mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 03:10:46 +08:00
docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
a69899d146
commit
bac4a609b1
4 changed files with 16 additions and 16 deletions
|
|
@ -54,7 +54,7 @@ def default_huawei_hop_template(protocol: str, vrf: str = "") -> str:
|
||||||
|
|
||||||
|
|
||||||
def default_bastion_username_template() -> str:
|
def default_bastion_username_template() -> str:
|
||||||
"""SSH bastion composite username (JumpServer/CBH/ZTE-TSM style)."""
|
"""SSH bastion composite username (JumpServer/CBH/generic protocol-proxy style)."""
|
||||||
return "{hop_user}@{target_user}@{target_ip}@{hop_host}"
|
return "{hop_user}@{target_user}@{target_ip}@{hop_host}"
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -20,15 +20,15 @@ class BastionTemplateTests(unittest.TestCase):
|
||||||
def test_render_bastion_composite_username(self) -> None:
|
def test_render_bastion_composite_username(self) -> None:
|
||||||
creds = {
|
creds = {
|
||||||
"hop_vendor": "bastion",
|
"hop_vendor": "bastion",
|
||||||
"hop_username": "ZTE-TSM",
|
"hop_username": "bastion-user",
|
||||||
"hop_host": "10.34.145.27",
|
"hop_host": "1.1.1.1",
|
||||||
"username": "ca-oper",
|
"username": "target-user",
|
||||||
"ip_address": "114.0.44.11",
|
"ip_address": "2.2.2.2",
|
||||||
"hop_protocol": "ssh",
|
"hop_protocol": "ssh",
|
||||||
"hop_vrf": "",
|
"hop_vrf": "",
|
||||||
}
|
}
|
||||||
out = render_hop_command("", creds)
|
out = render_hop_command("", creds)
|
||||||
self.assertEqual(out, "ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27")
|
self.assertEqual(out, "bastion-user@target-user@2.2.2.2@1.1.1.1")
|
||||||
|
|
||||||
def test_render_custom_bastion_template(self) -> None:
|
def test_render_custom_bastion_template(self) -> None:
|
||||||
creds = {
|
creds = {
|
||||||
|
|
@ -73,14 +73,14 @@ class BastionConnectImplTests(unittest.TestCase):
|
||||||
conn = MagicMock()
|
conn = MagicMock()
|
||||||
connect_handler.return_value = conn
|
connect_handler.return_value = conn
|
||||||
creds = {
|
creds = {
|
||||||
"hop_host": "10.34.145.27",
|
"hop_host": "1.1.1.1",
|
||||||
"hop_username": "ZTE-TSM",
|
"hop_username": "bastion-user",
|
||||||
"hop_password": "vault-pass",
|
"hop_password": "vault-pass",
|
||||||
"hop_port": 22,
|
"hop_port": 22,
|
||||||
"device_type": "zte_zxros",
|
"device_type": "zte_zxros",
|
||||||
"protocol": "ssh",
|
"protocol": "ssh",
|
||||||
"username": "ca-oper",
|
"username": "target-user",
|
||||||
"ip_address": "114.0.44.11",
|
"ip_address": "2.2.2.2",
|
||||||
"password": "",
|
"password": "",
|
||||||
"hop_target_auth_mode": "bastion_managed",
|
"hop_target_auth_mode": "bastion_managed",
|
||||||
"hop_vendor": "bastion",
|
"hop_vendor": "bastion",
|
||||||
|
|
@ -89,8 +89,8 @@ class BastionConnectImplTests(unittest.TestCase):
|
||||||
}
|
}
|
||||||
_connect_via_bastion(creds)
|
_connect_via_bastion(creds)
|
||||||
kwargs = connect_handler.call_args.kwargs
|
kwargs = connect_handler.call_args.kwargs
|
||||||
self.assertEqual(kwargs["host"], "10.34.145.27")
|
self.assertEqual(kwargs["host"], "1.1.1.1")
|
||||||
self.assertEqual(kwargs["username"], "ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27")
|
self.assertEqual(kwargs["username"], "bastion-user@target-user@2.2.2.2@1.1.1.1")
|
||||||
self.assertEqual(kwargs["password"], "vault-pass")
|
self.assertEqual(kwargs["password"], "vault-pass")
|
||||||
conn.disconnect.assert_not_called()
|
conn.disconnect.assert_not_called()
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -202,14 +202,14 @@ const en = {
|
||||||
ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.",
|
ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.",
|
||||||
linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).",
|
linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).",
|
||||||
bastionHint:
|
bastionHint:
|
||||||
"SSH with composite username via bastion protocol proxy. Example: user@account@target_ip@bastion_host; password is the bastion/Vault password. JumpServer/CBH often use port 2222.",
|
"SSH with composite username via bastion protocol proxy. Example: bastion-user@target-user@2.2.2.2@1.1.1.1; password is the bastion/Vault password. JumpServer/CBH often use port 2222.",
|
||||||
targetAuthMode: "Target credentials",
|
targetAuthMode: "Target credentials",
|
||||||
targetAuthBastionManaged: "Bastion-managed (target password optional)",
|
targetAuthBastionManaged: "Bastion-managed (target password optional)",
|
||||||
targetAuthManual: "Manual (secondary auth after connect)",
|
targetAuthManual: "Manual (secondary auth after connect)",
|
||||||
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
|
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
|
||||||
usernameTemplate: "SSH username template",
|
usernameTemplate: "SSH username template",
|
||||||
templateHintBastion:
|
templateHintBastion:
|
||||||
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank.",
|
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank. Example: bastion-user@target-user@2.2.2.2@1.1.1.1.",
|
||||||
host: "Jump host",
|
host: "Jump host",
|
||||||
port: "Jump port",
|
port: "Jump port",
|
||||||
protocol: "Jump protocol",
|
protocol: "Jump protocol",
|
||||||
|
|
|
||||||
|
|
@ -200,14 +200,14 @@ const zh = {
|
||||||
ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。",
|
ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。",
|
||||||
linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。",
|
linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。",
|
||||||
bastionHint:
|
bastionHint:
|
||||||
"SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。",
|
"SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:bastion-user@target-user@2.2.2.2@1.1.1.1;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。",
|
||||||
targetAuthMode: "目标凭据",
|
targetAuthMode: "目标凭据",
|
||||||
targetAuthBastionManaged: "堡垒机托管(目标密码可留空)",
|
targetAuthBastionManaged: "堡垒机托管(目标密码可留空)",
|
||||||
targetAuthManual: "手动输入(连接后二次认证)",
|
targetAuthManual: "手动输入(连接后二次认证)",
|
||||||
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
|
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
|
||||||
usernameTemplate: "SSH 用户名模板",
|
usernameTemplate: "SSH 用户名模板",
|
||||||
templateHintBastion:
|
templateHintBastion:
|
||||||
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27。",
|
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:bastion-user@target-user@2.2.2.2@1.1.1.1。",
|
||||||
host: "跳板地址",
|
host: "跳板地址",
|
||||||
port: "跳板端口",
|
port: "跳板端口",
|
||||||
protocol: "跳板协议",
|
protocol: "跳板协议",
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue