volker.raschekandCopilot c3f714a7c6 fix(tasks)!: stop flushing /etc/sudoers.d
Recreating /etc/sudoers.d on every run deleted every drop-in file on the host, not only the ones managed by this role.
That removes files shipped by packages or other tooling, such as 90-cloud-init-users on cloud instances, which can lock
out the remaining login paths. The task also reported changed on every run and therefore made check mode and CI runs
useless for detecting real drift.

The directory is now only ensured with its owner, group and permissions. To keep entries removable, each item of
sudo_users_sudoers accepts an optional state, which is passed to community.general.sudoers and defaults to present.

BREAKING CHANGE: Entries dropped from sudo_users_sudoers are no longer deleted implicitly. Set state: absent on the
entry to remove its drop-in file.

Co-authored-by: Copilot <copilot@github.com>
2026-09-10 21:41:34 +02:00
2025-11-23 16:19:51 +01:00
2025-11-23 16:19:51 +01:00
2025-04-14 22:31:30 +02:00
2022-05-10 13:40:31 +02:00
2025-04-14 22:31:30 +02:00
2025-04-14 22:31:30 +02:00
2025-04-14 22:31:30 +02:00
2022-05-10 13:40:31 +02:00
2025-06-01 12:27:38 +02:00

sudo_users

Ansible Role

With following role can be created sudoers files in /etc/sudoers.d. For example to grant a user special perimssions to execute a program as root.

Supported distributions

  • Arch Linux
  • Debian
  • Fedora
  • RHEL
  • Ubuntu 20.04

Features

  • Installing sudo
  • Configuring drop-on files in /etc/sudoers.d

Configuring

In the default directory are examples how to configure the network stack. Copy the defaults into your host_vars or group_vars and adapt the examples.

S
Description
Ansible role to create drop-in files for sudoers.d
Readme MIT
158 KiB