# Openssh-cookbook - extending sshd\_config? (was: Re: Re: Append text to beginning of file)

**URL:** <https://discourse.chef.io/t/openssh-cookbook-extending-sshd-config-was-re-re-append-text-to-beginning-of-file/6881>\
**Category:** Chef Infra (archive)\
**Created:** [September 2, 2015, 2:58pm UTC](https://discourse.chef.io/t/openssh-cookbook-extending-sshd-config-was-re-re-append-text-to-beginning-of-file/6881 "2015-09-02T14:58:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexander\_Skwar](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/alexander_skwar/32/1205_2.png) [@Alexander\_Skwar](https://discourse.chef.io/u/Alexander_Skwar)\
**Post date:** [September 2, 2015, 2:58pm UTC](https://discourse.chef.io/t/openssh-cookbook-extending-sshd-config-was-re-re-append-text-to-beginning-of-file/6881/1 "2015-09-02T14:58:05Z")

</div>

​Hello Matt

Yes, I understand, that it is much more "Chef'fy" to put a COMPLETE  
configuration file under Chef. But sometimes, that's not really doable.

As FileEdit doesn't support my request, I worked around that and am not  
using it for this task 😉

Reg. openssh cookbook. Cool!

We'd have a "generic" sshd\_config for all hosts. Could I use this cookbook  
to _extend_ or change an existing sshd\_config? For example, I'd like to have

PermitRootLogin without-password

But for certain hosts (or in certain other cookbooks or so), I'd like to  
have

PermitRootLogin no

Also, for some systems, I'd like to extend the sshd\_config with a "Match  
group" block (to allow or deny certain groups).

Could I use the openssh-cookbook for this? Could you show me how?

Thanks a lot,  
Alexander

​​

2015-09-02 15:55 GMT+02:00 Matthew Moretti [werebus@gmail.com](mailto:werebus@gmail.com):

