Compilation results for pki1001.eqiad.wmnet: System changes detected
You can retrieve this result from host.json.Catalog differences
Summary
| Total Resources: | 4897 |
|---|---|
| Resources added: | 165 |
| Resources removed: | 2222 |
| Resources modified: | 2414 |
| Change percentage: | 98.04% |
Resources only in the new catalog
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
- Nftables::Set[DEPLOYMENT_HOSTS]
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv4.nft]
- Prometheus::Node_textfile[check-nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_MAIN_ipv4.nft]
- File[/etc/systemd/system/nftables.service.d]
- Exec[systemd daemon-reload for prometheus-node-textfile-check-nft.service (prometheus-node-textfile-check-nft.service)]
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
- Nftables::Set[CLOUD_NETWORKS]
- File[/etc/nftables/]
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv6.nft]
- Exec[unmask_nftables.service]
- Nftables::Set[LABSTORE_HOSTS]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf]
- Nftables::Set[CUMIN_MASTERS]
- Nftables::Set[ANALYTICS_NETWORKS]
- File[/etc/nftables/input/10_ssh-from-bastion.nft]
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
- File[/lib/systemd/system/prometheus-node-textfile-check-nft.timer]
- File[/etc/nftables.conf]
- File[/var/log/prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/LINK_LOCAL_ipv6.nft]
- Nftables::Set[MLSERVE_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
- Nftables::Set[KAFKA_BROKERS_JUMBO]
- Nftables::Service[ssh-from-cumin-masters]
- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/NETWORK_INFRA_ipv4.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
- Nftables::Set[MONITORING_HOSTS]
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft]
- Exec[systemd daemon-reload for prometheus-node-textfile-check-nft.timer (prometheus-node-textfile-check-nft.timer)]
- Class[Nftables]
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft]
- Systemd::Timer::Job[prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft]
- File[/etc/logrotate.d/prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/BASTION_HOSTS_ipv6.nft]
- Nftables::Set[STAGING_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
- Nftables::Set[KAFKAMON_HOSTS]
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/PROMETHEUS_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/input]
- Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS]
- Nftables::Service[full-monitoring-metrics-access-udp]
- Motd::Script[insetup::infrastructure_foundations_nftables]
- Nftables::File[base]
- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Rsyslog::Conf[prometheus-node-textfile-check-nft]
- Nftables::Set[INSTALL_HOSTS]
- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft]
- Nftables::Set[PROMETHEUS_HOSTS]
- Nftables::Set[FRACK_NETWORKS]
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv6.nft]
- Nftables::Service[full-monitoring-metrics-access-tcp]
- File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/KAFKAMON_HOSTS_ipv6.nft]
- Nftables::Set[NETWORK_INFRA]
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
- Nftables::Set[ZOOKEEPER_FLINK_HOSTS]
- Motd::Message[insetup::infrastructure_foundations_nftables]
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Service[prometheus-node-textfile-check-nft.timer]
- Nftables::Set[ZOOKEEPER_HOSTS_MAIN]
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv4.nft]
- Nftables::Set[LABS_NETWORKS]
- Systemd::Unit[prometheus-node-textfile-check-nft.service]
- Nftables::Set[PRODUCTION_NETWORKS]
- File[/etc/nftables/sets/LABS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/MYSQL_ROOT_CLIENTS_ipv6.nft]
- File[/etc/nftables/output]
- Systemd::Service[prometheus-node-textfile-check-nft]
- File[/usr/local/bin/check-nft]
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
- Logrotate::Conf[prometheus-node-textfile-check-nft]
- File[/etc/update-motd.d/05-insetup--infrastructure-foundations-nftables]
- File[/etc/nftables/sets/MYSQL_ROOT_CLIENTS_ipv4.nft]
- File[/etc/nftables/sets]
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv4.nft]
- Package[nftables]
- Class[Profile::Firewall::Nftables_base_sets]
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
- File[/etc/nftables/main.nft]
- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- File[/etc/nftables/sets/KAFKAMON_HOSTS_ipv4.nft]
- Systemd::Unit[nftables]
- File[/etc/nftables/sets/CACHES_ipv6.nft]
- File[/etc/nftables/sets/INTERNAL_ipv4.nft]
- File[/etc/nftables/prerouting]
- Nftables::Set[SANDBOX_NETWORKS]
- Nftables::Set[WIKIKUBE_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
- Systemd::Syslog[prometheus-node-textfile-check-nft]
- Class[Role::Insetup::Infrastructure_foundations_nftables]
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
- Systemd::Service[nftables]
- Nftables::Set[LOAD_BALANCER_HEALTH_CHECKS]
- Systemd::Unmask[nftables.service]
- Nftables::Set[CACHES]
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- Nftables::Set[MYSQL_ROOT_CLIENTS]
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft]
- File[/etc/nftables/forward]
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
- Nftables::Set[DOMAIN_NETWORKS]
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_MAIN_ipv6.nft]
- File[/etc/nftables/postrouting]
- Systemd::Unit[prometheus-node-textfile-check-nft.timer]
- File[/etc/nftables/sets/CACHES_ipv4.nft]
- Node[__node_regexp__pki1001.eqiad.]
- Nftables::Set[DRUID_PUBLIC_HOSTS]
- Nftables::Set[MGMT_NETWORKS]
- Nftables::Set[INTERNAL]
- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
- File[/etc/nftables/input/10_full-monitoring-metrics-access-udp.nft]
- File[/etc/systemd/system/nftables.service.d/puppet-override.conf]
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft]
- Service[nftables]
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv6.nft]
- Nftables::Set[MW_APPSERVER_NETWORKS]
- Nftables::Set[KAFKA_BROKERS_LOGGING]
- Nftables::Set[AUX_KUBEPODS_NETWORKS]
- Systemd::Timer[prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft]
- Nftables::Set[DSE_KUBEPODS_NETWORKS]
- File[/etc/nftables/notrack]
- Nftables::Set[CLOUD_PRIVATE_NETWORKS]
- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft]
- Exec[systemd daemon-reload for nftables.service (nftables)]
- File[/lib/systemd/system/prometheus-node-textfile-check-nft.service]
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft]
- Nftables::Set[LINK_LOCAL]
- Nftables::Set[BASTION_HOSTS]
- Nftables::Set[CLOUD_NETWORKS_PUBLIC]
- File[/etc/nftables/input/10_full-monitoring-metrics-access-tcp.nft]
- Nftables::Set[KAFKA_BROKERS_MAIN]
- File[/etc/nftables/100_base_puppet.nft]
- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- Nftables::Service[ssh-from-bastion]
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv6.nft]
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/PROMETHEUS_HOSTS_ipv4.nft]
Resources only in the old catalog
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_dse.cfg]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg]
- Firewall::Service[multirootca-tls-termination-for-cfssl-issuer-k8s-pods]
- File[/etc/cfssl/signers/wikikube_staging/ca/wikikube_staging-key.pem]
- Cfssl::Signer[dse]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.service (nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.service)]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_kafka]
- Systemd::Unit[cfssl-ocsprefresh-mlserve.service]
- Service[cfssl-ocsprefresh-kafka.timer]
- File[/srv/cfssl/bundles/network_devices.pem]
- Systemd::Unit[cfssl-ocsprefresh-etcd.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service)]
- Exec[Generate cert OCSP_discovery2026_pki1001_eqiad_wmnet refresh]
- Prometheus::Node_textfile[prometheus-check-puppet_rsa-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_front_proxy.timer]
- Package[python3-pymysql]
- File[/etc/apache2/conf-available/00-defaults.conf]
- Exec[systemd daemon-reload for cfssl-ocspserve@wikikube_front_proxy.service (cfssl-ocspserve@wikikube_front_proxy)]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/usr/local/bin/prometheus-check-aux-certificate-expiry]
- File[/lib/systemd/system/cfssl-ocspserve@zuul.service]
- Nrpe::Monitor_service[check_certificate_expiry_kafka]
- File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.service (cfssl-ocsprefresh-mlserve.service)]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka]
- File[/lib/systemd/system/cfssl-ocsprefresh-syslog.timer]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- Systemd::Syslog[cfssl-ocsprefresh-zuul]
- Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet refresh]
- Systemd::Service[cfssl-ocsprefresh-cloud_wmnet_ca]
- File[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Systemd::Syslog[cfssl-ocsprefresh-discovery]
- Exec[ensure_present_mod_filter]
- Exec[renew certificate - OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_puppet_rsa]
- Systemd::Service[cfssl-ocspserve@etcd]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_network_devices]
- File[/etc/logrotate.d/ulogd]
- File[/etc/cfssl/ocsp/mlserve_staging_front_proxy.ocsp]
- Rsyslog::Conf[cfssl-ocsprefresh-syslog]
- Systemd::Service[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- Service[cfssl-ocsprefresh-mlserve_staging.timer]
- Systemd::Service[cfssl-ocsprefresh-aux_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service)]
- Service[ferm]
- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_front_proxy_pki1001_eqiad_wmnet-key.pem]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.timer)]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.timer (cfssl-ocsprefresh-debmonitor.timer)]
- Cfssl::Cert[OCSP_discovery2026_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service]
- Service[cfssl-ocspserve@mlserve]
- Prometheus::Node_textfile[prometheus-check-dse-certificate-expiry]
- Systemd::Timer::Job[nrpe2nodexp-ferm_active]
- File[/etc/cfssl/signers/syslog/cfssl.conf]
- Sudo::User[nrpe_certificate_check_wikikube]
- Systemd::Timer[cfssl-ocsprefresh-kafka]
- Exec[Generate cert puppet_rsa__pki_discovery_wmnet refresh]
- File[/etc/sudoers.d/nrpe_certificate_check_wikikube]
- File[/var/log/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr]
- Cfssl::Config[wikikube]
- File[/var/log/prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Cfssl::Config[mlserve_staging_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service)]
- File[/etc/cfssl/ocsp/mlserve_staging.ocsp]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/var/log/cfssl-ocsprefresh-discovery]
- File[/srv/cfssl/bundles/mlserve_staging_front_proxy.pem]
- Systemd::Timer[cfssl-ocsprefresh-dse_front_proxy]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.timer]
- File[/etc/cfssl/signers/mlserve_staging/cfssl.conf]
- File[/lib/systemd/system/cfssl-ocsprefresh-dse.service]
- Sudo::User[nrpe_certificate_check_dse]
- Exec[Generate initial CRL for mlserve]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr]
- Service[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.service]
- File[/etc/cfssl/signers/wikikube_staging]
- File[/lib/systemd/system/cfssl-ocspserve@wikikube_staging.service]
- Systemd::Timer::Job[cfssl-ocsprefresh-mlserve_staging]
- Class[Profile::Pki::Multirootca]
- Cfssl::Ocsp[aux]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service (prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service)]
- File[/etc/cfssl/signers/discovery2026]
- Exec[systemd daemon-reload for cfssl-ocspserve@dse.service (cfssl-ocspserve@dse)]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-wikikube-front-proxy.conf]
- File[/var/log/cfssl-ocsprefresh-dse_front_proxy]
- File[/srv/cfssl/bundles/puppet_rsa.pem]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery.timer (cfssl-ocsprefresh-discovery.timer)]
- File[/etc/cfssl/signers/dse_front_proxy/ca/dse_front_proxy.pem]
- File[/etc/rsyslog.d/25-nrpe2nodexp-ferm-active.conf]
- File[/etc/cfssl/ssl/ocsp/OCSP_network_devices_pki1001_eqiad_wmnet.pem]
- Service[cfssl-ocsprefresh-wikikube.timer]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/cfssl-ocsprefresh-dse.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_cloud_wmnet_ca]
- Systemd::Service[cfssl-ocsprefresh-wikikube_front_proxy]
- File[/srv/cfssl/bundles/discovery.pem]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca]
- Exec[systemd daemon-reload for wmf_auto_restart_apache-htcacheclean.timer (wmf_auto_restart_apache-htcacheclean.timer)]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_wikikube_front_proxy]
- Service[cfssl-ocspserve@dse]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-etcd.timer (cfssl-ocsprefresh-etcd.timer)]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_zuul.timer (nrpe2nodexp-check_certificate_expiry_zuul.timer)]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Systemd::Service[cfssl-ocspserve@cloud_wmnet_ca]
- Service[cfssl-ocspserve@network_devices]
- File[/etc/cfssl/signers/wikikube_front_proxy/ca/wikikube_front_proxy.pem]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-dse.conf]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.conf]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy]
- Exec[renew certificate - OCSP_discovery_pki1001_eqiad_wmnet]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_wikikube_staging]
- Prometheus::Blackbox::Check::Http[PKI_syslog]
- Profile::Pki::Multirootca::Monitoring[wikikube_front_proxy]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_mlserve.cfg]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_aux_pki1001_eqiad_wmnet.csr]
- Sudo::User[nrpe_certificate_check_cloud_wmnet_ca]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- File[/srv/cfssl/bundles/mlserve_staging.pem]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_mlserve]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_dse_front_proxy.timer]
- File[/etc/cfssl/db.conf.json]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_network_devices.timer (nrpe2nodexp-check_certificate_expiry_network_devices.timer)]
- Prometheus::Blackbox::Check::Http[PKI_mlserve_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_cassandra_pki1001_eqiad_wmnet-key.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_discovery2026.service]
- Cfssl::Ocsp[dse_front_proxy]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_dse_front_proxy]
- Systemd::Unit[wmf_auto_restart_apache-htcacheclean.timer]
- File[/var/log/prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- File[/etc/apache2/conf-enabled]
- File[/etc/ferm/conf.d/01_drop-blocked-nets]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-mlserve-staging-certificate-expiry.conf]
- Sudo::User[nrpe_certificate_check_mlserve]
- Monitoring::Service[check_certificate_expiry_puppet_rsa]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_aux_front_proxy.timer]
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_udp]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.conf]
- Systemd::Service[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- Sudo::User[nrpe-check_check_certificate_expiry_wikikube]
- File[/etc/cfssl/csr/OCSP_discovery_pki1001_eqiad_wmnet.csr]
- Augeas[Apache2 logs]
- Cfssl::Ocsp[Wikimedia_Internal_Root_CA]
- File[/var/log/prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- File[/var/log/prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Ferm::Rule[dscp-default]
- File[/etc/cfssl/ssl/ocsp/OCSP_syslog_pki1001_eqiad_wmnet.csr]
- Nrpe::Check[check_ferm_active]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-kafka.service (cfssl-ocsprefresh-kafka.service)]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_aux.timer]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet.csr]
- Nrpe::Check[check_check_certificate_expiry_dse]
- Exec[Generate initial CRL for wikikube_staging_front_proxy]
- File[/etc/apache2/env-available]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-syslog.timer]
- Prometheus::Node_textfile[prometheus-check-mlserve_staging-certificate-expiry]
- Systemd::Timer::Job[cfssl-ocsprefresh-wikikube_staging]
- Nrpe::Monitor_service[check_certificate_expiry_aux]
- File[/lib/systemd/system/cfssl-ocspserve@mlserve_front_proxy.service]
- File[/etc/cfssl/signers/wikikube_front_proxy]
- Systemd::Timer::Job[cfssl-ocsprefresh-aux]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.service (prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.service)]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_cassandra.timer (nrpe2nodexp-check_certificate_expiry_cassandra.timer)]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Systemd::Timer[cfssl-ocsprefresh-puppet_rsa]
- Systemd::Unit[cfssl-ocsprefresh-discovery.timer]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_syslog.timer]
- Exec[Generate cert OCSP_discovery_pki1001_eqiad_wmnet refresh]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_front_proxy_pki1001_eqiad_wmnet.csr]
- Cfssl::Cert[puppet_rsa__pki_discovery_wmnet]
- Nrpe::Check[check_check_certificate_expiry_syslog]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.timer (cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.timer)]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_dse.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-dse-front-proxy.conf]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_etcd.service (nrpe2nodexp-check_certificate_expiry_etcd.service)]
- Systemd::Timer::Job[nrpe2nodexp-check_cfssl-multirootca_status]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet.pem]
- File[/srv/cfssl/bundles/kafka.pem]
- File[/etc/sudoers.d/nrpe_certificate_check_zuul]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Nrpe::Monitor_service[check_certificate_expiry_network_devices]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- File[/srv/cfssl/bundles/zuul.pem]
- File[/etc/cfssl/ocsp/Wikimedia_Internal_Root_CA.ocsp]
- File[/var/log/prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- File[/etc/cfssl/csr/OCSP_mlserve_staging_pki1001_eqiad_wmnet.csr]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_wikikube_front_proxy.prom]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_mlserve]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer)]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-dse.timer (cfssl-ocsprefresh-dse.timer)]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_aux]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet-key.pem]
- File[/lib/systemd/system/cfssl-ocsprefresh-network_devices.service]
- Nrpe::Check[check_check_certificate_expiry_dse_front_proxy]
- Prometheus::Blackbox::Check::Http[PKI_aux_front_proxy]
- File[/var/log/prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- File[/etc/ulogd.conf]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-ferm_active.service (nrpe2nodexp-ferm_active.service)]
- File[/etc/nagios/nrpe.d/check_ferm_active.cfg]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_network_devices.cfg]
- Systemd::Unit[cfssl-ocsprefresh-mlserve.timer]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_mlserve_front_proxy.prom]
- Profile::Pki::Multirootca::Monitoring[syslog]
- File[/etc/cfssl/csr/OCSP_wikikube_staging_pki1001_eqiad_wmnet.csr]
- Logrotate::Conf[ulogd]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.service]
- File[/etc/ferm/conf.d/10_ssh_from_cumin_masters]
- Systemd::Timer[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy]
- File[/etc/ferm/conf.d/00_defs]
- Systemd::Unit[cfssl-ocsprefresh-dse_front_proxy.service]
- Systemd::Unit[cfssl-ocsprefresh-debmonitor.service]
- Systemd::Service[cfssl-ocsprefresh-discovery]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_dse_front_proxy.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.service]
- Service[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.timer]
- Httpd::Mod_conf[status]
- File[/lib/systemd/system/cfssl-ocspserve@wikikube_front_proxy.service]
- File[/etc/cfssl/ocsp/syslog.ocsp]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_wikikube_staging]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_discovery.prom]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Exec[Generate initial CRL for dse_front_proxy]
- File[/srv/cfssl/bundles/dse_front_proxy.pem]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_syslog]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_discovery2026]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_debmonitor]
- Systemd::Unit[cfssl-ocspserve@mlserve_staging]
- Systemd::Unit[cfssl-ocspserve@cassandra]
- Exec[create chained cert /etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet.chain.pem]
- Systemd::Service[cfssl-ocsprefresh-puppet_rsa]
- Systemd::Service[cfssl-gc-expired-certs]
- Sudo::User[nrpe-check_check_certificate_expiry_syslog]
- Cfssl::Signer[puppet_rsa]
- Nrpe::Check[check_check_certificate_expiry_wikikube]
- Systemd::Unit[cfssl-gc-expired-certs.service]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Exec[renew certificate - OCSP_etcd_pki1001_eqiad_wmnet]
- Rsyslog::Conf[wmf_auto_restart_ulogd2]
- Prometheus::Node_textfile[prometheus-check-discovery-certificate-expiry]
- Systemd::Service[cfssl-ocspserve@discovery]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_front_proxy.service (cfssl-ocsprefresh-wikikube_front_proxy.service)]
- Logrotate::Conf[cfssl-ocsprefresh-dse]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.timer)]
- File[/etc/cfssl/signers/discovery/cfssl.conf]
- Prometheus::Alert::Rule[check_check_certificate_expiry_dse_front_proxy_2560f4f577ba169af651cf96bd5dc1ba]
- Exec[Generate cert OCSP_cassandra_pki1001_eqiad_wmnet refresh]
- Prometheus::Alert::Rule[check_check_certificate_expiry_syslog_e3b9b989d5062ce2d267023dfe42fcd8]
- Systemd::Unit[cfssl-ocsprefresh-puppet_rsa.service]
- File[/etc/logrotate.d/cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Service[ulogd2]
- File[/etc/cfssl/csr/OCSP_aux_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/dse_front_proxy]
- Systemd::Unit[cfssl-ocsprefresh-aux_front_proxy.timer]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.timer]
- Class[Role::Pki::Multirootca]
- Systemd::Syslog[cfssl-ocsprefresh-wikikube_staging]
- File[/etc/sudoers.d/nrpe_certificate_check_discovery2026]
- File[/etc/cfssl/signers/mlserve_staging/ca/mlserve_staging-key.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_etcd.timer]
- Prometheus::Blackbox::Check::Http[PKI_wikikube_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_cassandra_pki1001_eqiad_wmnet.pem]
- Logrotate::Conf[cfssl-ocsprefresh-cassandra]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- Service[wmf_auto_restart_ulogd2.timer]
- Exec[Generate initial CRL for cloud_wmnet_ca]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_discovery]
- Nrpe::Check[check_check_certificate_expiry_mlserve_staging_front_proxy]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_zuul.service (nrpe2nodexp-check_certificate_expiry_zuul.service)]
- Systemd::Service[cfssl-ocsprefresh-wikikube_staging]
- Systemd::Unit[cfssl-ocsprefresh-etcd.timer]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-cassandra.timer (cfssl-ocsprefresh-cassandra.timer)]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Service[cfssl-ocspserve@mlserve_front_proxy]
- File_line[auto_restart_file_presence_apache2]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_puppet_rsa.service]
- File[/var/log/prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- Monitoring::Service[ferm_active]
- File[/var/log/cfssl-gc-expired-certs]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.timer)]
- File[/etc/cfssl/signers/zuul/cfssl.conf]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_syslog]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_discovery2026]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.timer]
- Systemd::Service[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_debmonitor.timer]
- Exec[Generate cert OCSP_network_devices_pki1001_eqiad_wmnet refresh]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-mlserve-staging-front-proxy-certificate-expiry.conf]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_etcd.timer]
- Cfssl::Ocsp[dse]
- File[/srv/cfssl/bundles/wikikube_staging.pem]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_zuul]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_network_devices.service]
- File[/etc/cfssl/signers/mlserve_staging/ca]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca]
- File[/srv/cfssl/bundles/Puppet_Internal_CA.pem.pem]
- File[/etc/cfssl/signers/dse_front_proxy/ca/dse_front_proxy-key.pem]
- Systemd::Service[cfssl-ocspserve@dse]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-puppet_rsa.service (cfssl-ocsprefresh-puppet_rsa.service)]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_zuul.cfg]
- Prometheus::Blackbox::Check::Http[PKI_network_devices]
- Systemd::Timer[wmf_auto_restart_apache-htcacheclean]
- Systemd::Unit[cfssl-ocspserve@cloud_wmnet_ca]
- Rsyslog::Conf[cfssl-ocsprefresh-mlserve_staging]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_staging_front_proxy.timer]
- Sudo::User[nrpe_certificate_check_dse_front_proxy]
- File[/etc/logrotate.d/cfssl-ocsprefresh-dse_front_proxy]
- Service[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.timer]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.conf]
- Exec[renew certificate - OCSP_discovery2026_pki1001_eqiad_wmnet]
- Cfssl::Ocsp[wikikube_staging_front_proxy]
- Service[wmf_auto_restart_apache-htcacheclean.timer]
- File[/etc/cfssl/csr/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/usr/local/sbin/cfssl-ocsprefresh]
- Prometheus::Node_textfile[prometheus-check-mlserve_front_proxy-certificate-expiry]
- File[/var/log/wmf_auto_restart_apache2]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-discovery.conf]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- Nrpe::Check[check_check_certificate_expiry_kafka]
- File[/var/log/ulogd]
- File[/lib/systemd/system/cfssl-ocspserve@cloud_wmnet_ca.service]
- Cfssl::Config[cloud_wmnet_ca]
- Systemd::Syslog[cfssl-ocsprefresh-network_devices]
- Systemd::Syslog[cfssl-ocsprefresh-aux]
- File[/lib/systemd/system/cfssl-ocspserve@wikikube_staging_front_proxy.service]
- File[/lib/systemd/system/cfssl-ocspserve@dse_front_proxy.service]
- Service[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.timer]
- Service[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.service (nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.service)]
- Monitoring::Service[check_certificate_expiry_wikikube]
- File[/usr/local/bin/prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- File[/var/log/prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-wikikube-staging-front-proxy-certificate-expiry.conf]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.service]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.timer]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_zuul]
- Service[cfssl-ocspserve@mlserve_staging]
- File[/lib/systemd/system/cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.timer]
- Sudo::User[nrpe_certificate_check_zuul]
- Prometheus::Alert::Rule[check_check_certificate_expiry_wikikube_d2a76a31e44e204e2d4788a2698d0e6c]
- File[/lib/systemd/system/cfssl-ocsprefresh-aux.timer]
- Cfssl::Ocsp[mlserve_front_proxy]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Exec[Generate cert OCSP_debmonitor_pki1001_eqiad_wmnet refresh]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.service)]
- Exec[Generate initial CRL for zuul]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-wikikube-staging-front-proxy.conf]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.service]
- Cfssl::Signer[syslog]
- Systemd::Timer[cfssl-ocsprefresh-mlserve_staging]
- File[/etc/ssl/dhparam.pem]
- File[/etc/apache2/ports.conf]
- File[/etc/cfssl/csr/OCSP_puppet_rsa_pki1001_eqiad_wmnet.csr]
- Service[cfssl-gc-expired-certs.timer]
- File[/etc/cfssl/signers/mlserve]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_mlserve_front_proxy]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_debmonitor]
- File[/lib/systemd/system/cfssl-ocspserve@etcd.service]
- Exec[Generate initial CRL for discovery]
- Profile::Auto_restarts::Service[apache-htcacheclean]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_zuul_pki1001_eqiad_wmnet.csr]
- File[/etc/ferm/conf.d/10_multirootca_tls_termination_for_cfssl_issuer_k8s_pods]
- Service[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.timer]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_cassandra.service]
- Exec[Generate initial CRL for discovery2026]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.service (prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.service)]
- File[/lib/systemd/system/cfssl-ocsprefresh-network_devices.timer]
- Cfssl::Config[etcd]
- Sudo::User[nrpe-check_check_certificate_expiry_aux_front_proxy]
- Logrotate::Conf[cfssl-ocsprefresh-discovery2026]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.timer]
- File[/etc/systemd/system/ferm.service.d]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_mlserve_staging]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_mlserve_staging]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.conf]
- Monitoring::Service[check_certificate_expiry_dse_front_proxy]
- Systemd::Timer[cfssl-ocsprefresh-mlserve]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_staging.service]
- Firewall::Service[csr_and_ocsp_responder]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.timer]
- Systemd::Unit[wmf_auto_restart_ulogd2.service]
- Cfssl::Config[discovery2026]
- Systemd::Timer::Job[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-mlserve-front-proxy.conf]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve.timer (nrpe2nodexp-check_certificate_expiry_mlserve.timer)]
- File[/etc/sudoers.d/nrpe_certificate_check_debmonitor]
- File[/srv/cfssl]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_syslog.service]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.service]
- File[/etc/sudoers.d/nrpe_certificate_check_cassandra]
- Monitoring::Service[check_certificate_expiry_discovery2026]
- Service[cfssl-ocsprefresh-syslog.timer]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.service]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-puppet-rsa-certificate-expiry.conf]
- Prometheus::Alert::Rule[check_check_certificate_expiry_mlserve_bfd2f7c6497e1da6323bef48d24f9e8e]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_puppet_rsa.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.timer]
- File[/srv/cfssl/bundles/discovery2026.pem]
- Systemd::Override[apache2-after-network-online-target]
- Systemd::Service[cfssl-ocsprefresh-mlserve_staging]
- Systemd::Timer[cfssl-ocsprefresh-dse]
- Exec[Generate cert OCSP_syslog_pki1001_eqiad_wmnet]
- Package[python3-cryptography]
- Systemd::Service[cfssl-ocspserve@mlserve_staging]
- File[/usr/local/bin/prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/lib/systemd/system/cfssl-gc-expired-certs.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_aux.timer (nrpe2nodexp-check_certificate_expiry_aux.timer)]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_network_devices.timer]
- Exec[Generate initial CRL for etcd]
- Systemd::Unit[nrpe2nodexp-ferm_active.service]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery2026.service (nrpe2nodexp-check_certificate_expiry_discovery2026.service)]
- Profile::Pki::Multirootca::Monitoring[dse]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery.timer]
- Service[cfssl-ocspserve@debmonitor]
- Nrpe::Check[check_check_certificate_expiry_etcd]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.service]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-cassandra.conf]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-dse-certificate-expiry.timer]
- Nrpe::Monitor_service[check_certificate_expiry_debmonitor]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_staging_front_proxy.timer (cfssl-ocsprefresh-wikikube_staging_front_proxy.timer)]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- File[/var/log/prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Service[nrpe2nodexp-check_certificate_expiry_wikikube_staging.timer]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.conf]
- Logrotate::Conf[wmf_auto_restart_apache2]
- Prometheus::Node_textfile[prometheus-check-kafka-certificate-expiry]
- Exec[Generate initial CRL for network_devices]
- File[/etc/cfssl/signers/discovery2026/ca]
- Rsyslog::Conf[cfssl-ocsprefresh-dse]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_aux]
- Rsyslog::Conf[cfssl-ocsprefresh-discovery]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.timer]
- Prometheus::Node_textfile[prometheus-check-wikikube_staging-certificate-expiry]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- File[/lib/systemd/system/cfssl-ocspserve@aux_front_proxy.service]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery.service]
- Prometheus::Node_textfile[prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_pki1001_eqiad_wmnet-key.pem]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.service]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_staging_front_proxy.timer]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.timer)]
- Nrpe::Check[check_check_certificate_expiry_discovery2026]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Systemd::Timer[cfssl-ocsprefresh-syslog]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_pki1001_eqiad_wmnet-key.pem]
- File[/srv/cfssl/bundles/syslog.pem]
- File[/etc/sudoers.d/nrpe_certificate_check_syslog]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_aux.service (nrpe2nodexp-check_certificate_expiry_aux.service)]
- File[/etc/cfssl/ocsp/puppet_rsa.ocsp]
- File[/etc/apache2/sites-available]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_cassandra]
- File[/usr/local/lib/nagios/plugins/check_ferm]
- File[/etc/cfssl/signers/wikikube_staging_front_proxy/cfssl.conf]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-mlserve-staging.conf]
- Exec[Generate initial CRL for mlserve_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet-key.pem]
- Systemd::Unit[cfssl-ocsprefresh-discovery2026.timer]
- Systemd::Unit[cfssl-ocspserve@zuul]
- File[/etc/cfssl/ssl/ocsp/OCSP_etcd_pki1001_eqiad_wmnet.csr]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Rsyslog::Conf[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Systemd::Timer::Job[cfssl-ocsprefresh-mlserve_front_proxy]
- Systemd::Service[cfssl-ocspserve@wikikube_staging]
- File[/srv/cfssl/bundles/mlserve.pem]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_discovery2026.prom]
- Systemd::Timer::Job[cfssl-ocsprefresh-syslog]
- Systemd::Syslog[cfssl-ocsprefresh-dse_front_proxy]
- Systemd::Service[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service (prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service)]
- Exec[Generate initial CRL for wikikube_staging]
- Exec[renew certificate - OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet]
- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-aux-certificate-expiry.timer]
- File[/srv/cfssl/bundles/aux.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_front_proxy_pki1001_eqiad_wmnet.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_syslog_pki1001_eqiad_wmnet.pem]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_syslog_pki1001_eqiad_wmnet.csr]
- Systemd::Service[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-puppet-rsa.conf]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_debmonitor.timer]
- Cfssl::Cert[OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_cassandra]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.timer]
- Prometheus::Alert::Rule[check_check_certificate_expiry_debmonitor_224e2ac3574a9ce482218106d95a2931]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_puppet_rsa.service (nrpe2nodexp-check_certificate_expiry_puppet_rsa.service)]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-aux-front-proxy-certificate-expiry.conf]
- Systemd::Timer::Job[cfssl-ocsprefresh-discovery2026]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.service]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocspserve@mlserve_staging_front_proxy.service (cfssl-ocspserve@mlserve_staging_front_proxy)]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_puppet_rsa]
- Service[cfssl-ocsprefresh-aux_front_proxy.timer]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_aux_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.timer)]
- File[/var/log/cfssl-ocsprefresh-mlserve_front_proxy]
- Sudo::User[nrpe_certificate_check_wikikube_staging_front_proxy]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_wikikube_staging]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_puppet_rsa.service]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.timer]
- File[/srv/cfssl/bundles/aux_front_proxy.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.pem]
- File[/var/log/cfssl-ocsprefresh-network_devices]
- Cfssl::Config[aux_front_proxy]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Monitoring::Exported_nagios_service[pki1001 check_cfssl-multirootca_status]
- File[/etc/cfssl/ssl/ocsp/OCSP_debmonitor_pki1001_eqiad_wmnet.pem]
- Systemd::Syslog[cfssl-ocsprefresh-aux_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_pki1001_eqiad_wmnet-key.pem]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.service]
- File[/srv/cfssl/bundles/wikikube.pem]
- Sudo::User[nrpe_certificate_check_puppet_rsa]
- Systemd::Timer[cfssl-ocsprefresh-discovery]
- Exec[renew certificate - OCSP_mlserve_staging_pki1001_eqiad_wmnet]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-syslog.conf]
- Exec[renew certificate - OCSP_kafka_pki1001_eqiad_wmnet]
- File[/etc/cfssl/multiroot.conf]
- Cfssl::Signer[wikikube_front_proxy]
- Ferm::Service[multirootca_tls_termination]
- Systemd::Syslog[cfssl-ocsprefresh-debmonitor]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_front_proxy.timer]
- Exec[systemd daemon-reload for cfssl-gc-expired-certs.timer (cfssl-gc-expired-certs.timer)]
- Cfssl::Config[syslog]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_network_devices]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-mlserve-staging-front-proxy.conf]
- Service[nrpe2nodexp-check_certificate_expiry_discovery2026.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_kafka.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Exec[systemd daemon-reload for wmf_auto_restart_apache2.service (wmf_auto_restart_apache2.service)]
- Prometheus::Alert::Rule[check_check_certificate_expiry_network_devices_21dac3775d059b8c991626e2ca33f951]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_kafka.service]
- Cfssl::Signer[discovery2026]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-dse-front-proxy-certificate-expiry.conf]
- File[/etc/cfssl/signers/mlserve/ca/mlserve.pem]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.service]
- Class[Httpd]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-wikikube-front-proxy-certificate-expiry.conf]
- File[/etc/cfssl/signers/aux_front_proxy/ca/aux_front_proxy.pem]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.service (prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.service)]
- Profile::Auto_restarts::Service[apache2]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve.service]
- Systemd::Timer::Job[wmf_auto_restart_apache-htcacheclean]
- Cfssl::Signer[wikikube]
- Profile::Pki::Multirootca::Monitoring[wikikube]
- Systemd::Unit[cfssl-ocspserve@dse]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Systemd::Timer::Job[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_cassandra]
- File[/etc/cfssl/signers/mlserve_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery2026_pki1001_eqiad_wmnet.pem]
- Systemd::Syslog[cfssl-ocsprefresh-mlserve_staging]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_aux.timer]
- Service[apache2]
- Systemd::Timer::Job[cfssl-ocsprefresh-wikikube]
- File[/etc/logrotate.d/cfssl-ocsprefresh-puppet_rsa]
- File[/etc/logrotate.d/cfssl-ocsprefresh-cassandra]
- Prometheus::Alert::Rule[check_check_certificate_expiry_etcd_c834f873297e445663ead81279c0b928]
- Exec[renew certificate - OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet]
- Service[cfssl-ocsprefresh-mlserve_front_proxy.timer]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-etcd.conf]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_mlserve_staging_pki1001_eqiad_wmnet.csr]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging.cfg]
- Service[cfssl-ocsprefresh-zuul.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-cloud-wmnet-ca.conf]
- File[/etc/cfssl/signers/cloud_wmnet_ca/cfssl.conf]
- File[/etc/cfssl/signers/mlserve_front_proxy/cfssl.conf]
- File[/etc/logrotate.d/cfssl-ocsprefresh-kafka]
- File[/etc/cfssl/ocsp/aux.ocsp]
- Service[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.timer]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_syslog.timer (nrpe2nodexp-check_certificate_expiry_syslog.timer)]
- Systemd::Unit[cfssl-ocsprefresh-cloud_wmnet_ca.timer]
- Nrpe::Monitor_service[check_certificate_expiry_wikikube_staging]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_pki1001_eqiad_wmnet.csr]
- File[/var/log/prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- File[/lib/systemd/system/cfssl-ocsprefresh-cassandra.timer]
- Systemd::Unit[cfssl-ocsprefresh-zuul.timer]
- Systemd::Unit[cfssl-ocsprefresh-puppet_rsa.timer]
- Systemd::Service[cfssl-ocsprefresh-zuul]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Monitoring::Service[check_certificate_expiry_mlserve_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery2026_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/wikikube_front_proxy/cfssl.conf]
- Class[Ulogd]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_wikikube]
- File[/etc/cfssl/signers/zuul]
- Systemd::Service[cfssl-ocspserve@aux]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_mlserve_pki1001_eqiad_wmnet.csr]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve.service (nrpe2nodexp-check_certificate_expiry_mlserve.service)]
- File[/etc/logrotate.d/cfssl-ocsprefresh-etcd]
- Cfssl::Config[kafka]
- Exec[Generate cert OCSP_etcd_pki1001_eqiad_wmnet refresh]
- Exec[Generate cert OCSP_zuul_pki1001_eqiad_wmnet refresh]
- Exec[Generate cert OCSP_aux_pki1001_eqiad_wmnet refresh]
- Systemd::Service[cfssl-ocspserve@kafka]
- File[/etc/apache2/sites-enabled]
- Prometheus::Alert::Rule[check_check_certificate_expiry_wikikube_front_proxy_4d759acaf0fd7dd3abaa03dc4565aef6]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-aux-front-proxy.conf]
- Systemd::Unit[apache2-apache2-after-network-online-target]
- Systemd::Service[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Nrpe::Monitor_service[check_certificate_expiry_dse]
- Logrotate::Conf[cfssl-ocsprefresh-etcd]
- Ferm::Conf[main]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_syslog]
- Systemd::Service[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Cfssl::Signer[cloud_wmnet_ca]
- Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- Service[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.timer]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery2026.timer (cfssl-ocsprefresh-discovery2026.timer)]
- File[/etc/cfssl/signers/discovery2026/ca/discovery2026-key.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_pki1001_eqiad_wmnet.pem]
- Service[nrpe2nodexp-check_certificate_expiry_dse.timer]
- Exec[systemd daemon-reload for cfssl-ocspserve@cassandra.service (cfssl-ocspserve@cassandra)]
- Prometheus::Node_textfile[prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_cassandra.cfg]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_debmonitor]
- File[/srv/cfssl/bundles/etcd.pem]
- Logrotate::Conf[cfssl-ocsprefresh-syslog]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_front_proxy.service]
- File[/etc/cfssl/ocsp/mlserve_front_proxy.ocsp]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_wikikube]
- Cfssl::Config[mlserve_staging]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_debmonitor.service]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_dse_front_proxy.service (nrpe2nodexp-check_certificate_expiry_dse_front_proxy.service)]
- Service[nrpe2nodexp-check_certificate_expiry_aux_front_proxy.timer]
- File[/var/log/prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_staging.timer (nrpe2nodexp-check_certificate_expiry_mlserve_staging.timer)]
- Service[cfssl-ocsprefresh-mlserve.timer]
- Exec[Generate initial CRL for wikikube_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocspserve@zuul.service (cfssl-ocspserve@zuul)]
- Service[nrpe2nodexp-check_certificate_expiry_etcd.timer]
- Exec[systemd daemon-reload for cfssl-ocspserve@discovery.service (cfssl-ocspserve@discovery)]
- File[/etc/cfssl/signers/mlserve_front_proxy]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-discovery.conf]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_dse_front_proxy]
- Systemd::Service[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Service[cfssl-ocspserve@Wikimedia_Internal_Root_CA]
- Prometheus::Blackbox::Check::Http[PKI_kafka]
- Httpd::Mod_conf[access_compat]
- Sudo::User[nrpe_certificate_check_cassandra]
- File[/etc/ferm/conf.d/98_filter_log_filter-bootp]
- Sudo::User[nrpe-check_check_certificate_expiry_mlserve]
- Monitoring::Service[check_certificate_expiry_mlserve_staging]
- Systemd::Unit[cfssl-ocsprefresh-kafka.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube.service]
- Sudo::User[nrpe_certificate_check_aux_front_proxy]
- File[/etc/cfssl/signers/aux/cfssl.conf]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube.timer (nrpe2nodexp-check_certificate_expiry_wikikube.timer)]
- Exec[Generate initial CRL for dse]
- Prometheus::Blackbox::Check::Http[PKI_discovery]
- Nrpe::Monitor_service[check_certificate_expiry_cloud_wmnet_ca]
- Systemd::Unit[cfssl-ocsprefresh-network_devices.service]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.timer]
- File[/lib/systemd/system/cfssl-ocspserve@kafka.service]
- Exec[systemd daemon-reload for nrpe2nodexp-check_cfssl-multirootca_status.service (nrpe2nodexp-check_cfssl-multirootca_status.service)]
- Systemd::Service[cfssl-ocspserve@mlserve]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_staging.service]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-wikikube-front-proxy.conf]
- Exec[Generate initial CRL for mlserve_staging]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.timer]
- File[/lib/systemd/system/cfssl-ocspserve@aux.service]
- Systemd::Unit[cfssl-gc-expired-certs.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-debmonitor.service]
- File[/etc/sudoers.d/nrpe_certificate_check_aux]
- Ferm::Filter_log[filter-bootp]
- Exec[systemd daemon-reload for cfssl-ocspserve@kafka.service (cfssl-ocspserve@kafka)]
- Service[cfssl-ocsprefresh-dse.timer]
- Systemd::Timer[wmf_auto_restart_ulogd2]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- File[/etc/cfssl/signers/zuul/ca/zuul.pem]
- File[/etc/logrotate.d/cfssl-ocsprefresh-discovery]
- Httpd::Mod_conf[headers]
- File[/etc/cfssl/signers/mlserve_staging_front_proxy/ca/mlserve_staging_front_proxy-key.pem]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service]
- Cfssl::Cert[OCSP_dse_front_proxy_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/cfssl-ocsprefresh-cloud_wmnet_ca.timer]
- Exec[systemd daemon-reload for cfssl-ocspserve@network_devices.service (cfssl-ocspserve@network_devices)]
- Class[Profile::Firewall::Log::Ferm]
- File[/etc/sudoers.d/nrpe_certificate_check_mlserve_staging_front_proxy]
- File[/srv/cfssl/bundles/cloud_wmnet_ca.pem]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_discovery2026_pki1001_eqiad_wmnet.csr]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.service (prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.service)]
- File[/lib/systemd/system/wmf_auto_restart_ulogd2.timer]
- Exec[Generate cert OCSP_mlserve_pki1001_eqiad_wmnet]
- Prometheus::Alert::Rule[check_check_certificate_expiry_mlserve_staging_7cff186656c3cabbca85b5b57d0c8679]
- File[/etc/cfssl/signers/wikikube_staging/ca]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_staging.timer (cfssl-ocsprefresh-mlserve_staging.timer)]
- Sudo::User[nrpe_certificate_check_aux]
- File[/var/log/cfssl-ocsprefresh-puppet_rsa]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_mlserve_staging]
- File[/srv/cfssl/bundles/dse.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_debmonitor.service]
- Systemd::Unit[cfssl-multirootca]
- Systemd::Syslog[cfssl-ocsprefresh-etcd]
- File[/etc/cfssl/ssl/ocsp/OCSP_debmonitor_pki1001_eqiad_wmnet-key.pem]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.service]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_etcd.service]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- Alternatives::Select[iptables]
- Systemd::Monitor[cfssl-multirootca]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.service]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_pki1001_eqiad_wmnet.csr]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_aux_front_proxy.prom]
- Cfssl::Ocsp[etcd]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_syslog.service (nrpe2nodexp-check_certificate_expiry_syslog.service)]
- Service[cfssl-ocspserve@kafka]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.service (prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.service)]
- Nrpe::Monitor_service[check_certificate_expiry_discovery]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.timer)]
- File[/var/log/prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- File[/etc/cfssl/signers/mlserve_staging_front_proxy/ca]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_network_devices]
- File[/etc/cfssl/csr/OCSP_syslog_pki1001_eqiad_wmnet.csr]
- Systemd::Timer::Job[cfssl-ocsprefresh-puppet_rsa]
- Cfssl::Config[debmonitor]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.service]
- Profile::Pki::Multirootca::Monitoring[mlserve]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_dse]
- Service[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.timer]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.timer)]
- Systemd::Timer::Job[cfssl-ocsprefresh-mlserve]
- Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-status-restart)]
- Cfssl::Ocsp[discovery2026]
- File[/etc/cfssl/ssl/ocsp/OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet.csr]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-dse-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-dse-certificate-expiry.timer)]
- Cfssl::Config[aux]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_zuul]
- Service[nrpe2nodexp-check_certificate_expiry_debmonitor.timer]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_wikikube.prom]
- Monitoring::Service[check_certificate_expiry_mlserve_front_proxy]
- Logrotate::Conf[wmf_auto_restart_apache-htcacheclean]
- File[/etc/cfssl/csr/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.timer]
- Prometheus::Alert::Rule[check_check_certificate_expiry_cloud_wmnet_ca_f87f54115f2f782169eed72541c30a1e]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_cassandra]
- Cfssl::Signer[mlserve_staging_front_proxy]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-aux-certificate-expiry.conf]
- Service[prometheus-node-textfile-prometheus-check-dse-certificate-expiry.timer]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-aux.timer]
- Prometheus::Alert::Rule[check_check_certificate_expiry_wikikube_staging_f389c556cebfcfc345b3d6802f320045]
- Service[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.timer]
- Systemd::Syslog[cfssl-ocsprefresh-dse]
- Systemd::Unit[cfssl-ocspserve@mlserve_staging_front_proxy]
- Systemd::Unit[cfssl-ocsprefresh-cloud_wmnet_ca.service]
- Rsyslog::Conf[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_pki1001_eqiad_wmnet-key.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery2026_pki1001_eqiad_wmnet-key.pem]
- Prometheus::Alert::Rule[check_check_certificate_expiry_aux_front_proxy_99cf4f8f014e8fd527800abcc213f494]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_mlserve]
- Nrpe::Monitor_service[check_certificate_expiry_mlserve_staging]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_staging.service (nrpe2nodexp-check_certificate_expiry_mlserve_staging.service)]
- File[/etc/rsyslog.d/40-wmf-auto-restart-apache-htcacheclean.conf]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Exec[ensure_present_mod_status]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet-key.pem]
- Systemd::Service[cfssl-ocspserve@aux_front_proxy]
- File[/etc/cfssl/ocsp/wikikube_staging.ocsp]
- Service[cfssl-ocspserve@zuul]
- Systemd::Timer::Job[cfssl-ocsprefresh-aux_front_proxy]
- File[/lib/systemd/system/cfssl-gc-expired-certs.service]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_dse.prom]
- Systemd::Unit[cfssl-ocsprefresh-discovery2026.service]
- File[/etc/logrotate.d/cfssl-ocsprefresh-dse]
- Service[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.timer]
- File[/lib/systemd/system/cfssl-ocspserve@syslog.service]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-wikikube-staging.conf]
- Cfssl::Config[wikikube_front_proxy]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Syslog[cfssl-ocsprefresh-mlserve_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube.timer (cfssl-ocsprefresh-wikikube.timer)]
- Exec[renew certificate - OCSP_zuul_pki1001_eqiad_wmnet]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_pki1001_eqiad_wmnet.csr]
- Cfssl::Signer[mlserve]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_discovery2026]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-network_devices.timer (cfssl-ocsprefresh-network_devices.timer)]
- File[/lib/systemd/system/wmf_auto_restart_apache2.timer]
- Exec[systemd daemon-reload for cfssl-ocspserve@mlserve.service (cfssl-ocspserve@mlserve)]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Service[nrpe2nodexp-ferm_active.timer]
- Service[nrpe2nodexp-check_cfssl-multirootca_status.timer]
- File[/lib/systemd/system/cfssl-ocspserve@mlserve_staging_front_proxy.service]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_dse.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.service]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- File[/etc/cfssl/ocsp/aux_front_proxy.ocsp]
- Logrotate::Conf[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- Systemd::Timer[cfssl-ocsprefresh-etcd]
- Motd::Message[pki::multirootca]
- Service[wmf_auto_restart_apache2.timer]
- Cfssl::Cert[OCSP_wikikube_staging_pki1001_eqiad_wmnet]
- Systemd::Service[cfssl-ocspserve@mlserve_staging_front_proxy]
- File[/etc/apache2/mods-available/status.conf]
- Nrpe::Plugin[check_ferm]
- Rsyslog::Conf[cfssl-ocsprefresh-cloud_wmnet_ca]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.timer]
- Prometheus::Blackbox::Check::Http[PKI_zuul]
- Exec[systemd daemon-reload for nrpe2nodexp-ferm_active.timer (nrpe2nodexp-ferm_active.timer)]
- Sudo::User[nrpe-check_check_certificate_expiry_etcd]
- File[/etc/logrotate.d/cfssl-ocsprefresh-debmonitor]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.timer]
- Cfssl::Ocsp[mlserve]
- Service[cfssl-ocsprefresh-network_devices.timer]
- Systemd::Service[cfssl-ocspserve@debmonitor]
- Service[cfssl-ocsprefresh-cloud_wmnet_ca.timer]
- File[/etc/cfssl/signers/kafka/cfssl.conf]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_etcd]
- Prometheus::Blackbox::Check::Http[PKI_cassandra]
- Rsyslog::Conf[cfssl-ocsprefresh-puppet_rsa]
- Prometheus::Alert::Rule[check_check_certificate_expiry_discovery2026_bf2e3510cb63e5f05f545e816bab4edf]
- Cfssl::Signer[debmonitor]
- File[/etc/cfssl/signers/cloud_wmnet_ca/ca/cloud_wmnet_ca-key.pem]
- Prometheus::Alert::Rule[check_check_certificate_expiry_zuul_373325faaa689f3e9b058d91d4eb6cdb]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_pki1001_eqiad_wmnet.pem]
- Service[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.timer]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_puppet_rsa.prom]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-aux.conf]
- Service[cfssl-ocspserve@mlserve_front_proxy]
- Logrotate::Conf[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-wikikube-staging.conf]
- Sudo::User[nrpe-check_check_certificate_expiry_wikikube_front_proxy]
- Exec[Generate initial CRL for mlserve_front_proxy]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.service]
- Systemd::Service[cfssl-ocspserve@wikikube_front_proxy]
- Prometheus::Node_textfile[prometheus-check-discovery2026-certificate-expiry]
- Profile::Pki::Multirootca::Monitoring[kafka]
- Sudo::User[nrpe_certificate_check_wikikube_staging]
- File[/usr/local/bin/prometheus-check-cloud_wmnet_ca-certificate-expiry]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-mlserve-staging.conf]
- Systemd::Service[cfssl-ocsprefresh-discovery2026]
- File[/etc/cfssl/signers/cloud_wmnet_ca/ca/cloud_wmnet_ca.pem]
- Rsyslog::Conf[cfssl-ocsprefresh-mlserve]
- Systemd::Syslog[cfssl-gc-expired-certs]
- Systemd::Syslog[cfssl-ocsprefresh-mlserve]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Exec[renew certificate - OCSP_mlserve_pki1001_eqiad_wmnet]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.service)]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_aux_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.timer)]
- Service[cfssl-ocspserve@syslog]
- File[/etc/cfssl/signers/syslog/ca]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- File[/etc/cfssl/signers/zuul/ca]
- Sudo::User[nrpe-check_check_certificate_expiry_zuul]
- File[/etc/logrotate.d/cfssl-ocsprefresh-mlserve]
- Systemd::Timer[wmf_auto_restart_apache2]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_mlserve_staging_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_pki1001_eqiad_wmnet.pem]
- Cfssl::Signer[kafka]
- File[/etc/cfssl/signers/cloud_wmnet_ca]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_staging.timer]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_staging.timer (cfssl-ocsprefresh-wikikube_staging.timer)]
- Systemd::Syslog[cfssl-ocsprefresh-syslog]
- Nrpe::Check[check_check_certificate_expiry_puppet_rsa]
- Service[cfssl-ocsprefresh-mlserve_staging_front_proxy.timer]
- Systemd::Timer::Job[cfssl-ocsprefresh-cassandra]
- Systemd::Syslog[cfssl-ocsprefresh-cloud_wmnet_ca]
- File[/etc/cfssl/ssl/ocsp/OCSP_etcd_pki1001_eqiad_wmnet-key.pem]
- Exec[Generate cert OCSP_dse_front_proxy_pki1001_eqiad_wmnet]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- Exec[Generate initial CRL for wikikube]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_cloud_wmnet_ca.prom]
- File[/usr/local/bin/prometheus-check-discovery2026-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocspserve@puppet_rsa.service (cfssl-ocspserve@puppet_rsa)]
- File[/etc/cfssl/ocsp/etcd.ocsp]
- File[/etc/cfssl/ssl/ocsp/OCSP_network_devices_pki1001_eqiad_wmnet-key.pem]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_debmonitor]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_dse_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_dse_front_proxy.timer)]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-discovery2026.conf]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.timer)]
- File[/etc/ferm/conf.d/10_ssh_from_bastion]
- Rsyslog::Conf[cfssl-gc-expired-certs]
- Exec[renew certificate - OCSP_dse_pki1001_eqiad_wmnet]
- Systemd::Unit[cfssl-ocspserve@kafka]
- Profile::Pki::Multirootca::Monitoring[discovery2026]
- Systemd::Unit[cfssl-ocspserve@aux]
- Prometheus::Blackbox::Check::Http[PKI_puppet_rsa]
- Systemd::Unit[cfssl-ocsprefresh-syslog.service]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.timer]
- Systemd::Unit[cfssl-ocspserve@syslog]
- Systemd::Timer[cfssl-ocsprefresh-zuul]
- File[/etc/apache2/sites-enabled/00-dummy.conf]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-mlserve.conf]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-mlserve-front-proxy-certificate-expiry.conf]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.service)]
- File[/var/log/cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Class[Cfssl::Multirootca]
- File[/etc/cfssl/signers/wikikube_staging_front_proxy/ca]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_staging.timer]
- Systemd::Service[cfssl-ocspserve@wikikube_staging_front_proxy]
- File[/lib/systemd/system/wmf_auto_restart_apache2.service]
- Profile::Pki::Multirootca::Monitoring[aux]
- Exec[systemd daemon-reload for cfssl-ocspserve@etcd.service (cfssl-ocspserve@etcd)]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.timer]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.timer]
- Prometheus::Node_textfile[prometheus-check-mlserve-certificate-expiry]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Sudo::User[nrpe-check_check_certificate_expiry_kafka]
- Systemd::Service[cfssl-ocsprefresh-dse]
- Cfssl::Signer[mlserve_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocspserve@cloud_wmnet_ca.service (cfssl-ocspserve@cloud_wmnet_ca)]
- Httpd::Conf[dummy]
- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.service (wmf_auto_restart_ulogd2.service)]
- Monitoring::Service[check_certificate_expiry_zuul]
- File[/etc/cfssl/signers/discovery/ca/discovery.pem]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- Node[__node_regexp__pki10012.eqiad.]
- File[/etc/update-motd.d/05-pki--multirootca]
- Systemd::Unit[cfssl-ocspserve@mlserve_front_proxy]
- Profile::Pki::Multirootca::Monitoring[network_devices]
- Nrpe::Monitor_service[check_certificate_expiry_puppet_rsa]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.service)]
- Systemd::Timer::Job[cfssl-ocsprefresh-discovery]
- File[/etc/apache2/env-enabled]
- Prometheus::Node_textfile[prometheus-check-cassandra-certificate-expiry]
- File[/etc/cfssl/signers/wikikube/ca/wikikube.pem]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet.csr]
- File[/etc/sudoers.d/nrpe_certificate_check_mlserve]
- File[/lib/systemd/system/cfssl-ocsprefresh-dse_front_proxy.service]
- File[/srv/cfssl/bundles]
- Cfssl::Cert[OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet]
- File[/etc/cfssl/ssl/ocsp/OCSP_zuul_pki1001_eqiad_wmnet-key.pem]
- Systemd::Override[ferm-service-status-restart]
- File[/var/log/cfssl-ocsprefresh-zuul]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.service]
- Ferm::Service[full_monitoring_metrics_access_tcp]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_dse.service]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-cloud-wmnet-ca.conf]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_cloud_wmnet_ca.cfg]
- Profile::Pki::Multirootca::Monitoring[discovery]
- Systemd::Unit[cfssl-ocsprefresh-wikikube.service]
- File[/etc/cfssl/ocsp/dse_front_proxy.ocsp]
- Service[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.timer]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.timer]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_discovery]
- File[/lib/systemd/system/cfssl-ocspserve@debmonitor.service]
- Systemd::Timer[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-aux-certificate-expiry.service]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.timer]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.timer)]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-wikikube.conf]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_pki1001_eqiad_wmnet.csr]
- Prometheus::Blackbox::Check::Http[PKI_mlserve_staging]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy]
- Sudo::User[nrpe_certificate_check_mlserve_staging]
- File[/usr/local/bin/prometheus-check-dse-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.timer]
- File[/etc/cfssl/csr/OCSP_wikikube_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/discovery/ca/discovery-key.pem]
- File[/etc/cfssl/ocsp/discovery2026.ocsp]
- Prometheus::Blackbox::Check::Http[PKI_etcd]
- File[/etc/apache2/conf-enabled/50-server-status.conf]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_puppet_rsa]
- File[/etc/apache2/sites-enabled/50-pki-discovery-wmnet.conf]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_etcd.cfg]
- Exec[systemd daemon-reload for cfssl-gc-expired-certs.service (cfssl-gc-expired-certs.service)]
- Systemd::Unit[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.service]
- Exec[renew certificate - OCSP_aux_pki1001_eqiad_wmnet]
- Prometheus::Alert::Rule[check_check_certificate_expiry_dse_4384c5ebc49e03dbe331e279fac3f393]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_zuul.timer]
- File[/etc/cfssl/csr/OCSP_kafka_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/mlserve_staging/ca/mlserve_staging.pem]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_kafka]
- Service[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-syslog.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- File[/etc/cfssl/signers/wikikube_staging/cfssl.conf]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.service]
- File[/etc/cfssl/ssl/Wikimedia_Internal_Root_CA.pem]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy]
- Systemd::Unit[cfssl-ocspserve@debmonitor]
- Exec[apache2_test_config_and_restart]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_pki1001_eqiad_wmnet.pem]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-aux.timer (cfssl-ocsprefresh-aux.timer)]
- File[/etc/apache2/conf-enabled/50-cfssl-issuer-k8s-pods-vhost-port.conf]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_staging_front_proxy.timer (cfssl-ocsprefresh-mlserve_staging_front_proxy.timer)]
- File[/etc/cfssl/signers/mlserve_staging_front_proxy/ca/mlserve_staging_front_proxy.pem]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-dse-certificate-expiry.timer]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.service]
- Nrpe::Monitor_service[check_cfssl-multirootca_status]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_dse.timer (nrpe2nodexp-check_certificate_expiry_dse.timer)]
- Service[nrpe2nodexp-check_certificate_expiry_cassandra.timer]
- Systemd::Timer[cfssl-ocsprefresh-discovery2026]
- Profile::Pki::Multirootca::Monitoring[puppet_rsa]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-zuul.conf]
- File[/etc/logrotate.d/cfssl-ocsprefresh-zuul]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_discovery.service]
- Prometheus::Alert::Rule[check_check_certificate_expiry_cassandra_f5e260f525c48c963fb2e6c86a0d5d63]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.service (prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.service)]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.timer)]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.timer]
- Exec[Generate cert OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.timer)]
- File[/var/log/cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Systemd::Timer::Job[cfssl-ocsprefresh-debmonitor]
- File[/etc/cfssl/signers/discovery2026/ca/discovery2026.pem]
- File[/etc/cfssl/csr/OCSP_mlserve_pki1001_eqiad_wmnet.csr]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_aux]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.service]
- Cfssl::Ocsp[cassandra]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-dse.conf]
- Systemd::Unit[cfssl-ocsprefresh-zuul.service]
- Service[prometheus-node-textfile-prometheus-check-aux-certificate-expiry.timer]
- Systemd::Unit[cfssl-ocsprefresh-dse.service]
- Package[apache2]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_staging_front_proxy.service]
- Systemd::Service[cfssl-ocsprefresh-aux]
- File[/etc/cfssl/csr/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/cfssl-ocsprefresh-kafka.service]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-debmonitor.conf]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.timer]
- File_line[auto_restart_file_presence_ulogd2]
- File[/etc/cfssl/ssl/ocsp/OCSP_puppet_rsa_pki1001_eqiad_wmnet.csr]
- Systemd::Service[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Service[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.timer]
- File[/etc/cfssl/signers/cassandra/cfssl.conf]
- Exec[Generate cert OCSP_puppet_rsa_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.service]
- Logrotate::Conf[cfssl-ocsprefresh-kafka]
- File[/lib/systemd/system/nrpe2nodexp-check_cfssl-multirootca_status.service]
- Nrpe::Monitor_service[ferm_active]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-kafka.conf]
- Nrpe::Monitor_service[check_certificate_expiry_zuul]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_network_devices.service]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Prometheus::Blackbox::Check::Http[PKI_cloud_wmnet_ca]
- Cfssl::Signer[cassandra]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_discovery]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_debmonitor.service (nrpe2nodexp-check_certificate_expiry_debmonitor.service)]
- Profile::Pki::Multirootca::Monitoring[cassandra]
- Prometheus::Alert::Rule[check_check_certificate_expiry_discovery_38e4dbcfd07ed60daf5bb89397abbe29]
- Service[cfssl-ocsprefresh-dse_front_proxy.timer]
- File[/etc/cfssl/csr/OCSP_aux_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Syslog[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- Logrotate::Conf[cfssl-ocsprefresh-discovery]
- Nrpe::Monitor_service[check_certificate_expiry_wikikube_front_proxy]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_network_devices.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-aux_front_proxy.service]
- File[/etc/cfssl/signers/debmonitor]
- File[/etc/sudoers.d/nrpe_certificate_check_etcd]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-aux-front-proxy.conf]
- Systemd::Timer::Job[cfssl-ocsprefresh-cloud_wmnet_ca]
- Cfssl::Cert[OCSP_etcd_pki1001_eqiad_wmnet]
- Service[cfssl-ocsprefresh-discovery2026.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_dse]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- File[/etc/cfssl/signers/puppet_rsa]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Exec[Generate cert OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet]
- Systemd::Unit[cfssl-ocspserve@wikikube_staging]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.service (cfssl-ocsprefresh-debmonitor.service)]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_mlserve_staging]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet.chain.pem]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.timer)]
- Exec[Generate cert puppet_rsa__pki_discovery_wmnet refresh on intermediate ca change]
- File[/etc/ferm/conf.d/02_main]
- Ferm::Rule[log-everything]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.service]
- Service[nrpe2nodexp-check_certificate_expiry_wikikube.timer]
- Monitoring::Service[check_certificate_expiry_cassandra]
- File[/var/log/prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- File[/etc/cfssl/signers/syslog]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- File[/usr/local/bin/prometheus-check-wikikube-certificate-expiry]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube.cfg]
- File[/etc/logrotate.d/cfssl-gc-expired-certs]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_dse]
- Systemd::Service[cfssl-ocspserve@syslog]
- Exec[renew certificate - OCSP_wikikube_staging_pki1001_eqiad_wmnet]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube.timer]
- File[/lib/systemd/system/wmf_auto_restart_ulogd2.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.timer)]
- File[/lib/systemd/system/cfssl-ocspserve@dse.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.timer (cfssl-ocsprefresh-mlserve.timer)]
- File[/etc/cfssl/signers/puppet_rsa/cfssl.conf]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- Exec[ensure_present_mod_headers]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-aux-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-aux-certificate-expiry.timer)]
- Systemd::Unit[cfssl-ocspserve@mlserve]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Monitoring::Service[check_certificate_expiry_network_devices]
- Systemd::Service[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Sudo::User[nrpe_certificate_check_debmonitor]
- Systemd::Service[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.timer)]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_mlserve]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery.service (cfssl-ocsprefresh-discovery.service)]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_wikikube]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_staging.timer]
- File[/etc/cfssl/signers/discovery2026/cfssl.conf]
- Rsyslog::Conf[cfssl-ocsprefresh-kafka]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_wikikube]
- File[/etc/cfssl/ocsp/zuul.ocsp]
- Prometheus::Blackbox::Check::Http[PKI_discovery2026]
- Systemd::Service[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- Exec[Generate cert OCSP_aux_front_proxy_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/cfssl-ocsprefresh-etcd.service]
- Sudo::User[nrpe_certificate_check_mlserve_front_proxy]
- Logrotate::Conf[cfssl-ocsprefresh-wikikube_front_proxy]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_syslog.prom]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_cassandra]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_dse_front_proxy]
- Package[ulogd2]
- Cfssl::Cert[OCSP_syslog_pki1001_eqiad_wmnet]
- Prometheus::Blackbox::Check::Http[PKI_wikikube_staging]
- Systemd::Unit[cfssl-ocsprefresh-aux.service]
- File[/etc/systemd/system/apache2.service.d/apache2-after-network-online-target.conf]
- File[/lib/systemd/system/cfssl-ocsprefresh-puppet_rsa.timer]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Service[nrpe2nodexp-check_certificate_expiry_dse_front_proxy.timer]
- Logrotate::Conf[cfssl-ocsprefresh-aux]
- Prometheus::Alert::Rule[check_check_certificate_expiry_aux_f7dfe9e2cd77303dfae7ae11c5c56d90]
- Rsyslog::Conf[cfssl-ocsprefresh-aux]
- File[/usr/local/bin/prometheus-check-mlserve-certificate-expiry]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_kafka.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_aux_front_proxy.timer]
- File[/etc/logrotate.d/wmf_auto_restart_apache2]
- Systemd::Unit[cfssl-ocspserve@discovery]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.conf]
- File[/etc/cfssl/signers/kafka]
- Exec[systemd daemon-reload for wmf_auto_restart_apache-htcacheclean.service (wmf_auto_restart_apache-htcacheclean.service)]
- Systemd::Service[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.timer]
- Systemd::Syslog[cfssl-ocsprefresh-kafka]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_mlserve_staging_front_proxy.prom]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_etcd]
- Systemd::Unit[nrpe2nodexp-ferm_active.timer]
- Monitoring::Service[check_certificate_expiry_aux]
- File[/etc/cfssl/signers/cassandra/ca/cassandra-key.pem]
- Rsyslog::Conf[cfssl-ocsprefresh-dse_front_proxy]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet.chained.pem]
- Monitoring::Service[check_certificate_expiry_syslog]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_kafka.service (nrpe2nodexp-check_certificate_expiry_kafka.service)]
- Systemd::Unit[cfssl-ocsprefresh-aux_front_proxy.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-cloud_wmnet_ca.timer (cfssl-ocsprefresh-cloud_wmnet_ca.timer)]
- File[/etc/logrotate.d/wmf_auto_restart_apache-htcacheclean]
- Cfssl::Cert[OCSP_zuul_pki1001_eqiad_wmnet]
- Exec[Generate cert OCSP_dse_front_proxy_pki1001_eqiad_wmnet refresh]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-syslog.service (cfssl-ocsprefresh-syslog.service)]
- Service[cfssl-ocspserve@aux]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- File[/etc/cfssl/ocsp/wikikube_front_proxy.ocsp]
- Sudo::User[nrpe-check_check_certificate_expiry_discovery2026]
- Systemd::Unit[cfssl-ocsprefresh-debmonitor.timer]
- Service[cfssl-ocsprefresh-wikikube_staging_front_proxy.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_aux]
- Exec[Generate cert OCSP_kafka_pki1001_eqiad_wmnet]
- File[/var/log/cfssl-ocsprefresh-syslog]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Cfssl::Cert[OCSP_cassandra_pki1001_eqiad_wmnet]
- Service[nrpe2nodexp-check_certificate_expiry_syslog.timer]
- File[/etc/systemd/system/ferm.service.d/ferm-service-status-restart.conf]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-network-devices.conf]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-wikikube.conf]
- Nrpe::Check[check_check_certificate_expiry_cloud_wmnet_ca]
- File[/lib/systemd/system/cfssl-ocspserve@mlserve_staging.service]
- Prometheus::Blackbox::Check::Http[PKI_aux]
- File[/lib/systemd/system/cfssl-multirootca.service]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.service]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Service[cfssl-ocsprefresh-wikikube_staging.timer]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_wikikube_staging_front_proxy]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_staging_front_proxy.timer]
- File[/usr/local/bin/prometheus-check-kafka-certificate-expiry]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_discovery]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery2026.timer (nrpe2nodexp-check_certificate_expiry_discovery2026.timer)]
- Exec[systemd daemon-reload for cfssl-ocspserve@Wikimedia_Internal_Root_CA.service (cfssl-ocspserve@Wikimedia_Internal_Root_CA)]
- File[/etc/cfssl/signers/syslog/ca/syslog.pem]
- File_line[load_env_enabled]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_dse_front_proxy.service]
- Nrpe::Check[check_check_certificate_expiry_aux]
- File[/etc/cfssl/csr/puppet_rsa__pki_discovery_wmnet.csr]
- Exec[systemd daemon-reload for cfssl-ocspserve@dse_front_proxy.service (cfssl-ocspserve@dse_front_proxy)]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy]
- Service[nrpe2nodexp-check_certificate_expiry_network_devices.timer]
- Systemd::Service[cfssl-ocspserve@zuul]
- Nrpe::Check[check_check_certificate_expiry_wikikube_staging_front_proxy]
- File[/lib/systemd/system/nrpe2nodexp-ferm_active.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_staging.timer]
- Logrotate::Conf[cfssl-ocsprefresh-cloud_wmnet_ca]
- File[/etc/apache2/mods-enabled/status.conf]
- Systemd::Service[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Httpd::Mod_conf[ssl]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Service[apache-htcacheclean]
- File[/etc/cfssl/ssl/ocsp/OCSP_puppet_rsa_pki1001_eqiad_wmnet.pem]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery2026.service]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry.service]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_staging.service]
- File[/etc/apache2/sites-available/00-dummy.conf]
- Profile::Pki::Multirootca::Monitoring[wikikube_staging_front_proxy]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_network_devices.prom]
- Exec[Generate cert OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet refresh]
- File[/lib/systemd/system/cfssl-ocsprefresh-aux_front_proxy.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_cassandra.timer]
- File[/etc/cfssl/signers/dse/ca/dse-key.pem]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-aux-certificate-expiry.service (prometheus-node-textfile-prometheus-check-aux-certificate-expiry.service)]
- Prometheus::Node_textfile[prometheus-check-zuul-certificate-expiry]
- Systemd::Timer[cfssl-ocsprefresh-wikikube_front_proxy]
- Service[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.timer]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Httpd::Site[dummy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.timer)]
- File[/etc/cfssl/signers/etcd/ca/etcd-key.pem]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.service]
- Monitoring::Service[check_certificate_expiry_wikikube_staging_front_proxy]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_mlserve_staging.prom]
- Nrpe::Monitor_service[check_certificate_expiry_syslog]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-dse-front-proxy.conf]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_kafka]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_etcd.service]
- Exec[update_alternative_iptables]
- File[/lib/systemd/system/wmf_auto_restart_apache-htcacheclean.service]
- Service[cfssl-ocsprefresh-puppet_rsa.timer]
- Systemd::Syslog[ulogd]
- File[/etc/cfssl/csr/OCSP_dse_pki1001_eqiad_wmnet.csr]
- Systemd::Timer[nrpe2nodexp-check_cfssl-multirootca_status]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-dse.service (cfssl-ocsprefresh-dse.service)]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_dse.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy]
- Systemd::Unit[cfssl-ocspserve@discovery2026]
- Nrpe::Check[check_check_certificate_expiry_zuul]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy]
- Cfssl::Db[multirootca-db]
- File[/etc/cfssl/ssl/ocsp]
- Sudo::User[nrpe_certificate_check_discovery]
- File[/srv/cfssl/bundles/cassandra.pem]
- Cfssl::Cert[OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet]
- Cfssl::Csr[/etc/cfssl/csr/puppet_rsa__pki_discovery_wmnet.csr]
- File[/etc/cfssl/ssl/ocsp/OCSP_zuul_pki1001_eqiad_wmnet.pem]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- Systemd::Unit[cfssl-ocspserve@dse_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Ferm::Service[ssh_from_cumin_masters]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.timer]
- Systemd::Timer[cfssl-ocsprefresh-cloud_wmnet_ca]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_staging_front_proxy.service]
- File[/etc/logrotate.d/cfssl-ocsprefresh-wikikube_staging]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.timer]
- File[/etc/cfssl/signers/dse/cfssl.conf]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_pki1001_eqiad_wmnet-key.pem]
- File[/var/log/cfssl-ocsprefresh-mlserve_staging]
- Systemd::Service[cfssl-ocspserve@network_devices]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_staging.service]
- File[/etc/cfssl/signers/network_devices/ca/network_devices.pem]
- File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa.pem]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.service]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.timer]
- File[/var/log/prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.service]
- Profile::Pki::Multirootca::Monitoring[mlserve_staging]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.timer]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_mlserve_staging_front_proxy.cfg]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-dse_front_proxy.service (cfssl-ocsprefresh-dse_front_proxy.service)]
- Systemd::Unit[cfssl-ocspserve@wikikube_staging_front_proxy]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.timer]
- File_line[auto_restart_file_presence_apache-htcacheclean]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_mlserve_front_proxy.cfg]
- File[/etc/cfssl/signers/mlserve_front_proxy/ca]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_etcd]
- Sudo::User[nrpe-check_check_certificate_expiry_dse_front_proxy]
- File[/etc/sudoers.d/nrpe_certificate_check_network_devices]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_pki1001_eqiad_wmnet.csr]
- Nrpe::Check[check_check_certificate_expiry_mlserve]
- Nrpe::Monitor_service[check_certificate_expiry_mlserve]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_staging.service (cfssl-ocsprefresh-wikikube_staging.service)]
- Service[cfssl-ocspserve@dse_front_proxy]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_front_proxy.service]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.conf]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_front_proxy.timer (cfssl-ocsprefresh-mlserve_front_proxy.timer)]
- Service[cfssl-ocspserve@wikikube_staging]
- File[/lib/systemd/system/wmf_auto_restart_apache-htcacheclean.timer]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- Profile::Pki::Multirootca::Monitoring[mlserve_front_proxy]
- File[/usr/local/bin/prometheus-check-dse_front_proxy-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-syslog.timer (cfssl-ocsprefresh-syslog.timer)]
- Nrpe::Check[check_check_certificate_expiry_wikikube_front_proxy]
- Systemd::Service[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_zuul.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery.timer (nrpe2nodexp-check_certificate_expiry_discovery.timer)]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_zuul]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-dse_front_proxy.timer (cfssl-ocsprefresh-dse_front_proxy.timer)]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_etcd.prom]
- Prometheus::Node_textfile[prometheus-check-debmonitor-certificate-expiry]
- Cfssl::Ocsp[debmonitor]
- Sudo::User[nrpe-check_check_certificate_expiry_network_devices]
- File[/etc/cfssl/signers/network_devices/ca]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_cassandra]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet-key.pem]
- Sudo::User[nrpe_certificate_check_kafka]
- Cfssl::Signer[wikikube_staging_front_proxy]
- Sudo::User[nrpe_certificate_check_mlserve_staging_front_proxy]
- Systemd::Timer::Job[cfssl-ocsprefresh-wikikube_front_proxy]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.service (cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.service)]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.service (nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.service)]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.service]
- Sudo::User[nrpe-check_check_certificate_expiry_debmonitor]
- File[/var/log/prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- Logrotate::Conf[cfssl-ocsprefresh-network_devices]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_aux.prom]
- File[/var/log/cfssl-ocsprefresh-wikikube]
- Systemd::Unit[cfssl-ocspserve@aux_front_proxy]
- File[/usr/local/bin/prometheus-check-wikikube_staging-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_staging_front_proxy.timer]
- Service[nrpe2nodexp-check_certificate_expiry_aux.timer]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_staging_front_proxy.service (cfssl-ocsprefresh-mlserve_staging_front_proxy.service)]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_staging.service]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_etcd]
- Systemd::Timer[cfssl-ocsprefresh-network_devices]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.service (nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.service)]
- Exec[Generate cert OCSP_aux_pki1001_eqiad_wmnet]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_wikikube_staging]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.timer]
- Cfssl::Ocsp[kafka]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.service]
- File[/etc/cfssl/signers/aux/ca]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_kafka.cfg]
- Service[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-zuul.conf]
- Service[nrpe2nodexp-check_certificate_expiry_kafka.timer]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_discovery2026.timer]
- Cfssl::Config[network_devices]
- Systemd::Unit[wmf_auto_restart_apache2.service]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery2026.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.timer]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- File[/etc/cfssl/ocsp/cloud_wmnet_ca.ocsp]
- Ferm::Rule[drop-blocked-nets]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.timer]
- File[/etc/cfssl/signers/aux/ca/aux-key.pem]
- Cfssl::Cert[OCSP_aux_front_proxy_pki1001_eqiad_wmnet]
- Cfssl::Ocsp[discovery]
- File[/var/log/prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- File[/etc/cfssl/ssl/ocsp/OCSP_debmonitor_pki1001_eqiad_wmnet.csr]
- Service[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer]
- Systemd::Service[wmf_auto_restart_ulogd2]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_aux]
- Systemd::Timer[cfssl-ocsprefresh-wikikube]
- Prometheus::Alert::Rule[check_check_certificate_expiry_mlserve_front_proxy_9d6dd05c8e5e1bb294462d932b24bd1a]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy]
- File[/etc/sudoers.d/nrpe_certificate_check_wikikube_staging_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry.timer)]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_dse_front_proxy.prom]
- Exec[renew certificate - OCSP_puppet_rsa_pki1001_eqiad_wmnet]
- Systemd::Timer[cfssl-gc-expired-certs]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_mlserve_staging]
- File[/var/lib/prometheus/node.d/check_check_cfssl-multirootca_status.prom]
- Sudo::User[nrpe_certificate_check_etcd]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- File[/etc/cfssl/ocsp/wikikube_staging_front_proxy.ocsp]
- Exec[Generate cert OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet refresh]
- Logrotate::Conf[cfssl-ocsprefresh-mlserve_front_proxy]
- Prometheus::Node_textfile[prometheus-check-dse_front_proxy-certificate-expiry]
- Cfssl::Config[zuul]
- Rsyslog::Conf[cfssl-ocsprefresh-wikikube]
- File[/etc/cfssl/signers/mlserve/ca/mlserve-key.pem]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_wikikube_staging]
- File[/lib/systemd/system/cfssl-ocsprefresh-cassandra.service]
- Systemd::Unit[cfssl-ocsprefresh-dse_front_proxy.timer]
- File[/usr/local/bin/prometheus-check-mlserve_staging-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_aux_front_proxy.service (nrpe2nodexp-check_certificate_expiry_aux_front_proxy.service)]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-aux-certificate-expiry.service]
- Cfssl::Ocsp[puppet_rsa]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_aux_front_proxy_pki1001_eqiad_wmnet.csr]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_aux]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_network_devices_pki1001_eqiad_wmnet.csr]
- Rsyslog::Conf[cfssl-ocsprefresh-wikikube_front_proxy]
- File[/etc/cfssl/signers/discovery/ca]
- Systemd::Service[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Nrpe::Check[check_check_cfssl-multirootca_status]
- File[/etc/cfssl/csr/OCSP_zuul_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.timer]
- File[/etc/logrotate.d/cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.conf]
- Logrotate::Conf[cfssl-ocsprefresh-aux_front_proxy]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_aux_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_aux_front_proxy.timer)]
- Systemd::Syslog[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Exec[Generate cert OCSP_mlserve_staging_pki1001_eqiad_wmnet]
- Nrpe::Monitor_service[check_certificate_expiry_mlserve_staging_front_proxy]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_mlserve_staging_front_proxy]
- File[/usr/local/sbin/cfssl-certs]
- Httpd::Conf[server-status]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- Sudo::User[nrpe_certificate_check_syslog]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- File[/etc/ferm/conf.d/10_multirootca_tls_termination]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.service]
- File[/srv/cfssl/bundles/mlserve_front_proxy.pem]
- Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c]
- Prometheus::Alert::Rule[check_check_certificate_expiry_kafka_22922fd6bc2d570e018cbe5ccd8d1727]
- Exec[Generate cert OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet]
- Systemd::Timer::Job[cfssl-gc-expired-certs]
- Cfssl::Config[mlserve_front_proxy]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/etc/cfssl/ssl/ocsp/OCSP_Wikimedia_Internal_Root_CA_pki1001_eqiad_wmnet-key.pem]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_dse]
- Nrpe::Plugin[check_systemd_unit_status]
- Exec[renew certificate - OCSP_network_devices_pki1001_eqiad_wmnet]
- Exec[renew certificate - OCSP_debmonitor_pki1001_eqiad_wmnet]
- File[/usr/local/lib/nagios/plugins/check_systemd_unit_status]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.service]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Sudo::User[nrpe-check_check_certificate_expiry_wikikube_staging_front_proxy]
- Exec[ensure_present_mod_ssl]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- File[/etc/apache2/conf-available/50-cfssl-issuer-k8s-pods-vhost-port.conf]
- Profile::Pki::Multirootca::Monitoring[dse_front_proxy]
- Cfssl::Signer[discovery]
- Nrpe::Check[check_check_certificate_expiry_debmonitor]
- File[/etc/sudoers.d/nrpe_certificate_check_discovery]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Cfssl::Cert[OCSP_wikikube_pki1001_eqiad_wmnet]
- File[/srv/cfssl/crl]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.service]
- Cfssl::Config[discovery]
- Service[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry.timer]
- Exec[Generate cert OCSP_etcd_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_aux.service]
- File[/etc/ferm/ferm.conf]
- File[/etc/ferm/conf.d/98_log-everything]
- Cfssl::Cert[OCSP_kafka_pki1001_eqiad_wmnet]
- Service[cfssl-ocsprefresh-aux.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_mlserve_front_proxy]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry]
- File[/etc/sudoers.d/nrpe_certificate_check_wikikube_staging]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.timer]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_wikikube_staging]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Systemd::Service[nrpe2nodexp-check_cfssl-multirootca_status]
- File[/etc/sudoers.d/nrpe_certificate_check_mlserve_staging]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_dse_front_proxy.cfg]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_mlserve]
- File[/etc/cfssl/signers/kafka/ca/kafka.pem]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.timer]
- Systemd::Unit[nrpe2nodexp-check_cfssl-multirootca_status.timer]
- File[/etc/cfssl/signers/etcd]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_kafka_pki1001_eqiad_wmnet.csr]
- File[/lib/systemd/system/cfssl-ocsprefresh-dse_front_proxy.timer]
- Cfssl::Ocsp[network_devices]
- Cfssl::Signer[wikikube_staging]
- Exec[Generate initial CRL for aux_front_proxy]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.timer]
- Cfssl::Ocsp[mlserve_staging_front_proxy]
- File[/var/log/cfssl-ocsprefresh-wikikube_front_proxy]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_kafka]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Systemd::Service[wmf_auto_restart_apache-htcacheclean]
- Exec[Generate cert OCSP_syslog_pki1001_eqiad_wmnet refresh]
- File[/etc/cfssl/ocsp/kafka.ocsp]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_pki1001_eqiad_wmnet-key.pem]
- Exec[Generate initial CRL for aux]
- Systemd::Timer::Job[cfssl-ocsprefresh-mlserve_staging_front_proxy]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_cassandra.prom]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube.service]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-mlserve-front-proxy.conf]
- Ferm::Rule[filter_log_filter-bootp]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_syslog]
- Profile::Auto_restarts::Service[ulogd2]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_debmonitor.cfg]
- Systemd::Timer::Job[cfssl-ocsprefresh-dse]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_staging_front_proxy.service (cfssl-ocsprefresh-wikikube_staging_front_proxy.service)]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- Service[nrpe2nodexp-check_certificate_expiry_zuul.timer]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service]
- File[/usr/local/bin/apache-status]
- Systemd::Syslog[cfssl-ocsprefresh-puppet_rsa]
- Nrpe::Monitor_service[check_certificate_expiry_etcd]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_discovery]
- Nrpe::Monitor_service[check_certificate_expiry_aux_front_proxy]
- Nrpe::Monitor_service[check_certificate_expiry_wikikube_staging_front_proxy]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_mlserve_staging.cfg]
- Systemd::Unit[ferm-ferm-service-status-restart]
- Cfssl::Signer[aux]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-aux_front_proxy.service (cfssl-ocsprefresh-aux_front_proxy.service)]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_cassandra.timer]
- File[/etc/cfssl/signers/mlserve/ca]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_aux_front_proxy]
- File[/etc/cfssl/signers/zuul/ca/zuul-key.pem]
- File[/etc/cfssl/signers/dse_front_proxy/cfssl.conf]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.service (prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.service)]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- Logrotate::Conf[cfssl-ocsprefresh-debmonitor]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_mlserve_front_proxy]
- Monitoring::Service[check_certificate_expiry_etcd]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Exec[Generate cert OCSP_dse_pki1001_eqiad_wmnet]
- Systemd::Timer::Job[wmf_auto_restart_ulogd2]
- File[/etc/cfssl/ssl/ocsp/OCSP_Wikimedia_Internal_Root_CA_pki1001_eqiad_wmnet.pem]
- Ferm::Service[multirootca_tls_termination_for_cfssl_issuer_k8s_pods]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_dse_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_puppet_rsa_pki1001_eqiad_wmnet-key.pem]
- File[/etc/cfssl/signers/network_devices/ca/network_devices-key.pem]
- File[/etc/apache2/conf-available]
- File[/etc/ferm/conf.d/99_dscp-default]
- Cfssl::Ocsp[wikikube]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-debmonitor.conf]
- Rsyslog::Conf[cfssl-ocsprefresh-cassandra]
- Cfssl::Signer[etcd]
- Systemd::Unit[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA.timer]
- File[/var/log/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery2026.service]
- Nrpe::Monitor_service[check_certificate_expiry_mlserve_front_proxy]
- Cfssl::Signer[aux_front_proxy]
- Ferm::Conf[defs]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_pki1001_eqiad_wmnet.csr]
- Cfssl::Config[dse]
- Httpd::Mod_conf[proxy_http]
- File[/etc/cfssl/signers/etcd/ca]
- Exec[renew certificate - OCSP_aux_front_proxy_pki1001_eqiad_wmnet]
- Monitoring::Service[check_certificate_expiry_wikikube_front_proxy]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_staging.service]
- Systemd::Service[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry]
- Service[cfssl-ocspserve@aux_front_proxy]
- Cfssl::Ocsp[wikikube_staging]
- Prometheus::Node_textfile[prometheus-check-syslog-certificate-expiry]
- Systemd::Unit[cfssl-ocspserve@etcd]
- Exec[systemd daemon-reload for cfssl-ocspserve@wikikube.service (cfssl-ocspserve@wikikube)]
- Systemd::Unit[cfssl-ocspserve@network_devices]
- File[/etc/ferm/functions.conf]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_zuul]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-aux.conf]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.service]
- File[/etc/cfssl/signers/wikikube_staging_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-puppet_rsa.timer (cfssl-ocsprefresh-puppet_rsa.timer)]
- Exec[Generate cert OCSP_aux_front_proxy_pki1001_eqiad_wmnet refresh]
- Sudo::User[nrpe_certificate_check_discovery2026]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-zuul.service (cfssl-ocsprefresh-zuul.service)]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-dse-certificate-expiry.conf]
- File[/etc/cfssl/signers/aux]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.timer (nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.timer)]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry]
- Service[cfssl-ocspserve@cloud_wmnet_ca]
- Logrotate::Conf[cfssl-ocsprefresh-zuul]
- Exec[renew certificate - OCSP_dse_front_proxy_pki1001_eqiad_wmnet]
- Logrotate::Conf[cfssl-ocsprefresh-wikikube_staging]
- Nrpe::Check[check_check_certificate_expiry_mlserve_front_proxy]
- File[/etc/cfssl/signers/wikikube_staging_front_proxy/ca/wikikube_staging_front_proxy-key.pem]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_front_proxy.service]
- Systemd::Syslog[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Systemd::Service[cfssl-ocsprefresh-dse_front_proxy]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-mlserve.conf]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_dse]
- Prometheus::Node_textfile[prometheus-check-aux_front_proxy-certificate-expiry]
- Exec[Generate cert OCSP_dse_pki1001_eqiad_wmnet refresh]
- Exec[systemd daemon-reload for cfssl-ocspserve@debmonitor.service (cfssl-ocspserve@debmonitor)]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.timer]
- Exec[renew certificate - OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet]
- File[/etc/nagios/nrpe.d/check_check_cfssl-multirootca_status.cfg]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_kafka.prom]
- Cfssl::Config[puppet_rsa]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Httpd::Conf[defaults]
- Exec[systemd daemon-reload for cfssl-ocspserve@mlserve_front_proxy.service (cfssl-ocspserve@mlserve_front_proxy)]
- Systemd::Timer::Job[cfssl-ocsprefresh-etcd]
- Systemd::Unit[cfssl-ocsprefresh-dse.timer]
- Service[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.timer]
- Exec[Generate cert OCSP_discovery2026_pki1001_eqiad_wmnet]
- Systemd::Service[cfssl-ocsprefresh-wikikube]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_debmonitor.prom]
- File[/etc/ferm/conf.d/10_csr_and_ocsp_responder]
- Exec[systemd daemon-reload for nrpe2nodexp-check_cfssl-multirootca_status.timer (nrpe2nodexp-check_cfssl-multirootca_status.timer)]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_debmonitor_pki1001_eqiad_wmnet.csr]
- Exec[Generate initial CRL for debmonitor]
- File[/etc/apache2/sites-available/50-pki-discovery-wmnet.conf]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.service]
- Profile::Pki::Multirootca::Monitoring[wikikube_staging]
- Systemd::Unit[wmf_auto_restart_ulogd2.timer]
- Monitoring::Service[check_certificate_expiry_wikikube_staging]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-cassandra.conf]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_pki1001_eqiad_wmnet.pem]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_syslog.cfg]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Monitoring::Service[check_certificate_expiry_cloud_wmnet_ca]
- File[/usr/local/bin/prometheus-check-cassandra-certificate-expiry]
- Systemd::Timer[cfssl-ocsprefresh-aux]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_aux.service]
- Exec[Generate cert puppet_rsa__pki_discovery_wmnet]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_zuul.service]
- Sudo::User[nrpe-check_check_certificate_expiry_wikikube_staging]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-wikikube-staging-certificate-expiry.conf]
- Service[cfssl-ocspserve@cassandra]
- File[/etc/cfssl/signers/dse/ca/dse.pem]
- Systemd::Syslog[cfssl-ocsprefresh-wikikube_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-aux.service (cfssl-ocsprefresh-aux.service)]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_puppet_rsa]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-cloud-wmnet-ca-certificate-expiry.conf]
- File[/lib/systemd/system/cfssl-ocsprefresh-zuul.timer]
- Prometheus::Alert::Rule[check_check_certificate_expiry_puppet_rsa_c1b324b3d8ac107f8d7483b4017f5edf]
- Systemd::Unit[cfssl-ocspserve@wikikube_front_proxy]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve_staging.service]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_staging.timer]
- File[/etc/ferm/conf.d]
- Cfssl::Cert[OCSP_mlserve_pki1001_eqiad_wmnet]
- File[/var/log/cfssl-ocsprefresh-cassandra]
- File[/etc/logrotate.d/cfssl-ocsprefresh-aux]
- Service[cfssl-ocspserve@mlserve_staging_front_proxy]
- Rsyslog::Conf[cfssl-ocsprefresh-zuul]
- Prometheus::Node_textfile[prometheus-check-aux-certificate-expiry]
- File[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/csr/OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet.csr]
- Exec[Generate cert OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet refresh]
- File[/etc/sudoers.d/nrpe_certificate_check_aux_front_proxy]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_staging.timer]
- Monitoring::Exported_nagios_service[pki1001 ferm_active]
- Sudo::User[nrpe-check_check_certificate_expiry_mlserve_staging]
- Prometheus::Blackbox::Check::Http[PKI_wikikube_front_proxy]
- File[/etc/cfssl/signers/dse/ca]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube.service (nrpe2nodexp-check_certificate_expiry_wikikube.service)]
- Exec[systemd daemon-reload for cfssl-ocspserve@aux_front_proxy.service (cfssl-ocspserve@aux_front_proxy)]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer]
- Service[nrpe2nodexp-check_certificate_expiry_puppet_rsa.timer]
- Cfssl::Signer[network_devices]
- Exec[systemd daemon-reload for apache2.service (apache2-apache2-after-network-online-target)]
- Monitoring::Service[check_certificate_expiry_dse]
- Exec[Generate cert OCSP_debmonitor_pki1001_eqiad_wmnet]
- Exec[renew certificate - puppet_rsa__pki_discovery_wmnet]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-syslog.conf]
- File[/var/log/prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube_staging.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_front_proxy.service (cfssl-ocsprefresh-mlserve_front_proxy.service)]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.timer]
- File[/etc/cfssl/signers/network_devices]
- File[/var/log/prometheus-node-textfile-prometheus-check-cloud_wmnet_ca-certificate-expiry]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.service]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet.pem]
- Cfssl::Cert[OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet]
- Service[cfssl-ocspserve@discovery]
- Systemd::Syslog[wmf_auto_restart_apache2]
- Systemd::Service[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.service)]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.service]
- File[/etc/cfssl/signers/kafka/ca]
- File[/etc/cfssl/signers/cassandra]
- Httpd::Site[pki.discovery.wmnet]
- File[/etc/cfssl/ocsp/wikikube.ocsp]
- Profile::Pki::Multirootca::Monitoring[debmonitor]
- File[/etc/cfssl/ssl/ocsp/OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet.pem]
- Service[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.timer]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- File[/usr/local/bin/prometheus-check-zuul-certificate-expiry]
- File[/etc/logrotate.d/cfssl-ocsprefresh-mlserve_staging]
- Nrpe::Monitor_service[check_certificate_expiry_discovery2026]
- File[/etc/cfssl/signers/mlserve/cfssl.conf]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_wikikube_staging_front_proxy.prom]
- Exec[renew certificate - OCSP_syslog_pki1001_eqiad_wmnet]
- Systemd::Timer::Job[wmf_auto_restart_apache2]
- Systemd::Unit[cfssl-ocspserve@Wikimedia_Internal_Root_CA]
- File[/srv/cfssl/bundles/debmonitor.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_syslog.timer]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_network_devices]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_aux]
- File[/lib/systemd/system/cfssl-ocspserve@wikikube.service]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service]
- Systemd::Syslog[wmf_auto_restart_apache-htcacheclean]
- Exec[Generate initial CRL for puppet_rsa]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-cfssl-multirootca-status.conf]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_discovery.timer]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_staging.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-puppet_rsa.service]
- Monitoring::Service[check_certificate_expiry_kafka]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.timer]
- Systemd::Timer[nrpe2nodexp-ferm_active]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/mlserve_front_proxy/ca/mlserve_front_proxy-key.pem]
- Systemd::Service[cfssl-ocsprefresh-syslog]
- Cfssl::Ocsp[mlserve_staging]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-cassandra.service (cfssl-ocsprefresh-cassandra.service)]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-network-devices-certificate-expiry.conf]
- File[/etc/cfssl/signers/wikikube_staging/ca/wikikube_staging.pem]
- File[/etc/cfssl/csr/OCSP_discovery2026_pki1001_eqiad_wmnet.csr]
- Cfssl::Signer[dse_front_proxy]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_staging_front_proxy.service]
- Service[cfssl-ocspserve@wikikube]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_puppet_rsa.timer]
- Alternatives::Select[ip6tables]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_dse_front_proxy]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- Exec[Generate cert OCSP_zuul_pki1001_eqiad_wmnet]
- Service[cfssl-ocspserve@puppet_rsa]
- File[/etc/cfssl/db.conf]
- Exec[renew certificate - OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet]
- Profile::Pki::Multirootca::Monitoring[etcd]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_dse]
- Exec[systemd daemon-reload for cfssl-ocspserve@syslog.service (cfssl-ocspserve@syslog)]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-puppet-rsa.conf]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.service]
- Sudo::User[nrpe-check_check_cfssl-multirootca_status]
- File[/etc/cfssl/csr/OCSP_etcd_pki1001_eqiad_wmnet.csr]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_aux_front_proxy]
- File[/etc/cfssl/ocsp/discovery.ocsp]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_discovery2026]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_wikikube]
- File[/lib/systemd/system/nrpe2nodexp-ferm_active.service]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_network_devices]
- Logrotate::Conf[cfssl-ocsprefresh-wikikube]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_syslog]
- File[/etc/rsyslog.d/40-wmf-auto-restart-ulogd2.conf]
- Exec[Generate cert OCSP_network_devices_pki1001_eqiad_wmnet]
- Systemd::Syslog[wmf_auto_restart_ulogd2]
- File[/etc/cfssl/signers/debmonitor/ca/debmonitor.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_dse_front_proxy.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-network_devices.service (cfssl-ocsprefresh-network_devices.service)]
- Rsyslog::Conf[cfssl-ocsprefresh-debmonitor]
- Exec[Generate initial CRL for cassandra]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-discovery2026-certificate-expiry.timer)]
- File[/etc/cfssl/signers/aux_front_proxy/ca]
- File[/var/log/cfssl-ocsprefresh-dse]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet-key.pem]
- File[/etc/rsyslog.d/40-wmf-auto-restart-apache2.conf]
- Prometheus::Blackbox::Check::Http[PKI_mlserve]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.timer)]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- File[/lib/systemd/system/cfssl-ocspserve@discovery.service]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_puppet_rsa.timer (nrpe2nodexp-check_certificate_expiry_puppet_rsa.timer)]
- File[/etc/sudoers.d/nrpe_certificate_check_puppet_rsa]
- File[/etc/cfssl/signers/wikikube/cfssl.conf]
- Systemd::Service[nrpe2nodexp-ferm_active]
- File[/etc/cfssl/signers/cassandra/ca]
- Exec[ensure_present_mod_access_compat]
- File[/etc/cfssl/ocsp/cassandra.ocsp]
- Rsyslog::Conf[cfssl-ocsprefresh-discovery2026]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-aux-certificate-expiry]
- Systemd::Service[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_aux.cfg]
- Systemd::Unit[cfssl-ocspserve@puppet_rsa]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.service]
- File[/var/log/cfssl-ocsprefresh-discovery2026]
- File[/etc/cfssl/signers/network_devices/cfssl.conf]
- Exec[Generate cert OCSP_wikikube_staging_pki1001_eqiad_wmnet refresh]
- Service[cfssl-multirootca]
- Sudo::User[nrpe-check_check_certificate_expiry_mlserve_staging_front_proxy]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-aux-certificate-expiry.timer]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_front_proxy.cfg]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_kafka.timer]
- File[/etc/cfssl/signers/aux_front_proxy/ca/aux_front_proxy-key.pem]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.service (nrpe2nodexp-check_certificate_expiry_cloud_wmnet_ca.service)]
- Cfssl::Config[wikikube_staging]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_discovery.timer]
- Cfssl::Config[wikikube_staging_front_proxy]
- Exec[Generate cert OCSP_puppet_rsa_pki1001_eqiad_wmnet refresh]
- File[/etc/cfssl/signers/discovery]
- Logrotate::Conf[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Prometheus::Alert::Rule[check_check_certificate_expiry_mlserve_staging_front_proxy_b194b5b9b6c9d6e05b9eed8dcfcc40cf]
- File[/etc/cfssl/signers/mlserve_staging]
- File[/lib/systemd/system/cfssl-ocsprefresh-zuul.service]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_network_devices.service (nrpe2nodexp-check_certificate_expiry_network_devices.service)]
- Systemd::Timer[cfssl-ocsprefresh-debmonitor]
- Systemd::Service[cfssl-ocspserve@dse_front_proxy]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_dse_front_proxy]
- File[/etc/cfssl/signers/debmonitor/ca/debmonitor-key.pem]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_front_proxy.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-etcd.service (cfssl-ocsprefresh-etcd.service)]
- File[/var/log/cfssl-ocsprefresh-mlserve]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_mlserve.prom]
- Prometheus::Blackbox::Check::Http[PKI_mlserve_staging_front_proxy]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- Systemd::Timer[cfssl-ocsprefresh-wikikube_staging]
- File[/etc/apache2/conf-enabled/00-defaults.conf]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.service]
- Service[cfssl-ocspserve@discovery2026]
- Nrpe::Check[check_check_certificate_expiry_wikikube_staging]
- File[/etc/cfssl/signers/wikikube_front_proxy/ca/wikikube_front_proxy-key.pem]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_aux_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_aux_front_proxy_pki1001_eqiad_wmnet-key.pem]
- File[/etc/logrotate.d/cfssl-ocsprefresh-cloud_wmnet_ca]
- File[/etc/cfssl/ssl/ocsp/OCSP_network_devices_pki1001_eqiad_wmnet.csr]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.timer]
- Cfssl::Cert[OCSP_mlserve_staging_pki1001_eqiad_wmnet]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.service (prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.service)]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry.timer]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-mlserve-staging-front-proxy.conf]
- Prometheus::Blackbox::Check::Http[PKI_debmonitor]
- Service[cfssl-ocspserve@etcd]
- File[/etc/sudoers.d/nrpe_certificate_check_mlserve_front_proxy]
- File[/var/log/prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy]
- File[/etc/cfssl/signers/puppet_rsa/ca]
- File[/lib/systemd/system/cfssl-ocspserve@mlserve.service]
- File[/etc/cfssl/signers/cloud_wmnet_ca/ca]
- Exec[Generate cert OCSP_wikikube_pki1001_eqiad_wmnet refresh]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- File[/etc/sudoers.d/nrpe-check_check_cfssl-multirootca_status]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_wikikube_pki1001_eqiad_wmnet.csr]
- File[/etc/default/ferm]
- Cfssl::Ocsp[cloud_wmnet_ca]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.pem]
- File[/etc/logrotate.d/cfssl-ocsprefresh-aux_front_proxy]
- File[/var/log/cfssl-ocsprefresh-aux_front_proxy]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_puppet_rsa]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_wikikube_staging_front_proxy]
- Exec[Generate cert OCSP_wikikube_pki1001_eqiad_wmnet]
- Service[cfssl-ocsprefresh-cassandra.timer]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_debmonitor]
- Prometheus::Blackbox::Check::Http[PKI_wikikube]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_syslog]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_aux_front_proxy]
- Monitoring::Service[check_certificate_expiry_discovery]
- File[/lib/systemd/system/cfssl-ocsprefresh-cloud_wmnet_ca.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry.service)]
- Exec[systemd daemon-reload for cfssl-ocspserve@wikikube_staging_front_proxy.service (cfssl-ocspserve@wikikube_staging_front_proxy)]
- Service[prometheus-node-textfile-prometheus-check-cassandra-certificate-expiry.timer]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-discovery2026.conf]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_wikikube.service]
- File[/lib/systemd/system/cfssl-ocspserve@puppet_rsa.service]
- Systemd::Service[cfssl-ocsprefresh-cassandra]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- File[/etc/logrotate.d/cfssl-ocsprefresh-network_devices]
- File[/etc/cfssl/ssl/ocsp/OCSP_zuul_pki1001_eqiad_wmnet.csr]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-dse_front_proxy-certificate-expiry]
- Systemd::Unit[nrpe2nodexp-check_cfssl-multirootca_status.service]
- Nrpe::Monitor_service[check_certificate_expiry_dse_front_proxy]
- File[/usr/local/bin/prometheus-check-network_devices-certificate-expiry]
- Nrpe::Check[check_check_certificate_expiry_aux_front_proxy]
- Monitoring::Service[check_cfssl-multirootca_status]
- Systemd::Timer::Job[cfssl-ocsprefresh-dse_front_proxy]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_network_devices]
- File[/lib/systemd/system/cfssl-ocspserve@discovery2026.service]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet]
- File[/etc/cfssl/signers/wikikube/ca/wikikube-key.pem]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_syslog.service]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.service)]
- Service[cfssl-ocsprefresh-wikikube_front_proxy.timer]
- Httpd::Conf[cfssl-issuer-k8s-pods-vhost-port]
- Systemd::Service[cfssl-ocsprefresh-debmonitor]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-zuul-certificate-expiry.conf]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Monitoring::Service[check_certificate_expiry_debmonitor]
- Monitoring::Service[check_certificate_expiry_mlserve]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.service]
- File[/lib/systemd/system/cfssl-ocsprefresh-debmonitor.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_etcd.timer (nrpe2nodexp-check_certificate_expiry_etcd.timer)]
- Systemd::Unit[cfssl-ocsprefresh-wikikube.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_staging.timer (nrpe2nodexp-check_certificate_expiry_wikikube_staging.timer)]
- Service[cfssl-ocspserve@wikikube_staging_front_proxy]
- Nrpe::Check[check_check_certificate_expiry_mlserve_staging]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_etcd_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/ssl/puppet_rsa__pki_discovery_wmnet/puppet_rsa__pki_discovery_wmnet.pem]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube_front_proxy.timer]
- Cfssl::Signer[mlserve_staging]
- Exec[Generate cert OCSP_kafka_pki1001_eqiad_wmnet refresh]
- Prometheus::Blackbox::Check::Http[PKI_dse_front_proxy]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry.timer]
- File[/var/log/wmf_auto_restart_ulogd2]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_puppet_rsa_pki1001_eqiad_wmnet.csr]
- Cfssl::Config[mlserve]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- Service[cfssl-ocsprefresh-debmonitor.timer]
- Systemd::Service[cfssl-ocspserve@wikikube]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_cassandra.service (nrpe2nodexp-check_certificate_expiry_cassandra.service)]
- File[/lib/systemd/system/cfssl-ocspserve@cassandra.service]
- File[/etc/rsyslog.d/40-cfssl-gc-expired-certs.conf]
- File[/lib/systemd/system/cfssl-ocspserve@network_devices.service]
- Systemd::Service[cfssl-ocsprefresh-network_devices]
- Prometheus::Alert::Rule[check_check_cfssl-multirootca_status_52832284a5fb8b8ea6f55bb6271912c9]
- Rsyslog::Conf[cfssl-ocsprefresh-etcd]
- File[/etc/sudoers.d/nrpe-check_ferm_active]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_staging.service (nrpe2nodexp-check_certificate_expiry_wikikube_staging.service)]
- Service[cfssl-ocsprefresh-discovery.timer]
- Service[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.timer]
- File[/var/log/prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- Systemd::Service[cfssl-ocsprefresh-etcd]
- Exec[update_alternative_ip6tables]
- Systemd::Service[cfssl-ocspserve@discovery2026]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve.timer]
- Systemd::Service[cfssl-ocsprefresh-kafka]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_etcd]
- File[/var/log/wmf_auto_restart_apache-htcacheclean]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-cloud_wmnet_ca.service (cfssl-ocsprefresh-cloud_wmnet_ca.service)]
- File[/usr/local/bin/prometheus-check-puppet_rsa-certificate-expiry]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_staging.timer]
- Cfssl::Signer[zuul]
- Cfssl::Cert[OCSP_debmonitor_pki1001_eqiad_wmnet]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-prometheus-check-etcd-certificate-expiry.conf]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_discovery]
- File[/etc/cfssl/ocsp/mlserve.ocsp]
- Systemd::Service[wmf_auto_restart_apache2]
- Exec[Generate cert OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet]
- Service[nrpe2nodexp-check_certificate_expiry_mlserve_staging.timer]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_kafka.timer (nrpe2nodexp-check_certificate_expiry_kafka.timer)]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry.timer)]
- Service[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy.timer]
- Cfssl::Ocsp[aux_front_proxy]
- Exec[Generate cert OCSP_wikikube_staging_pki1001_eqiad_wmnet]
- Systemd::Syslog[cfssl-ocsprefresh-cassandra]
- Logrotate::Conf[wmf_auto_restart_ulogd2]
- File[/lib/systemd/system/cfssl-ocsprefresh-wikikube.timer]
- Service[nrpe2nodexp-check_certificate_expiry_discovery.timer]
- File[/etc/cfssl/signers/etcd/cfssl.conf]
- Exec[systemd daemon-reload for cfssl-ocspserve@aux.service (cfssl-ocspserve@aux)]
- Sudo::User[nrpe_certificate_check_wikikube_front_proxy]
- Systemd::Unit[cfssl-ocsprefresh-mlserve_staging_front_proxy.service]
- File[/lib/systemd/system/nrpe2nodexp-check_cfssl-multirootca_status.timer]
- Systemd::Service[prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry]
- Prometheus::Node_textfile[prometheus-check-network_devices-certificate-expiry]
- Rsyslog::Conf[cfssl-ocsprefresh-aux_front_proxy]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube.service (cfssl-ocsprefresh-wikikube.service)]
- Cfssl::Config[cassandra]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry.timer)]
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp]
- Rsyslog::Conf[cfssl-ocsprefresh-wikikube_staging_front_proxy]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_cloud_wmnet_ca]
- Cfssl::Ocsp[wikikube_front_proxy]
- File[/etc/cfssl/signers/dse_front_proxy/ca]
- File[/etc/cfssl/ssl/ocsp/OCSP_discovery_pki1001_eqiad_wmnet-key.pem]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-kafka-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocspserve@mlserve_staging.service (cfssl-ocspserve@mlserve_staging)]
- File[/etc/cfssl/ssl/ocsp/OCSP_syslog_pki1001_eqiad_wmnet-key.pem]
- Rsyslog::Conf[wmf_auto_restart_apache2]
- Systemd::Timer::Job[cfssl-ocsprefresh-network_devices]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_dse.service (nrpe2nodexp-check_certificate_expiry_dse.service)]
- File[/lib/systemd/system/cfssl-ocspserve@Wikimedia_Internal_Root_CA.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-kafka.timer (cfssl-ocsprefresh-kafka.timer)]
- Exec[systemd daemon-reload for cfssl-ocspserve@discovery2026.service (cfssl-ocspserve@discovery2026)]
- File[/etc/cfssl/signers/aux/ca/aux.pem]
- Systemd::Timer[cfssl-ocsprefresh-Wikimedia_Internal_Root_CA]
- Service[cfssl-ocspserve@wikikube_front_proxy]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_wikikube_staging_pki1001_eqiad_wmnet.csr]
- Logrotate::Conf[cfssl-ocsprefresh-dse_front_proxy]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_puppet_rsa]
- File[/lib/systemd/system/cfssl-ocsprefresh-discovery2026.timer]
- Sudo::User[nrpe-check_check_certificate_expiry_discovery]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_mlserve_staging]
- File[/etc/logrotate.d/cfssl-ocsprefresh-wikikube_front_proxy]
- Firewall::Service[multirootca tls termination]
- File[/etc/cfssl/signers/etcd/ca/etcd.pem]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_wikikube_staging.prom]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-Wikimedia-Internal-Root-CA.conf]
- Systemd::Unit[cfssl-ocsprefresh-cassandra.timer]
- Exec[systemd daemon-reload for wmf_auto_restart_apache2.timer (wmf_auto_restart_apache2.timer)]
- File[/etc/cfssl/signers/dse]
- Logrotate::Conf[cfssl-ocsprefresh-mlserve_staging]
- File[/etc/sudoers.d/nrpe_certificate_check_dse]
- Prometheus::Node_textfile[prometheus-check-cloud_wmnet_ca-certificate-expiry]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-discovery2026.service (cfssl-ocsprefresh-discovery2026.service)]
- Exec[Generate cert OCSP_mlserve_staging_pki1001_eqiad_wmnet refresh]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.timer (prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.timer)]
- Service[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.timer]
- Exec[systemd daemon-reload for cfssl-ocspserve@wikikube_staging.service (cfssl-ocspserve@wikikube_staging)]
- Rsyslog::Conf[wmf_auto_restart_apache-htcacheclean]
- Exec[Generate cert OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet refresh]
- Cfssl::Ocsp[zuul]
- Cfssl::Cert[OCSP_discovery_pki1001_eqiad_wmnet]
- File[/etc/sudoers.d/nrpe_certificate_check_kafka]
- File[/lib/systemd/system/cfssl-ocsprefresh-aux.service]
- File[/usr/local/bin/prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Package[links]
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_cloud_wmnet_ca]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_cassandra.service]
- Cfssl::Cert[OCSP_aux_pki1001_eqiad_wmnet]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-etcd.conf]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-zuul.timer (cfssl-ocsprefresh-zuul.timer)]
- Sudo::User[nrpe-check_ferm_active]
- Systemd::Service[cfssl-multirootca]
- Systemd::Syslog[cfssl-ocsprefresh-discovery2026]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_discovery2026]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.timer]
- File[/etc/cfssl/signers/aux_front_proxy/cfssl.conf]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_staging-certificate-expiry]
- File[/usr/local/bin/prometheus-check-debmonitor-certificate-expiry]
- Prometheus::Alert::Rule[check_check_certificate_expiry_wikikube_staging_front_proxy_e515778a769f523fb98a7f642670e011]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_zuul.service]
- File[/etc/cfssl/signers/cassandra/ca/cassandra.pem]
- Exec[Generate initial CRL for kafka]
- File[/usr/local/bin/prometheus-check-etcd-certificate-expiry]
- File[/usr/local/bin/prometheus-check-syslog-certificate-expiry]
- File[/etc/sudoers.d/nrpe_certificate_check_wikikube_front_proxy]
- File[/etc/logrotate.d/cfssl-ocsprefresh-mlserve_front_proxy]
- File[/etc/cfssl/ssl/ocsp/OCSP_etcd_pki1001_eqiad_wmnet.pem]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_discovery2026.cfg]
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve_front_proxy.timer]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve_staging.service (cfssl-ocsprefresh-mlserve_staging.service)]
- Exec[Generate initial CRL for syslog]
- File[/var/log/cfssl-ocsprefresh-aux]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-wikikube_front_proxy.timer (cfssl-ocsprefresh-wikikube_front_proxy.timer)]
- Nrpe::Check[check_check_certificate_expiry_discovery]
- File[/etc/cfssl/ssl/ocsp/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.pem]
- File[/etc/cfssl/signers/wikikube_front_proxy/ca]
- Exec[systemd daemon-reload for cfssl-multirootca.service (cfssl-multirootca)]
- Ferm::Service[full_monitoring_metrics_access_udp]
- File[/var/lib/prometheus/node.d/check_check_certificate_expiry_zuul.prom]
- Exec[renew certificate - OCSP_wikikube_pki1001_eqiad_wmnet]
- File[/etc/cfssl/ssl/ocsp/OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet.csr]
- Prometheus::Node_textfile[prometheus-check-etcd-certificate-expiry]
- Systemd::Timer::Job[cfssl-ocsprefresh-zuul]
- File[/etc/cfssl/csr/OCSP_debmonitor_pki1001_eqiad_wmnet.csr]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.timer)]
- Systemd::Unit[cfssl-ocsprefresh-network_devices.timer]
- Class[Sslcert::Dhparam]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_dse]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- File[/etc/cfssl/csr/OCSP_network_devices_pki1001_eqiad_wmnet.csr]
- Nrpe::Monitor_service[check_certificate_expiry_cassandra]
- File[/var/log/cfssl-ocsprefresh-cloud_wmnet_ca]
- Exec[renew certificate - OCSP_cassandra_pki1001_eqiad_wmnet]
- Nrpe::Monitor_service[check_certificate_expiry_wikikube]
- Exec[Generate cert OCSP_mlserve_pki1001_eqiad_wmnet refresh]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_aux_front_proxy.service]
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry]
- File[/usr/local/bin/prometheus-check-aux_front_proxy-certificate-expiry]
- Systemd::Unit[cfssl-ocsprefresh-kafka.service]
- File[/etc/rsyslog.d/25-nrpe2nodexp-check-certificate-expiry-kafka.conf]
- Systemd::Service[cfssl-ocspserve@puppet_rsa]
- Systemd::Syslog[cfssl-ocsprefresh-wikikube]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-wikikube-staging-front-proxy.conf]
- Rsyslog::Conf[nrpe2nodexp-check_cfssl-multirootca_status]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_discovery.cfg]
- Rsyslog::Conf[prometheus-node-textfile-prometheus-check-network_devices-certificate-expiry]
- Systemd::Unit[wmf_auto_restart_apache2.timer]
- Exec[Generate cert OCSP_cassandra_pki1001_eqiad_wmnet]
- Profile::Pki::Multirootca::Monitoring[mlserve_staging_front_proxy]
- Systemd::Timer[cfssl-ocsprefresh-cassandra]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- File[/etc/cfssl/signers/mlserve_front_proxy/ca/mlserve_front_proxy.pem]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_etcd]
- File[/etc/logrotate.d/cfssl-ocsprefresh-syslog]
- File[/var/log/cfssl-ocsprefresh-wikikube_staging]
- Profile::Pki::Multirootca::Monitoring[cloud_wmnet_ca]
- Systemd::Timer[cfssl-ocsprefresh-mlserve_front_proxy]
- Systemd::Unit[prometheus-node-textfile-prometheus-check-mlserve_staging_front_proxy-certificate-expiry.service]
- Service[cfssl-ocsprefresh-etcd.timer]
- File[/lib/systemd/system/cfssl-ocsprefresh-etcd.timer]
- Systemd::Unit[cfssl-ocsprefresh-cassandra.service]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_puppet_rsa]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/signers/mlserve_staging_front_proxy/cfssl.conf]
- Rsyslog::Conf[nrpe2nodexp-check_certificate_expiry_wikikube]
- Prometheus::Node_textfile[prometheus-check-mlserve_staging_front_proxy-certificate-expiry]
- Cfssl::Cert[OCSP_puppet_rsa_pki1001_eqiad_wmnet]
- Monitoring::Service[check_certificate_expiry_aux_front_proxy]
- File[/srv/cfssl/bundles/wikikube_staging_front_proxy.pem]
- Systemd::Syslog[prometheus-node-textfile-prometheus-check-discovery-certificate-expiry]
- File[/usr/local/bin/prometheus-check-mlserve_front_proxy-certificate-expiry]
- Cfssl::Cert[OCSP_dse_pki1001_eqiad_wmnet]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.timer]
- Exec[ensure_present_mod_proxy_http]
- File[/var/log/cfssl-ocsprefresh-etcd]
- Httpd::Conf[pki.discovery.wmnet]
- File[/srv/cfssl/bundles/wikikube_front_proxy.pem]
- File[/var/log/prometheus-node-textfile-prometheus-check-syslog-certificate-expiry]
- Systemd::Service[cfssl-ocspserve@Wikimedia_Internal_Root_CA]
- File[/etc/cfssl/signers/wikikube_staging_front_proxy/ca/wikikube_staging_front_proxy.pem]
- Prometheus::Blackbox::Check::Http[PKI_dse]
- Systemd::Timer[cfssl-ocsprefresh-aux_front_proxy]
- File[/var/log/cfssl-ocsprefresh-debmonitor]
- Rsyslog::Conf[nrpe2nodexp-ferm_active]
- File[/etc/cfssl/signers/debmonitor/cfssl.conf]
- Prometheus::Node_textfile[prometheus-check-wikikube-certificate-expiry]
- File[/etc/logrotate.d/cfssl-ocsprefresh-discovery2026]
- File[/etc/cfssl/csr/OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/ocsp/debmonitor.ocsp]
- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet-key.pem]
- Logrotate::Conf[cfssl-ocsprefresh-puppet_rsa]
- Systemd::Service[cfssl-ocsprefresh-mlserve]
- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.timer (wmf_auto_restart_ulogd2.timer)]
- File[/etc/ssl/localcerts/multiroot_ca.pem]
- Systemd::Service[cfssl-ocsprefresh-mlserve_front_proxy]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.service (prometheus-node-textfile-prometheus-check-puppet_rsa-certificate-expiry.service)]
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_aux_front_proxy.service]
- File[/etc/cfssl/ocsp/network_devices.ocsp]
- Systemd::Timer::Job[cfssl-ocsprefresh-kafka]
- File[/lib/systemd/system/prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.timer]
- File[/etc/rsyslog.d/40-cfssl-ocsprefresh-network-devices.conf]
- Nrpe::Check[check_check_certificate_expiry_cassandra]
- File[/usr/local/bin/prometheus-check-discovery-certificate-expiry]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_kafka]
- File[/lib/systemd/system/cfssl-ocsprefresh-kafka.timer]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_pki1001_eqiad_wmnet.pem]
- File[/etc/cfssl/signers/kafka/ca/kafka-key.pem]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-zuul-certificate-expiry]
- File[/etc/logrotate.d/cfssl-ocsprefresh-mlserve_staging_front_proxy]
- Service[nrpe2nodexp-check_certificate_expiry_mlserve.timer]
- File[/etc/cfssl/signers/aux_front_proxy]
- File[/var/log/cfssl-ocsprefresh-kafka]
- Systemd::Unit[cfssl-ocsprefresh-wikikube_staging_front_proxy.service]
- Monitoring::Exported_nagios_service[pki1001 check_certificate_expiry_wikikube_front_proxy]
- Logrotate::Conf[cfssl-ocsprefresh-mlserve]
- Cfssl::Ocsp[syslog]
- Ferm::Service[csr_and_ocsp_responder]
- File[/etc/cfssl/signers/wikikube/ca]
- Logrotate::Conf[cfssl-gc-expired-certs]
- File[/etc/apache2/conf-available/50-server-status.conf]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_discovery.service (nrpe2nodexp-check_certificate_expiry_discovery.service)]
- File[/etc/cfssl/ocsp/dse.ocsp]
- Systemd::Unit[wmf_auto_restart_apache-htcacheclean.service]
- File[/etc/cfssl/signers/syslog/ca/syslog-key.pem]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.pem]
- Systemd::Unit[nrpe2nodexp-check_certificate_expiry_mlserve_front_proxy.service]
- File[/etc/cfssl/signers/wikikube]
- Rsyslog::Conf[ulogd]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.timer (nrpe2nodexp-check_certificate_expiry_wikikube_front_proxy.timer)]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_discovery_pki1001_eqiad_wmnet.csr]
- Service[prometheus-node-textfile-prometheus-check-mlserve_front_proxy-certificate-expiry.timer]
- Systemd::Unit[cfssl-ocsprefresh-discovery.service]
- Ferm::Service[ssh_from_bastion]
- Sudo::User[nrpe_certificate_check_network_devices]
- Systemd::Timer[nrpe2nodexp-check_certificate_expiry_discovery2026]
- File[/etc/logrotate.d/wmf_auto_restart_ulogd2]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.service (prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry.service)]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-aux_front_proxy.timer (cfssl-ocsprefresh-aux_front_proxy.timer)]
- File[/etc/sudoers.d/nrpe_certificate_check_dse_front_proxy]
- Systemd::Unit[cfssl-ocspserve@wikikube]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_aux_front_proxy.cfg]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-wikikube_staging_front_proxy-certificate-expiry]
- Cfssl::Cert[OCSP_mlserve_front_proxy_pki1001_eqiad_wmnet]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-debmonitor-certificate-expiry]
- File[/etc/sudoers.d/nrpe_certificate_check_cloud_wmnet_ca]
- Nrpe::Check[check_check_certificate_expiry_network_devices]
- File[/etc/logrotate.d/cfssl-ocsprefresh-wikikube]
- Cfssl::Cert[OCSP_network_devices_pki1001_eqiad_wmnet]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_wikikube_staging_front_proxy]
- Exec[Generate cert OCSP_discovery_pki1001_eqiad_wmnet]
- Rsyslog::Conf[cfssl-ocsprefresh-network_devices]
- File[/etc/rsyslog.d/40-ulogd.conf]
- Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_debmonitor.timer (nrpe2nodexp-check_certificate_expiry_debmonitor.timer)]
- Systemd::Service[prometheus-node-textfile-prometheus-check-dse-certificate-expiry]
- Motd::Script[pki::multirootca]
- Logrotate::Conf[prometheus-node-textfile-prometheus-check-etcd-certificate-expiry]
- Service[prometheus-node-textfile-prometheus-check-syslog-certificate-expiry.timer]
- Rsyslog::Conf[cfssl-ocsprefresh-wikikube_staging]
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_puppet_rsa.cfg]
- File[/etc/cfssl/ssl/ocsp/OCSP_cloud_wmnet_ca_pki1001_eqiad_wmnet-key.pem]
- Systemd::Timer::Job[nrpe2nodexp-check_certificate_expiry_mlserve]
- Cfssl::Config[dse_front_proxy]
- Profile::Pki::Multirootca::Monitoring[zuul]
- Rsyslog::Conf[cfssl-ocsprefresh-mlserve_front_proxy]
- Profile::Pki::Multirootca::Monitoring[aux_front_proxy]
- Systemd::Service[cfssl-ocspserve@cassandra]
- Sudo::User[nrpe-check_check_certificate_expiry_cassandra]
- Systemd::Timer[prometheus-node-textfile-prometheus-check-mlserve-certificate-expiry]
- File[/var/log/cfssl-ocsprefresh-mlserve_staging_front_proxy]
- Systemd::Service[nrpe2nodexp-check_certificate_expiry_debmonitor]
- File[/etc/cfssl/signers/debmonitor/ca]
- Httpd::Mod_conf[filter]
Resources modified
- Class[Profile::Firewall]
- Parameters differences:
--- Class[Profile::Firewall].orig +++ Class[Profile::Firewall] @@ - provider => ferm + provider => nftables
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg]
- Parameters differences:
--- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg].orig +++ File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg] - tag => nrpe::check - notify => Service[nagios-nrpe-server] - owner => root - ensure => present - group => root - mode => 0444 - require => Package[nagios-nrpe-server]
- Content differences:
--- /etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg.orig +++ /etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg @@ -1,2 +0,0 @@ -# File generated by puppet. DO NOT edit by hand -command[check_check_certificate_expiry_wikikube_staging_front_proxy]=/usr/bin/sudo /usr/bin/openssl x509 -checkend 4687200 -in /etc/cfssl/signers/wikikube_staging_front_proxy/ca/wikikube_staging_front_proxy.pem
- Prometheus::Node_textfile[check-nft]
- Parameters differences:
--- Prometheus::Node_textfile[check-nft].orig +++ Prometheus::Node_textfile[check-nft] + user => root + run_cmd => /usr/local/bin/check-nft + interval => *:0/30 + environment => {} + extra_packages => [] + filesource => puppet:///modules/profile/firewall/check_nftables.py + ensure => present- Cfssl::Signer[dse]
- Parameters differences:
--- Cfssl::Signer[dse].orig +++ Cfssl::Signer[dse] - ca_cert_content => -----BEGIN CERTIFICATE----- MIIDpTCCAwegAwIBAgIUb4Tdc/LBMz08oj3vXm9vyvVoa8kwCgYIKoZIzj0EAwQw gZwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1T YW4gRnJhbmNpc2NvMSIwIAYDVQQKExlXaWtpbWVkaWEgRm91bmRhdGlvbiwgSW5j MRcwFQYDVQQLEw5DbG91ZCBTZXJ2aWNlczEjMCEGA1UEAwwaV2lraW1lZGlhX0lu dGVybmFsX1Jvb3RfQ0EwHhcNMjMwMjIyMTczMzAwWhcNMjgwMjIxMTczMzAwWjBx MQswCQYDVQQGEwJVUzEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEiMCAGA1UEChMZ V2lraW1lZGlhIEZvdW5kYXRpb24sIEluYzEYMBYGA1UECxMPU1JFIEZvdW5kYXRp b25zMQwwCgYDVQQDEwNkc2UwgZswEAYHKoZIzj0CAQYFK4EEACMDgYYABAEKIsRi rMZazQ75DhhEGhtUEr3248uYpcVNJ3Mp/1IdsIkgdy3vU97D4x+FWvbcITOzw9xz apIVnwWIAU7hei4jEwCAIr3llako75gtbD7Xvq9y6UDUcp/LOGBkmGMBktL2Q9qz Dgc4AgI29X2/hGBuYEglW2Qhpnbu0+q+7Xi/eKSG3aOCAQwwggEIMA4GA1UdDwEB /wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQWBBSp3KLmcR8APKuf wQNUAmw4ugiWrzAfBgNVHSMEGDAWgBQ7raJx5jS9G/yAvzVxg5HQ72kTNjBWBggr BgEFBQcBAQRKMEgwRgYIKwYBBQUHMAGGOmh0dHA6Ly9wa2kuZGlzY292ZXJ5Lndt bmV0L29jc3AvV2lraW1lZGlhX0ludGVybmFsX1Jvb3RfQ0EwSgYDVR0fBEMwQTA/ oD2gO4Y5aHR0cDovL3BraS5kaXNjb3Zlcnkud21uZXQvY3JsL1dpa2ltZWRpYV9J bnRlcm5hbF9Sb290X0NBMAoGCCqGSM49BAMEA4GLADCBhwJCAYGa4oeqY5OQzJhU JqhW7Wn0V5dXQ3F0LJKbf70afe5Xx/jkMKMXv6cpUoCgq6OW5CzFHvwyYGDYc3Uy Dj63k3tQAkFP3CHPBJahbaziMXpat5mFpYeRit/bScad+W+ysdXe4wLSRK3skzhU pOp2n7NgGJQbM1fWuRcBPMQLEZVFsbo04A== -----END CERTIFICATE----- - ca_file => /etc/cfssl/signers/dse/ca/dse.pem - listen_addr => pki1001.eqiad.wmnet - listen_port => 8888 - manage_db => False - manage_services => False - db_user => cfssl - db_pass => changeme - serve_service => cfssl-multirootca - default_expiry => 672h - auth_keys => {'default_auth': {'key': 'aaaabbbbccccdddd', 'type': 'standard'}, 'k8s_staging': {'key': 'ddddccccbbbbaaaa', 'type': 'standard'}, 'k8s_wikikube': {'key': 'ddddccccbbbbaaab', 'type': 'standard'}, 'k8s_mlserve': {'key': 'bbbbccccddddaaaa', 'type': 'standard'}, 'k8s_mlstaging': {'key': 'ccccbbbbaaaadddd', 'type': 'standard'}, 'k8s_dse': {'key': 'bbbbaaaaddddcccc', 'type': 'standard'}, 'k8s_aux': {'key': 'ffffffffffffffff', 'type': 'standard'}} - db_driver => sqlite3 - default_crl_url => http://pki.discovery.wmnet/crl/dse - log_level => info - db_name => cfssl - default_ocsp_url => http://pki.discovery.wmnet/ocsp/dse - db_conf_file => /etc/cfssl/db.conf - ca_key_file => /etc/cfssl/signers/dse/ca/dse-key.pem - default_usages => ['signing', 'key encipherment', 'client auth'] - profiles => {'ocsp': {'usages': ['digital signature', 'ocsp signing'], 'expiry': '43800h'}, 'server': {'usages': ['digital signature', 'key encipherment', 'server auth'], 'expiry': '672h'}, 'service-account-management': {'usages': ['digital signature', 'key encipherment']}, 'prometheus': {'expiry': '8760h', 'usages': ['digital signature', 'key encipherment', 'client auth']}} - serve_ensure => absent - db_host => localhost - default_auth_key => default_auth - ca_key_content =>- File[/srv/cfssl/bundles/network_devices.pem]
- Parameters differences:
--- File[/srv/cfssl/bundles/network_devices.pem].orig +++ File[/srv/cfssl/bundles/network_devices.pem] - owner => root - group => root - mode => 0444 - ensure => file
- Content differences:
--- /srv/cfssl/bundles/network_devices.pem.orig +++ /srv/cfssl/bundles/network_devices.pem @@ -1,22 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDsjCCAxOgAwIBAgIUS2pUBD1erPOX2W9m08l4NjcjbVYwCgYIKoZIzj0EAwQw -gZwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1T -YW4gRnJhbmNpc2NvMSIwIAYDVQQKExlXaWtpbWVkaWEgRm91bmRhdGlvbiwgSW5j -MRcwFQYDVQQLEw5DbG91ZCBTZXJ2aWNlczEjMCEGA1UEAwwaV2lraW1lZGlhX0lu -dGVybmFsX1Jvb3RfQ0EwHhcNMjMwNzE0MTAxODAwWhcNMjgwNzEyMTAxODAwWjB9 -MQswCQYDVQQGEwJVUzEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEiMCAGA1UEChMZ -V2lraW1lZGlhIEZvdW5kYXRpb24sIEluYzEYMBYGA1UECxMPU1JFIEZvdW5kYXRp -b25zMRgwFgYDVQQDDA9uZXR3b3JrX2RldmljZXMwgZswEAYHKoZIzj0CAQYFK4EE -ACMDgYYABABVWARjDjpjG7IlggP4BkOm5hanZXdtYYzUb1CsmHvpBA4W6s8CjzHp -QlZoBzaMi6SSO5Q7v9rAuymjLctweVRy7gAkNU3jjQXZPjRKaW/ofZlUhDyhgyCS -WNr9LBjYklAnMM3yz3J6EG9aHehHbV11lq24AQDrZ4bEtNzGHMQyU9ufZ6OCAQww -ggEIMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQW -BBRmY7aPPiOyhsjgXpDtumx9X/wcGzAfBgNVHSMEGDAWgBQ7raJx5jS9G/yAvzVx -g5HQ72kTNjBWBggrBgEFBQcBAQRKMEgwRgYIKwYBBQUHMAGGOmh0dHA6Ly9wa2ku -ZGlzY292ZXJ5LndtbmV0L29jc3AvV2lraW1lZGlhX0ludGVybmFsX1Jvb3RfQ0Ew -SgYDVR0fBEMwQTA/oD2gO4Y5aHR0cDovL3BraS5kaXNjb3Zlcnkud21uZXQvY3Js -L1dpa2ltZWRpYV9JbnRlcm5hbF9Sb290X0NBMAoGCCqGSM49BAMEA4GMADCBiAJC -ARWhtt4Mi0I8j+6LUC+ZJfTnhYkEWSXa6nhttbzNPLzHuBTnj42WE8a2oQW2Mv5w -mzRdtJGsstcrgGwGt5FyLP6WAkIAxYlEt4MHqohD9adWY1IsnX4qWBYRw4tXrx0T -tF1M2n2K7ww/zCL9HkBoWVe249y+ctpGqqgw0ROMnMN6Q2Zg8ic= ------END CERTIFICATE-----
- Systemd::Unit[cfssl-ocsprefresh-etcd.service]
- Parameters differences:
--- Systemd::Unit[cfssl-ocsprefresh-etcd.service].orig +++ Systemd::Unit[cfssl-ocsprefresh-etcd.service] - unit => cfssl-ocsprefresh-etcd.service - override => False - ensure => present - restart => False - override_filename => puppet-override.conf - require => ['Class[Systemd]']
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service)].orig +++ Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service)] - refreshonly => True - command => /bin/systemctl daemon-reload
- File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf]
- Parameters differences:
--- File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf].orig +++ File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf] + notify => Service[rsyslog] + owner => root + group => root + mode => 0444 + ensure => present
- Content differences:
--- /etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf.orig +++ /etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf @@ -0,0 +1,10 @@ +# rsyslog.conf(5) configuration file for services. +# This file is managed by Puppet. +if $programname startswith "prometheus-node-textfile-check-nft" then { + action( + type="omfile" file="/var/log/prometheus-node-textfile-check-nft/syslog.log" + fileOwner="root" fileGroup="root" + fileCreateMode="0644" + ) + & stop +}- Systemd::Unit[cfssl-ocsprefresh-mlserve_front_proxy.timer]
- Parameters differences:
--- Systemd::Unit[cfssl-ocsprefresh-mlserve_front_proxy.timer].orig +++ Systemd::Unit[cfssl-ocsprefresh-mlserve_front_proxy.timer] - unit => cfssl-ocsprefresh-mlserve_front_proxy.timer - override => False - ensure => present - restart => False - override_filename => puppet-override.conf - require => ['Class[Systemd]']
- File[/etc/apache2/conf-available/00-defaults.conf]
- Parameters differences:
--- File[/etc/apache2/conf-available/00-defaults.conf].orig +++ File[/etc/apache2/conf-available/00-defaults.conf] - notify => Service[apache2] - owner => root - source => puppet:///modules/httpd/defaults.conf - group => root - mode => 0444 - ensure => present
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Parameters differences:
--- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry].orig +++ File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry] - owner => root - group => root - mode => 0444 - ensure => present
- Content differences:
--- /etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.orig +++ /etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry @@ -1,12 +0,0 @@ -# logrotate(8) config for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry - -/var/log/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry/*.log { - daily - copytruncate - missingok - compress - delaycompress - notifempty - rotate 15 - size 256M -}- File[/usr/local/bin/prometheus-check-aux-certificate-expiry]
- Parameters differences:
--- File[/usr/local/bin/prometheus-check-aux-certificate-expiry].orig +++ File[/usr/local/bin/prometheus-check-aux-certificate-expiry] - owner => root - source => puppet:///modules/prometheus/check_certificate_expiry.py - group => root - mode => 0555 - ensure => present
- Nrpe::Monitor_service[check_certificate_expiry_kafka]
- Parameters differences:
--- Nrpe::Monitor_service[check_certificate_expiry_kafka].orig +++ Nrpe::Monitor_service[check_certificate_expiry_kafka] - contact_group => admins - sudo_user => root - notes_url => https://wikitech.wikimedia.org/wiki/PKI/CA_Operations - description => Check to ensure the signer certificate is valid CA: kafka - retries => 3 - check_interval => 1 - migration_task => T350694 - retry_interval => 1 - nrpe_command => /usr/bin/openssl x509 -checkend 4687200 -in /etc/cfssl/signers/kafka/ca/kafka.pem - alertmanager_team => observability - enable_nrpe2nodexp => False - enable_icinga_check => True - nrpe2nodexp_parse_perf_data => False - critical => False - timeout => 10 - ensure => present
- File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem]
- Parameters differences:
--- File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem].orig +++ File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem] - show_diff => False - notify => Service[cfssl-multirootca] - owner => root - group => root - mode => 0400 - ensure => file
- Content differences:
--- /etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem.orig +++ /etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem @@ -1 +0,0 @@ -nosecret
- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.service (cfssl-ocsprefresh-mlserve.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.service (cfssl-ocsprefresh-mlserve.service)].orig +++ Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.service (cfssl-ocsprefresh-mlserve.service)] - refreshonly => True - command => /bin/systemctl daemon-reload
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka]
- Parameters differences:
--- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka].orig +++ File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka] - validate_cmd => /usr/sbin/visudo -cqf % - owner => root - ensure => present - group => root - mode => 0440 - require => Package[nagios-nrpe-server]
- Content differences:
--- /etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka.orig +++ /etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka @@ -1,3 +0,0 @@ -# This file is managed by Puppet! - -nagios ALL = (root) NOPASSWD: /usr/bin/openssl x509 -checkend 4687200 -in /etc/cfssl/signers/kafka/ca/kafka.pem
- File[/lib/systemd/system/cfssl-ocsprefresh-syslog.timer]
- Parameters differences:
--- File[/lib/systemd/system/cfssl-ocsprefresh-syslog.timer].orig +++ File[/lib/systemd/system/cfssl-ocsprefresh-syslog.timer] - notify => Exec[systemd daemon-reload for cfssl-ocsprefresh-syslog.timer (cfssl-ocsprefresh-syslog.timer)] - owner => root - group => root - mode => 0444 - ensure => present
- Content differences:
--- /lib/systemd/system/cfssl-ocsprefresh-syslog.timer.orig +++ /lib/systemd/system/cfssl-ocsprefresh-syslog.timer @@ -1,13 +0,0 @@ -[Unit] -Description=Periodic execution of cfssl-ocsprefresh-syslog.service - -[Timer] -Unit=cfssl-ocsprefresh-syslog.service -# Accuracy sets the maximum time interval around the execution time we want to allow -AccuracySec=15sec -OnUnitInactiveSec=1h -OnActiveSec=1s -RandomizedDelaySec=0 - -[Install] -WantedBy=multi-user.target
- Systemd::Syslog[cfssl-ocsprefresh-zuul]
- Parameters differences:
--- Systemd::Syslog[cfssl-ocsprefresh-zuul].orig +++ Systemd::Syslog[cfssl-ocsprefresh-zuul] - force_stop => True - readable_by => all - owner => root - base_dir => /var/log - group => root - programname_comparison => startswith - log_filename => syslog.log - ensure => present
- Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet refresh]
- Parameters differences:
--- Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet refresh].orig +++ Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet refresh] - environment => ['GODEBUG=x509ignoreCN=0'] - refreshonly => True - command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/pki1001.eqiad.wmnet.pem -label mlserve_staging_front_proxy -profile ocsp /etc/cfssl/csr/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/ocsp/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet - subscribe => File[/etc/cfssl/csr/OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Parameters differences:
--- File[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr].orig +++ File[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr] - owner => root - group => root - mode => 0400 - ensure => file
- Content differences:
--- /etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr.orig +++ /etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr @@ -1,13 +0,0 @@ -{ - "CN": "pki1001.eqiad.wmnet", - "hosts": [ - "pki1001.eqiad.wmnet" - ], - "key": { - "algo": "ecdsa", - "size": 256 - }, - "names": [ - - ] -}- Exec[renew certificate - OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet]
- Parameters differences:
--- Exec[renew certificate - OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet].orig +++ Exec[renew certificate - OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet] - environment => ['GODEBUG=x509ignoreCN=0'] - unless => /usr/bin/openssl x509 -in /etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.pem -checkend 952200 - command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/pki1001.eqiad.wmnet.pem -label wikikube_staging_front_proxy -profile ocsp /etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/ocsp/OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet - require => Exec[Generate cert OCSP_wikikube_staging_front_proxy_pki1001_eqiad_wmnet]
- Sudo::User[nrpe-check_check_certificate_expiry_puppet_rsa]
- Parameters differences:
--- Sudo::User[nrpe-check_check_certificate_expiry_puppet_rsa].orig +++ Sudo::User[nrpe-check_check_certificate_expiry_puppet_rsa] - user => nagios - tag => nrpe::check - privileges => ['ALL = (root) NOPASSWD: /usr/bin/openssl x509 -checkend 4687200 -in /etc/cfssl/signers/puppet_rsa/ca/puppet_rsa.pem'] - ensure => present - require => ['Class[Sudo]']
- File[/etc/cfssl/ocsp/mlserve_staging_front_proxy.ocsp]
- Parameters differences:
--- File[/etc/cfssl/ocsp/mlserve_staging_front_proxy.ocsp].orig +++ File[/etc/cfssl/ocsp/mlserve_staging_front_proxy.ocsp] - group => root - ensure => file - owner => root
- Service[cfssl-ocsprefresh-mlserve_staging.timer]
- Parameters differences:
--- Service[cfssl-ocsprefresh-mlserve_staging.timer].orig +++ Service[cfssl-ocsprefresh-mlserve_staging.timer] - enable => True - ensure => running - provider => systemd
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service)].orig +++ Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service)] - refreshonly => True - command => /bin/systemctl daemon-reload
- File[/etc/confd/conf.d/_etc_ferm_conf.d_00_defs_requestctl.toml]
- Parameters differences:
--- File[/etc/confd/conf.d/_etc_ferm_conf.d_00_defs_requestctl.toml].orig +++ File[/etc/confd/conf.d/_etc_ferm_conf.d_00_defs_requestctl.toml] @@ - ensure => present + ensure => absent
- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.pem].orig +++ File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.pem] - owner => root - group => root - mode => 0440 - ensure => file
- Cfssl::Csr[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr].orig +++ Cfssl::Csr[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr] - ensure => present - hosts => [] - names => [] - key => {'algo': 'ecdsa', 'size': 256} - common_name => pki1001.eqiad.wmnet- Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.timer (cfssl-ocsprefresh-debmonitor.timer)]
- Parameters differences:
--- Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.timer (cfssl-ocsprefresh-debmonitor.timer)].orig +++ Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.timer (cfssl-ocsprefresh-debmonitor.timer)] - before => ['Service[cfssl-ocsprefresh-debmonitor.timer]'] - refreshonly => True - command => /bin/systemctl daemon-reload
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service]
- Parameters differences:
--- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service].orig +++ File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service] - notify => Exec[systemd daemon-reload for nrpe2nodexp-check_certificate_expiry_mlserve.service (nrpe2nodexp-check_certificate_expiry_mlserve.service)] - owner => root - group => root - mode => 0444 - ensure => absent
- Content differences:
--- /lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service.orig +++ /lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service @@ -1,11 +0,0 @@ -[Unit] -Description=execution of nrpe2nodexp for the check_check_certificate_expiry_mlserve command. -Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - -[Service] -Type=oneshot -User=nagios - -Group=prometheus-node-exporter -SyslogIdentifier=nrpe2nodexp-check_certificate_expiry_mlserve -ExecStart=-/usr/local/bin/nrpe2nodexp --alert-rule-hash "bfd2f7c6497e1da6323bef48d24f9e8e" --timeout 10 --check-command "check_check_certificate_expiry_mlserve"
- Prometheus::Node_textfile[prometheus-check-dse-certificate-expiry]
- Parameters differences:
--- Prometheus::Node_textfile[prometheus-check-dse-certificate-expiry].orig +++ Prometheus::Node_textfile[prometheus-check-dse-certificate-expiry] - user => root - filesource => puppet:///modules/prometheus/check_certificate_expiry.py - environment => {} - require => ['Package[python3-cryptography]', 'Package[python3-prometheus-client]'] - run_cmd => /usr/local/bin/prometheus-check-dse-certificate-expiry --cert-path /etc/cfssl/signers/dse/ca/dse.pem --outfile /var/lib/prometheus/node.d/dse_intermediate.prom - extra_packages => [] - interval => daily - ensure => present- Systemd::Timer::Job[nrpe2nodexp-ferm_active]
- Parameters differences:
--- Systemd::Timer::Job[nrpe2nodexp-ferm_active].orig +++ Systemd::Timer::Job[nrpe2nodexp-ferm_active] - user => nagios - logfile_group => root - send_mail_only_on_error => True - syslog_identifier => nrpe2nodexp-ferm_active - splay => 600 - send_mail => False - group => prometheus-node-exporter - success_exit_status => [] - command => /usr/local/bin/nrpe2nodexp --alert-rule-hash "bba0a2572329bb500b832470e08b381c" --timeout 10 --check-command "check_ferm_active" - description => execution of nrpe2nodexp for the check_ferm_active command. - syslog_force_stop => True - monitoring_contact_groups => admins - interval => [{'start': 'OnUnitInactiveSec', 'interval': '10min'}] - logfile_perms => all - logging_enabled => False - syslog_match_startswith => True - logfile_name => syslog.log - send_mail_to => root@pki1001.eqiad.wmnet - environment => {} - private_tmp => False - monitoring_enabled => False - fixed_random_delay => True - ignore_errors => True - monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - logfile_basedir => /var/log - ensure => present- File[/etc/cfssl/signers/syslog/cfssl.conf]
