Don't use become for Kolla Ansible
Using become for all Kolla Ansible tasks is not ideal from a security perspective. It is also incompatible with fact caching, since it causes facts to be gathered and cached as root, which changes some facts. This change modifies the default value of kolla_ansible_become to false. Change-Id: I9ee5c55e59276f70c92e9c698c01123dcf8919a1 Story: 2007492 Task: 39217
This commit is contained in:
parent
15e2dce049
commit
939e298c56
@ -335,7 +335,7 @@ kolla_ansible_group: kolla
|
||||
|
||||
# Whether to use privilege escalation for all operations performed via Kolla
|
||||
# Ansible.
|
||||
kolla_ansible_become: true
|
||||
kolla_ansible_become: false
|
||||
|
||||
###############################################################################
|
||||
# Kolla feature flag configuration.
|
||||
|
@ -54,7 +54,7 @@ kolla_ansible_group: kolla
|
||||
|
||||
# Whether to use privilege escalation for all operations performed via Kolla
|
||||
# Ansible.
|
||||
kolla_ansible_become: true
|
||||
kolla_ansible_become: false
|
||||
|
||||
###############################################################################
|
||||
# Kolla-ansible inventory configuration.
|
||||
|
@ -151,7 +151,7 @@ The following variables affect how Ansible accesses the remote hosts.
|
||||
Primary group of Kolla SSH user. Default is ``kolla``.
|
||||
``kolla_ansible_become``
|
||||
Whether to use privilege escalation for all operations performed via Kolla
|
||||
Ansible. Default is ``true``.
|
||||
Ansible. Default is ``false`` since the 8.0.0 Ussuri release.
|
||||
``kolla_ansible_target_venv``
|
||||
Path to a virtual environment on remote hosts to use for Ansible module
|
||||
execution. Default is ``{{ virtualenv_path }}/kolla-ansible``. May be set
|
||||
|
@ -169,7 +169,7 @@
|
||||
#kolla_ansible_group:
|
||||
|
||||
# Whether to use privilege escalation for all operations performed via Kolla
|
||||
# Ansible. Default is 'true'.
|
||||
# Ansible. Default is 'false'.
|
||||
#kolla_ansible_become:
|
||||
|
||||
###############################################################################
|
||||
|
@ -0,0 +1,6 @@
|
||||
---
|
||||
upgrade:
|
||||
- |
|
||||
Modifies the default value of ``kolla_ansible_become`` to ``false``. This
|
||||
means that Kolla Ansible will no longer use privilege escalation for all
|
||||
tasks, and will only use it where necessary.
|
Loading…
Reference in New Issue
Block a user