{"id":37882881,"url":"https://github.com/cisco-en-programmability/ansible-collection-sdwan-deployment","last_synced_at":"2026-01-16T16:49:47.923Z","repository":{"id":230093228,"uuid":"777712701","full_name":"cisco-en-programmability/ansible-collection-sdwan-deployment","owner":"cisco-en-programmability","description":"This repository contains the necessary ansible modules for deploying SDWAN resources","archived":false,"fork":false,"pushed_at":"2026-01-13T18:39:29.000Z","size":277,"stargazers_count":3,"open_issues_count":3,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-13T20:55:50.151Z","etag":null,"topics":["ansible","ansible-playbook","aws","azure","deployment","sdwan"],"latest_commit_sha":null,"homepage":"","language":"Jinja","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cisco-en-programmability.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"docs/CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"docs/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2024-03-26T11:27:23.000Z","updated_at":"2025-12-12T11:21:46.000Z","dependencies_parsed_at":"2024-03-27T20:31:07.658Z","dependency_job_id":"bcc75306-9142-4ec1-bb98-6b6fd30a66da","html_url":"https://github.com/cisco-en-programmability/ansible-collection-sdwan-deployment","commit_stats":null,"previous_names":["cisco-open/ansible-collection-sdwan-deployment","cisco-en-programmability/ansible-collection-sdwan-deployment"],"tags_count":8,"template":false,"template_full_name":null,"purl":"pkg:github/cisco-en-programmability/ansible-collection-sdwan-deployment","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cisco-en-programmability%2Fansible-collection-sdwan-deployment","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cisco-en-programmability%2Fansible-collection-sdwan-deployment/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cisco-en-programmability%2Fansible-collection-sdwan-deployment/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cisco-en-programmability%2Fansible-collection-sdwan-deployment/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cisco-en-programmability","download_url":"https://codeload.github.com/cisco-en-programmability/ansible-collection-sdwan-deployment/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cisco-en-programmability%2Fansible-collection-sdwan-deployment/sbom","scorecard":{"id":18,"data":{"date":"2025-08-09T03:08:06Z","repo":{"name":"github.com/cisco-en-programmability/ansible-collection-sdwan-deployment","commit":"a131dc004afb58a0c0a222ae111d1ad599dfa4ce"},"scorecard":{"version":"v5.0.0","commit":"ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4"},"score":5.1,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":10,"reason":"15 out of 15 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#ci-tests"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":8,"reason":"Found 15/17 approved changesets -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#code-review"}},{"name":"Contributors","score":3,"reason":"project has 1 contributing companies or organizations -- score normalized to 3","details":["Info: cisco-open contributor org/company found, "],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#contributors"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dangerous-workflow"}},{"name":"Dependency-Update-Tool","score":0,"reason":"no update tool detected","details":["Warn: no dependency update tool configurations found"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dependency-update-tool"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#license"}},{"name":"Maintained","score":0,"reason":"1 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":3,"reason":"dependency not pinned by hash detected -- score normalized to 3","details":["Warn: pipCommand not pinned by hash: .github/workflows/galaxy-importer.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/galaxy-importer.yml:51","Warn: pipCommand not pinned by hash: .github/workflows/galaxy-importer.yml:52","Warn: pipCommand not pinned by hash: .github/workflows/linters.yml:41","Warn: pipCommand not pinned by hash: .github/workflows/release-from-tag.yml:60","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:32","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:33","Info:   8 out of   8 GitHub-owned GitHubAction dependencies pinned","Info:   2 out of   2 third-party GitHubAction dependencies pinned","Info:   0 out of   7 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 28 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#sast"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: docs/SECURITY.md:1","Info: Found linked content: docs/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: docs/SECURITY.md:1","Info: Found text in security policy: docs/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#signed-releases"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/scorecard.yml:25","Info: topLevel permissions set to 'read-all': .github/workflows/galaxy-importer.yml:15","Info: topLevel permissions set to 'read-all': .github/workflows/linters.yml:11","Info: topLevel permissions set to 'read-all': .github/workflows/release-from-tag.yml:8","Info: topLevel permissions set to 'read-all': .github/workflows/requirements.yml:11","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:17"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":0,"reason":"16 