cloudera.services.ssb_user_keytab module – Set the user keytab in SSB
Note
This module is part of the cloudera.services collection (version 1.0.0).
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install git+https://github.com/cloudera-labs/cloudera.services.git.
To use it in a playbook, specify: cloudera.services.ssb_user_keytab.
New in cloudera.services 1.0.0
Synopsis
Set or remove the user keytab in Cloudera SSB.
The module can either upload an existing keytab file or data, or generate a new keytab using a provided password.
The module supports
check_mode.
Parameters
Parameter |
Comments |
|---|---|
The path to a client certificate for authenticating to the API endpoint. |
|
The path to a client key for authenticating to the API endpoint. |
|
A flag to enable debug logging of the module’s execution. Choices:
|
|
A flag to force a refresh of the API request, ignoring any cached results. Choices:
|
|
A flag to force basic authentication for API requests. Choices:
|
|
The User-Agent string to send with API requests. Default: |
|
The raw data of an existing keytab to upload as base64. This parameter is mutually exclusive with This parameter is not logged. |
|
The path to an existing keytab file to upload. This parameter is mutually exclusive with |
|
The password to use to generate a new keytab. This parameter is mutually exclusive with This parameter is not logged. |
|
The number of items to return per page in a paginated API response. Default: |
|
The Kerberos principal associated with the keytab. This parameter is required when |
|
The desired state of the keytab. Choices:
|
|
The timeout in seconds for any API requests. Default: |
|
The base URL of the API endpoint, including the port if necessary. |
|
The password for authenticating to the API endpoint. |
|
The username for authenticating to the API endpoint. |
|
A flag to enable or disable GSSAPI authentication for API requests. Choices:
|
|
A flag to enable or disable the use of a proxy for API requests. Choices:
|
|
A flag to enable or disable SSL certificate validation for API requests. Choices:
|
Examples
- name: Generate a new keytab for a user
cloudera.services.ssb_user_keytab:
principal: "user@REALM.COM"
keytab_password: "password"
state: present
- name: Upload an existing keytab file for a user
cloudera.services.ssb_user_keytab:
principal: "user@REALM.COM"
keytab_file: "/path/to/user.keytab"
state: present
- name: Upload an existing keytab from base64 data for a user
cloudera.services.ssb_user_keytab:
principal: "user@REALM.COM"
keytab_base64: "{{ lookup('file', '/path/to/user.keytab') | ansible.builtin.b64encode }}"
state: present
- name: Remove the keytab for a user
cloudera.services.ssb_user_keytab:
principal: "user@REALM.COM"
state: absent
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
The Kerberos principal associated with the keytab. Returned: when |
|
Returns the captured CDP SDK log. Returned: when supported |
|
Returns a list of each line of the captured CDP SDK log. Returned: when supported |