Page MenuHomePhabricator

Requesting access to GLOBAL ROOT for Michael DiPietro
Closed, ResolvedPublicRequest

Description

Requestor provided information and prerequisites

This section is to be completed by the individual requesting access.

  • Wikitech username: Michael DiPietro
  • Email address: mdipietro@wikimedia.org
  • SSH public key (must be a separate key from Wikimedia cloud SSH access): ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM3xenp/i5Yv06X5KIEPPwpLSqE8d0KPCHHa/M8IgH4I michael@mouse
  • Requested group membership: ops
  • Reason for access: New hire for the WMCS team
  • Name of approving party (manager for WMF/WMDE staff): Nicholas Skaggs
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: ack
  • Please coordinate obtaining a comment of approval on this task from the approving party.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: wikitech username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

Legoktm triaged this task as Medium priority.Jul 29 2021, 6:12 PM

@mdipietro The only thing left on the checklist is approval from @nskaggs.

One question I had is whether you're using a yubikey (or other hardware storage) for your SSH key, I don't think it's required but strongly recommended. If you don't have a yubikey, ITS can send some to you.

Typically I would make the Gerrit patch for you to get access, however it's probably a good learning opportunity for you to make the patch yourself, the file you need to edit is https://gerrit.wikimedia.org/r/plugins/gitiles/operations/puppet/+/refs/heads/production/modules/admin/data/data.yaml (see the README in that directory too). Let me know if you have any questions, feel free to ping me on IRC as well.

I am not using a yubikey, though I could put in a request for one. I'll have a look at the git

Change 708830 had a related patch set uploaded (by Michael DiPietro; author: Michael DiPietro):

[operations/puppet@production] adding new hire mdipietro to ops

https://gerrit.wikimedia.org/r/708830

Change 708830 merged by Michael DiPietro:

[operations/puppet@production] adding new hire mdipietro to ops

https://gerrit.wikimedia.org/r/708830

Legoktm updated the task description. (Show Details)