diff --git a/tests/integration/targets/vyos_nat/tests/cli/deleted_full_match.yaml b/tests/integration/targets/vyos_nat/tests/cli/deleted_full_match.yaml index bf7e03d6..43a8124f 100644 --- a/tests/integration/targets/vyos_nat/tests/cli/deleted_full_match.yaml +++ b/tests/integration/targets/vyos_nat/tests/cli/deleted_full_match.yaml @@ -1,44 +1,70 @@ --- - debug: msg: START vyos_nat deleted full-match integration tests on connection={{ ansible_connection }} - include_tasks: _populate.yaml - block: - name: Delete destination rule 100 with full matching config register: result vyos.vyos.vyos_nat: config: nat: destination: rule: - id: 100 description: Web server NAT protocol: tcp log: true inbound_interface: name: eth2 destination: address: 198.51.100.10 port: "80" translation: address: 192.168.1.10 port: "8080" state: deleted - assert: that: - result.changed == true - result.commands == ["delete nat destination rule 100"] - vyos.vyos.vyos_facts: gather_network_resources: nat - name: Assert rule 100 is actually gone from the device assert: that: - - ansible_facts['network_resources']['nat'].destination is not defined or - ansible_facts['network_resources']['nat'].destination.rule | default([]) | selectattr('id', 'equalto', 100) | list | length == 0 + - ansible_facts['network_resources']['nat'].nat.destination is not defined or + ansible_facts['network_resources']['nat'].nat.destination.rule | default([]) | selectattr('id', 'equalto', 100) | list | length == 0 + + - name: Delete the same configuration again (IDEMPOTENT) + register: result + vyos.vyos.vyos_nat: + config: + nat: + destination: + rule: + - id: 100 + description: Web server NAT + protocol: tcp + log: true + inbound_interface: + name: eth2 + destination: + address: 198.51.100.10 + port: "80" + translation: + address: 192.168.1.10 + port: "8080" + state: deleted + + - name: Assert that the previous task was idempotent + assert: + that: + - result['changed'] == false always: - include_tasks: _remove_config.yaml diff --git a/tests/integration/targets/vyos_nat/tests/cli/merged.yaml b/tests/integration/targets/vyos_nat/tests/cli/merged.yaml index b572c6fc..73184fb6 100644 --- a/tests/integration/targets/vyos_nat/tests/cli/merged.yaml +++ b/tests/integration/targets/vyos_nat/tests/cli/merged.yaml @@ -1,92 +1,110 @@ --- - debug: msg: START vyos_nat merged integration tests on connection={{ ansible_connection }} - include_tasks: _populate.yaml - block: - name: Merge new NAT rule with existing configuration register: result vyos.vyos.vyos_nat: &id001 config: nat: destination: rule: - id: 101 description: New DNAT rule protocol: tcp destination: address: 198.51.100.11 port: "443" translation: address: 192.168.1.11 port: "8443" state: merged - vyos.vyos.vyos_facts: gather_network_resources: nat - assert: that: - result.changed == true - result.commands|symmetric_difference(merged.commands) == [] - result.after|symmetric_difference(ansible_facts['network_resources']['nat']) == [] - name: Assert that before dicts were correctly generated assert: that: - merged['before'] | symmetric_difference(result['before']) | length == 0 - name: Merge the provided configuration with the existing running configuration (IDEMPOTENT) register: result vyos.vyos.vyos_nat: *id001 - name: Assert that the previous task was idempotent assert: that: - result['changed'] == false - name: Add static rule with plain inbound_interface string register: result - vyos.vyos.vyos_nat: + vyos.vyos.vyos_nat: &id002 config: nat: static: rule: - id: 300 description: Static mapping inbound_interface: eth2 destination: address: 192.168.100.20 translation: address: 192.168.1.20 state: merged - assert: that: - result.changed == true - "'set nat static rule 300 inbound-interface eth2' in result.commands" + - name: Add static rule again (IDEMPOTENT) + register: result + vyos.vyos.vyos_nat: *id002 + + - name: Assert that the previous task was idempotent + assert: + that: + - result['changed'] == false + - name: Change static rule inbound_interface register: result - vyos.vyos.vyos_nat: + vyos.vyos.vyos_nat: &id003 config: nat: static: rule: - id: 300 description: Static mapping inbound_interface: eth3 destination: address: 192.168.100.20 translation: address: 192.168.1.20 state: merged - assert: that: - result.changed == true - result.commands == ["set nat static rule 300 inbound-interface eth3"] + - name: Change static rule inbound_interface again (IDEMPOTENT) + register: result + vyos.vyos.vyos_nat: *id003 + + - name: Assert that the previous task was idempotent + assert: + that: + - result['changed'] == false + always: - include_tasks: _remove_config.yaml diff --git a/tests/integration/targets/vyos_nat/tests/cli/merged_load_balance.yaml b/tests/integration/targets/vyos_nat/tests/cli/merged_load_balance.yaml new file mode 100644 index 00000000..04ee5816 --- /dev/null +++ b/tests/integration/targets/vyos_nat/tests/cli/merged_load_balance.yaml @@ -0,0 +1,107 @@ +--- +- debug: + msg: START vyos_nat load balance integration tests on connection={{ ansible_connection }} + +- include_tasks: _populate.yaml + +- block: + - name: Add destination rule with load-balance hash and backends + register: result + vyos.vyos.vyos_nat: &id001 + config: + nat: + destination: + rule: + - id: 105 + protocol: tcp + destination: + port: "80" + inbound_interface: + name: eth0 + load_balance: + hash: + - source-address + - destination-address + backend: + - ip: 10.10.10.1 + weight: 60 + - ip: 10.10.10.2 + weight: 40 + state: merged + + - assert: + that: + - result.changed == true + - "'set nat destination rule 105 load-balance hash source-address' in result.commands" + - "'set nat destination rule 105 load-balance hash destination-address' in result.commands" + - "'set nat destination rule 105 load-balance backend 10.10.10.1 weight 60' in result.commands" + - "'set nat destination rule 105 load-balance backend 10.10.10.2 weight 40' in result.commands" + + - name: Re-apply same load-balance config (IDEMPOTENT) + register: result + vyos.vyos.vyos_nat: *id001 + + - name: Assert that the previous task was idempotent + assert: + that: + - result['changed'] == false + + - name: Change backend weights only (in-place overwrite check) + register: result + vyos.vyos.vyos_nat: &id002 + config: + nat: + destination: + rule: + - id: 105 + protocol: tcp + destination: + port: "80" + inbound_interface: + name: eth0 + load_balance: + hash: + - source-address + - destination-address + backend: + - ip: 10.10.10.1 + weight: 70 + - ip: 10.10.10.2 + weight: 30 + state: merged + + - assert: + that: + - result.changed == true + + - vyos.vyos.vyos_facts: + gather_network_resources: nat + + - name: Extract rule 105 from gathered facts + set_fact: + rule_105: "{{ ansible_facts['network_resources']['nat'].nat.destination.rule | selectattr('id', 'equalto', 105) | first }}" + + - name: Extract backend weights from rule 105 + set_fact: + backend_105: "{{ rule_105.load_balance.backend }}" + weight_101: "{{ (rule_105.load_balance.backend | selectattr('ip', 'equalto', '10.10.10.1') | first).weight }}" + weight_102: "{{ (rule_105.load_balance.backend | selectattr('ip', 'equalto', '10.10.10.2') | first).weight }}" + + - name: Assert weights updated and no duplicate/stale backend entries + assert: + that: + - backend_105 | length == 2 + - weight_101 == 70 + - weight_102 == 30 + + - name: Re-apply changed weights again (IDEMPOTENT) + register: result + vyos.vyos.vyos_nat: *id002 + + - name: Assert that the previous task was idempotent + assert: + that: + - result['changed'] == false + + always: + - include_tasks: _remove_config.yaml