Infrastructure as a Code

Hello!
I would like you to ask for your ways to OpenWRT Infrastructure as a Code (IaaC) management.

OpenWRT Community created few interesting projects/setups like:

So there are quite nice stack, although a wiki is missing a article about implementing such IaaC approach.

I created this topic to discuss your ways to obtain that that approach.

I am personally started to use pyinfra, although as of now I am still in stage of preparing the setup, thus I did not create a topic in https://forum.openwrt.org/c/community-builds-projects-packages, and I wanted to hear from you about the approaches to maybe change/improve mine.

I built OpenWrt Configurator to be a simple and easy to use UCI-like infrastructure/config-as-code tool: https://github.com/jasrusable/openwrt-configurator

I wanted a reliable way to manage openwrt with Terraform. I developed uapi as control plane called by my terraform provider. I am using exclusively uapi to manage my router since a few months, it works well.

For myself I use bash based tooling and each device gets its firmware build with a local image builder and then I flash everything.

:person_shrugging:

In case you want to change something you reflash the device?

Yes.

For really small changes like adding an extra vlan I have small helper scripts which just place the config and restart the network

But the norm is reflash and reboot.
In a home network the frequency of chances are quiet low. Even in most Soho environments so if you don't reflash every single day it should be no issue...

Hi @h4k1

I am the maintainer of the community.openwrt collection in Ansible - by the way, Ansible collection community.openwrt 1.8.0 released! yesterday.

I cannot do the comparison with the other projects and, TBH, I am a big defender of testing things and finding what makes sense for you. I used Ansible to manage my home computers, and I was sick and tired of that lousy router provided by the ISP, so when I decided to buy a new one, I wanted to have something that I could use Ansible to configure. OpenWrt was hitting the sweet spot between features and affordability, then I used an existing Ansible role to manage the router and, eventually, I wanted to improve it. Long story short, now I am taking care of the OpenWrt collection.

The announcement above already spills the beans on what we are doing right now: natively, Ansible works with Python and Powershell. We had to come up with a framework of sorts to make it work with shell script (derived from that previously existing Ansible role - it was the base for the collection code), but using shell script for it is quite cumbersome, so we are writing a similar framework to run the modules in ucode. My plan is to eventually migrate all the modules to ucode and remove the legacy shell-based stuff.

If any of that catches your eye, by all means, hop on the bandwagon. If you'd rather go with pyinfra, by all means, go and make something awesome there :slight_smile: I am happy to share our experience on c.openwrt, so that you don't fall on the same traps we did before. The first thing I would say is: if you do not want to force the installation of Python on the router (our case), go straight to ucode, don't even think twice.