Difference between revisions of "Operations Bulletin Latest"

From GridPP Wiki
Jump to: navigation, search
()
()
Line 437: Line 437:
  
 
===== =====
 
===== =====
 +
'''Tuesday 25th April'''
 +
* One EGI CSIRT advisory issued under [TLP:AMBER] regarding poorly configured Docker engine (13/4/2017)
 +
 
'''Tuesday 11th April'''
 
'''Tuesday 11th April'''
 
* One EGI SVG advisory issued under [TLP:AMBER] regarding Openstack
 
* One EGI SVG advisory issued under [TLP:AMBER] regarding Openstack
Line 445: Line 448:
 
** For developers - SWAMP software assurance toolset [https://wiki.geant.org/download/attachments/63963422/SiB-1March2017.pdf?version=1&modificationDate=1490611818146&api=v2]  
 
** For developers - SWAMP software assurance toolset [https://wiki.geant.org/download/attachments/63963422/SiB-1March2017.pdf?version=1&modificationDate=1490611818146&api=v2]  
 
** For operations - Incident response in the Federated identity world - Sirtfi [https://wiki.geant.org/download/attachments/63963422/20160327%20Incident%20Response%20Identity%20Federations.pptx?version=2&modificationDate=1490606503314&api=v2]
 
** For operations - Incident response in the Federated identity world - Sirtfi [https://wiki.geant.org/download/attachments/63963422/20160327%20Incident%20Response%20Identity%20Federations.pptx?version=2&modificationDate=1490606503314&api=v2]
* UK Security Team meeting this afternoon.  
+
* UK Security Team meeting this afternoon.
 
+
'''Tuesday 28th March'''
+
* The following advisories were issued under [TLP:AMBER], check the advisory for details and if you might be affected -
+
** 1 High risk vulnerability advisory issued by EGI SVG potentially affecting a number of services.
+
** 1 Critical risk vulnerability advisory issued by EGI SVG affecting 1 service.
+
** 1 Security Incident reported via the EGI CSIRT, not in the UK.
+
* Updated IGTF distribution 1.82 available - updated CA root certificates [https://dist.igtf.net/distribution/igtf/current/]
+
* WISE - Security for collaborating infrastructures meeting this week [https://wiki.geant.org/display/WISE/WISE+Home]
+
 
+
  
 
|}
 
|}

Revision as of 07:59, 25 April 2017

Bulletin archive


Week commencing Monday 24th April 2017
Task Areas
General updates

Tuesday 25th April


Tuesday 18th April

  • RHEL/SL 6.9 openssl update fall-out.
  • Enabling support for the DUNE VO (joining up requests).


Tuesday 4th April

  • Minutes of Monday's operations meeting are available.
  • This year's WLCG workshop will be held June 19-22 in Manchester: Agenda. Registration.
  • Andrew L: Advance warning: FTS3 deprecation of SOAP (4th April CERN and soon at RAL)
    • people should no longer use the very old glite-transfer-* commands and instead use fts-transfer-* commands
    • when specifying an FTS server use port 8446 rather than 8443.
    • This move presents a problem for non-LHC VOs ... RAL options to postpone?
  • Tier-2 reports for Q117 being generated. Please support their timely availability!
  • ATLAS monitoring page usage survey. Their quick links page.
  • There was an EGI OMB last Thursday | Agenda.
  • cvmfs repo for the gridpp VO - status and plans for regional VOs to move
  • There is a pre-GDB next Tuesday with an agenda focused on "Collaborating with other communities".
  • The GDB next week has the following agenda and an afternoon discussion on containers.

Monday 27th March

  • EGI Operations Broadcast - March 2017
  • HSF Workshop on Visualization software - starting Tuesday March 28, 16hrs - BE Auditorium (6-2-024)

Tuesday 21st March

  • Status of EMI and UMD UI/WN in CVMFS grid.cern.ch ... and planning CentOS7.
  • GridPP VO CVMFS discussion. (Naming?).
  • Minutes of Monday's WLCG ops meeting are available.
  • Reminder of the survey (table) for GridPP38.
  • The final T2 reliability and availability reports for February 2017 are available.
  • Steve asks about ARGO monitoring for the UK and ARC site greyness. File a ticket.
  • Simon points out there is a GridPP DIRAC users list at Imperial connected with support.
  • On 16th: Many ATLAS sites were set in a test mode because of "no SE/SURL protocols defined for output". AGIS had the wrong update values.
  • VAPOR application v2.2 is now online. Map |Faulty Resources | Figures - CPU & Storage split | API.


