- User Pool
- User Schedd
Prerequisite Component Installation
|Software||Version||WMS collector||Factory||User collector||Submit||Glidein Frontend||Comments|
|Linux OS||y||y||y||y||y||A reasonably recent Condor-supported Linux OS (RH/SL5 tested at press time).|
|HTCondor||v7.2.+||y||y||y||y||The installer will use the tarball or rpm to install and configure Condor inline. It is recommended to use v7.4 and above.|
|OSG client||current version||y||y||y||y||Needed to generate grid/voms proxies. See below for instructions.|
|HTTP server||y||y||Apache, TUX or whatever server of choice. This port will need open access to the internet, so worker nodes can download data from this service.|
The perl-Time-HiRes rpm is needed for this package. Please verify all dependencies:
|M2Crypto||v0.17+||y||y||This can be installed using yum, if available. Or via tarball.|
- HTCondor version v7.3.1 has a known issue with incorrect return/exit codes of condor_status and condor_q
If you are using HTCondor version v7.3.2 disable VOMS checking in condor_config file used by Condor daemons other
than that used by user schedd. VOMS checking adds unrequired overhead. To do so, set
USE_VOMS_ATTRIBUTES = Falseor for individual condor daemons like collector
COLLECTOR.USE_VOMS_ATTRIBUTES = False
1. HTTP server
You will need to install an HTTP server for GlideinWMS to be used for staging and monitoring. This needs to be installed on a port accessible to the outside. The server should be installed on the same node, but a different node can be used as long as the web area is writable from this one. In particular, the staging directory will need to be accessible to glideins so they can download appropriate software.
The choice of web server is independent of glideinWMS, but this documentation will only show the example of Apache Web Server. For most systems, this can be installed via yum:
yum install httpd
Other options are available from Apache here.
There are several recommended tasks you may want to also do post-installation to secure and prepare your web server.
- Disable all unneeded modules. Glideinwms does not any non-standard modules and many can be disabled. A list of example modules to keep enabled is below: 'access_module','include_module','log_config_module', 'mime_magic_module','expires_module','deflate_module', 'headers_module','setenvif_module','mime_module', 'status_module','autoindex_module','negotiation_module', 'dir_module','imap_module','alias_module','rewrite_module', 'cache_module','file_cache_module','mem_cache_module', 'authz_host_module','authz_default_module'.
- Disable any (unneeded) extensions in /etc/httpd/conf.d
- Recommended: disable indexes (Options -Indexes) in all directories/locations, such as frontend/factory stage/monitor directories.
2. OSG Client
The OSG Client (formerly known as VDT Client) is now available as a set of RPMs. OSG provides a complete set of instructions that that we recommend. Here folow a short version to install OSG Client on RHEL6 based systems (including CentOS and SL). First you will need to enable the EPEL and OSG repositories. It is also advisable to enable the yum priorities module in order to guarantee the correct packages. The following commands will enable the repositories:
rpm -Uvh http://download.fedoraproject.org/pub/epel/6/i386/epel-release-6-8.noarch.rpm yum install yum-priorities yum install http://repo.grid.iu.edu/osg/3.2/osg-3.2-el6-release-latest.rpmNext, you can install the CA certificates and OSG client:
yum install osg-ca-certs yum install osg-clientYou may also want to enable the fetch-crl service to keep your certificate revocation lists up to date:
fetch-crl /sbin/service fetch-crl-boot start /sbin/service fetch-crl-cron start /sbin/chkconfig fetch-crl-boot on /sbin/chkconfig fetch-crl-cron onIf you have no root privileges, OSG Client is available also in a tarball distribution check here for more information.
You will also need the python module for RRDTool (v1.2.18 or later). Many systems come with packages for it; if possible use that.
RPMs for Redhat/Scientific Linux distributions can be found
However, if you have the OSG repositories enabled, you can install it via yum:
yum install rrdtool rrdtool-python
If installing as root is not an option, you can build from the sources, as the glidein factory
user, and put the python libraries into the PYTHON_PATH.
The source code can be downloaded from here. Beware: The build process has several dependencies that make it complicated. Use this option only if you cannot install from RPMs (or similar).
You will need the M2Crypto python library. However, if you have the OSG repositories enabled, you can install it via yum:
yum install m2crypto
If your system does not come with m2crypto package, or you do not can/want install it as root, compile it from source as
the glidein factory user.
The source code can be downloaded from here.
The build process is very easy:
python setup.py build
python setup.py install --root <base dir>
Finally add M2Crypto site-packages into the PYTHONPATH, possibly in the .profile, .bashrc and/or in the .cshrc.
The exact path is system specific. On a 32bit system with python 2.3.x it will look like this:
export PYTHONPATH=$PYTHONPATH:<base dir>/usr/lib/python2.3/site-packages/
Otherwise, download the tarball (with flot), and untar it. You will need to point the installer to this directory. The installer will copy the library files to the Web directories during the installation or reconfig steps.