Lesson 20 / 26
Least Privilege and no_log
Limit privilege escalation and keep secrets out of logs.
Narrow privilege, quiet logs
Use become: true only on tasks that need it, rather than a whole play, and consider become_user for a service account. Tasks that handle passwords or tokens should set no_log: true so their arguments and results do not appear in console output, CI logs or callback plugins. Remember that -v output and debug tasks can also leak secrets, so never print secret variables.
no_log on a sensitive task
Without no_log, the module arguments (including the password hash) could be printed on failure. (Illustrative.)
- name: Create database user
community.mysql.mysql_user:
name: app
password: "{{ vault_db_password }}"
priv: "appdb.*:ALL"
state: present
no_log: true
become: trueQuick check: What does `no_log: true` do?
- Disables the task
- Hides the task's arguments and results from output and logs
- Encrypts the playbook
- Skips error checking
Answer
Hides the task's arguments and results from output and logs — It prevents sensitive values from appearing in console or log output.