From 502cec92f36b2d7c50a5620b35805e01210daf20 Mon Sep 17 00:00:00 2001 From: Hyperling Date: Fri, 2 Oct 2026 11:11:38 -0700 Subject: [PATCH] sudo, fix to current lint standards. --- tasks/general/acct_mgmt/sudo.yml | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/tasks/general/acct_mgmt/sudo.yml b/tasks/general/acct_mgmt/sudo.yml index a387d7c..d3f3c76 100644 --- a/tasks/general/acct_mgmt/sudo.yml +++ b/tasks/general/acct_mgmt/sudo.yml @@ -2,32 +2,33 @@ # Ensure the proper users have sudo access. - name: General | Account Management | Sudo | Copy Ansible - copy: + ansible.builtin.copy: src: sudo/sudoers_ansible dest: "{{ sudoers_install_dir }}" owner: root group: "{{ root_group }}" - mode: 0440 + mode: "0440" - name: General | Account Management | Sudo | Copy Sudo Group - copy: + ansible.builtin.copy: src: sudo/sudoers_sudo dest: "{{ sudoers_install_dir }}" owner: root group: "{{ root_group }}" - mode: 0440 + mode: "0440" # Disable these two lines in openSUSE default configuration. #Defaults targetpw # ask for the password of the target user i.e. root #ALL ALL=(ALL) ALL # WARNING! Only use this together with 'Defaults targetpw'! - name: General | Account Management | Sudo | Disable openSUSE Root PW Prompt - lineinfile: + ansible.builtin.lineinfile: path: "{{ sudoers_config }}" regexp: '{{ item.key }}' line: '{{ item.value }} # MANAGED BY ANSIBLE' state: present create: true backup: true + mode: "644" loop: - { "key": '^[\#]?Defaults targetpw', "value": '#Defaults targetpw'} - { "key": '^[\#]?ALL ALL\=\(ALL\) ALL', "value": '#ALL ALL=(ALL) ALL'}