golden hour
/opt/saltstack/salt/lib/python3.10/site-packages/salt/states
⬆️ Go Up
Upload
File/Folder
Size
Actions
__init__.py
25 B
Del
OK
__pycache__
-
Del
OK
acme.py
5.08 KB
Del
OK
alias.py
2.49 KB
Del
OK
alternatives.py
6.75 KB
Del
OK
ansiblegate.py
7.93 KB
Del
OK
apache.py
3.95 KB
Del
OK
apache_conf.py
2.72 KB
Del
OK
apache_module.py
2.73 KB
Del
OK
apache_site.py
2.66 KB
Del
OK
aptpkg.py
1.42 KB
Del
OK
archive.py
68.24 KB
Del
OK
artifactory.py
6.84 KB
Del
OK
at.py
7.48 KB
Del
OK
augeas.py
10.57 KB
Del
OK
aws_sqs.py
2.59 KB
Del
OK
azurearm_compute.py
11.78 KB
Del
OK
azurearm_dns.py
26.05 KB
Del
OK
azurearm_network.py
89.12 KB
Del
OK
azurearm_resource.py
28.23 KB
Del
OK
beacon.py
7.58 KB
Del
OK
bigip.py
96.63 KB
Del
OK
blockdev.py
5.13 KB
Del
OK
boto3_elasticache.py
48.01 KB
Del
OK
boto3_elasticsearch.py
32.58 KB
Del
OK
boto3_route53.py
37.54 KB
Del
OK
boto3_sns.py
12.69 KB
Del
OK
boto_apigateway.py
82.83 KB
Del
OK
boto_asg.py
31.93 KB
Del
OK
boto_cfn.py
11.53 KB
Del
OK
boto_cloudfront.py
6.01 KB
Del
OK
boto_cloudtrail.py
13.18 KB
Del
OK
boto_cloudwatch_alarm.py
6.4 KB
Del
OK
boto_cloudwatch_event.py
12.33 KB
Del
OK
boto_cognitoidentity.py
13.69 KB
Del
OK
boto_datapipeline.py
18.5 KB
Del
OK
boto_dynamodb.py
29.32 KB
Del
OK
boto_ec2.py
71.98 KB
Del
OK
boto_elasticache.py
16.75 KB
Del
OK
boto_elasticsearch_domain.py
12.27 KB
Del
OK
boto_elb.py
55.1 KB
Del
OK
boto_elbv2.py
12.19 KB
Del
OK
boto_iam.py
69.16 KB
Del
OK
boto_iam_role.py
27.12 KB
Del
OK
boto_iot.py
25.33 KB
Del
OK
boto_kinesis.py
16.69 KB
Del
OK
boto_kms.py
12.11 KB
Del
OK
boto_lambda.py
35.52 KB
Del
OK
boto_lc.py
11.04 KB
Del
OK
boto_rds.py
26 KB
Del
OK
boto_route53.py
19.49 KB
Del
OK
boto_s3.py
9.32 KB
Del
OK
boto_s3_bucket.py
24.67 KB
Del
OK
boto_secgroup.py
32.62 KB
Del
OK
boto_sns.py
8.92 KB
Del
OK
boto_sqs.py
7.97 KB
Del
OK
boto_vpc.py
62.23 KB
Del
OK
bower.py
8.26 KB
Del
OK
btrfs.py
10.34 KB
Del
OK
cabal.py
5.73 KB
Del
OK
ceph.py
1.9 KB
Del
OK
chef.py
3.76 KB
Del
OK
chocolatey.py
16.15 KB
Del
OK
chronos_job.py
4.6 KB
Del
OK
cimc.py
14.32 KB
Del
OK
cisconso.py
3.14 KB
Del
OK
cloud.py
14.4 KB
Del
OK
cmd.py
40.92 KB
Del
OK
composer.py
8.38 KB
Del
OK
consul.py
5.4 KB
Del
OK
cron.py
23.39 KB
Del
OK
cryptdev.py
6.17 KB
Del
OK
csf.py
9.98 KB
Del
OK
cyg.py
7.05 KB
Del
OK
ddns.py
4.2 KB
Del
OK
debconfmod.py
6.33 KB
Del
OK
dellchassis.py
24.49 KB
Del
OK
disk.py
6.49 KB
Del
OK
docker_container.py
85.27 KB
Del
OK
docker_image.py
16.7 KB
Del
OK
docker_network.py
36.78 KB
Del
OK
docker_volume.py
6.72 KB
Del
OK
drac.py
4.17 KB
Del
OK
dvs.py
26.29 KB
Del
OK
elasticsearch.py
20.38 KB
Del
OK
elasticsearch_index.py
3.25 KB
Del
OK
elasticsearch_index_template.py
3.67 KB
Del
OK
environ.py
5.81 KB
Del
OK
eselect.py
2.27 KB
Del
OK
esxcluster.py
22.4 KB
Del
OK
esxdatacenter.py
4.44 KB
Del
OK
esxi.py
63.07 KB
Del
OK
esxvm.py
20.11 KB
Del
OK
etcd_mod.py
11 KB
Del
OK
ethtool.py
9.88 KB
Del
OK
event.py
2.48 KB
Del
OK
file.py
316.7 KB
Del
OK
firewall.py
1.33 KB
Del
OK
firewalld.py
26.08 KB
Del
OK
gem.py
7.13 KB
Del
OK
git.py
123.85 KB
Del
OK
github.py
27.25 KB
Del
OK
glance_image.py
2.26 KB
Del
OK
glassfish.py
21.47 KB
Del
OK
glusterfs.py
12.21 KB
Del
OK
gnomedesktop.py
7.47 KB
Del
OK
gpg.py
5.28 KB
Del
OK
grafana.py
12.11 KB
Del
OK
grafana4_dashboard.py
17.31 KB
Del
OK
grafana4_datasource.py
6.15 KB
Del
OK
grafana4_org.py
7.73 KB
Del
OK
grafana4_user.py
5.52 KB
Del
OK
grafana_dashboard.py
17.74 KB
Del
OK
grafana_datasource.py
5.31 KB
Del
OK
grains.py
15.57 KB
Del
OK
group.py
9.84 KB
Del
OK
heat.py
9.69 KB
Del
OK
helm.py
10.39 KB
Del
OK
hg.py
6.33 KB
Del
OK
highstate_doc.py
1.41 KB
Del
OK
host.py
8.64 KB
Del
OK
http.py
7.46 KB
Del
OK
icinga2.py
9.07 KB
Del
OK
idem.py
3.91 KB
Del
OK
ifttt.py
2.12 KB
Del
OK
incron.py
5.71 KB
Del
OK
influxdb08_database.py
2.85 KB
Del
OK
influxdb08_user.py
3.39 KB
Del
OK
influxdb_continuous_query.py
2.83 KB
Del
OK
influxdb_database.py
2.11 KB
Del
OK
influxdb_retention_policy.py
4.82 KB
Del
OK
influxdb_user.py
4.84 KB
Del
OK
infoblox_a.py
4.24 KB
Del
OK
infoblox_cname.py
4.19 KB
Del
OK
infoblox_host_record.py
6.59 KB
Del
OK
infoblox_range.py
6.85 KB
Del
OK
ini_manage.py
12.67 KB
Del
OK
ipmi.py
8.42 KB
Del
OK
ipset.py
9.66 KB
Del
OK
iptables.py
27.65 KB
Del
OK
jboss7.py
23.95 KB
Del
OK
jenkins.py
3.36 KB
Del
OK
junos.py
17.78 KB
Del
OK
kapacitor.py
6.46 KB
Del
OK
kernelpkg.py
6.42 KB
Del
OK
keyboard.py
2.01 KB
Del
OK
keystone.py
27.12 KB
Del
OK
keystone_domain.py
2.81 KB
Del
OK
keystone_endpoint.py
4.69 KB
Del
OK
keystone_group.py
3.25 KB
Del
OK
keystone_project.py
3.36 KB
Del
OK
keystone_role.py
2.33 KB
Del
OK
keystone_role_grant.py
4.08 KB
Del
OK
keystone_service.py
2.89 KB
Del
OK
keystone_user.py
3.47 KB
Del
OK
keystore.py
5.67 KB
Del
OK
kmod.py
8.59 KB
Del
OK
kubernetes.py
24.87 KB
Del
OK
layman.py
2.44 KB
Del
OK
ldap.py
19.78 KB
Del
OK
libcloud_dns.py
5.7 KB
Del
OK
libcloud_loadbalancer.py
5.66 KB
Del
OK
libcloud_storage.py
5.13 KB
Del
OK
linux_acl.py
24.42 KB
Del
OK
locale.py
2.52 KB
Del
OK
logadm.py
4.67 KB
Del
OK
logrotate.py
3.86 KB
Del
OK
loop.py
7.74 KB
Del
OK
lvm.py
13.33 KB
Del
OK
lvs_server.py
6.28 KB
Del
OK
lvs_service.py
4.38 KB
Del
OK
lxc.py
22.17 KB
Del
OK
lxd.py
7.88 KB
Del
OK
lxd_container.py
22.25 KB
Del
OK
lxd_image.py
10.59 KB
Del
OK
lxd_profile.py
7.11 KB
Del
OK
mac_assistive.py
1.55 KB
Del
OK
mac_keychain.py
5.59 KB
Del
OK
mac_xattr.py
3.15 KB
Del
OK
macdefaults.py
2.65 KB
Del
OK
macpackage.py
6.76 KB
Del
OK
makeconf.py
6.87 KB
Del
OK
marathon_app.py
4.45 KB
Del
OK
mdadm_raid.py
6.41 KB
Del
OK
memcached.py
3.95 KB
Del
OK
modjk.py
2.84 KB
Del
OK
modjk_worker.py
6.49 KB
Del
OK
module.py
18.64 KB
Del
OK
mongodb_database.py
1.65 KB
Del
OK
mongodb_user.py
6.26 KB
Del
OK
monit.py
2.68 KB
Del
OK
mount.py
50.32 KB
Del
OK
mssql_database.py
3 KB
Del
OK
mssql_login.py
3.64 KB
Del
OK
mssql_role.py
2.37 KB
Del
OK
mssql_user.py
3.51 KB
Del
OK
msteams.py
2.53 KB
Del
OK
mysql_database.py
6.05 KB
Del
OK
mysql_grants.py
8.49 KB
Del
OK
mysql_query.py
13.07 KB
Del
OK
mysql_user.py
9.51 KB
Del
OK
net_napalm_yang.py
9.15 KB
Del
OK
netacl.py
31.92 KB
Del
OK
netconfig.py
33.42 KB
Del
OK
netntp.py
12.51 KB
Del
OK
netsnmp.py
11.33 KB
Del
OK
netusers.py
16.1 KB
Del
OK
network.py
23.97 KB
Del
OK
neutron_network.py
3.96 KB
Del
OK
neutron_secgroup.py
4 KB
Del
OK
neutron_secgroup_rule.py
4.75 KB
Del
OK
neutron_subnet.py
4.29 KB
Del
OK
nexus.py
4.97 KB
Del
OK
nfs_export.py
4.92 KB
Del
OK
nftables.py
19.5 KB
Del
OK
npm.py
11.21 KB
Del
OK
ntp.py
2.12 KB
Del
OK
nxos.py
10.37 KB
Del
OK
nxos_upgrade.py
3.5 KB
Del
OK
openstack_config.py
3.26 KB
Del
OK
openvswitch_bridge.py
4.36 KB
Del
OK
openvswitch_db.py
2.24 KB
Del
OK
openvswitch_port.py
17.24 KB
Del
OK
opsgenie.py
4.07 KB
Del
OK
pagerduty.py
1.89 KB
Del
OK
pagerduty_escalation_policy.py
5.42 KB
Del
OK
pagerduty_schedule.py
6.09 KB
Del
OK
pagerduty_service.py
3.93 KB
Del
OK
pagerduty_user.py
1.18 KB
Del
OK
panos.py
48.13 KB
Del
OK
pbm.py
20.46 KB
Del
OK
pcs.py
36.46 KB
Del
OK
pdbedit.py
3.43 KB
Del
OK
pecl.py
3.65 KB
Del
OK
pip_state.py
38.55 KB
Del
OK
pkg.py
138.08 KB
Del
OK
pkgbuild.py
11.37 KB
Del
OK
pkgng.py
685 B
Del
OK
pkgrepo.py
27.53 KB
Del
OK
portage_config.py
5.01 KB
Del
OK
ports.py
5.65 KB
Del
OK
postgres_cluster.py
4.19 KB
Del
OK
postgres_database.py
6.08 KB
Del
OK
postgres_extension.py
5.68 KB
Del
OK
postgres_group.py
8.52 KB
Del
OK
postgres_initdb.py
2.84 KB
Del
OK
postgres_language.py
3.94 KB
Del
OK
postgres_privileges.py
7.86 KB
Del
OK
postgres_schema.py
4.34 KB
Del
OK
postgres_tablespace.py
6.62 KB
Del
OK
postgres_user.py
9.49 KB
Del
OK
powerpath.py
2.34 KB
Del
OK
probes.py
15.06 KB
Del
OK
process.py
1.32 KB
Del
OK
proxy.py
4.94 KB
Del
OK
pushover.py
3.13 KB
Del
OK
pyenv.py
6.07 KB
Del
OK
pyrax_queues.py
2.97 KB
Del
OK
quota.py
1.4 KB
Del
OK
rabbitmq_cluster.py
1.84 KB
Del
OK
rabbitmq_plugin.py
2.77 KB
Del
OK
rabbitmq_policy.py
4.59 KB
Del
OK
rabbitmq_upstream.py
7.9 KB
Del
OK
rabbitmq_user.py
8.89 KB
Del
OK
rabbitmq_vhost.py
3.04 KB
Del
OK
rbac_solaris.py
6.67 KB
Del
OK
rbenv.py
7.36 KB
Del
OK
rdp.py
1.28 KB
Del
OK
redismod.py
4.76 KB
Del
OK
reg.py
19.22 KB
Del
OK
restconf.py
6.41 KB
Del
OK
rsync.py
4.45 KB
Del
OK
rvm.py
6.56 KB
Del
OK
salt_proxy.py
1.34 KB
Del
OK
saltmod.py
33.12 KB
Del
OK
saltutil.py
8.91 KB
Del
OK
schedule.py
12.47 KB
Del
OK
selinux.py
18.61 KB
Del
OK
serverdensity_device.py
6.41 KB
Del
OK
service.py
37.89 KB
Del
OK
slack.py
4.98 KB
Del
OK
smartos.py
44.83 KB
Del
OK
smtp.py
2.3 KB
Del
OK
snapper.py
7.24 KB
Del
OK
solrcloud.py
4.48 KB
Del
OK
splunk.py
4.32 KB
Del
OK
splunk_search.py
3.17 KB
Del
OK
sqlite3.py
14.7 KB
Del
OK
ssh_auth.py
19.57 KB
Del
OK
ssh_known_hosts.py
7.92 KB
Del
OK
stateconf.py
494 B
Del
OK
status.py
2.21 KB
Del
OK
statuspage.py
17.29 KB
Del
OK
supervisord.py
10.48 KB
Del
OK
svn.py
8.14 KB
Del
OK
sysctl.py
4.11 KB
Del
OK
sysfs.py
2.13 KB
Del
OK
syslog_ng.py
2.97 KB
Del
OK
sysrc.py
2.82 KB
Del
OK
telemetry_alert.py
7.04 KB
Del
OK
test.py
13.09 KB
Del
OK
testinframod.py
1.35 KB
Del
OK
timezone.py
3.42 KB
Del
OK
tls.py
1.81 KB
Del
OK
tomcat.py
9.72 KB
Del
OK
trafficserver.py
8.82 KB
Del
OK
tuned.py
3.32 KB
Del
OK
uptime.py
1.87 KB
Del
OK
user.py
38.63 KB
Del
OK
vagrant.py
11.4 KB
Del
OK
vault.py
3.28 KB
Del
OK
vbox_guest.py
4.05 KB
Del
OK
victorops.py
3.32 KB
Del
OK
virt.py
80.41 KB
Del
OK
virtualenv_mod.py
11.21 KB
Del
OK
webutil.py
3.89 KB
Del
OK
win_certutil.py
4.8 KB
Del
OK
win_dacl.py
7.96 KB
Del
OK
win_dism.py
14.97 KB
Del
OK
win_dns_client.py
8.32 KB
Del
OK
win_firewall.py
6.87 KB
Del
OK
win_iis.py
31.56 KB
Del
OK
win_lgpo.py
24.99 KB
Del
OK
win_lgpo_reg.py
10.96 KB
Del
OK
win_license.py
1.6 KB
Del
OK
win_network.py
14.18 KB
Del
OK
win_path.py
6.39 KB
Del
OK
win_pki.py
5.56 KB
Del
OK
win_powercfg.py
3.79 KB
Del
OK
win_servermanager.py
10.4 KB
Del
OK
win_shortcut.py
7.81 KB
Del
OK
win_smtp_server.py
10.01 KB
Del
OK
win_snmp.py
6.64 KB
Del
OK
win_system.py
13.78 KB
Del
OK
win_wua.py
16.27 KB
Del
OK
win_wusa.py
3.53 KB
Del
OK
winrepo.py
2.74 KB
Del
OK
wordpress.py
4.82 KB
Del
OK
x509.py
27.86 KB
Del
OK
x509_v2.py
64.78 KB
Del
OK
xml.py
1.75 KB
Del
OK
xmpp.py
2.61 KB
Del
OK
zabbix_action.py
9.35 KB
Del
OK
zabbix_host.py
27.25 KB
Del
OK
zabbix_hostgroup.py
5.64 KB
Del
OK
zabbix_mediatype.py
16.89 KB
Del
OK
zabbix_template.py
35.14 KB
Del
OK
zabbix_user.py
17.6 KB
Del
OK
zabbix_usergroup.py
9.64 KB
Del
OK
zabbix_usermacro.py
9.69 KB
Del
OK
zabbix_valuemap.py
8.11 KB
Del
OK
zcbuildout.py
5.16 KB
Del
OK
zenoss.py
2.89 KB
Del
OK
zfs.py
34.48 KB
Del
OK
zk_concurrency.py
5.81 KB
Del
OK
zone.py
46.48 KB
Del
OK
zookeeper.py
11.55 KB
Del
OK
zpool.py
13.4 KB
Del
OK
Edit: keystone.py
""" Management of Keystone users ============================ :depends: - keystoneclient Python module :configuration: See :py:mod:`salt.modules.keystone` for setup instructions. .. code-block:: yaml Keystone tenants: keystone.tenant_present: - names: - admin - demo - service Keystone roles: keystone.role_present: - names: - admin - Member admin: keystone.user_present: - password: R00T_4CC3SS - email: admin@domain.com - roles: admin: # tenants - admin # roles service: - admin - Member - require: - keystone: Keystone tenants - keystone: Keystone roles nova: keystone.user_present: - password: '$up3rn0v4' - email: nova@domain.com - tenant: service - roles: service: - admin - require: - keystone: Keystone tenants - keystone: Keystone roles demo: keystone.user_present: - password: 'd3m0n$trati0n' - email: demo@domain.com - tenant: demo - roles: demo: - Member - require: - keystone: Keystone tenants - keystone: Keystone roles nova service: keystone.service_present: - name: nova - service_type: compute - description: OpenStack Compute Service """ def __virtual__(): """ Only load if the keystone module is in __salt__ """ if "keystone.auth" in __salt__: return "keystone" return (False, "keystone module could not be loaded") _OS_IDENTITY_API_VERSION = 2 _TENANT_ID = "tenant_id" def _api_version(profile=None, **connection_args): """ Sets global variables _OS_IDENTITY_API_VERSION and _TENANT_ID depending on API version. """ global _TENANT_ID global _OS_IDENTITY_API_VERSION try: if ( float( __salt__["keystone.api_version"]( profile=profile, **connection_args ).strip("v") ) >= 3 ): _TENANT_ID = "project_id" _OS_IDENTITY_API_VERSION = 3 except KeyError: pass def user_present( name, password, email, tenant=None, enabled=True, roles=None, profile=None, password_reset=True, project=None, **connection_args ): """ Ensure that the keystone user is present with the specified properties. name The name of the user to manage password The password to use for this user. .. note:: If the user already exists and a different password was set for the user than the one specified here, the password for the user will be updated. Please set the ``password_reset`` option to ``False`` if this is not the desired behavior. password_reset Whether or not to reset password after initial set. Defaults to ``True``. email The email address for this user tenant The tenant (name) for this user project The project (name) for this user (overrides tenant in api v3) enabled Availability state for this user roles The roles the user should have under given tenants. Passed as a dictionary mapping tenant names to a list of roles in this tenant, i.e.:: roles: admin: # tenant - admin # role service: - admin - Member """ ret = { "name": name, "changes": {}, "result": True, "comment": 'User "{}" will be updated'.format(name), } _api_version(profile=profile, **connection_args) if project and not tenant: tenant = project # Validate tenant if set if tenant is not None: tenantdata = __salt__["keystone.tenant_get"]( name=tenant, profile=profile, **connection_args ) if "Error" in tenantdata: ret["result"] = False ret["comment"] = 'Tenant / project "{}" does not exist'.format(tenant) return ret tenant_id = tenantdata[tenant]["id"] else: tenant_id = None # Check if user is already present user = __salt__["keystone.user_get"](name=name, profile=profile, **connection_args) if "Error" not in user: change_email = False change_enabled = False change_tenant = False change_password = False if user[name].get("email", None) != email: change_email = True if user[name].get("enabled", None) != enabled: change_enabled = True if tenant and ( _TENANT_ID not in user[name] or user[name].get(_TENANT_ID, None) != tenant_id ): change_tenant = True if password_reset is True and not __salt__["keystone.user_verify_password"]( name=name, password=password, profile=profile, **connection_args ): change_password = True if __opts__.get("test") and ( change_email or change_enabled or change_tenant or change_password ): ret["result"] = None ret["comment"] = 'User "{}" will be updated'.format(name) if change_email is True: ret["changes"]["Email"] = "Will be updated" if change_enabled is True: ret["changes"]["Enabled"] = "Will be True" if change_tenant is True: ret["changes"]["Tenant"] = 'Will be added to "{}" tenant'.format(tenant) if change_password is True: ret["changes"]["Password"] = "Will be updated" return ret ret["comment"] = 'User "{}" is already present'.format(name) if change_email: __salt__["keystone.user_update"]( name=name, email=email, profile=profile, **connection_args ) ret["comment"] = 'User "{}" has been updated'.format(name) ret["changes"]["Email"] = "Updated" if change_enabled: __salt__["keystone.user_update"]( name=name, enabled=enabled, profile=profile, **connection_args ) ret["comment"] = 'User "{}" has been updated'.format(name) ret["changes"]["Enabled"] = "Now {}".format(enabled) if change_tenant: __salt__["keystone.user_update"]( name=name, tenant=tenant, profile=profile, **connection_args ) ret["comment"] = 'User "{}" has been updated'.format(name) ret["changes"]["Tenant"] = 'Added to "{}" tenant'.format(tenant) if change_password: __salt__["keystone.user_password_update"]( name=name, password=password, profile=profile, **connection_args ) ret["comment"] = 'User "{}" has been updated'.format(name) ret["changes"]["Password"] = "Updated" if roles: for tenant in roles: args = dict( {"user_name": name, "tenant_name": tenant, "profile": profile}, **connection_args ) tenant_roles = __salt__["keystone.user_role_list"](**args) for role in roles[tenant]: if role not in tenant_roles: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'User roles "{}" will been updated'.format( name ) return ret addargs = dict( { "user": name, "role": role, "tenant": tenant, "profile": profile, }, **connection_args ) newrole = __salt__["keystone.user_role_add"](**addargs) if "roles" in ret["changes"]: ret["changes"]["roles"].append(newrole) else: ret["changes"]["roles"] = [newrole] roles_to_remove = list(set(tenant_roles) - set(roles[tenant])) for role in roles_to_remove: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'User roles "{}" will been updated'.format( name ) return ret addargs = dict( { "user": name, "role": role, "tenant": tenant, "profile": profile, }, **connection_args ) oldrole = __salt__["keystone.user_role_remove"](**addargs) if "roles" in ret["changes"]: ret["changes"]["roles"].append(oldrole) else: ret["changes"]["roles"] = [oldrole] else: # Create that user! if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Keystone user "{}" will be added'.format(name) ret["changes"]["User"] = "Will be created" return ret __salt__["keystone.user_create"]( name=name, password=password, email=email, tenant_id=tenant_id, enabled=enabled, profile=profile, **connection_args ) if roles: for tenant in roles: for role in roles[tenant]: __salt__["keystone.user_role_add"]( user=name, role=role, tenant=tenant, profile=profile, **connection_args ) ret["comment"] = "Keystone user {} has been added".format(name) ret["changes"]["User"] = "Created" return ret def user_absent(name, profile=None, **connection_args): """ Ensure that the keystone user is absent. name The name of the user that should not exist """ ret = { "name": name, "changes": {}, "result": True, "comment": 'User "{}" is already absent'.format(name), } # Check if user is present user = __salt__["keystone.user_get"](name=name, profile=profile, **connection_args) if "Error" not in user: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'User "{}" will be deleted'.format(name) return ret # Delete that user! __salt__["keystone.user_delete"](name=name, profile=profile, **connection_args) ret["comment"] = 'User "{}" has been deleted'.format(name) ret["changes"]["User"] = "Deleted" return ret def tenant_present( name, description=None, enabled=True, profile=None, **connection_args ): """ Ensures that the keystone tenant exists name The name of the tenant to manage description The description to use for this tenant enabled Availability state for this tenant """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Tenant / project "{}" already exists'.format(name), } _api_version(profile=profile, **connection_args) # Check if tenant is already present tenant = __salt__["keystone.tenant_get"]( name=name, profile=profile, **connection_args ) if "Error" not in tenant: if