You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Puppet实现sshd_config.d自定义文件覆盖sshd_config默认配置并解决冲突?

问题描述

我安装的OpenSSH RPM包版本如下:

openssh-clients-8.0p1-13.el8.x86_64
openssh-8.0p1-13.el8.x86_64
openssh-server-8.0p1-13.el8.x86_64

默认的/etc/ssh/sshd_config文件中没有Include指令,执行grep -nr "Include" /etc/ssh/sshd_config无输出,且/etc/ssh/sshd_config.d目录也不是由RPM包创建的。我自行创建了这个目录,并在sshd_config文件末尾添加了Include /etc/ssh/sshd_config.d/*.conf。

之后我通过Puppet的ssh模块,将sshd_config_path参数设置为/etc/sshd_config.d/custom_sshd_config.conf,想以此覆盖默认配置,但该模块会复制默认sshd_config的内容并按配置替换行,导致出现大量重复、冲突的配置项。例如:

sshd_config内容:

HostKey /etc/ssh/ssh_host_rsa_key # duplicate
HostKey /etc/ssh/ssh_host_ecdsa_key
HostKey /etc/ssh/ssh_host_ed25519_key
Subsystem sftp /usr/libexec/openssh/sftp-server 

sshd_config.d/custom_sshd_config.conf内容:

HostKey /etc/ssh/ssh_host_rsa_key  # duplicate (由Puppet ssh模块自动添加)
Subsystem sftp /usr/libexec/openssh/sftp-server # 当两处都定义Subsystem时,sshd服务启动失败,我只能手动注释其中一个文件里的配置

执行sshd -T可以看到输出中存在重复项:

...
hostkey /etc/ssh/ssh_host_rsa_key
hostkey /etc/ssh/ssh_host_ecdsa_key
hostkey /etc/ssh/ssh_host_ed25519_key
hostkey /etc/ssh/ssh_host_rsa_key
...

我尝试将Include指令移到文件顶部,也无法解决问题。我了解sshd手册中的说明:

first obtained value for each parameter is used in sshd : Order matters only when conflicting parameters exist, as the first obtained value for each parameter is used

直接用Puppet覆盖整个sshd_config文件可以解决重复冲突,但我需要维护独立的自定义配置文件,不想直接修改原sshd_config。

我期望通过Include引入的文件能作为sshd_config默认配置的覆盖项,请问能否通过Puppet实现自动化:当自定义文件中覆盖某项配置时,自动注释默认sshd_config中的对应项,从而实现真正的覆盖?


内容的提问来源于stack exchange,提问作者anonymous user

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 16:40:22