Here to discuss the ansible behavior when user at managed nodes is given
sudo privileges to specific commands.
I have sudo privileges on remote managed host [rm-host.company.com] to
specific commands. Two of them are:
/bin/mkdir /opt/somedir/unit*
/bin/chmod 2775 /opt/somedir/unit*
PS: /opt/somedir at remote nodes exists already.
My ansible control machine version:
ansible 2.7.10
python version = 2.7.5 (default, Mar 26 2019, 22:13:06) [GCC 4.8.5 20150623
(Red Hat 4.8.5-36)]
YAML code fails when I use ansbile "file" module even though I have sudo
privileges to chmod and mkdir as listed above.
- name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions
are 2775
become: yes
become_method: sudo
file: path="/opt/somedir/{{ ENV_CHOSEN }}" state=directory mode=2775
when:
- ansible_facts['os_family'] == "CentOS" or ansible_facts['os_family']
== "RedHat"
- ansible_distribution_version | int >= 6
- http_dir_path.stat.exists == true
- http_dir_path.stat.isdir == true
- CreateWebAgentEnvDir is defined
- CreateWebAgentEnvDir is succeeded
register: ChangeDirPermission
- debug:
var: ChangeDirPermission
Runtime error:
TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775]
**************************************************************************************************************************************************************************************
fatal: [rm-host.company.com]: FAILED! => {"changed": false, "module_stderr":
"FIPS mode initialized\r\nShared connection to rm-host.company.com
closed.\r\n", "module_stdout": "sudo: a password is required\r\n", "msg":
"MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 1}
to retry, use: --limit
@/u/joker/scripts/Ansible/playbooks/agent/plays/agent_Install.retry
PLAY RECAP
***************************************************************************************************************************************************************************************************************************************************
rm-host.company.com : ok=9 changed=2 unreachable=0 failed=1
But succeeds when I use command module:
- name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions
are 2775
command: sudo /bin/chmod 2775 "/opt/somedir/{{ ENV_CHOSEN }}"
when:
- ansible_facts['os_family'] == "CentOS" or ansible_facts['os_family']
== "RedHat"
- ansible_distribution_version | int >= 6
- http_dir_path.stat.exists == true
- http_dir_path.stat.isdir == true
- CreateagentEnvDir is defined
- CreateagentEnvDir is succeeded
register: ChangeDirPermission
- debug:
var: ChangeDirPermission
Success Runtime debug output:
TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775]
**************************************************************************************************************************************************************************************
[WARNING]: Consider using 'become', 'become_method', and 'become_user' rather
than running sudo
changed: [rm-host.company.com]
TASK [debug]
*************************************************************************************************************************************************************************************************************************************************
ok: [rm-host.company.com] => {
"ChangeDirPermission": {
"changed": true,
"cmd": [
"sudo",
"/bin/chmod",
"2775",
"/opt/somedir/unitc"
],
"delta": "0:00:00.301570",
"end": "2019-06-22 13:20:17.300266",
"failed": false,
"rc": 0,
"start": "2019-06-22 13:20:16.998696",
"stderr": "",
"stderr_lines": [],
"stdout": "",
"stdout_lines": [],
"warnings": [
"Consider using 'become', 'become_method', and 'become_user' rather
than running sudo"
]
}
}
*Question: *
How can I make this work without using command module? I want to stick to
ansible core modules using 'become', 'become_method' rather than running
sudo in command module.
1.
*Note:*
It works when sudo is enabled for ALL commands. But [ user ALL=(ALL)
NOPASSWD: ALL ] cannot be given on remote host. Not allowed by company
policy for the group I am in.
I posted this on
https://stackoverflow.com/questions/56717879/ansible-behavior-to-specific-sudo-commands-on-managed-nodes
as
well.
1.
--
You received this message because you are subscribed to the Google Groups
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/ansible-project/58e49e9c-055f-44ca-9726-b3877bd2151c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.