--- Class[Adduser].orig
+++ Class[Adduser]
@@
- before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[prometheus-ethtool-exporter]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[dstat]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[atop]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[libicu67]', 'Package[libwsutil12]', 'Package[libwireshark14]', 'Package[libopencsd0]', 'Package[libwiretap11]', 'Package[ruby2.7]', 'Package[python3.9-minimal]', 'Package[python3.9]', 'Package[perl-modules-5.32]', 'Package[libpython3.9]', 'Package[libperl5.32]', 'Package[libpython3.9-minimal]', 'Package[libpython3.9-stdlib]', 'Package[libidn11]', 'Package[libldap-2.4-2]', 'Package[liburing1]', 'Package[libwebp6]', 'Package[libcbor0]', 'Package[libusb-0.1-4]', 'Package[telnet]', 'Package[libruby2.7]', 'Package[libdns-export1110]', 'Package[libisc-export1105]', 'Package[libbpf0]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[ulogd2]', 'Package[conntrack]', 'Package[crictl]', 'Package[containerd]', 'Package[nerdctl]', 'Package[rsyslog-kubernetes]', 'Package[cpufrequtils]', 'Package[apparmor]', 'Package[socat]', 'Package[geoip-bin]', 'Package[mmdb-bin]', 'Package[wikimedia-lvs-realserver]', 'Package[linux-base]', 'Package[linux-image-6.12.74+deb12-amd64]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[kubernetes-node]', 'Package[calicoctl]', 'Package[calico-cni]', 'Package[istio-cni]']
+ before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[prometheus-ethtool-exporter]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[dstat]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[atop]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[libicu67]', 'Package[libwsutil12]', 'Package[libwireshark14]', 'Package[libopencsd0]', 'Package[libwiretap11]', 'Package[ruby2.7]', 'Package[python3.9-minimal]', 'Package[python3.9]', 'Package[perl-modules-5.32]', 'Package[libpython3.9]', 'Package[libperl5.32]', 'Package[libpython3.9-minimal]', 'Package[libpython3.9-stdlib]', 'Package[libidn11]', 'Package[libldap-2.4-2]', 'Package[liburing1]', 'Package[libwebp6]', 'Package[libcbor0]', 'Package[libusb-0.1-4]', 'Package[telnet]', 'Package[libruby2.7]', 'Package[libdns-export1110]', 'Package[libisc-export1105]', 'Package[libbpf0]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[ulogd2]', 'Package[conntrack]', 'Package[crictl]', 'Package[containerd]', 'Package[nerdctl]', 'Package[rsyslog-kubernetes]', 'Package[cpufrequtils]', 'Package[apparmor]', 'Package[socat]', 'Package[geoip-bin]', 'Package[mmdb-bin]', 'Package[wikimedia-lvs-realserver]', 'Package[tcp-mss-clamper]', 'Package[linux-base]', 'Package[linux-image-6.12.74+deb12-amd64]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[kubernetes-node]', 'Package[calicoctl]', 'Package[calico-cni]', 'Package[istio-cni]']
Exec[disable-rp-filter-ipip60]
- Parameters differences:
--- Exec[disable-rp-filter-ipip60].orig
+++ Exec[disable-rp-filter-ipip60]
+ unless => /usr/sbin/sysctl -n net.ipv4.conf.ipip60.rp_filter |grep -- '0'
+ command => /usr/sbin/sysctl -q net.ipv4.conf.ipip60.rp_filter=0
+ require => Interface::Ipip[ipip_ipv6]
- Interface::Ipip[ipip_ipv4]
- Parameters differences:
--- Interface::Ipip[ipip_ipv4].orig
+++ Interface::Ipip[ipip_ipv4]
+ ensure => present
+ interface => ipip0
+ address => 127.0.0.42
+ family => inet
- File[/lib/systemd/system/prometheus_ferm_mss.service]
- Parameters differences:
--- File[/lib/systemd/system/prometheus_ferm_mss.service].orig
+++ File[/lib/systemd/system/prometheus_ferm_mss.service]
+ ensure => absent
+ notify => Exec[systemd daemon-reload for prometheus_ferm_mss.service (prometheus_ferm_mss.service)]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /lib/systemd/system/prometheus_ferm_mss.service.orig
+++ /lib/systemd/system/prometheus_ferm_mss.service
@@ -0,0 +1,8 @@
+[Unit]
+Description=Regular job to collect MSS values of ferm-based hosts
+Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+
+[Service]
+Type=oneshot
+User=root
+ExecStart=/usr/local/bin/prometheus-ferm-mss -o /var/lib/prometheus/node.d/ferm-mss.prom -e
- Exec[ip link set up dev ipip0]
- Parameters differences:
--- Exec[ip link set up dev ipip0].orig
+++ Exec[ip link set up dev ipip0]
+ unless => ip link show ipip0 | grep -q UP
+ path => /bin:/usr/bin
+ returns => [0, 2]
- Ferm::Rule[ip6ip6]
- Parameters differences:
--- Ferm::Rule[ip6ip6].orig
+++ Ferm::Rule[ip6ip6]
+ ensure => present
+ domain => (ip6)
+ table => filter
+ rule => saddr 0100::/64 proto ipv6 ACCEPT;
+ chain => INPUT
+ prio => 10
+ desc =>
- File[/lib/systemd/system/nrpe2nodexp-check_tcp-mss-clamper_status.service]
- Parameters differences:
--- File[/lib/systemd/system/nrpe2nodexp-check_tcp-mss-clamper_status.service].orig
+++ File[/lib/systemd/system/nrpe2nodexp-check_tcp-mss-clamper_status.service]
+ ensure => absent
+ notify => Exec[systemd daemon-reload for nrpe2nodexp-check_tcp-mss-clamper_status.service (nrpe2nodexp-check_tcp-mss-clamper_status.service)]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /lib/systemd/system/nrpe2nodexp-check_tcp-mss-clamper_status.service.orig
+++ /lib/systemd/system/nrpe2nodexp-check_tcp-mss-clamper_status.service
@@ -0,0 +1,11 @@
+[Unit]
+Description=execution of nrpe2nodexp for the check_check_tcp-mss-clamper_status command.
+Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+
+[Service]
+Type=oneshot
+User=nagios
+
+Group=prometheus-node-exporter
+SyslogIdentifier=nrpe2nodexp-check_tcp-mss-clamper_status
+ExecStart=-/usr/local/bin/nrpe2nodexp --alert-rule-hash "295d6d5dd0a784bb9ba1d5983fd1894f" --timeout 10 --check-command "check_check_tcp-mss-clamper_status"
- Systemd::Timer::Job[prometheus_ferm_mss]
- Parameters differences:
--- Systemd::Timer::Job[prometheus_ferm_mss].orig
+++ Systemd::Timer::Job[prometheus_ferm_mss]
+ monitoring_contact_groups => admins
+ logfile_perms => all
+ logging_enabled => True
+ syslog_match_startswith => True
+ logfile_basedir => /var/log
+ environment => {}
+ logfile_name => syslog.log
+ interval => {'start': 'OnCalendar', 'interval': 'minutely'}
+ monitoring_enabled => False
+ monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+ ignore_errors => False
+ send_mail_to => root@dse-k8s-worker1012.eqiad.wmnet
+ user => root
+ syslog_force_stop => True
+ ensure => absent
+ send_mail_only_on_error => True
+ description => Regular job to collect MSS values of ferm-based hosts
+ fixed_random_delay => False
+ success_exit_status => []
+ private_tmp => False
+ command => /usr/local/bin/prometheus-ferm-mss -o /var/lib/prometheus/node.d/ferm-mss.prom -e
+ logfile_group => root
+ send_mail => False
- Systemd::Unit[tcp-mss-clamper]
- Parameters differences:
--- Systemd::Unit[tcp-mss-clamper].orig
+++ Systemd::Unit[tcp-mss-clamper]
+ ensure => absent
+ require => ['Class[Systemd]']
+ restart => False
+ unit => tcp-mss-clamper
+ override => False
+ override_filename => puppet-override.conf
- Augeas[ipip0_set_up]
- Parameters differences:
--- Augeas[ipip0_set_up].orig
+++ Augeas[ipip0_set_up]
+ context => /files/etc/network/interfaces/*[. = 'ipip0' and ./family = 'inet']
+ require => Augeas[ipip0_add_up]
+ incl => /etc/network/interfaces
+ onlyif => match up[. = 'ip link set up dev ipip0'] size == 0
+ lens => Interfaces.lns
+ changes => set up[last()+1] 'ip link set up dev ipip0'
- File[/lib/systemd/system/prometheus_ferm_mss.timer]
- Parameters differences:
--- File[/lib/systemd/system/prometheus_ferm_mss.timer].orig
+++ File[/lib/systemd/system/prometheus_ferm_mss.timer]
+ ensure => absent
+ notify => Exec[systemd daemon-reload for prometheus_ferm_mss.timer (prometheus_ferm_mss.timer)]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /lib/systemd/system/prometheus_ferm_mss.timer.orig
+++ /lib/systemd/system/prometheus_ferm_mss.timer
@@ -0,0 +1,12 @@
+[Unit]
+Description=Periodic execution of prometheus_ferm_mss.service
+
+[Timer]
+Unit=prometheus_ferm_mss.service
+# Accuracy sets the maximum time interval around the execution time we want to allow
+AccuracySec=15sec
+OnCalendar=minutely
+RandomizedDelaySec=0
+
+[Install]
+WantedBy=multi-user.target
- Augeas[ipip60_add_up]
- Parameters differences:
--- Augeas[ipip60_add_up].orig
+++ Augeas[ipip60_add_up]
+ context => /files/etc/network/interfaces/*[. = 'ipip60' and ./family = 'inet6']
+ require => Interface::Manual[ipip_ipv6]
+ incl => /etc/network/interfaces
+ onlyif => match up[. = 'ip link add name ipip60 type ip6tnl external'] size == 0
+ lens => Interfaces.lns
+ changes => set up[last()+1] 'ip link add name ipip60 type ip6tnl external'
- File[/usr/local/bin/prometheus-lvs-realserver-mss]
- Parameters differences:
--- File[/usr/local/bin/prometheus-lvs-realserver-mss].orig
+++ File[/usr/local/bin/prometheus-lvs-realserver-mss]
+ ensure => absent
+ source => puppet:///modules/prometheus/usr/local/bin/prometheus-lvs-realserver-mss.py
+ group => root
+ owner => root
+ mode => 0555
- Exec[systemd daemon-reload for nrpe2nodexp-check_tcp-mss-clamper_status.service (nrpe2nodexp-check_tcp-mss-clamper_status.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for nrpe2nodexp-check_tcp-mss-clamper_status.service (nrpe2nodexp-check_tcp-mss-clamper_status.service)].orig
+++ Exec[systemd daemon-reload for nrpe2nodexp-check_tcp-mss-clamper_status.service (nrpe2nodexp-check_tcp-mss-clamper_status.service)]
+ refreshonly => True
+ command => /bin/systemctl daemon-reload
- Exec[systemd daemon-reload for prometheus_ferm_mss.timer (prometheus_ferm_mss.timer)]
- Parameters differences:
--- Exec[systemd daemon-reload for prometheus_ferm_mss.timer (prometheus_ferm_mss.timer)].orig
+++ Exec[systemd daemon-reload for prometheus_ferm_mss.timer (prometheus_ferm_mss.timer)]
+ refreshonly => True
+ command => /bin/systemctl daemon-reload
- Ferm::Rule[clamp-mss-ipv6]
- Parameters differences:
--- Ferm::Rule[clamp-mss-ipv6].orig
+++ Ferm::Rule[clamp-mss-ipv6]
+ ensure => absent
+ domain => (ip6)
+ chain => OUTPUT
+ rule => outerface (ens2f0np0 lo) saddr @ipfilter(()) proto tcp sport () tcp-flags (SYN) SYN TCPMSS set-mss 1400;
