19Q0097_Statement_of_Work.docx

DOCX document 51 KB Posted

Attached to
Linux HPC Cluster Computer Federal contract opportunity
Solicitation number
N6893619Q0097
Issued by
Department of the Navy Naval Air Systems Command Naval Air Warfare Center

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

High Performance Computing Cluster Upgrade 20 December 2018

1.0 BACKGROUND

The Naval Air Warfare Center Weapons Division (NAWCWD), China Lake requires the purchase of a Linux-based high performance computing (HPC) cluster computer to execute numerical analyses performed by multiple programs in the support of various US Navy and DoD weapons programs.

1.1 SCOPE OF WORK

Modeling and simulation and numerical analyses constitute a significant portion of weapon system research and development efforts. Completing these simulations requires significant computational resources such as large amounts of memory and fast processor speed. Parallelization (the use of multiple processor cores by one simulation) is typically used to make problems tractable and to greatly reduce the time required to obtain results.

The existing system is over ten years in age, nearing end of useful manufacturer support, and experiencing increased maintenance costs to replace failing components. In order to maintain and expand the capability currently at NAWCWD for performing these numerical simulations, an upgraded Linux-based high performance computing cluster is required. This new cluster will utilize National Information Assurance Partnership (NIAP) appliances to include the latest advances in processor speed, networking speed, memory, and processing core count.

2.0 APPLICABLE DOCUMENTS

2.1 CLINGER COHEN ACT

2.1.1 The Contractor shall conduct analysis of program/project needs, acquisition strategy and program artifacts to identify and capture specific factors required to satisfy the 11 elements of Clinger-Cohen Act (CCA) compliance listed in DODI 5000.02, Enclosure 1, Table 9. Using Microsoft Word, the Contractor shall prepare a CCA compliance matrix following the organization and appearance of Table 11 with additional separate columns for the display of artifact: titles, date(s) of approval, page number(s), and paragraph or section number(s). The right-hand column shall include an embedded object permitting the reader to open unclassified artifacts. The column shall identify classified artifacts and shall describe approved classified channels for access of classified artifacts.

2.1.2 Updating approved CCA compliance packages: For updates of approved CCA compliance packages, the Contractor shall conduct analysis of program/project needs, acquisition strategy and program artifacts to identify and to determine if each of the Eleven (11) elements of CCA has changed and if no change has occurred a notation stating “no change” shall be entered in the CCA compliance matrix. If changes have been found, the Contractor shall update the CCA compliance matrix to reflect the changes. The Contractor shall support the program manager during CCA compliance review and assist in responding to reviewer comments if and when additional supporting information or revisions are required.

2.2 CYBER SECURITY

2.2.1 The Contractor shall conduct investigation and analysis of acquisition program artifacts such as but not limited to Initial Capabilities Document (ICD), Capability Description Document (CDD), Capability Production Document (CPD), Navy urgent operational need (UON) and Marine Corps urgent universal need statement (UUNS), joint urgent operational needs (JUONs), threat assessments and acquisition strategies (AS). Knowledge gained from this analysis shall be used when developing the Cybersecurity Strategy (CS) needed to steer and inform the program’s development of a System Security Plan (SSP) in accordance with DoDI 8510.01, of 12 March 2014

2.2.2 At a minimum, hardware, firmware, software, documentation (data deliverables) and/or Information Technology (IT) services delivered by this contract shall be in compliance with the following References:

2.2.2.1
DoDI 8500.01 Cybersecurity, 14 March 2014
2.2.2.2
DoD 5239.3 – Designated Approving Authority (DAA) Guidebook
2.2.2.3
CJCSI 6212.01C – Interoperability and Supportability of Information Technology and National Security Systems
2.2.2.4
DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), 12 March 2014, Incorporating Change 1, May 24, 2016
2.2.2.5
Committee on National Security Systems Instruction 1253, “Security Categorization and Control Selection for National Security Systems,” March 27, 2014, as amended.
2.2.2.6
DoDD 8140.01, Cyberspace Workforce Management, 11 August 2015.
2.2.2.7
DoD 8570.01-M Information Assurance Workforce Improvement Program, 15 August 2004, Certified Current as of 10 November 2015.
2.2.2.8
ISO: 9001 2015 Certified, and ANSI/ESD 20.20 Electrostatic Discharge Certified

The Contractor shall conduct investigation and perform analysis including; criticality analysis, threat assessment and vulnerability assessments. All findings and recommendations shall be reported to the government in technical reviews and submitted as written reports or documents as listed in Contract Data Requirements Lists. The Contractor shall support government efforts needed for Information systems (IS) (enclaves or major applications), Platform Information Technology (PIT) or PIT systems to successfully categorize the system, achieve favorable assessment for selection, implementation and testing of security controls and authorization (approval to operate) before use or interconnection in an operating environment in accordance with references (a), (b) and (c). This includes IT that is standalone and IT that is connected to other systems, networks or enclaves. Information systems (IS) (enclaves or major applications), planning proposed or performed under this contract shall be in compliance with reference (b) Enclosure 8, Figure 2 and all hardware, firmware and software deliverables shall be capable of receiving Authorization to Operate in accordance with reference (b).

Information technology services shall only be performed by personnel who are qualified and certified in accordance with reference (d). Personnel proposed and/or used in the performance of this contract as certified personnel shall be limited to those whose specifically assigned duties and responsibilities require certification.

All IT procured on behalf of this contract shall meet all DoD/DON and Naval Air Systems Command (NAVAIR) cybersecurity polices. These cybersecurity policies are standard across the Department and ensure cybersecurity compatibility and interoperability.

Given the standalone nature of the cluster, Contractor-owned equipment will not be permitted connection to NAVAIR/DoD networks in order to carry out the performance of this contract. Contractor-owned and operated networks are prohibited on any NAVAIR facility or site in support of this contract. The Contractor may access non-government, external IP space via the NAVAIR-provided Virtual Private Network (VPN) Outreach service or NAVAIR CIO approved Internet Protocol (IP) service.

The Contractor shall support the program manager during CCA compliance review and assist in responding to reviewer comments if and when additional supporting information or revisions are required.

3.0 REQUIREMENT/SPECIFICATIONS

3.1 Requirements

3.1.1 Hardware Manufacturing

All hardware shall be manufactured at the contractor-owned facility using industry-proven best practice quality control and manufacturing processes. All manufacturing shall be completed in an ISO: 9001 2015 Certified, and ANSI/ESD 20.20 Electrostatic Discharge Certified manufacturing facility.

3.1.2 Support

The Contractor shall provide identical ongoing technical, hardware and software support for the system expansions as is provided for the existing system, which includes regular onsite system administration and system engineering support.

3.1.3 System Management

The Contractor shall implement the identical system management, software tools, and software build currently being used in this environment, in order to maintain a consistent, identical operating and system administration / system management environment with current compute resources.

3.1.3.1 The Contractor shall incorporate Fault and Power Management with the deployment of the required Uninterruptible Electrical Power Supply system.

3.1.3.2 Fault Management shall include the following attributes:

3.1.3.2.1 Fault notification
3.1.3.2.2 Hardware diagnostics
3.1.3.2.3 ECC memory error notification and multibit error protection
3.1.3.2.4 Remote/local hardware monitoring
3.1.3.2.5 Fan speed/temperature environment monitoring
3.1.3.2.6 Temperature CPU monitoring and CPU, NIC utilization
3.1.3.2.7 Power-on self-test
3.1.3.2.8 Remote troubleshooting (Power On/Off) and diagnostics

3.1.3.3 Power Management shall include the following attributes:

3.1.3.3.1 Environmental controls / probes shall be connected to the Ethernet; To shut down the operating systems of the connected servers automatically in a controlled manner.

3.1.3.3.2 It shall be manageable via SNMP or other management protocols which enables prompt reaction on any unwanted situation.

3.1.3.4 The Contractor shall provide Diskless Compute Node capability. This capability shall include diskless compute node deployment method and diskless cluster management that can turn any supported Linux distribution into a master image capable of being used in a diskless environment.

