Re: Additional account with read DB access

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 3 Feb 2016 22:16:12 +0100
Pierre-Yves Chibon <pingou@xxxxxxxxxxxx> wrote:

> On Wed, Feb 03, 2016 at 05:59:31PM +0100, Aurelien Bompard wrote:
> >    Hey folks,
> > 
> >    Matt would like read access on HyperKitty's production database
> > to collect some statistics[1], and I wondered if we have a
> > procedure for this kind of request.
> > 
> >    [1] https://fedorahosted.org/fedora-infrastructure/ticket/5070
> > 
> >    Should it be done via a script that would be stored in our
> > ansible repo? I'm pretty sure I don't have the permissions to touch
> > the private repo though. If it's the right way, who should I ping
> > about that?  
> 
> How sensible is the data stored in the DB? Too much to be made public?

Yeah, I wondered the same. Could we sanatize any user auth/account data
and just make the raw posts of all the public lists available?

> Otherwise if it's for a one-off we could see to either let one of
> sysadmin-main run the script or provide a DB dump to one person but I
> guess this isn't quite sustainable if it's a regular script to run.
> IIRC, so far I think somone in sysadmin-main ran the script when
> needed.

Yeah, we have never allowed external db access before, and I don't
really like the idea now. ;( 

We do have a process for database dumps... they have to get 2 +1's from
sysadmin-main folks and get dumped out by one of them and given to the
person. So we could do that short term.

kevin

Attachment: pgpxcMPBYjXG5.pgp
Description: OpenPGP digital signature

_______________________________________________
infrastructure mailing list
infrastructure@xxxxxxxxxxxxxxxxxxxxxxx
http://lists.fedoraproject.org/admin/lists/infrastructure@xxxxxxxxxxxxxxxxxxxxxxx

[Index of Archives]     [Fedora Development]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]

  Powered by Linux