Lesson 4 / 26
SSH, Become and ansible.cfg
Connect with SSH keys, escalate privileges with become and set project defaults in ansible.cfg.
Keys, users and privilege
Ansible uses your normal SSH setup: key-based login, the remote user (ansible_user) and ~/.ssh/config. Prefer SSH keys over passwords. Many tasks need root, so use become: true (sudo) for those tasks rather than logging in as root. A project-level ansible.cfg sets defaults such as the inventory path and number of parallel connections (forks) so every command in the repo behaves the same way.
A small ansible.cfg
Commit this next to your playbooks. Keep host-key checking on for real environments; turn it off only in throwaway labs.
[defaults]
inventory = inventory.ini
remote_user = deploy
forks = 10
retry_files_enabled = False
host_key_checking = True
[privilege_escalation]
become = False # opt in per play/task with become: true
become_method = sudoGive the deploy user only the sudo it needs
A dedicated automation user with passwordless sudo limited to needed commands is safer than using a shared root account. Rotate and protect its SSH key.
Quick check: How should a task that needs root normally get it?
- Logging in as root with a password
- become: true on that task or play
- Disabling SSH
- Sharing a private key in chat
Answer
become: true on that task or play — Privilege escalation per task keeps the connection user unprivileged by default.