Page MenuHomePhabricator

IDM: Central logging on all changes
Closed, ResolvedPublic

Description

We should implement a central logging facility of all changes, so that we have a central audit trail of which account changes were triggered when, what and by whom. Logs should be rotated using Logrotate and we should also add them to backups.

For LDAP changes we can probably hook into the existing logging of the LDAP library for managing users and groups, but in addition we also need to include some additional level of detail (e.g. triggered by admin changes).

Related Objects

StatusSubtypeAssignedTask
OpenNone
OpenNone
OpenNone
OpenSLyngshede-WMF
ResolvedNone
OpenNone
Opentaavi
OpenNone
Resolved Marostegui
ResolvedAndrew
Resolved Marostegui
ResolvedAndrew
DeclinedAndrew
ResolvedAndrew
ResolvedAndrew
ResolvedLadsgroup
DuplicateNone
Resolved Bstorm
DeclinedNone
Resolvedtaavi
ResolvedJdforrester-WMF
DeclinedNone
Openjijiki
OpenNone
OpenFeatureNone
StalledFeatureNone
OpenFeatureSLyngshede-WMF
OpenNone
OpenAndrew
OpenSLyngshede-WMF
OpenABran-WMF
Resolvedtaavi
ResolvedPRODUCTION ERRORTgr
OpenNone
Resolvedbd808
Resolvedyuvipanda
Resolvedbd808
Resolvedbd808
Resolvedbd808
Opentaavi
Resolvedtaavi
DeclinedNone
OpenNone
ResolvedSLyngshede-WMF
ResolvedSLyngshede-WMF

Event Timeline

SLyngshede-WMF claimed this task.
SLyngshede-WMF triaged this task as Low priority.

Let's keep this open until we also have logrotate configs?

Change 853283 had a related patch set uploaded (by Slyngshede; author: Slyngshede):

[operations/puppet@production] C:idm::deployment logrotation for Django logs.

https://gerrit.wikimedia.org/r/853283

Change 853283 merged by Slyngshede:

[operations/puppet@production] C:idm::deployment logrotation for Django logs.

https://gerrit.wikimedia.org/r/853283