Conversation
mikewiebe
requested review from
akinross,
allenrobel,
anvitha-jain,
gmicol,
lhercot,
mtarking,
sajagana,
samiib and
shrsr
as code owners
August 25, 2026 03:14
mikewiebe
marked this pull request as draft
August 25, 2026 03:14
mikewiebe
marked this pull request as ready for review
August 25, 2026 14:56
mikewiebe
marked this pull request as draft
August 25, 2026 14:56
Support implicit policy transitions for merged and replaced workflows, policy-aware deletion, pair-aware vPC safety, protected-member checks, and structural collision validation. Preserve shared snapshot and bulk-provisioning scale behavior, harden switch-scoped interface summary pagination, and treat non-429 HTTP client errors as terminal to avoid deterministic retry delays.
Add guarded lifecycle, transition, deletion, deployment-control, output, validation, shared-snapshot, and property-matrix scenarios across all ten supported interface families and the selected fabric types.
Support deployment-only execution for requested pending or out-of-sync interfaces, reconcile post-write inventory, and return compact resource-scoped operations without duplicate snapshots or counters. Update unit tests, integration coverage, and module documentation for the resulting contract.
…ator # Conflicts: # plugins/module_utils/models/interfaces/svi_interface.py # plugins/module_utils/models/interfaces/vpc_access_interface.py # plugins/module_utils/models/interfaces/vpc_trunk_host_interface.py # plugins/module_utils/orchestrators/vpc_interface_base.py # tests/unit/module_utils/models/test_vpc_access_interface.py # tests/unit/module_utils/models/test_vpc_trunk_host_interface.py # tests/unit/module_utils/test_response_handler_nd.py
Add verify.enabled with a false default so successful mutations can return projected state without post-write inventory refreshes. Preserve forced reconciliation for partial and failed writes, and update module documentation, integration coverage, and unit tests for after_verified semantics.
Merge dependent address and NetFlow fields without transient validation failures. Compare workflow integration results against normalized proposed data and add regression coverage.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related Issue(s)
Resolves #456
Related safety/correlation defect: #554
Proposed Changes
cisco.nd.nd_interfaces_workCHANT, a single aggregate workflow for all eleven interface families now available ondevelop: Ethernet access, Ethernet routed, Ethernet trunk-host, loopback, port-channel access/trunk-host, managed/unmanaged subinterfaces, SVI, and vPC access/trunk-host.cisco.nd.nd_interface_flow_rulesoutside the aggregator scope.cisco.nd.nd_manage_linksalso remains outside because it manages topology links rather than a host-interface policy family.mergedandreplaced; consolidates compatible deletes and deployment requests; and keepsverify.enabled=falseas the scale-oriented default.deletedpolicy-independent within the selected structural family. Logical interfaces are deleted. Physical NX-OS Ethernet interfaces reset to defaulttrunkHost; IOS-XE routed ports retainiosXeRoutedHostwith defaults-only policy data.deploy=true, deploys only targets backed by exact controller-success evidence; failed, uncertain, unattempted, and supplemental replay targets are excluded.Develop Reconciliation
Merged
developthrough49d3d697713f939f4af3118f76ac75cf5f55066eand retained both feature sets from:FabricContext, retained switch records, platform lookup, and shared sync-state lookup.config_actions_spec()andapply_config_actions().nd_manage_linksplus gathered/prepared-config/secret/unsupported-policy framework behavior.The four content conflicts and nine semantic overlap files were reconciled without discarding either the aggregator behavior or the merged
developbehavior.Why
manage_vpc_pair/resources.pychangesVpcPairStateMachinealready had a private_manage_override_deletions(override_exceptions)helper ondevelop. The sharedNDStateMachinealso had a same-named method. The interface-aggregator planning refactor changed the shared method to accept an optionalNDStatePlan, allowing a plan calculated before mutation to be reused during execution.That signature change exposed the pre-existing name collision as a pylint
arguments-renamedfailure: the shared method expects a state plan, while the vPC helper expects identifiers to retain. The specialized vPC helper and its sole caller are therefore renamed to_manage_vpc_override_deletions(override_exceptions). This is behavior-preserving; a focused regression verifies override exceptions remain while other stale vPC pairs are deleted.Test Notes
Local validation against the repaired branch head:
4,872 passed.563tracked Python files unchanged.562Python files passed.49files passed.git diff --check: passed.1,031Git-visible files.ansible-test sanity --docker --python 3.11 -v --color --truncate 0: exit0; ansible-doc, compile/import, pep8, pylint, validate-modules, yamllint, and the remaining sanity targets passed.0; private context, Git metadata, caches, bytecode, and test output were absent from the archive.0, zero errors; only the four repository-accepted Ansible 2.16–2.19 sanity-ignore warnings.145tasks passed,0failed,0unreachable; all eleven family files were included, withmutations_sent=0anddeployments_sent=0.Live mutation/idempotency was not run because the shared-lab global ownership gate detected an unrelated controller/registry identity mismatch and a prior stop marker remains. No testbed mutations or deployments were issued. Mutation qualification must remain pending until a fresh global ownership audit passes.
Cisco Nexus Dashboard Version
The workflow continues to use the existing per-interface mutation paths supported by the underlying standalone modules. No ND 4.3.1-only bulk-modify dependency is introduced by this repair.
Related ND API Resource Category
Checklist
developwith merge conflicts resolved