Page MenuHomePhabricator

Requesting access to analytics-privatedata-users for BGerdemann_(WMF)
Open, In Progress, HighPublicRequest

Description

Requestor provided information and prerequisites

Complete ALL items below as the individual person who is requesting access:

  • Wikimedia developer account username: bgwiki
  • Email address: bgerdemann@wikimedia.org
  • SSH public key (must be a separate key from Wikimedia cloud SSH access): ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJsjWB2dshlaxCaUyAqSpLXdUQLvadC0xeFH06ZO4llL (separate from WM cloud SSH access)
  • Requested group membership: analytics-privatedata-users — Level 2 access
  • Reason for access: I need analytics-privatedata-users Level 2 to use the Wikimedia Data Platform’s Jupyter environment to identify users who meet defined editing criteria for approved user-experience research studies. I will follow Wikimedia’s data-access, privacy, retention, and data-publication requirements and will limit my access and outputs to the minimum information necessary for the approved research work.
  • Name of approving party (manager for WMF/WMDE staff): Debra Kumar (or Leila Zia in her absence)
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: Signed and affirmed
  • Please coordinate obtaining a comment of approval on this task from the approving party: I will ask Debra and Leila for one of their approvals. Debra is currently OOO and Leila is on her way out, so whoever gets to it first.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: developer account username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - The provided SSH key has been confirmed out of band and is verified not being used in WMCS.
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

@leila or @DKumar-WMF, could one of you please review and comment with your approval of this Level 3 analytics-privatedata-users access request? This access will allow me to run a template query developed by Megan to identify eligible participants and streamline recruitment for our research studies. More context here.

Wikimedia developer account username: BGerdemann_(WMF)

That might be incorrect per https://ldap.toolforge.org/user/bgwiki ?

thanks @Aklapper. I put my wikitech account username but clearly wasn't sure which username was needed.

@Bethany happy to help here. A couple of questions:

  • Can you confirm that you have read https://phabricator.wikimedia.org/L3 and agree to its terms? (You may have already signed this form, but I don't have access to it and want to make sure you're aware of the details there.) Please pay special attention to the "Handling sensitive data" section.
  • Why do you need Level 3 access compared to Level 2? If you will need to use Hadoop, please explain briefly why.

@leila , I signed the L3 Wikimedia Server Access Responsibilities document on July 11, 2022, at 9:11 p.m., and I reaffirm my acceptance of those responsibilities.

The queries will be conducted in partnership with Product Analytics (PA), ensuring that another staff member reviews and approves them. As an additional guardrail, the required data deletion is also incorporated into our standard project closeout process.

I am narrowing my request to Level 2 and updating the ticket description accordingly. Because this particular workflow uses MariaDB only and does not use Hadoop, Presto, Hive, or Spark, Level 2 is the appropriate scope for the time being. I'll come back with a Level 3 request when necessary, but at this time please treat this as a Level 2 request.

.. https://phabricator.wikimedia.org/L3 and agree to its terms? (You may have already signed this form, but I don't have access to it

I can confirm this has been signed back in 2022. Well, a previous version of it to be precise. But seems ok to me.

@Bethany and @Dzahn: thank you.

I approve bgwiki's request for Level 2 access to analytics-privatedata-users. Thank you.

Arnoldokoth changed the task status from Open to In Progress.Wed, Aug 5, 5:31 PM
Arnoldokoth updated the task description. (Show Details)

@Bethany @leila

Thanks as well! We were about to close this ticket out and verify that last open checkbox and then noticed it seems like:

You already have the access you are requesting here.

You are requesting level 2 analytics-privatedata-users and we are seeing an existing user bgwiki with group membership in analytics-privatedata-users that also has an SSH key, which would make it that "level 2".

So yea, it seems like this should be resolved as already existing / working.

oooh! I see now in the ticket body it says "level 2" but in the first comment of @Bethany it then refers to "level 3"! is that what confused us? Is this a request to "level up" from 2 to 3? (cc: @Arnoldokoth @leila )

jcrespo subscribed.

@Bethany could you provide feedback to @Dzahn 's latest comment? If level 3 is required, could you update the original request accordingly? Thank you.

jcrespo triaged this task as High priority.Fri, Aug 7, 12:29 PM