graphiant.naas.graphiant_ospfv2 module – Manage Graphiant OSPFv2 configuration (edge.segments.*.ospfv2)
Note
This module is part of the graphiant.naas collection (version 26.7.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install graphiant.naas.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: graphiant.naas.graphiant_ospfv2.
New in graphiant.naas 26.7.0
Synopsis
Configure or delete OSPFv2 processes under edge segments (edge.segments.<segment>.ospfv2).
Reads a structured YAML config file and builds the raw device-config payload in Python.
All operations are idempotent and safe to run multiple times.
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.7
graphiant-sdk >= 26.7.0 (required for OSPFv2 interface MD5 authentication support)
Parameters
Parameter |
Comments |
|---|---|
Bearer token for API authentication (for example, from If not passed as a module argument, the collection reads When a bearer token is present (module argument or environment), it takes precedence over If no valid token is available, the module authenticates with |
|
Enable detailed logging. Choices:
|
|
Graphiant portal host URL for API connectivity. Example: “https://api.graphiant.com” |
|
Specific operation to perform.
Choices:
|
|
Path to the ospf YAML file. Can be an absolute path or relative to the configured config_path. Expected top-level key is |
|
Graphiant portal password for authentication. Required for password-based login when no valid bearer token is available from |
|
Desired state for OSPF processes.
Choices:
|
|
Graphiant portal username for authentication. Required for password-based login when no valid bearer token is available from |
|
Dict of device name to interface name to OSPF MD5 authentication key (configure only). Pass from playbook vars loaded from encrypted vault_secrets.yml; secrets in memory only. Keys must match the device name and Default: |
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: full In check mode, no configuration is pushed to devices, but the module still reads current device state to determine whether changes would be made. Payloads that would be pushed are logged with a |
Supports check mode. |
|
Support: full When the playbook runs with |
Supports Ansible’s |
Notes
Note
OSPF Operations:
- Configure: Create/update OSPFv2 processes listed in the config.
- Deconfigure: Delete OSPFv2 processes listed in the config.
Configuration files support Jinja2 templating syntax for dynamic configuration generation.
The module automatically resolves device names to IDs.
YAML schema uses camelCase keys (for example:
staticRoutes,lanSegment,destinationPrefix,nextHops).Vault (configure only):
vault_ospf_md5_passwords.Use encrypted configs/vault_secrets.yml, configs/vault-password-file.sh; no plaintext.
Load with ansible.builtin.include_vars (no_log true); pass the dict so secrets stay in memory.
Vault keys are
device name->interfaceName. Leaveauthentication.keynull in YAML to fill it from vault. See configs/vault_secrets.yml.example.Configure idempotency: compares intended routes to existing device state per segment + prefix; skips push when already matched (
changed=false).Deconfigure deletes only the prefixes listed in the YAML (per segment).
Deconfigure payload uses
route: nullper prefix; this module preserves nulls in the final payload pushed to the API.
Examples
- name: Configure OSPF
graphiant.naas.graphiant_ospfv2:
operation: configure
ospfv2_config_file: "sample_ospfv2_config.yaml"
host: "{{ graphiant_host }}"
username: "{{ graphiant_username }}"
password: "{{ graphiant_password }}"
detailed_logs: true
state: present
register: ospfv2_result
no_log: true
- name: Display result message (includes detailed logs)
ansible.builtin.debug:
msg: "{{ ospfv2_result.msg }}"
- name: Configure OSPF with MD5 auth keys from Ansible Vault (leave authentication.key null in YAML)
graphiant.naas.graphiant_ospfv2:
operation: configure
ospfv2_config_file: "sample_ospfv2_config.yaml"
host: "{{ graphiant_host }}"
username: "{{ graphiant_username }}"
password: "{{ graphiant_password }}"
vault_ospf_md5_passwords: "{{ vault_ospf_md5_passwords | default({}) }}"
state: present
register: ospfv2_result
- name: Deconfigure OSPF (deletes only OSPF processes listed in YAML)
graphiant.naas.graphiant_ospfv2:
operation: deconfigure
ospfv2_config_file: "sample_ospfv2_config.yaml"
host: "{{ graphiant_host }}"
username: "{{ graphiant_username }}"
password: "{{ graphiant_password }}"
detailed_logs: true
state: absent
no_log: true
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
Whether the operation made changes.
In check mode ( Returned: always Sample: |
|
Device names where configuration was pushed (when changed=true). Returned: when supported Sample: |
|
Raw manager result details (includes changed/configured/skipped device lists). Returned: when supported |
|
Ansible Returned: when playbook uses |
|
Result message from the operation, including detailed logs when Returned: always Sample: |
|
The operation performed. Returned: always Sample: |
|
The OSPFv2 config file used for the operation. Returned: always Sample: |
|
Device names that were skipped because desired state already matched. Returned: when supported Sample: |