How to submit request for hda roles on My DataLake Services

Roles allow you to access different features of Destination Earth cloud. In this article, you will learn how to request for roles for hda service.

What we are going to cover

Prerequisites

No. 1 Account

You need a profile on My DataLake Services: How to create a profile on My DataLake Services.

No. 2 Administrative privileges within a project

You need to be a member of a project and have administrative privileges in it. That project must be accepted by an operator of My DataLake Services.

To learn how to create a project, check How to create a project on My DataLake Services.

Alternatively, you can join an existing project and its admin can grant you admin privileges.

Choosing which role to request

Sign in to My DataLake Services https://application.data.destination-earth.eu/.

Navigate to Role requests and see a page similar to this:

../../_images/hda-role-new-11.png

hda service is installed even if you do not have a project.

To request access to a new service click on Request access and to change the preferences for an already requested service, click on Edit access. You should be transferred to a page entitled Request access and it will have two sections: Access roles and Quota roles. You will need to fill both of these forms.

Access roles

For hda service, project administrators can request any of the available HDA access roles. HDA supports any number of access roles, and each role can grant access to a defined subset of HDA collections. The available roles depend on the HDA configuration.

The following example shows two access roles:

hda-public-data-access

Access to public HDA data sets.

This is the default role you have even without the creation of project.

hda-restricted-data-access

Access to Harmonised Data Access (HDA) restricted data sets.

../../_images/hda-role-new-2.png

It is mandatory to enter text into field Description of planned activities.

Once you click on button Request role, a message appears in the lower right corner:

../../_images/hda-role-new-3.png

Another part of the screen scrolls up, this time to request quota role.

Quota roles

For hda service, there are three quota roles to choose from:

hda-basic

Basic quota for Harmonised Data Access (HDA). Maximum 4 requests per second, bandwidth up to 20 MBps per connection. Monthly transfer 5 GB.

hda-medium

Medium quota for Harmonised Data Access (HDA). Maximum 15 requests per second, bandwidth up to 100 MBps per connection. Monthly transfer 300 TB.

hda-high

High quota for Harmonised Data Access (HDA). Maximum 20 requests per second, bandwidth up to 500 MBps per connection. Monthly transfer 750 TB.

../../_images/hda-role--2.png

Click on Select role circle to choose.

It is mandatory to enter text into field Description of planned activities.

Operator approval

The next phase is waiting for the DEDL operator to approve (or disapprove) your requests. You will see the approved role requests, like this:

../../_images/hda-role-new-5.png

When approved, you will see it in the list of Active roles.

Unlike services that provide a single access type, HDA can have multiple access roles. You can have one or more approved access roles, depending on the HDA collections you need to access:

../../_images/hda-role-new-6.png

List active roles

With option Access -> Active roles from the left side menu, you can see the existing active roles. In the following image, the user has activated all of the available services:

../../_images/islet-role--4.png

That may or may not be exactly your situation; it is totally fine to have just one or two services activated.

List role requests

Option Role requests shows the history of requested roles, offering to see the exact details of a selected role. For instance, here are the details for hda-medium role:

../../_images/hda-role-new-7.png

How to change roles for hda service

It is possible to change the role you already have for another one that is available for the service. If there is only one role to start with, it is not possible to change it for something else. However, there are several quota roles and there you can request for a change.

Let’s say that you have decided to start high with hda-high and that this is the state you see in option Active roles:

../../_images/hda-role-new-8-new.png

To try to change current quota from hda-high to hda-low, click on Role requests to see all active services and click on Edit access for row hda:

../../_images/hda-role-new-8.png

You will now be able to choose from the other available quota roles for hda service:

../../_images/hda-role-new-10.png

You already have the high quota role for hda, so now you can choose from the other three, for basic, low or medium access.

Click on the Select role column and enter some text into field Description of planned activities. The Request role button will become active so click on it. A message will appear in the bottom right corner:

../../_images/hda-role-new-111.png

In the list of role requests, a new request to the operator will appear as PENDING:

../../_images/hda-role-new-12.png

There are two options now available for that request:

Details

This is the standard option for all requests.

Delete

This is the new option, with which you can delete the request before the operator sees it.

You will have a chance to cancel or confirm:

../../_images/stack-dask-role--12-hda.png

If you confirm, a message will appear in the bottom right corner of the browser window:

../../_images/stack-dask-role--13-hda.png

The request will become REJECTED and if you now click on Details, you will see that the reason for rejection is labeled as deleted directly.

../../_images/hda-role-new-14.png

If not deleted by the user, the request will in due time appear before the operator, who will approve it or reject it.

In case of approval, the role request will become APPROVED:

../../_images/hda-role-new-15.png

Click on Active roles to verify that the quota has changed to low:

../../_images/hda-role-new-16.png

If rejected, you will, under Details, see the message that the operator sent you. In this case it is “Not available” but it can be anything else the operator wants you know about the rejection:

../../_images/islet-role--17.png

Email notifications

Every role request update sends an email to the address used for your login. It looks like this:

../../_images/email-hda-low-approved.png

Example of a notification email for a role status change.

Using the search mechanism in your email client, you can track every change in quota status for any service in My DataLake Services.

How to remove access to a service

For each service, one quota role and at least one access role are required. If quota and/or access role is missing, service will not be available. To eliminate access role for the hda service, click on User & privileges to see access roles that are active:

../../_images/hda-active-access-role.png

Now click on checkbox near hda-workflows, which will make it inactive while the Save button is now active.

../../_images/checkbox-not-active-for-hda-workflows.png

Click on Save produces a message in lower right corner:

../../_images/access-role-updated-successfully2.png

and the now there is no active access role for hda service. To verify, click on Active roles and see that hda only has a quota role but not the access role, meaning, it cannot access the data.

../../_images/hda-without-access-role.png

How to delete the account

If you want to stop being an owner of a My DataLake Services account, you use Delete account button from the Profile page. See How to create a profile on My DataLake Services.

Troubleshooting assigned roles

My DataLake Services provide a way to state what you want to use and how much. In exploitation, however, various problems may arise:

Incorrect roles assigned

If you have been assigned an incorrect role for Edge services, you will get the following message:

Request failed with status code 403
Response text: Missing quota role

Quota or limits exceeded

If the quota or limits have been exceeded, see FAQ article HDA quotas exceeded

What To Do Next

You should have access to all features associated with your new roles. In particular, you can start using hda page with the allocated quotas.

Also of interest:

How to invite a user to a project on My DataLake Services

How to manage users within a project on My DataLake Services

See status page for Destination Earth Data Lake hda services.