Ansible openstack.cloud module reference
This page lists the openstack.cloud Ansible collection modules that are usable on Quake AI, grouped by service. Each entry names the module, the operation it performs, and Quake AI-specific constraints.
Modules excluded from this reference target services Quake AI does not expose; the excluded modules section names them and the reason.
For a conceptual overview of where Ansible fits on Quake AI, read Ansible on Quake AI. For installation steps and a first playbook, read the getting-started how-to.
Conventions#
- The modules below assume the
openstack.cloudcollection version 2.x (current: 2.6.0). The 1.x series is not supported on Antelope. - Authentication uses
clouds.yamlwith application credentials, or theOS_*environment variables sourced fromopenrc.sh. Module-levelcloud:parameters reference a named cloud inclouds.yaml. - Real Quake AI values: flavor
m2a.large, imageUbuntu-24.04, regionus-east-1, external networkPublicStatic, identity endpointhttps://keystone.rumble.cloud/v3(not per-region). - Quake AI flavor families advertise
disk: 0. Theopenstack.cloud.servermodule therefore needsboot_from_volume: trueplusvolume_size:(in GiB) on Quake AI. Without those settings, server creation fails because the flavor has no disk. - Module compatibility targets Antelope through
openstacksdk1.x.
Compute#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.server | Create or delete a compute instance | Use flavor (for example m2a.large) and image (Ubuntu-24.04) values that match the Quake AI catalog. Set boot_from_volume: true plus volume_size: (and typically terminate_volume: true) because Quake AI flavors advertise disk: 0. Supports auto_ip, security_groups, metadata, and userdata for cloud-init. |
openstack.cloud.server_info | List or query instances | Filter by name, id, or metadata. The dynamic inventory plugin can group the returned instances. |
openstack.cloud.server_action | Stop, start, pause, rebuild, or shelve an instance | The rebuild action requires an image parameter. |
openstack.cloud.server_volume | Attach or detach a Cinder volume | The volume must already exist; combine with openstack.cloud.volume to provision and attach in one play. |
openstack.cloud.server_metadata | Manage instance metadata | The dynamic inventory plugin reads metadata for grouping (role, environment). |
openstack.cloud.server_group | Create or delete a server group (affinity or anti-affinity) | Reference the group by name from openstack.cloud.server to place instances together or apart. |
openstack.cloud.compute_flavor_info | Look up flavors | Returns flavor names and attributes for validation before server creation. |
openstack.cloud.keypair | Create or delete an SSH keypair | The keypair must exist in the project before openstack.cloud.server can reference it. |
openstack.cloud.keypair_info | List keypairs | |
openstack.cloud.image | Upload or delete a Glance image | Pair with openstack.cloud.image_info to resolve an existing image before referencing it from openstack.cloud.server. |
openstack.cloud.image_info | Look up base images | Use to discover the current Ubuntu-24.04 image ID when scripting against a pinned ID instead of a name. |
Network#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.network | Create or delete a network | |
openstack.cloud.networks_info | List networks | |
openstack.cloud.subnet | Create or delete a subnet | Supports allocation_pools and dns_nameservers. |
openstack.cloud.subnets_info | List subnets | |
openstack.cloud.router | Create or delete a router | Set external_gateway_info to attach the public network. |
openstack.cloud.routers_info | List routers | |
openstack.cloud.security_group | Create or delete a security group | |
openstack.cloud.security_group_info | List security groups | |
openstack.cloud.security_group_rule | Manage security group rules | Idempotent on direction, ethertype, protocol, port range, and CIDR. |
openstack.cloud.security_group_rule_info | List security group rules | |
openstack.cloud.floating_ip | Allocate or assign a floating IP | openstack.cloud.server can allocate one with auto_ip: true; this module manages explicit allocation and assignment. |
openstack.cloud.floating_ip_info | List floating IPs | |
openstack.cloud.port | Create, update, or delete a Neutron port | |
openstack.cloud.port_info | List Neutron ports | |
openstack.cloud.address_scope | Create or delete a Neutron address scope | |
openstack.cloud.subnet_pool | Create, update, or delete a subnet pool | Associate with an address scope to manage allocation ranges. |
openstack.cloud.neutron_rbac_policy | Create or delete a network RBAC policy | Shares a network or other Neutron object with another project. |
openstack.cloud.neutron_rbac_policies_info | List network RBAC policies |
Storage#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.volume | Create or delete a Cinder block volume | The Compute API attaches volumes via openstack.cloud.server_volume. |
openstack.cloud.volume_info | List volumes | |
openstack.cloud.volume_manage | Bring an existing Cinder volume under management or release it | The volume must already exist in the storage backend; state: absent releases it from Block Storage without deleting the data. |
openstack.cloud.volume_snapshot | Create or delete a volume snapshot | |
openstack.cloud.volume_snapshot_info | List volume snapshots | |
