Refactored federation_idp{,_info} modules

Change-Id: Icbff6c799a9c33f1104633f7d9521f02228217a5
This commit is contained in:
Jakob Meng 2022-08-22 14:09:39 +02:00
parent c9afdbfd73
commit 90b110794f
5 changed files with 493 additions and 591 deletions

View File

@ -1,29 +1,14 @@
idp_name: 'test-idp' expected_fields:
idp_name_2: 'test-idp-2' - description
idp_description: 'My example IDP' - domain_id
idp_description_2: 'My example Identity Provider' - id
- is_enabled
domain_name: 'test-domain' - name
- remote_ids
remote_ids_1: remote_ids_1:
- 'https://auth.example.com/auth/realms/ExampleRealm' - 'https://auth.example.com/auth/realms/ExampleRealm'
- 'https://auth.stage.example.com/auth/realms/ExampleRealm' - 'https://auth.stage.example.com/auth/realms/ExampleRealm'
remote_ids_2: remote_ids_2:
- 'https://auth.example.com/auth/realms/ExampleRealm' - 'https://auth.example.com/auth/realms/ExampleRealm'
remote_ids_3: remote_ids_3:
- 'https://auth.stage.example.com/auth/realms/ExampleRealm' - 'https://auth.stage.example.com/auth/realms/ExampleRealm'
idp_info_expected_fields:
- description
- domain_id
- id
- is_enabled
- name
- remote_ids
idp_expected_fields:
- description
- domain_id
- id
- is_enabled
- name
- remote_ids

View File

@ -18,136 +18,133 @@
block: block:
# ======================================================================== # ========================================================================
# Initial setup # Initial setup
- name: 'Create test domain' - name: 'Create test domain'
openstack.cloud.identity_domain: openstack.cloud.identity_domain:
name: '{{ domain_name }}' name: ansible_domain
register: create_domain register: domain
- name: 'Store domain ID as fact'
set_fact:
domain_id: '{{ create_domain.domain.id }}'
# We *should* have a blank slate to start with, but we also shouldn't # We *should* have a blank slate to start with, but we also should not
# explode if I(state=absent) and the IDP doesn't exist # explode if state is absent and the identity provider does not exist
- name: "Ensure IDP doesn't exist to start" - name: "Ensure IDP doesn't exist to start"
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: delete_idp
- assert:
that:
- delete_idp is successful
# ======================================================================== # ========================================================================
# Creation (simple case) # Creation (simple case)
- name: 'Create IDP - CHECK_MODE' - name: 'Create IDP - CHECK_MODE'
check_mode: yes check_mode: true
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' id: 'ansible_identity_provider'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
register: create_idp register: idp
- assert: - assert:
that: that:
- create_idp is successful - idp is changed
- create_idp is changed
- name: 'Fetch identity_provider info (provider should be absent)' - name: 'Fetch identity_provider info (provider should be absent)'
openstack.cloud.federation_idp_info: openstack.cloud.federation_idp_info:
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: identity_provider_info register: idps
- assert: - assert:
that: that:
- identity_provider_info.identity_providers | length == 0 - idps.identity_providers | length == 0
- name: 'Create IDP' - name: 'Create IDP'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is changed
- create_identity_provider is changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - not _idp.description
- not idp.description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == []
- idp.remote_ids == []
vars: vars:
idp: '{{ create_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: Verify returned values - name: Assert return values of federation_idp module
assert: assert:
that: item in create_identity_provider.identity_provider that:
loop: "{{ idp_expected_fields }}" # allow new fields to be introduced but prevent fields from being removed
- expected_fields|difference(idp.identity_provider.keys())|length == 0
- name: 'Fetch IDP info - with name' - name: 'Fetch IDP info - with name'
openstack.cloud.federation_idp_info: openstack.cloud.federation_idp_info:
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: identity_provider_info register: idps
- assert: - assert:
that: that:
- idps | length == 1 - _idps | length == 1
- idp.id == idp_name - _idp.id == 'ansible_identity_provider'
- idp.name == idp_name - _idp.name == 'ansible_identity_provider'
- idp.domain_id == domain_id - _idp.domain_id == domain.domain.id
- not idp.description - not _idp.description
- idp.is_enabled == True - _idp.is_enabled == False
- idp.remote_ids == [] - _idp.remote_ids == []
vars: vars:
idps: '{{ identity_provider_info.identity_providers }}' _idps: '{{ idps.identity_providers }}'
idp: '{{ identity_provider_info.identity_providers[0] }}' _idp: '{{ idps.identity_providers[0] }}'
- name: Verify returned values - name: Assert return values of federation_idp_info module
assert: assert:
that: item in identity_provider_info.identity_providers[0] that:
loop: "{{ idp_info_expected_fields }}" # allow new fields to be introduced but prevent fields from being removed
- expected_fields|difference(idps.identity_providers.0.keys())|length == 0
- name: 'Fetch identity_provider info - without name' - name: 'Fetch identity_provider info - without name'
openstack.cloud.federation_idp_info: {} openstack.cloud.federation_idp_info: {}
register: identity_provider_info register: idps
- assert: - assert:
that: that:
- '"identity_providers" in identity_provider_info'
# In CI we generally have a clean slate, but this might # In CI we generally have a clean slate, but this might
# not be true for everyone... # not be true for everyone...
- idps | length >= 1 - _idps | length >= 1
vars: vars:
idps: '{{ identity_provider_info.identity_providers }}' _idps: '{{ idps.identity_providers }}'
- name: 'Create identity_provider (retry - no change) - CHECK_MODE' - name: 'Create identity_provider (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is not changed
- create_identity_provider is not changed
- name: 'Create identity_provider (retry - no change)' - name: 'Create identity_provider (retry - no change)'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is not changed
- create_identity_provider is not changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - not _idp.description
- not idp.description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == []
- idp.remote_ids == []
vars: vars:
idp: '{{ create_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
# ======================================================================== # ========================================================================
# Update (simple cases) # Update (simple cases)
@ -155,219 +152,220 @@
- name: 'Update IDP set description - CHECK_MODE' - name: 'Update IDP set description - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description }}' description: 'ansible idp 1'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed
- name: 'Update IDP set description' - name: 'Update IDP set description'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description }}' description: 'ansible idp 1'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == []
- idp.remote_ids == []
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update IDP set description (retry - no change) - CHECK_MODE' - name: 'Update IDP set description (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description }}' description: 'ansible idp 1'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed
- name: 'Update IDP set description (retry - no change)' - name: 'Update IDP set description (retry - no change)'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description }}' description: 'ansible idp 1'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == []
- idp.remote_ids == []
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update IDP set Remote IDs - CHECK_MODE' - name: 'Update IDP set Remote IDs - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
remote_ids: '{{ remote_ids_1 }}' remote_ids: '{{ remote_ids_1 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed
- name: 'Update IDP set Remote IDs' - name: 'Update IDP set Remote IDs'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
remote_ids: '{{ remote_ids_1 }}' remote_ids: '{{ remote_ids_1 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == remote_ids_1
- idp.remote_ids == remote_ids_1
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update IDP set Remote IDs (retry - no change) - CHECK_MODE' - name: 'Update IDP set Remote IDs (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
remote_ids: '{{ remote_ids_1 }}' remote_ids: '{{ remote_ids_1 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed
- name: 'Update IDP set Remote IDs (retry - no change)' - name: 'Update IDP set Remote IDs (retry - no change)'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
remote_ids: '{{ remote_ids_1 }}' remote_ids: '{{ remote_ids_1 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == True - _idp.remote_ids == remote_ids_1
- idp.remote_ids == remote_ids_1
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update IDP set Disabled - CHECK_MODE' - name: 'Update IDP set Enabled - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
enabled: False is_enabled: True
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed
- name: 'Update IDP set Disabled' - name: 'Update IDP set Disabled'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
enabled: False is_enabled: True
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == True
- idp.is_enabled == False - _idp.remote_ids == remote_ids_1
- idp.remote_ids == remote_ids_1
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update IDP set Disabled (retry - no change) - CHECK_MODE' - name: 'Update IDP set Enabled (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
enabled: False is_enabled: True
register: update_identity_provider register: idp
- assert:
that:
- update_identity_provider is successful
- update_identity_provider is not changed
- name: 'Update IDP set Disabled (retry - no change)'
openstack.cloud.federation_idp:
state: 'present'
name: '{{ idp_name }}'
enabled: False
register: update_identity_provider
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed
- idp.id == idp_name - name: 'Update IDP set Enabled (retry - no change)'
- idp.name == idp_name openstack.cloud.federation_idp:
- idp.domain_id == domain_id state: present
- idp.description == idp_description name: 'ansible_identity_provider'
- idp.is_enabled == False is_enabled: True
- idp.remote_ids == remote_ids_1 register: idp
- assert:
that:
- idp is not changed
- _idp.id == 'ansible_identity_provider'
- _idp.name == 'ansible_identity_provider'
- _idp.domain_id == domain.domain.id
- _idp.description == 'ansible idp 1'
- _idp.is_enabled == True
- _idp.remote_ids == remote_ids_1
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
# If we don't specify anything to change, then nothing should change... # If we don't specify anything to change, then nothing should change...
