mirror of
https://github.com/saltstack-formulas/openssh-formula.git
synced 2026-10-02 18:49:05 +02:00
Use iteritems() instead of items().
Signed-off-by: René Jochum <rene@jochums.at>
This commit is contained in:
commit
c27f9a81f3
9 files changed
+241
-46
No files matched your search
@@ -17,10 +17,24 @@ sshd_config:
|
||||
{% if salt['pillar.get']('openssh:generate_' ~ keyType ~ '_keys', False) %}
|
||||
ssh_generate_host_{{ keyType }}_key:
|
||||
cmd.run:
|
||||
{%- if salt['pillar.get']('openssh:generate_' ~ keyType ~ '_size', False) %}
|
||||
{%- set keySize = salt['pillar.get']('openssh:generate_' ~ keyType ~ '_size', 4096) %}
|
||||
- name: ssh-keygen -t {{ keyType }} -b {{ keySize }} -N '' -f /etc/ssh/ssh_host_{{ keyType }}_key
|
||||
{%- else %}
|
||||
- name: ssh-keygen -t {{ keyType }} -N '' -f /etc/ssh/ssh_host_{{ keyType }}_key
|
||||
{%- endif %}
|
||||
- creates: /etc/ssh/ssh_host_{{ keyType }}_key
|
||||
- user: root
|
||||
|
||||
{% elif salt['pillar.get']('openssh:absent_' ~ keyType ~ '_keys', False) %}
|
||||
ssh_host_{{ keyType }}_key:
|
||||
file.absent:
|
||||
- name: /etc/ssh/ssh_host_{{ keyType }}_key
|
||||
|
||||
ssh_host_{{ keyType }}_key.pub:
|
||||
file.absent:
|
||||
- name: /etc/ssh/ssh_host_{{ keyType }}_key.pub
|
||||
|
||||
{% elif salt['pillar.get']('openssh:provide_' ~ keyType ~ '_keys', False) %}
|
||||
ssh_host_{{ keyType }}_key:
|
||||
file.managed:
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
openssh:
|
||||
sshd_config: /etc/ssh/sshd_config
|
||||
sshd_config_src: salt://openssh/files/sshd_config
|
||||
banner: /etc/ssh/banner
|
||||
banner_src: salt://openssh/files/banner
|
||||
ssh_known_hosts: /etc/ssh/ssh_known_hosts
|
||||
dig_pkg: dnsutils
|
||||
ssh_moduli: /etc/ssh/moduli
|
||||
@@ -0,0 +1,38 @@
|
||||
{#
|
||||
# vi:syntax=jinja
|
||||
#}
|
||||
|
||||
{%- set target = salt['pillar.get']('openssh:known_hosts:target', '*') -%}
|
||||
{%- set expr_form = salt['pillar.get']('openssh:known_hosts:expr_form', 'glob') -%}
|
||||
{%- set keys_function = salt['pillar.get']('openssh:known_hosts:mine_keys_function', 'public_ssh_host_keys') -%}
|
||||
{%- set hostname_function = salt['pillar.get']('openssh:known_hosts:mine_hostname_function', 'public_ssh_hostname') -%}
|
||||
{#- Lookup IP of all aliases so that when we have a matching IP, we inject the alias name
|
||||
in the SSH known_hosts entry -#}
|
||||
{%- set aliases = salt['pillar.get']('openssh:known_hosts:aliases', []) -%}
|
||||
{%- set aliases_ips = {} -%}
|
||||
{%- for alias in aliases -%}
|
||||
{%- for ip in salt['dig.A'](alias) + salt['dig.AAAA'](alias) -%}
|
||||
{%- do aliases_ips.setdefault(ip, []).append(alias) -%}
|
||||
{%- endfor -%}
|
||||
{%- endfor -%}
|
||||
{#- Loop over targetted minions -#}
|
||||
{%- set host_keys = salt['mine.get'](target, keys_function, expr_form=expr_form) -%}
|
||||
{%- set host_names = salt['mine.get'](target, hostname_function, expr_form=expr_form) -%}
|
||||
{%- for host, keys in host_keys|dictsort -%}
|
||||
{%- set ip4 = salt['dig.A'](host) -%}
|
||||
{%- set ip6 = salt['dig.AAAA'](host) -%}
|
||||
{%- set names = [host_names.get(host, host)] -%}
|
||||
{%- for ip in ip4 + ip6 -%}
|
||||
{%- do names.append(ip) -%}
|
||||
{%- for alias in aliases_ips.get(ip, []) -%}
|
||||
{%- if alias not in names -%}
|
||||
{%- do names.append(alias) -%}
|
||||
{%- endif -%}
|
||||
{%- endfor -%}
|
||||
{%- endfor -%}
|
||||
{%- for line in keys.split('\n') -%}
|
||||
{%- if line -%}
|
||||
{{ ','.join(names) }} {{ line }}
|
||||
{% endif -%}
|
||||
{%- endfor -%}
|
||||
{%- endfor -%}
|
||||
@@ -139,7 +139,7 @@
|
||||
|
||||
# Restricting Users and Hosts
|
||||
# example:
|
||||
# AllowUsers vader@10.0.0.1 maul@sproing.evil.com luke
|
||||
# AllowUsers vader@10.0.0.1 maul@sproing.evil.com luke
|
||||
# AllowGroups wheel staff
|
||||
#
|
||||
# Keep in mind that using AllowUsers or AllowGroups means that anyone
|
||||
@@ -156,6 +156,15 @@
|
||||
# AllowGroups
|
||||
{{ option('AllowGroups', '') }}
|
||||
|
||||
# Specifies the available KEX (Key Exchange) algorithms.
|
||||
{{ option('KexAlgorithms', 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1') }}
|
||||
|
||||
# Specifies the ciphers allowed for protocol version 2.
|
||||
{{ option('Ciphers', 'aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se') }}
|
||||
|
||||
# Specifies the available MAC (message authentication code) algorithms.
|
||||
{{ option('MACs', 'hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-sha2-256,hmac-sha2-256-96,hmac-sha2-512,hmac-sha2-512-96,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96') }}
|
||||
|
||||
{# Handling unknown in salt template options #}
|
||||
{%- for keyword in sshd_config.keys() %}
|
||||
{#- Matches have to be at the bottem and should be handled differently -#}
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
{% from "openssh/map.jinja" import openssh with context %}
|
||||
|
||||
ensure dig is available:
|
||||
pkg.installed:
|
||||
- name: {{ openssh.dig_pkg }}
|
||||
|
||||
manage ssh_known_hosts file:
|
||||
file.managed:
|
||||
- name: {{ openssh.ssh_known_hosts }}
|
||||
- source: salt://openssh/files/ssh_known_hosts
|
||||
- template: jinja
|
||||
- user: root
|
||||
- group: root
|
||||
- mode: 644
|
||||
- require:
|
||||
- pkg: ensure dig is available
|
||||
+50
-39
@@ -1,45 +1,56 @@
|
||||
{% set openssh = salt['grains.filter_by']({
|
||||
{## Start with defaults from defaults.yaml ##}
|
||||
{% import_yaml "openssh/defaults.yaml" as default_settings %}
|
||||
|
||||
{##
|
||||
Setup variable using grains['os_family'] based logic, only add key:values here
|
||||
that differ from whats in defaults.yaml
|
||||
##}
|
||||
{% set os_family_map = salt['grains.filter_by']({
|
||||
'Arch': {
|
||||
'server': 'openssh',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd',
|
||||
},
|
||||
'Debian': {
|
||||
'server': 'openssh-server',
|
||||
'client': 'openssh-client',
|
||||
'service': 'ssh',
|
||||
'sshd_config': '/etc/ssh/sshd_config',
|
||||
'sshd_config_src': 'salt://openssh/files/sshd_config',
|
||||
'banner': '/etc/ssh/banner',
|
||||
'banner_src': 'salt://openssh/files/banner',
|
||||
'server': 'openssh-server',
|
||||
'client': 'openssh-client',
|
||||
'service': 'ssh',
|
||||
},
|
||||
'FreeBSD': {
|
||||
'service': 'sshd',
|
||||
'dig_pkg': 'bind-tools',
|
||||
},
|
||||
'Gentoo': {
|
||||
'server': 'net-misc/openssh',
|
||||
'client': 'net-misc/openssh',
|
||||
'service': 'sshd',
|
||||
'dig_pkg': 'net-dns/bind-tools',
|
||||
},
|
||||
'RedHat': {
|
||||
'server': 'openssh-server',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd',
|
||||
'sshd_config': '/etc/ssh/sshd_config',
|
||||
'sshd_config_src': 'salt://openssh/files/sshd_config',
|
||||
'banner': '/etc/ssh/banner',
|
||||
'banner_src': 'salt://openssh/files/banner',
|
||||
'server': 'openssh-server',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd',
|
||||
'dig_pkg': 'bind-utils',
|
||||
},
|
||||
'Suse': {
|
||||
'server': 'openssh',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd',
|
||||
'sshd_config': '/etc/ssh/sshd_config',
|
||||
'sshd_config_src': 'salt://openssh/files/sshd_config',
|
||||
'banner': '/etc/ssh/banner',
|
||||
'banner_src': 'salt://openssh/files/banner',
|
||||
},
|
||||
'FreeBSD': {
|
||||
'service': 'sshd',
|
||||
'sshd_config': '/etc/ssh/sshd_config',
|
||||
'sshd_config_src': 'salt://openssh/files/sshd_config',
|
||||
'banner': '/etc/ssh/banner',
|
||||
'banner_src': 'salt://openssh/files/banner',
|
||||
'server': 'openssh',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd',
|
||||
'dig_pkg': 'bind-utils',
|
||||
},
|
||||
'Arch': {
|
||||
'server': 'openssh',
|
||||
'client': 'openssh',
|
||||
'service': 'sshd.socket',
|
||||
'sshd_config': '/etc/ssh/sshd_config',
|
||||
'sshd_config_src': 'salt://openssh/files/sshd_config',
|
||||
'banner': '/etc/ssh/banner',
|
||||
'banner_src': 'salt://openssh/files/banner',
|
||||
},
|
||||
}, merge=salt['pillar.get']('openssh:lookup')) %}
|
||||
}
|
||||
, grain="os_family"
|
||||
, merge=salt['pillar.get']('openssh:lookup'))
|
||||
%}
|
||||
|
||||
{## Merge the flavor_map to the default settings ##}
|
||||
{% do default_settings.openssh.update(os_family_map) %}
|
||||
|
||||
{## Merge in openssh:lookup pillar ##}
|
||||
{% set openssh = salt['pillar.get'](
|
||||
'openssh',
|
||||
default=default_settings.openssh,
|
||||
merge=True
|
||||
)
|
||||
%}
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
{% from "openssh/map.jinja" import openssh with context %}
|
||||
|
||||
{% if salt['pillar.get']('openssh:moduli', False) %}
|
||||
ssh_moduli:
|
||||
file.managed:
|
||||
- name: {{ openssh.ssh_moduli }}
|
||||
- contents_pillar: openssh:moduli
|
||||
{% endif %}
|
||||
Reference in new issue
Block a user