|
Packit |
bc9a3a |
# Copyright (C) 2009-2010 Canonical Ltd.
|
|
Packit |
bc9a3a |
# Copyright (C) 2012, 2013 Hewlett-Packard Development Company, L.P.
|
|
Packit |
bc9a3a |
#
|
|
Packit |
bc9a3a |
# Author: Scott Moser <scott.moser@canonical.com>
|
|
Packit |
bc9a3a |
# Author: Juerg Haefliger <juerg.haefliger@hp.com>
|
|
Packit |
bc9a3a |
#
|
|
Packit |
bc9a3a |
# This file is part of cloud-init. See LICENSE file for license information.
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
"""
|
|
Packit |
bc9a3a |
SSH Import Id
|
|
Packit |
bc9a3a |
-------------
|
|
Packit |
bc9a3a |
**Summary:** import ssh id
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
This module imports ssh keys from either a public keyserver, usually launchpad
|
|
Packit |
bc9a3a |
or github using ``ssh-import-id``. Keys are referenced by the username they are
|
|
Packit |
bc9a3a |
associated with on the keyserver. The keyserver can be specified by prepending
|
|
Packit |
bc9a3a |
either ``lp:`` for launchpad or ``gh:`` for github to the username.
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
**Internal name:** ``cc_ssh_import_id``
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
**Module frequency:** per instance
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
**Supported distros:** ubuntu, debian
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
**Config keys**::
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
ssh_import_id:
|
|
Packit |
bc9a3a |
- user
|
|
Packit |
bc9a3a |
- gh:user
|
|
Packit |
bc9a3a |
- lp:user
|
|
Packit |
bc9a3a |
"""
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
from cloudinit.distros import ug_util
|
|
Packit |
bc9a3a |
from cloudinit import util
|
|
Packit |
bc9a3a |
import pwd
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
# https://launchpad.net/ssh-import-id
|
|
Packit |
bc9a3a |
distros = ['ubuntu', 'debian']
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
def handle(_name, cfg, cloud, log, args):
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
# import for "user: XXXXX"
|
|
Packit |
bc9a3a |
if len(args) != 0:
|
|
Packit |
bc9a3a |
user = args[0]
|
|
Packit |
bc9a3a |
ids = []
|
|
Packit |
bc9a3a |
if len(args) > 1:
|
|
Packit |
bc9a3a |
ids = args[1:]
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
import_ssh_ids(ids, user, log)
|
|
Packit |
bc9a3a |
return
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
# import for cloudinit created users
|
|
Packit |
bc9a3a |
(users, _groups) = ug_util.normalize_users_groups(cfg, cloud.distro)
|
|
Packit |
bc9a3a |
elist = []
|
|
Packit |
bc9a3a |
for (user, user_cfg) in users.items():
|
|
Packit |
bc9a3a |
import_ids = []
|
|
Packit |
bc9a3a |
if user_cfg['default']:
|
|
Packit |
bc9a3a |
import_ids = util.get_cfg_option_list(cfg, "ssh_import_id", [])
|
|
Packit |
bc9a3a |
else:
|
|
Packit |
bc9a3a |
try:
|
|
Packit |
bc9a3a |
import_ids = user_cfg['ssh_import_id']
|
|
Packit |
bc9a3a |
except Exception:
|
|
Packit |
bc9a3a |
log.debug("User %s is not configured for ssh_import_id", user)
|
|
Packit |
bc9a3a |
continue
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
try:
|
|
Packit |
bc9a3a |
import_ids = util.uniq_merge(import_ids)
|
|
Packit |
bc9a3a |
import_ids = [str(i) for i in import_ids]
|
|
Packit |
bc9a3a |
except Exception:
|
|
Packit |
bc9a3a |
log.debug("User %s is not correctly configured for ssh_import_id",
|
|
Packit |
bc9a3a |
user)
|
|
Packit |
bc9a3a |
continue
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
if not len(import_ids):
|
|
Packit |
bc9a3a |
continue
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
try:
|
|
Packit |
bc9a3a |
import_ssh_ids(import_ids, user, log)
|
|
Packit |
bc9a3a |
except Exception as exc:
|
|
Packit |
bc9a3a |
util.logexc(log, "ssh-import-id failed for: %s %s", user,
|
|
Packit |
bc9a3a |
import_ids)
|
|
Packit |
bc9a3a |
elist.append(exc)
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
if len(elist):
|
|
Packit |
bc9a3a |
raise elist[0]
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
def import_ssh_ids(ids, user, log):
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
if not (user and ids):
|
|
Packit |
bc9a3a |
log.debug("empty user(%s) or ids(%s). not importing", user, ids)
|
|
Packit |
bc9a3a |
return
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
try:
|
|
Packit |
bc9a3a |
pwd.getpwnam(user)
|
|
Packit |
bc9a3a |
except KeyError as exc:
|
|
Packit |
bc9a3a |
raise exc
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
cmd = ["sudo", "-Hu", user, "ssh-import-id"] + ids
|
|
Packit |
bc9a3a |
log.debug("Importing ssh ids for user %s.", user)
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
try:
|
|
Packit |
bc9a3a |
util.subp(cmd, capture=False)
|
|
Packit |
bc9a3a |
except util.ProcessExecutionError as exc:
|
|
Packit |
bc9a3a |
util.logexc(log, "Failed to run command to import %s ssh ids", user)
|
|
Packit |
bc9a3a |
raise exc
|
|
Packit |
bc9a3a |
|
|
Packit |
bc9a3a |
# vi: ts=4 expandtab
|