Difference between revisions of "Operations Bulletin Latest"

From GridPP Wiki
Jump to: navigation, search
()
()
Line 390: Line 390:
 
* CVE-2016-7117 still waiting for distro. kernel updates
 
* CVE-2016-7117 still waiting for distro. kernel updates
 
* Next Security Team meeting on the 13th Dec.
 
* Next Security Team meeting on the 13th Dec.
 +
* Certificate has expired on pakiti.egi.eu 5/12/2016
  
 
'''Monday 21st November'''
 
'''Monday 21st November'''

Revision as of 07:56, 6 December 2016

Bulletin archive


Week commencing Monday 5th December 2016
Task Areas
General updates

Monday 21st November

  • There is a GridPP Oversight Committee meeting this week.
  • ATLAS - APEL accounting records comparison. Bug found in scripts for ARC and Torque.
  • Marcus: xrdcp test for sites with DPM.
  • The EGI Security Policy Group has produced a new revised and updated Top-Level Security Policy document. This brings the document up to date in terms of terminology and the current set of security policy documents, although one of our aims was also not to change more than we needed to (as the old document has served us well over many years!). Just to be clear – this policy applies to ALL current and future EGI infrastructures and services. The draft is available for comment until the OMB this Thursday.
  • HEPSYSMAN 2017 dates to be confirmed soon.
  • A new release of the Accounting Portal is ready for testing. Please test the new release for the next 2 weeks, and report via the tracking GGUS ticket any comment, bugs or suggestions for improvement.
  • WLCG meeting (pre-GDB) on networking: 10 Jan 2017 at CERN. It will be the opportunity for LHC experiments, Network operators, WLCG service and site managers to meet and discuss the network requirements for the 3rd run of the LHC, planned for 2021-2023.
  • The ARC brainstorming camp takes place 28th November - 2nd December.
  • Reminder of Andy W's request on: Call for UK feedback to the ARC brainstorming camp.

Monday 14th November


Monday 7th November

WLCG Operations Coordination - AgendasWiki Page

Monday 7th November

Tuesday 25th October

Monday 3rd October

  • There was a WLCG ops coordination meeting last week: Agenda. (Good to review in the ops meeting).

Monday 26th September

Monday 19th September


Tier-1 - Status Page

Tuesday 6th December A reminder that there is a weekly Tier-1 experiment liaison meeting. Notes from the last meeting here

  • Owing to staff availability the upgrade of Castor to version 2.1.15 is being scheduled to take place in January.
  • We need to carry out firmware updates on a particular batch of servers - which are in use by Atlas, VMS and LHCb. Will arrange when this can be done. We are also looking to merge the small disk pools in use by Atlas and LHCb into their larger pools.
  • Following Andrew's return from vacation there has been an update of the FTS3 service.
Storage & Data Management - Agendas/Minutes

Wednesday 16 Nov

  • Some curious operational issues with failed xroot transfers - need more testing
  • Duncan provided feedback from the JISC data transfer/campus networking workshop

Wednesday 09 Nov

  • Storage related issues from hepsysman?
  • ...

Wednesday 02 Nov

  • Big picture: an attempt to explain where GridPP fits with other things such as "UKT0" and other infrastructures

Wednesday 26 Oct

  • Feedback from WLCHEPiXG - don't miss it!

Wednesday 19 Oct

  • Long list of loose ends - accounting and information systems, IPv6 surprising successes


Tier-2 Evolution - GridPP JIRA

Tuesday 22 November

  • Next generation LHCb pilots / VMs deployed at all VM-based sites. Includes multiple parallel payloads support for multiprocessor VMs and new WLCG SAM probes framework, addressing JIRA task GridPP-5
  • Vac 2.0 mixed-sized VMs support in testing, using Super Slots mechanism to create multiple single-processor VMs in groups to avoid breaking up N processor slots for multiprocessor VMs.
  • skatelescope.eu and LHCb demo at RCUK workshop on 29th Nov, showing transparent access to OpenStack resources at DataCentred Ltd and CERN using GridPP/LHCb DIRAC services and DIRAC VMs.

Tuesday 15 November

  • LHCb prototype of implementation of SAM probes for VMs done. Next step is to install the client script in the ETF/SAM test setup and test at multiple sites. Once finished, will address JIRA task GridPP-5

Tuesday 8 November

  • Agreement with ETF about how to implement SAM probes for VMs, initially for LHCb. (We will use an external service provided by LHCb which the probes inside the VMs will report to.)
  • Enabling DataCentred and StackHPC to run skatelescope.eu jobs in GridPP DIRAC VMs. i.e. two OpenStack providers with academic links.
  • Vcycle at 1.0 prerelease, and now includes an Admin Guide.



Accounting - UK Grid Metrics HEPSPEC06 Atlas Dashboard HS06

Monday 14th November

  • Alessandra has written an FAQ to extract numbers from ATLAS and APEL avoiding the SSB.

Monday 26th September

  • A problem with the APEL Pub and Sync tests developed last Tuesday and was resolved on Wednesday. This had a temporary impact on the accounting portal.
Documentation - KeyDocs

Tue 22nd Nov

  • More on Accounting audit tools

The process for ARC, Toque and VAC is now documented here.

https://github.com/gridpp/audit/wiki


Tue 15 Nov

  • Accounting audit tools

GridPP project in github used to host documents and scripts to audit work done accounts independently of APEL. So far, methods exist for ARC CE, and Torque batch system. Method for VAC still rough and being worked out by (e.g.) next week. To get the material:

git clone https://sjones-hep-ph-liv-ac-uk@github.com/gridpp/audit.git

Substituting you own github username. Or go to:

https://github.com/gridpp/audit

For write access, ask Andrew McNab.

  • Changes to CMS resource requirements in Approved VOs

See https://www.gridpp.ac.uk/wiki/GridPP_approved_VOs

Scroll to the Resources table at the bottom and check the new CMS requirements.

Tue 1 Nov

Publishing tutorial updated to use new wording for various measurements.

https://www.gridpp.ac.uk/wiki/Publishing_tutorial#Accounting_transmissions



https://www.gridpp.ac.uk/wiki/GridPP_approved_VOs


General note

See the worst KeyDocs list for documents needing review now and the names of the responsible people.

Interoperation - EGI ops agendas

Monday 7th November

  • There was an EGI Ops meeting today: agenda
  • UMD 3.14.5 released today
    • VOMS 3.5.0, which makes RFC proxies the default for voms-proxy-init
  • UMD 4.3.0 'October' release, release candidate ready, to be released by end of this week, including:
    • ARC, GFAL2, XROOT, Davix, dCache, ARGUS, Gridsite, edg-mkgrid, umd-release for CentOS7
  • please start using UMD4/SL6 or UMD4/CentOS7 instead of UMD3/SL6 & please don't use anymore EMI3
    • (think there may be a campaign around this soon)
  • Downtimes due to the vulnerability CVE-2016-5195: request an A/R recomputation
    • All the resource centres that were affected by the vulnerability CVE-2016-5195 and that declared a downtime between 2016-10-20 16:00 UTC and 2016-10-31 18:00 UTC are invited to request a recomputation of A/R figures for the days in which the downtime was ongoing.
Monitoring - Links MyWLCG

Tuesday 1st December


Tuesday 16th June

  • F Melaccio & D Crooks decided to add a FAQs section devoted to common monitoring issues under the monitoring page.
  • Feedback welcome.


Tuesday 31st March

Monday 7th December

On-duty - Dashboard ROD rota

Monday 21st November

  • EFDA low-availability (egi.eu.lowAvailability-/EFDA-JET@EFDA-JET_Availability) ticket finally removed!

Monday 14th November

  • AM reports: End of two week shift. Various planned and unplanned downtimes. No grid-wide issues.


Rollout Status WLCG Baseline

Tuesday 7th December

  • Raul reports: validation of site BDII on Centos 7 done.

Tuesday 15th September

Tuesday 12th May

  • MW Readiness WG meeting Wed May 6th at 4pm. Attended by Raul, Matt, Sam and Jeremy.


References


Security - Incident Procedure Policies Rota

Tuesday 6th December

  • One user suspension (and subsequent release) in Argus due to an EGI FedCloud incident. Not know to affect UK.
  • CVE-2016-7117 still waiting for distro. kernel updates
  • Next Security Team meeting on the 13th Dec.
  • Certificate has expired on pakiti.egi.eu 5/12/2016

Monday 21st November

  • The IGTF will release a regular update to the trust anchor repository (1.79) on Monday, Nov 28th 2016.
  • We are still seeing sites pop-up in the dashboard in relation to EGI-SVG-2016-11476.
  • CVE-2016-7117 still waiting for distro. kernel updates

Monday 14th November

  • CVE-2016-7117


The EGI security dashboard.


Services - PerfSonar production dashboard |PerfSonar development dashboard | GridPP VOMS

- This includes notifying of (inter)national services that will have an outage in the coming weeks or will be impacted by work elsewhere. (Cross-check the Tier-1 update).

Tuesday 25th October

  • Duncan has recreated the UK perfSONAR mesh. Link here!


Monday 19th September

  • UK eScience CA - certificate issuance problems. Jens reported that on 15th a partial but significant database corruption occurred on the signing system for the CA. Data was restored from (offline) backups but the rebuild was not correctly configured.
  • A large number of site admins and other GridPP supporters appeared to be suspended from the dteam VO last week. “During a planned upgrade operation of VOMS service, a system malfunction occurred. As a result, some users received false notification about membership expiration. We are in contact with the software development team in order to identify the cause.”


Tickets

Monday 5th December 2016, 14.30 GMT
22 Open UK Tickets this month.

SUSSEX
122772 (11/7)
atlas xroot/http ticket. No progress expected till January, but Jeremy M has noted this in the ticket. On hold (21/11)

124614 (24/10)
Availability ticket, on hold as is S.O.P., but this one is hanging around longer then usual. Perhaps it has something to do with the blips of "Unknown" status? On hold (14/11)

RALPP
125320 (2/12)
Intermittant nagios test failures for the RALPP dcache - Chris is fighting load issues but sadly doesn't seem to be reporting much luck. In progress (2/12)

OXFORD
121924 (2/6)
Perfsonar performance drop at Oxford. Pete G updated the ticket reporting a similar issue to that seen elsewhere - the perfsonar isn't filling up the available bandwidth. On hold (5/12)

BIRMINGHAM
122771 (11/7)
Atlas xrootd and http ticket - any luck (or lack thereof) with it Mark now that you're not dealing with ungrateful undergrads? In progress (29/11)

125169 (24/11)
Small VO acls on the Birmingham batch system, Mark is just getting round to look at this too. In progress (29/11)

GLASGOW
124821 (3/11)
One of the AFS tickets - on hold whilst Gordon asks around to see who's using afs. On hold (16/11)

124052 (25/9)
LHCB ticket about the incorrect job numbers reported by the Glasgow ARCs. IIRC the Glasgow position is to wait on an official release with the fix? No movement on the linked bugzilla or ticket. Booo. On hold (26/9)

EDINBURGH
124758 (1/11)
Another Availability ticket (which I'm thinking of renaming "Bauer-Banes" for how much they righteously annoy Daniela). Just waiting for it to clear. On hold (14/11)

125209 (27/11)
ECDF failing apel sync tests. Andy added their apel node (back?) into the gocdb, and things are looking better, although there is a gap in October. If this hole can be plugged then the ticket can be closed I think (if it can't then the ticket can also be closed, but it would be a less happy ending). In progress (1/12)

MANCHESTER, LIVERPOOL and RHUL AFS TICKETS
124822 (3/11)
The Manchester ticket was referred to Sabah (who in turn referred it to the Uni firewall admins)- Andrew M noted his righteous displeasure at the Tier 2s being ticketed about this. I would advise self closing the ticket (or at least on holding it). In progress (8/11)

124819 (3/11)
John B fielded this for Liverpool, again it's a ticket that could do with being On Holded if you don't want to just close it. In progress (3/11)

124816 (3/11)
Simon fielded the RHUL ticket, forwarding the information on. Same deal as the previous two tickets with this chap. In progress (7/11)

THE TIER ONE
124606 (24/10)
CMS consistency checking ticket - Andrew L is deletions in progress so this is chugging along nicely now. In progress (2/12)

124876 (7/11)
Nagios test failures to the echo instance - Alastair has been working on getting the probe fixed so it's relevant to this object store (see 125026). On hold (21/11)

125348 (5/12)
Request from CMS to update phedex- Andrew L has added it to this week's to do list. In progress (5/12)

125325 (3/12)
Atlas MCORE job stagein failing - possibly due to problems with some disk servers/switches that occured overnight, although Brian points out that FTS transfers are okay. Looking on panda though I don't think the picture has improved greatly. In progress (5/12)

125157 (24/11)
Creation of a cvmfs repo for extras-fp7.eu. Catalin has worked hard debugging some user problems, just skimming the ticket but things are looking better for the user now (after switching UIs!), they should be uploading stuff soon. In progress (2/12)

124478 (17/10)
na62 WMS jobs getting stuck forever at RAL. Dan from na62 has asked for an update. In progress (29/11)

122827 (12/7)
Sno+ ticket asking for more disk space. Gareth asked for an update, and David reports that there hasn't been any recent complaints about MC access times. Perhaps the ticket can be closed? In progress (1/12)

117683 (18/11/2015)
Castor not publishing glue2 - Jens updated in October with word that available effort for developing this is minimal, this should tide the ticket over till next year. On hold (5/10)

JET-TING OFF 122198 (17/6)
I forgot to talk to Jeremy about closing Jet in the GOCDB last week, I'll do it this week. In progress (5/12)

Tools - MyEGI Nagios

29th November 2016

LSST monitoring is available through vo-nagios

https://vo-nagios.physics.ox.ac.uk/nagios/cgi-bin/status.cgi?servicegroup=lsst&style=detail

13th September 2016


19th July

Both instances of gridppnagios at Oxford and Lancaster has been decommissioned.

12th July 2016

Central ARGO monitoring service has started from 1st of July. All grid resources are monitored through two Nagios instances

https://argo-mon.egi.eu/nagios/

https://argo-mon2.egi.eu/nagios/

It has same interface as gridppnagios. Alarms from these instances goes to Operational Dashboard

http://argo.egi.eu/ is a web interface which provides availability/reliability figures and site status. It is equivalent of old myegi interface with some additional services.

I am planning to decommission both instances of gridppnagios in coming weeks. I have stopped nagios and httpd on both instances so it will not send tests to grid resources in UK. I will also decommission storage-monit.physics.ox.ac.uk which was only used for storage replication test.

We will keep vo-nagios.physics.ox.ac.uk running until we get a replacement for vo-monitoring.


Monday 13th June

  • Active Nagios instance moved to Lancaster

Tuesday 5th April 2016

Oxford had a scheduled network warning so active nagios instance was moved from Oxford to Lancaster. I am not planning to move it back to Oxford for the time being.


Tuesday 26th Jan 2016

One of the message broker was in downtime for almost three days. Nagios probes picks up a random message broker and failover is not working so a lot of ops jobs hanged for long time. Its a known issue and unlikely to be fixed as SAM Nagios is in its last leg. Monitoring is moving to ARGO and many things are not clear at the moment.

Monday 30th November

  • The SAM/ARGO team has created a document describing Availability reliability calculation in ARGO tool.
VOs - GridPP VOMS VO IDs Approved VO table

Tuesday 19th May

  • There is a current priority for enabling/supporting our joining communities.

Tuesday 5th May

  • We have a number of VOs to be removed. Dedicated follow-up meeting proposed.

Tuesday 28th April

  • For SNOPLUS.SNOLAB.CA, the port numbers for voms02.gridpp.ac.uk and voms03.gridpp.ac.uk have both been updated from 15003 to 15503.

Tuesday 31st March

  • LIGO are in need of additional support for debugging some tests.
  • LSST now enabled on 3 sites. No 'own' CVMFS yet.
Site Updates

Tuesday 23rd February

  • For January:

ALICE: All okay.

RHUL 89%:89% Lancaster 0%:0%

RALPP: 80%::80%

RALPP: 77%:77%

  • Site responses:
    • RHUL: The largest problem was related to the SRM. The DPM version was upgraded and it took several weeks to get it working again (13 Jan onwards). Several short-lived occurrences of running out of space on the SRM for non-ATLAS VOs. For around 3 days (15-17 Jan) the site suffered from a DNS configuration error by their site network manager which removed their SRM from the DNS, causing external connections such as tests and transfers to fail. For one day (25 Jan) the site network was down for upgrade to the 10Gb link to JANET. Some unexpected problems occurred extending the interruption from an hour to a day. The link has been successfully commissioned.
    • Lancaster: The ASAP metric for Lancaster for January is 97.5 %. There is a particular problem with ATLAS SAM tests which doesn’t affect the site activity in production and analysis and this relates to the path name being too long. A re-calculation has been performed.
    • RALPP: Both CMS and LHCb low figures are due to specific CMS jobs overloading the site SRM head node. The jobs should have stopped now.



Meeting Summaries
Project Management Board - MembersMinutes Quarterly Reports

Empty

GridPP ops meeting - Agendas Actions Core Tasks

Empty


RAL Tier-1 Experiment Liaison Meeting (Wednesday 13:30) Agenda Meeting takes place on Vidyo.

Highlights from this meeting are now included in the Tier1 report farther up this page.

WLCG Grid Deployment Board - Agendas MB agendas

Empty



NGI UK - Homepage CA

Empty

Events
UK ATLAS - Shifter view News & Links

Atlas S&C week 2-6 Feb 2015

Production

• Prodsys-2 in production since Dec 1st

• Deployment has not been transparent , many issued has been solved, the grid is filled again

• MC15 is expected to start soon, waiting for physics validations, evgen testing is underway and close to finalised.. Simulation expected to be broadly similar to MC14, no blockers expected.

Rucio

• Rucio in production since Dec 1st and is ready for LHC RUN-2. Some fields need improvements, including transfer and deletion agents, documentation and monitoring.

Rucio dumps available.

Dark data cleaning

files declaration . Only Only DDM ops can issue lost files declaration for now, cloud support needs to fill a ticket.

• Webdav panda functional tests with Hammercloud are ongoing

Monitoring

Main page

DDM Accounting

space

Deletion

ASAP

• ASAP (ATLAS Site Availability Performance) in place. Every 3 months the T2s sites performing BELOW 80% are reported to the International Computing Board.


UK CMS

Empty

UK LHCb

Empty

UK OTHER
  • N/A
To note

  • N/A