Files
VPNaaS-Migrator/ipsec_migrator/__pycache__/sync.cpython-311.pyc
T

100 lines
18 KiB
Plaintext
Raw Normal View History

2026-07-21 15:05:52 +03:00
§
É_jž6ãó¢dZddlmZddlZddlmZddlmZddlm Z ddl
m Z dd l m
Z
d#d Zd#d
Zd$dZd%dZd&dZd'dZd(dZd)dZd*d"„ZdS)+a¶STAGE 2-4: collecting existing Sprut objects, comparing/creating missing
IKE/IPsec policies, endpoint groups and VPN services, and finally creating
IPsec site connections.
STAGE 3's four compare_and_create_* functions each return a
neutron_id -> sprut_id correspondence dict (replacing the bash originals'
`declare -A neutron_to_sprut_*` globals). STAGE 4 looks these up by the
raw connection's referenced IDs to build its request body.
é)Ú annotationsNé)Úaudit)ÚMigrationState)Ú
redact_psk)Ú SprutClient)Úprint_kv_tableÚreturnÚstrcó.tj|d¬¦«S))Úindent)ÚjsonÚdumps)Úobjs ú+/root/vkcloud/vpnaas/ipsec_migrator/sync.pyÚ_dumprsÝ Œ:c  có^|dSt|t¦«r|rdndSt|¦«S)a3Mirrors `jq -r`: a JSON null stringifies to the 4-char string "null"
(not Python None/absence), a JSON boolean stringifies to lowercase
"true"/"false" (not Python's "True"/"False" -- confirmed against a real
tenant, where Neutron's ipsec site connection ".State" is a genuine JSON
boolean), everything else via str(). STAGE 4's request body in the bash
original is built entirely with `jq -n --arg`, which means every field
-- even ones that look numeric/boolean -- is sent to Sprut as a JSON
string. Do not "fix" this to native types.NÚnullÚtrueÚfalse)Ú
isinstanceÚboolr )Úvalues rÚ _jq_r_strrs;ð
€}؈vÝ%ÑÔðÐ+ˆvˆv GÐ ˆu‰:Œ:ÐrÚ sprut_clientrÚdictcóÎtd¦«| d¦«}td¦«tt|¦«¦«t¦«td¦«| d¦«}td¦«tt|¦«¦«t¦«td¦«| d¦«}td ¦«tt|¦«¦«t¦«td
¦«| d ¦«}td ¦«tt|¦«¦«t¦«td
¦«| d¦«}td¦«ttt|¦«¦«¦«t¦«|||||dœS)Nz%Collecting IKE policies from Sprut...ú/vpn/ikepolicieszIKE policies collected:z'Collecting IPsec policies from Sprut...ú/vpn/ipsecpolicieszIPsec policies collected:z(Collecting Endpoint Groups from Sprut...ú/vpn/endpoint-groupszEndpoint Groups collected:z%Collecting VPN services from Sprut...ú/vpn/vpnserviceszVPN services collected:z/Collecting IPsec site connections from Sprut...ú/vpn/ipsec-site-connectionsz!IPsec site connections collected:)Ú ike_policiesÚipsec_policiesÚendpoint_groupsÚ vpn_servicesÚipsec_site_connections)ÚprintÚgetrr)rr%r&r'r(r)s rÚcollect_sprut_stater,-Ý Ð
×#Ð$6Ñ7€LÝ Ð
 % Ñ
Ô
ÑÔÐÝ G„G€Gå Ð
!×%Ð&:Ñ;€NÝ Ð
 %Ñ
Ô
Ñ Ô Ð Ý G„G€Gå Ð
"×&Ð'=Ñ>€OÝ Ð
 %Ñ
Ô
Ñ G„G€Gå Ð
×#Ð$6Ñ7€LÝ Ð
 % Ñ
Ô
ÑÔÐÝ G„G€Gå Ð
)×-Ð.KÑÝ Ð
 %•
Ð
 G„G€Gð$Ø"8ð  ð ðrÚstaterÚsprut_ike_policiesúdict[str, str]c ó⇠—i}|jD]b}|j|}| d¦«Š tˆ fd| dg¦«D¦«d¦«}|sót dd¦«d| d¦«| d¦«| d¦«| d ¦«| d
¦«| d ¦«| d ¦«d
œi}| d|¦«}| d¦«pi d¦«}|jr|sd|}nt dd¦«|||<Œd|S)namec3ótK|]2}| d¦«k¯| d¦«VŒ3dS©r1ÚidN©r+©Ú.0Úpr1s €rú <genexpr>z2compare_and_create_ike_policies.<locals>.<genexpr>bsCøèèÐ e˜QÈqÏuÊuÐU[É}Ì}Ð`dÒOdÐOdˆQUŠU4‰[Œ[ÐOdÐOdÐOdÐOdÐ erÚ ikepolicieszCreating IKE policy 'ú
