Page MenuHomePhabricator

Split the permission to access Logstash from the cn=wmf and cn=nda groups
Open, HighPublic

Description

Currently the membership of cn=wmf and cn=nda grants access to Logstash. This access is fairly sensitive and by far not anyone who's in these groups for other reasons actually needs Logstash. As such, the plan is to split it out to a separate group cn=logstash-access.

Next steps:

  • Create the group
  • Generate an initial list of users who have access Logstash in the last X days
  • Create a process to request users to cn=logstash-access for those who don't have it yet (eventually this will be implemened in Bitu/idm.wikimedia.org, but in the interim probably via Clinic Duty)

Event Timeline

Change #1084732 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Grant access to logstash to cn=logstash-access

https://gerrit.wikimedia.org/r/1084732

Change #1084732 merged by Muehlenhoff:

[operations/puppet@production] Grant access to logstash to cn=logstash-access

https://gerrit.wikimedia.org/r/1084732

For transparency: The ssotest03 user is used by myself for tests and has been temporarily added to cn=logstash-access.

Change #1088322 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Grant access to logstash to cn=logstash-access

https://gerrit.wikimedia.org/r/1088322

Change #1088322 merged by Muehlenhoff:

[operations/puppet@production] Grant access to logstash to cn=logstash-access

https://gerrit.wikimedia.org/r/1088322

Change #1115808 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] logstash: Grant access to cn=ops

https://gerrit.wikimedia.org/r/1115808

Change #1115811 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Enable logstash-access for production bitu

https://gerrit.wikimedia.org/r/1115811

Change #1115811 merged by Slyngshede:

[operations/puppet@production] Enable logstash-access for production bitu

https://gerrit.wikimedia.org/r/1115811

Change #1115808 merged by Muehlenhoff:

[operations/puppet@production] logstash: Grant access to cn=ops

https://gerrit.wikimedia.org/r/1115808

Change #1124732 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove access to logstash for cn=wmf

https://gerrit.wikimedia.org/r/1124732

Change #1124732 merged by Muehlenhoff:

[operations/puppet@production] Remove access to logstash for cn=wmf

https://gerrit.wikimedia.org/r/1124732

Status update: Access to Logstash has been split out of cn=wmf, cn=nda is next.

Change #1126008 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Add logstash-access to list of groups to drop on offboarding

https://gerrit.wikimedia.org/r/1126008

Change #1126008 merged by Muehlenhoff:

[operations/puppet@production] Add logstash-access to list of groups to drop on offboarding

https://gerrit.wikimedia.org/r/1126008

Hi folks, as part of this ticket I lost access to logstash. Can one of you please add me to the cn=logstash-access ldap group? Many thanks.

I think applying for logstash access is now done by visiting https://idm.wikimedia.org/permissions/ and filling out a short form. Hope that helps.

Thanks so much @Novem_Linguae , I confirm the link worked for me.