mirror of
https://github.com/alanorth/cgspace-notes.git
synced 2024-11-27 00:48:19 +01:00
396 lines
15 KiB
HTML
396 lines
15 KiB
HTML
<!DOCTYPE html>
|
||
<html lang="en">
|
||
|
||
<head>
|
||
<meta charset="utf-8">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||
|
||
<meta property="og:title" content="September, 2017" />
|
||
<meta property="og:description" content="2017-09-06
|
||
|
||
|
||
Linode sent an alert that CGSpace (linode18) was using 261% CPU for the past two hours
|
||
|
||
|
||
2017-09-07
|
||
|
||
|
||
Ask Sisay to clean up the WLE approvers a bit, as Marianne’s user account is both in the approvers step as well as the group
|
||
|
||
|
||
" />
|
||
<meta property="og:type" content="article" />
|
||
<meta property="og:url" content="https://alanorth.github.io/cgspace-notes/2017-09/" />
|
||
|
||
|
||
|
||
<meta property="article:published_time" content="2017-09-07T16:54:52+07:00"/>
|
||
<meta property="article:modified_time" content="2017-09-12T16:57:19+03:00"/>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<meta name="twitter:card" content="summary"/><meta name="twitter:title" content="September, 2017"/>
|
||
<meta name="twitter:description" content="2017-09-06
|
||
|
||
|
||
Linode sent an alert that CGSpace (linode18) was using 261% CPU for the past two hours
|
||
|
||
|
||
2017-09-07
|
||
|
||
|
||
Ask Sisay to clean up the WLE approvers a bit, as Marianne’s user account is both in the approvers step as well as the group
|
||
|
||
|
||
"/>
|
||
<meta name="generator" content="Hugo 0.27" />
|
||
|
||
|
||
|
||
<script type="application/ld+json">
|
||
{
|
||
"@context": "http://schema.org",
|
||
"@type": "BlogPosting",
|
||
"headline": "September, 2017",
|
||
"url": "https://alanorth.github.io/cgspace-notes/2017-09/",
|
||
"wordCount": "1241",
|
||
"datePublished": "2017-09-07T16:54:52+07:00",
|
||
"dateModified": "2017-09-12T16:57:19+03:00",
|
||
"author": {
|
||
"@type": "Person",
|
||
"name": "Alan Orth"
|
||
},
|
||
"keywords": "Notes"
|
||
}
|
||
</script>
|
||
|
||
|
||
|
||
<link rel="canonical" href="https://alanorth.github.io/cgspace-notes/2017-09/">
|
||
|
||
<title>September, 2017 | CGSpace Notes</title>
|
||
|
||
<!-- combined, minified CSS -->
|
||
<link href="https://alanorth.github.io/cgspace-notes/css/style.css" rel="stylesheet" integrity="sha384-zYRhIy0/Yl1e5lW9cimY1AugfdkHChXyCbs2NKFaLTgeQjVfj/CMPIUdjXm/JPWV" crossorigin="anonymous">
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
</head>
|
||
|
||
<body>
|
||
|
||
<div class="blog-masthead">
|
||
<div class="container">
|
||
<nav class="nav blog-nav">
|
||
<a class="nav-link " href="https://alanorth.github.io/cgspace-notes/">Home</a>
|
||
|
||
|
||
</nav>
|
||
</div>
|
||
</div>
|
||
|
||
<header class="blog-header">
|
||
<div class="container">
|
||
<h1 class="blog-title"><a href="https://alanorth.github.io/cgspace-notes/" rel="home">CGSpace Notes</a></h1>
|
||
<p class="lead blog-description">Documenting day-to-day work on the <a href="https://cgspace.cgiar.org">CGSpace</a> repository.</p>
|
||
</div>
|
||
</header>
|
||
|
||
<div class="container">
|
||
<div class="row">
|
||
<div class="col-sm-8 blog-main">
|
||
|
||
|
||
|
||
|
||
<article class="blog-post">
|
||
<header>
|
||
<h2 class="blog-post-title"><a href="https://alanorth.github.io/cgspace-notes/2017-09/">September, 2017</a></h2>
|
||
<p class="blog-post-meta"><time datetime="2017-09-07T16:54:52+07:00">Thu Sep 07, 2017</time> by Alan Orth in
|
||
|
||
<i class="fa fa-tag" aria-hidden="true"></i> <a href="/cgspace-notes/tags/notes" rel="tag">Notes</a>
|
||
|
||
</p>
|
||
</header>
|
||
<h2 id="2017-09-06">2017-09-06</h2>
|
||
|
||
<ul>
|
||
<li>Linode sent an alert that CGSpace (linode18) was using 261% CPU for the past two hours</li>
|
||
</ul>
|
||
|
||
<h2 id="2017-09-07">2017-09-07</h2>
|
||
|
||
<ul>
|
||
<li>Ask Sisay to clean up the WLE approvers a bit, as Marianne’s user account is both in the approvers step as well as the group</li>
|
||
</ul>
|
||
|
||
<p></p>
|
||
|
||
<h2 id="2017-09-10">2017-09-10</h2>
|
||
|
||
<ul>
|
||
<li>Delete 58 blank metadata values from the CGSpace database:</li>
|
||
</ul>
|
||
|
||
<pre><code>dspace=# delete from metadatavalue where resource_type_id=2 and text_value='';
|
||
DELETE 58
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>I also ran it on DSpace Test because we’ll be migrating the CGIAR Library soon and it would be good to catch these before we migrate</li>
|
||
<li>Run system updates and restart DSpace Test</li>
|
||
<li>We only have 7.7GB of free space on DSpace Test so I need to copy some data off of it before doing the CGIAR Library migration (requires lots of exporting and creating temp files)</li>
|
||
<li>I still have the original data from the CGIAR Library so I’ve zipped it up and sent it off to linode18 for now</li>
|
||
<li>sha256sum of <code>original-cgiar-library-6.6GB.tar.gz</code> is: bcfabb52f51cbdf164b61b7e9b3a0e498479e4c1ed1d547d32d11f44c0d5eb8a</li>
|
||
<li>Start doing a test run of the CGIAR Library migration locally</li>
|
||
<li>Notes and todo checklist here for now: <a href="https://gist.github.com/alanorth/3579b74e116ab13418d187ed379abd9c">https://gist.github.com/alanorth/3579b74e116ab13418d187ed379abd9c</a></li>
|
||
<li>Create pull request for Phase I and II changes to CCAFS Project Tags: <a href="https://github.com/ilri/DSpace/pull/336">#336</a></li>
|
||
<li>We’ve been discussing with Macaroni Bros and CCAFS for the past month or so and the list of tags was recently finalized</li>
|
||
<li>There will need to be some metadata updates — though if I recall correctly it is only about seven records — for that as well, I had made some notes about it in <a href="/cgspace-notes/2017-07">2017-07</a>, but I’ve asked for more clarification from Lili just in case</li>
|
||
<li>Looking at the DSpace logs to see if we’ve had a change in the “Cannot get a connection” errors since last month when we adjusted the <code>db.maxconnections</code> parameter on CGSpace:</li>
|
||
</ul>
|
||
|
||
<pre><code># grep -c "Cannot get a connection, pool error Timeout waiting for idle object" dspace.log.2017-09-*
|
||
dspace.log.2017-09-01:0
|
||
dspace.log.2017-09-02:0
|
||
dspace.log.2017-09-03:9
|
||
dspace.log.2017-09-04:17
|
||
dspace.log.2017-09-05:752
|
||
dspace.log.2017-09-06:0
|
||
dspace.log.2017-09-07:0
|
||
dspace.log.2017-09-08:10
|
||
dspace.log.2017-09-09:0
|
||
dspace.log.2017-09-10:0
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>Also, since last month (2017-08) Macaroni Bros no longer runs their REST API scraper every hour, so I’m sure that helped</li>
|
||
