purestorage.flashblade.purefb_user module – Create, modify or delete FlashBlade user accounts
Note
This module is part of the purestorage.flashblade collection (version 1.26.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install purestorage.flashblade.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: purestorage.flashblade.purefb_user.
New in purestorage.flashblade 1.0.0
Synopsis
Modify user on a Pure Stoage FlashBlade.
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.9
py-pure-client
netaddr
datetime
pytz
distro
pycountry
urllib3
Parameters
Parameter |
Comments |
|---|---|
Whether the user is in the AD system Not required for local users Choices:
|
|
Define whether to create an API token for this user Token can be exposed using the debug module Choices:
|
|
FlashBlade API token for admin privileged user. |
|
Clear user lockout flag Choices:
|
|
ID of the API Client that issues the identity token. Used with private_key_file. |
|
Disable insecure certificate warnings Choices:
|
|
FlashBlade management IP address or Hostname. |
|
A pre-signed JWT to authenticate with, as an alternative to api_token. The token is exchanged by the array for a short-lived access token. Requires a matching API Client to be registered on the array (see purestorage.flashblade.purefb_apiclient). |
|
The API Client’s trusted identity issuer registered on the array. Used with private_key_file. |
|
Key ID of the API Client that issues the identity token. Used with private_key_file. |
|
The name of the user account |
|
If changing an existing password, you must provide the old password for security |
|
Password for the local user. |
|
Path to the PEM RSA private key used to sign an identity token, as an alternative to api_token. Requires client_id, key_id, issuer and username. |
|
Password protecting private_key_file, if encrypted. |
|
The API clients PEM formatted (Base64 encoded) RSA public key. Include the —–BEGIN PUBLIC KEY—– and —–END PUBLIC KEY—– lines |
|
Sets the local user’s access level to the system Choices:
|
|
Create, delete or update local user account Choices:
|
|
The duration of API token validity. Valid values are weeks (w), days(d), hours(h), minutes(m) and seconds(s). Default: |
|
Username the issued token should be granted to. Must be a valid user on the array. Used with private_key_file. |
Notes
Note
You must set
PUREFB_URLandPUREFB_APIenvironment variables if fb_url and api_token arguments are not passed to the module directlyToken-based authentication (id_token, or private_key_file with client_id, key_id, issuer and username) may be used as an alternative to api_token, and requires a matching API Client registered on the array via purestorage.flashblade.purefb_apiclient
Examples
- name: Change password for local user (NOT IDEMPOTENT)
purestorage.flashblade.purefb_user:
name: pureuser
password: anewpassword
old_password: apassword
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Set public key for user
purestorage.flashblade.purefb_user:
name: fred
public_key: "{{lookup('file', 'public_pem_file') }}"
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Clear user lockout
purestorage.flashblade.purefb_user:
name: fred
clear_lock: true
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6
- name: Create an API token (TTL of 2 days) and assign a public key to an AD user
purestorage.flashblade.purefb_user:
name: ansible-ad
ad_user: true
public_key: "{{lookup('file', 'id_rsa.pub') }}"
api: true
timeout: 2d
fb_url: 10.10.10.2
api_token: T-9f276a18-50ab-446e-8a0c-666a3529a1b6