WLCG Operations Coordination - AgendasWiki Page

Tuesday 4th April

  • The next ops coordination meeting is this Thursday 6th April. Agenda. The theme is HTCondor accounting work at PIC.
    • Any T1 or T2 issues to be discussed?

Monday 20th March

Monday 6th March

  • There was an ops coordination meeting on Thursday 2nd March - agenda | Minutes.
  • The overview talks were: Mid-SLAs | Machine Job Features.
  • The main summary items:
    • Lessons learned from ATLAS tape usage tests. Follow up via FTS steering group. Will share experience with other experiments.
    • "Mid SLA" resources. During the next months accumulate experience at CERN (providing such resources) and in experiments (using such resources). Review accumulated experience after a couple of months and decide what we need to do in terms of tagging, accounting, etc...
    • MJF deployment is not as successful as desired. Find help (at least temporary) for deployment campaign concentrating on the LHCb sites. See whether this task would become more important considering outcome of the benchmarking discussion.
    • In order to avoid inconsistencies in the naming of the service types along the WLCG IS chain (GocDB, OIM, SAM, experiment-specific systems like Dirac), there will be agreement between representatives from OSG, EGI and GocDB team and IS evolution task force on the policy for introducing of the new service types.
    • The next WLCG ops coordination meeting will be on 6th April.
Tier-1 - Status Page

Tuesday 25th April A reminder that there is a weekly Tier-1 experiment liaison meeting. Notes from the last meeting here

  • There have been problems with the LHCb Castor instance since the SRM upgrade on the 23rd March. The SRM change was reverted on the 12th April (shortly before Easter weekend). One bug has been identified that is fixed in Castor 2.1.16. Work is now underway to test this Castor version with the aim of moving too it as soon as possible.
  • On the 19th April, Atlas reached a milestone of having 1PB of data in ECHO
  • The number of batch jobs running in SL6 containers on worker nodes running SL7 is being ramped up.
  • The IPv6 addressing scheme for the tier1 has been agreed and is in place. We hope to start offering services via IPv6 in the near future. The Perfsonar nodes on our production network are already running using IPv6.
Storage & Data Management - Agendas/Minutes

Wednesday 19 Apr

  • Case for (re)testing CVMFS for T2s? (and non-LHC VOs?)
  • Other storage related issues arising from use of containers?

Wednesday 12 Apr

  • Musings on the outcome of last week's GridPP meeting
  • Discussion of which of a selection of coming events to aim to do something for. If that makes sense, gramatically.

Wednesday 15 Feb

  • Space tokens! Use them!
  • Leafed through interesting topics (technology permitting) from the CS3 workshop

Wednesday 08 Feb

  • More on accounting (again)
Tier-2 Evolution - GridPP JIRA

Tuesday 21 March 2017


Tuesday 14 March 2017

Tuesday 28 February 2017

  • ATLAS jobs now running on Birmingham Vac VMs.
  • LHCb is now running its standard DIRAC VMs on Google Compute Engine using GridPP's Vcycle.

Tuesday 21 February 2017

  • Some ALICE production jobs running at Birmingham and Oxford in Vac VMs.

Tuesday 14 February 2017

  • Vac installed at Birmingham. Running LHCb production jobs. Preparing to run ALICE VMs.
  • ALICE VMs switched to using GSI proxies internally rather than host cert/keys.


Accounting - UK Grid Metrics HEPSPEC06 Atlas Dashboard HS06

Monday 16th January

  • The discussion topic for next week will be accounting comparisons. Please note Alessandra's comments last week.

Monday 14th November

  • Alessandra has written an FAQ to extract numbers from ATLAS and APEL avoiding the SSB.

Monday 26th September

  • A problem with the APEL Pub and Sync tests developed last Tuesday and was resolved on Wednesday. This had a temporary impact on the accounting portal.
Documentation - KeyDocs

Tue 7th Mar

I want to get rid of following stale docs...

  • Ten Easy Network Questions
  • GridPP Answers to 10 Easy Network Questions
  • SL5 status
  • Glasgow Middleware Operations Logbook
  • London Tier2 Shares
  • 23rd June 2010 Special Topic: NGS Technical Roadmap - Pete Gronbech
  • SAM availability: Monthly summary table
  • Transfer Tests Birmingham Endpoints
  • EVO Tips and Tricks
  • BaBar: bbrbsub270

Monday 13th Feb

  • Please check the keydocs page. Would all owners please review their pages and prepare a short note on how they will bring things up-to-date in the coming months. This will be discussed at a core ops meeting (poll to be circulated shortly).
  • There are several EGI operations document updates out for review. Please make comments to Jeremy by 20th Febraury for inclusion in the UK feedback:


Monday 30th January

The fusion VO has been removed from GridPP Approved VOs.

Monday 9th January

  • Tom put these together:
    • A snapshot of the GridPP UserGuide is now available as an offline document in the Zenodo repository:
    • ...and the v1.0 release of the LaTeX code used to compile it is here.
    • There are some minor differences (mainly hyperlink-related) to the online version [1], which has also had a v1.0 release here.


Tue 22nd Nov

  • More on Accounting audit tools

The process for ARC, Toque and VAC is now documented here.

https://github.com/gridpp/audit/wiki


General note

See the worst KeyDocs list for documents needing review now and the names of the responsible people.

Interoperation - EGI ops agendas

Tuesday 21st March

Monday 13th February

  • There was an ops meeting on 13th February. Agenda
    • frontier-squid-3 in UMD 4.4.0 - changes to config
    • Assess IPv6 readiness:
      • Resource Centres: assess the IPv6 readiness of the site infrastructure (real machines, cloud managers)
      • NGIs/ROCs please start discussing with sites and provide suggestions for the overall plan
    • Decommissioning of dCache 2.10
    • Discussed stale ARGO results; being discussed with Product Teams.

Monday 16th January

  • There was an ops meeting on 9th January. Agenda.


Monday 7th November

  • There was an EGI Ops meeting today: agenda
  • UMD 3.14.5 released today
    • VOMS 3.5.0, which makes RFC proxies the default for voms-proxy-init
  • UMD 4.3.0 'October' release, release candidate ready, to be released by end of this week, including:
    • ARC, GFAL2, XROOT, Davix, dCache, ARGUS, Gridsite, edg-mkgrid, umd-release for CentOS7
  • please start using UMD4/SL6 or UMD4/CentOS7 instead of UMD3/SL6 & please don't use anymore EMI3
    • (think there may be a campaign around this soon)
  • Downtimes due to the vulnerability CVE-2016-5195: request an A/R recomputation
    • All the resource centres that were affected by the vulnerability CVE-2016-5195 and that declared a downtime between 2016-10-20 16:00 UTC and 2016-10-31 18:00 UTC are invited to request a recomputation of A/R figures for the days in which the downtime was ongoing.
Monitoring - Links MyWLCG

Monday 13th Febraury

  • This category is pretty much inactive. Are there any topics under "monitoring" that anyone wants reported at this ops meeting? If not we will remove this section from the regular updates area of the bulletin and just leave the main links.

Tuesday 1st December


Tuesday 16th June

  • F Melaccio & D Crooks decided to add a FAQs section devoted to common monitoring issues under the monitoring page.
  • Feedback welcome.


On-duty - Dashboard ROD rota

Monday 24th April


20th March

  • Another quiet week. One ticket to Oxford and a new availablility ticket to Glasgow. Other than that, most of the tickets have been there for a couple of weeks.

27th February

  • Forwarded two tickets (RALPP and ECDF) to the monitoring team, as this looks like more ARC shenanigans.
  • There's also a bunch of low availability tickets which clog up the system.


Rollout Status WLCG Baseline

Monday 13th February

  • Please can we hear something from Raul and Sam (or others contributing to the middleware readiness work) about news in this area at the ops meeting next week? Thank you.
  • Does anyone want specific questions in this area tackled in a roundtable discussion?

Tuesday 7th December

  • Raul reports: validation of site BDII on Centos 7 done.

Tuesday 15th September

Tuesday 12th May

  • MW Readiness WG meeting Wed May 6th at 4pm. Attended by Raul, Matt, Sam and Jeremy.


References


Security - Incident Procedure Policies Rota

Tuesday 25th April

  • One EGI CSIRT advisory issued under [TLP:AMBER] regarding poorly configured Docker engine (13/4/2017)

Tuesday 11th April

  • One EGI SVG advisory issued under [TLP:AMBER] regarding Openstack

Tuesday 4th April

  • No advisories or incidents to report
  • Last week's WISE workshop [1], not new but ...
    • For developers - SWAMP software assurance toolset [2]
    • For operations - Incident response in the Federated identity world - Sirtfi [3]
  • UK Security Team meeting this afternoon.


Services - PerfSonar production dashboard |PerfSonar development dashboard | GridPP VOMS

- This includes notifying of (inter)national services that will have an outage in the coming weeks or will be impacted by work elsewhere. (Cross-check the Tier-1 update).

Monday 6th March

  • Last week it was noted that some ATLAS RIPE probes (the USB ones) have had hardware errors. If you need a replacement and RIPE are slow to respond then contact Jeremy.
  • Is anyone running any tests with their RIPE probe?

Tuesday 14th February

  • The development dashboard is now operational again. However the production dashboard is not currently displaying latency results (OSG ticket submitted).
  • Birmingham pS host had lost its entire network connection and both Lancaster's hosts their IPv6 connection. Durham results are incomplete, GGUS ticket submitted (#126587).

Tuesday 25th October

  • Duncan has recreated the UK perfSONAR mesh. Link here!


Tickets

Monday 24th April 2017, 14.30 GMT
36 Open UK tickets this week.

NGI
127588 (7/4)
As mentioned before Easter, this is a yearly review of the information in the gocdb. The deadline for this is Friday. Perhaps a swift wiki-table is in order to check the status? The really important security contact information has been check this year thanks to the security challenge, so we're good on one front at least. In progress (10/4)

126808 (24/2)
WMS usage ticket - not sure where we want to leave this and I don't think much will happen on it for a while. In progress (20/3)

SUSSEX
122772 (11/6/16)
Atlas webdav/xroot access ticket. I understand thanks to Dan's efforts there was some pre-gridpp progress on this. Can we have what was achieved "in writing" please! On Hold (6/3)

127767 (18/4)
ROD availability ticket from last week - not noticed by the site yet by the looks of it. Assigned (18/4)

127768 (18/4)
The likely cause of the low availability, a ROD "out of date CA test" ticket. Thanks to Daniela for providing some wisdom. In Progress (24/4)

125503 (9/12/16)
Sno+ file access ticket. A strategy was developed a while ago to try to tackle this, any further plans/problems? In progress (30/1)

RALPP
127555 (7/4)
A availability ticket due to the arc monitoring shenanigans. Chris has on held it as per the tradition. On hold (7/4)

OXFORD
127778 (19/4)
A CMS ticket, but I'm not sure it should have been assigned to the site. Some jobs that will never go anywhere somehow ended up at Oxford. Not the site's problem, but the conversation about Oxford's status within CMS production should be interesting. In progress (19/4)

BRISTOL
126865 (28/2)
A CMS related ticket from Daniela, regarding ipv6 phedex transfers from Bristol's SE. There's a question left hanging on the ticket regarding the IPv6 status of the cern gfal2 tools. Anyone have any knowledge about this? In progress (31/3)

127783 (19/4)
Some CMS sam test failures have re-cropped up. Although the link shows all green (or at least sickly yellowy-green) for me so perhaps this can be closed again? Reopened (21/4)

126864 (28/2)
Request to enable LZ at Bristol. How this progressing? In progress (31/3)

BIRMINGHAM
127319 (27/3)
Another Availability ticket, checking the argo link the Easter period has been full of Unknown's for Birmingham, so I didn't on hold the ticket yet. In progress (In progress (3/3)

GLASGOW
124052 (25/9/16)
The cursed ARC job publishing ticket- Gareth braved the bad mojo haunting this ticket to provide an update, hoping to be free of it by the end of May. On hold (4/4)

DURHAM
127832 (21/4)
LHCB job submission to Durham seems to be failing. Hope it's not all gone horribly wrong. Assigned (21/4)

SHEFFIELD
127766 (18/4)
Another ROD availability ticket, tests have turned green (after the website was fixed) so just needs to be waited out. On hold (19/4)

MANCHESTER
127644 (10/4)
After a brief config mishap some icecube GPU jobs ran on some non-GPU nodes. Alessandra pounced on the issue, and asks if the ticket can be closed. Waiting for reply (20/4)

QMUL
126261 (30/1)
One of the QM ces not working for biomed, at last check the problem persists- probably due to the other woes befalling ce04. In progress (4/4)

127445 (1/4)
A biomed ticket for the other CE, which is also still not working for biomed. In progress (24/4)

126650 (15/2)
cern@school pilot problems. The initial problem was fixed, but one of the CEs is still playing up after getting into a bad state running out of disk. In progress (19/4)

127551 (6/4)
A Sno+ ticket, where Sno+ jobs were having problems competing with atlas for disk space on the nodes - compounded by jobs not cleaning up properly. Not limited to QM (Lancaster had the same issue), but these issues seem to have passed - for now. In progress (19/4)

127352 (28/3)
An Icecube ticket regarding job problems on a GPU node. Dan is taking this node out to use for centos7 testing, which the VO was happy with. This ticket is in limbo now, either needing on holding or solving. In progress (31/3)

127144 (15/3)
LHCB having trouble with ce04 also - with the CE's recent problems I don't know if things would be looking better on this front? Waiting fore reply (31/3)

BRUNEL
127518 (5/4)
The last of the CMS tickets asking to remove rfio from site's storage.xml. Raul will deal with this when he's back in the UK, but thanks Daniela for the kind offer of help/being a scapegoat. Are you back yet Raul? In progress (12/4)

127117 (13/3)
A CMS request to upgrade the spacemon client, which Raul didn't get round to before his hols. Could do with an update when you can get to it. In progress (14/3)

THE IMPERIAL CLOUD (which is sadly not a Star Wars Super-Weapon)
127620 (9/4)
David from snoplus has noticed jobs landing and failing on the Imperial Cloud, and has asked what the heck it is (but he asked more politely). Simon has spotted the problems and disabled the cloud site so it won't eat more jobs, hoping to fix it this week. On Hold (12/4)

100IT have 2 tickets:
127827
127539
But they're being handled fine.

THE TIER ONE
127597 (7/4)
A request from CMS to test xrootd and networking performance at RAL after noticing a large drop in job efficiency when access data offsite. Andrew L spotted that this was likely due to using "lazy download", and this is being removed from across the WNs but it is noted that this is needed for CEPH... In progress (12/4)

127240 (21/3)
Another CMS ticket, for a Run2 staging test. Tests were done, Sebastian from CMS has asked for access to some site monitoring plots so they can compare what they see to the "real values". In progress (12/4)

126905 (2/3)
Finishing off commissioning the solidexperiment.org cvmfs server. Just needs one last check user-side to make sure that the statum replication took and job's a good'un. Waiting for reply (21/4)

127388 (29/3)
An lhcb user is having trouble accessing files at RAL. The user has provided details of how they are trying to access the files using root - it's been donkey's years since I've mucked about with root - is the problem simply that castor won't accept xroot connections like this? In progress (20/4)

127612 (8/4)
An LHCB ticket where all the RAL CEs rejected LHCB jobs. There were some issues for a while, but things petered out over Easter. Any news? Hopefully all is well. In progress (12/4)

127598 (7/4)
A CMS ticket from Chris, regarding a cunning plan that was likely set in motion at GridPP38 - the setting up of a UK XrootD Redirector at RAL to pair with the one at Imperial. Likely stalled due to Easter, but Simon's added some notes on their config changes. In progress (19/4)

124876 (7/11/16)
ROD gridftp tests failing for CEPH, due to a problem with the tests. Alaistair poked the ticket to fix the tests (https://www.ggus.org/index.php?mode=ticket_info&ticket_id=125026) - these fixes haven't been implemented yet. On hold (1/1)

117683 (18/11/15)
Castor Glue2 publishing. As expected slow progress here due to the lack of effort available, but the last update was promising. On hold (2/3)

Tools - MyEGI Nagios

29th November 2016

LSST monitoring is available through vo-nagios

https://vo-nagios.physics.ox.ac.uk/nagios/cgi-bin/status.cgi?servicegroup=lsst&style=detail

13th September 2016


VOs - GridPP VOMS VO IDs Approved VO table
Site Updates

Date



Meeting Summaries
Project Management Board - MembersMinutes Quarterly Reports

Empty

GridPP ops meeting - Agendas Actions Core Tasks

Empty


RAL Tier-1 Experiment Liaison Meeting (Wednesday 13:30) Agenda Meeting takes place on Vidyo.

Highlights from this meeting are now included in the Tier1 report farther up this page.

WLCG Grid Deployment Board - Agendas MB agendas

Empty



NGI UK - Homepage CA

Empty

Events
UK ATLAS - Shifter view News & Links

Atlas S&C week 2-6 Feb 2015

Production

• Prodsys-2 in production since Dec 1st

• Deployment has not been transparent , many issued has been solved, the grid is filled again

• MC15 is expected to start soon, waiting for physics validations, evgen testing is underway and close to finalised.. Simulation expected to be broadly similar to MC14, no blockers expected.

Rucio

• Rucio in production since Dec 1st and is ready for LHC RUN-2. Some fields need improvements, including transfer and deletion agents, documentation and monitoring.

Rucio dumps available.

Dark data cleaning

files declaration . Only Only DDM ops can issue lost files declaration for now, cloud support needs to fill a ticket.

• Webdav panda functional tests with Hammercloud are ongoing

Monitoring

Main page

DDM Accounting

space

Deletion

ASAP

• ASAP (ATLAS Site Availability Performance) in place. Every 3 months the T2s sites performing BELOW 80% are reported to the International Computing Board.


UK CMS

Empty

UK LHCb

Empty

UK OTHER
  • N/A
To note

  • N/A