– n° 1 Review resources access policy, procedures, rules and challenges: The Italian experience and future challenges Antonia Ghiselli INFN-CNAF Workshop.

Slides:



Advertisements
Similar presentations
WP1 Grid Workload Management Massimo Sgaravatto INFN Padova
Advertisements

European, National and Local INFN GRID projects Leonardo Merola Dipartimento di Scienze Fisiche - Università di Napoli Federico II Istituto Nazionale di.
INFN & Globus activities Massimo Sgaravatto INFN Padova.
Lousy Introduction into SWITCHaai
Introduction of Grid Security
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Grid Tech Team Certificates, Monitoring, & Firewall September 15, 2003 Chiang Mai, Thailand Allan Doyle, NASA With the help of the entire Grid Tech Team.
An open source approach for grids Bob Jones CERN EU DataGrid Project Deputy Project Leader EU EGEE Designated Technical Director
1 ALICE Grid Status David Evans The University of Birmingham GridPP 14 th Collaboration Meeting Birmingham 6-7 Sept 2005.
GridPP July 2003Stefan StonjekSlide 1 SAM middleware components Stefan Stonjek University of Oxford 7 th GridPP Meeting 02 nd July 2003 Oxford.
29 June 2006 GridSite Andrew McNabwww.gridsite.org VOMS and VOs Andrew McNab University of Manchester.
Tony Doyle GridPP2 Proposal, BT Meeting, Imperial, 23 July 2003.
The National Grid Service and OGSA-DAI Mike Mineter
Current status of grids: the need for standards Mike Mineter TOE-NeSC, Edinburgh.
Andrew McNab - Manchester HEP - 22 April 2002 EU DataGrid Testbed EU DataGrid Software releases Testbed 1 Job Lifecycle Authorisation at your site More.
Forschungszentrum Karlsruhe in der Helmholtz-Gemeinschaft Torsten Antoni – LCG Operations Workshop, CERN 02-04/11/04 Global Grid User Support - GGUS -
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Andrew McNab - Manchester HEP - 2 May 2002 Testbed and Authorisation EU DataGrid Testbed 1 Job Lifecycle Software releases Authorisation at your site Grid/Web.
Work Package 1 Installation and Evaluation of the Globus Toolkit Massimo Sgaravatto INFN Padova.
INFN Testbed1 status L. Gaido, A. Ghiselli WP6 meeting CERN, 11 December 2001.
Deployment Team. Deployment –Central Management Team Takes care of the deployment of the release, certificates the sites and manages the grid services.
Alessandro Italiano INFN – CNAF 26/09/2003 1/5 Status of the INFN - EDG testbeds Alessandro Italiano 7th DataGrid Conference.
1 Software & Grid Middleware for Tier 2 Centers Rob Gardner Indiana University DOE/NSF Review of U.S. ATLAS and CMS Computing Projects Brookhaven National.
Collaborative Campus Grid - Practices and experiences in Leiden University Campus Grid (LUCGrid) Hui Li Feb 4, 2005.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Status of Globus activities within INFN Massimo Sgaravatto INFN Padova for the INFN Globus group
Workload Management Workpackage Massimo Sgaravatto INFN Padova.
Globus activities within INFN Massimo Sgaravatto INFN Padova for the INFN Globus group
Globus activities within INFN Massimo Sgaravatto INFN Padova for the INFN Globus group
Security Mechanisms The European DataGrid Project Team
Workload Management Massimo Sgaravatto INFN Padova.
INFN Testbed status report L. Gaido WP6 meeting CERN - October 30th, 2002.
08/11/908 WP2 e-NMR Grid deployment and operations Technical Review in Brussels, 8 th of December 2008 Marco Verlato.
The EDG Testbed Deployment Details The European DataGrid Project
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Pilot Test-bed Operations and Support Work.
DATAGRID Testbed release 0 Organization and working model F.Etienne, A.Ghiselli CNRS/IN2P3 – Marseille, INFN-CNAF Bologna DATAGRID Conference, 7-9 March.
OSG Services at Tier2 Centers Rob Gardner University of Chicago WLCG Tier2 Workshop CERN June 12-14, 2006.
OSG Middleware Roadmap Rob Gardner University of Chicago OSG / EGEE Operations Workshop CERN June 19-20, 2006.
Grid Workload Management & Condor Massimo Sgaravatto INFN Padova.
WNoDeS – Worker Nodes on Demand Service on EMI2 WNoDeS – Worker Nodes on Demand Service on EMI2 Local batch jobs can be run on both real and virtual execution.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
Certification and test activity IT ROC/CIC Deployment Team LCG WorkShop on Operations, CERN 2-4 Nov
THE INFN GRID PROJECT zScope: Study and develop a general INFN computing infrastructure, based on GRID technologies, to be validated (as first use case)
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
6/23/2005 R. GARDNER OSG Baseline Services 1 OSG Baseline Services In my talk I’d like to discuss two questions:  What capabilities are we aiming for.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Certification and test activity ROC/CIC Deployment Team EGEE-SA1 Conference, CNAF – Bologna 05 Oct
Condor on WAN D. Bortolotti - INFN Bologna T. Ferrari - INFN Cnaf A.Ghiselli - INFN Cnaf P.Mazzanti - INFN Bologna F. Prelz - INFN Milano F.Semeria - INFN.
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
6 march Building the INFN Grid Proposal outline a.ghiselli,l.luminari,m.sgaravatto,c.vistoli INFN Grid meeting, milano.
M. Cristina Vistoli EGEE SA1 Organization Meeting EGEE is proposed as a project funded by the European Union under contract IST Regional Operations.
INFN GRID Production Infrastructure Status and operation organization Cristina Vistoli Cnaf GDB Bologna, 11/10/2005.
Placeholder ES 1 CERN IT EGI Technical Forum, Experiment Support group AAI usage, issues and wishes for WLCG Maarten Litmaath CERN.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
EGEE is a project funded by the European Union under contract IST Service Activity 1 M.Cristina Vistoli ROC Coordinator All activity meeting,
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
II EGEE conference Den Haag November, ROC-CIC status in Italy
1/3/2006 Grid operations: structure and organization Cristina Vistoli INFN CNAF – Bologna - Italy.
OSG Status and Rob Gardner University of Chicago US ATLAS Tier2 Meeting Harvard University, August 17-18, 2006.
SAM architecture EGEE 07 Service Availability Monitor for the LHC experiments Simone Campana, Alessandro Di Girolamo, Nicolò Magini, Patricia Mendez Lorenzo,
DGAS Distributed Grid Accounting System INFN Workshop /05/1009, Palau Giuseppe Patania Andrea Guarise 6/18/20161.
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Services for Distributed e-Infrastructure Access Tiziana Ferrari on behalf.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) gLite Grid Introduction Salma Saber Electronic.
– n° 1 The Grid Production infrastructure Cristina Vistoli INFN CNAF.
Bob Jones EGEE Technical Director
Workload Management Workpackage
Regional Operations Centres Core infrastructure Centres
INFN – GRID status and activities
Computing Coordination in Italy
Presentation transcript:

– n° 1 Review resources access policy, procedures, rules and challenges: The Italian experience and future challenges Antonia Ghiselli INFN-CNAF Workshop on eInfrastructures (Internet and Grids) The new foundation for knowledge-base Societies Roma, Accademia Nazionale dei Lincei 9 December 2003

– n° 2 Outline u Introduction: n INFN resource sharing experience in the past u INFN-Grid and the national research grid n Goals and Results u Italian-Grid present status n Resource access mechanism and management tools n production service :Management, operations and support organization u International Grid scenario: LCG and EGEE n Challenges: Multi-grids for multi-VOs n Multi–grids :definitions and issues u Conclusions

– n° 3 INFN Computing Resource sharing in the past u 80th u RJE to INFN resources by INFN users u Resource sharing within a single distributed community (agreement between sites based on common convenience ) u Access policy agreement: n low priority queues during the night n Proxy logins mechanism TORINO PADOVA BARI PALERMO FIRENZE PAVIA GENOVA NAPOLI CAGLIARI TRIESTE ROMA PISA LAQUILA CATANIA BOLOGNA UDINE TRENTO PERUGIA LNF LNGS SASSARI LECCE LNS LNL SALERNO COSENZA S.Piero FERRARA PARMA CNAF ROMA2 MILANO Network user VAX/VMS cluster

– n° 4 INFN Computing Resource sharing in the past u 90th : Condor – INFN collaboration u Condor submit to INFN desktops and workstations u Users Resource sharing by INFN users u Access policy agreement: transparent access through CPU cycle stealing u ~300 machines, still up. TORINO PADOVA BARI PALERMO FIRENZE PAVIA GENOVA NAPOLI CAGLIARI TRIESTE ROMA PISA LAQUILA CATANIA BOLOGNA UDINE TRENTO PERUGIA LNF LNGS SASSARI LECCE LNS LNL SALERNO COSENZA S.Piero FERRARA PARMA CNAF ROMA2 MILANO Condor on WAN user

– n° 5 INFN Computing Resource sharing in the past u 1999 u Globus evaluation on WAN u Preliminary grid tests to the INFN-Grid project. TORINO PADOVA BARI PALERMO FIRENZE PAVIA GENOVA NAPOLI CAGLIARI TRIESTE ROMA PISA LAQUILA CATANIA BOLOGNA UDINE TRENTO PERUGIA LNF LNGS SASSARI LECCE LNS LNL SALERNO COSENZA S.Piero FERRARA PARMA CNAF ROMA2 MILANO Globus test user

– n° 6 INFN-Grid – goals (started at 2000) 1.To promote computational grid technologies research & development: Middleware 1.Through european and international projects 1. DataGrid, DataTAG, GLUE 2.Internal R&D activities 2.To implement the INFN grid infrastructure 1.National layout: 20 sites 3.To set up the national Grid Infrastructure for the national research community 1.FIRB: Grid.it 4.To participate to the implementation of the global Grid infrastructure for the LHC community 1.LCG: Tier1 and n*Tier2 5.To set up the eInfrastructure for the European Research Area 1.EU FP6: EGEE, IG-BIGEST

– n° 7 INFN-Grid – collaborations and results u EU - Datagrid : middleware development n WMS = job submission to the Grid, s CE and SE selection on the basis of job requirements specification, CPU load, CE-SE network conditions….. s Support for interactive jobs s Job checkpointing s Support for parallel jobs n Virtual Organization authentication and authorization service: VOMS (VO Membership Service, EDG/EDT) u EU – DataTAG : inter-grid Interoperability; EU-US collaboration within the GLUE framework n Grid Resources Information modeling: GLUE schema for Computing and Storage Element n Authorization/authentication service : VOMS-VOX integration (EDT-Fnal/CMS coll.) n First WorldGrid demo by nov.2002 within IST2002 and SC2002 events n Grid monitoring system based on GLUE schemas extension u Italian Grid.it : Grid management and support infrastructure n First tools in production n R&D on Resource Utilization Policies

– n° 8 TORINO PADOVA BARI PALERMO FIRENZE PAVIA GENOVA NAPOLI CAGLIARI TRIESTE ROMA PISA LAQUILA CATANIA BOLOGNA UDINE TRENTO PERUGIA LNF LNGS SASSARI LECCE LNS LNL SALERNO COSENZA S.Piero FERRARA PARMA CNAF ROMA2 INFN CMS T2 T2/3 Atlas T2 T2/3 Alice T2 T2/3 LHCb T2 T2/3 Babar VIRGO T2 (50-80 nodes) T3 (10-15 nodes) T1 Cnaf (~200) grid.it resources INFN (15-25 nodes) INAF (5-10 nodes) INGV (NEC computers), BIO (tbd) general purpose resources (8-15 nodes) Italian – Grid now ( Site/resource map) MILANO National Grid (Internet) Tot. ~ 600 nodes, next year ~ 1000

– n° 9 Resource access policies: Basic grid Authorization, authentication mechanisms Security characteristics: u Login via X.509 certificates from PKI/Certificate Authorities (CA) u Single sign-on. n The user is not required to repeat login procedures on the grid more than once. u Delegation. n Once a user has successfully identified himself with the Grid, it is possible for grid services to act on the behalf of the user as if they were the user himself. u User-based trust relationship. n All trust mechanism have the users credential at their core. s If a user wants to access farms A and B, there should be no need for farms A and B to trust each other. u Integrated with local systems. n The grid security mechanism does not supplant the local authorization mechanism, but instead work on top of it. u New membership concept: user belongs to a Virtual Organization

– n° 10 User: CA, VO and Resource Providers u Certificates are issued by a set of well-defined Certification Authorities (CAs). u Grant authorization at the VO level. n Each VO has its own VOMS server. n Contains (group / role / capabilities) triples for each member of the VO. u RPs evaluate authorization granted by VO to a user and map into local credentials to access resources Authentication Request C=IT/O=INFN /L=CNAF /CN=Pinco Palla /CN=proxy VOMS pseudo -cert CAs CERN CESNET CNRS GermanGrid Grid-Ireland INFN NIKHEF NorduGrid LIP Russian DataGrid DATAGRID-ES GridPP US–DOE Root CA US-DOE Sub CA CrossGrid cert-request cert signing cert/crl update Service VO-Manager (administer user membership, roles and Capabilities) Resource provider (map into Local credential) CAs: Policies and procedures mutual thrust agreement

– n° 11 Resource access policies u Authentication/ authorization: coded and tested procedures and tools u New issue : resource sharing according to Service Level Agreement n first trials based on grid level priority queues n ongoing research on more sophisticated mechanisms based on accounting + resource utilization Policies management Grid management organization VO-users (Requirements Support) Resource providers / AA/SLA VO-managers (VOMS and SLA Control) Certificate Authorities Grid deployment planning Grid operations / support Grid release

