You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置免密sudo后Ansible仍提示缺少sudo密码,如何解决?

问题

先后执行两个Ansible playbook,第一个完成以下操作:安装python3、sudo,创建sudo组并添加用户,生成不保存的随机密码,配置SSH密钥对。第二个playbook通过私钥SSH登录执行时,短时间内所有目标主机均报错:

fatal: [HOSTNAME]: FAILED! => {"msg": "Missing sudo password"}

等待一段时间后可正常执行。已尝试删除/tmp/ansible文件、清理/tmp目录、检查过期SSH会话、重启目标主机SSH服务,但问题仍存在。需要消除这段等待时间,询问是否需要清理缓存或重启特定服务。

相关配置代码:

# 配置sudo权限
  - name: Allow 'sudo' group to have passwordless sudo
    lineinfile:
      dest: /etc/sudoers
      state: present
      regexp: '^%sudo'
      line: '%sudo ALL=(ALL) NOPASSWD: ALL'
      validate: '/usr/sbin/visudo -cf %s'

# 后续playbook使用的变量
ansible_host_key_checking: false
ansible_python_interpreter: /usr/bin/python3
ansible_connection: ssh
ansible_user: install
ansible_private_key_file: "{{ hostvars['HOSTNAME']['ssh_keyfile']['stat']['path'] }}"

# 报错的首个任务
- name: Install Zabbix repository on all Zabbix-components servers
  hosts:
    - zbxserver
    - zbxproxy
    - webserver
    - dbserver
  gather_facts: true
  vars_files:
    - vars/general.yaml
    - vars/login.yaml
    - vars/zabbix.yaml
  tasks:
    - name: Install Zabbix repository
      ansible.builtin.raw: |
        apt install curl -y
        curl -O https://repo.zabbix.com/zabbix/6.4/debian/pool/main/z/zabbix-release/zabbix-release_6.4-1+debian12_all.deb
        dpkg -i zabbix-release_6.4-1+debian12_all.deb
        apt remove curl -y
      become: true
      when: do_requirements == "no"
    - name: Update the package cache
      ansible.builtin.apt:
        update_cache: true
      become: true
      when: do_requirements == "no"

解决方案

1. 强制刷新sudoers缓存

sudo配置变更后可能存在缓存未及时生效的情况,在第一个playbook末尾添加任务强制刷新:

- name: Flush sudoers cache
  command: /usr/sbin/visudo -c
  changed_when: false

或者直接重启sudo服务(Debian/Ubuntu适用):

- name: Restart sudo service
  service:
    name: sudo
    state: restarted

2. 实时更新用户组权限

用户加入sudo组后,组信息可能未实时加载,在第一个playbook末尾添加:

- name: Refresh user group membership
  command: newgrp sudo
  become: yes
  become_user: install

也可以在第二个playbook的前置任务中添加:

pre_tasks:
  - name: Refresh group membership for install user
    raw: newgrp sudo || true
    become: no

3. 关闭sudo会话缓存

编辑sudo配置,禁用会话缓存,确保每次sudo都读取最新规则:

- name: Disable sudo timestamp cache
  lineinfile:
    dest: /etc/sudoers
    state: present
    regexp: '^Defaults\s+timestamp_timeout'
    line: 'Defaults        timestamp_timeout=0'
    validate: '/usr/sbin/visudo -cf %s'

4. 明确Ansible的become配置

在第二个playbook中明确指定sudo方法,避免变量冲突:

- name: Install Zabbix repository on all Zabbix-components servers
  hosts:
    - zbxserver
    - zbxproxy
    - webserver
    - dbserver
  gather_facts: true
  become: true
  become_method: sudo
  vars_files:
    - vars/general.yaml
    - vars/login.yaml
    - vars/zabbix.yaml
  # 后续任务...

同时添加空密码变量,强制使用无密码sudo:

vars:
  ansible_become_password: ""

5. 提升sudo规则优先级

将无密码sudo规则放在/etc/sudoers.d/目录下,避免被默认规则覆盖:

- name: Add passwordless sudo for sudo group
  copy:
    content: '%sudo ALL=(ALL) NOPASSWD: ALL'
    dest: /etc/sudoers.d/99-sudo-nopasswd
    mode: 0440
    validate: '/usr/sbin/visudo -cf %s'

内容的提问来源于stack exchange,提问作者w3ich3rt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 11:43:10