Compilation results for rdb2013.codfw.wmnet: System changes detected
You can retrieve this result from host.json.Catalog differences
Summary
| Total Resources: | 3152 |
|---|---|
| Resources added: | 158 |
| Resources removed: | 83 |
| Resources modified: | 255 |
| Change percentage: | 15.74% |
Resources only in the new catalog
- File[/etc/nftables/sets/MYSQL_ROOT_CLIENTS_ipv6.nft]
- Nftables::Set[MGMT_NETWORKS]
- Rsyslog::Conf[prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv6.nft]
- File[/usr/local/bin/check-nft]
- Prometheus::Node_textfile[check-nft]
- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv6.nft]
- Nftables::Set[PRODUCTION_NETWORKS]
- File[/etc/nftables/]
- Exec[systemd daemon-reload for nftables.service (nftables)]
- Nftables::Set[KAFKAMON_HOSTS]
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv4.nft]
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv4.nft]
- File[/etc/nftables/input/10_ssh-from-bastion.nft]
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv6.nft]
- Systemd::Unit[nftables]
- File[/etc/nftables/sets/MLSTAGE_KUBEPODS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/CACHES_ipv4.nft]
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft]
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets]
- Nftables::Set[DSE_KUBEPODS_NETWORKS]
- File[/etc/nftables/input/10_full-monitoring-metrics-access-tcp.nft]
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv4.nft]
- Nftables::Set[STAGING_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv6.nft]
- Nftables::Set[AUX_KUBEPODS_NETWORKS]
- Exec[systemd daemon-reload for prometheus-node-textfile-check-nft.timer (prometheus-node-textfile-check-nft.timer)]
- Nftables::Set[SANDBOX_NETWORKS]
- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv6.nft]
- File[/etc/rsyslog.d/40-prometheus-node-textfile-check-nft.conf]
- Nftables::Set[MLSERVE_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/NETWORK_INFRA_ipv6.nft]
- File[/lib/systemd/system/prometheus-node-textfile-check-nft.timer]
- Nftables::Set[LABS_NETWORKS]
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv4.nft]
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv6.nft]
- Nftables::Set[FRACK_NETWORKS]
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
- Systemd::Timer[prometheus-node-textfile-check-nft]
- Nftables::Set[CLOUD_PRIVATE_NETWORKS]
- Nftables::Set[KAFKA_BROKERS_LOGGING]
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv4.nft]
- File[/lib/systemd/system/prometheus-node-textfile-check-nft.service]
- File[/etc/nftables/sets/LABS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/KAFKAMON_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/INTERNAL_ipv4.nft]
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/KAFKAMON_HOSTS_ipv4.nft]
- Systemd::Service[nftables]
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv4.nft]
- Nftables::Set[LOAD_BALANCER_HEALTH_CHECKS]
- File[/etc/nftables/100_base_puppet.nft]
- Nftables::Set[KAFKA_BROKERS_MAIN]
- Nftables::Set[PROMETHEUS_HOSTS]
- Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS]
- Nftables::Set[WIKIKUBE_KUBEPODS_NETWORKS]
- File[/etc/nftables/sets/ZOOKEEPER_HOSTS_MAIN_ipv6.nft]
- Systemd::Timer::Job[prometheus-node-textfile-check-nft]
- Nftables::Set[CACHES]
- File[/etc/nftables.conf]
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/PROMETHEUS_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv4.nft]
- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft]
- Service[nftables]
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- File[/etc/nftables/main.nft]
- Nftables::Set[BASTION_HOSTS]
- File[/etc/nftables/sets/KAFKA_BROKERS_LOGGING_ipv6.nft]
- Systemd::Unmask[nftables.service]
- File[/etc/nftables/input/10_full-monitoring-metrics-access-udp.nft]
- File[/etc/nftables/sets/BASTION_HOSTS_ipv6.nft]
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/MYSQL_ROOT_CLIENTS_ipv4.nft]
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv6.nft]
- Nftables::Set[ZOOKEEPER_FLINK_HOSTS]
- Nftables::Set[NETWORK_INFRA]
- Nftables::Set[KAFKA_BROKERS_JUMBO]
- Nftables::Set[LINK_LOCAL]
- Nftables::Set[ZOOKEEPER_HOSTS_MAIN]
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv4.nft]
- Class[Profile::Firewall::Nftables_base_sets]
- File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft]
- Nftables::Set[LABSTORE_HOSTS]
- File[/etc/nftables/notrack/10_redis_master_role.nft]
- File[/etc/systemd/system/nftables.service.d]
- File[/etc/nftables/notrack]
- Nftables::Set[ANALYTICS_NETWORKS]
- Systemd::Service[prometheus-node-textfile-check-nft]
- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- File[/etc/nftables/sets/CACHES_ipv6.nft]
- File[/etc/nftables/input]
- Nftables::Set[MW_APPSERVER_NETWORKS]
- Nftables::Set[CLOUD_NETWORKS_PUBLIC]
- Nftables::Set[MYSQL_ROOT_CLIENTS]
- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv4.nft]
- Nftables::Set[DEPLOYMENT_HOSTS]
- Systemd::Syslog[prometheus-node-textfile-check-nft]
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/LABSTORE_HOSTS_ipv6.nft]
- File[/etc/logrotate.d/prometheus-node-textfile-check-nft]
- File[/etc/nftables/output]
- File[/etc/nftables/sets/PROMETHEUS_HOSTS_ipv6.nft]
- File[/etc/nftables/input/10_redis_master_role.nft]
- File[/etc/nftables/forward]
- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- Logrotate::Conf[prometheus-node-textfile-check-nft]
- Nftables::Set[INTERNAL]
- Service[prometheus-node-textfile-check-nft.timer]
- Class[Nftables]
- File[/etc/nftables/sets/INSTALL_HOSTS_ipv4.nft]
- File[/var/log/prometheus-node-textfile-check-nft]
- Systemd::Unit[prometheus-node-textfile-check-nft.timer]
- Nftables::Set[INSTALL_HOSTS]
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Nftables::Set[CUMIN_MASTERS]
- Exec[unmask_nftables.service]
- Nftables::Set[DRUID_PUBLIC_HOSTS]
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv6.nft]
- File[/etc/nftables/prerouting]
- File[/etc/nftables/sets/MLSERVE_KUBEPODS_NETWORKS_ipv6.nft]
- Systemd::Unit[prometheus-node-textfile-check-nft.service]
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_MAIN_ipv4.nft]
- File[/etc/nftables/sets/SANDBOX_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/FRACK_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/CLOUD_PRIVATE_NETWORKS_ipv6.nft]
- File[/etc/nftables/sets/KAFKA_BROKERS_MAIN_ipv6.nft]
- File[/etc/nftables/sets/LINK_LOCAL_ipv6.nft]
- File[/etc/nftables/sets/NETWORK_INFRA_ipv4.nft]
- Nftables::Set[DOMAIN_NETWORKS]
- Exec[systemd daemon-reload for prometheus-node-textfile-check-nft.service (prometheus-node-textfile-check-nft.service)]
- File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft]
- File[/etc/nftables/sets/ZOOKEEPER_FLINK_HOSTS_ipv4.nft]
- File[/etc/nftables/postrouting]
- File[/etc/systemd/system/nftables.service.d/puppet-override.conf]
