{"host": "cumin1003.eqiad.wmnet", "state": "core_diff", "description": "Differences to core resources", "diff": {"full": {"total": 3747, "only_in_self": ["Cfssl::Cert[kafka__kafka_fundraising_client_kafka_11]", "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]"], "only_in_other": ["Cfssl::Cert[kafka__kafka_fundraising_client]", "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client refresh]", "Exec[Generate cert kafka__kafka_fundraising_client]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]"], "resource_diffs": [{"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem]\n\n+    require => Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]\n+    ensure  => file\n+    group   => fr-tech-admins\n+    owner   => root\n"}, {"resource": "Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]", "parameters": "--- Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11].orig\n+++ Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]\n\n-    command     => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka -profile kafka_11 /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n-    unless      => /usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem -checkend 952200\n-    require     => Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]\n"}, {"resource": "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "parameters": "--- Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr].orig\n+++ Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]\n\n+    hosts       => []\n+    key         => {'algo': 'ecdsa', 'size': 256}\n+    names       => []\n+    ensure      => present\n+    common_name => kafka_fundraising_client\n"}, {"resource": "Cfssl::Cert[kafka__kafka_fundraising_client_kafka_11]", "parameters": "--- Cfssl::Cert[kafka__kafka_fundraising_client_kafka_11].orig\n+++ Cfssl::Cert[kafka__kafka_fundraising_client_kafka_11]\n\n-    provide_chain   => True\n-    hosts           => []\n-    names           => []\n-    group           => fr-tech-admins\n-    mode            => 0740\n-    notify_services => []\n-    ensure          => present\n-    label           => kafka\n-    key             => {'algo': 'ecdsa', 'size': 256}\n-    profile         => kafka_11\n-    renew_seconds   => 952200\n-    auto_renew      => True\n-    before_services => []\n-    outdir          => /etc/fr-tech-kafka-client\n-    environment     => ['GODEBUG=x509ignoreCN=0']\n-    common_name     => kafka_fundraising_client\n-    owner           => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client_kafka_11].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]\n\n-    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka -profile kafka_11 /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n-    unless      => /usr/bin/test \"$(/usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem -noout -pubkey 2>&1)\" == \"$(/usr/bin/openssl pkey -pubout -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem 2>&1)\"\n\n-    require     => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]\n\n-    ensure => file\n-    group  => fr-tech-admins\n-    mode   => 0440\n-    owner  => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]\n\n-    refreshonly => True\n-    require     => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]\n-    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka -profile kafka_11 /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n-    subscribe   => File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]\n"}, {"resource": "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "parameters": "--- Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem].orig\n+++ Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]\n\n+    require   => Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]\n+    command   => /bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem > /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem\n+    unless    => /usr/bin/test \"$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem | sha512sum)\" == \"$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem | sha512sum)\"\n\n+    subscribe => ['Exec[renew certificate - kafka__kafka_fundraising_client]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]']\n"}, {"resource": "File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "content": "--- /etc/cfssl/csr/kafka__kafka_fundraising_client.csr.orig\n+++ /etc/cfssl/csr/kafka__kafka_fundraising_client.csr\n@@ -0,0 +1,13 @@\n+{\n+  \"CN\": \"kafka_fundraising_client\",\n+  \"hosts\": [\n+    \"kafka_fundraising_client\"\n+  ],\n+  \"key\": {\n+    \"algo\": \"ecdsa\",\n+    \"size\": 256\n+  },\n+  \"names\": [\n+\n+  ]\n+}", "parameters": "--- File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr].orig\n+++ File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]\n\n+    ensure => file\n+    group  => root\n+    mode   => 0400\n+    owner  => root\n"}, {"resource": "Cfssl::Cert[kafka__kafka_fundraising_client]", "parameters": "--- Cfssl::Cert[kafka__kafka_fundraising_client].orig\n+++ Cfssl::Cert[kafka__kafka_fundraising_client]\n\n+    provide_chain   => True\n+    hosts           => []\n+    names           => []\n+    group           => fr-tech-admins\n+    mode            => 0740\n+    notify_services => []\n+    ensure          => present\n+    label           => kafka\n+    key             => {'algo': 'ecdsa', 'size': 256}\n+    renew_seconds   => 952200\n+    auto_renew      => True\n+    before_services => []\n+    outdir          => /etc/fr-tech-kafka-client\n+    environment     => ['GODEBUG=x509ignoreCN=0']\n+    common_name     => kafka_fundraising_client\n+    owner           => root\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]\n\n+    ensure => file\n+    group  => fr-tech-admins\n+    mode   => 0440\n+    owner  => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client refresh]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client refresh].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client refresh]\n\n+    refreshonly => True\n+    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka  /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n+    subscribe   => File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]\n"}, {"resource": "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "parameters": "--- Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem].orig\n+++ Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]\n\n-    require   => Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]\n-    command   => /bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem > /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem\n-    unless    => /usr/bin/test \"$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem | sha512sum)\" == \"$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem | sha512sum)\"\n\n-    subscribe => ['Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]']\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]\n\n-    ensure => file\n-    group  => fr-tech-admins\n-    mode   => 0440\n-    owner  => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]\n\n+    refreshonly => True\n+    require     => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]\n+    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka  /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n+    subscribe   => File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]\n\n-    owner     => root\n-    ensure    => file\n-    group     => fr-tech-admins\n-    backup    => False\n-    mode      => 0440\n-    show_diff => False\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]\n\n+    owner     => root\n+    ensure    => file\n+    group     => fr-tech-admins\n+    backup    => False\n+    mode      => 0440\n+    show_diff => False\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]\n\n-    require => Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]\n-    ensure  => file\n-    group   => fr-tech-admins\n-    owner   => root\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]\n\n+    source => puppet:///modules/profile/pki/intermediates/kafka-cert.pem\n+    ensure => file\n+    group  => fr-tech-admins\n+    mode   => 0440\n+    owner  => root\n"}, {"resource": "Exec[renew certificate - kafka__kafka_fundraising_client]", "parameters": "--- Exec[renew certificate - kafka__kafka_fundraising_client].orig\n+++ Exec[renew certificate - kafka__kafka_fundraising_client]\n\n+    command     => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka  /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n+    unless      => /usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem -checkend 952200\n+    require     => Exec[Generate cert kafka__kafka_fundraising_client]\n"}, {"resource": "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "parameters": "--- Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr].orig\n+++ Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]\n\n-    hosts       => []\n-    key         => {'algo': 'ecdsa', 'size': 256}\n-    names       => []\n-    ensure      => present\n-    common_name => kafka_fundraising_client\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]\n\n-    source => puppet:///modules/profile/pki/intermediates/kafka-cert.pem\n-    ensure => file\n-    group  => fr-tech-admins\n-    mode   => 0440\n-    owner  => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]\n\n-    refreshonly => True\n-    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka -profile kafka_11 /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11\n\n-    environment => ['GODEBUG=x509ignoreCN=0']\n-    subscribe   => File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]\n"}, {"resource": "File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "content": "--- /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr.orig\n+++ /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr\n@@ -1,13 +0,0 @@\n-{\n-  \"CN\": \"kafka_fundraising_client\",\n-  \"hosts\": [\n-    \"kafka_fundraising_client\"\n-  ],\n-  \"key\": {\n-    \"algo\": \"ecdsa\",\n-    \"size\": 256\n-  },\n-  \"names\": [\n-\n-  ]\n-}", "parameters": "--- File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr].orig\n+++ File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]\n\n-    ensure => file\n-    group  => root\n-    mode   => 0400\n-    owner  => root\n"}, {"resource": "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]", "parameters": "--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr].orig\n+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]\n\n+    ensure => file\n+    group  => fr-tech-admins\n+    mode   => 0440\n+    owner  => root\n"}, {"resource": "Exec[Generate cert kafka__kafka_fundraising_client]", "parameters": "--- Exec[Generate cert kafka__kafka_fundraising_client].orig\n+++ Exec[Generate cert kafka__kafka_fundraising_client]\n\n+    command     => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka  /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client\n\n+    environment => ['GODEBUG=x509ignoreCN=0']\n+    unless      => /usr/bin/test \"$(/usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem -noout -pubkey 2>&1)\" == \"$(/usr/bin/openssl pkey -pubout -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem 2>&1)\"\n\n+    require     => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]\n"}], "perc_changed": "1.39%"}, "core": {"total": 3747, "only_in_self": ["Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]"], "only_in_other": ["Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client refresh]", "Exec[Generate cert kafka__kafka_fundraising_client]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]"], "resource_diffs": [], "perc_changed": "0.59%"}, "main": {"total": 3747, "only_in_self": ["Cfssl::Cert[kafka__kafka_fundraising_client_kafka_11]", "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]", "Exec[Generate cert kafka__kafka_fundraising_client_kafka_11]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]"], "only_in_other": ["Cfssl::Cert[kafka__kafka_fundraising_client]", "Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]", "Exec[Generate cert kafka__kafka_fundraising_client refresh]", "Exec[Generate cert kafka__kafka_fundraising_client]", "Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "Exec[renew certificate - kafka__kafka_fundraising_client]", "File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]", "File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]"], "resource_diffs": [], "perc_changed": "0.69%"}}}