maintaining individual traceability in shared project
play

Maintaining Individual Traceability in Shared Project Accounts with - PowerPoint PPT Presentation

Maintaining Individual Traceability in Shared Project Accounts with CEDPS/VDT Tools Shreyas Cholia Software Group, NERSC OSG All Hands-Meeting, Baton Rouge LA, March 2009 Motivation for Project Accounts at NERSC Analogous to OSG group


  1. Maintaining Individual Traceability in Shared Project Accounts with CEDPS/VDT Tools Shreyas Cholia Software Group, NERSC OSG All Hands-Meeting, Baton Rouge LA, March 2009

  2. Motivation for Project Accounts at NERSC • Analogous to OSG group accounts • Needed by scientific groups for collaborative computing • Jobs and data owned by common UNIX user • Allow multiple users to share files and manage jobs, … without relying on group UNIX permissions, … while maintaining individual accountability • Built around standard OSG/VDT grid tools – Netlogger – GSISSH – GridFTP/GRAM – MyProxy

  3. Project Account Implementation • Use grid certificates to track “real” user performing a given operation – DOE and NIST guidelines require individual level traceability for actions on NERSC systems • Limit access to project accounts to grid interfaces (GSISSH, GridFTP, WS-GRAM) • Scrape log and accounting files on the system to track process tree – Parent Process ID logs (To track child processes) – GSISSH/SSH logs – GridFTP logs – WS-GRAM logs – PBS/SGE/Loadleveler job accounting records • Feed logs into netlogger to reconcile job/file information with original user – Query database to return the real user associated with a given action

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend