General updates
|
Monday 21st November
- There is a GridPP Oversight Committee meeting this week.
- ATLAS - APEL accounting records comparison. Bug found in scripts for ARC and Torque.
- Marcus: xrdcp test for sites with DPM.
- The EGI Security Policy Group has produced a new revised and updated Top-Level Security Policy document. This brings the document up to date in terms of terminology and the current set of security policy documents, although one of our aims was also not to change more than we needed to (as the old document has served us well over many years!). Just to be clear – this policy applies to ALL current and future EGI infrastructures and services. The draft is available for comment until the OMB this Thursday.
- HEPSYSMAN 2017 dates to be confirmed soon.
- A new release of the Accounting Portal is ready for testing. Please test the new release for the next 2 weeks, and report via the tracking GGUS ticket any comment, bugs or suggestions for improvement.
- WLCG meeting (pre-GDB) on networking: 10 Jan 2017 at CERN. It will be the opportunity for LHC experiments, Network operators, WLCG service and site managers to meet and discuss the network requirements for the 3rd run of the LHC, planned for 2021-2023.
- The ARC brainstorming camp takes place 28th November - 2nd December.
Monday 14th November
Monday 7th November
|
WLCG Operations Coordination - AgendasWiki Page
|
Monday 7th November
Tuesday 25th October
Monday 3rd October
- There was a WLCG ops coordination meeting last week: Agenda. (Good to review in the ops meeting).
Monday 26th September
Monday 19th September
|
Tier-1 - Status Page
|
Tuesday 22nd November
A reminder that there is a weekly Tier-1 experiment liaison meeting. Notes from the last meeting here
- Owing to staff availability the upgrade of Castor to version 2.1.15 is being scheduled to take place in January.
- The migration of LHCb data from 'C' to 'D' tapes is underway. Some 10% (out of 1000) tapes migrated so far.
|
Storage & Data Management - Agendas/Minutes
|
Wednesday 16 Nov
- Some curious operational issues with failed xroot transfers - need more testing
- Duncan provided feedback from the JISC data transfer/campus networking workshop
Wednesday 09 Nov
- Storage related issues from hepsysman?
- ...
Wednesday 02 Nov
- Big picture: an attempt to explain where GridPP fits with other things such as "UKT0" and other infrastructures
Wednesday 26 Oct
- Feedback from WLCHEPiXG - don't miss it!
Wednesday 19 Oct
- Long list of loose ends - accounting and information systems, IPv6 surprising successes
|
Tier-2 Evolution - GridPP JIRA
|
Tuesday 15 November
- LHCb prototype of implementation of SAM probes for VMs done. Next step is to install the client script in the ETF/SAM test setup and test at multiple sites. Once finished, will address JIRA task GridPP-5
Tuesday 8 November
- Agreement with ETF about how to implement SAM probes for VMs, initially for LHCb. (We will use an external service provided by LHCb which the probes inside the VMs will report to.)
- Enabling DataCentred and StackHPC to run skatelescope.eu jobs in GridPP DIRAC VMs. i.e. two OpenStack providers with academic links.
- Vcycle at 1.0 prerelease, and now includes an Admin Guide.
Monday 24th October
- Started HTCvcm (HTCondor Vacuum VM), using ATLAS VMs as the starting point, to provide a generic HTCondor client VM that will connect to HTCondor pools run by the local site, experiments, or larger sites.
- Merging LHCb multipayload VM code into DIRAC Pilots repo.
- CernVM team updated CernVM to use kernel with fix for CVE-2016-5195 ("DirtyCOW")
|
Accounting - UK Grid Metrics HEPSPEC06 Atlas Dashboard HS06
|
Monday 14th November
- Alessandra has written an FAQ to extract numbers from ATLAS and APEL avoiding the SSB.
Monday 26th September
- A problem with the APEL Pub and Sync tests developed last Tuesday and was resolved on Wednesday. This had a temporary impact on the accounting portal.
|
Interoperation - EGI ops agendas
|
Monday 7th November
- There was an EGI Ops meeting today: agenda
- UMD 3.14.5 released today
- VOMS 3.5.0, which makes RFC proxies the default for voms-proxy-init
- UMD 4.3.0 'October' release, release candidate ready, to be released by end of this week, including:
- ARC, GFAL2, XROOT, Davix, dCache, ARGUS, Gridsite, edg-mkgrid, umd-release for CentOS7
- please start using UMD4/SL6 or UMD4/CentOS7 instead of UMD3/SL6 & please don't use anymore EMI3
- (think there may be a campaign around this soon)
- Downtimes due to the vulnerability CVE-2016-5195: request an A/R recomputation
- All the resource centres that were affected by the vulnerability CVE-2016-5195 and that declared a downtime between 2016-10-20 16:00 UTC and 2016-10-31 18:00 UTC are invited to request a recomputation of A/R figures for the days in which the downtime was ongoing.
- ARGO proposal to use GOCDB as the only source of topology information
- VAPOR 2.1 released in September, it replaces GSTAT
|
Monitoring - Links MyWLCG
|
Tuesday 1st December
Tuesday 16th June
- F Melaccio & D Crooks decided to add a FAQs section devoted to common monitoring issues under the monitoring page.
- Feedback welcome.
Tuesday 31st March
Monday 7th December
|
On-duty - Dashboard ROD rota
|
Monday 21st November
- EFDA low-availability (egi.eu.lowAvailability-/EFDA-JET@EFDA-JET_Availability) ticket finally removed!
Monday 14th November
- AM reports: End of two week shift. Various planned and unplanned downtimes. No grid-wide issues.
|
Rollout Status WLCG Baseline
|
Tuesday 7th December
- Raul reports: validation of site BDII on Centos 7 done.
Tuesday 15th September
Tuesday 12th May
- MW Readiness WG meeting Wed May 6th at 4pm. Attended by Raul, Matt, Sam and Jeremy.
References
|
Security - Incident Procedure Policies Rota
|
Monday 21st November
(1.79) on Monday, Nov 28th 2016.
- We are still seeing sites pop-up in the dashboard in relation to EGI-SVG-2016-11476.
Monday 14th November
Tuesday 8th November
- UK now showing clear of both CVE-2016-5195 (D.Cow) and EGI-SVG-2016-11476 (canl-c) on EGI monitoring.
- Talks at Hepsysman [1]
- Matt - soundings for interest in UK pakiti instance [2]
- David - overview of authentication using Federated Identities [3]
- GDB tomorrow (9th Nov) "Facilitating campus and grid security teams working on the same threats - Romain & Liviu" [4]
- EGI Security Policy Group last week [5] See SPG Drafts - [6]
- Top Level Security Policy
- EGI AAI CheckIn Service. Example of FIM - David's hepsysman talk, see also DI4R presentation [7]
- Policies around FedCloud - responsibility as root user etc.
The EGI security dashboard.
|
|
Services - PerfSonar production dashboard |PerfSonar development dashboard | GridPP VOMS
|
- This includes notifying of (inter)national services that will have an outage in the coming weeks or will be impacted by work elsewhere. (Cross-check the Tier-1 update).
Tuesday 25th October
- Duncan has recreated the UK perfSONAR mesh. Link here!
Monday 19th September
- UK eScience CA - certificate issuance problems. Jens reported that on 15th a partial but significant database corruption occurred on the signing system for the CA. Data was restored from (offline) backups but the rebuild was not correctly configured.
- A large number of site admins and other GridPP supporters appeared to be suspended from the dteam VO last week. “During a planned upgrade operation of VOMS service, a system malfunction occurred. As a result, some users received false notification about membership expiration. We are in contact with the software development team in order to identify the cause.”
|
Tickets
|
Monday 21st of November, 14.30 GMT
21 Open UK Tickets this week.
TIER 1
124606 (24/10)
This CMS consistency checking *really* needs an update - for three weeks the user has been requesting some news. Even a simple placation would be worth something at this point. In Progress (1/11)
124876 (7/11)
Nagios tests (not unexpectedly) failing against the RAL ECHO endpoint. At Daniela's advice Alastair filed a ticket to the monitoring group (125026). This ticket has been answered and closed, as Daniela asks did it help clarify things? On Hold (15/11)
124785 (2/11)
Another CMS ticket, about xroot server settings, that seems to be going a bit stale after being reopened. Has it simply escaped notice? Reopened (10/11)
BRISTOL
125083 (18/11)
FYI for the Bristol admins - this CMS waiting rool ticket might have snuck by when it came in last Friday. Assigned (18/11)
ATLAS XROOT/webdav tickets
122771 - Birmingham
122772 - Sussex
Both these tickets could do with an update, even if it's an unexciting "nothing to see here" one.
OXFORD
121924 (2/6)
Similarly this Oxford perfsonar performance ticket could do with some kind of update. On Hold (10/8)
LSST tickets
120351 - Glasgow
120350 - RAL
An FYI that Alessandra has started tackling sites that had LSST job problems again. After a spot of arc being arc at Glasgow both sites are able to run "hello world" jobs, ready for some proper testing.
AFS jobs
Just a suggestion, but sites who have decided not to close the AFS tickets assigned to them might want to put them On Hold.
|
Tools - MyEGI Nagios
|
13th September 2016
19th July
Both instances of gridppnagios at Oxford and Lancaster has been decommissioned.
12th July 2016
Central ARGO monitoring service has started from 1st of July. All grid resources are monitored through two Nagios instances
https://argo-mon.egi.eu/nagios/
https://argo-mon2.egi.eu/nagios/
It has same interface as gridppnagios. Alarms from these instances goes to Operational Dashboard
http://argo.egi.eu/ is a web interface which provides availability/reliability figures and site status. It is equivalent of old myegi interface with some additional services.
I am planning to decommission both instances of gridppnagios in coming weeks. I have stopped nagios and httpd on both instances so it will not send tests to grid resources in UK. I will also decommission storage-monit.physics.ox.ac.uk which was only used for storage replication test.
We will keep vo-nagios.physics.ox.ac.uk running until we get a replacement for vo-monitoring.
Monday 13th June
- Active Nagios instance moved to Lancaster
Tuesday 5th April 2016
Oxford had a scheduled network warning so active nagios instance was moved from Oxford to Lancaster. I am not planning to move it back to Oxford for the time being.
Tuesday 26th Jan 2016
One of the message broker was in downtime for almost three days. Nagios probes picks up a random message broker and failover is not working so a lot of ops jobs hanged for long time. Its a known issue and unlikely to be fixed as SAM Nagios is in its last leg. Monitoring is moving to ARGO and many things are not clear at the moment.
Monday 30th November
- The SAM/ARGO team has created a document describing Availability reliability calculation in ARGO tool.
|
VOs - GridPP VOMS VO IDs Approved VO table
|
Tuesday 19th May
- There is a current priority for enabling/supporting our joining communities.
Tuesday 5th May
- We have a number of VOs to be removed. Dedicated follow-up meeting proposed.
Tuesday 28th April
- For SNOPLUS.SNOLAB.CA, the port numbers for voms02.gridpp.ac.uk and voms03.gridpp.ac.uk have both been updated from 15003 to 15503.
Tuesday 31st March
- LIGO are in need of additional support for debugging some tests.
- LSST now enabled on 3 sites. No 'own' CVMFS yet.
|
Site Updates
|
Tuesday 23rd February
ALICE:
All okay.
RHUL 89%:89%
Lancaster 0%:0%
RALPP: 80%::80%
RALPP: 77%:77%
- RHUL: The largest problem was related to the SRM. The DPM version was upgraded and it took several weeks to get it working again (13 Jan onwards). Several short-lived occurrences of running out of space on the SRM for non-ATLAS VOs. For around 3 days (15-17 Jan) the site suffered from a DNS configuration error by their site network manager which removed their SRM from the DNS, causing external connections such as tests and transfers to fail. For one day (25 Jan) the site network was down for upgrade to the 10Gb link to JANET. Some unexpected problems occurred extending the interruption from an hour to a day. The link has been successfully commissioned.
- Lancaster: The ASAP metric for Lancaster for January is 97.5 %. There is a particular problem with ATLAS SAM tests which doesn’t affect the site activity in production and analysis and this relates to the path name being too long. A re-calculation has been performed.
- RALPP: Both CMS and LHCb low figures are due to specific CMS jobs overloading the site SRM head node. The jobs should have stopped now.
|
|