--- Nftables::Service[ssh-from-bastion].orig
+++ Nftables::Service[ssh-from-bastion]
+ notrack => False
+ port => 22
+ desc =>
+ src_ips => ['103.102.166.103', '185.15.58.6', '185.15.59.99', '195.200.68.99', '198.35.26.104', '2001:df2:e500:3:103:102:166:103', '208.80.153.110', '208.80.154.7', '2620:0:860:4:208:80:153:110', '2620:0:861:1:208:80:154:7', '2620:0:863:3:198:35:26:104', '2a02:ec80:300:3:185:15:59:99', '2a02:ec80:600:1:185:15:58:6', '2a02:ec80:700:3:195:200:68:99']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
Nftables::Service[mysql_wmcs_db_admin_s2]
- Parameters differences:
--- Nftables::Service[mysql_wmcs_db_admin_s2].orig
+++ Nftables::Service[mysql_wmcs_db_admin_s2]
+ notrack => True
+ port => 3312
+ desc =>
+ src_ips => ['10.64.148.21', '10.64.150.6', '10.64.151.8', '2620:0:861:11c:10:64:148:21', '2620:0:861:11e:10:64:150:6', '2620:0:861:11f:10:64:151:8']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[ssh-from-cumin-masters]
- Parameters differences:
--- Nftables::Service[ssh-from-cumin-masters].orig
+++ Nftables::Service[ssh-from-cumin-masters]
+ notrack => False
+ port => 22
+ desc =>
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['CUMIN_MASTERS']
- Nftables::Service[full-monitoring-metrics-access-udp]
- Parameters differences:
--- Nftables::Service[full-monitoring-metrics-access-udp].orig
+++ Nftables::Service[full-monitoring-metrics-access-udp]
+ notrack => False
+ desc =>
+ src_ips => ['10.64.0.82', '10.64.16.62', '10.64.32.85', '10.64.48.171', '208.80.153.42', '208.80.154.78', '2620:0:860:2:208:80:153:42', '2620:0:861:101:10:64:0:82', '2620:0:861:102:10:64:16:62', '2620:0:861:103:10:64:32:85', '2620:0:861:107:10:64:48:171', '2620:0:861:3:208:80:154:78']
+ proto => udp
+ unrestricted_access => False
+ prio => 10
+ port_range => [1, 65535]
+ ensure => present
- Nftables::Service[mysql_adm_alternate_s7]
- Parameters differences:
--- Nftables::Service[mysql_adm_alternate_s7].orig
+++ Nftables::Service[mysql_adm_alternate_s7]
+ notrack => False
+ port => 3337
+ desc =>
+ src_ips => ['10.192.16.191', '10.192.32.49', '10.64.0.20', '10.64.16.154', '10.64.16.90', '208.80.154.9']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_wmcs_db_admin_s7]
- Parameters differences:
--- Nftables::Service[mysql_wmcs_db_admin_s7].orig
+++ Nftables::Service[mysql_wmcs_db_admin_s7]
+ notrack => True
+ port => 3317
+ desc =>
+ src_ips => ['10.64.148.21', '10.64.150.6', '10.64.151.8', '2620:0:861:11c:10:64:148:21', '2620:0:861:11e:10:64:150:6', '2620:0:861:11f:10:64:151:8']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_admin_s2]
- Parameters differences:
--- Nftables::Service[mysql_admin_s2].orig
+++ Nftables::Service[mysql_admin_s2]
+ notrack => False
+ port => 3312
+ desc =>
+ src_ips => ['10.192.16.191', '10.192.32.49', '10.64.0.20', '10.64.16.154', '10.64.16.90', '208.80.154.9']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_admin_s7]
- Parameters differences:
--- Nftables::Service[mysql_admin_s7].orig
+++ Nftables::Service[mysql_admin_s7]
+ notrack => False
+ port => 3317
+ desc =>
+ src_ips => ['10.192.16.191', '10.192.32.49', '10.64.0.20', '10.64.16.154', '10.64.16.90', '208.80.154.9']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s2]
- Parameters differences:
--- Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s2].orig
+++ Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s2]
+ notrack => True
+ port => 3312
+ desc =>
+ src_ips => ['10.64.150.4', '10.64.151.2', '2620:0:861:11e:10:64:150:4', '2620:0:861:11f:10:64:151:2']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_adm_alternate_s2]
- Parameters differences:
--- Nftables::Service[mysql_adm_alternate_s2].orig
+++ Nftables::Service[mysql_adm_alternate_s2]
+ notrack => False
+ port => 3332
+ desc =>
+ src_ips => ['10.192.16.191', '10.192.32.49', '10.64.0.20', '10.64.16.154', '10.64.16.90', '208.80.154.9']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s7]
- Parameters differences:
--- Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s7].orig
+++ Nftables::Service[mysql_wikireplica_db_cloudlb_proxy_s7]
+ notrack => True
+ port => 3317
+ desc =>
+ src_ips => ['10.64.150.4', '10.64.151.2', '2620:0:861:11e:10:64:150:4', '2620:0:861:11f:10:64:151:2']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present