+ table => filter
+ prio => 10
+ desc =>
- Exec[disable-rp-filter-ens2f0np0]
- Parameters differences:
--- Exec[disable-rp-filter-ens2f0np0].orig
+++ Exec[disable-rp-filter-ens2f0np0]
+ unless => /usr/sbin/sysctl -n net.ipv4.conf.ens2f0np0.rp_filter |grep -- '0'
+ command => /usr/sbin/sysctl -q net.ipv4.conf.ens2f0np0.rp_filter=0
- File[/etc/logrotate.d/prometheus_lvs_realserver_mss]
- Parameters differences:
--- File[/etc/logrotate.d/prometheus_lvs_realserver_mss].orig
+++ File[/etc/logrotate.d/prometheus_lvs_realserver_mss]
+ ensure => absent
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /etc/logrotate.d/prometheus_lvs_realserver_mss.orig
+++ /etc/logrotate.d/prometheus_lvs_realserver_mss
@@ -0,0 +1,12 @@
+# logrotate(8) config for prometheus_lvs_realserver_mss
+
+/var/log/prometheus_lvs_realserver_mss/*.log {
+ daily
+ copytruncate
+ missingok
+ compress
+ delaycompress
+ notifempty
+ rotate 15
+ size 256M
+}
- Systemd::Monitor[tcp-mss-clamper]
- Parameters differences:
--- Systemd::Monitor[tcp-mss-clamper].orig
+++ Systemd::Monitor[tcp-mss-clamper]
+ ensure => absent
+ migration_task => T407130
+ critical => False
+ notes_url => https://wikitech.wikimedia.org/wiki/LVS#IPIP_encapsulation_experiments
+ retries => 2
+ check_interval => 10
+ contact_group => admins
- Sudo::User[nrpe-check_check_tcp-mss-clamper_status]
- Parameters differences:
--- Sudo::User[nrpe-check_check_tcp-mss-clamper_status].orig
+++ Sudo::User[nrpe-check_check_tcp-mss-clamper_status]
+ ensure => absent
+ require => ['Class[Sudo]']
+ user => nagios
+ tag => nrpe::check
+ privileges => []
- File[/usr/local/lib/nagios/plugins/check_systemd_unit_status]
- Parameters differences:
--- File[/usr/local/lib/nagios/plugins/check_systemd_unit_status].orig
+++ File[/usr/local/lib/nagios/plugins/check_systemd_unit_status]
+ ensure => file
+ require => File[/usr/local/lib/nagios/plugins/]
+ source => puppet:///modules/systemd/check_systemd_unit_status
+ tag => nrpe::plugin
+ group => root
+ owner => root
+ mode => 0555
- Interface::Ip[ipip_ipv4 ipv4]
- Parameters differences:
--- Interface::Ip[ipip_ipv4 ipv4].orig
+++ Interface::Ip[ipip_ipv4 ipv4]
+ ensure => present
+ require => Augeas[ipip0_set_up]
+ address => 127.0.0.42
+ interface => ipip0
+ prefixlen => 32
- File[/etc/logrotate.d/prometheus_ferm_mss]
- Parameters differences:
--- File[/etc/logrotate.d/prometheus_ferm_mss].orig
+++ File[/etc/logrotate.d/prometheus_ferm_mss]
+ ensure => absent
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /etc/logrotate.d/prometheus_ferm_mss.orig
+++ /etc/logrotate.d/prometheus_ferm_mss
@@ -0,0 +1,12 @@
+# logrotate(8) config for prometheus_ferm_mss
+
+/var/log/prometheus_ferm_mss/*.log {
+ daily
+ copytruncate
+ missingok
+ compress
+ delaycompress
+ notifempty
+ rotate 15
+ size 256M
+}
- Ferm::Rule[ipip]
- Parameters differences:
--- Ferm::Rule[ipip].orig
+++ Ferm::Rule[ipip]
+ ensure => present
+ domain => (ip)
+ table => filter
+ rule => saddr 172.16.0.0/12 proto ipencap ACCEPT;
+ chain => INPUT
+ prio => 10
+ desc =>
- Class[Base::Sysctl]
- Parameters differences:
--- Class[Base::Sysctl].orig
+++ Class[Base::Sysctl]
@@
- all_rp_filter => 1
+ all_rp_filter => 0
- Class[Profile::Base]
- Parameters differences:
--- Class[Profile::Base].orig
+++ Class[Profile::Base]
@@
- rp_filter => True
+ rp_filter => {'all_rp_filter': 0, 'default_rp_filter': 1}
- Augeas[ipip0_add_up]
- Parameters differences:
--- Augeas[ipip0_add_up].orig
+++ Augeas[ipip0_add_up]
+ context => /files/etc/network/interfaces/*[. = 'ipip0' and ./family = 'inet']
+ require => Interface::Manual[ipip_ipv4]
+ incl => /etc/network/interfaces
+ onlyif => match up[. = 'ip link add name ipip0 type ipip external'] size == 0
+ lens => Interfaces.lns
+ changes => set up[last()+1] 'ip link add name ipip0 type ipip external'
- Exec[/usr/sbin/tc qdisc del dev lo clsact]
- Parameters differences:
--- Exec[/usr/sbin/tc qdisc del dev lo clsact].orig
+++ Exec[/usr/sbin/tc qdisc del dev lo clsact]
+ onlyif => /usr/sbin/tc qdisc show dev lo | grep -q clsact
- Augeas[ipip0_127.0.0.42/32]
- Parameters differences:
--- Augeas[ipip0_127.0.0.42/32].orig
+++ Augeas[ipip0_127.0.0.42/32]
+ context => /files/etc/network/interfaces/*[. = 'ipip0' and ./family = 'inet']
+ incl => /etc/network/interfaces
+ onlyif => match up[. = 'ip addr add 127.0.0.42/32 dev ipip0'] size == 0
+ lens => Interfaces.lns
+ changes => set up[last()+1] 'ip addr add 127.0.0.42/32 dev ipip0'
- Interface::Manual[ipip_ipv4]
- Parameters differences:
--- Interface::Manual[ipip_ipv4].orig
+++ Interface::Manual[ipip_ipv4]
+ ensure => present
+ interface => ipip0
+ family => inet
+ hotplug => False
- Sysctl::Conffile[ubuntu defaults]
- Monitoring::Service[check_tcp-mss-clamper_status]
- Parameters differences:
--- Monitoring::Service[check_tcp-mss-clamper_status].orig
+++ Monitoring::Service[check_tcp-mss-clamper_status]
+ ensure => absent
+ migration_task => T407130
+ description => Check unit status of tcp-mss-clamper
+ retry_interval => 1
+ retries => 2
+ notes_url => https://wikitech.wikimedia.org/wiki/LVS#IPIP_encapsulation_experiments
+ config_dir => /etc/nagios
+ host => dse-k8s-worker1012
+ critical => False
+ passive => False
+ check_interval => 10
+ freshness => 36000
+ contact_group => admins
+ check_command => nrpe_check!check_check_tcp-mss-clamper_status!10
- File[/lib/systemd/system/prometheus_lvs_realserver_mss.service]
- Parameters differences:
--- File[/lib/systemd/system/prometheus_lvs_realserver_mss.service].orig
+++ File[/lib/systemd/system/prometheus_lvs_realserver_mss.service]
+ ensure => absent
+ notify => Exec[systemd daemon-reload for prometheus_lvs_realserver_mss.service (prometheus_lvs_realserver_mss.service)]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /lib/systemd/system/prometheus_lvs_realserver_mss.service.orig
+++ /lib/systemd/system/prometheus_lvs_realserver_mss.service
@@ -0,0 +1,8 @@
+[Unit]
+Description=Regular job to collect MSS values of realserver endpoints
+Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+
+[Service]
+Type=oneshot
+User=root
+ExecStart=/usr/local/bin/prometheus-lvs-realserver-mss -o /var/lib/prometheus/node.d/lvs-realserver-mss.prom -e
- File[/etc/ferm/conf.d/10_clamp-mss-ipv6]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_clamp-mss-ipv6].orig
+++ File[/etc/ferm/conf.d/10_clamp-mss-ipv6]
+ ensure => absent
+ require => File[/etc/ferm/conf.d]
+ tag => ferm
+ notify => Service[ferm]
+ group => root
+ owner => root
+ mode => 0400
- Content differences:
--- /etc/ferm/conf.d/10_clamp-mss-ipv6.orig
+++ /etc/ferm/conf.d/10_clamp-mss-ipv6
@@ -0,0 +1,11 @@
+# Autogenerated by puppet. DO NOT EDIT BY HAND!
