purestorage.flasharray.purefa_kmip module – Manage FlashArray KMIP server objects
Note
This module is part of the purestorage.flasharray collection (version 1.43.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install purestorage.flasharray.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: purestorage.flasharray.purefa_kmip.
New in purestorage.flasharray 1.10.0
Synopsis
Manage FlashArray KMIP Server objects
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.3
purestorage >= 1.19
py-pure-client >= 1.26.0
netaddr
requests
pycountry
urllib3
Parameters
Parameter |
Comments |
|---|---|
FlashArray API token for admin privileged user. |
|
The text of the CA certificate for the KMIP server. Includes the “-----BEGIN CERTIFICATE-----” and “-----END CERTIFICATE-----” lines Does not exceed 3000 characters in length |
|
Name of existing certificate used to verify FlashArray authenticity to the KMIP server. Use the purestorage.flasharray.purefa_certs module to create certificates. |
|
ID of the API Client that issues the identity token. Used with private_key_file. |
|
Disable insecure certificate warnings in debug logs Choices:
|
|
FlashArray management IPv4 address or Hostname. |
|
A pre-signed JWT to authenticate with, as an alternative to api_token. The token is exchanged by the array for a short-lived access token. Requires a matching API Client to be registered on the array (see purestorage.flasharray.purefa_apiclient). |
|
The API Client’s trusted identity issuer registered on the array. Used with private_key_file. |
|
Key ID of the API Client that issues the identity token. Used with private_key_file. |
|
Name of the KMIP server object |
|
Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token. Requires client_id, key_id, issuer and username. |
|
Password protecting private_key_file, if encrypted. |
|
Action for the module to perform Choices:
|
|
A list of URIs for the configured KMIP servers. |
|
Username the issued token should be granted to. Must be a valid user on the array. Used with private_key_file. |
Notes
Note
This module requires the
purestorageandpy-pure-clientPython libraries.Additional Python libraries may be required for specific modules.
You must set
PUREFA_URLandPUREFA_APIenvironment variables if fa_url and api_token arguments are not passed to the module directly.Token-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flasharray.purefa_apiclient.
Examples
- name: Create KMIP object
purestorage.flasharray.purefa_kmip:
name: foo
certificate: bar
ca_certificate: "{{lookup('file', 'example.crt') }}"
uris:
- 1.1.1.1:8888
- 2.3.3.3:9999
fa_url: 10.10.10.2
api_token: e31060a7-21fc-e277-6240-25983c6c4592
- name: Delete KMIP object
purestorage.flasharray.purefa_kmip:
name: foo
state: absent
fa_url: 10.10.10.2
api_token: e31060a7-21fc-e277-6240-25983c6c4592
- name: Update KMIP object
purestorage.flasharray.purefa_kmip:
name: foo
ca_certificate: "{{lookup('file', 'example2.crt') }}"
uris:
- 3.3.3.3:8888
- 4.4.4.4:9999
fa_url: 10.10.10.2
api_token: e31060a7-21fc-e277-6240-25983c6c4592