It's handy to be able to create users that *don't* have sudo rights.
Here at Stanford we use this to add users to our VPC bastion box (ssh
proxy) so these users can use this machine for ssh tunneling, but I
don't want to give those users the keys to the kingdom.
This let's me configure a playbook like this.
roles:
- common
- supervisor
- role: gh_users
gh_users:
- su1
- su2
- su3
gh_users_no_sudo:
- normal1
- normal2
The new gh_users_no_sudo list can be empty.
| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| .gitignore | Loading commit data... | |
| README.md | Loading commit data... | |
| ansible.cfg | Loading commit data... | |
| carnegie-prod-app.yml | Loading commit data... | |
| carnegie-prod-worker.yml | Loading commit data... | |
| cloudformation.yml | Loading commit data... | |
| cme-prod-app.yml | Loading commit data... | |
| cme-prod-worker.yml | Loading commit data... | |
| ec2.ini | Loading commit data... | |
| ec2.py | Loading commit data... | |
| edxapp_rolling_example.yml | Loading commit data... | |
| files | Loading commit data... | |
| group_vars | Loading commit data... | |
| prod-app.yml | Loading commit data... | |
| prod-jumpbox.yml | Loading commit data... | |
| prod-log.yml | Loading commit data... | |
| prod-ora.yml | Loading commit data... | |
| prod-worker.yml | Loading commit data... | |
| prod-xqueue.yml | Loading commit data... | |
| roles | Loading commit data... | |
| secure_example | Loading commit data... | |
| stage-all.yml | Loading commit data... | |
| stage-ansible.cfg | Loading commit data... | |
| stage-app.yml | Loading commit data... | |
| stage-debug.yml | Loading commit data... | |
| stage-jumpbox.yml | Loading commit data... | |
| stage-log.yml | Loading commit data... | |
| stage-notifier-only.yml | Loading commit data... | |
| stage-ora.yml | Loading commit data... | |
| stage-rabbit.yml | Loading commit data... | |
| stage-ssh-config | Loading commit data... | |
| stage-worker.yml | Loading commit data... | |
| stage-xqueue.yml | Loading commit data... |