【问题标题】:Ansible SSH as one user and Sudo as anotherAnsible SSH 作为一个用户,Sudo 作为另一个用户
【发布时间】:2014-07-14 18:14:37
【问题描述】:

我在调整 Ansible 配置以适应我的环境时遇到了一些困难。

我的测试环境:

  • PermitRootLogin 没有
  • 只允许一个用户通过 SSH 连接(foo,没有任何权限)
  • 具有 sudo 权限的用户(bar ALL=(ALL) ALL)

我的 ansible 主机清单如下所示:

[servers]
server1 ansible_ssh_host=192.168.0.1 ansible_sudo=true ansible_ssh_user=foo ansible_sudo_user=bar

我有一个 foo 用户的 SSH 密钥。

当我使用 bar 密码尝试这个临时命令(或任何其他命令)时:

ansible server1 -m raw -a "echo test > /etc/testfile" --ask-sudo-pass
server1 | FAILED => Incorrect sudo password

然后,如果我使用 foo 密码执行相同的命令:

ansible server1 -m raw -a "echo test > /etc/testfile" --ask-sudo-pass
Sorry, user foo is not allowed to execute '/bin/bash -c echo SUDO-SUCCESS-rlpfhamukjnsfyokqbjpbttviiuildif; echo test > /etc/testfile' as bar on server1.

所以 Ansible 绝对使用 foo 作为 sudo 用户,而不是我指定的 bar。有没有办法强制使用 bar 而不是 foo?我真的不了解 Ansible 上的 sudo 功能,即使我对所有内容(SSH 栏和密码栏)都使用相同的用户 ansible give 返回我:

server1 | FAILED | rc=1 >>
echo test > /etc/testfile : Permission denied

当我在主机上以 bar 身份登录并执行“sudo echo test > /etc/testfile”时,它会询问我 bar 密码并正确执行命令。我的 Ansible 行为哪里错了?

【问题讨论】:

    标签: ssh ansible sudo ansible-inventory ansible-ad-hoc


    【解决方案1】:

    这样想:

    • ansible_ssh_user 是 ssh 到主机的用户
    • ansible_sudo_user 是主机上 sudo 的用户

    换句话说,以你的用户和命令为例,ansible 将运行的等效命令是:

    ssh foo@server1 sudo -u bar "echo test > testfile"

    因此需要提供foo 用户的密码,而不是bar 用户。 foo 用户需要以bar 的身份使用 sudo 权限。 sudoers 中的类似内容:

    foo    ALL=(bar) NOPASSWD: ALL
    

    现在foo 可以以bar 身份运行所有命令,无需密码。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2012-07-15
      • 1970-01-01
      • 1970-01-01
      • 2017-02-14
      相关资源
      最近更新 更多