Skip to content

Ansible openstack.cloud module reference

Reference · Updated Sep 2026

Coming from another cloud?

▸AWS·Systems Manager

This Quake AI feature maps to AWS’s Systems Manager.

▸Azure·Automation DSC

This Quake AI feature maps to Azure’s Automation DSC.

Ansible openstack.cloud module reference

This page lists the openstack.cloud Ansible collection modules that are usable on Quake AI, grouped by service. Each entry names the module, the operation it performs, and Quake AI-specific constraints.

Modules excluded from this reference target services Quake AI does not expose; the excluded modules section names them and the reason.

For a conceptual overview of where Ansible fits on Quake AI, read Ansible on Quake AI. For installation steps and a first playbook, read the getting-started how-to.

Conventions#

  • The modules below assume the openstack.cloud collection version 2.x (current: 2.6.0). The 1.x series is not supported on Antelope.
  • Authentication uses clouds.yaml with application credentials, or the OS_* environment variables sourced from openrc.sh. Module-level cloud: parameters reference a named cloud in clouds.yaml.
  • Real Quake AI values: flavor m2a.large, image Ubuntu-24.04, region us-east-1, external network PublicStatic, identity endpoint https://keystone.rumble.cloud/v3 (not per-region).
  • Quake AI flavor families advertise disk: 0. The openstack.cloud.server module therefore needs boot_from_volume: true plus volume_size: (in GiB) on Quake AI. Without those settings, server creation fails because the flavor has no disk.
  • Module compatibility targets Antelope through openstacksdk 1.x.

Compute#

ModulePurposeQuake AI notes
openstack.cloud.serverCreate or delete a compute instanceUse flavor (for example m2a.large) and image (Ubuntu-24.04) values that match the Quake AI catalog. Set boot_from_volume: true plus volume_size: (and typically terminate_volume: true) because Quake AI flavors advertise disk: 0. Supports auto_ip, security_groups, metadata, and userdata for cloud-init.
openstack.cloud.server_infoList or query instancesFilter by name, id, or metadata. The dynamic inventory plugin can group the returned instances.
openstack.cloud.server_actionStop, start, pause, rebuild, or shelve an instanceThe rebuild action requires an image parameter.
openstack.cloud.server_volumeAttach or detach a Cinder volumeThe volume must already exist; combine with openstack.cloud.volume to provision and attach in one play.
openstack.cloud.server_metadataManage instance metadataThe dynamic inventory plugin reads metadata for grouping (role, environment).
openstack.cloud.server_groupCreate or delete a server group (affinity or anti-affinity)Reference the group by name from openstack.cloud.server to place instances together or apart.
openstack.cloud.compute_flavor_infoLook up flavorsReturns flavor names and attributes for validation before server creation.
openstack.cloud.keypairCreate or delete an SSH keypairThe keypair must exist in the project before openstack.cloud.server can reference it.
openstack.cloud.keypair_infoList keypairs
openstack.cloud.imageUpload or delete a Glance imagePair with openstack.cloud.image_info to resolve an existing image before referencing it from openstack.cloud.server.
openstack.cloud.image_infoLook up base imagesUse to discover the current Ubuntu-24.04 image ID when scripting against a pinned ID instead of a name.

Network#

ModulePurposeQuake AI notes
openstack.cloud.networkCreate or delete a network
openstack.cloud.networks_infoList networks
openstack.cloud.subnetCreate or delete a subnetSupports allocation_pools and dns_nameservers.
openstack.cloud.subnets_infoList subnets
openstack.cloud.routerCreate or delete a routerSet external_gateway_info to attach the public network.
openstack.cloud.routers_infoList routers
openstack.cloud.security_groupCreate or delete a security group
openstack.cloud.security_group_infoList security groups
openstack.cloud.security_group_ruleManage security group rulesIdempotent on direction, ethertype, protocol, port range, and CIDR.
openstack.cloud.security_group_rule_infoList security group rules
openstack.cloud.floating_ipAllocate or assign a floating IPopenstack.cloud.server can allocate one with auto_ip: true; this module manages explicit allocation and assignment.
openstack.cloud.floating_ip_infoList floating IPs
openstack.cloud.portCreate, update, or delete a Neutron port
openstack.cloud.port_infoList Neutron ports
openstack.cloud.address_scopeCreate or delete a Neutron address scope
openstack.cloud.subnet_poolCreate, update, or delete a subnet poolAssociate with an address scope to manage allocation ranges.
openstack.cloud.neutron_rbac_policyCreate or delete a network RBAC policyShares a network or other Neutron object with another project.
openstack.cloud.neutron_rbac_policies_infoList network RBAC policies

Storage#

ModulePurposeQuake AI notes
openstack.cloud.volumeCreate or delete a Cinder block volumeThe Compute API attaches volumes via openstack.cloud.server_volume.
openstack.cloud.volume_infoList volumes
openstack.cloud.volume_manageBring an existing Cinder volume under management or release itThe volume must already exist in the storage backend; state: absent releases it from Block Storage without deleting the data.
openstack.cloud.volume_snapshotCreate or delete a volume snapshot
openstack.cloud.volume_snapshot_infoList volume snapshots
openstack.cloud.volume_type_infoList volume typesUse to discover valid volume_type values before creating a volume.
openstack.cloud.objectUpload or delete a Swift objectThis module communicates with Swift. The Quake AI S3-compatible layer works with S3 clients such as amazon.aws.s3_object or mc.
openstack.cloud.object_containerManage Swift containers
openstack.cloud.object_containers_infoList Swift containers

Identity#

ModulePurposeQuake AI notes
openstack.cloud.project_infoQuery project detailsReturns project details used in quota checks before provisioning.
openstack.cloud.identity_user_infoQuery user information
openstack.cloud.application_credentialCreate or delete application credentialsAdded in collection 2.3.0. Use this to rotate credentials from a maintenance playbook.
openstack.cloud.authRetrieve an auth tokenRetrieves a token directly. Standard playbooks authenticate through clouds.yaml.
openstack.cloud.quotaView or set quotasRequires admin or a delegated role; project-scoped users can only view.

Kubernetes (Magnum)#

ModulePurposeQuake AI notes
openstack.cloud.coe_clusterCreate or delete a Magnum clusterRequires openstacksdk >= 1.0.0. Cluster lifecycle only; cluster operations (scaling, upgrading) go through kubectl or the openstack coe cluster CLI.
openstack.cloud.coe_cluster_templateCreate or delete a cluster templateDefines Kubernetes version, flavors, network driver, volume driver, and labels. The Quake AI Kubernetes service docs describe available cluster shapes.

The Kubernetes service documentation covers cluster operations after creation. The Ansible Magnum modules in this reference manage cluster creation and deletion.

Orchestration (Heat)#

ModulePurposeQuake AI notes
openstack.cloud.stackCreate or delete a Heat stackRuns existing Heat templates through the Quake AI Automation service. Quake AI also supports OpenTofu for provisioning.
openstack.cloud.stack_infoQuery Heat stacks

Generic and SDK modules#

These service-agnostic modules cover resources without a dedicated collection module.

ModulePurposeQuake AI notes
openstack.cloud.resourceCreate, update, or delete a generic OpenStack resourceUse when the collection has no dedicated module for the resource.
openstack.cloud.resourcesList generic OpenStack resourcesRead-only counterpart to openstack.cloud.resource.
openstack.cloud.configRead the openstacksdk client configurationLoads and returns clouds.yaml data.

Modules excluded from this reference#

Quake AI excludes some collection modules because it does not expose the underlying OpenStack service:

  • baremetal_* (Ironic): Quake AI does not offer bare metal instances.
  • dns_zone, dns_zone_info, recordset (Designate): Quake AI does not expose a DNS-as-a-service API.
  • share_type* (Manila): Quake AI does not expose a shared file system service.
  • loadbalancer, lb_listener, lb_pool, lb_member, lb_health_monitor: Quake AI does not offer tenant-managed LBaaS through these Ansible modules. Kubernetes Service type: LoadBalancer remains available through Kubernetes tooling.
  • secret, secret_info: Quake AI does not offer public secret storage.
  • volume_backup, volume_backup_info: Quake AI does not offer native volume backups. Use volume snapshots and clones.
  • trunk (Neutron): the Neutron trunks API is unavailable in us-east-1 and returns HTTP 404.
  • federation_*, keystone_federation_protocol* (Keystone federation): platform operators configure federation.

Other modules require the operator role on Quake AI. The service tables omit these modules because tenant credentials cannot drive them:

  • compute_flavor, compute_flavor_access, compute_service_info: flavors and compute services are operator-managed. Use openstack.cloud.compute_flavor_info to read flavors as a tenant.
  • catalog_service, catalog_service_info, endpoint, trait: the service catalog, endpoints, and resource-class traits are operator-managed.
  • host_aggregate: host aggregates are operator-managed.
  • identity_domain, identity_domain_info, identity_group, identity_group_info, identity_role, identity_role_info, identity_user: domain, group, role, and user administration is operator-managed. Use openstack.cloud.identity_user_info to read users as a tenant.
  • group_assignment, role_assignment, project: role assignment and project creation are operator-managed. Use openstack.cloud.project_info to read project details as a tenant.
  • volume_service_info, volume_type, volume_type_access, volume_type_encryption: volume services and volume-type definitions are operator-managed. Use openstack.cloud.volume_type_info to read volume types as a tenant.

Quake AI returns an HTTP 403 authorization error when tenant credentials call an operator-only module.

The upstream collection includes modules beyond those listed here. Verify service availability and tenant permissions against your project before using an unlisted module.

See also#

Quick answers

Was this page helpful?