OCM test services on SURF Research Cloud
Find a file
Richard Freitag 89264551a6 README: the drive servers are deployed outside this repository
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 11:21:00 +01:00
deploy opencloud4ocm.geant.dev in the OCM federation 2026-10-07 15:01:03 +01:00
.gitignore OCM test services: Nextcloud and OpenCloud with pretty names and trust 2026-10-07 02:19:12 +01:00
CLAUDE.md OCM test services: Nextcloud and OpenCloud with pretty names and trust 2026-10-07 02:19:12 +01:00
federation.json opencloud4ocm.geant.dev in the OCM federation 2026-10-07 15:01:03 +01:00
Makefile nextcloud4ocm in the OCM federation (federation.json); make nextcloud-app 2026-10-07 11:58:07 +01:00
README.md README: the drive servers are deployed outside this repository 2026-10-08 11:21:00 +01:00

OCM test services

A test collaboration for Open Cloud Mesh (OCM) on SURF Research Cloud (SRC): a Nextcloud and an OpenCloud instance that form a trusted federation and share with each other after an invitation. Overview and access: https://geant.dev/ocm/ (request access).

Service Address SRC workspace (CO opencloudmeshoc) Component
Nextcloud (OCM invitations in Contacts) https://nextcloud4ocm.geant.dev nextcloud4ocm.opencloudmeshoc.src.surf-hosted.nl geant/panes3 deploy/src/nextcloud/application-nextcloud.yml
OpenCloud (OCM invitations in ScienceMesh) https://opencloud4ocm.geant.dev opencloud4ocm.opencloudmeshoc.src.surf-hosted.nl geant/panes3 deploy/src/opencloud/application-opencloud.yml

Other members of the federation (PanES3's Nextclouds, CO geantpanes3: access through the PanES3 collaboration; deployed with geant/panes3's playbooks, outside this repository):

Service Address Note
PanES3 Nextcloud https://drive.geant.dev production; on https://geant.dev/ocm/
PanES3 test Nextcloud https://drive.test.geant.dev for testing only, not on the website

Each workspace comes from an SRC catalog item: SRC-OS, SRC-CO, SRC-nginx, then the component (see its README in panes3 for parameters). This repository holds what is specific to these tests: which VM is which service, their pretty names and the trust between them.

Pretty names and trust

The *.geant.dev names are added afterwards over SSH with panes3's custom-domain playbooks (the app configured for the pretty name, a Let's Encrypt certificate, SRC's login returning via the SRC name, the SRC name redirecting browsers; OCM, discovery and status keep working under the SRC name). For OpenCloud this runs its role again with the pretty name and with opencloud_ocm_providers from deploy/inventory.ini: OpenCloud federates only with the instances listed there (here: the Nextcloud).

git clone https://code.geant.dev/geant/panes3.git ../panes3
make pretty-names SRC_USER=<your SRC username> [CHECK=1]    # or: make nextcloud / opencloud

Run it again after SRC reruns a component (that sets the address back to the SRC name). Admins: opencloud_admins= / panes3's Nextcloud settings in a local copy, deploy/inventory.local.ini (gitignored), INVENTORY=deploy/inventory.local.ini; the OpenCloud run without opencloud_admins leaves nobody admin.

Federation for OCM invitations

federation.json lists the Nextcloud servers that form one OCM federation for invitations (a "mesh providers service": {"federation": name, "servers": [{"url", "displayName"}]}). Each Nextcloud points to it (panes3's nextcloud_ocm_mesh_providers, Contacts' mesh_providers_service) at https://code.geant.dev/ocm/demoservices/raw/branch/main/federation.json; Contacts offers these servers when an invitation is accepted. Members: drive.geant.dev, drive.test.geant.dev, nextcloud4ocm.geant.dev and opencloud4ocm.geant.dev (which in turn trusts the three Nextclouds: opencloud_ocm_providers in deploy/inventory.ini).

Status

Both servers announce OCM with invitations (/.well-known/ocm: Nextcloud API "1.0-proposal1", OpenCloud "1.2.0"). Accepting an invitation between them failed in a first test (2026-10); being looked at.