ウィキメディア財団は法的にサーバを管理します。ウィキメディア財団理事会(Wikimedia Foundation Board of Trustees)は誰に システム管理者権限を付与するか究極の責任を負い、その権限の行使を規定します。しかしながら、その権能はウィキメディア財団のさまざまな部長に委ねられます。日常の基準ではさまざまなシステム管理者がルートもしくはシェルのアクセス権を預かり、サーバのクラスタを管理します。
Approving the on-wiki sysadmin global group to any account (staff and volunteers) is the responsibility of the Trust and Safety team in consultation with Legal at the Foundation. Not all system administrators have this permission. The on-wiki permission can be given to those who already have relevant permission/access in Wikimedia’s technical spaces (i.e. shell access) and can demonstrate a need of doing related on-wiki changes in order to better support the communities.
The requester needs to submit their request on the Steward requests/Global permissions Meta page. After submitting the request on Meta, the requester needs to send a note with a detailed use case (i.e. what do you need the rights for?) to Trust and Safety through cawikimedia.org for approval.
Once approved by the Legal department, one of the members from the Trust and Safety team will coordinate with the Stewards and will confirm the approval on the Meta request page.
Once the approval from the Foundation is secured, the Stewards ensure that the 2FA requirement for the user account is met and grant the rights.
The Stewards will remove the rights if the user wishes to resign and/or loses access to the server, Foundation asks for removal, or in case of abuse and in an emergency situation (i.e. account compromised).
There are various levels of shell access (through user groups) and many (whether or not overlapping) groups of servers that access is granted to. The canonical list of users with access to the servers is maintained in the Git repository that hosts the Puppet configuration used to configure the servers.
Users in the restricted, deployment, or ops groups (and by extension the release-engineering group which is included by reference) have sysadmin access to the servers running MediaWiki itself.