GEANT4EOSC demo services on SURF Research Cloud: eLabFTW, FileSender, AyakaLeaf
  • Python 52.5%
  • Jinja 38%
  • Shell 4.8%
  • Makefile 4.7%
Find a file
Richard Freitag 0c9a617222 BigBlueButton: tests against a real workspace (make test-bigbluebutton)
BigBlueButton doesn't fit the stand-in: the tests check a workspace
the component runs on (default bbb4eoscdev; BBB_SSH from the
environment, no usernames in the repository), from outside and over
SSH: what needs the SRC login and what doesn't, BigBlueButton's own
check, FreeSWITCH's address, the storage volume, the API secret,
TURN, Greenlight's settings, branding, permissions, and a second run
changing nothing. 19 pass on bbb4eoscdev, 18 (without the run) on
bbb4eosc.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-10 20:23:57 +01:00
deploy BigBlueButton: tests against a real workspace (make test-bigbluebutton) 2026-10-10 20:23:57 +01:00
scripts eduMEET as an SRC component, with the SRC login (via Dex) 2026-10-09 11:10:47 +01:00
tests BigBlueButton: tests against a real workspace (make test-bigbluebutton) 2026-10-10 20:23:57 +01:00
.gitignore RSpace as an SRC component, with the SRC login 2026-10-08 17:14:27 +01:00
CLAUDE.md BigBlueButton with Greenlight as an SRC component (first version) 2026-10-10 17:37:35 +01:00
Makefile BigBlueButton: tests against a real workspace (make test-bigbluebutton) 2026-10-10 20:23:57 +01:00
README.md BigBlueButton: optional logos for Greenlight (bbb_branding), GÉANT's on both instances 2026-10-10 19:51:07 +01:00

GEANT4EOSC demo services

GEANT4EOSC is a showcase of services that can be offered through SURF Research Cloud (SRC). Any member of the collaboration (the SRC/SRAM CO geant4eosc) logs on with their single sign-on identity. The workspaces run on the SURF HPC Cloud and are co-managed by SURF's technical staff and the members of the CO. Overview and access: https://geant.dev/geant4eosc/ (request access).

Service Address SRC workspace Component
Meetings (BigBlueButton) https://bbb4eosc.geant.dev bbb4eosc.geant4eosc.src.surf-hosted.nl this repository, deploy/src/bigbluebutton/application-bigbluebutton.yml
Lab notebook (RSpace) https://rspace4eosc.geant.dev rspace4eosc.geant4eosc.src.surf-hosted.nl this repository, deploy/src/rspace/application-rspace.yml
Lab notebook (eLabFTW) https://eln4eosc.geant.dev eln4eosc.geant4eosc.src.surf-hosted.nl freitaglab deploy/src/elabftw/application-elabftw.yml
File transfer (FileSender) https://filesender4eosc.geant.dev filesender4eosc.geant4eosc.src.surf-hosted.nl sunet/filesender deploy/src/filesender/application-filesender.yml
LaTeX (AyakaLeaf) https://tex4eosc.geant.dev ayakaleaf4eosc.geant4eosc.src.surf-hosted.nl freitaglab deploy/src/ayakaleaf/application-ayakaleaf.yml
Notebooks (JupyterLab) https://jupyter4eosc.geant.dev jupyter4eosc.geant4eosc.src.surf-hosted.nl SURF's application-jupyter application-jupyter.yml

Each workspace comes from an SRC catalog item: SRC-OS, SRC-CO, SRC-nginx, then the component (see the component's README for parameters and sizing). This repository holds what is specific to the showcase: which VM is which service, and their pretty names.

RSpace (component in this repository)

The lab notebook RSpace is an SRC component of its own here: deploy/src/rspace (catalog item: SRC-OS, SRC-CO, SRC-nginx, then deploy/src/rspace/application-rspace.yml from https://code.geant.dev/geant4eosc/demoservices.git; parameters and design in its README). Pretty name: make rspace (deploy/custom-domain-rspace.yml, with deploy/roles/custom_domain). Tested on a stand-in workspace with make srcvm-test-rspace and make srcvm-domain-test-rspace (needs SRC's plugin-nginx in ../src-plugins).

eduMEET (component in this repository)

Video meetings: deploy/src/edumeet (catalog item: SRC-OS, SRC-CO, SRC-nginx, then deploy/src/edumeet/application-edumeet.yml; parameters, firewall ports and design in its README). Pretty name: make meet. Tested with make srcvm-test-edumeet and make srcvm-domain-test-edumeet.

BigBlueButton (component in this repository)

Video meetings with BigBlueButton 3.0 and Greenlight: deploy/src/bigbluebutton (catalog item: SRC-OS, SRC-CO, SRC-nginx, then deploy/src/bigbluebutton/application-bigbluebutton.yml; parameters, firewall ports and design in its README). Pretty name: make bbb (deploy/custom-domain-bigbluebutton.yml). https://bbb4eosc.geant.dev.

Pretty names

SRC names the workspaces <name>.geant4eosc.src.surf-hosted.nl. The *.geant.dev names are added afterwards, over SSH, with the components' custom-domain playbooks: the app is configured for the pretty name, nginx gets a Let's Encrypt certificate for it, SRC's login returns via the SRC name, and the SRC name redirects browsers to the pretty name (302 for now).

git clone https://code.geant.dev/freitaglab/freitaglab.git ../freitaglab
git clone https://code.geant.dev/sunet/filesender.git ../filesender
make pretty-names SRC_USER=<your SRC username> [CHECK=1]    # or: make eln / filesender / tex / jupyter

deploy/inventory.ini lists the VMs (IP address, pretty name). Run it again after SRC reruns a component (that sets the address back to the SRC name). Admins: eLabFTW makes the first account a sysadmin; for AyakaLeaf and FileSender add ayakaleaf_admins= / filesender_admins= (SRC usernames) in a local copy, deploy/inventory.local.ini (gitignored), and run with INVENTORY=deploy/inventory.local.ini. FileSender's admins are its configuration: a run without them removes them.

JupyterLab is SURF's component, so its pretty-name playbook is here (and RSpace's, see above): deploy/custom-domain-jupyter.yml with deploy/roles/custom_domain (the same role as in freitaglab and sunet/filesender; JupyterHub itself needs no change, it uses relative addresses and the Host header). If sudo on a VM asks for a password, add BECOME_PASS=1.

Note on SURF's Jupyter component: JupyterHub listens on 127.0.0.1:8000 and trusts the REMOTE_USER request header from anyone, so a user with a shell on the VM can log in to JupyterHub as another user (and run code as them) by sending that header to the local port. Our components avoid this (header names with a secret, Dex, or a Unix socket only nginx opens); worth reporting to SURF.

Logos

All services except JupyterLab show the GÉANT logo and, as favicon, the GÉANT symbol, set per VM in deploy/host_vars/ with the components' branding options (images on geant.dev, checksums pinned; the logos are not in this repository):

  • eln4eosc.yml: freitaglab's elabftw_branding (header, login page, favicon), make eln
  • tex4eosc.yml: freitaglab's ayakaleaf_branding (navigation bar, favicon), make tex
  • filesender4eosc.yml: sunet/filesender's filesender_branding (logo, favicon), make filesender
  • rspace4eosc.yml: rspace_branding (header logo, favicon) and links to the GEANT4EOSC page, make deploy-rspace (or make rspace)
  • edumeet4eosc.yml, edumeet4eoscdev.yml: edumeet_branding (logo in a white frame for the dark top bar, favicon), make deploy-edumeet (or make meet)
  • bbb4eosc.yml, bbb4eoscdev.yml: bbb_branding (Greenlight's logo, favicon) and GÉANT blue as Greenlight's colours, make deploy-bigbluebutton (or make bbb)

SURF HPC Cloud

The VMs run on the SURF HPC Cloud instead of SUNET's cloud; for the components that makes no difference (checked 2026-10-03): Ubuntu 22.04, SRC's plugin-nginx with acme.sh, port 80 open for Let's Encrypt, the SRC name is the VM's FQDN.