Registration: Difference between revisions

From bwCloud-OS
Jump to navigation Jump to search
No edit summary
 
(47 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{InANutshell|<li>Access to bwCloud-OS requires an active account from a '''bwIDM'''-participating institution.</li>
<span id="In-a-Nutshell"></span>
<li>Your account must include a valid '''bwCloud entitlement''', assigned by your '''home institution'''. This is usually automatic. If missing, contact your institution’s IT support. The bwCloud-OS team cannot assign entitlements.</li>
{{InANutshell|
<li>Log in once to the [https://dashboard.bw-cloud.org Dashboard] to activate your profile. Setup is automated via bwIDM.</li>
<li>Access to bwCloud-OS requires an active account from a '''bwIDM'''-participating institution.</li>
<li>After login, select your '''home region''' as described [[Registration#What_is_a_"home_region"?|here]] to begin using bwCloud-OS.</li>}}
<li>Your account must include a valid '''entitlement''', assigned by your '''home institution'''. This is usually automatic. If it is missing (see [[Registration#How_can_I_find_out_which_entitlements_my_account_contains?|here]]), contact your institution’s IT support. The bwCloud-OS team cannot assign entitlements.</li>
<li>Log in once to the [https://portal.bw-cloud.org/ '''Dashboard'''] to activate your profile. Setup is automated via bwIDM.</li>
<li>After login, select your '''region''' as described [[Registration#Region-Selection|here]] to begin using bwCloud-OS.</li>}}




__TOC__
__TOC__
= Entitlements =
= Entitlements =
This page explains the '''bwIDM entitlements''' required to use bwCloud-OS and their impact on access, resources, and operating rules.
''Entitlements are currently under revision and might change soon.''


== What Are bwIDM and Entitlements? ==
== What are "bwIDM" and "entitlements"? ==
<span id="Entitlements"></span>


Every member of a higher education institution in Baden-Württemberg  (university, college, PH, HAW, etc.)has a personal account for accessing the IT services provided by their institution. If the institution participates in the federated identity management system  [https://www.bwidm.de/ '''bwIDM'''], its members can also apply for additional IT services offered by other participating institutions.
Every member of a higher education institution in Baden-Württemberg  (university, college, PH, HAW, etc.) has a personal account for accessing the IT services provided by their institution. If the institution participates in the federated identity management system  [https://www.bwidm.de/ '''bwIDM'''], its members can also apply for additional IT services offered by other participating institutions.


To allow external IT services to identify users, certain personal data is transmitted during registration and/or use of the service. Federated identity management ensures, through a model of mutual trust, that the external service can verify the user’s affiliation with their institution — confirming that the account is valid and the user is officially recognized. Within the bwIDM Federation, participating institutions have agreed on a minimum set of personal data that is transmitted to external IT services. This includes standard attributes such as <code>eduPersonPrincipalName</code>, <code>mail</code>, and <code>givenName</code>.
To allow external IT services to identify users, certain personal data is transmitted during registration and/or use of the service. Federated identity management ensures, through a model of mutual trust, that the external service can verify the user’s affiliation with their institution — confirming that the account is valid and the user is officially recognized. Within the bwIDM Federation, participating institutions have agreed on a minimum set of personal data that is transmitted to external IT services. This includes standard attributes such as <code>eduPersonPrincipalName</code>, <code>mail</code>, and <code>givenName</code>.
Line 19: Line 20:


== Which entitlements are required to use bwCloud-OS? ==
== Which entitlements are required to use bwCloud-OS? ==
To access and use bwCloud-OS, you need a valid ''bwCloud entitlement''. A detailed overview of the current entitlement regulations can be found [[Entitlements|here]].
<span id="Entitlements-bwCloud-OS"></span>
 
To access and use bwCloud-OS, you need a valid bwCloud(-OS) entitlement. A detailed overview of current regulations can be found on the page [[Entitlements in bwCloud-OS]].
 
'''📌 Note:''' The bwCloud(-OS) entitlement model is currently being restructured and subject to change.


'''Note:''' The specific bwCloud-OS entitlements are currently under review and may be subject to change.
== How can I find out which entitlements my account contains?==
== How can I find out which entitlements my account contains?==
To find out which Entitlements are linked to an account, you can for example log into the "[https://login.bwidm.de/welcome/index.xhtml RegApp]".
<span id="My-Entitlements"></span>
When logging into a RegApp, an overview of the data to be transmitted is displayed. This overview also includes the supplied Entitlements (see screenshot).
 
To view information about bwIDM services linked to your account, log in to the "[https://login.bwidm.de/welcome/index.xhtml RegApp]".
 
For detailed information on the entitlements associated with your account (including those for services not yet registered), navigate to:
 
'''Index → Personal Data → Shibboleth'''


<div style="text-align:center;">
In the '''Value''' column, you should see entries such as <code>bwCloud-Basic</code> or <code>bwCloud-Extended</code>. If such an entry containing <code>bwCloud</code> exists, you are entitled to register for and use bwCloud-OS. Which specific entitlement you have is determined by your home institution and cannot be changed by you or the bwCloud-OS team.
[[File:Screenshot login bwSupportPortal.png|450x450px|border]]
</div>


<br>
== What should I do if my account has no bwCloud-OS entitlement assigned? ==
<span id="No-Entitlements"></span>


== What do I do if my account has no bwCloud entitlement assigned to it? ==
The assignment of entitlements is exclusively managed by your home institution. The bwCloud-OS team does '''not''' have the authority to add or remove entitlements on user accounts.
The assignment of the entitlement is the sole responsibility of the respective home institiution. The bwCloud-OS team ''cannot add or remove entitlements'' to user accounts! In this case, please contact the central IT service department (computer center, IT service center, service center, ...) and request the assignment of the desired entitlement.


If your account lacks the necessary entitlement, please contact your institution’s central IT service department or service desk.


= Regions =  
= Regions =  


== What does "region" mean in bwCloud-OS? ==
<span id="Regions"></span>
In bwCloud-OS, a '''region''' refers to one of the four operating sites: '''Freiburg''', '''Karlsruhe''', '''Mannheim''', and '''Ulm'''. Each region runs its own infrastructure but is accessible through a shared interface ([https://portal.bw-cloud.org/ Dashboard]).


== What does "region" mean in bwCloud-OS? ==
Resources such as virtual machines (VMs, instances), networks, and storage are bound to the region in which they are created. For example, an instance launched in the Mannheim region will receive an IP address from Mannheim’s specific IP range(s) — this address cannot be transferred to another region.
bwCloud-OS currently consists of '''four different operating sites = regions''', which can be selected and administered via a common interface ([https://portal.bw-cloud.org/auth/login/?next=/ dashboard]). Each of the four operating sites acts as an independent region. This means: running instances in the Mannheim region receive an IP address according to the configuration of the Mannheim region. The IP address is specific to Mannheim and cannot move to another region. The region selection can be changed as described [[Registration#Where_do_I_select_the_region_in_the_dashboard?|here]].
 
You can switch between regions in the Dashboard interface as described [[Registration#Region-Selection|here]].
 
== What is my "home region"? ==
<span id="Home-Region"></span>


== What is a "home region"? ==
In bwCloud-OS, each user is initially assigned a '''home region''' during account setup. For users from one of the four operating sites (Freiburg, Karlsruhe, Mannheim, Ulm), this assignment is straightforward. For users from other institutions, the assignment is based on the network topology of [https://www.belwue.de/ BelWue] — aiming to route each user to the nearest operating site for optimal connectivity. However, you can [[Projects and Quota#Group-Project-Application|apply for a project]] with resources (also) in other regions.
Each user in the bwCloud-OS is initially assigned a home region during the setup. For users from the four operating locations this assignment is of course trivial. For users from other locations we have oriented ourselves to the network topology of the BelWü. The goal of the current assignment is the shortest possible connection of the respective location to one of our operating sites.


For users, the assignment is usually not relevant. A table with the assignment can be found [[Region|here]].
A table showing the current home region assignments can be found [[Regions|here]].  


== Where do I select the region in the dashboard? ==
== Where do I select the region in the Dashboard? ==
In the left half of the top navigation bar in the dashboard you can click on a drop-down menu to display the regions. The currently selected region is marked with a tick. A click on the respective region switches there.
<span id="Region-Selection"></span>


[[File:Select region dashboard.png|border|center|thumb|722x722px]]
You can select a region from the drop-down menu located on the left side of the top navigation bar in the [https://portal.bw-cloud.org/ Dashboard]. The currently active region is marked with a checkmark. Simply click on a different region in the list to switch to it.
[[File:Region selection.png|center|thumb|722x722px]]

Latest revision as of 18:07, 10 November 2025

In a Nutshell
  • Access to bwCloud-OS requires an active account from a bwIDM-participating institution.
  • Your account must include a valid entitlement, assigned by your home institution. This is usually automatic. If it is missing (see here), contact your institution’s IT support. The bwCloud-OS team cannot assign entitlements.
  • Log in once to the Dashboard to activate your profile. Setup is automated via bwIDM.
  • After login, select your region as described here to begin using bwCloud-OS.


Entitlements

What are "bwIDM" and "entitlements"?

Every member of a higher education institution in Baden-Württemberg (university, college, PH, HAW, etc.) has a personal account for accessing the IT services provided by their institution. If the institution participates in the federated identity management system bwIDM, its members can also apply for additional IT services offered by other participating institutions.

To allow external IT services to identify users, certain personal data is transmitted during registration and/or use of the service. Federated identity management ensures, through a model of mutual trust, that the external service can verify the user’s affiliation with their institution — confirming that the account is valid and the user is officially recognized. Within the bwIDM Federation, participating institutions have agreed on a minimum set of personal data that is transmitted to external IT services. This includes standard attributes such as eduPersonPrincipalName, mail, and givenName.

Some services, however, require additional information — for example, whether a user’s home institution is authorized to access a particular external service. This is handled through the assignment of special attributes, such as eduPersonEntitlement, to the user's account.

Which entitlements are required to use bwCloud-OS?

To access and use bwCloud-OS, you need a valid bwCloud(-OS) entitlement. A detailed overview of current regulations can be found on the page Entitlements in bwCloud-OS.

📌 Note: The bwCloud(-OS) entitlement model is currently being restructured and subject to change.

How can I find out which entitlements my account contains?

To view information about bwIDM services linked to your account, log in to the "RegApp".

For detailed information on the entitlements associated with your account (including those for services not yet registered), navigate to:

Index → Personal Data → Shibboleth

In the Value column, you should see entries such as bwCloud-Basic or bwCloud-Extended. If such an entry containing bwCloud exists, you are entitled to register for and use bwCloud-OS. Which specific entitlement you have is determined by your home institution and cannot be changed by you or the bwCloud-OS team.

What should I do if my account has no bwCloud-OS entitlement assigned?

The assignment of entitlements is exclusively managed by your home institution. The bwCloud-OS team does not have the authority to add or remove entitlements on user accounts.

If your account lacks the necessary entitlement, please contact your institution’s central IT service department or service desk.

Regions

What does "region" mean in bwCloud-OS?

In bwCloud-OS, a region refers to one of the four operating sites: Freiburg, Karlsruhe, Mannheim, and Ulm. Each region runs its own infrastructure but is accessible through a shared interface (Dashboard).

Resources such as virtual machines (VMs, instances), networks, and storage are bound to the region in which they are created. For example, an instance launched in the Mannheim region will receive an IP address from Mannheim’s specific IP range(s) — this address cannot be transferred to another region.

You can switch between regions in the Dashboard interface as described here.

What is my "home region"?

In bwCloud-OS, each user is initially assigned a home region during account setup. For users from one of the four operating sites (Freiburg, Karlsruhe, Mannheim, Ulm), this assignment is straightforward. For users from other institutions, the assignment is based on the network topology of BelWue — aiming to route each user to the nearest operating site for optimal connectivity. However, you can apply for a project with resources (also) in other regions.

A table showing the current home region assignments can be found here.

Where do I select the region in the Dashboard?

You can select a region from the drop-down menu located on the left side of the top navigation bar in the Dashboard. The currently active region is marked with a checkmark. Simply click on a different region in the list to switch to it.