add support for multiple private and public keys

This commit is contained in:
Daniel Kraemer 2016-10-04 20:53:01 +02:00
parent 0c364461c7
commit 34328aff1c

View File

@ -170,35 +170,44 @@ user_keydir_{{ name }}:
{% endif %} {% endif %}
{% if 'ssh_keys' in user %} {% if 'ssh_keys' in user %}
{% set key_type = 'id_' + user.get('ssh_key_type', 'rsa') %} {% for _key in user.ssh_keys.keys() %}
users_user_{{ name }}_private_key: {% if _key == 'privkey' %}
{% set key_name = 'id_' + user.get('ssh_key_type', 'rsa') %}
{% elif _key == 'pubkey' %}
{% set key_name = 'id_' + user.get('ssh_key_type', 'rsa') + '.pub' %}
{% else %}
{% set key_name = _key %}
{% endif %}
users_{{ name }}_{{ key_name }}_private_key:
file.managed: file.managed:
- name: {{ home }}/.ssh/{{ key_type }} - name: {{ home }}/.ssh/{{ key_name }}
- user: {{ name }} - user: {{ name }}
- group: {{ user_group }} - group: {{ user_group }}
- mode: 600 - mode: 600
- show_diff: False - show_diff: False
- contents_pillar: users:{{ name }}:ssh_keys:privkey - contents_pillar: users:{{ name }}:ssh_keys:{{ _key }}
- require: - require:
- user: users_{{ name }}_user - user: users_{{ name }}_user
{% for group in user.get('groups', []) %} {% for group in user.get('groups', []) %}
- group: users_{{ name }}_{{ group }}_group - group: users_{{ name }}_{{ group }}_group
{% endfor %} {% endfor %}
users_user_{{ name }}_public_key: users_{{ name }}_{{ key_name }}_public_key:
file.managed: file.managed:
- name: {{ home }}/.ssh/{{ key_type }}.pub - name: {{ home }}/.ssh/{{ key_name }}
- user: {{ name }} - user: {{ name }}
- group: {{ user_group }} - group: {{ user_group }}
- mode: 644 - mode: 644
- show_diff: False - show_diff: False
- contents_pillar: users:{{ name }}:ssh_keys:pubkey - contents_pillar: users:{{ name }}:ssh_keys:{{ _key }}
- require: - require:
- user: users_{{ name }}_user - user: users_{{ name }}_user
{% for group in user.get('groups', []) %} {% for group in user.get('groups', []) %}
- group: users_{{ name }}_{{ group }}_group - group: users_{{ name }}_{{ group }}_group
{% endfor %} {% endfor %}
{% endfor %}
{% endif %} {% endif %}
{% if 'ssh_auth_file' in user or 'ssh_auth_pillar' in user %} {% if 'ssh_auth_file' in user or 'ssh_auth_pillar' in user %}
users_authorized_keys_{{ name }}: users_authorized_keys_{{ name }}:
file.managed: file.managed: