amazon.aws.ec2_metadata_facts – gathers facts (instance metadata) about remote hosts within EC2
Note
This plugin is part of the amazon.aws collection (version 1.5.1).
You might already have this collection installed if you are using the ansible
package. It is not included in ansible-core
. To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install amazon.aws
.
To use it in a playbook, specify: amazon.aws.ec2_metadata_facts
.
New in version 1.0.0: of amazon.aws
Synopsis
- This module fetches data from the instance metadata endpoint in EC2 as per https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html.
- The module must be called from within the EC2 instance itself.
- The module is configured to utilize the session oriented Instance Metadata Service v2 (IMDSv2) https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html.
- If the HttpEndpoint parameter https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMetadataOptions.html#API_ModifyInstanceMetadataOptions_RequestParameters is set to disabled for the EC2 instance, the module will return an error while retrieving a session token.
Notes
Note
- Parameters to filter on ec2_metadata_facts may be added later.
Examples
# Gather EC2 metadata facts - amazon.aws.ec2_metadata_facts: - debug: msg: "This instance is a t1.micro" when: ansible_ec2_instance_type == "t1.micro"
Returned Facts
Facts returned by this module are added/updated in the hostvars
host facts and can be referenced by name just like any other host fact. They do not need to be registered in order to use them.
Fact | Returned | Description | |
---|---|---|---|
ansible_ec2_ami_id string / elements=string | success | The AMI ID used to launch the instance. Sample: ami-XXXXXXXX | |
ansible_ec2_ami_launch_index string / elements=string | success | If you started more than one instance at the same time, this value indicates the order in which the instance was launched. The value of the first instance launched is 0. Sample: 0 | |
ansible_ec2_ami_manifest_path string / elements=string | success | The path to the AMI manifest file in Amazon S3. If you used an Amazon EBS-backed AMI to launch the instance, the returned result is unknown. Sample: (unknown) | |
ansible_ec2_ancestor_ami_ids string / elements=string | success | The AMI IDs of any instances that were rebundled to create this AMI. This value will only exist if the AMI manifest file contained an ancestor-amis key. Sample: (unknown) | |
ansible_ec2_block_device_mapping_ami string / elements=string | success | The virtual device that contains the root/boot file system. Sample: /dev/sda1 | |
ansible_ec2_block_device_mapping_ebsN string / elements=string | success | The virtual devices associated with Amazon EBS volumes, if any are present. Amazon EBS volumes are only available in metadata if they were present at launch time or when the instance was last started. The N indicates the index of the Amazon EBS volume (such as ebs1 or ebs2). Sample: /dev/xvdb | |
ansible_ec2_block_device_mapping_ephemeralN string / elements=string | success | The virtual devices associated with ephemeral devices, if any are present. The N indicates the index of the ephemeral volume. Sample: /dev/xvdc | |
ansible_ec2_block_device_mapping_root string / elements=string | success | The virtual devices or partitions associated with the root devices, or partitions on the virtual device, where the root (/ or C) file system is associated with the given instance. Sample: /dev/sda1 | |
ansible_ec2_block_device_mapping_swap string / elements=string | success | The virtual devices associated with swap. Not always present. Sample: /dev/sda2 | |
ansible_ec2_fws_instance_monitoring string / elements=string | success | Value showing whether the customer has enabled detailed one-minute monitoring in CloudWatch. Sample: enabled | |
ansible_ec2_hostname string / elements=string | success | The private IPv4 DNS hostname of the instance. In cases where multiple network interfaces are present, this refers to the eth0 device (the device for which the device number is 0). Sample: ip-10-0-0-1.ec2.internal | |
ansible_ec2_iam_info complex / elements=string | success | If there is an IAM role associated with the instance, contains information about the last time the instance profile was updated, including the instance's LastUpdated date, InstanceProfileArn, and InstanceProfileId. Otherwise, not present. | |
InstanceProfileArn string / elements=string | success | The ARN of the InstanceProfile associated with the Instance. | |
InstanceProfileId string / elements=string | success | The Id of the InstanceProfile associated with the Instance. | |
LastUpdated string / elements=string | success | The last time which InstanceProfile is associated with the Instance changed. | |
ansible_ec2_iam_info_instanceprofilearn string / elements=string | success | The IAM instance profile ARN. Sample: arn:aws:iam::<account id>:instance-profile/<role name> | |
ansible_ec2_iam_info_instanceprofileid string / elements=string | success | IAM instance profile ID. | |
ansible_ec2_iam_info_lastupdated string / elements=string | success | IAM info last updated time. Sample: 2017-05-12T02:42:27Z | |
ansible_ec2_iam_instance_profile_role string / elements=string | success | IAM instance role. Sample: role_name | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | If there is an IAM role associated with the instance, role-name is the name of the role, and role-name contains the temporary security credentials associated with the role. Otherwise, not present. | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role access key ID. | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM code. Sample: Success | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role credentials expiration time. Sample: 2017-05-12T09:11:41Z | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role last updated time. Sample: 2017-05-12T02:40:44Z | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role secret access key. | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role token. | |
ansible_ec2_iam_security_credentials_ string / elements=string | success | IAM role type. Sample: AWS-HMAC | |
ansible_ec2_instance_action string / elements=string | success | Notifies the instance that it should reboot in preparation for bundling. Sample: none | |
ansible_ec2_instance_id string / elements=string | success | The ID of this instance. Sample: i-XXXXXXXXXXXXXXXXX | |
ansible_ec2_instance_identity_document string / elements=string | success | JSON containing instance attributes, such as instance-id, private IP address, etc. | |
ansible_ec2_instance_identity_document_accountid string / elements=string | success | Sample: 012345678901 | |
ansible_ec2_instance_identity_document_architecture string / elements=string | success | Instance system architecture. Sample: x86_64 | |
ansible_ec2_instance_identity_document_availabilityzone string / elements=string | success | The Availability Zone in which the instance launched. Sample: us-east-1a | |
ansible_ec2_instance_identity_document_billingproducts string / elements=string | success | Billing products for this instance. | |
ansible_ec2_instance_identity_document_devpayproductcodes string / elements=string | success | Product codes for the launched AMI. | |
ansible_ec2_instance_identity_document_imageid string / elements=string | success | The AMI ID used to launch the instance. Sample: ami-01234567 | |
ansible_ec2_instance_identity_document_instanceid string / elements=string | success | The ID of this instance. Sample: i-0123456789abcdef0 | |
ansible_ec2_instance_identity_document_instancetype string / elements=string | success | The type of instance. Sample: m4.large | |
ansible_ec2_instance_identity_document_kernelid string / elements=string | success | The ID of the kernel launched with this instance, if applicable. | |
ansible_ec2_instance_identity_document_pendingtime string / elements=string | success | The instance pending time. Sample: 2017-05-11T20:51:20Z | |
ansible_ec2_instance_identity_document_privateip string / elements=string | success | The private IPv4 address of the instance. In cases where multiple network interfaces are present, this refers to the eth0 device (the device for which the device number is 0). Sample: 10.0.0.1 | |
ansible_ec2_instance_identity_document_ramdiskid string / elements=string | success | The ID of the RAM disk specified at launch time, if applicable. | |
ansible_ec2_instance_identity_document_region string / elements=string | success | The Region in which the instance launched. Sample: us-east-1 | |
ansible_ec2_instance_identity_document_version string / elements=string | success | Identity document version. Sample: 2010-08-31 | |
ansible_ec2_instance_identity_pkcs7 string / elements=string | success | Used to verify the document's authenticity and content against the signature. | |
ansible_ec2_instance_identity_rsa2048 string / elements=string | success | Used to verify the document's authenticity and content against the signature. | |
ansible_ec2_instance_identity_signature string / elements=string | success | Data that can be used by other parties to verify its origin and authenticity. | |
ansible_ec2_instance_life_cycle string / elements=string | success | The purchasing option of the instance. Sample: on-demand | |
ansible_ec2_instance_type string / elements=string | success | The type of the instance. Sample: m4.large | |
ansible_ec2_local_hostname string / elements=string | success | The private IPv4 DNS hostname of the instance. In cases where multiple network interfaces are present, this refers to the eth0 device (the device for which the device number is 0). Sample: ip-10-0-0-1.ec2.internal | |
ansible_ec2_local_ipv4 string / elements=string | success | The private IPv4 address of the instance. In cases where multiple network interfaces are present, this refers to the eth0 device (the device for which the device number is 0). Sample: 10.0.0.1 | |
ansible_ec2_mac string / elements=string | success | The instance's media access control (MAC) address. In cases where multiple network interfaces are present, this refers to the eth0 device (the device for which the device number is 0). Sample: 00:11:22:33:44:55 | |
ansible_ec2_metrics_vhostmd string / elements=string | success | Metrics; no longer available. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The unique device number associated with that interface. The device number corresponds to the device name; for example, a device-number of 2 is for the eth2 device. This category corresponds to the DeviceIndex and device-index fields that are used by the Amazon EC2 API and the EC2 commands for the AWS CLI. Sample: 0 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The elastic network interface ID. Sample: eni-12345678 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The private IPv4 addresses that are associated with each public-ip address and assigned to that interface. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv6 addresses associated with the interface. Returned only for instances launched into a VPC. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The interface's local hostname. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The private IPv4 addresses associated with the interface. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The instance's MAC address. Sample: 00:11:22:33:44:55 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The ID of the owner of the network interface. In multiple-interface environments, an interface can be attached by a third party, such as Elastic Load Balancing. Traffic on an interface is always billed to the interface owner. Sample: 01234567890 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The interface's public DNS (IPv4). If the instance is in a VPC, this category is only returned if the enableDnsHostnames attribute is set to true. Sample: ec2-1-2-3-4.compute-1.amazonaws.com | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The Elastic IP addresses associated with the interface. There may be multiple IPv4 addresses on an instance. Sample: 1.2.3.4 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IDs of the security groups to which the network interface belongs. Returned only for instances launched into a VPC. Sample: sg-01234567,sg-01234568 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | Security groups to which the network interface belongs. Returned only for instances launched into a VPC. Sample: secgroup1,secgroup2 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The ID of the subnet in which the interface resides. Returned only for instances launched into a VPC. Sample: subnet-01234567 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv4 CIDR block of the subnet in which the interface resides. Returned only for instances launched into a VPC. Sample: 10.0.1.0/24 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv6 CIDR block of the subnet in which the interface resides. Returned only for instances launched into a VPC. | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The ID of the VPC in which the interface resides. Returned only for instances launched into a VPC. Sample: vpc-0123456 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv4 CIDR block of the VPC in which the interface resides. Returned only for instances launched into a VPC. Sample: 10.0.0.0/16 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv4 CIDR block of the VPC in which the interface resides. Returned only for instances launched into a VPC. Sample: 10.0.0.0/16 | |
ansible_ec2_network_interfaces_macs_ string / elements=string | success | The IPv6 CIDR block of the VPC in which the interface resides. Returned only for instances launched into a VPC. | |
ansible_ec2_placement_availability_zone string / elements=string | success | The Availability Zone in which the instance launched. Sample: us-east-1a | |
ansible_ec2_placement_region string / elements=string | success | The Region in which the instance launched. Sample: us-east-1 | |
ansible_ec2_product_codes string / elements=string | success | Product codes associated with the instance, if any. Sample: aw0evgkw8e5c1q413zgy5pjce | |
ansible_ec2_profile string / elements=string | success | EC2 instance hardware profile. Sample: default-hvm | |
ansible_ec2_public_hostname string / elements=string | success | The instance's public DNS. If the instance is in a VPC, this category is only returned if the enableDnsHostnames attribute is set to true. Sample: ec2-1-2-3-4.compute-1.amazonaws.com | |
ansible_ec2_public_ipv4 string / elements=string | success | The public IPv4 address. If an Elastic IP address is associated with the instance, the value returned is the Elastic IP address. Sample: 1.2.3.4 | |
ansible_ec2_public_key string / elements=string | success | Public key. Only available if supplied at instance launch time. | |
ansible_ec2_ramdisk_id string / elements=string | success | The ID of the RAM disk specified at launch time, if applicable. | |
ansible_ec2_reservation_id string / elements=string | success | The ID of the reservation. Sample: r-0123456789abcdef0 | |
ansible_ec2_security_groups string / elements=string | success | The names of the security groups applied to the instance. After launch, you can only change the security groups of instances running in a VPC. Such changes are reflected here and in network/interfaces/macs/mac/security-groups. Sample: securitygroup1,securitygroup2 | |
ansible_ec2_services_domain string / elements=string | success | The domain for AWS resources for the region; for example, amazonaws.com for us-east-1. Sample: amazonaws.com | |
ansible_ec2_services_partition string / elements=string | success | The partition that the resource is in. For standard AWS regions, the partition is aws. If you have resources in other partitions, the partition is aws-partitionname. For example, the partition for resources in the China (Beijing) region is aws-cn. Sample: aws | |
ansible_ec2_spot_termination_time string / elements=string | success | The approximate time, in UTC, that the operating system for your Spot instance will receive the shutdown signal. This item is present and contains a time value only if the Spot instance has been marked for termination by Amazon EC2. The termination-time item is not set to a time if you terminated the Spot instance yourself. Sample: 2015-01-05T18:02:00Z | |
ansible_ec2_user_data string / elements=string | success | The instance user data. Sample: #!/bin/bash |
Authors
- Silviu Dicu (@silviud)
- Vinay Dandekar (@roadmapper)
© 2012–2018 Michael DeHaan
© 2018–2021 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/amazon/aws/ec2_metadata_facts_module.html