- File[/etc/nftables/sets/DOMAIN_NETWORKS_ipv4.nft]
- Package[nftables]
- Nftables::File[base]
- File[/etc/nftables/sets/WIKIKUBE_KUBEPODS_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- File[/etc/nftables/sets/LABS_NETWORKS_ipv6.nft]
- Nftables::Set[CLOUD_NETWORKS]
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft]
- Nftables::Set[MONITORING_HOSTS]
- File[/etc/nftables/sets/CUMIN_MASTERS_ipv6.nft]
Resources only in the old catalog
- File[/etc/ferm/conf.d/02_main]
- Profile::Auto_restarts::Service[ulogd2]
- File[/lib/systemd/system/wmf_auto_restart_ulogd2.service]
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_udp]
- File[/etc/ferm/conf.d/10_ssh_from_bastion]
- File[/etc/rsyslog.d/40-wmf-auto-restart-ulogd2.conf]
- File[/etc/ferm/conf.d/01_drop-blocked-nets]
- Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c]
- File[/etc/systemd/system/ferm.service.d/ferm-service-status-restart.conf]
- Class[Ulogd]
- Systemd::Unit[wmf_auto_restart_ulogd2.service]
- File[/etc/ferm/conf.d]
- File[/etc/ferm/ferm.conf]
- Ferm::Filter_log[filter-bootp]
- Ferm::Rule[dscp-default]
- File[/usr/local/lib/nagios/plugins/check_ferm]
- Systemd::Timer[nrpe2nodexp-ferm_active]
- Service[ulogd2]
- Ferm::Rule[drop-blocked-nets]
- Nrpe::Plugin[check_ferm]
- Systemd::Timer::Job[nrpe2nodexp-ferm_active]
- File[/etc/rsyslog.d/25-nrpe2nodexp-ferm-active.conf]
- File[/etc/logrotate.d/wmf_auto_restart_ulogd2]
- File[/etc/ferm/conf.d/10_ssh_from_cumin_masters]
- Systemd::Override[ferm-service-status-restart]
- File[/lib/systemd/system/nrpe2nodexp-ferm_active.service]
- File[/etc/ferm/functions.conf]
- Logrotate::Conf[wmf_auto_restart_ulogd2]
- File[/etc/ferm/conf.d/10_redis_master_role]
- Exec[update_alternative_iptables]
- Systemd::Syslog[wmf_auto_restart_ulogd2]
- File_line[auto_restart_file_presence_ulogd2]
- File[/etc/ferm/conf.d/00_defs]
- Nrpe::Monitor_service[ferm_active]
- Ferm::Conf[main]
- Exec[systemd daemon-reload for nrpe2nodexp-ferm_active.service (nrpe2nodexp-ferm_active.service)]
- File[/var/log/wmf_auto_restart_ulogd2]
- Monitoring::Service[ferm_active]
- File[/etc/nagios/nrpe.d/check_ferm_active.cfg]
- Systemd::Service[wmf_auto_restart_ulogd2]
- Systemd::Syslog[ulogd]
- Rsyslog::Conf[nrpe2nodexp-ferm_active]
- Service[nrpe2nodexp-ferm_active.timer]
- File[/etc/ferm/conf.d/98_filter_log_filter-bootp]
- File[/etc/ulogd.conf]
- Systemd::Unit[ferm-ferm-service-status-restart]
- File[/etc/ferm/conf.d/98_log-everything]
- File[/etc/default/ferm]
- Service[ferm]
- Systemd::Service[nrpe2nodexp-ferm_active]
- File[/etc/sudoers.d/nrpe-check_ferm_active]
- Rsyslog::Conf[wmf_auto_restart_ulogd2]
- Alternatives::Select[ip6tables]
- File[/etc/logrotate.d/ulogd]
- Systemd::Timer[wmf_auto_restart_ulogd2]
- Systemd::Timer::Job[wmf_auto_restart_ulogd2]
- Logrotate::Conf[ulogd]
- File[/etc/systemd/system/ferm.service.d]
- Systemd::Unit[nrpe2nodexp-ferm_active.timer]
- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.timer (wmf_auto_restart_ulogd2.timer)]
- Systemd::Unit[wmf_auto_restart_ulogd2.timer]
- File[/etc/rsyslog.d/40-ulogd.conf]
- Rsyslog::Conf[ulogd]
- File[/lib/systemd/system/nrpe2nodexp-ferm_active.timer]
- Class[Profile::Firewall::Log::Ferm]
- Ferm::Rule[filter_log_filter-bootp]
- Exec[systemd daemon-reload for wmf_auto_restart_ulogd2.service (wmf_auto_restart_ulogd2.service)]
- Sudo::User[nrpe-check_ferm_active]
- Alternatives::Select[iptables]
- Ferm::Conf[defs]
- Nrpe::Check[check_ferm_active]
- Exec[update_alternative_ip6tables]
- Monitoring::Exported_nagios_service[rdb2013 ferm_active]
- Package[ulogd2]
- File[/var/log/ulogd]
- Exec[systemd daemon-reload for nrpe2nodexp-ferm_active.timer (nrpe2nodexp-ferm_active.timer)]
- Systemd::Unit[nrpe2nodexp-ferm_active.service]
- File[/lib/systemd/system/wmf_auto_restart_ulogd2.timer]
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp]
- Ferm::Rule[log-everything]
- Exec[systemd daemon-reload for ferm.service (ferm-ferm-service-status-restart)]
- File[/etc/ferm/conf.d/99_dscp-default]
- Service[wmf_auto_restart_ulogd2.timer]
Resources modified
- File[/etc/nftables/main.nft]
- Parameters differences:
--- File[/etc/nftables/main.nft].orig +++ File[/etc/nftables/main.nft] + ensure => present + require => File[/etc/nftables] + notify => Service[nftables] + group => root + source => puppet:///modules/nftables/main.nft + owner => root
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft].orig +++ File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft.orig +++ /etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft @@ -0,0 +1,191 @@ +# Autogenerated by puppet +set PRODUCTION_NETWORKS_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2001:df2:e500:101::/64, + 2001:df2:e500:102::/64, + 2001:df2:e500:103::/64, + 2001:df2:e500:1::/64, + 2001:df2:e500:2::/64, + 2001:df2:e500:3::/64, + 2001:df2:e500:ed1a::/64, + 2620:0:860:100::/64, + 2620:0:860:101::/64, + 2620:0:860:102::/64, + 2620:0:860:103::/64, + 2620:0:860:104::/64, + 2620:0:860:105::/64, + 2620:0:860:106::/64, + 2620:0:860:107::/64, + 2620:0:860:108::/64, + 2620:0:860:109::/64, + 2620:0:860:10a::/64, + 2620:0:860:10b::/64, + 2620:0:860:10c::/64, + 2620:0:860:10d::/64, + 2620:0:860:10e::/64, + 2620:0:860:10f::/64, + 2620:0:860:110::/64, + 2620:0:860:111::/64, + 2620:0:860:112::/64, + 2620:0:860:113::/64, + 2620:0:860:114::/64, + 2620:0:860:115::/64, + 2620:0:860:116::/64, + 2620:0:860:118::/64, + 2620:0:860:119::/64, + 2620:0:860:11a::/64, + 2620:0:860:11b::/64, + 2620:0:860:11c::/64, + 2620:0:860:11d::/64, + 2620:0:860:11e::/64, + 2620:0:860:11f::/64, + 2620:0:860:120::/64, + 2620:0:860:121::/64, + 2620:0:860:122::/64, + 2620:0:860:123::/64, + 2620:0:860:124::/64, + 2620:0:860:125::/64, + 2620:0:860:126::/64, + 2620:0:860:127::/64, + 2620:0:860:12b::/64, + 2620:0:860:12c::/64, + 2620:0:860:12d::/64, + 2620:0:860:12e::/64, + 2620:0:860:140::/64, + 2620:0:860:1::/64, + 2620:0:860:2::/64, + 2620:0:860:300::/64, + 2620:0:860:301::/64, + 2620:0:860:302::/64, + 2620:0:860:303::/64, + 2620:0:860:304::/64, + 2620:0:860:305::/64, + 2620:0:860:307::/64, + 2620:0:860:308::/64, + 2620:0:860:3::/64, + 2620:0:860:4::/64, + 2620:0:860:5::/64, + 2620:0:860:6::/64, + 2620:0:860:7::/64, + 2620:0:860:8::/64, + 2620:0:860:babe::/64, + 2620:0:860:babf::/64, + 2620:0:860:cabe::/64, + 2620:0:860:cabf::/64, + 2620:0:860:ed1a::/64, + 2620:0:861:100::/64, + 2620:0:861:101::/64, + 2620:0:861:102::/64, + 2620:0:861:103::/64, + 2620:0:861:104::/64, + 2620:0:861:105::/64, + 2620:0:861:106::/64, + 2620:0:861:107::/64, + 2620:0:861:108::/64, + 2620:0:861:109::/64, + 2620:0:861:10a::/64, + 2620:0:861:10b::/64, + 2620:0:861:10c::/64, + 2620:0:861:10d::/64, + 2620:0:861:10e::/64, + 2620:0:861:10f::/64, + 2620:0:861:110::/64, + 2620:0:861:111::/64, + 2620:0:861:112::/64, + 2620:0:861:113::/64, + 2620:0:861:114::/64, + 2620:0:861:115::/64, + 2620:0:861:116::/64, + 2620:0:861:117::/64, + 2620:0:861:118::/64, + 2620:0:861:119::/64, + 2620:0:861:11a::/64, + 2620:0:861:11c::/64, + 2620:0:861:11d::/64, + 2620:0:861:11e::/64, + 2620:0:861:11f::/64, + 2620:0:861:120::/64, + 2620:0:861:121::/64, + 2620:0:861:122::/64, + 2620:0:861:123::/64, + 2620:0:861:124::/64, + 2620:0:861:125::/64, + 2620:0:861:126::/64, + 2620:0:861:127::/64, + 2620:0:861:128::/64, + 2620:0:861:129::/64, + 2620:0:861:12a::/64, + 2620:0:861:12b::/64, + 2620:0:861:12c::/64, + 2620:0:861:12d::/64, + 2620:0:861:12e::/64, + 2620:0:861:12f::/64, + 2620:0:861:131::/64, + 2620:0:861:132::/64, + 2620:0:861:133::/64, + 2620:0:861:134::/64, + 2620:0:861:135::/64, + 2620:0:861:136::/64, + 2620:0:861:137::/64, + 2620:0:861:138::/64, + 2620:0:861:139::/64, + 2620:0:861:13a::/64, + 2620:0:861:13b::/64, + 2620:0:861:13c::/64, + 2620:0:861:13d::/64, + 2620:0:861:13e::/64, + 2620:0:861:13f::/64, + 2620:0:861:140::/64, + 2620:0:861:141::/64, + 2620:0:861:142::/64, + 2620:0:861:143::/64, + 2620:0:861:144::/64, + 2620:0:861:145::/64, + 2620:0:861:1::/64, + 2620:0:861:2::/64, + 2620:0:861:300::/64, + 2620:0:861:301::/116, + 2620:0:861:302::/64, + 2620:0:861:303::/116, + 2620:0:861:304::/116, + 2620:0:861:305::/64, + 2620:0:861:3::/64, + 2620:0:861:4::/64, + 2620:0:861:6::/64, + 2620:0:861:7::/64, + 2620:0:861:8::/64, + 2620:0:861:babe::/64, + 2620:0:861:babf::/116, + 2620:0:861:cabe::/64, + 2620:0:861:cabf::/116, + 2620:0:861:ed1a::/64, + 2620:0:863:101::/64, + 2620:0:863:102::/64, + 2620:0:863:103::/64, + 2620:0:863:1::/64, + 2620:0:863:2::/64, + 2620:0:863:3::/64, + 2620:0:863:ed1a::/64, + 2a02:ec80:300:101::/64, + 2a02:ec80:300:102::/64, + 2a02:ec80:300:103::/64, + 2a02:ec80:300:1::/64, + 2a02:ec80:300:2::/64, + 2a02:ec80:300:3::/64, + 2a02:ec80:300:ed1a::/64, + 2a02:ec80:600:101::/64, + 2a02:ec80:600:102::/64, + 2a02:ec80:600:1::/64, + 2a02:ec80:600:2::/64, + 2a02:ec80:600:ed1a::/64, + 2a02:ec80:700:101::/64, + 2a02:ec80:700:102::/64, + 2a02:ec80:700:103::/64, + 2a02:ec80:700:1::/64, + 2a02:ec80:700:2::/64, + 2a02:ec80:700:3::/64, + 2a02:ec80:700:ed1a::/64 + } +}- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft].orig +++ File[/etc/nftables/sets/MGMT_NETWORKS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/MGMT_NETWORKS_ipv4.nft.orig +++ /etc/nftables/sets/MGMT_NETWORKS_ipv4.nft @@ -0,0 +1,14 @@ +# Autogenerated by puppet +set MGMT_NETWORKS_ipv4 { + type ipv4_addr + flags interval + auto-merge + elements = { 10.65.0.0/16, + 10.128.128.0/17, + 10.193.0.0/16, + 10.80.128.0/17, + 10.132.128.0/17, + 10.136.128.0/17, + 10.140.128.0/17 + } +}- File[/etc/rsyslog.d/40-ulogd.conf]
- Parameters differences:
--- File[/etc/rsyslog.d/40-ulogd.conf].orig +++ File[/etc/rsyslog.d/40-ulogd.conf] - ensure => present - notify => Service[rsyslog] - group => root - owner => root - mode => 0444
- Content differences:
--- /etc/rsyslog.d/40-ulogd.conf.orig +++ /etc/rsyslog.d/40-ulogd.conf @@ -1,10 +0,0 @@ -# rsyslog.conf(5) configuration file for services. -# This file is managed by Puppet. -if $programname startswith "ulogd" then { - action( - type="omfile" file="/var/log/ulogd/syslog.log" - fileOwner="root" fileGroup="root" - fileCreateMode="0600" - ) - & stop -}- Nftables::Set[CUMIN_MASTERS]
- Parameters differences:
--- Nftables::Set[CUMIN_MASTERS].orig +++ Nftables::Set[CUMIN_MASTERS] + ensure => present + hosts => ['10.64.16.154', '2620:0:861:102:10:64:16:154', '10.192.32.49', '2620:0:860:103:10:192:32:49']
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft].orig +++ File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft.orig +++ /etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft @@ -0,0 +1,27 @@ +# Autogenerated by puppet +set CLOUD_NETWORKS_ipv4 { + type ipv4_addr + flags interval + auto-merge + elements = { 172.16.0.0/21, + 172.16.128.0/24, + 172.16.129.0/24, + 172.16.130.0/24, + 172.16.131.0/24, + 172.16.16.0/21, + 172.16.24.0/24, + 172.16.8.0/21, + 172.20.1.0/24, + 172.20.2.0/24, + 172.20.254.0/24, + 172.20.255.0/24, + 172.20.3.0/24, + 172.20.4.0/24, + 172.20.5.0/24, + 185.15.56.0/25, + 185.15.56.160/28, + 185.15.57.0/29, + 185.15.57.16/29, + 185.15.57.24/29 + } +}- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft].orig +++ File[/etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft.orig +++ /etc/nftables/sets/DSE_KUBEPODS_NETWORKS_ipv6.nft @@ -0,0 +1,9 @@ +# Autogenerated by puppet +set DSE_KUBEPODS_NETWORKS_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2620:0:861:302::/64, + 2620:0:860:308::/64 + } +}- Logrotate::Conf[wmf_auto_restart_ulogd2]
- Parameters differences:
--- Logrotate::Conf[wmf_auto_restart_ulogd2].orig +++ Logrotate::Conf[wmf_auto_restart_ulogd2] - ensure => present
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft].orig +++ File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft.orig +++ /etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft @@ -0,0 +1,9 @@ +# Autogenerated by puppet +set STAGING_KUBEPODS_NETWORKS_ipv4 { + type ipv4_addr + flags interval + auto-merge + elements = { 10.64.64.0/21, + 10.192.64.0/21 + } +}- Nftables::Set[MW_APPSERVER_NETWORKS]
- Parameters differences:
--- Nftables::Set[MW_APPSERVER_NETWORKS].orig +++ Nftables::Set[MW_APPSERVER_NETWORKS] + ensure => present + hosts => ['10.64.0.0/22', '10.64.130.0/24', '10.64.131.0/24', '10.64.132.0/24', '10.64.133.0/24', '10.64.134.0/24', '10.64.135.0/24', '10.64.136.0/24', '10.64.141.0/24', '10.64.152.0/24', '10.64.154.0/24', '10.64.156.0/24', '10.64.158.0/24', '10.64.16.0/22', '10.64.160.0/24', '10.64.162.0/24', '10.64.164.0/24', '10.64.166.0/24', '10.64.169.0/24', '10.64.171.0/24', '10.64.173.0/24', '10.64.175.0/24', '10.64.177.0/24', '10.64.179.0/24', '10.64.181.0/24', '10.64.183.0/24', '10.64.185.0/24', '10.64.187.0/24', '10.64.189.0/24', '10.64.32.0/22', '10.64.48.0/22', '2620:0:861:101::/64', '2620:0:861:102::/64', '2620:0:861:103::/64', '2620:0:861:107::/64', '2620:0:861:109::/64', '2620:0:861:10a::/64', '2620:0:861:10b::/64', '2620:0:861:10c::/64', '2620:0:861:10d::/64', '2620:0:861:10e::/64', '2620:0:861:10f::/64', '2620:0:861:113::/64', '2620:0:861:119::/64', '2620:0:861:120::/64', '2620:0:861:122::/64', '2620:0:861:124::/64', '2620:0:861:126::/64', '2620:0:861:128::/64', '2620:0:861:12a::/64', '2620:0:861:12c::/64', '2620:0:861:12e::/64', '2620:0:861:131::/64', '2620:0:861:133::/64', '2620:0:861:135::/64', '2620:0:861:137::/64', '2620:0:861:139::/64', '2620:0:861:13b::/64', '2620:0:861:13d::/64', '2620:0:861:13f::/64', '2620:0:861:142::/64', '2620:0:861:144::/64', '10.192.0.0/22', '10.192.10.0/24', '10.192.11.0/24', '10.192.12.0/24', '10.192.13.0/24', '10.192.14.0/24', '10.192.15.0/24', '10.192.16.0/22', '10.192.21.0/24', '10.192.22.0/24', '10.192.23.0/24', '10.192.26.0/24', '10.192.27.0/24', '10.192.28.0/24', '10.192.29.0/24', '10.192.30.0/24', '10.192.31.0/24', '10.192.32.0/22', '10.192.36.0/24', '10.192.37.0/24', '10.192.38.0/24', '10.192.39.0/24', '10.192.4.0/24', '10.192.40.0/24', '10.192.41.0/24', '10.192.42.0/24', '10.192.43.0/24', '10.192.44.0/24', '10.192.45.0/24', '10.192.46.0/24', '10.192.47.0/24', '10.192.48.0/22', '10.192.5.0/24', '10.192.52.0/24', '10.192.56.0/24', '10.192.57.0/24', '10.192.58.0/24', '10.192.59.0/24', '10.192.6.0/24', '10.192.7.0/24', '10.192.8.0/24', '10.192.9.0/24', '2620:0:860:100::/64', '2620:0:860:101::/64', '2620:0:860:102::/64', '2620:0:860:103::/64', '2620:0:860:104::/64', '2620:0:860:105::/64', '2620:0:860:106::/64', '2620:0:860:107::/64', '2620:0:860:108::/64', '2620:0:860:109::/64', '2620:0:860:10a::/64', '2620:0:860:10b::/64', '2620:0:860:10c::/64', '2620:0:860:10d::/64', '2620:0:860:10e::/64', '2620:0:860:10f::/64', '2620:0:860:110::/64', '2620:0:860:111::/64', '2620:0:860:112::/64', '2620:0:860:113::/64', '2620:0:860:114::/64', '2620:0:860:115::/64', '2620:0:860:116::/64', '2620:0:860:119::/64', '2620:0:860:11a::/64', '2620:0:860:11b::/64', '2620:0:860:11c::/64', '2620:0:860:11d::/64', '2620:0:860:11e::/64', '2620:0:860:11f::/64', '2620:0:860:120::/64', '2620:0:860:121::/64', '2620:0:860:122::/64', '2620:0:860:123::/64', '2620:0:860:124::/64', '2620:0:860:125::/64', '2620:0:860:126::/64', '2620:0:860:127::/64', '2620:0:860:12b::/64', '2620:0:860:12c::/64', '2620:0:860:12d::/64', '2620:0:860:12e::/64', '10.192.64.0/21', '10.192.96.0/21', '10.194.128.0/17', '10.194.16.0/21', '10.194.61.0/24', '10.194.80.0/21', '10.64.64.0/21', '10.67.128.0/17', '10.67.16.0/21', '10.67.24.0/21', '10.67.80.0/21', '2620:0:860:300::/64', '2620:0:860:302::/64', '2620:0:860:305::/64', '2620:0:860:308::/64', '2620:0:860:babe::/64', '2620:0:860:cabe::/64', '2620:0:861:300::/64', '2620:0:861:302::/64', '2620:0:861:305::/64', '2620:0:861:babe::/64', '2620:0:861:cabe::/64', '208.80.154.0/26', '208.80.154.128/26', '208.80.154.64/26', '208.80.155.96/27', '2620:0:861:1::/64', '2620:0:861:2::/64', '2620:0:861:3::/64', '2620:0:861:4::/64', '208.80.153.0/27', '208.80.153.32/27', '208.80.153.64/27', '208.80.153.96/27', '2620:0:860:1::/64', '2620:0:860:2::/64', '2620:0:860:3::/64', '2620:0:860:4::/64']
- Confd::File[/etc/ferm/conf.d/00_defs_requestctl]
- Parameters differences:
--- Confd::File[/etc/ferm/conf.d/00_defs_requestctl].orig +++ Confd::File[/etc/ferm/conf.d/00_defs_requestctl] @@ - ensure => present + ensure => absent
- Nftables::Set[INSTALL_HOSTS]
- Parameters differences:
--- Nftables::Set[INSTALL_HOSTS].orig +++ Nftables::Set[INSTALL_HOSTS] + ensure => present + hosts => ['208.80.154.134', '208.80.153.70', '185.15.59.101', '198.35.26.98', '103.102.166.104', '185.15.58.7', '195.200.68.100', '2620:0:861:2:208:80:154:134', '2620:0:860:3:208:80:153:70', '2a02:ec80:300:3:185:15:59:101', '2620:0:863:3:198:35:26:98', '2001:df2:e500:3:103:102:166:104', '2a02:ec80:600:1:185:15:58:7', '2a02:ec80:700:3:195:200:68:100']
- Class[Profile::Firewall::Log::Ferm]
- Parameters differences:
--- Class[Profile::Firewall::Log::Ferm].orig +++ Class[Profile::Firewall::Log::Ferm] - log_rate => 1/second - log_burst => 5 - separate_file => True
- Sudo::User[nrpe-check_ferm_active]
- Parameters differences:
--- Sudo::User[nrpe-check_ferm_active].orig +++ Sudo::User[nrpe-check_ferm_active] - ensure => present - tag => nrpe::check - require => ['Class[Sudo]'] - user => nagios - privileges => ['ALL = (root) NOPASSWD: /usr/local/lib/nagios/plugins/check_ferm']
- File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft].orig +++ File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/BASTION_HOSTS_ipv4.nft.orig +++ /etc/nftables/sets/BASTION_HOSTS_ipv4.nft @@ -0,0 +1,12 @@ +# Autogenerated by puppet +set BASTION_HOSTS_ipv4 { + type ipv4_addr + elements = { 208.80.154.7, + 208.80.153.110, + 185.15.59.99, + 198.35.26.104, + 103.102.166.103, + 185.15.58.6, + 195.200.68.99 + } +}- File[/var/log/ulogd]
- Parameters differences:
--- File[/var/log/ulogd].orig +++ File[/var/log/ulogd] - ensure => directory - force => True - backup => False - group => root - owner => root - mode => 0755
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft].orig +++ File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft.orig +++ /etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft @@ -0,0 +1,7 @@ +# Autogenerated by puppet +set DEPLOYMENT_HOSTS_ipv6 { + type ipv6_addr + elements = { 2620:0:861:102:10:64:16:93, + 2620:0:860:103:10:192:32:7 + } +}- File[/usr/local/bin/check-nft]
- Parameters differences:
--- File[/usr/local/bin/check-nft].orig +++ File[/usr/local/bin/check-nft] + ensure => present + group => root + source => puppet:///modules/profile/firewall/check_nftables.py + owner => root + mode => 0555
- Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c]
- Parameters differences:
--- Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c].orig +++ Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c] - ensure => present - alert_name => nrpe_Check_whether_ferm_is_active_by_checking_the_default_input_chain - summary => NRPE CHECK: Check whether ferm is active by checking the default input chain - site => codfw - for => 32m - dashboard => TODO - instance => ops - description => NRPE CHECK: Check whether ferm is active by checking the default input chain - expr => (nagios_nrpe_check_result{alert_rule_hash="bba0a2572329bb500b832470e08b381c",check_name="check_ferm_active", status=~"(WARNING|CRITICAL)", severity=~"(warning|critical)"} > 0) * on (instance) group_left (team) role_owner - def_label_whitelst => ['team', 'severity'] - logs => https://logstash.wikimedia.org/app/dashboards#/view/2d343ac0-6df8-11f0-8e08-7fab0da52b33?_g=(filters:!((query:(match_phrase:(event.module:check_ferm_active))),(query:(match_phrase:(host.name:{{$labels.instance|stripPort}}))))) - team => observability - group => nrpechecks - runbook => https://wikitech.wikimedia.org/wiki/Monitoring/check_ferm - severity => info- Systemd::Unit[wmf_auto_restart_ulogd2.service]
- Parameters differences:
--- Systemd::Unit[wmf_auto_restart_ulogd2.service].orig +++ Systemd::Unit[wmf_auto_restart_ulogd2.service] - ensure => present - unit => wmf_auto_restart_ulogd2.service - override => False - require => ['Class[Systemd]'] - override_filename => puppet-override.conf - restart => False
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft].orig +++ File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft.orig +++ /etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft @@ -0,0 +1,38 @@ +# Autogenerated by puppet +set ANALYTICS_NETWORKS_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2620:0:861:100::/64, + 2620:0:861:104::/64, + 2620:0:861:105::/64, + 2620:0:861:106::/64, + 2620:0:861:108::/64, + 2620:0:861:110::/64, + 2620:0:861:111::/64, + 2620:0:861:112::/64, + 2620:0:861:114::/64, + 2620:0:861:115::/64, + 2620:0:861:116::/64, + 2620:0:861:117::/64, + 2620:0:861:11a::/64, + 2620:0:861:121::/64, + 2620:0:861:123::/64, + 2620:0:861:125::/64, + 2620:0:861:127::/64, + 2620:0:861:129::/64, + 2620:0:861:12b::/64, + 2620:0:861:12d::/64, + 2620:0:861:12f::/64, + 2620:0:861:132::/64, + 2620:0:861:134::/64, + 2620:0:861:136::/64, + 2620:0:861:138::/64, + 2620:0:861:13a::/64, + 2620:0:861:13c::/64, + 2620:0:861:13e::/64, + 2620:0:861:141::/64, + 2620:0:861:143::/64, + 2620:0:861:145::/64 + } +}- File[/etc/nftables/sets/INTERNAL_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/INTERNAL_ipv6.nft].orig +++ File[/etc/nftables/sets/INTERNAL_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/INTERNAL_ipv6.nft.orig +++ /etc/nftables/sets/INTERNAL_ipv6.nft @@ -0,0 +1,15 @@ +# Autogenerated by puppet +set INTERNAL_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2620:0:860:100::/56, + 2620:0:861:100::/56, + 2620:0:863:100::/56, + 2a02:ec80:300:100::/56, + 2a02:ec80:600:100::/56, + 2a02:ec80:700:100::/56, + 2001:df2:e500:100::/56, + 2a02:ec80:ff00:100::/56 + } +}- Systemd::Service[prometheus-node-textfile-check-nft]
- Parameters differences:
--- Systemd::Service[prometheus-node-textfile-check-nft].orig +++ Systemd::Service[prometheus-node-textfile-check-nft] + ensure => present + monitoring_contact_group => admins + unit_type => timer + migration_task => T407130 + restart => False + service_params => {} + monitoring_enabled => False + override => False + require => Systemd::Unit[prometheus-node-textfile-check-nft.service] + monitoring_critical => False- Systemd::Timer[wmf_auto_restart_ulogd2]
- Parameters differences:
--- Systemd::Timer[wmf_auto_restart_ulogd2].orig +++ Systemd::Timer[wmf_auto_restart_ulogd2] - ensure => present - splay => 0 - fixed_random_delay => False - timer_intervals => [{'start': 'OnCalendar', 'interval': 'Mon,Tue,Wed,Thu,Fri *-*-* 18:28:00'}] - accuracy => 15sec - unit_name => wmf_auto_restart_ulogd2.service- File[/etc/ferm/conf.d/00_defs_requestctl]
- Parameters differences:
--- File[/etc/ferm/conf.d/00_defs_requestctl].orig +++ File[/etc/ferm/conf.d/00_defs_requestctl] @@ - ensure => file + ensure => absent
- File[/var/log/prometheus-node-textfile-check-nft]
- Parameters differences:
--- File[/var/log/prometheus-node-textfile-check-nft].orig +++ File[/var/log/prometheus-node-textfile-check-nft] + ensure => directory + force => True + backup => False + group => root + owner => root + mode => 0755
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft].orig +++ File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft.orig +++ /etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft @@ -0,0 +1,9 @@ +# Autogenerated by puppet +set AUX_KUBEPODS_NETWORKS_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2620:0:861:305::/64, + 2620:0:860:305::/64 + } +}- Systemd::Unit[nftables]
- Parameters differences:
--- Systemd::Unit[nftables].orig +++ Systemd::Unit[nftables] + ensure => present + unit => nftables + override => True + require => ['Class[Systemd]'] + override_filename => puppet-override.conf + restart => False
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft].orig +++ File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft.orig +++ /etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft @@ -0,0 +1,14 @@ +# Autogenerated by puppet +set KAFKA_BROKERS_JUMBO_ipv4 { + type ipv4_addr + elements = { 10.64.130.10, + 10.64.131.16, + 10.64.132.21, + 10.64.134.9, + 10.64.135.16, + 10.64.136.11, + 10.64.154.15, + 10.64.160.16, + 10.64.0.126 + } +}- Systemd::Timer::Job[nrpe2nodexp-ferm_active]
- Parameters differences:
--- Systemd::Timer::Job[nrpe2nodexp-ferm_active].orig +++ Systemd::Timer::Job[nrpe2nodexp-ferm_active] - monitoring_notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - logfile_group => root - fixed_random_delay => True - syslog_force_stop => True - send_mail_only_on_error => True - send_mail => False - interval => [{'start': 'OnUnitInactiveSec', 'interval': '10min'}] - logfile_perms => all - splay => 600 - description => execution of nrpe2nodexp for the check_ferm_active command. - environment => {} - send_mail_to => root@rdb2013.codfw.wmnet - monitoring_contact_groups => admins - ignore_errors => True - ensure => present - syslog_match_startswith => True - user => nagios - logfile_basedir => /var/log - logfile_name => syslog.log - command => /usr/local/bin/nrpe2nodexp --alert-rule-hash "bba0a2572329bb500b832470e08b381c" --timeout 10 --check-command "check_ferm_active" - logging_enabled => False - monitoring_enabled => False - private_tmp => False - success_exit_status => [] - syslog_identifier => nrpe2nodexp-ferm_active - group => prometheus-node-exporter- File[/lib/systemd/system/nrpe2nodexp-ferm_active.service]
- Parameters differences:
--- File[/lib/systemd/system/nrpe2nodexp-ferm_active.service].orig +++ File[/lib/systemd/system/nrpe2nodexp-ferm_active.service] - ensure => present - notify => Exec[systemd daemon-reload for nrpe2nodexp-ferm_active.service (nrpe2nodexp-ferm_active.service)] - group => root - owner => root - mode => 0444
- Content differences:
--- /lib/systemd/system/nrpe2nodexp-ferm_active.service.orig +++ /lib/systemd/system/nrpe2nodexp-ferm_active.service @@ -1,11 +0,0 @@ -[Unit] -Description=execution of nrpe2nodexp for the check_ferm_active command. -Documentation=https://wikitech.wikimedia.org/wiki/Monitoring/systemd_unit_state - -[Service] -Type=oneshot -User=nagios - -Group=prometheus-node-exporter -SyslogIdentifier=nrpe2nodexp-ferm_active -ExecStart=-/usr/local/bin/nrpe2nodexp --alert-rule-hash "bba0a2572329bb500b832470e08b381c" --timeout 10 --check-command "check_ferm_active"
- Nftables::Set[CLOUD_PRIVATE_NETWORKS]
- Parameters differences:
--- Nftables::Set[CLOUD_PRIVATE_NETWORKS].orig +++ Nftables::Set[CLOUD_PRIVATE_NETWORKS] + ensure => present + hosts => ['172.20.1.0/24', '172.20.2.0/24', '172.20.3.0/24', '172.20.4.0/24', '2a02:ec80:a000:201::/64', '2a02:ec80:a000:202::/64', '2a02:ec80:a000:203::/64', '2a02:ec80:a000:204::/64', '172.20.5.0/24', '2a02:ec80:a100:205::/64']
- Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS]
- Parameters differences:
--- Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS].orig +++ Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS] + ensure => present + hosts => ['10.194.61.0/24', '2620:0:860:302::/64']
- Nrpe::Monitor_service[ferm_active]
- Parameters differences:
--- Nrpe::Monitor_service[ferm_active].orig +++ Nrpe::Monitor_service[ferm_active] - critical => False - contact_group => admins - check_interval => 30 - alertmanager_team => observability - sudo_user => root - timeout => 10 - description => Check whether ferm is active by checking the default input chain - retry_interval => 1 - enable_icinga_check => True - nrpe2nodexp_parse_perf_data => False - ensure => present - migration_task => T350694 - enable_nrpe2nodexp => True - notes_url => https://wikitech.wikimedia.org/wiki/Monitoring/check_ferm - nrpe_command => /usr/local/lib/nagios/plugins/check_ferm - retries => 3
- File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft].orig +++ File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/LINK_LOCAL_ipv4.nft.orig +++ /etc/nftables/sets/LINK_LOCAL_ipv4.nft @@ -0,0 +1,8 @@ +# Autogenerated by puppet +set LINK_LOCAL_ipv4 { + type ipv4_addr + flags interval + auto-merge + elements = { 169.254.0.0/16 + } +}- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft].orig +++ File[/etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft.orig +++ /etc/nftables/sets/MW_APPSERVER_NETWORKS_ipv4.nft @@ -0,0 +1,99 @@ +# Autogenerated by puppet +set MW_APPSERVER_NETWORKS_ipv4 { + type ipv4_addr + flags interval + auto-merge + elements = { 10.64.0.0/22, + 10.64.130.0/24, + 10.64.131.0/24, + 10.64.132.0/24, + 10.64.133.0/24, + 10.64.134.0/24, + 10.64.135.0/24, + 10.64.136.0/24, + 10.64.141.0/24, + 10.64.152.0/24, + 10.64.154.0/24, + 10.64.156.0/24, + 10.64.158.0/24, + 10.64.16.0/22, + 10.64.160.0/24, + 10.64.162.0/24, + 10.64.164.0/24, + 10.64.166.0/24, + 10.64.169.0/24, + 10.64.171.0/24, + 10.64.173.0/24, + 10.64.175.0/24, + 10.64.177.0/24, + 10.64.179.0/24, + 10.64.181.0/24, + 10.64.183.0/24, + 10.64.185.0/24, + 10.64.187.0/24, + 10.64.189.0/24, + 10.64.32.0/22, + 10.64.48.0/22, + 10.192.0.0/22, + 10.192.10.0/24, + 10.192.11.0/24, + 10.192.12.0/24, + 10.192.13.0/24, + 10.192.14.0/24, + 10.192.15.0/24, + 10.192.16.0/22, + 10.192.21.0/24, + 10.192.22.0/24, + 10.192.23.0/24, + 10.192.26.0/24, + 10.192.27.0/24, + 10.192.28.0/24, + 10.192.29.0/24, + 10.192.30.0/24, + 10.192.31.0/24, + 10.192.32.0/22, + 10.192.36.0/24, + 10.192.37.0/24, + 10.192.38.0/24, + 10.192.39.0/24, + 10.192.4.0/24, + 10.192.40.0/24, + 10.192.41.0/24, + 10.192.42.0/24, + 10.192.43.0/24, + 10.192.44.0/24, + 10.192.45.0/24, + 10.192.46.0/24, + 10.192.47.0/24, + 10.192.48.0/22, + 10.192.5.0/24, + 10.192.52.0/24, + 10.192.56.0/24, + 10.192.57.0/24, + 10.192.58.0/24, + 10.192.59.0/24, + 10.192.6.0/24, + 10.192.7.0/24, + 10.192.8.0/24, + 10.192.9.0/24, + 10.192.64.0/21, + 10.192.96.0/21, + 10.194.128.0/17, + 10.194.16.0/21, + 10.194.61.0/24, + 10.194.80.0/21, + 10.64.64.0/21, + 10.67.128.0/17, + 10.67.16.0/21, + 10.67.24.0/21, + 10.67.80.0/21, + 208.80.154.0/26, + 208.80.154.128/26, + 208.80.154.64/26, + 208.80.155.96/27, + 208.80.153.0/27, + 208.80.153.32/27, + 208.80.153.64/27, + 208.80.153.96/27 + } +}- Rsyslog::Conf[prometheus-node-textfile-check-nft]
- Parameters differences:
--- Rsyslog::Conf[prometheus-node-textfile-check-nft].orig +++ Rsyslog::Conf[prometheus-node-textfile-check-nft] + ensure => present + priority => 40 + require => File[/var/log/prometheus-node-textfile-check-nft] + mode => 0444
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft].orig +++ File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft.orig +++ /etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft @@ -0,0 +1,191 @@ +# Autogenerated by puppet +set LOAD_BALANCER_HEALTH_CHECKS_ipv4 { + type ipv4_addr + elements = { 10.64.131.17, + 10.64.16.60, + 10.64.158.19, + 10.64.166.19, + 10.64.133.19, + 10.64.141.19, + 10.64.169.19, + 10.64.171.19, + 10.64.173.19, + 10.64.175.19, + 10.64.177.19, + 10.64.179.19, + 10.64.181.19, + 10.64.183.19, + 10.64.185.19, + 10.64.187.19, + 10.64.189.19, + 10.64.48.72, + 10.64.37.17, + 10.64.1.17, + 10.64.17.17, + 10.64.33.17, + 10.64.130.20, + 10.64.131.20, + 10.64.132.20, + 10.64.134.20, + 10.64.135.20, + 10.64.136.20, + 10.64.158.20, + 10.64.166.20, + 10.64.133.20, + 10.64.141.20, + 10.64.169.20, + 10.64.171.20, + 10.64.173.20, + 10.64.175.20, + 10.64.177.20, + 10.64.179.20, + 10.64.181.20, + 10.64.183.20, + 10.64.185.20, + 10.64.187.20, + 10.64.189.20, + 10.192.23.8, + 10.192.0.29, + 10.192.17.8, + 10.192.33.8, + 10.192.49.8, + 10.192.23.2, + 10.192.5.2, + 10.192.6.2, + 10.192.7.2, + 10.192.8.2, + 10.192.9.2, + 10.192.10.2, + 10.192.11.2, + 10.192.12.2, + 10.192.13.2, + 10.192.14.2, + 10.192.15.2, + 10.192.21.2, + 10.192.22.2, + 10.192.4.2, + 10.192.26.2, + 10.192.27.2, + 10.192.28.2, + 10.192.29.2, + 10.192.30.2, + 10.192.31.2, + 10.192.36.2, + 10.192.37.2, + 10.192.38.2, + 10.192.39.2, + 10.192.40.2, + 10.192.41.2, + 10.192.42.2, + 10.192.43.2, + 10.192.11.8, + 10.192.16.140, + 10.192.1.8, + 10.192.33.9, + 10.192.49.9, + 10.192.23.3, + 10.192.5.3, + 10.192.6.3, + 10.192.7.3, + 10.192.8.3, + 10.192.9.3, + 10.192.10.3, + 10.192.11.3, + 10.192.12.3, + 10.192.13.3, + 10.192.14.3, + 10.192.15.3, + 10.192.21.3, + 10.192.22.3, + 10.192.4.3, + 10.192.26.3, + 10.192.27.3, + 10.192.28.3, + 10.192.29.3, + 10.192.30.3, + 10.192.31.3, + 10.192.36.3, + 10.192.37.3, + 10.192.38.3, + 10.192.39.4, + 10.192.40.3, + 10.192.41.3, + 10.192.42.3, + 10.192.43.3, + 10.192.32.14, + 10.192.1.9, + 10.192.17.9, + 10.192.49.10, + 10.192.23.4, + 10.192.5.4, + 10.192.6.4, + 10.192.7.4, + 10.192.8.4, + 10.192.9.4, + 10.192.10.4, + 10.192.11.4, + 10.192.12.4, + 10.192.13.4, + 10.192.14.4, + 10.192.15.4, + 10.192.21.4, + 10.192.22.4, + 10.192.4.5, + 10.192.26.5, + 10.192.27.5, + 10.192.28.5, + 10.192.29.5, + 10.192.30.5, + 10.192.31.5, + 10.192.36.5, + 10.192.37.5, + 10.192.38.5, + 10.192.39.6, + 10.192.40.5, + 10.192.41.5, + 10.192.42.5, + 10.192.43.5, + 10.192.48.213, + 10.192.1.13, + 10.192.17.10, + 10.192.33.10, + 10.192.23.5, + 10.192.5.8, + 10.192.6.5, + 10.192.7.5, + 10.192.8.5, + 10.192.9.5, + 10.192.10.5, + 10.192.11.5, + 10.192.12.5, + 10.192.13.5, + 10.192.14.5, + 10.192.15.5, + 10.192.21.5, + 10.192.22.5, + 10.80.0.3, + 10.80.1.8, + 10.80.1.14, + 10.80.0.9, + 10.80.0.2, + 10.80.1.10, + 10.128.1.18, + 10.128.0.9, + 10.128.1.11, + 10.132.0.39, + 10.132.0.6, + 10.132.0.7, + 10.136.0.16, + 10.136.1.19, + 10.136.1.15, + 10.136.0.19, + 10.136.0.17, + 10.136.1.20, + 10.140.0.13, + 10.140.1.2, + 10.140.1.14, + 10.140.0.2, + 10.140.0.14, + 10.140.1.3 + } +}- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft]
- Parameters differences:
--- File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft].orig +++ File[/etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft.orig +++ /etc/nftables/sets/DRUID_PUBLIC_HOSTS_ipv4.nft @@ -0,0 +1,10 @@ +# Autogenerated by puppet +set DRUID_PUBLIC_HOSTS_ipv4 { + type ipv4_addr + elements = { 10.64.131.9, + 10.64.132.12, + 10.64.135.9, + 10.64.32.101, + 10.64.48.185 + } +}- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft]
- Parameters differences:
--- File[/etc/nftables/input/10_ssh-from-cumin-masters.nft].orig +++ File[/etc/nftables/input/10_ssh-from-cumin-masters.nft] + ensure => present + tag => nft + require => ['Nftables::Set[CUMIN_MASTERS]'] + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/input/10_ssh-from-cumin-masters.nft.orig +++ /etc/nftables/input/10_ssh-from-cumin-masters.nft @@ -0,0 +1,4 @@ +# Managed by puppet +# +ip saddr @CUMIN_MASTERS_ipv4 tcp dport { 22 } accept +ip6 saddr @CUMIN_MASTERS_ipv6 tcp dport { 22 } accept- Class[Ferm]
- Parameters differences:
--- Class[Ferm].orig +++ Class[Ferm] @@ - ensure => present + ensure => absent
- File[/etc/nftables/prerouting]
- Parameters differences:
--- File[/etc/nftables/prerouting].orig +++ File[/etc/nftables/prerouting] + ensure => directory + group => root + owner => root + purge => True + recurse => True
- Nrpe::Check[check_ferm_active]
- Parameters differences:
--- Nrpe::Check[check_ferm_active].orig +++ Nrpe::Check[check_ferm_active] - ensure => present - sudo_user => root - command => /usr/local/lib/nagios/plugins/check_ferm - before => Monitoring::Service[ferm_active]
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp]
- Parameters differences:
--- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp].orig +++ File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp] - ensure => present - tag => ferm - require => File[/etc/ferm/conf.d] - notify => Service[ferm] - group => root - owner => root - mode => 0400
- Content differences:
--- /etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp.orig +++ /etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp @@ -1,6 +0,0 @@ -# Autogenerated by puppet. DO NOT EDIT BY HAND! -# -# -&R_SERVICE(tcp, 1:65535, (10.192.16.75 10.192.32.67 10.192.39.10 10.192.9.11 208.80.153.42 208.80.154.78 2620:0:860:102:10:192:16:75 2620:0:860:103:10:192:32:67 2620:0:860:10a:10:192:9:11 2620:0:860:11e:10:192:39:10 2620:0:860:2:208:80:153:42 2620:0:861:3:208:80:154:78)); - -
- Nftables::Set[PRODUCTION_NETWORKS]
- Parameters differences:
--- Nftables::Set[PRODUCTION_NETWORKS].orig +++ Nftables::Set[PRODUCTION_NETWORKS] + ensure => present + hosts => ['10.128.0.0/24', '10.128.1.0/24', '10.128.2.0/24', '10.132.0.0/24', '10.132.1.0/24', '10.132.2.0/24', '10.136.0.0/24', '10.136.1.0/24', '10.140.0.0/24', '10.140.1.0/24', '10.140.2.0/24', '10.192.0.0/22', '10.192.10.0/24', '10.192.11.0/24', '10.192.12.0/24', '10.192.13.0/24', '10.192.14.0/24', '10.192.15.0/24', '10.192.16.0/22', '10.192.20.0/24', '10.192.21.0/24', '10.192.22.0/24', '10.192.23.0/24', '10.192.24.0/23', '10.192.26.0/24', '10.192.27.0/24', '10.192.28.0/24', '10.192.29.0/24', '10.192.30.0/24', '10.192.31.0/24', '10.192.32.0/22', '10.192.36.0/24', '10.192.37.0/24', '10.192.38.0/24', '10.192.39.0/24', '10.192.4.0/24', '10.192.40.0/24', '10.192.41.0/24', '10.192.42.0/24', '10.192.43.0/24', '10.192.44.0/24', '10.192.45.0/24', '10.192.46.0/24', '10.192.47.0/24', '10.192.48.0/22', '10.192.5.0/24', '10.192.52.0/24', '10.192.56.0/24', '10.192.57.0/24', '10.192.58.0/24', '10.192.59.0/24', '10.192.6.0/24', '10.192.64.0/21', '10.192.7.0/24', '10.192.72.0/24', '10.192.76.0/24', '10.192.8.0/24', '10.192.80.0/20', '10.192.9.0/24', '10.192.96.0/21', '10.194.0.0/20', '10.194.128.0/17', '10.194.16.0/21', '10.194.61.0/24', '10.194.62.0/23', '10.194.64.0/20', '10.194.80.0/21', '10.2.1.0/24', '10.2.2.0/24', '10.2.3.0/24', '10.2.4.0/24', '10.2.5.0/24', '10.2.6.0/24', '10.2.7.0/24', '10.64.0.0/22', '10.64.130.0/24', '10.64.131.0/24', '10.64.132.0/24', '10.64.133.0/24', '10.64.134.0/24', '10.64.135.0/24', '10.64.136.0/24', '10.64.137.0/24', '10.64.138.0/24', '10.64.139.0/24', '10.64.140.0/24', '10.64.141.0/24', '10.64.142.0/24', '10.64.143.0/24', '10.64.144.0/24', '10.64.145.0/24', '10.64.148.0/24', '10.64.149.0/24', '10.64.150.0/24', '10.64.151.0/24', '10.64.152.0/24', '10.64.153.0/24', '10.64.154.0/24', '10.64.155.0/24', '10.64.156.0/24', '10.64.157.0/24', '10.64.158.0/24', '10.64.159.0/24', '10.64.16.0/22', '10.64.160.0/24', '10.64.161.0/24', '10.64.162.0/24', '10.64.163.0/24', '10.64.164.0/24', '10.64.165.0/24', '10.64.166.0/24', '10.64.167.0/24', '10.64.169.0/24', '10.64.170.0/24', '10.64.171.0/24', '10.64.172.0/24', '10.64.173.0/24', '10.64.174.0/24', '10.64.175.0/24', '10.64.176.0/24', '10.64.177.0/24', '10.64.178.0/24', '10.64.179.0/24', '10.64.180.0/24', '10.64.181.0/24', '10.64.182.0/24', '10.64.183.0/24', '10.64.184.0/24', '10.64.185.0/24', '10.64.186.0/24', '10.64.187.0/24', '10.64.188.0/24', '10.64.189.0/24', '10.64.190.0/24', '10.64.20.0/24', '10.64.21.0/24', '10.64.24.0/23', '10.64.32.0/22', '10.64.36.0/24', '10.64.48.0/22', '10.64.5.0/24', '10.64.53.0/24', '10.64.64.0/21', '10.64.72.0/24', '10.64.76.0/24', '10.67.0.0/20', '10.67.128.0/17', '10.67.16.0/21', '10.67.24.0/21', '10.67.32.0/20', '10.67.64.0/20', '10.67.80.0/21', '10.80.0.0/24', '10.80.1.0/24', '10.80.2.0/24', '103.102.166.0/28', '103.102.166.224/27', '103.102.166.32/27', '103.102.166.96/27', '185.15.58.0/27', '185.15.58.224/27', '185.15.58.32/27', '185.15.59.0/27', '185.15.59.224/27', '185.15.59.32/27', '185.15.59.96/27', '195.200.68.0/27', '195.200.68.224/27', '195.200.68.32/27', '195.200.68.96/27', '198.35.26.0/27', '198.35.26.32/27', '198.35.26.96/27', '198.35.26.96/27', '2001:df2:e500:101::/64', '2001:df2:e500:102::/64', '2001:df2:e500:103::/64', '2001:df2:e500:1::/64', '2001:df2:e500:2::/64', '2001:df2:e500:3::/64', '2001:df2:e500:ed1a::/64', '208.80.152.128/27', '208.80.153.0/27', '208.80.153.128/28', '208.80.153.144/28', '208.80.153.160/28', '208.80.153.224/27', '208.80.153.32/27', '208.80.153.64/27', '208.80.153.96/27', '208.80.154.0/26', '208.80.154.128/26', '208.80.154.224/27', '208.80.154.64/26', '208.80.155.32/28', '208.80.155.48/28', '208.80.155.80/28', '208.80.155.96/27', '2620:0:860:100::/64', '2620:0:860:101::/64', '2620:0:860:102::/64', '2620:0:860:103::/64', '2620:0:860:104::/64', '2620:0:860:105::/64', '2620:0:860:106::/64', '2620:0:860:107::/64', '2620:0:860:108::/64', '2620:0:860:109::/64', '2620:0:860:10a::/64', '2620:0:860:10b::/64', '2620:0:860:10c::/64', '2620:0:860:10d::/64', '2620:0:860:10e::/64', '2620:0:860:10f::/64', '2620:0:860:110::/64', '2620:0:860:111::/64', '2620:0:860:112::/64', '2620:0:860:113::/64', '2620:0:860:114::/64', '2620:0:860:115::/64', '2620:0:860:116::/64', '2620:0:860:118::/64', '2620:0:860:119::/64', '2620:0:860:11a::/64', '2620:0:860:11b::/64', '2620:0:860:11c::/64', '2620:0:860:11d::/64', '2620:0:860:11e::/64', '2620:0:860:11f::/64', '2620:0:860:120::/64', '2620:0:860:121::/64', '2620:0:860:122::/64', '2620:0:860:123::/64', '2620:0:860:124::/64', '2620:0:860:125::/64', '2620:0:860:126::/64', '2620:0:860:127::/64', '2620:0:860:12b::/64', '2620:0:860:12c::/64', '2620:0:860:12d::/64', '2620:0:860:12e::/64', '2620:0:860:140::/64', '2620:0:860:1::/64', '2620:0:860:2::/64', '2620:0:860:300::/64', '2620:0:860:301::/64', '2620:0:860:302::/64', '2620:0:860:303::/64', '2620:0:860:304::/64', '2620:0:860:305::/64', '2620:0:860:307::/64', '2620:0:860:308::/64', '2620:0:860:3::/64', '2620:0:860:4::/64', '2620:0:860:5::/64', '2620:0:860:6::/64', '2620:0:860:7::/64', '2620:0:860:8::/64', '2620:0:860:babe::/64', '2620:0:860:babf::/64', '2620:0:860:cabe::/64', '2620:0:860:cabf::/64', '2620:0:860:ed1a::/64', '2620:0:861:100::/64', '2620:0:861:101::/64', '2620:0:861:102::/64', '2620:0:861:103::/64', '2620:0:861:104::/64', '2620:0:861:105::/64', '2620:0:861:106::/64', '2620:0:861:107::/64', '2620:0:861:108::/64', '2620:0:861:109::/64', '2620:0:861:10a::/64', '2620:0:861:10b::/64', '2620:0:861:10c::/64', '2620:0:861:10d::/64', '2620:0:861:10e::/64', '2620:0:861:10f::/64', '2620:0:861:110::/64', '2620:0:861:111::/64', '2620:0:861:112::/64', '2620:0:861:113::/64', '2620:0:861:114::/64', '2620:0:861:115::/64', '2620:0:861:116::/64', '2620:0:861:117::/64', '2620:0:861:118::/64', '2620:0:861:119::/64', '2620:0:861:11a::/64', '2620:0:861:11c::/64', '2620:0:861:11d::/64', '2620:0:861:11e::/64', '2620:0:861:11f::/64', '2620:0:861:120::/64', '2620:0:861:121::/64', '2620:0:861:122::/64', '2620:0:861:123::/64', '2620:0:861:124::/64', '2620:0:861:125::/64', '2620:0:861:126::/64', '2620:0:861:127::/64', '2620:0:861:128::/64', '2620:0:861:129::/64', '2620:0:861:12a::/64', '2620:0:861:12b::/64', '2620:0:861:12c::/64', '2620:0:861:12d::/64', '2620:0:861:12e::/64', '2620:0:861:12f::/64', '2620:0:861:131::/64', '2620:0:861:132::/64', '2620:0:861:133::/64', '2620:0:861:134::/64', '2620:0:861:135::/64', '2620:0:861:136::/64', '2620:0:861:137::/64', '2620:0:861:138::/64', '2620:0:861:139::/64', '2620:0:861:13a::/64', '2620:0:861:13b::/64', '2620:0:861:13c::/64', '2620:0:861:13d::/64', '2620:0:861:13e::/64', '2620:0:861:13f::/64', '2620:0:861:140::/64', '2620:0:861:141::/64', '2620:0:861:142::/64', '2620:0:861:143::/64', '2620:0:861:144::/64', '2620:0:861:145::/64', '2620:0:861:1::/64', '2620:0:861:2::/64', '2620:0:861:300::/64', '2620:0:861:301::/116', '2620:0:861:302::/64', '2620:0:861:303::/116', '2620:0:861:304::/116', '2620:0:861:305::/64', '2620:0:861:3::/64', '2620:0:861:4::/64', '2620:0:861:6::/64', '2620:0:861:7::/64', '2620:0:861:8::/64', '2620:0:861:babe::/64', '2620:0:861:babf::/116', '2620:0:861:cabe::/64', '2620:0:861:cabf::/116', '2620:0:861:ed1a::/64', '2620:0:863:101::/64', '2620:0:863:102::/64', '2620:0:863:103::/64', '2620:0:863:1::/64', '2620:0:863:2::/64', '2620:0:863:3::/64', '2620:0:863:ed1a::/64', '2a02:ec80:300:101::/64', '2a02:ec80:300:102::/64', '2a02:ec80:300:103::/64', '2a02:ec80:300:1::/64', '2a02:ec80:300:2::/64', '2a02:ec80:300:3::/64', '2a02:ec80:300:ed1a::/64', '2a02:ec80:600:101::/64', '2a02:ec80:600:102::/64', '2a02:ec80:600:1::/64', '2a02:ec80:600:2::/64', '2a02:ec80:600:ed1a::/64', '2a02:ec80:700:101::/64', '2a02:ec80:700:102::/64', '2a02:ec80:700:103::/64', '2a02:ec80:700:1::/64', '2a02:ec80:700:2::/64', '2a02:ec80:700:3::/64', '2a02:ec80:700:ed1a::/64']
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft].orig +++ File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft.orig +++ /etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft @@ -0,0 +1,9 @@ +# Autogenerated by puppet +set CLOUD_NETWORKS_PUBLIC_ipv6 { + type ipv6_addr + flags interval + auto-merge + elements = { 2a02:ec80:a000:4000::/64, + 2a02:ec80:a100:4000::/64 + } +}- Systemd::Unit[ferm-ferm-service-status-restart]
- Parameters differences:
--- Systemd::Unit[ferm-ferm-service-status-restart].orig +++ Systemd::Unit[ferm-ferm-service-status-restart] - ensure => present - unit => ferm - override => True - require => ['Class[Systemd]'] - override_filename => ferm-service-status-restart - restart => False - source => puppet:///modules/ferm/ferm_systemd_override
- File[/etc/systemd/system/nftables.service.d]
- Parameters differences:
--- File[/etc/systemd/system/nftables.service.d].orig +++ File[/etc/systemd/system/nftables.service.d] + ensure => directory + group => root + owner => root + mode => 0555
- Ferm::Rule[filter_log_filter-bootp]
- Parameters differences:
--- Ferm::Rule[filter_log_filter-bootp].orig +++ Ferm::Rule[filter_log_filter-bootp] - ensure => present - table => filter - prio => 98 - chain => INPUT - desc => - domain => (ip ip6) - rule => proto udp daddr 255.255.255.255 sport 67 dport 68 DROP;
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- Parameters differences:
--- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft].orig +++ File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft] + ensure => present + tag => nft + notify => ['Service[nftables]'] + group => root + owner => root + mode => 0444
- Content differences:
--- /etc/nftables/sets/MONITORING_HOSTS_ipv6.nft.orig +++ /etc/nftables/sets/MONITORING_HOSTS_ipv6.nft @@ -0,0 +1,7 @@ +# Autogenerated by puppet +set MONITORING_HOSTS_ipv6 { + type ipv6_addr + elements = { 2620:0:861:3:208:80:154:78, + 2620:0:860:2:208:80:153:42 + } +}- Service[ulogd2]
- Parameters differences:
- Content differences:
- File[/etc/nftables/sets/MONITORING_HOSTS_ipv6.nft]
- Ferm::Rule[filter_log_filter-bootp]
- File[/etc/systemd/system/nftables.service.d]
- Content differences:
- File[/etc/nftables/sets/CLOUD_NETWORKS_PUBLIC_ipv6.nft]
- Content differences:
- File[/etc/ferm/conf.d/10_full_monitoring_metrics_access_tcp]
- Nrpe::Check[check_ferm_active]
- File[/etc/nftables/prerouting]
- Content differences:
- Content differences:
- Content differences:
- File[/etc/nftables/sets/LOAD_BALANCER_HEALTH_CHECKS_ipv4.nft]
- Content differences:
- Content differences:
- File[/etc/nftables/sets/LINK_LOCAL_ipv4.nft]
- Nrpe::Monitor_service[ferm_active]
- Nftables::Set[MLSTAGE_KUBEPODS_NETWORKS]
- Content differences:
- File[/lib/systemd/system/nrpe2nodexp-ferm_active.service]
- Content differences:
- File[/etc/nftables/sets/KAFKA_BROKERS_JUMBO_ipv4.nft]
- Content differences:
- File[/etc/nftables/sets/AUX_KUBEPODS_NETWORKS_ipv6.nft]
- File[/var/log/prometheus-node-textfile-check-nft]
- File[/etc/ferm/conf.d/00_defs_requestctl]
- Systemd::Timer[wmf_auto_restart_ulogd2]
- Content differences:
- Content differences:
- File[/etc/nftables/sets/ANALYTICS_NETWORKS_ipv6.nft]
- Systemd::Unit[wmf_auto_restart_ulogd2.service]
- Prometheus::Alert::Rule[check_ferm_active_bba0a2572329bb500b832470e08b381c]
- Content differences:
- File[/etc/nftables/sets/DEPLOYMENT_HOSTS_ipv6.nft]
- Content differences:
- File[/etc/nftables/sets/BASTION_HOSTS_ipv4.nft]
- Sudo::User[nrpe-check_ferm_active]
- Class[Profile::Firewall::Log::Ferm]
- Nftables::Set[INSTALL_HOSTS]
- Confd::File[/etc/ferm/conf.d/00_defs_requestctl]
- Content differences:
- File[/etc/nftables/sets/STAGING_KUBEPODS_NETWORKS_ipv4.nft]
- Content differences:
- Content differences:
- File[/etc/nftables/sets/CLOUD_NETWORKS_ipv4.nft]
- Content differences:
- Content differences:
- Content differences:
- File[/etc/nftables/sets/PRODUCTION_NETWORKS_ipv6.nft]
- Parameters differences: