vpnaccess
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| vpnaccess [2026/02/23 14:22] – [Requesting Access] djgalloway | vpnaccess [2026/09/16 18:42] (current) – djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== VPN Access ====== | ====== VPN Access ====== | ||
| - | ===== Requesting Access ===== | + | ===== Requesting |
| - | To request access to the Sepia lab, | + | |
| - | - Generate login credentials by following directions under **VPN Client Access** below. | + | |
| - | - [[http:// | + | |
| - | - Copy and paste the questions below into your ticket | + | |
| - | < | + | Visit https:// |
| - | 1) Do you just need VPN access or will you also be running teuthology jobs? | + | ===== Existing User Additional Credential ===== |
| - | 2) Desired Username: | + | Use this form if you are registering an additional machine and need another Wireguard or SSH key. |
| - | 3) Alternate e-mail address(es) we can reach you at: | + | See https://onboarding.sepia.ceph.com/ |
| - | | + | |
| - | 4) If you don't already have an established history of code contributions to Ceph, is there an existing community or core developer you've worked with who has reviewed your work and can vouch for your access request? | + | ===== Existing User Replace Credential ===== |
| - | If you answered " | + | Use this form if you are // |
| - | 4a) Paste a link to a Blueprint or planning doc of yours that was reviewed at a Ceph Developer Monthly. | + | https:// |
| - | 4b) Paste a link to an accepted pull request for a major patch or feature. | + | ===== Existing User Remove SSH Key ===== |
| - | 4c) If applicable, include a link to the current project (planning doc, dev branch, or pull request) that you are looking to test. | + | https:// |
| - | 5) Paste your SSH public key(s) between the pre tags: < | + | ===== Approvals ===== |
| - | 6) Paste your Wireguard public key between the pre tags < | + | User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link. (Other domains can be added. |
| - | </ | + | |
| - | ===== VPN Client Access ===== | + | |
| - | See [[wireguard|Wireguard Access]] | + | |
| - | ===== A Note About DNS ===== | + | Non-whitelisted domains require an existing lab user to " |
| - | Due to complexities around adding nameservers to various Linux distro VPN clients, our OpenVPN server does not use the [[https:// | + | |
| - | Instead, we serve our private DNS records publicly. | + | Once an account is approved, automation runs to add the user's public key to https:// |
| - | If you're using dnsmasq, you can add '' | + | The user will then be e-mailed their Wireguard IP and can log in. |
| + | |||
| + | Admins can approve/deny/clean up at https:// | ||
vpnaccess.1771856521.txt.gz · Last modified: by djgalloway
