Skip to content

[FEATURE] Add sesudo support for cmd.run #56726

Description

Is your feature request related to a problem? Please describe.

Let me preface this by saying that the reason I'm not filing this as a bug, is because I believe that salt intentionally works this way.

Our upper environments don't have sudo. They use sesudo roles instead. The only problem we've encountered based on our use cases involve cmd.run.

A simple example:

salt 'minion' cmd.run runas=fake group=fake 'touch /tmp/test;ls -la /tmp/test'
minion:
    ERROR: group argument requires sudo but not found
ERROR: Minions returned with non-zero exit code
salt 'minion' cmd.run runas=fake 'touch /tmp/test;ls -la /tmp/test'
minion:
    -rw-r--r-- 1 fake root 0 Feb 19 17:31 /tmp/test

In essence, we need to have a way for the group to be set without sudo, as well as user ownership. The use case I provided is straightforward, but we are using the command for more complex tasks.

Describe the solution you'd like

We arrive at a solution. If a code change is needed, I can do it.

Describe alternatives you've considered

We have a workaround for the sophisticated use case I mentioned earlier, which involves JBoss security, but it's far from ideal and not something we want as a permanent solution.

Additional context

I think I've found the culprit code and have been tinkering with a solution in my local environment.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Execution-ModuleFeaturenew functionality including changes to functionality and code refactors, etc.pending-discussionThe issue or pull request needs more discussion before it can be closed or merged

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions