blob: e7f8c31442737ddeb57a0f6a2b575b790a40d2f3 [file] [log] [blame]
Moritz Mühlenhoff14759462020-04-07 12:02:30 +02001## Production & External Zones
Lucac528fcc2021-03-05 18:23:40 +01002Host bast1002.wikimedia.org bast2002.wikimedia.org bast3005.wikimedia.org bast4003.wikimedia.org bast5002.wikimedia.org restricted.bastion.wmcloud.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +02003 StrictHostKeyChecking yes
4 ProxyCommand none
5 ControlMaster auto
6 IdentitiesOnly yes
7
8# See https://wikitech.wikimedia.org/wiki/Managing_multiple_SSH_agents#Using_multiple_agents_via_systemd for setting up multiple agents using systemd
9Host *.wikimedia.org !gerrit.wikimedia.org !git-ssh.wikimedia.org
10 User USERNAME
11 StrictHostKeyChecking yes
12 IdentitiesOnly yes
13 IdentityAgent /run/user/1000/ssh-wmf-prod.socket
14 IdentityFile ~/.ssh/PRODUCTION_KEY
15 UserKnownHostsFile ~/.ssh/known_hosts.d/wmf-prod
16 ProxyCommand ssh -a -W %h:%p bast1002.wikimedia.org
17
18## Internal Zones
19Host *.mgmt.eqiad.wmnet *.mgmt.codfw.wmnet *.mgmt.ulsfo.wmnet *.mgmt.esams.wmnet *.mgmt.eqsin.wmnet
20 User root
21 StrictHostKeyChecking no
22
23# See https://wikitech.wikimedia.org/wiki/Managing_multiple_SSH_agents#Using_multiple_agents_via_systemd for setting up multiple agents using systemd
24Host *.wmnet
25 User USERNAME
26 StrictHostKeyChecking yes
27 IdentitiesOnly yes
28 IdentityAgent /run/user/1000/ssh-wmf-prod.socket
29 IdentityFile ~/.ssh/PRODUCTION_KEY
30 UserKnownHostsFile ~/.ssh/known_hosts.d/wmf-prod
31
32Host *.eqiad.wmnet
33 ProxyCommand ssh -a -W %h:%p bast1002.wikimedia.org
34
35Host *.codfw.wmnet
36 ProxyCommand ssh -a -W %h:%p bast2002.wikimedia.org
37
38Host *.esams.wmnet
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010039 ProxyCommand ssh -a -W %h:%p bast3005.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020040
41Host *.ulsfo.wmnet
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010042 ProxyCommand ssh -a -W %h:%p bast4003.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020043
44Host *.eqsin.wmnet
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010045 ProxyCommand ssh -a -W %h:%p bast5002.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020046
47## Networking Equipment
48Host *-eqiad.wikimedia.org *-eqord.wikimedia.org
49 ProxyCommand ssh -a -W %h:%p bast1002.wikimedia.org
50
51Host *-codfw.wikimedia.org *-eqdfw.wikimedia.org
52 ProxyCommand ssh -a -W %h:%p bast2002.wikimedia.org
53
54Host *-esams.wikimedia.org *-knams.wikimedia.org
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010055 ProxyCommand ssh -a -W %h:%p bast3005.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020056
57Host *-ulsfo.wikimedia.org
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010058 ProxyCommand ssh -a -W %h:%p bast4003.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020059
60Host *-eqsin.wikimedia.org
Moritz Mühlenhoffcc95e042021-01-15 14:16:50 +010061 ProxyCommand ssh -a -W %h:%p bast5003.wikimedia.org
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020062
63## Gerrit and Cloud VPS
64# See https://wikitech.wikimedia.org/wiki/Managing_multiple_SSH_agents#Using_multiple_agents_via_systemd for setting up multiple agents using systemd
65Host gerrit.wikimedia.org
66 User USERNAME
Stephen Shirley628ef5b2020-04-14 16:14:44 +020067 Port 29418
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020068 StrictHostKeyChecking yes
69 ProxyCommand none
70 IdentitiesOnly yes
71 IdentityAgent /run/user/1000/ssh-wmf-cloud.socket
72 IdentityFile ~/.ssh/WMCS_KEY
73 UserKnownHostsFile ~/.ssh/known_hosts.d/wmf-cloud
74
75# See https://wikitech.wikimedia.org/wiki/Managing_multiple_SSH_agents#Using_multiple_agents_via_systemd for setting up multiple agents using systemd
Lucac528fcc2021-03-05 18:23:40 +010076Host *.wmflabs.org *.wmflabs *.wmcloud.org *.wikimedia.cloud
Moritz Mühlenhoff14759462020-04-07 12:02:30 +020077 User USERNAME
78 IdentityFile ~/.ssh/WMCS_KEY
79 IdentityAgent /run/user/1000/ssh-wmf-cloud.socket
80 StrictHostKeyChecking no
81 UserKnownHostsFile ~/.ssh/known_hosts.d/wmf-cloud
Lucac528fcc2021-03-05 18:23:40 +010082 ProxyCommand ssh -a -W %h:%p restricted.bastion.wmcloud.org