openstack.cloud.volume_type_info | List volume types | Use to discover valid volume_type values before creating a volume. |
openstack.cloud.object | Upload or delete a Swift object | This module communicates with Swift. The Quake AI S3-compatible layer works with S3 clients such as amazon.aws.s3_object or mc. |
openstack.cloud.object_container | Manage Swift containers | |
openstack.cloud.object_containers_info | List Swift containers |
Identity#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.project_info | Query project details | Returns project details used in quota checks before provisioning. |
openstack.cloud.identity_user_info | Query user information | |
openstack.cloud.application_credential | Create or delete application credentials | Added in collection 2.3.0. Use this to rotate credentials from a maintenance playbook. |
openstack.cloud.auth | Retrieve an auth token | Retrieves a token directly. Standard playbooks authenticate through clouds.yaml. |
openstack.cloud.quota | View or set quotas | Requires admin or a delegated role; project-scoped users can only view. |
Kubernetes (Magnum)#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.coe_cluster | Create or delete a Magnum cluster | Requires openstacksdk >= 1.0.0. Cluster lifecycle only; cluster operations (scaling, upgrading) go through kubectl or the openstack coe cluster CLI. |
openstack.cloud.coe_cluster_template | Create or delete a cluster template | Defines Kubernetes version, flavors, network driver, volume driver, and labels. The Quake AI Kubernetes service docs describe available cluster shapes. |
The Kubernetes service documentation covers cluster operations after creation. The Ansible Magnum modules in this reference manage cluster creation and deletion.
Orchestration (Heat)#
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.stack | Create or delete a Heat stack | Runs existing Heat templates through the Quake AI Automation service. Quake AI also supports OpenTofu for provisioning. |
openstack.cloud.stack_info | Query Heat stacks |
Generic and SDK modules#
These service-agnostic modules cover resources without a dedicated collection module.
| Module | Purpose | Quake AI notes |
|---|---|---|
openstack.cloud.resource | Create, update, or delete a generic OpenStack resource | Use when the collection has no dedicated module for the resource. |
openstack.cloud.resources | List generic OpenStack resources | Read-only counterpart to openstack.cloud.resource. |
openstack.cloud.config | Read the openstacksdk client configuration | Loads and returns clouds.yaml data. |
Modules excluded from this reference#
Quake AI excludes some collection modules because it does not expose the underlying OpenStack service:
baremetal_*(Ironic): Quake AI does not offer bare metal instances.dns_zone,dns_zone_info,recordset(Designate): Quake AI does not expose a DNS-as-a-service API.share_type*(Manila): Quake AI does not expose a shared file system service.loadbalancer,lb_listener,lb_pool,lb_member,lb_health_monitor: Quake AI does not offer tenant-managed LBaaS through these Ansible modules. KubernetesService type: LoadBalancerremains available through Kubernetes tooling.secret,secret_info: Quake AI does not offer public secret storage.volume_backup,volume_backup_info: Quake AI does not offer native volume backups. Use volume snapshots and clones.trunk(Neutron): the Neutron trunks API is unavailable inus-east-1and returns HTTP 404.federation_*,keystone_federation_protocol*(Keystone federation): platform operators configure federation.
Other modules require the operator role on Quake AI. The service tables omit these modules because tenant credentials cannot drive them:
compute_flavor,compute_flavor_access,compute_service_info: flavors and compute services are operator-managed. Useopenstack.cloud.compute_flavor_infoto read flavors as a tenant.catalog_service,catalog_service_info,endpoint,trait: the service catalog, endpoints, and resource-class traits are operator-managed.host_aggregate: host aggregates are operator-managed.identity_domain,identity_domain_info,identity_group,identity_group_info,identity_role,identity_role_info,identity_user: domain, group, role, and user administration is operator-managed. Useopenstack.cloud.identity_user_infoto read users as a tenant.group_assignment,role_assignment,project: role assignment and project creation are operator-managed. Useopenstack.cloud.project_infoto read project details as a tenant.volume_service_info,volume_type,volume_type_access,volume_type_encryption: volume services and volume-type definitions are operator-managed. Useopenstack.cloud.volume_type_infoto read volume types as a tenant.
Quake AI returns an HTTP 403 authorization error when tenant credentials call an operator-only module.
The upstream collection includes modules beyond those listed here. Verify service availability and tenant permissions against your project before using an unlisted module.
See also#
- Ansible on Quake AI: conceptual overview and Day 0 / Day 1 / Day 2 model
- Get started with Ansible on Quake AI: install the collection and run a first playbook
- Configure a VM with Ansible: post-provision configuration template
- Provision and configure with OpenTofu plus Ansible: combined-tool workflow template
openstack.cloudcollection documentation: upstream module reference and changelog