Download presentation
Presentation is loading. Please wait.
Published byBeverley Pope Modified over 6 years ago
1
Windows in BE-CO Terminal Servers, VirtualPCs, Consoles
Luigi Gallerani – Pablo Pinés León – Enzo Genuardi BE-CO-IN 28 September 2017
2
Windows in BE-CO? Lots of Controls Applications only run on Windows: They need Windows OS Experts on piquet for cryogenics, cooling, vacuum, transfer lines, RF, power converters etc. need a platform to access and intervene quickly on TN equipment. Specific pre-configured software is used by multiple non-expert computer users: They need Windows Terminal Servers PLC experts, operators and many different users need Windows Virtual PCs to program their devices. Some VPCs are in PLC control sets: They need trusted Windows VPCs Lots of Java developers prefer to run Eclipse on Windows: They need trusted Windows VPCs TIOP, PS OP and general operators: They need Windows Consoles in the CCC Being responsible for the TN Infrastructure, it is our job to ensure that functionality and performance are adequate and that the Windows infrastructure is properly patched and does not become a security threat. We manage the Windows installations of TN and TN Trusted machines and in the CCC ….. This amounts to more than 400 BE-CO Windows Machines!
3
Some applications requiring Windows and the TN
Passerelle BE-OP PS Island Isolde PCREX, WebNavigator BE-OP (Isolde, SPS) WinCC OA BE-ICS Hardware card win drivers TE-EPC POPS cards Labview / Rade TE-ABT, BE-BI, EN-STI TIM Train Matlab/Mathematica BE-RF cavity controls and studies Schneider Twido TE-CRG PLC Programming Siemens Step7, TIAPortal TE-CRG PLC Programming SQLDev + Benthic BE-CO CCDB 32bit app/drivers BE-BI PLC bit shifter Matrox BE-CO Vistar distribution Vacuum Expert TE-VSC PLC Supervision … Eclipse, TortoiseSVN, HPGL viewer, NFS Access via Samba…
4
Windows TS/VPC as a Technical Platform
For many technical experts (approx~300), TS and VPCs are the only place where they can run critical Windows applications that require access to TN devices (PLC) Piquet experts need fast access from home or from their offices. They expect the Windows TS and some VPCs to be always available. Cluster for HA and no stops during TS Redundant critical VPCs Reference contact for each system, to ensure all the applications are properly configured and installed Large investment in the current configuration to make it stable Example screenshot from a Win2008 R2 TN Terminal Server Cluster. Expert Applications can be launched directly or using the CCM
5
Windows Infrastructure maintained by BE-CO-IN
GPN TN Piquet/Remote Intervention and running expert applications 70 Dedicated TN terminal server in clusters cerntscryo, cerntsEL, cerntsICE… General Purpose Terminal Server cerntsbegp Common applications e.g. TIMBER, CCM… 4 OPENSTACK Matrox encoders for Vistar ICE “emergency” TS TN only 3 TN servers cerntsbews, icetn Special applications non compatible with TS multi-user architecture i.e. PLC development/programming Windows Virtual Machines cwe-513-vmw* cwe-513-vow* 278 56 Administrative Consoles Technical Consoles Control Rooms TIOP + Passerelle + Operators Total : 411
6
Load Balancer cerntscryo
~70 Terminal Servers cerntsbe# Rdesktop Persistent Session 93 ACTIVE 94 All VIRTUAL Openstack nodes Load Balancer cerntscryo xfreerdp 95 108 DRAIN Ha-Proxy Load balancer, persistent session Since 2016 no cluster interruption during TS interventions 3 cerntsICE EN-ICE BE-ICS Scada WinCC 1 cerntsbe17 Collimators EN-STI, 1 cerntsbe05 LinRF Piquet Labview 4 cerntsgcs Gas GSC Experts experiment 3 cerntsRF BE-RF Labview and Mathlab 2 cerntsbeTIM Tim Train Control EN-STI 2 cerntsiceTN Emergency TN only TS EN-ICE 2 cerntsNA62 1 cerntsbews Matrox Video Distribution +dev nodes new WinCC Versions 6 cerntsCRYO BE-ICS TE-CRG 5 cerntsEL BE-ICS 4 cerntscv Cooling Ventilation BE-ICE 12 cernts-ABT/ABT2 & abtwincc01 TE-ABT 4 cerntsvac2016 & cerntsvac2008 TE-VSC 4 cerntsmpe Interlock system TE-MPE 4 cerntsepc Power Converter TE-EPC 4 bits04/bitsdev04 BE-BI 2 cerntsbegp BE-CO BE-OP General Purpose
