Note
This module is part of the community.proxmox collection (version 1.3.0).
You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install community.proxmox. You need further requirements to be able to use this module, see Requirements for details.
To use it in a playbook, specify: community.proxmox.proxmox_access_acl.
New in community.proxmox 1.1.0
/access/acls to grant permission to interact with objects.The below requirements are needed on the host that executes this module.
Parameter | Comments |
|---|---|
api_host string / required | Specify the target host of the Proxmox VE cluster. Uses the |
api_password string | Specify the password to authenticate with. Uses the |
api_port integer | Specify the target port of the Proxmox VE cluster. Uses the |
api_token_id string | Specify the token ID. Uses the |
api_token_secret string | Specify the token secret. Uses the |
api_user string / required | Specify the user to authenticate with. Uses the |
path string | Access Control Path |
propagate boolean | Allow to propagate (inherit) permissions. Choices:
|
roleid string | name of the role |
state string / required | create or delete Choices:
|
type string | type of access control Choices:
|
ugid string | id of user or group |
validate_certs boolean | If This should only be used on personally controlled sites using self-signed certificates. Uses the Choices:
|
Attribute | Support | Description |
|---|---|---|
action_group | Action group: community.proxmox.proxmox | Use |
check_mode | Support: none | Can run in |
diff_mode | Support: none | Will return details on what has changed (or possibly needs changing in |
- name: Create ACE
community.proxmox.proxmox_access_acl:
api_host: "{{ ansible_host }}"
api_password: "{{ proxmox_root_pw | default(lookup('ansible.builtin.env', 'PROXMOX_PASSWORD', default='')) }}"
api_user: root@pam
state: "present"
path: /vms/100
type: user
ugid: "a01mako@pam"
roleid: PVEVMUser
propagate: 1
- name: Delete all ACEs for a given path
community.proxmox.proxmox_access_acl:
api_host: "{{ ansible_host }}"
api_password: "{{ proxmox_root_pw | default(lookup('ansible.builtin.env', 'PROXMOX_PASSWORD', default='')) }}"
api_user: root@pam
state: "absent"
path: /vms/100
Common return values are documented here, the following are the fields unique to this module:
Key | Description |
|---|---|
new_acls list / elements=string | The output message that the test module generates. Returned: when changed |
old_acls list / elements=string | The original name param that was passed in. Returned: always |
© 2012–2018 Michael DeHaan
© 2018–2025 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/community/proxmox/proxmox_access_acl_module.html