/
usr
/
lib
/
python3.6
/
site-packages
/
cloudinit
/
config
/
/usr/lib/python3.6/site-packages/cloudinit/config
mkdir
upload
Name
Size
Mode
Actions
schemas/
-
0755
rm
__pycache__/
-
0755
rm
cc_ansible.py
8894
0644
edit
dl
rm
cc_apk_configure.py
5792
0644
edit
dl
rm
cc_apt_configure.py
42995
0644
edit
dl
rm
cc_apt_pipelining.py
2771
0644
edit
dl
rm
cc_bootcmd.py
2921
0644
edit
dl
rm
cc_byobu.py
3738
0644
edit
dl
rm
cc_ca_certs.py
9347
0644
edit
dl
rm
cc_chef.py
14102
0644
edit
dl
rm
cc_disable_ec2_metadata.py
2074
0644
edit
dl
rm
cc_disk_setup.py
33136
0644
edit
dl
rm
cc_fan.py
3093
0644
edit
dl
rm
cc_final_message.py
3470
0644
edit
dl
rm
cc_growpart.py
21538
0644
edit
dl
rm
cc_grub_dpkg.py
6812
0644
edit
dl
rm
cc_install_hotplug.py
3904
0644
edit
dl
rm
cc_keyboard.py
2439
0644
edit
dl
rm
cc_keys_to_console.py
3694
0644
edit
dl
rm
cc_landscape.py
5433
0644
edit
dl
rm
cc_locale.py
1903
0644
edit
dl
rm
cc_lxd.py
18580
0644
edit
dl
rm
cc_mcollective.py
6251
0644
edit
dl
rm
cc_migrator.py
3569
0644
edit
dl
rm
cc_mounts.py
20186
0644
edit
dl
rm
cc_ntp.py
21341
0644
edit
dl
rm
cc_package_update_upgrade_install.py
4652
0644
edit
dl
rm
cc_phone_home.py
5615
0644
edit
dl
rm
cc_power_state_change.py
7591
0644
edit
dl
rm
cc_puppet.py
14435
0644
edit
dl
rm
cc_reset_rmc.py
4575
0644
edit
dl
rm
cc_resizefs.py
10983
0644
edit
dl
rm
cc_resolv_conf.py
5103
0644
edit
dl
rm
cc_rh_subscription.py
17378
0644
edit
dl
rm
cc_rightscale_userdata.py
4387
0644
edit
dl
rm
cc_rsyslog.py
13800
0644
edit
dl
rm
cc_runcmd.py
2974
0644
edit
dl
rm
cc_salt_minion.py
6022
0644
edit
dl
rm
cc_scripts_per_boot.py
1697
0644
edit
dl
rm
cc_scripts_per_instance.py
1852
0644
edit
dl
rm
cc_scripts_per_once.py
1803
0644
edit
dl
rm
cc_scripts_user.py
1893
0644
edit
dl
rm
cc_scripts_vendor.py
2347
0644
edit
dl
rm
cc_seed_random.py
4837
0644
edit
dl
rm
cc_set_hostname.py
5254
0644
edit
dl
rm
cc_set_passwords.py
11234
0644
edit
dl
rm
cc_snap.py
6448
0644
edit
dl
rm
cc_spacewalk.py
3514
0644
edit
dl
rm
cc_ssh.py
15216
0644
edit
dl
rm
cc_ssh_authkey_fingerprints.py
4318
0644
edit
dl
rm
cc_ssh_import_id.py
6264
0644
edit
dl
rm
cc_timezone.py
1492
0644
edit
dl
rm
cc_ubuntu_advantage.py
17411
0644
edit
dl
rm
cc_ubuntu_autoinstall.py
4604
0644
edit
dl
rm
cc_ubuntu_drivers.py
4668
0644
edit
dl
rm
cc_update_etc_hosts.py
5283
0644
edit
dl
rm
cc_update_hostname.py
3963
0644
edit
dl
rm
cc_users_groups.py
8777
0644
edit
dl
rm
cc_wireguard.py
9439
0644
edit
dl
rm
cc_write_files.py
6819
0644
edit
dl
rm
cc_write_files_deferred.py
1721
0644
edit
dl
rm
cc_yum_add_repo.py
7633
0644
edit
dl
rm
cc_zypper_add_repo.py
6749
0644
edit
dl
rm
modules.py
12019
0644
edit
dl
rm
schema.py
56165
0644
edit
dl
rm
__init__.py
14
0644
edit
dl
rm
Edit:
/usr/lib/python3.6/site-packages/cloudinit/config/cc_keys_to_console.py
(3694B)
# Copyright (C) 2011 Canonical Ltd. # Copyright (C) 2012 Hewlett-Packard Development Company, L.P. # # Author: Scott Moser <scott.moser@canonical.com> # Author: Juerg Haefliger <juerg.haefliger@hp.com> # # This file is part of cloud-init. See LICENSE file for license information. """Keys to Console: Control which SSH host keys may be written to console""" import logging import os from textwrap import dedent from cloudinit import subp, util from cloudinit.cloud import Cloud from cloudinit.config import Config from cloudinit.config.schema import MetaSchema, get_meta_doc from cloudinit.settings import PER_INSTANCE # This is a tool that cloud init provides HELPER_TOOL_TPL = "%s/cloud-init/write-ssh-key-fingerprints" distros = ["all"] meta: MetaSchema = { "id": "cc_keys_to_console", "name": "Keys to Console", "title": "Control which SSH host keys may be written to console", "description": ( "For security reasons it may be desirable not to write SSH host keys" " and their fingerprints to the console. To avoid either being written" " to the console the ``emit_keys_to_console`` config key under the" " main ``ssh`` config key can be used. To avoid the fingerprint of" " types of SSH host keys being written to console the" " ``ssh_fp_console_blacklist`` config key can be used. By default," " all types of keys will have their fingerprints written to console." " To avoid host keys of a key type being written to console the" "``ssh_key_console_blacklist`` config key can be used. By default," " ``ssh-dss`` host keys are not written to console." ), "distros": distros, "examples": [ dedent( """\ # Do not print any SSH keys to system console ssh: emit_keys_to_console: false """ ), dedent( """\ # Do not print certain ssh key types to console ssh_key_console_blacklist: [dsa, ssh-dss] """ ), dedent( """\ # Do not print specific ssh key fingerprints to console ssh_fp_console_blacklist: - E25451E0221B5773DEBFF178ECDACB160995AA89 - FE76292D55E8B28EE6DB2B34B2D8A784F8C0AAB0 """ ), ], "frequency": PER_INSTANCE, "activate_by_schema_keys": [], } __doc__ = get_meta_doc(meta) LOG = logging.getLogger(__name__) def _get_helper_tool_path(distro): try: base_lib = distro.usr_lib_exec except AttributeError: base_lib = "/usr/lib" return HELPER_TOOL_TPL % base_lib def handle(name: str, cfg: Config, cloud: Cloud, args: list) -> None: if util.is_false(cfg.get("ssh", {}).get("emit_keys_to_console", True)): LOG.debug( "Skipping module named %s, logging of SSH host keys disabled", name ) return helper_path = _get_helper_tool_path(cloud.distro) if not os.path.exists(helper_path): LOG.warning( "Unable to activate module %s, helper tool not found at %s", name, helper_path, ) return fp_blacklist = util.get_cfg_option_list( cfg, "ssh_fp_console_blacklist", [] ) key_blacklist = util.get_cfg_option_list( cfg, "ssh_key_console_blacklist", ["ssh-dss"] ) try: cmd = [helper_path, ",".join(fp_blacklist), ",".join(key_blacklist)] (stdout, _stderr) = subp.subp(cmd) util.multi_log("%s\n" % (stdout.strip()), stderr=False, console=True) except Exception: LOG.warning("Writing keys to the system console failed!") raise
Save
cmd:
run