[13:32:27] hi o11y, wanted to pint out the following https://phabricator.wikimedia.org/T286716#7224351. tl;dr the cloud idp service now proxies authentication to the production idp services so no need to create a local account on idp01 [13:34:40] Thanks [13:35:02] I’ll add it to our things to chat about in our upcoming team meet [13:36:55] lmata: ack sounds good, im not sure how much its used but i know godog was playing with it a bit [13:46:33] jbond: that's super cool and useful, thank you! [13:46:46] definitely a plus not to have to setup users [13:48:01] mmhh I'm getting unauthorized messages when trying to browse e.g. https://alerts.monitoring.wmflabs.org/ [13:48:27] unless there's something to update on the cloud idp client's end ? [13:49:39] godog: looks like the authentication all went through and something in apache dosn;t like it, what is the actuall server? [13:50:08] godog: i suspect its the required_groups bit [13:50:21] it probably refrences the labs ldap ou instead of production [13:50:33] jbond: ah yeah that makes sense, the host is pontoon-icinga-01.monitoring.eqiad1.wikimedia.cloud [13:55:18] godog: yes its the require lin " Require cas-attribute memberOf:cn=ops,ou=groups,dc=sso,dc=eqiad1,dc=wikimedia,dc=cloud [13:55:29] cant find where its configuered for theses boxes though [13:56:24] jbond: it is in pontoon, I'll send a review to change the base-dn [13:56:34] ack cher [13:56:36] rcheers [13:57:25] actually nevermind no need for a review, I changed it locally [13:57:32] cool [13:57:32] I'll test with the default value [14:00:37] jbond: all good! thanks again, now https://alerts.monitoring.wmflabs.org/ works as expected with my production token [14:02:04] awesome :) \o/, thanks [14:07:43] \o/