Page MenuHomeDevCentral

Allow salt group to run salt-call as root
ClosedPublic

Authored by dereckson on Apr 28 2017, 16:12.
Tags
None
Referenced Files
F10941489: D977.id2510.diff
Wed, Aug 6, 16:31
F10939966: D977.id2498.diff
Wed, Aug 6, 14:27
F10933476: D977.id2498.diff
Tue, Aug 5, 19:21
Unknown Object (File)
Tue, Aug 5, 06:42
Unknown Object (File)
Mon, Aug 4, 13:39
Unknown Object (File)
Mon, Aug 4, 07:43
Unknown Object (File)
Sun, Aug 3, 15:23
Unknown Object (File)
Sat, Aug 2, 20:25
Subscribers
None

Details

Summary

By default, salt-call runs to the current user. As such, we should
allow to use as root to avoid to first have to touch files/directory,
then to .

Furthermore, it's not convenient to install packages or chown.

Security implication is salt group's members have a root access
to the Salt master too, currently Ysul, in addition to other servers.

Ref. T795.

Test Plan

sudo salt-call --local test.ping

Diff Detail

Repository
rOPS Nasqueron Operations
Lint
Lint Passed
Unit
No Test Coverage
Branch
allow-salt-call-as-root (branched from master)
Build Status
Buildable 1522
Build 1770: arc lint + arc unit