{"id":11,"date":"2014-01-15T15:59:39","date_gmt":"2014-01-15T15:59:39","guid":{"rendered":"http:\/\/ri.itservices.manchester.ac.uk\/rvms\/?page_id=11"},"modified":"2025-01-10T14:28:05","modified_gmt":"2025-01-10T14:28:05","slug":"getting-started","status":"publish","type":"page","link":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/getting-started\/","title":{"rendered":"Getting Started"},"content":{"rendered":"<h2>Requesting Your Virtual Machine (VM)<\/h2>\n<p>To request a VM, please <a href=\"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/apply\/\"> complete the Research Virtual Machine Request Form<\/a>.<\/p>\n<h2>Assessment\/Limited Resources<\/h2>\n<ul class=\"gaplist\">\n<li>Contributing research groups will be allocated VMs equivalent to contributed funds.<\/li>\n<li>Free-at-the-point-of-use resources for this service are <strong><em>very<\/em><\/strong> limited: for those groups which have not contributed, there may be sufficient capacity to offer a low-specification VM at no charge. The amount of resource available is dependent on the allocations made to contributing groups and the resources requested (including length of time for which you wish to run the VM).<\/li>\n<li>An assessment will be made of each request for a VM to ensure that there is not an existing service (e.g, Web farm) which can fulfil the requirements.<\/li>\n<\/ul>\n<h2>Available Operating Systems. Installing your VM.<\/h2>\n<ul class=\"gaplist\">\n<li>Our preferred standard image as of November 2022, is Ubuntu 20.04.<\/li>\n<li>Otherwise, a member of IT Staff <em>may<\/em> be able to install another Linux distribution\/image for you &#8211; please ask for details.<\/li>\n<li>A MS Windows installation may be available &#8211; please ask for details.<\/li>\n<li>For licensing reasons, OS-X is not available.<\/li>\n<\/ul>\n<h2>Who administers the VM? Can I have root\/admin access?<\/h2>\n<p>See <a href=\"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/responsibilities\/\">Responsibilities of the VM Owner and VM Administrator<\/a>.<\/p>\n<h2>How do I access my VM once it is installed?<\/h2>\n<p>Access to the VM is <em>via<\/em> SSH (Linux) or RDP (MS Windows). Account details will be supplied.<\/p>\n<h2>VM Firewall<\/h2>\n<p>As supplied, the VM image will have a strong firewall implemented. SSH access will be possible only from a small number of agreed IP addresses, which should be those used by the nominated system administrator(s). The system administrator can customise the firewall to allow access on ports required for the intended service, e.g., port 80 for HTTP.<\/p>\n<p><em>It is very strongly recommended that a strong firewall is maintained.<\/em><\/p>\n<h2>Logging in for the First Time<\/h2>\n<p>If your VM is installed by us with the standard image, it will not be possible to login directly as <tt>root<\/tt>; you must login by using your IT Services username and password.<\/p>\n<p>As indicated in the previous section, you will be able to login only from the IP address(es) agreed.<\/p>\n<h2>Securing your VM<\/h2>\n<p>The nominated VM Administrator is required to ensure that your VM is patched in a timely manner and is secured, by means of a firewall and any other appropriate measures. It is strongly recommended that you restrict <em>who<\/em> can login to your VM by using the <code>AllowUsers<\/code> field in your SSH daemon configuration. For example, setting<\/p>\n<pre>AllowUsers mabcpqr2 mxyzmno2 \r\n<\/pre>\n<p>in <code>\/etc\/ssh\/sshd_config<\/code> <em>and restarting the SSH daemon<\/em> will restrict access to the two usernames. There may be additional usernames already in the list so that members of Research IT can access the VM. The above example relies on the VM&#8217;s firewall controlling <em>where<\/em> access is permitted from &#8211; the <code>AllocUsers<\/code> controls <em>who<\/em> can log in.<\/p>\n<p>If your firewall is not very restrictive (not recommended) then you can restricted where users can log in from via the <code>AllowUsers<\/code> line. For example:<\/p>\n<pre>AllowUsers mabcpqr2@130.88.0.0\/16 mabcpqr2@10.99.0.0\/16 mxyzmno2@130.88.0.0\/16 mxyzmno2@10.99.0.0\/16\r\n<\/pre>\n<p>in <code>\/etc\/ssh\/sshd_config<\/code> <em>and restarting the SSH daemon<\/em> will allow only those two users to login via SSH, and only from on campus. But it is better to restrict <em>where<\/em> logins are permitted from using the firewall and use only usernames in the <code>AllowUsers<\/code> line.<\/p>\n<h2>Research IT VM access<\/h2>\n<p>Research IT have an account on your VM which we can use to access the VM if required and you should not remove this account. If we are unable to access the VM due to our account being removed, we reserve the right to terminate your VM. We may use this account for essential platform maintenance, for example updating vulnerability scanning tools. Note that your nominated VM administrator remains responsible for security and maintenance.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Requesting Your Virtual Machine (VM) To request a VM, please complete the Research Virtual Machine Request Form. Assessment\/Limited Resources Contributing research groups will be allocated VMs equivalent to contributed funds. Free-at-the-point-of-use resources for this service are very limited: for those groups which have not contributed, there may be sufficient capacity to offer a low-specification VM at no charge. The amount of resource available is dependent on the allocations made to contributing groups and the resources.. <a href=\"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/getting-started\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/pages\/11","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/comments?post=11"}],"version-history":[{"count":21,"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/pages\/11\/revisions"}],"predecessor-version":[{"id":2366,"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/pages\/11\/revisions\/2366"}],"wp:attachment":[{"href":"https:\/\/ri.itservices.manchester.ac.uk\/rvms\/wp-json\/wp\/v2\/media?parent=11"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}