Page MenuHomePhabricator

Create cloudelastic-root group
Closed, ResolvedPublic

Description

Create cloudelastic-root group and add discovery members to this new group

Event Timeline

Mathew.onipe triaged this task as Normal priority.Jan 29 2019, 3:41 PM
Mathew.onipe created this task.

Change 487040 had a related patch set uploaded (by Mathew.onipe; owner: Mathew.onipe):
[operations/puppet@production] admin: create new system groups for cloudelastic nodes

https://gerrit.wikimedia.org/r/487040

Joe added a subscriber: Joe.Feb 7 2019, 8:46 AM

Hi @Mathew.onipe I'd need more context on why we want to create this group please.

Hi @Joe
cloudelastic is a replica of cirrussearch like labsdb* is to maps*. So this group separates access to cloudelastic and our main search cluster. This will allow access to members of the cloud platform team who should not access search cluster

Joe added a comment.Feb 7 2019, 11:48 AM

ok great - this should be discussed in the SRE meeting on monday.

bd808 added a comment.Feb 7 2019, 7:50 PM

Related rights groups are wmcs-roots and wmcs-admin. Those 2 groups grant broader rights across Cloud Services bare metal instances (OpenStack servers, Wiki Replica databases). Keeping the rights for these cloud replicas separate from the rights for the production cirrussearch elasticsearch hosts is a good practice for cross-purpose limiting rights escalation issues.

Dzahn added a comment.Feb 11 2019, 7:09 PM

It was in the SRE meeting and there were no objections (SRE-2019-02-11#Access_Requests)

Change 487040 merged by Gehel:
[operations/puppet@production] admin: create new system groups for cloudelastic nodes

https://gerrit.wikimedia.org/r/487040

debt closed this task as Resolved.Feb 15 2019, 7:00 PM
debt claimed this task.