Bläddra i källkod

Move ssh_auth_file key processing to before ssh_auth key to extend instead of overwrite functionality.

tags/v0.45.0
root 9 år sedan
förälder
incheckning
d416b6d839
1 ändrade filer med 11 tillägg och 12 borttagningar
  1. +11
    -12
      users/init.sls

+ 11
- 12
users/init.sls Visa fil

@@ -142,6 +142,17 @@ user_{{ name }}_public_key:
{% endfor %}
{% endif %}

{% if 'ssh_auth_file' in user %}
{{ home }}/.ssh/authorized_keys:
file.managed:
- user: {{ name }}
- group: {{ name }}
- mode: 600
- contents: |
{% for auth in user.ssh_auth_file -%}
{{ auth }}
{% endfor -%}
{% endif %}

{% if 'ssh_auth' in user %}
{% for auth in user['ssh_auth'] %}
@@ -167,18 +178,6 @@ ssh_auth_delete_{{ name }}_{{ loop.index0 }}:
{% endfor %}
{% endif %}

{% if 'ssh_auth_file' in user %}
{{ home }}/.ssh/authorized_keys:
file.managed:
- user: {{ name }}
- group: {{ name }}
- mode: 600
- contents: |
{% for auth in user.ssh_auth_file -%}
{{ auth }}
{% endfor -%}
{% endif %}

{% if 'sudouser' in user and user['sudouser'] %}

sudoer-{{ name }}:

Laddar…
Avbryt
Spara