WLCG AuthZ Call
Notes:
Previous Actions:
Proposed agenda:
- TBC - in email
Zoom meeting:
Link below, in the videoconference section. Please ensure you are signed in to Indico to see the meeting password!
Next Meeting:
- TBC
Present: Anders, Berk, Dave D, Enrico, Federica, Francesco, Jacopo, John, Linda, Maarten (notes), Matt, Mischa, Roberta, Stephan, Tom
Notes:
Roberta takes us through the presentation attached to the agenda. A few items are then discussed. John asks if audit logs could be made available directly through IAM instead of via OpenSearch, as it can be a nuisance to access the latter from outside the institute hosting that service, in this case CERN: an SSH tunnel is typically required. Enrico and others answer that the whole idea behind using OpenSearch and Grafana is that those tools have exactly been created for the purpose at hand, that IAM could only provide a limited-functionality imitation, and at considerable effort: not going to happen. Dave describes how at least Firefox and Chrome can be easily configured to make use of the right tunnel configuration per site that needs one. He offers his elaborate configuration file as an example.
Next, Berk would like to know how OPA would depend on GitHub exactly? Surely, we cannot have our IAM operations directly rely on the latter. Federica answers that the 1.15 release will allow OPA to be tried out for the first time and that the use of GitHub was deemed OK just for getting experience; furthermore, should an update fail due to some issue with GitHub at the given time, OPA will keep using what it has. Maarten recalls from the workshop that the idea was to allow VOs to manage their policies directly themselves, in a very convenient way through standard Git workflows.
Finally, given that refresh tokens are still stored in the DB, Berk informs us that the CERN IAM team is planning refresh token stress tests in the coming weeks, to see how far CMS can scale up their FTS workflows in DC27, before the DB bottleneck might again become a concern. There is cautious optimism that we won't have to worry about that, because CMS will still be using tokens per data set, not per file.
The next meeting is currently planned for Oct 8.