基于Ruby开发Puppet函数生成StandardPasswordEncoder密码哈希
Solution: Puppet Function for Spring Security StandardPasswordEncoder Hashes
To generate password hashes compatible with org.springframework.security.crypto.password.StandardPasswordEncoder directly in Puppet, you can create a custom Ruby function that replicates the encoder's core logic. Here's a complete, production-ready implementation:
Step 1: Create the Puppet Function
Place this file in your Puppet module's lib/puppet/functions directory (e.g., modules/your_app/lib/puppet/functions/spring_security_standard_password_hash.rb):
Puppet::Functions.create_function(:spring_security_standard_password_hash) do dispatch :generate_hash do param 'String', :password return_type 'String' end def generate_hash(password) require 'openssl' require 'securerandom' require 'base64' # Generate 8-byte random salt (matches StandardPasswordEncoder's default) salt = SecureRandom.random_bytes(8) # Compute SHA-256 hash of UTF-8 encoded password + salt bytes password_bytes = password.encode('UTF-8') hash_bytes = OpenSSL::Digest::SHA256.digest(password_bytes + salt) # Base64 encode both salt and hash using strict (non-wrapping) encoding salt_base64 = Base64.strict_encode64(salt) hash_base64 = Base64.strict_encode64(hash_bytes) # Format to match Spring's expected {salt}hash structure "{#{salt_base64}}#{hash_base64}" end end
Step 2: Use the Function in Your Puppet Workflow
Once deployed with your module, you can use this function to generate hashes from your encrypted passwords stored in hieradata (eyaml):
Example Puppet Manifest
# Retrieve plaintext password from encrypted hieradata $plaintext_password = lookup('your_app.admin.password', String) # Generate Spring-compatible password hash $password_hash = spring_security_standard_password_hash($plaintext_password) # Inject the hash into your application configuration file '/opt/your_app/config/application.yml' do content template('your_app/application.yml.erb') mode '0640' owner 'your_app' end
Example ERB Template (application.yml.erb)
security: users: admin: password: <%= @password_hash %>
Key Implementation Details
- Salt Generation: Uses
SecureRandomto create an 8-byte random salt (the default forStandardPasswordEncoder). Adjust therandom_bytesargument if your application uses a custom salt length. - Hashing Logic: Exact replication of Spring's algorithm: SHA-256 digest of the UTF-8 encoded password concatenated with raw salt bytes.
- Formatting: Produces the
{base64_salt}base64_hashstring format that Spring's encoder expects for verification.
Important Notes
- Hash Volatility: Each Puppet run generates a new salt, so the hash will change even for the same password. This is secure behavior—Spring extracts the salt from the hash during validation and will still verify correctly.
- Security: Storing plaintext passwords in encrypted eyaml ensures they never appear in plaintext in your Puppet code, logs, or infrastructure. Hash generation happens locally on the Puppet agent/master.
- Dependencies: Uses only Ruby's standard libraries (
openssl,securerandom,base64)—no extra gems are required for modern Puppet distributions.
内容的提问来源于stack exchange,提问作者Christian Meißner
相关产品推荐
相关产品推荐

