Skip to content

Commit 121ffbd

Browse files
thirasclaude
andcommitted
docs(ansible): mark -u root as a placeholder for the image's bootstrap user
Also note that a per-host ansible_user must be added only after bootstrap, since it overrides -u on the first converge. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 0701993 commit 121ffbd

2 files changed

Lines changed: 8 additions & 5 deletions

File tree

‎ansible/README.md‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -96,14 +96,16 @@ bootstrap each new host once as a sudo-capable user (root, or the image's defaul
9696
as `ubuntu`):
9797

9898
```bash
99-
make deploy LIMIT=decdn-node-1 ANSIBLE_ARGS='-u root' # first converge only
100-
make deploy LIMIT=decdn-node-1 # every run after that
99+
make deploy LIMIT=decdn-node-1 ANSIBLE_ARGS='-u root' # first converge only; swap root for your image's bootstrap user
100+
make deploy LIMIT=decdn-node-1 # every run after that first converge succeeds
101101
```
102102

103103
Set a per-host `ansible_user` only when the admin account's name differs from your `$USER`
104104
(you listed a different name in `baseline_sudo_users`) or you set
105105
`baseline_sudo_autodetect_runner: false`. Never set it to the bootstrap user: an inventory
106-
`ansible_user` beats `-u`, and root login is gone after the first converge.
106+
`ansible_user` beats `-u`, and root login is gone after the first converge. For the same
107+
reason, add a per-host `ansible_user` only after that host's bootstrap run, or `-u` is
108+
ignored on the first converge.
107109

108110
---
109111

‎ansible/inventory/hosts.yml.example‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,12 +7,13 @@
77
# account the baseline role creates (the auto-detected runner). A fresh box doesn't have
88
# it yet, so bootstrap each new host ONCE as a user that can sudo (root, or the image's
99
# default user such as ubuntu):
10-
# make deploy LIMIT=<host> ANSIBLE_ARGS='-u root'
10+
# make deploy LIMIT=<host> ANSIBLE_ARGS='-u root' # swap root for your image's bootstrap user
1111
# After that first converge ssh_hardening disables root login, and plain `make deploy`
1212
# connects as $USER. Set a per-host ansible_user only if the admin account's name differs
1313
# from your $USER (you listed another name in baseline_sudo_users) or you set
1414
# baseline_sudo_autodetect_runner: false. Never set it to the bootstrap user: an
1515
# inventory ansible_user overrides -u, and root login is gone after the first converge.
16+
# For the same reason, add a per-host ansible_user only AFTER that host's bootstrap run.
1617
#
1718
# Ubuntu sudo-rs workaround: 25.10 (Questing) and 26.04 ship sudo-rs as the default
1819
# /usr/bin/sudo. Ansible's sudo become plugin passes a custom `-p` prompt sentinel and
@@ -35,5 +36,5 @@ decdn_nodes:
3536
hosts:
3637
decdn-node-1:
3738
ansible_host: REPLACE_WITH_NODE_VPS_IP_OR_DNS
38-
# ansible_user: alice # only if the admin account's name ≠ your $USER — see note above
39+
# ansible_user: alice # post-bootstrap, only if the admin account's name ≠ your $USER — see note above
3940
# ansible_become_exe: /usr/bin/sudo.ws # Ubuntu sudo-rs workaround — see note above

0 commit comments

Comments
 (0)