--- Ferm::Service[exim].orig
+++ Ferm::Service[exim]
@@
- srange => @resolve((mx1001.wikimedia.org mx2001.wikimedia.org wiki-mail-eqiad.wikimedia.org wiki-mail-codfw.wikimedia.org mx-in1001.wikimedia.org mx-in2001.wikimedia.org))
+ srange => ['wiki-mail-eqiad.wikimedia.org', 'wiki-mail-codfw.wikimedia.org', 'mx-in1001.wikimedia.org', 'mx-in2001.wikimedia.org']
@@
- port => 3306
+ port => 3306
Ferm::Service[netbox-librenms-reports]
- Parameters differences:
--- Ferm::Service[netbox-librenms-reports].orig
+++ Ferm::Service[netbox-librenms-reports]
- desc =>
- port => 3306
- srange => @resolve((netbox1003.eqiad.wmnet netbox2003.codfw.wmnet))
- ensure => present
- unrestricted_access => False
- prio => 10
- notrack => True
- proto => tcp
- Ferm::Service[netmon_librenms]
- Parameters differences:
--- Ferm::Service[netmon_librenms].orig
+++ Ferm::Service[netmon_librenms]
+ desc =>
+ port => 3306
+ srange => ['netmon1003.wikimedia.org', 'netmon2002.wikimedia.org']
+ ensure => present
+ unrestricted_access => False
+ prio => 10
+ notrack => True
+ proto => tcp
- File[/etc/ferm/conf.d/10_netbox_librenms_reports]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_netbox_librenms_reports].orig
+++ File[/etc/ferm/conf.d/10_netbox_librenms_reports]
+ group => root
+ mode => 0400
+ notify => Service[ferm]
+ require => File[/etc/ferm/conf.d]
+ owner => root
+ ensure => present
+ tag => ferm
- Content differences:
--- /etc/ferm/conf.d/10_netbox_librenms_reports.orig
+++ /etc/ferm/conf.d/10_netbox_librenms_reports
@@ -0,0 +1,8 @@
+# Autogenerated by puppet. DO NOT EDIT BY HAND!
+#
+#
+&R_SERVICE(tcp, 3306, (10.192.0.54 10.64.0.103 2620:0:860:101:10:192:0:54 2620:0:861:101:10:64:0:103));
+
+
+
+&NO_TRACK(tcp, 3306);
- Firewall::Service[idp_staging]
- Parameters differences:
--- Firewall::Service[idp_staging].orig
+++ Firewall::Service[idp_staging]
+ desc =>
+ port => 3306
+ srange => ['idp-test1005.wikimedia.org', 'idp-test2005.wikimedia.org']
+ ensure => present
+ unrestricted_access => False
+ prio => 10
+ notrack => True
+ proto => tcp
- File[/etc/ferm/conf.d/10_netmon-librenms]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_netmon-librenms].orig
+++ File[/etc/ferm/conf.d/10_netmon-librenms]
- group => root
- mode => 0400
- notify => Service[ferm]
- require => File[/etc/ferm/conf.d]
- owner => root
- ensure => present
- tag => ferm
- Content differences:
--- /etc/ferm/conf.d/10_netmon-librenms.orig
+++ /etc/ferm/conf.d/10_netmon-librenms
@@ -1,8 +0,0 @@
-# Autogenerated by puppet. DO NOT EDIT BY HAND!
-#
-#
-&R_SERVICE(tcp, 3306, @resolve((netmon1003.wikimedia.org netmon2002.wikimedia.org)));
-
-
-
-&NO_TRACK(tcp, 3306);
- Firewall::Service[exim]
- Parameters differences:
--- Firewall::Service[exim].orig
+++ Firewall::Service[exim]
+ desc =>
+ port => 3306
+ srange => ['wiki-mail-eqiad.wikimedia.org', 'wiki-mail-codfw.wikimedia.org', 'mx-in1001.wikimedia.org', 'mx-in2001.wikimedia.org']
+ ensure => present
+ unrestricted_access => False
+ prio => 10
+ notrack => True
+ proto => tcp
- Ferm::Service[idp]
- Parameters differences:
--- Ferm::Service[idp].orig
+++ Ferm::Service[idp]
@@
- srange => @resolve((idp1005.wikimedia.org idp2005.wikimedia.org))
+ srange => ['idp1005.wikimedia.org', 'idp2005.wikimedia.org']
@@
- port => 3306
+ port => 3306
- File[/etc/ferm/conf.d/10_netbox-librenms-reports]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_netbox-librenms-reports].orig
+++ File[/etc/ferm/conf.d/10_netbox-librenms-reports]
- group => root
- mode => 0400
- notify => Service[ferm]
- require => File[/etc/ferm/conf.d]
- owner => root
- ensure => present
- tag => ferm
- Content differences:
--- /etc/ferm/conf.d/10_netbox-librenms-reports.orig
+++ /etc/ferm/conf.d/10_netbox-librenms-reports
@@ -1,8 +0,0 @@
-# Autogenerated by puppet. DO NOT EDIT BY HAND!
-#
-#
-&R_SERVICE(tcp, 3306, @resolve((netbox1003.eqiad.wmnet netbox2003.codfw.wmnet)));
-
-
-
-&NO_TRACK(tcp, 3306);
- Ferm::Service[netbox_librenms_reports]
- Parameters differences:
--- Ferm::Service[netbox_librenms_reports].orig
+++ Ferm::Service[netbox_librenms_reports]
+ desc =>
+ port => 3306
+ srange => ['netbox1003.eqiad.wmnet', 'netbox2003.codfw.wmnet']
+ ensure => present
+ unrestricted_access => False
+ prio => 10
+ notrack => True
+ proto => tcp
- File[/etc/ferm/conf.d/10_idp_staging]
- Content differences:
--- /etc/ferm/conf.d/10_idp_staging.orig
+++ /etc/ferm/conf.d/10_idp_staging
@@ -1,7 +1,7 @@
# Autogenerated by puppet. DO NOT EDIT BY HAND!
#
#
-&R_SERVICE(tcp, 3306, @resolve((idp-test1005.wikimedia.org idp-test2005.wikimedia.org)));
+&R_SERVICE(tcp, 3306, (208.80.153.76 208.80.154.8 2620:0:860:3:208:80:153:76 2620:0:861:1:208:80:154:8));
- Firewall::Service[idp]
- Parameters differences:
--- Firewall::Service[idp].orig
+++ Firewall::Service[idp]
+ desc =>
+ port => 3306
+ srange => ['idp1005.wikimedia.org', 'idp2005.wikimedia.org']
+ ensure => present
+ unrestricted_access => False
+ prio => 10
+ notrack => True
+ proto => tcp
- Ferm::Service[netmon-librenms]
- Parameters differences:
--- Ferm::Service[netmon-librenms].orig
+++ Ferm::Service[netmon-librenms]
- desc =>
- port => 3306
- srange => @resolve((netmon1003.wikimedia.org netmon2002.wikimedia.org))
- ensure => present
- unrestricted_access => False
- prio => 10
- notrack => True
- proto => tcp