Page MenuHomePhabricator

Requesting access to phabricator-admin for urbanecm
Closed, ResolvedPublicRequest

Description

Requestor provided information and prerequisites

Complete ALL items below as the individual person who is requesting access:

  • Wikimedia developer account username: urbanecm
  • Email address: murbanec@wikimedia.org (listed in LDAP), martin.urbanec@wikimedia.cz (personal address)
  • SSH public key (must be a separate key from Wikimedia cloud SSH access): listed in Puppet
  • Requested group membership: phabricator-admin
  • Reason for access: (a) for workboard organizing purposes, it would be useful to silence notifications for bulk actions (Growth-Team is currently restructuring its boards a lot, which includes a lot of tag-changes, which would be nicer in silence-mode) (b) as a Steward, I occasionally receive 2FA resets reqs, which include Phabricator; so far, I've been connecting people, but I consider it useful to have the ability (I'm familiar with the process page, as well as procedures used on-SUL); I've had a brief discussion about both use-cases with @thcipriani beforehand.
  • Name of approving party (manager for WMF/WMDE staff): @DMburugu (as my manager@WMF), @thcipriani (as group approver)
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: signed
  • Please coordinate obtaining a comment of approval on this task from the approving party.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: developer account username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - The provided SSH key has been confirmed out of band and is verified not being used in WMCS.
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

As noted in the description, @Urbanecm and I chatted, the rationale for access looks good to me. I approve!

Raine updated the task description. (Show Details)
Raine subscribed.

@DMburugu can you please approve this? Thanks!

Change #1198340 had a related patch set uploaded (by Kamila Součková; author: Kamila Součková):

[operations/puppet@production] admin: add urbanecm to phabricator-admins

https://gerrit.wikimedia.org/r/1198340

Change #1198340 merged by Dzahn:

[operations/puppet@production] admin: add urbanecm to phabricator-admins

https://gerrit.wikimedia.org/r/1198340

@Urbanecm You have access to phab1004.eqiad.wmnet (currently active) and phab2002.codfw.wmnet (currently failover) now.

This also made puppet drop a .my.cnf in your new home dir. for mysql access. Please use carefully. Cheers