3.1.3.5 The Contractor shall configure the cluster with standalone Yellowdog Updater (YUM). This is a tool for getting, installing, deleting, querying, and managing Red Hat Enterprise Linux RPM software packages.

3.1.3.6 The Contractor shall provide Node Provisioning capability included in ACME network bootable Linux environment independent of the environment installed on a cluster node which is used for deploying images across HPC cluster, testing and pre-configuration of cluster nodes, and stress testing. Images are created using ‘aspencopy’ and deployed through ACME ‘aspenrestore’.

3.1.3.7 The Contractor shall provide command line and graphical user interface (GUI) Tools for imaging, remote power and sensor programs. It will be used to quickly check status on nodes, remotely power cluster nodes on or off, or to reimage large groups of nodes. The Contractor shall install and configure resource manager, job scheduler and Ganglia scalable distributed monitoring system for clusters and grids. The Contractor shall configure the clusters with monitoring tools including performance/utilization, network saturation, power consumption and temperature monitoring.

3.1.3.8 The Contractor shall provide Data at Rest (DAR) FIPS-140-2 compliant cluster. The cryptographic mechanisms shall be employed on all non-volatile digital media.

3.1.4 System Requirements

The system will be made available for onsite benchmarking, testing, evaluation, and acceptance at the contractor’s manufacturing facility, with an option for remote access to the system prior to the final delivery. The Contractor shall provide opportunities for Government personnel to visit the contractor facility and work side-by-side with contractor personnel to assist in developing/providing feedback to items listed under section 3.1.5.

3.1.5 Documentation

The Contractor shall provide three technical documents for the cluster:

3.1.5.1 A detailed document on the proper procedures to perform periods processing with the cluster equipment. Periods processing is defined as the ability to process data of two or more classifications on the same equipment, one classification at a time, at different periods of time. A proper procedure will ensure that no residual data can be carried over into another processing period. At a minimum, the document will include procedures on safely shutting down the cluster, ensuring proper sanitization of all equipment, repopulating the cluster with new media, and reconfiguring the cluster. The documented procedure must be supported by statements of volatility from each equipment manufacturer, including all switches, servers, and KVMs.

3.1.5.2 A detailed document on how to perform system recovery procedures to rebuild the entire cluster. The document will contain all steps necessary to recover the system from bare-bone hardware, including procedures for hardware configuration, software installation and configuration, and base operating system security configuration, to and operational cluster environment. In the event of total system failure or in the need to rebuild a new system with new hard drives, the document must be able to provide sufficient procedures to assist a journey-level system administrator with rebuilding the cluster to operating with a base operating system, install contractor-provided utilities, and securely configure it to meet DoD Cybersecurity requirements.

3.1.5.3 A detailed document on maintaining the clusters hardware and software, including intervals for periodic maintenance. Relying on years of experience supporting the current systems, and its technical experts, performing maintenance on the cluster and its components.

3.2 SPECIFICATIONS

The Contractor shall provide a plug-and-play Linux-based high performance computing cluster which meets the following specifications to include NIAP appliances:

3.2.1 Head Nodes:

Two (2) 2U Dual Socket Head Node (Supermicro SuperServer SYS-6029P-TR) shall be provided, with the following specifications:

3.2.1.1 Two (2) Intel® Xeon Gold 6132 (Skylake, 2.6GHz Fourteen-Core 10.4GT/s 19.25MB, Processor)

3.2.1.2 Twelve (12) sticks of 16 gigabytes (GB) (192 GB Total) DDR4 2666MHz ECC Registered Memory

3.2.1.3 Three (3) 960GB Intel S4500 Series 2.5" Solid State Hard drive (SSD) (SSDSC2KB960G701) (Configured as RAID5)

3.2.1.4 One (1) Intel X722 GbE (onboard)

3.2.1.5 One (1) Broadcom, P1100P, NX-E Single port 1/10/25/40/50/100 Gbps QSFP28 PCIe 3.0 x16 card

3.2.1.6 One (1) Broadcom 9361-8i 12Gb/s RAID Controller

3.2.1.7 One (1) Onboard Intel® X722 Dual Port Gigabit Ethernet

3.2.1.8 One (1) Intel X710-DA2 Dual Port 10Gigabit SFP+ Converged Network Adapter PCIE x8 Low-Profile

3.2.1.9 Power and Ethernet cables

3.2.1.10 Red Hat Enterprise operating system installation and configuration

3.2.1.11 Supermicro Update Manager license

3.2.1.12 5-Year Hardware Warranty Support with 8x5 Support, Expedited RMA Shipments

3.2.1.13 Lifetime Technical Support (Original Software Configuration, minor updates)

3.2.2 Compute Nodes:

Eight (8) 2U Twin/Twin Dual Socket Compute Servers(s) (Supermicro SuperServer SYS-6029TP-HTR, each server has four (4) independent nodes per chassis), each independent node with the following specifications:

3.2.2.1 Two (2) Intel® Xeon Gold 6142 (Skylake, 2.6GHz, Sixteen-Core, 10.40GT/s, 22MB, 150W TDP Processor)

3.2.2.2 Twelve (12) sticks of 16 GB (192 GB Total) DDR4 2666MHz ECC Registered Memory

3.2.2.3 One (1) Intel i350 GbE NIC

3.2.2.4 One (1) Broadcom, P1100P, NX-E Single port 1/10/25/40/50/100 Gbps QSFP28 PCIe 3.0 x16 card

3.2.2.5 One (1) SIOM Intel i350 dual port 1GbE, RJ45 adapter

3.2.2.6 Power and Ethernet cables

3.2.2.7 Supermicro Update Manager license

3.2.2.8 5-Year Hardware Warranty Support with 8x5 Support, Expedited RMA Shipments

3.2.2.9 Lifetime Technical Support (Original Software Configuration, minor updates)

3.2.3 Network Attached Server (NAS):

Two (2) 4U 36-bay Dual Socket Storage Server (Supermicro SuperServer SSG-6049P-E1CR36H) with the following specifications:

3.2.3.1 Two (2) Intel® Xeon Silver 4110 (Skylake, 2.1GHz, Eight-Core, 9.6GT/s, 11MB, 85W TDP Processor)

3.2.3.2 Twelve (12) sticks of 16 GB (192GB Total) DDR4 2666MHz ECC Registered Memory

3.2.3.3 Thirty-six (36) 6 Terabyte (TB) HGST Ultrastar (HUS726T6TAL5204), 256MB Cache SAS 12Gb/s Hard Drive (Configured as RAID6)

3.2.3.4 Two (2) Intel 960GB S4500 Series 2.5" SSD (SSDSC2KB960G701) (Configured as RAID1)

3.2.3.5 One (1) Intel X722 + X557 10GbE (onboard)

3.2.3.6 One (1) Intel X710-DA2 Dual Port 10Gigabit SFP+ Converged Network Adapter PCIE x8 Low-Profile

3.2.3.7 One (1) Broadcom, P1100P, NX-E Single port 1/10/25/40/50/100 Gbps QSFP28 PCIe 3.0 x16 card

3.2.3.8 One (1) Broadcom 3108 12Gb/s RAID Controller, with battery backup

3.2.3.9 One (1) Onboard Intel® X722 + X557 Dual Port 10Gigabit Ethernet

3.2.3.10 Power and Ethernet cables

3.2.3.11 Red Hat operating system installation and configuration

3.2.3.12 Supermicro Update Manager license

3.2.3.13 5-Year Hardware Warranty Support with 8x5 Support, Expedited RMA Shipments

3.2.3.14 Lifetime Technical Support (Original Software Configuration, minor updates)

3.2.4 10 GigE Network:

Networking appliance be NIAP validated.

3.2.4.1 Two (2) Brocade ICX-7450-48 switches (each with 48 ports)

3.2.4.2 Cabling as necessary to connect switches and cluster nodes

3.2.5 100 GigE Network:

A high-speed network connecting all cluster nodes shall be provided, with the following specifications and must be NIAP validated:

3.2.5.1 Two (2) Extreme Networks Summit x870-32c 32-port 100 GigE Network Switch

3.2.5.2 Two (2) Extreme Networks 770W AC Power Supplies, front to back airflow

3.2.5.3 Six (6) Extreme Networks, module fan, front to back airflow

3.2.5.4 5-Year Hardware Warranty Support with 8x5 Support, Expedited RMA Shipments

3.2.5.5 QSFP passive copper cabling as necessary to connect switches and cluster nodes

3.2.6 Power Distribution System:

A power distribution system shall be provided, with the following specifications:

3.2.6.1 Six (6) Eaton Metered Vertical Power Distribution Unit (PDU) 5.76kW (EMO107-10) with L6-30P connector

3.2.6.2 Four (4) Eaton 9PX11K 11 kVA 6U rackmount uninterruptible power supply (UPS) with L6-30R output

3.2.6.3 Two (2) Eaton environmental monitoring probe (EMP001) for measuring humidity and temperature

3.2.6.4 Power cables as necessary to connect all cluster components to power distribution unit

3.1.7 Keyboard, Video, Monitor

3.1.7.1Two (2) Aten, 17.3" LCD KVM Switch (CL6700MW) 1920x1080, supports external console with USB, DVI, VGA, and HDMI, includes 1x 6ft KVM cable (DVI-D, USB, Audio)

3.1.8 Spare Equipment

3.1.8.1 Twelve (12) Intel S4500 Series 2.5" 960GB SATA III SSD (SSDSC2KB960G701)

3.1.8.2 Ten (10) HGST, Ultrastar (HUS726T6TAL5204) 6TB Hard Drive, 7200 RPM, 256MB Cache, SAS 12Gb/s 3.5"

3.1.8.3 Spare drive 5-year RAID Storage Unit Warranty

3.1.9 Software

The Contractor shall provide, install, and configure a Linux operating system on all cluster nodes, in accordance with the following specifications:

3.1.9.1 Four (4) Red Hat Enterprise Linux Server Entry Level Licenses (RH00005F3), Self-support, 3 Year

3.1.9.2 Thirty-two (32) Red Hat Enterprise Linux Server Licenses for HPC Compute Node (RH0635043F3), Self-support (1-2 sockets) (Up to 1 guest), 3 Year

3.1.9.3 Contractor systems cluster software stack including Cluster Management Software Aspen Cluster Management Environment (ACME), hardware and software configuration, operating system, applications, schedules, monitoring tools, compilers, MPI, and additional software and/or scripts for cluster management and node provisioning.

3.1.10 Training and Installation Assistance

The Contractor shall assist in the installation and integration into the existing compute facility located at China Lake, CA. and perform testing and evaluation at its Contractor facility.

3.1.10.1 China Lake, CA - Minimum 3-dayonsite cluster installation, integration and training.

3.1.10.2 Contractor Facility - Minimum 3-day dedicated to engineering with the contractor at its facility for system testing, evaluation, benchmarking, and modifications with the government evaluation team. The government team will work in parallel with the contractor, as the contractor configures one cluster the government evaluation team will replicate the configuration on the second cluster.

3.1.11 Software Compatibility

Cluster shall have demonstrated compatibility (successful, multi-processor operation using the high speed network) with the following software packages:

Star-CCM+ v. 12.04
EMACS Viewer 24.3

Tiger VNC 1.3 Avago Mega RAID Storage Manager 17.05

McAfee Virus Scan Linux 6.1 RHEL v.7.X (The most current version of RHEL)

4.0 DELIVERY

4.1 Delivery

The high performance computing cluster shall be delivered within 3 months after date of award to:

Commander, NAWCWD Attn: Ceferino Aratea JR Building 01371 China Lake, CA 93555

5.0 MISCELLANEOUS

5.1 Warranty

The Contractor shall provide a standard, extended commercial warranty (5 year parts replacement warranty).

5.2 Component Release

Any failed parts, components, and/or equipment will not be returned to any vendor for replacement, as such all standard and extended commercial warranties will be fully honored.

File details come from the government source that posted it.