- Python 52.5%
- Jinja 38%
- Shell 4.8%
- Makefile 4.7%
BigBlueButton doesn't fit the stand-in: the tests check a workspace the component runs on (default bbb4eoscdev; BBB_SSH from the environment, no usernames in the repository), from outside and over SSH: what needs the SRC login and what doesn't, BigBlueButton's own check, FreeSWITCH's address, the storage volume, the API secret, TURN, Greenlight's settings, branding, permissions, and a second run changing nothing. 19 pass on bbb4eoscdev, 18 (without the run) on bbb4eosc. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| deploy | ||
| scripts | ||
| tests | ||
| .gitignore | ||
| CLAUDE.md | ||
| Makefile | ||
| README.md | ||
GEANT4EOSC demo services
GEANT4EOSC is a showcase of services that can be offered through SURF Research Cloud (SRC). Any
member of the collaboration (the SRC/SRAM CO geant4eosc) logs on with their single sign-on
identity. The workspaces run on the SURF HPC Cloud and are co-managed by SURF's technical staff
and the members of the CO. Overview and access: https://geant.dev/geant4eosc/
(request access).
| Service | Address | SRC workspace | Component |
|---|---|---|---|
| Meetings (BigBlueButton) | https://bbb4eosc.geant.dev | bbb4eosc.geant4eosc.src.surf-hosted.nl | this repository, deploy/src/bigbluebutton/application-bigbluebutton.yml |
| Lab notebook (RSpace) | https://rspace4eosc.geant.dev | rspace4eosc.geant4eosc.src.surf-hosted.nl | this repository, deploy/src/rspace/application-rspace.yml |
| Lab notebook (eLabFTW) | https://eln4eosc.geant.dev | eln4eosc.geant4eosc.src.surf-hosted.nl | freitaglab deploy/src/elabftw/application-elabftw.yml |
| File transfer (FileSender) | https://filesender4eosc.geant.dev | filesender4eosc.geant4eosc.src.surf-hosted.nl | sunet/filesender deploy/src/filesender/application-filesender.yml |
| LaTeX (AyakaLeaf) | https://tex4eosc.geant.dev | ayakaleaf4eosc.geant4eosc.src.surf-hosted.nl | freitaglab deploy/src/ayakaleaf/application-ayakaleaf.yml |
| Notebooks (JupyterLab) | https://jupyter4eosc.geant.dev | jupyter4eosc.geant4eosc.src.surf-hosted.nl | SURF's application-jupyter application-jupyter.yml |
Each workspace comes from an SRC catalog item: SRC-OS, SRC-CO, SRC-nginx, then the component (see the component's README for parameters and sizing). This repository holds what is specific to the showcase: which VM is which service, and their pretty names.
RSpace (component in this repository)
The lab notebook RSpace is an SRC component of its own here: deploy/src/rspace (catalog item:
SRC-OS, SRC-CO, SRC-nginx, then deploy/src/rspace/application-rspace.yml from
https://code.geant.dev/geant4eosc/demoservices.git; parameters and design in its
README). Pretty name: make rspace (deploy/custom-domain-rspace.yml,
with deploy/roles/custom_domain). Tested on a stand-in workspace with make srcvm-test-rspace
and make srcvm-domain-test-rspace (needs SRC's plugin-nginx in ../src-plugins).
eduMEET (component in this repository)
Video meetings: deploy/src/edumeet (catalog item: SRC-OS, SRC-CO, SRC-nginx, then
deploy/src/edumeet/application-edumeet.yml; parameters, firewall ports and design in its
README). Pretty name: make meet. Tested with
make srcvm-test-edumeet and make srcvm-domain-test-edumeet.
BigBlueButton (component in this repository)
Video meetings with BigBlueButton 3.0 and Greenlight: deploy/src/bigbluebutton (catalog item:
SRC-OS, SRC-CO, SRC-nginx, then deploy/src/bigbluebutton/application-bigbluebutton.yml;
parameters, firewall ports and design in its README).
Pretty name: make bbb (deploy/custom-domain-bigbluebutton.yml). https://bbb4eosc.geant.dev.
Pretty names
SRC names the workspaces <name>.geant4eosc.src.surf-hosted.nl. The *.geant.dev names are
added afterwards, over SSH, with the components' custom-domain playbooks: the app is configured
for the pretty name, nginx gets a Let's Encrypt certificate for it, SRC's login returns via the
SRC name, and the SRC name redirects browsers to the pretty name (302 for now).
git clone https://code.geant.dev/freitaglab/freitaglab.git ../freitaglab
git clone https://code.geant.dev/sunet/filesender.git ../filesender
make pretty-names SRC_USER=<your SRC username> [CHECK=1] # or: make eln / filesender / tex / jupyter
deploy/inventory.ini lists the VMs (IP address, pretty name). Run it again after SRC reruns a
component (that sets the address back to the SRC name). Admins: eLabFTW makes the first account
a sysadmin; for AyakaLeaf and FileSender add ayakaleaf_admins= / filesender_admins= (SRC
usernames) in a local copy, deploy/inventory.local.ini (gitignored), and run with
INVENTORY=deploy/inventory.local.ini. FileSender's admins are its configuration: a run without
them removes them.
JupyterLab is SURF's component, so its pretty-name playbook is here (and RSpace's, see above):
deploy/custom-domain-jupyter.yml with deploy/roles/custom_domain (the same role as in
freitaglab and sunet/filesender; JupyterHub itself needs no change, it uses relative addresses
and the Host header). If sudo on a VM asks for a password, add BECOME_PASS=1.
Note on SURF's Jupyter component: JupyterHub listens on 127.0.0.1:8000 and trusts the
REMOTE_USER request header from anyone, so a user with a shell on the VM can log in to
JupyterHub as another user (and run code as them) by sending that header to the local port.
Our components avoid this (header names with a secret, Dex, or a Unix socket only nginx opens);
worth reporting to SURF.
Logos
All services except JupyterLab show the GÉANT logo and, as favicon, the GÉANT symbol, set per VM in
deploy/host_vars/ with the components' branding options (images on geant.dev, checksums
pinned; the logos are not in this repository):
eln4eosc.yml: freitaglab'selabftw_branding(header, login page, favicon),make elntex4eosc.yml: freitaglab'sayakaleaf_branding(navigation bar, favicon),make texfilesender4eosc.yml: sunet/filesender'sfilesender_branding(logo, favicon),make filesenderrspace4eosc.yml:rspace_branding(header logo, favicon) and links to the GEANT4EOSC page,make deploy-rspace(ormake rspace)edumeet4eosc.yml,edumeet4eoscdev.yml:edumeet_branding(logo in a white frame for the dark top bar, favicon),make deploy-edumeet(ormake meet)bbb4eosc.yml,bbb4eoscdev.yml:bbb_branding(Greenlight's logo, favicon) and GÉANT blue as Greenlight's colours,make deploy-bigbluebutton(ormake bbb)
SURF HPC Cloud
The VMs run on the SURF HPC Cloud instead of SUNET's cloud; for the components that makes no difference (checked 2026-10-03): Ubuntu 22.04, SRC's plugin-nginx with acme.sh, port 80 open for Let's Encrypt, the SRC name is the VM's FQDN.