Bot SAC Overview
Revision as of 20:47, 22 June 2026 by Darkblueb (talk | contribs) (Created page with "Infrastructure of OSGeo System Administration Committee (SAC)\n\nFor emergency plans see: SAC:Admin and Troubleshooting\n\n\n= Servers at OSL =\nOSL | Open Source La...")
Infrastructure of OSGeo System Administration Committee (SAC)\n\nFor emergency plans see: SAC:Admin and Troubleshooting\n\n\n= Servers at OSL =\n Open Source Labs - 6 physical machines that are lxd hosts containing x virtual machines/containers. 1 is currently shutdown\n\nhistory:\n* 7 physical machines of which 5 ar lxd hosts containing x virtual machines/containers.\n* As part of migration of data center 2025)\n** 2 machines: backup, osgeo3 are historical servers.\n\n== Logging into Physical Machines ==\n\nCurrently we do not have physical machines under LDAP control.
lsblk -i\nNAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT\nsda 8:0 0 1.8T 0 disk \n|-sda1 8:1 0 953M 0 part \n| `-md0 9:0 0 952M 0 raid1 /boot\n`-sda2 8:2 0 46.6G 0 part \n `-md1 9:1 0 46.5G 0 raid1 \n\t|-lvm-root 253:0 0 37.3G 0 lvm /\n\t`-lvm-swap 253:1 0 7.5G 0 lvm [SWAP]\nsdb 8:16 0 1.8T 0 disk \n|-sdb1 8:17 0 953M 0 part \n| `-md0 9:0 0 952M 0 raid1 /boot\n`-sdb2 8:18 0 46.6G 0 part \n `-md1 9:1 0 46.5G 0 raid1 \n\t|-lvm-root 253:0 0 37.3G 0 lvm /\n\t`-lvm-swap 253:1 0 7.5G 0 lvm [SWAP]\nsdc 8:32 0 1.8T 0 disk \nsdd 8:48 0 1.8T 0 disk \nsde 8:64 0 1.8T 0 disk \nsdf 8:80 0 1.8T 0 disk \n\n\n
\nsdc,sdd,sde,sdf form a zfs osgeo4_lxd partition (sdc,sdd) mirrors sde,sdf for total lxd capacity of 3.62 TB\n\n\nNightly backups of osgeo7, and osgeo4 containers are kept here and named <container>-backup and be kept in a stopped state.\n\n= Cloud Hosted Servers and other external under SAC Control =\n\n== Future Hosting Plans for Windows / Mac Building ==\n\nSAC Shared Building Services\n\n\n== Atlantic.net ==\n\n* host.postgis.net -p 2222 is an LXD Ubuntu 18.04 16GB RAM/ 6 vCPU, 350GB data, 250GB block storage\n* Currenlty running two lxd containers:\n debbie: debian 10 postgis.net, planet.postgis.net, debbie.postgis.net (jenkins build bot) \n debbie-docker.host.postgis.net - runs docker and serves as a 1.0 agent for dronie.osgeo.org\n\n= QGIS off OSGeo =\nServices on separated machines rented and managed by the QGIS project at hetzner\n\n* website including documentation http://www.qgis.org\n* website building, documentation building, debian/ubuntu nightlies, plugins.qgis.org\n* issues.qgis.org: redmine\n\n= Historical servers (not more in use) =\n\n- Telascience Blades (Historical)\n\n== web18a.osgeo.osuosl.org ==\nNO LONGER USED - turned off\n2019-09-03 Production services www.osgeo.org, 2018.foss4g.org moved to wordpress container on osgeo7\nStaging services (staging.www.osgeo.org, dev.www.osgeo.org move to wordpress-dev container on osgeo4\nGrass wordpress is disabled as grass decided to go with another solution, so have grass container on osgeo7\n(Cloud hosted server on OSUOSL hardware (not ours) )\n* Debian 9.3 4GB server, host name: web18a.osgeo.osuosl.org require ssh key to log in.\n* Hosts wordpress sites staging.www.osgeo.org,www.osgeo.org, staging.grass.osgeo.org, foss4g2018.osgeo.org\n* Setup details on Web18a setup\n\n\n== OSGeo funtoo ==\n\nFor lxd experimentation it's an lxd container running other lxd containers and provided by funtoo.org.\n\nOSGeo is paying funtoo via treasurer at osgeo.org.\n\n* OSGeo Funtoo osgeo.host.funtoo.org\n\n\n* funtoo LXDs currently running:\n**
}
],
"id": "rcj2vdf6x0j",
"parent": "ohurhl3jbn9"
},
{
"convId": "qjvr2shpkjd",
"type": "text",
"role": "assistant",
"content": "Infrastructure of OSGeo System Administration Committee (SAC)\n\n= Presentation: OSGeo Service Infrastructure Overview =\n\nThis document outlines a proposed 12-slide presentation for the OSGeo leadership. The focus shifts from specific hardware inventory to the value, reliability, and strategic benefit of the services provided to the community.\n\n== Slide 1: Introduction ==\nTitle: Empowering the Open Geospatial Community: OSGeo Infrastructure Overview\n\nContent:\n* **Presenter:** SAC Infrastructure Team\n* **Objective:** To provide a high-level overview of the technical infrastructure supporting OSGeo projects.\n* **Key Message:** Our infrastructure is not just about servers; it is about enabling collaboration, development, and community engagement for the global open-source geospatial movement.\n* **Scope:** Overview of core services, hosting strategies, and future resilience.\n\n== Slide 2: Strategic Vision & Philosophy ==\nTitle: From Hardware to Service-Oriented Infrastructure\n\nContent:\n* **The Shift:** Moving away from \"managing servers\" to \"delivering services.\"\n* **Core Principles:**\n * **Reliability:** High availability for critical community tools.\n * **Scalability:** Flexible resources to support growing projects (e.g., Docker, CI/CD).\n * **Security:** Robust access controls and data protection.\n * **Community-Centric:** Infrastructure tailored to the needs of GIS developers, researchers, and users.\n* **Goal:** A unified, resilient platform that allows project teams to focus on code and content, not sysadmin tasks.\n\n== Slide 3: The Foundation: Modern Virtualization ==\nTitle: Efficient Resource Utilization via LXD/Incus\n\nContent:\n* **Technology Stack:** Migration to modern containerization (LXD/Incus) and virtualization.\n* **Benefits:**\n * **Density:** More services per physical machine, reducing energy and hardware costs.\n * **Isolation:** Secure separation of projects (e.g., Nextcloud vs. Jenkins).\n * **Speed:** Rapid deployment and cloning of environments for testing and production.\n* **Current State:** Primary hosts (osgeo4, osgeo7, osgeo8, osgeo9, osgeo10) form a robust, distributed cluster.\n\n== Slide 4: Core Web Presence & Community Hub ==\nTitle: The OSGeo Website & Wiki Ecosystem\n\nContent:\n* **Services:**\n * **www.osgeo.org:** The main portal for news, events, and project listings.\n * **wiki.osgeo.org:** The central knowledge base for documentation and community guides.\n* **Infrastructure:**\n * Hosted on modern LXD containers (osgeo6/osgeo7).\n * Automated deployments via Ansible ensure consistency and easy updates.\n * Staging environments (wordpress-dev, wiki-staging) allow safe testing before production release.\n* **Benefit:** A stable, up-to-date face of OSGeo for millions of visitors.\n\n== Slide 5: Communication & Collaboration Tools ==\nTitle: Keeping the Community Connected\n\nContent:\n* **Real-Time Chat:**\n * **Matrix (gitter/irc bridges):** Secure, federated chat for developer discussions.\n * **Heisenbridge:** Bridges IRC channels to Matrix for broader accessibility.\n* **Video Conferencing:**\n * **Jitsi Meet (meet.osgeo.org):** Self-hosted, privacy-focused video meetings for SAC and project meetings.\n* **Mailing Lists:**\n * **Mailman (lists.osgeo.org):** The backbone of asynchronous communication for announcements and technical debates.\n* **Benefit:** Diverse, accessible, and self-hosted communication channels that respect user privacy.\n\n== Slide 6: Development & Continuous Integration ==\nTitle: Powering Project Development with CI/CD\n\nContent:\n* **Code Hosting:**\n * **Gitea (git.osgeo.org):** Lightweight, self-hosted Git service for project repositories.\n* **Continuous Integration:**\n * **Jenkins (host.postgis.net & osgeo10):** Automated testing and building for major projects like PostGIS and GRASS GIS.\n * **Dronie:** Automated release management and build coordination.\n* **Benefit:** Accelerates development cycles, ensures code quality, and automates the release process for critical geospatial software.\n\n== Slide 7: Data Management & Storage ==\nTitle: Secure Data Sharing and Distribution\n\nContent:\n* **File Sharing:**\n * **Nextcloud (nextcloud.osgeo.org):** Secure, self-hosted cloud storage for project teams and sensitive data.\n * **Photoprism:** AI-powered photo management for community events and galleries.\n* **Software Distribution:**\n * **Download Server (download.osgeo.org):** High-bandwidth mirror for OSGeo Live, ISOs, and project binaries.\n * **Repo Server (repo.osgeo.org):** Centralized repository for Debian/Ubuntu packages and Docker images.\n* **Benefit:** Reliable access to software and data for users worldwide, with secure internal collaboration tools for teams.\n\n== Slide 8: Project-Specific Hosting & Specialized Services ==\nTitle: Supporting Diverse Project Needs\n\nContent:\n* **GRASS GIS:** Dedicated hosting (grass.osgeo.org) with automated website generation and security updates.\n* **GeoServer:** Certification testing environment (cite.geoserver.org) and demo instances.\n* **QGIS:** Separate, high-performance hosting for QGIS project needs (website, docs, plugins).\n* **LimeSurvey:** Self-hosted survey tool for community feedback and elections.\n* **Benefit:** Tailored infrastructure that meets the unique technical requirements of different projects, from heavy compute to simple web hosting.\n\n== Slide 9: Monitoring, Security & Reliability ==\nTitle: Proactive Maintenance and Security\n\nContent:\n* **Monitoring:**\n * **Prometheus & Grafana (monitor.osgeo.org):** Real-time visibility into server health, container metrics, and service status.\n * Automated alerts for SAC administrators.\n* **Security:**\n * **LDAP Integration:** Centralized identity management for secure access.\n * **SSH Key Management:** Strict key-based access control with jump hosts for isolation.\n * **Regular Updates:** Automated security patches (unattended-upgrades) and regular OS upgrades.\n* **Benefit:** Proactive identification of issues, ensuring high uptime and protecting community data.\n\n== Slide 10: Disaster Recovery & Backup Strategy ==\nTitle: Ensuring Business Continuity\n\nContent:\n* **Backup Infrastructure:**\n * Dedicated backup hardware (osgeo5) for critical data.\n * Rsync backups for download mirrors.\n * Bacula backups for VMs and containers.\n* **Redundancy:**\n * Distributed hosting across multiple physical machines.\n * Regular restoration tests to verify backup integrity.\n* **Benefit:** Peace of mind knowing that community data and project history are protected against hardware failure or accidental deletion.\n\n== Slide 11: Future Roadmap & Optimization ==\nTitle: Evolving Infrastructure for Future Growth\n\nContent:\n* **Consolidation:** Migrating remaining legacy services to modern LXD/Incus hosts.\n* **Performance:** Optimizing network proxies (Nginx) and storage (ZFS) for better throughput.\n* **Expansion:** Preparing for increased demand from growing projects (e.g., more CI/CD agents, larger download mirrors).\n* **Sustainability:** Reducing physical footprint through efficient virtualization.\n* **Benefit:** A forward-looking infrastructure that is cost-effective, efficient, and ready for the next decade of open geospatial innovation.\n\n== Slide 12: Conclusion & Q&A ==\nTitle: Summary and Next Steps\n\nContent:\n* **Summary:**\n * OSGeo infrastructure is a robust, modern, and community-focused platform.\n * It supports a wide range of services from web hosting to complex CI/CD pipelines.\n * Continuous improvement ensures reliability and security.\n* **Call to Action:**\n * Support for ongoing maintenance and potential upgrades.\n * Collaboration between SAC and project teams to identify future needs.\n* **Q&A:** Open floor for questions and discussion.\n\n= Notes for Presentation Delivery =\n\n* **Emphasis on Benefit:** When discussing each slide, always link the technical detail back to the user or project benefit (e.g., \"This Jenkins server means faster releases for PostGIS users\").\n* **Visuals:** Use diagrams showing the flow from user -> web proxy -> container -> service. Show screenshots of the monitoring dashboard to demonstrate proactive management.\n* **Simplicity:** Avoid deep technical jargon where possible. Focus on concepts like \"reliability,\" \"speed,\" and \"security.\"\n* **Addressing Mistakes:** The original document contained outdated information (e.g., osgeo3 status, specific container names). This presentation uses the corrected, high-level view to avoid confusion. Ensure the slide deck reflects the *current* state as described in the revised service list.