QuantaStor Shell Utilities
Every QuantaStor appliance ships a set of command-line utilities under /usr/bin/qs-* alongside the main qs management CLI. They cover the work that is easier from a shell than from the web interface -- log collection, triage, upgrades, kernel and driver management, I/O fencing, Ceph maintenance and low-level pool repair. This page describes each of them, what it is for, and how to invoke it.
Almost all of these commands require root. Log in as qadmin and use sudo, or run them from a root shell.
| Area | Utilities | Purpose |
|---|---|---|
| Management CLI | qs |
The full management API as a command-line tool -- everything the web interface can do. |
| Status and logs | qs-version, qs-status, qs-showlog, qs-audit |
What is running, what version, and what the service has been doing. |
| Support logs | qs-sendlogs, qs-trunclog, qs-download-link |
Collect a log bundle, keep /var/log from filling, hand a file to support.
|
| Upgrades and packages | qs-upgrade, qs-distupgrade, qs-apt-channel, qs-package-check, qs-kernel, qs-kernelupgrade, qs-dkms-install |
Product upgrades, repository channel selection, kernel and driver installs. |
| Performance | qs-iostat, qs-zfstunings, qs-perftest, qs-ramdisk |
Measure device and cache behaviour, compare tunables against their defaults, run baseline benchmarks. |
| General maintenance | qs-util |
The large general-purpose toolbox: networking, ZFS memory, encryption keys, iSCSI/FC, SNMP, hardening. |
| Pools, shares, encryption | qs-zconvert, qs-zvolutil, qs-zpoolscrub, qs-luksutil, qs-fsmon, qs-shareusage |
Import foreign pools, repair bit-rot, tune encrypted pools, scan share capacity. |
| High availability | qs-crm, qs-iofence, qs-scstdlm, qs-pcsnodealert |
Corosync/Pacemaker state, SCSI-3 persistent reservations, clustered reservation locking. |
| Scale-out (Ceph) | qs-ceph, qs-ceph-journalgroup, qs-osd-compact, qs-cephfsutil, qs-s3util, qs-rgw-autotier, qs-rgw-monitor, qs-rgw-moveobjects |
Cluster health, OSD and journal maintenance, CephFS and S3 object tooling. |
| Certificates | qs-sslcert |
Inspect, generate, install and reset the grid and web certificates. |
| Statistics | qs-statsdb |
Query and maintain the InfluxDB time-series database behind the dashboards. |
| Replication keys | qs-sshkey |
Manage the SSH keys remote replication uses. |
| Enclosures | qs-seagate, qs-wd |
Vendor-specific enclosure log collection and zoning. |
| Boot repair | qs-bootefi-fix |
Repair an EFI boot partition entry in /etc/fstab.
|
Getting help from a utility
The utilities do not all take --help. Most of the shell-based ones print their usage block when they are run with no arguments, or when they are given an operation they do not recognise -- so --help produces the usage text followed by an ERROR: Specified operation '--help' is not supported line. That error is harmless; the usage above it is the real output.
Two exceptions are worth knowing:
qs-iofence --helpprints only the flag list. Runqs-iofencewith no arguments to get the full command list.qs-zfstuningshas no help at all. Its optional first argument is a configuration file path, so--helpis read as a filename and rejected.
The Python-based utilities -- qs-audit, qs-iostat, qs-sendlogs, qs-upgrade, qs-kernelupgrade, qs-dkms-install, qs-perftest -- take -h / --help in the usual way. The compiled utilities -- qs-s3util, qs-cephfsutil, qs-shareusage -- take a help operation.
qs -- the management CLI
qs is the full QuantaStor management interface as a command-line tool. It exposes the same operations as the web interface, and it is the tool to reach for when provisioning, licensing or cluster configuration needs to be scripted -- which is why it is the basis of most MSP and service-provider automation around QuantaStor.
It is installed on every appliance, and it also runs remotely: point it at an appliance with --server, the QS_SERVER environment variable, or a ~/.qs.cnf file holding ipaddress,username,password. Client packages for Debian/Ubuntu, RedHat/CentOS and Windows are on the OSNEXUS downloads page, so the same commands can be run from an administrator's own workstation.
The command set is large -- around two thousand commands and aliases -- so discovery matters more than memorisation:
qs help # full help qs help pool # help for every command whose name contains 'pool' qs help --min # one line per command: name plus required arguments qs pool-list --verbose # every argument of one command, with descriptions qs imode # interactive mode
Output can be rendered as XML, JSON or CSV with --xml, --json or --csv, which is what makes it usable from scripts.
A malformed qs command exits zero, so check the printed error rather than the exit status when scripting against it.
The complete command reference is the QuantaStor CLI Command Reference; the equivalent for PowerShell is the QuantaStor PowerShell Command Reference, and the same operations are available over HTTP through the REST API Reference Guide. See also the CLI Guide Overview.
System status and logs
qs-version
Prints the CLI, service and web manager versions, then lists the version of every member of the storage grid. The grid listing needs root; run as an unprivileged user it prints the local versions and warns that it cannot report on grid members.
# qs-version ## CLI Version Info ## OSNEXUS QuantaStor CLI 6.9.0 ## Service Version Info ## OSNEXUS QuantaStor Service 6.9.0 ## Web Manager Version Info ## OSNEXUS QuantaStor Web Manager 6.9.0 ## Storage Grid Server List ## ...
Note that a few of the utilities on this page print a version of their own in their banner which does not track the product version. qs-version is the authoritative answer.
qs-status
Prints a one-line systemd state for each QuantaStor and protocol service, grouped into four sections -- core service, internal services, web services and protocol services. A service whose unit is not installed prints missing rather than an error, so the report is readable on an appliance that does not run every protocol.
The internal services covered are qs-snmpagentd, qs-zfseventd, qs-jsonrpcd, qs-rest-soap-relay, qs-statsd, qs-scriptd and qs-sso-authd; the protocol services are iscsi-target, nfs-server (with a count of running nfsd threads), nfs-ganesha, smb, nmb and winbind. The web tier is nginx.
# qs-status
[core service]
quantastor: active (running) since Thu 2026-09-03 04:53:21 UTC; 39min ago
[internal services]
qs-jsonrpcd: active (running) since Thu 2026-09-03 04:53:12 UTC; 40min ago
qs-rest-soap-relay: active (running) since Thu 2026-09-03 04:53:12 UTC; 40min ago
...
qs-showlog
A front end to the log files under /var/log/qs/. It saves remembering which file holds what, and it knows which logs are toggled on rather than always written.
qs-showlog is a helper script for printing various QuantaStor service logs
Usage:
Service Log:
qs-showlog -a : Dump QuantaStor service log to the console (cat /var/log/qs/qs_service.log)
qs-showlog -f : View service log (tail -F /var/log/qs/qs_service.log)
qs-showlog -e : Print just the errors and warnings in the qs_service.log.
Service Internals:
qs-showlog -audit [-f] : View the QuantaStor service audit log (tail /var/log/qs/qs_audit.log)
qs-showlog -api [--clear] : View API command log (tail /var/log/qs/qs_apicall.log)
qs-showlog -boot : View the QuantaStor service boot log (tail /var/log/qs/qs_boot.log)
qs-showlog -crypto : View crypto log traces (tail /var/log/qs/qs_crypto.log)
qs-showlog -event [<seconds>] : View grid events being processed and generated by the QuantaStor service.
Each capture writes a new /var/log/qs/qs_event_<timestamp>_<window>.log and stops
itself when the window elapses, defaulting to 600 seconds
(10 minutes). Pass a window in seconds to override it.
qs-showlog -event --clear : Stop event logging now, leaving the capture in place.
qs-showlog -execcmd [--clear] : View commands being run by the core service (tail /var/log/qs/qs_exec.log)
qs-showlog -gs [--clear] : View grid stats (tail /var/log/qs/qs_gridstats.log)
qs-showlog -running : View currently running commands (tail /var/log/qs/qs_service.log)
qs-showlog -shutdown : View the QuantaStor system shutdown log (tail /var/log/qs/qs_shutdown.log)
qs-showlog -snmp : View the QuantaStor SNMP agent log (tail /var/log/qs/qs_snmpagent.log)
qs-showlog -scst [--clear] : VIew SCST sysfs commands (tail /var/log/qs/qs_scst.log)
qs-showlog -vols [--clear] : View iSCSI/FC volume sessions (tail /var/log/qs/qs_volsession.log)
qs-showlog -e is the usual first move on a reported problem: it filters the service log down to just its errors and warnings, with the source line number of each entry.
Event logging is bounded rather than left on. qs-showlog -event starts a capture that writes its own timestamped file and stops itself after ten minutes; pass a number of seconds to change the window, or --clear to stop the capture early and keep what has been written.
qs-showlog -shutdown reports that the file is missing on a system that has not been shut down since the log was last rotated. That is expected -- the log is written during shutdown.
qs-audit
Reads /var/log/qs/qs_audit.log, the JSON record of every API call the service has handled, and prints it with syntax colouring. It runs without root.
Its most useful capability is translation: -c converts each logged call back into the equivalent qs CLI command, and -u / -j into an equivalent curl call using query parameters or a JSON body. That turns "do it once in the web interface, then read back the command" into a practical way of writing automation, and it is the fastest way to find the argument set a dialog actually sends.
# qs-audit -c -q -n 5 Displaying 5 of 64 entries: Thu Sep 03 05:36:56 2026 qs_audit.log entry converted to CLI: qs share-modify --share "sales-share" --name "sales-share" --active "true" --cifs-enable "true" ...
Arguments that matter:
| Argument | Effect |
|---|---|
-n <count> |
Number of matching entries to show. Default 100, or 5 in follow mode. |
-a |
Show every entry in the log. |
-f |
Follow the log in real time. |
--filter <string> |
Show only entries matching a search term. Comma-separated terms are allowed. |
--filter-apis |
Restrict the filter to the method_api field, expanded through the CLI name mapping. Cannot be combined with -v.
|
-c / -u / -j |
Convert entries to a qs CLI command, a query-parameter curl call, or a JSON-body curl call.
|
-q |
Suppress the raw JSON and print only the conversion. Only valid with a conversion option. |
-v |
Include entries that carry no method_api field, which are hidden by default.
|
--file <path> |
Read a different log file -- for example one unpacked from a support bundle. |
The web interface offers the same log through the Audit Log Analyzer.
Support log collection
qs-sendlogs
Collects a support log bundle and uploads it to OSNEXUS support. The web interface uses this same script, so the bundle is the same either way. Requires root.
Scrubbing and uploading are both on by default, which is the opposite of what older documentation said. There is no --scrub argument, because personally identifiable information is removed unless you ask for it to be kept:
| Argument | Effect |
|---|---|
--no-upload |
Collect the bundle but do not upload it. Use on a system with no outbound internet access. |
--no-scrub |
Keep personally identifiable information in the bundle. Off by default. |
--no-trunc |
Do not truncate large log files. |
--proxy <url> |
Upload through an HTTP proxy, as http://proxyserver:port.
|
--filepath <path> |
Send only the single file at this path instead of collecting a bundle. |
--no-cleanup |
Keep the temporary collection directory, so the bundle can be reviewed locally. |
For a permanently disconnected site, create the touchfile /var/opt/osnexus/quantastor/touchfiles/qs_logs.no_upload rather than remembering --no-upload on every run -- it disables uploading for good, including for collections started from the web interface.
Collection from the web interface, and what the bundle contains, is covered on Send System Log Report.
qs-trunclog
Truncates oversized files in /var/log when the filesystem is close to full. It looks for files larger than 1 GiB and acts only when usage on the log or root filesystem is above 85%. Truncation preserves the inode, so processes with the file already open keep writing without needing a restart. Requires root.
# qs-trunclog scan
{Thu Sep 3 05:34:31 2026, INFO, sh:qs_trunclog} Log/Root filesystem usage: / = 25%
{Thu Sep 3 05:34:32 2026, INFO, sh:qs_trunclog} No files in /var/log exceed 1024 MiB.
Three operations: scan reports without changing anything, truncate acts if the threshold is crossed, and cronsetup installs an hourly job under /etc/cron.hourly to run truncate. Add --quiet for cron use and --debug when working out why it did or did not act.
Run scan first. It is the safe way to see what truncate would take.
qs-download-link
Publishes a file over HTTPS on port 8889 behind a short-lived random token, so a log bundle or a diagnostic capture can be pulled off an appliance without opening SSH access or setting up a share. Requires root.
# qs-download-link create /var/tmp/qs_logs.zip 30 https://10.0.8.141:8889/669936a2aeab5fd644c2deca?name=qs_logs.zip # qs-download-link list TOKEN EXPIRES_IN FILE 669936a2aeab5fd644c2deca 1799s /var/tmp/qs_logs.zip
| Command | Purpose |
|---|---|
auto [minutes] |
Pick the newest /var/tmp/*.zip and the best local address automatically. This is the one to use straight after qs-sendlogs --no-upload.
|
create <file> [minutes] [--host <ip>] [--port <port>] |
Publish a specific file, optionally on a chosen address and port. |
list |
Show the active tokens, the file each maps to, and the seconds left on each. |
cleanup |
Remove expired and stale tokens. |
Links default to 30 minutes. Tokens live in /var/tmp/nginx_tokens; cleanup is what removes them once they lapse.
Upgrades, packages and kernels
qs-upgrade
The product upgrade driver. It refreshes the package catalog and upgrades the QuantaStor packages and platform security updates from the configured repository, using the platform's own apt tooling. An upgrade started from the web interface runs this script, so the two paths are equivalent.
The arguments that matter in practice are --dryrun (do the setup work but do not upgrade), --coreOnly (QuantaStor core packages only), --includeKernel (also take kernel and driver packages, which needs a reboot), --force (discard cached repository metadata and re-download the package lists), --repoUrl (upgrade from a specific repository) and --getConfigValues (print the configuration it would use and do nothing else). Progress is written to /var/log/qs/qs_upgrade.log.
Note that these are Python argparse options that each take a value, so they are written --dryrun 1 rather than as bare flags.
Driving upgrades from the web interface, and the release-to-release notes, are on Upgrade Manager. Security-only package updates are covered on QuantaStor Security Updates.
qs-distupgrade
Upgrades the underlying Ubuntu release. A routine QuantaStor upgrade deliberately does not do this, because a distribution upgrade replaces drivers and platform packages and needs a much longer maintenance window. Reserve a maintenance window and contact OSNEXUS support before running it, so your logs can be reviewed on both sides of the upgrade.
The command itself is a dispatcher: it reads VERSION_CODENAME from /etc/os-release and hands off to the per-platform upgrade script for that release, preserving arguments and stdin. If no upgrade path exists from the running platform it says so and exits rather than doing anything. Run it inside screen so the upgrade survives a dropped session.
See Upgrade Manager for the surrounding procedure.
qs-apt-channel
Selects which QuantaStor apt repository channels the appliance uses, with validation and automatic rollback. Requires root.
Several channels can be enabled at once. Because apt resolves an overlapping package by taking the newest version, the script works out which of the enabled repositories will actually win for QuantaStor packages and reports that before it applies the change.
# qs-apt-channel --status
Current QuantaStor apt repositories (/etc/apt/sources.list.d/osnexus.list):
release deb http://packages.osnexus.com/packages quantastor-jammy main
# qs-apt-channel --list
Channels (from /opt/osnexus/quantastor/conf/qs_apt_channel.conf + ...):
http://packages.osnexus.com/packages
[x] release quantastor-jammy default, production
[ ] optional quantastor-jammy-optional add-on/optional packages ...
[ ] rc quantastor-jammy-rc staged stable build (release candidate), not yet GA
[ ] preview quantastor-jammy-preview TESTING ONLY - next-release preview; NOT for production use
...
| Argument | Effect |
|---|---|
<channel> |
Enable exactly that channel and nothing else. |
--channels a,b,c |
Enable exactly this set of channels. |
--select |
Choose interactively. |
--url <base-url> |
Use a custom repository base. Combinable with --channels; on its own it becomes the only source.
|
--status |
Show the repository entries currently in place. |
--list |
List the configured channels and which are enabled. |
--dry-run |
Validate the target selection and change nothing. |
--non-interactive |
Skip the confirmation prompts, and roll back automatically if post-switch validation fails. |
--force |
Keep the new repositories even if post-switch validation fails. |
--repair-pins |
Regenerate the apt pin file when an enabled suite has no pin stanza. |
The channel definitions come from /opt/osnexus/quantastor/conf/qs_apt_channel.conf, extended additively by drop-in files under /var/opt/osnexus/quantastor/conf/qs_apt_channel.conf.d/. Production systems belong on release; the rc and preview channels are for testing, and optional carries add-on packages and is meant to be enabled alongside a main channel rather than on its own.
Exit codes are meaningful: 0 for success, 1 for a usage or environment error, and 2 when the target selection failed validation.
qs-package-check
Compares the packages installed on the appliance against the reference package list captured for that QuantaStor version and platform, which makes an unexpected package install or a missing dependency visible. Runs without root.
# qs-package-check get-tag qs-pkglist-ubuntu-jammy-6.8.0-90-generic-qs-6.9.0.274
check diffs against the best-matching baseline ignoring versions; check-withver includes versions. Both accept a path to a specific package list file. capture-list prints the current package set as a sorted list and log-list writes it under /var/log/qs/, which is the right thing to do before a change you may need to compare against later. list-all, list-matching and list-best show which baselines are available, and get-tag prints the baseline tag for the local system.
qs-kernel
Installs a specific Ubuntu kernel version and builds the QuantaStor DKMS drivers against it. Requires root. Intended for systems that do not have Secure Boot enabled, since the DKMS modules it builds are unsigned.
qs-kernel --list sudo qs-kernel --custom-kernel 6.8.0-90-generic --reboot sudo qs-kernel --purge-old --yes
--list shows the most recent signed generic kernels. --custom-kernel <version> installs that kernel's headers, image, modules and extras, and --reboot reboots when it is done. --purge-old removes kernels that are not in the shipped list for the platform release, with --yes to skip the prompt.
Around the install it turns on DKMS source builds with a touchfile, temporarily lifts QuantaStor's apt pinning so the kernel packages can install cleanly, and puts the pinning back afterwards. It runs the driver install a second time deliberately, to cover the case where the kernel and headers were already present and the DKMS hook was skipped. Follow the build with tail -f /var/log/qs/qs_dkms.log.
qs-kernelupgrade
Upgrades the kernel and driver packages to the current shipped versions. This is the path qs-upgrade --includeKernel takes, rather than something normally run by hand. --repoUrl selects a repository and --targetDist a target platform release; --taskId is used by the service to attach progress to an upgrade task.
Use qs-kernel instead when the goal is a specific kernel version rather than the shipped one.
qs-dkms-install
Builds and installs the QuantaStor DKMS drivers. It normally runs from the kernel package's post-install hook rather than by hand, which is why its first two positional arguments are a kernel version and a boot path. Requires root. Logs to /var/log/qs/qs_dkms.log.
--dryrun performs the setup steps without installing, --getConfigValues prints the configuration and exits, --buildDrivers builds from source when no pre-built driver is available, --skipDownload uses only what is already local, and --repoUrl names the repository to pull driver packages from.
Driver support and the shipped driver set are covered on QuantaStor Driver Upgrades.
Performance measurement and tuning
qs-iostat
A front end to iostat and the ZFS kernel statistics, for looking at where I/O time is going. Runs without root.
| Argument | Shows |
|---|---|
-c |
Globally averaged CPU statistics. |
-d |
I/O statistics for all devices. |
-z |
Extended I/O statistics for the devices backing ZFS storage pools only. |
-a |
ZFS ARC, ZIL, prefetch and L2ARC statistics. |
-f |
Repeat every 2 seconds. |
--extra "<args>" |
Pass additional arguments straight through to iostat.
|
# qs-iostat -a ZFS Adaptive Replacement Cache (ARC) / read cache statistics Name Data --------------------------------------------- hits 1582909 misses 4 c_min 260208768 c_max 5692719104 size 16686912 l2_hits 0 ...
-z is the one to reach for on a pool that feels slow: it restricts the device view to the pool members, so a single slow disk stands out instead of being averaged away. Use qs-iostat -z -f while the workload is running.
What the ARC and ZIL numbers mean, and what to do about them, is on Performance Tuning; see also IO Performance Tuning and Performance Monitoring.
qs-zfstunings
Prints every ZFS and system tunable QuantaStor manages, with its current value beside its default and a state column saying whether the two agree. Runs without root, and changes nothing.
# qs-zfstunings SECTION | TYPE | STATE | TITLE | CURRENT | DEFAULT sst_resilver_min_time_ms | range | MATCH | Resilver Priority (msec/TXG) | 3000 | 3000 sst_cache_size | percentage | MATCH | Cache Size (% of RAM) | 68.37% (5.30 GiB) | 70% (5.43 GiB) sst_prefetch_disable | boolean | MATCH | Prefetch Disable | 0 | 0 sst_resilver_prio | - | SKIP | deprecated | <deprecated> | <none> ...
The state is MATCH when the running value agrees with the default, DIFF when it does not, and SKIP for tunables that are retained but deprecated. Percentage tunables are compared with a small tolerance, so a value derived from installed RAM is not reported as a difference just because the arithmetic rounds differently.
This is the quickest way to answer "has anything on this system been tuned away from stock", which is usually the first question when a pool underperforms. Definitions come from /opt/osnexus/quantastor/conf/qs_systemtunables.conf; pass a different file as the first argument to read one from elsewhere, such as a copy taken from another appliance.
Each of these tunables is settable from the web interface -- see Storage System Optimization for the full option reference and Storage System Tunable Set for the dialog.
qs-perftest
Baseline disk, pool and share benchmarking, wrapping fio, dd, elbencho and iozone. It can read every disk in the system, read only the disks backing one pool, write and re-read a file on a pool, or create temporary shares and benchmark them. Requires root.
Full coverage of the operations, arguments and how to read the results is on Performance Testing.
qs-ramdisk
Creates transient RAM-backed SCSI disks, so a benchmark can be run against memory and the storage transport measured on its own without the pool in the way. Optionally adds a synthetic per-command latency, which is how you calibrate how much latency a transport is contributing.
These devices are volatile: everything on them is lost on destroy and on reboot. They are for measurement only -- never place data on them and never build a production pool from them.
Operations and worked examples are on Performance Testing.
qs-util -- general maintenance
qs-util is the largest of these utilities: one command with around 150 operations covering Linux-level maintenance that has no natural home elsewhere. Some of it is support tooling, but a good deal of it is the sort of thing an administrator needs during a network change, a hardware swap or a capacity problem.
Run qs-util with no arguments for the full usage block.
Almost every operation requires root. Ten do not: lastreboot, lastshutdown, iscsiiqn, monitorinstall, distro, nvmelist, nvmecompression, mexec, fixosrelease and usage. Everything else prints ERROR: Use 'sudo' with this command, operations must be run as root. and stops.
Note that the usage block does not list every operation the command accepts; a number of internal operations are dispatched but undocumented.
System information
| Operation | Purpose |
|---|---|
lastreboot / lastshutdown |
When the system last came up, and when it last went down cleanly. The pair distinguishes a clean shutdown from a crash. |
distro |
The platform release codename, e.g. jammy.
|
zfsversion |
The installed ZFS package and driver versions. |
checkports |
Which process is listening on each QuantaStor service port. |
showservices |
Every listening socket on the system, including NFS and SMB. |
showclients |
Currently connected clients across NFS, SMB and the other protocols. |
devicemap |
Each /dev/sdX beside its stable /dev/disk/by-id/ path, make, model and serial. The one to use when a log names a device that has since been renumbered.
|
devinfo <sdN> |
The I/O tuning settings in effect for one device. |
nvmelist |
PCIe paths of the NVMe devices, in the form the slot map configuration file expects. |
nvmecompression |
Compression achieved on NVMe media that reports it. |
iscsiiqn |
The local system's iSCSI IQN. |
checkpass |
Whether the qadmin console account is still on its default password.
|
# qs-util devicemap /dev/sdb /dev/disk/by-id/scsi-SVMware_Virtual_disk_6000c295..., VMware, Virtual disk, 6000c295...
ZFS memory and swap
| Operation | Purpose |
|---|---|
zfsparams |
Print every ZFS tuning parameter currently in effect. |
zfsarcsummary |
The ZFS subsystem report -- ARC sizing, hit rates and breakdown. |
setzfsarcmax <pct> / setzfsarcmin <pct> |
Set the ARC ceiling and floor as a percentage of system RAM. |
zfsarcfix [-c] |
Drop the ARC if it has grown too large. -c only checks.
|
clearcache |
Drop the system page cache. |
checkswap [-c] |
Clear the cache if swap use is above 90%. -c only checks.
|
addswap <GB> / resizeswap <GB> |
Add a swap file, or resize the existing swap. |
importall |
Import every available ZFS storage pool. |
zpooldisks |
zpool status annotated with enclosure, slot, serial, make and model for each disk -- so a faulted member maps to a physical slot.
|
zpooldisks is the one to run before pulling a disk. Plain zpool status gives a device name; this gives the enclosure and slot to walk to.
Networking
| Operation | Purpose |
|---|---|
flusharp |
Flush the ARP cache. |
arping |
Send gratuitous ARP request and reply packets, to make switches relearn a moved address. |
addgw <ip> <nic> / delgw <ip> <nic> |
Add or remove a default gateway. |
addnet <net> <mask> <nic> / delnet <net> |
Add or remove a route. |
ifdown <nic> |
Bring an interface down, with extra checks first. |
pingtest <ip>,<ip>,... [timeout] |
Ping a list of addresses, with an optional timeout in milliseconds. |
npblink <nic> <seconds> |
Blink an interface's port LED, to identify the physical cable. |
gppset <uuid> <ip>, gpplist, gppclear |
Override, list and clear the grid preferred port -- the address a grid member is reached on. |
iSCSI initiator and Fibre Channel target
| Operation | Purpose |
|---|---|
iscsiinstall |
Install the open-iscsi initiator software. |
iscsidiscover <ip> |
Discover iSCSI targets at an address. |
iscsilogin <ip> |
Discover and log in to every target at an address. |
iscsirelogin <ip> |
Log back in to targets already established at an address. |
alua |
Print the ALUA configuration state. |
listfcclients |
List the connected Fibre Channel clients. |
issuelip |
Issue a LIP to every FC port, forcing a loop re-initialisation. |
enabledualmode / disabledualmode |
Put the QLogic FC driver into combined initiator+target mode, or back to target-only. |
Encryption keys and LUKS devices
These operate on the LUKS layer under an encrypted storage pool. Key material is handled directly, so treat them as support-assisted operations.
| Operation | Purpose |
|---|---|
cryptgenkey <outfile> |
Generate a new 256-bit encryption key file. |
cryptwrapkey <keyfile> <kwfile> <saltfile> |
Wrap a key and write the key-wrap and salt files. Prompts for the passphrase; for a pool with no passphrase, use the storage pool ID as the passphrase. |
cryptdecryptkey <kwfile> <saltfile> [outfile] |
Unwrap a wrapped key using its salt file. |
cryptrecoverkey <pooluuid> |
Unwrap a pool's key-wrap and salt files and place the plaintext key in /run/quantastor/cryptconf/keys.
|
cryptformat <device> <keyfile> |
LUKS-format a device with a given key. |
cryptopen <device> [keyfile] |
Open a LUKS device. With no key file, every key under /run/quantastor/cryptconf/keys is tried.
|
cryptclose <device> / cryptcloseall |
Close one or all LUKS devices. |
crypttabopenall |
Open every device listed in /etc/crypttab.
|
crypttabrepair |
Rebuild /etc/crypttab by trying every available key against every LUKS device.
|
cryptrekeydevice <oldkey> <device> <newkey> |
Add a new key slot to a device using the existing key. |
cryptswap <device> |
Encrypt the swap device, updating /etc/fstab and /etc/crypttab.
|
Pool key export and import from the web interface are on Storage Pool Export Encryption Keys and Storage Pool Import Encryption Keys.
Web access, ciphers and hardening
| Operation | Purpose |
|---|---|
disablehttp / enablehttp |
Restrict web management to HTTPS, or allow plain HTTP as well. |
disablehttpgzip / enablehttpgzip |
Turn HTTP gzip compression in nginx off or on. |
setweblogin "admin" |
Set the username prefilled on the login page; pass "" to clear it.
|
ciphers [HIGH|ALL] |
Set the OpenSSL cipher selection the core service uses. |
wuicustomcerts |
Allow custom certificate and cipher settings for the web interface, from /var/opt/osnexus/quantastor/ssl/nginx_quantastor_ssl_custom.conf.
|
wuicustomcertsrestart |
Restart nginx after changing those files, checking for configuration errors. |
wuicustomcertsdefault |
Revert to the shipped certificates and cipher settings. |
cacertusedefault / cacertuselegacy |
Use the standard 2048-bit RSA CA certificates, or the legacy 1024-bit set for compatibility with very old clients. |
enablefips / disablefips |
Turn FIPS mode on or off. |
ssh-sha1-audit |
Detect and remediate SHA-1 HMAC algorithms offered by OpenSSH. |
Certificate replacement, cipher policy and the web access model are covered in full on Security Configuration.
Protocol services
| Operation | Purpose |
|---|---|
enablesmbmulti / disablesmbmulti |
Turn SMB multi-channel support on or off. |
nfsganesha |
Give the scale-out NFS Ganesha service the primary NFS port, 2049. |
nfsstandard |
Move Ganesha to the secondary port, 2249, leaving 2049 to the kernel NFS server. |
nfsrdma |
Enable NFS RDMA mode. |
snmprestart |
Restart the SNMP service and agent. |
snmpmib |
Print the contents of the QuantaStor SNMP MIB. |
snmpwalkall, snmpwalkvolumes, snmpwalkalerts |
Walk the whole MIB, or just the volume or alert subtrees. |
Replication and clone bandwidth
| Operation | Purpose |
|---|---|
rlinkcheck <ssid> <ip> |
Verify that a remote system is reachable for replication over a given address. |
clratelimitget |
The current maximum clone throughput, shared across all active clone operations. |
clratelimitset <MB/s> |
Set that shared maximum. |
clraterebalance |
Rebalance active clone operations across the shared limit. |
The default shared clone limit is 200 MB/sec, and QuantaStor rebalances active clone streams every minute on its own unless /etc/clratelimit.disable exists -- so clraterebalance is only needed by hand when that file is in place.
Replication bandwidth is no longer set here; it is a per-link setting on the Storage System Link. See Remote-replication / Disaster Recovery Setup.
Triage, simulation and recovery
| Operation | Purpose | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
loadlog |
Append top -bn 1 output to /var/log/qs/qs_load.log.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
loadlogenable / loadlogdisable |
Add or remove a cron job doing that every 2 minutes -- the way to catch a load spike that only happens overnight. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
enablesysstats |
Enable sysstat collection, viewable with sar.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
simstart <osn.db> |
Put the service into simulation mode against a configuration database from another system, including one fetched over HTTP from a log server. Support use. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
hwsimstart <url> |
Simulate hardware controllers from information in a service log. Support use. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
simstop |
Leave simulation mode. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
dbtables |
List the tables in the configuration database. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
dblist |