purestorage.flashblade.purefb_keytabs module – Manage FlashBlade Kerberos Keytabs
Note
This module is part of the purestorage.flashblade collection (version 1.26.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install purestorage.flashblade.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: purestorage.flashblade.purefb_keytabs.
New in purestorage.flashblade 1.6.0
Synopsis
Manage Kerberos Keytabs for FlashBlades
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.9
py-pure-client
netaddr
datetime
pytz
distro
pycountry
urllib3
Parameters
Parameter |
Comments |
|---|---|
FlashBlade API token for admin privileged user. |
|
ID of the API Client that issues the identity token. Used with private_key_file. |
|
Disable insecure certificate warnings Choices:
|
|
FlashBlade management IP address or Hostname. |
|
Format of the keytab file Choices:
|
|
A pre-signed JWT to authenticate with, as an alternative to api_token. The token is exchanged by the array for a short-lived access token. Requires a matching API Client to be registered on the array (see purestorage.flashblade.purefb_apiclient). |
|
The API Client’s trusted identity issuer registered on the array. Used with private_key_file. |
|
Key ID of the API Client that issues the identity token. Used with private_key_file. |
|
Name of file holding Keytab |
|
Name of the Keytab Must include prefix and suffix |
|
Only required for import or rotate Prefix to use for naming the files slots Specifying a file entry prefix is required because a single keytab file can contain multiple keytab entries in multiple slots. If not provided for import the current AD Account name will be used. |
|
Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token. Requires client_id, key_id, issuer and username. |
|
Password protecting private_key_file, if encrypted. |
|
Manage Kerberos Keytabs Choices:
|
|
Username the issued token should be granted to. Must be a valid user on the array. Used with private_key_file. |
Notes
Note
You must set
PUREFB_URLandPUREFB_APIenvironment variables if fb_url and api_token arguments are not passed to the module directlyToken-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flashblade.purefb_apiclient
Examples
- name: Import a binary keytab
purestorage.flashblade.purefb_keytabs:
state: import
prefix: example
keytab_file: pure_krb.keytab
filetype: binary
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Import a base64 keytab
purestorage.flashblade.purefb_keytabs:
state: import
prefix: example
keytab_file: pure_krb.keytab.mime
filetype: base64
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Export a keytab
purestorage.flashblade.purefb_keytabs:
state: export
name: example.3
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
register: download_file
- name: Delete a keytab
purestorage.flashblade.purefb_keytabs:
state: absent
name: example.3
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Rotate current AD account keytabs
purestorage.flashblade.purefb_keytabs:
state: rotate
fb_url: 10.10.10.2
- name: Rotate AD account keytabs by creating new series
purestorage.flashblade.purefb_keytabs:
state: rotate
name: next_prefix
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
Name of file containing exported keytab Returned: When using export option Sample: |