stephrobert.scaleway.lb_certificate module – Manage a Scaleway Load Balancer certificate

Note

This module is part of the stephrobert.scaleway collection (version 0.7.0).

It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install stephrobert.scaleway. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: stephrobert.scaleway.lb_certificate.

New in stephrobert.scaleway 0.1.0

Synopsis

  • Update the name of a particular SSL/TLS certificate, specified by its certificate ID.

  • The module reads the resource first and writes the whole body, because this operation replaces the resource: fields you do not set keep the value the API returns. A second run reports no change.

Requirements

The below requirements are needed on the host that executes this module.

  • scaleway >= 2.9.0

Parameters

Parameter

Comments

access_key

string

Scaleway API access key.

api_allow_insecure

boolean

Allow the API endpoint to be reached without verifying its TLS certificate.

Falls back to the Scaleway configuration file, then to false.

Choices:

  • false

  • true

api_timeout

integer

Seconds allowed for a single API call, connection and read.

Without a limit a silent connection would hang the module forever: the Scaleway SDK issues its requests with no timeout at all.

This bounds a single call, not a whole wait. Modules that can wait for a state bound the overall wait separately.

Default: 60

api_url

string

URL of the Scaleway API endpoint.

Point it at a local emulator to exercise a playbook without credentials.

Falls back to the Scaleway configuration file, then to https://api.scaleway.com. It carries no module default on purpose: a default is never unset, so it would always override the profile.

certificate_id

string / required

Certificate ID.

config_file

path

Path to the Scaleway configuration file.

name

string / required

Certificate name.

organization_id

string

Default Organization ID used when an operation does not name one.

profile

string

Name of the profile to read in the Scaleway configuration file.

project_id

string

Default Project ID used when an operation does not name one.

secret_key

string

Scaleway API secret key.

user_agent

string

Value of the User-Agent header sent to the API.

zone

string / required

The zone you want to target

Choices:

  • "fr-par-1"

  • "fr-par-2"

  • "nl-ams-1"

  • "nl-ams-2"

  • "nl-ams-3"

  • "pl-waw-1"

  • "pl-waw-2"

  • "pl-waw-3"

Attributes

Attribute

Support

Description

check_mode

Support: full

In check mode the module reads the resource and compares it, then reports what it would write without writing it.

diff_mode

Support: full

The module reports the fields that differ, read through the same projection the comparison uses.

Notes

Note

  • Every option can be set from its environment variable, respectively SCW_PROFILE, SCW_CONFIG_PATH, SCW_ACCESS_KEY, SCW_SECRET_KEY, SCW_API_URL, SCW_DEFAULT_ORGANIZATION_ID and SCW_DEFAULT_PROJECT_ID.

  • Module options take precedence over environment variables, which take precedence over the configuration file.

Examples

# The module reads the resource, compares, and writes only what
# differs: run it twice and the second run reports no change.
#
# Check mode compares without writing, and `--diff` shows what would
# change. A parameter you do not pass is a parameter the module does
# not touch.

- name: Update a Scaleway Load Balancer certificate
  stephrobert.scaleway.lb_certificate:
    zone: fr-par-1
    certificate_id: 11111111-2222-3333-4444-555555555555
    name: my-certificate
  register: result
- name: Preview the change on a Scaleway Load Balancer certificate without writing
  stephrobert.scaleway.lb_certificate:
    zone: fr-par-1
    certificate_id: 11111111-2222-3333-4444-555555555555
    name: my-certificate
  register: result
  check_mode: true
  diff: true

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

resource

dictionary

Get information for a particular SSL/TLS certificate, specified by its certificate ID. The response returns full details of the certificate, including its type, main domain name, and alternative domain names.

Returned: success

common_name

string

Main domain name of certificate.

Returned: when the API returns it

created_at

string

Date on which the certificate was created. (RFC 3339 format)

Returned: when the API returns it

fingerprint

string

Identifier (SHA-1) of the certificate.

Returned: when the API returns it

id

string

Certificate ID.

Returned: when the API returns it

lb

dictionary

Load Balancer object the certificate is attached to.

Returned: when the API returns it

name

string

Certificate name.

Returned: when the API returns it

not_valid_after

string

Upper validity bound. (RFC 3339 format)

Returned: when the API returns it

not_valid_before

string

Lower validity bound. (RFC 3339 format)

Returned: when the API returns it

status

string

Certificate status.

Returned: when the API returns it

status_details

string

Additional information about the certificate status (useful in case of certificate generation failure, for example).

Returned: when the API returns it

subject_alternative_name

list / elements=string

Alternative domain names.

Returned: when the API returns it

type

string

Certificate type (Let’s Encrypt or custom).

Returned: when the API returns it

updated_at

string

Date on which the certificate was last updated. (RFC 3339 format)

Returned: when the API returns it

Authors

  • Stéphane Robert (@stephrobert)