How to use pbrun_exe in 1.9+

60 views
Skip to first unread message

Wim Van Dijck

unread,
Apr 28, 2015, 10:18:55 AM4/28/15
to ansible...@googlegroups.com

Hi,

running ansible 2.0.0 from git repo.
I'm very excited to try out the new become feature with powerbroker, but I'm struggling to get it to work with our setup.
I do realize this feature is still alpha btw ;)

I read that there is a setting ''pbrun_exe", just like su_exe, but I cannot get it to work.
I would like to try it, since our powerbroker profiles are very strict and pbrun can run very few commands.
However, for installation purposes we can get root elevation, so pbrun su root is allowed.
So I would basically like to run all commands that way.

This works fine for adhoc commands btw, if I use su_exe = pbrun su root, then I can run single commands and even modules.
But for playbooks this doesn't seem to work.

Any pointers on how I can get this to work?

Kind regards,
Wim

Brian Coca

unread,
Apr 28, 2015, 11:48:36 AM4/28/15
to ansible...@googlegroups.com
ansible does not support chaining privilege escalation methods and
requires permissive access to run commands as a user
http://docs.ansible.com/become.html (read notes)
> --
> You received this message because you are subscribed to the Google Groups
> "Ansible Project" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ansible-proje...@googlegroups.com.
> To post to this group, send email to ansible...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ansible-project/b0dace16-1027-459a-b0b3-c050a59dc114%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.



--
Brian Coca
Reply all
Reply to author
Forward
0 new messages