
Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­
<!DOCTYPE html>
<html>
3
\¼meI"  ã               @   sÞ   U d Z ddlZddlmZ ddlmZ ddlmZ ddlm	Z	m
Z
 ddlmZ ddlmZ d	Zd
ddedgedƒedƒedƒedƒedƒedƒedƒedƒgeg dœZe	e
eƒZ ejeƒZdZd Zeeeeddœdd„ZdS )!z,Users and Groups: Configure users and groupsé    N)Údedent)ÚCloud)ÚConfig)Ú
MetaSchemaÚget_meta_doc)Úug_util)ÚPER_INSTANCEaÏ	  This module configures users and groups. For more detailed information on user
options, see the :ref:`Including users and groups<yaml_examples>` config
example.

Groups to add to the system can be specified under the ``groups`` key as
a string of comma-separated groups to create, or a list. Each item in
the list should either contain a string of a single group to create,
or a dictionary with the group name as the key and string of a single user as
a member of that group or a list of users who should be members of the group.

.. note::
   Groups are added before users, so any users in a group list must
   already exist on the system.

Users to add can be specified as a string or list under the ``users`` key.
Each entry in the list should either be a string or a dictionary. If a string
is specified, that string can be comma-separated usernames to create or the
reserved string ``default`` which represents the primary admin user used to
access the system. The ``default`` user varies per distribution and is
generally configured in ``/etc/cloud/cloud.cfg`` by the ``default_user`` key.

Each ``users`` dictionary item must contain either a ``name`` or ``snapuser``
key, otherwise it will be ignored. Omission of ``default`` as the first item
in the ``users`` list skips creation the default user. If no ``users`` key is
provided the default behavior is to create the default user via this config::

 users:
 - default

.. note::
    Specifying a hash of a user's password with ``passwd`` is a security risk
    if the cloud-config can be intercepted. SSH authentication is preferred.

.. note::
    If specifying a doas rule for a user, ensure that the syntax for the rule
    is valid, as the only checking performed by cloud-init is to ensure that
    the user referenced in the rule is the correct user.

.. note::
    If specifying a sudo rule for a user, ensure that the syntax for the rule
    is valid, as it is not checked by cloud-init.

.. note::
    Most of these configuration options will not be honored if the user
    already exists. The following options are the exceptions; they are applied
    to already-existing users: ``plain_text_passwd``, ``doas``,
    ``hashed_passwd``, ``lock_passwd``, ``sudo``, ``ssh_authorized_keys``,
    ``ssh_redirect_user``.

The ``user`` key can be used to override the ``default_user`` configuration
defined in ``/etc/cloud/cloud.cfg``. The ``user`` value should be a dictionary
which supports the same config keys as the ``users`` dictionary items.
Zcc_users_groupszUsers and GroupszConfigure users and groupsÚallzÌ        # Add the ``default_user`` from /etc/cloud/cloud.cfg.
        # This is also the default behavior of cloud-init when no `users` key
        # is provided.
        users:
        - default
        z¶        # Add the 'admingroup' with members 'root' and 'sys' and an empty
        # group cloud-users.
        groups:
        - admingroup: [root,sys]
        - cloud-users
        a9          # Skip creation of the <default> user and only create newsuper.
        # Password-based login is rejected, but the github user TheRealFalcon
        # and the launchpad user falcojr can SSH as newsuper. The default
        # shell for newsuper is bash instead of system default.
        users:
        - name: newsuper
          gecos: Big Stuff
          groups: users, admin
          sudo: ALL=(ALL) NOPASSWD:ALL
          shell: /bin/bash
          lock_passwd: true
          ssh_import_id:
            - lp:falcojr
            - gh:TheRealFalcon
        a£          # Skip creation of the <default> user and only create newsuper.
        # Password-based login is rejected, but the github user TheRealFalcon
        # and the launchpad user falcojr can SSH as newsuper. doas/opendoas
        # is configured to permit this user to run commands as other users
        # (without being prompted for a password) except not as root.
        users:
        - name: newsuper
          gecos: Big Stuff
          groups: users, admin
          doas:
            - permit nopass newsuper
            - deny newsuper as root
          lock_passwd: true
          ssh_import_id:
            - lp:falcojr
            - gh:TheRealFalcon
        a+          # On a system with SELinux enabled, add youruser and set the
        # SELinux user to 'staff_u'. When omitted on SELinux, the system will
        # select the configured default SELinux user.
        users:
        - default
        - name: youruser
          selinux_user: staff_u
        am          # To redirect a legacy username to the <default> user for a
        # distribution, ssh_redirect_user will accept an SSH connection and
        # emit a message telling the client to ssh as the <default> user.
        # SSH clients will get the message:
        users:
        - default
        - name: nosshlogins
          ssh_redirect_user: true
        aW          # Override any ``default_user`` config in /etc/cloud/cloud.cfg with
        # supplemental config options.
        # This config will make the default user to mynewdefault and change
        # the user to not have sudo rights.
        ssh_import_id: [chad.smith]
        user:
          name: mynewdefault
          sudo: null
        zI        # Avoid creating any ``default_user``.
        users: []
        )ÚidÚnameÚtitleÚdescriptionZdistrosZexamplesZ	frequencyZactivate_by_schema_keysÚno_create_homeÚsystemÚssh_authorized_keysÚssh_import_idÚssh_redirect_user)r   ÚcfgÚcloudÚargsÚreturnc          	      s<  t j||jƒ\}}t j|ƒ\}}|jƒ p*g }x"|jƒ D ]\} }	|jj| |	ƒ q6W xæ|jƒ D ]Ú\}
‰ ‡ fdd„tD ƒ}‡ fdd„tD ƒ}|r´|r´t	d|
› ddj
|ƒ› ddj
|ƒ› �ƒ‚ˆ jdd	ƒ}|�r$d
ˆ ksÖdˆ krât	d|
 ƒ‚|dkrút	d|
|f ƒ‚|d k�rtjd||
ƒ n|ˆ d< |ˆ d< |jj|
fˆ Ž qZW d S )Nc                s   g | ]}ˆ j |ƒr|‘qS © )Úget)Ú.0Úkey)Úconfigr   ú%/usr/lib/python3.6/cc_users_groups.pyú
<listcomp>Í   s    zhandle.<locals>.<listcomp>c                s   g | ]}ˆ j |ƒr|‘qS r   )r   )r   r   )r   r   r   r   Î   s    zNot creating user z	. Key(s) z, z cannot be provided with r   Fr   r   zdNot creating user %s. ssh_redirect_user cannot be provided with ssh_import_id or ssh_authorized_keysTÚdefaultzfNot creating user %s. Invalid value of ssh_redirect_user: %s. Expected values: true, default or false.zzIgnoring ssh_redirect_user: %s for %s. No default_user defined. Perhaps missing cloud configuration users:  [default, ..].Zcloud_public_ssh_keys)Tr   )r   Znormalize_users_groupsZdistroZextract_defaultZget_public_ssh_keysÚitemsZcreate_groupÚNO_HOMEÚ	NEED_HOMEÚ
ValueErrorÚjoinÚpopÚLOGZwarningZcreate_user)r   r   r   r   ZusersÚgroupsZdefault_userZ_user_configZ
cloud_keysÚmembersÚuserZno_homeZ	need_homer   r   )r   r   ÚhandleÃ   s:    $
r)   )r   r   )r   r   r   )Ú__doc__ZloggingÚtextwrapr   Zcloudinit.cloudr   Zcloudinit.configr   Zcloudinit.config.schemar   r   Zcloudinit.distrosr   Zcloudinit.settingsr   ZMODULE_DESCRIPTIONÚmetaZ	getLoggerÚ__name__r%   r    r!   ÚstrÚlistr)   r   r   r   r   Ú<module>   sH   7	


