diff --git a/tasks/general/acct_mgmt/sudo.yml b/tasks/general/acct_mgmt/sudo.yml index a387d7c..d3f3c76 100644 --- a/tasks/general/acct_mgmt/sudo.yml +++ b/tasks/general/acct_mgmt/sudo.yml @@ -2,32 +2,33 @@ # Ensure the proper users have sudo access. - name: General | Account Management | Sudo | Copy Ansible - copy: + ansible.builtin.copy: src: sudo/sudoers_ansible dest: "{{ sudoers_install_dir }}" owner: root group: "{{ root_group }}" - mode: 0440 + mode: "0440" - name: General | Account Management | Sudo | Copy Sudo Group - copy: + ansible.builtin.copy: src: sudo/sudoers_sudo dest: "{{ sudoers_install_dir }}" owner: root group: "{{ root_group }}" - mode: 0440 + mode: "0440" # Disable these two lines in openSUSE default configuration. #Defaults targetpw # ask for the password of the target user i.e. root #ALL ALL=(ALL) ALL # WARNING! Only use this together with 'Defaults targetpw'! - name: General | Account Management | Sudo | Disable openSUSE Root PW Prompt - lineinfile: + ansible.builtin.lineinfile: path: "{{ sudoers_config }}" regexp: '{{ item.key }}' line: '{{ item.value }} # MANAGED BY ANSIBLE' state: present create: true backup: true + mode: "644" loop: - { "key": '^[\#]?Defaults targetpw', "value": '#Defaults targetpw'} - { "key": '^[\#]?ALL ALL\=\(ALL\) ALL', "value": '#ALL ALL=(ALL) ALL'}