Alert.png The wiki is deprecated and due to be decommissioned by the end of September 2022.
The content is being migrated to other supports, new updates will be ignored and lost.
If needed you can get in touch with EGI SDIS team using operations @ egi.eu.

Difference between revisions of "Agenda-17-07-2017"

From EGIWiki
Jump to navigation Jump to search
 
(13 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{TOC right}}  
{{Template:Op menubar}} {{Template:Doc_menubar}} {{TOC_right}}
[[Category:Grid Operations Meetings]]


= General information  =
= General information  =
Line 14: Line 15:
* CMD-ONE dry run successful
* CMD-ONE dry run successful
** including products for OpenNebula 5 for CentOS7 (Ubuntu not requested by FedCloud)
** including products for OpenNebula 5 for CentOS7 (Ubuntu not requested by FedCloud)
* UMD 4.5 (June) in progress
** Staged-Rollout ongoing
* UMD 4.5 (June, delayed to July) in progress
** WN and CREAM for C7
** WN and CREAM for C7
** ARGUS 1.7.2  
** ARGUS 1.7.2  
Line 26: Line 28:
= Operations  =
= Operations  =


== ARGO/SAM ==
== ARGO/SAM ==
 
<br>


== Testing FedCloud sites  ==
== Testing FedCloud sites  ==
Credits to Baptiste Grenier (EGI Operations). Using fedcloud.egi.eu, <span style="font-size:13px;color:#1155cc;font-weight:400;text-decoration:underline;font-family:'Arial';font-style:normal;">https://appdb.egi.eu/store/vappliance/egi.centos.6</span>, and <span style="font-size:13px;color:#1155cc;font-weight:400;text-decoration:underline;font-family:'Arial';font-style:normal;">https://github.com/EGI-Foundation/sscmon-occi</span> to execute the tests.<br>
{| width="1208" cellspacing="1" cellpadding="1" border="1"
|-
! scope="col" | Site
! scope="col" | Status
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">BEgrid-BELNET</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">CESGA</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">CESNET-MetaCloud</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">IISAS-FedCloud</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">IN2P3-IRES</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">INFN-CATANIA-STACK</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">INFN-PADOVA-STACK</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">RECAS-BARI</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">TR-FC1-ULAKBIM</span>
| OK
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">BIFI</span>
| errors about floating IP pool
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">CLOUDIFIN</span>
| no default network, some VAs not synced
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">CYFRONET-CLOUD</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">Closed ports on public IP. Using old version of OCCI-OS and OpenStack Juno, site upgrade in progress.
</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">HG-09-Okeanos-Cloud</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">cloudkeeper was installed, missing appliance. Site BDII updated but almost empty, hence very difficult to use.
</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">FZJ</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">Server unavailable (OCCI endpoint), upgrade of OS to mitaka and OOI ongoing with troubles, openstack image list fails (but openstack flavor list succeeds). Working from time to time, unstable. Downtime published in GOCDB. Waiting for site admin to confirm that upgrade is over and troubles were fixed.
</span>
|-
| 100IT
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">No default network, need to link the net1 network on VM creation</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">GoeGrid</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">On hold, reinstalling with ONE5 to use cloudkeeper with no downtime in GocDB, 9 GGUS tickets open.
</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">IFCA-LCG2</span>
| Cannot list networks.
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">SCAI</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">No more works manually and not with scripts as there is no default network and endpoint is Critical in ARGO, moving to cloudkeeper-OS</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">UPV-GRyCAP</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">Moved to cloudkeeper and to cloud-info-provider 0.8.3. Able to create VM manually, but it is not possible to link the public network, Carlos is working on it</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">IISAS-Nebula</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">site does not support fedcloud.egi.eu</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">IISAS-GPUCloud</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">GP-GPU-specific site, does not support fedcloud.egi.eu</span>
|-
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">NCG-INGRID-PT</span>
| <span style="font-size:13px;color:#000000;font-weight:400;text-decoration:none;font-family:'Arial';font-style:normal;">keystone v3 with OpenID Connect (experimental).
</span>
|-
| <br>
| <br>
|}


== Feedback from Helpdesk  ==
== Feedback from Helpdesk  ==
Line 126: Line 232:
***'''NGIs/ROCs please start discussing with sites and provide suggestions for the overall plan'''
***'''NGIs/ROCs please start discussing with sites and provide suggestions for the overall plan'''


== Decommissioning of dCache 2.10 and 2.13 ==
== Decommissioning of dCache 2.10 and 2.13 ==


