Forge Home

doas

Manage doas.conf(5)

167 downloads

164 latest version

5.0 quality score

We run a couple of automated
scans to help you access a
module's quality. Each module is
given a score based on how well
the author has formatted their
code and documentation and
modules are also checked for
malware using VirusTotal.

Please note, the information below
is for guidance only and neither of
these methods should be considered
an endorsement by Puppet.

Version information

  • 0.1.1 (latest)
  • 0.1.0 (deleted)
released Jun 8th 2023
This version is compatible with:
  • Puppet Enterprise 2023.2.x, 2023.1.x, 2023.0.x, 2021.7.x, 2021.6.x, 2021.5.x, 2021.4.x, 2021.3.x, 2021.2.x, 2021.1.x, 2021.0.x, 2019.8.x
  • Puppet >= 6.21.0 < 8.0.0

Start using this module

  • r10k or Code Manager
  • Bolt
  • Manual installation
  • Direct download

Add this module to your Puppetfile:

mod 'kn-doas', '0.1.1'
Learn more about managing modules with a Puppetfile

Add this module to your Bolt project:

bolt module add kn-doas
Learn more about using this module with an existing project

Manually install this module globally with Puppet module tool:

puppet module install kn-doas --version 0.1.1

Direct download is not typically how you would use a Puppet module to manage your infrastructure, but you may want to download the module in order to inspect the code.

Download

Documentation

kn/doas — version 0.1.1 Jun 8th 2023

doas

Description

Manager doas.conf(5) rulesets on OpenBSD. Strong types, stable configuration order and validation help avoiding mistakes.

Usage

Ensure the configuration file to be absent in case no rules are defined:

include doas

Permit the developer's group to deploy tests without flexibility:

doas::rule { 'deploy':
  identity => ':dev',
  target   => '_push',
  cmd      => '/usr/local/bin/deploy',
  args     => [
    '--testing',
  ],
}

Grant the admin group passwordless access to all users and programs:

doas::rule { 'admins':
  identity => ':wheel',
  nopass   => true,
}

Permit user to run script as root, e.g. doas /usr/local/bin/script:

doas::rule { 'script':
  identity => 'kn',
  target   => 'root',
  cmd      => '/usr/local/bin/script',
}

Permit admin to configure the network, but in dry-run, i.e. doas /bin/sh /etc/netstart -n:

doas::rule { 'netstart':
  identity => ':wheel',
  target   => 'root',
  cmd      => '/usr/local/bin/script',
}

Limitations

This module is written for and tested on OpenBSD.

Development

Feedback and diffs are always welcome.