum write bandwidth.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=32

[fio-createfiles-00]
stonewall
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-bandwidthSW-00]
stonewall
description='Sequential Write bandwidth workload'
blocksize=1Mi
rw=write
iodepth=1
```

#### **Read IOPS job definition**

This job measures the maximum read IOPS using a 4k block size.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=64

[fio-createfiles-00]
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-iopsR-00]
stonewall
description='Read iops workload'
iodepth=8
bs=4k
rw=randread
```

#### **Write IOPS job definition**

This job measures the maximum write IOPS using a 4k block size.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=64

[fio-createfiles-00]
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-iopsW-00]
stonewall
description='Write iops workload'
iodepth=8
bs=4k
rw=randwrite
```

#### **Read latency job definition**

This job measures read latency using a 4k block size.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=1

[fio-createfiles-00]
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-latencyR-00]
stonewall
description='Read latency workload'
bs=4k
rw=randread
iodepth=1
```

#### **Write latency job definition**

This job measures write latency using a 4k block size.

```toml
[global]
filesize=2G
time_based=1
startdelay=5
exitall_on_error=1
create_serialize=0
filename_format=$filenum/$jobnum
directory=/mnt/weka
group_reporting=1
clocksource=gettimeofday
runtime=30
ioengine=libaio
disk_util=0
direct=1
numjobs=1

[fio-createfiles-00]
blocksize=1Mi
description='pre-create files'
create_only=1

[fio-latencyW-00]
stonewall
description='Write latency workload'
bs=4k
rw=randwrite
iodepth=1
```

## Testing metadata performance with MDTest

MDTest is an open-source tool designed to test metadata performance, measuring the rate of operations such as file creates, stats, and deletes across the cluster.

MDTest uses an MPI framework to coordinate jobs across multiple nodes. The examples shown here assume the use of MDTest version 1.9.3 with [MPICH](https://www.mpich.org/downloads/) version 3.3.2 ([MPITCH documentation](https://www.mpich.org/documentation/guides/)).

**Procedure**

Run the MDTest benchmark from a client machine with access to the WEKA filesystem. The following command runs the test across multiple clients defined in a hostfile. It uses 8 clients with 136 threads each to test the performance on 20 million files.

**Job definition**

```bash
mpiexec -f <hostfile> -np 1088 mdtest-v-N 136i 3 n 18382 -F -u-d /mnt/weka/mdtest
```

**Result example**

The following table shows an example summary from three test iterations.

| Operation         | Max         | Min         | Mean        | Std Dev |
| ----------------- | ----------- | ----------- | ----------- | ------- |
| **File creation** | 40784.448   | 40784.447   | 40784.448   | 0.001   |
| **File stat**     | 2352915.997 | 2352902.666 | 2352911.311 | 6.121   |
| **File read**     | 217236.252  | 217236.114  | 217236.162  | 0.064   |
| **File removal**  | 44101.905   | 44101.896   | 44101.902   | 0.004   |
| **Tree creation** | 3.788       | 3.097       | 3.342       | 0.316   |
| **Tree removal**  | 1.192       | 1.142       | 1.172       | 0.022   |

## Performance test results summary

The following tables show example results from tests run in specific AWS and SuperMicro environments.

### **Single client results**

<table><thead><tr><th width="203.96484375">Benchmark</th><th width="230.95703125">AWS</th><th>SuperMicro</th></tr></thead><tbody><tr><td><strong>Read Throughput</strong></td><td>8.9 GiB/s</td><td>21.4 GiB/s</td></tr><tr><td><strong>Write Throughput</strong></td><td>9.4 GiB/s</td><td>17.2 GiB/s</td></tr><tr><td><strong>Read IOPS</strong></td><td>393,333 ops/s</td><td>563,667 ops/s</td></tr><tr><td><strong>Write IOPS</strong></td><td>302,333 ops/s</td><td>378,667 ops/s</td></tr><tr><td><strong>Read Latency</strong></td><td>272 µs avg.&#x26;lt;br>99.5% completed under 459 µs</td><td>144.76 µs avg.&#x26;lt;br>99.5% completed under 260 µs</td></tr><tr><td><strong>Write Latency</strong></td><td>298 µs avg.&#x26;lt;br>99.5% completed under 432 µs</td><td>107.12 µs avg.&#x26;lt;br>99.5% completed under 142 µs</td></tr></tbody></table>

### **Aggregated cluster results (with multiple clients)**

<table><thead><tr><th width="203.94921875">Benchmark</th><th width="232.93359375">AWS</th><th>SuperMicro</th></tr></thead><tbody><tr><td><strong>Read Throughput</strong></td><td>36.2 GiB/s</td><td>123 GiB/s</td></tr><tr><td><strong>Write Throughput</strong></td><td>11.6 GiB/s</td><td>37.6 GiB/s</td></tr><tr><td><strong>Read IOPS</strong></td><td>1,978,330 ops/s</td><td>4,346,330 ops/s</td></tr><tr><td><strong>Write IOPS</strong></td><td>404,670 ops/s</td><td>1,317,000 ops/s</td></tr><tr><td><strong>Creates</strong></td><td>79,599 ops/s</td><td>234,472 ops/s</td></tr><tr><td><strong>Stats</strong></td><td>1,930,721 ops/s</td><td>3,257,394 ops/s</td></tr><tr><td><strong>Deletes</strong></td><td>117,644 ops/s</td><td>361,755 ops/s</td></tr></tbody></table>


# Performance test environment configurations

This section details the specific hardware and software configurations used to generate the example performance results.

## **AWS configuration**

#### **AWS cluster**

* Stripe Size: 4+2
* 8 backend server instances of [i3en.12xlarge](https://aws.amazon.com/ec2/instance-types/i3en/), placed in the same placement group
* OS: Amazon Linux AMI 2017.09.0.20170930 x86\_64 HVM
* 7 dedicated cores for WEKA (4 compute, 2 drives, 1 frontend)

#### **AWS clients**

* [c5n.18xlarge](https://aws.amazon.com/ec2/instance-types/c5/) instances; 8 clients were used for aggregated results
* OS: Amazon Linux AMI 2017.09.0.20170930 x86\_64 HVM
* 4 frontend cores
* DPDK networking
* Mount options: system defaults

## **SuperMicro configuration**

#### **SuperMicro cluster**

* Stripe Size: 4+2
* 8 backend servers (SYS-2029BT-HNR / X11DPT-B)
* OS: CentOS Linux release 7.8.2003
* CPU: 24/48 Threads (Intel Xeon Gold 6126 CPU @ 2.60GHz)
* Memory: 384 GB
* Drives: 6x Micron 9300 drives
* Network: Dual 100 Gbps Ethernet
* 19 dedicated cores for WEKA (12 compute, 6 drives, 1 frontend)

#### **SuperMicro clients**

* SYS-2029BT-HNR / X11DPT-B servers; 8 clients were used for aggregated results
* OS: CentOS Linux release 7.8.2003
* CPU: 24/48 Threads (Intel Xeon Gold 6126 CPU @ 2.60GHz)
* Memory: 192 GB
* Network: Dual 100 Gbps Ethernet
* 6 frontend cores
* DPDK networking
* Mount options: system defaults


# Manage object stores

This page provides an overview about managing object stores.

Object stores in WEKA are optional external storage media, complementing SSD storage with a more cost-effective solution. This allows for the strategic allocation of resources, with object stores accommodating warm data (infrequently accessed) and SSDs handling hot data (frequently accessed).

In WEKA, object store buckets can be distributed across different physical object stores. However, to ensure optimal Quality of Service (QoS), a crucial mapping between the bucket and the physical object store is required.

WEKA treats object stores as physical entities, either on-premises or in the cloud, grouping multiple object store buckets. These buckets can be categorized as either local (used for tiering and snapshots) or remote (exclusively for snapshots). An object-store bucket must be added to an object store with the same type and remain inaccessible to other applications.

While a single object store bucket can potentially serve different filesystems and multiple WEKA systems, it is advisable to dedicate each bucket to a specific filesystem. For instance, if managing three-tiered file systems, assigning a dedicated local object storage bucket to each file system is recommended.

For each filesystem, users can attach up to three object store buckets:

* A local object store bucket for tiering and snapshots.
* A second local object store bucket for additional tiering and snapshots. Note that adding a second local bucket renders the first local bucket read-only.
* A remote object store bucket exclusively for snapshots.

{% hint style="info" %}
Remote object store buckets employ a write-once-delete-never approach to snapshot uploads. This means the bucket will only grow in size over time, even if the snapshots uploaded to it are deleted from the filesystem.
{% endhint %}

Multiple object store buckets offer flexibility for various use cases, including:

* Migrating to different local object stores when detaching a read-only bucket from a filesystem tiered to two local object store buckets.
* Scaling object store capacity.
* Increasing total tiering capacity for filesystems.
* Backing up data in a remote site.

In cloud environments, users can employ cloud lifecycle policies to transition storage tiers or classes. For example, in AWS, users can move objects from the S3 standard storage class to the S3 intelligent tiering storage class for long-term retention using the AWS lifecycle policy.

{% hint style="danger" %}
**Warning: Do not modify WEKA-managed object store data**

WEKA manages data in its own internal structures and automatically handles deduplication between live tiered data and filesystem snapshots stored in the object store.

Do not attempt to manually manage, delete, or apply lifecycle policies to any data that WEKA uploads to the object store.

This includes policies that delete or age-out data objects. Interfering with WEKA-managed data can result in irreversible data loss, including loss of live filesystem data.
{% endhint %}


# Manage object stores using the GUI

This page describes how to view and manage object stores using the GUI.

Using the GUI, you can perform the following actions:

* [Edit the default object stores](#edit-the-default-object-stores)
* [Add an object store bucket](#add-an-object-store-bucket)
* [View object store buckets](#view-object-store-buckets)
* [Edit an object store bucket](#edit-an-object-store-bucket)
* [Show recent operations of an object store bucket](#show-recent-operations-of-an-object-store-bucket)
* [Delete an object store bucket](#delete-an-object-store-bucket)

## Edit the default object stores <a href="#edit-the-default-object-stores" id="edit-the-default-object-stores"></a>

Object store buckets can reside in different physical object stores. To achieve good QoS between the buckets, WEKA requires mapping the buckets to the physical object store.

You can edit the default local and remote object stores to meet your connection demands. When you add an object store bucket, you apply the relevant object store to it.

Editing the default object store provides you with the following additional advantages:

* Set restrictions on downloads from a remote object store.\
  For on-premises systems where the remote bucket is in the cloud, to reduce the cost, you set a very low bandwidth for downloading from a remote bucket.
* Ease of adding new buckets.\
  You can set the connection parameters on the object store level and, if not specified differently, automatically use the default settings for the buckets you add.

**Procedure**

1. From the menu, select **Manage > Object Stores**.
2. On the left, select the pencil icon near the default object store you want to edit.
3. On the **Edit Object Store** dialog, select the type of object store, and update the relevant parameters. Select one of the following tabs according to the object store type you choose.\
   For details, see the parameter descriptions in the [Add an object store bucket](#add-an-object-store-bucket) topic.

{% tabs %}
{% tab title="AWS" %}
It is not mandatory to set the Access Key and Secret Key in the **Edit Object Store** dialog in AWS. The AWS object store type is accessed from the WEKA EC2 instances to the object store and granted by the IAM roles assigned to the instances.

If you select **Enable AssumeRole API**, set also the **Role ARN** and **Role Session Name**. For details, see the [Add an object store bucket](#add-an-object-store-bucket) topic.

<div data-with-frame="true"><figure><img src="/files/DgX1sGg68xyGGqAKsDOI" alt=""><figcaption><p>Edit local default object store for AWS</p></figcaption></figure></div>
{% endtab %}

{% tab title="GCP" %}
It is not mandatory to set the Access Key and Secret Key in the **Edit Object Store** dialog in GCP. Google Cloud Storage is accessed using a service account attached to each Compute Engine Instance that is running WEKA software, provided that the service account has the required permissions granted by the IAM role (`storage.admin` for creating buckets. `storage.objectAdmin` for using an existing bucket ).

<div data-with-frame="true"><figure><img src="/files/FSbcTayNVJd4ROWfUMxW" alt=""><figcaption><p>Edit local default object store for GCP</p></figcaption></figure></div>
{% endtab %}

{% tab title="Azure" %}

<div data-with-frame="true"><figure><img src="/files/a0qkDSL5e9n8MndS5UxF" alt=""><figcaption><p>Edit local default object store for Azure</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}

## Add an object store bucket <a href="#add-an-object-store-bucket" id="add-an-object-store-bucket"></a>

Add object store buckets to be used for tiering or snapshots.

**Procedure**

1. From the menu, select **Manage > Object Stores**.
2. Select the **+Create** button.

<div data-with-frame="true"><img src="/files/vb5xsPHC5RqZGSe6ew2z" alt="Create object store bucket"></div>

3. In the **Create Object Store Bucket** dialog, set the following:
   * **Name**: Enter a meaningful name for the bucket.
   * **Object Store**: Select the location of the object store. For tiering and snapshots, select the local object store. For snapshots only, select the remote object store.
   * **Type**: Select the type of object store: AWS, AZURE, or OTHER (for GCP and others).
   * **Buckets Default Parameters**: Select one of the following tabs according to the object store type you choose.

{% tabs %}
{% tab title="AWS" %}
WEKA supports the following options for creating AWS S3 buckets:

* AWS S3 bucket creation for WEKA cluster on EC2.
* AWS S3 bucket creation for WEKA cluster not on EC2 using STS[^1].

Set the following:

1. **Protocol and Port:** Select the protocol to use when connecting to the bucket.
2. **Bucket:** Set the name of the bucket to store and access data.
3. **Region:** Set the region assigned to work with.
4. **For AWS S3 bucket creation for WEKA cluster on EC2:**\
   If the WEKA EC2 instances have the required permissions granted by the IAM role, then it is not required to provide the Access Key and Secret Key. Otherwise, set the Access Key and Secret Key of the user granted with read/write access to the bucket.
5. **For AWS S3 bucket creation for WEKA cluster not on EC2 using STS:**
   * Select **Enable AssumeRole API**.
   * **Role ARN:** Set the Amazon Resource Name (ARN) to assume. The ARN must have the equivalent permissions defined in the IAM role for S3 access. See [IAM role created in the template](broken://pages/-L7TzTC5r8BR5kqD5J-u#iam-role-created-in-the-template).
   * **Role Session Name:** Set a unique identifier[^2] for the assumed role session.
   * **Session Duration:** Set the duration of the temporary security credentials in seconds.

     Possible values: 900 - 43200 (default 3600).
   * **Access Key and Secret Key:** Set the keys of the user granted with the AssumeRole permissions.
6. **Advanced settings:**
   * **Download Bandwidth**: Object store download bandwidth limitation per core (Mbps).
   * **Upload Bandwidth**: Object store upload bandwidth limitation per core (Mbps).
   * **Max concurrent Downloads**: Maximum number of downloads concurrently performed on this object store in a single IO node.
   * **Max concurrent Uploads**: Maximum number of uploads concurrently performed on this object store in a single IO node.
   * **Max concurrent Removals**: Maximum number of removals concurrently performed on this object store in a single IO node.
   * **Enable Upload Tags**: Enable tagging of uploaded objects. For details, see [object-tagging](broken://pages/-M4D3-jpP94VjWGvg4Am#object-tagging).
   * **Data Storage Class**: Configurable Amazon S3 storage classes, allowing users to optimize storage based on cost and access needs. Supports STANDARD, REDUCED\_REDUNDANCY, STANDARD\_IA, ONEZONE\_IA, INTELLIGENT\_TIERING, OUTPOSTS, GLACIER\_IR, and EXPRESS\_ONEZONE. For details, For details, see the documentation for Amazon S3 Storage Classes.
   * **Metadata Storage Class:** Configurable Amazon S3 storage classes for metadata. Supports STANDARD, REDUCED\_REDUNDANCY, STANDARD\_IA, ONEZONE\_IA, INTELLIGENT\_TIERING, OUTPOSTS, GLACIER\_IR, and EXPRESS\_ONEZONE.

<div data-with-frame="true"><figure><img src="/files/JX1aJ1vWYnuPhCx6VRGT" alt=""><figcaption><p>AWS S3 bucket creation for WEKA cluster on EC2</p></figcaption></figure></div>
{% endtab %}

{% tab title="GCP" %}
Set the following:

* **Protocol and Port:** Select the protocol and port to use when connecting to the bucket.
* **Hostname:** Set the DNS name (or IP address) of the bucket entry point.
* **Bucket:** Set the name of the bucket to store and access data.
* **Auth Method:** Select the authentication method to connect to the bucket.
* **Region:** Set the region assigned to work with (usually you can leave it empty).
* **Access Key and Secret Key:** If the service account has the required permissions granted by the IAM role, then it is not required to provide the Access Key and Secret Key. If the WEKA cluster is not running on GCP instances then the Access Key and Secret Key are required.
* **Advanced settings:**
  * **Download Bandwidth**: Object store download bandwidth limitation per core (Mbps).
  * **Upload Bandwidth**: Object store upload bandwidth limitation per core (Mbps).
  * **Max concurrent Downloads**: Maximum number of downloads concurrently performed on this object store in a single IO node.
  * **Max concurrent Uploads**: Maximum number of uploads concurrently performed on this object store in a single IO node.
  * **Max concurrent Removals**: Maximum number of removals concurrently performed on this object store in a single IO node.
  * **Enable Upload Tags**: Enable tagging of uploaded objects. For details, see [object-tagging](broken://pages/-M4D3-jpP94VjWGvg4Am#object-tagging).

<div data-with-frame="true"><figure><img src="/files/i9OO1vSF4wxT9gMP3G2Y" alt=""><figcaption><p>GCP S3 bucket creation</p></figcaption></figure></div>
{% endtab %}

{% tab title="Azure" %}
Set the following:

1. **Protocol and Port:** Select the protocol and port to use when connecting to the bucket.
2. **Hostname:** Set the DNS name (or IP address) of the bucket entry point.
3. **Bucket:** Set the name of the bucket to store and access data.
4. **Auth Method:** Select the authentication method to connect to the bucket.
5. **Access Key and Secret Key:** Set the the Access Key and Secret Key of the user granted with read/write access to the bucket.
6. **Advanced settings:**
   * **Download Bandwidth**: Object store download bandwidth limitation per core (Mbps).
   * **Upload Bandwidth**: Object store upload bandwidth limitation per core (Mbps).
   * **Max concurrent Downloads**: Maximum number of downloads concurrently performed on this object store in a single IO node.
   * **Max concurrent Uploads**: Maximum number of uploads concurrently performed on this object store in a single IO node.
   * **Max concurrent Removals**: Maximum number of removals concurrently performed on this object store in a single IO node.
   * **Enable Upload Tags**: Enable tagging of uploaded objects. For details, see [object-tagging](broken://pages/-M4D3-jpP94VjWGvg4Am#object-tagging).
   * **Data Storage Class:** Configurable Azure access storage tier, allowing users to optimize storage based on cost and access needs. Supports HOT, COOL, and COLD. For details, see the documentation for Azure Access tiers for blob data.
   * **Metadata Storage Class:** Configurable Azure access storage tier for metadata. Supports HOT, COOL, and COLD.

<div data-with-frame="true"><figure><img src="/files/ETi4EquJ02SLU1xZLHrT" alt=""><figcaption><p>Azure S3 bucket creation</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}

4. To validate the connection to the object store bucket, select **Validate**.
5. Select **Create**.

{% hint style="info" %}
If an error message about the object store bucket configuration appears, to save the configuration, select **Create Anyway**.
{% endhint %}

## View object store buckets <a href="#view-object-store-buckets" id="view-object-store-buckets"></a>

The object store buckets are displayed on the **Object Stores** page. Each object store indicates the status, bucket name, protocol (HTTP/HTTPS), port, region, object store location (local or remote), authentication method, and error information (if it exists).

**Procedure**

1. From the menu, select **Manage > Object Stores**.

The following example shows two object store buckets.

<div data-with-frame="true"><img src="/files/WM45EHPVFuUWQLfwa7Tx" alt="View object store buckets"></div>

## Edit an object store bucket <a href="#edit-an-object-store-bucket" id="edit-an-object-store-bucket"></a>

You can modify the object store bucket parameters according to your demand changes.

**Procedure**

1. From the menu, select **Manage > Object Stores**.
2. Select the three dots on the right of the object store you want to modify and select **Edit**.

<div data-with-frame="true"><img src="/files/A4rpTqJgPg4MPo3VzCOV" alt="Edit an object store bucket"></div>

3. In the Edit Object Store Bucket dialog, modify the details, and select **Update**.

<div data-with-frame="true"><img src="/files/eH2IPGtmzPBz3215eXxY" alt="Edit an object store bucket"></div>

## Show recent operations of an object store bucket

For active object store buckets connected to filesystems, the system tracks this activity and provides details about each activity on the Bucket Operations page.

The details include the operation type (download or upload), start time, execution time, previous attempts results, cURL errors, and more.

**Procedure**

1. From the menu, select **Manage > Object Stores**.
2. Select the three dots on the right of the object store bucket you want to show its recent operation, and select **Show Recent Operations**.

<div data-with-frame="true"><figure><img src="/files/g3zrI0ZvfD8HaahiyKPp" alt=""><figcaption><p>Show recent operations of an object store bucket</p></figcaption></figure></div>

The recent operations page for the selected object store bucket appears. To focus on specific operations, you can sort the columns and use the filters that appear on the top of the columns.

<div data-with-frame="true"><figure><img src="/files/vsxR1lrUyqXM3cdkPv7y" alt=""><figcaption><p>Bucket Operations page</p></figcaption></figure></div>

## Delete an object store bucket

You can delete an object store bucket if it is no longer required. The data in the object store remains intact.

**Procedure**

1. From the menu, select **Manage > Object Stores**.
2. Select the three dots on the right of the object store bucket you want to delete, and select **Remove**.
3. To confirm the object store bucket deletion, select **Yes**.

[^1]: WEKA supports the AWS Security Token Service (STS) that enables you to request temporary, limited-privilege credentials for users using the [AssumeRole](https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html) API.

[^2]: The length must be between 2 and 64 characters. Allowed characters include alphanumeric characters (upper and lower case), underscore (\_), equal sign (=), comma (,), period (.), at symbol (@), and hyphen (-). Space is not allowed.


# Manage object stores using the CLI

This page describes how to view and manage object stores using the CLI.

Using the CLI, you can perform the following actions:

* [View object stores](#view-object-stores)
* [Edit an object store](#edit-an-object-store)
* [Add an object store](#add-an-object-store-bucket)
* [View object store buckets](#view-object-store-buckets)
* [Add an object store bucket](#add-an-object-store-bucket)
* [Edit an object store bucket](#edit-an-object-store-bucket)
* [List recent operations of an object store bucket](#show-recent-operations-of-an-object-store-bucket)
* [Delete an object store bucket](#delete-an-object-store-bucket)

## View object stores

**Command:** `weka fs tier obs`

Use this command to view information on all the object stores configured to the WEKA system.

{% hint style="info" %}
Using the GUI, only object store buckets are present. Adding an object store bucket only adds to the present `local` or `remote` object store. If more than one is present (such as during the time recovering from a remote snapshot), use the CLI.
{% endhint %}

## Edit an object store

**Command:** `weka fs tier obs update`

Use the following command line to edit an object store:

`weka fs tier obs update <name> [--new-name new-name] [--site site] [--hostname=<hostname>] [--port=<port>] [--auth-method=<auth-method>] [--region=<region>] [--access-key-id=<access-key-id>] [--secret-key=<secret-key>] [--protocol=<protocol>] [--bandwidth=<bandwidth>] [--download-bandwidth=<download-bandwidth>] [--upload-bandwidth=<upload-bandwidth>] [--remove-bandwidth=<remove-bandwidth>] [--max-concurrent-downloads=<max-concurrent-downloads>] [--max-concurrent-uploads=<max-concurrent-uploads>] [--max-concurrent-removals=<max-concurrent-removals>] [--enable-upload-tags=<enable-upload-tags>]`

**Parameters**

<table><thead><tr><th width="293">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code> *</td><td>Name of the object store to create.</td></tr><tr><td><code>new-name</code></td><td>New name for the object store.</td></tr><tr><td><code>site</code></td><td>Site location of the object store.<br>Possible values:<br><code>local</code> - for tiering+snapshots<br><code>remote</code> - for snapshots only</td></tr><tr><td><code>hostname</code></td><td>Object store host identifier (hostname or IP address) to use as a default for added buckets.</td></tr><tr><td><code>port</code></td><td>Object store port, to be used as a default for added buckets.</td></tr><tr><td><code>auth-method</code></td><td>Authentication method to use as a default for added buckets.<br>Possible values: <code>None</code>,<code>AWSSignature2</code>,<code>AWSSignature4</code></td></tr><tr><td><code>region</code></td><td>Region name to use as a default for added buckets.</td></tr><tr><td><code>access-key-id</code></td><td>Object store access key ID to use as a default for added buckets.</td></tr><tr><td><code>secret-key</code></td><td>Object store secret key to use as a default for added buckets.</td></tr><tr><td><code>protocol</code></td><td>Protocol type to use as a default for added buckets.<br>Possible values: <code>HTTP</code>,<code>HTTPS</code>,<code>HTTPS_UNVERIFIED</code></td></tr><tr><td><code>bandwidth</code></td><td>Bandwidth limitation per core (Mbps).</td></tr><tr><td><code>download-bandwidth</code></td><td>Object store download bandwidth limitation per core (Mbps).</td></tr><tr><td><code>upload-bandwidth</code></td><td>Object store upload bandwidth limitation per core (Mbps).</td></tr><tr><td><code>remove-bandwidth</code></td><td>A bandwidth (Mbps) to limit the throughput of delete requests sent to the object store.<br>Setting a bandwidth equal to or lower than the object store deletion throughput prevents an increase in the object store deletions queue.</td></tr><tr><td><code>max-concurrent-downloads</code></td><td>Maximum number of downloads concurrently performed on this object store in a single IO node.<br>Possible values: <code>1</code>-<code>64</code></td></tr><tr><td><code>max-concurrent-uploads</code></td><td>Maximum number of uploads concurrently performed on this object store in a single IO node.<br>Possible values: <code>1</code>-<code>64</code></td></tr><tr><td><code>max-concurrent-removals</code></td><td>Maximum number of removals concurrently performed on this object store in a single IO node.<br>Possible values: <code>1</code>-<code>64</code></td></tr><tr><td><code>enable-upload-tags</code></td><td>Determines whether to enable <a href="/pages/-M4D3-jpP94VjWGvg4Am#object-tagging">object-tagging</a> or not. To use as a default for added buckets.<br>Possible values: <code>true</code>,<code>false</code></td></tr></tbody></table>

## View object store buckets

**Command:** `weka fs tier s3`

Use this command to view information on all the object store buckets configured to the WEKA system.

## Add an object store bucket

**Command:** `weka fs tier s3 add`

Use the following command line to add an S3 object store:

`weka fs tier s3 add <name> [--site site] [--obs-name obs-name] [--hostname=<hostname>] [--port=<port> [--bucket=<bucket>] [--auth-method=<auth-method>] [--region=<region>] [--access-key-id=<access-key-id>] [--secret-key=<secret-key>] [--protocol=<protocol>] [--bandwidth=<bandwidth>] [--download-bandwidth=<download-bandwidth>] [--remove-bandwidth=<remove-bandwidth>] [--upload-bandwidth=<upload-bandwidth>] [--errors-timeout=<errors-timeout>] [--prefetch-mib=<prefetch-mib>] [--enable-upload-tags=<enable-upload-tags>] [--max-concurrent-downloads=<max-concurrent-downloads>] [--max-concurrent-uploads=<max-concurrent-uploads>] [--max-concurrent-removals=<max-concurrent-removals>] [--max-extents-in-data-blob=<max-extents-in-data-blob>] [--max-data-blob-size=<max-data-blob-size>] [--enable-upload-tags enable-upload-tags] [--data-storage-class data-storage-class] [--metadata-storage-class metadata-storage-class][--sts-operation-type=<sts-operation-type>] [--sts-role-arn=<sts-role-arn>] [--sts-role-session-name=<sts-role-session-name>] [--sts-session-duration=<sts-session-duration>]`

**Parameters**

<table><thead><tr><th width="236">Name</th><th width="337">Description</th><th>Default</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the object store to edit.</td><td>​</td></tr><tr><td><code>site</code></td><td><code>local</code> - for tiering+snapshots,<br><code>remote</code> - for snapshots only.<br>It must be the same as the object store site it is added to <code>(obs-name)</code>.</td><td><code>local</code></td></tr><tr><td><code>obs-name</code></td><td>Name of the existing object store to add this object store bucket to.</td><td>If there is only one object store of type mentioned in <code>site</code> it is chosen automatically</td></tr><tr><td><code>hostname</code> *</td><td>Object store host identifier or IP.<br>Mandatory, if not specified at the object store level.</td><td>The <code>hostname</code> specified in <code>obs-name</code> if present</td></tr><tr><td><code>port</code></td><td>A valid object store port.</td><td>The <code>port</code> specified in <code>obs-name</code> if present, otherwise 80</td></tr><tr><td><code>bucket</code></td><td>A valid object store bucket name.</td><td></td></tr><tr><td><code>auth-method</code> *</td><td>Authentication method.<br>Possible values: <code>None</code>, <code>AWSSignature2</code>, <code>AWSSignature4</code>.<br>Mandatory, if not specified in the object store level .</td><td>The <code>auth-method</code> specified in <code>obs-name</code> if present</td></tr><tr><td><code>region</code> *</td><td>Region name.<br>Mandatory, if not specified in the object store level .</td><td>The <code>region</code> specified in <code>obs-name</code> if present</td></tr><tr><td><code>access-key-id</code> *</td><td>Object store bucket access key ID.<br>Mandatory, if not specified in the object store level (can be left empty when using IAM role in AWS or GCP).</td><td>The <code>access-key-id</code> specified in <code>obs-name</code> if present</td></tr><tr><td><code>secret-key</code> *</td><td>Object store bucket secret key.<br>Mandatory, if not specified in the object store level (can be left empty when using IAM role in AWS or GCP).</td><td>The <code>secret-key</code> specified in <code>obs-name</code> if present</td></tr><tr><td><code>protocol</code></td><td>Protocol type to be used.<br>Possible values: <code>HTTP</code>, <code>HTTPS</code> or <code>HTTPS_UNVERIFIED</code>.</td><td>The <code>protocol</code> specified in <code>obs-name</code> if present, otherwise<code>HTTP</code></td></tr><tr><td><code>bandwidth</code></td><td>Bucket bandwidth limitation per core (Mbps).</td><td></td></tr><tr><td><code>download-bandwidth</code></td><td>Bucket download bandwidth limitation per core (Mbps)</td><td></td></tr><tr><td><code>upload-bandwidth</code></td><td>Bucket upload bandwidth limitation per core (Mbps)</td><td></td></tr><tr><td><code>remove-bandwidth</code></td><td>A bandwidth (Mbps) to limit the throughput of delete requests sent to the object store.<br>Setting a bandwidth equal to or lower than the object store deletion throughput prevents an increase in the object store deletions queue.</td><td></td></tr><tr><td><code>errors-timeout</code></td><td>If the object store link is down longer than this timeout period, all IOs that need data return an error.<br>Possible values: <code>1m</code>-<code>15m</code>, or <code>60s</code>-<code>900s</code>.<br>For example, <code>300s</code>.</td><td><code>300s</code></td></tr><tr><td><code>prefetch-mib</code></td><td>The data size (MiB) to prefetch when reading a whole MiB on the object store.</td><td><code>128</code></td></tr><tr><td><code>enable-upload-tags</code></td><td>Whether to enable <a href="/pages/-M4D3-jpP94VjWGvg4Am#object-tagging">object-tagging</a> or not.<br>Possible values: <code>true</code> or <code>false</code></td><td><code>false</code></td></tr><tr><td><code>max-concurrent-downloads</code></td><td><p>Maximum number of downloads we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p></td><td></td></tr><tr><td><code>max-concurrent-uploads</code></td><td><p>Maximum number of uploads we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p></td><td></td></tr><tr><td><code>max-concurrent-removals</code></td><td><p>Maximum number of removals we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p></td><td></td></tr><tr><td><code>max-extents-in-data-blob</code></td><td>Maximum number of extents' data to upload to an object store data blob.</td><td></td></tr><tr><td><code>max-data-blob-size</code></td><td><p>Maximum size to upload to an object store data blob.</p><p>Format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB.</p></td><td></td></tr><tr><td><code>enable-upload-tags</code></td><td>Enable tagging of uploaded objects. For details, see <a href="/pages/-M4D3-jpP94VjWGvg4Am#object-tagging">object-tagging</a>.</td><td></td></tr><tr><td><code>data-storage-class</code></td><td><p><strong>AWS</strong></p><p>Configurable Amazon S3 storage classes, allowing users to optimize storage based on cost and access needs. Supports STANDARD, REDUCED_REDUNDANCY, STANDARD_IA, ONEZONE_IA, INTELLIGENT_TIERING, OUTPOSTS, GLACIER_IR, and EXPRESS_ONEZONE. For details, see the documentation for Amazon S3 Storage Classes.<br><strong>Azure</strong><br>Configurable Azure access storage tier, allowing users to optimize storage based on cost and access needs. Supports HOT, COOL, and COLD. For details, see the documentation for Azure Access tiers for blob data.</p></td><td></td></tr><tr><td><code>metadata-storage-class</code></td><td><strong>AWS</strong><br>Configurable storage classes for the metadata on AWS.<br><strong>Azure</strong><br>Configurable Azure access storage tier for metadata. Supports HOT, COOL, and COLD.</td><td></td></tr><tr><td><code>sts-operation-type</code></td><td><p>AWS <a data-footnote-ref href="#user-content-fn-1">STS</a> operation type to use.</p><p>Possible values: <code>assume_role</code> or <code>none</code></p></td><td><code>none</code></td></tr><tr><td><code>sts-role-arn</code></td><td>The Amazon Resource Name (ARN) of the role to assume. Mandatory when setting <code>sts-operation</code> to <code>assume_role</code>.</td><td></td></tr><tr><td><code>sts-role-session</code></td><td>A unique identifier for the assumed role session.<br>The length must be between 2 and 64 characters. Allowed characters include alphanumeric characters (upper and lower case), underscore (_), equal sign (=), comma (,), period (.), at symbol (@), and hyphen (-). Space is not allowed.</td><td></td></tr><tr><td><code>sts-session-duration</code></td><td><p>The duration of the temporary security credentials in seconds.</p><p>Possible values: <code>900</code> - <code>43200</code>.</p></td><td><code>3600</code></td></tr></tbody></table>

{% hint style="info" %}
When using the CLI, by default a misconfigured object store are not created. To create an object store even when it is misconfigured, use the `--skip-verification` option.
{% endhint %}

{% hint style="warning" %}
The `max-concurrent` settings are applied per WEKA compute process and the minimum setting of all object stores is applied.
{% endhint %}

{% hint style="success" %}
When you create the object store bucket in AWS, to use the storage classes: S3 Intelligent-Tiering, S3 Standard-IA, S3 One Zone-IA, and S3 Glacier Instant Retrieval, do the following:

1. Create the bucket in S3 Standard.
2. Create an AWS lifecycle policy to transition objects to these storage classes.
3. Make the relevant changes and click **Update** to update the object store bucket.
   {% endhint %}

## Edit an object store bucket

**Command:** `weka fs tier s3 update`

Use the following command line to edit an object store bucket:

`weka fs tier s3 update <name> [--new-name=<new-name>] [--new-obs-name new-obs-name] [--hostname=<hostname>] [--port=<port> [--bucket=<bucket>] [--auth-method=<auth-method>] [--region=<region>] [--access-key-id=<access-key-id>] [--secret-key=<secret-key>] [--protocol=<protocol>] [--bandwidth=<bandwidth>] [--download-bandwidth=<download-bandwidth>] [--upload-bandwidth=<upload-bandwidth>] [--remove-bandwidth=<remove-bandwidth>] [--errors-timeout=<errors-timeout>] [--prefetch-mib=<prefetch-mib>] [--enable-upload-tags=<enable-upload-tags>] [--max-concurrent-downloads=<max-concurrent-downloads>] [--max-concurrent-uploads=<max-concurrent-uploads>] [--max-concurrent-removals=<max-concurrent-removals>] [--max-extents-in-data-blob=<max-extents-in-data-blob>] [--max-data-blob-size=<max-data-blob-size>] [--sts-operation-type=<sts-operation-type>] [--sts-role-arn=<sts-role-arn>] [--sts-role-session-name=<sts-role-session-name>] [--sts-session-duration=<sts-session-duration>]`

**Parameters**

| Name                       | Value                                                                                                                                                                                                                                                                                               |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`\*                   | A valid name of the object store bucket to edit.                                                                                                                                                                                                                                                    |
| `new-name`                 | New name for the object store bucket                                                                                                                                                                                                                                                                |
| `new-obs-name`             | A new object store name to add this object store bucket to. It must be an existing object store with the same `site` value.                                                                                                                                                                         |
| `hostname`                 | Object store host identifier or IP.                                                                                                                                                                                                                                                                 |
| `port`                     | A valid object store port                                                                                                                                                                                                                                                                           |
| `bucket`                   | A valid object store bucket name                                                                                                                                                                                                                                                                    |
| `auth-method`              | <p>Authentication method.<br>Possible values: <code>None</code>, <code>AWSSignature2</code> or <code>AWSSignature4</code></p>                                                                                                                                                                       |
| `region`                   | Region name                                                                                                                                                                                                                                                                                         |
| `access-key-id`            | Object store bucket access key ID                                                                                                                                                                                                                                                                   |
| `secret-key`               | Object store bucket secret key                                                                                                                                                                                                                                                                      |
| `protocol`                 | <p>Protocol type to be used.<br>Possible values: <code>HTTP</code>, <code>HTTPS</code> or <code>HTTPS\_UNVERIFIED</code></p>                                                                                                                                                                        |
| `bandwidth`                | Bandwidth limitation per core (Mbps)                                                                                                                                                                                                                                                                |
| `download-bandwidth`       | Bucket download bandwidth limitation per core (Mbps)                                                                                                                                                                                                                                                |
| `upload-bandwidth`         | Bucket upload bandwidth limitation per core (Mbps)                                                                                                                                                                                                                                                  |
| `remove-bandwidth`         | <p>A bandwidth (Mbps) to limit the throughput of delete requests sent to the object store.<br>Setting a bandwidth equal to or lower than the object store deletion throughput prevents an increase in the object store deletions queue.</p>                                                         |
| `errors-timeout`           | <p>If the object store link is down longer than this timeout period, all IOs that need data return an error.<br>Possible values: <code>1m</code>-<code>15m</code>, or <code>60s</code>-<code>900s</code>.<br>For example, <code>300s</code>.</p>                                                    |
| `prefetch-mib`             | The data size in MiB to prefetch when reading a whole MiB on the object store                                                                                                                                                                                                                       |
| `enable-upload-tags`       | <p>Whether to enable <a href="/pages/-M4D3-jpP94VjWGvg4Am#object-tagging">object-tagging</a> or not.<br>Possible values: <code>true</code>, <code>false</code></p>                                                                                                                                  |
| `max-concurrent-downloads` | <p>Maximum number of downloads we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p>                                                                                                                                          |
| `max-concurrent-uploads`   | <p>Maximum number of uploads we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p>                                                                                                                                            |
| `max-concurrent-removals`  | <p>Maximum number of removals we concurrently perform on this object store in a single IO node.</p><p>Possible values: <code>1</code>-<code>64</code></p>                                                                                                                                           |
| `max-extents-in-data-blob` | Maximum number of extents' data to upload to an object store data blob.                                                                                                                                                                                                                             |
| `max-data-blob-size`       | <p>Maximum size to upload to an object store data blob.</p><p>Format: capacity in decimal or binary units: 1B, 1KB, 1MB, 1GB, 1TB, 1PB, 1EB, 1KiB, 1MiB, 1GiB, 1TiB, 1PiB, 1EiB.</p>                                                                                                                |
| `sts-operation-type`       | <p>AWS <a data-footnote-ref href="#user-content-fn-1">STS</a> operation type to use.</p><p>Possible values: <code>assume\_role</code> or <code>none</code></p>                                                                                                                                      |
| `sts-role-arn`             | The Amazon Resource Name (ARN) of the role to assume. Mandatory when setting `sts-operation` to `assume_role`.                                                                                                                                                                                      |
| `sts-role-session`         | <p>A unique identifier for the assumed role session.<br>The length must be between 2 and 64 characters. Allowed characters include alphanumeric characters (upper and lower case), underscore (\_), equal sign (=), comma (,), period (.), at symbol (@), and hyphen (-). Space is not allowed.</p> |
| `sts-session-duration`     | <p>The duration of the temporary security credentials in seconds.</p><p>Possible values: <code>900</code> - <code>43200</code>.</p>                                                                                                                                                                 |

## List recent operations of an object store bucket

**Command:** `weka fs tier ops`

Use the following command line to list the recent operations running on an object store:

`weka fs tier ops <name> [--format format] [--output output]...[--sort sort]...[--filter filter]...[--raw-units] [--UTC] [--no-header] [--verbose]`

**Parameters**

| Name        | Value                                                                                                                                                                                                                                                                                                                                                                     | Default     |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| `name`\*    | A valid object store bucket name to show its recent operations.                                                                                                                                                                                                                                                                                                           | ​           |
| `format`    | <p>Specify the output format.<br>Possible values: <code>view</code>, <code>csv</code>, <code>markdown</code>, <code>json</code>, or <code>oldview</code></p>                                                                                                                                                                                                              | `view`      |
| `output`    | <p>Specify the columns in the output.<br>Possible values:<br><code>node</code>, <code>obsBucket</code>, <code>key</code>, <code>type</code>, <code>execution</code>, <code>phase</code>, <code>previous</code>, <code>start</code>, <code>size</code>, <code>results</code>, <code>errors</code>, <code>lastHTTP</code>, <code>concurrency</code>, <code>inode</code></p> | All columns |
| `sort`      | Specify the column(s) to consider when sorting the output. For the sorting order, ascending or descending, add - or + signs respectively before the column name.                                                                                                                                                                                                          |             |
| `filter`    | Specify the values to filter by in a specific column. Usage: `column1=val1[,column2=val2[,..]]`                                                                                                                                                                                                                                                                           |             |
| `raw-units` | <p>Print values in a readable format of raw units such as bytes and seconds.<br>Possible value examples: <code>1KiB</code> <code>234MiB</code> <code>2GiB</code>.</p>                                                                                                                                                                                                     |             |
| `no-header` | Don't show column headers in the output,                                                                                                                                                                                                                                                                                                                                  |             |
| `verbose`   | Show all columns in the output.                                                                                                                                                                                                                                                                                                                                           |             |

## Delete an object store bucket

**Command:** `weka fs tier s3 delete`

Use the following command line to delete an object store bucket:

`weka fs tier s3 delete <name>`

**Parameters**

<table><thead><tr><th width="197">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>A valid name of the object store bucket to delete.</td></tr></tbody></table>

[^1]: WEKA supports the AWS Security Token Service (STS) that enables you to request temporary, limited-privilege credentials for users using the [AssumeRole](https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html) API.


# Manage filesystem groups

This page provides an overview about managing filesystem groups.

A filesystem group in the WEKA system is used specifically to manage tiering policies for filesystems. It defines key parameters, including the drive retention period and the tiering queue time, which determine how and when data is tiered.

When you add a filesystem, it must be associated with a filesystem group to apply these tiering behaviors. The WEKA system supports up to eight filesystem groups, allowing flexibility in managing tiering policies across different filesystems.

**Related topics**

[Filesystems, object stores, and filesystem groups](/weka-system-overview/filesystems-object-stores-and-filesystem-groups)

[Manage filesystem groups using the GUI](/weka-filesystems-and-object-stores/managing-filesystem-groups/managing-filesystem-groups)

[Manage filesystem groups using the CLI](/weka-filesystems-and-object-stores/managing-filesystem-groups/manage-filesystem-groups-using-the-cli)


# Manage filesystem groups using the GUI

This page describes how to view and manage filesystem groups using the GUI.

Using the GUI, you can perform the following actions:

* [View filesystem groups](#view-filesystem-groups)
* [Add filesystem groups](#add-a-filesystem-group)
* [Edit filesystem groups](#edit-a-filesystem-group)
* [Delete a filesystem group](#delete-a-filesystem-group)

## View filesystem groups

The filesystem groups are displayed on the **Filesystems** page. Each filesystem group indicates the number of filesystems that use it.

**Procedure**

1. From the menu, select **Manage > Filesystems**.

<div data-with-frame="true"><img src="/files/8L0fKby05ImwxyRtnj45" alt="Filesystem groups example"></div>

## Add a filesystem group

A filesystem group is required when adding a filesystem. You can create more filesystem groups if you want to apply a different tiering policy on specific filesystems.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the + sign right to the Filesystem Groups title.
3. In the **Create Filesystem Group** dialog, set the following:
   * **Name:** Set a meaningful name for the filesystem group.
   * **Drive Retention Period**: Set the period for keeping data on the SSD after it is copied to the object store. After this period, the copy of the data is deleted from the SSD.
   * **Tiering Cue**: Set the time to wait after the last update before the data is copied from the SSD and sent to the object store.

<div data-with-frame="true"><img src="/files/bFpljwrq2YwbJiXuB56S" alt="Add a filesystem group"></div>

4. Select **Create**.

**Related topics**

To learn more about the drive retention period and tiering cue, see [Manage data lifecycle for tiered systems](/weka-filesystems-and-object-stores/tiering).

## Edit a filesystem group

You can edit the filesystem group policy according to your system requirements.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the filesystem group you want to edit.
3. Select the pencil sign right to the filesystem group name.
4. In the **Edit Filesystem Group** dialog, update the settings as you need. (See the parameter descriptions in the [Add a filesystem group](#add-a-filesystem-group) topic.)

<div data-with-frame="true"><img src="/files/OngvUrhmqZtuFnlvrFcw" alt="Edit a filesystem group"></div>

5. Select **Update**.

## Delete a filesystem group

You can delete a filesystem group no longer used by any filesystem.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the filesystem group you want to delete.
3. Verify that the filesystem group is not used by any filesystems (indicates 0 filesystems).

<div data-with-frame="true"><img src="/files/dUOLJ8oEydydcm3q0Oc2" alt="Delete a filesystem group"></div>

5. Select the **Remove** icon. In the pop-up message, select **Yes** to delete the filesystem group.


# Manage filesystem groups using the CLI

This page describes how to view and manage filesystem groups using the CLI.

Using the CLI, you can perform the following actions:

* [View filesystem groups](#view-filesystem-groups)
* [Add a filesystem group](#add-a-filesystem-group)
* [Edit a filesystem group](#edit-a-filesystem-group)
* [Remove a filesystem group](#remove-a-filesystem-group)

## **View filesystem groups**

**Command:** `weka fs group`

Use this command to view information on the filesystem groups in the WEKA system.

## Add a filesystem group

**Command:** `weka fs group add`

Use the following command to add a filesystem group:

`weka fs group add <name> [--target-ssd-retention=<target-ssd-retention>] [--start-demote=<start-demote>]`

**Parameters**

| Name                   | Value                                                                                                                                                                                     | Default |
| ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `name`\*               | Set a meaningful name for the filesystem group.                                                                                                                                           | ​       |
| `target-ssd-retention` | <p>The time for keeping data on the SSD after it is copied to the object store. After this period, the copy of the data is deleted from the SSD.<br>Format: 3s, 2h, 4m, 1d, 1d5h, 1w.</p> | 1d      |
| `start-demote`         | <p>The time to wait after the last update before the data is copied from the SSD and sent to the object store.<br>Format: 3s, 2h, 4m, 1d, 1d5h, 1w.</p>                                   | 10s     |

## Edit a filesystem group

**Command:** `weka fs group update`

Use the following command to edit a filesystem group:

`weka fs group update <name> [--new-name=<new-name>] [--target-ssd-retention=<target-ssd-retention>] [--start-demote=<start-demote>]`

**Parameters**

<table><thead><tr><th width="291.43669250645996">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the filesystem group to edit.<br>It must be a valid name.</td></tr><tr><td><code>new-name</code></td><td>New name for the filesystem group.</td></tr><tr><td><code>target-ssd-retention</code></td><td>The time for keeping data on the SSD after it is copied to the object store. After this period, the copy of the data is deleted from the SSD.<br>Format: 3s, 2h, 4m, 1d, 1d5h, 1w.</td></tr><tr><td><code>start-demote</code></td><td>The time to wait after the last update before the data is copied from the SSD and sent to the object store.<br>Format: 3s, 2h, 4m, 1d, 1d5h, 1w.</td></tr></tbody></table>

## Remove a filesystem group

**Command:** `weka fs group remove`

Use the following command line to delete a filesystem group:

`weka fs group remove <name>`

**Parameters**

<table><thead><tr><th width="295">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the filesystem group to delete</td></tr></tbody></table>

**Related topics**

To learn about the tiring policy, see:

[Manage data lifecycle for tiered systems](/weka-filesystems-and-object-stores/tiering)


# Manage filesystems

Filesystem management is an integral part of the successful running and performance of the WEKA system and of overall data lifecycle management.

Managing filesystems in the WEKA system involves overseeing entities that function like conventional on-disk filesystems but distribute data across all servers in the cluster. These filesystems are not tied to specific physical objects and act as root directories with space limitations.

The WEKA system can support up to 1024 filesystems. Effective management ensures optimal resource allocation and performance, including tasks such as creating new filesystems, resizing existing ones, and configuring features like thin provisioning and data reduction.

**Related topics**

[Filesystems, object stores, and filesystem groups](/weka-system-overview/filesystems-object-stores-and-filesystem-groups) (detailed overview)

[Manage filesystems using the GUI](/weka-filesystems-and-object-stores/managing-filesystems/managing-filesystems)

[Manage filesystems using the CLI](/weka-filesystems-and-object-stores/managing-filesystems/managing-filesystems-1)


# Manage filesystems using the GUI

This page describes how to view and manage filesystems using the GUI.

Using the GUI, you can perform the following actions:

* [View filesystems](#view-filesystems)
* [Create a filesystem](#create-a-filesystem)
* [Edit a filesystem](#edit-a-filesystem)
* [Delete a filesystem](#delete-a-filesystem)

## View filesystems

The filesystems are displayed on the **Filesystems** page. Each filesystem indicates the status, tiering, remote backup, encryption, SDD capacity, total capacity, filesystem group, and data reduction details.

**Before you begin**

Ensure a filesystem group is set with the required tiering policy. See [Manage filesystem groups using the GUI](/weka-filesystems-and-object-stores/managing-filesystem-groups/managing-filesystem-groups#add-a-filesystem-group).

**Procedure**

1. From the menu, select **Manage > Filesystems**.

<div data-with-frame="true"><img src="/files/jvtiwQCHf5q2O6oBSl29" alt="View filesystems example"></div>

## Create a filesystem

When deploying a WEKA system on-premises, no filesystem is initially provided. You must create the filesystem and configure its properties, including capacity, group, tiering, thin provisioning, encryption, and required authentication during mounting.

When deploying a WEKA system on a cloud platform (AWS, Azure, or GCP), the WEKA system includes a default filesystem configured to maximum capacity. If your deployment necessitates additional filesystems with varied settings, reduce the provisioned capacity of the default filesystem and create a new filesystem with the desired properties to meet your specific requirements.

**Before you begin**

* Verify that the system has free capacity.
* Verify that a filesystem group is already set.
* If tiering is required, verify that an object store bucket is set.
* If audit logging required, verify that the Audit and Forwarding feature is enabled and configured.
* If encryption is required, verify that a KMS is configured.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the **+Create** button.

<div data-with-frame="true"><img src="/files/FTb3RoK07VZjB4NS6gNG" alt="Create filesystem"></div>

3. In the **Create Filesystem** dialog, set the following:
   * **Name**: Enter a descriptive label for the filesystem, limited to 32 characters and excluding slash (`/`) or backslash (`\`).
   * **Group**: Select the filesystem group that fits your filesystem.
   * **Capacity**: Enter the storage size to provision, or select **Use All** to provision all the free capacity.

<div data-with-frame="true"><figure><img src="/files/9CaFwnC85r2YXHd4Tbhi" alt=""><figcaption><p>Create filesystem</p></figcaption></figure></div>

4. Optional: [**Tiering**](broken://pages/-LxWGVbB9iYC1u6AKg_O#tiering-cue-policy).\
   If tiering is required, and the following conditions are met:

   * An object store bucket is already defined.
   * Data reduction is not enabled.

   Then, enable tiering by selecting the Tiering toggle and specifying the following details:

   * **Object Store Bucket:** Select a predefined object store bucket from the list.
   * **Drive Capacity:** Enter the SSD capacity to provision, or select **Use All** to allocate all available free capacity.
   * **Total Capacity:** Enter the total capacity of the object store bucket, including the drive capacity.

   **Best practice:** Use a 1:4 ratio between the drive capacity and total capacity, as shown in the example below.

   When tiering is enabled, you can also create the file system from an uploaded snapshot. For more information, see the related topics below.

<div data-with-frame="true"><img src="/files/SjE5tT7SHYGkPdudsxPy" alt="Tiering"></div>

5. Optional: **Thin Provision**.\
   If Thin Provision is required, select the toggle button, and set the minimum (guaranteed) and the maximum capacity for the thin provisioned filesystem.\
   The minimum capacity must be less or equal to the available SSD capacity.\
   You can set any maximum capacity, but the available capacity depends on the actual free space of the SSD capacity.\
   Thin provisioning is mandatory when enabling data reduction.

<div data-with-frame="true"><img src="/files/WoCN6XKgqaEC3knpxht9" alt="Thin provisioning"></div>

6. Optional: **Data Reduction**.

   Data reduction can be enabled only when all of the following conditions are met:

   * Filesystem is **thin provisioned**
   * Filesystem is **non-tiered**
   * Filesystem is **unencrypted**
   * Cluster has a **valid data reduction license**

     * The license status can be verified in the cluster settings

     For more details, see the related topics below.

   \
   To enable the Data Reduction, select the toggle button.

<div data-with-frame="true"><figure><img src="/files/hoAyYw5r1s9QooBsly9y" alt=""><figcaption><p>Data reduction</p></figcaption></figure></div>

7. Optional: If **Audit Logging** is required for this filesystem, select the toggle button. When on, the WEKA system Forwards this filesystem's audit logs to a configured events monitoring platform, provided that cluster-wide auditing is also enabled.

{% hint style="info" %}
To use the **Audit Logging** option, ensure the **Audit and Forwarding** feature is enabled and configured. For more information, see [Audit and forwarding management](/operation-guide/audit-and-forwarding-management).
{% endhint %}

8. Optional: If **Encryption** is required and your WEKA system is deployed with a KMS, select the toggle button.
9. Optional: **Required Authentication**.\
   When ON, user authentication is required when mounting to the filesystem. This option is only relevant to a filesystem created in the root organization.\
   Enabling authentication is not allowed for a filesystem hosting NFS client permissions or SMB shares.\
   To authenticate during mount, the user must run the `weka user login` command or use the `auth_token_path` parameter.
10. Select **Save**.

**Related topics**

[Manage filesystem groups](/weka-filesystems-and-object-stores/managing-filesystem-groups)

[Manage object stores](/weka-filesystems-and-object-stores/managing-object-stores)

[Manage KMS](/security/kms-management)

[Licensing overview](/licensing/overview)

[Filesystems, object stores, and filesystem groups](/weka-system-overview/filesystems-object-stores-and-filesystem-groups#data-reduction-in-weka-filesystems)

[Manage Snap-To-Object using the GUI](/weka-filesystems-and-object-stores/snap-to-obj/snap-to-obj#create-a-filesystem-from-an-uploaded-snapshot)

## Edit a filesystem

You can modify the filesystem parameters according to your demand changes over time. The parameters you can modify include filesystem name, capacity, tiering, thin provisioning, and required authentication (but not encryption).

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the three dots on the right of the filesystem you want to modify, and select **Edit**.

<div data-with-frame="true"><img src="/files/E5YduQS5UKMKg880DM6l" alt="Filesystem menu"></div>

3. In the **Edit Filesystem** dialog, modify the parameters according to your requirements. (See the parameter descriptions in the [Add a filesystem](#add-a-filesystem) topic.)

<div data-with-frame="true"><figure><img src="/files/M3t2b31K5Hqt7XUWGyjp" alt=""><figcaption><p>Edit a filesystem</p></figcaption></figure></div>

4. Select **Save**.

## Delete a filesystem

You can delete a filesystem if its data is no longer required. Deleting a filesystem does not delete the data in the tiered object store bucket.

{% hint style="info" %}
If you must also delete the data in the tiered object store bucket, see the [Delete a filesystem](/weka-filesystems-and-object-stores/managing-filesystems/managing-filesystems-1#delete-a-filesystem) topic in the CLI section.
{% endhint %}

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. Select the three dots on the right of the filesystem you want to delete, and select **Remove**.
3. To confirm the filesystem deletion, enter the filesystem name and select **Confirm**.

<div data-with-frame="true"><img src="/files/iX1QP5XIgBpQXDOGiaZs" alt="Delete a filesystem"></div>


# Manage filesystems using the CLI

This page describes how to view and manage filesystems using the CLI.

Using the CLI, you can perform the following actions:

* [View filesystems](#view-filesystems)
* [Add a filesystem](#add-a-filesystem)
* [Add a filesystem with thin-provisioning](#add-a-filesystem-with-thin-provisioning)
* [Edit a filesystem](#edit-a-filesystem)
* [Remove a filesystem](#remove-a-filesystem)
* [Rewrap the filesystem encryption key](#rewrap-the-filesystem-encryption-key)

{% hint style="info" %}
Several parameters in this topic relate to Key Management System (KMS) configuration, which supports both per-filesystem encryption keys and cluster encryption keys. For more information about how KMS integration works and setup guidance, see [Manage KMS](/security/kms-management).
{% endhint %}

## View filesystems

**Command:** `weka fs`

Use this command to view information on the filesystems in the WEKA system.

## Add a filesystem

**Command:** `weka fs add`

Use the following command line to create a filesystem:

`weka fs add <name> <group-name> <total-capacity> [--obs-name <obs-name>] [--ssd-capacity <ssd-capacity>] [--thin-provision-min-ssd <thin-provision-min-ssd>] [--thin-provision-max-ssd <thin-provision-max-ssd>] [--audit-enabled audit-enabled] [--kms-key-identifier kms-key-identifier] [--kms-namespace kms-namespace] [--kms-role-id kms-role-id] [--kms-secret-id kms-secret-id] [--index-enabled index-enabled] [--max-throughput max-throughput] [--max-iops max-iops] [--auth-required auth-required] [--encrypted] [--data-reduction]`

**Parameters**

<table><thead><tr><th width="229.9140625">Name</th><th width="384.859375">Value</th><th>Default</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>A descriptive label for the filesystem, limited to 32 characters and excluding slash (<code>/</code>) or backslash (<code>\</code>).</td><td>​</td></tr><tr><td><code>group-name</code>*</td><td>Name of the filesystem group to which the new filesystem is to be connected.</td><td></td></tr><tr><td><code>total-capacity</code>*</td><td>Total capacity of the new filesystem.<br>Minimum value: 1GiB.</td><td></td></tr><tr><td><code>obs-name</code></td><td>Object store name for tiering.<br>Mandatory for tiered filesystems.</td><td></td></tr><tr><td><code>ssd-capacity</code></td><td><p>Specifies the SSD capacity to allocate for a tiered file system. If this parameter is not specified, the file system is fully pinned to SSD storage.</p><p>When specified, the SSD capacity defines the portion of total capacity that resides on SSD. The recommended best practice is to maintain a 1:4 ratio between the SSD capacity and the total capacity of the file system.</p><p>To create a thin-provisioned file system, use the <code>thin-provision-min-ssd</code> attribute instead.</p></td><td>As set in <code>total-capacity</code></td></tr><tr><td><code>thin-provision-min-ssd</code></td><td>For thin-provisioned filesystems, this is the minimum SSD capacity that is ensured to be always available to this filesystem.<br>Must be set when defining a thin-provisioned filesystem.<br>Minimum value: 1GiB.<br>For details, see <a href="/pages/3dgkHLifLyHWt3bxBSLr#thin-provisioning-in-weka-filesystems">Filesystems, object stores, and filesystem groups</a>.</td><td></td></tr><tr><td><code>thin-provision-max-ssd</code></td><td>For thin-provisioned filesystem, this is the maximum SSD capacity the filesystem can consume.<br>The value cannot exceed the <code>total-capacity</code>.</td><td></td></tr><tr><td><code>audit</code></td><td>Forwards this filesystem's audit logs to a configured events monitoring platform, provided that cluster-wide auditing is also enabled.</td><td></td></tr><tr><td><code>kms-key-identifier</code></td><td>Customize KMS key identifier for this filesystem (only for HashiCorp Vault).</td><td></td></tr><tr><td><code>kms-namespace</code></td><td>Customize KMS namespace for this filesystem (only for HashiCorp Vault).</td><td></td></tr><tr><td><code>kms-role-id</code></td><td>Customize KMS role-id for this filesystem (only for HashiCorp Vault).</td><td></td></tr><tr><td><code>kms-secret-id</code></td><td>Customize KMS secret-id for this filesystem (only for HashiCorp Vault).</td><td></td></tr><tr><td><code>index-enabled</code></td><td>Enable catalog indexing for this filesystem (format: '<code>yes</code>', '<code>no</code>', '<code>true</code>', '<code>false</code>', '<code>on</code>', '<code>off</code>', '<code>y</code>' or '<code>n</code>').</td><td></td></tr><tr><td><code>max-throughput</code></td><td><p>The maximum total throughput allowed for the filesystem per second. Use a number with capacity units in Decimal or Binary: for example, 200GiB or 500GB.<br>For details, see</p><p><a href="/pages/3dgkHLifLyHWt3bxBSLr#quality-of-service-qos">Filesystems, object stores, and filesystem groups</a></p></td><td>0<br>(Unlimited)</td></tr><tr><td><code>max-iops</code></td><td><p>The maximum total I/O operations allowed for the filesystem per second. Use a number without units: for example, 500000.<br>For details, see</p><p><a href="/pages/3dgkHLifLyHWt3bxBSLr#quality-of-service-qos">Filesystems, object stores, and filesystem groups</a></p></td><td>0<br>(Unlimited)</td></tr><tr><td><code>auth-required</code></td><td>Require the mounting user to be authenticated for mounting this filesystem. This flag is only effective in the root organization, users in non-root organizations must be authenticated to perform a mount operation.<br>Format: <code>yes</code> or <code>no</code>.<br>For details, see <a data-mention href="/pages/-L7U3uOF66W0Xu-swyWR">/pages/-L7U3uOF66W0Xu-swyWR</a>.</td><td>No</td></tr><tr><td><code>encrypted</code></td><td>Encryption of filesystem.</td><td>No</td></tr><tr><td><code>data-reduction</code></td><td>Enable data reduction.<br>Data reduction can be enabled only on thin provision, non-tiered, and unencrypted filesystems on a cluster with a valid data reduction license. For details, see <a href="/pages/3dgkHLifLyHWt3bxBSLr#data-reduction-in-weka-filesystems">Filesystems, object stores, and filesystem groups</a>.</td><td>No</td></tr></tbody></table>

{% hint style="info" %}
To create an encrypted filesystem, you must define a KMS.

If a KMS is unavailable for a POC, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team) for guidance.
{% endhint %}

## Add a filesystem with thin-provisioning

When adding a new filesystem, you need unprovisioned SSD space. With thin provisioning, existing filesystems may be using their provisioned SSD space in two ways:

* Actively storing data.
* Holding space available for potential data promotions from object-store.

Even if existing filesystems are tiered, their SSD space might remain occupied due to:

* Continuous new data writes.
* Ongoing data promotions from object-store to SSD tier.

To ensure space for a new filesystem, follow these steps:

1. Use the `weka fs reserve set <ssd-capacity>` CLI command to reserve the required SSD space.
2. Wait for the system to free up sufficient SSD space through either:
   * Automatic data release to object-store.
   * Manual data deletion.
3. Create the new filesystem using the reserved space.

This ensures the new filesystem has its required minimum capacity while maintaining the performance of existing filesystems.

## Edit a filesystem

**Command:** `weka fs update`

Use the following command line to edit an existing filesystem:

`weka fs update <name> [--new-name new-name] [--total-capacity total-capacity] [--ssd-capacity ssd-capacity] [--thin-provision-min-ssd thin-provision-min-ssd] [--thin-provision-max-ssd thin-provision-max-ssd] [--audit-enabled audit-enabled] [--data-reduction data-reduction] [--auth-required auth-required] [--kms-key-identifier kms-key-identifier] [--kms-namespace kms-namespace] [--kms-role-id kms-role-id] [--kms-secret-id kms-secret-id] [--index-enabled index-enabled] [--max-throughput max-throughput] [--max-iops max-iops][--use-cluster-kms-key-identifier]`

**Parameters**

<table><thead><tr><th width="284.95703125">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the filesystem to edit.</td></tr><tr><td><code>new-name</code></td><td>New name for the filesystem.</td></tr><tr><td><code>total-capacity</code></td><td>Total capacity of the edited filesystem.</td></tr><tr><td><code>ssd-capacity</code></td><td>SSD capacity of the edited filesystem.<br>Minimum value: 1GiB.</td></tr><tr><td><code>thin-provision-min-ssd</code></td><td>For thin-provisioned filesystems, this is the minimum SSD capacity that is ensured to be always available to this filesystem.<br>Minimum value: 1GiB.<br>For details, see <a href="/pages/3dgkHLifLyHWt3bxBSLr#thin-provisioning-in-weka-filesystems">Filesystems, object stores, and filesystem groups</a>.</td></tr><tr><td><code>thin-provision-max-ssd</code></td><td>For thin-provisioned filesystem, this is the maximum SSD capacity the filesystem can consume.<br>The value must not exceed the <code>total-capacity</code>.</td></tr><tr><td><code>audit-enabled</code></td><td>Forwards this filesystem's audit logs to a configured events monitoring platform, provided that cluster-wide auditing is also enabled.</td></tr><tr><td><code>data-reduction</code></td><td>Enable data reduction.<br>Data reduction can be enabled only on thin provision, non-tiered, and unencrypted filesystems on a cluster with a valid data reduction license. For details, see <a href="/pages/3dgkHLifLyHWt3bxBSLr#data-reduction-in-weka-filesystems">Filesystems, object stores, and filesystem groups</a>.</td></tr><tr><td><code>auth-required</code></td><td>Determines if mounting the filesystem requires being authenticated to WEKA (<a href="/pages/-L7U3uOF66W0Xu-swyWR#user-log-in">weka user login</a>).<br>Possible values: <code>yes</code> or <code>no</code>.</td></tr><tr><td><code>kms-key-identifier</code></td><td>Customize KMS key identifier for this filesystem (only for HashiCorp Vault).</td></tr><tr><td><code>kms-namespace</code></td><td>Customize KMS namespace for this filesystem (only for HashiCorp Vault).</td></tr><tr><td><code>kms-role-id</code></td><td>Customize KMS role-id for this filesystem (only for HashiCorp Vault).</td></tr><tr><td><code>kms-secret-id</code></td><td>Customize KMS secret-id for this filesystem (only for HashiCorp Vault).</td></tr><tr><td><code>index-enabled</code></td><td>Enable catalog indexing for this filesystem (format: '<code>yes</code>', '<code>no</code>', '<code>true</code>', '<code>false</code>', '<code>on</code>', '<code>off</code>', '<code>y</code>' or '<code>n</code>').</td></tr><tr><td><code>max-throughput</code></td><td>The maximum total throughput allowed for the filesystem per second. Use a number with capacity units in Decimal or Binary: for example, 200GiB or 500GB.</td></tr><tr><td><code>max-iops</code></td><td>The maximum total I/O operations allowed for the filesystem per second. Use a number without units: for example, 500000.</td></tr><tr><td><code>use-cluster-kms-key-identifier</code></td><td>Enable cluster KMS configuration for this filesystem, which removes any custom KMS settings previously applied to it.</td></tr></tbody></table>

## Filesystem QoS using the CLI

Use filesystem QoS parameters to cap per-filesystem throughput and IOPS.

Look for these parameters in both filesystem workflows:

* In [Add a filesystem](#add-a-filesystem), use `--max-throughput` and `--max-iops` when you create a new filesystem.
* In [Edit a filesystem](#edit-a-filesystem), use `--max-throughput` and `--max-iops` to change limits on an existing filesystem.

## Remove a filesystem

**Command:** `weka fs remove`

Use the following command line to remove a filesystem:

`weka fs remove <name> [--purge-from-obs]`

**Parameters**

<table><thead><tr><th>Name</th><th width="377">Value</th><th>Default</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the filesystem to delete.</td><td></td></tr><tr><td><code>purge-from-obs</code></td><td>For a tiered filesystem, if set, all filesystem data is deleted from the object store bucket.</td><td>False</td></tr></tbody></table>

{% hint style="danger" %}
Using `purge-from-obs` removes all data from the object-store. This includes any backup data or snapshots created from this filesystem (if this filesystem has been downloaded from a snapshot of a different filesystem, it will leave the original snapshot data intact).

* If any of the removed snapshots have been (or are) downloaded and used by a different filesystem, that filesystem will stop functioning correctly, data might be unavailable and errors might occur when accessing the data.

It is possible to either un-tier or migrate such a filesystem to a different object store bucket before deleting the snapshots it has downloaded.
{% endhint %}

## Rewrap the filesystem encryption key

**Command:** `weka fs kms-rewrap`

Rewrap operations can be performed per filesystem, enabling each key to be re-encrypted with a new version if there are concerns about key compromise. Use the following command to run this operation:

`weka fs kms-rewrap <name>`

**Parameters**

<table><thead><tr><th width="252">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Filesystem name</td></tr></tbody></table>


# Attach or detach object store buckets

Attach and detach local or remote object store buckets for filesystem tiering and backup.

## Attachment of a local object store bucket to a filesystem

When attaching a local object store bucket to a non-tiered filesystem, the filesystem becomes tiered. Two local object store buckets can be attached to a filesystem, but only the most recently attached bucket is writable.

A local object store bucket is used for both tiering and snapshots. When attaching a new local object store bucket to an already tiered filesystem, the existing local object store bucket becomes read-only. The new object store bucket is read/write.

Multiple local object stores allow a range of use cases. These include migration to different object stores, scaling object store capacity, and increasing total filesystem tiering capacity.

## Detachment of a local object store bucket from a filesystem

Detaching a local object store bucket from a filesystem migrates the filesystem data residing in the object store bucket to the writable object store bucket (if one exists) or to the SSD.

{% hint style="warning" %}
Detaching an object store bucket is irreversible. Attaching the same bucket again is considered as re-attaching a new bucket regardless of the data stored in the bucket.
{% endhint %}

When detaching, the background task of detaching the object store bucket begins. Detaching can be a long process, depending on the amount of data and the load on the object stores.

* **Migration to a different object store:** When detaching from a filesystem tiered to two local object store buckets, only the read-only object store bucket can be detached. In such cases, the background task copies only the data that remains in the filesystem to the writable object store. In addition, the allocated SSD capacity only requires enough SSD capacity for the metadata.
* **Un-tiering a filesystem:** Detaching from a filesystem tiered to one object store bucket un-tiers the filesystem and copies the data back to the SSD. The allocated SSD capacity must be at least the total capacity the filesystem uses.

On completion of detaching, the object store bucket does not appear under the filesystem when using the `weka fs` command. However, it still appears in the object stores list and can be removed if any other filesystem does not use it. The data in the read-only object store bucket remains in the object store bucket for backup purposes. If this is unnecessary or the reclamation of object store space is required, it is possible to delete the object store bucket.

{% hint style="info" %}
Before deleting an object store bucket, remember to consider data from another filesystem or data not relevant to the WEKA system on the object store bucket.
{% endhint %}

{% hint style="warning" %}
Once the migration process is completed, while relevant data is migrated, old snapshots (and old locators) reside on the old object store bucket. To recreate snapshot locators on the new object store bucket, snapshots should be re-uploaded to the (new) bucket.
{% endhint %}

## Migration considerations

The detach operation migrates all data that remains in the filesystem; you cannot select which data to copy. To reduce migration time and the capacity consumed on the new bucket, delete the snapshots that do not need to be migrated before detaching the old bucket. Snapshots you delete before detaching remain on the old bucket.

**Migration workflow**

The order of the following steps is important.

1. Attach a new object store bucket (the old object store bucket becomes read-only).
2. Delete any snapshot that does not need to be migrated. This action keeps the snapshot on the old bucket but does not migrate its data to the new bucket.
3. Detach the old object store bucket.

{% hint style="info" %}
If you perform the workflow steps in a different order, the snapshots can be completely deleted from any of the object store buckets. It is also possible that the snapshots are already in a migration process and cannot be deleted until the migration is completed.
{% endhint %}

### Attach a remote object store bucket

One remote object store bucket can be attached to a filesystem. A remote object store bucket is used for backup. Only snapshots are uploaded using **Snap-To-Object**. The snapshot uploads are incremental to the previous one.

### Detach a remote object store bucket

Detaching a remote object store bucket from a filesystem keeps the backup data within the bucket intact, and you can still use these snapshots for recovery. However, after detaching, you cannot resume incremental snapshot uploads to that bucket.

Attaching a bucket after detachment is treated as attaching a new bucket: the first snapshot upload is a full baseline, and subsequent uploads are incremental to it. To simplify future cleanup, start the new upload chain in an empty bucket.

**Related topics**

[Background tasks](/operation-guide/background-tasks)

[Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj)

[Attach or detach object store bucket using the GUI](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems/attaching-detaching-object-stores-to-from-filesystems)

[Attach or detach object store buckets using the CLI](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems/attaching-detaching-object-stores-to-from-filesystems-1)


# Attach or detach object store bucket using the GUI

This page describes how to attach or detach object stores buckets to or from filesystems using the GUI.

Using the GUI, you can:

* [Attach object store bucket to a filesystem](#attach-or-detach-object-store-bucket-to-a-filesystem)
* [Detach object store bucket from a filesystem](#detach-object-store-bucket-from-a-filesystem)

## Attach object store bucket to a filesystem

**Before you begin**

Verify that an object store bucket is available.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. On the **Filesystem** page, select the three dots on the right of the filesystem that you want to attach to the object store bucket. Then, from the menu, select **Attach Object Store Bucket**.
3. On the Attach Object Store Bucket dialog, select the relevant object store bucket.

<div data-with-frame="true"><img src="/files/e5YT1SU1gWIrdRTmrzG2" alt="Attach object store bucket"></div>

## Detach object store bucket from a filesystem

Detaching a local object store bucket from a filesystem migrates the filesystem data residing in the object store bucket either to the writable object store bucket (if one exists) or to the SSD.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. On the **Filesystem** page, select the filesystem from which you want to detach the object store bucket.
3. From the **Detach Object Store Bucket** dialog, select **Detach.**\
   If the filesystem is attached to two object store buckets (one is read-only, and the other is writable), you can detach only the read-only one. The data of the detached object store bucket is migrated to the writable object store bucket.
4. In the message that appears, to confirm the detachment, select **Yes**.

<div data-with-frame="true"><img src="/files/uKjeBdWy2fEBIweeKC5B" alt="Detach an object store bucket from a filesystem"></div>

5. If the filesystem is tiered and only one object store is attached, detaching the object store bucket opens the following message:

<div data-with-frame="true"><img src="/files/O1my4B6Vr7vvvDJLIxE1" alt="Detach"></div>

6. Object store buckets usually expand the filesystem capacity. Un-tiering of a filesystem requires adjustment of its total capacity. Select one of the following options:
   * Increase the SSD capacity to match the current total capacity.
   * Reduce the total filesystem capacity to match the SSD or used capacity (the decrease option depends on the used capacity).
   * Configure a different capacity.

{% hint style="info" %}
Used capacity must be taken into account. Un-tiering takes time to propagate the data from the object store to the SSD. When un-tiering an active filesystem, to accommodate the additional writes during the detaching process, it is recommended to adjust to a higher value than the used capacity.
{% endhint %}

7. Select the option that best meets your needs, and select **Continue**.
8. In the message that appears, select **Detach** to confirm the action.


# Attach or detach object store buckets using the CLI

This page describes how to attach or detach object store buckets to or from filesystems using the CLI.

Using the CLI, you can:

* [Attach an object store bucket to a filesystem](#attach-an-object-store-bucket)
* [Detach an object store bucket from a filesystem](#detach-an-object-store-bucket)

## **Attach an object store bucket** to a filesystem

**Command:** `weka fs tier s3 attach`

To attach an object store to a filesystem, use the following command:

`weka fs tier s3 attach <fs-name> <obs-name> [--mode mode]`

**Parameters**

<table><thead><tr><th>Name</th><th width="367.3333333333333">Value</th><th>Default</th></tr></thead><tbody><tr><td><code>fs-name</code>*</td><td>Name of the filesystem to attach with the object store.</td><td>​</td></tr><tr><td><code>obs-name</code>*</td><td>Name of the object store to attach.</td><td></td></tr><tr><td><code>mode</code></td><td><p>The operational mode for the object store bucket.<br>The possible values are:</p><ul><li><code>writable</code>: Local access for read/write operations.</li><li><code>remote</code>: Read-only access for remote object stores.</li></ul></td><td><code>writable</code></td></tr></tbody></table>

## **Detach an object store bucket** from a filesystem

**Command:** `weka fs tier s3 detach`

To detach an object store from a filesystem, use the following command:

`weka fs tier s3 detach <fs-name> <obs-name>`

**Parameters**

<table><thead><tr><th width="265">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>fs-name</code>*</td><td>Name of the filesystem to be detached from the object store</td></tr><tr><td><code>obs-name</code>*</td><td>Name of the object store to be detached</td></tr></tbody></table>

{% hint style="info" %}
To [recover from a snapshot](/weka-filesystems-and-object-stores/snap-to-obj#creating-a-filesystem-from-a-snapshot-using-the-cli) uploaded when two `local` object stores have been attached, use the `--additional-obs` parameter in the `weka fs download` command. The primary object store should be the one where the locator has been uploaded to
{% endhint %}


# Manage data lifecycle for tiered systems

Learn how the system manages data storage in tiered configurations, covering lifecycle policies, capacity management, and operational controls.

## Tiered storage overview

WEKA tiered storage combines high-speed SSD performance with object storage scalability, automatically optimizing data placement to manage costs without sacrificing speed.

**Data vs. metadata handling:** Tiering applies exclusively to file data content. All filesystem metadata, including directory structures, file attributes, and permissions, remains permanently pinned on the SSD tier. This ensures that metadata operations, such as file lookups and directory listings, always perform at sub-millisecond speeds, regardless of where the actual data resides.

**Automated lifecycle:**

* **Active data:** Resides on the SSD tier for maximum IOPS and throughput.
* **Inactive data:** Automatically moves to the object storage tier for cost efficiency once the configured retention period expires.

The system automates this movement based on administrator-defined policies, eliminating the need for manual file migration or complex data classification workflows.

**Related information**

[Data lifecycle management overview](/weka-system-overview/data-storage)

## Data lifecycle policy controls

Two time-based policies govern the data lifecycle in a tiered filesystem: the tiering cue and the drive retention period. These policies function as timing controls, determining when the system copies data to the object store and how long it remains cached on the SSD.

**Policy configuration scope:** Tiering cues and drive retention periods are configured at the filesystem group level. This architecture enforces consistent data aging and retention policies across all filesystems assigned to a specific group. When planning data lifecycle strategies, define the configuration requirements for the entire group rather than individual filesystems.

### Tiering cue

The tiering cue defines the wait time after a data write before the system copies it to the object store. This delay prevents the unnecessary transfer of temporary or rapidly changing data. For example, temporary analysis files created and deleted within an hour never consume object store bandwidth if the tiering cue exceeds that duration.

**Key behaviors:**

* **Timer reset:** If an application modifies data during the waiting period, the system resets the timer. Actively changing data remains on the SSD and does not cycle between tiers.
* **Chunk-level granularity:** The system manages data in chunks (up to 1 MB), tracking timestamps independently for each chunk. Consequently, frequently modified parts of a large file remain on the SSD, while unchanged parts tier to the object store.
* **Configuration constraint:** The tiering cue cannot exceed one-third of the drive retention period.

#### Guidelines for tiering cue configuration

Optimize storage efficiency and performance by aligning the tiering cue settings with specific workload patterns.

* **Write-once workloads:** For data such as sensor captures or finished renders, set a short tiering cue. The minimum value is 10 seconds, and the default is 15 minutes. This setting facilitates rapid tiering to the object store.
* **Active editing:** For data undergoing frequent modification, set a longer tiering cue, typically measured in days or weeks. This configuration ensures data remains on the high-performance tier until it stabilizes.

### Drive retention period

The drive retention period determines how long data remains cached on the SSD after the system successfully copies it to the object store. This policy maintains a read cache of recently tiered data to ensure fast access.

**Key behaviors:**

* **SSD caching:** Data copied to the object store remains on the SSD for low-latency access. This leverages the principle of temporal locality, assuming recently accessed data is likely to be accessed again.
* **Data release:** When the retention period expires, the system releases the SSD copy to free space for new data. The authoritative copy remains in the object store.
* **Re-caching:** Accessing released data retrieves it from the object store and writes it back to the SSD with a new timestamp.

**Capacity considerations**

The drive retention period acts as a target, not a guarantee. If the data ingest rate exceeds the SSD capacity within the configured period, the system releases data early to prevent SSD exhaustion.

#### Guidelines for retention period configuration

Align retention periods with user access patterns and available storage resources to optimize performance and capacity management.

* **High access frequency:** Configure a longer retention period, for example, 30 days, when users frequently access recent data. This configuration keeps data on the high-performance tier to ensure low-latency access for ongoing operations.
* **Limited SSD capacity:** Configure a shorter retention period if SSD capacity is limited relative to the data generation rate. This configuration frees up high-performance storage resources more rapidly, preventing the cluster from reaching capacity limits.

**Related topic**

[Manage filesystem groups](/weka-filesystems-and-object-stores/managing-filesystem-groups)

## Data flow in tiered systems

Understanding the lifecycle of data in a tiered system helps predict performance behavior and interpret observations during monitoring and troubleshooting. The data journey involves writing, tiering, retention, release, and reclamation.

### Write operations

All data written to a tiered filesystem initially lands on the SSD tier. The system does not write directly to the object store, ensuring write completion at SSD latency.

Upon ingestion, the system assigns a creation timestamp to the data. This timestamp serves as the reference for subsequent tiering decisions. At this stage, the data resides exclusively on the SSD (write-cache).

**Chunk-level management:** The system tracks modifications at a fine granularity, maintaining timestamps per data chunk (up to 1 MB) rather than per file. When an application modifies a specific chunk within a large file, only that chunk’s timestamp is refreshed.

This model enables efficient handling of mixed access recency within a single file. For example, a large database file can contain recently modified chunks that remain on the SSD alongside older, unmodified chunks that are eligible for tiering.

### Tiering process

Once the Tiering Cue period expires for a chunk, the system begins copying that data to the object store in the background. This process does not interrupt application access.

**Object bundling:** To improve object store efficiency, the system bundles data from multiple files and chunks into larger objects, typically up to 64 MB. This reduces the number of stored objects, lowers management costs, and optimizes bandwidth usage. This bundling is transparent; the system maintains metadata mapping file data to specific regions within bundled objects.

**Handle modifications during tiering:** If an application modifies data during the tiering process, the modified chunks receive new timestamps and exit the current tiering operation. Portions already copied to the object store remain there to prevent inconsistencies.

### Retention and release

After copying to the object store, data enters the read-cache placement condition, existing on both the SSD and the object store. The SSD copy remains available for fast access according to the configured Drive Retention Period.

**Release process:** When cached data exceeds the retention period, the system releases it by removing the SSD copy while preserving the object store copy. This frees SSD capacity for newer data. The system prioritizes releasing the oldest cached data first.

**Read-path cache promotion:** When accessed, released data is retrieved from the object store and automatically promoted to the SSD read cache. The system assigns the chunk a new access timestamp to track recency. Once cached, the chunk persists on the SSD and is not re-uploaded to the object store unless explicitly rewritten or evicted during cache reclamation. This mechanism ensures that frequently accessed data remains in the high-performance SSD cache tier, independent of the data's original write time.

### Object storage space reclamation

Data bundling impacts storage efficiency. When users delete or modify files, the system marks the space they occupied within up to 64 MB objects as reclaimable rather than immediately freeing it.

**Reclamation thresholds:** The system tracks reclaimable space per filesystem to trigger the reclamation process:

* **Start threshold:** Reclamation begins automatically when reclaimable space exceeds 13% of the total object storage usage.
* **Stop threshold:** The process continues until reclaimable space drops below 7%.

**Reclamation overhead:** The reclamation process reads objects with significant reclaimable space, rewrites active data into new objects, and deletes the fragmented ones. Consequently, object storage usage typically runs 7–13% higher than the logical size of active data.

{% hint style="info" %}
For filesystems created from uploaded snapshots, only data written *after* creation is eligible for reclamation. Data inherited from the snapshot remains in its original layout.
{% endhint %}

<div data-with-frame="true"><figure><img src="/files/7hwzarWdxaWOd3XjXVRV" alt=""><figcaption><p>Object store space reclamation</p></figcaption></figure></div>

## System behavior under resource constraints

Operational constraints can force the system to deviate from configured policies. Understanding the system's behavior under these conditions assists in interpreting system status and diagnosing issues.

### Time-based data management

The system organizes data temporally to manage releases efficiently when SSD capacity is limited. Data is divided into 8 time-based intervals, allowing the system to release the oldest data first when space is needed.

Due to the imprecision of these internal interval boundaries, the actual retention period on SSD may be up to twice as long as the configured Drive Retention Period. For example, with a 20-day retention policy, data might remain on the SSD for up to 40 days, depending on available capacity and interval alignment.

The system makes release decisions at the interval level rather than the file level. When the system requires SSD space, it releases the oldest complete interval to the object store. This coarse-grained approach efficiently tracks and manages billions of files across storage servers.

### High write rates and capacity limits

A constraint scenario occurs when data write rates exceed the SSD capacity required to support the configured retention period.

**System behavior:** If the workload generates more data than the SSD can hold for the full retention period, the system releases data early to prioritize system availability.

**Example: Effective retention vs. configured policy**

Consider a cluster with 100 TB of SSD capacity and a configured 20-day retention policy. If the workload writes 8 TB of new data daily, the SSD reaches capacity in approximately 12.5 days (100 TB/8 TB/day).

To prevent the SSD from filling, the system releases the oldest data intervals early. This effectively reduces the actual retention period to approximately 10–15 days. While applications continue to function normally, data older than this effective period moves to the object store sooner than configured. Accessing this data incurs object storage latency.

**Resolution options:**

* **Increase SSD capacity:** Expand the cluster storage to cache more data intervals.
* **Reduce drive retention period:** Adjust the policy to align with the available capacity and actual write rate.
* **Accept the status quo:** If the early release of data does not impact the performance of critical workflows, no action is required.

### Object storage throughput limits and backpressure

A second constraint scenario involves object storage throughput. If the system cannot tier data fast enough to match the write rate, the SSD fills up even if sufficient capacity exists for the retention policy.

**Backpressure mechanism:** The system activates backpressure when SSD utilization exceeds 95% per filesystem. This emergency release mode bypasses normal retention policies to prevent the SSD from filling completely.

* **Action:** The system aggressively releases data from the SSD as quickly as the object store can accept it.
* **Duration:** Backpressure continues until SSD utilization drops below 90%.
* **Impact:** Data may be released immediately after tiering, bypassing the retention window. First access to this data requires retrieval from the object store.

**Causes and resolution:** Throughput bottlenecks often stem from insufficient network bandwidth, object storage performance limits, or resource contention (for example, concurrent backups). Resolving this requires increasing bandwidth, upgrading the object store, or distributing the load.

### Distinction: Tiering cue vs. capacity constraints

The Tiering Cue policy defines when data becomes *eligible* for tiering, not when it must leave the SSD. Writing large amounts of data during the tiering cue period does not cause a policy violation; the data simply waits for the period to end before tiering begins.

Policy violations and early releases occur specifically due to capacity or throughput constraints on the retention side (how long data stays cached), never due to the tiering cue itself.

## Monitor system status

Effective management of a tiered WEKA system requires visibility into capacity utilization, space reclamation status, and data distribution. Use the available tools to monitor the system status and interpret the metrics.

### View capacity and reclamation status

The `weka fs tier capacity` command provides insights into data residence in the object store, active versus reclaimable data, and the automatic space reclamation low and high thresholds (7% and 13%). Running the command without arguments displays statistics for all tiered filesystems. Add the `--filesystem` option to filter the output for a specific filesystem.

**Example:**

```bash
$ weka fs tier capacity
FILESYSTEM     BUCKET                TOTAL CONSUMED CAPACITY  USED CAPACITY  RECLAIMABLE%  RECLAIMABLE THRESHOLD LOW%  RECLAIMABLE THRESHOLD HIGH%
bmrb           wekalow-bmrb          51.08 TB                 50.16 TB       1.78          7.00                        13.00
cam_archive    wekalow-archive       3.34 TB                  3.17 TB        5.10          7.00                        13.00
nmr_backup     wekalow-nmrbackup     121.38 TB                110.99 TB      8.55          7.00                        13.00
```

**Metric definitions:**

* **TOTAL CONSUMED CAPACITY:** The actual space used in the object store, including active data and reclaimable space (overhead) from deleted or modified files. This metric reflects the billable object storage usage.
* **USED CAPACITY:** The size of active data currently existing in the filesystem.
* **RECLAIMABLE THRESHOLD HIGH%**: System starts reclamation when reclaimable space exceeds this percentage.
* **RECLAIMABLE THRESHOLD LOW%**: System stops reclamation when reclaimable space drops below this percentage.

{% hint style="info" %}
If the filesystem was created from an uploaded snapshot, data from the original filesystem is not accounted for in the displayed capacity.
{% endhint %}

**Interpretation:** Use these metrics to interpret object storage usage and costs:

* **Normal overhead:** If consumed capacity slightly exceeds active used capacity (for example, 11 TB consumed for 10 TB active), the difference represents the expected reclaimable space overhead (7–13%).
* **Active reclamation:** If consumed capacity significantly exceeds used capacity (for example, 15 TB consumed for 10 TB active), the system is likely processing a reclamation cycle following significant deletions or modifications.

### Identify data location

Depending on the tiering policy and retention period, files reside on the SSD, the object store, or both. Use the `weka fs tier location` command to track a file's location throughout its lifecycle. This visibility is essential for diagnosing latency, verifying tiering operations, and understanding performance characteristics.

**Command syntax**

```bash
weka fs tier location <path> [paths...]
```

**Parameters**

* `<path>`: The specific directory path to investigate.
* `[paths...]`: Space-separated list of paths to investigate.
* `*` (Wildcard): Retrieves location information for all files in a specific directory (for example, `weka fs tier location /mnt/data/*`).

#### Data lifecycle placement conditions

The command output reveals the file's placement condition based on which storage tier consumes capacity.

**1. Before tiering (SSD write-cache)**

This is the initial placement condition for any new or modified data. The data resides exclusively on the SSD to ensure maximum write performance. At this stage, the file is considered frequently accessed and has not yet been asynchronously pushed to the backend object store.

* **Capacity in SSD (write-cache):** The total amount of high-performance SSD space currently occupied by new or modified data blocks that are pending tiering.
* **Capacity in SSD (read-cache):** 0 B, as the data has not yet been replicated to the backend storage.
* **Capacity in object store:** 0 B, as the data has not yet been replicated to the backend storage.

**Example:** In this scenario, a 102.39 MB file has been written to the filesystem but the tiering process to the object store has not yet commenced.

{% code fullWidth="false" %}

```bash
$ weka fs tier location image
PATH   FILE TYPE  FILE SIZE  CAPACITY IN SSD (WRITE-CACHE)  CAPACITY IN SSD (READ-CACHE)  CAPACITY IN OBJECT STORAGE
image  regular    102.39 MB  102.39 MB                      0 B                           0 B
```

{% endcode %}

**2. Tiered and retained storage (SSD read-cache + object store)**

This condition occurs when a file's data is stored long-term in an object store while also residing on an SSD for enhanced performance. This happens in two cases:

* **Retention:** The file is moved to the object store, but the Drive Retention Period keeps a local SSD copy.
* **Promotion:** A file previously only in the object store is cached on the SSD after a "read" operation.

This placement ensures data protection with a durable object store copy and low-latency access from the local SSD.

* **Capacity in SSD (write-cache):** 0 B. No SSD space currently occupied.
* **SSD capacity (read-cache):** The total physical SSD space occupied by the file's data blocks.
* **Object store capacity:** The file's data footprint in the backend bucket/container.

**Example:** A 102.39 MB file is securely stored in the object store while easily accessible on the SSD flash layer.

```bash
$ weka fs tier location image
PATH   FILE TYPE  FILE SIZE  CAPACITY IN SSD (WRITE-CACHE)  CAPACITY IN SSD (READ-CACHE)  CAPACITY IN OBJECT STORAGE
image  regular    102.39 MB  0 B                            102.39 MB                     102.39 MB
```

**3. Released (object store only)**

Once the Drive Retention Period expires, and the local SSD copy is removed to free up high-performance space, the file transitions to its primary residence in the object store. It remains fully protected and accessible.

{% hint style="info" %}
When accessing a file in this condition, a "promotion" occurs. The system retrieves the data from the object store to the SSD, which temporarily increases latency for the initial read.
{% endhint %}

* **Capacity in SSD (write-cache/read cache):** 0 B, as no data blocks are currently occupying physical space on the local SSD layer.
* **Capacity in object store:** The total footprint of the file's data as stored in the backend bucket/container.

**Example:** A 102.39 MB file has been tiered, and the local cache has been cleared successfully.

```bash
$ weka fs tier location image
PATH   FILE TYPE  FILE SIZE  CAPACITY IN SSD (WRITE-CACHE)  CAPACITY IN SSD (READ-CACHE)  CAPACITY IN OBJECT STORAGE
image  regular    102.39 MB  0 B                            0 B                           102.39 MB
```

## Transition between tiered and SSD-only filesystems

Understand the storage behavior and capacity requirements when reconfiguring filesystems between SSD-only and tiered modes.

### Transition from SSD-only to tiered filesystems

You can reconfigure an SSD-only filesystem as a tiered filesystem by attaching an object store bucket.

When you attach an object store, the default behavior maintains the current filesystem size. To increase the filesystem size, modify the total capacity field while keeping the existing allocated SSD capacity unchanged.

**Data management behavior**

Upon reconfiguration to a tiered filesystem, the system treats all existing data as a single baseline group for the purpose of tiering. This data is managed according to the standard background processes. However, because it was written before the policy change, the system releases the SSD copy in a system-optimized, arbitrary order. Consequently, the release process for this pre-existing data does not follow original creation or modification timestamps.

### Transition from tiered to SSD-only filesystems

You can convert a tiered filesystem back to an SSD-only configuration by detaching the object store bucket. This action triggers the system to copy all tiered data back to the SSDs.

**Capacity requirements**

Before detaching the object store, ensure the SSD tier has sufficient capacity. The allocated SSD capacity must be equal to or greater than the total capacity currently used by the filesystem.

WEKA filesystems support transitions between SSD-only and tiered configurations. You can adapt the storage architecture by attaching an object store to an SSD-only filesystem or detaching it from a tiered filesystem.

**Related topic**

[Attach or detach object store buckets](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems)

## Special operational modes and manual controls

While WEKA tiered storage operates automatically based on configured policies, specific workflows benefit from manual intervention. Use the available manual controls to pre-position data on the SSD, free SSD space, or bypass normal caching behaviors.

### Manual data fetching

The `weka fs tier fetch` command retrieves specific files from the object store and places them on the SSD. This pre-fetching capability eliminates the latency associated with the first access of tiered data.

File metadata always resides on the SSD, enabling you to traverse directories and identify files to fetch without performance penalties, even if the data itself is tiered.

**Command syntax**

```bash
weka fs tier fetch <path> [--verbose]
```

**Parameters**

* `<path>`: A comma-separated list of file paths to fetch.
* `-v`, `--verbose`: Displays fetch requests as the system submits them. Default is Off.

#### Batch fetching

To fetch large directory trees efficiently, for example, combine the command with Unix tools to parallelize the operation.

```bash
find -L <directory_path> -type f | xargs -r -n512 -P64 weka fs tier fetch -v
```

#### Constraints and considerations

Pre-fetching files does not guarantee they will remain on the SSD until accessed. To ensure an effective fetch operation, consider the following factors:

* **Tiering policy conflicts:** The system applies lifecycle policies even to fetched data. If the configured retention period is short, the system may release files back to the object store immediately after, or even during, the fetch operation. Ensure the retention policy provides a sufficient window to complete the fetch and access the data.
* **SSD capacity:** The SSD must have sufficient free capacity to retain the fetched data.

### Manual data release

The `weka fs tier release` command forces the immediate release of data from the SSD to the object store, overriding standard retention policies. This is useful for clearing SSD space in advance of specific operations, such as shrinking a filesystem's SSD capacity or preparing for a job that requires significant high-performance storage.

**Key behaviors**

* **Metadata retention:** The filesystem metadata remains on the SSD, ensuring fast directory traversal and file lookup even after the data is released.
* **Prioritization:** Data marked for manual release is queued to move to the object store immediately, taking priority over files scheduled for release by standard lifecycle policies.

**Command syntax**

```bash
weka fs tier release <path> [--verbose]
```

**Parameters**

* `<path>`: A comma-separated list of file paths to release.
* `-v`, `--verbose`: Displays release requests as the system submits them. Default is Off.

#### Release large datasets

To release a directory containing a large number of files or a specific list of files, use the `xargs` command to parallelize the operation.

**Release a directory:** Use `find` combined with `xargs` to release all files within a specific path:

```sh
find -L <directory_path> -type f | xargs -r -n512 -P64 weka fs tier release
```

**Release from a file list:** Use `cat` combined with `xargs` to release files listed in a text file:

```sh
cat file-list | xargs -P32 -n200 weka fs tier release
```

### Direct object store mount (`obs_direct`)

The `obs_direct` mount option enables a special operational mode that bypasses retention policies.

**System behavior:**

* **Writes:** Data is initially written to the SSD and immediately scheduled for release to the object store. This means data temporarily consumes SSD write-cache space during transit.
* **Reads:** Data is retrieved from object storage to serve the request and not promoted to SSD.

**Use case:** Use this mode for bulk data imports (migrations) where the target destination is object storage. It ensures incoming data flows to the object store without occupying the SSD cache long-term.

{% hint style="warning" %}
**Important:** Do not use `obs_direct` for ongoing application access. Because this mode disables caching, every read request triggers a retrieval from object storage. For cloud deployments (for example, AWS S3), repeated reads of the same file generate excessive retrieval charges. Use this option only for the duration of the import task.
{% endhint %}

### Object tagging

WEKA categorizes objects uploaded to the object store by assigning specific tags. These tags support external lifecycle management rules, allowing the identification of objects belonging to a specific filesystem for operations such as transfer to archival storage (for example, [S3 Glacier Deep Archive](https://aws.amazon.com/s3/storage-classes/glacier/instant-retrieval/)).

#### Tag definitions

When object tagging is enabled, the system applies the following tags to uploaded objects:

<table><thead><tr><th width="174">Tag</th><th>Description</th></tr></thead><tbody><tr><td><code>wekaBlobType</code></td><td><p>The internal type representation of the object.</p><p>Possible values: <code>DATA</code>, <code>METADATA</code>, <code>METAMETADATA</code>, <code>LOCATOR</code>, <code>RELOCATIONS</code></p></td></tr><tr><td><code>wekaFsId</code></td><td>A unique filesystem identifier combining the filesystem ID and the cluster GUID.</td></tr><tr><td><code>wekaGuid</code></td><td>The cluster GUID.</td></tr><tr><td><code>wekaFsName</code></td><td>The name of the filesystem that uploaded the object.</td></tr></tbody></table>

#### Enable object tagging

You can enable tagging when adding or updating an object store bucket.

* **GUI:** Select **Enable Upload Tags** in the **Advanced** section of the object store bucket configuration. For details, see [Manage object stores using the GUI](/weka-filesystems-and-object-stores/managing-object-stores/managing-object-stores).
* **CLI:** Include the `--enable-upload-tags` parameter in the `weka fs tier s3 add` or `weka fs tier s3 update` commands. For details, see [Manage object stores using the CLI](/weka-filesystems-and-object-stores/managing-object-stores/managing-object-stores-1).

#### Prerequisites and considerations

* **Platform support:** The object store must support S3 object tagging.
* **Permissions:** For example, AWS S3 requires the `s3:PutObjectTagging` and `s3:DeleteObjectTagging` permissions.
* **Cost:** Cloud service providers may charge additional fees for using object tagging.


# Mount filesystems

Discover the two modes for mounting a filesystem on a cluster server: persistent mount mode (stateful) and stateless mount mode. You can also use fstab or autofs for mounting.

## Overview

There are two modes available for mounting a filesystem in a cluster server:

* **Persistent mount mode (stateful):** This mode involves configuring a client to join the cluster before running the mount command.
* **Stateless mount mode:** This mode simplifies and improves client management by eliminating the need for the Adding Clients process.

If you need to mount filesystems from multiple clusters on a single client, refer to the relevant topic for detailed instructions.

In addition, you can mount a filesystem using **fstab** or **autofs**.

**Related topics**

[#mount-a-filesystem-using-the-persistent-mount-mode](#mount-a-filesystem-using-the-persistent-mount-mode "mention")

[#mounting-filesystems-using-stateless-clients](#mounting-filesystems-using-stateless-clients "mention")

[#mount-a-filesystem-using-fstab](#mount-a-filesystem-using-fstab "mention")

[#mount-a-filesystem-using-autofs](#mount-a-filesystem-using-autofs "mention")

[Mount filesystems from Single Client to Multiple Clusters (SCMC)](/weka-filesystems-and-object-stores/mounting-filesystems/mount-fs-from-scmc)

***

## Mount a filesystem using the persistent mount mode

To mount a WEKA filesystem persistently, follow these steps:

1. **Install the WEKA client**: Ensure the WEKA persistent client is installed, configured, and connected to your cluster. See [Add a persistent client to the cluster](/planning-and-installation/bare-metal/adding-clients-bare-metal#add-a-persistent-client-to-the-cluster).
2. **Identify the filesystem**: Determine the name of the filesystem you want to mount. For this example, we use a filesystem named `demo`.
3. **Create a mount point**: SSH into one of your cluster servers and create a directory to serve as the mount point for the filesystem:

   ```bash
   mkdir -p /mnt/weka/demo
   ```
4. **Mount the filesystem**: As the root user, run the following command to mount the filesystem:

   ```bash
   mount -t wekafs demo /mnt/weka/demo
   ```

**General command structure**: The general syntax for mounting a WEKA filesystem is:

```bash
mount -t wekafs [-o option[,option]...] <fs-name> <mount-point>
```

Replace `<fs-name>` with the name of your filesystem and `<mount-point>` with the directory you created for mounting.

**Read and write cache modes:** When mounting a filesystem, you can choose between two cache modes: read cache and write cache. Each mode offers distinct advantages depending on your use case. For detailed descriptions of these modes, refer to the following links:

* [Read cache mount mode](/weka-system-overview/weka-client-and-mount-modes#read-cache-mount-mode-default)
* [Write cache mount mode](/weka-system-overview/weka-client-and-mount-modes#write-cache-mount-mode)

***

## Mount a filesystem using the stateless mount mode <a href="#mounting-filesystems-using-stateless-clients" id="mounting-filesystems-using-stateless-clients"></a>

The stateless mount mode simplifies client management by deferring the joining of the cluster until the mount operation is performed. This approach is particularly beneficial in environments like AWS, where clients frequently join and leave the cluster.

**Key benefits**

* **Simplified client management**: Eliminates the need for tedious client management procedures.
* **Unified security**: Consolidates all security aspects within the mount command, removing the need to manage separate credentials for cluster join and mount.

**Prerequisites**

* The stateless clients must have a connection to all the backends, dedicated protocol servers (gateways), and persistent clients.
* Ensure the WEKA agent is installed on your client to utilize the stateless mount mode. See [Add clients](/planning-and-installation/bare-metal/adding-clients-bare-metal).

**Mount a filesystem**

Once the WEKA agent is installed, you can create and configure mounts using the mount command. To mount a filesystem:

* **Create and configure mounts**: Use the `mount` command to create and configure the mounts. See [#mount-command-options](#mount-command-options "mention").
* **Unmounting**: Remove existing mounts from the cluster using the `unmount` command.

**Authentication**

To restrict mounting to only WEKA authenticated users, set the `--auth-required` flag to `yes` for the filesystem. For more information, refer to [Broken mention](broken://pages/sL8r2o6E4aM1LQqoL3Kf).

### **Set a stateless client with restricted operations on an Isolated port**

To restrict a stateless client's operations to only the essential APIs for mounting and unmounting, connect to WEKA clusters through TCP base port + 3 (for example, 14003). This configuration enables operational segregation between client and backend control plane requests.

### **Mount with restricted options**

When mounting with the restricted option, the logged-in user's privileges are set to regular user privileges, regardless of the user's role.

### Install the WEKA agent

To install a WEKA agent on a client, run one of the following commands as `root` on the client:

* For a non-restricted client:

```sh
curl -k https://hostname:14000/dist/v1/install | sh
```

* For a restricted client:

```bash
curl -k https://hostname:14003/dist/v1/install | sh
```

{% hint style="info" %}
The `-k` flag instructs the `curl` command to bypass SSL certificate verification.
{% endhint %}

After running the appropriate command, the agent is installed on the client.

### Run the mount command

**Command:** `mount -t wekafs`

#### Command syntax

Use one of the following command lines to invoke the mount command. The delimiter between the server and filesystem can be either `:/` or `/`:

{% code overflow="wrap" %}

```bash
mount -t wekafs -o <options> <backend0>[,<backend1>,...,<backendN>]/<fs> <mount-point>

mount -t wekafs -o <options> <backend0>[,<backend1>,...,<backendN>]:/<fs> <mount-point>
```

{% endcode %}

### **Example: Mount for a restricted stateless client on an isolated port**

{% code overflow="wrap" %}

```bash
mount -t wekafs -o restricted -o <options> <backend0>[,<backend1>,...,<backendN>]/<fs> <mount-point>
```

{% endcode %}

This setup ensures that the stateless client operates with restricted privileges, maintaining a secure and controlled environment for mounting and unmounting operations on an isolated port.

**Parameters**

<table><thead><tr><th width="250">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>options</code></td><td>See Additional Mount Options below.</td></tr><tr><td><code>backend</code></td><td>IP/hostname of a backend container.<br>Mandatory.</td></tr><tr><td><code>fs</code></td><td>Filesystem name.<br>Mandatory.</td></tr><tr><td><code>mount-point</code></td><td>Path to mount on the local server.<br>Mandatory.</td></tr></tbody></table>

***

## Mount command options

Each mount option can be passed by an individual `-o` flag to `mount.`

### For all client types

<table data-full-width="false"><thead><tr><th width="221.87109375">Option</th><th width="343.1953125">Description</th><th width="97.6484375">Default</th><th>Remount supported</th></tr></thead><tbody><tr><td><code>readcache</code></td><td><p>Enables read-only cache mode for mounts. When enabled, data is read from cache, and <code>writecache</code> is automatically disabled.</p><p><strong>Note:</strong> SMB share mounts always use <code>readcache</code> mode; use this flag for SMB shares.</p></td><td>Disabled</td><td>Yes</td></tr><tr><td><code>writecache</code></td><td>Enables write-to-cache mode for mounts, allowing data to be written to the cache.</td><td>Enabled</td><td>Yes</td></tr><tr><td><code>forcedirect</code></td><td><p>Enables direct I/O mode, bypassing cache for both read and write operations. Automatically disables <code>writecache</code> and <code>readcache</code> when enabled.</p><p><strong>Notes:</strong></p><ul><li>This may impact performance. Use with caution. If unsure, contact the <a href="/pages/-LIFO5pWHg9bMZYn0q2X#contact-customer-success-team">Customer Success Team</a>.</li><li>It is not supported for SMB shares.</li></ul></td><td>Disabled</td><td>Yes</td></tr><tr><td><code>dentry_max_age_positive</code></td><td><p>Maximum time in milliseconds to cache positive directory entries before refreshing metadata. This ensures the WEKA client detects metadata changes made by other clients.</p><p><strong>Values:</strong> Time in milliseconds</p></td><td><code>1000</code></td><td>Yes</td></tr><tr><td><code>dentry_max_age_negative</code></td><td><p>Time in milliseconds to cache "file not found" results. When a file lookup fails, the system remembers this failure for the specified duration. After this time expires, the system will check again, allowing detection of files created by other clients.</p><p><strong>Values:</strong> Time in milliseconds</p></td><td><code>0</code></td><td>Yes</td></tr><tr><td><code>ro</code></td><td>Mounts the filesystem in read-only mode, preventing write operations.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>rw</code></td><td>Mounts the filesystem in read-write mode, allowing both read and write operations.</td><td>Enabled</td><td>Yes</td></tr><tr><td><code>inode_bits</code></td><td>Sets the inode size in bits. May be required for compatibility with 32-bit applications.<br>Values: <code>32</code>, <code>64</code>, <code>auto</code></td><td><code>Auto</code></td><td>No</td></tr><tr><td><code>verbose</code></td><td>Enables debug logging output to the console.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>quiet</code></td><td>Disables all log output to the console.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>acl</code></td><td><p>Enables POSIX ACL support for the mount. When ACLs are defined, they can modify effective group permissions through mask permissions.</p><p>If ACLs are configured but not present on the mount, effective group permissions are granted.</p></td><td>Disabled</td><td>No</td></tr><tr><td><code>obs_direct</code></td><td><p>Enables bypassing time-based file retention policies, prioritizing the immediate release of files to the object store regardless of other policies. Data is still written to the SSD first, but released with precedence.</p><p>For more details, see <a data-mention href="/pages/-L7U2tDRXvdbEBrj_KnR#direct-object-store-mount-obs_direct">/pages/-L7U2tDRXvdbEBrj_KnR#direct-object-store-mount-obs_direct</a></p></td><td>Disabled</td><td>Yes</td></tr><tr><td><code>noatime</code></td><td>Disables updating of inode access times on file reads, improving performance by reducing metadata writes.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>strictatime</code></td><td>Enables always updating inode access times on file access, ensuring accurate access time tracking.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>relatime</code></td><td><p>Updates inode access times (<code>atime</code>) only if the file has been modified or changed since the last access time, or when accessed after the <code>relatime_threshold</code> has elapsed.</p><p>This is the default behavior and prevents unnecessary writes while remaining compatible with applications that need to know if a file has been read since its last modification.</p></td><td>Enabled</td><td>Yes</td></tr><tr><td><code>relatime_threshold</code></td><td><p>Time in seconds to wait since the last inode access before updating the access time again. Only applies when <code>relatime</code> is enabled.</p><p>Values: Time in seconds.</p><ul><li>Set to <code>0</code> (default) for <code>atime</code> to only be updated if the file was modified since the last read (<code>mtime</code> more recent than <code>atime</code>).</li><li>Set to <code>86400</code> (24 hours) to match the Linux kernel default behavior, where <code>atime</code> is updated if the last read was more than 24 hours ago.</li></ul></td><td><code>0</code> (infinite)</td><td>Yes</td></tr><tr><td><code>nosuid</code></td><td>Ignores <code>setuid</code> and <code>setgid</code> bits on files, preventing privilege escalation through these mechanisms.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>nodev</code></td><td>Prevents interpretation of character and block device files, disabling device access through the mount.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>noexec</code></td><td>Prevents direct execution of binaries on the mounted filesystem.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>file_create_mask</code></td><td><p>File creation mask. A numeric (octal) notation of POSIX permissions.<br>Newly created file permissions are masked with the creation mask. For example, if a user creates a file with permissions=777 but the <code>file_create_mask</code> is 770, the file is created with 770 permissions.</p><p>First, the <code>umask</code> is taken into account, followed by the <code>file_create_mask</code> and then the <code>force_file_mode</code>.</p></td><td><code>0777</code></td><td>Yes</td></tr><tr><td><code>directory_create_mask</code></td><td><p>Directory creation mask in octal notation. Newly created directories have their permissions masked with this value. For example, creating a directory with 777 permissions and a mask of 770 results in 770 permissions.</p><p>Permission precedence: <code>umask</code> → <code>directory_create_mask</code> → <code>force_directory_mode</code></p><p><strong>Values:</strong> Octal permissions (for example, <code>755</code>, <code>770</code>)</p></td><td><code>0777</code></td><td>Yes</td></tr><tr><td><code>force_file_mode</code></td><td><p>Forces file permissions using octal notation. Newly created files have their permissions logically OR'ed with this value. For example, creating a file with 770 permissions and force mode 775 results in 775 permissions.</p><p>Permission precedence: <code>umask</code> → <code>file_create_mask</code> → <code>force_file_mode</code></p><p><strong>Values:</strong> Octal permissions (for example, <code>644</code>, <code>755</code>)</p></td><td><code>0</code></td><td>Yes</td></tr><tr><td><code>force_directory_mode</code></td><td><p>Forces directory permissions using octal notation. Newly created directories have their permissions logically OR'ed with this value. For example, creating a directory with 770 permissions and force mode 775 results in 775 permissions.</p><p>Permission precedence: <code>umask</code> → <code>directory_create_mask</code> → <code>force_directory_mode</code></p><p><strong>Values:</strong> Octal permissions (for example, <code>755</code>, <code>775</code>)</p></td><td><code>0</code></td><td>Yes</td></tr><tr><td><code>sync_on_close</code></td><td>Ensures all file data is written to the server when files are closed, providing immediate data consistency. Simulates NFS open-to-close semantics with <code>writecache</code> mode and directory quotas. Required for applications that expect write errors at <code>close()</code> when quotas are exceeded.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>nosync_on_close</code></td><td>Cancels <code>sync_on_close</code> behavior, allowing files to close without waiting for server confirmation that data is written to disk. Changes are buffered in memory and written asynchronously, improving performance but reducing immediate data consistency.</td><td>Disabled</td><td>Yes</td></tr><tr><td><code>df_remote</code></td><td>Ensures the mount source includes a colon (<code>:</code>), identifying the filesystem as remote. This prevents tools that list only local filesystems, such as df -l, from incorrectly including the WEKA filesystem in their output.</td><td>Disabled</td><td>No</td></tr></tbody></table>

### Remount of general options

To remount using the specified options, use the `mount -o remount` command. Options marked as **Remount supported** in the tables above and below are usable. If you have explicitly set a mount option previously, ensure you include it during remounting to maintain its state. For instance, if you initially mount with `ro` (read-only), omitting it during remounting will switch it to the default `rw` (read-write). Conversely, if you start with `rw`, you don’t need to specify it again during remounting, as it is the default setting.

**Operational guidance:** Plan all remount operations as disruptive events. Execute remounts during a maintenance window to avoid impacting active workloads and to ensure predictable operational behavior.

### Remount operations and client container restarts

When using the `mount -o remount` command, it is important to understand which options apply dynamically and which trigger a restart of the WEKA client container.

**Standard remount operations**

Most standard mount options (such as `rw`, `ro`, `noatime`, `nodev`, `nosuid`, and similar options) apply immediately without restarting the client container. These operations do not interrupt active I/O to the filesystem.

**Stateless client and operational parameter remounts**

A specific set of stateless client mount options define the fundamental operational parameters of the client (for example, memory allocation, CPU core affinity, QoS limits). Changing any of these specific options using remount triggers a planned restart of the client container to apply the new configuration.

This restart is an expected behavior for these specific options and causes a temporary pause in active I/O. Applications performing I/O during the remount may experience a brief "resource temporarily unavailable" or similar error before resuming normal operation once the container is back online.

It is highly recommended to schedule remount operations that modify these parameters during a maintenance window to minimize the impact on active user workloads.

The following options trigger a client container restart:

* `dpdk_base_memory_mb`
* `qos_max_ops`
* `qos_max_throughput_mbps`
* `qos_preferred_throughput_mbps`
* `dedicated_mode`
* `reserve_1g_hugepages`
* `remove_after_secs`
* `core`
* `num_cores`
* `memory_mb`

### **Additional mount options using the stateless clients feature**

<table data-full-width="false"><thead><tr><th width="256.51171875">Option</th><th width="312.5230712890625">Description</th><th width="98.5347900390625">Default</th><th>Remount supported</th></tr></thead><tbody><tr><td><code>memory_mb=&#x3C;memory_mb></code></td><td>The memory size in MiB the client can use for hugepages.</td><td><code>1400</code></td><td>Yes</td></tr><tr><td><code>num_cores=&#x3C;frontend-cores></code></td><td><p>Specifies the number of processing cores allocated to handle client network operations.</p><p><strong>Values:</strong></p><ul><li>1 to N (where N is the maximum available cores)</li><li>0 (only valid with UDP networking mode)</li></ul><p><strong>Notes</strong>:</p><ul><li>Cannot be used with <code>core</code> parameter</li><li>For VF-based configurations, <code>num_cores</code> usually matches the number of configured network devices (<code>net=</code>)</li><li>For NVIDIA VF single-IP configurations, set <code>nvidia_vf_single_ip=true</code>. In that mode, this rule does not apply.</li><li>Higher core counts may improve performance for multi-connection workloads</li></ul><p>Example: <code>num_cores=4</code> # Allocates 4 cores for client processing</p></td><td><code>1</code></td><td>Yes</td></tr><tr><td><code>core=&#x3C;core-id></code></td><td><p>Assigns specific CPU cores to the WEKA client.</p><p>For multiple cores, you can either repeat the <code>core=&#x3C;core-id></code> option for each core, or use a comma-separated list.</p><p>Examples:</p><ul><li>Single core: <code>-o core=1</code></li><li>Multiple cores: <code>-o core=1 -o core=3 -o core=5</code><br>or <code>-o core=1,core=3,core=5</code></li></ul><p><strong>Restrictions:</strong></p><ul><li>Core IDs must be unique and available on the system.</li><li>Cannot be used concurrently with the <code>num_cores</code> parameter.</li><li>Core 0 is reserved for system use and cannot be assigned.</li></ul></td><td></td><td>Yes</td></tr><tr><td><code>net=&#x3C;netdev>[/&#x3C;ip>/&#x3C;bits>[/&#x3C;gateway>]]</code></td><td><p>Specifies network devices for WEKA client connections. Required for on-premises installations.</p><p>Format:</p><ul><li>Single device: <code>-o net=eth1</code></li><li>Multiple devices: <code>-o net=eth1 -o net=eth2 -o net=eth3</code></li></ul><p><strong>Important</strong>:</p><ul><li>For VF-based configurations, the number of network devices usually must equal <code>num_cores</code></li><li>For NVIDIA VF single-IP configurations, set <code>nvidia_vf_single_ip=true</code>. In that mode, this rule does not apply.</li><li>Supports both physical NICs and virtual functions</li><li>Must specify at least one network device</li></ul><p>For additional options, see <a data-mention href="#advanced-network-configuration-for-stateless-clients">#advanced-network-configuration-for-stateless-clients</a></p></td><td></td><td>Yes</td></tr><tr><td><code>remove_after_secs=&#x3C;secs></code></td><td>The time in seconds without connectivity, after which the client is removed from the cluster.<br>Minimum value: <code>60</code> seconds.<br><code>3600</code> seconds = 1 hour.</td><td><code>3600</code></td><td>Yes</td></tr><tr><td><code>traces_capacity_mb=&#x3C;size-in-mb></code></td><td><p>Traces capacity limit in MB.</p><p>Minimum value: 512 MB.</p></td><td></td><td>No</td></tr><tr><td><code>reserve_1g_hugepages=&#x3C;true or false></code></td><td>Controls the page allocation algorithm to reserve hugepages.<br><strong>Values:</strong><br><code>true</code>: reserves 1 GB<br><code>false</code>: reserves 2 MB</td><td><code>true</code></td><td>Yes</td></tr><tr><td><code>readahead_kb=&#x3C;readahead></code></td><td>The readahead size in KB per mount. A higher readahead is better for sequential reads of large files.</td><td><code>32768</code></td><td>Yes</td></tr><tr><td><code>auth_token_path</code></td><td>The path to the mount authentication token (per mount).</td><td><code>~/.weka/auth-token.json</code></td><td>No</td></tr><tr><td><code>nvidia_vf_single_ip=&#x3C;true or false></code></td><td><p>Treats an NVIDIA VF as a single IP resource.</p><p>Set this option when an NVIDIA VF configuration requires single-IP mapping and the behavior is not detected automatically.</p><p>This option lets multiple frontend processes share the same VF/IP mapping.</p></td><td><code>false</code></td><td>No</td></tr><tr><td><code>dedicated_mode</code></td><td><p>Controls CPU core allocation for DPDK networking.</p><p>Set to <code>full</code> to dedicate an entire core to network processing, or <code>none</code> to operate without core dedication (requires NIC driver support).</p><p>Only applies when DPDK networking is enabled (<code>net=udp</code> not set). See <a href="/pages/-Liq-zdnnpaS84PR-4fp#dpdk-without-the-core-dedication">DPDK without the core dedication</a>.</p><p><strong>Values:</strong> <code>full</code>, <code>none</code></p></td><td><code>full</code></td><td>Yes</td></tr><tr><td><code>qos_preferred_throughput_mbps</code></td><td>Specifies the preferred request rate for Quality of Service (QoS), in megabytes per second. This is a soft target used to guide bandwidth allocation. The system aims to maintain this rate under normal conditions but allows the frontend to exceed it, up to the maximum, when additional resources are available.<br>The cluster admin can set the default value. See <a href="#set-mount-option-default-values">Set mount option default values</a>.</td><td><code>0</code> (unlimited)<br></td><td>Yes</td></tr><tr><td><code>qos_max_throughput_mbps</code></td><td>Specifies the maximum request rate for Quality of Service (QoS), in megabytes per second. This is an average-based limit applied at the front end. The system allows short bursts above this value but aims to maintain the specified limit over time.<br>The cluster admin can set the default value. See <a href="#set-mount-option-default-values">Set mount option default value</a>.</td><td><code>0</code> (unlimited)</td><td>Yes</td></tr><tr><td><code>qos_max_ops</code></td><td>Maximum number of IO operations a client can perform per second.<br>Set a limit to a client or clients to prevent starvation from the rest of the clients. (Do not set this option for mounting from a backend.)</td><td><code>0</code> (unlimited)</td><td>Yes</td></tr><tr><td><code>connect_timeout_secs</code></td><td>The timeout, in seconds, for establishing a connection to a single server. </td><td><code>10</code></td><td>Yes</td></tr><tr><td><code>response_timeout_secs</code></td><td>The timeout, in seconds, waiting for the response from a single server.</td><td><code>60</code></td><td>Yes</td></tr><tr><td><code>join_timeout_secs</code></td><td>The timeout, in seconds, for the client container to join the Weka cluster.</td><td><code>360</code></td><td>Yes</td></tr><tr><td><code>dpdk_base_memory_mb</code></td><td>The base memory in MB to allocate for DPDK. Set this option when mounting to a WEKA cluster on GCP.<br>Example: <code>-o dpdk_base_memory_mb=16</code></td><td><code>0</code></td><td>Yes</td></tr><tr><td><code>weka_version</code></td><td>The WEKA client version to run.</td><td>Cluster version</td><td>No</td></tr><tr><td><code>restricted</code></td><td>Restricts a stateless client’s operations to only the essential APIs for mounting and unmounting operations.</td><td></td><td>No</td></tr></tbody></table>

{% hint style="info" %}
The additional mount options parameters above are only effective on the first mount command for each client, unless stated otherwise.
{% endhint %}

### Client QoS mount options

Use client QoS mount options to cap frontend throughput and IOPS for stateless clients.

Look for these options in the stateless client mount table:

* `qos_max_ops`: Sets the maximum client IOPS.
* `qos_max_throughput_mbps`: Sets the maximum client throughput.
* `qos_preferred_throughput_mbps`: Sets the preferred client throughput target.

{% hint style="info" %}
By default, the command selects the optimal core allocation for WEKA. If necessary, multiple `core` parameters can be used to allocate specific cores to the WEKA client. For example, `mount -t wekafs -o core=2 -o core=4 -o net=ib0 backend-server-0/my_fs /mnt/weka`
{% endhint %}

{% hint style="success" %}
**Example: On-Premise Installations**

`mount -t wekafs -o num_cores=1 -o net=ib0 backend-server-0/my_fs /mnt/weka`

Running this command on a server installed with the Weka agent downloads the appropriate WEKA version from the `backend-server-0`and creates a WEKA container that allocates a single core and a named network interface (`ib0`). Then it joins the cluster that `backend-server-0` is part of and mounts the filesystem `my_fs` on `/mnt/weka.`

`mount -t wekafs -o num_cores=0 -o net=udp backend-server-0/my_fs /mnt/weka`

Running this command uses [UDP mode ](/weka-system-overview/networking-in-wekaio#udp-mode)(usually selected when the use of DPDK is not available).
{% endhint %}

{% hint style="success" %}
**Example: AWS Installations**

`mount -t wekafs -o num_cores=2 backend1,backend2,backend3/my_fs /mnt/weka`

Running this command on an AWS EC2 instance allocates two cores (multiple-frontends), attaches and configures two ENIs on the new client. The client attempts to rejoin the cluster through all three backends specified in the command line.
{% endhint %}

For stateless clients, the first `mount` command serves a dual purpose:

1. It installs the WEKA client software.
2. It joins the WEKA cluster.

Subsequent `mount` commands can be simplified, requiring only the persistent or per-mount parameters as defined in the [#mount-command-options](#mount-command-options "mention"). The full cluster configuration is not needed for these additional mounts.

WEKA filesystems can be accessed directly through the mount point. You can navigate to the filesystem using standard directory commands, such as `cd /mnt/weka/`.

When the final WEKA filesystem is unmounted using the `umount` command, two key actions occur:

* The client is automatically disconnected from the cluster.
* The WEKA client software is uninstalled by the agent.

As a result, initiating a new `mount` operation requires re-specifying the complete cluster configuration, including cluster details, cores, and networking parameters.

{% hint style="info" %}
When running in AWS, the instance IAM role must provide permissions to several AWS APIs (see the [IAM role created in template](broken://pages/-L7TzTC5r8BR5kqD5J-u#iam-role-created-in-the-template) section).
{% endhint %}

{% hint style="info" %}
Memory allocation for a client is predefined. To change the memory allocation, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}

### Remount options for stateless clients

Mount options explicitly marked as `Remount Supported` can be modified using the `mount -o remount` command. During a remount operation:

* Unspecified mount options retain their current configuration.
* To reset a specific option to its default value, use the `default` modifier.

Example of resetting an option to its default:

* `memory_mb=default` restores the default memory configuration.

This approach allows for flexible, granular adjustments to mount parameters without requiring a complete filesystem unmount and remount.

{% hint style="info" %}
Remounting a stateless client restarts the client container. Once the restart process is complete, all active I/O operations of that client resume automatically.
{% endhint %}

### Set mount option default values <a href="#set-mount-option-default-values" id="set-mount-option-default-values"></a>

#### Default throughput settings

* By default, `qos_max_throughput_mbps` and `qos_preferred_throughput_mbps` are unset, meaning no throughput limit is enforced.

#### Cluster administrator capabilities

* Set custom default values aligned with organizational requirements.
* Reset to initial unlimited configuration.
* View current default settings.

#### Key characteristics

* QoS settings apply to the frontend process, not individual mounts. All mounts on the same frontend share the same QoS limits.
* If a client connects to multiple WEKA clusters, each frontend enforces its QoS settings independently.
* Default value changes only affect new mounts. Existing mounts retain the QoS values they were created with.

#### Available commands

* Set defaults: `weka cluster mount-defaults set`
* Reset to initial values: `weka cluster mount-defaults reset`
* Display current defaults: `weka cluster mount-defaults show`

#### Command syntax

{% code overflow="wrap" %}

```
weka cluster mount-defaults set [--qos-max-throughput qos-max-throughput] [--qos-preferred-throughput qos-preferred-throughput]
```

{% endcode %}

**Parameters**

<table><thead><tr><th width="249.9453125">Option</th><th>Description</th></tr></thead><tbody><tr><td><code>qos_max_throughput</code></td><td>Specifies the default maximum request rate for Quality of Service (QoS), in megabytes per second. This is an average-based limit applied at the frontend. The system allows short bursts above this value but aims to maintain the specified limit over time.</td></tr><tr><td><code>qos_preferred_throughput</code></td><td>Specifies the default preferred request rate for Quality of Service (QoS), in megabytes per second. This is a soft target used to guide bandwidth allocation. The system aims to maintain this rate under normal conditions but allows the frontend to exceed it, up to the maximum, when additional resources are available.</td></tr></tbody></table>

### Monitor active mounts per container

Tracking the number of active mounts per container is important for troubleshooting, validating mount configurations, and identifying potential issues in the WEKA cluster. It provides visibility into mount activity, helping users and automation tools detect anomalies and ensure expected behavior.

To view the active mount count for a specific container, read the following `/proc` interface:

```
/proc/wekafs/<container-name>/interface
```

***

## Advanced network configuration for stateless clients

Stateless clients allow for customizable network configurations to enhance performance and connectivity. The following parameters can be adjusted:

* Virtual Functions (VFs)
* IP addresses
* Gateway configuration (required if the client is on a different subnet)
* Physical network devices (for improved performance and high availability)
* UDP mode

To configure networking, use the `-o net=<netdev>` mount option with the appropriate modifiers.

#### **Identify `<netdev>`**

`<netdev>` can be specified using:

* Network interface name
* MAC address
* PCI address of the physical network device
* Bonded device for redundancy and load balancing

#### **Networking technology compatibility**

When using WEKA mounts (`wekafs`), ensure that clients and backends use the same network type. Supported options include InfiniBand (IB) or Ethernet.

#### **Key considerations**

* The `-o net=<netdev>` option provides detailed control over network interfaces.
* Selecting the appropriate configuration helps optimize performance and connectivity.
* Consistent networking technology is essential for system reliability.

### **Configure IP, subnet, gateway, and Virtual Functions (VFs)**

For improved performance, multiple frontend processes may be required. When using a Network Interface Card (NIC) other than Mellanox, or when deploying a DPDK client on a virtual machine (VM), **Single Root I/O Virtualization (SR-IOV)** must be used to expose a **Virtual Function (VF)** of the physical device to the client. Once exposed, the VF can be configured using the `mount` command.

#### **Assign VF IP addresses and routing**

To assign an IP address to a VF or to enable routing when the client is in a different subnet, use the following format:

```bash
net=<netdev>/[ip]/[bits]/[gateway]
```

* `ip`, `bits`, and `gateway` are optional parameters.
* If these parameters are not provided, the WEKA system assigns values based on the environment:
  * **Cloud environment**: The system automatically deduces the IP address, subnet mask, and gateway.
  * **On-premises environment**: The system assigns values based on the cluster’s default network configuration.
    * If the default network is not set, the WEKA cluster may fail to allocate an IP address for the client.

#### Use NVIDIA VF single-IP mode

Use NVIDIA VF single-IP mode for exposed NVIDIA VFs that must be handled as a single IP resource during a stateless mount.

**Before you begin**

* Confirm the client uses an NVIDIA VF.
* Confirm the environment requires single-IP VF mapping.
* Confirm this behavior is not detected automatically.

**Procedure**

1. Specify the VF in the `net=` mount option.
2. Add `-o nvidia_vf_single_ip=true` to the mount command.
3. Set `num_cores` based on the required frontend processes.

When NVIDIA VF single-IP mode is enabled, multiple frontend processes can share the same VF/IP mapping. In this mode, the number of configured `net=` devices does not need to equal `num_cores`.

For resource-based client creation, set the `nvidia_vf_single_ip` parameter to `true`.

**Example**

{% code overflow="wrap" %}

```bash
mount -t wekafs \
-o num_cores=4 \
-o net=eth1/192.168.1.100/24/192.168.1.254 \
-o nvidia_vf_single_ip=true \
backend1/my_fs /mnt/weka
```

{% endcode %}

Use this option only for NVIDIA VF environments that require single-IP mapping for correct connectivity.

{% hint style="warning" %}
**Important:** Ensure that the **WEKA cluster default data networking** is configured before executing the `mount` command. For configuration details, see /pages/ospkBUXCQGIqEwyRlWwn#id-6.-configure-default-data-networking-optional.
{% endhint %}

#### **Example: Configuring VFs on a single physical network device**

The following command configures VFs for a specified network device and assigns each VF to a frontend process.

* The first frontend process is assigned **192.168.1.100**.
* The second frontend process is assigned **192.168.1.101**.
* Both IPs are configured with a **24-bit subnet mask** and a **default gateway of 192.168.1.254**.

{% code overflow="wrap" %}

```bash
mount -t wekafs -o num_cores=2 -o net=intel0/192.168.1.100+192.168.1.101/24/192.168.1.254 backend1/my_fs /mnt/weka
```

{% endcode %}

### Multiple physical network devices for performance and high availability

Utilizing multiple physical network interface cards (NICs) on a WEKA client can unlock significant gains in data throughput and enhance system resilience. By strategically distributing network traffic across several interfaces, you can overcome single-NIC bottlenecks for demanding applications and ensure continuous data access even if one network path fails.

This section delves into the various methods for configuring and managing multiple NICs with WEKA. It covers how to:

* Aggregate NICs for increased overall performance.
* Set up redundant configurations to achieve high availability.
* Implement advanced NUMA-aware setups for optimal efficiency on multi-socket servers.
* Use specific mount options, including detailed slot notation, to precisely control how client processes uses the available network interfaces.

The following subsections provide detailed explanations and practical examples for each of these configurations, enabling you to tailor your WEKA client's network setup to your specific performance and availability requirements.

<details>

<summary>Multiple physical network devices for better performance</summary>

Demanding workloads on WEKA can readily saturate the bandwidth of a single network interface. For higher throughput, you can leverage multiple network interface cards (NICs). By using the `-o net=<interface>` mount option for each desired NIC, you instruct the WEKA client driver to utilize these specific interfaces, potentially distributing the load and increasing overall bandwidth.

For example, the following command allocates two cores and two physical network devices for increased throughput:

```bash
mount -t wekafs \
-o num_cores=2 \
-o net=mlnx0 -o net=mlnx1 \
backend1/my_fs /mnt/weka
```

</details>

<details>

<summary>Multiple physical network devices for high availability configuration</summary>

Multiple NICs can also be configured to achieve redundancy and higher throughput for a complete, highly available solution. For that, use more than one physical device as previously described, and also, specify the client management IPs using `-o mgmt_ip=<ip1>+<ip2>` command-line option.

For example, the following command uses two network devices (`mlnx0` and `mlnx1`) for high availability and allocates both devices to four Frontend processes on the client(because `num_cores=4`). The modifier `ha` is used here, which stands for using the device on all processes. Note that in this example, `10.0.0.1` is the IP address of `mlnx0` while `10.0.0.2` is the IP address of `mlnx1`.

{% code overflow="wrap" %}

```bash
mount -t wekafs \
-o num_cores=4 \
-o net:ha=mlnx0,net:ha=mlnx1 \
-o mgmt_ip=10.0.0.1+10.0.0.2 \
backend1/my_fs /mnt/weka
```

{% endcode %}

{% hint style="info" %}
The `mgmt_ip` option identifies management processes on the data plane network. It does not identify external management interfaces such as the CLI or REST API.
{% endhint %}

</details>

<details>

<summary>Advanced configuration: NUMA affinity with multiple physical network devices and sockets</summary>

For more complex systems, especially those with multiple CPU sockets and NUMA (Non-Uniform Memory Access) nodes, you can achieve higher performance and efficiency by pinning client processes and their network traffic to specific NUMA nodes. This involves assigning cores from a specific NUMA node to WekaFS client processes and then mapping these processes to a network interface card (NIC) physically located on the same NUMA node.

Consider a server with four NUMA nodes and four InfiniBand (IB) network interfaces, where each IB interface is assumed to reside on a different NUMA node. The NUMA configuration of the CPUs is as follows:

* NUMA node0 CPU(s): 0-63
* NUMA node1 CPU(s): 64-127
* NUMA node2 CPU(s): 128-191
* NUMA node3 CPU(s): 192-255

Let's assume you have four IB interfaces: `ib0` (on NUMA node0), `ib1` (on NUMA node1), `ib2` (on NUMA node2), and `ib3` (on NUMA node3). To configure WekaFS for optimal NUMA affinity, you would pin specific cores from each NUMA node to WekaFS frontend processes and then map these groups of processes to their corresponding NUMA-local IB interface. Management IPs must also be specified for high availability.

**Example:**

The following command configures 16 WekaFS client processes. Four processes are pinned to cores on each of the four NUMA nodes. Each group of four processes is then mapped to its local IB interface.

```
mount -t wekafs \
-o core=63 -o core=62 -o core=61 -o core=60 \
-o core=127 -o core=126 -o core=125 -o core=124 \
-o core=191 -o core=190 -o core=189 -o core=188 \
-o core=255 -o core=254 -o core=253 -o core=252 \
-o net:s1-4=ib0 \
-o net:s5-8=ib1 \
-o net:s9-12=ib2 \
-o net:s13-16=ib3 \
backend_servers/my_fs /mnt/weka
```

**Explanation of the options in this example:**

* **`-o core=...`**: Sixteen specific CPU cores are assigned to WekaFS client processes:
  * Cores 63, 62, 61, 60 are on NUMA node0.
  * Cores 127, 126, 125, 124 are on NUMA node1.
  * Cores 191, 190, 189, 188 are on NUMA node2.
  * Cores 255, 254, 253, 252 are on NUMA node3. This creates 16 frontend processes, with each group of four processes affinitized to a specific NUMA node.
* **`-o net:s1-4=ib0, net:s5-8=ib1, net:s9-12=ib2, net:s13-16=ib3`**: These options use the "multiple NIC slot notation" to map the WekaFS client processes (referred to by "slots") to the specified network interfaces (`ib0`, `ib1`, `ib2`, `ib3`). In this configuration with 16 frontend processes, the intended mapping is:
  * The first group of four processes (running on cores 63,62,61,60 on NUMA0) uses `ib0` (assumed to be on NUMA0).
  * The second group of four processes (running on cores 127,126,125,124 on NUMA1) uses `ib1` (assumed to be on NUMA1).
  * The third group of four processes (running on cores 191,190,189,188 on NUMA2) uses `ib2` (assumed to be on NUMA2).
  * The fourth group of four processes (running on cores 255,254,253,252 on NUMA3) uses `ib3` (assumed to be on NUMA3). This setup ensures that network traffic for processes on a given NUMA node utilizes the NIC local to that NUMA node, minimizing cross-NUMA data transfers and potentially improving performance.
* **`backend_servers/my_fs`**: Replace with your WekaFS backend server address(es) and filesystem name.
* **`/mnt/weka`**: Replace with your desired mount point.

This type of granular configuration is beneficial for maximizing throughput and minimizing latency in high-performance computing (HPC) and AI workloads that are sensitive to NUMA effects.

</details>

<details>

<summary>Advanced mounting options for multiple physical network devices</summary>

With multiple Frontend processes (as expressed by `-o num_cores=X`), it is possible to control what processes use what NICs. This can be accomplished through the use of special command line modifiers called *slots*. In WEKA, *slot* is synonymous with a process number. Typically, the first WEKA Frontend process will occupy slot 1, then the second - slot 2 and so on.

Examples of slot notation include `s1`, `s2`, `s2+1`, `s1-2`, `slots1+3`, `slot1`, `slots1-4` , where `-` specifies a range of devices, while `+` specifies a list. For example, `s1-4` implies slots 1, 2, 3, and 4, while `s1+4` specifies slots 1 and 4.

For example, in the following command, `mlnx0` is bound to the second Frontend process while `mlnx1` to the first one for improved performance.

{% code overflow="wrap" %}

```bash
mount -t wekafs \
-o num_cores=2 -o net:s2=mlnx0,net:s1=mlnx1 \
backend1/my_fs /mnt/weka
```

{% endcode %}

For exampl&#x65;**,** in the following mounting command, two cores (two Frontend processes) and two physical network devices (`mlnx0`, `mlnx1`) are allocated. By explicitly specifying `s2+1`, `s1-2` modifiers for network devices, both devices will be used by both Frontend processes. Notation `s2+1` stands for the first and second processes, while `s1-2` stands for the range of 1 to 2, and are effectively the same.

{% code overflow="wrap" %}

```bash
mount -t wekafs \
-o num_cores=2 \
-o net:s2+1=mlnx0,net:s1-2=mlnx1 \
backend1/my_fs \
-o mgmt_ip=10.0.0.1+10.0.0.2 /mnt/weka
```

{% endcode %}

{% hint style="info" %}
The `mgmt_ip` option identifies management processes on the data plane network. It does not identify external management interfaces such as the CLI or REST API.
{% endhint %}

</details>

### Network label configuration for stateless clients

In environments with stateless clients and high-availability backend networks, configuring network labels is essential for optimizing data path locality and minimizing inter-switch traffic.

Stateless clients, which typically lack persistent state or configuration storage, often connect to a single top-of-rack switch. In contrast, backend servers are usually dual-connected across multiple switches to ensure high availability. In topologies where these switches are interconnected via inter-switch links (ISLs), traffic between nodes may traverse these ISLs unnecessarily if peer selection is left to default behavior. This can introduce additional latency and consume limited east-west bandwidth.

To influence peer selection and ensure efficient traffic routing, stateless clients can use **network labels**. These labels bind the client’s traffic to a specific network segment or switch, helping ensure that peering remains within the local switch when possible.

**Use case**

This configuration is especially beneficial in:

* Two-switch topologies with ISL connections.
* Deployments where backend nodes are dual-attached and clients are single-attached.
* Scenarios requiring controlled peering to reduce east-west traffic.

**Configuration**

To assign a network label, use the `-o net` mount option in the following format:

```
mount -t wekafs -o net=<device>/label@<label> <filesystem> <mountpoint>
```

**Parameters:**

* `<device>`: The name of the client’s network interface (for example, `eth0`).
* `<label>`: The label that corresponds to the client’s network attachment point.
* `<filesystem>`: The WEKA filesystem to mount.
* `<mountpoint`>: The local directory where the filesystem will be mounted.

**Example:**

```
mount -t wekafs -o net=eth0/label@datacenter-a  project-fs1/data
```

In this example:

* The client uses the `eth0` interface.
* The label `datacenter-a` indicates the switch or network zone the interface is connected to.
* The `project-fs1` WEKA filesystem is mounted at `/data`.

By using a label that reflects the client’s physical or logical network location, the system can make more informed decisions about peering and data path selection, reducing cross-switch communication and improving overall performance.

**Remount support**

The network label configuration using the `-o net` option is also supported during remount operations. This allows administrators to change the network label dynamically without needing to fully unmount and remount the filesystem. For example:

```
mount -o remount,net=eth0/label@datacenter-b /data
```

In this scenario, the client updates the network label to datacenter-b for the existing mount at `/data`. This flexibility is useful when network topology or client attachment changes, allowing adjustments to peering behavior with minimal disruption.

**Related topic**

[Networking](/weka-system-overview/networking-in-wekaio#high-availability)

### UDP mode

If DPDK cannot be used, you can use the WEKA filesystem UDP networking mode through the kernel. Use `net=udp` in the mount command to set the UDP networking mode, for example:

```bash
mount -t wekafs -o net=udp backend-server-0/my_fs /mnt/weka
```

{% hint style="info" %}
A client in UDP mode cannot be configured in high availability mode (`ha`). However, the client can still work with a highly available cluster.
{% endhint %}

{% hint style="info" %}
Providing multiple IPs in the \<mgmt-ip> in UDP mode uses their network interfaces for more bandwidth, which can be useful in RDMA environments rather than using only one NIC.
{% endhint %}

**Related topic**

[Networking](/weka-system-overview/networking-in-wekaio#udp-mode) (in the WEKA Networking topic)

***

## Mount a filesystem using fstab

Using the fstab (filesystem table) enables automatic remount after a reboot. This applies to stateless clients running on an OS that supports systemd, such as RHEL/CentOS 7.2 and up, Ubuntu 16.04 and up, and Amazon Linux 2 LTS.

#### Before you begin

* If the mount point you want to set in the fstab is already mounted, unmount it before setting the fstab file.

#### Procedure

1. **Create a mount point:** Run the following command to create a mount point:

```
mkdir -p /mnt/weka/my_fs  
```

2. **Edit the `/etc/fstab` file:** Add the entry for the WEKA filesystem.

**fstab structure**

{% code overflow="wrap" %}

```php-template
<backend servers/my_fs> <mount point> <filesystem type> <mount options> <systemd mount options> 0 0  
```

{% endcode %}

**Example**

{% code overflow="wrap" %}

```
backend-0,backend-1,backend-3/my_fs /mnt/weka/my_fs wekafs num_cores=1,net=eth1,x-systemd.after=weka-agent.service,x-systemd.mount-timeout=infinity,_netdev 0 0  
```

{% endcode %}

**fstab configuration parameters**

<table><thead><tr><th width="298">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>Backend servers/my_fs</td><td>Comma-separated list of backend servers with the filesystem name.</td></tr><tr><td>Mount point</td><td><p>If mounting multiple clusters, specify a unique name.</p><p>For two client containers, set <code>container_name=client1</code> and <code>container_name=client2</code>.</p></td></tr><tr><td>Filesystem type</td><td>Must be <code>wekafs</code>.</td></tr><tr><td>Systemd mount options</td><td><ul><li><code>x-systemd.after=weka-agent.service</code></li><li><code>x-systemd.mount-timeout=infinity</code></li><li><code>_netdev</code></li></ul><p>Adjust the mount-timeout to your preference, for example, 180 seconds.</p></td></tr><tr><td>Mount options</td><td>See <a data-mention href="#additional-mount-options-using-the-stateless-clients-feature">#additional-mount-options-using-the-stateless-clients-feature</a></td></tr></tbody></table>

3. **Mount the filesystem:** Test the fstab setting by running:

```
mount /mnt/weka/my_fs  
```

4. **Reboot the server:** Reboot the server to apply the fstab settings. The filesystem is automatically mounted after the reboot.

***

## Mount a filesystem using autofs

Autofs allows filesystems to be mounted dynamically when accessed and unmounted after a period of inactivity. This approach reduces system overhead and ensures efficient resource utilization. Follow these steps to configure autofs for mounting Weka filesystems.

#### Procedure

1. **Install autofs on the server:** Install the autofs package based on your operating system:
   * **For Red Hat or CentOS**:

     ```
     yum install -y autofs
     ```
   * **For Debian or Ubuntu**:

     ```
     apt-get install -y autofs
     ```
2. **Configure autofs for WEKA filesystems:** Set up the autofs configuration files according to the client type:
   * **Stateless client**: Run the following commands, replacing `<backend-1>`, `<backend-2>`, and `<netdevice>` with appropriate values:

     <pre data-overflow="wrap"><code>echo "/mnt/weka /etc/auto.wekafs -fstype=wekafs,num_cores=1,net=&#x3C;netdevice>" > /etc/auto.master.d/wekafs.autofs
     echo "* &#x3C;backend-1>,&#x3C;backend-2>/&#x26;" > /etc/auto.wekafs
     </code></pre>
   * **Persistent client**: Run the following commands:

     <pre data-overflow="wrap"><code>echo "/mnt/weka /etc/auto.wekafs -fstype=wekafs" > /etc/auto.master.d/wekafs.autofs
     echo "* &#x26;" > /etc/auto.wekafs
     </code></pre>
3. **Restart the autofs service:** Apply the changes by restarting the autofs service:

   ```
   service autofs restart
   ```
4. **Ensure autofs starts automatically on reboot:** Verify that autofs is configured to start on reboot:

   ```bash
   systemctl is-enabled autofs
   ```

   * If the output is `enabled`, no further action is required.

   **For Amazon Linux**: Use `chkconfig` to confirm autofs is enabled for the current runlevel:

   ```
   chkconfig | grep autofs
   ```

   Ensure the output indicates `on` for the active runlevel.\
   Example output:

   ```
   autofs 0:off 1:off 2:off 3:on 4:on 5:on 6:off
   ```
5. **Access the WEKA filesystem:** Navigate to the mount point to access the WEKA filesystem. Replace `<fs-name>` with the desired filesystem name:

   ```
   cd /mnt/weka/<fs-name>
   ```

{% hint style="info" %}

* Adjust backend and network device configurations as needed for your deployment.
* Review distribution-specific documentation for additional configuration options.
  {% endhint %}


# Mount filesystems from Single Client to Multiple Clusters (SCMC)

Mount a single stateless WEKA client to multiple clusters simultaneously, optimizing data access and workload distribution.

## Overview

Mounting filesystems from a single stateless WEKA client to multiple clusters provides the following benefits:

* **Expanded cluster connectivity:** A single stateless client can establish connections with up to seven clusters concurrently, thereby increasing the aggregate storage capacity and computational resources available.
* **Unified data access:** Enables a consolidated view of data across multiple clusters, streamlining data access and management while improving availability, flexibility, and overall resource utilization.
* **Optimized workload distribution:** Facilitates the efficient distribution of workloads across clusters, supporting scalable application deployments and enhancing system performance.
* **Seamless integration:** The WEKA SCMC feature ensures reliable and efficient integration for stateless clients requiring access to multiple clusters.

<div data-with-frame="true"><figure><img src="/files/zlJZNnif8lIW1R1e6Rbr" alt=""><figcaption><p>Mount filesystems from Single Client to Multiple Clusters (SCMC)</p></figcaption></figure></div>

### **Bandwidth division considerations in SCMC**

The bandwidth division in SCMC is a universal consideration based on the specific NIC's bandwidth. It applies across various NIC types, including those using DPDK or specific models like the X500-T1.

During SCMC mounts, each active connection can use the bandwidth available on its associated NIC port. This is true during peak usage and idle cases. In scenarios where NICs are dual-ported, each connection operates independently, leveraging its dedicated port.

When working with low-bandwidth NICs such as the X500-T1, a 10Gb/s NIC, consider bandwidth calculations. In the context of SCMC, each container (representing connectivity to a different cluster) uses half of the available bandwidth (5Gb/s) for a shared port. Note that a dual-port NIC has a dedicated port for each container, optimizing bandwidth distribution. Keep these factors in mind for an optimal SCMC setup.

## Prerequisites

Ensure the following requirements are met:

* All clusters that run in this configuration must be at least version 4.2.
* All client containers in the WEKA client must run the same minor version, at least version 4.2. The client version must be the same as the cluster or, at most, one version earlier.
* All client containers must be configured as stateless clients.
* Each client container must run on its port. The default ports are 14000, 14101, 14201, 14301, 14401, 14501, and 14601. Ensure these ports allow egress on the client and ingress on the cluster.
* For DPDK, each client container must have 5 GB of free RAM, and it is recommended to have a dedicated CPU core to get optimal performance.

Mounting a filesystem without these requirements may fail or overload the WEKA client.

## Set the client target version in the clusters

When a stateless client mounts a filesystem in a cluster, it creates a client container with the same version as provided by the cluster. Because there may be situations where some of the clusters run a different WEKA version than the others, such as during an upgrade, it is required to set the same client target version on all clusters. The client target version is retained regardless of the cluster upgrade.

{% hint style="warning" %}
The client target version must be consistent across all clusters. It can match the cluster version or be one major version earlier (regardless the minor), provided that version is available in the cluster for client download.

To upgrade the cluster to a version higher than the first major release above the client version, see [Upgrade WEKA versions](/operation-guide/upgrading-weka-versions).
{% endhint %}

#### Procedure:

1. Connect to each cluster and run the following command to set the client target version.

```bash
weka cluster client-target-version set <version>
```

Where: `<version>` is the designated client target version, which will be installed on the client container upon the mount command. Ensure this version is installed on the backend servers.

2. To display the existing client target version in the cluster, run the following command:

```bash
weka cluster client-target-version show
```

3. To reset the client target version to the cluster version, run the following command:

```bash
weka cluster client-target-version reset
```

## Mount a stateless client container on multiple clusters

Use the same commands as with a single client.

{% code overflow="wrap" %}

```bash
mount -t wekafs <backend-name> <fs-name> <mount-point> -o container_name=<container-name>
```

{% endcode %}

To mount a stateless client using UDP mode, add `-o net=udp -o core=<core-id>` to the command line. For example:

{% code overflow="wrap" %}

```bash
mount -t wekafs backend-server-0/my_fs /mnt/weka -o net=udp -o core=2 -o container_name=frontend0
```

{% endcode %}

## Run commands from a server with multiple client containers

When running WEKA CLI commands from a server hosting multiple client containers, each connected to a different WEKA cluster, it’s required to specify the client container port or the backend IP address/name of the cluster (linked to that client) in the command.

Consider a server with two client containers:

```bash
weka local ps
CONTAINER  STATE    DISABLED  UPTIME    MONITORING  PERSISTENT  PORT   PID    STATUS  VERSION LAST FAILURE
client1    Running  False     3:15:57h  True        False       14000  58318  Ready   4.3.0
client2    Running  False     3:14:35h  True        False       14101  59529  Ready   4.3.0
```

To run a WEKA CLI command on the second cluster (associated with `client2`), use either of the following methods:

* By specifying the backend IP address or name linked to that client container (assuming the backend name is `DataSphere2-1`):

  ```
  weka status -H DataSphere2-1
  ```
* By specifying the client container port:

  ```
  weka status -P 14101
  ```

This approach ensures that your WEKA CLI command targets the correct WEKA cluster associated with the specified client container.

#### Related topics

[Add clients](/planning-and-installation/bare-metal/adding-clients-bare-metal)

[Mount filesystems](/weka-filesystems-and-object-stores/mounting-filesystems)


# Manage authentication across multiple clusters with connection profiles

Learn how to manage authentication across multiple clusters in the WEKA CLI using connection profiles, enabling seamless switching between clusters without re-authentication.

## Overview

Managing authentication across multiple clusters in the WEKA CLI is streamlined with connection profiles. By default, when you run the `weka user login` command, it creates a profile stored as `.weka/auth-token.json`. This is sufficient for single-cluster environments. However, in a multi-cluster environment, use the `--profile` parameter to create and manage separate profiles for each cluster. This allows you to switch between clusters without needing to re-authenticate each time, enhancing efficiency and usability.

**Profile naming conventions**

When creating a connection profile, follow these guidelines:

* **Maximum length:** 50 characters
* **Allowed characters:**
  * Alphanumeric (A-Z, a-z, 0-9)
  * Underscores (\_)
  * Hyphens (-)

Profile names dictate where authentication details are stored in the `.weka` directory:

* **Default profile:** `.weka/auth-token.json`
* **Named profiles:** `.weka/auth-token-<profile-name>.json`

## **Log in with profiles**

The `weka user login` command supports profiles, enabling you to specify which profile to use or create a new one.

**Command syntax:**

```bash
weka user login --profile <profile-name>
```

* **Default profile:** If no profile is specified, the system uses the default profile.
* **Profile-specific file:** Authentication information is saved in a file named after the profile.
* **Success message:** After a successful login, the following message appears:

  ```bash
  Login completed successfully.
  <Default/profileN> profile updated.
  ```
* **Failure message:** If the profile is not found or the login fails, an error message displays the profile name and file path.

## **Log out of profiles**

The `weka user logout` command supports profiles, enabling you to remove the authentication details for a specific profile.

**Command syntax:**

```
weka user logout --profile <profile-name>
```

* The specified profile’s authentication file is deleted.
* If no profile is specified, the default profile is logged out.

## **Using profiles with WEKA CLI commands**

You can specify a profile when executing most WEKA CLI commands using the `--profile` option. If no profile is provided, the default profile is used.

**Command syntax:**

```
weka <command> --profile <profile-name>
```

{% hint style="info" %}
The `--profile` option is not supported with `weka diag` commands. The default profile is used for diagnostics.
{% endhint %}

**Related topic**

[Mount filesystems from Single Client to Multiple Clusters (SCMC)](/weka-filesystems-and-object-stores/mounting-filesystems/mount-fs-from-scmc)


# Snapshots

Snapshots enable the saving of a filesystem state to a directory and can be used for backup, archiving and testing purposes.

Snapshots allow the saving of a filesystem state to a hidden `.snapshots` directory under the root filesystem. They can be used for:

* **Physical backup:** The snapshots directory can be copied into a different storage system, possibly on another site, using either the WEKA system Snap-To-Object feature or third-party software.
* **Logical backup:** Periodic snapshots enable filesystem restoration to a previous state if logical data corruption occurs.
* **Archive:** Periodic snapshots enable accessing a previous filesystem state for compliance or other needs.
* **DevOps environments:** Writable snapshots enable the execution of software tests on copies of the data.

Snapshots do not impact system performance and can be taken for each filesystem while applications run. They consume minimal space, according to the differences between the filesystem and the snapshots, or between the snapshots, in 4K granularity.

Snapshot space consumption is taken from the free space available in the filesystem. As snapshots grow due to changes in the filesystem, they continue to consume additional space.

{% hint style="info" %}
If the filesystem reaches its free space limit, additional writes may be temporarily restricted until space is freed. In such cases, managing available storage—such as deleting older snapshots or optimizing storage usage—can help maintain smooth system operation.

You can retrieve the estimated reclaimable space using the command: `weka fs snapshot`. See [#working-with-snapshots-considerations](#working-with-snapshots-considerations "mention").
{% endhint %}

You can create a writable snapshot. A writable snapshot cannot be changed to a read-only snapshot.

The WEKA system supports the following snapshot operations:

* View snapshots.
* Create a snapshot of an existing filesystem.
* Delete a snapshot.
* Access a snapshot under a dedicated directory name.
* Restore a filesystem from a snapshot.
* Create a snapshot of a snapshot (relevant for writable snapshots or read-only snapshots before being made writable).
* List the snapshots and obtain their metadata.
* Schedule automatic snapshots. For details, see [Snapshot policies](/weka-filesystems-and-object-stores/snapshot-policies).

To access the hidden `.snapshot` directory, see [/pages/ZXv8pQvcGrZTRm69WKqN#access-the-.snapshots-directory](https://docs.weka.io/weka-filesystems-and-object-stores/pages/ZXv8pQvcGrZTRm69WKqN#access-the-.snapshots-directory "mention").

## Working with snapshots considerations

* **Do not move a file within a snapshot directory or between snapshots:**\
  Moving a file within a snapshot directory or between snapshots is implemented as a copy operation by the kernel, similar to moving between different filesystems. However, such operations for directories will fail.
* **Working with symlinks (symbolic links):**\
  When accessing symlinks through the `.snapshots` directory, symlinks with absolute paths can lead to the current filesystem. Depending on your needs, consider either not following symlinks or using relative paths.
* **Snapshot estimated reclaimable space:**\
  The estimated reclaimable space represents the upper limit of capacity that can be freed by deleting a snapshot. It corresponds to the total size of data that is accessible from a snapshot but not from newer snapshots or the active filesystem.

  In snapshot chains without writable snapshots, deleting multiple consecutive snapshots (only the oldest N snapshots) releases the combined total of their respective Estimated Reclaimable Space values.

  Snapshots created before an upgrade to version 4.4 or downloaded from OBS may not have an Estimated Reclaimable Space value available.

## Maximum supported snapshots

The maximum number of snapshots in a system depends on whether they are read-only or writeable.

* If all snapshots are read-only, the maximum is 24K (24,576).
* If all snapshots are writable, the maximum is 14K (14,336).

A system can have a mix of read-only and writable snapshots, given that a writable snapshot consumes about twice the internal resources of a read-only snapshot.

Some examples of mixing maximum read-only and writable snapshots that a system can have:

* 20K read-only and 4K writable snapshots.
* 12K read-only and 8K writable snapshots.

{% hint style="info" %}
A live filesystem is counted as part of the maximum writable snapshots.
{% endhint %}

## Track filesystem changes with the DiffList REST API

Use the DiffList REST API to identify and list changes between two filesystem states, such as two snapshots or a snapshot and the live state. This function supports backup, auditing, and data movement workflows by detecting changes without performing a full filesystem scan.

The DiffList API service runs on a configured and active Data Service container (`dataserv`). You can compare any two filesystem states, regardless of their creation order. For example, you can compare an early snapshot with a more recent one. The API returns paginated results to effectively manage large datasets.

Each change entry provides an operation type (`opType`) that combines the object type and the change action. The entry also includes attributes that describe the event, such as its path, size, and whether it was renamed.

Using the API is a two-step process that supports parallel processing, enabling fast, large-scale change analysis for automated workflows

**Before you begin**

Ensure at least one `dataserv` container is configured and running.

**Procedure**

1. Prepare the change query using the `POST /snapshots/diff/prepare` endpoint to obtain processing tokens.
2. Retrieve the paginated change lists using the `POST /snapshots/diff/getResults` endpoint.

**Related topics**

[Manage snapshots using the GUI](/weka-filesystems-and-object-stores/snapshots/snapshots)

[Manage snapshots using the CLI](/weka-filesystems-and-object-stores/snapshots/snapshots-1)

[WEKA REST API and equivalent CLI commands](/getting-started-with-weka/weka-rest-api-and-equivalent-cli-commands) (Snapshots)

[Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks)


# Manage snapshots using the GUI

This page describes how to manage snapshots using the GUI.

Using the GUI, you can:

* [View snapshots](#view-snapshots)
* [Create a snapshot](#create-a-snapshot)
* [Duplicate a snapshot](#duplicate-a-snapshot)
* [Delete a snapshot](#delete-a-snapshot)
* [Restore a snapshot to a filesystem or another snapshot](#restore-a-snapshot)
* [Update a snapshot](#update-a-snapshot)

## View snapshots

**Procedure**

1. To display all snapshots, select **Manage > Snapshots** from the menu.\
   The Snapshots page opens.

<div data-with-frame="true"><img src="/files/7TBozDiac8aFqqZkpPmT" alt="View all snapshots"></div>

2\. To display a snapshot of a selected filesystem, do one of the following:

* Select the Filesystem filter. Then, select the filesystem from the list.
* From the menu, select **Manage > Filesystems**.\
  From the filesystem, select the three dots, and from the menu, select **Go To Snapshot**.

<div data-with-frame="true"><img src="/files/L8IVpnq4VtkM31fE1llJ" alt="View a snapshot of a specific filesystem"></div>

## Create a snapshot

You can create a snapshot from the **Snapshots page** or directly from the **Filesystems** page.

**Before you begin**

Create a directory for filesystem-level snapshots that serves as the access point for snapshots.

**Procedure:**

1. Do one of the following:
   * From the menu, select **Manage > Snapshots**. From the Snapshots page, select **+Create**.\
     The Create Snapshot dialog opens.
   * From the menu, select **Manage > Filesystems**. From the Filesystems page, select the three dots, and from the menu, select **Create Snapshot** (the source filesystem is automatically set).

<div data-with-frame="true"><img src="/files/0GUFIWTstJ30IJrl0Idw" alt="Create a snapshot from the Snapshots page"></div>

<div data-with-frame="true"><img src="/files/8TkquaZfSsTuXRAi2cqI" alt="Filesystems menu: Create a snapshot directly from a filesystem"></div>

3. On the Create Snapshot dialog set the following properties:
   * **Name**: A unique name for the filesystem snapshot.
   * **Access Point**: A name of the newly-created directory for filesystem-level snapshots that serves as the snapshot's access point. If you do not specify the access point, the system sets it automatically (in GMT format).
   * **Writable**: Determines whether to set the snapshot to be writable.
   * **Source Filesystem**: The source filesystem from which to create the snapshot.
   * **Upload to local object store**: Determines whether to upload the snapshot to a local object store. You can also upload the snapshot later (see [Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj)).
   * **Upload to remote object store**: Determines whether to upload the snapshot to a remote object store. You can also upload the snapshot later.
4. Select **Create**.

## Duplicate a snapshot

You can duplicate a snapshot (clone), which enables creating a writable snapshot from a read-only snapshot.

**Procedure**

1. From the menu, select **Manage > Snapshots**.
2. From the Snapshots page, select the three dots of the snapshot you want to duplicate, and from the menu, select **Duplicate Snapshot**.

<div data-with-frame="true"><img src="/files/4417ZdpIpsYS4BOkYH06" alt="Snapshots menu: Duplicate Snapshot"></div>

3. In the Duplicate Snapshot dialog, set the properties like you create a snapshot.\
   The source filesystem and source snapshot are already set.
4. Select **Duplicate**.

<div data-with-frame="true"><img src="/files/GcBsaek23YgXbtdBfK8I" alt="Duplicate Snapshot dialog" width="301"></div>

## Delete a snapshot

When deleting a snapshot, consider the following guidelines:

* Deleting a snapshot parallel to a snapshot upload to the same filesystem is impossible. Uploading a snapshot to a remote object store can take time. Therefore, it is advisable to delete the desired snapshot before uploading it to the remote object store.
* When uploading snapshots to both local and remote object stores. While the local and remote uploads can progress in parallel, consider the case of a remote upload in progress. A snapshot is deleted, and later a snapshot is uploaded to the local object store. In this scenario, the local snapshot upload waits for the pending deletion of the snapshot (which happens only once the remote snapshot upload is done).

**Procedure**

1. From the menu, select **Manage > Snapshots**.
2. From the Snapshots page, select the three dots of the snapshot you want to delete, and from the menu, select **Remove**.
3. In the Deletion Of Snapshot message, select **Yes** to delete the snapshot.

<div data-with-frame="true"><img src="/files/z6KwLmzHMxqhqfiSPUHQ" alt="Remove a snapshot"></div>

## Restore a snapshot to a filesystem or another snapshot <a href="#restore-a-snapshot" id="restore-a-snapshot"></a>

Restoring a snapshot to a filesystem or another snapshot (target) modifies the data and metadata of the target.

**Before you begin**

If you restore the snapshot to a filesystem, make sure to stop the IO services of the filesystem during the restore operation.

**Procedure**

1. From the menu, select **Manage > Snapshots**.
2. From the Snapshots page, select the three dots of the snapshot you want to restore, and from the menu, select **Restore To**.
3. In the Restore To dialog, select the destination: **Filesystem** or **Snapshot**.
4. Select **Save**.

<div data-with-frame="true"><img src="/files/7QTOEklpOY6zHWWHBTgN" alt="Restore a snapshot to a filesystem"></div>

## Update a snapshot

You can update the snapshot name and access point properties.

**Procedure**

1. From the menu, select **Manage > Snapshots**.
2. From the Snapshots page, select the three dots of the snapshot you want to update, and from the menu, select **Edit**.
3. Modify the **Name** and **Access Point** properties as required.
4. Select **Save**.

<div data-with-frame="true"><img src="/files/ZYRqVJ7ArY1gxrqMZM9E" alt="Edit snapshot properties"></div>


# Manage snapshots using the CLI

This page describes how to manage snapshots using the CLI.

Using the CLI, you can:

* [#add-a-snapshot](#add-a-snapshot "mention")
* [#remove-a-snapshot](#remove-a-snapshot "mention")
* [#restore-a-snapshot-to-a-filesystem-or-another-snapshot](#restore-a-snapshot-to-a-filesystem-or-another-snapshot "mention")
* [#update-a-snapshot](#update-a-snapshot "mention")
* [#access-the-.snapshots-directory](#access-the-.snapshots-directory "mention")
* [#retrieve-snapshot-details](#retrieve-snapshot-details "mention")

## Add a snapshot

**Command:** `weka fs snapshot add`

Use the following command line to create a snapshot:

`weka fs snapshot add <file-system> <name> [--access-point access-point] [--source-snap=<source-snap>] [--is-writable]`

{% hint style="info" %}
The newly created snapshot is saved in the `.snapshots` directory.\
See [#access-the-.snapshots-directory](#access-the-.snapshots-directory "mention").
{% endhint %}

**Parameters**

<table><thead><tr><th width="154.90625">Name</th><th width="254.96875">Value</th><th>Default</th></tr></thead><tbody><tr><td><code>file-system</code>*</td><td>A valid filesystem identifier.</td><td>​</td></tr><tr><td><code>name</code>*</td><td>Unique name for filesystem snapshot.</td><td></td></tr><tr><td><code>access-point</code></td><td>Name of the newly-created directory for filesystem-level snapshots, which serves as the access point for the snapshots.</td><td>Controlled by <code>weka fs snapshot access-point-naming-convention update &#x3C;date/name>.</code> By default, it is &#x3C;date> format: @GMT_%Y.%m.%d-%H.%M.%S, which is compatible with <a href="/pages/-LTbl5mR86j-qUX1Q7dA#windows-previous-versions">Windows' previous versions' format for SMB</a>.</td></tr><tr><td><code>source-snap</code></td><td>Must be an existing snapshot.</td><td>The snapshot name of the specified filesystem.</td></tr><tr><td><code>is-writable</code></td><td>Sets the created snapshot to be writable.</td><td>False</td></tr></tbody></table>

## Remove a snapshot

**Command:** `weka fs snapshot remove`

Use the following command line to remove a snapshot:

`weka fs snapshot remove <file-system> <name>`

**Parameters**

<table><thead><tr><th width="227.9375">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>file-system</code>*</td><td>A valid filesystem identifier</td></tr><tr><td><code>name</code>*</td><td>Unique name for filesystem snapshot</td></tr></tbody></table>

{% hint style="warning" %}
A snapshot deletion cannot happen parallel to a snapshot upload to the same filesystem. Since uploading a snapshot to a remote object store might take a while, it is advisable to delete the desired snapshots before uploading to the remote object store.

This becomes more important when uploading snapshots to local and remote object stores. While local and remote uploads can progress in parallel, consider the case of a remote upload in progress, then a snapshot is deleted, and later a snapshot is uploaded to the local object store. In this scenario, the local snapshot upload waits for the pending deletion of the snapshot (which happens only once the remote snapshot upload is done).
{% endhint %}

## Restore a snapshot to a filesystem or another snapshot

**Commands:** `weka fs restore` or `weka fs snapshot copy`

Use the following command line to restore a filesystem from a snapshot:

`weka fs restore <file-system> <source-name> [--preserved-overwritten-snapshot-name=preserved-overwritten-snapshot-name] [--preserved-overwritten-snapshot-access-point=preserved-overwritten-snapshot-access-point]`

Use the following command line to restore a snapshot to another snapshot:

`weka fs snapshot copy <file-system> <source-name> <destination-name> [--preserved-overwritten-snapshot-name=preserved-overwritten-snapshot-name] [--preserved-overwritten-snapshot-access-point=preserved-overwritten-snapshot-access-point]`

**Parameters**

| Name                                          | Value                                                                                                                                                                                                                                                             | Default                                                                                                                                                                                             |
| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `file-system`\*                               | A valid filesystem identifier                                                                                                                                                                                                                                     | ​                                                                                                                                                                                                   |
| `source-name`\*                               | Unique name for the source of the snapshot                                                                                                                                                                                                                        |                                                                                                                                                                                                     |
| `destination-``name`\*                        | The destination name to which the existing snapshot should be copied.                                                                                                                                                                                             |                                                                                                                                                                                                     |
| `preserved-overwritten-snapshot-name`         | <p>A new name for the overwritten snapshot to preserve, thus allowing the IO operations continuity to the filesystem.<br>If not specified, the original snapshot or active filesystem is overwritten, and IO operations to an existing filesystem might fail.</p> |                                                                                                                                                                                                     |
| `preserved-overwritten-snapshot-access-point` | A directory that serves as the access point for the preserved overwritten snapshot.                                                                                                                                                                               | If the `preserved-overwritten-snapshot-name` parameter is specified, but the `preserved-overwritten-snapshot-access-point`parameter is not, it is created automatically based on the snapshot name. |

{% hint style="warning" %}
When restoring a filesystem from a snapshot (or copying over an existing snapshot), the filesystem data and metadata are changed. If you do not specify the `preserved-overwritten-snapshot-name` parameter, ensure IOs to the filesystem are stopped during this time.
{% endhint %}

## Update a snapshot

**Command:** `weka fs snapshot update`

This command changes the snapshot attributes. Use the following command line to update an existing snapshot:

`weka fs snapshot update <file-system> <name> [--new-name=<new-name>] [--access-point=<access-point>]`

**Parameters**

<table><thead><tr><th width="231.953125">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>file-system</code>*</td><td>A valid filesystem identifier</td></tr><tr><td><code>name</code>*</td><td>Unique name for the updated snapshot</td></tr><tr><td><code>new-name</code></td><td>New name for the updated snapshot</td></tr><tr><td><code>access-point</code></td><td>Name of a directory for the snapshot that serves as the access point for the snapshot</td></tr></tbody></table>

## Access the `.snapshots` directory

The `.snapshots` directory is located in the root directory of each mounted filesystem. It is not displayed with the `ls -la` command. You can access this directory using the `cd .snapshots` command from the root directory.

#### Example

The following example shows a filesystem named `default` mounted to `/mnt/weka`.

To confirm you are in the root directory of the mounted filesystem, change into the `.snapshots` directory, and then display any snapshots in that directory:

```
[root@ip-172-31-23-177 weka]# pwd 
/mnt/weka 
[root@ip-172-31-23-177 weka]# ls -la 
total 0 
drwxrwxr-x 1 root root   0 Sep 19 04:56 . 
drwxr-xr-x 4 root root  33 Sep 20 06:48 .. 
drwx------ 1 user1 user1 0 Sep 20 09:26 user1 
[root@ip-172-31-23-177 weka]# cd .snapshots 
[root@ip-172-31-23-177 .snapshots]# ls -l 
total 0 
drwxrwxr-x 1 root root 0 Sep 21 02:44 @GMT-2023.09.21-02.44.38 
[root@ip-172-31-23-177 .snapshots]#
```

## Retrieve snapshot details

**Command:** `weka fs snapshot`

Use the following command to retrieve snapshot details, such as its UID, local object locator, estimated reclaimable space, and metadata size:

{% code overflow="wrap" %}

```sh
weka fs snapshot [--file-system file-system] [--name name] [--output output]...
```

{% endcode %}

<table><thead><tr><th width="199">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>--file-system</code></td><td>Filesystem name</td></tr><tr><td><code>--name</code></td><td>Snapshot name</td></tr><tr><td><code>-o</code>, <code>--output</code>...</td><td>Specify which columns to output. May include any of the following: uid, id, filesystem, name, access, writeable, created, local_upload_size, remote_upload_size, local_object_status, local_object_progress, local_object_locator, remote_object_status, remote_object_progress, remote_object_locator, removing, prefetched, est_reclaimable_size, metadata_size (may be repeated or comma-separated)</td></tr></tbody></table>


# Snap-To-Object

Explore the Snap-To-Object feature, a capability facilitating the seamless data transfer from a designated snapshot to an object store.

The Snap-To-Object feature enables the consolidation of all data from a specific snapshot, including filesystem metadata, every file, and all associated data, into an object store. The complete snapshot data can be used to restore the data on the WEKA cluster or another cluster running the same or a higher WEKA version.

## Snap-To-Object feature use cases

The Snap-To-Object feature is helpful for a range of use cases, as follows:

* **On-premises and cloud use cases**
  * [External backup of data](#external-backup-of-data)
  * [Archiving data](#archiving-data)
  * [Data replication](#data-replication)
* **Cloud-only use cases**
  * [Cloud pause/restart](#cloud-pause-restart)
  * [Data protection against cloud availability zone failures](#data-protection-against-cloud-availability-zone-failures)
  * [Migration of filesystems to another region](#migration-of-filesystems-to-another-region)
* **Hybrid cloud use case**
  * [Cloud bursting](#cloud-bursting)

### External backup of data

Suppose it is required to recover data stored on a WEKA filesystem due to a complete or partial loss of the data within it. You can use a data snapshot saved to an object store to recreate the same data in the snapshot on the same or another WEKA cluster.

This use case supports backup in any of the following WEKA system deployment modes:

* **Local object store:** The WEKA cluster and object store are close to each other and will be highly performant during data recovery operations. The WEKA cluster can recover a filesystem from any snapshot on the object store for which it has a reference locator.
* **Remote object store:** The WEKA cluster and object store are located in different geographic locations, typically with longer latencies between them. In such a deployment, you can send snapshots to local and remote object stores.

{% hint style="info" %}
This deployment type requires supporting the latency of hundreds of milliseconds. For performance issues on Snap-To-Object tiering cross-interactions/resonance, contact the [Customer Success Team](/support/getting-support-for-your-weka-system).
{% endhint %}

* **Local object store replicating to a remote object store:** A local object store in one data center replicates data to another object store using the object store system features, such as [AWS S3 cross-region replication](https://docs.aws.amazon.com/AmazonS3/latest/dev/crr.html).\
  This deployment provides both integrated tiering and Snap-To-Object local high performance between the WEKA object store and the additional object store. The object store manages the data replication, enabling data survival in multiple regions.

{% hint style="info" %}
This deployment requires ensuring that the object store system perfectly replicates all objects on time to ensure consistency across regions.
{% endhint %}

### Archiving data

The periodic creation and uploading of snapshots to an object store generate an archive, allowing access to past copies of data.

When any compliance or application requirement occurs, it is possible to make the relevant snapshot available on a WEKA cluster and view the content of past versions of data.

### Data replication

Combining a local cluster with a replicated object store in another data center allows for the following use cases:

* **Disaster recovery:** where you can take the replicated data and make it available to applications in the destination location.
* **Backup:** where you can take multiple snapshots and create point-in-time images of the data that can be mounted, and specific files may be restored.

### Cloud pause/restart

In a public cloud, with a WEKA cluster running on compute instances with local SSDs, sometimes the data needs to be retained, even though ongoing access to the WEKA cluster is unnecessary. In such cases, using Snap-To-Object can save the costs of compute instances running the WEKA system.

To pause a cluster, you need to take a snapshot of the data and then use Snap-To-Object to upload the snapshot to an S3-compliant object store. When the upload process is complete, the WEKA cluster instances can be stopped, and the data is safe on the object store.

To re-enable access to the data, you need to form a new cluster or use an existing one and download the snapshot from the object store.

### Data protection against cloud availability zone failures

This use case ensures data protection against cloud availability zone failures in the various clouds: AWS Availability Zones, Google Cloud Platform (GCP) Zones, and Oracle Cloud Infrastructure (OCI) Availability Domains.

In AWS, for example, the WEKA cluster can run on a single availability zone, providing the best performance and no cross-AZ bandwidth charges. Using Snap-To-Object, you can take and upload snapshots of the cluster to S3 (which is a cross-AZ service). If an AZ failure occurs, a new WEKA cluster can be created on another AZ, and the last snapshot uploaded to S3 can be downloaded to this new cluster.

### Migration of filesystems to another region

Using WEKA snapshots uploaded to S3 combined with S3 cross-region replication enables the migration of a filesystem from one region to another.

### Cloud bursting

On-premises WEKA deployments can often benefit from cloud elasticity to consume large quantities of computation power for short periods.

Cloud bursting requires the following steps:

1. Take a snapshot of an on-premises WEKA filesystem.
2. Upload the data snapshot to S3 at AWS using Snap-To-Object.
3. Create a WEKA cluster in AWS and make the data uploaded to S3 available to the newly formed cluster at AWS.
4. Process the data in-cloud using cloud compute resources.

Optionally, you may also promote data back to on-premises by doing the following:

1. Take a snapshot of the WEKA filesystem in the cloud on completion of cloud processing.
2. Upload the cloud snapshot to the on-premises WEKA cluster.

## Snapshots management considerations

* **Simultaneous snapshot uploads**: WEKA supports concurrent uploads of multiple snapshots from different filesystems to both remote and local object stores.
* **Writeable snapshots cannot be uploaded**: A writeable snapshot is a clone of the live filesystem or other snapshots at a specific point in time. Because its data continues to change, the snapshot cannot be uploaded to the object store as a read-only snapshot and is tiered according to existing policies.
* **Snapshot upload order**: Uploading snapshots to a remote object store benefits from a chronological approach. When uploading a monthly snapshot, it may be more efficient to first upload the preceding daily snapshots.
* **Snapshot deletion and upload constraints**: Parallel deletion during snapshot upload requires careful handling. The local snapshot upload pauses and waits for any pending snapshot deletion, which only proceeds after the remote snapshot upload is complete.
* **Pausing or aborting snapshot uploads**: Users can pause or abort snapshot uploads using commands detailed in the background tasks section.
* **New filesystem creation from snapshots**: When creating a new filesystem from a snap-to-object operation, the original filesystem quotas are not preserved in the new filesystem.

{% hint style="warning" %}
The system does not support restoring or downloading a filesystem from snapshots stored in object storage when the object store is located within the same cluster.
{% endhint %}

## Synchronous snapshots

Synchronous snapshots are point-in-time backups for filesystems. When taken, they consist only of the changes since the last snapshot (incremental snapshots). When you download and restore a snapshot to a live filesystem, the system reconstructs the filesystem on the fly with the changes since the previous snapshot.

This capability for filesystem snapshots makes them more cost-effective because you do not have to update the entire filesystem with each snapshot. You only update the changes since the last snapshot.

It is recommended that the synchronous snapshots be applied in chronological order.

## Object store space reclamation after a snapshot download

When you download a snapshot to create a filesystem (`weka fs download`), the new filesystem reads the objects in the bucket but does not take ownership of them. A filesystem reclaims space only for objects it wrote itself. Objects inherited from a downloaded snapshot are never modified or deleted by the new filesystem, regardless of which cluster originally uploaded them. This applies even when the snapshot was uploaded from the same cluster. As a result, deleting data from the downloaded filesystem does not release space in the object store bucket.

**Example**: A tiered filesystem consumes 5 PB in the object store bucket. After you download its snapshot to a new filesystem and delete 3 PB of data, the bucket still consumes 5 PB.

<div data-with-frame="true"><figure><img src="/files/Am6xqR77a64sIJNJGoBX" alt=""><figcaption><p>Object store space reclamation after a snapshot download</p></figcaption></figure></div>

To enable space reclamation for a downloaded filesystem, migrate it to a different object store bucket. During migration, the object store must accommodate the original data and the migrated data. This temporarily requires up to twice the filesystem’s tiered capacity. Delete the original data after migration completes.

## Delete snapshots residing on an object store

Deleting a snapshot uploaded from a filesystem removes all its data from the local object store bucket. It does not remove any data from a remote object store bucket.

{% hint style="danger" %}
If the snapshot has been (or is) downloaded and used by a different filesystem, deleting it causes that filesystem to stop functioning correctly. Data can become unavailable, and errors can occur when accessing the data.

Before deleting the snapshot, un-tier the downloaded filesystem or migrate it to a different object store bucket. See [Attach or detach object store buckets](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems).
{% endhint %}

## Snap-To-Object and tiering

Snap-To-Object and tiering use SSDs and object stores for data storage. The WEKA system uses the same paradigm for holding SSD and object store data for both Snap-To-Object and tiering to save storage and performance resources.

You can implement this paradigm for each filesystem using one of the following use cases:

* **Data resides on the SSDs only, and the object store is used only for the various Snap-To-Object use cases, such as backup, archiving, and bursting:**\
  The allocated SSD capacity must be identical to the filesystem size (total capacity) for each filesystem. The drive retention period must be defined as the longest time possible (which is 60 months).\
  The Tiering Cue must be defined using the same considerations based on IO patterns. In this case, the applications always work with a high-performance SSD storage system and use the object store only as a backup device.
* **Snap-To-Object on filesystems is used with active tiering between the SSDs and the object store:**\
  Objects in the object store are used to tier all data and back up using Snap-To-Object. If possible, the WEKA system uses the same object for both purposes, eliminating the unnecessary need to acquire additional storage and copy data.

{% hint style="info" %}
When using Snap-To-Object to promote data from an object store, some metadata may still be in the object store until it is accessed for the first time.
{% endhint %}

**Related topics**

[Manage Snap-To-Object using the GUI](/weka-filesystems-and-object-stores/snap-to-obj/snap-to-obj)

[Manage Snap-To-Object using the CLI](/weka-filesystems-and-object-stores/snap-to-obj/snap-to-obj-1)


# Manage Snap-To-Object using the GUI

This page describes the Snap-To-Object feature, which enables the committing of all the data of a specific snapshot to an object store.

Using the GUI, you can:

* [Upload a snapshot](#upload-a-snapshot)
* [Create a filesystem from an uploaded snapshot](#create-a-filesystem-from-an-uploaded-snapshot)
* [Sync a filesystem from a snapshot](#sync-a-filesystem-from-a-snapshot)

**Related topics**

To learn about how to view, create, update, delete, and restore snapshots, see [Manage snapshots using the GUI](/weka-filesystems-and-object-stores/snapshots/snapshots).

## Upload a snapshot

You can upload a snapshot to a local, remote, or both object store buckets.

**Procedure**

1. From the menu, select **Manage > Snapshots**.
2. Select the three dots on the right of the required snapshot. From the menu, select **Upload To Object Store**.

<div data-with-frame="true"><img src="/files/lBMB86zSZ36ZCXBWAbJp" alt="Upload a snapshot to the object store"></div>

3. A relevant message appears if a local or remote object store bucket is not attached to the filesystem. It enables opening a dialog to select an object store bucket and attach it to the filesystem. To add an object store, select **Yes**.
4. In the Attach Object Store to Filesystem dialog, select the object store bucket to attach the snapshot.

<div data-with-frame="true"><img src="/files/sL4TQZssWLsdslYCYzt7" alt="Upload a snapshot"></div>

5. Select **Save**.\
   The snapshot is uploaded to the target object store bucket.
6. **Copy the snapshot locator:**
   * Select the three dots on the right of the required snapshot, and select **Copy Locator to Clipboard**.
   * Save the locator in a dedicated file so later you can use it for creating a filesystem from the uploaded snapshot.

<div data-with-frame="true"><img src="/files/aga9jsgJBpTNQeXXrzBe" alt="Copy snapshot locator"></div>

***

**Related topics**

[Background tasks](/operation-guide/background-tasks#pause-resume-abort-a-background-task)

## Create a filesystem from an uploaded snapshot

You can create (or recreate) a filesystem from an uploaded snapshot, for example, when you need to migrate the filesystem data from one cluster to another.

When recreating a filesystem from a snapshot, adhere to the following guidelines:

* **Pay attention to upload and download costs**: Due to the bandwidth characteristics and potential costs when interacting with remote object stores, it is not allowed to download a filesystem from a remote object store bucket. If a snapshot on a local object store bucket exists, it is advisable to use that one. Otherwise, follow the procedure in the [Recover from a remote snapshot](/weka-filesystems-and-object-stores/snap-to-obj/snap-to-obj-1#recover-from-a-remote-snapshot) topic using the CLI.
* **Use the same KMS master key**: For an encrypted filesystem, to decrypt the snapshot data, use the same KMS master key as used in the encrypted filesystem. See the [KMS Management Overview](/security/kms-management#overview) topic.

