--- Ferm::Service[ceph_daemons].orig
+++ Ferm::Service[ceph_daemons]
+ notrack => False
+ desc =>
+ before => Class[Ceph::Common]
+ srange => ['10.64.130.13', '10.64.131.21', '10.64.132.23', '10.64.134.12', '10.64.135.21', '10.192.28.20', '10.192.42.14', '10.64.0.149', '10.64.0.156', '10.64.0.38', '10.64.0.45', '10.64.130.6', '10.64.132.8', '10.64.134.5', '10.64.136.7', '10.64.16.47', '10.64.169.6', '10.64.171.3', '10.64.183.5', '2620:0:860:115:10:192:28:20', '2620:0:860:121:10:192:42:14', '2620:0:861:101:10:64:0:149', '2620:0:861:101:10:64:0:156', '2620:0:861:101:10:64:0:38', '2620:0:861:101:10:64:0:45', '2620:0:861:102:10:64:16:47', '2620:0:861:109:10:64:130:6', '2620:0:861:10b:10:64:132:8', '2620:0:861:10d:10:64:134:5', '2620:0:861:10f:10:64:136:7', '2620:0:861:119:10:64:169:6', '2620:0:861:131:10:64:171:3', '2620:0:861:13d:10:64:183:5', '10.192.32.106', '10.64.0.127', '10.64.16.179', '10.64.32.136', '10.64.48.183', '2620:0:860:103:10:192:32:106', '2620:0:861:101:10:64:0:127', '2620:0:861:102:10:64:16:179', '2620:0:861:103:10:64:32:136', '2620:0:861:107:10:64:48:183']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ port_range => [6800, 7300]
+ ensure => present
+ src_sets => ['AUX_KUBEPODS_NETWORKS', 'DSE_KUBEPODS_NETWORKS', 'ANALYTICS_NETWORKS']
Ferm::Service[ceph_mon_v2]
- Parameters differences:
--- Ferm::Service[ceph_mon_v2].orig
+++ Ferm::Service[ceph_mon_v2]
+ notrack => False
+ port => 3300
+ desc =>
+ before => Class[Ceph::Common]
+ srange => ['10.64.130.13', '10.64.131.21', '10.64.132.23', '10.64.134.12', '10.64.135.21', '10.192.28.20', '10.192.42.14', '10.64.0.149', '10.64.0.156', '10.64.0.38', '10.64.0.45', '10.64.130.6', '10.64.132.8', '10.64.134.5', '10.64.136.7', '10.64.16.47', '10.64.169.6', '10.64.171.3', '10.64.183.5', '2620:0:860:115:10:192:28:20', '2620:0:860:121:10:192:42:14', '2620:0:861:101:10:64:0:149', '2620:0:861:101:10:64:0:156', '2620:0:861:101:10:64:0:38', '2620:0:861:101:10:64:0:45', '2620:0:861:102:10:64:16:47', '2620:0:861:109:10:64:130:6', '2620:0:861:10b:10:64:132:8', '2620:0:861:10d:10:64:134:5', '2620:0:861:10f:10:64:136:7', '2620:0:861:119:10:64:169:6', '2620:0:861:131:10:64:171:3', '2620:0:861:13d:10:64:183:5', '10.192.32.106', '10.64.0.127', '10.64.16.179', '10.64.32.136', '10.64.48.183', '2620:0:860:103:10:192:32:106', '2620:0:861:101:10:64:0:127', '2620:0:861:102:10:64:16:179', '2620:0:861:103:10:64:32:136', '2620:0:861:107:10:64:48:183']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['AUX_KUBEPODS_NETWORKS', 'DSE_KUBEPODS_NETWORKS', 'ANALYTICS_NETWORKS']
- Ferm::Service[ssh_from_cumin_masters]
- Parameters differences:
--- Ferm::Service[ssh_from_cumin_masters].orig
+++ Ferm::Service[ssh_from_cumin_masters]
+ notrack => False
+ port => 22
+ desc =>
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['CUMIN_MASTERS']
- Ferm::Service[full_monitoring_metrics_access_tcp]
- Parameters differences:
--- Ferm::Service[full_monitoring_metrics_access_tcp].orig
+++ Ferm::Service[full_monitoring_metrics_access_tcp]
+ notrack => False
+ desc =>
+ srange => ['prometheus1005.eqiad.wmnet', 'prometheus1006.eqiad.wmnet', 'prometheus1007.eqiad.wmnet', 'prometheus1008.eqiad.wmnet', '208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ port_range => [1, 65535]
+ ensure => present
- Ferm::Service[full_monitoring_metrics_access_udp]
- Parameters differences:
--- Ferm::Service[full_monitoring_metrics_access_udp].orig
+++ Ferm::Service[full_monitoring_metrics_access_udp]
+ notrack => False
+ desc =>
+ srange => ['prometheus1005.eqiad.wmnet', 'prometheus1006.eqiad.wmnet', 'prometheus1007.eqiad.wmnet', 'prometheus1008.eqiad.wmnet', '208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
+ proto => udp
+ unrestricted_access => False
+ prio => 10
+ port_range => [1, 65535]
+ ensure => present
- Ferm::Service[bird_bfd_control]
- Parameters differences:
--- Ferm::Service[bird_bfd_control].orig
+++ Ferm::Service[bird_bfd_control]
+ notrack => False
+ port => 3784
+ desc =>
+ srange => ['10.64.134.1', '2620:0:861:10d::1']
+ proto => udp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['LINK_LOCAL']
- Ferm::Service[ssh_from_bastion]
- Parameters differences:
--- Ferm::Service[ssh_from_bastion].orig
+++ Ferm::Service[ssh_from_bastion]
+ notrack => False
+ port => 22
+ desc =>
+ srange => ['208.80.154.7', '2620:0:861:1:208:80:154:7', '208.80.153.110', '2a02:ec80:300:3:185:15:59:99', '185.15.59.99', '2620:0:860:4:208:80:153:110', '198.35.26.104', '2620:0:863:3:198:35:26:104', '103.102.166.103', '2001:df2:e500:3:103:102:166:103', '185.15.58.6', '2a02:ec80:600:1:185:15:58:6', '195.200.68.99', '2a02:ec80:700:3:195:200:68:99']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Ferm::Service[bird_bgp]
- Parameters differences:
--- Ferm::Service[bird_bgp].orig
+++ Ferm::Service[bird_bgp]
+ notrack => False
+ port => 179
+ desc =>
+ srange => ['10.64.134.1', '2620:0:861:10d::1']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Ferm::Service[envoy_tls_termination_src_sets]
- Parameters differences:
--- Ferm::Service[envoy_tls_termination_src_sets].orig
+++ Ferm::Service[envoy_tls_termination_src_sets]
+ notrack => True
+ port => 443
+ desc =>
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['ANALYTICS_NETWORKS', 'DSE_KUBEPODS_NETWORKS', 'DEPLOYMENT_HOSTS']
- Ferm::Service[bird_bfd_echo]
- Parameters differences:
--- Ferm::Service[bird_bfd_echo].orig
+++ Ferm::Service[bird_bfd_echo]
+ notrack => False
+ port => 3785
+ desc =>
+ srange => ['10.64.134.1', '2620:0:861:10d::1']
+ proto => udp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['LINK_LOCAL']
- Ferm::Service[envoy_tls_termination]
- Parameters differences:
--- Ferm::Service[envoy_tls_termination].orig
+++ Ferm::Service[envoy_tls_termination]
+ notrack => True
+ port => 443
+ desc =>
+ srange => ['db1208.eqiad.wmnet']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Ferm::Service[ceph_mon_v1]
- Parameters differences:
--- Ferm::Service[ceph_mon_v1].orig
+++ Ferm::Service[ceph_mon_v1]
+ notrack => False
+ port => 6789
+ desc =>
+ before => Class[Ceph::Common]
+ srange => ['10.64.130.13', '10.64.131.21', '10.64.132.23', '10.64.134.12', '10.64.135.21', '10.192.28.20', '10.192.42.14', '10.64.0.149', '10.64.0.156', '10.64.0.38', '10.64.0.45', '10.64.130.6', '10.64.132.8', '10.64.134.5', '10.64.136.7', '10.64.16.47', '10.64.169.6', '10.64.171.3', '10.64.183.5', '2620:0:860:115:10:192:28:20', '2620:0:860:121:10:192:42:14', '2620:0:861:101:10:64:0:149', '2620:0:861:101:10:64:0:156', '2620:0:861:101:10:64:0:38', '2620:0:861:101:10:64:0:45', '2620:0:861:102:10:64:16:47', '2620:0:861:109:10:64:130:6', '2620:0:861:10b:10:64:132:8', '2620:0:861:10d:10:64:134:5', '2620:0:861:10f:10:64:136:7', '2620:0:861:119:10:64:169:6', '2620:0:861:131:10:64:171:3', '2620:0:861:13d:10:64:183:5', '10.192.32.106', '10.64.0.127', '10.64.16.179', '10.64.32.136', '10.64.48.183', '2620:0:860:103:10:192:32:106', '2620:0:861:101:10:64:0:127', '2620:0:861:102:10:64:16:179', '2620:0:861:103:10:64:32:136', '2620:0:861:107:10:64:48:183']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['AUX_KUBEPODS_NETWORKS', 'DSE_KUBEPODS_NETWORKS', 'ANALYTICS_NETWORKS']