Page MenuHomePhabricator

Add Tilman to analytics-admins
Closed, ResolvedPublic1 Story Points

Description

Tilman needs temporary (probably in 2-6 months?) access to data readable by the analytics-admins group. Tilman has signed a data preservation notice.

Event Timeline

Ottomata created this task.Oct 23 2017, 1:50 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptOct 23 2017, 1:50 PM
Restricted Application added a project: Operations. · View Herald TranscriptOct 23 2017, 1:50 PM
Nuria added a comment.Oct 23 2017, 3:16 PM

Approved on my end.

Change 386015 had a related patch set uploaded (by Ottomata; owner: Ottomata):
[operations/puppet@production] Add tbayer to analytics-admins

https://gerrit.wikimedia.org/r/386015

Change 386015 merged by Ottomata:
[operations/puppet@production] Add tbayer to analytics-admins

https://gerrit.wikimedia.org/r/386015

Ottomata set the point value for this task to 1.Oct 23 2017, 4:57 PM
Ottomata moved this task from Next Up to Done on the Analytics-Kanban board.
RobH added a subscriber: RobH.Oct 23 2017, 5:01 PM

Please note adding Tilman to analytics-admins access was approved in today's operations meeting.

Tbayer closed this task as Resolved.Oct 23 2017, 8:27 PM

Thanks all!

@HaeB Hi! Do you still need these perms or can we roll them back?

Tbayer removed a subscriber: HaeB.Mar 3 2018, 4:18 AM

Yes, still need them (at least through this month, probably a bit longer).

Ottomata added a subscriber: HaeB.Oct 4 2018, 1:32 PM

@HaeB do you still need this? Can we roll this back?

Tbayer removed a subscriber: HaeB.Oct 6 2018, 6:00 AM

@HaeB do you still need this? Can we roll this back?

Yes, until the end of January it looks like (see also our timeline document).

Nuria added a comment.Oct 9 2018, 8:06 PM

@Tbayer, you do not need any special permissions to access any type of data, the datasources that were accessible through these permits have since then being migrated to cluster.

@Tbayer, you do not need any special permissions to access any type of data, the datasources that were accessible through these permits have since then being migrated to cluster.

(@Nuria and I cleared this up offline - this was a misunderstanding, it is about a different piece of data which still requires analytics-admins to view.)

In the interest of allowing minimal access in the Analytics cluster I'd like to review again this access request and establish what level of access is needed, and possibly create a special (permanent) group in puppet dedicated to this use case. Currently being into analytics-admins gives the ability to govern the Hadoop cluster and several services across the various hosts, that is not related to what @Tbayer needs to do IIUC (again I completely trust @Tbayer but this is tangent to following good security practices, I hope that everybody understands it :).

I think @Tbayer does not need access to this data in the immediate future so permits can be withdrawn (and added later should need arise). @Tbayer to confirm

@elukey Sure, that totally makes sense! The end of January estimate from T178802#4647106 turned out a bit optimistic (see again our internal timeline document which I have been trying to keep up to date as information became available to me), but as of a few weeks ago this now indeed looks completed for the foreseeable future. Please remove the bits. What might the turnaround time be to reinstate them if needed?

Change 500765 had a related patch set uploaded (by Elukey; owner: Elukey):
[operations/puppet@production] admin: remove tbayer from analytics-admins

https://gerrit.wikimedia.org/r/500765

elukey added a comment.Apr 2 2019, 3:35 PM

@elukey Sure, that totally makes sense! The end of January estimate from T178802#4647106 turned out a bit optimistic (see again our internal timeline document which I have been trying to keep up to date as information became available to me), but as of a few weeks ago this now indeed looks completed for the foreseeable future. Please remove the bits. What might the turnaround time be to reinstate them if needed?

Thanks! I'd say come days to figure out what is the appropriate group to create/use, especially depending on how long it will be needed. Ping me if you need anything follow up, I'll be glad to help :)

Change 500765 merged by Elukey:
[operations/puppet@production] admin: remove tbayer from analytics-admins

https://gerrit.wikimedia.org/r/500765