Page MenuHomePhabricator

give John Lewis shell access on the mailman staging VM
Closed, ResolvedPublic

Description

after the new VM has been created, give @JohnLewis shell access on it so he can help testing the import of list configs/archives and related things

Details

Related Gerrit Patches:
operations/puppet : productionadmin: add johnflewis to mailman-admins
operations/puppet : productionadmin: add mailman root group and add john
operations/puppet : productionadmin: non-sudo shell for johnflewis on fermium
operations/puppet : productionadmin: add non-root user group for mailman staging
operations/puppet : productionadmin: add user for John F. Lewis

Related Objects

Event Timeline

Dzahn created this task.Aug 5 2015, 6:42 PM
Dzahn raised the priority of this task from to High.
Dzahn updated the task description. (Show Details)
Dzahn added subscribers: MZMcBride, Dzahn, faidon and 4 others.

acked by Faidon/Mark in meeting today

Krenair renamed this task from give John Lewis shell access on the staging VM to give John Lewis shell access on the mailman staging VM.Aug 5 2015, 6:43 PM
Krenair set Security to None.

T102075 is previous ticket which was discussed in an ops meeting.

Currently unable to provide a SSH key due to ongoing ISP issues. L3 was signed with that request. Except the key, the old ticket is valid for username etc.

Managed to get access (creatively) to my encrypted store. Generated ssh key is at P1837. Thanks.

Dzahn added a comment.Aug 5 2015, 8:46 PM

This means sudo ALL ALL on the staging VM for the testing phase.

Change 229585 had a related patch set uploaded (by Dzahn):
admin: add mailman root group and add john

https://gerrit.wikimedia.org/r/229585

Change 229587 had a related patch set uploaded (by Dzahn):
admin: add user for John F. Lewis

https://gerrit.wikimedia.org/r/229587

Change 229587 merged by Dzahn:
admin: add user for John F. Lewis

https://gerrit.wikimedia.org/r/229587

Change 229995 had a related patch set uploaded (by Dzahn):
admin: add non-root user group for mailman staging

https://gerrit.wikimedia.org/r/229995

Change 229995 merged by Dzahn:
admin: add non-root user group for mailman staging

https://gerrit.wikimedia.org/r/229995

Change 230000 had a related patch set uploaded (by Dzahn):
admin: non-sudo shell for johnflewis on fermium

https://gerrit.wikimedia.org/r/230000

Change 230000 merged by Dzahn:
admin: non-sudo shell for johnflewis on fermium

https://gerrit.wikimedia.org/r/230000

Dzahn closed this task as Resolved.Aug 6 2015, 11:21 PM

fermium:

Notice: /Stage[main]/Admin/Admin::Hashuser[johnflewis]/Admin::User[johnflewis]/File[/home/johnflewis]/ensure: created

bast1001:

Notice: /Stage[main]/Admin/Admin::Hashuser[johnflewis]/Admin::User[johnflewis]/File[/home/johnflewis]/ensure: created


16:20 <JohnFLewis> johnflewis@bast1001:~$
23:20:51 fermium sshd[25289]: Starting session: shell on pts/2 for johnflewis

JohnLewis reopened this task as Open.Aug 7 2015, 4:59 PM

Re-open for sudo access. Patch coming for group.

Change 230134 had a related patch set uploaded (by John F. Lewis):
admin: add johnflewis to mailman-admins

https://gerrit.wikimedia.org/r/230134

Change 229585 abandoned by Andrew Bogott:
admin: add mailman root group and add john

Reason:
Dropping in favor of https://gerrit.wikimedia.org/r/#/c/230133/

https://gerrit.wikimedia.org/r/229585

Dzahn added a comment.Aug 7 2015, 9:11 PM

since regular shell access is already done, and there is T108349 for the privilege escalation, we can resolve here again

Change 230134 merged by Dzahn:
admin: add johnflewis to mailman-admins

https://gerrit.wikimedia.org/r/230134