Page MenuHomePhabricator

Icinga contact/permissions for cwdent (cdentinger)
Closed, ResolvedPublic

Description

I can get in and see, but get "Not Authorized" on writes. I could use the ability to put alerts on pause etc.

Event Timeline

RobH subscribed.

So by default you can ack anything that you are alerted for. The main reason this doesn't work is if there is a mismatch between what your username is in ldap, and what we have your contact name as in icinga.

I'll check into this right now, because I'm intrigued.

@cwdent: It doesn't look like you are actually setup to be emailed or SMS/paged for any particular services, which is why you cannot acknowledge any of them.

I'm happy to help get you setup, since it was an excellent excuse for me to re-familiarize myself with the check_group implementation.

Things I'll need from you:

  • Some personal contact info, such as if you only want emails, or if you want SMS messages.
    • No need to list off your email or cell on this thread, since I can pull off the contact list on officewiki!
    • If you do want SMS, what time zone are you in, so I can set it where it won't page you during non-traditionally-awake hours. Also what cellular carrier do you have (it matters for what we use as an sms gateway.)
  • I'm assuming the work email and cell listed on officewiki for contacts are correct.

Then I'll have to coordinate with @Jgreen on auditing/updating nsca_frack.cfg & iplementing an updated fundraising-tech alert group.

Change 341051 had a related patch set uploaded (by robh):
[operations/puppet] this updates fundraising team members for icinga alerts

https://gerrit.wikimedia.org/r/341051

@RobH Contact info is correct on officewiki, and I'd like to receive SMS.
Time zone is MST. My carrier is Google fi so it switches, usually between
T-Mobile and Sprint. Thanks very much for your help!

Change 341051 merged by RobH:
[operations/puppet] this updates fundraising team members for icinga alerts

https://gerrit.wikimedia.org/r/341051

Change 341075 had a related patch set uploaded (by robh):
[operations/puppet] rename contactgroup fundraising to fr-tech

https://gerrit.wikimedia.org/r/341075

Change 341075 merged by RobH:
[operations/puppet] rename contactgroup fundraising to fr-tech

https://gerrit.wikimedia.org/r/341075

@cwdent: It turns out we don't have anyone in MST getting pages. We can set you up to receive pages 24x7, or only during your waking hours. Since you are the only one in that time period, you can also set what those waking hours are. (Its not dynamic though, and we tend to not bother shifting them for daylight versus non daylight savings hours.). The common hours selected are 8AM-Midnight, so unless you state otherwise, that is what I'll tend to pick.

If you are someone who always puts your phone in DnD and rather just be paged 24x7, that is also an option.

Please advise.

So Casey is currently setup to receive emails 24x7 and can ack all the fundraising based hosts. Once we ensure that 8-midnight local is acceptable (or if 24x7 is preferred), I'll change it over to SMS.

@RobH - sorry for the delay, was afk for awhile. Being paged any time is
fine, I will keep it on silent mode if need be.

RobH closed this task as Resolved.EditedMar 3 2017, 11:54 PM

Cool, you should now be all setup.

I setup the sms to use the google fi email to sms gateway, so it should work. You are also setup to receive emails for everything you get a text/sms for, so if you have emails starting from now and no SMS on future alerts, we may need to troubleshoot.

So now you receive SMS alerts for ALL THINGS frack, but not for normal production systems. You should also be able to put any host that you receive alerts for into maintainance mode or acknowledge any alerts for them.

If anything doesn't work as it should, feel free to ping me (or Jeff, we worked on this together to ensure proper coverage of services for frack) in irc, or just reopen this task.

@RobH - I finally got around to trying to ack something but still got "Not authorized" logged in as cdentinger - not cwdent as my login in is here and a couple other places. I think I may have 2 LDAP accounts? Maybe this would be a good motivator to sort that out.

In LDAP there is just 1 user "cwdent" but it has a uid "cwdent", with sn and cn "Cdentinger". The Icinga contact name is cwdent but i think it's the sn it has to match.

Change 347050 had a related patch set uploaded (by Dzahn):
[operations/puppet@production] nagios_common: rename cwdent to cdentinger

https://gerrit.wikimedia.org/r/347050

Dzahn renamed this task from Write access to Icinga to Icinga contact/permissions for cwdent (cdentinger).Apr 7 2017, 7:32 PM
Dzahn claimed this task.

Change 347050 merged by Dzahn:
[operations/puppet@production] nagios_common: rename cwdent to cdentinger

https://gerrit.wikimedia.org/r/347050

@cwdent I renamed your Icinga contact to "cdentinger". Please log out of Icinga and login again, using "cdentinger" (not capitalized, it would let you login as both Cdentinger and cdentinger but we want to match the icinga contact name, this can be confusing because both can log in but only one has the additional permissions).

Let me know if you can send a command now (for a service you are a contact for).

Dzahn triaged this task as Medium priority.Apr 7 2017, 7:42 PM
Dzahn removed a project: Patch-For-Review.

@Dzahn thank you for the help, everything seems to be working now.