* support for the '''dCache 2.10''' ended at December 2016, tickets opened by EGI Operations to track decommissioning
*support for the '''dCache 2.10''' ended at December 2016, tickets opened by EGI Operations to track decommissioning  
* dCache 2.13 decommissioning procedure started, in June the probes will get CRITICAL, '''support from dCache ends in July''', upgrades to be performed by August  
*dCache 2.13 decommissioning procedure started, in June the probes will get CRITICAL, '''support from dCache ends in July''', upgrades to be performed by August  
* please upgrade to 2.16, whose support ends on May 2018, or to 3.0
*please upgrade to 2.16, whose support ends on May 2018, or to 3.0  
** take care that the dCache team does not support the upgrade from 2.10 directly to 2.16; only 2.10-&gt;2.13 and 2.13-&gt;2.16 transitions are supported.  
**take care that the dCache team does not support the upgrade from 2.10 directly to 2.16; only 2.10-&gt;2.13 and 2.13-&gt;2.16 transitions are supported.  
* decommissioning campaign will be started by EGI Operations to monitor the upgrade of the dCache 2.13 instances and follow up with the NGIs/sites at the beginning of August
*decommissioning campaign will be started by EGI Operations to monitor the upgrade of the dCache 2.13 instances and follow up with the NGIs/sites '''at the beginning of August'''


== webdav probes in production  ==
== webdav probes in production  ==
Line 207: Line 313:
*The webdav service endpoint should be registered in GOC-DB for being properly monitored: the nagios probes are executed using the VO ops, so please ensure that the protocol is enabled for ops VO as well
*The webdav service endpoint should be registered in GOC-DB for being properly monitored: the nagios probes are executed using the VO ops, so please ensure that the protocol is enabled for ops VO as well
*the webdav probes are harmless: they are not in any critical profile, they don't raise any alarm in the operations dashboard, and the A/R figures are not affected. We need time and more sites for gathering statistics on their results before making them critical.
*the webdav probes are harmless: they are not in any critical profile, they don't raise any alarm in the operations dashboard, and the A/R figures are not affected. We need time and more sites for gathering statistics on their results before making them critical.


For registering on GOC-DB the webdav service endpoint, follow the [[HOWTO21]] in order to filling in the proper information. '''In particular''':
For registering on GOC-DB the webdav service endpoint, follow the [[HOWTO21]] in order to filling in the proper information. '''In particular''':
Line 235: Line 342:
== Next meeting  ==
== Next meeting  ==


*'''Aug 7th, 2017''' https://indico.egi.eu/indico/event/3351/
*'''Aug 7th, 2017''' https://indico.egi.eu/indico/event/3351/  
*do we move to '''Aug 21th, 2017? '''(previuos meeting is today, far enough)
*switching to '''GoToMeeting '''from next meeting on (cannot make it for today due to technical issues with the plugin)

Latest revision as of 14:25, 25 October 2017

Main EGI.eu operations services Support Documentation Tools Activities Performance Technology Catch-all Services Resource Allocation Security


Documentation menu: Home Manuals Procedures Training Other Contact For: VO managers Administrators


General information

Middleware

UMD/CMD

  • CMD-OS 1.1.2 (C7/Xenial) is out
    • CentOS7 (bdii-infoprovider 0.7.0, rOCCI client 4.3.8, APEL SSM 2.1.7, Infrastructure Manager 1.5.1, Site BDII 1.2.1, ooi 1.1.1, keystone-VOMS 9.0.4, cASO 1.1.0)
    • Ubuntu Xenial (bdii-infoprovider 0.7.0, rOCCI client 4.3.8, Infrastructure Manager 1.5.1, ooi 1.1.1, keystone-VOMS 9.0.4, cASO 1.1.0,
  • CMD-ONE dry run successful
    • including products for OpenNebula 5 for CentOS7 (Ubuntu not requested by FedCloud)
    • Staged-Rollout ongoing
  • UMD 4.5 (June, delayed to July) in progress
    • WN and CREAM for C7
    • ARGUS 1.7.2
    • APEL, DynaFed, XROOTD, dCache, QCG, ARC

Preview repository

Released on 2017-07-07:

  • Preview 1.13.0 AppDB info (sl6): ARC 15.03 u15, dCache 2.16.40, frontier-squid 3.5.24-3.1, LCGdm-dav 0.18.2, QCG Broker 4.2.0
  • Preview 2.13.0 AppDB info (CentOS 7): ARC 15.03 u15, ARGUS 1.7.1, CREAM 1.16.5, dCache 3.1.9 & SRM client 3.0.11, frontier-squid 3.5.24-3.1, LCGdm-dav 0.18.2, QCG Broker 4.2.0

Operations

ARGO/SAM


Testing FedCloud sites

Credits to Baptiste Grenier (EGI Operations). Using fedcloud.egi.eu, https://appdb.egi.eu/store/vappliance/egi.centos.6, and https://github.com/EGI-Foundation/sscmon-occi to execute the tests.

Site Status
BEgrid-BELNET OK
CESGA OK
CESNET-MetaCloud OK
IISAS-FedCloud OK
IN2P3-IRES OK
INFN-CATANIA-STACK OK
INFN-PADOVA-STACK OK
RECAS-BARI OK
TR-FC1-ULAKBIM OK
BIFI errors about floating IP pool
CLOUDIFIN no default network, some VAs not synced
CYFRONET-CLOUD Closed ports on public IP. Using old version of OCCI-OS and OpenStack Juno, site upgrade in progress.



HG-09-Okeanos-Cloud cloudkeeper was installed, missing appliance. Site BDII updated but almost empty, hence very difficult to use.



FZJ Server unavailable (OCCI endpoint), upgrade of OS to mitaka and OOI ongoing with troubles, openstack image list fails (but openstack flavor list succeeds). Working from time to time, unstable. Downtime published in GOCDB. Waiting for site admin to confirm that upgrade is over and troubles were fixed.



100IT No default network, need to link the net1 network on VM creation
GoeGrid On hold, reinstalling with ONE5 to use cloudkeeper with no downtime in GocDB, 9 GGUS tickets open.



IFCA-LCG2 Cannot list networks.
SCAI No more works manually and not with scripts as there is no default network and endpoint is Critical in ARGO, moving to cloudkeeper-OS
UPV-GRyCAP Moved to cloudkeeper and to cloud-info-provider 0.8.3. Able to create VM manually, but it is not possible to link the public network, Carlos is working on it
IISAS-Nebula site does not support fedcloud.egi.eu
IISAS-GPUCloud GP-GPU-specific site, does not support fedcloud.egi.eu
NCG-INGRID-PT keystone v3 with OpenID Connect (experimental).





Feedback from Helpdesk

yearly review of the information registered into GOC-DB

2017-04-07

On a yearly basis, the information registered into GOC-DB need to be verified. NGIs and RCs have been asked to check them. In particular:

  1. NGI managers should review the people registered and the roles assigned to them, and in particular check the following information:
    • E-Mail
    • ROD E-Mail
    • Security E-Mail
NGI Managers should also review the status of the "not certified" RCs, in according to the RC Status Workflow;
  1. RCs administrators should review the people registered and the roles assigned to them, and in particular check the following information:
    • E-Mail
    • telephone numbers
    • CSIRT E-Mail
RC administrators should also review the information related to the registered service endpoints.

The process should be completed by Apr 28th.

To track the process, a series of tickets have been opened.

2017-07-13 UPDATE:

  • AfricaArabia, NGI_IT, NGI_NL still checking;
  • no feedback yet by: NGI_DE;
  • status of NGI_IL Operations centre is uncertain: we are verifying it

Monthly Availability/Reliability

suspended sites: ZA-UCT-ICTS, MY-USM-GCL, UA-NSCMBR

Decommissioning EMI WMS

As discussed at the February and April/May OMBs, we are making plans for decommissioning the WMS and moving to DIRAC.

NGIs provided WMS usage statistics, and in general the usage is relatively low, mainly for local testing

Moderate usage by few VOs:

  • NGI_CZ: eli-beams.eu
  • NGI_GRNET: see
  • NGI_IT: calet.org, compchem, theophys, virgo
  • NGI_PL: gaussian, vo.plgrid.pl, vo.nedm.cyfronet
  • NGI_UK: mice, t2k.org

EGI contacted these VOs to agree a smooth migration of their activities to DIRAC, only some of them replied till now:

  • compchem is already testing DIRAC
  • calet.org: discussing with the users the migration to DIRAC. Interested in a webinar on DIRAC.
  • mice: enabled on the GridPP DIRAC server

We need the VO feedback for better defining technical details and timeline:

  • NGIs with VOs using WMS (not necessarily limited to the VOs above), please contact them to ensure that these VOs have a back-up plan.

WMS servers can be decommissioned as soon as the supported VOs do not need them any more. The proposal is:

  • WMS will be removed from production starting from 1st January 2018.
    • VOs have 5 months to find alternatives or migrate to DIRAC
  • Considering that this is not an update, the decommission can be performed in few weeks.

IPv6 readiness plans

    • Resource Centres: assess the IPv6 readiness of the site infrastructure (real machines, cloud managers)
      • NGIs/ROCs please start discussing with sites and provide suggestions for the overall plan

Decommissioning of dCache 2.10 and 2.13

  • support for the dCache 2.10 ended at December 2016, tickets opened by EGI Operations to track decommissioning
  • dCache 2.13 decommissioning procedure started, in June the probes will get CRITICAL, support from dCache ends in July, upgrades to be performed by August
  • please upgrade to 2.16, whose support ends on May 2018, or to 3.0
    • take care that the dCache team does not support the upgrade from 2.10 directly to 2.16; only 2.10->2.13 and 2.13->2.16 transitions are supported.
  • decommissioning campaign will be started by EGI Operations to monitor the upgrade of the dCache 2.13 instances and follow up with the NGIs/sites at the beginning of August

webdav probes in production

The webdav probes have been deployed in production. Some sites were already contacted for enabling the monitoring of their webdav endpoints:

Site Host GGUSID note
CYFRONET-LCG2 se01.grid.cyfronet.pl https://ggus.eu/index.php?mode=ticket_info&ticket_id=128325 SOLVED
GRIF node12.datagrid.cea.fr https://ggus.eu/index.php?mode=ticket_info&ticket_id=128329
IGI-BOLOGNA darkstorm.cnaf.infn.it https://ggus.eu/index.php?mode=ticket_info&ticket_id=127930 SOLVED
INFN-T1 removed https://ggus.eu/index.php?mode=ticket_info&ticket_id=128326 SOLVED
NCG-INGRID-PT gftp01.ncg.ingrid.pt https://ggus.eu/index.php?mode=ticket_info&ticket_id=128327 SOLVED
UKI-NORTHGRID-LIV-HEP hepgrid11.ph.liv.ac.uk https://ggus.eu/index.php?mode=ticket_info&ticket_id=128328 SOLVED
egee.irb.hr lorienmaster.irb.hr

link to nagios results: https://argo-mon.egi.eu/nagios/cgi-bin/status.cgi?servicegroup=SERVICE_webdav&style=detail

Several sites are publishing in the BDII the webdav endpoints:

  • AsiaPacific: JP-KEK-CRC-02
  • NGI_AEGIS: AEGIS01-IPB-SCL
  • NGI_CH: UNIGE-DPNC, UNIBE-LHEP
  • NGI_DE: UNI-SIEGEN-HEP
  • NGI_GRNET: GR-01-AUTH, HG-03-AUTH
  • NGI_HR: egee.irb.hr, egee.srce.hr
  • NGI_IBERGRID: CETA-GRID, NCG-INGRID-PT
  • NGI_FRANCE: GRIF-IPNO, GRIF-LAL, GRIF-LPNHE
  • NGI_IL: IL-TAU-HEP, TECHNION-HEP, WEIZMANN-LCG2
  • NGI_IT: IGI-BOLOGNA, INFN-GENOVA, INFN-MILANO-ATLASC, INFN-ROMA3, INFN-T1
  • NGI_PL: CYFRONET-LCG2, WUT
  • NGI_RO: NIHAM
  • NGI_UK: UKI-NORTHGRID-LIV-HEP, UKI-NORTHGRID-MAN-HEP
  • ROC_CANADA: CA-MCGILL-CLUMEQ-T2

Checked with:

$ ldapsearch -x -LLL -H ldap://egee-bdii.cnaf.infn.it:2170 -b "GLUE2GroupID=grid,o=glue" '(&(objectClass=GLUE2Endpoint)(GLUE2EndpointInterfaceName=webdav))' GLUE2EndpointImplementationName GLUE2EndpointURL

ACTIONS for NGIs and sites: The Operations Centres are asked to verify with their sites if the webdav protocol is really (intentional) enabled on their storage elements (if not, the information should be removed from the BDII), and report to EGI Operations

  • The webdav service endpoint should be registered in GOC-DB for being properly monitored: the nagios probes are executed using the VO ops, so please ensure that the protocol is enabled for ops VO as well
  • the webdav probes are harmless: they are not in any critical profile, they don't raise any alarm in the operations dashboard, and the A/R figures are not affected. We need time and more sites for gathering statistics on their results before making them critical.


For registering on GOC-DB the webdav service endpoint, follow the HOWTO21 in order to filling in the proper information. In particular:

Testing of the storage accounting

As discussed during the January OMB, the APEL team would need one site per NGI for testing the storage accounting. The eligible sites are the ones providing either dCache or DPM storage elements.

More information can be found in the following wiki: https://wiki.egi.eu/wiki/APEL/Storage

List of sites available for test.

2017-07-14 UPDATE (more details in the June OMB presentation):

  • 31 sites are sending storage accounting data (only from dCache and DPM SEs); The data validation is on-going.
  • It was created a new service type on GOC-DB, eu.egi.storage.accounting, which will be used for:
    • authorising the site/SE to publish the accounting data
    • making the site/SE appear in the portal
    • monitoring that the accounting data are regularly published
  • by September we should be ready for a wide roll-out of storage accounting
    • detailed instructions for the sites will be circulated

AOB

Next meeting

  • Aug 7th, 2017 https://indico.egi.eu/indico/event/3351/
  • do we move to Aug 21th, 2017? (previuos meeting is today, far enough)
  • switching to GoToMeeting from next meeting on (cannot make it for today due to technical issues with the plugin)