.. _vyos.rest.vyos_httpapi:
**************
vyos.rest.vyos
**************
**VyOS REST API**
.. contents::
:local:
:depth: 1
Synopsis
--------
- HTTPAPI plugin for interacting with VyOS REST API.
- Supports multiple authentication methods against the VyOS REST API -- ``key`` (API key in the request body), ``header`` (API key as an ``X-API-Key`` header), ``bearer`` (a VyOS-issued bearer token, fetched and cached), ``mtls`` (mutual TLS, no application-level credential), and ``oidc`` (a bearer token obtained from an external OpenID Connect provider via the client_credentials grant, fetched and cached).
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Configuration |
Comments |
|
api_key
string
|
|
ini entries:
[httpapi] api_key = VALUE
env:ANSIBLE_HTTPAPI_API_KEY
env:VYOS_API_KEY
var: ansible_httpapi_api_key
var: ansible_vyos_api_key
|
VyOS API key. Required for auth_method key, header, and bearer.
|
|
auth_method
string
|
Choices:
key ←
- header
- bearer
- mtls
- oidc
|
ini entries:
[httpapi] auth_method = key
var: ansible_httpapi_auth_method
|
Authentication method to use against the VyOS REST API.
|
|
oidc_client_id
string
|
|
ini entries:
[httpapi] oidc_client_id = VALUE
var: ansible_httpapi_oidc_client_id
|
OIDC client ID for the client_credentials grant.
|
|
oidc_client_secret
string
|
|
ini entries:
[httpapi] oidc_client_secret = VALUE
var: ansible_httpapi_oidc_client_secret
|
OIDC client secret for the client_credentials grant.
|
|
oidc_timeout
integer
|
Default:
10
|
ini entries:
[httpapi] oidc_timeout = 10
var: ansible_httpapi_oidc_timeout
|
Timeout, in seconds, for the token request made to the OIDC provider. An unavailable or stalled identity provider would otherwise hang the Ansible task indefinitely.
|
|
oidc_token_url
string
|
|
ini entries:
[httpapi] oidc_token_url = VALUE
var: ansible_httpapi_oidc_token_url
|
Token endpoint URL of the OIDC provider. Required for auth_method oidc.
|