Closed Bug 1852853 Opened 2 years ago Closed 2 years ago

Request to install dbt app in MozillaSocial

Categories

(mozilla.org :: Github: Administration, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: cknowles, Assigned: cknowles)

References

Details

User Kenny Long has requested that the app dbt cloud be installed in the repo MozillaSocial/mozillasocial-dbt

The app requests the following permissions:
Read access to metadata
Read and write access to checks, code, commit statuses, pull requests, repository hooks, and workflows

dbt-cloud is not in the list of pre-approved apps here

Hal, Austin, please advise

Flags: needinfo?(hwine)
Flags: needinfo?(asargent)

:klong -- the RRA for DBT doesn't cover any modification by DBT of the code, but the app requires permission to modify a lot of stuff. That makes me suspect that the GitHub app is a separate SaaS offering from our prior use of DBT. (I.e. it's working on code, not data.)

Please open an RRA request for the DBT GitHub app, and we can go from there.

Flags: needinfo?(klong)
Flags: needinfo?(hwine)
Flags: needinfo?(asargent)
Flags: needinfo?(klong) → needinfo?(breyes)

(In reply to Hal Wine [:hwine] (use NI) from comment #1)

:klong -- the RRA for DBT doesn't cover any modification by DBT of the code, but the app requires permission to modify a lot of stuff. That makes me suspect that the GitHub app is a separate SaaS offering from our prior use of DBT. (I.e. it's working on code, not data.)

Please open an RRA request for the DBT GitHub app, and we can go from there.

:hwine Does this new RRA new to apply to dbt Cloud connecting to BigQuery to running queries or does the original one cover the concept of 3rd party connection to the Data Warehouse? The write access needed to github is to allow developers at Mozilla the ability to use the dbt Cloud IDE for data model development. The IDE can then commit changes and push to a branch in Github (not main), which can then be merged via PR. Should the RRA be scoped to just that?

Flags: needinfo?(breyes)

Setting NI for Hal to answer comment 2

Flags: needinfo?(hwine)

(In reply to Braun Reyes from comment #2)

Should the RRA be scoped to just that?

Maybe? For sure:

  • an RRA for the GitHub app's access to code is required
  • I don't see mention of the IDE access in the current RRA for DBT. Usually we would cover that, so I don't know if it's an oversight from the original RRA or functionality added since then. Or maybe even because I'm unfamiliar with the world of datalakes, etc.!

To move things along, I'd suggest requesting the RRA for the GitHub app. That RRA will trigger any questions about the original RRA, if needed. (It might be that the original RRA just needs some clarification for folks like me.)

The use case you mention in comment 5 will be good material for the RRA -- that sounds like what might we might end up recommending 😉

Flags: needinfo?(hwine) → needinfo?(cknowles)
Flags: needinfo?(cknowles) → needinfo?(klong)
Flags: needinfo?(breyes)

hey folks,

Just opened a RRA for DBT (for MozSocial): https://bugzilla.mozilla.org/show_bug.cgi?id=1854015

Let me know if there are any questions

Thanks!

:gkatre please comment on this ticket that you are taking over the process from me.

That way we have clear ownership documented.

Thanks

-Braun

Flags: needinfo?(klong)
Flags: needinfo?(gkatre)
Flags: needinfo?(breyes)

Thanks Braun Reyes!

I will be taking over this request for installing DBT cloud for MozSocial.

Flags: needinfo?(gkatre)
Duplicate of this bug: 1857374

Hi :cknowles, the RRA for dbt has been completed successfully and we should be able proceed with the github repo (MozillaSocial/mozillasocial-dbt) integration with dbt Cloud.
The process for connecting the github repo to dbt Cloud is explained here: https://docs.getdbt.com/docs/cloud/git/connect-github
Thanks!

Looking at the RRA, there's a recommendation "Restrict table access and the allowed actions for the DBT user" - I've asked Stephanie if this is a blocking concern - once we have word regarding that, we can enable the app.

As to the install -

As owner of the org, I can approved the app's installation, and its ability to access the repo in question - a repo admin should be able to log into dbt cloud and complete the installation. (This is preferred, as oauth sessions can bring any elevated permissions with them, and as owner of all the orgs, I've got pretty elevated permissions.)

(In reply to Chris Knowles [:cknowles] from comment #10)

Looking at the RRA, there's a recommendation "Restrict table access and the allowed actions for the DBT user" - I've asked Stephanie if this is a blocking concern - once we have word regarding that, we can enable the app.

As to the install -

As owner of the org, I can approved the app's installation, and its ability to access the repo in question - a repo admin should be able to log into dbt cloud and complete the installation. (This is preferred, as oauth sessions can bring any elevated permissions with them, and as owner of all the orgs, I've got pretty elevated permissions.)

Thanks :cknowles !
I can add you as a admin user to dbt Cloud, for you to be able to log into the app.

Again, as my account has significantly elevated permissions, I'd really rather one of the existing repo admins try the setup steps after we've enabled the app for GitHub. If that simply won't work, we can work with a temp org user to get things going. But that will require coordination between several teams to get things working - so let's try the easy steps first.

Once we have word from Stephanie, I'll update here, and we can figure out next steps.

Alright, I've approved the app for the repo from the GitHub side - please have a repo admin see if they can setup the app from the DBT cloud side, and let me know if there's any concerns.

Flags: needinfo?(gkatre)

(In reply to Chris Knowles [:cknowles] from comment #13)

Alright, I've approved the app for the repo from the GitHub side - please have a repo admin see if they can setup the app from the DBT cloud side, and let me know if there's any concerns.

Thanks for reviewing the RRA and for the approval!

I was able to setup the integration with the GitHub repo.

Flags: needinfo?(gkatre)

Great, good to hear.

Assignee: nobody → cknowles
Status: NEW → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.