SSHD Service extensions
This change adds an `include` statement to bring in the extra functionality available from the existing puppet-ssh module in already available in RDO. By using puppet-ssh it provides a framework to allow the passing in of server options using just hiera values under ssh::server_options. For example, sshd_config banner can now be passed a server option, as well as all the new parameters outlined in the launchpad issue that the patch references for Closing. For this reason, the former augeas setting for `Banner /etc/issue` is now managed by the main puppet-ssh module instead. The change also allows population of MOTD text to `/etc/motd` as well as `issue.net`. $bannertext is refactored in accordance with patch [1] [1] https://review.openstack.org/#/c/442406/ Change-Id: Id329538fb7b623526f1d91d8a513cf3440c86a7c Closes-Bug: 1668543
This commit is contained in:
parent
d9916ce773
commit
b35bc80ac2
@ -48,3 +48,7 @@ mod 'systemd',
|
|||||||
mod 'opendaylight',
|
mod 'opendaylight',
|
||||||
:git => 'https://github.com/dfarrell07/puppet-opendaylight',
|
:git => 'https://github.com/dfarrell07/puppet-opendaylight',
|
||||||
:ref => 'master'
|
:ref => 'master'
|
||||||
|
|
||||||
|
mod 'ssh',
|
||||||
|
:git => 'https://github.com/saz/puppet-ssh',
|
||||||
|
:ref => 'v3.0.1'
|
||||||
|
@ -15,47 +15,45 @@
|
|||||||
#
|
#
|
||||||
# == Class: tripleo::profile::base::sshd
|
# == Class: tripleo::profile::base::sshd
|
||||||
#
|
#
|
||||||
# SSH profile for tripleo
|
# SSH composable service for TripleO
|
||||||
#
|
#
|
||||||
# === Parameters
|
# === Parameters
|
||||||
#
|
#
|
||||||
# [*bannertext*]
|
# [*bannertext*]
|
||||||
# The text used within SSH Banner
|
# The text used within /etc/issue and /etc/issue.net
|
||||||
# Defaults to hiera('BannerText')
|
# Defaults to hiera('BannerText')
|
||||||
#
|
#
|
||||||
|
# [*motd*]
|
||||||
|
# The text used within SSH Banner
|
||||||
|
# Defaults to hiera('MOTD')
|
||||||
|
#
|
||||||
class tripleo::profile::base::sshd (
|
class tripleo::profile::base::sshd (
|
||||||
$bannertext = hiera('BannerText', undef),
|
$bannertext = hiera('BannerText', undef),
|
||||||
|
$motd = hiera('MOTD', undef),
|
||||||
) {
|
) {
|
||||||
|
|
||||||
|
include ::ssh
|
||||||
|
|
||||||
if $bannertext {
|
if $bannertext {
|
||||||
$action = 'set'
|
$filelist = [ '/etc/issue', '/etc/issue.net', ]
|
||||||
} else {
|
file { $filelist:
|
||||||
$action = 'rm'
|
|
||||||
}
|
|
||||||
|
|
||||||
package {'openssh-server':
|
|
||||||
ensure => installed,
|
|
||||||
}
|
|
||||||
|
|
||||||
augeas { 'sshd_config_banner':
|
|
||||||
context => '/files/etc/ssh/sshd_config',
|
|
||||||
changes => [ "${action} Banner /etc/issue" ],
|
|
||||||
notify => Service['sshd']
|
|
||||||
}
|
|
||||||
|
|
||||||
file { '/etc/issue':
|
|
||||||
ensure => file,
|
ensure => file,
|
||||||
backup => false,
|
backup => false,
|
||||||
content => $bannertext,
|
content => $bannertext,
|
||||||
owner => 'root',
|
owner => 'root',
|
||||||
group => 'root',
|
group => 'root',
|
||||||
mode => '0600'
|
mode => '0644'
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
service { 'sshd':
|
if $motd {
|
||||||
ensure => 'running',
|
file { '/etc/motd':
|
||||||
enable => true,
|
ensure => file,
|
||||||
hasstatus => false,
|
backup => false,
|
||||||
require => Package['openssh-server'],
|
content => $motd,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644'
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -1,3 +1,5 @@
|
|||||||
---
|
---
|
||||||
features:
|
features:
