4 ms·
> It has unrestricted access to everything It only has unrestricted access to what you give it unrestricted access to. If your ansible playbooks use a user th
by crymer11 9y ago
> It has unrestricted access to everything
It only has unrestricted access to what you give it unrestricted access to.
If your ansible playbooks use a user that doesn't have root access and limited sudo powers, then it's not much different from using Ara.
- mikepurvis 9y agoThat's fair, but Ansible culture is to do everything as sudo, and traditionally it was pretty painful to execute only portions of a playbook as the sudo. Though it looks like that's gotten better in more recent times: http://docs.ansible.com/ansible/latest/become.html http://docs.ansible.com/ansible/latest/become.html
- emmelaich 9y agoThe big improvement was the ability to turn sudo off/on for a particular task. Not sure when that was introduced. 1.9.something?
- ghjm 9y agoEven if your playbooks run everything as sudo, that doesn't mean you have to grant AWX/Tower users the ability to create arbitrary playbooks or run anything else as sudo. You certainly can do that, but the point of the RBAC feature of Tower is that you don't have to.
- lima 9y agoIf you're using Ansible for configuration management, it'll need root access either way.
- user5994461 9y agoIt doesn't need root access. It's just that most of the useful things to do on a server require root.
- rmenr 9y agoTo do anything useful, you'd have to give it sudoer privs - this is true. If you're squeamish about that, on principle, then Salt, Chef, and Puppet would be problematic as well. The only logical choice would be to provision and bake all of your images and push the AMI up to AWS...in which case Ansible would be an excellent utility anyway.