Compilation results for ml-serve1014.eqiad.wmnet: System changes detected
You can retrieve this result from host.json.Catalog differences
Summary
| Total Resources: | 2865 |
|---|---|
| Resources added: | 353 |
| Resources removed: | 5 |
| Resources modified: | 364 |
| Change percentage: | 25.20% |
Resources only in the new catalog
- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet refresh]
- File[/etc/rsyslog.d/00-imfile.conf]
- Systemd::Unit[cpupower]
- Exec[renew certificate - mlserve__istio-cni]
- Class[Profile::Containerd]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__calicoctl.csr]
- Service[containerd]
- Exec[/usr/sbin/dpkg-reconfigure -p critical -f noninteractive wikimedia-lvs-realserver]
- File[/etc/apt/sources.list.d/component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia.list]
- File[/etc/apt/sources.list.d/component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia.list]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__calico-cni.chain.pem]
- Service[kubelet]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chained.pem]
- File[/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr]
- Exec[Generate cert discovery__ml-serve1014_eqiad_wmnet refresh on intermediate ca change]
- File[/etc/calico/calicoctl.cfg]
- Package[containerd]
- Concat[/etc/apt/sources.list.d/component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- Sysctl::Conffile[kube_proxy_conntrack]
- Exec[/sbin/modprobe overlay]
- Exec[Generate cert mlserve__rsyslog refresh]
- File[/etc/modules-load.d/overlay.conf]
- File[/lib/systemd/system/rsyslog-release-deleted-inotify-watches.service]
- File[/etc/systemd/system/kubelet.service.d]
- File[/etc/cni/net.d/istio-kubeconfig]
- Exec[systemd daemon-reload for kube-proxy.service (kube-proxy)]
- File[/etc/kubernetes/pki/mlserve__kubelet_server.chain.pem]
- File[/etc/cni/net.d/calico-kubeconfig]
- Class[Profile::Dragonfly::Dfdaemon]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.csr]
- Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.timer (rsyslog-release-deleted-inotify-watches.timer)]
- File[/etc/ferm/conf.d/10_calico_typha]
- Exec[Generate cert mlserve__istio-cni]
- Class[Containerd::Nerdctl]
- File[/etc/cfssl/csr/mlserve__system_kube-proxy.csr]
- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet]
- Package[linux-cpupower]
- Exec[apt_pin_apt_pin_linux-6.16-trixie_trixie-bpo]
- Service[kube-proxy]
- File[/etc/udev/rules.d/70-render.rules]
- Cfssl::Cert[mlserve__rsyslog]
- Apt::Package_from_bpo[firmware-amd-graphics-trixie-bpo]
- Exec[apt_package_from_component_kubernetes131]
- Exec[systemd daemon-reload for rsyslog-imfile-remedy.timer (rsyslog-imfile-remedy.timer)]
- Concat_fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/apt/preferences.d/apt_pin_firmware_amd_graphics_trixie_bpo_trixie_bpo.pref]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.pem]
- Systemd::Syslog[rsyslog-release-deleted-inotify-watches]
- File[/etc/cfssl/csr/mlserve__kubelet_server.csr]
- Concat::Fragment[component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/kubernetes/pki/mlserve__calico-cni.chain.pem]
- Systemd::Override[ferm-service-auto-restart]
- Class[Calico]
- Exec[apt_repository_component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- K8s::Package[proxy]
- File[/etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.csr]
- File[/etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf]
- Ferm::Service[dragonfly_dfget]
- Node[__node_regexp__ml-serve1001-910-5.eqiad.]
- Cfssl::Csr[/etc/cfssl/csr/discovery__ml-serve1014_eqiad_wmnet.csr]
- K8s::Kubeconfig[/etc/kubernetes/kubelet.conf]
- Rsyslog::Conf[input-file-kubernetes-json]
- Package[kubernetes-node]
- Systemd::Timer::Job[rsyslog-imfile-remedy]
- File[/etc/ferm/conf.d/10_kubelet-http]
- File[/var/lib/kubelet/config.json]
- File[/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.pem]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__calicoctl.chain.pem]
- File[/etc/default/kube-proxy]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__system_kube-proxy.csr]
- Exec[Generate cert mlserve__istio-cni refresh on intermediate ca change]
- Rsyslog::Conf[rsyslog-release-deleted-inotify-watches]
- Sysctl::Parameters[increase_inotify_limits]
- File[/etc/default/cpupower]
- Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Concat[/etc/apt/sources.list.d/component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- Concat_file[/etc/apt/sources.list.d/component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- Systemd::Unit[rsyslog-imfile-remedy.timer]
- File[/etc/kubernetes/pki/mlserve__calicoctl.chained.pem]
- File[/etc/kubernetes/proxy.conf]
- File[/etc/cfssl/csr/mlserve__calicoctl.csr]
- File[/usr/local/sbin/rsyslog-release-deleted-inotify-watches]
- Package[amd-k8s-node-labeller]
- K8s::Kubeconfig[/etc/calico/calicoctl-kubeconfig]
- Firewall::Service[dragonfly_dfget]
- Package[amd-k8s-device-plugin]
- Exec[cpupower_reload]
- Exec[Generate cert mlserve__calico-cni]
- Apt::Package_from_component[kubernetes131]
- File[/etc/dragonfly/dfget.yml]
- Service[dragonfly-dfdaemon]
- File[/etc/kubernetes/pki]
- File[/etc/containerd]
- File[/etc/systemd/system/ferm.service.d/ferm-service-auto-restart.conf]
- Class[K8s::Kubelet]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.chain.pem]
- Cfssl::Cert[mlserve__system_kube-proxy]
- Class[Wmflib::Service::Catalog]
- Apt::Package_from_component[calico329]
- Exec[Generate cert mlserve__calico-cni refresh]
- Class[K8s::Base_dirs]
- File[/etc/udev/rules.d/75-kube_proxy_conntrack.rules]
- Systemd::Unit[ferm-ferm-service-auto-restart]
- Exec[systemd daemon-reload for rsyslog-imfile-remedy.service (rsyslog-imfile-remedy.service)]
- File[/etc/kubernetes/pki/mlserve__amdgpu-node-labeller-key.pem]
- Class[Profile::Calico::Kubernetes]
- File[/etc/ferm/conf.d/10_dragonfly_dfget]
- Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.service (rsyslog-release-deleted-inotify-watches.service)]
- Exec[Generate cert mlserve__system_kube-proxy refresh]
- Sysctl::Parameters[kube_proxy_conntrack]
- Package[dragonfly-dfget]
- Service[cpupower]
- Ferm::Service[kubelet-http]
- Ferm::Service[calico_typha]
- Exec[systemd daemon-reload for amd-k8s-node-labeller.service (amd-k8s-node-labeller-amd-devplugin-after-labeller)]
- File[/etc/default/wikimedia-lvs-realserver]
- Concat_file[/etc/apt/sources.list.d/component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- K8s::Kubelet::Cni[calico]
- Systemd::Service[cpupower]
- File[/etc/calico/pki]
- Cfssl::Cert[mlserve__calico-cni]
- Cfssl::Cert[mlserve__system_node_ml-serve1014_eqiad_wmnet]
- File[/etc/kubernetes/pki/mlserve__kubelet_server.chained.pem]
- Exec[apt_repository_component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- Apt::Package_from_component[istio115]
- Class[Toil::Rsyslog_imfile_remedy]
- Kmod::Module[overlay]
- Exec[Generate cert mlserve__amdgpu-node-labeller]
- Systemd::Service[rsyslog-release-deleted-inotify-watches]
- File[/etc/kubernetes/pki/mlserve__calicoctl.pem]
- Apt::Repository[component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/cfssl/csr/mlserve__calico-cni.csr]
- Concat::Fragment[component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Systemd::Override[container-runtime]
- Class[Base::Sysctl::Inotify]
- Rsyslog::Conf[output_kafka_k8s]
- File[/etc/apt/preferences.d/apt_pin_linux_6_16_trixie_trixie_bpo.pref]
- Group[kube]
- Sysctl::Conffile[ipv6-fowarding-accept-ra]
- K8s::Kubeconfig[/etc/kubernetes/proxy.conf]
- Package[calicoctl]
- File[/etc/kubernetes/pki/mlserve__calico-cni.csr]
- Class[Profile::Rsyslog::Kubernetes]
- File[/etc/amd]
- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet refresh on intermediate ca change]
- Apt::Pin[apt_pin_firmware-amd-graphics-trixie-bpo_trixie-bpo]
- Exec[renew certificate - mlserve__kubelet_server]
- File[/etc/nerdctl/nerdctl.toml]
- File[/etc/systemd/system/kube-proxy.service.d]
- Exec[Generate cert mlserve__kubelet_server]
- Exec[Generate cert discovery__ml-serve1014_eqiad_wmnet]
- Package[wikimedia-lvs-realserver]
- Class[Dragonfly::Dfdaemon]
- Sysctl::Conffile[kube_proxy_icmp]
- K8s::Kubeconfig[/etc/cni/net.d/calico-kubeconfig]
- Exec[exec-apt-get-update-firmware-amd-graphics-trixie-bpo_trixie-bpo]
- File[/etc/kubernetes/pki/mlserve__istio-cni.csr]
- File[/etc/cni/net.d]
- File[/etc/rsyslog.d/40-rsyslog-release-deleted-inotify-watches.conf]
- Exec[Generate cert mlserve__kubelet_server refresh]
- File[/etc/amd/node-labeller-kubeconfig]
- File[/etc/nerdctl]
- File[/etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.chained.pem]
- File[/var/run/kubernetes]
- Firewall::Service[calico-typha]
- File[/etc/kubernetes/pki/mlserve__istio-cni-key.pem]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__rsyslog.csr]
- Class[K8s::Proxy]
- File[/etc/dragonfly]
- Cfssl::Cert[discovery__ml-serve1014_eqiad_wmnet]
- File[/lib/systemd/system/rsyslog-release-deleted-inotify-watches.timer]
- Package[calico-cni]
- Concat_fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Class[Profile::Rsyslog::Shellbox]
- Concat::Fragment[component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Concat_fragment[component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet-key.pem]
- Exec[Generate cert mlserve__amdgpu-node-labeller refresh on intermediate ca change]
- File[/etc/ferm/conf.d/10_calico-bird]
- Concat_fragment[component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Exec[systemd daemon-reload for kubelet.service (kubelet-container-runtime)]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.pem]
- File[/etc/cni]
- Class[Apparmor]
- Exec[apt_repository_component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/default/kubelet]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chain.pem]
- File[/etc/sysctl.d/70-increase_inotify_limits.conf]
- File[/etc/kubernetes/pki/mlserve__calico-cni.chained.pem]
- Ferm::Service[calico-bird]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__kubelet_server.chain.pem]
- Exec[Generate cert mlserve__calico-cni refresh on intermediate ca change]
- Concat_fragment[component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- Class[Lvs::Realserver]
- Systemd::Unit[rsyslog-release-deleted-inotify-watches.service]
- Exec[renew certificate - mlserve__calicoctl]
- File[/etc/rsyslog.d/35-output-kafka-k8s.conf]
- Cfssl::Cert[mlserve__kubelet_server]
- Systemd::Unit[kube-proxy]
- File[/usr/libexec/cpupower]
- Class[Profile::Kubernetes::Node]
- Sysctl::Conffile[increase_inotify_limits]
- Class[Containerd]
- Package[rsyslog-kubernetes]
- Exec[apt_package_from_component_istio115]
- File[/etc/rsyslog.d/10-kubernetes-node-filters.conf]
- Class[Cpufrequtils]
- Systemd::Unit[rsyslog-imfile-remedy.service]
- Systemd::Unit[kubelet-container-runtime]
- Exec[Generate cert mlserve__system_kube-proxy]
- File[/etc/cfssl/ssl/mlserve__rsyslog]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.csr]
- File[/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.chained.pem]
- Systemd::Override[amd-devplugin-after-labeller]
- Exec[Generate cert mlserve__kubelet_server refresh on intermediate ca change]
- Exec[Generate cert mlserve__calicoctl]
- File[/etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.chain.pem]
- Class[K8s::Clusters]
- File[/etc/kubernetes/kube-proxy-config.yaml]
- File[/etc/kubernetes]
- File[/etc/rsyslog.d/09-kubernetes.conf]
- Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-auto-restart)]
- Package[dragonfly-dfdaemon]
- Exec[create chained cert /etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chain.pem]
- Class[Profile::Kubernetes::Container_runtime]
- Rsyslog::Conf[kubernetes-node-filters]
- Exec[Generate cert discovery__ml-serve1014_eqiad_wmnet refresh]
- Package[crictl]
- Apt::Repository[component-kubernetes131-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- Concat_fragment[component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Exec[Generate cert mlserve__calicoctl refresh]
- Exec[renew certificate - mlserve__rsyslog]
- Service[rsyslog-release-deleted-inotify-watches.timer]
- File[/etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.pem]
- File[/etc/sysctl.d/75-kube_proxy_icmp.conf]
- Exec[systemd daemon-reload for cpupower.service (cpupower)]
- File[/var/log/rsyslog-release-deleted-inotify-watches]
- File[/etc/kubernetes/pki/mlserve__amdgpu-node-labeller.csr]
- K8s::Package[kubelet]
- File[/etc/kubernetes/pki/mlserve__kubelet_server-key.pem]
- Systemd::Unit[rsyslog-release-deleted-inotify-watches.timer]
- Exec[exec-apt-get-update-linux-6.16-trixie_trixie-bpo]
- Class[Role::Ml_k8s::Worker]
- User[kube]
- Systemd::Timer[rsyslog-release-deleted-inotify-watches]
- K8s::Kubeconfig[/etc/cni/net.d/istio-kubeconfig]
- File[/etc/kubernetes/pki/mlserve__amdgpu-node-labeller.chained.pem]
- Concat::Fragment[component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.chained.pem]
- File[/etc/kubernetes/kubelet.conf]
- File[/etc/rsyslog.d/20-shellbox.conf]
- Logrotate::Conf[rsyslog-release-deleted-inotify-watches]
- Exec[apt_package_from_component_calico329]
- Exec[Generate cert mlserve__istio-cni refresh]
- File[/etc/cfssl/csr/discovery__ml-serve1014_eqiad_wmnet.csr]
- Exec[Generate cert mlserve__rsyslog]
- Udev::Rule[kube_proxy_conntrack]
- Sysctl::Parameters[ipv6-fowarding-accept-ra]
- File[/etc/dragonfly/dfdaemon.yml]
- Systemd::Timer[rsyslog-imfile-remedy]
- Exec[Generate cert mlserve__amdgpu-node-labeller refresh]
- File[/etc/kubernetes/pki/mlserve__amdgpu-node-labeller.pem]
- Docker::Credentials[/var/lib/kubelet/config.json]
- File[/etc/kubernetes/pki/mlserve__calicoctl-key.pem]
- Exec[Generate cert mlserve__calicoctl refresh on intermediate ca change]
- File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem]
- File[/etc/kubernetes/pki/mlserve__calicoctl.chain.pem]
- File[/etc/kubernetes/pki/mlserve__kubelet_server.pem]
- File[/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.chain.pem]
- File[/etc/calico/calicoctl-kubeconfig]
- File[/etc/kubernetes/pki/mlserve__amdgpu-node-labeller.chain.pem]
- Package[nerdctl]
- File[/etc/systemd/system/amd-k8s-node-labeller.service.d]
- Package[linux-image-6.16.3+deb13-amd64]
- Apt::Package_from_bpo[linux-6.16-trixie]
- File[/etc/kubernetes/kubelet-config.yaml]
- Motd::Script[ml_k8s::worker]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__istio-cni.csr]
- Rsyslog::Conf[kubernetes]
- File[/etc/rsyslog.d/08-input-file-kubernetes-json.conf]
- Cfssl::Cert[mlserve__calicoctl]
- Exec[renew certificate - mlserve__system_kube-proxy]
- File[/lib/systemd/system/rsyslog-imfile-remedy.service]
- Cfssl::Cert[mlserve__amdgpu-node-labeller]
- Class[Profile::Lvs::Realserver]
- Exec[Generate cert mlserve__system_kube-proxy refresh on intermediate ca change]
- File[/etc/containerd/config.toml]
- File[/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet-key.pem]
- Cfssl::Cert[mlserve__istio-cni]
- Concat_file[/etc/apt/sources.list.d/component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- Service[rsyslog-imfile-remedy.timer]
- Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- File[/etc/systemd/system/kube-proxy.service.d/puppet-override.conf]
- Systemd::Timer::Job[rsyslog-release-deleted-inotify-watches]
- File[/etc/cfssl/csr/mlserve__rsyslog.csr]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy-key.pem]
- K8s::Kubeconfig[/etc/amd/node-labeller-kubeconfig]
- Exec[renew certificate - mlserve__calico-cni]
- File[/lib/systemd/system/cpupower.service]
- File[/etc/udev/rules.d/70-kfd.rules]
- Package[apparmor]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__amdgpu-node-labeller.chain.pem]
- Class[Containerd::Configuration]
- Package[socat]
- File[/etc/systemd/system/kubelet.service.d/container-runtime.conf]
- File[/etc/cfssl/csr/mlserve__amdgpu-node-labeller.csr]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__kubelet_server.csr]
- Systemd::Service[kube-proxy]
- Class[K8s::Kubelet::Cni::Base]
- Sysctl::Parameters[kube_proxy_icmp]
- File[/etc/sysctl.d/70-ipv6-fowarding-accept-ra.conf]
- File[/lib/systemd/system/rsyslog-imfile-remedy.timer]
- File[/etc/calico]
- File[/etc/logrotate.d/rsyslog-release-deleted-inotify-watches]
- Exec[renew certificate - mlserve__system_node_ml-serve1014_eqiad_wmnet]
- File[/etc/cfssl/csr/mlserve__istio-cni.csr]
- Apt::Repository[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- Package[istio-cni]
- File[/etc/kubernetes/pki/mlserve__calicoctl.csr]
- File[/etc/apparmor.d/abstractions]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.chain.pem]
- File[/etc/sysctl.d/75-kube_proxy_conntrack.conf]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__amdgpu-node-labeller.csr]
- File[/var/lib/kubelet]
- Rsyslog::Conf[imfile]
- Rsyslog::Input::File[kubernetes-json]
- Systemd::Unit[amd-k8s-node-labeller-amd-devplugin-after-labeller]
- File[/etc/update-motd.d/05-ml-k8s--worker]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__calico-cni.csr]
- File[/etc/kubernetes/pki/mlserve__istio-cni.chained.pem]
- File[/etc/kubernetes/pki/mlserve__kubelet_server.csr]
- File[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr]
- File[/etc/cni/net.d/10-calico.conflist]
- File[/etc/kubernetes/pki/mlserve__calico-cni.pem]
- Exec[renew certificate - discovery__ml-serve1014_eqiad_wmnet]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__istio-cni.chain.pem]
- Apt::Pin[apt_pin_linux-6.16-trixie_trixie-bpo]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog-key.pem]
- Exec[create chained cert /etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.chain.pem]
- File[/etc/apt/sources.list.d/component-calico329-apt.wikimedia.org-wikimedia-trixie-wikimedia.list]
- Systemd::Service[rsyslog-imfile-remedy]
- Exec[apt_pin_apt_pin_firmware-amd-graphics-trixie-bpo_trixie-bpo]
- File[/etc/kubernetes/pki/mlserve__istio-cni.pem]
- Exec[Generate cert mlserve__rsyslog refresh on intermediate ca change]
- Exec[renew certificate - mlserve__amdgpu-node-labeller]
- Motd::Message[ml_k8s::worker]
- File[/etc/kubernetes/pki/mlserve__calico-cni-key.pem]
- Rsyslog::Conf[shellbox]
- Concat[/etc/apt/sources.list.d/component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources]
- Service[apparmor]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr]
- Class[Profile::Lvs::Configuration]
- Exec[create chained cert /etc/kubernetes/pki/mlserve__system_kube-proxy.chain.pem]
Resources only in the old catalog
- Motd::Script[ml_k8s::insetup_gpu]
- Class[Role::Ml_k8s::Insetup_gpu]
- Motd::Message[ml_k8s::insetup_gpu]
- Node[__node_regexp__ml-serve10145.eqiad.]
- File[/etc/update-motd.d/05-ml-k8s--insetup-gpu]
Resources modified
- Exec[create chained cert /etc/kubernetes/pki/mlserve__calico-cni.chain.pem]
- Parameters differences:
--- Exec[create chained cert /etc/kubernetes/pki/mlserve__calico-cni.chain.pem].orig +++ Exec[create chained cert /etc/kubernetes/pki/mlserve__calico-cni.chain.pem] + require => Exec[Generate cert mlserve__calico-cni refresh on intermediate ca change] + unless => /usr/bin/test "$(/bin/cat /etc/kubernetes/pki/mlserve__calico-cni.pem /etc/kubernetes/pki/mlserve__calico-cni.chain.pem | sha512sum)" == "$(/bin/cat /etc/kubernetes/pki/mlserve__calico-cni.chained.pem | sha512sum)" + subscribe => ['Exec[renew certificate - mlserve__calico-cni]', 'File[/etc/kubernetes/pki/mlserve__calico-cni.chain.pem]', 'File[/etc/kubernetes/pki/mlserve__calico-cni.pem]'] + command => /bin/cat /etc/kubernetes/pki/mlserve__calico-cni.pem /etc/kubernetes/pki/mlserve__calico-cni.chain.pem > /etc/kubernetes/pki/mlserve__calico-cni.chained.pem
- File[/etc/systemd/system/kubelet.service.d]
- Parameters differences:
--- File[/etc/systemd/system/kubelet.service.d].orig +++ File[/etc/systemd/system/kubelet.service.d] + owner => root + group => root + mode => 0555 + ensure => directory
- Exec[systemd daemon-reload for kube-proxy.service (kube-proxy)]
- Parameters differences:
--- Exec[systemd daemon-reload for kube-proxy.service (kube-proxy)].orig +++ Exec[systemd daemon-reload for kube-proxy.service (kube-proxy)] + notify => ['Service[kube-proxy]'] + refreshonly => True + command => /bin/systemctl daemon-reload
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.csr]
- Parameters differences:
--- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.csr].orig +++ File[/etc/kubernetes/pki/mlserve__system_kube-proxy.csr] + owner => kube + group => root + mode => 0440 + ensure => file
- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet]
- Parameters differences:
--- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet].orig +++ Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet] + command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve /etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet + require => Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr] + notify => ['Service[kubelet]'] + unless => /usr/bin/test "$(/usr/bin/openssl x509 -in /etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.pem -noout -pubkey 2>&1)" == "$(/usr/bin/openssl pkey -pubout -in /etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet-key.pem 2>&1)" + environment => ['GODEBUG=x509ignoreCN=0']
- Package[linux-cpupower]
- Parameters differences:
--- Package[linux-cpupower].orig +++ Package[linux-cpupower] + ensure => installed + provider => apt
- Exec[apt_pin_apt_pin_linux-6.16-trixie_trixie-bpo]
- Parameters differences:
--- Exec[apt_pin_apt_pin_linux-6.16-trixie_trixie-bpo].orig +++ Exec[apt_pin_apt_pin_linux-6.16-trixie_trixie-bpo] + refreshonly => True + command => /usr/bin/apt-get update
- Class[Calico]
- Parameters differences:
--- Class[Calico].orig +++ Class[Calico] + auth_cert => {'cert': '/etc/kubernetes/pki/mlserve__calicoctl.pem', 'key': '/etc/kubernetes/pki/mlserve__calicoctl-key.pem', 'chain': '/etc/kubernetes/pki/mlserve__calicoctl.chain.pem', 'chained': '/etc/kubernetes/pki/mlserve__calicoctl.chained.pem'} + calicoctl_username => calicoctl + version => 3.29 + master_fqdn => ml-ctrl.svc.eqiad.wmnet- Ferm::Service[dragonfly_dfget]
- Parameters differences:
--- Ferm::Service[dragonfly_dfget].orig +++ Ferm::Service[dragonfly_dfget] + proto => tcp + notrack => False + ensure => present + prio => 10 + port => 15001 + src_sets => ['DOMAIN_NETWORKS'] + desc =>
- Exec[Generate cert mlserve__istio-cni refresh on intermediate ca change]
- Parameters differences:
--- Exec[Generate cert mlserve__istio-cni refresh on intermediate ca change].orig +++ Exec[Generate cert mlserve__istio-cni refresh on intermediate ca change] + subscribe => File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem] + refreshonly => True + environment => ['GODEBUG=x509ignoreCN=0'] + command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve /etc/cfssl/csr/mlserve__istio-cni.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__istio-cni
- K8s::Kubelet::Cni[calico]
- Parameters differences:
--- K8s::Kubelet::Cni[calico].orig +++ K8s::Kubelet::Cni[calico] + require => ['Class[K8s::Kubelet::Cni::Base]'] + priority => 10 + config => {'name': 'k8s-pod-network', 'cniVersion': '0.3.1', 'plugins': [{'type': 'calico', 'log_level': 'info', 'datastore_type': 'kubernetes', 'mtu': 1460, 'ipam': {'type': 'calico-ipam', 'assign_ipv4': 'true', 'assign_ipv6': 'true'}, 'policy': {'type': 'k8s'}, 'kubernetes': {'kubeconfig': '/etc/cni/net.d/calico-kubeconfig'}}, {'name': 'istio-cni', 'type': 'istio-cni', 'log_level': 'info', 'kubernetes': {'kubeconfig': '/etc/cni/net.d/istio-kubeconfig', 'cni_bin_dir': '/opt/cni/bin', 'exclude_namespaces': ['istio-system', 'kube-system', 'knative-serving', 'cert-manager', 'kserve']}}]}- Systemd::Override[container-runtime]
- Parameters differences:
--- Systemd::Override[container-runtime].orig +++ Systemd::Override[container-runtime] + unit => kubelet + ensure => present + restart => True
- Group[kube]
- Parameters differences:
--- Group[kube].orig +++ Group[kube] + system => True + ensure => present
- Exec[renew certificate - mlserve__kubelet_server]
- Parameters differences:
--- Exec[renew certificate - mlserve__kubelet_server].orig +++ Exec[renew certificate - mlserve__kubelet_server] + command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve -profile server /etc/kubernetes/pki/mlserve__kubelet_server.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__kubelet_server + require => Exec[Generate cert mlserve__kubelet_server] + notify => ['Service[kubelet]'] + unless => /usr/bin/openssl x509 -in /etc/kubernetes/pki/mlserve__kubelet_server.pem -checkend 952200 + environment => ['GODEBUG=x509ignoreCN=0']
- File[/etc/ferm/conf.d/10_calico-bird]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_calico-bird].orig +++ File[/etc/ferm/conf.d/10_calico-bird] + group => root + mode => 0400 + ensure => present + tag => ferm + require => File[/etc/ferm/conf.d] + owner => root + notify => Service[ferm]
- Content differences:
--- /etc/ferm/conf.d/10_calico-bird.orig +++ /etc/ferm/conf.d/10_calico-bird @@ -0,0 +1,6 @@ +# Autogenerated by puppet. DO NOT EDIT BY HAND! +# +# +&R_SERVICE(tcp, 179, ($NETWORK_INFRA 10.64.155.1)); + +
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chain.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chain.pem].orig +++ File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog.chain.pem] + group => root + mode => 0440 + ensure => file + source => puppet:///modules/profile/pki/intermediates/mlserve-cert.pem + owner => root
- Exec[renew certificate - mlserve__calicoctl]
- Parameters differences:
--- Exec[renew certificate - mlserve__calicoctl].orig +++ Exec[renew certificate - mlserve__calicoctl] + require => Exec[Generate cert mlserve__calicoctl] + unless => /usr/bin/openssl x509 -in /etc/kubernetes/pki/mlserve__calicoctl.pem -checkend 952200 + environment => ['GODEBUG=x509ignoreCN=0'] + command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve /etc/kubernetes/pki/mlserve__calicoctl.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__calicoctl
- Systemd::Unit[kube-proxy]
- Parameters differences:
--- Systemd::Unit[kube-proxy].orig +++ Systemd::Unit[kube-proxy] + override => True + ensure => present + override_filename => puppet-override.conf + restart => True + require => ['Class[Systemd]'] + unit => kube-proxy
- Exec[Generate cert mlserve__calicoctl]
- Parameters differences:
--- Exec[Generate cert mlserve__calicoctl].orig +++ Exec[Generate cert mlserve__calicoctl] + require => Cfssl::Csr[/etc/cfssl/csr/mlserve__calicoctl.csr] + unless => /usr/bin/test "$(/usr/bin/openssl x509 -in /etc/kubernetes/pki/mlserve__calicoctl.pem -noout -pubkey 2>&1)" == "$(/usr/bin/openssl pkey -pubout -in /etc/kubernetes/pki/mlserve__calicoctl-key.pem 2>&1)" + environment => ['GODEBUG=x509ignoreCN=0'] + command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve /etc/cfssl/csr/mlserve__calicoctl.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__calicoctl
- Exec[systemd daemon-reload for cpupower.service (cpupower)]
- Parameters differences:
--- Exec[systemd daemon-reload for cpupower.service (cpupower)].orig +++ Exec[systemd daemon-reload for cpupower.service (cpupower)] + notify => ['Service[cpupower]'] + refreshonly => True + command => /bin/systemctl daemon-reload
- User[kube]
- Parameters differences:
--- User[kube].orig +++ User[kube] + shell => /usr/sbin/nologin + system => True + home => /nonexistent + ensure => present + gid => kube
- File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem]
- Parameters differences:
--- File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem].orig +++ File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem] + group => root + mode => 0440 + ensure => file + source => puppet:///modules/profile/pki/intermediates/mlserve-cert.pem + owner => root
- File[/etc/kubernetes/pki/mlserve__calicoctl.chain.pem]
- Parameters differences:
--- File[/etc/kubernetes/pki/mlserve__calicoctl.chain.pem].orig +++ File[/etc/kubernetes/pki/mlserve__calicoctl.chain.pem] + group => root + mode => 0440 + ensure => file + source => puppet:///modules/profile/pki/intermediates/mlserve-cert.pem + owner => root
- File[/etc/kubernetes/kubelet-config.yaml]
- Parameters differences:
--- File[/etc/kubernetes/kubelet-config.yaml].orig +++ File[/etc/kubernetes/kubelet-config.yaml] + group => kube + mode => 0400 + ensure => file + require => K8s::Package[kubelet] + owner => kube + notify => Service[kubelet]
- Content differences:
--- /etc/kubernetes/kubelet-config.yaml.orig +++ /etc/kubernetes/kubelet-config.yaml @@ -0,0 +1,25 @@ +--- +apiVersion: kubelet.config.k8s.io/v1beta1 +kind: KubeletConfiguration +tlsPrivateKeyFile: "/etc/kubernetes/pki/mlserve__kubelet_server-key.pem" +tlsCertFile: "/etc/kubernetes/pki/mlserve__kubelet_server.chained.pem" +clusterDomain: cluster.local +clusterDNS: +- 10.67.0.3 +authentication: + anonymous: + enabled: false + webhook: + enabled: true + x509: + clientCAFile: "/etc/kubernetes/pki/mlserve__kubelet_server.chain.pem" +authorization: + mode: Webhook +cgroupDriver: systemd +evictionHard: + imagefs.available: 15% + memory.available: 300M + nodefs.available: 10% + nodefs.inodesFree: 5% +containerRuntimeEndpoint: unix:///run/containerd/containerd.sock +seccompDefault: true
- Systemd::Timer::Job[rsyslog-release-deleted-inotify-watches]
- Parameters differences:
--- Systemd::Timer::Job[rsyslog-release-deleted-inotify-watches].orig +++ Systemd::Timer::Job[rsyslog-release-deleted-inotify-watches] + user => root + monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state + send_mail_only_on_error => True + environment => {} + ignore_errors => False + send_mail_to => root@ml-serve1014.eqiad.wmnet + syslog_match_startswith => True + command => /usr/local/sbin/rsyslog-release-deleted-inotify-watches + logfile_basedir => /var/log + logging_enabled => True + logfile_group => root + logfile_perms => all + syslog_force_stop => True + success_exit_status => [] + ensure => absent + fixed_random_delay => False + private_tmp => False + interval => {'start': 'OnCalendar', 'interval': '*-*-* *:7:00'} + send_mail => False + monitoring_enabled => False + description => Restart rsyslog to release inotify watches of deleted container logs + logfile_name => syslog.log + monitoring_contact_groups => admins- Package[socat]
- Parameters differences:
--- Package[socat].orig +++ Package[socat] + ensure => installed + provider => apt
- File[/etc/systemd/system/kubelet.service.d/container-runtime.conf]
- Parameters differences:
--- File[/etc/systemd/system/kubelet.service.d/container-runtime.conf].orig +++ File[/etc/systemd/system/kubelet.service.d/container-runtime.conf] + group => root + mode => 0444 + ensure => present + owner => root + notify => Exec[systemd daemon-reload for kubelet.service (kubelet-container-runtime)]
- Content differences:
--- /etc/systemd/system/kubelet.service.d/container-runtime.conf.orig +++ /etc/systemd/system/kubelet.service.d/container-runtime.conf @@ -0,0 +1,3 @@ +[Unit] +After=containerd.service +Requires=containerd.service
- Apt::Repository[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia]
- Parameters differences:
--- Apt::Repository[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia].orig +++ Apt::Repository[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia] + allow_releaseinfo_change => False + source => True + ensure => present + trust_repo => False + keyfile => puppet:///modules/install_server/autoinstall/keyring/wikimedia-archive-keyring.gpg + uri => http://apt.wikimedia.org/wikimedia + dist => trixie-wikimedia + components => component/istio115 + bin => True
- File[/etc/kubernetes/pki/mlserve__calicoctl.csr]
- Parameters differences:
--- File[/etc/kubernetes/pki/mlserve__calicoctl.csr].orig +++ File[/etc/kubernetes/pki/mlserve__calicoctl.csr] + owner => root + group => root + mode => 0440 + ensure => file
- Rsyslog::Input::File[kubernetes-json]
- Parameters differences:
--- Rsyslog::Input::File[kubernetes-json].orig +++ Rsyslog::Input::File[kubernetes-json] + ensure => present + syslog_tag => kubernetes + syslog_tag_prefix => input-file + addmetadata => on + reopen_on_truncate => on + priority => 8 + path => /var/log/containers/*.log + addceetag => on
- Exec[renew certificate - discovery__ml-serve1014_eqiad_wmnet]
- Parameters differences:
--- Exec[renew certificate - discovery__ml-serve1014_eqiad_wmnet].orig +++ Exec[renew certificate - discovery__ml-serve1014_eqiad_wmnet] + command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label discovery /etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet + require => Exec[Generate cert discovery__ml-serve1014_eqiad_wmnet] + notify => ['Service[dragonfly-dfdaemon]'] + unless => /usr/bin/openssl x509 -in /etc/dragonfly/discovery__ml-serve1014_eqiad_wmnet.pem -checkend 952200 + environment => ['GODEBUG=x509ignoreCN=0']
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog-key.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog-key.pem].orig +++ File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog-key.pem] + group => root + mode => 0440 + ensure => file + owner => root + show_diff => False + backup => False
- Exec[renew certificate - mlserve__amdgpu-node-labeller]
- Parameters differences:
--- Exec[renew certificate - mlserve__amdgpu-node-labeller].orig +++ Exec[renew certificate - mlserve__amdgpu-node-labeller] + require => Exec[Generate cert mlserve__amdgpu-node-labeller] + unless => /usr/bin/openssl x509 -in /etc/kubernetes/pki/mlserve__amdgpu-node-labeller.pem -checkend 952200 + environment => ['GODEBUG=x509ignoreCN=0'] + command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ml-serve1014.eqiad.wmnet.pem -label mlserve /etc/kubernetes/pki/mlserve__amdgpu-node-labeller.csr | /usr/bin/cfssljson -bare /etc/kubernetes/pki/mlserve__amdgpu-node-labeller
- Service[apparmor]
- Parameters differences:
--- Service[apparmor].orig +++ Service[apparmor] + require => Package[apparmor] + hasstatus => True + ensure => running + hasrestart => True
- Rsyslog::Conf[shellbox]
- Parameters differences:
--- Rsyslog::Conf[shellbox].orig +++ Rsyslog::Conf[shellbox] + mode => 0444 + priority => 20 + source => puppet:///modules/profile/rsyslog/shellbox.rsyslog.conf + ensure => present
- Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr].orig +++ Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr] + ensure => present + common_name => system:node:ml-serve1014.eqiad.wmnet + key => {'algo': 'ecdsa', 'size': 256} + hosts => [] + names => [{'organisation': 'system:nodes'}]- Package[containerd]
- Parameters differences:
--- Package[containerd].orig +++ Package[containerd] + ensure => installed + provider => apt
- Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.timer (rsyslog-release-deleted-inotify-watches.timer)]
- Parameters differences:
--- Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.timer (rsyslog-release-deleted-inotify-watches.timer)].orig +++ Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.timer (rsyslog-release-deleted-inotify-watches.timer)] + refreshonly => True + command => /bin/systemctl daemon-reload
- Service[kube-proxy]
- Parameters differences:
--- Service[kube-proxy].orig +++ Service[kube-proxy] + enable => True + ensure => running
- Apt::Package_from_bpo[firmware-amd-graphics-trixie-bpo]
- Parameters differences:
--- Apt::Package_from_bpo[firmware-amd-graphics-trixie-bpo].orig +++ Apt::Package_from_bpo[firmware-amd-graphics-trixie-bpo] + priority => 1001 + ensure_packages => True + distro => trixie + packages => {'firmware-amd-graphics': '20251021-1~bpo13+1'}- File[/etc/modprobe.d/blacklist-wmf_overlay.conf]
- Parameters differences:
--- File[/etc/modprobe.d/blacklist-wmf_overlay.conf].orig +++ File[/etc/modprobe.d/blacklist-wmf_overlay.conf] @@ - ensure => present + ensure => absent
- Content differences:
--- /etc/modprobe.d/blacklist-wmf_overlay.conf.orig +++ /etc/modprobe.d/blacklist-wmf_overlay.conf @@ -1,7 +1,3 @@ # wmf_overlay - blacklisted kernel modules # This file is managed by Puppet # -blacklist overlay -install overlay /bin/true -blacklist overlayfs -install overlayfs /bin/true
- File[/etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf]
- Parameters differences:
--- File[/etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf].orig +++ File[/etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf] + group => root + mode => 0444 + ensure => present + owner => root + notify => Exec[systemd daemon-reload for amd-k8s-node-labeller.service (amd-k8s-node-labeller-amd-devplugin-after-labeller)]
- Content differences:
--- /etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf.orig +++ /etc/systemd/system/amd-k8s-node-labeller.service.d/amd-devplugin-after-labeller.conf @@ -0,0 +1,3 @@ +[Unit] +After=amd-k8s-device-plugin.service +Requires=amd-k8s-device-plugin.service
- K8s::Kubeconfig[/etc/kubernetes/kubelet.conf]
- Parameters differences:
--- K8s::Kubeconfig[/etc/kubernetes/kubelet.conf].orig +++ K8s::Kubeconfig[/etc/kubernetes/kubelet.conf] + auth_cert => {'cert': '/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.pem', 'key': '/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet-key.pem', 'chain': '/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.chain.pem', 'chained': '/etc/kubernetes/pki/mlserve__system_node_ml-serve1014_eqiad_wmnet.chained.pem'} + group => kube + mode => 0400 + ensure => present + owner => kube + master_host => ml-ctrl.svc.eqiad.wmnet + require => ['Class[K8s::Base_dirs]'] + username => default-auth- Rsyslog::Conf[input-file-kubernetes-json]
- Parameters differences:
--- Rsyslog::Conf[input-file-kubernetes-json].orig +++ Rsyslog::Conf[input-file-kubernetes-json] + require => Rsyslog::Conf[imfile] + priority => 8 + mode => 0444 + ensure => present
- File[/etc/ferm/conf.d/10_kubelet-http]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_kubelet-http].orig +++ File[/etc/ferm/conf.d/10_kubelet-http] + group => root + mode => 0400 + ensure => present + tag => ferm + require => File[/etc/ferm/conf.d] + owner => root + notify => Service[ferm]
- Content differences:
--- /etc/ferm/conf.d/10_kubelet-http.orig +++ /etc/ferm/conf.d/10_kubelet-http @@ -0,0 +1,6 @@ +# Autogenerated by puppet. DO NOT EDIT BY HAND! +# +# +&R_SERVICE(tcp, 10250, (@resolve((ml-serve-ctrl1001.eqiad.wmnet ml-serve-ctrl1002.eqiad.wmnet)) @resolve((ml-serve-ctrl1001.eqiad.wmnet ml-serve-ctrl1002.eqiad.wmnet), AAAA))); + +
- Sysctl::Parameters[increase_inotify_limits]
- Parameters differences:
--- Sysctl::Parameters[increase_inotify_limits].orig +++ Sysctl::Parameters[increase_inotify_limits] + priority => 70 + values => {'fs.inotify.max_user_watches': 32768, 'fs.inotify.max_user_instances': 512} + ensure => present- Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Parameters differences:
--- Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header].orig +++ Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header] + source => puppet:///modules/apt/sources-deb822-header.txt + target => /etc/apt/sources.list.d/component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia.sources + order => 01
- File[/etc/dragonfly/dfget.yml]
- Parameters differences:
--- File[/etc/dragonfly/dfget.yml].orig +++ File[/etc/dragonfly/dfget.yml] + group => root + mode => 0644 + ensure => file + owner => root + notify => Service[dragonfly-dfdaemon]
- Content differences:
--- /etc/dragonfly/dfget.yml.orig +++ /etc/dragonfly/dfget.yml @@ -0,0 +1,5 @@ +# List of supernodes in the format +# host:port(default:8002)=weight(default:1) +# FIXME: Figure out how weight is exactly handled, could we use multiple supernodes without split brain? +nodes: + - dragonfly-supernode1001.eqiad.wmnet:8002=1
- Service[dragonfly-dfdaemon]
- Parameters differences:
--- Service[dragonfly-dfdaemon].orig +++ Service[dragonfly-dfdaemon] + ensure => running
- Systemd::Unit[ferm-ferm-service-auto-restart]
- Parameters differences:
--- Systemd::Unit[ferm-ferm-service-auto-restart].orig +++ Systemd::Unit[ferm-ferm-service-auto-restart] + source => puppet:///modules/profile/kubernetes/node/ferm_systemd_override + override => True + override_filename => ferm-service-auto-restart + ensure => present + restart => False + require => ['Class[Systemd]'] + unit => ferm
- Cfssl::Cert[mlserve__system_node_ml-serve1014_eqiad_wmnet]
- Parameters differences:
- Cfssl::Cert[mlserve__system_node_ml-serve1014_eqiad_wmnet]
- Systemd::Unit[ferm-ferm-service-auto-restart]
- Content differences:
- File[/etc/dragonfly/dfget.yml]
- Concat::Fragment[component-istio115-apt.wikimedia.org-wikimedia-trixie-wikimedia-header]
- Content differences:
- File[/etc/ferm/conf.d/10_kubelet-http]
- Rsyslog::Conf[input-file-kubernetes-json]
- Content differences:
- Content differences:
- File[/etc/modprobe.d/blacklist-wmf_overlay.conf]
- Apt::Package_from_bpo[firmware-amd-graphics-trixie-bpo]
- Service[kube-proxy]
- Exec[systemd daemon-reload for rsyslog-release-deleted-inotify-watches.timer (rsyslog-release-deleted-inotify-watches.timer)]
- Package[containerd]
- Cfssl::Csr[/etc/cfssl/csr/mlserve__system_node_ml-serve1014_eqiad_wmnet.csr]
- Rsyslog::Conf[shellbox]
- Service[apparmor]
- Exec[renew certificate - mlserve__amdgpu-node-labeller]
- File[/etc/cfssl/ssl/mlserve__rsyslog/mlserve__rsyslog-key.pem]
- Exec[renew certificate - discovery__ml-serve1014_eqiad_wmnet]
- Rsyslog::Input::File[kubernetes-json]
- File[/etc/kubernetes/pki/mlserve__calicoctl.csr]
- Content differences:
- File[/etc/systemd/system/kubelet.service.d/container-runtime.conf]
- Package[socat]
- Content differences:
- File[/etc/kubernetes/kubelet-config.yaml]
- File[/etc/kubernetes/pki/mlserve__calicoctl.chain.pem]
- File[/etc/kubernetes/pki/mlserve__istio-cni.chain.pem]
- User[kube]
- Exec[systemd daemon-reload for cpupower.service (cpupower)]
- Exec[Generate cert mlserve__calicoctl]
- Systemd::Unit[kube-proxy]
- Exec[renew certificate - mlserve__calicoctl]
- Content differences:
- File[/etc/ferm/conf.d/10_calico-bird]
- Exec[renew certificate - mlserve__kubelet_server]
- Group[kube]
- Systemd::Override[container-runtime]
- K8s::Kubelet::Cni[calico]
- Exec[Generate cert mlserve__istio-cni refresh on intermediate ca change]
- Ferm::Service[dragonfly_dfget]
- Class[Calico]
- Exec[apt_pin_apt_pin_linux-6.16-trixie_trixie-bpo]
- Package[linux-cpupower]
- Exec[Generate cert mlserve__system_node_ml-serve1014_eqiad_wmnet]
- File[/etc/kubernetes/pki/mlserve__system_kube-proxy.csr]
- Exec[systemd daemon-reload for kube-proxy.service (kube-proxy)]
- File[/etc/systemd/system/kubelet.service.d]
- Parameters differences: