ansible.mysql.mysql_replication_filter module – Manage MySQL or MariaDB replication filters

Note

This module is part of the ansible.mysql collection (version 5.2.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install ansible.mysql. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: ansible.mysql.mysql_replication_filter.

New in ansible.mysql 5.2.0

Synopsis

  • Important: MariaDB support will be dropped in collection version 6.0.0. Use the ansible.mariadb.mariadb_replication_filter instead.

  • Manage replica-side replication filters declaratively.

  • MySQL uses CHANGE REPLICATION FILTER.

  • MariaDB uses SET GLOBAL replicate_* variables.

  • Changes are runtime only and are not persisted across restart by this module.

  • Persist filter settings separately through server configuration if they must survive a restart.

Requirements

The below requirements are needed on the host that executes this module.

  • PyMySQL (Python 2.7 and Python 3.x)

Parameters

Parameter

Comments

ca_cert

aliases: ssl_ca

path

The path to a Certificate Authority (CA) certificate. This option, if used, must specify the same certificate as used by the server.

channel

string

MySQL replication channel name.

Supported only for MySQL.

check_hostname

boolean

added in ansible.mysql 1.1.0

Whether to validate the server host name when an SSL connection is required. Corresponds to MySQL CLIs --ssl switch.

Setting this to false disables hostname verification. Use with caution.

Requires pymysql >= 0.7.11.

Choices:

  • false

  • true

client_cert

aliases: ssl_cert

path

The path to a client public key certificate.

client_key

aliases: ssl_key

path

The path to the client private key.

config_file

path

Specify a config file from which user and password are to be read.

The default config file, ~/.my.cnf, if it exists, will be read, even if config_file is not specified.

The default config file, ~/.my.cnf, if it exists, must contain a [client] section as a MySQL connector requirement.

To prevent the default config file from being read, set config_file to be an empty string.

Default: "~/.my.cnf"

connect_timeout

integer

The connection timeout when connecting to the MySQL server.

Default: 30

connection_name

string

MariaDB replication connection name.

Supported only for MariaDB multi-source replication.

login_host

string

Host running the database.

In some cases for local connections the login_unix_socket=/path/to/mysqld/socket, that is usually /var/run/mysqld/mysqld.sock, needs to be used instead of login_host=localhost.

Default: "localhost"

login_password

string

The password used to authenticate with.

login_port

integer

Port of the MySQL server. Requires login_host be defined as other than localhost if login_port is used.

Default: 3306

login_unix_socket

string

The path to a Unix domain socket for local connections.

Use this parameter to avoid the Please explicitly state intended protocol error.

login_user

string

The username used to authenticate with.

replicate_do_db

list / elements=string

Databases that should be replicated.

Provide an empty list to clear the filter.

replicate_do_table

list / elements=string

Fully qualified tables that should be replicated.

Values must use database.table syntax.

Provide an empty list to clear the filter.

replicate_ignore_db

list / elements=string

Databases that should be ignored during replication.

Provide an empty list to clear the filter.

replicate_ignore_table

list / elements=string

Fully qualified tables that should be ignored during replication.

Values must use database.table syntax.

Provide an empty list to clear the filter.

replicate_wild_do_table

list / elements=string

Wildcard table patterns that should be replicated.

Values must use database.table syntax with % and _ wildcards.

Provide an empty list to clear the filter.

replicate_wild_ignore_table

list / elements=string

Wildcard table patterns that should be ignored during replication.

Values must use database.table syntax with % and _ wildcards.

Provide an empty list to clear the filter.

Attributes

Attribute

Support

Description

check_mode

Support: full

Can run in check_mode and return changed status prediction without modifying target.

idempotent

Support: full

When run twice in a row outside check mode, with the same arguments, the second invocation indicates no change.

This assumes that the system controlled/queried by the module has not changed in a relevant way.

Notes

Note

  • Compatible with MariaDB or MySQL.

  • At least one replication filter option must be provided.

  • Unspecified filters are left unchanged.

  • Requires the PyMySQL (Python 2.7 and Python 3.X) package installed on the remote host. The Python package may be installed with apt-get install python-pymysql (Ubuntu; see ansible.builtin.apt) or yum install python2-PyMySQL (RHEL/CentOS/Fedora; see ansible.builtin.yum). You can also use dnf install python2-PyMySQL for newer versions of Fedora; see ansible.builtin.dnf.

  • Be sure you have PyMySQL library installed on the target machine for the Python interpreter Ansible discovers. For example if ansible discovers and uses Python 3, you need to install the Python 3 version of PyMySQL. If ansible discovers and uses Python 2, you need to install the Python 2 version of PyMySQL.

  • If you have trouble, it may help to force Ansible to use the Python interpreter you need by specifying ansible_python_interpreter. For more information, see https://docs.ansible.com/ansible/latest/reference_appendices/interpreter_discovery.html.

  • Both login_password and login_user are required when you are passing credentials. If none are present, the module will attempt to read the credentials from ~/.my.cnf, and finally fall back to using the MySQL default login of ‘root’ with no password.

  • If there are problems with local connections, using login_unix_socket=/path/to/mysqld/socket instead of login_host=localhost might help. As an example, the default MariaDB installation of version 10.4 and later uses the unix_socket authentication plugin by default that without using login_unix_socket=/var/run/mysqld/mysqld.sock (the default path) causes the error ``Host ‘127.0.0.1’ is not allowed to connect to this MariaDB server``.

  • If credentials from the config file (for example, /root/.my.cnf) are not needed to connect to a database server, but the file exists and does not contain a [client] section, before any other valid directives, it will be read and this will cause the connection to fail, to prevent this set it to an empty string, (for example config_file: '').

  • To avoid the Please explicitly state intended protocol error, use the login_unix_socket argument, for example, login_unix_socket: /run/mysqld/mysqld.sock.

  • Alternatively, to avoid using login_unix_socket argument on each invocation you can specify the socket path using the `socket` option in your MySQL config file (usually ~/.my.cnf) on the destination host, for example socket=/var/lib/mysql/mysql.sock.

Examples

- name: Ignore one database on a MySQL replica
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    replicate_ignore_db:
      - audit

- name: Replicate selected tables on a MySQL replica
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    replicate_do_table:
      - app.orders
      - reporting.summary

- name: Set wildcard filters on a MySQL replica
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    replicate_wild_do_table:
      - app.%
      - reporting.sales_%
    replicate_wild_ignore_table:
      - archive.old_%
      - tmp.%

- name: Set multiple MySQL filters in one task
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    replicate_do_db:
      - app
    replicate_ignore_table:
      - archive.events

- name: Set one channel-specific MySQL filter
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    channel: analytics
    replicate_do_db:
      - reporting

- name: Set one named MariaDB replication filter
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    connection_name: analytics
    replicate_do_db:
      - reporting

- name: Clear one MariaDB wildcard filter
  ansible.mysql.mysql_replication_filter:
    login_unix_socket: /run/mysqld/mysqld.sock
    replicate_wild_ignore_table: []

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

filters

dictionary

Effective normalized filter state after execution or prediction.

Returned: always

Sample: {"replicate_do_db": ["app", "reporting"], "replicate_do_table": [], "replicate_ignore_db": [], "replicate_ignore_table": [], "replicate_wild_do_table": [], "replicate_wild_ignore_table": []}

replicate_do_db

list / elements=string

Databases that should be replicated.

Returned: always

replicate_do_table

list / elements=string

Fully qualified tables that should be replicated.

Returned: always

replicate_ignore_db

list / elements=string

Databases that should be ignored during replication.

Returned: always

replicate_ignore_table

list / elements=string

Fully qualified tables that should be ignored during replication.

Returned: always

replicate_wild_do_table

list / elements=string

Wildcard table patterns that should be replicated.

Returned: always

replicate_wild_ignore_table

list / elements=string

Wildcard table patterns that should be ignored during replication.

Returned: always

queries

list / elements=string

Executed SQL statements or predicted SQL statements in check mode.

Returned: always

Sample: ["CHANGE REPLICATION FILTER REPLICATE_DO_DB = (`app`,`reporting`)"]

Authors

  • Ron Gershburg (@ronger4)