-
Notifications
You must be signed in to change notification settings - Fork 5.6k
[FEATURE] Add sesudo support for cmd.run #56726
Copy link
Copy link
Closed
Labels
Execution-ModuleFeaturenew functionality including changes to functionality and code refactors, etc.new functionality including changes to functionality and code refactors, etc.pending-discussionThe issue or pull request needs more discussion before it can be closed or mergedThe issue or pull request needs more discussion before it can be closed or merged
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
Execution-ModuleFeaturenew functionality including changes to functionality and code refactors, etc.new functionality including changes to functionality and code refactors, etc.pending-discussionThe issue or pull request needs more discussion before it can be closed or mergedThe issue or pull request needs more discussion before it can be closed or merged
Is your feature request related to a problem? Please describe.
Let me preface this by saying that the reason I'm not filing this as a bug, is because I believe that salt intentionally works this way.
Our upper environments don't have sudo. They use sesudo roles instead. The only problem we've encountered based on our use cases involve
cmd.run.A simple example:
In essence, we need to have a way for the group to be set without sudo, as well as user ownership. The use case I provided is straightforward, but we are using the command for more complex tasks.
Describe the solution you'd like
We arrive at a solution. If a code change is needed, I can do it.
Describe alternatives you've considered
We have a workaround for the sophisticated use case I mentioned earlier, which involves JBoss security, but it's far from ideal and not something we want as a permanent solution.
Additional context
I think I've found the culprit code and have been tinkering with a solution in my local environment.