ELIXIR Virtual Organisation

From EGIWiki
Jump to: navigation, search
EGI-Engage Competence centres: Main page ELIXIR BBMRI MoBrain DARIAH LifeWatch EISCAT_3D EPOS Disaster Mitigation | EGI-Engage Knowledge Commons


Contents

Introduction

This Virtual Organisation (VO) contributes to the ELIXIR effort of building a sustainable European infrastructure for biological information, supporting life science research and its translation to medicine, agriculture, bioindustries and society. The Virtual Organisation constitutes the backbone of the ELIXIR Compute Platform and federates cloud compute and storage resources from ELIXIR and EGI providers.

The VO is currently open for the application piloting activities of the ELIXIR Competence Centre of the EGI-Engage H2020 project. Further information about the Competence Centre is available at https://wiki.egi.eu/wiki/CC-ELIXIR. Access to the VO resources is restricted to those working on the Competence Centre activities.

Cloud resources in the VO

Under finalisation: GRNET Under discussion: CSC, SURFsara

VO Managers

VO ID card in the EGI Operations Portal

Acceptable use policy

This Acceptable Use Policy applies to all members of the "vo.elixir-europe.org" Virtual Organisation, hereafter referred to as the VO, and the resources that members are able to access through the VO mechanism. Members of the EGI-Engage Competence Centre (https://wiki.egi.eu/wiki/CC-ELIXIR) owns and gives authority to this policy. This VO contributes to the ELIXIR effort of building a sustainable European infrastructure for biological information, supporting life science research and its translation to medicine, agriculture, bioindustries and society.

All VO members (users, managers, infrastructure providers) agree to be bound by this Acceptable Use Policy and to use the resources within the VO only in the furtherance of the stated goal of the VO. By registering in the VO as a user you shall be deemed to accept these conditions of use:

  1. You shall only use the VO services to perform work, or transmit or store data consistent with the stated goals, policies and conditions of use as defined by the body or bodies granting you access.
  2. You shall not use the VO for any unlawful purpose and not (attempt to) breach or circumvent any administrative or security controls.
  3. You shall respect intellectual property and confidentiality agreements.
  4. You shall protect your access credentials (e.g. passwords or private keys).
  5. You shall immediately report any known or suspected security breach or misuse of the VO or access credentials to abuse@egi.eu and to the relevant credential issuing authorities. (aai-contact@elixir-europe.org for ELIXIR accounts)
  6. You must notify the Registrar of any changes to your Registration Information.
  7. Use of the VO is at your own risk. There is no guarantee that the VO will be available at any time or that it will suit any purpose.
  8. Logged information, including information provided by you for registration purposes, is used for administrative, operational, accounting, monitoring and security purposes only. This information may be disclosed, via secured mechanisms, only for the same purposes and only as far as necessary to other organisations cooperating with the VO. Although efforts are made to maintain confidentiality, no guarantees are given.
  9. The access-granting bodies and Resource Providers are entitled to regulate, suspend or terminate your access, within their domain of authority, and you shall immediately comply with their instructions.
  10. You are liable for the consequences of you violating any of these conditions of use.
  11. The VO includes core services from the EGI e-infrastructure, thus other relevant EGI Policies and Procedures also apply to certain VO member groups. See these policies at http://www.egi.eu/about/policy/policies_procedures.html. (Policies tagged 'Users' apply to VO members, Policies tagged 'Infrastructure' apply to cloud providers)

Instruction for users

How to register

  1. Apply for VO membership at https://perun.elixir-czech.cz/registrar/?vo=elixir&group=EGI:vo.elixir-europe.org. You will be asked to create an account in ELIXIR, this is part of the registration process to the VO vo.elixir-europe.org.
  2. VO membership is received and evaluated by the VO Managers. Membership is currently restricted to those working in the ELIXIR Competence Centre application/service porting activities. Membership is expected to be broadened for other ELIXIR partners during 2017.
  3. You receive a notification email about the approval/rejection of your VO membership request.

How to use IaaS clouds

GUI: AppDB VMOps Dashboard

The EGI Application Database (AppDB) has recently evolved its functionalities from its catalogue of applications and virtual machines (VMs) to include a Graphical User Interface (GUI) to perform VM management operations on the distributed infrastructure.

Follow the VMOps Dashboard guide to get more information about its usage. You should be able to access it with login in via EGI CheckIn and selecting ELIXIR as identity provider.


API and CLI

Authentication

Resources available on the ELIXIR VO are accessed using X.509 proxy certificates with VOMS extensions (claims stating the membership of the user to the VO). You can use your ELIXIR identity to get one valid proxy by interacting with the CILogin service, currently there are two methods:

Once you have a proxy, you need to add the VOMS extensions. This can be done with voms-proxy-init with the --noregen option, for example (this copies first the proxy to the default location so you don't overwrite you original one):

cp your_proxy /tmp/x509up_u$(id -u)
chmod 600 /tmp/x509up_u$(id -u)
voms-proxy-init --noregen --rfc --voms vo.elixir-europe.org
OCCI and OpenStack access

IaaS cloud resources can expose two types of interfaces towards users (one or the other or both - depending on the cloud provider):

The user can interact with IaaS cloud resources via programming APIs and command line interfaces. Web dashboard access and Ansible orchestrator access are currently under development. The different access modes are summarized in the following table:

Open Standards interface OpenStack interface
API level access OCCI OpenStack Compute & Openstack Object Storage
Command Line access rOCCI-cli OpenStack CLI with VOMS authentication plugin
Web dashboard access AppDB VMOps Dashboard OpenStack Horizon (in tests)
Orchestrator access

Known options:

Known options:

  • Terraform (See below)

Check out these tutorial slides for a practical overview on how to use the IaaS resources using the rOCCI-cli. The slides cover the following topics:

Terraform orchestrator
Native OpenStack with EGI-OpenStack-Terraform

EGI provides a Terraform provider plugin that extends the builtin OpenStack provider of OpenStack with support for EGI AAI. Documentation on how to install and use is avaiable at Federated Cloud IaaS Orchestration page

Native OpenStack with tokens

Terraform has OpenStack support out of the box, however it does not support the X.509 based authentication of EGI. Instead you can use token based authentication. Tokens normally have a lifetime of 1 hour, if your deployment last longer you should check the EGI OpenStack Terraform plugin . For obtaining such token, you can follow these steps:

$ pip install python-openstackclient
$ pip install openstack-voms-auth-type
$ openstack --os-auth-url https://extcloud04.ebi.ac.uk:5000/v2.0 --os-auth-type v2voms \
            --os-x509-user-proxy /tmp/x509up_u1000 project list
+----------------------------------+--------+
| ID                               | Name   |
+----------------------------------+--------+
| e99a879a2d9e4b01b9152637c7bde4cb | elixir |
+----------------------------------+--------+ 

In case of getting SSL errors, check the CA Certificates information for OpenStack CLI

$ export OS_AUTH_TOKEN=$(openstack --os-auth-url https://extcloud04.ebi.ac.uk:5000/v2.0 \
                                   --os-auth-type v2voms \
                                   --os-x509-user-proxy /tmp/x509up_u1000 \
                                   --os-project-id e99a879a2d9e4b01b9152637c7bde4cb \
                                   token issue -c id -f value)

The OS_AUTH_TOKEN variable will be used by Terraform if available in the environment so you don't have to include in your .tf file.

Terraform with OCCI

There is a OCCI plugin for Terraform developed by CESNET and available at GitHub: https://github.com/cduongt/terraform/tree/occi.

Installation of this plugin requires compilation, check the README file for specific information. The plugin allows to manage VMs at OCCI endpoints


Joining the VO as IaaS cloud provider

The VO welcomes further IaaS cloud providers. D6.10 deliverable of the ELIXIR Competence Centre provides guidance for cloud providers on how can an IaaS cloud federate into the VO: https://documents.egi.eu/document/2841. Technology currently exist to federate OpenStack, OpenNebula and Synnefo cloud management framework based cloud sites.

Please write to <cc-elixir@mailman.egi.eu> to express your interest in joining the VO as a cloud provider.

Personal tools
Namespaces
Variants
Actions
Navigation
Toolbox
Print/export