tenant[name].get("description", None) != description: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Tenant / project "{}" will be updated'.format(name) ret["changes"]["Description"] = "Will be updated" return ret __salt__["keystone.tenant_update"]( name=name, description=description, enabled=enabled, profile=profile, **connection_args ) ret["comment"] = 'Tenant / project "{}" has been updated'.format(name) ret["changes"]["Description"] = "Updated" if tenant[name].get("enabled", None) != enabled: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Tenant / project "{}" will be updated'.format(name) ret["changes"]["Enabled"] = "Will be {}".format(enabled) return ret __salt__["keystone.tenant_update"]( name=name, description=description, enabled=enabled, profile=profile, **connection_args ) ret["comment"] = 'Tenant / project "{}" has been updated'.format(name) ret["changes"]["Enabled"] = "Now {}".format(enabled) else: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Tenant / project "{}" will be added'.format(name) ret["changes"]["Tenant"] = "Will be created" return ret # Create tenant if _OS_IDENTITY_API_VERSION > 2: created = __salt__["keystone.project_create"]( name=name, domain="default", description=description, enabled=enabled, profile=profile, **connection_args ) else: created = __salt__["keystone.tenant_create"]( name=name, description=description, enabled=enabled, profile=profile, **connection_args ) ret["changes"]["Tenant"] = "Created" if created is True else "Failed" ret["result"] = created ret["comment"] = 'Tenant / project "{}" has been added'.format(name) return ret def tenant_absent(name, profile=None, **connection_args): """ Ensure that the keystone tenant is absent. name The name of the tenant that should not exist """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Tenant / project "{}" is already absent'.format(name), } # Check if tenant is present tenant = __salt__["keystone.tenant_get"]( name=name, profile=profile, **connection_args ) if "Error" not in tenant: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Tenant / project "{}" will be deleted'.format(name) return ret # Delete tenant __salt__["keystone.tenant_delete"]( name=name, profile=profile, **connection_args ) ret["comment"] = 'Tenant / project "{}" has been deleted'.format(name) ret["changes"]["Tenant/Project"] = "Deleted" return ret def project_present( name, description=None, enabled=True, profile=None, **connection_args ): """ Ensures that the keystone project exists Alias for tenant_present from V2 API to fulfill V3 API naming convention. .. versionadded:: 2016.11.0 name The name of the project to manage description The description to use for this project enabled Availability state for this project .. code-block:: yaml nova: keystone.project_present: - enabled: True - description: 'Nova Compute Service' """ return tenant_present( name, description=description, enabled=enabled, profile=profile, **connection_args ) def project_absent(name, profile=None, **connection_args): """ Ensure that the keystone project is absent. Alias for tenant_absent from V2 API to fulfill V3 API naming convention. .. versionadded:: 2016.11.0 name The name of the project that should not exist .. code-block:: yaml delete_nova: keystone.project_absent: - name: nova """ return tenant_absent(name, profile=profile, **connection_args) def role_present(name, profile=None, **connection_args): """' Ensures that the keystone role exists name The name of the role that should be present """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Role "{}" already exists'.format(name), } # Check if role is already present role = __salt__["keystone.role_get"](name=name, profile=profile, **connection_args) if "Error" not in role: return ret else: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Role "{}" will be added'.format(name) return ret # Create role __salt__["keystone.role_create"](name, profile=profile, **connection_args) ret["comment"] = 'Role "{}" has been added'.format(name) ret["changes"]["Role"] = "Created" return ret def role_absent(name, profile=None, **connection_args): """ Ensure that the keystone role is absent. name The name of the role that should not exist """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Role "{}" is already absent'.format(name), } # Check if role is present role = __salt__["keystone.role_get"](name=name, profile=profile, **connection_args) if "Error" not in role: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Role "{}" will be deleted'.format(name) return ret # Delete role __salt__["keystone.role_delete"](name=name, profile=profile, **connection_args) ret["comment"] = 'Role "{}" has been deleted'.format(name) ret["changes"]["Role"] = "Deleted" return ret def service_present( name, service_type, description=None, profile=None, **connection_args ): """ Ensure service present in Keystone catalog name The name of the service service_type The type of Openstack Service description (optional) Description of the service """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Service "{}" already exists'.format(name), } # Check if service is already present role = __salt__["keystone.service_get"]( name=name, profile=profile, **connection_args ) if "Error" not in role: return ret else: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Service "{}" will be added'.format(name) return ret # Create service __salt__["keystone.service_create"]( name, service_type, description, profile=profile, **connection_args ) ret["comment"] = 'Service "{}" has been added'.format(name) ret["changes"]["Service"] = "Created" return ret def service_absent(name, profile=None, **connection_args): """ Ensure that the service doesn't exist in Keystone catalog name The name of the service that should not exist """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Service "{}" is already absent'.format(name), } # Check if service is present role = __salt__["keystone.service_get"]( name=name, profile=profile, **connection_args ) if "Error" not in role: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Service "{}" will be deleted'.format(name) return ret # Delete service __salt__["keystone.service_delete"]( name=name, profile=profile, **connection_args ) ret["comment"] = 'Service "{}" has been deleted'.format(name) ret["changes"]["Service"] = "Deleted" return ret def endpoint_present( name, publicurl=None, internalurl=None, adminurl=None, region=None, profile=None, url=None, interface=None, **connection_args ): """ Ensure the specified endpoints exists for service name The Service name publicurl The public url of service endpoint (for V2 API) internalurl The internal url of service endpoint (for V2 API) adminurl The admin url of the service endpoint (for V2 API) region The region of the endpoint url The endpoint URL (for V3 API) interface The interface type, which describes the visibility of the endpoint. (for V3 API) """ ret = {"name": name, "changes": {}, "result": True, "comment": ""} _api_version(profile=profile, **connection_args) endpoint = __salt__["keystone.endpoint_get"]( name, region, profile=profile, interface=interface, **connection_args ) def _changes(desc): return ret.get("comment", "") + desc + "\n" def _create_endpoint(): if _OS_IDENTITY_API_VERSION > 2: ret["changes"] = __salt__["keystone.endpoint_create"]( name, region=region, url=url, interface=interface, profile=profile, **connection_args ) else: ret["changes"] = __salt__["keystone.endpoint_create"]( name, region=region, publicurl=publicurl, adminurl=adminurl, internalurl=internalurl, profile=profile, **connection_args ) if endpoint and "Error" not in endpoint and endpoint.get("region") == region: if _OS_IDENTITY_API_VERSION > 2: change_url = False change_interface = False if endpoint.get("url", None) != url: ret["comment"] = _changes( 'URL changes from "{}" to "{}"'.format( endpoint.get("url", None), url ) ) change_url = True if endpoint.get("interface", None) != interface: ret["comment"] = _changes( 'Interface changes from "{}" to "{}"'.format( endpoint.get("interface", None), interface ) ) change_interface = True if __opts__.get("test") and (change_url or change_interface): ret["result"] = None ret["changes"]["Endpoint"] = "Will be updated" ret["comment"] += 'Endpoint for service "{}" will be updated'.format( name ) return ret if change_url: ret["changes"]["url"] = url if change_interface: ret["changes"]["interface"] = interface else: change_publicurl = False change_adminurl = False change_internalurl = False if endpoint.get("publicurl", None) != publicurl: change_publicurl = True ret["comment"] = _changes( 'Public URL changes from "{}" to "{}"'.format( endpoint.get("publicurl", None), publicurl ) ) if endpoint.get("adminurl", None) != adminurl: change_adminurl = True ret["comment"] = _changes( 'Admin URL changes from "{}" to "{}"'.format( endpoint.get("adminurl", None), adminurl ) ) if endpoint.get("internalurl", None) != internalurl: change_internalurl = True ret["comment"] = _changes( 'Internal URL changes from "{}" to "{}"'.format( endpoint.get("internalurl", None), internalurl ) ) if __opts__.get("test") and ( change_publicurl or change_adminurl or change_internalurl ): ret["result"] = None ret["comment"] += 'Endpoint for service "{}" will be updated'.format( name ) ret["changes"]["Endpoint"] = "Will be updated" return ret if change_publicurl: ret["changes"]["publicurl"] = publicurl if change_adminurl: ret["changes"]["adminurl"] = adminurl if change_internalurl: ret["changes"]["internalurl"] = internalurl if ret["comment"]: # changed __salt__["keystone.endpoint_delete"]( name, region, profile=profile, interface=interface, **connection_args ) _create_endpoint() ret["comment"] += 'Endpoint for service "{}" has been updated'.format(name) else: # Add new endpoint if __opts__.get("test"): ret["result"] = None ret["changes"]["Endpoint"] = "Will be created" ret["comment"] = 'Endpoint for service "{}" will be added'.format(name) return ret _create_endpoint() ret["comment"] = 'Endpoint for service "{}" has been added'.format(name) if ret["comment"] == "": # => no changes ret["comment"] = 'Endpoint for service "{}" already exists'.format(name) return ret def endpoint_absent(name, region=None, profile=None, interface=None, **connection_args): """ Ensure that the endpoint for a service doesn't exist in Keystone catalog name The name of the service whose endpoints should not exist region (optional) The region of the endpoint. Defaults to ``RegionOne``. interface The interface type, which describes the visibility of the endpoint. (for V3 API) """ ret = { "name": name, "changes": {}, "result": True, "comment": 'Endpoint for service "{}"{} is already absent'.format( name, ', interface "{}",'.format(interface) if interface is not None else "", ), } # Check if service is present endpoint = __salt__["keystone.endpoint_get"]( name, region, profile=profile, interface=interface, **connection_args ) if not endpoint: return ret else: if __opts__.get("test"): ret["result"] = None ret["comment"] = 'Endpoint for service "{}" will be deleted'.format(name) return ret # Delete service __salt__["keystone.endpoint_delete"]( name, region, profile=profile, interface=interface, **connection_args ) ret["comment"] = 'Endpoint for service "{}"{} has been deleted'.format( name, ', interface "{}",'.format(interface) if interface is not None else "", ) ret["changes"]["endpoint"] = "Deleted" return ret
Save