Difference between revisions of "Analytics/Team/Onboarding"

From Wikitech-static
Jump to navigation Jump to search
m (→‎Sample ssh config: fix link to redirect)
imported>Lucas Werkmeister
m (→‎E-mail lists: fix typo)
Line 19: Line 19:
* analytics-alerts - needs a phabricator task like [[phab:T123141|https://phabricator.wikimedia.org/T123141]]
* analytics-alerts - needs a phabricator task like [[phab:T123141|https://phabricator.wikimedia.org/T123141]]
* [[mail:analytics-announce|analytics-announce@]]
* [[mail:analytics-announce|analytics-announce@]]
* Please request acces to:
* Please request access to:
** [[mail:Ops|Operations]]
** [[mail:Ops|Operations]]
** [[mail:Engineering|Engineering]]  
** [[mail:Engineering|Engineering]]  

Revision as of 17:15, 16 October 2021


You will need lots of accounts, memberships and other secret keys to become a real productive member of the Analytics team. Here's an overview of things you should do in the first week. Please update this document as you go along! Last but not the least, the most important thing: welcome to the Analytics team!

First Steps

This section is related to the first logistic steps to effectively join the Wikimedia's staff crew. Take your time to explore and look around, don't rush!

Wikimedia tech employee orientation

Starting point for each new Wikimedia employee: https://office.wikimedia.org/wiki/New_tech_employee_orientation

Wikimedia account

Your manager and the Wikimedia's IT department will help you open several accounts including your work email. Right after this step, you will be able to communicate and participate to the day to day discussions between staff members. Be patient and don't be scared about the huge amount of information and emails that you'll receive!

E-mail lists

Reading mailing lists is important. All projects we build or use are open-source, and as most open-source projects, they have communities which come together on mailing lists. There is much knowledge to be gained in these mailing lists.

Once you have a Wikimedia e-mail address you should subscribe yourself to these e-mail lists:

For an overview of all available mailing lists see https://lists.wikimedia.org/mailman/listinfo

  • Optionally you may want to read archives or subscribe to the following mailing lists:
  1. Mediawiki
  2. Mobile
  3. Mediawiki API

If there are mailing lists you want to read without subscribing you may consider using the following gateways:

  1. Mail Archive
  2. Gmane
  3. Gossamer Threads


Most of our communication happens on IRC, you should set up an IRC nick

  1. Install an IRC client -- ask team members for recommendations (some would be quassel, irssi, pidgin, Hexchat, textual or adium if you're on a Mac)
  2. Follow instructions on meta:IRC/Cloaks to request an IRC cloak
  3. Connect to #wikimedia-analytics connect
  4. Other channels you might be interested in: #wikimedia-cloud connect, #wikimedia-operations connect, #wikimedia-office connect

Office wiki

Make sure you have an employee account and that you can use the office wiki, your office wiki user will be given to you once you get your wikimedia e-mail address.



Please buy a high-quality headset -- your colleagues will love you for this. For more tips see https://office.wikimedia.org/wiki/Office_IT/Projects/Telepresence


We are part of a movement with a unique culture. It's worth taking the time to read a bit about how our biggest project works. This policy could be a useful start, as it introduces the core concepts from a concrete point of view: https://en.wikipedia.org/wiki/Wikipedia:Biographies_of_living_persons

Getting permits

Please follow the next subsections (order matters!) to get permissions for various fundamental services. Access to Production will be covered in a separate section.

Wikitech/Cloud VPS

Cloud VPS is a cluster of virtual machines. Access is completely decoupled from production and different ssh keys should be used.

Cloud VPS is not production but we have several tools hosted on the cluster, accessing to Cloud VPS requires a Wikimedia developer account:

  1. Create account
  2. Log in
  3. You need to set up ssh keys
  4. Upload your public SSH key. Please have in mind that Cloud VPS is a testing environment thus this ssh key should only be used in testing, if you need access to machines in the production cluster your ssh key should be different (see section below about Production access).
  5. Configure your ~/.ssh/config with bastion hosts. See Sample ssh config for a template.
  6. Ask someone in the team to add you to the relevant projects in Cloud VPS.
  7. Get familiar with the Cloud VPS environment, how to use the Horizon interface to spin up nodes, remove nodes, etc


https://phabricator.wikimedia.org is the version of Phabricator that we use. Follow this page to log in for the first time (please use the sunflower icon as suggested by the tutorial to leverage the single sign on).


In order to access sites like turnilo and yarn, you need to be added to the wmf group in LDAP. You can ask for this by opening a new task using the LDAP-Access-Requests tag in Phabricator.


  1. Create an account
  2. Log in


  1. Gerrit is the code review workflow we use, build on top of git
  2. Log in to Gerrit using your Wikimedia developer account credentials.
  3. To verify everything works, clone a repo repo from https://gerrit.wikimedia.org/r/#/admin/projects/?filter=analytics using SSH.
  4. Take a look at how to deal with gerrit in different work scenarios: http://etherpad.wikimedia.org/p/analytics-gerrit

Accessing production infrastructure

With great power comes great responsibility. Please do read carefully the Wikimedia's SSH access guidelines and familiarize with your new SSH config before proceeding. Moreover we manage very sensitive data, please read Analytics/Data access to familiarize yourself with our procedures.

Shell access to Wikimedia cluster and production infrastructure

Tickets are filed for the ops team to see and need to be approved by a manger (example: https://phabricator.wikimedia.org/T96053).

You will also need to receive and acknowledge a legal disclaimer about data deletion. This is an important legal requirement for which we need to ping legal everytime someone gains access to data with sudo permissions.

When opening the request for a new Analytics Dev in Phabricator, specify that a kerberos principal is needed for your user.

Talk with Andrew Otto about how to submit your ssh public key. You would likely need to proxy your ssh connection from a know machine to access some of the hosts above. You should not use the same ssh key for Cloud VPS (testing) and stat1 machines (production).

The easiest would be to ask some team member for its .ssh/config file and get the proxy setup.

Please have in mind that different processes are required to access production machines (stat1) and testing machines (Cloud VPS).

Sample ssh config

See SSH access#SSH configuration for sample SSH config. If you're in the analytics team you will probably SSH into both Cloud VPS and Production, so add relevant config for both in your ~/.ssh/config file.

Logging in

Once you have your SSH setup in place and your credentials have been approved by Ops (using the Phabricator task created before) you will be able to explore the Analytics infrastructure. Please start from Analytics and check the instruction for projects, for example:

Talk with the people of your team on IRC about their work and pointers to their projects, so you will get a more precise idea about who does what. Be patient, it will take a while to get a good overall picture!


Google Calendar

Add the Analytics Team Calendar to your default view. Someone (we all can manage sharing) should go to https://calendar.google.org and add you:

  • My Calendars -> Settings
  • Click Team Analytics -> Share This Calendar
  • Add the new person



As far as equipment goes you will need a good development machine.

Minimum machine specs:

  • >=4GB RAM
  • i7 >= 2.4 Ghz quad-core or better
  • 300GB disk

Recommended machine specs:

  • >=8GB RAM
  • i7 >= 2.4 Ghz quad-core or better
  • SSD
  • 300GB disk

At first sight you might think these are not required, but you will have to run VMs, you will be using vagrant to re-create various environments(sometimes with multiple nodes), so you will need some hardware for that.

Optional accounts

You could consider creating accounts for:

Operating System

The machines we deploy on are using Ubuntu and it would be more convenient for you to have Ubuntu installed on your development machine or any other UNIX based operating system. It will considerably facilitate your work. You may choose any other Linux distribution you're familiar with.

Mac is also a very possible choice.


This is a collection of things you might find useful in your work.

Design Documents

Take a look at the shared drive with technical design documents: https://drive.google.com/drive/u/0/folders/0AB5b7sFjfnJXUk9PVA

Sync tools

You may find the following tools useful for sync-ing files between your local machine and remote machines(one-way or two-way). You can also mount remote directories as if they were your local directories:

  1. sshfs
  2. rsync
  3. lsync
  4. unison
  5. scp

IDEs and editors

For Java development you might want to look at IDEA also. For remote development you may find vim to be useful(or a combination of a sync tool and your favorite editor/IDE). Other editors you might find useful may include Sublime Text, Emacs.


You may find the following tools useful to search through configuration files or code:

  1. Ack (mainly for grepping code. video presentation)
  2. grep
  3. GNU find
  4. codesearch for mediawiki

Environment simulation

It may be useful that you familiarize yourself with Vagrant and Puppet to be able to recreate smaller environments/conditions on your machine to test various software you're developing or contributing to.

Important Talks

Data Practices and Privacy Engineering

General Overview: What is analytics doing back there?

Our most recent talk that gives you an overview of the stack:

Talks recommended by other members of the Analytics team: