{"host": "wdqs1026.eqiad.wmnet", "state": "core_diff", "description": "Differences to core resources", "diff": {"full": {"total": 3535, "only_in_self": [], "only_in_other": [], "resource_diffs": [{"resource": "Envoyproxy::Listener[tls_terminator_443]"}, {"resource": "Envoyproxy::Conf[tls_terminator_443]"}, {"resource": "File[/etc/envoy/listeners.d/00-tls_terminator_443.yaml]", "content": "--- /etc/envoy/listeners.d/00-tls_terminator_443.yaml.orig\n+++ /etc/envoy/listeners.d/00-tls_terminator_443.yaml\n@@ -9,6 +9,49 @@\n     \"@type\": type.googleapis.com/envoy.extensions.filters.listener.tls_inspector.v3.TlsInspector\n tcp_fast_open_queue_length: 150\n filter_chains:\n+- filter_chain_match:\n+    server_names: [\"*\"]\n+  transport_socket:\n+    name: envoy.transport_sockets.tls\n+    typed_config:\n+      '@type': type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.DownstreamTlsContext\n+      common_tls_context:\n+        tls_certificates:\n+        - certificate_chain: { filename: \"\" }\n+          private_key: { filename: \"\" }\n+  filters:\n+  - name: envoy.http_connection_manager\n+    typed_config:\n+      \"@type\": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager\n+      http_protocol_options:\n+        accept_http_10: true\n+      stat_prefix: ingress_http\n+      route_config:\n+        virtual_hosts:\n+        - name: default\n+          domains: [\"*\"]\n+          routes:\n+          - match: { prefix: \"/\" }\n+            route:\n+              cluster: local_port_80\n+              timeout: 65.0s\n+              retry_policy:\n+                num_retries: 1\n+                retry_on: \"5xx\"\n+      http_filters:\n+      - name: envoy.filters.http.router\n+        typed_config:\n+          \"@type\": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router\n+      server_header_transformation: APPEND_IF_ABSENT\n+      internal_address_config:\n+        unix_sockets: true\n+        cidr_ranges:\n+        - address_prefix: 10.0.0.0\n+          prefix_len: 8\n+        - address_prefix: 127.0.0.1\n+          prefix_len: 32\n+        - address_prefix: ::1\n+          prefix_len: 128\n # Non-SNI support\n - transport_socket:\n     name: envoy.transport_sockets.tls"}, {"resource": "Envoyproxy::Tls_terminator[443]", "parameters": "--- Envoyproxy::Tls_terminator[443].orig\n+++ Envoyproxy::Tls_terminator[443]\n\n-    global_certs            => [{'cert_path': '/etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server.chained.pem', 'key_path': '/etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server-key.pem'}]\n-    generate_request_id     => True\n-    stek_files              => []\n-    circuit_breakers_config => defaults\n+    global_key_path         => /etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server-key.pem\n+    global_cert_path        => /etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server.chained.pem\n@@\n-    upstreams               => [{'server_names': ['*'], 'certificates': None, 'upstream': {'port': 80, 'addr': 'wdqs1026.eqiad.wmnet'}}]\n+    upstreams               => [{'server_names': ['*'], 'cert_path': None, 'key_path': None, 'upstream_port': 80, 'upstream_addr': 'wdqs1026.eqiad.wmnet'}]\n"}], "perc_changed": "0.11%"}, "core": {"total": 3535, "only_in_self": [], "only_in_other": [], "resource_diffs": [{"resource": "File[/etc/envoy/listeners.d/00-tls_terminator_443.yaml]", "content": "--- /etc/envoy/listeners.d/00-tls_terminator_443.yaml.orig\n+++ /etc/envoy/listeners.d/00-tls_terminator_443.yaml\n@@ -9,6 +9,49 @@\n     \"@type\": type.googleapis.com/envoy.extensions.filters.listener.tls_inspector.v3.TlsInspector\n tcp_fast_open_queue_length: 150\n filter_chains:\n+- filter_chain_match:\n+    server_names: [\"*\"]\n+  transport_socket:\n+    name: envoy.transport_sockets.tls\n+    typed_config:\n+      '@type': type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.DownstreamTlsContext\n+      common_tls_context:\n+        tls_certificates:\n+        - certificate_chain: { filename: \"\" }\n+          private_key: { filename: \"\" }\n+  filters:\n+  - name: envoy.http_connection_manager\n+    typed_config:\n+      \"@type\": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager\n+      http_protocol_options:\n+        accept_http_10: true\n+      stat_prefix: ingress_http\n+      route_config:\n+        virtual_hosts:\n+        - name: default\n+          domains: [\"*\"]\n+          routes:\n+          - match: { prefix: \"/\" }\n+            route:\n+              cluster: local_port_80\n+              timeout: 65.0s\n+              retry_policy:\n+                num_retries: 1\n+                retry_on: \"5xx\"\n+      http_filters:\n+      - name: envoy.filters.http.router\n+        typed_config:\n+          \"@type\": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router\n+      server_header_transformation: APPEND_IF_ABSENT\n+      internal_address_config:\n+        unix_sockets: true\n+        cidr_ranges:\n+        - address_prefix: 10.0.0.0\n+          prefix_len: 8\n+        - address_prefix: 127.0.0.1\n+          prefix_len: 32\n+        - address_prefix: ::1\n+          prefix_len: 128\n # Non-SNI support\n - transport_socket:\n     name: envoy.transport_sockets.tls"}], "perc_changed": "0.03%"}, "main": {"total": 3535, "only_in_self": [], "only_in_other": [], "resource_diffs": [{"resource": "Envoyproxy::Listener[tls_terminator_443]"}, {"resource": "Envoyproxy::Conf[tls_terminator_443]"}, {"resource": "File[/etc/envoy/listeners.d/00-tls_terminator_443.yaml]", "content": "--- /etc/envoy/listeners.d/00-tls_terminator_443.yaml.orig\n+++ /etc/envoy/listeners.d/00-tls_terminator_443.yaml\n@@ -9,6 +9,49 @@\n     \"@type\": type.googleapis.com/envoy.extensions.filters.listener.tls_inspector.v3.TlsInspector\n tcp_fast_open_queue_length: 150\n filter_chains:\n+- filter_chain_match:\n+    server_names: [\"*\"]\n+  transport_socket:\n+    name: envoy.transport_sockets.tls\n+    typed_config:\n+      '@type': type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.DownstreamTlsContext\n+      common_tls_context:\n+        tls_certificates:\n+        - certificate_chain: { filename: \"\" }\n+          private_key: { filename: \"\" }\n+  filters:\n+  - name: envoy.http_connection_manager\n+    typed_config:\n+      \"@type\": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager\n+      http_protocol_options:\n+        accept_http_10: true\n+      stat_prefix: ingress_http\n+      route_config:\n+        virtual_hosts:\n+        - name: default\n+          domains: [\"*\"]\n+          routes:\n+          - match: { prefix: \"/\" }\n+            route:\n+              cluster: local_port_80\n+              timeout: 65.0s\n+              retry_policy:\n+                num_retries: 1\n+                retry_on: \"5xx\"\n+      http_filters:\n+      - name: envoy.filters.http.router\n+        typed_config:\n+          \"@type\": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router\n+      server_header_transformation: APPEND_IF_ABSENT\n+      internal_address_config:\n+        unix_sockets: true\n+        cidr_ranges:\n+        - address_prefix: 10.0.0.0\n+          prefix_len: 8\n+        - address_prefix: 127.0.0.1\n+          prefix_len: 32\n+        - address_prefix: ::1\n+          prefix_len: 128\n # Non-SNI support\n - transport_socket:\n     name: envoy.transport_sockets.tls"}, {"resource": "Envoyproxy::Tls_terminator[443]", "parameters": "--- Envoyproxy::Tls_terminator[443].orig\n+++ Envoyproxy::Tls_terminator[443]\n\n-    global_certs            => [{'cert_path': '/etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server.chained.pem', 'key_path': '/etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server-key.pem'}]\n-    generate_request_id     => True\n-    stek_files              => []\n-    circuit_breakers_config => defaults\n+    global_key_path         => /etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server-key.pem\n+    global_cert_path        => /etc/envoy/ssl/discovery2026__wdqs-internal-main_discovery_wmnet_server.chained.pem\n@@\n-    upstreams               => [{'server_names': ['*'], 'certificates': None, 'upstream': {'port': 80, 'addr': 'wdqs1026.eqiad.wmnet'}}]\n+    upstreams               => [{'server_names': ['*'], 'cert_path': None, 'key_path': None, 'upstream_port': 80, 'upstream_addr': 'wdqs1026.eqiad.wmnet'}]\n"}], "perc_changed": "0.11%"}}}