From fc761c1952a12f2a27d136349b47d103a82e4636 Mon Sep 17 00:00:00 2001 From: cyberops7 <18562612+cyberops7@users.noreply.github.com> Date: Thu, 2 Jul 2026 00:18:43 -0600 Subject: [PATCH] Add explicit become: true to apply-manifests kubectl tasks MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit These tasks set become_user without a task-level become, tripping ansible-lint's partial-become rule. become is already enabled globally via ansible_become in group_vars/all.yaml, so the tasks already escalate to the ansible user — but that is invisible to the linter (and to anyone reading the task in isolation). Make it explicit with become: true alongside become_user. Behavior-neutral: verified with ansible-playbook -vvv that the escalation target is unchanged (sudo -u ansible; chown ansible on the temp files), so kubectl still runs as the ansible user that owns ~/.kube/config. --- .../Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml b/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml index 9eb8a60..4a3bd28 100644 --- a/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml +++ b/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml @@ -6,6 +6,7 @@ retries: 120 delay: 10 changed_when: true + become: true become_user: "{{ ansible_user }}" when: inventory_hostname == groups['servers'][0] @@ -13,6 +14,7 @@ - name: Apply metallb namespace ansible.builtin.command: cmd: kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.12.1/manifests/namespace.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -21,6 +23,7 @@ - name: Apply metallb manifest ansible.builtin.command: cmd: kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/{{ metallb_version }}/config/manifests/metallb-native.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -30,6 +33,7 @@ ansible.builtin.command: cmd: "kubectl wait --namespace metallb-system --for=condition=ready pod --selector=component=controller --timeout=1800s" changed_when: true + become: true become_user: "{{ ansible_user }}" when: inventory_hostname == groups['servers'][0] @@ -47,6 +51,7 @@ - name: Apply metallb L2 Advertisement ansible.builtin.command: cmd: kubectl apply -f /home/{{ ansible_user }}/l2advertisement.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -65,6 +70,7 @@ - name: Apply metallb ipppool ansible.builtin.command: cmd: kubectl apply -f /home/{{ ansible_user }}/ippool.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0]