Skip to content

Public demonstration

The public demonstration is one dedicated instance, always named demo, where anybody can look around without an account. A visitor presses Look around on the sign-in page and gets a short visit of the public NLOG sample: the province wells and a gamma-ray log. Nothing can be changed. The demonstration is reset to the same copy on a schedule.

It runs on a trial host next to other instances, made and kept by ophiolite-ops instance, as on Dedicated instances. Read that page first: the host rule, the prerequisites and the host proxy are the same.

A visitor can open the sample project, list and filter its data, plot a log, look at the wells and download what they see. A visitor cannot upload, edit, run a calculation, invite anybody, connect an application or see who else is looking. Every request that would change something is refused with the same sentence, and the Workspace shows it as one dialog: “This is a public demonstration: you can look, filter, plot and download, but not change anything.”

A visit ends after a while, and every visit ends when the demonstration is reset. The Workspace then shows the end of the visit and a Look around again button.

Starting a visit is limited per client address and overall. When too many people start at once, a visitor sees a page that says the demonstration is busy and how long to wait.

Terminal window
python3 ophiolite-ops instance create demo --kind demonstration --image REF

create makes the instance as it makes a trial, then:

  • loads the sample as the instance’s administrator, so the visitor is never an author;
  • makes the visitor account a viewer of the sample project, without calculations or administration;
  • issues the visitor’s credential and checks it against the server before the gateway uses it;
  • turns the demonstration on, checks it, and keeps a golden copy of the database outside the instance’s volumes, in instances/demo/golden/, with its checksum;
  • routes demo.DOMAIN through the host proxy.

Nobody is sent a link, so create takes no --email. A host has one demonstration.

Terminal window
python3 ophiolite-ops instance health demo

health answers ok, degraded or down, with the reasons, and exits 0, 1 or 2. It asks the server directly, inside the instance, with the visitor’s credential: no sign-in, no session. It is down when the server does not answer, when the visitor sees anything but one project as a viewer, when the sample differs from the golden copy, when any account other than the administrator and the visitor is enabled, or when the credential is revoked or ends within a day. It is degraded when the credential ends within five days.

python3 ophiolite-ops instance check demo also names the command that resumes a reset that stopped, and finishes a credential change that was interrupted.

Terminal window
python3 ophiolite-ops instance reset demo

A reset brings the demonstration back to its golden copy:

  1. The golden copy is checked first: its checksum, its contents and its release. If anything is wrong, the reset stops and nothing has changed.
  2. The host proxy answers demo.DOMAIN itself with a maintenance page (status 503, Retry-After), so visitors see it while the instance is down.
  3. The instance and its volumes are removed and made again, the golden copy is restored into them, and the server starts on its own loopback port only.
  4. A new visitor credential is issued and checked, and every other one, including the one inside the golden copy, is revoked.
  5. Only when health is ok does the route serve visitors again.

If a reset stops after step 2, the demonstration stays on the maintenance page. Run the same command again to finish it. While a reset runs, reset, rotate, upgrade and remove for demo refuse and name the command that runs; health still answers.

After an upgrade of demo the golden copy is from the older release, and reset refuses it: remove the demonstration and create it again.

Terminal window
python3 ophiolite-ops instance rotate demo

The new credential is a separate one: it is issued, checked against the server, and put in place of the old one in a single step; only then is the old one revoked. If the command is interrupted, the credential in use still works, and check or the next rotate finishes the change. A credential lasts 14 days; every reset issues a new one.

Terminal window
python3 ophiolite-ops instance timers demo

timers prints two systemd user timers, a health check every five minutes and a nightly reset, with the commands they run. It writes nothing: save the files it prints and enable them yourself. A failed health check shows as a failed unit.

Before you tell anybody the address, have someone who did not set it up try it, with nothing but the address:

  1. Open the address in a fresh browser profile, with no saved sign-in.
  2. Press Look around and note how many seconds pass before the project appears.
  3. Open the wells, plot a log, and download what you see.
  4. Try three changes: upload a file, edit a value, start a calculation. Each one shows the same sentence and changes nothing.
  5. Run health demo afterwards; it still answers ok.
  • The demonstration is read-only for everybody who has not signed in, and nobody signs in to it.
  • It has one sample project; a visitor’s own work is never kept.
  • The demonstration’s public address is not published yet.