revoke-sudo: delete cloud-config sudoers file
Change-Id: Icc3d1b4122d5328dd900d8ce581755f53030ed21
This commit is contained in:
parent
7325aca987
commit
86b6edb421
@ -3,11 +3,13 @@
|
||||
failed_when: false
|
||||
register: zuul_is_sudoer
|
||||
|
||||
# We do this in one command and not in a loop
|
||||
# to make sure we don't revoke sudo in the first file
|
||||
# and then error because we lost sudo access when we
|
||||
# try to delete the next file.
|
||||
- name: Remove sudo access for zuul user.
|
||||
become: yes
|
||||
file:
|
||||
path: /etc/sudoers.d/zuul
|
||||
state: absent
|
||||
command: rm -rf /etc/sudoers.d/zuul /etc/sudoers.d/90-cloud-init-users # noqa 302
|
||||
when: zuul_is_sudoer.rc == 0
|
||||
|
||||
- name: Prove that general sudo access is actually revoked.
|
||||
|
Loading…
Reference in New Issue
Block a user