AWS Security ChangesHomeSearch

AWS parallelcluster: Note warns against UID/GID overlap with ParallelCluster reserved users

Service: parallelcluster · 2026-09-27 · Documentation medium

File: parallelcluster/latest/ug/DirectoryService-v3.md · Type: authz

Summary

Adds a note advising that directory service users' and groups' UIDs and GIDs must not overlap with the IDs AWS ParallelCluster reserves, linking to the reserved users and groups page.

Security assessment

This is hardening guidance for identity/ownership collisions: if an AD/LDAP user is assigned a UID/GID that matches a reserved system user or group, that user could gain unintended ownership/permissions over files and processes on the cluster nodes. It documents a security best practice (not a specific vulnerability fix), so it is security documentation of medium impact rather than a CVE remediation.

Evidence

+Make sure the UIDs and GIDs of directory service users and groups don't overlap with those that AWS ParallelCluster reserves. See [AWS ParallelCluster reserved users and groups](./users-and-groups-v3.html).

Diff

diff --git a/parallelcluster/latest/ug/DirectoryService-v3.md b/parallelcluster/latest/ug/DirectoryService-v3.md
index 410386273..9dc6bdfe9 100644
--- a//parallelcluster/latest/ug/DirectoryService-v3.md
+++ b//parallelcluster/latest/ug/DirectoryService-v3.md
@@ -20,0 +21,4 @@ We recommend that you use LDAP over TLS/SSL (abbreviated LDAPS for short) to ens
+###### Note
+
+Make sure the UIDs and GIDs of directory service users and groups don't overlap with those that AWS ParallelCluster reserves. See [AWS ParallelCluster reserved users and groups](./users-and-groups-v3.html).
+