Compilation results for pki1001.eqiad.wmnet: System changes detected
You can retrieve this result from host.json.Catalog differences
Summary
| Total Resources: | 4897 |
|---|---|
| Resources added: | 0 |
| Resources removed: | 45 |
| Resources modified: | 2 |
| Change percentage: | 0.96% |
Resources only in the old catalog
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery.service]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery.service (nrpe2nodexp-check_certificate_expiry_discovery.service)]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-discovery.conf]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery.timer (cfssl-ocsprefresh-discovery.timer)]
- File[/lib/systemd/system/cfssl-ocspserve@discovery.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service (prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service)]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet-key.pem]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.conf]
- File[/etc/cfssl/csr/OCSP_discovery_pki1001_eqiad_wmnet.csr]
- File[/var/log/cfssl-ocsprefresh-discovery]
- File[/var/log/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery.timer]
- File[/etc/cfssl/ocsp/discovery.ocsp]
- File[/usr/local/bin/prometheus-check-discovery-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service]
- File[/etc/cfssl/signers/discovery/cfssl.conf]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery.service (cfssl-ocsprefresh-discovery.service)]
- File[/etc/cfssl/signers/discovery/ca]
- Exec[Generate initial CRL for discovery]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery.timer]
- Service[cfssl-ocspserve@discovery]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery.service]
- File[/etc/logrotate.d/cfssl-ocsprefresh-discovery]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet.pem]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-discovery.conf]
- File[/etc/cfssl/signers/discovery/ca/discovery.pem]
- Service[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer]
- File[/etc/cfssl/signers/discovery]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_discovery.cfg]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- File[/etc/cfssl/signers/discovery/ca/discovery-key.pem]
- File[/srv/cfssl/bundles/discovery.pem]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_discovery.prom]
- File[/etc/sudoers.d/nrpe_certificate_check_discovery]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_discovery]
- Exec[Generate cert OCSP_discovery_pki1001_eqiad_wmnet refresh]
- Exec[systemd daemon-reload for cfssl-ocspserve@discovery.service (cfssl-ocspserve@discovery)]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery.timer (nrpe2nodexp-check_certificate_expiry_discovery.timer)]
- Exec[renew certificate - OCSP_discovery_pki1001_eqiad_wmnet]
- Exec[Generate cert OCSP_discovery_pki1001_eqiad_wmnet]
- Service[cfssl-ocsprefresh-discovery.timer]
- Service[nrpe2nodexp-check_certificate_expiry_discovery.timer]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer)]
Resources modified
- File[/etc/apache2/sites-available/50-pki-discovery-wmnet.conf]
- Content differences:
--- /etc/apache2/sites-available/50-pki-discovery-wmnet.conf.orig +++ /etc/apache2/sites-available/50-pki-discovery-wmnet.conf @@ -24,9 +24,6 @@ # debmonitor ProxyPass /ocsp/debmonitor http://localhost:10001/ ProxyPassReverse /ocsp/debmonitor http://localhost:10001/ - # discovery - ProxyPass /ocsp/discovery http://localhost:10002/ - ProxyPassReverse /ocsp/discovery http://localhost:10002/ # kafka ProxyPass /ocsp/kafka http://localhost:10003/ ProxyPassReverse /ocsp/kafka http://localhost:10003/
- Content differences:
- File[/etc/cfssl/multiroot.conf]
- Content differences:
--- /etc/cfssl/multiroot.conf.orig +++ /etc/cfssl/multiroot.conf @@ -2,12 +2,6 @@ private = file:///etc/cfssl/signers/debmonitor/ca/debmonitor-key.pem certificate = /etc/cfssl/signers/debmonitor/ca/debmonitor.pem config = /etc/cfssl/signers/debmonitor/cfssl.conf -dbconfig = /etc/cfssl/db.conf - -[discovery] -private = file:///etc/cfssl/signers/discovery/ca/discovery-key.pem -certificate = /etc/cfssl/signers/discovery/ca/discovery.pem -config = /etc/cfssl/signers/discovery/cfssl.conf dbconfig = /etc/cfssl/db.conf [kafka]
- Content differences: