doas

pdk
Manage doas.conf(5)

230 downloads

211 latest version

5.0 quality score

Version information

  • 0.1.1 (latest)
  • 0.1.0 (deleted)
released Jun 8th 2023
This version is compatible with:
  • Puppet Enterprise 2023.2.x, 2023.1.x, 2023.0.x, 2021.7.x, 2021.6.x, 2021.5.x, 2021.4.x, 2021.3.x, 2021.2.x, 2021.1.x, 2021.0.x, 2019.8.x
  • Puppet >= 6.21.0 < 8.0.0
  • OpenBSD

Start using this module

  • r10k or Code Manager
  • Bolt
  • Manual installation
  • Direct download

Add this module to your Puppetfile:

mod 'kn-doas', '0.1.1'
Learn more about managing modules with a Puppetfile

Add this module to your Bolt project:

bolt module add kn-doas
Learn more about using this module with an existing project

Manually install this module globally with Puppet module tool:

puppet module install kn-doas --version 0.1.1

Direct download is not typically how you would use a Puppet module to manage your infrastructure, but you may want to download the module in order to inspect the code.

Download

Documentation

kn/doas — version 0.1.1 Jun 8th 2023

doas

Description

Manager doas.conf(5) rulesets on OpenBSD. Strong types, stable configuration order and validation help avoiding mistakes.

Usage

Ensure the configuration file to be absent in case no rules are defined:

include doas

Permit the developer's group to deploy tests without flexibility:

doas::rule { 'deploy':
  identity => ':dev',
  target   => '_push',
  cmd      => '/usr/local/bin/deploy',
  args     => [
    '--testing',
  ],
}

Grant the admin group passwordless access to all users and programs:

doas::rule { 'admins':
  identity => ':wheel',
  nopass   => true,
}

Permit user to run script as root, e.g. doas /usr/local/bin/script:

doas::rule { 'script':
  identity => 'kn',
  target   => 'root',
  cmd      => '/usr/local/bin/script',
}

Permit admin to configure the network, but in dry-run, i.e. doas /bin/sh /etc/netstart -n:

doas::rule { 'netstart':
  identity => ':wheel',
  target   => 'root',
  cmd      => '/usr/local/bin/script',
}

Limitations

This module is written for and tested on OpenBSD.

Development

Feedback and diffs are always welcome.