Hi Robert, That is actually working as designed. As a task automation tool, Ansible is idempotent in nature. This means that any task will be performed exactly as prescribed. That same task can be performed repeatedly and nothing will change as long as none of the parameters have changed. However, if any parameter changes from what is currently defined, the new parameter will be applied in whole. If a parameter such as an address group list contains 1,000 members and you simply need to add one more, you will need to specify all 1,001 members. Otherwise the 1,000 will be overwritten by the 1. This concept is much broader than Ansible and is actually a fundamental concept of Infrastructure as Code (IaC) in automation. All of the Ansible modules for PAN-OS support this notion of idempotent operations. Hopefully this clears up any confusion. Regards, -Bob-
... View more