1
0
Fork 0
mirror of https://github.com/ansible-collections/community.general.git synced 2024-09-14 20:13:21 +02:00

Removes the f5-sdk from bigip_routedomain (#48543)

This commit is contained in:
Tim Rupp 2018-11-11 11:29:21 -08:00 committed by GitHub
parent 708c2b4b71
commit 62332155b5
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 193 additions and 91 deletions

View file

@ -1,7 +1,7 @@
#!/usr/bin/python #!/usr/bin/python
# -*- coding: utf-8 -*- # -*- coding: utf-8 -*-
# #
# Copyright (c) 2016 F5 Networks Inc. # Copyright: (c) 2016, F5 Networks Inc.
# GNU General Public License v3.0 (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) # GNU General Public License v3.0 (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
from __future__ import absolute_import, division, print_function from __future__ import absolute_import, division, print_function
@ -87,9 +87,14 @@ options:
vlans: vlans:
description: description:
- VLANs for the system to use in the route domain. - VLANs for the system to use in the route domain.
fw_enforced_policy:
description:
- Specifies AFM policy to be attached to route domain.
version_added: 2.8
extends_documentation_fragment: f5 extends_documentation_fragment: f5
author: author:
- Tim Rupp (@caphrim007) - Tim Rupp (@caphrim007)
- Wojciech Wypior (@wojtek0806)
''' '''
EXAMPLES = r''' EXAMPLES = r'''
@ -167,35 +172,38 @@ service_policy:
returned: changed returned: changed
type: string type: string
sample: /Common-my-service-policy sample: /Common-my-service-policy
fw_enforced_policy:
description: Specfies AFM policy to be attached to route domain.
returned: changed
type: string
sample: /Common/afm-blocking-policy
''' '''
from ansible.module_utils.basic import AnsibleModule from ansible.module_utils.basic import AnsibleModule
from ansible.module_utils.basic import env_fallback from ansible.module_utils.basic import env_fallback
try: try:
from library.module_utils.network.f5.bigip import HAS_F5SDK from library.module_utils.network.f5.bigip import F5RestClient
from library.module_utils.network.f5.bigip import F5Client
from library.module_utils.network.f5.common import F5ModuleError from library.module_utils.network.f5.common import F5ModuleError
from library.module_utils.network.f5.common import AnsibleF5Parameters from library.module_utils.network.f5.common import AnsibleF5Parameters
from library.module_utils.network.f5.common import cleanup_tokens from library.module_utils.network.f5.common import cleanup_tokens
from library.module_utils.network.f5.common import fq_name from library.module_utils.network.f5.common import fq_name
from library.module_utils.network.f5.common import transform_name
from library.module_utils.network.f5.common import f5_argument_spec from library.module_utils.network.f5.common import f5_argument_spec
try: from library.module_utils.network.f5.common import exit_json
from library.module_utils.network.f5.common import iControlUnexpectedHTTPError from library.module_utils.network.f5.common import fail_json
except ImportError: from library.module_utils.network.f5.compare import cmp_simple_list
HAS_F5SDK = False
except ImportError: except ImportError:
from ansible.module_utils.network.f5.bigip import HAS_F5SDK from ansible.module_utils.network.f5.bigip import F5RestClient
from ansible.module_utils.network.f5.bigip import F5Client
from ansible.module_utils.network.f5.common import F5ModuleError from ansible.module_utils.network.f5.common import F5ModuleError
from ansible.module_utils.network.f5.common import AnsibleF5Parameters from ansible.module_utils.network.f5.common import AnsibleF5Parameters
from ansible.module_utils.network.f5.common import cleanup_tokens from ansible.module_utils.network.f5.common import cleanup_tokens
from ansible.module_utils.network.f5.common import fq_name from ansible.module_utils.network.f5.common import fq_name
from ansible.module_utils.network.f5.common import transform_name
from ansible.module_utils.network.f5.common import f5_argument_spec from ansible.module_utils.network.f5.common import f5_argument_spec
try: from ansible.module_utils.network.f5.common import exit_json
from ansible.module_utils.network.f5.common import iControlUnexpectedHTTPError from ansible.module_utils.network.f5.common import fail_json
except ImportError: from ansible.module_utils.network.f5.compare import cmp_simple_list
HAS_F5SDK = False
class Parameters(AnsibleF5Parameters): class Parameters(AnsibleF5Parameters):
@ -204,7 +212,9 @@ class Parameters(AnsibleF5Parameters):
'servicePolicy': 'service_policy', 'servicePolicy': 'service_policy',
'bwcPolicy': 'bwc_policy', 'bwcPolicy': 'bwc_policy',
'flowEvictionPolicy': 'flow_eviction_policy', 'flowEvictionPolicy': 'flow_eviction_policy',
'routingProtocol': 'routing_protocol' 'routingProtocol': 'routing_protocol',
'fwEnforcedPolicy': 'fw_enforced_policy',
'fwEnforcedPolicyReference': 'fw_policy_link',
} }
api_attributes = [ api_attributes = [
@ -217,7 +227,9 @@ class Parameters(AnsibleF5Parameters):
'flowEvictionPolicy', 'flowEvictionPolicy',
'routingProtocol', 'routingProtocol',
'vlans', 'vlans',
'id' 'id',
'fwEnforcedPolicy',
'fwEnforcedPolicyReference',
] ]
returnables = [ returnables = [
@ -230,7 +242,7 @@ class Parameters(AnsibleF5Parameters):
'routing_protocol', 'routing_protocol',
'vlans', 'vlans',
'connection_limit', 'connection_limit',
'id' 'id',
] ]
updatables = [ updatables = [
@ -243,7 +255,9 @@ class Parameters(AnsibleF5Parameters):
'routing_protocol', 'routing_protocol',
'vlans', 'vlans',
'connection_limit', 'connection_limit',
'id' 'id',
'fw_enforced_policy',
'fw_policy_link',
] ]
@property @property
@ -271,12 +285,26 @@ class ApiParameters(Parameters):
@property @property
def domains(self): def domains(self):
domains = self.read_domains_from_device() domains = self.read_domains_from_device()
result = [x.fullPath for x in domains] result = [x['fullPath'] for x in domains['items']]
return result return result
def read_domains_from_device(self): def read_domains_from_device(self):
collection = self.client.api.tm.net.route_domains.get_collection() uri = "https://{0}:{1}/mgmt/tm/net/route-domain/".format(
return collection self.client.provider['server'],
self.client.provider['server_port'],
)
resp = self.client.api.get(uri)
try:
response = resp.json()
except ValueError as ex:
raise F5ModuleError(str(ex))
if 'code' in response and response['code'] == 400:
if 'message' in response:
raise F5ModuleError(response['message'])
else:
raise F5ModuleError(resp.content)
return response
class ModuleParameters(Parameters): class ModuleParameters(Parameters):
@ -327,6 +355,24 @@ class ModuleParameters(Parameters):
return '' return ''
return self._values['routing_protocol'] return self._values['routing_protocol']
@property
def fw_enforced_policy(self):
if self._values['fw_enforced_policy'] is None:
return None
if self._values['fw_enforced_policy'] in ['none', '']:
return None
name = self._values['fw_enforced_policy']
return fq_name(self.partition, name)
@property
def fw_policy_link(self):
policy = self.fw_enforced_policy
if policy is None:
return None
tmp = policy.split('/')
link = dict(link='https://localhost/mgmt/tm/security/firewall/policy/~{0}~{1}'.format(tmp[1], tmp[2]))
return link
class Changes(Parameters): class Changes(Parameters):
def to_return(self): def to_return(self):
@ -383,33 +429,20 @@ class Difference(object):
@property @property
def routing_protocol(self): def routing_protocol(self):
if self.want.routing_protocol is None: return cmp_simple_list(self.want.routing_protocol, self.have.routing_protocol)
return None
if self.want.routing_protocol == '' and self.have.routing_protocol is None:
return None
if self.want.routing_protocol == '' and len(self.have.routing_protocol) > 0:
return []
if self.have.routing_protocol is None:
return self.want.routing_protocol
want = set(self.want.routing_protocol)
have = set(self.have.routing_protocol)
if want != have:
return list(want)
@property @property
def vlans(self): def vlans(self):
if self.want.vlans is None: return cmp_simple_list(self.want.vlans, self.have.vlans)
@property
def fw_policy_link(self):
if self.want.fw_enforced_policy is None:
return None return None
if self.want.vlans == '' and self.have.vlans is None: if self.want.fw_enforced_policy == self.have.fw_enforced_policy:
return None return None
if self.want.vlans == '' and len(self.have.vlans) > 0: if self.want.fw_policy_link != self.have.fw_policy_link:
return [] return self.want.fw_policy_link
if self.have.vlans is None:
return self.want.vlans
want = set(self.want.vlans)
have = set(self.have.vlans)
if want != have:
return list(want)
class ModuleManager(object): class ModuleManager(object):
@ -457,13 +490,10 @@ class ModuleManager(object):
result = dict() result = dict()
state = self.want.state state = self.want.state
