Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 813528 - Uploading to experimental
Summary: Uploading to experimental
Status: CONFIRMED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Other (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Infrastructure
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-09-18 07:07 UTC by Andreas K. Hüttel
Modified: 2021-10-16 11:22 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas K. Hüttel archtester gentoo-dev 2021-09-18 07:07:41 UTC
Dear Infra, 

1) please add my account dilfridge to the exp_amd64 group (on woodpecker?)

2) please add on woodpecker a service account, 
-- name, e.g., binhost-demeter or similar
-- scp / sftp / rsync only 
-- which is also part of the group exp_amd64
-- can upload to /space/experimental-local/amd64
-- and where the following key has access:

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIz9GdxPCccwEuBOoMGqzHsbFyHG5Qf19L0j1hFMtwq3 root@demeter.amd64.dev.gentoo.org

Thanks!
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-09-18 07:39:19 UTC
1) done (via puppet, so will take a minute).
Comment 2 Andreas K. Hüttel archtester gentoo-dev 2021-09-18 18:09:27 UTC
(In reply to Michał Górny from comment #1)
> 1) done (via puppet, so will take a minute).

Dunno what exactly happened, but I don't see any difference.

dilfridge@woodpecker ~ $ id
uid=2276(dilfridge) gid=100(users) groups=100(users)
Comment 3 Alec Warner (RETIRED) archtester gentoo-dev Security 2021-09-19 18:23:26 UTC
(In reply to Andreas K. Hüttel from comment #2)
> (In reply to Michał Górny from comment #1)
> > 1) done (via puppet, so will take a minute).
> 
> Dunno what exactly happened, but I don't see any difference.
> 
> dilfridge@woodpecker ~ $ id
> uid=2276(dilfridge) gid=100(users) groups=100(users)

I don't think puppet controls th ose on woodpecker (hilarious I know.)

I did it manually for now.

-A
Comment 4 Andreas K. Hüttel archtester gentoo-dev 2021-10-09 21:17:06 UTC
ping
Comment 5 Andreas K. Hüttel archtester gentoo-dev 2021-10-16 11:22:20 UTC
> 2) please add on woodpecker a service account, 
> -- name, e.g., binhost-demeter or similar
> -- scp / sftp / rsync only 
> -- which is also part of the group exp_amd64
> -- can upload to /space/experimental-local/amd64
> -- and where the following key has access:
> 
> ssh-ed25519
> AAAAC3NzaC1lZDI1NTE5AAAAIIz9GdxPCccwEuBOoMGqzHsbFyHG5Qf19L0j1hFMtwq3
> root@demeter.amd64.dev.gentoo.org

If we can find another way to upload to the experimental tree (or somewhere else on the mirrors) from demeter then I'm open to options...

I just want to keep the binhost/releng builders like demeter free of incoming connections (the only open port is SSH).
I trust myself less to keep it secure than I trust Infra to keep woodpecker and other infra servers secure.