fix: deploy user ssh keypair for user account only (#19133)

Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
Jian Qiu
2023-12-30 16:56:24 +08:00
committed by GitHub
co-authored by Qiu Jian
parent d70dd2f541
commit 33556cdf40
5 changed files with 42 additions and 19 deletions
+1 -1
View File
@@ -102,7 +102,7 @@ func init() {
oldKeys = string(output)
}
pubKeys := &deployapi.SSHKeys{AdminPublicKey: pubKey}
newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys)
newKeys := fsdriver.MergeAuthorizedKeys(oldKeys, pubKeys, true)
if output, err := procutils.NewCommand(
"sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil {
return errors.Wrapf(err, "write public keys: %s", output)
+20 -8
View File
@@ -153,13 +153,13 @@ const (
modeAuthorizedKeysRW = syscall.S_IRUSR | syscall.S_IWUSR
)
func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool) error {
func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error {
var oldKeys = ""
if !replace {
bOldKeys, _ := rootFs.FileGetContents(authFile, false)
oldKeys = string(bOldKeys)
}
newKeys := MergeAuthorizedKeys(oldKeys, pubkeys)
newKeys := MergeAuthorizedKeys(oldKeys, pubkeys, admin)
if err := rootFs.FilePutContents(authFile, newKeys, false, false); err != nil {
return fmt.Errorf("Put keys to %s: %v", authFile, err)
}
@@ -172,7 +172,7 @@ func deployAuthorizedKeys(rootFs IDiskPartition, authFile string, uid, gid int,
return nil
}
func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool) error {
func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deployapi.SSHKeys, replace bool, admin bool) error {
usrStat := rootFs.Stat(usrDir, false)
if usrStat != nil {
sshDir := path.Join(usrDir, ".ssh")
@@ -192,18 +192,24 @@ func DeployAuthorizedKeys(rootFs IDiskPartition, usrDir string, pubkeys *deploya
return err
}
}
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace)
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, admin)
}
return nil
}
func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string {
const sshKeySignature = "@yunioncloudpods"
func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys, isAdmin bool) string {
var allkeys = make(map[string]string)
if len(oldKeys) > 0 {
for _, line := range strings.Split(oldKeys, "\n") {
line = strings.TrimSpace(line)
dat := strings.Split(line, " ")
if len(dat) > 1 {
if len(dat) > 2 && dat[2] == sshKeySignature {
// skip ssh keys with signature
continue
}
if _, ok := allkeys[dat[1]]; !ok {
allkeys[dat[1]] = line
}
@@ -218,13 +224,19 @@ func MergeAuthorizedKeys(oldKeys string, pubkeys *deployapi.SSHKeys) string {
}
}
}
for _, k := range []string{pubkeys.PublicKey, pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey} {
var candiateKeys []string
if isAdmin {
candiateKeys = []string{pubkeys.AdminPublicKey, pubkeys.ProjectPublicKey}
} else {
candiateKeys = []string{pubkeys.PublicKey}
}
for _, k := range candiateKeys {
if len(k) > 0 {
k = strings.TrimSpace(k)
dat := strings.Split(k, " ")
if len(dat) > 1 {
if _, ok := allkeys[dat[1]]; !ok {
allkeys[dat[1]] = k
allkeys[dat[1]] = strings.Join([]string{dat[0], dat[1], sshKeySignature}, " ")
}
}
}
@@ -265,7 +277,7 @@ func DeployAdminAuthorizedKeys(s *mcclient.ClientSession) error {
}
oldKeys = string(output)
}
newKeys := MergeAuthorizedKeys(oldKeys, pubKeys)
newKeys := MergeAuthorizedKeys(oldKeys, pubKeys, true)
if output, err := procutils.NewRemoteCommandAsFarAsPossible(
"sh", "-c", fmt.Sprintf("echo '%s' > %s", newKeys, authFile)).Output(); err != nil {
return errors.Wrapf(err, "write public keys: %s", output)
+17 -6
View File
@@ -26,22 +26,33 @@ func TestMergeAuthorizedKeys(t *testing.T) {
pubkeys *deployapi.SSHKeys
}
tests := []struct {
name string
args args
want string
name string
args args
admin bool
want string
}{
{
name: "MergeAuthorizedKeys",
args: args{
oldKeys: "Test KEY",
oldKeys: "ssh-rsa KEY",
pubkeys: &deployapi.SSHKeys{},
},
want: "Test KEY\n",
admin: true,
want: "ssh-rsa KEY\n",
},
{
name: "MergeAuthorizedKeys",
args: args{
oldKeys: "ssh-rsa KEY " + sshKeySignature,
pubkeys: &deployapi.SSHKeys{},
},
admin: true,
want: "\n",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys); got != tt.want {
if got := MergeAuthorizedKeys(tt.args.oldKeys, tt.args.pubkeys, tt.admin); got != tt.want {
t.Errorf("MergeAuthorizedKeys() = %v, want %v", got, tt.want)
}
})
+3 -3
View File
@@ -222,7 +222,7 @@ func (l *sLinuxRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, pub
} else {
usrDir = path.Join("/home", selUsr)
}
return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false)
return DeployAuthorizedKeys(rootFs, usrDir, pubkeys, false, false)
}
func (d *SCoreOsRootFs) DeployQgaBlackList(rootFs IDiskPartition) error {
@@ -276,7 +276,7 @@ func (l *sLinuxRootFs) DeployYunionroot(rootFs IDiskPartition, pubkeys *deployap
return errors.Wrap(err, "unable to CheckOrAddUser")
}
log.Infof("DeployYunionroot %s home %s", yunionroot, rootdir)
err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true)
err = DeployAuthorizedKeys(rootFs, rootdir, pubkeys, true, true)
if err != nil {
log.Infof("DeployAuthorizedKeys error: %s", err.Error())
return fmt.Errorf("DeployAuthorizedKeys: %v", err)
@@ -1858,7 +1858,7 @@ func (d *SOpenWrtRootFs) DeployPublicKey(rootFs IDiskPartition, selUsr string, p
gid = 0
replace = false
)
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace)
return deployAuthorizedKeys(rootFs, authFile, uid, gid, pubkeys, replace, false)
}
return d.sLinuxRootFs.DeployPublicKey(rootFs, selUsr, pubkeys)
}
+1 -1
View File
@@ -75,7 +75,7 @@ func (m *SMacOSRootFs) RootSignatures() []string {
func (m *SMacOSRootFs) DeployPublicKey(rootfs IDiskPartition, uname string, pubkeys *deployapi.SSHKeys) error {
usrDir := fmt.Sprintf("/Users/%s", uname)
return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false)
return DeployAuthorizedKeys(m.rootFs, usrDir, pubkeys, false, false)
}
func (m *SMacOSRootFs) addScripts(lines []string) {