Merge pull request #326 from preo/ec2-eip-refactor

Refactor and improve the EC2 Elastic IP module.
reviewable/pr18780/r1
Brian Coca 9 years ago
commit 05a2ef106f

@ -37,15 +37,11 @@ options:
version_added: "1.4" version_added: "1.4"
reuse_existing_ip_allowed: reuse_existing_ip_allowed:
description: description:
- Reuse an EIP that is not associated to an instance (when available), instead of allocating a new one. - Reuse an EIP that is not associated to an instance (when available),'''
''' instead of allocating a new one.
required: false required: false
default: false default: false
version_added: "1.6" version_added: "1.6"
wait_timeout:
description:
- how long to wait in seconds for newly provisioned EIPs to become available
default: 300
version_added: "1.7"
extends_documentation_fragment: aws extends_documentation_fragment: aws
author: Lorin Hochstein <lorin@nimbisservices.com> author: Lorin Hochstein <lorin@nimbisservices.com>
@ -53,9 +49,9 @@ notes:
- This module will return C(public_ip) on success, which will contain the - This module will return C(public_ip) on success, which will contain the
public IP address associated with the instance. public IP address associated with the instance.
- There may be a delay between the time the Elastic IP is assigned and when - There may be a delay between the time the Elastic IP is assigned and when
the cloud instance is reachable via the new address. Use wait_for and pause the cloud instance is reachable via the new address. Use wait_for and
to delay further playbook execution until the instance is reachable, if pause to delay further playbook execution until the instance is reachable,
necessary. if necessary.
''' '''
EXAMPLES = ''' EXAMPLES = '''
@ -78,7 +74,8 @@ EXAMPLES = '''
ec2_eip: state='present' ec2_eip: state='present'
- name: provision new instances with ec2 - name: provision new instances with ec2
ec2: keypair=mykey instance_type=c1.medium image=ami-40603AD1 wait=yes group=webserver count=3 ec2: keypair=mykey instance_type=c1.medium image=emi-40603AD1 wait=yes'''
''' group=webserver count=3
register: ec2 register: ec2
- name: associate new elastic IPs with each of the instances - name: associate new elastic IPs with each of the instances
ec2_eip: "instance_id={{ item }}" ec2_eip: "instance_id={{ item }}"
@ -97,178 +94,165 @@ try:
except ImportError: except ImportError:
HAS_BOTO = False HAS_BOTO = False
wait_timeout = 0
def associate_ip_and_instance(ec2, address, instance_id, module): class EIPException(Exception):
if ip_is_associated_with_instance(ec2, address.public_ip, instance_id, module): pass
module.exit_json(changed=False, public_ip=address.public_ip)
# If we're in check mode, nothing else to do
if module.check_mode:
module.exit_json(changed=True)
try: def associate_ip_and_instance(ec2, address, instance_id, check_mode):
if address.domain == "vpc": if address_is_associated_with_instance(ec2, address, instance_id):
res = ec2.associate_address(instance_id, allocation_id=address.allocation_id) return {'changed': False}
# If we're in check mode, nothing else to do
if not check_mode:
if address.domain == 'vpc':
res = ec2.associate_address(instance_id,
allocation_id=address.allocation_id)
else: else:
res = ec2.associate_address(instance_id, public_ip=address.public_ip) res = ec2.associate_address(instance_id,
except boto.exception.EC2ResponseError, e: public_ip=address.public_ip)
module.fail_json(msg=str(e)) if not res:
raise EIPException('association failed')
if res:
module.exit_json(changed=True, public_ip=address.public_ip)
else:
module.fail_json(msg="association failed")
return {'changed': True}
def disassociate_ip_and_instance(ec2, address, instance_id, module):
if not ip_is_associated_with_instance(ec2, address.public_ip, instance_id, module):
module.exit_json(changed=False, public_ip=address.public_ip)
# If we're in check mode, nothing else to do def disassociate_ip_and_instance(ec2, address, instance_id, check_mode):
if module.check_mode: if not address_is_associated_with_instance(ec2, address, instance_id):
module.exit_json(changed=True) return {'changed': False}
try: # If we're in check mode, nothing else to do
if address.domain == "vpc": if not check_mode:
res = ec2.disassociate_address(association_id=address.association_id) if address.domain == 'vpc':
res = ec2.disassociate_address(
association_id=address.association_id)
else: else:
res = ec2.disassociate_address(public_ip=address.public_ip) res = ec2.disassociate_address(public_ip=address.public_ip)
except boto.exception.EC2ResponseError, e:
module.fail_json(msg=str(e))
if res: if not res:
module.exit_json(changed=True) raise EIPException('disassociation failed')
else:
module.fail_json(msg="disassociation failed") return {'changed': True}
