#11796 Member of sysadmin&sysadmin-coreos unable to run rbac-playbook on batcave
Closed: Fixed with Explanation a year ago by c4rt0. Opened a year ago by c4rt0.

I am a member of both sysadmin and sysadmin-coreos.

[c4rt0@batcave01 ~][PROD-IAD2]$ groups
c4rt0 signed_fpca fedora-contributor fedorabugs packager sysadmin sysadmin-coreos

I was expecting to be able to run :

[c4rt0@batcave01 ~][PROD-IAD2]$ rbac-playbook -C openshift-apps/fedora-coreos-pipeline.yml

The above attempt however fails with an error:

Sorry, user c4rt0 is not allowed to execute '/bin/bash -i -c cd /srv/web/infra/ansible ; /usr/bin/python3 /usr/bin/ansible-playbook /srv/web/infra/ansible/playbooks/openshift-apps/fedora-coreos-pipeline.yml --check' as root on batcave01.iad2.fedoraproject.org.

Can I please receive some assistance here?
cc. @cverna


Metadata Update from @zlopez:
- Issue tagged with: Needs investigation

a year ago

You need to use 'sudo' for the command?

Pretty sure we tried with sudo, could you check that sysadmin-coreos actually gives permission to this playbook?

Metadata Update from @phsmoura:
- Issue priority set to: Waiting on Assignee (was: Needs Review)
- Issue tagged with: low-gain, low-trouble, ops

a year ago

Only now I verified the above and it turns out I was not using sudo.
Thank you @kevin & @cverna - this issue can now be closed.

Metadata Update from @c4rt0:
- Issue close_status updated to: Fixed with Explanation
- Issue status updated to: Closed (was: Open)

a year ago

Log in to comment on this ticket.

Metadata
Boards 1
ops Status: Backlog