Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
A
ansible
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
OpenEdx
ansible
Commits
3c57018a
Commit
3c57018a
authored
Aug 06, 2015
by
Brian Coca
Browse files
Options
Browse Files
Download
Plain Diff
Merge pull request #11778 from Ensighten/add_credstash_plugin
add credstash lookup plugin
parents
d47d0b1d
87ef53c9
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
87 additions
and
0 deletions
+87
-0
docsite/rst/playbooks_lookups.rst
+36
-0
lib/ansible/plugins/lookup/credstash.py
+51
-0
No files found.
docsite/rst/playbooks_lookups.rst
View file @
3c57018a
...
@@ -140,6 +140,42 @@ default empty string return value if the key is not in the csv file
...
@@ -140,6 +140,42 @@ default empty string return value if the key is not in the csv file
.. note:: The default delimiter is TAB, *not* comma.
.. note:: The default delimiter is TAB, *not* comma.
.. _credstash_lookup:
The Credstash Lookup
````````````````````
Credstash is a small utility for managing secrets using AWS's KMS and DynamoDB: https://github.com/LuminalOSS/credstash
First, you need to store your secrets with credstash::
$ credstash put my-github-password secure123
my-github-password has been stored
Example usage::
---
- name: "Test credstash lookup plugin -- get my github password"
debug: msg="Credstash lookup! {{ lookup('credstash', 'my-github-password') }}"
You can specify regions or tables to fetch secrets from::
---
- name: "Test credstash lookup plugin -- get my other password from us-west-1"
debug: msg="Credstash lookup! {{ lookup('credstash', 'my-other-password', region='us-west-1') }}"
- name: "Test credstash lookup plugin -- get the company's github password"
debug: msg="Credstash lookup! {{ lookup('credstash', 'company-github-password', table='company-passwords') }}"
.. _more_lookups:
.. _more_lookups:
More Lookups
More Lookups
...
...
lib/ansible/plugins/lookup/credstash.py
0 → 100644
View file @
3c57018a
# (c) 2015, Ensighten <infra@ensighten.com>
#
# This file is part of Ansible
#
# Ansible is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# Ansible is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
from
__future__
import
(
absolute_import
,
division
,
print_function
)
__metaclass__
=
type
from
ansible.errors
import
AnsibleError
from
ansible.plugins.lookup
import
LookupBase
CREDSTASH_INSTALLED
=
False
try
:
import
credstash
CREDSTASH_INSTALLED
=
True
except
ImportError
:
CREDSTASH_INSTALLED
=
False
class
LookupModule
(
LookupBase
):
def
run
(
self
,
terms
,
variables
,
**
kwargs
):
if
not
CREDSTASH_INSTALLED
:
raise
AnsibleError
(
'The credstash lookup plugin requires credstash to be installed.'
)
if
isinstance
(
terms
,
basestring
):
terms
=
[
terms
]
ret
=
[]
for
term
in
terms
:
try
:
val
=
credstash
.
getSecret
(
term
,
**
kwargs
)
except
credstash
.
ItemNotFound
:
raise
AnsibleError
(
'Key {0} not found'
.
format
(
term
))
except
Exception
,
e
:
raise
AnsibleError
(
'Encountered exception while fetching {0}: {1}'
.
format
(
term
,
e
.
message
))
ret
.
append
(
val
)
return
ret
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment