From 30a5897c364ef4692f02b6aef15cd77803c938d0 Mon Sep 17 00:00:00 2001 From: Julian Labus Date: Tue, 25 Sep 2018 16:41:43 +0200 Subject: [PATCH] roles: don't become root when writing in /home/admin --- roles/service-bird-lg/tasks/lg-proxy.yml | 1 + roles/service-bird-lg/tasks/lg-webservice.yml | 1 + roles/service-bird-lg/tasks/main.yml | 1 + roles/service-nginx-meshviewer/tasks/main.yml | 4 ++++ 4 files changed, 7 insertions(+) diff --git a/roles/service-bird-lg/tasks/lg-proxy.yml b/roles/service-bird-lg/tasks/lg-proxy.yml index 87b4b04..fd4975a 100644 --- a/roles/service-bird-lg/tasks/lg-proxy.yml +++ b/roles/service-bird-lg/tasks/lg-proxy.yml @@ -3,6 +3,7 @@ template: src: lgproxy.cfg.j2 dest: "{{ lg_path }}/lgproxy.cfg" + become: false notify: - restart bird-lg-proxy diff --git a/roles/service-bird-lg/tasks/lg-webservice.yml b/roles/service-bird-lg/tasks/lg-webservice.yml index bf338da..c86e11a 100644 --- a/roles/service-bird-lg/tasks/lg-webservice.yml +++ b/roles/service-bird-lg/tasks/lg-webservice.yml @@ -3,6 +3,7 @@ template: src: lg.cfg.j2 dest: "{{ lg_path }}/lg.cfg" + become: false notify: - restart bird-lg-webservice diff --git a/roles/service-bird-lg/tasks/main.yml b/roles/service-bird-lg/tasks/main.yml index 73d7973..875c12c 100644 --- a/roles/service-bird-lg/tasks/main.yml +++ b/roles/service-bird-lg/tasks/main.yml @@ -5,6 +5,7 @@ dest: "{{ lg_path }}" version: master force: yes + become: false - name: install dependencies package: diff --git a/roles/service-nginx-meshviewer/tasks/main.yml b/roles/service-nginx-meshviewer/tasks/main.yml index aac90ec..c454a4e 100644 --- a/roles/service-nginx-meshviewer/tasks/main.yml +++ b/roles/service-nginx-meshviewer/tasks/main.yml @@ -13,10 +13,12 @@ dest: "{{ meshviewer_src }}" version: develop force: yes + become: false - name: install dependencies yarn: path: "{{ meshviewer_src }}" + become: false - name: create meshviewer config template: @@ -25,11 +27,13 @@ mode: 0644 owner: admin group: admin + become: false - name: build shell: yarn run gulp args: chdir: "{{ meshviewer_src }}" + become: false - name: deploy shell: 'rm -rf {{ meshviewer_path }}/* && cp -ar build/* {{ meshviewer_path }} && chown www-data:www-data -R {{ meshviewer_path }}'