浏览代码

Add 'ssh_auth_file' pillar key to generate an authorized_keys file from given ssh public keys.

lookup-fix-3
root 9 年前
父节点
当前提交
fdc2fc2dfc
共有 2 个文件被更改,包括 16 次插入0 次删除
  1. +4
    -0
      pillar.example
  2. +12
    -0
      users/init.sls

+ 4
- 0
pillar.example 查看文件

@@ -28,6 +28,10 @@ users:
- PUBLICKEY
ssh_auth.absent:
- PUBLICKEY_TO_BE_REMOVED
# Generates an authorized_keys file for the user
# with the given keys
ssh_auth_file:
- PUBLICKEY
google_auth:
ssh: |
SOMEGAUTHHASHVAL

+ 12
- 0
users/init.sls 查看文件

@@ -167,6 +167,18 @@ ssh_auth_delete_{{ name }}_{{ loop.index0 }}:
{% endfor %}
{% endif %}

{% if 'ssh_auth_file' in user %}
{{ home }}/.ssh/authorized_keys:
file.managed:
- user: {{ name }}
- group: {{ name }}
- mode: 600
- contents: |
{% for auth in user.ssh_auth_file -%}
{{ auth }}
{% endfor -%}
{% endif %}

{% if 'sudouser' in user and user['sudouser'] %}

sudoer-{{ name }}:

正在加载...
取消
保存