iSCSI & Stratis
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
This page covers two block storage solutions commonly used on enterprise Linux. iSCSI lets you share a disk on one server over the network to another server, which mounts it and uses it just like a local disk. Stratis is the local storage management tool provided by RHEL, layering pooling, thin provisioning, and snapshots on top of XFS and device-mapper, which is simpler to use than traditional LVM plus a filesystem.
What You Will Learn
Section titled “What You Will Learn”- The roles of the iSCSI target and initiator
- How to build an iSCSI target with
targetcliand persist the configuration - How to discover and log in to a remote block device from the initiator, and enable automatic login at boot
- How to create storage pools, filesystems, and snapshots with Stratis
- How to make a Stratis filesystem mount reliably at boot
Prerequisites
Section titled “Prerequisites”- Two systems running EL 9.x or EL 10.x (the iSCSI part needs one target host and one initiator host)
- sudo privileges
- A spare disk or partition on the target (such as
/dev/sdb) - Network connectivity between the two hosts
Part 1: iSCSI Network Block Storage
Section titled “Part 1: iSCSI Network Block Storage”iSCSI (Internet SCSI) transports SCSI commands over an ordinary TCP/IP network, presenting a remote disk to the client as a block device. It involves two roles:
- target: the server, which provides block devices. Each target is identified by an IQN (iSCSI Qualified Name).
- initiator: the client, which connects to a target and mounts the remote block device locally. After login, a new block device (such as
/dev/sdb) appears.
iSCSI target (192.168.1.10) iSCSI initiator (192.168.1.20)/dev/sdb ──> backstore ──> LUN ──network──> /dev/sdb (appears after login) IQN + ACL partition / format / mountInstall targetcli
Section titled “Install targetcli”$ sudo dnf install targetcliConfigure the iSCSI target
Section titled “Configure the iSCSI target”targetcli is an interactive shell. Once inside, you organize the configuration using filesystem-like paths. The example below uses a spare disk /dev/sdb as the backend storage.
-
Enter the targetcli interactive shell:
Start targetcli $ sudo targetcli -
Create a backstore. You can use a whole device (block) or an ordinary file (fileio):
targetcli: create a block backstore /> backstores/block create disk1 /dev/sdbIf you have no spare disk, use a file as the backend instead:
targetcli: create a fileio backstore (optional) /> backstores/fileio create disk1 /var/lib/iscsi_disks/disk1.img 5G -
Create an iSCSI target, which automatically generates an IQN:
targetcli: create a target /> iscsi/ create iqn.2026-06.com.example:target1 -
Attach the backstore to the target as a LUN:
targetcli: create a LUN /> iscsi/iqn.2026-06.com.example:target1/tpg1/luns create /backstores/block/disk1Match the LUN path to the backstore type you created in the previous step: use
/backstores/block/disk1for a block backstore, or/backstores/fileio/disk1for a fileio backstore. -
Configure an ACL so that only the specified initiator IQN may connect. The initiator’s IQN comes from its
/etc/iscsi/initiatorname.iscsi:targetcli: create an ACL /> iscsi/iqn.2026-06.com.example:target1/tpg1/acls create iqn.2026-06.com.example:client1 -
Exit. On exit, the configuration is saved automatically to
/etc/target/saveconfig.json:targetcli: exit and save /> exit
Persistence and start at boot
Section titled “Persistence and start at boot”The target service loads the configuration from /etc/target/saveconfig.json at boot. Be sure to enable it, otherwise all your configuration is lost after a reboot:
$ sudo systemctl enable --now targetOpen the firewall
Section titled “Open the firewall”iSCSI uses 3260/tcp, which must be allowed on the target:
$ sudo firewall-cmd --permanent --add-port=3260/tcp$ sudo firewall-cmd --reloadInstall the initiator tools
Section titled “Install the initiator tools”$ sudo dnf install iscsi-initiator-utilsSet the initiator IQN
Section titled “Set the initiator IQN”The initiator’s IQN is set in /etc/iscsi/initiatorname.iscsi, and it must match exactly the IQN configured in the target’s ACL:
$ sudo vi /etc/iscsi/initiatorname.iscsiInitiatorName=iqn.2026-06.com.example:client1Restart iscsid after editing so the change takes effect:
$ sudo systemctl restart iscsidDiscover and log in to the target
Section titled “Discover and log in to the target”-
Run discovery against the target to list all targets it provides:
Discover the target $ sudo iscsiadm -m discovery -t st -p 192.168.1.10Output 192.168.1.10:3260,1 iqn.2026-06.com.example:target1 -
Log in to the target:
Log in to the target $ sudo iscsiadm -m node -T iqn.2026-06.com.example:target1 -p 192.168.1.10 --login -
After a successful login, a new block device appears. Confirm with
lsblk:View the new block device $ lsblkOutput (excerpt) NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTSsdb 8:16 0 5G 0 disk
Use the remote block device
Section titled “Use the remote block device”This new block device (such as /dev/sdb) is no different from a local disk; you can partition, format, and mount it normally:
$ sudo mkfs.xfs /dev/sdb$ sudo mkdir -p /mnt/iscsi$ sudo mount /dev/sdb /mnt/iscsiEnable automatic login at boot
Section titled “Enable automatic login at boot”By default, the login relationship does not persist across reboots. Set the node’s node.startup to automatic so it logs in automatically at boot:
$ sudo iscsiadm -m node -T iqn.2026-06.com.example:target1 -p 192.168.1.10 -o update -n node.startup -v automaticLog out of the target
Section titled “Log out of the target”When you no longer need it, unmount the filesystem first, then log out:
$ sudo umount /mnt/iscsi$ sudo iscsiadm -m node -T iqn.2026-06.com.example:target1 -p 192.168.1.10 --logoutPart 2: Stratis Local Storage Management
Section titled “Part 2: Stratis Local Storage Management”Stratis is the local storage management solution provided by RHEL and compatible distributions. Under the hood it uses XFS and device-mapper to handle the tedious configuration automatically, while exposing a simple command line that lets you manage pools, filesystems, and snapshots as objects, with thin provisioning built in.
It has two parts: the background service stratisd does the actual storage management, while the command-line tool stratis (from stratis-cli) takes your commands.
Install and enable
Section titled “Install and enable”$ sudo dnf install stratisd stratis-cli$ sudo systemctl enable --now stratisdCreate a pool and a filesystem
Section titled “Create a pool and a filesystem”-
Create a storage pool named
pool1from a spare disk:Create a pool $ sudo stratis pool create pool1 /dev/sdb -
Create a filesystem named
data1in the pool:Create a filesystem $ sudo stratis filesystem create pool1 data1 -
The filesystem’s device path is
/dev/stratis/<pool>/<filesystem>. List them to confirm:List pools and filesystems $ stratis pool list$ stratis filesystem list
Mount and auto-mount at boot
Section titled “Mount and auto-mount at boot”You can mount it temporarily first to test:
$ sudo mkdir -p /mnt/data$ sudo mount /dev/stratis/pool1/data1 /mnt/dataFor auto-mount at boot, you must use the UUID and add the systemd dependency. First find the filesystem’s UUID:
$ sudo lsblk --output=UUID /dev/stratis/pool1/data1Then add this to /etc/fstab (note x-systemd.requires=stratisd.service):
UUID=<the UUID from the previous step> /mnt/data xfs defaults,x-systemd.requires=stratisd.service 0 0Verify the fstab entry is correct (so you catch errors without rebooting):
$ sudo umount /mnt/data$ sudo systemctl daemon-reload$ sudo mount -a$ df -hT /mnt/dataSnapshots
Section titled “Snapshots”Stratis snapshots are based on thin provisioning, so they are fast to create and take almost no space initially:
$ sudo stratis filesystem snapshot pool1 data1 data1-snapA snapshot is itself an independent filesystem that you can mount separately to recover data:
$ sudo mkdir -p /mnt/snap$ sudo mount /dev/stratis/pool1/data1-snap /mnt/snapGrow the pool
Section titled “Grow the pool”When the pool runs low on space, add another disk to it with no data migration required:
$ sudo stratis pool add-data pool1 /dev/sdctargetcli configuration is lost after a reboot
Section titled “targetcli configuration is lost after a reboot”The most common causes are not saving the configuration when exiting targetcli, or not enabling the target service. Confirm two things: that you ran saveconfig inside targetcli (or exited normally with exit), and that sudo systemctl enable --now target is in place.
$ sudo targetcli saveconfigiSCSI login fails
Section titled “iSCSI login fails”Troubleshoot in order:
- Whether the IQN in the initiator’s
/etc/iscsi/initiatorname.iscsimatches the IQN configured in the target’s ACL exactly (spelling and case must match). - Whether the target’s firewall allows
3260/tcp. - Whether the network is reachable (
pingthe target IP) and whetheriscsiadm -m discoveryreturns the target list.
Stratis filesystem fails to mount at boot
Section titled “Stratis filesystem fails to mount at boot”Almost always the fstab entry is missing x-systemd.requires=stratisd.service. Add this option so the mount waits until stratisd is ready. Also confirm you are using the UUID rather than the /dev/stratis/... path.
Can I use fdisk/LVM directly on disks in a Stratis pool
Section titled “Can I use fdisk/LVM directly on disks in a Stratis pool”No. The physical devices in a pool are managed exclusively by Stratis, and all operations must go through the stratis command. Using other tools directly will corrupt the metadata.
Further Reading
Section titled “Further Reading”- LVM Management
- Filesystems (XFS/EXT4)
- Disks & Partitions
man targetcli/man iscsiadm/man stratis