blob: d92dc8ee4f1ae76045cce2bc4f271400d5b02708 [file] [log] [blame]
Filip Pytlouna1898572016-01-25 22:35:13 +01001linux:
2 system:
3 enabled: true
4 cluster: default
Petr Michalec1c4c8d82017-02-28 19:09:21 +01005 name: linux
Filip Pytlouna1898572016-01-25 22:35:13 +01006 domain: local
7 environment: prd
Petr Michalec1c4c8d82017-02-28 19:09:21 +01008 hostname: system.pillar.local
Filip Pytlouna1898572016-01-25 22:35:13 +01009 apparmor:
10 enabled: false
Filip Pytloun8296bb92016-02-19 18:42:09 +010011 haveged:
12 enabled: true
Filip Pytlouna1898572016-01-25 22:35:13 +010013 prompt:
Petr Michalec1c4c8d82017-02-28 19:09:21 +010014 default: "linux.ci.local$"
Jakub Pavlikb148c8c2017-02-12 21:30:48 +010015 kernel:
Jakub Pavlik6c9ead12017-02-16 21:53:13 +010016 isolcpu: 1,2,3,4
Filip Pytlouna1898572016-01-25 22:35:13 +010017 motd:
18 - warning: |
19 #!/bin/sh
20 printf "WARNING: This is tcpcloud network.\n"
21 printf " Unauthorized access is strictly prohibited.\n"
22 printf "\n"
23 - info: |
24 #!/bin/sh
25 printf -- "--[tcp cloud]---------------------------\n"
26 printf " Hostname | ${linux:system:name}\n"
27 printf " Domain | ${linux:system:domain}\n"
28 printf " System | %s\n" "$(lsb_release -s -d)"
29 printf " Kernel | %s\n" "$(uname -r)"
30 printf -- "----------------------------------------\n"
31 printf "\n"
32 user:
33 root:
34 enabled: true
35 home: /root
36 name: root
37 test:
38 enabled: true
39 name: test
40 sudo: true
41 uid: 9999
42 full_name: Test User
43 home: /home/test
Petr Michalec1c4c8d82017-02-28 19:09:21 +010044 groups:
45 - root
46 salt_user1:
47 enabled: true
48 name: saltuser1
49 sudo: false
50 uid: 9991
51 full_name: Salt User1
52 home: /home/saltuser1
53 salt_user2:
54 enabled: true
55 name: saltuser2
56 sudo: false
57 uid: 9992
58 full_name: Salt Sudo User2
59 home: /home/saltuser2
Filip Pytlouna1898572016-01-25 22:35:13 +010060 group:
61 test:
62 enabled: true
63 name: test
64 gid: 9999
65 system: true
Petr Michalec1c4c8d82017-02-28 19:09:21 +010066 db-ops:
67 enabled: true
68 name: testgroup
69 salt-ops:
70 enabled: true
71 name: sudogroup0
72 sudogroup1:
73 enabled: true
74 name: sudogroup1
75 sudogroup2:
76 enabled: true
77 name: sudogroup2
78 sudogroup3:
79 enabled: false
80 name: sudogroup3
Filip Pytlouna1898572016-01-25 22:35:13 +010081 job:
82 test:
83 enabled: true
84 command: "/bin/sleep 3"
85 user: test
86 minute: 0
87 hour: 13
88 package:
89 htop:
90 version: latest
91 repo:
92 opencontrail:
93 source: "deb http://ppa.launchpad.net/tcpcloud/contrail-2.20/ubuntu trusty main"
94 architectures: amd64
Filip Pytlounc49445a2016-04-04 14:23:20 +020095 locale:
96 en_US.UTF-8:
97 enabled: true
98 default: true
Filip Pytlounee1745f2016-04-04 17:39:41 +020099 "cs_CZ.UTF-8 UTF-8":
Filip Pytlounc49445a2016-04-04 14:23:20 +0200100 enabled: true
Filip Pytlounc665ee22017-02-17 12:17:32 +0100101 autoupdates:
102 enabled: true
Petr Michalec1c4c8d82017-02-28 19:09:21 +0100103 sudo:
104 enabled: true
105 alias:
106 runas:
107 DBA:
108 - postgres
109 - mysql
110 SALT:
111 - root
112 host:
113 LOCAL:
114 - localhost
115 PRODUCTION:
116 - db1
117 - db2
118 command:
119 SUDO_RESTRICTED_SU:
120 - /bin/vi /etc/sudoers
121 - /bin/su - root
122 - /bin/su -
123 - /bin/su
124 - /usr/sbin/visudo
125 SUDO_SHELLS:
126 - /bin/sh
127 - /bin/ksh
128 - /bin/bash
129 - /bin/rbash
130 - /bin/dash
131 - /bin/zsh
132 - /bin/csh
133 - /bin/fish
134 - /bin/tcsh
135 - /usr/bin/login
136 - /usr/bin/su
137 - /usr/su
138 SUDO_SALT_SAFE:
139 - /usr/bin/salt state*
140 - /usr/bin/salt service*
141 - /usr/bin/salt pillar*
142 - /usr/bin/salt grains*
143 - /usr/bin/salt saltutil*
144 - /usr/bin/salt-call state*
145 - /usr/bin/salt-call service*
146 - /usr/bin/salt-call pillar*
147 - /usr/bin/salt-call grains*
148 - /usr/bin/salt-call saltutil*
149 SUDO_SALT_TRUSTED:
150 - /usr/bin/salt*
151 users:
152 saltuser1: {}
153 saltuser2:
154 hosts:
155 - LOCAL
156 # User Alias:
157 DBA:
158 hosts:
159 - ALL
160 commands:
161 - SUDO_SALT_SAFE
162 groups:
163 db-ops:
164 hosts:
165 - ALL
166 - '!PRODUCTION'
167 runas:
168 - DBA
169 commands:
170 - /bin/cat *
171 - /bin/less *
172 - /bin/ls *
173 - SUDO_SALT_SAFE
174 - '!SUDO_SHELLS'
175 - '!SUDO_RESTRICTED_SU'
176 salt-ops:
177 hosts:
178 - 'ALL'
179 runas:
180 - SALT
181 commands:
182 - SUDO_SALT_TRUSTED
183 salt-ops2:
184 name: salt-ops
185 runas:
186 - DBA
187 commands:
188 - SUDO_SHELLS
189 sudogroup1:
190 commands:
191 - ALL
192 sudogroup2:
193 commands:
194 - ALL
195 hosts:
196 - localhost
197 users:
198 - test
199 nopasswd: false
200 sudogroup3:
201 commands:
202 - ALL