Blame cloudinit/config/cc_ssh_import_id.py

Packit bc9a3a
# Copyright (C) 2009-2010 Canonical Ltd.
Packit bc9a3a
# Copyright (C) 2012, 2013 Hewlett-Packard Development Company, L.P.
Packit bc9a3a
#
Packit bc9a3a
# Author: Scott Moser <scott.moser@canonical.com>
Packit bc9a3a
# Author: Juerg Haefliger <juerg.haefliger@hp.com>
Packit bc9a3a
#
Packit bc9a3a
# This file is part of cloud-init. See LICENSE file for license information.
Packit bc9a3a
Packit bc9a3a
"""
Packit bc9a3a
SSH Import Id
Packit bc9a3a
-------------
Packit bc9a3a
**Summary:** import ssh id
Packit bc9a3a
Packit bc9a3a
This module imports ssh keys from either a public keyserver, usually launchpad
Packit bc9a3a
or github using ``ssh-import-id``. Keys are referenced by the username they are
Packit bc9a3a
associated with on the keyserver. The keyserver can be specified by prepending
Packit bc9a3a
either ``lp:`` for launchpad or ``gh:`` for github to the username.
Packit bc9a3a
Packit bc9a3a
**Internal name:** ``cc_ssh_import_id``
Packit bc9a3a
Packit bc9a3a
**Module frequency:** per instance
Packit bc9a3a
Packit bc9a3a
**Supported distros:** ubuntu, debian
Packit bc9a3a
Packit bc9a3a
**Config keys**::
Packit bc9a3a
Packit bc9a3a
    ssh_import_id:
Packit bc9a3a
        - user
Packit bc9a3a
        - gh:user
Packit bc9a3a
        - lp:user
Packit bc9a3a
"""
Packit bc9a3a
Packit bc9a3a
from cloudinit.distros import ug_util
Packit bc9a3a
from cloudinit import util
Packit bc9a3a
import pwd
Packit bc9a3a
Packit bc9a3a
# https://launchpad.net/ssh-import-id
Packit bc9a3a
distros = ['ubuntu', 'debian']
Packit bc9a3a
Packit bc9a3a
Packit bc9a3a
def handle(_name, cfg, cloud, log, args):
Packit bc9a3a
Packit bc9a3a
    # import for "user: XXXXX"
Packit bc9a3a
    if len(args) != 0:
Packit bc9a3a
        user = args[0]
Packit bc9a3a
        ids = []
Packit bc9a3a
        if len(args) > 1:
Packit bc9a3a
            ids = args[1:]
Packit bc9a3a
Packit bc9a3a
        import_ssh_ids(ids, user, log)
Packit bc9a3a
        return
Packit bc9a3a
Packit bc9a3a
    # import for cloudinit created users
Packit bc9a3a
    (users, _groups) = ug_util.normalize_users_groups(cfg, cloud.distro)
Packit bc9a3a
    elist = []
Packit bc9a3a
    for (user, user_cfg) in users.items():
Packit bc9a3a
        import_ids = []
Packit bc9a3a
        if user_cfg['default']:
Packit bc9a3a
            import_ids = util.get_cfg_option_list(cfg, "ssh_import_id", [])
Packit bc9a3a
        else:
Packit bc9a3a
            try:
Packit bc9a3a
                import_ids = user_cfg['ssh_import_id']
Packit bc9a3a
            except Exception:
Packit bc9a3a
                log.debug("User %s is not configured for ssh_import_id", user)
Packit bc9a3a
                continue
Packit bc9a3a
Packit bc9a3a
        try:
Packit bc9a3a
            import_ids = util.uniq_merge(import_ids)
Packit bc9a3a
            import_ids = [str(i) for i in import_ids]
Packit bc9a3a
        except Exception:
Packit bc9a3a
            log.debug("User %s is not correctly configured for ssh_import_id",
Packit bc9a3a
                      user)
Packit bc9a3a
            continue
Packit bc9a3a
Packit bc9a3a
        if not len(import_ids):
Packit bc9a3a
            continue
Packit bc9a3a
Packit bc9a3a
        try:
Packit bc9a3a
            import_ssh_ids(import_ids, user, log)
Packit bc9a3a
        except Exception as exc:
Packit bc9a3a
            util.logexc(log, "ssh-import-id failed for: %s %s", user,
Packit bc9a3a
                        import_ids)
Packit bc9a3a
            elist.append(exc)
Packit bc9a3a
Packit bc9a3a
    if len(elist):
Packit bc9a3a
        raise elist[0]
Packit bc9a3a
Packit bc9a3a
Packit bc9a3a
def import_ssh_ids(ids, user, log):
Packit bc9a3a
Packit bc9a3a
    if not (user and ids):
Packit bc9a3a
        log.debug("empty user(%s) or ids(%s). not importing", user, ids)
Packit bc9a3a
        return
Packit bc9a3a
Packit bc9a3a
    try:
Packit bc9a3a
        pwd.getpwnam(user)
Packit bc9a3a
    except KeyError as exc:
Packit bc9a3a
        raise exc
Packit bc9a3a
Packit bc9a3a
    cmd = ["sudo", "-Hu", user, "ssh-import-id"] + ids
Packit bc9a3a
    log.debug("Importing ssh ids for user %s.", user)
Packit bc9a3a
Packit bc9a3a
    try:
Packit bc9a3a
        util.subp(cmd, capture=False)
Packit bc9a3a
    except util.ProcessExecutionError as exc:
Packit bc9a3a
        util.logexc(log, "Failed to run command to import %s ssh ids", user)
Packit bc9a3a
        raise exc
Packit bc9a3a
Packit bc9a3a
# vi: ts=4 expandtab