# Least Privilege and no_log — Ansible: Automate Servers with Playbooks

Source: https://www.geekswithgeeks.com/en/ansible/sec-become-no-log

> Limit privilege escalation and keep secrets out of logs.

## Narrow privilege, quiet logs

Use `become: true` only on tasks that need it, rather than a whole play, and consider `become_user` for a service account. Tasks that handle passwords or tokens should set **`no_log: true`** so their arguments and results do not appear in console output, CI logs or callback plugins. Remember that `-v` output and `debug` tasks can also leak secrets, so never print secret variables.

## no_log on a sensitive task

Without `no_log`, the module arguments (including the password hash) could be printed on failure. (Illustrative.)

```yaml
- name: Create database user
  community.mysql.mysql_user:
    name: app
    password: "{{ vault_db_password }}"
    priv: "appdb.*:ALL"
    state: present
  no_log: true
  become: true
```

**Quiz:** What does `no_log: true` do?

- [ ] Disables the task
- [x] Hides the task's arguments and results from output and logs
- [ ] Encrypts the playbook
- [ ] Skips error checking

*Answer:* Hides the task's arguments and results from output and logs. It prevents sensitive values from appearing in console or log output.
