cloudera.cloud.dw_secret module – Create, register, and delete CDP Data Warehouse secrets
Note
This module is part of the cloudera.cloud collection (version 3.3.0).
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install cloudera.cloud.
To use it in a playbook, specify: cloudera.cloud.dw_secret.
New in cloudera.cloud 3.4.0
Synopsis
Manage secrets for a CDP Data Warehouse (CDW) cluster.
A secret is provisioned by one of two mutually exclusive approaches.
Creation stores the secret value in the cluster’s Kubernetes metadata via
secret_value.Registration references a secret already held in the cloud provider’s vault via
secret_provider_key.Secrets are immutable; an existing secret is left unchanged. To alter one, delete it and provision it again.
The module supports
check_mode.
Parameters
Parameter |
Comments |
|---|---|
If provided, the Cloudera on cloud API will use this value as its access key. If not provided, the API will attempt to use the value from the environment variable Required if Mutually exclusive with |
|
The name of the Azure Key Vault holding the secret. Only used with |
|
The identifier of the Data Warehouse Cluster. |
|
If provided, the Cloudera on cloud API will use this value as its credentials path. If not provided, the API will attempt to use the value from the environment variable Default: |
|
If Choices:
|
|
The Cloudera on cloud API endpoint to use. If not provided, the API will attempt to use the value from the environment variable Mutually exclusive with |
|
Specify the Cloudera on cloud API endpoint region. See Cloudera Control Plane regions for more information. If not provided, the API will attempt to use the value from the environment variable
Mutually exclusive with Choices:
|
|
Verify the TLS certificates for the Cloudera on cloud API endpoint. Choices:
|
|
The HTTP user agent to use for Cloudera on cloud API requests. Default: |
|
The name of the secret. |
|
If provided, the Cloudera on cloud API will use this value as its private key. If not provided, the API will attempt to use the value from the environment variable Required if |
|
If provided, the Cloudera on cloud API will use this value as its profile. If not provided, the API will attempt to use the value from the environment variable Default: |
|
The key of a secret already stored in the cloud provider’s vault. Selects the registration approach and is mutually exclusive with Required for |
|
The value (contents) of the secret to store in the cluster’s Kubernetes metadata. Selects the creation approach and is mutually exclusive with Required for |
|
The declarative state of the secret.
Choices:
|
|
Legacy CDPy SDK error handling. Choices:
|
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: full |
Can run in check_mode and return changed status prediction without modifying target, if not supported the action will be skipped. |
|
Support: full |
Will return details on what has changed (or possibly needs changing in check_mode), when in diff mode |
|
Platforms: all |
Target OS/families that can be operated against |
Examples
# Note: These examples do not set authentication details.
- name: Create a Kubernetes-stored secret
cloudera.cloud.dw_secret:
cluster_id: example-cluster-id
name: mydbpassword
secret_value: "{{ vaulted_db_password }}"
state: present
- name: Register a secret from an Azure Key Vault
cloudera.cloud.dw_secret:
cluster_id: example-cluster-id
name: myregisteredsecret
secret_provider_key: my-provider-key
azure_vault_name: my-key-vault
state: present
- name: Register a secret from a cloud provider vault (non-Azure)
cloudera.cloud.dw_secret:
cluster_id: example-cluster-id
name: awssecret
secret_provider_key: "arn:aws:secretsmanager:us-west-2:1234567890:secret:my-secret"
- name: Delete a secret
cloudera.cloud.dw_secret:
cluster_id: example-cluster-id
name: mydbpassword
state: absent
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
Returns the captured CDP SDK log. Returned: when debug is true |
|
Returns a list of each line of the captured CDP SDK log. Returned: when debug is true |
|
The details of the CDP Data Warehouse secret. Returned: always |
|
The CRN of the user who created the secret. Returned: when available |
|
The properties of the secret. Returned: when available |
|
The name of the Azure Key Vault. Returned: when available |
|
The cloud provider associated with the secret. Returned: when available |
|
The version of the secret. Returned: when available |
|
The user-facing name of the secret. Returned: when available |
|
The provider key name associated with the secret. Returned: when available |