-
Notifications
You must be signed in to change notification settings - Fork 10
/
Copy pathelasticsearch_role.py
94 lines (76 loc) · 2.69 KB
/
elasticsearch_role.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
#!/usr/bin/python
# Copyright (c) 2024, Tobias Bauriedel <[email protected]>
# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or
# https://www.gnu.org/licenses/gpl-3.0.txt)
from __future__ import (absolute_import, division, print_function)
__metaclass__ = type
from ansible.module_utils.basic import AnsibleModule
from ansible_collections.netways.elasticstack.plugins.module_utils.elasticsearch_role import (
Role
)
def run_module():
'''
Elasticsearch user management.
```
netways.elasticstack.elasticsearch_role:
name: new-role
cluster:
- manage_own_api_key
- delegate_pki
indicies:
- names:
- foobar
privileges:
- read
- write
state: present
host: https://localhost:9200
auth_user: elastic
auth_pass: changeMe123!
verify_certs: false
ca_certs: /etc/elasticsearch/certs/http_ca.crt
```
'''
# get role
# https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-role.html
# create or update role
# https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html
module = AnsibleModule(
argument_spec=dict(
# User args
name=dict(type=str, required=True),
cluster=dict(type=list, required=False),
indicies=dict(type=list, required=False),
state=dict(type=str, required=False, default='present'),
# Auth args
host=dict(type=str, required=True),
auth_user=dict(type=str, required=True),
auth_pass=dict(type=str, required=True, no_log=True),
ca_certs=dict(type=str, required=False),
verify_certs=dict(type=bool, required=False, default=True)
)
)
result = dict(
failed=False,
changed=False
)
if module.params['state'] != 'absent' and module.params['state'] != 'present':
result['stderr'] = "Invalid state given. Please use 'absent' or 'present'"
result['failed'] = True
module.exit_json(**result)
role = Role(
result=result,
role_name=module.params['name'],
cluster=module.params['cluster'],
indicies=module.params['indicies'],
state=module.params['state'],
host=module.params['host'],
auth_user=module.params['auth_user'],
auth_pass=module.params['auth_pass'],
ca_certs=module.params['ca_certs'],
verify_certs=module.params['verify_certs'],
)
result = role.return_result()
module.exit_json(**result)
if __name__ == "__main__":
run_module()