Prometheus

Overview

This is a flavour containing the prometheus time series database along with the alertmanager notification tool configured for email alerts.

The flavour includes a local consul agent instance to be available that it can connect to (see configuration below). You can e.g. use the consul pot flavour on this site to run consul.

Installation

  • Create a ZFS data set on the parent system beforehand zfs create -o mountpoint=/mnt/prometheusdata zroot/prometheusdata
  • Create your local jail from the image or the flavour files.
  • Clone the local jail
  • Mount in the ZFS data set you created pot mount-in -p <jailname> -m /mnt -d /mnt/prometheusdata
  • Optionally export the ports after creating the jail:
    pot export-ports -p <jailname> -e 9090:9090 -e 9100:9100 -e 3000:3000
  • Adjust to your environment:
    sudo pot set-env -p <jailname> -E DATACENTER=<datacentername> -E NODENAME=<nodename> \
    -E IP=<IP address of this system> -E CONSULSERVERS='<correctly formatted list of quoted IP addresses>' \
    -E VAULTSERVER=<IP address vault server> -E VAULTTOKEN=<token> \
    -E SFTPUSER=<user> -E SFTPPASS=<password> \
    -E SCRAPECONSUL="'10.0.0.1:8501', '10.0.0.2:8501', '10.0.0.3:8501', '10.0.0.4:8501', '10.0.0.5:8501'" \
    -E SCRAPENOMAD="'10.0.0.6:4646', '10.0.0.7:4646', '10.0.0.8:4646', '10.0.0.9:4646', '10.0.0.10:4646'" \
    -E SCRAPEDATABASE="'10.0.0.11:9187', '10.0.0.12:9187'" \
    -E SMTPHOSTPORT="smtp.host.com:25" -E SMTPFROM="alertmanager@example.com" \
    -E ALERTADDRESS="<email address to notify>" \
    [-E GOSSIPKEY=<32 byte Base64 key from consul keygen>] [-E REMOTELOG=<remote syslog IP>]
    

The CONSULSERVERS parameter defines the consul server instances, and must be set as CONSULSERVERS='"10.0.0.2"' or CONSULSERVERS='"10.0.0.2", "10.0.0.3", "10.0.0.4"' or CONSULSERVERS='"10.0.0.2", "10.0.0.3", "10.0.0.4", "10.0.0.5", "10.0.0.6"'

The GOSSIPKEY parameter is the gossip encryption key for consul agent. We’re using a default key if you do not set the parameter, do not use the default key for production encryption, instead provide your own.

The VAULTSERVER parameter is the IP address of the vault server to authenticate to, and obtain certificates from.

The VAULTTOKEN parameter is the issued token from the vault server.

The SCRAPECONSUL parameter is a list of consul servers with port 8501 for TLS, to pass into prometheus.yml.

The SCRAPENOMAD parameter is a list of nomad servers with port 4646 for TLS, to pass into prometheus.yml.

The SCRAPEDATABASE parameter is a list of postgres_exporter instances on postgresql-patroni images, with port 9187 to pass into prometheus.yml.

The REMOTELOG parameter is the IP address of a remote syslog server to send logs to, such as for the loki flavour on this site.

The SMTPHOSTPORT parameter is for alertmanager and must be entered in as smtphostname:port.

The SMTPFROM parameter is the alertmanager FROM email address.

The SMTPUSER and SMTPPASS parameters are for SMTP authentication.

The ALERTADDRESS parameter is the email address to send notifications to.

Usage

To access prometheus open the following in a browser:

  • http://:9090
  • http://:9090/targets/

To access this node’s own metrics, visit:

  • http://:9100/metrics

or run fetch -o - 'https://127.0.0.1:9100/metrics'

To see the targets being captured via consul, visit

  • http://:9090/targets

To access Grafana open the following in a browser and accept the self-signed certificate:

  • https://:3000

Persistent Storage

Persistent storage will be in the ZFS data set zroot/prometheusdata, available inside the image at /mnt

If you stop the image, the data will still exist, and a new image can be started up and still use it.

If you need to change the directory parameters for the ZFS data set, adjust the mount-in command accordingly for the source directory as mounted by the parent OS.

Do not adjust the image destination mount point at /mnt because Prometheus is configured to use this directory for data.

Getting Started

How To Use The Ready-Made Image

FreeBSD 13.0:
pot import -p prometheus-amd64-13_0 -t 0.9.28 -U https://potluck.honeyguide.net/prometheus

FreeBSD 12.2:
pot import -p prometheus-amd64-12_2 -t 0.9.28 -U https://potluck.honeyguide.net/prometheus

If you don’t want to use the default pot bridged network configuration but instead need an individual network setup (e.g. assign a host IP address), after importing it you can simply clone the jail like that (em0 is the host network adapter in this example):
pot clone -P prometheus-amd64-13_0 -p my-cloned-jail -N alias -i "em0|10.10.10.10"

Note: Some images might require specific network configuration, double check the Overview-chapter at the top.

Alternatively: Create a Jail With This Flavour Yourself

1. Create Flavour Files

Save all files and directories from https://github.com/hny-gd/potluck/tree/master/prometheus to /usr/local/etc/pot/flavours/

2. Create Jail From Flavour

Run
pot create -b <FreeBSD Version> -p <jailname> -t single -N public-bridge -f fbsd-update

with your FreeBSD version (e.g. 12.1) and the name your jail should get.

Note: Some images might require specific network configuration, double check the Overview-chapter at the top.

Version History

0.9.28

  • Updating version for merge

0.9.27

  • Fixing missing certs directory

0.9.26

  • Adding syslog-ng back

0.9.25

  • Implementing metric pki and new cook setup

0.9.24

  • Setting stricter permissions on key.pem

0.9.23

  • Removing sftppass, unsetting consul sysrc parameters where needed

0.9.22

  • General security updates, and updating changelog this time

0.9.21

  • Tweaking mandatory variables for optional parameters

0.9.20

  • Bug-fix on gossip key

0.9.19

  • Implementing mandatory variables

0.9.18

  • Prometheus alertmanager added

0.9.17

  • Adding in postgres_exporter config to scrape

0.9.16

  • Updates needed to support Nomad and Vault dashboards in Grafana image

0.9.15

  • Setup for tls-client-validation

0.9.14

  • Turning off flow-control in syslog-ng, setting 120s time_reopen, and reducing log-fifo parameter

0.9.13

  • Clearing syslog-ng /dev/console entries to remove log spam

0.9.12

  • Updates to syslog-ng and standardising cert.pem key.pem ca.pem

0.9.11

  • Implementing syslog-ng with tls for remote logging

0.9.10

  • Switched to quarterly package sources

0.9.9

  • Removing Grafana to own flavour

0.9.8

  • Optional remote logging capability added

0.9.7

  • Node-exporter TLS

0.9.6

  • Vault integration

0.9.5

  • Persistent storage added at /mnt

0.9.4

  • Changed method of Grafana startup to fix non-starting instance

0.9.3

  • Updates for grafana default datasource and dashboard, removing specific targets adjustment in favour of consul

0.9.2

  • Correcting consul published service name to use “node-exporter”

0.9.1

  • Updating to use consul for announcing node_exporter as a service

0.9

  • First test build of Prometheus with node_exporter and Grafana7

These images were built on Tue Nov 30 19:42:29 UTC 2021

Manual Image Download Links

prometheus-amd64-13_0_0.9.28.xz ( 565.16 MB )
prometheus-amd64-13_0_0.9.28.xz.skein ( 0.250977 KB )

prometheus-amd64-12_2_0.9.28.xz ( 615.084 MB )
prometheus-amd64-12_2_0.9.28.xz.skein ( 0.250977 KB )

Jenkins Pot Creation Logs

prometheus-amd64-13_0_0.9.28:


prometheus/prometheus:
copy-in -s /usr/local/etc/pot/flavours/prometheus.d/local -d /root/.pot_local
prometheus/prometheus.sh:
#!/bin/sh

# Based on POTLUCK TEMPLATE v3.0
# Altered by Michael Gmelin
#
# EDIT THE FOLLOWING FOR NEW FLAVOUR:
# 1. RUNS_IN_NOMAD - true or false
# 2. If RUNS_IN_NOMAD is false, can delete the <flavour>+4 file, else
#    make sure pot create command doesn't include it
# 3. Create a matching <flavour> file with this <flavour>.sh file that
#    contains the copy-in commands for the config files from <flavour>.d/
#    Remember that the package directories don't exist yet, so likely copy
#    to /root
# 4. Adjust package installation between BEGIN & END PACKAGE SETUP
# 5. Adjust jail configuration script generation between BEGIN & END COOK
#    Configure the config files that have been copied in where necessary

# Set this to true if this jail flavour is to be created as a nomad
# (i.e. blocking) jail.
# You can then query it in the cook script generation below and the script
# is installed appropriately at the end of this script
RUNS_IN_NOMAD=false

# set the cook log path/filename
COOKLOG=/var/log/cook.log

# check if cooklog exists, create it if not
if [ ! -e $COOKLOG ]
then
    echo "Creating $COOKLOG" | tee -a $COOKLOG
else
    echo "WARNING $COOKLOG already exists"  | tee -a $COOKLOG
fi
date >> $COOKLOG

# -------------------- COMMON ---------------

STEPCOUNT=0
step() {
  STEPCOUNT=$(("$STEPCOUNT" + 1))
  STEP="$*"
  echo "Step $STEPCOUNT: $STEP" | tee -a $COOKLOG
}

exit_ok() {
  trap - EXIT
  exit 0
}

FAILED=" failed"
exit_error() {
  STEP="$*"
  FAILED=""
  exit 1
}

set -e
trap 'echo ERROR: $STEP$FAILED | (>&2 tee -a $COOKLOG)' EXIT

# -------------- BEGIN PACKAGE SETUP -------------

step "Bootstrap package repo"
mkdir -p /usr/local/etc/pkg/repos
# only modify repo if not already done in base image
# shellcheck disable=SC2016
test -e /usr/local/etc/pkg/repos/FreeBSD.conf || \
  echo 'FreeBSD: { url: "pkg+http://pkg.FreeBSD.org/${ABI}/quarterly" }' \
    >/usr/local/etc/pkg/repos/FreeBSD.conf
ASSUME_ALWAYS_YES=yes pkg bootstrap

step "Touch /etc/rc.conf"
touch /etc/rc.conf

# this is important, otherwise running /etc/rc from cook will
# overwrite the IP address set in tinirc
step "Remove ifconfig_epair0b from config"
# shellcheck disable=SC2015
sysrc -cq ifconfig_epair0b && sysrc -x ifconfig_epair0b || true

step "Disable sendmail"
service sendmail onedisable

step "Disable sshd"
service sshd onedisable || true

step "Create /usr/local/etc/rc.d"
mkdir -p /usr/local/etc/rc.d

step "Update package repository"
pkg update -f

# we need consul for consul agent
step "Install package consul"
pkg install -y consul

step "Install package consul-template"
pkg install -y consul-template

step "Patching consul-template rc scripts"
sed -i '' 's/^\(start_precmd=consul_template_startprecmd\)$/\1;'\
'extra_commands=reload/'  /usr/local/etc/rc.d/consul-template || true

step "Install package prometheus"
pkg install -y prometheus

step "Install package alertmanager"
pkg install -y alertmanager

step "Install package node_exporter"
pkg install -y node_exporter

step "Install package syslog-ng"
pkg install -y syslog-ng

step "Install package openssl"
pkg install -y openssl

step "Install package sudo"
pkg install -y sudo

step "Install package curl"
pkg install -y curl

step "Install package jq"
pkg install -y jq

step "Install package jo"
pkg install -y jo

step "Install package vault"
pkg install -y vault

step "Clean package installation"
pkg clean -y

# -------------- END PACKAGE SETUP -------------

#
# Create configurations
#

#
# Now generate the run command script "cook"
# It configures the system on the first run by creating the config file(s)
# On subsequent runs, it only starts sleeps (if nomad-jail) or simply exits
#


# this runs when image boots
# ----------------- BEGIN COOK ------------------


step "Clean cook artifacts"
rm -rf /usr/local/bin/cook /usr/local/share/cook

step "Install pot local"
tar -C /root/.pot_local -cf - . | tar -C /usr/local -xf -
rm -rf /root/.pot_local

step "Set file ownership on cook scripts"
chown -R root:wheel /usr/local/bin/cook /usr/local/share/cook
chmod 755 /usr/local/share/cook/bin/*


# ----------------- END COOK ------------------


# ---------- NO NEED TO EDIT BELOW ------------

step "Make cook script executable"
if [ -e /usr/local/bin/cook ]
then
    echo "setting executable bit on /usr/local/bin/cook" | tee -a $COOKLOG
    chmod u+x /usr/local/bin/cook
else
    exit_error "there is no /usr/local/bin/cook to make executable"
fi

#
# There are two ways of running a pot jail: "Normal", non-blocking mode and
# "Nomad", i.e. blocking mode (the pot start command does not return until
# the jail is stopped).
# For the normal mode, we create a /usr/local/etc/rc.d script that starts
# the "cook" script generated above each time, for the "Nomad" mode, the cook
# script is started by pot (configuration through flavour file), therefore
# we do not need to do anything here.
#

# Create rc.d script for "normal" mode:
step "Create rc.d script to start cook"
echo "creating rc.d script to start cook" | tee -a $COOKLOG

echo "#!/bin/sh
#
# PROVIDE: cook
# REQUIRE: LOGIN
# KEYWORD: shutdown
#
. /etc/rc.subr
name=\"cook\"
rcvar=\"cook_enable\"
load_rc_config \$name
: \${cook_enable:=\"NO\"}
: \${cook_env:=\"\"}
command=\"/usr/local/bin/cook\"
command_args=\"\"
run_rc_command \"\$1\"
" > /usr/local/etc/rc.d/cook

step "Make rc.d script to start cook executable"
if [ -e /usr/local/etc/rc.d/cook ]
then
  echo "Setting executable bit on cook rc file" | tee -a $COOKLOG
  chmod u+x /usr/local/etc/rc.d/cook
else
  exit_error "/usr/local/etc/rc.d/cook does not exist"
fi

if [ "$RUNS_IN_NOMAD" != "true" ]
then
  step "Enable cook service"
  # This is a non-nomad (non-blocking) jail, so we need to make sure the script
  # gets started when the jail is started:
  # Otherwise, /usr/local/bin/cook will be set as start script by the pot
  # flavour
  echo "enabling cook" | tee -a $COOKLOG
  service cook enable
fi

# -------------------- DONE ---------------
exit_ok

prometheus/prometheus+1:
prometheus/prometheus+1.sh:

prometheus/prometheus+2:
prometheus/prometheus+2.sh:

prometheus/prometheus+3:
prometheus/prometheus+3.sh:

prometheus/prometheus+4:
prometheus/prometheus+4.sh:
Password:===>  Creating a new pot
===>  pot name : prometheus-amd64-13_0
===>  type : single
===>  base : 13.0
===>  pot_base :
===>  level : 0
===>  network-type : public-bridge
===>  network-stack: ipv4
===>  ip : 10.192.0.3
===>  bridge :
===>  dns : inherit
===>  flavours : fbsd-update prometheus prometheus+1 prometheus+2 prometheus+3 prometheus+4
===>  Fetching FreeBSD 13.0
===>  Extract the tarball
=====>  Flavour: fbsd-update
=====>  Starting prometheus-amd64-13_0 pot for the initial bootstrap
=====>  mount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
defaultrouter: NO -> 10.192.0.1
===>  Starting the pot prometheus-amd64-13_0
ELF ldconfig path: /lib /usr/lib /usr/lib/compat
32-bit compatibility ldconfig path: /usr/lib32
Starting Network: lo0 epair0b.
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
	inet6 ::1 prefixlen 128
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
	inet 127.0.0.1 netmask 0xff000000
	groups: lo
	nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
epair0b: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 02:88:0c:c4:a6:0b
	inet 10.192.0.3 netmask 0xffc00000 broadcast 10.255.255.255
	groups: epair
	media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
	status: active
	nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
add host 127.0.0.1: gateway lo0 fib 0: route already in table
add net default: gateway 10.192.0.1
add host ::1: gateway lo0 fib 0: route already in table
add net fe80::: gateway ::1
add net ff02::: gateway ::1
add net ::ffff:0.0.0.0: gateway ::1
add net ::0.0.0.0: gateway ::1
Updating /var/run/os-release done.
Creating and/or trimming log files.
Clearing /tmp (X related).
Updating motd:.
Starting syslogd.
Starting sendmail_submit.
Starting sendmail_msp_queue.
Starting cron.

Tue Nov 30 19:24:03 UTC 2021
/usr/local/etc/pot/flavours/fbsd-update.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp/fbsd-update.sh
=====>  Executing fbsd-update script on prometheus-amd64-13_0
src component not installed, skipped
Looking up update.FreeBSD.org mirrors... 2 mirrors found.
Fetching public key from update1.freebsd.org... done.
Fetching metadata signature for 13.0-RELEASE from update1.freebsd.org... done.
Fetching metadata index... done.
Fetching 2 metadata files... done.
Inspecting system... done.
Preparing to download files... done.
Fetching 155 patches.....10....20....30....40....50....60....70....80....90....100....110....120....130....140....150.. done.
Applying patches... done.
Fetching 15 files... ....10.. done.
The following files will be removed as part of updating to
13.0-RELEASE-p5:
/etc/ssl/certs/080911ac.0
/etc/ssl/certs/0b7c536a.0
/etc/ssl/certs/0c4c9b6c.0
/etc/ssl/certs/116bf586.0
/etc/ssl/certs/1320b215.0
/etc/ssl/certs/26312675.0
/etc/ssl/certs/349f2832.0
/etc/ssl/certs/442adcac.0
/etc/ssl/certs/5a4d6896.0
/etc/ssl/certs/9c2e7d30.0
/etc/ssl/certs/a8dee976.0
/etc/ssl/certs/b1b8a7f3.0
/etc/ssl/certs/c01cdfa2.0
/etc/ssl/certs/c47d9980.0
/etc/ssl/certs/cb59f961.0
/etc/ssl/certs/d853d49e.0
/etc/ssl/certs/dc45b0bd.0
/etc/ssl/certs/ee1365c0.0
/etc/ssl/certs/f90208f7.0
/usr/share/certs/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
/usr/share/certs/trusted/Camerfirma_Global_Chambersign_Root.pem
/usr/share/certs/trusted/Certum_Root_CA.pem
/usr/share/certs/trusted/Chambers_of_Commerce_Root_-_2008.pem
/usr/share/certs/trusted/D-TRUST_Root_CA_3_2013.pem
/usr/share/certs/trusted/EC-ACC.pem
/usr/share/certs/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
/usr/share/certs/trusted/Global_Chambersign_Root_-_2008.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
/usr/share/certs/trusted/QuoVadis_Root_CA.pem
/usr/share/certs/trusted/Sonera_Class_2_Root_CA.pem
/usr/share/certs/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
/usr/share/certs/trusted/SwissSign_Platinum_CA_-_G2.pem
/usr/share/certs/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/trusted/Trustis_FPS_Root_CA.pem
/usr/share/certs/trusted/VeriSign_Universal_Root_Certification_Authority.pem
/usr/share/certs/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
The following files will be added as part of updating to
13.0-RELEASE-p5:
/etc/ssl/blacklisted/080911ac.0
/etc/ssl/blacklisted/0b7c536a.0
/etc/ssl/blacklisted/0c4c9b6c.0
/etc/ssl/blacklisted/116bf586.0
/etc/ssl/blacklisted/1320b215.0
/etc/ssl/blacklisted/26312675.0
/etc/ssl/blacklisted/349f2832.0
/etc/ssl/blacklisted/442adcac.0
/etc/ssl/blacklisted/5a4d6896.0
/etc/ssl/blacklisted/9c2e7d30.0
/etc/ssl/blacklisted/a8dee976.0
/etc/ssl/blacklisted/b1b8a7f3.0
/etc/ssl/blacklisted/c01cdfa2.0
/etc/ssl/blacklisted/c47d9980.0
/etc/ssl/blacklisted/cb59f961.0
/etc/ssl/blacklisted/d853d49e.0
/etc/ssl/blacklisted/dc45b0bd.0
/etc/ssl/blacklisted/ee1365c0.0
/etc/ssl/blacklisted/f90208f7.0
/etc/ssl/certs/002c0b4f.0
/etc/ssl/certs/9482e63a.0
/etc/ssl/certs/b433981b.0
/etc/ssl/certs/b81b93f0.0
/etc/ssl/certs/e35234b1.0
/etc/ssl/certs/fa5da96b.0
/etc/ssl/certs/feffd413.0
/usr/include/c++/v1/barrier
/usr/include/c++/v1/concepts
/usr/include/c++/v1/execution
/usr/include/c++/v1/latch
/usr/include/c++/v1/numbers
/usr/include/c++/v1/semaphore
/usr/include/c++/v1/tr1/barrier
/usr/include/c++/v1/tr1/concepts
/usr/include/c++/v1/tr1/execution
/usr/include/c++/v1/tr1/latch
/usr/include/c++/v1/tr1/numbers
/usr/include/c++/v1/tr1/semaphore
/usr/share/certs/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
/usr/share/certs/blacklisted/Camerfirma_Global_Chambersign_Root.pem
/usr/share/certs/blacklisted/Certum_Root_CA.pem
/usr/share/certs/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
/usr/share/certs/blacklisted/D-TRUST_Root_CA_3_2013.pem
/usr/share/certs/blacklisted/EC-ACC.pem
/usr/share/certs/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
/usr/share/certs/blacklisted/Global_Chambersign_Root_-_2008.pem
/usr/share/certs/blacklisted/OISTE_WISeKey_Global_Root_GA_CA.pem
/usr/share/certs/blacklisted/QuoVadis_Root_CA.pem
/usr/share/certs/blacklisted/Sonera_Class_2_Root_CA.pem
/usr/share/certs/blacklisted/Staat_der_Nederlanden_Root_CA_-_G3.pem
/usr/share/certs/blacklisted/SwissSign_Platinum_CA_-_G2.pem
/usr/share/certs/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/blacklisted/Trustis_FPS_Root_CA.pem
/usr/share/certs/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
/usr/share/certs/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
/usr/share/certs/trusted/ANF_Secure_Server_Root_CA.pem
/usr/share/certs/trusted/Certum_EC-384_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Root_CA.pem
/usr/share/certs/trusted/GLOBALTRUST_2020.pem
/usr/share/certs/trusted/GlobalSign_Root_E46.pem
/usr/share/certs/trusted/GlobalSign_Root_R46.pem
The following files will be updated as part of updating to
13.0-RELEASE-p5:
/bin/freebsd-version
/lib/libcasper.so.1
/lib/libcrypto.so.111
/rescue/[
/rescue/bectl
/rescue/bsdlabel
/rescue/bunzip2
/rescue/bzcat
/rescue/bzip2
/rescue/camcontrol
/rescue/cat
/rescue/ccdconfig
/rescue/chflags
/rescue/chgrp
/rescue/chio
/rescue/chmod
/rescue/chown
/rescue/chroot
/rescue/clri
/rescue/cp
/rescue/csh
/rescue/date
/rescue/dd
/rescue/devfs
/rescue/df
/rescue/dhclient
/rescue/disklabel
/rescue/dmesg
/rescue/dump
/rescue/dumpfs
/rescue/dumpon
/rescue/echo
/rescue/ed
/rescue/ex
/rescue/expr
/rescue/fastboot
/rescue/fasthalt
/rescue/fdisk
/rescue/fsck
/rescue/fsck_4.2bsd
/rescue/fsck_ffs
/rescue/fsck_msdosfs
/rescue/fsck_ufs
/rescue/fsdb
/rescue/fsirand
/rescue/gbde
/rescue/geom
/rescue/getfacl
/rescue/glabel
/rescue/gpart
/rescue/groups
/rescue/gunzip
/rescue/gzcat
/rescue/gzip
/rescue/halt
/rescue/head
/rescue/hostname
/rescue/id
/rescue/ifconfig
/rescue/init
/rescue/ipf
/rescue/iscsictl
/rescue/iscsid
/rescue/kenv
/rescue/kill
/rescue/kldconfig
/rescue/kldload
/rescue/kldstat
/rescue/kldunload
/rescue/ldconfig
/rescue/less
/rescue/link
/rescue/ln
/rescue/ls
/rescue/lzcat
/rescue/lzma
/rescue/md5
/rescue/mdconfig
/rescue/mdmfs
/rescue/mkdir
/rescue/mknod
/rescue/more
/rescue/mount
/rescue/mount_cd9660
/rescue/mount_msdosfs
/rescue/mount_nfs
/rescue/mount_nullfs
/rescue/mount_udf
/rescue/mount_unionfs
/rescue/mt
/rescue/mv
/rescue/nc
/rescue/newfs
/rescue/newfs_msdos
/rescue/nos-tun
/rescue/pgrep
/rescue/ping
/rescue/ping6
/rescue/pkill
/rescue/poweroff
/rescue/ps
/rescue/pwd
/rescue/rcorder
/rescue/rdump
/rescue/realpath
/rescue/reboot
/rescue/red
/rescue/rescue
/rescue/restore
/rescue/rm
/rescue/rmdir
/rescue/route
/rescue/routed
/rescue/rrestore
/rescue/rtquery
/rescue/rtsol
/rescue/savecore
/rescue/sed
/rescue/setfacl
/rescue/sh
/rescue/shutdown
/rescue/sleep
/rescue/spppcontrol
/rescue/stty
/rescue/swapon
/rescue/sync
/rescue/sysctl
/rescue/tail
/rescue/tar
/rescue/tcsh
/rescue/tee
/rescue/test
/rescue/tunefs
/rescue/umount
/rescue/unlink
/rescue/unlzma
/rescue/unxz
/rescue/unzstd
/rescue/vi
/rescue/whoami
/rescue/xz
/rescue/xzcat
/rescue/zcat
/rescue/zdb
/rescue/zfs
/rescue/zpool
/rescue/zstd
/rescue/zstdcat
/rescue/zstdmt
/sbin/ggatec
/usr/bin/bc
/usr/bin/dc
/usr/bin/openssl
/usr/include/openssl/opensslv.h
/usr/include/private/event1/event.h
/usr/lib/libcrypto.a
/usr/lib/libcrypto_p.a
/usr/lib/libfetch.a
/usr/lib/libfetch.so.6
/usr/lib/libfetch_p.a
/usr/lib/libprivateevent1.a
/usr/lib/libprivateevent1.so.1
/usr/lib/libprivateevent1_p.a
/usr/lib/libradius.a
/usr/lib/libradius.so.4
/usr/lib/libradius_p.a
/usr/lib/libssl.a
/usr/lib/libssl.so.111
/usr/lib/libssl_p.a
/usr/sbin/bhyve
/usr/sbin/ftp-proxy
/usr/sbin/hostapd
/usr/sbin/ntp-keygen
/usr/sbin/wpa_cli
/usr/sbin/wpa_supplicant
/usr/sbin/ypldap
/usr/share/certs/trusted/ACCVRAIZ1.pem
/usr/share/certs/trusted/AC_RAIZ_FNMT-RCM.pem
/usr/share/certs/trusted/Actalis_Authentication_Root_CA.pem
/usr/share/certs/trusted/AffirmTrust_Commercial.pem
/usr/share/certs/trusted/AffirmTrust_Networking.pem
/usr/share/certs/trusted/AffirmTrust_Premium.pem
/usr/share/certs/trusted/AffirmTrust_Premium_ECC.pem
/usr/share/certs/trusted/Amazon_Root_CA_1.pem
/usr/share/certs/trusted/Amazon_Root_CA_2.pem
/usr/share/certs/trusted/Amazon_Root_CA_3.pem
/usr/share/certs/trusted/Amazon_Root_CA_4.pem
/usr/share/certs/trusted/Atos_TrustedRoot_2011.pem
/usr/share/certs/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
/usr/share/certs/trusted/Baltimore_CyberTrust_Root.pem
/usr/share/certs/trusted/Buypass_Class_2_Root_CA.pem
/usr/share/certs/trusted/Buypass_Class_3_Root_CA.pem
/usr/share/certs/trusted/CA_Disig_Root_R2.pem
/usr/share/certs/trusted/CFCA_EV_ROOT.pem
/usr/share/certs/trusted/COMODO_Certification_Authority.pem
/usr/share/certs/trusted/COMODO_ECC_Certification_Authority.pem
/usr/share/certs/trusted/COMODO_RSA_Certification_Authority.pem
/usr/share/certs/trusted/Certigna.pem
/usr/share/certs/trusted/Certigna_Root_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Network_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Network_CA_2.pem
/usr/share/certs/trusted/Comodo_AAA_Services_root.pem
/usr/share/certs/trusted/Cybertrust_Global_Root.pem
/usr/share/certs/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
/usr/share/certs/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
/usr/share/certs/trusted/DST_Root_CA_X3.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_G2.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_G3.pem
/usr/share/certs/trusted/DigiCert_Global_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Global_Root_G2.pem
/usr/share/certs/trusted/DigiCert_Global_Root_G3.pem
/usr/share/certs/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Trusted_Root_G4.pem
/usr/share/certs/trusted/E-Tugra_Certification_Authority.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_G2.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_G4.pem
/usr/share/certs/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
/usr/share/certs/trusted/GDCA_TrustAUTH_R5_ROOT.pem
/usr/share/certs/trusted/GTS_Root_R1.pem
/usr/share/certs/trusted/GTS_Root_R2.pem
/usr/share/certs/trusted/GTS_Root_R3.pem
/usr/share/certs/trusted/GTS_Root_R4.pem
/usr/share/certs/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
/usr/share/certs/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
/usr/share/certs/trusted/GlobalSign_Root_CA.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R2.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R3.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R6.pem
/usr/share/certs/trusted/Go_Daddy_Class_2_CA.pem
/usr/share/certs/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
/usr/share/certs/trusted/Hongkong_Post_Root_CA_1.pem
/usr/share/certs/trusted/Hongkong_Post_Root_CA_3.pem
/usr/share/certs/trusted/ISRG_Root_X1.pem
/usr/share/certs/trusted/IdenTrust_Commercial_Root_CA_1.pem
/usr/share/certs/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
/usr/share/certs/trusted/Izenpe_com.pem
/usr/share/certs/trusted/Microsec_e-Szigno_Root_CA_2009.pem
/usr/share/certs/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem
/usr/share/certs/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem
/usr/share/certs/trusted/NAVER_Global_Root_Certification_Authority.pem
/usr/share/certs/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
/usr/share/certs/trusted/Network_Solutions_Certificate_Authority.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_1_G3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_2.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_2_G3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_3_G3.pem
/usr/share/certs/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
/usr/share/certs/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
/usr/share/certs/trusted/SSL_com_Root_Certification_Authority_ECC.pem
/usr/share/certs/trusted/SSL_com_Root_Certification_Authority_RSA.pem
/usr/share/certs/trusted/SZAFIR_ROOT_CA2.pem
/usr/share/certs/trusted/SecureSign_RootCA11.pem
/usr/share/certs/trusted/SecureTrust_CA.pem
/usr/share/certs/trusted/Secure_Global_CA.pem
/usr/share/certs/trusted/Security_Communication_RootCA2.pem
/usr/share/certs/trusted/Security_Communication_Root_CA.pem
/usr/share/certs/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
/usr/share/certs/trusted/Starfield_Class_2_CA.pem
/usr/share/certs/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/SwissSign_Gold_CA_-_G2.pem
/usr/share/certs/trusted/SwissSign_Silver_CA_-_G2.pem
/usr/share/certs/trusted/T-TeleSec_GlobalRoot_Class_2.pem
/usr/share/certs/trusted/T-TeleSec_GlobalRoot_Class_3.pem
/usr/share/certs/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
/usr/share/certs/trusted/TWCA_Global_Root_CA.pem
/usr/share/certs/trusted/TWCA_Root_Certification_Authority.pem
/usr/share/certs/trusted/TeliaSonera_Root_CA_v1.pem
/usr/share/certs/trusted/TrustCor_ECA-1.pem
/usr/share/certs/trusted/TrustCor_RootCert_CA-1.pem
/usr/share/certs/trusted/TrustCor_RootCert_CA-2.pem
/usr/share/certs/trusted/Trustwave_Global_Certification_Authority.pem
/usr/share/certs/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
/usr/share/certs/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
/usr/share/certs/trusted/UCA_Extended_Validation_Root.pem
/usr/share/certs/trusted/UCA_Global_G2_Root.pem
/usr/share/certs/trusted/USERTrust_ECC_Certification_Authority.pem
/usr/share/certs/trusted/USERTrust_RSA_Certification_Authority.pem
/usr/share/certs/trusted/XRamp_Global_CA_Root.pem
/usr/share/certs/trusted/certSIGN_ROOT_CA.pem
/usr/share/certs/trusted/certSIGN_Root_CA_G2.pem
/usr/share/certs/trusted/e-Szigno_Root_CA_2017.pem
/usr/share/certs/trusted/ePKI_Root_Certification_Authority.pem
/usr/share/certs/trusted/emSign_ECC_Root_CA_-_C3.pem
/usr/share/certs/trusted/emSign_ECC_Root_CA_-_G3.pem
/usr/share/certs/trusted/emSign_Root_CA_-_C1.pem
/usr/share/certs/trusted/emSign_Root_CA_-_G1.pem
/usr/share/zoneinfo/Asia/Amman
/usr/share/zoneinfo/Asia/Gaza
/usr/share/zoneinfo/Asia/Hebron
/usr/share/zoneinfo/Pacific/Apia
/usr/share/zoneinfo/Pacific/Fiji
Installing updates...Scanning //usr/share/certs/blacklisted for certificates...
Scanning //usr/share/certs/trusted for certificates...
 done.
=====>  Stop the pot prometheus-amd64-13_0
=====>  Remove epair0[a|b] network interfaces
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-13_0/m/dev
=====>  Flavour: prometheus
=====>  Executing prometheus pot commands on prometheus-amd64-13_0
=====>  mount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
/usr/local/etc/pot/flavours/prometheus.d/local -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local
/usr/local/etc/pot/flavours/prometheus.d/local/bin -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/bin
/usr/local/etc/pot/flavours/prometheus.d/local/bin/cook -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/bin/cook
/usr/local/etc/pot/flavours/prometheus.d/local/share -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consulca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-template-metrics.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consul-template-metrics.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-template.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consul-template.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/client.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/client.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/alertmanager.yml.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/alertmanager.yml.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-agent.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consul-agent.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/syslog-ng.conf.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/syslog-ng.conf.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metricsca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/metricsca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulagent.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consulagent.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/metrics.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics-ca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/metrics-ca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/prometheus.yml.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/prometheus.yml.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/client.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/client.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulagent.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/consulagent.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/ca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/ca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/templates/metrics.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-metrics-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/unwrap-metrics-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-node-exporter.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-node-exporter.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-metrics.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/reload-metrics.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-syslog-ng.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-syslog-ng.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-consul.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/reload-consul.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/setup-local-unbound-provision.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/setup-local-unbound-provision.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-consul.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-consul.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-metrics.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-metrics.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-cluster-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/unwrap-cluster-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-consul-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/unwrap-consul-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/setup-local-unbound.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/setup-local-unbound.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-prometheus.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-prometheus.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-consul-template.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/reload-consul-template.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-consul-template.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/root/.pot_local/share/cook/bin/configure-consul-template.sh
=====>  Source /usr/local/etc/pot/flavours/prometheus.d/local copied in the pot prometheus-amd64-13_0
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
=====>  /mnt/data/pot/jails/prometheus-amd64-13_0/m/dev is already unmounted
=====>  Starting prometheus-amd64-13_0 pot for the initial bootstrap
=====>  mount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
defaultrouter: 10.192.0.1 -> 10.192.0.1
===>  Starting the pot prometheus-amd64-13_0
ELF ldconfig path: /lib /usr/lib /usr/lib/compat
32-bit compatibility ldconfig path: /usr/lib32
Starting Network: lo0 epair0b.
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
	inet6 ::1 prefixlen 128
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
	inet 127.0.0.1 netmask 0xff000000
	groups: lo
	nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
epair0b: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 02:22:b5:08:71:0b
	inet 10.192.0.3 netmask 0xffc00000 broadcast 10.255.255.255
	groups: epair
	media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
	status: active
	nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
add host 127.0.0.1: gateway lo0 fib 0: route already in table
add net default: gateway 10.192.0.1
add host ::1: gateway lo0 fib 0: route already in table
add net fe80::: gateway ::1
add net ff02::: gateway ::1
add net ::ffff:0.0.0.0: gateway ::1
add net ::0.0.0.0: gateway ::1
Updating /var/run/os-release done.
Creating and/or trimming log files.
Clearing /tmp (X related).
Updating motd:.
Starting syslogd.
Starting sendmail_submit.
Starting sendmail_msp_queue.
Starting cron.

Tue Nov 30 19:25:11 UTC 2021
/usr/local/etc/pot/flavours/prometheus.sh -> /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp/prometheus.sh
=====>  Executing prometheus script on prometheus-amd64-13_0
Creating /var/log/cook.log
Step 1: Bootstrap package repo
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] Installing pkg-1.17.5...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] Extracting pkg-1.17.5: .......... done
Bootstrapping pkg from pkg+http://pkg.FreeBSD.org/FreeBSD:13:amd64/quarterly, please wait...
Step 2: Touch /etc/rc.conf
Step 3: Remove ifconfig_epair0b from config
Step 4: Disable sendmail
sendmail disabled in /etc/rc.conf
sendmail_submit disabled in /etc/rc.conf
sendmail_msp_queue disabled in /etc/rc.conf
Step 5: Disable sshd
sshd disabled in /etc/rc.conf
Step 6: Create /usr/local/etc/rc.d
Step 7: Update package repository
Updating FreeBSD repository catalogue...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] Fetching meta.conf: . done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] Fetching packagesite.pkg: .......... done
Processing entries: .......... done
FreeBSD repository update completed. 31147 packages processed.
All repositories are up to date.
Step 8: Install package consul
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
Updating database digests format: . done
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	consul: 1.9.9

Number of packages to be installed: 1

The process will require 78 MiB more space.
26 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching consul-1.9.9.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing consul-1.9.9...
===> Creating groups.
Creating group 'consul' with gid '469'.
===> Creating users
Creating user 'consul' with uid '469'.
===> Creating homedir(s)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting consul-1.9.9: ..... done
Step 9: Install package consul-template
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	consul-template: 0.27.0

Number of packages to be installed: 1

The process will require 10 MiB more space.
3 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching consul-template-0.27.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing consul-template-0.27.0...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting consul-template-0.27.0: ..... done
Step 10: Patching consul-template rc scripts
Step 11: Install package prometheus
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	prometheus: 2.30.0

Number of packages to be installed: 1

The process will require 143 MiB more space.
27 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching prometheus-2.30.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing prometheus-2.30.0...
===> Creating groups.
Creating group 'prometheus' with gid '478'.
===> Creating users
Creating user 'prometheus' with uid '478'.
===> Creating homedir(s)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting prometheus-2.30.0: .......... done
Step 12: Install package alertmanager
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	alertmanager: 0.23.0

Number of packages to be installed: 1

The process will require 40 MiB more space.
10 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching alertmanager-0.23.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing alertmanager-0.23.0...
===> Creating groups.
Creating group 'alertmanager' with gid '479'.
===> Creating users
Creating user 'alertmanager' with uid '479'.
===> Creating homedir(s)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting alertmanager-0.23.0: ....... done
Step 13: Install package node_exporter
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	node_exporter: 1.2.2

Number of packages to be installed: 1

The process will require 11 MiB more space.
3 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching node_exporter-1.2.2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing node_exporter-1.2.2...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting node_exporter-1.2.2: .......... done
=====
Message from node_exporter-1.2.2:

--
If upgrading from a version of node_exporter <0.15.0 you'll need to update any
custom command line flags that you may have set as it now requires a
double-dash (--flag) instead of a single dash (-flag).
The collector flags in 0.15.0 have now been replaced with individual boolean
flags and the -collector.procfs` and -collector.sysfs` flags have been renamed
to --path.procfs and --path.sysfs respectively.
Step 14: Install package syslog-ng
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 17 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	ca_root_nss: 3.69_1
	curl: 7.79.1
	e2fsprogs-libuuid: 1.46.4
	gettext-runtime: 0.21
	glib: 2.70.1,2
	indexinfo: 0.3.1
	json-c: 0.15_1
	libffi: 3.3_1
	libiconv: 1.16
	libnghttp2: 1.44.0
	libssh2: 1.9.0_3,3
	libxml2: 2.9.12
	mpdecimal: 2.5.1
	pcre: 8.45
	python38: 3.8.12
	readline: 8.1.1
	syslog-ng: 3.34.1

Number of packages to be installed: 17

The process will require 167 MiB more space.
27 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/17] Fetching syslog-ng-3.34.1.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/17] Fetching e2fsprogs-libuuid-1.46.4.pkg: ..... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [3/17] Fetching curl-7.79.1.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [4/17] Fetching libnghttp2-1.44.0.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [5/17] Fetching libssh2-1.9.0_3,3.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [6/17] Fetching ca_root_nss-3.69_1.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [7/17] Fetching pcre-8.45.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [8/17] Fetching json-c-0.15_1.pkg: ........ done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [9/17] Fetching glib-2.70.1,2.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [10/17] Fetching libxml2-2.9.12.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [11/17] Fetching python38-3.8.12.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [12/17] Fetching mpdecimal-2.5.1.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [13/17] Fetching readline-8.1.1.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [14/17] Fetching indexinfo-0.3.1.pkg: . done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [15/17] Fetching libffi-3.3_1.pkg: ..... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [16/17] Fetching gettext-runtime-0.21.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [17/17] Fetching libiconv-1.16.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/17] Installing indexinfo-0.3.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/17] Extracting indexinfo-0.3.1: .... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/17] Installing mpdecimal-2.5.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/17] Extracting mpdecimal-2.5.1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [3/17] Installing readline-8.1.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [3/17] Extracting readline-8.1.1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [4/17] Installing libffi-3.3_1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [4/17] Extracting libffi-3.3_1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [5/17] Installing gettext-runtime-0.21...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [5/17] Extracting gettext-runtime-0.21: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [6/17] Installing libnghttp2-1.44.0...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [6/17] Extracting libnghttp2-1.44.0: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [7/17] Installing libssh2-1.9.0_3,3...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [7/17] Extracting libssh2-1.9.0_3,3: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [8/17] Installing ca_root_nss-3.69_1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [8/17] Extracting ca_root_nss-3.69_1: ........ done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [9/17] Installing pcre-8.45...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [9/17] Extracting pcre-8.45: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [10/17] Installing libxml2-2.9.12...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [10/17] Extracting libxml2-2.9.12: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [11/17] Installing python38-3.8.12...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [11/17] Extracting python38-3.8.12: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [12/17] Installing libiconv-1.16...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [12/17] Extracting libiconv-1.16: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [13/17] Installing e2fsprogs-libuuid-1.46.4...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [13/17] Extracting e2fsprogs-libuuid-1.46.4: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [14/17] Installing curl-7.79.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [14/17] Extracting curl-7.79.1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [15/17] Installing json-c-0.15_1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [15/17] Extracting json-c-0.15_1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [16/17] Installing glib-2.70.1,2...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [16/17] Extracting glib-2.70.1,2: .......... done
No schema files found: doing nothing.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [17/17] Installing syslog-ng-3.34.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [17/17] Extracting syslog-ng-3.34.1: .......... done
=====
Message from ca_root_nss-3.69_1:

--
FreeBSD does not, and can not warrant that the certification authorities
whose certificates are included in this package have in any way been
audited for trustworthiness or RFC 3647 compliance.

Assessment and verification of trust is the complete responsibility of the
system administrator.


This package installs symlinks to support root certificates discovery by
default for software that uses OpenSSL.

This enables SSL Certificate Verification by client software without manual
intervention.

If you prefer to do this manually, replace the following symlinks with
either an empty file or your site-local certificate bundle.

  * /etc/ssl/cert.pem
  * /usr/local/etc/ssl/cert.pem
  * /usr/local/openssl/cert.pem
=====
Message from python38-3.8.12:

--
Note that some standard Python modules are provided as separate ports
as they require additional dependencies. They are available as:

py38-gdbm       databases/py-gdbm@py38
py38-sqlite3    databases/py-sqlite3@py38
py38-tkinter    x11-toolkits/py-tkinter@py38
=====
Message from syslog-ng-3.34.1:

--
syslog-ng is now installed!  To replace FreeBSD's standard syslogd
(/usr/sbin/syslogd), complete these steps:

1. Create a configuration file named /usr/local/etc/syslog-ng.conf
   (a sample named syslog-ng.conf.sample has been included in
   /usr/local/etc). Note that this is a change in 2.0.2
   version, previous ones put the config file in
   /usr/local/etc/syslog-ng/syslog-ng.conf, so if this is an update
   move that file in the right place

2. Configure syslog-ng to start automatically by adding the following
   to /etc/rc.conf:

        syslog_ng_enable="YES"

3. Prevent the standard FreeBSD syslogd from starting automatically by
   adding a line to the end of your /etc/rc.conf file that reads:

        syslogd_enable="NO"

4. Shut down the standard FreeBSD syslogd:

     kill `cat /var/run/syslog.pid`

5. Start syslog-ng:

     /usr/local/etc/rc.d/syslog-ng start
Step 15: Install package openssl
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	openssl: 1.1.1l,1

Number of packages to be installed: 1

The process will require 14 MiB more space.
4 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching openssl-1.1.1l,1.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing openssl-1.1.1l,1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting openssl-1.1.1l,1: .......... done
Step 16: Install package sudo
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	sudo: 1.9.8p2

Number of packages to be installed: 1

The process will require 7 MiB more space.
1 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching sudo-1.9.8p2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing sudo-1.9.8p2...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting sudo-1.9.8p2: .......... done
Step 17: Install package curl
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
Checking integrity... done (0 conflicting)
The most recent versions of packages are already installed
Step 18: Install package jq
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 2 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	jq: 1.6
	oniguruma: 6.9.7.1

Number of packages to be installed: 2

The process will require 2 MiB more space.
499 KiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/2] Fetching jq-1.6.pkg: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/2] Fetching oniguruma-6.9.7.1.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/2] Installing oniguruma-6.9.7.1...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/2] Extracting oniguruma-6.9.7.1: .......... done
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/2] Installing jq-1.6...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [2/2] Extracting jq-1.6: .......... done
Step 19: Install package jo
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	jo: 1.4

Number of packages to be installed: 1

19 KiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching jo-1.4.pkg: ... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing jo-1.4...
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting jo-1.4: ...... done
Step 20: Install package vault
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	vault: 1.8.2

Number of packages to be installed: 1

The process will require 156 MiB more space.
49 MiB to be downloaded.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching vault-1.8.2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Installing vault-1.8.2...
===> Creating groups.
Creating group 'vault' with gid '471'.
===> Creating users
Creating user 'vault' with uid '471'.
[prometheus-amd64-13_0.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting vault-1.8.2: ..... done
=====
Message from vault-1.8.2:

--
The vault user created by the vault package is now a member of the daemon
class, which will allow it to use mlock() when started by the rc script. This
will not be reflected in systems where the user already exists. Please add the
vault user to the daemon class manually by running:

pw usermod -L daemon -n vault

or delete the user and reinstall the package.

You may also need to increase memorylocked for the daemon class in
/etc/rc.conf to more than 1024M (the default) or more:

vault_limits_mlock="2048M"

Or to disable mlock, add:

disable_mlock = 1

to /usr/local/etc/vault.hcl
Step 21: Clean package installation
Nothing to do.
Step 22: Clean cook artifacts
Step 23: Install pot local
Step 24: Set file ownership on cook scripts
Step 25: Make cook script executable
setting executable bit on /usr/local/bin/cook
Step 26: Create rc.d script to start cook
creating rc.d script to start cook
Step 27: Make rc.d script to start cook executable
Setting executable bit on cook rc file
Step 28: Enable cook service
enabling cook
cook enabled in /etc/rc.conf
=====>  Stop the pot prometheus-amd64-13_0
=====>  Remove epair0[a|b] network interfaces
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-13_0/m/tmp
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-13_0/m/dev
=====>  Flavour: prometheus+1
=====>  Executing prometheus+1 pot commands on prometheus-amd64-13_0
=====>  No shell script available for the flavour prometheus+1
=====>  Flavour: prometheus+2
=====>  Executing prometheus+2 pot commands on prometheus-amd64-13_0
=====>  No shell script available for the flavour prometheus+2
=====>  Flavour: prometheus+3
=====>  Executing prometheus+3 pot commands on prometheus-amd64-13_0
=====>  No shell script available for the flavour prometheus+3
=====>  Flavour: prometheus+4
=====>  Executing prometheus+4 pot commands on prometheus-amd64-13_0
=====>  No shell script available for the flavour prometheus+4

prometheus-amd64-12_2_0.9.28:


prometheus/prometheus:
copy-in -s /usr/local/etc/pot/flavours/prometheus.d/local -d /root/.pot_local
prometheus/prometheus.sh:
#!/bin/sh

# Based on POTLUCK TEMPLATE v3.0
# Altered by Michael Gmelin
#
# EDIT THE FOLLOWING FOR NEW FLAVOUR:
# 1. RUNS_IN_NOMAD - true or false
# 2. If RUNS_IN_NOMAD is false, can delete the <flavour>+4 file, else
#    make sure pot create command doesn't include it
# 3. Create a matching <flavour> file with this <flavour>.sh file that
#    contains the copy-in commands for the config files from <flavour>.d/
#    Remember that the package directories don't exist yet, so likely copy
#    to /root
# 4. Adjust package installation between BEGIN & END PACKAGE SETUP
# 5. Adjust jail configuration script generation between BEGIN & END COOK
#    Configure the config files that have been copied in where necessary

# Set this to true if this jail flavour is to be created as a nomad
# (i.e. blocking) jail.
# You can then query it in the cook script generation below and the script
# is installed appropriately at the end of this script
RUNS_IN_NOMAD=false

# set the cook log path/filename
COOKLOG=/var/log/cook.log

# check if cooklog exists, create it if not
if [ ! -e $COOKLOG ]
then
    echo "Creating $COOKLOG" | tee -a $COOKLOG
else
    echo "WARNING $COOKLOG already exists"  | tee -a $COOKLOG
fi
date >> $COOKLOG

# -------------------- COMMON ---------------

STEPCOUNT=0
step() {
  STEPCOUNT=$(("$STEPCOUNT" + 1))
  STEP="$*"
  echo "Step $STEPCOUNT: $STEP" | tee -a $COOKLOG
}

exit_ok() {
  trap - EXIT
  exit 0
}

FAILED=" failed"
exit_error() {
  STEP="$*"
  FAILED=""
  exit 1
}

set -e
trap 'echo ERROR: $STEP$FAILED | (>&2 tee -a $COOKLOG)' EXIT

# -------------- BEGIN PACKAGE SETUP -------------

step "Bootstrap package repo"
mkdir -p /usr/local/etc/pkg/repos
# only modify repo if not already done in base image
# shellcheck disable=SC2016
test -e /usr/local/etc/pkg/repos/FreeBSD.conf || \
  echo 'FreeBSD: { url: "pkg+http://pkg.FreeBSD.org/${ABI}/quarterly" }' \
    >/usr/local/etc/pkg/repos/FreeBSD.conf
ASSUME_ALWAYS_YES=yes pkg bootstrap

step "Touch /etc/rc.conf"
touch /etc/rc.conf

# this is important, otherwise running /etc/rc from cook will
# overwrite the IP address set in tinirc
step "Remove ifconfig_epair0b from config"
# shellcheck disable=SC2015
sysrc -cq ifconfig_epair0b && sysrc -x ifconfig_epair0b || true

step "Disable sendmail"
service sendmail onedisable

step "Disable sshd"
service sshd onedisable || true

step "Create /usr/local/etc/rc.d"
mkdir -p /usr/local/etc/rc.d

step "Update package repository"
pkg update -f

# we need consul for consul agent
step "Install package consul"
pkg install -y consul

step "Install package consul-template"
pkg install -y consul-template

step "Patching consul-template rc scripts"
sed -i '' 's/^\(start_precmd=consul_template_startprecmd\)$/\1;'\
'extra_commands=reload/'  /usr/local/etc/rc.d/consul-template || true

step "Install package prometheus"
pkg install -y prometheus

step "Install package alertmanager"
pkg install -y alertmanager

step "Install package node_exporter"
pkg install -y node_exporter

step "Install package syslog-ng"
pkg install -y syslog-ng

step "Install package openssl"
pkg install -y openssl

step "Install package sudo"
pkg install -y sudo

step "Install package curl"
pkg install -y curl

step "Install package jq"
pkg install -y jq

step "Install package jo"
pkg install -y jo

step "Install package vault"
pkg install -y vault

step "Clean package installation"
pkg clean -y

# -------------- END PACKAGE SETUP -------------

#
# Create configurations
#

#
# Now generate the run command script "cook"
# It configures the system on the first run by creating the config file(s)
# On subsequent runs, it only starts sleeps (if nomad-jail) or simply exits
#


# this runs when image boots
# ----------------- BEGIN COOK ------------------


step "Clean cook artifacts"
rm -rf /usr/local/bin/cook /usr/local/share/cook

step "Install pot local"
tar -C /root/.pot_local -cf - . | tar -C /usr/local -xf -
rm -rf /root/.pot_local

step "Set file ownership on cook scripts"
chown -R root:wheel /usr/local/bin/cook /usr/local/share/cook
chmod 755 /usr/local/share/cook/bin/*


# ----------------- END COOK ------------------


# ---------- NO NEED TO EDIT BELOW ------------

step "Make cook script executable"
if [ -e /usr/local/bin/cook ]
then
    echo "setting executable bit on /usr/local/bin/cook" | tee -a $COOKLOG
    chmod u+x /usr/local/bin/cook
else
    exit_error "there is no /usr/local/bin/cook to make executable"
fi

#
# There are two ways of running a pot jail: "Normal", non-blocking mode and
# "Nomad", i.e. blocking mode (the pot start command does not return until
# the jail is stopped).
# For the normal mode, we create a /usr/local/etc/rc.d script that starts
# the "cook" script generated above each time, for the "Nomad" mode, the cook
# script is started by pot (configuration through flavour file), therefore
# we do not need to do anything here.
#

# Create rc.d script for "normal" mode:
step "Create rc.d script to start cook"
echo "creating rc.d script to start cook" | tee -a $COOKLOG

echo "#!/bin/sh
#
# PROVIDE: cook
# REQUIRE: LOGIN
# KEYWORD: shutdown
#
. /etc/rc.subr
name=\"cook\"
rcvar=\"cook_enable\"
load_rc_config \$name
: \${cook_enable:=\"NO\"}
: \${cook_env:=\"\"}
command=\"/usr/local/bin/cook\"
command_args=\"\"
run_rc_command \"\$1\"
" > /usr/local/etc/rc.d/cook

step "Make rc.d script to start cook executable"
if [ -e /usr/local/etc/rc.d/cook ]
then
  echo "Setting executable bit on cook rc file" | tee -a $COOKLOG
  chmod u+x /usr/local/etc/rc.d/cook
else
  exit_error "/usr/local/etc/rc.d/cook does not exist"
fi

if [ "$RUNS_IN_NOMAD" != "true" ]
then
  step "Enable cook service"
  # This is a non-nomad (non-blocking) jail, so we need to make sure the script
  # gets started when the jail is started:
  # Otherwise, /usr/local/bin/cook will be set as start script by the pot
  # flavour
  echo "enabling cook" | tee -a $COOKLOG
  service cook enable
fi

# -------------------- DONE ---------------
exit_ok

prometheus/prometheus+1:
prometheus/prometheus+1.sh:

prometheus/prometheus+2:
prometheus/prometheus+2.sh:

prometheus/prometheus+3:
prometheus/prometheus+3.sh:

prometheus/prometheus+4:
prometheus/prometheus+4.sh:
Password:===>  Creating a new pot
===>  pot name : prometheus-amd64-12_2
===>  type : single
===>  base : 12.2
===>  pot_base :
===>  level : 0
===>  network-type : public-bridge
===>  network-stack: ipv4
===>  ip : 10.192.0.4
===>  bridge :
===>  dns : inherit
===>  flavours : fbsd-update prometheus prometheus+1 prometheus+2 prometheus+3 prometheus+4
===>  Fetching FreeBSD 12.2
===>  Extract the tarball
=====>  Flavour: fbsd-update
=====>  Starting prometheus-amd64-12_2 pot for the initial bootstrap
=====>  mount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
defaultrouter: NO -> 10.192.0.1
===>  Starting the pot prometheus-amd64-12_2
ELF ldconfig path: /lib /usr/lib /usr/lib/compat
32-bit compatibility ldconfig path: /usr/lib32
Starting Network: lo0 epair0b.
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
	inet6 ::1 prefixlen 128
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
	inet 127.0.0.1 netmask 0xff000000
	groups: lo
	nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
epair0b: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 02:55:76:5a:91:0b
	inet 10.192.0.4 netmask 0xffc00000 broadcast 10.255.255.255
	groups: epair
	media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
	status: active
	nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
add host 127.0.0.1: gateway lo0 fib 0: route already in table
add net default: gateway 10.192.0.1
add host ::1: gateway lo0 fib 0: route already in table
add net fe80::: gateway ::1
add net ff02::: gateway ::1
add net ::ffff:0.0.0.0: gateway ::1
add net ::0.0.0.0: gateway ::1
Generating host.conf.
Creating and/or trimming log files.
Starting syslogd.
Clearing /tmp (X related).
Updating motd:.
Updating /var/run/os-release done.
Starting sendmail_submit.
Starting sendmail_msp_queue.
Starting cron.

Tue Nov 30 19:32:32 UTC 2021
/usr/local/etc/pot/flavours/fbsd-update.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp/fbsd-update.sh
=====>  Executing fbsd-update script on prometheus-amd64-12_2
src component not installed, skipped
Looking up update.FreeBSD.org mirrors... 2 mirrors found.
Fetching public key from update2.freebsd.org... done.
Fetching metadata signature for 12.2-RELEASE from update2.freebsd.org... done.
Fetching metadata index... done.
Fetching 2 metadata files... done.
Inspecting system... done.
Preparing to download files... done.
Fetching 209 patches.....10....20....30....40....50....60....70....80....90....100....110....120....130....140....150....160....170....180....190....200.... done.
Applying patches... done.
Fetching 27 files... ....10....20... done.
The following files will be removed as part of updating to
12.2-RELEASE-p11:
/etc/ssl/certs/080911ac.0
/etc/ssl/certs/0b7c536a.0
/etc/ssl/certs/0c4c9b6c.0
/etc/ssl/certs/116bf586.0
/etc/ssl/certs/1320b215.0
/etc/ssl/certs/26312675.0
/etc/ssl/certs/2c543cd1.0
/etc/ssl/certs/2e4eed3c.0
/etc/ssl/certs/349f2832.0
/etc/ssl/certs/442adcac.0
/etc/ssl/certs/480720ec.0
/etc/ssl/certs/5a4d6896.0
/etc/ssl/certs/7d0b38bd.0
/etc/ssl/certs/8867006a.0
/etc/ssl/certs/9c2e7d30.0
/etc/ssl/certs/a8dee976.0
/etc/ssl/certs/ad088e1d.0
/etc/ssl/certs/b1b8a7f3.0
/etc/ssl/certs/b204d74a.0
/etc/ssl/certs/ba89ed3b.0
/etc/ssl/certs/c01cdfa2.0
/etc/ssl/certs/c089bbbd.0
/etc/ssl/certs/c47d9980.0
/etc/ssl/certs/cb59f961.0
/etc/ssl/certs/d853d49e.0
/etc/ssl/certs/dc45b0bd.0
/etc/ssl/certs/e2799e36.0
/etc/ssl/certs/ee1365c0.0
/etc/ssl/certs/f90208f7.0
/usr/share/certs/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
/usr/share/certs/trusted/Camerfirma_Global_Chambersign_Root.pem
/usr/share/certs/trusted/Certum_Root_CA.pem
/usr/share/certs/trusted/Chambers_of_Commerce_Root_-_2008.pem
/usr/share/certs/trusted/D-TRUST_Root_CA_3_2013.pem
/usr/share/certs/trusted/EC-ACC.pem
/usr/share/certs/trusted/GeoTrust_Global_CA.pem
/usr/share/certs/trusted/GeoTrust_Primary_Certification_Authority.pem
/usr/share/certs/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
/usr/share/certs/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/trusted/GeoTrust_Universal_CA.pem
/usr/share/certs/trusted/GeoTrust_Universal_CA_2.pem
/usr/share/certs/trusted/Global_Chambersign_Root_-_2008.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
/usr/share/certs/trusted/QuoVadis_Root_CA.pem
/usr/share/certs/trusted/Sonera_Class_2_Root_CA.pem
/usr/share/certs/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
/usr/share/certs/trusted/SwissSign_Platinum_CA_-_G2.pem
/usr/share/certs/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/trusted/Trustis_FPS_Root_CA.pem
/usr/share/certs/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
/usr/share/certs/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
/usr/share/certs/trusted/VeriSign_Universal_Root_Certification_Authority.pem
/usr/share/certs/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/trusted/thawte_Primary_Root_CA.pem
/usr/share/certs/trusted/thawte_Primary_Root_CA_-_G2.pem
/usr/share/certs/trusted/thawte_Primary_Root_CA_-_G3.pem
The following files will be added as part of updating to
12.2-RELEASE-p11:
/etc/ssl/blacklisted/080911ac.0
/etc/ssl/blacklisted/0b7c536a.0
/etc/ssl/blacklisted/0c4c9b6c.0
/etc/ssl/blacklisted/116bf586.0
/etc/ssl/blacklisted/1320b215.0
/etc/ssl/blacklisted/26312675.0
/etc/ssl/blacklisted/2c543cd1.0
/etc/ssl/blacklisted/2e4eed3c.0
/etc/ssl/blacklisted/349f2832.0
/etc/ssl/blacklisted/442adcac.0
/etc/ssl/blacklisted/480720ec.0
/etc/ssl/blacklisted/5a4d6896.0
/etc/ssl/blacklisted/7d0b38bd.0
/etc/ssl/blacklisted/8867006a.0
/etc/ssl/blacklisted/9c2e7d30.0
/etc/ssl/blacklisted/a8dee976.0
/etc/ssl/blacklisted/ad088e1d.0
/etc/ssl/blacklisted/b1b8a7f3.0
/etc/ssl/blacklisted/b204d74a.0
/etc/ssl/blacklisted/ba89ed3b.0
/etc/ssl/blacklisted/c01cdfa2.0
/etc/ssl/blacklisted/c089bbbd.0
/etc/ssl/blacklisted/c47d9980.0
/etc/ssl/blacklisted/cb59f961.0
/etc/ssl/blacklisted/d853d49e.0
/etc/ssl/blacklisted/dc45b0bd.0
/etc/ssl/blacklisted/e2799e36.0
/etc/ssl/blacklisted/ee1365c0.0
/etc/ssl/blacklisted/f90208f7.0
/etc/ssl/certs/002c0b4f.0
/etc/ssl/certs/3fb36b73.0
/etc/ssl/certs/9482e63a.0
/etc/ssl/certs/b433981b.0
/etc/ssl/certs/b81b93f0.0
/etc/ssl/certs/e35234b1.0
/etc/ssl/certs/fa5da96b.0
/etc/ssl/certs/feffd413.0
/usr/share/certs/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
/usr/share/certs/blacklisted/Camerfirma_Global_Chambersign_Root.pem
/usr/share/certs/blacklisted/Certum_Root_CA.pem
/usr/share/certs/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
/usr/share/certs/blacklisted/D-TRUST_Root_CA_3_2013.pem
/usr/share/certs/blacklisted/EC-ACC.pem
/usr/share/certs/blacklisted/GeoTrust_Global_CA.pem
/usr/share/certs/blacklisted/GeoTrust_Primary_Certification_Authority.pem
/usr/share/certs/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
/usr/share/certs/blacklisted/GeoTrust_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/blacklisted/GeoTrust_Universal_CA.pem
/usr/share/certs/blacklisted/GeoTrust_Universal_CA_2.pem
/usr/share/certs/blacklisted/Global_Chambersign_Root_-_2008.pem
/usr/share/certs/blacklisted/OISTE_WISeKey_Global_Root_GA_CA.pem
/usr/share/certs/blacklisted/QuoVadis_Root_CA.pem
/usr/share/certs/blacklisted/Sonera_Class_2_Root_CA.pem
/usr/share/certs/blacklisted/Staat_der_Nederlanden_Root_CA_-_G3.pem
/usr/share/certs/blacklisted/SwissSign_Platinum_CA_-_G2.pem
/usr/share/certs/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
/usr/share/certs/blacklisted/Trustis_FPS_Root_CA.pem
/usr/share/certs/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
/usr/share/certs/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
/usr/share/certs/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
/usr/share/certs/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
/usr/share/certs/blacklisted/thawte_Primary_Root_CA.pem
/usr/share/certs/blacklisted/thawte_Primary_Root_CA_-_G2.pem
/usr/share/certs/blacklisted/thawte_Primary_Root_CA_-_G3.pem
/usr/share/certs/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
/usr/share/certs/trusted/ANF_Secure_Server_Root_CA.pem
/usr/share/certs/trusted/Certum_EC-384_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Root_CA.pem
/usr/share/certs/trusted/GLOBALTRUST_2020.pem
/usr/share/certs/trusted/GlobalSign_Root_E46.pem
/usr/share/certs/trusted/GlobalSign_Root_R46.pem
/usr/share/certs/trusted/NAVER_Global_Root_Certification_Authority.pem
The following files will be updated as part of updating to
12.2-RELEASE-p11:
/bin/freebsd-version
/lib/libcasper.so.1
/lib/libcrypto.so.111
/lib/libzfs.so.3
/lib/libzfs_core.so.2
/lib/libzpool.so.2
/rescue/[
/rescue/bectl
/rescue/bsdlabel
/rescue/bunzip2
/rescue/bzcat
/rescue/bzip2
/rescue/camcontrol
/rescue/cat
/rescue/ccdconfig
/rescue/chflags
/rescue/chgrp
/rescue/chio
/rescue/chmod
/rescue/chown
/rescue/chroot
/rescue/clri
/rescue/cp
/rescue/csh
/rescue/date
/rescue/dd
/rescue/devfs
/rescue/df
/rescue/dhclient
/rescue/disklabel
/rescue/dmesg
/rescue/dump
/rescue/dumpfs
/rescue/dumpon
/rescue/echo
/rescue/ed
/rescue/ex
/rescue/expr
/rescue/fastboot
/rescue/fasthalt
/rescue/fdisk
/rescue/fsck
/rescue/fsck_4.2bsd
/rescue/fsck_ffs
/rescue/fsck_msdosfs
/rescue/fsck_ufs
/rescue/fsdb
/rescue/fsirand
/rescue/gbde
/rescue/geom
/rescue/getfacl
/rescue/glabel
/rescue/gpart
/rescue/groups
/rescue/gunzip
/rescue/gzcat
/rescue/gzip
/rescue/halt
/rescue/head
/rescue/hostname
/rescue/id
/rescue/ifconfig
/rescue/init
/rescue/ipf
/rescue/iscsictl
/rescue/iscsid
/rescue/kenv
/rescue/kill
/rescue/kldconfig
/rescue/kldload
/rescue/kldstat
/rescue/kldunload
/rescue/ldconfig
/rescue/less
/rescue/link
/rescue/ln
/rescue/ls
/rescue/lzcat
/rescue/lzma
/rescue/md5
/rescue/mdconfig
/rescue/mdmfs
/rescue/mkdir
/rescue/mknod
/rescue/more
/rescue/mount
/rescue/mount_cd9660
/rescue/mount_msdosfs
/rescue/mount_nfs
/rescue/mount_nullfs
/rescue/mount_udf
/rescue/mount_unionfs
/rescue/mt
/rescue/mv
/rescue/nc
/rescue/newfs
/rescue/newfs_msdos
/rescue/nos-tun
/rescue/pgrep
/rescue/ping
/rescue/ping6
/rescue/pkill
/rescue/poweroff
/rescue/ps
/rescue/pwd
/rescue/rcorder
/rescue/rdump
/rescue/realpath
/rescue/reboot
/rescue/red
/rescue/rescue
/rescue/restore
/rescue/rm
/rescue/rmdir
/rescue/route
/rescue/routed
/rescue/rrestore
/rescue/rtquery
/rescue/rtsol
/rescue/savecore
/rescue/sed
/rescue/setfacl
/rescue/sh
/rescue/shutdown
/rescue/sleep
/rescue/spppcontrol
/rescue/stty
/rescue/swapon
/rescue/sync
/rescue/sysctl
/rescue/tail
/rescue/tar
/rescue/tcsh
/rescue/tee
/rescue/test
/rescue/tunefs
/rescue/umount
/rescue/unlink
/rescue/unlzma
/rescue/unxz
/rescue/unzstd
/rescue/vi
/rescue/whoami
/rescue/xz
/rescue/xzcat
/rescue/zcat
/rescue/zdb
/rescue/zfs
/rescue/zpool
/rescue/zstd
/rescue/zstdcat
/rescue/zstdmt
/sbin/ggatec
/sbin/ipfw
/sbin/rtsol
/sbin/zpool
/usr/bin/lldb
/usr/bin/openssl
/usr/bin/zinject
/usr/bin/ztest
/usr/include/net/if_var.h
/usr/include/openssl/asn1err.h
/usr/include/openssl/evperr.h
/usr/include/openssl/opensslv.h
/usr/include/sys/filedesc.h
/usr/include/sys/jail.h
/usr/lib/libcrypto.a
/usr/lib/libcrypto_p.a
/usr/lib/libfetch.a
/usr/lib/libfetch.so.6
/usr/lib/libfetch_p.a
/usr/lib/libpam.a
/usr/lib/libradius.a
/usr/lib/libradius.so.4
/usr/lib/libradius_p.a
/usr/lib/libssl.a
/usr/lib/libssl.so.111
/usr/lib/libssl_p.a
/usr/lib/libzfs.a
/usr/lib/libzfs_core.a
/usr/lib/libzfs_core_p.a
/usr/lib/libzfs_p.a
/usr/lib/libzpool.a
/usr/lib/pam_login_access.so.6
/usr/sbin/bhyve
/usr/sbin/freebsd-update
/usr/sbin/hostapd
/usr/sbin/ntp-keygen
/usr/sbin/rtsold
/usr/sbin/wpa_cli
/usr/sbin/wpa_supplicant
/usr/sbin/zdb
/usr/sbin/zfsd
/usr/sbin/zhack
/usr/share/certs/trusted/ACCVRAIZ1.pem
/usr/share/certs/trusted/AC_RAIZ_FNMT-RCM.pem
/usr/share/certs/trusted/Actalis_Authentication_Root_CA.pem
/usr/share/certs/trusted/AffirmTrust_Commercial.pem
/usr/share/certs/trusted/AffirmTrust_Networking.pem
/usr/share/certs/trusted/AffirmTrust_Premium.pem
/usr/share/certs/trusted/AffirmTrust_Premium_ECC.pem
/usr/share/certs/trusted/Amazon_Root_CA_1.pem
/usr/share/certs/trusted/Amazon_Root_CA_2.pem
/usr/share/certs/trusted/Amazon_Root_CA_3.pem
/usr/share/certs/trusted/Amazon_Root_CA_4.pem
/usr/share/certs/trusted/Atos_TrustedRoot_2011.pem
/usr/share/certs/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
/usr/share/certs/trusted/Baltimore_CyberTrust_Root.pem
/usr/share/certs/trusted/Buypass_Class_2_Root_CA.pem
/usr/share/certs/trusted/Buypass_Class_3_Root_CA.pem
/usr/share/certs/trusted/CA_Disig_Root_R2.pem
/usr/share/certs/trusted/CFCA_EV_ROOT.pem
/usr/share/certs/trusted/COMODO_Certification_Authority.pem
/usr/share/certs/trusted/COMODO_ECC_Certification_Authority.pem
/usr/share/certs/trusted/COMODO_RSA_Certification_Authority.pem
/usr/share/certs/trusted/Certigna.pem
/usr/share/certs/trusted/Certigna_Root_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Network_CA.pem
/usr/share/certs/trusted/Certum_Trusted_Network_CA_2.pem
/usr/share/certs/trusted/Comodo_AAA_Services_root.pem
/usr/share/certs/trusted/Cybertrust_Global_Root.pem
/usr/share/certs/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
/usr/share/certs/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
/usr/share/certs/trusted/DST_Root_CA_X3.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_G2.pem
/usr/share/certs/trusted/DigiCert_Assured_ID_Root_G3.pem
/usr/share/certs/trusted/DigiCert_Global_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Global_Root_G2.pem
/usr/share/certs/trusted/DigiCert_Global_Root_G3.pem
/usr/share/certs/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
/usr/share/certs/trusted/DigiCert_Trusted_Root_G4.pem
/usr/share/certs/trusted/E-Tugra_Certification_Authority.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_G2.pem
/usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_G4.pem
/usr/share/certs/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
/usr/share/certs/trusted/GDCA_TrustAUTH_R5_ROOT.pem
/usr/share/certs/trusted/GTS_Root_R1.pem
/usr/share/certs/trusted/GTS_Root_R2.pem
/usr/share/certs/trusted/GTS_Root_R3.pem
/usr/share/certs/trusted/GTS_Root_R4.pem
/usr/share/certs/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
/usr/share/certs/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
/usr/share/certs/trusted/GlobalSign_Root_CA.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R2.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R3.pem
/usr/share/certs/trusted/GlobalSign_Root_CA_-_R6.pem
/usr/share/certs/trusted/Go_Daddy_Class_2_CA.pem
/usr/share/certs/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
/usr/share/certs/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
/usr/share/certs/trusted/Hongkong_Post_Root_CA_1.pem
/usr/share/certs/trusted/Hongkong_Post_Root_CA_3.pem
/usr/share/certs/trusted/ISRG_Root_X1.pem
/usr/share/certs/trusted/IdenTrust_Commercial_Root_CA_1.pem
/usr/share/certs/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
/usr/share/certs/trusted/Izenpe_com.pem
/usr/share/certs/trusted/Microsec_e-Szigno_Root_CA_2009.pem
/usr/share/certs/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem
/usr/share/certs/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem
/usr/share/certs/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
/usr/share/certs/trusted/Network_Solutions_Certificate_Authority.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
/usr/share/certs/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_1_G3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_2.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_2_G3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_3.pem
/usr/share/certs/trusted/QuoVadis_Root_CA_3_G3.pem
/usr/share/certs/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
/usr/share/certs/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
/usr/share/certs/trusted/SSL_com_Root_Certification_Authority_ECC.pem
/usr/share/certs/trusted/SSL_com_Root_Certification_Authority_RSA.pem
/usr/share/certs/trusted/SZAFIR_ROOT_CA2.pem
/usr/share/certs/trusted/SecureSign_RootCA11.pem
/usr/share/certs/trusted/SecureTrust_CA.pem
/usr/share/certs/trusted/Secure_Global_CA.pem
/usr/share/certs/trusted/Security_Communication_RootCA2.pem
/usr/share/certs/trusted/Security_Communication_Root_CA.pem
/usr/share/certs/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
/usr/share/certs/trusted/Starfield_Class_2_CA.pem
/usr/share/certs/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
/usr/share/certs/trusted/SwissSign_Gold_CA_-_G2.pem
/usr/share/certs/trusted/SwissSign_Silver_CA_-_G2.pem
/usr/share/certs/trusted/T-TeleSec_GlobalRoot_Class_2.pem
/usr/share/certs/trusted/T-TeleSec_GlobalRoot_Class_3.pem
/usr/share/certs/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
/usr/share/certs/trusted/TWCA_Global_Root_CA.pem
/usr/share/certs/trusted/TWCA_Root_Certification_Authority.pem
/usr/share/certs/trusted/TeliaSonera_Root_CA_v1.pem
/usr/share/certs/trusted/TrustCor_ECA-1.pem
/usr/share/certs/trusted/TrustCor_RootCert_CA-1.pem
/usr/share/certs/trusted/TrustCor_RootCert_CA-2.pem
/usr/share/certs/trusted/Trustwave_Global_Certification_Authority.pem
/usr/share/certs/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
/usr/share/certs/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
/usr/share/certs/trusted/UCA_Extended_Validation_Root.pem
/usr/share/certs/trusted/UCA_Global_G2_Root.pem
/usr/share/certs/trusted/USERTrust_ECC_Certification_Authority.pem
/usr/share/certs/trusted/USERTrust_RSA_Certification_Authority.pem
/usr/share/certs/trusted/XRamp_Global_CA_Root.pem
/usr/share/certs/trusted/certSIGN_ROOT_CA.pem
/usr/share/certs/trusted/certSIGN_Root_CA_G2.pem
/usr/share/certs/trusted/e-Szigno_Root_CA_2017.pem
/usr/share/certs/trusted/ePKI_Root_Certification_Authority.pem
/usr/share/certs/trusted/emSign_ECC_Root_CA_-_C3.pem
/usr/share/certs/trusted/emSign_ECC_Root_CA_-_G3.pem
/usr/share/certs/trusted/emSign_Root_CA_-_C1.pem
/usr/share/certs/trusted/emSign_Root_CA_-_G1.pem
/usr/share/man/man2/jail.2.gz
/usr/share/man/man2/jail_attach.2.gz
/usr/share/man/man2/jail_get.2.gz
/usr/share/man/man2/jail_remove.2.gz
/usr/share/man/man2/jail_set.2.gz
/usr/share/zoneinfo/Africa/Accra
/usr/share/zoneinfo/Africa/Addis_Ababa
/usr/share/zoneinfo/Africa/Algiers
/usr/share/zoneinfo/Africa/Asmara
/usr/share/zoneinfo/Africa/Asmera
/usr/share/zoneinfo/Africa/Bangui
/usr/share/zoneinfo/Africa/Brazzaville
/usr/share/zoneinfo/Africa/Casablanca
/usr/share/zoneinfo/Africa/Dar_es_Salaam
/usr/share/zoneinfo/Africa/Djibouti
/usr/share/zoneinfo/Africa/Douala
/usr/share/zoneinfo/Africa/El_Aaiun
/usr/share/zoneinfo/Africa/Juba
/usr/share/zoneinfo/Africa/Kampala
/usr/share/zoneinfo/Africa/Kinshasa
/usr/share/zoneinfo/Africa/Lagos
/usr/share/zoneinfo/Africa/Libreville
/usr/share/zoneinfo/Africa/Luanda
/usr/share/zoneinfo/Africa/Malabo
/usr/share/zoneinfo/Africa/Mogadishu
/usr/share/zoneinfo/Africa/Nairobi
/usr/share/zoneinfo/Africa/Niamey
/usr/share/zoneinfo/Africa/Porto-Novo
/usr/share/zoneinfo/America/Belize
/usr/share/zoneinfo/America/Dawson
/usr/share/zoneinfo/America/Grand_Turk
/usr/share/zoneinfo/America/Nassau
/usr/share/zoneinfo/America/Whitehorse
/usr/share/zoneinfo/Antarctica/Casey
/usr/share/zoneinfo/Antarctica/Macquarie
/usr/share/zoneinfo/Asia/Amman
/usr/share/zoneinfo/Asia/Gaza
/usr/share/zoneinfo/Asia/Hebron
/usr/share/zoneinfo/Asia/Jerusalem
/usr/share/zoneinfo/Asia/Tel_Aviv
/usr/share/zoneinfo/Atlantic/Bermuda
/usr/share/zoneinfo/Australia/ACT
/usr/share/zoneinfo/Australia/Adelaide
/usr/share/zoneinfo/Australia/Brisbane
/usr/share/zoneinfo/Australia/Broken_Hill
/usr/share/zoneinfo/Australia/Canberra
/usr/share/zoneinfo/Australia/Currie
/usr/share/zoneinfo/Australia/Darwin
/usr/share/zoneinfo/Australia/Eucla
/usr/share/zoneinfo/Australia/Hobart
/usr/share/zoneinfo/Australia/Lindeman
/usr/share/zoneinfo/Australia/Melbourne
/usr/share/zoneinfo/Australia/NSW
/usr/share/zoneinfo/Australia/North
/usr/share/zoneinfo/Australia/Perth
/usr/share/zoneinfo/Australia/Queensland
/usr/share/zoneinfo/Australia/South
/usr/share/zoneinfo/Australia/Sydney
/usr/share/zoneinfo/Australia/Tasmania
/usr/share/zoneinfo/Australia/Victoria
/usr/share/zoneinfo/Australia/West
/usr/share/zoneinfo/Australia/Yancowinna
/usr/share/zoneinfo/Canada/Yukon
/usr/share/zoneinfo/Europe/Budapest
/usr/share/zoneinfo/Europe/Monaco
/usr/share/zoneinfo/Europe/Paris
/usr/share/zoneinfo/Europe/Volgograd
/usr/share/zoneinfo/Indian/Antananarivo
/usr/share/zoneinfo/Indian/Comoro
/usr/share/zoneinfo/Indian/Mahe
/usr/share/zoneinfo/Indian/Mayotte
/usr/share/zoneinfo/Israel
/usr/share/zoneinfo/Pacific/Apia
/usr/share/zoneinfo/Pacific/Efate
/usr/share/zoneinfo/Pacific/Fiji
/usr/share/zoneinfo/zone.tab
/usr/share/zoneinfo/zone1970.tab

WARNING: FreeBSD 12.2-RELEASE is approaching its End-of-Life date.
It is strongly recommended that you upgrade to a newer
release within the next 1 month.
Installing updates...Scanning //usr/share/certs/blacklisted for certificates...
Scanning //usr/share/certs/trusted for certificates...
 done.
=====>  Stop the pot prometheus-amd64-12_2
=====>  Remove epair0[a|b] network interfaces
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-12_2/m/dev
=====>  Flavour: prometheus
=====>  Executing prometheus pot commands on prometheus-amd64-12_2
=====>  mount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
/usr/local/etc/pot/flavours/prometheus.d/local -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local
/usr/local/etc/pot/flavours/prometheus.d/local/bin -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/bin
/usr/local/etc/pot/flavours/prometheus.d/local/bin/cook -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/bin/cook
/usr/local/etc/pot/flavours/prometheus.d/local/share -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consulca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-template-metrics.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consul-template-metrics.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-template.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consul-template.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/client.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/client.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/alertmanager.yml.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/alertmanager.yml.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consul-agent.hcl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consul-agent.hcl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/syslog-ng.conf.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/syslog-ng.conf.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metricsca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/metricsca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulagent.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consulagent.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/metrics.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics-ca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/metrics-ca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/prometheus.yml.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/prometheus.yml.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/client.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/client.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/consulagent.key.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/consulagent.key.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/ca.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/ca.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/templates/metrics.crt.tpl.in -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/templates/metrics.crt.tpl.in
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-metrics-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/unwrap-metrics-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-node-exporter.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-node-exporter.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-metrics.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/reload-metrics.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-syslog-ng.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-syslog-ng.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-consul.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/reload-consul.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/setup-local-unbound-provision.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/setup-local-unbound-provision.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-consul.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-consul.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-metrics.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-metrics.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-cluster-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/unwrap-cluster-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/unwrap-consul-credentials.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/unwrap-consul-credentials.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/setup-local-unbound.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/setup-local-unbound.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-prometheus.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-prometheus.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/reload-consul-template.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/reload-consul-template.sh
/usr/local/etc/pot/flavours/prometheus.d/local/share/cook/bin/configure-consul-template.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/root/.pot_local/share/cook/bin/configure-consul-template.sh
=====>  Source /usr/local/etc/pot/flavours/prometheus.d/local copied in the pot prometheus-amd64-12_2
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
=====>  /mnt/data/pot/jails/prometheus-amd64-12_2/m/dev is already unmounted
=====>  Starting prometheus-amd64-12_2 pot for the initial bootstrap
=====>  mount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
defaultrouter: 10.192.0.1 -> 10.192.0.1
===>  Starting the pot prometheus-amd64-12_2
ELF ldconfig path: /lib /usr/lib /usr/lib/compat
32-bit compatibility ldconfig path: /usr/lib32
Starting Network: lo0 epair0b.
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
	inet6 ::1 prefixlen 128
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
	inet 127.0.0.1 netmask 0xff000000
	groups: lo
	nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
epair0b: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 02:fd:c9:87:28:0b
	inet 10.192.0.4 netmask 0xffc00000 broadcast 10.255.255.255
	groups: epair
	media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
	status: active
	nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
add host 127.0.0.1: gateway lo0 fib 0: route already in table
add net default: gateway 10.192.0.1
add host ::1: gateway lo0 fib 0: route already in table
add net fe80::: gateway ::1
add net ff02::: gateway ::1
add net ::ffff:0.0.0.0: gateway ::1
add net ::0.0.0.0: gateway ::1
Creating and/or trimming log files.
Starting syslogd.
Clearing /tmp (X related).
Updating motd:.
Updating /var/run/os-release done.
Starting sendmail_submit.
Starting sendmail_msp_queue.
Starting cron.

Tue Nov 30 19:34:07 UTC 2021
/usr/local/etc/pot/flavours/prometheus.sh -> /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp/prometheus.sh
=====>  Executing prometheus script on prometheus-amd64-12_2
Creating /var/log/cook.log
Step 1: Bootstrap package repo
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] Installing pkg-1.17.5...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] Extracting pkg-1.17.5: .......... done
Bootstrapping pkg from pkg+http://pkg.FreeBSD.org/FreeBSD:12:amd64/quarterly, please wait...
Step 2: Touch /etc/rc.conf
Step 3: Remove ifconfig_epair0b from config
Step 4: Disable sendmail
sendmail disabled in /etc/rc.conf
sendmail_submit disabled in /etc/rc.conf
sendmail_msp_queue disabled in /etc/rc.conf
Step 5: Disable sshd
sshd disabled in /etc/rc.conf
Step 6: Create /usr/local/etc/rc.d
Step 7: Update package repository
Updating FreeBSD repository catalogue...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] Fetching meta.conf: . done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] Fetching packagesite.pkg: .......... done
Processing entries: .......... done
FreeBSD repository update completed. 31244 packages processed.
All repositories are up to date.
Step 8: Install package consul
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
Updating database digests format: . done
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	consul: 1.9.9

Number of packages to be installed: 1

The process will require 78 MiB more space.
26 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching consul-1.9.9.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing consul-1.9.9...
===> Creating groups.
Creating group 'consul' with gid '469'.
===> Creating users
Creating user 'consul' with uid '469'.
===> Creating homedir(s)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting consul-1.9.9: ..... done
Step 9: Install package consul-template
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	consul-template: 0.27.0

Number of packages to be installed: 1

The process will require 10 MiB more space.
3 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching consul-template-0.27.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing consul-template-0.27.0...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting consul-template-0.27.0: ..... done
Step 10: Patching consul-template rc scripts
Step 11: Install package prometheus
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	prometheus: 2.30.0

Number of packages to be installed: 1

The process will require 143 MiB more space.
27 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching prometheus-2.30.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing prometheus-2.30.0...
===> Creating groups.
Creating group 'prometheus' with gid '478'.
===> Creating users
Creating user 'prometheus' with uid '478'.
===> Creating homedir(s)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting prometheus-2.30.0: .......... done
Step 12: Install package alertmanager
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	alertmanager: 0.23.0

Number of packages to be installed: 1

The process will require 40 MiB more space.
10 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching alertmanager-0.23.0.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing alertmanager-0.23.0...
===> Creating groups.
Creating group 'alertmanager' with gid '479'.
===> Creating users
Creating user 'alertmanager' with uid '479'.
===> Creating homedir(s)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting alertmanager-0.23.0: ....... done
Step 13: Install package node_exporter
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	node_exporter: 1.2.2

Number of packages to be installed: 1

The process will require 11 MiB more space.
3 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching node_exporter-1.2.2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing node_exporter-1.2.2...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting node_exporter-1.2.2: .......... done
=====
Message from node_exporter-1.2.2:

--
If upgrading from a version of node_exporter <0.15.0 you'll need to update any
custom command line flags that you may have set as it now requires a
double-dash (--flag) instead of a single dash (-flag).
The collector flags in 0.15.0 have now been replaced with individual boolean
flags and the -collector.procfs` and -collector.sysfs` flags have been renamed
to --path.procfs and --path.sysfs respectively.
Step 14: Install package syslog-ng
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 17 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	ca_root_nss: 3.69_1
	curl: 7.79.1
	e2fsprogs-libuuid: 1.46.4
	gettext-runtime: 0.21
	glib: 2.70.1,2
	indexinfo: 0.3.1
	json-c: 0.15_1
	libffi: 3.3_1
	libiconv: 1.16
	libnghttp2: 1.44.0
	libssh2: 1.9.0_3,3
	libxml2: 2.9.12
	mpdecimal: 2.5.1
	pcre: 8.45
	python38: 3.8.12
	readline: 8.1.1
	syslog-ng: 3.34.1

Number of packages to be installed: 17

The process will require 167 MiB more space.
27 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/17] Fetching syslog-ng-3.34.1.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/17] Fetching e2fsprogs-libuuid-1.46.4.pkg: ..... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [3/17] Fetching curl-7.79.1.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [4/17] Fetching libnghttp2-1.44.0.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [5/17] Fetching libssh2-1.9.0_3,3.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [6/17] Fetching ca_root_nss-3.69_1.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [7/17] Fetching pcre-8.45.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [8/17] Fetching json-c-0.15_1.pkg: ........ done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [9/17] Fetching glib-2.70.1,2.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [10/17] Fetching libxml2-2.9.12.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [11/17] Fetching python38-3.8.12.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [12/17] Fetching mpdecimal-2.5.1.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [13/17] Fetching readline-8.1.1.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [14/17] Fetching indexinfo-0.3.1.pkg: . done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [15/17] Fetching libffi-3.3_1.pkg: ..... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [16/17] Fetching gettext-runtime-0.21.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [17/17] Fetching libiconv-1.16.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/17] Installing indexinfo-0.3.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/17] Extracting indexinfo-0.3.1: .... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/17] Installing mpdecimal-2.5.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/17] Extracting mpdecimal-2.5.1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [3/17] Installing readline-8.1.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [3/17] Extracting readline-8.1.1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [4/17] Installing libffi-3.3_1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [4/17] Extracting libffi-3.3_1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [5/17] Installing gettext-runtime-0.21...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [5/17] Extracting gettext-runtime-0.21: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [6/17] Installing libnghttp2-1.44.0...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [6/17] Extracting libnghttp2-1.44.0: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [7/17] Installing libssh2-1.9.0_3,3...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [7/17] Extracting libssh2-1.9.0_3,3: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [8/17] Installing ca_root_nss-3.69_1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [8/17] Extracting ca_root_nss-3.69_1: ........ done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [9/17] Installing pcre-8.45...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [9/17] Extracting pcre-8.45: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [10/17] Installing libxml2-2.9.12...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [10/17] Extracting libxml2-2.9.12: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [11/17] Installing python38-3.8.12...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [11/17] Extracting python38-3.8.12: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [12/17] Installing libiconv-1.16...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [12/17] Extracting libiconv-1.16: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [13/17] Installing e2fsprogs-libuuid-1.46.4...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [13/17] Extracting e2fsprogs-libuuid-1.46.4: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [14/17] Installing curl-7.79.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [14/17] Extracting curl-7.79.1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [15/17] Installing json-c-0.15_1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [15/17] Extracting json-c-0.15_1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [16/17] Installing glib-2.70.1,2...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [16/17] Extracting glib-2.70.1,2: .......... done
No schema files found: doing nothing.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [17/17] Installing syslog-ng-3.34.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [17/17] Extracting syslog-ng-3.34.1: .......... done
=====
Message from ca_root_nss-3.69_1:

--
FreeBSD does not, and can not warrant that the certification authorities
whose certificates are included in this package have in any way been
audited for trustworthiness or RFC 3647 compliance.

Assessment and verification of trust is the complete responsibility of the
system administrator.


This package installs symlinks to support root certificates discovery by
default for software that uses OpenSSL.

This enables SSL Certificate Verification by client software without manual
intervention.

If you prefer to do this manually, replace the following symlinks with
either an empty file or your site-local certificate bundle.

  * /etc/ssl/cert.pem
  * /usr/local/etc/ssl/cert.pem
  * /usr/local/openssl/cert.pem
=====
Message from python38-3.8.12:

--
Note that some standard Python modules are provided as separate ports
as they require additional dependencies. They are available as:

py38-gdbm       databases/py-gdbm@py38
py38-sqlite3    databases/py-sqlite3@py38
py38-tkinter    x11-toolkits/py-tkinter@py38
=====
Message from syslog-ng-3.34.1:

--
syslog-ng is now installed!  To replace FreeBSD's standard syslogd
(/usr/sbin/syslogd), complete these steps:

1. Create a configuration file named /usr/local/etc/syslog-ng.conf
   (a sample named syslog-ng.conf.sample has been included in
   /usr/local/etc). Note that this is a change in 2.0.2
   version, previous ones put the config file in
   /usr/local/etc/syslog-ng/syslog-ng.conf, so if this is an update
   move that file in the right place

2. Configure syslog-ng to start automatically by adding the following
   to /etc/rc.conf:

        syslog_ng_enable="YES"

3. Prevent the standard FreeBSD syslogd from starting automatically by
   adding a line to the end of your /etc/rc.conf file that reads:

        syslogd_enable="NO"

4. Shut down the standard FreeBSD syslogd:

     kill `cat /var/run/syslog.pid`

5. Start syslog-ng:

     /usr/local/etc/rc.d/syslog-ng start
Step 15: Install package openssl
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	openssl: 1.1.1l,1

Number of packages to be installed: 1

The process will require 14 MiB more space.
4 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching openssl-1.1.1l,1.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing openssl-1.1.1l,1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting openssl-1.1.1l,1: .......... done
Step 16: Install package sudo
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	sudo: 1.9.8p2

Number of packages to be installed: 1

The process will require 7 MiB more space.
1 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching sudo-1.9.8p2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing sudo-1.9.8p2...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting sudo-1.9.8p2: .......... done
Step 17: Install package curl
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
Checking integrity... done (0 conflicting)
The most recent versions of packages are already installed
Step 18: Install package jq
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 2 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	jq: 1.6
	oniguruma: 6.9.7.1

Number of packages to be installed: 2

The process will require 2 MiB more space.
497 KiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/2] Fetching jq-1.6.pkg: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/2] Fetching oniguruma-6.9.7.1.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/2] Installing oniguruma-6.9.7.1...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/2] Extracting oniguruma-6.9.7.1: .......... done
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/2] Installing jq-1.6...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [2/2] Extracting jq-1.6: .......... done
Step 19: Install package jo
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	jo: 1.4

Number of packages to be installed: 1

19 KiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching jo-1.4.pkg: ... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing jo-1.4...
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting jo-1.4: ...... done
Step 20: Install package vault
Updating FreeBSD repository catalogue...
FreeBSD repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	vault: 1.8.2

Number of packages to be installed: 1

The process will require 156 MiB more space.
49 MiB to be downloaded.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Fetching vault-1.8.2.pkg: .......... done
Checking integrity... done (0 conflicting)
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Installing vault-1.8.2...
===> Creating groups.
Creating group 'vault' with gid '471'.
===> Creating users
Creating user 'vault' with uid '471'.
[prometheus-amd64-12_2.vsf00001.cpt.za.honeyguide.net] [1/1] Extracting vault-1.8.2: ..... done
=====
Message from vault-1.8.2:

--
The vault user created by the vault package is now a member of the daemon
class, which will allow it to use mlock() when started by the rc script. This
will not be reflected in systems where the user already exists. Please add the
vault user to the daemon class manually by running:

pw usermod -L daemon -n vault

or delete the user and reinstall the package.

You may also need to increase memorylocked for the daemon class in
/etc/rc.conf to more than 1024M (the default) or more:

vault_limits_mlock="2048M"

Or to disable mlock, add:

disable_mlock = 1

to /usr/local/etc/vault.hcl
Step 21: Clean package installation
Nothing to do.
Step 22: Clean cook artifacts
Step 23: Install pot local
Step 24: Set file ownership on cook scripts
Step 25: Make cook script executable
setting executable bit on /usr/local/bin/cook
Step 26: Create rc.d script to start cook
creating rc.d script to start cook
Step 27: Make rc.d script to start cook executable
Setting executable bit on cook rc file
Step 28: Enable cook service
enabling cook
cook enabled in /etc/rc.conf
=====>  Stop the pot prometheus-amd64-12_2
=====>  Remove epair0[a|b] network interfaces
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-12_2/m/tmp
=====>  unmount /mnt/data/pot/jails/prometheus-amd64-12_2/m/dev
=====>  Flavour: prometheus+1
=====>  Executing prometheus+1 pot commands on prometheus-amd64-12_2
=====>  No shell script available for the flavour prometheus+1
=====>  Flavour: prometheus+2
=====>  Executing prometheus+2 pot commands on prometheus-amd64-12_2
=====>  No shell script available for the flavour prometheus+2
=====>  Flavour: prometheus+3
=====>  Executing prometheus+3 pot commands on prometheus-amd64-12_2
=====>  No shell script available for the flavour prometheus+3
=====>  Flavour: prometheus+4
=====>  Executing prometheus+4 pot commands on prometheus-amd64-12_2
=====>  No shell script available for the flavour prometheus+4

This site © Honeyguide Group (Pty) Ltd, all the hosted software their respective license owners 2020 - 2021 - Disclaimer