Present: Dimitrios C, Tom D (notes), Maarten L, John SDS Jr, Brian B, Federica A, Alexandre B, Francesco G, Diotalevi, Andrei T, Julie M, Hannah S, Mine AC, Stefano DP, Dave D, Thomas H, Christophe H, Petr V
Apologies:
No Previous Actions
GDB Update:
- Took longer than allotted time due to questions about testing and upgrade details
- Potential concern about CE and batch on different condor versions, could that work - definitely yes
- Stefano raised at the GDB - concern was that Condor 10.2 can not work with a condor CE supporting GSI
- Context of sites running multiple CEs - could potentially partition them to run the old and new systems.
- Stefano notes a colleague had to roll back from Condor 10 to support GSI
- Brian believes the condor team should be able to help with this, and Stefano notes he has a meeting where he can ask questions
- Brian: have we heard much back from ARC&EGI checkin?
- Maarten was pointed to an arc instance which was available to develop against, with github pull requests to make changes to configuration etc.
- Brian will pass details on to Maarten to send to CheckIn devs
- Know that the LHC-b and Alice content is not completely okay due to the default import options - has resulting in suspended users being ignored
- Christophe - for LHC-b, robot accounts have been merged with primary accounts. Low priority, as it does not block any tests - could potentially just refresh things after testing completed
- Christophe and Maarten to open tickets for tracking reasons
Hannah had concerns raised to here about CMS turning off VOMs admin
- Suggestion was that there was a backup instance with VOMs endpoints ready to go
- Either have it active and pointing at the database or ready to go if needed
- Further discussions needed within the IAM maintainer team
- Could generate the VOMs compatible DB from the IAM DB and run VOMs against it
- Look to have the CERN new starter look into this
- Concerns around backing up the CERN HR DB off site
- Replica could be located elsewhere - likely needs more thought before a final decision
- Deployment should be on a different infrastructure, though could still be at CERN just if hosted elsewhere
- Could set up two K8s clusters in different locations rather than just on OpenShift - to be considered internally. Advantages and disadvantages to the OpenShift deployment
- "Hot Spare" feels like a good solution
- Look to investigate pros and cons to moving to K8s deployment. Hannah has previously investigated tools to use for making the deployment process easier
Atlas to be moved to IAM 1.8
Brian - Petr had flagged the new version of JobSub with Vault support, and getting a report on Dune's overall plans
- Mine: Feb 15 will make version current to try and make users use the new one, with March 15th being the shut-off for the older version of JobSub
- Dave: new system uses SciTokens to authenticate the connection, and tokens can then be passed for storage access.
- Are all using token compatible protocol, or still some GridFTP? Dave thinks all have moved from GridFTP
- First time that vault will be in production - htgettoken will be in the JobSub flow
- ManageToken service runs htgettoken to get token for production users and store the credential into condor cred.d
- Brian asks if there is a Chep talk, Mine notes there is an architecture document - though very long and detailed
- Mine will investigate deadlines for sharing details with community. Hopes that soon will have more news about token use in production
There are minutes attached to this event.
Show them.