ssh-client: the mesh's region first in ~/.ssh/config, its hosts in config.d, tools in Go
The region at the end let earlier Host lines win over the mesh's (research 027/03). A roster fact cannot be placed at the start, so the region holds one Include of config.d, and the hosts are config.d/00-mesh, read first. Eight tools; authorized_keys and known_hosts stay found until the controller holds those facts.
This commit is contained in:
@@ -1,6 +1,16 @@
|
||||
{
|
||||
"module": "ssh-client",
|
||||
"version": "1",
|
||||
"tools": [
|
||||
"ssh_client_hosts",
|
||||
"ssh_client_resolve",
|
||||
"ssh_client_check",
|
||||
"ssh_client_keys",
|
||||
"ssh_client_authorized",
|
||||
"ssh_client_revoke",
|
||||
"ssh_client_known_host",
|
||||
"ssh_client_test"
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "ssh-dir",
|
||||
@@ -8,14 +18,45 @@
|
||||
"path": "${machine:account-home}/.ssh",
|
||||
"owner": "${machine:account}",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "config-d",
|
||||
"type": "directory",
|
||||
"path": "${machine:account-home}/.ssh/config.d",
|
||||
"owner": "${machine:account}",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "file",
|
||||
"path": "${machine:account-home}/.ssh/config",
|
||||
"owner": "${machine:account}",
|
||||
"mode": "0600",
|
||||
"into": "block",
|
||||
"at": "start",
|
||||
"content": "# The mesh's region (module ssh-client, novox/hq research 027/03). It comes first because ssh\n# takes the first value it finds for each option. It brings in ~/.ssh/config.d/ in name order:\n# 00-mesh, the mesh's Host per machine, then each file another module places there. Replaced at\n# every push. Everything below it is yours, kept as you wrote it, and applies to every host the\n# files above leave unsettled.\nInclude ~/.ssh/config.d/*\n"
|
||||
}
|
||||
],
|
||||
"facts": {
|
||||
"ssh-config": {
|
||||
"path": ".ssh/config",
|
||||
"mesh-hosts": {
|
||||
"path": ".ssh/config.d/00-mesh",
|
||||
"home": true,
|
||||
"shared": true,
|
||||
"template": "# The mesh's Host blocks — every other node, so `ssh <node>` reaches it as the\n# right account. This region is replaced whenever a node joins, leaves or is\n# renamed; the rest of this file is yours and is kept untouched.\n{{range .Machines}}{{if ne .Name $.Node}}\nHost {{.Name}} {{.FQDN}}\n HostName {{.FQDN}}\n{{if .Account}} User {{.Account}}\n{{end}}{{end}}{{end}}"
|
||||
"template": "# Generated by the mesh. Do not edit — module ssh-client writes this file whenever a machine\n# joins, leaves or is renamed. ~/.ssh/config includes it first, so these hosts win over every\n# later line; a host of your own goes below the mesh's region in ~/.ssh/config.\n{{range .Machines}}{{if ne .Name $.Node}}\nHost {{.Name}} {{.FQDN}}\n HostName {{.FQDN}}\n{{if .Account}} User {{.Account}}\n{{end}}{{end}}{{end}}"
|
||||
}
|
||||
},
|
||||
"build": {
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "tools",
|
||||
"kind": "bundle",
|
||||
"language": "go",
|
||||
"system": "arch",
|
||||
"from": "cmd/ssh-client-tools",
|
||||
"binary": "ssh-client-tools",
|
||||
"loads": [
|
||||
"ssh-client-tools"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user