Bug 1295908
Summary: | permission denied retrieving etcd cert tarball when using localhost in inventory | ||
---|---|---|---|
Product: | OpenShift Container Platform | Reporter: | Matthew Farrellee <matt> |
Component: | Installer | Assignee: | Scott Dodson <sdodson> |
Status: | CLOSED WONTFIX | QA Contact: | Xiaoli Tian <xtian> |
Severity: | low | Docs Contact: | |
Priority: | high | ||
Version: | 3.1.0 | CC: | aos-bugs, bleanhar, jdetiber, jokerman, matt, mmccomas |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2017-08-24 20:49:40 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Matthew Farrellee
2016-01-05 18:38:01 UTC
Hi Matthew, what user are you running ansible as? I'm curious if we should use 'become' here to escalate privileges. I'll summon Jason. username was cloud-user, which had sudo access Can you provide the following: - version of ansible - full inventory file(s) - the ansible.cfg file if you have made any changes... (lookup path is /ansible.cfg, ~/.ansible.cfg, /etc/ansible.cfg) - The permissions and SELinux contexts of '/tmp/openshift-ansible-S0CPusr/' and '/etc/etcd/generated_certs/etcd-192.1.0.3.tgz' - The error when running ansible-playbook with -vvvv When running under localhost, the task that failed *should* work, since it should be running under sudo already, otherwise the tarball creation would have failed, since it's created under /etc/etcd/generated_certs/ and cloud-user wouldn't have permission. There could be some oddities around our use of the fetch module or SELinux preventing us from accessing the temp directory created without sudo. jason, unfortunately i don't have the environment anymore. |