purestorage.flasharray.purefa_default_protection module – Manage SafeMode default protection for a Everpure FlashArray

Note

This module is part of the purestorage.flasharray collection (version 1.43.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install purestorage.flasharray. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: purestorage.flasharray.purefa_default_protection.

New in purestorage.flasharray 1.14.0

Synopsis

  • Configure automatic protection group membership for new volumes and copied volumes array wide, or at the pod level.

  • Requires a minimum of Purity 6.3.4

Requirements

The below requirements are needed on the host that executes this module.

  • python >= 3.3

  • purestorage >= 1.19

  • py-pure-client >= 1.26.0

  • netaddr

  • requests

  • pycountry

  • urllib3

Parameters

Parameter

Comments

api_token

string

FlashArray API token for admin privileged user.

client_id

string

added in purestorage.flasharray 1.43.0

ID of the API Client that issues the identity token.

Used with private_key_file.

context

string

added in purestorage.flasharray 1.37.0

Name of fleet member on which to perform the operation.

This requires the array receiving the request is a member of a fleet and the context name to be a member of the same fleet.

Default: ""

disable_warnings

boolean

added in purestorage.flasharray 1.29.0

Disable insecure certificate warnings in debug logs

Choices:

  • false ← (default)

  • true

fa_url

string

FlashArray management IPv4 address or Hostname.

id_token

string

added in purestorage.flasharray 1.43.0

A pre-signed JWT to authenticate with, as an alternative to api_token.

The token is exchanged by the array for a short-lived access token.

Requires a matching API Client to be registered on the array (see purestorage.flasharray.purefa_apiclient).

issuer

string

added in purestorage.flasharray 1.43.0

The API Client’s trusted identity issuer registered on the array.

Used with private_key_file.

key_id

string

added in purestorage.flasharray 1.43.0

Key ID of the API Client that issues the identity token.

Used with private_key_file.

name

list / elements=string / required

The name of the protection group to assign or remove as default for the scope.

If scope is pod only the short-name for the pod protection group is needed. See examples

pod

string

name of the pod to apply the default protection to.

Only required for scope is pod

private_key_file

string

added in purestorage.flasharray 1.43.0

Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token.

Requires client_id, key_id, issuer and username.

private_key_password

string

added in purestorage.flasharray 1.43.0

Password protecting private_key_file, if encrypted.

scope

string

The scope of the default protection group

Choices:

  • "array" ← (default)

  • "pod"

state

string

Define whether to add or delete the protection group to the default list

Choices:

  • "absent"

  • "present" ← (default)

username

string

added in purestorage.flasharray 1.43.0

Username the issued token should be granted to.

Must be a valid user on the array. Used with private_key_file.

Notes

Note

  • This module requires the purestorage and py-pure-client Python libraries.

  • Additional Python libraries may be required for specific modules.

  • You must set PUREFA_URL and PUREFA_API environment variables if fa_url and api_token arguments are not passed to the module directly.

  • Token-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flasharray.purefa_apiclient.

Examples

- name: Add protection group foo::bar as default for pod foo
  purestorage.flasharray.purefa_default_protection:
    name: bar
    pod: foo
    scope: pod
    fa_url: 10.10.10.2
    api_token: e31060a7-21fc-e277-6240-25983c6c4592

- name: Add protection group foo as default for array
  purestorage.flasharray.purefa_default_protection:
    name: foo
    scope: array
    fa_url: 10.10.10.2
    api_token: e31060a7-21fc-e277-6240-25983c6c4592

- name: Remove protection group foo from array default protection
  purestorage.flasharray.purefa_default_protection:
    name: foo
    scope: array
    fa_url: 10.10.10.2
    api_token: e31060a7-21fc-e277-6240-25983c6c4592
    state: absent

- name: Clear default protection for the array
  purestorage.flasharray.purefa_default_protection:
    name: ''
    scope: array
    fa_url: 10.10.10.2
    api_token: e31060a7-21fc-e277-6240-25983c6c4592
    state: absent

Authors

  • Everpure Ansible Team (@sdodsley)