def find_address(ec2, public_ip, module, fail_on_not_found=True):
""" Find an existing Elastic IP address """
if wait_timeout != 0:
timeout = time.time() + wait_timeout
while timeout > time.time():
try:
addresses = ec2.get_all_addresses([public_ip])
break
except boto.exception.EC2ResponseError, e:
if "Address '%s' not found." % public_ip in e.message :
if not fail_on_not_found:
return None
else:
module.fail_json(msg=str(e.message))
time.sleep(5)
if timeout <= time.time():
module.fail_json(msg = "wait for EIPs timeout on %s" % time.asctime())
else:
try:
addresses = ec2.get_all_addresses([public_ip])
except boto.exception.EC2ResponseError, e:
if "Address '%s' not found." % public_ip in e.message :
if not fail_on_not_found:
return None
module.fail_json(msg=str(e.message))
return addresses[0]
def _find_address_by_ip(ec2, public_ip):
try:
return ec2.get_all_addresses([public_ip])[0]
except boto.exception.EC2ResponseError as e:
if "Address '{}' not found.".format(public_ip) not in e.message:
raise
def _find_address_by_instance_id(ec2, instance_id):
addresses = ec2.get_all_addresses(None, {'instance-id': instance_id})
if addresses:
return addresses[0]
def ip_is_associated_with_instance(ec2, public_ip, instance_id, module): def find_address(ec2, public_ip, instance_id):
""" Find an existing Elastic IP address """
if public_ip:
return _find_address_by_ip(ec2, public_ip)
elif instance_id:
return _find_address_by_instance_id(ec2, instance_id)
def address_is_associated_with_instance(ec2, address, instance_id):
""" Check if the elastic IP is currently associated with the instance """ """ Check if the elastic IP is currently associated with the instance """
address = find_address(ec2, public_ip, module)
if address: if address:
return address.instance_id == instance_id return address and address.instance_id == instance_id
else: return False
return False
def instance_is_associated(ec2, instance, module):
"""
Check if the given instance object is already associated with an
elastic IP
"""
instance_ip = instance.ip_address
if not instance_ip:
return False
eip = find_address(ec2, instance_ip, module, fail_on_not_found=False)
return (eip and (eip.public_ip == instance_ip))
def allocate_address(ec2, domain, module, reuse_existing_ip_allowed):
""" Allocate a new elastic IP address (when needed) and return it """
# If we're in check mode, nothing else to do
if module.check_mode:
module.exit_json(change=True)
def allocate_address(ec2, domain, reuse_existing_ip_allowed):
""" Allocate a new elastic IP address (when needed) and return it """
if reuse_existing_ip_allowed: if reuse_existing_ip_allowed:
if domain: domain_filter = {'domain': domain or 'standard'}
domain_filter = { 'domain' : domain } all_addresses = ec2.get_all_addresses(filters=domain_filter)
else:
domain_filter = { 'domain' : 'standard' } unassociated_addresses = [a for a in all_addresses
all_addresses = ec2.get_all_addresses(filters=domain_filter) if not a.instance_id]
if unassociated_addresses:
unassociated_addresses = filter(lambda a: not a.instance_id, all_addresses) return unassociated_addresses[0]
if unassociated_addresses:
address = unassociated_addresses[0];
else:
address = ec2.allocate_address(domain=domain)
else:
address = ec2.allocate_address(domain=domain)
return address return ec2.allocate_address(domain=domain)
def release_address(ec2, public_ip, module): def release_address(ec2, address, check_mode):
""" Release a previously allocated elastic IP address """ """ Release a previously allocated elastic IP address """
address = find_address(ec2, public_ip, module)
# If we're in check mode, nothing else to do # If we're in check mode, nothing else to do
if module.check_mode: if not check_mode:
module.exit_json(change=True) if not address.release():
EIPException('release failed')
res = address.release()
if res: return {'changed': True}
module.exit_json(changed=True)
else:
module.fail_json(msg="release failed")
def find_instance(ec2, instance_id, module): def find_instance(ec2, instance_id):
""" Attempt to find the EC2 instance and return it """ """ Attempt to find the EC2 instance and return it """
try: reservations = ec2.get_all_reservations(instance_ids=[instance_id])
reservations = ec2.get_all_reservations(instance_ids=[instance_id])
except boto.exception.EC2ResponseError, e:
module.fail_json(msg=str(e))
if len(reservations) == 1: if len(reservations) == 1:
instances = reservations[0].instances instances = reservations[0].instances
if len(instances) == 1: if len(instances) == 1:
return instances[0] return instances[0]
module.fail_json(msg="could not find instance" + instance_id)
def allocate_eip(ec2, eip_domain, module, reuse_existing_ip_allowed, new_eip_timeout): raise EIPException("could not find instance" + instance_id)
# Allocate a new elastic IP
address = allocate_address(ec2, eip_domain, module, reuse_existing_ip_allowed)
# overriding the timeout since this is a a newly provisioned ip def ensure_present(ec2, domain, address, instance_id,
global wait_timeout reuse_existing_ip_allowed, check_mode):
wait_timeout = new_eip_timeout changed = False
return address
# Return the EIP object since we've been given a public IP
if not address:
if check_mode:
return {'changed': True}
address = allocate_address(ec2, domain, reuse_existing_ip_allowed)
changed = True
if instance_id:
# Allocate an IP for instance since no public_ip was provided
instance = find_instance(ec2, instance_id)
if instance.vpc_id:
domain = 'vpc'
# Associate address object (provided or allocated) with instance
assoc_result = associate_ip_and_instance(ec2, address, instance_id,
check_mode)
changed = changed or assoc_result['changed']
return {'changed': changed, 'public_ip': address.public_ip}
def ensure_absent(ec2, domain, address, instance_id, check_mode):
if not address:
return {'changed': False}
# disassociating address from instance
if instance_id:
return disassociate_ip_and_instance(ec2, address, instance_id,
check_mode)
# releasing address
else:
return release_address(ec2, address, check_mode)
def main(): def main():
argument_spec = ec2_argument_spec() argument_spec = ec2_argument_spec()
argument_spec.update(dict( argument_spec.update(dict(
instance_id = dict(required=False), instance_id=dict(required=False),
public_ip = dict(required=False, aliases= ['ip']), public_ip=dict(required=False, aliases=['ip']),
state = dict(required=False, default='present', state=dict(required=False, default='present',
choices=['present', 'absent']), choices=['present', 'absent']),
in_vpc = dict(required=False, type='bool', default=False), in_vpc=dict(required=False, type='bool', default=False),
reuse_existing_ip_allowed = dict(required=False, type='bool', default=False), reuse_existing_ip_allowed=dict(required=False, type='bool',
wait_timeout = dict(default=300), default=False),
) wait_timeout=dict(default=300),
) ))
module = AnsibleModule( module = AnsibleModule(
argument_spec=argument_spec, argument_spec=argument_spec,
@ -284,54 +268,27 @@ def main():
public_ip = module.params.get('public_ip') public_ip = module.params.get('public_ip')
state = module.params.get('state') state = module.params.get('state')
in_vpc = module.params.get('in_vpc') in_vpc = module.params.get('in_vpc')
domain = "vpc" if in_vpc else None domain = 'vpc' if in_vpc else None
reuse_existing_ip_allowed = module.params.get('reuse_existing_ip_allowed') reuse_existing_ip_allowed = module.params.get('reuse_existing_ip_allowed')
new_eip_timeout = int(module.params.get('wait_timeout'))
if state == 'present':
# If both instance_id and public_ip are not specified, allocate a new
# elastic IP, and exit.
if not instance_id and not public_ip:
address = allocate_eip(ec2, domain, module,
reuse_existing_ip_allowed, new_eip_timeout)
module.exit_json(changed=True, public_ip=address.public_ip)
# Return the EIP object since we've been given a public IP
if public_ip:
address = find_address(ec2, public_ip, module)
if instance_id and not public_ip:
instance = find_instance(ec2, instance_id, module)
if instance.vpc_id: try:
domain = "vpc" address = find_address(ec2, public_ip, instance_id)
# Do nothing if the instance is already associated with an
# elastic IP.
if instance_is_associated(ec2, instance, module):
module.exit_json(changed=False, public_ip=instance.ip_address)
# If the instance is not already associated with an elastic IP,
# allocate a new one.
address = allocate_eip(
ec2, domain, module, reuse_existing_ip_allowed, new_eip_timeout)
# Associate address object (provided or allocated) with instance
associate_ip_and_instance(ec2, address, instance_id, module)
else: if state == 'present':
#disassociating address from instance result = ensure_present(ec2, domain, address, instance_id,
if instance_id: reuse_existing_ip_allowed,
address = find_address(ec2, public_ip, module) module.check_mode)
disassociate_ip_and_instance(ec2, address, instance_id, module)
#releasing address
else: else:
release_address(ec2, public_ip, module) result = ensure_absent(ec2, domain, address, instance_id, module.check_mode)
except (boto.exception.EC2ResponseError, EIPException) as e:
module.fail_json(msg=str(e))
module.exit_json(**result)
# import module snippets # import module snippets
from ansible.module_utils.basic import * from ansible.module_utils.basic import * # noqa
from ansible.module_utils.ec2 import * from ansible.module_utils.ec2 import * # noqa
if __name__ == '__main__': if __name__ == '__main__':
main() main()

Loading…
Cancel
Save