ngine_io.cloudstack.cs_role_permission module – Manages role permissions on Apache CloudStack based clouds.
Note
This module is part of the ngine_io.cloudstack collection (version 2.2.4).
You might already have this collection installed if you are using the ansible
package.
It is not included in ansible-core
.
To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install ngine_io.cloudstack
.
To use it in a playbook, specify: ngine_io.cloudstack.cs_role_permission
.
New in version 0.1.0: of ngine_io.cloudstack
Synopsis
Create, update and remove CloudStack role permissions.
Managing role permissions only supported in CloudStack >= 4.9.
Requirements
The below requirements are needed on the host that executes this module.
python >= 2.6
cs >= 0.9.0
Parameters
Parameter |
Comments |
---|---|
HTTP method used to query the API endpoint. If not given, the Choices:
|
|
API key of the CloudStack API. If not given, the |
|
Secret key of the CloudStack API. If not set, the |
|
HTTP timeout in seconds. If not given, the Default: 10 |
|
URL of the CloudStack API e.g. https://cloud.example.com/client/api. If not given, the |
|
Verify CA authority cert file. If not given, the |
|
The description of the role permission. |
|
The API name of the permission. |
|
The parent role permission uuid. use 0 to move this rule at the top of the list. |
|
The rule permission, allow or deny. Defaulted to deny. Choices:
|
|
Name or ID of the role. |
|
State of the role permission. Choices:
|
Notes
Note
A detailed guide about cloudstack modules can be found in the CloudStack Cloud Guide.
This module supports check mode.
Examples
- name: Create a role permission
ngine_io.cloudstack.cs_role_permission:
role: My_Custom_role
name: createVPC
permission: allow
description: My comments
- name: Remove a role permission
ngine_io.cloudstack.cs_role_permission:
state: absent
role: My_Custom_role
name: createVPC
- name: Update a system role permission
ngine_io.cloudstack.cs_role_permission:
role: Domain Admin
name: createVPC
permission: deny
- name: Update rules order. Move the rule at the top of list
ngine_io.cloudstack.cs_role_permission:
role: Domain Admin
name: createVPC
parent: 0
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
---|---|
The description of the role permission Returned: success Sample: “Deny createVPC for users” |
|
The ID of the role permission. Returned: success Sample: “a6f7a5fc-43f8-11e5-a151-feff819cdc9f” |
|
The API name of the permission. Returned: success Sample: “createVPC” |
|
The permission type of the api name. Returned: success Sample: “allow” |
|
The ID of the role to which the role permission belongs. Returned: success Sample: “c6f7a5fc-43f8-11e5-a151-feff819cdc7f” |
Authors
David Passante (@dpassante)