purestorage.flashblade.purefb_s3_export_policy module – Manage FlashBlade S3 Export Policies

Note

This module is part of the purestorage.flashblade collection (version 1.26.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install purestorage.flashblade. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: purestorage.flashblade.purefb_s3_export_policy.

New in purestorage.flashblade 1.26.0

Synopsis

  • Create, update, rename or delete FlashBlade S3 Export Policies and their rules.

  • An S3 export policy is a reusable object-store policy that controls which buckets in an object-store account are visible for S3 through an object-store account export.

  • The policy shell (name, enabled flag, inline rules) is managed via the /s3-export-policies endpoint. The set of rules is reconciled against the /s3-export-policies/rules sub-resource on update.

Requirements

The below requirements are needed on the host that executes this module.

  • python >= 3.9

  • py-pure-client

  • netaddr

  • datetime

  • pytz

  • distro

  • pycountry

  • urllib3

Parameters

Parameter

Comments

api_token

string

FlashBlade API token for admin privileged user.

client_id

string

added in purestorage.flashblade 1.26.0

ID of the API Client that issues the identity token.

Used with private_key_file.

context

string

Name of fleet member on which to perform the operation.

This requires the array receiving the request is a member of a fleet and the context name to be a member of the same fleet.

Default: ""

disable_warnings

boolean

added in purestorage.flashblade 1.18.0

Disable insecure certificate warnings

Choices:

  • false ← (default)

  • true

enabled

boolean

If true the policy is enabled.

Defaults to true on creation if not specified.

Choices:

  • false

  • true

fb_url

string

FlashBlade management IP address or Hostname.

id_token

string

added in purestorage.flashblade 1.26.0

A pre-signed JWT to authenticate with, as an alternative to api_token.

The token is exchanged by the array for a short-lived access token.

Requires a matching API Client to be registered on the array (see purestorage.flashblade.purefb_apiclient).

issuer

string

added in purestorage.flashblade 1.26.0

The API Client’s trusted identity issuer registered on the array.

Used with private_key_file.

key_id

string

added in purestorage.flashblade 1.26.0

Key ID of the API Client that issues the identity token.

Used with private_key_file.

name

string / required

Name of the S3 export policy.

private_key_file

string

added in purestorage.flashblade 1.26.0

Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token.

Requires client_id, key_id, issuer and username.

private_key_password

string

added in purestorage.flashblade 1.26.0

Password protecting private_key_file, if encrypted.

rename

string

New name for the S3 export policy.

Only takes effect when the policy already exists.

rules

list / elements=dictionary

Ordered list of rules to apply to the policy.

When supplied on create, rules are materialised in a single round trip.

When supplied on update, rules are reconciled against the current state - missing rules are added, divergent rules are patched, and rules not in this list are removed.

Omit this option entirely to leave existing rules untouched.

actions

list / elements=string

List of actions granted by this rule.

Currently only pure:S3Access is supported.

effect

string

Effect of this rule.

Choices:

  • "allow"

  • "deny"

name

string / required

Name of the rule. Used as the idempotency key.

resources

list / elements=string

List of bucket resources from the account that this rule applies to.

Glob patterns are supported (for example my-bucket* or *).

state

string

Define whether the S3 export policy should exist or not.

Choices:

  • "absent"

  • "present" ← (default)

username

string

added in purestorage.flashblade 1.26.0

Username the issued token should be granted to.

Must be a valid user on the array. Used with private_key_file.

Notes

Note

  • You must set PUREFB_URL and PUREFB_API environment variables if fb_url and api_token arguments are not passed to the module directly

  • Token-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flashblade.purefb_apiclient

Examples

- name: Create an S3 export policy with two rules
  purestorage.flashblade.purefb_s3_export_policy:
    name: my_export_policy
    enabled: true
    rules:
      - name: allow_all_buckets
        actions:
          - "pure:S3Access"
        effect: allow
        resources:
          - "*"
      - name: deny_finance
        actions:
          - "pure:S3Access"
        effect: deny
        resources:
          - "finance-*"
    fb_url: 10.10.10.2
    api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3

- name: Disable an existing S3 export policy
  purestorage.flashblade.purefb_s3_export_policy:
    name: my_export_policy
    enabled: false
    fb_url: 10.10.10.2
    api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3

- name: Rename an S3 export policy
  purestorage.flashblade.purefb_s3_export_policy:
    name: my_export_policy
    rename: tenant_a_export_policy
    fb_url: 10.10.10.2
    api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3

- name: Delete an S3 export policy
  purestorage.flashblade.purefb_s3_export_policy:
    name: tenant_a_export_policy
    state: absent
    fb_url: 10.10.10.2
    api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3

Authors

  • Pure Storage Ansible Team (@sdodsley)