Use Globus Connect

Use Globus Connect

Introduction

The Globus service can be used to connect to Setonix /scratch or an Acacia project at Pawsey. There are other Globus endpoints and collections available in Australia, with a registry maintained by AARNet at the following link. https://support.aarnet.edu.au/hc/en-us/articles/14944937395471-Globus-data-transfer-nodes-in-Australia

Disclaimer: Please be aware of the following two items.

  1. The Globus service offered by Pawsey is currently a technology preview being run as a trial service. This creates an opportunity to evaluate if the presented technology can add value to your research outcomes. Further work is being done with a view to providing a production service in future.

  2. To access Acacia, you will need to entrust your S3 credentials to the Globus Connect service. It is your responsibility to ensure that this does not conflict with your home institution’s security policies.

Procedure

Step 1 - Sign up to Globus

Go to app.globus.org and sign in using your home institution (e.g. Curtin University, CSIRO, The University of Western Australia). If your home institution is not available, then you can consider one of the alternative signups. However, if you don't sign up via your home institution then it may not be possible to link your Globus identity to your Pawsey identity and the service effectively will not work.

Some institutions require additional authorisation to use Globus. If you receive a message similar to the following, raise a support request with your institutional IT team.

Sorry, but we're having trouble signing you in. AADSTS50105: Your administrator has configured the application Globus Online ... to block users unless they are specifically granted access.

Step 2 - Grant Consent

If this is the first time that you have logged in to the Globus app, then you will see a screen similar to this:

image-20260607-235426.png

You will need to select Allow for the above permissions in order to successfully link your accounts.

You will then see the Globus Dashboard displayed.

Step 3 - Access Pawsey Collections

Setonix scratch filesystem

Open the File Manager within the Globus App. To access the Setonix scratch collection, enter “pawsey” in the collection search field. You should see an entry entitled “Setonix scratch filesystem” in the search results. Click on that entry to proceed. As this is the first time you have tried to access this collection, you should see a prompt like this: Click Continue to proceed. You will then be presented with a screen asking you to re-authenticate to grant the data access consent: Click Continue to proceed. You will then be presented with a screen asking you to re-authenticate to grant the data access consent: Your home institution should be selected automatically, so click Continue to proceed. Once authenticated, you will be presented with a screen requesting the data access consent: Click Allow to grant the required consent. You should now be presented with a screen that is basically informing you that you currently don’t have a linked identity to access the collection: Click the Continue button to start the process of linking your Globus identity to your Pawsey identity. You should then see a page like this: Click on “Link a Pawsey Keycloak OIDC (sso.pawsey.org.au) identity” to continue. You will then be redirected to a page where you can enter your Pawsey credentials: Click on “Link a Pawsey Keycloak OIDC (sso.pawsey.org.au) identity” to continue. You will then be redirected to a page where you can enter your Pawsey credentials: Once you have entered your Pawsey credentials and clicked Sign In, you will be prompted for an MFA code. If this is the first time that you have used MFA with your Pawsey account, you should be presented with a QR code. Scan that code with your preferred MFA app. Once you have authenticated, you will see another Globus page similar to the one above about linking you identity, but this one will contain a link looking like this: Use my <username>@sso.pawsey.org.au identity Where <username> will show your Pawsey username. Click on that link to complete the linking of your identities. At this point, you are ready to browse the collection and initiate file transfers. See the Globus documentation for details on how to use the File Manager:

Acacia S3

Open the File Manager within the Globus App. To access the Acacia object storage collection, enter “pawsey” in the collection search field. You should see an entry entitled “Acacia object storage” in the search results. Click on that entry to proceed. If this is the first time you have tried to access this collection, you should see a prompt like this:   Click Continue to proceed. You will then be presented with a screen asking you to re-authenticate to grant the data access consent:   Your home institution should be selected automatically, so click Continue to proceed. Once authenticated, you will be presented with a screen requesting the data access consent:  Click Allow to grant the required consent. You should now be presented with a screen that is basically informing you that you currently don’t have a linked identity to access the collection: Click the Continue button to start the process of linking your Globus identity to your Pawsey identity. You should then see a page like this: Click on “Link a Pawsey Keycloak OIDC (sso.pawsey.org.au) identity” to continue. You will then be redirected to a page where you can enter your Pawsey credentials: Once you have entered your Pawsey credentials and clicked Sign In, you will be prompted for an MFA code. If this is the first time that you have used MFA with your Pawsey account, you should be presented with a QR code. Scan that code with your preferred MFA app. Once you have authenticated, you will see another Globus page similar to the one above about linking you identity, but this one will contain a link looking like this: Use my <username>@sso.pawsey.org.au identity Where <username> will show your Pawsey username. Click on that link to complete the linking of your identities. You should now see a page like this: Click on Continue. Next, you will see a page asking for your consent to allow the Globus Web App to manage collections: Click Allow to proceed. You will now be presented with a dialog box where you can upload your S3 key. Enter your access key and your secret key and click Save. Please refer to the for information on creating Acacia S3 credentials. You will now be presented with a page confirming that the credentials have been successfully added. To browse your Acacia project, click on the Overview tab and the click on Open in File Manager.

FAQ

In principle, yes, but this has not been tested. If you want to try this, you will have to follow the instructions here: Globus Connect Personal Installation
Currently, it is only possible to configure the Acacia endpoint with a single default set of credentials. This limits the Globus service to displaying all the buckets in a single Acacia project. However, additional (non-default) credentials for a specific bucket in any of your other projects can be manually added to the Acacia configuration.