<div data-with-frame="true"><figure><img src="/files/4oLGmYUtlf6CcYPmymgm" alt=""><figcaption><p>Create a filesystem from an uploaded snapshot example</p></figcaption></figure></div>

**Before you begin**

* Verify that the locator of the required snapshot (from the source cluster) is available (see the last step in the [Upload a snapshot](#upload-a-snapshot) procedure).
* Ensure the object store is attached to the destination cluster.

**Procedure**

1. Connect to the destination cluster where you want to create the filesystem.
2. From the menu, select **Manage > Filesystems**, and select **+Create**.
3. In the Create Filesystem, do the following:
   * Set the filesystem name, group, and tiering properties.
   * Select **Create From Uploaded Snapshot** (it only appears when you select **Tiering**).\
     Paste the copied snapshot locator in the Object Store Bucket Locator (from the source cluster).\
     In the Snapshot Name, set a meaningful snapshot name to override the default (uploaded snapshot name).\
     In the Access Point, set a meaningful access point name to override the default (uploaded access point name) for the directory that serves as the snapshot's access point.
4. Select **Save**.

<div data-with-frame="true"><img src="/files/hA3Es17VAdfQgDsCQ1Ja" alt="Create a filesystem from an uploaded snapshot"></div>

## Sync a filesystem from a snapshot <a href="#sync-a-filesystem-from-a-snapshot" id="sync-a-filesystem-from-a-snapshot"></a>

You can synchronize a filesystem from a snapshot using the Synchronous Snap feature (incremental snapshot). Synchronous Snap only downloads changes since the last snapshot from the object store bucket.

{% hint style="info" %}
Only snapshots uploaded from version 4.3 or later can be downloaded using Synchronous Snap.
{% endhint %}

**Before you begin**

Copy the locator of the snapshot you want to sync with the filesystem.

**Procedure**

1. From the menu, select **Manage > Filesystems**.
2. From the Filesystems page, select the three dots of the filesystem you want to sync, and from the menu, select **Synchronous Snap**.

<div data-with-frame="true"><figure><img src="/files/Mp19pbppZ4J7b0fsu6Tp" alt=""><figcaption><p>Filesystem menu: Synchronous Snap</p></figcaption></figure></div>

3. Paste the snapshot object locator in the Run Synchronous Snap to Existing Filesystem dialog.
4. Select **Start**.\
   The filesystem starts syncing with the snapshot.

<div data-with-frame="true"><figure><img src="/files/Gw4six8xr8hjfk6NjD4k" alt="" width="375"><figcaption><p>Run synchronous snap to an existing filesystem</p></figcaption></figure></div>

5. Once the sync is completed, restore the snapshot to update the production filesystem.

**Related topics**

[Manage filesystems using the GUI](/weka-filesystems-and-object-stores/managing-filesystems/managing-filesystems#add-a-filesystem)


# Manage Snap-To-Object using the CLI

The Snap-To-Object feature enables the committing of all the data of a specific snapshot to an object store.

Using the CLI, you can:

* [Upload a snapshot](#upload-a-snapshot)
* [Create a filesystem from a local uploaded snapshot](#create-a-filesystem-from-a-local-uploaded-snapshot)
* [Manage synchronous snapshots](#manage-synchronous-snapshots)
* [Recover a filesystem from a remote-only snapshot](#recover-a-filesystem-from-a-remote-only-snapshot)

## Upload a snapshot

**Command:** `weka fs snapshot upload`

Use the following command line to upload an existing snapshot:

`weka fs snapshot upload <file-system> <snapshot> [--site site]`

**Parameters**

<table><thead><tr><th width="186.33333333333331">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>file-system</code>*</td><td>Filesystem name.</td></tr><tr><td><code>snapshot</code>*</td><td>Snapshot name of the <code>&#x3C;file-system></code> filesystem to upload.<br></td></tr><tr><td><code>site</code>*</td><td>Location for the snapshot upload.<br>Mandatory only if both <code>local</code> and <code>remote</code> buckets are attached.<br>Possible values: <code>local</code> or <code>remote</code><br>Default: Auto-selected if only one bucket for upload is attached.</td></tr></tbody></table>

## Create a filesystem from a local uploaded snapshot

**Command:** `weka fs download`

Create or recreate a filesystem from a snapshot that is available in a local object store bucket. Use this procedure after a regular snapshot upload, or after you temporarily map a remote snapshot bucket as local during recovery. If the snapshot exists only in a remote bucket, use [Recover a filesystem from a remote-only snapshot](#recover-a-filesystem-from-a-remote-only-snapshot). If the snapshot originates from an encrypted source, include the required KMS-related parameters:

`weka fs download <name> <group-name> <total-capacity> <ssd-capacity> <obs-bucket> <locator>` \[--auth-required auth-required] `[--additional-obs additional-obs] [--snapshot-name snapshot-name] [--access-point access-point] [--kms-key-identifier kms-key-identifier] [--kms-namespace kms-namespace] [--kms-role-id kms-role-id] [--kms-secret-id kms-secret-id] [--skip-resource-validation]`

When creating a filesystem from a snapshot, a background cluster task automatically prefetches its metadata, providing better latency for metadata queries.

**Parameters**

<table><thead><tr><th width="240">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Name of the filesystem to create.</td></tr><tr><td><code>group-name</code>*</td><td>Name of the filesystem group in which the new filesystem is placed.</td></tr><tr><td><code>total-capacity</code>*</td><td>The total capacity of the downloaded filesystem.</td></tr><tr><td><code>ssd-capacity</code>*</td><td>SSD capacity of the downloaded filesystem.</td></tr><tr><td><code>obs-bucket</code>*</td><td>Object store name for tiering.</td></tr><tr><td><code>locator</code>*</td><td>Object store locator obtained from a previously successful snapshot upload.</td></tr><tr><td><code>auth-required</code></td><td>Require authentication for the mounting user when mounting this filesystem. This setting is only applicable in the root organization; users in non-root organizations must always be authenticated to perform a mount operation. Format: <code>yes</code> or <code>no</code>.<br>Default: <code>no</code></td></tr><tr><td><code>additional-obs</code></td><td>An additional object-store name.<br>If the data to recover reside in two object stores (a second object store attached to the filesystem, and the filesystem has not undergone full migration), this object store is attached in a <code>read-only</code> mode.<br>The snapshot locator must be in the primary object store specified in the <code>obs</code> parameter.</td></tr><tr><td><code>snapshot-name</code></td><td>The downloaded snapshot name.<br>Default: The uploaded snapshot name.</td></tr><tr><td><code>access-point</code></td><td>The downloaded snapshot access point.<br>Default: The uploaded access point.</td></tr><tr><td><code>kms-key-identifier</code></td><td>Customize KMS key name for this filesystem (applicable only for HashiCorp Vault).</td></tr><tr><td><code>kms-namespace</code></td><td>Customize the KMS role ID for this filesystem (applicable only for HashiCorp Vault).</td></tr><tr><td><code>kms-role-id</code></td><td>Customize the KMS role ID for this filesystem (applicable only for HashiCorp Vault).</td></tr><tr><td><code>kms-secret-id</code></td><td>Customize the KMS secret ID for this filesystem (applicable only for HashiCorp Vault).</td></tr><tr><td><code>skip-resource-validation</code></td><td>Skip verifying RAM and SSD resource allocation for the downloaded filesystem on the cluster.</td></tr></tbody></table>

{% hint style="info" %}
For encrypted filesystems, when downloading, you must use the same KMS cluster-wide key or, if configured, the per-filesystem encryption parameters to decrypt the snapshot data. For more information, see [Manage KMS](/security/kms-management).
{% endhint %}

The `locator` can be a previously saved locator for disaster scenarios, or you can obtain the `locator` using the `weka fs snapshot` command on a system with a live filesystem with snapshots.

If you need to pause and resume the download process, use the command: `weka cluster task pause / resume`. To abort the download process, delete the downloaded filesystem directly. For details, see [Background tasks](/operation-guide/background-tasks).

{% hint style="info" %}
Use this procedure only when the uploaded snapshot is available in a local object store bucket. Direct download from a remote object store bucket is not allowed because of bandwidth and cost considerations. If the snapshot exists only in a remote bucket, follow [Recover a filesystem from a remote-only snapshot](#recover-a-filesystem-from-a-remote-only-snapshot).
{% endhint %}

## Manage synchronous snapshots

The workflow to manage the synchronous snapshots includes:

1. Upload snapshots using, for example, the snapshots scheduler.
2. Download the synchronous snapshot (described below).
3. Restore a specific snapshot to a filesystem. See

**Related topics**

[Snapshots](/weka-filesystems-and-object-stores/snapshots)

[Manage snapshots using the CLI](/weka-filesystems-and-object-stores/snapshots/snapshots-1#restore-a-snapshot-to-a-filesystem-or-another-snapshot)

### Download a synchronous snapshot

**Command:** `weka fs snapshot download`

Use the following command line to download a synchronous snapshot. This command is only relevant for snapshots uploaded from a system of version 4.3 and later:

`weka fs snapshot download <file-system> <locator>`

{% hint style="warning" %}
Make sure to download synchronous snapshots in chronological order. Non-chronological snapshots are inefficient and are not synchronous.

If you need to download a snapshot earlier than the latest downloaded one, for example, when you need one of the daily synchronous snapshots after the weekly synchronous snapshot was downloaded, add the `--allow-non-chronological` flag to download it anyway.
{% endhint %}

**Parameters**

<table><thead><tr><th width="146">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>file-system</code>*</td><td>Name of the filesystem.</td></tr><tr><td><code>locator</code>*</td><td>Object store locator obtained from a previously successful snapshot upload.</td></tr></tbody></table>

If you need to pause and resume the download process, use the command: `weka cluster task pause / resume`. To abort the download process, delete the downloaded snapshot directly.

**Related topics**

[Snap-To-Object](/weka-filesystems-and-object-stores/snap-to-obj#synchronous-snapshots)

[Background tasks](/operation-guide/background-tasks)

## Recover a filesystem from a remote-only snapshot

Recover a filesystem when the required snapshot exists only in a remote object store bucket. This workflow differs from the local download workflow in one step. You still use `weka fs download` to create the filesystem, but you first create a temporary local bucket definition that points to the remote snapshot bucket.

**Before you begin**

* Identify the remote bucket endpoint, bucket name, region, and credentials.
* Use object store credentials that can read and write the bucket. For example, use an S3 user with a `readwrite` policy.
* Ensure the WEKA cluster has network connectivity to the remote object store.
* Identify the filesystem group, capacities, and snapshot locator.
* Verify sufficient licensing for the new filesystem capacity.

**Procedure**

1. Add a temporary local bucket definition that points to the remote snapshot bucket:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">weka fs tier s3 add &#x3C;recovery-bucket-name> [--site local] [--obs-name obs-name] [--hostname hostname] [--bucket bucket] [--auth-method auth-method] [--region region] [--access-key-id access-key-id] [--secret-key secret-key] [--protocol protocol]
   </code></pre>

   Use the bucket that contains the uploaded snapshot. The `recovery-bucket-name` value is the WEKA OBS connection name. Use this name in later `attach` and `detach` commands. If the endpoint is another WEKA system that uses a self-signed certificate, set `--protocol HTTPS_UNVERIFIED`.
2. Create the filesystem from the snapshot:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">weka fs download &#x3C;name> &#x3C;group-name> &#x3C;total-capacity> &#x3C;ssd-capacity> &#x3C;recovery-bucket-name> &#x3C;locator>
   </code></pre>
3. If the recovered filesystem needs a writable tiering bucket, add it and attach it:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">weka fs tier s3 add &#x3C;tier-bucket-name> [--site local] [--obs-name obs-name] [--hostname hostname] [--bucket bucket] [--auth-method auth-method] [--region region] [--access-key-id access-key-id] [--secret-key secret-key] [--protocol protocol]
   weka fs tier s3 attach &#x3C;fs-name> &#x3C;tier-bucket-name> [--mode writable]
   </code></pre>
4. Detach the temporary recovery bucket from the recovered filesystem:

   ```bash
   weka fs tier s3 detach <fs-name> <recovery-bucket-name>
   ```

   If the CLI asks for confirmation, rerun the command with `-f`.
5. If the filesystem also needs a remote backup bucket, create the bucket definition and attach it in remote mode:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">weka fs tier s3 add &#x3C;remote-bucket-name> --site remote [--obs-name obs-name] [--hostname hostname] [--bucket bucket] [--auth-method auth-method] [--region region] [--access-key-id access-key-id] [--secret-key secret-key] [--protocol protocol]
   weka fs tier s3 attach &#x3C;fs-name> &#x3C;remote-bucket-name> --mode remote
   </code></pre>
6. Delete the temporary recovery bucket definition when recovery is complete:

   ```bash
   weka fs tier s3 delete <recovery-bucket-name>
   ```

   If the delete command reports that the bucket is still in use, wait a few seconds and retry.

{% hint style="info" %}
For full bucket syntax, see [Manage object stores using the CLI](/weka-filesystems-and-object-stores/managing-object-stores/managing-object-stores-1). For attach and detach syntax, see [Attach or detach object store buckets using the CLI](/weka-filesystems-and-object-stores/attaching-detaching-object-stores-to-from-filesystems/attaching-detaching-object-stores-to-from-filesystems-1).
{% endhint %}

**Related topic**

[Manage object stores](/weka-filesystems-and-object-stores/managing-object-stores)


# Snapshot policies

Snapshot policies define rules and schedules for creating and managing point-in-time data copies, ensuring reliable recovery from deletion, corruption, or integrity issues.

## Overview

Snapshot policies establish the rules and schedules for creating, managing, and retaining point-in-time copies of data, known as snapshots. These snapshots provide a reliable mechanism for data recovery or rollback in scenarios such as accidental deletion, corruption, or other data integrity issues.

By automating the creation of snapshots based on specified criteria, such as time intervals or frequency, snapshot policies enhance data protection, streamline disaster recovery, and ensure business continuity. They enable organizations to restore their data to a consistent state quickly without requiring full backups, optimizing storage usage while minimizing the risk of data loss.

WEKA provides a default system policy that can serve as a foundation for customizing snapshot policies. Each policy defines the following key parameters:

* **Schedule:** Specifies when snapshots are created, including hourly, daily, weekly, monthly, or at periodic intervals.
* **Retention:** Determines the number of snapshots to retain, defining a rotation policy.
* **Destination:** Determines whether snapshots are also uploaded to a local and remote object store.

Background tasks handle operations related to snapshots, including creation and uploads to local or remote object stores. This system operates in the background to improve efficiency and ensure uninterrupted performance during snapshot management processes.

Administrators of the root organization only can configure policies to create hourly, daily, weekly, monthly, and periodic snapshots. These policies can be assigned to filesystems already connected to a local or remote object store.

The example below demonstrates how to configure a policy using the GUI. The policy schedules a snapshot every Saturday and uploads it to a local object store. Alternatively, you can use CLI commands to achieve the same result.

<div data-with-frame="true"><figure><img src="/files/vbF0YkviSxm1IX0bwtcc" alt=""><figcaption><p>Create a snapshot policy</p></figcaption></figure></div>

## General guidelines and considerations

* **Plan and structure policies:**
  * Decide whether to store snapshots on the local server or upload them to a local or remote object store.
  * If uploading snapshots to an object store, configure the filesystem to use the appropriate local or remote object store before attaching the policy.
  * Attach a snapshot policy to each filesystem.
  * Design policies based on workload priorities, recovery objectives, and storage capacity requirements.
* **Adhere to system limits:**
  * You can define up to **1,024 snapshot policies** across the cluster, in addition to the default policy.
  * A single snapshot policy can be attached to maximum **1,024 filesystems**.
  * A single filesystem can have maximum **10 snapshot policies** assigned.
* **Optimize policy assignments:**
  * Consolidate policies wherever possible to reduce complexity and duplication.
* **Monitor object store connectivity:**
  * Ensure that each filesystem is properly connected to a local or remote object store to enable seamless assignment to a snapshot policy.
* **Multiple schedules overlap:**

  * When multiple schedules overlap on the same filesystem, only one snapshot is taken, following this priority:
    1. **Monthly** (highest priority)
    2. **Weekly**
    3. **Daily**
    4. **Hourly**
    5. **Periodic** (lowest priority)

  This means that if multiple schedules overlap, the snapshot with the highest priority (for example, Monthly) are taken, and the lower-priority ones (for example, Weekly, Daily, Hourly, Periodic) are skipped. This hierarchy prevents redundant snapshots. Plan schedules accordingly.
* **Snapshot name format:**
  * \<policy name>-\<schedule type>.\<time-stamp format: YYMMDDHHMM>
  * Example: `policy1-weekly.2412301152`
* **Restricted manual uploads of policy-based snapshots:**
  * Snapshots created by policies cannot be manually uploaded to an object store. Ensure all uploads align with the configured policy.
* **Retaining snapshots outside rotation:**
  * To prevent a snapshot from being deleted during the rotation process, rename the snapshot to exclude it from automated deletion.
* **Manually upload snapshots to object store:**
  * To manually upload a policy-created snapshot that isn't configured for automatic object store upload, rename the snapshot. This change enables you to manually upload the snapshot and prevents automatic deletion.
* **Snapshot deletion with disabled policy:**
  * Snapshots of attached filesystems may still be deleted even when the policy is disabled. If the retention period is reduced, snapshots are deleted according to the updated retention settings, regardless of the policy's status.
* **Snapshot behavior during DST transitions**:

  The following behavior applies to snapshot schedules during Daylight Saving Time (DST) transitions:

  * **DST starts (clocks move forward):** The system creates snapshots scheduled in the skipped hour (for example, 2:00 AM to 3:00 AM) after the corresponding duration in the skipped interval, immediately following clock adjustment. For example, if a snapshot is scheduled for 2:15 AM, the system creates it at 3:15 AM. The system skips any other snapshot for the same schedule between 2:15 AM and 3:15 AM.
  * **DST ends (clocks move back):** The system does not duplicate snapshots scheduled in the repeated hour (for example, 1:00 AM to 2:00 AM), because the system already created them during the first pass.

**Related topics**

[Snapshots](/weka-filesystems-and-object-stores/snapshots)

[Background tasks](/operation-guide/background-tasks)


# Manage snapshot policies using the GUI

Manage snapshot policies using the GUI, ensuring efficient data protection.

Using the GUI, you can:

* Explore the snapshot policies
* Create a snapshot policy
* Attach filesystems to a snapshot policy
* Detach a filesystem from a snapshot policy
* Modify an existing snapshot policy
* Delete a snapshot policy

## Explore the snapshot policies

The **Snapshot Policies** page provides a centralized interface for managing and reviewing snapshot policies. This page allows administrators to search for specific policies, view a comprehensive list of configured policies, and examine detailed information about individual policies. Additionally, you can search for filesystems attached to a policy and view a list of all associated filesystems.

The following is a screenshot of the Snapshot Policies page with callouts highlighting its key features:

* **Search a policy:** Filter and identify specific snapshot policies by entering keywords in the search bar.
* **View the list of policies:** Browse all configured snapshot policies in a clear list format.
* **Details of a selected policy:** Access detailed configuration and status information for a highlighted snapshot policy.
* **Search for an attached filesystem:** Filter and identify specific filesystems assigned to the selected snapshot policy by entering keywords in the search bar.
* **View a list of attached filesystems:** See all filesystems assigned with the selected snapshot policy.

<div align="left" data-with-frame="true"><figure><img src="/files/gUXeclWNtBqznrdejBfV" alt=""><figcaption><p>Snapshot policies</p></figcaption></figure></div>

**Procedure**

1. From the **Manage** menu, select **Snapshot Policies**.

The next sections describe how to perform common tasks on this page, leveraging the features highlighted above.

## Create a snapshot policy

This procedure guides you through creating a snapshot policy, which includes defining the policy name, description, schedule, retention settings, and optional upload configuration. Follow these steps to configure a policy tailored to your data protection requirements.

<div align="center" data-with-frame="true"><figure><img src="/files/K1FR28dwewqPNPyuMOPn" alt="" width="563"><figcaption><p>Create a snapshot policy</p></figcaption></figure></div>

**Procedure**

1. From the **Manage** menu, select **Snapshot Policies**.
2. On the top-right of the **Snapshot Policies** page, select **+Create Policy**.
3. Configure the following settings:
   * **Policy Name:** Provide a descriptive name for the snapshot policy, up to 12 characters.
   * **Description:** Enter a brief description of the policy's purpose, up to 128 characters.
   * **Schedule:** Select the desired scheduling option:
     * **Hourly:** Creates one snapshot in specific hours or per hour with a customizable start time (offset).
     * **Daily:** Creates one snapshot at specific times and days.
     * **Weekly:** Creates one snapshot on specified days and times each week.
     * **Monthly:** Supports up to four snapshots on specified days, either monthly or in selected months.
     * **Periodic:** Creates snapshots at custom intervals within a defined time window.
   * **Retention:** Define the number of snapshots to retain, allowing for automatic rotation. Alternatively, use the default retention settings for the selected schedule.
   * **Upload to OBS (Object Store):** Specify whether to upload snapshots to a local, remote, or both object stores.
   * **Enable or disable the schedule:**
     * **ON:** Enable the schedule.
     * **OFF:** Disable the schedule.
4. Select **Save** to finalize the policy configuration.

The newly created snapshot policy appears in the list on the **Snapshot Policies** page.

## Attach filesystems to a snapshot policy

Attaching filesystems to a snapshot policy ensures that the policy governs the creation, management, and retention of snapshots for these specific filesystems. This association helps maintain consistent data protection and recovery practices across selected filesystems.

<div data-with-frame="true"><figure><img src="/files/UUD0aChujxXkkZZgR0qV" alt=""><figcaption><p>Attach a snapshot policy to a filesystem</p></figcaption></figure></div>

**Procedure**

1. Select the snapshot policy to which you want to attach a filesystem from the **Snapshot Policies** list.
2. In the **Assigned Filesystems** pane on the right, click the **Attach Filesystems** icon (represented by a link symbol) to open the attachment dialog.
3. Select the required filesystems from the available list.
4. Select **Attach** to complete the process.

The filesystem is associated with the selected snapshot policy, and the policy's configurations apply to snapshots for the attached filesystem.

## Detach filesystems from a snapshot policy

Detaching filesystems from a snapshot policy can be necessary when you no longer need to associate the filesystems with the policy, either due to changes in backup strategies or system configurations. This procedure ensures that the filesystems are removed from the policy without affecting its data or storage.

<div data-with-frame="true"><figure><img src="/files/bMdsaQEZ4XczHl9G7YWF" alt=""><figcaption><p>Detach a snapshot policy from a filesystem</p></figcaption></figure></div>

**Procedure**

1. Navigate to the list of snapshot policies and choose the one from which you want to detach filesystems.
2. In the **Assigned Filesystems** pane (on the right), locate the filesystems you want to detach.
3. Move your mouse over the **Detach** icon (represented by an unlink symbol).
4. In the Detach dialog, choose **ON** if you also want to remove any waiting tasks associated with the filesystems.
5. Select **Detach** to complete the process.

## Modify an existing snapshot policy

Updating a snapshot policy is necessary when modifications to schedules, retention settings, or other parameters are required to align with evolving data protection needs. Regularly reviewing and updating policies ensures that they remain effective and consistent with organizational objectives.

<div data-with-frame="true"><figure><img src="/files/WpLKjNCjiupwKnO7W47j" alt=""><figcaption><p>Update a snapshot policy</p></figcaption></figure></div>

**Procedure**

1. Select the snapshot policy you want to update from the **Snapshot Policies** list.
2. Modify the policy configuration as needed:\
   Update the policy name, description, schedule, retention, object store upload, or status settings.
3. Select **Save** to apply the changes.

The updated snapshot policy immediately reflects the new configuration and continue managing snapshots based on the revised settings.

## Set policy status

You can enable or disable a policy directly from the policies list pane, for example, to temporarily disable a policy while adjusting configurations.

**Procedure**

1. In the policies list pane, locate the desired policy.
2. Click on the current status of the policy (Enabled or Disabled).

<div align="center" data-with-frame="true"><figure><img src="/files/EZA2b5XVkF8fPVaXxxyU" alt="" width="455"><figcaption></figcaption></figure></div>

3. In the confirmation message that appears, select **Yes** to confirm the status change.

<div align="center" data-with-frame="true"><figure><img src="/files/T0YQ8jG0Ysic1nICExO5" alt="" width="257"><figcaption></figcaption></figure></div>

## Delete a snapshot policy

Snapshot policies may need to be deleted when they are no longer required, are incorrectly configured, or are replaced by updated policies. Removing unnecessary policies helps maintain a clean and manageable environment, ensuring that only relevant configurations are active.

<div align="center" data-with-frame="true"><figure><img src="/files/IobCGxjwOGrkvfJ8EjJD" alt="" width="375"><figcaption><p>Delete a snapshot policy</p></figcaption></figure></div>

**Procedure**

1. Select the snapshot policy you wish to delete from the **Snapshot Policies** list.
2. Move your mouse over the policy and click the **trash icon**.
3. In the **Remove Snapshot Policy** confirmation message, select **Yes** to confirm the deletion.

The selected snapshot policy is permanently removed and is no longer appear in the policy list.


# Manage snapshot policies using the CLI

Manage snapshot policies using the CLI, ensuring efficient data protection and disaster recovery.

## Overview

Creating policies using the CLI involves leveraging policy templates for efficient and consistent policy management that align with organizational requirements.

**Process overview:**

1. **Export an existing policy to a template**:\
   The first step in creating a policy template is exporting an existing policy. If this is your first time, you can use the `sys-default` policy (json file), a predefined system policy that serves as a baseline. The `sys-default` policy is not editable, so it is ideal for use as an initial template.
2. **Edit the exported policy template**:\
   After exporting the `sys-default` policy, you can modify the exported json file to suit your specific requirements. This customization allows you to create tailored templates for different groups of policies, streamlining policy creation for various scenarios.
3. **Create a policy from a policy template**:\
   Create a new policy from the desired policy template and customize it further as needed to address specific use cases. This approach provides flexibility while ensuring consistency across policies derived from the same template.
4. **Attach filesystems to a snapshot policy**:\
   Attach the relevant filesystems to the snapshot policy to ensure that the policy governs the creation, management, and retention of snapshots for these specific filesystems. This step links the policy to the filesystems, enabling consistent enforcement of snapshot rules and schedules.

After understanding the workflow for creating policies using the CLI, you can use the following commands to manage snapshot policies:

* List snapshot policies
* Show snapshot policy details
* Export snapshot policy
* Create snapshot policy
* Attach filesystems to a snapshot policy
* Detach filesystems from a snapshot policy
* Update snapshot policy
* Delete snapshot policy

## List snapshot policies

**Command:** `weka fs protection snapshot-policy list`

This command displays a list of all existing snapshot policies in the system. The output includes details such as the policy ID, name, enabled status, description, and any filesystems the policy is attached to.

```sh
weka fs protection snapshot-policy list
```

<details>

<summary>Example: List snapshot policies</summary>

```bash
$ weka fs protection snapshot-policy list
SNAPSHOT POLICY ID  NAME         IS ENABLED  DESCRIPTION                                                                                         ATTACHED FILESYSTEMS
0                   sys-default  True        This snapshot policy is a fixed example configuration, it can be used as-is but cannot be modified
1                   weekly       True        Create a snapshot weekly on Saturdays                                                               fs1
2                   Policy1      True        Schedule daily snapshots                                                                            fs1, default
```

</details>

## Show snapshot policy details

**Command:** `weka fs protection snapshot-policy show`

This command displays the configuration of a snapshot policy in JSON format. It provides a detailed representation of the policy, including schedules (hourly, daily, weekly, monthly, and periodic), retention settings, associated filesystems, and whether specific features are enabled.

**JSON overview**

* **Schedules**: Defines hourly, daily, weekly, monthly, and periodic snapshot schedules, including time, days, and upload settings.
* **Retention**: Specifies the number of snapshots to retain for each schedule type.
* **Filesystems**: Lists the filesystems attached to the policy.
* **General settings**: Includes the policy name, description, and enable/disable status.

```sh
weka fs protection snapshot-policy show <name>
```

**Parameters**

<table><thead><tr><th width="272">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Policy name</td></tr></tbody></table>

<details>

<summary>Example: Show snapshot policy details</summary>

```
$ weka fs protection snapshot-policy show Policy1
{
    "daily": {
        "days": "monday, wednesday, friday",
        "enable": true,
        "retention": 7,
        "time": "22:05",
        "upload": "local"
    },
    "description": "Policy description",
    "enabled": true,
    "filesystems": [
        "fs1",
        "default"
    ],
    "hourly": {
        "days": "monday, tuesday, wednesday, thursday, friday",
        "enable": false,
        "hours": "09, 10, 11, 12, 13, 14, 15, 16, 17, 18",
        "minuteOffset": 10,
        "retention": 10,
        "upload": "none"
    },
    "monthly": {
        "days": "07",
        "enable": false,
        "months": "all",
        "retention": 12,
        "time": "00:05",
        "upload": "local"
    },
    "name": "Policy1",
    "periodic": {
        "days": "monday, tuesday, wednesday, thursday, friday",
        "enable": false,
        "end_time": "18:00",
        "interval": 30,
        "retention": 4,
        "start_time": "09:00",
        "upload": "none"
    },
    "weekly": {
        "days": "saturday",
        "enable": false,
        "retention": 4,
        "time": "23:05",
        "upload": "local"
    }
}
```

</details>

## Export snapshot policy

**Command:** `weka fs protection snapshot-policy export`

This command exports the configuration of an existing snapshot policy to a template file. Use the `sys-default` policy to export the cluster's default configuration as a baseline for creating customized policy templates.

```sh
weka fs protection snapshot-policy export <name> <path>
```

**Parameters**

<table><thead><tr><th width="208">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>The snapshot policy to export.</td></tr><tr><td><code>path</code>*</td><td>The path to the directory to save the export policy file.</td></tr></tbody></table>

<details>

<summary>Example: Export snapshot policy</summary>

```
$ weka fs protection snapshot-policy export sys-default /tmp/policy_template
Exported snapshot policy to /tmp/policy_template
```

</details>

### Customize the policy template

To customize a policy template, follow these steps:

1. **Open the exported template**:\
   Use a text editor, such as `vi`, to open the policy template file that you exported from the `sys-default` template or an existing snapshot policy.
2. **Modify configuration details**:\
   Edit the template to customize the policy's configuration, such as schedules, retention rules, or other relevant settings, to meet your specific requirements.
3. **Reuse the customized template**:\
   Save your changes. The modified template can now be used to create new policies tailored to your needs.

<details>

<summary>Example: Customize the policy template</summary>

In this example, the daily schedule is set for Monday, Wednesday, and Friday. The remaining schedules are disabled (`"enable"=false,`).

```
$ vi /tmp/policy_template

{
    "daily": {
        "days": "monday, wednesday, friday",
        "enable": true,
        "retention": 7,
        "time": "12:10",
        "upload": "local"
    },
    "hourly": {
        "days": "monday, tuesday, wednesday, thursday, friday",
        "enable": false,
        "hours": "09, 10, 11, 12, 13, 14, 15, 16, 17, 18",
        "minuteOffset": 5,
        "retention": 10,
        "upload": "none"
    },
    "monthly": {
        "days": "07",
        "enable": false,
        "months": "all",
        "retention": 12,
        "time": "00:05",
        "upload": "local"
    },
    "periodic": {
        "days": "monday, tuesday, wednesday, thursday, friday",
        "enable": false,
        "end_time": "18:00",
        "interval": 30,
        "retention": 4,
        "start_time": "09:00",
        "upload": "none"
    },
    "weekly": {
        "days": "saturday",
        "enable": false,
        "retention": 4,
        "time": "23:05",
        "upload": "local"
    }
}
-- INSERT --
```

</details>

## Create snapshot policy

**Command:** `weka fs protection snapshot-policy add`

This command creates a new snapshot policy based on a specified template file. Provide the policy name, template file path, and optional parameters such as a description or enabled status.

{% code overflow="wrap" %}

```sh
weka fs protection snapshot-policy add <name> <path> [--description description] [--enabled enabled]
```

{% endcode %}

**Parameters**

<table><thead><tr><th width="170">Parameter</th><th width="483">Description</th><th>Default</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>The snapshot policy name. Up to 12 alphanumeric characters, hyphens (-), underscores (_), and periods (.)</td><td></td></tr><tr><td><code>path</code>*</td><td>The path to the snapshot policy file. It must be in JSON format.</td><td></td></tr><tr><td><code>description</code></td><td>Policy description. Up to 128 characters.</td><td></td></tr><tr><td><code>enabled</code></td><td>Set snapshot policy status.<br>Possible values: <code>true</code> or <code>false</code></td><td><code>true</code></td></tr></tbody></table>

<details>

<summary>Example: Create a snapshot policy from a policy template</summary>

In this example, a new snapshot policy named `policy2` is created using the template file located at `/tmp/policy_template`. The system returns the newly created policy's ID.

```
$ weka fs protection snapshot-policy create policy2 /tmp/policy_template
SnapPolicyId: 3
```

</details>

## Attach filesystems to a snapshot policy

**Command:** **weka fs protection snapshot-policy attach**

This command attaches existing filesystems to a snapshot policy. Before proceeding, ensure each filesystem is attached to an object store.

```sh
weka fs protection snapshot-policy attach <name> [<filesystems>]...
```

**Parameters**

| Parameter           | Description                                             |
| ------------------- | ------------------------------------------------------- |
| `name`\*            | The snapshot policy name.                               |
| `filesystems`... \* | A list of filesystems you want to attach to the policy. |

<details>

<summary>Example:</summary>

This command attaches the snapshot policy `policy1` to the filesystems `fs1` and `default`.

```
$ weka fs protection snapshot-policy attach policy1 fs1 default
$ weka fs protection snapshot-policy list
SNAPSHOT POLICY ID  NAME         IS ENABLED  DESCRIPTION                     ATTACHED FILESYSTEMS
0                   sys-default  True        Cluster default configuration  
1                   policy1      False       Schedule daily snapshots        fs1, default
```

</details>

## Detach filesystems from a snapshot policy

**Command:** `weka fs protection snapshot-policy detach`

This command detaches the specified filesystems from the snapshot policy. To remove waiting tasks associated with the filesystems, add the `--remove-waiting-tasks` option.

<pre data-overflow="wrap"><code><strong>weka fs protection snapshot-policy detach &#x3C;name> [--remove-waiting-tasks] [&#x3C;filesystems>]...
</strong></code></pre>

**Parameters**

<table><thead><tr><th width="289">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>The snapshot policy name.</td></tr><tr><td><code>filesystems</code>... *</td><td>A list of filesystems you want to detach from the policy.</td></tr><tr><td><code>remove-waiting-tasks</code></td><td>Allow to delete all waiting tasks corresponding to the filesystems.</td></tr></tbody></table>

<details>

<summary>Example: Detach a snapshot policy from filesystems</summary>

```
$ weka fs protection snapshot-policy detach pol1 fs1

Warning: You are about to detach filesystems. This action detach existing filesystem from the snapshot policy and cannot be undone.
Are you sure you want to continue (yes/no)? yes
Filesystems detached successfully
```

</details>

## Update a snapshot policy

**Command:** `weka fs protection snapshot-policy update`

This command updates an existing snapshot policy. You can modify its name, description, policy parameters or enabled status.

{% code overflow="wrap" %}

```sh
weka fs protection snapshot-policy update <name> [--new-name new-name] [--description description] [--path path] [--enabled enabled]
```

{% endcode %}

**Parameters**

<table><thead><tr><th width="266">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Existing snapshot policy name.</td></tr><tr><td><code>new-name</code></td><td>New policy name. Up to 12 alphanumeric characters, hyphens (-), underscores (_), and periods (.).</td></tr><tr><td><code>description</code></td><td>New policy description. Up to 128 characters.</td></tr><tr><td><code>path</code></td><td>The path to the new or modified snapshot policy file. It must be in JSON format.</td></tr><tr><td><code>enabled</code></td><td>Set snapshot policy status.<br>Possible values: <code>true</code> or <code>false</code></td></tr></tbody></table>

## Delete a snapshot policy

**Command:** `weka fs protection snapshot-policy delete <name>`

This command deletes the specified snapshot policy from the system. Ensure that no filesystems are attached to the policy before proceeding with the deletion.

```
weka fs protection snapshot-policy delete <name>
```

**Parameters**

<table><thead><tr><th width="223">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><code>name</code>*</td><td>Existing snapshot policy name.</td></tr></tbody></table>

<details>

<summary>Example: Delete a snapshot policy</summary>

```
$ weka fs protection snapshot-policy delete policy2
Warning: You are about to delete a snapshot policy. This action deletes the snapshot policy and cannot be undone.

Are you sure you want to continue (yes/no)? yes
```

</details>


# Quota management

Implement quota management to monitor and control usage of the WEKA filesystem effectively.

## Overview

The WEKA system offers multiple layers where you can limit capacity usage:

* **Tenant level**: Monitor tenant usage, including SSD and total capacity, and restrict usage with quotas per tenant. Use this quota for chargebacks based on consumed or allocated SSD or object store capacity. See [Multi-tenancy cluster-level administration](/operation-guide/weka-native-multi-tenancy-management/multi-tenancy-cluster-level-administration).
* **Filesystem level**: Allocate a unique filesystem for each department or project.
* **Directory level**: Assign a unique quota for each project directory (beneficial when users are involved in multiple projects) or for each user’s home directory.
* **User and group level:** Assign a quota per user (UID) or per group (GID) to limit the total capacity consumed across the entire filesystem, regardless of which directories the user writes to. User and group quotas complement directory quotas: when both apply to a write operation, the most restrictive limit takes effect. User and group quota management is available through the CLI and REST API.

A tenant administrator can set a quota on a directory. This action initiates calculating the current directory usage in a background task. Once this calculation is complete, the quota is considered.

The tenant administrator sets quotas to inform users and prevent overuse of filesystem capacity. Only data that the user controls is considered. The quota does not include protection overhead or snapshots. It includes file data and metadata in the directory, whether tiered or not.

## Guidelines for quota management

When managing quotas, adhere to the following guidelines and requirements.

### Prerequisites

* Configure at least one Data Services container before setting any quotas. This is the recommended approach and does not require a filesystem mount. For details, see [Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks).
* If no Data Services container is available, quota operations fall back to single-process mode using a filesystem mount. In this mode:
  * The target filesystem must be mounted natively through POSIX on the server where the quota command runs.
  * The quota `set` command must run to completion without interruption, as it triggers quota accounting.
  * The POSIX user running the command must have access to the target directory within the mount point. This requirement applies even if the user has elevated privileges (for example, tenant administrator or higher).
  * If the POSIX user does not have access to the target directory, use the `--filesystem` flag and provide the path to the directory relative to the root of the target filesystem.
  * Without a Data Services container, quota operations may cause the CLI to hang for extended periods.

### Quota coloring and accounting

* When setting or unsetting a directory quota, a background process called `QUOTA_COLORING` runs. This process scans the entire directory tree and assigns the quota ID to all files and directories under it.
* When enabling user or group quotas on an existing filesystem, the same `QUOTA_COLORING` process runs to stamp existing objects with the appropriate UID or GID quota identifiers. Quotas are not enforced on pre-existing data until this process completes.
* Ownership changes (`chown` / `chgrp`) trigger an asynchronous reattribution of the file's capacity from the previous UID or GID quota domain to the new one. During the transition, usage counters may temporarily reflect the previous owner.

### Capacity enforcement

* User and group quotas track capacity across the entire filesystem, not per directory. A user's total writes across all directories contribute to a single quota domain.
* A single write operation may be subject to multiple active quota domains simultaneously: a directory quota, a user quota, and a group quota. WEKA enforces the most restrictive remaining capacity among all applicable domains.
* When a quota domain is exhausted, writes fail with `ENOSPC`.
* When quotas are enforced in `writecache` mount mode, exceeding a quota may leave some cache writes unsynced with backend servers. This behavior is consistent with other POSIX implementations. To ensure data integrity, use `sync`, `syncfs`, or `fsync` to explicitly commit changes to the backend (or fail if the quota is exceeded).

### Nested quotas

* Quotas can be defined within nested directories, up to four levels deep.
* Over-provisioning is supported under the same directory quota tree.
* Example: the `/home` directory has a 1 TiB quota, and 200 user directories under `/home` each have a 10 GiB quota. This setup exceeds 1 TiB in total child quotas but is valid. The parent quota always takes precedence and is enforced across all subdirectories.

### Hard links

* Set quotas before creating hard links to ensure accurate quota accounting.
* When a quota is set on a directory, files with two or more existing hard links are excluded from quota accounting. The system cannot verify that all links reside within the same quota boundary.
* Use files with a single hard link in quota-controlled directories to ensure accurate tracking.
* Quota rules apply only to newly created hard links. Pre-existing hard links are unaffected.
* Keep all hard links to a file within the same quota boundary to ensure consistent behavior.
* Do not create a hard link across different quotas.

### File movement

* The `rename()` operation, when implemented by `link()` and `unlink()`, behaves like an atomic file move across filesystems.
* Moving files into or out of quota-enforced directories triggers `EXDEV` (cross-device link error).
* Applications must fall back to a copy-and-delete workflow: copy the file to the new location, then delete the original. Standard tools such as `mv` in Linux handle this automatically.

### Snapshots and filesystem recovery

* Snapshot capacity is tracked separately from the live filesystem and does not count toward a user or group quota in the live filesystem. Writable snapshot usage is accounted independently within the snapshot scope.
* Restoring a filesystem from a snapshot reverts quotas to their configuration at the time of the snapshot.
* Creating a new filesystem from a snap-to-object does not preserve the original quotas.

## Integration with the `df` utility for directory quotas

By default, when a hard quota is set on a directory, the `df` utility interprets it as the directory's total capacity and displays the usage percentage (`use%`) relative to that quota. This helps users understand their storage usage and proximity to the quota limit.

This integration applies to directory quotas only. It is not available for user or group level quotas.

{% hint style="info" %}
The `df` utility integration with quotas is a global setting in the WEKA system. To change this global behavior to use soft quotas or to ignore quotas instead, contact the [Customer Success Team](/support/getting-support-for-your-weka-system#contact-customer-success-team).
{% endhint %}


# Manage quotas using the GUI

Manage directory quotas and default quota settings for your filesystems using the WEKA GUI.

Using the GUI, you can:

* [Set default directory quota](#set-default-directory-quota)
* [Set directory quota](#set-directory-quota)
* [View directory quotas and default quota](#view-directory-quotas-and-default-quota)
* [Update a directory quota or default quota](#update-a-directory-quota-or-default-quota)
* [Remove a directory quota](#remove-a-directory-quota)
* [Remove the default quota for new directories](#remove-the-default-quota-for-new-directories)

{% hint style="info" %}
To manage user or group quota, use the CLI. See [Manage quotas using the CLI](/weka-filesystems-and-object-stores/quota-management/quota-management).
{% endhint %}

## Set default directory quota

A default directory quota automatically applies quota limits to every new subdirectory created under a specified parent directory. It does not apply retroactively to existing subdirectories. Use it for cases where new directories should inherit consistent limits by default, such as user home directories or project folders.

**Before you begin**

Ensure a mount point to the relevant filesystem is set.

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select the **Default Directory Quotas** tab, then select **Create**.
3. Select the filesystem the default quota applies to..
4. In the **Create Default Quota** dialog, set the following fields:
   * **Directory Path:** The full path to the parent directory. New subdirectories created under this path will automatically inherit the quota.
   * **Hard Quota Limit:** The maximum capacity a subdirectory can use. Writes are blocked when this limit is reached.
   * **Soft Quota Limit:** The capacity threshold that starts the grace period timer. Writes are allowed until the grace period expires or the hard quota limit is reached.
   * **Owner:** Optional. An identifier for the directory owner, such as a username, email address, or Slack ID (up to 48 characters).
   * **Grace Period:** The time allowed after the soft quota limit is reached before writes are blocked.
5. Select **Save**.

<div data-with-frame="true"><figure><img src="/files/TsY0d1205aQ7Iuqjf1Xd" alt=""><figcaption><p>Set default directory quota</p></figcaption></figure></div>

## Set directory quota

The tenant admin can set a quota on a directory, which triggers a background task to calculate the current usage. Once this calculation is finished, the quota takes effect.

**Before you begin**

* To apply a quota to a directory, ensure there is a mount point for the relevant filesystem.
* Configure at least one Data Services container before setting a directory quota. The **Create** button is not available until a Data Services container is active. See

  &#x20;See [Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks).

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select **Directory Quotas**.
3. Select the filesystem the directory quota applies to.
4. In the Create Quota dialog, set the following:
   * **Directory Path:** The full path to the directory quota to be set on.
   * **Hard Quota Limit:** The hard quota limit defines the maximum used capacity above the soft quota limit, which prevents writing to the directory.
   * **Soft Quota Limit:** The soft quota limit defines the maximum used capacity that triggers a grace period timer. Data can be written to the directory until the grace period ends or the hard quota limit is reached.
   * **Owner:** The directory’s owner, such as user name, email, or slack ID (up to 48 characters).
   * **Grace Period:** When the soft quota limit is reached, a grace period starts. After this period, data cannot be written to the directory.\
     The system sets the directory quota in the background.
5. To monitor the directory quota setting background task, select **Monitor > Background Tasks.**

<div data-with-frame="true"><figure><img src="/files/yEe7EAqZfEV2h59Hv5Uh" alt=""><figcaption><p>Set a directory quota and monitor the background task</p></figcaption></figure></div>

## View directory quotas and default quota

You can view existing directory quotas and the default quota that are already set.

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select the relevant tab: **Directory Quotas** or **Default Directories Quota**.
3. Select the filesystem in which the directory quotas are already set.
4. To view all quotas or only the exceeding quotas, select the **Exceeding quotas/All quotas** switch.

<div data-with-frame="true"><figure><img src="/files/XAli2nTmOkAEQphcu6t4" alt=""><figcaption><p>View directory quotas and default quota</p></figcaption></figure></div>

## Update a directory quota or default quota

You can update an existing directory quota or the default quota for directories. Updating the default quota only applies to new directories.

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select the relevant tab: **Directory Quotas** or **Default Directories Quota**.
3. Select the filesystem in which the directory quotas are set (through the CLI).
4. Select the three dots on the right of the required directory. From the menu, select **Update**.

<div data-with-frame="true"><figure><img src="/files/XXLKhoVyNhfSBoGOv39u" alt=""><figcaption><p>Directory Quotas</p></figcaption></figure></div>

5. In the Quota Settings Update dialog, modify the following settings according to your needs:
   * **Hard Quota Limit:** The hard quota limit defines the maximum used capacity above the soft quota limit, which prevents writing to the directory.
   * **Soft Quota Limit:** The soft quota limit defines the maximum used capacity that triggers a grace period timer. Data can be written to the directory until the grace period ends or the hard quota limit is reached.
   * **Owner:** The directory’s owner, such as user name, email, or slack ID (up to 48 characters).
   * **Grace Period:** When the soft quota limit is reached, a grace period starts. After this period, data cannot be written to the directory.
6. Click **Save**.

<div align="center" data-with-frame="true"><figure><img src="/files/NGVrTiZ4x7ngP9HeRAdV" alt="" width="264"><figcaption><p>Quota Settings Update</p></figcaption></figure></div>

## Remove a directory quota

You can remove (unset) a directory quota if it is no longer required.

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select the **Directory Quotas** tab.
3. Select the filesystem in which the directory quota is set.
4. Select the three dots on the right of the required default quota. From the menu, select **Remove**.
5. In the Quota Deletion message, select **Yes**.

<div data-with-frame="true"><figure><img src="/files/EAJPIyQ3AVVisi5U1hhe" alt=""><figcaption><p>Remove a default quota</p></figcaption></figure></div>

## Remove the default quota for new directories

You can remove (unset) the default quota settings for new directories created in a specific filesystem. The quota of existing directories is not affected.

**Procedure**

1. From the menu, select **Manage > Directory Quotas**.
2. Select the **Default Directories Quota** tab.
3. Select the filesystem in which the default quotas are already set.
4. Select the three dots on the right of the required default quota. From the menu, select **Remove**.
5. In the Default Quota Deletion message, select **Yes**.


# Manage quotas using the CLI

Manage directory, user, and group quotas for your filesystems using the WEKA CLI.

Using the CLI, you can:

* [Set default quota](#set-default-quota)
* [Set quota](#set-quota)
* [Enable or disable user quota accounting](#enable-or-disable-user-quota-accounting)
* [List quotas or default quotas](#list-quotas-or-default-quotas)
* [Unset default quota](#unset-default-quota)
* [Reset quota](#reset-quota)

## Set default quota

**Command**: `weka fs quota set-default`

Sets the default quota for the specified path. The default quota is automatically applied when new instances of the selected quota type are created under that path. For example, when a new subdirectory is created (`directory` type), or when a new user or group starts consuming space in the filesystem (`user` or `group` type).

Before using this command, ensure that a mount point to the relevant filesystem is set.

`weka fs quota set-default <path> [--type type] [--soft soft] [--hard hard] [--grace grace] [--owner owner]`

#### **Parameters**

<table><thead><tr><th width="107">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>path</code>*</td><td>Path to the directory to set the quota. Required for directory quota only.<br>The relevant filesystem must be mounted when setting the quota.</td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code><br>Default: <code>directory</code></p></td></tr><tr><td><code>soft</code></td><td>Soft quota limit.<br>Exceeding this number is displayed as an exceeded quota, but it is not enforced until the <code>grace</code> period is over.<br>The capacity can be in decimal or binary units.<br>Format: <code>1GB</code>, <code>1TB</code>, <code>1GiB</code>, <code>1TiB</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>hard</code></td><td>Hard quota limit.<br>Exceeding this number does not allow more writes before clearing some space in the directory.<br>The capacity can be in decimal or binary units.<br>Format: <code>1GB</code>, <code>1TB</code>, <code>1GiB</code>, <code>1TiB</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>grace</code></td><td>Specify the grace period before the soft limit is treated as a hard limit.<br>Format: <code>1d</code>, <code>1w</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>owner</code></td><td>A unique string identifying the directory owner (can be a name, email, slack ID, and so on.) This owner is shown in the quota report and can be notified upon exceeding the quota. Supports up to 48 characters.</td></tr></tbody></table>

{% hint style="info" %}

* To set advisory only quotas, use a `soft` quota limit without setting a `grace` period.
* When `hard` and `soft` quotas exist, setting the value of one of them to `0` clears this quota.
  {% endhint %}

<details>

<summary>Set and display default user and group quotas</summary>

**Set a default user quota**

A default user quota is automatically applied to any new user who starts consuming space in the filesystem. Use the following command to set it:

```bash
weka fs quota set-default --type user --soft <soft-limit> --hard <hard-limit> <path>
```

**Example:** Set a default 90 GB soft limit and a 100 GB hard limit for all new users writing to `/mnt/default`:

```bash
weka fs quota set-default --type user --soft 90GB --hard 100GB /mnt/default
```

**Set a default group quota**

A default group quota is automatically applied to any new group that starts consuming space in the filesystem. Use the following command to set it:

```bash
weka fs quota set-default --type group --soft <soft-limit> --hard <hard-limit> <path>
```

**Example:** Set a default 450 GB soft limit and a 500 GB hard limit for all new groups writing to `/mnt/default`:

```bash
weka fs quota set-default --type group --soft 450GB --hard 500GB /mnt/default
```

**Display default user quotas**

Use the following command to list all default user quotas:

```bash
weka fs quota list-default --type user
```

To list default user quotas for a specific filesystem:

```bash
weka fs quota list-default <filesystem-name> --type user
```

**Display default group quotas**

Use the following command to list all default group quotas:

```bash
weka fs quota list-default --type group
```

To list default group quotas for a specific filesystem:

```bash
weka fs quota list-default <filesystem-name> --type group
```

</details>

## Set quota

**Command**: `weka fs quota set`

Before setting a quota, check which scenario applies:

* **Directory quota:** A Data Services container is required to run the `QUOTA_COLORING` background task.
* **User or group quota on filesystems created in WEKA 5.1.20 or later:** User quota accounting is enabled automatically. No Data Services container is required.
* **User or group quota on filesystems created before WEKA 5.1.20:** Run `weka fs quota enable-users` before setting the quota. A Data Services container is required for this one-time operation.

**Related topic**

[Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks).

Use the following command to set a quota:

`weka fs quota set <path> [--type type] [--id id] [--soft soft] [--hard hard] [--grace grace] [--owner owner] [--filesystem filesystem] [--snap-name snap-name] [--color color]`

**Parameters**

<table><thead><tr><th width="134">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>path</code>*</td><td>Path to the directory to set the quota. Required for directory quota only.<br>The relevant filesystem must be mounted when setting the quota.</td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code><br>Default: <code>directory</code></p></td></tr><tr><td><code>id</code></td><td>The UID or GID the quota applies to. Required when <strong><code>type</code></strong> is <code>user</code> or <code>group</code>.</td></tr><tr><td><code>soft</code></td><td>Soft quota limit.<br>Exceeding this number is displayed as an exceeded quota, but it is not enforced until the <code>grace</code> period is over.<br>The capacity can be in decimal or binary units.<br>Format: <code>1GB</code>, <code>1TB</code>, <code>1GiB</code>, <code>1TiB</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>hard</code></td><td>Hard quota limit.<br>Exceeding this number does not allow more writes before clearing some space in the directory.<br>The capacity can be in decimal or binary units.<br>Format: <code>1GB</code>, <code>1TB</code>, <code>1GiB</code>, <code>1TiB</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>grace</code></td><td>Specify the grace period before the soft limit is treated as a hard limit.<br>Format: <code>1d</code>, <code>1w</code>, <code>unlimited</code><br>Default: <code>unlimited</code></td></tr><tr><td><code>owner</code></td><td>A unique string identifying the directory owner (can be a name, email, slack ID, and so on.) This owner will be shown in the quota report and can be notified upon exceeding the quota.<br>Supports up to 48 characters.</td></tr><tr><td><code>filesystem</code></td><td>Specifies the target filesystem for applying the quota. This parameter only applies for user or group quota. Use this parameter when the quota must be enforced outside of a mount point, or in cases where the POSIX user does not have direct access to the directory through a mounted path.<br>For requirement details, see <a data-mention href="/pages/-MNHl-A73zrRftNBsDnu#guidelines-for-quota-management">/pages/-MNHl-A73zrRftNBsDnu#guidelines-for-quota-management</a>.</td></tr><tr><td><code>snap-name</code></td><td>Name of the writable snapshot. Use this parameter to set a quota outside the mount point.</td></tr></tbody></table>

<details>

<summary>Set and display user and group quotas</summary>

**Set a user quota**

Use the following command to set a quota for a specific user:

```bash
weka fs quota set --type user --id <UID> --soft <soft-limit> --hard <hard-limit> --filesystem <filesystem-name>
```

**Example:** Set a 90 GB soft limit and a 100 GB hard limit for user ID 1001 on the filesystem `default`:

```bash
weka fs quota set --type user --id 1001 --soft 90GB --hard 100GB --filesystem default
```

**Set a group quota**

Use the following command to set a quota for a specific group:

```bash
weka fs quota set --type group --id <GID> --soft <soft-limit> --hard <hard-limit> --filesystem <filesystem-name>
```

**Example:** Set a 450 GB soft limit and a 500 GB hard limit for group ID 2001 on the filesystem `default`:

```bash
weka fs quota set --type group --id 2001 --soft 450GB --hard 500GB --filesystem default
```

**Display user quotas**

Use the following command to list all user quotas across all filesystems:

```bash
weka fs quota list --type user
```

To list user quotas for a specific filesystem:

```bash
weka fs quota list <filesystem-name> --type user --all
```

By default, only quotas that exceed their limits are displayed. Use `--all` to display all user quotas, including those within their limits.

**Display group quotas**

Use the following command to list all group quotas across all filesystems:

```bash
weka fs quota list --type group
```

To list group quotas for a specific filesystem:

```bash
weka fs quota list <filesystem-name> --type group --all
```

</details>

## Enable or disable user quota accounting

**Command**: `weka fs quota enable-users` / `weka fs quota disable-users`

User quota accounting applies to both user quotas and group quotas.

* **Filesystems created in WEKA 5.1.20 or later:** User quota accounting is enabled automatically. User and group quotas can be set immediately.
* **Filesystems created before WEKA 5.1.20:** Enable user quota accounting before setting user or group quotas. Run the following command:

```bash
weka fs quota enable-users <filesystem>
```

This triggers a one-time background `QUOTA_COLORING` task that stamps existing objects with UID quota identifiers. A Data Services container must be running on the cluster for this operation to complete.

There is no fallback mode for this operation. If no Data Services container is available, the command does not complete.

Per-user and per-group quota limits can be set after accounting is enabled.

To disable user quota accounting, run the following command:

```bash
weka fs quota disable-users <filesystem>
```

{% hint style="info" %}
Only a Data Services container is required to enable user quota accounting on an existing filesystem. A frontend container on the backend server is not required for this operation.
{% endhint %}

**Parameters**

<table><thead><tr><th width="157">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>filesystem</code>*</td><td>Filesystem name.</td></tr><tr><td><code>snap-name</code></td><td>Name of the writable snapshot.</td></tr></tbody></table>

## List quotas or default quotas

**Command**: `weka fs quota list` / `weka fs quota list-default`

Use the following command to list the quotas (by default, only exceeding quotas are listed):

`weka fs quota list [filesystem] [--snap-name snap-name] [--type type] [--path path] [--under under] [--over over] [--quick] [--all]`

**Parameters**

<table><thead><tr><th width="133">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>filesystem</code></td><td>Filesystem name. Use this parameter to display a quota report only on the specified filesystem.<br>Default: All filesystems</td></tr><tr><td><code>snap-name</code></td><td>Displays the quota report from the time of the snapshot.<br>It must be a valid snapshot name and be given along with the corresponding filesystem.</td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code><br>Default: <code>directory</code></p></td></tr><tr><td><code>path</code></td><td>Path to a directory. Shows quota report only on the specified directory.<br>The relevant filesystem must be mounted in the server running the query.</td></tr><tr><td><code>under</code></td><td>A path to a directory under a wekafs mount.<br>The relevant filesystem must be mounted in the server running the query.</td></tr><tr><td><code>over</code></td><td>Shows only quotas over this percentage of usage.<br>Possible values: <code>0</code>-<code>100</code></td></tr><tr><td><code>quick</code></td><td>Do not resolve inode to a path. Provides quicker results if the report contains many entries.<br>Default: False</td></tr><tr><td><code>all</code></td><td>Shows all the quotas, not just the exceeding ones.<br>Default: False</td></tr></tbody></table>

Use the following command to list the directory default quotas:

`weka fs quota list-default [filesystem] [--snap-name snap-name] [--type type] [--path path]`

#### **Parameters**

<table><thead><tr><th width="156">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>filesystem</code></td><td>Filesystem name. Use this parameter to display the default quotas only on the specified filesystem.<br>Default: All filesystems</td></tr><tr><td><code>snap-name</code></td><td>Displays the default quotas from the time of the snapshot.<br>It must be a valid snapshot name and specified along with the corresponding <code>fs-name.</code></td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code><br>Default: <code>directory</code></p></td></tr><tr><td><code>path</code></td><td>Path to a directory. Shows the default quotas report only on the specified directory.<br>The relevant filesystem must be mounted in the server running the query.</td></tr></tbody></table>

## Unset default quota

**Command**: `weka fs quota unset-default`

Use the following command to unset a default quota of a directory:

`weka fs quota unset-default <path> [--type type] [--filesystem filesystem] [--snap-name snap-name]`

**Parameters**

<table><thead><tr><th width="157">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>path</code>*</td><td>Path to the directory to set the quota.<br>The relevant filesystem must be mounted when setting the quota.</td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code></p></td></tr><tr><td><code>filesystem</code></td><td>Filesystem name.<br>Required for <code>user</code> or <code>group</code> types.</td></tr><tr><td><code>snap-name</code></td><td>Name of the writable snapshot.<br>Only applies to <code>user</code> or <code>group</code> types.</td></tr></tbody></table>

## Reset quota

**Command**: `weka fs quota reset`

Use the following command to reset a quota:

`weka fs quota reset [path] [--type type] [--id id] [--generation generation] [--filesystem filesystem] [--snap-name snap-name]`

**Parameters**

<table><thead><tr><th width="178">Name</th><th>Value</th></tr></thead><tbody><tr><td><code>path</code>*</td><td>Path to the directory to unset the quota.<br>The relevant filesystem must be mounted when setting the quota.</td></tr><tr><td><code>type</code></td><td><p>Quota type.</p><p>Possible values: <code>directory</code>, <code>user</code>, or <code>group</code></p></td></tr><tr><td><code>id</code></td><td>The UID or GID the quota applies to. Required when <strong><code>type</code></strong> is <code>user</code> or <code>group</code>.</td></tr><tr><td><code>generation</code></td><td>The generation of the directory quota to remove. Applies to directory quotas only. If omitted, the current generation is used.</td></tr><tr><td><code>filesystem</code></td><td>Filesystem name.<br>Required for <code>user</code> or <code>group</code> types.</td></tr><tr><td><code>snap-name</code></td><td>Name of the writable snapshot to remove if exists.<br>Only applies to <code>user</code> or <code>group</code> types.</td></tr></tbody></table>


# Data catalog

Manage, index, and query filesystem metadata using the data catalog. This feature provides macro-level insights and granular data discovery, enabling visibility into large filesystems at scale.

## Data catalog overview

The data catalog offers advanced indexing and querying capabilities for filesystem data through a user-friendly graphical dashboard and REST APIs. It provides an indexed perspective on the filesystem, enabling macro-level insights into storage capacity usage and facilitating detailed data exploration.

The data catalog uses a distributed query engine for metadata storage. The engine is embedded directly into catalog services, runs in Data Service containers, and stores filesystem metadata in a dedicated index filesystem.

IT administrators leverage the data catalog to manage, monitor, and query large filesystems metadata at scale without depending on external systems.

### Key benefits

* **Native integration:** Eliminates the need for additional tools to monitor capacity.
* **Visibility at scale:** Use the sunburst chart on the Data Insights dashboard to pinpoint directories contributing most to storage usage, by size or file count. This tool effectively visualizes the hierarchy and capacity across the filesystem, illustrating filesystem trends clearly.
* **Actionable analytics:** Enables the export of panel statistics and chart data as CSV files for reporting purposes.
* **Enhanced discoverability:**

  With a user-friendly SQL query builder and ready-to-use templates, execute queries straight from the UI. Common tasks include:

  * **Growth analysis:** Identify directories growing by more than 50GB in the past 24 hours.
  * **Capacity forecasting:** Determine which filesystems will reach 90% capacity within the next 14 days.
  * **Cold data identification:** Find all files and directories untouched by any user in the last 90 days.
  * **Export query results:** Download results in JSON format for sharing and analyzing data with other tools.
* **Data forecast:** The data ingestion in the file system, alongside data patterns from the catalog, provides projections for future growth. It offers a visual graphical representation of forecasted numbers.
* **Comparative analysis:** Compare data between two points in time using Comparison Insights. Review a delta summary of added, modified, and deleted files and directories, then identify which directories drove the change.

## Identify storage trends with the Filesystem Analytics dashboard

Monitor storage trends and capacity distribution using the Filesystem Analytics dashboard. This tool, powered by the Data Catalog, provides high-level visualization and granular discovery of filesystem metadata to eliminate the need for external capacity monitoring systems.

#### Dashboard components and behavior

The dashboard features several specialized panels to present filesystem metadata:

* **Sunburst chart:** The centerpiece of the dashboard designed for top-level view of directory hierarchy and capacity consumption.
* **File count by extension:** Shows how files are distributed by extension across the filesystem. Select a bar, then select **Deep Dive** to explore the underlying files.
* **Usage statistics by user or group:** Charts that identify storage consumption attributed to specific accounts or organizational units.
* **Historical trends and forecasting:** The Filesystem Capacity Over Time chart shows historical growth and provides predictable usage based on current patterns if at least 24 hours of data is available.
* **Comparison Insights:** Compares a filesystem between two points in time, summarizing added, modified, and deleted files and directories and ranking directories by storage impact.

#### Sunburst chart characteristics

The chart provides top-level snapshots of the filesystem. It includes the following features:

* **Interactive tooltips:** Hover over a segment to view the directory path, size, and percentage of total capacity.
* **Inner circle distinctions:** Differentiates directory levels at a glance with clear visual boundaries.
* **Other directories (...):** A non-interactive segment represented by an ellipsis **(...)**, grouping smaller directories to enhance UI clarity. Hovering over this section reveals a tooltip summarizing the cumulative folder info: total size, percentage, and capacity of this segment.

<div data-with-frame="true"><figure><img src="/files/NgbePR02JQ3z1bWFQWNW" alt=""><figcaption><p>Sunburst chart example</p></figcaption></figure></div>

### Use case: Optimizing filesystem capacity

Effectively manage storage resources by identifying the root causes of unexpected capacity usage and relocating inactive data.

**Address unexpected capacity challenges**

When filesystem usage unexpectedly approaches 90%, a systematic investigation is essential. Traditional tools like `du -sh` or `du -sb` can take hours to complete on filesystems with billions of files. A data catalog backed by a high-performance indexing database dramatically reduces discovery time, providing immediate insights and intuitive data visualization.

Use the Sunburst view to drill into storage hierarchies and quickly pinpoint the directories or users driving significant disk space consumption.

**Identify and migrate stale data**

Predefined templates in the data catalog allow you to categorize files by access patterns (for example, files inactive for 90 or more days), enabling targeted, cost-saving action:

* **Identify inactive files:** Surface data that is no longer needed by active workloads.
* **Migrate to cost-effective storage:** Move stale data to S3 or low-cost HDD clusters.
* **Optimize premium resources:** Reserve SSD-based cluster capacity for high-priority, frequently accessed data.

{% embed url="<https://youtu.be/6E49xsY0uOw>" fullWidth="true" %}
Demo: WEKA Data Catalog
{% endembed %}


# Configure data catalog

Deploy and configure data catalog to enable high-performance data indexing and metadata management across filesystems.

## Data catalog architecture

Gain insights into how data catalog components collaboratively function to index and query filesystem metadata at scale. By deploying dedicated catalog services, the system concurrently scans modified files and stores searchable metadata in a centralized index database.

#### Catalog components

The catalog feature integrates several components within the WEKA cluster to manage and query metadata:

* **Data service containers:** The compute units that power catalog services. The catalog requires a minimum of five data service containers: one serves as the coordinator and the others function as workers.
* **Difflist:** A service that runs on the data service containers to detect changes in the filesystems.
* **Data manager:** The component that manages rolling snapshots used by the difflist to track data changes.
* **Index database:** The central repository that receives indexed fields and stores results for metadata queries.
* **Index filesystem (.indexfs):** A dedicated filesystem that stores catalog index data.
* **Query API and GUI:** Interfaces used to access and visualize the indexed metadata.

**Related topics**

[Set up a Data Services container for background tasks](/operation-guide/background-tasks/set-up-a-data-services-container-for-background-tasks)

[Snapshots](/weka-filesystems-and-object-stores/snapshots#track-filesystem-changes-with-the-difflist-rest-api)

#### Catalog workflow

The data catalog maintains synchronization through a structured three-step process:

1. **Snapshot management:** The Data manager creates rolling snapshots of the filesystems to provide a reference point for the Difflist.
2. **Parallel scanning:** The system identifies changed files and scans them in parallel across the data service containers to maintain high performance.
3. **Indexing and storage:** The service indexes common metadata fields and sends the results to the Index database. This data is stored on the **index filesystem** for long-term retention and querying.

<div data-with-frame="true"><figure><img src="/files/wtTEdsXvbp9QFquLkddc" alt=""><figcaption><p>Catalog architecture</p></figcaption></figure></div>

## Deploy the catalog services

Configure the infrastructure and filesystems required to activate catalog services for your data.

#### Before you begin

* The catalog services require at least five backend servers. Ensure each server has 32 GB for the data catalog service plus 5.5 GB for the data services, and connectivity on port 14400.
* Each server that runs catalog services must also run a frontend container. The catalog feature requires a frontend container and a data service container on the same server.
* For optimal operation, ensure a minimum of 500 GB of available storage for the index filesystem (`.indexfs`). See [#sizing-guidelines](#sizing-guidelines "mention").

#### Procedure

1. **Create the configuration filesystem:** New clusters do not create `.config_fs` by default. Create it if it does not already exist. Existing clusters already include this filesystem.

```bash
weka fs add .config_fs default 50GB
```

{% hint style="info" %}
For details about the .config\_fs sizing, see the [Dedicated filesystem requirement for cluster-wide persistent protocol configurations](/additional-protocols/additional-protocols-overview#dedicated-filesystem-requirement-for-cluster-wide-persistent-protocol-configurations).
{% endhint %}

2. **Create the index filesystem:** Add the `.indexfs`.

<pre class="language-bash"><code class="lang-bash"><strong>weka fs add .indexfs default 500GB
</strong></code></pre>

3. **Deploy data service containers:**

Run the following command on each server, whether dedicated backend servers or existing backend servers:

```bash
sudo weka local setup container \
  --name dataservN \
  --base-port 14400 \
  --join-ips <CLUSTER_LEADER_IP> \
  --only-dataserv-cores \
  --allow-mix-setting
```

You can use the same name on all servers or increment it across servers (for example, `dataserv0`, `dataserv1`, and so on).<br>

**Dedicated backend servers only:** To avoid impact on client workload I/Os, also run the following command on each dedicated backend server to add a frontend container (existing backend servers already contain frontend containers):

{% code overflow="wrap" %}

```bash
sudo weka local setup container \
   --name frontend0 \
   --cores 1 \
   --frontend-dedicated-cores 1 \
   --join-ips <CLUSTER_LEADER_IP> \
   --net <INTERFACE>
```

{% endcode %}

4. Set **global configuration of data service** container by running the following command on any of the cluster servers.

{% code overflow="wrap" %}

```bash
weka dataservice global-config set --config-fs .config_fs
```

{% endcode %}

5. **Initialize the catalog services:**
6. Add the newly created `dataserv` container IDs to the catalog cluster. You can specify the container IDs or provide the `--all-servers` flag.

   ```bash
   weka catalog cluster add .indexfs --containers <ID1>,<ID2>,<ID3>,<ID4>,<ID5>
   #or
   weka catalog cluster add .indexfs --all-servers
   ```
7. Wait for 30 seconds and then check if the catalog services are active:

   ```bash
   weka catalog cluster status
   ```

   Output example:

   ```bash
   SERVICE NAME         CONTAINER ID  HOSTNAME  CONTAINER  IP             STATUS  ROLE
   catalog-coordinator  23            sphere-3  dataserv0  10.121.43.123  active  COORDINATOR
   catalog-worker-2     25            sphere-2  dataserv0  10.121.74.183  active  WORKER
   catalog-worker-4     22            sphere-4  dataserv0  10.121.101.84  active  WORKER
   catalog-worker-5     21            sphere-5  dataserv0  10.121.10.21   active  WORKER
   catalog-worker-6     24            sphere-6  dataserv0  10.121.97.143  active  WORKER
   ```
8. **Enable indexing:**
   1. Enable the catalog feature on your specified filesystem. Replace `fs-name` with the name of the filesystem you want to index.

      ```bash
      weka fs update <fs-name> --index-enabled true
      ```
   2. View the filesystem listing as seen from the catalog perspective:

      ```bash
      weka catalog fs status
      ```

      Output example:

      ```bash
      FILESYSTEM   INDEXING  HAS METADATA  SNAPSHOTS  LATEST SNAPSHOT         OLDEST SNAPSHOT         LAST INGEST  LAST ERROR
      catalogtest  Enabled   Yes           7          cat-ingest-3.2604061605  cat-ingest-3.2604061553 Never       -
      fs1          Enabled   Yes           6          cat-ingest-5.2604061605  cat-ingest-5.2604061555 Never       -
      ```
   3. Verify catalog configuration:

      ```bash
      weka catalog config show
      ```

      Output example:

      ```bash
      Indexing enabled: true
      Index filesystem: .indexfs (ID: FSId<4>)
      Coordinator: test-catalog (ID: HostId<23>)
      IP: 10.121.43.123
      Port: 14511
      Indexing interval: 1d 0:00:00h
      Retention period: 30d 0:00:00h
      Max ingest tasks: 1
      ```
9. **Configure index interval and snapshot retention period:** Adjust these settings to match your workload needs. They dictate how often data is indexed and the duration for which point-in-time snapshots are kept. By default, the `--index-interval` is set to 1 day, and the `--retention-period` is 30 days. Use the following command to update these configurations:

   ```shell
   weka catalog config update --index-interval <time> --retention-period <time>
   ```

   Supported time units:

   * `--index-interval`: Accepts values in minutes, hours, or days (for example: `30m`, `2h`, `1d5h` , `3d8h30m`, `7d`). Valid range: `30m`–`7d`.
   * `--retention-period`: Accepts values in minutes, hours, or days (for example: `30d, 45d, 90d, 180d or 366d`). Must be at least `--index-interval` and no more than `366d`.

{% hint style="info" %}
The duration of the initial Data Catalog snapshot creation is proportional to the total number of objects (files and directories) in the filesystem. For approximate baseline and differential snapshot creation times, refer to **Sizing for baseline indexing time** below. The Data Catalog UI remains unpopulated until the first snapshot has been successfully created.
{% endhint %}

### Troubleshoot catalog deployment issues

Resolve issues related to container deployment and catalog services operations by following these resolution steps.

#### Troubleshoot container deployment

<details>

<summary>Container with name already exists</summary>

**Resolution:**

1. If a container exists but is not functional, remove it manually by running `weka local stop <name>` and `weka local rm <name>`.
2. Re-run the script after removal.

</details>

<details>

<summary>Container not found after creation</summary>

**Resolution:** The system waits 30 seconds and retries after 15 seconds. If containers do not appear in `weka cluster container`, verify the following:

* Network connectivity to the cluster leader process.
* The accuracy of the `--join-ips` value.

</details>

#### Troubleshoot catalog cluster operations

<details>

<summary>Catalog cluster status shows inactive</summary>

**Resolution:**

1. Check the cluster state:

```bash
weka catalog cluster status
```

2. Verify that all data service containers are in the `UP` state:

```bash
weka cluster container
```

3. For any failed container, SSH to the server and restart it:

```bash
weka local stop <name>
weka local start <name>
```

</details>

<details>

<summary>Indexing does not progress</summary>

**Resolution:**

1. Verify indexing is enabled by checking the `Indexing` column in `weka catalog fs status`.
2. Check the index interval with `weka catalog config show`.
3. Ensure the catalog services have a sufficient number of servers configured and running with active status.

</details>

<details>

<summary>Catalog tasks are stuck or slow</summary>

**Resolution:**

1. Run `weka cluster task --show-catalog` to view the progress of each ingestion phase.
2. Identify the phase with the longest elapsed time and investigate resource availability on those specific containers.

</details>

### Catalog diagnostic command reference

To monitor and diagnose the health of the catalog cluster, use these CLI commands. Review the example outputs to understand the expected results for these diagnostic commands.

