3
\meI" @ s U d Z ddlZddlmZ ddlmZ ddlmZ ddlm Z m
Z
ddlmZ ddl
mZ d Zd
dded
gededededededededgeg dZe e
eZ ejeZdZd ZeeeeddddZdS )!z,Users and Groups: Configure users and groups N)dedent)Cloud)Config)
MetaSchemaget_meta_doc)ug_util)PER_INSTANCEa This module configures users and groups. For more detailed information on user
options, see the :ref:`Including users and groups` config
example.
Groups to add to the system can be specified under the ``groups`` key as
a string of comma-separated groups to create, or a list. Each item in
the list should either contain a string of a single group to create,
or a dictionary with the group name as the key and string of a single user as
a member of that group or a list of users who should be members of the group.
.. note::
Groups are added before users, so any users in a group list must
already exist on the system.
Users to add can be specified as a string or list under the ``users`` key.
Each entry in the list should either be a string or a dictionary. If a string
is specified, that string can be comma-separated usernames to create or the
reserved string ``default`` which represents the primary admin user used to
access the system. The ``default`` user varies per distribution and is
generally configured in ``/etc/cloud/cloud.cfg`` by the ``default_user`` key.
Each ``users`` dictionary item must contain either a ``name`` or ``snapuser``
key, otherwise it will be ignored. Omission of ``default`` as the first item
in the ``users`` list skips creation the default user. If no ``users`` key is
provided the default behavior is to create the default user via this config::
users:
- default
.. note::
Specifying a hash of a user's password with ``passwd`` is a security risk
if the cloud-config can be intercepted. SSH authentication is preferred.
.. note::
If specifying a doas rule for a user, ensure that the syntax for the rule
is valid, as the only checking performed by cloud-init is to ensure that
the user referenced in the rule is the correct user.
.. note::
If specifying a sudo rule for a user, ensure that the syntax for the rule
is valid, as it is not checked by cloud-init.
.. note::
Most of these configuration options will not be honored if the user
already exists. The following options are the exceptions; they are applied
to already-existing users: ``plain_text_passwd``, ``doas``,
``hashed_passwd``, ``lock_passwd``, ``sudo``, ``ssh_authorized_keys``,
``ssh_redirect_user``.
The ``user`` key can be used to override the ``default_user`` configuration
defined in ``/etc/cloud/cloud.cfg``. The ``user`` value should be a dictionary
which supports the same config keys as the ``users`` dictionary items.
Zcc_users_groupszUsers and GroupszConfigure users and groupsallz # Add the ``default_user`` from /etc/cloud/cloud.cfg.
# This is also the default behavior of cloud-init when no `users` key
# is provided.
users:
- default
z # Add the 'admingroup' with members 'root' and 'sys' and an empty
# group cloud-users.
groups:
- admingroup: [root,sys]
- cloud-users
a9 # Skip creation of the user and only create newsuper.
# Password-based login is rejected, but the github user TheRealFalcon
# and the launchpad user falcojr can SSH as newsuper. The default
# shell for newsuper is bash instead of system default.
users:
- name: newsuper
gecos: Big Stuff
groups: users, admin
sudo: ALL=(ALL) NOPASSWD:ALL
shell: /bin/bash
lock_passwd: true
ssh_import_id:
- lp:falcojr
- gh:TheRealFalcon
a # Skip creation of the user and only create newsuper.
# Password-based login is rejected, but the github user TheRealFalcon
# and the launchpad user falcojr can SSH as newsuper. doas/opendoas
# is configured to permit this user to run commands as other users
# (without being prompted for a password) except not as root.
users:
- name: newsuper
gecos: Big Stuff
groups: users, admin
doas:
- permit nopass newsuper
- deny newsuper as root
lock_passwd: true
ssh_import_id:
- lp:falcojr
- gh:TheRealFalcon
a+ # On a system with SELinux enabled, add youruser and set the
# SELinux user to 'staff_u'. When omitted on SELinux, the system will
# select the configured default SELinux user.
users:
- default
- name: youruser
selinux_user: staff_u
am # To redirect a legacy username to the user for a
# distribution, ssh_redirect_user will accept an SSH connection and
# emit a message telling the client to ssh as the user.
# SSH clients will get the message:
users:
- default
- name: nosshlogins
ssh_redirect_user: true
aW # Override any ``default_user`` config in /etc/cloud/cloud.cfg with
# supplemental config options.
# This config will make the default user to mynewdefault and change
# the user to not have sudo rights.
ssh_import_id: [chad.smith]
user:
name: mynewdefault
sudo: null
zI # Avoid creating any ``default_user``.
users: []
)idnametitledescriptionZdistrosZexamplesZ frequencyZactivate_by_schema_keysno_create_homesystemssh_authorized_keys
ssh_import_idssh_redirect_user)r cfgcloudargsreturnc s< t j||j\}}t j|\}}|j p*g }x"|j D ]\} } |jj| | q6W x|j D ]\}
fddtD } fddtD }|r|rt d|
ddj
| ddj
| jdd }
|
r$d
ksd krt d|
|
dkrt d|
|
f |d krtj
d|
|
n| d<