--- Class[Profile::Firewall::Nftables_base_sets].orig
+++ Class[Profile::Firewall::Nftables_base_sets]
+ kafkamon_hosts => ['10.64.32.11', '2620:0:861:103:10:64:32:11', '10.192.16.139', '2620:0:860:102:10:192:16:139']
+ install_hosts => {'eqiad': '208.80.154.134', 'codfw': '208.80.153.70', 'esams': '185.15.59.101', 'ulsfo': '198.35.26.98', 'eqsin': '103.102.166.104', 'drmrs': '185.15.58.7', 'magru': '195.200.68.100'}
+ zookeeper_flink_hosts => ['10.64.16.9', '2620:0:861:102:10:64:16:9', '10.64.0.8', '2620:0:861:101:10:64:0:8', '10.64.32.41', '2620:0:861:103:10:64:32:41', '10.192.16.227', '2620:0:860:102:10:192:16:227', '10.192.32.179', '2620:0:860:103:10:192:32:179', '10.192.48.219', '2620:0:860:104:10:192:48:219']
+ kafka_brokers_jumbo => ['10.64.130.10', '2620:0:861:109:10:64:130:10', '10.64.131.16', '2620:0:861:10a:10:64:131:16', '10.64.132.21', '2620:0:861:10b:10:64:132:21', '10.64.134.9', '2620:0:861:10d:10:64:134:9', '10.64.135.16', '2620:0:861:10e:10:64:135:16', '10.64.136.11', '2620:0:861:10f:10:64:136:11', '10.64.154.15', '2620:0:861:122:10:64:154:15', '10.64.160.16', '2620:0:861:128:10:64:160:16', '10.64.0.126', '2620:0:861:101:10:64:0:126']
+ monitoring_hosts => ['208.80.154.78', '2620:0:861:3:208:80:154:78', '208.80.153.42', '2620:0:860:2:208:80:153:42']
+ lb_health_checks => ['10.64.0.136', '10.64.16.60', '10.64.158.19', '10.64.166.19', '10.64.133.19', '10.64.141.19', '10.64.169.19', '10.64.171.19', '10.64.173.19', '10.64.175.19', '10.64.177.19', '10.64.179.19', '10.64.181.19', '10.64.183.19', '10.64.185.19', '10.64.187.19', '10.64.189.19', '10.64.48.72', '10.64.37.17', '10.64.1.17', '10.64.17.17', '10.64.33.17', '10.64.130.20', '10.64.131.20', '10.64.132.20', '10.64.134.20', '10.64.135.20', '10.64.136.20', '10.64.158.20', '10.64.166.20', '10.64.133.20', '10.64.141.20', '10.64.169.20', '10.64.171.20', '10.64.173.20', '10.64.175.20', '10.64.177.20', '10.64.179.20', '10.64.181.20', '10.64.183.20', '10.64.185.20', '10.64.187.20', '10.64.189.20', '2620:0:861:101::/64', '2620:0:861:102::/64', '2620:0:861:103::/64', '2620:0:861:107::/64', '2620:0:861:109::/64', '2620:0:861:10a::/64', '2620:0:861:10b::/64', '2620:0:861:10d::/64', '2620:0:861:10e::/64', '2620:0:861:10f::/64', '2620:0:861:119::/64', '2620:0:861:10c::/64', '2620:0:861:113::/64', '2620:0:861:119::/64', '2620:0:861:131::/64', '2620:0:861:133::/64', '2620:0:861:135::/64', '2620:0:861:137::/64', '2620:0:861:139::/64', '2620:0:861:13b::/64', '2620:0:861:13d::/64', '2620:0:861:13f::/64', '2620:0:861:142::/64', '2620:0:861:144::/64', '10.192.23.8', '10.192.0.29', '10.192.17.8', '10.192.33.8', '10.192.49.8', '10.192.23.2', '10.192.5.2', '10.192.6.2', '10.192.7.2', '10.192.8.2', '10.192.9.2', '10.192.10.2', '10.192.11.2', '10.192.12.2', '10.192.13.2', '10.192.14.2', '10.192.15.2', '10.192.21.2', '10.192.22.2', '10.192.4.2', '10.192.26.2', '10.192.27.2', '10.192.28.2', '10.192.29.2', '10.192.30.2', '10.192.31.2', '10.192.36.2', '10.192.37.2', '10.192.38.2', '10.192.39.2', '10.192.40.2', '10.192.41.2', '10.192.42.2', '10.192.43.2', '10.192.11.8', '10.192.16.140', '10.192.1.8', '10.192.33.9', '10.192.49.9', '10.192.23.3', '10.192.5.3', '10.192.6.3', '10.192.7.3', '10.192.8.3', '10.192.9.3', '10.192.10.3', '10.192.11.3', '10.192.12.3', '10.192.13.3', '10.192.14.3', '10.192.15.3', '10.192.21.3', '10.192.22.3', '10.192.4.3', '10.192.26.3', '10.192.27.3', '10.192.28.3', '10.192.29.3', '10.192.30.3', '10.192.31.3', '10.192.36.3', '10.192.37.3', '10.192.38.3', '10.192.39.4', '10.192.40.3', '10.192.41.3', '10.192.42.3', '10.192.43.3', '10.192.32.14', '10.192.1.9', '10.192.17.9', '10.192.49.10', '10.192.23.4', '10.192.5.4', '10.192.6.4', '10.192.7.4', '10.192.8.4', '10.192.9.4', '10.192.10.4', '10.192.11.4', '10.192.12.4', '10.192.13.4', '10.192.14.4', '10.192.15.4', '10.192.21.4', '10.192.22.4', '10.192.4.5', '10.192.26.5', '10.192.27.5', '10.192.28.5', '10.192.29.5', '10.192.30.5', '10.192.31.5', '10.192.36.5', '10.192.37.5', '10.192.38.5', '10.192.39.6', '10.192.40.5', '10.192.41.5', '10.192.42.5', '10.192.43.5', '10.192.48.213', '10.192.1.13', '10.192.17.10', '10.192.33.10', '10.192.23.5', '10.192.5.8', '10.192.6.5', '10.192.7.5', '10.192.8.5', '10.192.9.5', '10.192.10.5', '10.192.11.5', '10.192.12.5', '10.192.13.5', '10.192.14.5', '10.192.15.5', '10.192.21.5', '10.192.22.5', '10.192.4.5', '10.192.26.5', '10.192.27.5', '10.192.28.5', '10.192.29.5', '10.192.30.5', '10.192.31.5', '10.192.36.5', '10.192.37.5', '10.192.38.5', '10.192.39.6', '10.192.40.5', '10.192.41.5', '10.192.42.5', '10.192.43.5', '2620:0:860:101::/64', '2620:0:860:102::/64', '2620:0:860:103::/64', '2620:0:860:104::/64', '10.80.0.3', '10.80.1.8', '10.80.1.14', '10.80.0.9', '10.80.0.2', '10.80.1.10', '2a02:ec80:300:101::/64', '2a02:ec80:300:102::/64', '10.128.1.18', '10.128.0.9', '10.128.1.11', '2620:0:863:101::/64', '2620:0:863:102::/64', '10.132.0.39', '10.132.0.6', '10.132.0.7', '2001:df2:e500:101::/64', '10.136.0.16', '10.136.1.19', '10.136.1.15', '10.136.0.19', '10.136.0.17', '10.136.1.20', '2a02:ec80:600:101::/64', '2a02:ec80:600:102::/64', '10.140.0.13', '10.140.1.2', '10.140.1.14', '10.140.0.2', '10.140.0.14', '10.140.1.3', '2a02:ec80:700:101::/64', '2a02:ec80:700:102::/64']
+ labstore_hosts => ['208.80.154.142', '2620:0:861:2:208:80:154:142', '208.80.154.71', '2620:0:861:3:208:80:154:71']
+ druid_public_hosts => ['10.64.131.9', '2620:0:861:10a:10:64:131:9', '10.64.132.12', '2620:0:861:10b:10:64:132:12', '10.64.135.9', '2620:0:861:10e:10:64:135:9', '10.64.32.101', '2620:0:861:103:10:64:32:101', '10.64.48.185', '2620:0:861:107:10:64:48:185']
+ kafka_brokers_logging => ['10.64.16.205', '2620:0:861:102:10:64:16:205', '10.64.133.11', '2620:0:861:10c:10:64:133:11', '10.64.183.12', '2620:0:861:13d:10:64:183:12', '10.64.131.13', '2620:0:861:10a:10:64:131:13', '10.64.135.13', '2620:0:861:10e:10:64:135:13', '10.192.23.29', '2620:0:860:113:10:192:23:29', '10.192.11.28', '2620:0:860:10c:10:192:11:28', '10.192.26.22', '2620:0:860:105:10:192:26:22', '10.192.11.27', '2620:0:860:10c:10:192:11:27', '10.192.39.25', '2620:0:860:11e:10:192:39:25']
+ cumin_masters => ['10.64.16.154', '2620:0:861:102:10:64:16:154', '10.192.32.49', '2620:0:860:103:10:192:32:49']
+ deployment_hosts => ['10.64.16.93', '2620:0:861:102:10:64:16:93', '10.192.32.7', '2620:0:860:103:10:192:32:7']
+ prometheus_nodes => ['prometheus2005.codfw.wmnet', 'prometheus2006.codfw.wmnet', 'prometheus2007.codfw.wmnet', 'prometheus2008.codfw.wmnet']
+ bastion_hosts => ['208.80.154.7', '2620:0:861:1:208:80:154:7', '208.80.153.110', '2a02:ec80:300:3:185:15:59:99', '185.15.59.99', '2620:0:860:4:208:80:153:110', '198.35.26.104', '2620:0:863:3:198:35:26:104', '103.102.166.103', '2001:df2:e500:3:103:102:166:103', '185.15.58.6', '2a02:ec80:600:1:185:15:58:6', '195.200.68.99', '2a02:ec80:700:3:195:200:68:99']
+ mysql_root_clients => ['10.64.16.90', '10.192.16.191', '10.64.16.154', '10.192.32.49', '208.80.154.9', '10.64.0.20']
+ install_hosts6 => {'eqiad': '2620:0:861:2:208:80:154:134', 'codfw': '2620:0:860:3:208:80:153:70', 'esams': '2a02:ec80:300:3:185:15:59:101', 'ulsfo': '2620:0:863:3:198:35:26:98', 'eqsin': '2001:df2:e500:3:103:102:166:104', 'drmrs': '2a02:ec80:600:1:185:15:58:7', 'magru': '2a02:ec80:700:3:195:200:68:100'}
+ cache_hosts => ['10.64.0.79', '2620:0:861:101:10:64:0:79', '10.64.0.229', '2620:0:861:101:10:64:0:229', '10.64.0.14', '2620:0:861:101:10:64:0:14', '10.64.0.51', '2620:0:861:101:10:64:0:51', '10.64.16.241', '2620:0:861:102:10:64:16:241', '10.64.16.94', '2620:0:861:102:10:64:16:94', '10.64.16.95', '2620:0:861:102:10:64:16:95', '10.64.16.240', '2620:0:861:102:10:64:16:240', '10.64.32.14', '2620:0:861:103:10:64:32:14', '10.64.32.60', '2620:0:861:103:10:64:32:60', '10.64.32.15', '2620:0:861:103:10:64:32:15', '10.64.32.65', '2620:0:861:103:10:64:32:65', '10.64.48.16', '2620:0:861:107:10:64:48:16', '10.64.48.41', '2620:0:861:107:10:64:48:41', '10.64.48.27', '2620:0:861:107:10:64:48:27', '10.64.48.28', '2620:0:861:107:10:64:48:28', '10.192.23.26', '2620:0:860:113:10:192:23:26', '10.192.6.20', '2620:0:860:107:10:192:6:20', '10.192.12.35', '2620:0:860:10d:10:192:12:35', '10.192.14.25', '2620:0:860:10f:10:192:14:25', '10.192.4.22', '2620:0:860:100:10:192:4:22', '10.192.29.26', '2620:0:860:116:10:192:29:26', '10.192.30.29', '2620:0:860:119:10:192:30:29', '10.192.36.19', '2620:0:860:11b:10:192:36:19', '10.192.40.25', '2620:0:860:11f:10:192:40:25', '10.192.41.21', '2620:0:860:120:10:192:41:21', '10.192.56.3', '2620:0:860:12b:10:192:56:3', '10.192.56.4', '2620:0:860:12b:10:192:56:4', '10.192.57.3', '2620:0:860:12c:10:192:57:3', '10.192.58.2', '2620:0:860:12d:10:192:58:2', '10.192.58.3', '2620:0:860:12d:10:192:58:3', '10.192.59.2', '2620:0:860:12e:10:192:59:2', '10.80.0.14', '2a02:ec80:300:101:10:80:0:14', '10.80.1.11', '2a02:ec80:300:102:10:80:1:11', '10.80.0.13', '2a02:ec80:300:101:10:80:0:13', '10.80.1.9', '2a02:ec80:300:102:10:80:1:9', '10.80.0.12', '2a02:ec80:300:101:10:80:0:12', '10.80.1.7', '2a02:ec80:300:102:10:80:1:7', '10.80.0.11', '2a02:ec80:300:101:10:80:0:11', '10.80.1.6', '2a02:ec80:300:102:10:80:1:6', '10.80.0.10', '2a02:ec80:300:101:10:80:0:10', '10.80.1.5', '2a02:ec80:300:102:10:80:1:5', '10.80.0.8', '2a02:ec80:300:101:10:80:0:8', '10.80.1.4', '2a02:ec80:300:102:10:80:1:4', '10.80.0.7', '2a02:ec80:300:101:10:80:0:7', '10.80.1.3', '2a02:ec80:300:102:10:80:1:3', '10.80.0.6', '2a02:ec80:300:101:10:80:0:6', '10.80.1.2', '2a02:ec80:300:102:10:80:1:2', '10.128.0.19', '2620:0:863:101:10:128:0:19', '10.128.1.27', '2620:0:863:102:10:128:1:27', '10.128.0.22', '2620:0:863:101:10:128:0:22', '10.128.1.28', '2620:0:863:102:10:128:1:28', '10.128.0.25', '2620:0:863:101:10:128:0:25', '10.128.1.29', '2620:0:863:102:10:128:1:29', '10.128.0.26', '2620:0:863:101:10:128:0:26', '10.128.1.31', '2620:0:863:102:10:128:1:31', '10.128.0.14', '2620:0:863:101:10:128:0:14', '10.128.1.35', '2620:0:863:102:10:128:1:35', '10.128.0.21', '2620:0:863:101:10:128:0:21', '10.128.1.36', '2620:0:863:102:10:128:1:36', '10.128.0.24', '2620:0:863:101:10:128:0:24', '10.128.1.10', '2620:0:863:102:10:128:1:10', '10.128.0.37', '2620:0:863:101:10:128:0:37', '10.128.1.12', '2620:0:863:102:10:128:1:12', '10.132.0.17', '2001:df2:e500:101:10:132:0:17', '10.132.0.18', '2001:df2:e500:101:10:132:0:18', '10.132.0.19', '2001:df2:e500:101:10:132:0:19', '10.132.0.24', '2001:df2:e500:101:10:132:0:24', '10.132.0.29', '2001:df2:e500:101:10:132:0:29', '10.132.0.30', '2001:df2:e500:101:10:132:0:30', '10.132.0.34', '2001:df2:e500:101:10:132:0:34', '10.132.0.35', '2001:df2:e500:101:10:132:0:35', '10.132.0.36', '2001:df2:e500:101:10:132:0:36', '10.132.0.37', '2001:df2:e500:101:10:132:0:37', '10.132.0.38', '2001:df2:e500:101:10:132:0:38', '10.132.0.25', '2001:df2:e500:101:10:132:0:25', '10.132.0.26', '2001:df2:e500:101:10:132:0:26', '10.132.0.27', '2001:df2:e500:101:10:132:0:27', '10.132.0.28', '2001:df2:e500:101:10:132:0:28', '10.132.0.16', '2001:df2:e500:101:10:132:0:16', '10.136.0.6', '2a02:ec80:600:101:10:136:0:6', '10.136.1.6', '2a02:ec80:600:102:10:136:1:6', '10.136.0.7', '2a02:ec80:600:101:10:136:0:7', '10.136.1.7', '2a02:ec80:600:102:10:136:1:7', '10.136.0.8', '2a02:ec80:600:101:10:136:0:8', '10.136.1.8', '2a02:ec80:600:102:10:136:1:8', '10.136.0.9', '2a02:ec80:600:101:10:136:0:9', '10.136.1.9', '2a02:ec80:600:102:10:136:1:9', '10.136.0.10', '2a02:ec80:600:101:10:136:0:10', '10.136.1.10', '2a02:ec80:600:102:10:136:1:10', '10.136.0.11', '2a02:ec80:600:101:10:136:0:11', '10.136.1.11', '2a02:ec80:600:102:10:136:1:11', '10.136.0.12', '2a02:ec80:600:101:10:136:0:12', '10.136.1.12', '2a02:ec80:600:102:10:136:1:12', '10.136.0.13', '2a02:ec80:600:101:10:136:0:13', '10.136.1.13', '2a02:ec80:600:102:10:136:1:13', '10.140.0.3', '2a02:ec80:700:101:10:140:0:3', '10.140.1.4', '2a02:ec80:700:102:10:140:1:4', '10.140.0.4', '2a02:ec80:700:101:10:140:0:4', '10.140.1.5', '2a02:ec80:700:102:10:140:1:5', '10.140.0.5', '2a02:ec80:700:101:10:140:0:5', '10.140.1.6', '2a02:ec80:700:102:10:140:1:6', '10.140.0.6', '2a02:ec80:700:101:10:140:0:6', '10.140.1.7', '2a02:ec80:700:102:10:140:1:7', '10.140.0.7', '2a02:ec80:700:101:10:140:0:7', '10.140.1.8', '2a02:ec80:700:102:10:140:1:8', '10.140.0.8', '2a02:ec80:700:101:10:140:0:8', '10.140.1.9', '2a02:ec80:700:102:10:140:1:9', '10.140.0.9', '2a02:ec80:700:101:10:140:0:9', '10.140.1.10', '2a02:ec80:700:102:10:140:1:10', '10.140.0.10', '2a02:ec80:700:101:10:140:0:10', '10.140.1.11', '2a02:ec80:700:102:10:140:1:11']
+ zookeeper_hosts_main => ['10.64.0.207', '2620:0:861:101:10:64:0:207', '10.64.16.110', '2620:0:861:102:10:64:16:110', '10.64.48.154', '2620:0:861:107:10:64:48:154', '10.192.16.45', '2620:0:860:102:10:192:16:45', '10.192.32.52', '2620:0:860:103:10:192:32:52', '10.192.48.59', '2620:0:860:104:10:192:48:59']
+ kafka_brokers_main => ['10.192.5.9', '2620:0:860:106:10:192:5:9', '10.192.22.6', '2620:0:860:112:10:192:22:6', '10.192.32.4', '2620:0:860:103:10:192:32:4', '10.192.48.33', '2620:0:860:104:10:192:48:33', '10.192.48.35', '2620:0:860:104:10:192:48:35', '10.64.0.101', '2620:0:861:101:10:64:0:101', '10.64.16.30', '2620:0:861:102:10:64:16:30', '10.64.32.45', '2620:0:861:103:10:64:32:45', '10.64.48.37', '2620:0:861:107:10:64:48:37', '10.64.152.5', '2620:0:861:120:10:64:152:5']
File[/etc/nftables/100_base_puppet.nft]
- Parameters differences:
--- File[/etc/nftables/100_base_puppet.nft].orig
+++ File[/etc/nftables/100_base_puppet.nft]
+ tag => nft
+ require => File[/etc/nftables/]
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/100_base_puppet.nft.orig
+++ /etc/nftables/100_base_puppet.nft
@@ -0,0 +1,45 @@
+# SPDX-License-Identifier: Apache-2.0
+table inet base {
+
+ # Include all Puppet-managed sets
+ include "/etc/nftables/sets/*.nft"
+
+ chain prerouting {
+ type filter hook prerouting priority -300;
+
+ # Include all Puppet-managed rules targetting prerouting chain
+ include "/etc/nftables/prerouting/*.nft"
+ # Include all Puppet-managed exceptions from connection tracking
+ include "/etc/nftables/notrack/*.nft"
+ }
+
+ chain input {
+ type filter hook input priority 0 ; policy drop;
+
+ ct state related,established accept
+ iifname "lo" accept
+ pkttype multicast accept
+ meta l4proto ipv6-icmp accept
+ ip protocol icmp accept
+
+ # Include all Puppet-managed service definitions for incoming traffic
+ include "/etc/nftables/input/*.nft"
+ }
+
+ chain output {
+ type filter hook output priority 0 ; policy accept;
+
+ # Include any Puppet-managed client definitions filtering outbound traffic
+ include "/etc/nftables/output/*.nft"
+ }
+
+ chain postrouting {
+ type filter hook postrouting priority 0 ;
+
+ # Include any Puppet-managed custom rules to mark DSCP bits
+ include "/etc/nftables/postrouting/*.nft"
+ # Anything else mark as CS0 / default priority class
+ ip dscp != cs0 ip dscp set cs0 counter
+ ip6 dscp != cs0 ip6 dscp set cs0 counter
+ }
+}
- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.timer (wmf_auto_restart_ulogd2.timer)]
- Parameters differences:
--- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.timer (wmf_auto_restart_ulogd2.timer)].orig
+++ Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.timer (wmf_auto_restart_ulogd2.timer)]
- command => /bin/systemctl daemon-reload
- before => ['Service[wmf_auto_restart_ulogd2.timer]']
- refreshonly => True
- Class[Profile::Apt]
- Parameters differences:
--- Class[Profile::Apt].orig
+++ Class[Profile::Apt]
@@
- before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[starship]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[linux-sysctl-defaults]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[perccli]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[ulogd2]', 'Package[conntrack]', 'Package[wmf-mariadb1011]', 'Package[percona-toolkit]', 'Package[grc]', 'Package[mariadb-backup]', 'Package[python3-wmfmariadbpy]', 'Package[wmfmariadbpy-common]', 'Package[monitoring-plugins-contrib]', 'Package[ruby-concurrent]', 'Package[ruby]', 'Package[libruby]', 'Package[puppet-agent]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[prometheus-mysqld-exporter]']
+ before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[starship]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[linux-sysctl-defaults]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[perccli]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[nftables]', 'Package[conntrack]', 'Package[wmf-mariadb1011]', 'Package[percona-toolkit]', 'Package[grc]', 'Package[mariadb-backup]', 'Package[python3-wmfmariadbpy]', 'Package[wmfmariadbpy-common]', 'Package[monitoring-plugins-contrib]', 'Package[ruby-concurrent]', 'Package[ruby]', 'Package[libruby]', 'Package[puppet-agent]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[prometheus-mysqld-exporter]']
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft.orig
+++ /etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft
@@ -0,0 +1,189 @@
+# Autogenerated by puppet
+set PRODUCTION_NETWORKS_ipv4 {
+ type ipv4_addr
+ flags interval
+ auto-merge
+ elements = { 10.128.0.0/24,
+ 10.128.1.0/24,
+ 10.128.2.0/24,
+ 10.132.0.0/24,
+ 10.132.2.0/24,
+ 10.136.0.0/24,
+ 10.136.1.0/24,
+ 10.140.0.0/24,
+ 10.140.1.0/24,
+ 10.140.2.0/24,
+ 10.192.0.0/22,
+ 10.192.10.0/24,
+ 10.192.11.0/24,
+ 10.192.12.0/24,
+ 10.192.13.0/24,
+ 10.192.14.0/24,
+ 10.192.15.0/24,
+ 10.192.16.0/22,
+ 10.192.20.0/24,
+ 10.192.21.0/24,
+ 10.192.22.0/24,
+ 10.192.23.0/24,
+ 10.192.24.0/23,
+ 10.192.26.0/24,
+ 10.192.27.0/24,
+ 10.192.28.0/24,
+ 10.192.29.0/24,
+ 10.192.30.0/24,
+ 10.192.31.0/24,
+ 10.192.32.0/22,
+ 10.192.36.0/24,
+ 10.192.37.0/24,
+ 10.192.38.0/24,
+ 10.192.39.0/24,
+ 10.192.4.0/24,
+ 10.192.40.0/24,
+ 10.192.41.0/24,
+ 10.192.42.0/24,
+ 10.192.43.0/24,
+ 10.192.44.0/24,
+ 10.192.45.0/24,
+ 10.192.46.0/24,
+ 10.192.47.0/24,
+ 10.192.48.0/22,
+ 10.192.5.0/24,
+ 10.192.52.0/24,
+ 10.192.56.0/24,
+ 10.192.57.0/24,
+ 10.192.58.0/24,
+ 10.192.59.0/24,
+ 10.192.6.0/24,
+ 10.192.64.0/21,
+ 10.192.7.0/24,
+ 10.192.72.0/24,
+ 10.192.76.0/24,
+ 10.192.8.0/24,
+ 10.192.80.0/20,
+ 10.192.9.0/24,
+ 10.192.96.0/21,
+ 10.194.0.0/20,
+ 10.194.128.0/17,
+ 10.194.16.0/21,
+ 10.194.61.0/24,
+ 10.194.62.0/23,
+ 10.194.64.0/20,
+ 10.194.80.0/21,
+ 10.2.1.0/24,
+ 10.2.2.0/24,
+ 10.2.3.0/24,
+ 10.2.4.0/24,
+ 10.2.5.0/24,
+ 10.2.6.0/24,
+ 10.2.7.0/24,
+ 10.64.0.0/22,
+ 10.64.130.0/24,
+ 10.64.131.0/24,
+ 10.64.132.0/24,
+ 10.64.133.0/24,
+ 10.64.134.0/24,
+ 10.64.135.0/24,
+ 10.64.136.0/24,
+ 10.64.137.0/24,
+ 10.64.138.0/24,
+ 10.64.139.0/24,
+ 10.64.140.0/24,
+ 10.64.141.0/24,
+ 10.64.142.0/24,
+ 10.64.143.0/24,
+ 10.64.144.0/24,
+ 10.64.145.0/24,
+ 10.64.148.0/24,
+ 10.64.149.0/24,
+ 10.64.150.0/24,
+ 10.64.151.0/24,
+ 10.64.152.0/24,
+ 10.64.153.0/24,
+ 10.64.154.0/24,
+ 10.64.155.0/24,
+ 10.64.156.0/24,
+ 10.64.157.0/24,
+ 10.64.158.0/24,
+ 10.64.159.0/24,
+ 10.64.16.0/22,
+ 10.64.160.0/24,
+ 10.64.161.0/24,
+ 10.64.162.0/24,
+ 10.64.163.0/24,
+ 10.64.164.0/24,
+ 10.64.165.0/24,
+ 10.64.166.0/24,
+ 10.64.167.0/24,
+ 10.64.169.0/24,
+ 10.64.170.0/24,
+ 10.64.171.0/24,
+ 10.64.172.0/24,
+ 10.64.173.0/24,
+ 10.64.174.0/24,
+ 10.64.175.0/24,
+ 10.64.176.0/24,
+ 10.64.177.0/24,
+ 10.64.178.0/24,
+ 10.64.179.0/24,
+ 10.64.180.0/24,
+ 10.64.181.0/24,
+ 10.64.182.0/24,
+ 10.64.183.0/24,
+ 10.64.184.0/24,
+ 10.64.185.0/24,
+ 10.64.186.0/24,
+ 10.64.187.0/24,
+ 10.64.188.0/24,
+ 10.64.189.0/24,
+ 10.64.190.0/24,
+ 10.64.20.0/24,
+ 10.64.21.0/24,
+ 10.64.24.0/23,
+ 10.64.32.0/22,
+ 10.64.36.0/24,
+ 10.64.48.0/22,
+ 10.64.5.0/24,
+ 10.64.53.0/24,
+ 10.64.64.0/21,
+ 10.64.72.0/24,
+ 10.64.76.0/24,
+ 10.67.0.0/20,
+ 10.67.128.0/17,
+ 10.67.16.0/21,
+ 10.67.24.0/21,
+ 10.67.32.0/20,
+ 10.67.64.0/20,
+ 10.67.80.0/21,
+ 10.80.0.0/24,
+ 10.80.1.0/24,
+ 10.80.2.0/24,
+ 103.102.166.0/28,
+ 103.102.166.224/27,
+ 103.102.166.96/27,
+ 185.15.58.0/27,
+ 185.15.58.224/27,
+ 185.15.58.32/27,
+ 185.15.59.0/27,
+ 185.15.59.224/27,
+ 185.15.59.32/27,
+ 185.15.59.96/27,
+ 195.200.68.0/27,
+ 195.200.68.224/27,
+ 195.200.68.32/27,
+ 195.200.68.96/27,
+ 198.35.26.0/27,
+ 198.35.26.32/27,
+ 198.35.26.96/27,
+ 208.80.152.128/27,
+ 208.80.153.0/27,
+ 208.80.153.224/27,
+ 208.80.153.32/27,
+ 208.80.153.64/27,
+ 208.80.153.96/27,
+ 208.80.154.0/26,
+ 208.80.154.128/26,
+ 208.80.154.224/27,
+ 208.80.154.64/26,
+ 208.80.155.96/27
+ }
+}
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft
@@ -0,0 +1,13 @@
+# Autogenerated by puppet
+set SANDBOX_NETWORKS_ipv6 {
+ type ipv6_addr
+ flags interval
+ auto-merge
+ elements = { 2001:df2:e500:202::/64,
+ 2620:0:860:201::/64,
+ 2620:0:861:202::/64,
+ 2620:0:863:201::/64,
+ 2a02:ec80:300:202::/64,
+ 2a02:ec80:700:201::/64
+ }
+}
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft.orig
+++ /etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft
@@ -0,0 +1,27 @@
+# Autogenerated by puppet
+set CLOUD_NETWORKS_ipv4 {
+ type ipv4_addr
+ flags interval
+ auto-merge
+ elements = { 172.16.0.0/21,
+ 172.16.128.0/24,
+ 172.16.129.0/24,
+ 172.16.130.0/24,
+ 172.16.131.0/24,
+ 172.16.16.0/21,
+ 172.16.24.0/24,
+ 172.16.8.0/21,
+ 172.20.1.0/24,
+ 172.20.2.0/24,
+ 172.20.254.0/24,
+ 172.20.255.0/24,
+ 172.20.3.0/24,
+ 172.20.4.0/24,
+ 172.20.5.0/24,
+ 185.15.56.0/25,
+ 185.15.56.160/28,
+ 185.15.57.0/29,
+ 185.15.57.16/29,
+ 185.15.57.24/29
+ }
+}
- Class[Adduser]
- Parameters differences:
--- Class[Adduser].orig
+++ Class[Adduser]
@@
- before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[starship]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[linux-sysctl-defaults]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[perccli]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[ulogd2]', 'Package[conntrack]', 'Package[wmf-mariadb1011]', 'Package[percona-toolkit]', 'Package[grc]', 'Package[mariadb-backup]', 'Package[python3-wmfmariadbpy]', 'Package[wmfmariadbpy-common]', 'Package[monitoring-plugins-contrib]', 'Package[ruby-concurrent]', 'Package[ruby]', 'Package[libruby]', 'Package[puppet-agent]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[prometheus-mysqld-exporter]']
