World-writable /runner and /runner/project make Ansible ignore project ansible.cfg #1

Closed
opened 2026-09-19 12:23:47 +00:00 by daniel · 1 comment
Owner

Summary

The image sets /runner and /runner/project to mode 0777. When AWX runs a container-group job, Ansible (via ansible-runner worker) warns and refuses to read any ansible.cfg from the project directory.

Evidence

Observed in a real AWX job (fractal apt update, job 1748) running git.valid.dk/daniel/awx-debian-ee:13-latest:

[WARNING]: Ansible is being run in a world writable directory (/runner/project), ignoring it as an ansible.cfg source.

Verified from the image:

$ podman run --rm --user 1000:0 git.valid.dk/daniel/awx-debian-ee:13-latest \
    stat -c '%a %U:%G %n' /runner /runner/project
777 root:root /runner
777 root:root /runner/project

Root cause

Containerfile:73:

RUN mkdir -p /runner/project && chmod 0777 /runner /runner/project \
 && chmod ug+rw /etc/passwd \
 && rm -rf /runner/.ansible

AWX's default pod spec has no volumes, so /runner keeps the image's permissions. A project that ships an ansible.cfg in its repo root will have it silently ignored, which can change module defaults, callbacks, inventory behaviour, etc. It is also a needless security smell.

Suggested fix

The entrypoint only needs the directory to be writable by an arbitrary UID running with gid 0. Group-writable is sufficient and avoids the world-writable warning:

chmod 2775 /runner /runner/project

(Keep chmod ug+rw /etc/passwd so entrypoint can append the ephemeral UID.) After the change, re-run the smoke test and add a check that the directory is not world-writable.

Impact

Cosmetic warning today, but a real behavioural bug for any project relying on a project-local ansible.cfg.

## Summary The image sets `/runner` and `/runner/project` to mode `0777`. When AWX runs a container-group job, Ansible (via `ansible-runner worker`) warns and refuses to read any `ansible.cfg` from the project directory. ## Evidence Observed in a real AWX job (`fractal apt update`, job 1748) running `git.valid.dk/daniel/awx-debian-ee:13-latest`: ``` [WARNING]: Ansible is being run in a world writable directory (/runner/project), ignoring it as an ansible.cfg source. ``` Verified from the image: ``` $ podman run --rm --user 1000:0 git.valid.dk/daniel/awx-debian-ee:13-latest \ stat -c '%a %U:%G %n' /runner /runner/project 777 root:root /runner 777 root:root /runner/project ``` ## Root cause `Containerfile:73`: ``` RUN mkdir -p /runner/project && chmod 0777 /runner /runner/project \ && chmod ug+rw /etc/passwd \ && rm -rf /runner/.ansible ``` AWX's default pod spec has no volumes, so `/runner` keeps the image's permissions. A project that ships an `ansible.cfg` in its repo root will have it silently ignored, which can change module defaults, callbacks, inventory behaviour, etc. It is also a needless security smell. ## Suggested fix The `entrypoint` only needs the directory to be writable by an arbitrary UID running with gid 0. Group-writable is sufficient and avoids the world-writable warning: ``` chmod 2775 /runner /runner/project ``` (Keep `chmod ug+rw /etc/passwd` so `entrypoint` can append the ephemeral UID.) After the change, re-run the smoke test and add a check that the directory is not world-writable. ## Impact Cosmetic warning today, but a real behavioural bug for any project relying on a project-local `ansible.cfg`.
Author
Owner

Moved to beads: work-3j0

Moved to beads: `work-3j0`
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
daniel/awx-debian-ee#1
No description provided.