Page MenuHomePhabricator

Access to WikimediaFoundation.org analytics for Deb
Closed, ResolvedPublic

Description

Hello - can we please get access for one of our new Directors, Deb Zierten, to the analytics system for WikimediaFoundation.org? Her Wikitech account is "Deb Zierten". Please let me know if you need anything else. Thank you!

Event Timeline

Please add ldap username (it should be one word)

Is their LDAP the same as our Google Accounts username? I was told previously it was associated with Wikitech, but perhaps I am remembering wrong or was told wrong. :)

ldap is associated with wikitech, normally 1 word

If it is their username, I suspect then that it is "Deb_Zierten" as they are User:Deb Zierten.

Then they should have access already using "Deb_Zierten"

Okay - so basically anyone that registers on Wikitech and knows the account password for our analytics instance can get access - you do not need to add any permissions?

Okay - so basically anyone that registers on Wikitech and knows the account password for our analytics instance can get access

That's correct

Awesome - thank you! Sorry for the confusion. :)

@Nuria - Deb does not seem to have access to the piwik login, after she enters her LDAP she gets an error that she does not have access to the site and does not get the second login prompt. Any ideas?

mmm, I thought that piwik might not require an NDA on file but it might, @elukey is piwik access also restricted to NDA group?

Peachey88 reopened this task as Open.EditedJul 20 2019, 4:51 AM
Peachey88 subscribed.

The user needs to be in either wmf or nda for access (see: https://wikitech.wikimedia.org/wiki/Analytics/Systems/Piwik)

Their LDAP account currently isn't in any if you have a look at https://tools.wmflabs.org/ldap/user/Deb_Zierten

fdans triaged this task as High priority.
fdans moved this task from Incoming to Operational Excellence on the Analytics board.
fdans moved this task from Operational Excellence to Ops Week on the Analytics board.

@Varnent Deb needs to sign an nda (she might have done it de-facto on her onboarding), someone will verify is been so and she can be added to the group that has access to this data, sorry my first message on this regard was incorrect.

@Nuria - the NDA was a part of her onboarding - so she should be all set. :)

No worries - thank you!! :)

I think someone (that can do so ) needs to verify nda on file + employment and then access can be granted

I think someone (that can do so ) needs to verify nda on file + employment and then access can be granted

That would be @RStallman-legalteam

Would @Heather be able to do so as our department executive?

herron subscribed.

I wasn't able to find an ldap account with shell username Deb_Zierten, but I do see shell username dz1 associated with Deb's wikitech account and wmf email address.

https://tools.wmflabs.org/ldap/user/dz1

I've added the dz1 account to the NDA group, and will set this to resolved as a soft close. If any follow up is needed please don't hesitate to re-open. Thanks!

MoritzMuehlenhoff subscribed.

@herron: If you add an account to a PII-relevant LDAP group which does not have shell access to the production cluster, it needs to be added to modules/admin/data/data.yaml

Change 525294 had a related patch set uploaded (by Herron; owner: Herron):
[operations/puppet@production] admin: add dz1 to ldap_only_users

https://gerrit.wikimedia.org/r/525294

Change 525294 merged by Herron:
[operations/puppet@production] admin: add dz1 to ldap_only_users

https://gerrit.wikimedia.org/r/525294

I don't actually see the paper work for WMF full time req # employees, so I think having the manager or C-level approve here would be the best practice. Thanks!

It doesn't seem like you need it, but this is approved. Let me know if you need something else.

Great! Thanks all

@herron : You've added her to the wrong group, staff members need to be a member of cn=wmf, cn=nda is for people who have access to PII-relevant data, but are not staff members of the Foundation (i.e. community members or staff of Wikimedia Deutschland).

staff members need to be a member of cn=wmf, cn=nda is for people who have access to PII-relevant data, but are not staff members

Glad you spotted that! Group membership has been switched from nda to wmf.