- Parameters differences:
--- File[/etc/cfssl/signers/syslog/cfssl.conf].orig +++ File[/etc/cfssl/signers/syslog/cfssl.conf] - show_diff => False - owner => root - group => root - mode => 0440 - ensure => present
- Content differences:
--- /etc/cfssl/signers/syslog/cfssl.conf.orig +++ /etc/cfssl/signers/syslog/cfssl.conf @@ -1,65 +0,0 @@ -{ - "auth_keys": { - "default_auth": { - "key": "aaaabbbbccccdddd", - "type": "standard" - }, - "k8s_staging": { - "key": "ddddccccbbbbaaaa", - "type": "standard" - }, - "k8s_wikikube": { - "key": "ddddccccbbbbaaab", - "type": "standard" - }, - "k8s_mlserve": { - "key": "bbbbccccddddaaaa", - "type": "standard" - }, - "k8s_mlstaging": { - "key": "ccccbbbbaaaadddd", - "type": "standard" - }, - "k8s_dse": { - "key": "bbbbaaaaddddcccc", - "type": "standard" - }, - "k8s_aux": { - "key": "ffffffffffffffff", - "type": "standard" - } - }, - "signing": { - "default": { - "auth_key": "default_auth", - "usages": [ - "digital signature", - "key encipherment", - "server auth", - "client auth" - ], - "expiry": "672h", - "crl_url": "http://pki.discovery.wmnet/crl/syslog", - "ocsp_url": "http://pki.discovery.wmnet/ocsp/syslog" - }, - "profiles": { - "ocsp": { - "auth_key": "default_auth", - "expiry": "43800h", - "usages": [ - "digital signature", - "ocsp signing" - ] - }, - "server": { - "auth_key": "default_auth", - "expiry": "672h", - "usages": [ - "digital signature", - "key encipherment", - "server auth" - ] - } - } - } -}- File[/var/log/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry]
- Parameters differences:
--- File[/var/log/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry].orig +++ File[/var/log/prometheus-node-textfile-prometheus-check-aux_front_proxy-certificate-expiry] - owner => root - force => True - backup => False - group => root - mode => 0755 - ensure => directory
- Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr].orig +++ Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr] - ensure => present - hosts => [] - names => [] - key => {'algo': 'ecdsa', 'size': 256} - common_name => pki1001.eqiad.wmnet- Cfssl::Config[wikikube]
- Parameters differences:
--- Cfssl::Config[wikikube].orig +++ Cfssl::Config[wikikube] - default_ocsp_url => http://pki.discovery.wmnet/ocsp/wikikube - path => /etc/cfssl/signers/wikikube/cfssl.conf - default_auth_remote => {} - default_usages => ['signing', 'key encipherment', 'client auth'] - remotes => {} - profiles => {'ocsp': {'usages': ['digital signature', 'ocsp signing'], 'expiry': '43800h'}, 'server': {'usages': ['digital signature', 'key encipherment', 'server auth'], 'expiry': '672h'}, 'service-account-management': {'usages': ['digital signature', 'key encipherment']}, 'prometheus': {'expiry': '8760h', 'usages': ['digital signature', 'key encipherment', 'client auth']}} - notify => Service[cfssl-multirootca] - default_expiry => 672h - default_auth_key => default_auth - auth_keys => {'default_auth': {'key': 'aaaabbbbccccdddd', 'type': 'standard'}, 'k8s_staging': {'key': 'ddddccccbbbbaaaa', 'type': 'standard'}, 'k8s_wikikube': {'key': 'ddddccccbbbbaaab', 'type': 'standard'}, 'k8s_mlserve': {'key': 'bbbbccccddddaaaa', 'type': 'standard'}, 'k8s_mlstaging': {'key': 'ccccbbbbaaaadddd', 'type': 'standard'}, 'k8s_dse': {'key': 'bbbbaaaaddddcccc', 'type': 'standard'}, 'k8s_aux': {'key': 'ffffffffffffffff', 'type': 'standard'}} - ensure => present - default_crl_url => http://pki.discovery.wmnet/crl/wikikube- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service)]
- Parameters differences:
--- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service)].orig +++ Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service)] - refreshonly => True - command => /bin/systemctl daemon-reload
- File[/etc/cfssl/ocsp/mlserve_staging.ocsp]
- Parameters differences:
--- File[/etc/cfssl/ocsp/mlserve_staging.ocsp].orig +++ File[/etc/cfssl/ocsp/mlserve_staging.ocsp] - group => root - ensure => file - owner => root
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- Parameters differences:
--- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry].orig +++ Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry] - user => root - logfile_group => root - send_mail_only_on_error => True - send_mail => False - success_exit_status => [] - command => /usr/local/bin/prometheus-check-wikikube_front_proxy-certificate-expiry --cert-path /etc/cfssl/signers/wikikube_front_proxy/ca/wikikube_front_proxy.pem --outfile /var/lib/prometheus/node.d/wikikube_front_proxy_intermediate.prom - description => Systemd timer to gather node metrics for prometheus-check-wikikube_front_proxy-certificate-expiry - syslog_force_stop => True - monitoring_contact_groups => admins - interval => {'start': 'OnCalendar', 'interval': 'daily'} - logfile_perms => all - logging_enabled => True - syslog_match_startswith => True - logfile_name => syslog.log - send_mail_to => root@pki1001.eqiad.wmnet - environment => {} - private_tmp => False - monitoring_enabled => False - fixed_random_delay => False - ignore_errors => False - monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - logfile_basedir => /var/log - ensure => present- File[/var/log/cfssl-ocsprefresh-discovery]
- Parameters differences:
--- File[/var/log/cfssl-ocsprefresh-discovery].orig +++ File[/var/log/cfssl-ocsprefresh-discovery] - owner => root - force => True - backup => False - group => root - mode => 0755 - ensure => directory
- Systemd::Timer[cfssl-ocsprefresh-dse_front_proxy]
- Parameters differences:
--- Systemd::Timer[cfssl-ocsprefresh-dse_front_proxy].orig +++ Systemd::Timer[cfssl-ocsprefresh-dse_front_proxy] - accuracy => 15sec - splay => 0 - unit_name => cfssl-ocsprefresh-dse_front_proxy.service - ensure => present - fixed_random_delay => False - timer_intervals => [{'start': 'OnUnitInactiveSec', 'interval': '1h'}, {'interval': '1s', 'start': 'OnActiveSec'}]- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft].orig +++ File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft] + tag => nft + notify => ['Service[nftables]'] + owner => root + group => root + mode => 0444 + ensure => present
- Content differences:
--- /etc/nftables/sets/FRACK_NETWORKS_ipv6.nft.orig +++ /etc/nftables/sets/FRACK_NETWORKS_ipv6.nft @@ -0,0 +1,4 @@ +# Autogenerated by puppet +set FRACK_NETWORKS_ipv6 { + type ipv6_addr +}- File[/etc/cfssl/signers/mlserve_staging/cfssl.conf]
- Parameters differences:
--- File[/etc/cfssl/signers/mlserve_staging/cfssl.conf].orig +++ File[/etc/cfssl/signers/mlserve_staging/cfssl.conf] - show_diff => False - owner => root - group => root - mode => 0440 - ensure => present
- Content differences:
--- /etc/cfssl/signers/mlserve_staging/cfssl.conf.orig +++ /etc/cfssl/signers/mlserve_staging/cfssl.conf @@ -1,81 +0,0 @@ -{ - "auth_keys": { - "default_auth": { - "key": "aaaabbbbccccdddd", - "type": "standard" - }, - "k8s_staging": { - "key": "ddddccccbbbbaaaa", - "type": "standard" - }, - "k8s_wikikube": { - "key": "ddddccccbbbbaaab", - "type": "standard" - }, - "k8s_mlserve": { - "key": "bbbbccccddddaaaa", - "type": "standard" - }, - "k8s_mlstaging": { - "key": "ccccbbbbaaaadddd", - "type": "standard" - }, - "k8s_dse": { - "key": "bbbbaaaaddddcccc", - "type": "standard" - }, - "k8s_aux": { - "key": "ffffffffffffffff", - "type": "standard" - } - }, - "signing": { - "default": { - "auth_key": "default_auth", - "usages": [ - "signing", - "key encipherment", - "client auth" - ], - "expiry": "72h", - "crl_url": "http://pki.discovery.wmnet/crl/mlserve_staging", - "ocsp_url": "http://pki.discovery.wmnet/ocsp/mlserve_staging" - }, - "profiles": { - "ocsp": { - "auth_key": "default_auth", - "expiry": "43800h", - "usages": [ - "digital signature", - "ocsp signing" - ] - }, - "server": { - "auth_key": "default_auth", - "expiry": "72h", - "usages": [ - "digital signature", - "key encipherment", - "server auth" - ] - }, - "service-account-management": { - "auth_key": "default_auth", - "expiry": "72h", - "usages": [ - "digital signature", - "key encipherment" - ] - }, - "prometheus": { - "auth_key": "default_auth", - "expiry": "8760h", - "usages": [ - "digital signature", - "key encipherment", - "client auth" - ] - } - } - } -}- File[/lib/systemd/system/cfssl-ocsprefresh-dse.service]
- Parameters differences:
--- File[/lib/systemd/system/cfssl-ocsprefresh-dse.service].orig +++ File[/lib/systemd/system/cfssl-ocsprefresh-dse.service] - notify => Exec[systemd daemon-reload for cfssl-ocsprefresh-dse.service (cfssl-ocsprefresh-dse.service)] - owner => root - group => root - mode => 0444 - ensure => present
- Content differences:
--- /lib/systemd/system/cfssl-ocsprefresh-dse.service.orig +++ /lib/systemd/system/cfssl-ocsprefresh-dse.service @@ -1,8 +0,0 @@ -[Unit] -Description=OCSP Refresh job - dse -Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - -[Service] -Type=oneshot -User=root -ExecStart=/usr/local/sbin/cfssl-ocsprefresh --update --responder-cert /etc/cfssl/ssl/ocsp/OCSP_dse_pki1001_eqiad_wmnet.pem --responder-key /etc/cfssl/ssl/ocsp/OCSP_dse_pki1001_eqiad_wmnet-key.pem --ca-file /etc/cfssl/signers/dse/ca/dse.pem --responses-file /etc/cfssl/ocsp/dse.ocsp --dbconfig /etc/cfssl/db.conf --restart-service 'cfssl-ocspserve@dse' dse
- Sudo::User[nrpe_certificate_check_dse]
- Parameters differences:
--- Sudo::User[nrpe_certificate_check_dse].orig +++ Sudo::User[nrpe_certificate_check_dse] - user => nrpe_certificate_check_dse - privileges => [] - ensure => absent - require => ['Class[Sudo]']
- Exec[Generate initial CRL for mlserve]
- Parameters differences:
--- Exec[Generate initial CRL for mlserve].orig +++ Exec[Generate initial CRL for mlserve] - creates => /srv/cfssl/crl/mlserve - path => ['/usr/bin'] - command => /usr/bin/cfssl gencrl - /etc/cfssl/signers/mlserve/ca/mlserve.pem /etc/cfssl/signers/mlserve/ca/mlserve-key.pem 157680000 </dev/null |/usr/bin/base64 -d > /srv/cfssl/crl/mlserve - require => ['Package[golang-cfssl]']
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr]
- Parameters differences:
--- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr].orig +++ File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr] - owner => root - group => root - mode => 0440 - ensure => file
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.service]
- Parameters differences:
--- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.service].orig +++ File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.service] - notify => Exec[systemd daemon-reload for cfssl-ocsprefresh-mlserve.service (cfssl-ocsprefresh-mlserve.service)] - owner => root - group => root - mode => 0444 - ensure => present
- Content differences:
--- /lib/systemd/system/cfssl-ocsprefresh-mlserve.service.orig +++ /lib/systemd/system/cfssl-ocsprefresh-mlserve.service @@ -1,8 +0,0 @@ -[Unit] -Description=OCSP Refresh job - mlserve -Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - -[Service] -Type=oneshot -User=root -ExecStart=/usr/local/sbin/cfssl-ocsprefresh --update --responder-cert /etc/cfssl/ssl/ocsp/OCSP_mlserve_pki1001_eqiad_wmnet.pem --responder-key /etc/cfssl/ssl/ocsp/OCSP_mlserve_pki1001_eqiad_wmnet-key.pem --ca-file /etc/cfssl/signers/mlserve/ca/mlserve.pem --responses-file /etc/cfssl/ocsp/mlserve.ocsp --dbconfig /etc/cfssl/db.conf --restart-service 'cfssl-ocspserve@mlserve' mlserve
- Nftables::Set[PRODUCTION_NETWORKS]
- Parameters differences:
--- Nftables::Set[PRODUCTION_NETWORKS].orig +++ Nftables::Set[PRODUCTION_NETWORKS] + hosts => ['10.128.0.0/24', '10.128.1.0/24', '10.128.2.0/24', '10.132.0.0/24', '10.132.2.0/24', '10.136.0.0/24', '10.136.1.0/24', '10.140.0.0/24', '10.140.1.0/24', '10.140.2.0/24', '10.192.0.0/22', '10.192.10.0/24', '10.192.11.0/24', '10.192.12.0/24', '10.192.13.0/24', '10.192.14.0/24', '10.192.15.0/24', '10.192.16.0/22', '10.192.20.0/24', '10.192.21.0/24', '10.192.22.0/24', '10.192.23.0/24', '10.192.24.0/23', '10.192.26.0/24', '10.192.27.0/24', '10.192.28.0/24', '10.192.29.0/24', '10.192.30.0/24', '10.192.31.0/24', '10.192.32.0/22', '10.192.36.0/24', '10.192.37.0/24', '10.192.38.0/24', '10.192.39.0/24', '10.192.4.0/24', '10.192.40.0/24', '10.192.41.0/24', '10.192.42.0/24', '10.192.43.0/24', '10.192.44.0/24', '10.192.45.0/24', '10.192.46.0/24', '10.192.47.0/24', '10.192.48.0/22', '10.192.5.0/24', '10.192.52.0/24', '10.192.56.0/24', '10.192.57.0/24', '10.192.58.0/24', '10.192.59.0/24', '10.192.6.0/24', '10.192.64.0/21', '10.192.7.0/24', '10.192.72.0/24', '10.192.76.0/24', '10.192.8.0/24', '10.192.80.0/20', '10.192.9.0/24', '10.192.96.0/21', '10.194.0.0/20', '10.194.128.0/17', '10.194.16.0/21', '10.194.61.0/24', '10.194.62.0/23', '10.194.64.0/20', '10.194.80.0/21', '10.2.1.0/24', '10.2.2.0/24', '10.2.3.0/24', '10.2.4.0/24', '10.2.5.0/24', '10.2.6.0/24', '10.2.7.0/24', '10.64.0.0/22', '10.64.130.0/24', '10.64.131.0/24', '10.64.132.0/24', '10.64.133.0/24', '10.64.134.0/24', '10.64.135.0/24', '10.64.136.0/24', '10.64.137.0/24', '10.64.138.0/24', '10.64.139.0/24', '10.64.140.0/24', '10.64.141.0/24', '10.64.142.0/24', '10.64.143.0/24', '10.64.144.0/24', '10.64.145.0/24', '10.64.148.0/24', '10.64.149.0/24', '10.64.150.0/24', '10.64.151.0/24', '10.64.152.0/24', '10.64.153.0/24', '10.64.154.0/24', '10.64.155.0/24', '10.64.156.0/24', '10.64.157.0/24', '10.64.158.0/24', '10.64.159.0/24', '10.64.16.0/22', '10.64.160.0/24', '10.64.161.0/24', '10.64.162.0/24', '10.64.163.0/24', '10.64.164.0/24', '10.64.165.0/24', '10.64.166.0/24', '10.64.167.0/24', '10.64.169.0/24', '10.64.170.0/24', '10.64.171.0/24', '10.64.172.0/24', '10.64.173.0/24', '10.64.174.0/24', '10.64.175.0/24', '10.64.176.0/24', '10.64.177.0/24', '10.64.178.0/24', '10.64.179.0/24', '10.64.180.0/24', '10.64.181.0/24', '10.64.182.0/24', '10.64.183.0/24', '10.64.184.0/24', '10.64.185.0/24', '10.64.186.0/24', '10.64.187.0/24', '10.64.188.0/24', '10.64.189.0/24', '10.64.190.0/24', '10.64.20.0/24', '10.64.21.0/24', '10.64.24.0/23', '10.64.32.0/22', '10.64.36.0/24', '10.64.48.0/22', '10.64.5.0/24', '10.64.53.0/24', '10.64.64.0/21', '10.64.72.0/24', '10.64.76.0/24', '10.67.0.0/20', '10.67.128.0/17', '10.67.16.0/21', '10.67.24.0/21', '10.67.32.0/20', '10.67.64.0/20', '10.67.80.0/21', '10.80.0.0/24', '10.80.1.0/24', '10.80.2.0/24', '103.102.166.0/28', '103.102.166.224/27', '103.102.166.96/27', '185.15.58.0/27', '185.15.58.224/27', '185.15.58.32/27', '185.15.59.0/27', '185.15.59.224/27', '185.15.59.32/27', '185.15.59.96/27', '195.200.68.0/27', '195.200.68.224/27', '195.200.68.32/27', '195.200.68.96/27', '198.35.26.0/27', '198.35.26.32/27', '198.35.26.96/27', '198.35.26.96/27', '2001:df2:e500:101::/64', '2001:df2:e500:103::/64', '2001:df2:e500:1::/64', '2001:df2:e500:3::/64', '2001:df2:e500:ed1a::/64', '208.80.152.128/27', '208.80.153.0/27', '208.80.153.224/27', '208.80.153.32/27', '208.80.153.64/27', '208.80.153.96/27', '208.80.154.0/26', '208.80.154.128/26', '208.80.154.224/27', '208.80.154.64/26', '208.80.155.96/27', '2620:0:860:100::/64', '2620:0:860:101::/64', '2620:0:860:102::/64', '2620:0:860:103::/64', '2620:0:860:104::/64', '2620:0:860:105::/64', '2620:0:860:106::/64', '2620:0:860:107::/64', '2620:0:860:108::/64', '2620:0:860:109::/64', '2620:0:860:10a::/64', '2620:0:860:10b::/64', '2620:0:860:10c::/64', '2620:0:860:10d::/64', '2620:0:860:10e::/64', '2620:0:860:10f::/64', '2620:0:860:110::/64', '2620:0:860:111::/64', '2620:0:860:112::/64', '2620:0:860:113::/64', '2620:0:860:114::/64', '2620:0:860:115::/64', '2620:0:860:116::/64', '2620:0:860:118::/64', '2620:0:860:119::/64', '2620:0:860:11a::/64', '2620:0:860:11b::/64', '2620:0:860:11c::/64', '2620:0:860:11d::/64', '2620:0:860:11e::/64', '2620:0:860:11f::/64', '2620:0:860:120::/64', '2620:0:860:121::/64', '2620:0:860:122::/64', '2620:0:860:123::/64', '2620:0:860:124::/64', '2620:0:860:125::/64', '2620:0:860:126::/64', '2620:0:860:127::/64', '2620:0:860:12b::/64', '2620:0:860:12c::/64', '2620:0:860:12d::/64', '2620:0:860:12e::/64', '2620:0:860:140::/64', '2620:0:860:1::/64', '2620:0:860:2::/64', '2620:0:860:300::/64', '2620:0:860:301::/64', '2620:0:860:302::/64', '2620:0:860:303::/64', '2620:0:860:304::/64', '2620:0:860:305::/64', '2620:0:860:307::/64', '2620:0:860:308::/64', '2620:0:860:3::/64', '2620:0:860:4::/64', '2620:0:860:5::/64', '2620:0:860:babe::/64', '2620:0:860:babf::/64', '2620:0:860:cabe::/64', '2620:0:860:cabf::/64', '2620:0:860:ed1a::/64', '2620:0:861:100::/64', '2620:0:861:101::/64', '2620:0:861:102::/64', '2620:0:861:103::/64', '2620:0:861:104::/64', '2620:0:861:105::/64', '2620:0:861:106::/64', '2620:0:861:107::/64', '2620:0:861:108::/64', '2620:0:861:109::/64', '2620:0:861:10a::/64', '2620:0:861:10b::/64', '2620:0:861:10c::/64', '2620:0:861:10d::/64', '2620:0:861:10e::/64', '2620:0:861:10f::/64', '2620:0:861:110::/64', '2620:0:861:111::/64', '2620:0:861:112::/64', '2620:0:861:113::/64', '2620:0:861:114::/64', '2620:0:861:115::/64', '2620:0:861:116::/64', '2620:0:861:117::/64', '2620:0:861:118::/64', '2620:0:861:119::/64', '2620:0:861:11a::/64', '2620:0:861:11c::/64', '2620:0:861:11d::/64', '2620:0:861:11e::/64', '2620:0:861:11f::/64', '2620:0:861:120::/64', '2620:0:861:121::/64', '2620:0:861:122::/64', '2620:0:861:123::/64', '2620:0:861:124::/64', '2620:0:861:125::/64', '2620:0:861:126::/64', '2620:0:861:127::/64', '2620:0:861:128::/64', '2620:0:861:129::/64', '2620:0:861:12a::/64', '2620:0:861:12b::/64', '2620:0:861:12c::/64', '2620:0:861:12d::/64', '2620:0:861:12e::/64', '2620:0:861:12f::/64', '2620:0:861:131::/64', '2620:0:861:132::/64', '2620:0:861:133::/64', '2620:0:861:134::/64', '2620:0:861:135::/64', '2620:0:861:136::/64', '2620:0:861:137::/64', '2620:0:861:138::/64', '2620:0:861:139::/64', '2620:0:861:13a::/64', '2620:0:861:13b::/64', '2620:0:861:13c::/64', '2620:0:861:13d::/64', '2620:0:861:13e::/64', '2620:0:861:13f::/64', '2620:0:861:140::/64', '2620:0:861:141::/64', '2620:0:861:142::/64', '2620:0:861:143::/64', '2620:0:861:144::/64', '2620:0:861:145::/64', '2620:0:861:1::/64', '2620:0:861:2::/64', '2620:0:861:300::/64', '2620:0:861:301::/116', '2620:0:861:302::/64', '2620:0:861:303::/116', '2620:0:861:304::/116', '2620:0:861:305::/64', '2620:0:861:3::/64', '2620:0:861:4::/64', '2620:0:861:babe::/64', '2620:0:861:babf::/116', '2620:0:861:cabe::/64', '2620:0:861:cabf::/116', '2620:0:861:ed1a::/64', '2620:0:863:101::/64', '2620:0:863:102::/64', '2620:0:863:103::/64', '2620:0:863:1::/64', '2620:0:863:2::/64', '2620:0:863:3::/64', '2620:0:863:ed1a::/64', '2a02:ec80:300:101::/64', '2a02:ec80:300:102::/64', '2a02:ec80:300:103::/64', '2a02:ec80:300:1::/64', '2a02:ec80:300:2::/64', '2a02:ec80:300:3::/64', '2a02:ec80:300:ed1a::/64', '2a02:ec80:600:101::/64', '2a02:ec80:600:102::/64', '2a02:ec80:600:1::/64', '2a02:ec80:600:2::/64', '2a02:ec80:600:ed1a::/64', '2a02:ec80:700:101::/64', '2a02:ec80:700:102::/64', '2a02:ec80:700:103::/64', '2a02:ec80:700:1::/64', '2a02:ec80:700:2::/64', '2a02:ec80:700:3::/64', '2a02:ec80:700:ed1a::/64'] + ensure => present
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul]
- Parameters differences:
--- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul].orig +++ File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul] - validate_cmd => /usr/sbin/visudo -cqf % - owner => root - ensure => present - group => root - mode => 0440 - require => Package[nagios-nrpe-server]
- Content differences:
--- /etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul.orig +++ /etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul @@ -1,3 +0,0 @@ -# This file is managed by Puppet! - -nagios ALL = (root) NOPASSWD: /usr/bin/openssl x509 -checkend 4687200 -in /etc/cfssl/signers/zuul/ca/zuul.pem
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service (prometheus-node-textfile-prometheus-check-dse-certificate-expiry.service)]
- Parameters differences:
- Content differences:
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_zuul]
- Content differences:
- File[/lib/systemd/system/cfssl-ocsprefresh-mlserve.service]
- File[/etc/cfssl/ssl/ocsp/OCSP_wikikube_front_proxy_pki1001_eqiad_wmnet.csr]
- Exec[Generate initial CRL for mlserve]
- Content differences:
- Content differences:
- Content differences:
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
- Systemd::Timer[cfssl-ocsprefresh-dse_front_proxy]
- File[/var/log/cfssl-ocsprefresh-discovery]
- Systemd::Timer::Job[prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/etc/cfssl/ocsp/mlserve_staging.ocsp]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube-certificate-expiry.service)]
- Cfssl::Config[wikikube]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_dse_front_proxy_pki1001_eqiad_wmnet.csr]
- Content differences:
- File[/etc/cfssl/signers/syslog/cfssl.conf]
- Systemd::Timer::Job[nrpe2nodexp-ferm_active]
- Content differences:
- File[/lib/systemd/system/nrpe2nodexp-check_certificate_expiry_mlserve.service]
- Exec[systemd daemon-reload for cfssl-ocsprefresh-debmonitor.timer (cfssl-ocsprefresh-debmonitor.timer)]
- Cfssl::Csr[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- File[/etc/cfssl/ssl/ocsp/OCSP_kafka_pki1001_eqiad_wmnet.pem]
- File[/etc/confd/conf.d/_etc_ferm_conf.d_00_defs_requestctl.toml]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service (prometheus-node-textfile-prometheus-check-mlserve_staging-certificate-expiry.service)]
- Service[cfssl-ocsprefresh-mlserve_staging.timer]
- File[/etc/cfssl/ocsp/mlserve_staging_front_proxy.ocsp]
- Sudo::User[nrpe-check_check_certificate_expiry_puppet_rsa]
- Content differences:
- File[/etc/cfssl/csr/OCSP_cassandra_pki1001_eqiad_wmnet.csr]
- Exec[Generate cert OCSP_mlserve_staging_front_proxy_pki1001_eqiad_wmnet refresh]
- Content differences:
- Content differences:
- File[/etc/sudoers.d/nrpe-check_check_certificate_expiry_kafka]
- Content differences:
- File[/etc/cfssl/signers/puppet_rsa/ca/puppet_rsa-key.pem]
- Nrpe::Monitor_service[check_certificate_expiry_kafka]
- Content differences:
- File[/etc/logrotate.d/prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry]
- File[/etc/apache2/conf-available/00-defaults.conf]
- Content differences:
- File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf]
- Exec[systemd daemon-reload for prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service (prometheus-node-textfile-prometheus-check-wikikube_front_proxy-certificate-expiry.service)]
- Content differences:
- File[/srv/cfssl/bundles/network_devices.pem]
- Cfssl::Signer[dse]
- Content differences:
- File[/etc/nagios/nrpe.d/check_check_certificate_expiry_wikikube_staging_front_proxy.cfg]
- Parameters differences: