Published April 22, 2026 | Version v1

Event-Driven Group Storage Provisioning in dCache via the Helmholtz Cloud Portal: A Reference Architecture

  • 1. ROR icon Deutsches Elektronen-Synchrotron DESY
  • 2. ROR icon HTW Berlin - University of Applied Sciences

Description

Provisioning research group storage at large-scale scientific computing facilities typically requires manual intervention from storage administrators: a user submits a request, an administrator logs into the storage management console, creates a namespace directory, sets quotas, and assigns ownership. This process does not scale as the number of virtual organisations (VOs) and research groups grows.

We present an open-source, cloud-native agent that automates this workflow end-to-end for dCache, one of the most widely deployed distributed storage systems in the high-energy physics and photon science communities. The agent integrates the Helmholtz Cloud Portal, the dCache HTTP namespace API, the dCache SSH administrative interface, and LDAP-based group identity resolution into a cohesive, event-driven provisioning pipeline. A companion shell script running as a cron job on the dCache POSIX frontend completes the ownership assignment step, which cannot be performed through the namespace API alone.

The architecture is idempotent, stateless, and deployable on Kubernetes via Helm. All components are open source. We describe the design decisions, the integration challenges encountered, and the deployment model in production at DESY, where the system serves as the storage solution for the Helmholtz Federated IT Services (HIFIS) community.

Files

hepix-rhee-storage-provisioning.pdf

Files (2.6 MB)

Name Size Download all
md5:4f411cc904bbc0b3a041334020ae400a
2.6 MB Preview Download