mirror of
https://github.com/saltstack-formulas/openssh-formula.git
synced 2026-07-23 16:12:52 +02:00
feat(semantic-release): implement for this formula
* Close #165 * Move existing `.kitchen.yml` => `kitchen.vagrant.yml` * Semi-automated using https://github.com/myii/ssf-formula/pull/30 * Fix errors shown below: ```bash openssh-formula$ yamllint -s . ./pillar.example 49:3 error duplication of key "AllowUsers" in mapping (key-duplicates) 57:3 error duplication of key "DenyUsers" in mapping (key-duplicates) 63:3 error duplication of key "AllowGroups" in mapping (key-duplicates) 70:3 error duplication of key "DenyGroups" in mapping (key-duplicates) 79:24 warning truthy value should be one of [false, true] (truthy) 80:29 warning truthy value should be one of [false, true] (truthy) 118:4 warning missing starting space in comment (comments) 119:4 warning missing starting space in comment (comments) 119:89 error line too long (122 > 88 characters) (line-length) 120:4 warning missing starting space in comment (comments) 120:89 error line too long (144 > 88 characters) (line-length) 147:30 warning truthy value should be one of [false, true] (truthy) 148:21 warning truthy value should be one of [false, true] (truthy) 149:19 warning truthy value should be one of [false, true] (truthy) 150:32 warning truthy value should be one of [false, true] (truthy) 151:26 warning truthy value should be one of [false, true] (truthy) 152:31 warning truthy value should be one of [false, true] (truthy) 153:32 warning truthy value should be one of [false, true] (truthy) 154:29 warning truthy value should be one of [false, true] (truthy) 155:34 warning truthy value should be one of [false, true] (truthy) 175:8 warning missing starting space in comment (comments) 175:89 error line too long (152 > 88 characters) (line-length) 176:8 warning missing starting space in comment (comments) 176:89 error line too long (126 > 88 characters) (line-length) 177:8 warning missing starting space in comment (comments) 177:89 error line too long (148 > 88 characters) (line-length) 213:18 warning truthy value should be one of [false, true] (truthy) 219:18 warning truthy value should be one of [false, true] (truthy) 225:18 warning truthy value should be one of [false, true] (truthy) 241:22 warning truthy value should be one of [false, true] (truthy) 243:22 warning truthy value should be one of [false, true] (truthy) 244:20 warning truthy value should be one of [false, true] (truthy) 245:21 warning truthy value should be one of [false, true] (truthy) 254:24 warning truthy value should be one of [false, true] (truthy) 255:22 warning truthy value should be one of [false, true] (truthy) 256:23 warning truthy value should be one of [false, true] (truthy) 265:22 warning truthy value should be one of [false, true] (truthy) 268:21 warning truthy value should be one of [false, true] (truthy) 269:20 warning truthy value should be one of [false, true] (truthy) 270:21 warning truthy value should be one of [false, true] (truthy) 279:26 warning truthy value should be one of [false, true] (truthy) 280:24 warning truthy value should be one of [false, true] (truthy) 281:25 warning truthy value should be one of [false, true] (truthy) 307:16 warning truthy value should be one of [false, true] (truthy) 308:6 warning missing starting space in comment (comments) 314:6 warning missing starting space in comment (comments) 316:24 warning truthy value should be one of [false, true] (truthy) 339:89 error line too long (546 > 88 characters) (line-length) 340:89 error line too long (546 > 88 characters) (line-length) 341:89 error line too long (546 > 88 characters) (line-length) 342:89 error line too long (546 > 88 characters) (line-length) 344:4 warning missing starting space in comment (comments) 345:4 warning missing starting space in comment (comments) 357:19 warning truthy value should be one of [false, true] (truthy) ./openssh/osfamilymap.yaml 1:1 warning missing document start "---" (document-start) ./openssh/osfingermap.yaml 1:1 warning missing document start "---" (document-start) ./openssh/osmap.yaml 1:1 warning missing document start "---" (document-start) ./openssh/defaults.yaml 1:1 warning missing document start "---" (document-start) 3:18 warning truthy value should be one of [false, true] (truthy) 6:34 warning too few spaces before comment (comments) 10:25 warning truthy value should be one of [false, true] (truthy) 12:32 warning too few spaces before comment (comments) 16:24 warning truthy value should be one of [false, true] (truthy) 18:24 warning too few spaces before comment (comments) 20:42 warning too few spaces before comment (comments) 27:6 warning missing starting space in comment (comments) ```
This commit is contained in:
+55
-46
@@ -1,3 +1,6 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# vim: ft=yaml
|
||||
---
|
||||
sshd_config:
|
||||
# This keyword is totally optional
|
||||
ConfigBanner: |
|
||||
@@ -41,7 +44,7 @@ sshd_config:
|
||||
UsePAM: 'yes'
|
||||
UseDNS: 'yes'
|
||||
# set as string
|
||||
AllowUsers: 'vader@10.0.0.1 maul@evil.com sidious luke'
|
||||
# AllowUsers: 'vader@10.0.0.1 maul@evil.com sidious luke'
|
||||
# or set as list
|
||||
AllowUsers:
|
||||
- vader@10.0.0.1
|
||||
@@ -49,20 +52,20 @@ sshd_config:
|
||||
- sidious
|
||||
- luke
|
||||
# set as string
|
||||
DenyUsers: 'yoda chewbaca@112.10.21.1'
|
||||
# DenyUsers: 'yoda chewbaca@112.10.21.1'
|
||||
# or set as list
|
||||
DenyUsers:
|
||||
- yoda
|
||||
- chewbaca@112.10.21.1
|
||||
# set as string
|
||||
AllowGroups: 'wheel staff imperial'
|
||||
# AllowGroups: 'wheel staff imperial'
|
||||
# or set as list
|
||||
AllowGroups:
|
||||
- wheel
|
||||
- staff
|
||||
- imperial
|
||||
# set as string
|
||||
DenyGroups: 'rebel'
|
||||
# DenyGroups: 'rebel'
|
||||
# or set as list
|
||||
DenyGroups:
|
||||
- rebel
|
||||
@@ -73,8 +76,8 @@ sshd_config:
|
||||
Group: sftpusers
|
||||
options:
|
||||
ChrootDirectory: /sftp-chroot/%u
|
||||
X11Forwarding: no
|
||||
AllowTcpForwarding: no
|
||||
X11Forwarding: 'no'
|
||||
AllowTcpForwarding: 'no'
|
||||
ForceCommand: internal-sftp
|
||||
# Supports complex compound matches in Match criteria. For example, be able
|
||||
# to match against multiple Users for a given Match, or be able to match
|
||||
@@ -108,13 +111,15 @@ sshd_config:
|
||||
options:
|
||||
ChrootDirectory: /ex/%u
|
||||
|
||||
# yamllint disable rule:line-length
|
||||
# Check `man sshd_config` for supported KexAlgorithms, Ciphers and MACs first.
|
||||
# You can specify KexAlgorithms, Ciphers and MACs as both key or a list.
|
||||
# The configuration given in the example below is based on:
|
||||
# https://stribika.github.io/2015/01/04/secure-secure-shell.html
|
||||
#KexAlgorithms: 'curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256'
|
||||
#Ciphers: 'chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr'
|
||||
#MACs: 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com'
|
||||
# KexAlgorithms: 'curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256'
|
||||
# Ciphers: 'chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr'
|
||||
# MACs: 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com'
|
||||
# yamllint enable rule:line-length
|
||||
KexAlgorithms:
|
||||
- 'curve25519-sha256@libssh.org'
|
||||
- 'diffie-hellman-group-exchange-sha256'
|
||||
@@ -141,15 +146,15 @@ sshd_config:
|
||||
ssh_config:
|
||||
Hosts:
|
||||
'*':
|
||||
StrictHostKeyChecking: no
|
||||
ForwardAgent: no
|
||||
ForwardX11: no
|
||||
RhostsRSAAuthentication: no
|
||||
RSAAuthentication: yes
|
||||
PasswordAuthentication: yes
|
||||
HostbasedAuthentication: no
|
||||
GSSAPIAuthentication: no
|
||||
GSSAPIDelegateCredentials: no
|
||||
StrictHostKeyChecking: 'no'
|
||||
ForwardAgent: 'no'
|
||||
ForwardX11: 'no'
|
||||
RhostsRSAAuthentication: 'no'
|
||||
RSAAuthentication: 'yes'
|
||||
PasswordAuthentication: 'yes'
|
||||
HostbasedAuthentication: 'no'
|
||||
GSSAPIAuthentication: 'no'
|
||||
GSSAPIDelegateCredentials: 'no'
|
||||
BatchMode: 'yes'
|
||||
CheckHostIP: 'yes'
|
||||
AddressFamily: 'any'
|
||||
@@ -162,6 +167,7 @@ ssh_config:
|
||||
TunnelDevice: 'any:any'
|
||||
PermitLocalCommand: 'no'
|
||||
VisualHostKey: 'no'
|
||||
# yamllint disable rule:line-length
|
||||
# Check `man ssh_config` for supported KexAlgorithms, Ciphers and MACs first.
|
||||
# WARNING! Please make sure you understand the implications of the below
|
||||
# settings. The examples provided below might break your connection to older /
|
||||
@@ -169,9 +175,10 @@ ssh_config:
|
||||
# The configuration given in the example below is based on:
|
||||
# https://stribika.github.io/2015/01/04/secure-secure-shell.html
|
||||
# You can specify KexAlgorithms, Ciphers and MACs as both key or a list.
|
||||
#KexAlgorithms: 'curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1'
|
||||
#Ciphers: 'chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr'
|
||||
#MACs: 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com'
|
||||
# KexAlgorithms: 'curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1'
|
||||
# Ciphers: 'chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr'
|
||||
# MACs: 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com'
|
||||
# yamllint enable rule:line-length
|
||||
KexAlgorithms:
|
||||
- 'curve25519-sha256@libssh.org'
|
||||
- 'diffie-hellman-group-exchange-sha256'
|
||||
@@ -207,19 +214,19 @@ openssh:
|
||||
auth:
|
||||
joe-valid-ssh-key-desktop:
|
||||
- user: joe
|
||||
present: True
|
||||
present: true
|
||||
enc: ssh-rsa
|
||||
comment: main key - desktop
|
||||
source: salt://ssh_keys/joe.desktop.pub
|
||||
joe-valid-ssh-key-notebook:
|
||||
- user: joe
|
||||
present: True
|
||||
present: true
|
||||
enc: ssh-rsa
|
||||
comment: main key - notebook
|
||||
source: salt://ssh_keys/joe.netbook.pub
|
||||
joe-non-valid-ssh-key:
|
||||
- user: joe
|
||||
present: False
|
||||
present: false
|
||||
enc: ssh-rsa
|
||||
comment: obsolete key - removed
|
||||
source: salt://ssh_keys/joe.no-valid.pub
|
||||
@@ -235,11 +242,11 @@ openssh:
|
||||
joe.netbook:
|
||||
options: [] # see salt.states.ssh_auth.present
|
||||
joe.no-valid:
|
||||
present: False
|
||||
present: false
|
||||
|
||||
generate_dsa_keys: False
|
||||
absent_dsa_keys: False
|
||||
provide_dsa_keys: False
|
||||
generate_dsa_keys: false
|
||||
absent_dsa_keys: false
|
||||
provide_dsa_keys: false
|
||||
dsa:
|
||||
private_key: |
|
||||
-----BEGIN DSA PRIVATE KEY-----
|
||||
@@ -248,9 +255,9 @@ openssh:
|
||||
public_key: |
|
||||
ssh-dss NOT_DEFINED
|
||||
|
||||
generate_ecdsa_keys: False
|
||||
absent_ecdsa_keys: False
|
||||
provide_ecdsa_keys: False
|
||||
generate_ecdsa_keys: false
|
||||
absent_ecdsa_keys: false
|
||||
provide_ecdsa_keys: false
|
||||
ecdsa:
|
||||
private_key: |
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
@@ -259,12 +266,12 @@ openssh:
|
||||
public_key: |
|
||||
ecdsa-sha2-nistp256 NOT_DEFINED
|
||||
|
||||
generate_rsa_keys: False
|
||||
generate_rsa_keys: false
|
||||
generate_rsa_size: 4096
|
||||
# Will remove the old key if it is to short and generate a new one.
|
||||
enforce_rsa_size: False
|
||||
absent_rsa_keys: False
|
||||
provide_rsa_keys: False
|
||||
enforce_rsa_size: false
|
||||
absent_rsa_keys: false
|
||||
provide_rsa_keys: false
|
||||
rsa:
|
||||
private_key: |
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
@@ -273,9 +280,9 @@ openssh:
|
||||
public_key: |
|
||||
ssh-rsa NOT_DEFINED
|
||||
|
||||
generate_ed25519_keys: False
|
||||
absent_ed25519_keys: False
|
||||
provide_ed25519_keys: False
|
||||
generate_ed25519_keys: false
|
||||
absent_ed25519_keys: false
|
||||
provide_ed25519_keys: false
|
||||
ed25519:
|
||||
private_key: |
|
||||
-----BEGIN OPENSSH PRIVATE KEY-----
|
||||
@@ -301,16 +308,16 @@ openssh:
|
||||
# Includes short hostnames derived from the FQDN
|
||||
# (host.example.test -> host)
|
||||
# (Deactivated by default, because there can be collisions!)
|
||||
hostnames: False
|
||||
#hostnames:
|
||||
hostnames: false
|
||||
# hostnames:
|
||||
# Restrict wich hosts you want to use via their hostname
|
||||
# (i.e. ssh user@host instead of ssh user@host.example.com)
|
||||
# target: '*' # Defaults to "*.{{ grains['domain']}}"
|
||||
# tgt_type: 'glob'
|
||||
# To activate the defaults you can just set an empty dict.
|
||||
#hostnames: {}
|
||||
# Include localhost, 127.0.0.1 and ::1 (default: False)
|
||||
include_localhost: False
|
||||
# hostnames: {}
|
||||
# Include localhost, 127.0.0.1 and ::1 (default: false)
|
||||
include_localhost: false
|
||||
# Host keys fetched via salt-ssh
|
||||
salt_ssh:
|
||||
# The salt-ssh user
|
||||
@@ -330,6 +337,7 @@ openssh:
|
||||
github.com: 'ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGm[...]'
|
||||
gitlab.com: 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCsj2bN[...]'
|
||||
|
||||
# yamllint disable rule:line-length
|
||||
# specify DH parameters (see /etc/ssh/moduli)
|
||||
moduli: |
|
||||
# Time Type Tests Tries Size Generator Modulus
|
||||
@@ -337,9 +345,10 @@ openssh:
|
||||
20120821045830 2 6 100 2047 2 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C6042936814C2FFB
|
||||
20120821050046 2 6 100 2047 2 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C60429368214FC53
|
||||
20120821050054 2 6 100 2047 5 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C60429368218E83F
|
||||
# yamllint enable rule:line-length
|
||||
# ALTERNATIVELY, specify the location of the moduli file. Examples:
|
||||
#moduli_source: http://some.server.somewhere/salt/moduli
|
||||
#moduli_source: salt://files/ssh/moduli
|
||||
# moduli_source: http://some.server.somewhere/salt/moduli
|
||||
# moduli_source: salt://files/ssh/moduli
|
||||
# If moduli is specified, moduli_source will be ignored.
|
||||
# Also, a proper hash file *must* be included in the same path. E.g.:
|
||||
# http://some.server.somewhere/salt/moduli.hash
|
||||
@@ -351,7 +360,7 @@ mine_functions:
|
||||
public_ssh_host_keys:
|
||||
mine_function: cmd.run
|
||||
cmd: cat /etc/ssh/ssh_host_*_key.pub
|
||||
python_shell: True
|
||||
python_shell: true
|
||||
public_ssh_hostname:
|
||||
mine_function: grains.get
|
||||
key: id
|
||||
|
||||
Reference in New Issue
Block a user