Advertisement
Guest User

Untitled

a guest
Jul 27th, 2022
69
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 39.21 KB | None | 0 0
  1. firezone-ctl reconfigure
  2.  
  3. root@ubuntu-nc:/home/ncadmin/Desktop# firezone-ctl reconfigure
  4. Starting Chef Infra Client, version 16.17.51
  5. Patents: https://www.chef.io/patents
  6. resolving cookbooks for run list: ["firezone::default"]
  7. Synchronizing Cookbooks:
  8. - firezone (0.0.1)
  9. - enterprise (1.2.0)
  10. - runit (5.1.7)
  11. - line (4.5.2)
  12. - packagecloud (1.0.1)
  13. - yum-epel (4.5.0)
  14. Installing Cookbook Gems:
  15. Compiling Cookbooks...
  16. Converging 55 resources
  17. Recipe: firezone::config
  18. * linux_user[firezone] action create (up to date)
  19. * group[firezone] action create (up to date)
  20. * directory[/etc/firezone] action create (up to date)
  21. * directory[/var/opt/firezone] action create (up to date)
  22. * directory[/opt/firezone/embedded/service/firezone/tmp] action create (up to date)
  23. * directory[/var/log/firezone] action create (up to date)
  24. * directory[/var/opt/firezone/etc] action create (up to date)
  25. * file[configuration-variables] action create (up to date)
  26. * file[/etc/firezone/secrets.json] action create (up to date)
  27. * file[/var/opt/firezone/cache/wg_private_key] action create (up to date)
  28. Recipe: firezone::log_management
  29. * directory[/var/opt/firezone/etc/logrotate.d] action create (up to date)
  30. * template[/var/opt/firezone/etc/logrotate.conf] action create (up to date)
  31. * template[/etc/cron.hourly/firezone_logrotate] action create (up to date)
  32. Recipe: firezone::ssl
  33. * directory[/var/opt/firezone/ssl] action create (up to date)
  34. * directory[/var/opt/firezone/ssl/ca] action create (up to date)
  35. * openssl_dhparam[/var/opt/firezone/ssl/ca/dhparams.pem] action create
  36. * file[/var/opt/firezone/ssl/ca/dhparams.pem] action create (up to date)
  37. (up to date)
  38. * openssl_x509_certificate[/var/opt/firezone/ssl/ca/73.174.22.122.crt] action create
  39. * file[/var/opt/firezone/ssl/ca/73.174.22.122.crt] action create_if_missing (up to date)
  40. * file[/var/opt/firezone/ssl/ca/73.174.22.122.key] action create_if_missing (up to date)
  41. (up to date)
  42. * link[/var/opt/firezone/ssl/cacert.pem] action create (up to date)
  43. Recipe: firezone::network
  44. * replace_or_add[IPv4 packet forwarding] action edit
  45. * file[/etc/sysctl.conf] action create (up to date)
  46. (up to date)
  47. * replace_or_add[IPv6 packet forwarding] action edit
  48. * file[/etc/sysctl.conf] action create (up to date)
  49. (up to date)
  50. * execute[sysctl -p /etc/sysctl.conf] action run
  51. - execute sysctl -p /etc/sysctl.conf
  52. Recipe: enterprise::runit
  53. * component_runit_supervisor[firezone] action create
  54. * template[/etc/systemd/system/firezone-runsvdir-start.service] action create (up to date)
  55. * execute[systemctl daemon-reload] action nothing (skipped due to action :nothing)
  56. * file[/usr/lib/systemd/system/firezone-runsvdir-start.service] action delete (up to date)
  57. * service[firezone-runsvdir-start.service] action enable (up to date)
  58. * service[firezone-runsvdir-start.service] action start (up to date)
  59. (up to date)
  60. Recipe: firezone::postgresql
  61. * sysctl[kernel.shmmax] action apply (up to date)
  62. * sysctl[kernel.shmall] action apply (up to date)
  63. * directory[/var/log/firezone/postgresql] action create (up to date)
  64. * enterprise_pg_cluster[firezone] action init
  65. * directory[/var/opt/firezone/postgresql/13.3/data] action create (up to date)
  66. * execute[initialize_cluster_/var/opt/firezone/postgresql/13.3/data] action run (skipped due to not_if)
  67. * template[/var/opt/firezone/postgresql/13.3/data/postgresql.conf] action create (up to date)
  68. * template[/var/opt/firezone/postgresql/13.3/data/pg_hba.conf] action create (up to date)
  69. (up to date)
  70. * component_runit_service[postgresql] action enable
  71. * template[/var/log/firezone/postgresql/config] action create (up to date)
  72. Recipe: <Dynamically Defined Resource>
  73. * service[postgresql] action nothing (skipped due to action :nothing)
  74. * runit_service[postgresql] action enable
  75. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  76. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  77. * directory[/opt/firezone/sv/postgresql] action create (up to date)
  78. * template[/opt/firezone/sv/postgresql/run] action create (up to date)
  79. * directory[/opt/firezone/sv/postgresql/log] action create (up to date)
  80. * directory[/opt/firezone/sv/postgresql/log/main] action create (up to date)
  81. * directory[/var/log/postgresql] action create (up to date)
  82. * template[/opt/firezone/sv/postgresql/log/config] action create (up to date)
  83. * link[/var/log/postgresql/config] action create (up to date)
  84. * template[/opt/firezone/sv/postgresql/log/run] action create (up to date)
  85. * directory[/opt/firezone/sv/postgresql/env] action create (up to date)
  86. * ruby_block[Delete unmanaged env files for postgresql service] action run (skipped due to only_if)
  87. * template[/opt/firezone/sv/postgresql/check] action create (skipped due to only_if)
  88. * template[/opt/firezone/sv/postgresql/finish] action create (skipped due to only_if)
  89. * directory[/opt/firezone/sv/postgresql/control] action create (up to date)
  90. * template[/opt/firezone/sv/postgresql/control/t] action create (up to date)
  91. * link[/opt/firezone/init/postgresql] action create (up to date)
  92. * file[/opt/firezone/sv/postgresql/down] action nothing (skipped due to action :nothing)
  93. * directory[/opt/firezone/service] action create (up to date)
  94. * link[/opt/firezone/service/postgresql] action create (up to date)
  95. * ruby_block[wait for postgresql service socket] action run
  96. - execute the ruby block wait for postgresql service socket
  97.  
  98.  
  99. Recipe: firezone::nginx
  100. * directory[/var/opt/firezone/nginx/cache] action create (up to date)
  101. * directory[/var/log/firezone/nginx] action create (up to date)
  102. * directory[/var/opt/firezone/nginx/etc] action create (up to date)
  103. * directory[/var/opt/firezone/nginx/etc/conf.d] action create (up to date)
  104. * directory[/var/opt/firezone/nginx/etc/sites-enabled] action create (up to date)
  105. * link[/var/opt/firezone/nginx/etc/mime.types] action create (up to date)
  106. * template[nginx.conf] action create (up to date)
  107. * component_runit_service[nginx] action enable
  108. * template[/var/log/firezone/nginx/config] action create (up to date)
  109. Recipe: <Dynamically Defined Resource>
  110. * service[nginx] action nothing (skipped due to action :nothing)
  111. * runit_service[nginx] action enable
  112. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  113. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  114. * directory[/opt/firezone/sv/nginx] action create (up to date)
  115. * template[/opt/firezone/sv/nginx/run] action create (up to date)
  116. * directory[/opt/firezone/sv/nginx/log] action create (up to date)
  117. * directory[/opt/firezone/sv/nginx/log/main] action create (up to date)
  118. * directory[/var/log/nginx] action create (up to date)
  119. * template[/opt/firezone/sv/nginx/log/config] action create (up to date)
  120. * link[/var/log/nginx/config] action create (up to date)
  121. * template[/opt/firezone/sv/nginx/log/run] action create (up to date)
  122. * directory[/opt/firezone/sv/nginx/env] action create (up to date)
  123. * ruby_block[Delete unmanaged env files for nginx service] action run (skipped due to only_if)
  124. * template[/opt/firezone/sv/nginx/check] action create (skipped due to only_if)
  125. * template[/opt/firezone/sv/nginx/finish] action create (skipped due to only_if)
  126. * directory[/opt/firezone/sv/nginx/control] action create (up to date)
  127. * link[/opt/firezone/init/nginx] action create (up to date)
  128. * file[/opt/firezone/sv/nginx/down] action nothing (skipped due to action :nothing)
  129. * directory[/opt/firezone/service] action create (up to date)
  130. * link[/opt/firezone/service/nginx] action create (up to date)
  131. * ruby_block[wait for nginx service socket] action run
  132. - execute the ruby block wait for nginx service socket
  133.  
  134.  
  135. Recipe: firezone::nginx
  136. * template[/var/opt/firezone/etc/logrotate.d/nginx] action create (up to date)
  137. Recipe: firezone::database
  138. * enterprise_pg_user[firezone] action create (skipped due to not_if)
  139. * enterprise_pg_database[firezone] action create
  140. * execute[create_database_firezone] action run (skipped due to not_if)
  141. (up to date)
  142. * execute[create postgresql plpgsql extension] action run (skipped due to not_if)
  143. * execute[create postgresql pg_trgm extension] action run (skipped due to not_if)
  144. Recipe: firezone::setcap
  145. * file[/opt/firezone/embedded/sbin/nft] action touch
  146. - update utime on file /opt/firezone/embedded/sbin/nft
  147. * execute[setcap_nft] action run
  148. - execute setcap 'cap_net_admin,cap_net_raw+eip' /opt/firezone/embedded/sbin/nft
  149. Recipe: firezone::wireguard
  150. * directory[/var/log/firezone/wireguard] action create (up to date)
  151. * component_runit_service[wireguard] action enable
  152. * template[/var/log/firezone/wireguard/config] action create (up to date)
  153. Recipe: <Dynamically Defined Resource>
  154. * service[wireguard] action nothing (skipped due to action :nothing)
  155. * runit_service[wireguard] action enable
  156. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  157. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  158. * directory[/opt/firezone/sv/wireguard] action create (up to date)
  159. * template[/opt/firezone/sv/wireguard/run] action create (up to date)
  160. * directory[/opt/firezone/sv/wireguard/log] action create (up to date)
  161. * directory[/opt/firezone/sv/wireguard/log/main] action create (up to date)
  162. * directory[/var/log/wireguard] action create (up to date)
  163. * template[/opt/firezone/sv/wireguard/log/config] action create (up to date)
  164. * link[/var/log/wireguard/config] action create (up to date)
  165. * template[/opt/firezone/sv/wireguard/log/run] action create (up to date)
  166. * directory[/opt/firezone/sv/wireguard/env] action create (up to date)
  167. * ruby_block[Delete unmanaged env files for wireguard service] action run (skipped due to only_if)
  168. * template[/opt/firezone/sv/wireguard/check] action create (skipped due to only_if)
  169. * template[/opt/firezone/sv/wireguard/finish] action create (skipped due to only_if)
  170. * directory[/opt/firezone/sv/wireguard/control] action create (up to date)
  171. * link[/opt/firezone/init/wireguard] action create (up to date)
  172. * file[/opt/firezone/sv/wireguard/down] action nothing (skipped due to action :nothing)
  173. * directory[/opt/firezone/service] action create (up to date)
  174. * link[/opt/firezone/service/wireguard] action create (up to date)
  175. * ruby_block[wait for wireguard service socket] action run
  176. - execute the ruby block wait for wireguard service socket
  177.  
  178.  
  179. Recipe: firezone::phoenix
  180. * directory[/var/log/firezone/phoenix] action create (up to date)
  181. * directory[/var/opt/firezone/phoenix/run] action create (up to date)
  182. * template[phoenix.nginx.conf] action create (up to date)
  183. * component_runit_service[phoenix] action enable
  184. * template[/var/log/firezone/phoenix/config] action create (up to date)
  185. Recipe: <Dynamically Defined Resource>
  186. * service[phoenix] action nothing (skipped due to action :nothing)
  187. * runit_service[phoenix] action enable
  188. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  189. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  190. * directory[/opt/firezone/sv/phoenix] action create (up to date)
  191. * template[/opt/firezone/sv/phoenix/run] action create (up to date)
  192. * directory[/opt/firezone/sv/phoenix/log] action create (up to date)
  193. * directory[/opt/firezone/sv/phoenix/log/main] action create (up to date)
  194. * directory[/var/log/phoenix] action create (up to date)
  195. * template[/opt/firezone/sv/phoenix/log/config] action create (up to date)
  196. * link[/var/log/phoenix/config] action create (up to date)
  197. * template[/opt/firezone/sv/phoenix/log/run] action create (up to date)
  198. * directory[/opt/firezone/sv/phoenix/env] action create (up to date)
  199. * file[/opt/firezone/sv/phoenix/env/EGRESS_INTERFACE] action create (up to date)
  200. * file[/opt/firezone/sv/phoenix/env/NFT_PATH] action create (up to date)
  201. * file[/opt/firezone/sv/phoenix/env/MIX_ENV] action create (up to date)
  202. * file[/opt/firezone/sv/phoenix/env/DATABASE_NAME] action create (up to date)
  203. * file[/opt/firezone/sv/phoenix/env/DATABASE_USER] action create (up to date)
  204. * file[/opt/firezone/sv/phoenix/env/DATABASE_HOST] action create (up to date)
  205. * file[/opt/firezone/sv/phoenix/env/DATABASE_PORT] action create (up to date)
  206. * file[/opt/firezone/sv/phoenix/env/DATABASE_POOL] action create (up to date)
  207. * file[/opt/firezone/sv/phoenix/env/DATABASE_SSL] action create (up to date)
  208. * file[/opt/firezone/sv/phoenix/env/DATABASE_SSL_OPTS] action create (up to date)
  209. * file[/opt/firezone/sv/phoenix/env/DATABASE_PARAMETERS] action create (up to date)
  210. * file[/opt/firezone/sv/phoenix/env/PHOENIX_LISTEN_ADDRESS] action create (up to date)
  211. * file[/opt/firezone/sv/phoenix/env/PHOENIX_PORT] action create (up to date)
  212. * file[/opt/firezone/sv/phoenix/env/EXTERNAL_URL] action create (up to date)
  213. * file[/opt/firezone/sv/phoenix/env/ADMIN_EMAIL] action create (up to date)
  214. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_INTERFACE_NAME] action create (up to date)
  215. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PORT] action create (up to date)
  216. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_MTU] action create (up to date)
  217. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_ENDPOINT] action create (up to date)
  218. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_DNS] action create (up to date)
  219. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_ALLOWED_IPS] action create (up to date)
  220. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PERSISTENT_KEEPALIVE] action create (up to date)
  221. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_ENABLED] action create (up to date)
  222. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_MASQUERADE] action create (up to date)
  223. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_NETWORK] action create (up to date)
  224. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_ADDRESS] action create (up to date)
  225. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_MASQUERADE] action create (up to date)
  226. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_ENABLED] action create (up to date)
  227. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_NETWORK] action create (up to date)
  228. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_ADDRESS] action create (up to date)
  229. * file[/opt/firezone/sv/phoenix/env/MAX_DEVICES_PER_USER] action create (up to date)
  230. * file[/opt/firezone/sv/phoenix/env/ALLOW_UNPRIVILEGED_DEVICE_MANAGEMENT] action create (up to date)
  231. * file[/opt/firezone/sv/phoenix/env/TELEMETRY_ENABLED] action create (up to date)
  232. * file[/opt/firezone/sv/phoenix/env/TELEMETRY_ID] action create (up to date)
  233. * file[/opt/firezone/sv/phoenix/env/CONNECTIVITY_CHECKS_ENABLED] action create (up to date)
  234. * file[/opt/firezone/sv/phoenix/env/CONNECTIVITY_CHECKS_INTERVAL] action create (up to date)
  235. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_PROVIDER] action create (up to date)
  236. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_CONFIGS] action create (up to date)
  237. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_FROM] action create (up to date)
  238. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PRIVATE_KEY_PATH] action create (up to date)
  239. * file[/opt/firezone/sv/phoenix/env/LOCAL_AUTH_ENABLED] action create (up to date)
  240. * file[/opt/firezone/sv/phoenix/env/OKTA_AUTH_ENABLED] action create (up to date)
  241. * file[/opt/firezone/sv/phoenix/env/OKTA_CLIENT_ID] action create (up to date)
  242. * file[/opt/firezone/sv/phoenix/env/OKTA_CLIENT_SECRET] action create (up to date)
  243. * file[/opt/firezone/sv/phoenix/env/OKTA_SITE] action create (up to date)
  244. * file[/opt/firezone/sv/phoenix/env/GOOGLE_AUTH_ENABLED] action create (up to date)
  245. * file[/opt/firezone/sv/phoenix/env/GOOGLE_CLIENT_ID] action create (up to date)
  246. * file[/opt/firezone/sv/phoenix/env/GOOGLE_CLIENT_SECRET] action create (up to date)
  247. * file[/opt/firezone/sv/phoenix/env/GOOGLE_REDIRECT_URI] action create (up to date)
  248. * file[/opt/firezone/sv/phoenix/env/DISABLE_VPN_ON_OIDC_ERROR] action create (up to date)
  249. * file[/opt/firezone/sv/phoenix/env/AUTO_CREATE_OIDC_USERS] action create (up to date)
  250. * file[/opt/firezone/sv/phoenix/env/AUTH_OIDC] action create (up to date)
  251. * file[/opt/firezone/sv/phoenix/env/GUARDIAN_SECRET_KEY] action create (up to date)
  252. * file[/opt/firezone/sv/phoenix/env/SECRET_KEY_BASE] action create (up to date)
  253. * file[/opt/firezone/sv/phoenix/env/LIVE_VIEW_SIGNING_SALT] action create (up to date)
  254. * file[/opt/firezone/sv/phoenix/env/COOKIE_SIGNING_SALT] action create (up to date)
  255. * file[/opt/firezone/sv/phoenix/env/COOKIE_ENCRYPTION_SALT] action create (up to date)
  256. * file[/opt/firezone/sv/phoenix/env/DATABASE_ENCRYPTION_KEY] action create (up to date)
  257. * file[/opt/firezone/sv/phoenix/env/DEFAULT_ADMIN_PASSWORD] action create (up to date)
  258. * ruby_block[Delete unmanaged env files for phoenix service] action run (skipped due to only_if)
  259. * template[/opt/firezone/sv/phoenix/check] action create (skipped due to only_if)
  260. * template[/opt/firezone/sv/phoenix/finish] action create (up to date)
  261. * directory[/opt/firezone/sv/phoenix/control] action create (up to date)
  262. * template[/opt/firezone/sv/phoenix/control/t] action create (up to date)
  263. * link[/opt/firezone/init/phoenix] action create (up to date)
  264. * file[/opt/firezone/sv/phoenix/down] action nothing (skipped due to action :nothing)
  265. * directory[/opt/firezone/service] action create (up to date)
  266. * link[/opt/firezone/service/phoenix] action create (up to date)
  267. * ruby_block[wait for phoenix service socket] action run
  268. - execute the ruby block wait for phoenix service socket
  269.  
  270.  
  271. Recipe: firezone::app
  272. * execute[fix app permissions] action run
  273. - execute chown -R firezone:firezone /opt/firezone/embedded/service/firezone && chmod -R o-rwx /opt/firezone/embedded/service/firezone && chmod -R g-rwx /opt/firezone/embedded/service/firezone
  274. * execute[setcap_beam] action run
  275. - execute setcap 'cap_net_admin+eip' /opt/firezone/embedded/service/firezone/erts-13.0.1/bin/beam.smp
  276. * file[environment-variables] action create (up to date)
  277. * execute[database schema] action run
  278. - execute bin/firezone eval "FzHttp.Release.migrate"
  279. Recipe: firezone::telemetry
  280. * file[disable_telemetry] action delete (up to date)
  281. Recipe: firezone::default
  282. * file[/etc/firezone/firezone-running.json] action create (up to date)
  283. * file[/var/opt/firezone/.license.accepted] action create (up to date)
  284. Recipe: firezone::phoenix
  285. * component_runit_service[phoenix] action restart
  286. Recipe: <Dynamically Defined Resource>
  287. * service[phoenix] action nothing (skipped due to action :nothing)
  288. * runit_service[phoenix] action restart (up to date)
  289. (up to date)
  290.  
  291. Running handlers:
  292. Running handlers complete
  293. Chef Infra Client finished, 18/226 resources updated in 05 seconds
  294. [2022-07-27T09:28:07-04:00] WARN: This release of Chef Infra Client became end of life (EOL) on May 1st 2022. Please update to a supported release to receive new features, bug fixes, and security updates.
  295. firezone Reconfigured!
  296.  
  297.  
  298. root@ubuntu-nc:/home/ncadmin/Desktop# firezone-ctl reconfigure
  299. Starting Chef Infra Client, version 16.17.51
  300. Patents: https://www.chef.io/patents
  301. resolving cookbooks for run list: ["firezone::default"]
  302. Synchronizing Cookbooks:
  303. - firezone (0.0.1)
  304. - enterprise (1.2.0)
  305. - runit (5.1.7)
  306. - line (4.5.2)
  307. - packagecloud (1.0.1)
  308. - yum-epel (4.5.0)
  309. Installing Cookbook Gems:
  310. Compiling Cookbooks...
  311. Converging 55 resources
  312. Recipe: firezone::config
  313. * linux_user[firezone] action create (up to date)
  314. * group[firezone] action create (up to date)
  315. * directory[/etc/firezone] action create (up to date)
  316. * directory[/var/opt/firezone] action create (up to date)
  317. * directory[/opt/firezone/embedded/service/firezone/tmp] action create (up to date)
  318. * directory[/var/log/firezone] action create (up to date)
  319. * directory[/var/opt/firezone/etc] action create (up to date)
  320. * file[configuration-variables] action create (up to date)
  321. * file[/etc/firezone/secrets.json] action create (up to date)
  322. * file[/var/opt/firezone/cache/wg_private_key] action create (up to date)
  323. Recipe: firezone::log_management
  324. * directory[/var/opt/firezone/etc/logrotate.d] action create (up to date)
  325. * template[/var/opt/firezone/etc/logrotate.conf] action create (up to date)
  326. * template[/etc/cron.hourly/firezone_logrotate] action create (up to date)
  327. Recipe: firezone::ssl
  328. * directory[/var/opt/firezone/ssl] action create (up to date)
  329. * directory[/var/opt/firezone/ssl/ca] action create (up to date)
  330. * openssl_dhparam[/var/opt/firezone/ssl/ca/dhparams.pem] action create
  331. * file[/var/opt/firezone/ssl/ca/dhparams.pem] action create (up to date)
  332. (up to date)
  333. * openssl_x509_certificate[/var/opt/firezone/ssl/ca/73.174.22.122.crt] action create
  334. * file[/var/opt/firezone/ssl/ca/73.174.22.122.crt] action create_if_missing (up to date)
  335. * file[/var/opt/firezone/ssl/ca/73.174.22.122.key] action create_if_missing (up to date)
  336. (up to date)
  337. * link[/var/opt/firezone/ssl/cacert.pem] action create (up to date)
  338. Recipe: firezone::network
  339. * replace_or_add[IPv4 packet forwarding] action edit
  340. * file[/etc/sysctl.conf] action create (up to date)
  341. (up to date)
  342. * replace_or_add[IPv6 packet forwarding] action edit
  343. * file[/etc/sysctl.conf] action create (up to date)
  344. (up to date)
  345. * execute[sysctl -p /etc/sysctl.conf] action run
  346. - execute sysctl -p /etc/sysctl.conf
  347. Recipe: enterprise::runit
  348. * component_runit_supervisor[firezone] action create
  349. * template[/etc/systemd/system/firezone-runsvdir-start.service] action create (up to date)
  350. * execute[systemctl daemon-reload] action nothing (skipped due to action :nothing)
  351. * file[/usr/lib/systemd/system/firezone-runsvdir-start.service] action delete (up to date)
  352. * service[firezone-runsvdir-start.service] action enable (up to date)
  353. * service[firezone-runsvdir-start.service] action start (up to date)
  354. (up to date)
  355. Recipe: firezone::postgresql
  356. * sysctl[kernel.shmmax] action apply (up to date)
  357. * sysctl[kernel.shmall] action apply (up to date)
  358. * directory[/var/log/firezone/postgresql] action create (up to date)
  359. * enterprise_pg_cluster[firezone] action init
  360. * directory[/var/opt/firezone/postgresql/13.3/data] action create (up to date)
  361. * execute[initialize_cluster_/var/opt/firezone/postgresql/13.3/data] action run (skipped due to not_if)
  362. * template[/var/opt/firezone/postgresql/13.3/data/postgresql.conf] action create (up to date)
  363. * template[/var/opt/firezone/postgresql/13.3/data/pg_hba.conf] action create (up to date)
  364. (up to date)
  365. * component_runit_service[postgresql] action enable
  366. * template[/var/log/firezone/postgresql/config] action create (up to date)
  367. Recipe: <Dynamically Defined Resource>
  368. * service[postgresql] action nothing (skipped due to action :nothing)
  369. * runit_service[postgresql] action enable
  370. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  371. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  372. * directory[/opt/firezone/sv/postgresql] action create (up to date)
  373. * template[/opt/firezone/sv/postgresql/run] action create (up to date)
  374. * directory[/opt/firezone/sv/postgresql/log] action create (up to date)
  375. * directory[/opt/firezone/sv/postgresql/log/main] action create (up to date)
  376. * directory[/var/log/postgresql] action create (up to date)
  377. * template[/opt/firezone/sv/postgresql/log/config] action create (up to date)
  378. * link[/var/log/postgresql/config] action create (up to date)
  379. * template[/opt/firezone/sv/postgresql/log/run] action create (up to date)
  380. * directory[/opt/firezone/sv/postgresql/env] action create (up to date)
  381. * ruby_block[Delete unmanaged env files for postgresql service] action run (skipped due to only_if)
  382. * template[/opt/firezone/sv/postgresql/check] action create (skipped due to only_if)
  383. * template[/opt/firezone/sv/postgresql/finish] action create (skipped due to only_if)
  384. * directory[/opt/firezone/sv/postgresql/control] action create (up to date)
  385. * template[/opt/firezone/sv/postgresql/control/t] action create (up to date)
  386. * link[/opt/firezone/init/postgresql] action create (up to date)
  387. * file[/opt/firezone/sv/postgresql/down] action nothing (skipped due to action :nothing)
  388. * directory[/opt/firezone/service] action create (up to date)
  389. * link[/opt/firezone/service/postgresql] action create (up to date)
  390. * ruby_block[wait for postgresql service socket] action run
  391. - execute the ruby block wait for postgresql service socket
  392.  
