What sort of issues have you run into when your institutions IT manages access to tools and services?
How does the security of the EaaSI service need to be managed by IT? What sort of requirements are they looking for?
Do you need to set up a free-standing machine with independent access to SSH, or has your IT found ways to use existing Linux images to allow the service to run?
How much intervention/maintenance does it require of your IT departments?
On my end at Yale, I have very little direct access to the infrastructure our EaaSI/EaaS instances run on. I’ve been granted permissions by IT to access the storage volumes that serve as our Object Archive (so that I can upload new Software and Object/Content resources in batches on the back-end) but never got SSH access to the machines themselves (despite asking ). Yale IT also provides an on-demand spinup service providing virtual Linux machines (from AWS I believe) on the Yale network, so I’ve used that to set up test EaaSI machines that I can SSH to and play with it a bit, which allowed me to get some more direct experience with the deployment, configuration, and maintenance processes, but still very much in an experimental, non-production way, as it would cost a bunch more to pay for the computing power and storage space to truly run an EaaSI node that way. It’s all behind Yale’s firewall so they are very hands-off with what you’re doing with spinup machines as long as you check the box saying you’re not uploading any sensitive data (student records, HIPPA stuff, etc)
So I’ll leave it to @klaus.rechert , @seth.r.anderson et al to say more about Yale’s infrastructure and what it takes to keep things running with Library and Yale IT. I also wonder if @mgolson or @msuhovec might have thoughts here from their experiences running local nodes!
Hi everyone, sorry about the delay in my response. For the Stanford node only the System admins have root access. Actually, I might have access but I’ve very purposefully stayed away from even trying to get into our box as I’m concerned that poking around I might inadvertantly break something. Similar to Yale we’re heavily firewalled at our institution and I have stayed away from sshing into this box.
With early version of EaaSI our institution found it difficult to create custom environments without backend access where we could large install packages. We’re still on the ancient UI from early 2019 so I’m sure it has improved but I’ve been waiting for the new release. I anticipate that we’re going to need what Cynde’s alluding to; instructions for how to do more advanced set-ups.