This commit is contained in:
mwiegand 2021-06-25 17:54:39 +02:00
parent 1abc99b6f8
commit 1030fe95e0
4 changed files with 55 additions and 39 deletions

View file

@ -1,35 +1,29 @@
from os.path import join, exists for group, config in node.metadata.get('groups', {}).items():
groups[group] = config
for group, attrs in node.metadata.get('groups', {}).items(): for name, config in node.metadata.get('users').items():
groups[group] = attrs users[name] = {
k:v for k,v in config.items() if k in [
for username, attrs in node.metadata['users'].items(): "full_name", "gid", "groups", "home", "password_hash", "shell", "uid",
home = attrs.get('home', '/home/{}'.format(username)) ]
user = users.setdefault(username, {})
user['home'] = home
user['shell'] = attrs.get('shell', '/bin/bash')
if 'password' in attrs:
user['password'] = attrs['password']
else:
user['password_hash'] = 'x' if node.use_shadow_passwords else '*'
if 'groups' in attrs:
user['groups'] = attrs['groups']
directories[home] = {
'owner': username,
'mode': attrs.get('home-mode', '0700'),
} }
if 'ssh_pubkey' in attrs: directories[config['home']] = {
files[home + '/.ssh/authorized_keys'] = { 'owner': name,
'content': '\n'.join(sorted(attrs['ssh_pubkey'])) + '\n', }
'owner': username,
'mode': '0600',
}
elif not attrs.get('do_not_remove_authorized_keys_from_home', False): files[f"{config['home']}/.ssh/id_{config['keytype']}"] = {
files[home + '/.ssh/authorized_keys'] = {'delete': True} 'content': config['privkey'],
'owner': name,
'mode': '0600',
}
files[f"{config['home']}/.ssh/id_{config['keytype']}.pub"] = {
'content': config['pubkey'],
'owner': name,
'mode': '0600',
}
files[config['home'] + '/.ssh/authorized_keys'] = {
'content': '\n'.join(sorted(config['authorized_keys'])),
'owner': name,
'mode': '0600',
}

View file

@ -13,18 +13,30 @@ defaults = {
@metadata_reactor.provides( @metadata_reactor.provides(
'users', 'users',
) )
def users(metadata): def user(metadata):
users = {} users = {}
for name in metadata.get('users'): for name, config in metadata.get('users').items():
privkey, pubkey = repo.libs.ssh.generate_ad25519_key_pair(
b64decode(str(repo.vault.random_bytes_as_base64_for(metadata.get('id'), length=32)))
)
users[name] = { users[name] = {
'home': f'/home/{name}', 'authorized_keys': []
'privkey': privkey,
'pubkey': pubkey,
} }
if not 'home' in config:
users[name]['home'] = f'/home/{name}'
if not 'shell' in config:
users[name]['shell'] = '/bin/bash'
if not 'password_hash' in config:
users[name]['password_hash'] = 'x' if node.use_shadow_passwords else '*'
if not 'privkey' in users[name]:
privkey, pubkey = repo.libs.ssh.generate_ad25519_key_pair(
b64decode(str(repo.vault.random_bytes_as_base64_for(metadata.get('id'), length=32)))
)
users[name]['keytype'] = 'ed25519'
users[name]['privkey'] = privkey
users[name]['pubkey'] = pubkey + f' {name}@{node.name}'
return { return {
'users': users, 'users': users,

View file

@ -8,5 +8,12 @@
'server': 'backups.sublimity.de', 'server': 'backups.sublimity.de',
}, },
'dns': {}, 'dns': {},
'users': {
'root': {
'authorized_keys': [
'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEU1l2ijW3ZqzFGZcdWg2ESgTGehdNfBTfafxsjWvWdS mwiegand@macbook',
],
},
},
} }
} }

View file

@ -78,6 +78,9 @@
'version': '1.4.11', 'version': '1.4.11',
'installer': True, 'installer': True,
}, },
'users': {
'test': {},
},
'vm': { 'vm': {
'cpu': 2, 'cpu': 2,
}, },