Page MenuHomePhabricator

Clarify whether members of ldap/nda should be added to #WMF-NDA
Open, MediumPublic

Description

@Dzahn wrote this a few days ago.

<mutante> there is a "when added to LDAP wmf you automatically also get Phab WMF-NDA" nowadays
<mutante> but maybe not the same for "nda", not the automatic part
<mutante> feel free to reopen that ticket to ask for phab nda

Basically this is the volunteer counterpart of T290605: When WMF staff requests to be added to ldap/wmf, also add their Phabricator account to #WMF-NDA.

Event Timeline

Adding WMF-NDA-Requests, @mark, @faidon and @MoritzMuehlenhoff for SRE, Security and @KFrancis for feedback.

One thing to clarify is how we can ensure that the off-boarding process from this group will be performed when the NDA expires or is revoked.
Is that already covered by the offboarding script?

Ladsgroup triaged this task as Medium priority.Jan 31 2022, 8:34 AM

Adding WMF-NDA-Requests, @mark, @faidon and @MoritzMuehlenhoff for SRE, Security and @KFrancis for feedback.

One thing to clarify is how we can ensure that the off-boarding process from this group will be performed when the NDA expires or is revoked.
Is that already covered by the offboarding script?

Yes, that is covered by the offboarding script, the NDA group is Phabricator is a privileged group and "offboard -p" removes access to it (which gets run as part of offboarding in the part handled by SRE).

One thing to clarify is how we can ensure that the off-boarding process from this group will be performed when the NDA expires or is revoked.

The nda ldap group (which this task is about) is explicitely for volunteers and not staff.

In T299839#7662797, @Majavah wrote:

One thing to clarify is how we can ensure that the off-boarding process from this group will be performed when the NDA expires or is revoked.

The nda ldap group (which this task is about) is explicitely for volunteers and not staff.

A large chunk of cn=nda members are researchers with time-limited access which do get tracked by the WMF offboarding process (an estimate is given until when the project will be completed and than access is extended or revoked as needed).

The volunteer NDA isn't time-limited, as such there's also no specific offboarding (except when people ask for their access to be removed or potentially if the access needs to be removed for other reasons (e.g. violation of terms of use)).

Does this still need WMF-NDA-Requests tagging in it? It means it appears in the Clinic Duty dashboard, which is probably not what we want?

Does this still need WMF-NDA-Requests tagging in it? It means it appears in the Clinic Duty dashboard, which is probably not what we want?

Not sure what the correct tags are, I copied them from T290605.

jbond claimed this task.
jbond edited projects, added Infrastructure-Foundations; removed SRE.
jbond subscribed.

It was now also implemented that members of ldap/wmde should be added to WMF-NDA, see https://wikitech.wikimedia.org/w/index.php?title=SRE/Clinic_Duty/Access_requests&diff=2012791&oldid=2012786.

going to close this task but please re-open if there is still an outstanding action

going to close this task but please re-open if there is still an outstanding action

So what is the outcome? Should members of ldap/nda be added to WMF-NDA or not?

going to close this task but please re-open if there is still an outstanding action

So what is the outcome? Should members of ldap/nda be added to WMF-NDA or not?

Ahh sorry the diff is only about the wmde group. ill clarify and update

Yea, basically the wmde things was given as an example, or further support argument. But I don't think we have resolved the original ticket yet. So thank you for that!:)

This is coming up again. Also see T338611#8969307

We would still benefit from this being clarified and resolved.

@jbond: How could we make some progress here and who could drive it as this issue is repeatedly biting us? (For the records, the "staff counterpart" of this task got resolved in T290605: When WMF staff requests to be added to ldap/wmf, also add their Phabricator account to #WMF-NDA.) Thanks in advance for any hints!