Is the option "requiretty" enabled in /etc/sudoers
On Sat, Jun 22, 2019 at 5:58 PM Raman Kathpalia <[email protected]> wrote:
> Here to discuss the ansible behavior when user at managed nodes is given
> sudo privileges to specific commands.
>
>
> I have sudo privileges on remote managed host [rm-host.company.com] to
> specific commands. Two of them are:
>
> /bin/mkdir /opt/somedir/unit*
> /bin/chmod 2775 /opt/somedir/unit*
>
> PS: /opt/somedir at remote nodes exists already.
>
>
> My ansible control machine version:
>
> ansible 2.7.10
> python version = 2.7.5 (default, Mar 26 2019, 22:13:06) [GCC 4.8.5 20150623
> (Red Hat 4.8.5-36)]
>
>
>
> YAML code fails when I use ansbile "file" module even though I have sudo
> privileges to chmod and mkdir as listed above.
>
>
> - name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions
> are 2775
>
> become: yes
> become_method: sudo
> file: path="/opt/somedir/{{ ENV_CHOSEN }}" state=directory mode=2775
>
> when:
> - ansible_facts['os_family'] == "CentOS" or ansible_facts['os_family']
> == "RedHat"
> - ansible_distribution_version | int >= 6
> - http_dir_path.stat.exists == true
> - http_dir_path.stat.isdir == true
> - CreateWebAgentEnvDir is defined
> - CreateWebAgentEnvDir is succeeded
>
> register: ChangeDirPermission
>
> - debug:
> var: ChangeDirPermission
>
> Runtime error:
>
> TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775]
> **************************************************************************************************************************************************************************************
> fatal: [rm-host.company.com]: FAILED! => {"changed": false, "module_stderr":
> "FIPS mode initialized\r\nShared connection to rm-host.company.com
> closed.\r\n", "module_stdout": "sudo: a password is required\r\n", "msg":
> "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 1}
> to retry, use: --limit
> @/u/joker/scripts/Ansible/playbooks/agent/plays/agent_Install.retry
>
> PLAY RECAP
> ***************************************************************************************************************************************************************************************************************************************************rm-host.company.com
> : ok=9 changed=2 unreachable=0 failed=1
>
>
> But succeeds when I use command module:
>
> - name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions
> are 2775
>
> command: sudo /bin/chmod 2775 "/opt/somedir/{{ ENV_CHOSEN }}"
>
> when:
> - ansible_facts['os_family'] == "CentOS" or ansible_facts['os_family']
> == "RedHat"
> - ansible_distribution_version | int >= 6
> - http_dir_path.stat.exists == true
> - http_dir_path.stat.isdir == true
> - CreateagentEnvDir is defined
> - CreateagentEnvDir is succeeded
>
> register: ChangeDirPermission
>
> - debug:
> var: ChangeDirPermission
>
>
> Success Runtime debug output:
>
>
> TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775]
> **************************************************************************************************************************************************************************************
> [WARNING]: Consider using 'become', 'become_method', and 'become_user'
> rather than running sudo
>
> changed: [rm-host.company.com]
>
> TASK [debug]
> *************************************************************************************************************************************************************************************************************************************************
> ok: [rm-host.company.com] => {
> "ChangeDirPermission": {
> "changed": true,
> "cmd": [
> "sudo",
> "/bin/chmod",
> "2775",
> "/opt/somedir/unitc"
> ],
> "delta": "0:00:00.301570",
> "end": "2019-06-22 13:20:17.300266",
> "failed": false,
> "rc": 0,
> "start": "2019-06-22 13:20:16.998696",
> "stderr": "",
> "stderr_lines": [],
> "stdout": "",
> "stdout_lines": [],
> "warnings": [
> "Consider using 'become', 'become_method', and 'become_user'
> rather than running sudo"
> ]
> }
> }
>
>
>
> *Question: *
>
> How can I make this work without using command module? I want to stick to
> ansible core modules using 'become', 'become_method' rather than running
> sudo in command module.
>
>
> 1.
>
> *Note:*
>
> It works when sudo is enabled for ALL commands. But [ user ALL=(ALL)
> NOPASSWD: ALL ] cannot be given on remote host. Not allowed by company
> policy for the group I am in.
>
>
> I posted this on
> https://stackoverflow.com/questions/56717879/ansible-behavior-to-specific-sudo-commands-on-managed-nodes
> as
> well.
>
> 1.
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "Ansible Project" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To post to this group, send email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ansible-project/58e49e9c-055f-44ca-9726-b3877bd2151c%40googlegroups.com
> <https://groups.google.com/d/msgid/ansible-project/58e49e9c-055f-44ca-9726-b3877bd2151c%40googlegroups.com?utm_medium=email&utm_source=footer>
> .
> For more options, visit https://groups.google.com/d/optout.
>
--
You received this message because you are subscribed to the Google Groups
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/ansible-project/CAA3McK-eWUNb8P%3DdQjX6aoTK5byvNSf7deOiKUhxUL6aMSo%3DPw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.