Browse Source

Merge pull request #165 from jdsieci/unique_switch

Unique switch
tags/v0.45.0
N 6 years ago
parent
commit
5b67c5513a
No account linked to committer's email address
2 changed files with 13 additions and 0 deletions
  1. +5
    -0
      pillar.example
  2. +8
    -0
      users/init.sls

+ 5
- 0
pillar.example View File

manage_bashrc: False manage_bashrc: False
manage_profile: False manage_profile: False
expire: 16426 expire: 16426
# Disables user management except sudo rules.
# Useful for setting sudo rules for system accounts created by package instalation
sudoonly: False
sudouser: True sudouser: True
# sudo_rules doesn't need the username as a prefix for the rule # sudo_rules doesn't need the username as a prefix for the rule
# this is added automatically by the formula. # this is added automatically by the formula.
33333333 33333333
44444444 44444444
55555555 55555555
# unique: True allows user to have non unique uid
unique: False
uid: 1001 uid: 1001


user_files: user_files:

+ 8
- 0
users/init.sls View File

{%- if user == None -%} {%- if user == None -%}
{%- set user = {} -%} {%- set user = {} -%}
{%- endif -%} {%- endif -%}
{%- if 'sudoonly' in user and user['sudoonly'] %}
{%- set _dummy=user.update({'sudouser': True}) %}
{%- endif %}
{%- if 'sudouser' in user and user['sudouser'] %} {%- if 'sudouser' in user and user['sudouser'] %}
{%- do used_sudo.append(1) %} {%- do used_sudo.append(1) %}
{%- endif %} {%- endif %}
{%- set user_group = name -%} {%- set user_group = name -%}
{%- endif %} {%- endif %}


{%- if not ( 'sudoonly' in user and user['sudoonly'] ) %}
{% for group in user.get('groups', []) %} {% for group in user.get('groups', []) %}
users_{{ name }}_{{ group }}_group: users_{{ name }}_{{ group }}_group:
group.present: group.present:
{% if not user.get('createhome', True) %} {% if not user.get('createhome', True) %}
- createhome: False - createhome: False
{% endif %} {% endif %}
{% if not user.get('unique', True) %}
- unique: False
{% endif %}
{% if 'expire' in user -%} {% if 'expire' in user -%}
{% if grains['kernel'].endswith('BSD') and {% if grains['kernel'].endswith('BSD') and
user['expire'] < 157766400 %} user['expire'] < 157766400 %}
- name: {{ host }} - name: {{ host }}
{% endfor %} {% endfor %}
{% endif %} {% endif %}
{% endif %}


{% set sudoers_d_filename = name|replace('.','_') %} {% set sudoers_d_filename = name|replace('.','_') %}
{% if 'sudouser' in user and user['sudouser'] %} {% if 'sudouser' in user and user['sudouser'] %}

Loading…
Cancel
Save