GDB March 07 2007 - 1 User-Level, VOMS Groups and Roles Dave Kant CCLRC, e-Science Centre.

Slides:



Advertisements
Similar presentations
LCG WLCG Operations John Gordon, CCLRC GridPP18 Glasgow 21 March 2007.
Advertisements

Andrew McNab - Manchester HEP - 2 May 2002 Testbed and Authorisation EU DataGrid Testbed 1 Job Lifecycle Software releases Authorisation at your site Grid/Web.
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
Accounting in LCG Dave Kant & John Gordon CCLRC, e-Science Centre.
Accounting Update Dave Kant Grid Deployment Board Nov 2007.
Accounting in EGEE … and beyond John Gordon and David Kant CCLRC, e-Science Centre.
Storage Accounting John Gordon, STFC GDB June 2012.
LCG Accounting Reporting Update John Gordon, CCLRC LCG Grid Deployment Board 5 th April 2006.
OSG Services at Tier2 Centers Rob Gardner University of Chicago WLCG Tier2 Workshop CERN June 12-14, 2006.
Dave Kant Grid Monitoring and Accounting Dave Kant CCLRC e-Science Centre, UK HEPiX at Brookhaven 18 th – 22 nd Oct 2004.
Summary of Accounting Discussion at the GDB in Bologna Dave Kant CCLRC, e-Science Centre.
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
A.Guarise – F.Rosso 1 Enabling Grids for E-sciencE INFSO-RI Comprehensive Accounting Views on large computing farms. Andrea Guarise & Felice Rosso.
Monitoring in EGEE EGEE/SEEGRID Summer School 2006, Budapest Judit Novak, CERN Piotr Nyczyk, CERN Valentin Vidic, CERN/RBI.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
The huge amount of resources available in the Grids, and the necessity to have the most up-to-date experimental software deployed in all the sites within.
Grid User Management System Gabriele Carcassi HEPIX October 2004.
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
Maarten Litmaath (CERN), GDB meeting, CERN, 2006/02/08 VOMS deployment Extent of VOMS usage in LCG-2 –Node types gLite 3.0 Issues Conclusions.
Accounting in LCG Dave Kant CCLRC, e-Science Centre.
Grid Operations Centre LCG Accounting Trevor Daniels, John Gordon GDB 8 Mar 2004.
Some Title from the Headrer and Footer, 19 April Overview Requirements Current Design Work in Progress.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
Overview of Privilege Project at Fermilab (compilation of multiple talks and documents written by various authors) Tanya Levshina.
WLCG Grid Deployment Board, CERN 11 June 2008 Storage Update Flavia Donno CERN/IT.
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
LCG Storage Accounting John Gordon CCLRC – RAL LCG Grid Deployment Board September 2006.
LCG Accounting John Gordon Grid Deployment Board 13 th January 2004.
Glite. Architecture Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed.
Storage Accounting John Gordon, STFC GDB March 2013.
HLRmon accounting portal DGAS (Distributed Grid Accounting System) sensors collect accounting information at site level. Site data are sent to site or.
INFSO-RI Enabling Grids for E-sciencE ARDA Experiment Dashboard Ricardo Rocha (ARDA – CERN) on behalf of the Dashboard Team.
Recent improvements in HLRmon, an accounting portal suitable for national Grids Enrico Fattibene (speaker), Andrea Cristofori, Luciano Gaido, Paolo Veronesi.
Accounting Update John Gordon and Stuart Pullinger January 2014 GDB.
Accounting non-Grid Use John Gordon Management Board 7/6/2007.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks APEL CPU Accounting in the EGEE/WLCG infrastructure.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Accounting Old and New Requirements John Gordon Revised 22/3/12.
LCG WLCG Accounting: Update, Issues, and Plans John Gordon RAL Management Board, 19 December 2006.
LCG Accounting Update John Gordon, CCLRC-RAL WLCG Workshop, CERN 24/1/2007 LCG.
INFSO-RI Enabling Grids for E-sciencE Policy management and fair share in gLite Andrea Guarise HPDC 2006 Paris June 19th, 2006.
LCG User Level Accounting John Gordon CCLRC-RAL LCG Grid Deployment Board October 2006.
GridView - A Monitoring & Visualization tool for LCG Rajesh Kalmady, Phool Chand, Kislay Bhatt, D. D. Sonvane, Kumar Vaibhav B.A.R.C. BARC-CERN/LCG Meeting.
Accounting in LCG/EGEE Can We Gauge Grid Usage via RBs? Dave Kant CCLRC, e-Science Centre.
LCG Accounting/Reporting John Gordon, STFC MB November 9 th 2011.
Accounting in LCG Dave Kant CCLRC, e-Science Centre.
APEL Accounting Update Dave Kant CCLRC, e-Science Centre.
HLRmon accounting portal The accounting layout A. Cristofori 1, E. Fattibene 1, L. Gaido 2, P. Veronesi 1 INFN-CNAF Bologna (Italy) 1, INFN-Torino Torino.
Site Authorization Service Local Resource Authorization Service (VOX Project) Vijay Sekhri Tanya Levshina Fermilab.
INFSO-RI Enabling Grids for E-sciencE DGAS, current status & plans Andrea Guarise EGEE JRA1 All Hands Meeting Plzen July 11th, 2006.
Placeholder ES 1 CERN IT EGI Technical Forum, Experiment Support group AAI usage, issues and wishes for WLCG Maarten Litmaath CERN.
Status of gLite-3.0 deployment and uptake Ian Bird CERN IT LCG-LHCC Referees Meeting 29 th January 2007.
John Gordon Grid Accounting Update John Gordon (for Dave Kant) CCLRC e-Science Centre, UK LCG Grid Deployment Board NIKHEF, October.
Accounting in LCG Dave Kant CCLRC, e-Science Centre.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Accounting Portal Pablo Rey, Javier Lopez.
TIFR, Mumbai, India, Feb 13-17, GridView - A Grid Monitoring and Visualization Tool Rajesh Kalmady, Digamber Sonvane, Kislay Bhatt, Phool Chand,
HLRmon Enrico Fattibene INFN-CNAF 1EGI-TF Lyon, France19-23 September 2011.
DGAS Distributed Grid Accounting System INFN Workshop /05/1009, Palau Giuseppe Patania Andrea Guarise 6/18/20161.
APEL Architecture Alison Packer. Overview Grid jobs accounting tool APEL Client software - installed in sites (CEs, gLite- APEL node) APEL Server accepts.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Storage Accounting John Gordon, STFC OMB August 2013.
Using HLRmon for advanced visualization of resource usage Enrico Fattibene INFN - CNAF ISCG 2010 – Taipei March 11 th, 2010.
LCG Accounting Update John Gordon, CCLRC-RAL 10/1/2007.
Enabling Grids for E-sciencE INFN Workshop – May 7-11 Rimini 1 Grid Accounting Status at INFN Riccardo Brunetti INFN-TORINO.
John Gordon EMI TF and EGI CF March 2012 Accounting Workshop.
Accounting Update John Gordon. Outline Multicore CPU Accounting Developments Cloud Accounting Storage Accounting Miscellaneous.
Accounting Update Dave Kant, John Gordon RAL Javier Lopez, Pablo Rey Mayo CESGA.
GDB July APEL Accounting Summary Dave Kant Rutherford Appleton Laboratory.
WLCG Resources Reporting
Accounting at the T1/T2 Sites of the Italian Grid
Cristina del Cano Novales STFC - RAL
Presentation transcript:

GDB March User-Level, VOMS Groups and Roles Dave Kant CCLRC, e-Science Centre

GDB March Outline  User-Level Accounting  Group and Role Accounting  Accounting Portal  Storage Accounting  Summary

GDB March User-Level Accounting  LCG JSPG User-Level Accounting Data Policy –Discusses the treatment of accounting data –Topics covered  User Consent, What is stored and where? Who has Access rights? For what purposes? Confidentiality –Document in progress  APEL Feature –Sites can switch on User DN encryption when publishing data –1024-bit RSA public/private key-pair to maintain confidentiality  Request: –Policy document isn’t official yet; we ask the Tier-1s publish encrypted User DNs. –18 sites have already done this:- CESGA-EGEE, CIEMAT-LCG2, CNB-LCG2, CSCS-LCG2, FZK-LCG2, IFAE, IFCA-LCG2, INFN-TORINO, ITEP,JINR-LCG2, LIP-Lisbon, RAL-LCG2, RU-SPbSU, TAU-LCG2, UB-LCG2, UKI-NORTHGRID-LANCS-HEP, UPV-GRyCAP, USC-LCG2

GDB March Group and Role Accounting  Requirement –Define how CPU resources should be allocated to different activities  60% of CPU to production at site X for the next three months –Measure what has been delivered  In last quarter of 2006, site X delivered Y% production to VO_1  What needs to be in place? –Users should get a VOMS proxy before job submisision –Extract the users VOMS proxy from the CE –Include this information in the job accounting record  Implementation –On LCG-CE via the Grid Accounting Mapping File (Patch #898)  Maps grid credentials to local batch resources –Users FQAN Chain –LCMAPS will map the user according to the VOMS FQANs in the proxy –APEL Patch #1047 in Certification  Tests performed against Patch #898 (CERN, CNAF)  We take the whole chain (can be quite long)  Group and Role determined from PRIMARY part of UserFQAN chain

GDB March What FQANs have been published?  Activity Related –Breakdown of usage according to activity and VO /cms/Role=production/Capability=NULL /lhcb/lcgprod/Role=NULL/Capability=NULL /atlas/Role=lcgadmin/Capability=NULL  Chain with primary and secondary components. –No activity information in the primary –Can only account usage to the VO /dteam/Role=NULL/Capability=NULL;/dteam/cern/Role =NULL/Capability=NULL

GDB March Test Record  What you see in R-GMA GlobalJobID: UserDN: *APEL V.0.2* P7IMQIkPndWbCpeecX/iqqBhqYdsOp+DZl+9+o9GQ3BPXx8uzcHUqZOJQSq8F6KIczAvxSw+I8x8 lwHJ6l9kxIyYbLTEkELI3Ul77I6zhzT90zUDLEpgsQ+0XY3tPRGwu5uG/ibtcWxefOtvZoM6FWwf 8yZmv8yLpjmNkMxZOtI= UserFQAN: /dteam/Role=NULL/Capability=NULL;/dteam/cern/Role=NULL/Capability=NULL; ExecutingCE: lxb2034.cern.ch:2119/jobmanager-lcgpbs-dteam

GDB March Is User FQAN Confidential?  User FQAN Chain readable in R-GMA by anyone with an IGTF approved certificate.  Should we encrypt this information?  If yes, can explore two options. –Encrypt only the primary FQAN  Throw away the secondary/tertiary parts …  Easy to implement. –Encrypt the whole chain  More complicated, because the FQAN Chain length can be very long and encryption is limited by the length of the public key.  RGMA schema change results in accounting data in two archivers …

GDB March Data Life Cycle  Site Publish  Migration –Extract from R-GMA –Send data to offline Database  Off-line Data Processing –Decrypt UserDN –Extract Group and Role from UserFQAN chain  Off-line Aggregation –Build summaries of data: –Site-Level, VO-level, User- Level, intra-VO Offline DB RGMA MySQL HotCopy HotCopyInsert (Every Hour) From Site to Portal Desirable to refresh the data shown on the portal at frequent intervals Aim for hourly updates

GDB March Portal  Accounting Portal –Access Right according to the “Actor Model” –Five Actors:  Users, VO-Resources Manager, VO-Member, Site-Admin GOC Admin  Three are implemented via DN proxy and ACLs  VO-Member access requires the VOMS proxy information. –How do we do this via the web?  Display Features –Build Resource statistics as a function of User and FQAN –How much CPU consumed by User X at Site Y –Top Ten Users in a VO –How much production work done by VO X at Site Y

GDB March VO Resource Manager  Table shows CPU, WCT and Job Eff. of the Top 10 Anonymised Users  Breakdown of Usage: DN / VO / Group / Role

GDB March  OSG –Deployment of Gratia accounting system across the CMS and ATLAS tier 1 and 2 centers. –Expect monthly summaries.  DGAS –Validating sites after the deployment of Patch #898 –Publish job records from T1 and T2’s daily  Comparison between CERN and APEL –Found a large discrepancies in usage numbers which was traced to a bug in multiple CE support in APEL. –Implemented a bug fix. –Repeat the test for the February 2007 dataset. Other Accounting Issues/Status

GDB March Storage Accounting  Display of Storage Information published by GIPs into the information system.  Query top-level BDII, write data to MySQL, process the data and build RRD graphs  Used and Allocated, Disk and Tape at the VO level  Visualisation of Storage Used and Allocated per VO for Disk and Tape  No breakdown of these numbers at a deeper level –Group/Role –File Transactions (Uploads, downloads) –Protocols

GDB March Select Resources via a Tree Select time interval (last year, last month, last week, last day) Select VOs, SEArchitecture

GDB March CSV dump of current Used and Allocated storage

GDB March Other Storage Accounting Plans and Issues  Enhance the LHC view of storage resources –Tier-1 tree  Extend breakdown per site to the RRD graphs  To show AverageUsage, AverageAllocated per Month per VO per LHC Tier1. –Example: Ral-LCG2-ALICE use 50TB tape in the first week of Jan, and then deleted the data.  How do we get data from OSG?  Bring the Storage and CPU reporting together into a single Portal.

GDB March Summary  User level accounting is deployed and many sites are publishing. T1s are encouraged to deploy.  This is not sufficient for the role/group based accounting that VOs have requested.  New release of APEL in certification; together with the accounting mapping log file, FQAN accounting is possible.  Storage Accounting Visualisation tools displaying Used and Allocated per VO; LHC view is needed