-
Notifications
You must be signed in to change notification settings - Fork 672
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Docs: Add MD for no-same-owner rule (#2552)
* Docs: Add MD for no-same-owner rule * chore: auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
- Loading branch information
1 parent
655ca30
commit e8c1ecc
Showing
2 changed files
with
56 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
# no-same-owner | ||
|
||
This rule checks that the owner and group do not transfer across hosts. | ||
|
||
In many cases the owner and group on remote hosts do not match the owner and group assigned to source files. | ||
Preserving the owner and group during transfer can result in errors with permissions or leaking sensitive information. | ||
|
||
When you synchronize files, you should avoid transferring the owner and group by setting `owner: false` and `group: false` arguments. | ||
When you unpack archives with the `ansible.builtin.unarchive` module you should set the `--no-same-owner` option. | ||
|
||
This is an opt-in rule. | ||
You must enable it in your Ansible-lint configuration as follows: | ||
|
||
```yaml | ||
enable_list: | ||
- no-same-owner | ||
``` | ||
## Problematic Code | ||
```yaml | ||
--- | ||
- name: Example playbook | ||
hosts: all | ||
tasks: | ||
- name: Synchronize conf file | ||
ansible.posix.synchronize: | ||
src: /path/conf.yaml | ||
dest: /path/conf.yaml # <- Transfers the owner and group for the file. | ||
- name: Extract tarball to path | ||
ansible.builtin.unarchive: | ||
src: "{{ file }}.tar.gz" | ||
dest: /my/path/ # <- Transfers the owner and group for the file. | ||
``` | ||
## Correct Code | ||
```yaml | ||
--- | ||
- name: Example playbook | ||
hosts: all | ||
tasks: | ||
- name: Synchronize conf file | ||
ansible.posix.synchronize: | ||
src: /path/conf.yaml | ||
dest: /path/conf.yaml | ||
owner: false | ||
group: false # <- Does not transfer the owner and group for the file. | ||
- name: Extract tarball to path | ||
ansible.builtin.unarchive: | ||
src: "{{ file }}.tar.gz" | ||
dest: /my/path/ | ||
extra_opts: | ||
- --no-same-owner # <- Does not transfer the owner and group for the file. | ||
``` |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters