A unified topology system for �a large scale, heterogeneous and dynamic computing infrastructure
Alexey Anisenkov (BINP)
on behalf of CRIC team�
1
CHEP 2019, Australia, Adelaida, 7 Nov 2019
CRIC: a high-level information middleware to configure computing environment and describes resources as VOs need
2
Alexey Anisenkov, CHEP-2019
Rucio
Pilots
OIM
Open�LDAP BDII
�
REBUS
GOCDB
Other sources
- Low-level infosys
- Data providers
- Service discovery
�
WLCG Central �ops
GlideinWMS
Phedex
WLCG squids
And many others…
Resources description
Experiment applications
CRIC mission: link Resources & VOs together
Key functional capabilities of CRIC information concept:
3
Alexey Anisenkov, CHEP-2019
** CRIC is not coupled to WLCG, it could be applied beyond LHC experiments
CRIC Architecture: examples of shared features out of the box
4
CORE
CORE
CORE
CMS CRIC
ATLAS CRIC
WLCG CRIC�(serves ALICE, LHCb, overall view)
REST API
WebUI
SiteDB
REBUS��
Other Sources
BDII
GlideinWMS configs
COMPASS CRIC
CORE
CORE
Generic CRIC
VOs can use shared WLCG CRIC instance as the master source� or optionally fetch data directly from low-level info providers
Few Implementation details: Web2.0 based
5
Alexey Anisenkov, CHEP-2019
CMS CRIC
In production for CMS Community since the end of 2018
6
Alexey Anisenkov, CHEP-2019
WLCG CRIC
Dedicated CRIC instance for central WLCG operations
7
Alexey Anisenkov, CHEP-2019
ATLAS CRIC (ongoing)
Moving from AGIS to ATLAS CRIC has started
In fact CRIC is the evolution of AGIS (ATLAS Grid Information system) - completely refactored code, inherits all AGIS features
8
Alexey Anisenkov, CHEP-2019
Tentative Plan for the migration:
DOMA CRIC
Dedicated CRIC instance for Rucio TPC tests� and DOMA related activities
9
Alexey Anisenkov, CHEP-2019
COMPASS CRIC
Dedicated CRIC instance for COMPASS Experiment � at CERN SPS
10
Alexey Anisenkov, CHEP-2019
Lightweight CRIC plugin (ongoing)
Universal topology description of generic distributed infrastructure
Requested by Experiments at JINR (NICA and beyond)�as the Information component�for the Unified Resource Management System
11
Collaborative support model
12
Alexey Anisenkov, CHEP-2019
Conclusion. CRIC family
13
Alexey Anisenkov, CHEP-2019
in production
core-0.2.7
cms-0.2.6
CMS CRIC
core-0.3.0
wlcg-0.1.5
WLCG CRIC
core-0.3.0
doma-rc
DOMA CRIC
core-0.2.9
atlas-testbed
ATLAS CRIC
core-0.2.3
compass-rc
COMPASS CRIC
ongoing
lightweight CRIC
development
integration
Thank you for your attention!
Backup slides
14
Alexey Anisenkov, CHEP-2019
Distributed Computing Environment (Resources)
LHC Experiments rely on heterogeneous distributed computing
�
15
Alexey Anisenkov, CHEP-2019
Research granted access
Opportunistic backfilling
HPC
HPC
Grid
WLCG Pledged resources
Cloud
Volunteers
Rented, �on demand
Opportunistic
Opportunistic�backfilling
others ..
Distributed Computing Environment (Experiments)
16
Alexey Anisenkov, CHEP-2019
…
Authorization and Authentication (A&A)
Each Experiment could configure own Data access policies!
17
User Profiles
SSO
SSL
VOMS
Local
User
Custom Groups
permissions
Roles
Group memberships
Auth Groups
Alexey Anisenkov, CHEP-2019
Example of A&A use-cases for different VOs
18
Experiment decides what elements should be used out of the CRIC box to implement own policies and follow own workflow.
Alexey Anisenkov, CHEP-2019
SiteDB�Groups
Groups membership
Auth Groups
per Facility Groups
Group Responsibilities
Auth Groups
CMS User
ATLAS User
Roles
Roles
Automatic sync with CERN User DB
Data export availability
19
Latest (stable) caches can be further mirrored to CVMFS (e.g. used by ATLAS) as (failover, cache) access to topology data from worker nodes
Alexey Anisenkov, CHEP-2019
Recent core developments (tableviews)
Inline editor for bulk updates
Flexible table view visualization
20
Alexey Anisenkov, CHEP-2019
Update required fields for several objects,
Bulk save
Customize visualization on fly, prepare custom data view for share and distribution
Recent core developments (request user privileges)
ADMIN Privileges Request/approval wizard
21
Alexey Anisenkov, CHEP-2019
Clicky-Clicky wizard to request privileges by user
ADMIN decides/grants only required perms.�Email notification sent on request/approval steps
Ongoing core developments
Moving to use-case oriented approach of updating data
22
Alexey Anisenkov, CHEP-2019