[go: up one dir, main page]

Page MenuHomePhabricator

MediaWiki deployment shell access request for SDunlap
Closed, ResolvedPublic

Description

Full Name: Stef Dunlap
User:Stef_Dunlap on wikitech and User:SDunlap-WMF on all other wikis
Libera: kindrobot
labs username: kindrobot
prod shell username: kindrobot (I'm not sure if this account exists yet. I am part of the WMF LDAP group.)
SSH Public public key for prod: https://wikitech.wikimedia.org/wiki/User:Stef_Dunlap

I am a member of QTE as a Staff Software Engineer in Test, currently embedded on the Abstract Wikipedia team. While I don't imminently have any code of my own to deploy to production, I would like to volunteer with the backport patching deployments and learn more about production topology.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: wikitech username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

Hello,

yes, confirmed your username "kindrobot" already is in LDAP and in the 'wmf' group.

It does not have shell access yet though. So the answer is yes and no.

This is an upgrade from "ldap_only"-admins to shell users.

Could you get approval from a manager on this ticket?

Meanwhile adding @thcipriani for approval for additions to the deployment group.

cc @Jrbranaa (manager)

Could I please get your approval?

@SDunlap Please also make yourself familiar with L3 and sign it here on Phabricator. Thank you

Meanwhile adding @thcipriani for approval for additions to the deployment group.

Approved!

herron triaged this task as Medium priority.Oct 21 2022, 3:06 PM
herron updated the task description. (Show Details)

Change 845591 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] admin: add kindrobot to deployers

https://gerrit.wikimedia.org/r/845591

Change 845591 merged by Herron:

[operations/puppet@production] admin: add kindrobot to deployers

https://gerrit.wikimedia.org/r/845591

herron claimed this task.
herron subscribed.

The requested access has been granted and will fully propagate within 30 minutes. I'll transition this to resolved now, please reopen if any followup is needed. Thanks!