--- Ferm::Service[ssh_from_bastion].orig
+++ Ferm::Service[ssh_from_bastion]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ srange => ['208.80.155.110', '2620:0:861:4:208:80:155:110', '208.80.154.7', '2620:0:861:1:208:80:154:7', '208.80.153.110', '2a02:ec80:300:3:185:15:59:99', '185.15.59.99', '2620:0:860:4:208:80:153:110', '103.102.166.6', '2001:df2:e500:1:103:102:166:6', '185.15.58.6', '2a02:ec80:600:1:185:15:58:6', '195.200.68.99', '2a02:ec80:700:3:195:200:68:99']
File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft].orig
+++ File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[ssh_from_cumin_masters]
- Parameters differences:
--- Ferm::Service[ssh_from_cumin_masters].orig
+++ Ferm::Service[ssh_from_cumin_masters]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ src_sets => ['CUMIN_MASTERS']
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/100_base_puppet.nft]
- Parameters differences:
--- File[/etc/nftables/100_base_puppet.nft].orig
+++ File[/etc/nftables/100_base_puppet.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[memcached_notls]
- Parameters differences:
--- Ferm::Service[memcached_notls].orig
+++ Ferm::Service[memcached_notls]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 11211
+ desc =>
+ src_sets => ['DOMAIN_NETWORKS']
- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv6.nft].orig
+++ File[/etc/nftables/sets/INTERNAL_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_memcached_notls.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_memcached_notls.nft].orig
+++ File[/etc/nftables/input/10_memcached_notls.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[memcached]
- Parameters differences:
--- Ferm::Service[memcached].orig
+++ Ferm::Service[memcached]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 11214
+ desc =>
+ src_sets => ['DOMAIN_NETWORKS']
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft].orig
+++ File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[full_monitoring_metrics_access_udp]
- Parameters differences:
--- Ferm::Service[full_monitoring_metrics_access_udp].orig
+++ Ferm::Service[full_monitoring_metrics_access_udp]
+ proto => udp
+ prio => 10
+ ensure => present
+ notrack => False
+ desc =>
+ srange => ['prometheus2005.codfw.wmnet', 'prometheus2006.codfw.wmnet', 'prometheus2007.codfw.wmnet', 'prometheus2008.codfw.wmnet', '208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
+ port_range => [1, 65535]
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft].orig
+++ File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INTERNAL_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv4.nft].orig
+++ File[/etc/nftables/sets/INTERNAL_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv6.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[full_monitoring_metrics_access_tcp]
- Parameters differences: