{"host": "zuul1001.eqiad.wmnet", "state": "core_diff", "description": "Differences to core resources", "diff": {"full": {"total": 2971, "only_in_self": ["Cfssl::Cert[zuul__zuul1001_eqiad_wmnet]", "Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh]", "Exec[Generate cert zuul__zuul1001_eqiad_wmnet]", "Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]", "File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet]"], "only_in_other": ["Cfssl::Cert[zuul__nodepool]", "Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr]", "Exec[Generate cert zuul__nodepool refresh]", "Exec[Generate cert zuul__nodepool]", "Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "Exec[renew certificate - zuul__nodepool]", "File[/etc/cfssl/csr/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]"], "resource_diffs": [{"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem]\n\n-    mode      => 0440\n-    ensure    => file\n-    show_diff => False\n-    group     => root\n-    owner     => root\n-    backup    => False\n"}, {"resource": "File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]", "parameters": "--- File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem].orig\n+++ File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]\n\n+    owner  => nodepool\n+    ensure => file\n+    mode   => 0440\n+    group  => root\n"}, {"resource": "Systemd::Service[zuul-nodepool]"}, {"resource": "File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "content": "--- /etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr.orig\n+++ /etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr\n@@ -1,13 +0,0 @@\n-{\n-  \"CN\": \"zuul1001.eqiad.wmnet\",\n-  \"hosts\": [\n-    \"zuul1001.eqiad.wmnet\"\n-  ],\n-  \"key\": {\n-    \"algo\": \"ecdsa\",\n-    \"size\": 256\n-  },\n-  \"names\": [\n-\n-  ]\n-}", "parameters": "--- File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr].orig\n+++ File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]\n\n-    owner  => root\n-    ensure => file\n-    mode   => 0400\n-    group  => root\n"}, {"resource": "Cfssl::Cert[zuul__nodepool]", "parameters": "--- Cfssl::Cert[zuul__nodepool].orig\n+++ Cfssl::Cert[zuul__nodepool]\n\n+    common_name     => nodepool\n+    provide_chain   => True\n+    names           => []\n+    environment     => ['GODEBUG=x509ignoreCN=0']\n+    outdir          => /etc/zookeeper/zuul-tls\n+    label           => zuul\n+    mode            => 0740\n+    notify_services => []\n+    auto_renew      => True\n+    renew_seconds   => 952200\n+    before_services => []\n+    ensure          => present\n+    group           => root\n+    key             => {'algo': 'ecdsa', 'size': 256}\n+    hosts           => []\n+    owner           => nodepool\n"}, {"resource": "Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "parameters": "--- Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr].orig\n+++ Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]\n\n-    ensure      => present\n-    common_name => zuul1001.eqiad.wmnet\n-    key         => {'algo': 'ecdsa', 'size': 256}\n-    hosts       => []\n-    names       => []\n"}, {"resource": "Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]", "parameters": "--- Exec[renew certificate - zuul__zuul1001_eqiad_wmnet].orig\n+++ Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]\n\n-    require     => Exec[Generate cert zuul__zuul1001_eqiad_wmnet]\n-    unless      => /usr/bin/openssl x509 -in /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem -checkend 952200\n-    command     => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "File[/etc/cfssl/csr/zuul__nodepool.csr]", "content": "--- /etc/cfssl/csr/zuul__nodepool.csr.orig\n+++ /etc/cfssl/csr/zuul__nodepool.csr\n@@ -0,0 +1,13 @@\n+{\n+  \"CN\": \"nodepool\",\n+  \"hosts\": [\n+    \"nodepool\"\n+  ],\n+  \"key\": {\n+    \"algo\": \"ecdsa\",\n+    \"size\": 256\n+  },\n+  \"names\": [\n+\n+  ]\n+}", "parameters": "--- File[/etc/cfssl/csr/zuul__nodepool.csr].orig\n+++ File[/etc/cfssl/csr/zuul__nodepool.csr]\n\n+    owner  => root\n+    ensure => file\n+    mode   => 0400\n+    group  => root\n"}, {"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr]\n\n-    owner  => root\n-    ensure => file\n-    mode   => 0440\n-    group  => root\n"}, {"resource": "Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh]", "parameters": "--- Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh].orig\n+++ Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh]\n\n-    subscribe   => File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]\n-    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet\n\n-    refreshonly => True\n-    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "File[/etc/nodepool/nodepool.yaml]", "content": "--- /etc/nodepool/nodepool.yaml.orig\n+++ /etc/nodepool/nodepool.yaml\n@@ -7,10 +7,10 @@\n       - name: kubernetes-namespace\n         type: namespace\n zookeeper-servers:\n-  - host: \n+  - host: 10.64.32.104\n     port: 2281\n     chroot: /nodepool\n zookeeper-tls:\n-   cert: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem\n-   key: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem\n-   ca: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem\n+   cert: /etc/zookeeper/zuul-tls/zuul__nodepool.pem\n+   key: /etc/zookeeper/zuul-tls/zuul__nodepool-key.pem\n+   ca: /etc/zookeeper/zuul-tls/zuul_full_chain.pem"}, {"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]\n\n-    owner  => root\n-    ensure => file\n-    mode   => 0440\n-    group  => root\n"}, {"resource": "Cfssl::Cert[zuul__zuul1001_eqiad_wmnet]", "parameters": "--- Cfssl::Cert[zuul__zuul1001_eqiad_wmnet].orig\n+++ Cfssl::Cert[zuul__zuul1001_eqiad_wmnet]\n\n-    mode            => 0740\n-    notify_services => []\n-    common_name     => zuul1001.eqiad.wmnet\n-    provide_chain   => True\n-    auto_renew      => True\n-    names           => []\n-    renew_seconds   => 952200\n-    before_services => []\n-    environment     => ['GODEBUG=x509ignoreCN=0']\n-    ensure          => present\n-    group           => root\n-    label           => zuul\n-    key             => {'algo': 'ecdsa', 'size': 256}\n-    hosts           => []\n-    owner           => root\n"}, {"resource": "Exec[Generate cert zuul__nodepool]", "parameters": "--- Exec[Generate cert zuul__nodepool].orig\n+++ Exec[Generate cert zuul__nodepool]\n\n+    require     => Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr]\n+    unless      => /usr/bin/test \"$(/usr/bin/openssl x509 -in /etc/zookeeper/zuul-tls/zuul__nodepool.pem -noout -pubkey 2>&1)\" == \"$(/usr/bin/openssl pkey -pubout -in /etc/zookeeper/zuul-tls/zuul__nodepool-key.pem 2>&1)\"\n\n+    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/cfssl/csr/zuul__nodepool.csr | /usr/bin/cfssljson -bare /etc/zookeeper/zuul-tls/zuul__nodepool\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "parameters": "--- File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem].orig\n+++ File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]\n\n+    mode   => 0440\n+    ensure => file\n+    group  => root\n+    source => puppet:///modules/profile/pki/intermediates/zuul-cert.pem\n+    owner  => nodepool\n"}, {"resource": "Exec[Generate cert zuul__nodepool refresh]", "parameters": "--- Exec[Generate cert zuul__nodepool refresh].orig\n+++ Exec[Generate cert zuul__nodepool refresh]\n\n+    subscribe   => File[/etc/cfssl/csr/zuul__nodepool.csr]\n+    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/cfssl/csr/zuul__nodepool.csr | /usr/bin/cfssljson -bare /etc/zookeeper/zuul-tls/zuul__nodepool\n\n+    refreshonly => True\n+    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem]", "parameters": "--- File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem].orig\n+++ File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem]\n\n+    mode      => 0440\n+    ensure    => file\n+    show_diff => False\n+    group     => root\n+    owner     => nodepool\n+    backup    => False\n"}, {"resource": "Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "parameters": "--- Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem].orig\n+++ Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]\n\n-    command   => /bin/cat /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem > /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem\n-    unless    => /usr/bin/test \"$(/bin/cat /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem | sha512sum)\" == \"$(/bin/cat /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem | sha512sum)\"\n\n-    subscribe => ['Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]', 'File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]', 'File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]']\n"}, {"resource": "File[/lib/systemd/system/zuul-nodepool.service]", "content": "--- /lib/systemd/system/zuul-nodepool.service.orig\n+++ /lib/systemd/system/zuul-nodepool.service\n@@ -5,7 +5,7 @@\n ExecStart=/usr/bin/docker run \\\n          --add-host=host.docker.internal:10.64.32.104 \\\n          --mount type=bind,src=/etc/nodepool,dst=/etc/nodepool \\\n-         --mount type=bind,src=/etc/cfssl,dst=/etc/cfssl \\\n+         --mount type=bind,src=/etc/zookeeper/zuul-tls,dst=/etc/zookeeper/zuul-tls \\\n          docker-registry.wikimedia.org/repos/releng/zuul/zuul/nodepool-launcher:wmf-12.0.0-5\n \n ; https://www.groundcover.com/kubernetes-troubleshooting/exit-code-143"}, {"resource": "Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "parameters": "--- Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem].orig\n+++ Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]\n\n+    command   => /bin/cat /etc/zookeeper/zuul-tls/zuul__nodepool.pem /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem > /etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem\n+    unless    => /usr/bin/test \"$(/bin/cat /etc/zookeeper/zuul-tls/zuul__nodepool.pem /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem | sha512sum)\" == \"$(/bin/cat /etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem | sha512sum)\"\n\n+    subscribe => ['Exec[renew certificate - zuul__nodepool]', 'File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]', 'File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]']\n"}, {"resource": "Systemd::Unit[zuul-nodepool]"}, {"resource": "Exec[Generate cert zuul__zuul1001_eqiad_wmnet]", "parameters": "--- Exec[Generate cert zuul__zuul1001_eqiad_wmnet].orig\n+++ Exec[Generate cert zuul__zuul1001_eqiad_wmnet]\n\n-    require     => Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]\n-    unless      => /usr/bin/test \"$(/usr/bin/openssl x509 -in /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem -noout -pubkey 2>&1)\" == \"$(/usr/bin/openssl pkey -pubout -in /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem 2>&1)\"\n\n-    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "Exec[renew certificate - zuul__nodepool]", "parameters": "--- Exec[renew certificate - zuul__nodepool].orig\n+++ Exec[renew certificate - zuul__nodepool]\n\n+    require     => Exec[Generate cert zuul__nodepool]\n+    unless      => /usr/bin/openssl x509 -in /etc/zookeeper/zuul-tls/zuul__nodepool.pem -checkend 952200\n+    command     => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/zuul1001.eqiad.wmnet.pem -label zuul  /etc/zookeeper/zuul-tls/zuul__nodepool.csr | /usr/bin/cfssljson -bare /etc/zookeeper/zuul-tls/zuul__nodepool\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n"}, {"resource": "File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr]", "parameters": "--- File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr].orig\n+++ File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr]\n\n+    owner  => nodepool\n+    ensure => file\n+    mode   => 0440\n+    group  => root\n"}, {"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]\n\n-    mode   => 0440\n-    ensure => file\n-    group  => root\n-    source => puppet:///modules/profile/pki/intermediates/zuul-cert.pem\n-    owner  => root\n"}, {"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem]\n\n-    owner   => root\n-    ensure  => file\n-    group   => root\n-    require => Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]\n"}, {"resource": "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem]", "parameters": "--- File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem].orig\n+++ File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem]\n\n+    owner   => nodepool\n+    ensure  => file\n+    group   => root\n+    require => Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]\n"}, {"resource": "Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr]", "parameters": "--- Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr].orig\n+++ Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr]\n\n+    ensure      => present\n+    common_name => nodepool\n+    key         => {'algo': 'ecdsa', 'size': 256}\n+    hosts       => []\n+    names       => []\n"}, {"resource": "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet]", "parameters": "--- File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet].orig\n+++ File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet]\n\n-    mode    => 0740\n-    ensure  => directory\n-    group   => root\n-    owner   => root\n-    recurse => True\n"}, {"resource": "Class[Profile::Zuul::Nodepool]", "parameters": "--- Class[Profile::Zuul::Nodepool].orig\n+++ Class[Profile::Zuul::Nodepool]\n\n+    main_nodes              => ['zuul1001.eqiad.wmnet', 'zuul2001.codfw.wmnet']\n+    tls_config_dir          => /etc/zookeeper/zuul-tls\n+    zookeeper_tls_fullchain => /etc/zookeeper/zuul-tls/zuul_full_chain.pem\n"}], "perc_changed": "1.85%"}, "core": {"total": 2971, "only_in_self": ["Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh]", "Exec[Generate cert zuul__zuul1001_eqiad_wmnet]", "Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]", "File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet]"], "only_in_other": ["Exec[Generate cert zuul__nodepool refresh]", "Exec[Generate cert zuul__nodepool]", "Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "Exec[renew certificate - zuul__nodepool]", "File[/etc/cfssl/csr/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]"], "resource_diffs": [{"resource": "File[/lib/systemd/system/zuul-nodepool.service]", "content": "--- /lib/systemd/system/zuul-nodepool.service.orig\n+++ /lib/systemd/system/zuul-nodepool.service\n@@ -5,7 +5,7 @@\n ExecStart=/usr/bin/docker run \\\n          --add-host=host.docker.internal:10.64.32.104 \\\n          --mount type=bind,src=/etc/nodepool,dst=/etc/nodepool \\\n-         --mount type=bind,src=/etc/cfssl,dst=/etc/cfssl \\\n+         --mount type=bind,src=/etc/zookeeper/zuul-tls,dst=/etc/zookeeper/zuul-tls \\\n          docker-registry.wikimedia.org/repos/releng/zuul/zuul/nodepool-launcher:wmf-12.0.0-5\n \n ; https://www.groundcover.com/kubernetes-troubleshooting/exit-code-143"}, {"resource": "File[/etc/nodepool/nodepool.yaml]", "content": "--- /etc/nodepool/nodepool.yaml.orig\n+++ /etc/nodepool/nodepool.yaml\n@@ -7,10 +7,10 @@\n       - name: kubernetes-namespace\n         type: namespace\n zookeeper-servers:\n-  - host: \n+  - host: 10.64.32.104\n     port: 2281\n     chroot: /nodepool\n zookeeper-tls:\n-   cert: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem\n-   key: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem\n-   ca: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem\n+   cert: /etc/zookeeper/zuul-tls/zuul__nodepool.pem\n+   key: /etc/zookeeper/zuul-tls/zuul__nodepool-key.pem\n+   ca: /etc/zookeeper/zuul-tls/zuul_full_chain.pem"}], "perc_changed": "0.77%"}, "main": {"total": 2971, "only_in_self": ["Cfssl::Cert[zuul__zuul1001_eqiad_wmnet]", "Cfssl::Csr[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "Exec[Generate cert zuul__zuul1001_eqiad_wmnet refresh]", "Exec[Generate cert zuul__zuul1001_eqiad_wmnet]", "Exec[create chained cert /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "Exec[renew certificate - zuul__zuul1001_eqiad_wmnet]", "File[/etc/cfssl/csr/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chained.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.csr]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem]", "File[/etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet]"], "only_in_other": ["Cfssl::Cert[zuul__nodepool]", "Cfssl::Csr[/etc/cfssl/csr/zuul__nodepool.csr]", "Exec[Generate cert zuul__nodepool refresh]", "Exec[Generate cert zuul__nodepool]", "Exec[create chained cert /etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "Exec[renew certificate - zuul__nodepool]", "File[/etc/cfssl/csr/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool-key.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chain.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.chained.pem]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.csr]", "File[/etc/zookeeper/zuul-tls/zuul__nodepool.pem]"], "resource_diffs": [{"resource": "Systemd::Service[zuul-nodepool]"}, {"resource": "File[/lib/systemd/system/zuul-nodepool.service]", "content": "--- /lib/systemd/system/zuul-nodepool.service.orig\n+++ /lib/systemd/system/zuul-nodepool.service\n@@ -5,7 +5,7 @@\n ExecStart=/usr/bin/docker run \\\n          --add-host=host.docker.internal:10.64.32.104 \\\n          --mount type=bind,src=/etc/nodepool,dst=/etc/nodepool \\\n-         --mount type=bind,src=/etc/cfssl,dst=/etc/cfssl \\\n+         --mount type=bind,src=/etc/zookeeper/zuul-tls,dst=/etc/zookeeper/zuul-tls \\\n          docker-registry.wikimedia.org/repos/releng/zuul/zuul/nodepool-launcher:wmf-12.0.0-5\n \n ; https://www.groundcover.com/kubernetes-troubleshooting/exit-code-143"}, {"resource": "Systemd::Unit[zuul-nodepool]"}, {"resource": "File[/etc/nodepool/nodepool.yaml]", "content": "--- /etc/nodepool/nodepool.yaml.orig\n+++ /etc/nodepool/nodepool.yaml\n@@ -7,10 +7,10 @@\n       - name: kubernetes-namespace\n         type: namespace\n zookeeper-servers:\n-  - host: \n+  - host: 10.64.32.104\n     port: 2281\n     chroot: /nodepool\n zookeeper-tls:\n-   cert: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.pem\n-   key: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet-key.pem\n-   ca: /etc/cfssl/ssl/zuul__zuul1001_eqiad_wmnet/zuul__zuul1001_eqiad_wmnet.chain.pem\n+   cert: /etc/zookeeper/zuul-tls/zuul__nodepool.pem\n+   key: /etc/zookeeper/zuul-tls/zuul__nodepool-key.pem\n+   ca: /etc/zookeeper/zuul-tls/zuul_full_chain.pem"}, {"resource": "Class[Profile::Zuul::Nodepool]", "parameters": "--- Class[Profile::Zuul::Nodepool].orig\n+++ Class[Profile::Zuul::Nodepool]\n\n+    main_nodes              => ['zuul1001.eqiad.wmnet', 'zuul2001.codfw.wmnet']\n+    tls_config_dir          => /etc/zookeeper/zuul-tls\n+    zookeeper_tls_fullchain => /etc/zookeeper/zuul-tls/zuul_full_chain.pem\n"}], "perc_changed": "1.01%"}}}