[volunteers] (forw) Re: [svlug] [svlug-announce] (forw) Re: Resubscribing to the SVLUG List
Rick Moen
rick at linuxmafia.com
Mon Oct 31 20:10:50 PST 2016
Forwarding w/o the attachments.
----- Forwarded message from Rick Moen <rick at linuxmafia.com> -----
Date: Mon, 31 Oct 2016 20:48:19 -0700
From: Rick Moen <rick at linuxmafia.com>
To: Ivan Sergio Borgonovo <mail at webthatworks.it>
Subject: Re: [svlug] [svlug-announce] (forw) Re: [volunteers] Resubscribing
to the SVLUG List
Organization: If you lived here, you'd be $HOME already.
Quoting Ivan Sergio Borgonovo (mail at webthatworks.it):
> Then I'll give a look to the volunteers@ archives and get an idea
> about the problems you generally have to face to see if I can
> actually be of help.
Yeah, I understand the problem of not knowing how to help or what you
can reasonably do.
http://www.svlug.org/teams/web-team.php has a significant amount
(reachable from the front page or any other SVLUG Web page via Navbar ->
About Us -> Projects -> SVLUG Web Team). Looks like it's complete and
correct concerning www.svlug.org, the virthost at Linode. I notice now
that it says very little about lists.svlug.org, the virthost at
prgmr.com , which is a flaw that ideally someone, some time, would fix.
(That is not a suggestion to you, just an observation.)
Some process documentation is in the site-docs directory on
www.svlug.org. Here is a dir display of that directory:
rick at gruyere:~/site-docs$ ls -al
total 104
drwxrwsr-x 3 www-data www-data 4096 Oct 31 20:05 .
drwxrwsr-x 3 root staff 4096 Apr 30 2016 ..
-rw-rw-r-- 1 www-data www-data 24752 Sep 14 19:25 ChangeLog
lrwxrwxrwx 1 www-data www-data 15 Mar 31 2011 SENSITIVE-DATA-DIRECTORY -> /root/sensitive
-rw-rw-r-- 1 www-data www-data 176 May 3 17:23 TODO
lrwxrwxrwx 1 www-data www-data 19 May 27 2015 lists.svlug.org-documentation -> svlug.xen.prgrm.com
-rw-rw-r-- 1 www-data www-data 2218 Nov 12 2013 new-user
-rw-rw-r-- 1 www-data www-data 7835 Sep 14 19:22 nsd-instructions
drwxrwsr-x 2 www-data www-data 4096 May 2 2016 obsolete
-rw-rw-r-- 1 www-data www-data 5359 May 2 2016 package-operations
-rw-r--r-- 1 www-data www-data 2749 Oct 9 21:42 possible-venue
-rw-rw-r-- 1 www-data www-data 519 Oct 1 2015 socialnet-info
-rw-rw-r-- 1 www-data www-data 6819 Dec 24 2015 svlug.xen.prgmr.com
-rw-rw-r-- 1 www-data www-data 4413 May 2 2016 svn-instructions
-rw-rw-r-- 1 www-data www-data 13509 Oct 6 02:26 symantec-site-contact
rick at gruyere:~/site-docs$
> Before you give me root access is there anything you could send me to
> get an idea of the things I may have to do and see if I can hold them?
> eg, the Changelog?
All of those files are now attached, not including the root-owned files
in SENSITIVE-DATA-DIRECTORY. It's perhaps a little excessive, but a
couple of bits of information such as the Linode customer account
credentials for the Linode Web-administrative controls, root password of
lists.svlug.org and the domain registrar credentials for SVLUG's domains
are deemed so private that we need to keep them in a root-only-readable
directory with permissions 0600, so not just _any_ shell user can get to
them. This is excessive at the moment because all shell users on
www.svlug.org also have root shell via sudo, but in theory there could
in the future be shell users who don't.
The intention about site-docs is that it should ideally _not_ contain
anything that would be better relocated to a public Web page, because
it's been our long and painful experience that excessive secrecy and
hypercontrol are harmful to the user group. Anything that can be made
fully public, should be. Ideally, site-docs is limited to information
with at least some privacy or security sensitivity. (I say 'ideally'
because I'm not sure some present contents shouldn't be moved to the
Web.)
> I'll do my best, but I hate the menial part of thinking. Realizing
> you made a mistake is the interesting part, cleaning up is boring
> and stressing.
But if you need to fix someone _else's_ mistake -- or find a mistake
that might exist or might not, you absolutely need an accurate and
sufficient description of exactly what got done, one exactly accurate
enough to revert the change. This seems to be the key concept that some
folks don't internalise, causing me large amounts of problems when it
turns out the person screwed up -- or, worse, when that person might
have screwed up but there's so little record of what the person did that
one cannot easily tell.
> I generally start doing things when I've a good and
> obvious plan to undo them.
But the reversion plan needs to also be obvious to the _other_
volunteers. It's not enough that you know how to revert your work if
necessary. The ChangeLog entry is intended to have just enough detailed
information so that any _other_ volunteer can, if necessary, revert your
work. (Of course, some work cannot be reverted. For that work, I guess
ChangeLog should get enough detail to understand the basics about what
you did.)
> You could guess right now I'm not up to the task (I'm wondering as
> well), you could risk to invest some of your time to give me some
> more information for nothing in return, you could give me root and
> let me find out.
I have no problem with your having that access. I just need whatever
method you prefer of sending you credential information. If you want,
then plaintext e-mail is OK with me. (I can use a method that
sufficiently conceals the usable context of that information to anyone
intercepting that mail.)
BTW, there's no longer much justification for the Web-Team mailing list
continuing to exist in addition to Volunteers. I merely resurrected
Web-Team in protest, sort of (in anger, anyway), upon the departure of a
particularly disasterous President/VP team, who had unilaterally
destroyed without discussion _all_ of the working mailing lists and
replaced them with a single, highly private (at the time), excessively
controlled new mailing list called Volunteers. Web-Team then sprang
back into existence but all the life had been choked out of it, and it's
never actually been useful since then. The 'webmaster at svlug.org' public
contact address resolves to the Web-Team Mailman list via an e-mail
alias. All other such aliases for public contact resolve to Volunteers.
Basic rule: Try to be careful, try a _lot_ to avoid doing anything
irreversible by others, and discuss things on Volunteers if others ought
to know or be consulted. (Deciding unilaterally to rearrange things
without discussion pisses everyone off.)
----- End forwarded message -----
More information about the volunteers
mailing list