2015-10-26 15:45:48 +01:00
|
|
|
package vcd
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"github.com/hashicorp/terraform/helper/schema"
|
2015-11-06 11:19:59 +01:00
|
|
|
"github.com/hmrc/vmware-govcd"
|
2015-10-26 15:45:48 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
func resourceVcdSNAT() *schema.Resource {
|
|
|
|
return &schema.Resource{
|
|
|
|
Create: resourceVcdSNATCreate,
|
|
|
|
Delete: resourceVcdSNATDelete,
|
|
|
|
Read: resourceVcdSNATRead,
|
|
|
|
|
|
|
|
Schema: map[string]*schema.Schema{
|
|
|
|
"edge_gateway": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
ForceNew: true,
|
|
|
|
},
|
|
|
|
|
|
|
|
"external_ip": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
2015-11-10 19:39:58 +01:00
|
|
|
ForceNew: true,
|
2015-10-26 15:45:48 +01:00
|
|
|
},
|
|
|
|
|
|
|
|
"internal_ip": &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
2015-11-10 19:39:58 +01:00
|
|
|
ForceNew: true,
|
2015-10-26 15:45:48 +01:00
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func resourceVcdSNATCreate(d *schema.ResourceData, meta interface{}) error {
|
2015-11-16 21:11:05 +01:00
|
|
|
vcdClient := meta.(*govcd.VCDClient)
|
2015-10-26 15:45:48 +01:00
|
|
|
// Multiple VCD components need to run operations on the Edge Gateway, as
|
|
|
|
// the edge gatway will throw back an error if it is already performing an
|
|
|
|
// operation we must wait until we can aquire a lock on the client
|
2015-11-16 21:11:05 +01:00
|
|
|
vcdClient.Mutex.Lock()
|
|
|
|
defer vcdClient.Mutex.Unlock()
|
2015-10-26 15:45:48 +01:00
|
|
|
|
|
|
|
// Creating a loop to offer further protection from the edge gateway erroring
|
|
|
|
// due to being busy eg another person is using another client so wouldn't be
|
|
|
|
// constrained by out lock. If the edge gateway reurns with a busy error, wait
|
|
|
|
// 3 seconds and then try again. Continue until a non-busy error or success
|
2015-11-16 21:11:05 +01:00
|
|
|
edgeGateway, err := vcdClient.OrgVdc.FindEdgeGateway(d.Get("edge_gateway").(string))
|
2015-11-02 17:39:56 +01:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Unable to find edge gateway: %#v", err)
|
|
|
|
}
|
2015-10-26 15:45:48 +01:00
|
|
|
|
2015-11-02 17:39:56 +01:00
|
|
|
err = retryCall(4, func() error {
|
|
|
|
task, err := edgeGateway.AddNATMapping("SNAT", d.Get("internal_ip").(string),
|
2015-10-26 15:45:48 +01:00
|
|
|
d.Get("external_ip").(string),
|
|
|
|
"any")
|
|
|
|
if err != nil {
|
2015-11-02 17:39:56 +01:00
|
|
|
return fmt.Errorf("Error setting SNAT rules: %#v", err)
|
2015-10-26 15:45:48 +01:00
|
|
|
}
|
2015-11-02 17:39:56 +01:00
|
|
|
return task.WaitTaskCompletion()
|
|
|
|
})
|
2015-10-26 15:45:48 +01:00
|
|
|
if err != nil {
|
2015-11-02 17:39:56 +01:00
|
|
|
return err
|
2015-10-26 15:45:48 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
d.SetId(d.Get("internal_ip").(string))
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func resourceVcdSNATRead(d *schema.ResourceData, meta interface{}) error {
|
2015-11-16 21:11:05 +01:00
|
|
|
vcdClient := meta.(*govcd.VCDClient)
|
|
|
|
e, err := vcdClient.OrgVdc.FindEdgeGateway(d.Get("edge_gateway").(string))
|
2015-10-26 15:45:48 +01:00
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Unable to find edge gateway: %#v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
var found bool
|
|
|
|
|
|
|
|
for _, r := range e.EdgeGateway.Configuration.EdgeGatewayServiceConfiguration.NatService.NatRule {
|
|
|
|
if r.RuleType == "SNAT" &&
|
|
|
|
r.GatewayNatRule.OriginalIP == d.Id() {
|
|
|
|
found = true
|
|
|
|
d.Set("external_ip", r.GatewayNatRule.TranslatedIP)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if !found {
|
|
|
|
d.SetId("")
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func resourceVcdSNATDelete(d *schema.ResourceData, meta interface{}) error {
|
2015-11-16 21:11:05 +01:00
|
|
|
vcdClient := meta.(*govcd.VCDClient)
|
2015-10-26 15:45:48 +01:00
|
|
|
// Multiple VCD components need to run operations on the Edge Gateway, as
|
|
|
|
// the edge gatway will throw back an error if it is already performing an
|
|
|
|
// operation we must wait until we can aquire a lock on the client
|
2015-11-16 21:11:05 +01:00
|
|
|
vcdClient.Mutex.Lock()
|
|
|
|
defer vcdClient.Mutex.Unlock()
|
2015-10-26 15:45:48 +01:00
|
|
|
|
2015-11-16 21:11:05 +01:00
|
|
|
edgeGateway, err := vcdClient.OrgVdc.FindEdgeGateway(d.Get("edge_gateway").(string))
|
2015-11-02 17:39:56 +01:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Unable to find edge gateway: %#v", err)
|
|
|
|
}
|
2015-10-26 15:45:48 +01:00
|
|
|
|
2015-11-02 17:39:56 +01:00
|
|
|
err = retryCall(4, func() error {
|
|
|
|
task, err := edgeGateway.RemoveNATMapping("SNAT", d.Get("internal_ip").(string),
|
2015-10-26 15:45:48 +01:00
|
|
|
d.Get("external_ip").(string),
|
|
|
|
"")
|
|
|
|
if err != nil {
|
2015-11-02 17:39:56 +01:00
|
|
|
return fmt.Errorf("Error setting SNAT rules: %#v", err)
|
2015-10-26 15:45:48 +01:00
|
|
|
}
|
2015-11-02 17:39:56 +01:00
|
|
|
return task.WaitTaskCompletion()
|
|
|
|
})
|
2015-10-26 15:45:48 +01:00
|
|
|
if err != nil {
|
2015-11-02 17:39:56 +01:00
|
|
|
return err
|
2015-10-26 15:45:48 +01:00
|
|
|
}
|
2015-11-02 17:39:56 +01:00
|
|
|
|
2015-10-26 15:45:48 +01:00
|
|
|
return nil
|
|
|
|
}
|