– n° 12 Italian Grid organization : integrates all the actors to provide flexible and efficient grid computing service Experiments (VOs) GRID resources Projects/owners Coordination Committee Management coordination Operations coordination VO representatives, Grid technical coord., Operations resp. grid experts Deployment Planning resource Policy application ……. Central management Team Site-man Resource admin GridService support VO admin New VO admin & support VO User support User Application Grid Resource Coordination Experimemt or research org. support release Configuration management Release distribution, documentation and porting Grid Technical coordination Service level Agreement Resource availability Shared resources VO admin Support for New VO-users

– n° 13 Tools for Operations u Software repository : release maintenance and distribution u Installation and configuration: n Configuration and automatic installation tools for the production infrastructure sites u Release validation: n Integration/customization of middleware release with application specific software u GRID Site and GRID service validation n Testing programs to verify and validate site and services installation u Site manager support u Grid services, VO services support and User support u Monitoring: GridICE s Based on automatic resource discovery from Grid Information System s Dynamic monitoring of Grid services, Grid resources and Jobs s Customized view for n Grid Operation Center operators, and site managers n VO-managers and Grid Users

– n° 14 0perations Portal u User documentation u site managers documentation u Software repository u Monitoring u Trouble tickets system u Knowledge base

– n° 15 Get your personal certificate

– n° 16 How to register to a VO

– n° 17 Monitoring tool

– n° 18 VO server atlas VO server atlas Grid services INGV-Bologna Computing Element Storage Element GIIS GRIS1 GRIS Information IndexResource Broker User Interface GRAM BDII VO server ingv WorkerNode...WorkerNode INFN-Padova Computing Element Storage Element GIIS GRIS1 GRIS GRAM WorkerNode...WorkerNode Grid Monitoring (GridICE) RLS

– n° 19 Grid Service monitoring

– n° 20 Outline u Introduction: n INFN resource sharing experience in the past u INFN-Grid and the national research grid n Goals and Results u Italian-Grid present status n Resource access mechanism and management tools n production service :Management, operations and support organization u International Grid scenario: LCG and EGEE n Challenges: Multi-grids for multi-VOs n Multi-grids: definitions and issues u Conclusions

– n° 21 International Grids scenario u LCG : First international experience on sharing resources between national grids n Grid Resource sharing issues : s how to guarantee the committed CPU power and satisfy local needs s How to guarantee priorities on VO-owned resources n Different needs for different VOs (HEP experiments plans) n Management coordination n Support coordination u EGEE : project based on national grids interconnection for an increased number of VOs n Not only middleware but mainly policies, service level agreement and management coordination issues n Need to find a model …..

– n° 22 Grid access challenge: Grid and Virtual Organisations u The real problem at the basis of the grid idea is how to implement a coordinated resource sharing on a large scale for a multi-institutional and dynamic virtual organisation. - u From computer sharing to grid sharing u From multiple users to multiple VOs (INFN experiments + others research organizations)

– n° 23 Challenges: Capability to provide multi- Grid computing service to Multi-VO Shared Resources and Services VO services and private resources VO services and private resources VO services Shared Resources and Services VO services and private resources Shared Resources and Services General scenario

– n° 24 u International VO is a multi-institutional distributed user community u Etherogeneous grid environment n Dedicated VO services n Dedicated resources n Shared resources with different policies EGEE Italian-Grid US-Grid same middleware shared resources VO-User VO-Virtual Grid on top of Multi-Grids same core services RB VOMS VO-monitoring Vo-RLS VO - Virtual Grid RB National and International Grids Coordinated Vo-support

– n° 25 multi - grids : definitions and issues u National grid identity and authority boundaries n A coordinated set of shared resources and services providing defined SLAs. n A single management and operations organization n Specific authorization, accounting and monitoring tools n A collection of user communities (VOs) u Federation of grids, what doest mean? n Cooperating grids to provide services to the common VOs? s Which level of transparency to VO-users? n Which Interoperability Requirements: s common core services? s common or interoperable collective services? (level of service interoperability) s Common Resource sharing policies? n What level of management/operations/support coordinations?

– n° 26 Conclusions u Production grid does not mean only efficient, stable services but also: n A topology/organizational model capable to provide the most flexible and efficient computing service to VO-users across multiple grids n Sufficient level of service quality (SLA) n Operations and support coordination n the minimum level of interoperability in order to allow VO virtual grid configuration across multiple grids