oci_service_gateway – Manage service gateways in OCI

New in version 2.5.

Synopsis

  • This module allows the user to create, block or allow traffic to, delete and update a service gateway in OCI.

Requirements

The below requirements are needed on the host that executes this module.

Parameters

Parameter Choices/Defaults Comments
api_user
string
The OCID of the user, on whose behalf, OCI APIs are invoked. If not set, then the value of the OCI_USER_OCID environment variable, if any, is used. This option is required if the user is not specified through a configuration file (See config_file_location). To get the user's OCID, please refer https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm.
api_user_fingerprint
string
Fingerprint for the key pair being used. If not set, then the value of the OCI_USER_FINGERPRINT environment variable, if any, is used. This option is required if the key fingerprint is not specified through a configuration file (See config_file_location). To get the key pair's fingerprint value please refer https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm.
api_user_key_file
string
Full path and filename of the private key (in PEM format). If not set, then the value of the OCI_USER_KEY_FILE variable, if any, is used. This option is required if the private key is not specified through a configuration file (See config_file_location). If the key is encrypted with a pass-phrase, the api_user_key_pass_phrase option must also be provided.
api_user_key_pass_phrase
string
Passphrase used by the key referenced in api_user_key_file, if it is encrypted. If not set, then the value of the OCI_USER_KEY_PASS_PHRASE variable, if any, is used. This option is required if the key passphrase is not specified through a configuration file (See config_file_location).
auth_type
string
    Choices:
  • api_key ←
  • instance_principal
The type of authentication to use for making API requests. By default auth_type="api_key" based authentication is performed and the API key (see api_user_key_file) in your config file will be used. If this 'auth_type' module option is not specified, the value of the OCI_ANSIBLE_AUTH_TYPE, if any, is used. Use auth_type="instance_principal" to use instance principal based authentication when running ansible playbooks within an OCI compute instance.
block_traffic
boolean
    Choices:
  • no ←
  • yes
Whether the service gateway blocks all traffic through it. The default is false. When this is true, traffic is not routed to any services, regardless of route rules.
compartment_id
-
The OCID of the compartment to contain the service gateway. Required when creating a service gateway with state=present.
config_file_location
string
Path to configuration file. If not set then the value of the OCI_CONFIG_FILE environment variable, if any, is used. Otherwise, defaults to ~/.oci/config.
config_profile_name
string
The profile to load from the config file referenced by config_file_location. If not set, then the value of the OCI_CONFIG_PROFILE environment variable, if any, is used. Otherwise, defaults to the "DEFAULT" profile in config_file_location.
defined_tags
dictionary
Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see https://docs.us-phoenix-1.oraclecloud.com/Content/General/Concepts/resourcetags.htm.
display_name
-
A user-friendly name. Does not have to be unique, and it's changeable.

aliases: name
force_create
boolean
    Choices:
  • no ←
  • yes
Whether to attempt non-idempotent creation of a resource. By default, create resource is an idempotent operation, and doesn't create the resource if it already exists. Setting this option to true, forcefully creates a copy of the resource, even if it already exists.This option is mutually exclusive with key_by.
freeform_tags
dictionary
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see https://docs.us-phoenix-1.oraclecloud.com/Content/General/Concepts/resourcetags.htm.
key_by
list
The list of comma-separated attributes of this resource which should be used to uniquely identify an instance of the resource. By default, all the attributes of a resource except freeform_tags are used to uniquely identify a resource.
region
string
The Oracle Cloud Infrastructure region to use for all OCI API requests. If not set, then the value of the OCI_REGION variable, if any, is used. This option is required if the region is not specified through a configuration file (See config_file_location). Please refer to https://docs.us-phoenix-1.oraclecloud.com/Content/General/Concepts/regions.htm for more information on OCI regions.
service_gateway_id
-
The OCID of the service gateway. Required when deleting a service gateway with state=absent or updating a service gateway with state=present or to enable a service on a gateway using state=present or to disable a service on a gateway.

aliases: id
service_id
-
The OCID of the service. Required to enable a service on a gateway using state=present or disable a service on a gateway using state=absent.
services
-
List of the service OCIDs. These are the services that will be enabled on the service gateway. This list can be empty. Required to create a service gateway with state=present or update services enabled on a service gateway.
state
-
    Choices:
  • present ←
  • absent
Use state=present to create or update a service gateway or enable a service on a gateway. Use state=absent to delete a service gateway or disable a service on a gateway.
tenancy
string
OCID of your tenancy. If not set, then the value of the OCI_TENANCY variable, if any, is used. This option is required if the tenancy OCID is not specified through a configuration file (See config_file_location). To get the tenancy OCID, please refer https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm
vcn_id
-
The OCID of the VCN. Required to create a service gateway with state=present.
wait
boolean
    Choices:
  • no
  • yes ←
Whether to wait for create or delete operation to complete.
wait_timeout
integer
Default:
1200
Time, in seconds, to wait when wait=yes.
wait_until
string
The lifecycle state to wait for the resource to transition into when wait=yes. By default, when wait=yes, we wait for the resource to get into ACTIVE/ATTACHED/AVAILABLE/PROVISIONED/ RUNNING applicable lifecycle state during create operation & to get into DELETED/DETACHED/ TERMINATED lifecycle state during delete operation.

Examples

- name: Create a service gateway
  oci_service_gateway:
    compartment_id: 'ocid1.compartment.oc1..xxxxxEXAMPLExxxxx'
    services:
        - service_id: ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx
        - service_id: ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx
    vcn_id: 'ocid1.vcn.oc1.phx.xxxxxEXAMPLExxxxx'
    display_name: my_service_gateway

- name: Update list of all the services to be enabled on a service gateway
  oci_service_gateway:
    id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    services:
        - service_id: ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx

- name: Update service gateway to disable all services by using an empty list
  oci_service_gateway:
    id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    services: []

- name: Block all traffic through the service gateway
  oci_service_gateway:
    id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    block_traffic: True

- name: Allow traffic through the service gateway
  oci_service_gateway:
    id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    block_traffic: False

- name: Update the specified service gateway's display name
  oci_service_gateway:
    service_gateway_id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    display_name: ansible_service_gateway

- name: Enable/attach a service on a service gateway
  oci_service_gateway:
    service_gateway_id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    service_id: ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx

- name: Disable/detach a service from a service gateway
  oci_service_gateway:
    service_gateway_id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    service_id: ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx
    state: absent

- name: Delete the specified service gateway
  oci_service_gateway:
    id: ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx
    state: absent

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key Returned Description
service_gateway
dictionary
On successful operation
Information about the service gateway

Sample:
{'lifecycle_state': 'AVAILABLE', 'display_name': 'ansible_service_gateway', 'compartment_id': 'ocid1.compartment.oc1..xxxxxEXAMPLExxxxx', 'vcn_id': 'ocid1.vcn.oc1.phx.xxxxxEXAMPLExxxxx', 'defined_tags': {}, 'freeform_tags': {}, 'time_created': '2017-11-13T20:22:40.626000+00:00', 'block_traffic': False, 'services': [{'service_id': 'ocid1.service.oc1.phx.xxxxxEXAMPLExxxxx', 'service_name': 'OCI IAD Object Storage'}], 'id': 'ocid1.servicegateway.oc1.phx.xxxxxEXAMPLExxxxx'}


Status

  • This module is not guaranteed to have a backwards compatible interface. [preview]
  • This module is maintained by the Ansible Community. [community]

Authors

  • Rohit Chaware (@rohitChaware)

Hint

If you notice any issues in this documentation you can edit this document to improve it.