
219 lines
5.4 KiB
Raw Normal View History

2015-02-05 13:49:23 +01:00
package openstack
import (
2015-02-05 13:49:23 +01:00
func TestAccFWRuleV1_basic(t *testing.T) {
rule1 := &rules.Rule{
Name: "rule_1",
Protocol: "udp",
Action: "deny",
IPVersion: 4,
Enabled: true,
rule2 := &rules.Rule{
Name: "rule_1",
Protocol: "udp",
Action: "deny",
Description: "Terraform accept test",
IPVersion: 4,
SourceIPAddress: "",
DestinationIPAddress: "",
SourcePort: "444",
DestinationPort: "555",
Enabled: true,
rule3 := &rules.Rule{
Name: "rule_1",
Protocol: "tcp",
Action: "allow",
Description: "Terraform accept test updated",
IPVersion: 4,
SourceIPAddress: "",
DestinationIPAddress: "",
SourcePort: "666",
DestinationPort: "777",
Enabled: false,
2015-02-05 13:49:23 +01:00
resource.Test(t, resource.TestCase{
PreCheck: func() { testAccPreCheck(t) },
Providers: testAccProviders,
CheckDestroy: testAccCheckFWRuleV1Destroy,
2015-02-05 13:49:23 +01:00
Steps: []resource.TestStep{
Config: testAccFWRuleV1_basic_1,
2015-02-05 13:49:23 +01:00
Check: resource.ComposeTestCheckFunc(
testAccCheckFWRuleV1Exists("openstack_fw_rule_v1.rule_1", rule1),
2015-02-05 13:49:23 +01:00
Config: testAccFWRuleV1_basic_2,
2015-02-05 13:49:23 +01:00
Check: resource.ComposeTestCheckFunc(
testAccCheckFWRuleV1Exists("openstack_fw_rule_v1.rule_1", rule2),
2015-02-05 13:49:23 +01:00
Config: testAccFWRuleV1_basic_3,
2015-02-05 13:49:23 +01:00
Check: resource.ComposeTestCheckFunc(
testAccCheckFWRuleV1Exists("openstack_fw_rule_v1.rule_1", rule3),
2015-02-05 13:49:23 +01:00
func TestAccFWRuleV1_anyProtocol(t *testing.T) {
rule := &rules.Rule{
Name: "rule_1",
Description: "Allow any protocol",
Protocol: "",
Action: "allow",
IPVersion: 4,
SourceIPAddress: "",
Enabled: true,
resource.Test(t, resource.TestCase{
PreCheck: func() { testAccPreCheck(t) },
Providers: testAccProviders,
CheckDestroy: testAccCheckFWRuleV1Destroy,
Steps: []resource.TestStep{
Config: testAccFWRuleV1_anyProtocol,
Check: resource.ComposeTestCheckFunc(
testAccCheckFWRuleV1Exists("openstack_fw_rule_v1.rule_1", rule),
func testAccCheckFWRuleV1Destroy(s *terraform.State) error {
2015-02-05 13:49:23 +01:00
config := testAccProvider.Meta().(*Config)
networkingClient, err := config.networkingV2Client(OS_REGION_NAME)
if err != nil {
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
2015-02-05 13:49:23 +01:00
2015-02-05 13:49:23 +01:00
for _, rs := range s.RootModule().Resources {
if rs.Type != "openstack_firewall_rule" {
_, err = rules.Get(networkingClient, rs.Primary.ID).Extract()
if err == nil {
return fmt.Errorf("Firewall rule (%s) still exists.", rs.Primary.ID)
if _, ok := err.(gophercloud.ErrDefault404); !ok {
return err
2015-02-05 13:49:23 +01:00
return nil
func testAccCheckFWRuleV1Exists(n string, expected *rules.Rule) resource.TestCheckFunc {
2015-02-05 13:49:23 +01:00
return func(s *terraform.State) error {
rs, ok := s.RootModule().Resources[n]
if !ok {
return fmt.Errorf("Not found: %s", n)
if rs.Primary.ID == "" {
return fmt.Errorf("No ID is set")
config := testAccProvider.Meta().(*Config)
networkingClient, err := config.networkingV2Client(OS_REGION_NAME)
if err != nil {
return fmt.Errorf("Error creating OpenStack networking client: %s", err)
2015-02-05 13:49:23 +01:00
var found *rules.Rule
for i := 0; i < 5; i++ {
// Firewall rule creation is asynchronous. Retry some times
// if we get a 404 error. Fail on any other error.
found, err = rules.Get(networkingClient, rs.Primary.ID).Extract()
if err != nil {
if _, ok := err.(gophercloud.ErrDefault404); ok {
2015-02-05 13:49:23 +01:00
return err
2015-02-05 13:49:23 +01:00
expected.ID = found.ID
// Erase the tenant id because we don't want to compare
// it as long it is not present in the expected
found.TenantID = ""
2015-02-05 13:49:23 +01:00
if !reflect.DeepEqual(expected, found) {
return fmt.Errorf("Expected:\n%#v\nFound:\n%#v", expected, found)
return nil
const testAccFWRuleV1_basic_1 = `
resource "openstack_fw_rule_v1" "rule_1" {
name = "rule_1"
protocol = "udp"
action = "deny"
2015-02-05 13:49:23 +01:00
const testAccFWRuleV1_basic_2 = `
resource "openstack_fw_rule_v1" "rule_1" {
name = "rule_1"
2015-02-05 13:49:23 +01:00
description = "Terraform accept test"
protocol = "udp"
action = "deny"
2015-02-05 13:49:23 +01:00
ip_version = 4
source_ip_address = ""
destination_ip_address = ""
source_port = "444"
destination_port = "555"
enabled = true
const testAccFWRuleV1_basic_3 = `
resource "openstack_fw_rule_v1" "rule_1" {
name = "rule_1"
2015-02-05 13:49:23 +01:00
description = "Terraform accept test updated"
protocol = "tcp"
action = "allow"
2015-02-05 13:49:23 +01:00
ip_version = 4
source_ip_address = ""
destination_ip_address = ""
source_port = "666"
destination_port = "777"
enabled = false
const testAccFWRuleV1_anyProtocol = `
resource "openstack_fw_rule_v1" "rule_1" {
name = "rule_1"
description = "Allow any protocol"
protocol = "any"
action = "allow"
ip_version = 4
source_ip_address = ""
enabled = true