inspec/docs/resources/powershell.md.erb

117 lines
2.5 KiB
Text
Raw Normal View History

2016-09-22 12:43:57 +00:00
---
title: About the powershell Resource
---
# powershell
Use the `powershell` InSpec audit resource to test a Powershell script on the Windows platform.
## Syntax
2016-09-22 12:43:57 +00:00
A `powershell` resource block declares a Powershell script to be tested, and then compares the output of that command to the matcher in the test:
script = <<-EOH
# a PowerShell script
EOH
describe powershell(script) do
2016-09-22 12:43:57 +00:00
its('matcher') { should eq 'output' }
end
where
* `'script'` must specify a Powershell script to be run
* `'matcher'` is one of `exit_status`, `stderr`, or `stdout`
* `'output'` tests the output of the command run on the system versus the output value stated in the test
## Matchers
2016-09-22 12:43:57 +00:00
This InSpec audit resource has the following matchers:
### be
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_be" %>
### cmp
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_cmp" %>
### eq
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_eq" %>
### exit_status
2016-09-22 12:43:57 +00:00
The `exit_status` matcher tests the exit status for the command:
its('exit_status') { should eq 123 }
### include
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_include" %>
### match
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_match" %>
### stderr
2016-09-22 12:43:57 +00:00
The `stderr` matcher tests results of the command as returned in standard error (stderr):
its('stderr') { should eq 'error' }
### stdout
2016-09-22 12:43:57 +00:00
The `stdout` matcher tests results of the command as returned in standard output (stdout):
its('stdout') { should eq '/^1$/' }
## Examples
2016-09-22 12:43:57 +00:00
The following examples show how to use this InSpec audit resource.
### Get all groups of Administrator user
2016-09-22 12:43:57 +00:00
script = <<-EOH
# find user
$user = Get-WmiObject Win32_UserAccount -filter "Name = 'Administrator'"
# get related groups
$groups = $user.GetRelated('Win32_Group') | Select-Object -Property Caption, Domain, Name, LocalAccount, SID, SIDType, Status
$groups | ConvertTo-Json
EOH
describe powershell(script) do
its('stdout') { should_not eq '' }
end
### Write-Output 'hello'
2016-09-22 12:43:57 +00:00
The following Powershell script:
script = <<-EOH
Write-Output 'hello'
EOH
can be tested in the following ways.
For a newline:
describe powershell(script) do
its('stdout') { should eq "hello\r\n" }
its('stderr') { should eq '' }
end
Removing whitespace `\r\n` from `stdout`:
describe powershell(script) do
its('strip') { should eq "hello" }
end
No newline:
describe powershell("'hello' | Write-Host -NoNewLine") do
its('stdout') { should eq 'hello' }
its('stderr') { should eq '' }
end