Page MenuHomePhabricator

Requesting access to deployment for Chlod Alejandro
Closed, ResolvedPublicRequest

Description

Requestor provided information and prerequisites

Complete ALL items below as the individual person who is requesting access:

  • Wikimedia developer account username: Chlod Alejandro (https://ldap.toolforge.org/user/chlod)
  • Email address: chlod@chlod.net
  • SSH public key (must be a separate key from Wikimedia cloud SSH access): sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIAvK3hOUrrqsf8T7nvO11PtB4kWxJo/DENeGZUyVkjFpAAAADXNzaDp3aWtpbWVkaWE= Chlod Alejandro - Primary Yubikey + Wikimedia production, sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIJi0fJ9sj8LIj6h94QiQJhIiIkHT7G2Xoqzwn8b2IWxAAAAADXNzaDp3aWtpbWVkaWE= Chlod Alejandro - Backup Yubikey + Wikimedia production
  • Requested group membership: deployment (access to LDAP groups spiderpig-access and [logstash-access or nda] would also be great but I can request this separately in IDM if needed)
  • Reason for access: Mainly for helping out on backport windows (particularly the underappreciated UTC morning window; it happens in the afternoon for my timezone so it's perfectly within my strike zone) and also to deploy my own patches (mostly ops/mediawiki-config changes). Spiderpig access is for making my life easier with low-risk config changes. NDA/Logstash access is for debugging production errors which may be related to ongoing extension/core work that I'm doing (and potentially also gadget/user script work, as I believe client-side JS errors also get sent to Logstash per T226986).
  • Name of approving party (manager for WMF/WMDE staff): @jsn.sherman
  • Ensure you have signed the L3 Wikimedia Server Access Responsibilities document: just signed it ;)
  • Please coordinate obtaining a comment of approval on this task from the approving party.

SRE Clinic Duty Confirmation Checklist for Access Requests

This checklist should be used on all access requests to ensure that all steps are covered, including expansion to existing access. Please double check the step has been completed before checking it off.

This section is to be confirmed and completed by a member of the SRE team.

  • - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
  • - User has a valid NDA on file with WMF legal. (All WMF Staff/Contractor hiring are covered by NDA. Other users can be validated via the NDA tracking sheet)
  • - User has provided the following: developer account username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform)
  • - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not shared with any other service (this includes not sharing with WMCS access, no shared keys.)
  • - The provided SSH key has been confirmed out of band and is verified not being used in WMCS.
  • - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
  • - access request (or expansion) has sign off of group approver indicated by the approval field in data.yaml

For additional details regarding access request requirements, please see https://wikitech.wikimedia.org/wiki/Requesting_shell_access

Event Timeline

@Chlod is a solid technical contributor who has demonstrated good judgement in the time we have known each other. Exactly the kind of human you want to have on hand for backports and troubleshooting. Let's do this!

Arnoldokoth changed the task status from Open to In Progress.Aug 5 2026, 8:59 AM
Arnoldokoth updated the task description. (Show Details)

Hi all, I don't have an NDA on file, so I will process one and confirm when it's complete. Thanks!

@dancy This request would also need approval from the group approver for deployment which lists you and Tyler.

@dancy This request would also need approval from the group approver for deployment which lists you and Tyler.

Approved.

Dzahn updated the task description. (Show Details)

@Chlod while NDA approval is ongoing, do you mind generating a new gerrit PR (I believe it won't be hard for you) on the operations/puppet repo, path production/modules/admin/data/data.yaml , with your public production SSH key adding yourself at the end of the users yaml key, here: https://gerrit.wikimedia.org/r/plugins/gitiles/operations/puppet/+/refs/heads/production/modules/admin/data/data.yaml#7326

It doesn't have to be a correct PR- I will just take over its amends and deployment: just an out of band transmission of the key through gerrit (like our checklist requires), which in your case I think you won't find complicated. But we can agree on other methods if that's unwanted.

Change #1322077 had a related patch set uploaded (by Chlod Alejandro; author: Chlod Alejandro):

[operations/puppet@production] admin: add shell and key for chlod

https://gerrit.wikimedia.org/r/1322077

^ Done! I've also added an SSH key for my backup Yubikey. If additional permission is needed for that or if that's something that should only be done in the future, please feel free to take it off (and I'll invalidate it locally just in case). Thanks!

Hello all, the NDA is out for signatures. I'll confirm when it's complete. Thanks!

^ Done! I've also added an SSH key for my backup Yubikey. If additional permission is needed for that or if that's something that should only be done in the future, please feel free to take it off (and I'll invalidate it locally just in case). Thanks!

Hi, thanks, reviewing now. Would you mind adding your yubikey to the request here. That way we can consider it verified out of band, as the checklist requires (trasmitted using both Phabricator and your developer account).

As you can see in the amended PR, you will be provided deployment rights, which includes some spiderpig rights. After access is approved you will be able to ask for more rights, if those are not enough, but deployment is what is approved by the service owner for now.

jcrespo triaged this task as High priority.

This is blocked right now on getting legal confirmation that an NDA has been signed.

As you can see in the amended PR, you will be provided deployment rights, which includes some spiderpig rights. After access is approved you will be able to ask for more rights, if those are not enough, but deployment is what is approved by the service owner for now.

Gotcha, thanks!

This is blocked right now on getting legal confirmation that an NDA has been signed.

I've signed the NDA, though Docusign tells me it's still awaiting signatures on the WMF's side.

Hi all, I'm waiting on legal counsel. I'll ping him again.

Hi all, the NDA is complete! Thanks!

Change #1322077 merged by Jcrespo:

[operations/puppet@production] admin: Add chlod to production access and deployment rights

https://gerrit.wikimedia.org/r/1322077

Access and deployment rights, toghether with LDAP nda grants have been deployed. It can take up to 30 minutes to propagate to all. Please follow https://wikitech.wikimedia.org/wiki/SRE/Production_access#Setting_up_your_access to setup your production access and confirm everything is ok. Please you can also reopen this ticket or contact the person on clinic duty to ask further questions or get help.

Thank you, @jcrespo! Can confirm that I'm able to connect to the bastion and deployment hosts. Per https://wikitech.wikimedia.org/wiki/How_to_deploy_code#Deployment_requirements I've sent a request to join the ops@ mailing list and would also appreciate it if I were added into the wmf-deployment Gerrit group.

I added you myself to the last group, as well as the WMF-NDA group here on phabricator, but please sync with release engineering team for coordination, on this ticket we SRE only handle the server access, ultimately they decide and coordinate everything related to deployment.