mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: deploy user ssh keypair for user account only (#19133)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
@@ -102,7 +102,7 @@ func init() {
|
||||
oldKeys = string(output)
|
||||
}
|
||||
pubKeys := &deployapi.SSHKeys{AdminPublicKey: pubKey}
|
||||
newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys)
|
||||
newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys, true)
|
||||
if output, err := procutils.NewCommand(
|
||||
"sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil {
|
||||
return errors.Wrapf(err, "write public keys: %s", output)
|
||||
|
||||
@@ -153,13 +153,13 @@ const (
|
||||
modeAuthorizedKeysRW = syscall.S_IRUSR | syscall.S_IWUSR
|
||||
)
|
||||
|
||||
func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool) error {
|
||||
func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error {
|
||||
var oldKeys = ""
|
||||
if !replace {
|
||||
bOldKeys, _ := rootFs.FileGetContents(authFile, false)
|
||||
oldKeys = string(bOldKeys)
|
||||
}
|
||||
newKeys := MergeAuthorizedKeys(oldKeys, pubkeys)
|
||||
newKeys := MergeAuthorizedKeys(oldKeys, pubkeys, admin)
|
||||
if err := rootFs.FilePutContents(authFile, newKeys, false, false); err != nil {
|
||||
return fmt.Errorf("Put keys to %s: %v", authFile, err)
|
||||
}
|
||||
@@ -172,7 +172,7 @@ func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int,
|
||||
return nil
|
||||
}
|
||||
|
||||
func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool) error {
|
||||
func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error {
|
||||
usrStat := rootFs.Stat(usrDir, false)
|
||||
if usrStat != nil {
|
||||
sshDir := path.Join(usrDir, ".ssh")
|
||||
@@ -192,18 +192,24 @@ func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deploya
|
||||
return err
|
||||
}
|
||||
}
|
||||
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace)
|
||||
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, admin)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string {
|
||||
const sshKeySignature = "@yunioncloudpods"
|
||||
|
||||
func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys, isAdmin bool) string {
|
||||
var allkeys = make(map[string]string)
|
||||
if len(oldKeys) > 0 {
|
||||
for _, line := range strings.Split(oldKeys, "\n") {
|
||||
line = strings.TrimSpace(line)
|
||||
dat := strings.Split(line, " ")
|
||||
if len(dat) > 1 {
|
||||
if len(dat) > 2 && dat[2] == sshKeySignature {
|
||||
// skip ssh keys with signature
|
||||
continue
|
||||
}
|
||||
if _, ok := allkeys[dat[1]]; !ok {
|
||||
allkeys[dat[1]] = line
|
||||
}
|
||||
@@ -218,13 +224,19 @@ func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string {
|
||||
}
|
||||
}
|
||||
}
|
||||
for _, k := range []string{pubkeys.PublicKey, pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey} {
|
||||
var candiateKeys []string
|
||||
if isAdmin {
|
||||
candiateKeys = []string{pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey}
|
||||
} else {
|
||||
candiateKeys = []string{pubkeys.PublicKey}
|
||||
}
|
||||
for _, k := range candiateKeys {
|
||||
if len(k) > 0 {
|
||||
k = strings.TrimSpace(k)
|
||||
dat := strings.Split(k, " ")
|
||||
if len(dat) > 1 {
|
||||
if _, ok := allkeys[dat[1]]; !ok {
|
||||
allkeys[dat[1]] = k
|
||||
allkeys[dat[1]] = strings.Join([]string{dat[0], dat[1], sshKeySignature}, " ")
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -265,7 +277,7 @@ func DeployAdminAuthorizedKeys(s *mcclient.ClientSession) error {
|
||||
}
|
||||
oldKeys = string(output)
|
||||
}
|
||||
newKeys := MergeAuthorizedKeys(oldKeys, pubKeys)
|
||||
newKeys := MergeAuthorizedKeys(oldKeys, pubKeys, true)
|
||||
if output, err := procutils.NewRemoteCommandAsFarAsPossible(
|
||||
"sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil {
|
||||
return errors.Wrapf(err, "write public keys: %s", output)
|
||||
|
||||
@@ -26,22 +26,33 @@ func TestMergeAuthorizedKeys(t *testing.T) {
|
||||
pubkeys *deployapi.SSHKeys
|
||||
}
|
||||
tests := []struct {
|
||||
name string
|
||||
args args
|
||||
want string
|
||||
name string
|
||||
args args
|
||||
admin bool
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "MergeAuthorizedKeys",
|
||||
args: args{
|
||||
oldKeys: "Test KEY",
|
||||
oldKeys: "ssh-rsa KEY",
|
||||
pubkeys: &deployapi.SSHKeys{},
|
||||
},
|
||||
want: "Test KEY\n",
|
||||
admin: true,
|
||||
want: "ssh-rsa KEY\n",
|
||||
},
|
||||
{
|
||||
name: "MergeAuthorizedKeys",
|
||||
args: args{
|
||||
oldKeys: "ssh-rsa KEY " + sshKeySignature,
|
||||
pubkeys: &deployapi.SSHKeys{},
|
||||
},
|
||||
admin: true,
|
||||
want: "\n",
|
||||
},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys); got != tt.want {
|
||||
if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys, tt.admin); got != tt.want {
|
||||
t.Errorf("MergeAuthorizedKeys() = %v, want %v", got, tt.want)
|
||||
}
|
||||
})
|
||||
|
||||
@@ -222,7 +222,7 @@ func (l *sLinuxRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, pub
|
||||
} else {
|
||||
usrDir = path.Join("/home", selUsr)
|
||||
}
|
||||
return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false)
|
||||
return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false, false)
|
||||
}
|
||||
|
||||
func (d *SCoreOsRootFs) DeployQgaBlackList(rootFs IDiskPartition) error {
|
||||
@@ -276,7 +276,7 @@ func (l *sLinuxRootFs) DeployYunionroot(rootFs IDiskPartition, pubkeys *deployap
|
||||
return errors.Wrap(err, "unable to CheckOrAddUser")
|
||||
}
|
||||
log.Infof("DeployYunionroot %s home %s", yunionroot, rootdir)
|
||||
err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true)
|
||||
err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true, true)
|
||||
if err != nil {
|
||||
log.Infof("DeployAuthorizedKeys error: %s", err.Error())
|
||||
return fmt.Errorf("DeployAuthorizedKeys: %v", err)
|
||||
@@ -1858,7 +1858,7 @@ func (d *SOpenWrtRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, p
|
||||
gid = 0
|
||||
replace = false
|
||||
)
|
||||
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace)
|
||||
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, false)
|
||||
}
|
||||
return d.sLinuxRootFs.DeployPublicKey(rootFs, selUsr, pubkeys)
|
||||
}
|
||||
|
||||
@@ -75,7 +75,7 @@ func (m *SMacOSRootFs) RootSignatures() []string {
|
||||
|
||||
func (m *SMacOSRootFs) DeployPublicKey(rootfs IDiskPartition, uname string, pubkeys *deployapi.SSHKeys) error {
|
||||
usrDir := fmt.Sprintf("/Users/%s", uname)
|
||||
return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false)
|
||||
return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false, false)
|
||||
}
|
||||
|
||||
func (m *SMacOSRootFs) addScripts(lines []string) {
|
||||
|
||||
Reference in New Issue
Block a user