Skip to content

simp/pupmod-simp-sudo

Repository files navigation

License CII Best Practices Puppet Forge Puppet Forge Downloads Build Status

sudo

Table of Contents

  1. Module Description - What the module does and why it is useful
  2. Setup - The basics of getting started with sudo
  3. Usage - Configuration options and additional functionality
  4. Reference
  5. Limitations - OS compatibility, etc.
  6. Development - Guide for contributing to the module
  7. Acceptance Tests

Module Description

Constructs a sudoers file based on configuration aliases, defaults, and user specifications.

Setup

What sudo affects

sudo will ensure the sudo package is installed, and will manage /etc/sudoers.

Setup Requirements

The only necessary steps to begin using sudo is the install pupmod-simp-sudo into your modulepath

Beginning with sudo

To create the default SIMP /etc/sudoers file:

include 'sudo'

Usage

Add a user to sudoers

Giving a user root permissions

# NOTE: '%' in sudo signifies a group
# %powerusers is the powerusers group

sudo::user_specification { 'power_users':
  user_list => [ 'persona', 'personb', '%powerusers' ],
  runas     => 'root',
  cmnd      => [ '/bin/su root', '/bin/su - root' ]
}

Giving a system user access to a command without root

sudo::user_specification { 'myapp':
  user_list => [ 'myappuser' ],
  runas     => 'root',
  cmnd      => [ '/usr/bin/someservice' ],
  passwd    => false,
}

Create a sudo default entry

To create a defaults line in sudoers:

# Creates Defaults   requiretty, syslog=authpriv, !root_sudo, !umask, env_reset

sudo::default_entry { '00_main':
  content => [ 'requiretty',
               'syslog=authpriv',
               '!root_sudo',
               '!umask',
               'env_reset',
             ],
}

Create an alias

To create the following alias in sudoers: User_Alias FULLTIMERS = millert, mikef, dowdy

sudo::alias { 'FULLTIMERS':
  content => [ 'millert','mikef','dowdy' ],
  alias_type => 'user'
}

Additionally, these may be called by additional defined types for user, cmnd, host, or runas for easier readibility:

sudo::alias::user { 'FULLTIMERS':
  content => [ 'millert','mikef','dowdy' ],
}

Reference

Classes

Public Classes

  • sudo: Handles main /etc/sudoers file

Defined Types

Limitations

SIMP Puppet modules are generally intended to be used on a Red Hat Enterprise Linux-compatible distribution.

Development

Please read our Contribution Guide.

If you find any issues, they can be submitted to our JIRA.

Acceptance tests

To run the system tests, you need Vagrant installed.

You can then run the following to execute the acceptance tests:

   bundle exec rake beaker:suites

Some environment variables may be useful:

   BEAKER_debug=true
   BEAKER_provision=no
   BEAKER_destroy=no
   BEAKER_use_fixtures_dir_for_modules=yes
  • BEAKER_debug: show the commands being run on the STU and their output.
  • BEAKER_destroy=no: prevent the machine destruction after the tests finish so you can inspect the state.
  • BEAKER_provision=no: prevent the machine from being recreated. This can save a lot of time while you're writing the tests.
  • BEAKER_use_fixtures_dir_for_modules=yes: cause all module dependencies to be loaded from the spec/fixtures/modules directory, based on the contents of .fixtures.yml. The contents of this directory are usually populated by bundle exec rake spec_prep. This can be used to run acceptance tests to run on isolated networks.