Yorokobi
06/09/2022, 8:06 PMYorokobi
06/09/2022, 8:06 PMcsharpsteen
06/09/2022, 8:08 PMroot
--- so non-root agents isn’t something I’d recommend as it’s pretty much signing up for a perpetual uphill push.Ken Meservy
06/09/2022, 8:09 PMKen Meservy
06/09/2022, 8:09 PMbastelfreak
06/09/2022, 8:10 PMhbui
06/09/2022, 8:10 PMhbui
06/09/2022, 8:10 PMbastelfreak
06/09/2022, 8:10 PMbastelfreak
06/09/2022, 8:10 PMKen Meservy
06/09/2022, 8:12 PMYorokobi
06/09/2022, 8:12 PMKen Meservy
06/09/2022, 8:12 PMcsharpsteen
06/09/2022, 8:12 PMadmin_command
won’t work, but <pick your sudo> admin_command
would work.
However, making that decision is extra complexity which means extra work for module authors. In the grand scheme of things, the number of folks running non-root agents rounds to 0 — so module authors reasonably assume root
and skip the extra work.Yorokobi
06/09/2022, 8:13 PMcapabilities(7)
can the agent use?Ken Meservy
06/09/2022, 8:13 PMYorokobi
06/09/2022, 8:13 PMcapabilities(7)
can the agent use?hbui
06/09/2022, 8:16 PMsystem
? If you can get the security team to see it in terms of a product that they've accepted the risk on, maybe you can get them to budge on puppet. I assume any windows configuration management tools are running as the equivalent of root.Slackbot
06/09/2022, 8:18 PMKen Meservy
06/09/2022, 8:19 PMcsharpsteen
06/09/2022, 8:20 PMSlackbot
06/09/2022, 8:21 PMhbui
06/09/2022, 8:31 PMhbui
06/09/2022, 8:32 PMSamy
06/10/2022, 9:28 AMbastelfreak
06/10/2022, 9:33 AMbastelfreak
06/10/2022, 9:33 AMbastelfreak
06/10/2022, 9:33 AMSlackbot
06/10/2022, 9:34 AMSamy
06/10/2022, 11:02 AM