Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Date

Attendees

Goals

  • Status updates and planning

Discussion items

TimeItemWhoNotes
PDAC notebooks


  • Existing PDAC notebook ticket 
    Jira
    serverJIRA
    columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
    serverId9da94fb6-5771-303d-a785-1b6c5ab0f2d2
    keyIHS-1164
    should be closed out.
  • Instead, notebooks are to be set up on PDAC k8s cluster on the old SUIT proxy node
 Kubernetes Commons transition 
  • All of PDAC will transfer into Kubernetes Commons, anticipated in October
  • Gated on NCSA resource availability for setting up namespace, moving hardware, etc.
  • Plans for transition from PDAC to Kubernetes Commons to be discussed by Unknown User (mbutler) and Fritz Mueller at LSST2018; will be documented in Confluence page
  • Also should document current and near-future PDAC state/design

"lsp-demo"
  • In the longer term, a separate controlled, certified Kubernetes environment will be exposed to the Internet for demos.
  • Should consider whether this can be combined with PDAC, as it serves many of the same purposes.

/scratch
  • /scratch open to root for next two weeks to support Firefly for review demo
  • Snapshots turned on during that time to avoid data loss

Firefly non-root user
  • Firefly containers need to be run as non-root after two weeks
  • Might be configured in Dockerfile; might also be configured in Kubernetes
  • IPAC will investigate

FY2019 provisioning

Container Standards Guide
  • Standards guide for container development and Kubernetes would be useful, especially regarding settings related to security

Security
  • Container build file and itself should be vetted by NCSA security

Action items

  •