Updated 15/02/2024
DTE Infrastructure Component

ALISE

Federated Data Infrastructure
Image

Description

A tool for linking a user’s federated identity with their facility account.

Account LInking Service (ALISE) is a tool for linking a user’s federated identity with their facility account.  ALISE provides an automated procedure for users of a facility to register their federated identity.

Most facilities have some account identity and access management (IAM) system.  Among other things, this component is responsible for handling supported authentication, with typical features allowing passwords to be changed, handling forgotten passwords, and registering SSH public keys.

Currently, most facilities have no support for OIDC (token-based) authentication.  Therefore, their IAM solutions typically do not allow a user to register their OIDC identity.

ALISE is an easy-to-deploy stand-along service.  By allowing users to register their OIDC identity, an ALISE instance allows sites to deploy other services that require OIDC/token-based authentication, and for those other services to identify users by their federated identity.

The process to register a user’s OIDC identity is needed only once per user.  It requires no admin intervention

 

Target Audience
+

All DT users that (directly or otherwise) make use of a facility that does not allow users to register their federated identity.

License
+

MIT

Created by
+

Release Notes

This release represents the final release of the interTwin federated data management solution.

There are two external software components: FTS and Rucio.  They are fully established projects, independent of the interTwin project.  The software is production-ready, at TRL 9, and hardened with many years of production-critical use.  Both projects have multiple deployments of their software, operated by different communities.

The ALISE software is currently in a development phase, under the aegis of interTwin.  At the time of release, ALISE is TRL 4.  The user-facing functionality of ALISE is mostly feature-complete; however, anticipated changes to the API imply that the necessary integration work (whereby a service uses ALISE to identify a user) should be considered experimental. Feedback from early adopters is encouraged, but any plans to deploy ALISE should be tempered by the anticipated changes to the API.

The teapot software has also been developed within the interTwin project.  With this release, teapot is now TRL 6–7 and supports data transfer requirements of multiple, concurrent users. The per-user WebDAV instance management is automated, starting new services on demand, and terminating them if there is sufficient idle time.

Finally the first version of the Onedata S3 component is released, allowing integration of Onedata technology in the interTwin federated data management solution.

Future Plans

Some further improvements are planned for teapot. This includes integrating teapot with ALISE, to support automated identity management.

For ALISE, we anticipate possible improvements and stabilisation of the service-integration API, based on experience gained from integrating ALISE into various services. In addition, we plan to add support for client authentication in future versions of ALISE. This will limit access to the identity mapping information, providing this information to authorised services only.

As work continues with integrating the Datalake with various science use-cases, limitations may be found with the various components within the Datalake.  Any such problems will be reported to the corresponding component’s development and support teams.  The members of interTwin will offer effort to fix such issues, should such capacity become available during the project’s remaining lifetime.