--- Ferm::Service[ganeti_rapi_cluster].orig
+++ Ferm::Service[ganeti_rapi_cluster]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 5080
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet', 'netbox1003.eqiad.wmnet', 'netbox2003.codfw.wmnet', 'netbox-dev2003.codfw.wmnet', 'netmon1003.wikimedia.org', 'netmon2002.wikimedia.org', 'cumin1003.eqiad.wmnet', 'cumin2002.codfw.wmnet']
Ferm::Service[ganeti_ssh_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_ssh_cluster].orig
+++ Ferm::Service[ganeti_ssh_cluster]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 22
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ssh_from_cumin_masters]
- Parameters differences:
--- Ferm::Service[ssh_from_cumin_masters].orig
+++ Ferm::Service[ssh_from_cumin_masters]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ src_sets => ['CUMIN_MASTERS']
+ desc =>
+ notrack => False
+ port => 22
- Ferm::Service[full_monitoring_metrics_access_tcp]
- Parameters differences:
--- Ferm::Service[full_monitoring_metrics_access_tcp].orig
+++ Ferm::Service[full_monitoring_metrics_access_tcp]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ port_range => [1, 65535]
+ ensure => present
+ desc =>
+ notrack => False
+ srange => ['prometheus2005.codfw.wmnet', 'prometheus2006.codfw.wmnet', 'prometheus2007.codfw.wmnet', 'prometheus2008.codfw.wmnet', '208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
- Ferm::Service[ganeti_confd_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_confd_cluster].orig
+++ Ferm::Service[ganeti_confd_cluster]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 1814
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ganeti_drbd]
- Parameters differences:
--- Ferm::Service[ganeti_drbd].orig
+++ Ferm::Service[ganeti_drbd]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ port_range => [11000, 14999]
+ ensure => present
+ desc =>
+ notrack => False
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ganeti_noded_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_noded_cluster].orig
+++ Ferm::Service[ganeti_noded_cluster]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 1811
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ganeti_migration]
- Parameters differences:
--- Ferm::Service[ganeti_migration].orig
+++ Ferm::Service[ganeti_migration]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 8102
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ganeti_prometheus_exporter]
- Parameters differences:
--- Ferm::Service[ganeti_prometheus_exporter].orig
+++ Ferm::Service[ganeti_prometheus_exporter]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ src_sets => ['PRODUCTION_NETWORKS']
+ desc =>
+ notrack => False
+ port => 8080
- Ferm::Service[ganeti_mond_cluster]
- Parameters differences:
--- Ferm::Service[ganeti_mond_cluster].orig
+++ Ferm::Service[ganeti_mond_cluster]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 1815
+ srange => ['ganeti2025.codfw.wmnet', 'ganeti2026.codfw.wmnet', 'ganeti2027.codfw.wmnet', 'ganeti2028.codfw.wmnet', 'ganeti2029.codfw.wmnet', 'ganeti2030.codfw.wmnet', 'ganeti2031.codfw.wmnet', 'ganeti2032.codfw.wmnet', 'ganeti2035.codfw.wmnet', 'ganeti2036.codfw.wmnet', 'ganeti2037.codfw.wmnet', 'ganeti2038.codfw.wmnet', 'ganeti2039.codfw.wmnet', 'ganeti2040.codfw.wmnet', 'ganeti2041.codfw.wmnet', 'ganeti2042.codfw.wmnet', 'ganeti2043.codfw.wmnet', 'ganeti2044.codfw.wmnet', 'ganeti2045.codfw.wmnet', 'ganeti2046.codfw.wmnet', 'ganeti2047.codfw.wmnet', 'ganeti2048.codfw.wmnet', 'ganeti2049.codfw.wmnet', 'ganeti2050.codfw.wmnet']
- Ferm::Service[ssh_from_bastion]
- Parameters differences:
--- Ferm::Service[ssh_from_bastion].orig
+++ Ferm::Service[ssh_from_bastion]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ port => 22
+ srange => ['208.80.154.7', '2620:0:861:1:208:80:154:7', '208.80.153.110', '2a02:ec80:300:3:185:15:59:99', '185.15.59.99', '2620:0:860:4:208:80:153:110', '198.35.26.104', '2620:0:863:3:198:35:26:104', '103.102.166.103', '2001:df2:e500:3:103:102:166:103', '185.15.58.6', '2a02:ec80:600:1:185:15:58:6', '195.200.68.99', '2a02:ec80:700:3:195:200:68:99']