cisco.catalystcenter.access_groups module -- Resource module for Access Groups

Note

This module is part of the cisco.catalystcenter collection (version 2.12.0).

To install it, use: ansible-galaxy collection install cisco.catalystcenter. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: cisco.catalystcenter.access_groups.

New in cisco.catalystcenter 2.3.0

Synopsis

  • Manage operations create, update and delete of the resource Access Groups. - > Add an access group into the system.This API provides the ability to create an access group. An access group is an entity that provides RBAC and site access to users on the system. Each access group is associated with a role and a site. Each role must be based on the permissions returned by the Get permissions v2 API GET /dna/system/api/v2/roles/permissions and must be created using the Add role v2 API POST /dna/system/api/v2/roles. The site details can be obtained from the get sites API GET /dna/intent/api/v1/sites. The full site hierarchy should a / delimited list of site ids.

  • Delete an access group from the system.

  • Update an access group in the system.

Note

This module has a corresponding action plugin.

Requirements

The below requirements are needed on the host that executes this module.

  • catalystcentersdk >= 3.2.3.0.0

  • python >= 3.12

Parameters

Parameter

Comments

catalystcenter_debug

aliases: dnac_debug

boolean

Flag for Cisco Catalyst Center SDK to enable debugging.

Choices:

catalystcenter_host

aliases: dnac_host

string / required

The Cisco Catalyst Center hostname.

catalystcenter_password

aliases: dnac_password

string

The Cisco Catalyst Center password to authenticate.

catalystcenter_port

aliases: dnac_port, catalystcenter_api_port

integer

The Cisco Catalyst Center port.

Default: :ansible-option-default:`443`

catalystcenter_username

aliases: dnac_username, user

string

The Cisco Catalyst Center username to authenticate.

Default: :ansible-option-default:`"admin"`

catalystcenter_verify

aliases: dnac_verify

boolean

Flag to enable or disable SSL certificate verification.

Choices:

catalystcenter_version

aliases: dnac_version

string

Informs the SDK which version of Cisco Catalyst Center to use.

Default: :ansible-option-default:`"3.1.6.0"`

description

string

Description of the access group.

id

string

Id path parameter. Id of the access group to be deleted.

name

string

Name of the access group.

resourceGroups

list / elements=dictionary

List of sites to be associated with the access group.

name

string

The name of the resource. This should always be the site hierarchy id you would like to associate to this access group to.

srcResourceId

string

Id of the resource.

type

string

The type of resource. In the case of Site-based RBAC, this should always be set to "site".

role

list / elements=string

List of role names.

validate_response_schema

boolean

Flag for Cisco Catalyst Center SDK to enable the validation of request bodies against a JSON schema.

Choices:

Notes

Note

  • SDK Method used are user_and_roles.UserAndRoles.add_access_group, user_and_roles.UserAndRoles.delete_access_group, user_and_roles.UserAndRoles.update_access_group,

  • Paths used are post /dna/system/api/v1/accessGroups, delete /dna/system/api/v1/accessGroups/{id}, put /dna/system/api/v1/accessGroups/{id},

  • Does not support check_mode

  • The plugin runs on the control node and does not use any ansible connection plugins,

  • but instead uses the embedded connection manager from Cisco CATALYST SDK

  • Requires Python >= 3.10, matching the controller Python versions supported by the collection's minimum ansible-core version (see the collection README for the current ansible-core / Python compatibility range)

See Also

See also

Cisco Catalyst Center documentation for User and Roles AddAccessGroup

Complete reference of the AddAccessGroup API.

Cisco Catalyst Center documentation for User and Roles DeleteAccessGroup

Complete reference of the DeleteAccessGroup API.

Cisco Catalyst Center documentation for User and Roles UpdateAccessGroup

Complete reference of the UpdateAccessGroup API.

Examples

---
- name: Delete by id
  cisco.catalystcenter.access_groups:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: absent
    id: string
- name: Update by id
  cisco.catalystcenter.access_groups:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: present
    description: string
    id: string
    resourceGroups:
      - name: string
        srcResourceId: string
        type: string
    role:
      - string
- name: Create
  cisco.catalystcenter.access_groups:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: present
    description: string
    name: string
    resourceGroups:
      - name: string
        srcResourceId: string
        type: string
    role:
      - string

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

catalystcenter_response

string

A dictionary or list with the response returned by the Cisco Catalyst Center Python SDK

Returned: always

Sample: :ansible-rv-sample-value:`"\\"'string'\\"\\n"`

Authors

  • Bryan Vargas (@bvargasre)