Bug 2045508
| Summary: | RFE: Allow created user to sudo without password | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Marko Myllynen <myllynen> |
| Component: | osbuild-composer | Assignee: | Image Builder team <osbuilders> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Release Test Team <release-test-team> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.5 | CC: | obudai, thozza |
| Target Milestone: | rc | Keywords: | FutureFeature, RFE, Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-06-27 13:28:15 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Marko Myllynen
2022-01-25 16:52:43 UTC
Hello Tom, we have this in our EC2 images, right? What about other images? Was there some kind of consensus on how we should handle this? Thanks! (In reply to Ondřej Budai from comment #2) > Hello Tom, > > we have this in our EC2 images, right? What about other images? Was there > some kind of consensus on how we should handle this? The password-less sudo for the default user in EC2 images is configured by cloud-init. AFAIK, we currently don't have any way to achieve this for custom users. There were some discussions about this in the past, but no real consensus or agreement. Nevertheless there is definitely a demand to allow this in composer / image-builder. Since 8.8/9.2, this can be achieved via the custom files customization: [[customizations.files]] path = "/etc/sudoers.d/wheel-passwordless-sudo" mode = "0400" data = """ %wheel ALL=(ALL) NOPASSWD: ALL """ Marko, would that work for you? Yes, that looks reasonable, thanks! |