 
    New in version 2.4.
| Parameter | Choices/Defaults | Comments | 
|---|---|---|
| certificate_name 
                    string
                                         | The X.509 certificate name attached to the APIC AAA user used for signature-based authentication. If a  private_keyfilename was provided, this defaults to theprivate_keybasename, without extension.If PEM-formatted content was provided for  private_key, this defaults to theusernamevalue.aliases: cert_name | |
| consumer_match 
                    string
                                         | 
 | The match criteria across consumers. The APIC defaults to  at_least_onewhen unset during creation. | 
| contract 
                    string
                                         | The name of the Contract. aliases: contract_name | |
| description 
                    string
                                         | Description for the contract subject. aliases: descr | |
| dscp 
                    string
                                         | 
 | The target DSCP. The APIC defaults to  unspecifiedwhen unset during creation.aliases: target | 
| host 
                    string
                     / required                     | IP Address or hostname of APIC resolvable by Ansible control host. aliases: hostname | |
| output_level 
                    string
                                         | 
 | Influence the output of this ACI module. normalmeans the standard output, incl.currentdictinfoadds informational output, incl.previous,proposedandsentdictsdebugadds debugging output, incl.filter_string,method,response,statusandurlinformation | 
| password 
                    string
                     / required                     | The password to use for authentication. This option is mutual exclusive with  private_key. Ifprivate_keyis provided too, it will be used instead. | |
| port 
                    integer
                                         | Port number to be used for REST connection. The default value depends on parameter  use_ssl. | |
| priority 
                    string
                                         | 
 | The QoS class. The APIC defaults to  unspecifiedwhen unset during creation. | 
| private_key 
                    string
                     / required                     | Either a PEM-formatted private key file or the private key content used for signature-based authentication. This value also influences the default  certificate_namethat is used.This option is mutual exclusive with  password. Ifpasswordis provided too, it will be ignored.aliases: cert_key | |
| provider_match 
                    string
                                         | 
 | The match criteria across providers. The APIC defaults to  at_least_onewhen unset during creation. | 
| reverse_filter 
                    boolean
                                         | 
 | Determines if the APIC should reverse the src and dst ports to allow the return traffic back, since ACI is stateless filter. The APIC defaults to  yeswhen unset during creation. | 
| state 
                    string
                                         | 
 | Use  presentorabsentfor adding or removing.Use  queryfor listing an object or multiple objects. | 
| subject 
                    string
                                         | The contract subject name. aliases: contract_subject, name, subject_name | |
| tenant 
                    string
                                         | The name of the tenant. aliases: tenant_name | |
| timeout 
                    integer
                                         | Default: 30 | The socket level timeout in seconds. | 
| use_proxy 
                    boolean
                                         | 
 | If  no, it will not use a proxy, even if one is defined in an environment variable on the target hosts. | 
| use_ssl 
                    boolean
                                         | 
 | If  no, an HTTP connection will be used instead of the default HTTPS connection. | 
| username 
                    string
                                         | Default: "admin" | The username to use for authentication. aliases: user | 
| validate_certs 
                    boolean
                                         | 
 | If  no, SSL certificates will not be validated.This should only set to  nowhen used on personally controlled sites using self-signed certificates. | 
Note
tenant and contract used must exist before using this module in your playbook. The aci_tenant and aci_contract modules can be used for this.See also
- name: Add a new contract subject
  aci_contract_subject:
    host: apic
    username: admin
    password: SomeSecretPassword
    tenant: production
    contract: web_to_db
    subject: default
    description: test
    reverse_filter: yes
    priority: level1
    dscp: unspecified
    state: present
  register: query_result
- name: Remove a contract subject
  aci_contract_subject:
    host: apic
    username: admin
    password: SomeSecretPassword
    tenant: production
    contract: web_to_db
    subject: default
    state: absent
  delegate_to: localhost
- name: Query a contract subject
  aci_contract_subject:
    host: apic
    username: admin
    password: SomeSecretPassword
    tenant: production
    contract: web_to_db
    subject: default
    state: query
  delegate_to: localhost
  register: query_result
- name: Query all contract subjects
  aci_contract_subject:
    host: apic
    username: admin
    password: SomeSecretPassword
    state: query
  delegate_to: localhost
  register: query_result
Common return values are documented here, the following are the fields unique to this module:
| Key | Returned | Description | 
|---|---|---|
| current list | success | The existing configuration from the APIC after the module has finished Sample: [{'fvTenant': {'attributes': {'dn': 'uni/tn-production', 'ownerKey': '', 'name': 'production', 'descr': 'Production environment', 'nameAlias': '', 'ownerTag': ''}}}] | 
| error dictionary | failure | The error information as returned from the APIC Sample: {'text': 'unknown managed object class foo', 'code': '122'} | 
| filter_string string | failure or debug | The filter string used for the request Sample: ?rsp-prop-include=config-only | 
| method string | failure or debug | The HTTP method used for the request to the APIC Sample: POST | 
| previous list | info | The original configuration from the APIC before the module has started Sample: [{'fvTenant': {'attributes': {'dn': 'uni/tn-production', 'ownerKey': '', 'name': 'production', 'descr': 'Production', 'nameAlias': '', 'ownerTag': ''}}}] | 
| proposed dictionary | info | The assembled configuration from the user-provided parameters Sample: {'fvTenant': {'attributes': {'name': 'production', 'descr': 'Production environment'}}} | 
| raw string | parse error | The raw output returned by the APIC REST API (xml or json) Sample: <?xml version="1.0" encoding="UTF-8"?><imdata totalCount="1"><error code="122" text="unknown managed object class foo"/></imdata> | 
| response string | failure or debug | The HTTP response from the APIC Sample: OK (30 bytes) | 
| sent list | info | The actual/minimal configuration pushed to the APIC Sample: {'fvTenant': {'attributes': {'descr': 'Production environment'}}} | 
| status integer | failure or debug | The HTTP status from the APIC Sample: 200 | 
| url string | failure or debug | The HTTP url used for the request to the APIC Sample: https://10.11.12.13/api/mo/uni/tn-production.json | 
Hint
If you notice any issues in this documentation you can edit this document to improve it.