World-writable /runner and /runner/project make Ansible ignore project ansible.cfg #1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The image sets
/runnerand/runner/projectto mode0777. When AWX runs a container-group job, Ansible (viaansible-runner worker) warns and refuses to read anyansible.cfgfrom the project directory.Evidence
Observed in a real AWX job (
fractal apt update, job 1748) runninggit.valid.dk/daniel/awx-debian-ee:13-latest:Verified from the image:
Root cause
Containerfile:73:AWX's default pod spec has no volumes, so
/runnerkeeps the image's permissions. A project that ships anansible.cfgin its repo root will have it silently ignored, which can change module defaults, callbacks, inventory behaviour, etc. It is also a needless security smell.Suggested fix
The
entrypointonly needs the directory to be writable by an arbitrary UID running with gid 0. Group-writable is sufficient and avoids the world-writable warning:(Keep
chmod ug+rw /etc/passwdsoentrypointcan append the ephemeral UID.) After the change, re-run the smoke test and add a check that the directory is not world-writable.Impact
Cosmetic warning today, but a real behavioural bug for any project relying on a project-local
ansible.cfg.Moved to beads:
work-3j0