Skip to content

feat(dids): show ATLAS AMI tags for DIDs (feature-gated) - #845

Open
maany wants to merge 27 commits into
rucio:mainfrom
maany:feat/843-ami-tags
Open

maany wants to merge 27 commits into
rucio:mainfrom
maany:feat/843-ami-tags

Conversation

@maany

@maany maany commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

Resolves #843. ATLAS DID names carry AMI tags and, often, a PanDA task ID. For example, data22_13p6TeV.00437756.physics_Main.merge.AOD.r15869_p6304_tid40703687_00 has tags r15869 and p6304 and task 40703687. With this PR, the WebUI:

  • parses ATLAS DID names with a single parser that follows the ATLAS naming conventions,
  • shows AMI Tags chips that link to AMI, with tag details from AMI on hover,
  • shows a PanDA Task chip that links to BigPanDA (/task/?jeditaskid=<id>).

Both are ATLAS-specific, so each sits behind its own feature flag, off by default. Other deployments see no change.

How it works

ATLAS name parsing (src/lib/core/utils/atlas-did-name.ts)

parseAtlasDIDName(name) returns a typed result per naming scheme. The schemes were confirmed with ATLAS (thanks Mario):

Prefix Fields
data* project.runNumber.streamName.prodStep.dataType.Version
mc*, valid* project.datasetNumber.physicsShort.prodStep.dataType.Version
cond* project.internalCondNumber.shortComment.COND
user / group user.userName.… / group.groupName.… (rest ignored)
files dataType.pandaTaskId._jobNumber.…, e.g. DAOD_PHYS.34870879._000001.pool.root.1, log.34870879._000001.job.log.tgz.1
  • Version field: split into AMI tags and a PanDA task. r15869_p6304_tid40703687_00 gives tags r15869, p6304 and task 40703687; the trailing _00 retry counter is ignored.
  • Positional detection: tags come only from the Version field.
  • Names that yield nothing: user.*/group.* names, even when they embed an official name, and names that don't follow a scheme.
  • Period containers: data18_13TeV.periodAllYear…PhysCont… doesn't count as a production name, because run and dataset numbers must be numeric.
  • Legacy containers: a single trailing / is ignored.

AMI tags (dids.ami_tags)

  • GET /api/feature/get-ami-tag-info?tags=… calls AMI's command API (POST <AMI_BASE_URL>/AMI2/FrontEnd, AMIGetAMITagInfo, no auth) through a new AMIGateway.
  • Tags are looked up in parallel with a 5 s timeout. Unknown tags show "Not found in AMI".
  • If AMI is unreachable, the link still works and the popover says the details are unavailable.
  • The popover opens on hover or keyboard focus, is linked to the chip with aria-describedby, and stays open while the pointer moves onto it.

PanDA task (dids.panda_task)

  • GET /api/feature/get-panda-task-link?taskId=… builds the link from PANDA_BASE_URL on the server. This mirrors the existing DDM-link feature.
  • It is link only: BigPanDA needs CERN SSO, so we don't fetch task details.

Gating (both features)

  • Routes are wrapped in withFeature and return 404 while the flag is off.
  • The IoC feature is only loaded when its flag is on at startup, so a flag change needs a restart. If a flag is switched on without a restart, the route still returns 404 rather than an error.
  • The UI rows render nothing, and make no request, when the flag is off or the name has nothing to show.

Configuration

Variable Default
FEATURE_DIDS_AMI_TAGS false AMI tag chips + get-ami-tag-info
AMI_BASE_URL https://atlas-ami.cern.ch AMI instance for links and lookups
FEATURE_DIDS_PANDA_TASK false PanDA task chip + get-panda-task-link
PANDA_BASE_URL https://bigpanda.cern.ch BigPanDA instance for task links

All four are wired into the env-generator, with http(s) validation for the URLs. They're also documented in its README and in .env.development.local.template.

Deployment note: atlas-ami.cern.ch uses a CERN Grid CA certificate. The server needs the CERN Grid CA and CERN Root CA 2 in SERVER_CA_BUNDLE (NODE_EXTRA_CA_CERTS), the same mechanism used for CERN-hosted Rucio. Without them the AMI chips still link out, but no details load. The PanDA link is built without calling BigPanDA, so it isn't affected.

Things worth a look

  • Conditional IoC loading in container-config.ts. Other flag-gated features rely only on withFeature. We load these two only when enabled, so non-ATLAS deployments don't register AMI or PanDA controllers at all.
  • AMI tag rule. It is now AMI's own rule, ^[a-z]\d+$. Detection is positional, so the earlier "3+ digits" safeguard for free-form names is no longer needed.
  • Touch devices. A tap follows the link, so the AMI details popover isn't reachable on touch. The links themselves work everywhere.

Out of scope

  • Showing the other parsed ATLAS fields in the UI
  • PanDA task status
  • AMI/PanDA columns in the DID search table
  • Inheriting tags for files from their parent dataset
  • Filtering by tag or task
  • Server-side caching of AMI responses

Testing

  • npm test: 126 suites / 607 tests pass. npm run build succeeds. npm run lint: 0 errors.
  • New tests cover:
    • the parser, with all of ATLAS's reference names plus period containers, trailing slashes, user/group names and log files
    • the AMI gateway, using captured AMI responses
    • both use cases and presenters
    • conditional feature loading
    • both routes: 404 when disabled or not loaded, 400 for bad input
    • the chips, the popover (including accessibility) and the rows
    • the page wiring
  • We ran the AMI gateway and use case against live AMI: known tags return details, and unknown tags are reported as not found.

How to test locally

1. Environment

Add the following to .env.development.local, then restart the dev server. Both features are loaded at startup, so a restart is required.

# ATLAS AMI tags
FEATURE_DIDS_AMI_TAGS=true
AMI_BASE_URL=https://atlas-ami.cern.ch

# ATLAS PanDA task links
FEATURE_DIDS_PANDA_TASK=true
PANDA_BASE_URL=https://bigpanda.cern.ch

# Needed for AMI tag details (hover popover): atlas-ami.cern.ch uses a CERN Grid CA certificate.
# Either trust the CERN Grid CA + CERN Root CA 2 ...
NODE_EXTRA_CA_CERTS=/path/to/bundle-with-cern-grid-ca.pem
# ... or, for local development only:
# NODE_TLS_REJECT_UNAUTHORIZED=0

With the env-generator, use the RUCIO_WEBUI_-prefixed names: RUCIO_WEBUI_FEATURE_DIDS_AMI_TAGS, RUCIO_WEBUI_AMI_BASE_URL, RUCIO_WEBUI_FEATURE_DIDS_PANDA_TASK and RUCIO_WEBUI_PANDA_BASE_URL. The CA bundle goes in RUCIO_WEBUI_SERVER_CA_BUNDLE.

2. Test DIDs

Run these with the rucio CLI against your dev Rucio server, e.g. inside the rucio dev container. They use the root account and the MOCK-POSIX RSE, which needs no X509 proxy.

cd "$(mktemp -d)"

# Datasets whose Version field carries AMI tags and a PanDA task (tid...)
rucio scope add --account root data22_13p6TeV
rucio scope add --account root mc23_5p36TeV
rucio did add --type dataset data22_13p6TeV:data22_13p6TeV.00437756.physics_Main.merge.AOD.r15869_p6304_tid40703687_00
rucio did add --type dataset mc23_5p36TeV:mc23_5p36TeV.801664.Py8_gammajet_direct_DP17_35_FullSW.merge.EVNT.e8514_e8528_tid44601789_00

# Files in the ATLAS file scheme (<dataType>.<taskId>._<job>...) carry the task ID too
head -c 1024 /dev/urandom > AOD.40703687._000001.pool.root.1
head -c 1024 /dev/urandom > log.40703687._000001.job.log.tgz.1
rucio upload --rse MOCK-POSIX --scope data22_13p6TeV --guid "$(python3 -c 'import uuid; print(uuid.uuid4())')" AOD.40703687._000001.pool.root.1
rucio upload --rse MOCK-POSIX --scope data22_13p6TeV log.40703687._000001.job.log.tgz.1
rucio did content add --to-did data22_13p6TeV:data22_13p6TeV.00437756.physics_Main.merge.AOD.r15869_p6304_tid40703687_00 \
  data22_13p6TeV:AOD.40703687._000001.pool.root.1 data22_13p6TeV:log.40703687._000001.job.log.tgz.1

The --guid flag lets rucio upload accept a .pool.root file without the ATHENA GUID tool.

3. What to expect

DID AMI Tags row PanDA Task row
data22_13p6TeV:data22_13p6TeV.00437756…r15869_p6304_tid40703687_00 r15869, p6304 40703687
mc23_5p36TeV:mc23_5p36TeV.801664…e8514_e8528_tid44601789_00 e8514, e8528 44601789
data22_13p6TeV:AOD.40703687._000001.pool.root.1 none 40703687
data22_13p6TeV:log.40703687._000001.job.log.tgz.1 none 40703687

The rows appear on the DID details page (/did/<scope>/<name>) and in the side panel when you select the DID in the DID list.

  • Hover an AMI chip to see the tag details from AMI.
  • Click a chip to open AMI or BigPanDA in a new tab.
  • With either flag off, its row disappears and its API route returns 404.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Show ATLAS AMI tags for DIDs (feature-gated)

1 participant