<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Documentation – Cloud Compute</title><link>/providers/cloud-compute/</link><description>Recent content in Cloud Compute on Documentation</description><generator>Hugo -- gohugo.io</generator><atom:link href="/providers/cloud-compute/index.xml" rel="self" type="application/rss+xml"/><item><title>Providers: Requirements</title><link>/providers/cloud-compute/requirements/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/providers/cloud-compute/requirements/</guid><description>
&lt;p>Resource Centres are free to use any Cloud Management Platform as long as they
are able to integrate with the EGI Federation components. At the moment this
compliance is supported for OpenStack open-source cloud platform.&lt;/p>
&lt;p>The general minimum requirements are described below.&lt;/p>
&lt;ul>
&lt;li>
&lt;p>Relevant parts of
&lt;a href="https://confluence.egi.eu/display/EGIPP/PROC09+Resource+Centre+Registration+and+Certification">PROC09 Resource Centre Registration and Certification&lt;/a>
have been successfully completed&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Hardware requirements greatly depend on your cloud infrastructure, EGI
components in general do lightweight operations by interacting with your
services APIs.&lt;/p>
&lt;ul>
&lt;li>Image sync requires enough space to store the community images into your
local catalogue. The number and size of images which will be downloaded
depends on the communities you plan to support. For the operations VO &lt;code>ops&lt;/code>,
a &amp;lt; 4GB image is used.&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>
&lt;p>Servers need X.509 host certificates in order to authenticate to each other or
to act as public endpoints in the EGI Federated Cloud context. For accounting
purposes one IGTF-accredited X.509 certificate is needed per site, but the
other public endpoints can use ordinary certificates (issued by Let’s Encrypt
for example).&lt;/p>
&lt;ul>
&lt;li>For the IGTF-accredited certificates, a list of national / regional
Certificate Authorities is available at
&lt;a href="https://www.eugridpma.org/members/membership">EUGridPMA Membership&lt;/a>; it is
expected that the Resource Centre will obtain the IGTF certificate from a
close Certificate Authority&lt;/li>
&lt;/ul>
&lt;/li>
&lt;li>
&lt;p>For operational purposes, the &lt;code>ops&lt;/code> VO needs to be supported by the Resource
Centre as per Resource Centre OLA. Also at least one community VO that
supports EGI users is expected to be supported by the Resource Centre (i.e.
&lt;code>vo.access.egi.eu&lt;/code> for piloting and prototyping FedCloud usage).&lt;/p>
&lt;/li>
&lt;li>
&lt;p>The public endpoints need to have proper firewall configuration (to allow
inbound external access)&lt;/p>
&lt;/li>
&lt;li>
&lt;p>A flavor (a preset configuration that defines the compute, memory, and storage
capacity - min 8 GB - of an instance) needs to be made available by the site
for monitoring purposes.&lt;/p>
&lt;/li>
&lt;/ul></description></item><item><title>Providers: GOCDB Registration</title><link>/providers/cloud-compute/registration/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/providers/cloud-compute/registration/</guid><description>
&lt;p>Site endpoints must be registered in
&lt;a href="https://goc.egi.eu">EGI Configuration Management Database (GOCDB)&lt;/a>. Cloud
services can coexist within an existing (Grid) site, but we are recommending to
register a new site for the cloud services (as per
&lt;a href="https://confluence.egi.eu/display/EGIPP/PROC09+Resource+Centre+Registration+and+Certification">PROC09 Resource Centre Registration and Certification&lt;/a>
procedure - see
&lt;a href="../../joining/federated-resource-centre/">Joining as a provider&lt;/a> section)&lt;/p>
&lt;h2 id="expected-services">Expected Services&lt;/h2>
&lt;p>These are the expected services for a working site:&lt;/p>
&lt;ul>
&lt;li>
&lt;p>&lt;code>org.openstack.nova&lt;/code> for the Nova endpoint of the site. The &lt;strong>endpoint URL&lt;/strong>
must contain the Keystone v3 URL: &lt;code>https://hostname:port/url/v3&lt;/code>. Set the
&lt;strong>Host DN&lt;/strong> so the cloud-info-provider can be enabled.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;code>eu.egi.cloud.accounting&lt;/code> for the host sending the records to the accounting
repository (executing SSM send). This host needs a valid IGTF-accredited X.509
certificate. Set the &lt;strong>Host DN&lt;/strong> so the SSM can be enabled.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;code>org.openstack.horizon&lt;/code> for the dashboard endpoint of the site (optional). The
endpoint URL field must contain the horizon URL: &lt;code>https://hostname:port/url/&lt;/code>.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>(Optional, if offering object storage) &lt;code>org.openstack.swift&lt;/code> for the swift
endpoint of the site. The &lt;strong>endpoint URL&lt;/strong> field must contain the Keystone v3
URL: &lt;code>https://hostname:port/url/v3&lt;/code>.&lt;/p>
&lt;/li>
&lt;/ul>
&lt;h2 id="deprecated-services">Deprecated services&lt;/h2>
&lt;p>Deprecated services for cloud providers:&lt;/p>
&lt;ul>
&lt;li>
&lt;p>&lt;code>Site-BDII&lt;/code>. This service collects and publishes site's data for the
Information System. There is no need to run a BDII for cloud providers.
&lt;code>eu.egi.cloud.information.bdii&lt;/code> is also deprecated and no longer in use.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;code>eu.egi.cloud.vm-metadata.vmcatcher&lt;/code> for the VMI replication mechanism.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>&lt;code>eu.egi.cloud.vm-management.occi&lt;/code> for the OCCI endpoint offered by the site.
OCCI is no longer in use in FedCloud.&lt;/p>
&lt;/li>
&lt;/ul></description></item><item><title>Providers: OpenStack</title><link>/providers/cloud-compute/openstack/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/providers/cloud-compute/openstack/</guid><description>
&lt;p>This section provides information on how to set up a Resource Centre providing
cloud resources in the EGI infrastructure. Integration with FedCloud requires a
&lt;em>working OpenStack installation&lt;/em> as a pre-requirement. EGI supports any recent
&lt;a href="https://releases.openstack.org">OpenStack version&lt;/a> (tested from OpenStack
Mitaka).&lt;/p>
&lt;p>The following OpenStack services are expected to be available and accessible
from outside the site:&lt;/p>
&lt;ul>
&lt;li>Keystone&lt;/li>
&lt;li>Nova&lt;/li>
&lt;li>Cinder&lt;/li>
&lt;li>Glance&lt;/li>
&lt;li>Neutron&lt;/li>
&lt;li>Swift (if providing Object Storage)&lt;/li>
&lt;/ul>
&lt;p>The integration is performed by a set of EGI components that interact with the
OpenStack services APIs:&lt;/p>
&lt;ul>
&lt;li>&lt;a href="./aai">Authentication and authorization of EGI users&lt;/a> into your system is
performed by configuring the native OpenID Connect support of Keystone&lt;/li>
&lt;li>&lt;strong>cASO&lt;/strong> collects &lt;a href="./accounting">accounting&lt;/a> data from OpenStack and uses
&lt;strong>SSM&lt;/strong> to send the records to the central accounting database on
the &lt;a href="../../../internal/accounting">EGI Accounting service&lt;/a>
(&lt;a href="https://apel.github.io/">APEL&lt;/a>). cASO and SSM are operated by the site.&lt;/li>
&lt;li>EGI runs &lt;a href="./catch-all">catch-all components&lt;/a> &amp;ndash; cloud-info-provider and
cloudkeeper &amp;ndash; information discovery and VM image synchronisation.&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="openstacksite.png" alt="image">&lt;/p>
&lt;h2 id="installation-options">Installation options&lt;/h2>
&lt;p>cASO and SSM releases can be be obtained from GitHub:&lt;/p>
&lt;ul>
&lt;li>&lt;a href="https://github.com/IFCA-Advanced-Computing/caso/releases">cASO&lt;/a>. cASO
containers are available in the
&lt;a href="https://github.com/EGI-Federation/fedcloud-catchall-operations/pkgs/container/fedcloud-caso">fedcloud-caso&lt;/a>
package from
&lt;!-- cspell:disable-next-line -->
&lt;a href="https://github.com/EGI-Federation/fedcloud-catchall-operations">fedcloud-catchall-operations&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://github.com/apel/ssm/releases">SSM&lt;/a>.&lt;/li>
&lt;/ul>
&lt;h2 id="open-ports">Open Ports&lt;/h2>
&lt;h3 id="inbound">Inbound&lt;/h3>
&lt;p>The following &lt;strong>services&lt;/strong> must be accessible to allow access to an
OpenStack-based FedCloud site (default ports listed below, can be adjusted to
your installation).&lt;/p>
&lt;!-- markdownlint-disable line-length -->
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Port&lt;/th>
&lt;th>Application&lt;/th>
&lt;th>Note&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>&lt;strong>5000&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;strong>OpenStack&lt;/strong>/Keystone&lt;/td>
&lt;td>Authentication to your OpenStack.&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>8776&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;strong>OpenStack&lt;/strong>/cinder&lt;/td>
&lt;td>Block Storage management.&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>8774&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;strong>OpenStack&lt;/strong>/nova&lt;/td>
&lt;td>VM management.&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>9696&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;strong>OpenStack&lt;/strong>/neutron&lt;/td>
&lt;td>Network management.&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>9292&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;strong>OpenStack&lt;/strong>/glance&lt;/td>
&lt;td>VM Image management.&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;!-- markdownlint-enable line-length -->
&lt;h3 id="outbound">Outbound&lt;/h3>
&lt;p>The EGI Cloud components require the following outgoing connections open:&lt;/p>
&lt;!-- markdownlint-disable line-length -->
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Port&lt;/th>
&lt;th>Host&lt;/th>
&lt;th>Note&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>&lt;strong>443&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;code>msg.argo.grnet.gr&lt;/code>&lt;/td>
&lt;td>ARGO Messaging System (used to send accounting records by SSM).&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;strong>8443&lt;/strong>/TCP&lt;/td>
&lt;td>&lt;code>msg.argo.grnet.gr&lt;/code>&lt;/td>
&lt;td>AMS authentication (used to send accounting records by SSM).&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;!-- markdownlint-enable line-length -->
&lt;h2 id="users">Users&lt;/h2>
&lt;h3 id="local-users">Local Users&lt;/h3>
&lt;p>In order to get accounting information from your OpenStack, cASO needs to be run
with a user that is a member of the projects to extract accounting information
from and it&amp;rsquo;s allowed to access &lt;code>identity:list_users&lt;/code> and
&lt;code>identity:list_projects&lt;/code> in Keystone. Check
&lt;a href="https://caso.readthedocs.io/en/stable/configuration.html#user-credentials-required">cASO documentation&lt;/a>
for further information.&lt;/p>
&lt;h3 id="federated-users">Federated Users&lt;/h3>
&lt;p>Regular user accounts will be managed by the
&lt;a href="https://docs.openstack.org/keystone/latest/admin/federation/federated_identity.html">Federated Identity&lt;/a>
features of OpenStack. These users are created into a specific OpenStack domain
for every configured identity provider. All users within the &lt;code>egi.eu&lt;/code> domain
will have a unique username. For users whose community identity is managed by
Check-in, this identifier is of the form &lt;code>&amp;lt;uniqueID&amp;gt;@egi.eu&lt;/code>. The &lt;code>&amp;lt;uniqueID&amp;gt;&lt;/code>
portion is an opaque identifier issued by Check-in, for example:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-shell" data-lang="shell">&lt;span style="display:flex;">&lt;span>$ openstack domain list
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+----------------------------------+----------------------------------+---------+---------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> ID &lt;span style="color:#000;font-weight:bold">|&lt;/span> Name &lt;span style="color:#000;font-weight:bold">|&lt;/span> Enabled &lt;span style="color:#000;font-weight:bold">|&lt;/span> Description &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+----------------------------------+----------------------------------+---------+---------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> 0125ed0ebc8045a49ed8c34c2a78740d &lt;span style="color:#000;font-weight:bold">|&lt;/span> 0125ed0ebc8045a49ed8c34c2a78740d &lt;span style="color:#000;font-weight:bold">|&lt;/span> True &lt;span style="color:#000;font-weight:bold">|&lt;/span> Auto generated federated domain &lt;span style="color:#204a87;font-weight:bold">for&lt;/span> Identity Provider: egi.eu &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> default &lt;span style="color:#000;font-weight:bold">|&lt;/span> Default &lt;span style="color:#000;font-weight:bold">|&lt;/span> True &lt;span style="color:#000;font-weight:bold">|&lt;/span> The default domain &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+----------------------------------+----------------------------------+---------+---------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>$ openstack user list --domain 0125ed0ebc8045a49ed8c34c2a78740d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+------------------------------------------------------------------+-------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> ID &lt;span style="color:#000;font-weight:bold">|&lt;/span> Name &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+------------------------------------------------------------------+-------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> 2c096b11a1410d44e3936fa40479ad26eaa649cfd6887f06b3c6669e5d6c03d0 &lt;span style="color:#000;font-weight:bold">|&lt;/span> efb8534478028XXXXXXXXXXXXXXXfeed9766fafc@sram.surf.nl &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> 933c692b53192e4d893e5ed5c026aa444acb4d75f6ee6c304422861207ce1ea5 &lt;span style="color:#000;font-weight:bold">|&lt;/span> e9c37aa0d1XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX2867bc43581b835c@egi.eu &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> d52112709a37975903576f80f37dde4604d1a227c53cb1fef43c45981673640c &lt;span style="color:#000;font-weight:bold">|&lt;/span> 529a87e5ceXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXe714cb1309cc3907@egi.eu &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+------------------------------------------------------------------+-------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>If you have set the email of the user in the mapping, you will be able to also
get this information:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-shell" data-lang="shell">&lt;span style="display:flex;">&lt;span>$ openstack user show d52112709a37975903576f80f37dde4604d1a227c53cb1fef43c45981673640c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+---------------------+------------------------------------------------------------------------------------------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> Field &lt;span style="color:#000;font-weight:bold">|&lt;/span> Value &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+---------------------+------------------------------------------------------------------------------------------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> domain_id &lt;span style="color:#000;font-weight:bold">|&lt;/span> 0125ed0ebc8045a49ed8c34c2a78740d &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> email &lt;span style="color:#000;font-weight:bold">|&lt;/span> XXXX-redacted@example.com &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> enabled &lt;span style="color:#000;font-weight:bold">|&lt;/span> True &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> federated &lt;span style="color:#000;font-weight:bold">|&lt;/span> &lt;span style="color:#ce5c00;font-weight:bold">[{&lt;/span>&lt;span style="color:#4e9a06">&amp;#39;idp_id&amp;#39;&lt;/span>: &lt;span style="color:#4e9a06">&amp;#39;egi.eu&amp;#39;&lt;/span>, &lt;span style="color:#4e9a06">&amp;#39;protocols&amp;#39;&lt;/span>: &lt;span style="color:#ce5c00;font-weight:bold">[{&lt;/span>&lt;span style="color:#4e9a06">&amp;#39;protocol_id&amp;#39;&lt;/span>: &lt;span style="color:#4e9a06">&amp;#39;openid&amp;#39;&lt;/span>, &lt;span style="color:#4e9a06">&amp;#39;unique_id&amp;#39;&lt;/span>: &lt;span style="color:#4e9a06">&amp;#39;529a87e5ceXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXe714cb1309cc3907%40egi.eu&amp;#39;&lt;/span>&lt;span style="color:#ce5c00;font-weight:bold">}]}]&lt;/span> &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> id &lt;span style="color:#000;font-weight:bold">|&lt;/span> d52112709a37975903576f80f37dde4604d1a227c53cb1fef43c45981673640c &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> name &lt;span style="color:#000;font-weight:bold">|&lt;/span> 529a87e5ceXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXe714cb1309cc3907@egi.eu &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> options &lt;span style="color:#000;font-weight:bold">|&lt;/span> &lt;span style="color:#ce5c00;font-weight:bold">{}&lt;/span> &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#000;font-weight:bold">|&lt;/span> password_expires_at &lt;span style="color:#000;font-weight:bold">|&lt;/span> None &lt;span style="color:#000;font-weight:bold">|&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>+---------------------+------------------------------------------------------------------------------------------------------------------------------------------------------------+
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Every VO has a VO identity card available via the
&lt;a href="https://operations-portal.egi.eu/vo/a/list">Operations Portal&lt;/a>, where you can
also get contact information for the VO managers.&lt;/p>
&lt;p>VMs created by
&lt;a href="../../../users/compute/orchestration/im/">EGI&amp;rsquo;s Infrastructure Manager&lt;/a> have
additional metadata properties that can help to identify the workload:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-shell" data-lang="shell">&lt;span style="display:flex;">&lt;span>$ openstack server show 0f3e1420-4480-4bea-95f1-9920a70b324d -c properties -f yaml
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>properties:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> eu.egi.cloud.orchestrator: es.upv.grycap.im
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> eu.egi.cloud.orchestrator.id: 0afdc7ba-bf5d-11ed-9e89-86ce117c3fcf
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> eu.egi.cloud.orchestrator.url: https://im.egi.eu/im
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> eu.egi.cloud.orchestrator.user: __OPENID__XXXXXXredacted
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div></description></item><item><title>Providers: Installation Validation</title><link>/providers/cloud-compute/validation/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/providers/cloud-compute/validation/</guid><description>
&lt;p>Once the site services are registered in GOCDB (and flagged as &amp;quot;monitored&amp;quot;)
they will appear in the EGI service monitoring tools. EGI will check the status
of the services. Check if your services are present in the EGI service
monitoring tools and passing the tests; if you experience any issues (services
not shown, services are not OK...) please contact back EGI Operations or your
reference Resource Infrastructure.&lt;/p>
&lt;p>Extra checks for your installation:&lt;/p>
&lt;ul>
&lt;li>
&lt;p>Check in &lt;a href="https://argo.egi.eu/egi/CriticalUncert">ARGO&lt;/a> that your services are
listed and are passing the tests. If all the tests are OK, your installation
is already in good shape.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Check that all the images listed in the AppDB for the VOs you support (e.g.
&lt;a href="https://appdb.egi.eu/store/vo/vo.access.egi.eu">AppDB page for vo.access.egi.eu VO&lt;/a>)
are listed in your BDII. This sample query will return all the template IDs
registered in your BDII: :&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-shell" data-lang="shell">&lt;span style="display:flex;">&lt;span>ldapsearch -x -h &amp;lt;site bdii host&amp;gt; -p &lt;span style="color:#0000cf;font-weight:bold">2170&lt;/span> -b &lt;span style="color:#000">Glue2GroupID&lt;/span>&lt;span style="color:#ce5c00;font-weight:bold">=&lt;/span>cloud,Glue2DomainID&lt;span style="color:#ce5c00;font-weight:bold">=&lt;/span>&amp;lt;your site name&amp;gt;,o&lt;span style="color:#ce5c00;font-weight:bold">=&lt;/span>glue &lt;span style="color:#000">objectClass&lt;/span>&lt;span style="color:#ce5c00;font-weight:bold">=&lt;/span>GLUE2ApplicationEnvironment GLUE2ApplicationEnvironmentRepository
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;/li>
&lt;li>
&lt;p>Try to start one of those images in your cloud. You can do it with
[onetemplate instantiate]{.title-ref} or OCCI commands, the result should be
the same.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Execute the
&lt;a href="../../../providers/operations-manuals/howto04_site_certification_manual_tests/#check-the-functionality-of-the-cloud-elements">site certification manual tests&lt;/a>
against your endpoints.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Check in the &lt;a href="https://accounting.egi.eu/">accounting portal&lt;/a> that your site is
listed and the values reported look consistent with the usage of your site.&lt;/p>
&lt;/li>
&lt;/ul></description></item><item><title>Providers: FAQ</title><link>/providers/cloud-compute/faq/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/providers/cloud-compute/faq/</guid><description>
&lt;h2 id="why-joining-the-egi-cloud">Why joining the EGI Cloud?&lt;/h2>
&lt;ul>
&lt;li>To support international communities supported by EGI (e.g.
&lt;a href="https://www.egi.eu/use-cases/">research communities and applications&lt;/a>
or
&lt;a href="https://www.egi.eu/publication/egi-support-for-research-infrastructures/">research infrastructures&lt;/a>
or
&lt;a href="https://eosc-dih.eu/pilots/">business pilots in the EOSC Digital Innovation Hub&lt;/a>.&lt;/li>
&lt;li>To participate in e-Infrastructure projects (H2020, EOSC) as an EGI compliant
IaaS cloud provider.&lt;/li>
&lt;li>To participate in resource allocation and in pay-for-use campaigns run by EGI.&lt;/li>
&lt;li>To align access policies and operational model of your cloud with
international good practices.&lt;/li>
&lt;li>To adopt best practices of multi-cloud federation for the benefit of your
local users.&lt;/li>
&lt;/ul>
&lt;h2 id="do-i-lose-control-on-who-can-access-my-resources-if-i-join-federated-cloud">Do I lose control on who can access my resources if I join federated cloud?&lt;/h2>
&lt;p>&lt;strong>No&lt;/strong>. EGI uses the concept of Virtual Organisation (VO) to group users. The
resource provider has complete control on which VOs he wants to allow on its
resources and which quotas or restrictions to assign to each VO. In the case of
OpenStack, each VO is mapped to a regular OpenStack project that can be managed
as any other and are isolated to other projects you may have configured in your
deployment. Although not recommended, you can even restrict the automatic access
of users within a VO and manually enable individual members.&lt;/p>
&lt;h2 id="how-many-components-do-i-have-to-install">How many components do I have to install?&lt;/h2>
&lt;p>Depending on your cloud management framework and the kind of integration this
will vary.&lt;/p>
&lt;p>In general, the federation requires your cloud management framework to be
configured to support Federated AAI with EGI Check-in. This may require changes
in your current setup.&lt;/p>
&lt;p>Other components are designed to access your cloud management framework public
APIs and do not require modification of your deployment. For OpenStack, these
components can be run on a single VM that encapsulates them for convenience.&lt;/p>
&lt;h2 id="which-components-of-my-cloud-will-interact-with-the-federated-cloud-components">Which components of my cloud will interact with the federated cloud components?&lt;/h2>
&lt;p>For OpenStack they are:&lt;/p>
&lt;ul>
&lt;li>Keystone&lt;/li>
&lt;li>Nova&lt;/li>
&lt;li>Glance&lt;/li>
&lt;li>Swift (optional)&lt;/li>
&lt;/ul>
&lt;p>Users will also interact with:&lt;/p>
&lt;ul>
&lt;li>Neutron&lt;/li>
&lt;li>Cinder&lt;/li>
&lt;/ul>
&lt;p>to perform their regular activities.&lt;/p>
&lt;h2 id="how-will-my-daily-operational-activities-change">How will my daily operational activities change?&lt;/h2>
&lt;p>For the most part daily operations will not change.&lt;/p>
&lt;p>A resource centre part of the EGI Federation, and supporting international
communities, needs to provide support through the EGI channels. This means
following up &lt;a href="https://helpdesk.ggus.eu">GGUS tickets&lt;/a>. This includes requests
from user communities and tickets triggered by failures detected by the
monitoring infrastructure.&lt;/p>
&lt;p>A resource centre needs to maintain the services federated in EGI properly
configured with the EGI AAI.&lt;/p>
&lt;p>The resource centre will have to comply with the operational and security
requirements. All the EGI policies aim at implementing service provisioning best
practices and common requirements. EGI operations may conduct campaigns targeted
to mitigate security vulnerabilities and to update unsupported operating system
and software. These activities are part of the regular activities of a resource
centre anyway (also for the non-federated ones). EGI and the Operations Centres
coordinate these actions in order to have them implemented in a timely manner.&lt;/p>
&lt;p>In summary, most of the site activities that are coordinated by EGI and the NGIs
are already part of the work plan of a well-maintained resource centre, the
additional task for a site manager is to acknowledge to EGI that the task has
been performed.&lt;/p></description></item></channel></rss>