Skip to content

refactor(ansible): rename keeper_create folder_uid parameter to subfolder_uid (KSM-1454) - #1182

Merged
stas-schaller merged 1 commit into
release/integration/ansible/v1.5.0from
feat/KSM-1454-ansible-subfolder-uid
Sep 21, 2026
Merged

stas-schaller merged 1 commit into
release/integration/ansible/v1.5.0from
feat/KSM-1454-ansible-subfolder-uid

Conversation

@mgallego-keeper

Copy link
Copy Markdown
Contributor

Summary

The keeper_create module can create a record inside a subfolder. KSM-845 added this in v1.5.0 under the parameter name folder_uid. KSM-1445 later added the sibling module keeper_create_folder, which uses subfolder_uid for the same concept. The Python SDK's CreateOptions class also uses subfolder_uid. This PR renames keeper_create's parameter to subfolder_uid. All three now use one name.

Why now

Version 1.5.0 is not published yet. PyPI shows 1.4.0 as the latest release. Ansible Galaxy also shows 1.4.0. The release PR into master is still open. No released user can set folder_uid today. This rename breaks no public interface.

A decision this revisits

Commit cafdaab already faced this exact naming conflict. Its message says the author dropped an external PR's subfolder_uid addition to create_record(), in favor of the shipped name folder_uid. That same commit then added keeper_create_folder, which uses subfolder_uid for the identical concept. The shipped state today has two names for one idea, split across two sibling modules. This PR finishes that conflict resolution. It does not reverse it. subfolder_uid is now the name in both modules, and it matches the SDK too.

Two defects fixed in the same lines

  1. create_record() now turns an empty subfolder_uid into None. Before this change, the SDK payload sent subFolderUid: "" to the server. CreateOptions receives the raw value, and the payload serializes every attribute unconditionally.
  2. keeper_create now raises a clear error if a playbook still sets the old folder_uid key. No plugin in this integration declares an argument_spec. Ansible would otherwise drop an unknown key with no warning. Without this check, an unmigrated playbook would create the record at the shared folder root instead of the intended subfolder.

You can ask me to remove the second fix if you would rather not have it.

Also fixed

The subfolder_uid option now carries version_added: "1.5.0". The option had no version_added before, even though it lands in a version later than the module's own 1.1.2.

Origin

External contributor Geoffroy RABOUIN opened GitHub PR #1170. It adds this same ability under the name subfolder_uid. The ability already existed under folder_uid, so the PR added no new function. It does show that an outside user expects the name subfolder_uid, which matches KSM-845's own ticket title. This PR leaves GitHub PR #1170 open. A maintainer will follow up with the contributor separately.

Out of scope

keeper_create_folder's own CreateOptions call has the same empty-string gap that create_record() had before this fix. That call belongs to KSM-1445's code, not this ticket. It needs its own fix in a separate change.

Testing

CI runs no Ansible job for a pull request based on release/integration/ansible/**. The only Ansible workflow filters on branches: [master]. Local verification only:

  • Python 3.9.6, which matches the CI floor.
  • ansible-core 2.15.13, keeper-secrets-manager-core 17.3.0, keeper-secrets-manager-helper 1.1.2. All versions come from requirements.txt.
  • Baseline before this change: 47 passed, 0 failed.
  • After this change: 49 passed, 0 failed. The two new tests cover the empty-string case and the old-key rejection.
  • Mutation-tested both fixes by hand. Reverting the empty-string normalization fails the new empty-string test. Reverting the guard fails the new rejection test.
  • Confirmed by hand, before adding the guard, that an unmigrated playbook using the old folder_uid key was silently accepted. It created the record at the shared folder root with no error.
  • Confirmed with ansible-doc --json that the rendered module documentation shows subfolder_uid with version_added 1.5.0, and shows no folder_uid option.
  • Grepped the whole integration directory for folder_uid after the change. Every remaining line is either shared_folder_uid, an SDK attribute name, keeper_create_folder's own code, or the guard's own error text.

Files changed

  • keeper_secrets_manager_ansible/init.py
  • keeper_secrets_manager_ansible/plugins/action/keeper_create.py
  • keeper_secrets_manager_ansible/plugins/modules/keeper_create.py
  • tests/ansible_example/playbooks/keeper_create_subfolder.yml
  • tests/ansible_example/playbooks/keeper_create_subfolder_stale_key.yml (new fixture, tests the guard)
  • tests/keeper_create_subfolder_test.py
  • README.md
  • ansible_galaxy/keepersecurity/keeper_secrets_manager/README.md

JIRA: KSM-1454

…lder_uid (KSM-1454)

KSM-845 added the ability to create a keeper_create record inside a subfolder
and named the parameter folder_uid. KSM-1445 then added the sibling module
keeper_create_folder, which names the same concept subfolder_uid, and the
Python SDK's CreateOptions has always used subfolder_uid for the same thing.
This aligns keeper_create with both.

Collection version 1.5.0 is unpublished (PyPI and Ansible Galaxy both top out
at 1.4.0, and release PR 982 into master is still open), so folder_uid is not
a public interface yet and this rename breaks no released user.

Also fixes two defects found while making this change:
- create_record() now normalizes an empty subfolder_uid to None. The SDK sets
  payload.subFolderUid unconditionally and serializes the whole payload, so a
  playbook passing subfolder_uid: "" would otherwise send an empty value to
  the server.
- keeper_create now raises an explicit error if a playbook still sets the old
  folder_uid key. No plugin in this integration declares an argument_spec, so
  Ansible would otherwise silently drop the unknown key and create the record
  at the shared folder root instead of the intended subfolder.

Adds version_added: "1.5.0" to the option, matching the point release it
actually ships in; the option previously had none.

This surfaced while porting external contribution PR #1170 (Geoffroy
RABOUIN), which adds this same subfolder capability under the name
subfolder_uid. The capability already existed under a different name, so
there was nothing new to port; this commit adopts the contributor's
parameter name instead.

Co-authored-by: RABOUIN Geoffroy <grabouin@sigma.fr>

@stas-schaller stas-schaller left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great stuff!

@stas-schaller
stas-schaller merged commit 0bb9441 into release/integration/ansible/v1.5.0 Sep 21, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants