Closed Bug 1588010 Opened 6 years ago Closed 6 years ago

Logging into staging taskcluster does not grant roles associated to mozilla-groups et al

Categories

(Cloud Services :: Operations: Taskcluster, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: tomprince, Assigned: edunham)

References

Details

On taskcluster.net, I get various scopes associated to groups like assume:mozilla-group:releng. I'd expect this to happen on staging as well, and it isn't currently happening.

Flags: needinfo?(helfi92)

The mozilla auth0 client being used for the staging site doesn't seem to be authorized to access that kind of information. We should probably ask someone from the IAM team to update the client with the necessary permissions.

Flags: needinfo?(helfi92)

We should add something to the deployment docs about it, too.

Hassan, can you update the docs with the right thing to ask, and then cloudops can ask it?

Flags: needinfo?(helfi92)

Awesome. @edunham, can you update the request or otherwise coordinate with jabba / IAM folks to set up the permissions mentioned in that PR?

Component: General → Operations: Taskcluster
Flags: needinfo?(edunham)
Product: Taskcluster → Cloud Services
Assignee: nobody → edunham

I worked with Jabba on this yesterday and I think the auth0 settings there now match the FirefoxCI cluster. Could you test to see if this is still an issue please?

This still appears to be problem. When I log in to staging and look at https://stage.taskcluster.nonprod.cloudops.mozgcp.net/profile I see just an assume:login-identity:... scope. When I log in to firefox-ci and look at https://firefox-ci-tc.services.mozilla.com/profile I see a bunch of assume:mozilla-group:... scopes, corresponding to the non hris_ prefixed groups on https://sso.mozilla.com/info.

Seems to work now.

Status: NEW → RESOLVED
Closed: 6 years ago
Flags: needinfo?(edunham)
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.