Server IP : 85.214.239.14 / Your IP : 18.222.218.28 Web Server : Apache/2.4.62 (Debian) System : Linux h2886529.stratoserver.net 4.9.0 #1 SMP Tue Jan 9 19:45:01 MSK 2024 x86_64 User : www-data ( 33) PHP Version : 7.4.18 Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare, MySQL : OFF | cURL : OFF | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : OFF Directory : /proc/2/cwd/lib/python3/dist-packages/ansible_collections/ovirt/ovirt/plugins/modules/ |
Upload File : |
#!/usr/bin/python # -*- coding: utf-8 -*- # # Copyright (c) 2016 Red Hat, Inc. # # This file is part of Ansible # # Ansible is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # Ansible is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with Ansible. If not, see <http://www.gnu.org/licenses/>. # from __future__ import (absolute_import, division, print_function) __metaclass__ = type DOCUMENTATION = ''' --- module: ovirt_user short_description: Module to manage users in oVirt/RHV version_added: "1.0.0" author: "Ondra Machacek (@machacekondra)" description: - "Module to manage users in oVirt/RHV." options: name: description: - "Name of the user to manage. In most LDAPs it's I(uid) of the user, but in Active Directory you must specify I(UPN) of the user." required: true type: str state: description: - "Should the user be present/absent." choices: ['present', 'absent'] default: present type: str authz_name: description: - "Authorization provider of the user. In previous versions of oVirt/RHV known as domain." required: true aliases: ['domain'] type: str namespace: description: - "Namespace where the user resides. When using the authorization provider that stores users in the LDAP server, this attribute equals the naming context of the LDAP server." type: str ssh_public_key: description: - "The user public key." type: str version_added: 1.4.0 extends_documentation_fragment: ovirt.ovirt.ovirt ''' EXAMPLES = ''' # Examples don't contain auth parameter for simplicity, # look at ovirt_auth module to see how to reuse authentication: # Add user user1 from authorization provider example.com-authz - ovirt.ovirt.ovirt_user: name: user1 domain: example.com-authz # Add user user1 from authorization provider example.com-authz # In case of Active Directory specify UPN: - ovirt.ovirt.ovirt_user: name: user1@ad2.example.com domain: example.com-authz # Remove user user1 with authorization provider example.com-authz - ovirt.ovirt.ovirt_user: state: absent name: user1 authz_name: example.com-authz # Remove ssh_public_key - ovirt.ovirt.ovirt_user: name: user1 authz_name: example.com-authz ssh_public_key: "" ''' RETURN = ''' id: description: ID of the user which is managed returned: On success if user is found. type: str sample: 7de90f31-222c-436c-a1ca-7e655bd5b60c user: description: "Dictionary of all the user attributes. User attributes can be found on your oVirt/RHV instance at following url: http://ovirt.github.io/ovirt-engine-api-model/master/#types/user." returned: On success if user is found. type: dict ''' import traceback try: import ovirtsdk4.types as otypes except ImportError: pass from ansible.module_utils.basic import AnsibleModule from ansible_collections.ovirt.ovirt.plugins.module_utils.ovirt import ( BaseModule, check_sdk, check_params, create_connection, ovirt_full_argument_spec, ) def username(module): return '{0}@{1}'.format(module.params['name'], module.params['authz_name']) class UsersModule(BaseModule): def build_entity(self): return otypes.User( domain=otypes.Domain( name=self._module.params['authz_name'] ), user_name=username(self._module), principal=self._module.params['name'], namespace=self._module.params['namespace'], ) def main(): argument_spec = ovirt_full_argument_spec( state=dict( choices=['present', 'absent'], default='present', ), name=dict(required=True), authz_name=dict(required=True, aliases=['domain']), namespace=dict(default=None), ssh_public_key=dict(default=None), ) module = AnsibleModule( argument_spec=argument_spec, supports_check_mode=True, ) check_sdk(module) check_params(module) try: auth = module.params.pop('auth') connection = create_connection(auth) users_service = connection.system_service().users_service() users_module = UsersModule( connection=connection, module=module, service=users_service, ) state = module.params['state'] if state == 'present': ret = users_module.create( search_params={ 'usrname': username(module), } ) if module.params['ssh_public_key'] is not None: ssh_public_keys_service = users_service.user_service(ret['id']).ssh_public_keys_service() ssh_public_keys = ssh_public_keys_service.list() if ssh_public_keys: if not module.params['ssh_public_key']: ssh_public_keys_service.service(ssh_public_keys[0].id).remove() ret['changed'] = True elif module.params['ssh_public_key'] != ssh_public_keys[0].content: ssh_public_keys_service.service(ssh_public_keys[0].id).update(otypes.SshPublicKey(content=module.params['ssh_public_key'])) ret['changed'] = True elif module.params['ssh_public_key']: ssh_public_keys_service.add(otypes.SshPublicKey(content=module.params['ssh_public_key'])) ret['changed'] = True elif state == 'absent': ret = users_module.remove( search_params={ 'usrname': username(module), } ) module.exit_json(**ret) except Exception as e: module.fail_json(msg=str(e), exception=traceback.format_exc()) finally: connection.close(logout=auth.get('token') is None) if __name__ == "__main__": main()