WLCG AuthZ Call

Europe/Zurich
Description

Notes:

Previous Actions:

  •  


Proposed agenda:

  • TBC - in email

 

Zoom meeting:

Link below, in the videoconference section. Please ensure you are signed in to Indico to see the meeting password!

Next Meeting: 

  • TBC
Zoom Meeting ID
61554826915
Description
Zoom room for WLCG AuthZ Call
Host
Tom Dack
Alternative hosts
Maarten Litmaath, Hannah Short
Useful links
Join via phone
Zoom URL

Present: Anders, Berk, Dave D, Enrico, Federica, Francesco, Jacopo, John, Linda, Maarten (notes), Matt, Mischa, Roberta, Stephan, Tom

Notes:

Roberta takes us through the presentation attached to the agenda. A few items are then discussed. John asks if audit logs could be made available directly through IAM instead of via OpenSearch, as it can be a nuisance to access the latter from outside the institute hosting that service, in this case CERN: an SSH tunnel is typically required. Enrico and others answer that the whole idea behind using OpenSearch and Grafana is that those tools have exactly been created for the purpose at hand, that IAM could only provide a limited-functionality imitation, and at considerable effort: not going to happen. Dave describes how at least Firefox and Chrome can be easily configured to make use of the right tunnel configuration per site that needs one. He offers his elaborate configuration file as an example.

Next, Berk would like to know how OPA would depend on GitHub exactly? Surely, we cannot have our IAM operations directly rely on the latter. Federica answers that the 1.15 release will allow OPA to be tried out for the first time and that the use of GitHub was deemed OK just for getting experience; furthermore, should an update fail due to some issue with GitHub at the given time, OPA will keep using what it has. Maarten recalls from the workshop that the idea was to allow VOs to manage their policies directly themselves, in a very convenient way through standard Git workflows.

Finally, given that refresh tokens are still stored in the DB, Berk informs us that the CERN IAM team is planning refresh token stress tests in the coming weeks, to see how far CMS can scale up their FTS workflows in DC27, before the DB bottleneck might again become a concern. There is cautious optimism that we won't have to worry about that, because CMS will still be using tokens per data set, not per file.

The next meeting is currently planned for Oct 8.

There are minutes attached to this event. Show them.
The agenda of this meeting is empty