2015-02-03 22:14:56 +01:00
|
|
|
package openstack
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"log"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/hashicorp/terraform/helper/resource"
|
|
|
|
"github.com/hashicorp/terraform/helper/schema"
|
|
|
|
"github.com/rackspace/gophercloud"
|
|
|
|
"github.com/rackspace/gophercloud/openstack/networking/v2/extensions/fwaas/firewalls"
|
|
|
|
)
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func resourceFWFirewallV1() *schema.Resource {
|
2015-02-03 22:14:56 +01:00
|
|
|
return &schema.Resource{
|
2015-02-19 22:55:54 +01:00
|
|
|
Create: resourceFWFirewallV1Create,
|
|
|
|
Read: resourceFWFirewallV1Read,
|
|
|
|
Update: resourceFWFirewallV1Update,
|
|
|
|
Delete: resourceFWFirewallV1Delete,
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
Schema: map[string]*schema.Schema{
|
|
|
|
"region": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
ForceNew: true,
|
2015-04-11 06:11:34 +02:00
|
|
|
DefaultFunc: envDefaultFuncAllowMissing("OS_REGION_NAME"),
|
2015-02-03 22:14:56 +01:00
|
|
|
},
|
|
|
|
"name": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Optional: true,
|
|
|
|
},
|
|
|
|
"description": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Optional: true,
|
|
|
|
},
|
|
|
|
"policy_id": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
},
|
|
|
|
"admin_state_up": &schema.Schema{
|
|
|
|
Type: schema.TypeBool,
|
|
|
|
Optional: true,
|
|
|
|
Default: true,
|
|
|
|
},
|
2015-02-10 00:19:01 +01:00
|
|
|
"tenant_id": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Optional: true,
|
|
|
|
ForceNew: true,
|
2015-05-10 06:38:36 +02:00
|
|
|
Computed: true,
|
2015-02-10 00:19:01 +01:00
|
|
|
},
|
2015-02-03 22:14:56 +01:00
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func resourceFWFirewallV1Create(d *schema.ResourceData, meta interface{}) error {
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
config := meta.(*Config)
|
|
|
|
networkingClient, err := config.networkingV2Client(d.Get("region").(string))
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
adminStateUp := d.Get("admin_state_up").(bool)
|
|
|
|
|
|
|
|
firewallConfiguration := firewalls.CreateOpts{
|
|
|
|
Name: d.Get("name").(string),
|
|
|
|
Description: d.Get("description").(string),
|
|
|
|
PolicyID: d.Get("policy_id").(string),
|
|
|
|
AdminStateUp: &adminStateUp,
|
2015-02-10 00:19:01 +01:00
|
|
|
TenantID: d.Get("tenant_id").(string),
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
log.Printf("[DEBUG] Create firewall: %#v", firewallConfiguration)
|
|
|
|
|
|
|
|
firewall, err := firewalls.Create(networkingClient, firewallConfiguration).Extract()
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Printf("[DEBUG] Firewall created: %#v", firewall)
|
|
|
|
|
|
|
|
stateConf := &resource.StateChangeConf{
|
|
|
|
Pending: []string{"PENDING_CREATE"},
|
|
|
|
Target: "ACTIVE",
|
2015-02-19 22:55:54 +01:00
|
|
|
Refresh: waitForFirewallActive(networkingClient, firewall.ID),
|
2015-02-03 22:14:56 +01:00
|
|
|
Timeout: 30 * time.Second,
|
|
|
|
Delay: 0,
|
|
|
|
MinTimeout: 2 * time.Second,
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = stateConf.WaitForState()
|
|
|
|
|
2015-02-18 00:12:04 +01:00
|
|
|
d.SetId(firewall.ID)
|
|
|
|
|
2015-02-19 23:44:49 +01:00
|
|
|
return resourceFWFirewallV1Read(d, meta)
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func resourceFWFirewallV1Read(d *schema.ResourceData, meta interface{}) error {
|
2015-02-03 22:14:56 +01:00
|
|
|
log.Printf("[DEBUG] Retrieve information about firewall: %s", d.Id())
|
|
|
|
|
|
|
|
config := meta.(*Config)
|
|
|
|
networkingClient, err := config.networkingV2Client(d.Get("region").(string))
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
firewall, err := firewalls.Get(networkingClient, d.Id()).Extract()
|
2015-02-19 23:31:19 +01:00
|
|
|
|
2015-02-03 22:14:56 +01:00
|
|
|
if err != nil {
|
2015-05-05 14:01:49 +02:00
|
|
|
return CheckDeleted(d, err, "firewall")
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
2015-03-24 13:59:55 +01:00
|
|
|
d.Set("name", firewall.Name)
|
|
|
|
d.Set("description", firewall.Description)
|
|
|
|
d.Set("policy_id", firewall.PolicyID)
|
|
|
|
d.Set("admin_state_up", firewall.AdminStateUp)
|
|
|
|
d.Set("tenant_id", firewall.TenantID)
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func resourceFWFirewallV1Update(d *schema.ResourceData, meta interface{}) error {
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
config := meta.(*Config)
|
|
|
|
networkingClient, err := config.networkingV2Client(d.Get("region").(string))
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
opts := firewalls.UpdateOpts{}
|
|
|
|
|
|
|
|
if d.HasChange("name") {
|
2015-02-17 22:07:01 +01:00
|
|
|
opts.Name = d.Get("name").(string)
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if d.HasChange("description") {
|
2015-02-17 22:07:01 +01:00
|
|
|
opts.Description = d.Get("description").(string)
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if d.HasChange("policy_id") {
|
|
|
|
opts.PolicyID = d.Get("policy_id").(string)
|
|
|
|
}
|
|
|
|
|
2015-02-18 00:12:04 +01:00
|
|
|
if d.HasChange("admin_state_up") {
|
|
|
|
adminStateUp := d.Get("admin_state_up").(bool)
|
|
|
|
opts.AdminStateUp = &adminStateUp
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
2015-02-18 00:12:04 +01:00
|
|
|
log.Printf("[DEBUG] Updating firewall with id %s: %#v", d.Id(), opts)
|
|
|
|
|
2015-02-03 22:14:56 +01:00
|
|
|
stateConf := &resource.StateChangeConf{
|
2015-02-18 00:12:04 +01:00
|
|
|
Pending: []string{"PENDING_CREATE", "PENDING_UPDATE"},
|
2015-02-03 22:14:56 +01:00
|
|
|
Target: "ACTIVE",
|
2015-02-19 22:55:54 +01:00
|
|
|
Refresh: waitForFirewallActive(networkingClient, d.Id()),
|
2015-02-03 22:14:56 +01:00
|
|
|
Timeout: 30 * time.Second,
|
|
|
|
Delay: 0,
|
|
|
|
MinTimeout: 2 * time.Second,
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = stateConf.WaitForState()
|
|
|
|
|
2015-02-19 23:44:49 +01:00
|
|
|
err = firewalls.Update(networkingClient, d.Id(), opts).Err
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return resourceFWFirewallV1Read(d, meta)
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func resourceFWFirewallV1Delete(d *schema.ResourceData, meta interface{}) error {
|
2015-02-03 22:14:56 +01:00
|
|
|
log.Printf("[DEBUG] Destroy firewall: %s", d.Id())
|
|
|
|
|
|
|
|
config := meta.(*Config)
|
|
|
|
networkingClient, err := config.networkingV2Client(d.Get("region").(string))
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
|
|
|
|
}
|
|
|
|
|
2015-02-18 00:12:04 +01:00
|
|
|
stateConf := &resource.StateChangeConf{
|
|
|
|
Pending: []string{"PENDING_CREATE", "PENDING_UPDATE"},
|
|
|
|
Target: "ACTIVE",
|
2015-02-19 22:55:54 +01:00
|
|
|
Refresh: waitForFirewallActive(networkingClient, d.Id()),
|
2015-02-18 00:12:04 +01:00
|
|
|
Timeout: 30 * time.Second,
|
|
|
|
Delay: 0,
|
|
|
|
MinTimeout: 2 * time.Second,
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = stateConf.WaitForState()
|
|
|
|
|
2015-02-03 22:14:56 +01:00
|
|
|
err = firewalls.Delete(networkingClient, d.Id()).Err
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2015-02-18 00:12:04 +01:00
|
|
|
stateConf = &resource.StateChangeConf{
|
2015-02-03 22:14:56 +01:00
|
|
|
Pending: []string{"DELETING"},
|
|
|
|
Target: "DELETED",
|
2015-02-19 22:55:54 +01:00
|
|
|
Refresh: waitForFirewallDeletion(networkingClient, d.Id()),
|
2015-02-03 22:14:56 +01:00
|
|
|
Timeout: 2 * time.Minute,
|
|
|
|
Delay: 0,
|
|
|
|
MinTimeout: 2 * time.Second,
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = stateConf.WaitForState()
|
|
|
|
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func waitForFirewallActive(networkingClient *gophercloud.ServiceClient, id string) resource.StateRefreshFunc {
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
return func() (interface{}, string, error) {
|
|
|
|
fw, err := firewalls.Get(networkingClient, id).Extract()
|
|
|
|
log.Printf("[DEBUG] Get firewall %s => %#v", id, fw)
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return nil, "", err
|
|
|
|
}
|
|
|
|
return fw, fw.Status, nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-02-19 22:55:54 +01:00
|
|
|
func waitForFirewallDeletion(networkingClient *gophercloud.ServiceClient, id string) resource.StateRefreshFunc {
|
2015-02-03 22:14:56 +01:00
|
|
|
|
|
|
|
return func() (interface{}, string, error) {
|
|
|
|
fw, err := firewalls.Get(networkingClient, id).Extract()
|
|
|
|
log.Printf("[DEBUG] Get firewall %s => %#v", id, fw)
|
|
|
|
|
|
|
|
if err != nil {
|
2015-02-17 22:07:01 +01:00
|
|
|
httpStatus := err.(*gophercloud.UnexpectedResponseCodeError)
|
2015-02-03 22:14:56 +01:00
|
|
|
log.Printf("[DEBUG] Get firewall %s status is %d", id, httpStatus.Actual)
|
|
|
|
|
|
|
|
if httpStatus.Actual == 404 {
|
|
|
|
log.Printf("[DEBUG] Firewall %s is actually deleted", id)
|
|
|
|
return "", "DELETED", nil
|
|
|
|
}
|
2015-02-19 23:53:30 +01:00
|
|
|
return nil, "", fmt.Errorf("Unexpected status code %d", httpStatus.Actual)
|
2015-02-03 22:14:56 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
log.Printf("[DEBUG] Firewall %s deletion is pending", id)
|
|
|
|
return fw, "DELETING", nil
|
|
|
|
}
|
|
|
|
}
|