Open OnDemand
Open OnDemand is a open source project by the Ohio Supercomputer Center that provides a web portal for HPC users. It is designed as a platform allowing system administrators to add additional modules or 'apps'. Users can use this platform to launch interactive jobs or VNC/SSH sessions, view their job statuses, interact with their files. It supports a variety of authentication mechanisms including federated authentication (OpenID, CAS, Shiboleth) or with an the system's underlying PAM (ldap, password file, etc.).
Open OnDemand is in use by:
- https://arc-ts.umich.edu/greatlakes/user-guide/#document-3
- Yale: https://docs.ycrc.yale.edu/clusters-at-yale/access/ood/
Troubleshooting
SSH App: Failed to establish a websocket connection.
After setting up OnDemand, I had a hard time getting the SSH app to connect. I kept on getting:
Failed to establish a websocket connection. Be sure you are using a browser that supports websocket connections.
Debugging the socket revealed that it was getting a 401 error from PUN. At first, I thought the reverse proxy (traefik 1.7) wasn't forwarding the authentication headers, but this was a red herring. Something with the PUN application was throwing this 401 error. I verified that the node is able to SSH and that the default hostname is correct in /etc/ood/config/apps/shell/env. I even tried connecting to a specific host to no avail. I then set OOD_SSH_WRAPPER=/test.sh with test.sh just dumping the environment to a tmp file which showed me that it wasn't even reaching the point of calling the SSH wrapper. OOD 1.8 also requires setting the OOD_SSHHOST_ALLOWLIST, but that didn't help.
Solution: This only worked after setting OOD_SHELL_ORIGIN_CHECK='off'.
Other notes
- Supports Slurm
- A demo can be run inside a container: https://github.com/osc/ood-images