ansible.mysql.mysql_password_policy module – Manage MySQL or MariaDB password policy settings

Note

This module is part of the ansible.mysql collection (version 5.2.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install ansible.mysql. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: ansible.mysql.mysql_password_policy.

New in ansible.mysql 5.2.0

Synopsis

  • Important: MariaDB support will be dropped in collection version 6.0.0. Use the ansible.mariadb.mariadb_password_policy instead.

  • Manage password policy settings on MySQL or MariaDB.

  • This module is configuration-only and does not install or uninstall password validation components or plugins.

  • On MySQL, the module manages validate_password settings and related global password policy variables.

  • On MariaDB, the module manages the simple_password_check plugin settings only.

Requirements

The below requirements are needed on the host that executes this module.

  • PyMySQL (Python 2.7 and Python 3.x)

Parameters

Parameter

Comments

ca_cert

aliases: ssl_ca

path

The path to a Certificate Authority (CA) certificate. This option, if used, must specify the same certificate as used by the server.

check_hostname

boolean

added in ansible.mysql 1.1.0

Whether to validate the server host name when an SSL connection is required. Corresponds to MySQL CLIs --ssl switch.

Setting this to false disables hostname verification. Use with caution.

Requires pymysql >= 0.7.11.

Choices:

  • false

  • true

check_user_name

boolean

Whether passwords are checked against the user name.

Supported only on MySQL.

Choices:

  • false

  • true

client_cert

aliases: ssl_cert

path

The path to a client public key certificate.

client_key

aliases: ssl_key

path

The path to the client private key.

config_file

path

Specify a config file from which user and password are to be read.

The default config file, ~/.my.cnf, if it exists, will be read, even if config_file is not specified.

The default config file, ~/.my.cnf, if it exists, must contain a [client] section as a MySQL connector requirement.

To prevent the default config file from being read, set config_file to be an empty string.

Default: "~/.my.cnf"

connect_timeout

integer

The connection timeout when connecting to the MySQL server.

Default: 30

length

integer

Minimum number of characters in a password.

Maps to the active password validation facility for the current engine.

login_host

string

Host running the database.

In some cases for local connections the login_unix_socket=/path/to/mysqld/socket, that is usually /var/run/mysqld/mysqld.sock, needs to be used instead of login_host=localhost.

Default: "localhost"

login_password

string

The password used to authenticate with.

login_port

integer

Port of the MySQL server. Requires login_host be defined as other than localhost if login_port is used.

Default: 3306

login_unix_socket

string

The path to a Unix domain socket for local connections.

Use this parameter to avoid the Please explicitly state intended protocol error.

login_user

string

The username used to authenticate with.

mixed_case_count

integer

Minimum number of lowercase and uppercase letters required each by the active password validation facility.

Supported on MySQL and on MariaDB simple_password_check.

mode

string

How supported MySQL variables are set.

global uses SET GLOBAL and does not survive restarts by itself.

persist uses SET PERSIST on MySQL.

Supported only on MySQL.

Choices:

  • "global" ← (default)

  • "persist"

number_count

integer

Minimum number of numeric characters required.

Supported on MySQL and on MariaDB simple_password_check.

password_history

integer

Number of previous passwords that cannot be reused.

Supported only on MySQL.

password_lifetime

integer

Default password expiration lifetime in days.

Supported only on MySQL.

policy

string

Password validation policy level on MySQL.

Supported only on MySQL.

Choices:

  • "low"

  • "medium"

  • "strong"

reuse_interval

integer

Number of days before a password can be reused.

Supported only on MySQL.

special_char_count

integer

Minimum number of non-alphanumeric characters required.

Supported on MySQL and on MariaDB simple_password_check.

Attributes

Attribute

Support

Description

check_mode

Support: full

Can run in check_mode and return changed status prediction without modifying target.

idempotent

Support: full

When run twice in a row outside check mode, with the same arguments, the second invocation indicates no change.

This assumes that the system controlled/queried by the module has not changed in a relevant way.

Notes

Note

  • The required password validation component or plugin must already be enabled on the target server.

  • The module does not install validate_password or MariaDB password validation plugins.

  • MariaDB support in the first iteration is limited to simple_password_check.

  • Requires the PyMySQL (Python 2.7 and Python 3.X) package installed on the remote host. The Python package may be installed with apt-get install python-pymysql (Ubuntu; see ansible.builtin.apt) or yum install python2-PyMySQL (RHEL/CentOS/Fedora; see ansible.builtin.yum). You can also use dnf install python2-PyMySQL for newer versions of Fedora; see ansible.builtin.dnf.

  • Be sure you have PyMySQL library installed on the target machine for the Python interpreter Ansible discovers. For example if ansible discovers and uses Python 3, you need to install the Python 3 version of PyMySQL. If ansible discovers and uses Python 2, you need to install the Python 2 version of PyMySQL.

  • If you have trouble, it may help to force Ansible to use the Python interpreter you need by specifying ansible_python_interpreter. For more information, see https://docs.ansible.com/ansible/latest/reference_appendices/interpreter_discovery.html.

  • Both login_password and login_user are required when you are passing credentials. If none are present, the module will attempt to read the credentials from ~/.my.cnf, and finally fall back to using the MySQL default login of ‘root’ with no password.

  • If there are problems with local connections, using login_unix_socket=/path/to/mysqld/socket instead of login_host=localhost might help. As an example, the default MariaDB installation of version 10.4 and later uses the unix_socket authentication plugin by default that without using login_unix_socket=/var/run/mysqld/mysqld.sock (the default path) causes the error ``Host ‘127.0.0.1’ is not allowed to connect to this MariaDB server``.

  • If credentials from the config file (for example, /root/.my.cnf) are not needed to connect to a database server, but the file exists and does not contain a [client] section, before any other valid directives, it will be read and this will cause the connection to fail, to prevent this set it to an empty string, (for example config_file: '').

  • To avoid the Please explicitly state intended protocol error, use the login_unix_socket argument, for example, login_unix_socket: /run/mysqld/mysqld.sock.

  • Alternatively, to avoid using login_unix_socket argument on each invocation you can specify the socket path using the `socket` option in your MySQL config file (usually ~/.my.cnf) on the destination host, for example socket=/var/lib/mysql/mysql.sock.

See Also

See also

ansible.mysql.mysql_query

Run MySQL or MariaDB queries.

ansible.mysql.mysql_variables

Manage MySQL or MariaDB global variables.

MySQL password validation component

Oracle MySQL reference for validate_password.

MariaDB simple password check plugin

MariaDB reference for simple_password_check.

Examples

- name: Configure shared password complexity settings on MySQL
  ansible.mysql.mysql_password_policy:
    login_unix_socket: /run/mysqld/mysqld.sock
    length: 12
    mixed_case_count: 2
    number_count: 2
    special_char_count: 1

- name: Configure MySQL-specific password policy settings persistently
  ansible.mysql.mysql_password_policy:
    login_unix_socket: /run/mysqld/mysqld.sock
    policy: medium
    check_user_name: true
    password_lifetime: 90
    password_history: 5
    reuse_interval: 365
    mode: persist

- name: Configure MariaDB simple_password_check settings
  ansible.mysql.mysql_password_policy:
    login_unix_socket: /run/mysqld/mysqld.sock
    length: 14
    mixed_case_count: 2
    number_count: 2
    special_char_count: 2

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

queries

list / elements=string

List of executed or predicted (in check mode) SQL statements.

Returned: always

Sample: ["SET GLOBAL `validate_password`.`length` = 12"]

settings

dictionary

Normalized requested settings after execution or prediction (in check mode).

Returned: always

Sample: {"length": 12, "number_count": 2}

Authors

  • Steve Fulmer (@stevefulme1)

  • Ron Gershburg (@ronger4)