#### Display catalog cluster status

`weka catalog cluster status`

Check the overall health of the catalog services. Ensure each container displays a status of `active` during normal operation. Use this as the initial step when troubleshooting catalog-related issues.

<details>

<summary>Example</summary>

```bash
$ weka catalog cluster status
SERVICE NAME         CONTAINER ID  HOSTNAME  CONTAINER  IP             STATUS  ROLE
catalog-coordinator  23            sphere-3  dataserv0  10.121.43.123  active  COORDINATOR
catalog-worker-2     25            sphere-2  dataserv0  10.121.74.183  active  WORKER
catalog-worker-4     22            sphere-4  dataserv0  10.121.101.84  active  WORKER
catalog-worker-5     21            sphere-5  dataserv0  10.121.10.21   active  WORKER
catalog-worker-6     24            sphere-6  dataserv0  10.121.97.143  active  WORKER
```

</details>

#### List cluster containers

`weka cluster container`

This section details all containers within the cluster, including data service (`dataserv`) containers. It provides information on the status, host, and resource allocation for each container. This is useful for verifying that all `dataserv` containers are running and properly registered.

<details>

<summary>Example</summary>

{% code fullWidth="true" %}

```bash
$ weka cluster container
CONTAINER ID  HOSTNAME         CONTAINER  IPS             STATUS  REQUESTED ACTION  RELEASE                                      FAILURE DOMAIN  CORES  MEMORY   UPTIME     LAST FAILURE  REQUESTED ACTION FAILURE
0             sphere-0  drives0     10.121.113.136  UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-000         2      3.14 GB  4:29:43h  
1             sphere-1  drives0     10.121.40.40    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-001         2      3.14 GB  4:29:49h  
2             sphere-2  drives0     10.121.74.183   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-002         2      3.14 GB  4:29:48h  
3             sphere-3  drives0     10.121.43.123   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-003         2      3.14 GB  4:29:43h  
4             sphere-4  drives0     10.121.101.84   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-004         2      3.14 GB  4:29:50h  
5             sphere-5  drives0     10.121.10.21    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-005         2      3.14 GB  4:29:49h  
6             sphere-6  drives0     10.121.97.143   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-006         2      3.14 GB  4:29:42h  
7             sphere-6  compute0    10.121.97.143   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-006         3      6.81 GB  4:27:25h  
8             sphere-0  compute0    10.121.113.136  UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-000         3      6.81 GB  4:27:25h  
9             sphere-1  compute0    10.121.40.40    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-001         3      6.81 GB  4:27:26h  
10            sphere-5  compute0    10.121.10.21    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-005         3      6.81 GB  4:27:25h  
11            sphere-4  compute0    10.121.101.84   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-004         3      6.81 GB  4:27:24h  
12            sphere-2  compute0    10.121.74.183   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-002         3      6.81 GB  4:27:24h  
13            sphere-3  compute0    10.121.43.123   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-003         3      6.81 GB  4:27:24h  
14            sphere-5  frontend0   10.121.10.21    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-005         1      1.48 GB  4:27:14h  
15            sphere-4  frontend0   10.121.101.84   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-004         1      1.48 GB  4:27:13h  
16            sphere-1  frontend0   10.121.40.40    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-001         1      1.48 GB  4:27:15h  
17            sphere-3  frontend0   10.121.43.123   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-003         1      1.48 GB  4:27:13h  
18            sphere-0  frontend0   10.121.113.136  UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-000         1      1.48 GB  4:27:13h  
19            sphere-6  frontend0   10.121.97.143   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-006         1      1.48 GB  4:27:14h  
20            sphere-2  frontend0   10.121.74.183   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7  DOM-002         1      1.48 GB  4:27:13h  
21            sphere-5  dataserv0   10.121.10.21    UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0              1:58:39h  
22            sphere-4  dataserv0   10.121.101.84   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0              1:58:39h  
23            sphere-3  dataserv0   10.121.43.123   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0              1:58:39h  
24            sphere-6  dataserv0   10.121.97.143   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0              1:58:39h  
25            sphere-2  dataserv0   10.121.74.183   UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0              1:58:39h  
26            sphere-0  dataserv0   10.121.113.136  UP      NONE            5.1.2.787-17c29aa703f2bc560f787173130a15b7                     0
```

{% endcode %}

</details>

#### Show catalog configuration

`weka catalog config show`

Displays the catalog configuration settings, including the index filesystem status, snapshot scheduling frequency, retention period, and the maximum number of concurrent ingest tasks.

<details>

<summary>Example</summary>

```bash
$ weka catalog config show
Indexing enabled: true
Index filesystem: .indexfs (ID: FSId<4>)
Coordinator: test-catalog (ID: HostId<23>)
IP: 10.121.43.123
Port: 14511
Indexing interval: 0:30:00h
Retention period: 1d 0:00:00h
Max ingest tasks: 1
```

</details>

#### List filesystem snapshots

`weka catalog metadata show <fs-name>`

Lists all catalog point-in-time snapshots (not filesystem snapshots) for a specified filesystem. These snapshots are essential for the catalog's data ingestion strategy, as they help discover changes between point-in-time snapshot names. This understanding is crucial for the catalog indexing pipeline.

<details>

<summary>Example</summary>

```bash
$ weka catalog metadata show catalogtest
SEQ  SNAPSHOT                ACCESS POINT           SNAPSHOT TIME         REFERENCE             STARTED              COMPLETED            TASK ID       EVENTS ID          VIEW ID              FS META ID           METRICS ID
40   cat-ingest-3.2604061605 @GMT-2026.04.06-13.06.01 2026-04-06T13:06:02 cat-ingest-3.2604061603 2026-04-06T13:06:03 2026-04-06T13:06:12 CWTaskId<327> 25459437255425818 7342889946016094527 2236839568792752410 8008097189329068864
39   cat-ingest-3.2604061603 @GMT-2026.04.06-13.04.01 2026-04-06T13:04:02 cat-ingest-3.2604061601 2026-04-06T13:04:03 2026-04-06T13:04:12 CWTaskId<321> 25459437255425818 7342889946016094527 5380056034073099149 5760528872397688708
38   cat-ingest-3.2604061601 @GMT-2026.04.06-13.02.01 2026-04-06T13:02:02 cat-ingest-3.2604061559 2026-04-06T13:02:03 2026-04-06T13:02:12 CWTaskId<314> 25459437255425818 7342889946016094527 8978198626367922268 7109968065680670082
37   cat-ingest-3.2604061559 @GMT-2026.04.06-13.00.01 2026-04-06T13:00:02 cat-ingest-3.2604061557 2026-04-06T13:00:03 2026-04-06T13:00:11 CWTaskId<307> 25459437255425818 7342889946016094527 5670197150205091422 1674236124679297555
36   cat-ingest-3.2604061557 @GMT-2026.04.06-12.58.01 2026-04-06T12:58:02 cat-ingest-3.2604061555 2026-04-06T12:58:02 2026-04-06T12:58:11 CWTaskId<301> 25459437255425818 7342889946016094527 2326292917784777347 853921236900376655
35   cat-ingest-3.2604061555 @GMT-2026.04.06-12.56.01 2026-04-06T12:56:02 cat-ingest-3.2604061553 2026-04-06T12:56:02 2026-04-06T12:56:12 CWTaskId<294> 25459437255425818 7342889946016094527 3516686023505608780 520645449336946985
34   cat-ingest-3.2604061553 @GMT-2026.04.06-12.54.01 2026-04-06T12:54:03 cat-ingest-3.2604061551 2026-04-06T12:54:03 2026-04-06T12:54:13 CWTaskId<288> 25459437255425818 7342889946016094527 3385908729197653719 4551599420237089072
```

</details>

#### Monitor ingestion tasks

`weka cluster task --show-catalog`

Use this essential diagnostic command to monitor catalog ingestion progress. It displays the ongoing ingestion phases, elapsed time for each phase, and the percentage of completion. Use this data to pinpoint bottlenecks and track overall catalog data processing advancement effectively.

<details>

<summary>Example</summary>

```bash
$ weka cluster task --show-catalog
TASK ID  TYPE           STATE    PHASE                PROGRESS  USER PAUSED  DESCRIPTION                                                                                               TIME
340      FSCK           RUNNING  CHECK_REGISTRY 0/2   98.49     False        Checking metadata integrity                                                                              0:09:49h
341      RAID_SCANNER   RUNNING  RUN 0/1              96.78     False        Checking data integrity of the RAID BucketId<INVALID> PlacementIdx<0> PlacementIdx<12288>                 0:05:28h
343      CATALOG_INGEST RUNNING  UPDATE_VIEW 2/3      80        False        catalogtest/cat-ingest-3.2604061637 (ref: cat-ingest-3.2604061605): Computing recursive statistics (staging) depth 28, chunk 1...  0:04:26h
```

</details>

## Sizing guidelines

Use the following guidelines to determine the hardware resources required for the catalog deployment before enabling indexing. Resource requirements scale with the number of filesystem objects and the anticipated data growth rate.

#### Find the filesystem statistics

If you already have current filesystem statistics, skip this section and continue to [Sizing for the catalog deployment](#sizing-for-the-catalog-deployment).

Download the `filestats.sh` script and run it on your filesystem to measure its object count and directory-to-file ratio before sizing your hardware:

{% file src="/files/fzAgU1D0D1KFR9RYtNiD" %}

```bash
chmod +x filestats.sh
./filestats.sh /mnt/weka/<filesystem_name>
```

**Script example output**

Use the **Total Items** count from the script output to select the appropriate column in the sizing tables below. For example, 40 million objects falls under the 200+ million objects column.

{% code overflow="wrap" %}

```
Analyzing file system structure for: /home/
Please wait, scanning...
------------------------------------------------
### Raw Statistics
Total Directories:    2255000
Total Files:          38269000
Total Items:          40524000 ( ~40 million objects )
### Complexity Metrics
------------------------------------------------
1.A Average Breadth (Fan-out):  17.97
    (Formula: Items / Dirs)
    -> Interpretation: On average, each folder contains 17.97 items.
1.B Maximum Depth:              27 levels
    (Formula: Longest path segment count)
    -> Interpretation: The deepest nesting level relative to start.
1.C Dir-to-File Ratio:          0.0589
    (Formula: Dirs / Files)
    -> Interpretation: value > 0.5 implies deep/sparse nesting.
                       value near 0 implies flat/dense structure.
------------------------------------------------
### Generalized Classification
Structure Type: DEEP / SKYSCRAPER (High Depth)
```

{% endcode %}

### Sizing for the catalog deployment

The table below maps filesystem scale to the minimum recommended resources. These values are tested sizing guidance based on a typical dataset (files and directories).

Each specification assumes approximately 10% monthly data growth over a 12 to 18 month horizon and a directory-to-file ratio between 0.05 and 0.50.

* 0.05 means about 1 directory for every 20 files.
* 0.50 means about 1 directory for every 2 files.

Review and adjust catalog resource allocations every 6–9 months to account for filesystem growth. Run the `filestats.sh` script to get the current object count per filesystem, then use the sizing table to determine whether your existing resources still meet the requirements.

| Parameter                   | Up to 200+ million objects                   | Up to 500+ million objects                   | Up to 1+ billion objects                 |
| --------------------------- | -------------------------------------------- | -------------------------------------------- | ---------------------------------------- |
| **Data service containers** | 5 total: 4 workers + 1 coordinator           | 10 total: 9 workers + 1 coordinator          | 10 total: 9 workers + 1 coordinator      |
| **CPU**                     | 2 spare cores per server (minimum)           | 2 spare cores per server (minimum)           | 2 spare cores per server (minimum)       |
| **Memory**                  | 32 GB free per server                        | 32 GB free per server                        | 64 GB free per server                    |
| **Disk (index filesystem)** | 150 GB – 500 GB (30 days – 1 year retention) | 250 GB – 1.5 TB (30 days – 1 year retention) | 1 TB – 5 TB (30 days – 1 year retention) |

\
The following considerations apply to all deployment sizes:

* The catalog supports selective manual assignment of data service containers or automatic assignment of all backend servers. Coordinator and worker servers cannot be assigned manually.
* Deploy one data service container per server.
* Disk sizing for the index filesystem depends on the snapshot retention period configured with `--retention-period`.

### Sizing for baseline indexing time

The table below provides estimated durations for the initial full ingest and ongoing incremental (delta) indexing.

* Baseline ingest time depends on the directory-to-file ratio: a lower ratio means fewer directory scans and faster ingestion.
* Delta estimates assume 1% change per day.

| Operation                                                          | 200+ million objects | 500+ million objects | 1+ billion objects |
| ------------------------------------------------------------------ | -------------------- | -------------------- | ------------------ |
| <p><strong>Baseline</strong><br><strong>(full ingest)</strong></p> | 8–22 hours           | 24–40 hours          | 48–60 hours        |
| **Delta (incremental changes)**                                    | 40–50 minutes        | 1–2 hours            | 3–5 hours          |

To monitor ingest progress in real time, run:

```bash
weka cluster task --show-catalog
```

## Catalog REST API examples

The following examples show request and response payloads for each catalog REST API endpoint.

{% hint style="info" %}
For the catalog REST API reference, see [Catalog](/getting-started-with-weka/weka-rest-api-and-equivalent-cli-commands#catalog).
{% endhint %}

### Run a catalog query

Query the catalog index to retrieve files and directories that match the specified conditions. This is the API equivalent of the Catalog Discovery feature. Use the `criteria` field to filter results with nested `AND` and `OR` conditions.

Results are paginated. When the response includes a `next_cookie` value, pass it as `resume_cookie` in the next request to retrieve the following page. Repeat until `next_cookie` is empty, which indicates the last page.

`POST /catalog/query`

The following fields are available in `select_fields`:

`inode`, `filepath`, `filename`, `size`, `file_type`, `uid`, `gid`, `file_extension`, `mode`, `birth_time`, `access_time`, `modify_time`, `change_time`

#### Basic example with pagination

This example searches for all files named `test.log` across the filesystem, returning 100 results per page.

<details>

<summary>Request example</summary>

```json
{
  "fs_uuid": "1f66f596-d0fb-7adf-06de-e8e2332f98d0",
  "point_in_time": "@GMT-2026.02.03-14.43.18",
  "select_fields": ["inode", "filepath", "filename"],
  "page_size": 100,
  "criteria": {
    "operator": "AND",
    "conditions": [
      { "field": "filename", "operation": "LIKE", "value": "test.log" }
    ]
  },
  "resume_cookie": ""
}
```

</details>

<details>

<summary>Response example. Page 1</summary>

```json
{
  "success": true,
  "data": [
    { "inode": "649301521884840177", "filepath": "/var/log", "filename": "test.log" },
    { "inode": "2081169670824263921", "filepath": "/data/logs", "filename": "test.log" },
    { "inode": "2594795838286135537", "filepath": "/data/tmp", "filename": "test.log" }
  ],
  "page_size": 100,
  "next_cookie": "eyJzb3J0RmllbGQiOiJmaWxlbmFtZSJ9..."
}
```

</details>

To retrieve the next page, resubmit the same request body with `resume_cookie` set to the value of `next_cookie` from the previous response:

<details>

<summary>Request example. Next page</summary>

```json
{
  "fs_uuid": "1f66f596-d0fb-7adf-06de-e8e2332f98d0",
  "point_in_time": "@GMT-2026.02.03-14.43.18",
  "select_fields": ["inode", "filepath", "filename"],
  "page_size": 100,
  "criteria": {
    "operator": "AND",
    "conditions": [
      { "field": "filename", "operation": "LIKE", "value": "test.log" }
    ]
  },
  "resume_cookie": "eyJzb3J0RmllbGQiOiJmaWxlbmFtZSJ9..."
}
```

</details>

When `next_cookie` is empty in the response, all pages have been retrieved.

#### Complex example 1: AND query with multiple field filters

This example filters for regular files named `test.log` under `/data/logs` that are larger than 1024 bytes, sorted by filename ascending.

<details>

<summary>Request example</summary>

```json
{
  "fs_uuid": "1f66f596-d0fb-7adf-06de-e8e2332f98d0",
  "point_in_time": "@GMT-2026.02.03-14.43.18",
  "select_fields": ["inode", "filepath", "filename", "size", "uid", "gid"],
  "page_size": 100,
  "sort": { "field": "filename", "order": "ASC" },
  "criteria": {
    "operator": "AND",
    "conditions": [
      { "field": "filepath", "operation": "LIKE", "value": "/data/logs" },
      { "field": "filename", "operation": "LIKE", "value": "test.log" },
      { "field": "size", "operation": "GREATER_THAN", "value": 1024 },
      { "field": "file_type", "operation": "IN", "value": "regular file" }
    ]
  },
  "resume_cookie": ""
}
```

</details>

#### Complex example 2: OR query across multiple paths

This example retrieves files from two directories, `/data/logs` and `/data/tmp`, in a single query using an `OR` operator.

<details>

<summary>Request example</summary>

```json
{
  "fs_uuid": "1f66f596-d0fb-7adf-06de-e8e2332f98d0",
  "point_in_time": "@GMT-2026.02.03-14.43.18",
  "select_fields": ["inode", "filepath", "filename", "size"],
  "page_size": 100,
  "criteria": {
    "operator": "OR",
    "conditions": [
      { "field": "filepath", "operation": "LIKE", "value": "/data/logs" },
      { "field": "filepath", "operation": "LIKE", "value": "/data/tmp" }
    ]
  },
  "resume_cookie": ""
}
```

</details>

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "inode": "2081169670824263921", "filepath": "/data/logs", "filename": "test.log", "size": 1024 },
    { "inode": "2594795838286135537", "filepath": "/data/tmp", "filename": "test.log", "size": 4096 },
    { "inode": "3149782970401030385", "filepath": "/data/logs", "filename": "test_5.log", "size": 1024 }
  ],
  "page_size": 100,
  "next_cookie": ""
}
```

</details>

### Get changes between two point-in-time snapshots

Return the files and directories added, deleted, or modified between two point-in-time snapshots. This is the API equivalent of Comparison Insights.

`POST /catalog/query/diff`

<details>

<summary>Request example</summary>

```json
{
  "fs_uuid": "326933be-23fe-b497-a50f-58774d6cbe4b",
  "old_point_in_time": "@GMT-2025.01.01-00.00.00",
  "new_point_in_time": "@GMT-2025.02.01-00.00.00",
  "select_fields": ["size", "modify_time"],
  "change_types": ["FILE_CREATE", "FILE_MODIFY"],
  "filepath": "/data/",
  "show_changed_fields": false,
  "page_size": 1000
}
```

</details>

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "old_snapshot": "@GMT-2025.01.01-00.00.00",
  "new_snapshot": "@GMT-2025.02.01-00.00.00",
  "data": [
    { "inode": "12345", "change_type": "FILE_CREATE", "parent_inode": "100", "filepath": "/data/new", "filename": "file.txt", "size": 1024, "modify_time": "2025-02-01T10:00:00Z" },
    {
      "inode": "67890", "change_type": "FILE_MODIFY", "parent_inode": "100", "filepath": "/data/existing", "filename": "doc.txt", "size": 2048, "modify_time": "2025-02-01T12:00:00Z",
      "changed_fields": {
        "size": { "old": 1024, "new": 2048 },
        "modify_time": { "old": "2025-01-15T10:00:00Z", "new": "2025-02-01T12:00:00Z" }
      }
    }
  ],
  "summary": { "file_create": 150, "file_delete": 10, "file_modify": 25, "dir_create": 5, "dir_delete": 2, "dir_modify": 3, "symlink_create": 0, "symlink_delete": 0, "symlink_modify": 0 },
  "next_cookie": "eyJsYXN0SW5vZGUiOiIxMjM0NTY3ODkwIn0"
}
```

</details>

### Get data usage by user ID

Query filesystem usage statistics grouped by user, returning file count and total size per User ID (UID).

`GET /catalog/stats/usageByUser`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "uid": 1000, "username": "john.doe", "file_count": 15234, "total_size": 52428800000 },
    { "uid": 1001, "username": "jane.smith", "file_count": 8456, "total_size": 21474836480 },
    { "uid": 0, "username": "root", "file_count": 342, "total_size": 1073741824 }
  ]
}
```

</details>

### Get data usage by group ID

Query filesystem usage statistics grouped by group name, returning file count and total size per Group ID (GID).

`GET /catalog/stats/usageByGroup`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "gid": 100, "groupname": "engineering", "file_count": 45678, "total_size": 107374182400 },
    { "gid": 101, "groupname": "research", "file_count": 23456, "total_size": 53687091200 },
    { "gid": 0, "groupname": "root", "file_count": 1024, "total_size": 5368709120 }
  ]
}
```

</details>

### Get list of snapshot metadata available for a filesystem

List the catalog snapshots available for a filesystem, including the start and end timestamps of each data ingestion cycle into the index filesystem.

`GET /catalog/snapshots/{fs_uuid}`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "filesystem_uuid": "326933be-23fe-b497-a50f-58774d6cbe4b",
  "filesystem_name": "default",
  "latest_snapshot": { "access_point": "@GMT-2025.10.20-12.00.00", "snapshot_id": "snap-001234", "snapshot_name": "daily-backup-2025-10-20", "sequence_number": 1542 },
  "snapshots": [
    { "access_point": "@GMT-2025.10.20-12.00.00", "snapshot_name": "daily-backup-2025-10-20", "snapshot_id": "snap-001234", "sequence_number": 1542, "completion_timestamp": "2025-10-20T12:05:23Z" },
    { "access_point": "@GMT-2025.10.19-12.00.00", "snapshot_name": "daily-backup-2025-10-19", "snapshot_id": "snap-001233", "sequence_number": 1541, "completion_timestamp": "2025-10-19T12:04:56Z" },
    { "access_point": "@GMT-2025.10.18-12.00.00", "snapshot_name": "daily-backup-2025-10-18", "snapshot_id": "snap-001232", "sequence_number": 1540, "completion_timestamp": "2025-10-18T12:05:01Z" }
  ],
  "total_count": 3
}
```

</details>

### Get file distribution by extension types

Query file count and total size grouped by file extension types across the filesystem.

`GET /catalog/stats/distributionByExtension`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "extension": "pdf", "file_count": 12500, "total_size": 26843545600 },
    { "extension": "jpg", "file_count": 45000, "total_size": 13421772800 },
    { "extension": "log", "file_count": 8900, "total_size": 5368709120 },
    { "extension": "", "file_count": 2300, "total_size": 1073741824 }
  ]
}
```

</details>

### Get data by file size ranges

Query file distribution grouped by size ranges, from 0–1 KB up to 10 TB and above.

`GET /catalog/stats/filesBySize`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "size_bucket": "0-1KB", "file_count": 125000, "total_size_bytes": 64000000, "total_size_formatted": "61.04 MB" },
    { "size_bucket": "1KB-10KB", "file_count": 450000, "total_size_bytes": 2250000000, "total_size_formatted": "2.10 GB" },
    { "size_bucket": "10KB-100KB", "file_count": 320000, "total_size_bytes": 16000000000, "total_size_formatted": "14.90 GB" },
    { "size_bucket": "100KB-1MB", "file_count": 180000, "total_size_bytes": 90000000000, "total_size_formatted": "83.82 GB" },
    { "size_bucket": "1MB-10MB", "file_count": 95000, "total_size_bytes": 475000000000, "total_size_formatted": "442.38 GB" },
    { "size_bucket": "10MB-100MB", "file_count": 45000, "total_size_bytes": 2250000000000, "total_size_formatted": "2.05 TB" },
    { "size_bucket": "100MB-1GB", "file_count": 12000, "total_size_bytes": 6000000000000, "total_size_formatted": "5.46 TB" },
    { "size_bucket": "1GB-10GB", "file_count": 2500, "total_size_bytes": 12500000000000, "total_size_formatted": "11.37 TB" },
    { "size_bucket": "10GB-100GB", "file_count": 150, "total_size_bytes": 7500000000000, "total_size_formatted": "6.82 TB" },
    { "size_bucket": "100GB-1TB", "file_count": 5, "total_size_bytes": 2500000000000, "total_size_formatted": "2.27 TB" },
    { "size_bucket": "1TB-10TB", "file_count": 0, "total_size_bytes": 0, "total_size_formatted": "0 B" },
    { "size_bucket": "10TB+", "file_count": 0, "total_size_bytes": 0, "total_size_formatted": "0 B" }
  ]
}
```

</details>

### Get capacity by file age

Query total file capacity grouped by file age based on modification time, from under one week to five years and older.

`GET /catalog/stats/capacityByFileAge`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "age_bucket": "< 1 week", "file_count": 85000, "total_size_bytes": 425000000000, "total_size_formatted": "395.81 GB" },
    { "age_bucket": "1 week - 1 month", "file_count": 120000, "total_size_bytes": 600000000000, "total_size_formatted": "558.79 GB" },
    { "age_bucket": "1-3 months", "file_count": 180000, "total_size_bytes": 900000000000, "total_size_formatted": "838.19 GB" },
    { "age_bucket": "3-6 months", "file_count": 250000, "total_size_bytes": 1250000000000, "total_size_formatted": "1.14 TB" },
    { "age_bucket": "6-12 months", "file_count": 320000, "total_size_bytes": 1600000000000, "total_size_formatted": "1.46 TB" },
    { "age_bucket": "1-2 years", "file_count": 180000, "total_size_bytes": 900000000000, "total_size_formatted": "838.19 GB" },
    { "age_bucket": "2-5 years", "file_count": 95000, "total_size_bytes": 475000000000, "total_size_formatted": "442.38 GB" },
    { "age_bucket": "5+ years", "file_count": 20000, "total_size_bytes": 100000000000, "total_size_formatted": "93.13 GB" }
  ]
}
```

</details>

### Get dashboard statistics

Get a top-level summary of filesystem statistics, including total file count, directory count, capacity, and the top users ranked by file count and total size.

`GET /catalog/stats/dashboard`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "quick_stats": { "total_files": 1250000, "total_directories": 85000, "total_size": 5368709120000 },
  "top_users": [
    { "uid": 1000, "username": "john.doe", "file_count": 150000, "total_size": 536870912000 },
    { "uid": 1001, "username": "jane.smith", "file_count": 120000, "total_size": 429496729600 }
  ],
  "top_extensions": [
    { "extension": "parquet", "file_count": 45000, "total_size": 1073741824000 },
    { "extension": "csv", "file_count": 89000, "total_size": 214748364800 }
  ]
}
```

</details>

### Get hierarchical directory tree with size statistics

Retrieve a directory tree up to a specified depth, showing direct and recursive size aggregations for each node. All sizes are returned in bytes.

`GET /catalog/stats/directoryTree`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "path": "/",
  "levels": 2,
  "tree": {
    "path": "/", "depth": 0, "direct_size": 1048576, "direct_file_count": 5,
    "recursive_size": 1099511627776, "recursive_file_count": 1250000, "subdirectory_count": 4,
    "subdirs": {
      "data": {
        "path": "/data", "depth": 1, "direct_size": 0, "direct_file_count": 0,
        "recursive_size": 824633720832, "recursive_file_count": 950000, "subdirectory_count": 3,
        "subdirs": {
          "projects": { "path": "/data/projects", "depth": 2, "direct_size": 52428800, "direct_file_count": 10, "recursive_size": 549755813888, "recursive_file_count": 650000, "subdirectory_count": 25 }
        }
      },
      "logs": { "path": "/logs", "depth": 1, "direct_size": 0, "direct_file_count": 0, "recursive_size": 214748364800, "recursive_file_count": 250000, "subdirectory_count": 12 }
    }
  }
}
```

</details>

### Get filesystem capacity metadata history

Query filesystem capacity metadata showing SSD and total capacity trends across multiple snapshots over time.

`GET /catalog/filesystem/metadata`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "used_ssd_capacity": 524288000000, "used_total_capacity": 1099511627776, "ssd_capacity": 1099511627776, "total_capacity": 10995116277760, "access_point": "@GMT-2025.10.20-12.00.00", "timestamp": "2025-10-20T12:00:00Z" },
    { "used_ssd_capacity": 520093696000, "used_total_capacity": 1090921693184, "ssd_capacity": 1099511627776, "total_capacity": 10995116277760, "access_point": "@GMT-2025.10.19-12.00.00", "timestamp": "2025-10-19T12:00:00Z" },
    { "used_ssd_capacity": 515899392000, "used_total_capacity": 1082331758592, "ssd_capacity": 1099511627776, "total_capacity": 10995116277760, "access_point": "@GMT-2025.10.18-12.00.00", "timestamp": "2025-10-18T12:00:00Z" }
  ]
}
```

</details>

### Get point-in-time filesystem capacity metadata

Query filesystem capacity metadata for a specific snapshot access point. If `access_point` is provided, the response returns metadata for that snapshot. If `access_point` is omitted, the response returns the most recent metadata.

`GET /catalog/filesystem/metadata/point-in-time`

<details>

<summary>Response example</summary>

```json
{
  "success": true,
  "data": [
    { "used_ssd_capacity": 524288000000, "used_total_capacity": 1099511627776, "ssd_capacity": 1099511627776, "total_capacity": 10995116277760, "access_point": "@GMT-2025.10.16-06.48.29" }
  ]
}
```

</details>

Use the returned capacity values to compare current usage with the configured filesystem capacity. Specify an `access_point` to retrieve values from a retained catalog snapshot.


# Analyze storage distribution

Analyze storage distribution with the data catalog. Explore directory hierarchies, visualize file statistics, and perform granular metadata discovery.

Explore filesystem metadata to identify usage patterns and discover specific data sets through the Filesystem Analytics dashboard. Powered by the data catalog, these tools provide macro-level insights and granular discovery to eliminate reliance on external capacity monitoring systems.

* **Analyze capacity usage:** Explore the directory hierarchy and identify storage consumption.
* **Visualize file distribution:** Review file statistics by extension, user, or group.
* **Monitor storage distribution and trends:** Observe how files are distributed by size and age, and track capacity growth.
* **Search files with discovery queries:** Build custom queries to locate files based on metadata attributes.
* **Use discovery templates:** Apply pre-defined query patterns for common analysis tasks.
* **Export catalog data:** Save capacity reports and query results as CSV or JSON files.
* **Compare storage activity:** Compare added, modified, and deleted files and directories between two points in time using the Comparison Insights tab.

## Analyze capacity usage

Explore the distribution of storage across different directory levels to identify large data sets and review high-level filesystem metrics.

<div data-with-frame="true"><figure><img src="/files/NgbePR02JQ3z1bWFQWNW" alt=""><figcaption><p>Capacity usage: Sunburst and File Statistics charts</p></figcaption></figure></div>

**Before you begin**

Verify that the target filesystem is indexed by the data catalog.

**Procedure**

1. Select **Investigate > Filesystem Analytics**.
2. Select the **Capacity Usage** tab.
3. Select the target filesystem from the **Filesystem** dropdown menu.
4. Select a specific point in time from the **Data Collection** dropdown menu.
5. To display the chart from a custom file path, click the pencil icon and enter the desired path.\
   All chart information will relate to this file path.
6. Review the high-level metrics:
   * **Filesystem Capacity:** Displays used and total provisioned space. Hover over the info icon to view the actual block-level occupancy.
   * **File and Directory counts:** Displays the total number of files and directories indexed in the filesystem.
7. Interact with the sunburst chart to navigate the directory hierarchy:
   * Select a sector to zoom into a specific directory.
   * Hover over a sector to view the directory path, total size, and percentage of the total filesystem capacity. Dark purple sectors represent directories, while light purple sectors represent individual files or groups of smaller items.
   * Select the center of the chart to move up one directory level.
8. Use the **File Statistics** chart to view data distribution.
   1. Select an option from the dropdown menu:
      * File Count by Extension
      * Usage Statistics by Group
      * Usage Statistics by User
   2. Select **Deep Dive** on a bar to explore the individual files within that segment. This leaves the **Capacity Usage** report and opens **Discovery** with relevant query parameters populated. Select **Run Query** to view the results.

## Monitor storage distribution and trends

Observe how files are distributed by size and age, and track capacity growth over time to forecast future storage needs.

<div data-with-frame="true"><figure><img src="/files/APo0qgHZXs15RHt7wsCp" alt=""><figcaption><p>File Size Distribution and Capacity by File Age charts</p></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="/files/1W7acewljSmc7KAgO5Ze" alt=""><figcaption><p>Filesystem Capacity Over Time and Forecast chart</p></figcaption></figure></div>

**Before you begin**

Access the **Capacity Usage** tab and scroll to the **Filesystem Analytics** section.

Scroll down to view additional distribution metrics.

**Procedure**

1. Review the **File Size Distribution** chart:
   * Identify the number of files within specific size ranges (for example: 1MB-10MB).
   * Hover over a bar to view the exact File Count for that range.
2. Review the **Capacity by File Age** chart:
   * Identify the volume of data based on the time elapsed since the last modification (for example: < 1 week or 5+ years).
   * Hover over a bar to view the Total Size of the files in that age category.
3. Analyze the **Filesystem Capacity Over Time** chart:
   * Observe historical trends for Total Capacity and Used Capacity.
   * Toggle the **Forecast** switch to ON to view projected storage needs. The chart displays Total Forecast and Used Forecast lines based on current data patterns. This requires at least 24 hours of historical snapshot data.
4. Select the **Download** icon in the top right corner of any chart to export the specific chart data as a CSV file.

## Search files with discovery queries

Filter and locate specific files by defining complex metadata conditions such as file size, access time, or owner.

<div data-with-frame="true"><figure><img src="/files/H9losfh6Xz0rsycTF2WX" alt=""><figcaption><p>Discovery query</p></figcaption></figure></div>

**Before you begin**

Access the **Discovery** tab within the **Filesystem Analytics** view.

**Procedure**

1. Select the **Filesystem** and **Data Collection** date.
2. In the **Show** section, select the columns to display in the results table, for example: File Name, Size, and Created At.
3. In the **Conditions** section, define the search criteria:
   * Select a metadata field (for example: File Size, Access Time, or UID).
   * Select an operator (for example: In, Between, >, or Regular File).
   * Enter or select the value for the condition.
4. Select the **+** icon to add more conditions. Use the Operator dropdown to select AND or OR logic between conditions.
5. In the **Sort** section, select a field and the sort order (ASC or DESC).
6. Set the number of **Rows per Page** to display.
7. Select **Run Query**.

## Compare storage insights

Compare a filesystem between two points in time to identify what changed and which directories drove the change.

<div data-with-frame="true"><figure><img src="/files/8LsuAgZYS5K2gh54Glc7" alt=""><figcaption><p>Compare storage insights</p></figcaption></figure></div>

**Before you begin**

Verify that the target filesystem is indexed by the data catalog and has at least two point-in-time snapshots available.

**Procedure**

1. Select **Investigate > Filesystem Analytics**.
2. Select the **Comparison Insights** tab.
3. Select the target filesystem from the **Filesystem** dropdown menu.
4. Select the **Baseline** and **Compare to** points in time. The elapsed time between the two points appears next to the selectors.
5. Select **Compare** to run the comparison.
6. Review the summary cards. Each card shows the number of affected files and directories, plus the associated capacity:
   * **Added:** New files and directories, with the total size of new data.
   * **Modified:** Changed files and directories, with the net size change.
   * **Deleted:** Removed files and directories, with the capacity freed.
   * **Net Storage Delta:** The overall capacity change and the total number of entries changed.
7. Review the **Storage Impact by Directory** chart to identify which directories contributed most to the change. Each bar is color-coded by change type (added, modified, or deleted) and shows the net capacity delta and number of changed entries.
8. Select a directory row to view its detailed breakdown, including added, modified, and deleted capacity, net delta, total entries changed, and the number of files and directories in that path.
   * Use the copy icon next to a directory path. Paste the path into **Discovery** to analyze its directory structure without retyping it.
9. Use the download icon to export the comparison results as a CSV file.

## Apply discovery query templates

Use pre-configured templates to quickly identify common file categories like cold data or recently modified files.

<div data-with-frame="true"><figure><img src="/files/7K11VjK3ZaWNPrCxrqBn" alt=""><figcaption><p>Discovery query templates</p></figcaption></figure></div>

**Before you begin**

Access the **Discovery** tab within the **Filesystem Analytics** view.

**Procedure**

1. Select **Templates** in the **Build a New Query** section.
2. Select a template from the list, for example: Files Not Accessed in Last 90 Days (Cold Data).
3. Review the auto-populated conditions.
4. Modify the values if required, for example: change the date range or the file size threshold.
5. Select **Run Query**.

**Query results handling**

The query results table supports full filesystems exploration through pagination. Navigate across pages to review the complete result set.

The GUI exports up to 10,000 records per query. To retrieve more records, use the REST API. See [WEKA REST API and equivalent CLI commands](/getting-started-with-weka/weka-rest-api-and-equivalent-cli-commands#catalog).

## Export catalog data

Save the results of a capacity analysis or a discovery query for external reporting or further processing.

<div data-with-frame="true"><figure><img src="/files/qkyn3XSdRKm0C87OySYk" alt=""><figcaption></figcaption></figure></div>

**Before you begin**

Generate a visualization in the **Capacity Usage** tab or run a query in the **Discovery** tab.

**To export capacity data:**

1. Navigate to the **Capacity Usage** tab.
2. Select the **Download CSV** icon located above the sunburst or distribution charts.

The exported CSV reflects the current visualization scope. It includes the top-level directory statistics displayed in the chart. The “**...**” entry represents an aggregated summary of additional directories outside the top view.

**To export discovery results:**

1. Navigate to the **Discovery** tab.
2. Select **Export** above the results table.
3. Select the preferred format and scope:
   * **CSV (current page results)**
   * **JSON (current page results)**
   * **CSV (all results)**
   * **JSON (all results)**

Retrieve the file from the default downloads folder of the browser.




---

[Next Page](/llms-full.txt/1)

