2020-03-09 10:11:07 +01:00
|
|
|
# -*- coding: utf-8 -*-
|
2022-08-05 12:28:29 +02:00
|
|
|
# Copyright (c) 2018, Scott Buchanan <sbuchanan@ri.pn>
|
|
|
|
# Copyright (c) 2016, Andrew Zenk <azenk@umn.edu> (lastpass.py used as starting point)
|
|
|
|
# Copyright (c) 2018, Ansible Project
|
|
|
|
# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt)
|
|
|
|
# SPDX-License-Identifier: GPL-3.0-or-later
|
2020-03-09 10:11:07 +01:00
|
|
|
|
|
|
|
from __future__ import (absolute_import, division, print_function)
|
|
|
|
__metaclass__ = type
|
|
|
|
|
|
|
|
DOCUMENTATION = '''
|
2021-01-12 07:12:03 +01:00
|
|
|
name: onepassword_raw
|
2020-03-09 10:11:07 +01:00
|
|
|
author:
|
|
|
|
- Scott Buchanan (@scottsb)
|
|
|
|
- Andrew Zenk (@azenk)
|
|
|
|
- Sam Doran (@samdoran)
|
|
|
|
requirements:
|
|
|
|
- C(op) 1Password command line utility. See U(https://support.1password.com/command-line/)
|
|
|
|
short_description: fetch an entire item from 1Password
|
|
|
|
description:
|
2023-06-10 09:28:40 +02:00
|
|
|
- P(community.general.onepassword_raw#lookup) wraps C(op) command line utility to fetch an entire item from 1Password.
|
2020-03-09 10:11:07 +01:00
|
|
|
options:
|
|
|
|
_terms:
|
|
|
|
description: identifier(s) (UUID, name, or domain; case-insensitive) of item(s) to retrieve.
|
2022-09-06 20:42:17 +02:00
|
|
|
required: true
|
2020-03-09 10:11:07 +01:00
|
|
|
master_password:
|
|
|
|
description: The password used to unlock the specified vault.
|
|
|
|
aliases: ['vault_password']
|
|
|
|
section:
|
|
|
|
description: Item section containing the field to retrieve (case-insensitive). If absent will return first match from any section.
|
|
|
|
subdomain:
|
|
|
|
description: The 1Password subdomain to authenticate against.
|
2022-11-09 07:28:49 +01:00
|
|
|
domain:
|
|
|
|
description: Domain of 1Password.
|
|
|
|
version_added: 6.0.0
|
|
|
|
default: '1password.com'
|
|
|
|
type: str
|
2023-09-28 21:26:49 +02:00
|
|
|
account_id:
|
|
|
|
description: The account ID to target.
|
|
|
|
type: str
|
|
|
|
version_added: 7.5.0
|
2020-03-09 10:11:07 +01:00
|
|
|
username:
|
|
|
|
description: The username used to sign in.
|
|
|
|
secret_key:
|
|
|
|
description: The secret key used when performing an initial sign in.
|
2023-06-15 19:18:12 +02:00
|
|
|
service_account_token:
|
|
|
|
description:
|
|
|
|
- The access key for a service account.
|
|
|
|
- Only works with 1Password CLI version 2 or later.
|
|
|
|
type: string
|
|
|
|
version_added: 7.1.0
|
2023-11-16 21:02:54 +01:00
|
|
|
connect_host:
|
|
|
|
description: The host for 1Password Connect. Must be used in combination with O(connect_token).
|
|
|
|
type: str
|
|
|
|
env:
|
|
|
|
- name: OP_CONNECT_HOST
|
|
|
|
version_added: 8.1.0
|
|
|
|
connect_token:
|
|
|
|
description: The token for 1Password Connect. Must be used in combination with O(connect_host).
|
|
|
|
type: str
|
|
|
|
env:
|
|
|
|
- name: OP_CONNECT_TOKEN
|
|
|
|
version_added: 8.1.0
|
2020-03-09 10:11:07 +01:00
|
|
|
vault:
|
|
|
|
description: Vault containing the item to retrieve (case-insensitive). If absent will search all vaults.
|
|
|
|
notes:
|
|
|
|
- This lookup will use an existing 1Password session if one exists. If not, and you have already
|
2023-06-10 09:28:40 +02:00
|
|
|
performed an initial sign in (meaning C(~/.op/config exists)), then only the O(master_password) is required.
|
|
|
|
You may optionally specify O(subdomain) in this scenario, otherwise the last used subdomain will be used by C(op).