7
~270 Openstack Windows VPCs
BE 133 TE 74 EN 44 Migrate Java developer to Linux where possible save ~60 win vpc Windows Virtual Machines are: cwe-513-vmw* cwe-513-vow*
8
TIOP Tech Consoles, Power Meter SCADA, CCC Lighting and curtains
Technical consoles: Passerelle, POPS, Siemens WebNavigator… Administrative Consoles: Minimal Support for Windows after NICE Installation and hardware replacement
9
Windows Support Approximately 20 tickets/month for Windows vpc-support, as recorded in SNOW. (remaining 50% of VPCs are linux) Windows versions in production: Win7 32/64bit, Win10, 2008R2 Openstack VPC/TS Installations User access via Egroups/DFS Agreements with IT to ensure resources and issue resolution Software installation, regular interaction with Application Experts Security Patches during TS. Fast response for Security issues e.g. WannaCry ransomware, SMB v1 switch off… JWS for windows, Rdesktop wrapper Samba for NFS Access Tickets via SNOW and Wiki 40 2015 2016 2017 Support contacts: vpc-support for TS and VPC acc-adm-support for consoles
10
TS Evolutions and Plans
70 Win2008R2 Openstack Clusters OPENSTACK MIGRATION ~100 servers Rdesktop Wrapper 42 Win2008R2 cerntsbe* CVI HyperV WinCC OA 3.15 PHY To VIRT MIGRATION No downtime for Intervention JWS 20132008R2 25 Win2003 cerntsab* CLUSTER Load Balancer Win2012 or Win2016 migration? CMF Diamon Egroups CVIOpenstack New Monitoring Openstack Technology CVI HyperV Phase out Evaluation 2012 2013 2014 2015 2016 2017 2018 2019 2020 LS1 LS2
11
Virtual Machines and Consoles
Openstack ~270 VPC cwe-513-vow* OPENSTACK MIGRATION ~250 HyperV VPC cwe-513-vmw* SSD Disks SNOW MS to KVM Migration WinXP ~200 Physical consoles ~200 VPC WannaCry? consolidation 32->64bit Win10 64bit WinXP Eradication VPC automation Win7 64 bit 80 HyperV Win7 Win10 64bit Migration HyperV new hardware HyperV Phased out! Openstack Introduction ~50 Win7 consoles New Monitoring 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 LS1 LS2
12
Windows: Plans for LS2 WINDOWS VPC & Consoles TERMINAL SERVERS
End of Microsoft Support for Win7 & Win2008R th January 2020 TERMINAL SERVERS NOW: Stable, to be maintained until end LS2 Openstack Win2008 R2 All expert software to be validated for Win2012 or Win2016 Mainly driven by requirement and compatibility issues. Test/Validation has to start in 2018. Requirements need to be rediscussed More nodes for critical clusters #Target: scale up to ~100 servers …keep openstack technology WINDOWS VPC & Consoles NOW: Stable, to be maintained until end LS2 Openstack Win7 32bit 64bit Win10 64bit Eradicate Win7 32bit Reduce number of Windows VPCs required by moving CO & OP Eclipse developers to Linux Move to Win10 (or later) Reduce the support effort #Target: scale down to ~200 VPCs,keep openstack scale down to less than 40 consoles Next Windows OS version upgrade has to start in 2018 and MUST be completed before the end of LS2
13
Summary: Windows in BE-CO
Many Windows installations are critical for experts in BE, TE, EN. They need Terminal Servers, VirtualPCs and Technical Consoles to: Run Windows Expert Applications Connect to TN devices Perform piquet and interventions We support and maintain ~400 Windows machines on the TN and TN Trusted Infrastructure Win2008 R2, Win7 and Win10 are now in production. Mainly based on virtual Openstack The consolidation and evolution of the Windows infrastructure since 2012 shows the time scale involved for major infrastructure change Whilst keeping Openstack as the major hardware base solution, evaluation and validation of the next Windows OS has to start in 2018 and has to be completed before end LS2
14
Windows in BE-CO Terminal Servers, VirtualPCs, Consoles
Questions?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.