path: root/lib
diff options
authorTim Rupp <>2018-01-14 17:40:59 -0800
committerGitHub <>2018-01-14 17:40:59 -0800
commit9aba711519fb1982db0019e76e3104d050772d81 (patch)
treeaa77dfce47199b5da749e81497c7d6485bacb44f /lib
parent5540e2f8a917d68d8abe7abbffb8e7b1e3a80302 (diff)
Adds bigip_static_route module (#34859)
This module can be used to manage static routes on a BIG-IP
Diffstat (limited to 'lib')
1 files changed, 612 insertions, 0 deletions
diff --git a/lib/ansible/modules/network/f5/ b/lib/ansible/modules/network/f5/
new file mode 100644
index 0000000000..9506fb7b03
--- /dev/null
+++ b/lib/ansible/modules/network/f5/
@@ -0,0 +1,612 @@
+# -*- coding: utf-8 -*-
+# Copyright (c) 2017 F5 Networks Inc.
+# GNU General Public License v3.0 (see COPYING or
+from __future__ import absolute_import, division, print_function
+__metaclass__ = type
+ANSIBLE_METADATA = {'metadata_version': '1.1',
+ 'status': ['preview'],
+ 'supported_by': 'community'}
+module: bigip_static_route
+short_description: Manipulate static routes on a BIG-IP
+ - Manipulate static routes on a BIG-IP.
+version_added: 2.5
+ name:
+ description:
+ - Name of the static route.
+ required: True
+ description:
+ description:
+ - Descriptive text that identifies the route.
+ destination:
+ description:
+ - Specifies an IP address for the static entry in the routing table.
+ When creating a new static route, this value is required.
+ - This value cannot be changed once it is set.
+ netmask:
+ description:
+ - The netmask for the static route. When creating a new static route, this value
+ is required.
+ - This value can be in either IP or CIDR format.
+ - This value cannot be changed once it is set.
+ gateway_address:
+ description:
+ - Specifies the router for the system to use when forwarding packets
+ to the destination host or network. Also known as the next-hop router
+ address. This can be either an IPv4 or IPv6 address. When it is an
+ IPv6 address that starts with C(FE80:), the address will be treated
+ as a link-local address. This requires that the C(vlan) parameter
+ also be supplied.
+ vlan:
+ description:
+ - Specifies the VLAN or Tunnel through which the system forwards packets
+ to the destination. When C(gateway_address) is a link-local IPv6
+ address, this value is required
+ pool:
+ description:
+ - Specifies the pool through which the system forwards packets to the
+ destination.
+ reject:
+ description:
+ - Specifies that the system drops packets sent to the destination.
+ mtu:
+ description:
+ - Specifies a specific maximum transmission unit (MTU).
+ route_domain:
+ description:
+ - The route domain id of the system. When creating a new static route, if
+ this value is not specified, a default value of C(0) will be used.
+ - This value cannot be changed once it is set.
+ state:
+ description:
+ - When C(present), ensures that the cloud connector exists. When
+ C(absent), ensures that the cloud connector does not exist.
+ required: False
+ default: present
+ choices:
+ - present
+ - absent
+ - Requires the netaddr Python package on the host. This is as easy as pip
+ install netaddr.
+extends_documentation_fragment: f5
+ - netaddr
+ - Tim Rupp (@caphrim007)
+EXAMPLES = r'''
+- name: Create static route with gateway address
+ bigip_static_route:
+ destination:
+ netmask:
+ gateway_address:
+ name: test-route
+ password: secret
+ server: lb.mydomain.come
+ user: admin
+ validate_certs: no
+ delegate_to: localhost
+RETURN = r'''
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+ description: Route domain of the static route.
+ returned: changed
+ type: int
+ sample: 1
+ description: Netmask of the destination.
+ returned: changed
+ type: string
+ sample:
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+ description: Whether the banner is enabled or not.
+ returned: changed
+ type: string
+ sample: true
+import re
+from ansible.module_utils.basic import AnsibleModule
+from ansible.module_utils.parsing.convert_bool import BOOLEANS_TRUE
+ # Sideband repository used for dev
+ from import HAS_F5SDK
+ from import F5Client
+ from import F5ModuleError
+ from import AnsibleF5Parameters
+ from import cleanup_tokens
+ from import fqdn_name
+ from import f5_argument_spec
+ try:
+ from import iControlUnexpectedHTTPError
+ except ImportError:
+ HAS_F5SDK = False
+except ImportError:
+ # Upstream Ansible
+ from import HAS_F5SDK
+ from import F5Client
+ from import F5ModuleError
+ from import AnsibleF5Parameters
+ from import cleanup_tokens
+ from import fqdn_name
+ from import f5_argument_spec
+ try:
+ from import iControlUnexpectedHTTPError
+ except ImportError:
+ HAS_F5SDK = False
+ import netaddr
+except ImportError:
+class Parameters(AnsibleF5Parameters):
+ api_map = {
+ 'tmInterface': 'vlan',
+ 'gw': 'gateway_address',
+ 'network': 'destination',
+ 'blackhole': 'reject'
+ }
+ updatables = [
+ 'description', 'gateway_address', 'vlan',
+ 'pool', 'mtu', 'reject', 'destination', 'route_domain',
+ 'netmask'
+ ]
+ returnables = [
+ 'vlan', 'gateway_address', 'destination', 'pool', 'description',
+ 'reject', 'mtu', 'netmask', 'route_domain'
+ ]
+ api_attributes = [
+ 'tmInterface', 'gw', 'network', 'blackhole', 'description', 'pool', 'mtu'
+ ]
+ def to_return(self):
+ result = {}
+ for returnable in self.returnables:
+ result[returnable] = getattr(self, returnable)
+ result = self._filter_params(result)
+ return result
+ @property
+ def reject(self):
+ if self._values['reject'] in BOOLEANS_TRUE:
+ return True
+class ModuleParameters(Parameters):
+ @property
+ def vlan(self):
+ if self._values['vlan'] is None:
+ return None
+ return fqdn_name(self.partition, self._values['vlan'])
+ @property
+ def gateway_address(self):
+ if self._values['gateway_address'] is None:
+ return None
+ try:
+ ip = netaddr.IPNetwork(self._values['gateway_address'])
+ return str(ip.ip)
+ except netaddr.core.AddrFormatError:
+ raise F5ModuleError(
+ "The provided gateway_address is not an IP address"
+ )
+ @property
+ def route_domain(self):
+ if self._values['route_domain'] is None:
+ return None
+ result = int(self._values['route_domain'])
+ return result
+ @property
+ def destination(self):
+ if self._values['destination'] is None:
+ return None
+ if self._values['destination'] == 'default':
+ self._values['destination'] = ''
+ try:
+ ip = netaddr.IPNetwork(self.destination_ip)
+ if self.route_domain:
+ return '{0}%{2}/{1}'.format(ip.ip, ip.prefixlen, self.route_domain)
+ else:
+ return '{0}/{1}'.format(ip.ip, ip.prefixlen)
+ except netaddr.core.AddrFormatError:
+ raise F5ModuleError(
+ "The provided destination is not an IP address"
+ )
+ @property
+ def destination_ip(self):
+ if self._values['destination']:
+ ip = netaddr.IPNetwork('{0}/{1}'.format(self._values['destination'], self.netmask))
+ return '{0}/{1}'.format(ip.ip, ip.prefixlen)
+ @property
+ def netmask(self):
+ if self._values['netmask'] is None:
+ return None
+ # Check if numeric
+ if isinstance(self._values['netmask'], int):
+ result = int(self._values['netmask'])
+ if 0 < result < 256:
+ return result
+ raise F5ModuleError(
+ 'The provided netmask {0} is neither in IP or CIDR format'.format(result)
+ )
+ else:
+ try:
+ # IPv4 netmask
+ address = '' + self._values['netmask']
+ ip = netaddr.IPNetwork(address)
+ except netaddr.AddrFormatError as ex:
+ try:
+ # IPv6 netmask
+ address = '::/' + self._values['netmask']
+ ip = netaddr.IPNetwork(address)
+ except netaddr.AddrFormatError as ex:
+ raise F5ModuleError(
+ 'The provided netmask {0} is neither in IP or CIDR format'.format(self._values['netmask'])
+ )
+ result = int(ip.prefixlen)
+ return result
+class ApiParameters(Parameters):
+ @property
+ def route_domain(self):
+ if self._values['destination'] is None:
+ return None
+ pattern = r'([0-9:]%(?P<rd>[0-9]+))'
+ matches =, self._values['destination'])
+ if matches:
+ return int('rd'))
+ return 0
+ @property
+ def destination_ip(self):
+ if self._values['destination'] is None:
+ return None
+ if self._values['destination'] == 'default':
+ self._values['destination'] = ''
+ try:
+ pattern = r'(?P<rd>%[0-9]+)'
+ addr = re.sub(pattern, '', self._values['destination'])
+ ip = netaddr.IPNetwork(addr)
+ return '{0}/{1}'.format(ip.ip, ip.prefixlen)
+ except netaddr.core.AddrFormatError:
+ raise F5ModuleError(
+ "The provided destination is not an IP address"
+ )
+ @property
+ def netmask(self):
+ ip = netaddr.IPNetwork(self.destination_ip)
+ return int(ip.prefixlen)
+class Changes(Parameters):
+ pass
+class UsableChanges(Parameters):
+ pass
+class ReportableChanges(Parameters):
+ pass
+class Difference(object):
+ def __init__(self, want, have=None):
+ self.want = want
+ self.have = have
+ def compare(self, param):
+ try:
+ result = getattr(self, param)
+ return result
+ except AttributeError:
+ return self.__default(param)
+ def __default(self, param):
+ attr1 = getattr(self.want, param)
+ try:
+ attr2 = getattr(self.have, param)
+ if attr1 != attr2:
+ return attr1
+ except AttributeError:
+ return attr1
+ @property
+ def destination(self):
+ if self.want.destination_ip is None:
+ return None
+ if self.want.destination_ip != self.have.destination_ip:
+ raise F5ModuleError(
+ "The destination cannot be changed. Delete and recreate "
+ "the static route if you need to do this."
+ )
+ @property
+ def route_domain(self):
+ if self.want.route_domain is None:
+ return None
+ if self.want.route_domain is None and self.have.route_domain == 0:
+ return None
+ if self.want.route_domain != self.have.route_domain:
+ raise F5ModuleError("You cannot change the route domain.")
+ @property
+ def netmask(self):
+ if self.want.netmask is None:
+ return None
+ # It's easiest to just check the netmask by comparing dest IPs.
+ if self.want.destination_ip != self.have.destination_ip:
+ raise F5ModuleError(
+ "The netmask cannot be changed. Delete and recreate "
+ "the static route if you need to do this."
+ )
+class ModuleManager(object):
+ def __init__(self, *args, **kwargs):
+ self.module = kwargs.get('module', None)
+ self.client = kwargs.get('client', None)
+ self.have = None
+ self.want = ModuleParameters(params=self.module.params)
+ self.changes = UsableChanges()
+ def _set_changed_options(self):
+ changed = {}
+ for key in Parameters.returnables:
+ if getattr(self.want, key) is not None:
+ changed[key] = getattr(self.want, key)
+ if changed:
+ self.changes = UsableChanges(params=changed)
+ def _update_changed_options(self):
+ diff = Difference(self.want, self.have)
+ updatables = Parameters.updatables
+ changed = dict()
+ for k in updatables:
+ change =
+ if change is None:
+ continue
+ else:
+ if k in ['netmask', 'route_domain']:
+ changed['address'] = change
+ else:
+ changed[k] = change
+ if changed:
+ self.changes = UsableChanges(params=changed)
+ return True
+ return False
+ def exec_module(self):
+ changed = False
+ result = dict()
+ state = self.want.state
+ try:
+ if state == "present":
+ changed = self.present()
+ elif state == "absent":
+ changed = self.absent()
+ except iControlUnexpectedHTTPError as e:
+ raise F5ModuleError(str(e))
+ reportable = ReportableChanges(params=self.changes.to_return())
+ changes = reportable.to_return()
+ result.update(**changes)
+ result.update(dict(changed=changed))
+ self._announce_deprecations(result)
+ return result
+ def _announce_deprecations(self, result):
+ warnings = result.pop('__warnings', [])
+ for warning in warnings:
+ self.module.deprecate(
+ msg=warning['msg'],
+ version=warning['version']
+ )
+ def exists(self):
+ collection =
+ for resource in collection:
+ if ==
+ if resource.partition == self.want.partition:
+ return True
+ return False
+ def present(self):
+ if self.exists():
+ return self.update()
+ else:
+ return self.create()
+ def create(self):
+ required_resources = ['pool', 'vlan', 'reject', 'gateway_address']
+ self._set_changed_options()
+ if self.want.destination is None:
+ raise F5ModuleError(
+ 'destination must be specified when creating a static route'
+ )
+ if self.want.netmask is None:
+ raise F5ModuleError(
+ 'netmask must be specified when creating a static route'
+ )
+ if all(getattr(self.want, v) is None for v in required_resources):
+ raise F5ModuleError(
+ "You must specify at least one of " + ', '.join(required_resources)
+ )
+ if self.module.check_mode:
+ return True
+ self.create_on_device()
+ return True
+ def should_update(self):
+ result = self._update_changed_options()
+ if result:
+ return True
+ return False
+ def update(self):
+ self.have = self.read_current_from_device()
+ if not self.should_update():
+ return False
+ if self.module.check_mode:
+ return True
+ self.update_on_device()
+ return True
+ def update_on_device(self):
+ params = self.want.api_params()
+ # The 'network' attribute is not updatable
+ params.pop('network', None)
+ result =
+ partition=self.want.partition
+ )
+ result.modify(**params)
+ def read_current_from_device(self):
+ resource =
+ partition=self.want.partition
+ )
+ result = resource.attrs
+ return ApiParameters(params=result)
+ def create_on_device(self):
+ params = self.want.api_params()
+ partition=self.want.partition,
+ **params
+ )
+ def absent(self):
+ if self.exists():
+ return self.remove()
+ return False
+ def remove(self):
+ if self.module.check_mode:
+ return True
+ self.remove_from_device()
+ if self.exists():
+ raise F5ModuleError("Failed to delete the static route")
+ return True
+ def remove_from_device(self):
+ result =
+ partition=self.want.partition
+ )
+ if result:
+ result.delete()
+class ArgumentSpec(object):
+ def __init__(self):
+ self.supports_check_mode = True
+ argument_spec = dict(
+ name=dict(required=True),
+ description=dict(),
+ destination=dict(),
+ netmask=dict(),
+ gateway_address=dict(),
+ vlan=dict(),
+ pool=dict(),
+ mtu=dict(),
+ reject=dict(
+ type='bool'
+ ),
+ state=dict(
+ default='present',
+ choices=['absent', 'present']
+ ),
+ route_domain=dict(type='int')
+ )
+ self.argument_spec = {}
+ self.argument_spec.update(f5_argument_spec)
+ self.argument_spec.update(argument_spec)
+ self.mutually_exclusive = [
+ ['gateway_address', 'vlan', 'pool', 'reject']
+ ]
+def main():
+ spec = ArgumentSpec()
+ module = AnsibleModule(
+ argument_spec=spec.argument_spec,
+ supports_check_mode=spec.supports_check_mode,
+ mutually_exclusive=spec.mutually_exclusive,
+ )
+ if not HAS_F5SDK:
+ module.fail_json(msg="The python f5-sdk module is required")
+ if not HAS_NETADDR:
+ module.fail_json(msg="The python netaddr module is required")
+ try:
+ client = F5Client(**module.params)
+ mm = ModuleManager(module=module, client=client)
+ results = mm.exec_module()
+ cleanup_tokens(client)
+ module.exit_json(**results)
+ except F5ModuleError as ex:
+ cleanup_tokens(client)
+ module.fail_json(msg=str(ex))
+if __name__ == '__main__':
+ main()