2 ms·
In addition to the usual backup/restore policies, at $previous_workplace we disabled the "normal" prod DB admin accounts from running the usual suspect destruct
by snackbroken 2y ago
In addition to the usual backup/restore policies, at $previous_workplace we disabled the "normal" prod DB admin accounts from running the usual suspect destructive queries (drop, alter, update, etc.) on the production DB. If you really needed to run something dangerous, we had a script named FuckUpProduction that
1) made you wait one minute before it would do anything to give you time to reflect on your life choices,
2) made sure to begin a transaction so you could roll it back before it was too late,
3) showed you the affected tables & rows,
4) made you type "FUCK MY SHIT UP" to confirm and
5) pinged everyone in our #DBA channel "<username> is about to fuck up production by running <query> affecting <rows> in <tables>. To stop them from doing something stupid, type STOP or NO" and aborted if anyone did so within the waiting period.
Anyone having to use FuckUpProduction was treated as a process failure and we did the whole RCA song and dance to determine why the normal testing/deployment process was insufficient. When FuckUpProduction was designed, some team members expressed discomfort at the use of profanity. This was considered a feature. We had a "swear jar" in the office that you had to put a dollar in if you were ever saved from accidentally running a query in prod either by FuckUpProduction or by the restrictive DBA accounts. The jar had enough money to buy a pizza before I left the company.
- inglor_cz 2y ago4) made you type "FUCK MY SHIT UP" to confirm That is amazing, will inspire myself.