> Hello Alexander,
> 
> The general advice I’ve seen about using Chef to _edit_ configuration  
> files is that you should generally avoid doing so if you can. If you have  
> the option of having Chef be the only entity that manages the file in  
> question, it’s much easier to put Chef in charge of the entire file and use  
> a file or template resource instead.
> 
> In the case of ssshd\_config, I’ve never had a complaint about the openssh  
> [https://supermarket.chef.io/cookbooks/openssh](https://supermarket.chef.io/cookbooks/openssh) cookbook which uses  
> attributes to build the whole config (nice for wrapper cookbooks,  
> environments, roles, etc.).
> 
> To answer your actual question though, it doesn’t look like FileEdit will  
> append to the beginning of a file, no. If that’s definitely what you want  
> to do, you’ll probably have to break out some ruby\_blocks  
> [https://docs.chef.io/resource\_ruby\_block.html](https://docs.chef.io/resource_ruby_block.html) and use the slightly  
> lower-level ::File [http://ruby-doc.org/core-2.2.0/File.html](http://ruby-doc.org/core-2.2.0/File.html) methods.
> 
> Hope that helps.
> 
> Matt Moretti
> 
> On Thu, Aug 27, 2015 at 11:14 AM, Alexander Skwar  
> [alexanders.mailinglists+nospam@gmail.com](mailto:alexanders.mailinglists+nospam@gmail.com)  
> [http://mailto:alexanders.mailinglists+nospam@gmail.com](http://mailto:alexanders.mailinglists+nospam@gmail.com) wrote:
> 
> Hello
> 
> > With Chef 11.8.2 and FileEdit and the help of this list :), I've now  
> > got a way to replace text in a file and use the captured text. As it  
> > turned out, I'm not using the captured text at all… Oh, well 🙂
> > 
> > I am now replacing all old values in a config file (sshd\_config, to be  
> > exact). And when a certain config setting wasn't there at all, I  
> > insert a line with the new setting. But it will get appended to the  
> > file; it will be at the end of the file.
> > 
> > That's (maybe…) a problem, as a sshd\_config file might have a "Match  
> > …" block at the end.
> > 
> > Is there maybe an easy to way to add text to the BEGINNING of the file? 🙂
> > 
> > Here (or, for maybe better readability on  
> > [Chef - adding text to BEGINNING of file - how? - Pastebin.com](http://pastebin.com/1QWfsnFZ)) is, what I've got now:
> > 
> > #############################################
> > 
> > # SSH Parameter
> > 
> > {"Protocol" =\> "2", "LogLevel" =\> "INFO", "MaxAuthTries" =\> "4",  
> > "IgnoreRhosts" =\> "yes", "HostbasedAuthentication" =\> "no",  
> > "PermitRootLogin" =\> "no", "PermitEmptyPasswords" =\> "no", "Banner" =\>  
> > "/etc/issue.net"}.each do |param, value|  
> > cfg\_file = "/etc/ssh/sshd\_config"
> > 
> > ```
> > replace_line_re = /^#{param}.*/
> > insert_line_text = replace_line_text = "#{param} #{value}"
> > insert_line_re = /^#{replace_line_text}/
> > 
> > ruby_block "CIS: SSHd Parameter modifizieren. " + param + " => " +
> > 
> > ```
> > 
> > value do  
> > block do  
> > fe = Chef::Util::FileEdit.new(cfg\_file)
> > 
> > ```
> > # Alte Werte durch neue Werte ersetzen
> > fe.search_file_replace_line(replace_line_re,
> > 
> > ```
> > 
> > replace\_line\_text)
> > 
> > ```
> > # Zeile mit neuem Wert am Ende der Datei einfügen - falls
> > 
> > ```
> > 
> > nicht schon vorhanden  
> > fe.insert\_line\_if\_no\_match(insert\_line\_re, insert\_line\_text)
> > 
> > ```
> > # Datei schreiben
> > fe.write_file
> > end # of block do
> > notifies :reload, "service[ssh]", :delayed
> > end # of ruby_block "CIS: SSHd Parameter modifizieren. " + param +
> > 
> > ```
> > 
> > " =\> " + value do  
> > end # of {"Protocol" =\> "2", "LogLevel" =\> "INFO", "MaxAuthTries" =\>  
> > "4", "IgnoreRhosts" =\> "yes", "HostbasedAuthentication" =\> "no",  
> > "PermitRootLogin" =\> "no", "PermitEmptyPasswords" =\> "no", "Banner" =\>  
> > "/etc/issue.net"}.each do |param, value|
> > 
> > Thanks so much again,
> > 
> > ## Alexander
> > 
> > =\> Google+ =\> [http://plus.skwar.me](http://plus.skwar.me) \<==  
> > =\> Chat (Jabber/Google Talk) =\> [a.skwar@gmail.com](mailto:a.skwar@gmail.com) \<==
> 
> ​

--

## Alexander

=\> _Google+_ =\> [http://plus.skwar.me](http://plus.skwar.me) \<==  
=\> _Chat_ (Jabber/Google Talk) =\> [a.skwar@gmail.com](mailto:a.skwar@gmail.com) \<==

---

<div class="post-metadata">

**Author:** ![Shubby](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@Shubby](https://discourse.chef.io/u/Shubby)\
**Post date:** [September 2, 2015, 3:30pm UTC](https://discourse.chef.io/t/openssh-cookbook-extending-sshd-config-was-re-re-append-text-to-beginning-of-file/6881/2 "2015-09-02T15:30:36Z")

</div>

Alexander,

The openssh cookbook is designed to accept any setting you add to your Chef  
attributes. Most have presets if you look at the attributes/default.rb file  
of the cookbook:

> <https://github.com/sous-chefs/openssh/blob/main/attributes/default.rb>

-- however most are commented. The sshd service itself has many defaults.

Because Chef will manage the entire sshd\_config file, you cannot simply  
extend the config, like you asked; Chef will overwrite everything because  
it just does a diff between the existing state and the desired state, so  
anything that's not in the desired state will be removed. The cookbook and  
sshd itself have sane presets but if you have an existing, tweaked config,  
it's easy to lock yourself out of a node.  
So the first thing you'll want to do is study your existing config and  
compare it to the presets to correct any discrepancies.

