Lesson 20 / 26

Least Privilege and no_log

Limit privilege escalation and keep secrets out of logs.

Narrow privilege, quiet logs

Use become: true only on tasks that need it, rather than a whole play, and consider become_user for a service account. Tasks that handle passwords or tokens should set no_log: true so their arguments and results do not appear in console output, CI logs or callback plugins. Remember that -v output and debug tasks can also leak secrets, so never print secret variables.

no_log on a sensitive task

Without no_log, the module arguments (including the password hash) could be printed on failure. (Illustrative.)

- name: Create database user
  community.mysql.mysql_user:
    name: app
    password: "{{ vault_db_password }}"
    priv: "appdb.*:ALL"
    state: present
  no_log: true
  become: true

Quick check: What does `no_log: true` do?

  • Disables the task
  • Hides the task's arguments and results from output and logs
  • Encrypts the playbook
  • Skips error checking
Answer

Hides the task's arguments and results from output and logs — It prevents sensitive values from appearing in console or log output.