Page MenuHomePhabricator

Grant access to nda LDAP group to xqt
Closed, ResolvedPublic

Description

  • The username of your existing account on wikitech.wikimedia.org: Xqt
  • Do you currently have shell access (Yes/No)? No
  • Purpose (Specify which service you need to get access to, e.g. Icinga, Grafana, Superset etc): Turnilo; see below (and T312794) for more information.
  • The specific LDAP group that you want to be added to (optional): nda

For contractors only:

  • Contract end date: Not applicable
  • Contract contact person: Not applicable
Original description

I am herewith requesting NDA permission due to proposals by @Urbanecm_WMF and @Legoktm with T312794 to access *Turnillo* to extract Python version usage statistics by my own as requested previously by the task given above.

Event Timeline

Restricted Application edited subscribers, added: Aklapper; removed: Urbanecm. · View Herald TranscriptOct 10 2023, 11:02 AM
Xqt renamed this task from Volunteer NDA request for xqt to Volunteer NDA permission for xqt.Oct 10 2023, 11:03 AM
Xqt added a subscriber: Urbanecm.

👍 from me. Xqt is a key maintainer of Pywikibot. I've processed Turnillo data for @Xqt a couple of times for deprecation and user behavior decisions and I believe having NDA access would help them with Pywikibot maintenance.

Anything left to do on my side?

I confirm that Xqt is listed on https://phabricator.wikimedia.org/legalpad/signatures/2/ and thus has signed L2.

https://wikitech.wikimedia.org/wiki/Volunteer_NDA#Get_support lists as the next step "Get sign off by a C-level staff of the Wikimedia Foundation. WMF employees will arrange this as a last sign-off (e.g. with the WMF CTO) when all other criteria have been met." before adding you to WMF-NDA's https://phabricator.wikimedia.org/project/members/61/ . @Urbanecm_WMF: Would you have someone in mind?

I confirm that Xqt is listed on https://phabricator.wikimedia.org/legalpad/signatures/2/ and thus has signed L2.

Thanks for confirming.

https://wikitech.wikimedia.org/wiki/Volunteer_NDA#Get_support lists as the next step "Get sign off by a C-level staff of the Wikimedia Foundation. WMF employees will arrange this as a last sign-off (e.g. with the WMF CTO) when all other criteria have been met." before adding you to WMF-NDA's https://phabricator.wikimedia.org/project/members/61/ . @Urbanecm_WMF: Would you have someone in mind?

I'm happy to run this by my manager as a first next step. They're OoO until Friday though, so a reply from them would likely come during the next week.

Also adding LDAP-Access-Requests (and updated description to fit the form) , since this is a request for the nda LDAP group, not WMF-NDA, as only the LDAP group gives Turnillo access, which is what Xqt looks for.

Urbanecm_WMF renamed this task from Volunteer NDA permission for xqt to Grant access to nda LDAP group to xqt.Oct 24 2023, 12:04 PM
Urbanecm_WMF updated the task description. (Show Details)

Thanks Dennis!

@JMeybohm Hi Janis, I see you're on SRE clinic duty this week. This request now should have sponsorship from a WMF staff member (me) and approval by @DMburugu as my manager (see above). Is there anything else I can help with to move this request forward?

Sign off by a WMF C-level staff

Sign off by a WMF C-level staff

While that is indeed currently a part of the relevant docs, it's currently not mentioned (requested) in any of the past volunteer NDA requests, such as: T341272, T337121 (has a mention of C-lvl signoff by a volunteer, but that is not recorded on the task and the request got processed anyhow) or T333884 (or, my own request). As such, there is very little clarity on my part on what exact next steps should be taken (and if it is a C-lvl review, how that would be requested), since that is not apparent from observing prior such requests.

If a C-level reviews requests like this one, it has to happen secretly and in the background, as none of the recent tasks contain an explicit C-level approval. However, I think it is more likely that this step is actually not required (despite what the docs say). This confusion is why I pinged @JMeybohm in my previous comment, asking for advice, as I expect they (being a SRE) have more experience in how requests like this one are actually handled. If possible, I'd appreciate a slightly more detailed advice :). We should probably have a task to clarify the NDA process, if my "C-level review does not actually happen" assumption is a correct one.

Thanks for raising this @Urbanecm_WMF, we will have the docs clarified soon. Standard volunteer NDA access did not regularly require on C level approval in the past, so we're gtg here.
@KFrancis I can't see the user in the NDA tracking sheet as of now. Could you please make sure NDA has been signed and you have a legal name on file? Thanks!

hnowlan changed the task status from Open to Stalled.Nov 10 2023, 12:48 PM

Hello, would someone mind clarifying what is this stalled on please?

@Urbanecm_WMF I think this is awaiting confirmation from @KFrancis that an NDA has been signed (and that we have a legal name on file), per the comment from 1st Nov.

Hi all, I was finally granted access to see the signature confirmation page. I can confirm https://phabricator.wikimedia.org/p/Xqt/ has signed. We are still researching if we should be using this process for NDA's in the future, but for now, please proceed with the access request. Thank you for your patience.

Dzahn changed the task status from Stalled to Open.Nov 15 2023, 6:36 PM
Dzahn subscribed.

@Xqt Would you like us to keep your real name out of public repos or you don't mind?

Thanks @KFrancis! Should we expect Xqt to be on the "NDA and MOU.." Google doc? Can we just use the "known to legal" string as real name regardless if we see it there?

I think the 'known to legal' is okay for now. Now that I have access to the 'signed' page, you can always check with me as well.

@Xqt Can we publish the email address associated with your LDAP/Wikitech account? Is it accurate or would you like to use a different one?

Xqt removed Xqt as the assignee of this task.Dec 4 2023, 11:12 AM

@Dzahn:

@Xqt Would you like us to keep your real name out of public repos or you don't mind?

I propose not to publish my real name if possible.

@Xqt Can we publish the email address associated with your LDAP/Wikitech account? Is it accurate or would you like to use a different one?

Yes, it can be published; the associated mail address is still valid and should also be used here.

Thanks for responding @Xqt. Yes, it's possible to not publish the real name. We will just use "known to legal" in the realname field in the repo. Thanks for confirming we can publish the mail address. We can move forward with this ticket now.

Change 980013 had a related patch set uploaded (by Dzahn; author: Dzahn):

[operations/puppet@production] admin: add user xqt to ldap_only admins, volunteer NDA

https://gerrit.wikimedia.org/r/980013

Hi all, I was finally granted access to see the signature confirmation page. I can confirm https://phabricator.wikimedia.org/p/Xqt/ has signed.

Hi @KFrancis, can you add Xqt to the 'NDA and MOU' doc? Thanks!

Change 980013 merged by Dzahn:

[operations/puppet@production] admin: add user xqt to ldap_only admins, volunteer NDA

https://gerrit.wikimedia.org/r/980013

Mentioned in SAL (#wikimedia-operations) [2023-12-05T01:18:49Z] <mutante> LDAP - added user xqt to group nda (T348520)

Done, thanks!

Thank you as well!

Also done on our side.

@Xqt You have been added to the LDAP group "nda" as requested.