amazon.cloud.rdsdb_proxy (0.1.0) — module

Create and manage DB proxies

| "added in version" 0.1.0 of amazon.cloud"

Authors: Ansible Cloud Team (@ansible-collections)

Install collection

Install with ansible-galaxy collection install amazon.cloud:==0.1.0


Add to requirements.yml

  collections:
    - name: amazon.cloud
      version: 0.1.0

Description

Creates and manage DB proxies (list, create, update, describe, delete).


Requirements

Inputs

    
auth:
    description:
    - The authorization mechanism that the proxy uses.
    elements: dict
    required: true
    suboptions:
      auth_scheme:
        choices:
        - SECRETS
        description:
        - The type of authentication that the proxy uses for connections from the proxy
          to the underlying database.
        type: str
      description:
        description:
        - A user-specified description about the authentication used by a proxy to log
          in as a specific database user.
        type: str
      iam_auth:
        choices:
        - DISABLED
        - REQUIRED
        description:
        - Whether to require or disallow AWS Identity and Access Management (IAM) authentication
          for connections to the proxy.
        type: str
      secret_arn:
        description:
        - The Amazon Resource Name (ARN) representing the secret that the proxy uses to
          authenticate to the RDS DB instance or Aurora DB cluster.
        - These secrets are stored within Amazon Secrets Manager.
        type: str
      user_name:
        description:
        - The name of the database user to which the proxy connects.
        type: str
    type: list

tags:
    aliases:
    - resource_tags
    description:
    - A dict of tags to apply to the resource.
    - To remove all tags set I(tags={}) and I(purge_tags=true).
    required: false
    type: dict

wait:
    default: false
    description:
    - Wait for operation to complete before returning.
    type: bool

state:
    choices:
    - present
    - absent
    - list
    - describe
    - get
    default: present
    description:
    - Goal state for resource.
    - I(state=present) creates the resource if it doesn't exist, or updates to the provided
      state if the resource already exists.
    - I(state=absent) ensures an existing instance is deleted.
    - I(state=list) get all the existing resources.
    - I(state=describe) or I(state=get) retrieves information on an existing resource.
    type: str

region:
    aliases:
    - aws_region
    - ec2_region
    description:
    - The AWS region to use. If not specified then the value of the AWS_REGION or EC2_REGION
      environment variable, if any, is used. See U(http://docs.aws.amazon.com/general/latest/gr/rande.html#ec2_region)
    type: str

ec2_url:
    aliases:
    - aws_endpoint_url
    - endpoint_url
    description:
    - URL to use to connect to EC2 or your Eucalyptus cloud (by default the module will
      use EC2 endpoints). Ignored for modules where region is required. Must be specified
      for all other modules if region is not used. If not set then the value of the EC2_URL
      environment variable, if any, is used.
    type: str

profile:
    aliases:
    - aws_profile
    description:
    - Using I(profile) will override I(aws_access_key), I(aws_secret_key) and I(security_token)
      and support for passing them at the same time as I(profile) has been deprecated.
    - I(aws_access_key), I(aws_secret_key) and I(security_token) will be made mutually
      exclusive with I(profile) after 2022-06-01.
    type: str

role_arn:
    description:
    - The Amazon Resource Name (ARN) of the IAM role that the proxy uses to access secrets
      in AWS Secrets Manager.
    required: true
    type: str

aws_config:
    description:
    - A dictionary to modify the botocore configuration.
    - Parameters can be found at U(https://botocore.amazonaws.com/v1/documentation/api/latest/reference/config.html#botocore.config.Config).
    type: dict

purge_tags:
    default: true
    description:
    - Remove tags not listed in I(tags).
    required: false
    type: bool

require_tls:
    description:
    - A Boolean parameter that specifies whether Transport Layer Security (TLS) encryption
      is required for connections to the proxy.
    type: bool

wait_timeout:
    default: 320
    description:
    - How many seconds to wait for an operation to complete before timing out.
    type: int

aws_ca_bundle:
    description:
    - The location of a CA Bundle to use when validating SSL certificates.
    - 'Note: The CA Bundle is read ''module'' side and may need to be explicitly copied
      from the controller if not run locally.'
    type: path

db_proxy_name:
    description:
    - The identifier for the proxy.
    - This name must be unique for all proxies owned by your AWS account in the specified
      AWS Region.
    required: true
    type: str

debug_logging:
    description:
    - Whether the proxy includes detailed information about SQL statements in its logs.
    type: bool

engine_family:
    choices:
    - MYSQL
    - POSTGRESQL
    description:
    - The kinds of databases that the proxy can connect to.
    required: true
    type: str

aws_access_key:
    aliases:
    - ec2_access_key
    - access_key
    description:
    - C(AWS access key). If not set then the value of the C(AWS_ACCESS_KEY_ID), C(AWS_ACCESS_KEY)
      or C(EC2_ACCESS_KEY) environment variable is used.
    - If I(profile) is set this parameter is ignored.
    - Passing the I(aws_access_key) and I(profile) options at the same time has been deprecated
      and the options will be made mutually exclusive after 2022-06-01.
    type: str

aws_secret_key:
    aliases:
    - ec2_secret_key
    - secret_key
    description:
    - C(AWS secret key). If not set then the value of the C(AWS_SECRET_ACCESS_KEY), C(AWS_SECRET_KEY),
      or C(EC2_SECRET_KEY) environment variable is used.
    - If I(profile) is set this parameter is ignored.
    - Passing the I(aws_secret_key) and I(profile) options at the same time has been deprecated
      and the options will be made mutually exclusive after 2022-06-01.
    type: str

security_token:
    aliases:
    - aws_session_token
    - session_token
    - aws_security_token
    - access_token
    description:
    - C(AWS STS security token). If not set then the value of the C(AWS_SECURITY_TOKEN)
      or C(EC2_SECURITY_TOKEN) environment variable is used.
    - If I(profile) is set this parameter is ignored.
    - Passing the I(security_token) and I(profile) options at the same time has been deprecated
      and the options will be made mutually exclusive after 2022-06-01.
    - Aliases I(aws_session_token) and I(session_token) have been added in version 3.2.0.
    type: str

validate_certs:
    default: true
    description:
    - When set to "no", SSL certificates will not be validated for communication with
      the AWS APIs.
    type: bool

vpc_subnet_ids:
    description:
    - VPC subnet IDs to associate with the new proxy.
    elements: str
    required: true
    type: list

idle_client_timeout:
    description:
    - The number of seconds that a connection to the proxy can be inactive before the
      proxy disconnects it.
    type: int

vpc_security_group_ids:
    description:
    - VPC security group IDs to associate with the new proxy.
    elements: str
    type: list

debug_botocore_endpoint_logs:
    default: 'no'
    description:
    - Use a botocore.endpoint logger to parse the unique (rather than total) "resource:action"
      API calls made during a task, outputing the set to the resource_actions key in the
      task results. Use the aws_resource_action callback to output to total list made
      during a playbook. The ANSIBLE_DEBUG_BOTOCORE_LOGS environment variable may also
      be used.
    type: bool

Outputs

result:
  contains:
    identifier:
      description: The unique identifier of the resource.
      type: str
    properties:
      description: The resource properties.
      type: dict
  description: Dictionary containing resource information.
  returned: always
  type: complex