sudo, fix to current lint standards.
This commit is contained in:
@@ -2,32 +2,33 @@
|
||||
# Ensure the proper users have sudo access.
|
||||
|
||||
- name: General | Account Management | Sudo | Copy Ansible
|
||||
copy:
|
||||
ansible.builtin.copy:
|
||||
src: sudo/sudoers_ansible
|
||||
dest: "{{ sudoers_install_dir }}"
|
||||
owner: root
|
||||
group: "{{ root_group }}"
|
||||
mode: 0440
|
||||
mode: "0440"
|
||||
|
||||
- name: General | Account Management | Sudo | Copy Sudo Group
|
||||
copy:
|
||||
ansible.builtin.copy:
|
||||
src: sudo/sudoers_sudo
|
||||
dest: "{{ sudoers_install_dir }}"
|
||||
owner: root
|
||||
group: "{{ root_group }}"
|
||||
mode: 0440
|
||||
mode: "0440"
|
||||
|
||||
# Disable these two lines in openSUSE default configuration.
|
||||
#Defaults targetpw # ask for the password of the target user i.e. root
|
||||
#ALL ALL=(ALL) ALL # WARNING! Only use this together with 'Defaults targetpw'!
|
||||
- name: General | Account Management | Sudo | Disable openSUSE Root PW Prompt
|
||||
lineinfile:
|
||||
ansible.builtin.lineinfile:
|
||||
path: "{{ sudoers_config }}"
|
||||
regexp: '{{ item.key }}'
|
||||
line: '{{ item.value }} # MANAGED BY ANSIBLE'
|
||||
state: present
|
||||
create: true
|
||||
backup: true
|
||||
mode: "644"
|
||||
loop:
|
||||
- { "key": '^[\#]?Defaults targetpw', "value": '#Defaults targetpw'}
|
||||
- { "key": '^[\#]?ALL ALL\=\(ALL\) ALL', "value": '#ALL ALL=(ALL) ALL'}
|
||||
|
||||
Reference in New Issue
Block a user