Page MenuHomePhabricator

Create a service account to manage toolforge.org. from acme-chief
Closed, ResolvedPublic

Description

We need a service user with enough access to create/append/delete TXT records under the DNS zone toolforge.org.

This service user will be used by acme-chief to fulfill dns-01 challenges from Let's Encrypt.

Following the naming schema used in the deployment-prep and traffic projects tools-dns-manager could be the name for this service account. See https://wikitech.wikimedia.org/wiki/Portal:Cloud_VPS/Admin/Service_accounts for service account information.

Details

Related Gerrit Patches:

Event Timeline

Krenair reopened this task as Open.Oct 11 2019, 9:02 PM

<Krenair> Well the next step is for someone with novaadmin access to give it the designateadmin role (and maybe observer?) in the tools project.
<Krenair> Don't think it's something us mortal projectadmins can grant from the horizon UI
<Krenair> actually the ticket said 'with enough access', guess I'll leave it open for that

Krenair removed Krenair as the assignee of this task.Oct 11 2019, 9:02 PM

Mentioned in SAL (#wikimedia-cloud) [2019-10-11T21:16:30Z] <jeh> grant tools-dns-manager designateadmin role in tools project T235304

Change 542605 had a related patch set uploaded (by Jhedden; owner: Jhedden):
[operations/puppet@production] openstack: Allow tools-dns-manager to connect from labs networks

https://gerrit.wikimedia.org/r/542605

Assigned roles for the tools-dns-manager user in eqiad1

+----------------+---------------------------+-------+---------------+--------+-----------+
| Role           | User                      | Group | Project       | Domain | Inherited |
+----------------+---------------------------+-------+---------------+--------+-----------+
| observer       | Tools-dns-manager@Default |       | tools@Default |        | False     |
| designateadmin | Tools-dns-manager@Default |       | tools@Default |        | False     |
+----------------+---------------------------+-------+---------------+--------+-----------+

Change 542605 merged by Jhedden:
[operations/puppet@production] openstack: Allow tools-dns-manager to connect from labs networks

https://gerrit.wikimedia.org/r/542605

Krenair closed this task as Resolved.Oct 11 2019, 9:30 PM

Thank you!