Puppet Class: usbguard
- Defined in:
- manifests/init.pp
Summary
Install and configure usbguardOverview
usbguard
43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 |
# File 'manifests/init.pp', line 43
class usbguard(
Boolean $manage_service = true,
Boolean $manage_package = true,
Boolean $manage_rules_file = true,
String $package_name = 'usbguard',
String $service_name = 'usbguard',
Enum['running', 'stopped'] $service_ensure = 'running',
# usbguard-daemon.conf settings settings
String $daemon_audit_file_path = '/var/log/usbguard/usbguard-audit.log',
Boolean $daemon_device_rules_with_port = false,
Enum['allow', 'block', 'reject'] $daemon_implicit_policy_target = 'block',
Array[String] $daemon_ipc_allowed_groups = [ 'wheel' ],
Array[String] $daemon_ipc_allowed_users = ['root'],
Enum['allow','block','reject','keep','apply-policy'] $daemon_present_controller_policy = 'keep',
Enum['allow','block','reject','keep','apply-policy'] $daemon_present_device_policy= 'apply-policy',
String $daemon_rule_file = '/etc/usbguard/rules-managed-by-puppet.conf',
# rules to provide by hiera/lookup or as class param
Optional[Array[String]] $rules = undef,
) {
contain ::usbguard::install
contain ::usbguard::config
contain ::usbguard::service
Class['::usbguard::install']
-> Class['::usbguard::config']
~> Class['::usbguard::service']
if $rules != undef {
$rules.each |$rule| {
::usbguard::rule { $rule: }
}
}
}
|