Check the intended execution of Ansible become settings

Make the target user and the scope of user switching explicit.

Description

Setting become_user alone does not enable user switching. However, become can be supplied by higher-level settings or variables, so a single task line does not establish the execution account.

Potential impact

Misunderstanding the execution account can cause failures or changes made with the wrong account’s permissions.

Remediation

For plays or tasks that need switching, specify the target become_user together with become: true. Avoid expanding privileges to unrelated tasks and verify the effective settings.

Examples

The examples show explicit user-switching configuration. The target account and permission to switch must exist; whoami can check the account used for a command.

Before

yaml
- hosts: localhost
  name: become_user without become
  become_user: bar
  tasks:
    - name: Simple hello
      ansible.builtin.debug:
        msg: hello

- hosts: localhost
  tasks:
    - name: become_user without become
      ansible.builtin.command: whoami
      become_user: mysql
      changed_when: false

After

yaml
- hosts: localhost
  become_user: postgres
  become: true
  tasks:
    - name: some task
      ansible.builtin.command: whoami
      changed_when: false

References