User Tools

Site Tools


vpnaccess

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
vpnaccess [2026/08/17 21:14] – djgallowayvpnaccess [2026/09/16 18:42] (current) – djgalloway
Line 1: Line 1:
 ====== VPN Access ====== ====== VPN Access ======
-===== Requesting Access =====+===== Requesting New Access =====
  
 Visit https://onboarding.sepia.ceph.com/ Visit https://onboarding.sepia.ceph.com/
 +
 +===== Existing User Additional Credential =====
 +
 +Use this form if you are registering an additional machine and need another Wireguard or SSH key.
 +
 +See https://onboarding.sepia.ceph.com/wireguard/request
 +
 +===== Existing User Replace Credential =====
 +
 +Use this form if you are //replacing// a machine and no longer need your previous Wireguard key/SSH key.
 +
 +https://onboarding.sepia.ceph.com/wireguard/replace
 +
 +===== Existing User Remove SSH Key =====
 +
 +https://onboarding.sepia.ceph.com/keys/request
 +
 +===== Approvals =====
 +
 +User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link.  (Other domains can be added.  For now, IBM and Red Hat seemed safest.)
 +
 +Non-whitelisted domains require an existing lab user to "vouch" for them by clicking a magic link in their e-mail.  Then a Lab Admin still has to approve.
 +
 +Once an account is approved, automation runs to add the user's public key to https://github.com/ceph/keys and their user entry to https://github.com/ceph/ceph-sepia-secrets.
 +
 +The user will then be e-mailed their Wireguard IP and can log in.
 +
 +Admins can approve/deny/clean up at https://onboarding-admin.front.sepia.ceph.com/admin.
vpnaccess.1787001270.txt.gz · Last modified: by djgalloway