FAS group and Forge group for Discourse Moderation Team (in order to facilitate the necessary Docs repo) #449
Labels
No labels
ai-review-please
Org/Team Modification
Private Issues
Runner Request
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
forge/forge#449
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
I would like to ask for an FAS group and a Forge group for the Discourse Moderation Team.
Theoretically, we can re-use the old
ask-fedoragroup, but the name already suggests it's from a time before we merged our Discourse instances, so that could be confusing and the members are obsoleted along with the channels that are linked from and to the oldask-fedoragroup. A new FAS group thus might be less confusing. However, I think the majority of us is fine with both, and we would leave it to you to re-use the old one of create a new FAS group.The primary reason to get an FAS group organized is to get a Forge group because we need a new repo on Forge to provide our Docs: this is linked to the recent decision & poll about the new
Fedora Discussion Forum (Self-)Moderation Guidelines and Rulesand where to publish them -> the decision was to use the Docs.In both cases, I would like to ask to set the regularly-active moderators as sponsors/owners: I assume that would be @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm (I just took every person with mod privilege I found in any 2+ "top 5 poster" lists of any moderation topic of the 12 months before the poll discussion; that "definition" is just a suggestion that felt reasonable -> did I forget someone? I was not sure if @jflory7 and @jspaleta want to join there?).
Please do not auto-add all moderators/TL3/TL4, because the majority is not active on Discourse, and I would like to use this as an incentive to allow the moderation to get some "space" to distinguish themselves and develop some self-determination as a team, in order to maybe at some point (if the need exists) go beyond the daily tackling of what comes up towards preventive / strategic organizing their resources, and thus also better integrate/represent as team in the wider community, communicate their "supply & demand" etc. I see much potential to increase the value of the team and for the team itself. Hope that makes some sense :)
Let me know if there are questions or something I can do to help ;)
This is not urgent.
Thanks again to @jflory7 to provide the incentive that got this development started :)
Since I have admin access on Fedora Discourse, you can keep me included as a group member and sponsor.
Happy to help @py0xc3!
would this be more suitable for a team and repo under commops? rather than an entirely new organization?
we can set up say a
forge-commops-discoursemodsteam, and give them access to just the repo that is needed?It would be good to have our sponsors added to either a new or the existing FAS group.
As far as it concerns Forge, we need to add and remove ourselves the people who can merge/edit in the Docs repo. If that works with the alternative you suggested, that is fine.
so yes, we can create a new group on FAS,
forge-commops-discoursemoderationand link it to a new team in the comm-ops organization.We can then give members of that team access to just the discousce moderation docs repo. (and other repos too if you add more in the future.)
The one caveat here is that currently the commops-members team is set up to have access to all repos in the org, so that would include the discourse moderation docs repos. My suggestion here is to set up the members team to have access to just a specific set of repos as well.
I meant that in general, have a FAS group for the Discourse team, in contrast to the current state in which the "old" FAS group
ask-fedoracontains mostly sponsors (and members) no longer active/available -> that is not only for the Forge group :) As I said, we don't care if we keep using the existingask-fedoraFAS group and update the sponsors, or if we create something new to avoid the confusion (->ask-fedorano longer exists as dedicated platform). We leave that to whatever is better for you / commops / infra.You do not need to automatically map FAS group <-> Forge repo (not every FAS group member should have MR privileges anyway!), we can do that "manually" too as long as the sponsors of the FAS group are also owners of the repo (if we have the necessary privileges and if it is easier for you, we can maintain that "state" in future manually as well). The background of our need is, one one hand, the issue that this repo is "powerful" and is published as the rules that are to be enforced for our Discourse, so we have to be careful who can merge stuff there. On the other hand, especially in the beginning (and when new developments around AI or new technologies emerge) it might be more often necessary that we adjust it, and we need to ensure that adjustments are possible by those currently active in moderation (not all mods are available at all times due to other obligations, so we need to avoid bottlenecks as some changes can be time critical -> e.g., we had such an issue with AI, when exploitation started to take place and we found out our rules are not prepared for that). The latter might also make it necessary to involve long term TL4 members or so to some extent (we do not yet know how this will develop as a big change is ongoing with us). Just to elaborate the background of our needs. Sorry for causing the confusion :)
Concerning your suggestion about Forge, that is fine for me. As long as we can add/remove people with privileges to make changes to the repo on ourselves, we are fine with whatever fits you best :)
I would ask @jflory7 though: is that fine for commops too? I don't want to "break" anything for you or so.
Sorry, what i am suggesting is that we have
forge-commops-discoursemoderationgroup created. and we add members to that group, for example, we add these members:@ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm
then we map that group to a new team in commops
discoursemoderationteam, and only people that are members in that FAS group have access to that repo.Wait a second – Fedora Discussion is not managed by the Fedora Community Ops Team. I don't want to conflate Discourse forum moderation with the Community Ops team, because that is not what we do.
I think we probably just need to have a Discourse/forum FAS staff group? I am not sure if we have some FAS group syncing going on there or not, but if we can leverage any other group which already exists, that would also be useful.
I think we should go back to my original proposal, as the Discourse Moderation is a SIG itself and not part of another team, as you say.
Also, this is getting complex and it would be useful if the structures would be straightforward to every mod.
So, just get us either a new FAS group (
Discourse-Moderationor so) or update the old one (ask-fedora), and then create a new group in Forge, ensuring the sponsors of the FAS group are the owners of the Forge group and can administrate privileges within the group.(I have a tendency to create a new FAS and delete the old one -> it's dead and refers to a discourse that no longer exists, that can be confusing)
So far not, the old
ask-fedoraFAS that formally still exists is, as the name suggests, from the time when we had two Discourse instances. It's not connected to the current Discourse.my bad -- my assumption that moderating the discussion forums was a commops type task. Just trying to avoid creating new orgs when they are in fact sub-teams of existing teams.
would this work?
forge-discussion-ownerssponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdmforge-discussion-members. sponsors the list above, and members the list above + whoever else has commit access.discussion-- i chose this since it does not lock us into discourse if we change for some reason, and we might also want to store other things related to discussion other than moderation docs in the future. (this is similar to how we have theforgeorg already)No worries. Thanks for taking care of the case :-)
Mostly, but "members" who are not owners should not have commit access in order to avoid that every individual member can change the rules that are published. So they should be able to do PR/MR, and of course everyone on forge should be able to open a ticket: I assume we can change the privileges of individual members on forge manually, so that we can add commit privileges to single members on demand, rather than generally to the whole members group, right? So the idea is to start by default without commit, and owners decide individually when a single member needs (temporarily) commit rights.
It's not a requirement, but as the FAS groups are intended for general use (not necessarily only for forge), does it make sense to remove the
forge-in the name? That's more curiosity, not a "must have" :)Sounds like you don't really need a members group at all.
lets just make the
forge-discussion-ownersmap to the owners team. Then if you want to add access, you can add them to that group.we are keeping the "forge-" prefix for all the forge permissions groups, but if you want a general purpose group, we can use whatever one you want, and just make the forge-discussion-owners group inherit the membership from the general purpose group.
As mentioned, we need a general group that is not only for forge. Let's finalize to use not the old FAS group but create a new one:
Fedora-DiscussionorDiscussion(this is a SIG, not only related to the activities on Forge). I suggest to delete the oldask-fedora, as the name refers to a no-longer-existing Discourse instance.As far as it concerns forge, the need would be that every owner/sponsor (the mentioned group of 8 people) of the FAS group / SIG becomes an owner of Forge. But the members of the FAS/SIG who are not owners/sponsors should not become owner access to Forge: one of the reasons we choose Docs/Forge is to avoid that every member of the SIG can re-write the official / published rules.
If we can manually add FAS accounts to Forge and give them any privileges (such as commit), and if I assume right that every Forge/FAS member at all can do tickets and PR, then you are right: we do not need a members group for forge in this case. We can do that manually. Then the forge-specific part would be Just a mapping from FAS
Fedora-DiscussionOWNER toforge-discussion-owner.My expectation was that other SIG with FAS groups also not allow every member automatically full rights to make changes. So I assumed that possible?
+ jflory7 :)
This is now ready to go.
The https://accounts.fedoraproject.org/group/forge-discussion-owners/ group is now created, and the members are inherited from
[discussion-mods](https://accounts.fedoraproject.org/group/discussion-mods)which has all the sponsors and owners listed above.On next login, members of that group will be owners in the new forge org:
https://forge.fedoraproject.org/discussion
@ryanlerch If we add members to
discussion-modsthat are not sponsors, they will not be mapped toforge-discussion-ownerswith any privilege that contains commit ?I have to re-open this ticket, we cannot leave it the way it is: now every "trust level"-based contributor of the SIG becomes owner of the Forge Discussion group and can delete repos. So that's more problematic than having a separated member group with committing privileges each.
If I understand it right how Forge and FAS are connected, I assume the only possibility is to create a third FAS group
forge-discussion-membersso that we have in total 3 FAS groups:discussion-mods-> that's our FAS group of the SIG, for now, nothing moreforge-discussion-owners-> that's the owners of Forge who can create and delete repos and other actions that can cause serious issues. For now, it is likely to remain identical to the known 8 sponsors, though we might add "full moderators" or "site admins" to it on demand.forge-discussion-members-> that's members of the Forge group with the least possible privileges (I assume that's commit privileges but not the right to delete/add repos, right?). We use this to involve some of the experienced TL4 members on demand in maintaining our guidelines or other stuff in the repos, but this should only contain privileges that are revertible (so that we at the worst have to revert a commit or so). There is no general profile for this (only minimal requirements candidates have to fulfill when we need some on demand temporarily or permanently), so the sponsors would add people of the SIG here on demand and at the discretion of the mod group manually.The 8 sponsors should be the same in all 3 FAS groups, but adding anyone to any of the 3 groups should not automatically lead to them being added also to any other group: e.g., we have SIG members who should not automatically get commit rights (and therefore also not the right to delete repos), which excludes that all members of
discussion-modsare automatically members offorge-discussion-membersorforge-discussion-owners.I hope that make sense? :-)
So you don't want discussion-mods mapped to anything?
I don't like it, but I see no alternatives: originally, the requirement was that not every SIG member can directly commit. But the current result is that every SIG member is owner: every member can currently commit and delete repos (we tested that before Easter), which we cannot allow.
We need to be able to manually add individual members of the SIG to forge to allow them to commit as members but not delete repos (which excludes owners), whereas not all SIG members shall be able to commit. Every other SIG member should be able to create MR/PR, which I assume everyone can do anyway.
So the sponsors should be the same in all three FAS groups, and add to the respective group on demand whoever is needed there. Some are just SIG members without special privileges on Forge and can create MR/PR, some shall commit directly, some are owners.
So, unless I understood something wrong ...
yes, for now. The SIG's FAS group (discussion-mods) is not just for forge but also other things.
It appears that what you are after is very doable, easily -- i am just having issues determining what and who you want in each group.
Can you tell me:
Who are to be the members and sponsors for the
forge-discussion-ownersgroup, which will map to the owners team on forge. These are the super users for your organization, and have access to everything. Owner permissions cannot be tweaked, they are hard coded in forgejo. Note too, that all sponsors can do on FAS groups is add members to that group.Who are the sponsors and members for
forge-discussion-memberswhich will map to the members team? All other teams, you can manage the permissions for what they can do you can remove commit access, and just give them ticket access. Note too we can add more teams and FAS groups. for finer grained permissions if you want just a team that has access to managing tickets.it might be easier altogehter to meet up in real time to discuss this.
I guess we have a time zone issue :) I am in Matrix available most of the time until around 20:00 UTC+2/CEST (maybe 20:30), in case that is realistic (feel free to ping me there with @py0xc3 in the room you opened)
The group mentioned above (owners and sponsors are the same): ankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7
So it's the same as the sponsors of
discussion-modsThe sponsors are again the same.
For members, the issue starts: this cannot be mapped 1:1. Only some members of
discussion-modsare to become members (= to become allowed commit access), but some other members ofdiscussion-modsare NOT intended to become members. This will change over time and we need to be able to do this short notice (so, short notice decide to add someone in this group, temporarily or permanently). I therefore assumed its most useful to just add the sponsors there, and then the sponsors can manually add and remove team members to give and remove commit access.If I get it right, we can also have teams that have fine grained access: all access of members, but without immediate commit access (so they need to do PR/MR and then a member/owner must accept it). That would be great: in this group, every member of
discussion-modscan be a member too (I assume this will not override higher privileges of other groups).Sorry for the special needs :) I try to be available in Matrix most of the time.
ok, it sounds just like you need what we are using as the common setup for SIGS:
forge-discussion-owners. with sponsors and members being bothankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7and maps to the Owners team on the forge org.forge-discussion-membersthat inherits its membership fromdiscussion-mods-- this group will not have any sponsors, as you simply add members todiscussion-modsand this group inherits the members. This group maps to the "Members" team on forge, which you then can set the permissions for to what ever you want.Sounds good. Regarding 2. -> You mean
forge-discussion-ownerscan determine within forge what privileges every member (of the forge member group) has (including remove commit privileges from them), and then every member ofdiscussion-modswould (indirectly throughforge-discussion-members) automatically be added to forge with these member privileges? Or can we also individualize / customize individual members? Just to be sure I understand the implications :)@py0xc3 wrote in #449 (comment):
Every member of the forge-discussion-members group in FAS would be a member of the "Members" team in forge. and have the privs that you specify for that team (can be commit to all or specific repos, or just ticket privs to all or specific repos).
Looks good. Just checked in the security SIG how that works. Seems to fit.
Let's do it that way.
We maybe ask at some point in the future to get another member group, for us to add those who shall be able to commit to repos but without other ownership privileges, but we do not yet know for sure if that will be even necessary, so let's stick for now with the way you suggested. Thanks again!
https://accounts.fedoraproject.org/group/forge-discussion-owners/
** Sponsors: @ankursinha, @alciregi, @jakfrost, @x3mboy, @kevin, @py0xc3 , @mattdm, @jflory7
** Members: : @ankursinha, @alciregi, @jakfrost, @x3mboy, @kevin, @py0xc3 , @mattdm, @jflory7
https://accounts.fedoraproject.org/group/forge-discussion-members/
https://accounts.fedoraproject.org/group/discussion-mods/Permissions for the members team on forge is pretty low (read on repos), but this can be adjusted appropriately by an org owner.
I assume it's intended that https://accounts.fedoraproject.org/group/forge-discussion-members/ leads to a 404 error. However, I have seen after my recent login that I was added additionally to the forge members group, so it seems to work. Thanks!