map.jinja: replace defaults.merge with grains.filter_by

This commit is contained in:
Alexander Weidinger 2019-02-12 19:11:46 +01:00
parent 0c6a353969
commit 29b89f0fb9
2 changed files with 37 additions and 39 deletions

View File

@ -1,28 +1,29 @@
openssh: default:
sshd_enable: True openssh:
sshd_binary: /usr/sbin/sshd sshd_enable: True
sshd_config: /etc/ssh/sshd_config sshd_binary: /usr/sbin/sshd
sshd_config_src: salt://openssh/files/sshd_config sshd_config: /etc/ssh/sshd_config
sshd_config_user: root sshd_config_src: salt://openssh/files/sshd_config
sshd_config_group: root sshd_config_user: root
sshd_config_mode: '644' sshd_config_group: root
sshd_config_backup: True sshd_config_mode: '644'
ssh_config: /etc/ssh/ssh_config sshd_config_backup: True
ssh_config_src: salt://openssh/files/ssh_config ssh_config: /etc/ssh/ssh_config
ssh_config_user: root ssh_config_src: salt://openssh/files/ssh_config
ssh_config_group: root ssh_config_user: root
ssh_config_mode: '644' ssh_config_group: root
ssh_config_backup: True ssh_config_mode: '644'
banner: /etc/ssh/banner ssh_config_backup: True
banner_src: salt://openssh/files/banner banner: /etc/ssh/banner
ssh_known_hosts: /etc/ssh/ssh_known_hosts banner_src: salt://openssh/files/banner
dig_pkg: dnsutils ssh_known_hosts: /etc/ssh/ssh_known_hosts
ssh_moduli: /etc/ssh/moduli dig_pkg: dnsutils
root_group: root ssh_moduli: /etc/ssh/moduli
# Prevent merge of array; always override values root_group: root
host_key_algos: ecdsa,ed25519,rsa # Prevent merge of array; always override values
# To manage/remove DSA: host_key_algos: ecdsa,ed25519,rsa
#host_key_algos: dsa,ecdsa,ed25519,rsa # To manage/remove DSA:
#host_key_algos: dsa,ecdsa,ed25519,rsa
sshd_config: {} sshd_config: {}
ssh_config: {} ssh_config: {}

View File

@ -2,22 +2,19 @@
# vim: ft=jinja # vim: ft=jinja
{## Start imports as ##} {## Start imports as ##}
{% import_yaml 'openssh/defaults.yaml' as defaults %} {% import_yaml 'openssh/defaults.yaml' as default_settings %}
{% import_yaml 'openssh/osfamilymap.yaml' as osfamilymap %} {% import_yaml 'openssh/osfamilymap.yaml' as osfamilymap %}
{% import_yaml 'openssh/osmap.yaml' as osmap %} {% import_yaml 'openssh/osmap.yaml' as osmap %}
{% import_yaml 'openssh/osfingermap.yaml' as osfingermap %} {% import_yaml 'openssh/osfingermap.yaml' as osfingermap %}
{## merge the osfamilymap ##} {% set defaults = salt['grains.filter_by'](default_settings,
{% set osfamily = salt['grains.filter_by'](osfamilymap, grain='os_family') or {} %} default='default',
{% do salt['defaults.merge'](defaults, osfamily) %} merge=salt['grains.filter_by'](osfamilymap, grain='os_family',
merge=salt['grains.filter_by'](osmap, grain='os',
{## merge the osmap ##} merge=salt['grains.filter_by'](osfingermap, grain='osfinger')
{% set os = salt['grains.filter_by'](osmap, grain='os') or {} %} )
{% do salt['defaults.merge'](defaults, os) %} )
) %}
{## merge the osfingermap ##}
{% set osfinger = salt['grains.filter_by'](osfingermap, grain='osfinger') or {} %}
{% do salt['defaults.merge'](defaults, osfinger) %}
{## merge the openssh pillar ##} {## merge the openssh pillar ##}
{% set openssh = salt['pillar.get']('openssh', default=defaults['openssh'], merge=True) %} {% set openssh = salt['pillar.get']('openssh', default=defaults['openssh'], merge=True) %}