Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Excerpt
hiddentrue

Logging into the HPC supercomputers starts with your UArizona NetID and password with two-factor authentication enabled. Logging in will first connect you to something called the bastion host, a computer that provides a gateway to our three clusters: Ocelote, ElGato, and Puma. This is the only function the bastion host serves. It is not for storing files, running programs, or accessing software. 


Insert excerpt
Getting Help
Getting Help
nopaneltrue


Panel
borderColor#07105b
bgColor#fafafe

Overview

Logging into the HPC supercomputers starts with your UArizona NetID and password with two-factor authentication enabled. Logging in will first connect you to something called the bastion host, a computer that provides a gateway to our three clusters: Ocelote, ElGato, and Puma. This is the only function the bastion host serves. It is not for storing files, running programs, or accessing software. 

A comprehensive walkthrough of this process is in our Puma Quick Start page. This page is intended to provide you with instructions on getting terminal access to the system from your specific OS, how to log into the system from our web interface (Open OnDemand), how to set up X11 (image) forwarding, and how to configure your account to allow for a password-less login (see: 75991258).

If you experience any problems, refer to our FAQ page which provides some solutions to common problems.



Panel
borderColor#9c9fb5
bgColor#fcfcfc
titleColor#fcfcfc
titleBGColor#021D61
borderStylesolid
titleContents

Table of Contents
maxLevel1




Panel
borderColor#07105b
bgColor#fafafe

Web Access

The web interface, Open OnDemand, provides access to HPC's three clusters. More comprehensive information on this service can be found on our Open On Demand page.

Deck
startHiddenfalse
idWeb Access


Card
title-oldTerminal access through Open OnDemand
idterminal-access
labelTerminal Access
titleTerminal Access

Terminal Access

Users can gain command line access to HPC through our OOD web interface as an alternative to using a local SSH Client. To use this interface:

  1. Log into https://ood.hpc.arizona.edu/
  2. Go to the dropdown menu at the top of the screen and select Clusters
  3. Click Shell
  4. This will put you on the command line on one of the login nodes where you may perform regular housekeeping work, submit jobs, or request an interactive session.. By default, you will automatically be connected to Puma. To navigate to a different cluster, use the displayed shortcuts. 


Card
title-oldWork on HPC using a virtual desktop
idvirtual-desktop
labelVirtual Desktop
titleVirtual Desktop

Virtual Desktop

Users may also interact with a cluster using a virtual desktop interface. To do this:

  1. Log into https://ood.hpc.arizona.edu/ and, under My Interactive Sessions, select Interactive Desktop under Desktops on the left-hand side of the page.

  2. A form will appear where you will select the target cluster, enter the amount of time you'd like to be allotted (in hours), the number of cores you need, your PI Group (if you are unsure what your group name is, you can check in https://portal.hpc.arizona.edu/portal/), and the queue. Once you've filled in your request, click Launch.
  3. A window will appear with the status of your request. It will start in a Pending state and will switch to Running when your desktop session is ready. Click Launch Interactive Desktop to access your session.
  4. That's it! You can now use the cluster with a Desktop interface







Panel
borderColor#07105b
bgColor#fafafe

Command Line/Terminal Access

Deck
startHiddenfalse
idTerminal Access


Tip
  • All the integration on UArizona HPC supercomputers is done with the  "bash” shell which means to get consistent results, bash must be your shell.  New HPC users automatically are set to the bash shell unless they already are using a different shell.
  • When using SSH, if you leave out the netid@ then it may default to your workstation username, which may not be valid; on Linux and MacOS you can override this via a ~/.ssh/config "User netid" config line. On Windows, there may be an application-specific way to set the username for hpc.arizona.edu connections.

  • If you try to log in and get a continuous prompt of "password" and nothing else, you are probably not registered for NetID+


To log into HPC, you will need NetID+ enabled, an HPC account, and internet access. Because we require Duo-authentication to access the system, no VPN is required. 

Logging in will first connect you to something called the bastion host, a computer that provides a gateway to our three clusters: Ocelote, ElGato, and Puma. This is the only function the bastion host serves. It is not for storing files, running programs, or accessing software.

Card
labelMac Access
titleMac Access

Mac Access

Mac systems provide a built-in SSH client, so there is no need to install any additional software. You will find the terminal application under Applications → Utilities → Terminal.

Open the terminal and enter:

Code Block
languagebash
themeMidnight
$ ssh netid@hpc.arizona.edu

where netid is your UArizona NetID. When you press enter, you will be prompted for your university password. Note: you will not see any characters appear on the screen while typing during this step. This is normal and everything is working as it should. After successfully entering your password, you will be prompted to Duo Authenticate. If everything is successful, you will be connected to the bastion host.


Card
labelWindows Access
titleWindows Access

Windows Access

Windows systems do not have any built-in support for using SSH, so you will have to download a software package to do so. There are several available for Windows workstations.  Free SSH clients are available for download from the University of Arizona's Site License website.  

PuTTY

PuTTY is the most popular open source SSH Windows client. To use it: download, install, and open the Putty client. Next, open a connection and enter hpc.arizona.edu under Host Name and press Open

This will open a terminal. At the prompt, enter the following, replacing <netid> with your own NetID:

Code Block
languagebash
themeMidnight
Login as: <netid>

You will then be prompted to Duo-Authenticate. If the process is successful, you will be connected to the bastion host.

MobaXterm

MobaXterm is another available SSH Windows client. To connect to HPC, download and install MobaXterm, open the software, select Session → SSH and enter hpc.arizona.edu under Remote host. Next, select the box next to Specify username and enter your UArizona NetID. To connect, click OK at the bottom of the screen:

This will open a terminal and will prompt you for your UArizona password. You will then need to Duo-authenticate. If everything is successful, you will be connected to the bastion host.



Card
labelLinux Access
titleLinux Access

Linux

Linux systems provide a built-in SSH client, so there is no need to install additional software. Simply locate and run the Terminal app.

Open the terminal and enter:


Code Block
languagebash
themeMidnight
$ ssh netid@hpc.arizona.edu

where netid is your UArizona NetID. When you press enter, you will be prompted for your university password. Note: you will not see any characters appear on the screen while typing during this step. This is normal and everything is working as it should. After successfully entering your password, you will be prompted to Duo Authenticate. If everything is successful, you will be connected to the bastion host.

Once you reach the bastion host, regardless of method, you should see the following:

Code Block
languagebash
themeMidnight
Success. Logging you in...
Last login:
This is a bastion host used to access the rest of the RT/HPC environment.
  
Type "shell" to access the job submission hosts for all environments
-----------------------------------------

From there, type shell to connect to the login nodes that will provide access to our three clusters. On the login nodes, you should see:

Code Block
languagebash
themeMidnight
***
The default cluster for job submission is Puma
***
Shortcut commands change the target cluster
-----------------------------------------
Puma:
$ puma
(puma) $
Ocelote:
$ ocelote
(ocelote) $
ElGato:
$ elgato
(elgato) $
-----------------------------------------

By default, you will be connected to Puma when you first log in. To access the other clusters, follow the shortcut commands. 





Panel
borderColor#07105b
bgColor#fafafe

X11 Forwarding

Deck
startHiddenfalse
idX11 Forwarding

X11 forwarding is a mechanism that allows a user to start up a remote application (e.g. VisIt or Matlab) and forward the application display to their local machine. The key to make forwarding work successfully is to include the -X flag at each login step. To check whether X11 forwarding is active, you may run the command:

Code Block
languagebash
themeMidnight
$ echo $DISPLAY

If it comes back blank, something has gone wrong.

Card
defaulttrue
title-oldConfigure X11 Forwarding on Mac/Linux
idx11-mac-linux
labelX11 Forwarding on Mac/Linux
titleX11 Forwarding on Mac/Linux

X11 Forwarding on Mac and Linux

Tip
  • On a Mac, if you get a blank response to "echo $DISPLAY, you might need this line in your .ssh/config file: ForwardX11Trusted yes
  • Mac users will want to install the additional software package XQuartz onto their machines to use X11 forwarding with HPC. 
  • Be aware forwarding X traffic does not work with the DEPRECATED menu interface enabled.  You should disable the menu option and use the hostname shortcuts instead.

Start a terminal session and connect as you typically would with an additional flag -X in your ssh command (shown in the example below). Once you're connected to the bastion host, enter the name of the cluster you want to access, including the additional -X flag again. An example of this process is provided below:

Code Block
languagebash
themeMidnight
$ ssh -X netid@hpc.arizona.edu
Password:
Duo two-factor login for netid
Enter a passcode or select one of the following options:

 1. Duo Push to XXX-XXX-8969
 2. Phone call to XXX-XXX-8969
 3. Phone call to XXX-XXX-0502
 4. SMS passcodes to XXX-XXX-8969

Passcode or option (1-4): 1
Success. Logging you in...
Last login:
This is a bastion host used to access the rest of the RT/HPC environment.
 
Type "shell" to access the job submission hosts for all environments
-----------------------------------------            
[netid@gatekeeper ~]$ echo $DISPLAY
localhost:13.0

[netid@gatekeeper ~]$ shell -X
***
The default cluster for job submission is Puma
***
Shortcut commands change the target cluster
-----------------------------------------
Ocelote:
$ ocelote
(ocelote) $
Puma:
$ puma
(puma) $

(puma)[netid@junonia ~]$ echo $DISPLAY
localhost:18.0



Card
title-oldConfigure X11 Forwarding on Windows
idwindows-x11
labelX11 Forwarding on Windows
titleX11 Forwarding on Windows

X11 Forwarding on Windows

To use X11 forwarding on a Windows system, you will need to download an X11 display server such as Xming. 

PuTTY

To enable X11 forwarding in PuTTY, go to SSH → X11 and select the box next to Enable X11 forwarding.

Once you've connected to the bastion host, connect to the login nodes with the an additional flag -X:

Code Block
languagebash
themeMidnight
$ shell -X

MobaXterm

To enable X11 forwarding in MobaXterm, open a new session, select SSH, and open Advanced SSH settings. Select the option below called X11-Forwarding.

Once you've connected to the bastion host, connect to the login nodes with the an additional flag -X:

Code Block
languagebash
themeMidnight
$ shell -X









Panel
borderColor#07105b
bgColor#fafafe

SSH Keys

Why Use SSH Keys?

The Bastion Host uses two-factor authentication and will, by default, prompt you for a password and 2nd factor when you attempt to log in. As an alternative, you can use PKI (Public Key Authentication). This means you will not have to provide a password or Duo-authenticate for any future sessions. To do this, you will need to create an SSH Key on your local workstation and copy the public key to the ~/.ssh/authorized_keys file in your HPC account on the bastion host.


Deck
startHiddenfalse
idSSH Keys


Card
title-oldGenerating SSH keys with Mac or Linux
idmac-and-linux
labelMac and Linux
titleMac and Linux

SSH keys on Mac or Linux

In a Terminal session on your local workstation:

  1. Create a public-key pair: 

    Code Block
    languagebash
    themeMidnight
    $ ssh-keygen -t rsa

    You will be prompted to enter a passphrase. This is optional, but we strongly recommend that you do so.

  2. After running that command, you will have two new files on your local computer: ~/.ssh/id_rsa and ~/.ssh/id_rsa.pub
    • id_rsa is your private key file. Do not share this with anybody! It is analagous to your password; anybody who has this file can impersonate you.
    • id_rsa.pub is your public key file. You will upload this onto any servers that you wish to automatically login to.

  3. Copy the public key to the Bastion Host (you will need to enter your password this one time): 

    Code Block
    languagebash
    themeMidnight
    $ ssh-copy-id netid@hpc.arizona.edu
    


  4. If your computer does not support the ssh-copy-id command, run the following commands:

    Code Block
    languagebash
    themeMidnight
    $ scp ~/.ssh/id_rsa.pub netid@hpc.arizona.edu:
    $ ssh netid@hpc.arizona.edu # (you will need to use your password this time)
    $ mkdir -p ~/.ssh && cat ~/id_rsa.pub >> .ssh/authorized_keys && rm ~/id_rsa.pub # On the server, copies the key into the appropriate file


Now, logout and attempt to login to the server again. You should not be prompted for a password!



Card
title-oldGenerate SSH Keys with Windows
idwindows-keys
labelWindows
titleWindows

SSH Keys on Windows

To setup SSH keys on Windows with the PuTTy client, refer to the official PuTTy documentation.

Using SSH Keys for file transfers

Note that SSH Keys can also be used to avoid entering a password and 2nd factor when transferring files to to the cluster via the file transfer node (filexfer.hpc.arizona.edu) using command line programs like scp or sftp.  Follow the steps above (2-4 under the Mac and Linux instructions), except use filexfer.hpc.arizona.edu instead of hpc.arizona.edu.  Note that you only need to generate the keys in Step 1 once.  The same ~/.ssh/id_rsa.pub file may be used to identify yourself to multiple hosts.