Skip to content

fix: run controller-side tasks without sudo, pin the Python interpreter - #413

Merged
NavidSassan merged 2 commits into
mainfrom
fix/delegated-tasks-become
Oct 2, 2026
Merged

NavidSassan merged 2 commits into
mainfrom
fix/delegated-tasks-become

Conversation

@markuslf

@markuslf markuslf commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Stacked on #412 (base fix/setup-basic-lab-findings), so this PR only shows its own two commits.

Changes

  • roles: all 123 tasks and blocks delegated to localhost get vars: ansible_become: false next to become: false. ansible_become: true in the inventory, the usual way to run LFOps, overrides the become: false keyword, so these tasks ran via sudo on the controller: they failed without passwordless sudo, or ran as root, left root-owned files in /tmp and lost the environment of the ansible-playbook call. CONTRIBUTING and roles/example describe the rule; the variable carries # noqa var-naming[pattern], as in kernel_settings.
  • README: recommend ansible_python_interpreter: '/usr/bin/python3' for all hosts except RHEL 8. Since ansible-core 2.17 the interpreter discovery picks the newest python3.X; after setup_basic installed Python 3.11 (RHEL 9) or 3.13 (RHEL 10) for duplicity, the next run failed in kernel_settings, python_venv and monitoring_plugins.

Tests

  • Become: with ansible-core 2.16 and 2.18, the keyword alone runs a delegated task as uid 0, with the task variable as the calling user. Live run of monitoring_plugins (Rocky 8.3, 2.16) with ansible_become: true in the inventory: 625 files created in /tmp, none owned by root.
  • Interpreter: second setup_basic run without pin on Rocky 9 (python3.11) and Rocky 10 (python3.13) with ansible-core 2.18 fails exactly in kernel_settings (configobj), python_venv and monitoring_plugins (packaging); with the pin it passes. ansible-core 2.16 picks /usr/libexec/platform-python on RHEL 8 and /usr/bin/python3 on RHEL 9; the 2.17 wheel ships an empty distro map.
  • ansible-lint: no new findings. pre-commit green.

Base automatically changed from fix/setup-basic-lab-findings to main October 2, 2026 12:00
ansible_become: true in the inventory, the usual way to run LFOps,
overrides the `become: false` keyword, so every task delegated to
localhost escalated via sudo on the controller: it failed without
passwordless sudo, or ran as root, left root-owned files in /tmp and lost
the environment of the ansible-playbook call. A task variable takes
precedence over the inventory, so add `vars: ansible_become: false` next to
the keyword on all 123 delegated tasks and blocks, and say so in
CONTRIBUTING and the example role. Verified with ansible-core 2.16 and
2.18.
Since ansible-core 2.17 the interpreter discovery picks the newest
python3.X instead of the system Python. After setup_basic installed Python
3.11 (RHEL 9) or 3.13 (RHEL 10) for duplicity, the next run failed in
kernel_settings, python_venv and monitoring_plugins. Measured on Rocky 9
and 10 with ansible-core 2.18.
@NavidSassan
NavidSassan force-pushed the fix/delegated-tasks-become branch from aa317f9 to ff8251b Compare October 2, 2026 12:00
@NavidSassan
NavidSassan merged commit a08a68f into main Oct 2, 2026
13 checks passed
@NavidSassan
NavidSassan deleted the fix/delegated-tasks-become branch October 2, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants