purestorage.flashblade.purefb_s3acc_export module – Manage FlashBlade Object Store Account exports
Note
This module is part of the purestorage.flashblade collection (version 1.26.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install purestorage.flashblade.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: purestorage.flashblade.purefb_s3acc_export.
New in purestorage.flashblade 1.26.0
Synopsis
Create, update or delete a FlashBlade object-store account export.
An account export binds an object-store account to a server using an S3 export policy, making the account’s buckets visible for S3 through that server.
The account export is uniquely identified by the (account, server) pair.
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.9
py-pure-client
netaddr
datetime
pytz
distro
pycountry
urllib3
Parameters
Parameter |
Comments |
|---|---|
Name of the object store account to export. |
|
FlashBlade API token for admin privileged user. |
|
ID of the API Client that issues the identity token. Used with private_key_file. |
|
Name of fleet member on which to perform the operation. This requires the array receiving the request is a member of a fleet and the context name to be a member of the same fleet. Default: |
|
Disable insecure certificate warnings Choices:
|
|
If Defaults to Choices:
|
|
FlashBlade management IP address or Hostname. |
|
A pre-signed JWT to authenticate with, as an alternative to api_token. The token is exchanged by the array for a short-lived access token. Requires a matching API Client to be registered on the array (see purestorage.flashblade.purefb_apiclient). |
|
The API Client’s trusted identity issuer registered on the array. Used with private_key_file. |
|
Key ID of the API Client that issues the identity token. Used with private_key_file. |
|
Name of the S3 export policy used for the export. Required when creating a new account export. When supplied on update, the export will be re-pointed at the named policy. |
|
Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token. Requires client_id, key_id, issuer and username. |
|
Password protecting private_key_file, if encrypted. |
|
Name of the server the account will be exported on. |
|
Define whether the account export should exist or not. Choices:
|
|
Username the issued token should be granted to. Must be a valid user on the array. Used with private_key_file. |
Notes
Note
You must set
PUREFB_URLandPUREFB_APIenvironment variables if fb_url and api_token arguments are not passed to the module directlyToken-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flashblade.purefb_apiclient
Examples
- name: Export account acme on server fb-01 using policy acme-export
purestorage.flashblade.purefb_s3acc_export:
account: acme
server: fb-01
policy: acme-export
fb_url: 10.10.10.2
api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3
- name: Disable an existing account export
purestorage.flashblade.purefb_s3acc_export:
account: acme
server: fb-01
enabled: false
fb_url: 10.10.10.2
api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3
- name: Re-point an existing account export at a different policy
purestorage.flashblade.purefb_s3acc_export:
account: acme
server: fb-01
policy: acme-export-v2
fb_url: 10.10.10.2
api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3
- name: Delete an account export
purestorage.flashblade.purefb_s3acc_export:
account: acme
server: fb-01
state: absent
fb_url: 10.10.10.2
api_token: T-68618f31-0c9e-4e57-aa44-5306a2cf10e3