fix: run controller-side tasks without sudo, pin the Python interpreter - #413
Merged
Merged
Conversation
markuslf
force-pushed
the
fix/delegated-tasks-become
branch
from
October 2, 2026 08:10
79955fb to
aa317f9
Compare
NavidSassan
added this pull request to stack #415
October 2, 2026 08:20
NavidSassan
approved these changes
Oct 2, 2026
ansible_become: true in the inventory, the usual way to run LFOps, overrides the `become: false` keyword, so every task delegated to localhost escalated via sudo on the controller: it failed without passwordless sudo, or ran as root, left root-owned files in /tmp and lost the environment of the ansible-playbook call. A task variable takes precedence over the inventory, so add `vars: ansible_become: false` next to the keyword on all 123 delegated tasks and blocks, and say so in CONTRIBUTING and the example role. Verified with ansible-core 2.16 and 2.18.
Since ansible-core 2.17 the interpreter discovery picks the newest python3.X instead of the system Python. After setup_basic installed Python 3.11 (RHEL 9) or 3.13 (RHEL 10) for duplicity, the next run failed in kernel_settings, python_venv and monitoring_plugins. Measured on Rocky 9 and 10 with ansible-core 2.18.
NavidSassan
force-pushed
the
fix/delegated-tasks-become
branch
from
October 2, 2026 12:00
aa317f9 to
ff8251b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #412 (base
fix/setup-basic-lab-findings), so this PR only shows its own two commits.Changes
vars: ansible_become: falsenext tobecome: false.ansible_become: truein the inventory, the usual way to run LFOps, overrides thebecome: falsekeyword, so these tasks ran via sudo on the controller: they failed without passwordless sudo, or ran as root, left root-owned files in/tmpand lost the environment of theansible-playbookcall. CONTRIBUTING androles/exampledescribe the rule; the variable carries# noqa var-naming[pattern], as inkernel_settings.ansible_python_interpreter: '/usr/bin/python3'for all hosts except RHEL 8. Since ansible-core 2.17 the interpreter discovery picks the newestpython3.X; after setup_basic installed Python 3.11 (RHEL 9) or 3.13 (RHEL 10) for duplicity, the next run failed in kernel_settings, python_venv and monitoring_plugins.Tests
monitoring_plugins(Rocky 8.3, 2.16) withansible_become: truein the inventory: 625 files created in/tmp, none owned by root.setup_basicrun without pin on Rocky 9 (python3.11) and Rocky 10 (python3.13) with ansible-core 2.18 fails exactly in kernel_settings (configobj), python_venv and monitoring_plugins (packaging); with the pin it passes. ansible-core 2.16 picks/usr/libexec/platform-pythonon RHEL 8 and/usr/bin/python3on RHEL 9; the 2.17 wheel ships an empty distro map.