Table of Contents

VPN Access

Requesting New Access

Visit https://onboarding.sepia.ceph.com/

Existing User Additional Credential

Use this form if you are registering an additional machine and need another Wireguard or SSH key.

See https://onboarding.sepia.ceph.com/wireguard/request

Existing User Replace Credential

Use this form if you are replacing a machine and no longer need your previous Wireguard key/SSH key.

https://onboarding.sepia.ceph.com/wireguard/replace

Existing User Remove SSH Key

https://onboarding.sepia.ceph.com/keys/request

Approvals

User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link. (Other domains can be added. For now, IBM and Red Hat seemed safest.)

Non-whitelisted domains require an existing lab user to “vouch” for them by clicking a magic link in their e-mail. Then a Lab Admin still has to approve.

Once an account is approved, automation runs to add the user's public key to https://github.com/ceph/keys and their user entry to https://github.com/ceph/ceph-sepia-secrets.

The user will then be e-mailed their Wireguard IP and can log in.

Admins can approve/deny/clean up at https://onboarding-admin.front.sepia.ceph.com/admin.