oracle.oci.oci_network_vtap (5.0.0) — module

Manage a Vtap resource in Oracle Cloud Infrastructure

| "added in version" 2.9.0 of oracle.oci"

Authors: Oracle (@oracle)

preview | supported by community

Install collection

Install with ansible-galaxy collection install oracle.oci:==5.0.0


Add to requirements.yml

  collections:
    - name: oracle.oci
      version: 5.0.0

Description

This module allows the user to create, update and delete a Vtap resource in Oracle Cloud Infrastructure

For I(state=present), creates a virtual test access point (VTAP) in the specified compartment.

For the purposes of access control, you must provide the L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm) of the compartment that contains the VTAP. For more information about compartments and access control, see L(Overview of the IAM Service,https://docs.cloud.oracle.com/iaas/Content/Identity/Concepts/overview.htm). For information about OCIDs, see L(Resource Identifiers,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm).

You may optionally specify a *display name* for the VTAP, otherwise a default is provided. It does not have to be unique, and you can change it.

This resource has the following action operations in the M(oracle.oci.oci_network_vtap_actions) module: change_compartment.


Requirements

Usage examples

  • Success
    Steampunk Spotter scan finished with no errors, warnings or hints.
- name: Create vtap
  oci_network_vtap:
    # required
    compartment_id: "ocid1.compartment.oc1..xxxxxxEXAMPLExxxxxx"
    vcn_id: "ocid1.vcn.oc1..xxxxxxEXAMPLExxxxxx"
    source_id: "ocid1.source.oc1..xxxxxxEXAMPLExxxxxx"
    capture_filter_id: "ocid1.capturefilter.oc1..xxxxxxEXAMPLExxxxxx"

    # optional
    defined_tags: {'Operations': {'CostCenter': 'US'}}
    display_name: display_name_example
    freeform_tags: {'Department': 'Finance'}
    target_id: "ocid1.target.oc1..xxxxxxEXAMPLExxxxxx"
    target_ip: target_ip_example
    encapsulation_protocol: VXLAN
    vxlan_network_identifier: 56
    is_vtap_enabled: true
    traffic_mode: DEFAULT
    max_packet_size: 56
    source_private_endpoint_ip: source_private_endpoint_ip_example
    source_private_endpoint_subnet_id: "ocid1.sourceprivateendpointsubnet.oc1..xxxxxxEXAMPLExxxxxx"
    target_type: VNIC
    source_type: VNIC
  • Success
    Steampunk Spotter scan finished with no errors, warnings or hints.
- name: Update vtap
  oci_network_vtap:
    # required
    vtap_id: "ocid1.vtap.oc1..xxxxxxEXAMPLExxxxxx"

    # optional
    defined_tags: {'Operations': {'CostCenter': 'US'}}
    display_name: display_name_example
    freeform_tags: {'Department': 'Finance'}
    source_id: "ocid1.source.oc1..xxxxxxEXAMPLExxxxxx"
    target_id: "ocid1.target.oc1..xxxxxxEXAMPLExxxxxx"
    target_ip: target_ip_example
    capture_filter_id: "ocid1.capturefilter.oc1..xxxxxxEXAMPLExxxxxx"
    encapsulation_protocol: VXLAN
    vxlan_network_identifier: 56
    is_vtap_enabled: true
    traffic_mode: DEFAULT
    max_packet_size: 56
    source_private_endpoint_ip: source_private_endpoint_ip_example
    source_private_endpoint_subnet_id: "ocid1.sourceprivateendpointsubnet.oc1..xxxxxxEXAMPLExxxxxx"
    target_type: VNIC
    source_type: VNIC
  • Success
    Steampunk Spotter scan finished with no errors, warnings or hints.
- name: Update vtap using name (when environment variable OCI_USE_NAME_AS_IDENTIFIER is set)
  oci_network_vtap:
    # required
    compartment_id: "ocid1.compartment.oc1..xxxxxxEXAMPLExxxxxx"
    display_name: display_name_example

    # optional
    defined_tags: {'Operations': {'CostCenter': 'US'}}
    freeform_tags: {'Department': 'Finance'}
    source_id: "ocid1.source.oc1..xxxxxxEXAMPLExxxxxx"
    target_id: "ocid1.target.oc1..xxxxxxEXAMPLExxxxxx"
    target_ip: target_ip_example
    capture_filter_id: "ocid1.capturefilter.oc1..xxxxxxEXAMPLExxxxxx"
    encapsulation_protocol: VXLAN
    vxlan_network_identifier: 56
    is_vtap_enabled: true
    traffic_mode: DEFAULT
    max_packet_size: 56
    source_private_endpoint_ip: source_private_endpoint_ip_example
    source_private_endpoint_subnet_id: "ocid1.sourceprivateendpointsubnet.oc1..xxxxxxEXAMPLExxxxxx"
    target_type: VNIC
    source_type: VNIC
  • Success
    Steampunk Spotter scan finished with no errors, warnings or hints.
- name: Delete vtap
  oci_network_vtap:
    # required
    vtap_id: "ocid1.vtap.oc1..xxxxxxEXAMPLExxxxxx"
    state: absent
  • Success
    Steampunk Spotter scan finished with no errors, warnings or hints.
- name: Delete vtap using name (when environment variable OCI_USE_NAME_AS_IDENTIFIER is set)
  oci_network_vtap:
    # required
    compartment_id: "ocid1.compartment.oc1..xxxxxxEXAMPLExxxxxx"
    display_name: display_name_example
    state: absent

Inputs

    
wait:
    default: true
    description: Whether to wait for create or delete operation to complete.
    type: bool

state:
    choices:
    - present
    - absent
    default: present
    description:
    - The state of the Vtap.
    - Use I(state=present) to create or update a Vtap.
    - Use I(state=absent) to delete a Vtap.
    required: false
    type: str

key_by:
    description: The list of attributes of this resource which should be used to uniquely
      identify an instance of the resource. By default, all the attributes of a resource
      are used to uniquely identify a resource.
    elements: str
    type: list

region:
    description:
    - The Oracle Cloud Infrastructure region to use for all OCI API requests. If not set,
      then the value of the OCI_REGION variable, if any, is used. This option is required
      if the region is not specified through a configuration file (See C(config_file_location)).
      Please refer to U(https://docs.us-phoenix-1.oraclecloud.com/Content/General/Concepts/regions.htm)
      for more information on OCI regions.
    type: str

vcn_id:
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the VCN containing the `Vtap` resource.
    - Required for create using I(state=present).
    type: str

tenancy:
    description:
    - OCID of your tenancy. If not set, then the value of the OCI_TENANCY variable, if
      any, is used. This option is required if the tenancy OCID is not specified through
      a configuration file (See C(config_file_location)). To get the tenancy OCID, please
      refer U(https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm)
    type: str

vtap_id:
    aliases:
    - id
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the VTAP.
    - Required for update using I(state=present) when environment variable C(OCI_USE_NAME_AS_IDENTIFIER)
      is not set.
    - Required for delete using I(state=absent) when environment variable C(OCI_USE_NAME_AS_IDENTIFIER)
      is not set.
    type: str

api_user:
    description:
    - The OCID of the user, on whose behalf, OCI APIs are invoked. If not set, then the
      value of the OCI_USER_ID environment variable, if any, is used. This option is required
      if the user is not specified through a configuration file (See C(config_file_location)).
      To get the user's OCID, please refer U(https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm).
    type: str

auth_type:
    choices:
    - api_key
    - instance_principal
    - instance_obo_user
    - resource_principal
    - security_token
    default: api_key
    description:
    - The type of authentication to use for making API requests. By default C(auth_type="api_key")
      based authentication is performed and the API key (see I(api_user_key_file)) in
      your config file will be used. If this 'auth_type' module option is not specified,
      the value of the OCI_ANSIBLE_AUTH_TYPE, if any, is used. Use C(auth_type="instance_principal")
      to use instance principal based authentication when running ansible playbooks within
      an OCI compute instance.
    type: str

source_id:
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the source point where packets are captured.
    - Required for create using I(state=present).
    - This parameter is updatable.
    type: str

target_id:
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the destination resource where mirrored packets are sent.
    - This parameter is updatable.
    type: str

target_ip:
    description:
    - The IP address of the destination resource where mirrored packets are sent.
    - This parameter is updatable.
    type: str

cert_bundle:
    description:
    - The full path to a CA certificate bundle to be used for SSL verification. This will
      override the default CA certificate bundle. If not set, then the value of the OCI_ANSIBLE_CERT_BUNDLE
      variable, if any, is used.
    type: str

source_type:
    choices:
    - VNIC
    - SUBNET
    - LOAD_BALANCER
    - DB_SYSTEM
    - EXADATA_VM_CLUSTER
    - AUTONOMOUS_DATA_WAREHOUSE
    description:
    - The source type for the VTAP.
    - This parameter is updatable.
    type: str

target_type:
    choices:
    - VNIC
    - NETWORK_LOAD_BALANCER
    - IP_ADDRESS
    description:
    - The target type for the VTAP.
    - This parameter is updatable.
    type: str

auth_purpose:
    choices:
    - service_principal
    description:
    - The auth purpose which can be used in conjunction with 'auth_type=instance_principal'.
      The default auth_purpose for instance_principal is None.
    type: str

defined_tags:
    description:
    - Defined tags for this resource. Each key is predefined and scoped to a namespace.
      For more information, see L(Resource Tags,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/resourcetags.htm).
    - 'Example: `{"Operations": {"CostCenter": "42"}}`'
    - This parameter is updatable.
    type: dict

display_name:
    aliases:
    - name
    description:
    - A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering
      confidential information.
    - Required for create, update, delete when environment variable C(OCI_USE_NAME_AS_IDENTIFIER)
      is set.
    - This parameter is updatable when C(OCI_USE_NAME_AS_IDENTIFIER) is not set.
    type: str

force_create:
    default: false
    description: Whether to attempt non-idempotent creation of a resource. By default,
      create resource is an idempotent operation, and doesn't create the resource if it
      already exists. Setting this option to true, forcefully creates a copy of the resource,
      even if it already exists.This option is mutually exclusive with I(key_by).
    type: bool

traffic_mode:
    choices:
    - DEFAULT
    - PRIORITY
    description:
    - Used to control the priority of traffic. It is an optional field. If it not passed,
      the value is DEFAULT
    - This parameter is updatable.
    type: str

wait_timeout:
    description: Time, in seconds, to wait when I(wait=yes). Defaults to 1200 for most
      of the services but some services might have a longer wait timeout.
    type: int

freeform_tags:
    description:
    - Free-form tags for this resource. Each tag is a simple key-value pair with no predefined
      name, type, or namespace. For more information, see L(Resource Tags,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/resourcetags.htm).
    - 'Example: `{"Department": "Finance"}`'
    - This parameter is updatable.
    type: dict

compartment_id:
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the compartment containing the `Vtap` resource.
    - Required for create using I(state=present).
    - Required for update when environment variable C(OCI_USE_NAME_AS_IDENTIFIER) is set.
    - Required for delete when environment variable C(OCI_USE_NAME_AS_IDENTIFIER) is set.
    type: str

is_vtap_enabled:
    description:
    - Used to start or stop a `Vtap` resource.
    - '* `TRUE` directs the VTAP to start mirroring traffic. * `FALSE` (Default) directs
      the VTAP to stop mirroring traffic.'
    - This parameter is updatable.
    type: bool

max_packet_size:
    description:
    - The maximum size of the packets to be included in the filter.
    - This parameter is updatable.
    type: int

api_user_key_file:
    description:
    - Full path and filename of the private key (in PEM format). If not set, then the
      value of the OCI_USER_KEY_FILE variable, if any, is used. This option is required
      if the private key is not specified through a configuration file (See C(config_file_location)).
      If the key is encrypted with a pass-phrase, the C(api_user_key_pass_phrase) option
      must also be provided.
    type: str

capture_filter_id:
    description:
    - The capture filter's Oracle ID (L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)).
    - Required for create using I(state=present).
    - This parameter is updatable.
    type: str

config_profile_name:
    description:
    - The profile to load from the config file referenced by C(config_file_location).
      If not set, then the value of the OCI_CONFIG_PROFILE environment variable, if any,
      is used. Otherwise, defaults to the "DEFAULT" profile in C(config_file_location).
    type: str

api_user_fingerprint:
    description:
    - Fingerprint for the key pair being used. If not set, then the value of the OCI_USER_FINGERPRINT
      environment variable, if any, is used. This option is required if the key fingerprint
      is not specified through a configuration file (See C(config_file_location)). To
      get the key pair's fingerprint value please refer U(https://docs.us-phoenix-1.oraclecloud.com/Content/API/Concepts/apisigningkey.htm).
    type: str

config_file_location:
    description:
    - Path to configuration file. If not set then the value of the OCI_CONFIG_FILE environment
      variable, if any, is used. Otherwise, defaults to ~/.oci/config.
    type: str

encapsulation_protocol:
    choices:
    - VXLAN
    description:
    - Defines an encapsulation header type for the VTAP's mirrored traffic.
    - This parameter is updatable.
    type: str

api_user_key_pass_phrase:
    description:
    - Passphrase used by the key referenced in C(api_user_key_file), if it is encrypted.
      If not set, then the value of the OCI_USER_KEY_PASS_PHRASE variable, if any, is
      used. This option is required if the key passphrase is not specified through a configuration
      file (See C(config_file_location)).
    type: str

vxlan_network_identifier:
    description:
    - The virtual extensible LAN (VXLAN) network identifier (or VXLAN segment ID) that
      uniquely identifies the VXLAN.
    - This parameter is updatable.
    type: int

source_private_endpoint_ip:
    description:
    - The IP Address of the source private endpoint.
    - This parameter is updatable.
    type: str

source_private_endpoint_subnet_id:
    description:
    - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
      of the subnet that source private endpoint belongs to.
    - This parameter is updatable.
    type: str

realm_specific_endpoint_template_enabled:
    description:
    - Enable/Disable realm specific endpoint template for service client. By Default,
      realm specific endpoint template is disabled. If not set, then the value of the
      OCI_REALM_SPECIFIC_SERVICE_ENDPOINT_TEMPLATE_ENABLED variable, if any, is used.
    type: bool

Outputs

vtap:
  contains:
    capture_filter_id:
      description:
      - The capture filter's Oracle ID (L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)).
      returned: on success
      sample: ocid1.capturefilter.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    compartment_id:
      description:
      - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
        of the compartment containing the `Vtap` resource.
      returned: on success
      sample: ocid1.compartment.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    defined_tags:
      description:
      - Defined tags for this resource. Each key is predefined and scoped to a namespace.
        For more information, see L(Resource Tags,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/resourcetags.htm).
      - 'Example: `{"Operations": {"CostCenter": "42"}}`'
      returned: on success
      sample:
        Operations:
          CostCenter: US
      type: dict
    display_name:
      description:
      - A user-friendly name. Does not have to be unique, and it's changeable. Avoid
        entering confidential information.
      returned: on success
      sample: display_name_example
      type: str
    encapsulation_protocol:
      description:
      - Defines an encapsulation header type for the VTAP's mirrored traffic.
      returned: on success
      sample: VXLAN
      type: str
    freeform_tags:
      description:
      - Free-form tags for this resource. Each tag is a simple key-value pair with
        no predefined name, type, or namespace. For more information, see L(Resource
        Tags,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/resourcetags.htm).
      - 'Example: `{"Department": "Finance"}`'
      returned: on success
      sample:
        Department: Finance
      type: dict
    id:
      description:
      - The VTAP's Oracle ID (L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)).
      returned: on success
      sample: ocid1.resource.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    is_vtap_enabled:
      description:
      - Used to start or stop a `Vtap` resource.
      - '* `TRUE` directs the VTAP to start mirroring traffic. * `FALSE` (Default)
        directs the VTAP to stop mirroring traffic.'
      returned: on success
      sample: true
      type: bool
    lifecycle_state:
      description:
      - The VTAP's administrative lifecycle state.
      returned: on success
      sample: PROVISIONING
      type: str
    lifecycle_state_details:
      description:
      - The VTAP's current running state.
      returned: on success
      sample: RUNNING
      type: str
    max_packet_size:
      description:
      - The maximum size of the packets to be included in the filter.
      returned: on success
      sample: 56
      type: int
    source_id:
      description:
      - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
        of the source point where packets are captured.
      returned: on success
      sample: ocid1.source.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    source_private_endpoint_ip:
      description:
      - The IP Address of the source private endpoint.
      returned: on success
      sample: source_private_endpoint_ip_example
      type: str
    source_private_endpoint_subnet_id:
      description:
      - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
        of the subnet that source private endpoint belongs to.
      returned: on success
      sample: ocid1.sourceprivateendpointsubnet.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    source_type:
      description:
      - The source type for the VTAP.
      returned: on success
      sample: VNIC
      type: str
    target_id:
      description:
      - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
        of the destination resource where mirrored packets are sent.
      returned: on success
      sample: ocid1.target.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    target_ip:
      description:
      - The IP address of the destination resource where mirrored packets are sent.
      returned: on success
      sample: target_ip_example
      type: str
    target_type:
      description:
      - The target type for the VTAP.
      returned: on success
      sample: VNIC
      type: str
    time_created:
      description:
      - The date and time the VTAP was created, in the format defined by L(RFC3339,https://tools.ietf.org/html/rfc3339).
      - 'Example: `2020-08-25T21:10:29.600Z`'
      returned: on success
      sample: '2013-10-20T19:20:30+01:00'
      type: str
    traffic_mode:
      description:
      - Used to control the priority of traffic. It is an optional field. If it not
        passed, the value is DEFAULT
      returned: on success
      sample: DEFAULT
      type: str
    vcn_id:
      description:
      - The L(OCID,https://docs.cloud.oracle.com/iaas/Content/General/Concepts/identifiers.htm)
        of the VCN containing the `Vtap` resource.
      returned: on success
      sample: ocid1.vcn.oc1..xxxxxxEXAMPLExxxxxx
      type: str
    vxlan_network_identifier:
      description:
      - The virtual extensible LAN (VXLAN) network identifier (or VXLAN segment ID)
        that uniquely identifies the VXLAN.
      returned: on success
      sample: 56
      type: int
  description:
  - Details of the Vtap resource acted upon by the current operation
  returned: on success
  sample:
    capture_filter_id: ocid1.capturefilter.oc1..xxxxxxEXAMPLExxxxxx
    compartment_id: ocid1.compartment.oc1..xxxxxxEXAMPLExxxxxx
    defined_tags:
      Operations:
        CostCenter: US
    display_name: display_name_example
    encapsulation_protocol: VXLAN
    freeform_tags:
      Department: Finance
    id: ocid1.resource.oc1..xxxxxxEXAMPLExxxxxx
    is_vtap_enabled: true
    lifecycle_state: PROVISIONING
    lifecycle_state_details: RUNNING
    max_packet_size: 56
    source_id: ocid1.source.oc1..xxxxxxEXAMPLExxxxxx
    source_private_endpoint_ip: source_private_endpoint_ip_example
    source_private_endpoint_subnet_id: ocid1.sourceprivateendpointsubnet.oc1..xxxxxxEXAMPLExxxxxx
    source_type: VNIC
    target_id: ocid1.target.oc1..xxxxxxEXAMPLExxxxxx
    target_ip: target_ip_example
    target_type: VNIC
    time_created: '2013-10-20T19:20:30+01:00'
    traffic_mode: DEFAULT
    vcn_id: ocid1.vcn.oc1..xxxxxxEXAMPLExxxxxx
    vxlan_network_identifier: 56
  type: complex