User Tools

Site Tools


vpnaccess

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
vpnaccess [2026/02/23 14:22] – [Requesting Access] djgallowayvpnaccess [2026/09/16 18:42] (current) – djgalloway
Line 1: Line 1:
 ====== VPN Access ====== ====== VPN Access ======
-===== Requesting Access ===== +===== Requesting New Access =====
-To request access to the Sepia lab, +
-  - Generate login credentials by following directions under **VPN Client Access** below. +
-  - [[http://tracker.ceph.com/projects/lab/issues/new?issue[tracker_id]=3|File a ticket]]. +
-  - Copy and paste the questions below into your ticket+
  
-<code>+Visit https://onboarding.sepia.ceph.com/
  
-1) Do you just need VPN access or will you also be running teuthology jobs?+===== Existing User Additional Credential =====
  
-2) Desired Username:+Use this form if you are registering an additional machine and need another Wireguard or SSH key.
  
-3) Alternate e-mail address(es) we can reach you at: +See https://onboarding.sepia.ceph.com/wireguard/request
-   (Other than the one used to create your tracker/Redmine account.  Optional.)+
  
-4) If you don't already have an established history of code contributions to Ceph, is there an existing community or core developer you've worked with who has reviewed your work and can vouch for your access request?+===== Existing User Replace Credential =====
  
-If you answered "No" to # 4, please answer the following (paste directly below the question to keep indentation):+Use this form if you are //replacing// a machine and no longer need your previous Wireguard key/SSH key.
  
-4a) Paste a link to a Blueprint or planning doc of yours that was reviewed at a Ceph Developer Monthly.+https://onboarding.sepia.ceph.com/wireguard/replace
  
-4b) Paste a link to an accepted pull request for a major patch or feature.+===== Existing User Remove SSH Key =====
  
-4c) If applicable, include a link to the current project (planning doc, dev branch, or pull request) that you are looking to test.+https://onboarding.sepia.ceph.com/keys/request
  
-5) Paste your SSH public key(s) between the pre tags: <pre></pre>+===== Approvals =====
  
-6) Paste your Wireguard public key between the pre tags <pre></pre> +User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link.  (Other domains can be added.  For now, IBM and Red Hat seemed safest.)
-</code> +
-===== VPN Client Access ===== +
-See [[wireguard|Wireguard Access]]+
  
-===== A Note About DNS ===== +Non-whitelisted domains require an existing lab user to "vouch" for them by clicking a magic link in their e-mail.  Then a Lab Admin still has to approve.
-Due to complexities around adding nameservers to various Linux distro VPN clients, our OpenVPN server does not use the [[https://openvpn.net/index.php/open-source/documentation/howto.html#dhcp|dhcp-option DNS]] option.+
  
-Instead, we serve our private DNS records publicly.  Your machine should be able to resolve hostnames under the ''sepia.ceph.com'' subdomain automatically.+Once an account is approved, automation runs to add the user's public key to https://github.com/ceph/keys and their user entry to https://github.com/ceph/ceph-sepia-secrets.
  
-If you're using dnsmasq, you can add ''server=/sepia.ceph.com/172.21.0.1'' to ''/etc/dnsmasq.conf''.+The user will then be e-mailed their Wireguard IP and can log in. 
 + 
 +Admins can approve/deny/clean up at https://onboarding-admin.front.sepia.ceph.com/admin.
vpnaccess.1771856521.txt.gz · Last modified: by djgalloway