From cea9a67ef9ec14224451f8739d3a8912fd86a4c6 Mon Sep 17 00:00:00 2001 From: Eldo Varghese Date: Mon, 26 Aug 2019 17:57:30 -0700 Subject: [PATCH] migrating over to aws --- sudoers/files/sudoers | 10 +++++----- sudoers/init.sls | 4 ++-- sudoers/map.jinja | 2 +- 3 files changed, 8 insertions(+), 8 deletions(-) diff --git a/sudoers/files/sudoers b/sudoers/files/sudoers index 1786748..e5a5c04 100644 --- a/sudoers/files/sudoers +++ b/sudoers/files/sudoers @@ -1,4 +1,4 @@ -{% from "sudoers/map.jinja" import ad_group_maps with context %} +{% from "sudoers/map.jinja" import plos_group_maps with context %} {%- if (not included) %} {%- set sudoers = pillar.get('sudoers', {}) %} {%- if grains['os_family'] == 'Debian' %} @@ -95,11 +95,11 @@ Runas_Alias {{ name }} = {{ ",".join(runas) }} %{{ group }} {{ spec }} {%- endfor %} {%- endfor %} -{%- for unix_group in ad_groups %} - {%- if unix_group in ad_group_maps.keys() %} -%{{ unix_group }} {{ ad_group_maps[unix_group] }} +{%- for unix_group in plos_groups %} + {%- if unix_group in plos_group_maps.keys() %} +%{{ unix_group }} {{ plos_group_maps[unix_group] }} {%- else %} -%{{ unix_group }} {{ ad_group_maps['default'] }} +%{{ unix_group }} {{ plos_group_maps['default'] }} {%- endif %} {%- endfor %} diff --git a/sudoers/init.sls b/sudoers/init.sls index 6859af7..3fb0332 100644 --- a/sudoers/init.sls +++ b/sudoers/init.sls @@ -1,7 +1,7 @@ {% from "sudoers/map.jinja" import sudoers with context %} # our list of plos core active directory groups -{%- set ad_groups = salt['pillar.get']('group_map:core').keys() %} +{%- set plos_groups = salt['pillar.get']('group_map:core').keys() %} sudo: pkg.installed: @@ -17,6 +17,6 @@ sudo: - check_cmd: {{ sudoers.get('exec-prefix', '/usr/sbin') }}/visudo -c -f - context: included: False - ad_groups: {{ ad_groups|tojson }} + plos_groups: {{ plos_groups|tojson }} - require: - pkg: sudo diff --git a/sudoers/map.jinja b/sudoers/map.jinja index 120fd2a..529edb8 100644 --- a/sudoers/map.jinja +++ b/sudoers/map.jinja @@ -16,7 +16,7 @@ }, merge=salt['pillar.get']('sudoers:lookup', None)) %} # our plos active directory core groups sudoers permissions, filtered by environment -{% set ad_group_maps = salt['grains.filter_by']({ +{% set plos_group_maps = salt['grains.filter_by']({ 'default': { 'default': 'ALL = (root) NOEXEC:NOPASSWD: SUPPORT' }, 'vagrant': { 'default': 'ALL = (ALL:ALL) NOPASSWD: ALL' }, 'dev': { 'default': 'ALL = (ALL:ALL) NOPASSWD: ALL' },