Page MenuHomePhabricator

SSH access for Lex Nasser, analytics intern
Closed, ResolvedPublic

Description

Lex will be working with the analytics team until february 15th in the capacity of intern

Full Name: Lex Nasser
Developer Access Username: lexnasser
Public ED25519 Key: AAAAC3NzaC1lZDI1NTE5AAAAIAgozlHmJxSSkQjDKhjx4ZlMw0hqr+3F+1M2In7CGRCo
Reason: Need access to analytics servers to begin work on the Analytics team.

Details

Related Gerrit Patches:

Event Timeline

Nuria created this task.Oct 16 2019, 5:49 PM
Restricted Application added a project: Operations. · View Herald TranscriptOct 16 2019, 5:49 PM
Restricted Application added a subscriber: Aklapper. · View Herald Transcript
Nuria renamed this task from SSH access for Lex Nasser, analytics inter to SSH access for Lex Nasser, analytics intern.Oct 16 2019, 5:49 PM

Approving as the relevant Wikimedia Foundation employee.

Nuria added a comment.Oct 16 2019, 6:05 PM

Approved on my end, i think @lexnasser needs to provide ssh keys and sign NDA per https://wikitech.wikimedia.org/wiki/Production_access

lexnasser updated the task description. (Show Details)Oct 16 2019, 6:15 PM
crusnov assigned this task to Dzahn.Oct 17 2019, 2:44 PM
crusnov triaged this task as Normal priority.

@lexnasser @Nuria Could you please specify which groups are requested from https://wikitech.wikimedia.org/wiki/Analytics/Data_access#Access_Groups

@lexnasser Could you please read and sign L3?

@Dzahn It shows that I signed L3 Wednesday (image attached) .Let me know if I am mistaken. Will have to defer to @Nuria regarding which groups.

analytics-privatedata-users would be the group

Nuria added a comment.Oct 18 2019, 5:01 PM

And also we need to add lex to nda group for access to turnilo and superset

@RStallman-legalteam Hi, do you have NDA on file for Lex Nasser?

Dzahn added a comment.Oct 18 2019, 5:08 PM

@Nuria Thank you for the groups, will prepare a change and move forward with this asap.

@lexnasser Thank you, yes, i see the signature looks good!

Dzahn added a comment.Oct 18 2019, 5:26 PM

@Nuria Is Lex going to get a @wikimedia.org email address? I was wondering because i need to specify one in the code change and it looks like it doesn't exist under the standard naming scheme.

@lexnasser Pending the question above which email account to use, could you please Create a Wikimedia developer account and let me know the name you used? You will pick 2 separate names, one for the wiki and one for the shell account, in that form.

@Dzahn I do not have an NDA on file for Lex Nasser, but it is possible that the paperwork for Lex's internship was completed through HR. @Nuria can you confirm?

Nuria added a comment.Oct 18 2019, 8:43 PM

@RStallman-legalteam it was done through HR, yes, he probably needs to sign an NDA as well?

Ok, probably best for me to just create one since it looks like shell access is needed. @lexnasser could you email your physical (snail mail) address rstallman@wikimedia.org

Thanks!

Nuria added a comment.Oct 21 2019, 6:47 PM

Please let us know what else is needd @RStallman-legalteam

Thanks @Nuria. Working on the NDA now. Can you confirm the exact access set for the NDA - would listing SSH access be clear enough?

Nuria added a comment.Oct 21 2019, 8:13 PM

@RStallman-legalteam, ssh access and access to private data up to February 15th

NDA is signed and on file. Thanks!

Nuria added a comment.EditedTue, Oct 22, 3:59 PM

Thank you!
@lexnasser: please ping @Dzahn with your e-mail address/user for wikitech

Change 545388 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] admins: add shell account for Lex Nasser

https://gerrit.wikimedia.org/r/545388

Change 545388 merged by Dzahn:
[operations/puppet@production] admins: add shell account for Lex Nasser

https://gerrit.wikimedia.org/r/545388

Dzahn added a comment.Tue, Oct 22, 9:40 PM

@lexnasser Within max. 30 minutes this should work for you now. Please take a look at https://wikitech.wikimedia.org/wiki/Production_access#Setting_up_your_access how to setup SSH config. You will be jumping via the bastion hosts to other machines behind them. Other analytics team members can help you which hosts exactly to connect to.

Dzahn closed this task as Resolved.Tue, Oct 22, 9:41 PM

If any unexpected issues please just reopen the ticket.

Nuria added a comment.Tue, Oct 22, 9:41 PM

+1 , also let's make sure to go over the Data guidelines before working with the data.

Mentioned in SAL (#wikimedia-operations) [2019-10-22T21:45:21Z] <mutante> LDAP - added lexnasser to nda group (T235688)

Dzahn added a comment.Tue, Oct 22, 9:46 PM

And also we need to add lex to nda group for access to turnilo and superset

Done!

@lexnasser You should now also be able to login on https://turnilo.wikimedia.org/ and https://superset.wikimedia.org/

MoritzMuehlenhoff reopened this task as Open.Wed, Oct 23, 7:39 AM

Reopening, currently the same key is used in Cloud VPS and production, which is a security risk.

Dzahn added a comment.Wed, Oct 23, 4:49 PM

@lexnasser Please create a new SSH key that is not used in cloud and let us know the public part so we can update the production access.

Dzahn reassigned this task from Dzahn to lexnasser.Wed, Oct 23, 4:49 PM
Dzahn added a subscriber: Dzahn.

Here's another public ED25519 key: AAAAC3NzaC1lZDI1NTE5AAAAIOBTDDmL8isvso6xqOJB5qkk3n8xuM0XxFc1Q34ZnZRj

Let me know which service is associated with which key. Thanks!

Change 545630 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] admins: re-enable shell account for lexnasser with new key

https://gerrit.wikimedia.org/r/545630

Change 545630 merged by Dzahn:
[operations/puppet@production] admins: re-enable shell account for lexnasser with new key

https://gerrit.wikimedia.org/r/545630

Dzahn added a comment.Wed, Oct 23, 7:15 PM

@lexnasser Thanks, your access has been re-enabled with the new key.

The services associated with the new (production) key are: any host name ending in .wmnet or .wikimedia.org.

The services associated with the previous (cloud) key are: any host names ending in .wmflabs.org or cloud instances (virtual machines) you created using https://horizon.wikimedia.org. You probably don't need this.

Dzahn closed this task as Resolved.Wed, Oct 23, 7:15 PM