AWS parallelcluster: Note warns multi-user clusters about UID/GID collisions
Summary
Adds a note requiring that UIDs and GIDs of directory service users and groups not collide with AWS ParallelCluster reserved IDs, with a link to the reserved users and groups topic.
Security assessment
In a multi-user cluster, a directory user whose UID/GID matches a reserved system account could inherit that account's access to files or processes, enabling unintended privilege/ownership escalation. The change documents this hardening best practice; it is not tied to a specific reported vulnerability.
Evidence
+Make sure the UIDs and GIDs of directory service users and groups don't overlap with those that AWS ParallelCluster reserves. See [AWS ParallelCluster reserved users and groups](./users-and-groups-v3.html).
Diff
diff --git a/parallelcluster/latest/ug/multi-user-v3.md b/parallelcluster/latest/ug/multi-user-v3.md index 674520564..5ba66fc22 100644 --- a//parallelcluster/latest/ug/multi-user-v3.md +++ b//parallelcluster/latest/ug/multi-user-v3.md @@ -12,0 +13,4 @@ In this topic, an AWS ParallelCluster user refers to a system user for compute i +###### Note + +Make sure the UIDs and GIDs of directory service users and groups don't overlap with those that AWS ParallelCluster reserves. See [AWS ParallelCluster reserved users and groups](./users-and-groups-v3.html). +