try: if state == "present":
if state == "present": changed = self.present()
changed = self.present() elif state == "absent":
elif state == "absent": changed = self.absent()
changed = self.absent()
except iControlUnexpectedHTTPError as e:
raise F5ModuleError(str(e))
reportable = ReportableChanges(params=self.changes.to_return()) reportable = ReportableChanges(params=self.changes.to_return())
changes = reportable.to_return() changes = reportable.to_return()
@ -486,12 +516,10 @@ class ModuleManager(object):
else: else:
return self.create() return self.create()
def exists(self): def absent(self):
result = self.client.api.tm.net.route_domains.route_domain.exists( if self.exists():
name=self.want.name, return self.remove()
partition=self.want.partition return False
)
return result
def update(self): def update(self):
self.have = self.read_current_from_device() self.have = self.read_current_from_device()
@ -529,42 +557,112 @@ class ModuleManager(object):
self.create_on_device() self.create_on_device()
return True return True
def exists(self):
uri = "https://{0}:{1}/mgmt/tm/net/route-domain/{2}".format(
self.client.provider['server'],
self.client.provider['server_port'],
transform_name(self.want.partition, self.want.name),
)
resp = self.client.api.get(uri)
try:
response = resp.json()
except ValueError:
return False
if resp.status == 404 or 'code' in response and response['code'] == 404:
return False
return True
def create_on_device(self): def create_on_device(self):
params = self.changes.api_params() params = self.changes.api_params()
self.client.api.tm.net.route_domains.route_domain.create( params['name'] = self.want.name
name=self.want.name, params['partition'] = self.want.partition
partition=self.want.partition, uri = "https://{0}:{1}/mgmt/tm/net/route-domain/".format(
**params self.client.provider['server'],
self.client.provider['server_port'],
) )
resp = self.client.api.post(uri, json=params)
try:
response = resp.json()
except ValueError as ex:
raise F5ModuleError(str(ex))
if 'code' in response and response['code'] in [400, 403]:
if 'message' in response:
raise F5ModuleError(response['message'])
else:
raise F5ModuleError(resp.content)
if self.want.fw_enforced_policy:
payload = dict(
fwEnforcedPolicy=self.want.fw_enforced_policy,
fwEnforcedPolicyReference=self.want.fw_policy_link
)
uri = "https://{0}:{1}/mgmt/tm/net/route-domain/{2}".format(
self.client.provider['server'],
self.client.provider['server_port'],
transform_name(self.want.partition, self.want.name),
)
resp = self.client.api.patch(uri, json=payload)
try:
response = resp.json()
except ValueError as ex:
raise F5ModuleError(str(ex))
if 'code' in response and response['code'] in [400, 403]:
if 'message' in response:
raise F5ModuleError(response['message'])
else:
raise F5ModuleError(resp.content)
return True
def update_on_device(self): def update_on_device(self):
params = self.changes.api_params() params = self.changes.api_params()
resource = self.client.api.tm.net.route_domains.route_domain.load( uri = "https://{0}:{1}/mgmt/tm/net/route-domain/{2}".format(
name=self.want.name, self.client.provider['server'],
partition=self.want.partition self.client.provider['server_port'],
transform_name(self.want.partition, self.want.name),
) )
resource.modify(**params) resp = self.client.api.patch(uri, json=params)
try:
response = resp.json()
except ValueError as ex:
raise F5ModuleError(str(ex))
def absent(self): if 'code' in response and response['code'] == 400:
if self.exists(): if 'message' in response:
return self.remove() raise F5ModuleError(response['message'])
return False else:
raise F5ModuleError(resp.content)
def remove_from_device(self): def remove_from_device(self):
resource = self.client.api.tm.net.route_domains.route_domain.load( uri = "https://{0}:{1}/mgmt/tm/net/route-domain/{2}".format(
name=self.want.name, self.client.provider['server'],
partition=self.want.partition self.client.provider['server_port'],
transform_name(self.want.partition, self.want.name),
) )
if resource: response = self.client.api.delete(uri)
resource.delete() if response.status == 200:
return True
raise F5ModuleError(response.content)
def read_current_from_device(self): def read_current_from_device(self):
resource = self.client.api.tm.net.route_domains.route_domain.load( uri = "https://{0}:{1}/mgmt/tm/net/route-domain/{2}".format(
name=self.want.name, self.client.provider['server'],
partition=self.want.partition self.client.provider['server_port'],
transform_name(self.want.partition, self.want.name),
) )
result = resource.attrs resp = self.client.api.get(uri)
return ApiParameters(params=result, client=self.client) try:
response = resp.json()
except ValueError as ex:
raise F5ModuleError(str(ex))
if 'code' in response and response['code'] == 400:
if 'message' in response:
raise F5ModuleError(response['message'])
else:
raise F5ModuleError(resp.content)
return ApiParameters(params=response, client=self.client)
class ArgumentSpec(object): class ArgumentSpec(object):
@ -585,6 +683,7 @@ class ArgumentSpec(object):
connection_limit=dict(type='int'), connection_limit=dict(type='int'),
flow_eviction_policy=dict(), flow_eviction_policy=dict(),
service_policy=dict(), service_policy=dict(),
fw_enforced_policy=dict(),
partition=dict( partition=dict(
default='Common', default='Common',
fallback=(env_fallback, ['F5_PARTITION']) fallback=(env_fallback, ['F5_PARTITION'])
@ -609,18 +708,17 @@ def main():
argument_spec=spec.argument_spec, argument_spec=spec.argument_spec,
supports_check_mode=spec.supports_check_mode supports_check_mode=spec.supports_check_mode
) )
if not HAS_F5SDK:
module.fail_json(msg="The python f5-sdk module is required") client = F5RestClient(**module.params)
try: try:
client = F5Client(**module.params)
mm = ModuleManager(module=module, client=client) mm = ModuleManager(module=module, client=client)
results = mm.exec_module() results = mm.exec_module()
cleanup_tokens(client) cleanup_tokens(client)
module.exit_json(**results) exit_json(module, results, client)
except F5ModuleError as ex: except F5ModuleError as ex:
cleanup_tokens(client) cleanup_tokens(client)
module.fail_json(msg=str(ex)) fail_json(module, ex, client)
if __name__ == '__main__': if __name__ == '__main__':

View file

@ -8,16 +8,12 @@ __metaclass__ = type
import os import os
import json import json
import pytest
import sys import sys
from nose.plugins.skip import SkipTest from nose.plugins.skip import SkipTest
if sys.version_info < (2, 7): if sys.version_info < (2, 7):
raise SkipTest("F5 Ansible modules require Python >= 2.7") raise SkipTest("F5 Ansible modules require Python >= 2.7")
from units.compat import unittest
from units.compat.mock import Mock
from units.compat.mock import patch
from ansible.module_utils.basic import AnsibleModule from ansible.module_utils.basic import AnsibleModule
try: try:
@ -25,17 +21,25 @@ try:
from library.modules.bigip_routedomain import ModuleParameters from library.modules.bigip_routedomain import ModuleParameters
from library.modules.bigip_routedomain import ModuleManager from library.modules.bigip_routedomain import ModuleManager
from library.modules.bigip_routedomain import ArgumentSpec from library.modules.bigip_routedomain import ArgumentSpec
from library.module_utils.network.f5.common import F5ModuleError
from library.module_utils.network.f5.common import iControlUnexpectedHTTPError # In Ansible 2.8, Ansible changed import paths.
from test.unit.modules.utils import set_module_args from test.units.compat import unittest
from test.units.compat.mock import Mock
from test.units.compat.mock import patch
from test.units.modules.utils import set_module_args
except ImportError: except ImportError:
try: try:
from ansible.modules.network.f5.bigip_routedomain import ApiParameters from ansible.modules.network.f5.bigip_routedomain import ApiParameters
from ansible.modules.network.f5.bigip_routedomain import ModuleParameters from ansible.modules.network.f5.bigip_routedomain import ModuleParameters
from ansible.modules.network.f5.bigip_routedomain import ModuleManager from ansible.modules.network.f5.bigip_routedomain import ModuleManager
from ansible.modules.network.f5.bigip_routedomain import ArgumentSpec from ansible.modules.network.f5.bigip_routedomain import ArgumentSpec
from ansible.module_utils.network.f5.common import F5ModuleError
from ansible.module_utils.network.f5.common import iControlUnexpectedHTTPError # Ansible 2.8 imports
from units.compat import unittest
from units.compat.mock import Mock
from units.compat.mock import patch
from units.modules.utils import set_module_args from units.modules.utils import set_module_args
except ImportError: except ImportError:
raise SkipTest("F5 Ansible modules require the f5-sdk Python library") raise SkipTest("F5 Ansible modules require the f5-sdk Python library")