aboutsummaryrefslogtreecommitdiff
path: root/manifests
diff options
context:
space:
mode:
authorMicah <micah@riseup.net>2015-10-09 19:02:41 +0000
committerMicah <micah@riseup.net>2015-10-09 19:02:41 +0000
commitb3e81589eec604768e08ed56ce5ca42a4b33db89 (patch)
tree6d05e753d1091049a2dbfb0cb3dddfbc9c99a021 /manifests
parent571373e0817a6441fb53303736a4666f2a672f26 (diff)
parent6ea0beb114cdb836cfe9b3ef67504f3641c518ca (diff)
downloadpuppet-sshd-b3e81589eec604768e08ed56ce5ca42a4b33db89.tar.gz
puppet-sshd-b3e81589eec604768e08ed56ce5ca42a4b33db89.tar.bz2
Merge branch 'autossh' into 'master'
autossh support this series of commits adds support for autossh, to automatically create a tunnel with port forwarding. we use this to login to *really* remote servers reliably, behind multiple NATs and satellite connexions. it rocks. See merge request !18
Diffstat (limited to 'manifests')
-rw-r--r--manifests/autossh.pp40
1 files changed, 40 insertions, 0 deletions
diff --git a/manifests/autossh.pp b/manifests/autossh.pp
new file mode 100644
index 0000000..5650584
--- /dev/null
+++ b/manifests/autossh.pp
@@ -0,0 +1,40 @@
+class sshd::autossh($host,
+ $port = undef, # this should be a remote->local hash
+ $remote_user = undef,
+ $user = 'root',
+ $pidfile = '/var/run/autossh.pid',
+) {
+ if $port {
+ $port_ensure = $port
+ }
+ else {
+ # random port between 10000 and 20000
+ $port_ensure = fqdn_rand(10000) + 10000
+ }
+ if $remote_user {
+ $remote_user_ensure = $remote_user
+ }
+ else {
+ $remote_user_ensure = "host-$fqdn"
+ }
+ file {
+ '/etc/init.d/autossh':
+ mode => '0555',
+ source => 'puppet:///modules/sshd/autossh.init.d';
+ '/etc/default/autossh':
+ mode => '0444',
+ content => "USER=$user\nPIDFILE=$pidfile\nDAEMON_ARGS='-M0 -f -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -q -N -R $port_ensure:localhost:22 $remote_user_ensure@$host'\n";
+ }
+ package { 'autossh':
+ ensure => present,
+ }
+ service { 'autossh':
+ ensure => running,
+ enable => true,
+ subscribe => [
+ File['/etc/init.d/autossh'],
+ File['/etc/default/autossh'],
+ Package['autossh'],
+ ],
+ }
+}