Skip to main content

User Policies

This page summarises the Access and Usage Policy for the ACE HPC (Compute and Storage Resources) that governs every user of the African Centre of Excellence in Bioinformatics & Data Intensive Sciences (ACE) high performance computing infrastructure.

Introduction

In 2019, the Infectious Diseases Institute (IDI), Makerere University's College of Computing & Health Sciences, in partnership with the US Government National Institute of Allergy and Infectious Diseases and the Office of Cyber Infrastructure and Computational Biology (NIH/NIAID/OCICB), established the African Centre of Excellence in Bioinformatics & Data Intensive Sciences — one of only two such centres on the African continent, the other located in Mali. Since its establishment, the ACE has assembled a variety of computational facilities.

The ACE computational facilities encompass hardware (a high performance computing cluster, a data centre, a tele-learning centre, a Virtual Reality room and a 3D printer), software, network connections and data. Failure to use these resources properly may result in various penalties, including but not limited to loss of access and administrative, academic, civil and/or criminal action.

The policies below apply to all IDI staff, the wider Makerere University research community and Uganda at large, foreign nationals (such as visiting scholars and external users), students, and all end-users who by the nature of their work need to use or visit the facilities. For the purposes of this policy, the term "HPC" includes all systems operated by ACE — virtual machines, VPN concentrators, workstations, the HPC cluster, virtual reality equipment and any other platforms.

note

These policies are neither exhaustive nor exclusive. The fact that a certain action is not mentioned does not imply that it is permitted or prohibited. Before taking such an action, check with the ACE Service Desk at support@ace-bioinformatics.org and wait for confirmation.

Access and Usage Policy

Access is granted for research and education that meets the objectives of the ACE program and can be revoked at any time if users do not adhere to the terms of use. The ACE infrastructure provides a suite of services including Virtual Reality, HPC, Virtual Machines and Kubernetes.

Requirements

Authorisation

Matriculated students and faculty in the Bioinformatics program can request accounts. Other users must be part of an approved project with a Principal Investigator who sponsors their account, and then be approved by the ACE Director or authorised delegate. Authorisation is granted via ACE User registration, upon which a user account is created. As part of this process, users must read and sign the ACE HPC User Policy and complete the appropriate training.

Obtaining a User Account

To get an account on the ACE HPC, a prospective user follows the application process below:

  1. Send an email to support@ace-bioinformatics.org. In response, you are required to fill in a request form containing information about your research goals, technical requirements (including CPU core hours and storage), scientific programming needs and HPC experience.
  2. Complete a quiz testing your knowledge of Slurm and Linux technologies used on the HPC. Support documents are provided to help you prepare, based on the experience indicated in your request form. A minimum score of 14/15 is required to pass.
  3. Read thoroughly through the HPC user policy and return a signed copy via email.
  4. New proposals are reviewed weekly and outcomes reported to applicants (for those requesting a waiver) or quotations sent otherwise.
  5. Indicate training requirements, as this helps the ACE team prioritise and schedule training workshops.

Valid Contact Email

Every account must have an associated contact email address. Email is the primary communication channel between ACE@HPC and the user.

Subscription to the ACE HPC Users Mailing List

While an account is active, the user must subscribe to the ACE users mailing list. This list is used to notify everyone of important changes and events such as training, software updates and scheduled maintenance. Membership is automatic upon account creation and persists until the account is deactivated.

Training

Prior to account activation, each new user must attend/complete whatever training is specified for the resource requested, and a certificate of completion is issued. All new users must complete new-user training in addition to any resource-specific training.

Usernames and Passwords

A unique username and associated password are required of all ACE HPC users. Passwords must follow the minimum strength policy below:

  • Consist of a minimum of 14 characters.
  • Use a random mixture of upper- and lower-case letters, numbers and symbols (remember you may need to enter it on a tablet or smartphone).
  • Avoid dictionary words, names, dates or common phrases.
  • Avoid simple sequences or keyboard patterns such as qwertyuiop or 23456789.
  • Do not share usernames, passwords, authentication codes or SSH keys used to access ACE Uganda HPC resources.

Access to the HPC Cluster

Access to the HPC Linux cluster is via the Secure Shell protocol (SSH) to the respective login nodes, or via other interfaces intended for direct access (e.g. the Open OnDemand web portal). All access to compute nodes must be via the job scheduler (SLURM) — direct access to compute nodes is not permitted. A maximum number of concurrent login sessions is enforced on login nodes, and idle SSH sessions are automatically disconnected. These limits are adjusted as necessary to manage login-node resources and comply with applicable security standards.

Remote Access Policy

Access to the platform from offsite of ACE-IDI is only allowed via encrypted VPN with a multifactor token (a physical token or a virtual token used with one-time password software on a smartphone). When account entitlement ends, the user's token is disabled. Physical tokens remain the property of ACE and must be returned upon completion of approved activities.

The remote device (any laptop, tablet or PC) does not need to be managed by ACE, however:

  • Users are responsible for deploying firewalls, anti-malware software and automatic updates on remote devices, all of which should be up to date.
  • Users are responsible for the risk of connecting from public networks and must act with care in public places to avoid screens and confidential activity being overlooked by unauthorised persons.
  • Users are responsible for the usernames and passwords on their machine, following the password guidelines above.
  • Users must connect to the ACE HPC using a secure encrypted connection.
ACE Cyberinfrastructure Use by Foreign Nationals

ACE Uganda was launched as a regional platform to enable science. Its use by foreign nationals is generally permitted regardless of whether access is from within Uganda or abroad. Foreign nationals must comply with all ACE usage policies and with local and Government of Uganda policies and regulations on national security.

User Responsibilities

Individual Account Management

Access to HPC@ACE is via password-protected personal accounts created by ACE administrators. You are responsible for protecting your account from unauthorised access and for the proper expenditure of allocated resources. Users are expected to follow standard security practices to ensure the safety of their accounts and data. Policies regarding account creation and access are subject to change.

Maintaining an Up-to-date Contact Email

Every user is responsible for keeping their contact email address up to date. If an address is discovered to be invalid, the associated account will be locked. Promptly inform ACE of any changes in contact information.

Account Sharing

Users may not share their accounts, passwords, personal identification numbers, security tokens or similar identification/authorisation information or devices. Your account is for your use only — it is not to be shared with students, collaborators or anyone else. Others who need access must request their own account. Under no circumstances may any user make use of another user's account.

Account Passwords

Each account is associated with a password that serves as the key to account access. You are responsible for protecting your password from unauthorised access. Don't write your password where it can be easily found. Passwords must not be shared and must be changed as soon as possible upon suspected compromise, or at the direction of ACE personnel. Passwords must be changed every 180 days.

Mailing List Membership

Mailing list membership is automatic upon account creation and persists until the account is deactivated. Anyone wishing to be removed should email support@ace-bioinformatics.org and request that their account be terminated.

Fair (Acceptable) Usage Policy

Reporting Suspicious Activity

ACE personnel and HPC users are required to address, safeguard against and report misuse, abuse, criminal activity and all violations of the ACE HPC Policy to the ACE HPC Help Desk (support@ace-bioinformatics.org) so that necessary steps can be taken to contain and rectify the incident. Misuse can lead to temporary or permanent disabling of accounts, administrative sanctions or legal action.

You are responsible for reporting, as soon as possible, any suspicious activity on your account and any exposure or compromise of passwords.

Data Protection and Confidentiality

You are responsible for ensuring the confidentiality of any data you use or store on the ACE HPC and for compliance with any legal or regulatory frameworks governing that data. Such data may include intellectual property (e.g. research in progress), protected health information (e.g. patient medical records), personally identifiable information (e.g. names, National Identification Numbers, student registration numbers), and proprietary or licensed data. It is your responsibility to be aware of any requirements on a particular data set.

ACE HPC resources are operated as research systems and should only be used to process and store data related to authorised research. This prohibits the use of the HPC to profit from non-sanctioned activities such as cryptocurrency generation. Any additional encryption required by data owners must be applied by the user; if system-level encryption is required for a project, it must be included in the project request or as an amendment to an existing request.

Acknowledgment

Papers, publications and web pages of any material — whether copyrighted or not — based on or developed under ACE-supported projects must acknowledge this support by including the following statement:

"Portions of this research were conducted with high performance computing resources provided by the African Centres of Excellence in Bioinformatics and Data Intensive Sciences (https://ace.ac.ug)"

The acknowledgment shall include a citation referencing the ACE publication available at https://doi.org/10.37191/Mapsci-JIDM-1(2)-006, and may include the ACE logo when appropriate.

Software Licenses

All software used on HPC@ACE systems must be appropriately acquired and used according to its licensing. Possession, transmission or use of illegally acquired software on HPC resources is prohibited. Users shall not copy copyrighted software or materials except as permitted by the owner or copyright. Project requests should list the software that will be used; requests for commercial software licenses should be directed to the ACE Centre Director and the Operations team.

Final Reports

Requests for subsequent resource allocation awards will not be permitted until an end-of-project report has been received for all prior awards. Continuing projects are encouraged to attach prior award final reports to the submitted resource request proposal.

Read the Announcements

Users are responsible for reading system messages and announcements. These appear during login via SSH or the Open OnDemand web portal and are also sent to all users at their registered email. It is the user's responsibility to monitor that email account for messages.

System Protection, Data Retention and Recovery

Backup and Retention

ACE-UHPCC provides daily backups of Home Directories for disaster recovery purposes only, retained for 90 days. Project directories are not automatically backed up — it is the responsibility of the project owner to ensure critical data is saved elsewhere.

Although ACE takes steps to ensure the integrity of stored data, it does not guarantee that data files are protected against destruction. Users are strongly encouraged to make backup copies of their data. ACE reserves the right to remove any data after a user account is deleted or a user no longer has a business association with ACE.

Monitoring and Privacy

Privacy Policy

ACE HPC users have no explicit or implicit expectation of privacy. ACE retains the right to actively monitor all HPC resources, activities on ACE systems and networks, and to access any file without prior knowledge or consent of users, senders or recipients.

Data Collected

The ACE servers hold details of user accounts to enable login and use of HPC resources. The following data are collected and maintained for each user:

  • Name
  • User identifier (account name)
  • Institution affiliation
  • Project affiliation
  • Email address
  • Contact telephone number
  • User administration history
  • Login history (session begin/end times and originating IP address)
  • Resource consumption (job records accumulated by the job scheduler)
  • Use of licensed applications (while ensuring license-term compliance)

These data are held from the time the account is created, whether or not the user ever uses the ACE HPC. Unused accounts, or accounts idle for 6 months, will be disabled; reactivation requires approval by the project owner or the ACE Director. Research data in home directories or other personal/group storage is stored as required for ACE services, until purged by the user or by ACE to enforce policy (such as account termination or expiry of access). From time to time, ACE may gather publication data from external journals or preprint listings to assess research outputs facilitated by its infrastructure.

User Problems and Staff Response

Users are welcomed and encouraged to email the HPC team if they have problems or concerns relating to HPC@ACE. The HPC staff respond during normal weekday business hours.

Scheduled Maintenance

To improve system security and availability, a monthly maintenance cycle has been instituted, generally involving a reboot of some nodes (not the entire cluster). Unscheduled maintenance requiring longer downtime is announced separately to the ACE users email list. Every effort is made to minimise disruptions.

Resource Scheduling and Jobs

The ACE HPC resources are shared by many users. ACE uses a workload management system to implement and enforce policies that provide each user with fair but limited access to the clusters.

Jobs exceeding their allocated resource amounts will be terminated by the system or system administrators with little or no warning. To avoid loss of data due to unexpected termination, users are strongly encouraged to checkpoint running jobs at regular intervals. Misuse of the system, deliberate or otherwise, is subject to the three-strike policy.

General Storage Quotas

HPC User Home Directories

  • Default quota: 50 GB per user.
  • Maximum quota: Up to 200 GB upon a valid request and justification.

Project Directories

  • Default quota: 1 TB per project.
  • Maximum quota: Up to 5 TB with a valid request and justification.

Procedure for Requesting Additional Storage

  • Submission: Users or projects requiring storage beyond the default quota should formally submit a request to the HPC administration via the HPC admin contact.
  • Content of request: The request should detail the justification for the additional storage, specifics of the project, estimated data sizes, and the duration for which additional storage is needed.
  • Review process: The HPC administration team reviews the request. If deemed appropriate, it is forwarded to the Centre Director for final approval.
  • Notification: Users are notified of the final decision within the specified duration (e.g. two weeks).

Overage and Clean-up

  • Warning notification: Users are alerted when storage consumption crosses the 90% threshold of their allocated quota.
  • Exceeding quota: If a user or project surpasses its quota, write access may be provisionally revoked. Write privileges are restored once stored data is reduced to align with the assigned quota.
  • Temporary storage maintenance: Data in temporary storage zones is systematically deleted after 30 days of inactivity.

Account Expiration

ACE audits cluster accounts annually, and all accounts not associated with a valid email address are terminated, since ACE must be able to contact all account holders for security and communication purposes. Accounts expire after the duration specified at the time of issuance. Users wishing to continue access beyond the allocated duration should apply to renew. Users are ultimately responsible for ensuring all files are properly managed or removed prior to account expiration. Upon expiration, user accounts and associated data are deleted.

Prohibited Conduct

The following conduct is prohibited under this policy and is subject to penalties:

  • Unauthorised access to or use of ACE resources.
  • Requesting or actively using more than one individual account.
  • Creation, transmission or storage of illegal, inappropriate or sexually explicit data on information resources.
  • Usage beyond the stated purposes in the allocation proposal.
  • Unauthorised alteration of system configurations or disruption of IT administration.
  • Unauthorised installation of software. Requests for software installations should be directed to support@ace-bioinformatics.org.
  • Unauthorised access to others' accounts, files or communications.
  • Misrepresentation in electronic communication.
  • Violation of copyright and software agreements.
  • Interference with others' use of ACE resources.
  • Commercial use or representation of unaffiliated groups without ACE authorisation.
  • Non-compliance with departmental or unit policies.
  • Unauthorised facilitation of access to ACE resources.
  • Unauthorised disclosure or exposure of sensitive/confidential information.
  • Illegal, fraudulent or malicious use of IT resources, including activities against Uganda regulations.
  • Transmission of unsolicited bulk/marketing material.
  • Harassment, threats, bullying, or promotion of hatred, terrorism or illegal activities.
  • Activity that degrades ACE HPC performance, deprives authorised access, or circumvents security unless authorised.
  • Unauthorised use of security utilities or programs that exploit ACE HPC vulnerabilities.
  • Unauthorised personal benefit, political activity, advertising, fundraising, or actions prohibited by Uganda law.

Penalties / Sanctions / Enforcement

Breaches of this policy may result in a variety of penalties, including but not limited to:

Account Suspension/Revocation

Accounts may be suspended or permanently revoked if compromised or abused. Your account may be suspended without advance notice if there is suspicion of account compromise, system compromise, or malicious or illegal activity.

Loss of Allocation

Unauthorised behaviour can result in loss of your current allocation and may lead to the inability to obtain future allocations.

Administrative Action

Unauthorised activity may be reported to your PI, supervisor, academic authorities or ACE authorities for administrative review and action.

Civil Penalties

Civil remedies may be pursued to recoup costs incurred from unauthorised use of resources or incident response due to compromise or malicious activity.

Criminal Penalties

Activities in violation of university, national or local law may be reported to the appropriate authorities for investigation and prosecution.

Exceptions

There are no exceptions to this policy. HPC users may not deviate from the terms of this ACE HPC Appropriate Use Policy in any way.

References

  1. docs.hpc.cam.ac.uk/srcp/isms-docs
  2. projects.ncsu.edu/hpc — AUP
  3. hpcc.umd.edu/hpcc/policies
  4. policies.umd.edu
  5. iiap.res.in — HPC Usage Policies (PDF)
  6. hpc.inl.gov — Access and Usage Policy
  7. nrel.gov/hpc — Appropriate Use Policy
  8. hpc.loni.org — HPC Policy
  9. research.computing.yale.edu — HPC Policies
  10. tacc.utexas.edu — User Policies