+ before => ['Package[puppet]', 'Package[facter]', 'Package[augeas-tools]', 'Package[virt-what]', 'Package[puppet-module-puppetlabs-augeas-core]', 'Package[python3-prometheus-client]', 'Package[python3-yaml]', 'Package[ruby-net-ssh]', 'Package[openssl]', 'Package[ssl-cert]', 'Package[ca-certificates]', 'Package[wmf-certificates]', 'Package[ntp]', 'Package[systemd-timesyncd]', 'Package[exim4-config]', 'Package[exim4-daemon-light]', 'Package[logrotate]', 'Package[prometheus-node-exporter]', 'Package[bsdutils]', 'Package[smartmontools]', 'Package[rsyslog]', 'Package[rsyslog-openssl]', 'Package[cadvisor]', 'Package[acct]', 'Package[byobu]', 'Package[colordiff]', 'Package[curl]', 'Package[debian-goodies]', 'Package[ethtool]', 'Package[gdb]', 'Package[gdisk]', 'Package[git]', 'Package[htop]', 'Package[httpry]', 'Package[iotop]', 'Package[iperf]', 'Package[jq]', 'Package[libtemplate-perl]', 'Package[lldpd]', 'Package[lshw]', 'Package[molly-guard]', 'Package[moreutils]', 'Package[net-tools]', 'Package[numactl]', 'Package[ncdu]', 'Package[ngrep]', 'Package[pigz]', 'Package[psmisc]', 'Package[pv]', 'Package[python3]', 'Package[screen]', 'Package[strace]', 'Package[sysstat]', 'Package[tcpdump]', 'Package[tmux]', 'Package[tree]', 'Package[vim]', 'Package[vim-addon-manager]', 'Package[vim-scripts]', 'Package[wipe]', 'Package[xfsprogs]', 'Package[zsh]', 'Package[icdiff]', 'Package[linux-perf]', 'Package[bsd-mailx]', 'Package[ack]', 'Package[netcat-openbsd]', 'Package[tshark]', 'Package[fzf]', 'Package[ripgrep]', 'Package[fd-find]', 'Package[kitty-terminfo]', 'Package[mtr-tiny]', 'Package[bat]', 'Package[efibootmgr]', 'Package[bind9-dnsutils]', 'Package[tzdata]', 'Package[python3-wmflib]', 'Package[starship]', 'Package[ruby-sorted-set]', 'Package[btop]', 'Package[linux-sysctl-defaults]', 'Package[apport]', 'Package[command-not-found]', 'Package[command-not-found-data]', 'Package[ecryptfs-utils]', 'Package[mlocate]', 'Package[os-prober]', 'Package[python3-apport]', 'Package[wpasupplicant]', 'Package[apt-listchanges]', 'Package[isc-dhcp-client]', 'Package[rasdaemon]', 'Package[openssh-client]', 'Package[openssh-server]', 'Package[debdeploy-client]', 'Package[python3-dateutil]', 'Package[sudo]', 'Package[golang-cfssl]', 'Package[debmonitor-client]', 'Package[perccli]', 'Package[nagios-nrpe-server]', 'Package[monitoring-plugins]', 'Package[monitoring-plugins-basic]', 'Package[monitoring-plugins-standard]', 'Package[liburiparser1]', 'Package[python3-attr]', 'Package[iucode-tool]', 'Package[freeipmi-tools]', 'Package[freeipmi-ipmiseld]', 'Package[rsyslog-kafka]', 'Package[emacs-nox]', 'Package[prometheus-ipmi-exporter]', 'Package[libnet-dns-perl]', 'Package[iptables]', 'Package[ferm]', 'Package[nftables]', 'Package[conntrack]', 'Package[wmf-mariadb1011]', 'Package[percona-toolkit]', 'Package[grc]', 'Package[mariadb-backup]', 'Package[python3-wmfmariadbpy]', 'Package[wmfmariadbpy-common]', 'Package[monitoring-plugins-contrib]', 'Package[ruby-concurrent]', 'Package[ruby]', 'Package[libruby]', 'Package[puppet-agent]', 'Package[prometheus-rsyslog-exporter]', 'Package[initramfs-tools]', 'Package[python3-click]', 'Package[python3-box]', 'Package[confd]', 'Package[python3-toml]', 'Package[prometheus-mysqld-exporter]']
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/MONITORING_HOSTS_ipv6.nft.orig
+++ /etc/nftables/sets/MONITORING_HOSTS_ipv6.nft
@@ -0,0 +1,7 @@
+# Autogenerated by puppet
+set MONITORING_HOSTS_ipv6 {
+ type ipv6_addr
+ elements = { 2620:0:861:3:208:80:154:78,
+ 2620:0:860:2:208:80:153:42
+ }
+}
- Nftables::Set[MLSERVE_KUBEPODS_NETWORKS]
- Parameters differences:
--- Nftables::Set[MLSERVE_KUBEPODS_NETWORKS].orig
+++ Nftables::Set[MLSERVE_KUBEPODS_NETWORKS]
+ hosts => ['10.67.16.0/21', '2620:0:861:300::/64', '10.194.16.0/21', '2620:0:860:300::/64']
+ ensure => present
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft
@@ -0,0 +1,9 @@
+# Autogenerated by puppet
+set WIKIKUBE_KUBEPODS_NETWORKS_ipv6 {
+ type ipv6_addr
+ flags interval
+ auto-merge
+ elements = { 2620:0:861:cabe::/64,
+ 2620:0:860:cabe::/64
+ }
+}
- Nftables::Service[mariadb_internal]
- Parameters differences:
--- Nftables::Service[mariadb_internal].orig
+++ Nftables::Service[mariadb_internal]
+ desc =>
+ ensure => present
+ proto => tcp
+ src_sets => ['INTERNAL']
+ notrack => True
+ port => 3306
+ prio => 10
+ unrestricted_access => False
- Systemd::Service[nftables]
- Parameters differences:
--- Systemd::Service[nftables].orig
+++ Systemd::Service[nftables]
+ monitoring_contact_group => admins
+ unit_type => service
+ restart => False
+ ensure => present
+ monitoring_enabled => False
+ override => True
+ monitoring_critical => False
+ migration_task => T407130
+ service_params => {'hasrestart': True, 'restart': '/usr/bin/systemctl reload nftables'}
- File[/etc/nftables/sets/LABS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LABS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/LABS_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/LABS_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/LABS_NETWORKS_ipv6.nft
@@ -0,0 +1,20 @@
+# Autogenerated by puppet
+set LABS_NETWORKS_ipv6 {
+ type ipv6_addr
+ flags interval
+ auto-merge
+ elements = { 2a02:ec80:a000:100::/64,
+ 2a02:ec80:a000:1::/64,
+ 2a02:ec80:a000:201::/64,
+ 2a02:ec80:a000:202::/64,
+ 2a02:ec80:a000:203::/64,
+ 2a02:ec80:a000:204::/64,
+ 2a02:ec80:a000:2ff::/64,
+ 2a02:ec80:a000:4000::/64,
+ 2a02:ec80:a100:100::/64,
+ 2a02:ec80:a100:1::/64,
+ 2a02:ec80:a100:205::/64,
+ 2a02:ec80:a100:2ff::/64,
+ 2a02:ec80:a100:4000::/64
+ }
+}
- Nftables::Set[MYSQL_ROOT_CLIENTS]
- Parameters differences:
--- Nftables::Set[MYSQL_ROOT_CLIENTS].orig
+++ Nftables::Set[MYSQL_ROOT_CLIENTS]
+ hosts => ['10.64.16.90', '10.192.16.191', '10.64.16.154', '10.192.32.49', '208.80.154.9', '10.64.0.20']
+ ensure => present
- File[/etc/nftables/input/10_ssh-from-bastion.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh-from-bastion.nft].orig
+++ File[/etc/nftables/input/10_ssh-from-bastion.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/input/10_ssh-from-bastion.nft.orig
+++ /etc/nftables/input/10_ssh-from-bastion.nft
@@ -0,0 +1,4 @@
+# Managed by puppet
+#
+ip saddr { 103.102.166.103, 185.15.58.6, 185.15.59.99, 195.200.68.99, 198.35.26.104, 208.80.153.110, 208.80.154.7 } tcp dport { 22 } accept
+ip6 saddr { 2001:df2:e500:3:103:102:166:103, 2620:0:860:4:208:80:153:110, 2620:0:861:1:208:80:154:7, 2620:0:863:3:198:35:26:104, 2a02:ec80:300:3:185:15:59:99, 2a02:ec80:600:1:185:15:58:6, 2a02:ec80:700:3:195:200:68:99 } tcp dport { 22 } accept
- Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-status-restart)]
- Parameters differences:
--- Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-status-restart)].orig
+++ Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-status-restart)]
- command => /bin/systemctl daemon-reload
- before => ['Service[ferm]']
- refreshonly => True
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/FRACK_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/FRACK_NETWORKS_ipv6.nft
@@ -0,0 +1,4 @@
+# Autogenerated by puppet
+set FRACK_NETWORKS_ipv6 {
+ type ipv6_addr
+}
- Nrpe::Monitor_service[ferm_active]
- Parameters differences:
--- Nrpe::Monitor_service[ferm_active].orig
+++ Nrpe::Monitor_service[ferm_active]
- nrpe_command => /usr/local/lib/nagios/plugins/check_ferm
- notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/check_ferm
- sudo_user => root
- enable_icinga_check => True
- alertmanager_team => observability
- timeout => 10
- enable_nrpe2nodexp => True
- ensure => present
- retry_interval => 1
- description => Check whether ferm is active by checking the default input chain
- nrpe2nodexp_parse_perf_data => False
- check_interval => 30
- critical => False
- contact_group => admins
- retries => 3
- migration_task => T350694
- Nftables::Set[INSTALL_HOSTS]
- Parameters differences:
--- Nftables::Set[INSTALL_HOSTS].orig
+++ Nftables::Set[INSTALL_HOSTS]
+ hosts => ['208.80.154.134', '208.80.153.70', '185.15.59.101', '198.35.26.98', '103.102.166.104', '185.15.58.7', '195.200.68.100', '2620:0:861:2:208:80:154:134', '2620:0:860:3:208:80:153:70', '2a02:ec80:300:3:185:15:59:101', '2620:0:863:3:198:35:26:98', '2001:df2:e500:3:103:102:166:104', '2a02:ec80:600:1:185:15:58:7', '2a02:ec80:700:3:195:200:68:100']
+ ensure => present
- Package[nftables]
- Parameters differences:
--- Package[nftables].orig
+++ Package[nftables]
+ provider => apt
+ ensure => present
- Nftables::Set[MW_APPSERVER_NETWORKS]
- Parameters differences:
--- Nftables::Set[MW_APPSERVER_NETWORKS].orig
+++ Nftables::Set[MW_APPSERVER_NETWORKS]
+ hosts => ['10.64.0.0/22', '10.64.130.0/24', '10.64.131.0/24', '10.64.132.0/24', '10.64.133.0/24', '10.64.134.0/24', '10.64.135.0/24', '10.64.136.0/24', '10.64.141.0/24', '10.64.152.0/24', '10.64.154.0/24', '10.64.156.0/24', '10.64.158.0/24', '10.64.16.0/22', '10.64.160.0/24', '10.64.162.0/24', '10.64.164.0/24', '10.64.166.0/24', '10.64.169.0/24', '10.64.171.0/24', '10.64.173.0/24', '10.64.175.0/24', '10.64.177.0/24', '10.64.179.0/24', '10.64.181.0/24', '10.64.183.0/24', '10.64.185.0/24', '10.64.187.0/24', '10.64.189.0/24', '10.64.32.0/22', '10.64.48.0/22', '2620:0:861:101::/64', '2620:0:861:102::/64', '2620:0:861:103::/64', '2620:0:861:107::/64', '2620:0:861:109::/64', '2620:0:861:10a::/64', '2620:0:861:10b::/64', '2620:0:861:10c::/64', '2620:0:861:10d::/64', '2620:0:861:10e::/64', '2620:0:861:10f::/64', '2620:0:861:113::/64', '2620:0:861:119::/64', '2620:0:861:120::/64', '2620:0:861:122::/64', '2620:0:861:124::/64', '2620:0:861:126::/64', '2620:0:861:128::/64', '2620:0:861:12a::/64', '2620:0:861:12c::/64', '2620:0:861:12e::/64', '2620:0:861:131::/64', '2620:0:861:133::/64', '2620:0:861:135::/64', '2620:0:861:137::/64', '2620:0:861:139::/64', '2620:0:861:13b::/64', '2620:0:861:13d::/64', '2620:0:861:13f::/64', '2620:0:861:142::/64', '2620:0:861:144::/64', '10.192.0.0/22', '10.192.10.0/24', '10.192.11.0/24', '10.192.12.0/24', '10.192.13.0/24', '10.192.14.0/24', '10.192.15.0/24', '10.192.16.0/22', '10.192.21.0/24', '10.192.22.0/24', '10.192.23.0/24', '10.192.26.0/24', '10.192.27.0/24', '10.192.28.0/24', '10.192.29.0/24', '10.192.30.0/24', '10.192.31.0/24', '10.192.32.0/22', '10.192.36.0/24', '10.192.37.0/24', '10.192.38.0/24', '10.192.39.0/24', '10.192.4.0/24', '10.192.40.0/24', '10.192.41.0/24', '10.192.42.0/24', '10.192.43.0/24', '10.192.44.0/24', '10.192.45.0/24', '10.192.46.0/24', '10.192.47.0/24', '10.192.48.0/22', '10.192.5.0/24', '10.192.52.0/24', '10.192.56.0/24', '10.192.57.0/24', '10.192.58.0/24', '10.192.59.0/24', '10.192.6.0/24', '10.192.7.0/24', '10.192.8.0/24', '10.192.9.0/24', '2620:0:860:100::/64', '2620:0:860:101::/64', '2620:0:860:102::/64', '2620:0:860:103::/64', '2620:0:860:104::/64', '2620:0:860:105::/64', '2620:0:860:106::/64', '2620:0:860:107::/64', '2620:0:860:108::/64', '2620:0:860:109::/64', '2620:0:860:10a::/64', '2620:0:860:10b::/64', '2620:0:860:10c::/64', '2620:0:860:10d::/64', '2620:0:860:10e::/64', '2620:0:860:10f::/64', '2620:0:860:110::/64', '2620:0:860:111::/64', '2620:0:860:112::/64', '2620:0:860:113::/64', '2620:0:860:114::/64', '2620:0:860:115::/64', '2620:0:860:116::/64', '2620:0:860:119::/64', '2620:0:860:11a::/64', '2620:0:860:11b::/64', '2620:0:860:11c::/64', '2620:0:860:11d::/64', '2620:0:860:11e::/64', '2620:0:860:11f::/64', '2620:0:860:120::/64', '2620:0:860:121::/64', '2620:0:860:122::/64', '2620:0:860:123::/64', '2620:0:860:124::/64', '2620:0:860:125::/64', '2620:0:860:126::/64', '2620:0:860:127::/64', '2620:0:860:12b::/64', '2620:0:860:12c::/64', '2620:0:860:12d::/64', '2620:0:860:12e::/64', '10.192.64.0/21', '10.192.96.0/21', '10.194.128.0/17', '10.194.16.0/21', '10.194.61.0/24', '10.194.80.0/21', '10.64.64.0/21', '10.67.128.0/17', '10.67.16.0/21', '10.67.24.0/21', '10.67.80.0/21', '2620:0:860:300::/64', '2620:0:860:302::/64', '2620:0:860:305::/64', '2620:0:860:308::/64', '2620:0:860:babe::/64', '2620:0:860:cabe::/64', '2620:0:861:300::/64', '2620:0:861:302::/64', '2620:0:861:305::/64', '2620:0:861:babe::/64', '2620:0:861:cabe::/64', '208.80.154.0/26', '208.80.154.128/26', '208.80.154.64/26', '208.80.155.96/27', '2620:0:861:1::/64', '2620:0:861:2::/64', '2620:0:861:3::/64', '2620:0:861:4::/64', '208.80.153.0/27', '208.80.153.32/27', '208.80.153.64/27', '208.80.153.96/27', '2620:0:860:1::/64', '2620:0:860:2::/64', '2620:0:860:3::/64', '2620:0:860:4::/64']
+ ensure => present
- Systemd::Timer::Job[prometheus-node-textfile-check-nft]
- Parameters differences:
--- Systemd::Timer::Job[prometheus-node-textfile-check-nft].orig
+++ Systemd::Timer::Job[prometheus-node-textfile-check-nft]
+ monitoring_contact_groups => admins
+ send_mail_only_on_error => True
+ monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state
+ logfile_basedir => /var/log
+ logfile_name => syslog.log
+ send_mail_to => root@pc2022.codfw.wmnet
+ monitoring_enabled => False
+ private_tmp => False
+ logfile_perms => all
+ fixed_random_delay => False
+ ensure => present
+ command => /usr/local/bin/check-nft
+ interval => {'start': 'OnCalendar', 'interval': '*:0/30'}
+ logfile_group => root
+ user => root
+ description => Systemd timer to gather node metrics for check-nft
+ environment => {}
+ logging_enabled => True
+ syslog_match_startswith => True
+ success_exit_status => []
+ send_mail => False
+ ignore_errors => False
+ syslog_force_stop => True
- Nftables::Set[LABSTORE_HOSTS]
- Parameters differences:
--- Nftables::Set[LABSTORE_HOSTS].orig
+++ Nftables::Set[LABSTORE_HOSTS]
+ hosts => ['208.80.154.142', '2620:0:861:2:208:80:154:142', '208.80.154.71', '2620:0:861:3:208:80:154:71']
+ ensure => present
- Systemd::Unit[wmf_auto_restart_ulogd2.timer]
- Parameters differences:
--- Systemd::Unit[wmf_auto_restart_ulogd2.timer].orig
+++ Systemd::Unit[wmf_auto_restart_ulogd2.timer]
- require => ['Class[Systemd]']
- restart => False
- override => False
- ensure => present
- override_filename => puppet-override.conf
- unit => wmf_auto_restart_ulogd2.timer
- Systemd::Timer[prometheus-node-textfile-check-nft]
- Parameters differences:
--- Systemd::Timer[prometheus-node-textfile-check-nft].orig
+++ Systemd::Timer[prometheus-node-textfile-check-nft]
+ fixed_random_delay => False
+ splay => 0
+ timer_intervals => [{'start': 'OnCalendar', 'interval': '*:0/30'}]
+ ensure => present
+ accuracy => 15sec
+ unit_name => prometheus-node-textfile-check-nft.service
- Systemd::Override[ferm-service-status-restart]
- Parameters differences:
--- Systemd::Override[ferm-service-status-restart].orig
+++ Systemd::Override[ferm-service-status-restart]
- source => puppet:///modules/ferm/ferm_systemd_override
- restart => False
- ensure => present
- unit => ferm
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft].orig
+++ File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft.orig
+++ /etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft
@@ -0,0 +1,12 @@
+# Autogenerated by puppet
+set CLOUD_PRIVATE_NETWORKS_ipv4 {
+ type ipv4_addr
+ flags interval
+ auto-merge
+ elements = { 172.20.1.0/24,
+ 172.20.2.0/24,
+ 172.20.3.0/24,
+ 172.20.4.0/24,
+ 172.20.5.0/24
+ }
+}
- File[/etc/ulogd.conf]
- Parameters differences:
--- File[/etc/ulogd.conf].orig
+++ File[/etc/ulogd.conf]
- owner => root
- group => root
- notify => Service[ulogd2]
- ensure => file
- Content differences:
--- /etc/ulogd.conf.orig
+++ /etc/ulogd.conf
@@ -1,71 +0,0 @@
-# MANAGED BY PUPPET
-[global]
-logfile=syslog
-loglevel=3
-
-
-stack=log1:NFLOG,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,print1:PRINTPKT,syslog1:SYSLOG
-
-
-
-
-[ct1]
-
-[ct2]
-hash_enable=0
-
-[mark]
-
-[log1]
-group=0
-
-[log2]
-group=1
-
-[log3]
-group=2
-
-[logemu1]
-sync=1
-file=/var/log/ulog/syslogemu.log
-
-[emunfct1]
-sync=1
-file=/var/log/ulog/syslogemu_nfct.log
-
-[json1]
-sync=1
-file=/var/log/ulog/ulogd.json
-
-[jsonnfct1]
-sync=1
-file=/var/log/ulog/ulogd_nfct.json
-
-
-[oprint1]
-sync=1
-file=/var/log/ulog/oprint.log
-
-[gprint1]
-sync=1
-file=/var/log/ulog/gprint.log
-
-[json1]
-sync=1
-file=/var/log/ulog/ulogd.json
-
-[xml1]
-sync=1
-file=/var/log/ulog/
-
-[pcap1]
-sync=1
-file=
-
-[nacct1]
-sync=1
-file=
-
-[syslog1]
-facility=LOG_LOCAL7
-level=LOG_INFO
- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft
@@ -0,0 +1,8 @@
+# Autogenerated by puppet
+set MLSTAGE_KUBEPODS_NETWORKS_ipv6 {
+ type ipv6_addr
+ flags interval
+ auto-merge
+ elements = { 2620:0:860:302::/64
+ }
+}
- Exec[systemd daemon-reload for nftables.service (nftables)]
- Parameters differences:
--- Exec[systemd daemon-reload for nftables.service (nftables)].orig
+++ Exec[systemd daemon-reload for nftables.service (nftables)]
+ command => /bin/systemctl daemon-reload
+ before => ['Service[nftables]']
+ refreshonly => True
- File[/etc/nftables/]
- Parameters differences:
--- File[/etc/nftables/].orig
+++ File[/etc/nftables/]
+ group => root
+ recurse => True
+ path => /etc/nftables
+ ensure => directory
+ purge => True
+ owner => root
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft].orig
+++ File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft]
+ tag => nft
+ group => root
+ ensure => present
+ mode => 0444
+ notify => ['Service[nftables]']
+ owner => root
- Content differences:
--- /etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft.orig
+++ /etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft
@@ -0,0 +1,183 @@
+# Autogenerated by puppet
+set DOMAIN_NETWORKS_ipv6 {
+ type ipv6_addr
+ flags interval
+ auto-merge
+ elements = { 2001:df2:e500:101::/64,
+ 2001:df2:e500:103::/64,
+ 2001:df2:e500:1::/64,
+ 2001:df2:e500:3::/64,
+ 2001:df2:e500:ed1a::/64,
+ 2620:0:860:100::/64,
+ 2620:0:860:101::/64,
+ 2620:0:860:102::/64,
+ 2620:0:860:103::/64,
+ 2620:0:860:104::/64,
+ 2620:0:860:105::/64,
+ 2620:0:860:106::/64,
+ 2620:0:860:107::/64,
+ 2620:0:860:108::/64,
+ 2620:0:860:109::/64,
+ 2620:0:860:10a::/64,
+ 2620:0:860:10b::/64,
+ 2620:0:860:10c::/64,
+ 2620:0:860:10d::/64,
+ 2620:0:860:10e::/64,
+ 2620:0:860:10f::/64,
+ 2620:0:860:110::/64,
+ 2620:0:860:111::/64,
+ 2620:0:860:112::/64,
+ 2620:0:860:113::/64,
+ 2620:0:860:114::/64,
+ 2620:0:860:115::/64,
+ 2620:0:860:116::/64,
+ 2620:0:860:118::/64,
+ 2620:0:860:119::/64,
+ 2620:0:860:11a::/64,
+ 2620:0:860:11b::/64,
+ 2620:0:860:11c::/64,
+ 2620:0:860:11d::/64,
+ 2620:0:860:11e::/64,
+ 2620:0:860:11f::/64,
+ 2620:0:860:120::/64,
+ 2620:0:860:121::/64,
+ 2620:0:860:122::/64,
+ 2620:0:860:123::/64,
+ 2620:0:860:124::/64,
+ 2620:0:860:125::/64,
+ 2620:0:860:126::/64,
+ 2620:0:860:127::/64,
+ 2620:0:860:12b::/64,
+ 2620:0:860:12c::/64,
+ 2620:0:860:12d::/64,
+ 2620:0:860:12e::/64,
+ 2620:0:860:140::/64,
+ 2620:0:860:1::/64,
+ 2620:0:860:2::/64,
+ 2620:0:860:300::/64,
+ 2620:0:860:301::/64,
+ 2620:0:860:302::/64,
+ 2620:0:860:303::/64,
+ 2620:0:860:304::/64,
+ 2620:0:860:305::/64,
+ 2620:0:860:307::/64,
+ 2620:0:860:308::/64,
+ 2620:0:860:3::/64,
+ 2620:0:860:4::/64,
+ 2620:0:860:5::/64,
+ 2620:0:860:babe::/64,
+ 2620:0:860:babf::/64,
+ 2620:0:860:cabe::/64,
+ 2620:0:860:cabf::/64,
+ 2620:0:860:ed1a::/64,
+ 2620:0:861:100::/64,
+ 2620:0:861:101::/64,
+ 2620:0:861:102::/64,
+ 2620:0:861:103::/64,
+ 2620:0:861:104::/64,
+ 2620:0:861:105::/64,
+ 2620:0:861:106::/64,
+ 2620:0:861:107::/64,
+ 2620:0:861:108::/64,
+ 2620:0:861:109::/64,
+ 2620:0:861:10a::/64,
+ 2620:0:861:10b::/64,
+ 2620:0:861:10c::/64,
+ 2620:0:861:10d::/64,
+ 2620:0:861:10e::/64,
+ 2620:0:861:10f::/64,
+ 2620:0:861:110::/64,
+ 2620:0:861:111::/64,
+ 2620:0:861:112::/64,
+ 2620:0:861:113::/64,
+ 2620:0:861:114::/64,
+ 2620:0:861:115::/64,
+ 2620:0:861:116::/64,
+ 2620:0:861:117::/64,
+ 2620:0:861:118::/64,
+ 2620:0:861:119::/64,
+ 2620:0:861:11a::/64,
+ 2620:0:861:11c::/64,
+ 2620:0:861:11d::/64,
+ 2620:0:861:11e::/64,
+ 2620:0:861:11f::/64,
+ 2620:0:861:120::/64,
+ 2620:0:861:121::/64,
+ 2620:0:861:122::/64,
+ 2620:0:861:123::/64,
+ 2620:0:861:124::/64,
+ 2620:0:861:125::/64,
+ 2620:0:861:126::/64,
+ 2620:0:861:127::/64,
+ 2620:0:861:128::/64,
+ 2620:0:861:129::/64,
+ 2620:0:861:12a::/64,
+ 2620:0:861:12b::/64,
+ 2620:0:861:12c::/64,
+ 2620:0:861:12d::/64,
+ 2620:0:861:12e::/64,
+ 2620:0:861:12f::/64,
+ 2620:0:861:131::/64,
+ 2620:0:861:132::/64,
+ 2620:0:861:133::/64,
+ 2620:0:861:134::/64,
+ 2620:0:861:135::/64,
+ 2620:0:861:136::/64,
+ 2620:0:861:137::/64,
+ 2620:0:861:138::/64,
+ 2620:0:861:139::/64,
+ 2620:0:861:13a::/64,
+ 2620:0:861:13b::/64,
+ 2620:0:861:13c::/64,
+ 2620:0:861:13d::/64,
+ 2620:0:861:13e::/64,
+ 2620:0:861:13f::/64,
+ 2620:0:861:140::/64,
+ 2620:0:861:141::/64,
+ 2620:0:861:142::/64,
+ 2620:0:861:143::/64,
+ 2620:0:861:144::/64,
+ 2620:0:861:145::/64,
+ 2620:0:861:1::/64,
+ 2620:0:861:2::/64,
+ 2620:0:861:300::/64,
+ 2620:0:861:301::/116,
+ 2620:0:861:302::/64,
+ 2620:0:861:303::/116,
+ 2620:0:861:304::/116,
+ 2620:0:861:305::/64,
+ 2620:0:861:3::/64,
+ 2620:0:861:4::/64,
+ 2620:0:861:babe::/64,
+ 2620:0:861:babf::/116,
+ 2620:0:861:cabe::/64,
+ 2620:0:861:cabf::/116,
+ 2620:0:861:ed1a::/64,
+ 2620:0:863:101::/64,
+ 2620:0:863:102::/64,
+ 2620:0:863:103::/64,
+ 2620:0:863:1::/64,
+ 2620:0:863:2::/64,
+ 2620:0:863:3::/64,
+ 2620:0:863:ed1a::/64,
+ 2a02:ec80:300:101::/64,
+ 2a02:ec80:300:102::/64,
+ 2a02:ec80:300:103::/64,
+ 2a02:ec80:300:1::/64,
+ 2a02:ec80:300:2::/64,
+ 2a02:ec80:300:3::/64,
+ 2a02:ec80:300:ed1a::/64,
+ 2a02:ec80:600:101::/64,
+ 2a02:ec80:600:102::/64,
+ 2a02:ec80:600:1::/64,
+ 2a02:ec80:600:2::/64,
+ 2a02:ec80:600:ed1a::/64,
+ 2a02:ec80:700:101::/64,
+ 2a02:ec80:700:102::/64,
+ 2a02:ec80:700:103::/64,
+ 2a02:ec80:700:1::/64,
+ 2a02:ec80:700:2::/64,
+ 2a02:ec80:700:3::/64,
+ 2a02:ec80:700:ed1a::/64
+ }
+}
- Package[ferm]
- Parameters differences:
--- Package[ferm].orig
+++ Package[ferm]
@@
- ensure => installed
+ ensure => purged
- File[/etc/nftables/prerouting]
- Parameters differences: