WLCG DOMA BDT Meeting
Topic: WLCG DOMA BDT Meeting (twiki)
-
-
16:30
→
16:35
News 5m
-
16:35
→
16:55
Rucio & tokens 20mSpeaker: Dimitrios Christidis (CERN)
- Rucio:
- Reminder: at the time of writing, Rucio officially supports only single-VO instances, INDIGO IAM, the WLCG token profile, TPC and deletions, only disk RSEs, only the WebDAV protocol using the GFAL implementation.
- We’re currently restricting ourselves to refining what’s already implemented.
- The development of new features will resume after DC24.
- We’ve identified a regression affecting deletions.
- Tokens are not used, even in cases where they’re supposed to.
- Will be addressed in the next release.
- The interaction between Rucio and IAM is non-standard.
- Rucio uses the client credentials flow to request a token with a specific scope and audience. The audience part is not described in the OAuth specifications.
- A different interaction that was tried was to use the client credentials flow to acquire a scope- and audience-less token, then use the token exchange flow to acquire a scope- and audience-specific token (and the former can be cached and reused many times). This seems to be standard and mostly worked, except IAM disallows this if the requested scope contains offline_access (needed by FTS).
- This seems to be the relevant commit.
- Possily also related: https://github.com/indigo-iam/iam/issues/381
- It would seem prudent to not deviate from the standards.
- Rucio will need to support more token providers (e.g. CILogon).
- Reminder: at the time of writing, Rucio officially supports only single-VO instances, INDIGO IAM, the WLCG token profile, TPC and deletions, only disk RSEs, only the WebDAV protocol using the GFAL implementation.
- ATLAS:
- We’re steadily increasing the number of RSEs with token support.
- 10 sites, but only SCRATCHDISKs; the DATADISKs will be enabled next week.
- The ATLAS and Pilot FTS instances are upgraded and configured to use tokens.
- Sites in North America which are capable of using tokens will be reassigned from the BNL to the Pilot instance.
- We’re steadily increasing the number of RSEs with token support.
- CMS (from K. Ellis):
- Release 33 being tested in integration.
- Manual testing is unable to confirm that Rucio will be able to acquire the necessary tokens from IAM.
- Some restriction appears to prevent the acquisition of a token with the fts scope.
- Rucio:
-
16:55
→
17:05
Transfers with tokens 10mSpeakers: Petr Vokac (Czech Technical University in Prague (CZ)), Francesco Giacomini (INFN CNAF)
-
17:05
→
17:10
Tape REST access 5mSpeaker: Mihai PATRASCOIU (CERN)
ATLAS status
- sites with TAPE rest in production
- CTA: CERN, RAL
- dCache: FZK, DESY-HH (T2)
- sites with TAPE rest available
- dCache: BNL-OSG2, IN2P3-CC, NDGF-T1, PIC
- StoRM: INFN-T1
- sites without configured TAPE REST
- dCache: SARA-MATRIX, TRIUMF-LCG2
- sites with old SE
- dCache 7.x: RRC-KI-T1
- we would like to move forward with TAPE REST deployment after DC24, details
- CERN-PROD (REST) - production (April 2023)
- BNL-OSG2 (REST)
- FZK-LCG2 (REST) - production (March 2023)
- IN2P3-CC (REST)
- INFN-T1 (REST)
- NDGF-T1 (REST) - they would like to test ENDIT with SRM before moving to REST (January 2024)
- PIC (REST)
- RAL-LCG2 (REST) - production (~ May 2023)
- RRC-KI-T1 (REST) - old dCache 7.x
- SARA-MATRIX (REST) - REST JSON not yet configured
- TRIUMF-LCG2 (REST) - REST JSON not yet configured
- sites with TAPE rest in production
-
17:10
→
17:20
Packet marking 10mSpeakers: Marian Babik (CERN), Shawn Mc Kee (University of Michigan (US))
Notes from yesterday's LHCONE/LHCOPN meeting https://indico.cern.ch/event/1360679/
Packet marking
- Firefly (R&E) dashboard
- Validation - UNL looking into possible internal dashboards that could be helpful
- Deployment at Jisc (started)
- Collector forwarding (from Jisc to ESnet) would be useful for DC24 (if Jisc dashboard won't be public by then it could help us bring the data to ESNet and show it there)
- RFC Draft v3 TBDPacket pacing
- Carmen run some tests during the holiday period, TBD at the next meeting
- Testbed Google sheet -
- Still missing information from RNP and Jisc (to be followed up by mail together with request for changes on the nodes)
- https://docs.google.com/spreadsheets/d/1U0VXIfWHfpK7bX7k2ucFep4Xo_4KQ5x-7rKD7e4az7Y/edit?usp=sharing -
17:20
→
17:25
WebDAV Error Message Improvement Project & unified error message format 5m
Discuss with experts improvements in the error messages produced by failed transfers.
https://twiki.cern.ch/twiki/bin/view/LCG/WebdavErrorImprovementSpeaker: Stephan Lammel (Fermi National Accelerator Lab. (US)) -
17:25
→
17:30
AOB 5m
-
16:30
→
16:35