1 of 15

É

Trust and Identity Incubator

T&I Service Dashboard

GÉANT Trust & Identity Incubator

Niels van Dijk

2 of 15

Service Dashboard for GEANT T&I Services

Create a comprehensive, high level and user friendly publicly facing service dashboard for Trust and Identity Services

  • Identify high level requirements for the dashboard and discuss with service owners
  • Identify T&I services and their endpoints candidates for presentation in the dashboard
  • Identify available free and commercial services for measuring availability
  • Select at minimum 2 services for testing.
  • Discuss with service owners how to best represent the metrics
  • Implement a test with these services for at least 2 GEANT T&I services.
  • Demonstrate the results of this activity on at least 1 relevant event.

2

3 of 15

T&I Services discussed

  • GEANT proxy
    • Will use test instance to monitor
    • Will develop full chain test against this proxy
  • InAcademia
    • Would like multiple endpoints reported on
  • eduroam
    • Please re-use data from eduroam technical monitor site
  • eduGAIN
    • Report on eduGAIN metadata and supporting sites
    • DO NOT query eduGAIN metadata itself
  • eduTEAMS
    • Per T&I service dashboard required
    • No endpoints discussed yet

3

4 of 15

Requirements from service owners

Must

  • Allows per service public status pages (also for multiple monitors)
  • Checks: HTTP(S), keyword(s), ping, port
  • Allows further link to specific services components if listed
  • CNAME possible per status page

Should

  • Allows messages to be presented at public page
  • API access
  • Multiple users
  • Separation of duties (multiple users for separate monitors)

Could

  • 2FA access to management portal
  • Authenticated access to pages (http basic/digest)
  • Check specific headers

4

5 of 15

Services tested

  • Uptime Robot
  • Pingdom
  • Uptrends - no maintenance reporting, too many feature?
  • Gazer - only http(s) based checks, too little features
  • Host-tracker - very technical, no public dashboard
  • Site 24x7 - security concerns
  • Status.io - not a monitor by itself

At first glance, most services match most requirements. �But proof of the pudding is in the eating...

5

6 of 15

Uptime robot

Must

  • Allows per service public status pages (also for multiple monitors)
  • Checks: HTTP(S) keyword(s), ping, port
  • Allows further link to specific services components if listed
  • CNAME possible per status page

Should

  • Allows messages to be presented at public page (in pro plan, untested)
  • API access (untested)
  • Multiple users (untested)
  • Separation of duties (untested)

Could

  • 2FA access to management portal
  • Authenticated access to pages (http basic/digest)
  • Optional: check specific headers (in pro plan, untested)
  • Free plan includes 50 sites to be monitored

6

7 of 15

Uptime Robot - per service status spage

7

8 of 15

Uptime Robot - detailed service page

8

9 of 15

Pingdom

Must

  • Checks: HTTP(S) keyword(s), ping, port
  • Allows further link to specific services components if listed
  • CNAME possible per status page

Should

  • Allows messages to be presented at public page (in pro plan, untested)
  • API access to ‘almost everything in your account’ (untested)

Could

  • 2FA access to management portal
  • Authenticated access to pages (http basic/digest)
  • Optional: check specific headers (in pro plan, untested)

Blockers

  • Only 1 public status pages (also for multiple monitors)

9

10 of 15

Pingdom - Service status page

10

11 of 15

Pingdom - detailed service page

11

12 of 15

Uptrends

Must

  • Allows per service public status pages (also for multiple monitors)
  • Checks: HTTP(S) keyword(s), ping, port
  • Allows further link to specific services components if listed
  • CNAME possible per status page

Should

  • Does not allow messages to be presented at public page
  • API access to ‘almost everything in your account’ (untested)
  • Multiple users (untested)
  • Separation of duties (untested)

Could

  • Federated login (untested)
  • 2FA access to management portal
  • Authenticated access to pages (http basic/digest)
  • Optional: check specific headers

Notes

  • Can be noisy; one test site used during the assessment phase would be working without error, and yet a number of the globally-distributed testing servers would report a problem with this test site. No pattern was found for this behaviour.
  • Layout changes for public page partially done via helpdesk

12

13 of 15

Uptrends - Service status page

13

14 of 15

Uptrends - detailed service page

14

15 of 15

Recommendations

Proceed with Uptime Robot and Pingdom

Include pricing in comparison

Extend test to make ‘proper’ dashboards for more T&I services in collab w/ service owner

Further develop end-2-end testing for e.g. InAcademia

15