OXIESEC PANEL
- Current Dir:
/
/
snap
/
core24
/
888
/
usr
/
lib
/
python3
/
dist-packages
/
cloudinit
/
config
Server IP: 139.59.38.164
Upload:
Create Dir:
Name
Size
Modified
Perms
📁
..
-
03/18/2025 08:12:15 AM
rwxr-xr-x
📄
__init__.py
40 bytes
01/15/2025 03:24:11 PM
rw-r--r--
📁
__pycache__
-
03/18/2025 08:12:15 AM
rwxr-xr-x
📄
cc_ansible.py
7.74 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_apk_configure.py
4.23 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_apt_configure.py
38.08 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_apt_pipelining.py
1.85 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_bootcmd.py
1.75 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_byobu.py
2.73 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ca_certs.py
8.67 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_chef.py
12.19 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_disable_ec2_metadata.py
1.6 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_disk_setup.py
29.61 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_fan.py
1.95 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_final_message.py
2.51 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_growpart.py
18.37 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_grub_dpkg.py
5.39 KB
02/04/2025 10:36:06 PM
rw-r--r--
📄
cc_install_hotplug.py
3.19 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_keyboard.py
1.49 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_keys_to_console.py
2.09 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_landscape.py
3.06 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_locale.py
1.19 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_lxd.py
13.47 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_mcollective.py
4.11 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_mounts.py
18.16 KB
02/04/2025 10:36:06 PM
rw-r--r--
📄
cc_ntp.py
18.97 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_package_update_upgrade_install.py
3.99 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_phone_home.py
3.75 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_power_state_change.py
6.09 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_puppet.py
10.72 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_reset_rmc.py
4.33 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_resizefs.py
10.63 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_resolv_conf.py
3.13 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_rh_subscription.py
15.21 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_rsyslog.py
11.55 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_runcmd.py
1.6 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_salt_minion.py
3.96 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_scripts_per_boot.py
1.27 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_scripts_per_instance.py
1.26 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_scripts_per_once.py
1.24 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_scripts_user.py
1.25 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_scripts_vendor.py
1.26 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_seed_random.py
3 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_set_hostname.py
3.4 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_set_passwords.py
9.36 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_snap.py
3.36 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_spacewalk.py
2.64 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ssh.py
11 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ssh_authkey_fingerprints.py
3.76 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ssh_import_id.py
5.43 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_timezone.py
1.14 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ubuntu_autoinstall.py
2.99 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ubuntu_drivers.py
4.08 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_ubuntu_pro.py
13.65 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_update_etc_hosts.py
2.46 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_update_hostname.py
2.18 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_users_groups.py
2.86 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_wireguard.py
6.67 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_write_files.py
6 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_write_files_deferred.py
1.28 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_yum_add_repo.py
4.53 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
cc_zypper_add_repo.py
4.93 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
modules.py
13.23 KB
01/15/2025 03:24:11 PM
rw-r--r--
📄
schema.py
50.86 KB
01/15/2025 03:24:11 PM
rw-r--r--
📁
schemas
-
03/18/2025 08:12:15 AM
rwxr-xr-x
Editing: cc_ansible.py
Close
"""ansible enables running on first boot either ansible-pull""" import abc import logging import os import re import sys import sysconfig from copy import deepcopy from typing import Optional from cloudinit import lifecycle, signal_handler, subp from cloudinit.cloud import Cloud from cloudinit.config import Config from cloudinit.config.schema import MetaSchema from cloudinit.distros import ALL_DISTROS, Distro from cloudinit.settings import PER_INSTANCE from cloudinit.util import get_cfg_by_path meta: MetaSchema = { "id": "cc_ansible", "frequency": PER_INSTANCE, "distros": [ALL_DISTROS], "activate_by_schema_keys": ["ansible"], } LOG = logging.getLogger(__name__) CFG_OVERRIDE = "ansible_config" class AnsiblePull(abc.ABC): def __init__(self, distro: Distro): self.cmd_pull = ["ansible-pull"] self.cmd_version = ["ansible-pull", "--version"] self.distro = distro self.env = {} self.run_user: Optional[str] = None # some ansible modules directly reference os.environ["HOME"] # and cloud-init might not have that set, default: /root self.env["HOME"] = os.environ.get("HOME", "/root") def get_version(self) -> Optional[lifecycle.Version]: stdout, _ = self.do_as(self.cmd_version) first_line = stdout.splitlines().pop(0) matches = re.search(r"([\d\.]+)", first_line) if matches: version = matches.group(0) return lifecycle.Version.from_str(version) return None def pull(self, *args) -> str: stdout, _ = self.do_as([*self.cmd_pull, *args]) return stdout def check_deps(self): if not self.is_installed(): raise ValueError("command: ansible is not installed") def do_as(self, command: list, **kwargs): if not self.run_user: return self.subp(command, **kwargs) return self.distro.do_as(command, self.run_user, **kwargs) def subp(self, command, **kwargs): with signal_handler.suspend_crash(): return subp.subp(command, update_env=self.env, **kwargs) @abc.abstractmethod def is_installed(self): pass @abc.abstractmethod def install(self, pkg_name: str): pass class AnsiblePullPip(AnsiblePull): def __init__(self, distro: Distro, user: Optional[str]): super().__init__(distro) self.run_user = user # Add pip install site to PATH user_base, _ = self.do_as( [sys.executable, "-c", "'import site; print(site.getuserbase())'"] ) ansible_path = f"{user_base}/bin/" old_path = self.env.get("PATH") if old_path: self.env["PATH"] = ":".join([old_path, ansible_path]) else: self.env["PATH"] = ansible_path def install(self, pkg_name: str): """should cloud-init grow an interface for non-distro package managers? this seems reusable """ if not self.is_installed(): # bootstrap pip if required try: import pip # noqa: F401 except ImportError: self.distro.install_packages([self.distro.pip_package_name]) cmd = [ sys.executable, "-m", "pip", "install", ] if os.path.exists( os.path.join( sysconfig.get_path("stdlib"), "EXTERNALLY-MANAGED" ) ): cmd.append("--break-system-packages") if self.run_user: cmd.append("--user") self.do_as([*cmd, "--upgrade", "pip"]) self.do_as([*cmd, pkg_name]) def is_installed(self) -> bool: stdout, _ = self.do_as([sys.executable, "-m", "pip", "list"]) return "ansible" in stdout class AnsiblePullDistro(AnsiblePull): def install(self, pkg_name: str): if not self.is_installed(): self.distro.install_packages([pkg_name]) def is_installed(self) -> bool: return bool(subp.which("ansible")) def handle(name: str, cfg: Config, cloud: Cloud, args: list) -> None: ansible_cfg: dict = cfg.get("ansible", {}) ansible_user = ansible_cfg.get("run_user") install_method = ansible_cfg.get("install_method") setup_controller = ansible_cfg.get("setup_controller") galaxy_cfg = ansible_cfg.get("galaxy") pull_cfg = ansible_cfg.get("pull") package_name = ansible_cfg.get("package_name", "") if ansible_cfg: ansible: AnsiblePull validate_config(ansible_cfg) distro: Distro = cloud.distro if install_method == "pip": ansible = AnsiblePullPip(distro, ansible_user) else: ansible = AnsiblePullDistro(distro) ansible.install(package_name) ansible.check_deps() ansible_config = ansible_cfg.get("ansible_config", "") if ansible_config: ansible.env[CFG_OVERRIDE] = ansible_config if galaxy_cfg: ansible_galaxy(galaxy_cfg, ansible) if pull_cfg: run_ansible_pull(ansible, deepcopy(pull_cfg)) if setup_controller: ansible_controller(setup_controller, ansible) def validate_config(cfg: dict): required_keys = ( "install_method", "package_name", ) for key in required_keys: if not get_cfg_by_path(cfg, key): raise ValueError(f"Missing required key '{key}' from {cfg}") if cfg.get("pull"): for key in "pull/url", "pull/playbook_name": if not get_cfg_by_path(cfg, key): raise ValueError(f"Missing required key '{key}' from {cfg}") controller_cfg = cfg.get("setup_controller") if controller_cfg: if not any( [ controller_cfg.get("repositories"), controller_cfg.get("run_ansible"), ] ): raise ValueError(f"Missing required key from {controller_cfg}") install = cfg["install_method"] if install not in ("pip", "distro"): raise ValueError("Invalid install method {install}") def filter_args(cfg: dict) -> dict: """remove boolean false values""" return { key.replace("_", "-"): value for (key, value) in cfg.items() if value is not False } def run_ansible_pull(pull: AnsiblePull, cfg: dict): playbook_name: str = cfg.pop("playbook_name") v = pull.get_version() if not v: LOG.warning("Cannot parse ansible version") elif v < lifecycle.Version(2, 7, 0): # diff was added in commit edaa0b52450ade9b86b5f63097ce18ebb147f46f if cfg.get("diff"): raise ValueError( f"Ansible version {v.major}.{v.minor}.{v.patch}" "doesn't support --diff flag, exiting." ) stdout = pull.pull( *[ f"--{key}={value}" if value is not True else f"--{key}" for key, value in filter_args(cfg).items() ], playbook_name, ) if stdout: sys.stdout.write(f"{stdout}") def ansible_galaxy(cfg: dict, ansible: AnsiblePull): actions = cfg.get("actions", []) if not actions: LOG.warning("Invalid config: %s", cfg) for command in actions: ansible.do_as(command) def ansible_controller(cfg: dict, ansible: AnsiblePull): for repository in cfg.get("repositories", []): ansible.do_as( ["git", "clone", repository["source"], repository["path"]] ) for args in cfg.get("run_ansible", []): playbook_dir = args.pop("playbook_dir") playbook_name = args.pop("playbook_name") command = [ "ansible-playbook", playbook_name, *[f"--{key}={value}" for key, value in filter_args(args).items()], ] ansible.do_as(command, cwd=playbook_dir)