2018-08-21 21:12:46 +00:00
|
|
|
// ----------------------------------------------------------------------------
|
|
|
|
//
|
|
|
|
// *** AUTO GENERATED CODE *** AUTO GENERATED CODE ***
|
|
|
|
//
|
|
|
|
// ----------------------------------------------------------------------------
|
|
|
|
//
|
|
|
|
// This file is automatically generated by Magic Modules and manual
|
|
|
|
// changes will be clobbered when the file is regenerated.
|
|
|
|
//
|
|
|
|
// Please read more about how to change this file in
|
|
|
|
// .github/CONTRIBUTING.md.
|
|
|
|
//
|
|
|
|
// ----------------------------------------------------------------------------
|
|
|
|
|
2014-08-26 05:09:38 +00:00
|
|
|
package google
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
"fmt"
|
2018-08-21 21:12:46 +00:00
|
|
|
"log"
|
|
|
|
"reflect"
|
2014-08-26 05:09:38 +00:00
|
|
|
"sort"
|
2018-08-21 21:12:46 +00:00
|
|
|
"strconv"
|
|
|
|
"time"
|
2014-08-26 05:09:38 +00:00
|
|
|
|
|
|
|
"github.com/hashicorp/terraform/helper/hashcode"
|
|
|
|
"github.com/hashicorp/terraform/helper/schema"
|
2017-08-08 20:28:49 +00:00
|
|
|
"github.com/hashicorp/terraform/helper/validation"
|
2018-08-21 21:12:46 +00:00
|
|
|
compute "google.golang.org/api/compute/v1"
|
2014-08-26 05:09:38 +00:00
|
|
|
)
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
func resourceComputeFirewallRuleHash(v interface{}) int {
|
|
|
|
var buf bytes.Buffer
|
|
|
|
m := v.(map[string]interface{})
|
|
|
|
buf.WriteString(fmt.Sprintf("%s-", m["protocol"].(string)))
|
|
|
|
|
|
|
|
// We need to make sure to sort the strings below so that we always
|
|
|
|
// generate the same hash code no matter what is in the set.
|
|
|
|
if v, ok := m["ports"]; ok {
|
|
|
|
s := convertStringArr(v.([]interface{}))
|
|
|
|
sort.Strings(s)
|
|
|
|
|
|
|
|
for _, v := range s {
|
|
|
|
buf.WriteString(fmt.Sprintf("%s-", v))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return hashcode.String(buf.String())
|
|
|
|
}
|
|
|
|
|
2014-08-26 05:09:38 +00:00
|
|
|
func resourceComputeFirewall() *schema.Resource {
|
|
|
|
return &schema.Resource{
|
|
|
|
Create: resourceComputeFirewallCreate,
|
|
|
|
Read: resourceComputeFirewallRead,
|
2014-08-26 19:50:08 +00:00
|
|
|
Update: resourceComputeFirewallUpdate,
|
2014-08-26 05:09:38 +00:00
|
|
|
Delete: resourceComputeFirewallDelete,
|
2018-08-21 21:12:46 +00:00
|
|
|
|
2016-08-04 20:51:29 +00:00
|
|
|
Importer: &schema.ResourceImporter{
|
2018-08-21 21:12:46 +00:00
|
|
|
State: resourceComputeFirewallImport,
|
|
|
|
},
|
|
|
|
|
|
|
|
Timeouts: &schema.ResourceTimeout{
|
|
|
|
Create: schema.DefaultTimeout(240 * time.Second),
|
|
|
|
Update: schema.DefaultTimeout(240 * time.Second),
|
|
|
|
Delete: schema.DefaultTimeout(240 * time.Second),
|
2016-08-04 20:51:29 +00:00
|
|
|
},
|
2018-12-13 01:28:44 +00:00
|
|
|
|
2016-08-04 20:51:29 +00:00
|
|
|
SchemaVersion: 1,
|
2016-08-22 17:24:29 +00:00
|
|
|
MigrateState: resourceComputeFirewallMigrateState,
|
2014-08-26 05:09:38 +00:00
|
|
|
|
|
|
|
Schema: map[string]*schema.Schema{
|
2016-08-22 17:27:36 +00:00
|
|
|
"name": {
|
2018-08-21 21:12:46 +00:00
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
ForceNew: true,
|
|
|
|
ValidateFunc: validateGCPName,
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"network": {
|
2017-09-28 19:02:39 +00:00
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
DiffSuppressFunc: compareSelfLinkOrResourceName,
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"allow": {
|
2018-08-21 21:12:46 +00:00
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
2014-08-26 05:09:38 +00:00
|
|
|
Elem: &schema.Resource{
|
|
|
|
Schema: map[string]*schema.Schema{
|
2016-08-22 17:27:36 +00:00
|
|
|
"protocol": {
|
2014-08-26 05:09:38 +00:00
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"ports": {
|
2016-08-04 20:51:29 +00:00
|
|
|
Type: schema.TypeList,
|
2014-08-26 05:09:38 +00:00
|
|
|
Optional: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
Set: resourceComputeFirewallRuleHash,
|
|
|
|
ConflictsWith: []string{"deny"},
|
2017-08-07 20:14:35 +00:00
|
|
|
},
|
|
|
|
"deny": {
|
2018-08-21 21:12:46 +00:00
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
2017-08-07 20:14:35 +00:00
|
|
|
Elem: &schema.Resource{
|
|
|
|
Schema: map[string]*schema.Schema{
|
|
|
|
"protocol": {
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Required: true,
|
|
|
|
},
|
|
|
|
"ports": {
|
|
|
|
Type: schema.TypeList,
|
|
|
|
Optional: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2017-08-07 20:14:35 +00:00
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
Set: resourceComputeFirewallRuleHash,
|
|
|
|
ConflictsWith: []string{"allow"},
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"description": {
|
2016-04-10 21:34:15 +00:00
|
|
|
Type: schema.TypeString,
|
|
|
|
Optional: true,
|
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"destination_ranges": {
|
|
|
|
Type: schema.TypeSet,
|
|
|
|
Computed: true,
|
|
|
|
Optional: true,
|
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
|
|
|
Set: schema.HashString,
|
|
|
|
ConflictsWith: []string{"source_ranges", "source_tags"},
|
|
|
|
},
|
2017-08-08 20:28:49 +00:00
|
|
|
"direction": {
|
|
|
|
Type: schema.TypeString,
|
2017-12-20 21:14:33 +00:00
|
|
|
Computed: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Optional: true,
|
|
|
|
ValidateFunc: validation.StringInSlice([]string{"INGRESS", "EGRESS", ""}, false),
|
2017-08-08 20:28:49 +00:00
|
|
|
},
|
2018-05-29 20:27:29 +00:00
|
|
|
"disabled": {
|
|
|
|
Type: schema.TypeBool,
|
|
|
|
Optional: true,
|
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"priority": {
|
|
|
|
Type: schema.TypeInt,
|
|
|
|
Optional: true,
|
|
|
|
ValidateFunc: validation.IntBetween(0, 65535),
|
|
|
|
Default: 1000,
|
2016-04-10 21:34:15 +00:00
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"source_ranges": {
|
|
|
|
Type: schema.TypeSet,
|
2016-04-10 21:34:15 +00:00
|
|
|
Computed: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Optional: true,
|
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2018-12-04 19:23:38 +00:00
|
|
|
Set: schema.HashString,
|
|
|
|
ConflictsWith: []string{"destination_ranges"},
|
2016-04-10 21:34:15 +00:00
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"source_service_accounts": {
|
2014-08-26 05:09:38 +00:00
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
MaxItems: 1,
|
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
|
|
|
Set: schema.HashString,
|
|
|
|
ConflictsWith: []string{"source_tags", "target_tags"},
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"source_tags": {
|
2014-08-26 05:09:38 +00:00
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2018-12-04 19:23:38 +00:00
|
|
|
Set: schema.HashString,
|
|
|
|
ConflictsWith: []string{"destination_ranges", "source_service_accounts", "target_service_accounts"},
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"target_service_accounts": {
|
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
|
|
|
MaxItems: 1,
|
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2017-08-08 20:28:49 +00:00
|
|
|
Set: schema.HashString,
|
2018-08-21 21:12:46 +00:00
|
|
|
ConflictsWith: []string{"source_tags", "target_tags"},
|
2017-08-08 20:28:49 +00:00
|
|
|
},
|
2016-08-22 17:27:36 +00:00
|
|
|
"target_tags": {
|
2014-09-26 05:15:31 +00:00
|
|
|
Type: schema.TypeSet,
|
|
|
|
Optional: true,
|
2018-08-21 21:12:46 +00:00
|
|
|
Elem: &schema.Schema{
|
|
|
|
Type: schema.TypeString,
|
|
|
|
},
|
2018-12-04 19:23:38 +00:00
|
|
|
Set: schema.HashString,
|
|
|
|
ConflictsWith: []string{"source_service_accounts", "target_service_accounts"},
|
2014-09-26 05:15:31 +00:00
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"creation_timestamp": {
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Computed: true,
|
2017-11-06 17:34:48 +00:00
|
|
|
},
|
2018-08-21 21:12:46 +00:00
|
|
|
"project": {
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Optional: true,
|
|
|
|
Computed: true,
|
|
|
|
ForceNew: true,
|
|
|
|
},
|
|
|
|
"self_link": {
|
|
|
|
Type: schema.TypeString,
|
|
|
|
Computed: true,
|
2017-11-06 17:34:48 +00:00
|
|
|
},
|
2014-08-26 05:09:38 +00:00
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func resourceComputeFirewallCreate(d *schema.ResourceData, meta interface{}) error {
|
|
|
|
config := meta.(*Config)
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
obj := make(map[string]interface{})
|
|
|
|
allowedProp, err := expandComputeFirewallAllow(d.Get("allow"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("allow"); !isEmptyValue(reflect.ValueOf(allowedProp)) && (ok || !reflect.DeepEqual(v, allowedProp)) {
|
|
|
|
obj["allowed"] = allowedProp
|
|
|
|
}
|
|
|
|
deniedProp, err := expandComputeFirewallDeny(d.Get("deny"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("deny"); !isEmptyValue(reflect.ValueOf(deniedProp)) && (ok || !reflect.DeepEqual(v, deniedProp)) {
|
|
|
|
obj["denied"] = deniedProp
|
|
|
|
}
|
|
|
|
descriptionProp, err := expandComputeFirewallDescription(d.Get("description"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("description"); !isEmptyValue(reflect.ValueOf(descriptionProp)) && (ok || !reflect.DeepEqual(v, descriptionProp)) {
|
|
|
|
obj["description"] = descriptionProp
|
|
|
|
}
|
|
|
|
destinationRangesProp, err := expandComputeFirewallDestinationRanges(d.Get("destination_ranges"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("destination_ranges"); !isEmptyValue(reflect.ValueOf(destinationRangesProp)) && (ok || !reflect.DeepEqual(v, destinationRangesProp)) {
|
|
|
|
obj["destinationRanges"] = destinationRangesProp
|
|
|
|
}
|
|
|
|
directionProp, err := expandComputeFirewallDirection(d.Get("direction"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("direction"); !isEmptyValue(reflect.ValueOf(directionProp)) && (ok || !reflect.DeepEqual(v, directionProp)) {
|
|
|
|
obj["direction"] = directionProp
|
|
|
|
}
|
|
|
|
disabledProp, err := expandComputeFirewallDisabled(d.Get("disabled"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("disabled"); ok || !reflect.DeepEqual(v, disabledProp) {
|
|
|
|
obj["disabled"] = disabledProp
|
|
|
|
}
|
|
|
|
nameProp, err := expandComputeFirewallName(d.Get("name"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("name"); !isEmptyValue(reflect.ValueOf(nameProp)) && (ok || !reflect.DeepEqual(v, nameProp)) {
|
|
|
|
obj["name"] = nameProp
|
|
|
|
}
|
|
|
|
networkProp, err := expandComputeFirewallNetwork(d.Get("network"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("network"); !isEmptyValue(reflect.ValueOf(networkProp)) && (ok || !reflect.DeepEqual(v, networkProp)) {
|
|
|
|
obj["network"] = networkProp
|
|
|
|
}
|
|
|
|
priorityProp, err := expandComputeFirewallPriority(d.Get("priority"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("priority"); !isEmptyValue(reflect.ValueOf(priorityProp)) && (ok || !reflect.DeepEqual(v, priorityProp)) {
|
|
|
|
obj["priority"] = priorityProp
|
|
|
|
}
|
|
|
|
sourceRangesProp, err := expandComputeFirewallSourceRanges(d.Get("source_ranges"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_ranges"); !isEmptyValue(reflect.ValueOf(sourceRangesProp)) && (ok || !reflect.DeepEqual(v, sourceRangesProp)) {
|
|
|
|
obj["sourceRanges"] = sourceRangesProp
|
|
|
|
}
|
|
|
|
sourceServiceAccountsProp, err := expandComputeFirewallSourceServiceAccounts(d.Get("source_service_accounts"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_service_accounts"); !isEmptyValue(reflect.ValueOf(sourceServiceAccountsProp)) && (ok || !reflect.DeepEqual(v, sourceServiceAccountsProp)) {
|
|
|
|
obj["sourceServiceAccounts"] = sourceServiceAccountsProp
|
|
|
|
}
|
|
|
|
sourceTagsProp, err := expandComputeFirewallSourceTags(d.Get("source_tags"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_tags"); !isEmptyValue(reflect.ValueOf(sourceTagsProp)) && (ok || !reflect.DeepEqual(v, sourceTagsProp)) {
|
|
|
|
obj["sourceTags"] = sourceTagsProp
|
|
|
|
}
|
|
|
|
targetServiceAccountsProp, err := expandComputeFirewallTargetServiceAccounts(d.Get("target_service_accounts"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("target_service_accounts"); !isEmptyValue(reflect.ValueOf(targetServiceAccountsProp)) && (ok || !reflect.DeepEqual(v, targetServiceAccountsProp)) {
|
|
|
|
obj["targetServiceAccounts"] = targetServiceAccountsProp
|
|
|
|
}
|
|
|
|
targetTagsProp, err := expandComputeFirewallTargetTags(d.Get("target_tags"), d, config)
|
2016-04-10 16:59:57 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
2018-08-21 21:12:46 +00:00
|
|
|
} else if v, ok := d.GetOkExists("target_tags"); !isEmptyValue(reflect.ValueOf(targetTagsProp)) && (ok || !reflect.DeepEqual(v, targetTagsProp)) {
|
|
|
|
obj["targetTags"] = targetTagsProp
|
2016-04-10 16:59:57 +00:00
|
|
|
}
|
|
|
|
|
2018-10-12 16:55:14 +00:00
|
|
|
url, err := replaceVars(d, config, "https://www.googleapis.com/compute/v1/projects/{{project}}/global/firewalls")
|
2014-08-26 05:09:38 +00:00
|
|
|
if err != nil {
|
2014-08-26 19:50:08 +00:00
|
|
|
return err
|
2014-08-26 05:09:38 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
log.Printf("[DEBUG] Creating new Firewall: %#v", obj)
|
2018-12-13 01:28:44 +00:00
|
|
|
res, err := sendRequestWithTimeout(config, "POST", url, obj, d.Timeout(schema.TimeoutCreate))
|
2018-05-09 18:24:40 +00:00
|
|
|
if err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error creating Firewall: %s", err)
|
2014-08-26 05:09:38 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
// Store the ID now
|
|
|
|
id, err := replaceVars(d, config, "{{name}}")
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("Error constructing id: %s", err)
|
|
|
|
}
|
|
|
|
d.SetId(id)
|
2014-08-26 05:09:38 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
project, err := getProject(d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
op := &compute.Operation{}
|
|
|
|
err = Convert(res, op)
|
2014-08-26 05:44:27 +00:00
|
|
|
if err != nil {
|
2015-09-24 20:30:12 +00:00
|
|
|
return err
|
2014-08-26 05:44:27 +00:00
|
|
|
}
|
2014-08-26 05:09:38 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
waitErr := computeOperationWaitTime(
|
|
|
|
config.clientCompute, op, project, "Creating Firewall",
|
|
|
|
int(d.Timeout(schema.TimeoutCreate).Minutes()))
|
2016-08-04 20:51:29 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
if waitErr != nil {
|
|
|
|
// The resource didn't actually create
|
|
|
|
d.SetId("")
|
|
|
|
return fmt.Errorf("Error waiting to create Firewall: %s", waitErr)
|
2016-08-04 20:51:29 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
log.Printf("[DEBUG] Finished creating Firewall %q: %#v", d.Id(), res)
|
2017-08-07 20:14:35 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
return resourceComputeFirewallRead(d, meta)
|
2017-08-07 20:14:35 +00:00
|
|
|
}
|
|
|
|
|
2014-08-26 05:09:38 +00:00
|
|
|
func resourceComputeFirewallRead(d *schema.ResourceData, meta interface{}) error {
|
|
|
|
config := meta.(*Config)
|
|
|
|
|
2018-10-12 16:55:14 +00:00
|
|
|
url, err := replaceVars(d, config, "https://www.googleapis.com/compute/v1/projects/{{project}}/global/firewalls/{{name}}")
|
2016-04-10 16:59:57 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
res, err := sendRequest(config, "GET", url, nil)
|
2018-05-09 18:24:40 +00:00
|
|
|
if err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return handleNotFoundError(err, d, fmt.Sprintf("ComputeFirewall %q", d.Id()))
|
|
|
|
}
|
|
|
|
|
2018-11-20 20:31:26 +00:00
|
|
|
project, err := getProject(d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if err := d.Set("project", project); err != nil {
|
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("allow", flattenComputeFirewallAllow(res["allowed"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("creation_timestamp", flattenComputeFirewallCreationTimestamp(res["creationTimestamp"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("deny", flattenComputeFirewallDeny(res["denied"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("description", flattenComputeFirewallDescription(res["description"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("destination_ranges", flattenComputeFirewallDestinationRanges(res["destinationRanges"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("direction", flattenComputeFirewallDirection(res["direction"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("disabled", flattenComputeFirewallDisabled(res["disabled"