[09:27:57] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto opened https://gitlab.wikimedia.org/repos/sre/miscweb/transparencyreport/-/merge_requ... [11:11:38] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto merged https://gitlab.wikimedia.org/repos/sre/miscweb/transparencyreport/-/merge_requ... [11:23:34] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto opened https://gitlab.wikimedia.org/repos/sre/miscweb/bienvenida/-/merge_requests/2... [11:25:06] 10GitLab (Project Migration), 10collaboration-services: Migrate SRE repositories to GitLab - operations/software - https://phabricator.wikimedia.org/T341504 (10LSobanski) [11:31:00] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto merged https://gitlab.wikimedia.org/repos/sre/miscweb/bienvenida/-/merge_requests/2... [11:44:10] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto opened https://gitlab.wikimedia.org/repos/sre/miscweb/annualreport/-/merge_requests/5... [11:48:42] 10GitLab (Pipeline Services MigrationšŸ¤), 10collaboration-services, 10Patch-For-Review: Move micro sites from Ganeti to Kubernetes and from Gerrit to GitLab - https://phabricator.wikimedia.org/T300171 (10CodeReviewBot) jelto merged https://gitlab.wikimedia.org/repos/sre/miscweb/annualreport/-/merge_requests/5... [12:23:09] 10GitLab (Auth & Access), 10CAS-SSO, 10Infrastructure-Foundations, 10SRE, and 4 others: migrate gitlab away from the CAS protocol - https://phabricator.wikimedia.org/T320390 (10SLyngshede-WMF) Depending on how the Gitlab OIDC pulls information we might have to change: userinfo_endpoint in client config opt... [14:31:28] 10GitLab (Auth & Access), 10CAS-SSO, 10Infrastructure-Foundations, 10SRE, and 4 others: migrate gitlab away from the CAS protocol - https://phabricator.wikimedia.org/T320390 (10SLyngshede-WMF) We didn't find a solution yet, but I'll spend some time looking into the CAS side of things tomorrow. [15:10:37] 10GitLab (Auth & Access), 10CAS-SSO, 10Infrastructure-Foundations, 10SRE, and 4 others: migrate gitlab away from the CAS protocol - https://phabricator.wikimedia.org/T320390 (10Arnoldokoth) @Jelto @SLyngshede-WMF I believe my login works now. I did sign in to the replica and I can see `Signed in with ope... [15:38:48] 10GitLab, 10Patch-For-Review: Add tests+linting to docpub - https://phabricator.wikimedia.org/T341225 (10CodeReviewBot) jnuche merged https://gitlab.wikimedia.org/repos/releng/docpub/-/merge_requests/3 add linting and tests to the project [15:41:40] 10GitLab, 10Patch-For-Review: Add tests+linting to docpub - https://phabricator.wikimedia.org/T341225 (10jnuche) 05Openā†’03Resolved [16:13:36] 10GitLab (Project Migration), 10collaboration-services: Migrate SRE repositories to GitLab - https://phabricator.wikimedia.org/T341468 (10LSobanski) [16:22:13] 10GitLab (Auth & Access), 10Release-Engineering-Team, 10collaboration-services, 10Patch-For-Review, 10User-brennen: Create bot to sync LDAP groups with related GitLab groups - https://phabricator.wikimedia.org/T319211 (10dancy) a:03dancy [17:34:16] 10GitLab (Integrations), 10Phabricator, 10Release-Engineering-Team: GitLab repos are not correctly mirrored to Diffusion - https://phabricator.wikimedia.org/T324151 (10Aklapper) p:05Triageā†’03Medium [19:28:04] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 4 others: Evaluate and confirm potential licensing issues for gitlab appsec pipeline tools - https://phabricator.wikimedia.org/T304737 (10sbassett) [19:29:45] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Implement an outdated modules check for golang - https://phabricator.wikimedia.org/T309997 (10sbassett) [19:34:24] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Design and Build Application Security Pipeline Components for Gitlab - https://phabricator.wikimedia.org/T289290 (10sbassett) [19:34:45] 10GitLab, 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 3 others: Create Security Team group within gitlab.wikimedia.org - https://phabricator.wikimedia.org/T289292 (10sbassett) [19:35:05] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Create initial proof of concept application security pipeline repository - https://phabricator.wikimedia.org/T289293 (10sbassett) [19:35:23] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 4 others: Migrate existing proof-of-concept node ci templates to slim node wm node docker images - https://phabricator.wikimedia.org/T294306 (10sbassett) [19:35:40] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Research and design basic ci processing scripts (to exit 1 for tools that report errors and generate report artifacts) - https://phabricator.wikimedia.org/T294307 (10sbassett) [19:36:00] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Finish node/npm initial tool ci templates for npm audit (Node 10, 12, 14) - https://phabricator.wikimedia.org/T294309 (10sbassett) [19:36:14] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Finish for node/npm initial tool ci templates for npm outdated (Node 10, 12, 14) - https://phabricator.wikimedia.org/T294310 (10sbassett) [19:40:19] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 3 others: Finish node/npm initial tool ci templates for auditjs (Node 10, 12, 14) - https://phabricator.wikimedia.org/T294311 (10sbassett) [19:40:44] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Investigate SAST template options now included with Gitlab CE and formulate use-cases and documentation - https://phabricator.wikimedia.org/T294312 (10sbassett) [19:41:09] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Add minimal yaml file linting as part of ci for security ci templates repository - https://phabricator.wikimedia.org/T294596 (10sbassett) [19:41:19] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Create a simple tool to check for bidirectional unicode characters - https://phabricator.wikimedia.org/T295333 (10sbassett) [19:41:43] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Create best practices / guidelines documentation for Gitlab application security ci templates - https://phabricator.wikimedia.org/T295374 (10sbassett) [19:41:58] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 3 others: Confirm with releng which docker images make the most sense to use - https://phabricator.wikimedia.org/T296805 (10sbassett) [19:42:20] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security, 10user-sbassett: Find optimal solution for projects with nested package.json files (within the context of Gitlab CI) - https://phabricator.wikimedia.org/T296806 (10sbassett) [19:42:41] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Create semgrep initial tool ci template - https://phabricator.wikimedia.org/T297991 (10sbassett) [19:42:50] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security, 10user-sbassett: Create local-php-security-checker/php-security-checker ci yaml template - https://phabricator.wikimedia.org/T301828 (10sbassett) [19:43:00] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10SecTeam-Processed, 10Security: Create composer outdated ci yaml template - https://phabricator.wikimedia.org/T301829 (10sbassett) [19:43:29] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10SecTeam-Processed, and 2 others: Create safety (w/ poetry support) ci yaml template - https://phabricator.wikimedia.org/T301830 (10sbassett) [19:43:40] 10Gitlab-Application-Security-Pipeline, 10Release-Engineering-Team, 10Security Team AppSec, 10Security-Team, and 2 others: Create nancy ci yaml template - https://phabricator.wikimedia.org/T301831 (10sbassett) [19:43:46] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10SecTeam-Processed, and 2 others: Create phan/phan-taint-check plugin port as ci template - https://phabricator.wikimedia.org/T301832 (10sbassett) [19:44:33] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10SecTeam-Processed, and 2 others: Create python bandit ci template - https://phabricator.wikimedia.org/T301833 (10sbassett) [19:44:48] 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10SecTeam-Processed, 10Security: Create gosec ci yaml template - https://phabricator.wikimedia.org/T301834 (10sbassett) [19:45:03] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Merge templates that are part of initial release to production branch - https://phabricator.wikimedia.org/T303482 (10sbassett) [19:46:43] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Research best ways to pass certain credentials to external services within application security-related ci templates - https://phabricator.wikimedia.org/T295508 (10sbassett) 05Openā†’... [19:46:47] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Design and Build Application Security Pipeline Components for Gitlab - https://phabricator.wikimedia.org/T289290 (10sbassett) [19:47:44] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Design and Build Application Security Pipeline Components for Gitlab - https://phabricator.wikimedia.org/T289290 (10sbassett) [19:48:21] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Better support branches and add support for mw core to the phan-taint-check gitlab appsec template - https://phabricator.wikimedia.org/T305083 (10sbassett) [19:48:37] 10Gitlab-Application-Security-Pipeline, 10Security Risk Management, 10Security Team AppSec, 10Security-Team, and 2 others: Create Risk Rating Calculator for Security Reviews / Gitlab AppSec CI - https://phabricator.wikimedia.org/T293138 (10sbassett) [19:49:31] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Support conda environments with a new gitlab appsec ci template - https://phabricator.wikimedia.org/T305732 (10sbassett) [19:49:44] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, 10Security: Create osv.dev ci includes - https://phabricator.wikimedia.org/T307514 (10sbassett) [19:50:08] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 3 others: Write a phame / tech blog post detailing the appsec pipeline, as it currently exists - https://phabricator.wikimedia.org/T307517 (10sbassett) [19:50:16] 10GitLab (CI & Job Runners), 10Gitlab-Application-Security-Pipeline, 10Security Team AppSec, 10Security-Team, and 2 others: Investigate container scanning options within the context of the Gitlab appsec pipeline - https://phabricator.wikimedia.org/T307523 (10sbassett) [22:52:53] I am quitting IRC until end of October, then I will be back. cya [23:26:33] 10GitLab, 10Patch-For-Review, 10Release-Engineering-Team (Priority Backlog šŸ“„): WMCS GitLab runners running frequently running out of disk space - https://phabricator.wikimedia.org/T340887 (10dduvall) I'm still unable to repro this issue locally, and according to upstream the ref counting is solely in memory...