Page MenuHomePhabricator

Add @pmiazga @Niedzielski and @phuedx to the deploy-service group
Closed, ResolvedPublic

Description

@pmiazga, @Niedzielski and @phuedx will be the owners of the Proton PDF render. As such, they need to be in the deploy-service group. Note this constitutes a sudo request, since Scap ran by users in this group can start/stop services.

Related Objects

StatusAssignedTask
StalledNone
OpenNone
ResolvedBawolff
Resolvedphuedx
Resolvedmobrovac
Resolvedmobrovac
Resolvedphuedx
ResolvedJdrewniak
Resolvedphuedx
Resolvedphuedx
Resolvedphuedx
Resolvedphuedx
DeclinedNone
Resolvedbmansurov
Resolvedmobrovac
Resolvedovasileva
InvalidNone
ResolvedJdlrobson
Resolvedphuedx
Resolvedphuedx
Resolvedholger.knust
ResolvedTgr
Openjijiki
OpenMSantos
Resolvedmobrovac
Resolvedovasileva
Resolvedphuedx
Declinedpmiazga
ResolvedDzahn
Resolvedpmiazga
Duplicateholger.knust
OpenNone
ResolvedTgr
ResolvedJohan
OpenNone
StalledNone
Resolvedmobrovac
Resolvedfaidon

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald TranscriptJun 21 2018, 11:46 AM

@pmiazga, @Niedzielski and @phuedx, in order for this access to be granted, it needs to be approved by your respective managers. Please subscribe them and let them review the request.

Change 441379 had a related patch set uploaded (by Mobrovac; owner: Mobrovac):
[operations/puppet@production] Add niedzielski, pmiazga and phuedx to deploy-service

https://gerrit.wikimedia.org/r/441379

@mobrovac, @phuedx is my manager so good to go Thank you!

@mobrovac, @phuedx is my manager so good to go Thank you!

Euh, no, it's not, he needs to approve this request for you.

phuedx added a subscriber: dr0ptp4kt.EditedJun 21 2018, 12:11 PM

I approve this request for @Niedzielski and @pmiazga (I'm the Engineering Manager for Readers Web). @dr0ptp4kt will have to approve this request for me.

@phuedx thanks for your approval.

RobH added a subscriber: RobH.Jun 21 2018, 6:37 PM

Just reviewing this as clinic duty this week, and this seems to be a deploy service, but doesn't list sudo rights in data.yaml. Does this include sudo rights deeper within the puppet code for this group, or does this group not act as any user other than the user's own?

I think that group is just trusted by keyholder or something?

The users in the deploy-service group can sudo service (start|stop|restart) * on the target nodes, so it essentially is a sudo request.

RobH added a comment.Jun 21 2018, 10:47 PM

Thanks for feedback, duly noted and set in the proper column for SRE meeting review approval.

RobH triaged this task as Normal priority.Jun 22 2018, 3:44 PM

Change 441379 merged by Alexandros Kosiaris:
[operations/puppet@production] Add niedzielski, pmiazga and phuedx to deploy-service

https://gerrit.wikimedia.org/r/441379

RobH added subscribers: mark, faidon.Jun 25 2018, 4:16 PM

Change 441379 merged by Alexandros Kosiaris:
[operations/puppet@production] Add niedzielski, pmiazga and phuedx to deploy-service
https://gerrit.wikimedia.org/r/441379

Was this reviewed/approved by either @mark or @faidon out of band of this task? (Just checking, since this normally is a sudo group requiring meeting or director approval.)

RobH added a comment.EditedJun 26 2018, 5:04 PM

I've emailed both @faidon and @mark for how to handle this, since it was merged without the meeting approval (at least as far as I can see.) This may have been discussed at the SRE offsite last week, which I did not attend, and it may have been approved there.

So with either @mark or @faidon's approval, we can leave this patchset merged/live and resolve this task.

faidon closed this task as Resolved.Jun 27 2018, 3:58 PM
faidon claimed this task.

Sure, that's fine :)

Vvjjkkii renamed this task from Add @pmiazga @Niedzielski and @phuedx to the deploy-service group to ajaaaaaaaa.Jul 1 2018, 1:02 AM
Vvjjkkii reopened this task as Open.
Vvjjkkii removed faidon as the assignee of this task.
Vvjjkkii raised the priority of this task from Normal to High.
Vvjjkkii updated the task description. (Show Details)
Vvjjkkii removed subscribers: gerritbot, Aklapper.
mobrovac renamed this task from ajaaaaaaaa to Add @pmiazga @Niedzielski and @phuedx to the deploy-service group.Jul 1 2018, 10:46 AM
mobrovac closed this task as Resolved.
mobrovac claimed this task.
mobrovac lowered the priority of this task from High to Normal.
mobrovac updated the task description. (Show Details)