community.network.avi_pkiprofile – Module for setup of PKIProfile Avi RESTful Object

Note

This plugin is part of the community.network collection (version 2.1.1).

To install it use: ansible-galaxy collection install community.network.

To use it in a playbook, specify: community.network.avi_pkiprofile.

Synopsis

Requirements

The below requirements are needed on the host that executes this module.

  • avisdk

Parameters

Parameter Choices/Defaults Comments
api_context
dictionary
Avi API context that includes current session ID and CSRF Token.
This allows user to perform single login and re-use the session.
api_version
string
Default:
"16.4.4"
Avi API version of to use for Avi API and objects.
avi_api_patch_op
string
    Choices:
  • add
  • replace
  • delete
Patch operation to use when using avi_api_update_method as patch.
avi_api_update_method
string
    Choices:
  • put ←
  • patch
Default method for object update is HTTP PUT.
Setting to patch will override that behavior to use HTTP PATCH.
avi_credentials
dictionary
Avi Credentials dictionary which can be used in lieu of enumerating Avi Controller login details.
api_version
string
Default:
"16.4.4"
Avi controller version
controller
string
Avi controller IP or SQDN
csrftoken
string
Avi controller API csrftoken to reuse existing session with session id
password
string
Avi controller password
port
string
Avi controller port
session_id
string
Avi controller API session id to reuse existing session with csrftoken
tenant
string
Default:
"admin"
Avi controller tenant
tenant_uuid
string
Avi controller tenant UUID
timeout
string
Default:
300
Avi controller request timeout
token
string
Avi controller API token
username
string
Avi controller username
avi_disable_session_cache_as_fact
boolean
    Choices:
  • no ←
  • yes
It disables avi session information to be cached as a fact.
ca_certs
string
List of certificate authorities (root and intermediate) trusted that is used for certificate validation.
controller
string
Default:
""
IP address or hostname of the controller. The default value is the environment variable AVI_CONTROLLER.
created_by
string
Creator name.
crl_check
boolean
    Choices:
  • no
  • yes
When enabled, avi will verify via crl checks that certificates in the trust chain have not been revoked.
Default value when not specified in API or module is interpreted by Avi Controller as True.
crls
string
Certificate revocation lists.
ignore_peer_chain
boolean
    Choices:
  • no
  • yes
When enabled, avi will not trust intermediate and root certs presented by a client.
Instead, only the chain certs configured in the certificate authority section will be used to verify trust of the client's cert.
Default value when not specified in API or module is interpreted by Avi Controller as False.
is_federated
boolean
    Choices:
  • no
  • yes
This field describes the object's replication scope.
If the field is set to false, then the object is visible within the controller-cluster and its associated service-engines.
If the field is set to true, then the object is replicated across the federation.
Field introduced in 17.1.3.
Default value when not specified in API or module is interpreted by Avi Controller as False.
name
string / required
Name of the pki profile.
password
string
Default:
""
Password of Avi user in Avi controller. The default value is the environment variable AVI_PASSWORD.
state
string
    Choices:
  • absent
  • present ←
The state that should be applied on the entity.
tenant
string
Default:
"admin"
Name of tenant used for all Avi API calls and context of object.
tenant_ref
string
It is a reference to an object of type tenant.
tenant_uuid
string
Default:
""
UUID of tenant used for all Avi API calls and context of object.
url
string
Avi controller URL of the object.
username
string
Default:
""
Username used for accessing Avi controller. The default value is the environment variable AVI_USERNAME.
uuid
string
Unique object identifier of the object.
validate_only_leaf_crl
boolean
    Choices:
  • no
  • yes
When enabled, avi will only validate the revocation status of the leaf certificate using crl.
To enable validation for the entire chain, disable this option and provide all the relevant crls.
Default value when not specified in API or module is interpreted by Avi Controller as True.

Notes

Note

Examples

- name: Example to create PKIProfile object
  community.network.avi_pkiprofile:
    controller: 10.10.25.42
    username: admin
    password: something
    state: present
    name: sample_pkiprofile

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key Returned Description
obj
dictionary
success, changed
PKIProfile (api/pkiprofile) object



Authors