Operational control of a Kemp LoadMaster appliance over its /access management API: discover every Virtual Service and its Real Servers, add or remove a Virtual Service, and add/remove/enable/disable a Real Server — the standard maintenance action for draining traffic before patching a backend.
sync fans out — one API call lists every Virtual Service and writes one virtualService resource per VS. Every mutating method re-reads the affected VS after its write, so stored state never drifts from the appliance. Real Server operations are idempotent — adding a member that's already there, or removing one already gone, is a no-op rather than an error.
Auth is HTTP Basic against the LoadMaster's API user; supply the password via a vault reference. Response field names are read defensively (a short alias list per field) since exact tag names have drifted across firmware releases — a genuinely unexpected shape throws a specific, actionable error instead of silently mis-parsing.
Quick Start
--global-arg host=lm.example.com \
--global-arg apiUser=bal \
--global-arg 'apiPassword=${{ vault.get("briefing", "LOADMASTER_PASSWORD") }}'
swamp model method run lb-1 sync swamp model method run lb-1 set_real_server_status \
--input vsIndex=1 --input address=198.51.100.10 --input port=8443 --input enabled=false