--- Ferm::Service[ssh_from_bastion].orig
+++ Ferm::Service[ssh_from_bastion]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ srange => ['208.80.155.110', '2620:0:861:4:208:80:155:110', '208.80.154.7', '2620:0:861:1:208:80:154:7', '208.80.153.110', '2a02:ec80:300:3:185:15:59:99', '185.15.59.99', '2620:0:860:4:208:80:153:110', '103.102.166.6', '2001:df2:e500:1:103:102:166:6', '185.15.58.6', '2a02:ec80:600:1:185:15:58:6', '195.200.68.99', '2a02:ec80:700:3:195:200:68:99']
File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft].orig
+++ File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[ssh_from_cumin_masters]
- Parameters differences:
--- Ferm::Service[ssh_from_cumin_masters].orig
+++ Ferm::Service[ssh_from_cumin_masters]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ src_sets => ['CUMIN_MASTERS']
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_ssh_cluster.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh_cluster.nft].orig
+++ File[/etc/nftables/input/10_ssh_cluster.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[deployment_ssh]
- Parameters differences:
--- Ferm::Service[deployment_ssh].orig
+++ Ferm::Service[deployment_ssh]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 22
+ desc =>
+ src_sets => ['DEPLOYMENT_HOSTS']
- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_rsyncd_access_phabricator-repos.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_rsyncd_access_phabricator-repos.nft].orig
+++ File[/etc/nftables/input/10_rsyncd_access_phabricator-repos.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[bacula_file_daemon_backup1014_eqiad_wmnet]
- Parameters differences:
--- Ferm::Service[bacula_file_daemon_backup1014_eqiad_wmnet].orig
+++ Ferm::Service[bacula_file_daemon_backup1014_eqiad_wmnet]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => 9102
+ desc =>
+ srange => ['backup1014.eqiad.wmnet']
- File[/etc/nftables/100_base_puppet.nft]
- Parameters differences:
--- File[/etc/nftables/100_base_puppet.nft].orig
+++ File[/etc/nftables/100_base_puppet.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv6.nft].orig
+++ File[/etc/nftables/sets/INTERNAL_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[rsyncd_access_phabricator_home_dirs]
- Parameters differences:
--- Ferm::Service[rsyncd_access_phabricator_home_dirs].orig
+++ Ferm::Service[rsyncd_access_phabricator_home_dirs]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => [873, 1873]
+ desc =>
+ srange => ['phab2002.codfw.wmnet']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_phabmain-smtp.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_phabmain-smtp.nft].orig
+++ File[/etc/nftables/input/10_phabmain-smtp.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft].orig
+++ File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- Ferm::Service[rsyncd_access_srv_dumps]
- Parameters differences:
--- Ferm::Service[rsyncd_access_srv_dumps].orig
+++ Ferm::Service[rsyncd_access_srv_dumps]
+ proto => tcp
+ prio => 10
+ ensure => present
+ notrack => False
+ port => [873, 1873]
+ desc =>
+ srange => ['phab1004.eqiad.wmnet', 'phab2002.codfw.wmnet', 'clouddumps1001.wikimedia.org', 'clouddumps1002.wikimedia.org']
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft].orig
+++ File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft].orig
+++ File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/input/10_deployment-ssh.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_deployment-ssh.nft].orig
+++ File[/etc/nftables/input/10_deployment-ssh.nft]
@@
- notify => Service[nftables]
+ notify => ['Service[nftables]']
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
- Parameters differences: