Page MenuHomePhabricator

monitoring and swift project instances not permitting access from cloud-cumin-01
Open, Needs TriagePublic

Description

(18) pc-02.swift.eqiad.wmflabs,pm-04.swift.eqiad.wmflabs,pontoon-acmechief-01.monitoring.eqiad.wmflabs,pontoon-conf-01.monitoring.eqiad.wmflabs,pontoon-elastic7-01.monitoring.eqiad.wmflabs,pontoon-grafana-01.monitoring.eqiad.wmflabs,pontoon-graphite-[01,03].monitoring.eqiad.wmflabs,pontoon-icinga-01.monitoring.eqiad.wmflabs,pontoon-kafka-01.monitoring.eqiad.wmflabs,pontoon-log-01.monitoring.eqiad.wmflabs,pontoon-logstash7-02.monitoring.eqiad.wmflabs,pontoon-ms-be-[01-02].monitoring.eqiad.wmflabs,pontoon-prometheus-01.monitoring.eqiad.wmflabs,pontoon-puppet-01.monitoring.eqiad.wmflabs,pontoon-puppetdb-01.monitoring.eqiad.wmflabs,pontoon-thanos-01.monitoring.eqiad.wmflabs
----- OUTPUT of 'apt-cache policy exim4' -----                                                                                                                                                              
Permission denied (publickey,keyboard-interactive).

Event Timeline

Indeed these hosts are running an experimental self hosted puppetmaster (https://wikitech.wikimedia.org/wiki/User:Filippo_Giunchedi/Pontoon), and I'm assuming from the permission denied that root's authorized_keys is missing certain public keys. Which puppet classe(s) should be included for the right keys to be authorized?