This workboard represents access requests for LDAP groups, including the ldap/wmf group which controls access in Gerrit, Logstash, and various other developer tools.
Please include:
- Username: (The user name used on Wikitech.)
- Shell access: Yes/No (Whether you currently have shell access).
- Purpose: (Specify which service you need to get access to, e.g. Icinga, Grafana, Superset etc).
- Group: (The specific group you want to be added to - optional).
- Contract end date: End date of contract (Contractors only)
- Contract contact: Contact person for the contractor (Contractors only)
Refer to https://wikitech.wikimedia.org/wiki/LDAP/Groups for documentation on what each LDAP group is for.
How to create a LDAP account?
- Make sure you have an LDAP account (aka "Wikimedia Developer" account). If you can login at https://idm.wikimedia.org or https://gerrit.wikimedia.org, then you have an LDAP account. If not, then create your LDAP account via idm.wikimedia.org.
For LDAP admins only, how to process a request?
- Check and follow https://wikitech.wikimedia.org/wiki/SRE/Clinic_Duty/Access_requests#LDAP_access
- Note that LDAP flags can only be added to users who are listed in the admin/data.yaml file in Puppet. This is for auditing purposes. This basically means that for a user to gain access to one or more restricted LDAP groups, there is a paper trail managed by SRE with a Git commit recording that the user has signed the relevant NDAs or other documents.