cloudera.services.ssb_user_keytab module – Set the user keytab in SSB

Note

This module is part of the cloudera.services collection (version 1.0.0).

It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install git+https://github.com/cloudera-labs/cloudera.services.git.

To use it in a playbook, specify: cloudera.services.ssb_user_keytab.

New in cloudera.services 1.0.0

Synopsis

  • Set or remove the user keytab in Cloudera SSB.

  • The module can either upload an existing keytab file or data, or generate a new keytab using a provided password.

  • The module supports check_mode.

Parameters

Parameter

Comments

client_cert

path

The path to a client certificate for authenticating to the API endpoint.

client_key

path

The path to a client key for authenticating to the API endpoint.

debug

aliases: debug_endpoints

boolean

A flag to enable debug logging of the module’s execution.

Choices:

  • false ← (default)

  • true

force

boolean

A flag to force a refresh of the API request, ignoring any cached results.

Choices:

  • false ← (default)

  • true

force_basic_auth

boolean

A flag to force basic authentication for API requests.

Choices:

  • false ← (default)

  • true

http_agent

aliases: user_agent

string

The User-Agent string to send with API requests.

Default: "cloudera-services-module"

keytab_base64

string

The raw data of an existing keytab to upload as base64.

This parameter is mutually exclusive with keytab_password and keytab_file.

This parameter is not logged.

keytab_file

string

The path to an existing keytab file to upload.

This parameter is mutually exclusive with keytab_password and keytab_base64.

keytab_password

string

The password to use to generate a new keytab.

This parameter is mutually exclusive with keytab_file and keytab_base64.

This parameter is not logged.

page_size

aliases: default_page_size

integer

The number of items to return per page in a paginated API response.

Default: 100

principal

string

The Kerberos principal associated with the keytab.

This parameter is required when state is present.

state

string

The desired state of the keytab.

Choices:

  • "present" ← (default)

  • "absent"

timeout

aliases: timeout_seconds

integer

The timeout in seconds for any API requests.

Default: 60

url

aliases: endpoint, endpoint_url

string / required

The base URL of the API endpoint, including the port if necessary.

url_password

string

The password for authenticating to the API endpoint.

url_username

string

The username for authenticating to the API endpoint.

use_gssapi

boolean

A flag to enable or disable GSSAPI authentication for API requests.

Choices:

  • false ← (default)

  • true

use_proxy

boolean

A flag to enable or disable the use of a proxy for API requests.

Choices:

  • false

  • true ← (default)

validate_certs

boolean

A flag to enable or disable SSL certificate validation for API requests.

Choices:

  • false

  • true ← (default)

Examples

- name: Generate a new keytab for a user
  cloudera.services.ssb_user_keytab:
    principal: "user@REALM.COM"
    keytab_password: "password"
    state: present

- name: Upload an existing keytab file for a user
  cloudera.services.ssb_user_keytab:
    principal: "user@REALM.COM"
    keytab_file: "/path/to/user.keytab"
    state: present

- name: Upload an existing keytab from base64 data for a user
  cloudera.services.ssb_user_keytab:
    principal: "user@REALM.COM"
    keytab_base64: "{{ lookup('file', '/path/to/user.keytab') | ansible.builtin.b64encode }}"
    state: present

- name: Remove the keytab for a user
  cloudera.services.ssb_user_keytab:
    principal: "user@REALM.COM"
    state: absent

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

principal

string

The Kerberos principal associated with the keytab.

Returned: when state=present

sdk_out

string

Returns the captured CDP SDK log.

Returned: when supported

sdk_out_lines

list / elements=string

Returns a list of each line of the captured CDP SDK log.

Returned: when supported

Authors

  • Webster Mudge (@wmudge)

  • Andre Araujo (@asdaraujo)