Description
Setting become_user alone does not enable user switching. However, become can be supplied by higher-level settings or variables, so a single task line does not establish the execution account.
Potential impact
Misunderstanding the execution account can cause failures or changes made with the wrong account’s permissions.
Remediation
For plays or tasks that need switching, specify the target become_user together with become: true. Avoid expanding privileges to unrelated tasks and verify the effective settings.
Examples
The examples show explicit user-switching configuration. The target account and permission to switch must exist; whoami can check the account used for a command.
Before
yaml
- hosts: localhost
name: become_user without become
become_user: bar
tasks:
- name: Simple hello
ansible.builtin.debug:
msg: hello
- hosts: localhost
tasks:
- name: become_user without become
ansible.builtin.command: whoami
become_user: mysql
changed_when: false
After
yaml
- hosts: localhost
become_user: postgres
become: true
tasks:
- name: some task
ansible.builtin.command: whoami
changed_when: false