Defined Type: sudo::conf

Defined in:
manifests/conf.pp

Summary

Manages sudo configuration snippets

Overview

Define: sudo::conf

Examples:

sudo::conf { 'admins':
  source => 'puppet:///files/etc/sudoers.d/admins',
}

Parameters:

  • ensure (Enum['present', 'absent']) (defaults to: present)

    Ensure if present or absent

  • priority (Variant[String[1], Integer[0]]) (defaults to: 10)

    Prefix file name with $priority

  • content (Optional[Variant[Array[String[1]], String[1]]]) (defaults to: undef)

    Content of configuration snippet

  • source (Optional[String[1]]) (defaults to: undef)

    Source of configuration snippet

  • template (Optional[String[1]]) (defaults to: undef)

    Path of a template file

  • sudo_config_dir (Optional[String[1]]) (defaults to: undef)

    Where to place configuration snippets. Only set this, if your platform is not supported or you know, what you’re doing.

  • sudo_file_name (Optional[String[1]]) (defaults to: undef)

    Set a custom file name for the snippet

  • sudo_syntax_path (String[1]) (defaults to: '/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin')

    Path to use for executing the sudo syntax check



37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# File 'manifests/conf.pp', line 37

define sudo::conf (
  Enum['present', 'absent']                      $ensure           = present,
  Variant[String[1], Integer[0]]                 $priority         = 10,
  Optional[Variant[Array[String[1]], String[1]]] $content          = undef,
  Optional[String[1]]                            $source           = undef,
  Optional[String[1]]                            $template         = undef,
  Optional[String[1]]                            $sudo_config_dir  = undef,
  Optional[String[1]]                            $sudo_file_name   = undef,
  String[1]                                      $sudo_syntax_path = '/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin'
) {
  include sudo

  # Hack to allow the user to set the config_dir from the
  # sudo::config parameter, but default to $sudo::params::config_dir
  # if it is not provided. $sudo::params isn't included before
  # the parameters are loaded in.
  $sudo_config_dir_real = $sudo_config_dir ? {
    undef            => $sudo::config_dir,
    $sudo_config_dir => $sudo_config_dir
  }

  # Append suffix
  if $sudo::suffix {
    $_name_suffix = "${name}${sudo::suffix}"
  } else {
    $_name_suffix = $name
  }

  # sudo skip file name that contain a "."
  $dname = regsubst($_name_suffix, '\.', '-', 'G')

  # Prepend prefix
  if $sudo::prefix {
    $_name_prefix = $sudo::prefix
  }  else {
    $_name_prefix = ''
  }

  if size("x${priority}") == 2 {
    $priority_real = "0${priority}"
  } else {
    $priority_real = $priority
  }

  # build current file name with path
  if $sudo_file_name != undef {
    $cur_file = "${sudo_config_dir_real}/${sudo_file_name}"
  } else {
    $cur_file = "${sudo_config_dir_real}/${_name_prefix}${priority_real}_${dname}"
  }

  # replace whitespace in file name
  $cur_file_real = regsubst($cur_file, '\s+', '_', 'G')

  if $content != undef {
    if $content =~ Array {
      $lines = join($content, "\n")
      $content_real = "# This file is managed by Puppet; changes may be overwritten\n${lines}\n"
    } else {
      $content_real = "# This file is managed by Puppet; changes may be overwritten\n${content}\n"
    }
  } elsif $template != undef {
    $content_real = template($template)
  } else {
    $content_real = undef
  }

  if $ensure == 'present' {
    if $sudo::validate_single {
      $validate_cmd_real = 'visudo -c -f %'
    } else {
      $validate_cmd_real = undef
    }
    if $sudo::delete_on_error {
      $notify_real = Exec["sudo-syntax-check for file ${cur_file}"]
      $delete_cmd = "( rm -f '${cur_file_real}' && exit 1)"
    } else {
      $notify_real = Exec["sudo-syntax-check for file ${cur_file}"]
      $errormsg = "Error on global-syntax-check with file ${cur_file_real}"
      $delete_cmd = "( echo '${errormsg}' && echo '#${errormsg}' >>${cur_file_real} && exit 1)"
    }
  } else {
    $delete_cmd = ''
    $notify_real = undef
    $validate_cmd_real = undef
  }

  file { "${priority_real}_${dname}":
    ensure       => $ensure,
    path         => $cur_file_real,
    owner        => 'root',
    group        => $sudo::params::config_file_group,
    mode         => $sudo::params::config_file_mode,
    source       => $source,
    content      => $content_real,
    notify       => $notify_real,
    require      => File[$sudo_config_dir_real],
    validate_cmd => $validate_cmd_real,
  }

  exec { "sudo-syntax-check for file ${cur_file}":
    command     => "visudo -c || ${delete_cmd}",
    refreshonly => true,
    path        => $sudo_syntax_path,
  }
}