]> git-server-git.apps.pok.os.sepia.ceph.com Git - ceph-ansible.git/commitdiff
ceph-mon: No become during gen mon initial keyring
authorJukka Nousiainen <jukka.nousiainen@csc.fi>
Wed, 2 Dec 2020 09:07:25 +0000 (11:07 +0200)
committerGuillaume Abrioux <gabrioux@redhat.com>
Thu, 3 Dec 2020 09:04:21 +0000 (10:04 +0100)
Since the backing generate_secret() just hands out urandom output,
running as privileged doesn't seem to be required. It's not
desireable to provide sudo in some Ansible runner environments.

Signed-off-by: Jukka Nousiainen <jukka.nousiainen@csc.fi>
roles/ceph-mon/tasks/deploy_monitors.yml

index a8d713758bcef7785ad7bd6c11fb028a43259d4b..7e8091fd03d3372be52aa98d1020471319c5f996 100644 (file)
@@ -20,6 +20,7 @@
     state: generate_secret
   register: monitor_keyring
   delegate_to: localhost
+  become: false
   run_once: true
   when:
     - initial_mon_key.skipped is defined