Node Navigation
Get Started Here
Featured Content
Start Here
Getting Started: 5 Steps to Get the Most Out of the Everpure Customer Community
2 MIN READ Welcome! You've taken the first step and created an account here. What to do next you ask? Here's five simple steps to take after registering to ensure you're getting the most out of this community...bmcdougallPlace User BlogsUser BlogsCommunity Manager3.2KViews19likes9Comments
Recent Discussions
Entra ID SAML2 SSO on FlashArray (Purity//FA 6.12.3), including fleets
Hi everyone, Here is a working setup for single sign-on from Microsoft Entra ID to a FlashArray, tested on Purity//FA 6.12.3, which is the newest version at the time of writing. It follows the Microsoft tutorial for Pure Storage SSO (https://learn.microsoft.com/en-us/entra/identity/saas-apps/pure-storage-sso-tutorial) and adds the fixes I needed to get the login test to pass. It also covers adding more arrays and fleets. Two things that break the login if you skip them The gallery app ships with role names that do not match the FlashArray role names. If you do not rename them, the login test fails because the array cannot find the role (Step 6). The claims must have no namespace URI (Step 5). What you need An array admin login Entra admin rights (Enterprise applications and App registrations) The Pure Storage SSO app from the Entra App Gallery A user or group to assign Overview Create a certificate on the array Configure SAML2 SSO on the array Entra app and the array certificate Load the Entra signing certificate on the array Claims (delete the namespace URI) Fix the app role names Assign, test and enable Plus: more arrays and fleets, and a troubleshooting list at the end. Step 1: Create a certificate on the array The array needs its own RSA certificate to sign SAML requests and decrypt assertions. Do not use the management certificate: it is EC 256 and caused a 500 error for me. purecert self-signed create saml-sp --common-name myarray.pure --days 365 purecert list The saml-sp row should show self-signed, rsa, 2048. Note the expiry date: SSO signing stops working when it expires. Step 2: Configure SAML2 SSO on the array Go to Settings › Access › Users and Policies › SAML2 SSO and edit the configuration. Array URL: the array FQDN, for example https://myarray.pure/. Signing Credential and Decryption Credential: type the certificate name saml-sp. Do not paste certificate text. Switch on Sign Request and Encrypt Assertion. IdP Entity ID, URL and IdP Metadata URL: copy them from the Entra app (Set up Pure Storage SSO section). Keep Enabled off for now and save. Without credentials, saving fails with "Must provide signing credential when signed request is enabled" and the same message for decryption. The GUI can silently keep management, so check the result in the CLI: puresso saml2 list puresso saml2 test Both credential columns must show saml-sp. If not, set them directly: puresso saml2 setattr Entra-ID --signing-credential saml-sp --decryption-credential saml-sp This can print "Certificate claim does not exist." even though the values were applied, so trust the list output. Step 3: Entra app and the array certificate In the Entra admin center go to Enterprise apps › New application, search Pure Storage SSO and add it. Open Single sign-on › SAML › Basic SAML Configuration. Set Identifier to the array's SP Entity ID and Reply URL to the array's Assertion Consumer URL. Both are shown in the array's SAML2 SSO dialog, so copy them from there. On the array, open the certificates page and download saml-sp. Rename the extension from .crt to .cer. In the Entra app go to Single sign-on › SAML Certificates › Verification certificates › Edit, tick Require verification certificates, and upload the .cer. Because Encrypt Assertion is on, also import the same .cer under Token encryption and activate it (see the token encryption guide under Links). Check that you exported the right certificate: openssl x509 -in saml-sp.cer -noout -subject -enddate The subject must show the common name you used in Step 1, not the GUI certificate. Step 4: Load the Entra signing certificate on the array The array needs Entra's signing certificate to validate the response. If this is empty the array test still shows OK, but a real login fails. In Entra open Single sign-on › SAML Certificates and download Certificate (Base64). Open the file, copy everything including the BEGIN CERTIFICATE and END CERTIFICATE lines. In the array's SAML2 SSO dialog click Edit next to Verification Certificate and paste it. CLI alternative: puresso saml2 setattr Entra-ID --verification-certificate Step 5: Claims (delete the namespace URI) In the Entra app go to Single sign-on › Attributes & Claims › Edit. Open each claim, clear the Namespace field completely, and make sure the names match exactly: dn: user.onpremisesdistinguishedname email: user.mail (or user.userprincipalname for UPN) family_name: user.surname given_name: user.givenname purity_roles: user.assignedroles (required for array level SSO) Step 6: Fix the app role names The Pure Storage SSO gallery app is set up incorrectly for its role names. It ships readonly_role, ops_admin_role, storage_admin_role and array_admin_role with an empty value. The names must match the FlashArray role names exactly, otherwise the login test fails because the array cannot find the role. The roles are edited in App registrations, not in the Enterprise application: Go to App registrations › All applications and search for the app name. Open App roles and click a role. In Display name, remove the _role suffix. In Value, enter the role name, for example array_admin. Click Apply and repeat for the other roles. array_admin_role → Display name: array_admin, Value: array_admin storage_admin_role → Display name: storage_admin, Value: storage_admin ops_admin_role → Display name: ops_admin, Value: ops_admin readonly_role → Display name: readonly, Value: readonly Leave msiam_access as it is. Step 7: Assign, test and enable In the Entra app go to Users and groups › Add user/group, pick the user, click Select a role and choose one of the renamed roles. Only one role per assignment. On the array open the SAML2 SSO dialog and click Test. All lines must be green and the first two must show saml-sp. Click E2E Test, sign in with the assigned user, then click Check E2E Test Result. If it passes, switch Enabled on and save. The login page now shows Click for Single Sign-On and a Local Access link. Tip: Keep a working local admin login in case something on the Entra side breaks or a certificate expires. More arrays and fleets Each array needs its own certificate, and that certificate must be uploaded to Entra under Verification certificates, next to the ones from the other arrays. You do not need a new Enterprise application per array. If you use Fusion / fleet manager, enable Trust Other SAML Service Providers In Fleet in the SAML2 SSO configuration and apply these settings on each additional array: Create the certificate on that array (Step 1) with its own common name. Use the same SSO configuration name as on the first array. Array URL: the FQDN of the new array. SP Entity ID: set it to Manual and paste the SP Entity ID of the first array. All fleet members must use the same SP Entity ID. Signing Credential and Decryption Credential: saml-sp, the certificate of this array. Switch on Sign Request and Encrypt Assertion. Identity Provider fields and Verification Certificate: the same values you used on the first array. In the Entra app, add a second Reply URL with the Assertion Consumer URL of the new array, and upload the new array's saml-sp .cer under Verification certificates. Run Test and E2E Test before enabling. After that you can sign in on the other arrays with the same Entra users, roles and claims. Note: If you use Encrypt Assertion on several arrays, check this: Entra token encryption uses one active certificate per application, so test each array with the E2E test. Troubleshooting Save fails: must provide signing or decryption credential: Create saml-sp and enter its name in both fields Red error echoes a long MIID... string: You pasted certificate text. Type the certificate name instead Test shows management as credential: Run puresso saml2 setattr as in Step 2 500 Internal Server Error when starting login: The credential was the EC management certificate. Switch to the RSA saml-sp certificate Login test fails, role not found: Rename role display name and value in App registrations (Step 6) Login fails or user has no role: Clear the claim namespaces and check purity_roles = user.assignedroles (Step 5) Verification certificate shows - in the test: Paste the Entra Base64 certificate (Step 4) If you do not need signed requests or encrypted assertions, you can switch off Sign Request and Encrypt Assertion and skip the certificate steps. Links Configure Pure Storage SSO for Single sign-on with Microsoft Entra ID (https://learn.microsoft.com/en-us/entra/identity/saas-apps/pure-storage-sso-tutorial) Configure Microsoft Entra SAML token encryption (https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/howto-saml-token-encryption) Manage certificates for federated single sign-on (https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/tutorial-manage-certificates-for-federated-single-sign-on) App roles UI (https://learn.microsoft.com/en-us/entra/identity-platform/howto-add-app-roles-in-apps#app-roles-ui) Hope this saves someone some time. Questions and corrections are welcome.12Views2likes0CommentsActive Cluster for File
Hello everyone :-) I'm new to Active Cluster for File and I'm looking for some documentation or introductory material. I'd like to understand: How Active Cluster for File works How it is configured via the management interface General setup, requirements, and administration tasks If anyone can point me to official documentation, knowledge base articles, or deployment guides, I would really appreciate it. Thanks!Solved167Views2likes5CommentsOur First Virtual Pure User Group Meeting
I hope you’re enjoying the fall weather. Baseball fans have already seen two roof balls this postseason, while Bengals fans know the drill. We tried to gather this summer, but the July 4th holiday and vacations made scheduling tough. We’re planning one last community get-together before 2027, and details are coming soon. In the meantime, join us for our first virtual Pure User Group, focused on modern virtualization. Subject matter experts and customers will share their experience and answer questions. We’re bringing together Pure User Group communities from across the Midwest, including Pittsburgh, but don’t let the Steelers fans scare you off even though they got the best of our Bengals a few weeks ago. Event Date/Time: Thursday, October 29, 2026, 1:00–2:20 p.m. Eastern Register: https://experience.everpuredata.com/virtualizationlunchlearn I’ve loved the community we’ve built in 2025 and 2026. We have a great foundation, and I’m looking forward to building on it in 2027.Purity//FB 4.8.6 FR has released
We are happy to announce the general availability of 4.8.6, the seventh Feature Release in the 4.8/4.9 line, helping customers move from managing storage to managing their data, with governance that enforces itself, a fleet that runs as one, and real-time insight that keeps critical workloads performing, all with less manual effort and less risk. See the release notes for all the details about the features and improvements included in this release.9Views0likes0CommentsPurity//FA 6.12.3 FR has released
We are happy to announce the general availability of 6.12.3, the fourth Feature Release in the 6.12/6.13 line, including new capabilities that help customers advance their Enterprise Data Cloud with deeper VM-level workload visibility, standardized fleet-wide bucket provisioning, and simpler data replication with less complexity and risk. See the release notes for all the details about the many features, enhancements, bug fixes, and security updates included in this release.19Views0likes0CommentsActive Cluster for File
Hello, I have another question. I am currently implementing Active Cluster for FILE, but regarding the server interface configuration—specifically for the Realm server—I need to add the sub-interfaces for each array, correct? For example, I add `ct0.eth1` for Array 1; then, since `array1:ct0.eth1` is automatically replicated, I should edit it to add the `ct0.eth1` on Array 2, and likewise add the `Array2:ct0.eth1` interface on Array 1, right? To test this, I make the change using Bulk Edit, select the "Remediate" option, and I am able to ping the interface IP. Is this the correct procedure? I didn't find any mention of this "Remediate" procedure in the articles, only in the GUI itself. Thank you.49Views1like2CommentsRecommended Beginner Recipes
Greetings, I am just starting my Pure1 Workflows journey, and wanted to know some "Recipe ideas" others would recommend for beginners in order to get the hang of how to create them before progressing onto more complex ones? Example, setting up monitoring, provisioning volumes, etc...Solved116Views1like4CommentsHow much more inference could you get from the GPUs you already have?
As inference workloads grow, it’s not always the GPU compute that becomes the bottleneck. Recomputing tokens of a known context vs reloading from KV cache can take up a lot of GPU bandwidth and limit how many workloads you can run in a given amount of time. That’s one of the things we’ve been working on with PureKVA, reusing KV cache so you can get more out of the GPU capacity you already have. With v1.2, we’ve also added a 3-tier memory architecture, TurboQuant KV cache support, along with things like multi-tenancy and storage isolation. We’re seeing some of the benefits internally as well, particularly around reducing throttling when usage spikes. Curious what others are seeing. Is GPU compute the bigger constraint for you, or GPU memory?16Views1like0Comments09222026 - Demo Recap - From CSI to Snapshots—Seamless VM Management on Red Hat OpenShift
If you missed our latest Expert Led Demo, Matt Webb and I walked through how teams can manage virtual machines on Red Hat OpenShift while using Everpure FlashArray through CSI. The goal was not to turn every VMware administrator into a Kubernetes expert overnight. It was to connect the dots: many familiar VM operations still exist, but the platform uses different objects, policies, and automation to get the job done. What you missed 👇 🗺️ A familiar operating model with new terminology. Worker nodes, StorageClasses, PersistentVolumeClaims, live migration, and VirtualMachine objects map closely to concepts many VMware administrators already know. ⚙️ CSI automates the storage plumbing. A StorageClass defines the storage policy, while the CSI driver provisions volumes, maps them to the right node, and handles the day-to-day attachment work. 🔀 Choose the right storage-consumption model. Teams can use Portworx Enterprise volumes for flexible, software-defined storage services across mixed infrastructure, or FlashArray Direct Access when they want array-level data services and visibility in Purity. 🚀 Keep VM operations simple. In the demo, we showed a live compute migration, created a VM from a template, and used the OpenShift console to work through familiar virtualization tasks. 📸 Use array-based snapshots for fast recovery. With CSI configured, snapshots are FlashArray-based. The demo showed taking a snapshot, deleting data, restoring the VM, and bringing the data back quickly. 🧳 Plan migrations around your environment. Migration Toolkit for Virtualization can support cold migrations, while storage-offload migration can use SCSI XCOPY when source VMware storage and OpenShift storage share the same FlashArray. The practical takeaway: storage policies and automation remove much of the manual LUN, mapping, rescan, and multipathing work. That gives virtualization and platform teams more time to focus on the workload—not the plumbing behind it. 🎥Catch up on the demo HERE 🎥 💬 What is the biggest question your team has about running VMs on OpenShift: migration, storage policy, snapshots, or day-two operations? Share it in the comments.10Views1like0Comments10012026 - TechTalk Recap - Oracle Resiliency—Choosing the Right Data Protection Approach🛡️
If you missed our latest TechTalks session, Lester Wells and I explored an important reality for Oracle teams: there is no single data-protection feature that covers every failure scenario. Keeping Oracle resilient means looking beyond a simple “backup or HA” decision. The right approach layers protection for local failures, site failures, operational recovery, and logical corruption—then aligns each layer to the application’s business requirements. What you missed 👇 🧭 HA and DR are different problems. High availability helps applications continue through infrastructure failures; disaster recovery protects against a broader site-level event. Both matter, but not every database needs the same RPO or RTO. ⚡ Snapshots improve operational recovery. Fast, space-efficient snapshots can help reduce backup and recovery pressure, refresh dev/test environments, support reporting copies, and provide recovery points for ransomware or user errors. 🏢 ActiveCluster is designed for continuous availability. For metro-distance deployments that meet latency requirements, synchronous replication can provide zero RPO and zero RTO protection against array or site failure. 🌍 ActiveDR extends protection across distance. Continuous, asynchronous replication supports disaster recovery where synchronous replication is not practical—and enables non-disruptive DR testing. 🧩 Layered protection covers more failure modes. Oracle RAC, ActiveCluster, ActiveDR, Data Guard, Flashback, and snapshots each address different risks. Combining the right layers helps protect both availability and recoverability. 🔎 Replication does not replace logical recovery. A bad write, accidental delete, or corruption can replicate correctly. Point-in-time snapshots and database-level recovery tools remain important parts of the plan. One of the best practical examples was using ActiveDR to bring up and validate a DR environment without disrupting production. That makes it easier to test your recovery plan more often—before you need it. 🎥 Catch up on the session HERE🎥 💬 Which Oracle resilience challenge is top of mind for your team: backup windows, recovery time, site-level availability, DR testing, or protection from logical errors? Share your perspective in the comments.9Views0likes0Comments
Upcoming Events
- Oct13Tuesday, Oct 13, 2026, 05:00 AM PDT
- Oct13Tuesday, Oct 13, 2026, 11:00 AM PDT
- Oct13Tuesday, Oct 13, 2026, 04:45 PM PDT
- Oct13Tuesday, Oct 13, 2026, 04:45 PM PDT
- Oct14Wednesday, Oct 14, 2026, 02:00 AM PDT
- Oct15Thursday, Oct 15, 2026, 09:00 AM PDT
- Oct20Tuesday, Oct 20, 2026, 09:00 AM PDT
- Oct28Wednesday, Oct 28, 2026, 04:00 PM PDT
- Nov5Thursday, Nov 05, 2026, 04:00 AM PST
- Nov25Wednesday, Nov 25, 2026, 04:00 AM PST
Featured Places
Introductions
Welcome! Please introduce yourself to the Pure Storage Community.Pure User Groups
Explore groups and meetups near you./CODE
The Everpure /Code community is where collaboration thrives and everyone, from beginners taking their first steps to experts honing their craft, comes together to learn, share, and grow. In this inclusive space, find support, inspiration, and opportunities to elevate your automation, scripting, and coding skills, no matter your starting point or career position. The goal is to break barriers, solve challenges, and most of all, learn from each other.Career Growth
A forum to discuss career growth and skill development for technology professionals.
Featured Content
Fleet Security Assessment
The Pure1 Fleet Security Assessment provides a fleet-wide view of the security posture of FlashArray and FlashBlade systems by correlating each asset's current software ve...
1 month ago181Views
0likes
0Comments
If you are moving Oracle databases off Exadata, the first sizing mistake is usually looking at only one database at a time.
Exadata is not a traditional Oracle architecture. Some of the work that w...
1 month ago127Views
1like
0Comments
If you missed last week’s TechTalks, Ashish Gupta and I dug into a practical question many teams are working through right now: before you ask AI to make decisions with your data, do you really know ...
29 days ago207Views
5likes
1Comment
What happens when you take the enterprise storage capabilities IT teams rely on and deliver them as a fully managed, Azure-native experience?
That question was at the heart of our latest Ask Us Eve...
30 days ago150Views
2likes
0Comments