KB: TCM Computing Access
Purpose: This draft knowledge base article consolidates the most common TCM-related support questions seen in ITHD tickets over the last year so Rovo can suggest more accurate answers and agents can respond more consistently.
The most frequent themes in recent TCM tickets are: access to TCM systems, new starter and visitor onboarding, SSH and login problems, software availability and installation, and how to get support for TCM machines.
Scope: This article covers recurring user-facing questions about the TCM computing environment. It does not replace internal runbooks or restricted operational documentation.
Key facts at a glance
Access to TCM systems is not automatic; it must be requested for each user.
Most access requests need the user’s CRSid and a sponsoring PI or group lead.
New users commonly need access to one or more of the following: TCM Linux desktops, TCM gateway, SC compute machines, or specific restricted machine groups such as PC71–80.
Many connection problems are caused by one of four issues: account not yet enabled, wrong target host, SSH key or login setup incomplete, or machine-specific authentication/access restrictions.
SSH key access is possible but the users should be encouraged to password protect their keys.
Software requests for TCM systems are common and are typically handled through the IT Help Desk as standard service requests.
For help, users should raise a ticket through the IT Services portal or contact it.helpdesk@phy.cam.ac.uk.
Access and onboarding
Over the last year, the single most common TCM question has been some version of: “Can you add this person to the TCM computing system?” This applies to PhD students, MPhil students, summer students, visitors, new staff, and researchers joining the group.
Best practice for requests: include the user’s full name, CRSid, group or supervisor, and exactly what access is needed.
Typical access requests include:
General access to the TCM computing system
Access to TCM Linux desktops
Access to
phy-tcm-gw.phy.cam.ac.ukAccess to
sc1or other SC compute machinesAccess to restricted machine groups such as
PC71–80
If someone is a new starter or visitor, access is set up after a valid University identity exists and a sponsoring academic or group lead has confirmed the request.
Having a CRSid does not by itself guarantee access to TCM systems.
For new user requests, the most useful wording is:
Who needs access
Their CRSid
Whether they need desktops, gateway, SC machines, or a restricted subgroup
Who is sponsoring or authorising the request
Login and SSH questions
The next most common category is login failure. These questions usually sound like:
I cannot log in to the new TCM machines
I can log in to the gateway but not to a desktop or SC machine
I get
Permission denied (publickey,password)SSH prompts appear, then the connection drops
I forgot the password for a TCM desktop
Important: TCM systems may use different access criteria and controls depending on the machine. A user being able to reach one TCM host does not prove they have permission on all TCM hosts.
Common causes and responses:
Account not yet enabled: the user exists in University systems but has not yet been added to TCM access groups.
Wrong authentication method: the user expects a password-only workflow when gateway-first approach is required.
Machine-specific restrictions: access to SC machines or reserved desktops may be limited to named users or research subgroups.
Forgotten local password on a workstation: TCM uses University accounts for access, there are no separate accounts or passwords.
Name resolution or internal SSH issues: sometimes host-to-host SSH or internal DNS resolution on TCM machines needs investigation by IT.
Software and application questions
Software-related requests are another recurring theme. Recent tickets include requests or issues involving TenPy, kcachegrind, and Mathematica, along with general questions about package availability on TCM Linux systems.
The support pattern is clear:
Users often assume a package is already installed because it appears in older documentation or was available on another machine.
Research packages can often be installed when there is a clear use case and no policy or licensing blocker.
Useful answer pattern: if a package is needed for research work, ask for the package name, preferred machine or group of machines, and whether a standard Ubuntu package, Conda package, or licensed application is required.
Examples of common software questions:
Is Mathematica preinstalled on TCM desktops?
Can you install
kcachegrind?Can you install
TenPyon SC1?Why is Mathematica asking for a licence?
Support route and article usage
Users also regularly ask where the documentation lives and who they should contact. The safest standard answer is:
Raise a request through the IT Services portal for new access, login issues, software installs, or machine problems
Or email it.helpdesk@phy.cam.ac.uk
Include the hostname, CRSid, exact error, and what you are trying to do
For agents and Rovo: when answering from this article, prefer concrete guidance over generic troubleshooting. Ask for the hostname, CRSid, sponsoring PI if relevant, and the exact error message.