<li>There are still some errors, though, so maybe I should bump the connection limit up a bit</li>
|
||
<li>I remember seeing that Munin shows that the average number of connections is 50 (which is probably mostly from the XMLUI) and we’re currently allowing 40 connections per app, so maybe it would be good to bump that value up to 50 or 60 along with the system’s PostgreSQL <code>max_connections</code> (formula should be: webapps * 60 + 3, or 3 * 60 + 3 = 183 in our case)</li>
|
||
<li>I updated both CGSpace and DSpace Test to use these new settings (60 connections per web app and 183 for system PostgreSQL limit)</li>
|
||
<li>I’m expecting to see 0 connection errors for the next few months</li>
|
||
</ul>
|
||
|
||
<h2 id="2017-09-11">2017-09-11</h2>
|
||
|
||
<ul>
|
||
<li>Lots of work testing the CGIAR Library migration</li>
|
||
<li>Many technical notes and TODOs here: <a href="https://gist.github.com/alanorth/3579b74e116ab13418d187ed379abd9c">https://gist.github.com/alanorth/3579b74e116ab13418d187ed379abd9c</a></li>
|
||
</ul>
|
||
|
||
<h2 id="2017-09-12">2017-09-12</h2>
|
||
|
||
<ul>
|
||
<li>I was testing the <a href="https://wiki.duraspace.org/display/DSDOC5x/AIP+Backup+and+Restore#AIPBackupandRestore-AIPConfigurationsToImproveIngestionSpeedwhileValidating">METS XSD caching during AIP ingest</a> but it doesn’t seem to help actually</li>
|
||
<li>The import process takes the same amount of time with and without the caching</li>
|
||
<li>Also, I captured TCP packets destined for port 80 and both imports only captured ONE packet (an update check from some component in Java):</li>
|
||
</ul>
|
||
|
||
<pre><code>$ sudo tcpdump -i en0 -w without-cached-xsd.dump dst port 80 and 'tcp[32:4] = 0x47455420'
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>Great TCP dump guide here: <a href="https://danielmiessler.com/study/tcpdump">https://danielmiessler.com/study/tcpdump</a></li>
|
||
<li>The last part of that command filters for HTTP GET requests, of which there should have been many to fetch all the XSD files for validation</li>
|
||
<li>I sent a message to the mailing list to see if anyone knows more about this</li>
|
||
<li>In looking at the tcpdump results I notice that there is an update check to the ehcache server on <em>every</em> iteration of the ingest loop, for example:</li>
|
||
</ul>
|
||
|
||
<pre><code>09:39:36.008956 IP 192.168.8.124.50515 > 157.189.192.67.http: Flags [P.], seq 1736833672:1736834103, ack 147469926, win 4120, options [nop,nop,TS val 1175113331 ecr 550028064], length 431: HTTP: GET /kit/reflector?kitID=ehcache.default&pageID=update.properties&id=2130706433&os-name=Mac+OS+X&jvm-name=Java+HotSpot%28TM%29+64-Bit+Server+VM&jvm-version=1.8.0_144&platform=x86_64&tc-version=UNKNOWN&tc-product=Ehcache+Core+1.7.2&source=Ehcache+Core&uptime-secs=0&patch=UNKNOWN HTTP/1.1
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>Turns out this is a known issue and Ehcache has refused to make it opt-in: <a href="https://jira.terracotta.org/jira/browse/EHC-461">https://jira.terracotta.org/jira/browse/EHC-461</a></li>
|
||
<li>But we can disable it by adding an <code>updateCheck="false"</code> attribute to the main <code><ehcache ></code> tag in <code>dspace-services/src/main/resources/caching/ehcache-config.xml</code></li>
|
||
<li>After re-compiling and re-deploying DSpace I no longer see those update checks during item submission</li>
|
||
<li>I had a Skype call with Bram Luyten from Atmire to discuss various issues related to ORCID in DSpace
|
||
|
||
<ul>
|
||
<li>First, ORCID is deprecating their version 1 API (which DSpace uses) and in version 2 API they have removed the ability to search for users by name</li>
|
||
<li>The logic is that searching by name actually isn’t very useful because ORCID is essentially a global phonebook and there are tons of legitimately duplicate and ambiguous names</li>
|
||
<li>Atmire’s proposed integration would work by having users lookup and add authors to the authority core directly using their ORCID ID itself (this would happen during the item submission process or perhaps as a standalone / batch process, for example to populate the authority core with a list of known ORCIDs)</li>
|
||
<li>Once the association between name and ORCID is made in the authority then it can be autocompleted in the lookup field</li>
|
||
<li>Ideally there could also be a user interface for cleanup and merging of authorities</li>
|
||
<li>He will prepare a quote for us with keeping in mind that this could be useful to contribute back to the community for a 5.x release</li>
|
||
<li>As far as exposing ORCIDs as flat metadata along side all other metadata, he says this should be possible and will work on a quote for us</li>
|
||
</ul></li>
|
||
</ul>
|
||
|
||
<h2 id="2017-09-13">2017-09-13</h2>
|
||
|
||
<ul>
|
||
<li>Last night Linode sent an alert about CGSpace (linode18) that it has exceeded the outbound traffic rate threshold of 10Mb/s for the last two hours</li>
|
||
<li>I wonder what was going on, and looking into the nginx logs I think maybe it’s OAI…</li>
|
||
<li>Here is yesterday’s top ten IP addresses making requests to <code>/oai</code>:</li>
|
||
</ul>
|
||
|
||
<pre><code># awk '{print $1}' /var/log/nginx/oai.log | sort -n | uniq -c | sort -h | tail -n 10
|
||
1 213.136.89.78
|
||
1 66.249.66.90
|
||
1 66.249.66.92
|
||
3 68.180.229.31
|
||
4 35.187.22.255
|
||
13745 54.70.175.86
|
||
15814 34.211.17.113
|
||
15825 35.161.215.53
|
||
16704 54.70.51.7
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>Compared to the previous day’s logs it looks VERY high:</li>
|
||
</ul>
|
||
|
||
<pre><code># awk '{print $1}' /var/log/nginx/oai.log.1 | sort -n | uniq -c | sort -h | tail -n 10
|
||
1 207.46.13.39
|
||
1 66.249.66.93
|
||
2 66.249.66.91
|
||
4 216.244.66.194
|
||
14 66.249.66.90
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>The user agents for those top IPs are:
|
||
|
||
<ul>
|
||
<li>54.70.175.86: API scraper</li>
|
||
<li>34.211.17.113: API scraper</li>
|
||
<li>35.161.215.53: API scraper</li>
|
||
<li>54.70.51.7: API scraper</li>
|
||
</ul></li>
|
||
<li>And this user agent has never been seen before today (or at least recently!):</li>
|
||
</ul>
|
||
|
||
<pre><code># grep -c "API scraper" /var/log/nginx/oai.log
|
||
62088
|
||
# zgrep -c "API scraper" /var/log/nginx/oai.log.*.gz
|
||
/var/log/nginx/oai.log.10.gz:0
|
||
/var/log/nginx/oai.log.11.gz:0
|
||
/var/log/nginx/oai.log.12.gz:0
|
||
/var/log/nginx/oai.log.13.gz:0
|
||
/var/log/nginx/oai.log.14.gz:0
|
||
/var/log/nginx/oai.log.15.gz:0
|
||
/var/log/nginx/oai.log.16.gz:0
|
||
/var/log/nginx/oai.log.17.gz:0
|
||
/var/log/nginx/oai.log.18.gz:0
|
||
/var/log/nginx/oai.log.19.gz:0
|
||
/var/log/nginx/oai.log.20.gz:0
|
||
/var/log/nginx/oai.log.21.gz:0
|
||
/var/log/nginx/oai.log.22.gz:0
|
||
/var/log/nginx/oai.log.23.gz:0
|
||
/var/log/nginx/oai.log.24.gz:0
|
||
/var/log/nginx/oai.log.25.gz:0
|
||
/var/log/nginx/oai.log.26.gz:0
|
||
/var/log/nginx/oai.log.27.gz:0
|
||
/var/log/nginx/oai.log.28.gz:0
|
||
/var/log/nginx/oai.log.29.gz:0
|
||
/var/log/nginx/oai.log.2.gz:0
|
||
/var/log/nginx/oai.log.30.gz:0
|
||
/var/log/nginx/oai.log.3.gz:0
|
||
/var/log/nginx/oai.log.4.gz:0
|
||
/var/log/nginx/oai.log.5.gz:0
|
||
/var/log/nginx/oai.log.6.gz:0
|
||
/var/log/nginx/oai.log.7.gz:0
|
||
/var/log/nginx/oai.log.8.gz:0
|
||
/var/log/nginx/oai.log.9.gz:0
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>Some of these heavy users are also using XMLUI, and their user agent isn’t matched by the <a href="https://github.com/ilri/rmg-ansible-public/blob/master/roles/dspace/templates/tomcat/server-tomcat7.xml.j2#L158">Tomcat Session Crawler valve</a>, so each request uses a different session</li>
|
||
<li>Yesterday alone the IP addresses using the <code>API scraper</code> user agent were responsible for 16,000 sessions in XMLUI:</li>
|
||
</ul>
|
||
|
||
<pre><code># grep -a -E "(54.70.51.7|35.161.215.53|34.211.17.113|54.70.175.86)" /home/cgspace.cgiar.org/log/dspace.log.2017-09-12 | grep -o -E 'session_id=[A-Z0-9]{32}' | sort -n | uniq | wc -l
|
||
15924
|
||
</code></pre>
|
||
|
||
<ul>
|
||
<li>If this continues I will definitely need to figure out who is responsible for this scraper and add their user agent to the session crawler valve regex</li>
|
||
<li>Also, in looking at the DSpace logs I noticed a warning from OAI that I should look into:</li>
|
||
</ul>
|
||
|
||
<pre><code>WARN org.dspace.xoai.services.impl.xoai.DSpaceRepositoryConfiguration @ { OAI 2.0 :: DSpace } Not able to retrieve the dspace.oai.url property from oai.cfg. Falling back to request address
|
||
</code></pre>
|
||
|
||
|
||
|
||
|
||
|
||
</article>
|
||
|
||
|
||
|
||
</div> <!-- /.blog-main -->
|
||
|
||
<aside class="col-sm-3 ml-auto blog-sidebar">
|
||
|
||
|
||
|
||
<section class="sidebar-module">
|
||
<h4>Recent Posts</h4>
|
||
<ol class="list-unstyled">
|
||
|
||
|
||
<li><a href="/cgspace-notes/2017-09/">September, 2017</a></li>
|
||
|
||
<li><a href="/cgspace-notes/2017-08/">August, 2017</a></li>
|
||
|
||
<li><a href="/cgspace-notes/2017-07/">July, 2017</a></li>
|
||
|
||
<li><a href="/cgspace-notes/2017-06/">June, 2017</a></li>
|
||
|
||
<li><a href="/cgspace-notes/2017-05/">May, 2017</a></li>
|
||
|
||
</ol>
|
||
</section>
|
||
|
||
|
||
|
||
|
||
<section class="sidebar-module">
|
||
<h4>Links</h4>
|
||
<ol class="list-unstyled">
|
||
|
||
<li><a href="https://cgspace.cgiar.org">CGSpace</a></li>
|
||
|
||
<li><a href="https://dspacetest.cgiar.org">DSpace Test</a></li>
|
||
|
||
<li><a href="https://github.com/ilri/DSpace">CGSpace @ GitHub</a></li>
|
||
|
||
</ol>
|
||
</section>
|
||
|
||
</aside>
|
||
|
||
|
||
</div> <!-- /.row -->
|
||
</div> <!-- /.container -->
|
||
|
||
<footer class="blog-footer">
|
||
<p>
|
||
|
||
Blog template created by <a href="https://twitter.com/mdo">@mdo</a>, ported to Hugo by <a href='https://twitter.com/mralanorth'>@mralanorth</a>.
|
||
|
||
</p>
|
||
<p>
|
||
<a href="#">Back to top</a>
|
||
</p>
|
||
</footer>
|
||
|
||
</body>
|
||
|
||
</html>
|