Page MenuHomePhabricator

Requesting access to deployment for rscout
Closed, ResolvedPublicRequest

Description

Requestor provided information and prerequisites

Complete ALL items below as the individual person who is requesting access:

  • Wikimedia developer account username: rscout
  • Email address: rscout@wikimedia.org
  • SSH public key (must be a separate key from Wikimedia cloud SSH access):

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFcXq6WtYnmdoT3NVZLDw4irvQaOKSWLtVGE5FAIQhxC rscout+production@wikimedia.org

  • Requested group membership: deployment
  • Reason for access: new security engineering hire
  • Name of approving party (manager for WMF/WMDE staff): Riku Silvola
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: Signed 2026-06-26
  • Please coordinate obtaining a comment of approval on this task from the approving party.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: developer account username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - The provided SSH key has been confirmed out of band and is verified not being used in WMCS.
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

Rscout renamed this task from Requesting access to <ENTER RESOURCE NAME> for <ENTER YOUR USERNAME> to Requesting access to production for RScout-WMF.Jun 29 2026, 9:30 PM
Rscout renamed this task from Requesting access to production for RScout-WMF to Requesting access to production for rscout.
Rscout updated the task description. (Show Details)
Dzahn renamed this task from Requesting access to production for rscout to Requesting access to deployment for rscout.Jun 29 2026, 10:19 PM
Dzahn added subscribers: thcipriani, Dzahn.

@thcipriani hello, please take a look

Dzahn changed the task status from Open to In Progress.Jun 29 2026, 10:20 PM

@thcipriani hello, please take a look

Approved. @Rscout if you need access to our web deploy tool (as opposed to only doing deployments on the command line), you'll also want these bits:

  • Our web deploy tool SpiderPig also requires you request membership in the spiderpig-access group in Bitu/IDM
    • Once requested, I can approve there and then you should be able to login to the web interface.
    • For clarity, both deployment group membership and spiderpig-access are needed to access the web interface.
  • Ensure you've joined the ops-l mailing list – announcements impacting deployers are often sent there.

Thanks!

Change #1306500 had a related patch set uploaded (by Filippo Giunchedi; author: Filippo Giunchedi):

[operations/puppet@production] admin: add rscout to deployment group

https://gerrit.wikimedia.org/r/1306500

@Rscout we need to verify your ssh key out of band, please let me know when it would be a good time for a quick google meet. feel also free to send a meeting invite my way: fgiunchedi@wikimedia.org

Approving as Randall's manager.

Change #1306500 merged by Filippo Giunchedi:

[operations/puppet@production] admin: add rscout to deployment group

https://gerrit.wikimedia.org/r/1306500

fgiunchedi claimed this task.
fgiunchedi updated the task description. (Show Details)

All steps done, I'm tentatively resolving though @Rscout please reach out and reopen if something is amiss