# SSH, Become and ansible.cfg — Ansible: Automate Servers with Playbooks

Source: https://www.geekswithgeeks.com/en/ansible/ans-connection-config

> Connect with SSH keys, escalate privileges with become and set project defaults in ansible.cfg.

## Keys, users and privilege

Ansible uses your normal SSH setup: key-based login, the remote user (`ansible_user`) and `~/.ssh/config`. Prefer **SSH keys** over passwords. Many tasks need root, so use **`become: true`** (sudo) for those tasks rather than logging in as root. A project-level **`ansible.cfg`** sets defaults such as the inventory path and number of parallel connections (`forks`) so every command in the repo behaves the same way.

## A small ansible.cfg

Commit this next to your playbooks. Keep host-key checking on for real environments; turn it off only in throwaway labs.

```ini
[defaults]
inventory = inventory.ini
remote_user = deploy
forks = 10
retry_files_enabled = False
host_key_checking = True

[privilege_escalation]
become = False          # opt in per play/task with become: true
become_method = sudo
```

## Give the deploy user only the sudo it needs

A dedicated automation user with passwordless sudo limited to needed commands is safer than using a shared root account. Rotate and protect its SSH key.

**Quiz:** How should a task that needs root normally get it?

- [ ] Logging in as root with a password
- [x] become: true on that task or play
- [ ] Disabling SSH
- [ ] Sharing a private key in chat

*Answer:* become: true on that task or play. Privilege escalation per task keeps the connection user unprivileged by default.