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("name", flattenComputeFirewallName(res["name"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("network", flattenComputeFirewallNetwork(res["network"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("priority", flattenComputeFirewallPriority(res["priority"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("source_ranges", flattenComputeFirewallSourceRanges(res["sourceRanges"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("source_service_accounts", flattenComputeFirewallSourceServiceAccounts(res["sourceServiceAccounts"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("source_tags", flattenComputeFirewallSourceTags(res["sourceTags"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("target_service_accounts", flattenComputeFirewallTargetServiceAccounts(res["targetServiceAccounts"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
if err := d.Set("target_tags", flattenComputeFirewallTargetTags(res["targetTags"], d)); err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
|
|
|
if err := d.Set("self_link", ConvertSelfLinkToV1(res["selfLink"].(string))); err != nil {
|
|
|
|
return fmt.Errorf("Error reading Firewall: %s", err)
|
|
|
|
}
|
2014-08-26 05:09:38 +00:00
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2014-08-26 19:50:08 +00:00
|
|
|
func resourceComputeFirewallUpdate(d *schema.ResourceData, meta interface{}) error {
|
|
|
|
config := meta.(*Config)
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
obj := make(map[string]interface{})
|
|
|
|
allowedProp, err := expandComputeFirewallAllow(d.Get("allow"), d, config)
|
2016-04-10 16:59:57 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
2018-08-21 21:12:46 +00:00
|
|
|
} else if v, ok := d.GetOkExists("allow"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, allowedProp)) {
|
|
|
|
obj["allowed"] = allowedProp
|
|
|
|
}
|
|
|
|
deniedProp, err := expandComputeFirewallDeny(d.Get("deny"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("deny"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, deniedProp)) {
|
|
|
|
obj["denied"] = deniedProp
|
|
|
|
}
|
|
|
|
descriptionProp, err := expandComputeFirewallDescription(d.Get("description"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("description"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, descriptionProp)) {
|
|
|
|
obj["description"] = descriptionProp
|
|
|
|
}
|
|
|
|
destinationRangesProp, err := expandComputeFirewallDestinationRanges(d.Get("destination_ranges"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("destination_ranges"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, destinationRangesProp)) {
|
|
|
|
obj["destinationRanges"] = destinationRangesProp
|
|
|
|
}
|
|
|
|
directionProp, err := expandComputeFirewallDirection(d.Get("direction"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("direction"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, directionProp)) {
|
|
|
|
obj["direction"] = directionProp
|
|
|
|
}
|
|
|
|
disabledProp, err := expandComputeFirewallDisabled(d.Get("disabled"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("disabled"); ok || !reflect.DeepEqual(v, disabledProp) {
|
|
|
|
obj["disabled"] = disabledProp
|
|
|
|
}
|
|
|
|
networkProp, err := expandComputeFirewallNetwork(d.Get("network"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("network"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, networkProp)) {
|
|
|
|
obj["network"] = networkProp
|
|
|
|
}
|
|
|
|
priorityProp, err := expandComputeFirewallPriority(d.Get("priority"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("priority"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, priorityProp)) {
|
|
|
|
obj["priority"] = priorityProp
|
|
|
|
}
|
|
|
|
sourceRangesProp, err := expandComputeFirewallSourceRanges(d.Get("source_ranges"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_ranges"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, sourceRangesProp)) {
|
|
|
|
obj["sourceRanges"] = sourceRangesProp
|
|
|
|
}
|
|
|
|
sourceServiceAccountsProp, err := expandComputeFirewallSourceServiceAccounts(d.Get("source_service_accounts"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_service_accounts"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, sourceServiceAccountsProp)) {
|
|
|
|
obj["sourceServiceAccounts"] = sourceServiceAccountsProp
|
|
|
|
}
|
|
|
|
sourceTagsProp, err := expandComputeFirewallSourceTags(d.Get("source_tags"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("source_tags"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, sourceTagsProp)) {
|
|
|
|
obj["sourceTags"] = sourceTagsProp
|
|
|
|
}
|
|
|
|
targetServiceAccountsProp, err := expandComputeFirewallTargetServiceAccounts(d.Get("target_service_accounts"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("target_service_accounts"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, targetServiceAccountsProp)) {
|
|
|
|
obj["targetServiceAccounts"] = targetServiceAccountsProp
|
|
|
|
}
|
|
|
|
targetTagsProp, err := expandComputeFirewallTargetTags(d.Get("target_tags"), d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
} else if v, ok := d.GetOkExists("target_tags"); !isEmptyValue(reflect.ValueOf(v)) && (ok || !reflect.DeepEqual(v, targetTagsProp)) {
|
|
|
|
obj["targetTags"] = targetTagsProp
|
2016-04-10 16:59:57 +00:00
|
|
|
}
|
|
|
|
|
2018-10-12 16:55:14 +00:00
|
|
|
url, err := replaceVars(d, config, "https://www.googleapis.com/compute/v1/projects/{{project}}/global/firewalls/{{name}}")
|
2014-08-26 19:50:08 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
log.Printf("[DEBUG] Updating Firewall %q: %#v", d.Id(), obj)
|
2018-12-13 01:28:44 +00:00
|
|
|
res, err := sendRequestWithTimeout(config, "PATCH", url, obj, d.Timeout(schema.TimeoutUpdate))
|
2018-08-21 21:12:46 +00:00
|
|
|
|
2018-05-09 18:24:40 +00:00
|
|
|
if err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return fmt.Errorf("Error updating Firewall %q: %s", d.Id(), err)
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
project, err := getProject(d, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
op := &compute.Operation{}
|
|
|
|
err = Convert(res, op)
|
2014-08-26 19:50:08 +00:00
|
|
|
if err != nil {
|
2015-09-24 20:30:12 +00:00
|
|
|
return err
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
err = computeOperationWaitTime(
|
|
|
|
config.clientCompute, op, project, "Updating Firewall",
|
|
|
|
int(d.Timeout(schema.TimeoutUpdate).Minutes()))
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2014-08-27 03:33:53 +00:00
|
|
|
|
2014-08-26 19:50:08 +00:00
|
|
|
return resourceComputeFirewallRead(d, meta)
|
|
|
|
}
|
|
|
|
|
2014-08-26 05:09:38 +00:00
|
|
|
func resourceComputeFirewallDelete(d *schema.ResourceData, meta interface{}) error {
|
|
|
|
config := meta.(*Config)
|
|
|
|
|
2018-10-12 16:55:14 +00:00
|
|
|
url, err := replaceVars(d, config, "https://www.googleapis.com/compute/v1/projects/{{project}}/global/firewalls/{{name}}")
|
2016-04-10 16:59:57 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
var obj map[string]interface{}
|
|
|
|
log.Printf("[DEBUG] Deleting Firewall %q", d.Id())
|
2018-12-13 01:28:44 +00:00
|
|
|
res, err := sendRequestWithTimeout(config, "DELETE", url, obj, d.Timeout(schema.TimeoutDelete))
|
2018-05-09 18:24:40 +00:00
|
|
|
if err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return handleNotFoundError(err, d, "Firewall")
|
2014-08-26 05:09:38 +00:00
|
|
|
}
|
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
project, err := getProject(d, config)
|
2014-08-26 05:44:27 +00:00
|
|
|
if err != nil {
|
2015-09-24 20:30:12 +00:00
|
|
|
return err
|
2014-08-26 05:44:27 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
op := &compute.Operation{}
|
|
|
|
err = Convert(res, op)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
err = computeOperationWaitTime(
|
|
|
|
config.clientCompute, op, project, "Deleting Firewall",
|
|
|
|
int(d.Timeout(schema.TimeoutDelete).Minutes()))
|
2014-08-26 05:09:38 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Printf("[DEBUG] Finished deleting Firewall %q: %#v", d.Id(), res)
|
2014-08-26 05:09:38 +00:00
|
|
|
return nil
|
|
|
|
}
|
2014-08-26 19:50:08 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
func resourceComputeFirewallImport(d *schema.ResourceData, meta interface{}) ([]*schema.ResourceData, error) {
|
2014-08-26 19:50:08 +00:00
|
|
|
config := meta.(*Config)
|
2018-08-21 21:12:46 +00:00
|
|
|
parseImportId([]string{"projects/(?P<project>[^/]+)/global/firewalls/(?P<name>[^/]+)", "(?P<project>[^/]+)/(?P<name>[^/]+)", "(?P<name>[^/]+)"}, d, config)
|
2014-08-26 19:50:08 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
// Replace import id for the resource id
|
|
|
|
id, err := replaceVars(d, config, "{{name}}")
|
2017-10-10 16:53:57 +00:00
|
|
|
if err != nil {
|
2018-08-21 21:12:46 +00:00
|
|
|
return nil, fmt.Errorf("Error constructing id: %s", err)
|
2017-10-10 16:53:57 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
d.SetId(id)
|
2017-10-10 16:53:57 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
return []*schema.ResourceData{d}, nil
|
|
|
|
}
|
2017-08-07 20:14:35 +00:00
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallAllow(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
2017-08-07 20:14:35 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
l := v.([]interface{})
|
|
|
|
transformed := make([]interface{}, 0, len(l))
|
|
|
|
for _, raw := range l {
|
|
|
|
original := raw.(map[string]interface{})
|
2018-11-16 20:45:58 +00:00
|
|
|
if len(original) < 1 {
|
|
|
|
// Do not include empty json objects coming back from the api
|
|
|
|
continue
|
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
transformed = append(transformed, map[string]interface{}{
|
2018-11-21 21:57:16 +00:00
|
|
|
"protocol": flattenComputeFirewallAllowProtocol(original["IPProtocol"], d),
|
|
|
|
"ports": flattenComputeFirewallAllowPorts(original["ports"], d),
|
2018-08-21 21:12:46 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
return transformed
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallAllowProtocol(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
2017-08-07 20:14:35 +00:00
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallAllowPorts(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
2014-08-26 19:50:08 +00:00
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallCreationTimestamp(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDeny(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
l := v.([]interface{})
|
|
|
|
transformed := make([]interface{}, 0, len(l))
|
|
|
|
for _, raw := range l {
|
|
|
|
original := raw.(map[string]interface{})
|
2018-11-16 20:45:58 +00:00
|
|
|
if len(original) < 1 {
|
|
|
|
// Do not include empty json objects coming back from the api
|
|
|
|
continue
|
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
transformed = append(transformed, map[string]interface{}{
|
2018-11-21 21:57:16 +00:00
|
|
|
"protocol": flattenComputeFirewallDenyProtocol(original["IPProtocol"], d),
|
|
|
|
"ports": flattenComputeFirewallDenyPorts(original["ports"], d),
|
2018-08-21 21:12:46 +00:00
|
|
|
})
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
return transformed
|
|
|
|
}
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDenyProtocol(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
2014-08-26 19:50:08 +00:00
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDenyPorts(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDescription(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDestinationRanges(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDirection(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallDisabled(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallName(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallNetwork(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
return ConvertSelfLinkToV1(v.(string))
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallPriority(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
// Handles the string fixed64 format
|
|
|
|
if strVal, ok := v.(string); ok {
|
|
|
|
if intVal, err := strconv.ParseInt(strVal, 10, 64); err == nil {
|
|
|
|
return intVal
|
|
|
|
} // let terraform core handle it if we can't convert the string to an int.
|
|
|
|
}
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallSourceRanges(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallSourceServiceAccounts(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallSourceTags(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallTargetServiceAccounts(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
2014-08-26 19:50:08 +00:00
|
|
|
|
2018-11-21 21:57:16 +00:00
|
|
|
func flattenComputeFirewallTargetTags(v interface{}, d *schema.ResourceData) interface{} {
|
2018-08-21 21:12:46 +00:00
|
|
|
if v == nil {
|
|
|
|
return v
|
|
|
|
}
|
|
|
|
return schema.NewSet(schema.HashString, v.([]interface{}))
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallAllow(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
l := v.([]interface{})
|
|
|
|
req := make([]interface{}, 0, len(l))
|
|
|
|
for _, raw := range l {
|
2018-10-03 22:51:49 +00:00
|
|
|
if raw == nil {
|
|
|
|
continue
|
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
original := raw.(map[string]interface{})
|
|
|
|
transformed := make(map[string]interface{})
|
|
|
|
|
|
|
|
transformedProtocol, err := expandComputeFirewallAllowProtocol(original["protocol"], d, config)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2018-09-28 16:47:20 +00:00
|
|
|
} else if val := reflect.ValueOf(transformedProtocol); val.IsValid() && !isEmptyValue(val) {
|
|
|
|
transformed["IPProtocol"] = transformedProtocol
|
2018-08-21 21:12:46 +00:00
|
|
|
}
|
2018-09-28 16:47:20 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
transformedPorts, err := expandComputeFirewallAllowPorts(original["ports"], d, config)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2018-09-28 16:47:20 +00:00
|
|
|
} else if val := reflect.ValueOf(transformedPorts); val.IsValid() && !isEmptyValue(val) {
|
|
|
|
transformed["ports"] = transformedPorts
|
2017-08-08 20:28:49 +00:00
|
|
|
}
|
2018-09-28 16:47:20 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
req = append(req, transformed)
|
2017-08-08 20:28:49 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
return req, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallAllowProtocol(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallAllowPorts(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
2017-08-08 20:28:49 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
func expandComputeFirewallDeny(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
l := v.([]interface{})
|
|
|
|
req := make([]interface{}, 0, len(l))
|
|
|
|
for _, raw := range l {
|
2018-10-03 22:51:49 +00:00
|
|
|
if raw == nil {
|
|
|
|
continue
|
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
original := raw.(map[string]interface{})
|
|
|
|
transformed := make(map[string]interface{})
|
|
|
|
|
|
|
|
transformedProtocol, err := expandComputeFirewallDenyProtocol(original["protocol"], d, config)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2018-09-28 16:47:20 +00:00
|
|
|
} else if val := reflect.ValueOf(transformedProtocol); val.IsValid() && !isEmptyValue(val) {
|
|
|
|
transformed["IPProtocol"] = transformedProtocol
|
2014-09-26 05:15:31 +00:00
|
|
|
}
|
2018-09-28 16:47:20 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
transformedPorts, err := expandComputeFirewallDenyPorts(original["ports"], d, config)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2018-09-28 16:47:20 +00:00
|
|
|
} else if val := reflect.ValueOf(transformedPorts); val.IsValid() && !isEmptyValue(val) {
|
|
|
|
transformed["ports"] = transformedPorts
|
2018-08-21 21:12:46 +00:00
|
|
|
}
|
2018-09-28 16:47:20 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
req = append(req, transformed)
|
|
|
|
}
|
|
|
|
return req, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDenyProtocol(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDenyPorts(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDescription(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDestinationRanges(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDirection(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallDisabled(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallName(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallNetwork(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
f, err := parseGlobalFieldValue("networks", v.(string), "project", d, config, true)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("Invalid value for network: %s", err)
|
2014-09-26 05:15:31 +00:00
|
|
|
}
|
2018-08-21 21:12:46 +00:00
|
|
|
return f.RelativeLink(), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallPriority(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallSourceRanges(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallSourceServiceAccounts(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallSourceTags(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func expandComputeFirewallTargetServiceAccounts(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
|
|
|
}
|
2014-09-26 05:15:31 +00:00
|
|
|
|
2018-08-21 21:12:46 +00:00
|
|
|
func expandComputeFirewallTargetTags(v interface{}, d *schema.ResourceData, config *Config) (interface{}, error) {
|
|
|
|
v = v.(*schema.Set).List()
|
|
|
|
return v, nil
|
2014-08-26 19:50:08 +00:00
|
|
|
}
|