t_systems_mms.icinga_director.icinga_zone – Manage zones in Icinga2

Note

This plugin is part of the t_systems_mms.icinga_director collection (version 1.26.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install t_systems_mms.icinga_director.

To use it in a playbook, specify: t_systems_mms.icinga_director.icinga_zone.

New in version 1.5.0: of t_systems_mms.icinga_director

Synopsis

  • Add or remove a zone to Icinga2 through the director API.

Parameters

Parameter

Comments

append

boolean

added in 1.25.0 of t_systems_mms.icinga_director

Do not overwrite the whole object but instead append the defined properties.

Note - Appending to existing vars, imports or any other list/dict is not possible. You have to overwrite the complete list/dict.

Note - Variables that are set by default will also be applied, even if not set.

Choices:

  • no

  • yes

client_cert

path

PEM formatted certificate chain file to be used for SSL client authentication.

This file can also include the key as well, and if the key is included, client_key is not required.

client_key

path

PEM formatted file that contains your private key to be used for SSL client authentication.

If client_cert contains both the certificate and key, this option is not required.

force

aliases: thirsty

boolean

If yes do not get a cached copy.

Alias thirsty has been deprecated and will be removed in 2.13.

Choices:

  • no ← (default)

  • yes

force_basic_auth

boolean

Credentials specified with url_username and url_password should be passed in HTTP Header.

Choices:

  • no ← (default)

  • yes

http_agent

string

Header to identify as, generally appears in web server logs.

Default: “ansible-httpget”

is_global

boolean

Whether configuration files for this zone should be synced to all endpoints.

Choices:

  • no ← (default)

  • yes

object_name

aliases: name

string / required

Icinga object name for this zone.

This is usually a fully qualified host name but it could basically be any kind of string.

To make things easier for your users we strongly suggest to use meaningful names for templates.

For example “generic-zone” is ugly, “Standard Linux Server” is easier to understand.

parent

string

The name of the parent zone.

state

string

Apply feature state.

Choices:

  • present ← (default)

  • absent

url

string / required

HTTP, HTTPS, or FTP URL in the form (http|https|ftp)://[user[:pass]]@host.domain[:port]/path

url_password

string

The password for use in HTTP basic authentication.

If the url_username parameter is not specified, the url_password parameter will not be used.

url_username

string

The username for use in HTTP basic authentication.

This parameter can be used without url_password for sites that allow empty passwords

use_gssapi

boolean

added in 2.11 of ansible.builtin

Use GSSAPI to perform the authentication, typically this is for Kerberos or Kerberos through Negotiate authentication.

Requires the Python library gssapi to be installed.

Credentials for GSSAPI can be specified with url_username/url_password or with the GSSAPI env var KRB5CCNAME that specified a custom Kerberos credential cache.

NTLM authentication is not supported even if the GSSAPI mech for NTLM has been installed.

Choices:

  • no ← (default)

  • yes

use_proxy

boolean

If no, it will not use a proxy, even if one is defined in an environment variable on the target hosts.

Choices:

  • no

  • yes ← (default)

validate_certs

boolean

If no, SSL certificates will not be validated.

This should only be used on personally controlled sites using self-signed certificates.

Choices:

  • no

  • yes ← (default)

Notes

Note

  • This module supports check mode.

Examples

- name: Create a zone in icinga
  t_systems_mms.icinga_director.icinga_zone:
    state: present
    url: "{{ icinga_url }}"
    url_username: "{{ icinga_user }}"
    url_password: "{{ icinga_pass }}"
    object_name: "foozone"

- name: Update a zone in icinga
  t_systems_mms.icinga_director.icinga_zone:
    state: present
    url: "{{ icinga_url }}"
    url_username: "{{ icinga_user }}"
    url_password: "{{ icinga_pass }}"
    object_name: "foozone"
    parent: "master"
    append: true

Authors

  • Aaron Bulmahn (@arbu)