from os.path import join, exists directories = {} users = {} files = {} groups = {} users['root'] = { 'home': '/root', 'shell': '/bin/bash', 'password': repo.vault.human_password_for('root on {}'.format(node.name)), } files['/etc/bash.bashrc'] = { 'source': 'bashrc', 'content_type': 'mako', } files['/etc/tmux.conf'] = { 'source': 'tmux.conf', 'content_type': 'mako', } files['/etc/vim/vimrc.local'] = { 'source': 'vimrc', } for username, attrs in node.metadata['users'].items(): home = attrs.get('home', '/home/{}'.format(username)) if attrs.get('delete', False): users[username] = {'delete': True} files[home] = {'delete': True} else: user = users.setdefault(username, {}) user['home'] = home user['shell'] = '/bin/bash' user['password_hash'] = 'x' if 'groups' in attrs: user['groups'] = attrs['groups'] directories[home] = { 'owner': username, 'mode': attrs.get('home-mode', '0700'), } if 'ssh_pubkey' in attrs: files[home + '/.ssh/authorized_keys'] = { 'content': "\n".join(attrs['ssh_pubkey']), 'owner': username, 'mode': '0600', } elif not attrs.get('do_not_remove_authorized_keys_from_home', False): files[home + '/.ssh/authorized_keys'] = {'delete': True} if exists(join(repo.path, 'data', 'users', 'files', 'tmux', '{}.conf'.format(username))): files[home + '/.tmux.conf'] = { 'content_type': 'mako', 'source': 'tmux/{}.conf'.format(username), } else: files[home + '/.tmux.conf'] = { 'delete': True, } files[home + '/.config/fish'] = { 'delete': True } if exists(join(repo.path, 'data', 'users', 'files', 'bash', '{}.bashrc'.format(username))): files[home + '/.bashrc'] = { 'content_type': 'mako', 'source': 'bash/{}.bashrc'.format(username), } else: files[home + '/.bashrc'] = { 'delete': True, }