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2020-220","Warn: Project is vulnerable to: GHSA-32p4-gm2c-wmch","Warn: Project is vulnerable to: GHSA-99w6-3xph-cx78","Warn: Project is vulnerable to: GHSA-jpxc-vmjf-9fcj","Warn: Project is vulnerable to: GHSA-248v-346w-9cwc / PYSEC-2024-230","Warn: Project is vulnerable to: GHSA-79v4-65xg-pq4g","Warn: Project is vulnerable to: GHSA-h4gh-qq45-vh27","Warn: Project is vulnerable to: GHSA-cpwx-vrp4-4pq7","Warn: Project is vulnerable to: GHSA-gmj6-6f8f-6699","Warn: Project is vulnerable to: GHSA-h75v-3vvj-5mfj","Warn: Project is vulnerable to: GHSA-q2x7-8rv6-6q7h","Warn: Project is vulnerable to: GHSA-9hjg-9r4m-mvj7","Warn: Project is vulnerable to: GHSA-5rjg-fvgr-3xxf / PYSEC-2025-49","Warn: Project is vulnerable to: GHSA-34jh-p97f-mpxf","Warn: Project is vulnerable to: GHSA-48p4-8xcf-vxj5","Warn: Project is vulnerable to: GHSA-pq67-6m6q-mj2v"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-14T12:09:22.933Z","repository_id":230093228,"created_at":"2025-08-14T12:09:22.934Z","updated_at":"2025-08-14T12:09:22.934Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28480081,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-16T11:59:17.896Z","status":"ssl_error","status_checked_at":"2026-01-16T11:55:55.838Z","response_time":107,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","ansible-playbook","aws","azure","deployment","sdwan"],"created_at":"2026-01-16T16:49:47.779Z","updated_at":"2026-01-16T16:49:47.899Z","avatar_url":"https://github.com/cisco-en-programmability.png","language":"Jinja","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Cisco SD-WAN Deployment on AWS and Azure using Ansible\n\nAnsible roles and playbooks for deployment and teardown of Cisco SD-WAN on AWS and Azure.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Roadmap](#roadmap)\n- [Requirements](#requirements)\n- [Installing this collection](#installing-this-collection)\n- [Using this collection](#using-this-collection)\n- [Troubleshooting](#troubleshooting)\n- [Useful Links](#useful-links)\n- [Contact Information](#contact-information)\n- [License](#license)\n- [Contributing](#contributing)\n- [Code of Conduct](#code-of-conduct)\n- [Releasing, Versioning and Deprecation](#releasing-versioning-and-deprecation)\n\n---\n\n## Overview\n\nThis repository includes:\n\n- `aws_network_infrastructure`\n- `aws_controllers`\n- `aws_edges`\n- `aws_teardown`\n- cisco.sdwan_deployment.common`\n- `azure_controllers`\n- `azure_edges`\n- `azure_teardown`\n- `azure_controllers`\n- `template_cloudinit`\n\nAnsible roles, which can be used to automate the deployment (and teardown) of SD-WAN systems on the AWS cloud.\n\nIn order to have more convenient way of handling next onboarding processes, the `aws` and `azure` roles are generating files via:\n\n- `roles/common/tasks/generate_deployment_facts_controllers.yml` and\n\n- `roles/common/tasks/generate_deployment_facts_edges.yml`\n\nPath of this output file customizable via `results_dir` `results_path_controllers` and `results_path_edges` variables in input config file.\n\n---\n\n## Roadmap\n\nCurrent coverage:\n\n- [x] Deployment on AWS\n- [x] Deployment on Azure\n- [x] Deployment of:\n  - [x] vManage\n  - [x] vBond\n  - [x] vSmart\n  - [x] cEdge\n- [x] Local installation via Ansible Galaxy\n- [x] Installation via git repository link\n- [x] Migration to CiscoDevNet/Cisco Open\n- [x] Separate role for cloudinit templating\n- [x] Share roles via Ansible Galaxy\n\nFuture Goals:\n\n- [ ] Support for cluster deployment\n- [ ] Provide AWX (web-based user interface)\n- [ ] Deployment on GCP\n- [ ] Enhance cloud-init configuration (complex bringup)\n\n---\n\n## Requirements\n\nThis collection is based on `ansible-core==2.16.6`, see [ansible-core-support-matrix](https://docs.ansible.com/ansible/latest/reference_appendices/release_and_maintenance.html#ansible-core-support-matrix).\n\nBefore you begin, ensure you have met the following requirements:\n\n- You have installed Python 3.10 - 3.12\n- You have an AWS or Azure account with the necessary permissions\n- You have access to a Cisco SD-WAN AMIs on AWS or images on Azure\n\n### Python dependencies\n\nThe python module dependencies are not installed by ansible-galaxy. They can be manually installed using pip:\n\n```bash\npip install -r requirements.txt\n```\n\n---\n\n## Installing this collection\n\n### Using `requirements.yml`\n\nIn `requirements.yml` inside your project add:\n\n```yml\n- name: git@github.com:cisco-en-programmability/ansible-collection-sdwan-deployment.git\n  type: git\n  version: main\n```\n\nNote: If you are not using full ansible installation, you might install also `aws.collection` and `azure.azcollection` by adding:\n\n```yml\n  - name: amazon.aws\n    version: 6.5.0\n  - name: azure.azcollection\n    version: 1.19.0\n```\n\nto `requirements.yml` inside your project.\n\nAt the end always run:\n\n```bash\nansible-galaxy install -r requirements.yml\n```\n\n## Using this collection\n\n### Prepare your configuration\n\n*Note:* Current solution supports topology that consist of vManage, vBond, vSmart and C8000V edge device.\n\nThere are configuration files which has been initially filled with values:\n\n- `.playbooks/aws_sdwan_config.yml`\n- `.playbooks/azure_sdwan_config.yml`\n\nBoth files are supplemented by config defaults from all roles.\n\nNOTE: You can call the variables file any name, but remember to choose one option:\n\n- include that name in playbook\n\n```yml\n- name: Deploy Cisco SD-WAN on AWS\n  hosts: localhost\n  roles:\n    - aws_network_infrastructure\n    - aws_controllers\n  vars_files:\n    - ./playbooks/aws_sdwan_config.yml\n```\n\n- or pass the variables by directly including your configuration file with:\n\n```bash\nansible-playbook playbooks/aws_deploy_controllers.yml -e \"@./playbooks/aws_sdwan_config.yml\"\n```\n\n(notice @ that suggest we are reffering to the file)\n\n### Deploying Cisco SD-WAN\n\nTo deploy Cisco SD-WAN on AWS or Azure, run the example playbook using roles:\n\nFor AWS:\n\n- `aws_network_infrastructure`\n- `aws_controllers`\n- `aws_edges`\n\nFor Azure:\n\n- `azure_network_infrastructure`\n- `azure_controllers`\n- `azure_edges`\n\n\u003c/br\u003e\n\nCurrent version of this solution assumes that users will authenticate with their cloud providers in order to run ansible playbooks. See [Useful Links](#useful-links).\n\nWe provided example playbooks that you can execute with:\n\n```bash\nansible-playbook playbooks/aws_deploy_controllers.yml\nansible-playbook playbooks/aws_deploy_edges.yml\n```\n\nor\n\n```bash\nansible-playbook playbooks/azure_deploy_controllers.yml\nansible-playbook playbooks/azure_deploy_edges.yml\n```\n\nFor desired changes, please update configuration files.\n\n### Tearing down Cisco SD-WAN on AWS\n\nTo teardown the deployed system, run the example playbook using the `aws_teardown` role or `azure_teardown`.\n\n```bash\nansible-playbook ./playbooks/aws_teardown.yml\n\nor\n\nansible-playbook ./playbooks/azure_teardown.yml\n```\n\nIf you want to teardown only specific ec2 instances (with their EiPs and NICs associated):\n\n```bash\nansible-playbook ./playbooks/aws_teardown.yml -e \"@instances_to_teardown.yml\"\n```\n\nWhere `instances_to_teardown.yml` is path to file with definition:\n\n```yml\nteardown_specific_instances:\n  - \"acich-ansible-cedge-111\"\n  - \"acich-ansible-cedge-222\"\n```\n\n### Generating cloud-init configuration\n\nRole `template_cloudinit` provide tasks that can generate `cloudinit` (also known as `userdata`) configuration, without deployment of any machines.\nExamples usage of `template_cloudinit` role can be taken from `playbooks/template_cloudinit.yml`. Note, that in this example playbook, configuration file\nis used from `playbooks/template_cloudinit.yml`.\n\n---\n\n## Troubleshooting\n\n### 1. Consol connectivity works, but cannot reach with SSH or ICMP\n\nIf your instances are up and running, and you can log to them via ec2 console, please verify that your ip address\nis \"allow-listed\". See `aws_allowed_subnets` in `roles/aws_controllers/defaults/main.yml` to verify.\n\n### 2. Services status\n\nIf vManage is not starting NMS service:\n\n- check if your disk /opt/data is more than 20% free. Otherwise that case shutdown application as well\n- remember to make sure the sdwan manager and other sdwan virtual machines are right sized for your deployment needs - cisco's server recommendations are available here: [server-requirements](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/release/notes/compatibility-and-server-recommendations/server-requirements.html)\n\n---\n\n## Compatibility\n\nNote that azure collection python requirements include package `uamqp` which can generate wheel issues.\nFor MacOS you migth install cmake: `brew install cmake` and: `pip install cmake`.\nThen install working `uamqp` package (which is below `v1.6.9`) with: `pip install uamqp==1.6.8`.\n\n---\n\n## Useful links\n\n### AWS CLI\n\n- [Installing AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-install.html)\n- [Configuring the AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-configure.html)\n\n### AWS Authentication\n\n- [Understanding and Getting Your Security Credentials](https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html)\n- [Configuring AWS Credentials](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-files.html)\n\n### Azure Authentication\n\n- [Authenticating with Azure](https://docs.ansible.com/ansible/latest/scenario_guides/guide_azure.html#authenticating-with-azure)\n\n---\n\n## Contact Information\n\nFor any questions or concerns, please open an issue on this repository.\n\n## License\n\nSee [LICENSE](./LICENSE) file.\n\n## Contributing\n\nSee [Contributing](./docs/CONTRIBUTING.md) file.\n\n## Code of Conduct\n\nSee [Code of Conduct](./docs/CODE_OF_CONDUCT.md) file.\n\n## Releasing, Versioning and Deprecation\n\nThis collection follows Semantic Versioning. More details on versioning can be found in [Understanding collection versioning](https://docs.ansible.com/ansible/latest/dev_guide/developing_collections_distributing.html#understanding-collection-versioning).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcisco-en-programmability%2Fansible-collection-sdwan-deployment","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcisco-en-programmability%2Fansible-collection-sdwan-deployment","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcisco-en-programmability%2Fansible-collection-sdwan-deployment/lists"}