ansible.mariadb.mariadb_password_policy module – Manage MariaDB password policy settings
Note
This module is part of the ansible.mariadb collection (version 6.0.2).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install ansible.mariadb.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: ansible.mariadb.mariadb_password_policy.
New in ansible.mariadb 5.2.0
Synopsis
This module only supports MariaDB; all MySQL-related options will be removed in the next releases. Use the
ansible.mysqlcollection for MySQL automation.Manage password policy settings on MariaDB.
This module is configuration-only and does not install or uninstall password validation components or plugins.
On MySQL, the module manages
validate_passwordsettings and related global password policy variables.On MariaDB, the module manages the
simple_password_checkplugin settings only.
Requirements
The below requirements are needed on the host that executes this module.
PyMySQL (Python 2.7 and Python 3.x)
Parameters
Parameter |
Comments |
|---|---|
The path to a Certificate Authority (CA) certificate. This option, if used, must specify the same certificate as used by the server. |
|
Whether to validate the server host name when an SSL connection is required. Corresponds to MySQL CLIs Setting this to Requires pymysql >= 0.7.11. Choices:
|
|
This option is scheduled for removal. Whether passwords are checked against the user name. Supported only on MySQL. Choices:
|
|
The path to a client public key certificate. |
|
The path to the client private key. |
|
Specify a config file from which user and password are to be read. The default config file, The default config file, To prevent the default config file from being read, set config_file to be an empty string. Default: |
|
The connection timeout when connecting to the MySQL server. Default: |
|
Minimum number of characters in a password. Maps to the active password validation facility for the current engine. |
|
Host running the database. In some cases for local connections the login_unix_socket=/path/to/mysqld/socket, that is usually Default: |
|
The password used to authenticate with. |
|
Port of the MySQL server. Requires login_host be defined as other than localhost if login_port is used. Default: |
|
The path to a Unix domain socket for local connections. Use this parameter to avoid the |
|
The username used to authenticate with. |
|
Minimum number of lowercase and uppercase letters required each by the active password validation facility. Supported on MySQL and on MariaDB |
|
This option is scheduled for removal. How supported MySQL variables are set.
Supported only on MySQL. Choices:
|
|
Minimum number of numeric characters required. Supported on MySQL and on MariaDB |
|
This option is scheduled for removal. Number of previous passwords that cannot be reused. Supported only on MySQL. |
|
This option is scheduled for removal. Default password expiration lifetime in days. Supported only on MySQL. |
|
This option is scheduled for removal. Password validation policy level on MySQL. Supported only on MySQL. Choices:
|
|
This option is scheduled for removal. Number of days before a password can be reused. Supported only on MySQL. |
|
Minimum number of non-alphanumeric characters required. Supported on MySQL and on MariaDB |
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: full |
Can run in check_mode and return changed status prediction without modifying target. |
|
Support: full |
When run twice in a row outside check mode, with the same arguments, the second invocation indicates no change. This assumes that the system controlled/queried by the module has not changed in a relevant way. |
Notes
Note
The required password validation component or plugin must already be enabled on the target server.
The module does not install
validate_passwordor MariaDB password validation plugins.MariaDB support in the first iteration is limited to
simple_password_check.Requires the PyMySQL (Python 2.7 and Python 3.X) package installed on the remote host. The Python package may be installed with apt-get install python-pymysql (Ubuntu; see ansible.builtin.apt) or yum install python2-PyMySQL (RHEL/CentOS/Fedora; see ansible.builtin.yum). You can also use dnf install python2-PyMySQL for newer versions of Fedora; see ansible.builtin.dnf.
Be sure you have PyMySQL library installed on the target machine for the Python interpreter Ansible discovers. For example if ansible discovers and uses Python 3, you need to install the Python 3 version of PyMySQL. If ansible discovers and uses Python 2, you need to install the Python 2 version of PyMySQL.
If you have trouble, it may help to force Ansible to use the Python interpreter you need by specifying
ansible_python_interpreter. For more information, see https://docs.ansible.com/ansible/latest/reference_appendices/interpreter_discovery.html.Both
login_passwordandlogin_userare required when you are passing credentials. If none are present, the module will attempt to read the credentials from~/.my.cnf, and finally fall back to using the MySQL default login of ‘root’ with no password.If there are problems with local connections, using login_unix_socket=/path/to/mysqld/socket instead of login_host=localhost might help. As an example, the default MariaDB installation of version 10.4 and later uses the unix_socket authentication plugin by default that without using login_unix_socket=/var/run/mysqld/mysqld.sock (the default path) causes the error ``Host ‘127.0.0.1’ is not allowed to connect to this MariaDB server``.
If credentials from the config file (for example,
/root/.my.cnf) are not needed to connect to a database server, but the file exists and does not contain a[client]section, before any other valid directives, it will be read and this will cause the connection to fail, to prevent this set it to an empty string, (for exampleconfig_file: '').To avoid the
Please explicitly state intended protocolerror, use the login_unix_socket argument, for example,login_unix_socket: /run/mysqld/mysqld.sock.Alternatively, to avoid using login_unix_socket argument on each invocation you can specify the socket path using the `socket` option in your MySQL config file (usually
~/.my.cnf) on the destination host, for examplesocket=/var/lib/mysql/mysql.sock.
See Also
See also
- ansible.mariadb.mariadb_query
Run MariaDB queries.
- ansible.mariadb.mariadb_variables
Manage MariaDB global variables.
- MySQL password validation component
Oracle MySQL reference for validate_password.
- MariaDB simple password check plugin
MariaDB reference for simple_password_check.
Examples
- name: Configure shared password complexity settings on MySQL
ansible.mariadb.mariadb_password_policy:
login_unix_socket: /run/mysqld/mysqld.sock
length: 12
mixed_case_count: 2
number_count: 2
special_char_count: 1
- name: Configure MariaDB simple_password_check settings
ansible.mariadb.mariadb_password_policy:
login_unix_socket: /run/mysqld/mysqld.sock
length: 14
mixed_case_count: 2
number_count: 2
special_char_count: 2
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
List of executed or predicted (in check mode) SQL statements. Returned: always Sample: |
|
Normalized requested settings after execution or prediction (in check mode). Returned: always Sample: |