Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@freedge
Copy link

@freedge freedge commented Mar 31, 2023

when updating a large security rule group, one action=move API call is made for each rule of the security rule group, the first rule is placed according to the group position, then each succeeding rule is moved after the previous one.

We introduce a loose ordering of rules where we only order newly created rules and put them below any other rule of the security group. This considerably reduces the amount of API calls needed to update rules.

PaloAltoNetworks/terraform-provider-panos#378

How Has This Been Tested?

tested using the matching terraform-provider-panos change (not submitted).
My security group rule contains 900 elements, the overall terraform plan/update (that does much more than just the rules) goes from 1m30s to 1m in local, where there is no communication delay between terraform and the NGFW.

Types of changes

  • New feature (non-breaking change which adds functionality)

Checklist

  • I have updated the documentation accordingly.
  • I have read the CONTRIBUTING document.
  • I have added tests to cover my changes if appropriate.
  • All new and existing tests passed.

@welcome-to-palo-alto-networks

🎉 Thanks for opening this pull request! We really appreciate contributors like you! 🙌

when updating a large security rule group, one action=move API call is
made for each rule of the security rule group, the first rule is placed
according to the group position, then each succeeding rule is moved
after the previous one.

We introduce a **loose** ordering of rules where we only order newly
created rules and put them below any other rule of the security group.
This considerably reduces the amount of API calls needed to update
rules.

PaloAltoNetworks/terraform-provider-panos#378
@freedge
Copy link
Author

freedge commented Apr 3, 2023

there is no CONTRIBUTING document. test and doc can be done in the terraform-provider-panos repo if maintainers are OK with the idea

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant