PRACE tools and solutions for federated service management

Slides:



Advertisements
Similar presentations
1 Ideas About the Future of HPC in Europe “The views expressed in this presentation are those of the author and do not necessarily reflect the views of.
Advertisements

EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
GILDA testbed GILDA Certification Authority GILDA Certification Authority User Support and Training Services in IGI IGI Site Administrators IGI Users IGI.
This document produced by Members of the Helix Nebula Partners and Consortium is licensed under a Creative Commons Attribution 3.0 Unported License. Permissions.
Bob Jones Technical Director CERN - August 2003 EGEE is proposed as a project to be funded by the European Union under contract IST
RI EGI-InSPIRE RI EGI Future activities Peter Solagna – EGI.eu.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
EGI-InSPIRE Steven Newhouse Interim EGI.eu Director EGI-InSPIRE Project Director Technical Director EGEE-III 1GDB - December 2009.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
PIC port d’informació científica EGEE – EGI Transition for WLCG in Spain M. Delfino, G. Merino, PIC Spanish Tier-1 WLCG CB 13-Nov-2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
NREN Trust and Identity Strategy Ann Harding, SWITCH Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
3rd Helix Nebula Workshop on Interoperability among e-Infrastructures and Commercial Clouds Carmela ASERO, EGI.eu 17 September 2013, Madrid
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Who doesn’t need to be WISE? Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
PRACE security Jules Wolfrat, SURFsara, The Netherlands April 25, 2013, EGI CSIRT meeting, Linköping, Sweden 10 May Montpellier.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI A pan-European Research Infrastructure supporting the digital European Research.
EGI-InSPIRE RI EGI Compute and Data Services for Open Access in H2020 Tiziana Ferrari Technical Director, EGI.eu
EGI-InSPIRE EGI-InSPIRE RI EGI strategy towards the Open Science Commons Tiziana Ferrari EGI-InSPIRE Director at EGI.eu.
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
EGI-InSPIRE RI An Introduction to European Grid Infrastructure (EGI) March An Introduction to the European Grid Infrastructure.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
Networks ∙ Services ∙ People Di4R Network. Services. People. GÉANT 28 th September, Krakow.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No EUDAT – the pan.
Break out group coordinator:
WISE Information Security for Collaborating E-Infrastructures
Introduction to AAI Services
Bob Jones EGEE Technical Director
Security Management Geant SIG-SIM – Alf Moens
Accessing the VI-SEEM infrastructure
WISE 2016 WISE: a global trust community where security experts share information and work together, creating collaboration among different e- infrastructures.
AENEAS WP6 first conference call
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Pasquale Pagano (CNR-ISTI) Project technical director
RCauth.eu CILogon-like service in EGI and the EOSC
GISELA & CHAIN Workshop Digital Cultural Heritage Network
AAI for a Collaborative Data Infrastructure
JRA3 Introduction Åke Edlund EGEE Security Head
INFN Computing Outlook The Bologna Initiative
eduTEAMS platform for collaboration Niels Van Dijk
Integrated Management System and Certification
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
GÉANT International Networking and Collaboration
EGI-Engage Engaging the EGI Community towards an Open Science Commons
Antonella Fresa Technical Coordinator
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Vision for Open Science
Connecting the European Grid Infrastructure to Research Communities
Solutions for federated services management EGI
DATA SPHINX & EUDAT Collaboration
Leigh Grundhoefer Indiana University
EGI Webinar - Introduction -
OIDC Federation for Infrastructures
AAI Architectures – current and future
RCauth.eu CILogon-like service in EGI and the EOSC
David Kelsey (STFC-RAL)
GISELA & CHAIN Workshop Digital Cultural Heritage Network
Federated Incident Response
EOSC-hub Contribution to the EOSC WGs
Presentation transcript:

PRACE tools and solutions for federated service management G. Erbacci, (CINECA and PRACE) Solutions for federated services management DI4R, Krakow 28-30 September 2016

Partnership for Advanced Computing in Europe PRACE is an international not-for-profit association under Belgian law, with its seat in Brussels. PRACE counts 25 members and 2 observers. The PRACE Hosting Members are France, Germany, Italy and Spain. PRACE is governed by the PRACE Council in which each member has a seat. The daily management of the association is delegated to the Board of Directors. PRACE is funded by its members as well as through a series of implementation projects supported by the European Commission.

4 Hosting Members offering core hours on 6 world-class machines JUQUEEN: IBM BlueGene/Q GAUSS/FZJ Jülich, Germany SuperMUC: IBM GAUSS/LRZ Garching, Germany Hazel Hen: Cray GAUSS/HLRS, Stuttgart, Germany CURIE: Bull Bullx GENCI/CEA Bruyères-le-Châtel, France MareNostrum: IBM BSC, Barcelona, Spain Marconi: Lenovo CINECA Bologna, Italy ~24 PFlop/s in total 11.4 thousand million core hours awarded since 2010 Tier-1 Systems 26 PRACE national sites distributed in 19 different Countries are operational > 17 PFlop/s in total Tier-1 fot Tier-0 services Apart Tier-1 for Tier-0 services, partners provide resources for DECI calls

Operation and Coordination of the Comprehensive common PRACE Operational Services - Common view of the PRACE infrastructure  more than a collection of individual systems - Responsible for both Tier-0 systems and Tier-1 systems providing Tier-1 for Tier-0 services Key assets of the operational infrastructure Infrastructure and common services Consolidated Operational Structure and Procedures PRACE Service Catalogue Implement operational Key Performance Indicators Security Forum to address security issues 4

PRACE Operational Coordination Team Matrix organisation for Operations Coordinated by WP6 Leader Task Leaders for the deployment of service categories: Networking, Data, Compute, AAA, User, Monitoring and Generic Site representatives are responsible for services at their site Bi-weekly telcos to discuss the status of services and sites and proposed or planned changes Changes are managed following a well defined procedure 5

Network services Current PRACE dedicated network A central L2/L3 switch in Frankfurt connecting • 14 partners via 10 Gb/s wavelength An IPSEC/GRE gateway in Frankfurt connecting • 5 partners with 1 Gb/s IPSEC/GRE tunnels • two partners via 1 Gb/s GÉANT-L2VPN connections Future PRACE dedicated network The infrastructure will be setup on the combined GÉANT / NRENs backbone providing a VPN between the PRACE partners (MDVPN service) All partners will be connected by VLANs through their normal NREN connection to this PRACEVPN At NRENs, where MDVPN solutions are not available, partners can be connected via an MDVPN-Proxy provided by GÉANT

Monitoring of PRACE-RI Services INCA no more supported by SDSC Replaced by ICINGA 2 monitoring tools Deployed the new middleware and corresponding user interface for gathering and presenting monitoring data New domain name: https://mon.prace-ri.eu/ 14 Hosts now connected 7 independent sets of services monitored Integration for all PRACE sites with valid user certificate gsissh.port – Host availability check based on gsissh port state gsissh.s2s – site to site gsissh connection check gridftp.s2s – site to site gridftp connection check software.version.tools Checks: software.version.libraries software.version.compilers software.version.shells 7

PRACE Security Forum  Coordinates security activities Define Policies and Procedures: to build “a trust model that allows smooth interoperation of the distributed PRACE services” Risk reviews: to define and maintain “An agreed list of software and protocols that are considered robust and secure enough to implement the minimal security requirements” Operational security: coordination of incident handling All PRACE operational partners are members of the Security Forum Collaboration with other large distributed computing infrastructures (EGI, EUDAT, XSEDE, WLCG, OSG) on policies and procedures Continues the representation of PRACE as relying party of EUGridPMA, the policy authority for trusted Certificate Authorities 8

Security collaboration Operational Security Collaboration with EGI CSIRT and EUDAT on sharing of information on incidents and vulnerabilities Accreditation of PRACE CSIRT team at Trusted Introducer service from GEANT ongoing AAI PRACE is Relying Party of EUGridPMA, the policy authority for the distribution of trusted Certificate Authorities PRACE is represented in the AARC (Authentication and Authorisation for Research and Collaboration) Project https://aarc-project.eu AARC objective: Enable the use of existing user credentials by the federation of existing Identity Providers and Service Providers WISE Information Security for Collaborating E-Infrastructures A trusted global framework where security experts can share information on different topics like risk management, experiences about certification process and threat intelligence Joint effort of GEANT SIG-ISM and SCI (EGI, EUDAT, HBP, PRACE, WLCG, XSEDE) 9

Data Collaboration with EUDAT MoU signed between PRACE and EUDAT Data pilots proposal analysis to identify use cases Get required changes on EUDAT services roadmap Data pilot identification: DECI Call 13: 5 pilots Deliver data management training to data pilots team ongoing work to make it available for PRACE users Gather detailed requirements Resources available for the project Detailed timelines Data Management Plan Technical constraints Implementation ongoing in close collaboration with EUDAT team Contacts with CoEs on Data Management Issues 10

Registered Data Domain Overview of the 4 pilots User scripts Workflows Module EUDAT Post processing Post processing User space Workspace Registered Data Domain Digital Object Data Data MD

Analysis and Development of Prototypal New Services - Provision of urgent computing services - Link with large-scale scientific instruments Link with the European Synchrotron Radiation Facility (CaSToRC) MIC-oriented Multithreading for HEP and Health Geant4 Computations (NCSA) HPC support for Extreme Light Infrastructure ELI-ALPS project (NIIF) Linking Next Generation Sequencers with PRACE (UiO) Large Synoptic Survey Telescope (CNRS) - Smart post processing tools including in-situ visualisation - Provision of repositories for European open source scientific libraries and applications, to promote wide adoption of European products Analyse and investigate the prototypal implementations at the pre-production level (involving first Tier-1 systems and then Tier-0 systems) Investigate the possible adoption in a next phase as production services 12