Page MenuHomePhabricator

Create service account user for OpenTofu automation
Closed, ResolvedPublic

Description

Create a "ZuulDevOpsBot" service account to run tofu for the zuul Cloud VPS project.

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
  • Created ZuulDevOpsBot Developer account using idp.wikimedia.org
  • Created ZuulDevOpsBot SUL account using meta.wikimedia.org
  • Added ZuulDevOpsBot Developer account as a member+reader for the zuul project via Horizon
  • Created OpenStack credentials for ZuulDevOpsBot via Horizon.
    • NOTE: Application credentials need to include the "Unrestricted (dangerous)" permission or things will blow up when Magnum tries to create a service account related to the cluster (T372365#10063201)
  • Created ec2 credentials for S3 gateway
bd808 changed the task status from Open to In Progress.Jun 13 2025, 10:24 PM
bd808 triaged this task as Medium priority.
bd808 added a subscriber: thcipriani.

Many of these creds will end up in the GitLab project's CI secrets. @thcipriani is getting me access to the Release-Engineering-Team's 1Password vault so I can stick a copy in there too.

Credentials added to Release Engineering 1password vault as:

  • ZuulDevOpsBot Developer account
  • ZuulDevOpsBot SUL account
  • ZuulDevOpsBot OpenStack API credentials
  • ZuulDevOpsBot AWS/ec2 credentials