Skip to content

Commit 83180f5

Browse files
committed
update policies
1 parent adfe5a2 commit 83180f5

3 files changed

Lines changed: 59 additions & 16 deletions

File tree

docs/staff-docs/policies/keycard.md

Lines changed: 1 addition & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -22,22 +22,7 @@ Keycard access, once given, can be revoked at the discretion of SMs or GMs.
2222

2323

2424
## After hours policy
25-
26-
Staffers with keycard access to the lab are free to enter and leave as they
27-
please. In contrast, staffers without keycard access may only be in the lab
28-
when there is someone with keycard access in the lab as well. More
29-
specifically, no staffer without keycard access is permitted within the lab if
30-
there is no one with keycard also within the lab as well. As circumstances may
31-
result in staffers with keycard having to step out of the lab for short periods
32-
of time, a general rule of thumb will be that if those with keycard will return
33-
in a 30 minute time frame, non-keycarded staffers are free to stay.
34-
35-
OCF staffers are permitted to bring in as many guests after hours as is
36-
considered reasonable. Note that this is not a right, but a privilege and as
37-
such can be revoked if SMs/GMs feel that guests are being disruptive. Any
38-
non-staffer in the lab after hours must be logged in the OCF guest sign-in
39-
sheet, and failure to do so may be considered abuse of keycard privileges.
40-
25+
See Staff Docs -> Procedures -> SUFMO Access -> MOU
4126

4227
## Abuse of privileges
4328

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
# !!! SM/Root Handoff Guide !!!
2+
3+
## These steps must be followed when on-boarding/off-boarding rootstaff or SMs, or I will be disappointed in you.
4+
5+
6+
### On-boarding/off-boarding rootstaff
7+
8+
The following privileges/accounts must be granted when someone is made root, **and taken away/disabled when they are no longer root**.
9+
10+
* /root and /admin Kerberos principals
11+
* Membership of the ocfroot LDAP group
12+
- `kinit you/admin`
13+
- `ldapvi cn=ocfroot`
14+
* Kerberos permissions in the ACL list
15+
- `add otherstaffer/admin`
16+
- `add otherstaffer/root`
17+
* 24/7 Keycard Access, and their name on the Emergency after hours list
18+
* Membership of the root@ Google group to receive technical spam
19+
* Membership of the workspace-admins@ Google group to enforce physical security token 2fa
20+
* Super Admin status in Google Workspace
21+
* "Root" role in the OCF Discord
22+
* Owner status in the OCF Github
23+
* A 1password account, membership of the "Owners" group, and access to the root (and really-root?) vaults
24+
* Their hardware token ssh key added to agenix in the ocf/nix repo
25+
* Their ssh key added to nix deploy users
26+
* Membership of the security contact in socreg
27+
* Panorama access (perhaps this should be SM only?)
28+
* //TODO anything I missed?
29+
30+
31+
### SM Handoff
32+
33+
The following steps must be taken every time there is a new Site Manager, to ensure proper transfer of accounts.
34+
35+
* All of the above steps if one SM is gaining or losing root.
36+
* The following should always be held by one of the current SMs, and such should be transferred to an incoming SM if the person who holds it is leaving:
37+
* Ownership of the OCF Discord
38+
* //TODO i probably forgot a lot of things
39+
* Any account that requires a single user to be the owner
40+
* Additionally, the incoming/outgoing SMs should perform an audit of this list, and ensure that any new/removed manually assigned privileges are reflected here.
41+
42+
meow
43+
meow (with Brazilian characteristics)
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# Afterhour Access
2+
## MOU with SUFMO:
3+
https://drive.google.com/drive/search?q=OCF%20SUFMO%20access
4+
5+
## Adding user to access list
6+
PLEASE READ MOU for updated instructions on how to make changes.
7+
8+
The access list is at: https://docs.google.com/spreadsheets/d/1h1sumblh7tsxqhoZP1lxi-p-7HGpSJjJnC-A4ZbXm3M/edit?gid=214657590#gid=214657590
9+
10+
## Keycard Access
11+
- Add user to OCF Keycard roster: https://docs.google.com/spreadsheets/d/12kwr-CdhHpV1VzznSNfGx0FaOA8T3YUH0c8jqwftBRs/edit?gid=0#gid=0
12+
- MLK OCF Limited is for access to OCF & OCF Storage Room
13+
- MLK OCF is MLK OCF Limited + Access to side-doors and server rooms
14+
- Fill out keycard access form: https://berkeleysa.tfaforms.net/28?tfa_12=Access%20Request
15+
- Email OCF advisor (Lauren Beal, as of Spring 2026)

0 commit comments

Comments
 (0)