Monty Taylor 0d82c620b8 Fix ssh key error and also remove duplicates
We need specific key ids for keys, and if the key id changes, we need
a way to delete old ones. We also need the file to be writable by at
least the user so that puppet doesn't complain.

Change-Id: I5718b80d844d5f95149d0e23d98960879955c43c
2014-04-29 10:08:24 -07:00

70 lines
1.4 KiB
Puppet

# usage
#
# user::virtual::localuser['username']
define user::virtual::localuser(
$realname,
$groups = [ 'sudo', 'admin', ],
$sshkeys = '',
$key_id = '',
$old_keys = [],
$shell = '/bin/bash',
$home = "/home/${title}",
$managehome = true
) {
group { $title:
ensure => present,
}
user { $title:
ensure => present,
comment => $realname,
gid => $title,
groups => $groups,
home => $home,
managehome => $managehome,
membership => 'minimum',
shell => $shell,
require => Group[$title],
}
file { "${title}_sshdir":
ensure => directory,
name => "${home}/.ssh",
owner => $title,
group => $title,
mode => '0700',
require => User[$title],
}
file { "${title}_keyfile":
ensure => present,
mode => '0600',
name => "${home}/.ssh/authorized_keys",
require => File["${title}_sshdir"],
}
ssh_authorized_key { $key_id:
ensure => present,
key => $sshkeys,
user => $title,
type => 'ssh-rsa',
require => File["${title}_keyfile"],
}
ssh_authorized_key { "${title}_keys":
ensure => absent,
user => $title,
}
if ( $old_keys != [] ) {
ssh_authorized_key { $old_keys:
ensure => absent,
user => $title,
}
}
}
# vim:sw=2:ts=2:expandtab:textwidth=79