如何用Puppet实现sshd_config.d自定义文件覆盖sshd_config默认配置并解决冲突?
我安装的OpenSSH RPM包版本如下:
openssh-clients-8.0p1-13.el8.x86_64 openssh-8.0p1-13.el8.x86_64 openssh-server-8.0p1-13.el8.x86_64
默认的/etc/ssh/sshd_config文件中没有Include指令,执行grep -nr "Include" /etc/ssh/sshd_config无输出,且/etc/ssh/sshd_config.d目录也不是由RPM包创建的。我自行创建了这个目录,并在sshd_config文件末尾添加了Include /etc/ssh/sshd_config.d/*.conf。
之后我通过Puppet的ssh模块,将sshd_config_path参数设置为/etc/sshd_config.d/custom_sshd_config.conf,想以此覆盖默认配置,但该模块会复制默认sshd_config的内容并按配置替换行,导致出现大量重复、冲突的配置项。例如:
sshd_config内容:
HostKey /etc/ssh/ssh_host_rsa_key # duplicate HostKey /etc/ssh/ssh_host_ecdsa_key HostKey /etc/ssh/ssh_host_ed25519_key Subsystem sftp /usr/libexec/openssh/sftp-server
sshd_config.d/custom_sshd_config.conf内容:
HostKey /etc/ssh/ssh_host_rsa_key # duplicate (由Puppet ssh模块自动添加) Subsystem sftp /usr/libexec/openssh/sftp-server # 当两处都定义Subsystem时,sshd服务启动失败,我只能手动注释其中一个文件里的配置
执行sshd -T可以看到输出中存在重复项:
... hostkey /etc/ssh/ssh_host_rsa_key hostkey /etc/ssh/ssh_host_ecdsa_key hostkey /etc/ssh/ssh_host_ed25519_key hostkey /etc/ssh/ssh_host_rsa_key ...
我尝试将Include指令移到文件顶部,也无法解决问题。我了解sshd手册中的说明:
first obtained value for each parameter is used in sshd : Order matters only when conflicting parameters exist, as the first obtained value for each parameter is used
直接用Puppet覆盖整个sshd_config文件可以解决重复冲突,但我需要维护独立的自定义配置文件,不想直接修改原sshd_config。
我期望通过Include引入的文件能作为sshd_config默认配置的覆盖项,请问能否通过Puppet实现自动化:当自定义文件中覆盖某项配置时,自动注释默认sshd_config中的对应项,从而实现真正的覆盖?
内容的提问来源于stack exchange,提问作者anonymous user

