Page MenuHomePhabricator

Provide access to iOS team for piwik production server
Closed, ResolvedPublic

Description

Members of the iOS team needs access to https://piwik.wikimedia.org/index.php for analytics reporting.

The ldap configuration can be found here:
https://github.com/wikimedia/operations-puppet/blob/088fe6a3f7198acba1e2a82817a3fae033f42d9c/manifests/role/piwik.pp#L47

Below is the list of users who need access:
JMinor
Bgerstle-WMF
Mhurd
Fjalapeno
Etonkovidova
KHammerstein
Nirzar
pizzzacat

Please let me know if you need any more info. @Milimetric can also provide more context if needed.

Event Timeline

Fjalapeno raised the priority of this task from to Needs Triage.
Fjalapeno updated the task description. (Show Details)
Fjalapeno moved this task to Backlog on the SRE board.
akosiaris claimed this task.

Hello,

Users:

@KHammerstein
@Fjalapeno
@JMinor
@BGerstle-WMF
@Nirzar

have been added to the wmf group and now have access with their labs LDAP account.

Users:

@Mhurd
@Etonkovidova
@pizzzacat

were already part of the above group and should have had already access.

Resolving, feel free to reopen if any problems arise.

Krenair subscribed.
krenair@bastion-01:~$ ldaplist -l group wmf | grep -i jminor
krenair@bastion-01:~$ ldaplist -l group wmf | grep -i fjalapeno
krenair@bastion-01:~$

Ah - that second one is due to cn != uid... But the first one definitely appears missing?

Hmm, looking into my .bash_history, it seems indeed I never added @JMinor to the group. I did add everyone else in the first list and even checked the other 3 already existing users. I can only declare it a mistake on my part.

I 've just added the user, sorry about that.

Re-resolving

Thanks. I was able to log in this afternoon, no problems.

@akosiaris @Krenair I still don't have the LDAP access to production server.

you definitely appear to:

krenair@bastion-01:~$ ldaplist -l group wmf | grep nirzar
	member: uid=nirzar,ou=people,dc=wikimedia,dc=org

@AlexMonk-WMF my LDAP is not "Nirzar" :( I don't know the password for this. my LDAP is NPangarkar (WMF)

Please don't subscribe that account, it's not relevant here.

krenair@bastion-01:~$ ldaplist -l passwd nirzar

dn: uid=nirzar,ou=people,dc=wikimedia,dc=org
	uid: nirzar
	objectClass: person
	objectClass: inetorgperson
	objectClass: organizationalPerson
	objectClass: ldappublickey
	objectClass: shadowaccount
	objectClass: posixaccount
	objectClass: top
	loginShell: /bin/bash
	sshPublicKey: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDaO3TzBd9fmWzTsrSvh4wkgrxOxeLeA2kNDrwH1PfEuix+fI4kYotXEHSGIDPk33Wq6MmlHoYNtt/eX+A7NjeFstI8ylbemy1ueFCPcNkGnmDukzqR7vNSdI9onmBZVOPC1m1arM6Cql1ZPfOsawYGhPIYubbjKiFYdZ1tQx11o8kIbQL0/rclNlAvfVc63DcwOBaO25c/gvPWkjieGRnfQ0MM8l3qYeTAHxQdu/Q3NIURKEHVVf2z423yJ85bcYmDEna/aSiM9Ji9vfq1moQw23WU1kK1jvgkXnb+ybh243KzOeSGuB8dvdU8ZPiMtEdX25WcvQDOyQg3DOZs4l3d npangarkar@wikimedia.org
	uidNumber: 11557
	gidNumber: 500
	sn: Nirzar
	homeDirectory: /home/nirzar
	mail: npangarkar@wikimedia.org
	cn: Nirzar

It has your email address on.

@AlexMonk-WMF Okay, i will try all my passwords. Thank you for confirming this :)