Review Ansible’s default user-switching settings

Enable user switching only where required and verify the execution account.

Description

become_user selects the target account; it does not enable switching by itself. In ansible.cfg, user-switching settings belong in the [privilege_escalation] section.

Potential impact

A mismatch between effective settings and execution intent can cause failures or run tasks with an unexpected account’s permissions.

Remediation

When switching users is required, set become=True and the intended become_user. Apply it only to the plays or tasks that need it; leave it disabled otherwise.

Examples

The examples compare disabled and enabled settings in the correct section. Other settings or variables can take precedence, so verify the effective configuration and permission to switch users.

Before

text
[privilege_escalation]
become=False
become_method=sudo
become_user=root

After

text
[privilege_escalation]
become=True
become_method=sudo
become_user=root

References