User Tools

Site Tools


vpnaccess

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
vpnaccess [2026/02/23 14:20]
djgalloway
vpnaccess [2026/08/18 20:25] (current)
djgalloway [Approvals]
Line 1: Line 1:
 ====== VPN Access ====== ====== VPN Access ======
 ===== Requesting Access ===== ===== Requesting Access =====
-To request access to the Sepia lab, 
-  - Generate login credentials by following directions under **VPN Client Access** below. 
-  - [[http://​tracker.ceph.com/​projects/​lab/​issues/​new?​issue[tracker_id]=3|File a ticket]]. 
-  - Copy and paste the questions below into your ticket 
  
-<​code>​+Visit https://​onboarding.sepia.ceph.com/​
  
-1) Do you just need VPN access or will you also be running teuthology jobs?+===== Approvals =====
  
-2Desired Username:+User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link.  (Other domains can be added. ​ For now, IBM and Red Hat seemed safest.)
  
-3) Alternate ​e-mail ​address(es) we can reach you at:+Non-whitelisted domains require an existing lab user to "​vouch"​ for them by clicking a magic link in their e-mail.  Then a Lab Admin still has to approve.
  
-4) If you don't already have an established history of code contributions to Ceph, is there an existing community or core developer you've worked with who has reviewed your work and can vouch for your access request?+Once an account ​is approved, automation runs to add the user's public key to https://​github.com/​ceph/​keys ​and their user entry to https://​github.com/​ceph/​ceph-sepia-secrets.
  
-If you answered "​No"​ to # 4, please answer the following (paste directly below the question to keep indentation):​ +The user will then be e-mailed their Wireguard ​IP and can log in.
- +
-4a) Paste a link to a Blueprint or planning doc of yours that was reviewed at a Ceph Developer Monthly. +
- +
-4b) Paste a link to an accepted pull request for a major patch or feature. +
- +
-4c) If applicable, include a link to the current project (planning doc, dev branch, or pull request) that you are looking to test. +
- +
-5) Paste your SSH public key(s) between the pre tags +
- +
-6) Paste your Wireguard ​public key between the pre tags +
-</​code>​ +
-===== VPN Client Access ===== +
-See [[wireguard|Wireguard Access]] +
- +
-===== A Note About DNS ===== +
-Due to complexities around adding nameservers to various Linux distro VPN clients, our OpenVPN server does not use the [[https://​openvpn.net/​index.php/​open-source/​documentation/​howto.html#​dhcp|dhcp-option DNS]] option. +
- +
-Instead, we serve our private DNS records publicly. ​ Your machine should be able to resolve hostnames under the ''​sepia.ceph.com''​ subdomain automatically. +
- +
-If you're using dnsmasq, you can add ''​server=/​sepia.ceph.com/​172.21.0.1''​ to ''/​etc/​dnsmasq.conf''​.+
vpnaccess.1771856422.txt.gz · Last modified: 2026/02/23 14:20 by djgalloway