Requestor provided information and prerequisites
Complete ALL items below as the individual person who is requesting access:
- Wikimedia developer account username: Chlod Alejandro (https://ldap.toolforge.org/user/chlod)
- Email address: chlod@chlod.net
- SSH public key (must be a separate key from Wikimedia cloud SSH access): sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIAvK3hOUrrqsf8T7nvO11PtB4kWxJo/DENeGZUyVkjFpAAAADXNzaDp3aWtpbWVkaWE= Chlod Alejandro - Primary Yubikey + Wikimedia production, sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIJi0fJ9sj8LIj6h94QiQJhIiIkHT7G2Xoqzwn8b2IWxAAAAADXNzaDp3aWtpbWVkaWE= Chlod Alejandro - Backup Yubikey + Wikimedia production
- Requested group membership: deployment (access to LDAP groups spiderpig-access and [logstash-access or nda] would also be great but I can request this separately in IDM if needed)
- Reason for access: Mainly for helping out on backport windows (particularly the underappreciated UTC morning window; it happens in the afternoon for my timezone so it's perfectly within my strike zone) and also to deploy my own patches (mostly ops/mediawiki-config changes). Spiderpig access is for making my life easier with low-risk config changes. NDA/Logstash access is for debugging production errors which may be related to ongoing extension/core work that I'm doing (and potentially also gadget/user script work, as I believe client-side JS errors also get sent to Logstash per T226986).
- Name of approving party (manager for WMF/WMDE staff): @jsn.sherman
- Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: just signed it ;)
- Please coordinate obtaining a comment of approval on this task from the approving party.
SRE Clinic Duty Confirmation Checklist for Access Requests
This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.
This section is to be confirmed and completed by a member of the SRE team.
- - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
- - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
- - User has provided the following: developer account username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
- - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
- - The provided SSH key has been confirmed out of band and is verified not being used in WMCS.
- - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
- - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml
For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access