From eb7473491b25c5f899a110f6ae1076ef5096d6d5 Mon Sep 17 00:00:00 2001 From: Jukka Nousiainen Date: Wed, 2 Dec 2020 11:07:25 +0200 Subject: [PATCH] ceph-mon: No become during gen mon initial keyring Since the backing generate_secret() just hands out urandom output, running as privileged doesn't seem to be required. It's not desireable to provide sudo in some Ansible runner environments. Signed-off-by: Jukka Nousiainen --- roles/ceph-mon/tasks/deploy_monitors.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/roles/ceph-mon/tasks/deploy_monitors.yml b/roles/ceph-mon/tasks/deploy_monitors.yml index a8d713758..7e8091fd0 100644 --- a/roles/ceph-mon/tasks/deploy_monitors.yml +++ b/roles/ceph-mon/tasks/deploy_monitors.yml @@ -20,6 +20,7 @@ state: generate_secret register: monitor_keyring delegate_to: localhost + become: false run_once: true when: - initial_mon_key.skipped is defined -- 2.39.5