stephrobert.scaleway.instance_security_group_rule module – Manage a Scaleway Instance security group rule
Note
This module is part of the stephrobert.scaleway collection (version 0.7.0).
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install stephrobert.scaleway.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: stephrobert.scaleway.instance_security_group_rule.
New in stephrobert.scaleway 0.1.0
Synopsis
Update the properties of a rule from a specified security group.
The module reads the resource first and writes only the fields that differ, so a second run reports no change.
Requirements
The below requirements are needed on the host that executes this module.
scaleway >= 2.9.0
Parameters
Parameter |
Comments |
|---|---|
Scaleway API access key. |
|
Action to apply when the rule matches a packet. Choices:
|
|
Allow the API endpoint to be reached without verifying its TLS certificate. Falls back to the Scaleway configuration file, then to Choices:
|
|
Seconds allowed for a single API call, connection and read. Without a limit a silent connection would hang the module forever: the Scaleway SDK issues its requests with no timeout at all. This bounds a single call, not a whole wait. Modules that can wait for a state bound the overall wait separately. Default: |
|
URL of the Scaleway API endpoint. Point it at a local emulator to exercise a playbook without credentials. Falls back to the Scaleway configuration file, then to |
|
Path to the Scaleway configuration file. |
|
Beginning of the range of ports this rule applies to (inclusive). If 0 is provided, unset the parameter. The contract marks this field clearable, but int has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing. |
|
End of the range of ports this rule applies to (inclusive). If 0 is provided, unset the parameter. The contract marks this field clearable, but int has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing. |
|
Direction the rule applies to. Choices:
|
|
Range of IP addresses these rules apply to. (IP network) To clear this field, write `ip_range: “”`; omit the option to leave the current value untouched. Setting it to null is refused: this API reads null as “field not provided” and would change nothing. |
|
Default Organization ID used when an operation does not name one. |
|
Position of this rule in the security group rules list. The contract marks this field clearable, but int has no empty value, so the API cannot clear it. Setting it to null is refused: this API reads null as “field not provided” and would change nothing. |
|
Name of the profile to read in the Scaleway configuration file. |
|
Default Project ID used when an operation does not name one. |
|
Protocol family this rule applies to. Choices:
|
|
Scaleway API secret key. |
|
UUID of the security group. (UUID format) |
|
UUID of the rule. (UUID format) |
|
Value of the User-Agent header sent to the API. |
|
The zone you want to target Choices:
|
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: full |
In check mode the module reads the resource and compares it, then reports what it would write without writing it. |
|
Support: full |
The module reports the fields that differ, read through the same projection the comparison uses. |
Notes
Note
Every option can be set from its environment variable, respectively
SCW_PROFILE,SCW_CONFIG_PATH,SCW_ACCESS_KEY,SCW_SECRET_KEY,SCW_API_URL,SCW_DEFAULT_ORGANIZATION_IDandSCW_DEFAULT_PROJECT_ID.Module options take precedence over environment variables, which take precedence over the configuration file.
Examples
# The module reads the resource, compares, and writes only what
# differs: run it twice and the second run reports no change.
#
# Check mode compares without writing, and `--diff` shows what would
# change. A parameter you do not pass is a parameter the module does
# not touch.
- name: Update a Scaleway Instance security group rule
stephrobert.scaleway.instance_security_group_rule:
zone: fr-par-1
security_group_id: 11111111-2222-3333-4444-555555555555
security_group_rule_id: 11111111-2222-3333-4444-555555555555
protocol: TCP
register: result
- name: Preview the change on a Scaleway Instance security group rule without writing
stephrobert.scaleway.instance_security_group_rule:
zone: fr-par-1
security_group_id: 11111111-2222-3333-4444-555555555555
security_group_rule_id: 11111111-2222-3333-4444-555555555555
protocol: TCP
register: result
check_mode: true
diff: true
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
Get details of a security group rule with the specified ID. Returned: success |
|
Action to apply when the rule matches a packet. Returned: when the API returns it |
|
Beginning of the range of ports this rule applies to (inclusive). This value will be set to null if protocol is ICMP or ANY. Returned: when the API returns it |
|
End of the range of ports this rule applies to (inclusive). This value will be set to null if protocol is ICMP or ANY, or if it is equal to dest_port_from. Returned: when the API returns it |
|
Direction the rule applies to. Returned: when the API returns it |
|
Indicates if this rule is editable. Rules with the value false will be ignored. Returned: when the API returns it |
|
Unique ID of the security group rule. Returned: when the API returns it |
|
(IP network) Returned: when the API returns it |
|
Position of this rule in the security group rules list. If several rules are passed with the same position, the resulting order is undefined. Returned: when the API returns it |
|
Protocol family this rule applies to. Returned: when the API returns it |
|
The zone you want to target Returned: when the API returns it |