]> git-server-git.apps.pok.os.sepia.ceph.com Git - ceph-ansible.git/commitdiff
ceph-mon: No become during gen mon initial keyring
authorJukka Nousiainen <jukka.nousiainen@csc.fi>
Wed, 2 Dec 2020 09:07:25 +0000 (11:07 +0200)
committerGuillaume Abrioux <gabrioux@redhat.com>
Tue, 15 Dec 2020 16:31:37 +0000 (17:31 +0100)
Since the backing generate_secret() just hands out urandom output,
running as privileged doesn't seem to be required. It's not
desireable to provide sudo in some Ansible runner environments.

Signed-off-by: Jukka Nousiainen <jukka.nousiainen@csc.fi>
(cherry picked from commit eb7473491b25c5f899a110f6ae1076ef5096d6d5)

roles/ceph-mon/tasks/deploy_monitors.yml

index 81eb2f64c9f777d848967d3be2eb88f66964e524..ef057f96bb9a0723c69ce1c6c4838f4db51df434 100644 (file)
@@ -19,6 +19,7 @@
     state: generate_secret
   register: monitor_keyring
   delegate_to: localhost
+  become: false
   run_once: true
   when:
     - initial_mon_key.skipped is defined