AWS pcs: FAQ clarifies scontrol token is incompatible with PCS Slurm REST API
Summary
Rewrites the FAQ answer to state that standard scontrol token output is never compatible with AWS PCS, on any Slurm version including 26.05, because it lacks the required POSIX identity (uid/gids/username) claims, and links to the authentication topic.
Security assessment
Documents the token requirements for authenticating to the Slurm REST API and confirms that tokens missing required identity claims are rejected, reinforcing authentication expectations without describing a patched vulnerability.
Evidence
The PCS Slurm REST API requires enriched JWT tokens that contain POSIX identity claims, and `scontrol token` generates a token without them. Tokens that lack the required claims are rejected by the API.
Diff
diff --git a/pcs/latest/userguide/slurm-rest-api-faq.md b/pcs/latest/userguide/slurm-rest-api-faq.md index c50dd21b6..d02eab0c1 100644 --- a//pcs/latest/userguide/slurm-rest-api-faq.md +++ b//pcs/latest/userguide/slurm-rest-api-faq.md @@ -19 +19 @@ The Slurm REST API is an HTTP interface that allows you to interact with the Slu -No, standard `scontrol token` output is not compatible with AWS PCS. The PCS Slurm REST API requires enriched JWT tokens containing specific identity claims that include username(`sun`), POSIX user ID(`uid`), and group IDs(`gids`). Standard Slurm tokens lack these required claims and will be rejected by the API. +No, standard `scontrol token` output is not compatible with AWS PCS on any supported Slurm version, including 26.05. The PCS Slurm REST API requires enriched JWT tokens that contain POSIX identity claims, and `scontrol token` generates a token without them. Tokens that lack the required claims are rejected by the API. For the claims a token must contain, see [Authenticating with Slurm REST API in AWS PCS](./slurm-rest-api-authenticate.html).