--- Ferm::Service[ganeti_noded_cluster].orig
+++ Ferm::Service[ganeti_noded_cluster]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 1811
+ desc =>
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[ganeti_confd_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_confd_cluster].orig
+++ Ferm::Service[ganeti_confd_cluster]
+ proto => udp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 1814
+ desc =>
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft].orig
+++ File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[ssh_from_cumin_masters]
- Parameters differences:
--- Ferm::Service[ssh_from_cumin_masters].orig
+++ Ferm::Service[ssh_from_cumin_masters]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ src_sets => ['CUMIN_MASTERS']
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/100_base_puppet.nft]
- Parameters differences:
--- File[/etc/nftables/100_base_puppet.nft].orig
+++ File[/etc/nftables/100_base_puppet.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ganeti_ssh_cluster.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ganeti_ssh_cluster.nft].orig
+++ File[/etc/nftables/input/10_ganeti_ssh_cluster.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv6.nft].orig
+++ File[/etc/nftables/sets/INTERNAL_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ganeti_mond_cluster.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ganeti_mond_cluster.nft].orig
+++ File[/etc/nftables/input/10_ganeti_mond_cluster.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft].orig
+++ File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[ganeti_ssh_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_ssh_cluster].orig
+++ Ferm::Service[ganeti_ssh_cluster]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[full_monitoring_metrics_access_udp]
- Parameters differences:
--- Ferm::Service[full_monitoring_metrics_access_udp].orig
+++ Ferm::Service[full_monitoring_metrics_access_udp]
+ proto => udp
+ prio => 10
+ ensure => present
+ notrack => False
+ desc =>
+ srange => ['prometheus2005.codfw.wmnet', 'prometheus2006.codfw.wmnet', 'prometheus2007.codfw.wmnet', 'prometheus2008.codfw.wmnet', '208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
+ port_range => [1, 65535]
- File[/etc/nftables/input/10_ganeti_migration.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ganeti_migration.nft].orig
+++ File[/etc/nftables/input/10_ganeti_migration.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ganeti_confd_cluster.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ganeti_confd_cluster.nft].orig
+++ File[/etc/nftables/input/10_ganeti_confd_cluster.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft].orig
+++ File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INTERNAL_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv4.nft].orig
+++ File[/etc/nftables/sets/INTERNAL_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft]
- Parameters differences: