This commit is contained in:
Elouin 2024-06-01 19:24:19 +02:00
commit afde75508f
5 changed files with 82 additions and 0 deletions

16
basics/ssh/init.sls Normal file
View file

@ -0,0 +1,16 @@
ssh server installed:
pkg.installed:
- name: openssh-server
sshd config file is present:
file.managed:
- name: /etc/ssh/sshd_config
- source: salt://basics/ssh/sshd_config.jinja
- template: jinja
restart sshd service on config file change:
module.run:
- service.restart:
- name: sshd
- onchanges:
- file: /etc/ssh/sshd_config

View file

@ -0,0 +1,15 @@
Port {{ salt['pillar.get']('basics:ssh:port', 22) }}
PermitRootLogin {{ salt['pillar.get']('basics:ssh:permit_root_login', 'yes') }}
MaxSessions 1
PubkeyAuthentication {{ salt['pillar.get']('basics:ssh:pubkey_authentication', 'yes') }}
HostbasedAuthentication no
IgnoreRhosts yes
PasswordAuthentication {{ salt['pillar.get']('basics:ssh:password_authentication', 'no') }}
ChallengeResponseAuthentication no
UsePAM yes
AllowTcpForwarding {{ salt['pillar.get']('basics:ssh:allow_tcp_forwarding', 'no') }}
X11Forwarding {{ salt['pillar.get']('basics:ssh:x11_forwarding', 'no') }}
PrintMotd no
MaxStartups 5:50:30
AcceptEnv LANG LC_*
Subsystem sftp /usr/lib/openssh/sftp-server