There are many ways of going about what you're asking. A typical solution  
is to use a wrapper cookbook with a one-line recipe that simply reads:  
include\_recipe 'openssh::default'  
Add all the openssh attributes you want in that wrapper cookbook's  
attributes/default.rb, exactly as you see them formatted in the GitHub link  
above, but change the settings you want, as needed. You can then add that  
cookbook to your node's run list, and the next chef-client run will apply  
those settings.  
You could also use environments or roles to achieve the same result, but  
some people will argue that you should just use cookbooks for everything  
because they're versioned, which makes it easier to roll back if you mess  
something up.

At this point you might call your cookbook of universal sshd settings an  
environment cookbook and apply it to all nodes early on in the run list. If  
you need additional settings applied only to certain nodes, such as a Match  
Group block, again there are many ways of doing that. You could add t

This is how I do it:

1. I have a common set of sshd settings for all my nodes contained in a  
role file. I just add that role to all the nodes. This is what that role  
file looks like: [name "openssh-ubuntu"description "Sets up OpenSSH using my preferred generic s - Pastebin.com](http://pastebin.com/GCUFL9Jd)
2. I have separate roles for subsets of nodes, here's just one example:  
[name "foo"description "Sets up foo nodes"default\_attributes( "openssh" =\> - Pastebin.com](http://pastebin.com/NxUkAEUy) -- as you can see it adds a couple of other  
things to the nodes' run list, you certainly don't need that.  
All of the above can be accomplished exclusively with cookbooks, and again,  
some would suggest that you do it with cookbooks rather than roles or  
environments, since cookbooks are versioned. Read this about that:  
[Role Cookbooks and Wrapper Cookbooks](http://realityforge.org/code/2012/11/19/role-cookbooks-and-wrapper-cookbooks.html)  
[http://blog.vialstudios.com/the-environment-cookbook-pattern/](http://blog.vialstudios.com/the-environment-cookbook-pattern/) is good  
reading, too.

On Wed, Sep 2, 2015 at 10:58 AM, Alexander Skwar \<  
[alexanders.mailinglists+nospam@gmail.com](mailto:alexanders.mailinglists+nospam@gmail.com)\> wrote:

