Question:
What are best practices for privilege escalation when dealing with molecule?
Scenario:
I’m trying to write a role that burns an ISO to a USB. In testing this in ansible, I noticed I’m using a pattern to create a loop device. So despite not really requiring a create_loop_device play for my end goal, I decided to make one and test it just so I could use it in my other tests. Various commands for that setup require become, however molecule runs everything non-interactively (afaiui).
What I’ve tried
Using ansible native, I was able to get around this in 2 ways:
- add
-Kto the molecule config
this screws up the terminal - run a sudo command and then run
moleculewhile the pam timeout is active
Neither of which seems ideal to me. Then I thought, “well, if I use docker, then ansible can just run commands as root”
My Guess
The final playbook I’m writing is intended to run on localhost. Since there are commands that genuinely need become in the task, I’d use -K when running the playbook with ansible-playbook. I would think that’s the best practice when running playbooks that need to use commands such as losetup, esp on localhost where a password prompt is typical. In molecule, I am thinking I could spin up a docker container and just run the commands as root, but there would need to be a way to ignore the become directives in the tasks it’s testing (i.e. “I am already root, I don’t need to run sudo”).