Skip to content

ND Interface Aggregator - #522

Draft
mikewiebe wants to merge 13 commits into
CiscoDevNet:developfrom
mikewiebe:interface_aggregator
Draft

mikewiebe wants to merge 13 commits into
CiscoDevNet:developfrom
mikewiebe:interface_aggregator

Conversation

@mikewiebe

@mikewiebe mikewiebe commented Aug 25, 2026 •

Copy link
Copy Markdown
Collaborator

Related Issue(s)

Resolves #456

Related safety/correlation defect: #554

Proposed Changes

  • Adds cisco.nd.nd_interfaces_workCHANT, a single aggregate workflow for all eleven interface families now available on develop: Ethernet access, Ethernet routed, Ethernet trunk-host, loopback, port-channel access/trunk-host, managed/unmanaged subinterfaces, SVI, and vPC access/trunk-host.
  • Keeps cisco.nd.nd_interface_flow_rules outside the aggregator scope. cisco.nd.nd_manage_links also remains outside because it manages topology links rather than a host-interface policy family.
  • Shares fabric resolution, paginated interface inventory, vPC-pair discovery, and lazy IOS-XE fabric-link discovery across resource groups to avoid redundant controller GETs.
  • Separates validation/planning from mutation; supports implicit safe policy transitions for merged and replaced; consolidates compatible deletes and deployment requests; and keeps verify.enabled=false as the scale-oriented default.
  • Makes explicit deleted policy-independent within the selected structural family. Logical interfaces are deleted. Physical NX-OS Ethernet interfaces reset to default trunkHost; IOS-XE routed ports retain iosXeRoutedHost with defaults-only policy data.
  • Rejects link-owned/system-owned Ethernet transitions and deletes during planning and repeats the check immediately before writes.
  • Adds exact request-boundary response correlation for deferred operations, resolving issue A stale HTTP 207 response can mark an unsent group as accepted. #554's stale HTTP 207 response hazard.
  • On partial mutation failure with deploy=true, deploys only targets backed by exact controller-success evidence; failed, uncertain, unattempted, and supplemental replay targets are excluded.
  • Preserves standalone interface-module models/orchestrators while keeping child deployment disabled and issuing at most one consolidated deployment request per execution path.

Develop Reconciliation

Merged develop through 49d3d697713f939f4af3118f76ac75cf5f55066e and retained both feature sets from:

The four content conflicts and nine semantic overlap files were reconciled without discarding either the aggregator behavior or the merged develop behavior.

Why manage_vpc_pair/resources.py changes

VpcPairStateMachine already had a private _manage_override_deletions(override_exceptions) helper on develop. The shared NDStateMachine also had a same-named method. The interface-aggregator planning refactor changed the shared method to accept an optional NDStatePlan, allowing a plan calculated before mutation to be reused during execution.

That signature change exposed the pre-existing name collision as a pylint arguments-renamed failure: the shared method expects a state plan, while the vPC helper expects identifiers to retain. The specialized vPC helper and its sole caller are therefore renamed to _manage_vpc_override_deletions(override_exceptions). This is behavior-preserving; a focused regression verifies override exceptions remain while other stale vPC pairs are deleted.

Test Notes

Local validation against the repaired branch head:

  • Full unit suite: 4,872 passed.
  • Black, line length 159: all 563 tracked Python files unchanged.
  • Compileall: 562 Python files passed.
  • Integration YAML safe-load: all 49 files passed.
  • git diff --check: passed.
  • Strict conflict-marker scan: no matches across 1,031 Git-visible files.
  • ansible-test sanity --docker --python 3.11 -v --color --truncate 0: exit 0; ansible-doc, compile/import, pep8, pylint, validate-modules, yamllint, and the remaining sanity targets passed.
  • Clean-staging collection build: exit 0; private context, Git metadata, caches, bytecode, and test output were absent from the archive.
  • Galaxy importer 0.4.43: exit 0, zero errors; only the four repository-accepted Ansible 2.16–2.19 sanity-ignore warnings.
  • Guarded VXLAN iBGP integration smoke in internal check mode: 145 tasks passed, 0 failed, 0 unreachable; all eleven family files were included, with mutations_sent=0 and deployments_sent=0.

Live mutation/idempotency was not run because the shared-lab global ownership gate detected an unrelated controller/registry identity mismatch and a prior stop marker remains. No testbed mutations or deployments were issued. Mutation qualification must remain pending until a fresh global ownership audit passes.

Cisco Nexus Dashboard Version

The workflow continues to use the existing per-interface mutation paths supported by the underlying standalone modules. No ND 4.3.1-only bulk-modify dependency is introduced by this repair.

Related ND API Resource Category

  • analyze
  • infa
  • manage
  • onemanage
  • other

Checklist

  • Latest commit incorporates current develop with merge conflicts resolved
  • New or updated module documentation has been made accordingly
  • Unit, formatting, sanity, build, and importer validation completed
  • Guarded eleven-family check-mode integration completed
  • Guarded live mutation/idempotency (blocked by shared-testbed ownership gate)
  • Assigned the proper reviewers

@mikewiebe
mikewiebe marked this pull request as ready for review August 25, 2026 14:56
@mikewiebe
mikewiebe marked this pull request as draft August 25, 2026 14:56
@mikewiebe mikewiebe changed the title Initial Interface Aggregator Work ND Interface Aggregator Aug 25, 2026
Support implicit policy transitions for merged and replaced workflows, policy-aware deletion, pair-aware vPC safety, protected-member checks, and structural collision validation.

Preserve shared snapshot and bulk-provisioning scale behavior, harden switch-scoped interface summary pagination, and treat non-429 HTTP client errors as terminal to avoid deterministic retry delays.
Add guarded lifecycle, transition, deletion, deployment-control, output, validation, shared-snapshot, and property-matrix scenarios across all ten supported interface families and the selected fabric types.
Support deployment-only execution for requested pending or out-of-sync interfaces, reconcile post-write inventory, and return compact resource-scoped operations without duplicate snapshots or counters. Update unit tests, integration coverage, and module documentation for the resulting contract.
…ator

# Conflicts:
#	plugins/module_utils/models/interfaces/svi_interface.py
#	plugins/module_utils/models/interfaces/vpc_access_interface.py
#	plugins/module_utils/models/interfaces/vpc_trunk_host_interface.py
#	plugins/module_utils/orchestrators/vpc_interface_base.py
#	tests/unit/module_utils/models/test_vpc_access_interface.py
#	tests/unit/module_utils/models/test_vpc_trunk_host_interface.py
#	tests/unit/module_utils/test_response_handler_nd.py
Add verify.enabled with a false default so successful mutations can return projected state without post-write inventory refreshes. Preserve forced reconciliation for partial and failed writes, and update module documentation, integration coverage, and unit tests for after_verified semantics.
Merge dependent address and NetFlow fields without transient validation failures. Compare workflow integration results against normalized proposed data and add regression coverage.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add aggregate nd_interfaces_workflow coordinator with shared interface-state snapshots

1 participant