- name: 'Minimal call to IDP (no change) - CHECK_MODE' - name: 'Minimal call to IDP (no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed
- name: 'Minimal call to IDP (no change)' - name: 'Minimal call to IDP (no change)'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: update_identity_provider is_enabled: True
register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == True
- idp.is_enabled == False - _idp.remote_ids == remote_ids_1
- idp.remote_ids == remote_ids_1
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
# ======================================================================== # ========================================================================
# Update (mass-update) # Update (mass-update)
@ -375,72 +373,72 @@
- name: 'Update all updatable IDP parameters - CHECK_MODE' - name: 'Update all updatable IDP parameters - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description_2 }}' description: 'ansible idp 2'
enabled: True is_enabled: True
remote_ids: '{{ remote_ids_2 }}' remote_ids: '{{ remote_ids_2 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed
- name: 'Update all updatable IDP parameters' - name: 'Update all updatable IDP parameters'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description_2 }}' description: 'ansible idp 2'
enabled: True is_enabled: True
remote_ids: '{{ remote_ids_2 }}' remote_ids: '{{ remote_ids_2 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is changed
- update_identity_provider is changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 2'
- idp.description == idp_description_2 - _idp.is_enabled == True
- idp.is_enabled == True - _idp.remote_ids == remote_ids_2
- idp.remote_ids == remote_ids_2
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Update all updatable IDP parameters (no change) - CHECK_MODE' - name: 'Update all updatable IDP parameters (no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description_2 }}' description: 'ansible idp 2'
enabled: True is_enabled: True
remote_ids: '{{ remote_ids_2 }}' remote_ids: '{{ remote_ids_2 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed
- name: 'Update all updatable IDP parameters (no change)' - name: 'Update all updatable IDP parameters (no change)'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name }}' name: 'ansible_identity_provider'
description: '{{ idp_description_2 }}' description: 'ansible idp 2'
enabled: True is_enabled: True
remote_ids: '{{ remote_ids_2 }}' remote_ids: '{{ remote_ids_2 }}'
register: update_identity_provider register: idp
- assert: - assert:
that: that:
- update_identity_provider is successful - idp is not changed
- update_identity_provider is not changed - _idp.id == 'ansible_identity_provider'
- idp.id == idp_name - _idp.name == 'ansible_identity_provider'
- idp.name == idp_name - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 2'
- idp.description == idp_description_2 - _idp.is_enabled == True
- idp.is_enabled == True - _idp.remote_ids == remote_ids_2
- idp.remote_ids == remote_ids_2
vars: vars:
idp: '{{ update_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
# ======================================================================== # ========================================================================
# Create complex IDP # Create complex IDP
@ -448,190 +446,190 @@
- name: 'Create complex IDP - CHECK_MODE' - name: 'Create complex IDP - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
description: '{{ idp_description }}' description: 'ansible idp 1'
enabled: False is_enabled: False
remote_ids: '{{ remote_ids_3 }}' remote_ids: '{{ remote_ids_3 }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is changed
- create_identity_provider is changed
- name: 'Create complex IDP' - name: 'Create complex IDP'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
description: '{{ idp_description }}' description: 'ansible idp 1'
enabled: False is_enabled: False
remote_ids: '{{ remote_ids_3 }}' remote_ids: '{{ remote_ids_3 }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is changed
- create_identity_provider is changed - _idp.id == 'ansible_identity_provider2'
- idp.id == idp_name_2 - _idp.name == 'ansible_identity_provider2'
- idp.name == idp_name_2 - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == False - _idp.remote_ids == remote_ids_3
- idp.remote_ids == remote_ids_3
vars: vars:
idp: '{{ create_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
- name: 'Create complex IDP (retry - no change) - CHECK_MODE' - name: 'Create complex IDP (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
description: '{{ idp_description }}' description: 'ansible idp 1'
enabled: False is_enabled: False
remote_ids: '{{ remote_ids_3 }}' remote_ids: '{{ remote_ids_3 }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is not changed
- create_identity_provider is not changed
- name: 'Create complex IDP' - name: 'Create complex IDP'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'present' state: present
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
domain_id: '{{ domain_id }}' domain_id: '{{ domain.domain.id }}'
description: '{{ idp_description }}' description: 'ansible idp 1'
enabled: False is_enabled: False
remote_ids: '{{ remote_ids_3 }}' remote_ids: '{{ remote_ids_3 }}'
register: create_identity_provider register: idp
- assert: - assert:
that: that:
- create_identity_provider is successful - idp is not changed
- create_identity_provider is not changed - _idp.id == 'ansible_identity_provider2'
- idp.id == idp_name_2 - _idp.name == 'ansible_identity_provider2'
- idp.name == idp_name_2 - _idp.domain_id == domain.domain.id
- idp.domain_id == domain_id - _idp.description == 'ansible idp 1'
- idp.description == idp_description - _idp.is_enabled == False
- idp.is_enabled == False - _idp.remote_ids == remote_ids_3
- idp.remote_ids == remote_ids_3
vars: vars:
idp: '{{ create_identity_provider.identity_provider }}' _idp: '{{ idp.identity_provider }}'
# Attempt to ensure that if we search we only get the one we expect # Attempt to ensure that if we search we only get the one we expect
- name: 'Fetch Complex IDP info - with name' - name: 'Fetch Complex IDP info - with name'
openstack.cloud.federation_idp_info: openstack.cloud.federation_idp_info:
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
register: identity_provider_info register: idps
- assert: - assert:
that: that:
- identity_provider_info.identity_providers | length == 1 - idps.identity_providers | length == 1
- idp.id == idp_name_2 - _idp.id == 'ansible_identity_provider2'
- idp.name == idp_name_2 - _idp.name == 'ansible_identity_provider2'
- idp.domain_id == domain_id - _idp.domain_id == domain.domain.id
- idp.description == idp_description - _idp.description == 'ansible idp 1'
- idp.is_enabled == False - _idp.is_enabled == False
- idp.remote_ids == remote_ids_3 - _idp.remote_ids == remote_ids_3
vars: vars:
idp: '{{ identity_provider_info.identity_providers[0] }}' _idp: '{{ idps.identity_providers[0] }}'
# Ensure that if we do search we get both of the results we expect # Ensure that if we do search we get both of the results we expect
- name: 'Fetch multiple IDP info - without name' - name: 'Fetch multiple IDP info - without name'
openstack.cloud.federation_idp_info: {} openstack.cloud.federation_idp_info: {}
register: identity_provider_info register: idps
- assert: - assert:
that: that:
# In CI we generally have a clean slate, but this might # In CI we generally have a clean slate, but this might
# not be true for everyone... # not be true for everyone...
- identity_provider_info.identity_providers | length >= 2 - idps.identity_providers | length >= 2
# In theory these could be attached to different IDPs but let's keep # In theory these could be attached to different IDPs but let's keep
# things simple # things simple
- idp_name in (identity_provider_info.identity_providers | map(attribute='id')) - "'ansible_identity_provider' in (idps.identity_providers | map(attribute='id'))"
- idp_name in (identity_provider_info.identity_providers | map(attribute='name')) - "'ansible_identity_provider' in (idps.identity_providers | map(attribute='name'))"
- idp_name_2 in (identity_provider_info.identity_providers | map(attribute='id')) - "'ansible_identity_provider2' in (idps.identity_providers | map(attribute='id'))"
- idp_name_2 in (identity_provider_info.identity_providers | map(attribute='name')) - "'ansible_identity_provider2' in (idps.identity_providers | map(attribute='name'))"
- domain_id in (identity_provider_info.identity_providers | map(attribute='domain_id')) - domain.domain.id in (idps.identity_providers | map(attribute='domain_id'))
- idp_description in (identity_provider_info.identity_providers | map(attribute='description')) - "'ansible idp 1' in (idps.identity_providers | map(attribute='description'))"
- idp_description_2 in (identity_provider_info.identity_providers | map(attribute='description')) - "'ansible idp 2' in (idps.identity_providers | map(attribute='description'))"
- True in (identity_provider_info.identity_providers | map(attribute='is_enabled')) - True in (idps.identity_providers | map(attribute='is_enabled'))
- False in (identity_provider_info.identity_providers | map(attribute='is_enabled')) - False in (idps.identity_providers | map(attribute='is_enabled'))
- name: 'Delete identity_provider - CHECK_MODE' - name: 'Delete identity_provider - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: delete_identity_provider register: idp
- assert: - assert:
that: that:
- delete_identity_provider is successful - idp is changed
- delete_identity_provider is changed
- name: 'Delete identity_provider' - name: 'Delete identity_provider'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: delete_identity_provider register: idp
- assert: - assert:
that: that:
- delete_identity_provider is successful - idp is changed
- delete_identity_provider is changed
- name: 'Delete identity_provider (retry - no change) - CHECK_MODE' - name: 'Delete identity_provider (retry - no change) - CHECK_MODE'
check_mode: yes check_mode: yes
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: delete_identity_provider register: idp
- assert: - assert:
that: that:
- delete_identity_provider is successful - idp is not changed
- delete_identity_provider is not changed
- name: 'Delete identity_provider (retry - no change) ' - name: 'Delete identity_provider (retry - no change) '
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: delete_identity_provider register: idp
- assert: - assert:
that: that:
- delete_identity_provider is successful - idp is not changed
- delete_identity_provider is not changed
- name: 'Fetch identity_provider info after deletion' - name: 'Fetch identity_provider info after deletion'
openstack.cloud.federation_idp_info: openstack.cloud.federation_idp_info:
name: '{{ idp_name }}' name: 'ansible_identity_provider'
register: identity_provider_info register: idps
- assert: - assert:
that: that:
- identity_provider_info.identity_providers | length == 0 - idps.identity_providers | length == 0
- name: 'Delete second identity_provider' - name: 'Delete second identity_provider'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
register: delete_identity_provider register: idp
- assert: - assert:
that: that:
- delete_identity_provider is successful - idp is changed
- delete_identity_provider is changed
always: always:
- name: 'Delete idp' - name: 'Delete idp'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name }}' name: 'ansible_identity_provider'
ignore_errors: yes
- name: 'Delete second identity_provider' - name: 'Delete second identity_provider'
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
state: 'absent' state: absent
name: '{{ idp_name_2 }}' name: 'ansible_identity_provider2'
ignore_errors: yes
- name: 'Delete domain' - name: 'Delete domain'
openstack.cloud.identity_domain: openstack.cloud.identity_domain:
state: 'absent' state: absent
name: '{{ domain_name }}' name: ansible_domain
ignore_errors: yes

View File

@ -24,9 +24,7 @@
- { role: identity_role, tags: identity_role } - { role: identity_role, tags: identity_role }
- { role: image, tags: image } - { role: image, tags: image }
- { role: keypair, tags: keypair } - { role: keypair, tags: keypair }
- role: keystone_idp - { role: keystone_idp, tags: keystone_idp }
tags: keystone_idp
when: sdk_version is version(0.44, '>=')
- role: keystone_federation_protocol - role: keystone_federation_protocol
tags: keystone_federation_protocol tags: keystone_federation_protocol
when: sdk_version is version(0.44, '>=') when: sdk_version is version(0.44, '>=')

View File

@ -4,54 +4,54 @@
# Copyright: Ansible Project # Copyright: Ansible Project
# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) # GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
DOCUMENTATION = ''' DOCUMENTATION = r'''
---
module: federation_idp module: federation_idp
short_description: manage a federation Identity Provider short_description: Manage an identity provider in a OpenStack cloud
author: OpenStack Ansible SIG author: OpenStack Ansible SIG
description: description:
- Manage a federation Identity Provider. - Create, update or delete an identity provider of the OpenStack
identity (Keystone) service.
options: options:
name:
description:
- The name of the Identity Provider.
type: str
required: true
aliases: ['id']
state:
description:
- Whether the Identity Provider should be C(present) or C(absent).
choices: ['present', 'absent']
default: present
type: str
description: description:
description: description:
- The description of the Identity Provider. - The description of the identity provider.
type: str type: str
domain_id: domain_id:
description: description:
- The ID of a domain that is associated with the Identity Provider. - The ID of a domain that is associated with the identity provider.
Federated users that authenticate with the Identity Provider will be - Federated users that authenticate with the identity provider will be
created under the domain specified. created under the domain specified.
- Required when creating a new Identity Provider. - Required when creating a new identity provider.
type: str type: str
enabled: id:
description: description:
- Whether the Identity Provider is enabled or not. - The ID (and name) of the identity provider.
- Will default to C(true) when creating a new Identity Provider. type: str
required: true
aliases: ['name']
is_enabled:
description:
- Whether the identity provider is enabled or not.
- Will default to C(false) when creating a new identity provider.
type: bool type: bool
aliases: ['is_enabled'] aliases: ['enabled']
remote_ids: remote_ids:
description: description:
- "List of the unique Identity Provider's remote IDs." - "List of the unique identity provider's remote IDs."
- Will default to an empty list when creating a new Identity Provider. - Will default to an empty list when creating a new identity provider.
type: list type: list
elements: str elements: str
state:
description:
- Whether the identity provider should be C(present) or C(absent).
choices: ['present', 'absent']
default: present
type: str
extends_documentation_fragment: extends_documentation_fragment:
- openstack.cloud.openstack - openstack.cloud.openstack
''' '''
EXAMPLES = ''' EXAMPLES = r'''
- name: Create an identity provider - name: Create an identity provider
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
cloud: example_cloud cloud: example_cloud
@ -59,7 +59,7 @@ EXAMPLES = '''
domain_id: 0123456789abcdef0123456789abcdef domain_id: 0123456789abcdef0123456789abcdef
description: 'My example IDP' description: 'My example IDP'
remote_ids: remote_ids:
- 'https://auth.example.com/auth/realms/ExampleRealm' - 'https://auth.example.com/auth/realms/ExampleRealm'
- name: Delete an identity provider - name: Delete an identity provider
openstack.cloud.federation_idp: openstack.cloud.federation_idp:
@ -68,160 +68,86 @@ EXAMPLES = '''
state: absent state: absent
''' '''
RETURN = ''' RETURN = r'''
identity_provider: identity_provider:
description: Dictionary describing the identity providers description: Dictionary describing the identity providers
returned: On success when I(state) is 'present' returned: On success when I(state) is C(present).
type: dict type: dict
elements: dict contains:
contains: description:
description: description: Identity provider description
description: Identity provider description type: str
type: str sample: "demodescription"
sample: "demodescription" domain_id:
domain_id: description: Domain to which the identity provider belongs
description: Domain to which the identity provider belongs type: str
type: str sample: "default"
sample: "default" id:
id: description: Identity provider ID
description: Identity provider ID type: str
type: str sample: "test-idp"
sample: "test-idp" is_enabled:
is_enabled: description: Indicates whether the identity provider is enabled
description: Indicates whether the identity provider is enabled type: bool
type: bool name:
name: description: Name of the identity provider, equals its ID.
description: Name of the identity provider, equals its ID. type: str
type: str sample: "test-idp"
sample: "test-idp" remote_ids:
remote_ids: description: Remote IDs associated with the identity provider
description: Remote IDs associated with the identity provider type: list
type: list
''' '''
from ansible_collections.openstack.cloud.plugins.module_utils.openstack import OpenStackModule from ansible_collections.openstack.cloud.plugins.module_utils.openstack import OpenStackModule
from ansible_collections.openstack.cloud.plugins.module_utils.resource import StateMachine
class IdentityFederationIdpModule(OpenStackModule): class IdentityProviderModule(OpenStackModule):
argument_spec = dict( argument_spec = dict(
name=dict(required=True, aliases=['id']),
state=dict(default='present', choices=['absent', 'present']),
description=dict(), description=dict(),
domain_id=dict(), domain_id=dict(),
enabled=dict(type='bool', aliases=['is_enabled']), id=dict(required=True, aliases=['name']),
is_enabled=dict(type='bool', aliases=['enabled']),
remote_ids=dict(type='list', elements='str'), remote_ids=dict(type='list', elements='str'),
state=dict(default='present', choices=['absent', 'present']),
) )
module_kwargs = dict( module_kwargs = dict(
supports_check_mode=True, supports_check_mode=True,
) )
def delete_identity_provider(self, idp):
"""
Delete an existing Identity Provider
returns: the "Changed" state
"""
if idp is None:
return False
if self.ansible.check_mode:
return True
self.conn.identity.delete_identity_provider(idp)
return True
def create_identity_provider(self, name):
"""
Create a new Identity Provider
returns: the "Changed" state and the new identity provider
"""
if self.ansible.check_mode:
return True, None
description = self.params.get('description')
enabled = self.params.get('enabled')
domain_id = self.params.get('domain_id')
remote_ids = self.params.get('remote_ids')
if enabled is None:
enabled = True
if remote_ids is None:
remote_ids = []
attributes = {
'domain_id': domain_id,
'enabled': enabled,
'remote_ids': remote_ids,
}
if description is not None:
attributes['description'] = description
idp = self.conn.identity.create_identity_provider(id=name, **attributes)
return (True, idp.to_dict(computed=False))
def update_identity_provider(self, idp):
"""
Update an existing Identity Provider
returns: the "Changed" state and the new identity provider
"""
description = self.params.get('description')
enabled = self.params.get('enabled')
domain_id = self.params.get('domain_id')
remote_ids = self.params.get('remote_ids')
attributes = {}
if (description is not None) and (description != idp.description):
attributes['description'] = description
if (enabled is not None) and (enabled != idp.is_enabled):
attributes['enabled'] = enabled
if (domain_id is not None) and (domain_id != idp.domain_id):
attributes['domain_id'] = domain_id
if (remote_ids is not None) and (remote_ids != idp.remote_ids):
attributes['remote_ids'] = remote_ids
if not attributes:
return False, idp.to_dict(computed=False)
if self.ansible.check_mode:
return True, None
new_idp = self.conn.identity.update_identity_provider(idp, **attributes)
return (True, new_idp.to_dict(computed=False))
def run(self): def run(self):
""" Module entry point """ sm = StateMachine(connection=self.conn,
service_name='identity',
type_name='identity_provider',
sdk=self.sdk)
name = self.params.get('name') kwargs = dict((k, self.params[k])
state = self.params.get('state') for k in ['state', 'timeout']
changed = False if self.params[k] is not None)
idp = self.conn.identity.find_identity_provider(name) kwargs['attributes'] = \
dict((k, self.params[k])
for k in ['description', 'domain_id', 'id', 'is_enabled',
'remote_ids']
if self.params[k] is not None)
if state == 'absent': identity_provider, is_changed = \
if idp is not None: sm(check_mode=self.ansible.check_mode,
changed = self.delete_identity_provider(idp) updateable_attributes=None,
self.exit_json(changed=changed) non_updateable_attributes=['domain_id'],
wait=False,
**kwargs)
# state == 'present' if identity_provider is None:
self.exit_json(changed=is_changed)
else: else:
if idp is None: self.exit_json(
if self.params.get('domain_id') is None: changed=is_changed,
self.fail_json(msg='A domain_id must be passed when creating' identity_provider=identity_provider.to_dict(computed=False))
' an identity provider')
(changed, idp) = self.create_identity_provider(name)
self.exit_json(changed=changed, identity_provider=idp)
(changed, new_idp) = self.update_identity_provider(idp)
self.exit_json(changed=changed, identity_provider=new_idp)
def main(): def main():
module = IdentityFederationIdpModule() module = IdentityProviderModule()
module() module()

View File

@ -4,25 +4,23 @@
# Copyright: Ansible Project # Copyright: Ansible Project
# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) # GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
DOCUMENTATION = ''' DOCUMENTATION = r'''
---
module: federation_idp_info module: federation_idp_info
short_description: Get the information about the available federation identity short_description: Fetch OpenStack federation identity providers
providers
author: OpenStack Ansible SIG author: OpenStack Ansible SIG
description: description:
- Fetch available federation identity providers. - Fetch OpenStack federation identity providers.
options: options:
name: id:
description: description:
- The name of the identity provider to fetch. - The ID (and name) of the identity provider to fetch.
type: str type: str
aliases: ['id'] aliases: ['name']
extends_documentation_fragment: extends_documentation_fragment:
- openstack.cloud.openstack - openstack.cloud.openstack
''' '''
EXAMPLES = ''' EXAMPLES = r'''
- name: Fetch a specific identity provider - name: Fetch a specific identity provider
openstack.cloud.federation_idp_info: openstack.cloud.federation_idp_info:
cloud: example_cloud cloud: example_cloud
@ -33,35 +31,35 @@ EXAMPLES = '''
cloud: example_cloud cloud: example_cloud
''' '''
RETURN = ''' RETURN = r'''
identity_providers: identity_providers:
description: Dictionary describing the identity providers description: Dictionary describing the identity providers
returned: success returned: always
type: list type: list
elements: dict elements: dict
contains: contains:
description: description:
description: Identity provider description description: Identity provider description
type: str type: str
sample: "demodescription" sample: "demodescription"
domain_id: domain_id:
description: Domain to which the identity provider belongs description: Domain to which the identity provider belongs
type: str type: str
sample: "default" sample: "default"
id: id:
description: Identity provider ID description: Identity provider ID
type: str type: str
sample: "test-idp" sample: "test-idp"
is_enabled: is_enabled:
description: Indicates wether the identity provider is enabled description: Indicates whether the identity provider is enabled
type: bool type: bool
name: name:
description: Name of the identity provider, equals its ID. description: Name of the identity provider, equals its ID.
type: str type: str
sample: "test-idp" sample: "test-idp"
remote_ids: remote_ids:
description: Remote IDs associated with the identity provider description: Remote IDs associated with the identity provider
type: list type: list
''' '''
from ansible_collections.openstack.cloud.plugins.module_utils.openstack import OpenStackModule from ansible_collections.openstack.cloud.plugins.module_utils.openstack import OpenStackModule
@ -69,24 +67,21 @@ from ansible_collections.openstack.cloud.plugins.module_utils.openstack import O
class IdentityFederationIdpInfoModule(OpenStackModule): class IdentityFederationIdpInfoModule(OpenStackModule):
argument_spec = dict( argument_spec = dict(
name=dict(aliases=['id']), id=dict(aliases=['name']),
) )
module_kwargs = dict( module_kwargs = dict(
supports_check_mode=True supports_check_mode=True
) )
def run(self): def run(self):
""" Module entry point """ kwargs = dict((k, self.params[k])
for k in ['id']
name = self.params['name'] if self.params[k] is not None)
identity_providers = self.conn.identity.identity_providers(**kwargs)
query = {} self.exit_json(
if name: changed=False,
query["id"] = name identity_providers=[i.to_dict(computed=False)
for i in identity_providers])
idps = self.conn.identity.identity_providers(**query)
idps = [idp.to_dict(computed=False) for idp in idps]
self.exit_json(changed=False, identity_providers=idps)
def main(): def main():