> ​Hello Matt
> 
> Yes, I understand, that it is much more "Chef'fy" to put a COMPLETE  
> configuration file under Chef. But sometimes, that's not really doable.
> 
> As FileEdit doesn't support my request, I worked around that and am not  
> using it for this task 😉
> 
> Reg. openssh cookbook. Cool!
> 
> We'd have a "generic" sshd\_config for all hosts. Could I use this cookbook  
> to _extend_ or change an existing sshd\_config? For example, I'd like to have
> 
> PermitRootLogin without-password
> 
> But for certain hosts (or in certain other cookbooks or so), I'd like to  
> have
> 
> PermitRootLogin no
> 
> Also, for some systems, I'd like to extend the sshd\_config with a "Match  
> group" block (to allow or deny certain groups).
> 
> Could I use the openssh-cookbook for this? Could you show me how?
> 
> Thanks a lot,  
> Alexander
> 
> ​​
> 
> 2015-09-02 15:55 GMT+02:00 Matthew Moretti [werebus@gmail.com](mailto:werebus@gmail.com):
> 
> > Hello Alexander,
> > 
> > The general advice I’ve seen about using Chef to _edit_ configuration  
> > files is that you should generally avoid doing so if you can. If you have  
> > the option of having Chef be the only entity that manages the file in  
> > question, it’s much easier to put Chef in charge of the entire file and use  
> > a file or template resource instead.
> > 
> > In the case of ssshd\_config, I’ve never had a complaint about the openssh  
> > [https://supermarket.chef.io/cookbooks/openssh](https://supermarket.chef.io/cookbooks/openssh) cookbook which uses  
> > attributes to build the whole config (nice for wrapper cookbooks,  
> > environments, roles, etc.).
> > 
> > To answer your actual question though, it doesn’t look like FileEdit will  
> > append to the beginning of a file, no. If that’s definitely what you want  
> > to do, you’ll probably have to break out some ruby\_blocks  
> > [https://docs.chef.io/resource\_ruby\_block.html](https://docs.chef.io/resource_ruby_block.html) and use the slightly  
> > lower-level ::File [http://ruby-doc.org/core-2.2.0/File.html](http://ruby-doc.org/core-2.2.0/File.html) methods.
> > 
> > Hope that helps.
> > 
> > Matt Moretti
> > 
> > On Thu, Aug 27, 2015 at 11:14 AM, Alexander Skwar  
> > [alexanders.mailinglists+nospam@gmail.com](mailto:alexanders.mailinglists+nospam@gmail.com)  
> > [http://mailto:alexanders.mailinglists+nospam@gmail.com](http://mailto:alexanders.mailinglists+nospam@gmail.com) wrote:
> > 
> > Hello
> > 
> > > With Chef 11.8.2 and FileEdit and the help of this list :), I've now  
> > > got a way to replace text in a file and use the captured text. As it  
> > > turned out, I'm not using the captured text at all… Oh, well 🙂
> > > 
> > > I am now replacing all old values in a config file (sshd\_config, to be  
> > > exact). And when a certain config setting wasn't there at all, I  
> > > insert a line with the new setting. But it will get appended to the  
> > > file; it will be at the end of the file.
> > > 
> > > That's (maybe…) a problem, as a sshd\_config file might have a "Match  
> > > …" block at the end.
> > > 
> > > Is there maybe an easy to way to add text to the BEGINNING of the file?  
> > > 🙂
> > > 
> > > Here (or, for maybe better readability on  
> > > [Chef - adding text to BEGINNING of file - how? - Pastebin.com](http://pastebin.com/1QWfsnFZ)) is, what I've got now:
> > > 
> > > #############################################
> > > 
> > > # SSH Parameter
> > > 
> > > {"Protocol" =\> "2", "LogLevel" =\> "INFO", "MaxAuthTries" =\> "4",  
> > > "IgnoreRhosts" =\> "yes", "HostbasedAuthentication" =\> "no",  
> > > "PermitRootLogin" =\> "no", "PermitEmptyPasswords" =\> "no", "Banner" =\>  
> > > "/etc/issue.net"}.each do |param, value|  
> > > cfg\_file = "/etc/ssh/sshd\_config"
> > > 
> > > ```
> > > replace_line_re = /^#{param}.*/
> > > insert_line_text = replace_line_text = "#{param} #{value}"
> > > insert_line_re = /^#{replace_line_text}/
> > > 
> > > ruby_block "CIS: SSHd Parameter modifizieren. " + param + " => " +
> > > 
> > > ```
> > > 
> > > value do  
> > > block do  
> > > fe = Chef::Util::FileEdit.new(cfg\_file)
> > > 
> > > ```
> > > # Alte Werte durch neue Werte ersetzen
> > > fe.search_file_replace_line(replace_line_re,
> > > 
> > > ```
> > > 
> > > replace\_line\_text)
> > > 
> > > ```
> > > # Zeile mit neuem Wert am Ende der Datei einfügen - falls
> > > 
> > > ```
> > > 
> > > nicht schon vorhanden  
> > > fe.insert\_line\_if\_no\_match(insert\_line\_re, insert\_line\_text)
> > > 
> > > ```
> > > # Datei schreiben
> > > fe.write_file
> > > end # of block do
> > > notifies :reload, "service[ssh]", :delayed
> > > end # of ruby_block "CIS: SSHd Parameter modifizieren. " + param +
> > > 
> > > ```
> > > 
> > > " =\> " + value do  
> > > end # of {"Protocol" =\> "2", "LogLevel" =\> "INFO", "MaxAuthTries" =\>  
> > > "4", "IgnoreRhosts" =\> "yes", "HostbasedAuthentication" =\> "no",  
> > > "PermitRootLogin" =\> "no", "PermitEmptyPasswords" =\> "no", "Banner" =\>  
> > > "/etc/issue.net"}.each do |param, value|
> > > 
> > > Thanks so much again,
> > > 
> > > ## Alexander
> > > 
> > > =\> Google+ =\> [http://plus.skwar.me](http://plus.skwar.me) \<==  
> > > =\> Chat (Jabber/Google Talk) =\> [a.skwar@gmail.com](mailto:a.skwar@gmail.com) \<==
> > 
> > ​
> 
> --
> 
> ## Alexander
> 
> =\> _Google+_ =\> [http://plus.skwar.me](http://plus.skwar.me) \<==  
> =\> _Chat_ (Jabber/Google Talk) =\> [a.skwar@gmail.com](mailto:a.skwar@gmail.com) \<==