  393.  
  394. Recipe: firezone::nginx
  395. * directory[/var/opt/firezone/nginx/cache] action create (up to date)
  396. * directory[/var/log/firezone/nginx] action create (up to date)
  397. * directory[/var/opt/firezone/nginx/etc] action create (up to date)
  398. * directory[/var/opt/firezone/nginx/etc/conf.d] action create (up to date)
  399. * directory[/var/opt/firezone/nginx/etc/sites-enabled] action create (up to date)
  400. * link[/var/opt/firezone/nginx/etc/mime.types] action create (up to date)
  401. * template[nginx.conf] action create (up to date)
  402. * component_runit_service[nginx] action enable
  403. * template[/var/log/firezone/nginx/config] action create (up to date)
  404. Recipe: <Dynamically Defined Resource>
  405. * service[nginx] action nothing (skipped due to action :nothing)
  406. * runit_service[nginx] action enable
  407. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  408. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  409. * directory[/opt/firezone/sv/nginx] action create (up to date)
  410. * template[/opt/firezone/sv/nginx/run] action create (up to date)
  411. * directory[/opt/firezone/sv/nginx/log] action create (up to date)
  412. * directory[/opt/firezone/sv/nginx/log/main] action create (up to date)
  413. * directory[/var/log/nginx] action create (up to date)
  414. * template[/opt/firezone/sv/nginx/log/config] action create (up to date)
  415. * link[/var/log/nginx/config] action create (up to date)
  416. * template[/opt/firezone/sv/nginx/log/run] action create (up to date)
  417. * directory[/opt/firezone/sv/nginx/env] action create (up to date)
  418. * ruby_block[Delete unmanaged env files for nginx service] action run (skipped due to only_if)
  419. * template[/opt/firezone/sv/nginx/check] action create (skipped due to only_if)
  420. * template[/opt/firezone/sv/nginx/finish] action create (skipped due to only_if)
  421. * directory[/opt/firezone/sv/nginx/control] action create (up to date)
  422. * link[/opt/firezone/init/nginx] action create (up to date)
  423. * file[/opt/firezone/sv/nginx/down] action nothing (skipped due to action :nothing)
  424. * directory[/opt/firezone/service] action create (up to date)
  425. * link[/opt/firezone/service/nginx] action create (up to date)
  426. * ruby_block[wait for nginx service socket] action run
  427. - execute the ruby block wait for nginx service socket
  428.  
  429.  
  430. Recipe: firezone::nginx
  431. * template[/var/opt/firezone/etc/logrotate.d/nginx] action create (up to date)
  432. Recipe: firezone::database
  433. * enterprise_pg_user[firezone] action create (skipped due to not_if)
  434. * enterprise_pg_database[firezone] action create
  435. * execute[create_database_firezone] action run (skipped due to not_if)
  436. (up to date)
  437. * execute[create postgresql plpgsql extension] action run (skipped due to not_if)
  438. * execute[create postgresql pg_trgm extension] action run (skipped due to not_if)
  439. Recipe: firezone::setcap
  440. * file[/opt/firezone/embedded/sbin/nft] action touch
  441. - update utime on file /opt/firezone/embedded/sbin/nft
  442. * execute[setcap_nft] action run
  443. - execute setcap 'cap_net_admin,cap_net_raw+eip' /opt/firezone/embedded/sbin/nft
  444. Recipe: firezone::wireguard
  445. * directory[/var/log/firezone/wireguard] action create (up to date)
  446. * component_runit_service[wireguard] action enable
  447. * template[/var/log/firezone/wireguard/config] action create (up to date)
  448. Recipe: <Dynamically Defined Resource>
  449. * service[wireguard] action nothing (skipped due to action :nothing)
  450. * runit_service[wireguard] action enable
  451. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  452. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  453. * directory[/opt/firezone/sv/wireguard] action create (up to date)
  454. * template[/opt/firezone/sv/wireguard/run] action create (up to date)
  455. * directory[/opt/firezone/sv/wireguard/log] action create (up to date)
  456. * directory[/opt/firezone/sv/wireguard/log/main] action create (up to date)
  457. * directory[/var/log/wireguard] action create (up to date)
  458. * template[/opt/firezone/sv/wireguard/log/config] action create (up to date)
  459. * link[/var/log/wireguard/config] action create (up to date)
  460. * template[/opt/firezone/sv/wireguard/log/run] action create (up to date)
  461. * directory[/opt/firezone/sv/wireguard/env] action create (up to date)
  462. * ruby_block[Delete unmanaged env files for wireguard service] action run (skipped due to only_if)
  463. * template[/opt/firezone/sv/wireguard/check] action create (skipped due to only_if)
  464. * template[/opt/firezone/sv/wireguard/finish] action create (skipped due to only_if)
  465. * directory[/opt/firezone/sv/wireguard/control] action create (up to date)
  466. * link[/opt/firezone/init/wireguard] action create (up to date)
  467. * file[/opt/firezone/sv/wireguard/down] action nothing (skipped due to action :nothing)
  468. * directory[/opt/firezone/service] action create (up to date)
  469. * link[/opt/firezone/service/wireguard] action create (up to date)
  470. * ruby_block[wait for wireguard service socket] action run
  471. - execute the ruby block wait for wireguard service socket
  472.  
  473.  
  474. Recipe: firezone::phoenix
  475. * directory[/var/log/firezone/phoenix] action create (up to date)
  476. * directory[/var/opt/firezone/phoenix/run] action create (up to date)
  477. * template[phoenix.nginx.conf] action create (up to date)
  478. * component_runit_service[phoenix] action enable
  479. * template[/var/log/firezone/phoenix/config] action create (up to date)
  480. Recipe: <Dynamically Defined Resource>
  481. * service[phoenix] action nothing (skipped due to action :nothing)
  482. * runit_service[phoenix] action enable
  483. * ruby_block[restart_service] action nothing (skipped due to action :nothing)
  484. * ruby_block[restart_log_service] action nothing (skipped due to action :nothing)
  485. * directory[/opt/firezone/sv/phoenix] action create (up to date)
  486. * template[/opt/firezone/sv/phoenix/run] action create (up to date)
  487. * directory[/opt/firezone/sv/phoenix/log] action create (up to date)
  488. * directory[/opt/firezone/sv/phoenix/log/main] action create (up to date)
  489. * directory[/var/log/phoenix] action create (up to date)
  490. * template[/opt/firezone/sv/phoenix/log/config] action create (up to date)
  491. * link[/var/log/phoenix/config] action create (up to date)
  492. * template[/opt/firezone/sv/phoenix/log/run] action create (up to date)
  493. * directory[/opt/firezone/sv/phoenix/env] action create (up to date)
  494. * file[/opt/firezone/sv/phoenix/env/EGRESS_INTERFACE] action create (up to date)
  495. * file[/opt/firezone/sv/phoenix/env/NFT_PATH] action create (up to date)
  496. * file[/opt/firezone/sv/phoenix/env/MIX_ENV] action create (up to date)
  497. * file[/opt/firezone/sv/phoenix/env/DATABASE_NAME] action create (up to date)
  498. * file[/opt/firezone/sv/phoenix/env/DATABASE_USER] action create (up to date)
  499. * file[/opt/firezone/sv/phoenix/env/DATABASE_HOST] action create (up to date)
  500. * file[/opt/firezone/sv/phoenix/env/DATABASE_PORT] action create (up to date)
  501. * file[/opt/firezone/sv/phoenix/env/DATABASE_POOL] action create (up to date)
  502. * file[/opt/firezone/sv/phoenix/env/DATABASE_SSL] action create (up to date)
  503. * file[/opt/firezone/sv/phoenix/env/DATABASE_SSL_OPTS] action create (up to date)
  504. * file[/opt/firezone/sv/phoenix/env/DATABASE_PARAMETERS] action create (up to date)
  505. * file[/opt/firezone/sv/phoenix/env/PHOENIX_LISTEN_ADDRESS] action create (up to date)
  506. * file[/opt/firezone/sv/phoenix/env/PHOENIX_PORT] action create (up to date)
  507. * file[/opt/firezone/sv/phoenix/env/EXTERNAL_URL] action create (up to date)
  508. * file[/opt/firezone/sv/phoenix/env/ADMIN_EMAIL] action create (up to date)
  509. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_INTERFACE_NAME] action create (up to date)
  510. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PORT] action create (up to date)
  511. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_MTU] action create (up to date)
  512. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_ENDPOINT] action create (up to date)
  513. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_DNS] action create (up to date)
  514. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_ALLOWED_IPS] action create (up to date)
  515. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PERSISTENT_KEEPALIVE] action create (up to date)
  516. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_ENABLED] action create (up to date)
  517. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_MASQUERADE] action create (up to date)
  518. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_NETWORK] action create (up to date)
  519. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV4_ADDRESS] action create (up to date)
  520. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_MASQUERADE] action create (up to date)
  521. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_ENABLED] action create (up to date)
  522. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_NETWORK] action create (up to date)
  523. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_IPV6_ADDRESS] action create (up to date)
  524. * file[/opt/firezone/sv/phoenix/env/MAX_DEVICES_PER_USER] action create (up to date)
  525. * file[/opt/firezone/sv/phoenix/env/ALLOW_UNPRIVILEGED_DEVICE_MANAGEMENT] action create (up to date)
  526. * file[/opt/firezone/sv/phoenix/env/TELEMETRY_ENABLED] action create (up to date)
  527. * file[/opt/firezone/sv/phoenix/env/TELEMETRY_ID] action create (up to date)
  528. * file[/opt/firezone/sv/phoenix/env/CONNECTIVITY_CHECKS_ENABLED] action create (up to date)
  529. * file[/opt/firezone/sv/phoenix/env/CONNECTIVITY_CHECKS_INTERVAL] action create (up to date)
  530. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_PROVIDER] action create (up to date)
  531. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_CONFIGS] action create (up to date)
  532. * file[/opt/firezone/sv/phoenix/env/OUTBOUND_EMAIL_FROM] action create (up to date)
  533. * file[/opt/firezone/sv/phoenix/env/WIREGUARD_PRIVATE_KEY_PATH] action create (up to date)
  534. * file[/opt/firezone/sv/phoenix/env/LOCAL_AUTH_ENABLED] action create (up to date)
  535. * file[/opt/firezone/sv/phoenix/env/OKTA_AUTH_ENABLED] action create (up to date)
  536. * file[/opt/firezone/sv/phoenix/env/OKTA_CLIENT_ID] action create (up to date)
  537. * file[/opt/firezone/sv/phoenix/env/OKTA_CLIENT_SECRET] action create (up to date)
  538. * file[/opt/firezone/sv/phoenix/env/OKTA_SITE] action create (up to date)
  539. * file[/opt/firezone/sv/phoenix/env/GOOGLE_AUTH_ENABLED] action create (up to date)
  540. * file[/opt/firezone/sv/phoenix/env/GOOGLE_CLIENT_ID] action create (up to date)
  541. * file[/opt/firezone/sv/phoenix/env/GOOGLE_CLIENT_SECRET] action create (up to date)
  542. * file[/opt/firezone/sv/phoenix/env/GOOGLE_REDIRECT_URI] action create (up to date)
  543. * file[/opt/firezone/sv/phoenix/env/DISABLE_VPN_ON_OIDC_ERROR] action create (up to date)
  544. * file[/opt/firezone/sv/phoenix/env/AUTO_CREATE_OIDC_USERS] action create (up to date)
  545. * file[/opt/firezone/sv/phoenix/env/AUTH_OIDC] action create (up to date)
  546. * file[/opt/firezone/sv/phoenix/env/GUARDIAN_SECRET_KEY] action create (up to date)
  547. * file[/opt/firezone/sv/phoenix/env/SECRET_KEY_BASE] action create (up to date)
  548. * file[/opt/firezone/sv/phoenix/env/LIVE_VIEW_SIGNING_SALT] action create (up to date)
  549. * file[/opt/firezone/sv/phoenix/env/COOKIE_SIGNING_SALT] action create (up to date)
  550. * file[/opt/firezone/sv/phoenix/env/COOKIE_ENCRYPTION_SALT] action create (up to date)
  551. * file[/opt/firezone/sv/phoenix/env/DATABASE_ENCRYPTION_KEY] action create (up to date)
  552. * file[/opt/firezone/sv/phoenix/env/DEFAULT_ADMIN_PASSWORD] action create (up to date)
  553. * ruby_block[Delete unmanaged env files for phoenix service] action run (skipped due to only_if)
  554. * template[/opt/firezone/sv/phoenix/check] action create (skipped due to only_if)
  555. * template[/opt/firezone/sv/phoenix/finish] action create (up to date)
  556. * directory[/opt/firezone/sv/phoenix/control] action create (up to date)
  557. * template[/opt/firezone/sv/phoenix/control/t] action create (up to date)
  558. * link[/opt/firezone/init/phoenix] action create (up to date)
  559. * file[/opt/firezone/sv/phoenix/down] action nothing (skipped due to action :nothing)
  560. * directory[/opt/firezone/service] action create (up to date)
  561. * link[/opt/firezone/service/phoenix] action create (up to date)
  562. * ruby_block[wait for phoenix service socket] action run
  563. - execute the ruby block wait for phoenix service socket
  564.  
  565.  
  566. firezone-ctl show-config
  567.  
  568. Recipe: firezone::app
  569. * execute[fix app permissions] action run
  570. - execute chown -R firezone:firezone /opt/firezone/embedded/service/firezone && chmod -R o-rwx /opt/firezone/embedded/service/firezone && chmod -R g-rwx /opt/firezone/embedded/service/firezone
  571. * execute[setcap_beam] action run
  572. - execute setcap 'cap_net_admin+eip' /opt/firezone/embedded/service/firezone/erts-13.0.1/bin/beam.smp
  573. * file[environment-variables] action create (up to date)
  574. * execute[database schema] action run
  575. - execute bin/firezone eval "FzHttp.Release.migrate"
  576. Recipe: firezone::telemetry
  577. * file[disable_telemetry] action delete (up to date)
  578. Recipe: firezone::default
  579. * file[/etc/firezone/firezone-running.json] action create (up to date)
  580. * file[/var/opt/firezone/.license.accepted] action create (up to date)
  581. Recipe: firezone::phoenix
  582. * component_runit_service[phoenix] action restart
  583. Recipe: <Dynamically Defined Resource>
  584. * service[phoenix] action nothing (skipped due to action :nothing)
  585. * runit_service[phoenix] action restart (up to date)
  586. (up to date)
  587.  
  588. Running handlers:
  589. Running handlers complete
  590. Chef Infra Client finished, 18/226 resources updated in 05 seconds
  591. [2022-07-27T09:28:07-04:00] WARN: This release of Chef Infra Client became end of life (EOL) on May 1st 2022. Please update to a supported release to receive new features, bug fixes, and security updates.
  592. firezone Reconfigured!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement