stephrobert.scaleway.instance_security_group module – Manage a Scaleway Instance security group

Note

This module is part of the stephrobert.scaleway collection (version 0.7.0).

It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install stephrobert.scaleway. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: stephrobert.scaleway.instance_security_group.

New in stephrobert.scaleway 0.1.0

Synopsis

  • Update the properties of security group.

  • The module reads the resource first and writes only the fields that differ, so a second run reports no change.

Requirements

The below requirements are needed on the host that executes this module.

  • scaleway >= 2.9.0

Parameters

Parameter

Comments

access_key

string

Scaleway API access key.

api_allow_insecure

boolean

Allow the API endpoint to be reached without verifying its TLS certificate.

Falls back to the Scaleway configuration file, then to false.

Choices:

  • false

  • true

api_timeout

integer

Seconds allowed for a single API call, connection and read.

Without a limit a silent connection would hang the module forever: the Scaleway SDK issues its requests with no timeout at all.

This bounds a single call, not a whole wait. Modules that can wait for a state bound the overall wait separately.

Default: 60

api_url

string

URL of the Scaleway API endpoint.

Point it at a local emulator to exercise a playbook without credentials.

Falls back to the Scaleway configuration file, then to https://api.scaleway.com. It carries no module default on purpose: a default is never unset, so it would always override the profile.

config_file

path

Path to the Scaleway configuration file.

description

string

Description of the security group.

To clear this field, write `description: “”`; omit the option to leave the current value untouched.

Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

enable_default_security

boolean

True to block SMTP on IPv4 and IPv6. This feature is read only, please open a support ticket if you need to make it configurable.

The contract marks this field clearable, but bool has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

Choices:

  • false

  • true

inbound_default_policy

string

Default inbound policy.

Choices:

  • "unknown_policy"

  • "accept"

  • "drop"

name

string

Name of the security group.

To clear this field, write `name: “”`; omit the option to leave the current value untouched.

Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

organization_default

boolean

Please use project_default instead.

Deprecated by the Scaleway API contract.

The contract marks this field clearable, but bool has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

Choices:

  • false

  • true

organization_id

string

Default Organization ID used when an operation does not name one.

outbound_default_policy

string

Default outbound policy.

Choices:

  • "unknown_policy"

  • "accept"

  • "drop"

profile

string

Name of the profile to read in the Scaleway configuration file.

project_default

boolean

True use this security group for future Instances created in this project.

The contract marks this field clearable, but bool has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

Choices:

  • false

  • true

project_id

string

Default Project ID used when an operation does not name one.

secret_key

string

Scaleway API secret key.

security_group_id

string / required

UUID of the security group. (UUID format)

stateful

boolean

True to set the security group as stateful.

The contract marks this field clearable, but bool has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

Choices:

  • false

  • true

tags

list / elements=string

Tags of the security group.

To clear this field, write `tags: []`; omit the option to leave the current value untouched.

Setting it to null is refused: this API reads null as “field not provided” and would change nothing.

user_agent

string

Value of the User-Agent header sent to the API.

zone

string / required

The zone you want to target

Choices:

  • "fr-par-1"

  • "fr-par-2"

  • "fr-par-3"

  • "nl-ams-1"

  • "nl-ams-2"

  • "nl-ams-3"

  • "pl-waw-1"

  • "pl-waw-2"

  • "pl-waw-3"

  • "it-mil-1"

Attributes

Attribute

Support

Description

check_mode

Support: full

In check mode the module reads the resource and compares it, then reports what it would write without writing it.

diff_mode

Support: full

The module reports the fields that differ, read through the same projection the comparison uses.

Notes

Note

  • Every option can be set from its environment variable, respectively SCW_PROFILE, SCW_CONFIG_PATH, SCW_ACCESS_KEY, SCW_SECRET_KEY, SCW_API_URL, SCW_DEFAULT_ORGANIZATION_ID and SCW_DEFAULT_PROJECT_ID.

  • Module options take precedence over environment variables, which take precedence over the configuration file.

Examples

# The module reads the resource, compares, and writes only what
# differs: run it twice and the second run reports no change.
#
# Check mode compares without writing, and `--diff` shows what would
# change. A parameter you do not pass is a parameter the module does
# not touch.

- name: Update a Scaleway Instance security group
  stephrobert.scaleway.instance_security_group:
    zone: fr-par-1
    security_group_id: 11111111-2222-3333-4444-555555555555
    name: my-security-group
  register: result
- name: Preview the change on a Scaleway Instance security group without writing
  stephrobert.scaleway.instance_security_group:
    zone: fr-par-1
    security_group_id: 11111111-2222-3333-4444-555555555555
    name: my-security-group
  register: result
  check_mode: true
  diff: true

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

security_group

dictionary

Get the details of a security group with the specified ID.

Returned: success

creation_date

string

Security group creation date. (RFC 3339 format)

Returned: when the API returns it

description

string

Security group description.

Returned: when the API returns it

enable_default_security

boolean

True if SMTP is blocked on IPv4 and IPv6. This feature is read only, please open a support ticket if you need to make it configurable.

Returned: when the API returns it

id

string

Security group unique ID.

Returned: when the API returns it

inbound_default_policy

string

Default inbound policy.

Returned: when the API returns it

modification_date

string

Security group modification date. (RFC 3339 format)

Returned: when the API returns it

name

string

Security group name.

Returned: when the API returns it

organization

string

Security group Organization ID.

Returned: when the API returns it

organization_default

boolean

True if it is your default security group for this Organization ID.

Deprecated by the Scaleway API contract.

Returned: when the API returns it

outbound_default_policy

string

Default outbound policy.

Returned: when the API returns it

project

string

Security group Project ID.

Returned: when the API returns it

project_default

boolean

True if it is your default security group for this Project ID.

Returned: when the API returns it

servers

list / elements=dictionary

List of Instances attached to this security group.

Returned: when the API returns it

state

string

The state of the security group. Set to `syncing` (until the changes. Are applied) when the security group is updated (e.g., rules added, modified, or deleted) or when it is attached to or detached from a server’s public network interface.

Returned: when the API returns it

stateful

boolean

Defines whether the security group is stateful.

Returned: when the API returns it

tags

list / elements=string

Security group tags.

Returned: when the API returns it

zone

string

Zone in which the security group is located.

Returned: when the API returns it

Authors

  • Stéphane Robert (@stephrobert)