Page MenuHomePhabricator

IDM: Central logging on all changes
Closed, ResolvedPublic

Description

We should implement a central logging facility of all changes, so that we have a central audit trail of which account changes were triggered when, what and by whom. Logs should be rotated using Logrotate and we should also add them to backups.

For LDAP changes we can probably hook into the existing logging of the LDAP library for managing users and groups, but in addition we also need to include some additional level of detail (e.g. triggered by admin changes).

Event Timeline

SLyngshede-WMF claimed this task.
SLyngshede-WMF triaged this task as Low priority.

Let's keep this open until we also have logrotate configs?

Change 853283 had a related patch set uploaded (by Slyngshede; author: Slyngshede):

[operations/puppet@production] C:idm::deployment logrotation for Django logs.

https://gerrit.wikimedia.org/r/853283

Change 853283 merged by Slyngshede:

[operations/puppet@production] C:idm::deployment logrotation for Django logs.

https://gerrit.wikimedia.org/r/853283