summaryrefslogtreecommitdiff
path: root/roles/nat
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /roles/nat
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'roles/nat')
-rw-r--r--roles/nat/defaults/main.yml3
-rw-r--r--roles/nat/meta/argument_specs.yml33
-rw-r--r--roles/nat/meta/main.yml11
-rw-r--r--roles/nat/tasks/main.yml15
-rw-r--r--roles/nat/tasks/verify.yml25
-rw-r--r--roles/nat/vars/main.yml2
6 files changed, 89 insertions, 0 deletions
diff --git a/roles/nat/defaults/main.yml b/roles/nat/defaults/main.yml
new file mode 100644
index 0000000..6ba6f0a
--- /dev/null
+++ b/roles/nat/defaults/main.yml
@@ -0,0 +1,3 @@
+---
+nat_source_rules: []
+nat_destination_rules: []
diff --git a/roles/nat/meta/argument_specs.yml b/roles/nat/meta/argument_specs.yml
new file mode 100644
index 0000000..43c260e
--- /dev/null
+++ b/roles/nat/meta/argument_specs.yml
@@ -0,0 +1,33 @@
+---
+argument_specs:
+ main:
+ short_description: Source and destination NAT
+ description:
+ - Configures source NAT (masquerade, SNAT, exclusions such as
+ traffic into a VPN) and destination NAT (port forwarding).
+ - Rules use the rule format of vyos.vyos.vyos_nat (id, description,
+ protocol, exclude, outbound_interface / inbound_interface, source,
+ destination, translation, ...), passed through unchanged, so every
+ option of the module is available.
+ - For a simple small-office edge, C(vyos.blueprints.edge_nat) is shorter.
+ options:
+ nat_source_rules:
+ type: list
+ elements: dict
+ default: []
+ description: "Source NAT rules in vyos_nat format, e.g. C({id: 20, outbound_interface: {name: eth0}, translation: {address: masquerade}})."
+ nat_destination_rules:
+ type: list
+ elements: dict
+ default: []
+ description: Destination NAT rules in vyos_nat format.
+ vyos_blueprints_render_only:
+ type: bool
+ default: false
+ description: Collect commands into C(vyos_blueprints_rendered) instead of configuring.
+ verify:
+ short_description: Post-deployment checks for the nat role
+ description: Run with C(tasks_from=verify). Checks every rule is installed.
+ options:
+ nat_source_rules: {type: list, elements: dict, default: [], description: Same value as for C(main).}
+ nat_destination_rules: {type: list, elements: dict, default: [], description: Same value as for C(main).}
diff --git a/roles/nat/meta/main.yml b/roles/nat/meta/main.yml
new file mode 100644
index 0000000..682f983
--- /dev/null
+++ b/roles/nat/meta/main.yml
@@ -0,0 +1,11 @@
+---
+galaxy_info:
+ author: VyOS maintainers and contributors
+ description: Source and destination NAT rules
+ license: GPL-3.0-or-later
+ min_ansible_version: "2.16"
+ platforms:
+ - name: GenericLinux
+ versions: [all]
+ galaxy_tags: [vyos, networking, nat]
+dependencies: []
diff --git a/roles/nat/tasks/main.yml b/roles/nat/tasks/main.yml
new file mode 100644
index 0000000..6f5007b
--- /dev/null
+++ b/roles/nat/tasks/main.yml
@@ -0,0 +1,15 @@
+---
+- name: Configure source and destination NAT
+ vyos.vyos.vyos_nat:
+ config:
+ nat: >-
+ {{ ({'source': {'rule': nat_source_rules}} if nat_source_rules else {})
+ | combine({'destination': {'rule': nat_destination_rules}} if nat_destination_rules else {}) }}
+ state: "{{ _nat_state }}"
+ register: _nat_r
+ when: (nat_source_rules | length > 0) or (nat_destination_rules | length > 0)
+
+- name: Collect rendered commands # noqa: var-naming[no-role-prefix] - shared across roles by design
+ ansible.builtin.set_fact:
+ vyos_blueprints_rendered: "{{ vyos_blueprints_rendered | default([]) + (_nat_r.rendered | default([])) }}"
+ when: vyos_blueprints_render_only | default(false) | bool
diff --git a/roles/nat/tasks/verify.yml b/roles/nat/tasks/verify.yml
new file mode 100644
index 0000000..a100d3a
--- /dev/null
+++ b/roles/nat/tasks/verify.yml
@@ -0,0 +1,25 @@
+---
+- name: Read NAT rules
+ vyos.vyos.vyos_command:
+ commands:
+ - show nat source rules
+ - show nat destination rules
+ register: _nat_v
+
+- name: Every source NAT rule is installed
+ ansible.builtin.assert:
+ that: _nat_v.stdout[0] is search('(?m)^\s*' ~ item.id ~ '\b')
+ fail_msg: "source NAT rule {{ item.id }} is not installed"
+ quiet: true
+ loop: "{{ nat_source_rules }}"
+ loop_control:
+ label: "{{ item.id }}"
+
+- name: Every destination NAT rule is installed
+ ansible.builtin.assert:
+ that: _nat_v.stdout[1] is search('(?m)^\s*' ~ item.id ~ '\b')
+ fail_msg: "destination NAT rule {{ item.id }} is not installed"
+ quiet: true
+ loop: "{{ nat_destination_rules }}"
+ loop_control:
+ label: "{{ item.id }}"
diff --git a/roles/nat/vars/main.yml b/roles/nat/vars/main.yml
new file mode 100644
index 0000000..a354487
--- /dev/null
+++ b/roles/nat/vars/main.yml
@@ -0,0 +1,2 @@
+---
+_nat_state: "{{ 'rendered' if (vyos_blueprints_render_only | default(false) | bool) else 'merged' }}"