From aabffef634f01718aa6ff9836957a75584340f50 Mon Sep 17 00:00:00 2001 From: Markus Frei Date: Thu, 1 Oct 2026 21:11:05 +0200 Subject: [PATCH 1/2] fix(roles): run tasks delegated to localhost without sudo ansible_become: true in the inventory, the usual way to run LFOps, overrides the `become: false` keyword, so every task delegated to localhost escalated via sudo on the controller: it failed without passwordless sudo, or ran as root, left root-owned files in /tmp and lost the environment of the ansible-playbook call. A task variable takes precedence over the inventory, so add `vars: ansible_become: false` next to the keyword on all 123 delegated tasks and blocks, and say so in CONTRIBUTING and the example role. Verified with ansible-core 2.16 and 2.18. --- CHANGELOG.md | 1 + CONTRIBUTING.md | 6 ++++- roles/acme_sh/tasks/issue-cert.yml | 2 ++ roles/apache_solr/tasks/main.yml | 4 +++ roles/blocky/tasks/main.yml | 6 +++++ roles/example/tasks/main.yml | 9 ++++--- roles/exoscale_vm/tasks/main.yml | 16 ++++++++++++ roles/firewall/tasks/main.yml | 2 ++ roles/glpi_agent/tasks/main.yml | 4 +++ roles/grafana/tasks/main.yml | 2 ++ roles/grafana_grizzly/tasks/main.yml | 4 +++ roles/hetzner_vm/tasks/main.yml | 16 ++++++++++++ roles/icinga2_agent/tasks/Windows.yml | 2 ++ roles/icinga_kubernetes_web/tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ .../icingaweb2_module_company/tasks/main.yml | 2 ++ roles/icingaweb2_module_cube/tasks/main.yml | 2 ++ .../icingaweb2_module_director/tasks/main.yml | 4 +++ .../tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ .../icingaweb2_module_grafana/tasks/main.yml | 8 ++++++ .../tasks/main.yml | 2 ++ roles/icingaweb2_module_jira/tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ roles/icingaweb2_module_x509/tasks/main.yml | 2 ++ .../tasks/main.yml | 2 ++ roles/infomaniak_vm/tasks/main.yml | 20 +++++++++++++++ roles/keycloak/tasks/main.yml | 2 ++ roles/kvm_vm/tasks/main.yml | 2 ++ roles/libmaxminddb/tasks/main.yml | 2 ++ roles/logrotate/tasks/main.yml | 2 ++ roles/mariadb_server/tasks/main.yml | 2 ++ roles/mod_maxminddb/tasks/main.yml | 2 ++ roles/monitoring_plugins/tasks/install.yml | 8 ++++++ .../monitoring_plugins/tasks/linux-source.yml | 25 +++++++++++++++++++ .../tasks/windows-download.yml | 2 ++ .../tasks/main.yml | 2 ++ roles/moodle/tasks/main.yml | 6 +++++ roles/opensearch/tasks/main.yml | 2 ++ roles/openvpn_server/tasks/main.yml | 2 ++ roles/repo_elasticsearch/tasks/Debian.yml | 2 ++ roles/repo_epel/tasks/main.yml | 2 ++ roles/repo_grafana/tasks/Debian.yml | 2 ++ roles/repo_grafana/tasks/RedHat.yml | 2 ++ roles/repo_graylog/tasks/Debian.yml | 2 ++ roles/repo_graylog/tasks/RedHat.yml | 2 ++ roles/repo_icinga/tasks/Debian.yml | 2 ++ roles/repo_icinga/tasks/RedHat.yml | 2 ++ roles/repo_influxdb/tasks/Debian.yml | 2 ++ roles/repo_influxdb/tasks/RedHat.yml | 2 ++ roles/repo_mariadb/tasks/Debian.yml | 2 ++ roles/repo_mariadb/tasks/RedHat.yml | 2 ++ roles/repo_mariadb/tasks/download-gpg-key.yml | 2 ++ roles/repo_mongodb/tasks/Debian.yml | 2 ++ roles/repo_mongodb/tasks/RedHat.yml | 2 ++ .../repo_monitoring_plugins/tasks/Debian.yml | 2 ++ .../repo_monitoring_plugins/tasks/RedHat.yml | 2 ++ roles/repo_monitoring_plugins/tasks/Suse.yml | 2 ++ roles/repo_mydumper/tasks/Debian.yml | 2 ++ roles/repo_opensearch/tasks/Debian.yml | 2 ++ roles/repo_opensearch/tasks/RedHat.yml | 2 ++ roles/repo_proxysql/tasks/Debian.yml | 2 ++ roles/repo_proxysql/tasks/RedHat.yml | 2 ++ roles/repo_redis/tasks/main.yml | 2 ++ .../repo_rpmfusion/tasks/download-gpg-key.yml | 2 ++ roles/repo_sury/tasks/main.yml | 2 ++ roles/rstudio_server/tasks/main.yml | 2 ++ roles/shared/tasks/clone-lib-repo.yml | 6 +++++ .../tasks/clone-monitoring-plugins-repo.yml | 6 +++++ roles/shiny_server/tasks/main.yml | 2 ++ 72 files changed, 255 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index bce2c0570..c1c97e339 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -88,6 +88,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed +* **roles**: Tasks that run on the Ansible controller no longer escalate via sudo when the inventory sets `ansible_become: true`, where they failed without passwordless sudo on the controller or ran as root and left root-owned files in `/tmp`. * **plugin:bitwarden_item, module:bitwarden_item**: A failed sync of the Bitwarden vault, such as an "HTTP Error 400: Bad Request" or a timeout of `bw serve`, is tried again after 10, 30 and 60 seconds instead of aborting the run right away. * **role:aide**: Before it creates the database, the role also waits for running `dnf-automatic` jobs on the Red Hat family and for the update jobs of the system_update role on every platform, not only for the apt jobs on Debian and Ubuntu. An update during the initialisation left files in the database that the first check then reported. * **playbook:setup_basic**: With `setup_basic__skip_duplicity` or `setup_basic__skip_glances`, the playbook no longer builds the Python venv of the skipped role, which could abort the run with a pip error on hosts that do not back up with duplicity. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 17baa1783..931ffa60d 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -366,7 +366,7 @@ The project-agnostic "Changelog" rules above apply. LFOps overrides only the sor * When you must use `ansible.builtin.shell`, pin the interpreter with `executable: '/bin/bash'` (in the task's `args:`, or as a sibling of `cmd:`). On Debian `/bin/sh` is `dash`, which rejects bashisms such as `set -o pipefail`, `[[ ... ]]` and `source` (Debian 12's dash errors on `set -o pipefail` outright); pinning bash keeps shell tasks working across the Red Hat family and Debian/Ubuntu. Use `/bin/bash`, not `/usr/bin/bash`, so it resolves with or without usrmerge. * Do not use `state: 'latest'` for the `ansible.builtin.package` module as this is not idempotent. Always use `state: 'present'`. * Always use `delegate_to: 'localhost'` instead of `local_action`. -* Always set `become: false` on every task delegated to localhost. When a play sets `become: true` at the play level (not typical for lfops, but useful if others import our roles in their playbooks), it propagates to delegated tasks too and tries to escalate via sudo on the Ansible controller. On a controller without passwordless sudo this fails with `sudo: a password is required`, even though the delegated task only writes to `/tmp` or hits a remote API and does not need root locally. Example: +* Always set both `become: false` and `vars: ansible_become: false` on every task (or block) delegated to localhost. Otherwise the task escalates via sudo on the Ansible controller: `become: true` at the play level propagates to delegated tasks, and `ansible_become: true` in the inventory, the usual way to run LFOps, even overrides the `become: false` keyword, since a connection variable takes precedence over the keyword. The task variable in turn overrides the inventory. On a controller without passwordless sudo the task fails with `sudo: a password is required`; with it, the task runs as root, leaves root-owned files in `/tmp` and loses most of the environment of the `ansible-playbook` call, since sudo resets it, although it only writes to `/tmp` or hits a remote API. Verified with ansible-core 2.16 and 2.18. Example: ```yaml - name: 'curl --output /tmp/ansible.example.tar.gz https://example.com/releases/example.tar.gz' @@ -376,6 +376,8 @@ The project-agnostic "Changelog" rules above apply. LFOps overrides only the sor mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the target check_mode: false # run task even if `--check` is specified ``` @@ -393,6 +395,8 @@ The project-agnostic "Changelog" rules above apply. LFOps overrides only the sor depth: 1 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified ``` diff --git a/roles/acme_sh/tasks/issue-cert.yml b/roles/acme_sh/tasks/issue-cert.yml index 80291c15c..ed3f42d0f 100644 --- a/roles/acme_sh/tasks/issue-cert.yml +++ b/roles/acme_sh/tasks/issue-cert.yml @@ -7,6 +7,8 @@ register: 'acme_sh__curl_result' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] - name: 'check if acme-challenge was reachable' ansible.builtin.assert: diff --git a/roles/apache_solr/tasks/main.yml b/roles/apache_solr/tasks/main.yml index 1f06e0d83..6e9553320 100644 --- a/roles/apache_solr/tasks/main.yml +++ b/roles/apache_solr/tasks/main.yml @@ -12,6 +12,8 @@ checksum: '{{ apache_solr__checksum }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified changed_when: false # just gathering info, no actual change when: @@ -24,6 +26,8 @@ checksum: '{{ apache_solr__checksum }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified changed_when: false # just gathering info, no actual change when: diff --git a/roles/blocky/tasks/main.yml b/roles/blocky/tasks/main.yml index 010959f90..588eb4917 100644 --- a/roles/blocky/tasks/main.yml +++ b/roles/blocky/tasks/main.yml @@ -31,6 +31,8 @@ check_mode: false # run task even if `--check` is specified delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] run_once: true - name: 'Store the latest release version' @@ -47,6 +49,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified @@ -56,6 +60,8 @@ dest: '/tmp' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] ignore_errors: '{{ ansible_check_mode }}' # ignore errors if `--check` is specified - name: 'scp /tmp/blocky {{ inventory_hostname }}:/usr/local/sbin/blocky' diff --git a/roles/example/tasks/main.yml b/roles/example/tasks/main.yml index 1d282d7cc..e324e1a56 100644 --- a/roles/example/tasks/main.yml +++ b/roles/example/tasks/main.yml @@ -132,9 +132,10 @@ # download on the controller (`delegate_to: 'localhost'`) and copy to the target afterwards, # so that targets without internet access can still be provisioned. - # always set `become: false` on tasks delegated to localhost. otherwise `become: true` - # from the playbook level propagates and triggers sudo on the controller, which is - # unneeded for a download into /tmp and usually fails because no sudo password is set. + # always set `become: false` and the task variable `ansible_become: false` on tasks + # delegated to localhost. otherwise `become: true` from the playbook level, or + # `ansible_become: true` from the inventory (which beats the keyword), triggers sudo on the + # controller, which is unneeded for a download into /tmp and fails without a sudo password. # do not use `run_once: true` here. `run_once` binds the task to the first host of the # batch and evaluates any `when` against that host, so a host that skips the role (or a # block-level `when`) on the first host skips the download for everyone. `get_url` writes @@ -148,6 +149,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the target check_mode: false # run task even if `--check` is specified diff --git a/roles/exoscale_vm/tasks/main.yml b/roles/exoscale_vm/tasks/main.yml index 92fc5a9f9..b73e2472f 100644 --- a/roles/exoscale_vm/tasks/main.yml +++ b/roles/exoscale_vm/tasks/main.yml @@ -9,6 +9,8 @@ state: 'present' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'exoscale_vm__security_group_rules is defined and exoscale_vm__security_group_rules | length > 0' - 'exoscale_vm__state != "absent"' @@ -28,6 +30,8 @@ loop: '{{ exoscale_vm__security_group_rules }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'exoscale_vm__security_group_rules is defined and exoscale_vm__security_group_rules | length > 0' - 'exoscale_vm__state != "absent"' @@ -64,6 +68,8 @@ register: 'exoscale_vm__instance_list_result' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # just gathering information, no actual change happening here - name: 'Create the VM at Exoscale' @@ -86,6 +92,8 @@ '{{ exoscale_vm__name }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'exoscale_vm__state != "absent"' - 'exoscale_vm__name not in exoscale_vm__instance_list_result["stdout"] | from_json | map(attribute="name")' @@ -100,6 +108,8 @@ '{{ exoscale_vm__name }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'exoscale_vm__state == "absent"' - 'exoscale_vm__name in exoscale_vm__instance_list_result["stdout"] | from_json | map(attribute="name")' @@ -128,6 +138,8 @@ - 'item["cidr"] is defined' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] - name: "Manage the VM's networks" ngine_io.cloudstack.cs_instance_nic: @@ -142,6 +154,8 @@ when: 'exoscale_vm__state != "absent"' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] tags: - 'exoscale_vm' @@ -159,6 +173,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'exoscale_vm__security_group_rules is defined and exoscale_vm__security_group_rules | length > 0' - 'exoscale_vm__state == "absent"' diff --git a/roles/firewall/tasks/main.yml b/roles/firewall/tasks/main.yml index e76f4a792..4a18050dc 100644 --- a/roles/firewall/tasks/main.yml +++ b/roles/firewall/tasks/main.yml @@ -181,6 +181,8 @@ changed_when: false # not a config change on the server delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified diff --git a/roles/glpi_agent/tasks/main.yml b/roles/glpi_agent/tasks/main.yml index 3a7f54c7e..75f672eed 100644 --- a/roles/glpi_agent/tasks/main.yml +++ b/roles/glpi_agent/tasks/main.yml @@ -32,6 +32,8 @@ check_mode: false # run task even if `--check` is specified delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] run_once: true - name: 'Store the latest release version' @@ -48,6 +50,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/grafana/tasks/main.yml b/roles/grafana/tasks/main.yml index f4057ff01..8c7e72297 100644 --- a/roles/grafana/tasks/main.yml +++ b/roles/grafana/tasks/main.yml @@ -277,6 +277,8 @@ label: '{{ item["json"]["name"] | d(item) }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'not grafana__skip_token_to_bitwarden' - 'not (item["skipped"] is defined and item["skipped"])' diff --git a/roles/grafana_grizzly/tasks/main.yml b/roles/grafana_grizzly/tasks/main.yml index 99b7b8c8e..5ec4f4b1b 100644 --- a/roles/grafana_grizzly/tasks/main.yml +++ b/roles/grafana_grizzly/tasks/main.yml @@ -14,6 +14,8 @@ check_mode: false # run task even if `--check` is specified delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] run_once: true - name: 'Store the latest release version' @@ -30,6 +32,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/hetzner_vm/tasks/main.yml b/roles/hetzner_vm/tasks/main.yml index faf7f3512..973142b1a 100644 --- a/roles/hetzner_vm/tasks/main.yml +++ b/roles/hetzner_vm/tasks/main.yml @@ -9,6 +9,8 @@ loop: '{{ hetzner_vm__networks }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__state != "absent"' - 'item["cidr"] is defined' @@ -24,6 +26,8 @@ loop: '{{ hetzner_vm__networks }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__state != "absent"' - 'item["cidr"] is defined' @@ -38,6 +42,8 @@ loop: '{{ hetzner_vm__networks | subelements("routes", skip_missing=True) }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__state != "absent"' @@ -49,6 +55,8 @@ state: 'present' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__firewall_rules is defined and hetzner_vm__firewall_rules | length > 0' - 'hetzner_vm__state != "absent"' # cannot remove the firewall here, as it is still in use @@ -71,6 +79,8 @@ state: '{{ hetzner_vm__state }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] - name: 'Manage the firewall of the VM' hetzner.hcloud.hcloud_firewall: @@ -79,6 +89,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__firewall_rules is defined and hetzner_vm__firewall_rules | length > 0' - 'hetzner_vm__state == "absent"' # cannot remove the firewall here, as it is still in use @@ -94,6 +106,8 @@ loop: '{{ hetzner_vm__networks }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'hetzner_vm__state != "absent"' - 'item["fixed_ip"] is defined' @@ -110,6 +124,8 @@ loop: '{{ hetzner_vm__volumes }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] tags: - 'hetzner_vm' diff --git a/roles/icinga2_agent/tasks/Windows.yml b/roles/icinga2_agent/tasks/Windows.yml index 9a393080c..8bd3e938a 100644 --- a/roles/icinga2_agent/tasks/Windows.yml +++ b/roles/icinga2_agent/tasks/Windows.yml @@ -6,6 +6,8 @@ dest: '/tmp/ansible.Icinga2-{{ icinga2_agent__windows_version }}-x86_64.msi' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy msi file from "/tmp/ansible.Icinga2-{{ icinga2_agent__windows_version }}-x86_64.msi" to "{{ icinga2_agent__windows_download_path }}\Icinga2-{{ icinga2_agent__windows_version }}-x86_64.msi"' diff --git a/roles/icinga_kubernetes_web/tasks/main.yml b/roles/icinga_kubernetes_web/tasks/main.yml index 2e5caa21a..aea853893 100644 --- a/roles/icinga_kubernetes_web/tasks/main.yml +++ b/roles/icinga_kubernetes_web/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-kubernetes-web-{{ icinga_kubernetes_web__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-kubernetes-web-{{ icinga_kubernetes_web__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_businessprocess/tasks/main.yml b/roles/icingaweb2_module_businessprocess/tasks/main.yml index 844797008..63cd6bc5c 100644 --- a/roles/icingaweb2_module_businessprocess/tasks/main.yml +++ b/roles/icingaweb2_module_businessprocess/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-businessprocess-{{ icingaweb2_module_businessprocess__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-businessprocess-{{ icingaweb2_module_businessprocess__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_company/tasks/main.yml b/roles/icingaweb2_module_company/tasks/main.yml index 027317707..33b9f416c 100644 --- a/roles/icingaweb2_module_company/tasks/main.yml +++ b/roles/icingaweb2_module_company/tasks/main.yml @@ -29,6 +29,8 @@ dest: '/tmp/ansible.icingaweb2-theme-company-v1.0.0.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-theme-company-v1.0.0.tar.gz to the server' diff --git a/roles/icingaweb2_module_cube/tasks/main.yml b/roles/icingaweb2_module_cube/tasks/main.yml index 3137d547c..dbfac69c8 100644 --- a/roles/icingaweb2_module_cube/tasks/main.yml +++ b/roles/icingaweb2_module_cube/tasks/main.yml @@ -22,6 +22,8 @@ dest: '/tmp/ansible.icingaweb2-module-cube-{{ icingaweb2_module_cube__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-cube-{{ icingaweb2_module_cube__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_director/tasks/main.yml b/roles/icingaweb2_module_director/tasks/main.yml index 4f079ab84..5b6b6084e 100644 --- a/roles/icingaweb2_module_director/tasks/main.yml +++ b/roles/icingaweb2_module_director/tasks/main.yml @@ -45,6 +45,8 @@ dest: '/tmp/ansible.icingaweb2-module-director-{{ icingaweb2_module_director__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-director-{{ icingaweb2_module_director__version }}.tar.gz to the server' @@ -171,6 +173,8 @@ chdir: '/tmp/ansible.monitoring-plugins-repo/' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified changed_when: false # no change on the remote host diff --git a/roles/icingaweb2_module_fileshipper/tasks/main.yml b/roles/icingaweb2_module_fileshipper/tasks/main.yml index 3e5ead8c8..37f74c8a8 100644 --- a/roles/icingaweb2_module_fileshipper/tasks/main.yml +++ b/roles/icingaweb2_module_fileshipper/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-fileshipper-{{ icingaweb2_module_fileshipper__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-fileshipper-{{ icingaweb2_module_fileshipper__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_generictts/tasks/main.yml b/roles/icingaweb2_module_generictts/tasks/main.yml index 519b29510..ea9359b85 100644 --- a/roles/icingaweb2_module_generictts/tasks/main.yml +++ b/roles/icingaweb2_module_generictts/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-generictts-{{ icingaweb2_module_generictts__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-generictts-{{ icingaweb2_module_generictts__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_grafana/tasks/main.yml b/roles/icingaweb2_module_grafana/tasks/main.yml index 83585b863..e42fb84d9 100644 --- a/roles/icingaweb2_module_grafana/tasks/main.yml +++ b/roles/icingaweb2_module_grafana/tasks/main.yml @@ -43,6 +43,8 @@ dest: '/tmp/ansible.icingaweb2-module-grafana-{{ icingaweb2_module_grafana__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-grafana-{{ icingaweb2_module_grafana__version }}.tar.gz to the server' # noqa risky-file-permissions (temp file) @@ -127,6 +129,8 @@ executable: '/bin/bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified changed_when: false # no change on the remote host @@ -137,6 +141,8 @@ dest: '/tmp/ansible.monitoring-plugins-repo-flattened/icingaweb2-module-grafana/z00-custom.ini' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'Assemble /tmp/ansible.icingaweb2-module-grafana-combined.ini' # noqa risky-file-permissions (temp file) @@ -146,6 +152,8 @@ delimiter: '\n\n' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified changed_when: false # no change on the remote host diff --git a/roles/icingaweb2_module_incubator/tasks/main.yml b/roles/icingaweb2_module_incubator/tasks/main.yml index a29507f3c..8a707c5a9 100644 --- a/roles/icingaweb2_module_incubator/tasks/main.yml +++ b/roles/icingaweb2_module_incubator/tasks/main.yml @@ -22,6 +22,8 @@ dest: '/tmp/ansible.icingaweb2-module-incubator-{{ icingaweb2_module_incubator__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-incubator-{{ icingaweb2_module_incubator__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_jira/tasks/main.yml b/roles/icingaweb2_module_jira/tasks/main.yml index 5a1127d82..f3b8b9754 100644 --- a/roles/icingaweb2_module_jira/tasks/main.yml +++ b/roles/icingaweb2_module_jira/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-jira-{{ icingaweb2_module_jira__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-jira-{{ icingaweb2_module_jira__version }}.tar.gz to the server' diff --git a/roles/icingaweb2_module_pdfexport/tasks/main.yml b/roles/icingaweb2_module_pdfexport/tasks/main.yml index a2a493dfe..3cf239f3e 100644 --- a/roles/icingaweb2_module_pdfexport/tasks/main.yml +++ b/roles/icingaweb2_module_pdfexport/tasks/main.yml @@ -25,6 +25,8 @@ dest: '/tmp/ansible.icingaweb2-module-pdfexport-{{ icingaweb2_module_pdfexport__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-pdfexport-{{ icingaweb2_module_pdfexport__version }}.tar.gz to the server' # noqa risky-file-permissions (temporary file) diff --git a/roles/icingaweb2_module_reporting/tasks/main.yml b/roles/icingaweb2_module_reporting/tasks/main.yml index 84fdb31b9..867337348 100644 --- a/roles/icingaweb2_module_reporting/tasks/main.yml +++ b/roles/icingaweb2_module_reporting/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-reporting-{{ icingaweb2_module_reporting__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-reporting-{{ icingaweb2_module_reporting__version }}.tar.gz to /tmp/ansible.icingaweb2-module-reporting-{{ icingaweb2_module_reporting__version }}.tar.gz' diff --git a/roles/icingaweb2_module_vspheredb/tasks/main.yml b/roles/icingaweb2_module_vspheredb/tasks/main.yml index 4d9bf4089..10cfe0684 100644 --- a/roles/icingaweb2_module_vspheredb/tasks/main.yml +++ b/roles/icingaweb2_module_vspheredb/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-vspheredb-{{ icingaweb2_module_vspheredb__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false - name: 'copy /tmp/ansible.icingaweb2-module-vspheredb-{{ icingaweb2_module_vspheredb__version }}.tar.gz to /tmp/ansible.icingaweb2-module-vspheredb-{{ icingaweb2_module_vspheredb__version }}.tar.gz' diff --git a/roles/icingaweb2_module_x509/tasks/main.yml b/roles/icingaweb2_module_x509/tasks/main.yml index bab79eee6..caab0f62a 100644 --- a/roles/icingaweb2_module_x509/tasks/main.yml +++ b/roles/icingaweb2_module_x509/tasks/main.yml @@ -30,6 +30,8 @@ dest: '/tmp/ansible.icingaweb2-module-x509-{{ icingaweb2_module_x509__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-module-x509-{{ icingaweb2_module_x509__version }}.tar.gz to /tmp/ansible.icingaweb2-module-x509-{{ icingaweb2_module_x509__version }}.tar.gz' diff --git a/roles/icingaweb2_theme_linuxfabrik/tasks/main.yml b/roles/icingaweb2_theme_linuxfabrik/tasks/main.yml index 5087cee2f..60c830e5a 100644 --- a/roles/icingaweb2_theme_linuxfabrik/tasks/main.yml +++ b/roles/icingaweb2_theme_linuxfabrik/tasks/main.yml @@ -22,6 +22,8 @@ dest: '/tmp/ansible.icingaweb2-theme-linuxfabrik-{{ icingaweb2_theme_linuxfabrik__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'copy /tmp/ansible.icingaweb2-theme-linuxfabrik-{{ icingaweb2_theme_linuxfabrik__version }}.tar.gz to the server' diff --git a/roles/infomaniak_vm/tasks/main.yml b/roles/infomaniak_vm/tasks/main.yml index 7879d3666..57ddd5b46 100644 --- a/roles/infomaniak_vm/tasks/main.yml +++ b/roles/infomaniak_vm/tasks/main.yml @@ -14,6 +14,8 @@ state: 'present' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__security_group_rules is defined and infomaniak_vm__security_group_rules | length > 0' - 'infomaniak_vm__state != "absent"' @@ -39,6 +41,8 @@ loop: '{{ infomaniak_vm__security_group_rules }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__security_group_rules is defined and infomaniak_vm__security_group_rules | length > 0' - 'infomaniak_vm__state != "absent"' @@ -64,6 +68,8 @@ state: 'present' # we only use state present, as other vms could use the network too delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] loop: '{{ infomaniak_vm__networks }}' when: 'infomaniak_vm__state != "absent"' @@ -85,6 +91,8 @@ state: 'present' # we only use state present, as other vms could use the network too delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] loop: '{{ infomaniak_vm__networks }}' when: - 'infomaniak_vm__state != "absent"' @@ -110,6 +118,8 @@ state: 'present' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] loop: '{{ infomaniak_vm__networks }}' loop_control: label: 'name={{ item["name"] }}, port_name={{ item["port_name"] | default(infomaniak_vm__name ~ "--" ~ item["name"] ~ "--port") }}' @@ -145,6 +155,8 @@ volume_type: 'CEPH_1_{{ infomaniak_vm__separate_boot_volume_type }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__separate_boot_volume_size is defined and infomaniak_vm__separate_boot_volume_size | string | length > 0' @@ -168,6 +180,8 @@ auto_ip: false # not all VMs need to have a public ip delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__separate_boot_volume_size is defined and infomaniak_vm__separate_boot_volume_size | string | length > 0' @@ -191,6 +205,8 @@ auto_ip: false # not all VMs need to have a public ip delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__separate_boot_volume_size is not defined or not infomaniak_vm__separate_boot_volume_size | string | length > 0' @@ -209,6 +225,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] loop: '{{ infomaniak_vm__networks }}' when: - 'infomaniak_vm__state == "absent"' @@ -228,6 +246,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] when: - 'infomaniak_vm__security_group_rules is defined and infomaniak_vm__security_group_rules | length > 0' - 'infomaniak_vm__state == "absent"' diff --git a/roles/keycloak/tasks/main.yml b/roles/keycloak/tasks/main.yml index 8aea23c1b..9a94ae2f3 100644 --- a/roles/keycloak/tasks/main.yml +++ b/roles/keycloak/tasks/main.yml @@ -134,6 +134,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the target check_mode: false # run task even if `--check` is specified diff --git a/roles/kvm_vm/tasks/main.yml b/roles/kvm_vm/tasks/main.yml index 58aeebafc..da8eb394f 100644 --- a/roles/kvm_vm/tasks/main.yml +++ b/roles/kvm_vm/tasks/main.yml @@ -17,6 +17,8 @@ delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] tags: - 'kvm_vm' diff --git a/roles/libmaxminddb/tasks/main.yml b/roles/libmaxminddb/tasks/main.yml index 9bf456e7f..e83a7bb0a 100644 --- a/roles/libmaxminddb/tasks/main.yml +++ b/roles/libmaxminddb/tasks/main.yml @@ -19,6 +19,8 @@ dest: '/tmp/libmaxminddb-{{ libmaxminddb__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'mkdir -p {{ ansible_env["HOME"] }}/libmaxminddb-{{ libmaxminddb__version }}' diff --git a/roles/logrotate/tasks/main.yml b/roles/logrotate/tasks/main.yml index adb60a13a..ffd0b9e73 100644 --- a/roles/logrotate/tasks/main.yml +++ b/roles/logrotate/tasks/main.yml @@ -43,6 +43,8 @@ path: '{{ inventory_dir }}/host_files/{{ inventory_hostname }}/etc/logrotate.d' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: 'logrotate__custom_configs' diff --git a/roles/mariadb_server/tasks/main.yml b/roles/mariadb_server/tasks/main.yml index f656e2877..fd1063b02 100644 --- a/roles/mariadb_server/tasks/main.yml +++ b/roles/mariadb_server/tasks/main.yml @@ -901,6 +901,8 @@ dest: '/tmp/ansible.mariadb-sys-schema.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/mod_maxminddb/tasks/main.yml b/roles/mod_maxminddb/tasks/main.yml index 54da6985e..8ee16816c 100644 --- a/roles/mod_maxminddb/tasks/main.yml +++ b/roles/mod_maxminddb/tasks/main.yml @@ -19,6 +19,8 @@ dest: '/tmp/mod_maxminddb-{{ mod_maxminddb__version }}.tar.gz' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'mkdir -p {{ ansible_env["HOME"] }}/mod_maxminddb-{{ mod_maxminddb__version }}' diff --git a/roles/monitoring_plugins/tasks/install.yml b/roles/monitoring_plugins/tasks/install.yml index 9b7451d05..e9654705b 100644 --- a/roles/monitoring_plugins/tasks/install.yml +++ b/roles/monitoring_plugins/tasks/install.yml @@ -60,6 +60,8 @@ - 'monitoring_plugins__icinga2_api_password is defined and monitoring_plugins__icinga2_api_password | length > 0' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] ignore_errors: true tags: @@ -194,6 +196,8 @@ executable: '/bin/bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified changed_when: false # no change on the remote host @@ -225,6 +229,8 @@ path: '{{ inventory_dir }}/host_files/{{ inventory_hostname }}/usr/lib64/nagios/plugins' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: '__monitoring_plugins__custom_plugins' @@ -273,6 +279,8 @@ - 'monitoring_plugins__icinga2_api_password is defined and monitoring_plugins__icinga2_api_password | length > 0' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] ignore_errors: true # we still want to start the icinga2 service again tags: diff --git a/roles/monitoring_plugins/tasks/linux-source.yml b/roles/monitoring_plugins/tasks/linux-source.yml index 2c2245a0d..dfa68a09e 100644 --- a/roles/monitoring_plugins/tasks/linux-source.yml +++ b/roles/monitoring_plugins/tasks/linux-source.yml @@ -24,6 +24,8 @@ executable: '/bin/bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] register: '__monitoring_plugins__lib_pin_result' changed_when: false # read-only check_mode: false # run task even if `--check` is specified @@ -105,6 +107,8 @@ executable: '/bin/bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts register: '__monitoring_plugins__flattened_plugins' check_mode: false # run task even if `--check` is specified @@ -119,6 +123,8 @@ chdir: '/tmp/ansible.monitoring-plugins-repo-flattened' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts register: '__monitoring_plugins__snmp_device_files' check_mode: false # run task even if `--check` is specified @@ -150,6 +156,8 @@ path: '/tmp/ansible.monitoring-plugins-repo/lockfiles/{{ __monitoring_plugins__legacy_py_tag }}/requirements.txt' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: '__monitoring_plugins__legacy_lockfile' @@ -293,6 +301,8 @@ path: '/tmp/ansible.monitoring-plugins-repo/lockfiles/{{ __monitoring_plugins__source_py_tag }}/requirements.txt' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] register: '__monitoring_plugins__lockfile_result' changed_when: false check_mode: false # run task even if `--check` is specified @@ -310,6 +320,8 @@ path: '/tmp/ansible.lib-repo/lockfiles/{{ __monitoring_plugins__source_py_tag }}/requirements.txt' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] register: '__monitoring_plugins__lib_lockfile_result' changed_when: false check_mode: false # run task even if `--check` is specified @@ -333,6 +345,8 @@ mode: 0o755 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # no change on the remote host check_mode: false # run task even if `--check` is specified @@ -353,6 +367,8 @@ }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts changed_when: false # no change on the remote host check_mode: false # run task even if `--check` is specified @@ -375,6 +391,7 @@ + __monitoring_plugins__platform_args }}' vars: + ansible_become: false # noqa var-naming[pattern] __monitoring_plugins__platform_args: '{{ (range(17, (__monitoring_plugins__source_glibc_version.split(".")[1] | int) + 1) | map("string") @@ -407,6 +424,8 @@ }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts changed_when: false # no change on the remote host check_mode: false # run task even if `--check` is specified @@ -734,6 +753,8 @@ path: '/tmp/ansible.monitoring-plugins-repo/assets/sudoers/{{ ansible_facts["os_family"] }}-logging.sudoers' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: '__monitoring_plugins__sudoers_logging_source' @@ -770,6 +791,8 @@ path: '/tmp/ansible.monitoring-plugins-repo/assets/bash-completion/linuxfabrik-monitoring-plugins.bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: '__monitoring_plugins__bash_completion_source' @@ -822,6 +845,8 @@ path: '/tmp/ansible.monitoring-plugins-repo/assets/selinux/linuxfabrik-monitoring-plugins.cil' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false register: '__monitoring_plugins__selinux_module_source' diff --git a/roles/monitoring_plugins/tasks/windows-download.yml b/roles/monitoring_plugins/tasks/windows-download.yml index 45b320fda..4cd2c263a 100644 --- a/roles/monitoring_plugins/tasks/windows-download.yml +++ b/roles/monitoring_plugins/tasks/windows-download.yml @@ -21,6 +21,8 @@ dest: '/tmp/ansible.{{ __monitoring_plugins__download_url | basename }}' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] check_mode: false # run task even if `--check` is specified - name: 'Copy zip file from "/tmp/ansible.{{ __monitoring_plugins__download_url | basename }}" to "C:\Temp\{{ __monitoring_plugins__download_url | basename }}"' diff --git a/roles/monitoring_plugins_grafana_dashboards/tasks/main.yml b/roles/monitoring_plugins_grafana_dashboards/tasks/main.yml index f6bc9e71d..495f95b7b 100644 --- a/roles/monitoring_plugins_grafana_dashboards/tasks/main.yml +++ b/roles/monitoring_plugins_grafana_dashboards/tasks/main.yml @@ -37,6 +37,8 @@ executable: '/bin/bash' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified changed_when: false # no change on the remote host diff --git a/roles/moodle/tasks/main.yml b/roles/moodle/tasks/main.yml index 22d7fec4d..45f61cc06 100644 --- a/roles/moodle/tasks/main.yml +++ b/roles/moodle/tasks/main.yml @@ -15,6 +15,8 @@ check_mode: false # run task even if `--check` is specified delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] run_once: true - name: 'Get the latest patch version of moodle v{{ moodle__version }}' @@ -45,6 +47,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified @@ -190,6 +194,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/opensearch/tasks/main.yml b/roles/opensearch/tasks/main.yml index 5500607a8..7972330c3 100644 --- a/roles/opensearch/tasks/main.yml +++ b/roles/opensearch/tasks/main.yml @@ -263,6 +263,8 @@ delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] tags: - 'never' - 'opensearch:generate_certs' diff --git a/roles/openvpn_server/tasks/main.yml b/roles/openvpn_server/tasks/main.yml index a805949e5..f5a6ecbab 100644 --- a/roles/openvpn_server/tasks/main.yml +++ b/roles/openvpn_server/tasks/main.yml @@ -103,6 +103,8 @@ mode: 0o600 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change to the server tags: diff --git a/roles/repo_elasticsearch/tasks/Debian.yml b/roles/repo_elasticsearch/tasks/Debian.yml index dd9b63974..8c75c5931 100644 --- a/roles/repo_elasticsearch/tasks/Debian.yml +++ b/roles/repo_elasticsearch/tasks/Debian.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_epel/tasks/main.yml b/roles/repo_epel/tasks/main.yml index 9dc279380..a7580a5f8 100644 --- a/roles/repo_epel/tasks/main.yml +++ b/roles/repo_epel/tasks/main.yml @@ -34,6 +34,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_grafana/tasks/Debian.yml b/roles/repo_grafana/tasks/Debian.yml index 3f40e5a70..a446efa5b 100644 --- a/roles/repo_grafana/tasks/Debian.yml +++ b/roles/repo_grafana/tasks/Debian.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_grafana/tasks/RedHat.yml b/roles/repo_grafana/tasks/RedHat.yml index 937017538..37abaf0bb 100644 --- a/roles/repo_grafana/tasks/RedHat.yml +++ b/roles/repo_grafana/tasks/RedHat.yml @@ -6,6 +6,8 @@ dest: '/tmp/ansible.grafana.key' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_graylog/tasks/Debian.yml b/roles/repo_graylog/tasks/Debian.yml index 04a2d5b12..2fd777183 100644 --- a/roles/repo_graylog/tasks/Debian.yml +++ b/roles/repo_graylog/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_graylog/tasks/RedHat.yml b/roles/repo_graylog/tasks/RedHat.yml index 0b46d0b83..df03b1d83 100644 --- a/roles/repo_graylog/tasks/RedHat.yml +++ b/roles/repo_graylog/tasks/RedHat.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_icinga/tasks/Debian.yml b/roles/repo_icinga/tasks/Debian.yml index 91707c3bb..a1c5ba964 100644 --- a/roles/repo_icinga/tasks/Debian.yml +++ b/roles/repo_icinga/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_icinga/tasks/RedHat.yml b/roles/repo_icinga/tasks/RedHat.yml index 68973b6d1..143ee87a6 100644 --- a/roles/repo_icinga/tasks/RedHat.yml +++ b/roles/repo_icinga/tasks/RedHat.yml @@ -60,6 +60,8 @@ dest: '/tmp/ansible.RPM-GPG-KEY-ICINGA' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_influxdb/tasks/Debian.yml b/roles/repo_influxdb/tasks/Debian.yml index 9e7d7bab9..787c90d79 100644 --- a/roles/repo_influxdb/tasks/Debian.yml +++ b/roles/repo_influxdb/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_influxdb/tasks/RedHat.yml b/roles/repo_influxdb/tasks/RedHat.yml index b7bb08c7d..b0180c7e3 100644 --- a/roles/repo_influxdb/tasks/RedHat.yml +++ b/roles/repo_influxdb/tasks/RedHat.yml @@ -6,6 +6,8 @@ dest: '/tmp/ansible.influxdata-archive.key' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mariadb/tasks/Debian.yml b/roles/repo_mariadb/tasks/Debian.yml index ce54b3666..fa62bb407 100644 --- a/roles/repo_mariadb/tasks/Debian.yml +++ b/roles/repo_mariadb/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mariadb/tasks/RedHat.yml b/roles/repo_mariadb/tasks/RedHat.yml index e5ad77e70..1e9debc40 100644 --- a/roles/repo_mariadb/tasks/RedHat.yml +++ b/roles/repo_mariadb/tasks/RedHat.yml @@ -52,6 +52,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mariadb/tasks/download-gpg-key.yml b/roles/repo_mariadb/tasks/download-gpg-key.yml index 1ccecab55..07a0df5ea 100644 --- a/roles/repo_mariadb/tasks/download-gpg-key.yml +++ b/roles/repo_mariadb/tasks/download-gpg-key.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mongodb/tasks/Debian.yml b/roles/repo_mongodb/tasks/Debian.yml index 51d96c3c7..9f4d01d15 100644 --- a/roles/repo_mongodb/tasks/Debian.yml +++ b/roles/repo_mongodb/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mongodb/tasks/RedHat.yml b/roles/repo_mongodb/tasks/RedHat.yml index 98b415d67..51dedf421 100644 --- a/roles/repo_mongodb/tasks/RedHat.yml +++ b/roles/repo_mongodb/tasks/RedHat.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_monitoring_plugins/tasks/Debian.yml b/roles/repo_monitoring_plugins/tasks/Debian.yml index 5624e85b0..bec90cca2 100644 --- a/roles/repo_monitoring_plugins/tasks/Debian.yml +++ b/roles/repo_monitoring_plugins/tasks/Debian.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_monitoring_plugins/tasks/RedHat.yml b/roles/repo_monitoring_plugins/tasks/RedHat.yml index aa36f1077..975dc183c 100644 --- a/roles/repo_monitoring_plugins/tasks/RedHat.yml +++ b/roles/repo_monitoring_plugins/tasks/RedHat.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_monitoring_plugins/tasks/Suse.yml b/roles/repo_monitoring_plugins/tasks/Suse.yml index a6c0ab5bb..0a9268586 100644 --- a/roles/repo_monitoring_plugins/tasks/Suse.yml +++ b/roles/repo_monitoring_plugins/tasks/Suse.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_mydumper/tasks/Debian.yml b/roles/repo_mydumper/tasks/Debian.yml index ec027ba99..8216f29c4 100644 --- a/roles/repo_mydumper/tasks/Debian.yml +++ b/roles/repo_mydumper/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_opensearch/tasks/Debian.yml b/roles/repo_opensearch/tasks/Debian.yml index fb2f5e651..df87d1b9e 100644 --- a/roles/repo_opensearch/tasks/Debian.yml +++ b/roles/repo_opensearch/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_opensearch/tasks/RedHat.yml b/roles/repo_opensearch/tasks/RedHat.yml index b881563d6..5f8d6d12c 100644 --- a/roles/repo_opensearch/tasks/RedHat.yml +++ b/roles/repo_opensearch/tasks/RedHat.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_proxysql/tasks/Debian.yml b/roles/repo_proxysql/tasks/Debian.yml index 4d3d7e214..d23e30397 100644 --- a/roles/repo_proxysql/tasks/Debian.yml +++ b/roles/repo_proxysql/tasks/Debian.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_proxysql/tasks/RedHat.yml b/roles/repo_proxysql/tasks/RedHat.yml index d72746f35..71db6c708 100644 --- a/roles/repo_proxysql/tasks/RedHat.yml +++ b/roles/repo_proxysql/tasks/RedHat.yml @@ -8,6 +8,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_redis/tasks/main.yml b/roles/repo_redis/tasks/main.yml index 052d0f955..df6f48d96 100644 --- a/roles/repo_redis/tasks/main.yml +++ b/roles/repo_redis/tasks/main.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_rpmfusion/tasks/download-gpg-key.yml b/roles/repo_rpmfusion/tasks/download-gpg-key.yml index 7d526c12b..8b50ced77 100644 --- a/roles/repo_rpmfusion/tasks/download-gpg-key.yml +++ b/roles/repo_rpmfusion/tasks/download-gpg-key.yml @@ -7,6 +7,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/repo_sury/tasks/main.yml b/roles/repo_sury/tasks/main.yml index a9d2a0618..37eb861b0 100644 --- a/roles/repo_sury/tasks/main.yml +++ b/roles/repo_sury/tasks/main.yml @@ -9,6 +9,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the server check_mode: false # run task even if `--check` is specified diff --git a/roles/rstudio_server/tasks/main.yml b/roles/rstudio_server/tasks/main.yml index 61fe44d57..c68f9fe98 100644 --- a/roles/rstudio_server/tasks/main.yml +++ b/roles/rstudio_server/tasks/main.yml @@ -163,6 +163,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the target check_mode: false # run task even if `--check` is specified diff --git a/roles/shared/tasks/clone-lib-repo.yml b/roles/shared/tasks/clone-lib-repo.yml index 6f271e468..f917ceafb 100644 --- a/roles/shared/tasks/clone-lib-repo.yml +++ b/roles/shared/tasks/clone-lib-repo.yml @@ -17,6 +17,8 @@ depth: 1 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified @@ -28,6 +30,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts changed_when: false # no change on the remote host @@ -39,5 +43,7 @@ depth: 1 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified diff --git a/roles/shared/tasks/clone-monitoring-plugins-repo.yml b/roles/shared/tasks/clone-monitoring-plugins-repo.yml index 291c85854..c0fde0ca5 100644 --- a/roles/shared/tasks/clone-monitoring-plugins-repo.yml +++ b/roles/shared/tasks/clone-monitoring-plugins-repo.yml @@ -17,6 +17,8 @@ depth: 1 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified @@ -28,6 +30,8 @@ state: 'absent' delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts changed_when: false # no change on the remote host @@ -39,5 +43,7 @@ depth: 1 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] throttle: 1 # serialize: shared git working dir on the controller, avoid races between hosts check_mode: false # run task even if `--check` is specified diff --git a/roles/shiny_server/tasks/main.yml b/roles/shiny_server/tasks/main.yml index 9a7b9ec31..95bb9478e 100644 --- a/roles/shiny_server/tasks/main.yml +++ b/roles/shiny_server/tasks/main.yml @@ -204,6 +204,8 @@ mode: 0o644 delegate_to: 'localhost' become: false + vars: + ansible_become: false # noqa var-naming[pattern] changed_when: false # not an actual config change on the target check_mode: false # run task even if `--check` is specified From ff8251b38b983c3acfad6f58db9eaabab8f4c3db Mon Sep 17 00:00:00 2001 From: Markus Frei Date: Thu, 1 Oct 2026 21:11:07 +0200 Subject: [PATCH 2/2] docs(readme): recommend pinning the Python interpreter of managed nodes Since ansible-core 2.17 the interpreter discovery picks the newest python3.X instead of the system Python. After setup_basic installed Python 3.11 (RHEL 9) or 3.13 (RHEL 10) for duplicity, the next run failed in kernel_settings, python_venv and monitoring_plugins. Measured on Rocky 9 and 10 with ansible-core 2.18. --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index c2db8f715..be3c7f2c6 100644 --- a/README.md +++ b/README.md @@ -86,6 +86,14 @@ Full documentation is available at [linuxfabrik.github.io/lfops](https://linuxfa If you manage RHEL 8 hosts with the default system Python (3.6), use **ansible-core 2.16**. If all your managed nodes have Python >= 3.8 (e.g. RHEL 9+, Debian 12+, Ubuntu 22.04+), you can use **ansible-core 2.18** for the latest features. +**Set the Python interpreter of the managed nodes.** Since ansible-core 2.17, Ansible no longer prefers the system Python of the distribution, but the newest `python3.X` from its list of known versions that it finds on the host. Some roles install an additional Python, for example duplicity (Python 3.11 on RHEL 9, Python 3.13 on RHEL 10). From the next run on, Ansible then runs its modules under that Python, which lacks the Python libraries of the distribution, and roles such as kernel_settings, monitoring_plugins and python_venv fail. Pin the system Python in the inventory for all hosts except RHEL 8, where ansible-core 2.16 already picks `/usr/libexec/platform-python`: + +```yaml +ansible_python_interpreter: '/usr/bin/python3' +``` + +Tasks that run on the Ansible controller are not affected by this setting, they use the Python that runs Ansible. + ## Installation