Page MenuHomePhabricator

Requesting access to Deployment shell for derick
Closed, ResolvedPublicRequest

Description

Requestor provided information and prerequisites

This section is to be completed by the individual requesting access.

  • Wikitech username: Alangi_Derick
  • Email address: xsavitar.wiki@aol.com
  • SSH public key (must be a separate key from Wikimedia cloud SSH access): Wikimedia Prod Access Pub Key
  • Requested group membership: wmf-deployments
  • Reason for access: Assist in deployment of patches (back-ports, config) to production.
  • Name of approving party (manager for WMF/WMDE staff): @thcipriani
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: Read, Ack & Signed
  • Please coordinate obtaining a comment of approval on this task from the approving party.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: wikitech username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

@xSavitar Hi, ticket looks good. I'll handle it as the "clinic duty" person this week.

@thcipriani Let's start with your approval. Do you approve?

@xSavitar Hi, ticket looks good. I'll handle it as the "clinic duty" person this week.

@thcipriani Let's start with your approval. Do you approve?

approved! @xSavitar has gone through round 1 of deployment training and will need this access to go further :)

Thanks @thcipriani

I confirm L3 has already been signed as well.

@xSavitar All boxes are checked except the "sign valid NDA with legal". Assuming you haven't already done this, I will add @KFrancis to get this going.

@KFrancis Hello, this is another volunteer NDA request. The needed data is already on this ticket I believe:

Wikitech username: Alangi_Derick
Email address: alangiderick@gmail.com

Dzahn triaged this task as Medium priority.

@Dzahn I am confirming Alangi Derick has a signed NDA on file with legal. Thanks!

Thank you @KFrancis , perfect. Will go ahead.

Change 685189 had a related patch set uploaded (by Dzahn; author: Dzahn):

[operations/puppet@production] admin: update email address for shell user Alangi Derick

https://gerrit.wikimedia.org/r/685189

Kizule subscribed.
Kizule unsubscribed.

Change 685190 had a related patch set uploaded (by Dzahn; author: Dzahn):

[operations/puppet@production] admin: upgrade derick from ldap_only to deployer

https://gerrit.wikimedia.org/r/685190

Change 685189 abandoned by Dzahn:

[operations/puppet@production] admin: update email address for shell user Alangi Derick

Reason:

merging into a single change

https://gerrit.wikimedia.org/r/685189

Change 685189 restored by Dzahn:

[operations/puppet@production] admin: update email address for shell user Alangi Derick

https://gerrit.wikimedia.org/r/685189

@xSavitar Could you take a look at https://gerrit.wikimedia.org/r/c/operations/puppet/+/685189 ? That is updating the email address associated with the existing shell account (that is yours, right?) to match with the one you used here on the ticket.

Is that correct? And if so, could you please login on Wikitech and update your profile there to also use that new address?

Then the information we have in LDAP will match what is in this ticket and reduce confusion.

Thank you

@Dzahn, I think I should just use the xsavitar.wiki@aol.com one as it's what I'm using here on Gerrit & on Wikitech too. Sorry about the confusion there. I'll update the phab ticket now.

I'm just trying not to over use my personal email for wiki activities as the notifications from Phab, Gerrit can really bloat my personal inbox :).

Change 685189 abandoned by Dzahn:

[operations/puppet@production] admin: update email address for shell user Alangi Derick

Reason:

keeping the existing address is preferred. we verified it's the same person

https://gerrit.wikimedia.org/r/685189

Change 685190 merged by Dzahn:

[operations/puppet@production] admin: upgrade derick from ldap_only to deployer

https://gerrit.wikimedia.org/r/685190

We talked on IRC and I confirm Derick could succesfully connect to deploy1002 via a bastion. Resolving!