ansible-community / ansible-nomad

:watch: Ansible role for Nomad
https://galaxy.ansible.com/brianshumate/nomad
BSD 2-Clause "Simplified" License
294 stars 163 forks source link

What specific task needs sudo/root privilege's when nomad_user is not root? #145

Open saurabh-sp-tripathi opened 2 years ago

saurabh-sp-tripathi commented 2 years ago

I understand the nomad need to be start/restart as a 'root' user because many operation it runs, needs root privilege.

However as a system admin I would like to harden/limit the scope of 'sudo' access to specific tasks only. As far as I have analyzed the following will need sudo/become/root privilege's:

Is there anything out of this list ? and Is there any cautions or recommendations?

ref: https://www.nomadproject.io/docs/install/production/requirements