' in SprutÚ ikepolicyÚphase1_negotiation_modeÚauth_algorithmÚencryption_algorithmÚpfsÚlifetimeÚ ike_version)r1r=r>r?r@rArBr r4úDRY-RUN-z IKE policy 'ú' already exists in Sprut)Úin_scope_ike_policy_idsÚneutron_ike_policy_by_idr+Únextr*ÚpostÚdry_run)
r-rr.ÚmappingÚ
neutron_idÚneutron_policyÚsprut_idÚ request_bodyÚresponser1s
@rÚcompare_and_create_ike_policiesrPYø€ð!€GØÔ'ˆ
ØÔ7¸
ÔCˆØ×! )ˆåØ eÐ"4×"8Ò"8¸ÈÑ"KÔ"KÐ ñ
ô
ˆð
ð BÝ Ð:¨$Ð Ø*×.¨vÑ6Ø/=×/AÒ/AÐB[Ñ/\Ô/\Ø&4×&8Ò&8Ð9IÑ&JÔ&JØ,:×,>Ò,>Ð?UÑ,VÔ,VØ)×-¨eÑ4Ø .× 2Ò 2°:Ñ >Ô >Ø#1×#5Ò#5°mÑ#DÔ#Dððð
ˆLð(Ð);¸\ÑJˆHØ Ÿ š  7°R×<¸BˆÔ
3¨Hð
2 jÐ2øå ÐÐ &ˆ
ÑÑØ €NrÚsprut_ipsec_policiesc ó⇠—i}|jD]b}|j|}| d¦«Š tˆ fd| dg¦«D¦«d¦«}|sót dd¦«d| d¦«| d¦«| d¦«| d ¦«| d
¦«| d ¦«| d ¦«d
œi}| d|¦«}| d¦«pi d¦«}|jr|sd|}nt dd¦«|||<Œd|S)Nr1c3ótK|]2}| d¦«k¯| d¦«VŒ3dSr3r5r6s €rr9z4compare_and_create_ipsec_policies.<locals>.<genexpr>‡sHøèèÐ i˜QÐST×SXÒSXÐY_ÑS`ÔS`ÐdhÒShÐShˆQUŠU4‰[Œ[ÐShÐShÐShÐShÐ irÚ
ipsecpolicieszCreating IPsec policy 'r;Ú ipsecpolicyÚtransform_protocolr>r?Úencapsulation_moder@rA)r1rVr>r?rWr@rAr!r4rCzIPsec policy 'rD)Úin_scope_ipsec_policy_idsÚneutron_ipsec_policy_by_idr+rGr*rHrI)
r-rrQrJrKrLrMrNrOr1s
@rÚ!compare_and_create_ipsec_policiesrZ~ø€ð!€GØÔ'ˆ
ØÔ9¸*ÔEˆØ×! )ˆåØ iÐ"6×":Ò":¸?ÈBÑ"OÔ"OÐ ñ
ô
ˆð
ð DÝ Ð<¨DÐ Ø*×.¨vÑ6Ø*8×*<Ò*<Ð=QÑ*RÔ*RØ&4×&8Ò&8Ð9IÑ&JÔ&JØ,:×,>Ò,>Ð?UÑ,VÔ,VØ*8×*<Ò*<Ð=QÑ*RÔ*RØ)×-¨eÑ4Ø .× 2Ò 2°:Ñ >Ô >ð ð ð
ˆLð(Ð)=¸|ÑLˆHØ Ÿ š  9°r×>¸DˆÔ
3¨Hð
2 jÐ2øå ÐB 4Ð &ˆ
ÑÑØ €NrÚsprut_endpoint_groupsc óÄ i}|jD]Ó}|j|}| d¦«}tj||j¦«Š t
dd  ¦«¦«tˆ fd| dg¦«D¦«d¦«}|r| d¦«nd}t
d|dd  ¦«¦«|r&t
d | d
¦«¦«nt
d ¦«|s t
d |d
¦«d| ddœi} t
dtj
| ¦«¦«|  d| ¦«}
|
 d¦«pi d¦«}|j r|sd|}t
d|¦«nt
d|¦«|||<t
¦«ŒÕ|S)Nr1z$Total converted UUIDs in endpoints: z, c3óNK|]}| d¦«k¯|VŒ dS)Ú endpointsNr5)r7ÚgÚ converteds €rr9z5compare_and_create_endpoint_groups.<locals>.<genexpr>¯s;øèèÐ l1ÈAÏEÊEÐR]ÑL^ÔL^ÐbkÒLkÐLkˆQÐLkÐLkÐLkÐLkÐ lrr'r4z"Comparing Neutron endpoint group 'z' with endpoints: z> -> Found corresponding Sprut endpoint group with endpoints: r^zD -> No corresponding Sprut endpoint group found for these endpointszCreating Endpoint Group 'r;Úendpoint_groupÚcidr)r1r^ÚtypezRequest body: r"rCzCreated Sprut Endpoint group: zGEndpoint Group with matching endpoints already exists in Sprut with id )
Úin_scope_endpoint_group_idsÚneutron_endpoint_group_by_idr+rÚresolve_endpoint_addressesÚsubnet_id_to_subnet_addressr*ÚjoinrGrrrHrI) r-rr[rJrKÚ
neutron_groupr1ÚmatchingrMrNrOr`s @rÚ"compare_and_create_endpoint_groupsrk£s9ø€ð!€GØÔ ñ ˆ
ØÔ:¸Fˆ
Ø× Ò  ÑåÔ4°]ÀEÔDeÑfˆ Ý
ÐK°T·Y²Y¸yÑ5IÔ5IÐØ -×1Ð2CÀRÑ ñ
ô
ˆð*2Ð;8—<< Ñ%°tˆå
Ða°4ÐaÈ4Ï9Ê9ÐU^ÑK_ÔK_Ð ð ZÝ ÐnÐS[×S_ÒS_Ð`kÑSlÔSlÐ Ð ð
hÝ Ð>¨dÐ ,°tÈ)Ð]cÐ.dÐ.dÐeˆ Ð=¥4¤:¨lÑ#;Ô#;Ð #×(Ð)?ÀÑNˆHØ Ÿ š Ð%5Ñ<¸"×AÀ$ÑGˆÔ
3¨Hð
2 jÐ2Ý Ð=°8Ð ÐfÐ\dÐ &ˆ