Page MenuHomePhabricator

SSH access for Lex Nasser, analytics intern
Closed, ResolvedPublic

Description

Lex will be working with the analytics team until february 15th in the capacity of intern

Full Name: Lex Nasser
Developer Access Username: lexnasser
Public ED25519 Key: AAAAC3NzaC1lZDI1NTE5AAAAIAgozlHmJxSSkQjDKhjx4ZlMw0hqr+3F+1M2In7CGRCo
Reason: Need access to analytics servers to begin work on the Analytics team.

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
Nuria renamed this task from SSH access for Lex Nasser, analytics inter to SSH access for Lex Nasser, analytics intern.Oct 16 2019, 5:49 PM

Approving as the relevant Wikimedia Foundation employee.

crusnov triaged this task as Medium priority.

@lexnasser @Nuria Could you please specify which groups are requested from https://wikitech.wikimedia.org/wiki/Analytics/Data_access#Access_Groups

@lexnasser Could you please read and sign L3?

@Dzahn It shows that I signed L3 Wednesday (image attached) .Let me know if I am mistaken. Will have to defer to @Nuria regarding which groups.

Messages Image(4165936584).png (344×1 px, 57 KB)

analytics-privatedata-users would be the group

And also we need to add lex to nda group for access to turnilo and superset

@Nuria Thank you for the groups, will prepare a change and move forward with this asap.

@lexnasser Thank you, yes, i see the signature looks good!

@Nuria Is Lex going to get a @wikimedia.org email address? I was wondering because i need to specify one in the code change and it looks like it doesn't exist under the standard naming scheme.

@lexnasser Pending the question above which email account to use, could you please Create a Wikimedia developer account and let me know the name you used? You will pick 2 separate names, one for the wiki and one for the shell account, in that form.

@Dzahn I do not have an NDA on file for Lex Nasser, but it is possible that the paperwork for Lex's internship was completed through HR. @Nuria can you confirm?

@RStallman-legalteam it was done through HR, yes, he probably needs to sign an NDA as well?

Ok, probably best for me to just create one since it looks like shell access is needed. @lexnasser could you email your physical (snail mail) address rstallman@wikimedia.org

Thanks!

Thanks @Nuria. Working on the NDA now. Can you confirm the exact access set for the NDA - would listing SSH access be clear enough?

@RStallman-legalteam, ssh access and access to private data up to February 15th

Thank you!
@lexnasser: please ping @Dzahn with your e-mail address/user for wikitech

Change 545388 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] admins: add shell account for Lex Nasser

https://gerrit.wikimedia.org/r/545388

Change 545388 merged by Dzahn:
[operations/puppet@production] admins: add shell account for Lex Nasser

https://gerrit.wikimedia.org/r/545388

@lexnasser Within max. 30 minutes this should work for you now. Please take a look at https://wikitech.wikimedia.org/wiki/Production_access#Setting_up_your_access how to setup SSH config. You will be jumping via the bastion hosts to other machines behind them. Other analytics team members can help you which hosts exactly to connect to.

If any unexpected issues please just reopen the ticket.

+1 , also let's make sure to go over the Data guidelines before working with the data.

Mentioned in SAL (#wikimedia-operations) [2019-10-22T21:45:21Z] <mutante> LDAP - added lexnasser to nda group (T235688)

And also we need to add lex to nda group for access to turnilo and superset

Done!

@lexnasser You should now also be able to login on https://turnilo.wikimedia.org/ and https://superset.wikimedia.org/

MoritzMuehlenhoff subscribed.

Reopening, currently the same key is used in Cloud VPS and production, which is a security risk.

@lexnasser Please create a new SSH key that is not used in cloud and let us know the public part so we can update the production access.

Here's another public ED25519 key: AAAAC3NzaC1lZDI1NTE5AAAAIOBTDDmL8isvso6xqOJB5qkk3n8xuM0XxFc1Q34ZnZRj

Let me know which service is associated with which key. Thanks!

Change 545630 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] admins: re-enable shell account for lexnasser with new key

https://gerrit.wikimedia.org/r/545630

Change 545630 merged by Dzahn:
[operations/puppet@production] admins: re-enable shell account for lexnasser with new key

https://gerrit.wikimedia.org/r/545630

@lexnasser Thanks, your access has been re-enabled with the new key.

The services associated with the new (production) key are: any host name ending in .wmnet or .wikimedia.org.

The services associated with the previous (cloud) key are: any host names ending in .wmflabs.org or cloud instances (virtual machines) you created using https://horizon.wikimedia.org. You probably don't need this.