You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Ruby开发Puppet函数生成StandardPasswordEncoder密码哈希

Solution: Puppet Function for Spring Security StandardPasswordEncoder Hashes

To generate password hashes compatible with org.springframework.security.crypto.password.StandardPasswordEncoder directly in Puppet, you can create a custom Ruby function that replicates the encoder's core logic. Here's a complete, production-ready implementation:

Step 1: Create the Puppet Function

Place this file in your Puppet module's lib/puppet/functions directory (e.g., modules/your_app/lib/puppet/functions/spring_security_standard_password_hash.rb):

Puppet::Functions.create_function(:spring_security_standard_password_hash) do
  dispatch :generate_hash do
    param 'String', :password
    return_type 'String'
  end

  def generate_hash(password)
    require 'openssl'
    require 'securerandom'
    require 'base64'

    # Generate 8-byte random salt (matches StandardPasswordEncoder's default)
    salt = SecureRandom.random_bytes(8)
    
    # Compute SHA-256 hash of UTF-8 encoded password + salt bytes
    password_bytes = password.encode('UTF-8')
    hash_bytes = OpenSSL::Digest::SHA256.digest(password_bytes + salt)
    
    # Base64 encode both salt and hash using strict (non-wrapping) encoding
    salt_base64 = Base64.strict_encode64(salt)
    hash_base64 = Base64.strict_encode64(hash_bytes)
    
    # Format to match Spring's expected {salt}hash structure
    "{#{salt_base64}}#{hash_base64}"
  end
end

Step 2: Use the Function in Your Puppet Workflow

Once deployed with your module, you can use this function to generate hashes from your encrypted passwords stored in hieradata (eyaml):

Example Puppet Manifest

# Retrieve plaintext password from encrypted hieradata
$plaintext_password = lookup('your_app.admin.password', String)

# Generate Spring-compatible password hash
$password_hash = spring_security_standard_password_hash($plaintext_password)

# Inject the hash into your application configuration
file '/opt/your_app/config/application.yml' do
  content template('your_app/application.yml.erb')
  mode '0640'
  owner 'your_app'
end

Example ERB Template (application.yml.erb)

security:
  users:
    admin:
      password: <%= @password_hash %>

Key Implementation Details

  • Salt Generation: Uses SecureRandom to create an 8-byte random salt (the default for StandardPasswordEncoder). Adjust the random_bytes argument if your application uses a custom salt length.
  • Hashing Logic: Exact replication of Spring's algorithm: SHA-256 digest of the UTF-8 encoded password concatenated with raw salt bytes.
  • Formatting: Produces the {base64_salt}base64_hash string format that Spring's encoder expects for verification.

Important Notes

  • Hash Volatility: Each Puppet run generates a new salt, so the hash will change even for the same password. This is secure behavior—Spring extracts the salt from the hash during validation and will still verify correctly.
  • Security: Storing plaintext passwords in encrypted eyaml ensures they never appear in plaintext in your Puppet code, logs, or infrastructure. Hash generation happens locally on the Puppet agent/master.
  • Dependencies: Uses only Ruby's standard libraries (openssl, securerandom, base64)—no extra gems are required for modern Puppet distributions.

内容的提问来源于stack exchange,提问作者Christian Meißner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:20:50