KB: TCM Computing Access

KB: TCM Computing Access

Purpose: This draft knowledge base article consolidates the most common TCM-related support questions seen in ITHD tickets over the last year so Rovo can suggest more accurate answers and agents can respond more consistently.

The most frequent themes in recent TCM tickets are: access to TCM systems, new starter and visitor onboarding, SSH and login problems, software availability and installation, and how to get support for TCM machines.

Scope: This article covers recurring user-facing questions about the TCM computing environment. It does not replace internal runbooks or restricted operational documentation.

Key facts at a glance

  • Access to TCM systems is not automatic; it must be requested for each user.

  • Most access requests need the user’s CRSid and a sponsoring PI or group lead.

  • New users commonly need access to one or more of the following: TCM Linux desktops, TCM gateway, SC compute machines, or specific restricted machine groups such as PC71–80.

  • Many connection problems are caused by one of four issues: account not yet enabled, wrong target host, SSH key or login setup incomplete, or machine-specific authentication/access restrictions.

  • SSH key access is possible but the users should be encouraged to password protect their keys.

  • Software requests for TCM systems are common and are typically handled through the IT Help Desk as standard service requests.

  • For help, users should raise a ticket through the IT Services portal or contact it.helpdesk@phy.cam.ac.uk.

Access and onboarding

Over the last year, the single most common TCM question has been some version of: “Can you add this person to the TCM computing system?” This applies to PhD students, MPhil students, summer students, visitors, new staff, and researchers joining the group.

Best practice for requests: include the user’s full name, CRSid, group or supervisor, and exactly what access is needed.

Typical access requests include:

  • General access to the TCM computing system

  • Access to TCM Linux desktops

  • Access to phy-tcm-gw.phy.cam.ac.uk

  • Access to sc1 or other SC compute machines

  • Access to restricted machine groups such as PC71–80

If someone is a new starter or visitor, access is set up after a valid University identity exists and a sponsoring academic or group lead has confirmed the request.

Having a CRSid does not by itself guarantee access to TCM systems.

For new user requests, the most useful wording is:

  • Who needs access

  • Their CRSid

  • Whether they need desktops, gateway, SC machines, or a restricted subgroup

  • Who is sponsoring or authorising the request

Login and SSH questions

The next most common category is login failure. These questions usually sound like:

  • I cannot log in to the new TCM machines

  • I can log in to the gateway but not to a desktop or SC machine

  • I get Permission denied (publickey,password)

  • SSH prompts appear, then the connection drops

  • I forgot the password for a TCM desktop

Important: TCM systems may use different access criteria and controls depending on the machine. A user being able to reach one TCM host does not prove they have permission on all TCM hosts.

Common causes and responses:

  • Account not yet enabled: the user exists in University systems but has not yet been added to TCM access groups.

  • Wrong authentication method: the user expects a password-only workflow when gateway-first approach is required.

  • Machine-specific restrictions: access to SC machines or reserved desktops may be limited to named users or research subgroups.

  • Forgotten local password on a workstation: TCM uses University accounts for access, there are no separate accounts or passwords.

  • Name resolution or internal SSH issues: sometimes host-to-host SSH or internal DNS resolution on TCM machines needs investigation by IT.

If you can’t log in to a TCM machine, the most common causes are that your TCM access has not yet been enabled for that specific system, or your SSH/login setup is incomplete. Please send us the hostname you are trying to reach, your CRSid, and the exact error message. If this is a new access request, include your supervisor or sponsoring PI and whether you need gateway, desktop, SC, or other restricted machine access.

Access to the TCM gateway does not automatically mean you have access to every TCM machine. Some systems, including SC machines or restricted desktop groups, may need separate permissions. Please tell us which host you are trying to access and the exact error shown, and we will check whether your account has been enabled for that system.

Software and application questions

Software-related requests are another recurring theme. Recent tickets include requests or issues involving TenPy, kcachegrind, and Mathematica, along with general questions about package availability on TCM Linux systems.

The support pattern is clear:

  • Users often assume a package is already installed because it appears in older documentation or was available on another machine.

  • Research packages can often be installed when there is a clear use case and no policy or licensing blocker.

Useful answer pattern: if a package is needed for research work, ask for the package name, preferred machine or group of machines, and whether a standard Ubuntu package, Conda package, or licensed application is required.

Examples of common software questions:

  • Is Mathematica preinstalled on TCM desktops?

  • Can you install kcachegrind?

  • Can you install TenPy on SC1?

  • Why is Mathematica asking for a licence?

Yes, in many cases we can install research software on TCM systems. Please send the package name, the machine or machine group you need it on, and any installation source or licensing details. If the software is already supposed to be available but is not working, include the command you ran and the exact error message.

Support route and article usage

Users also regularly ask where the documentation lives and who they should contact. The safest standard answer is:

  • Raise a request through the IT Services portal for new access, login issues, software installs, or machine problems

  • Or email it.helpdesk@phy.cam.ac.uk

  • Include the hostname, CRSid, exact error, and what you are trying to do

For agents and Rovo: when answering from this article, prefer concrete guidance over generic troubleshooting. Ask for the hostname, CRSid, sponsoring PI if relevant, and the exact error message.

Frequently asked questions

Raise a ticket with the user’s full name, CRSid, sponsoring PI or supervisor, and the systems they need access to. If relevant, specify whether they need access only to the gateway, to SC machines, or to restricted machine groups such as PC71–80.

A CRSid alone does not automatically create TCM access. Your account may still need to be enabled for the relevant TCM systems or groups. Send us the hostname you are trying to reach and the exact error so we can check.

Please include your CRSid, the hostname, how you are connecting, and the exact error message. If you are a new user, also tell us who is sponsoring your access and whether you have already been told your TCM account is active.

Often yes. Send the software name, target machine or machine group, and any relevant source or licensing details. For licensed software, approval and licence availability may be required.

Please use the IT Services portal or email it.helpdesk@phy.cam.ac.uk. Including the machine name and exact symptoms will help us respond faster.