Ignore that please, I've read incorrectly your message. On Sun, Jun 23, 2019 at 9:30 PM Angel Rengifo Cancino <[email protected]> wrote:
> Is the option "requiretty" enabled in /etc/sudoers > > On Sat, Jun 22, 2019 at 5:58 PM Raman Kathpalia <[email protected]> wrote: > >> Here to discuss the ansible behavior when user at managed nodes is given >> sudo privileges to specific commands. >> >> >> I have sudo privileges on remote managed host [rm-host.company.com] to >> specific commands. Two of them are: >> >> /bin/mkdir /opt/somedir/unit* >> /bin/chmod 2775 /opt/somedir/unit* >> >> PS: /opt/somedir at remote nodes exists already. >> >> >> My ansible control machine version: >> >> ansible 2.7.10 >> python version = 2.7.5 (default, Mar 26 2019, 22:13:06) [GCC 4.8.5 20150623 >> (Red Hat 4.8.5-36)] >> >> >> >> YAML code fails when I use ansbile "file" module even though I have sudo >> privileges to chmod and mkdir as listed above. >> >> >> - name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions >> are 2775 >> >> become: yes >> become_method: sudo >> file: path="/opt/somedir/{{ ENV_CHOSEN }}" state=directory mode=2775 >> >> when: >> - ansible_facts['os_family'] == "CentOS" or >> ansible_facts['os_family'] == "RedHat" >> - ansible_distribution_version | int >= 6 >> - http_dir_path.stat.exists == true >> - http_dir_path.stat.isdir == true >> - CreateWebAgentEnvDir is defined >> - CreateWebAgentEnvDir is succeeded >> >> register: ChangeDirPermission >> >> - debug: >> var: ChangeDirPermission >> >> Runtime error: >> >> TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775] >> ************************************************************************************************************************************************************************************** >> fatal: [rm-host.company.com]: FAILED! => {"changed": false, "module_stderr": >> "FIPS mode initialized\r\nShared connection to rm-host.company.com >> closed.\r\n", "module_stdout": "sudo: a password is required\r\n", "msg": >> "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 1} >> to retry, use: --limit >> @/u/joker/scripts/Ansible/playbooks/agent/plays/agent_Install.retry >> >> PLAY RECAP >> ***************************************************************************************************************************************************************************************************************************************************rm-host.company.com >> : ok=9 changed=2 unreachable=0 failed=1 >> >> >> But succeeds when I use command module: >> >> - name: 7|Ensure Directory - "/opt/somedir/{{ ENV_CHOSEN }}" Permissions >> are 2775 >> >> command: sudo /bin/chmod 2775 "/opt/somedir/{{ ENV_CHOSEN }}" >> >> when: >> - ansible_facts['os_family'] == "CentOS" or >> ansible_facts['os_family'] == "RedHat" >> - ansible_distribution_version | int >= 6 >> - http_dir_path.stat.exists == true >> - http_dir_path.stat.isdir == true >> - CreateagentEnvDir is defined >> - CreateagentEnvDir is succeeded >> >> register: ChangeDirPermission >> >> - debug: >> var: ChangeDirPermission >> >> >> Success Runtime debug output: >> >> >> TASK [7|Ensure Directory - "/opt/somedir/unitc" Permissions are 2775] >> ************************************************************************************************************************************************************************************** >> [WARNING]: Consider using 'become', 'become_method', and 'become_user' >> rather than running sudo >> >> changed: [rm-host.company.com] >> >> TASK [debug] >> ************************************************************************************************************************************************************************************************************************************************* >> ok: [rm-host.company.com] => { >> "ChangeDirPermission": { >> "changed": true, >> "cmd": [ >> "sudo", >> "/bin/chmod", >> "2775", >> "/opt/somedir/unitc" >> ], >> "delta": "0:00:00.301570", >> "end": "2019-06-22 13:20:17.300266", >> "failed": false, >> "rc": 0, >> "start": "2019-06-22 13:20:16.998696", >> "stderr": "", >> "stderr_lines": [], >> "stdout": "", >> "stdout_lines": [], >> "warnings": [ >> "Consider using 'become', 'become_method', and 'become_user' >> rather than running sudo" >> ] >> } >> } >> >> >> >> *Question: * >> >> How can I make this work without using command module? I want to stick to >> ansible core modules using 'become', 'become_method' rather than running >> sudo in command module. >> >> >> 1. >> >> *Note:* >> >> It works when sudo is enabled for ALL commands. But [ user ALL=(ALL) >> NOPASSWD: ALL ] cannot be given on remote host. Not allowed by company >> policy for the group I am in. >> >> >> I posted this on >> https://stackoverflow.com/questions/56717879/ansible-behavior-to-specific-sudo-commands-on-managed-nodes >> as >> well. >> >> 1. >> >> >> >> -- >> You received this message because you are subscribed to the Google Groups >> "Ansible Project" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected]. >> To post to this group, send email to [email protected]. >> To view this discussion on the web visit >> https://groups.google.com/d/msgid/ansible-project/58e49e9c-055f-44ca-9726-b3877bd2151c%40googlegroups.com >> <https://groups.google.com/d/msgid/ansible-project/58e49e9c-055f-44ca-9726-b3877bd2151c%40googlegroups.com?utm_medium=email&utm_source=footer> >> . >> For more options, visit https://groups.google.com/d/optout. >> > -- You received this message because you are subscribed to the Google Groups "Ansible Project" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/ansible-project/CAA3McK8rNTppaVvm8s5Y%2Bijcf%2B8MR_Tz89xGHyJfTJFda4EhfA%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.
