Skip to content
Snippets Groups Projects
Commit 829f1056 authored by Rafael Guterres Jeffman's avatar Rafael Guterres Jeffman
Browse files

ipasudorule: Allow execution of plugin in client host.

Update sudorule README file and add tests for executing plugin with
`ipaapi_context` set to `client`.

A new test playbook can be found at:

    tests/sudorule/test_sudorule_client_context.yml

The new test file can be executed in a FreeIPA client host that is
not a server. In this case, it should be defined in the `ipaclients`
group, in the inventory file.
parent 3cd99781
Branches
Tags
No related merge requests found
...@@ -120,6 +120,7 @@ Variable | Description | Required ...@@ -120,6 +120,7 @@ Variable | Description | Required
-------- | ----------- | -------- -------- | ----------- | --------
`ipaadmin_principal` | The admin principal is a string and defaults to `admin` | no `ipaadmin_principal` | The admin principal is a string and defaults to `admin` | no
`ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no `ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
`name` \| `cn` | The list of sudorule name strings. | yes `name` \| `cn` | The list of sudorule name strings. | yes
`description` | The sudorule description string. | no `description` | The sudorule description string. | no
`usercategory` \| `usercat` | User category the rule applies to. Choices: ["all", ""] | no `usercategory` \| `usercat` | User category the rule applies to. Choices: ["all", ""] | no
......
--- ---
- name: Test sudorule - name: Test sudorule
hosts: ipaserver hosts: "{{ ipa_test_host | default('ipaserver') }}"
become: true become: true
gather_facts: true gather_facts: true
...@@ -11,18 +11,21 @@ ...@@ -11,18 +11,21 @@
- name: Ensure user is absent - name: Ensure user is absent
ipauser: ipauser:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: user01 name: user01
state: absent state: absent
- name: Ensure group is absent - name: Ensure group is absent
ipagroup: ipagroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: group01 name: group01
state: absent state: absent
- name: Ensure user is present - name: Ensure user is present
ipauser: ipauser:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: user01 name: user01
first: user first: user
last: zeroone last: zeroone
...@@ -30,24 +33,28 @@ ...@@ -30,24 +33,28 @@
- name: Ensure group is present, with user01 on it. - name: Ensure group is present, with user01 on it.
ipagroup: ipagroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: group01 name: group01
user: user01 user: user01
- name: Ensure sudocmdgroup is absent - name: Ensure sudocmdgroup is absent
ipasudocmdgroup: ipasudocmdgroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: test_sudorule name: test_sudorule
state: absent state: absent
- name: Ensure hostgroup is present, with a host. - name: Ensure hostgroup is present, with a host.
ipahostgroup: ipahostgroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: cluster name: cluster
host: "{{ ansible_facts['fqdn'] }}" host: "{{ ansible_facts['fqdn'] }}"
- name: Ensure some sudocmds are available - name: Ensure some sudocmds are available
ipasudocmd: ipasudocmd:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: name:
- /sbin/ifconfig - /sbin/ifconfig
- /usr/bin/vim - /usr/bin/vim
...@@ -56,6 +63,7 @@ ...@@ -56,6 +63,7 @@
- name: Ensure sudocmdgroup is available - name: Ensure sudocmdgroup is available
ipasudocmdgroup: ipasudocmdgroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: test_sudorule name: test_sudorule
sudocmd: /usr/bin/vim sudocmd: /usr/bin/vim
state: present state: present
...@@ -63,6 +71,7 @@ ...@@ -63,6 +71,7 @@
- name: Ensure sudorules are absent - name: Ensure sudorules are absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: name:
- testrule1 - testrule1
- allusers - allusers
...@@ -75,6 +84,7 @@ ...@@ -75,6 +84,7 @@
- name: Ensure sudorule is present - name: Ensure sudorule is present
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
register: result register: result
failed_when: not result.changed or result.failed failed_when: not result.changed or result.failed
...@@ -82,6 +92,7 @@ ...@@ -82,6 +92,7 @@
- name: Ensure sudorule is present again - name: Ensure sudorule is present again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
register: result register: result
failed_when: result.changed or result.failed failed_when: result.changed or result.failed
...@@ -89,6 +100,7 @@ ...@@ -89,6 +100,7 @@
- name: Ensure user01 is on the list of users sudorule execute as. - name: Ensure user01 is on the list of users sudorule execute as.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasuser: runasuser:
- user01 - user01
...@@ -99,6 +111,7 @@ ...@@ -99,6 +111,7 @@
- name: Ensure user01 is on the list of users sudorule execute as, again. - name: Ensure user01 is on the list of users sudorule execute as, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasuser: runasuser:
- user01 - user01
...@@ -109,6 +122,7 @@ ...@@ -109,6 +122,7 @@
- name: Ensure user01 is not on the list of users sudorule execute as. - name: Ensure user01 is not on the list of users sudorule execute as.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasuser: runasuser:
- user01 - user01
...@@ -120,6 +134,7 @@ ...@@ -120,6 +134,7 @@
- name: Ensure user01 is not on the list of users sudorule execute as, again. - name: Ensure user01 is not on the list of users sudorule execute as, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasuser: runasuser:
- user01 - user01
...@@ -131,6 +146,7 @@ ...@@ -131,6 +146,7 @@
- name: Ensure group01 is on the list of group sudorule execute as. - name: Ensure group01 is on the list of group sudorule execute as.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasgroup: runasgroup:
- group01 - group01
...@@ -141,6 +157,7 @@ ...@@ -141,6 +157,7 @@
- name: Ensure group01 is on the list of group sudorule execute as, again. - name: Ensure group01 is on the list of group sudorule execute as, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasgroup: runasgroup:
- group01 - group01
...@@ -151,6 +168,7 @@ ...@@ -151,6 +168,7 @@
- name: Ensure group01 is not on the list of group sudorule execute as. - name: Ensure group01 is not on the list of group sudorule execute as.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasgroup: runasgroup:
- group01 - group01
...@@ -162,6 +180,7 @@ ...@@ -162,6 +180,7 @@
- name: Ensure group01 is not on the list of groups sudorule execute as, again. - name: Ensure group01 is not on the list of groups sudorule execute as, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
runasgroup: runasgroup:
- group01 - group01
...@@ -173,6 +192,7 @@ ...@@ -173,6 +192,7 @@
- name: Ensure sudorule is present, with usercategory 'all' - name: Ensure sudorule is present, with usercategory 'all'
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
usercategory: all usercategory: all
register: result register: result
...@@ -181,6 +201,7 @@ ...@@ -181,6 +201,7 @@
- name: Ensure sudorule is present, with usercategory 'all', again - name: Ensure sudorule is present, with usercategory 'all', again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
usercategory: all usercategory: all
register: result register: result
...@@ -189,6 +210,7 @@ ...@@ -189,6 +210,7 @@
- name: Ensure sudorule is with usercategory 'all' is absent - name: Ensure sudorule is with usercategory 'all' is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
state: absent state: absent
register: result register: result
...@@ -197,6 +219,7 @@ ...@@ -197,6 +219,7 @@
- name: Ensure sudorule is present, with runasusercategory 'all'. - name: Ensure sudorule is present, with runasusercategory 'all'.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
runasusercategory: all runasusercategory: all
register: result register: result
...@@ -205,6 +228,7 @@ ...@@ -205,6 +228,7 @@
- name: Ensure sudorule is present, with runasusercategory 'all', again. - name: Ensure sudorule is present, with runasusercategory 'all', again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
runasusercategory: all runasusercategory: all
register: result register: result
...@@ -213,6 +237,7 @@ ...@@ -213,6 +237,7 @@
- name: Ensure sudorule is with runasusercategory 'all' is absent - name: Ensure sudorule is with runasusercategory 'all' is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
state: absent state: absent
register: result register: result
...@@ -221,6 +246,7 @@ ...@@ -221,6 +246,7 @@
- name: Ensure sudorule is present, with runasgroupcategory 'all'. - name: Ensure sudorule is present, with runasgroupcategory 'all'.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
runasgroupcategory: all runasgroupcategory: all
register: result register: result
...@@ -229,6 +255,7 @@ ...@@ -229,6 +255,7 @@
- name: Ensure sudorule is present, with runasgroupcategory 'all', again. - name: Ensure sudorule is present, with runasgroupcategory 'all', again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
runasgroupcategory: all runasgroupcategory: all
register: result register: result
...@@ -237,6 +264,7 @@ ...@@ -237,6 +264,7 @@
- name: Ensure sudorule is with runasgroupcategory 'all' is absent - name: Ensure sudorule is with runasgroupcategory 'all' is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
state: absent state: absent
register: result register: result
...@@ -245,6 +273,7 @@ ...@@ -245,6 +273,7 @@
- name: Ensure sudorule is present, with usercategory 'all'. - name: Ensure sudorule is present, with usercategory 'all'.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
usercategory: all usercategory: all
register: result register: result
...@@ -253,6 +282,7 @@ ...@@ -253,6 +282,7 @@
- name: Ensure sudorule is present, with usercategory 'all', again. - name: Ensure sudorule is present, with usercategory 'all', again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
usercategory: all usercategory: all
register: result register: result
...@@ -261,6 +291,7 @@ ...@@ -261,6 +291,7 @@
- name: Ensure sudorule is present, with hostategory 'all' - name: Ensure sudorule is present, with hostategory 'all'
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allhosts name: allhosts
hostcategory: all hostcategory: all
register: result register: result
...@@ -269,6 +300,7 @@ ...@@ -269,6 +300,7 @@
- name: Ensure sudorule is present, with hostategory 'all', again - name: Ensure sudorule is present, with hostategory 'all', again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allhosts name: allhosts
hostcategory: all hostcategory: all
register: result register: result
...@@ -277,6 +309,7 @@ ...@@ -277,6 +309,7 @@
- name: Ensure sudorule is disabled - name: Ensure sudorule is disabled
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: disabled state: disabled
register: result register: result
...@@ -285,6 +318,7 @@ ...@@ -285,6 +318,7 @@
- name: Ensure sudorule is disabled, again - name: Ensure sudorule is disabled, again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: disabled state: disabled
register: result register: result
...@@ -293,6 +327,7 @@ ...@@ -293,6 +327,7 @@
- name: Ensure sudorule is enabled - name: Ensure sudorule is enabled
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: enabled state: enabled
register: result register: result
...@@ -301,6 +336,7 @@ ...@@ -301,6 +336,7 @@
- name: Ensure sudorule is enabled, again - name: Ensure sudorule is enabled, again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: enabled state: enabled
register: result register: result
...@@ -309,6 +345,7 @@ ...@@ -309,6 +345,7 @@
- name: Ensure user is present in sudorule. - name: Ensure user is present in sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
user: user01 user: user01
action: member action: member
...@@ -318,6 +355,7 @@ ...@@ -318,6 +355,7 @@
- name: Ensure user is present in sudorule, again. - name: Ensure user is present in sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
user: user01 user: user01
action: member action: member
...@@ -327,6 +365,7 @@ ...@@ -327,6 +365,7 @@
- name: Ensure user is absent from sudorule. - name: Ensure user is absent from sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
user: user01 user: user01
action: member action: member
...@@ -337,6 +376,7 @@ ...@@ -337,6 +376,7 @@
- name: Ensure user is absent from sudorule, again. - name: Ensure user is absent from sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
user: user01 user: user01
action: member action: member
...@@ -347,6 +387,7 @@ ...@@ -347,6 +387,7 @@
- name: Ensure group is present in sudorule. - name: Ensure group is present in sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
group: group01 group: group01
action: member action: member
...@@ -356,6 +397,7 @@ ...@@ -356,6 +397,7 @@
- name: Ensure group is present in sudorule, again. - name: Ensure group is present in sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
group: group01 group: group01
action: member action: member
...@@ -365,6 +407,7 @@ ...@@ -365,6 +407,7 @@
- name: Ensure group is absent from sudorule. - name: Ensure group is absent from sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
group: group01 group: group01
action: member action: member
...@@ -375,6 +418,7 @@ ...@@ -375,6 +418,7 @@
- name: Ensure group is absent from sudorule, again. - name: Ensure group is absent from sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
group: group01 group: group01
action: member action: member
...@@ -385,6 +429,7 @@ ...@@ -385,6 +429,7 @@
- name: Ensure sudorule has a sudooption. - name: Ensure sudorule has a sudooption.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
sudooption: '!authenticate' sudooption: '!authenticate'
action: member action: member
...@@ -394,6 +439,7 @@ ...@@ -394,6 +439,7 @@
- name: Ensure sudorule has a sudooption, again. - name: Ensure sudorule has a sudooption, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
sudooption: '!authenticate' sudooption: '!authenticate'
action: member action: member
...@@ -403,6 +449,7 @@ ...@@ -403,6 +449,7 @@
- name: Ensure sudorule has an order. - name: Ensure sudorule has an order.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
order: 1 order: 1
register: result register: result
...@@ -411,6 +458,7 @@ ...@@ -411,6 +458,7 @@
- name: Ensure sudorule has an order, again. - name: Ensure sudorule has an order, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
order: 1 order: 1
register: result register: result
...@@ -419,6 +467,7 @@ ...@@ -419,6 +467,7 @@
- name: Ensure sudorule has another order. - name: Ensure sudorule has another order.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
order: 10 order: 10
register: result register: result
...@@ -427,6 +476,7 @@ ...@@ -427,6 +476,7 @@
- name: Ensure sudorule is present and some sudocmd are allowed. - name: Ensure sudorule is present and some sudocmd are allowed.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmd: allow_sudocmd:
- /sbin/ifconfig - /sbin/ifconfig
...@@ -437,6 +487,7 @@ ...@@ -437,6 +487,7 @@
- name: Ensure sudorule is present and some sudocmd are allowed, again. - name: Ensure sudorule is present and some sudocmd are allowed, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmd: allow_sudocmd:
- /sbin/ifconfig - /sbin/ifconfig
...@@ -447,6 +498,7 @@ ...@@ -447,6 +498,7 @@
- name: Ensure sudorule is present and some sudocmd are denyed. - name: Ensure sudorule is present and some sudocmd are denyed.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmd: deny_sudocmd:
- /usr/bin/vim - /usr/bin/vim
...@@ -457,6 +509,7 @@ ...@@ -457,6 +509,7 @@
- name: Ensure sudorule is present and some sudocmd are denyed, again. - name: Ensure sudorule is present and some sudocmd are denyed, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmd: deny_sudocmd:
- /usr/bin/vim - /usr/bin/vim
...@@ -467,6 +520,7 @@ ...@@ -467,6 +520,7 @@
- name: Ensure sudorule is present and, sudocmds are absent. - name: Ensure sudorule is present and, sudocmds are absent.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmd: /sbin/ifconfig allow_sudocmd: /sbin/ifconfig
deny_sudocmd: /usr/bin/vim deny_sudocmd: /usr/bin/vim
...@@ -478,6 +532,7 @@ ...@@ -478,6 +532,7 @@
- name: Ensure sudorule is present and, sudocmds are absent, again. - name: Ensure sudorule is present and, sudocmds are absent, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmd: /sbin/ifconfig allow_sudocmd: /sbin/ifconfig
deny_sudocmd: /usr/bin/vim deny_sudocmd: /usr/bin/vim
...@@ -489,6 +544,7 @@ ...@@ -489,6 +544,7 @@
- name: Ensure sudorule is present with cmdcategory 'all'. - name: Ensure sudorule is present with cmdcategory 'all'.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allcommands name: allcommands
cmdcategory: all cmdcategory: all
register: result register: result
...@@ -497,6 +553,7 @@ ...@@ -497,6 +553,7 @@
- name: Ensure sudorule is present with cmdcategory 'all', again. - name: Ensure sudorule is present with cmdcategory 'all', again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allcommands name: allcommands
cmdcategory: all cmdcategory: all
register: result register: result
...@@ -505,6 +562,7 @@ ...@@ -505,6 +562,7 @@
- name: Ensure host "{{ ansible_facts['fqdn'] }}" is present in sudorule. - name: Ensure host "{{ ansible_facts['fqdn'] }}" is present in sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
host: "{{ ansible_facts['fqdn'] }}" host: "{{ ansible_facts['fqdn'] }}"
action: member action: member
...@@ -514,6 +572,7 @@ ...@@ -514,6 +572,7 @@
- name: Ensure host "{{ ansible_facts['fqdn'] }}" is present in sudorule, again. - name: Ensure host "{{ ansible_facts['fqdn'] }}" is present in sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
host: "{{ ansible_facts['fqdn'] }}" host: "{{ ansible_facts['fqdn'] }}"
action: member action: member
...@@ -523,6 +582,7 @@ ...@@ -523,6 +582,7 @@
- name: Ensure hostgroup is present in sudorule. - name: Ensure hostgroup is present in sudorule.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
hostgroup: cluster hostgroup: cluster
action: member action: member
...@@ -532,6 +592,7 @@ ...@@ -532,6 +592,7 @@
- name: Ensure hostgroup is present in sudorule, again. - name: Ensure hostgroup is present in sudorule, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
hostgroup: cluster hostgroup: cluster
action: member action: member
...@@ -541,6 +602,7 @@ ...@@ -541,6 +602,7 @@
- name: Ensure sudorule is present, with an allow_sudocmdgroup. - name: Ensure sudorule is present, with an allow_sudocmdgroup.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmdgroup: test_sudorule allow_sudocmdgroup: test_sudorule
state: present state: present
...@@ -550,6 +612,7 @@ ...@@ -550,6 +612,7 @@
- name: Ensure sudorule is present, with an allow_sudocmdgroup, again. - name: Ensure sudorule is present, with an allow_sudocmdgroup, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmdgroup: test_sudorule allow_sudocmdgroup: test_sudorule
state: present state: present
...@@ -559,6 +622,7 @@ ...@@ -559,6 +622,7 @@
- name: Ensure sudorule is present, but allow_sudocmdgroup is absent. - name: Ensure sudorule is present, but allow_sudocmdgroup is absent.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmdgroup: test_sudorule allow_sudocmdgroup: test_sudorule
action: member action: member
...@@ -569,6 +633,7 @@ ...@@ -569,6 +633,7 @@
- name: Ensure sudorule is present, but allow_sudocmdgroup is absent. - name: Ensure sudorule is present, but allow_sudocmdgroup is absent.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
allow_sudocmdgroup: test_sudorule allow_sudocmdgroup: test_sudorule
action: member action: member
...@@ -579,6 +644,7 @@ ...@@ -579,6 +644,7 @@
- name: Ensure sudorule is present, with an deny_sudocmdgroup. - name: Ensure sudorule is present, with an deny_sudocmdgroup.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmdgroup: test_sudorule deny_sudocmdgroup: test_sudorule
state: present state: present
...@@ -588,6 +654,7 @@ ...@@ -588,6 +654,7 @@
- name: Ensure sudorule is present, with an deny_sudocmdgroup, again. - name: Ensure sudorule is present, with an deny_sudocmdgroup, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmdgroup: test_sudorule deny_sudocmdgroup: test_sudorule
state: present state: present
...@@ -597,6 +664,7 @@ ...@@ -597,6 +664,7 @@
- name: Ensure sudorule is present, but deny_sudocmdgroup is absent. - name: Ensure sudorule is present, but deny_sudocmdgroup is absent.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmdgroup: test_sudorule deny_sudocmdgroup: test_sudorule
action: member action: member
...@@ -607,6 +675,7 @@ ...@@ -607,6 +675,7 @@
- name: Ensure sudorule is present, but deny_sudocmdgroup is absent, again. - name: Ensure sudorule is present, but deny_sudocmdgroup is absent, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
deny_sudocmdgroup: test_sudorule deny_sudocmdgroup: test_sudorule
action: member action: member
...@@ -617,6 +686,7 @@ ...@@ -617,6 +686,7 @@
- name: Ensure sudorule is absent - name: Ensure sudorule is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: absent state: absent
register: result register: result
...@@ -625,6 +695,7 @@ ...@@ -625,6 +695,7 @@
- name: Ensure sudorule is absent, again. - name: Ensure sudorule is absent, again.
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: testrule1 name: testrule1
state: absent state: absent
register: result register: result
...@@ -633,6 +704,7 @@ ...@@ -633,6 +704,7 @@
- name: Ensure sudorule allhosts is absent - name: Ensure sudorule allhosts is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allhosts name: allhosts
state: absent state: absent
register: result register: result
...@@ -641,6 +713,7 @@ ...@@ -641,6 +713,7 @@
- name: Ensure sudorule allhosts is absent, again - name: Ensure sudorule allhosts is absent, again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allhosts name: allhosts
state: absent state: absent
register: result register: result
...@@ -649,6 +722,7 @@ ...@@ -649,6 +722,7 @@
- name: Ensure sudorule allusers is absent - name: Ensure sudorule allusers is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
state: absent state: absent
register: result register: result
...@@ -657,6 +731,7 @@ ...@@ -657,6 +731,7 @@
- name: Ensure sudorule allusers is absent, again - name: Ensure sudorule allusers is absent, again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allusers name: allusers
state: absent state: absent
register: result register: result
...@@ -665,6 +740,7 @@ ...@@ -665,6 +740,7 @@
- name: Ensure sudorule allcommands is absent - name: Ensure sudorule allcommands is absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allcommands name: allcommands
state: absent state: absent
register: result register: result
...@@ -673,6 +749,7 @@ ...@@ -673,6 +749,7 @@
- name: Ensure sudorule allcommands is absent, again - name: Ensure sudorule allcommands is absent, again
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: allcommands name: allcommands
state: absent state: absent
register: result register: result
...@@ -682,12 +759,14 @@ ...@@ -682,12 +759,14 @@
- name : Ensure sudocmdgroup is absent - name : Ensure sudocmdgroup is absent
ipasudocmdgroup: ipasudocmdgroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: test_sudorule name: test_sudorule
state: absent state: absent
- name: Ensure sudocmds are absent - name: Ensure sudocmds are absent
ipasudocmd: ipasudocmd:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: name:
- /sbin/ifconfig - /sbin/ifconfig
- /usr/bin/vim - /usr/bin/vim
...@@ -696,6 +775,7 @@ ...@@ -696,6 +775,7 @@
- name: Ensure sudorules are absent - name: Ensure sudorules are absent
ipasudorule: ipasudorule:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: name:
- testrule1 - testrule1
- allusers - allusers
...@@ -706,5 +786,6 @@ ...@@ -706,5 +786,6 @@
- name: Ensure hostgroup is absent. - name: Ensure hostgroup is absent.
ipahostgroup: ipahostgroup:
ipaadmin_password: SomeADMINpassword ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: cluster name: cluster
state: absent state: absent
---
- name: Test sudorule
hosts: ipaclients, ipaserver
become: no
gather_facts: no
tasks:
- name: Include FreeIPA facts.
include_tasks: ../env_freeipa_facts.yml
# Test will only be executed if host is not a server.
- name: Execute with server context in the client.
ipasudorule:
ipaadmin_password: SomeADMINpassword
ipaapi_context: server
name: ThisShouldNotWork
register: result
failed_when: not (result.failed and result.msg is regex("No module named '*ipaserver'*"))
when: ipa_host_is_client
# Import basic module tests, and execute with ipa_context set to 'client'.
# If ipaclients is set, it will be executed using the client, if not,
# ipaserver will be used.
#
# With this setup, tests can be executed against an IPA client, against
# an IPA server using "client" context, and ensure that tests are executed
# in upstream CI.
- name: Test sudorule using client context, in client host.
import_playbook: test_sudorule.yml
when: groups['ipaclients']
vars:
ipa_test_host: ipaclients
- name: Test sudorule using client context, in server host.
import_playbook: test_sudorule.yml
when: groups['ipaclients'] is not defined or not groups['ipaclients']
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment