WLCG DOMA BDT Meeting

Europe/Zurich
Brian Paul Bockelman (University of Wisconsin Madison (US)), Maria Arsuaga Rios (CERN), Petr Vokac (Czech Technical University in Prague (CZ))
Description

Topic: WLCG DOMA BDT Meeting

Join Zoom Meeting
https://cern.zoom.us/j/99836057922?pwd=ZFhWN3NpYi9oZmwvM3pIRE9zdzFnZz09

Meeting ID: 998 3605 7922
Passcode: 733660
One tap mobile
+41315280988,,99836057922# Switzerland
+41432107042,,99836057922# Switzerland

Dial by your location
        +41 31 528 09 88 Switzerland
        +41 43 210 70 42 Switzerland
        +41 43 210 71 08 Switzerland
        +33 1 7037 2246 France
        +33 1 7037 9729 France
        +33 1 8699 5831 France
Meeting ID: 998 3605 7922
Find your local number: https://cern.zoom.us/u/aeB4ArMgmT

  • Tape REST access
    • most of endpoints specification already final, missing
      • Archival tape mapping
      • REST API discovery - JSON content of ".well-known"
    • Timeline for REST API support
      • EOS+CTA - before Run3 (may be even production instance)
      • dCache - working on Bulk service 2.0 - Tape REST just subset of functionalities - most probably available before Run3 start (golden release TBD)
      • StoRM - designing new interface for tapes
      • FTS - not priority before Run3
        • not long after beginning of Run3
  • Token authorization testbed
    • HTTP-TPC compliance tests
      • scope based authorization vs. group based authorization needs to be clarified (issue#21)
    • xroot compliance tests - not yet discussed
  • Packet marking - this will be discussed next time
  • AOB
    • FTS IPv4 vs. IPv6 monitoring for non-GridFTP protocols
      • Missing RemoteConnections in StoRM HTTP-TPC preformance marker
      • (Oracle) JVM by default use IPv4 for non-GridFTP TPC transfers (StoRM, dCache)
        • this should be at least configurable - documentation(?)
        • storage should come with preferred IPv6 by default or relay on OS preference
      • Implement performance markers processing in gfal2 for HTTP DMC-1278 and xroot DMC-1016
    • SE-tokens and non-TPC operations
      • not enough time to discuss this topic
      • discussed in an email thread
        • gfal-rename has to be fixed DMC-1297
        • new DPM 1.15.2 release add support for SE-tokens & HTTP MOVE
          • all DPM sites must upgrade once dmlite 1.15.2 gets released
There are minutes attached to this event. Show them.
    • 16:30 16:35
      Hot topics 5m

      DOMA BDT plans for 2023

      SE-tokens and non-TPC operations

      • Rucio uploads file with ".upload" suffix and rename file after successful transfer
      • Some storage implementation doesn't support MOVE HTTP operation with SE-tokens
        • or only one SE-token used for source and destination
        • DMC-1297
      • Should all our storage implementations support all HTTP operations with SE-tokens?
        • for HTTP-TPC we need SE-token only for COPY operation
        • gfal 2.20.x with built-in SE-token support try to use token for all operations
          • make cause one additional round-trip to get SE-token
          • fails with storage implementations that doesn't support MOVE
      • This is now blocking EPEL release of gfal 2.20.x
    • 16:35 16:45
      Tape REST access 10m
      Speaker: Cedric Caffy (CERN)
      REST API
      • What has currently been agreed?
      • What is the pending to agree? 
      • Which is the current status?
        • CTA?
        • Storm?
        • dCache?
      • Which will then be the timeline Agreement/Implementation/Tests/Production?
    • 16:45 17:00
      Token Authorization testbed 15m
      Speaker: Francesco Giacomini (INFN CNAF)

      Token Authorization Tesbed

      • Is XRootD considered? what XRootD version should be targeted by these tests?

        • https://github.com/xrootd/xrootd/issues/1567

      • Are scope token strings taken into account?

        • https://github.com/indigo-iam/wlcg-jwt-compliance-tests/issues/21

      • Would a "WLCG-standard" token authorization testbed be useful?

      • Are Paul's smoke tests (DOMA TPC tests) still being conducted?
        Is it possible to keep them for the purpose of discovering regression issues?

    • 17:00 17:10
      Packet marking 10m
      Speakers: Marian Babik (CERN), Shawn Mc Kee (University of Michigan (US))

      Packet and flow marking homepage is at https://www.scitags.org/

      The page has pointers to the recent updates, existing code, technical specification and mailling list. 

       

      Timeline - what can be done this year?

      Are UDP fireflies just a proof of concept or something you would like to see deployed on more sites?

      What are the plans with implementation using IPv6 flow label? Are developers of all our data transfer middleware aware of packet marking activity? Do they have plans / timelines? External dependencies / constraints (e.g. OS / kernel support)?

      Recent presentation on the packet marking and flow labeling efforts https://docs.google.com/presentation/d/1TJyqDL3HD0db72zzcEg034Cv8XPIxd-zdDigIASqMR0/edit?usp=sharing 

    • 17:10 17:20
      SRM+HTTP tape access 10m
      Speakers: Alessandra Forti (University of Manchester (GB)), Christophe Haen (CERN), Diego Davila Foyo (Univ. of California San Diego (US))

      ATLAS

      Done in November 2021

      Starting in March 2022 GridFTP become optional for ATLAS TPC and sites may remove gsiftp (we may even actively remove this protocol from third-party-copy Rucio activity). There are still number of sites with fragile WLCG SRR and that's why we can't yet completely remove this protocol from RSE configuration (waiting for WLCG + new dCache WLCG SRR documentation not yet published - it is not clear what is the recommended / most robust way for publishing WLCG SRR).

      CMS

      SRM+https

      has been tested at all T1s. Next steps 

      1. Ask the FTS admins to set TURL_3RD_PARTY_PROTOCOLS=https;gsiftp

         * Started with FNAL FTS GGUS:!55994

      2. Ask The Rucio admins to set srm_https_compatibility = True

      LHCb

      SRM+https

      For now, everything is still manual tests. Things should get more automated by the tape challenge

      https access to CTA

      CTA@CERN: we write and transfer out of CTA with https since the beginning. It is not bullet proof though, and the failure rate is of a few percents

      CTA@RAL: under discussion GGUS:155513

    • 17:20 17:30
      AOB 10m