|
|
|
|
- This lookup can perform an initial login by providing O(subdomain), O(username), O(secret_key), and O(master_password).
|
2023-09-28 21:26:49 +02:00
|
|
|
- Can target a specific account by providing the O(account_id).
|
2020-03-09 10:11:07 +01:00
|
|
|
- Due to the B(very) sensitive nature of these credentials, it is B(highly) recommended that you only pass in the minimal credentials
|
|
|
|
needed at any given time. Also, store these credentials in an Ansible Vault using a key that is equal to or greater in strength
|
|
|
|
to the 1Password master password.
|
|
|
|
- This lookup stores potentially sensitive data from 1Password as Ansible facts.
|
|
|
|
Facts are subject to caching if enabled, which means this data could be stored in clear text
|
|
|
|
on disk or in a database.
|
2022-11-06 11:32:35 +01:00
|
|
|
- Tested with C(op) version 2.7.0
|
2020-03-09 10:11:07 +01:00
|
|
|
'''
|
|
|
|
|
|
|
|
EXAMPLES = """
|
|
|
|
- name: Retrieve all data about Wintermute
|
2020-07-14 17:28:08 +02:00
|
|
|
ansible.builtin.debug:
|
2020-08-08 22:04:34 +02:00
|
|
|
var: lookup('community.general.onepassword_raw', 'Wintermute')
|
2020-03-09 10:11:07 +01:00
|
|
|
|
|
|
|
- name: Retrieve all data about Wintermute when not signed in to 1Password
|
2020-07-14 17:28:08 +02:00
|
|
|
ansible.builtin.debug:
|
2020-08-08 22:04:34 +02:00
|
|
|
var: lookup('community.general.onepassword_raw', 'Wintermute', subdomain='Turing', vault_password='DmbslfLvasjdl')
|
2020-03-09 10:11:07 +01:00
|
|
|
"""
|
|
|
|
|
|
|
|
RETURN = """
|
|
|
|
_raw:
|
|
|
|
description: field data requested
|
2020-09-16 11:06:45 +02:00
|
|
|
type: list
|
|
|
|
elements: dict
|
2020-03-09 10:11:07 +01:00
|
|
|
"""
|
|
|
|
|
|
|
|
import json
|
|
|
|
|
|
|
|
from ansible_collections.community.general.plugins.lookup.onepassword import OnePass
|
2023-11-16 21:02:54 +01:00
|
|
|
from ansible.errors import AnsibleOptionsError
|
2020-03-09 10:11:07 +01:00
|
|
|
from ansible.plugins.lookup import LookupBase
|
|
|
|
|
|
|
|
|
|
|
|
class LookupModule(LookupBase):
|
|
|
|
|
|
|
|
def run(self, terms, variables=None, **kwargs):
|
2022-11-06 11:32:35 +01:00
|
|
|
self.set_options(var_options=variables, direct=kwargs)
|
2020-03-09 10:11:07 +01:00
|
|
|
|
2022-11-06 11:32:35 +01:00
|
|
|
vault = self.get_option("vault")
|
|
|
|
subdomain = self.get_option("subdomain")
|
|
|
|
domain = self.get_option("domain", "1password.com")
|
|
|
|
username = self.get_option("username")
|
|
|
|
secret_key = self.get_option("secret_key")
|
|
|
|
master_password = self.get_option("master_password")
|
2023-06-15 19:18:12 +02:00
|
|
|
service_account_token = self.get_option("service_account_token")
|
2023-09-28 21:26:49 +02:00
|
|
|
account_id = self.get_option("account_id")
|
2023-11-16 21:02:54 +01:00
|
|
|
connect_host = self.get_option("connect_host")
|
|
|
|
connect_token = self.get_option("connect_token")
|
|
|
|
|
|
|
|
if (connect_host or connect_token) and None in (connect_host, connect_token):
|
|
|
|
raise AnsibleOptionsError("connect_host and connect_token are required together")
|
2020-03-09 10:11:07 +01:00
|
|
|
|
2023-11-16 21:02:54 +01:00
|
|
|
op = OnePass(subdomain, domain, username, secret_key, master_password, service_account_token, account_id, connect_host, connect_token)
|
2020-03-09 10:11:07 +01:00
|
|
|
op.assert_logged_in()
|
|
|
|
|
|
|
|
values = []
|
|
|
|
for term in terms:
|
|
|
|
data = json.loads(op.get_raw(term, vault))
|
|
|
|
values.append(data)
|
2022-11-06 11:32:35 +01:00
|
|
|
|
2020-03-09 10:11:07 +01:00
|
|
|
return values
|