"""
RemConfFS creates a filesytem for configuring remctl, like this:
/
+ |-- adminacl
|-- acl
| |-- machine1
| ...
def make_map(self):
m = Mapper()
- m.connect('', controller='getroot')
- m.connect('acl', controller='getmachines')
- m.connect('acl/:machine', controller='getacl')
- m.connect('conf', controller='getconf')
+ m.connect('/', controller='getroot')
+ m.connect('/acl', controller='getmachines')
+ m.connect('/acl/:machine', controller='getacl')
+ m.connect('/adminacl', controller='getadmin')
+ m.connect('/conf', controller='getconf')
return m
def getroot(self, **kw):
- return ['acl', 'conf']
+ return ['adminacl', 'acl', 'conf']
def getacl(self, machine, **kw):
"""Build the ACL file for a machine
from_obj=[database.machine_access_table, database.machine_table]) # from tables
users = [self.userToPrinc(acl[0]) for acl in
database.session.execute(s)]
- return "\n".join(users
- + ['include /etc/remctl/acl/web',
- ''])
+ return routefs.File("\n".join(users
+ + ['include /etc/remctl/acl/web',
+ '']))
def getconf(self, **kw):
"""Build the master conf file, with all machines
"""
- return '\n'.join("control %s /usr/sbin/invirt-remote-proxy-control"
- " /etc/remctl/remconffs/acl/%s"
- % (machine_name, machine_name)
- for machine_name in self.getmachines())+'\n'
+ return routefs.File('\n'.join("control %s /usr/sbin/invirt-remote-proxy-control"
+ " /etc/remctl/remconffs/acl/%s"
+ % (machine_name, machine_name)
+ for machine_name in self.getmachines())+'\n')
def getmachines(self, **kw):
"""Get the list of VMs in the database. Does not cache to prevent race conditions."""
- return list(row[0] for row in database.session.execute(sa.sql.select([database.Machine.c.name])))
+ return list(row[0] for row in database.session.execute(sa.sql.select([database.Machine.name])))
+
+ def getadmin(self, **kw):
+ """
+ Get the list of administrators for the global ACL.
+ """
+ acl = [self.userToPrinc(row[0]) for row in database.session.execute(sa.sql.select([database.admins_table.c.user]))]
+ acl.append('include /etc/remctl/acl/web\n')
+ return routefs.File('\n'.join(acl))
def userToPrinc(self, user):
"""Convert Kerberos v4-style names to v5-style and append a default
(princ, realm) = user.split('@')
else:
princ = user
- realm = config.authn[0].realm
+ realm = config.kerberos.realm
return princ.replace('.', '/') + '@' + realm