diff --git a/initial_server_setup/initial_setup.yml b/initial_server_setup/initial_setup.yml index 780347abf92ee3a75c56af11ad6f39068de916e1..f4b99a39dcfe75465449700a2c39bc2c48813209 100644 --- a/initial_server_setup/initial_setup.yml +++ b/initial_server_setup/initial_setup.yml @@ -146,11 +146,14 @@ loop: "{{ users_member | union(users_system) }}" - name: Allow for password-less sudo - community.general.sudoers: - name: passwordless-sudo - group: sudo - commands: ALL - nopassword: true + # Not done via community.general.sudoders because it does not support + # sudo-ing into users without a passsword. + ansible.builtin.copy: + dest: /etc/sudoers.d/passwordless-sudo + content: '%sudo ALL=(ALL:ALL) NOPASSWD: ALL' + owner: root + group: root + mode: '0440' tags: users - name: Reload SSHD