THIS REPOSITORY IS NO LONGER MAINTAINED - IF YOU LIKE TO TAKE CARE OF IT, PLEASE CONTACT ME
- Overview
- Module Description - What the module does and why it is useful
- Setup - The basics of getting started with openssh
- Usage - Configuration options and additional functionality
- Reference - An under-the-hood peek at what the module is doing and how
- Limitations - OS compatibility, etc.
- Development - Guide for contributing to the module
Module to manage OpenSSH with focus on using augeas for configfile modifications to provide compatibility with upstream changes in this files.
Puppetversion: >= 3.5.0
OS: RedHat, Debian
This Module installs the openssh server and client and manages the sshd_config. It optionally gathers the hostkeys and provides them for other hosts.
- Packages and service for openssh
- sshd_config
- system-wide known_hosts file
To use spreading of hostkeys you will need a puppetdb-enabled puppetserver
To begin using this module with default parameters, declare the class with
include openssh
Any Puppet code that uses anything from the apt module requires that the core apt class be declared.
Install packages, set some defaults, ensure service is running, export all keys to all hosts
class { 'openssh': }
Because the hash of the config-parameter gets passed comletely to augeas, you can use all options your augeas lens provides in the way your augeas lens specifies it. Here are some examples for that:
Install packages, set some custom values, ensure service is running, export and collect no keys
class { '::openssh':
config => {
'X11Forwarding' => 'no',
'AllowTcpForwarding' => 'yes',
'Port' => '222',
},
exporttag => false,
collecttag => false,
}
Install packages, set two listening ports and special parameters for group "no-admin", ensure service is running, export keys with tag "customer_hosts" and collect no keys
class { '::openssh':
config => {
'X11Forwarding' => 'no',
'AllowTcpForwarding' => 'yes',
'Port[1]' => '222',
'Port[2]' => '333',
'Match[1]/Condition/Group' => 'no-admin',
'Match[1]/Settings/ChrootDirectory' => '/home',
'Match[1]/Settings/X11Forwarding' => 'no',
},
exporttag => 'customer_hosts',
collecttag => false,
}
-
openssh
: Main class that is used to set the variables and includes the other classes -
openssh::params
: Sets defaults for the variables used by this module -
openssh::install
: Installs the packages on the system -
openssh::config
: Cares about the whole openssh-configuration including rollout of known hostkeys -
openssh::service
: Handles the openssh service
-
ensure
: Set the ensure-value for the packages. Default: 'present' -
packages
: Name or array of the packages to be installed. Default: osfamily-specific (see params.pp) -
servicename
: Name of the service to be started Default: osfamily-specific (see params.pp) -
sshd_config
: Path to the sshd_config file Default: /etc/ssh/sshd_config -
sshd_config_def
: Default values for sshd_config parameters. This should almost never need to be changed. -
config
: A hash with all options that should get set in sshd_config -
exporttag
: Tag that the exported hostkey get for collecting. If 'false', key won't get exported. Default: managedhosts -
collecttag
: Keys with this tag will get collected. If 'false', keys won't get collected.
If you like to contribute: pull requests are welcome :-)