purestorage.flashblade.purefb_bucket_access module – Manage FlashBlade bucket access policies

Note

This module is part of the purestorage.flashblade collection (version 1.26.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install purestorage.flashblade. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: purestorage.flashblade.purefb_bucket_access.

New in purestorage.flashblade 1.20.0

Synopsis

  • Manage object store bucket policies.

  • This modules allows the management of both bucket access and cross-origin resource sharing policies and their associated rules.

Requirements

The below requirements are needed on the host that executes this module.

  • python >= 3.9

  • py-pure-client

  • netaddr

  • datetime

  • pytz

  • distro

  • pycountry

  • urllib3

Parameters

Parameter

Comments

actions

list / elements=string

List of permissions to grant.

System-wide policy rules cannot be deleted or modified

Currently only s3:GetObject is allowed

Choices:

  • "s3:*"

  • "s3:AbortMultipartUpload"

  • "s3:BypassGovernanceRetention"

  • "s3:CreateBucket"

  • "s3:DeleteBucket"

  • "s3:DeleteObject"

  • "s3:DeleteObjectVersion"

  • "s3:ExtendSafemodeRetentionPeriod"

  • "s3:GetBucketAcl"

  • "s3:GetBucketLocation"

  • "s3:GetBucketVersioning"

  • "s3:GetLifecycleConfiguration"

  • "s3:GetObject" ← (default)

  • "s3:GetObjectAcl"

  • "s3:GetObjectLegalHold"

  • "s3:GetObjectLockConfiguration"

  • "s3:GetObjectRetention"

  • "s3:GetObjectTagging"

  • "s3:GetObjectVersion"

  • "s3:GetObjectVersionTagging"

  • "s3:ListAllMyBuckets"

  • "s3:ListBucket"

  • "s3:ListBucketMultipartUploads"

  • "s3:ListBucketVersions"

  • "s3:ListMultipartUploadParts"

  • "s3:PutBucketVersioning"

  • "s3:PutLifecycleConfiguration"

  • "s3:PutObject"

  • "s3:PutObjectLegalHold"

  • "s3:PutObjectLockConfiguration"

  • "s3:PutObjectRetention"

  • "s3:ResolveSafemodeConflicts"

Default: ["s3:GetObject"]

api_token

string

FlashBlade API token for admin privileged user.

client_id

string

added in purestorage.flashblade 1.26.0

ID of the API Client that issues the identity token.

Used with private_key_file.

context

string

added in purestorage.flashblade 1.22.0

Name of fleet member on which to perform the operation.

This requires the array receiving the request is a member of a fleet and the context name to be a member of the same fleet.

Default: ""

disable_warnings

boolean

added in purestorage.flashblade 1.18.0

Disable insecure certificate warnings

Choices:

  • false ← (default)

  • true

effect

string

Allow S3 requests that match all of the actions item selected. Rules are additive.

Choices:

  • "allow" ← (default)

  • "deny"

fb_url

string

FlashBlade management IP address or Hostname.

headers

list / elements=string

A list of headers that are permitted to be included in cross-origin requests to access a bucket.

The only currently supported allowed header is ‘*’.

Default: ["*"]

id_token

string

added in purestorage.flashblade 1.26.0

A pre-signed JWT to authenticate with, as an alternative to api_token.

The token is exchanged by the array for a short-lived access token.

Requires a matching API Client to be registered on the array (see purestorage.flashblade.purefb_apiclient).

issuer

string

added in purestorage.flashblade 1.26.0

The API Client’s trusted identity issuer registered on the array.

Used with private_key_file.

key_id

string

added in purestorage.flashblade 1.26.0

Key ID of the API Client that issues the identity token.

Used with private_key_file.

methods

list / elements=string

A list of HTTP methods that are permitted for cross-origin requests to access a bucket.

The only currently supported combination of allowed methods is all methods.

Choices:

  • "GET" ← (default)

  • "PUT" ← (default)

  • "HEAD" ← (default)

  • "POST" ← (default)

  • "DELETE" ← (default)

Default: ["GET", "PUT", "HEAD", "POST", "DELETE"]

name

string / required

Name of Object Store bucket the policy applies to.

origins

list / elements=string

A list of origins (domains) that are permitted to make cross-origin requests to access a bucket.

The only currently supported allowed origin is ‘*’.

Default: ["*"]

policy_type

string

Type of policy

Choices:

  • "access" ← (default)

  • "cors"

principals

boolean

Defines if the rule will apply to all object store users regardless of their origin or principal.

Choices:

  • false

  • true ← (default)

private_key_file

string

added in purestorage.flashblade 1.26.0

Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token.

Requires client_id, key_id, issuer and username.

private_key_password

string

added in purestorage.flashblade 1.26.0

Password protecting private_key_file, if encrypted.

resources

list / elements=string

The list of resources which this rule applies to.

The only currently supported resource is all objects in a bucket to which the parent policy belongs.

Default: ["*"]

rule

string

Name of the rule in the Bucket Policy

Required if state is present

state

string

Create or delete policy or rule.

Choices:

  • "absent"

  • "present" ← (default)

username

string

added in purestorage.flashblade 1.26.0

Username the issued token should be granted to.

Must be a valid user on the array. Used with private_key_file.

Notes

Note

  • You must set PUREFB_URL and PUREFB_API environment variables if fb_url and api_token arguments are not passed to the module directly

  • Token-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flashblade.purefb_apiclient

Examples

- name: Create a bucket access policy rule for bucket bar
  purestorage.flashblade.purefb_bucket_policy:
    rule: foo
    name: bar
    policy_type: access
    fb_url: 10.10.10.2
    api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Create a CORS policy rule for bucket bar
  purestorage.flashblade.purefb_bucket_policy:
    rule: foo
    name: bar
    policy_type: cors
    fb_url: 10.10.10.2
    api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Delete bucket policy rule foo from bucket bar
  purestorage.flashblade.purefb_bucket_policy:
    rule: foo
    name: bar
    policy_type: access
    state: absent
    fb_url: 10.10.10.2
    api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Delete all bucket policy rules from bucket bar
  purestorage.flashblade.purefb_bucket_policy:
    name: bar
    policy_type: access
    state: absent
    fb_url: 10.10.10.2
    api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6

Authors

  • Everpure Ansible Team (@sdodsley)