> I found an old mailing list discussion about this. I'm curious if any > progress has been made since and if there is a solution now? > > Is there a way to limit the SSH sessions of users to the cgroup defined by > their jobs? I'm using pam_slurm.so to limit SSH access > to only those users with running jobs. However, if a user reserves say 2 GPUs > on a 4 GPU system, the cgroups only give their job > access to 2 GPUs. But, they can login and have access to all 4 GPUs. I want > to prevent that.
Have you looked at "pam_slurm_adopt.so"? We are using that successfully. It "adopts" the cgroup of the user's job. -Tyler