ansible-collection-hetzner-.../plugins/modules/ssh_key.py

235 lines
7 KiB
Python
Raw Normal View History

2020-03-09 13:36:01 +00:00
#!/usr/bin/python
# Copyright: (c) 2019, Hetzner Cloud GmbH <info@hetzner-cloud.de>
# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
from __future__ import annotations
DOCUMENTATION = """
2020-03-09 13:36:01 +00:00
---
module: ssh_key
2020-03-09 13:36:01 +00:00
short_description: Create and manage ssh keys on the Hetzner Cloud.
description:
- Create, update and manage ssh keys on the Hetzner Cloud.
author:
- Lukas Kaemmerling (@LKaemmerling)
options:
id:
description:
- The ID of the Hetzner Cloud ssh_key to manage.
- Only required if no ssh_key I(name) is given
type: int
name:
description:
- The Name of the Hetzner Cloud ssh_key to manage.
- Only required if no ssh_key I(id) is given or a ssh_key does not exist.
2020-03-09 13:36:01 +00:00
type: str
fingerprint:
description:
- The Fingerprint of the Hetzner Cloud ssh_key to manage.
- Only required if no ssh_key I(id) or I(name) is given.
type: str
labels:
description:
- User-defined labels (key-value pairs)
type: dict
public_key:
description:
- The Public Key to add.
- Required if ssh_key does not exist.
2020-03-09 13:36:01 +00:00
type: str
state:
description:
- State of the ssh_key.
default: present
choices: [ absent, present ]
type: str
extends_documentation_fragment:
- hetzner.hcloud.hcloud
"""
2020-03-09 13:36:01 +00:00
EXAMPLES = """
- name: Create a basic ssh_key
hetzner.hcloud.ssh_key:
2020-03-09 13:36:01 +00:00
name: my-ssh_key
deps: update pre-commit hook ansible/ansible-lint to v6.21.0 (#365) [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [ansible/ansible-lint](https://togithub.com/ansible/ansible-lint) | repository | minor | `v6.20.3` -> `v6.21.0` | Note: The `pre-commit` manager in Renovate is not supported by the `pre-commit` maintainers or community. Please do not report any problems there, instead [create a Discussion in the Renovate repository](https://togithub.com/renovatebot/renovate/discussions/new) if you have any questions. --- ### Release Notes <details> <summary>ansible/ansible-lint (ansible/ansible-lint)</summary> ### [`v6.21.0`](https://togithub.com/ansible/ansible-lint/releases/tag/v6.21.0) [Compare Source](https://togithub.com/ansible/ansible-lint/compare/v6.20.3...v6.21.0) #### Minor Changes - Allow linting plugin EXAMPLES as playbooks ([#&#8203;3309](https://togithub.com/ansible/ansible-lint/issues/3309)) [@&#8203;Qalthos](https://togithub.com/Qalthos) #### Bugfixes - Add support for Rocky ([#&#8203;3843](https://togithub.com/ansible/ansible-lint/issues/3843)) [@&#8203;facorazza](https://togithub.com/facorazza) - Update supported Ubuntu versions in `meta.json` ([#&#8203;3845](https://togithub.com/ansible/ansible-lint/issues/3845)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Avoid false positives for handler in roles handlers directory ([#&#8203;3838](https://togithub.com/ansible/ansible-lint/issues/3838)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Hide stacktrace when loading invalid yaml ([#&#8203;3844](https://togithub.com/ansible/ansible-lint/issues/3844)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add some platforms to `meta.json` ([#&#8203;3841](https://togithub.com/ansible/ansible-lint/issues/3841)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Temporary avoid auto-fixing YAML files not owned by ansible ([#&#8203;3837](https://togithub.com/ansible/ansible-lint/issues/3837)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Add environment variable for skipping schema update ([#&#8203;3835](https://togithub.com/ansible/ansible-lint/issues/3835)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Avoid creating temporary YAML files inside source tree ([#&#8203;3819](https://togithub.com/ansible/ansible-lint/issues/3819)) [@&#8203;Qalthos](https://togithub.com/Qalthos) - Document environment variables ([#&#8203;3833](https://togithub.com/ansible/ansible-lint/issues/3833)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update schemas ([#&#8203;3832](https://togithub.com/ansible/ansible-lint/issues/3832)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Support complex requirements in argument_specs.yml ([#&#8203;3823](https://togithub.com/ansible/ansible-lint/issues/3823)) [@&#8203;tapetersen](https://togithub.com/tapetersen) - Fix SARIF-formatter severity levels ([#&#8203;3824](https://togithub.com/ansible/ansible-lint/issues/3824)) [@&#8203;4ch1m](https://togithub.com/4ch1m) - Add play level autofix for key-order rule ([#&#8203;3815](https://togithub.com/ansible/ansible-lint/issues/3815)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add support for python 3.12 ([#&#8203;3813](https://togithub.com/ansible/ansible-lint/issues/3813)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update SPDX license list ([#&#8203;3814](https://togithub.com/ansible/ansible-lint/issues/3814)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Use checkout action in install docs ([#&#8203;3810](https://togithub.com/ansible/ansible-lint/issues/3810)) [@&#8203;gma](https://togithub.com/gma) - Fix actions-tagger arguments ([#&#8203;3808](https://togithub.com/ansible/ansible-lint/issues/3808)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/ansible-collections/hetzner.hcloud). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xOS4yIiwidXBkYXRlZEluVmVyIjoiMzcuMTkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: jo <ljonas@riseup.net>
2023-10-19 10:41:44 +00:00
public_key: ssh-rsa AAAjjk76kgf...Xt
2020-03-09 13:36:01 +00:00
state: present
- name: Create a ssh_key with labels
hetzner.hcloud.ssh_key:
2020-03-09 13:36:01 +00:00
name: my-ssh_key
deps: update pre-commit hook ansible/ansible-lint to v6.21.0 (#365) [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [ansible/ansible-lint](https://togithub.com/ansible/ansible-lint) | repository | minor | `v6.20.3` -> `v6.21.0` | Note: The `pre-commit` manager in Renovate is not supported by the `pre-commit` maintainers or community. Please do not report any problems there, instead [create a Discussion in the Renovate repository](https://togithub.com/renovatebot/renovate/discussions/new) if you have any questions. --- ### Release Notes <details> <summary>ansible/ansible-lint (ansible/ansible-lint)</summary> ### [`v6.21.0`](https://togithub.com/ansible/ansible-lint/releases/tag/v6.21.0) [Compare Source](https://togithub.com/ansible/ansible-lint/compare/v6.20.3...v6.21.0) #### Minor Changes - Allow linting plugin EXAMPLES as playbooks ([#&#8203;3309](https://togithub.com/ansible/ansible-lint/issues/3309)) [@&#8203;Qalthos](https://togithub.com/Qalthos) #### Bugfixes - Add support for Rocky ([#&#8203;3843](https://togithub.com/ansible/ansible-lint/issues/3843)) [@&#8203;facorazza](https://togithub.com/facorazza) - Update supported Ubuntu versions in `meta.json` ([#&#8203;3845](https://togithub.com/ansible/ansible-lint/issues/3845)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Avoid false positives for handler in roles handlers directory ([#&#8203;3838](https://togithub.com/ansible/ansible-lint/issues/3838)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Hide stacktrace when loading invalid yaml ([#&#8203;3844](https://togithub.com/ansible/ansible-lint/issues/3844)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add some platforms to `meta.json` ([#&#8203;3841](https://togithub.com/ansible/ansible-lint/issues/3841)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Temporary avoid auto-fixing YAML files not owned by ansible ([#&#8203;3837](https://togithub.com/ansible/ansible-lint/issues/3837)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Add environment variable for skipping schema update ([#&#8203;3835](https://togithub.com/ansible/ansible-lint/issues/3835)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Avoid creating temporary YAML files inside source tree ([#&#8203;3819](https://togithub.com/ansible/ansible-lint/issues/3819)) [@&#8203;Qalthos](https://togithub.com/Qalthos) - Document environment variables ([#&#8203;3833](https://togithub.com/ansible/ansible-lint/issues/3833)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update schemas ([#&#8203;3832](https://togithub.com/ansible/ansible-lint/issues/3832)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Support complex requirements in argument_specs.yml ([#&#8203;3823](https://togithub.com/ansible/ansible-lint/issues/3823)) [@&#8203;tapetersen](https://togithub.com/tapetersen) - Fix SARIF-formatter severity levels ([#&#8203;3824](https://togithub.com/ansible/ansible-lint/issues/3824)) [@&#8203;4ch1m](https://togithub.com/4ch1m) - Add play level autofix for key-order rule ([#&#8203;3815](https://togithub.com/ansible/ansible-lint/issues/3815)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add support for python 3.12 ([#&#8203;3813](https://togithub.com/ansible/ansible-lint/issues/3813)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update SPDX license list ([#&#8203;3814](https://togithub.com/ansible/ansible-lint/issues/3814)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Use checkout action in install docs ([#&#8203;3810](https://togithub.com/ansible/ansible-lint/issues/3810)) [@&#8203;gma](https://togithub.com/gma) - Fix actions-tagger arguments ([#&#8203;3808](https://togithub.com/ansible/ansible-lint/issues/3808)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/ansible-collections/hetzner.hcloud). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xOS4yIiwidXBkYXRlZEluVmVyIjoiMzcuMTkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: jo <ljonas@riseup.net>
2023-10-19 10:41:44 +00:00
public_key: ssh-rsa AAAjjk76kgf...Xt
2020-03-09 13:36:01 +00:00
labels:
deps: update pre-commit hook ansible/ansible-lint to v6.21.0 (#365) [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [ansible/ansible-lint](https://togithub.com/ansible/ansible-lint) | repository | minor | `v6.20.3` -> `v6.21.0` | Note: The `pre-commit` manager in Renovate is not supported by the `pre-commit` maintainers or community. Please do not report any problems there, instead [create a Discussion in the Renovate repository](https://togithub.com/renovatebot/renovate/discussions/new) if you have any questions. --- ### Release Notes <details> <summary>ansible/ansible-lint (ansible/ansible-lint)</summary> ### [`v6.21.0`](https://togithub.com/ansible/ansible-lint/releases/tag/v6.21.0) [Compare Source](https://togithub.com/ansible/ansible-lint/compare/v6.20.3...v6.21.0) #### Minor Changes - Allow linting plugin EXAMPLES as playbooks ([#&#8203;3309](https://togithub.com/ansible/ansible-lint/issues/3309)) [@&#8203;Qalthos](https://togithub.com/Qalthos) #### Bugfixes - Add support for Rocky ([#&#8203;3843](https://togithub.com/ansible/ansible-lint/issues/3843)) [@&#8203;facorazza](https://togithub.com/facorazza) - Update supported Ubuntu versions in `meta.json` ([#&#8203;3845](https://togithub.com/ansible/ansible-lint/issues/3845)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Avoid false positives for handler in roles handlers directory ([#&#8203;3838](https://togithub.com/ansible/ansible-lint/issues/3838)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Hide stacktrace when loading invalid yaml ([#&#8203;3844](https://togithub.com/ansible/ansible-lint/issues/3844)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add some platforms to `meta.json` ([#&#8203;3841](https://togithub.com/ansible/ansible-lint/issues/3841)) [@&#8203;mcdonnnj](https://togithub.com/mcdonnnj) - Temporary avoid auto-fixing YAML files not owned by ansible ([#&#8203;3837](https://togithub.com/ansible/ansible-lint/issues/3837)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Add environment variable for skipping schema update ([#&#8203;3835](https://togithub.com/ansible/ansible-lint/issues/3835)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Avoid creating temporary YAML files inside source tree ([#&#8203;3819](https://togithub.com/ansible/ansible-lint/issues/3819)) [@&#8203;Qalthos](https://togithub.com/Qalthos) - Document environment variables ([#&#8203;3833](https://togithub.com/ansible/ansible-lint/issues/3833)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update schemas ([#&#8203;3832](https://togithub.com/ansible/ansible-lint/issues/3832)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Support complex requirements in argument_specs.yml ([#&#8203;3823](https://togithub.com/ansible/ansible-lint/issues/3823)) [@&#8203;tapetersen](https://togithub.com/tapetersen) - Fix SARIF-formatter severity levels ([#&#8203;3824](https://togithub.com/ansible/ansible-lint/issues/3824)) [@&#8203;4ch1m](https://togithub.com/4ch1m) - Add play level autofix for key-order rule ([#&#8203;3815](https://togithub.com/ansible/ansible-lint/issues/3815)) [@&#8203;ajinkyau](https://togithub.com/ajinkyau) - Add support for python 3.12 ([#&#8203;3813](https://togithub.com/ansible/ansible-lint/issues/3813)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Update SPDX license list ([#&#8203;3814](https://togithub.com/ansible/ansible-lint/issues/3814)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) - Use checkout action in install docs ([#&#8203;3810](https://togithub.com/ansible/ansible-lint/issues/3810)) [@&#8203;gma](https://togithub.com/gma) - Fix actions-tagger arguments ([#&#8203;3808](https://togithub.com/ansible/ansible-lint/issues/3808)) [@&#8203;ssbarnea](https://togithub.com/ssbarnea) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/ansible-collections/hetzner.hcloud). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xOS4yIiwidXBkYXRlZEluVmVyIjoiMzcuMTkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: jo <ljonas@riseup.net>
2023-10-19 10:41:44 +00:00
key: value
mylabel: 123
2020-03-09 13:36:01 +00:00
state: present
- name: Ensure the ssh_key is absent (remove if needed)
hetzner.hcloud.ssh_key:
2020-03-09 13:36:01 +00:00
name: my-ssh_key
state: absent
"""
RETURN = """
hcloud_ssh_key:
description: The ssh_key instance
returned: Always
type: complex
contains:
id:
description: ID of the ssh_key
type: int
returned: Always
sample: 12345
name:
description: Name of the ssh_key
type: str
returned: Always
sample: my-ssh-key
fingerprint:
description: Fingerprint of the ssh_key
type: str
returned: Always
sample: b7:2f:30:a0:2f:6c:58:6c:21:04:58:61:ba:06:3b:2f
public_key:
description: Public key of the ssh_key
type: str
returned: Always
sample: "ssh-rsa AAAjjk76kgf...Xt"
labels:
description: User-defined labels (key-value pairs)
type: dict
returned: Always
sample:
key: value
mylabel: 123
"""
from ansible.module_utils.basic import AnsibleModule
from ansible.module_utils.common.text.converters import to_native
from ..module_utils.hcloud import AnsibleHCloud
from ..module_utils.vendor.hcloud import HCloudException
from ..module_utils.vendor.hcloud.ssh_keys import BoundSSHKey
2020-03-09 13:36:01 +00:00
class AnsibleHCloudSSHKey(AnsibleHCloud):
represent = "hcloud_ssh_key"
hcloud_ssh_key: BoundSSHKey | None = None
2020-03-09 13:36:01 +00:00
def _prepare_result(self):
return {
"id": to_native(self.hcloud_ssh_key.id),
"name": to_native(self.hcloud_ssh_key.name),
"fingerprint": to_native(self.hcloud_ssh_key.fingerprint),
"public_key": to_native(self.hcloud_ssh_key.public_key),
"labels": self.hcloud_ssh_key.labels,
}
def _get_ssh_key(self):
try:
if self.module.params.get("id") is not None:
self.hcloud_ssh_key = self.client.ssh_keys.get_by_id(self.module.params.get("id"))
2020-03-09 13:36:01 +00:00
elif self.module.params.get("fingerprint") is not None:
self.hcloud_ssh_key = self.client.ssh_keys.get_by_fingerprint(self.module.params.get("fingerprint"))
2020-03-09 13:36:01 +00:00
elif self.module.params.get("name") is not None:
self.hcloud_ssh_key = self.client.ssh_keys.get_by_name(self.module.params.get("name"))
2020-03-09 13:36:01 +00:00
except HCloudException as exception:
self.fail_json_hcloud(exception)
2020-03-09 13:36:01 +00:00
def _create_ssh_key(self):
self.module.fail_on_missing_params(required_params=["name", "public_key"])
2020-03-09 13:36:01 +00:00
params = {
"name": self.module.params.get("name"),
"public_key": self.module.params.get("public_key"),
"labels": self.module.params.get("labels"),
2020-03-09 13:36:01 +00:00
}
if not self.module.check_mode:
try:
self.client.ssh_keys.create(**params)
except HCloudException as exception:
self.fail_json_hcloud(exception)
2020-03-09 13:36:01 +00:00
self._mark_as_changed()
self._get_ssh_key()
def _update_ssh_key(self):
name = self.module.params.get("name")
if name is not None and self.hcloud_ssh_key.name != name:
self.module.fail_on_missing_params(required_params=["id"])
2020-03-09 13:36:01 +00:00
if not self.module.check_mode:
self.hcloud_ssh_key.update(name=name)
self._mark_as_changed()
labels = self.module.params.get("labels")
if labels is not None and self.hcloud_ssh_key.labels != labels:
if not self.module.check_mode:
self.hcloud_ssh_key.update(labels=labels)
self._mark_as_changed()
self._get_ssh_key()
def present_ssh_key(self):
self._get_ssh_key()
if self.hcloud_ssh_key is None:
self._create_ssh_key()
else:
self._update_ssh_key()
def delete_ssh_key(self):
self._get_ssh_key()
if self.hcloud_ssh_key is not None:
if not self.module.check_mode:
try:
self.client.ssh_keys.delete(self.hcloud_ssh_key)
except HCloudException as exception:
self.fail_json_hcloud(exception)
2020-03-09 13:36:01 +00:00
self._mark_as_changed()
self.hcloud_ssh_key = None
@classmethod
def define_module(cls):
2020-03-09 13:36:01 +00:00
return AnsibleModule(
argument_spec=dict(
id={"type": "int"},
name={"type": "str"},
public_key={"type": "str"},
fingerprint={"type": "str"},
labels={"type": "dict"},
state={
"choices": ["absent", "present"],
"default": "present",
},
**super().base_module_arguments(),
2020-03-09 13:36:01 +00:00
),
required_one_of=[["id", "name", "fingerprint"]],
required_if=[["state", "present", ["name"]]],
2020-03-09 13:36:01 +00:00
supports_check_mode=True,
)
def main():
module = AnsibleHCloudSSHKey.define_module()
2020-03-09 13:36:01 +00:00
hcloud = AnsibleHCloudSSHKey(module)
2020-03-09 13:36:01 +00:00
state = module.params.get("state")
if state == "absent":
hcloud.delete_ssh_key()
elif state == "present":
hcloud.present_ssh_key()
module.exit_json(**hcloud.get_result())
if __name__ == "__main__":
main()