3 \meI"@sUdZddlZddlmZddlmZddlmZddlm Z m Z ddl m Z ddl mZd Zd d d ed gededededededededgegdZe e eZejeZdZd ZeeeeddddZdS)!z,Users and Groups: Configure users and groupsN)dedent)Cloud)Config) MetaSchema get_meta_doc)ug_util) PER_INSTANCEa This module configures users and groups. For more detailed information on user options, see the :ref:`Including users and groups` config example. Groups to add to the system can be specified under the ``groups`` key as a string of comma-separated groups to create, or a list. Each item in the list should either contain a string of a single group to create, or a dictionary with the group name as the key and string of a single user as a member of that group or a list of users who should be members of the group. .. note:: Groups are added before users, so any users in a group list must already exist on the system. Users to add can be specified as a string or list under the ``users`` key. Each entry in the list should either be a string or a dictionary. If a string is specified, that string can be comma-separated usernames to create or the reserved string ``default`` which represents the primary admin user used to access the system. The ``default`` user varies per distribution and is generally configured in ``/etc/cloud/cloud.cfg`` by the ``default_user`` key. Each ``users`` dictionary item must contain either a ``name`` or ``snapuser`` key, otherwise it will be ignored. Omission of ``default`` as the first item in the ``users`` list skips creation the default user. If no ``users`` key is provided the default behavior is to create the default user via this config:: users: - default .. note:: Specifying a hash of a user's password with ``passwd`` is a security risk if the cloud-config can be intercepted. SSH authentication is preferred. .. note:: If specifying a doas rule for a user, ensure that the syntax for the rule is valid, as the only checking performed by cloud-init is to ensure that the user referenced in the rule is the correct user. .. note:: If specifying a sudo rule for a user, ensure that the syntax for the rule is valid, as it is not checked by cloud-init. .. note:: Most of these configuration options will not be honored if the user already exists. The following options are the exceptions; they are applied to already-existing users: ``plain_text_passwd``, ``doas``, ``hashed_passwd``, ``lock_passwd``, ``sudo``, ``ssh_authorized_keys``, ``ssh_redirect_user``. The ``user`` key can be used to override the ``default_user`` configuration defined in ``/etc/cloud/cloud.cfg``. The ``user`` value should be a dictionary which supports the same config keys as the ``users`` dictionary items. Zcc_users_groupszUsers and GroupszConfigure users and groupsallz # Add the ``default_user`` from /etc/cloud/cloud.cfg. # This is also the default behavior of cloud-init when no `users` key # is provided. users: - default z # Add the 'admingroup' with members 'root' and 'sys' and an empty # group cloud-users. groups: - admingroup: [root,sys] - cloud-users a9 # Skip creation of the user and only create newsuper. # Password-based login is rejected, but the github user TheRealFalcon # and the launchpad user falcojr can SSH as newsuper. The default # shell for newsuper is bash instead of system default. users: - name: newsuper gecos: Big Stuff groups: users, admin sudo: ALL=(ALL) NOPASSWD:ALL shell: /bin/bash lock_passwd: true ssh_import_id: - lp:falcojr - gh:TheRealFalcon a # Skip creation of the user and only create newsuper. # Password-based login is rejected, but the github user TheRealFalcon # and the launchpad user falcojr can SSH as newsuper. doas/opendoas # is configured to permit this user to run commands as other users # (without being prompted for a password) except not as root. users: - name: newsuper gecos: Big Stuff groups: users, admin doas: - permit nopass newsuper - deny newsuper as root lock_passwd: true ssh_import_id: - lp:falcojr - gh:TheRealFalcon a+ # On a system with SELinux enabled, add youruser and set the # SELinux user to 'staff_u'. When omitted on SELinux, the system will # select the configured default SELinux user. users: - default - name: youruser selinux_user: staff_u am # To redirect a legacy username to the user for a # distribution, ssh_redirect_user will accept an SSH connection and # emit a message telling the client to ssh as the user. # SSH clients will get the message: users: - default - name: nosshlogins ssh_redirect_user: true aW # Override any ``default_user`` config in /etc/cloud/cloud.cfg with # supplemental config options. # This config will make the default user to mynewdefault and change # the user to not have sudo rights. ssh_import_id: [chad.smith] user: name: mynewdefault sudo: null zI # Avoid creating any ``default_user``. users: [] )idnametitle descriptionZdistrosZexamplesZ frequencyZactivate_by_schema_keysno_create_homesystemssh_authorized_keys ssh_import_idssh_redirect_user)r cfgcloudargsreturnc s<tj||j\}}tj|\}}|jp*g}x"|jD]\}} |jj|| q6Wx|jD]\} fddtD} fddtD} | r| rt d| ddj | ddj | j dd } | r$d ksd krt d | | dkrt d| | f|dkrt j d| | n|d<|d<|jj| fqZWdS)Ncsg|]}j|r|qS)get).0key)configr%/usr/lib/python3.6/cc_users_groups.py szhandle..csg|]}j|r|qSr)r)rr)rrrrszNot creating user z . Key(s) z, z cannot be provided with rFrrzdNot creating user %s. ssh_redirect_user cannot be provided with ssh_import_id or ssh_authorized_keysTdefaultzfNot creating user %s. Invalid value of ssh_redirect_user: %s. Expected values: true, default or false.zzIgnoring ssh_redirect_user: %s for %s. No default_user defined. Perhaps missing cloud configuration users: [default, ..].Zcloud_public_ssh_keys)Tr)rZnormalize_users_groupsZdistroZextract_defaultZget_public_ssh_keysitemsZ create_groupNO_HOME NEED_HOME ValueErrorjoinpopLOGZwarningZ create_user)r rrrZusersgroupsZ default_userZ _user_configZ cloud_keysmembersuserZno_homeZ need_homerr)rrhandles: $   r))rr)rrr)__doc__ZloggingtextwraprZcloudinit.cloudrZcloudinit.configrZcloudinit.config.schemarrZcloudinit.distrosrZcloudinit.settingsrZMODULE_DESCRIPTIONmetaZ getLogger__name__r%r r!strlistr)rrrrsH     7