|
||||||
- Added manifest and template to enable configuration of sshd_config
|
- Added /etc/issue & /etc/issue.net parameters
|
||||||
|
- Added MOTD banner parameters
|
||||||
|
- Added external module saz-ssh to allow management of sshd_config
|
||||||
|
@ -1,4 +1,4 @@
|
|||||||
# Copyright 2016 Red Hat, Inc.
|
# Copyright 2017 Red Hat, Inc.
|
||||||
# All Rights Reserved.
|
# All Rights Reserved.
|
||||||
#
|
#
|
||||||
# Licensed under the Apache License, Version 2.0 (the "License"); you may
|
# Licensed under the Apache License, Version 2.0 (the "License"); you may
|
||||||
@ -13,18 +13,64 @@
|
|||||||
# License for the specific language governing permissions and limitations
|
# License for the specific language governing permissions and limitations
|
||||||
# under the License.
|
# under the License.
|
||||||
#
|
#
|
||||||
|
# Unit tests for tripleo::profile::base::sshd
|
||||||
|
#
|
||||||
|
|
||||||
require 'spec_helper'
|
require 'spec_helper'
|
||||||
|
|
||||||
describe 'tripleo::profile::base::sshd' do
|
describe 'tripleo::profile::base::sshd' do
|
||||||
|
|
||||||
context 'with banner configured' do
|
shared_examples_for 'tripleo::profile::base::sshd' do
|
||||||
|
|
||||||
|
context 'it should do nothing' do
|
||||||
|
it do
|
||||||
|
is_expected.to contain_class('ssh')
|
||||||
|
is_expected.to_not contain_file('/etc/issue')
|
||||||
|
is_expected.to_not contain_file('/etc/issue.net')
|
||||||
|
is_expected.to_not contain_file('/etc/motd')
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
context 'with issue and issue.net configured' do
|
||||||
|
let(:params) {{ :bannertext => 'foo' }}
|
||||||
it do
|
it do
|
||||||
is_expected.to contain_file('/etc/issue').with({
|
is_expected.to contain_file('/etc/issue').with({
|
||||||
|
'content' => 'foo',
|
||||||
'owner' => 'root',
|
'owner' => 'root',
|
||||||
'group' => 'root',
|
'group' => 'root',
|
||||||
'mode' => '0600',
|
'mode' => '0644',
|
||||||
})
|
})
|
||||||
|
is_expected.to contain_file('/etc/issue.net').with({
|
||||||
|
'content' => 'foo',
|
||||||
|
'owner' => 'root',
|
||||||
|
'group' => 'root',
|
||||||
|
'mode' => '0644',
|
||||||
|
})
|
||||||
|
is_expected.to_not contain_file('/etc/motd')
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
context 'with motd configured' do
|
||||||
|
let(:params) {{ :motd => 'foo' }}
|
||||||
|
it do
|
||||||
|
is_expected.to contain_file('/etc/motd').with({
|
||||||
|
'content' => 'foo',
|
||||||
|
'owner' => 'root',
|
||||||
|
'group' => 'root',
|
||||||
|
'mode' => '0644',
|
||||||
|
})
|
||||||
|
is_expected.to_not contain_file('/etc/issue')
|
||||||
|
is_expected.to_not contain_file('/etc/issue.net')
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
on_supported_os.each do |os, facts|
|
||||||
|
context "on #{os}" do
|
||||||
|
let (:facts) {
|
||||||
|
facts
|
||||||
|
}
|
||||||
|
it_behaves_like 'tripleo::profile::base::sshd'
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
Loading…
x
Reference in New Issue
Block a user