diff --git a/changelogs/fragments/t6837-vyos_config-replace.yml b/changelogs/fragments/t6837-vyos_config-replace.yml
new file mode 100644
index 00000000..9a0ff2b8
--- /dev/null
+++ b/changelogs/fragments/t6837-vyos_config-replace.yml
@@ -0,0 +1,19 @@
+---
+minor_changes:
+ - vyos_config - added a new ``replace`` option value, ``config`` (in addition
+ to the existing default, ``line``). When set to ``replace=config``, the
+ module uploads the complete candidate configuration supplied via ``src``
+ to the device and issues VyOS's native ``load`` command in configuration
+ mode, letting VyOS's own configuration engine perform the replacement,
+ rather than the module computing a set/delete command diff. This mirrors
+ the mechanism offered by ``cisco.iosxr.iosxr_config``'s ``replace=config``
+ (https://vyos.dev/T6837).
+bugfixes:
+ - vyos_config - the ``allow_password_change`` filter used a regular
+ expression that only matched ``set`` lines
+ (``set system login user ... authentication (encrypted|plaintext)-password``),
+ so a ``delete`` line for the same path was never filtered regardless of
+ the ``allow_password_change`` value. This meant an account omitted from a
+ full-config candidate could have its password deleted without the
+ existing safety filter ever inspecting the line. The regular expression
+ now matches both ``set`` and ``delete`` lines.
diff --git a/docs/vyos.vyos.vyos_config_module.rst b/docs/vyos.vyos.vyos_config_module.rst
index 2f6f8b7e..701fc647 100644
--- a/docs/vyos.vyos.vyos_config_module.rst
+++ b/docs/vyos.vyos.vyos_config_module.rst
@@ -1,461 +1,485 @@
.. _vyos.vyos.vyos_config_module:
*********************
vyos.vyos.vyos_config
*********************
**Manage VyOS configuration on remote device**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module provides configuration file management of VyOS devices. It provides arguments for managing both the configuration file and state of the active configuration. All configuration statements are based on `set` and `delete` commands in the device configuration.
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
allow_password_change
string
|
Choices:
- all
plaintext ←
- encrypted
- none
|
The allow_password_change argument specifies whether any configuration lines which would change a user's password should be filtered out. By default only plaintext password changes are allowed and any encrypted-password keys are filtered out. In order to allow all password updates, both plaintext and encrypted, set this argument to all.
+ Not applied when replace is set to config; the candidate is loaded as-is via VyOS's native load, which has no equivalent filtering mechanism.
|
|
backup
boolean
|
|
The backup argument will backup the current devices active configuration to the Ansible control host prior to making any changes. If the backup_options value is not given, the backup file will be located in the backup folder in the playbook root directory or role root directory, if playbook is part of an ansible role. If the directory does not exist, it is created.
|
|
backup_options
dictionary
|
|
- This is a dict object containing configurable options related to backup file path. The value of this option is read only when backup is set to true, if backup is set to false this option will be silently ignored.
+ This is a dict object containing configurable options related to backup file path. The value of this option is read only when backup is set to yes, if backup is set to no this option will be silently ignored.
|
|
dir_path
path
|
|
This option provides the path ending with directory name in which the backup configuration file will be stored. If the directory does not exist it will be first created and the filename is either the value of filename or default filename as described in filename options description. If the path value is not given in that case a backup directory will be created in the current working directory and backup configuration will be copied in filename within backup directory.
|
|
filename
string
|
|
The filename to be used to store the backup configuration. If the filename is not given it will be generated based on the hostname, current time and date in format defined by <hostname>_config.<current-date>@<current-time>
|
|
comment
string
|
Default:
"configured by vyos_config"
|
Allows a commit description to be specified to be included when the configuration is committed. If the configuration is not changed or committed, this argument is ignored.
|
|
config
string
|
|
The config argument specifies the base configuration to use to compare against the desired configuration. If this value is not specified, the module will automatically retrieve the current active configuration from the remote device. The configuration lines in the option value should be similar to how it will appear if present in the running-configuration of the device including indentation to ensure idempotency and correct diff.
+ Ignored when replace is set to config.
|
|
confirm
string
|
Choices:
- automatic
- manual
- none
|
The confirm argument will tell vyos to revert to the previous configuration if not explicitly confirmed after applying the new config. When set to automatic this module will automatically confirm the configuration, if the current session remains working with the new config. When set to manual, this module does not issue the confirmation itself.
Defaults to automatic when match is set to enforce, since enforce can generate delete commands for configuration not mentioned in the candidate and a bad commit should self-revert rather than leave the device unreachable. Defaults to none for all other match values.
|
|
confirm_timeout
integer
|
Default:
10
|
Minutes to wait for confirmation before reverting the configuration. Does not apply when confirm is set to none .
|
|
lines
list
/ elements=string
|
|
The ordered set of commands that should be configured in the section. The commands must be the exact same commands as found in the device running-config as found in the device running-config to ensure idempotency and correct diff. Be sure to note the configuration command syntax as some commands are automatically modified by the device config parser.
+ Not supported when replace is set to config -- see replace below.
|
|
match
string
|
Choices:
line ←
- enforce
- none
|
The match argument controls the method used to match against the current active configuration. By default, the desired config is matched against the active config and the deltas are loaded. If the match argument is set to none, the active configuration is ignored and the configuration is always loaded. If the match argument is set to enforce, the supplied lines or src are treated as the complete desired end-state of the configuration, rather than a set of deltas to apply. enforce enforces only the top-level configuration sections present in the supplied candidate as complete end-states; existing configuration within those sections but not mentioned in the candidate is removed, so enforce can generate delete commands for configuration the candidate does not mention. Top-level sections the candidate does not reference at all are left completely untouched. enforce is intended for candidates made up of set commands only; supplying delete lines alongside match=enforce is not supported and will raise an error.
|
|
save
boolean
|
|
- The save argument controls whether or not changes made to the active configuration are saved to disk. This is independent of committing the config. When set to true, the active configuration is saved.
+ The save argument controls whether or not changes made to the active configuration are saved to disk. This is independent of committing the config. When set to True, the active configuration is saved.
|
|
src
path
|
|
The src argument specifies the path to the source config file to load. The source config file can either be in bracket format or set format. The source file can include Jinja2 template variables. The configuration lines in the source file should be similar to how it will appear if present in the running-configuration of the device including indentation to ensure idempotency and correct diff.
+ When replace is set to config, src is required and must contain a complete configuration in hierarchical/bracket format -- the same format produced by show configuration or found in /config/config.boot. Flat set/delete command format (as produced by show configuration commands) is not accepted in that mode; VyOS's native load command rejects it with a parse error.
|