+#
+# 10_clamp-mss-ipv6:
+
+domain (ip6) {
+ table filter {
+ chain OUTPUT {
+ outerface (ens2f0np0 lo) saddr @ipfilter(()) proto tcp sport () tcp-flags (SYN) SYN TCPMSS set-mss 1400;
+ }
+ }
+}
- Systemd::Unit[prometheus_ferm_mss.timer]
- Parameters differences:
--- Systemd::Unit[prometheus_ferm_mss.timer].orig
+++ Systemd::Unit[prometheus_ferm_mss.timer]
+ ensure => absent
+ require => ['Class[Systemd]']
+ restart => False
+ unit => prometheus_ferm_mss.timer
+ override => False
+ override_filename => puppet-override.conf
- Package[tcp-mss-clamper]
- Parameters differences:
--- Package[tcp-mss-clamper].orig
+++ Package[tcp-mss-clamper]
+ ensure => absent
+ provider => apt
- Exec[disable-rp-filter-ipip0]
- Parameters differences:
--- Exec[disable-rp-filter-ipip0].orig
+++ Exec[disable-rp-filter-ipip0]
+ unless => /usr/sbin/sysctl -n net.ipv4.conf.ipip0.rp_filter |grep -- '0'
+ command => /usr/sbin/sysctl -q net.ipv4.conf.ipip0.rp_filter=0
+ require => Interface::Ipip[ipip_ipv4]
- Exec[systemd daemon-reload for prometheus_ferm_mss.service (prometheus_ferm_mss.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for prometheus_ferm_mss.service (prometheus_ferm_mss.service)].orig
+++ Exec[systemd daemon-reload for prometheus_ferm_mss.service (prometheus_ferm_mss.service)]
+ refreshonly => True
+ command => /bin/systemctl daemon-reload
- File[/etc/nagios/nrpe.d/check_check_tcp-mss-clamper_status.cfg]
- Parameters differences:
--- File[/etc/nagios/nrpe.d/check_check_tcp-mss-clamper_status.cfg].orig
+++ File[/etc/nagios/nrpe.d/check_check_tcp-mss-clamper_status.cfg]
+ ensure => absent
+ require => Package[nagios-nrpe-server]
+ tag => nrpe::check
+ notify => Service[nagios-nrpe-server]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /etc/nagios/nrpe.d/check_check_tcp-mss-clamper_status.cfg.orig
+++ /etc/nagios/nrpe.d/check_check_tcp-mss-clamper_status.cfg
@@ -0,0 +1,2 @@
+# File generated by puppet. DO NOT edit by hand
+command[check_check_tcp-mss-clamper_status]=/usr/local/lib/nagios/plugins/check_systemd_unit_status tcp-mss-clamper
- File[/etc/rsyslog.d/40-prometheus-lvs-realserver-mss.conf]
- Parameters differences:
--- File[/etc/rsyslog.d/40-prometheus-lvs-realserver-mss.conf].orig
+++ File[/etc/rsyslog.d/40-prometheus-lvs-realserver-mss.conf]
+ ensure => absent
+ notify => Service[rsyslog]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /etc/rsyslog.d/40-prometheus-lvs-realserver-mss.conf.orig
+++ /etc/rsyslog.d/40-prometheus-lvs-realserver-mss.conf
@@ -0,0 +1,10 @@
+# rsyslog.conf(5) configuration file for services.
+# This file is managed by Puppet.
+if $programname startswith "prometheus_lvs_realserver_mss" then {
+ action(
+ type="omfile" file="/var/log/prometheus_lvs_realserver_mss/syslog.log"
+ fileOwner="root" fileGroup="root"
+ fileCreateMode="0644"
+ )
+ & stop
+}
- File[/var/log/prometheus_lvs_realserver_mss]
- Parameters differences:
--- File[/var/log/prometheus_lvs_realserver_mss].orig
+++ File[/var/log/prometheus_lvs_realserver_mss]
+ ensure => absent
+ force => True
+ group => root
+ owner => root
+ backup => False
+ mode => 0755
- Nrpe::Check[check_check_tcp-mss-clamper_status]
- Parameters differences:
--- Nrpe::Check[check_check_tcp-mss-clamper_status].orig
+++ Nrpe::Check[check_check_tcp-mss-clamper_status]
+ ensure => absent
+ command => /usr/local/lib/nagios/plugins/check_systemd_unit_status tcp-mss-clamper
+ before => Monitoring::Service[check_tcp-mss-clamper_status]
- File[/lib/systemd/system/tcp-mss-clamper.service]
- Parameters differences:
--- File[/lib/systemd/system/tcp-mss-clamper.service].orig
+++ File[/lib/systemd/system/tcp-mss-clamper.service]
+ ensure => absent
+ notify => Exec[systemd daemon-reload for tcp-mss-clamper.service (tcp-mss-clamper)]
+ group => root
+ owner => root
+ mode => 0444
- Content differences:
--- /lib/systemd/system/tcp-mss-clamper.service.orig
+++ /lib/systemd/system/tcp-mss-clamper.service
@@ -0,0 +1,11 @@
+[Unit]
+Description=eBPF based TCP MSS clamper
+After=network.target
+
+[Install]
+WantedBy=multi-user.target
+
+[Service]
+LimitMEMLOCK=infinity
+ExecStart=/usr/bin/tcp-mss-clamper --ipv4-mss 1440 --ipv6-mss 1400 -p :2200 -s "" -i ens2f0np0,lo
+Restart=on-failure
- File[/etc/ferm/conf.d/10_ipip]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_ipip].orig
+++ File[/etc/ferm/conf.d/10_ipip]
+ ensure => present
+ require => File[/etc/ferm/conf.d]
+ tag => ferm
+ notify => Service[ferm]
+ group => root
+ owner => root
+ mode => 0400
- Content differences:
--- /etc/ferm/conf.d/10_ipip.orig
+++ /etc/ferm/conf.d/10_ipip
@@ -0,0 +1,11 @@
+# Autogenerated by puppet. DO NOT EDIT BY HAND!
+#
+# 10_ipip:
+
+domain (ip) {
+ table filter {
+ chain INPUT {
+ saddr 172.16.0.0/12 proto ipencap ACCEPT;
+ }
+ }
+}
- Systemd::Syslog[prometheus_lvs_realserver_mss]
- Parameters differences:
--- Systemd::Syslog[prometheus_lvs_realserver_mss].orig
+++ Systemd::Syslog[prometheus_lvs_realserver_mss]
+ ensure => absent
+ programname_comparison => startswith
+ base_dir => /var/log
+ readable_by => all
+ group => root
+ force_stop => True
+ log_filename => syslog.log
+ owner => root
- File[/var/log/prometheus_ferm_mss]
- Parameters differences:
--- File[/var/log/prometheus_ferm_mss].orig
+++ File[/var/log/prometheus_ferm_mss]
+ ensure => absent
+ force => True
+ group => root
+ owner => root
+ backup => False
+ mode => 0755
- Systemd::Timer::Job[nrpe2nodexp-check_tcp-mss-clamper_status]
- Parameters differences:
--- Systemd::Timer::Job[nrpe2nodexp-check_tcp-mss-clamper_status].orig
+++ Systemd::Timer::Job[nrpe2nodexp-check_tcp-mss-clamper_status]
+ monitoring_contact_groups => admins
+ logfile_perms => all
+ logging_enabled => False
+ syslog_match_startswith => True
+ logfile_basedir => /var/log
+ environment => {}
+ logfile_name => syslog.log
+ group => prometheus-node-exporter
+ interval => [{'start': 'OnUnitInactiveSec', 'interval': '5min'}]
+ monitoring_enabled => False
+ monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+ ignore_errors => True
+ send_mail_to => root@dse-k8s-worker1012.eqiad.wmnet
+ user => nagios
+ syslog_force_stop => True
+ logfile_group => root
+ ensure => absent
+ send_mail_only_on_error => True
+ description => execution of nrpe2nodexp for the check_check_tcp-mss-clamper_status command.
+ fixed_random_delay => True
+ success_exit_status => []
+ syslog_identifier => nrpe2nodexp-check_tcp-mss-clamper_status
+ command => /usr/local/bin/nrpe2nodexp --alert-rule-hash "295d6d5dd0a784bb9ba1d5983fd1894f" --timeout 10 --check-command "check_check_tcp-mss-clamper_status"
+ private_tmp => False
+ splay => 300
+ send_mail => False
- Systemd::Unit[nrpe2nodexp-check_tcp-mss-clamper_status.service]
- Parameters differences:
--- Systemd::Unit[nrpe2nodexp-check_tcp-mss-clamper_status.service].orig
+++ Systemd::Unit[nrpe2nodexp-check_tcp-mss-clamper_status.service]
+ ensure => absent
+ require => ['Class[Systemd]']
+ restart => False
+ unit => nrpe2nodexp-check_tcp-mss-clamper_status.service
+ override => False
+ override_filename => puppet-override.conf
- Exec[/usr/sbin/tc qdisc del dev ens2f0np0 clsact]
- Parameters differences:
--- Exec[/usr/sbin/tc qdisc del dev ens2f0np0 clsact].orig
+++ Exec[/usr/sbin/tc qdisc del dev ens2f0np0 clsact]
+ onlyif => /usr/sbin/tc qdisc show dev ens2f0np0 | grep -q clsact
- Systemd::Unit[prometheus_ferm_mss.service]
- Parameters differences: