Create and destroy Security Groups. Be aware that this interacts with Amazon's services, and so may incur charges.
This module uses
boto, which can be installed via package, or pip.
This module accepts explicit EC2 credentials but can also utilize IAM roles assigned to the instance through Instance Profiles. Dynamic credentials are then automatically obtained from AWS API and no further configuration is necessary. More information available here.
If IAM roles are not used you need to specify them either in a pillar file or in the minion's config file:
secgroup.keyid: GKTADJGHEIQSXMKKRBJ08H secgroup.key: askdjghsdfjkghWupUjasdflkdfklgjsdfjajkghs
It's also possible to specify
region via a profile, either
passed in as a dict, or as a string to pull from pillars or minion config:
myprofile: keyid: GKTADJGHEIQSXMKKRBJ08H key: askdjghsdfjkghWupUjasdflkdfklgjsdfjajkghs region: us-east-1
Ensure mysecgroup exists: boto_secgroup.present: - name: mysecgroup - description: My security group - rules: - ip_protocol: tcp from_port: 80 to_port: 80 cidr_ip: - 10.0.0.0/0 - 192.168.0.0/0 - ip_protocol: icmp from_port: -1 to_port: -1 source_group_name: mysecgroup - rules_egress: - ip_protocol: all from_port: -1 to_port: -1 cidr_ip: - 10.0.0.0/0 - 192.168.0.0/0 - tags: SomeTag: 'My Tag Value' SomeOtherTag: 'Other Tag Value' - region: us-east-1 - keyid: GKTADJGHEIQSXMKKRBJ08H - key: askdjghsdfjkghWupUjasdflkdfklgjsdfjajkghs # Using a profile from pillars Ensure mysecgroup exists: boto_secgroup.present: - name: mysecgroup - description: My security group - profile: myprofile # Passing in a profile Ensure mysecgroup exists: boto_secgroup.present: - name: mysecgroup - description: My security group - profile: keyid: GKTADJGHEIQSXMKKRBJ08H key: askdjghsdfjkghWupUjasdflkdfklgjsdfjajkghs region: us-east-1
When using the
profile parameter and
region is set outside of
the profile group, region is ignored and a default region will be used.
region is missing from the
profile data set,
will be used as the default region.
absent(name, vpc_id=None, vpc_name=None, region=None, key=None, keyid=None, profile=None)¶
Ensure a security group with the specified name does not exist.
The name of the VPC to remove the security group from, if any. Exclusive with vpc_name.
A dict with region, key and keyid, or a pillar key (string) that contains a dict with region, key and keyid.
present(name, description, vpc_id=None, vpc_name=None, rules=None, rules_egress=None, region=None, key=None, keyid=None, profile=None, tags=None)¶
Ensure the security group exists with the specified rules.
The name of the VPC to create the security group in, if any. Exlusive with vpc_id.
rules=None, the ingress rules will be unmanaged. If set to an empty list,
, then all ingress rules will be removed.
rules_egress=None, the egress rules will be unmanaged. If set to an empty list,
, then all egress rules will be removed.
List of key:value pairs of tags to set on the security group